Not publishable as-is. 3 of 7 publication_gate checks fail. The renderer displays the gate rather than suppressing it. Legal review and sub-brief approval are informational and are not part of this test.
Arkansas, USA
US-ARschema gdpri-v2trajectory: not yet assessedregulated (sectoral)overlaps: FIM, WPM, AIC, Crypto
Last updated update date not yet available · 10 categories · 41
claims · 14 sources in the cumulative register
10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
41Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix(sums to 10 rendered categories; click to filter)
Jurisdiction brief
No content recorded at this JID path.
10 of 10 categories
Signal
Density
Selections OR within a group, AND across groups. Press / to search.
No omnibus statute exists (would be red for material/territorial/registration sub-modules), but a functioning breach-notification/security regime with an active enforcing regulator (AG) exists and is expanding via sectoral bills, justifying amber rather than red at the module level.
Primary frameworkArkansas Personal Information Protection Act (Ark. Code Ann. § 4-110-101 et seq.); backstopped by federal FTC Act Section 5
Traffic-light rationale — AmberNo omnibus statute exists (would be red for material/territorial/registration sub-modules), but a functioning breach-notification/security regime with an active enforcing regulator (AG) exists and is expanding via sectoral bills, justifying amber rather than red at the module level.
Sub-modules (5)
Regulator And AuthorityAmber
The Arkansas Attorney General enforces PIPA and the Arkansas Deceptive Trade Practices Act; there is no independent data-protection authority equivalent to a GDPR-style DPA.
Claims (1):
The Arkansas Attorney General is the state regulator responsible for enforcing the Personal Information Protection Act and the Arkansas Deceptive Trade Practices Act, including data-breach and consumer-privacy-adjacent violations.
Act And InstrumentsRed
PIPA is the principal instrument; no comprehensive consumer-privacy act exists.
Claims (1):
Arkansas has no comprehensive consumer data-protection or privacy statute; the state's principal privacy-relevant law is the Personal Information Protection Act, which addresses data-breach notification and reasonable-security/disposal obligations only.
Material ScopeAmber
PIPA covers persons, businesses and state agencies that acquire, own, or license personal information of Arkansas residents, and imposes reasonable-security and disposal duties.
Claims (1):
The Personal Information Protection Act (Ark. Code Ann. § 4-110-101 et seq.), effective April 4, 2005, requires individuals, businesses, and state agencies that acquire, own, or license personal information of Arkansas residents to implement reasonable security measures and reasonable data-disposal procedures.
Territorial ScopeAmber
Coverage turns on the residency of the data subject (Arkansas residents), not the location of the regulated entity, giving the statute extraterritorial reach comparable to other early-generation state breach laws.
Claims (1):
Arkansas expanded the entities subject to its breach-notification statute to any business that acquires, owns, or licenses personal information of a state resident, giving the law reach over out-of-state entities holding Arkansas residents' data.
Regulator Registration And FilingRed
No general controller registration or filing obligation exists under Arkansas law.
Absence provenance: unavailable. Searched: Arkansas data controller registration requirement, Arkansas Attorney General privacy filing obligation.
Claims (1):
Arkansas law does not impose a general registration or filing obligation on data controllers or processors.
Category narrative76 words
Arkansas has no comprehensive consumer data-protection statute. The state's privacy-relevant legal architecture is limited to the Personal Information Protection Act (PIPA, Ark. Code Ann. § 4-110-101 et seq.), a breach-notification and reasonable-security/disposal statute enforced by the Arkansas Attorney General, plus scattered sectoral instruments (Consumer Telephone Privacy Act, Protection of Minors from Distribution of Harmful Material Act, Children and Teens' Online Privacy Protection Act). The federal FTC Act Section 5 backstops the absence of an omnibus regime.
Sources and claims (5)
ConfirmedDataGuidance/OneTrust — The Arkansas Attorney General is the state regulator responsible for enforcing the Personal Information Protection Act and the Arkansas Deceptive Trade Practices Act, including data-breach and consumer-privacy-adjacent violations.observed
ConfirmedInternational Association of Privacy Professionals — Arkansas has no comprehensive consumer data-protection or privacy statute; the state's principal privacy-relevant law is the Personal Information Protection Act, which addresses data-breach notification and reasonable-security/disposal obligations only.observed
ConfirmedDataGuidance/OneTrust — The Personal Information Protection Act (Ark. Code Ann. § 4-110-101 et seq.), effective April 4, 2005, requires individuals, businesses, and state agencies that acquire, own, or license personal information of Arkansas residents to implement reasonable security measures and reasonable data-disposal procedures.observed
ProbableOPC Canada — Arkansas expanded the entities subject to its breach-notification statute to any business that acquires, owns, or licenses personal information of a state resident, giving the law reach over out-of-state entities holding Arkansas residents' data.observed
ConfirmedDataGuidance/OneTrust — Arkansas law does not impose a general registration or filing obligation on data controllers or processors.observed
Core sub-modules (lawful_bases, special_categories, pseudonymisation) are entirely absent; only a narrow, minors-specific consent overlay exists and part of that overlay has been struck down.
