🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
US-NC · run data-protection-2026-08-06 v13-gdpri-1.0.0
content: ai_generated 13 sources retrieved model claude-sonnet-5 ·

United States – North Carolina

US-NC schema gdpri-v2 trajectory: not recordedregulated (sectoral)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 24 claims · 13 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
24Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

No comprehensive material or territorial scope exists; coverage is confined to breach notification and general FTC Section 5 deceptive-practices authority.

Primary frameworkN.C. Gen. Stat. §§ 75-60 to 75-65 (Identity Theft Protection Act) + FTC Act Section 5 (federal baseline)
Traffic-light rationale — RedNo comprehensive material or territorial scope exists; coverage is confined to breach notification and general FTC Section 5 deceptive-practices authority.

Sub-modules (5)

Regulator And AuthorityAmber

The NC Attorney General's Office enforces the state's breach-notification statute and general consumer-protection law; the FTC provides the concurrent federal backstop under Section 5.

Claims (1):

  • The North Carolina Attorney General, currently Jeff Jackson, leads the North Carolina Department of Justice which enforces consumer-protection and data-breach law in the state.

Act And InstrumentsAmber

Primary instrument is the Identity Theft Protection Act (N.C. Gen. Stat. §§ 75-61, 75-65), supplemented by FTC Act Section 5 at the federal level.

Claims (2):

  • North Carolina's data-breach notification law was enacted as Senate Bill 1048 in 2005 and has been codified as N.C. Gen. Stat. §§ 75-61, 75-65.
  • Section 5 of the FTC Act provides a general federal unfair/deceptive-practices privacy enforcement baseline applicable nationally, including North Carolina, in the absence of state-level comprehensive privacy legislation.

Material ScopeRed

No omnibus material scope; the statute governs only breach notification for a narrowly defined category of 'personal information' tied to identity-theft risk.

Claims (1):

  • North Carolina's breach statute defines a breach narrowly as unauthorized acquisition or access to unredacted or unencrypted records containing personal information that could create a material risk of harm, rather than governing personal-data processing generally.

Territorial ScopeAmber

No confirmed extraterritorial-application language specific to NC's statute was independently verified in primary text; treated as Probable pending direct statute review.

Claims (1):

  • North Carolina's breach-notification statute is generally understood to apply to any entity that owns, licenses, or maintains personal information of North Carolina residents regardless of the entity's location, consistent with the typical structure of US state breach statutes, though the precise extraterritorial text was not independently verified against primary statute text in this run.

Regulator Registration And FilingAmber

No general registration/filing regime for controllers exists; the only filing duty is breach notification to the NC AG's Consumer Protection Division, required since a 2009 amendment removed the prior 1,000-person threshold.

Claims (1):

  • A 2009 amendment to North Carolina's breach law introduced a requirement that businesses notify the Attorney General whenever North Carolina residents are notified of a breach, removing the prior 1,000-person notification threshold.
Category narrative80 words

North Carolina has no dedicated data-protection authority and no comprehensive consumer-privacy statute. The state operates within the US federal sectoral patchwork: the FTC enforces general unfair/deceptive-practices privacy standards under Section 5 of the FTC Act, and the NC Attorney General (currently Jeff Jackson) enforces the state's narrow Identity Theft Protection Act (N.C. Gen. Stat. §§ 75-60 et seq., codifying breach-notification duties from 2005 Senate Bill 1048, amended 2009). Material and territorial scope are both narrow and breach-notification-specific rather than omnibus.

