United States — Nebraska
§ 87-1103. Applicability of act to persons or entities.
1 provisions
The Data Privacy Act applies only to certain persons and excludes several listed entities and organizations.
Browse 35,870 source-backed statutes, open stored provisions, and verify official source links.
Latest source update shown on this page: .
35,870 statutes · page 1,761 of 1,794
United States — Nebraska
1 provisions
The Data Privacy Act applies only to certain persons and excludes several listed entities and organizations.
United States — Nebraska
1 provisions
This section says the Data Privacy Act does not apply to listed health, research, employment, and other specified information categories.
United States — Nebraska
1 provisions
The Act does not apply to personal data processing done for purely personal or household activity.
United States — Nebraska
1 provisions
A controller or processor collecting online data is treated as complying with the Data Privacy Act’s parental-consent requirement if it meets COPPA verifiable parental consent rules and guidance as of January 1, 2024.
United States — Nebraska
1 provisions
A consumer may ask a controller to exercise specified consumer rights, and a parent or legal guardian may do so for a known child’s personal data.
United States — Nebraska
1 provisions
A controller must respond to consumer rights requests under section 87-1107, usually within 45 days, and may extend once by another 45 days if needed.
United States — Nebraska
1 provisions
A controller must have a consumer appeal process, make it easy to find, respond in writing within 60 days, and give the consumer the Attorney General complaint mechanism if the appeal is denied.
United States — Nebraska
1 provisions
A contract term cannot waive or limit certain consumer rights; if it does, it is void and unenforceable.
United States — Nebraska
1 provisions
Controllers must offer secure ways for consumers to submit privacy requests and must not require a new account. Consumers may also use authorized agents to make opt-out requests.
United States — Nebraska
1 provisions
A controller must limit personal data collection, use reasonable data security practices, and avoid certain processing and discrimination practices.
United States — Nebraska
1 provisions
If a controller sells personal data to a third party or uses it for targeted advertising, it must clearly disclose that process and how a consumer can opt out.
United States — Nebraska
1 provisions
A processor must follow the controller’s instructions and help the controller meet Data Privacy Act requirements.
United States — Nebraska
1 provisions
A controller must conduct and document data protection assessments for certain personal-data processing activities, and must provide a requested assessment to the Attorney General.
United States — Nebraska
1 provisions
A controller with deidentified data must take reasonable steps to keep it from being linked to an individual, publicly commit not to reidentify it, and require recipients to follow the Data Privacy Act.
United States — Nebraska
1 provisions
A covered person may not sell sensitive personal data without prior consumer consent.
United States — Nebraska
1 provisions
The Attorney General has exclusive authority to enforce the Data Privacy Act.
United States — Nebraska
1 provisions
The Attorney General must post specified Data Privacy Act information and an online complaint mechanism on the Attorney General’s website.
United States — Nebraska
1 provisions
The Attorney General may issue civil investigative demands and may ask a controller to disclose a relevant data protection assessment.
United States — Nebraska
1 provisions
Before suing under section 87-1124, the Attorney General must give the controller or processor written notice at least 30 days in advance, identifying the alleged violation. The Attorney General may not sue if the violation is cured within that period and the controller or processor gives the required written statement