🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
US-AK · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 15 sources retrieved model claude-sonnet-5 ·

United States – Alaska

US-AK schema gdpri-v2 trajectory: not recordedregulated (sectoral)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 20 claims · 15 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
20Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

A functioning breach-notification/PII-protection statute and an insurance-sector security law exist and are enforced by the AG and Division of Insurance, but there is no omnibus privacy statute, no dedicated DPA, and no general registration/filing regime.

Primary frameworkAlaska Personal Information Protection Act, AS 45.48.010 et seq.
Supervisory authorityOffice of the Attorney General, State of Alaska (Consumer Protection Unit)
Traffic-light rationale — AmberA functioning breach-notification/PII-protection statute and an insurance-sector security law exist and are enforced by the AG and Division of Insurance, but there is no omnibus privacy statute, no dedicated DPA, and no general registration/filing regime.

Sub-modules (5)

Regulator And AuthorityAmber

The Alaska AG enforces APIPA and is a Consumer Sentinel Network data contributor; the Division of Insurance enforces the Insurance Data Security Act.

Claims (2):

  • The Alaska Attorney General's office is the enforcing authority for the Alaska Personal Information Protection Act (breach notification, SSN protection, disposal, credit freeze).
  • The Alaska Attorney General is a listed data contributor to the FTC's Consumer Sentinel Network, evidencing its consumer-protection enforcement role relevant to data-privacy complaints.

Act And InstrumentsAmber

Core instruments are AS 45.48 (PIPA/breach notification) and the 2024 Insurance Data Security Act (SB134); no omnibus consumer privacy act exists.

Claims (2):

  • The Personal Information Protection Act under AS 45.48.010 et seq. of Chapter 47 of Title 45 of the Alaska Statutes was signed into law and entered into force on July 1, 2009.
  • Alaska enacted an Insurance Data Security Act (SB134) which became law without the Governor's signature, imposing data security standards on insurance licensees.

Material ScopeAmber

Material scope is limited to statutorily defined 'personal information' for breach/disposal/SSN purposes; it does not extend to general 'processing' of personal data as GDPR-style regimes do.

Claims (1):

  • APIPA's protections are structured around specific categories -- Social Security numbers, credit/financial account information, and records requiring disposal -- rather than a broad definition of 'processing' of personal data.

Territorial ScopeAmber

APIPA applies extraterritorially to any entity that owns, licenses, or maintains personal information of Alaska residents, mirroring the standard US state breach-law approach.

Claims (1):

  • Alaska's breach-notification and SSN-protection obligations apply to any business or government entity holding personal information of Alaska residents, regardless of the entity's state of establishment.

Regulator Registration And FilingRed

No general controller/processor registration or filing regime exists at state level; the Insurance Data Security Act introduces sector-specific security-program obligations to the Division of Insurance for licensees only.

Absence provenance: not recorded. Searched: Alaska data controller registration requirement, Alaska DPA filing obligation.

Claims (1):

  • No general data-controller or processor registration/filing regime applies in Alaska outside of insurance-sector security-program obligations under the new Insurance Data Security Act.
Category narrative91 words

Alaska has no dedicated data-protection authority. The Alaska Attorney General's Consumer Protection Unit enforces the state's breach-notification and information-security statutes (Personal Information Protection Act, AS 45.48) and is a recognized contributor to the FTC's Consumer Sentinel Network. A second sectoral regulator, the Alaska Division of Insurance, administers the newly enacted Insurance Data Security Act (2024 SB134). Repeated attempts to enact a comprehensive consumer data privacy statute (SB116, HB159, HB222) have failed to pass the legislature, so the material and territorial scope of Alaska's regime is narrower and sector/breach-specific rather than omnibus.

