🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
US-NV · run data-protection-2026-08-06 v13-gdpri-1.0.0
content: ai_generated 18 sources retrieved model claude-sonnet-5 ·

United States – Nevada

US-NV schema gdpri-v2 trajectory: not recordedregulated (sectoral)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 24 claims · 18 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
24Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

A real, in-force statutory floor exists (breach notification + two narrow sectoral add-ons) but there is no comprehensive material/territorial scope comparable to an omnibus regime.

Primary frameworkNRS Chapter 603A (Security and Privacy of Personal Information), as amended by SB 220 (2019) and SB 370 (2023)
Traffic-light rationale — AmberA real, in-force statutory floor exists (breach notification + two narrow sectoral add-ons) but there is no comprehensive material/territorial scope comparable to an omnibus regime.

Sub-modules (5)

Regulator And AuthorityGreen

The Nevada Attorney General is the sole enforcement authority for NRS 603A, SB 220, and SB 370; there is no dedicated privacy regulator or rulemaking agency comparable to the CPPA.

Claims (1):

  • The Nevada Attorney General is the exclusive enforcement authority for Nevada's opt-out-of-sale statute (SB 220), with power to bring district-court proceedings and impose civil penalties of up to $5,000 per violation.

Act And InstrumentsAmber

The operative instruments are NRS Chapter 603A (breach notification and records destruction), SB 220 (opt-out-of-sale), and SB 370 (consumer health data). None is comprehensive in the CCPA/GDPR sense.

Claims (1):

  • Unlike the California Consumer Privacy Act, Nevada's SB 220 is not a comprehensive privacy statute: it does not provide proportional data-portability rights and lacks an explicit anti-discrimination clause for consumers who opt out.

Material ScopeAmber

Material scope is defined narrowly and instrument-by-instrument: SB 220 covers 'covered information' collected via a website/online service; SB 370 covers 'consumer health data'; NRS 603A's breach provisions cover a separate, narrower 'personal information' definition.

Claims (1):

  • SB 220's 'covered information' is defined in NRS 603A.320 to include name, physical address, email address, telephone number, Social Security number, an online/physical contact identifier, and other information maintained in combination with such an identifier.

Territorial ScopeAmber

SB 220 applies extraterritorially to any operator of an online service (in or outside Nevada) that purposefully directs activity toward, or has sufficient constitutional nexus with, Nevada residents, but does not reach offline conduct.

Claims (1):

  • SB 220 applies to any operator of an online service, whether located inside or outside Nevada, that purposefully directs activity toward the state or otherwise has sufficient constitutional nexus, but does not apply to offline commercial activity.

Regulator Registration And FilingRed

No general controller-registration or filing obligation exists under current Nevada law. A 2025 bill (SB 199) would have required AI companies to register with the Bureau of Consumer Protection, but its enactment status could not be confirmed in this research pass.

Claims (1):

  • Nevada Senate Bill 199 (introduced February 11, 2025) would require AI companies operating in Nevada to register with the Bureau of Consumer Protection and conduct semi-annual self-assessments; enactment status is unconfirmed as of this research pass.
Category narrative85 words

Nevada has no comprehensive omnibus consumer-privacy statute equivalent to the GDPR or the CCPA. The state's data-protection footprint is a narrow sectoral patchwork built on NRS Chapter 603A (Security and Privacy of Personal Information), which combines a data-breach-notification/records-destruction regime with two narrower consumer-facing add-ons: SB 220 (2019, opt-out-of-sale for online 'covered information') and SB 370 (2023/2024, consumer health data). Enforcement of all three strands sits exclusively with the Nevada Attorney General. Federal sectoral law (FTC Act Section 5, HIPAA, GLBA, COPPA) supplies the remaining backstop.

