{
  "type": "practice-guide",
  "canonical": "https://openagreements.org/practice-guides/privacy/us/north-dakota",
  "links": [
    {
      "rel": "self",
      "href": "https://openagreements.org/practice-guides/privacy/us/north-dakota.json",
      "type": "application/json"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/north-dakota",
      "type": "text/html"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/north-dakota/markdown",
      "type": "text/markdown"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/north-dakota/json",
      "type": "application/json"
    }
  ],
  "data": {
    "topic": "privacy",
    "state": "north-dakota",
    "frontmatter": {
      "title": "North Dakota Consumer Privacy Law",
      "description": "North Dakota has no comprehensive consumer-privacy statute. Chapter 51-30 governs breach notification, enforced through the ch. 51-15 consumer-fraud law, and a 2025 chapter imposes data-security duties on state-regulated financial corporations.",
      "state": "North Dakota",
      "lastReviewed": "2026-06-12",
      "license": "CC BY 4.0",
      "authors": [
        "steven-obiajulu"
      ],
      "summary": {
        "keyLaw": "N.D. Cent. Code ch. 51-30 (breach notification) — North Dakota has no comprehensive consumer-privacy law; ch. 51-30 plus the consumer-fraud law (ch. 51-15) and the 2025 financial-corporation data-security chapter (ch. 13-01.2) are the operative state framework",
        "appliesTo": "Any person that owns or licenses computerized data including personal information of North Dakota residents — no revenue or consumer-volume threshold; the 2025 data-security chapter reaches financial corporations regulated by the Department of Financial Institutions",
        "privacyPolicyRequired": "No North Dakota statute mandates a consumer privacy policy or fixes its contents; a policy that misstates practices can be a deceptive practice under N.D. Cent. Code ch. 51-15 and FTC Act § 5, with GLBA, HIPAA, and COPPA supplying contents where those regimes apply",
        "privateRightOfAction": "Not expressly under ch. 51-30 — the Attorney General enforces it — but a ch. 51-30 violation is deemed a ch. 51-15 violation, and § 51-15-09 preserves private claims, with treble damages for knowing conduct, against a defendant who acquired money or property through an unlawful practice",
        "regulator": "North Dakota Attorney General; Commissioner of the Department of Financial Institutions for the 2025 financial-corporation data-security chapter",
        "bottomLine": "North Dakota has not enacted a comprehensive consumer-privacy law — the operative state framework is the ch. 51-30 breach-notification statute, enforced by the Attorney General through the ch. 51-15 consumer-fraud law, plus a 2025 information-security chapter for state-regulated financial corporations, with everything else riding the federal and sectoral overlay.",
        "lawCoverage": "baseline",
        "policyMandate": "none",
        "consumersCanSue": "narrow",
        "sensitiveDataConsent": "none",
        "universalOptOutSignal": "notRequired"
      },
      "about": [
        "North Dakota consumer privacy law",
        "North Dakota data breach notification 51-30",
        "North Dakota no comprehensive privacy law",
        "North Dakota privacy policy requirements",
        "North Dakota unlawful sales or advertising practices 51-15",
        "North Dakota attorney general privacy enforcement",
        "North Dakota data breach private right of action",
        "North Dakota financial corporation data security 13-01.2",
        "North Dakota vendor data processing contracts",
        "North Dakota breach notice attorney general 250 individuals"
      ],
      "translations": [
        {
          "language": "中文",
          "status": "planned"
        },
        {
          "language": "Español",
          "status": "planned"
        },
        {
          "language": "Português",
          "status": "planned"
        },
        {
          "language": "Deutsch",
          "status": "planned"
        }
      ]
    },
    "questions": [
      {
        "slug": "which-privacy-laws-apply",
        "label": "Which privacy laws apply to your business in North Dakota?",
        "heading": "Which privacy laws apply to your business in North Dakota?",
        "answerText": "There is no comprehensive North Dakota consumer-privacy law. The operative state statute for most businesses is chapter 51-30 of the Century Code, a breach-notification law that applies to any person that owns or licenses computerized data that includes personal information of North Dakota residents — with no revenue or consumer-volume threshold. Day-to-day data practices are policed instead by the state consumer-fraud law, chapter 51-15, which declares deceptive acts or practices in connection with the sale or advertisement of merchandise unlawful. And since 2025, a third state law applies to one sector: chapter 13-01.2 requires every state-regulated financial corporation to develop, implement, and maintain a comprehensive information security program.",
        "sources": [
          {
            "id": "stat-51-30-02-duty",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.D. Cent. Code § 51-30-02",
            "citation": "N.D. Cent. Code § 51-30-02.",
            "url": "https://ndlegis.gov/cencode/t51c30.pdf",
            "proposition": "North Dakota's breach-notification duty applies to any person that owns or licenses computerized data including personal information of state residents, with no size threshold.",
            "verbatimQuote": "Any person that owns or licenses computerized data that includes personal information, shall disclose any breach of the security system following discovery or notification of the breach in the security of the data to any resident of the state whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-dakota#src-stat-51-30-02-duty"
          },
          {
            "id": "stat-51-15-02-deception",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.D. Cent. Code § 51-15-02",
            "citation": "N.D. Cent. Code § 51-15-02.",
