Nebraska Data Privacy Act (NDPA) Compliance: Handle Nebraska Privacy Law Requests on the 45-Day Deadline
The Nebraska Data Privacy Act took effect on January 1, 2025 and it is the one comprehensive state privacy law with no consumer count in it at all. There is no 100,000-resident trigger to fall under. If you do business in Nebraska, you process personal data, and you are not a small business under the federal Small Business Act, you are covered. Obtainer finds where a person's data lives across your systems, compiles one reviewable manifest, drafts the response, and tracks the 45-day clock.
found
scanned
Assembling the cover letter from the template...
Helps you comply, not legal advice
In short
The Nebraska Data Privacy Act (NDPA), passed as LB 1074 and signed in April 2024, took effect on January 1, 2025. Its applicability test has three parts and none of them is a number of consumers: you conduct business in Nebraska or produce a product or service consumed by Nebraska residents, you process or engage in the sale of personal data, and you are not a small business as determined under the federal Small Business Act. Nebraska and Texas are the only two states that scope their privacy law this way. Everywhere else you can count residents and get an answer.
Nebraska consumers can confirm whether you are processing their personal data and access it, correct inaccuracies, delete it, obtain a portable digital copy of data they provided, and opt out of targeted advertising, the sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects. You have 45 days from receipt to respond, extendable once by another 45 days when reasonably necessary if you notify the consumer inside the first window. A denial has to explain itself and tell the consumer how to appeal, and you have 60 days to answer that appeal in writing, with an online route for the consumer to complain to the Attorney General if you refuse.
Enforcement sits exclusively with the Nebraska Attorney General, at up to $7,500 per violation, and there is no private right of action. Before suing, the Attorney General must give you written notice and 30 days to cure, and that cure period is permanent rather than a grace window that sunsets. Curing is not just fixing the problem: you have to provide the Attorney General with a written statement that the violation was cured and that no further violations will occur, and breaching that statement is itself separately actionable. Consent is required before you process sensitive data, and data protection assessments are required for targeted advertising, sales, profiling that presents a reasonably foreseeable risk of harm, sensitive data processing, and any processing that presents a heightened risk of harm.
Obtainer handles the operational half of a Nebraska request: it intakes the request, discovers where the person's data lives across your systems, compiles a source-system manifest, drafts a deadline-safe response, and tracks the 45-day clock and the 60-day appeal. Nothing is disclosed or erased automatically; a human reviews, redacts, and approves before anything goes out. Obtainer helps you comply. It is not legal advice, so whether you clear the small business standard, and every scope and exemption call, stay with your team. Self-serve from a planned $49/mo.
Last updated August 2026
Why it fits
Nebraska businesses of any size above the federal small business standard, plus out-of-state SaaS, ecommerce, retail, insurance, and B2C firms that serve Nebraska residents and never registered Nebraska as in scope because they were looking for a consumer count that does not exist in the statute.
There is no consumer threshold, so the usual scoping shortcut fails
Most privacy teams answer "does this state apply to us" by pulling a count of residents in the CRM. In Nebraska that query returns nothing useful, because the statute never asks. The test is whether you are a small business under the federal Small Business Act, and the SBA sets its size standards per industry against a NAICS code, generally on employee headcount or average annual receipts. A software company and a retailer with identical revenue can land on opposite sides of it. Practically, a mid-market company that assumed it was too small for Colorado or Connecticut can be squarely inside Nebraska.
45 days to respond, then 60 more on appeal
The clock starts when the request arrives, not when somebody opens the ticket. Obtainer stamps the arrival date, starts the countdown, finds the data, drafts the reply, and keeps the appeal on its own 60-day timer, because a denial in Nebraska creates a second deadline and a documented route for the consumer to complain to the Attorney General.
The 30-day cure is permanent, and it is earned with records
Nebraska kept its right to cure with no sunset date, which now puts it in a shrinking group alongside Texas, Virginia, Utah, Indiana, and Iowa. The Attorney General has to give you notice and 30 days before seeking $7,500 per violation. But curing requires a written statement to the Attorney General that the violation is fixed and will not recur, and you can only write that honestly if you can show what was searched, what was found, what was redacted, and what went out. Obtainer keeps that record as a by-product of doing the work. Self-serve from a planned $49/mo, with no five-figure floor before your first request.
Reference
Where the Nebraska Data Privacy Act differs from the state laws you already handle
Nebraska copied the Texas model rather than the Virginia one, and the differences are concentrated in scoping and enforcement rather than in the rights themselves. Each row is a place the NDPA departs from the template most states used, and what that departure changes in your request workflow.
