🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
US-AR · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 14 sources retrieved model claude-sonnet-5 ·

United States – Arkansas

US-AR schema gdpri-v2 trajectory: not recordedregulated (sectoral)overlaps: FIM, WPM, AIC, Crypto

Last updated · 10 categories · 41 claims · 14 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
41Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

No omnibus statute exists (would be red for material/territorial/registration sub-modules), but a functioning breach-notification/security regime with an active enforcing regulator (AG) exists and is expanding via sectoral bills, justifying amber rather than red at the module level.

Primary frameworkArkansas Personal Information Protection Act (Ark. Code Ann. § 4-110-101 et seq.); backstopped by federal FTC Act Section 5
Supervisory authorityArkansas Attorney General
Traffic-light rationale — AmberNo omnibus statute exists (would be red for material/territorial/registration sub-modules), but a functioning breach-notification/security regime with an active enforcing regulator (AG) exists and is expanding via sectoral bills, justifying amber rather than red at the module level.

Sub-modules (5)

Regulator And AuthorityAmber

The Arkansas Attorney General enforces PIPA and the Arkansas Deceptive Trade Practices Act; there is no independent data-protection authority equivalent to a GDPR-style DPA.

Claims (1):

  • The Arkansas Attorney General is the state regulator responsible for enforcing the Personal Information Protection Act and the Arkansas Deceptive Trade Practices Act, including data-breach and consumer-privacy-adjacent violations.

Act And InstrumentsRed

PIPA is the principal instrument; no comprehensive consumer-privacy act exists.

Claims (1):

  • Arkansas has no comprehensive consumer data-protection or privacy statute; the state's principal privacy-relevant law is the Personal Information Protection Act, which addresses data-breach notification and reasonable-security/disposal obligations only.

Material ScopeAmber

PIPA covers persons, businesses and state agencies that acquire, own, or license personal information of Arkansas residents, and imposes reasonable-security and disposal duties.

Claims (1):

  • The Personal Information Protection Act (Ark. Code Ann. § 4-110-101 et seq.), effective April 4, 2005, requires individuals, businesses, and state agencies that acquire, own, or license personal information of Arkansas residents to implement reasonable security measures and reasonable data-disposal procedures.

Territorial ScopeAmber

Coverage turns on the residency of the data subject (Arkansas residents), not the location of the regulated entity, giving the statute extraterritorial reach comparable to other early-generation state breach laws.

Claims (1):

  • Arkansas expanded the entities subject to its breach-notification statute to any business that acquires, owns, or licenses personal information of a state resident, giving the law reach over out-of-state entities holding Arkansas residents' data.

Regulator Registration And FilingRed

No general controller registration or filing obligation exists under Arkansas law.

Absence provenance: not recorded. Searched: Arkansas data controller registration requirement, Arkansas Attorney General privacy filing obligation.

Claims (1):

  • Arkansas law does not impose a general registration or filing obligation on data controllers or processors.
Category narrative76 words

Arkansas has no comprehensive consumer data-protection statute. The state's privacy-relevant legal architecture is limited to the Personal Information Protection Act (PIPA, Ark. Code Ann. § 4-110-101 et seq.), a breach-notification and reasonable-security/disposal statute enforced by the Arkansas Attorney General, plus scattered sectoral instruments (Consumer Telephone Privacy Act, Protection of Minors from Distribution of Harmful Material Act, Children and Teens' Online Privacy Protection Act). The federal FTC Act Section 5 backstops the absence of an omnibus regime.

Sources and claims (5)
  1. ConfirmedDataGuidance/OneTrustThe Arkansas Attorney General is the state regulator responsible for enforcing the Personal Information Protection Act and the Arkansas Deceptive Trade Practices Act, including data-breach and consumer-privacy-adjacent violations.observed
  2. ConfirmedInternational Association of Privacy ProfessionalsArkansas has no comprehensive consumer data-protection or privacy statute; the state's principal privacy-relevant law is the Personal Information Protection Act, which addresses data-breach notification and reasonable-security/disposal obligations only.observed
  3. ConfirmedDataGuidance/OneTrustThe Personal Information Protection Act (Ark. Code Ann. § 4-110-101 et seq.), effective April 4, 2005, requires individuals, businesses, and state agencies that acquire, own, or license personal information of Arkansas residents to implement reasonable security measures and reasonable data-disposal procedures.observed
  4. ProbableOPC CanadaArkansas expanded the entities subject to its breach-notification statute to any business that acquires, owns, or licenses personal information of a state resident, giving the law reach over out-of-state entities holding Arkansas residents' data.observed
  5. ConfirmedDataGuidance/OneTrustArkansas law does not impose a general registration or filing obligation on data controllers or processors.observed

#

Core sub-modules (lawful_bases, special_categories, pseudonymisation) are entirely absent; only a narrow, minors-specific consent overlay exists and part of that overlay has been struck down.

