North Carolina
North Carolina Data Privacy Laws: Consumer Rights & Protections (2026)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 34 primary sources cited on this page. How we verify our legal content

North Carolina does not have a comprehensive consumer data privacy law as of May 2026. The state's personal data protections come from a patchwork of sector-specific statutes: the Identity Theft Protection Act (N.C. Gen. Stat. Chapter 75, Article 2A) is the foundation, covering breach notification, Social Security number handling, credit freezes, and data disposal. Separate laws address student privacy, insurance information, public records, and health data. Three bills introduced in the 2025-2026 legislative session would change that picture, but none has been enacted.
In 2025, North Carolina businesses and government agencies reported 2,349 data breaches to the Department of Justice, a record high, exposing the personal information of approximately 9.3 million North Carolinians. Attorney General Jeff Jackson, who took office in January 2025, has pursued aggressive enforcement using existing breach-notification authority, launching investigations into PowerSchool and 23andMe and securing a court order blocking unlawful federal data-sharing with DOGE.
This guide covers every major North Carolina data privacy statute in force, the status of pending comprehensive privacy legislation, what rights North Carolina residents currently hold, what obligations businesses must meet, and how the Attorney General enforces these laws.
Overview of North Carolina's Data Privacy Framework
North Carolina takes a sector-specific approach to data privacy rather than relying on a single comprehensive consumer privacy law. Unlike California, Virginia, Colorado, and more than a dozen other states that have enacted omnibus consumer data protection statutes, North Carolina's protections are spread across targeted statutes that address identity theft, data breaches, Social Security number safeguards, student privacy, insurance data security, and public records confidentiality.
The most significant of these statutes is the Identity Theft Protection Act (N.C. Gen. Stat. Chapter 75, Article 2A), enacted in 2005 and amended several times since, most recently by Session Law 2025-25. It remains the cornerstone of the state's data protection framework.

The North Carolina Department of Information Technology (NCDIT) maintains the state's privacy program and has adopted the Fair Information Practice Principles (FIPPs) as a framework guiding how state agencies collect, use, and protect personal information. The Office of Privacy and Data Protection within NCDIT provides guidance, model policies, and technical assistance to state agencies.
North Carolina's data privacy framework covers these distinct areas through separate statutes:
- Data breach notification: G.S. 75-65
- Social Security number protections: G.S. 75-62
- Data disposal requirements: G.S. 75-64
- Student privacy protections: G.S. 115C-401.2 and G.S. 115C-402.5
- Insurance data security: G.S. Chapter 58, Article 39
- State employee personnel records: G.S. Chapter 126, Article 7
- Social Security numbers in government records: G.S. 132-1.10
Three bills introduced in the 2025-2026 legislative session would establish the state's first comprehensive consumer privacy law, but all remained in committee as of May 2026.
Identity Theft Protection Act (N.C. Gen. Stat. 75-60 through 75-66)
The Identity Theft Protection Act is North Carolina's most comprehensive data protection statute. It addresses multiple aspects of personal information protection: definitions of covered data, SSN restrictions, credit freezes, data disposal obligations, breach notification, and publication restrictions.
What Qualifies as Personal Information
Under G.S. 75-61, personal information means a person's first name or first initial and last name combined with any of the following: Social Security numbers, driver's license numbers, state identification card numbers, passport numbers, checking or savings account numbers, credit card or debit card numbers, Personal Identification (PIN) codes, electronic identification numbers or routing codes, digital signatures, biometric data, and fingerprints.
Personal information does not include publicly available directories containing information an individual has voluntarily consented to have publicly disseminated, such as name, address, and telephone number. It also excludes information lawfully available to the general public from federal, state, or local government records.
Social Security Number Protections (G.S. 75-62)

G.S. 75-62 places specific restrictions on how businesses handle Social Security numbers. Businesses operating in North Carolina may not intentionally communicate or make available an individual's Social Security number to the general public. Additional prohibitions include:
- Printing or embedding a Social Security number on any card required for accessing products or services
- Requiring individuals to transmit their Social Security number over the internet unless the connection is secure or the number is encrypted
- Requiring use of a Social Security number to access a website unless a password or unique personal identification number is also required
- Printing Social Security numbers on materials mailed to individuals, unless state or federal law requires it
- Selling, leasing, loaning, trading, renting, or otherwise intentionally disclosing a Social Security number to a third party without written consent when the disclosing party knows or should reasonably know the third party lacks a legitimate purpose
Exceptions apply when Social Security numbers are included in applications or enrollment documents, or when they are used to establish, amend, or terminate an account, contract, or policy.
Security Freeze Rights (G.S. 75-63)
Under G.S. 75-63, North Carolina consumers have the right to place a security freeze on their credit report. When a freeze is in place, a consumer reporting agency may not release credit report information to a third party without the consumer's prior express authorization.
A security freeze can be requested in writing by first-class mail, by telephone, or electronically. Consumer reporting agencies must remove a security freeze within 15 minutes of receiving an electronic removal request, or within three business days of receiving a written or telephonic request.
If a freeze is requested by telephone or mail, the consumer reporting agency may charge a fee not exceeding three dollars. No fee may be charged to consumers over the age of 62, to identity theft victims who have filed a report with law enforcement, or to the spouse of a qualifying identity theft victim. No additional fee may be charged for temporarily lifting, reinstating, or removing a freeze. Federal law under the Economic Growth, Regulatory Relief, and Consumer Protection Act also guarantees free credit freezes nationwide through the three major consumer reporting agencies.
Data Disposal Requirements (G.S. 75-64)
G.S. 75-64 requires any business that conducts business in North Carolina and maintains personal information of North Carolina residents to take reasonable measures to protect against unauthorized access to or use of that information in connection with or after its disposal.
Reasonable measures must include implementing and monitoring compliance with policies and procedures requiring the burning, pulverizing, or shredding of papers containing personal information. For electronic media, businesses must ensure the destruction or erasure of the media so that information cannot be practicably read or reconstructed. Businesses must also describe these disposal procedures as official policy in their written records.
A business may contract with a third party for record destruction after conducting due diligence. Due diligence should ordinarily include reviewing an independent audit of the disposal company's operations, obtaining references or requiring certification by a recognized trade association, or reviewing the disposal company's information security policies.
Data Breach Notification Requirements (G.S. 75-65)
North Carolina's data breach notification law under G.S. 75-65 establishes mandatory notification requirements when personal information is compromised. In 2025, the scope of this law was tested by a record-breaking year: the Attorney General's office received 2,349 breach reports affecting 9.3 million North Carolinians, the most since the law took effect in 2006.
