Comprehensive statute is in force but is narrower than GDPR-style regimes (no dedicated regulator, no registration regime, small-business/entity-level exemptions), and several adjacent instruments (Biometric Autonomy Liberty Law) remain at bill stage.
Primary frameworkNebraska Data Privacy Act (LB 1074), 2024, effective 1 January 2025
Traffic-light rationale — AmberComprehensive statute is in force but is narrower than GDPR-style regimes (no dedicated regulator, no registration regime, small-business/entity-level exemptions), and several adjacent instruments (Biometric Autonomy Liberty Law) remain at bill stage.
Sub-modules (5)
Regulator And AuthorityAmber
The Nebraska Attorney General, currently Mike Hilgers, is the sole enforcement authority for the NDPA and related privacy statutes; Nebraska has no separate privacy commissioner or agency analogous to California's CPPA.
Claims (1):
The Nebraska Data Privacy Act grants consumer data rights and imposes obligations on controllers, enforced by the Nebraska Attorney General.
Act And InstrumentsAmber
Primary instrument is the NDPA (LB 1074); adjacent instruments include GIPA (LB 308), the Financial Data Protection and Consumer Notification of Data Security Breach Act of 2006 (Neb. Rev. Stat. §87-801 et seq.), the Workplace Privacy Act as amended by LB 477, the Delete Act, LB 504, and the Age-Appropriate Online Design Code Act.
Claims (2):
Nebraska's Data Privacy Act (LB 1074) was signed into law by Governor Jim Pillen on April 17, 2024, and is set to go into effect on January 1, 2025.
Nebraska's Genetic Information Privacy Act (GIPA, LB 308) was signed by Governor Jim Pillen on February 13, 2024, and went into effect on July 17, 2024, mandating consumer consent and security measures for genetic-data handling by direct-to-consumer testing companies.
Material ScopeAmber
The NDPA governs personal data processing by controllers/processors conducting business in Nebraska or targeting Nebraska residents, following the Washington Privacy Act (WPA) template; consumer definition excludes individuals acting in an employment or B2B capacity.
Claims (1):
Nebraska also has data security and breach notification requirements pursuant to the Financial Data Protection and Consumer Notification of Data Security Breach Act, 2006, under §87-801 et seq. of Chapter 87 of the Nebraska Revised Statutes.
Territorial ScopeAmber
Applicability is not tied to a specific numeric revenue/volume threshold as in most WPA-model states; Nebraska instead exempts entities meeting the U.S. Small Business Administration's definition of a small business, a notable structural divergence from peer states.
Claims (1):
Nebraska's NDPA applicability threshold and enforcement structure materially differ from Nebraska's own GIPA and from other states' comprehensive laws, per comparative legal analysis contrasting the two statutes.
Regulator Registration And FilingAmber
No controller registration/filing regime exists under the NDPA itself; the Delete Act imposes data-broker registration obligations ahead of a 2028 compliance date.
Claims (1):
Nebraska's Delete Act mandates data brokers to register, secure data, and facilitate consumer data deletion requests by 2028.
Category narrative78 words
Nebraska has no dedicated data-protection authority. The Nebraska Data Privacy Act (NDPA, LB 1074), a WPA-model comprehensive consumer privacy statute, is enforced exclusively by the Nebraska Attorney General (AG). It sits alongside sector-specific instruments (Genetic Information Privacy Act, Financial Data Protection and Consumer Notification of Data Security Breach Act 2006, Workplace Privacy Act, Delete Act, Age-Appropriate Online Design Code Act) also enforced by the AG's office, producing a hybrid omnibus-plus-sectoral-overlay structure typical of post-2021 US state privacy laws.
Sources and claims (6)
ConfirmedDataGuidance — The Nebraska Data Privacy Act grants consumer data rights and imposes obligations on controllers, enforced by the Nebraska Attorney General.observed
ConfirmedDataGuidance — Nebraska's Data Privacy Act (LB 1074) was signed into law by Governor Jim Pillen on April 17, 2024, and is set to go into effect on January 1, 2025.observed
ConfirmedDataGuidance — Nebraska's Genetic Information Privacy Act (GIPA, LB 308) was signed by Governor Jim Pillen on February 13, 2024, and went into effect on July 17, 2024, mandating consumer consent and security measures for genetic-data handling by direct-to-consumer testing companies.observed
ConfirmedDataGuidance — Nebraska also has data security and breach notification requirements pursuant to the Financial Data Protection and Consumer Notification of Data Security Breach Act, 2006, under §87-801 et seq. of Chapter 87 of the Nebraska Revised Statutes.observed
ProbableDataGuidance — Nebraska's NDPA applicability threshold and enforcement structure materially differ from Nebraska's own GIPA and from other states' comprehensive laws, per comparative legal analysis contrasting the two statutes.observed
ProbableDataGuidance — Nebraska's Delete Act mandates data brokers to register, secure data, and facilitate consumer data deletion requests by 2028.observed
Consent and sensitive-data protections exist but are narrower and less codified than GDPR Art 6/9 equivalents; no explicit statutory list of lawful bases beyond consent/necessity language confirmed in research.
