Arkansas 2025 Regular Session

Arkansas Senate Bill SB258

Introduced
2/19/25  
Refer
2/19/25  
Refer
2/27/25  
Refer
3/13/25  
Report Pass
4/2/25  

Caption

To Create The Arkansas Digital Responsibility, Safety, And Trust Act.

Summary

SB258 creates the Arkansas Digital Responsibility, Safety, and Trust Act, a broad consumer privacy and artificial intelligence regulation law. It establishes a new chapter in Title 4 of the Arkansas Code that sets out legislative findings on privacy, data security, and the risks posed by modern digital technologies, including targeted advertising, biometric data collection, and artificial intelligence. The bill gives Arkansas residents new rights over their personal data, including the right to access, correct, delete, and obtain a portable copy of their data, and the right to opt out of targeted advertising, the sale of personal data, and certain profiling activities. The bill also imposes duties on businesses that process personal data, including notice requirements, data minimization, security safeguards, lawful-basis requirements for processing, restrictions on sensitive data and consumer health data, and mandatory data protection assessments for higher-risk processing. It separately regulates biometric data by requiring retention and destruction policies, written notice and consent before collection, and limits on sale or disclosure. In addition, the bill creates a new framework for “high-risk” artificial intelligence systems, requiring developers and deployers to conduct impact assessments, maintain risk management programs, disclose algorithmic discrimination risks, and provide consumer notices and appeal rights when AI is used in decisions with legal or similarly significant effects. The bill’s impact on state law would be substantial. It adds a new privacy and AI compliance regime to Arkansas law, preempts local ordinances regulating personal data processing, and makes violations enforceable exclusively by the Attorney General as unfair and deceptive trade practices under the Deceptive Trade Practices Act. It also exempts many existing regulated sectors and data categories, including state agencies, HIPAA-covered entities, financial institutions subject to GLBA, higher education institutions, utilities, and various research and employment-related data uses. The bill is scheduled to take effect in phases beginning January 1, 2026, with the AI-specific provisions and enforcement dates following later in 2026. The general sentiment reflected in the bill text and voting history appears mixed but serious and policy-driven, with the measure advancing on third reading by notable margins in both chambers. The bill’s findings emphasize privacy protection, consumer autonomy, and the need to address risks from data brokers, biometrics, and AI-driven decision-making, suggesting a strong pro-privacy and pro-consumer rationale. At the same time, the absence of committee transcript discussion makes it difficult to identify detailed floor debate, and the split vote totals suggest there was meaningful opposition or concern even as the bill moved forward. The main points of contention likely center on the breadth of the compliance obligations, the scope of the AI rules, and the potential burden on businesses. Businesses may be concerned about the cost of assessments, notice obligations, consent requirements, and restrictions on data use, especially for targeted advertising, profiling, and biometric processing. Another likely issue is the bill’s AI provisions, which require risk management, transparency, and consumer appeal rights for high-risk systems; supporters would view these as necessary safeguards against discrimination, while critics may argue they are complex, potentially vague, or burdensome for innovation. The bill also draws a line between covered businesses and exempt sectors, which may be seen as necessary tailoring by supporters and as uneven treatment by critics.

Impact

SB258 would add a comprehensive new privacy and artificial intelligence chapter to Arkansas law, creating enforceable duties for controllers, processors, developers, and deployers of high-risk AI systems. It would expand consumer rights over personal data, regulate sensitive and biometric data, require privacy notices and assessments, and authorize only the Attorney General to enforce the law through Deceptive Trade Practices Act remedies. It also preempts local regulation of personal data processing and exempts many existing regulated data categories and entities, with staggered effective dates in 2026.

Sentiment

The bill appears to have a generally favorable policy posture in the legislature, as reflected by its advancement on third reading in both chambers, but not without opposition. The measure is framed as a privacy and consumer-protection bill responding to modern data and AI risks, which suggests support from lawmakers concerned about digital privacy, discrimination, and data security. The recorded vote margins indicate that while the bill had enough support to move forward, it also faced a meaningful bloc of dissent.

Contention

The likely areas of contention are the scope and cost of compliance, especially for businesses that rely on targeted advertising, data sharing, biometric tools, or AI-driven decision-making. Opponents may object to the bill’s broad definitions, mandatory assessments, consent requirements, and restrictions on profiling and sensitive data processing, while supporters are likely to emphasize consumer privacy, anti-discrimination protections, and transparency. Additional debate may focus on the Attorney General’s exclusive enforcement authority, the preemption of local rules, and the many exemptions for regulated industries and institutions.

Companion Bills

No companion bills found.

Similar Bills

No similar bills found.