🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
US-AK v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing15 sources retrieved model claude-sonnet-5 · 2026-08-05

Alaska, USA

US-AK schema gdpri-v2 trajectory: not yet assessedregulated (sectoral)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 20 claims · 22 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
20Claimsbaseline..claims[]
8Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

Alaska remains without a comprehensive consumer-privacy statute, but this cycle brings the clearest sign yet of legislative momentum toward one: HB 367, the Consumer Personal Information Privacy Act, is understood to have advanced to the House Finance Committee, having been referred to committee on February 23, 2026, and having since picked up a duty-of-loyalty amendment modeled on Utah law. As introduced, HB 367 would grant Alaska residents rights to know, disclose, and delete personal information, and to opt out of its sale, would impose a data-broker registration requirement, and would apply to businesses meeting a 100,000-consumer coverage threshold. The bill remains pending, not enacted, as of the most recent record reviewed this cycle, dated 2026-05-12.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

A functioning breach-notification/PII-protection statute and an insurance-sector security law exist and are enforced by the AG and Division of Insurance, but there is no omnibus privacy statute, no dedicated DPA, and no general registration/filing regime.

Primary frameworkAlaska Personal Information Protection Act, AS 45.48.010 et seq.
Supervisory authorityOffice of the Attorney General, State of Alaska (Consumer Protection Unit)
Traffic-light rationale — AmberA functioning breach-notification/PII-protection statute and an insurance-sector security law exist and are enforced by the AG and Division of Insurance, but there is no omnibus privacy statute, no dedicated DPA, and no general registration/filing regime.

Sub-modules (5)

Regulator And AuthorityAmber

The Alaska AG enforces APIPA and is a Consumer Sentinel Network data contributor; the Division of Insurance enforces the Insurance Data Security Act.

Claims (2):

  • The Alaska Attorney General's office is the enforcing authority for the Alaska Personal Information Protection Act (breach notification, SSN protection, disposal, credit freeze).
  • The Alaska Attorney General is a listed data contributor to the FTC's Consumer Sentinel Network, evidencing its consumer-protection enforcement role relevant to data-privacy complaints.

Act And InstrumentsAmber

Core instruments are AS 45.48 (PIPA/breach notification) and the 2024 Insurance Data Security Act (SB134); no omnibus consumer privacy act exists.

Claims (2):

  • The Personal Information Protection Act under AS 45.48.010 et seq. of Chapter 47 of Title 45 of the Alaska Statutes was signed into law and entered into force on July 1, 2009.
  • Alaska enacted an Insurance Data Security Act (SB134) which became law without the Governor's signature, imposing data security standards on insurance licensees.

Material ScopeAmber

Material scope is limited to statutorily defined 'personal information' for breach/disposal/SSN purposes; it does not extend to general 'processing' of personal data as GDPR-style regimes do.

Claims (1):

  • APIPA's protections are structured around specific categories -- Social Security numbers, credit/financial account information, and records requiring disposal -- rather than a broad definition of 'processing' of personal data.

Territorial ScopeAmber

APIPA applies extraterritorially to any entity that owns, licenses, or maintains personal information of Alaska residents, mirroring the standard US state breach-law approach.

Claims (1):

  • Alaska's breach-notification and SSN-protection obligations apply to any business or government entity holding personal information of Alaska residents, regardless of the entity's state of establishment.

Regulator Registration And FilingRed

No general controller/processor registration or filing regime exists at state level; the Insurance Data Security Act introduces sector-specific security-program obligations to the Division of Insurance for licensees only.

Absence provenance: unavailable. Searched: Alaska data controller registration requirement, Alaska DPA filing obligation.

Claims (1):

  • No general data-controller or processor registration/filing regime applies in Alaska outside of insurance-sector security-program obligations under the new Insurance Data Security Act.
Category narrative91 words

Alaska has no dedicated data-protection authority. The Alaska Attorney General's Consumer Protection Unit enforces the state's breach-notification and information-security statutes (Personal Information Protection Act, AS 45.48) and is a recognized contributor to the FTC's Consumer Sentinel Network. A second sectoral regulator, the Alaska Division of Insurance, administers the newly enacted Insurance Data Security Act (2024 SB134). Repeated attempts to enact a comprehensive consumer data privacy statute (SB116, HB159, HB222) have failed to pass the legislature, so the material and territorial scope of Alaska's regime is narrower and sector/breach-specific rather than omnibus.

