🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
US-ID · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 13 sources retrieved model claude-sonnet-5 ·

United States – Idaho

US-ID schema gdpri-v2 trajectory: not recordedregulated (sectoral)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 28 claims · 13 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
28Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

A functioning enforcement authority and a narrow breach-notification statute exist, but there is no comprehensive material/territorial scope framework or registration regime.

Primary frameworkIdaho Code Title 28, Chapter 51 (breach notification) + FTC Act Section 5 (federal backstop)
Supervisory authorityIdaho Attorney General
Traffic-light rationale — AmberA functioning enforcement authority and a narrow breach-notification statute exist, but there is no comprehensive material/territorial scope framework or registration regime.

Sub-modules (5)

Regulator And AuthorityAmber

The Idaho Attorney General (Raúl Labrador) is the primary state enforcement authority for consumer-protection/privacy matters, operating under general consumer-protection statutes rather than a dedicated privacy-enforcement mandate.

Claims (1):

  • The Idaho Attorney General, currently Raúl Labrador, is the state's chief law-enforcement officer with general consumer-protection authority that extends to privacy-adjacent enforcement.

Act And InstrumentsAmber

No omnibus privacy act exists; the operative instruments are the Idaho breach-notification statute and federal sectoral/FTC authority.

Claims (2):

  • Idaho has no comprehensive state consumer-privacy statute; data-protection matters are governed by federal FTC Act Section 5 authority and applicable federal sectoral laws, plus the state's breach-notification statute.
  • Idaho Code Title 28, Chapter 51, §28-51-105 governs disclosure of breach of security of computerized personal information by an agency, individual, or commercial entity.

Material ScopeRed

Material scope is narrow: the breach statute covers only computerized personal information as statutorily defined, not general processing activity.

Claims (1):

  • The Idaho breach-notification statute's material scope is limited to unencrypted computerized personal information as statutorily defined, and does not establish a general processing-activity scope test.

Territorial ScopeAmber

The breach law is triggered by residency of affected individuals rather than an establishment or targeting test; there is no extraterritorial reach comparable to GDPR Art. 3.

Claims (1):

  • Idaho's breach law applies based on the residency of affected individuals rather than an establishment- or targeting-based territorial test.

Regulator Registration And FilingRed

No controller/processor registration or filing obligation exists under Idaho law.

Absence provenance: not recorded. Searched: Idaho controller registration privacy law, Idaho data protection registration requirement.

Category narrative67 words

Idaho has no dedicated data-protection regulator or comprehensive privacy statute. Enforcement authority rests with the Idaho Attorney General under general consumer-protection powers, layered under the FTC's federal Section 5 unfair/deceptive-practices jurisdiction. The only Idaho-specific instrument squarely on point is the state's computerized-data breach-notification statute (Idaho Code Title 28, Chapter 51, §28-51-105); there is no material-scope or territorial-scope test analogous to GDPR, and no controller registration/filing regime exists.

Sources and claims (5)
  1. ConfirmedNAAGThe Idaho Attorney General, currently Raúl Labrador, is the state's chief law-enforcement officer with general consumer-protection authority that extends to privacy-adjacent enforcement.observed
  2. ConfirmedIAPPIdaho has no comprehensive state consumer-privacy statute; data-protection matters are governed by federal FTC Act Section 5 authority and applicable federal sectoral laws, plus the state's breach-notification statute.observed
  3. ConfirmedDataGuidance (legal research compilation)Idaho Code Title 28, Chapter 51, §28-51-105 governs disclosure of breach of security of computerized personal information by an agency, individual, or commercial entity.observed
  4. ProbableNAAGThe Idaho breach-notification statute's material scope is limited to unencrypted computerized personal information as statutorily defined, and does not establish a general processing-activity scope test.observed
  5. ProbableNAAGIdaho's breach law applies based on the residency of affected individuals rather than an establishment- or targeting-based territorial test.observed

#

No general lawful-basis, consent, or special-category framework exists at the state level; coverage is incidental via federal sectoral overlays only.

Traffic-light rationale — RedNo general lawful-basis, consent, or special-category framework exists at the state level; coverage is incidental via federal sectoral overlays only.

Sub-modules (4)

Lawful BasesRed

No Idaho statute enumerates lawful bases for processing personal data equivalent to GDPR Art. 6.

Claims (1):

  • Idaho has no state-law-enumerated lawful bases for processing personal data equivalent to GDPR Art. 6; processing legality is instead assessed under federal sectoral frameworks and FTC Act unfairness/deception standards.

Special CategoriesRed

Idaho has no state special-category data statute; sensitive-data protection is incidental, arising from federal HIPAA for health information where a covered entity is involved.

Claims (1):

  • No Idaho state statute establishes a special/sensitive-category data regime; where sensitive health data is involved, protection derives from federal HIPAA coverage of covered entities rather than Idaho law.

Pseudonymisation And AnonymisationRed

No Idaho statutory definition or safe-harbour for pseudonymisation or anonymisation was identified.

Absence provenance: not recorded. Searched: Idaho pseudonymisation anonymisation statute privacy.

Category narrative43 words

Idaho has no state-enumerated lawful bases for processing personal data, no statutory consent-threshold standard, and no special/sensitive-category regime analogous to GDPR Art. 9. Where sensitive data protections exist, they arise from federal sectoral law (e.g., HIPAA for health data) rather than Idaho statute.

Sources and claims (2)
  1. ConfirmedIAPPIdaho has no state-law-enumerated lawful bases for processing personal data equivalent to GDPR Art. 6; processing legality is instead assessed under federal sectoral frameworks and FTC Act unfairness/deception standards.observed
  2. ProbableIAPPNo Idaho state statute establishes a special/sensitive-category data regime; where sensitive health data is involved, protection derives from federal HIPAA coverage of covered entities rather than Idaho law.observed

#

No comprehensive consumer data-subject-rights framework exists; only a narrow FERPA-derived education-records right applies.

Traffic-light rationale — RedNo comprehensive consumer data-subject-rights framework exists; only a narrow FERPA-derived education-records right applies.

Sub-modules (5)

Access RightRed

No general right of access to personal data exists under Idaho law.

Claims (1):

  • Idaho does not grant a general consumer right of access to personal data held by businesses, in contrast to states with comprehensive privacy statutes.

Rectification And ErasureRed

No general right to rectify or erase personal data exists under Idaho law; a narrow FERPA-derived amendment right applies only to education records.

Claims (1):

  • Federal FERPA affords parents and eligible students limited rights to inspect and seek amendment of education records maintained by Idaho schools and their education-technology vendors, though FERPA itself carries no private right of action.

Restriction And ObjectionRed

No restriction-of-processing or objection right (including profiling opt-out) exists under Idaho law.

Absence provenance: not recorded. Searched: Idaho right to restrict processing objection profiling opt-out.

Data PortabilityRed

No data-portability right exists under Idaho law.

Absence provenance: not recorded. Searched: Idaho data portability right consumer privacy.

Deadlines And Response WindowsRed

No general statutory response-window applies to consumer rights requests; Idaho's breach law does not impose subject-access-type deadlines.

Absence provenance: not recorded. Searched: Idaho consumer data request response deadline statute.

Category narrative43 words

Idaho grants no general consumer rights of access, rectification, erasure, restriction, objection, or portability. The only rights-adjacent federal overlay applicable to Idaho residents in the education context is FERPA, which gives parents/eligible students limited rights to inspect and seek amendment of education records.

Sources and claims (2)
  1. ConfirmedIAPPIdaho does not grant a general consumer right of access to personal data held by businesses, in contrast to states with comprehensive privacy statutes.observed
  2. ProbableIAPPFederal FERPA affords parents and eligible students limited rights to inspect and seek amendment of education records maintained by Idaho schools and their education-technology vendors, though FERPA itself carries no private right of action.observed

#

A functioning breach-notification duty exists and federal enforcement has imposed retention obligations by consent order, but no general accountability/DPIA/DPO/ROPA framework exists.

Primary frameworkIdaho Code Title 28, Chapter 51 (breach notification)
Supervisory authorityIdaho Attorney General
Traffic-light rationale — AmberA functioning breach-notification duty exists and federal enforcement has imposed retention obligations by consent order, but no general accountability/DPIA/DPO/ROPA framework exists.

Sub-modules (7)

Accountability And DpiaRed

No accountability principle or DPIA-trigger regime exists under Idaho law.

Absence provenance: not recorded. Searched: Idaho DPIA data protection impact assessment requirement.

Dpo RequirementsRed

No DPO-appointment threshold exists under Idaho law.

Absence provenance: not recorded. Searched: Idaho data protection officer requirement statute.

Ropa RequirementsRed

No records-of-processing-activity obligation exists under Idaho law.

Absence provenance: not recorded. Searched: Idaho records of processing activities requirement.

Joint Controller ArrangementsRed

No joint-controller framework exists under Idaho law.

Absence provenance: not recorded. Searched: Idaho joint controller processor agreement requirement.

Security MeasuresAmber

No general statutory technical/organisational security-of-processing standard exists; reasonable-security expectations arise implicitly from FTC Act unfairness doctrine as applied in enforcement actions.

Claims (1):

  • Idaho has no general statutory security-of-processing standard; reasonable-security obligations are enforced incidentally through FTC Act Section 5 unfairness doctrine.

Breach NotificationGreen

Idaho Code §28-51-105 requires notification of security breaches involving computerized personal information.

Claims (1):

  • Idaho Code Title 28, Chapter 51, §28-51-105 requires agencies, individuals, or commercial entities to disclose breaches of security involving computerized personal information.

Retention And DisposalAmber

No general statutory retention/disposal duty exists; the FTC's 2026 consent order against Kochava (an Idaho-based data broker) imposed a bespoke data-retention schedule as an enforcement remedy.

Claims (1):

  • The FTC's 2026 stipulated final order against Idaho-based data broker Kochava requires the company to create a data-retention schedule mandating deletion of sensitive location data on an established timeframe.
Category narrative47 words

Idaho imposes no general accountability, DPIA, DPO, ROPA, or joint-controller obligations. The breach-notification statute is the sole binding controller duty, requiring notification upon breach of computerized personal information. Federal enforcement action against an Idaho-based data broker (Kochava) has produced retention/deletion-schedule obligations via consent order rather than statute.

Sources and claims (3)
  1. ProbableFederal Trade Commission / US District CourtIdaho has no general statutory security-of-processing standard; reasonable-security obligations are enforced incidentally through FTC Act Section 5 unfairness doctrine.observed
  2. ConfirmedDataGuidance (legal research compilation)Idaho Code Title 28, Chapter 51, §28-51-105 requires agencies, individuals, or commercial entities to disclose breaches of security involving computerized personal information.observed
  3. ConfirmedFederal Trade CommissionThe FTC's 2026 stipulated final order against Idaho-based data broker Kochava requires the company to create a data-retention schedule mandating deletion of sensitive location data on an established timeframe.observed

#

No state-level cross-border transfer framework exists; adequacy and transfer-mechanism questions are resolved exclusively at the US federal level, which is out of scope for this state-bound JID.

Traffic-light rationale — RedNo state-level cross-border transfer framework exists; adequacy and transfer-mechanism questions are resolved exclusively at the US federal level, which is out of scope for this state-bound JID.

Sub-modules (6)

Transfer MechanismsRed

No Idaho-specific transfer mechanism exists; any applicable mechanism (e.g., SCCs used contractually by Idaho-based businesses) operates under general US contract law, not a state privacy statute.

Absence provenance: not recorded. Searched: Idaho data transfer mechanism cross-border statute.

Adequacy ReceivedRed

Adequacy decisions are granted to national governments, not sub-national US states; no Idaho-specific adequacy status exists.

Absence provenance: not recorded. Searched: Idaho adequacy decision EU GDPR.

Adequacy GrantedRed

Idaho does not grant adequacy decisions; this is a federal/executive-branch function, not a state one.

Absence provenance: not recorded. Searched: Idaho adequacy decision granted to third country.

Sccs And BcrsRed

No Idaho-specific SCC/BCR regime exists.

Absence provenance: not recorded. Searched: Idaho standard contractual clauses binding corporate rules.

Transfer Impact AssessmentRed

No Idaho-specific transfer-impact-assessment requirement exists.

Absence provenance: not recorded. Searched: Idaho transfer impact assessment requirement.

Data LocalisationRed

No Idaho data-localisation mandate was identified.

Absence provenance: not recorded. Searched: Idaho data localisation requirement statute.

Category narrative36 words

Cross-border transfer mechanisms, adequacy determinations, SCC/BCR frameworks, and data-localisation mandates are federal/EU-level constructs; Idaho has no state-specific transfer regime, adequacy status, or localisation mandate of its own. This module is largely inapplicable at the state level.

#

Multiple federal sectoral overlays plus two narrow Idaho sector statutes provide partial coverage, but no unifying framework exists.

Primary frameworkFederal sectoral statutes (HIPAA, GLBA, FCRA, COPPA) plus Idaho HB 348 and SB 1372 (2014)
Supervisory authorityIdaho Attorney General
Traffic-light rationale — AmberMultiple federal sectoral overlays plus two narrow Idaho sector statutes provide partial coverage, but no unifying framework exists.

Sub-modules (7)

Financial Sector OverlayAmber

The federal Gramm-Leach-Bliley Act applies to financial institutions operating in Idaho, displacing the need for a state financial-privacy statute.

Claims (1):

  • The federal Gramm-Leach-Bliley Act applies nationally, including to financial institutions operating in Idaho, imposing privacy-notice and safeguarding obligations in the absence of a state financial-privacy statute.

Health Sector OverlayAmber

Federal HIPAA governs protected health information held by covered entities and business associates operating in Idaho; Idaho additionally restricts access to prescription-drug-monitoring-program data.

Claims (2):

  • Federal HIPAA Privacy and Security Rules apply to covered entities and business associates handling protected health information in Idaho.
  • Idaho enacted HB 348 in 2014 restricting access to state prescription-drug-monitoring-program databases.

Telecoms And EprivacyRed

No Idaho-specific eprivacy/cookie statute exists; federal TCPA governs telemarketing/robocall conduct.

Absence provenance: not recorded. Searched: Idaho eprivacy telecoms cookie statute.

Employment DataRed

No Idaho-specific employment-data-privacy statute was identified.

Absence provenance: not recorded. Searched: Idaho employment data privacy statute.

Credit And ScoringAmber

Federal FCRA governs credit-reporting and scoring activity affecting Idaho residents; no supplementary Idaho statute was identified.

Claims (1):

  • The federal Fair Credit Reporting Act governs credit-reporting and scoring activity affecting Idaho residents, with no supplementary Idaho state statute identified.

EducationAmber

Idaho SB 1372 (2014) restricts access to student data, supplementing federal FERPA protections for education records.

Claims (1):

  • Idaho enacted SB 1372 in 2014 restricting access to student data, supplementing federal FERPA education-records protections.

InsuranceRed

No Idaho-specific insurance-sector data-privacy statute was identified beyond general NAIC-model-act-derived insurance regulation.

Absence provenance: not recorded. Searched: Idaho insurance data privacy statute.

Category narrative47 words

In the absence of an omnibus statute, Idaho residents' data receives protection principally through federal sectoral overlays: HIPAA (health), GLBA (financial), FCRA (credit/scoring), and COPPA (children). Idaho has also enacted narrow sector-specific statutes restricting access to prescription-drug-monitoring records (HB 348, 2014) and student data (SB 1372, 2014).

Sources and claims (5)
  1. ConfirmedIAPPThe federal Gramm-Leach-Bliley Act applies nationally, including to financial institutions operating in Idaho, imposing privacy-notice and safeguarding obligations in the absence of a state financial-privacy statute.observed
  2. ConfirmedIAPPFederal HIPAA Privacy and Security Rules apply to covered entities and business associates handling protected health information in Idaho.observed
  3. ProbableIAPPIdaho enacted HB 348 in 2014 restricting access to state prescription-drug-monitoring-program databases.observed
  4. ProbableIAPPThe federal Fair Credit Reporting Act governs credit-reporting and scoring activity affecting Idaho residents, with no supplementary Idaho state statute identified.observed
  5. ProbableIAPPIdaho enacted SB 1372 in 2014 restricting access to student data, supplementing federal FERPA education-records protections.observed

#

No dedicated adtech/commercial-privacy statute exists at the state level; the only meaningful check is reactive federal FTC enforcement.

Primary frameworkFTC Act Section 5 (federal, reactive only)
Supervisory authorityFederal Trade Commission
Traffic-light rationale — RedNo dedicated adtech/commercial-privacy statute exists at the state level; the only meaningful check is reactive federal FTC enforcement.

Sub-modules (6)

Cookies And TrackersRed

No Idaho cookie/tracker consent statute exists.

Absence provenance: not recorded. Searched: Idaho cookie consent tracker statute.

Dark PatternsRed

No Idaho dark-pattern prohibition statute exists.

Absence provenance: not recorded. Searched: Idaho dark patterns consumer protection statute.

Opt Out SignalsRed

Idaho does not require recognition of universal opt-out signals such as Global Privacy Control.

Absence provenance: not recorded. Searched: Idaho global privacy control opt-out signal law.

Clean Rooms And DcrRed

No Idaho clean-room/data-collaboration-room regulation exists.

Absence provenance: not recorded. Searched: Idaho data clean room regulation.

Cross Context AdvertisingAmber

No CPRA-style sale/share framework exists in Idaho; the FTC's 2026 Kochava order addresses undisclosed sale of sensitive location data under federal Section 5 authority rather than a state cross-context-advertising statute.

Claims (1):

  • The FTC's 2026 stipulated order against Idaho-based data broker Kochava prohibits the sale, sharing, or disclosure of sensitive location data without consumers' affirmative express consent, enforced under federal Section 5 authority rather than a state cross-context-advertising statute.

Direct MarketingRed

No Idaho-specific direct-marketing consent/suppression statute exists; federal TCPA and CAN-SPAM apply nationally.

Absence provenance: not recorded. Searched: Idaho direct marketing consent suppression statute.

Category narrative46 words

Idaho has no cookie/tracker consent statute, no dark-pattern prohibition, no opt-out-signal recognition law, no clean-room regime, and no CPRA-style 'sale'/'share' framework for cross-context advertising. The clearest applicable precedent is federal FTC Section 5 enforcement against an Idaho-based data broker for undisclosed sale of sensitive location data.

Sources and claims (1)
  1. ConfirmedFederal Trade CommissionThe FTC's 2026 stipulated order against Idaho-based data broker Kochava prohibits the sale, sharing, or disclosure of sensitive location data without consumers' affirmative express consent, enforced under federal Section 5 authority rather than a state cross-context-advertising statute.observed

#

Idaho has meaningful and growing AI-transparency and chatbot-specific legislation, but lacks a biometric-specific regime, general ADM-transparency right, or profiling restriction.

Primary frameworkIdaho Code §48-603h (AI communications disclosure, 2025) + Idaho companion/conversational-AI chatbot statute (2026)
Supervisory authorityIdaho Attorney General
Traffic-light rationale — AmberIdaho has meaningful and growing AI-transparency and chatbot-specific legislation, but lacks a biometric-specific regime, general ADM-transparency right, or profiling restriction.

Sub-modules (6)

Profiling RestrictionsRed

No Idaho profiling-restriction statute analogous to GDPR Art. 22 was identified.

Absence provenance: not recorded. Searched: Idaho profiling restriction automated decision-making statute.

Automated Decision Making TransparencyAmber

Idaho HB 127 (2025) requires disclosure when AI is used in consumer communications, functioning as a narrow ADM-transparency measure limited to AI-identity disclosure rather than a general explanation right.

Claims (1):

  • Idaho House Bill 127 (2025), codified as new Idaho Code §48-603h, deems it an unfair trade practice for AI communications to mislead consumers into believing they are interacting with a human absent clear disclosure, effective July 1, 2025.

Ai Risk AssessmentsRed

No Idaho AI-risk-assessment requirement analogous to the EU AI Act was identified.

Absence provenance: not recorded. Searched: Idaho AI risk assessment requirement statute.

Biometric RegimeRed

No Idaho biometric-data statute (facial recognition, fingerprint, gait) analogous to Illinois BIPA was identified.

Absence provenance: not recorded. Searched: Idaho biometric information privacy law facial recognition statute.

Genetic DataRed

No Idaho genetic-data-specific privacy statute was identified.

Absence provenance: not recorded. Searched: Idaho genetic data privacy statute.

State Surveillance CarveoutsRed

No Idaho-specific state-surveillance carve-out analysis was identified; national-security exemptions operate at the federal level.

Absence provenance: not recorded. Searched: Idaho state surveillance national security carveout privacy.

Category narrative85 words

Idaho has emerged as one of the more active states on AI-specific transparency legislation: HB 127 (2025, codified at Idaho Code §48-603h) requires disclosure when consumers are communicating with AI, and Idaho is reported among the broadest-approach states (with Colorado, Iowa, and Nebraska) to have passed a companion/conversational-AI chatbot law by mid-2026 covering any publicly accessible conversational AI system, not just companion apps. Idaho has also enacted deepfake legislation addressing nonconsensual intimate imagery and deceptive election media. No dedicated biometric-data or genetic-data statute was identified.

Sources and claims (3)
  1. ConfirmedDataGuidanceIdaho House Bill 127 (2025), codified as new Idaho Code §48-603h, deems it an unfair trade practice for AI communications to mislead consumers into believing they are interacting with a human absent clear disclosure, effective July 1, 2025.observed
  2. ProbableIAPPBy June 2026, Idaho was reported among the states with the broadest chatbot-law approach, covering any publicly accessible conversational AI service that primarily simulates human conversation, rather than limiting scope to companion apps.observed
  3. ProbableIAPPIdaho is among the states that have enacted deepfake legislation addressing nonconsensual intimate images and deceptive audio/visual media related to voting or candidates.observed

#

Federal COPPA plus a state student-data statute and emerging chatbot minor-protections provide partial coverage, but no dedicated age-verification, parental-consent, or dependent-adult privacy statute exists.

Primary frameworkCOPPA (federal) + Idaho SB 1372 (2014) + Idaho companion/chatbot statute (2026, minor provisions)
Supervisory authorityIdaho Attorney General
Traffic-light rationale — AmberFederal COPPA plus a state student-data statute and emerging chatbot minor-protections provide partial coverage, but no dedicated age-verification, parental-consent, or dependent-adult privacy statute exists.

Sub-modules (5)

Age VerificationAmber

No Idaho-specific general age-verification statute for data processing was identified beyond chatbot-law minor triggers.

Claims (1):

  • Multi-state chatbot laws, including Idaho's, are reported to share a common structure imposing additional minor-specific AI disclosures and content restrictions once an operator has reason to believe a user is a minor.

Minor Profiling BansRed

No general Idaho minor-profiling ban was identified outside chatbot-specific minor protections.

Absence provenance: not recorded. Searched: Idaho minor profiling ban statute.

Education SettingsAmber

Idaho SB 1372 (2014) restricts access to student data in education settings, supplementing federal FERPA.

Claims (1):

  • Idaho enacted SB 1372 in 2014 to restrict access to student data, addressing education-sector data-privacy concerns identified by the Idaho Attorney General's office.

Dependent AdultsRed

No Idaho dependent-adult (elderly/incapacitated) data-privacy statute was identified.

Absence provenance: not recorded. Searched: Idaho dependent adult elderly data privacy statute.

Category narrative61 words

Idaho relies on federal COPPA for online children's-privacy protection and on its 2014 student-data statute (SB 1372) for education-sector protections. Idaho's 2026 chatbot legislation is reported to follow the common multi-state pattern of imposing heightened minor-specific protections (additional AI disclosures, restrictions on sexual content, bars on manipulative engagement) alongside baseline requirements applicable to all users. No dependent-adult-specific data-privacy statute was identified.

Sources and claims (3)
  1. ProbableIAPPMulti-state chatbot laws, including Idaho's, are reported to share a common structure imposing additional minor-specific AI disclosures and content restrictions once an operator has reason to believe a user is a minor.observed
  2. ConfirmedIAPPFederal COPPA requires operators of online services directed to children under 13 to obtain verifiable parental consent before collecting personal information, applicable nationally including to Idaho-serving operators.observed
  3. ProbableIAPPIdaho enacted SB 1372 in 2014 to restrict access to student data, addressing education-sector data-privacy concerns identified by the Idaho Attorney General's office.observed

#

Despite the absence of a comprehensive statute, enforcement is demonstrably active via both the Idaho AG and federal FTC action against an Idaho-based entity within the review window.

Primary frameworkFTC Act Section 5 + Idaho AG consumer-protection authority
Supervisory authorityIdaho Attorney General
Traffic-light rationale — GreenDespite the absence of a comprehensive statute, enforcement is demonstrably active via both the Idaho AG and federal FTC action against an Idaho-based entity within the review window.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

The Idaho AG has general investigative and injunctive consumer-protection powers; the FTC has investigative, injunctive, and civil-penalty powers under Section 5, as demonstrated in the Kochava matter.

Claims (1):

  • The FTC possesses investigative and injunctive authority under Section 5 of the FTC Act, and has used it to pursue permanent injunctions against Idaho-based entities such as data broker Kochava.

Enforcement Activity IndexGreen

The FTC's 2026 stipulated final order against Kochava, an Idaho-based data broker, filed in the U.S. District Court for the District of Idaho, is the most significant recent enforcement action touching Idaho.

Claims (1):

  • In May 2026, the FTC obtained a stipulated final order in the U.S. District Court for the District of Idaho banning data broker Kochava and its subsidiary from selling sensitive location data without consumers' affirmative express consent.

Regulator Funding And CapacityAmber

No specific funding or headcount data for the Idaho AG's consumer-protection division was identified in this research pass.

Absence provenance: not recorded. Searched: Idaho Attorney General consumer protection division budget headcount.

Collective Redress And Class ActionsRed

No Idaho-specific collective-redress mechanism for data-privacy claims was identified beyond general state class-action procedure.

Absence provenance: not recorded. Searched: Idaho class action data privacy collective redress.

Private Right Of ActionRed

No comprehensive Idaho state private right of action for general data-privacy violations exists; breach-notification enforcement is primarily AG-driven.

Claims (1):

  • Some state breach-notification statutes allow private rights of action for noncompliance; Idaho's is not among the states most commonly cited as providing such a right, and enforcement is primarily attorney-general-driven.

Recent Developments 180DAmber

Within the 180-day window preceding this run, the FTC finalized its Kochava consent order (May 2026) and Idaho's broad-approach chatbot statute was reported as passed by June 2026.

Claims (1):

  • As of June 2026, Idaho was reported among 11 U.S. states that had passed chatbot laws regulating AI systems designed to interact with consumers, adopting one of the broadest scope definitions alongside Colorado, Iowa, and Nebraska.
Category narrative66 words

Enforcement in Idaho operates through two channels: the Idaho Attorney General's general consumer-protection powers, and federal FTC Section 5 authority, most visibly demonstrated by the FTC's 2026 stipulated final order against Idaho-based data broker Kochava banning the sale of sensitive location data. No comprehensive state private right of action for general data-privacy violations exists; the AG's office also participates in multistate coalitions on AI/chatbot child-safety advocacy.

Sources and claims (4)
  1. ConfirmedFederal Trade Commission / US District CourtThe FTC possesses investigative and injunctive authority under Section 5 of the FTC Act, and has used it to pursue permanent injunctions against Idaho-based entities such as data broker Kochava.observed
  2. ConfirmedFederal Trade CommissionIn May 2026, the FTC obtained a stipulated final order in the U.S. District Court for the District of Idaho banning data broker Kochava and its subsidiary from selling sensitive location data without consumers' affirmative express consent.observed
  3. UncertainNAAGSome state breach-notification statutes allow private rights of action for noncompliance; Idaho's is not among the states most commonly cited as providing such a right, and enforcement is primarily attorney-general-driven.observed
  4. ProbableIAPPAs of June 2026, Idaho was reported among 11 U.S. states that had passed chatbot laws regulating AI systems designed to interact with consumers, adopting one of the broadest scope definitions alongside Colorado, Iowa, and Nebraska.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United States – Idaho
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 28 claim(s), 13 source(s) in the cumulative register.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

Regulator_and_framework, controller_processor_duties (breach_notification), sectoral_watch, algorithmic_biometric_and_surveillance_governance, and enforcement_and_redress carry T1/T2/T3 primary-source support (FTC.gov, NAAG.org, Idaho statute compilation via DataGuidance, IAPP reporting). lawful_processing_and_special_data, data_subject_rights, and cross_border_and_adequacy are populated primarily with absence-findings supported by T3 tracker sources, consistent with Idaho's lack of an omnibus statute. children_and_vulnerable_groups relies partly on a 2014-dated T4 historical interview for the SB 1372/HB 348 claims and should be re-verified against current Idaho Code citations. The Idaho 2026 companion-chatbot statute's exact bill number, Idaho Code citation, and effective date could not be confirmed from available T1/T2 sources and rest on T3 IAPP secondary reporting only.

Unresolved questions (4):

  • What is the exact bill number, Idaho Code citation, and effective date of Idaho's 2026 companion/conversational-AI chatbot statute referenced by IAPP as one of the broadest-scope state chatbot laws?
  • Does the Idaho breach-notification statute (§28-51-105) include a private right of action, or is enforcement exclusively AG-driven?
  • Are Idaho HB 348 and SB 1372 (2014) still in force in their original form, or have they been amended/recodified since 2014?
  • Does Idaho recognize any universal opt-out signal (e.g., GPC) in any sector-specific context not captured in this research pass?

Escalate to primary-source review: yes