{
 "jurisdiction_id": "US-NC",
 "jurisdiction": "United States – North Carolina",
 "url": "https://dataprotection.gi/jurisdictions/united-states-north-carolina/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-06",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 24,
  "sub_modules": 57,
  "source_register": 13
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "red",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-north-carolina/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "No comprehensive material or territorial scope exists; coverage is confined to breach notification and general FTC Section 5 deceptive-practices authority.",
   "claims": [
    {
     "statement": "The North Carolina Attorney General, currently Jeff Jackson, leads the North Carolina Department of Justice which enforces consumer-protection and data-breach law in the state.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "NAAG",
     "source_url": "https://www.naag.org/attorney-general/jeff-jackson/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "North Carolina's data-breach notification law was enacted as Senate Bill 1048 in 2005 and has been codified as N.C. Gen. Stat. §§ 75-61, 75-65.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/changes-on-the-horizon-for-north-carolinas-data-breach-notification-law",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Section 5 of the FTC Act provides a general federal unfair/deceptive-practices privacy enforcement baseline applicable nationally, including North Carolina, in the absence of state-level comprehensive privacy legislation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "FTC",
     "source_url": "https://www.ftc.gov/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "North Carolina's breach statute defines a breach narrowly as unauthorized acquisition or access to unredacted or unencrypted records containing personal information that could create a material risk of harm, rather than governing personal-data processing generally.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/changes-on-the-horizon-for-north-carolinas-data-breach-notification-law",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "North Carolina's breach-notification statute is generally understood to apply to any entity that owns, licenses, or maintains personal information of North Carolina residents regardless of the entity's location, consistent with the typical structure of US state breach statutes, though the precise extraterritorial text was not independently verified against primary statute text in this run.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "OPC Canada",
     "source_url": "https://www.priv.gc.ca/en/opc-actions-and-decisions/advice-to-parliament/2007/sub_070222_06/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "A 2009 amendment to North Carolina's breach law introduced a requirement that businesses notify the Attorney General whenever North Carolina residents are notified of a breach, removing the prior 1,000-person notification threshold.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/changes-on-the-horizon-for-north-carolinas-data-breach-notification-law",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "red",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-north-carolina/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "No omnibus lawful-basis or special-category framework exists at the state level; coverage is fragmented and sectoral only.",
   "claims": [
    {
     "statement": "North Carolina has no general statutory lawful-basis framework for processing personal data comparable to GDPR Article 6; where lawful processing standards exist, they derive from sector-specific federal requirements rather than a state omnibus regime.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/resources/article/us-state-privacy-legislation-tracker",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "North Carolina's breach statute's definition of 'personal information' centers on identity-theft/financial-fraud building blocks (name plus SSN, driver's license, financial account numbers) rather than the broader special-category taxonomy (health, biometric, genetic, political, sexual) found in comprehensive regimes.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/iapp-updates-its-us-state-breach-notice-resource",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "North Carolina's breach law provides that notification is still required for encrypted personal information if the encryption keys were also compromised, functioning as a limited encryption-based safe harbour rather than a formal anonymisation/pseudonymisation regime.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "OPC Canada",
     "source_url": "https://www.priv.gc.ca/en/opc-actions-and-decisions/advice-to-parliament/2007/sub_070222_06/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "red",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-north-carolina/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "No comprehensive data-subject-rights regime exists; rights are limited to breach notice and credit-freeze mechanics plus disparate sectoral rights.",
   "claims": [
    {
     "statement": "North Carolina's Identity Theft Protection Act does not confer a general right of access to personal data held by private-sector businesses; it affords only credit-freeze rights and breach-notice mechanics.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/changes-on-the-horizon-for-north-carolinas-data-breach-notification-law",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "North Carolina's breach law requires businesses to provide notice of a security breach to affected persons following discovery or notification of the breach without unreasonable delay.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/changes-on-the-horizon-for-north-carolinas-data-breach-notification-law",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "A 2018 legislative proposal discussed by the NC Attorney General and a state representative would have replaced the 'unreasonable delay' standard with a specific 15-day notification deadline to consumers and the Attorney General, but this proposal's enactment status was not confirmed.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Speculative",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/changes-on-the-horizon-for-north-carolinas-data-breach-notification-law",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-north-carolina/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Breach notification and a basic security/destruction duty are in force; DPIA/DPO/ROPA/joint-controller concepts are entirely absent.",
   "claims": [
    {
