Dashboard / Global Laws / NE-DPA

πŸ‡ΊπŸ‡ΈNebraska Data Privacy Act

← Back to laws in United States

Nebraska Data Privacy Act

Nebraska Data Privacy Act

Nebraska Data Privacy Act is part of the United States state privacy-law framework. It regulates covered processing of personal data about Nebraska residents and must be assessed separately from federal sectoral laws and other states' statutes.

Current official version

Effective status: January 1, 2025

Citation: Neb. Rev. Stat. ss. 87-1101 through 87-1130

Source basis: Current Nebraska Revised Statutes, sections 87-1101 through 87-1130.

Scope and applicability

The Act generally applies to persons conducting business in Nebraska or producing products or services consumed by Nebraska residents that process or sell personal data and are not a small business as determined under the federal Small Business Act, subject to statutory exemptions. It does not use the common 100,000-consumer threshold.

Thresholds must be calculated using the law's defined consumer population and lookback period. Exemptions should be recorded at entity, data and processing-activity level; an exemption covering one regulated dataset should not automatically be applied to unrelated marketing, website, workforce or customer-support data.

Consumer rights

Consumers may access, correct, delete and obtain portable data, and opt out of targeted advertising, sale and qualifying profiling. Controllers must provide an appeal process and recognize authorized-agent opt-outs where required.

The operational workflow should authenticate requests without collecting excessive new data, meet the applicable response period, document extensions and denials, propagate deletion and opt-out decisions where required, and preserve evidence of the response and any appeal.

Controller and processor duties

Controllers must minimize collection, secure data, avoid incompatible uses and discrimination, publish notices, obtain consent for sensitive data, contract with processors and conduct data protection assessments for listed high-risk activities.

Processor agreements should identify instructions, purpose, duration, data types, confidentiality, subprocessor controls, deletion or return, audit information and assistance with rights, security, breach response and assessments to the extent required by the statute.

State-specific point

A small business remains prohibited from selling sensitive data without prior consumer consent even where the rest of the Act does not apply.

Enforcement and evidence

The Nebraska Attorney General has exclusive enforcement authority. The Act specifies notice, cure and civil-penalty procedures and does not create a private right of action.

Maintain an applicability memorandum, data map, notice versions, request and appeal logs, consent and opt-out records, processor contracts, assessment records, security evidence and a dated record of the official statutory version used. Recheck the official legislature and regulator sources before each scheduled legal review.

What this means for you

Use a shared multi-state privacy operating model, but configure it for this law's exact scope, exemptions, rights, deadlines, consent rules, opt-out signals, assessment triggers and enforcement provisions. Do not substitute a generic US privacy checklist for the state-specific controls.

Other laws in United States
CA-DELETE

California Delete Act and Data Broker Requirements

California Privacy Protection Agency

CPPA

California Privacy Rights Act and California Privacy Protection Agency provisions

California Privacy Protection Agency

CLOUD-ACT

Clarifying Lawful Overseas Use of Data Act (CLOUD Act)

United States Department of Justice

42-CFR-P2

Confidentiality of Substance Use Disorder Patient Records

U.S. Department of Health and Human Services, Office for Civil Rights

CAN-SPAM

Controlling the Assault of Non-Solicited Pornography And Marketing Act

Federal Trade Commission

CPNI

Customer Proprietary Network Information Rules

Federal Communications Commission

DPPA

Drivers Privacy Protection Act

United States Department of Justice and federal courts

ECPA-SCA

Electronic Communications Privacy Act and Stored Communications Act

United States Department of Justice

FERPA

Family Educational Rights and Privacy Act

U.S. Department of Education, Student Privacy Policy Office

GINA

Genetic Information Nondiscrimination Act

U.S. Equal Employment Opportunity Commission and federal health agencies

HITECH

Health Information Technology for Economic and Clinical Health Act

U.S. Department of Health and Human Services, Office for Civil Rights

HIPAA

Health Insurance Portability and Accountability Act of 1996

U.S. Department of Health and Human Services Office for Civil Rights

IL-BIPA

Illinois Biometric Information Privacy Act

Illinois Attorney General and private enforcement

MT-CDPA

Montana Consumer Data Privacy Act

Montana Attorney General, Office of Consumer Protection

NJDPA

New Jersey Data Privacy Law

New Jersey Attorney General and Division of Consumer Affairs

PRIVACY-ACT

Privacy Act of 1974

U.S. Department of Justice, Office of Privacy and Civil Liberties

RI-DTPPA

Rhode Island Data Transparency and Privacy Protection Act

Rhode Island Attorney General

UCPA

Utah Consumer Privacy Act

Utah Attorney General and Division of Consumer Protection

VT-DPOSA

Vermont Data Privacy and Online Surveillance Act

Vermont Attorney General

VPPA

Video Privacy Protection Act

United States Department of Justice and federal courts