Data Protection Impact Assessment (DPIA) (AK) - Alaska
DATA PROTECTION IMPACT ASSESSMENT — ALASKA OVERLAY
USE AND LEGAL-DUTY GATE
This is a voluntary governance worksheet. AS 45.48 supplies specific Alaska duties for security-breach notification and disposal of records; it is not a complete privacy or information-security code and does not by itself make this assessment mandatory.
| Gate | Finding |
|---|---|
| Project or processing activity | [________________________________] |
| Business owner | [________________________________] |
| Planned launch date | [__/__/____] |
| Why this assessment is being performed | [Contract / Policy / Sector rule / Foreign law / Voluntary risk review / Other] |
| Alaska residents or Alaska operations in scope? | [Yes / No / Unknown] |
| Counsel identified an independent assessment duty? | [Yes / No; source: ________________________________] |
| Legal sources checked through | [__/__/____] |
Do not label data “personal information,” “sensitive data,” or “consumer data” without identifying the particular law and definition being applied. AS 45.48 uses different definitions for breach notification and record disposal.
1. PROJECT AND DECISION MAP
| Item | Description |
|---|---|
| Business purpose | [________________________________] |
| Product, system, model, or vendor | [________________________________] |
| Project owner and executive sponsor | [________________________________] |
| Users and affected individuals | [________________________________] |
| Decisions or actions supported by the processing | [________________________________] |
| Human review and appeal path | [________________________________] |
| Launch, review, and retirement dates | [________________________________] |
2. DATA INVENTORY AND FLOW
| Data set | Source | Individuals | Elements | Destination or recipient | Retention and deletion |
|---|---|---|---|---|---|
| [____] | [____] | [____] | [____] | [____] | [____] |
| [____] | [____] | [____] | [____] | [____] | [____] |
| [____] | [____] | [____] | [____] | [____] | [____] |
Document:
- collection method and notice shown;
- purpose and each later use;
- storage location and access roles;
- disclosures, sales, licenses, and service-provider access;
- interstate or international transfers;
- derived, inferred, scored, or model-generated information; and
- backups, logs, test data, and deletion dependencies.
3. APPLICABLE-LAW AND CONTRACT REGISTER
| Source | Why it applies | Required action | Owner | Evidence |
|---|---|---|---|---|
| Alaska AS 45.48 | [Breach / Disposal / Neither] | [________________________________] | [____] | [____] |
| Federal or sector-specific law | [________________________________] | [________________________________] | [____] | [____] |
| Other state or foreign law | [________________________________] | [________________________________] | [____] | [____] |
| Licensing or professional rule | [________________________________] | [________________________________] | [____] | [____] |
| Customer or vendor contract | [________________________________] | [________________________________] | [____] | [____] |
| Internal policy or representation | [________________________________] | [________________________________] | [____] | [____] |
4. PURPOSE, NECESSITY, AND INDIVIDUAL EFFECTS
| Question | Assessment |
|---|---|
| Is each collected field necessary for a stated purpose? | [________________________________] |
| Can the purpose be achieved with less, aggregated, or deidentified data? | [________________________________] |
| Are later uses compatible with the collection notice and commitments? | [________________________________] |
| Does processing create a legal, financial, employment, housing, health, safety, or access effect? | [________________________________] |
| Are children or other vulnerable groups affected? | [________________________________] |
| Could errors, bias, surveillance, disclosure, or reidentification cause harm? | [________________________________] |
| What notice, choice, correction, review, or complaint channel is offered? | [________________________________] |
5. SECURITY AND VENDOR CONTROLS
Assess controls against the project’s actual risks and each independently applicable source. Do not cite AS 45.48 as a general “reasonable security” mandate. Its express reasonable-measures requirement in this context concerns disposal of records under AS 45.48.500.
| Control area | Existing control | Gap | Remediation owner and date |
|---|---|---|---|
| Access and privilege management | [____] | [____] | [____] |
| Authentication and secrets | [____] | [____] | [____] |
| Encryption and key management | [____] | [____] | [____] |
| Logging, detection, and response | [____] | [____] | [____] |
| Secure development and vulnerability management | [____] | [____] | [____] |
| Backup, recovery, and continuity | [____] | [____] | [____] |
| Vendor diligence and contract controls | [____] | [____] | [____] |
| Retention, deletion, and media disposal | [____] | [____] | [____] |
6. ALASKA BREACH-NOTIFICATION OVERLAY
A. Coverage and roles
AS 45.48.010 applies when a covered person owns or licenses personal information on an Alaska resident and a breach of the information system occurs. Under AS 45.48.090, a covered person is a person doing business, a governmental agency other than a judicial-branch agency, or a person with more than 10 employees.
| Question | Answer |
|---|---|
| Does the organization own or license covered personal information on an Alaska resident? | [Yes / No / Investigate] |
| Is it the information distributor or an information recipient for each data set? | [________________________________] |
| Incident-response owner | [________________________________] |
| Alaska-resident identification method | [________________________________] |
An information recipient that maintains covered information but does not own it or have the right to license it must notify the information distributor immediately after discovery and cooperate as AS 45.48.070 specifies. The information distributor then performs the resident-notice duties.
B. Breach-definition data map
For AS 45.48.010-.090, personal information generally requires an Alaska resident’s first name or first initial plus last name combined with one or more listed elements, where the information is not encrypted or redacted, or the encryption key has been accessed or acquired.
| Listed element under AS 45.48.090(7) | Present? | System and protection |
|---|---|---|
| Social Security number | [____] | [____] |
| Driver’s license or state identification number | [____] | [____] |
| Account, credit-card, or debit-card number | [____] | [____] |
| Required security/access code, PIN, or password for the listed account/card number | [____] | [____] |
| Password, PIN, or other access code for a financial account | [____] | [____] |
Do not import biometric, medical, general login-credential, or broad “sensitive data” categories into this breach definition unless another identified law or contract supplies them.