Supervisory authorityArkansas Attorney General
Traffic-light rationale — RedCore sub-modules (lawful_bases, special_categories, pseudonymisation) are entirely absent; only a narrow, minors-specific consent overlay exists and part of that overlay has been struck down.

Sub-modules (4)

Lawful BasesRed

No enumerated lawful bases for processing exist under Arkansas law.

Absence provenance: not recorded. Searched: Arkansas lawful basis data processing statute.

Claims (1):

  • Arkansas has no general statutory enumeration of lawful bases for processing personal data equivalent to GDPR Article 6; processing outside sector-specific contexts requires no specific lawful-basis justification under Arkansas law.

Special CategoriesRed

No independent state special/sensitive-category regime exists; coverage, if any, derives from federal sectoral overlays (HIPAA, COPPA).

Absence provenance: not recorded. Searched: Arkansas sensitive personal data statute, Arkansas biometric health genetic data law.

Claims (1):

  • Arkansas has no independent statutory scheme creating heightened protections for special/sensitive categories of personal data (health, biometric, genetic, etc.) outside of federal sectoral overlays such as HIPAA and COPPA.

Pseudonymisation And AnonymisationRed

No statutory definitions or safe-harbours for pseudonymisation or anonymisation exist under Arkansas law.

Absence provenance: not recorded. Searched: Arkansas pseudonymisation anonymisation statute.

Claims (1):

  • Arkansas law provides no statutory definition of, or safe-harbour for, pseudonymised or anonymised data.
Category narrative58 words

Arkansas has no general lawful-basis or consent-standard regime for personal-data processing outside of sector-specific minors' laws. The Children and Teens' Online Privacy Protection Act (HB1717, effective July 1, 2026) restricts targeted advertising and data collection directed at minors; the Social Media Safety Act's parental-consent/age-verification regime was enjoined and later ruled unconstitutional. No independent special-category or pseudonymisation regime exists.

Sources and claims (5)
  1. ConfirmedInternational Association of Privacy ProfessionalsArkansas has no general statutory enumeration of lawful bases for processing personal data equivalent to GDPR Article 6; processing outside sector-specific contexts requires no specific lawful-basis justification under Arkansas law.observed
  2. ConfirmedDataGuidance/OneTrustThe Arkansas Children and Teens' Online Privacy Protection Act (HB1717), effective July 1, 2026, prohibits covered operators from collecting personal data from minors for targeted-advertising purposes and mandates specific data-management practices.observed
  3. ConfirmedInternational Association of Privacy ProfessionalsThe Arkansas Social Media Safety Act (SB396), which would have required age verification and parental consent for minors under 18 to use social media platforms, was enjoined by the U.S. District Court for the Western District of Arkansas and subsequently held unconstitutional on First and Fourteenth Amendment grounds; its consent mechanism is not currently enforceable.observed
  4. ConfirmedInternational Association of Privacy ProfessionalsArkansas has no independent statutory scheme creating heightened protections for special/sensitive categories of personal data (health, biometric, genetic, etc.) outside of federal sectoral overlays such as HIPAA and COPPA.observed
  5. ConfirmedDataGuidance/OneTrustArkansas law provides no statutory definition of, or safe-harbour for, pseudonymised or anonymised data.observed

#

All consumer-rights sub-modules are absent except a narrow breach-notice timing rule.

Supervisory authorityArkansas Attorney General
Traffic-light rationale — RedAll consumer-rights sub-modules are absent except a narrow breach-notice timing rule.

Sub-modules (5)

Access RightRed

No general right of access to personal data held by private-sector controllers exists under Arkansas law.

Absence provenance: not recorded. Searched: Arkansas consumer right to access personal data.

Claims (1):

  • Arkansas law does not grant consumers a general right of access, rectification, erasure, restriction, objection, or data portability with respect to personal data held by private-sector controllers.

Rectification And ErasureRed

No general right to correct or delete personal data exists under Arkansas law.

Absence provenance: not recorded. Searched: Arkansas right to delete personal data.

Claims (1):

  • Arkansas law does not grant consumers a general right of access, rectification, erasure, restriction, objection, or data portability with respect to personal data held by private-sector controllers.

Restriction And ObjectionRed

No general right to restrict processing or object to profiling exists under Arkansas law.

Absence provenance: not recorded. Searched: Arkansas right to object to processing.

Claims (1):

  • Arkansas law does not grant consumers a general right of access, rectification, erasure, restriction, objection, or data portability with respect to personal data held by private-sector controllers.

Data PortabilityRed

No data-portability right exists under Arkansas law.

Absence provenance: not recorded. Searched: Arkansas data portability right.

Claims (1):

  • Arkansas law does not grant consumers a general right of access, rectification, erasure, restriction, objection, or data portability with respect to personal data held by private-sector controllers.

Deadlines And Response WindowsAmber

The only statutory deadline is PIPA's breach-notification timing obligation, not a general DSAR response window.

