Nevada Revised Statutes

Nev. Rev. Stat. § 603A.210 (2026)

Security measures

✓ current as of July 2026
Find cases: SyfertCases citing this section NRSleg.state.nv.us (official) Justiaon Justia CornellLII Search CasesGoogle Scholar
NRS 603A.210  Security measures.

      1.  A data collector that maintains records which contain personal information of a resident of this State shall implement and maintain reasonable security measures to protect those records from unauthorized access, acquisition, destruction, use, modification or disclosure.

      2.  If a data collector is a governmental agency and maintains records which contain personal information of a resident of this State, the data collector shall, to the extent practicable, with respect to the collection, dissemination and maintenance of those records, comply with the current version of the CIS Controls as published by the Center for Internet Security, Inc. or its successor organization, or corresponding standards adopted by the National Institute of Standards and Technology of the United States Department of Commerce.

      3.  A contract for the disclosure of the personal information of a resident of this State which is maintained by a data collector must include a provision requiring the person to whom the information is disclosed to implement and maintain reasonable security measures to protect those records from unauthorized access, acquisition, destruction, use, modification or disclosure.

      4.  If a state or federal law requires a data collector to provide greater protection to records that contain personal information of a resident of this State which are maintained by the data collector and the data collector is in compliance with the provisions of that state or federal law, the data collector shall be deemed to be in compliance with the provisions of this section.

      5.  The Office of Information Security and Cyber Defense of the Governor’s Technology Office within the Office of the Governor shall create, maintain and make available to the public a list of controls and standards with which the State is required to comply pursuant to any federal law, regulation or framework that also satisfy the controls and standards set forth in subsection 2.

      (Added to NRS by 2005, 2504; A 2019, 2574; 2025, 1967, 3569)

     

Notes of Decisions
Cited in 10 cases (5 in the last 5 years), 2016–2025 · leading case: Mcconnell Et Al. v. Dep't of Labor, 787 S.E.2d 794 (Ga. Ct. App. 2016).
Mcconnell Et Al. v. Dep't of Labor, 787 S.E.2d 794 (Ga. Ct. App. 2016). “”); Nev. Rev. Stat. Ann. § 603A.210 (1) (“A data collector that maintains records which contain personal information of a resident of this State shall implement and maintain reasonable security measures to protect those records from unauthorized access, acquisition, destruction,…”
Mcconnell Et Al. v. Dep't of Labor., 814 S.E.2d 790 (Ga. Ct. App. 2018). “"); Nev. Rev. Stat. Ann. § 603A.210 (1) ("A data collector that maintains records which contain personal information of a resident of this State shall implement and maintain reasonable security measures to protect those records from unauthorized access, acquisition, destruction,…”
Clark Cty. Sch. Dist. Vs. Las Vegas Review-journal, 2018 NV 84 (Nev. 2018). “040 that must be protected against disclosure under NRS 603A.210. The list in NRS 239.010(1) also includes confidentiality provisions in NRS 200.”
Archambault v. Riverside Resort & Casino, Inc. (D. Nev. 2025). · cites it 3× “Plaintiffs allege that Riverside violated this 23 provision by failing to disclose the material fact that its data security measures were inadequate 24 and by violating statutes such as the FTC and NRS 603A.210 requiring data collectors to 25 “implement and maintain reasonably…”
Clark Cty. Sch. Dist. Vs. Las Vegas Review-journal, 2018 NV 84 (Nev. 2018). · cites it 2× “040 that must be protected against disclosure under NRS 603A.210. The list in NRS 239.010(1) also includes confidentiality provisions in NRS 200.”
Gill v. Caesars Ent., Inc. (D. Nev. 2025). · cites it 2× “Plaintiffs allege that Caesars violated this provision by breaching 12 several federal and state statutes, including NRS 603A.210(1), which requires 13 that “[a] data collector that maintains records which contain personal information 14 of a resident of this States shall…”
Clark Cty. Sch. Dist. Vs. Las Vegas Review-journal, 2018 NV 84 (Nev. 2018). “040 that must be protected against disclosure under NRS 603A.210. The list in NRS 239.010(1) also includes confidentiality provisions in NRS 200.”
Whittum v. Univ. Med. Ctr. of S. Nevada (D. Nev. 2022). “Parts 160-64; HIPAA Privacy 28 Regulations), and NRS 603A.210, which protect the confidentiality of individually identifiable 1 personal and health information.”
Houghton v. Rancho Mesquite Casino, Inc. (D. Nev. 2024). “41 at 9 (citing NRS 603A.210 and Cal. Civ. Code § 1798.81.”
Smith v. Findlay Auto., Inc. (D. Nev. 2025). “21 Moreover, Defendants concede that NRS 603A.210(1) can establish duty and breach, as 22 alleged by Plaintiffs.”
— Nev. Rev. Stat. § 603A.210(1) — 3 cases
Gill v. Caesars Ent., Inc. (D. Nev. 2025). “Plaintiffs allege that Caesars violated this provision by breaching 12 several federal and state statutes, including NRS 603A.210(1), which requires 13 that “[a] data collector that maintains records which contain personal information 14 of a resident of this States shall…”
Archambault v. Riverside Resort & Casino, Inc. (D. Nev. 2025). “Plaintiffs allege that Riverside violated this 23 provision by failing to disclose the material fact that its data security measures were inadequate 24 and by violating statutes such as the FTC and NRS 603A.210 requiring data collectors to 25 “implement and maintain reasonably…”
Smith v. Findlay Auto., Inc. (D. Nev. 2025). “21 Moreover, Defendants concede that NRS 603A.210(1) can establish duty and breach, as 22 alleged by Plaintiffs.”
Annotations are extracted automatically from the opinions in the Syfert caselaw corpus and ranked by authority, recency, and treatment. Dots show Syfertize treatment of the citing case itself.