🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
US-WY v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing21 sources retrieved model claude-sonnet-5 · 2026-08-06

Wyoming, USA

US-WY schema gdpri-v2 trajectory: not yet assessedregulated (sectoral)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 46 claims · 22 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
46Claimsbaseline..claims[]
18Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

No comprehensive omnibus statute or dedicated DPA exists; coverage is limited to breach notification and general UDAP authority.

Primary frameworkWyoming Consumer Protection Act (Wyo. Stat. §40-12-101 et seq.) and Wyoming data breach notification statute (Wyo. Stat. §40-12-501 et seq.), overlaid by FTC Act Section 5
Traffic-light rationale — RedNo comprehensive omnibus statute or dedicated DPA exists; coverage is limited to breach notification and general UDAP authority.

Sub-modules (5)

Regulator And AuthorityAmber

The Consumer Protection Unit of the Wyoming AG enforces the breach-notification statute; the FTC enforces Section 5 nationally, including in Wyoming.

Claims (2):

  • The Consumer Protection Unit of the Wyoming Attorney General is responsible for enforcing the state's data breach notification statute.
  • The Federal Trade Commission exercises general unfair-and-deceptive-practices privacy enforcement authority under Section 5 of the FTC Act, applicable to entities operating in or affecting Wyoming.

Act And InstrumentsAmber

Operative instruments are the Wyoming Consumer Protection Act, the Wyoming breach-notification statute, and federal FTC Act Section 5; there is no comprehensive WY privacy act.

Claims (1):

  • Wyoming's principal consumer-facing statutes touching data protection are the Wyoming Consumer Protection Act (Wyo. Stat. §40-12-101 et seq.) and the data breach notification statute (Wyo. Stat. §40-12-501 et seq.).

Material ScopeRed

Wyoming does not define a comprehensive material scope of 'personal data' or 'processing' analogous to GDPR; scope is limited to the breach statute's definition of personal identifying information.

Claims (1):

  • Wyoming has no comprehensive consumer-privacy statute defining a GDPR/CCPA-equivalent material scope of covered personal data or processing activities.

Territorial ScopeAmber

FTC Section 5 authority extends to conduct causing or likely to cause injury within the United States regardless of the actor's location; no WY-specific extraterritorial trigger exists.

Claims (1):

  • Under 15 U.S.C. §45(a)(4), FTC Act unfair-or-deceptive-practices authority reaches foreign and domestic conduct causing or likely to cause reasonably foreseeable injury within the United States, including Wyoming.

Regulator Registration And FilingRed

No controller registration or filing regime exists in Wyoming.

Claims (1):

  • No Wyoming statute requires controllers to register or file processing notices with a state privacy regulator.

Key findings (1)

  • No comprehensive WY privacy statute or dedicated DPA; AG Consumer Protection Unit + FTC Section 5 govern. — source on file
Category narrative66 words

Wyoming has no dedicated data-protection regulator or comprehensive privacy statute. The Consumer Protection Unit of the Wyoming Attorney General enforces the state's general Consumer Protection Act (Wyo. Stat. §40-12-101 et seq.) and the state's data-breach notification statute (Wyo. Stat. §40-12-501 et seq.). Federally, the FTC exercises Section 5 unfair/deceptive-practices authority over Wyoming-based and Wyoming-facing commercial actors. There is no WY-specific registration or filing obligation for controllers.

Sources and claims (6)
  1. ConfirmedOneTrust DataGuidance — The Consumer Protection Unit of the Wyoming Attorney General is responsible for enforcing the state's data breach notification statute.observed
  2. ConfirmedFederal Trade Commission — The Federal Trade Commission exercises general unfair-and-deceptive-practices privacy enforcement authority under Section 5 of the FTC Act, applicable to entities operating in or affecting Wyoming.observed
  3. ConfirmedOneTrust DataGuidance — Wyoming's principal consumer-facing statutes touching data protection are the Wyoming Consumer Protection Act (Wyo. Stat. §40-12-101 et seq.) and the data breach notification statute (Wyo. Stat. §40-12-501 et seq.).observed
  4. ConfirmedIAPP — Wyoming has no comprehensive consumer-privacy statute defining a GDPR/CCPA-equivalent material scope of covered personal data or processing activities.observed
  5. ProbableFederal Trade Commission — Under 15 U.S.C. §45(a)(4), FTC Act unfair-or-deceptive-practices authority reaches foreign and domestic conduct causing or likely to cause reasonably foreseeable injury within the United States, including Wyoming.observed
  6. UncertainIAPP — No Wyoming statute requires controllers to register or file processing notices with a state privacy regulator.observed

#

No general Art.6-equivalent lawful-basis regime; only a narrow genetic-data consent statute and federal children's-data consent rule apply.