Sources and claims (7)
  1. ProbableFederal Trade Commission / Alaska Dept. of LawThe Alaska Attorney General's office is the enforcing authority for the Alaska Personal Information Protection Act (breach notification, SSN protection, disposal, credit freeze).observed
  2. ConfirmedFederal Trade CommissionThe Alaska Attorney General is a listed data contributor to the FTC's Consumer Sentinel Network, evidencing its consumer-protection enforcement role relevant to data-privacy complaints.observed
  3. ProbableOneTrust DataGuidanceThe Personal Information Protection Act under AS 45.48.010 et seq. of Chapter 47 of Title 45 of the Alaska Statutes was signed into law and entered into force on July 1, 2009.observed
  4. ProbableOneTrust DataGuidanceAlaska enacted an Insurance Data Security Act (SB134) which became law without the Governor's signature, imposing data security standards on insurance licensees.observed
  5. ProbableOneTrust DataGuidanceAPIPA's protections are structured around specific categories -- Social Security numbers, credit/financial account information, and records requiring disposal -- rather than a broad definition of 'processing' of personal data.observed
  6. ProbableFederal Trade Commission / Alaska Dept. of LawAlaska's breach-notification and SSN-protection obligations apply to any business or government entity holding personal information of Alaska residents, regardless of the entity's state of establishment.observed
  7. UncertainOneTrust DataGuidanceNo general data-controller or processor registration/filing regime applies in Alaska outside of insurance-sector security-program obligations under the new Insurance Data Security Act.observed

#

No state-level lawful-basis, consent, sensitive-data, or anonymisation framework exists; reliance is entirely on federal sectoral law.

Traffic-light rationale — RedNo state-level lawful-basis, consent, sensitive-data, or anonymisation framework exists; reliance is entirely on federal sectoral law.

Sub-modules (4)

Lawful BasesRed

No Alaska statute enumerates lawful bases for processing personal data akin to GDPR Art 6.

Absence provenance: not recorded. Searched: Alaska lawful basis for processing personal data, Alaska Consumer Data Privacy Act SB116 HB159.

Special CategoriesRed

No Alaska statute defines a general category of 'sensitive' or 'special category' personal data; sensitive-data protections arise only via federal HIPAA/GINA overlays.

Absence provenance: not recorded. Searched: Alaska sensitive data statute, Alaska genetic privacy act.

Pseudonymisation And AnonymisationRed

No Alaska statutory definition of pseudonymisation or anonymisation, nor an associated safe harbour, was located.

Absence provenance: not recorded. Searched: Alaska anonymisation safe harbor statute.

Category narrative42 words

Alaska has no GDPR-style enumerated lawful-basis regime, no general consent standard for commercial data processing, and no statutory definition of 'special category'/sensitive data outside of federal sectoral overlays (HIPAA for health, GINA for genetic-employment discrimination). No state pseudonymisation/anonymisation safe-harbour framework was identified.

#

No omnibus subject-rights framework exists at state level; only breach-notification receipt and credit-freeze rights are state-conferred.

Primary frameworkAlaska Personal Information Protection Act, AS 45.48.010 et seq.
Supervisory authorityOffice of the Attorney General, State of Alaska
Traffic-light rationale — RedNo omnibus subject-rights framework exists at state level; only breach-notification receipt and credit-freeze rights are state-conferred.

Sub-modules (5)

Access RightRed

No general state-law access right to personal data exists; federal FCRA/HIPAA access rights apply only in their respective sectors.

Absence provenance: not recorded. Searched: Alaska right to access personal data statute.

Rectification And ErasureRed

No Alaska statutory right to rectify or erase personal data held by private businesses.

Absence provenance: not recorded. Searched: Alaska right to erasure statute.

Restriction And ObjectionRed

No Alaska statutory restriction/objection right (including profiling opt-out) exists.

Absence provenance: not recorded. Searched: Alaska right to object profiling.

Data PortabilityRed

No Alaska data-portability right exists.

Absence provenance: not recorded. Searched: Alaska data portability right.

Deadlines And Response WindowsAmber

The only statutory response-window concept is the breach-notification timing obligation under APIPA, requiring notification without unreasonable delay following discovery of a breach.

Claims (1):

  • Alaska's Personal Information Protection Act requires businesses to notify the Attorney General, affected subscribers, and, where applicable, a credit reporting agency in the event of a breach of security concerning personal information.
Category narrative67 words

Alaska law does not grant a general access, rectification, erasure, restriction, objection, or portability right over personal data held by private-sector businesses. The only individual-facing rights under state law are breach-notification receipt, the ability to place/lift a security freeze on a credit report, and disposal obligations on holders of personal information; substantive access/correction rights exist only via federal sectoral law (e.g., FCRA file-disclosure rights, HIPAA access rights).