Sources and claims (7)
  1. ProbableFederal Trade Commission / Alaska Dept. of Law — The Alaska Attorney General's office is the enforcing authority for the Alaska Personal Information Protection Act (breach notification, SSN protection, disposal, credit freeze).observed
  2. ConfirmedFederal Trade Commission — The Alaska Attorney General is a listed data contributor to the FTC's Consumer Sentinel Network, evidencing its consumer-protection enforcement role relevant to data-privacy complaints.observed
  3. ProbableOneTrust DataGuidance — The Personal Information Protection Act under AS 45.48.010 et seq. of Chapter 47 of Title 45 of the Alaska Statutes was signed into law and entered into force on July 1, 2009.observed
  4. ProbableOneTrust DataGuidance — Alaska enacted an Insurance Data Security Act (SB134) which became law without the Governor's signature, imposing data security standards on insurance licensees.observed
  5. ProbableOneTrust DataGuidance — APIPA's protections are structured around specific categories -- Social Security numbers, credit/financial account information, and records requiring disposal -- rather than a broad definition of 'processing' of personal data.observed
  6. ProbableFederal Trade Commission / Alaska Dept. of Law — Alaska's breach-notification and SSN-protection obligations apply to any business or government entity holding personal information of Alaska residents, regardless of the entity's state of establishment.observed
  7. UncertainOneTrust DataGuidance — No general data-controller or processor registration/filing regime applies in Alaska outside of insurance-sector security-program obligations under the new Insurance Data Security Act.observed

#

No state-level lawful-basis, consent, sensitive-data, or anonymisation framework exists; reliance is entirely on federal sectoral law.

Traffic-light rationale — Not assessedNo state-level lawful-basis, consent, sensitive-data, or anonymisation framework exists; reliance is entirely on federal sectoral law.

Sub-modules (4)

Lawful BasesRed

No Alaska statute enumerates lawful bases for processing personal data akin to GDPR Art 6.

Absence provenance: unavailable. Searched: Alaska lawful basis for processing personal data, Alaska Consumer Data Privacy Act SB116 HB159.

Special CategoriesRed

No Alaska statute defines a general category of 'sensitive' or 'special category' personal data; sensitive-data protections arise only via federal HIPAA/GINA overlays.

Absence provenance: unavailable. Searched: Alaska sensitive data statute, Alaska genetic privacy act.

Pseudonymisation And AnonymisationRed

No Alaska statutory definition of pseudonymisation or anonymisation, nor an associated safe harbour, was located.

Absence provenance: unavailable. Searched: Alaska anonymisation safe harbor statute.

Category narrative42 words

Alaska has no GDPR-style enumerated lawful-basis regime, no general consent standard for commercial data processing, and no statutory definition of 'special category'/sensitive data outside of federal sectoral overlays (HIPAA for health, GINA for genetic-employment discrimination). No state pseudonymisation/anonymisation safe-harbour framework was identified.

#

No omnibus subject-rights framework exists at state level; only breach-notification receipt and credit-freeze rights are state-conferred.

Primary frameworkAlaska Personal Information Protection Act, AS 45.48.010 et seq.
Supervisory authorityOffice of the Attorney General, State of Alaska
Traffic-light rationale — RedNo omnibus subject-rights framework exists at state level; only breach-notification receipt and credit-freeze rights are state-conferred.

Sub-modules (5)

Access RightRed

No general state-law access right to personal data exists; federal FCRA/HIPAA access rights apply only in their respective sectors.

Absence provenance: unavailable. Searched: Alaska right to access personal data statute.

Rectification And ErasureRed

No Alaska statutory right to rectify or erase personal data held by private businesses.

Absence provenance: unavailable. Searched: Alaska right to erasure statute.

