🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
US-ND · run data-protection-2026-08-06 v13-gdpri-1.0.0
content: ai_generated 13 sources retrieved model claude-sonnet-5 ·

United States – North Dakota

US-ND schema gdpri-v2 trajectory: not recordedregulated (sectoral)overlaps: FIM, WPM

Last updated · 10 categories · 22 claims · 13 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
22Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

No omnibus statute exists (would be red for comprehensive-rights coverage), but a live, actively-amended breach-notification statute plus federal FTC Section 5 baseline provide a minimum enforceable floor, so amber rather than red.

Primary frameworkN.D. Cent. Code Chapter 51-30 (Notice of Security Breach) + FTC Act Section 5 (federal baseline)
Supervisory authorityNorth Dakota Attorney General
Traffic-light rationale — AmberNo omnibus statute exists (would be red for comprehensive-rights coverage), but a live, actively-amended breach-notification statute plus federal FTC Section 5 baseline provide a minimum enforceable floor, so amber rather than red.

Sub-modules (5)

Regulator And AuthorityAmber

The North Dakota Attorney General enforces state consumer-protection and breach-notification law; there is no separate ND data-protection authority. The FTC exercises concurrent federal Section 5 authority.

Claims (1):

  • The North Dakota Attorney General is the state's primary consumer-protection enforcement authority for privacy-adjacent matters, operating under general state consumer-protection powers rather than a dedicated data-protection statute.

Act And InstrumentsRed

Primary instruments are N.D. Cent. Code Ch. 51-30 (breach notification) and federal FTC Act Section 5; no comprehensive ND privacy statute exists, and the 2019-session comprehensive bill (HB 1485) was replaced by a study task force.

Claims (2):

  • North Dakota has no comprehensive consumer-privacy statute; a 2019 comprehensive privacy bill (HB 1485) was substituted with a study task force rather than enacted into law.
  • FTC Act Section 5 unfair/deceptive-practices authority applies nationally, including to North Dakota, as the federal general-baseline privacy enforcement mechanism.

Material ScopeAmber

Material scope is confined to the breach-notification statute's definition of 'personal information', which was expanded in 2014-2015 to include online-account login credentials; it does not define 'processing' or 'personal data' broadly as an omnibus statute would.

Claims (1):

  • North Dakota's breach-notification statute defines 'personal information' to include online-account login credentials, an expansion added circa 2014-2015 alongside similar amendments in Florida, Nevada and Wyoming.

Territorial ScopeAmber

The breach law applies extraterritorially to any entity holding personal information of ND residents, regardless of whether that entity conducts business in the state.

Claims (1):

  • North Dakota's breach law requires disclosure to affected North Dakota residents even where the disclosing entity does not otherwise conduct business in the state.

Regulator Registration And FilingAmber

No general controller-registration regime exists; the only filing obligation is AG notification of breaches affecting more than 250 ND residents.

Claims (1):

  • North Dakota's breach law includes a state Attorney General notification requirement where a breach affects more than 250 individuals.
Category narrative97 words

North Dakota has no dedicated comprehensive data-protection regulator or statute. Enforcement authority sits with the North Dakota Attorney General under general state consumer-protection powers, overlaid by the FTC's national Section 5 unfair/deceptive-practices authority. A prior attempt at a comprehensive state privacy bill (HB 1485) was substituted with a study task force rather than enacted, confirming ND's position outside the 19-state comprehensive-privacy cohort. The state's operative statutory instrument is its breach-notification law, N.D. Cent. Code Chapter 51-30, which is notification-only and creates no general controller/processor obligations, registration duties, or material-scope definitions of 'processing' akin to GDPR-style omnibus regimes.

