Not publishable as-is. 3 of 7 publication_gate checks fail. The renderer displays the gate rather than suppressing it. Legal review and sub-brief approval are informational and are not part of this test.
Based mainly on secondary sources. Only 1 of the sources retrieved for this jurisdiction is official or direct reporting of official material (tier 1 or 2), against the 3 we look for. No finding on this page is shown with confidence above “Uncertain” until stronger sources are retrieved.
Nevada, USA
US-NVschema gdpri-v2trajectory: not yet assessedregulated (sectoral)overlaps: FIM, WPM, AIC
Last updated update date not yet available · 10 categories · 24
claims · 18 sources in the cumulative register
10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
24Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix(sums to 10 rendered categories; click to filter)
No red categories; 36 sub-modules are flagged red.
Jurisdiction brief
No content recorded at this JID path.
10 of 10 categories
Signal
Density
Selections OR within a group, AND across groups. Press / to search.
A real, in-force statutory floor exists (breach notification + two narrow sectoral add-ons) but there is no comprehensive material/territorial scope comparable to an omnibus regime.
Primary frameworkNRS Chapter 603A (Security and Privacy of Personal Information), as amended by SB 220 (2019) and SB 370 (2023)
Traffic-light rationale — AmberA real, in-force statutory floor exists (breach notification + two narrow sectoral add-ons) but there is no comprehensive material/territorial scope comparable to an omnibus regime.
Sub-modules (5)
Regulator And AuthorityGreen
The Nevada Attorney General is the sole enforcement authority for NRS 603A, SB 220, and SB 370; there is no dedicated privacy regulator or rulemaking agency comparable to the CPPA.
Claims (1):
The Nevada Attorney General is the exclusive enforcement authority for Nevada's opt-out-of-sale statute (SB 220), with power to bring district-court proceedings and impose civil penalties of up to $5,000 per violation.
Act And InstrumentsAmber
The operative instruments are NRS Chapter 603A (breach notification and records destruction), SB 220 (opt-out-of-sale), and SB 370 (consumer health data). None is comprehensive in the CCPA/GDPR sense.
Claims (1):
Unlike the California Consumer Privacy Act, Nevada's SB 220 is not a comprehensive privacy statute: it does not provide proportional data-portability rights and lacks an explicit anti-discrimination clause for consumers who opt out.
Material ScopeAmber
Material scope is defined narrowly and instrument-by-instrument: SB 220 covers 'covered information' collected via a website/online service; SB 370 covers 'consumer health data'; NRS 603A's breach provisions cover a separate, narrower 'personal information' definition.
Claims (1):
SB 220's 'covered information' is defined in NRS 603A.320 to include name, physical address, email address, telephone number, Social Security number, an online/physical contact identifier, and other information maintained in combination with such an identifier.
Territorial ScopeAmber
SB 220 applies extraterritorially to any operator of an online service (in or outside Nevada) that purposefully directs activity toward, or has sufficient constitutional nexus with, Nevada residents, but does not reach offline conduct.
Claims (1):
SB 220 applies to any operator of an online service, whether located inside or outside Nevada, that purposefully directs activity toward the state or otherwise has sufficient constitutional nexus, but does not apply to offline commercial activity.
Regulator Registration And FilingRed
No general controller-registration or filing obligation exists under current Nevada law. A 2025 bill (SB 199) would have required AI companies to register with the Bureau of Consumer Protection, but its enactment status could not be confirmed in this research pass.
Claims (1):
Nevada Senate Bill 199 (introduced February 11, 2025) would require AI companies operating in Nevada to register with the Bureau of Consumer Protection and conduct semi-annual self-assessments; enactment status is unconfirmed as of this research pass.
Category narrative85 words
Nevada has no comprehensive omnibus consumer-privacy statute equivalent to the GDPR or the CCPA. The state's data-protection footprint is a narrow sectoral patchwork built on NRS Chapter 603A (Security and Privacy of Personal Information), which combines a data-breach-notification/records-destruction regime with two narrower consumer-facing add-ons: SB 220 (2019, opt-out-of-sale for online 'covered information') and SB 370 (2023/2024, consumer health data). Enforcement of all three strands sits exclusively with the Nevada Attorney General. Federal sectoral law (FTC Act Section 5, HIPAA, GLBA, COPPA) supplies the remaining backstop.
