🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
US-AZ · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 10 sources retrieved model claude-sonnet-5 ·

United States – Arizona

US-AZ schema gdpri-v2 trajectory: not recordedregulated (sectoral)overlaps: AIC

Last updated · 10 categories · 22 claims · 10 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
22Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

A named regulator and concrete instruments exist (breach notification statute, Consumer Fraud Act), but there is no comprehensive framework defining lawful bases, subject rights or controller obligations.

Primary frameworkArizona Revised Statutes §18-552 (breach notification) and Arizona Consumer Fraud Act A.R.S. §44-1521 et seq.
Supervisory authorityArizona Attorney General
Traffic-light rationale — AmberA named regulator and concrete instruments exist (breach notification statute, Consumer Fraud Act), but there is no comprehensive framework defining lawful bases, subject rights or controller obligations.

Sub-modules (5)

Regulator And AuthorityAmber

The Arizona Attorney General enforces breach-notification and consumer-fraud statutes touching personal data; there is no standalone data-protection regulator.

Claims (1):

  • The Arizona Attorney General is the primary enforcement authority for data-breach notification and consumer-data-practice violations in Arizona, in the absence of a dedicated data-protection regulator.

Act And InstrumentsAmber

Primary instruments are the breach-notification statute (A.R.S. §18-552, amended by HB2146 in 2022) and the Consumer Fraud Act; no comprehensive privacy bill has been passed despite repeated legislative attempts.

Claims (2):

  • Arizona currently has no comprehensive consumer-privacy statute; recent legislative attempts to pass general privacy legislation have not been enacted.
  • Breach and data-security requirements in Arizona are governed by the state's breach-notification law under §18-552 of the Arizona Revised Statutes, which requires notification to consumers and to the Arizona Attorney General or the Arizona Department of Homeland Security.

Material ScopeAmber

The breach-notification statute's material scope was expanded by the 2022 amendment to broaden the definition of covered personal information, but AZ has no general material-scope definition of 'personal data' or 'processing' comparable to omnibus regimes.

Claims (1):

  • HB 2146, signed by the Arizona Governor on 29 March 2022, amended A.R.S. §18-552 and expanded the definition of personal information subject to breach-notification duties, while also introducing a 45-day notification deadline.

Territorial ScopeAmber

No AZ-specific territorial-scope provision was located extending obligations to non-established controllers; the breach statute is understood to apply based on the residency of affected individuals rather than controller location, consistent with the general pattern of US state breach laws, but this has not been independently verified for Arizona in this run.

Absence provenance: not recorded. Searched: Arizona breach notification statute territorial scope A.R.S. 18-552 extraterritorial application.

Regulator Registration And FilingAmber

Arizona imposes no general controller registration or filing regime; the only filing-type obligation is notification to the AG/Department of Homeland Security for breaches affecting more than 1,000 residents.

Claims (1):

  • For breaches affecting more than 1,000 Arizona residents, HB 2146 requires notification to the three largest nationwide consumer-reporting agencies in addition to the Attorney General and the Arizona Department of Homeland Security.
Category narrative65 words

Arizona has no dedicated data-protection authority and no omnibus consumer-privacy statute. The Arizona Attorney General (AG) is the de facto regulator, exercising authority under the state's general breach-notification statute (A.R.S. §18-552) and the Arizona Consumer Fraud Act (A.R.S. §44-1521 et seq.) for deceptive/unfair data practices. Federal FTC Act Section 5 provides an additional reactive baseline. There is no AZ-specific registration or filing regime for controllers.

