Not publishable as-is. 1 of 5 publication_gate checks fail. The renderer displays the gate rather than suppressing it. Legal review and sub-brief approval are informational and are not part of this test.
Based mainly on secondary sources. Only 2 of the sources retrieved for this jurisdiction are official or direct reporting of official material (tier 1 or 2), against the 3 we look for. No finding on this page is shown with confidence above “Uncertain” until stronger sources are retrieved.
Arizona, USA
US-AZschema gdpri-v2trajectory: not yet assessedregulated (sectoral)overlaps: AIC
Last updated · 10 categories · 22
claims · 20 sources in the cumulative register
10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
22Claimsbaseline..claims[]
1Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix(sums to 10 rendered categories; click to filter)
Jurisdiction brief
Latest update · 28 September 2026
Lead Signal
Arizona's biometric-privacy legislative effort has again failed to advance, with SB1717, introduced in the 2026 session and proposing broader consumer biometric-privacy protections, dying without passing the 57th Legislature's 2nd Regular Session. This follows the same fate as SB1238 in 2023, establishing a now-repeated pattern of failed comprehensive biometric legislation in the state.
Other Developments
No comprehensive biometric statute exists as a result. With SB1717's failure, Arizona residents' biometric data remains protected only incidentally, through the personal-information definition in the state's breach-notification statute and through the education-sector-specific regime applicable to student biometric data. There is no general commercial consent requirement for biometric capture in Arizona following this bill's failure, and reports indicate SB1717 would have prohibited any person from capturing an individual's biometric identifier for a commercial purpose without first informing the individual, a requirement that does not currently exist in Arizona law outside the education-sector context.
Cross-Monitor Connections
The absence of a commercial biometric-consent requirement is relevant to the artificial-intelligence monitor's tracking of biometric and facial-recognition deployment, where Arizona's lack of a generally applicable notice-and-consent statute leaves algorithmic biometric processing largely unconstrained by state privacy law outside the education sector.
Outlook
Whether a further biometric-privacy bill is introduced in a subsequent session, following the pattern of SB1238 (2023) and SB1717 (2026), is the key variable to watch. Absent new legislation, Arizona's biometric data protection will continue to rest solely on the breach-notification statute's personal-information definition and the narrower education-sector regime.
Standing brief · as of 25 August 2026
Written before the update above. Where they differ, the update is the more recent position.
Lead Signal
Arizona's HB2861, which would require social media platforms to enable high-level privacy protections by default for minor users, passed the Arizona House in 2025, but its Senate and gubernatorial status remains unconfirmed at the time of this cycle's research. This is the sole development with material signal in Arizona's data-protection regulatory picture this cycle, and it sits within the Children and Vulnerable Groups dimension of the state's otherwise sectoral, non-omnibus privacy framework.
Other Developments
No other Arizona data-protection module carried material signal authorized for composition this cycle. The interpreter's gaps register confirms this is a genuine coverage limitation rather than an oversight: HB2861's final signed status was not confirmed as of the most recent source reviewed, and no other Arizona children-and-vulnerable-groups development was identified this cycle.
Cross-Monitor Connections
HB2861's default-privacy-protection-for-minors framing intersects with broader platform-governance and content-moderation questions that the Advennt monitor's own review of Arizona consumer-protection and marketing-to-minors provisions in the gambling sector may find structurally analogous, though this monitor does not re-analyze that sector-specific material here.
Outlook
Watch for confirmation of HB2861's Senate passage and gubernatorial signature or veto status, which would resolve whether Arizona joins the small group of states imposing default privacy-by-design requirements specifically for minors on social media platforms. If signed, the practical scope of "high-level privacy protections by default" would need further definition through implementing guidance or subsequent litigation. The regulatory horizon carries this development at a half-year uncertainty band with an estimated fourth-quarter 2026 impact date, reflecting genuine uncertainty about both the bill's final legislative disposition and, if signed, its effective date.
trust tier: ai_unverified
Standing brief, as of 25 August 2026.
Regulatory Status
Arizona's data-protection regime remains sectoral rather than omnibus. The one authorized development this cycle is HB2861, which would require social media platforms to enable high-level default privacy protections for minor users; it passed the Arizona House in 2025 but its Senate and gubernatorial status is unconfirmed.