Who Must Comply
Any business that owns or licenses personal information of North Carolina residents, or any business that conducts business in North Carolina and owns or licenses personal information in any form, whether computerized, paper, or otherwise, must comply with the breach notification law.
Government agencies are covered too, through a second statute rather than through Article 2A itself. G.S. 75-61(1) defines "business" to exclude any government or governmental subdivision or agency, but G.S. 132-1.10(c1) provides that if an agency of the State or its political subdivisions, or any agent or employee of a government agency, experiences a security breach, the agency must comply with the requirements of G.S. 75-65. The Attorney General's office describes the duty the same way, stating that a business, state or local government agency that owns or licenses records with personal information subject to a security breach must notify.
What Triggers Notification
A security breach is the unauthorized access to or acquisition of unencrypted or unredacted records or data containing personal information where illegal use of the personal information has occurred or is reasonably likely to occur, or that creates a material risk of harm to the affected person.
Notification Timeline
Notification must be made without unreasonable delay. The law permits delay consistent with the legitimate needs of law enforcement and any measures necessary to determine sufficient contact information, determine the scope of the breach, and restore the reasonable integrity, security, and confidentiality of the data system.
North Carolina does not specify a fixed number of days for notification, unlike some states that impose 30-day or 60-day deadlines. The "without unreasonable delay" standard gives businesses some flexibility but also exposes them to enforcement action if the Attorney General determines the delay was unreasonable.
Attorney General Reporting
Businesses must notify the Consumer Protection Division of the Attorney General's Office of the nature of the breach, the number of consumers affected, steps taken to investigate the breach, steps taken to prevent a similar breach in the future, and the timing, distribution, and content of the consumer notice.
Large-Scale Breaches
When a business provides notice to more than 1,000 persons at one time, it must also notify all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis (as defined in 15 U.S.C. 1681a(p)) of the timing, distribution, and content of the notice.
Third-Party Data Holders
Any business that maintains or possesses records or data containing personal information of North Carolina residents but does not own or license that information must notify the owner or licensee of the information immediately following discovery of the breach.
Publication of Personal Information (G.S. 75-66)
G.S. 75-66 makes it a violation to knowingly broadcast or publish another person's personal information to the public (on radio, television, in writing, or on the internet) with actual knowledge that the person previously objected to the disclosure. Covered personal information includes Social Security numbers, employer taxpayer identification numbers, driver's license numbers, state identification card numbers, and passport numbers.
The law does not apply to the collection, use, or release of personal information for a purpose permitted, authorized, or required by any federal, state, or local law, regulation, or ordinance. Any person whose property or person is injured by a violation of this section may sue for civil damages under G.S. 1-539.2C.
Identity Theft Criminal Penalties (G.S. 14-113.20)
North Carolina criminalizes identity theft under G.S. 14-113.20. A person who knowingly obtains, possesses, or uses identifying information of another person, living or dead, with the intent to fraudulently represent themselves as that person for financial or credit transactions, to obtain anything of value, or to avoid legal consequences is guilty of a felony.
G.S. 14-113.20(a) defines the offense but does not classify it; it makes the offense "a felony punishable as provided in G.S. 14-113.22(a)." Under G.S. 14-113.22(a), a violation is punishable as a Class G felony, except that it is punishable as a Class F felony if the victim suffers arrest, detention, or conviction as a proximate result of the offense, or the person is in possession of identifying information pertaining to three or more separate persons.
Under G.S. 14-113.20A, it is unlawful to sell, transfer, or purchase another person's identifying information with the intent to commit identity theft or to assist someone else in committing it. That offense, trafficking in stolen identities, is punishable as a Class E felony under G.S. 14-113.22(a1).
G.S. 14-113.22(a2) allows the court to order a person convicted under G.S. 14-113.20 or G.S. 14-113.20A to pay restitution for financial loss caused by the violation, which may include actual losses, lost wages, attorneys' fees, and other costs incurred by the victim in correcting credit history or in connection with any criminal, civil, or administrative proceeding brought against the victim.
Student Data Privacy Protections
North Carolina has enacted multiple statutes protecting student data, reflecting a strong commitment to safeguarding children's information in educational settings.

Student Online Privacy Protection (G.S. 115C-401.2)
The Student Online Privacy Protection Act (G.S. 115C-401.2) regulates how operators of educational technology platforms handle student information. An operator is defined as the operator of a website, online service, online application, or mobile application with actual knowledge that it is used primarily for K-12 school purposes and was designed and marketed for K-12 school purposes.
Covered information includes a broad range of personally identifiable data: first and last name, home address, telephone number, email address, discipline records, test results, special education data, juvenile dependency records, medical and health records, Social Security numbers, biometric information, socioeconomic information, food purchases, political affiliations, religious information, text messages, student identifiers, search activity, voice recordings, and geolocation information.
Operators are prohibited from engaging in targeted advertising based on information acquired through use of their platform for K-12 school purposes. They cannot use information gathered through their platform to amass a profile about a student except in furtherance of K-12 school purposes. They cannot sell or rent a student's information.
Student Data System Security (G.S. 115C-402.5)
G.S. 115C-402.5 establishes security requirements for student data systems and prohibits collection of certain categories of information. The following data about a student or student's family may not be collected in or reported as part of the student data system: biometric information, political affiliation, religion, and voting history.
Parents' Bill of Rights (SB 49 / Session Law 2023-106)
The Parents' Bill of Rights, enacted in 2023, strengthened parental rights regarding student data. Schools must provide parents with information about their rights under state and federal law regarding student records, including opt-out opportunities for directory information disclosure under FERPA. The law restricts collection of data about students' political affiliations, beliefs, sex behavior or attitudes, and illegal or demeaning behavior.
The relevance of these statutes was demonstrated in December 2024, when PowerSchool, a company that sells software products used by schools across the country, was hacked. The breach potentially exposed Social Security numbers, addresses, and medical and disciplinary information of approximately 4 million North Carolinians. Attorney General Jeff Jackson opened a formal investigation and issued a Civil Investigative Demand to PowerSchool in early 2025.
Insurance Data Security (G.S. Chapter 58, Article 39)
North Carolina regulates the handling of personal information by insurance companies through the Consumer and Customer Information Privacy Act (G.S. Chapter 58, Article 39). This article contains two key components.
Insurance Information and Privacy Protection Act
Insurance institutions, agents, and insurance-support organizations may not disclose personal or privileged information collected in connection with an insurance transaction unless the disclosure is authorized by law or regulation.
Under G.S. 58-39-25, insurance institutions must provide a notice of information practices to all applicants or policyholders. For policy renewals, the notice must be provided no later than the policy renewal date, except that no notice is required if a compliant notice was already given within the previous 24 months.
