How must a business accept privacy requests in Nebraska?
Nebraska requires a controller to offer at least two secure and reliable methods for consumers to submit privacy requests. A controller operating exclusively online with a direct relationship with the consumer needs only provide an email address. Consumers may also opt out through an authorized agent or browser signal.
Applies to: Controllers subject to the Nebraska Data Privacy Act that must provide consumers with a way to submit requests to exercise their rights, including opt-out requests sent by authorized agents.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanNebraska's rule on how consumers reach you is short, and it contains one genuine break for online businesses that most states do not offer.
Two methods, chosen deliberately
Section 87-1111(1) requires a controller to establish two or more secure and reliable methods to enable a consumer to submit a request to exercise consumer rights. The methods must take into account the ways in which consumers normally interact with the controller, the necessity for secure and reliable communications of those requests, and the ability of the controller to authenticate the identity of the consumer making the request.
Those three factors are not decoration. A method that consumers never use, or that you cannot authenticate through, does not really satisfy the section even if it technically exists.
Section 87-1111(2) adds the rule that appears in nearly every state law: a controller shall not require a consumer to create a new account to exercise a right, though it may require the consumer to use an existing account.
The online-only exception
Section 87-1111(3) requires a controller that maintains a website to provide a mechanism on that website for submitting requests for information the Act requires to be disclosed.
Then 87-1111(4) carves out an exception. A controller that operates exclusively online and has a direct relationship with a consumer from whom it collects personal information is only required to provide an email address for the submission of those requests.
Both conditions have to hold. Exclusively online, and a direct relationship with the consumer whose data you collect. A business with any offline channel, or one collecting data about people it has no relationship with, does not qualify. For a pure SaaS product with its own signed-up users, this is a real simplification.
Authorized agents and browser signals
Section 87-1111(5) lets a consumer designate another person as an authorized agent to opt out of the processing covered by 87-1107(2)(e)(i) and (ii). The designation may be made using a technology, including a link to a website, a browser setting or extension, or a global setting on an electronic device.
A controller must comply with an agent's opt-out where it can verify, with commercially reasonable effort, the consumer's identity and the agent's authority.
The four grounds for refusing an agent request
This is where Nebraska is unusually explicit. Under 87-1111(5), a controller is not required to comply if the authorized agent does not communicate the request in a clear and unambiguous manner; the controller cannot verify with commercially reasonable effort that the consumer is a Nebraska resident; the controller does not possess the ability to process the request; or the controller does not process similar or identical requests received from consumers for the purpose of complying with similar or identical laws or regulations of another state.
That last ground is worth reading twice. It effectively ties your Nebraska obligation to what you already do elsewhere: a business that honors browser opt-out signals for Colorado or California cannot then decline to honor them in Nebraska on capability grounds.
What the technology must do
Section 87-1111(6) sets three requirements for the opt-out technology. It shall not unfairly disadvantage another controller. It shall not make use of a default setting, but shall require the consumer to make an affirmative, freely given, and unambiguous choice. And it shall be consumer-friendly and easy to use by the average consumer.
The no-default rule cuts both ways: a signal that a browser turns on without the user choosing it is not one Nebraska obliges you to treat as a valid opt-out.
Next step
Request intake is the part of a privacy program that consumers actually see, and the requirements differ enough between states that one form rarely satisfies all of them. The free 2-minute Obligation Scan tells you which US state privacy laws apply to your business and what each requires. See the Nebraska Data Privacy Act overview for applicability, Nebraska's entity exemptions for whether the Act reaches you at all, and Texas browser opt-out signals for the comparable Texas route.
Compliance checklist
- Offer at least two secure and reliable submission methods unless the online-only exception applies to you.
- Choose those methods against the three factors in 87-1111(1): how consumers normally interact with you, the need for secure and reliable communication, and your ability to authenticate the requester.
- Never require a consumer to create a new account to exercise a right, though you may require them to use an existing one.
- If you run a website, provide a mechanism on the site for submitting requests for information the Act requires you to disclose.
- Accept authorized-agent opt-outs, including those signalled by a browser setting, extension, or global device setting, where you can verify the consumer's identity and the agent's authority with commercially reasonable effort.
- Do not rely on a default setting to infer an opt-out; the technology must require an affirmative, freely given, and unambiguous choice by the consumer.
Sources
- Neb. Rev. Stat. 87-1111, Consumer right; method to submit request, Nebraska Legislature
- Neb. Rev. Stat. 87-1107, Consumer rights, Nebraska Legislature
Last verified: 2026-08-23
Informational, not legal advice.