Restriction And ObjectionRed

No Alaska statutory restriction/objection right (including profiling opt-out) exists.

Absence provenance: unavailable. Searched: Alaska right to object profiling.

Data PortabilityRed

No Alaska data-portability right exists.

Absence provenance: unavailable. Searched: Alaska data portability right.

Deadlines And Response WindowsAmber

The only statutory response-window concept is the breach-notification timing obligation under APIPA, requiring notification without unreasonable delay following discovery of a breach.

Claims (1):

  • Alaska's Personal Information Protection Act requires businesses to notify the Attorney General, affected subscribers, and, where applicable, a credit reporting agency in the event of a breach of security concerning personal information.
Category narrative67 words

Alaska law does not grant a general access, rectification, erasure, restriction, objection, or portability right over personal data held by private-sector businesses. The only individual-facing rights under state law are breach-notification receipt, the ability to place/lift a security freeze on a credit report, and disposal obligations on holders of personal information; substantive access/correction rights exist only via federal sectoral law (e.g., FCRA file-disclosure rights, HIPAA access rights).

no periodic updates on record for this sub-brief

Sources and claims (1)
  1. ProbableOneTrust DataGuidance — Alaska's Personal Information Protection Act requires businesses to notify the Attorney General, affected subscribers, and, where applicable, a credit reporting agency in the event of a breach of security concerning personal information.observed

#

Concrete, enforceable security and breach-notification/disposal duties exist for general businesses (APIPA) and insurance licensees (SB134), but accountability-style obligations (DPIA, DPO, ROPA, joint-controller) are entirely absent.

Primary frameworkAlaska Personal Information Protection Act (AS 45.48) and Alaska Insurance Data Security Act (SB134, 2024)
Supervisory authorityOffice of the Attorney General, State of Alaska
Traffic-light rationale — AmberConcrete, enforceable security and breach-notification/disposal duties exist for general businesses (APIPA) and insurance licensees (SB134), but accountability-style obligations (DPIA, DPO, ROPA, joint-controller) are entirely absent.

Sub-modules (7)

Accountability And DpiaRed

No DPIA or general accountability-principle obligation exists in Alaska statute.

Absence provenance: unavailable. Searched: Alaska DPIA requirement, Alaska privacy impact assessment statute.

Dpo RequirementsRed

No DPO appointment requirement exists under Alaska law.

Absence provenance: unavailable. Searched: Alaska data protection officer requirement.

Ropa RequirementsRed

No records-of-processing obligation exists under Alaska law.

Absence provenance: unavailable. Searched: Alaska records of processing activities requirement.

Joint Controller ArrangementsRed

No statutory joint-controller framework exists in Alaska.

Absence provenance: unavailable. Searched: Alaska joint controller statute.

Security MeasuresAmber

The Insurance Data Security Act requires insurance licensees to implement an information security program; APIPA separately requires reasonable safeguards implicit in its breach and disposal duties.

Claims (1):

  • Alaska's Insurance Data Security Act (SB134) sets data security standards for insurance licensees, mandating implementation of an information security program.

Breach NotificationAmber

APIPA requires notification to the Alaska AG, affected residents, and (where thresholds are met) consumer reporting agencies following a security breach involving personal information.

Claims (1):

  • The Alaska Personal Information Protection Act requires notification to the Alaska Attorney General, subscribers, and (if applicable) a credit reporting agency in the event of a breach of security concerning personal information.

Retention And DisposalAmber

APIPA requires proper disposal of records containing personal information and truncation of credit card information in records.

Claims (1):

  • Alaska's Personal Information Protection Act mandates the disposal of records containing personal information and truncation of credit card information.
Category narrative56 words

Alaska imposes two concrete controller-side duties: (1) breach notification and secure disposal of records containing personal information under APIPA, AS 45.48; and (2) an information-security-program mandate on insurance licensees under the 2024 Insurance Data Security Act (SB134), modeled on the NAIC data security model law. No DPIA, DPO, ROPA, or joint-controller framework exists at state level.

