Is my business exempt from the Nebraska Data Privacy Act?
Nebraska's Data Privacy Act does not apply to state agencies, financial institutions or Gramm-Leach-Bliley data, HIPAA covered entities and business associates, nonprofits, institutions of higher education, or certain electric and natural gas utilities. Small businesses are also outside it, except that they still may not sell sensitive data without consent.
Applies to: Businesses deciding whether the Nebraska Data Privacy Act reaches them, including HIPAA covered entities and business associates, financial institutions, nonprofits, universities, utilities, and small businesses under the federal Small Business Act.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanNebraska put its exemptions in one short section, which makes this one of the faster applicability questions to answer. Read section 87-1103 top to bottom and you will usually know within a minute.
First, the three conditions that must all be true
Section 87-1103(1) says the Data Privacy Act applies only to a person that conducts business in Nebraska or produces a product or service consumed by residents of the state; processes or engages in the sale of personal data; and is not a small business as determined under the federal Small Business Act as that act existed on January 1, 2024, except to the extent that section 87-1118 applies.
All three have to be satisfied. Notice what is missing: there is no consumer-count threshold and no revenue threshold. Nebraska took the same approach Texas did and made federal small-business status the dividing line instead of a number.
The eight entity exemptions
Section 87-1103(2) then removes whole categories of organization. The Act does not apply to any:
State agency or political subdivision of Nebraska. Financial institution, affiliate of a financial institution, or data subject to Title V of the Gramm-Leach-Bliley Act as that title existed on January 1, 2024. Covered entity or business associate governed by the HHS privacy, security, and breach notification rules at 45 C.F.R. parts 160 and 164 as those parts existed on January 1, 2024, together with Division A, Title XIII and Division B, Title IV of the HITECH Act. Nonprofit organization. Institution of higher education. Electric supplier or supplier of electricity as defined in section 70-1001.01. Natural gas public utility as defined in section 66-1802. Natural gas utility owned or operated by a city or a metropolitan utilities district.
Why the HIPAA exemption is broader than it looks
This is the point most often misread. Nebraska exempts the entity, not merely the protected health information it holds.
Several states take the narrower route and exempt only PHI, which leaves a hospital or health-tech vendor in scope for its marketing lists, its website analytics, and its job applicant data. Nebraska does not do that. If you are a covered entity or a business associate governed by 45 C.F.R. parts 160 and 164, section 87-1103(2)(c) takes you out of the Act.
Two details are worth pinning down before relying on it. Nebraska defines covered entity in section 87-1102(9) by reference to 45 C.F.R. 160.103 as that regulation existed on January 1, 2024, and defines business associate in section 87-1102(4) by reference to HIPAA. Both definitions are frozen to that date, so later federal amendments do not automatically move the Nebraska line. And the exemption depends on actually being governed by those rules. A wellness app or a direct-to-consumer health service that never becomes a covered entity or a business associate does not get this exemption, however health-related its data feels.
The small-business route is not a clean exit
Section 87-1103(1)(c) carries a qualifier that is easy to skip: the small-business carve-out applies except to the extent that section 87-1118 applies.
Section 87-1118(1) provides that a person described by subdivision (1)(c) of section 87-1103 shall not engage in the sale of personal data that is sensitive data without receiving prior consent from the consumer. Subsection (2) makes a violator subject to the penalty under section 87-1124.
The cross-reference between these two provisions is drafted awkwardly, and we are not going to pretend it reads cleanly. What is clear from the text is that the small-business carve-out in 87-1103(1)(c) is expressly made subject to 87-1118, and that 87-1118 forbids selling sensitive data without prior consent. The practical planning assumption is straightforward: if you are a small business selling sensitive data about Nebraskans, do not treat the size exemption as the end of the analysis.
Sensitive data is defined in section 87-1102(30) and covers personal data revealing racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, or citizenship or immigration status; genetic or biometric data processed to uniquely identify an individual; personal data collected from a known child; and precise geolocation data.
Nonprofits and universities, briefly
Both are exempt outright under sections 87-1103(2)(d) and (2)(e). Nebraska's definition of nonprofit organization in section 87-1102(19) is wider than most: corporations under the Nebraska Nonprofit Corporation Act, organizations exempt under sections 501(c)(3), 501(c)(6), or 501(c)(12) of the Internal Revenue Code, certain 501(c)(4) organizations established to detect or prevent insurance-related crime or fraud, and subsidiaries or affiliates of cooperative corporations organized in the state.
This is a real divergence between states. Delaware and Maryland reach many nonprofits and universities that Nebraska leaves alone, so a national organization can be exempt here and in scope there.
Next step
An exemption in one state is not an exemption anywhere else, and that is where most compliance effort gets misallocated. The free 2-minute Obligation Scan checks your business against every US state privacy law and GDPR at once and tells you which ones actually reach you. For the applicability test itself, see the Nebraska Data Privacy Act overview, and for how the small-business gate compares with the numeric tests elsewhere, see privacy thresholds by state.
Compliance checklist
- Work through the three cumulative conditions in section 87-1103(1) first: you must conduct business in Nebraska or produce a product or service consumed by residents, process or sell personal data, and not be a small business.
- Check the eight entity exemptions in section 87-1103(2) before doing any threshold analysis, because an entity exemption ends the inquiry.
- If you are a HIPAA covered entity or business associate, confirm that status against 45 C.F.R. 160.103 as it existed on January 1, 2024, which is the version Nebraska's definition freezes.
- If you rely on the small-business route, do not treat it as a complete exemption: section 87-1118 still bars selling sensitive data without prior consent.
- Confirm whether the data you hold is sensitive data under section 87-1102(30), which covers racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, citizenship or immigration status, genetic or biometric data used to identify someone, data from a known child, and precise geolocation.
- Remember that an exemption in Nebraska says nothing about other states; the same company can be exempt here and in scope in California or Colorado.
Sources
- Neb. Rev. Stat. 87-1103, Applicability of act to persons or entities, Nebraska Legislature
- Neb. Rev. Stat. 87-1102, Terms, defined, Nebraska Legislature
- Neb. Rev. Stat. 87-1118, Sensitive data; sale; consent required, Nebraska Legislature
Last verified: 2026-08-21
Informational, not legal advice.