Sources and claims (6)
  1. ConfirmedNAAGThe North Carolina Attorney General, currently Jeff Jackson, leads the North Carolina Department of Justice which enforces consumer-protection and data-breach law in the state.observed
  2. ConfirmedIAPPNorth Carolina's data-breach notification law was enacted as Senate Bill 1048 in 2005 and has been codified as N.C. Gen. Stat. §§ 75-61, 75-65.observed
  3. ConfirmedFTCSection 5 of the FTC Act provides a general federal unfair/deceptive-practices privacy enforcement baseline applicable nationally, including North Carolina, in the absence of state-level comprehensive privacy legislation.observed
  4. ConfirmedIAPPNorth Carolina's breach statute defines a breach narrowly as unauthorized acquisition or access to unredacted or unencrypted records containing personal information that could create a material risk of harm, rather than governing personal-data processing generally.observed
  5. UncertainOPC CanadaNorth Carolina's breach-notification statute is generally understood to apply to any entity that owns, licenses, or maintains personal information of North Carolina residents regardless of the entity's location, consistent with the typical structure of US state breach statutes, though the precise extraterritorial text was not independently verified against primary statute text in this run.observed
  6. ConfirmedIAPPA 2009 amendment to North Carolina's breach law introduced a requirement that businesses notify the Attorney General whenever North Carolina residents are notified of a breach, removing the prior 1,000-person notification threshold.observed

#

No omnibus lawful-basis or special-category framework exists at the state level; coverage is fragmented and sectoral only.

Traffic-light rationale — RedNo omnibus lawful-basis or special-category framework exists at the state level; coverage is fragmented and sectoral only.

Sub-modules (4)

Lawful BasesRed

No NC statutory lawful-basis enumeration exists; processing legality for private-sector data is governed by contract, sectoral consent regimes, and general tort/consumer-protection law only.

Claims (1):

  • North Carolina has no general statutory lawful-basis framework for processing personal data comparable to GDPR Article 6; where lawful processing standards exist, they derive from sector-specific federal requirements rather than a state omnibus regime.

Special CategoriesAmber

The Identity Theft Protection Act's 'personal information' definition is narrower than a GDPR/CCPA-style special-category taxonomy; broader sensitive-category protection (health, genetic, biometric) is addressed only via federal sectoral law.

Claims (1):

  • North Carolina's breach statute's definition of 'personal information' centers on identity-theft/financial-fraud building blocks (name plus SSN, driver's license, financial account numbers) rather than the broader special-category taxonomy (health, biometric, genetic, political, sexual) found in comprehensive regimes.

Pseudonymisation And AnonymisationAmber

No statutory anonymisation/pseudonymisation safe harbour exists; the closest functional analogue is the breach law's encryption exemption.

Claims (1):

  • North Carolina's breach law provides that notification is still required for encrypted personal information if the encryption keys were also compromised, functioning as a limited encryption-based safe harbour rather than a formal anonymisation/pseudonymisation regime.
Category narrative51 words

North Carolina has no general lawful-basis, consent-standard, or special-category regime akin to GDPR Art. 6/9. Sensitive-data protections and consent requirements exist only through federal sectoral overlays (HIPAA authorization, GLBA opt-out, COPPA verifiable parental consent, GINA for genetic data) and through the narrow 'personal information' definition used in the state's breach-notification statute.

Sources and claims (3)
  1. ConfirmedIAPPNorth Carolina has no general statutory lawful-basis framework for processing personal data comparable to GDPR Article 6; where lawful processing standards exist, they derive from sector-specific federal requirements rather than a state omnibus regime.observed
  2. ConfirmedIAPPNorth Carolina's breach statute's definition of 'personal information' centers on identity-theft/financial-fraud building blocks (name plus SSN, driver's license, financial account numbers) rather than the broader special-category taxonomy (health, biometric, genetic, political, sexual) found in comprehensive regimes.observed
  3. ProbableOPC CanadaNorth Carolina's breach law provides that notification is still required for encrypted personal information if the encryption keys were also compromised, functioning as a limited encryption-based safe harbour rather than a formal anonymisation/pseudonymisation regime.observed

#

No comprehensive data-subject-rights regime exists; rights are limited to breach notice and credit-freeze mechanics plus disparate sectoral rights.

Traffic-light rationale — RedNo comprehensive data-subject-rights regime exists; rights are limited to breach notice and credit-freeze mechanics plus disparate sectoral rights.

Sub-modules (5)

Access RightRed

No general right of access to personal data held by private businesses exists under NC law; the ITPA affords only breach notice and credit-freeze rights.

Claims (1):

  • North Carolina's Identity Theft Protection Act does not confer a general right of access to personal data held by private-sector businesses; it affords only credit-freeze rights and breach-notice mechanics.

Rectification And ErasureRed

No statutory right to rectification or erasure of personal data by private controllers was found in North Carolina law.

Absence provenance: not recorded. Searched: N.C. Gen. Stat. Chapter 75 Article 2A, IAPP US State Privacy Legislation Tracker (NC absent from 19 comprehensive states).

Restriction And ObjectionRed

No statutory right to restrict processing or object to profiling exists under North Carolina law for private-sector data controllers.

Absence provenance: not recorded. Searched: IAPP US State Privacy Legislation Tracker, dataguidance NC jurisdiction page.

Data PortabilityRed

No statutory data-portability right exists under North Carolina law.

Absence provenance: not recorded. Searched: IAPP US State Privacy Legislation Tracker, dataguidance NC jurisdiction page.

Deadlines And Response WindowsAmber

The in-force standard requires notice 'without unreasonable delay' after discovery of a breach; a specific 15-day notification deadline was discussed in 2018 legislative reform proposals but was not confirmed as enacted.

Claims (2):

  • North Carolina's breach law requires businesses to provide notice of a security breach to affected persons following discovery or notification of the breach without unreasonable delay.
  • A 2018 legislative proposal discussed by the NC Attorney General and a state representative would have replaced the 'unreasonable delay' standard with a specific 15-day notification deadline to consumers and the Attorney General, but this proposal's enactment status was not confirmed.
Category narrative52 words

North Carolina confers no general subject-access, rectification, erasure, restriction/objection, or portability rights on individuals vis-à-vis private-sector data controllers. The Identity Theft Protection Act's individual-facing rights are limited to breach notification and security-freeze mechanics. Broader rights exist only through sectoral overlays (e.g., HIPAA access right for medical records, FCRA access to credit files).

Sources and claims (3)
  1. ConfirmedIAPPNorth Carolina's Identity Theft Protection Act does not confer a general right of access to personal data held by private-sector businesses; it affords only credit-freeze rights and breach-notice mechanics.observed
  2. ConfirmedIAPPNorth Carolina's breach law requires businesses to provide notice of a security breach to affected persons following discovery or notification of the breach without unreasonable delay.observed
  3. SpeculativeIAPPA 2018 legislative proposal discussed by the NC Attorney General and a state representative would have replaced the 'unreasonable delay' standard with a specific 15-day notification deadline to consumers and the Attorney General, but this proposal's enactment status was not confirmed.observed

#

Breach notification and a basic security/destruction duty are in force; DPIA/DPO/ROPA/joint-controller concepts are entirely absent.

Primary frameworkN.C. Gen. Stat. §§ 75-61 to 75-65
Traffic-light rationale — AmberBreach notification and a basic security/destruction duty are in force; DPIA/DPO/ROPA/joint-controller concepts are entirely absent.

Sub-modules (7)

Accountability And DpiaRed

No DPIA or general accountability-principle requirement exists in North Carolina law.

Absence provenance: not recorded. Searched: IAPP US State Privacy Legislation Tracker, dataguidance NC jurisdiction page.

Dpo RequirementsRed

No DPO appointment requirement exists under North Carolina law.

Absence provenance: not recorded. Searched: IAPP US State Privacy Legislation Tracker.

Ropa RequirementsRed

No records-of-processing-activities obligation exists under North Carolina law.

Absence provenance: not recorded. Searched: IAPP US State Privacy Legislation Tracker.

Joint Controller ArrangementsRed

No joint-controller framework exists at the state level; contractual data-sharing obligations arise only under sectoral federal law (e.g., GLBA service-provider contracts).

Absence provenance: not recorded. Searched: GLBA service-provider contract requirements, IAPP US State Privacy Legislation Tracker.

Security MeasuresAmber

Businesses must take reasonable measures to protect against unauthorized access to or use of consumers' personal information, including methods to secure sensitive information such as Social Security numbers.

