{
  "type": "practice-guide",
  "canonical": "https://openagreements.org/practice-guides/privacy/us/north-carolina",
  "links": [
    {
      "rel": "self",
      "href": "https://openagreements.org/practice-guides/privacy/us/north-carolina.json",
      "type": "application/json"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/north-carolina",
      "type": "text/html"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/north-carolina/markdown",
      "type": "text/markdown"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/north-carolina/json",
      "type": "application/json"
    }
  ],
  "data": {
    "topic": "privacy",
    "state": "north-carolina",
    "frontmatter": {
      "title": "North Carolina Consumer Privacy Law",
      "description": "North Carolina has no comprehensive consumer-privacy statute. The Identity Theft Protection Act governs breach notice, Social Security numbers, data disposal, and security freezes, with express Chapter 75 bridges for specific sections.",
      "state": "North Carolina",
      "lastReviewed": "2026-06-11",
      "license": "CC BY 4.0",
      "authors": [
        "steven-obiajulu"
      ],
      "summary": {
        "keyLaw": "Identity Theft Protection Act, N.C. Gen. Stat. §§ 75-60 to 75-66 (Article 2A of Chapter 75) — North Carolina has no comprehensive consumer-privacy law; breach-notification, Social Security number, disposal, and security-freeze sections contain express § 75-1.1 bridges",
        "appliesTo": "Any business that owns, licenses, maintains, or possesses personal information of North Carolina residents — in any form, computerized or paper — with no revenue or consumer-volume threshold",
        "privacyPolicyRequired": "No North Carolina statute mandates a general consumer privacy policy or fixes its contents; a materially misleading statement can support a § 75-1.1 or FTC Act § 5 deception theory if the required elements are met, alongside GLBA, HIPAA, and COPPA where those apply",
        "privateRightOfAction": "Yes for specific bridged ITPA sections — an injured consumer can use § 75-16 for mandatory treble damages where the section expressly makes the violation a § 75-1.1 violation; § 75-66 separately allows civil damages under G.S. 1-539.2C",
        "regulator": "North Carolina Attorney General (Consumer Protection Division)",
        "bottomLine": "North Carolina has not enacted a comprehensive consumer-privacy law; the operative statute is the Identity Theft Protection Act, whose breach-notification, Social Security number, disposal, and security-freeze sections expressly bridge violations into § 75-1.1.",
        "lawCoverage": "baseline",
        "policyMandate": "none",
        "consumersCanSue": "narrow",
        "sensitiveDataConsent": "none",
        "universalOptOutSignal": "notRequired"
      },
      "about": [
        "North Carolina consumer privacy law",
        "North Carolina Identity Theft Protection Act",
        "North Carolina data breach notification 75-65",
        "North Carolina treble damages unfair trade practices 75-16",
        "North Carolina no comprehensive privacy law",
        "North Carolina privacy policy requirements",
        "North Carolina Social Security number protection",
        "North Carolina security freeze credit report",
        "North Carolina Attorney General privacy enforcement",
        "North Carolina data breach private right of action"
      ],
      "translations": [
        {
          "language": "中文",
          "status": "planned"
        },
        {
          "language": "Español",
          "status": "planned"
        },
        {
          "language": "Português",
          "status": "planned"
        },
        {
          "language": "Deutsch",
          "status": "planned"
        }
      ]
    },
    "questions": [
      {
        "slug": "which-privacy-laws-apply",
        "label": "Which privacy laws apply to your business in North Carolina?",
        "heading": "Which privacy laws apply to your business in North Carolina?",
        "answerText": "There is no comprehensive North Carolina consumer-privacy law. The operative state statute is the Identity Theft Protection Act, an Article of Chapter 75 that governs breach notification, Social Security numbers, record disposal, and credit-report security freezes rather than data handling generally. Its breach-notice duty reaches any business that owns or licenses personal information of North Carolina residents, or that conducts business in North Carolina and owns or licenses personal information in any form — computerized, paper, or otherwise — with no revenue or consumer-volume threshold.",
        "sources": [
          {
            "id": "itpa-7560-title",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.C. Gen. Stat. § 75-60",
            "citation": "N.C. Gen. Stat. § 75-60.",
            "url": "https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_75/GS_75-60.html",
            "proposition": "North Carolina's operative privacy statute is Article 2A of Chapter 75, formally titled the Identity Theft Protection Act.",
            "verbatimQuote": "This Article shall be known and may be cited as the \"Identity Theft Protection Act\".",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-itpa-7560-title"
          },
          {
            "id": "itpa-7565-scope",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.C. Gen. Stat. § 75-65",
            "citation": "N.C. Gen. Stat. § 75-65(a).",
            "url": "https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_75/GS_75-65.html",
            "proposition": "The breach-notification duty applies to any business that owns or licenses personal information of North Carolina residents, or that conducts business in North Carolina and owns or licenses personal information in any form, including paper records.",
            "verbatimQuote": "Any business that owns or licenses personal information of residents of North Carolina or any business that conducts business in North Carolina that owns or licenses personal information in any form (whether computerized, paper, or otherwise) shall provide notice to the affected person that there has been a security breach following discovery or notification of the breach.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-itpa-7565-scope"
          },
          {
            "id": "itpa-115c-student-targeting",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.C. Gen. Stat. § 115C-401.2",
            "citation": "N.C. Gen. Stat. § 115C-401.2(b)(1).",
            "url": "https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_115C/GS_115C-401.2.html",
            "proposition": "Operators of websites, services, and applications used primarily for K-12 school purposes may not engage in targeted advertising based on information acquired through the school-use service.",
            "verbatimQuote": "Engage in targeted advertising on the operator's site, service, or application, or target advertising on any other site, service, or application if the targeting of the advertising is based on any information, including covered information and persistent unique identifiers, that the operator has acquired because of the use of that operator's site, service, or application for K-12 school purposes.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-itpa-115c-student-targeting"
