Arkansas § 4-110-105 - Disclosure of security breaches.
Full text of Arkansas Arkansas Code of 1987 Annotated § 4-110-105 — Disclosure of security breaches., with citation guidance and answers to common questions.
§ 4-110-105. Disclosure of security breaches.
Any person or business that acquires, owns, or licenses computerized data that includes personal information shall disclose any breach of the security of the system following discovery or notification of the breach of the security of the system to any resident of Arkansas whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person. The disclosure shall be made in the most expedient time and manner possible and without unreasonable delay, consistent with the legitimate needs of law enforcement as provided in subsection (c) of this section, or any measures necessary to determine the scope of the breach and to restore the reasonable integrity of the data system. A person or business that maintains computerized data that includes personal information that the person or business does not own shall notify the owner or licensee that there has been a breach of the security of the system immediately following discovery if the personal information was, or is reasonably believed to have been, acquired by an unauthorized person. If a breach of the security of a system affects the personal information of more than one thousand (1,000) individuals, the person or business required to make a disclosure of the security breach under subdivision (b)(1) of this section shall, at the same time the security breach is disclosed to an affected individual or within forty-five (45) days after the person or business determines that there is a reasonable likelihood of harm to customers, whichever occurs first, disclose the security breach to the Attorney General. The notification required by this section may be delayed if a law enforcement agency determines that the notification will impede a criminal investigation. The notification required by this section shall be made after the law enforcement agency determines that it will not compromise the investigation. Notification under this section is not required if, after a reasonable investigation, the person or business determines that there is no reasonable likelihood of harm to customers. For purposes of this section, notice may be provided by one (1) of the following methods: Written notice; Electronic mail notice if the notice provided is consistent with the provisions regarding electronic records and signatures set forth in 15 U.S.C. § 7001, as it existed on January 1, 2005; or Substitute notice if the person or business demonstrates that: The cost of providing notice would exceed two hundred fifty thousand dollars ($250,000); The affected class of persons to be notified exceeds five hundred thousand (500,000); or The person or business does not have sufficient contact information. Substitute notice shall consist of all of the following: Electronic mail notice when the person or business has an electronic mail address for the subject persons; Conspicuous posting of the notice on the website of the person or business if the person or business maintains a website; and Notification by statewide media. Notwithstanding subsection (e) of this section, a person or business that maintains its own notification procedures as part of an information security policy for the treatment of personal information and is otherwise consistent with the timing requirements of this section shall be deemed to be in compliance with the notification requirements of this section if the person or business notifies affected persons in accordance with its policies in the event of a breach of the security of the system. A person or business shall retain a copy of the written determination of a breach of the security of a system and supporting documentation for five (5) years from the date of determination of the breach of the security of the system. If the Attorney General submits a written request for the written determination of the breach of the security of the system, the person or business shall send a copy of the written determination of the breach of the security of the system and supporting documentation to the Attorney General no later than thirty (30) days after the date of receipt of the request. The determination and documentation retained under this subsection are confidential and not subject to public disclosure.
Source: official Arkansas text · Last verified 2026-08-27
Frequently Asked Questions About Arkansas § 4-110-105
What does Arkansas Code of 1987 Annotated § 4-110-105 cover?
Section 4-110-105 ("Disclosure of security breaches.") is part of the Arkansas Code of 1987 Annotated, the codified statutory law of Arkansas. It sets out the legal rule or procedure described in the text above. Statutes are amended regularly, so always verify against the official source.
How do I cite Arkansas § 4-110-105?
A common citation format is "Arkansas Code of 1987 Annotated § 4-110-105" (Arkansas). Legal writing may require the code abbreviation, section number, and year or edition. Match the style required by your court, professor, or publisher.
Is this the official text of Arkansas law?
No. This page is for research and education and may not include the most recent amendments. For official current law, check the Arkansas official source linked on this page or consult a licensed Arkansas attorney.
How does Arkansas § 4-110-105 apply to my situation?
Statutes are interpreted in context, and application depends on your specific facts. Only a licensed attorney in Arkansas can advise on how this section applies to you. Contact your state or local bar association for a referral.
Sources & Verification
Not legal advice. Verify against the official source and consult a licensed attorney in Arkansas.