Sources and claims (6)
  1. ProbableNAAGThe North Dakota Attorney General is the state's primary consumer-protection enforcement authority for privacy-adjacent matters, operating under general state consumer-protection powers rather than a dedicated data-protection statute.observed
  2. ConfirmedIAPPNorth Dakota has no comprehensive consumer-privacy statute; a 2019 comprehensive privacy bill (HB 1485) was substituted with a study task force rather than enacted into law.observed
  3. ConfirmedFederal Trade CommissionFTC Act Section 5 unfair/deceptive-practices authority applies nationally, including to North Dakota, as the federal general-baseline privacy enforcement mechanism.observed
  4. ConfirmedIAPPNorth Dakota's breach-notification statute defines 'personal information' to include online-account login credentials, an expansion added circa 2014-2015 alongside similar amendments in Florida, Nevada and Wyoming.observed
  5. ConfirmedDataGuidanceNorth Dakota's breach law requires disclosure to affected North Dakota residents even where the disclosing entity does not otherwise conduct business in the state.observed
  6. ConfirmedDataGuidanceNorth Dakota's breach law includes a state Attorney General notification requirement where a breach affects more than 250 individuals.observed

#

No enumerated lawful bases, no general consent standard, no special-category regime, and no pseudonymisation/anonymisation safe-harbour exist at state level; only narrow sectoral opt-out rights apply.

Traffic-light rationale — RedNo enumerated lawful bases, no general consent standard, no special-category regime, and no pseudonymisation/anonymisation safe-harbour exist at state level; only narrow sectoral opt-out rights apply.

Sub-modules (4)

Lawful BasesRed

No ND statute enumerates lawful processing bases; absent_field_provenance: searched 'North Dakota lawful basis processing personal data' and 'North Dakota consent standard privacy law' with no comprehensive-regime results.

Special CategoriesRed

No ND-specific special/sensitive-category regime (health, biometric, genetic, etc.) exists outside federal sectoral law (HIPAA, GINA) and the NAIC-model insurance privacy regulation's nonpublic-personal-health-information provisions.

Claims (1):

  • Insurance licensees in North Dakota are subject to NAIC-model privacy regulation provisions governing nonpublic personal health and financial information, implemented via a signed state NAIC-implementation bill, though the precise scope of ND's adoption could not be independently confirmed from the retrieved source content.

Pseudonymisation And AnonymisationRed

No ND statutory definition or safe-harbour for pseudonymised/anonymised data was located.

Category narrative69 words

North Dakota has no general statute enumerating lawful bases for processing, consent standards, or special/sensitive-category rules comparable to GDPR Art 6/7/9. The only consent/opt-out-adjacent mechanisms operative in the state derive from federal sectoral law (GLBA privacy/opt-out notices for financial institutions, applied via NAIC-model insurance privacy regulation) and a 2019-2021 legislative attempt at an opt-in marketing law that was voted down in committee. Anonymisation/pseudonymisation has no ND statutory safe-harbour definition.

Sources and claims (2)
  1. ProbableIAPPA proposed North Dakota opt-in consent law was voted down by a state House committee, leaving no general statutory opt-in consent requirement for commercial data collection.observed
  2. UncertainDataGuidanceInsurance licensees in North Dakota are subject to NAIC-model privacy regulation provisions governing nonpublic personal health and financial information, implemented via a signed state NAIC-implementation bill, though the precise scope of ND's adoption could not be independently confirmed from the retrieved source content.observed

#

No comprehensive data-subject-rights regime exists at state level; only narrow federal sectoral rights apply, so red with absent_field_provenance.

Traffic-light rationale — RedNo comprehensive data-subject-rights regime exists at state level; only narrow federal sectoral rights apply, so red with absent_field_provenance.

Sub-modules (5)

Access RightRed

No general ND right of access; searched 'North Dakota consumer right to access personal data' with no comprehensive-statute results. Federal FCRA/HIPAA access rights apply sectorally only.

Rectification And ErasureRed

No general ND right to rectify or delete personal data was identified.

Restriction And ObjectionRed

No general ND right to restrict processing or object to processing/profiling was identified.

Data PortabilityRed

No ND data-portability right was identified.

Deadlines And Response WindowsAmber

No general statutory response-deadline framework exists for subject requests; only the breach-notification statute imposes a notification timeline on controllers (to residents and, above threshold, to the AG), not a subject-request response window.