          },
          {
            "id": "itpa-115c-student",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.C. Gen. Stat. § 115C-401.2",
            "citation": "N.C. Gen. Stat. § 115C-401.2(b)(3).",
            "url": "https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_115C/GS_115C-401.2.html",
            "proposition": "Operators of websites, services, and applications used primarily for K-12 school purposes may not sell or rent student information.",
            "verbatimQuote": "Sell or rent a student's information, including covered information.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-itpa-115c-student"
          },
          {
            "id": "itpa-583215-genetic",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.C. Gen. Stat. § 58-3-215",
            "citation": "N.C. Gen. Stat. § 58-3-215(c).",
            "url": "https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_58/GS_58-3-215.html",
            "proposition": "North Carolina insurance law forbids health insurers from raising group premium rates, refusing to issue or deliver a health benefit plan, or charging a higher premium because of genetic information.",
            "verbatimQuote": "No insurer shall: (1) Raise the premium or contribution rates paid by a group for a group health benefit plan on the basis of genetic information obtained about an individual member of the group. (2) Refuse to issue or deliver a health benefit plan because of genetic information obtained about any person to be insured by the health benefit plan. (3) Charge a higher premium rate or charge for a health benefit plan because of genetic information obtained about any person to be insured by the health benefit plan.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-itpa-583215-genetic"
          }
        ]
      },
      {
        "slug": "breach-lawsuit-treble-damages",
        "label": "Can a consumer sue your business over a data breach in North Carolina?",
        "heading": "Can a consumer sue your business over a data breach in North Carolina?",
        "answerText": "Yes, if the consumer was injured and the violated section supplies the bridge. The breach-notification section itself says a violation is a violation of the state's unfair-trade-practices act, and an injured individual may bring a private action. Once a Chapter 75 violation injures a person, the damages remedy is not discretionary: judgment shall be rendered for treble the amount fixed by the verdict. A prevailing party may also recover a reasonable attorney fee in the court's discretion on a finding of willfulness and an unwarranted refusal to resolve the matter.",
        "sources": [
          {
            "id": "bridge-7565-per-se",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.C. Gen. Stat. § 75-65",
            "citation": "N.C. Gen. Stat. § 75-65(i).",
            "url": "https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_75/GS_75-65.html",
            "proposition": "A breach-notification violation is per se a § 75-1.1 unfair-trade-practice violation, and an injured individual — but only an injured one — may sue privately.",
            "verbatimQuote": "A violation of this section is a violation of G.S. 75-1.1. No private right of action may be brought by an individual for a violation of this section unless such individual is injured as a result of the violation.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-bridge-7565-per-se"
          },
          {
            "id": "bridge-7562-ssn",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.C. Gen. Stat. § 75-62",
            "citation": "N.C. Gen. Stat. § 75-62(d).",
            "url": "https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_75/GS_75-62.html",
            "proposition": "A violation of the Social Security number protection section is a violation of § 75-1.1.",
            "verbatimQuote": "A violation of this section is a violation of G.S. 75-1.1.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-bridge-7562-ssn"
          },
          {
            "id": "bridge-7563-freeze",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.C. Gen. Stat. § 75-63",
            "citation": "N.C. Gen. Stat. § 75-63(g).",
            "url": "https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_75/GS_75-63.html",
            "proposition": "A violation of the consumer security-freeze section is a violation of § 75-1.1.",
            "verbatimQuote": "A violation of this section is a violation of G.S. 75-1.1.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-bridge-7563-freeze"
          },
          {
            "id": "bridge-75631-protected-freeze",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.C. Gen. Stat. § 75-63.1",
            "citation": "N.C. Gen. Stat. § 75-63.1(g).",
            "url": "https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_75/GS_75-63.1.html",
            "proposition": "A violation of the protected-consumer security-freeze section is a violation of § 75-1.1.",
            "verbatimQuote": "A violation of this section is a violation of G.S. 75-1.1.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-bridge-75631-protected-freeze"
          },
          {
            "id": "bridge-7564-disposal",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.C. Gen. Stat. § 75-64",
            "citation": "N.C. Gen. Stat. § 75-64(f).",
            "url": "https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_75/GS_75-64.html",
            "proposition": "A disposal violation is a § 75-1.1 violation, with a special limit on trebling for certain nonmanagerial employee acts or omissions.",
            "verbatimQuote": "A violation of this section is a violation of G.S. 75-1.1, but any damages assessed against a business because of the acts or omissions of its nonmanagerial employees shall not be trebled as provided in G.S. 75-16 unless the business was negligent in the training, supervision, or monitoring of those employees.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-bridge-7564-disposal"
          },
          {
            "id": "bridge-7516-treble",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.C. Gen. Stat. § 75-16",
            "citation": "N.C. Gen. Stat. § 75-16.",
            "url": "https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_75/GS_75-16.html",
            "proposition": "A person injured by a Chapter 75 violation has a private right of action, and damages assessed must be trebled — the statute makes trebling mandatory, not discretionary.",
            "verbatimQuote": "If any person shall be injured or the business of any person, firm or corporation shall be broken up, destroyed or injured by reason of any act or thing done by any other person, firm or corporation in violation of the provisions of this Chapter, such person, firm or corporation so injured shall have a right of action on account of such injury done, and if damages are assessed in such case judgment shall be rendered in favor of the plaintiff and against the defendant for treble the amount fixed by the verdict.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-bridge-7516-treble"
          },
          {
