Does Nebraska's privacy law apply to small businesses selling sensitive data?
Neb. Rev. Stat. Section 87-1118(1) bars a small business from selling sensitive data without the consumer's prior consent. It is the one Data Privacy Act duty that reaches businesses otherwise excluded by Section 87-1103(1)(c), and Section 87-1124(1) backs it with penalties up to $7,500 per violation.
Applies to: Small businesses under the federal Small Business Act that operate in Nebraska or sell to Nebraska residents and assumed the state privacy law did not reach them, particularly any business that shares data with advertising or data partners.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanNebraska wrote its privacy law so that small businesses are outside almost all of it. Almost. There is one obligation that reaches through the exclusion, and it is the one most likely to be triggered by an ad tech integration nobody reviewed.
The exclusion, and the exception inside it
Section 87-1103(1) sets out three cumulative conditions. The Data Privacy Act applies only to a person that conducts business in Nebraska or produces a product or service consumed by Nebraska residents, processes or engages in the sale of personal data, and, at subdivision (c), "is not a small business as determined under the federal Small Business Act, as such act existed on January 1, 2024, except to the extent that section 87-1118 applies to a person described by this subdivision."
That closing clause is the whole point. The exclusion is not clean. It carries a named exception, and Section 87-1118 is the exception.
Note also the frozen reference date. Nebraska pins the federal Small Business Act to how it existed on January 1, 2024, so a later change to SBA size standards does not automatically move the Nebraska line.
What Section 87-1118 actually says
It is two sentences. Section 87-1118(1): a person described by subdivision (1)(c) of Section 87-1103 shall not engage in the sale of personal data that is sensitive data without receiving prior consent from the consumer. Section 87-1118(2): a person who violates this section is subject to the penalty under Section 87-1124.
So the duty is narrow in scope and absolute in form. It does not require a privacy notice. It does not require an opt-out mechanism. It prohibits one act, selling sensitive data, unless consent came first.
Why "prior" is the operative word
A great deal of privacy compliance is built around disclosure and opt-out. Tell the consumer what you do, give them a way to stop it. Section 87-1118 is not built that way. Consent has to be received before the sale.
That inverts the usual order of operations. A "do not sell my personal information" link, however well built, does not satisfy a prior consent requirement, because by the time the consumer uses it the sale has already happened. The compliant paths are to obtain affirmative consent up front, or to stop selling the sensitive data.
The penalty is the same as for everyone else
Section 87-1118(2) routes to Section 87-1124, which is the general penalty provision. Section 87-1124(1) makes a person who violates the act following the cure period in Section 87-1122, or who breaches a written statement given to the Attorney General under that section, liable for a civil penalty not to exceed seven thousand five hundred dollars for each violation.
Section 87-1124(2) lets the Attorney General sue to recover the penalty, to enjoin the conduct, or both, and Section 87-1124(3) allows recovery of reasonable attorney's fees and investigation expenses. A small business does not get a reduced ceiling for being small.
Texas does the same thing, which is the pattern worth learning
Texas built its law the same way. Section 541.002(a)(3) applies the Texas Data Privacy and Security Act only to a person that is not a small business as defined by the U.S. Small Business Administration, "except to the extent that Section 541.107 applies". Section 541.107(a) then bars a small business from engaging in the sale of sensitive data without prior consumer consent, with the Section 541.155 penalty attached.
Two states, same structure, same trap. If you are a small business selling into either state and you assumed the small business exclusion was total, the sensitive data question is the one to answer first.
Compliance checklist
- Determine whether you are a small business under the federal Small Business Act as it existed on January 1, 2024, because Section 87-1103(1)(c) fixes the reference date rather than tracking later SBA changes.
- Do not stop there if you are, since Section 87-1103(1)(c) expressly preserves Section 87-1118 against businesses that are otherwise outside the act.
- Inventory whether you sell any sensitive data, treating sharing for monetary or other valuable consideration as a sale rather than only cash transactions.
- Collect consent before the sale, not after, because Section 87-1118(1) requires prior consent from the consumer.
- Keep evidence of that consent, since the burden of showing it will sit with you if the attorney general asks.
- Budget the exposure at up to $7,500 for each violation under Section 87-1124(1), which applies after the cure period in Section 87-1122.
Sources
- Neb. Rev. Stat. Section 87-1118, Sensitive data; sale; consent required, Nebraska Legislature
- Neb. Rev. Stat. Section 87-1103, Applicability of act to persons or entities, Nebraska Legislature
- Neb. Rev. Stat. Section 87-1124, Violation; penalty; actions authorized, Nebraska Legislature
Last verified: 2026-09-07
Informational, not legal advice.