Sources and claims (1)
  1. ProbableOneTrust DataGuidanceAlaska's Personal Information Protection Act requires businesses to notify the Attorney General, affected subscribers, and, where applicable, a credit reporting agency in the event of a breach of security concerning personal information.observed

#

Concrete, enforceable security and breach-notification/disposal duties exist for general businesses (APIPA) and insurance licensees (SB134), but accountability-style obligations (DPIA, DPO, ROPA, joint-controller) are entirely absent.

Primary frameworkAlaska Personal Information Protection Act (AS 45.48) and Alaska Insurance Data Security Act (SB134, 2024)
Supervisory authorityOffice of the Attorney General, State of Alaska
Traffic-light rationale — AmberConcrete, enforceable security and breach-notification/disposal duties exist for general businesses (APIPA) and insurance licensees (SB134), but accountability-style obligations (DPIA, DPO, ROPA, joint-controller) are entirely absent.

Sub-modules (7)

Accountability And DpiaRed

No DPIA or general accountability-principle obligation exists in Alaska statute.

Absence provenance: not recorded. Searched: Alaska DPIA requirement, Alaska privacy impact assessment statute.

Dpo RequirementsRed

No DPO appointment requirement exists under Alaska law.

Absence provenance: not recorded. Searched: Alaska data protection officer requirement.

Ropa RequirementsRed

No records-of-processing obligation exists under Alaska law.

Absence provenance: not recorded. Searched: Alaska records of processing activities requirement.

Joint Controller ArrangementsRed

No statutory joint-controller framework exists in Alaska.

Absence provenance: not recorded. Searched: Alaska joint controller statute.

Security MeasuresAmber

The Insurance Data Security Act requires insurance licensees to implement an information security program; APIPA separately requires reasonable safeguards implicit in its breach and disposal duties.

Claims (1):

  • Alaska's Insurance Data Security Act (SB134) sets data security standards for insurance licensees, mandating implementation of an information security program.

Breach NotificationAmber

APIPA requires notification to the Alaska AG, affected residents, and (where thresholds are met) consumer reporting agencies following a security breach involving personal information.

Claims (1):

  • The Alaska Personal Information Protection Act requires notification to the Alaska Attorney General, subscribers, and (if applicable) a credit reporting agency in the event of a breach of security concerning personal information.

Retention And DisposalAmber

APIPA requires proper disposal of records containing personal information and truncation of credit card information in records.

Claims (1):

  • Alaska's Personal Information Protection Act mandates the disposal of records containing personal information and truncation of credit card information.
Category narrative56 words

Alaska imposes two concrete controller-side duties: (1) breach notification and secure disposal of records containing personal information under APIPA, AS 45.48; and (2) an information-security-program mandate on insurance licensees under the 2024 Insurance Data Security Act (SB134), modeled on the NAIC data security model law. No DPIA, DPO, ROPA, or joint-controller framework exists at state level.

Sources and claims (3)
  1. ProbableOneTrust DataGuidanceAlaska's Insurance Data Security Act (SB134) sets data security standards for insurance licensees, mandating implementation of an information security program.observed
  2. ProbableOneTrust DataGuidanceThe Alaska Personal Information Protection Act requires notification to the Alaska Attorney General, subscribers, and (if applicable) a credit reporting agency in the event of a breach of security concerning personal information.observed
  3. ProbableOneTrust DataGuidanceAlaska's Personal Information Protection Act mandates the disposal of records containing personal information and truncation of credit card information.observed

#

No state cross-border transfer regime exists; this module is structurally inapplicable to a US sectoral-only state absent an omnibus statute.

Traffic-light rationale — RedNo state cross-border transfer regime exists; this module is structurally inapplicable to a US sectoral-only state absent an omnibus statute.

Sub-modules (6)

Transfer MechanismsRed

No Alaska-specific transfer mechanism exists.

Absence provenance: not recorded. Searched: Alaska cross border data transfer law.

Adequacy ReceivedRed

Not applicable; adequacy determinations are a federal/international concept, not exercised by individual US states.

Absence provenance: not recorded. Searched: Alaska adequacy decision.

Adequacy GrantedRed

Not applicable for the same reason.

Absence provenance: not recorded. Searched: Alaska adequacy granted.

Sccs And BcrsRed

No Alaska SCC/BCR framework exists.