Outlook
Watch for confirmation of HB2861's final legislative disposition, expected around the fourth quarter of 2026.
10 of 10 categories
Signal
Density
Selections OR within a group, AND across groups. Press / to search.
A named regulator and concrete instruments exist (breach notification statute, Consumer Fraud Act), but there is no comprehensive framework defining lawful bases, subject rights or controller obligations.
Primary frameworkArizona Revised Statutes §18-552 (breach notification) and Arizona Consumer Fraud Act A.R.S. §44-1521 et seq.
Traffic-light rationale — AmberA named regulator and concrete instruments exist (breach notification statute, Consumer Fraud Act), but there is no comprehensive framework defining lawful bases, subject rights or controller obligations.
Sub-modules (5)
Regulator And AuthorityAmber
The Arizona Attorney General enforces breach-notification and consumer-fraud statutes touching personal data; there is no standalone data-protection regulator.
Claims (1):
The Arizona Attorney General is the primary enforcement authority for data-breach notification and consumer-data-practice violations in Arizona, in the absence of a dedicated data-protection regulator.
Act And InstrumentsAmber
Primary instruments are the breach-notification statute (A.R.S. §18-552, amended by HB2146 in 2022) and the Consumer Fraud Act; no comprehensive privacy bill has been passed despite repeated legislative attempts.
Claims (2):
Arizona currently has no comprehensive consumer-privacy statute; recent legislative attempts to pass general privacy legislation have not been enacted.
Breach and data-security requirements in Arizona are governed by the state's breach-notification law under §18-552 of the Arizona Revised Statutes, which requires notification to consumers and to the Arizona Attorney General or the Arizona Department of Homeland Security.
Material ScopeAmber
The breach-notification statute's material scope was expanded by the 2022 amendment to broaden the definition of covered personal information, but AZ has no general material-scope definition of 'personal data' or 'processing' comparable to omnibus regimes.
Claims (1):
HB 2146, signed by the Arizona Governor on 29 March 2022, amended A.R.S. §18-552 and expanded the definition of personal information subject to breach-notification duties, while also introducing a 45-day notification deadline.
Territorial ScopeAmber
No AZ-specific territorial-scope provision was located extending obligations to non-established controllers; the breach statute is understood to apply based on the residency of affected individuals rather than controller location, consistent with the general pattern of US state breach laws, but this has not been independently verified for Arizona in this run.
Arizona imposes no general controller registration or filing regime; the only filing-type obligation is notification to the AG/Department of Homeland Security for breaches affecting more than 1,000 residents.
Claims (1):
For breaches affecting more than 1,000 Arizona residents, HB 2146 requires notification to the three largest nationwide consumer-reporting agencies in addition to the Attorney General and the Arizona Department of Homeland Security.
Category narrative65 words
Arizona has no dedicated data-protection authority and no omnibus consumer-privacy statute. The Arizona Attorney General (AG) is the de facto regulator, exercising authority under the state's general breach-notification statute (A.R.S. §18-552) and the Arizona Consumer Fraud Act (A.R.S. §44-1521 et seq.) for deceptive/unfair data practices. Federal FTC Act Section 5 provides an additional reactive baseline. There is no AZ-specific registration or filing regime for controllers.
Sources and claims (5)
UncertainOneTrust DataGuidance — The Arizona Attorney General is the primary enforcement authority for data-breach notification and consumer-data-practice violations in Arizona, in the absence of a dedicated data-protection regulator.observed
UncertainOneTrust DataGuidance — Arizona currently has no comprehensive consumer-privacy statute; recent legislative attempts to pass general privacy legislation have not been enacted.observed
UncertainOneTrust DataGuidance — Breach and data-security requirements in Arizona are governed by the state's breach-notification law under §18-552 of the Arizona Revised Statutes, which requires notification to consumers and to the Arizona Attorney General or the Arizona Department of Homeland Security.observed
UncertainOneTrust DataGuidance — HB 2146, signed by the Arizona Governor on 29 March 2022, amended A.R.S. §18-552 and expanded the definition of personal information subject to breach-notification duties, while also introducing a 45-day notification deadline.observed
UncertainOneTrust DataGuidance — For breaches affecting more than 1,000 Arizona residents, HB 2146 requires notification to the three largest nationwide consumer-reporting agencies in addition to the Attorney General and the Arizona Department of Homeland Security.observed
Traffic-light rationale — RedNo omnibus lawful-basis, consent, or special-category regime exists at the state level; only a narrow genetic-testing carve-out was identified.