Primary frameworkWyoming Genetic Data Privacy Act; federal COPPA (verifiable parental consent)
Supervisory authorityWyoming Attorney General
Traffic-light rationale — RedNo general Art.6-equivalent lawful-basis regime; only a narrow genetic-data consent statute and federal children's-data consent rule apply.

Sub-modules (4)

Lawful BasesRed

No enumerated lawful-basis regime exists under Wyoming law for general commercial personal-data processing.

Claims (1):

  • Wyoming law does not enumerate lawful bases for processing personal data analogous to GDPR Article 6.

Special CategoriesAmber

Wyoming's Genetic Data Privacy Act treats genetic data as a special category requiring express consent from direct-to-consumer genetic testing companies; no broader special-category regime (health, biometric, ethnic, political, sexual, criminal) exists.

Claims (1):

  • Wyoming's Genetic Data Privacy Act imposes consent and disclosure obligations on direct-to-consumer genetic testing companies regarding the collection, use, and disclosure of consumers' genetic data.

Pseudonymisation And AnonymisationRed

No Wyoming statute defines pseudonymisation/anonymisation standards or safe harbours for commercial data.

Claims (1):

  • No Wyoming statute establishes pseudonymisation or anonymisation definitions or safe-harbour treatment for commercial personal data.

Key findings (1)

  • No general lawful-basis regime; Genetic Data Privacy Act and COPPA are the only consent-threshold instruments (dates corrected this cycle). — source on file
Category narrative39 words

Wyoming has no general lawful-basis or consent framework for commercial data processing. The narrow exception is the Wyoming Genetic Data Privacy Act, which imposes consent requirements on direct-to-consumer genetic testing companies. Federally, COPPA imposes verifiable-parental-consent standards for children's data.

Sources and claims (4)
  1. ConfirmedIAPP — Wyoming law does not enumerate lawful bases for processing personal data analogous to GDPR Article 6.observed
  2. ConfirmedFederal Trade Commission — The COPPA Rule requires operators to obtain verifiable parental consent before collecting, using, or disclosing personal information from children under 13, applicable nationally including Wyoming.observed
  3. ProbableOneTrust DataGuidance — Wyoming's Genetic Data Privacy Act imposes consent and disclosure obligations on direct-to-consumer genetic testing companies regarding the collection, use, and disclosure of consumers' genetic data.observed
  4. UncertainIAPP — No Wyoming statute establishes pseudonymisation or anonymisation definitions or safe-harbour treatment for commercial personal data.observed

#

Absence of any comprehensive consumer rights framework; only sectoral federal rights apply.

Primary frameworkFederal FERPA and COPPA (no WY state-law consumer rights)
Traffic-light rationale — RedAbsence of any comprehensive consumer rights framework; only sectoral federal rights apply.

Sub-modules (5)

Access RightRed

No general right of access to personal data exists under Wyoming law; FERPA provides parents/eligible students access to education records.

Claims (1):

  • FERPA gives parents and eligible students the right to inspect and review their education records, applicable to Wyoming educational institutions receiving federal funding.

Rectification And ErasureAmber

FERPA allows parents/eligible students to request amendment of inaccurate or misleading education records; no general erasure right exists commercially.

Claims (1):

  • FERPA permits a parent or eligible student to request amendment of education records believed to be inaccurate, misleading, or in violation of privacy rights.

Restriction And ObjectionRed

No restriction-of-processing or objection right (including profiling opt-out) exists under Wyoming law.

Claims (1):

  • No Wyoming or generally-applicable federal commercial-sector statute grants consumers a right to restrict processing or object to profiling.

Data PortabilityRed

No data portability right exists under Wyoming law.

Claims (1):

  • No Wyoming statute creates a consumer data portability right.

Deadlines And Response WindowsRed

No statutory response-window regime exists for consumer rights requests in Wyoming, as no general rights regime exists to trigger deadlines.

Claims (1):

  • No Wyoming statute prescribes response-window deadlines for consumer data-rights requests, since no general rights regime exists.

Key findings (1)

  • No general consumer rights regime; FERPA supplies sectoral education-records rights only. — source on file
Category narrative32 words

Wyoming confers no general consumer data-subject rights (access, deletion, restriction, portability). The only rights-like structure operative in the state derives from federal FERPA (education records) and COPPA (parental rights over children's data).

