800.668.7020
M-F 8:00AM TO 5:30PM CST
Better coverage. Better price.

Nebraska Data Breach Laws: Rules and Penalties  

Nebraska businesses that suffer a data breach must call, email, or write the affected individuals as soon as possible. If the cost of notification is excessive, business owners can use substitute methods to fulfill this requirement (e.g., posting a notice on their website). Businesses that are already regulated by federal law, such as healthcare providers governed by HIPAA, are in compliance when they follow the federal guidelines. When a company fails to comply with notification regulations, the Nebraska attorney general has the right to issue subpoenas and seek monetary damages for each resident affected by a breach.

Name of Law / Statute

Financial Data Protection and Consumer Notification of Data Security Breach Act of 2006

Definition of Protected Information

Combination of (1) name or other identifying info, PLUS (2) one or more of these "data" elements: SSN; driver's license number; or account number, credit card number, debit card number if accompanied by PIN, password, or access codes PLUS unique biometric data (like fingerprints, retina scans, DNA profiles, or any other "unique physical representations")

Who Is Subject to Law?

Any person or business conducting business in the state who licenses or owns PI

Notification of Consumers?

Yes, but only if breaches "materially compromise the security, confidentiality, or integrity of" PI

By what means?

Written, phone, or electronic

Substitute Notice Threshold?

If cost of notice >$75,000 or involves >100k residents

Notification of authorities / regulators required?

No

By what means?

N/A

Regulatory Fines

No (civil action by AG)

Credit monitoring requirement?

No

Private lawsuits allowed?

No

Private damages cap?

N/A

Regulatory actions allowed?

Yes

HIPAA Compliance exemption?

N/A

Other  (e.g., timeframe)

Law does not apply if PI was encrypted or redacted

Link to complete law

Nebraska's Data Breach Law

Read the full text of Nebraska’s data breach law for more information.

70% of businesses raise prices or cut hiring when sued