Sub-modules (4)
Lawful BasesRed
No AZ statute enumerates lawful bases for processing personal data comparable to GDPR Art 6; absent a comprehensive privacy law, processing is unconstrained except where sector-specific federal law applies.
Absence provenance: unavailable. Searched: Arizona lawful basis processing personal data statute, Arizona consumer privacy consent requirements 2026.
Consent ThresholdsRed
No general statutory consent-quality standard exists; consent is only referenced narrowly in the context of specific practices litigated under the Consumer Fraud Act (e.g., deceptive location-tracking consent claims against Google).
Claims (1):
The Arizona Attorney General alleged in litigation against Google that the company continued collecting users' location data via settings such as Web & App Activity even after users disabled Location History, framing this as a deceptive-consent practice under the Arizona Consumer Fraud Act.
Special CategoriesAmber
Arizona is one of a group of states with a statute specifically regulating direct-to-consumer genetic-testing companies; outside genetic data, no general special/sensitive-category regime exists at state level.
Claims (1):
Arizona is among twelve US states (alongside Alabama, California, Kentucky, Maryland, Montana, Tennessee, Texas, Utah, Virginia, Wyoming and Nebraska) with a statute specifically governing direct-to-consumer genetic-testing companies.
Pseudonymisation And AnonymisationRed
No Arizona statute defines pseudonymisation or anonymisation or provides safe-harbour treatment for de-identified data.
Arizona has no general lawful-basis framework, no statutory consent-quality standard for commercial data processing, and no general special-category regime. The one notable exception is a direct-to-consumer genetic-testing statute, placing Arizona among a small group of US states regulating that narrow category. Outside genetic testing, sensitive-data handling is governed only by sector-specific federal law (HIPAA, GLBA, COPPA) which falls outside this JID's scope.
Sources and claims (2)
UncertainOneTrust DataGuidance — The Arizona Attorney General alleged in litigation against Google that the company continued collecting users' location data via settings such as Web & App Activity even after users disabled Location History, framing this as a deceptive-consent practice under the Arizona Consumer Fraud Act.observed
UncertainOneTrust DataGuidance — Arizona is among twelve US states (alongside Alabama, California, Kentucky, Maryland, Montana, Tennessee, Texas, Utah, Virginia, Wyoming and Nebraska) with a statute specifically governing direct-to-consumer genetic-testing companies.observed
No comprehensive data-subject-rights regime exists in Arizona; this is a legitimate structural gap rather than an omission.
Traffic-light rationale — RedNo comprehensive data-subject-rights regime exists in Arizona; this is a legitimate structural gap rather than an omission.
Sub-modules (5)
Access RightRed
No general AZ statutory right of access to personal data held by private businesses.
Absence provenance: unavailable. Searched: Arizona right of access personal data statute consumer.
Rectification And ErasureRed
No general AZ statutory right to rectify or erase personal data held by businesses.
Absence provenance: unavailable. Searched: Arizona right to delete personal data statute.
Restriction And ObjectionRed
No general AZ statutory right to restrict processing or object to processing/profiling.
Absence provenance: unavailable. Searched: Arizona right to object profiling opt-out statute.
Data PortabilityRed
No AZ statutory data-portability right exists.
Absence provenance: unavailable. Searched: Arizona data portability right statute.
Deadlines And Response WindowsRed
Because no general subject-rights regime exists, there are no statutory response-window deadlines for rights requests (distinct from the 45-day breach-notification deadline, which is a controller-to-regulator/consumer breach obligation, not a rights-request deadline).
Claims (1):
Arizona's breach-notification statute imposes a 45-day deadline for notifying affected individuals of a data breach, but this is a breach-response deadline, not a subject-access-request response window, since no general access-request regime exists in Arizona.
Category narrative46 words
Arizona confers no general statutory rights of access, rectification, erasure, restriction, objection or portability over personal data held by private-sector businesses. Such rights exist only where a federal sectoral statute (e.g., HIPAA for health records) independently applies, which is out of scope for this state-level JID.
