Tag Archives: North Carolina

North Carolina

Who Is Covered?

Any business that owns or licenses personal information of residents of North Carolina or any business that conducts business in North Carolina that owns or licenses personal information in any form (whether computerized, paper, or otherwise). N.C. Gen. Stat. § 75-65(a).

What Information Is Protected?

A person’s first name or first initial and last name in combination with identifying information including the following:

  1. Social security or employer taxpayer identification numbers.   
  2. Drivers license, State identification card, or passport numbers.  
  3. Checking account numbers.  
  4. Savings account numbers.  
  5. Credit card numbers. 
  6. Debit card numbers.  
  7. Personal Identification (PIN) Code.    
  8. Digital signatures.  
  9. Any other numbers or information that can be used to access a person’s financial resources.  
  10. Biometric data.  
  11. Fingerprints.  
  12. Passwords if they would permit access to a person’s financial account or resources. N.C. Gen. Stat. §§ 75.61(10); 14-113.20(b).

What Is A “Breach”?

An incident of unauthorized access to and acquisition of unencrypted and unredacted records or data containing personal information where illegal use of the personal information has occurred or is reasonably likely to occur or that creates a material risk of harm to a consumer. Any incident of unauthorized access to and acquisition of encrypted records or data containing personal information along with the confidential process or key shall constitute a security breach. Good faith acquisition of personal information by an employee or agent of the business for a legitimate purpose is not a security breach, provided that the personal information is not used for a purpose other than a lawful purpose of the business and is not subject to further unauthorized disclosure. N.C. Gen. Stat. § 75-61(14).

What Triggers Notification?

Discovery or notification of the breach. N.C. Gen. Stat. § 75-65(a).

How Is Notice Provided To Individuals?

Timing: Notice must be made without unreasonable delay, consistent with the legitimate needs of law enforcement and consistent with any measures necessary to determine sufficient contact information, determine the scope of the breach and restore the reasonable integrity, security, and confidentiality of the data system. N.C. Gen. Stat. § 75-65(a).

Delivery: Delivery may be by:

  1. Written notice.  
  2. Electronic notice, for those persons for whom it has a valid e-mail address and who have agreed to receive communications electronically if the notice provided is consistent with the provisions of the E-Sign Act.  
  3. Telephonic notice provided that contact is made directly with the affected persons.  
  4. Substitute notice, if the business demonstrates that the cost of providing notice would exceed $250,000 or that the affected class of subject persons to be notified exceeds 500,000, or if the business does not have sufficient contact information or consent to satisfy subdivisions (1), (2), or (3) of this subsection, for only those affected persons without sufficient contact information or consent, or if the business is unable to identify particular affected persons, for only those unidentifiable affected persons. Substitute notice shall consist of all the following: a)  E-mail notice when the business has an electronic mail address for the subject persons. b)  Conspicuous posting of the notice on the Web site page of the business, if one is maintained. c)  Notification to major statewide media. N.C. Gen. Stat. § 75-65(e).

Content: The notice must be clear and conspicuous and include:

  1. A description of the incident in general terms.  
  2. A description of the type of personal information that was subject to the unauthorized access and acquisition.  
  3. A description of the general acts of the business to protect the personal information from further unauthorized access.  
  4. A telephone number for the business that the person may call for further information and assistance, if one exists.  
  5. Advice that directs the person to remain vigilant by reviewing account statements and monitoring free credit reports.  
  6. The toll-free numbers and addresses for the major consumer reporting agencies.  
  7. The toll-free numbers, addresses, and Web site addresses for the Federal Trade Commission and the North Carolina Attorney General’s Office, along with a statement that the individual can obtain information from these sources about preventing identity theft. N.C. Gen. Stat. § 75-65(d).

Is Notice To The Government Required?

Yes. In the event a business provides notice to an affected person pursuant to this section, the business shall notify without unreasonable delay the Consumer Protection Division of the Attorney General’s Office of the nature of the breach, the number of consumers affected by the breach, steps taken to investigate the breach, steps taken to prevent a similar breach in the future, and information regarding the timing, distribution, and content of the notice. N.C. Gen. Stat. § 75-65(e1).

Is Notice To Credit Reporting Agencies Required?

Yes. In the event a business provides notice to more than 1,000 persons at one time pursuant to this section, the business shall notify, without unreasonable delay, the Consumer Protection Division of the Attorney General’s Office and all consumer reporting agencies of the timing, distribution, and content of the notice. N.C. Gen. Stat. § 75-65(f).

Are There Security Measure Standards?

Yes, with regard to destruction of records. Any business that conducts business in North Carolina and any business that maintains or otherwise possesses personal information of a resident of North Carolina must take reasonable measures to protect against unauthorized access to or use of the information in connection with or after its disposal, which must include:

  1. Implementing and monitoring compliance with policies and procedures that require the burning, pulverizing, or shredding of papers containing personal information so that information cannot be practicably read or reconstructed.  
  2. Implementing and monitoring compliance with policies and procedures that require the destruction or erasure of electronic media and other nonpaper media containing personal information so that the information cannot practicably be read or reconstructed.  
  3. Describing procedures relating to the adequate destruction or proper disposal of personal records as official policy in the writings of the business entity. N.C. Gen. Stat. § 75-64(a), (b).

What Are The Possible Consequences Of A Violation?

A violation is an unfair or deceptive act or practice under N.C. Gen. Stat. § 75-1.1 which can result in a civil penalty of up to $5,000 per violation for knowing violations. No private right of action may be brought by an individual for a violation of this section unless such individual is injured as a result of the violation. N.C. Gen. Stat. §§ 75-65(i); 75-15.2; 75.16.

Are There Any Exemptions/Exceptions?

A financial institution that is subject to and in compliance with the Federal Interagency Guidance Response Programs for Unauthorized Access to Consumer Information and Customer Notice, issued on March 7, 2005, by the Board of Governors of the Federal Reserve System, the Federal Deposit Insurance Corporation, the Office of the Comptroller of the Currency, and the Office of Thrift Supervision; or a credit union that is subject to and in compliance with the Final Guidance on Response Programs for Unauthorized Access to Member Information and Member Notice, issued on April 14, 2005, by the National Credit Union Administration; and any revisions, additions, or substitutions relating to any of the said interagency guidance, shall be deemed to be in compliance with this section. N.C. Gen. Stat. § 75-65(h).