            "url": "https://ndlegis.gov/cencode/t51c15.pdf",
            "proposition": "North Dakota's consumer-fraud law declares deceptive acts or practices in connection with the sale or advertisement of merchandise unlawful, whether or not anyone was actually misled.",
            "verbatimQuote": "The act, use, or employment by any person of any deceptive act or practice, fraud, false pretense, false promise, or misrepresentation, with the intent that others rely thereon in connection with the sale or advertisement of any merchandise, whether or not any person has in fact been misled, deceived, or damaged thereby, is declared to be an unlawful practice.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-dakota#src-stat-51-15-02-deception"
          },
          {
            "id": "stat-51-15-01-merchandise",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.D. Cent. Code § 51-15-01",
            "citation": "N.D. Cent. Code § 51-15-01(3).",
            "url": "https://ndlegis.gov/cencode/t51c15.pdf",
            "proposition": "The consumer-fraud law defines merchandise broadly to include intangibles and services, which brings most consumer-facing data practices within its reach.",
            "verbatimQuote": "“Merchandise” means any objects, wares, goods, commodities, intangibles, real estate, charitable contributions, or services.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-dakota#src-stat-51-15-01-merchandise"
          },
          {
            "id": "stat-13-01-2-program",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.D. Cent. Code § 13-01.2-02",
            "citation": "N.D. Cent. Code § 13-01.2-02(1).",
            "url": "https://ndlegis.gov/cencode/t13c01-2.pdf",
            "proposition": "The 2025 financial-corporation chapter requires every covered financial corporation to develop, implement, and maintain a comprehensive information security program.",
            "verbatimQuote": "A financial corporation shall develop, implement, and maintain a comprehensive information security program.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-dakota#src-stat-13-01-2-program"
          }
        ]
      },
      {
        "slug": "privacy-policy-contents",
        "label": "What must your North Dakota privacy policy contain?",
        "heading": "What must your North Dakota privacy policy contain?",
        "answerText": "No North Dakota statute requires a general consumer privacy policy or fixes what it must say. For most businesses the governing rule is that whatever you publish has to be true: under Section 5 of the FTC Act, a policy that misstates how you collect, use, share, retain, or secure data is a deceptive practice, and North Dakota's consumer-fraud law reaches the same conduct as a deceptive act or practice — and separately condemns practices that are unconscionable or cause substantial, unavoidable injury to consumers. Where a sectoral regime applies, that regime supplies the contents instead.",
        "sources": [
          {
            "id": "fed-ftc5-deceptive",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "FTC Act § 5",
            "citation": "15 U.S.C. § 45(a)(1).",
            "url": "https://www.law.cornell.edu/uscode/text/15/45",
            "deepLink": "https://www.law.cornell.edu/uscode/text/15/45#:~:text=Unfair%20methods%20of%20competition%20in,commerce%2C%20are%20hereby%20declared%20unlawful.",
            "proposition": "Section 5 of the FTC Act declares unfair or deceptive acts or practices in or affecting commerce unlawful, which reaches a privacy policy that misstates a business's actual data practices.",
            "verbatimQuote": "Unfair methods of competition in or affecting commerce, and unfair or deceptive acts or practices in or affecting commerce, are hereby declared unlawful.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-dakota#src-fed-ftc5-deceptive"
          },
          {
            "id": "q2-stat-51-15-02-unlawful",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.D. Cent. Code § 51-15-02",
            "citation": "N.D. Cent. Code § 51-15-02.",
            "url": "https://ndlegis.gov/cencode/t51c15.pdf",
            "proposition": "North Dakota's consumer-fraud law makes deceptive acts and practices unlawful and separately condemns unconscionable practices and practices likely to cause substantial, unavoidable consumer injury — the state-law hook for a privacy policy that misstates actual practices.",
            "verbatimQuote": "The act, use, or employment by any person of any deceptive act or practice, fraud, false pretense, false promise, or misrepresentation, with the intent that others rely thereon in connection with the sale or advertisement of any merchandise, whether or not any person has in fact been misled, deceived, or damaged thereby, is declared to be an unlawful practice. The act, use, or employment by any person of any act or practice, in connection with the sale or advertisement of any merchandise, which is unconscionable or which causes or is likely to cause substantial injury to a person which is not reasonably avoidable by the injured person and not outweighed by countervailing benefits to consumers or to competition, is declared to be an unlawful practice.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-dakota#src-q2-stat-51-15-02-unlawful"
          },
          {
            "id": "fed-glba-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "GLBA privacy notice",
            "citation": "15 U.S.C. § 6802(a).",
            "url": "https://www.law.cornell.edu/uscode/text/15/6802",
            "deepLink": "https://www.law.cornell.edu/uscode/text/15/6802#:~:text=Except%20as%20otherwise%20provided%20in,section%206803%20of%20this%20title.",
            "proposition": "The GLBA bars a financial institution from disclosing nonpublic personal information to a nonaffiliated third party unless it has given the consumer a compliant privacy notice.",
            "verbatimQuote": "Except as otherwise provided in this subchapter, a financial institution may not, directly or through any affiliate, disclose to a nonaffiliated third party any nonpublic personal information, unless such financial institution provides or has provided to the consumer a notice that complies with section 6803 of this title.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-dakota#src-fed-glba-notice"