Sources and claims (1)
UncertainIAPP — Arizona's breach-notification statute imposes a 45-day deadline for notifying affected individuals of a data breach, but this is a breach-response deadline, not a subject-access-request response window, since no general access-request regime exists in Arizona.observed
Traffic-light rationale — AmberBreach notification is a real, enforceable duty; the remaining accountability infrastructure (DPIA, DPO, ROPA, retention) is absent at state level.
Sub-modules (7)
Accountability And DpiaRed
No AZ statute requires DPIAs or a general accountability principle akin to GDPR Art 5/25/35.
The breach-notification statute implies an expectation of reasonable security safeguards but does not prescribe specific technical/organisational measures comparable to GDPR Art 32.
Claims (1):
Arizona's breach-notification statute presumes an underlying duty of reasonable data security by penalizing failure to protect personal information that leads to a breach, though it does not itemize specific technical or organisational security measures.
Breach NotificationGreen
A.R.S. §18-552, as amended by HB 2146 (2022), is Arizona's core breach-notification obligation: a 45-day notification deadline, an expanded definition of personal information (including health-care data), and enhanced AG enforcement powers.
Claims (2):
Arizona's amended breach-notification law (via HB 2146) sets a 45-day deadline for notifying affected individuals, expands the definition of covered personal information to include health-care data, and gives the Attorney General enhanced power to prosecute violators.
Under A.R.S. §18-552, businesses must notify affected consumers and either the Arizona Attorney General or the Arizona Department of Homeland Security in the event of a data breach, and the Attorney General holds the power to sanction violations and issue penalties.
Retention And DisposalRed
No general AZ statutory retention-limit or disposal-duty regime was located outside of sector-specific federal law.
Arizona imposes concrete breach-notification duties (A.R.S. §18-552) but no general accountability, DPIA, DPO, ROPA, or retention-limit obligations. Security-of-processing is addressed only implicitly through the breach statute's reasonable-security expectations and via sector-specific federal law.
Sources and claims (3)
UncertainOneTrust DataGuidance — Arizona's breach-notification statute presumes an underlying duty of reasonable data security by penalizing failure to protect personal information that leads to a breach, though it does not itemize specific technical or organisational security measures.observed
UncertainIAPP — Arizona's amended breach-notification law (via HB 2146) sets a 45-day deadline for notifying affected individuals, expands the definition of covered personal information to include health-care data, and gives the Attorney General enhanced power to prosecute violators.observed
UncertainOneTrust DataGuidance — Under A.R.S. §18-552, businesses must notify affected consumers and either the Arizona Attorney General or the Arizona Department of Homeland Security in the event of a data breach, and the Attorney General holds the power to sanction violations and issue penalties.observed
No AZ-specific cross-border transfer, adequacy or localisation framework exists; this is a legitimate gap given the absence of a state omnibus law.
Traffic-light rationale — Not assessedNo AZ-specific cross-border transfer, adequacy or localisation framework exists; this is a legitimate gap given the absence of a state omnibus law.
Sub-modules (6)
Transfer MechanismsRed
No AZ-specific transfer mechanism statute exists.
Absence provenance: unavailable. Searched: Arizona cross-border data transfer mechanism statute.
Adequacy ReceivedRed
Not applicable at state level; adequacy determinations are a federal/EU-US construct.
No AZ-specific SCC/BCR regime; any use of SCCs/BCRs by AZ-based entities derives from federal/international frameworks, not state law.
Absence provenance: unavailable. Searched: Arizona standard contractual clauses BCR requirement.
Transfer Impact AssessmentRed
No AZ statutory TIA requirement exists.
Absence provenance: unavailable. Searched: Arizona transfer impact assessment requirement.
Data LocalisationRed
No AZ data-localisation mandate was identified.
Absence provenance: unavailable. Searched: Arizona data localisation requirement statute.
Category narrative39 words
Arizona has no state-level cross-border data-transfer regime, no adequacy mechanism, and no data-localisation mandate. Cross-border transfer questions arising from AZ-resident data are governed exclusively by federal law and mechanisms (SCCs, federal sectoral rules), which sit outside this state JID.
A narrow genetic-testing overlay exists; broader sectoral coverage (health, finance, education, insurance) is federal and out of scope for this state JID.
Traffic-light rationale — AmberA narrow genetic-testing overlay exists; broader sectoral coverage (health, finance, education, insurance) is federal and out of scope for this state JID.