| Requirement | Nebraska (NDPA) | Typical state law | What it changes for you |
|---|---|---|---|
| Applicability test | No consumer count at all. You are covered if you do business in Nebraska or serve Nebraska residents, process or sell personal data, and are not a small business under the federal Small Business Act | A numeric trigger, most often 100,000 residents, or 25,000 plus a revenue-from-sale prong. Connecticut cut its main trigger to 35,000 in July 2026 | You cannot scope Nebraska with a database query. Scope it against your SBA size standard, then treat coverage as a yes or no for the whole company. |
| Small business carve-out | Small businesses are exempt from the Act, but are still prohibited from selling sensitive data without the consumer's consent | Small size is usually irrelevant once you cross the consumer threshold | Being exempt is not being unregulated. If you sell sensitive data you have a consent obligation even as a small business. |
| Sensitive data sale notice | No mandatory notice language. Nebraska dropped the disclosure Texas requires | Texas requires the exact sentence "NOTICE: We may sell your sensitive personal data" in the privacy notice, and a biometric equivalent | If you copied your privacy notice from your Texas build, it is over-compliant in Nebraska rather than wrong. Leave it. |
| Response deadline | 45 days, extendable once by 45 days with notice inside the first window | 45 days plus a 45-day extension in most states. Iowa runs 90 days, Florida caps the extension at 15 | Same clock you already run for nineteen other states. The failure mode is intake, not drafting. |
| Appeal | Required, 60 days to respond in writing, plus an online method to submit a complaint to the Attorney General | Required in most states, usually 45 or 60 days | A denial creates a second deadline. Track it separately from the original request. |
| Universal opt-out signal | Honored only if another state's law already requires you to honor it. Nebraska imposes no independent mandate | Colorado, Connecticut, Texas, Montana, New Jersey, Delaware, Oregon and others require honoring an opt-out preference signal outright | In practice you already handle Global Privacy Control for those states, which switches the Nebraska duty on. Build it once. |
| Cure period and penalty | 30 days, permanent, and curing requires a written statement to the Attorney General that it will not recur. Up to $7,500 per violation, AG only, no private right of action | Commonly 30 or 60 days with a sunset, and Colorado, Connecticut, Delaware, Montana, Minnesota and New Jersey have already lapsed | You get a warning in Nebraska, but you have to sign for it. Producing a complete request record fast is what turns that notice into a closed file. |
More use cases
Related features
Questions
Common questions about this
Who has to comply with the Nebraska Data Privacy Act?
Any person or entity that conducts business in Nebraska or produces a product or service consumed by Nebraska residents, processes or engages in the sale of personal data, and is not a small business as determined under the federal Small Business Act. There is no consumer count and no revenue floor, which is what makes Nebraska different from almost every other state. Financial institutions and entities subject to Title V of the Gramm-Leach-Bliley Act, HIPAA covered entities and business associates, nonprofits, institutions of higher education, electricity suppliers, and natural gas public utilities are exempt at the entity level. If you are unsure which statutes reach you, start with which state privacy laws apply to your business.
When did the Nebraska Data Privacy Act take effect?
January 1, 2025. Governor Jim Pillen signed LB 1074 in April 2024, giving businesses roughly eight months of runway, which was one of the shorter lead times among the state privacy laws. Nebraska switched on the same day as the Delaware, Iowa, and New Hampshire laws, so a company operating nationally picked up four new jurisdictions at once on that date.
Is my business a small business under the Nebraska Data Privacy Act?
Nebraska points at the federal Small Business Act rather than defining the term itself, so the answer comes from the SBA size standards, which are set per industry against a NAICS code and are based on either average number of employees or average annual receipts. There is no single national number. Manufacturers are commonly small at 500 employees or fewer, and many non-manufacturing industries are commonly small under roughly $7.5 million in average annual receipts, but the standard for your specific NAICS code is the one that governs and the exceptions are numerous. The SBA publishes a size standards tool and the full table in 13 CFR 121.201. This is a legal determination about your own business, not something a software vendor can answer for you.
What is the penalty for violating the Nebraska Data Privacy Act?
Up to $7,500 per violation, sought by the Nebraska Attorney General, plus injunctive relief and reasonable expenses including attorney fees and investigative costs. There is no private right of action, so consumers cannot sue you directly. The Attorney General must first send written notice and give you 30 days to cure, and that window does not expire. To cure you have to actually fix the violation and provide a written statement that it has been cured and that no further violations will occur. If you breach that statement, the penalty is back on the table without a second warning.
How long do I have to respond to a Nebraska data subject request?
Forty-five days from receipt of the request. You can take one additional 45-day extension when reasonably necessary given the complexity and number of requests, as long as you notify the consumer of the extension and the reason inside the first 45 days. If you decline to act you have to say so within that same window, explain why, and give instructions for appealing. On appeal you have 60 days to respond in writing. Obtainer starts both clocks at intake and works the DSAR process against them rather than against the date somebody noticed the ticket.
Does Nebraska require honoring Global Privacy Control?
Only conditionally, and this is one of the odder provisions in US privacy law. The NDPA requires you to honor a universal opt-out mechanism such as Global Privacy Control if you are already required to honor one for compliance with another state's law. Nebraska imposes no independent mandate of its own. Since most companies operating nationally are already covered by Colorado, Connecticut, Texas, or one of the other states that do require signal handling, the practical answer for a multi-state business is yes. Build signal handling once and apply it everywhere rather than maintaining a state-by-state exception list.
How is the Nebraska Data Privacy Act different from the Texas privacy law?
Nebraska is closely modeled on the Texas Data Privacy and Security Act and shares the structure that matters most: no consumer threshold, the federal small business standard as the scoping test, the prohibition on small businesses selling sensitive data without consent, the conditional universal opt-out rule, 45 days to respond, and a permanent 30-day cure. The clearest difference is the privacy notice. Texas requires the exact sentence "NOTICE: We may sell your sensitive personal data" from controllers who sell sensitive data, plus a biometric equivalent, and Nebraska requires no such language. If you already run a Texas compliance build, Nebraska mostly rides on it, and the same discovery and subject access request software covers both.
Run a data subject access request end to end
Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.