Primary frameworkNebraska Data Privacy Act (LB 1074); Genetic Information Privacy Act (LB 308)
Traffic-light rationale — AmberConsent and sensitive-data protections exist but are narrower and less codified than GDPR Art 6/9 equivalents; no explicit statutory list of lawful bases beyond consent/necessity language confirmed in research.
Sub-modules (4)
Lawful BasesAmber
No GDPR Art 6-style enumerated legal-bases list was identified for the NDPA in this research; the statute follows the WPA consent/necessity template common to peer states.
Claims (1):
The Nebraska Data Privacy Act regulates personal data processing and imposes penalties for violations, following a consent/notice-based model rather than an enumerated legal-bases structure.
Consent ThresholdsAmber
Opt-in consent is required for processing sensitive data and for processing minors' data, consistent with the WPA-model approach adopted across the 2024 wave of state privacy laws including Nebraska's.
Claims (1):
Comparative analysis of the 2024 wave of state privacy laws, including Nebraska's, notes common threshold applicability, purpose and enforcement-structure differences between GIPA-style consent regimes and general NDPA consent requirements.
Special CategoriesGreen
GIPA specifically mandates consumer consent and security measures for genetic data handling by direct-to-consumer testing companies, operating alongside NDPA's general sensitive-data consent requirement.
Claims (1):
Nebraska's Genetic Information Privacy Act mandates consumer consent and security measures for genetic data handling by testing companies.
Pseudonymisation And AnonymisationRed
No Nebraska-specific statutory safe-harbour language for de-identified/pseudonymised data was located in this research pass; treated as an evidence gap pending direct statutory text review.
Absence provenance: not recorded. Searched: Nebraska Data Privacy Act pseudonymisation anonymisation de-identified data safe harbor.
Category narrative45 words
The NDPA follows the WPA-model consent/notice-based approach rather than a GDPR-style enumerated legal-bases regime. Processing must be reasonably necessary and proportionate to disclosed purposes; sensitive/special-category data and processing of minors' data requires opt-in consent. GIPA imposes a parallel, stricter consent regime for genetic data specifically.
Sources and claims (3)
ProbableDataGuidance — The Nebraska Data Privacy Act regulates personal data processing and imposes penalties for violations, following a consent/notice-based model rather than an enumerated legal-bases structure.observed
ProbableDataGuidance — Comparative analysis of the 2024 wave of state privacy laws, including Nebraska's, notes common threshold applicability, purpose and enforcement-structure differences between GIPA-style consent regimes and general NDPA consent requirements.observed
ConfirmedDataGuidance — Nebraska's Genetic Information Privacy Act mandates consumer consent and security measures for genetic data handling by testing companies.observed
Core rights are confirmed as granted by primary/secondary sources but exact deadline text (45+45 days) is inferred from the WPA template rather than directly cited from Nebraska statutory language retrieved in this research.
Primary frameworkNebraska Data Privacy Act (LB 1074)
Traffic-light rationale — AmberCore rights are confirmed as granted by primary/secondary sources but exact deadline text (45+45 days) is inferred from the WPA template rather than directly cited from Nebraska statutory language retrieved in this research.
Sub-modules (5)
Access RightAmber
The NDPA grants consumer data rights including access to personal data held by controllers.
Claims (1):
The Nebraska Data Privacy Act grants consumer data rights and imposes obligations on controllers, enforced by the Nebraska Attorney General.
Rectification And ErasureAmber
Consumer rights include correction and deletion of personal data, consistent with the AG's published FAQs on the NDPA.
Claims (1):
The Nebraska AG's FAQs on the NDPA outline data protection responsibilities and consumer rights effective January 1, 2025.
Restriction And ObjectionAmber
Consumers may opt out of processing for targeted advertising, sale, and certain profiling in furtherance of decisions producing legal or similarly significant effects.
Claims (1):
In Nebraska, the requirement to allow consumers to opt out of processing for targeted advertising or sale through opt-out preference signals is already in effect, having gone into effect January 1, 2025.
Data PortabilityRed
No specific statutory portability-format language was independently verified in this research pass beyond general WPA-model inclusion; flagged as an evidence gap.
Absence provenance: not recorded. Searched: Nebraska Data Privacy Act data portability right format.
Deadlines And Response WindowsAmber
Nebraska AG published FAQs on the NDPA outlining data protection responsibilities and consumer rights effective January 1, 2025, but specific response-window day-counts were not independently confirmed in this pass.
Claims (1):
The Nebraska AG published FAQs on the NDPA outlining data protection responsibilities and consumer rights, effective January 1, 2025.
Category narrative49 words
The NDPA grants Nebraska consumers WPA-model rights (access, correction, deletion, portability, and opt-out of targeted advertising/sale/certain profiling), enforced solely by the AG. Precise statutory response-window lengths (typically 45 days plus a 45-day extension in peer WPA states) were not independently verified against Nebraska's specific statutory text in this pass.
