North Carolina

North Carolina Privacy Law

North Carolina has no comprehensive consumer privacy statute, but its Identity Theft Protection Act does something only a handful of states do: it requires a report to the Attorney General’s Consumer Protection Division for every breach that triggers consumer notice, with no headcount threshold, and it specifies what that report must contain. The Article also carries a rare anti-waiver provision declaring any waiver of its terms void as contrary to public policy, bars assignment of causes of action arising under it, and channels violations into the state’s unfair-and-deceptive-practices statute while limiting private suits to individuals actually injured. Article 2A of Chapter 75 was amended by Session Law 2025-25.

Sector-Specific Privacy Laws in North Carolina

Social Security number protection (N.C. Gen. Stat. § 75-62)

Six practices are prohibited outright: intentionally communicating or otherwise making an individual’s Social Security number available to the general public; intentionally printing or embedding it on any card required to access the business’s products or services; requiring transmission of it over the internet unless the connection is secure or the number is encrypted; requiring its use to access a website unless a password, unique personal identification number or other authentication device is also required; printing it on materials mailed to the individual unless state or federal law requires it; and selling, leasing, loaning, trading, renting or otherwise intentionally disclosing it to a third party without written consent, where the discloser knows or with reasonable diligence would have reason to believe the third party lacks a legitimate purpose for obtaining it. Subsection (b) exempts, among other things, use in applications and enrolment documents, internal verification and administrative purposes, fraud investigation, background checks, debt collection, credit reporting under the Fair Credit Reporting Act, and disclosure to government entities — but adds that a number permitted to be mailed may not be printed on a postcard or other mailer not requiring an envelope, or be visible on or through the envelope. A violation is a violation of G.S. 75-1.1.

Destruction of personal information records (N.C. Gen. Stat. § 75-64)

Any business conducting business in North Carolina, and any business that maintains or possesses personal information of a North Carolina resident, must take reasonable measures to protect against unauthorized access to or use of that information in connection with or after its disposal. The section defines what “reasonable measures” must include: policies and procedures requiring burning, pulverizing or shredding of paper records, policies and procedures requiring destruction or erasure of electronic and other non-paper media, and a written statement of those procedures as official policy of the business. A business may contract out destruction, but only after due diligence, which the section says should ordinarily include reviewing an independent audit of the disposal business, obtaining references or requiring certification by a recognized trade association, or reviewing the disposal business’s information security policies. Disposal businesses carry their own duty under subsection (d). A violation is a violation of G.S. 75-1.1, with a carve-out: damages assessed because of the acts of non-managerial employees are not trebled under G.S. 75-16 unless the business was negligent in training, supervising or monitoring them.

Unfair and deceptive trade practices (N.C. Gen. Stat. § 75-1.1)

Section 75-1.1 is the hinge of the whole scheme rather than a parallel track. Sections 75-62, 75-64 and 75-65 each provide that a violation “is a violation of G.S. 75-1.1”, which is what supplies the remedies the Identity Theft Protection Act does not state for itself — including the treble damages of G.S. 75-16 referred to in § 75-64(f). The Act limits what private plaintiffs can do with that channel: §§ 75-64(f) and 75-65(i) both provide that no private right of action may be brought by an individual unless the individual is injured as a result of the violation, and § 75-65(j) provides that causes of action arising under the Article may not be assigned.

Data Breach Notification in North Carolina

Section 75-65(a) applies to any business that owns or licenses personal information of North Carolina residents, and to any business conducting business in the state that owns or licenses personal information “in any form (whether computerized, paper, or otherwise)” — the paper reference is unusual among state breach statutes. The same subsection narrows what counts: personal information does not include electronic identification numbers, email names or addresses, internet account numbers, internet identification names, a parent’s legal surname prior to marriage, or a password, unless the information would permit access to a person’s financial account or resources. Subsection (d) prescribes seven content elements for the notice, including advice directing the person to remain vigilant by reviewing account statements and monitoring free credit reports, the toll-free numbers and addresses of the major consumer reporting agencies, and the toll-free numbers, addresses and website addresses for the Federal Trade Commission and the North Carolina Attorney General’s Office with a statement that identity-theft prevention information can be obtained from them. Substitute notice under subsection (e)(4) requires a cost over $250,000 or a class over 500,000, and may also be used for the subset of affected persons for whom the business lacks contact information or consent. Subsection (e1) is the distinctive provision: whenever a business notifies an affected person, it must also notify the Consumer Protection Division of the Attorney General’s Office, without unreasonable delay, of the nature of the breach, the number of consumers affected, the steps taken to investigate it, the steps taken to prevent a similar breach in future, and the timing, distribution and content of the notice. Subsection (f) adds notice to the nationwide consumer reporting agencies once more than 1,000 persons are notified at one time. Subsection (g) makes any waiver of the Article’s provisions void and unenforceable as contrary to public policy, and subsection (h) deems compliant a financial institution or credit union that follows the applicable federal interagency guidance.