          },
          {
            "id": "fed-hipaa-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "HIPAA Notice of Privacy Practices",
            "citation": "45 C.F.R. § 164.520.",
            "url": "https://www.law.cornell.edu/cfr/text/45/164.520",
            "deepLink": "https://www.law.cornell.edu/cfr/text/45/164.520#:~:text=an%20individual%20has%20a%20right,respect%20to%20protected%20health%20information",
            "proposition": "A HIPAA covered entity must give individuals a notice describing the uses and disclosures of their protected health information and their rights and the entity's legal duties.",
            "verbatimQuote": "an individual has a right to adequate notice of the uses and disclosures of protected health information that may be made by the covered entity, and of the individual's rights and the covered entity's legal duties with respect to protected health information",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-dakota#src-fed-hipaa-notice"
          },
          {
            "id": "fed-coppa-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "COPPA notice requirement",
            "citation": "15 U.S.C. § 6502(b)(1)(A)(i).",
            "url": "https://www.law.cornell.edu/uscode/text/15/6502",
            "deepLink": "https://www.law.cornell.edu/uscode/text/15/6502#:~:text=to%20provide%20notice%20on%20the,disclosure%20practices%20for%20such%20information",
            "proposition": "COPPA requires an operator of a child-directed website or online service to post notice of what information it collects from children, how it uses the information, and its disclosure practices.",
            "verbatimQuote": "to provide notice on the website of what information is collected from children by the operator, how the operator uses such information, and the operator’s disclosure practices for such information",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-dakota#src-fed-coppa-notice"
          }
        ]
      },
      {
        "slug": "vendor-contracts",
        "label": "What must your contracts with vendors say?",
        "heading": "What must your contracts with vendors say?",
        "answerText": "North Dakota has no omnibus data-processing-agreement requirement — no state statute prescribes controller-to-processor terms, audit rights, deletion clauses, or subprocessor flow-downs for general private-sector contracts. The one state law that mandates vendor contract terms is sector-specific: a financial corporation covered by the 2025 data-security chapter must oversee its service providers, including by requiring them by contract to implement and maintain appropriate safeguards.",
        "sources": [
          {
            "id": "stat-13-01-2-vendor-oversight",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.D. Cent. Code § 13-01.2-03(8)",
            "citation": "N.D. Cent. Code § 13-01.2-03(8).",
            "url": "https://ndlegis.gov/cencode/t13c01-2.pdf",
            "proposition": "A covered financial corporation must oversee service providers through selection diligence, contractual safeguard requirements, and periodic risk-based reassessment.",
            "verbatimQuote": "A financial corporation shall oversee service providers by: a. Taking reasonable steps to select and retain service providers capable of maintaining appropriate safeguards for customer information; b. Requiring, by contract, the financial corporation's service providers implement and maintain appropriate safeguards; and c. Periodically assessing the financial corporation's service providers based on the risk they present, and the continued adequacy of the service providers' safeguards.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-dakota#src-stat-13-01-2-vendor-oversight"
          },
          {
            "id": "fed-glba-safeguards",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "GLBA Safeguards Rule",
            "citation": "16 C.F.R. § 314.4(f)(2).",
            "url": "https://www.law.cornell.edu/cfr/text/16/314.4",
            "deepLink": "https://www.law.cornell.edu/cfr/text/16/314.4#:~:text=Requiring%20your%20service%20providers%20by,implement%20and%20maintain%20such%20safeguards",
            "proposition": "The GLBA Safeguards Rule requires a financial institution to oversee its service providers, including by requiring them by contract to implement and maintain appropriate safeguards for customer information.",
            "verbatimQuote": "Requiring your service providers by contract to implement and maintain such safeguards",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-dakota#src-fed-glba-safeguards"
          },
          {
            "id": "fed-hipaa-baa",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "HIPAA Business Associate Contracts",
            "citation": "45 C.F.R. § 164.504(e)(2).",
            "url": "https://www.law.cornell.edu/cfr/text/45/164.504",
            "deepLink": "https://www.law.cornell.edu/cfr/text/45/164.504#:~:text=A%20contract%20between%20the%20covered,and%20a%20business%20associate%20must",
            "proposition": "HIPAA requires a written business-associate contract that establishes the permitted uses and disclosures of protected health information and binds the business associate to safeguard it.",
            "verbatimQuote": "A contract between the covered entity and a business associate must",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-dakota#src-fed-hipaa-baa"
          },
          {
            "id": "q3-stat-51-30-03-vendor-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.D. Cent. Code § 51-30-03",
            "citation": "N.D. Cent. Code § 51-30-03.",
            "url": "https://ndlegis.gov/cencode/t51c30.pdf",
            "proposition": "A person that maintains computerized personal information it does not own must notify the owner or licensee of a breach immediately following discovery.",
