North Carolina Privacy Law
North Carolina has no comprehensive consumer privacy statute, but its Identity Theft Protection Act does something only a handful of states do: it requires a report to the Attorney General’s Consumer Protection Division for every breach that triggers consumer notice, with no headcount threshold, and it specifies what that report must contain. The Article also carries a rare anti-waiver provision declaring any waiver of its terms void as contrary to public policy, bars assignment of causes of action arising under it, and channels violations into the state’s unfair-and-deceptive-practices statute while limiting private suits to individuals actually injured. Article 2A of Chapter 75 was amended by Session Law 2025-25.
Sector-Specific Privacy Laws in North Carolina
Social Security number protection (N.C. Gen. Stat. § 75-62)
Six practices are prohibited outright: intentionally communicating or otherwise making an individual’s Social Security number available to the general public; intentionally printing or embedding it on any card required to access the business’s products or services; requiring transmission of it over the internet unless the connection is secure or the number is encrypted; requiring its use to access a website unless a password, unique personal identification number or other authentication device is also required; printing it on materials mailed to the individual unless state or federal law requires it; and selling, leasing, loaning, trading, renting or otherwise intentionally disclosing it to a third party without written consent, where the discloser knows or with reasonable diligence would have reason to believe the third party lacks a legitimate purpose for obtaining it. Subsection (b) exempts, among other things, use in applications and enrolment documents, internal verification and administrative purposes, fraud investigation, background checks, debt collection, credit reporting under the Fair Credit Reporting Act, and disclosure to government entities — but adds that a number permitted to be mailed may not be printed on a postcard or other mailer not requiring an envelope, or be visible on or through the envelope. A violation is a violation of G.S. 75-1.1.
Destruction of personal information records (N.C. Gen. Stat. § 75-64)
Any business conducting business in North Carolina, and any business that maintains or possesses personal information of a North Carolina resident, must take reasonable measures to protect against unauthorized access to or use of that information in connection with or after its disposal. The section defines what “reasonable measures” must include: policies and procedures requiring burning, pulverizing or shredding of paper records, policies and procedures requiring destruction or erasure of electronic and other non-paper media, and a written statement of those procedures as official policy of the business. A business may contract out destruction, but only after due diligence, which the section says should ordinarily include reviewing an independent audit of the disposal business, obtaining references or requiring certification by a recognized trade association, or reviewing the disposal business’s information security policies. Disposal businesses carry their own duty under subsection (d). A violation is a violation of G.S. 75-1.1, with a carve-out: damages assessed because of the acts of non-managerial employees are not trebled under G.S. 75-16 unless the business was negligent in training, supervising or monitoring them.
Unfair and deceptive trade practices (N.C. Gen. Stat. § 75-1.1)
Section 75-1.1 is the hinge of the whole scheme rather than a parallel track. Sections 75-62, 75-64 and 75-65 each provide that a violation “is a violation of G.S. 75-1.1”, which is what supplies the remedies the Identity Theft Protection Act does not state for itself — including the treble damages of G.S. 75-16 referred to in § 75-64(f). The Act limits what private plaintiffs can do with that channel: §§ 75-64(f) and 75-65(i) both provide that no private right of action may be brought by an individual unless the individual is injured as a result of the violation, and § 75-65(j) provides that causes of action arising under the Article may not be assigned.
Data Breach Notification in North Carolina
Section 75-65(a) applies to any business that owns or licenses personal information of North Carolina residents, and to any business conducting business in the state that owns or licenses personal information “in any form (whether computerized, paper, or otherwise)” — the paper reference is unusual among state breach statutes. The same subsection narrows what counts: personal information does not include electronic identification numbers, email names or addresses, internet account numbers, internet identification names, a parent’s legal surname prior to marriage, or a password, unless the information would permit access to a person’s financial account or resources. Subsection (d) prescribes seven content elements for the notice, including advice directing the person to remain vigilant by reviewing account statements and monitoring free credit reports, the toll-free numbers and addresses of the major consumer reporting agencies, and the toll-free numbers, addresses and website addresses for the Federal Trade Commission and the North Carolina Attorney General’s Office with a statement that identity-theft prevention information can be obtained from them. Substitute notice under subsection (e)(4) requires a cost over $250,000 or a class over 500,000, and may also be used for the subset of affected persons for whom the business lacks contact information or consent. Subsection (e1) is the distinctive provision: whenever a business notifies an affected person, it must also notify the Consumer Protection Division of the Attorney General’s Office, without unreasonable delay, of the nature of the breach, the number of consumers affected, the steps taken to investigate it, the steps taken to prevent a similar breach in future, and the timing, distribution and content of the notice. Subsection (f) adds notice to the nationwide consumer reporting agencies once more than 1,000 persons are notified at one time. Subsection (g) makes any waiver of the Article’s provisions void and unenforceable as contrary to public policy, and subsection (h) deems compliant a financial institution or credit union that follows the applicable federal interagency guidance.