Sources and claims (5)
  1. ConfirmedIAPP — FERPA gives parents and eligible students the right to inspect and review their education records, applicable to Wyoming educational institutions receiving federal funding.observed
  2. ConfirmedIAPP — FERPA permits a parent or eligible student to request amendment of education records believed to be inaccurate, misleading, or in violation of privacy rights.observed
  3. ConfirmedIAPP — No Wyoming or generally-applicable federal commercial-sector statute grants consumers a right to restrict processing or object to profiling.observed
  4. ConfirmedIAPP — No Wyoming statute creates a consumer data portability right.observed
  5. UncertainIAPP — No Wyoming statute prescribes response-window deadlines for consumer data-rights requests, since no general rights regime exists.observed

#

Breach notification is well-established and binding; broader accountability/DPIA/DPO/ROPA obligations are absent outside sectoral overlays.

Primary frameworkWyoming breach notification statute (Wyo. Stat. §40-12-501 et seq.); federal GLBA Safeguards Rule; HIPAA Security Rule
Traffic-light rationale — AmberBreach notification is well-established and binding; broader accountability/DPIA/DPO/ROPA obligations are absent outside sectoral overlays.

Sub-modules (7)

Accountability And DpiaRed

No general accountability principle or DPIA trigger exists under Wyoming law.

Claims (1):

  • No Wyoming statute imposes a general accountability principle or requires data protection impact assessments.

Dpo RequirementsRed

No DPO appointment threshold exists under Wyoming law.

Claims (1):

  • No Wyoming statute establishes a data protection officer appointment threshold.

Ropa RequirementsRed

No records-of-processing obligation exists under Wyoming law.

Claims (1):

  • No Wyoming statute requires maintenance of records of processing activities.

Joint Controller ArrangementsRed

No statutory joint-controller framework exists under Wyoming law.

Claims (1):

  • No Wyoming statute establishes joint-controller apportionment-of-responsibility rules.

Security MeasuresAmber

Security-of-processing obligations arise only through sectoral federal overlays: the GLBA Safeguards Rule for financial institutions and the HIPAA Security Rule for covered health entities.

Claims (1):

  • The Gramm-Leach-Bliley Act's Safeguards Rule requires financial institutions to implement an information security program appropriate to the size and complexity of their operations, applicable to Wyoming-based financial institutions.

Breach NotificationGreen

Wyoming requires notification of security breaches involving personal identifying information under Wyo. Stat. §40-12-501 et seq., enforced by the AG's Consumer Protection Unit.

Claims (1):

  • Wyoming law requires notification of data breaches under §40-12-501 et seq. of Chapter 12, Article 5, Title 40 of the Wyoming Statutes.

Retention And DisposalRed

No general retention-limitation or disposal duty exists under Wyoming law outside sectoral federal rules (e.g., HIPAA, GLBA-linked disposal expectations).

Claims (1):

  • No general Wyoming statute imposes retention limits or disposal duties on commercial holders of personal data outside sector-specific federal overlays.

Key findings (1)

  • Breach notification is the only binding cross-cutting duty; GLBA/HIPAA overlays supply security-measures obligations. — source on file
Category narrative47 words

Wyoming's principal controller/processor duty is breach notification under Wyo. Stat. §40-12-501 et seq. Sectoral federal overlays (GLBA Safeguards Rule for financial institutions; HIPAA Security Rule for covered health entities) impose security-program obligations. No general accountability principle, DPIA trigger, DPO requirement, or ROPA obligation exists under Wyoming law.

Sources and claims (7)
  1. ConfirmedIAPP — No Wyoming statute imposes a general accountability principle or requires data protection impact assessments.observed
  2. ConfirmedIAPP — No Wyoming statute establishes a data protection officer appointment threshold.observed
  3. ConfirmedIAPP — No Wyoming statute requires maintenance of records of processing activities.observed
  4. UncertainIAPP — No Wyoming statute establishes joint-controller apportionment-of-responsibility rules.observed
  5. ConfirmedFederal Trade Commission — The Gramm-Leach-Bliley Act's Safeguards Rule requires financial institutions to implement an information security program appropriate to the size and complexity of their operations, applicable to Wyoming-based financial institutions.observed
  6. ConfirmedOneTrust DataGuidance — Wyoming law requires notification of data breaches under §40-12-501 et seq. of Chapter 12, Article 5, Title 40 of the Wyoming Statutes.observed
  7. UncertainIAPP — No general Wyoming statute imposes retention limits or disposal duties on commercial holders of personal data outside sector-specific federal overlays.observed

#

No state-level transfer regime exists; the only operative mechanism is the federal EU-U.S. DPF self-certification enforced by the FTC.