Claims (1):

  • North Dakota's breach-notification statute imposes disclosure timelines on entities following discovery of a security breach, but does not establish a general subject-access-request response deadline.
Category narrative52 words

North Dakota confers no general statutory subject-access, rectification, erasure, restriction, objection, or portability rights. Such rights as exist are narrow federal sectoral analogues (e.g., FCRA access/dispute rights for credit files, HIPAA access rights for health records) rather than a general ND consumer right. No statutory response-deadline framework exists outside the breach-notification context.

Sources and claims (1)
  1. ProbableDataGuidanceNorth Dakota's breach-notification statute imposes disclosure timelines on entities following discovery of a security breach, but does not establish a general subject-access-request response deadline.observed

#

Breach notification and narrow financial/insurance-sector security duties are in force (supporting amber), but no general accountability, DPIA, DPO, ROPA, or retention regime exists (which alone would justify red) for non-sectoral controllers.

Primary frameworkN.D. Cent. Code Chapter 51-30; North Dakota financial-institution data-security act (NAIC-model implementation)
Supervisory authorityNorth Dakota Attorney General
Traffic-light rationale — AmberBreach notification and narrow financial/insurance-sector security duties are in force (supporting amber), but no general accountability, DPIA, DPO, ROPA, or retention regime exists (which alone would justify red) for non-sectoral controllers.

Sub-modules (7)

Accountability And DpiaRed

No general accountability principle or DPIA trigger statute exists in North Dakota.

Dpo RequirementsRed

No DPO appointment threshold exists under ND law.

Ropa RequirementsRed

No records-of-processing-activities obligation exists under ND law.

Joint Controller ArrangementsAmber

No statutory joint-controller framework exists; student-data-sharing agreements between ND higher-education institutions and vendors are the closest analogue, governed by contract (data-sharing agreement legislation) rather than a general joint-controller statute.

Claims (1):

  • North Dakota enacted legislation on student-data-sharing agreements, governing data-sharing relationships between educational institutions and third-party providers.

Security MeasuresAmber

North Dakota enacted a financial-institution data-security act and an NAIC-model insurance data-security implementation bill imposing information-security-program obligations on regulated financial and insurance entities.

Claims (2):

  • North Dakota's Governor signed a bill implementing an NAIC model law affecting insurance-sector data-security obligations.
  • North Dakota enacted an act addressing financial-institution data security obligations.

Breach NotificationAmber

Chapter 51-30 requires notice to affected residents and, above a 250-person threshold, to the Attorney General, following a 2015 amendment extending scope and covered entities.

Claims (1):

  • North Dakota's 2015 breach-notification amendment expanded notification requirements and the range of businesses subject to them, requiring disclosure to affected residents and, for breaches over 250 individuals, to the Attorney General.

Retention And DisposalRed

No general ND retention/disposal statute for personal data was identified outside sector-specific records-retention rules.

Category narrative75 words

ND imposes no general accountability principle, DPIA trigger, DPO threshold, or ROPA requirement. Its principal controller duty is breach-related: the 2015-amended Chapter 51-30 requires disclosure to affected residents without unreasonable delay and to the Attorney General where more than 250 individuals are affected. A separate financial-institution data-security act and an NAIC-model insurance-sector implementation bill impose sector-specific security-of-processing obligations on regulated financial/insurance entities. No general retention/disposal statute for personal data was identified outside sectoral records-retention rules.

Sources and claims (4)
  1. UncertainDataGuidanceNorth Dakota enacted legislation on student-data-sharing agreements, governing data-sharing relationships between educational institutions and third-party providers.observed
  2. UncertainDataGuidanceNorth Dakota's Governor signed a bill implementing an NAIC model law affecting insurance-sector data-security obligations.observed
  3. UncertainDataGuidanceNorth Dakota enacted an act addressing financial-institution data security obligations.observed
  4. ConfirmedDataGuidanceNorth Dakota's 2015 breach-notification amendment expanded notification requirements and the range of businesses subject to them, requiring disclosure to affected residents and, for breaches over 250 individuals, to the Attorney General.observed

#

No state-level transfer mechanism, adequacy status, or localisation rule exists; this module is a genuine regulatory gap for the ND JID specifically.