            "verbatimQuote": "Any person that maintains computerized data that includes personal information that the person does not own shall notify the owner or licensee of the information of the breach of the security of the data immediately following the discovery, if the personal information was, or is reasonably believed to have been, acquired by an unauthorized person.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-dakota#src-q3-stat-51-30-03-vendor-notice"
          }
        ]
      },
      {
        "slug": "breach-notification",
        "label": "When must you notify people of a data breach in North Dakota?",
        "heading": "When must you notify people of a data breach in North Dakota?",
        "answerText": "Any person that owns or licenses computerized data including personal information must notify every North Dakota resident whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person. If the breach exceeds two hundred fifty individuals, the person must also notify the Attorney General, and the disclosure must be made in the most expedient time possible and without unreasonable delay. A reportable breach is the unauthorized acquisition of computerized data when access to personal information has not been secured by encryption or an equivalent method.",
        "sources": [
          {
            "id": "q4-stat-51-30-02-resident-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.D. Cent. Code § 51-30-02",
            "citation": "N.D. Cent. Code § 51-30-02.",
            "url": "https://ndlegis.gov/cencode/t51c30.pdf",
            "proposition": "Any person that owns or licenses computerized personal information must notify North Dakota residents whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person.",
            "verbatimQuote": "Any person that owns or licenses computerized data that includes personal information, shall disclose any breach of the security system following discovery or notification of the breach in the security of the data to any resident of the state whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-dakota#src-q4-stat-51-30-02-resident-notice"
          },
          {
            "id": "stat-51-30-02-ag-timing",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.D. Cent. Code § 51-30-02",
            "citation": "N.D. Cent. Code § 51-30-02.",
            "url": "https://ndlegis.gov/cencode/t51c30.pdf",
            "proposition": "A breach exceeding 250 individuals must also be disclosed to the Attorney General, and notice must be made in the most expedient time possible and without unreasonable delay.",
            "verbatimQuote": "In addition, any person that experiences a breach of the security system as provided in this section shall disclose to the attorney general by mail or electronic mail any breach of the security system which exceeds two hundred fifty individuals. The disclosure must be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement, as provided in section 51-30-04, or any measures necessary to determine the scope of the breach and to restore the integrity of the data system.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-dakota#src-stat-51-30-02-ag-timing"
          },
          {
            "id": "stat-51-30-01-breach-def",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.D. Cent. Code § 51-30-01",
            "citation": "N.D. Cent. Code § 51-30-01(1).",
            "url": "https://ndlegis.gov/cencode/t51c30.pdf",
            "proposition": "A breach is the unauthorized acquisition of computerized data when personal information was not secured by encryption or an equivalent method, and good-faith employee or agent acquisition without further misuse is excluded.",
            "verbatimQuote": "“Breach of the security system” means unauthorized acquisition of computerized data when access to personal information has not been secured by encryption or by any other method or technology that renders the electronic files, media, or databases unreadable or unusable. Good-faith acquisition of personal information by an employee or agent of the person is not a breach of the security of the system, if the personal information is not used or subject to further unauthorized disclosure.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-dakota#src-stat-51-30-01-breach-def"
          },
          {
            "id": "stat-51-30-01-personal-info",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.D. Cent. Code § 51-30-01",
            "citation": "N.D. Cent. Code § 51-30-01(4)(a).",
            "url": "https://ndlegis.gov/cencode/t51c30.pdf",
            "proposition": "Personal information is a resident's name combined with unencrypted data elements that include not only Social Security, license, and financial-account numbers but also date of birth, mother's maiden name, medical and health-insurance information, employer-assigned IDs with access codes, and electronic signatures.",
            "verbatimQuote": "“Personal information” means an individual's first name or first initial and last name in combination with any of the following data elements, when the name and the data elements are not encrypted: (1) The individual's social security number; (2) The operator's license number assigned to an individual by the department of transportation under section 39-06-14; (3) A nondriver color photo identification card number assigned to the individual by the department of transportation under section 39-06-03.1; (4) The individual's financial institution account number, credit card number, or debit card number in combination with any required security code, access code, or password that would permit access to an individual's financial accounts; (5) The individual's date of birth; (6) The maiden name of the individual's mother; (7) Medical information; (8) Health insurance information; (9) An identification number assigned to the individual by the individual's employer in combination with any required security code, access code, or password; or (10) The individual's digitized or other electronic signature.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-dakota#src-stat-51-30-01-personal-info"
          },
          {