Sources and claims (4)
ConfirmedDataGuidance — The Nebraska Data Privacy Act grants consumer data rights and imposes obligations on controllers, enforced by the Nebraska Attorney General.observed
ConfirmedDataGuidance — The Nebraska AG's FAQs on the NDPA outline data protection responsibilities and consumer rights effective January 1, 2025.observed
ConfirmedIAPP — In Nebraska, the requirement to allow consumers to opt out of processing for targeted advertising or sale through opt-out preference signals is already in effect, having gone into effect January 1, 2025.observed
ConfirmedDataGuidance — The Nebraska AG published FAQs on the NDPA outlining data protection responsibilities and consumer rights, effective January 1, 2025.observed
Core accountability/security obligations exist but breach-notification substance sits outside the NDPA in an older, narrower 2006 statute, and DPO/ROPA formalities characteristic of GDPR are absent.
Primary frameworkNebraska Data Privacy Act (LB 1074); Financial Data Protection and Consumer Notification of Data Security Breach Act of 2006 (Neb. Rev. Stat. §87-801 et seq.)
Traffic-light rationale — AmberCore accountability/security obligations exist but breach-notification substance sits outside the NDPA in an older, narrower 2006 statute, and DPO/ROPA formalities characteristic of GDPR are absent.
Sub-modules (7)
Accountability And DpiaAmber
WPA-model data protection assessment requirements are understood to apply to higher-risk processing, consistent with peer 2024-wave states; exact Nebraska DPIA trigger text was not independently retrieved in this pass.
Claims (1):
Data protection assessment requirements apply to processing activities created or generated after specified dates across the 2024-wave WPA-model states, a template Nebraska's NDPA follows.
Dpo RequirementsRed
No Nebraska-specific DPO appointment mandate was identified; WPA-model laws generally do not impose a formal DPO requirement.
Absence provenance: not recorded. Searched: Nebraska Data Privacy Act data protection officer requirement.
Ropa RequirementsRed
No records-of-processing-activities filing requirement analogous to GDPR Art 30 was identified for Nebraska in this research.
Absence provenance: not recorded. Searched: Nebraska Data Privacy Act records of processing activities requirement.
Joint Controller ArrangementsAmber
WPA-model processor-contract requirements are presumed applicable by template but were not independently sourced with Nebraska-specific text in this pass.
Absence provenance: not recorded. Searched: Nebraska Data Privacy Act processor contract joint controller requirements.
Security MeasuresAmber
Nebraska law states an individual or commercial entity complies with the reasonable-security requirement if it complies with a state or federal law providing greater protection, or complies with GLBA or HIPAA implementing regulations.
Claims (1):
Nebraska law states an individual or a commercial entity complies with the reasonable security requirement of Nebraska law if it complies with a state or federal law that provides greater protection to personal information than the Nebraska law or complies with the regulations promulgated under GLBA or HIPAA.
Breach NotificationAmber
The Data Privacy Act was approved April 18, 2024 and enters into effect January 1, 2025, but has only limited provisions on breach notification; substantive breach-notice obligations run through the 2006 Financial Data Protection and Consumer Notification of Data Security Breach Act instead.
Claims (2):
On April 18, 2024, the Data Privacy Act was approved by the Governor of Nebraska and will enter into effect on January 1, 2025; however, the DPA has only limited provisions on breach notifications.
Nebraska has data security and breach notification requirements pursuant to the Financial Data Protection and Consumer Notification of Data Security Breach Act, 2006, under §87-801 et seq., enforced by the Nebraska Attorney General, who may issue subpoenas and recover direct economic damages for each injured resident.
Retention And DisposalRed
No Nebraska-specific retention-limitation statutory text beyond general WPA-model data-minimization principles was independently retrieved in this pass.
Absence provenance: not recorded. Searched: Nebraska Data Privacy Act data retention limitation disposal requirement.
Category narrative93 words
NDPA controllers must implement reasonable administrative, technical and physical safeguards and conduct data protection assessments for higher-risk processing (targeted advertising, sale, certain profiling, sensitive data), per the WPA template. Nebraska's security-compliance provision contains a notable safe-harbour: compliance with GLBA or HIPAA regulations (or a stricter state/federal law) satisfies the reasonable-security requirement. Breach notification is governed primarily by the separate 2006 Financial Data Protection and Consumer Notification of Data Security Breach Act, not the NDPA itself, which the record describes as having only limited breach provisions. No formal DPO-appointment or ROPA-filing mandate was identified.
Sources and claims (4)
UncertainIAPP — Data protection assessment requirements apply to processing activities created or generated after specified dates across the 2024-wave WPA-model states, a template Nebraska's NDPA follows.observed
ConfirmedIAPP — Nebraska law states an individual or a commercial entity complies with the reasonable security requirement of Nebraska law if it complies with a state or federal law that provides greater protection to personal information than the Nebraska law or complies with the regulations promulgated under GLBA or HIPAA.observed
ConfirmedDataGuidance — On April 18, 2024, the Data Privacy Act was approved by the Governor of Nebraska and will enter into effect on January 1, 2025; however, the DPA has only limited provisions on breach notifications.observed
ConfirmedDataGuidance — Nebraska has data security and breach notification requirements pursuant to the Financial Data Protection and Consumer Notification of Data Security Breach Act, 2006, under §87-801 et seq., enforced by the Nebraska Attorney General, who may issue subpoenas and recover direct economic damages for each injured resident.observed
No comprehensive cross-border transfer regime exists at the Nebraska state level; this is an accurate 'gap' finding rather than a missed search.
