iQ Cookie  State Law Series

State 2 of 25 · Arkansas

Cookie & Privacy Law in Arkansas

Published July 2026 · Updated August 2026
Children’s law in effect
First “COPPA 2.0” state

Educational purposes only — not legal advice. This guide is intended to help you understand Arkansas’s privacy and cookie consent laws. Laws change, and your situation may vary. Always consult a qualified legal professional before making compliance decisions. iQ Cookie is a technology tool, not a law firm.

CHILDREN’S LAW
ACTOPPA
HB 1717, Act 952 of 2025
IN EFFECT SINCE
Jul 1, 2026
Teens 13–16 covered
BREACH LAW
PIPA
Act 1526 of 2005
COMPREHENSIVE LAW
None yet
No general opt-out rights

The short version

Arkansas is a different animal from most states in this series: it does not have a comprehensive consumer privacy law. There is no Arkansas version of Virginia’s VCDPA or California’s CCPA — no general right for adults to access, delete, or opt out of the sale of their data under state law. Bills have been floated, but as of this writing nothing comprehensive has passed.

What Arkansas does have is a national first. The Arkansas Children and Teens’ Online Privacy Protection Act (ACTOPPA) took effect July 1, 2026, making Arkansas the first state to enact a “COPPA 2.0” law — it extends child data protections to teenagers aged 13–16 and bans targeted advertising built on their data. Underneath that sits the Personal Information Protection Act (PIPA), the state’s 2005 data security and breach notification law. If your site could reach Arkansas kids or teens, ACTOPPA applies to you regardless of your size or revenue.

CHILDREN & TEENS LAW

Arkansas Children & Teens’ Online Privacy Protection Act (ACTOPPA)
HB 1717 / Act 952  ·  In effect since July 1, 2026

SECURITY & BREACH LAW

Personal Information Protection Act (PIPA)
Act 1526  ·  In effect since 2005, expanded 2019

Arkansas Legislature — Official Site
Arkansas Bureau of Legislative Research — ACTOPPA & PIPA bill text

Who does it apply to?

ACTOPPA has no revenue or user-count thresholds. It applies to any operator of an online service, website, or app that is:

TRIGGER 1

Directed at children or teens — the service’s content, design, or marketing targets users under 17.

TRIGGER 2

Has actual knowledge that it is collecting personal information from Arkansas children (under 13) or teens (13–16).

PIPA is broader still: any person or business that acquires, owns, or licenses computerized personal information of Arkansas residents must maintain reasonable security, destroy records it no longer needs, and notify affected residents after a breach.

No comprehensive law does not mean no rules. Your privacy policy still has to be honest — the FTC treats saying one thing and doing another as a deceptive practice, and so does the Arkansas AG under the state’s consumer protection law. And if your site draws visitors from neighboring states, their privacy laws travel with them.

What ACTOPPA requires

The law is modeled on federal COPPA and the proposed “COPPA 2.0” — familiar principles, extended to teens:

Notice
Clearly disclose what is collected from minors and why
Consent
Verifiable parental consent under 13; consent for teens 13–16
Data minimization
Collect only what the service reasonably needs
No targeted ads
No behavioral advertising built on minors’ data
Review & delete
Honor requests to review and remove a minor’s data
Security
Maintain reasonable safeguards for minors’ data

Federal COPPA only covers children under 13. Arkansas created a second tier for teens aged 13–16 — the first state in the country to do it.

What makes Arkansas stand out

First “COPPA 2.0” state in the nation. ACTOPPA extends federal-style child data protections to teenagers aged 13–16. Other states are watching Arkansas as the template — expect copycats in upcoming sessions.

Targeted advertising to minors is banned. If your service collects data from Arkansas users under 17, you cannot use that data for behavioral advertising. There is no business-size exception and no threshold to duck under.

No comprehensive consumer privacy law — yet. Adults in Arkansas have no general state-law right to access, delete, or opt out of the sale of their data. Watch this space: with 24 states now holding comprehensive laws, Arkansas legislators are under growing pressure to join them.

Beware of online sources claiming Arkansas has a comprehensive “data protection act.” As of this writing, it does not.

PIPA still has teeth. The 2005 law requires reasonable security practices, secure destruction of records, and breach notification — and the AG enforces violations as deceptive trade practices. A sloppy breach response is the fastest way for an Arkansas business to end up in the AG’s crosshairs.

What this means for your cookies

Cookie / data typeRequirementWhat to do
Any cookies — children under 13Opt-in requiredVerifiable parental consent before collecting personal information. No pre-ticked boxes, no dark patterns.
Any cookies — teens 13–16Opt-in requiredConsent required before collection — the tier federal COPPA never covered.
Targeted advertising to minorsBannedZero behavioral advertising to Arkansas users under 17. Implement age signals or treat unknown users conservatively.
Adult users’ cookiesNo specific AR requirementDisclose honestly in your privacy notice — and remember out-of-state visitors bring their own states’ laws with them.
GPC / opt-out signalsRecommendedNot legally required under Arkansas law, but recommended for multi-state compliance.
Stored personal informationPIPA securityReasonable security, secure destruction, and a breach notification plan for any Arkansas resident data you keep.

Enforcement

AG only
No private lawsuits
Deceptive practice
Enforced under consumer protection law
Jul 1, 2026
ACTOPPA enforcement live now

The Arkansas Attorney General has exclusive enforcement authority under both ACTOPPA and PIPA — there is no private right of action. Violations are pursued as deceptive or unfair trade practices, with injunctions, damages, and restitution on the table. The AG’s office has shown real appetite for data privacy cases, including suits against major companies over collecting and selling consumer data without consent. A brand-new, first-in-the-nation law is exactly the kind of thing an AG likes to enforce visibly.

Your action checklist

ACTOPPA is already in effect — this list is for right now:

1

Assess your ACTOPPA exposure. Could your site reach Arkansas users under 17? If yes — or if you don’t know — treat the law as applying. There is no threshold exemption.

2

Build the two consent tiers. Verifiable parental consent for children under 13, and a consent flow for teens 13–16 before collecting their personal information.

3

Kill targeted advertising for minors. No behavioral ads built on data from users under 17. Configure your ad stack with age signals, or default unknown users to the protected treatment.

4

Minimize what you collect from minors. Only what the service reasonably needs — no “collect everything” approach for that user segment.

5

Shore up PIPA compliance. Reasonable security for stored personal information, secure destruction of records you no longer need, and a written breach notification plan.

6

Update your privacy policy. Describe what you collect from minors, how consent works, how parents and teens can request review or deletion, and how you secure the data.

7

Watch for a comprehensive law. Arkansas is one of the shrinking number of states without one. When it comes, this guide will be updated — and your consent setup should be ready to extend to adults.

Not sure where your site stands with Arkansas?

iQ Cookie scans your site for compliance gaps and deploys a lightweight US-built consent banner with age-aware consent controls.

iQ Cookie State Law Series  ·  Guide 2 of 25  ·  Next: California →