Traffic-light rationale — RedCore sub-modules (lawful_bases, special_categories, pseudonymisation) are entirely absent; only a narrow, minors-specific consent overlay exists and part of that overlay has been struck down.
Sub-modules (4)
Lawful BasesRed
No enumerated lawful bases for processing exist under Arkansas law.
Absence provenance: unavailable. Searched: Arkansas lawful basis data processing statute.
Claims (1):
Arkansas has no general statutory enumeration of lawful bases for processing personal data equivalent to GDPR Article 6; processing outside sector-specific contexts requires no specific lawful-basis justification under Arkansas law.
Consent ThresholdsAmber
Minors-specific consent obligations exist via HB1717 (prospective) and via the now-unenforceable Social Media Safety Act.
Claims (2):
The Arkansas Children and Teens' Online Privacy Protection Act (HB1717), effective July 1, 2026, prohibits covered operators from collecting personal data from minors for targeted-advertising purposes and mandates specific data-management practices.
The Arkansas Social Media Safety Act (SB396), which would have required age verification and parental consent for minors under 18 to use social media platforms, was enjoined by the U.S. District Court for the Western District of Arkansas and subsequently held unconstitutional on First and Fourteenth Amendment grounds; its consent mechanism is not currently enforceable.
Special CategoriesRed
No independent state special/sensitive-category regime exists; coverage, if any, derives from federal sectoral overlays (HIPAA, COPPA).
Absence provenance: unavailable. Searched: Arkansas sensitive personal data statute, Arkansas biometric health genetic data law.
Claims (1):
Arkansas has no independent statutory scheme creating heightened protections for special/sensitive categories of personal data (health, biometric, genetic, etc.) outside of federal sectoral overlays such as HIPAA and COPPA.
Pseudonymisation And AnonymisationRed
No statutory definitions or safe-harbours for pseudonymisation or anonymisation exist under Arkansas law.
Arkansas law provides no statutory definition of, or safe-harbour for, pseudonymised or anonymised data.
Category narrative58 words
Arkansas has no general lawful-basis or consent-standard regime for personal-data processing outside of sector-specific minors' laws. The Children and Teens' Online Privacy Protection Act (HB1717, effective July 1, 2026) restricts targeted advertising and data collection directed at minors; the Social Media Safety Act's parental-consent/age-verification regime was enjoined and later ruled unconstitutional. No independent special-category or pseudonymisation regime exists.
Sources and claims (5)
ConfirmedInternational Association of Privacy Professionals — Arkansas has no general statutory enumeration of lawful bases for processing personal data equivalent to GDPR Article 6; processing outside sector-specific contexts requires no specific lawful-basis justification under Arkansas law.observed
ConfirmedDataGuidance/OneTrust — The Arkansas Children and Teens' Online Privacy Protection Act (HB1717), effective July 1, 2026, prohibits covered operators from collecting personal data from minors for targeted-advertising purposes and mandates specific data-management practices.observed
ConfirmedInternational Association of Privacy Professionals — The Arkansas Social Media Safety Act (SB396), which would have required age verification and parental consent for minors under 18 to use social media platforms, was enjoined by the U.S. District Court for the Western District of Arkansas and subsequently held unconstitutional on First and Fourteenth Amendment grounds; its consent mechanism is not currently enforceable.observed
ConfirmedInternational Association of Privacy Professionals — Arkansas has no independent statutory scheme creating heightened protections for special/sensitive categories of personal data (health, biometric, genetic, etc.) outside of federal sectoral overlays such as HIPAA and COPPA.observed
ConfirmedDataGuidance/OneTrust — Arkansas law provides no statutory definition of, or safe-harbour for, pseudonymised or anonymised data.observed
Traffic-light rationale — RedAll consumer-rights sub-modules are absent except a narrow breach-notice timing rule.
Sub-modules (5)
Access RightRed
No general right of access to personal data held by private-sector controllers exists under Arkansas law.
Absence provenance: unavailable. Searched: Arkansas consumer right to access personal data.
Claims (1):
Arkansas law does not grant consumers a general right of access, rectification, erasure, restriction, objection, or data portability with respect to personal data held by private-sector controllers.
Rectification And ErasureRed
No general right to correct or delete personal data exists under Arkansas law.
Absence provenance: unavailable. Searched: Arkansas right to delete personal data.