Customer Information Safeguards Act
The Customer Information Safeguards Act requires insurance companies to maintain policies that protect the confidentiality and security of nonpublic personal information and safeguard that information from unauthorized access.
Public Records and Government Data Protection
Social Security Numbers in Public Records (G.S. 132-1.10)
G.S. 132-1.10 protects Social Security numbers and other personal identifying information in government records. Identifying information is confidential and not considered a public record under Chapter 132. A record with identifying information removed or redacted remains a public record.
The same section also carries the state and local government breach-notification duty: under subsection (c1), an agency of the State or its political subdivisions, or any agent or employee of a government agency, that experiences a security breach must comply with G.S. 75-65, the same notification statute that applies to businesses.
Government agencies may not fail to segregate Social Security numbers on a separate page from the rest of the record when collecting them. Upon request, they must provide a statement of the purpose for which the Social Security number is being collected and used. Records of the register of deeds, the Department of the Secretary of State, or the courts may not include any person's Social Security number unless expressly required by law or court order.
State Employee Personnel Records (G.S. Chapter 126, Article 7)
G.S. Chapter 126, Article 7 protects the privacy of state employee personnel records. Under G.S. 126-22, personnel files are not subject to general public inspection.
Health Information Privacy
North Carolina aligns its health information privacy protections with federal HIPAA standards while maintaining additional state-specific provisions. G.S. 143-518 addresses confidentiality of patient information for medical records compiled by the Department of Health and Human Services, hospitals participating in the statewide trauma system, and EMS providers, specifically in connection with dispatch, response, treatment, or transport of patients or the statewide trauma registry under Article 7 of Chapter 131E.
The North Carolina Health Information Exchange Authority ensures that privacy and security safeguards for health data exchanged electronically meet or exceed federal, state, and local requirements, including the HIPAA Privacy Rule, HIPAA Security Rule, and HITECH Act. The NC Department of Public Instruction maintains separate data privacy and policy guidance for the K-12 education context.
Federal Privacy Laws Covering North Carolina Residents
Because North Carolina lacks a comprehensive state consumer privacy law, federal statutes provide significant baseline protection for North Carolina residents.

TAKE IT DOWN Act (Pub. L. 119-12, signed May 19, 2025). This federal law criminalizes the nonconsensual publication of intimate images, including AI-generated deepfakes (nonconsensual intimate images, or NCII). Criminal prohibitions took effect immediately upon signing. Covered online platforms were required to establish notice-and-removal processes by May 19, 2026, with FTC enforcement beginning on that date. North Carolina residents who are victims of NCII have both a federal criminal remedy and can report to the FTC.
Health Insurance Portability and Accountability Act (HIPAA). HIPAA governs how healthcare providers, insurers, and their business associates handle protected health information. The HIPAA Privacy Rule and Security Rule apply to covered entities in North Carolina regardless of whether state law imposes additional requirements.
Gramm-Leach-Bliley Act (GLBA). GLBA requires financial institutions to explain their information-sharing practices and safeguard sensitive data. North Carolina financial institutions operating under federal charters or state licenses must comply with GLBA's privacy notices and data security requirements.
Fair Credit Reporting Act (FCRA) and FACTA. FCRA regulates how consumer reporting agencies collect, access, use, and distribute credit information. FACTA's disposal rule requires businesses to dispose of consumer report information securely. North Carolina's G.S. 75-64 parallels the FACTA disposal rule for personal information generally.
Children's Online Privacy Protection Act (COPPA). COPPA restricts the collection of personal information from children under 13 by website operators. Operators serving North Carolina children must obtain verifiable parental consent before collecting, using, or disclosing personal information.
FTC Act Section 5. The Federal Trade Commission's authority to prevent unfair or deceptive acts or practices in commerce extends to data security failures. The FTC has taken enforcement action against companies that made material misrepresentations about their data security or failed to maintain reasonable safeguards, without a state comprehensive privacy law being required.
American Privacy Rights Act (APRA). A bipartisan federal comprehensive privacy bill, APRA, was introduced in the 118th Congress in 2024 but did not pass. The bill expired when the 118th Congress ended in January 2025 and has not been re-enacted as of May 2026. No federal comprehensive consumer privacy law is currently in effect.
Pending Legislation: North Carolina's Path to Comprehensive Privacy Law
Three bills introduced in the 2025-2026 legislative session would create North Carolina's first comprehensive consumer data privacy protections. None had been enacted as of May 2026.

House Bill 462: NC Personal Data Privacy Act and Social Media Safety Act
House Bill 462, introduced in the 2025-2026 session, contains two substantive parts. Part I would enact the North Carolina Personal Data Privacy Act, creating a new Chapter 75F of the General Statutes. Part II would enact the Social Media Safety Act, requiring social media platforms to use commercial age-verification systems before allowing North Carolina minors to open accounts.
Consumer rights under Part I. The bill would grant North Carolina consumers six key rights: the right to confirm whether a controller is processing their personal data and to access that data; the right to correct inaccuracies; the right to delete personal data; the right to obtain a portable copy of their data; the right to opt out of targeted advertising, data sales, and profiling; and the right to have an authorized agent exercise these rights on their behalf.
Scope thresholds. The bill would apply to entities that conduct business in North Carolina or target products or services to North Carolina residents and either control or process the personal data of at least 35,000 consumers (excluding data processed solely for payment transactions), or control or process the personal data of at least 10,000 consumers and derive more than 20 percent of gross revenue from the sale of personal data.
Enforcement. Exclusive enforcement authority would reside with the North Carolina Attorney General, with a 60-day cure period before initiating an enforcement action.
Status. As of May 2026, HB 462 was re-referred to the Committee on Commerce and Economic Development on April 29, 2025. It has not advanced to a floor vote.
Senate Bill 757: Consumer Privacy Act
Senate Bill 757, introduced March 2025, is a separate comprehensive consumer privacy bill in the Senate. The bill would establish the Consumer Privacy Act and provide residents with rights to access, correct, delete, and opt out of sales and targeted advertising. SB 757 remained in committee as of May 2026.
Senate Bill 963: AI Chatbots Safety and Privacy
Senate Bill 963 addresses privacy and safety obligations specific to AI chatbot operators, including age-verification, disclosure, and data-handling requirements. The bill remained in committee as of May 2026.
Tracking pending legislation. North Carolina residents and businesses should monitor ncleg.gov for updates on all three bills. The 2025-2026 session is a long session; legislation can move quickly once a bill reaches the floor.