Absence provenance: not recorded. Searched: Alaska standard contractual clauses requirement.

Transfer Impact AssessmentRed

No TIA requirement exists under Alaska law.

Absence provenance: not recorded. Searched: Alaska transfer impact assessment requirement.

Data LocalisationRed

No Alaska data-localisation mandate was identified.

Absence provenance: not recorded. Searched: Alaska data localisation requirement.

Category narrative54 words

As a US state without an omnibus privacy statute, Alaska has no state-level cross-border transfer mechanism, adequacy regime, SCC/BCR framework, transfer-impact-assessment requirement, or data-localisation mandate. Any cross-border constraints affecting Alaska-based data flows derive solely from federal sectoral law (e.g., GLBA safeguards for financial data, HIPAA for health data) rather than a state-specific transfer regime.

#

A concrete, enacted insurance-sector data-security law exists and is material, but most other sectors rely entirely on federal sectoral law with no Alaska-specific overlay.

Primary frameworkAlaska Insurance Data Security Act (SB134, 2024); federal GLBA/HIPAA/FCRA
Supervisory authorityAlaska Division of Insurance
Traffic-light rationale — AmberA concrete, enacted insurance-sector data-security law exists and is material, but most other sectors rely entirely on federal sectoral law with no Alaska-specific overlay.

Sub-modules (7)

Financial Sector OverlayAmber

Financial-sector personal data in Alaska is governed by the federal GLBA Safeguards Rule; no Alaska-specific banking-privacy overlay was identified.

Claims (1):

  • Financial institutions operating in Alaska are subject to the federal Gramm-Leach-Bliley Act's Safeguards Rule for protection of nonpublic personal financial information, in the absence of an Alaska-specific banking privacy statute.

Health Sector OverlayAmber

Health data is governed by federal HIPAA/HITECH; no comprehensive Alaska-specific health-privacy statute beyond HIPAA was identified in this pass.

Claims (1):

  • Health information held by covered entities operating in Alaska is subject to the federal HIPAA Privacy and Security Rules in the absence of an Alaska-specific comprehensive health-privacy statute.

Telecoms And EprivacyRed

No Alaska ePrivacy/cookie-consent statute exists; federal ECPA/TCPA govern telecoms privacy.

Absence provenance: not recorded. Searched: Alaska ePrivacy law, Alaska telecoms privacy statute.

Employment DataRed

No comprehensive Alaska employment-data-privacy statute was identified.

Absence provenance: not recorded. Searched: Alaska employee data privacy law.

Credit And ScoringAmber

Federal FCRA governs credit reporting; Alaska's APIPA supplements this with a statutory right to place a security freeze on a consumer credit report.

Claims (1):

  • Alaska's Personal Information Protection Act provides consumers the ability to place a security freeze on a consumer credit report, supplementing federal FCRA protections.

EducationRed

Federal FERPA/COPPA/PPRA govern student data; no Alaska-specific comprehensive student-data-privacy statute (akin to California's SOPIPA) was identified in this research pass.

Absence provenance: not recorded. Searched: Alaska student data privacy law, Alaska SOPIPA equivalent.

InsuranceGreen

Alaska enacted an Insurance Data Security Act (SB134) in 2024, becoming law without the Governor's signature, imposing NAIC-model-law-style data security standards on insurance licensees.

Claims (1):

  • Alaska's Senate Bill 134 sets data security standards for insurance licensees and became law without the Governor's approval.
Category narrative76 words

Alaska's data-protection landscape is almost entirely sectoral. Financial-sector data is governed by the federal Gramm-Leach-Bliley Act safeguards rule; health data by HIPAA/HITECH; credit/scoring by the federal Fair Credit Reporting Act supplemented by Alaska's security-freeze provisions under APIPA; and insurance-sector cybersecurity by Alaska's newly enacted Insurance Data Security Act (SB134, 2024), which is the most significant Alaska-specific sectoral development. No Alaska-specific telecoms/ePrivacy, employment-data, or comprehensive education-sector privacy statute was identified in this pass beyond federal FERPA/COPPA/PPRA baselines.