Sources and claims (5)
  1. ConfirmedInternational Association of Privacy ProfessionalsThe Nevada Attorney General is the exclusive enforcement authority for Nevada's opt-out-of-sale statute (SB 220), with power to bring district-court proceedings and impose civil penalties of up to $5,000 per violation.observed
  2. ConfirmedInternational Association of Privacy ProfessionalsUnlike the California Consumer Privacy Act, Nevada's SB 220 is not a comprehensive privacy statute: it does not provide proportional data-portability rights and lacks an explicit anti-discrimination clause for consumers who opt out.observed
  3. ConfirmedInternational Association of Privacy ProfessionalsSB 220's 'covered information' is defined in NRS 603A.320 to include name, physical address, email address, telephone number, Social Security number, an online/physical contact identifier, and other information maintained in combination with such an identifier.observed
  4. ConfirmedInternational Association of Privacy ProfessionalsSB 220 applies to any operator of an online service, whether located inside or outside Nevada, that purposefully directs activity toward the state or otherwise has sufficient constitutional nexus, but does not apply to offline commercial activity.observed
  5. UncertainDataGuidanceNevada Senate Bill 199 (introduced February 11, 2025) would require AI companies operating in Nevada to register with the Bureau of Consumer Protection and conduct semi-annual self-assessments; enactment status is unconfirmed as of this research pass.observed

#

Sensitive-category and consent-adjacent rules exist only within the narrow consumer-health-data statute; there is no general Article 6/Article 7-style regime.

Primary frameworkSB 370 (Nevada consumer health data law), NRS Chapter 603A
Traffic-light rationale — AmberSensitive-category and consent-adjacent rules exist only within the narrow consumer-health-data statute; there is no general Article 6/Article 7-style regime.

Sub-modules (4)

Lawful BasesRed

No general enumerated lawful-basis scheme exists outside SB 370's health-data-specific necessity standard.

Absence provenance: not recorded. Searched: Nevada data breach notification statute NRS 603A, Nevada SB 220 online sale opt-out privacy law 2019.

Special CategoriesAmber

SB 370 treats data on sexual activity, gender identity, reproductive health, and mental health as especially sensitive 'consumer health data' warranting conservative collection and sharing practices.

Claims (1):

  • SB 370 was explicitly drafted to address discrimination, stigma and harm risks associated with data on sexual activity, gender identity, reproductive health, and mental health, requiring conservative collection and sharing of such data.

Pseudonymisation And AnonymisationRed

No Nevada-specific statutory pseudonymisation/anonymisation safe harbour was identified in this research pass.

Absence provenance: not recorded. Searched: Nevada NRS 603A breach notification deadline encryption safe harbor.

Category narrative52 words

Nevada has no general enumerated lawful-basis framework for ordinary commercial data processing. The only codified consent/sensitive-data regime is SB 370's treatment of 'consumer health data' (modeled on Washington's My Health My Data Act), which restricts collection/sharing to purposes 'necessary' to a consumer request absent consent and singles out highly sensitive health-adjacent categories.

Sources and claims (2)
  1. ConfirmedInternational Association of Privacy ProfessionalsUnder SB 370, entities may collect and share consumer health data for purposes 'necessary' to meet a consumer's request without obtaining explicit consent, but neither SB 370 nor its Washington model law defines what qualifies as 'necessary.'observed
  2. ConfirmedInternational Association of Privacy ProfessionalsSB 370 was explicitly drafted to address discrimination, stigma and harm risks associated with data on sexual activity, gender identity, reproductive health, and mental health, requiring conservative collection and sharing of such data.observed

#

A narrow, single-purpose opt-out right with a defined response deadline exists; the broader DSR bundle (access/erasure/portability) is absent.

Primary frameworkSB 220 (Nevada opt-out-of-sale statute)
Traffic-light rationale — AmberA narrow, single-purpose opt-out right with a defined response deadline exists; the broader DSR bundle (access/erasure/portability) is absent.

Sub-modules (5)

Access RightRed

No general right of access to personal data exists under Nevada law; SB 220 is limited to a sale opt-out and does not create an access right.

Absence provenance: not recorded. Searched: Nevada SB 220 online sale opt-out privacy law 2019.

Rectification And ErasureRed

No statutory right to rectification or erasure ('right to be forgotten') exists under Nevada consumer-privacy law.

Absence provenance: not recorded. Searched: Nevada SB 220 online sale opt-out privacy law 2019, Nevada SB 370 2021 privacy law amendment health data.

Restriction And ObjectionAmber

The only restriction-type right is SB 220's consumer right to direct an operator, via a verified request, not to sell covered information.

