#
No omnibus statute exists (would be red for comprehensive-rights coverage), but a live, actively-amended breach-notification statute plus federal FTC Section 5 baseline provide a minimum enforceable floor, so amber rather than red.
Sub-modules (5)
Regulator And AuthorityAmber
The North Dakota Attorney General enforces state consumer-protection and breach-notification law; there is no separate ND data-protection authority. The FTC exercises concurrent federal Section 5 authority.
Claims (1):
- The North Dakota Attorney General is the state's primary consumer-protection enforcement authority for privacy-adjacent matters, operating under general state consumer-protection powers rather than a dedicated data-protection statute.
Act And InstrumentsRed
Primary instruments are N.D. Cent. Code Ch. 51-30 (breach notification) and federal FTC Act Section 5; no comprehensive ND privacy statute exists, and the 2019-session comprehensive bill (HB 1485) was replaced by a study task force.
Claims (2):
- North Dakota has no comprehensive consumer-privacy statute; a 2019 comprehensive privacy bill (HB 1485) was substituted with a study task force rather than enacted into law.
- FTC Act Section 5 unfair/deceptive-practices authority applies nationally, including to North Dakota, as the federal general-baseline privacy enforcement mechanism.
Material ScopeAmber
Material scope is confined to the breach-notification statute's definition of 'personal information', which was expanded in 2014-2015 to include online-account login credentials; it does not define 'processing' or 'personal data' broadly as an omnibus statute would.
Claims (1):
- North Dakota's breach-notification statute defines 'personal information' to include online-account login credentials, an expansion added circa 2014-2015 alongside similar amendments in Florida, Nevada and Wyoming.
Territorial ScopeAmber
The breach law applies extraterritorially to any entity holding personal information of ND residents, regardless of whether that entity conducts business in the state.
Claims (1):
- North Dakota's breach law requires disclosure to affected North Dakota residents even where the disclosing entity does not otherwise conduct business in the state.
Regulator Registration And FilingAmber
No general controller-registration regime exists; the only filing obligation is AG notification of breaches affecting more than 250 ND residents.
Claims (1):
- North Dakota's breach law includes a state Attorney General notification requirement where a breach affects more than 250 individuals.
Sources and claims (6)
- ProbableNAAG — The North Dakota Attorney General is the state's primary consumer-protection enforcement authority for privacy-adjacent matters, operating under general state consumer-protection powers rather than a dedicated data-protection statute.observed
- ConfirmedIAPP — North Dakota has no comprehensive consumer-privacy statute; a 2019 comprehensive privacy bill (HB 1485) was substituted with a study task force rather than enacted into law.observed
- ConfirmedFederal Trade Commission — FTC Act Section 5 unfair/deceptive-practices authority applies nationally, including to North Dakota, as the federal general-baseline privacy enforcement mechanism.observed
- ConfirmedIAPP — North Dakota's breach-notification statute defines 'personal information' to include online-account login credentials, an expansion added circa 2014-2015 alongside similar amendments in Florida, Nevada and Wyoming.observed
- ConfirmedDataGuidance — North Dakota's breach law requires disclosure to affected North Dakota residents even where the disclosing entity does not otherwise conduct business in the state.observed
- ConfirmedDataGuidance — North Dakota's breach law includes a state Attorney General notification requirement where a breach affects more than 250 individuals.observed