Residents must be notified without unreasonable delay, consistent with law enforcement needs and with measures to determine contact information, determine the scope of the breach and restore the data system. Report to the Attorney General's Consumer Protection Division for every breach that triggers consumer notice, with no minimum number of residents. Complaints are taken by the North Carolina Attorney General, which enforces the statute.
How North Carolina Enforces Its Privacy Laws
Breach failures are unfair trade practices, with private suits limited to the injured. Section 75-65(i) provides that a violation of the section is a violation of G.S. 75-1.1, and then limits who may use that: “No private right of action may be brought by an individual for a violation of this section unless such individual is injured as a result of the violation.” Section 75-65(j) adds that causes of action arising under the Article may not be assigned, which forecloses aggregation by assignment. The same injury limitation appears at § 75-64(f) for record-destruction violations.
Waivers are void. Section 75-65(g) states that “any waiver of the provisions of this Article is contrary to public policy and is void and unenforceable”. The provision reaches the whole Article rather than the breach section alone, so it applies to the Social Security number limits in § 75-62 and the disposal duties in § 75-64 as well.
Pending Privacy Legislation
Article 2A of Chapter 75 is not static: the history lines on §§ 75-62, 75-64 and 75-65 record amendments by Session Law 2005-414, Session Laws 2009-355 and 2009-573, and most recently Session Law 2025-25, section 29, which touched subsections (1), (3) and (5) of § 75-65 and subsections (3) and (5) of § 75-62. What the General Assembly has not done is enact a comprehensive consumer privacy statute of the kind neighbouring Virginia and Tennessee now have; North Carolina consumers still have no statutory right of access, correction, deletion or opt-out, and the state’s consumer-facing privacy law remains the identity-theft and breach architecture of Chapter 75.
Federal Privacy Laws That Apply in North Carolina
Federal privacy law applies in North Carolina by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.
The state-law counterpart to section 5 is the Unfair and deceptive trade practices (N.C. Gen. Stat. § 75-1.1), which the North Carolina Attorney General enforces against businesses whose stated data practices differ from their actual ones.
Industry Rules That Reach North Carolina Businesses
With no comprehensive state statute, most privacy obligations on a North Carolina business arrive through its industry: healthcare, financial services, online services, retail, employment and education. Each is covered in its own guide.
Two of those reach North Carolina businesses regardless of industry. A company serving residents of states that have enacted comprehensive laws can owe duties under those laws while North Carolina itself has none, and any business holding personal information about North Carolina residents is subject to the state’s breach-notification statute described above.
North Carolina Privacy Law FAQ
Does every North Carolina breach have to be reported to the Attorney General?
Does North Carolina’s breach law cover paper records?
What is excluded from “personal information” in North Carolina?
Can a North Carolina consumer sue over a breach?
Can a North Carolina business contract out of the Identity Theft Protection Act?
What does North Carolina law say about printing Social Security numbers?
Must a North Carolina business vet the company that shreds its records?
Sources
This guide describes what these documents say. Follow them to check the description against the source.
- N.C. Gen. Stat. § 75-65 — Protection from security breaches statute
- N.C. Gen. Stat. § 75-62 — Social security number protection statute
- N.C. Gen. Stat. § 75-64 — Destruction of personal information records statute
- 45 CFR Part 164 — HIPAA Privacy and Security Rules regulation
- 15 U.S.C. 6801 — Gramm-Leach-Bliley Act statute
- 20 U.S.C. 1232g — Family Educational Rights and Privacy Act statute
- 15 U.S.C. 1681 — Fair Credit Reporting Act statute
- 16 CFR Part 312 — Children’s Online Privacy Protection Rule regulation
- Section 5 of the FTC Act, 15 U.S.C. 45 statute
Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.