Nevada data breach law requires every business holding a Nevada resident’s personal information to maintain “reasonable security measures,” and — if you don’t take payment cards — to encrypt that information whenever it leaves your systems electronically. Comply, and the statute gives you something genuinely valuable: protection from damages if you’re breached anyway.

Most small business owners I meet around Reno and Sparks have never heard of NRS Chapter 603A. That’s not carelessness. Nobody sends you a letter about it when you register a business, and the obligations are spread across several sections that don’t read like they were written for a nine-person company. So here’s what it actually says, in plain terms.

I’m an IT consultant, not an attorney, and this is not legal advice. If you’re weighing real exposure, talk to a Nevada business lawyer. What I can tell you is what the statute requires in technical terms and what it costs to actually do.

First: what counts as “personal information”

NRS 603A.040 defines it, and the definition is broader than most people assume. It’s a person’s first name or first initial plus last name, in combination with any one of:

  • Social Security number
  • Driver’s license, driver authorization card, or ID card number
  • Account, credit card, or debit card number together with any code or password that would allow access to the account
  • A medical identification number or health insurance identification number
  • A username, unique identifier, or email address together with a password, access code, or security question and answer that would permit access to an online account

That last one catches people. If you hold a list of customer names alongside login credentials for an account you set up for them, you’re holding personal information under Nevada law — no Social Security numbers required. A lot of businesses that are certain this doesn’t apply to them are wrong for exactly that reason.

Two important carve-outs. The definition applies only when the name and data element are not encrypted — remember that, because it’s the hinge the whole chapter turns on. And it excludes the last four digits of those numbers, plus information lawfully available to the public from government records.

The duty everyone has

NRS 603A.210 is the universal one. If you maintain records containing a Nevada resident’s personal information, you must implement and maintain reasonable security measures to protect those records from unauthorized access, acquisition, destruction, use, modification, or disclosure.

There’s no headcount floor and no revenue threshold. A two-person operation in Spanish Springs carries this duty in the same terms a hundred-person firm does. The statute doesn’t define “reasonable,” which cuts both ways — there’s no checklist to complete, and no checklist to hide behind either.

The subsection almost nobody complies with is 603A.210(3): any contract under which you disclose that personal information to somebody else must include a provision requiring them to maintain reasonable security measures too. Your bookkeeper, your payroll processor, your marketing agency, the CRM vendor holding your client list — if your agreement with them is a handshake or a one-page invoice, that clause almost certainly isn’t there.

And you can’t sign your way out of any of it. NRS 603A.100 states that a waiver of these provisions is contrary to public policy, void, and unenforceable.

The fork: cards or no cards

NRS 603A.215 is where people misread the law, because it looks like a list of duties and is actually a fork. Which branch you’re on depends on one question: do you accept payment cards?

If you do take cards — subsection 1 — you must comply with the current version of the PCI Data Security Standard for those transactions. That’s it; that’s your branch.

If you don’t take cards — subsection 2, which applies specifically to businesses subsection 1 doesn’t cover — you must not do either of these things:

  • Transmit personal information outside your secure system by any electronic, non-voice means without encryption. True fax machine to fax machine is excepted; emailing a spreadsheet is not.
  • Move any data storage device containing personal information beyond your physical or logical control without encryption.

That second point has a detail worth pausing on. The statute defines a “data storage device” broadly — computers, phones, drives, tapes, the medium itself — and separately defines a “multifunctional device,” meaning a machine combining printing, copying, scanning, or faxing. Your office copier has a hard drive in it, and that drive has been quietly retaining scanned documents for years. When the lease ends and it goes back on a truck, that is a data storage device leaving your control.

The law is also specific about what “encryption” means: a technology adopted by a recognized standards body — it names NIST and the Federal Information Processing Standards — and appropriate management and safeguarding of the cryptographic keys. Both halves. Encryption with the key taped to the box is not encryption.

Why this is worth doing even if nobody is checking

Here’s the part that ought to be better known, because it turns compliance from a chore into a straightforwardly good deal.

NRS 603A.215(3) is a safe harbor. A business is not liable for damages arising from a breach if it was in compliance with the section and the breach wasn’t caused by its own gross negligence or intentional misconduct. You do the work in advance, and the statute limits what a bad day can cost you.

And encryption is the off-ramp from notification entirely. NRS 603A.220 requires you to notify affected Nevada residents when their unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person. Encrypted data doesn’t trigger that obligation. If a laptop with a properly encrypted drive is stolen from a truck in a parking lot off McCarran, you have lost a laptop. If that same drive is unencrypted, you may have a notification event, a disclosure conversation with every affected customer, and a permanent entry in the story your business tells about itself.