Attorney General Enforcement
The North Carolina Attorney General's Consumer Protection Division plays a central role in enforcing data privacy protections. Attorney General Jeff Jackson took office in January 2025 and has made data privacy enforcement a priority from his first months in office.
2025 Record Breach Statistics
The 2025 North Carolina Data Breach Report recorded 2,349 data breaches reported to the Department of Justice, the highest total since reporting began in 2006, exposing approximately 9.3 million North Carolinians. Hacking-related incidents caused 77 percent of all reported breaches. Since 2006, businesses have reported 19,318 total breaches impacting over 40 million people in all.
PowerSchool Investigation (2025)
In December 2024, PowerSchool, a company that sells software products used by schools across the country, was hacked, potentially exposing Social Security numbers, addresses, and medical and disciplinary information of 62.4 million current and former students and teachers nationally, including nearly 4 million people in North Carolina. Attorney General Jackson issued a Civil Investigative Demand to PowerSchool to obtain detailed information about the cause of the breach and the company's data security practices. The investigation was ongoing as of the publication date.
23andMe Genetic Data Lawsuit
Attorney General Jackson filed a lawsuit in 2025 against 23andMe in bankruptcy court to prevent the sale of North Carolinians' sensitive genetic information without their knowledge or consent. Jackson secured a consent order appointing a consumer privacy ombudsman to advocate for customers' privacy and security interests throughout the sale process. The case raised questions about the adequacy of North Carolina's existing privacy framework for protecting genetic and health-adjacent data outside of HIPAA.
DOGE Data-Sharing Injunction
In February 2025, a federal judge blocked the federal government from sharing North Carolinians' financial data with the Department of Government Efficiency (DOGE) following a lawsuit brought by Attorney General Jackson. The court held that the planned data-sharing raised serious concerns about the lawful use of sensitive personal and financial information.
AI Task Force
In 2025, Attorney General Jackson formed a bipartisan, nationwide AI task force alongside Utah Attorney General Derek Brown. The task force collaborates with leading AI developers, including OpenAI and Microsoft, to identify emerging privacy risks from AI-enabled misuse, promote responsible innovation, and develop consumer protection safeguards.
Major Prior Enforcement Settlements
Two significant multistate settlements from the prior administration remain precedent for North Carolina's data breach enforcement posture. A $52 million settlement with Marriott International resolved investigations into a multi-year data breach that affected hundreds of millions of guests, with North Carolina receiving $2,059,176. A $49.5 million settlement with Blackbaud addressed deficient data security practices and the company's response to a 2020 ransomware attack that exposed personal information of millions of nonprofit donors and healthcare organizations.
Unfair and Deceptive Trade Practices
The Attorney General can pursue data privacy violations under North Carolina's Unfair and Deceptive Trade Practices Act (G.S. Chapter 75, Article 1), which prohibits unfair or deceptive acts in commerce. A business that misrepresents its data security practices or fails to protect consumer data may face enforcement under this statute independent of a specific breach notification violation.
Practical Steps for North Carolina Residents
North Carolina residents can take several steps to protect their personal information under existing law.
You have the right to place a free or low-cost security freeze on your credit report with each of the three major credit bureaus. No fee may be charged if you are over age 62 or an identity theft victim who has filed a law enforcement report. Monitor your credit reports for unauthorized accounts or new account openings.
If you are a victim of identity theft, file a report with your local law enforcement agency and the NC Attorney General's office. The AG's office provides a breach reporting portal and identity theft resources at ncdoj.gov.
Parents of K-12 students should review their school's data privacy policies and exercise opt-out rights for directory information. Request information about which educational technology vendors have access to your child's data. The 2025 PowerSchool breach, which exposed 4 million North Carolinians' student records, underscores that school software vendors are a significant attack surface.
If you receive a data breach notification, take it seriously. Change passwords for affected accounts, monitor financial statements, and consider placing a fraud alert or security freeze on your credit file. If the breach involved genetic or medical data (similar to the 23andMe situation), contact the Attorney General's office to report any suspected misuse.
Practical Steps for Businesses Operating in North Carolina

Businesses that collect personal information from North Carolina residents have several legal obligations under current law, regardless of whether a comprehensive privacy statute is enacted.
Develop and implement a written data disposal policy that includes shredding paper records and destroying electronic media in accordance with G.S. 75-64. Establish a breach response plan that includes notifying affected consumers and the Attorney General without unreasonable delay under G.S. 75-65.
Review your handling of Social Security numbers to ensure compliance with G.S. 75-62. Never transmit Social Security numbers over unsecured internet connections. Do not print them on mailed materials unless required by law.
If you use educational technology platforms in K-12 settings, ensure your vendors comply with G.S. 115C-401.2 restrictions on targeted advertising, profiling, and data sales. Maintain written contracts with vendors that address breach notification obligations.
Monitor the status of HB 462, SB 757, and SB 963 in the 2025-2026 legislative session. If any of these bills passes, businesses meeting the applicable thresholds will need to implement consumer rights processes, data processing agreements, data protection assessments, and privacy notices before the effective date.
If you are an insurance company or insurance-related entity, review your obligations under G.S. Chapter 58, Article 39 regarding privacy notices and customer information safeguards.
Consider whether the federal TAKE IT DOWN Act (Pub. L. 119-12) affects your platform. If you operate an interactive online service that allows users to post content, FTC enforcement of platform takedown obligations began May 19, 2026.
More North Carolina Laws
Frequently Asked Questions
Does North Carolina have a comprehensive consumer data privacy law?
No. As of May 2026, North Carolina does not have a comprehensive consumer data privacy law comparable to California's CCPA or Virginia's VCDPA. The state relies on a patchwork of targeted statutes, primarily the Identity Theft Protection Act (G.S. 75-60 through 75-66). Three bills introduced in the 2025-2026 session would change that: House Bill 462 (NC Personal Data Privacy Act plus Social Media Safety Act), Senate Bill 757 (Consumer Privacy Act), and Senate Bill 963 (AI chatbot safety and privacy). None had been enacted as of May 2026.
How quickly must businesses notify North Carolina residents of a data breach?
North Carolina law requires notification 'without unreasonable delay' under G.S. 75-65 but does not set a specific number of days. Delays are permitted for law enforcement needs and to determine the scope of the breach. Businesses must also report breach details to the Attorney General's Consumer Protection Division. For breaches affecting more than 1,000 people, the three major consumer reporting agencies must also be notified.
What are the penalties for identity theft in North Carolina?