Traffic-light rationale — RedNo comprehensive cross-border transfer regime exists at the Nebraska state level; this is an accurate 'gap' finding rather than a missed search.
Sub-modules (6)
Transfer MechanismsRed
No Nebraska-specific international-transfer mechanism (adequacy/SCC/BCR/derogation) regime exists; state privacy law does not regulate cross-border data flows in the GDPR sense.
Absence provenance: not recorded. Searched: Nebraska Data Privacy Act international data transfer mechanism.
Adequacy ReceivedRed
Not applicable; US states do not receive adequacy determinations under foreign regimes.
Absence provenance: not recorded. Searched: Nebraska adequacy decision received EU GDPR.
Adequacy GrantedRed
Not applicable; Nebraska does not grant adequacy determinations to other regimes.
Absence provenance: not recorded. Searched: Nebraska adequacy decision granted.
Sccs And BcrsRed
No Nebraska-specific SCC/BCR framework exists.
Absence provenance: not recorded. Searched: Nebraska Data Privacy Act standard contractual clauses binding corporate rules.
Transfer Impact AssessmentRed
No transfer-impact-assessment requirement exists under Nebraska law.
Absence provenance: not recorded. Searched: Nebraska Data Privacy Act transfer impact assessment.
Data LocalisationRed
No general data-localisation mandate was identified for Nebraska in this research.
Absence provenance: not recorded. Searched: Nebraska data localisation requirement.
Category narrative56 words
As a US state consumer-privacy statute, the NDPA does not implement a GDPR-style international-transfer regime (no adequacy findings, SCC/BCR frameworks, or transfer impact assessments). Nebraska imposes no general data-localisation mandate. This module is materially inapplicable to a US state JID beyond ordinary contractual processor-transfer obligations, which were not independently sourced with Nebraska-specific text in this pass.
Sectoral overlays exist and are actively enforced, but several sub-modules (telecoms/ePrivacy, credit-scoring, education, insurance) had no Nebraska-specific findings in this pass.
Primary frameworkFinancial Data Protection and Consumer Notification of Data Security Breach Act of 2006; Nebraska Consumer Protection Act; Workplace Privacy Act
Traffic-light rationale — AmberSectoral overlays exist and are actively enforced, but several sub-modules (telecoms/ePrivacy, credit-scoring, education, insurance) had no Nebraska-specific findings in this pass.
Sub-modules (7)
Financial Sector OverlayAmber
GLBA-regulated entities benefit from an entity-level exemption and a security-compliance safe-harbour referencing GLBA regulations under Nebraska's breach-notification framework.
Claims (1):
An individual or commercial entity complies with Nebraska's reasonable security requirement if it complies with regulations promulgated under GLBA or HIPAA, or a state/federal law providing greater protection.
Health Sector OverlayAmber
The Nebraska AG sued Change Healthcare, UnitedHealth Group and Optum under the Consumer Protection Act, the Financial Data Protection and Consumer Notification of Data Security Breach Act of 2006, and the Uniform Deceptive Trade Practices Act following a breach exposing personal and protected health information of approximately 575,000 Nebraskans.
Claims (1):
The State of Nebraska, through Attorney General Michael T. Hilgers, brought an action against Change Healthcare Inc., UnitedHealth Group Incorporated, and Optum, Inc. for violations of the Consumer Protection Act, the Financial Data Protection and Consumer Notification of Data Security Breach Act of 2006, and the Uniform Deceptive Trade Practices Act stemming from a data breach that exposed personal information and electronic protected health information of approximately 575,000 Nebraskans.
Telecoms And EprivacyRed
No Nebraska-specific ePrivacy/telecoms-sector DP overlay was identified in this research pass.
Absence provenance: not recorded. Searched: Nebraska telecoms eprivacy data protection overlay.
Employment DataAmber
Nebraska's Bill 477 amends the Workplace Privacy Act, limiting employer access to employees' personal internet accounts and tracking devices; the NDPA itself excludes individuals acting in an employment context from its consumer definition.
Claims (1):
Nebraska's Bill 477 amends the Workplace Privacy Act, limiting employer access to personal internet accounts and tracking devices.
Credit And ScoringAmber
The GM/OnStar litigation touches credit/insurance-scoring concerns (driving data sold to build 'Driving Scores' used by insurers), but no dedicated Nebraska credit-scoring statute was identified.
Claims (1):
GM allegedly packaged and sold Nebraskans' driving data to third-party data brokers who used it to create 'Driving Scores' later sold to insurance companies to raise rates, deny coverage, or cancel policies without drivers' knowledge.
EducationRed
No Nebraska-specific education-sector data-protection overlay was identified in this research pass beyond presumed FERPA-alignment exemptions.