Sources and claims (5)
UncertainInternational Association of Privacy Professionals — The Nevada Attorney General is the exclusive enforcement authority for Nevada's opt-out-of-sale statute (SB 220), with power to bring district-court proceedings and impose civil penalties of up to $5,000 per violation.observed
UncertainInternational Association of Privacy Professionals — Unlike the California Consumer Privacy Act, Nevada's SB 220 is not a comprehensive privacy statute: it does not provide proportional data-portability rights and lacks an explicit anti-discrimination clause for consumers who opt out.observed
UncertainInternational Association of Privacy Professionals — SB 220's 'covered information' is defined in NRS 603A.320 to include name, physical address, email address, telephone number, Social Security number, an online/physical contact identifier, and other information maintained in combination with such an identifier.observed
UncertainInternational Association of Privacy Professionals — SB 220 applies to any operator of an online service, whether located inside or outside Nevada, that purposefully directs activity toward the state or otherwise has sufficient constitutional nexus, but does not apply to offline commercial activity.observed
UncertainDataGuidance — Nevada Senate Bill 199 (introduced February 11, 2025) would require AI companies operating in Nevada to register with the Bureau of Consumer Protection and conduct semi-annual self-assessments; enactment status is unconfirmed as of this research pass.observed
Sensitive-category and consent-adjacent rules exist only within the narrow consumer-health-data statute; there is no general Article 6/Article 7-style regime.
Primary frameworkSB 370 (Nevada consumer health data law), NRS Chapter 603A
Traffic-light rationale — AmberSensitive-category and consent-adjacent rules exist only within the narrow consumer-health-data statute; there is no general Article 6/Article 7-style regime.
Sub-modules (4)
Lawful BasesRed
No general enumerated lawful-basis scheme exists outside SB 370's health-data-specific necessity standard.
Absence provenance: unavailable. Searched: Nevada data breach notification statute NRS 603A, Nevada SB 220 online sale opt-out privacy law 2019.
Consent ThresholdsAmber
SB 370 permits collection/sharing of consumer health data without explicit consent only where 'necessary' to fulfil a consumer's request; neither SB 370 nor Washington's MHMDA (its model) defines 'necessary.'
Claims (1):
Under SB 370, entities may collect and share consumer health data for purposes 'necessary' to meet a consumer's request without obtaining explicit consent, but neither SB 370 nor its Washington model law defines what qualifies as 'necessary.'
Special CategoriesAmber
SB 370 treats data on sexual activity, gender identity, reproductive health, and mental health as especially sensitive 'consumer health data' warranting conservative collection and sharing practices.
Claims (1):
SB 370 was explicitly drafted to address discrimination, stigma and harm risks associated with data on sexual activity, gender identity, reproductive health, and mental health, requiring conservative collection and sharing of such data.
Pseudonymisation And AnonymisationRed
No Nevada-specific statutory pseudonymisation/anonymisation safe harbour was identified in this research pass.
Nevada has no general enumerated lawful-basis framework for ordinary commercial data processing. The only codified consent/sensitive-data regime is SB 370's treatment of 'consumer health data' (modeled on Washington's My Health My Data Act), which restricts collection/sharing to purposes 'necessary' to a consumer request absent consent and singles out highly sensitive health-adjacent categories.
Sources and claims (2)
UncertainInternational Association of Privacy Professionals — Under SB 370, entities may collect and share consumer health data for purposes 'necessary' to meet a consumer's request without obtaining explicit consent, but neither SB 370 nor its Washington model law defines what qualifies as 'necessary.'observed
UncertainInternational Association of Privacy Professionals — SB 370 was explicitly drafted to address discrimination, stigma and harm risks associated with data on sexual activity, gender identity, reproductive health, and mental health, requiring conservative collection and sharing of such data.observed
Traffic-light rationale — AmberA narrow, single-purpose opt-out right with a defined response deadline exists; the broader DSR bundle (access/erasure/portability) is absent.
Sub-modules (5)
Access RightRed
No general right of access to personal data exists under Nevada law; SB 220 is limited to a sale opt-out and does not create an access right.
Absence provenance: unavailable. Searched: Nevada SB 220 online sale opt-out privacy law 2019.
Rectification And ErasureRed
No statutory right to rectification or erasure ('right to be forgotten') exists under Nevada consumer-privacy law.