Claims (1):

  • SB 220 provides Nevada consumers with the ability to submit a verified request directing an operator not to sell certain covered information collected via a website or online service.

Data PortabilityRed

No data-portability right exists under current Nevada statute.

Absence provenance: not recorded. Searched: Nevada SB 220 online sale opt-out privacy law 2019.

Deadlines And Response WindowsGreen

SB 220 sets a 60-day response window for verified opt-out requests, extendable by up to 30 additional days with notice to the consumer.

Claims (1):

  • Operators receiving a verified opt-out request under SB 220 must respond within 60 days of receipt, with an available 30-day extension if the operator determines it reasonably necessary and notifies the consumer.
Category narrative64 words

Nevada does not grant a general bundle of data-subject rights (access, rectification, erasure, portability). The only individual-facing rights are (i) SB 220's right to opt out of the 'sale' of covered information, subject to a 60-day (extendable) response window, and (ii) SB 370's more limited consumer-health-data protections. There is no statutory right of access, rectification, erasure, restriction of processing, or portability comparable to CCPA/GDPR.

Sources and claims (2)
  1. ConfirmedInternational Association of Privacy ProfessionalsSB 220 provides Nevada consumers with the ability to submit a verified request directing an operator not to sell certain covered information collected via a website or online service.observed
  2. ConfirmedInternational Association of Privacy ProfessionalsOperators receiving a verified opt-out request under SB 220 must respond within 60 days of receipt, with an available 30-day extension if the operator determines it reasonably necessary and notifies the consumer.observed

#

Security and breach-notification duties are well-established and enforced; accountability-style duties (DPIA, DPO, ROPA, joint controllership) are entirely absent.

Primary frameworkNRS Chapter 603A (Security and Privacy of Personal Information)
Traffic-light rationale — AmberSecurity and breach-notification duties are well-established and enforced; accountability-style duties (DPIA, DPO, ROPA, joint controllership) are entirely absent.

Sub-modules (7)

Accountability And DpiaRed

No DPIA or general accountability-principle obligation exists under Nevada law.

Absence provenance: not recorded. Searched: Nevada data breach notification statute NRS 603A.

Dpo RequirementsRed

Nevada imposes no DPO-appointment or independence requirement on controllers or processors.

Absence provenance: not recorded. Searched: Nevada data breach notification statute NRS 603A.

Ropa RequirementsRed

No records-of-processing-activities obligation exists under Nevada statute.

Absence provenance: not recorded. Searched: Nevada data breach notification statute NRS 603A.

Joint Controller ArrangementsRed

Nevada law does not define or regulate joint-controller relationships.

Absence provenance: not recorded. Searched: Nevada data breach notification statute NRS 603A.

Security MeasuresAmber

NRS Chapter 603A imposes a general duty on data collectors to implement and maintain reasonable security measures to protect personal information from unauthorized access, acquisition, destruction, use, modification, or disclosure.

Claims (1):

  • Nevada's Privacy and Security of Personal Information chapter (NRS 603A) imposes a statutory duty on data collectors to implement and maintain reasonable security measures to protect personal information they maintain.

Breach NotificationGreen

NRS 603A.220 requires notification of affected Nevada residents following a security breach; the Attorney General's office reports it investigates breaches affecting a large number of Nevadans and recommends businesses err on the side of notifying the AG's office.

Claims (1):

  • When the Nevada Attorney General's office receives notice of a data breach that may impact a large number of Nevadans, it conducts an investigation, typically with the assistance of the affected company, into how the breach occurred and what security measures were in place.

Retention And DisposalAmber

NRS 603A.200 imposes a records-destruction obligation for certain records containing personal information; detailed operative text could not be retrieved due to source access limitations.

Claims (1):

  • NRS 603A.200 establishes a statutory obligation regarding destruction of certain records containing personal information in Nevada.
Category narrative53 words

Nevada imposes statutory duties centred on data security and breach notification (NRS Chapter 603A) rather than a full accountability/DPIA/DPO/ROPA framework. There is a records-destruction obligation (NRS 603A.200) and a breach-notification obligation (NRS 603A.220), with the Attorney General actively investigating breaches affecting large numbers of Nevadans. No DPIA, DPO-appointment, ROPA, or joint-controller regime exists.

