← All jurisdictions
AZ · data breach notification
medArizona
Ariz. Rev. Stat. §18-551 et seq.
Individual deadline
45 days
Trigger standard
Risk of harm
AG / regulator
Required
| Notice to individuals | 45 calendar days from discovery |
| Risk-of-harm standard | notice unless breach not reasonably likely to result in substantial economic loss |
| Encryption safe harbor | Yes, encrypted data (key not compromised) generally exempt. |
| Regulator notice | Arizona Attorney General + AZ Dept. of Homeland Security, required above 1,000 residents; within 45 days Form prescribed by AG/DHS |
| Credit reporting agencies | Notify CRAs above 1,000 residents (Three largest nationwide CRAs). |
| Substitute notice | Typically available above $250,000 cost / 500,000 affected (verify). |
| Private right of action | No, enforcement by the state. |
| Penalties | AG civil penalty up to $500,000 per breach |
| Notable PI definitions | Includes biometric, credentials. |
Rule last verified July 10, 2026 · confidence med. This is a reference summary, not legal advice; verify against the current statute. How we compile this →
Is a Arizona breach part of a multi-state incident?
See every jurisdiction at once, with letters and filing packets generated.
Run the calculator →