Absence provenance: unavailable. Searched: Nevada SB 220 online sale opt-out privacy law 2019, Nevada SB 370 2021 privacy law amendment health data.
Restriction And ObjectionAmber
The only restriction-type right is SB 220's consumer right to direct an operator, via a verified request, not to sell covered information.
Claims (1):
SB 220 provides Nevada consumers with the ability to submit a verified request directing an operator not to sell certain covered information collected via a website or online service.
Data PortabilityRed
No data-portability right exists under current Nevada statute.
Absence provenance: unavailable. Searched: Nevada SB 220 online sale opt-out privacy law 2019.
Deadlines And Response WindowsGreen
SB 220 sets a 60-day response window for verified opt-out requests, extendable by up to 30 additional days with notice to the consumer.
Claims (1):
Operators receiving a verified opt-out request under SB 220 must respond within 60 days of receipt, with an available 30-day extension if the operator determines it reasonably necessary and notifies the consumer.
Category narrative64 words
Nevada does not grant a general bundle of data-subject rights (access, rectification, erasure, portability). The only individual-facing rights are (i) SB 220's right to opt out of the 'sale' of covered information, subject to a 60-day (extendable) response window, and (ii) SB 370's more limited consumer-health-data protections. There is no statutory right of access, rectification, erasure, restriction of processing, or portability comparable to CCPA/GDPR.
Sources and claims (2)
UncertainInternational Association of Privacy Professionals — SB 220 provides Nevada consumers with the ability to submit a verified request directing an operator not to sell certain covered information collected via a website or online service.observed
UncertainInternational Association of Privacy Professionals — Operators receiving a verified opt-out request under SB 220 must respond within 60 days of receipt, with an available 30-day extension if the operator determines it reasonably necessary and notifies the consumer.observed
Security and breach-notification duties are well-established and enforced; accountability-style duties (DPIA, DPO, ROPA, joint controllership) are entirely absent.
Primary frameworkNRS Chapter 603A (Security and Privacy of Personal Information)
NRS Chapter 603A imposes a general duty on data collectors to implement and maintain reasonable security measures to protect personal information from unauthorized access, acquisition, destruction, use, modification, or disclosure.
Claims (1):
Nevada's Privacy and Security of Personal Information chapter (NRS 603A) imposes a statutory duty on data collectors to implement and maintain reasonable security measures to protect personal information they maintain.
Breach NotificationGreen
NRS 603A.220 requires notification of affected Nevada residents following a security breach; the Attorney General's office reports it investigates breaches affecting a large number of Nevadans and recommends businesses err on the side of notifying the AG's office.
Claims (1):
When the Nevada Attorney General's office receives notice of a data breach that may impact a large number of Nevadans, it conducts an investigation, typically with the assistance of the affected company, into how the breach occurred and what security measures were in place.
Retention And DisposalAmber
NRS 603A.200 imposes a records-destruction obligation for certain records containing personal information; detailed operative text could not be retrieved due to source access limitations.
Claims (1):
NRS 603A.200 establishes a statutory obligation regarding destruction of certain records containing personal information in Nevada.
Category narrative53 words
Nevada imposes statutory duties centred on data security and breach notification (NRS Chapter 603A) rather than a full accountability/DPIA/DPO/ROPA framework. There is a records-destruction obligation (NRS 603A.200) and a breach-notification obligation (NRS 603A.220), with the Attorney General actively investigating breaches affecting large numbers of Nevadans. No DPIA, DPO-appointment, ROPA, or joint-controller regime exists.
Sources and claims (3)
UncertainDataGuidance — Nevada's Privacy and Security of Personal Information chapter (NRS 603A) imposes a statutory duty on data collectors to implement and maintain reasonable security measures to protect personal information they maintain.observed
UncertainInternational Association of Privacy Professionals — When the Nevada Attorney General's office receives notice of a data breach that may impact a large number of Nevadans, it conducts an investigation, typically with the assistance of the affected company, into how the breach occurred and what security measures were in place.observed
UncertainDataGuidance — NRS 603A.200 establishes a statutory obligation regarding destruction of certain records containing personal information in Nevada.observed
Complete absence of a state-level cross-border/adequacy/localisation regime; this is a legitimate finding rather than a research gap.
Traffic-light rationale — Not assessedComplete absence of a state-level cross-border/adequacy/localisation regime; this is a legitimate finding rather than a research gap.
Sub-modules (6)
Transfer MechanismsRed
No Nevada-specific transfer mechanism (adequacy, SCCs, BCRs, derogations) exists in state law.
Absence provenance: unavailable. Searched: Nevada data breach notification statute NRS 603A, Nevada SB 220 online sale opt-out privacy law 2019, Nevada SB 370 2021 privacy law amendment health data.
Adequacy ReceivedRed
Not applicable; US states do not receive adequacy decisions independently of federal frameworks, and none was found for Nevada.
No Nevada-specific cross-border transfer regime, adequacy mechanism, SCC/BCR analogue, transfer-impact-assessment requirement, or data-localisation mandate was identified. As a US state operating under a federal system with no comprehensive omnibus privacy law, Nevada has not legislated in this area; any cross-border data-flow considerations for Nevada-linked processing arise from federal law or contractual practice, not from state statute.
Traffic-light rationale — AmberFinancial and health overlays are well documented; five of seven sub-modules have no identified Nevada-specific content.
Sub-modules (7)
Financial Sector OverlayAmber
SB 220 excludes from its 'operator' definition third parties that operate, host, or manage a website or service on behalf of a financial institution (or its affiliates) subject to the Gramm-Leach-Bliley Act.
Claims (1):
SB 220 amends the definition of 'operator' to exclude a third party that operates, hosts, or manages a website or online service on behalf of a financial institution, or its affiliates, subject to the Gramm-Leach-Bliley Act.
Health Sector OverlayAmber
SB 370 (Nevada consumer health data law), modeled on Washington's My Health My Data Act, took effect March 31, 2024; SB 220 separately excludes HIPAA-regulated entities from its 'operator' definition.
Claims (2):
Nevada's SB 370, a consumer health data privacy law modeled on Washington's My Health My Data Act, received final legislative passage and took effect March 31, 2024, and unlike the Washington law does not carry a private right of action.
SB 220 excludes from its 'operator' definition entities subject to the Health Insurance Portability and Accountability Act (HIPAA), avoiding duplicative obligations for HIPAA-regulated entities.
Telecoms And EprivacyRed
No Nevada-specific telecoms/ePrivacy overlay (e.g., cookie-consent statute) was identified.
Absence provenance: unavailable. Searched: Nevada SB 220 online sale opt-out privacy law 2019.
Employment DataRed
No Nevada-specific employment-data privacy overlay was identified.
Two sectoral overlays are confirmed for Nevada: (i) a financial-sector carve-out under SB 220, which excludes GLBA-regulated financial institutions and their affiliates/third parties from the 'operator' definition, and (ii) a dedicated health-sector overlay, SB 370, Nevada's consumer health data law modeled on Washington's My Health My Data Act, effective March 31, 2024, which also exempts HIPAA-regulated entities from SB 220's 'operator' definition. No Nevada-specific telecoms/ePrivacy, employment, credit-scoring, education, or insurance overlay was identified.
Sources and claims (3)
UncertainInternational Association of Privacy Professionals — SB 220 amends the definition of 'operator' to exclude a third party that operates, hosts, or manages a website or online service on behalf of a financial institution, or its affiliates, subject to the Gramm-Leach-Bliley Act.observed
UncertainInternational Association of Privacy Professionals — Nevada's SB 370, a consumer health data privacy law modeled on Washington's My Health My Data Act, received final legislative passage and took effect March 31, 2024, and unlike the Washington law does not carry a private right of action.observed
UncertainInternational Association of Privacy Professionals — SB 220 excludes from its 'operator' definition entities subject to the Health Insurance Portability and Accountability Act (HIPAA), avoiding duplicative obligations for HIPAA-regulated entities.observed
Traffic-light rationale — AmberA narrow sale-opt-out and cross-context 'sale' definition exist; most other adtech sub-domains are unaddressed by Nevada statute.
Sub-modules (6)
Cookies And TrackersRed
No Nevada-specific cookie or tracker consent statute was identified.
Absence provenance: unavailable. Searched: Nevada SB 220 online sale opt-out privacy law 2019.
Dark PatternsRed
No Nevada-specific dark-pattern prohibition was identified.
Absence provenance: unavailable. Searched: Nevada SB 220 online sale opt-out privacy law 2019.
Opt Out SignalsAmber
SB 220 requires operators to establish a 'designated request address' (email, toll-free number, or website) for verified opt-out requests; whether Nevada law recognizes browser-based universal opt-out signals such as Global Privacy Control could not be confirmed.