Sources and claims (3)
  1. ProbableDataGuidanceNevada's Privacy and Security of Personal Information chapter (NRS 603A) imposes a statutory duty on data collectors to implement and maintain reasonable security measures to protect personal information they maintain.observed
  2. ConfirmedInternational Association of Privacy ProfessionalsWhen the Nevada Attorney General's office receives notice of a data breach that may impact a large number of Nevadans, it conducts an investigation, typically with the assistance of the affected company, into how the breach occurred and what security measures were in place.observed
  3. UncertainDataGuidanceNRS 603A.200 establishes a statutory obligation regarding destruction of certain records containing personal information in Nevada.observed

#

Complete absence of a state-level cross-border/adequacy/localisation regime; this is a legitimate finding rather than a research gap.

Traffic-light rationale — RedComplete absence of a state-level cross-border/adequacy/localisation regime; this is a legitimate finding rather than a research gap.

Sub-modules (6)

Transfer MechanismsRed

No Nevada-specific transfer mechanism (adequacy, SCCs, BCRs, derogations) exists in state law.

Absence provenance: not recorded. Searched: Nevada data breach notification statute NRS 603A, Nevada SB 220 online sale opt-out privacy law 2019, Nevada SB 370 2021 privacy law amendment health data.

Adequacy ReceivedRed

Not applicable; US states do not receive adequacy decisions independently of federal frameworks, and none was found for Nevada.

Absence provenance: not recorded. Searched: Nevada data breach notification statute NRS 603A.

Adequacy GrantedRed

Not applicable; Nevada has no authority to grant adequacy determinations to other regimes.

Absence provenance: not recorded. Searched: Nevada data breach notification statute NRS 603A.

Sccs And BcrsRed

No Nevada-specific SCC or BCR framework exists.

Absence provenance: not recorded. Searched: Nevada data breach notification statute NRS 603A.

Transfer Impact AssessmentRed

No transfer-impact-assessment requirement exists under Nevada law.

Absence provenance: not recorded. Searched: Nevada data breach notification statute NRS 603A.

Data LocalisationRed

No data-localisation mandate (partial or absolute) was identified for Nevada.

Absence provenance: not recorded. Searched: Nevada data breach notification statute NRS 603A.

Category narrative56 words

No Nevada-specific cross-border transfer regime, adequacy mechanism, SCC/BCR analogue, transfer-impact-assessment requirement, or data-localisation mandate was identified. As a US state operating under a federal system with no comprehensive omnibus privacy law, Nevada has not legislated in this area; any cross-border data-flow considerations for Nevada-linked processing arise from federal law or contractual practice, not from state statute.

#

Financial and health overlays are well documented; five of seven sub-modules have no identified Nevada-specific content.

Primary frameworkSB 220 (financial/health carve-outs); SB 370 (consumer health data law)
Traffic-light rationale — AmberFinancial and health overlays are well documented; five of seven sub-modules have no identified Nevada-specific content.

Sub-modules (7)

Financial Sector OverlayAmber

SB 220 excludes from its 'operator' definition third parties that operate, host, or manage a website or service on behalf of a financial institution (or its affiliates) subject to the Gramm-Leach-Bliley Act.

Claims (1):

  • SB 220 amends the definition of 'operator' to exclude a third party that operates, hosts, or manages a website or online service on behalf of a financial institution, or its affiliates, subject to the Gramm-Leach-Bliley Act.

Health Sector OverlayAmber

SB 370 (Nevada consumer health data law), modeled on Washington's My Health My Data Act, took effect March 31, 2024; SB 220 separately excludes HIPAA-regulated entities from its 'operator' definition.

Claims (2):

  • Nevada's SB 370, a consumer health data privacy law modeled on Washington's My Health My Data Act, received final legislative passage and took effect March 31, 2024, and unlike the Washington law does not carry a private right of action.
  • SB 220 excludes from its 'operator' definition entities subject to the Health Insurance Portability and Accountability Act (HIPAA), avoiding duplicative obligations for HIPAA-regulated entities.

Telecoms And EprivacyRed

No Nevada-specific telecoms/ePrivacy overlay (e.g., cookie-consent statute) was identified.

Absence provenance: not recorded. Searched: Nevada SB 220 online sale opt-out privacy law 2019.

Employment DataRed

No Nevada-specific employment-data privacy overlay was identified.

Absence provenance: not recorded. Searched: Nevada data breach notification statute NRS 603A.

Credit And ScoringRed

No Nevada-specific credit-scoring overlay beyond federal FCRA was identified.

Absence provenance: not recorded. Searched: Nevada data breach notification statute NRS 603A.

EducationRed

No Nevada-specific education-sector data-privacy overlay was identified.

Absence provenance: not recorded. Searched: Nevada data breach notification statute NRS 603A.

InsuranceRed

No Nevada-specific insurance-sector data-privacy overlay was identified.

Absence provenance: not recorded. Searched: Nevada data breach notification statute NRS 603A.

Category narrative73 words

Two sectoral overlays are confirmed for Nevada: (i) a financial-sector carve-out under SB 220, which excludes GLBA-regulated financial institutions and their affiliates/third parties from the 'operator' definition, and (ii) a dedicated health-sector overlay, SB 370, Nevada's consumer health data law modeled on Washington's My Health My Data Act, effective March 31, 2024, which also exempts HIPAA-regulated entities from SB 220's 'operator' definition. No Nevada-specific telecoms/ePrivacy, employment, credit-scoring, education, or insurance overlay was identified.

Sources and claims (3)
  1. ConfirmedInternational Association of Privacy ProfessionalsSB 220 amends the definition of 'operator' to exclude a third party that operates, hosts, or manages a website or online service on behalf of a financial institution, or its affiliates, subject to the Gramm-Leach-Bliley Act.observed
  2. ConfirmedInternational Association of Privacy ProfessionalsNevada's SB 370, a consumer health data privacy law modeled on Washington's My Health My Data Act, received final legislative passage and took effect March 31, 2024, and unlike the Washington law does not carry a private right of action.observed
  3. ConfirmedInternational Association of Privacy ProfessionalsSB 220 excludes from its 'operator' definition entities subject to the Health Insurance Portability and Accountability Act (HIPAA), avoiding duplicative obligations for HIPAA-regulated entities.observed

#

A narrow sale-opt-out and cross-context 'sale' definition exist; most other adtech sub-domains are unaddressed by Nevada statute.

Primary frameworkSB 220 (Nevada opt-out-of-sale statute)
Traffic-light rationale — AmberA narrow sale-opt-out and cross-context 'sale' definition exist; most other adtech sub-domains are unaddressed by Nevada statute.

Sub-modules (6)

Cookies And TrackersRed

No Nevada-specific cookie or tracker consent statute was identified.

Absence provenance: not recorded. Searched: Nevada SB 220 online sale opt-out privacy law 2019.

Dark PatternsRed

No Nevada-specific dark-pattern prohibition was identified.

Absence provenance: not recorded. Searched: Nevada SB 220 online sale opt-out privacy law 2019.

Opt Out SignalsAmber

SB 220 requires operators to establish a 'designated request address' (email, toll-free number, or website) for verified opt-out requests; whether Nevada law recognizes browser-based universal opt-out signals such as Global Privacy Control could not be confirmed.

Claims (1):

  • SB 220 requires operators to provide a 'designated request address' -- an email address, toll-free telephone number, or website -- for accepting verified opt-out requests, rather than mandating support for automated browser-based opt-out signals.

Clean Rooms And DcrRed

No Nevada-specific clean-room or data-collaboration-room rule was identified.

Absence provenance: not recorded. Searched: Nevada SB 220 online sale opt-out privacy law 2019.

Cross Context AdvertisingAmber

SB 220's definition of 'selling' is narrower than the CCPA's 'sale'/'share' constructs, meaning fewer cross-context advertising arrangements trigger the Nevada opt-out right compared to California.

Claims (1):

  • Nevada's SB 220 applies to any operator of online services, within or outside Nevada, but not offline, and its definition of 'selling' is more narrowly defined than under the CCPA.

Direct MarketingRed

No Nevada-specific direct-marketing consent or suppression statute beyond the general sale opt-out was identified.

Absence provenance: not recorded. Searched: Nevada SB 220 online sale opt-out privacy law 2019.

Category narrative47 words

Nevada's only adtech-relevant provision is SB 220's narrow opt-out-of-sale right, which uses a materially narrower definition of 'sale' than the CCPA/CPRA and requires a single 'designated request address' rather than recognizing browser-based universal opt-out signals. No cookie/tracker-consent statute, dark-pattern prohibition, clean-room rule, or direct-marketing-specific statute was identified.

Sources and claims (2)
  1. ConfirmedInternational Association of Privacy ProfessionalsNevada's SB 220 applies to any operator of online services, within or outside Nevada, but not offline, and its definition of 'selling' is more narrowly defined than under the CCPA.observed
  2. UncertainInternational Association of Privacy ProfessionalsSB 220 requires operators to provide a 'designated request address' -- an email address, toll-free telephone number, or website -- for accepting verified opt-out requests, rather than mandating support for automated browser-based opt-out signals.observed

#

Some emergent signals exist (SB 370 profiling exemption, proposed SB 199) but the regime is immature, partly proposed, and unconfirmed on biometric/genetic scope.

Primary frameworkSB 370; SB 199 (proposed, status unconfirmed)
Traffic-light rationale — AmberSome emergent signals exist (SB 370 profiling exemption, proposed SB 199) but the regime is immature, partly proposed, and unconfirmed on biometric/genetic scope.

Sub-modules (6)

Profiling RestrictionsAmber

SB 370, as amended before final Assembly passage, includes an exemption for profiling that does not involve personal health data, implicitly restricting health-data-based profiling.

Claims (1):

  • SB 370 was amended before final passage by the Nevada State Assembly to include an exemption for profiling that does not include personal health data.

Automated Decision Making TransparencyRed

No general ADM-transparency or explanation-right statute was identified for Nevada.

Absence provenance: not recorded. Searched: Nevada AI law 2025 artificial intelligence deepfake chatbot.

Ai Risk AssessmentsAmber

SB 199 (introduced February 2025) proposed AI-company registration and semi-annual self-assessment duties; whether it was enacted, amended, or died could not be confirmed.

Claims (1):

  • Nevada Senate Bill 199, introduced February 11, 2025, would require AI companies to register with the Bureau of Consumer Protection and conduct semi-annual self-assessments to ensure compliance with legal and ethical standards.

Biometric RegimeAmber

As of a 2019 interview, Nevada's then-Attorney General recommended the legislature add biometric data to the categories of personal information covered by the state's privacy/breach laws; whether this was subsequently enacted was not confirmed in this research pass.

Claims (1):

  • In a 2019 interview, Nevada's Attorney General recommended the state legislature follow other states in classifying biometric data (fingerprints, voice, retinal images) as 'personal information' protected under Nevada's privacy laws, implying biometric data was not then covered.

Genetic DataRed

No Nevada-specific genetic-data privacy statute (comparable to Nebraska's Genetic Information Privacy Act) was identified.

Absence provenance: not recorded. Searched: Nevada biometric privacy law facial recognition statute.

State Surveillance CarveoutsRed

No Nevada-specific state-surveillance carve-out or national-security exemption provision was identified.

Absence provenance: not recorded. Searched: Nevada data breach notification statute NRS 603A.

Category narrative78 words

Nevada has no general Article-22-style profiling/ADM transparency regime. SB 370 contains a narrow profiling exemption tied to non-health personal data, and a 2025 bill (SB 199) proposed AI-company registration and self-assessment duties but its final status is unconfirmed. Biometric data is not confirmed to be included within Nevada's breach-notification 'personal information' definition; a 2019 AG interview recommended such an expansion, but subsequent enactment was not verified in this pass. No Nevada-specific genetic-data statute or state-surveillance carve-out was identified.

Sources and claims (3)
  1. ConfirmedInternational Association of Privacy ProfessionalsSB 370 was amended before final passage by the Nevada State Assembly to include an exemption for profiling that does not include personal health data.observed
  2. UncertainDataGuidanceNevada Senate Bill 199, introduced February 11, 2025, would require AI companies to register with the Bureau of Consumer Protection and conduct semi-annual self-assessments to ensure compliance with legal and ethical standards.observed
  3. ProbableInternational Association of Privacy ProfessionalsIn a 2019 interview, Nevada's Attorney General recommended the state legislature follow other states in classifying biometric data (fingerprints, voice, retinal images) as 'personal information' protected under Nevada's privacy laws, implying biometric data was not then covered.observed

#

No Nevada-specific statutory protections for children or vulnerable groups were located; this is treated as a legitimate gap finding.

Traffic-light rationale — RedNo Nevada-specific statutory protections for children or vulnerable groups were located; this is treated as a legitimate gap finding.

Sub-modules (5)

Age VerificationRed

No Nevada-specific age-verification statute was identified.

Absence provenance: not recorded. Searched: Nevada AI law 2025 artificial intelligence deepfake chatbot.

Minor Profiling BansRed

No general minor-profiling ban was identified for Nevada.

Absence provenance: not recorded. Searched: Nevada SB 370 2021 privacy law amendment health data.

Education SettingsRed

No Nevada-specific education-settings data-privacy statute was identified.

Absence provenance: not recorded. Searched: Nevada data breach notification statute NRS 603A.

Dependent AdultsRed

No Nevada-specific dependent-adult data-protection provision was identified.

Absence provenance: not recorded. Searched: Nevada data breach notification statute NRS 603A.

Category narrative50 words

No Nevada-specific age-verification, parental-consent, minor-profiling-ban, education-settings, or dependent-adult data-protection statute was identified in this research pass. Protections for minors in Nevada currently derive from federal COPPA (out of scope for this NV-bound run) rather than state law; SB 370's profiling exemption (algorithmic module) is health-data-specific, not a general minors' protection.

#

Powers, penalties, and PRA status are well documented (green-level clarity); enforcement-activity index, funding/capacity, and Nevada-specific 180-day developments are largely absent.

Primary frameworkSB 220; SB 370; NRS Chapter 603A
Traffic-light rationale — AmberPowers, penalties, and PRA status are well documented (green-level clarity); enforcement-activity index, funding/capacity, and Nevada-specific 180-day developments are largely absent.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

The Nevada Attorney General may institute district-court proceedings for violations of SB 220/NRS 603A.340, seeking a temporary or permanent injunction or a civil penalty of up to $5,000 per violation.

Claims (1):

  • If the Nevada Attorney General believes an operator has violated NRS 603A.340 or SB 220, the Attorney General may institute legal proceedings in district court, which may issue a temporary or permanent injunction or impose a civil penalty of no more than $5,000 per violation.

Enforcement Activity IndexRed

No Nevada-specific public enforcement-activity index (comprehensive-privacy-law fines/decisions) was identified for the last 12 months; the AG's office describes investigating large-scale breaches but public disclosure of resulting actions is limited.

Claims (1):

  • The Nevada Attorney General's office conducts investigations, usually with company cooperation, when it receives notice of a data breach that may impact a large number of Nevadans, and may decide to take further action depending on the facts.

Regulator Funding And CapacityRed

No Nevada-specific data on Attorney General privacy-enforcement funding or headcount was identified.

Absence provenance: not recorded. Searched: Nevada attorney general data privacy enforcement action 2025 2026.

Collective Redress And Class ActionsAmber

Neither SB 220 nor SB 370 provides a private right of action; the Nevada Attorney General has sole responsibility for enforcement of SB 220.

Claims (1):

  • The Nevada Attorney General's office has sole responsibility for enforcement of SB 220, meaning consumers cannot independently bring collective or class actions for its violation.

Private Right Of ActionAmber

SB 370 explicitly does not carry a private right of action, unlike its Washington MHMDA model; enforcement of Nevada's privacy statutes is AG-exclusive.

Claims (1):

  • Unlike Washington's My Health My Data Act, Nevada's SB 370 does not carry a private right of action, leaving enforcement exclusively with the Attorney General.

Recent Developments 180DRed

No Nevada-specific legislative, judicial, or guidance development within the last 180 days (i.e., since approximately February 2026) was identified; Nevada was not listed among the 11-12 states with enacted chatbot-specific laws as of mid-2026, and SB 199's final status remains unconfirmed.

Absence provenance: not recorded. Searched: Nevada attorney general data privacy enforcement action 2025 2026, Nevada AI law 2025 artificial intelligence deepfake chatbot.

Category narrative92 words

The Nevada Attorney General holds exclusive enforcement authority across NRS 603A, SB 220, and SB 370, with civil penalties of up to $5,000 per violation and access to injunctive relief in district court. Neither SB 220 nor SB 370 provides a private right of action, so collective redress and individual court access for consumers depend entirely on AG enforcement or general consumer-protection theories. No Nevada-specific enforcement-activity index, regulator funding/headcount data, or 180-day recent development specific to Nevada privacy law was identified, though Nevada AG has joined multistate coalition activity on AI policy.

Sources and claims (4)
  1. ConfirmedInternational Association of Privacy ProfessionalsIf the Nevada Attorney General believes an operator has violated NRS 603A.340 or SB 220, the Attorney General may institute legal proceedings in district court, which may issue a temporary or permanent injunction or impose a civil penalty of no more than $5,000 per violation.observed
  2. UncertainInternational Association of Privacy ProfessionalsThe Nevada Attorney General's office conducts investigations, usually with company cooperation, when it receives notice of a data breach that may impact a large number of Nevadans, and may decide to take further action depending on the facts.observed
  3. ConfirmedInternational Association of Privacy ProfessionalsThe Nevada Attorney General's office has sole responsibility for enforcement of SB 220, meaning consumers cannot independently bring collective or class actions for its violation.observed
  4. ConfirmedInternational Association of Privacy ProfessionalsUnlike Washington's My Health My Data Act, Nevada's SB 370 does not carry a private right of action, leaving enforcement exclusively with the Attorney General.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United States – Nevada
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 24 claim(s), 18 source(s) in the cumulative register.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (37 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacytransfer mechanisms
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer impact assessment
Art. 77Enforcement & Redresscollective redress and class actions
Art. 78Enforcement & Redressregulator powers and penalties
Art. 79Enforcement & Redressregulator powers and penalties
Art. 80Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressprivate right of action
Art. 84Enforcement & Redressprivate right of action

Self-audit

regulator_and_framework, controller_processor_duties (breach_notification), sectoral_watch (financial/health overlays), and enforcement_and_redress (powers/penalties, PRA) rest on decent multi-source T2/T3 corroboration (IAPP + NAAG + DataGuidance) anchored to the seed's T1 regulator/statute references. data_subject_rights and lawful_processing_and_special_data are populated only where SB 220/SB 370 create narrow rights (opt-out, health-data consent), with the general DSR/lawful-basis bundle explicitly absent. cross_border_and_adequacy and children_and_vulnerable_groups returned no Nevada-specific findings at all and are carried as legitimate red/absent modules per gap discipline. algorithmic_biometric_and_surveillance_governance relies substantially on T3 secondary reporting and one unconfirmed proposed bill (SB 199) and one 2019-vintage AG interview (biometric_regime), both flagged Uncertain/Probable pending primary-source verification.

Unresolved questions (6):

  • Has Nevada Senate Bill 199 (AI company registration/self-assessment, introduced Feb. 11, 2025) been enacted, amended, or has it died in committee?
  • Does NRS 603A's breach-notification 'personal information' definition currently include biometric data, following the 2019 AG recommendation to add it?
  • What is the exact statutory text, resident-count threshold, and Attorney-General-notification trigger under NRS 603A.220 (breach notification), and does it include an encryption safe harbor?
  • What are the precise NRS section numbers into which SB 370 (consumer health data) was codified, and what is its full definition of 'consumer health data' and applicability thresholds?
  • Does Nevada law recognize or require support for browser-based universal opt-out signals (e.g., Global Privacy Control) under SB 220, or is the 'designated request address' the exclusive mechanism?
  • Has Nevada enacted any biometric-specific privacy statute (facial recognition, fingerprint, voiceprint) since the 2019 AG recommendation?

Escalate to primary-source review: yes