Identity theft is defined by G.S. 14-113.20 and punished under G.S. 14-113.22(a), which makes it a Class G felony. If the victim suffers arrest, detention, or conviction as a proximate result, or if the offender possesses identifying information of three or more separate people, the offense is a Class F felony. Trafficking in stolen identities under G.S. 14-113.20A is a Class E felony under G.S. 14-113.22(a1). Under G.S. 14-113.22(a2), the court may also order restitution for financial loss, which can include lost wages, attorneys' fees, and costs of correcting credit history.
Can I place a security freeze on my credit report in North Carolina for free?
If you request a freeze by telephone or mail, the consumer reporting agency may charge up to $3.00. However, no fee may be charged to consumers over age 62, identity theft victims who have filed a law enforcement report, or their spouses. Electronic freeze requests and any requests to temporarily lift, reinstate, or remove a freeze are free of charge. Federal law under the Economic Growth, Regulatory Relief, and Consumer Protection Act also guarantees free credit freezes through the major reporting agencies.
How does North Carolina protect student data privacy?
North Carolina has multiple student data privacy protections. G.S. 115C-401.2 prohibits operators of educational technology platforms from targeted advertising based on student data, building non-educational profiles on students, or selling student information. G.S. 115C-402.5 bans collection of biometric data, political affiliations, and voting history in student data systems. The 2023 Parents' Bill of Rights (SB 49) strengthened parental rights to inspect records and opt out of directory information disclosure.
What has Attorney General Jeff Jackson done on data privacy since taking office in January 2025?
Attorney General Jeff Jackson has pursued several significant data privacy enforcement actions. He investigated PowerSchool over a breach that exposed records of 4 million North Carolinians. He filed a lawsuit to prevent 23andMe from selling North Carolinians' genetic data in bankruptcy, securing a consent order appointing a privacy ombudsman. He won a temporary restraining order blocking DOGE from accessing North Carolinians' financial data. He also formed a bipartisan AI task force with Utah's AG to address AI-enabled privacy risks. In 2025, his office reported a record 2,349 data breaches affecting 9.3 million North Carolinians.
What is the TAKE IT DOWN Act and how does it affect North Carolina residents?
The TAKE IT DOWN Act (Pub. L. 119-12) is a federal law signed on May 19, 2025, that criminalizes the nonconsensual publication of intimate images, including AI-generated deepfakes. Criminal prohibitions took effect immediately upon signing. Online platforms were required to establish notice-and-removal processes by May 19, 2026, with FTC enforcement beginning on that date. North Carolina residents who are victims of nonconsensual intimate image publication can report violations to the FTC and may have criminal remedies available at the federal level.
Does North Carolina have a biometric data privacy law?
North Carolina does not have a standalone biometric data privacy law comparable to Illinois' BIPA. However, biometric data is included in the definition of personal information under G.S. 75-61, meaning unauthorized acquisition of biometric data can trigger breach notification obligations under G.S. 75-65. The student data statutes (G.S. 115C-402.5) expressly prohibit collection of biometric information in the student data system. If HB 462 or SB 757 passes, sensitive data definitions in those bills would likely include biometric data with heightened protections.
Updates
Corrected the Identity Theft Protection Act amendment history, added the G.S. 132-1.10(c1) breach-notification duty that applies to state and local government agencies, and re-attributed the identity-theft felony classifications and restitution rules to G.S. 14-113.22.
Corrected the name of the 2023 North Carolina student-data-privacy law referenced in the Student Data Privacy section: it is the Parents' Bill of Rights (SB 49 / Session Law 2023-106), not the Protect Our Students Act (a different, unrelated 2023 law addressing educator misconduct penalties).
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Corrected 4 statute-attribution/legal-fact errors verified against primary sources.
Governing law re-checked for recent changes
Governing law re-checked for recent changes
May 2026 refresh: Updated Attorney General section to reflect Jeff Jackson (in office Jan 2025, replacing Josh Stein who became Governor). Added 2025 record breach statistics (2,349 breaches, 9.3M NC residents exposed per NCDOJ 2025 Data Breach Report). Added AG Jackson enforcement actions: PowerSchool investigation (CID issued; 4M NC students), 23andMe genetic data lawsuit (consent order with privacy ombudsman), DOGE data-sharing TRO (Feb 2025), and AI task force with Utah AG. Added TAKE IT DOWN Act (Pub. L. 119-12, signed May 19, 2025; FTC enforcement effective May 19, 2026). Added SB 757 (Consumer Privacy Act) and SB 963 (AI Chatbots) as additional pending bills alongside HB 462. Confirmed HB 462 still in committee (re-referred April 29, 2025). Confirmed G.S. 58-39A (NAIC Insurance Data Security Model Law) has NOT been enacted in NC as of May 2026. Clarified APRA did not pass and is not current law. Added 3 new FAQs (Jeff Jackson enforcement priorities, TAKE IT DOWN Act, biometric data). Updated KeyTakeaways to 7 bullets. Added 9 new citations (total: 35).
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
North Carolina General Statutes, Chapter 75: Monopolies, Trusts and Consumer Protection.
