EnglishEspañol
North Carolina flag

North Carolina

North Carolina Data Privacy Laws: Consumer Rights & Protections (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 34 primary sources cited on this page. How we verify our legal content

North Carolina Data Privacy Laws: Consumer Rights & Protections (2026)

Frequently Asked Questions

Does North Carolina have a comprehensive consumer data privacy law?

No. As of May 2026, North Carolina does not have a comprehensive consumer data privacy law comparable to California's CCPA or Virginia's VCDPA. The state relies on a patchwork of targeted statutes, primarily the Identity Theft Protection Act (G.S. 75-60 through 75-66). Three bills introduced in the 2025-2026 session would change that: House Bill 462 (NC Personal Data Privacy Act plus Social Media Safety Act), Senate Bill 757 (Consumer Privacy Act), and Senate Bill 963 (AI chatbot safety and privacy). None had been enacted as of May 2026.

How quickly must businesses notify North Carolina residents of a data breach?

North Carolina law requires notification 'without unreasonable delay' under G.S. 75-65 but does not set a specific number of days. Delays are permitted for law enforcement needs and to determine the scope of the breach. Businesses must also report breach details to the Attorney General's Consumer Protection Division. For breaches affecting more than 1,000 people, the three major consumer reporting agencies must also be notified.

What are the penalties for identity theft in North Carolina?

Identity theft is defined by G.S. 14-113.20 and punished under G.S. 14-113.22(a), which makes it a Class G felony. If the victim suffers arrest, detention, or conviction as a proximate result, or if the offender possesses identifying information of three or more separate people, the offense is a Class F felony. Trafficking in stolen identities under G.S. 14-113.20A is a Class E felony under G.S. 14-113.22(a1). Under G.S. 14-113.22(a2), the court may also order restitution for financial loss, which can include lost wages, attorneys' fees, and costs of correcting credit history.

Can I place a security freeze on my credit report in North Carolina for free?

If you request a freeze by telephone or mail, the consumer reporting agency may charge up to $3.00. However, no fee may be charged to consumers over age 62, identity theft victims who have filed a law enforcement report, or their spouses. Electronic freeze requests and any requests to temporarily lift, reinstate, or remove a freeze are free of charge. Federal law under the Economic Growth, Regulatory Relief, and Consumer Protection Act also guarantees free credit freezes through the major reporting agencies.

How does North Carolina protect student data privacy?

North Carolina has multiple student data privacy protections. G.S. 115C-401.2 prohibits operators of educational technology platforms from targeted advertising based on student data, building non-educational profiles on students, or selling student information. G.S. 115C-402.5 bans collection of biometric data, political affiliations, and voting history in student data systems. The 2023 Parents' Bill of Rights (SB 49) strengthened parental rights to inspect records and opt out of directory information disclosure.

What has Attorney General Jeff Jackson done on data privacy since taking office in January 2025?

Attorney General Jeff Jackson has pursued several significant data privacy enforcement actions. He investigated PowerSchool over a breach that exposed records of 4 million North Carolinians. He filed a lawsuit to prevent 23andMe from selling North Carolinians' genetic data in bankruptcy, securing a consent order appointing a privacy ombudsman. He won a temporary restraining order blocking DOGE from accessing North Carolinians' financial data. He also formed a bipartisan AI task force with Utah's AG to address AI-enabled privacy risks. In 2025, his office reported a record 2,349 data breaches affecting 9.3 million North Carolinians.

What is the TAKE IT DOWN Act and how does it affect North Carolina residents?

The TAKE IT DOWN Act (Pub. L. 119-12) is a federal law signed on May 19, 2025, that criminalizes the nonconsensual publication of intimate images, including AI-generated deepfakes. Criminal prohibitions took effect immediately upon signing. Online platforms were required to establish notice-and-removal processes by May 19, 2026, with FTC enforcement beginning on that date. North Carolina residents who are victims of nonconsensual intimate image publication can report violations to the FTC and may have criminal remedies available at the federal level.

Does North Carolina have a biometric data privacy law?

North Carolina does not have a standalone biometric data privacy law comparable to Illinois' BIPA. However, biometric data is included in the definition of personal information under G.S. 75-61, meaning unauthorized acquisition of biometric data can trigger breach notification obligations under G.S. 75-65. The student data statutes (G.S. 115C-402.5) expressly prohibit collection of biometric information in the student data system. If HB 462 or SB 757 passes, sensitive data definitions in those bills would likely include biometric data with heightened protections.

Updates

Corrected the Identity Theft Protection Act amendment history, added the G.S. 132-1.10(c1) breach-notification duty that applies to state and local government agencies, and re-attributed the identity-theft felony classifications and restitution rules to G.S. 14-113.22.

Corrected the name of the 2023 North Carolina student-data-privacy law referenced in the Student Data Privacy section: it is the Parents' Bill of Rights (SB 49 / Session Law 2023-106), not the Protect Our Students Act (a different, unrelated 2023 law addressing educator misconduct penalties).

