North Dakota Privacy Law
North Dakota has no comprehensive consumer privacy statute, and the statutes it does have are notable less for consumer rights than for the breadth of what they treat as identifying. Chapter 51-30 of the Century Code counts ten data elements as “personal information” — including a date of birth, a mother’s maiden name and a digitized signature, none of which appear in most states’ breach statutes — and routes every violation into the Attorney General’s consumer-fraud powers under chapter 51-15. A separate chapter, 26.1-02.2, puts insurance licensees on a three-business-day reporting clock to the Insurance Commissioner that runs far shorter than the general breach statute’s.
Sector-Specific Privacy Laws in North Dakota
Insurance Data Security (N.D.C.C. ch. 26.1-02.2)
The chapter applies to any “licensee” — defined in § 26.1-02.2-01(9) as a person licensed, authorized to operate, registered or required to be registered under the state’s insurance laws — and requires each one to maintain an information security program under § 26.1-02.2-03. Section 26.1-02.2-05 sets a reporting clock that is much shorter than chapter 51-30’s: a licensee must notify the Insurance Commissioner no later than three business days after determining a cybersecurity event has occurred, either where North Dakota is its state of domicile and the event triggers consumer notice under chapter 51-30, or where the nonpublic information of 250 or more North Dakota consumers is involved. The notice must carry twelve specified items, among them how the information was exposed, the identity of the source of the event, the period during which the system was compromised, the licensee’s best estimate of the number of affected North Dakota consumers, and a copy of its privacy policy. Section 26.1-02.2-08 exempts licensees with less than $5 million in gross revenue or less than $10 million in year-end assets from most of the security-program requirements, and treats a HIPAA-compliant licensee as compliant with § 26.1-02.2-03. Senate Bill 2088 of the 2025 session, introduced by the Senate Industry and Business Committee at the request of the Insurance Commissioner, rewrote §§ 26.1-02.2-05 and 26.1-02.2-07 and repealed the chapter’s implementation-date section; it passed the Senate 43-1 and the House 93-0 and was signed on March 26, 2025.
Unlawful Sales or Advertising Practices (N.D.C.C. ch. 51-15)
Section 51-15-02 declares unlawful any deceptive act or practice, fraud, false pretense, false promise or misrepresentation made with intent that others rely on it in connection with the sale or advertisement of merchandise, “whether or not any person has in fact been misled, deceived, or damaged thereby”, and separately reaches unconscionable practices and practices causing substantial unavoidable injury. Section 51-15-04 lets the Attorney General compel written statements under oath, examine persons under oath and impound records; § 51-15-05 adds subpoena power. Under § 51-15-07 the Attorney General may obtain an injunction, seek the appointment of a receiver where a person is about to conceal assets or leave the state, and issue a cease-and-desist order without notice or hearing, with a civil penalty of up to $1,000 for each violation of such an order. Section 51-15-11 authorises a court-assessed civil penalty of up to $5,000 for each violation of the chapter. Section 51-15-09 preserves private claims and directs that a court finding the defendant knowingly committed the conduct may award up to treble actual damages and must award costs and reasonable attorney’s fees. Section 51-15-12 bars a claim not brought within four years of accrual, with accrual deferred until the aggrieved party discovers the facts constituting the violation.
Disclosure of personal identifying information (N.D.C.C. § 12.1-17-07)
North Dakota’s harassment statute reaches conduct that other states address through separate doxxing laws. Section 12.1-17-07(2)(e) makes it an offense, when done with intent to frighten or harass another, to communicate in writing, by electronic communication, or by “electronically publishing, posting, or otherwise disclosing information to a public internet site or public forum an individual’s personal identifying information”. Subsection 3 grades that as a class B misdemeanor, reserving class A for threats to inflict injury and for false emergency reports. Subsection 1 defines “robot” to include remotely piloted aircraft and artificial intelligence, and subsection 2(f) makes using a robot for offensive conduct with no legitimate purpose an offense in its own right. House Bill 1134 of the 2025 session amended the section; it passed the House 90-2 on January 27, 2025 and the Senate 47-0 on March 11, 2025, and was signed on March 24, 2025.
Data Breach Notification in North Dakota
Chapter 51-30 of the Century Code carries an unusually wide definition of what a breach can expose. Section 51-30-01(4)(a) lists ten data elements that, combined with a first name or initial and last name, make information “personal information”: a Social Security number, an operator’s license number issued under § 39-06-14, a nondriver colour photo identification card number issued under § 39-06-03.1, a financial-institution account, credit-card or debit-card number with the code that would permit access, the individual’s date of birth, the maiden name of the individual’s mother, medical information, health insurance information, an employer-assigned identification number with its access code, and the individual’s digitized or other electronic signature. Section 51-30-01(1) defines the breach as unauthorized acquisition of computerized data where access has not been secured by encryption or another method rendering the files unreadable, and carves out good-faith acquisition by an employee or agent. Section 51-30-02 requires disclosure to any affected North Dakota resident and, separately, disclosure to the Attorney General by mail or electronic mail of any breach exceeding 250 individuals; the timing standard is the most expedient time possible and without unreasonable delay. Section 51-30-03 puts a person who merely maintains data it does not own on an immediate duty to tell the owner or licensee. Substitute notice becomes available under § 51-30-05(3) where notice would cost more than $250,000 or the affected class exceeds 500,000. Section 51-30-06 deems a financial institution, trust company or credit union that is examined for and compliant with the federal interagency guidance, and a HIPAA covered entity, business associate or subcontractor subject to 45 C.F.R. part 164 subpart D, to be in compliance.