Sources and claims (5)
  1. ConfirmedOneTrust DataGuidanceThe Arizona Attorney General is the primary enforcement authority for data-breach notification and consumer-data-practice violations in Arizona, in the absence of a dedicated data-protection regulator.observed
  2. ConfirmedOneTrust DataGuidanceArizona currently has no comprehensive consumer-privacy statute; recent legislative attempts to pass general privacy legislation have not been enacted.observed
  3. ConfirmedOneTrust DataGuidanceBreach and data-security requirements in Arizona are governed by the state's breach-notification law under §18-552 of the Arizona Revised Statutes, which requires notification to consumers and to the Arizona Attorney General or the Arizona Department of Homeland Security.observed
  4. ConfirmedOneTrust DataGuidanceHB 2146, signed by the Arizona Governor on 29 March 2022, amended A.R.S. §18-552 and expanded the definition of personal information subject to breach-notification duties, while also introducing a 45-day notification deadline.observed
  5. ConfirmedOneTrust DataGuidanceFor breaches affecting more than 1,000 Arizona residents, HB 2146 requires notification to the three largest nationwide consumer-reporting agencies in addition to the Attorney General and the Arizona Department of Homeland Security.observed

#

No omnibus lawful-basis, consent, or special-category regime exists at the state level; only a narrow genetic-testing carve-out was identified.

Supervisory authorityArizona Attorney General
Traffic-light rationale — RedNo omnibus lawful-basis, consent, or special-category regime exists at the state level; only a narrow genetic-testing carve-out was identified.

Sub-modules (4)

Lawful BasesRed

No AZ statute enumerates lawful bases for processing personal data comparable to GDPR Art 6; absent a comprehensive privacy law, processing is unconstrained except where sector-specific federal law applies.

Absence provenance: not recorded. Searched: Arizona lawful basis processing personal data statute, Arizona consumer privacy consent requirements 2026.

Special CategoriesAmber

Arizona is one of a group of states with a statute specifically regulating direct-to-consumer genetic-testing companies; outside genetic data, no general special/sensitive-category regime exists at state level.

Claims (1):

  • Arizona is among twelve US states (alongside Alabama, California, Kentucky, Maryland, Montana, Tennessee, Texas, Utah, Virginia, Wyoming and Nebraska) with a statute specifically governing direct-to-consumer genetic-testing companies.

Pseudonymisation And AnonymisationRed

No Arizona statute defines pseudonymisation or anonymisation or provides safe-harbour treatment for de-identified data.

Absence provenance: not recorded. Searched: Arizona pseudonymisation anonymisation data statute safe harbor.

Category narrative62 words

Arizona has no general lawful-basis framework, no statutory consent-quality standard for commercial data processing, and no general special-category regime. The one notable exception is a direct-to-consumer genetic-testing statute, placing Arizona among a small group of US states regulating that narrow category. Outside genetic testing, sensitive-data handling is governed only by sector-specific federal law (HIPAA, GLBA, COPPA) which falls outside this JID's scope.

Sources and claims (2)
  1. ConfirmedOneTrust DataGuidanceThe Arizona Attorney General alleged in litigation against Google that the company continued collecting users' location data via settings such as Web & App Activity even after users disabled Location History, framing this as a deceptive-consent practice under the Arizona Consumer Fraud Act.observed
  2. ProbableOneTrust DataGuidanceArizona is among twelve US states (alongside Alabama, California, Kentucky, Maryland, Montana, Tennessee, Texas, Utah, Virginia, Wyoming and Nebraska) with a statute specifically governing direct-to-consumer genetic-testing companies.observed

#

No comprehensive data-subject-rights regime exists in Arizona; this is a legitimate structural gap rather than an omission.

Traffic-light rationale — RedNo comprehensive data-subject-rights regime exists in Arizona; this is a legitimate structural gap rather than an omission.

Sub-modules (5)

Access RightRed

No general AZ statutory right of access to personal data held by private businesses.

Absence provenance: not recorded. Searched: Arizona right of access personal data statute consumer.

Rectification And ErasureRed

No general AZ statutory right to rectify or erase personal data held by businesses.

Absence provenance: not recorded. Searched: Arizona right to delete personal data statute.

Restriction And ObjectionRed

No general AZ statutory right to restrict processing or object to processing/profiling.

Absence provenance: not recorded. Searched: Arizona right to object profiling opt-out statute.