Claims (1):

  • North Carolina's Identity Theft Protection Act requires businesses to take reasonable measures to protect against unauthorized access to or use of consumers' personal information, using methods to secure sensitive data such as Social Security numbers.

Breach NotificationAmber

Breach notification to affected NC residents and to the Attorney General's Consumer Protection Division is required without unreasonable delay following discovery, with no numerical person-count threshold since the 2009 amendment.

Claims (1):

  • Following a 2009 amendment, North Carolina businesses must notify the Attorney General whenever North Carolina residents are notified of a breach, with no minimum affected-person threshold.

Retention And DisposalAmber

N.C. Gen. Stat. § 75-64 addresses destruction of personal-information records, suggesting a disposal duty, though the substantive text was not independently retrieved in this run.

Claims (1):

  • North Carolina General Statutes Chapter 75, Article 2A, Section 75-64 addresses the destruction of personal-information records, indicating a statutory disposal obligation distinct from a comprehensive retention-limitation regime.
Category narrative50 words

North Carolina imposes no DPIA, DPO, ROPA, or joint-controller framework. Security-of-processing and breach-notification duties exist under the Identity Theft Protection Act, including a data-destruction obligation (N.C. Gen. Stat. § 75-64) for records no longer needed; these operate as narrow analogues to GDPR Art. 25/32-34 rather than a full accountability regime.

Sources and claims (3)
  1. ConfirmedIAPPNorth Carolina's Identity Theft Protection Act requires businesses to take reasonable measures to protect against unauthorized access to or use of consumers' personal information, using methods to secure sensitive data such as Social Security numbers.observed
  2. ConfirmedIAPPFollowing a 2009 amendment, North Carolina businesses must notify the Attorney General whenever North Carolina residents are notified of a breach, with no minimum affected-person threshold.observed
  3. ProbableDataGuidanceNorth Carolina General Statutes Chapter 75, Article 2A, Section 75-64 addresses the destruction of personal-information records, indicating a statutory disposal obligation distinct from a comprehensive retention-limitation regime.observed

#

No sub-federal transfer regime exists; cross-border data flows involving NC residents are governed only by federal sectoral law (e.g., GLBA, HIPAA) and by whatever national-level EU-US adequacy/transfer framework applies to the United States as a whole.

Traffic-light rationale — RedNo sub-federal transfer regime exists; cross-border data flows involving NC residents are governed only by federal sectoral law (e.g., GLBA, HIPAA) and by whatever national-level EU-US adequacy/transfer framework applies to the United States as a whole.

Sub-modules (6)

Transfer MechanismsRed

No NC-specific transfer mechanism exists; cross-border transfers are governed at the federal sectoral level only.

Absence provenance: not recorded. Searched: NC General Statutes Chapter 75, IAPP US State Privacy Legislation Tracker.

Adequacy ReceivedRed

Adequacy is assessed by the EU at the national US level, not toward individual US states; no NC-specific adequacy determination exists or is applicable.

Absence provenance: not recorded. Searched: European Commission adequacy decisions list.

Adequacy GrantedRed

North Carolina does not independently grant adequacy status to foreign jurisdictions; this is not a sub-federal function under US law.

Absence provenance: not recorded. Searched: NC Department of Justice guidance on international transfers.

Sccs And BcrsRed

No NC-specific SCC/BCR uptake requirement exists.

Absence provenance: not recorded. Searched: NC General Statutes Chapter 75.

Transfer Impact AssessmentRed

No NC-specific transfer-impact-assessment requirement exists.

Absence provenance: not recorded. Searched: IAPP US State Privacy Legislation Tracker.

Data LocalisationRed

No NC data-localisation mandate was identified.

Absence provenance: not recorded. Searched: NC General Statutes Chapter 75, dataguidance NC jurisdiction page.

Category narrative40 words

North Carolina has no state-level cross-border transfer mechanism, adequacy-determination, SCC/BCR regime, transfer-impact-assessment requirement, or data-localisation mandate. Adequacy determinations under GDPR Art. 45 operate at the national (US) level, not sub-federally, and no independent NC-level adequacy or transfer regime was found.