Sources and claims (3)
  1. ProbableOneTrust DataGuidance — Alaska's Insurance Data Security Act (SB134) sets data security standards for insurance licensees, mandating implementation of an information security program.observed
  2. ProbableOneTrust DataGuidance — The Alaska Personal Information Protection Act requires notification to the Alaska Attorney General, subscribers, and (if applicable) a credit reporting agency in the event of a breach of security concerning personal information.observed
  3. ProbableOneTrust DataGuidance — Alaska's Personal Information Protection Act mandates the disposal of records containing personal information and truncation of credit card information.observed

#

No state cross-border transfer regime exists; this module is structurally inapplicable to a US sectoral-only state absent an omnibus statute.

Traffic-light rationale — Not assessedNo state cross-border transfer regime exists; this module is structurally inapplicable to a US sectoral-only state absent an omnibus statute.

Sub-modules (6)

Transfer MechanismsRed

No Alaska-specific transfer mechanism exists.

Absence provenance: unavailable. Searched: Alaska cross border data transfer law.

Adequacy ReceivedRed

Not applicable; adequacy determinations are a federal/international concept, not exercised by individual US states.

Absence provenance: unavailable. Searched: Alaska adequacy decision.

Adequacy GrantedRed

Not applicable for the same reason.

Absence provenance: unavailable. Searched: Alaska adequacy granted.

Sccs And BcrsRed

No Alaska SCC/BCR framework exists.

Absence provenance: unavailable. Searched: Alaska standard contractual clauses requirement.

Transfer Impact AssessmentRed

No TIA requirement exists under Alaska law.

Absence provenance: unavailable. Searched: Alaska transfer impact assessment requirement.

Data LocalisationRed

No Alaska data-localisation mandate was identified.

Absence provenance: unavailable. Searched: Alaska data localisation requirement.

Category narrative54 words

As a US state without an omnibus privacy statute, Alaska has no state-level cross-border transfer mechanism, adequacy regime, SCC/BCR framework, transfer-impact-assessment requirement, or data-localisation mandate. Any cross-border constraints affecting Alaska-based data flows derive solely from federal sectoral law (e.g., GLBA safeguards for financial data, HIPAA for health data) rather than a state-specific transfer regime.

#

A concrete, enacted insurance-sector data-security law exists and is material, but most other sectors rely entirely on federal sectoral law with no Alaska-specific overlay.

Primary frameworkAlaska Insurance Data Security Act (SB134, 2024); federal GLBA/HIPAA/FCRA
Supervisory authorityAlaska Division of Insurance
Traffic-light rationale — AmberA concrete, enacted insurance-sector data-security law exists and is material, but most other sectors rely entirely on federal sectoral law with no Alaska-specific overlay.

Sub-modules (7)

Financial Sector OverlayAmber

Financial-sector personal data in Alaska is governed by the federal GLBA Safeguards Rule; no Alaska-specific banking-privacy overlay was identified.

Claims (1):

  • Financial institutions operating in Alaska are subject to the federal Gramm-Leach-Bliley Act's Safeguards Rule for protection of nonpublic personal financial information, in the absence of an Alaska-specific banking privacy statute.

Health Sector OverlayAmber

Health data is governed by federal HIPAA/HITECH; no comprehensive Alaska-specific health-privacy statute beyond HIPAA was identified in this pass.

Claims (1):

  • Health information held by covered entities operating in Alaska is subject to the federal HIPAA Privacy and Security Rules in the absence of an Alaska-specific comprehensive health-privacy statute.

Telecoms And EprivacyRed

No Alaska ePrivacy/cookie-consent statute exists; federal ECPA/TCPA govern telecoms privacy.

Absence provenance: unavailable. Searched: Alaska ePrivacy law, Alaska telecoms privacy statute.

Employment DataRed

No comprehensive Alaska employment-data-privacy statute was identified.

Absence provenance: unavailable. Searched: Alaska employee data privacy law.

Credit And ScoringAmber

Federal FCRA governs credit reporting; Alaska's APIPA supplements this with a statutory right to place a security freeze on a consumer credit report.

