Arkansas · verified official-source register

Arkansas Privacy Enforcement Cases

3 verified case records from the authoritative 50-state register. The fields below preserve the supplied amount, date, legal basis and explanation of why the action was brought.

3 official case source links · state register dated August 31, 2026

Actual case links

Arkansas case register

Each record links directly to the official Attorney General or state-agency source supplied for this register. Shared multistate amounts are reproduced as stated and should not be summed as unique state penalties.

Verified case 1 of 3

Blackbaud

Date
not stated in the official release
Amount
$49.5 million payment to states; Arkansas share: $551,941
Legal basis
Arkansas Deceptive Trade Practices Act; Arkansas Personal Information Protection Act; HIPAA

Why the action was brought

Blackbaud’s 2020 ransomware attack exposed Arkansans’ personal information and affected millions of Americans. The company failed to implement reasonable data security, fix known security gaps, and provide customers timely, complete, or accurate breach information, violating Arkansas’s Deceptive Trade Practices Act and Personal Information Protection Act. The stated harm was the data breach and potential further misuse.

View Official Case Source ↗ (opens in a new tab)

Verified case 2 of 3

Marriott International, Inc.

Date
not stated in the official release
Amount
$52 million to states; Arkansas share: $804,965
Legal basis
state consumer protection laws, personal information protection laws, and, where applicable, breach notification laws

Why the action was brought

The settlement resolves allegations that Marriott failed to implement reasonable data security and remediate deficiencies, particularly while integrating Starwood. Intruders remained undetected from July 2014 through September 2018, resulting in the breach of 131.5 million U.S. guest records containing contact information, reservation details, preferences, and limited passport and payment-card information.

View Official Case Source ↗ (opens in a new tab)

Verified case 3 of 3

23andMe

Date
not stated in the official release
Amount
$18 million to the states; Arkansas’s portion: $431,937
Legal basis
No statutes or laws cited.

Why the action was brought

In 2023, 23andMe discovered a data breach affecting 6.9 million consumers, including more than 48,000 Arkansans. The breach exposed customer data, sometimes including genetic ancestry information. The statement says the company initially denied the breach and blamed customers for account setup, and holds it accountable for failing to protect Arkansans’ data.

View Official Case Source ↗ (opens in a new tab)

Source data is based on verified concluded privacy, data-breach and data-security enforcement actions located on official state Attorney General or state-agency sources. Multistate settlement amounts are reproduced as stated by the official source and should not be summed as unique state penalties.