Identity Theft Protection Act
· About Identity Theft Protection Act
Key Takeaways
- The Identity Theft Protection Act applies to businesses that own or license personal information of North Carolina residents, and to businesses that conduct business in North Carolina and maintain such information; it requires breach notice after discovery and reasonable security practices for covered data.
- A covered business must notify affected individuals without unreasonable delay, while a business that merely maintains another entity’s data must notify the owner or licensee immediately following discovery, subject to law-enforcement delay.
- North Carolina also requires businesses that own or license personal information to implement and maintain reasonable security procedures and practices appropriate to the nature of the information.
- The Act’s notice rules are enforced through North Carolina consumer-protection and identity-theft statutes, and violations can support civil enforcement under Chapter 75.
- The current statute remains in force in 2026; no 2025–2026 enactment has displaced the core breach-notification framework, although 2025 legislation has proposed cost-shifting for government breach notifications caused by third parties.
- The law is not limited to electronic records: it covers personal information in computerized, paper, or other form.
What It Is
Scope
North Carolina’s Identity Theft Protection Act is Article 2A of Chapter 75 of the North Carolina General Statutes, and it governs security-breach notifications, destruction of records, and related consumer-protection duties for covered businesses. The breach-notification provisions are codified in G.S. 75-65, which applies to businesses handling personal information of North Carolina residents and to businesses conducting business in North Carolina. The statute expressly covers personal information “in any form,” including computerized, paper, or otherwise.[3][4]
Enforcing body
The primary state enforcer is the North Carolina Attorney General, who can bring consumer-protection actions under Chapter 75 when the Act is violated. The statute also requires notices in certain breach situations, which can trigger direct regulatory and remedial scrutiny.[4][6]
Dates
The core article was enacted in 2005 as part of North Carolina’s identity-theft legislation.[10] The current statutory text remains in effect in 2026, and the breach-notification framework in G.S. 75-65 is still the operative law.[3][6] A 2025–2026 bill summary shows proposed amendments for government reimbursement of breach-notification costs caused by third-party vendors, but that proposal is separate from the base Act and does not itself appear to have replaced the existing statewide notification rules.[1][13]
Who Must Comply
Covered entities
The law applies to any business that owns or licenses personal information of residents of North Carolina and to any business that conducts business in North Carolina and owns or licenses that information.[4][6] It also applies to businesses that maintain or possess records or data containing personal information they do not own or license, if they conduct business in North Carolina.[4][6]
Extraterritorial reach
The statute reaches out-of-state businesses when they conduct business in North Carolina and hold North Carolina residents’ personal information.[4][6] That means a company does not need to be headquartered in North Carolina to fall within the Act if it does business there and handles covered data.
Exemptions
The statute does not create a broad sectoral exemption for private businesses, but government-related and vendor-allocation issues have become a separate policy focus in 2025 legislation.[1][13] The statutory notice timing also allows delay when necessary for law-enforcement needs.[4][6]
Core Requirements
- Security-breach notice to affected individuals. A business that owns or licenses covered personal information must notify affected persons after discovery or notification of a breach, without unreasonable delay and subject to law-enforcement needs.[4][6]
- Immediate notice to the owner or licensee. A business that merely maintains or possesses another entity’s personal information must notify the owner or licensee immediately after discovering the breach, again subject to law-enforcement delay.[4][6]
- Clear and conspicuous content. The notice must be clear and conspicuous and include the information required by statute, including a general description of the incident.[6]
- Reasonable security procedures. Businesses that own or license personal information must implement and maintain reasonable security procedures and practices appropriate to the nature of the personal information to protect it from a security breach.[9]
- Record destruction controls. The Act also requires businesses to take reasonable measures when disposing of records containing personal information, so the obligation is not limited to breach response alone.[14]
- Protected data handling. The law covers personal information in multiple forms, so paper records and offline files are within scope if they contain covered data.[4][6]
Deadlines and Penalties
| Milestone | Date | What applies | |---|---:|---| | Act enacted | 2005 | Article 2A was added to Chapter 75 and became the state’s identity-theft framework.[10] | | Breach notice to individuals | Upon discovery, without unreasonable delay | Covered businesses must notify affected residents unless delay is needed for law enforcement or investigation.[4][6] | | Notice to owner/licensee | Immediately following discovery | A data holder for another entity must notify the owner or licensee of the breach.[4][6] | | Security procedures duty | Ongoing | Businesses that own or license personal information must maintain reasonable security practices.[9] | | Proposed vendor reimbursement rule | 2025 bill; not shown as enacted here | A 2025 proposal would require third-party entities causing government breaches to reimburse notification costs, but it is separate from the base Act and should be treated as proposed unless enacted text is confirmed.[1][13] |
North Carolina’s Chapter 75 framework can support civil enforcement, injunctive relief, and statutory remedies for unlawful practices, and violations may also create exposure to attorney-general action and downstream litigation risk.[3][6] The Act itself focuses on notification and security obligations rather than a single standalone fine schedule, so penalties typically flow through Chapter 75 enforcement and related liability theories rather than a separate administrative penalty grid.[3][6]
How to Comply
- Map covered data. Identify where personal information of North Carolina residents is stored, including paper, endpoint, cloud, backup, and vendor systems; the statute covers information in any form.[4][6]
- Classify roles. Determine whether the organization owns/licenses data or merely maintains it for others, because notice timing differs materially.[4][6]
- Build a breach-response playbook. Set internal clocks for discovery, legal review, containment, law-enforcement consultation, notice drafting, and delivery so “without unreasonable delay” can be met consistently.[4][6]
- Adopt baseline controls. Use ISO 27001 for an information-security management system, NIST CSF 2.0 for governance, identify-protect-detect-respond-recover alignment, and ISO 42001 where AI systems process personal information and create data-governance risk.