One stolen laptop, two completely different years, and the only variable is whether somebody turned encryption on beforehand.

What compliance actually costs

Take that twelve-person Reno business again. Here’s the honest work involved, in hours, at my published business rate of $125/hour.

  • Find out what you actually hold and where it goes — 3 hours. Almost always the most valuable step, and almost always surprising.
  • Turn on and verify full-disk encryption across 12 machines — 3 hours. On modern Windows and Mac hardware this capability is already there and switched off.
  • Set up a way to send personal information securely, and train people to use it — 3 hours.
  • Add the required security clause to vendor agreements and write down your security position — 2 hours.

That’s 11 hours. Bought as a 10-hour prepaid block plus one hour at the standard rate: $1,000 + $125 = $1,125. Add a password manager rollout at $150, and $1,125 + $150 = $1,275 — one time, plus whatever your existing software licensing already costs. Bought as straight hourly instead, 11 × $125 = $1,375, so the block saves $250.

Now price the other side. A notification event doesn’t start with letters — it starts with establishing what was taken, which means someone billing hours to reconstruct it, usually under time pressure. Then legal review of the notice. Then the mailing. Then the phone calls from customers who received it. I’m not going to quote you a total, because the honest answer is that it depends heavily on what happened and I’d be making the number up. But look at the shape of it: the first line item alone is hourly professional work, done under time pressure, reconstructing events after the fact. Prevention is a scheduled job you can shop around for. Response is not.

The comparison isn’t close. It also isn’t the real argument, which is the safe harbor: the cheap version buys you a statutory limit on liability, and the expensive version is what you pay for not having bought it.

When this is over-engineering

I’d rather say this plainly than sell security to somebody who doesn’t need it.

If you genuinely hold no personal information, the encryption provisions in 603A.215 have nothing to attach to. A landscaping business whose customer records are names, addresses, and what was mowed is not holding personal information as the statute defines it. Names and addresses alone don’t qualify. Don’t buy a compliance project for data you don’t have.

If everything already lives in a reputable cloud service and nothing sensitive travels by email, you may be most of the way there without knowing it. Microsoft 365 and Google Workspace encrypt data in transit and at rest by default. The gaps in that setup are usually the exports — the spreadsheet someone downloaded to a laptop, the file emailed to the accountant — rather than the platform itself.

And if you take payment cards, PCI is your obligation, not subsection 2. Doing PCI properly is a bigger and more specific job than what I’ve described. Don’t let a general encryption conversation substitute for it.

One more, which cuts against my own interests: if your budget only stretches to one thing this year, spend it on backups rather than encryption. Ransomware and hardware failure are what actually take Northern Nevada small businesses off the air. Encryption limits what a breach costs you; backup determines whether you still have a business next week.

Does this apply to my business if I’m not based in Nevada?

The chapter reaches data collectors doing business in Nevada and holding personal information of Nevada residents. Where your office sits matters less than whose data you hold. If you have Nevada customers, assume it applies and ask a Nevada attorney if the answer would change what you do.

Are names and email addresses alone covered?

No. Under NRS 603A.040 a name only becomes personal information when combined with a listed element — a Social Security, license, financial account, or medical number, or an email or username paired with a password or security answer. A plain mailing list of names and email addresses does not meet that definition.

Is my email already encrypted enough?

Usually in transit, often not in the way that matters. Mainstream providers encrypt the connection between mail servers, but that does not guarantee the message stayed encrypted end to end or that attachments are protected once delivered. If you routinely email sensitive documents, that specific path is worth testing rather than assuming.

How fast do I have to notify people after a breach?

NRS 603A.220 requires disclosure in the most expedient time possible and without unreasonable delay, allowing for law enforcement needs and for the work of determining scope and restoring integrity. There is no fixed day count, which in practice means you cannot sit on it while you decide what to do.

What about the copier when its lease ends?

Its hard drive is a data storage device leaving your control, and it may hold years of scanned documents. Ask the leasing company in writing what happens to that drive. Many offer wiping or drive retention, sometimes for a fee, and it is far cheaper than discovering the answer afterward.

If you’d like to know where you actually stand, the useful first step is the boring one: finding out what personal information you hold and which paths it travels. That’s a few hours, and it usually reshapes the conversation. Cybersecurity work is where that starts, backup and data protection is the part I’d do first if you only do one, and if the answer turns out to be “move this off the shared drive and into something properly managed,” that’s cloud services. Call (775) 823-3333 or email [email protected].