12 | 13 | | A BILL TO BE ENTITLED 1 |
---|
13 | 14 | | AN ACT TO PROTECT CONSUMERS BY ENACTING THE CONSUMER PRIVACY ACT 2 |
---|
14 | 15 | | OF NORTH CAROLINA. 3 |
---|
15 | 16 | | The General Assembly of North Carolina enacts: 4 |
---|
16 | 17 | | SECTION 1. This act shall be known and may be cited as the "North Carolina 5 |
---|
17 | 18 | | Consumer Privacy Act." 6 |
---|
18 | 19 | | SECTION 2. The General Statutes are amended by adding a new Chapter to read: 7 |
---|
19 | 20 | | "Chapter 75F. 8 |
---|
20 | 21 | | "Consumer Privacy Act. 9 |
---|
21 | 22 | | "§ 75F-1. Definitions. 10 |
---|
22 | 23 | | (a) This Chapter shall be known and may be cited as the "North Carolina Consumer 11 |
---|
23 | 24 | | Privacy Act." 12 |
---|
24 | 25 | | (b) Definitions. – The following definitions apply in this Chapter: 13 |
---|
25 | 26 | | (1) Account. – The Consumer Privacy Restricted Account established in 14 |
---|
26 | 27 | | G.S. 75F-14. 15 |
---|
27 | 28 | | (2) Affiliate. – An entity that (i) controls, is controlled by, or is under common 16 |
---|
28 | 29 | | control with another entity or (ii) shares common branding with another entity. 17 |
---|
29 | 30 | | (3) Aggregated data. – Information that relates to a group or category of 18 |
---|
30 | 31 | | consumers (i) from which individual consumer identities have been removed 19 |
---|
31 | 32 | | and (ii) that is not linked or reasonably linkable to any consumer. 20 |
---|
32 | 33 | | (4) Air carrier. – As defined in 49 U.S.C. § 40102. 21 |
---|
33 | 34 | | (5) Authenticate. – To use reasonable means to determine that a consumer's 22 |
---|
34 | 35 | | request to exercise the rights described in G.S. 75F-4 is made by the consumer 23 |
---|
35 | 36 | | who is entitled to exercise those rights. 24 |
---|
36 | 37 | | (6) Biometric data. – Data generated by automatic measurements of an 25 |
---|
37 | 38 | | individual's unique biological characteristics. The term includes an 26 |
---|
38 | 39 | | individual's fingerprint, voiceprint, eye retinas, irises, or any other unique 27 |
---|
39 | 40 | | biological pattern or characteristic that is used to identify a specific individual. 28 |
---|
40 | 41 | | Biometric data does not include any of the following: 29 |
---|
41 | 42 | | a. A physical or digital photograph. 30 |
---|
42 | 43 | | b. A video or audio recording. 31 |
---|
43 | 44 | | c. Data generated from an item described in sub-subdivision a. or b. of 32 |
---|
44 | 45 | | this subdivision. 33 |
---|
47 | 52 | | e. Information collected, used, or stored for treatment, payment, or health 1 |
---|
48 | 53 | | care operations as those terms are defined in 45 C.F.R. Parts 160, 162, 2 |
---|
49 | 54 | | and 164. 3 |
---|
50 | 55 | | (7) Business associate. – As defined in 45 C.F.R. § 160.103. 4 |
---|
51 | 56 | | (8) Child. – An individual younger than 13 years old. 5 |
---|
52 | 57 | | (9) Consent. – An affirmative act by a consumer that unambiguously indicates the 6 |
---|
53 | 58 | | consumer's voluntary and informed agreement to allow a person to process 7 |
---|
54 | 59 | | personal data related to the consumer. 8 |
---|
55 | 60 | | (10) Consumer. – An individual who is a resident of this State acting in an 9 |
---|
56 | 61 | | individual or household context. The term does not include an individual 10 |
---|
57 | 62 | | acting in a commercial or employment context. 11 |
---|
58 | 63 | | (11) Control or controlled. – Includes each of the following: (i) ownership of, or 12 |
---|
59 | 64 | | the power to vote, more than fifty percent (50%) of the outstanding shares of 13 |
---|
60 | 65 | | any class of voting securities of an entity; (ii) control in any manner over the 14 |
---|
61 | 66 | | election of a majority of the directors or of the individuals exercising similar 15 |
---|
62 | 67 | | functions; and (iii) the power to exercise controlling influence of the 16 |
---|
63 | 68 | | management of an entity. 17 |
---|
64 | 69 | | (12) Controller. – A person doing business in this State who determines the 18 |
---|
65 | 70 | | purposes for which, and the means by which, personal data are processed, 19 |
---|
66 | 71 | | regardless of whether the person makes the determination alone or with others 20 |
---|
67 | 72 | | that, alone or jointly with others, determines the purpose and means of 21 |
---|
68 | 73 | | processing personal data. 22 |
---|
69 | 74 | | (13) Covered entity. – As defined in 45 C.F.R. § 160.103. 23 |
---|
70 | 75 | | (14) De-identified data. – Data that cannot reasonably be linked to an identified or 24 |
---|
71 | 76 | | identifiable individual that are possessed by a controller who does all of the 25 |
---|