A breach is unauthorized acquisition, or a reasonable belief of unauthorized acquisition, that compromises the security, confidentiality, or integrity of the covered personal information. Good-faith acquisition by an employee or agent for a legitimate purpose is excluded only if the information is not used for an unrelated purpose and is not further disclosed without authorization.
C. Notification decision
| Required decision | Finding and evidence |
|---|---|
| Discovery or notice date | [__/__/____] |
| Scope-determination and integrity-restoration work | [________________________________] |
| Resident notice required? | [Yes / No / Counsel review] |
| Notice method under AS 45.48.030 | [Written / Electronic / Substitute; basis: ______] |
| More than 1,000 Alaska residents notified? | [Yes / No] |
| Nationwide consumer-reporting-agency notice required under AS 45.48.040? | [Yes / No] |
| Law-enforcement interference determination under AS 45.48.020? | [Yes / No; agency and date: ______] |
| Written notice that disclosure will no longer interfere received? | [Yes / No; date: ______] |
Required resident notice must be made in the most expeditious time possible and without unreasonable delay, subject to the statutory investigation/system-integrity work and a qualifying law-enforcement determination. After the agency informs the information collector in writing that disclosure will no longer interfere with the investigation, disclosure must proceed in the most expeditious time possible and without unreasonable delay.
Alaska does not require blanket Attorney General notice for every breach in AS 45.48.010-.090. Written notification to the Attorney General is a condition of the no-reasonable-likelihood-of-harm exception in AS 45.48.010(c). A no-notice determination must follow an appropriate investigation, be documented in writing, and be retained for five years.
7. ALASKA RECORD-DISPOSAL OVERLAY
AS 45.48.500-.590 uses its own definitions. A business or governmental agency disposing of covered records must take all reasonable measures necessary to protect against unauthorized access or use. The statute requires written disposal policies and procedures and supplies diligence and written-contract measures for a third-party destruction vendor.
| Disposal control | Status and evidence |
|---|---|
| Records and personal-information definition mapped under AS 45.48.590 | [________________________________] |
| Written disposal policies adopted under AS 45.48.530 | [________________________________] |
| Paper destruction prevents practical reading or reconstruction | [________________________________] |
| Electronic and other media destruction prevents practical reading or reconstruction | [________________________________] |
| Destruction-vendor due diligence documented | [________________________________] |
| Written destruction contract addresses statutory disposal measures | [________________________________] |
| Federal-law or regulated-business exemption under AS 45.48.540 reviewed | [________________________________] |
8. RISK REGISTER AND DECISION
| Risk | Affected people | Likelihood | Impact | Control or change | Residual risk | Owner |
|---|---|---|---|---|---|---|
| [____] | [____] | [____] | [____] | [____] | [____] | [____] |
| [____] | [____] | [____] | [____] | [____] | [____] | [____] |
| [____] | [____] | [____] | [____] | [____] | [____] | [____] |
Decision: ☐ Approve ☐ Approve with conditions ☐ Remediate and reassess ☐ Do not proceed
Conditions, owners, and deadlines:
[________________________________]
[________________________________]
9. REVIEW AND APPROVAL RECORD
| Reviewer | Role | Decision | Date |
|---|---|---|---|
| [________________________________] | Privacy or compliance | [________________________________] | [__/__/____] |
| [________________________________] | Security | [________________________________] | [__/__/____] |
| [________________________________] | Alaska legal review | [________________________________] | [__/__/____] |
| [________________________________] | Business owner | [________________________________] | [__/__/____] |
| [________________________________] | Executive approver | [________________________________] | [__/__/____] |
Reassessment triggers: material new data, purpose, recipient, model, decision effect, security architecture, incident, law, contract, or risk level.
OFFICIAL SOURCES VERIFIED
- AS 45.48.010-.090, Security-Breach Notification — https://www.akleg.gov/basis/statutes.asp?title=45&media=print&secStart=45.48.010&secEnd=45.48.090
- AS 45.48.500-.590, Disposal of Records — https://www.akleg.gov/basis/statutes.asp?title=45&media=print&secStart=45.48.500&secEnd=45.48.590
Retain the completed assessment, source versions, data-flow evidence, approvals, and remediation records according to the organization’s verified legal and records schedules.
About this template
- Last updated
- August 9, 2026
- Citations checked
- August 9, 2026
- Jurisdiction
- Alaska
- Category
- Compliance & Regulatory
Legal authority
- AS 45.48.010-.090 - Alaska Security-Breach Notification
- AS 45.48.500-.590 - Disposal of Records Containing Personal Information
Compliance documents are what regulated businesses use to prove they follow the rules that apply to their industry, whether that is privacy, anti-money-laundering, consumer protection, or sector-specific requirements. Regulators look for consistent policies, up-to-date records, and clear evidence of employee training. The cost of getting compliance paperwork right is almost always smaller than the cost of an enforcement action, fine, or public disclosure.
Not legal advice
This template is provided for informational purposes. We recommend having an attorney review any legal document before signing, especially for high-value or complex matters.
Checked against the law it cites
A reviewer verified this template's legal citations against the official source on August 9, 2026.
Draft your Data Protection Impact Assessment (DPIA) (AK) in the editor
Answer a few questions, let the AI editor draft each section from your answers, review it, and download Word and PDF. $99 one time, or $249 per month for every document and every Ezel app.