§ 75-65Protection from security breachesIn forcecited in 4 of our articles
(a) Any business that owns or licenses personal information of residents of North Carolina or any business that conducts business in North Carolina that owns or licenses personal information in any form (whether computerized, paper, or otherwise) shall provide notice to the affected person that there has been a security breach following discovery or notification of the breach. The disclosure notification shall be made without unreasonable delay, consistent with the legitimate needs of law enforcement, as provided in subsection (c) of this section, and consistent with any measures necessary to determine sufficient contact information, determine the scope of the breach and restore the reasonable integrity, security, and confidentiality of the data system. For the purposes of this section, personal information shall not include electronic identification numbers, email names or addresses, internet account numbers, internet identification names, parent's legal surname prior to marriage, or a password unless this information would permit access to a person's financial account or resources.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at ncleg.gov
Cited in 2 court opinions in our collectionLatest citing opinion in our collection: 2025
Opinions citing this section in our collection:
- Rogers v. Keffer, Inc. (District Court, E.D. North Carolina 2017, 243 F. Supp. 3d 650)“…TPA for failing to notify the victim of a security breach. N.C. Gen. Stat. § 75-65 . “Any business that maintains or posse…”
- Rhodes v. Navy Federal Credit Union (District Court, E.D. North Carolina 2025)“…n. Stat. § 53-176; 5) “financial privacy violation,” under N.C. Gen. Stat. § 75-65; and 6) intentional infliction of emot…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: North Carolina Data Breach Notification Laws: Reporting Rules & Timelines (2026), North Carolina Employee Monitoring Laws: Workplace Surveillance and Social Media (2026), North Carolina Biometric Privacy Laws: Collection, Consent & Penalties (2026)
§ 75-62Social security number protectionIn force
(a) Except as provided in subsection (b) of this section, a business may not do any of the following: (1) Intentionally communicate or otherwise make available to the general public an individual's social security number. (2) Intentionally print or imbed an individual's social security number on any card required for the individual to access products or services provided by the person or entity. (3) Require an individual to transmit his or her social security number over the internet, unless the connection is secure or the social security number is encrypted. (4) Require an individual to use his or her social security number to access a website, unless a password or unique personal identification number or other authentication device is also required to access the website. (5) Print an individual's social security number on any materials that are mailed to the individual, unless state or federal law requires the social security number to be on the document to be mailed.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at ncleg.gov
Cited in 3 court opinions in our collectionLatest citing opinion in our collection: 2017
Opinions citing this section in our collection:
- Fisher v. Commc'n Workers of Am. (North Carolina Business Court 2008, 2008 NCBC 18)“…orth Carolina Identity Theft Protection Act (the “NCITPA”), N.C. Gen. Stat. § 75-62; (2) violated the Unfair and Deceptive…”
- Rogers v. Keffer, Inc. (District Court, E.D. North Carolina 2017, 243 F. Supp. 3d 650)“…e for obtaining the individual’s social security' number.” N.C. Gen. Stat. § 75-62 (a)(6). Rogers’s NCITPA claim arises fr…”
- Maple v. Colonial Orthopaedics, Inc. (In Re Maple) (United States Bankruptcy Court, E.D. Virginia 2010, 434 B.R. 363)“…olina’s Unfair and Deceptive Trade Practices Act ("UDTPA”). N.C. Gen.Stat. §§ 75-62(a)(1), 75-62(d) (2010). North Carolina'…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 75-63Security freezeIn force
(a) A consumer may place a security freeze on the consumer's credit report by making a request to a consumer reporting agency in accordance with this subsection. A security freeze shall prohibit, subject to exceptions in subsection (l) of this section, the consumer reporting agency from releasing the consumer's credit report or any information from it without the express authorization of the consumer. When a security freeze is in place, a consumer reporting agency may not release the consumer's credit report or information to a third party without prior express authorization from the consumer. This subsection does not prevent a consumer reporting agency from advising a third party that a security freeze is in effect with respect to the consumer's credit report, provided that the consumer reporting agency does not state or otherwise imply to the third party that the consumer's security freeze reflects a negative credit score, history, report, or rating. A consumer reporting agency shall place a security freeze on a consumer's credit report if the consumer requests a security freeze by any of the following methods: (1) First-class mail. (2) Telephone call.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at ncleg.gov
§ 75-64Destruction of personal information recordsIn force
(a) Any business that conducts business in North Carolina and any business that maintains or otherwise possesses personal information of a resident of North Carolina must take reasonable measures to protect against unauthorized access to or use of the information in connection with or after its disposal. (b) The reasonable measures must include: (1) Implementing and monitoring compliance with policies and procedures that require the burning, pulverizing, or shredding of papers containing personal information so that information cannot be practicably read or reconstructed. (2) Implementing and monitoring compliance with policies and procedures that require the destruction or erasure of electronic media and other nonpaper media containing personal information so that the information cannot practicably be read or reconstructed. (3) Describing procedures relating to the adequate destruction or proper disposal of personal records as official policy in the writings of the business entity.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at ncleg.gov
§ 75-66Publication of personal informationIn force
(a) It shall be a violation of this section for any person to knowingly broadcast or publish to the public on radio, television, cable television, in a writing of any kind, or on the internet, the personal information of another with actual knowledge that the person whose personal information is disclosed has previously objected to any such disclosure. (b) As used in this section, "person" means any individual, partnership, corporation, trust, estate, cooperative, association, or other entity, but does not include any: (1) Government, government subdivision or agency. (2) Entity subject to federal requirements pursuant to the Health Insurance Portability and Accountability Act (HIPAA). (c) As used in this section, the phrase "personal information" includes a person's first name or first initial and last name in combination with any of the following information: (1) Social security or employer taxpayer identification numbers. (2) Drivers license, State identification card, or passport numbers. (3) Checking account numbers. (4) Savings account numbers. (5) Credit card numbers. (6) Debit card numbers. (7) Personal Identification (PIN) Code as defined in G.S. 14-113.8(6).
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at ncleg.gov
Cited in 2 court opinions in our collectionLatest citing opinion in our collection: 2025
Opinions citing this section in our collection:
- Ehmann v. Medflow, Inc. (North Carolina Business Court 2020, 2020 NCBC 30)“…and publication of personal information in violation of N.C.G.S. § 75-66. (Medflow Defs. Answer & Countercl. 36–…”
- Rhodes v. Navy Federal Credit Union (District Court, E.D. North Carolina 2025)“…able. However, elsewhere in her complaint plaintiff cites N.C. Gen. Stat. § 75-66, which prohibits certain publications o…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 75-61DefinitionsIn forcecited in 3 of our articles
The following definitions apply in this Article: (1) "Business". - A sole proprietorship, partnership, corporation, association, or other group, however organized and whether or not organized to operate at a profit. The term includes a financial institution organized, chartered, or holding a license or authorization certificate under the laws of this State, any other state, the United States, or any other country, or the parent or the subsidiary of any such financial institution. Business shall not include any government or governmental subdivision or agency. (2) "Consumer". - An individual. (3) "Consumer report" or "credit report". - Any written, oral, or other communication of any information by a consumer reporting agency bearing on a consumer's creditworthiness, credit standing, credit capacity, character, general reputation, personal characteristics, or mode of living which is used or expected to be used or collected in whole or in part for the purpose of serving as a factor in establishing the consumer's eligibility for any of the following: a. Credit to be used primarily for personal, family, or household purposes. b. Employment purposes. c.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at ncleg.gov
Cited in 4 court opinions in our collectionLatest citing opinion in our collection: 2025
Opinions citing this section in our collection:
- Fisher v. Commc'n Workers of Am. (North Carolina Business Court 2008, 2008 NCBC 18)“…nized and whether or not organized to operate at a profit.” N.C. Gen. Stat. § 75-61(1) (2007). {48} A business does not…”
- DiCesare v. Charlotte-Mecklenburg Hosp. Auth. (Supreme Court of North Carolina 2020)“…chase of electricity or other municipal utilities) and N.C.G.S. § 75-61(9) (adopting a separate definition of…”
- Rogers v. Keffer, Inc. (District Court, E.D. North Carolina 2017, 243 F. Supp. 3d 650)“…s and is not subject to further unauthorized disclosure. N.C. Gen. Stat. § 75-61 (14). A plaintiff must bring a claim fo…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
North Carolina General Statutes, Chapter 115C: Elementary and Secondary Education.