#

Sectoral federal overlays are confirmed in force; state-level insurance-specific adoption status of NAIC model law is unconfirmed.

Primary frameworkGLBA / HIPAA / COPPA / FCRA (federal sectoral overlays)
Supervisory authorityFederal Trade Commission
Traffic-light rationale — AmberSectoral federal overlays are confirmed in force; state-level insurance-specific adoption status of NAIC model law is unconfirmed.

Sub-modules (7)

Financial Sector OverlayAmber

Insurance companies and agents operating in North Carolina are subject to GLBA's affirmative and continuing obligation to protect the security and confidentiality of customers' non-public personal information; NAIC model laws/principles are persuasive but not directly binding absent state adoption.

Claims (1):

  • Insurance companies and agents, including those operating in North Carolina, are subject to the Gramm-Leach-Bliley Act's affirmative and continuing obligation to respect customer privacy and protect the security and confidentiality of non-public personal information.

Health Sector OverlayAmber

Health data in North Carolina is governed by federal HIPAA rather than a state-specific health-privacy statute.

Absence provenance: not recorded. Searched: NC health information privacy statute search.

Telecoms And EprivacyRed

No NC-specific ePrivacy/telecoms data statute equivalent to EU ePrivacy was identified; federal telecoms/robocall rules apply nationally.

Absence provenance: not recorded. Searched: NC telecoms privacy statute search.

Employment DataRed

No NC-specific employment-data-privacy statute was identified.

Absence provenance: not recorded. Searched: NC employment data privacy statute search.

Credit And ScoringAmber

Credit-reporting and scoring practices affecting NC residents are governed by the federal Fair Credit Reporting Act rather than a state-specific credit-scoring statute.

Absence provenance: not recorded. Searched: NC credit scoring statute search.

EducationRed

No NC-specific comprehensive student-data-privacy statute distinct from federal FERPA/COPPA protections was confirmed in this run.

Absence provenance: not recorded. Searched: North Carolina student data privacy statute 2023 minors' data bill status.

InsuranceAmber

Insurance data practices are shaped by NAIC model laws (Insurance Information and Privacy Protection Model Act; Insurance Data Security Model Law), which require state-by-state adoption; North Carolina's specific adoption status for the Insurance Data Security Model Law was not confirmed in this run.

Claims (1):

  • NAIC model laws and regulations, including the Insurance Data Security Model Law, are not directly binding on the insurance industry until adopted in whole or part by individual state legislators or regulators, meaning North Carolina's specific obligations depend on independent state adoption not confirmed in this run.
Category narrative73 words

North Carolina relies entirely on federal sectoral overlays for financial, health, telecoms, employment, credit, education, and insurance data: GLBA for financial institutions, HIPAA for health data, COPPA for children's online data, and FCRA for credit reporting. Insurance-sector data practices are shaped by NAIC model laws/guidance, which are not directly binding absent state adoption; no confirmation of North Carolina's formal adoption of the NAIC Insurance Data Security Model Law was obtained in this run.

Sources and claims (2)
  1. ConfirmedIAPPInsurance companies and agents, including those operating in North Carolina, are subject to the Gramm-Leach-Bliley Act's affirmative and continuing obligation to respect customer privacy and protect the security and confidentiality of non-public personal information.observed
  2. ProbableIAPPNAIC model laws and regulations, including the Insurance Data Security Model Law, are not directly binding on the insurance industry until adopted in whole or part by individual state legislators or regulators, meaning North Carolina's specific obligations depend on independent state adoption not confirmed in this run.observed

#

No adtech-specific statutory regime exists in North Carolina; only general FTC Section 5 deceptive-practices enforcement applies.

Primary frameworkFTC Act Section 5 (federal baseline only)
Supervisory authorityFederal Trade Commission
Traffic-light rationale — RedNo adtech-specific statutory regime exists in North Carolina; only general FTC Section 5 deceptive-practices enforcement applies.

Sub-modules (6)

Cookies And TrackersRed

No NC cookie/tracker consent statute exists.