            "id": "q4-stat-51-30-03-vendor-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.D. Cent. Code § 51-30-03",
            "citation": "N.D. Cent. Code § 51-30-03.",
            "url": "https://ndlegis.gov/cencode/t51c30.pdf",
            "proposition": "A person that maintains computerized personal information it does not own must notify the owner or licensee of a breach immediately following discovery.",
            "verbatimQuote": "Any person that maintains computerized data that includes personal information that the person does not own shall notify the owner or licensee of the information of the breach of the security of the data immediately following the discovery, if the personal information was, or is reasonably believed to have been, acquired by an unauthorized person.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-dakota#src-q4-stat-51-30-03-vendor-notice"
          },
          {
            "id": "stat-51-30-04-delay",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.D. Cent. Code § 51-30-04",
            "citation": "N.D. Cent. Code § 51-30-04.",
            "url": "https://ndlegis.gov/cencode/t51c30.pdf",
            "proposition": "Notification may be delayed when a law enforcement agency determines it would impede a criminal investigation, and must be made once the agency determines notice will not compromise the investigation.",
            "verbatimQuote": "The notification required by this chapter may be delayed if a law enforcement agency determines that the notification will impede a criminal investigation. The notification required by this chapter must be made after the law enforcement agency determines that the notification will not compromise the investigation.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-dakota#src-stat-51-30-04-delay"
          },
          {
            "id": "stat-51-30-05-substitute",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.D. Cent. Code § 51-30-05",
            "citation": "N.D. Cent. Code § 51-30-05(3).",
            "url": "https://ndlegis.gov/cencode/t51c30.pdf",
            "proposition": "Substitute notice is available when direct notice would cost more than $250,000, the affected class exceeds 500,000 persons, or the person lacks sufficient contact information.",
            "verbatimQuote": "Substitute notice, if the person demonstrates that the cost of providing notice would exceed two hundred fifty thousand dollars, or that the affected class of subject persons to be notified exceeds five hundred thousand, or the person does not have sufficient contact information.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-dakota#src-stat-51-30-05-substitute"
          },
          {
            "id": "stat-51-30-06-own-policy",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.D. Cent. Code § 51-30-06",
            "citation": "N.D. Cent. Code § 51-30-06.",
            "url": "https://ndlegis.gov/cencode/t51c30.pdf",
            "proposition": "A person that follows its own breach-notification procedures under an information security policy consistent with the chapter's timing requirements is deemed compliant.",
            "verbatimQuote": "Notwithstanding section 51-30-05, a person that maintains its own notification procedures as part of an information security policy for the treatment of personal information and is otherwise consistent with the timing requirements of this chapter is deemed to be in compliance with the notification requirements of this chapter if the person notifies subject individuals in accordance with its policies in the event of a breach of security of the system.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-dakota#src-stat-51-30-06-own-policy"
          },
          {
            "id": "stat-51-30-06-deemed-compliance",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.D. Cent. Code § 51-30-06",
            "citation": "N.D. Cent. Code § 51-30-06.",
            "url": "https://ndlegis.gov/cencode/t51c30.pdf",
            "proposition": "Financial institutions complying with the federal interagency breach guidance, and HIPAA covered entities, business associates, and subcontractors subject to the federal breach-notification rule, are deemed in compliance with the chapter.",
            "verbatimQuote": "A financial institution, trust company, or credit union that is subject to, examined for, and in compliance with the federal interagency guidance on response programs for unauthorized access to customer information and customer notice is in compliance with this chapter. A covered entity, business associate, or subcontractor subject to breach notification requirements under title 45, Code of Federal Regulations, subpart D, part 164, is considered to be in compliance with this chapter.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-dakota#src-stat-51-30-06-deemed-compliance"
          }
        ]
      },
      {
        "slug": "financial-data-security",
        "label": "What does North Dakota's 2025 financial data-security law require?",
        "heading": "What does North Dakota's 2025 financial data-security law require?",
        "answerText": "In 2025 North Dakota enacted chapter 13-01.2, which requires every covered financial corporation to develop, implement, and maintain a comprehensive information security program. The chapter reaches entities regulated by the Department of Financial Institutions other than banks and credit unions — financial corporation is defined as all entities regulated by the department, excluding financial institutions and credit unions — so it covers nondepository licensees such as lenders, brokers, and servicers under the department's supervision.",
        "sources": [
          {
            "id": "q5-stat-13-01-2-program",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.D. Cent. Code § 13-01.2-02",
            "citation": "N.D. Cent. Code § 13-01.2-02(1).",
            "url": "https://ndlegis.gov/cencode/t13c01-2.pdf",
            "proposition": "Every covered financial corporation must develop, implement, and maintain a comprehensive information security program.",