Absence provenance: not recorded. Searched: Nebraska education sector data protection overlay FERPA.
InsuranceAmber
No dedicated Nebraska insurance-sector data-protection statute was identified in this research pass, though the GM/OnStar case demonstrates AG interest in insurer use of driving-behavior data.
Claims (1):
GM allegedly packaged and sold Nebraskans' driving data to third-party data brokers who used it to create 'Driving Scores' later sold to insurance companies to raise rates, deny coverage, or cancel policies without drivers' knowledge.
Category narrative91 words
GLBA-regulated financial institutions and HIPAA-covered entities/business associates benefit from entity-level exemptions under the NDPA and a compliance safe-harbour under the 2006 breach law. The AG's active litigation against Change Healthcare/UnitedHealth/Optum (health data breach affecting ~575,000 Nebraskans) and against General Motors/OnStar (unconsented sale of connected-vehicle driving data used for insurance underwriting) illustrate cross-sector enforcement under the Consumer Protection Act, breach-notification law, and deceptive-trade-practices law rather than the NDPA itself. The Workplace Privacy Act (amended by LB 477) supplies an employment-sector overlay limiting employer access to employees' personal internet accounts and tracking devices.
Sources and claims (4)
ConfirmedIAPP — An individual or commercial entity complies with Nebraska's reasonable security requirement if it complies with regulations promulgated under GLBA or HIPAA, or a state/federal law providing greater protection.observed
ConfirmedNebraska Attorney General — The State of Nebraska, through Attorney General Michael T. Hilgers, brought an action against Change Healthcare Inc., UnitedHealth Group Incorporated, and Optum, Inc. for violations of the Consumer Protection Act, the Financial Data Protection and Consumer Notification of Data Security Breach Act of 2006, and the Uniform Deceptive Trade Practices Act stemming from a data breach that exposed personal information and electronic protected health information of approximately 575,000 Nebraskans.observed
ProbableDataGuidance — Nebraska's Bill 477 amends the Workplace Privacy Act, limiting employer access to personal internet accounts and tracking devices.observed
ConfirmedNebraska Attorney General — GM allegedly packaged and sold Nebraskans' driving data to third-party data brokers who used it to create 'Driving Scores' later sold to insurance companies to raise rates, deny coverage, or cancel policies without drivers' knowledge.observed
Traffic-light rationale — AmberUOOM/opt-out rights are confirmed in force; several sub-modules (clean rooms, dark patterns specifics) lack direct Nebraska-specific sourcing.
Sub-modules (6)
Cookies And TrackersAmber
No standalone Nebraska cookie-consent statute was identified; tracking/cookie-based data collection falls within the NDPA's general personal-data and opt-out framework.
Absence provenance: not recorded. Searched: Nebraska cookie consent law statute.
Dark PatternsAmber
The WPA-model template Nebraska follows generally requires that consent not be obtained through dark patterns, but Nebraska-specific statutory text confirming this was not independently retrieved in this pass.
Absence provenance: not recorded. Searched: Nebraska Data Privacy Act dark patterns consent prohibition.
Opt Out SignalsGreen
In Nebraska, universal-opt-out-mechanism (UOOM) requirements for sale/targeted-advertising opt-outs are already in effect, having gone into effect January 1, 2025, alongside California, Colorado, Connecticut, Montana, New Hampshire and Texas.
Claims (1):
In California, Colorado, Connecticut, Montana, Nebraska, New Hampshire and Texas, universal-opt-out-mechanism (UOOM) related requirements are already in effect, with each states' UOOM requirements, excluding California and Colorado, going into effect 1 January.
Clean Rooms And DcrRed
No Nebraska-specific data clean-room or data-collaboration-room rule was identified in this research.
Absence provenance: not recorded. Searched: Nebraska data clean room data collaboration room privacy rule.
Cross Context AdvertisingAmber
The NDPA provides an opt-out right for targeted advertising and sale of personal data, without a distinct 'share' category as under California's CPRA.
Claims (1):
In California, Colorado, Connecticut, Montana, Nebraska, New Hampshire and Texas, universal-opt-out-mechanism (UOOM) related requirements are already in effect, with each states' UOOM requirements, excluding California and Colorado, going into effect 1 January.
Direct MarketingAmber
Direct marketing is governed through the general targeted-advertising opt-out right; no separate Nebraska telemarketing-specific DP statute was independently sourced in this pass.
Absence provenance: not recorded. Searched: Nebraska direct marketing consent suppression data protection statute.
Category narrative43 words
Nebraska requires businesses to honor universal opt-out mechanisms (UOOM) for sale and targeted-advertising opt-outs, a requirement already in effect since January 1, 2025. No separate cookie-consent statute or clean-room/data-collaboration-room rule was identified; adtech governance runs through the NDPA's general opt-out and consent architecture.
Sources and claims (1)
ConfirmedIAPP — In California, Colorado, Connecticut, Montana, Nebraska, New Hampshire and Texas, universal-opt-out-mechanism (UOOM) related requirements are already in effect, with each states' UOOM requirements, excluding California and Colorado, going into effect 1 January.observed
Genetic-data regime is confirmed in force; biometric-specific standalone law status is uncertain (bill vs enacted); AI risk-assessment and surveillance-carveout sub-modules are evidence gaps.