Traffic-light rationale — RedNo state-level transfer mechanism, adequacy status, or localisation rule exists; this module is a genuine regulatory gap for the ND JID specifically.

Sub-modules (6)

Transfer MechanismsRed

Absent_field_provenance: searched 'North Dakota data transfer mechanism cross-border privacy law' — no state-specific mechanism found; only generic federal sectoral contractual requirements apply.

Adequacy ReceivedRed

Not applicable at US sub-national level; adequacy determinations are made at the federal/EU level, not by North Dakota.

Adequacy GrantedRed

North Dakota, as a US state, has no authority to grant adequacy; this is a federal/EU-level function.

Sccs And BcrsRed

No ND-specific SCC/BCR framework exists; any use is driven by counterparties' GDPR exposure, not ND law.

Transfer Impact AssessmentRed

No ND-specific TIA requirement exists.

Data LocalisationRed

No ND data-localisation mandate was identified.

Category narrative56 words

North Dakota has no state-level cross-border transfer mechanism, adequacy regime, SCC/BCR framework, transfer-impact-assessment requirement, or data-localisation mandate. Any transfer governance affecting ND-resident data derives entirely from federal sectoral law (e.g., GLBA/HIPAA-adjacent contractual requirements) or from counterparties' own frameworks (e.g., EU SCCs used by controllers processing ND residents' data for GDPR-scoped reasons), none of which are ND-specific.

#

Multiple sectoral overlays are confirmed in force (financial, insurance, education), but health, telecoms, employment, and credit-scoring show no ND-specific overlay — hence amber rather than green.

Primary frameworkGLBA; HIPAA (federal); ND financial-institution data-security act; NAIC-model insurance implementation bill; FERPA + NDUS student-data policy
Supervisory authorityNorth Dakota Attorney General
Traffic-light rationale — AmberMultiple sectoral overlays are confirmed in force (financial, insurance, education), but health, telecoms, employment, and credit-scoring show no ND-specific overlay — hence amber rather than green.

Sub-modules (7)

Financial Sector OverlayAmber

North Dakota enacted an act on financial-institution data security, layered atop federal GLBA obligations for financial institutions operating in the state.

Claims (1):

  • North Dakota enacted an act addressing financial-institution data security, supplementing federal GLBA obligations for financial institutions in the state.

Health Sector OverlayRed

No ND-specific health-data overlay beyond federal HIPAA was identified; absent_field_provenance: searched 'North Dakota health data privacy law HIPAA overlay'.

Telecoms And EprivacyRed

No ND-specific telecoms/ePrivacy-equivalent cookie or communications-privacy overlay was identified.

Employment DataRed

No ND-specific employment-data privacy overlay was identified.

Credit And ScoringRed

No ND-specific credit-scoring overlay beyond federal FCRA was identified.

EducationAmber

The North Dakota University System (NDUS) Board of Higher Education adopted a policy restricting the sale of student personally-identifiable information for advertising purposes, and the state separately enacted legislation on student-data-sharing agreements between LEAs and vendors.

Claims (2):

  • The North Dakota Board of Higher Education passed a policy implementing guidelines on the collection, use and access of students' personally identifiable information and prohibiting the state's public colleges from selling student data for advertising purposes.
  • North Dakota enacted legislation governing student-data-sharing agreements between local education agencies and third-party service providers.

InsuranceAmber

North Dakota signed an NAIC-model implementation bill affecting insurance-sector data handling, though the precise operative text could not be fully verified from retrieved sources.

