North Dakota
North Dakota Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 5 primary sources cited on this page. How we verify our legal content

North Dakota requires businesses that experience a data breach to notify affected residents in the most expedient time possible and without unreasonable delay under N.D. Cent. Code 51-30. When more than 250 residents are affected, the Attorney General must also receive notice.
If your business handles personal information belonging to North Dakota residents, a data breach triggers specific legal obligations under the state's Notice of Security Breach for Personal Information law. N.D. Cent. Code Chapter 51-30 sets out who must be notified, what information triggers the duty, and how quickly you need to act. Originally enacted in 2005, the statute has been amended several times, most notably in 2015 to add the Attorney General notification requirement and expand the definition of personal information.
This guide covers the full scope of North Dakota's breach notification requirements, including what personal information triggers the law, who must be notified, the timeline, enforcement penalties, exemptions, and how the law connects to the state's broader data privacy framework.
Who Must Comply With North Dakota's Breach Notification Law
North Dakota's breach notification law applies to any person that owns or licenses computerized data that includes personal information. Unlike many state breach statutes, N.D. Cent. Code 51-30-02 contains no "conducts business in the state" limiter, so the duty turns on holding the data rather than on having a physical or commercial presence in North Dakota. The term "person" covers individuals, corporations, business trusts, estates, partnerships, associations, and any other legal entity.
The law also applies to any person that maintains computerized data belonging to another entity. If a third party discovers a breach of data it maintains on behalf of an owner, it must notify the data owner immediately following discovery. The data owner then carries the responsibility of notifying affected consumers and the Attorney General.
What Qualifies as a Security Breach
Under N.D. Cent. Code 51-30-01, a breach of the security system means the unauthorized acquisition of computerized data when access to personal information has not been secured by encryption or by any other method or technology that renders the electronic files, media, or databases unreadable or unusable.
The key term is "unauthorized acquisition." Mere unauthorized access, without actual acquisition of data, does not trigger the statute.
Good Faith Exception
A good faith acquisition of personal information by an employee or agent of the person owning the data does not constitute a breach, provided the personal information is not used and is not subject to further unauthorized disclosure.
The Encryption Safe Harbor

North Dakota provides one of the cleaner encryption safe harbors among state breach notification laws. If personal information was secured by encryption or any other method that renders the data unreadable or unusable, the incident does not qualify as a breach and no notification is required. Unlike some states, there is no carve-out requiring the encryption key to have remained uncompromised.
What Personal Information Triggers the Law
Under N.D. Cent. Code 51-30-01, personal information means an individual's first name or first initial and last name in combination with any of the following data elements:
- Social Security number
- Driver's license or state identification card number
- Financial institution account number, credit card number, or debit card number in combination with any required security code, access code, or password
- Date of birth
- Mother's maiden name
- Medical information
- Health insurance information (policy number, subscriber ID, or any unique identifier used by a health insurer)
- An identification number assigned by an employer, in combination with any required security code
- Digitized or other electronic signature
North Dakota's definition of personal information is notably broader than many states. The inclusion of employer-assigned ID numbers and health insurance information reflects amendments that expanded the law beyond its original scope.
Personal information does not include publicly available information lawfully made available to the general public from federal, state, or local government records.
Notification Timeline
North Dakota requires notification "in the most expedient time possible and without unreasonable delay." The statute allows for delays that are:
- Consistent with the legitimate needs of law enforcement
- Consistent with any measures necessary to determine the scope of the breach
- Necessary to restore the integrity of the data system
There is no fixed deadline measured in days. However, the "most expedient time possible" language sets a higher standard than states that use only "without unreasonable delay."
Law enforcement may request a delay if notification would compromise a criminal investigation.
Who Must Be Notified
Affected Individuals
Every North Dakota resident whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person must receive notification.
Chapter 51-30 does not prescribe what an individual notice must say. N.D. Cent. Code 51-30-05 addresses only the method of notice, and it sets required contents for substitute notice alone. Many businesses follow the content checklist that states such as California require by statute, but in North Dakota that is a best practice rather than a legal requirement.

Attorney General
Under N.D. Cent. Code 51-30-02, the North Dakota Attorney General must be notified when a breach affects more than 250 individuals. The statute directs that the disclosure be made by mail or electronic mail, and it does not prescribe any required contents for it.
The 250-person threshold is relatively low compared to many states, reflecting North Dakota's approach to ensuring the Attorney General has visibility into smaller breaches.
Methods of Notification
Businesses can provide notification through:
- Written notice sent to the individual's last known address
- Electronic notice consistent with the federal Electronic Signatures in Global and National Commerce Act (E-SIGN Act)
- Substitute notice, if specific cost or contact-information conditions are met (see below)
Substitute Notice
Substitute notice is available if the business demonstrates that:
- The cost of providing notice would exceed $250,000, or
- The affected class exceeds 500,000 individuals, or
- The business does not have sufficient contact information
Substitute notice must include: email notice (where available), conspicuous posting on the business's website, and notification to major statewide media.