Claims (1):

  • PIPA requires notification of a security breach to affected Arkansas residents and, depending on the number affected, to the Attorney General, functioning as a breach-notice timing obligation rather than a general subject-access-request deadline.
Category narrative46 words

Arkansas confers no general consumer rights of access, rectification, erasure, restriction, objection, or data portability with respect to personal data held by private-sector controllers. The only rights-adjacent obligation is the PIPA breach-notification timing requirement, which functions as a notice duty rather than a general DSAR framework.

Sources and claims (2)
  1. ConfirmedInternational Association of Privacy ProfessionalsArkansas law does not grant consumers a general right of access, rectification, erasure, restriction, objection, or data portability with respect to personal data held by private-sector controllers.observed
  2. ConfirmedDataGuidance/OneTrustPIPA requires notification of a security breach to affected Arkansas residents and, depending on the number affected, to the Attorney General, functioning as a breach-notice timing obligation rather than a general subject-access-request deadline.observed

#

Security, breach-notification and disposal duties are in force and enforced by the AG, but the broader accountability infrastructure (DPIA, DPO, ROPA, joint controllers) found in omnibus regimes is entirely absent.

Primary frameworkArkansas Personal Information Protection Act (Ark. Code Ann. § 4-110-101 et seq.)
Supervisory authorityArkansas Attorney General
Traffic-light rationale — AmberSecurity, breach-notification and disposal duties are in force and enforced by the AG, but the broader accountability infrastructure (DPIA, DPO, ROPA, joint controllers) found in omnibus regimes is entirely absent.

Sub-modules (7)

Accountability And DpiaRed

No accountability principle or DPIA-trigger regime exists under Arkansas law.

Absence provenance: not recorded. Searched: Arkansas DPIA requirement, Arkansas accountability principle privacy.

Claims (1):

  • Arkansas law contains no accountability principle or DPIA-trigger obligation comparable to GDPR Articles 5, 25, or 35.

Dpo RequirementsRed

No DPO-appointment threshold or independence requirement exists under Arkansas law.

Absence provenance: not recorded. Searched: Arkansas data protection officer requirement.

Claims (1):

  • Arkansas law imposes no requirement to appoint a data protection officer.

Ropa RequirementsRed

No records-of-processing obligation exists under Arkansas law.

Absence provenance: not recorded. Searched: Arkansas records of processing activities requirement.

Claims (1):

  • Arkansas law imposes no obligation to maintain records of processing activities.

Joint Controller ArrangementsRed

No statutory joint-controller framework exists under Arkansas law.

Absence provenance: not recorded. Searched: Arkansas joint controller obligations.

Claims (1):

  • Arkansas law contains no statutory framework governing joint-controller relationships or allocation of responsibility between co-controllers.

Security MeasuresGreen

PIPA requires reasonable security procedures and practices to protect personal information.

Claims (1):

  • The Personal Information Protection Act requires covered persons, businesses, and state agencies to implement and maintain reasonable security procedures and practices to protect personal information from unauthorized access, use, modification, or disclosure.

Breach NotificationGreen

PIPA requires notification of security breaches to affected residents and, above certain thresholds, to the Attorney General.

Claims (1):

  • PIPA requires notification of security breaches involving personal information to affected Arkansas residents and, depending on the number of individuals affected, to the Arkansas Attorney General.

Retention And DisposalAmber

PIPA requires reasonable procedures for the proper disposal of records containing personal information.

Claims (1):

  • PIPA requires covered entities to implement reasonable procedures for the proper disposal of records containing personal information to prevent unauthorized access to or use of the information.
Category narrative35 words

PIPA imposes reasonable security, breach-notification, and disposal duties on controllers, but Arkansas has no accountability/DPIA principle, DPO-appointment threshold, ROPA obligation, or joint-controller regime. Act 557 layers a sector-specific security-program and incident-response-plan requirement onto virtual-currency businesses.

Sources and claims (7)
  1. ConfirmedInternational Association of Privacy ProfessionalsArkansas law contains no accountability principle or DPIA-trigger obligation comparable to GDPR Articles 5, 25, or 35.observed
  2. ConfirmedInternational Association of Privacy ProfessionalsArkansas law imposes no requirement to appoint a data protection officer.observed
  3. ConfirmedInternational Association of Privacy ProfessionalsArkansas law imposes no obligation to maintain records of processing activities.observed
  4. ConfirmedInternational Association of Privacy ProfessionalsArkansas law contains no statutory framework governing joint-controller relationships or allocation of responsibility between co-controllers.observed
  5. ConfirmedDataGuidance/OneTrustThe Personal Information Protection Act requires covered persons, businesses, and state agencies to implement and maintain reasonable security procedures and practices to protect personal information from unauthorized access, use, modification, or disclosure.observed
  6. ConfirmedDataGuidance/OneTrustPIPA requires notification of security breaches involving personal information to affected Arkansas residents and, depending on the number of individuals affected, to the Arkansas Attorney General.observed
  7. ConfirmedDataGuidance/OneTrustPIPA requires covered entities to implement reasonable procedures for the proper disposal of records containing personal information to prevent unauthorized access to or use of the information.observed

#

No sub-module has any state-level content; all rely on absent_field_provenance.