Data PortabilityRed

No AZ statutory data-portability right exists.

Absence provenance: not recorded. Searched: Arizona data portability right statute.

Deadlines And Response WindowsRed

Because no general subject-rights regime exists, there are no statutory response-window deadlines for rights requests (distinct from the 45-day breach-notification deadline, which is a controller-to-regulator/consumer breach obligation, not a rights-request deadline).

Claims (1):

  • Arizona's breach-notification statute imposes a 45-day deadline for notifying affected individuals of a data breach, but this is a breach-response deadline, not a subject-access-request response window, since no general access-request regime exists in Arizona.
Category narrative46 words

Arizona confers no general statutory rights of access, rectification, erasure, restriction, objection or portability over personal data held by private-sector businesses. Such rights exist only where a federal sectoral statute (e.g., HIPAA for health records) independently applies, which is out of scope for this state-level JID.

Sources and claims (1)
  1. ConfirmedIAPPArizona's breach-notification statute imposes a 45-day deadline for notifying affected individuals of a data breach, but this is a breach-response deadline, not a subject-access-request response window, since no general access-request regime exists in Arizona.observed

#

Breach notification is a real, enforceable duty; the remaining accountability infrastructure (DPIA, DPO, ROPA, retention) is absent at state level.

Primary frameworkArizona Revised Statutes §18-552
Supervisory authorityArizona Attorney General
Traffic-light rationale — AmberBreach notification is a real, enforceable duty; the remaining accountability infrastructure (DPIA, DPO, ROPA, retention) is absent at state level.

Sub-modules (7)

Accountability And DpiaRed

No AZ statute requires DPIAs or a general accountability principle akin to GDPR Art 5/25/35.

Absence provenance: not recorded. Searched: Arizona data protection impact assessment requirement statute.

Dpo RequirementsRed

No AZ statute requires appointment of a data protection officer.

Absence provenance: not recorded. Searched: Arizona data protection officer appointment requirement.

Ropa RequirementsRed

No AZ statute requires maintenance of records of processing activity.

Absence provenance: not recorded. Searched: Arizona records of processing activities requirement statute.

Joint Controller ArrangementsRed

No AZ statute addresses joint-controller or processor-contract requirements.

Absence provenance: not recorded. Searched: Arizona joint controller processor agreement requirement statute.

Security MeasuresAmber

The breach-notification statute implies an expectation of reasonable security safeguards but does not prescribe specific technical/organisational measures comparable to GDPR Art 32.

Claims (1):

  • Arizona's breach-notification statute presumes an underlying duty of reasonable data security by penalizing failure to protect personal information that leads to a breach, though it does not itemize specific technical or organisational security measures.

Breach NotificationGreen

A.R.S. §18-552, as amended by HB 2146 (2022), is Arizona's core breach-notification obligation: a 45-day notification deadline, an expanded definition of personal information (including health-care data), and enhanced AG enforcement powers.

Claims (2):

  • Arizona's amended breach-notification law (via HB 2146) sets a 45-day deadline for notifying affected individuals, expands the definition of covered personal information to include health-care data, and gives the Attorney General enhanced power to prosecute violators.
  • Under A.R.S. §18-552, businesses must notify affected consumers and either the Arizona Attorney General or the Arizona Department of Homeland Security in the event of a data breach, and the Attorney General holds the power to sanction violations and issue penalties.

Retention And DisposalRed

No general AZ statutory retention-limit or disposal-duty regime was located outside of sector-specific federal law.

Absence provenance: not recorded. Searched: Arizona data retention limit disposal duty statute.

Category narrative33 words

Arizona imposes concrete breach-notification duties (A.R.S. §18-552) but no general accountability, DPIA, DPO, ROPA, or retention-limit obligations. Security-of-processing is addressed only implicitly through the breach statute's reasonable-security expectations and via sector-specific federal law.

Sources and claims (3)
  1. ProbableOneTrust DataGuidanceArizona's breach-notification statute presumes an underlying duty of reasonable data security by penalizing failure to protect personal information that leads to a breach, though it does not itemize specific technical or organisational security measures.observed
  2. ConfirmedIAPPArizona's amended breach-notification law (via HB 2146) sets a 45-day deadline for notifying affected individuals, expands the definition of covered personal information to include health-care data, and gives the Attorney General enhanced power to prosecute violators.observed
  3. ConfirmedOneTrust DataGuidanceUnder A.R.S. §18-552, businesses must notify affected consumers and either the Arizona Attorney General or the Arizona Department of Homeland Security in the event of a data breach, and the Attorney General holds the power to sanction violations and issue penalties.observed

#

No AZ-specific cross-border transfer, adequacy or localisation framework exists; this is a legitimate gap given the absence of a state omnibus law.

Traffic-light rationale — RedNo AZ-specific cross-border transfer, adequacy or localisation framework exists; this is a legitimate gap given the absence of a state omnibus law.

Sub-modules (6)

Transfer MechanismsRed

No AZ-specific transfer mechanism statute exists.

Absence provenance: not recorded. Searched: Arizona cross-border data transfer mechanism statute.

Adequacy ReceivedRed

Not applicable at state level; adequacy determinations are a federal/EU-US construct.

Absence provenance: not recorded. Searched: Arizona adequacy decision received.

Adequacy GrantedRed

Not applicable at state level.

Absence provenance: not recorded. Searched: Arizona adequacy decision granted.

Sccs And BcrsRed

No AZ-specific SCC/BCR regime; any use of SCCs/BCRs by AZ-based entities derives from federal/international frameworks, not state law.

Absence provenance: not recorded. Searched: Arizona standard contractual clauses BCR requirement.

Transfer Impact AssessmentRed

No AZ statutory TIA requirement exists.

Absence provenance: not recorded. Searched: Arizona transfer impact assessment requirement.

Data LocalisationRed

No AZ data-localisation mandate was identified.

Absence provenance: not recorded. Searched: Arizona data localisation requirement statute.

Category narrative39 words

Arizona has no state-level cross-border data-transfer regime, no adequacy mechanism, and no data-localisation mandate. Cross-border transfer questions arising from AZ-resident data are governed exclusively by federal law and mechanisms (SCCs, federal sectoral rules), which sit outside this state JID.

#

A narrow genetic-testing overlay exists; broader sectoral coverage (health, finance, education, insurance) is federal and out of scope for this state JID.

Supervisory authorityArizona Attorney General
Traffic-light rationale — AmberA narrow genetic-testing overlay exists; broader sectoral coverage (health, finance, education, insurance) is federal and out of scope for this state JID.

Sub-modules (7)

Financial Sector OverlayRed

No AZ-specific financial-sector data-protection overlay was located beyond the federal GLBA baseline (out of scope for this JID).

Absence provenance: not recorded. Searched: Arizona financial sector data privacy overlay statute.

Health Sector OverlayAmber

No AZ-specific health-data statute beyond federal HIPAA (out of scope); AZ health providers report breaches to HHS OCR under HIPAA, as illustrated by recent AZ healthcare ransomware incidents.

Claims (1):

  • Arizona healthcare entities, such as a regional medical center and other providers, have reported large-scale ransomware and malware-related patient-data breaches to HHS OCR under federal HIPAA breach-reporting obligations, impacting hundreds of thousands of individuals.

Telecoms And EprivacyAmber

Arizona has a state-level telephone-solicitation law restricting calls to numbers on the National Do-Not-Call registry, with specified exceptions.

Claims (1):

  • Arizona has enacted a law restricting telephone solicitations to numbers on the National Do-Not-Call registry, subject to specific exceptions.

Employment DataRed

No AZ-specific employment-data-privacy statute was located; federal GINA governs genetic-information-based employment discrimination nationally, out of scope for this state JID.

