#
No comprehensive material or territorial scope exists; coverage is confined to breach notification and general FTC Section 5 deceptive-practices authority.
Sub-modules (5)
Regulator And AuthorityAmber
The NC Attorney General's Office enforces the state's breach-notification statute and general consumer-protection law; the FTC provides the concurrent federal backstop under Section 5.
Claims (1):
- The North Carolina Attorney General, currently Jeff Jackson, leads the North Carolina Department of Justice which enforces consumer-protection and data-breach law in the state.
Act And InstrumentsAmber
Primary instrument is the Identity Theft Protection Act (N.C. Gen. Stat. §§ 75-61, 75-65), supplemented by FTC Act Section 5 at the federal level.
Claims (2):
- North Carolina's data-breach notification law was enacted as Senate Bill 1048 in 2005 and has been codified as N.C. Gen. Stat. §§ 75-61, 75-65.
- Section 5 of the FTC Act provides a general federal unfair/deceptive-practices privacy enforcement baseline applicable nationally, including North Carolina, in the absence of state-level comprehensive privacy legislation.
Material ScopeRed
No omnibus material scope; the statute governs only breach notification for a narrowly defined category of 'personal information' tied to identity-theft risk.
Claims (1):
- North Carolina's breach statute defines a breach narrowly as unauthorized acquisition or access to unredacted or unencrypted records containing personal information that could create a material risk of harm, rather than governing personal-data processing generally.
Territorial ScopeAmber
No confirmed extraterritorial-application language specific to NC's statute was independently verified in primary text; treated as Probable pending direct statute review.
Claims (1):
- North Carolina's breach-notification statute is generally understood to apply to any entity that owns, licenses, or maintains personal information of North Carolina residents regardless of the entity's location, consistent with the typical structure of US state breach statutes, though the precise extraterritorial text was not independently verified against primary statute text in this run.
Regulator Registration And FilingAmber
No general registration/filing regime for controllers exists; the only filing duty is breach notification to the NC AG's Consumer Protection Division, required since a 2009 amendment removed the prior 1,000-person threshold.
Claims (1):
- A 2009 amendment to North Carolina's breach law introduced a requirement that businesses notify the Attorney General whenever North Carolina residents are notified of a breach, removing the prior 1,000-person notification threshold.
Sources and claims (6)
- ConfirmedNAAG — The North Carolina Attorney General, currently Jeff Jackson, leads the North Carolina Department of Justice which enforces consumer-protection and data-breach law in the state.observed
- ConfirmedIAPP — North Carolina's data-breach notification law was enacted as Senate Bill 1048 in 2005 and has been codified as N.C. Gen. Stat. §§ 75-61, 75-65.observed
- ConfirmedFTC — Section 5 of the FTC Act provides a general federal unfair/deceptive-practices privacy enforcement baseline applicable nationally, including North Carolina, in the absence of state-level comprehensive privacy legislation.observed
- ConfirmedIAPP — North Carolina's breach statute defines a breach narrowly as unauthorized acquisition or access to unredacted or unencrypted records containing personal information that could create a material risk of harm, rather than governing personal-data processing generally.observed
- UncertainOPC Canada — North Carolina's breach-notification statute is generally understood to apply to any entity that owns, licenses, or maintains personal information of North Carolina residents regardless of the entity's location, consistent with the typical structure of US state breach statutes, though the precise extraterritorial text was not independently verified against primary statute text in this run.observed
- ConfirmedIAPP — A 2009 amendment to North Carolina's breach law introduced a requirement that businesses notify the Attorney General whenever North Carolina residents are notified of a breach, removing the prior 1,000-person notification threshold.observed