            "verbatimQuote": "A financial corporation shall develop, implement, and maintain a comprehensive information security program.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-dakota#src-q5-stat-13-01-2-program"
          },
          {
            "id": "stat-13-01-2-scope",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.D. Cent. Code § 13-01.2-01",
            "citation": "N.D. Cent. Code § 13-01.2-01(9).",
            "url": "https://ndlegis.gov/cencode/t13c01-2.pdf",
            "proposition": "The chapter covers financial corporations — all entities regulated by the Department of Financial Institutions, excluding financial institutions and credit unions.",
            "verbatimQuote": "“Financial corporation” means all entities regulated by the department of financial institutions, excluding financial institutions and credit unions.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-dakota#src-stat-13-01-2-scope"
          },
          {
            "id": "q5-fed-glba-qualified",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "GLBA Safeguards Rule",
            "citation": "16 C.F.R. § 314.4(a).",
            "url": "https://www.law.cornell.edu/cfr/text/16/314.4",
            "deepLink": "https://www.law.cornell.edu/cfr/text/16/314.4#:~:text=Designate%20a%20qualified%20individual%20responsible,enforcing%20your%20information%20security%20program",
            "proposition": "The federal GLBA Safeguards Rule requires designating a qualified individual responsible for overseeing, implementing, and enforcing the information security program — the structure North Dakota's 2025 chapter tracks.",
            "verbatimQuote": "Designate a qualified individual responsible for overseeing and implementing your information security program and enforcing your information security program",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-dakota#src-q5-fed-glba-qualified"
          },
          {
            "id": "stat-13-01-2-qualified",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.D. Cent. Code § 13-01.2-03(1)",
            "citation": "N.D. Cent. Code § 13-01.2-03(1).",
            "url": "https://ndlegis.gov/cencode/t13c01-2.pdf",
            "proposition": "A financial corporation's information security program must designate a qualified individual responsible for overseeing, implementing, and enforcing the program.",
            "verbatimQuote": "A financial corporation's information security program must denote a designation of a qualified individual responsible for overseeing and implementing the financial corporation's information security program and enforcing the financial corporation's information security program.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-dakota#src-stat-13-01-2-qualified"
          },
          {
            "id": "stat-13-01-2-encryption",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.D. Cent. Code § 13-01.2-03(5)(c)",
            "citation": "N.D. Cent. Code § 13-01.2-03(5)(c).",
            "url": "https://ndlegis.gov/cencode/t13c01-2.pdf",
            "proposition": "Covered financial corporations must encrypt all customer information in transit over external networks and at rest, with compensating controls allowed only on the qualified individual's review and approval when encryption is infeasible.",
            "verbatimQuote": "Protecting by encryption all customer information held or transmitted by the financial corporation both in transit over external networks and at rest. To the extent a financial corporation determines that encryption of customer information, either in transit over external networks or at rest, is infeasible, the financial corporation may secure customer information using effective alternative compensating controls reviewed and approved by the financial corporation's qualified individual.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-dakota#src-stat-13-01-2-encryption"
          },
          {
            "id": "stat-13-01-2-mfa",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.D. Cent. Code § 13-01.2-03(5)(e)",
            "citation": "N.D. Cent. Code § 13-01.2-03(5)(e).",
            "url": "https://ndlegis.gov/cencode/t13c01-2.pdf",
            "proposition": "Multifactor authentication is required for any individual accessing any information system unless the qualified individual approves a reasonably equivalent or more secure access control in writing.",
            "verbatimQuote": "Implementing multifactor authentication for any individual accessing any information system, unless the financial corporation's qualified individual has approved in writing the use of a reasonably equivalent or more secure access control.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-dakota#src-stat-13-01-2-mfa"
          },
          {
            "id": "stat-13-01-2-testing",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.D. Cent. Code § 13-01.2-03(6)",
            "citation": "N.D. Cent. Code § 13-01.2-03(6)(b).",
            "url": "https://ndlegis.gov/cencode/t13c01-2.pdf",
            "proposition": "A financial corporation's information systems monitoring and testing must include continuous monitoring or periodic penetration testing and vulnerability assessments.",
            "verbatimQuote": "Information systems monitoring and testing must include continuous monitoring or periodic penetration testing, and vulnerability assessments.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-dakota#src-stat-13-01-2-testing"
          },
          {
            "id": "stat-13-01-2-training",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.D. Cent. Code § 13-01.2-03(7)",
            "citation": "N.D. Cent. Code § 13-01.2-03(7).",
            "url": "https://ndlegis.gov/cencode/t13c01-2.pdf",
            "proposition": "A financial corporation must implement policies and procedures so its personnel can enact the information security program, including security awareness training updated for risks identified by the risk assessment and the use of qualified information security personnel.",