Residents must be notified in the most expedient time possible and without unreasonable delay, consistent with the needs of law enforcement and the measures needed to determine the scope of the breach. Notify the Attorney General by mail or email for any breach exceeding 250 individuals. Complaints are taken by the North Dakota Attorney General, which enforces the statute.
How North Dakota Enforces Its Privacy Laws
Breach violations are consumer-fraud violations. Section 51-30-07 does not create a standalone penalty schedule. It provides that the Attorney General may enforce chapter 51-30 with “all the powers provided in chapter 51-15”, may seek all the remedies in that chapter, and that a violation of chapter 51-30 “is deemed a violation of chapter 51-15”. The remedies are expressly non-exclusive and additive to other causes of action. In practice that means a failure to notify is prosecuted with the same investigative demands, subpoenas, injunctions, receiverships and cease-and-desist orders that reach deceptive advertising, and exposes the same court-assessed civil penalty of up to $5,000 per violation under § 51-15-11.
Assurance of voluntary compliance. Section 51-15-06.1 lets the Attorney General accept a written assurance of voluntary compliance in place of litigation, and names chapter 51-30 among the chapters it may cover. The assurance must be filed with and approved by the district court of the county where the alleged violator resides or does business, or by the district court of Burleigh County, and failure to comply with an approved assurance is contempt of court.
Recent Enforcement in North Dakota
Google location tracking — $391.5 million multistate settlement, $4.1 million to North Dakota. The Attorney General’s office announced on November 29, 2022 that North Dakota was one of 40 states settling with Google over its location-tracking practices, describing it as the largest multistate Attorney General privacy settlement in United States history. North Dakota’s share of the $391.5 million total was $4.1 million. The office states the investigation began after 2018 reporting that Google recorded users’ movements even where they had turned location tracking off. Beyond the payment, the settlement requires Google to show users additional information when they turn location-related account settings on or off, to make key information about location tracking unavoidable rather than buried, and to give users detailed information about the types of location data Google collects and how it is used through an expanded “Location Technologies” page.
Pending Privacy Legislation
North Dakota’s privacy output in the 69th Legislative Assembly was amendment rather than enactment. Senate Bill 2088, requested by the Insurance Commissioner, reworked the cybersecurity-event notice in § 26.1-02.2-05 — adding the requirement that a licensee describe the specific types of information acquired and report its best estimate of the number of affected North Dakota consumers — and repealed the implementation-date section of the Insurance Data Security chapter; it was signed on March 26, 2025. House Bill 1134 amended the harassment statute at § 12.1-17-07 and was signed on March 24, 2025. Nothing in the 2025 session created consumer rights of access, deletion or opt-out of the kind enacted in neighbouring Montana and Minnesota.
Federal Privacy Laws That Apply in North Dakota
Federal privacy law applies in North Dakota by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.
Outside those federal sectors, North Dakota obligations run through the state’s breach-notification statute and the North Dakota Attorney General’s general consumer-protection authority rather than through a privacy statute of its own.
Industry Rules That Reach North Dakota Businesses
With no comprehensive state statute, most privacy obligations on a North Dakota business arrive through its industry: healthcare, financial services, online services, retail, employment and education. Each is covered in its own guide.
Two of those reach North Dakota businesses regardless of industry. A company serving residents of states that have enacted comprehensive laws can owe duties under those laws while North Dakota itself has none, and any business holding personal information about North Dakota residents is subject to the state’s breach-notification statute described above.
North Dakota Privacy Law FAQ
When does a North Dakota breach have to be reported to the Attorney General?
What data elements count as “personal information” in North Dakota?
Is there a fixed deadline for notifying North Dakota residents after a breach?
What penalties attach to a failure to give breach notice in North Dakota?
Do North Dakota insurance licensees have a separate breach-reporting duty?
Can a private individual sue under North Dakota’s consumer-fraud statute?
Is posting someone’s personal information online a crime in North Dakota?
Sources
This guide describes what these documents say. Follow them to check the description against the source.
- N.D.C.C. ch. 51-30 — Notice of Security Breach for Personal Information statute
- N.D.C.C. ch. 51-15 — Unlawful Sales or Advertising Practices statute
- N.D.C.C. ch. 26.1-02.2 — Insurance Data Security statute
- N.D.C.C. § 12.1-17-07 — Harassment statute
- Senate Bill 2088 (2025) — Insurance data security amendments legislation
- House Bill 1134 (2025) — Harassment amendments legislation
- North Dakota Attorney General — Google settlement over location tracking practices agency
- North Dakota Attorney General — Consumer protection enforcement actions agency
- 45 CFR Part 164 — HIPAA Privacy and Security Rules regulation
- 15 U.S.C. 6801 — Gramm-Leach-Bliley Act statute
- 20 U.S.C. 1232g — Family Educational Rights and Privacy Act statute
- 15 U.S.C. 1681 — Fair Credit Reporting Act statute
- 16 CFR Part 312 — Children’s Online Privacy Protection Rule regulation
- Section 5 of the FTC Act, 15 U.S.C. 45 statute
Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.