Primary frameworkNebraska Data Privacy Act (LB 1074); Genetic Information Privacy Act (LB 308)
Traffic-light rationale — AmberGenetic-data regime is confirmed in force; biometric-specific standalone law status is uncertain (bill vs enacted); AI risk-assessment and surveillance-carveout sub-modules are evidence gaps.
Sub-modules (6)
Profiling RestrictionsAmber
The NDPA is understood to grant an opt-out right for profiling in furtherance of solely automated decisions with legal or similarly significant effects, consistent with the WPA template; direct Nebraska statutory text was not independently retrieved in this pass.
Absence provenance: not recorded. Searched: Nebraska Data Privacy Act profiling opt-out solely automated decision.
Automated Decision Making TransparencyAmber
No GDPR Art 22-style explanation/transparency right was identified for Nebraska; the regime is opt-out based rather than transparency/explanation based.
No Nebraska-specific AI-risk-assessment statute was identified in this research pass.
Absence provenance: not recorded. Searched: Nebraska AI risk assessment law artificial intelligence statute.
Biometric RegimeAmber
Nebraska's Legislative Bill 204 for a Biometric Autonomy Liberty Law was introduced January 14, 2024, and referred to the Banking, Commerce, and Insurance Committee on January 16, 2024, mandating written consent for biometric data collection with a proposed operative date of January 1, 2026; enactment (passage into law) was not confirmed in this research.
Claims (1):
Legislative Bill 204 for the Biometric Autonomy Liberty Law, referred to the Banking, Commerce, and Insurance Committee, mandates written consent for the collection and use of biometric data and is set to become operative on January 1, 2026; the bill was introduced on January 14, 2024.
Genetic DataGreen
Nebraska's Genetic Information Privacy Act mandates consumer consent and security measures for genetic data handling by testing companies, in force since July 17, 2024.
Claims (1):
Nebraska's Genetic Information Privacy Act mandates consumer consent and security measures for genetic data handling by testing companies.
State Surveillance CarveoutsRed
No Nebraska-specific state-surveillance carve-out text was independently retrieved in this research pass.
Absence provenance: not recorded. Searched: Nebraska Data Privacy Act national security law enforcement exemption.
Category narrative104 words
The NDPA provides an opt-out right for profiling in furtherance of solely automated decisions producing legal or similarly significant effects (WPA-model, not a full GDPR Art 22-style explanation right). Biometric data is treated as sensitive data requiring consent under the NDPA; a standalone Biometric Autonomy Liberty Law (LB 204) was introduced and referred to committee in January 2024 with a proposed operative date of January 1, 2026, but its enactment status was not confirmed as passed in this research pass. Genetic data is separately and more stringently regulated under GIPA (in force since July 2024). No Nebraska-specific AI-risk-assessment statute or state-surveillance-carveout text was identified.
Sources and claims (2)
UncertainDataGuidance — Legislative Bill 204 for the Biometric Autonomy Liberty Law, referred to the Banking, Commerce, and Insurance Committee, mandates written consent for the collection and use of biometric data and is set to become operative on January 1, 2026; the bill was introduced on January 14, 2024.observed
ConfirmedDataGuidance — Nebraska's Genetic Information Privacy Act mandates consumer consent and security measures for genetic data handling by testing companies.observed
Minors' protections are robust and dated, but enforcement has not yet commenced (begins July 2026) and dependent-adult/education-settings sub-modules are evidence gaps.
Traffic-light rationale — AmberMinors' protections are robust and dated, but enforcement has not yet commenced (begins July 2026) and dependent-adult/education-settings sub-modules are evidence gaps.
Sub-modules (5)
Age VerificationAmber
The Age-Appropriate Online Design Code Act applies to online services with significant revenue and user bases, exempting entities with minimal minor users and those covered by federal laws like HIPAA.
Claims (1):
The Code applies to online services with significant revenue and user bases, exempting entities with minimal minor users and those under federal laws like HIPAA, and enforcement by the Nebraska Attorney General begins July 1, 2026, with penalties up to $50,000 per violation, emphasizing compliance without a cure period.
Parental ConsentAmber
The NDPA requires opt-in consent for processing minors' data for targeted advertising, sale, or profiling purposes, consistent with the WPA-model template; exact age thresholds were not independently confirmed for Nebraska in this pass.
Absence provenance: not recorded. Searched: Nebraska Data Privacy Act minors consent age threshold.
Minor Profiling BansAmber
Nebraska's Age-Appropriate Online Design Code Act, effective January 1, 2026, strengthens online privacy protections for minors by mandating data minimization, default privacy settings, and restrictions on targeted advertising.
Claims (1):
On May 30, 2025, Nebraska became the third US state to adopt an age-appropriate design code law with the enactment of the Code, following California (2022) and Maryland (2024), strengthening online privacy protections for minors by mandating data minimization, default privacy settings, and restrictions on targeted advertising.