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Corrected 4 statute-attribution/legal-fact errors verified against primary sources.

Governing law re-checked for recent changes

Governing law re-checked for recent changes

May 2026 refresh: Updated Attorney General section to reflect Jeff Jackson (in office Jan 2025, replacing Josh Stein who became Governor). Added 2025 record breach statistics (2,349 breaches, 9.3M NC residents exposed per NCDOJ 2025 Data Breach Report). Added AG Jackson enforcement actions: PowerSchool investigation (CID issued; 4M NC students), 23andMe genetic data lawsuit (consent order with privacy ombudsman), DOGE data-sharing TRO (Feb 2025), and AI task force with Utah AG. Added TAKE IT DOWN Act (Pub. L. 119-12, signed May 19, 2025; FTC enforcement effective May 19, 2026). Added SB 757 (Consumer Privacy Act) and SB 963 (AI Chatbots) as additional pending bills alongside HB 462. Confirmed HB 462 still in committee (re-referred April 29, 2025). Confirmed G.S. 58-39A (NAIC Insurance Data Security Model Law) has NOT been enacted in NC as of May 2026. Clarified APRA did not pass and is not current law. Added 3 new FAQs (Jeff Jackson enforcement priorities, TAKE IT DOWN Act, biometric data). Updated KeyTakeaways to 7 bullets. Added 9 new citations (total: 35).

Reviewed and approved by an editor

Sources and References

  1. North Carolina Identity Theft Protection Act (G.S. Chapter 75, Article 2A)(ncleg.gov).gov
  2. G.S. 75-65: Protection from Security Breaches(ncleg.gov).gov
  3. G.S. 75-62: Social Security Number Protection(ncleg.gov).gov
  4. G.S. 75-61: Definitions(ncleg.gov).gov
  5. G.S. 75-63: Security Freeze(ncleg.gov).gov
  6. G.S. 75-64: Destruction of Personal Information Records(ncleg.gov).gov
  7. G.S. 75-66: Publication of Personal Information(ncleg.gov).gov
  8. G.S. 14-113.20: Identity Theft(ncleg.gov).gov
  9. G.S. 14-113.20A: Trafficking in Stolen Identities(ncleg.gov).gov
  10. G.S. 115C-401.2: Student Online Privacy Protection(ncleg.gov).gov
  11. G.S. 115C-402.5: Student Data System Security(ncleg.gov).gov
  12. Parents' Bill of Rights (SB 49 / SL 2023-106)(ncleg.gov).gov
  13. G.S. Chapter 58, Article 39: Insurance Data Privacy(ncleg.gov).gov
  14. G.S. 58-39-25: Notice of Insurance Information Practices(ncleg.gov).gov
  15. G.S. 132-1.10: Social Security Numbers in Public Records(ncleg.gov).gov
  16. G.S. Chapter 126, Article 7: State Employee Personnel Records(ncleg.gov).gov
  17. NC Attorney General: Security Breach Information(ncdoj.gov).gov
  18. NC Attorney General: Report a Security Breach(ncdoj.gov).gov
  19. Attorney General Marriott Settlement ($52M)(ncdoj.gov).gov
  20. Attorney General Blackbaud Settlement ($49.5M)(ncdoj.gov).gov
  21. NCDIT: Privacy Laws, Policies & Guidance(it.nc.gov).gov
  22. NCDIT: Office of Privacy & Data Protection(it.nc.gov).gov
  23. House Bill 462: NC Personal Data Privacy Act (2025-2026)(ncleg.gov).gov
  24. G.S. 143-518: Confidentiality of Patient Information(ncleg.gov).gov
  25. NC Health Information Exchange Authority: Privacy & Security(hiea.nc.gov).gov
  26. NC DPI: Data Privacy and Policy(dpi.nc.gov).gov
  27. NC Attorney General: 2025 Data Breach Report (Record 2,349 Breaches)(ncdoj.gov).gov
  28. AG Jeff Jackson Investigates PowerSchool Data Breach (4M North Carolinians)(ncdoj.gov).gov
  29. AG Jeff Jackson Sues 23andMe Over Genetic Data Sale(ncdoj.gov).gov
  30. AG Jeff Jackson Wins TRO Blocking DOGE Data Access(ncdoj.gov).gov
  31. Senate Bill 757: Consumer Privacy Act (2025-2026)(ncleg.gov).gov
  32. Senate Bill 963: AI Chatbots Safety and Privacy (2025-2026)(ncleg.gov).gov
  33. TAKE IT DOWN Act, Pub. L. 119-12 (signed May 19, 2025)(congress.gov).gov
  34. FTC: TAKE IT DOWN Act Enforcement Begins May 19, 2026(ftc.gov).gov
  35. 15 U.S.C. 1681a: FCRA Definitions(law.cornell.edu)
  36. G.S. 14-113.22: Punishment and Liability (identity theft classification and restitution)(ncleg.gov)
Share: