#
No omnibus statute exists (would be red for material/territorial/registration sub-modules), but a functioning breach-notification/security regime with an active enforcing regulator (AG) exists and is expanding via sectoral bills, justifying amber rather than red at the module level.
Sub-modules (5)
Regulator And AuthorityAmber
The Arkansas Attorney General enforces PIPA and the Arkansas Deceptive Trade Practices Act; there is no independent data-protection authority equivalent to a GDPR-style DPA.
Claims (1):
- The Arkansas Attorney General is the state regulator responsible for enforcing the Personal Information Protection Act and the Arkansas Deceptive Trade Practices Act, including data-breach and consumer-privacy-adjacent violations.
Act And InstrumentsRed
PIPA is the principal instrument; no comprehensive consumer-privacy act exists.
Claims (1):
- Arkansas has no comprehensive consumer data-protection or privacy statute; the state's principal privacy-relevant law is the Personal Information Protection Act, which addresses data-breach notification and reasonable-security/disposal obligations only.
Material ScopeAmber
PIPA covers persons, businesses and state agencies that acquire, own, or license personal information of Arkansas residents, and imposes reasonable-security and disposal duties.
Claims (1):
- The Personal Information Protection Act (Ark. Code Ann. § 4-110-101 et seq.), effective April 4, 2005, requires individuals, businesses, and state agencies that acquire, own, or license personal information of Arkansas residents to implement reasonable security measures and reasonable data-disposal procedures.
Territorial ScopeAmber
Coverage turns on the residency of the data subject (Arkansas residents), not the location of the regulated entity, giving the statute extraterritorial reach comparable to other early-generation state breach laws.
Claims (1):
- Arkansas expanded the entities subject to its breach-notification statute to any business that acquires, owns, or licenses personal information of a state resident, giving the law reach over out-of-state entities holding Arkansas residents' data.
Regulator Registration And FilingRed
No general controller registration or filing obligation exists under Arkansas law.
Absence provenance: not recorded. Searched: Arkansas data controller registration requirement, Arkansas Attorney General privacy filing obligation.
Claims (1):
- Arkansas law does not impose a general registration or filing obligation on data controllers or processors.
Sources and claims (5)
- ConfirmedDataGuidance/OneTrust — The Arkansas Attorney General is the state regulator responsible for enforcing the Personal Information Protection Act and the Arkansas Deceptive Trade Practices Act, including data-breach and consumer-privacy-adjacent violations.observed
- ConfirmedInternational Association of Privacy Professionals — Arkansas has no comprehensive consumer data-protection or privacy statute; the state's principal privacy-relevant law is the Personal Information Protection Act, which addresses data-breach notification and reasonable-security/disposal obligations only.observed
- ConfirmedDataGuidance/OneTrust — The Personal Information Protection Act (Ark. Code Ann. § 4-110-101 et seq.), effective April 4, 2005, requires individuals, businesses, and state agencies that acquire, own, or license personal information of Arkansas residents to implement reasonable security measures and reasonable data-disposal procedures.observed
- ProbableOPC Canada — Arkansas expanded the entities subject to its breach-notification statute to any business that acquires, owns, or licenses personal information of a state resident, giving the law reach over out-of-state entities holding Arkansas residents' data.observed
- ConfirmedDataGuidance/OneTrust — Arkansas law does not impose a general registration or filing obligation on data controllers or processors.observed