- Harden vendor management. Put breach-notification, cooperation, indemnity, and forensic-assistance clauses into contracts, especially where third parties host or process personal information.
- Test destruction and retention controls. Ensure records are disposed of securely and that retention schedules do not leave unnecessary personal information exposed.[14]
- Document decisions. Keep contemporaneous records of breach scope, legal basis for any delay, notice decisions, and security remediation, since these records are critical in regulator or class-action review.[4][9]
- Run tabletop exercises. Practice a North Carolina-specific incident scenario with legal, privacy, security, HR, and communications teams to confirm the notice path and escalation points.
Related Regulations
- North Carolina data-breach laws for government agencies can overlap with the Act when public bodies or their vendors are involved, and 2025 legislation indicates a policy push to shift breach-notification costs to third parties.[1][13]
- North Carolina consumer-protection law in Chapter 75 provides the enforcement context, so the Act is often litigated through broader unfair or deceptive practice theories.[3][6]
- Federal FTC data-security expectations can overlap with the Act for commercial entities, especially where inadequate security procedures create parallel federal risk.
- HIPAA may also apply where the same incident involves protected health information, creating separate notification and safeguard duties beyond the state Act.
- State breach-notification laws in other jurisdictions often interact with North Carolina if an incident affects residents in multiple states, requiring a multi-state notice matrix.
FAQ
Does the Identity Theft Protection Act apply to companies outside North Carolina?
Yes, if the company conducts business in North Carolina and owns, licenses, maintains, or possesses covered personal information of North Carolina residents.[4][6] The law is not limited to North Carolina-incorporated entities. Out-of-state vendors commonly fall within scope when they handle North Carolina resident data for a client.
What counts as personal information under the Act?
The statute covers personal information of North Carolina residents in computerized, paper, or other form.[4][6] The exact definition is found in the statute and may include combinations of identifiers and authentication data, so companies should use a conservative reading when classifying data. If a dataset can identify a resident and create misuse risk, it should be reviewed as potentially covered.
How fast does breach notification have to go out?
The general rule is without unreasonable delay after discovery or notification of the breach, subject to legitimate law-enforcement needs and steps needed to determine scope and restore security.[4][6] If the organization only maintains the data for another entity, notice to the owner or licensee must be immediate following discovery.[4][6] The statute does not set a single universal hour-count, so documented speed and justification matter.
Does the Act require security controls, or only breach notice?
It requires both. North Carolina’s policy materials and statutory framework require businesses that own or license personal information to implement and maintain reasonable security procedures and practices appropriate to the nature of the information.[9] Breach notice is the response obligation; reasonable security is the preventative obligation.
Are there 2025–2026 changes to the Act?
A 2025–2026 bill summary shows a proposal to require third-party entities that cause security breaches affecting North Carolina governments to reimburse notification costs.[1][13] That proposal is separate from the base Act and should not be treated as a confirmed amendment unless enacted text is verified. The core breach-notification statute itself remains in force in 2026.[3][6]
Sources
- North Carolina General Statutes, Chapter 75, Article 2A — Identity Theft Protection Act
- North Carolina General Statutes, G.S. 75-65
- UNC School of Government, Security Breaches Under the NC Identity Theft Protection Act
- North Carolina Department of Justice, Strengthen North Carolina Identity Theft Protection Act
- North Carolina General Assembly, Bills & Laws
- UNC School of Government, Bill Summary for S 711 (2025-2026)
- UNC School of Government, Bill Summary: S 711 (2025-2026)
- North Carolina General Statutes, G.S. 14-113.20
- Campbell Law Review, Protecting Personal Data: A Survey of Consumer Protections Throughout North Carolina's Identity Theft Protection Act
Put it into practice
- Generate the policy: Privacy policy generator (generatepolicy.com)
- Buy the policy pack: State Privacy Law Checklist (cyberpolicy.shop)
- Build it yourself: 2026 US Privacy Program Workbook (ciso.diy)