            "verbatimQuote": "A financial corporation shall implement policies and procedures to ensure the financial corporation's personnel are able to enact the financial corporation's information security program by: a. Providing the financial corporation's personnel with security awareness training that is updated as necessary to reflect risks identified by the risk assessment; b. Utilizing qualified information security personnel employed by the financial corporation or an affiliate or service provider sufficient to manage the financial corporation's information security risks and to perform or oversee the information security program; c. Providing information security personnel with security updates and training sufficient to address relevant security risks; and d. Verifying that key information security personnel take steps to maintain current knowledge of changing information security threats and countermeasures.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-dakota#src-stat-13-01-2-training"
          },
          {
            "id": "stat-13-01-2-irp",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.D. Cent. Code § 13-01.2-03(10)",
            "citation": "N.D. Cent. Code § 13-01.2-03(10).",
            "url": "https://ndlegis.gov/cencode/t13c01-2.pdf",
            "proposition": "A financial corporation must establish a written incident response plan designed to promptly respond to and recover from security events materially affecting the confidentiality, integrity, or availability of customer information.",
            "verbatimQuote": "A financial corporation shall establish a written incident response plan designed to promptly respond to, and recover from, any security event materially affecting the confidentiality, integrity, or availability of customer information the financial corporation controls.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-dakota#src-stat-13-01-2-irp"
          },
          {
            "id": "stat-13-01-2-annual-report",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.D. Cent. Code § 13-01.2-03(11)",
            "citation": "N.D. Cent. Code § 13-01.2-03(11).",
            "url": "https://ndlegis.gov/cencode/t13c01-2.pdf",
            "proposition": "The qualified individual must report in writing at least annually to the financial corporation's board of directors or equivalent governing body, or to a senior officer responsible for the program if no board exists.",
            "verbatimQuote": "A financial corporation shall require the financial corporation's qualified individual to report in writing, at least annually, to the financial corporation's board of directors or equivalent governing body. If no board of directors or equivalent governing body exists, the report shall be timely presented to a senior officer responsible for the financial corporation's information security program.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-dakota#src-stat-13-01-2-annual-report"
          },
          {
            "id": "q5-fed-glba-ftc-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "GLBA Safeguards Rule",
            "citation": "16 C.F.R. § 314.4(j)(1).",
            "url": "https://www.law.cornell.edu/cfr/text/16/314.4",
            "deepLink": "https://www.law.cornell.edu/cfr/text/16/314.4#:~:text=Upon%20discovery%20of%20a%20notification,after%20discovery%20of%20the%20event.",
            "proposition": "Under the federal Safeguards Rule, a financial institution must notify the FTC of a notification event involving the information of at least 500 consumers as soon as possible and no later than 30 days after discovery.",
            "verbatimQuote": "Upon discovery of a notification event as described in paragraph (j)(2) of this section, if the notification event involves the information of at least 500 consumers, you must notify the Federal Trade Commission as soon as possible, and no later than 30 days after discovery of the event.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-dakota#src-q5-fed-glba-ftc-notice"
          },
          {
            "id": "stat-13-01-2-notify",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.D. Cent. Code § 13-01.2-03(12)",
            "citation": "N.D. Cent. Code § 13-01.2-03(12)(b).",
            "url": "https://ndlegis.gov/cencode/t13c01-2.pdf",
            "proposition": "A financial corporation must notify the Commissioner of a notification event involving the information of at least 500 consumers as soon as possible and no later than 45 days after discovery.",
            "verbatimQuote": "After discovery of a notification event described in subdivision c, if the notification event involves the information of at least five hundred consumers, the financial corporation shall notify the commissioner as soon as possible, and no later than forty-five days after the event is discovered.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-dakota#src-stat-13-01-2-notify"
          },
          {
            "id": "stat-13-01-2-exemption",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.D. Cent. Code § 13-01.2-04",
            "citation": "N.D. Cent. Code § 13-01.2-04.",
            "url": "https://ndlegis.gov/cencode/t13c01-2.pdf",
            "proposition": "Section 13-01.2-04 states that the written-risk-assessment, penetration-testing and vulnerability-assessment, incident-response-plan, and annual-reporting elements do not apply to financial institutions that maintain customer information concerning fewer than five thousand consumers.",
            "verbatimQuote": "Subsection 4, subdivision b of subsection 6, and subsections 10 and 11 of section 13-01.2-03 do not apply to financial institutions that maintain customer information concerning fewer than five thousand consumers.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-dakota#src-stat-13-01-2-exemption"
          }
        ]
      },
      {
        "slug": "consumer-lawsuit",
        "label": "Can a consumer sue your business in North Dakota over privacy?",
        "heading": "Can a consumer sue your business in North Dakota over privacy?",