Absence provenance: not recorded. Searched: NC cookie consent law search, IAPP US State Privacy Legislation Tracker.

Dark PatternsRed

No NC dark-pattern prohibition statute exists; dark patterns may be reachable only via FTC Section 5 deceptive-practices enforcement.

Claims (1):

  • In the absence of a North Carolina-specific dark-pattern prohibition, deceptive interface design practices affecting NC consumers are reachable only through the FTC's general Section 5 unfair/deceptive-practices authority.

Opt Out SignalsRed

No NC statutory recognition of opt-out signals (e.g., Global Privacy Control) exists.

Absence provenance: not recorded. Searched: NC opt-out signal statute search.

Clean Rooms And DcrRed

No NC-specific clean-room/data-collaboration-room regulation exists.

Absence provenance: not recorded. Searched: NC data clean room regulation search.

Cross Context AdvertisingRed

No NC statutory 'sale'/'share' cross-context-advertising regime exists.

Absence provenance: not recorded. Searched: NC cross-context advertising statute search.

Direct MarketingRed

No NC-specific direct-marketing consent/suppression statute beyond general federal telemarketing rules (e.g., TCPA/TSR) was identified.

Absence provenance: not recorded. Searched: NC direct marketing consent statute search.

Category narrative41 words

North Carolina has no cookie/tracker consent law, dark-pattern prohibition, opt-out-signal recognition mandate, clean-room regulation, cross-context-advertising 'sale/share' regime, or direct-marketing-specific consent statute comparable to comprehensive state privacy laws (e.g., CCPA/CPRA). Commercial data practices are governed only by FTC Section 5 deceptive-practices enforcement.

Sources and claims (1)
  1. ProbableFTCIn the absence of a North Carolina-specific dark-pattern prohibition, deceptive interface design practices affecting NC consumers are reachable only through the FTC's general Section 5 unfair/deceptive-practices authority.observed

#

No state or targeted federal algorithmic/biometric statute applies to NC; only the FTC's general Section 5 biometric policy statement provides a partial federal analogue.

Primary frameworkFTC Section 5 Biometric Information Policy Statement (federal, non-binding guidance)
Supervisory authorityFederal Trade Commission
Traffic-light rationale — RedNo state or targeted federal algorithmic/biometric statute applies to NC; only the FTC's general Section 5 biometric policy statement provides a partial federal analogue.

Sub-modules (6)

Profiling RestrictionsRed

No NC or targeted federal profiling-restriction statute analogous to GDPR Art. 22 exists.

Absence provenance: not recorded. Searched: NC profiling restriction statute search.

Automated Decision Making TransparencyRed

No NC ADM-transparency statute exists.

Absence provenance: not recorded. Searched: NC automated decision-making transparency statute search.

Ai Risk AssessmentsRed

No NC AI-risk-assessment statute exists.

Absence provenance: not recorded. Searched: NC AI risk assessment statute search.

Biometric RegimeAmber

No federal biometric privacy act or facial-recognition-technology act exists; the FTC instead applies Section 5 to biometric-information practices through a dedicated policy statement covering facial, iris/retina, finger/handprint, voice, genetic, and gait/movement data, without preempting state or local biometric laws (none of which was found specific to North Carolina).

Claims (1):

  • There is currently no federal biometric privacy act or facial recognition technology act; the FTC instead relies on Section 5 of the FTC Act, applying it to biometric information technologies through a dedicated Commission Policy Statement, which explicitly does not preempt state or local biometric laws.

Genetic DataRed

No NC-specific genetic-data-privacy statute was identified; genetic data is treated as biometric information under the FTC's policy statement and is otherwise governed by federal GINA protections in specific employment/insurance contexts.

Absence provenance: not recorded. Searched: NC genetic privacy statute search.

State Surveillance CarveoutsRed

No NC-specific state-surveillance carve-out statute was identified; national-security exemptions operate at the federal level only.

Absence provenance: not recorded. Searched: NC state surveillance carve-out statute search.