Sources and claims (4)
  1. ConfirmedFederal Trade CommissionFinancial institutions operating in Alaska are subject to the federal Gramm-Leach-Bliley Act's Safeguards Rule for protection of nonpublic personal financial information, in the absence of an Alaska-specific banking privacy statute.observed
  2. ConfirmedHHS OCRHealth information held by covered entities operating in Alaska is subject to the federal HIPAA Privacy and Security Rules in the absence of an Alaska-specific comprehensive health-privacy statute.observed
  3. ProbableOneTrust DataGuidanceAlaska's Personal Information Protection Act provides consumers the ability to place a security freeze on a consumer credit report, supplementing federal FCRA protections.observed
  4. ProbableOneTrust DataGuidanceAlaska's Senate Bill 134 sets data security standards for insurance licensees and became law without the Governor's approval.observed

#

This entire module is unregulated at the state level in Alaska; only generic federal FTC Act unfairness/deception authority and federal telemarketing/email statutes apply.

Traffic-light rationale — RedThis entire module is unregulated at the state level in Alaska; only generic federal FTC Act unfairness/deception authority and federal telemarketing/email statutes apply.

Sub-modules (6)

Cookies And TrackersRed

No Alaska cookie-consent statute exists.

Absence provenance: not recorded. Searched: Alaska cookie consent law.

Dark PatternsRed

No Alaska-specific dark-patterns prohibition exists; only generic federal FTC Act unfairness/deception authority applies.

Absence provenance: not recorded. Searched: Alaska dark patterns statute.

Opt Out SignalsRed

No Alaska statute recognizes Global Privacy Control or similar opt-out signals.

Absence provenance: not recorded. Searched: Alaska Global Privacy Control recognition.

Clean Rooms And DcrRed

No Alaska regulation of data clean rooms/collaboration rooms exists.

Absence provenance: not recorded. Searched: Alaska data clean room regulation.

Cross Context AdvertisingRed

No CPRA-style 'sale'/'share' restriction on cross-context advertising exists under Alaska law.

Absence provenance: not recorded. Searched: Alaska sale of personal information restriction advertising.

Direct MarketingRed

Direct marketing in Alaska is governed only by federal TCPA/CAN-SPAM baselines; no Alaska-specific consent/suppression statute for direct marketing was identified.

Absence provenance: not recorded. Searched: Alaska direct marketing consent statute, Alaska do not call telemarketing statute.

Category narrative43 words

Alaska has no cookie/tracker consent statute, no dark-patterns prohibition, no opt-out-signal mandate (e.g., GPC recognition), no clean-room regulation, and no CPRA-style 'sale'/'share' restriction on cross-context advertising. Direct marketing is governed only by federal TCPA/CAN-SPAM; no Alaska-specific direct-marketing consent or suppression statute was identified.

#

No AI, ADM, biometric, or genetic-data statute exists in Alaska; the only relevant state-law hook is the general constitutional privacy clause, which does not provide AI/biometric-specific governance.

Primary frameworkConstitution of the State of Alaska, Article I, Section 22 (general right of privacy; not AI/biometric-specific)
Traffic-light rationale — RedNo AI, ADM, biometric, or genetic-data statute exists in Alaska; the only relevant state-law hook is the general constitutional privacy clause, which does not provide AI/biometric-specific governance.

Sub-modules (6)

Profiling RestrictionsRed

No Alaska profiling-restriction statute exists.

Absence provenance: not recorded. Searched: Alaska profiling restriction statute.

Automated Decision Making TransparencyRed

No Alaska ADM-transparency or explanation-right statute exists.

Absence provenance: not recorded. Searched: Alaska automated decision-making transparency law.

Ai Risk AssessmentsRed

No Alaska AI-specific risk-assessment statute exists.

Absence provenance: not recorded. Searched: Alaska AI risk assessment law 2026.

Biometric RegimeRed

No dedicated Alaska biometric-data statute (comparable to Illinois BIPA) was identified.

Absence provenance: not recorded. Searched: Alaska biometric privacy statute, Alaska BIPA equivalent.

Genetic DataRed

No dedicated Alaska genetic-data-privacy statute was identified in this research pass.

Absence provenance: not recorded. Searched: Alaska genetic privacy law, Alaska genetic information nondiscrimination statute.

State Surveillance CarveoutsAmber

Alaska's Constitution contains an explicit right-to-privacy clause (Article I, Section 22) that has informed state constitutional privacy jurisprudence, though national-security/law-enforcement carveouts follow federal law.