Claims (1):
Arkansas law does not grant consumers a general right of access, rectification, erasure, restriction, objection, or data portability with respect to personal data held by private-sector controllers.
Restriction And ObjectionRed
No general right to restrict processing or object to profiling exists under Arkansas law.
Absence provenance: unavailable. Searched: Arkansas right to object to processing.
Claims (1):
Arkansas law does not grant consumers a general right of access, rectification, erasure, restriction, objection, or data portability with respect to personal data held by private-sector controllers.
Data PortabilityRed
No data-portability right exists under Arkansas law.
Absence provenance: unavailable. Searched: Arkansas data portability right.
Claims (1):
Arkansas law does not grant consumers a general right of access, rectification, erasure, restriction, objection, or data portability with respect to personal data held by private-sector controllers.
Deadlines And Response WindowsAmber
The only statutory deadline is PIPA's breach-notification timing obligation, not a general DSAR response window.
Claims (1):
PIPA requires notification of a security breach to affected Arkansas residents and, depending on the number affected, to the Attorney General, functioning as a breach-notice timing obligation rather than a general subject-access-request deadline.
Category narrative46 words
Arkansas confers no general consumer rights of access, rectification, erasure, restriction, objection, or data portability with respect to personal data held by private-sector controllers. The only rights-adjacent obligation is the PIPA breach-notification timing requirement, which functions as a notice duty rather than a general DSAR framework.
Sources and claims (2)
ConfirmedInternational Association of Privacy Professionals — Arkansas law does not grant consumers a general right of access, rectification, erasure, restriction, objection, or data portability with respect to personal data held by private-sector controllers.observed
ConfirmedDataGuidance/OneTrust — PIPA requires notification of a security breach to affected Arkansas residents and, depending on the number affected, to the Attorney General, functioning as a breach-notice timing obligation rather than a general subject-access-request deadline.observed
Security, breach-notification and disposal duties are in force and enforced by the AG, but the broader accountability infrastructure (DPIA, DPO, ROPA, joint controllers) found in omnibus regimes is entirely absent.
Primary frameworkArkansas Personal Information Protection Act (Ark. Code Ann. § 4-110-101 et seq.)
Traffic-light rationale — AmberSecurity, breach-notification and disposal duties are in force and enforced by the AG, but the broader accountability infrastructure (DPIA, DPO, ROPA, joint controllers) found in omnibus regimes is entirely absent.
Sub-modules (7)
Accountability And DpiaRed
No accountability principle or DPIA-trigger regime exists under Arkansas law.
Arkansas law contains no statutory framework governing joint-controller relationships or allocation of responsibility between co-controllers.
Security MeasuresGreen
PIPA requires reasonable security procedures and practices to protect personal information.
Claims (1):
The Personal Information Protection Act requires covered persons, businesses, and state agencies to implement and maintain reasonable security procedures and practices to protect personal information from unauthorized access, use, modification, or disclosure.
Breach NotificationGreen
PIPA requires notification of security breaches to affected residents and, above certain thresholds, to the Attorney General.
Claims (1):
PIPA requires notification of security breaches involving personal information to affected Arkansas residents and, depending on the number of individuals affected, to the Arkansas Attorney General.
Retention And DisposalAmber
PIPA requires reasonable procedures for the proper disposal of records containing personal information.
Claims (1):
PIPA requires covered entities to implement reasonable procedures for the proper disposal of records containing personal information to prevent unauthorized access to or use of the information.
Category narrative35 words
PIPA imposes reasonable security, breach-notification, and disposal duties on controllers, but Arkansas has no accountability/DPIA principle, DPO-appointment threshold, ROPA obligation, or joint-controller regime. Act 557 layers a sector-specific security-program and incident-response-plan requirement onto virtual-currency businesses.
ConfirmedInternational Association of Privacy Professionals — Arkansas law contains no statutory framework governing joint-controller relationships or allocation of responsibility between co-controllers.observed
ConfirmedDataGuidance/OneTrust — The Personal Information Protection Act requires covered persons, businesses, and state agencies to implement and maintain reasonable security procedures and practices to protect personal information from unauthorized access, use, modification, or disclosure.observed
ConfirmedDataGuidance/OneTrust — PIPA requires notification of security breaches involving personal information to affected Arkansas residents and, depending on the number of individuals affected, to the Arkansas Attorney General.observed
ConfirmedDataGuidance/OneTrust — PIPA requires covered entities to implement reasonable procedures for the proper disposal of records containing personal information to prevent unauthorized access to or use of the information.observed
No sub-module has any state-level content; all rely on absent_field_provenance.
Traffic-light rationale — RedNo sub-module has any state-level content; all rely on absent_field_provenance.
Sub-modules (6)
Transfer MechanismsRed
No state-level transfer mechanism regime exists.