Claims (1):

  • Alaska's Personal Information Protection Act provides consumers the ability to place a security freeze on a consumer credit report, supplementing federal FCRA protections.

EducationRed

Federal FERPA/COPPA/PPRA govern student data; no Alaska-specific comprehensive student-data-privacy statute (akin to California's SOPIPA) was identified in this research pass.

Absence provenance: unavailable. Searched: Alaska student data privacy law, Alaska SOPIPA equivalent.

InsuranceGreen

Alaska enacted an Insurance Data Security Act (SB134) in 2024, becoming law without the Governor's signature, imposing NAIC-model-law-style data security standards on insurance licensees.

Claims (1):

  • Alaska's Senate Bill 134 sets data security standards for insurance licensees and became law without the Governor's approval.
Category narrative76 words

Alaska's data-protection landscape is almost entirely sectoral. Financial-sector data is governed by the federal Gramm-Leach-Bliley Act safeguards rule; health data by HIPAA/HITECH; credit/scoring by the federal Fair Credit Reporting Act supplemented by Alaska's security-freeze provisions under APIPA; and insurance-sector cybersecurity by Alaska's newly enacted Insurance Data Security Act (SB134, 2024), which is the most significant Alaska-specific sectoral development. No Alaska-specific telecoms/ePrivacy, employment-data, or comprehensive education-sector privacy statute was identified in this pass beyond federal FERPA/COPPA/PPRA baselines.

Periodic update · new data 2026-09-28

Sectoral Watch

A sectoral development adjacent to, but analytically distinct from, Alaskas data-protection framework surfaced this cycle in the states financial-services sector. Alaska SB 86, the money-transmission modernization law, is understood to impose new disclosure duties on virtual-currency licensees, covering fees, insurance coverage, transaction risks, error resolution, and account changes. This is a financial-services consumer-disclosure requirement, not a data-protection instrument, and it does not create or amend any personal-information-handling obligation of the kind this monitor otherwise tracks.

The reason this development is noted here at all is that it touches the same category of commercial actor, virtual-currency and money-transmission businesses operating in Alaska, that a future comprehensive privacy statute, were HB 367 or a successor bill to be enacted, would also reach. At present, however, there is no overlap in substantive obligation: SB 86s disclosure duties are financial-product-risk disclosures directed at customers of virtual-currency services, while HB 367, still pending, would separately govern the collection, use, and sale of personal information more broadly and across sectors.

No other sectoral development specific to data protection was identified for Alaska this cycle. The states approach to data protection remains sector-agnostic in the sense that it has no dedicated sectoral privacy statutes beyond the general breach-notification requirement; the SB 86 development is best understood as a financial-regulation development with incidental relevance to this monitors watch list, not as a sectoral privacy rule in its own right.

Outlook

This item will continue to be tracked as a watch-list entry rather than a core data-protection finding, given its adjacent but non-overlapping subject matter. Should SB 86s disclosure regime or a future amendment extend into personal-information-handling territory beyond financial-product-risk disclosure, or should HB 367 or a successor privacy bill advance further, the analytical boundary between these two regimes would warrant renewed attention. For now, readers seeking substantive analysis of SB 86 itself should consult the crypto and world-payments monitors, where that statute is the primary subject.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (4)
  1. ConfirmedFederal Trade Commission — Financial institutions operating in Alaska are subject to the federal Gramm-Leach-Bliley Act's Safeguards Rule for protection of nonpublic personal financial information, in the absence of an Alaska-specific banking privacy statute.observed
  2. ConfirmedHHS OCR — Health information held by covered entities operating in Alaska is subject to the federal HIPAA Privacy and Security Rules in the absence of an Alaska-specific comprehensive health-privacy statute.observed
  3. ProbableOneTrust DataGuidance — Alaska's Personal Information Protection Act provides consumers the ability to place a security freeze on a consumer credit report, supplementing federal FCRA protections.observed
  4. ProbableOneTrust DataGuidance — Alaska's Senate Bill 134 sets data security standards for insurance licensees and became law without the Governor's approval.observed

#

This entire module is unregulated at the state level in Alaska; only generic federal FTC Act unfairness/deception authority and federal telemarketing/email statutes apply.