        "answerText": "The breach-notification chapter is built for public enforcement: the Attorney General may enforce it with all the powers and remedies of the consumer-fraud law, and a violation of the breach chapter is deemed a violation of chapter 51-15. But the chapter expressly states that its remedies are not exclusive and sit on top of all other causes of action and remedies under chapter 51-15 or otherwise provided by law, and chapter 51-15 itself preserves private claims: it does not bar any claim for relief by any person against a defendant who acquired money or property through an unlawful practice, with treble damages available for knowing conduct plus mandatory costs and attorney's fees.",
        "sources": [
          {
            "id": "stat-51-30-07-ag-enforce",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.D. Cent. Code § 51-30-07",
            "citation": "N.D. Cent. Code § 51-30-07.",
            "url": "https://ndlegis.gov/cencode/t51c30.pdf",
            "proposition": "The Attorney General enforces the breach-notification chapter with all the powers and remedies of chapter 51-15, and a violation of the chapter is deemed a violation of chapter 51-15.",
            "verbatimQuote": "The attorney general may enforce this chapter. The attorney general, in enforcing this chapter, has all the powers provided in chapter 51-15 and may seek all the remedies in chapter 51-15. A violation of this chapter is deemed a violation of chapter 51-15.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-dakota#src-stat-51-30-07-ag-enforce"
          },
          {
            "id": "stat-51-30-07-not-exclusive",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.D. Cent. Code § 51-30-07",
            "citation": "N.D. Cent. Code § 51-30-07.",
            "url": "https://ndlegis.gov/cencode/t51c30.pdf",
            "proposition": "The breach chapter's remedies are not exclusive — they are in addition to all other causes of action, remedies, and penalties under chapter 51-15 or otherwise provided by law.",
            "verbatimQuote": "The remedies, duties, prohibitions, and penalties of this chapter are not exclusive and are in addition to all other causes of action, remedies, and penalties under chapter 51-15, or otherwise provided by law.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-dakota#src-stat-51-30-07-not-exclusive"
          },
          {
            "id": "stat-51-15-09-private",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.D. Cent. Code § 51-15-09",
            "citation": "N.D. Cent. Code § 51-15-09.",
            "url": "https://ndlegis.gov/cencode/t51c15.pdf",
            "proposition": "Chapter 51-15 preserves private claims against a defendant who acquired money or property through an unlawful practice, with treble damages available for knowing conduct and mandatory costs and attorney's fees for a prevailing plaintiff.",
            "verbatimQuote": "Except as provided in section 51-15-02.3, this chapter does not bar any claim for relief by any person against any person who has acquired any moneys or property by means of any practice declared to be unlawful in this chapter. If the court finds the defendant knowingly committed the conduct, the court may order that the person commencing the action recover up to three times the actual damages proven and the court must order that the person commencing the action recover costs, disbursements, and actual reasonable attorney's fees incurred in the action.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-dakota#src-stat-51-15-09-private"
          },
          {
            "id": "stat-51-15-07-injunction",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.D. Cent. Code § 51-15-07",
            "citation": "N.D. Cent. Code § 51-15-07.",
            "url": "https://ndlegis.gov/cencode/t51c15.pdf",
            "proposition": "The Attorney General may seek and obtain a district-court injunction against any practice declared unlawful by the consumer-fraud law.",
            "verbatimQuote": "Whenever it appears to the attorney general that a person has engaged in, or is engaging in, any practice declared to be unlawful by this chapter, or by other provisions of law, including chapter 50-22, 51-13, 51-14, 51-16.1, or 51-18, the attorney general may seek and obtain in an action in a district court an injunction prohibiting that person from continuing the unlawful practice or engaging in the unlawful practice or doing any act in furtherance of the unlawful practice after appropriate notice to that person.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-dakota#src-stat-51-15-07-injunction"
          },
          {
            "id": "stat-51-15-11-penalty",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.D. Cent. Code § 51-15-11",
            "citation": "N.D. Cent. Code § 51-15-11.",
            "url": "https://ndlegis.gov/cencode/t51c15.pdf",
            "proposition": "A court may assess a civil penalty of up to $5,000 for each violation of the consumer-fraud law, in addition to the chapter's other remedies.",
            "verbatimQuote": "The court may assess for the benefit of the state a civil penalty of not more than five thousand dollars for each violation of this chapter or for each violation of chapter 51-12, 51-13, 51-14, or 51-18.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-dakota#src-stat-51-15-11-penalty"
          },
          {
            "id": "stat-51-15-12-limitations",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "N.D. Cent. Code § 51-15-12",
            "citation": "N.D. Cent. Code § 51-15-12.",
            "url": "https://ndlegis.gov/cencode/t51c15.pdf",
            "proposition": "A consumer-fraud claim must be brought within four years, and the period does not accrue until the aggrieved party discovers the facts constituting the violation.",
            "verbatimQuote": "Notwithstanding chapter 28-01, an action for relief under this chapter is barred if the claim is not commenced within four years after the claim for relief accrues. The period of limitation for a claim for relief may not be deemed to have accrued until the aggrieved party discovers the facts constituting the violation of this chapter.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/north-dakota#src-stat-51-15-12-limitations"
          }
        ]
      }
    ]
  }
}