Claims (1):
SB 220 requires operators to provide a 'designated request address' -- an email address, toll-free telephone number, or website -- for accepting verified opt-out requests, rather than mandating support for automated browser-based opt-out signals.
Clean Rooms And DcrRed
No Nevada-specific clean-room or data-collaboration-room rule was identified.
Absence provenance: unavailable. Searched: Nevada SB 220 online sale opt-out privacy law 2019.
Cross Context AdvertisingAmber
SB 220's definition of 'selling' is narrower than the CCPA's 'sale'/'share' constructs, meaning fewer cross-context advertising arrangements trigger the Nevada opt-out right compared to California.
Claims (1):
Nevada's SB 220 applies to any operator of online services, within or outside Nevada, but not offline, and its definition of 'selling' is more narrowly defined than under the CCPA.
Direct MarketingRed
No Nevada-specific direct-marketing consent or suppression statute beyond the general sale opt-out was identified.
Absence provenance: unavailable. Searched: Nevada SB 220 online sale opt-out privacy law 2019.
Category narrative47 words
Nevada's only adtech-relevant provision is SB 220's narrow opt-out-of-sale right, which uses a materially narrower definition of 'sale' than the CCPA/CPRA and requires a single 'designated request address' rather than recognizing browser-based universal opt-out signals. No cookie/tracker-consent statute, dark-pattern prohibition, clean-room rule, or direct-marketing-specific statute was identified.
Sources and claims (2)
UncertainInternational Association of Privacy Professionals — Nevada's SB 220 applies to any operator of online services, within or outside Nevada, but not offline, and its definition of 'selling' is more narrowly defined than under the CCPA.observed
UncertainInternational Association of Privacy Professionals — SB 220 requires operators to provide a 'designated request address' -- an email address, toll-free telephone number, or website -- for accepting verified opt-out requests, rather than mandating support for automated browser-based opt-out signals.observed
Some emergent signals exist (SB 370 profiling exemption, proposed SB 199) but the regime is immature, partly proposed, and unconfirmed on biometric/genetic scope.
Primary frameworkSB 370; SB 199 (proposed, status unconfirmed)
Traffic-light rationale — AmberSome emergent signals exist (SB 370 profiling exemption, proposed SB 199) but the regime is immature, partly proposed, and unconfirmed on biometric/genetic scope.
Sub-modules (6)
Profiling RestrictionsAmber
SB 370, as amended before final Assembly passage, includes an exemption for profiling that does not involve personal health data, implicitly restricting health-data-based profiling.
Claims (1):
SB 370 was amended before final passage by the Nevada State Assembly to include an exemption for profiling that does not include personal health data.
Automated Decision Making TransparencyRed
No general ADM-transparency or explanation-right statute was identified for Nevada.
Absence provenance: unavailable. Searched: Nevada AI law 2025 artificial intelligence deepfake chatbot.
Ai Risk AssessmentsAmber
SB 199 (introduced February 2025) proposed AI-company registration and semi-annual self-assessment duties; whether it was enacted, amended, or died could not be confirmed.
Claims (1):
Nevada Senate Bill 199, introduced February 11, 2025, would require AI companies to register with the Bureau of Consumer Protection and conduct semi-annual self-assessments to ensure compliance with legal and ethical standards.
Biometric RegimeAmber
As of a 2019 interview, Nevada's then-Attorney General recommended the legislature add biometric data to the categories of personal information covered by the state's privacy/breach laws; whether this was subsequently enacted was not confirmed in this research pass.
Claims (1):
In a 2019 interview, Nevada's Attorney General recommended the state legislature follow other states in classifying biometric data (fingerprints, voice, retinal images) as 'personal information' protected under Nevada's privacy laws, implying biometric data was not then covered.
Genetic DataRed
No Nevada-specific genetic-data privacy statute (comparable to Nebraska's Genetic Information Privacy Act) was identified.
Nevada has no general Article-22-style profiling/ADM transparency regime. SB 370 contains a narrow profiling exemption tied to non-health personal data, and a 2025 bill (SB 199) proposed AI-company registration and self-assessment duties but its final status is unconfirmed. Biometric data is not confirmed to be included within Nevada's breach-notification 'personal information' definition; a 2019 AG interview recommended such an expansion, but subsequent enactment was not verified in this pass. No Nevada-specific genetic-data statute or state-surveillance carve-out was identified.