Absence provenance: not recorded. Searched: Arizona employment data privacy statute.

Credit And ScoringRed

No AZ-specific credit-scoring privacy statute was located beyond federal FCRA (out of scope).

Absence provenance: not recorded. Searched: Arizona credit scoring data privacy statute.

EducationRed

No AZ-specific education-sector data-privacy statute was located in this run beyond federal FERPA (out of scope).

Absence provenance: not recorded. Searched: Arizona student data privacy statute.

InsuranceRed

No AZ-specific insurance-sector data-privacy statute was located in this run.

Absence provenance: not recorded. Searched: Arizona insurance sector data privacy statute.

Category narrative52 words

Outside the breach-notification statute, Arizona's data-protection-relevant sectoral activity consists of a direct-to-consumer genetic-testing statute and reliance on federal sectoral overlays (HIPAA for health, GLBA for financial, COPPA for children) that are native to the US-federal JID rather than AZ. No AZ-specific insurance, education, or credit-scoring privacy statute was identified in this run.

Sources and claims (2)
  1. ProbableOneTrust DataGuidanceArizona healthcare entities, such as a regional medical center and other providers, have reported large-scale ransomware and malware-related patient-data breaches to HHS OCR under federal HIPAA breach-reporting obligations, impacting hundreds of thousands of individuals.observed
  2. ProbableOneTrust DataGuidanceArizona has enacted a law restricting telephone solicitations to numbers on the National Do-Not-Call registry, subject to specific exceptions.observed

#

No structural cookie/opt-out regime exists, but active AG enforcement under general consumer-fraud authority provides a meaningful, demonstrated deterrent against deceptive ad-tech data practices.

Primary frameworkArizona Consumer Fraud Act, A.R.S. §44-1521 et seq.
Supervisory authorityArizona Attorney General
Traffic-light rationale — AmberNo structural cookie/opt-out regime exists, but active AG enforcement under general consumer-fraud authority provides a meaningful, demonstrated deterrent against deceptive ad-tech data practices.

Sub-modules (6)

Cookies And TrackersRed

No AZ cookie-consent statute exists; tracking practices are addressed only reactively via consumer-fraud enforcement.

Absence provenance: not recorded. Searched: Arizona cookie consent law statute.

Dark PatternsRed

No AZ dark-patterns statute was located; deceptive-design practices are addressed only through the general Consumer Fraud Act.

Absence provenance: not recorded. Searched: Arizona dark patterns statute prohibition.

Opt Out SignalsRed

No AZ statute recognizes Global Privacy Control or comparable opt-out signals.

Absence provenance: not recorded. Searched: Arizona Global Privacy Control opt-out signal recognition statute.

Clean Rooms And DcrRed

No AZ-specific clean-room/data-collaboration statute was located.

Absence provenance: not recorded. Searched: Arizona data clean room statute.

Cross Context AdvertisingAmber

No AZ equivalent to CPRA 'sale'/'share' restrictions exists; the AG's Google settlement addressed deceptive location-data use for advertising under general consumer-fraud law rather than a cross-context-advertising-specific statute.

Claims (1):

  • The Arizona Attorney General secured an $85 million settlement with Google in 2022 resolving allegations that Google deceptively continued collecting and using consumers' location data for advertising purposes after users had disabled location tracking, brought under the Arizona Consumer Fraud Act.

Direct MarketingAmber

Direct marketing via telephone is regulated by the AZ Do-Not-Call statute (see sectoral_watch.telecoms_and_eprivacy); no general direct-mail/email suppression statute beyond federal CAN-SPAM/TCPA was located.

Category narrative64 words

Arizona has no cookie-consent or 'sale'/'share' opt-out statute comparable to CPRA. The principal lever against commercial ad-tech data practices is the Arizona Consumer Fraud Act, used by the AG to pursue deceptive location-tracking and data-collection practices (e.g., the $85M Google settlement and the pending Temu suit). A pending 2026 bill (HB 2489) would restrict surveillance-based pricing practices, but it is not yet in force.