Primary frameworkEU-U.S. Data Privacy Framework (federal, FTC-enforced); no Wyoming-specific transfer regime
Supervisory authorityFederal Trade Commission
Traffic-light rationale — AmberNo state-level transfer regime exists; the only operative mechanism is the federal EU-U.S. DPF self-certification enforced by the FTC.

Sub-modules (6)

Transfer MechanismsAmber

No Wyoming statute governs cross-border transfer mechanisms; participants in the federal EU-U.S. Data Privacy Framework self-certify to the Department of Commerce and are bound by FTC enforcement.

Claims (1):

  • Organizations may self-certify to the U.S. Department of Commerce under the EU-U.S. Data Privacy Framework, with FTC enforcement of compliance failures as unfair or deceptive acts under Section 5.

Adequacy ReceivedAmber

The European Commission's adequacy decision on the EU-U.S. Data Privacy Framework operates at the federal level and extends to Wyoming-based self-certified organizations; Wyoming has no independent adequacy status.

Claims (1):

  • On 17 July 2023 the European Commission issued an adequacy decision on the EU-U.S. Data Privacy Framework, providing a mechanism for EU-to-U.S. personal data transfers consistent with EU law.

Adequacy GrantedRed

Wyoming, as a U.S. state, does not itself grant adequacy determinations to foreign jurisdictions; this is a federal-level (or non-applicable) function.

Sccs And BcrsRed

No Wyoming-specific SCC/BCR framework exists; use of SCCs/BCRs by Wyoming entities is governed by counterpart jurisdictions' requirements (e.g., EU SCCs), not by Wyoming law.

Transfer Impact AssessmentRed

No Wyoming or general U.S. federal requirement mandates a transfer impact assessment.

Data LocalisationRed

Wyoming imposes no data-localisation mandate.

Claims (1):

  • No Wyoming statute requires personal data to be stored or processed within the state or the United States.

Key findings (1)

  • No WY transfer regime; EU-U.S. DPF operates federally only. — source on file
Category narrative37 words

Wyoming imposes no state-level cross-border transfer restrictions or data-localisation mandates. At the federal level, the EU-U.S. Data Privacy Framework provides an adequacy-linked self-certification mechanism enforced via FTC Section 5, relevant to Wyoming-based participants receiving EU personal data.

Sources and claims (3)
  1. ProbableFederal Trade Commission — Organizations may self-certify to the U.S. Department of Commerce under the EU-U.S. Data Privacy Framework, with FTC enforcement of compliance failures as unfair or deceptive acts under Section 5.observed
  2. ConfirmedFederal Trade Commission — On 17 July 2023 the European Commission issued an adequacy decision on the EU-U.S. Data Privacy Framework, providing a mechanism for EU-to-U.S. personal data transfers consistent with EU law.observed
  3. UncertainIAPP — No Wyoming statute requires personal data to be stored or processed within the state or the United States.observed

#

Strong federal sectoral coverage (GLBA/HIPAA/FERPA) offsets the absence of state-specific overlays in insurance, telecoms, and employment.

Primary frameworkGLBA (financial); HIPAA (health); FERPA (education); FCRA (credit/scoring)
Traffic-light rationale — AmberStrong federal sectoral coverage (GLBA/HIPAA/FERPA) offsets the absence of state-specific overlays in insurance, telecoms, and employment.

Sub-modules (7)

Financial Sector OverlayGreen

GLBA's Privacy Rule and Safeguards Rule govern financial institutions operating in Wyoming; the FTC has enforcement jurisdiction over financial institutions not regulated by other federal agencies.

Claims (1):

  • The Gramm-Leach-Bliley Act requires financial institutions, including those in Wyoming, to explain information-sharing practices to customers and safeguard nonpublic personal financial information, with the FTC enforcing against institutions not regulated by other federal agencies.

Health Sector OverlayGreen

HIPAA Privacy, Security, and Breach Notification Rules govern covered entities and business associates in Wyoming; the FTC Act and Health Breach Notification Rule fill gaps for non-HIPAA-covered health data holders.

Claims (1):

  • HIPAA Rules apply to covered entities (health plans, health care providers conducting standard electronic transactions, health care clearinghouses) and their business associates operating in Wyoming, governing use, disclosure, and breach notification of protected health information.

Telecoms And EprivacyRed

No Wyoming-specific telecoms/eprivacy (cookie/communications) statute was identified beyond general federal telemarketing rules (e.g., TCPA enforcement referenced in multistate AG robocall actions).

Claims (1):

  • No Wyoming-specific eprivacy or cookie-consent statute was identified; state attorneys general (including Wyoming's, per NAAG coalition activity) instead rely on federal robocall/telemarketing enforcement mechanisms.