Absence provenance: unavailable. Searched: Arkansas cross-border data transfer mechanism.
Claims (1):
Arkansas has no data-localisation mandate or state-level cross-border data-transfer mechanism (adequacy, SCCs, BCRs, or transfer-impact-assessment requirement) applicable to personal data generally, in the absence of a comprehensive consumer-privacy statute.
Adequacy ReceivedRed
Not applicable; Arkansas is a sub-national US jurisdiction and does not receive adequacy determinations.
Arkansas has no data-localisation mandate or state-level cross-border data-transfer mechanism (adequacy, SCCs, BCRs, or transfer-impact-assessment requirement) applicable to personal data generally, in the absence of a comprehensive consumer-privacy statute.
Transfer Impact AssessmentRed
No TIA requirement exists under Arkansas law.
Absence provenance: unavailable. Searched: Arkansas transfer impact assessment.
Claims (1):
Arkansas has no data-localisation mandate or state-level cross-border data-transfer mechanism (adequacy, SCCs, BCRs, or transfer-impact-assessment requirement) applicable to personal data generally, in the absence of a comprehensive consumer-privacy statute.
Data LocalisationRed
No data-localisation mandate exists under Arkansas law.
Absence provenance: unavailable. Searched: Arkansas data localisation requirement.
Claims (1):
Arkansas has no data-localisation mandate or state-level cross-border data-transfer mechanism (adequacy, SCCs, BCRs, or transfer-impact-assessment requirement) applicable to personal data generally, in the absence of a comprehensive consumer-privacy statute.
Category narrative25 words
In the absence of a comprehensive consumer-privacy statute, Arkansas has no state-level cross-border transfer-mechanism, adequacy, SCC/BCR, transfer-impact-assessment, or data-localisation regime applicable to personal data generally.
Sources and claims (1)
ConfirmedInternational Association of Privacy Professionals — Arkansas has no data-localisation mandate or state-level cross-border data-transfer mechanism (adequacy, SCCs, BCRs, or transfer-impact-assessment requirement) applicable to personal data generally, in the absence of a comprehensive consumer-privacy statute.observed
Several narrow, real sectoral overlays exist and are enforced, but broad sectors (employment, credit, education) have no state-specific coverage beyond federal baselines.
Traffic-light rationale — AmberSeveral narrow, real sectoral overlays exist and are enforced, but broad sectors (employment, credit, education) have no state-specific coverage beyond federal baselines.
Sub-modules (7)
Financial Sector OverlayAmber
Act 557 imposes data-security-program and incident-response-plan requirements on virtual-currency businesses.
Claims (1):
Arkansas Act 557 imposes data-security-program and incident-response-plan requirements on virtual-currency businesses operating in the state, supplementing the general PIPA security baseline for this sector.
Health Sector OverlayAmber
Health-sector personal information in Arkansas is governed primarily by the federal HIPAA framework in the absence of an independent state health-privacy statute.
Claims (1):
Health-sector personal information in Arkansas is governed primarily by the federal Health Insurance Portability and Accountability Act, as Arkansas has no independent comprehensive state health-privacy statute displacing HIPAA.
Telecoms And EprivacyAmber
The Arkansas Consumer Telephone Privacy Act establishes telemarketing restrictions and a state-wide Do-Not-Call database.
Claims (1):
The Arkansas Consumer Telephone Privacy Act, Ark. Code Ann. § 4-99-401 et seq., sets out telemarketing requirements and establishes a state-wide Do-Not-Call database.
Employment DataRed
No independent Arkansas employment-data-privacy statute was identified.
Absence provenance: unavailable. Searched: Arkansas employment data privacy statute.
Claims (1):
No independent Arkansas statute governs employment-data privacy, credit-scoring privacy, or education-data privacy beyond the general breach-notification baseline and applicable federal overlays (FCRA, FERPA).
Credit And ScoringRed
Credit and scoring data reliance is on the federal Fair Credit Reporting Act; no independent state credit-scoring privacy statute was identified.
No independent Arkansas statute governs employment-data privacy, credit-scoring privacy, or education-data privacy beyond the general breach-notification baseline and applicable federal overlays (FCRA, FERPA).
EducationRed
Education data reliance is on the federal FERPA; no independent Arkansas education-privacy statute beyond general breach law was identified.
Absence provenance: unavailable. Searched: Arkansas student data privacy statute.
Claims (1):
No independent Arkansas statute governs employment-data privacy, credit-scoring privacy, or education-data privacy beyond the general breach-notification baseline and applicable federal overlays (FCRA, FERPA).
InsuranceAmber
House Bill 1297 regulates AI use in health-insurance decision-making, mandating transparency and quality-assurance requirements.
