State Breach Law

North Carolina Data Breach Notification Law

N.C.G.S. § 75-61 et seq. • Effective 2005-12-01

North Carolina is strict about breach notification. You must notify affected residents "without unreasonable delay" and then notify the state within 24 HOURS of notifying residents. If SSNs were exposed, you must provide free credit monitoring. Waiver provisions that limit liability are void.

Notification deadline: Without unreasonable delay

Enforcement: North Carolina Attorney General

Overview

North Carolina requires businesses to notify affected residents "without unreasonable delay" and notify the Consumer Protection Division within 24 hours of notifying residents. The state requires free credit monitoring for Social Security number breaches.

Who Must Be Notified

  • Affected North Carolina residents
  • NC Attorney General Consumer Protection Division (within 24 hours of resident notification)
  • Consumer reporting agencies (if 1,000+ residents affected)

Covered Data Types

Social Security number, Driver's license number, State ID number, Financial account number with access code, Credit/debit card number, Passport number, Taxpayer ID number, Employer-assigned ID with password, Biometric data, Digital signatures

Notification Requirements

  • Written, telephonic, or electronic notice without unreasonable delay
  • Must notify Consumer Protection Division within 24 HOURS of resident notification
  • Description of incident and types of data involved
  • If SSN involved, must provide credit monitoring at no cost
  • Contact information for credit bureaus
  • Cannot require waiver of rights as condition of notification

Is your business exposed?

Exemptions

  • Encrypted data (if key not compromised)
  • Entities in compliance with GLBA, HIPAA, federal banking regulations
  • Good faith acquisition by employee

Penalties

Up to $5,000 per violation under Unfair and Deceptive Trade Practices Act. AG can seek treble damages in some cases.

If You Experience a Breach

  1. 1.

    Prepare for 24-hour AG notification requirement

  2. 2.

    Line up credit monitoring provider in advance

  3. 3.

    Create notification templates

  4. 4.

    Know how to contact NC Consumer Protection Division

    NC DOJ Consumer Protection

  5. 5.

    Implement reasonable security measures

  6. 6.

    Train employees on 24-hour AG notification requirement

Official Source

https://ncdoj.gov/protecting-consumers/

Other State Breach Laws

New York, Texas, Florida

Is your business exposed?

Check if your company data is circulating on the dark web

Free scan • No credit card required