Claims (1):

  • North Dakota's Governor signed a bill implementing an NAIC model law relevant to insurance-sector data handling and security obligations.
Category narrative86 words

Sectoral overlays are the dominant source of enforceable privacy obligation in North Dakota. Financial institutions are governed by GLBA and North Dakota's financial-institution data-security act; insurers by GLBA plus an NAIC-model implementation bill signed into ND law; health data by federal HIPAA (no ND-specific overlay identified); education by FERPA plus ND-specific higher-education student-data policy (NDUS Board of Higher Education policy restricting sale of student data for advertising) and a student-data-sharing-agreements act; telecoms/ePrivacy-equivalent, employment, and credit-scoring sectors show no ND-specific overlay beyond federal law (FCRA for credit).

Sources and claims (4)
  1. UncertainDataGuidanceNorth Dakota enacted an act addressing financial-institution data security, supplementing federal GLBA obligations for financial institutions in the state.observed
  2. ConfirmedIAPPThe North Dakota Board of Higher Education passed a policy implementing guidelines on the collection, use and access of students' personally identifiable information and prohibiting the state's public colleges from selling student data for advertising purposes.observed
  3. UncertainDataGuidanceNorth Dakota enacted legislation governing student-data-sharing agreements between local education agencies and third-party service providers.observed
  4. UncertainDataGuidanceNorth Dakota's Governor signed a bill implementing an NAIC model law relevant to insurance-sector data handling and security obligations.observed

#

No state adtech/commercial-privacy statute exists; the sole legislative attempt failed, confirming a genuine gap rather than an unresearched absence.

Traffic-light rationale — RedNo state adtech/commercial-privacy statute exists; the sole legislative attempt failed, confirming a genuine gap rather than an unresearched absence.

Sub-modules (6)

Cookies And TrackersRed

No ND cookie/tracker consent statute exists; absent_field_provenance: searched 'North Dakota cookie consent law' and 'North Dakota tracker privacy statute'.

Dark PatternsRed

No ND dark-pattern prohibition was identified.

Opt Out SignalsRed

No ND recognition of Global Privacy Control or DAA opt-out signals was identified.

Clean Rooms And DcrRed

No ND clean-room/data-collaboration-room regulation was identified.

Cross Context AdvertisingRed

No ND CPRA-style 'sale'/'share' cross-context-advertising regime was identified.

Direct MarketingRed

A 2021 ND opt-in consent bill targeting commercial data practices was voted down by a House committee; direct marketing in ND is governed only by federal law (CAN-SPAM, TCPA) and FTC Section 5.

Claims (1):

  • A proposed North Dakota opt-in consent law affecting commercial data/marketing practices was voted down by a state House committee, leaving no state-level opt-in marketing-consent requirement.
Category narrative62 words

North Dakota has no cookie/tracker consent statute, no dark-pattern prohibition, no recognition of opt-out signals (GPC/DAA), no clean-room regulation, and no CPRA-style 'sale'/'share' cross-context-advertising regime. A 2021 legislative attempt to impose an opt-in requirement on data brokers/marketers was voted down in a House committee, leaving direct-marketing practices governed only by federal law (e.g., CAN-SPAM, TCPA) and general FTC Section 5 deception principles.

Sources and claims (1)
  1. ProbableIAPPA proposed North Dakota opt-in consent law affecting commercial data/marketing practices was voted down by a state House committee, leaving no state-level opt-in marketing-consent requirement.observed

#

No ND-specific algorithmic, biometric, genetic, or surveillance-governance statute was identified in this research pass; this is a confirmed regulatory gap, not an unresearched one.

Traffic-light rationale — RedNo ND-specific algorithmic, biometric, genetic, or surveillance-governance statute was identified in this research pass; this is a confirmed regulatory gap, not an unresearched one.

Sub-modules (6)

Profiling RestrictionsRed

Absent_field_provenance: searched 'North Dakota profiling restriction automated decision law' with no comprehensive-regime results.

Automated Decision Making TransparencyRed

No ND ADM-transparency or explanation-right statute was identified.

Ai Risk AssessmentsRed

No ND AI-specific risk-assessment statute was identified; searched 'North Dakota AI risk assessment law 2026'.

Biometric RegimeRed

No ND biometric-data statute (facial recognition, fingerprint, gait) comparable to Illinois BIPA was identified.