Claims (1):
Arkansas House Bill 1297 regulates the use of artificial intelligence in health-insurance decision-making, mandating transparency and quality-assurance requirements for AI algorithms used by insurers.
Category narrative58 words
Arkansas layers a small number of sector-specific instruments atop the general breach-notification baseline: Act 557 (virtual-currency data-security programs), the Arkansas Consumer Telephone Privacy Act (telemarketing/Do-Not-Call), and HB1297 (AI transparency in health-insurance decision-making). Health-sector personal information otherwise relies on the federal HIPAA overlay; credit-scoring and education data rely on federal FCRA/FERPA overlays; no independent state employment-data statute was identified.
Sources and claims (5)
ProbableDataGuidance/OneTrust — Arkansas Act 557 imposes data-security-program and incident-response-plan requirements on virtual-currency businesses operating in the state, supplementing the general PIPA security baseline for this sector.observed
ProbableFederal Trade Commission — Health-sector personal information in Arkansas is governed primarily by the federal Health Insurance Portability and Accountability Act, as Arkansas has no independent comprehensive state health-privacy statute displacing HIPAA.observed
ConfirmedDataGuidance/OneTrust — The Arkansas Consumer Telephone Privacy Act, Ark. Code Ann. § 4-99-401 et seq., sets out telemarketing requirements and establishes a state-wide Do-Not-Call database.observed
ConfirmedInternational Association of Privacy Professionals — No independent Arkansas statute governs employment-data privacy, credit-scoring privacy, or education-data privacy beyond the general breach-notification baseline and applicable federal overlays (FCRA, FERPA).observed
ProbableDataGuidance/OneTrust — Arkansas House Bill 1297 regulates the use of artificial intelligence in health-insurance decision-making, mandating transparency and quality-assurance requirements for AI algorithms used by insurers.observed
General adtech sub-modules (cookies, dark patterns, opt-out signals, clean rooms) are entirely absent; only narrow minors-advertising and telemarketing suppression rules exist.
Arkansas has no general cookie/tracker consent law, dark-pattern prohibition, opt-out-signal recognition mandate, or clean-room regulation.
Dark PatternsRed
No dark-pattern prohibition statute exists.
Absence provenance: unavailable. Searched: Arkansas dark patterns statute.
Claims (1):
Arkansas has no general cookie/tracker consent law, dark-pattern prohibition, opt-out-signal recognition mandate, or clean-room regulation.
Opt Out SignalsRed
No Global Privacy Control or opt-out-signal recognition mandate exists.
Absence provenance: unavailable. Searched: Arkansas Global Privacy Control requirement.
Claims (1):
Arkansas has no general cookie/tracker consent law, dark-pattern prohibition, opt-out-signal recognition mandate, or clean-room regulation.
Clean Rooms And DcrRed
No clean-room/data-collaboration-room regulation exists.
Absence provenance: unavailable. Searched: Arkansas data clean room regulation.
Claims (1):
Arkansas has no general cookie/tracker consent law, dark-pattern prohibition, opt-out-signal recognition mandate, or clean-room regulation.
Cross Context AdvertisingAmber
HB1717 prohibits covered operators from engaging in targeted/cross-context advertising directed at minors, effective July 1, 2026.
Claims (1):
The Arkansas Children and Teens' Online Privacy Protection Act (HB1717) prohibits covered operators from engaging in targeted advertising directed at minors, effective July 1, 2026.
Direct MarketingAmber
The Arkansas Consumer Telephone Privacy Act provides a Do-Not-Call suppression mechanism for telemarketing.
Claims (1):
The Arkansas Consumer Telephone Privacy Act establishes a state-wide Do-Not-Call database that functions as a direct-marketing suppression mechanism for telemarketing calls.
Category narrative46 words
Arkansas has no general cookie/tracker consent law, dark-pattern prohibition, opt-out-signal mandate, or clean-room regulation. The main commercial-privacy overlays are minors-specific: HB1717 bans targeted advertising directed at minors (effective July 1, 2026), and the Consumer Telephone Privacy Act provides a direct-marketing suppression mechanism via the Do-Not-Call database.
Sources and claims (3)
ConfirmedInternational Association of Privacy Professionals — Arkansas has no general cookie/tracker consent law, dark-pattern prohibition, opt-out-signal recognition mandate, or clean-room regulation.observed
ConfirmedDataGuidance/OneTrust — The Arkansas Children and Teens' Online Privacy Protection Act (HB1717) prohibits covered operators from engaging in targeted advertising directed at minors, effective July 1, 2026.observed
ConfirmedDataGuidance/OneTrust — The Arkansas Consumer Telephone Privacy Act establishes a state-wide Do-Not-Call database that functions as a direct-marketing suppression mechanism for telemarketing calls.observed
Only one confirmed sectoral ADM-transparency obligation exists; profiling, biometric, genetic, and surveillance-carveout sub-modules are absent or unconfirmed.