Claims (1):

  • The Constitution of the State of Alaska, Article I, Section 22, contains an explicit textual right to privacy, distinguishing Alaska from the majority of US states that lack such an express constitutional privacy clause.
Category narrative74 words

Alaska has no profiling-restriction statute, no ADM-transparency/explanation right, no AI-specific risk-assessment law, and no dedicated biometric-privacy statute (i.e., no Illinois-BIPA equivalent) or genetic-data statute located in this research pass. Alaska's Constitution, Article I, Section 22, contains an explicit textual right to privacy that has been a basis for state constitutional privacy litigation, which is the closest state-law analogue to a general privacy protection in this space, though it is not itself an AI/biometric-specific statute.

Sources and claims (1)
  1. ProbableState of AlaskaThe Constitution of the State of Alaska, Article I, Section 22, contains an explicit textual right to privacy, distinguishing Alaska from the majority of US states that lack such an express constitutional privacy clause.observed

#

No Alaska-specific children's or vulnerable-groups data statute exists beyond the state's participation as a commenting/enforcing party in federal COPPA rulemaking.

Primary frameworkChildren's Online Privacy Protection Act (COPPA); FERPA; PPRA (all federal)
Supervisory authorityFederal Trade Commission (COPPA); Alaska Attorney General (state enforcement coordination)
Traffic-light rationale — RedNo Alaska-specific children's or vulnerable-groups data statute exists beyond the state's participation as a commenting/enforcing party in federal COPPA rulemaking.

Sub-modules (5)

Age VerificationRed

No Alaska-specific age-verification statute exists; COPPA's federal age-13 threshold governs.

Claims (1):

  • The Alaska Attorney General was among the state attorneys general who submitted comments to the FTC's 2024 COPPA Rule review, reflecting Alaska's participation in federal children's-privacy rulemaking rather than a separate state age-verification regime.

Minor Profiling BansRed

No Alaska minor-profiling-ban statute exists.

Absence provenance: not recorded. Searched: Alaska minor profiling ban.

Education SettingsRed

Education-sector privacy is governed federally by FERPA/PPRA; no Alaska-specific student-data-privacy statute was identified.

Absence provenance: not recorded. Searched: Alaska student data privacy statute.

Dependent AdultsRed

No Alaska data-privacy-specific statute for dependent/vulnerable adults was identified; general adult-protective-services statutes address abuse/exploitation but not data privacy specifically.

Absence provenance: not recorded. Searched: Alaska dependent adult data privacy statute.

Category narrative55 words

Children's data privacy in Alaska is governed entirely by federal law: COPPA for children under 13 (enforced by the FTC and, per COPPA rulemaking comment records, jointly monitored by state AGs including Alaska's), and FERPA/PPRA for education records. No Alaska-specific age-verification, parental-consent supplement, minor-profiling ban, or dependent-adults data-privacy statute was identified in this research pass.

Sources and claims (1)
  1. ConfirmedFederal Trade CommissionThe Alaska Attorney General was among the state attorneys general who submitted comments to the FTC's 2024 COPPA Rule review, reflecting Alaska's participation in federal children's-privacy rulemaking rather than a separate state age-verification regime.observed

#

AG enforcement capacity and multistate settlement participation are confirmed, but private-right-of-action, regulator funding/capacity, and 180-day developments are unconfirmed or negative findings.

Primary frameworkAlaska Personal Information Protection Act (AS 45.48); general Alaska Unfair Trade Practices and Consumer Protection Act
Supervisory authorityOffice of the Attorney General, State of Alaska
Traffic-light rationale — AmberAG enforcement capacity and multistate settlement participation are confirmed, but private-right-of-action, regulator funding/capacity, and 180-day developments are unconfirmed or negative findings.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

APIPA sets out penalties for violations of its business obligations, enforced by the Alaska Attorney General; exact statutory penalty figures were not independently re-verified this session.

Claims (1):

  • Alaska's Personal Information Protection Act sets out penalties for violations of the business obligations it imposes, enforceable by the Alaska Attorney General.

Enforcement Activity IndexAmber

Alaska's AG has participated in multistate breach-related settlements, including a $5M multistate settlement with Community Health Systems and a $39.5M multistate settlement with Anthem, both arising from healthcare data breaches.