Traffic-light rationale — RedNo sub-module has any state-level content; all rely on absent_field_provenance.

Sub-modules (6)

Transfer MechanismsRed

No state-level transfer mechanism regime exists.

Absence provenance: not recorded. Searched: Arkansas cross-border data transfer mechanism.

Claims (1):

  • Arkansas has no data-localisation mandate or state-level cross-border data-transfer mechanism (adequacy, SCCs, BCRs, or transfer-impact-assessment requirement) applicable to personal data generally, in the absence of a comprehensive consumer-privacy statute.

Adequacy ReceivedRed

Not applicable; Arkansas is a sub-national US jurisdiction and does not receive adequacy determinations.

Absence provenance: not recorded. Searched: Arkansas adequacy decision received.

Adequacy GrantedRed

Not applicable; Arkansas does not grant adequacy determinations.

Absence provenance: not recorded. Searched: Arkansas adequacy decision granted.

Sccs And BcrsRed

No state-level SCC or BCR framework exists.

Absence provenance: not recorded. Searched: Arkansas standard contractual clauses, Arkansas binding corporate rules.

Claims (1):

  • Arkansas has no data-localisation mandate or state-level cross-border data-transfer mechanism (adequacy, SCCs, BCRs, or transfer-impact-assessment requirement) applicable to personal data generally, in the absence of a comprehensive consumer-privacy statute.

Transfer Impact AssessmentRed

No TIA requirement exists under Arkansas law.

Absence provenance: not recorded. Searched: Arkansas transfer impact assessment.

Claims (1):

  • Arkansas has no data-localisation mandate or state-level cross-border data-transfer mechanism (adequacy, SCCs, BCRs, or transfer-impact-assessment requirement) applicable to personal data generally, in the absence of a comprehensive consumer-privacy statute.

Data LocalisationRed

No data-localisation mandate exists under Arkansas law.

Absence provenance: not recorded. Searched: Arkansas data localisation requirement.

Claims (1):

  • Arkansas has no data-localisation mandate or state-level cross-border data-transfer mechanism (adequacy, SCCs, BCRs, or transfer-impact-assessment requirement) applicable to personal data generally, in the absence of a comprehensive consumer-privacy statute.
Category narrative25 words

In the absence of a comprehensive consumer-privacy statute, Arkansas has no state-level cross-border transfer-mechanism, adequacy, SCC/BCR, transfer-impact-assessment, or data-localisation regime applicable to personal data generally.

Sources and claims (1)
  1. ConfirmedInternational Association of Privacy ProfessionalsArkansas has no data-localisation mandate or state-level cross-border data-transfer mechanism (adequacy, SCCs, BCRs, or transfer-impact-assessment requirement) applicable to personal data generally, in the absence of a comprehensive consumer-privacy statute.observed

#

Several narrow, real sectoral overlays exist and are enforced, but broad sectors (employment, credit, education) have no state-specific coverage beyond federal baselines.

Supervisory authorityArkansas Attorney General
Traffic-light rationale — AmberSeveral narrow, real sectoral overlays exist and are enforced, but broad sectors (employment, credit, education) have no state-specific coverage beyond federal baselines.

Sub-modules (7)

Financial Sector OverlayAmber

Act 557 imposes data-security-program and incident-response-plan requirements on virtual-currency businesses.

Claims (1):

  • Arkansas Act 557 imposes data-security-program and incident-response-plan requirements on virtual-currency businesses operating in the state, supplementing the general PIPA security baseline for this sector.

Health Sector OverlayAmber

Health-sector personal information in Arkansas is governed primarily by the federal HIPAA framework in the absence of an independent state health-privacy statute.

Claims (1):

  • Health-sector personal information in Arkansas is governed primarily by the federal Health Insurance Portability and Accountability Act, as Arkansas has no independent comprehensive state health-privacy statute displacing HIPAA.

Telecoms And EprivacyAmber

The Arkansas Consumer Telephone Privacy Act establishes telemarketing restrictions and a state-wide Do-Not-Call database.

Claims (1):

  • The Arkansas Consumer Telephone Privacy Act, Ark. Code Ann. § 4-99-401 et seq., sets out telemarketing requirements and establishes a state-wide Do-Not-Call database.

Employment DataRed

No independent Arkansas employment-data-privacy statute was identified.

Absence provenance: not recorded. Searched: Arkansas employment data privacy statute.

Claims (1):

  • No independent Arkansas statute governs employment-data privacy, credit-scoring privacy, or education-data privacy beyond the general breach-notification baseline and applicable federal overlays (FCRA, FERPA).

Credit And ScoringRed

Credit and scoring data reliance is on the federal Fair Credit Reporting Act; no independent state credit-scoring privacy statute was identified.