Enforcement and Penalties
North Dakota's breach notification law is enforced primarily by the Attorney General. Under N.D. Cent. Code 51-30-07, the AG has all the powers and may seek all the remedies available under NDCC Chapter 51-15, the state's consumer fraud statute. The same section adds that the chapter's remedies, duties, prohibitions, and penalties "are not exclusive and are in addition to all other causes of action, remedies, and penalties under chapter 51-15, or otherwise provided by law."
Penalties
- Civil penalties of up to $5,000 per violation under NDCC 51-15-11
- Temporary or permanent injunctive relief
- Attorney's fees, costs, and investigation expenses
Private Right of Action
Chapter 51-30 itself does not create a private cause of action, and the Attorney General is the law's primary enforcer. However, N.D. Cent. Code 51-30-07 deems a violation of this chapter a violation of chapter 51-15, and chapter 51-15's savings clause, 51-15-09, does not categorically bar private claims for relief under that chapter (it bars them only for violations of the separate 'facilitating and assisting' provision, 51-15-02.3). Whether an affected individual can bring a private claim over a breach notification failure is not clearly settled by the statutory text, and has not been tested in North Dakota case law reviewed for this article. Businesses should not assume they are shielded from every possible private suit.
Exemptions
HIPAA Compliance Exemption
Any covered entity, business associate, or subcontractor subject to breach notification requirements under 45 CFR Part 164, Subpart D (the HIPAA Breach Notification Rule) is deemed in compliance with North Dakota's law, provided they comply with the federal requirements.
Financial Institution Exemption
Financial institutions subject to and in compliance with the federal Gramm-Leach-Bliley Act interagency guidance on breach notification are also exempt from separate compliance with the state statute.
Alternate Compliance
Under N.D. Cent. Code 51-30-06, any entity that maintains its own notification procedures as part of an information security policy for the treatment of personal information is deemed in compliance, provided those procedures are consistent with the timing requirements of the state law.
Third-Party Data Maintainer Obligations
Under N.D. Cent. Code 51-30-03, any person that maintains computerized data belonging to another entity must notify the data owner of any security breach immediately following discovery. This obligation is in addition to any contractual notification requirements. The data owner then bears responsibility for notifying affected consumers and the Attorney General.
This article provides general legal information about North Dakota data privacy laws and breach notification requirements. It is not legal advice, and it does not create an attorney-client relationship. Data breach response involves time-sensitive obligations. Consult a qualified attorney licensed in North Dakota for guidance specific to your situation.
More North Dakota Laws
Frequently Asked Questions
How quickly must a business notify North Dakota residents of a data breach?
North Dakota requires notification in the most expedient time possible and without unreasonable delay under N.D. Cent. Code 51-30-02. There is no fixed deadline. The timeline accounts for law enforcement needs and the time needed to determine the breach scope and restore system integrity.
When must the North Dakota Attorney General be notified of a data breach?
The Attorney General must be notified when a breach affects more than 250 individuals. N.D. Cent. Code 51-30-02 requires that disclosure to be made by mail or electronic mail, and it does not prescribe any required contents for the notice.
Does encrypting data exempt a business from North Dakota breach notification?
Yes. North Dakota provides a complete encryption safe harbor. If the compromised data was secured by encryption or another method that renders it unreadable or unusable, the incident does not constitute a breach of the security system and no notification is required.
Can individuals sue a business in North Dakota for failing to provide breach notification?
North Dakota's breach notification chapter (51-30) does not itself create a private cause of action, and the Attorney General is the law's primary enforcer, using the powers and remedies available under NDCC Chapter 51-15. However, a violation of chapter 51-30 is deemed a violation of chapter 51-15, and that chapter's savings clause does not categorically bar private claims for relief. Whether an individual can bring a private suit over a breach-notification failure is not clearly settled by the statutory text.
Does North Dakota's breach notification law cover health insurance information?
Yes. North Dakota's definition of personal information specifically includes health insurance policy numbers, subscriber identification numbers, and any unique identifier used by a health insurer. It also covers medical information and employer-assigned ID numbers.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the North Dakota breach notification page: removed two notice-content requirement lists that are not in NDCC ch. 51-30, corrected the statute scope and its safe-harbor wording, dropped an unsupported per-individual penalty claim, and clarified that the attorney general is the primary rather than the exclusive enforcer.
Corrected the Attorney General notification threshold to more than 250 residents (not 250 or more), removed an inaccurate telephone-notice method and fabricated military ID number and passport number data elements, replaced an overstated no-private-right-of-action claim with an accurate description of the law's AG-primary enforcement, corrected the good-faith exception and third-party maintainer notice wording to match the statute, and replaced a dead Attorney General citation link.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
North Dakota Century Code
§ 51-30-02Notice to attorney general and consumersIn forcecited in 2 of our articles
Any person that owns or licenses computerized data that includes personal information, shall disclose any breach of the security system following discovery or notification of the breach in the security of the data to any resident of the state whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person. In addition, any person that experiences a breach of the security system as provided in this section shall disclose to the attorney general by mail or electronic mail any breach of the security system which exceeds two hundred fifty individuals. The disclosure must be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement, as provided in section 51-30-04, or any measures necessary to determine the scope of the breach and to restore the integrity of the data system.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at ndlegis.gov
Also relied on in: North Dakota Data Privacy Laws: Breach Notification & Consumer Rights (2026)
Explore the law
This article also draws on these acts and chapters (opening at their first section): North Dakota Century Code § 51-30-01 (Definitions) · North Dakota Century Code § 51-15-01 (Definitions)
Related law for further reading — not part of this article’s citations.
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- N.D. Cent. Code Chapter 51-30 - Notice of Security Breach(ndlegis.gov).gov
- NDCC Chapter 51-30 (PDF)(ndlegis.gov).gov
- North Dakota AG - Consumer Resources(attorneygeneral.nd.gov).gov
- North Dakota AG - Preventing Identity Theft(attorneygeneral.nd.gov).gov
- NDCC Chapter 51-15 - Consumer Fraud(ndlegis.gov).gov