Traffic-light rationale — RedOnly one confirmed sectoral ADM-transparency obligation exists; profiling, biometric, genetic, and surveillance-carveout sub-modules are absent or unconfirmed.
Sub-modules (6)
Profiling RestrictionsRed
No general profiling-restriction statute analogous to GDPR Art. 22 exists for the general population under Arkansas law.
Arkansas has no general statutory restriction on automated profiling of the general population comparable to GDPR Article 22.
Automated Decision Making TransparencyAmber
HB1297 mandates transparency and quality-assurance requirements for AI algorithms used in health-insurance decision-making.
Claims (1):
Arkansas House Bill 1297 mandates transparency and quality-assurance requirements for AI algorithms used by health insurers in coverage decision-making.
Ai Risk AssessmentsAmber
Arkansas Senate Bill 258 addresses AI and data protection, focused on high-risk AI systems and impact assessments, but its enactment status could not be confirmed.
Claims (1):
Arkansas Senate Bill 258 addresses AI and data protection, focusing on high-risk AI systems and their impact assessments; whether the bill has been enacted into law could not be confirmed from available sources.
Biometric RegimeRed
No dedicated biometric-data statute (comparable to Illinois BIPA) was identified in Arkansas.
Absence provenance: unavailable. Searched: Arkansas biometric information privacy act.
Claims (1):
No dedicated biometric-data or genetic-data statute, and no Arkansas-specific state-surveillance carve-out statute, was identified.
Genetic DataRed
No dedicated genetic-data statute was identified in Arkansas.
No dedicated biometric-data or genetic-data statute, and no Arkansas-specific state-surveillance carve-out statute, was identified.
State Surveillance CarveoutsRed
No Arkansas-specific state-surveillance carve-out statute was identified beyond generally applicable federal national-security exemptions.
Absence provenance: unavailable. Searched: Arkansas state surveillance carveout statute.
Claims (1):
No dedicated biometric-data or genetic-data statute, and no Arkansas-specific state-surveillance carve-out statute, was identified.
Category narrative44 words
Arkansas has no general profiling-restriction, biometric-data, or genetic-data statute. Sector-specific AI-transparency obligations exist in health insurance (HB1297); a broader AI/high-risk-system impact-assessment bill (SB258) has been introduced but its enactment status is unconfirmed. No state-specific surveillance carve-out beyond generally applicable federal national-security exemptions was identified.
ProbableDataGuidance/OneTrust — Arkansas House Bill 1297 mandates transparency and quality-assurance requirements for AI algorithms used by health insurers in coverage decision-making.observed
UncertainDataGuidance/OneTrust — Arkansas Senate Bill 258 addresses AI and data protection, focusing on high-risk AI systems and their impact assessments; whether the bill has been enacted into law could not be confirmed from available sources.observed
ConfirmedInternational Association of Privacy Professionals — No dedicated biometric-data or genetic-data statute, and no Arkansas-specific state-surveillance carve-out statute, was identified.observed
Meaningful minors-specific coverage exists (age verification, prospective ad-targeting ban) but the flagship consent mechanism (Social Media Safety Act) is unenforceable, and education/dependent-adult sub-modules are absent.
Primary frameworkArkansas Children and Teens' Online Privacy Protection Act (HB1717); Protection of Minors from Distribution of Harmful Material Act (Act 612)
Traffic-light rationale — AmberMeaningful minors-specific coverage exists (age verification, prospective ad-targeting ban) but the flagship consent mechanism (Social Media Safety Act) is unenforceable, and education/dependent-adult sub-modules are absent.
Sub-modules (5)
Age VerificationAmber
Act 612 requires age-verification methods for websites containing a substantial portion of material harmful to minors.
Claims (1):
Arkansas's Protection of Minors from the Distribution of Harmful Material Act requires age-verification methods before allowing access to a website containing a substantial portion of material that is harmful to minors.
Parental ConsentRed
The Social Media Safety Act's parental-consent requirement for minors under 18 was enjoined and later ruled unconstitutional; it is not currently enforceable.
Claims (1):
The Arkansas Social Media Safety Act (SB396), which would have required age verification and parental consent for minors under 18 to use social media platforms, was enjoined by the U.S. District Court for the Western District of Arkansas and subsequently held unconstitutional on First and Fourteenth Amendment grounds; its consent mechanism is not currently enforceable.
Minor Profiling BansAmber
HB1717 prohibits targeted advertising and mandates data-management practices for minors' data, effective July 1, 2026.
Claims (1):
The Arkansas Children and Teens' Online Privacy Protection Act (HB1717), effective July 1, 2026, prohibits covered operators from collecting personal data from minors for targeted-advertising purposes and mandates specific data-management practices.