Category narrative48 words

North Carolina has no state profiling-restriction, ADM-transparency, AI-risk-assessment, biometric-specific, or genetic-data-specific statute. At the federal level, no comprehensive biometric privacy act exists; the FTC instead applies Section 5 to biometric-information practices via a dedicated policy statement. National-security surveillance carve-outs are addressed only at the federal level (not state-specific).

Sources and claims (1)
  1. ConfirmedFTCThere is currently no federal biometric privacy act or facial recognition technology act; the FTC instead relies on Section 5 of the FTC Act, applying it to biometric information technologies through a dedicated Commission Policy Statement, which explicitly does not preempt state or local biometric laws.observed

#

Federal COPPA applies uniformly; state-specific minors'-data legislation status is unconfirmed/likely not enacted.

Primary frameworkCOPPA (federal)
Supervisory authorityFederal Trade Commission
Traffic-light rationale — AmberFederal COPPA applies uniformly; state-specific minors'-data legislation status is unconfirmed/likely not enacted.

Sub-modules (5)

Age VerificationAmber

No NC-specific age-verification statute was confirmed; the FTC has issued an enforcement policy statement promoting adoption of age-verification technology at the federal level.

Claims (1):

  • The FTC issued an Enforcement Policy Statement Promoting the Adoption of Age-Verification Technology, operating at the federal level and applicable to businesses serving North Carolina consumers in the absence of a state-specific age-verification statute.

Minor Profiling BansRed

No NC-specific minor-profiling ban was identified.

Absence provenance: not recorded. Searched: NC minor profiling ban statute search.

Education SettingsRed

No NC-specific education-settings data-privacy statute distinct from federal FERPA was confirmed.

Absence provenance: not recorded. Searched: NC student data privacy statute search.

Dependent AdultsRed

No NC-specific dependent-adults data-privacy statute was identified.

Absence provenance: not recorded. Searched: NC dependent adults data privacy statute search.

Category narrative54 words

North Carolina relies on the federal Children's Online Privacy Protection Act (COPPA) for age-of-consent and parental-consent mechanics; no NC-specific age-verification, minor-profiling-ban, education-settings, or dependent-adults data-privacy statute distinct from federal law was confirmed in this run. A 2023 NC bill addressing use of minors' data was identified but its enactment status could not be confirmed.

Sources and claims (1)
  1. ConfirmedFTCThe FTC issued an Enforcement Policy Statement Promoting the Adoption of Age-Verification Technology, operating at the federal level and applicable to businesses serving North Carolina consumers in the absence of a state-specific age-verification statute.observed

#

Regulator enforcement channels (state AG + FTC) are active and historically demonstrated via multistate settlements; no confirmed private right of action or NC-specific penalty cap was found.

Primary frameworkN.C. Gen. Stat. §§ 75-61 to 75-65 + FTC Act Section 5
Traffic-light rationale — AmberRegulator enforcement channels (state AG + FTC) are active and historically demonstrated via multistate settlements; no confirmed private right of action or NC-specific penalty cap was found.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

The NC AG enforces the breach statute and general consumer-protection law; specific statutory maximum-penalty figures for the ITPA were not independently retrieved in this run.

Absence provenance: not recorded. Searched: N.C. Gen. Stat. § 75-65 penalty provisions primary text.

Enforcement Activity IndexAmber

Historical multistate settlements involving North Carolina include the Target 2013 breach settlement, a 2017 Nationwide Insurance settlement, and a 2018 Uber breach settlement; no NC-specific enforcement action from the last 12 months was independently confirmed in this run.

Claims (2):

  • In 2017, North Carolina received $390,814 as part of an $18 million nationwide settlement with Target arising from its 2013 data breach.
  • In late 2018, North Carolina received $3,661,800.27 as part of a nationwide $148 million settlement with Uber over a data breach, with Uber also agreeing to implement improved data-security practices.

Regulator Funding And CapacityAmber

No specific funding/headcount data for the NC AG's Consumer Protection Division was retrieved in this run.

Absence provenance: not recorded. Searched: NC Department of Justice budget consumer protection division staffing.