Traffic-light rationale — Not assessedThis entire module is unregulated at the state level in Alaska; only generic federal FTC Act unfairness/deception authority and federal telemarketing/email statutes apply.

Sub-modules (6)

Cookies And TrackersRed

No Alaska cookie-consent statute exists.

Absence provenance: unavailable. Searched: Alaska cookie consent law.

Dark PatternsRed

No Alaska-specific dark-patterns prohibition exists; only generic federal FTC Act unfairness/deception authority applies.

Absence provenance: unavailable. Searched: Alaska dark patterns statute.

Opt Out SignalsRed

No Alaska statute recognizes Global Privacy Control or similar opt-out signals.

Absence provenance: unavailable. Searched: Alaska Global Privacy Control recognition.

Clean Rooms And DcrRed

No Alaska regulation of data clean rooms/collaboration rooms exists.

Absence provenance: unavailable. Searched: Alaska data clean room regulation.

Cross Context AdvertisingRed

No CPRA-style 'sale'/'share' restriction on cross-context advertising exists under Alaska law.

Absence provenance: unavailable. Searched: Alaska sale of personal information restriction advertising.

Direct MarketingRed

Direct marketing in Alaska is governed only by federal TCPA/CAN-SPAM baselines; no Alaska-specific consent/suppression statute for direct marketing was identified.

Absence provenance: unavailable. Searched: Alaska direct marketing consent statute, Alaska do not call telemarketing statute.

Category narrative43 words

Alaska has no cookie/tracker consent statute, no dark-patterns prohibition, no opt-out-signal mandate (e.g., GPC recognition), no clean-room regulation, and no CPRA-style 'sale'/'share' restriction on cross-context advertising. Direct marketing is governed only by federal TCPA/CAN-SPAM; no Alaska-specific direct-marketing consent or suppression statute was identified.

#

No AI, ADM, biometric, or genetic-data statute exists in Alaska; the only relevant state-law hook is the general constitutional privacy clause, which does not provide AI/biometric-specific governance.

Primary frameworkConstitution of the State of Alaska, Article I, Section 22 (general right of privacy; not AI/biometric-specific)
Traffic-light rationale — RedNo AI, ADM, biometric, or genetic-data statute exists in Alaska; the only relevant state-law hook is the general constitutional privacy clause, which does not provide AI/biometric-specific governance.

Sub-modules (6)

Profiling RestrictionsRed

No Alaska profiling-restriction statute exists.

Absence provenance: unavailable. Searched: Alaska profiling restriction statute.

Automated Decision Making TransparencyRed

No Alaska ADM-transparency or explanation-right statute exists.

Absence provenance: unavailable. Searched: Alaska automated decision-making transparency law.

Ai Risk AssessmentsRed

No Alaska AI-specific risk-assessment statute exists.

Absence provenance: unavailable. Searched: Alaska AI risk assessment law 2026.

Biometric RegimeRed

No dedicated Alaska biometric-data statute (comparable to Illinois BIPA) was identified.

Absence provenance: unavailable. Searched: Alaska biometric privacy statute, Alaska BIPA equivalent.

Genetic DataRed

No dedicated Alaska genetic-data-privacy statute was identified in this research pass.

Absence provenance: unavailable. Searched: Alaska genetic privacy law, Alaska genetic information nondiscrimination statute.

State Surveillance CarveoutsAmber

Alaska's Constitution contains an explicit right-to-privacy clause (Article I, Section 22) that has informed state constitutional privacy jurisprudence, though national-security/law-enforcement carveouts follow federal law.

Claims (1):

  • The Constitution of the State of Alaska, Article I, Section 22, contains an explicit textual right to privacy, distinguishing Alaska from the majority of US states that lack such an express constitutional privacy clause.
Category narrative74 words

Alaska has no profiling-restriction statute, no ADM-transparency/explanation right, no AI-specific risk-assessment law, and no dedicated biometric-privacy statute (i.e., no Illinois-BIPA equivalent) or genetic-data statute located in this research pass. Alaska's Constitution, Article I, Section 22, contains an explicit textual right to privacy that has been a basis for state constitutional privacy litigation, which is the closest state-law analogue to a general privacy protection in this space, though it is not itself an AI/biometric-specific statute.

Sources and claims (1)
  1. ProbableState of Alaska — The Constitution of the State of Alaska, Article I, Section 22, contains an explicit textual right to privacy, distinguishing Alaska from the majority of US states that lack such an express constitutional privacy clause.observed

#

No Alaska-specific children's or vulnerable-groups data statute exists beyond the state's participation as a commenting/enforcing party in federal COPPA rulemaking.

Primary frameworkChildren's Online Privacy Protection Act (COPPA); FERPA; PPRA (all federal)
Supervisory authorityFederal Trade Commission (COPPA); Alaska Attorney General (state enforcement coordination)
Traffic-light rationale — RedNo Alaska-specific children's or vulnerable-groups data statute exists beyond the state's participation as a commenting/enforcing party in federal COPPA rulemaking.

Sub-modules (5)

Age VerificationRed

No Alaska-specific age-verification statute exists; COPPA's federal age-13 threshold governs.

Claims (1):

  • The Alaska Attorney General was among the state attorneys general who submitted comments to the FTC's 2024 COPPA Rule review, reflecting Alaska's participation in federal children's-privacy rulemaking rather than a separate state age-verification regime.

Minor Profiling BansRed

No Alaska minor-profiling-ban statute exists.

Absence provenance: unavailable. Searched: Alaska minor profiling ban.

Education SettingsRed

Education-sector privacy is governed federally by FERPA/PPRA; no Alaska-specific student-data-privacy statute was identified.

Absence provenance: unavailable. Searched: Alaska student data privacy statute.

Dependent AdultsRed

No Alaska data-privacy-specific statute for dependent/vulnerable adults was identified; general adult-protective-services statutes address abuse/exploitation but not data privacy specifically.

Absence provenance: unavailable. Searched: Alaska dependent adult data privacy statute.

Category narrative55 words

Children's data privacy in Alaska is governed entirely by federal law: COPPA for children under 13 (enforced by the FTC and, per COPPA rulemaking comment records, jointly monitored by state AGs including Alaska's), and FERPA/PPRA for education records. No Alaska-specific age-verification, parental-consent supplement, minor-profiling ban, or dependent-adults data-privacy statute was identified in this research pass.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (1)
  1. ConfirmedFederal Trade Commission — The Alaska Attorney General was among the state attorneys general who submitted comments to the FTC's 2024 COPPA Rule review, reflecting Alaska's participation in federal children's-privacy rulemaking rather than a separate state age-verification regime.observed

#

AG enforcement capacity and multistate settlement participation are confirmed, but private-right-of-action, regulator funding/capacity, and 180-day developments are unconfirmed or negative findings.

Primary frameworkAlaska Personal Information Protection Act (AS 45.48); general Alaska Unfair Trade Practices and Consumer Protection Act
Supervisory authorityOffice of the Attorney General, State of Alaska
Traffic-light rationale — AmberAG enforcement capacity and multistate settlement participation are confirmed, but private-right-of-action, regulator funding/capacity, and 180-day developments are unconfirmed or negative findings.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

APIPA sets out penalties for violations of its business obligations, enforced by the Alaska Attorney General; exact statutory penalty figures were not independently re-verified this session.

Claims (1):

  • Alaska's Personal Information Protection Act sets out penalties for violations of the business obligations it imposes, enforceable by the Alaska Attorney General.

Enforcement Activity IndexAmber

Alaska's AG has participated in multistate breach-related settlements, including a $5M multistate settlement with Community Health Systems and a $39.5M multistate settlement with Anthem, both arising from healthcare data breaches.

Claims (2):

  • 27 state attorneys general, including Alaska, announced a $5 million settlement with Community Health Systems following a data breach affecting 6.1 million patients.
  • Anthem settled for $39.5 million with 43 state attorneys general, including Alaska, over a 2014 data breach affecting 78.8 million customers.