            "id": "bridge-7511-udap",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.C. Gen. Stat. § 75-1.1",
            "citation": "N.C. Gen. Stat. § 75-1.1(a).",
            "url": "https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_75/GS_75-1.1.html",
            "proposition": "Section 75-1.1 is North Carolina's general unfair-and-deceptive-practices statute, the section into which Identity Theft Protection Act violations are channeled.",
            "verbatimQuote": "Unfair methods of competition in or affecting commerce, and unfair or deceptive acts or practices in or affecting commerce, are declared unlawful.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-bridge-7511-udap"
          },
          {
            "id": "bridge-75161-fees",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.C. Gen. Stat. § 75-16.1",
            "citation": "N.C. Gen. Stat. § 75-16.1.",
            "url": "https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_75/GS_75-16.1.html",
            "proposition": "In a § 75-1.1 suit the judge may, in his discretion, award a reasonable attorney fee to the prevailing party's counsel, taxed as court costs against the losing party.",
            "verbatimQuote": "In any suit instituted by a person who alleges that the defendant violated G.S. 75-1.1, the presiding judge may, in his discretion, allow a reasonable attorney fee to the duly licensed attorney representing the prevailing party, such attorney fee to be taxed as a part of the court costs and payable by the losing party, upon a finding by the presiding judge that: (1) The party charged with the violation has willfully engaged in the act or practice, and there was an unwarranted refusal by such party to fully resolve the matter which constitutes the basis of such suit",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-bridge-75161-fees"
          },
          {
            "id": "bridge-7565-assignment",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.C. Gen. Stat. § 75-65",
            "citation": "N.C. Gen. Stat. § 75-65(j).",
            "url": "https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_75/GS_75-65.html",
            "proposition": "Causes of action arising under the Identity Theft Protection Act may not be assigned.",
            "verbatimQuote": "Causes of action arising under this Article may not be assigned.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-bridge-7565-assignment"
          }
        ]
      },
      {
        "slug": "privacy-policy-contents",
        "label": "What must your North Carolina privacy policy contain?",
        "heading": "What must your North Carolina privacy policy contain?",
        "answerText": "No North Carolina statute requires a general consumer privacy policy or fixes what it must say. The binding rule is that whatever you publish has to be true: a materially misleading policy statement can support a deception claim under § 75-1.1 and under Section 5 of the FTC Act, if the required elements are met. In North Carolina that truthfulness rule has unusual teeth for injured consumers, because damages assessed in a private Chapter 75 action are trebled.",
        "sources": [
          {
            "id": "policy-7511-udap",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.C. Gen. Stat. § 75-1.1",
            "citation": "N.C. Gen. Stat. § 75-1.1(a).",
            "url": "https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_75/GS_75-1.1.html",
            "proposition": "Section 75-1.1 declares unfair or deceptive acts or practices in or affecting commerce unlawful; a materially misleading privacy-policy statement can support a deception theory if the required elements are met.",
            "verbatimQuote": "Unfair methods of competition in or affecting commerce, and unfair or deceptive acts or practices in or affecting commerce, are declared unlawful.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-policy-7511-udap"
          },
          {
            "id": "policy-ftc5-deceptive",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "FTC Act § 5",
            "citation": "15 U.S.C. § 45(a)(1).",
            "url": "https://www.law.cornell.edu/uscode/text/15/45",
            "deepLink": "https://www.law.cornell.edu/uscode/text/15/45#:~:text=Unfair%20methods%20of%20competition%20in,commerce%2C%20are%20hereby%20declared%20unlawful.",
            "proposition": "Section 5 of the FTC Act declares unfair or deceptive acts or practices in or affecting commerce unlawful; a materially misleading privacy-policy statement can support an FTC deception theory if the required elements are met.",
            "verbatimQuote": "Unfair methods of competition in or affecting commerce, and unfair or deceptive acts or practices in or affecting commerce, are hereby declared unlawful.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-policy-ftc5-deceptive"
          },
          {
            "id": "policy-7516-treble",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.C. Gen. Stat. § 75-16",
            "citation": "N.C. Gen. Stat. § 75-16.",
            "url": "https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_75/GS_75-16.html",
            "proposition": "Damages assessed in a private Chapter 75 action are trebled as a matter of statutory command, which raises the stakes of a deceptive privacy policy.",
            "verbatimQuote": "if damages are assessed in such case judgment shall be rendered in favor of the plaintiff and against the defendant for treble the amount fixed by the verdict",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-policy-7516-treble"
          },
          {
            "id": "policy-glba-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "GLBA § 502",
            "citation": "15 U.S.C. § 6802(a).",
            "url": "https://www.law.cornell.edu/uscode/text/15/6802",
            "deepLink": "https://www.law.cornell.edu/uscode/text/15/6802#:~:text=Except%20as%20otherwise%20provided%20in,section%206803%20of%20this%20title.",
            "proposition": "A financial institution may not disclose nonpublic personal information to nonaffiliated third parties unless it has given the consumer the required GLBA privacy notice.",
            "verbatimQuote": "Except as otherwise provided in this subchapter, a financial institution may not, directly or through any affiliate, disclose to a nonaffiliated third party any nonpublic personal information, unless such financial institution provides or has provided to the consumer a notice that complies with section 6803 of this title.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-policy-glba-notice"
          },
          {
            "id": "policy-hipaa-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "HIPAA Notice of Privacy Practices",
            "citation": "45 C.F.R. § 164.520.",
            "url": "https://www.law.cornell.edu/cfr/text/45/164.520",
            "deepLink": "https://www.law.cornell.edu/cfr/text/45/164.520#:~:text=an%20individual%20has%20a%20right,respect%20to%20protected%20health%20information",
            "proposition": "A HIPAA covered entity must give individuals a notice describing the uses and disclosures of their protected health information and their rights and the entity's legal duties.",
            "verbatimQuote": "an individual has a right to adequate notice of the uses and disclosures of protected health information that may be made by the covered entity, and of the individual's rights and the covered entity's legal duties with respect to protected health information",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-policy-hipaa-notice"
          },
          {
            "id": "policy-coppa-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "COPPA",
            "citation": "15 U.S.C. § 6502(b)(1)(A)(i).",
            "url": "https://www.law.cornell.edu/uscode/text/15/6502",
            "deepLink": "https://www.law.cornell.edu/uscode/text/15/6502#:~:text=to%20provide%20notice%20on%20the,disclosure%20practices%20for%20such%20information",
            "proposition": "An operator of a child-directed website or online service must post notice of what information it collects from children, how it uses that information, and its disclosure practices.",
            "verbatimQuote": "to provide notice on the website of what information is collected from children by the operator, how the operator uses such information, and the operator’s disclosure practices for such information",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-policy-coppa-notice"
          }
        ]
      },
      {
        "slug": "vendor-contracts",
        "label": "What must your contracts with vendors say?",
        "heading": "What must your contracts with vendors say?",
        "answerText": "North Carolina has no omnibus data-processing-agreement requirement — no state statute prescribes controller-to-processor terms, audit rights, deletion clauses, or subprocessor flow-downs for general commercial contracts. The state does impose a disposal duty: covered businesses must take reasonable measures against unauthorized access to or use of personal information in connection with or after disposal. For paper and electronic media, those measures must include monitored policies for shredding, burning, pulverizing, destroying, or erasing records so the information cannot practicably be read or reconstructed.",
        "sources": [
          {
            "id": "vendor-7564-duty",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.C. Gen. Stat. § 75-64",
            "citation": "N.C. Gen. Stat. § 75-64(a).",
            "url": "https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_75/GS_75-64.html",
            "proposition": "A business conducting business in North Carolina or possessing a North Carolina resident's personal information must take reasonable measures against unauthorized access or use in connection with or after disposal.",
            "verbatimQuote": "Any business that conducts business in North Carolina and any business that maintains or otherwise possesses personal information of a resident of North Carolina must take reasonable measures to protect against unauthorized access to or use of the information in connection with or after its disposal.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-vendor-7564-duty"
          },
          {
            "id": "vendor-7564-measures",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.C. Gen. Stat. § 75-64",
            "citation": "N.C. Gen. Stat. § 75-64(b)(1)-(2).",
            "url": "https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_75/GS_75-64.html",
            "proposition": "Reasonable disposal measures include monitored policies for destroying paper and electronic media so personal information cannot practicably be read or reconstructed.",
            "verbatimQuote": "The reasonable measures must include: (1) Implementing and monitoring compliance with policies and procedures that require the burning, pulverizing, or shredding of papers containing personal information so that information cannot be practicably read or reconstructed. (2) Implementing and monitoring compliance with policies and procedures that require the destruction or erasure of electronic media and other nonpaper media containing personal information so that the information cannot practicably be read or reconstructed.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-vendor-7564-measures"
          },
          {
            "id": "vendor-7564-contract",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.C. Gen. Stat. § 75-64",
            "citation": "N.C. Gen. Stat. § 75-64(c).",
            "url": "https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_75/GS_75-64.html",
            "proposition": "A business may discharge its disposal duty through a written contract with a record-destruction vendor, entered after due diligence and subject to compliance monitoring.",
            "verbatimQuote": "A business may, after due diligence, enter into a written contract with, and monitor compliance by, another party engaged in the business of record destruction to destroy personal information in a manner consistent with this section.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-vendor-7564-contract"
          },
          {
            "id": "vendor-7564-treble",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.C. Gen. Stat. § 75-64",
            "citation": "N.C. Gen. Stat. § 75-64(f).",
            "url": "https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_75/GS_75-64.html",
            "proposition": "A disposal violation is a per se § 75-1.1 violation, but damages caused by nonmanagerial employees are not trebled unless the business was negligent in training, supervising, or monitoring them.",
            "verbatimQuote": "A violation of this section is a violation of G.S. 75-1.1, but any damages assessed against a business because of the acts or omissions of its nonmanagerial employees shall not be trebled as provided in G.S. 75-16 unless the business was negligent in the training, supervision, or monitoring of those employees.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-vendor-7564-treble"
          },
          {
            "id": "vendor-7565-maintainer",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.C. Gen. Stat. § 75-65",
            "citation": "N.C. Gen. Stat. § 75-65(b).",
            "url": "https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_75/GS_75-65.html",
            "proposition": "A business holding personal information it does not own or license must notify the owner or licensee immediately upon discovering a security breach.",
            "verbatimQuote": "Any business that maintains or possesses records or data containing personal information of residents of North Carolina that the business does not own or license, or any business that conducts business in North Carolina that maintains or possesses records or data containing personal information that the business does not own or license shall notify the owner or licensee of the information of any security breach immediately following discovery of the breach, consistent with the legitimate needs of law enforcement as provided in subsection (c) of this section.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-vendor-7565-maintainer"
          },
          {
            "id": "vendor-glba-safeguards",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "GLBA Safeguards Rule",
            "citation": "16 C.F.R. § 314.4(f)(2).",
            "url": "https://www.law.cornell.edu/cfr/text/16/314.4",
