Law note · North Carolina

Identity Theft Protection Act, security breach notification

cite N.C. Gen. Stat. Secs. 75-61, 75-65 stage IMMINENT commencement not set reviewed 2026-08-28

Any business that owns or licenses personal information of a North Carolina resident, or that conducts business in North Carolina and owns or licenses such information in any form, must give notice of a security breach to the affected person without unreasonable delay, consistent with the legitimate needs of law enforcement; the statute sets no numeric notification deadline.

Business is defined narrowly as a sole proprietorship, partnership, corporation, association, or other group, whether or not organized for profit, with no government entity included.

Personal information is a name combined with identifying information as cross-referenced from North Carolina's criminal identity-theft statute, G.S. Sec. 14-113.20(b), which lists biometric data as one of fourteen enumerated items alongside a Social Security number, a driver's license number, and financial account numbers, but no North Carolina statute anywhere defines what biometric data means for this purpose; the term is used but never defined.

Personal information excludes information a person voluntarily consented to have publicly disseminated and information made lawfully available to the general public from government records, but because biometric data is an undefined cross-referenced term, whether this carve-out would reach an identifier derived from a public recording cannot be evaluated.

A business must also notify the Consumer Protection Division of the Attorney General's Office on every breach requiring notice to any affected person, and separately, on any breach affecting more than 1,000 persons at one time, must notify nationwide consumer reporting agencies.

A violation of the notice duty is a violation of North Carolina's general Unfair and Deceptive Trade Practices Act, G.S. Sec. 75-1.1, but an individual may not sue for that violation unless injured by it; once that injury threshold is met, G.S. Sec. 75-16 arms the injured person with a civil action for treble damages. Most recently amended by Session Law 2025-25.

What it asks of an app

  • Notify each affected North Carolina resident of a security breach involving their personal information without unreasonable delay, consistent with the legitimate needs of law enforcement.
  • Notify the Consumer Protection Division of the North Carolina Attorney General's Office of every breach requiring notice to any affected person, not only breaches above the 1,000-person threshold.
  • Do not assume an identifier extracted from a public recording is exempt as biometric data. North Carolina law never defines the term, so neither an exclusion nor a carve-out for such data can be relied upon.
  • Expect a breach-notice violation to expose you to a private civil action for treble damages once an injured North Carolina resident can show injury from the violation.

When LexLint raises it

Declared activities: crawls_web, trains_models, deploys_chatbot, automated_outreach, processes_biometrics

Primary source: official North Carolina statute text, General Statutes Chapter 75, Article 2A

← Back to the example  ·  Lint your app →