§ 115C-401.2Student online privacy protectionIn force
(a) Definitions. - The following definitions apply in this section: (1) Covered information. - Personally identifiable information or material in any media or format that is any of the following: a. Created by or provided to an operator by a student, or the student's parent or legal guardian, in the course of the student's, parent's, or legal guardian's use of the operator's site, service, or application for K-12 school purposes. b. Created by or provided to an operator by an employee or agent of a K-12 school or local school administrative unit for K-12 school purposes. c. Gathered by an operator through the operation of a site, service, or application for K-12 school purposes and personally identifies a student, including, but not limited to, the following: 1. Information in the student's educational record or email. 2. First and last name. 3. Home address. 4. Telephone number. 5. Email address. 6. Other information that allows physical or online contact. 7. Discipline records. 8. Test results. 9. Special education data. 10. Juvenile dependency records. 11. Grades. 12. Evaluations. 13. Criminal records. 14. Medical records. 15. Health records. 16.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at ncleg.gov
§ 115C-402.5Student data system securityIn force
(a) Definitions. - The following definitions apply in this section: (1) Aggregate student data. - Data collected or reported at the group, cohort, or institutional level. (2) De-identified student data. - A student dataset in which parent and student personal or indirect identifiers, including the unique student identifier, have been removed. (3) FERPA. - The federal Family Educational Rights and Privacy Act, 20 U.S.C. § 1232g. (4) Personally identifiable student data. - Student data that: a. Includes, but is not limited to, the following: 1. Student name. 2. Name of the student's parent or other family members. 3. Address of the student or student's family. 4. Personal identifier, such as the student's Social Security number or unique student identifier. 5. Other indirect identifiers, such as the student's date of birth, place of birth, and mother's maiden name. 6. Other information that, alone or in combination, is linked or linkable to a specific student that would allow a reasonable person in the school community, who does not have personal knowledge of the relevant circumstances, to identify the student with reasonable certainty. 7.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at ncleg.gov
North Carolina General Statutes, Chapter 143: State Departments, Institutions, and Commissions
§ 143-518Confidentiality of patient informationIn force
(a) Medical records compiled and maintained by the Department, hospitals participating in the statewide trauma system, or EMS providers in connection with dispatch, response, treatment, or transport of individual patients or in connection with the statewide trauma system pursuant to Article 7 of Chapter 131E of the General Statutes may contain patient identifiable data which will allow linkage to other health care-based data systems for the purposes of quality management, peer review, and public health initiatives. These medical records and data shall be strictly confidential and shall not be considered public records within the meaning of G.S. 132-1 and shall not be released or made public except under any of the following conditions: (1) Release is made of specific medical or epidemiological information for statistical purposes in a way that no person can be identified. (2) Release is made of all or part of the medical record with the written consent of the person or persons identified or their guardians. (3) Release is made to health care personnel providing medical care to the patient. (4) Release is made pursuant to a court order.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at ncleg.gov
North Carolina General Statutes, Chapter 58: Insurance.
§ 58-39-25Notice of insurance information practicesIn force
(a) An insurance institution or agent shall provide a notice of information practices to all applicants or policyholders in connection with insurance transactions as provided in this section: (1) In the case of an application for insurance a notice shall be provided no later than: a. At the time of the delivery of the insurance policy or certificate when personal information is collected only from the applicant or from public records; or b. At the time the collection of personal information is initiated when personal information is collected from a source other than the applicant or public records; (2) In the case of a policy renewal, a notice shall be provided no later than the policy renewal date, except that no notice shall be required in connection with a policy renewal if: a. Personal information is collected only from the policyholder or from public records; or b.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at ncleg.gov
North Carolina General Statutes, Chapter 132: Public Records.
§ 132-1.10Social security numbers and other personal identifying informationIn force
(a) The General Assembly finds the following: (1) The social security number can be used as a tool to perpetuate fraud against a person and to acquire sensitive personal, financial, medical, and familial information, the release of which could cause great financial or personal harm to an individual. While the social security number was intended to be used solely for the administration of the federal Social Security System, over time this unique numeric identifier has been used extensively for identity verification purposes and other legitimate consensual purposes. (2) Although there are legitimate reasons for State and local government agencies to collect social security numbers and other personal identifying information from individuals, government should collect the information only for legitimate purposes or when required by law. (3) When State and local government agencies possess social security numbers or other personal identifying information, the governments should minimize the instances this information is disseminated either internally within government or externally with the general public.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at ncleg.gov
Cited in 3 court opinions in our collectionLatest citing opinion in our collection: 2023
Opinions citing this section in our collection:
- Fulmore v. Howell (Court of Appeals of North Carolina 2008, 189 N.C. App. 93)“…7, 88 Stat. 1909 ; 5 U.S.C. § 552a(b)(ll) (1974). N.C. Gen. Stat. § 132-1.10 (2007), also recognizes the importance…”
- Mughal v. Mesbahi (Court of Appeals of North Carolina 2021)“…en for potential identify theft. See generally N.C.G.S. § 132-1.10(a)(1) (2019) (“The General Assembly fin…”
- THE MCCLATCHY COMPANY v. TOWN OF CHAPEL HILL, NORTH CAROLINA (District Court, M.D. North Carolina 2023)“…ts is protected as personal-identifying information under N.C. Gen. Stat. § 132-1.10. (ECF No. 34 at 14–18.) Defendant la…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
North Carolina General Statutes, Chapter 14: Criminal Law.
§ 14-113.20Identity theftIn forcecited in 4 of our articles
(a) A person who knowingly obtains, possesses, or uses identifying information of another person, living or dead, with the intent to fraudulently represent that the person is the other person for the purposes of making financial or credit transactions in the other person's name, to obtain anything of value, benefit, or advantage, or for the purpose of avoiding legal consequences is guilty of a felony punishable as provided in G.S. 14-113.22(a). (b) The term "identifying information" as used in this Article includes the following: (1) Social security or employer taxpayer identification numbers. (2) Drivers license, State identification card, or passport numbers. (3) Checking account numbers. (4) Savings account numbers. (5) Credit card numbers. (6) Debit card numbers. (7) Personal Identification (PIN) Code as defined in G.S. 14-113.8(6). (8) Electronic identification numbers, email names or addresses, internet account numbers, or internet identification names. (9) Digital signatures. (10) Any other numbers or information that can be used to access a person's financial resources. (11) Biometric data. (12) Fingerprints. (13) Passwords.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at ncleg.gov
Cited in 19 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):State v. Jones (2014) held that signing a name different from the cardholder's does not escape Section 14-113.20, since possession of others' credit card numbers supported an inference of fraudulent intent. State v. Barron (2010) held that confirming another's social security digits to police was a use of identifying information.