Claims (2):

  • 27 state attorneys general, including Alaska, announced a $5 million settlement with Community Health Systems following a data breach affecting 6.1 million patients.
  • Anthem settled for $39.5 million with 43 state attorneys general, including Alaska, over a 2014 data breach affecting 78.8 million customers.

Regulator Funding And CapacityRed

No specific data on Alaska AG Consumer Protection Unit staffing or budget dedicated to privacy enforcement was located in this research pass.

Absence provenance: not recorded. Searched: Alaska Attorney General consumer protection unit budget staffing.

Collective Redress And Class ActionsRed

No Alaska-specific class-action mechanism dedicated to data-privacy claims beyond general Alaska civil procedure was identified.

Absence provenance: not recorded. Searched: Alaska class action data privacy mechanism.

Private Right Of ActionRed

No confirmed private right of action under APIPA was located; enforcement appears centered on the Attorney General.

Absence provenance: not recorded. Searched: Alaska Personal Information Protection Act private right of action.

Recent Developments 180DRed

No Alaska-specific data-privacy legislative or enforcement development within the last 180 days (i.e., since approximately February 2026) was identified; the most recent substantive development remains the 2024 enactment of the Insurance Data Security Act and continued failure of comprehensive consumer privacy bills.

Absence provenance: not recorded. Searched: Alaska data privacy law 2026, Alaska consumer data privacy act status legislature, Alaska HB 222 consumer data protection 2025 2026.

Category narrative84 words

Enforcement in Alaska is centered on the Attorney General's Consumer Protection Unit, which can bring actions under APIPA and participates in multistate data-breach settlements (e.g., the multistate Community Health Systems and Anthem settlements). No dedicated private right of action under APIPA was confirmed in this research pass, and no Alaska-specific class-action mechanism beyond general Alaska civil procedure was identified. No legislative or enforcement developments specific to Alaska data privacy were identified within the last 180 days beyond the continuing failure of comprehensive privacy bills.

Sources and claims (3)
  1. ProbableOneTrust DataGuidanceAlaska's Personal Information Protection Act sets out penalties for violations of the business obligations it imposes, enforceable by the Alaska Attorney General.observed
  2. ProbableOneTrust DataGuidance27 state attorneys general, including Alaska, announced a $5 million settlement with Community Health Systems following a data breach affecting 6.1 million patients.observed
  3. ProbableOneTrust DataGuidanceAnthem settled for $39.5 million with 43 state attorneys general, including Alaska, over a 2014 data breach affecting 78.8 million customers.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United States – Alaska
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 20 claim(s), 15 source(s) in the cumulative register.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redresscollective redress and class actions
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

Regulator_and_framework, controller_processor_duties (breach/disposal/security), and sectoral_watch (insurance) achieved T2-level coverage (an FTC-hosted Alaska AG presentation plus enactment-tracking secondary sources for SB134). Most other modules (lawful_processing_and_special_data, data_subject_rights beyond breach timing, cross_border_and_adequacy, adtech_and_commercial_privacy, algorithmic_biometric_and_surveillance_governance, children_and_vulnerable_groups, and most of enforcement_and_redress) returned genuine negative findings (no Alaska-specific statute) rather than T1/T2 confirmations, and are carried with explicit absent_field_provenance. Statute-citation claims for APIPA and the Insurance Data Security Act rely primarily on T3 secondary aggregator (DataGuidance) summaries rather than a directly retrieved akleg.gov primary text in this pass, and specific penalty figures/effective dates for SB134 were not independently confirmed.

Unresolved questions (6):

  • Exact statutory civil penalty amount(s) under AS 45.48 for APIPA violations.
  • Confirmed effective date of the Alaska Insurance Data Security Act (SB134) provisions.
  • Whether HB222 (2025-era consumer data protection bill) is still pending, has died, or has been reintroduced in the current legislative session.
  • Whether APIPA contains any express private right of action for affected consumers.
  • Whether Alaska has any dedicated genetic-privacy or biometric-privacy statute not surfaced in this research pass.
  • Current staffing/budget of the Alaska AG Consumer Protection Unit as it pertains to privacy enforcement capacity.

Escalate to primary-source review: yes