Sub-modules (7)
Financial Sector OverlayRed
No AZ-specific financial-sector data-protection overlay was located beyond the federal GLBA baseline (out of scope for this JID).
No AZ-specific health-data statute beyond federal HIPAA (out of scope); AZ health providers report breaches to HHS OCR under HIPAA, as illustrated by recent AZ healthcare ransomware incidents.
Claims (1):
Arizona healthcare entities, such as a regional medical center and other providers, have reported large-scale ransomware and malware-related patient-data breaches to HHS OCR under federal HIPAA breach-reporting obligations, impacting hundreds of thousands of individuals.
Telecoms And EprivacyAmber
Arizona has a state-level telephone-solicitation law restricting calls to numbers on the National Do-Not-Call registry, with specified exceptions.
Claims (1):
Arizona has enacted a law restricting telephone solicitations to numbers on the National Do-Not-Call registry, subject to specific exceptions.
Employment DataRed
No AZ-specific employment-data-privacy statute was located; federal GINA governs genetic-information-based employment discrimination nationally, out of scope for this state JID.
Absence provenance: unavailable. Searched: Arizona employment data privacy statute.
Credit And ScoringRed
No AZ-specific credit-scoring privacy statute was located beyond federal FCRA (out of scope).
Absence provenance: unavailable. Searched: Arizona credit scoring data privacy statute.
EducationRed
No AZ-specific education-sector data-privacy statute was located in this run beyond federal FERPA (out of scope).
Absence provenance: unavailable. Searched: Arizona student data privacy statute.
InsuranceRed
No AZ-specific insurance-sector data-privacy statute was located in this run.
Absence provenance: unavailable. Searched: Arizona insurance sector data privacy statute.
Category narrative52 words
Outside the breach-notification statute, Arizona's data-protection-relevant sectoral activity consists of a direct-to-consumer genetic-testing statute and reliance on federal sectoral overlays (HIPAA for health, GLBA for financial, COPPA for children) that are native to the US-federal JID rather than AZ. No AZ-specific insurance, education, or credit-scoring privacy statute was identified in this run.
Sources and claims (2)
UncertainOneTrust DataGuidance — Arizona healthcare entities, such as a regional medical center and other providers, have reported large-scale ransomware and malware-related patient-data breaches to HHS OCR under federal HIPAA breach-reporting obligations, impacting hundreds of thousands of individuals.observed
UncertainOneTrust DataGuidance — Arizona has enacted a law restricting telephone solicitations to numbers on the National Do-Not-Call registry, subject to specific exceptions.observed
No structural cookie/opt-out regime exists, but active AG enforcement under general consumer-fraud authority provides a meaningful, demonstrated deterrent against deceptive ad-tech data practices.
Primary frameworkArizona Consumer Fraud Act, A.R.S. §44-1521 et seq.
Traffic-light rationale — AmberNo structural cookie/opt-out regime exists, but active AG enforcement under general consumer-fraud authority provides a meaningful, demonstrated deterrent against deceptive ad-tech data practices.
Sub-modules (6)
Cookies And TrackersRed
No AZ cookie-consent statute exists; tracking practices are addressed only reactively via consumer-fraud enforcement.
Absence provenance: unavailable. Searched: Arizona cookie consent law statute.
Dark PatternsRed
No AZ dark-patterns statute was located; deceptive-design practices are addressed only through the general Consumer Fraud Act.
Absence provenance: unavailable. Searched: Arizona dark patterns statute prohibition.
Opt Out SignalsRed
No AZ statute recognizes Global Privacy Control or comparable opt-out signals.
Absence provenance: unavailable. Searched: Arizona Global Privacy Control opt-out signal recognition statute.
Clean Rooms And DcrRed
No AZ-specific clean-room/data-collaboration statute was located.
Absence provenance: unavailable. Searched: Arizona data clean room statute.
Cross Context AdvertisingAmber
No AZ equivalent to CPRA 'sale'/'share' restrictions exists; the AG's Google settlement addressed deceptive location-data use for advertising under general consumer-fraud law rather than a cross-context-advertising-specific statute.
Claims (1):
The Arizona Attorney General secured an $85 million settlement with Google in 2022 resolving allegations that Google deceptively continued collecting and using consumers' location data for advertising purposes after users had disabled location tracking, brought under the Arizona Consumer Fraud Act.
