How long do I have to notify Nebraska residents after a data breach?
As soon as possible and without unreasonable delay
Do I have to notify the Nebraska Attorney General?
Yes — written notice to the AG no later than the time individuals are notified
Does Nebraska require notification to nationwide consumer reporting agencies?
Yes — if more than 1,000 residents, notify nationwide CRAs
Is encrypted data exempt from Nebraska's breach notification requirement?
Yes — Nebraska has an encryption safe harbor. Breaches of properly encrypted personal information generally do not trigger notification, provided the encryption key was not also compromised.
Can Nebraska residents sue me directly for a data breach?
No — Nebraska's breach statute does not provide a direct private right of action. Residents typically must rely on the AG to enforce, or pursue common-law negligence claims.
What counts as 'personal information' under Nebraska law?
First name/initial + last name with SSN, DL/state ID, financial account + access code, unique electronic identifier + password, biometric data
What are the penalties for failing to comply with Nebraska's breach notification law?
Enforcement under Nebraska Consumer Protection Act — civil penalty up to $2,000 per violation