            "deepLink": "https://www.law.cornell.edu/cfr/text/16/314.4#:~:text=Requiring%20your%20service%20providers%20by,implement%20and%20maintain%20such%20safeguards",
            "proposition": "The GLBA Safeguards Rule requires a financial institution to oversee its service providers, including by requiring them by contract to implement and maintain appropriate safeguards for customer information.",
            "verbatimQuote": "Requiring your service providers by contract to implement and maintain such safeguards",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-vendor-glba-safeguards"
          },
          {
            "id": "vendor-hipaa-baa",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "HIPAA Business Associate Contracts",
            "citation": "45 C.F.R. § 164.504(e)(2).",
            "url": "https://www.law.cornell.edu/cfr/text/45/164.504",
            "deepLink": "https://www.law.cornell.edu/cfr/text/45/164.504#:~:text=A%20contract%20between%20the%20covered,with%20respect%20to%20such%20information",
            "proposition": "HIPAA requires a written business-associate contract with permitted-use terms, safeguards, breach reporting, and subcontractor flow-down obligations.",
            "verbatimQuote": "A contract between the covered entity and a business associate must: (i) Establish the permitted and required uses and disclosures of protected health information by the business associate. The contract may not authorize the business associate to use or further disclose the information in a manner that would violate the requirements of this subpart, if done by the covered entity, except that: (A) The contract may permit the business associate to use and disclose protected health information for the proper management and administration of the business associate, as provided in paragraph (e)(4) of this section; and (B) The contract may permit the business associate to provide data aggregation services relating to the health care operations of the covered entity. (ii) Provide that the business associate will: (A) Not use or further disclose the information other than as permitted or required by the contract or as required by law; (B) Use appropriate safeguards and comply, where applicable, with subpart C of this part with respect to electronic protected health information, to prevent use or disclosure of the information other than as provided for by its contract; (C) Report to the covered entity any use or disclosure of the information not provided for by its contract of which it becomes aware, including breaches of unsecured protected health information as required by § 164.410; (D) In accordance with § 164.502(e)(1)(ii), ensure that any subcontractors that create, receive, maintain, or transmit protected health information on behalf of the business associate agree to the same restrictions and conditions that apply to the business associate with respect to such information",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-vendor-hipaa-baa"
          }
        ]
      },
      {
        "slug": "consumer-rights",
        "label": "What rights do North Carolina consumers have over their personal data?",
        "heading": "What rights do North Carolina consumers have over their personal data?",
        "answerText": "Not the comprehensive-statute set. North Carolina law gives consumers no general rights to access, delete, correct, or port their personal data, no right to opt out of its sale or of targeted advertising, and no requirement that businesses honor universal opt-out signals such as Global Privacy Control. The rights that do exist are narrower and identity-theft-shaped: any consumer may place a security freeze on their credit report, a business may not sell or intentionally disclose a Social Security number to a third party without written consent where it has reason to believe the recipient lacks a legitimate purpose, and a person who has objected to disclosure can sue anyone who knowingly publishes their personal information anyway.",
        "sources": [
          {
            "id": "rights-7563-effect",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.C. Gen. Stat. § 75-63",
            "citation": "N.C. Gen. Stat. § 75-63(a).",
            "url": "https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_75/GS_75-63.html",
            "proposition": "A security freeze prohibits a consumer reporting agency from releasing a consumer's credit report or information from it without express authorization, subject to statutory exceptions.",
            "verbatimQuote": "A security freeze shall prohibit, subject to exceptions in subsection ( l ) of this section, the consumer reporting agency from releasing the consumer's credit report or any information from it without the express authorization of the consumer.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-rights-7563-effect"
          },
          {
            "id": "rights-7563-freeze",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.C. Gen. Stat. § 75-63",
            "citation": "N.C. Gen. Stat. § 75-63(a).",
            "url": "https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_75/GS_75-63.html",
            "proposition": "Any North Carolina consumer may place a security freeze on their credit report by request to a consumer reporting agency.",
            "verbatimQuote": "A consumer may place a security freeze on the consumer's credit report by making a request to a consumer reporting agency in accordance with this subsection.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-rights-7563-freeze"
          },
          {
            "id": "rights-7563-free",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.C. Gen. Stat. § 75-63",
            "citation": "N.C. Gen. Stat. § 75-63(o).",
            "url": "https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_75/GS_75-63.html",
            "proposition": "Consumer reporting agencies may not charge for placing, lifting, or removing a security freeze when the request is made electronically.",
            "verbatimQuote": "A consumer reporting agency shall not charge a fee to put a security freeze in place, remove a freeze, or lift a freeze pursuant to subsection (d) or (j) of this section, provided that any such request is made electronically.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-rights-7563-free"
          },
          {
            "id": "rights-7561-protected-definition",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.C. Gen. Stat. § 75-61",
            "citation": "N.C. Gen. Stat. § 75-61(11a).",
            "url": "https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_75/GS_75-61.html",
            "proposition": "A protected consumer includes an individual under age 16 when a security-freeze request is made and an incapacitated individual or one with a guardian or guardian ad litem.",
            "verbatimQuote": "An individual (i) who is under the age of 16 at the time a request for the placement of a security freeze is made pursuant to G.S. 75-63.1 or (ii) who is incapacitated or for whom a guardian or guardian ad litem has been appointed.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-rights-7561-protected-definition"
          },
          {