Sources and claims (1)
  1. ConfirmedIAPPThe Arizona Attorney General secured an $85 million settlement with Google in 2022 resolving allegations that Google deceptively continued collecting and using consumers' location data for advertising purposes after users had disabled location tracking, brought under the Arizona Consumer Fraud Act.observed

#

Meaningful legislative activity exists (biometric, AI, surveillance-pricing bills) but none confirmed in force; treat as pending/proposed pending regulator confirmation.

Traffic-light rationale — AmberMeaningful legislative activity exists (biometric, AI, surveillance-pricing bills) but none confirmed in force; treat as pending/proposed pending regulator confirmation.

Sub-modules (6)

Profiling RestrictionsAmber

No AZ statute restricts profiling comparable to GDPR Art 22; the pending surveillance-pricing bill (HB 2489) touches algorithmic pricing but is not yet law.

Claims (1):

  • Arizona House Bill 2489 would restrict surveillance-based pricing practices by defining and prohibiting such practices and establishing enforcement mechanisms, but has not been confirmed enacted as of this run.

Automated Decision Making TransparencyRed

No AZ statute requires ADM transparency or an explanation right.

Absence provenance: not recorded. Searched: Arizona automated decision making transparency statute.

Ai Risk AssessmentsAmber

A pending bill, HB 2311, would introduce disclosure, safety and content restrictions for conversational-AI services with enhanced protections for minors, but it has not been confirmed as enacted.

Claims (1):

  • Arizona House Bill 2311 would introduce disclosure, safety, and content restrictions for conversational AI services, with enhanced protections for minors, but its passage into law has not been confirmed in this run.

Biometric RegimeAmber

Senate Bill 1238 would regulate biometric-data handling by private entities and provide legal recourse for violations; introduction/first-reading was confirmed but enactment status could not be verified in this run.

Claims (1):

  • Arizona Senate Bill 1238 would regulate biometric-data handling by private entities and provide legal recourse for violations; the bill was read in the State Senate but its final enactment status could not be independently confirmed in this run.

Genetic DataAmber

See lawful_processing_and_special_data.special_categories: Arizona's direct-to-consumer genetic-testing statute is the only in-force genetic-data provision identified.

State Surveillance CarveoutsRed

No AZ-specific state-surveillance carve-out or national-security exemption provision was located in this run.

Absence provenance: not recorded. Searched: Arizona state surveillance carveout national security exemption data statute.

Category narrative63 words

Arizona has no in-force profiling, ADM-transparency, or AI-risk-assessment statute. A biometric-data bill (SB 1238) proposing regulation of biometric handling by private entities with a private right of action has been introduced but its enactment status is unconfirmed in this run. Pending 2026 bills would address conversational-AI services with minor protections (HB 2311) and surveillance-based pricing (HB 2489), but neither is yet in force.

Sources and claims (3)
  1. UncertainOneTrust DataGuidanceArizona House Bill 2489 would restrict surveillance-based pricing practices by defining and prohibiting such practices and establishing enforcement mechanisms, but has not been confirmed enacted as of this run.observed
  2. UncertainOneTrust DataGuidanceArizona House Bill 2311 would introduce disclosure, safety, and content restrictions for conversational AI services, with enhanced protections for minors, but its passage into law has not been confirmed in this run.observed
  3. UncertainOneTrust DataGuidanceArizona Senate Bill 1238 would regulate biometric-data handling by private entities and provide legal recourse for violations; the bill was read in the State Senate but its final enactment status could not be independently confirmed in this run.observed

#

Active pending legislative pipeline on minors' data exists, but nothing AZ-specific is confirmed in force; federal COPPA is the operative baseline, and is out of scope for this JID.

Supervisory authorityArizona Attorney General
Traffic-light rationale — AmberActive pending legislative pipeline on minors' data exists, but nothing AZ-specific is confirmed in force; federal COPPA is the operative baseline, and is out of scope for this JID.