Collective Redress And Class ActionsAmber

No NC-specific statutory collective-redress mechanism beyond ordinary state class-action procedure was identified for data-privacy claims.

Absence provenance: not recorded. Searched: NC class action data breach statute search.

Private Right Of ActionAmber

It was not confirmed in this run whether North Carolina's breach statute affords consumers a private right of action; some US state breach statutes do, others rely solely on AG enforcement.

Claims (1):

  • Some but not all US state breach-notification statutes provide a private right of action for noncompliance, while others rely solely on state attorney general enforcement; North Carolina's specific status on this point was not independently confirmed against primary statute text in this run.

Recent Developments 180DAmber

No North Carolina-specific comprehensive privacy legislation, new breach-law amendment, or adequacy-relevant development was confirmed within the last 180 days as of this run's dispatch date (2026-08-06); broader US state privacy activity in 2026 continued but did not include a new North Carolina enactment.

Claims (1):

  • As of early 2026, four new comprehensive state privacy laws had been enacted in the US generally, but this activity did not include a new North Carolina enactment, consistent with North Carolina's continued absence from the roster of states with comprehensive privacy statutes.
Category narrative67 words

Enforcement in North Carolina is bifurcated between the state Attorney General (breach-notification and general consumer-protection actions) and the FTC (Section 5 deceptive-practices actions). North Carolina has participated in multiple multistate breach settlements (e.g., Target, Uber, Nationwide Insurance) historically. No private right of action was confirmed under the NC breach statute in this run; enforcement is regulator-driven. No NC-specific collective-redress mechanism beyond standard state class-action procedure was identified.

Sources and claims (4)
  1. ConfirmedIAPPIn 2017, North Carolina received $390,814 as part of an $18 million nationwide settlement with Target arising from its 2013 data breach.observed
  2. ConfirmedIAPPIn late 2018, North Carolina received $3,661,800.27 as part of a nationwide $148 million settlement with Uber over a data breach, with Uber also agreeing to implement improved data-security practices.observed
  3. UncertainIAPPSome but not all US state breach-notification statutes provide a private right of action for noncompliance, while others rely solely on state attorney general enforcement; North Carolina's specific status on this point was not independently confirmed against primary statute text in this run.observed
  4. ProbableIAPPAs of early 2026, four new comprehensive state privacy laws had been enacted in the US generally, but this activity did not include a new North Carolina enactment, consistent with North Carolina's continued absence from the roster of states with comprehensive privacy statutes.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United States – North Carolina
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 24 claim(s), 13 source(s) in the cumulative register.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (37 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

Regulator identity, breach-notification statute framework (N.C. Gen. Stat. §§ 75-61 to 75-65), and FTC federal baseline are T2/T1-sourced with Confirmed confidence. Lawful-basis, DSR, DPIA/DPO/ROPA, cross-border, adtech, and algorithmic/biometric modules rely predominantly on absent_field_provenance (T3 tracker confirmation of non-comprehensive status) rather than direct T1 primary-statute retrieval, since no comprehensive NC statute exists to retrieve. Insurance NAIC-adoption status and the NC breach statute's private-right-of-action and exact penalty provisions were not independently verified against primary statute text (N.C. Gen. Stat. Ch. 75, Art. 2A) in this run and rely on T2/T3 secondary sources.

Unresolved questions (5):

  • Does N.C. Gen. Stat. § 75-65 provide a private right of action for breach-notification violations, or is enforcement exclusively via the Attorney General?
  • What is the current codified breach-notification deadline (if any specific number of days was ultimately enacted following the 2018 reform proposals), as opposed to the 'without unreasonable delay' standard?
  • Has North Carolina's Department of Insurance formally adopted the NAIC Insurance Data Security Model Law, and if so, on what effective date?
  • Did the 2023 North Carolina bill relating to use of minors' data advance or lapse, and is there any enacted NC-specific children's-data statute beyond federal COPPA?
  • What are the current statutory maximum penalties under N.C. Gen. Stat. § 75-65 for noncompliance with breach-notification duties?

Escalate to primary-source review: yes