Nebraska Data Privacy Act (NDPA)

The NDPA is a comprehensive data privacy act designed to protect consumers and give them control over their personal information.

Is Complying with NDPA Mandatory?

The law applies to a person who:  

  • Conducts business in the state or produces a product or service consumed by residents of Nebraska;  

  • Processes or engages in the sale of personal data; and  

  • Is not a small business as determined under the federal Small Business Act. 

What are the penalties for not complying with NDPA?

Those who don’t remedy a violation during the cure period or who breach their written statement will be subject to a $7,500 fine for each violation, which has become relatively standard in data privacy laws.