Alaska · verified through August 25, 2026

Alaska: law status and evidence context.

Law status, direct attached-library attribution, and public enforcement context are shown separately. A zero direct total does not mean no enforcement exists.

AK · 6 requirements mapped / control outcomes supported

Law status

No verified general comprehensive law

No comprehensive consumer privacy law verified in force (2021 Consumer Data Privacy Act bills HB 159/SB 116 were pending bill text only)

Official name / citation
n.a.
Status / effective date
Bills only - not verified as enacted
Principal enforcer
Alaska Attorney General / Department of Law

Direct attached-library attribution

0 cases · $0

These totals are assigned solely by the attachment’s state heading. Shared multistate totals are not allocated in full to every state.

The attached library does not enumerate participant-level allocations for every multistate matter; shared settlement totals are presented once at the national level and are not duplicated into state totals.

Official law sources

Other generally applicable PII law

Alaska Personal Information Protection Act, AS 45.48 (breach notification / identity theft) - https://www.akleg.gov/basis/Bill/Text/24?Hsid=HB0270A (bill text of the Act; codified chapter not fetched)

Public enforcement context

Tier 1

Blackbaud, Inc.

$49.5 million to the states; Alaska share stated as $358,925 · October 5, 2023

Alaska joined the 50-jurisdiction Blackbaud settlement over the 2020 ransomware breach.

Legal basis: State consumer protection and breach-notification laws; HIPAA

Official case source (opens in a new tab)

Mapped control outcomes

1 personal data inventory/data map; 2 sensitive-data discovery; 3 downstream copy tracking; 8 breach blast-radius analysis; 9 retention/minimization; 10 regulator audit evidence

Kestryl can evidence where regulated personal data actually resides across structured stores and unstructured attachments/images, produce audit rows and evidence packs showing when each location was discovered and reviewed, and apply structured-data remediation modes (mask, vault, strip) to reduce exposure. It does not alter source attachments or documents, and its output is technical evidence supporting controls, not proof of legal compliance.