Opinions citing this section in our collection:
- State v. Jones (Supreme Court of North Carolina 2014, 367 N.C. 299)✓A man possessed four people's credit card numbers and had used other victims' numbers under false names at two businesses; the court held that evidence supported the fraudulent intent element of section 14-113.20(a), and that signing a different name does not defeat it.
- State v. Barron (Court of Appeals of North Carolina 2010, 202 N.C. App. 686)✓Stopped by police, a man gave his brother's name and birth date and confirmed the last four digits of his brother's Social Security number; the court held that confirmation was itself a use of another person's identifying information under section 14-113.20(a).
- State v. Crook (Court of Appeals of North Carolina 2016, 247 N.C. App. 784)✓A man carried another man's driver license, accepted arrest warrants in that name, and used it on a bond application; the court found no plain error in instructing that the license was identifying information, since the license carries the number named in section 14-113.20(b)(2).
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: North Carolina Identity Theft Laws: Penalties, Restitution, and Victim Resources
§ 14-113.20ATrafficking in stolen identitiesIn force
(a) It is unlawful for a person to sell, transfer, or purchase the identifying information of another person with the intent to commit identity theft, or to assist another person in committing identity theft, as set forth in G.S. 14-113.20. (b) A violation of this section is a felony punishable as provided in G.S. 14-113.22(a1). (2002-175, s. 5; 2005-414, s. 7(2).)
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at ncleg.gov
United States Code Title 15
§ 1681aDefinitions; rules of constructionIn forcecited in 4 of our articles
Definitions and rules of construction set forth in this section are applicable for the purposes of this subchapter. The term “person” means any individual, partnership, corporation, trust, estate, cooperative, association, government or governmental subdivision or agency, or other entity. The term “consumer” means an individual. The term “consumer report” means any written, oral, or other communication of any information by a consumer reporting agency bearing on a consumer’s credit worthiness, credit standing, credit capacity, character, general reputation, personal characteristics, or mode of living which is used or expected to be used or collected in whole or in part for the purpose of serving as a factor in establishing the consumer’s eligibility for— credit or insurance to be used primarily for personal, family, or household purposes; employment purposes; or any other purpose authorized under section 1681b of this title.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at uscode.house.gov
Cited in 1,008 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Spokeo, Inc. v. Robins (Supreme Court of the United States 2016, 578 U.S. 330)“…ther purpose authorized under section 1681b of this title.” 15 U. S. C. §1681a(d)(1). 2 “The term ‘consumer reportin…”
- Pintos v. PACIFIC CREDITORS ASS'N (Court of Appeals for the Ninth Circuit 2010, 605 F.3d 665)“…n need to meet section 1681b(c)’s special conditions. Title 15 U.S.C. § 1681a(m) defines “credit ... transaction that…”
- Safeco Insurance Co. of America v. Burr (Supreme Court of the United States 2007, 551 U.S. 47)“…sed primarily for personal, family, or household purposes.” 15 U. S. C. §1681a(d)(1) (footnote omitted). The scope of…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Background Check Laws by State (2026 Guide), Missouri Data Breach Notification Laws: Reporting Rules & Timelines (2026), 15 U.S.C. § 1681 (FCRA): Credit Report Rights Explained
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- North Carolina Identity Theft Protection Act (G.S. Chapter 75, Article 2A)(ncleg.gov).gov
- G.S. 75-65: Protection from Security Breaches(ncleg.gov).gov
- G.S. 75-62: Social Security Number Protection(ncleg.gov).gov
- G.S. 75-61: Definitions(ncleg.gov).gov
- G.S. 75-63: Security Freeze(ncleg.gov).gov
- G.S. 75-64: Destruction of Personal Information Records(ncleg.gov).gov
- G.S. 75-66: Publication of Personal Information(ncleg.gov).gov
- G.S. 14-113.20: Identity Theft(ncleg.gov).gov
- G.S. 14-113.20A: Trafficking in Stolen Identities(ncleg.gov).gov
- G.S. 115C-401.2: Student Online Privacy Protection(ncleg.gov).gov
- G.S. 115C-402.5: Student Data System Security(ncleg.gov).gov
- Parents' Bill of Rights (SB 49 / SL 2023-106)(ncleg.gov).gov
- G.S. Chapter 58, Article 39: Insurance Data Privacy(ncleg.gov).gov
- G.S. 58-39-25: Notice of Insurance Information Practices(ncleg.gov).gov
- G.S. 132-1.10: Social Security Numbers in Public Records(ncleg.gov).gov
- G.S. Chapter 126, Article 7: State Employee Personnel Records(ncleg.gov).gov
- NC Attorney General: Security Breach Information(ncdoj.gov).gov
- NC Attorney General: Report a Security Breach(ncdoj.gov).gov
- Attorney General Marriott Settlement ($52M)(ncdoj.gov).gov
- Attorney General Blackbaud Settlement ($49.5M)(ncdoj.gov).gov
- NCDIT: Privacy Laws, Policies & Guidance(it.nc.gov).gov
- NCDIT: Office of Privacy & Data Protection(it.nc.gov).gov
- House Bill 462: NC Personal Data Privacy Act (2025-2026)(ncleg.gov).gov
- G.S. 143-518: Confidentiality of Patient Information(ncleg.gov).gov
- NC Health Information Exchange Authority: Privacy & Security(hiea.nc.gov).gov
- NC DPI: Data Privacy and Policy(dpi.nc.gov).gov
- NC Attorney General: 2025 Data Breach Report (Record 2,349 Breaches)(ncdoj.gov).gov
- AG Jeff Jackson Investigates PowerSchool Data Breach (4M North Carolinians)(ncdoj.gov).gov
- AG Jeff Jackson Sues 23andMe Over Genetic Data Sale(ncdoj.gov).gov
- AG Jeff Jackson Wins TRO Blocking DOGE Data Access(ncdoj.gov).gov
- Senate Bill 757: Consumer Privacy Act (2025-2026)(ncleg.gov).gov
- Senate Bill 963: AI Chatbots Safety and Privacy (2025-2026)(ncleg.gov).gov
- TAKE IT DOWN Act, Pub. L. 119-12 (signed May 19, 2025)(congress.gov).gov
- FTC: TAKE IT DOWN Act Enforcement Begins May 19, 2026(ftc.gov).gov
- 15 U.S.C. 1681a: FCRA Definitions(law.cornell.edu)
- G.S. 14-113.22: Punishment and Liability (identity theft classification and restitution)(ncleg.gov)