Employment DataRed

No Wyoming-specific employment-data-privacy statute was identified.

Credit And ScoringAmber

The federal Fair Credit Reporting Act governs credit-reporting and scoring data nationally, including Wyoming, supplementing GLBA notice/opt-out obligations.

Claims (1):

  • The federal Fair Credit Reporting Act supplements GLBA notice-and-opt-out obligations regarding consumer report information, applicable nationally including Wyoming.

EducationAmber

FERPA governs education records held by Wyoming schools and institutions receiving U.S. Department of Education funding; no Wyoming student-data-privacy statute analogous to California's SOPIPA was identified.

Claims (1):

  • FERPA establishes requirements regarding privacy protection of student educational records and applies to all academic institutions receiving applicable U.S. Department of Education funds, including those in Wyoming.

InsuranceAmber

GLBA privacy/safeguards obligations apply to insurers, enforced in part by state insurance regulators; no evidence was found that Wyoming has adopted the NAIC Insurance Data Security Model Law.

Claims (1):

  • No evidence was found that Wyoming has enacted an Insurance Data Security Act following the NAIC Insurance Data Security Model Law, unlike South Carolina, Ohio, and Michigan.

Key findings (1)

  • Federal sectoral overlays (GLBA/HIPAA/FERPA/FCRA) dominate; WY NAIC Insurance Model Law adoption unconfirmed. — source on file
Category narrative62 words

Sectoral federal overlays are the dominant source of data-protection obligation in Wyoming: GLBA for financial institutions, HIPAA for covered health entities, and FERPA for education records. No Wyoming-specific insurance-data-security statute mirroring the NAIC Insurance Data Security Model Law was identified; GLBA privacy/safeguards obligations apply to insurers via the Wyoming Insurance Department's GLBA enforcement role. No WY-specific telecoms/eprivacy or employment-data statute was identified.

Sources and claims (6)
  1. ConfirmedFederal Trade Commission — The Gramm-Leach-Bliley Act requires financial institutions, including those in Wyoming, to explain information-sharing practices to customers and safeguard nonpublic personal financial information, with the FTC enforcing against institutions not regulated by other federal agencies.observed
  2. ConfirmedFederal Trade Commission — HIPAA Rules apply to covered entities (health plans, health care providers conducting standard electronic transactions, health care clearinghouses) and their business associates operating in Wyoming, governing use, disclosure, and breach notification of protected health information.observed
  3. UncertainNAAG — No Wyoming-specific eprivacy or cookie-consent statute was identified; state attorneys general (including Wyoming's, per NAAG coalition activity) instead rely on federal robocall/telemarketing enforcement mechanisms.observed
  4. ConfirmedFederal Trade Commission — The federal Fair Credit Reporting Act supplements GLBA notice-and-opt-out obligations regarding consumer report information, applicable nationally including Wyoming.observed
  5. ConfirmedIAPP — FERPA establishes requirements regarding privacy protection of student educational records and applies to all academic institutions receiving applicable U.S. Department of Education funds, including those in Wyoming.observed
  6. UncertainOneTrust DataGuidance — No evidence was found that Wyoming has enacted an Insurance Data Security Act following the NAIC Insurance Data Security Model Law, unlike South Carolina, Ohio, and Michigan.observed

#

No state-level adtech-specific rules exist; only generic federal deception authority and telemarketing enforcement apply.

Primary frameworkFTC Act Section 5 (federal); no Wyoming-specific adtech statute
Supervisory authorityFederal Trade Commission
Traffic-light rationale — RedNo state-level adtech-specific rules exist; only generic federal deception authority and telemarketing enforcement apply.

Sub-modules (6)

Cookies And TrackersRed

No Wyoming statute regulates cookie or tracker consent.

Claims (1):

  • No Wyoming statute establishes a cookie- or tracker-consent regime for websites or apps.

Dark PatternsAmber

No Wyoming-specific dark-pattern prohibition exists; the FTC has used Section 5 deception authority against manipulative design nationally.

Claims (1):

  • The FTC has pursued negative-option and manipulative-design enforcement nationally under FTC Act Section 5, which is applicable to Wyoming-facing commercial practices though not a dedicated dark-pattern statute.

Opt Out SignalsRed

No Wyoming statute requires recognition of opt-out signals such as the Global Privacy Control.

Clean Rooms And DcrRed

No Wyoming statute addresses data clean rooms or data-collaboration-room practices.

Cross Context AdvertisingRed

No Wyoming statute defines or restricts 'sale' or 'share' of personal data for cross-context advertising, absent a CPRA-equivalent framework.