Education SettingsRed
No Arkansas education-settings-specific data-protection statute beyond federal FERPA was identified.
Absence provenance: unavailable. Searched: Arkansas student data privacy law.
Claims (1):
No Arkansas education-settings-specific data-protection statute beyond the federal Family Educational Rights and Privacy Act was identified.
Dependent AdultsRed
No Arkansas dependent-adults data-protection statute was identified; the SAFER AR Act addresses financial-exploitation reporting duties for Adult Protective Services but is not a data-protection statute.
Absence provenance: unavailable. Searched: Arkansas dependent adult data protection statute, Arkansas elder data privacy law.
Claims (1):
No Arkansas data-protection-specific statute for dependent adults was identified; the state's SAFER AR Act creates a financial-exploitation reporting duty for Adult Protective Services but does not create data-protection rights or obligations.
Category narrative81 words
Arkansas has an active legislative program on minors' data: Act 612 (Protection of Minors from Distribution of Harmful Material Act) mandates age verification for adult-content websites; HB1717 (Children and Teens' Online Privacy Protection Act) bans targeted advertising/profiling-adjacent data use for minors from July 1, 2026; the Social Media Safety Act's parental-consent mechanism was struck down as unconstitutional. No education-settings-specific or dependent-adults-specific data-protection statute was identified (the SAFER AR Act addresses financial-exploitation reporting for vulnerable adults but is not a data-protection statute).
Sources and claims (3)
ConfirmedDataGuidance/OneTrust — Arkansas's Protection of Minors from the Distribution of Harmful Material Act requires age-verification methods before allowing access to a website containing a substantial portion of material that is harmful to minors.observed
ProbableInternational Association of Privacy Professionals — No Arkansas education-settings-specific data-protection statute beyond the federal Family Educational Rights and Privacy Act was identified.observed
ProbableNAAG — No Arkansas data-protection-specific statute for dependent adults was identified; the state's SAFER AR Act creates a financial-exploitation reporting duty for Adult Protective Services but does not create data-protection rights or obligations.observed
Active, well-documented AG enforcement exists, but redress avenues for individuals (private right of action, class actions) are unconfirmed/absent, and regulator capacity appears limited relative to its broad portfolio.
Primary frameworkArkansas Personal Information Protection Act; Arkansas Deceptive Trade Practices Act
Traffic-light rationale — AmberActive, well-documented AG enforcement exists, but redress avenues for individuals (private right of action, class actions) are unconfirmed/absent, and regulator capacity appears limited relative to its broad portfolio.
Sub-modules (6)
Regulator Powers And PenaltiesGreen
The Attorney General holds the power to sanction PIPA violations and issue penalties; the Deceptive Trade Practices Act supplies broader civil-penalty authority used for privacy-adjacent enforcement.
Claims (1):
The Arkansas Attorney General holds the power to sanction violations of the Personal Information Protection Act and issue penalties.
Enforcement Activity IndexGreen
AG Griffin has brought or continued multiple 2024-2026 enforcement actions touching data privacy (TikTok, Meta, Temu, Google, GM).
Claims (1):
Arkansas Attorney General Tim Griffin has pursued active enforcement in 2024-2026 targeting privacy-adjacent deceptive practices, including suits against TikTok/ByteDance, Meta, and Temu based on Arkansans' personal information.
Regulator Funding And CapacityAmber
The AG's Consumer Protection Division is described as a small team managing a broad portfolio including privacy.
Claims (1):
The Consumer Protection Division of the Arkansas Attorney General's Office is described as a small team of lawyers and investigators managing antitrust, tobacco, charities enforcement, privacy, and other deceptive-trade-practices matters.
Collective Redress And Class ActionsRed
No confirmed data-protection-specific class-action mechanism was identified; enforcement is AG-driven.
Absence provenance: unavailable. Searched: Arkansas data breach class action mechanism.
Claims (1):
No Arkansas data-protection-specific collective-redress or class-action mechanism was identified; available enforcement is Attorney-General-driven.
Private Right Of ActionRed
PIPA does not appear to grant Arkansas consumers a private right of action; enforcement rests with the Attorney General.
Claims (1):
The Personal Information Protection Act does not grant Arkansas consumers an express private right of action; enforcement authority rests with the Attorney General.
Recent Developments 180DAmber
Within the last 180 days, the Social Media Safety Act was held unconstitutional and the Children and Teens' Online Privacy Protection Act's July 1, 2026 effective date approached/occurred.
Claims (1):
Within the recent reporting window, Arkansas courts held the Social Media Safety Act unconstitutional on First and Fourteenth Amendment grounds, and the Children and Teens' Online Privacy Protection Act's July 1, 2026 effective date approached.