            "id": "rights-75631-protected",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.C. Gen. Stat. § 75-63.1",
            "citation": "N.C. Gen. Stat. § 75-63.1(a).",
            "url": "https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_75/GS_75-63.1.html",
            "proposition": "A consumer reporting agency must place a protected-consumer security freeze — covering minors under 16 and incapacitated adults — within 30 days of a qualifying request by the protected consumer's representative.",
            "verbatimQuote": "A consumer reporting agency shall place a protected consumer security freeze on the protected consumer's credit report or on the protected consumer's file in accordance with subsection (b) of this section within 30 days of all of the following conditions being satisfied",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-rights-75631-protected"
          },
          {
            "id": "rights-7562-ssn",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.C. Gen. Stat. § 75-62",
            "citation": "N.C. Gen. Stat. § 75-62(a)(6).",
            "url": "https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_75/GS_75-62.html",
            "proposition": "A business may not sell, lease, trade, rent, or otherwise intentionally disclose an individual's Social Security number to a third party without written consent where it has reason to believe the third party lacks a legitimate purpose.",
            "verbatimQuote": "Sell, lease, loan, trade, rent, or otherwise intentionally disclose an individual's social security number to a third party without written consent to the disclosure from the individual, when the party making the disclosure knows or in the exercise of reasonable diligence would have reason to believe that the third party lacks a legitimate purpose for obtaining the individual's social security number.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-rights-7562-ssn"
          },
          {
            "id": "rights-7566-publication",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.C. Gen. Stat. § 75-66",
            "citation": "N.C. Gen. Stat. § 75-66(a).",
            "url": "https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_75/GS_75-66.html",
            "proposition": "Knowingly broadcasting or publishing a person's personal information after that person has objected to disclosure violates § 75-66.",
            "verbatimQuote": "It shall be a violation of this section for any person to knowingly broadcast or publish to the public on radio, television, cable television, in a writing of any kind, or on the internet, the personal information of another with actual knowledge that the person whose personal information is disclosed has previously objected to any such disclosure.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-rights-7566-publication"
          },
          {
            "id": "rights-7566-remedy",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.C. Gen. Stat. § 75-66",
            "citation": "N.C. Gen. Stat. § 75-66(e).",
            "url": "https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_75/GS_75-66.html",
            "proposition": "A person injured by an unlawful publication of personal information may sue for civil damages.",
            "verbatimQuote": "Any person whose property or person is injured by reason of a violation of this section may sue for civil damages pursuant to the provisions of G.S. 1-539.2C.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-rights-7566-remedy"
          }
        ]
      },
      {
        "slug": "breach-notification",
        "label": "When must you notify people of a data breach in North Carolina?",
        "heading": "When must you notify people of a data breach in North Carolina?",
        "answerText": "Without unreasonable delay, once you discover or are notified of a security breach. The notification may be paced only by the legitimate needs of law enforcement and by measures necessary to determine contact information, determine the scope of the breach, and restore the integrity, security, and confidentiality of the data system. A security breach is an incident of unauthorized access to and acquisition of unencrypted and unredacted records containing personal information where illegal use has occurred, is reasonably likely to occur, or creates a material risk of harm to a consumer; encrypted records count if the confidential process or key is also acquired. Every consumer-noticed breach also triggers a report to the Attorney General's Consumer Protection Division — there is no headcount floor.",
        "sources": [
          {
            "id": "breach-7565-timing",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.C. Gen. Stat. § 75-65",
            "citation": "N.C. Gen. Stat. § 75-65(a).",
            "url": "https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_75/GS_75-65.html",
            "proposition": "Breach notification must be made without unreasonable delay, qualified only by law-enforcement needs and the measures necessary to scope the breach and restore the system.",
            "verbatimQuote": "The disclosure notification shall be made without unreasonable delay, consistent with the legitimate needs of law enforcement, as provided in subsection (c) of this section, and consistent with any measures necessary to determine sufficient contact information, determine the scope of the breach and restore the reasonable integrity, security, and confidentiality of the data system.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-breach-7565-timing"
          },
          {
            "id": "breach-7561-definition",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.C. Gen. Stat. § 75-61",
            "citation": "N.C. Gen. Stat. § 75-61(14).",
            "url": "https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_75/GS_75-61.html",
            "proposition": "A security breach is unauthorized access to and acquisition of unencrypted, unredacted personal information where illegal use has occurred, is reasonably likely, or creates a material risk of harm to a consumer; encrypted records also trigger the definition if the confidential process or key is acquired.",
            "verbatimQuote": "An incident of unauthorized access to and acquisition of unencrypted and unredacted records or data containing personal information where illegal use of the personal information has occurred or is reasonably likely to occur or that creates a material risk of harm to a consumer. Any incident of unauthorized access to and acquisition of encrypted records or data containing personal information along with the confidential process or key shall constitute a security breach.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-breach-7561-definition"
          },
          {
            "id": "breach-7561-personal-info",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.C. Gen. Stat. § 75-61",
            "citation": "N.C. Gen. Stat. § 75-61(10).",
            "url": "https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_75/GS_75-61.html",
            "proposition": "Personal information under the ITPA means a person's first name or first initial and last name combined with identifying information as defined in G.S. 14-113.20(b), excluding certain public information.",