Direct MarketingAmber

Direct marketing suppression/consent obligations arise mainly from federal telemarketing law; Wyoming's AG participates in multistate coalitions urging stronger KYC rules against illegal robocalls.

Claims (1):

  • Wyoming's Attorney General has joined bipartisan multistate coalitions in 2026 urging federal action, including stronger KYC rules, to combat illegal robocalls affecting consumers.

Key findings (1)

  • No WY adtech-specific statute; only generic FTC Section 5 authority applies. — source on file
Category narrative42 words

Wyoming has no state-level cookie/tracker consent regime, dark-pattern prohibition, opt-out-signal recognition mandate, clean-room regulation, or 'sale'/'share' cross-context-advertising restriction. Direct marketing is addressed only through federal mechanisms such as FTC Act Section 5 deception enforcement and multistate AG action on illegal robocalls (TCPA-adjacent).

Sources and claims (3)
  1. ConfirmedIAPP — No Wyoming statute establishes a cookie- or tracker-consent regime for websites or apps.observed
  2. ProbableFederal Trade Commission — The FTC has pursued negative-option and manipulative-design enforcement nationally under FTC Act Section 5, which is applicable to Wyoming-facing commercial practices though not a dedicated dark-pattern statute.observed
  3. ProbableNAAG — Wyoming's Attorney General has joined bipartisan multistate coalitions in 2026 urging federal action, including stronger KYC rules, to combat illegal robocalls affecting consumers.observed

#

No AI-specific, profiling, or biometric consent regime exists; only genetic data and breach-notification biometric inclusion are operative.

Primary frameworkWyoming Genetic Data Privacy Act (genetic data only); no AI/biometric/ADM statute
Supervisory authorityWyoming Attorney General
Traffic-light rationale — RedNo AI-specific, profiling, or biometric consent regime exists; only genetic data and breach-notification biometric inclusion are operative.

Sub-modules (6)

Profiling RestrictionsRed

No Wyoming statute restricts automated profiling of individuals.

Claims (1):

  • No Wyoming statute restricts automated profiling of individuals or provides an Article 22-equivalent right against solely automated decisions.

Automated Decision Making TransparencyRed

No Wyoming statute requires disclosure or explanation of automated decision-making.

Ai Risk AssessmentsRed

No cross-sectoral Wyoming AI governance or AI risk-assessment statute was identified in the 2025-2026 legislative sessions.

Claims (1):

  • No cross-sectoral Wyoming AI governance statute requiring AI risk assessments was identified as of the 2026 legislative session.

Biometric RegimeAmber

Wyoming's breach-notification statute includes biometric information within its definition of personal information triggering notification duties, but Wyoming has not enacted a dedicated biometric-privacy statute comparable to Illinois BIPA, Texas CUBI, or Washington's biometric law.

Claims (1):

  • Wyoming is among a group of states (including Connecticut, Iowa, Kentucky, Nebraska, and Wisconsin) whose breach-notification statutes include biometric information within the definition of protected personal information, but only Illinois, Washington, and Texas have enacted dedicated biometric-privacy legislation.

Genetic DataAmber

The Genetic Data Privacy Act imposes consent obligations specifically on direct-to-consumer genetic testing companies operating in Wyoming.

Claims (1):

  • Wyoming's Genetic Data Privacy Act requires direct-to-consumer genetic testing companies to obtain consumer consent for collection, use, and disclosure of genetic data.

State Surveillance CarveoutsRed

No Wyoming-specific state-surveillance carveout distinct from general federal national-security exemptions was identified.

Key findings (1)

  • No AI governance/profiling statute; genetic-data consent regime is the sole special-category instrument. — source on file
Category narrative55 words

Wyoming has no cross-sectoral AI governance statute, profiling restriction, or ADM transparency right. Biometric data is included within the breach-notification statute's definition of protected personal information but is not subject to a dedicated consent/retention regime such as Illinois BIPA. The Genetic Data Privacy Act provides the state's only special-category-style regime, applicable to genetic data specifically.

Sources and claims (4)
  1. ConfirmedIAPP — No Wyoming statute restricts automated profiling of individuals or provides an Article 22-equivalent right against solely automated decisions.observed
  2. UncertainIAPP — No cross-sectoral Wyoming AI governance statute requiring AI risk assessments was identified as of the 2026 legislative session.observed
  3. ProbableIAPP — Wyoming is among a group of states (including Connecticut, Iowa, Kentucky, Nebraska, and Wisconsin) whose breach-notification statutes include biometric information within the definition of protected personal information, but only Illinois, Washington, and Texas have enacted dedicated biometric-privacy legislation.observed
  4. ProbableOneTrust DataGuidance — Wyoming's Genetic Data Privacy Act requires direct-to-consumer genetic testing companies to obtain consumer consent for collection, use, and disclosure of genetic data.observed

#

Federal COPPA/FERPA coverage is robust; no state-specific supplementary protections exist.

