Law note · North Dakota
Notice of Security Breach for Personal Information
Any person that owns or licenses computerized data including personal information must disclose a breach of the security system to any affected North Dakota resident, and separately to the Attorney General for a breach exceeding 250 individuals, in the most expedient time possible and without unreasonable delay; the chapter sets no numeric consumer-notification deadline and does not itself define or limit person to a private actor.
Personal information is a name combined with a Social Security number, a driver's or nondriver identification card number, a financial account number, a date of birth, a mother's maiden name, medical or health insurance information, an employer-assigned identification number, or a digitized signature, and excludes publicly available government-records information; biometric data is not among the ten enumerated categories, and this chapter does not reach it at all.
Enforcement runs to the Attorney General, who may use all the powers and remedies of chapter 51-15, North Dakota's unlawful-practices chapter, because a violation of this chapter is deemed a violation of chapter 51-15.
Whether that deeming clause makes chapter 51-15's own private-claim provision, Sec. 51-15-09, available to an individual for a bare notification failure is unresolved: that provision arms a claim specifically against a person who acquired any moneys or property by means of the unlawful practice, language that fits a fraud that took money more naturally than a business's mere failure to notify of someone else's breach, and no North Dakota case law construing this combination was found; secondary characterizations of chapter 51-30 disagree with each other on this point, and this document does not resolve it either way.
What it asks of an app
- Disclose a breach of the security system to any affected North Dakota resident in the most expedient time possible and without unreasonable delay.
- Disclose the breach to the North Dakota Attorney General by mail or electronic mail if it exceeds 250 individuals.
- Do not rely on this statute alone to cover a breach of biometric data with no accompanying enumerated element. North Dakota's personal information definition carries no biometric category.
When LexLint raises it
Declared activities: crawls_web, trains_models, deploys_chatbot, automated_outreach
Primary source: official North Dakota statute text, North Dakota Century Code chapter 51-30