Data Breach Requirements: N.C.G.S. §§ 75-61, 75-65.
The numbering and internal citations herein are derived from the applicable state statute.
Personal Information
The term “personal information” means a person’s first name or first initial and last name in combination with identifying information as defined in G.S. 14-113.20(b).
G.S. 14-113.20(b):
(b) The term “identifying information” includes the following:
(1) Social Security or employer taxpayer identification numbers.
(2) Driver’s license, state identification card, or passport numbers.
(3) Checking account numbers.
(4) Savings account numbers.
(5) Credit card numbers.
(6) Debit card numbers.
(7) Personal Identification (PIN) Code as defined in G.S. 14-113.8(6).
(8) Electronic identification numbers, electronic mail names or addresses, internet account numbers, or internet identification names.
(9) Digital signatures.
(10) Any other numbers or information that can be used to access a person’s financial resources.
(11) Biometric data.
(12) Fingerprints.
(13) Passwords.
(14) Parent’s legal surname prior to marriage.
However, personal information shall not include electronic identification numbers, electronic mail names or addresses, internet account numbers, internet identification names, parent’s legal surname prior to marriage, or a password unless this information would permit access to a person’s financial account or resources.
Security Breach Definition
The term “security breach” means an incident of unauthorized access to and acquisition of unencrypted and unredacted records or data containing personal information where illegal use of the personal information has occurred or is reasonably likely to occur or that creates a material risk of harm to a consumer. Any incident of unauthorized access to and acquisition of encrypted records or data containing personal information along with the confidential process or key shall constitute a security breach.
Good Faith Exception
Good faith acquisition of personal information by an employee or agent of the business for a legitimate purpose is not a security breach, provided that the personal information is not used for a purpose other than a lawful purpose of the business and is not subject to further unauthorized disclosure.
Risk of Harm Analysis
See Security Breach Definition (illegal use and material risk of harm standard).
Notification Timeline
The breach notification shall be made without unreasonable delay, consistent with the legitimate needs of law enforcement, and consistent with any measures necessary to determine sufficient contact information, determine the scope of the breach, and restore the reasonable integrity, security, and confidentiality of the data system.
Security and Investigation Exceptions
The breach notification shall be delayed if a law enforcement agency informs the business that notification may impede a criminal investigation or jeopardize national or homeland security, provided that such request is made in writing or the business documents such request contemporaneously in writing, including the name of the law enforcement officer making the request and the officer’s law enforcement agency engaged in the investigation. The breach notice shall be provided without unreasonable delay after the law enforcement agency communicates to the business its determination that notice will no longer impede the investigation or jeopardize national or homeland security.
Notification Content Requirements
The breach notice shall be clear and conspicuous and include all of the following:
(1) A description of the incident in general terms.
(2) A description of the type of personal information that was subject to the unauthorized access and acquisition.
(3) A description of the general acts of the business to protect the personal information from further unauthorized access.
(4) A telephone number for the business that the person may call for further information and assistance, if one exists.
(5) Advice that directs the person to remain vigilant by reviewing account statements and monitoring free credit reports.
(6) The toll-free numbers and addresses for the major consumer reporting agencies.
(7) The toll-free numbers, addresses, and website addresses for the Federal Trade Commission and the North Carolina Attorney General’s Office, along with a statement that the individual can obtain information from these sources about preventing identity theft.
Delivery Methods
A breach notice may be provided by one of the following methods:
(1) Written notice.
(2) Electronic notice, for those persons for whom it has a valid email address and who have agreed to receive communications electronically if the notice provided is consistent with the provisions regarding electronic records and signatures for notices legally required to be in writing, set forth in 15 U.S.C. § 7001 (The Electronic Signatures in Global and National Commerce Act).
(3) Telephonic notice provided that contact is made directly with the affected persons.
(4) Substitute notice, if the business demonstrates that the cost of providing notice would exceed $250,000, or that the affected class of subject persons to be notified exceeds 500,000, or if the business does not have sufficient contact information or consent to satisfy subdivisions (1), (2), or (3) of this subsection, for only those affected persons without sufficient contact information or consent, or if the business is unable to identify particular affected persons, for only those unidentifiable affected persons.
Substitute Notice
Substitute notice shall consist of all the following:
a. Email notice when the business has an electronic mail address for the subject persons.
b. Conspicuous posting of the notice on the website page of the business, if one is maintained.
c. Notification to major statewide media.
Notice to Government Agencies
In the event a business provides notice to an affected person of a breach, the business shall notify without unreasonable delay the Consumer Protection Division of the Attorney General’s Office of the nature of the breach, the number of consumers affected by the breach, steps taken to investigate the breach, steps taken to prevent a similar breach in the future, and information regarding the timing, distribution, and content of the notice.