Primary frameworkFederal COPPA and FERPA; no Wyoming state-law supplement
Traffic-light rationale — AmberFederal COPPA/FERPA coverage is robust; no state-specific supplementary protections exist.

Sub-modules (5)

Age VerificationAmber

No Wyoming-specific age-verification statute was identified; COPPA's actual-knowledge/directed-to-children standard governs at the federal level.

Claims (1):

  • The COPPA Rule applies where a site or service is directed to children under 13 or has actual knowledge that it is collecting personal information from users in that age group, applicable nationally including Wyoming.

Minor Profiling BansRed

No Wyoming or general federal cross-sectoral statute bans profiling of minors.

Education SettingsAmber

FERPA governs education-records privacy in Wyoming schools; COPPA's school-official exception allows limited ed-tech data collection without direct parental consent when schools act in loco parentis for educational purposes.

Claims (1):

  • Under COPPA, schools may consent on a parent's behalf for the collection of children's personal information solely for educational purposes, a role FERPA separately governs through its education-records-disclosure framework.

Dependent AdultsRed

No Wyoming-specific statute addressing data protection for dependent or incapacitated adults was identified.

Key findings (1)

  • Federal COPPA/FERPA supply all children's-data protection; no WY-specific supplement. — source on file
Category narrative35 words

Children's data protections in Wyoming derive entirely from federal law: COPPA's verifiable-parental-consent regime for online operators, and FERPA's parental-rights structure for education records. No Wyoming-specific age-verification, minor-profiling ban, or dependent-adult data protection statute was identified.

Sources and claims (3)
  1. ConfirmedFederal Trade Commission — The COPPA Rule applies where a site or service is directed to children under 13 or has actual knowledge that it is collecting personal information from users in that age group, applicable nationally including Wyoming.observed
  2. ConfirmedFederal Trade Commission — The COPPA Rule requires operators covered by the law to notify parents and obtain verifiable consent before collecting, using, or disclosing personal information from children under 13.observed
  3. ConfirmedFederal Trade Commission — Under COPPA, schools may consent on a parent's behalf for the collection of children's personal information solely for educational purposes, a role FERPA separately governs through its education-records-disclosure framework.observed

#

Enforcement authority is real but narrow (breach/UDAP); no dedicated privacy regulator penalties regime exists, and private redress avenues are uncertain.

Primary frameworkWyoming Consumer Protection Act / breach statute (state); FTC Act Section 5 (federal)
Traffic-light rationale — AmberEnforcement authority is real but narrow (breach/UDAP); no dedicated privacy regulator penalties regime exists, and private redress avenues are uncertain.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

The Wyoming AG's Consumer Protection Unit enforces the Consumer Protection Act and breach statute; the FTC separately can seek injunctive relief, civil penalties, and restitution under the FTC Act and GLBA.

Claims (1):

  • The FTC may seek injunctive and ancillary equitable relief in federal district court for violations of the GLBA Privacy Rule and has Section 5 authority to examine privacy practices for deception and unfairness nationally, including in Wyoming.

Enforcement Activity IndexAmber

Wyoming's AG has participated in 2026 multistate coalition enforcement-adjacent advocacy (robocall/KYC letters) rather than standalone privacy enforcement actions.

Claims (1):

  • In 2026, Wyoming joined bipartisan coalitions of state and territory attorneys general urging federal action, including stronger KYC rules, to combat illegal robocalls.

Regulator Funding And CapacityRed

No published data on the Wyoming AG Consumer Protection Unit's dedicated privacy-enforcement funding or headcount was identified.

Collective Redress And Class ActionsAmber

Multistate AG settlements (e.g., against major technology and data companies) provide the primary collective-redress avenue available to Wyoming consumers; no dedicated Wyoming consumer class-action privacy mechanism was identified.

Claims (1):

  • Attorneys general, including through NAAG-coordinated efforts, have negotiated multistate settlements on behalf of consumers resulting in civil penalties and added data-protection commitments from companies.

Private Right Of ActionRed

It is unconfirmed whether Wyoming's breach-notification statute affords consumers a private right of action; some U.S. state breach statutes do, but Wyoming-specific confirmation was not found.