Education SettingsRed
No Nebraska-specific education-settings data-protection provision was identified in this research pass.
Absence provenance: not recorded. Searched: Nebraska education settings student data privacy statute.
Dependent AdultsRed
No Nebraska-specific dependent-adults/elderly data-protection provision was identified; the AG's Consumer Affairs Response Team addresses elder-fraud generally but not through a DP-specific statute.
Absence provenance: not recorded. Searched: Nebraska dependent adults elderly data protection statute.
Category narrative72 words
Nebraska adopted an Age-Appropriate Online Design Code Act (signed May 30, 2025, becoming the third state after California and Maryland), effective January 1, 2026, with AG enforcement beginning July 1, 2026 and penalties up to $50,000 per violation with no cure period. LB 504 separately regulates online services accessed by minors under 13, targeting compulsive-use and psychological-harm risks, also effective January 1, 2026. No Nebraska-specific education-settings or dependent-adults data-protection provisions were identified.
Sources and claims (2)
ConfirmedDataGuidance — The Code applies to online services with significant revenue and user bases, exempting entities with minimal minor users and those under federal laws like HIPAA, and enforcement by the Nebraska Attorney General begins July 1, 2026, with penalties up to $50,000 per violation, emphasizing compliance without a cure period.observed
ConfirmedDataGuidance — On May 30, 2025, Nebraska became the third US state to adopt an age-appropriate design code law with the enactment of the Code, following California (2022) and Maryland (2024), strengthening online privacy protections for minors by mandating data minimization, default privacy settings, and restrictions on targeted advertising.observed
Enforcement authority and recent case activity are well evidenced; regulator funding/capacity data, NDPA-specific cure-period length, and collective-redress mechanisms were not independently confirmed in this pass.
Traffic-light rationale — AmberEnforcement authority and recent case activity are well evidenced; regulator funding/capacity data, NDPA-specific cure-period length, and collective-redress mechanisms were not independently confirmed in this pass.
Sub-modules (6)
Regulator Powers And PenaltiesAmber
The Nebraska AG is empowered to investigate and enforce NDPA and related privacy violations; GIPA specifically provides for a civil penalty of $2,500 per violation plus actual damages and attorney's fees, while the Age-Appropriate Online Design Code Act provides penalties up to $50,000 per violation with no cure period once enforcement begins.
Claims (2):
The Nebraska Attorney General is empowered to enforce GIPA's provisions, with violations incurring a civil penalty of $2,500 per violation, plus actual damages and attorney's fees.
Enforcement of the Age-Appropriate Online Design Code Act by the Nebraska Attorney General begins July 1, 2026, with penalties up to $50,000 per violation, emphasizing compliance without a cure period.
Enforcement Activity IndexAmber
Notable recent AG actions include the Change Healthcare/UnitedHealth/Optum data-breach suit and the General Motors/OnStar connected-vehicle-data suit, both litigated primarily under the Consumer Protection Act and Uniform Deceptive Trade Practices Act rather than the NDPA itself.
Claims (2):
The State of Nebraska, through Attorney General Michael T. Hilgers, brought an action against Change Healthcare Inc., UnitedHealth Group Incorporated, and Optum, Inc. for violations of the Consumer Protection Act, the Financial Data Protection and Consumer Notification of Data Security Breach Act of 2006, and the Uniform Deceptive Trade Practices Act stemming from a data breach affecting approximately 575,000 Nebraskans.
Nebraska Attorney General Mike Hilgers announced that the State of Nebraska filed a lawsuit against General Motors LLC and OnStar LLC for unlawfully collecting, processing, and selling sensitive driving data from Nebraskans without their knowledge or consent, alleging violations of the Nebraska Consumer Protection Act and Uniform Deceptive Trade Practices Act, and the complaint seeks civil penalties, restitution, and injunctive relief.
Regulator Funding And CapacityRed
No specific budget/headcount data for the AG's privacy-enforcement function was identified in this research pass.
Absence provenance: not recorded. Searched: Nebraska Attorney General privacy enforcement budget headcount capacity.
Collective Redress And Class ActionsAmber
No NDPA-specific class-action mechanism was identified; general Nebraska Consumer Protection Act litigation (as used against Change Healthcare and GM) may support broader consumer redress but is not a data-protection-specific collective mechanism.
Absence provenance: not recorded. Searched: Nebraska Data Privacy Act class action collective redress mechanism.
Private Right Of ActionAmber
Per the seed disambiguation and general pattern of 2024-wave state privacy statutes, the NDPA lacks a private right of action; enforcement runs exclusively through the Nebraska Attorney General's general authority.
Claims (1):
Consistent with most 2024-wave US state comprehensive privacy laws, the Nebraska Data Privacy Act lacks a private right of action, with enforcement running exclusively through the Nebraska Attorney General's general authority.
Recent Developments 180DAmber
Within the last 180 days of the current run date (Aug 2026), the most salient forward development is the commencement of Attorney General enforcement of the Age-Appropriate Online Design Code Act on July 1, 2026; the General Motors/OnStar suit (filed mid-2025) remains an active recent matter though slightly outside a strict 180-day window.