Direct MarketingAmber
Direct marketing via telephone is regulated by the AZ Do-Not-Call statute (see sectoral_watch.telecoms_and_eprivacy); no general direct-mail/email suppression statute beyond federal CAN-SPAM/TCPA was located.
Category narrative64 words
Arizona has no cookie-consent or 'sale'/'share' opt-out statute comparable to CPRA. The principal lever against commercial ad-tech data practices is the Arizona Consumer Fraud Act, used by the AG to pursue deceptive location-tracking and data-collection practices (e.g., the $85M Google settlement and the pending Temu suit). A pending 2026 bill (HB 2489) would restrict surveillance-based pricing practices, but it is not yet in force.
Sources and claims (1)
UncertainIAPP — The Arizona Attorney General secured an $85 million settlement with Google in 2022 resolving allegations that Google deceptively continued collecting and using consumers' location data for advertising purposes after users had disabled location tracking, brought under the Arizona Consumer Fraud Act.observed
Meaningful legislative activity exists (biometric, AI, surveillance-pricing bills) but none confirmed in force; treat as pending/proposed pending regulator confirmation.
Traffic-light rationale — AmberMeaningful legislative activity exists (biometric, AI, surveillance-pricing bills) but none confirmed in force; treat as pending/proposed pending regulator confirmation.
Sub-modules (6)
Profiling RestrictionsAmber
No AZ statute restricts profiling comparable to GDPR Art 22; the pending surveillance-pricing bill (HB 2489) touches algorithmic pricing but is not yet law.
Claims (1):
Arizona House Bill 2489 would restrict surveillance-based pricing practices by defining and prohibiting such practices and establishing enforcement mechanisms, but has not been confirmed enacted as of this run.
Automated Decision Making TransparencyRed
No AZ statute requires ADM transparency or an explanation right.
Absence provenance: unavailable. Searched: Arizona automated decision making transparency statute.
Ai Risk AssessmentsAmber
A pending bill, HB 2311, would introduce disclosure, safety and content restrictions for conversational-AI services with enhanced protections for minors, but it has not been confirmed as enacted.
Claims (1):
Arizona House Bill 2311 would introduce disclosure, safety, and content restrictions for conversational AI services, with enhanced protections for minors, but its passage into law has not been confirmed in this run.
Biometric RegimeAmber
Senate Bill 1238 would regulate biometric-data handling by private entities and provide legal recourse for violations; introduction/first-reading was confirmed but enactment status could not be verified in this run.
Claims (1):
Arizona Senate Bill 1238 would regulate biometric-data handling by private entities and provide legal recourse for violations; the bill was read in the State Senate but its final enactment status could not be independently confirmed in this run.
Genetic DataAmber
See lawful_processing_and_special_data.special_categories: Arizona's direct-to-consumer genetic-testing statute is the only in-force genetic-data provision identified.
State Surveillance CarveoutsRed
No AZ-specific state-surveillance carve-out or national-security exemption provision was located in this run.
Absence provenance: unavailable. Searched: Arizona state surveillance carveout national security exemption data statute.
Category narrative63 words
Arizona has no in-force profiling, ADM-transparency, or AI-risk-assessment statute. A biometric-data bill (SB 1238) proposing regulation of biometric handling by private entities with a private right of action has been introduced but its enactment status is unconfirmed in this run. Pending 2026 bills would address conversational-AI services with minor protections (HB 2311) and surveillance-based pricing (HB 2489), but neither is yet in force.
no periodic updates on record for this sub-brief
Sources and claims (3)
UncertainOneTrust DataGuidance — Arizona House Bill 2489 would restrict surveillance-based pricing practices by defining and prohibiting such practices and establishing enforcement mechanisms, but has not been confirmed enacted as of this run.observed
UncertainOneTrust DataGuidance — Arizona House Bill 2311 would introduce disclosure, safety, and content restrictions for conversational AI services, with enhanced protections for minors, but its passage into law has not been confirmed in this run.observed
UncertainOneTrust DataGuidance — Arizona Senate Bill 1238 would regulate biometric-data handling by private entities and provide legal recourse for violations; the bill was read in the State Senate but its final enactment status could not be independently confirmed in this run.observed
Active pending legislative pipeline on minors' data exists, but nothing AZ-specific is confirmed in force; federal COPPA is the operative baseline, and is out of scope for this JID.
