Arkansas · verified through August 25, 2026

Arkansas: law status and evidence context.

Law status, direct attached-library attribution, and public enforcement context are shown separately. A zero direct total does not mean no enforcement exists.

AR · 6 requirements mapped / control outcomes supported

Law status

No verified general comprehensive law

No comprehensive consumer privacy law verified

Official name / citation
n.a.
Status / effective date
n.a.
Principal enforcer
Arkansas Attorney General

Direct attached-library attribution

0 cases · $0

These totals are assigned solely by the attachment’s state heading. Shared multistate totals are not allocated in full to every state.

The attached library does not enumerate participant-level allocations for every multistate matter; shared settlement totals are presented once at the national level and are not duplicated into state totals.

Official law sources

Other generally applicable PII law

Arkansas Personal Information Protection Act, Ark. Code § 4-110-101 et seq. (Act 1526 of 2005) - https://www.transform.ar.gov/wp-content/uploads/2020/05/Act1526.pdf

Public enforcement context

Tier 1

Marriott International, Inc.

$52 million to the states; Arkansas share stated as $804,965 · n.a. (date not stated on page)

Arkansas joined the 50-AG Marriott/Starwood settlement over a multi-year reservation-database breach.

Legal basis: State consumer protection, personal-information protection and breach-notification laws

Official case source (opens in a new tab)

Mapped control outcomes

1 personal data inventory/data map; 2 sensitive-data discovery; 3 downstream copy tracking; 8 breach blast-radius analysis; 9 retention/minimization; 10 regulator audit evidence

Kestryl can evidence where regulated personal data actually resides across structured stores and unstructured attachments/images, produce audit rows and evidence packs showing when each location was discovered and reviewed, and apply structured-data remediation modes (mask, vault, strip) to reduce exposure. It does not alter source attachments or documents, and its output is technical evidence supporting controls, not proof of legal compliance.