Sub-modules (5)

Age VerificationAmber

Arizona House Bill 2920 would mandate age verification for app stores and developers handling minors' accounts, but enactment is unconfirmed.

Claims (1):

  • Arizona House Bill 2920 would mandate age verification, parental consent, and data-sharing duties for app stores and developers handling minors' accounts, but its enactment status has not been independently confirmed in this run.

Minor Profiling BansAmber

No confirmed AZ statute specifically bans profiling of minors; HB 2861 and HB 2858 (enhancing minors' social-media privacy protections) are pending and unconfirmed as enacted.

Claims (1):

  • Arizona House Bill 2861 would enhance privacy protections for minors on social media platforms, and House Bill 2858 similarly seeks to enhance online privacy and safety for minors on social media, but neither has been confirmed enacted in this run.

Education SettingsRed

No AZ-specific education-settings child-data statute was identified in this run.

Absence provenance: not recorded. Searched: Arizona student data privacy education setting statute minors.

Dependent AdultsRed

No AZ-specific dependent-adults data-protection provision was located in this run.

Absence provenance: not recorded. Searched: Arizona dependent adult data protection statute elderly.

Category narrative73 words

Arizona has no in-force comprehensive minors'-data statute. Multiple 2026-session bills address minors' online safety and social-media data practices (HB 2861, HB 2858, HB 2920 covering age verification/parental consent for app stores) alongside intimate-image/deepfake bills (SB 1462, SB 1336, HB 2678), but enactment status for the privacy-specific bills is not confirmed in this run. Federal COPPA applies nationally but is out of scope for this state JID. No AZ-specific dependent-adults data-protection provision was identified.

Sources and claims (2)
  1. UncertainOneTrust DataGuidanceArizona House Bill 2920 would mandate age verification, parental consent, and data-sharing duties for app stores and developers handling minors' accounts, but its enactment status has not been independently confirmed in this run.observed
  2. UncertainOneTrust DataGuidanceArizona House Bill 2861 would enhance privacy protections for minors on social media platforms, and House Bill 2858 similarly seeks to enhance online privacy and safety for minors on social media, but neither has been confirmed enacted in this run.observed

#

Enforcement powers and recent activity are real and material, but redress avenues remain reactive/consumer-fraud-based rather than a dedicated private right of action under a comprehensive privacy statute.

Primary frameworkArizona Consumer Fraud Act, A.R.S. §44-1521 et seq.; A.R.S. §18-552
Supervisory authorityArizona Attorney General
Traffic-light rationale — AmberEnforcement powers and recent activity are real and material, but redress avenues remain reactive/consumer-fraud-based rather than a dedicated private right of action under a comprehensive privacy statute.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

The AG holds sanction and penalty power under the breach-notification statute and broad injunctive/monetary remedies under the Consumer Fraud Act, evidenced by the $85M Google settlement.

Claims (1):

  • The Arizona Attorney General obtained an $85 million settlement with Google in 2022 for deceptive location-data practices found to violate the Arizona Consumer Fraud Act, with the bulk of proceeds directed to the state general fund and $5 million earmarked for attorney-general education programs.

Enforcement Activity IndexAmber

Recent AG enforcement activity includes the Google location-data settlement and a lawsuit against Temu for unlawful data collection and inadequate privacy disclosures.

Claims (1):

  • The Arizona Attorney General has sued Temu alleging unlawful data collection and inadequate privacy disclosures, representing recent state enforcement activity against a commercial data practice.

Regulator Funding And CapacityRed

No specific AZ AG privacy-unit funding or headcount data was located in this run.

Absence provenance: not recorded. Searched: Arizona Attorney General consumer protection unit funding headcount privacy.

Collective Redress And Class ActionsRed

No AZ-specific statutory collective-redress mechanism for data-privacy claims beyond general Arizona class-action procedure was identified in this run.

Absence provenance: not recorded. Searched: Arizona class action data privacy statute.