Absence provenance: not recorded. Searched: Arkansas credit scoring privacy statute.

Claims (1):

  • No independent Arkansas statute governs employment-data privacy, credit-scoring privacy, or education-data privacy beyond the general breach-notification baseline and applicable federal overlays (FCRA, FERPA).

EducationRed

Education data reliance is on the federal FERPA; no independent Arkansas education-privacy statute beyond general breach law was identified.

Absence provenance: not recorded. Searched: Arkansas student data privacy statute.

Claims (1):

  • No independent Arkansas statute governs employment-data privacy, credit-scoring privacy, or education-data privacy beyond the general breach-notification baseline and applicable federal overlays (FCRA, FERPA).

InsuranceAmber

House Bill 1297 regulates AI use in health-insurance decision-making, mandating transparency and quality-assurance requirements.

Claims (1):

  • Arkansas House Bill 1297 regulates the use of artificial intelligence in health-insurance decision-making, mandating transparency and quality-assurance requirements for AI algorithms used by insurers.
Category narrative58 words

Arkansas layers a small number of sector-specific instruments atop the general breach-notification baseline: Act 557 (virtual-currency data-security programs), the Arkansas Consumer Telephone Privacy Act (telemarketing/Do-Not-Call), and HB1297 (AI transparency in health-insurance decision-making). Health-sector personal information otherwise relies on the federal HIPAA overlay; credit-scoring and education data rely on federal FCRA/FERPA overlays; no independent state employment-data statute was identified.

Sources and claims (5)
  1. ProbableDataGuidance/OneTrustArkansas Act 557 imposes data-security-program and incident-response-plan requirements on virtual-currency businesses operating in the state, supplementing the general PIPA security baseline for this sector.observed
  2. ProbableFederal Trade CommissionHealth-sector personal information in Arkansas is governed primarily by the federal Health Insurance Portability and Accountability Act, as Arkansas has no independent comprehensive state health-privacy statute displacing HIPAA.observed
  3. ConfirmedDataGuidance/OneTrustThe Arkansas Consumer Telephone Privacy Act, Ark. Code Ann. § 4-99-401 et seq., sets out telemarketing requirements and establishes a state-wide Do-Not-Call database.observed
  4. ConfirmedInternational Association of Privacy ProfessionalsNo independent Arkansas statute governs employment-data privacy, credit-scoring privacy, or education-data privacy beyond the general breach-notification baseline and applicable federal overlays (FCRA, FERPA).observed
  5. ProbableDataGuidance/OneTrustArkansas House Bill 1297 regulates the use of artificial intelligence in health-insurance decision-making, mandating transparency and quality-assurance requirements for AI algorithms used by insurers.observed

#

General adtech sub-modules (cookies, dark patterns, opt-out signals, clean rooms) are entirely absent; only narrow minors-advertising and telemarketing suppression rules exist.

Supervisory authorityArkansas Attorney General
Traffic-light rationale — RedGeneral adtech sub-modules (cookies, dark patterns, opt-out signals, clean rooms) are entirely absent; only narrow minors-advertising and telemarketing suppression rules exist.

Sub-modules (6)

Cookies And TrackersRed

No state cookie/tracker consent law exists.

Absence provenance: not recorded. Searched: Arkansas cookie consent law.

Claims (1):

  • Arkansas has no general cookie/tracker consent law, dark-pattern prohibition, opt-out-signal recognition mandate, or clean-room regulation.

Dark PatternsRed

No dark-pattern prohibition statute exists.

Absence provenance: not recorded. Searched: Arkansas dark patterns statute.

Claims (1):

  • Arkansas has no general cookie/tracker consent law, dark-pattern prohibition, opt-out-signal recognition mandate, or clean-room regulation.

Opt Out SignalsRed

No Global Privacy Control or opt-out-signal recognition mandate exists.

Absence provenance: not recorded. Searched: Arkansas Global Privacy Control requirement.

Claims (1):

  • Arkansas has no general cookie/tracker consent law, dark-pattern prohibition, opt-out-signal recognition mandate, or clean-room regulation.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room regulation exists.

Absence provenance: not recorded. Searched: Arkansas data clean room regulation.

Claims (1):

  • Arkansas has no general cookie/tracker consent law, dark-pattern prohibition, opt-out-signal recognition mandate, or clean-room regulation.

Cross Context AdvertisingAmber

HB1717 prohibits covered operators from engaging in targeted/cross-context advertising directed at minors, effective July 1, 2026.

Claims (1):

  • The Arkansas Children and Teens' Online Privacy Protection Act (HB1717) prohibits covered operators from engaging in targeted advertising directed at minors, effective July 1, 2026.

Direct MarketingAmber

The Arkansas Consumer Telephone Privacy Act provides a Do-Not-Call suppression mechanism for telemarketing.

Claims (1):

  • The Arkansas Consumer Telephone Privacy Act establishes a state-wide Do-Not-Call database that functions as a direct-marketing suppression mechanism for telemarketing calls.
Category narrative46 words

Arkansas has no general cookie/tracker consent law, dark-pattern prohibition, opt-out-signal mandate, or clean-room regulation. The main commercial-privacy overlays are minors-specific: HB1717 bans targeted advertising directed at minors (effective July 1, 2026), and the Consumer Telephone Privacy Act provides a direct-marketing suppression mechanism via the Do-Not-Call database.

Sources and claims (3)
  1. ConfirmedInternational Association of Privacy ProfessionalsArkansas has no general cookie/tracker consent law, dark-pattern prohibition, opt-out-signal recognition mandate, or clean-room regulation.observed
  2. ConfirmedDataGuidance/OneTrustThe Arkansas Children and Teens' Online Privacy Protection Act (HB1717) prohibits covered operators from engaging in targeted advertising directed at minors, effective July 1, 2026.observed
  3. ConfirmedDataGuidance/OneTrustThe Arkansas Consumer Telephone Privacy Act establishes a state-wide Do-Not-Call database that functions as a direct-marketing suppression mechanism for telemarketing calls.observed

#

Only one confirmed sectoral ADM-transparency obligation exists; profiling, biometric, genetic, and surveillance-carveout sub-modules are absent or unconfirmed.

Traffic-light rationale — RedOnly one confirmed sectoral ADM-transparency obligation exists; profiling, biometric, genetic, and surveillance-carveout sub-modules are absent or unconfirmed.

Sub-modules (6)

Profiling RestrictionsRed

No general profiling-restriction statute analogous to GDPR Art. 22 exists for the general population under Arkansas law.

Absence provenance: not recorded. Searched: Arkansas profiling restriction statute.

Claims (1):

  • Arkansas has no general statutory restriction on automated profiling of the general population comparable to GDPR Article 22.

Automated Decision Making TransparencyAmber

HB1297 mandates transparency and quality-assurance requirements for AI algorithms used in health-insurance decision-making.

Claims (1):

  • Arkansas House Bill 1297 mandates transparency and quality-assurance requirements for AI algorithms used by health insurers in coverage decision-making.

Ai Risk AssessmentsAmber

Arkansas Senate Bill 258 addresses AI and data protection, focused on high-risk AI systems and impact assessments, but its enactment status could not be confirmed.

Claims (1):

  • Arkansas Senate Bill 258 addresses AI and data protection, focusing on high-risk AI systems and their impact assessments; whether the bill has been enacted into law could not be confirmed from available sources.

Biometric RegimeRed

No dedicated biometric-data statute (comparable to Illinois BIPA) was identified in Arkansas.

Absence provenance: not recorded. Searched: Arkansas biometric information privacy act.

Claims (1):

  • No dedicated biometric-data or genetic-data statute, and no Arkansas-specific state-surveillance carve-out statute, was identified.

Genetic DataRed

No dedicated genetic-data statute was identified in Arkansas.

Absence provenance: not recorded. Searched: Arkansas genetic privacy statute.

Claims (1):

  • No dedicated biometric-data or genetic-data statute, and no Arkansas-specific state-surveillance carve-out statute, was identified.

State Surveillance CarveoutsRed

No Arkansas-specific state-surveillance carve-out statute was identified beyond generally applicable federal national-security exemptions.

Absence provenance: not recorded. Searched: Arkansas state surveillance carveout statute.

Claims (1):

  • No dedicated biometric-data or genetic-data statute, and no Arkansas-specific state-surveillance carve-out statute, was identified.
Category narrative44 words

Arkansas has no general profiling-restriction, biometric-data, or genetic-data statute. Sector-specific AI-transparency obligations exist in health insurance (HB1297); a broader AI/high-risk-system impact-assessment bill (SB258) has been introduced but its enactment status is unconfirmed. No state-specific surveillance carve-out beyond generally applicable federal national-security exemptions was identified.

Sources and claims (4)
  1. ConfirmedInternational Association of Privacy ProfessionalsArkansas has no general statutory restriction on automated profiling of the general population comparable to GDPR Article 22.observed
  2. ProbableDataGuidance/OneTrustArkansas House Bill 1297 mandates transparency and quality-assurance requirements for AI algorithms used by health insurers in coverage decision-making.observed
  3. UncertainDataGuidance/OneTrustArkansas Senate Bill 258 addresses AI and data protection, focusing on high-risk AI systems and their impact assessments; whether the bill has been enacted into law could not be confirmed from available sources.observed
  4. ConfirmedInternational Association of Privacy ProfessionalsNo dedicated biometric-data or genetic-data statute, and no Arkansas-specific state-surveillance carve-out statute, was identified.observed

#

Meaningful minors-specific coverage exists (age verification, prospective ad-targeting ban) but the flagship consent mechanism (Social Media Safety Act) is unenforceable, and education/dependent-adult sub-modules are absent.

Primary frameworkArkansas Children and Teens' Online Privacy Protection Act (HB1717); Protection of Minors from Distribution of Harmful Material Act (Act 612)
Supervisory authorityArkansas Attorney General
Traffic-light rationale — AmberMeaningful minors-specific coverage exists (age verification, prospective ad-targeting ban) but the flagship consent mechanism (Social Media Safety Act) is unenforceable, and education/dependent-adult sub-modules are absent.

Sub-modules (5)

Age VerificationAmber

Act 612 requires age-verification methods for websites containing a substantial portion of material harmful to minors.

Claims (1):

  • Arkansas's Protection of Minors from the Distribution of Harmful Material Act requires age-verification methods before allowing access to a website containing a substantial portion of material that is harmful to minors.

Minor Profiling BansAmber

HB1717 prohibits targeted advertising and mandates data-management practices for minors' data, effective July 1, 2026.

Claims (1):

  • The Arkansas Children and Teens' Online Privacy Protection Act (HB1717), effective July 1, 2026, prohibits covered operators from collecting personal data from minors for targeted-advertising purposes and mandates specific data-management practices.

Education SettingsRed

No Arkansas education-settings-specific data-protection statute beyond federal FERPA was identified.

Absence provenance: not recorded. Searched: Arkansas student data privacy law.

Claims (1):

  • No Arkansas education-settings-specific data-protection statute beyond the federal Family Educational Rights and Privacy Act was identified.

Dependent AdultsRed

No Arkansas dependent-adults data-protection statute was identified; the SAFER AR Act addresses financial-exploitation reporting duties for Adult Protective Services but is not a data-protection statute.

Absence provenance: not recorded. Searched: Arkansas dependent adult data protection statute, Arkansas elder data privacy law.

Claims (1):

  • No Arkansas data-protection-specific statute for dependent adults was identified; the state's SAFER AR Act creates a financial-exploitation reporting duty for Adult Protective Services but does not create data-protection rights or obligations.
Category narrative81 words

Arkansas has an active legislative program on minors' data: Act 612 (Protection of Minors from Distribution of Harmful Material Act) mandates age verification for adult-content websites; HB1717 (Children and Teens' Online Privacy Protection Act) bans targeted advertising/profiling-adjacent data use for minors from July 1, 2026; the Social Media Safety Act's parental-consent mechanism was struck down as unconstitutional. No education-settings-specific or dependent-adults-specific data-protection statute was identified (the SAFER AR Act addresses financial-exploitation reporting for vulnerable adults but is not a data-protection statute).

Sources and claims (3)
  1. ConfirmedDataGuidance/OneTrustArkansas's Protection of Minors from the Distribution of Harmful Material Act requires age-verification methods before allowing access to a website containing a substantial portion of material that is harmful to minors.observed
  2. ProbableInternational Association of Privacy ProfessionalsNo Arkansas education-settings-specific data-protection statute beyond the federal Family Educational Rights and Privacy Act was identified.observed
  3. ProbableNAAGNo Arkansas data-protection-specific statute for dependent adults was identified; the state's SAFER AR Act creates a financial-exploitation reporting duty for Adult Protective Services but does not create data-protection rights or obligations.observed

#

Active, well-documented AG enforcement exists, but redress avenues for individuals (private right of action, class actions) are unconfirmed/absent, and regulator capacity appears limited relative to its broad portfolio.

Primary frameworkArkansas Personal Information Protection Act; Arkansas Deceptive Trade Practices Act
Supervisory authorityArkansas Attorney General
Traffic-light rationale — AmberActive, well-documented AG enforcement exists, but redress avenues for individuals (private right of action, class actions) are unconfirmed/absent, and regulator capacity appears limited relative to its broad portfolio.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

The Attorney General holds the power to sanction PIPA violations and issue penalties; the Deceptive Trade Practices Act supplies broader civil-penalty authority used for privacy-adjacent enforcement.

Claims (1):

  • The Arkansas Attorney General holds the power to sanction violations of the Personal Information Protection Act and issue penalties.

Enforcement Activity IndexGreen

AG Griffin has brought or continued multiple 2024-2026 enforcement actions touching data privacy (TikTok, Meta, Temu, Google, GM).

Claims (1):

  • Arkansas Attorney General Tim Griffin has pursued active enforcement in 2024-2026 targeting privacy-adjacent deceptive practices, including suits against TikTok/ByteDance, Meta, and Temu based on Arkansans' personal information.

Regulator Funding And CapacityAmber

The AG's Consumer Protection Division is described as a small team managing a broad portfolio including privacy.

Claims (1):

  • The Consumer Protection Division of the Arkansas Attorney General's Office is described as a small team of lawyers and investigators managing antitrust, tobacco, charities enforcement, privacy, and other deceptive-trade-practices matters.

Collective Redress And Class ActionsRed

No confirmed data-protection-specific class-action mechanism was identified; enforcement is AG-driven.

Absence provenance: not recorded. Searched: Arkansas data breach class action mechanism.

Claims (1):

  • No Arkansas data-protection-specific collective-redress or class-action mechanism was identified; available enforcement is Attorney-General-driven.

Private Right Of ActionRed

PIPA does not appear to grant Arkansas consumers a private right of action; enforcement rests with the Attorney General.

Claims (1):

  • The Personal Information Protection Act does not grant Arkansas consumers an express private right of action; enforcement authority rests with the Attorney General.

Recent Developments 180DAmber

Within the last 180 days, the Social Media Safety Act was held unconstitutional and the Children and Teens' Online Privacy Protection Act's July 1, 2026 effective date approached/occurred.

Claims (1):

  • Within the recent reporting window, Arkansas courts held the Social Media Safety Act unconstitutional on First and Fourteenth Amendment grounds, and the Children and Teens' Online Privacy Protection Act's July 1, 2026 effective date approached.
Category narrative77 words

The Arkansas Attorney General holds sanction and penalty power under PIPA and the Deceptive Trade Practices Act and has been highly active in 2024-2026, bringing or continuing enforcement actions against TikTok, Meta, Temu, Google, and General Motors over privacy-adjacent deceptive practices. Enforcement is AG-driven; no confirmed private right of action or class-action mechanism specific to data-protection claims was identified. The Consumer Protection Division is described as a small team covering privacy alongside antitrust, tobacco, and charities enforcement.

Sources and claims (6)
  1. ConfirmedDataGuidance/OneTrustThe Arkansas Attorney General holds the power to sanction violations of the Personal Information Protection Act and issue penalties.observed
  2. ConfirmedInternational Association of Privacy ProfessionalsArkansas Attorney General Tim Griffin has pursued active enforcement in 2024-2026 targeting privacy-adjacent deceptive practices, including suits against TikTok/ByteDance, Meta, and Temu based on Arkansans' personal information.observed
  3. ProbableNAAGThe Consumer Protection Division of the Arkansas Attorney General's Office is described as a small team of lawyers and investigators managing antitrust, tobacco, charities enforcement, privacy, and other deceptive-trade-practices matters.observed
  4. ProbableInternational Association of Privacy ProfessionalsNo Arkansas data-protection-specific collective-redress or class-action mechanism was identified; available enforcement is Attorney-General-driven.observed
  5. ProbableDataGuidance/OneTrustThe Personal Information Protection Act does not grant Arkansas consumers an express private right of action; enforcement authority rests with the Attorney General.observed
  6. ConfirmedDataGuidance/OneTrustWithin the recent reporting window, Arkansas courts held the Social Media Safety Act unconstitutional on First and Fourteenth Amendment grounds, and the Children and Teens' Online Privacy Protection Act's July 1, 2026 effective date approached.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United States – Arkansas
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 41 claim(s), 14 source(s) in the cumulative register.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (37 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsdeadlines and response windows
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacyadequacy granted
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacysccs and bcrs
Art. 49Cross-Border & Adequacytransfer impact assessment
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redressregulator powers and penalties
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

All 10 modules were researched and populated. Coverage is strongest (T1/T2-anchored) for regulator_and_framework and controller_processor_duties (PIPA breach-notification/security text, AG enforcement authority), relying on the seed T1 anchor (NAAG/PIPA) plus T3 secondary aggregators (DataGuidance, IAPP) for corroboration and detail not in the seed. Modules lawful_processing_and_special_data, data_subject_rights, and cross_border_and_adequacy are correctly thin/red, reflecting the genuine absence of an omnibus statute per the seed disambiguation, and are supported primarily by T3 sources describing that absence plus explicit absent_field_provenance. sectoral_watch, adtech_and_commercial_privacy, algorithmic_biometric_and_surveillance_governance, and children_and_vulnerable_groups rely mostly on T3 (DataGuidance/IAPP) reporting of recent 2025-2026 Arkansas acts and bills (HB1717, Act 612, Act 557, HB1297, SB258, Social Media Safety Act litigation); none of these were verified against primary Arkansas Code or Arkansas General Assembly bill-tracking text directly, since those hostnames were not confirmed on the retrieval allowlist.

Unresolved questions (5):

  • Exact effective date and current in-force status of Act 557 (virtual-currency data-security requirements) could not be confirmed beyond 'signed by Governor' reporting.
  • Enactment status of Senate Bill 258 (AI/high-risk-system impact assessments) is unconfirmed — reporting describes the bill's focus but not a signed/enacted outcome.
  • Precise effective date of Act 612 (Protection of Minors from Distribution of Harmful Material Act) age-verification requirement was not independently confirmed beyond 'became law' reporting from 2023.
  • Whether HB1297 (AI in health-insurance decision-making) has an enactment/effective date beyond legislative reporting was not confirmed.
  • Whether the Arkansas Deceptive Trade Practices Act contains an express private right of action for privacy-adjacent claims was not independently verified against primary statutory text.

Escalate to primary-source review: yes