EnglishEspañol
North Dakota flag

North Dakota

North Dakota Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 5 primary sources cited on this page. How we verify our legal content

North Dakota Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Frequently Asked Questions

How quickly must a business notify North Dakota residents of a data breach?

North Dakota requires notification in the most expedient time possible and without unreasonable delay under N.D. Cent. Code 51-30-02. There is no fixed deadline. The timeline accounts for law enforcement needs and the time needed to determine the breach scope and restore system integrity.

When must the North Dakota Attorney General be notified of a data breach?

The Attorney General must be notified when a breach affects more than 250 individuals. N.D. Cent. Code 51-30-02 requires that disclosure to be made by mail or electronic mail, and it does not prescribe any required contents for the notice.

Does encrypting data exempt a business from North Dakota breach notification?

Yes. North Dakota provides a complete encryption safe harbor. If the compromised data was secured by encryption or another method that renders it unreadable or unusable, the incident does not constitute a breach of the security system and no notification is required.

Can individuals sue a business in North Dakota for failing to provide breach notification?

North Dakota's breach notification chapter (51-30) does not itself create a private cause of action, and the Attorney General is the law's primary enforcer, using the powers and remedies available under NDCC Chapter 51-15. However, a violation of chapter 51-30 is deemed a violation of chapter 51-15, and that chapter's savings clause does not categorically bar private claims for relief. Whether an individual can bring a private suit over a breach-notification failure is not clearly settled by the statutory text.

Does North Dakota's breach notification law cover health insurance information?

Yes. North Dakota's definition of personal information specifically includes health insurance policy numbers, subscriber identification numbers, and any unique identifier used by a health insurer. It also covers medical information and employer-assigned ID numbers.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the North Dakota breach notification page: removed two notice-content requirement lists that are not in NDCC ch. 51-30, corrected the statute scope and its safe-harbor wording, dropped an unsupported per-individual penalty claim, and clarified that the attorney general is the primary rather than the exclusive enforcer.

Corrected the Attorney General notification threshold to more than 250 residents (not 250 or more), removed an inaccurate telephone-notice method and fabricated military ID number and passport number data elements, replaced an overstated no-private-right-of-action claim with an accurate description of the law's AG-primary enforcement, corrected the good-faith exception and third-party maintainer notice wording to match the statute, and replaced a dead Attorney General citation link.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. N.D. Cent. Code Chapter 51-30 - Notice of Security Breach(ndlegis.gov).gov
  2. NDCC Chapter 51-30 (PDF)(ndlegis.gov).gov
  3. North Dakota AG - Consumer Resources(attorneygeneral.nd.gov).gov
  4. North Dakota AG - Preventing Identity Theft(attorneygeneral.nd.gov).gov
  5. NDCC Chapter 51-15 - Consumer Fraud(ndlegis.gov).gov
Share: