#
A functioning enforcement authority and a narrow breach-notification statute exist, but there is no comprehensive material/territorial scope framework or registration regime.
Sub-modules (5)
Regulator And AuthorityAmber
The Idaho Attorney General (Raúl Labrador) is the primary state enforcement authority for consumer-protection/privacy matters, operating under general consumer-protection statutes rather than a dedicated privacy-enforcement mandate.
Claims (1):
- The Idaho Attorney General, currently Raúl Labrador, is the state's chief law-enforcement officer with general consumer-protection authority that extends to privacy-adjacent enforcement.
Act And InstrumentsAmber
No omnibus privacy act exists; the operative instruments are the Idaho breach-notification statute and federal sectoral/FTC authority.
Claims (2):
- Idaho has no comprehensive state consumer-privacy statute; data-protection matters are governed by federal FTC Act Section 5 authority and applicable federal sectoral laws, plus the state's breach-notification statute.
- Idaho Code Title 28, Chapter 51, §28-51-105 governs disclosure of breach of security of computerized personal information by an agency, individual, or commercial entity.
Material ScopeRed
Material scope is narrow: the breach statute covers only computerized personal information as statutorily defined, not general processing activity.
Claims (1):
- The Idaho breach-notification statute's material scope is limited to unencrypted computerized personal information as statutorily defined, and does not establish a general processing-activity scope test.
Territorial ScopeAmber
The breach law is triggered by residency of affected individuals rather than an establishment or targeting test; there is no extraterritorial reach comparable to GDPR Art. 3.
Claims (1):
- Idaho's breach law applies based on the residency of affected individuals rather than an establishment- or targeting-based territorial test.
Regulator Registration And FilingRed
No controller/processor registration or filing obligation exists under Idaho law.
Absence provenance: not recorded. Searched: Idaho controller registration privacy law, Idaho data protection registration requirement.
Sources and claims (5)
- ConfirmedNAAG — The Idaho Attorney General, currently Raúl Labrador, is the state's chief law-enforcement officer with general consumer-protection authority that extends to privacy-adjacent enforcement.observed
- ConfirmedIAPP — Idaho has no comprehensive state consumer-privacy statute; data-protection matters are governed by federal FTC Act Section 5 authority and applicable federal sectoral laws, plus the state's breach-notification statute.observed
- ConfirmedDataGuidance (legal research compilation) — Idaho Code Title 28, Chapter 51, §28-51-105 governs disclosure of breach of security of computerized personal information by an agency, individual, or commercial entity.observed
- ProbableNAAG — The Idaho breach-notification statute's material scope is limited to unencrypted computerized personal information as statutorily defined, and does not establish a general processing-activity scope test.observed
- ProbableNAAG — Idaho's breach law applies based on the residency of affected individuals rather than an establishment- or targeting-based territorial test.observed