            "verbatimQuote": "A person's first name or first initial and last name in combination with identifying information as defined in G.S. 14-113.20(b). Personal information does not include publicly available directories containing information an individual has voluntarily consented to have publicly disseminated or listed, including name, address, and telephone number, and does not include information made lawfully available to the general public from federal, state, or local government records.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-breach-7561-personal-info"
          },
          {
            "id": "breach-7565-exclusions",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.C. Gen. Stat. § 75-65",
            "citation": "N.C. Gen. Stat. § 75-65(a).",
            "url": "https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_75/GS_75-65.html",
            "proposition": "For breach-notification purposes, certain electronic identifiers, email information, account names, prior surnames, and passwords are excluded unless they would permit access to financial accounts or resources.",
            "verbatimQuote": "For the purposes of this section, personal information shall not include electronic identification numbers, email names or addresses, internet account numbers, internet identification names, parent's legal surname prior to marriage, or a password unless this information would permit access to a person's financial account or resources.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-breach-7565-exclusions"
          },
          {
            "id": "breach-7561-encryption",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.C. Gen. Stat. § 75-61",
            "citation": "N.C. Gen. Stat. § 75-61(8).",
            "url": "https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_75/GS_75-61.html",
            "proposition": "Encryption means using an algorithmic process to render data unreadable or unusable without a confidential process or key.",
            "verbatimQuote": "The use of an algorithmic process to transform data into a form in which the data is rendered unreadable or unusable without use of a confidential process or key.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-breach-7561-encryption"
          },
          {
            "id": "breach-7561-redaction",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.C. Gen. Stat. § 75-61",
            "citation": "N.C. Gen. Stat. § 75-61(13).",
            "url": "https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_75/GS_75-61.html",
            "proposition": "Redaction means rendering data unreadable or truncating it so no more than the last four digits of the identification number are accessible.",
            "verbatimQuote": "The rendering of data so that it is unreadable or is truncated so that no more than the last four digits of the identification number is accessible as part of the data.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-breach-7561-redaction"
          },
          {
            "id": "breach-7565-ag",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.C. Gen. Stat. § 75-65",
            "citation": "N.C. Gen. Stat. § 75-65(e1).",
            "url": "https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_75/GS_75-65.html",
            "proposition": "Whenever a business notifies any affected person of a breach, it must also notify the Attorney General's Consumer Protection Division — the duty attaches to every consumer-noticed breach with no headcount floor.",
            "verbatimQuote": "In the event a business provides notice to an affected person pursuant to this section, the business shall notify without unreasonable delay the Consumer Protection Division of the Attorney General's Office of the nature of the breach, the number of consumers affected by the breach, steps taken to investigate the breach, steps taken to prevent a similar breach in the future, and information regarding the timing, distribution, and content of the notice.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-breach-7565-ag"
          },
          {
            "id": "breach-7565-contents",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.C. Gen. Stat. § 75-65",
            "citation": "N.C. Gen. Stat. § 75-65(d).",
            "url": "https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_75/GS_75-65.html",
            "proposition": "North Carolina breach notices must be clear and conspicuous and include seven categories of information about the incident, data involved, protective measures, contact information, vigilance advice, consumer reporting agencies, the FTC, and the North Carolina Attorney General.",
            "verbatimQuote": "The notice shall be clear and conspicuous. The notice shall include all of the following: (1) A description of the incident in general terms. (2) A description of the type of personal information that was subject to the unauthorized access and acquisition. (3) A description of the general acts of the business to protect the personal information from further unauthorized access. (4) A telephone number for the business that the person may call for further information and assistance, if one exists. (5) Advice that directs the person to remain vigilant by reviewing account statements and monitoring free credit reports. (6) The toll-free numbers and addresses for the major consumer reporting agencies. (7) The toll-free numbers, addresses, and website addresses for the Federal Trade Commission and the North Carolina Attorney General's Office, along with a statement that the individual can obtain information from these sources about preventing identity theft.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-breach-7565-contents"
          },
          {
            "id": "breach-7565-substitute",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.C. Gen. Stat. § 75-65",
            "citation": "N.C. Gen. Stat. § 75-65(e)(4).",
            "url": "https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_75/GS_75-65.html",
            "proposition": "Substitute notice is available if notice would cost more than $250,000, the affected class exceeds 500,000, or the business lacks enough contact information, consent, or ability to identify particular affected persons.",
            "verbatimQuote": "Substitute notice, if the business demonstrates that the cost of providing notice would exceed two hundred fifty thousand dollars ($250,000) or that the affected class of subject persons to be notified exceeds 500,000, or if the business does not have sufficient contact information or consent to satisfy subdivisions (1), (2), or (3) of this subsection, for only those affected persons without sufficient contact information or consent, or if the business is unable to identify particular affected persons, for only those unidentifiable affected persons.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-breach-7565-substitute"
          },
          {
            "id": "breach-7565-cra",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.C. Gen. Stat. § 75-65",
            "citation": "N.C. Gen. Stat. § 75-65(f).",
            "url": "https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_75/GS_75-65.html",