Category narrative77 words
The Arkansas Attorney General holds sanction and penalty power under PIPA and the Deceptive Trade Practices Act and has been highly active in 2024-2026, bringing or continuing enforcement actions against TikTok, Meta, Temu, Google, and General Motors over privacy-adjacent deceptive practices. Enforcement is AG-driven; no confirmed private right of action or class-action mechanism specific to data-protection claims was identified. The Consumer Protection Division is described as a small team covering privacy alongside antitrust, tobacco, and charities enforcement.
Sources and claims (6)
ConfirmedDataGuidance/OneTrust — The Arkansas Attorney General holds the power to sanction violations of the Personal Information Protection Act and issue penalties.observed
ConfirmedInternational Association of Privacy Professionals — Arkansas Attorney General Tim Griffin has pursued active enforcement in 2024-2026 targeting privacy-adjacent deceptive practices, including suits against TikTok/ByteDance, Meta, and Temu based on Arkansans' personal information.observed
ProbableNAAG — The Consumer Protection Division of the Arkansas Attorney General's Office is described as a small team of lawyers and investigators managing antitrust, tobacco, charities enforcement, privacy, and other deceptive-trade-practices matters.observed
ProbableInternational Association of Privacy Professionals — No Arkansas data-protection-specific collective-redress or class-action mechanism was identified; available enforcement is Attorney-General-driven.observed
ProbableDataGuidance/OneTrust — The Personal Information Protection Act does not grant Arkansas consumers an express private right of action; enforcement authority rests with the Attorney General.observed
ConfirmedDataGuidance/OneTrust — Within the recent reporting window, Arkansas courts held the Social Media Safety Act unconstitutional on First and Fourteenth Amendment grounds, and the Children and Teens' Online Privacy Protection Act's July 1, 2026 effective date approached.observed
No categories match.
Filters combine as OR inside a group and AND across
groups.
Publication gate
Blocking. 3 failing check(s).
schema_valid
pass
min_architecture_patterns
0
min_red_flags
0
min_controls
0
worked_examples_count
0
decision_tree_nodes
0
counterparty_diligence_questions
0
min_t1_per_instrument_met
n/a — no subject in this jurisdiction
min_quoted_text_present
waived — floor 0%
translation_provenance_recorded
n/a — no subject in this jurisdiction
egress_verified
pass
board_briefing_present
FAIL
every_practical_object_has_source_id
FAIL
source_tier_integrity_ok
pass
jurisdiction_source_floor_met
FAIL
tier_a_b_national_primary_pct
0.0
aggregator_only_jurisdiction_count
0
manual_override
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for Arkansas, USA
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
no reviewer on record
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 41 claim(s) (41 category placement(s)), 14 source(s) in the cumulative register.
Audit trail
Machine checkChallenged on 29 Sep 2026: nothing tested (no claim on this page was eligible for an automated test). An automated, adversarial test run by a second model; no person has assessed the result.
All 10 modules were researched and populated. Coverage is strongest (T1/T2-anchored) for regulator_and_framework and controller_processor_duties (PIPA breach-notification/security text, AG enforcement authority), relying on the seed T1 anchor (NAAG/PIPA) plus T3 secondary aggregators (DataGuidance, IAPP) for corroboration and detail not in the seed. Modules lawful_processing_and_special_data, data_subject_rights, and cross_border_and_adequacy are correctly thin/red, reflecting the genuine absence of an omnibus statute per the seed disambiguation, and are supported primarily by T3 sources describing that absence plus explicit absent_field_provenance. sectoral_watch, adtech_and_commercial_privacy, algorithmic_biometric_and_surveillance_governance, and children_and_vulnerable_groups rely mostly on T3 (DataGuidance/IAPP) reporting of recent 2025-2026 Arkansas acts and bills (HB1717, Act 612, Act 557, HB1297, SB258, Social Media Safety Act litigation); none of these were verified against primary Arkansas Code or Arkansas General Assembly bill-tracking text directly, since those hostnames were not confirmed on the retrieval allowlist.
Unresolved questions (5):
Exact effective date and current in-force status of Act 557 (virtual-currency data-security requirements) could not be confirmed beyond 'signed by Governor' reporting.
Enactment status of Senate Bill 258 (AI/high-risk-system impact assessments) is unconfirmed — reporting describes the bill's focus but not a signed/enacted outcome.
Precise effective date of Act 612 (Protection of Minors from Distribution of Harmful Material Act) age-verification requirement was not independently confirmed beyond 'became law' reporting from 2023.
Whether HB1297 (AI in health-insurance decision-making) has an enactment/effective date beyond legislative reporting was not confirmed.
Whether the Arkansas Deceptive Trade Practices Act contains an express private right of action for privacy-adjacent claims was not independently verified against primary statutory text.