     "statement": "North Carolina's Identity Theft Protection Act requires businesses to take reasonable measures to protect against unauthorized access to or use of consumers' personal information, using methods to secure sensitive data such as Social Security numbers.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/changes-on-the-horizon-for-north-carolinas-data-breach-notification-law",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Following a 2009 amendment, North Carolina businesses must notify the Attorney General whenever North Carolina residents are notified of a breach, with no minimum affected-person threshold.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/changes-on-the-horizon-for-north-carolinas-data-breach-notification-law",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "North Carolina General Statutes Chapter 75, Article 2A, Section 75-64 addresses the destruction of personal-information records, indicating a statutory disposal obligation distinct from a comprehensive retention-limitation regime.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/legal-research/north-carolina-general-statutes-chapter-75",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "red",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-north-carolina/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "No sub-federal transfer regime exists; cross-border data flows involving NC residents are governed only by federal sectoral law (e.g., GLBA, HIPAA) and by whatever national-level EU-US adequacy/transfer framework applies to the United States as a whole.",
   "claims": []
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-north-carolina/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Sectoral federal overlays are confirmed in force; state-level insurance-specific adoption status of NAIC model law is unconfirmed.",
   "claims": [
    {
     "statement": "Insurance companies and agents, including those operating in North Carolina, are subject to the Gramm-Leach-Bliley Act's affirmative and continuing obligation to respect customer privacy and protect the security and confidentiality of non-public personal information.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/new-cybersecurity-regulatory-guidance-for-the-insurance-industry",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "NAIC model laws and regulations, including the Insurance Data Security Model Law, are not directly binding on the insurance industry until adopted in whole or part by individual state legislators or regulators, meaning North Carolina's specific obligations depend on independent state adoption not confirmed in this run.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/new-cybersecurity-regulatory-guidance-for-the-insurance-industry",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "red",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-north-carolina/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "No adtech-specific statutory regime exists in North Carolina; only general FTC Section 5 deceptive-practices enforcement applies.",
   "claims": [
    {
     "statement": "In the absence of a North Carolina-specific dark-pattern prohibition, deceptive interface design practices affecting NC consumers are reachable only through the FTC's general Section 5 unfair/deceptive-practices authority.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "FTC",
     "source_url": "https://www.ftc.gov/",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "red",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-north-carolina/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "No state or targeted federal algorithmic/biometric statute applies to NC; only the FTC's general Section 5 biometric policy statement provides a partial federal analogue.",
   "claims": [
    {
     "statement": "There is currently no federal biometric privacy act or facial recognition technology act; the FTC instead relies on Section 5 of the FTC Act, applying it to biometric information technologies through a dedicated Commission Policy Statement, which explicitly does not preempt state or local biometric laws.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "FTC",
     "source_url": "https://www.ftc.gov/system/files/ftc_gov/pdf/p225402biometricpolicystatement.pdf",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-north-carolina/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Federal COPPA applies uniformly; state-specific minors'-data legislation status is unconfirmed/likely not enacted.",
   "claims": [
    {
     "statement": "The FTC issued an Enforcement Policy Statement Promoting the Adoption of Age-Verification Technology, operating at the federal level and applicable to businesses serving North Carolina consumers in the absence of a state-specific age-verification statute.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "FTC",
     "source_url": "https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-north-carolina/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Regulator enforcement channels (state AG + FTC) are active and historically demonstrated via multistate settlements; no confirmed private right of action or NC-specific penalty cap was found.",
   "claims": [
    {
     "statement": "In 2017, North Carolina received $390,814 as part of an $18 million nationwide settlement with Target arising from its 2013 data breach.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/changes-on-the-horizon-for-north-carolinas-data-breach-notification-law",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "In late 2018, North Carolina received $3,661,800.27 as part of a nationwide $148 million settlement with Uber over a data breach, with Uber also agreeing to implement improved data-security practices.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/changes-on-the-horizon-for-north-carolinas-data-breach-notification-law",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "Some but not all US state breach-notification statutes provide a private right of action for noncompliance, while others rely solely on state attorney general enforcement; North Carolina's specific status on this point was not independently confirmed against primary statute text in this run.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/resources/article/state-data-breach-notification-chart",
     "source_tier": null,
     "observed_at": "2026-08-06"
    },
    {
     "statement": "As of early 2026, four new comprehensive state privacy laws had been enacted in the US generally, but this activity did not include a new North Carolina enactment, consistent with North Carolina's continued absence from the roster of states with comprehensive privacy statutes.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/emerging-trends-insights-from-public-enforcement-of-us-state-privacy-laws",
     "source_tier": null,
     "observed_at": "2026-08-06"
    }
   ]
  }
 ]
}