Financial Data Protection and Consumer Notification of Data Security Breach Act of 2006
Nebraska Data Breach Notification and Data Security Act
Breach notification · Data security · Biometric
Nebraska's breach law requires businesses and government entities that own or license computerized personal information to investigate a breach promptly and, if misuse has occurred or is reasonably likely, to notify affected residents and the Attorney General. Since 2018 it also requires reasonable security procedures, including for disposal, and contracts requiring vendors to safeguard the data. Notice to the Attorney General and the username/email-and-password element were added by LB835, effective July 21, 2016.
- Where
- Nebraska
- Citation
- Neb. Rev. Stat. 87-801 to 87-808
- Status
- In force
- In force since
- 2006-07-14
- Last amended
- 2018-07-19
- Enforced by
- Nebraska Attorney General
- People can sue
- No
- Penalties
- The Attorney General may issue subpoenas and recover direct economic damages for each injured Nebraska resident for notice violations (87-806(1)). A violation of the security requirement in 87-808 is an unfair or deceptive practice under the Consumer Protection Act (59-1602) but gives no private cause of action (87-806(2)).
- Applies to
- Individuals and commercial entities (including governments, agencies, and nonprofits) that conduct business in Nebraska and own or license computerized data containing personal information of Nebraska residents (87-802(2), 87-803(1))
- Entities that maintain such data for an owner or licensee (87-803(3))
- Personal information: name plus SSN, driver's license or state ID number, financial account or card number with access code, unique electronic ID or routing code with access code, or unique biometric data; or a username or email address with password or security question and answer (87-802(5))
What a privacy notice must say
- Notice may be written, telephonic, or electronic (E-SIGN compliant); substitute notice (email, website posting, statewide media) is allowed if cost exceeds $75,000, more than 100,000 residents are affected, or contact information is insufficient, with a separate option for entities with 10 or fewer employees.Neb. Rev. Stat. 87-802(4)
Security duties
- Implement and maintain reasonable security procedures and practices appropriate to the information and the business, including safeguards when disposing of personal information.Neb. Rev. Stat. 87-808(1) · From 2018-07-19
- Require by contract that nonaffiliated third-party service providers receiving personal information maintain reasonable security procedures (contracts entered or renewed on or after July 19, 2018).Neb. Rev. Stat. 87-808(2) · From 2018-07-19
Breach duties
- On becoming aware of a breach, conduct a good-faith, reasonable, and prompt investigation of the likelihood that personal information has been or will be misused.Neb. Rev. Stat. 87-803(1)
- Notify affected Nebraska residents as soon as possible and without unreasonable delay if misuse has occurred or is reasonably likely to occur.Neb. Rev. Stat. 87-803(1) · Only if: Risk-of-harm trigger: unauthorized use occurred or is reasonably likely
- Notify the Attorney General no later than the time residents are notified. The Attorney General's Consumer Protection Division provides a notification form that asks for the manner of notice, a sample notice letter, and any reason for delay.Neb. Rev. Stat. 87-803(2)
- An entity maintaining data it does not own or license must notify and cooperate with the owner or licensee, including sharing relevant breach information.Neb. Rev. Stat. 87-803(3)
- Notice may be delayed while a law enforcement agency determines it would impede a criminal investigation.Neb. Rev. Stat. 87-803(4)
Other duties
- Entities that follow their own consistent notice procedures, or procedures required by their primary state or federal regulator, are deemed compliant if they notify residents and the Attorney General; compliance with GLBA or HIPAA rules satisfies the security duties.Neb. Rev. Stat. 87-804; 87-808(3)
Sources
- Official text
- Neb. Rev. Stat. 87-801 to 87-808 (Nebraska Legislature)
- Neb. Rev. Stat. 87-802 definitions (Nebraska Legislature)
- Neb. Rev. Stat. 87-808 security procedures (Nebraska Legislature)
- Revisor cross-reference table of effective dates, 2018 session (LB757: July 19, 2018)
- Nebraska Attorney General, Data Breach Notification Form (Consumer Protection Division)
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Unverified: The Attorney General's breach form cites 'Neb. Rev. Stat. 87-303(2)', an apparent typo for 87-803(2).
Research reference, not legal advice.