Private Right Of ActionAmber

No general private right of action for data-privacy violations exists in Arizona; pending SB 1238 (biometric data) reportedly would include legal recourse for violations, but enactment is unconfirmed.

Claims (1):

  • Pending Arizona Senate Bill 1238 would regulate biometric-data handling by private entities and provide for legal recourse for violations, which would constitute a private right of action if enacted, but enactment has not been confirmed in this run.

Recent Developments 180DAmber

Within the last 180 days, the most notable AZ-specific development identified is the Attorney General's lawsuit against Temu over data-collection and privacy-disclosure practices; multiple minors'-privacy and biometric/AI bills remain pending in the 2026 legislative session.

Claims (1):

  • The Arizona Attorney General has sued Temu alleging unlawful data collection and inadequate privacy disclosures, representing recent state enforcement activity against a commercial data practice.
Category narrative83 words

The Arizona Attorney General has demonstrated active, real enforcement capacity against deceptive data practices under the Consumer Fraud Act, most notably the 2022 $85 million Google location-data settlement and the more recent lawsuit against Temu alleging unlawful data collection and inadequate privacy disclosures. Arizona's breach-notification statute gives the AG additional sanction and penalty powers. No AZ-specific private right of action for general data-privacy violations was identified; some breach/biometric bills (e.g., pending SB 1238) propose private rights of action but are not confirmed enacted.

Sources and claims (3)
  1. ConfirmedNAAGThe Arizona Attorney General obtained an $85 million settlement with Google in 2022 for deceptive location-data practices found to violate the Arizona Consumer Fraud Act, with the bulk of proceeds directed to the state general fund and $5 million earmarked for attorney-general education programs.observed
  2. ProbableOneTrust DataGuidanceThe Arizona Attorney General has sued Temu alleging unlawful data collection and inadequate privacy disclosures, representing recent state enforcement activity against a commercial data practice.observed
  3. UncertainOneTrust DataGuidancePending Arizona Senate Bill 1238 would regulate biometric-data handling by private entities and provide for legal recourse for violations, which would constitute a private right of action if enacted, but enactment has not been confirmed in this run.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United States – Arizona
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 22 claim(s), 10 source(s) in the cumulative register.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacydata localisation
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework, controller_processor_duties (breach_notification sub-module), sectoral_watch (telecoms), and enforcement_and_redress (regulator_powers_and_penalties) rest on T2/T3 sources with reasonably strong corroboration (multiple DataGuidance/IAPP/NAAG hits on the same facts, e.g., HB 2146 and the $85M Google settlement). lawful_processing_and_special_data, data_subject_rights, cross_border_and_adequacy, and most of children_and_vulnerable_groups and algorithmic_biometric_and_surveillance_governance rely on absent_field_provenance because no comprehensive AZ statute exists (confirmed structural gap per seed disambiguation) or because pending 2026-session bills (SB 1238, HB 2311, HB 2489, HB 2861, HB 2858, HB 2920) could not be confirmed as enacted versus still pending in this run — no T1 primary-source (azleg.gov) text was directly retrieved for any AZ statute; all statutory citations are via T2/T3 secondary legal-research aggregators.

Unresolved questions (5):

  • Has Arizona Senate Bill 1238 (biometric data) been enacted, and if so, on what effective date?
  • Have Arizona House Bills 2861, 2858, 2920, 2311, or 2489 (minors' privacy, conversational AI, surveillance-pricing) passed into law in the 2026 session, and what are their effective dates?
  • What is the current status of Arizona House Bill 2790 (consumer data protection and penalties)?
  • Can a direct azleg.gov citation for A.R.S. §18-552 (as amended) be retrieved to serve as a T1 primary source, given the seed-provided anchor (naag.org) does not host statutory text?
  • Does Arizona's genetic-testing statute apply to processing beyond direct-to-consumer testing companies, and what is its precise A.R.S. citation?

Escalate to primary-source review: yes