Genetic DataRed

No ND genetic-data-privacy statute comparable to neighboring states' Genetic Information Privacy Acts was identified.

State Surveillance CarveoutsRed

No ND-specific state-surveillance carve-out statute distinct from general federal law-enforcement exceptions was identified.

Category narrative37 words

No ND statute addresses profiling restrictions, automated-decision-making transparency, AI-specific risk assessments, a biometric-data regime, or a genetic-data regime. State-surveillance carve-outs exist only through general federal/state law-enforcement exceptions incidental to the breach-notification statute, not a dedicated surveillance-governance framework.

#

Education-settings protections are confirmed in force (supporting amber), but age-verification, parental-consent-beyond-COPPA, minor-profiling bans, and dependent-adults protections show no ND-specific coverage.

Primary frameworkCOPPA (federal); NDUS Board of Higher Education student-data policy; ND student-data-sharing-agreements act
Supervisory authorityNorth Dakota Attorney General
Traffic-light rationale — AmberEducation-settings protections are confirmed in force (supporting amber), but age-verification, parental-consent-beyond-COPPA, minor-profiling bans, and dependent-adults protections show no ND-specific coverage.

Sub-modules (5)

Age VerificationRed

No ND-specific age-verification statute was identified; federal COPPA age-13 threshold applies by default.

Minor Profiling BansRed

No ND minor-profiling-ban statute was identified.

Education SettingsAmber

The NDUS Board of Higher Education adopted a student-data-privacy policy prohibiting sale of student PII for advertising, and the state enacted legislation on student-data-sharing agreements between LEAs and providers.

Claims (2):

  • The North Dakota Board of Higher Education passed a policy implementing guidelines on the collection, use and access of students' personally identifiable information and prohibited the state's 11 public colleges from selling data for advertising purposes.
  • North Dakota enacted legislation governing student-data-sharing agreements between local education agencies and third-party service providers.

Dependent AdultsRed

No ND dependent-adults data-protection statute was identified.

Category narrative56 words

North Dakota relies on federal COPPA for parental-consent and age-of-consent protections for children's online data; no ND-specific age-verification, parental-consent, or minor-profiling-ban statute was identified. The state's education-sector protections are notable: NDUS Board of Higher Education policy restricts sale of student PII for advertising, and separate legislation governs student-data-sharing agreements. No dependent-adults (elderly/incapacitated) data-protection statute was identified.

Sources and claims (2)
  1. ConfirmedIAPPThe North Dakota Board of Higher Education passed a policy implementing guidelines on the collection, use and access of students' personally identifiable information and prohibited the state's 11 public colleges from selling data for advertising purposes.observed
  2. UncertainDataGuidanceNorth Dakota enacted legislation governing student-data-sharing agreements between local education agencies and third-party service providers.observed

#

A functioning AG enforcement channel plus federal FTC backstop exist (amber), but no ND-specific penalty schedule, private right of action, or class-action mechanism for privacy specifically was confirmed, and no recent (180-day) ND-specific enforcement activity was identified.

Primary frameworkN.D. Cent. Code Chapter 51-30; FTC Act Section 5
Supervisory authorityNorth Dakota Attorney General
Traffic-light rationale — AmberA functioning AG enforcement channel plus federal FTC backstop exist (amber), but no ND-specific penalty schedule, private right of action, or class-action mechanism for privacy specifically was confirmed, and no recent (180-day) ND-specific enforcement activity was identified.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

The ND AG's enforcement powers derive from general consumer-protection statutes and the breach-notification law; no ND-specific maximum-penalty figure for privacy violations distinct from general consumer-protection remedies was identified in this pass.

Claims (1):

  • The North Dakota Attorney General enforces the state's breach-notification statute and general consumer-protection law as the primary privacy-adjacent enforcement mechanism in the state.

Enforcement Activity IndexRed

No major ND-specific privacy/breach enforcement decision in the last 12 months was identified in this research pass; absent_field_provenance: searched 'North Dakota Attorney General privacy enforcement action 2025 2026'.