Residents must be notified without unreasonable delay, consistent with law enforcement needs and with measures to determine contact information, determine the scope of the breach and restore the data system. Report to the Attorney General's Consumer Protection Division for every breach that triggers consumer notice, with no minimum number of residents. Complaints are taken by the North Carolina Attorney General, which enforces the statute.

How North Carolina Enforces Its Privacy Laws

Breach failures are unfair trade practices, with private suits limited to the injured. Section 75-65(i) provides that a violation of the section is a violation of G.S. 75-1.1, and then limits who may use that: “No private right of action may be brought by an individual for a violation of this section unless such individual is injured as a result of the violation.” Section 75-65(j) adds that causes of action arising under the Article may not be assigned, which forecloses aggregation by assignment. The same injury limitation appears at § 75-64(f) for record-destruction violations.

Waivers are void. Section 75-65(g) states that “any waiver of the provisions of this Article is contrary to public policy and is void and unenforceable”. The provision reaches the whole Article rather than the breach section alone, so it applies to the Social Security number limits in § 75-62 and the disposal duties in § 75-64 as well.

Pending Privacy Legislation

Article 2A of Chapter 75 is not static: the history lines on §§ 75-62, 75-64 and 75-65 record amendments by Session Law 2005-414, Session Laws 2009-355 and 2009-573, and most recently Session Law 2025-25, section 29, which touched subsections (1), (3) and (5) of § 75-65 and subsections (3) and (5) of § 75-62. What the General Assembly has not done is enact a comprehensive consumer privacy statute of the kind neighbouring Virginia and Tennessee now have; North Carolina consumers still have no statutory right of access, correction, deletion or opt-out, and the state’s consumer-facing privacy law remains the identity-theft and breach architecture of Chapter 75.

Federal Privacy Laws That Apply in North Carolina

Federal privacy law applies in North Carolina by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.

The state-law counterpart to section 5 is the Unfair and deceptive trade practices (N.C. Gen. Stat. § 75-1.1), which the North Carolina Attorney General enforces against businesses whose stated data practices differ from their actual ones.

Industry Rules That Reach North Carolina Businesses

With no comprehensive state statute, most privacy obligations on a North Carolina business arrive through its industry: healthcare, financial services, online services, retail, employment and education. Each is covered in its own guide.

Two of those reach North Carolina businesses regardless of industry. A company serving residents of states that have enacted comprehensive laws can owe duties under those laws while North Carolina itself has none, and any business holding personal information about North Carolina residents is subject to the state’s breach-notification statute described above.

North Carolina Privacy Law FAQ

Does every North Carolina breach have to be reported to the Attorney General?
Every breach that triggers notice to an affected person does. Section 75-65(e1) requires a business that provides notice under the section to notify the Consumer Protection Division of the Attorney General’s Office, without unreasonable delay, and it sets no minimum number of affected residents. The report must cover the nature of the breach, the number of consumers affected, the steps taken to investigate it, the steps taken to prevent a similar breach in future, and the timing, distribution and content of the consumer notice.
Does North Carolina’s breach law cover paper records?
Yes. Section 75-65(a) applies to a business that owns or licenses personal information “in any form (whether computerized, paper, or otherwise)”. Most state breach statutes are limited to computerized data. The separate record-destruction duty in § 75-64 also addresses paper directly, requiring policies and procedures for burning, pulverizing or shredding papers containing personal information.
What is excluded from “personal information” in North Carolina?
Section 75-65(a) closes with an express exclusion list: electronic identification numbers, email names or addresses, internet account numbers, internet identification names, a parent’s legal surname prior to marriage, and passwords are not personal information for purposes of the section — unless that information would permit access to a person’s financial account or resources.
Can a North Carolina consumer sue over a breach?
Only if injured. Section 75-65(i) makes a violation of the section a violation of G.S. 75-1.1, but adds that no private right of action may be brought by an individual “unless such individual is injured as a result of the violation”. Section 75-65(j) separately provides that causes of action arising under the Article may not be assigned. The same injury requirement applies to record-destruction violations under § 75-64(f).
Can a North Carolina business contract out of the Identity Theft Protection Act?
No. Section 75-65(g) provides that any waiver of the provisions of the Article is contrary to public policy and is void and unenforceable. Because the provision reaches the whole Article, it applies to the Social Security number restrictions in § 75-62 and the disposal obligations in § 75-64 as well as to the breach section.
What does North Carolina law say about printing Social Security numbers?
Section 75-62(a) bars a business from printing an individual’s Social Security number on any card required to access its products or services, and from printing it on materials mailed to the individual unless state or federal law requires it. Where a number may lawfully be mailed, subsection (b)(1) adds that it may not be printed, in whole or in part, on a postcard or other mailer not requiring an envelope, and may not be visible on the envelope or without the envelope having been opened.
Must a North Carolina business vet the company that shreds its records?
Section 75-64(c) permits a business to contract out destruction only “after due diligence”, and describes what that ordinarily includes: reviewing an independent audit of the disposal business’s operations or its compliance with the statute, obtaining information from several references or requiring certification by a recognized trade association or similar third party, or reviewing and evaluating the disposal business’s information security policies. The contract must be written and compliance must be monitored.

Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.