Sources and claims (3)
UncertainInternational Association of Privacy Professionals — SB 370 was amended before final passage by the Nevada State Assembly to include an exemption for profiling that does not include personal health data.observed
UncertainDataGuidance — Nevada Senate Bill 199, introduced February 11, 2025, would require AI companies to register with the Bureau of Consumer Protection and conduct semi-annual self-assessments to ensure compliance with legal and ethical standards.observed
UncertainInternational Association of Privacy Professionals — In a 2019 interview, Nevada's Attorney General recommended the state legislature follow other states in classifying biometric data (fingerprints, voice, retinal images) as 'personal information' protected under Nevada's privacy laws, implying biometric data was not then covered.observed
No Nevada-specific statutory protections for children or vulnerable groups were located; this is treated as a legitimate gap finding.
Traffic-light rationale — Not assessedNo Nevada-specific statutory protections for children or vulnerable groups were located; this is treated as a legitimate gap finding.
Sub-modules (5)
Age VerificationRed
No Nevada-specific age-verification statute was identified.
Absence provenance: unavailable. Searched: Nevada AI law 2025 artificial intelligence deepfake chatbot.
Parental ConsentRed
No Nevada-specific parental-consent mechanism beyond federal COPPA was identified.
No Nevada-specific age-verification, parental-consent, minor-profiling-ban, education-settings, or dependent-adult data-protection statute was identified in this research pass. Protections for minors in Nevada currently derive from federal COPPA (out of scope for this NV-bound run) rather than state law; SB 370's profiling exemption (algorithmic module) is health-data-specific, not a general minors' protection.
Powers, penalties, and PRA status are well documented (green-level clarity); enforcement-activity index, funding/capacity, and Nevada-specific 180-day developments are largely absent.
Traffic-light rationale — AmberPowers, penalties, and PRA status are well documented (green-level clarity); enforcement-activity index, funding/capacity, and Nevada-specific 180-day developments are largely absent.
Sub-modules (6)
Regulator Powers And PenaltiesGreen
The Nevada Attorney General may institute district-court proceedings for violations of SB 220/NRS 603A.340, seeking a temporary or permanent injunction or a civil penalty of up to $5,000 per violation.
Claims (1):
If the Nevada Attorney General believes an operator has violated NRS 603A.340 or SB 220, the Attorney General may institute legal proceedings in district court, which may issue a temporary or permanent injunction or impose a civil penalty of no more than $5,000 per violation.
Enforcement Activity IndexRed
No Nevada-specific public enforcement-activity index (comprehensive-privacy-law fines/decisions) was identified for the last 12 months; the AG's office describes investigating large-scale breaches but public disclosure of resulting actions is limited.
Claims (1):
The Nevada Attorney General's office conducts investigations, usually with company cooperation, when it receives notice of a data breach that may impact a large number of Nevadans, and may decide to take further action depending on the facts.
Regulator Funding And CapacityRed
No Nevada-specific data on Attorney General privacy-enforcement funding or headcount was identified.
Absence provenance: unavailable. Searched: Nevada attorney general data privacy enforcement action 2025 2026.
Collective Redress And Class ActionsAmber
Neither SB 220 nor SB 370 provides a private right of action; the Nevada Attorney General has sole responsibility for enforcement of SB 220.
Claims (1):
The Nevada Attorney General's office has sole responsibility for enforcement of SB 220, meaning consumers cannot independently bring collective or class actions for its violation.
Private Right Of ActionAmber
SB 370 explicitly does not carry a private right of action, unlike its Washington MHMDA model; enforcement of Nevada's privacy statutes is AG-exclusive.
Claims (1):
Unlike Washington's My Health My Data Act, Nevada's SB 370 does not carry a private right of action, leaving enforcement exclusively with the Attorney General.
Recent Developments 180DRed
No Nevada-specific legislative, judicial, or guidance development within the last 180 days (i.e., since approximately February 2026) was identified; Nevada was not listed among the 11-12 states with enacted chatbot-specific laws as of mid-2026, and SB 199's final status remains unconfirmed.
Absence provenance: unavailable. Searched: Nevada attorney general data privacy enforcement action 2025 2026, Nevada AI law 2025 artificial intelligence deepfake chatbot.