            "proposition": "A breach notice to more than 1,000 persons at one time also requires notice to the nationwide consumer reporting agencies.",
            "verbatimQuote": "In the event a business provides notice to more than 1,000 persons at one time pursuant to this section, the business shall notify, without unreasonable delay, the Consumer Protection Division of the Attorney General's Office and all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis, as defined in 15 U.S.C. § 1681a(p), of the timing, distribution, and content of the notice.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-breach-7565-cra"
          },
          {
            "id": "breach-7565-per-se",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.C. Gen. Stat. § 75-65",
            "citation": "N.C. Gen. Stat. § 75-65(i).",
            "url": "https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_75/GS_75-65.html",
            "proposition": "A breach-notification violation is per se a § 75-1.1 unfair-trade-practice violation, privately actionable by an injured individual.",
            "verbatimQuote": "A violation of this section is a violation of G.S. 75-1.1. No private right of action may be brought by an individual for a violation of this section unless such individual is injured as a result of the violation.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-breach-7565-per-se"
          }
        ]
      },
      {
        "slug": "ag-enforcement",
        "label": "How is privacy law enforced in North Carolina?",
        "heading": "How is privacy law enforced in North Carolina?",
        "answerText": "For injured consumers, enforcement turns on the specific ITPA sections that expressly bridge into § 75-1.1 and on Chapter 75's civil action. The breach-notification section says a violation is a § 75-1.1 violation and allows a private action only for an injured individual; § 75-16 then gives an injured person a right of action and requires trebling when damages are assessed. There is no cure period, no right-to-fix window, and no contracting around the Article: any waiver of its provisions is contrary to public policy and is void and unenforceable.",
        "sources": [
          {
            "id": "enforce-7565-per-se",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.C. Gen. Stat. § 75-65",
            "citation": "N.C. Gen. Stat. § 75-65(i).",
            "url": "https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_75/GS_75-65.html",
            "proposition": "A breach-notification violation is a § 75-1.1 violation, and an individual may bring a private action only if injured by the violation.",
            "verbatimQuote": "A violation of this section is a violation of G.S. 75-1.1. No private right of action may be brought by an individual for a violation of this section unless such individual is injured as a result of the violation.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-enforce-7565-per-se"
          },
          {
            "id": "enforce-7516-treble",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.C. Gen. Stat. § 75-16",
            "citation": "N.C. Gen. Stat. § 75-16.",
            "url": "https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_75/GS_75-16.html",
            "proposition": "A person injured by a Chapter 75 violation has a private right of action, and damages assessed must be trebled.",
            "verbatimQuote": "If any person shall be injured or the business of any person, firm or corporation shall be broken up, destroyed or injured by reason of any act or thing done by any other person, firm or corporation in violation of the provisions of this Chapter, such person, firm or corporation so injured shall have a right of action on account of such injury done, and if damages are assessed in such case judgment shall be rendered in favor of the plaintiff and against the defendant for treble the amount fixed by the verdict.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-enforce-7516-treble"
          },
          {
            "id": "enforce-7511-udap",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.C. Gen. Stat. § 75-1.1",
            "citation": "N.C. Gen. Stat. § 75-1.1(a).",
            "url": "https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_75/GS_75-1.1.html",
            "proposition": "Section 75-1.1 declares unfair or deceptive acts or practices in or affecting commerce unlawful.",
            "verbatimQuote": "Unfair methods of competition in or affecting commerce, and unfair or deceptive acts or practices in or affecting commerce, are declared unlawful.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-enforce-7511-udap"
          },
          {
            "id": "enforce-7565-ag-report",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.C. Gen. Stat. § 75-65",
            "citation": "N.C. Gen. Stat. § 75-65(e1).",
            "url": "https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_75/GS_75-65.html",
            "proposition": "Whenever a business provides breach notice to an affected person, it must notify the Attorney General's Consumer Protection Division without unreasonable delay and provide specified breach-report details.",
            "verbatimQuote": "In the event a business provides notice to an affected person pursuant to this section, the business shall notify without unreasonable delay the Consumer Protection Division of the Attorney General's Office of the nature of the breach, the number of consumers affected by the breach, steps taken to investigate the breach, steps taken to prevent a similar breach in the future, and information regarding the timing, distribution, and content of the notice.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-enforce-7565-ag-report"
          },
          {
            "id": "enforce-7565-waiver",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.C. Gen. Stat. § 75-65",
            "citation": "N.C. Gen. Stat. § 75-65(g).",
            "url": "https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_75/GS_75-65.html",
            "proposition": "The Identity Theft Protection Act cannot be waived by contract — any waiver of the Article's provisions is void and unenforceable.",
            "verbatimQuote": "Any waiver of the provisions of this Article is contrary to public policy and is void and unenforceable.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-enforce-7565-waiver"
          },
          {
            "id": "enforce-115c-ag",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.C. Gen. Stat. § 115C-401.2",
            "citation": "N.C. Gen. Stat. § 115C-401.2(g).",
            "url": "https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_115C/GS_115C-401.2.html",
            "proposition": "The student online privacy statute is enforced by the Attorney General through civil actions for injunctive and equitable relief and creates no private right of action.",
            "verbatimQuote": "The Attorney General, upon ascertaining that an operator has violated this section, may bring a civil action seeking injunctive and other equitable relief.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-carolina#src-enforce-115c-ag"
          }
        ]
      }
    ]
  }
}