Consumer Reporting Agencies
In the event a business provides notice to more than 1,000 persons at one time of a breach, the business shall notify, without unreasonable delay, the Consumer Protection Division of the Attorney General’s Office and all consumer reporting agencies of the timing, distribution, and content of the notice.
Preemption and Compliance
A financial institution that is subject to and in compliance with the Federal Interagency Guidance Response Programs for Unauthorized Access to Consumer Information and Customer Notice or a credit union that is subject to and in compliance with the Final Guidance on Response Programs for Unauthorized Access to Member Information and Member Notice shall be deemed to be in compliance with this law.
Data Processor Obligations
Any business that maintains or possesses records or data containing personal information of residents of North Carolina that the business does not own or license, or any business that conducts business in North Carolina that maintains or possesses records or data containing personal information that the business does not own or license, shall notify the owner or licensee of the information of any security breach immediately following discovery of the breach, consistent with the legitimate needs of law enforcement.
Data Disposal and Security: N.C.G.S. § 75-61, and 75-64.
The numbering and internal citations herein are derived from the applicable state statute. See statute for any applicable exceptions or exemptions.
Key Terms
The term “disposal” includes the following: a. The discarding or abandonment of records containing personal information. b. The sale, donation, discarding, or transfer of any medium, including computer equipment or computer media, containing records of personal information, or other non-paper media upon which records of personal information are stored, or other equipment for non-paper storage of information.
The term “personal information” means a person’s first name or first initial and last name in combination with identifying information as defined in G.S. 14-113.20(b). Personal information does not include publicly available directories containing information an individual has voluntarily consented to have publicly disseminated or listed, including name, address, and telephone number, and does not include information made lawfully available to the general public from federal, state, or local government records.
G.S. 14-113.20(b):
(b) The term “identifying information” includes the following:
(1) Social Security or employer taxpayer identification numbers.
(2) Driver’s license, state identification card, or passport numbers.
(3) Checking account numbers.
(4) Savings account numbers.
(5) Credit card numbers.
(6) Debit card numbers.
(7) Personal Identification (PIN) Code as defined in G.S. 14-113.8(6).
(8) Electronic identification numbers, electronic mail names or addresses, internet account numbers, or internet identification names.
(9) Digital signatures.
(10) Any other numbers or information that can be used to access a person’s financial resources.
(11) Biometric data.
(12) Fingerprints.
(13) Passwords.
(14) Parent’s legal surname prior to marriage.
However, personal information shall not include electronic identification numbers, email names or addresses, internet account numbers, internet identification names, parent’s legal surname prior to marriage, or a password unless this information would permit access to a person’s financial account or resources.
The term “personal information” does not include publicly available directories containing information an individual has voluntarily consented to have publicly disseminated or listed, including name, address, and telephone number, and does not include information made lawfully available to the general public from federal, state, or local government records.
Written Policy
See Data Disposal (implementing and monitoring compliance with policies and procedures).
Data Disposal
Any business that conducts business in North Carolina and any business that maintains or otherwise possesses personal information of a resident of North Carolina must take reasonable measures to protect against unauthorized access to or use of the information in connection with or after its disposal. The reasonable measures must include:
(1) Implementing and monitoring compliance with policies and procedures that require the burning, pulverizing, or shredding of papers containing personal information so that information cannot be practicably read or reconstructed.
(2) Implementing and monitoring compliance with policies and procedures that require the destruction or erasure of electronic media and other non-paper media containing personal information so that the information cannot practicably be read or reconstructed.
(3) Describing procedures relating to the adequate destruction or proper disposal of personal records as official policy in the writings of the business entity.
A business may, after due diligence, enter into a written contract with, and monitor compliance by, another party engaged in the business of record destruction to destroy personal information in a manner consistent with this section. Due diligence should ordinarily include one or more of the following:
(1) Reviewing an independent audit of the disposal business’s operations or its compliance with this statute or its equivalent.
(2) Obtaining information about the disposal business from several references or other reliable sources and requiring that the disposal business be certified by a recognized trade association or similar third party with a reputation for high standards of quality review.
(3) Reviewing and evaluating the disposal business’s information security policies or procedures or taking other appropriate measures to determine the competency and integrity of the disposal business.
Other Information
A disposal business that conducts business in North Carolina or disposes of personal information of residents of North Carolina must take all reasonable measures to dispose of records containing personal information by implementing and monitoring compliance with policies and procedures that protect against unauthorized access to or use of personal information during or after the collection and transportation and disposing of such information.