Regulator Funding And CapacityRed

No specific data on Alaska AG Consumer Protection Unit staffing or budget dedicated to privacy enforcement was located in this research pass.

Absence provenance: unavailable. Searched: Alaska Attorney General consumer protection unit budget staffing.

Collective Redress And Class ActionsRed

No Alaska-specific class-action mechanism dedicated to data-privacy claims beyond general Alaska civil procedure was identified.

Absence provenance: unavailable. Searched: Alaska class action data privacy mechanism.

Private Right Of ActionRed

No confirmed private right of action under APIPA was located; enforcement appears centered on the Attorney General.

Absence provenance: unavailable. Searched: Alaska Personal Information Protection Act private right of action.

Recent Developments 180DRed

No Alaska-specific data-privacy legislative or enforcement development within the last 180 days (i.e., since approximately February 2026) was identified; the most recent substantive development remains the 2024 enactment of the Insurance Data Security Act and continued failure of comprehensive consumer privacy bills.

Absence provenance: unavailable. Searched: Alaska data privacy law 2026, Alaska consumer data privacy act status legislature, Alaska HB 222 consumer data protection 2025 2026.

Category narrative84 words

Enforcement in Alaska is centered on the Attorney General's Consumer Protection Unit, which can bring actions under APIPA and participates in multistate data-breach settlements (e.g., the multistate Community Health Systems and Anthem settlements). No dedicated private right of action under APIPA was confirmed in this research pass, and no Alaska-specific class-action mechanism beyond general Alaska civil procedure was identified. No legislative or enforcement developments specific to Alaska data privacy were identified within the last 180 days beyond the continuing failure of comprehensive privacy bills.

no periodic updates on record for this sub-brief

Sources and claims (3)
  1. ProbableOneTrust DataGuidance — Alaska's Personal Information Protection Act sets out penalties for violations of the business obligations it imposes, enforceable by the Alaska Attorney General.observed
  2. ProbableOneTrust DataGuidance — 27 state attorneys general, including Alaska, announced a $5 million settlement with Community Health Systems following a data breach affecting 6.1 million patients.observed
  3. ProbableOneTrust DataGuidance — Anthem settled for $39.5 million with 43 state attorneys general, including Alaska, over a 2014 data breach affecting 78.8 million customers.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct53.33
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Alaska, USA
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 20 claim(s) (20 category placement(s)), 22 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redresscollective redress and class actions
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

Regulator_and_framework, controller_processor_duties (breach/disposal/security), and sectoral_watch (insurance) achieved T2-level coverage (an FTC-hosted Alaska AG presentation plus enactment-tracking secondary sources for SB134). Most other modules (lawful_processing_and_special_data, data_subject_rights beyond breach timing, cross_border_and_adequacy, adtech_and_commercial_privacy, algorithmic_biometric_and_surveillance_governance, children_and_vulnerable_groups, and most of enforcement_and_redress) returned genuine negative findings (no Alaska-specific statute) rather than T1/T2 confirmations, and are carried with explicit absent_field_provenance. Statute-citation claims for APIPA and the Insurance Data Security Act rely primarily on T3 secondary aggregator (DataGuidance) summaries rather than a directly retrieved akleg.gov primary text in this pass, and specific penalty figures/effective dates for SB134 were not independently confirmed.

Unresolved questions (6):

  • Exact statutory civil penalty amount(s) under AS 45.48 for APIPA violations.
  • Confirmed effective date of the Alaska Insurance Data Security Act (SB134) provisions.
  • Whether HB222 (2025-era consumer data protection bill) is still pending, has died, or has been reintroduced in the current legislative session.
  • Whether APIPA contains any express private right of action for affected consumers.
  • Whether Alaska has any dedicated genetic-privacy or biometric-privacy statute not surfaced in this research pass.
  • Current staffing/budget of the Alaska AG Consumer Protection Unit as it pertains to privacy enforcement capacity.

Escalate to primary-source review: yes