Traffic-light rationale — AmberActive pending legislative pipeline on minors' data exists, but nothing AZ-specific is confirmed in force; federal COPPA is the operative baseline, and is out of scope for this JID.
Sub-modules (5)
Age VerificationAmber
Arizona House Bill 2920 would mandate age verification for app stores and developers handling minors' accounts, but enactment is unconfirmed.
Claims (1):
Arizona House Bill 2920 would mandate age verification, parental consent, and data-sharing duties for app stores and developers handling minors' accounts, but its enactment status has not been independently confirmed in this run.
Parental ConsentAmber
HB 2920 would also impose parental-consent duties on app-store/developer platforms handling minors' accounts; status unconfirmed.
Claims (1):
Arizona House Bill 2920 would mandate age verification, parental consent, and data-sharing duties for app stores and developers handling minors' accounts, but its enactment status has not been independently confirmed in this run.
Minor Profiling BansAmber
No confirmed AZ statute specifically bans profiling of minors; HB 2861 and HB 2858 (enhancing minors' social-media privacy protections) are pending and unconfirmed as enacted.
Claims (1):
Arizona House Bill 2861 would enhance privacy protections for minors on social media platforms, and House Bill 2858 similarly seeks to enhance online privacy and safety for minors on social media, but neither has been confirmed enacted in this run.
Education SettingsRed
No AZ-specific education-settings child-data statute was identified in this run.
Arizona has no in-force comprehensive minors'-data statute. Multiple 2026-session bills address minors' online safety and social-media data practices (HB 2861, HB 2858, HB 2920 covering age verification/parental consent for app stores) alongside intimate-image/deepfake bills (SB 1462, SB 1336, HB 2678), but enactment status for the privacy-specific bills is not confirmed in this run. Federal COPPA applies nationally but is out of scope for this state JID. No AZ-specific dependent-adults data-protection provision was identified.
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Sources and claims (2)
UncertainOneTrust DataGuidance — Arizona House Bill 2920 would mandate age verification, parental consent, and data-sharing duties for app stores and developers handling minors' accounts, but its enactment status has not been independently confirmed in this run.observed
UncertainOneTrust DataGuidance — Arizona House Bill 2861 would enhance privacy protections for minors on social media platforms, and House Bill 2858 similarly seeks to enhance online privacy and safety for minors on social media, but neither has been confirmed enacted in this run.observed
Enforcement powers and recent activity are real and material, but redress avenues remain reactive/consumer-fraud-based rather than a dedicated private right of action under a comprehensive privacy statute.
Traffic-light rationale — AmberEnforcement powers and recent activity are real and material, but redress avenues remain reactive/consumer-fraud-based rather than a dedicated private right of action under a comprehensive privacy statute.
Sub-modules (6)
Regulator Powers And PenaltiesGreen
The AG holds sanction and penalty power under the breach-notification statute and broad injunctive/monetary remedies under the Consumer Fraud Act, evidenced by the $85M Google settlement.
Claims (1):
The Arizona Attorney General obtained an $85 million settlement with Google in 2022 for deceptive location-data practices found to violate the Arizona Consumer Fraud Act, with the bulk of proceeds directed to the state general fund and $5 million earmarked for attorney-general education programs.
Enforcement Activity IndexAmber
Recent AG enforcement activity includes the Google location-data settlement and a lawsuit against Temu for unlawful data collection and inadequate privacy disclosures.
Claims (1):
The Arizona Attorney General has sued Temu alleging unlawful data collection and inadequate privacy disclosures, representing recent state enforcement activity against a commercial data practice.
Regulator Funding And CapacityRed
No specific AZ AG privacy-unit funding or headcount data was located in this run.
Absence provenance: unavailable. Searched: Arizona Attorney General consumer protection unit funding headcount privacy.
Collective Redress And Class ActionsRed
No AZ-specific statutory collective-redress mechanism for data-privacy claims beyond general Arizona class-action procedure was identified in this run.
Absence provenance: unavailable. Searched: Arizona class action data privacy statute.
Private Right Of ActionAmber
No general private right of action for data-privacy violations exists in Arizona; pending SB 1238 (biometric data) reportedly would include legal recourse for violations, but enactment is unconfirmed.