Claims (1):

  • A subset of U.S. state data-breach notification statutes allow a private right of action for noncompliance, but it is unconfirmed whether Wyoming's statute is among them.

Recent Developments 180DAmber

No Wyoming-specific privacy or breach-law amendments were identified within the last 180 days. The most relevant nearby federal development is FTC enforcement of Section 3 of the Take It Down Act, effective 19 May 2026, which is generally applicable including to Wyoming-based platforms.

Claims (1):

  • The FTC began enforcing Section 3 of the Take It Down Act effective 19 May 2026, requiring covered platforms to establish removal processes for non-consensual intimate imagery, a nationally applicable development touching platforms operating in Wyoming.

Key findings (1)

  • AG + FTC enforce; private-right-of-action status under WY breach statute unconfirmed. — source on file
Category narrative81 words

Enforcement in Wyoming rests with the AG's Consumer Protection Unit (breach notification, UDAP) and the FTC (Section 5, GLBA, COPPA). No private right of action was confirmed under the Wyoming breach statute; Wyoming participates in multistate AG collective actions (e.g., robocall/KYC coalitions). No Wyoming-specific developments to the state's privacy or breach framework were identified within the last 180 days; the most relevant recent federal development is the FTC's enforcement of the Take It Down Act's Section 3, effective 19 May 2026.

Sources and claims (5)
  1. ConfirmedFederal Trade Commission — The FTC may seek injunctive and ancillary equitable relief in federal district court for violations of the GLBA Privacy Rule and has Section 5 authority to examine privacy practices for deception and unfairness nationally, including in Wyoming.observed
  2. ProbableNAAG — In 2026, Wyoming joined bipartisan coalitions of state and territory attorneys general urging federal action, including stronger KYC rules, to combat illegal robocalls.observed
  3. ConfirmedNAAG — Attorneys general, including through NAAG-coordinated efforts, have negotiated multistate settlements on behalf of consumers resulting in civil penalties and added data-protection commitments from companies.observed
  4. UncertainIAPP — A subset of U.S. state data-breach notification statutes allow a private right of action for noncompliance, but it is unconfirmed whether Wyoming's statute is among them.observed
  5. ConfirmedFederal Trade Commission — The FTC began enforcing Section 3 of the Take It Down Act effective 19 May 2026, requiring covered platforms to establish removal processes for non-consensual intimate imagery, a nationally applicable development touching platforms operating in Wyoming.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct63.64
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Wyoming, USA
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 46 claim(s) (46 category placement(s)), 22 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsdata portability
Art. 19Data Subject Rightsrectification and erasure
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redressregulator powers and penalties
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redresscollective redress and class actions
Art. 83Enforcement & Redresscollective redress and class actions
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

T1 primary-instrument coverage was obtained for: the Wyoming breach-notification statute (via DataGuidance summary of Wyo. Stat. §40-12-501 et seq.), the Wyoming Consumer Protection Act (§40-12-101 et seq.), FTC Act Section 5, GLBA, COPPA, and HIPAA/FTC health-privacy guidance — grounding regulator_and_framework, controller_processor_duties (breach_notification, security_measures), sectoral_watch (financial/health/education), and children_and_vulnerable_groups. Modules relying predominantly on T2/T3 secondary trackers (IAPP state privacy/AI trackers, DataGuidance opinion notes) to document ABSENCE of regulation include lawful_processing_and_special_data (beyond genetic data), data_subject_rights, cross_border_and_adequacy (state-level), adtech_and_commercial_privacy, and algorithmic_biometric_and_surveillance_governance (beyond genetic/biometric breach-inclusion). The Genetic Data Privacy Act and biometric-inclusion-in-breach-statute findings rely on T2/T3 secondary description rather than direct primary-statute text retrieval, since the Wyoming Legislature's official statute portal was not in the retrieval allowlist for this run.

Unresolved questions (5):

  • Does the Wyoming breach-notification statute (Wyo. Stat. §40-12-501 et seq.) afford consumers a private right of action, or is enforcement exclusively via the Attorney General?
  • Has Wyoming adopted any version of the NAIC Insurance Data Security Model Law, and if so, under what statute/regulation?
  • What are the precise consent, retention, and enforcement mechanics of the Wyoming Genetic Data Privacy Act (primary statute text was not directly retrieved)?
  • Has any Wyoming-specific comprehensive consumer-privacy or cross-sectoral AI governance bill been introduced in the 2026 legislative session that has not yet surfaced in national trackers?
  • What is the current funding/headcount capacity of the Wyoming AG's Consumer Protection Unit for privacy-adjacent enforcement?

Escalate to primary-source review: yes