Category narrative92 words
The Nevada Attorney General holds exclusive enforcement authority across NRS 603A, SB 220, and SB 370, with civil penalties of up to $5,000 per violation and access to injunctive relief in district court. Neither SB 220 nor SB 370 provides a private right of action, so collective redress and individual court access for consumers depend entirely on AG enforcement or general consumer-protection theories. No Nevada-specific enforcement-activity index, regulator funding/headcount data, or 180-day recent development specific to Nevada privacy law was identified, though Nevada AG has joined multistate coalition activity on AI policy.
Sources and claims (4)
UncertainInternational Association of Privacy Professionals — If the Nevada Attorney General believes an operator has violated NRS 603A.340 or SB 220, the Attorney General may institute legal proceedings in district court, which may issue a temporary or permanent injunction or impose a civil penalty of no more than $5,000 per violation.observed
UncertainInternational Association of Privacy Professionals — The Nevada Attorney General's office conducts investigations, usually with company cooperation, when it receives notice of a data breach that may impact a large number of Nevadans, and may decide to take further action depending on the facts.observed
UncertainInternational Association of Privacy Professionals — The Nevada Attorney General's office has sole responsibility for enforcement of SB 220, meaning consumers cannot independently bring collective or class actions for its violation.observed
UncertainInternational Association of Privacy Professionals — Unlike Washington's My Health My Data Act, Nevada's SB 370 does not carry a private right of action, leaving enforcement exclusively with the Attorney General.observed
No categories match.
Filters combine as OR inside a group and AND across
groups.
Publication gate
Blocking. 3 failing check(s).
schema_valid
pass
min_architecture_patterns
0
min_red_flags
0
min_controls
0
worked_examples_count
0
decision_tree_nodes
0
counterparty_diligence_questions
0
min_t1_per_instrument_met
n/a — no subject in this jurisdiction
min_quoted_text_present
waived — floor 0%
translation_provenance_recorded
n/a — no subject in this jurisdiction
egress_verified
pass
board_briefing_present
FAIL
every_practical_object_has_source_id
FAIL
source_tier_integrity_ok
pass
jurisdiction_source_floor_met
FAIL
tier_a_b_national_primary_pct
0.0
aggregator_only_jurisdiction_count
0
manual_override
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for Nevada, USA
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
no reviewer on record
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 24 claim(s) (24 category placement(s)), 18 source(s) in the cumulative register.
Audit trail
Machine checkChallenged on 29 Sep 2026: nothing tested (no claim on this page was eligible for an automated test). An automated, adversarial test run by a second model; no person has assessed the result.
regulator_and_framework, controller_processor_duties (breach_notification), sectoral_watch (financial/health overlays), and enforcement_and_redress (powers/penalties, PRA) rest on decent multi-source T2/T3 corroboration (IAPP + NAAG + DataGuidance) anchored to the seed's T1 regulator/statute references. data_subject_rights and lawful_processing_and_special_data are populated only where SB 220/SB 370 create narrow rights (opt-out, health-data consent), with the general DSR/lawful-basis bundle explicitly absent. cross_border_and_adequacy and children_and_vulnerable_groups returned no Nevada-specific findings at all and are carried as legitimate red/absent modules per gap discipline. algorithmic_biometric_and_surveillance_governance relies substantially on T3 secondary reporting and one unconfirmed proposed bill (SB 199) and one 2019-vintage AG interview (biometric_regime), both flagged Uncertain/Probable pending primary-source verification.
Unresolved questions (6):
Has Nevada Senate Bill 199 (AI company registration/self-assessment, introduced Feb. 11, 2025) been enacted, amended, or has it died in committee?
Does NRS 603A's breach-notification 'personal information' definition currently include biometric data, following the 2019 AG recommendation to add it?
What is the exact statutory text, resident-count threshold, and Attorney-General-notification trigger under NRS 603A.220 (breach notification), and does it include an encryption safe harbor?
What are the precise NRS section numbers into which SB 370 (consumer health data) was codified, and what is its full definition of 'consumer health data' and applicability thresholds?
Does Nevada law recognize or require support for browser-based universal opt-out signals (e.g., Global Privacy Control) under SB 220, or is the 'designated request address' the exclusive mechanism?
Has Nevada enacted any biometric-specific privacy statute (facial recognition, fingerprint, voiceprint) since the 2019 AG recommendation?