Wyoming · verified through August 25, 2026

Wyoming: law status and evidence context.

Law status, direct attached-library attribution, and public enforcement context are shown separately. A zero direct total does not mean no enforcement exists.

WY · 6 requirements mapped / control outcomes supported

Law status

No verified general comprehensive law

No comprehensive consumer privacy law verified (Wyoming Data Privacy Act drafts were interim-committee working drafts)

Official name / citation
n.a.
Status / effective date
Draft bills only
Principal enforcer
Wyoming Attorney General (Consumer Protection and Antitrust Unit)

Direct attached-library attribution

0 cases · $0

These totals are assigned solely by the attachment’s state heading. Shared multistate totals are not allocated in full to every state.

The attached library does not enumerate participant-level allocations for every multistate matter; shared settlement totals are presented once at the national level and are not duplicated into state totals.

Official law sources

Other generally applicable PII law

Security breach notification, 2015 Wyo. Sess. Laws ch. 65 (SEA No. 0022) - https://wyoleg.gov/2015/Digest/SF0035.PDF (codified citation not verified in this session)

Public enforcement context

Tier 1

Equifax Inc.

$175 million to the states, including $1 million to Wyoming; $300 million consumer fund (up to $425 million total) · 2019 (resolved matter listing; exact announcement date not stated)

The Wyoming AG's resolved-matters page records Wyoming's participation in the Equifax settlement over the 2017 breach affecting more than 147 million Americans.

Legal basis: State consumer protection and data-security claims

Official case source (opens in a new tab)

Mapped control outcomes

1 personal data inventory/data map; 2 sensitive-data discovery; 3 downstream copy tracking; 8 breach blast-radius analysis; 9 retention/minimization; 10 regulator audit evidence

Kestryl can evidence where regulated personal data actually resides across structured stores and unstructured attachments/images, produce audit rows and evidence packs showing when each location was discovered and reviewed, and apply structured-data remediation modes (mask, vault, strip) to reduce exposure. It does not alter source attachments or documents, and its output is technical evidence supporting controls, not proof of legal compliance.