Nebraska Data Privacy Act
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Consumer Rights
Implement consumer rights per the NDPA covering: (a) right to confirm whether the controller is processing personal data + access to that data, (b) right to correct inaccuracies, (c) right to delete personal data provided by or obtained about the consumer, (d) right to obtain a portable copy of personal data, (e) right to opt out of targeted advertising + sale of personal data + profiling. Respond to requests within 45 days (extendable by 45 days with notice). Provide a clear and conspicuous appeal mechanism with response within 60 days. Recognise authorised agents acting on behalf of consumers with reasonable verification.
- Consumer rights request portal
- 45-day response tracking
- Appeal mechanism documentation
- Authorised agent verification procedure
- Request log with disposition
- Missing portal
- Late responses
- No appeal mechanism
- No authorised agent process
Enforcement and Compliance
Acknowledge exclusive enforcement by the Nebraska Attorney General Mike Hilgers (in office since January 2023). No private right of action. Civil penalties up to USD 7,500 per violation under the Nebraska Consumer Protection Act. Receive 30-day cure period (which is PERMANENT - unlike Connecticut + Indiana + Tennessee + Texas which have cure period sunsets) before AG may bring action. Effective date: 1 January 2025. Maintain compliance documentation including AG notification readiness + cure response procedures + executive accountability.
- AG notification readiness procedure
- 30-day cure response template
- Executive accountability matrix
- Compliance attestation
- Annual compliance review
- Penalty exposure analysis
- No AG notification readiness
- No cure response template
- No executive accountability
- Stale compliance review
Opt-Out Rights
Provide consumer opt-out rights for: (a) processing personal data for targeted advertising, (b) sale of personal data (defined more narrowly than CCPA - exchange of personal data for monetary consideration), (c) profiling in furtherance of decisions that produce legal or similarly significant effects. NDPA does NOT require Universal Opt-Out Mechanism (UOOM) recognition (unlike Colorado/Connecticut/Texas) but controllers may voluntarily honour GPC + ADPPA signals. Maintain a clear and conspicuous opt-out method including a prominent link to a privacy choices page.
- Privacy choices page
- Opt-out link on homepage
- Sale identification register
- Profiling activity inventory
- UOOM honor documentation (if voluntary)
- No opt-out page
- Sale not identified
- Profiling not inventoried
- No UOOM consideration
Privacy Notice and Data Hygiene
Provide a reasonably accessible + clear + meaningful privacy notice that includes: (1) categories of personal data processed, (2) purposes of processing, (3) how consumers may exercise their rights including the appeal process, (4) categories of personal data shared with third parties, (5) categories of third parties with whom data is shared, (6) opt-out method for sale + targeted advertising + profiling. Apply data minimisation - process only personal data adequate + relevant + reasonably necessary in relation to the disclosed purposes. Apply purpose limitation - do not process personal data for purposes incompatible with the disclosed purposes without consent.
- Privacy Notice covering all 6 mandatory elements
- Annual notice review
- Data inventory tied to purposes
- Minimisation justification
- Purpose change consent records
- Missing notice elements
- Stale notice
- No minimisation justification
- Purpose creep without consent
Risk and Vendor Management
Conduct and document Data Protection Assessments (DPAs) for high-risk processing including: (a) sale of personal data, (b) targeted advertising, (c) profiling presenting reasonably foreseeable risk of unfair or deceptive treatment + financial or physical injury + intrusion upon solitude + other substantial injury, (d) processing of sensitive data, (e) any processing presenting heightened risk of harm. Document risk vs benefit analysis. Make assessments available to AG upon request. Maintain processor contracts with required NDPA clauses (instructions + duration + nature + purpose + types of data + obligations + return/delete on termination + audit rights + subprocessor consent + confidentiality).
- DPA register with assessments
- Risk vs benefit analysis
- Processor contract template with NDPA clauses
- Subprocessor list with consent
- Annual processor audit
- No DPA register
- Missing risk analysis
- Processor contracts missing NDPA clauses
- No subprocessor visibility
Scope and Applicability
Determine applicability of the Nebraska Data Privacy Act (NDPA) per Neb. Rev. Stat. 87-1101 to 87-1124. The NDPA applies to any entity that: (a) conducts business in Nebraska or produces products or services targeted to Nebraska residents, (b) is not a small business as defined by the federal Small Business Administration (SBA), (c) processes or sells personal data UNLESS specifically exempt. Unique among US state laws - NO consumer threshold (broadest US state privacy law in this respect). Maintain documentation of exempt status (financial institutions subject to GLBA + HIPAA covered entities + FERPA institutions + nonprofits + government entities + air carriers + small businesses per SBA size standards + B2B data subject to limited exemption).
- Applicability analysis memo
- SBA small business size determination
- Exemption documentation (GLBA + HIPAA + FERPA)
- Nebraska business registration
- Annual review of applicability
- Incorrect small business test
- Missing exemption documentation
- No applicability memo
- Stale annual review
Security and Incident Response
Establish + implement + maintain reasonable administrative + technical + physical data security practices to protect the confidentiality + integrity + accessibility of personal data appropriate to the volume + nature of the personal data. Align with NIST Cybersecurity Framework or equivalent risk-based programme. Maintain an incident response plan covering detection + containment + eradication + recovery + post-incident review. Comply with Nebraska data breach notification law (Neb. Rev. Stat. 87-801 to 87-807) requiring notification to Nebraska AG and affected residents without unreasonable delay (no fixed deadline but typically within 30-60 days).
- Written security programme
- NIST CSF alignment evidence
- Incident response plan
- Annual tabletop exercise
- Breach notification procedures
- AG notification template
- No written programme
- Missing NIST alignment
- No tabletop
- No breach notification procedures
Sensitive Data and Minors
Obtain affirmative consent before processing sensitive data including racial or ethnic origin + religious beliefs + mental or physical health diagnosis + sexual orientation + citizenship or immigration status + genetic or biometric data processed for unique identification + precise geolocation + data of known children under 13. For known children under 13 process pursuant to COPPA. For minors aged 13 to under 17 obtain opt-in consent for sale of personal data + targeted advertising (one of the stronger US state law protections for teens).
- Sensitive data inventory
- Consent records
- Age verification mechanism
- COPPA compliance attestation
- Teen opt-in tracking (13-17)
- No sensitive data inventory
- Missing consent records
- No age verification
- Teens not opted in
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Nebraska Data Privacy Act framework page.