Regulator Funding And CapacityRed

No ND AG privacy-specific funding/headcount data was identified; the AG's consumer-protection division handles privacy matters as part of broader consumer-protection capacity.

Collective Redress And Class ActionsRed

No ND-specific collective-redress or class-action mechanism dedicated to privacy claims was identified.

Private Right Of ActionRed

No ND private right of action under the breach-notification statute was identified; enforcement is via the Attorney General only, consistent with the majority of US state breach laws.

Claims (1):

  • North Dakota's breach-notification statute is enforced by the Attorney General rather than through a private right of action, consistent with the majority pattern among US state breach-notification statutes.

Recent Developments 180DRed

No ND-specific legislative, case-law, or guidance development within the last 180 days (Feb-Aug 2026) was identified in this research pass; absent_field_provenance: searched 'North Dakota privacy law 2026 new bill' and 'North Dakota data breach law amendment 2026'.

Category narrative101 words

The North Dakota Attorney General enforces the breach-notification statute and general consumer-protection law; the FTC exercises concurrent federal Section 5 authority nationally. No ND-specific comprehensive-privacy penalty schedule exists (there is no comprehensive statute to penalize under). No ND private right of action for breach-notification violations or general collective-redress/class-action mechanism specific to privacy was identified; consumers would rely on general common-law or federal-statute (e.g., FCRA) private rights of action where applicable. No major ND-specific privacy enforcement action was identified in the 180-day recent-developments window; the most recent substantive developments concern historical breach-law amendments (2015) and sectoral bills (NAIC/financial-institution/student-data) of uncertain recent vintage.

Sources and claims (2)
  1. ProbableNAAGThe North Dakota Attorney General enforces the state's breach-notification statute and general consumer-protection law as the primary privacy-adjacent enforcement mechanism in the state.observed
  2. UncertainIAPPNorth Dakota's breach-notification statute is enforced by the Attorney General rather than through a private right of action, consistent with the majority pattern among US state breach-notification statutes.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United States – North Dakota
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 22 claim(s), 13 source(s) in the cumulative register.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (37 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrectification and erasure
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacydata localisation
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redresscollective redress and class actions
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

Module 1 (regulator_and_framework) and module 4 (controller_processor_duties, breach_notification sub-module) reached T1/T2 sourcing on the core breach-notification statute (N.D. Cent. Code Ch. 51-30) and FTC Section 5 baseline. Sectoral modules (sectoral_watch, children_and_vulnerable_groups education_settings) reached T2/T3 sourcing on NAIC-implementation, financial-institution data-security, and student-data-privacy bills, but underlying bill/statute full text could not be retrieved beyond DataGuidance/IAPP headline-level summaries, producing several Uncertain-confidence claims with absent_field_provenance. Modules 2 (lawful_processing_and_special_data), 3 (data_subject_rights), 5 (cross_border_and_adequacy), 7 (adtech_and_commercial_privacy), and 8 (algorithmic_biometric_and_surveillance_governance) returned no comprehensive-regime findings and are populated with red traffic_light + absent_field_provenance narratives reflecting genuine regulatory gaps consistent with the injected seed's CRITICAL caution flag that North Dakota has no comprehensive consumer-privacy statute. Enforcement module (10) found no ND-specific enforcement activity within the 180-day window.

Unresolved questions (5):

  • Full statutory text and precise scope of North Dakota's NAIC-implementation bill (insurance data security) could not be retrieved — only headline-level DataGuidance summary was accessible.
  • Full statutory text of North Dakota's financial-institution data-security act could not be retrieved beyond headline-level summary.
  • Full statutory text of North Dakota's student-data-sharing-agreements bill could not be retrieved beyond headline-level summary.
  • Whether N.D. Cent. Code Chapter 51-30 has been amended since 2015 (beyond the S.2214 amendment) was not independently re-verified against current statutory text in this pass.
  • Whether North Dakota has any private right of action under Chapter 51-30 could not be conclusively confirmed absent direct statutory text retrieval.

Escalate to primary-source review: yes