Claims (1):
Enforcement of the Age-Appropriate Online Design Code Act by the Nebraska Attorney General begins July 1, 2026, with penalties up to $50,000 per violation, emphasizing compliance without a cure period.
Category narrative112 words
Enforcement of the NDPA and related privacy statutes runs exclusively through the Nebraska Attorney General (currently Mike Hilgers, in office since 2022); the NDPA lacks a private right of action, consistent with the majority of 2024-wave state privacy laws. The AG has demonstrated active enforcement appetite in adjacent consumer-protection/data-breach litigation, including suits against Change Healthcare/UnitedHealth/Optum (health-data breach, ~575,000 Nebraskans affected) and against General Motors/OnStar (unconsented sale of connected-vehicle driving data used for insurance underwriting, filed under the Consumer Protection Act and Uniform Deceptive Trade Practices Act). The Age-Appropriate Online Design Code Act's AG enforcement start (July 1, 2026) is a recent/near-term development within the last 180 days of the current run date.
Sources and claims (5)
ConfirmedDataGuidance — The Nebraska Attorney General is empowered to enforce GIPA's provisions, with violations incurring a civil penalty of $2,500 per violation, plus actual damages and attorney's fees.observed
ConfirmedDataGuidance — Enforcement of the Age-Appropriate Online Design Code Act by the Nebraska Attorney General begins July 1, 2026, with penalties up to $50,000 per violation, emphasizing compliance without a cure period.observed
ConfirmedNebraska Attorney General — The State of Nebraska, through Attorney General Michael T. Hilgers, brought an action against Change Healthcare Inc., UnitedHealth Group Incorporated, and Optum, Inc. for violations of the Consumer Protection Act, the Financial Data Protection and Consumer Notification of Data Security Breach Act of 2006, and the Uniform Deceptive Trade Practices Act stemming from a data breach affecting approximately 575,000 Nebraskans.observed
ConfirmedNebraska Attorney General — Nebraska Attorney General Mike Hilgers announced that the State of Nebraska filed a lawsuit against General Motors LLC and OnStar LLC for unlawfully collecting, processing, and selling sensitive driving data from Nebraskans without their knowledge or consent, alleging violations of the Nebraska Consumer Protection Act and Uniform Deceptive Trade Practices Act, and the complaint seeks civil penalties, restitution, and injunctive relief.observed
ProbableDataGuidance — Consistent with most 2024-wave US state comprehensive privacy laws, the Nebraska Data Privacy Act lacks a private right of action, with enforcement running exclusively through the Nebraska Attorney General's general authority.observed
No categories match.
Filters combine as OR inside a group and AND across
groups.
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for United States – Nebraska
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
not recorded
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 31 claim(s), 15 source(s) in the cumulative register.
GDPR article map
Cross-reference: which category/sub-module covers each UK GDPR article (37 mapped).
regulator_and_framework, data_subject_rights, controller_processor_duties, sectoral_watch, adtech_and_commercial_privacy, algorithmic_biometric_and_surveillance_governance, children_and_vulnerable_groups and enforcement_and_redress carry a mix of T1 (ago.nebraska.gov primary regulator releases and court filings) and T3 (DataGuidance/IAPP secondary legal-tracker) sourcing, sufficient for Probable-to-Confirmed claims on core NDPA/GIPA/Age-Appropriate Design Code facts and on two live AG enforcement actions (Change Healthcare; GM/OnStar). lawful_processing_and_special_data relies mostly on T3 template-inference for the WPA-model consent/lawful-bases architecture, since no direct Nebraska statutory full-text (Nebraska Legislature bill-text site) was in the retrieval allowlist for this run. cross_border_and_adequacy is correctly emitted as a structural gap (red, empty claims, absent_field_provenance) since no state-level transfer regime exists. Several sub-modules across controller_processor_duties (DPO, ROPA, retention), adtech_and_commercial_privacy (cookies, dark patterns, clean rooms), algorithmic_biometric_and_surveillance_governance (AI risk assessments, ADM transparency detail, surveillance carve-outs), and children_and_vulnerable_groups (education settings, dependent adults) rely on absent_field_provenance because no Nebraska-specific primary or secondary source surfaced in the searches run.
Unresolved questions (5):
Does the NDPA's applicability threshold rely purely on an SBA small-business exemption with no numeric revenue/volume threshold, or does it also include a numeric processing-volume trigger as in most WPA-model peer states? Direct Nebraska statutory text was not retrieved to confirm.
What is the exact NDPA consumer-request response-window (e.g., 45 days + 45-day extension) and is there a statutory cure period (and if so, its length and sunset date)?
Has LB 204 (Biometric Autonomy Liberty Law) been enacted into law, or does it remain pending/referred to committee as of the current run date?
Does the NDPA contain an explicit DPIA/data-protection-assessment trigger list, and does it require a ROPA or DPO appointment under any threshold?
Is there a Nebraska-specific data-broker registration deadline/process detail under the Delete Act beyond the general 2028 compliance date?