Claims (1):
Pending Arizona Senate Bill 1238 would regulate biometric-data handling by private entities and provide for legal recourse for violations, which would constitute a private right of action if enacted, but enactment has not been confirmed in this run.
Recent Developments 180DAmber
Within the last 180 days, the most notable AZ-specific development identified is the Attorney General's lawsuit against Temu over data-collection and privacy-disclosure practices; multiple minors'-privacy and biometric/AI bills remain pending in the 2026 legislative session.
Claims (1):
The Arizona Attorney General has sued Temu alleging unlawful data collection and inadequate privacy disclosures, representing recent state enforcement activity against a commercial data practice.
Category narrative83 words
The Arizona Attorney General has demonstrated active, real enforcement capacity against deceptive data practices under the Consumer Fraud Act, most notably the 2022 $85 million Google location-data settlement and the more recent lawsuit against Temu alleging unlawful data collection and inadequate privacy disclosures. Arizona's breach-notification statute gives the AG additional sanction and penalty powers. No AZ-specific private right of action for general data-privacy violations was identified; some breach/biometric bills (e.g., pending SB 1238) propose private rights of action but are not confirmed enacted.
Sources and claims (3)
UncertainNAAG — The Arizona Attorney General obtained an $85 million settlement with Google in 2022 for deceptive location-data practices found to violate the Arizona Consumer Fraud Act, with the bulk of proceeds directed to the state general fund and $5 million earmarked for attorney-general education programs.observed
UncertainOneTrust DataGuidance — The Arizona Attorney General has sued Temu alleging unlawful data collection and inadequate privacy disclosures, representing recent state enforcement activity against a commercial data practice.observed
UncertainOneTrust DataGuidance — Pending Arizona Senate Bill 1238 would regulate biometric-data handling by private entities and provide for legal recourse for violations, which would constitute a private right of action if enacted, but enactment has not been confirmed in this run.observed
No categories match.
Filters combine as OR inside a group and AND across
groups.
Publication gate
Blocking. 1 failing check(s).
schema_valid
pass
min_t1_per_instrument_met
n/a — no subject in this jurisdiction
min_quoted_text_present
waived — floor 0%
translation_provenance_recorded
n/a — no subject in this jurisdiction
egress_verified
pass
source_tier_integrity_ok
pass
jurisdiction_source_floor_met
FAIL
tier_a_b_national_primary_pct
10.0
aggregator_only_jurisdiction_count
0
manual_override
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for Arizona, USA
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
no reviewer on record
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 22 claim(s) (22 category placement(s)), 20 source(s) in the cumulative register.
regulator_and_framework, controller_processor_duties (breach_notification sub-module), sectoral_watch (telecoms), and enforcement_and_redress (regulator_powers_and_penalties) rest on T2/T3 sources with reasonably strong corroboration (multiple DataGuidance/IAPP/NAAG hits on the same facts, e.g., HB 2146 and the $85M Google settlement). lawful_processing_and_special_data, data_subject_rights, cross_border_and_adequacy, and most of children_and_vulnerable_groups and algorithmic_biometric_and_surveillance_governance rely on absent_field_provenance because no comprehensive AZ statute exists (confirmed structural gap per seed disambiguation) or because pending 2026-session bills (SB 1238, HB 2311, HB 2489, HB 2861, HB 2858, HB 2920) could not be confirmed as enacted versus still pending in this run — no T1 primary-source (azleg.gov) text was directly retrieved for any AZ statute; all statutory citations are via T2/T3 secondary legal-research aggregators.
Unresolved questions (5):
Has Arizona Senate Bill 1238 (biometric data) been enacted, and if so, on what effective date?
Have Arizona House Bills 2861, 2858, 2920, 2311, or 2489 (minors' privacy, conversational AI, surveillance-pricing) passed into law in the 2026 session, and what are their effective dates?
What is the current status of Arizona House Bill 2790 (consumer data protection and penalties)?
Can a direct azleg.gov citation for A.R.S. §18-552 (as amended) be retrieved to serve as a T1 primary source, given the seed-provided anchor (naag.org) does not host statutory text?
Does Arizona's genetic-testing statute apply to processing beyond direct-to-consumer testing companies, and what is its precise A.R.S. citation?