72 | 77 | | following: 26 |
---|
73 | 78 | | a. Takes reasonable measures to ensure that a person cannot associate the 27 |
---|
74 | 79 | | data with an individual. 28 |
---|
75 | 80 | | b. Publicly commits to maintain and use the data only in de-identified 29 |
---|
76 | 81 | | form and not attempt to reidentify the data. 30 |
---|
77 | 82 | | c. Contractually obligates any recipients of the data to comply with the 31 |
---|
78 | 83 | | requirements described in sub-subdivisions a. and b. of this 32 |
---|
79 | 84 | | subdivision. 33 |
---|
80 | 85 | | (15) Director. – The Director of the Division. 34 |
---|
81 | 86 | | (16) Division. – Consumer Protection Division of the North Carolina Department 35 |
---|
82 | 87 | | of Justice or other unit of the Department of Justice engaging in activities 36 |
---|
83 | 88 | | under this Chapter. 37 |
---|
84 | 89 | | (17) Government entity. – The State or any local political subdivision of the State. 38 |
---|
85 | 90 | | (18) Health care facility. – Any entity licensed pursuant to Chapter 122C, 131D, 39 |
---|
86 | 91 | | or 131E of the General Statutes or Article 64 of Chapter 58 of the General 40 |
---|
87 | 92 | | Statutes, and any clinical laboratory certified under the federal Clinical 41 |
---|
88 | 93 | | Laboratory Improvement Amendments in section 353 of the Public Health 42 |
---|
89 | 94 | | Service Act (42 U.S.C. § 263a). 43 |
---|
90 | 95 | | (19) Health care provider. – Includes: 44 |
---|
91 | 96 | | a. An individual who is licensed, certified, or otherwise authorized under 45 |
---|
92 | 97 | | Chapter 90 or 90B of the General Statutes to provide health care 46 |
---|
93 | 98 | | services in the ordinary course of business or practice of a profession 47 |
---|
94 | 99 | | or in an approved education or training program. 48 |
---|
95 | 100 | | b. A health care facility where health care services are provided to 49 |
---|
96 | 101 | | patients, residents, or others to whom such services are provided as 50 |
---|
97 | 102 | | allowed by law. 51 General Assembly Of North Carolina Session 2025 |
---|
99 | 104 | | c. Individuals licensed under Chapter 90 of the General Statutes or 1 |
---|
100 | 105 | | practicing under a waiver in accordance with G.S. 90-12.5. 2 |
---|
101 | 106 | | d. Any emergency medical services personnel as defined in 3 |
---|
102 | 107 | | G.S. 131E-155(7). 4 |
---|
103 | 108 | | e. Any individual who is employed as a health care facility administrator, 5 |
---|
104 | 109 | | executive, supervisor, board member, trustee, or other person in a 6 |
---|
105 | 110 | | managerial position or comparable role at a health care facility. 7 |
---|
106 | 111 | | f. An agent or employee of a health care facility that is licensed, certified, 8 |
---|
107 | 112 | | or otherwise authorized to provide health care services. 9 |
---|
108 | 113 | | g. An officer or director of a health care facility. 10 |
---|
109 | 114 | | h. An agent or employee of a health care provider who is licensed, 11 |
---|
110 | 115 | | certified, or otherwise authorized to provide health care services. 12 |
---|
111 | 116 | | (20) Identifiable individual. – An individual who can be readily identified, directly 13 |
---|
112 | 117 | | or indirectly. 14 |
---|
113 | 118 | | (21) Institution of higher education. – A public or private institution of higher 15 |
---|
114 | 119 | | education. 16 |
---|
115 | 120 | | (22) Local political subdivision. – Includes a city, a county, a local school 17 |
---|
116 | 121 | | administrative unit as defined in G.S. 115C-5, or a community college. 18 |
---|
117 | 122 | | (23) Nonprofit organization. – Any corporation exempt from taxation under 19 |
---|
118 | 123 | | section 501(c)(3), 501(c)(6), or 501(c)(12) of the Internal Revenue Code. 20 |
---|
119 | 124 | | (24) Personal data. – Information that can be used to distinguish or trace an 21 |
---|
120 | 125 | | individual's identity, either alone or when combined with other information. 22 |
---|
121 | 126 | | The term does not include information that is a public record under Chapter 23 |
---|
122 | 127 | | 132 of the General Statutes or information made available to the general 24 |
---|
123 | 128 | | public lawfully and intentionally. 25 |
---|
124 | 129 | | (25) Process. – Any operation or set of operations performed on personal data, 26 |
---|
125 | 130 | | including collection, use, storage, disclosure, analysis, deletion, or 27 |
---|
126 | 131 | | modification of personal data. 28 |
---|
127 | 132 | | (26) Processor. – A person who processes personal data on behalf of a controller. 29 |
---|
128 | 133 | | (27) Protected health information. – As defined in 45 C.F.R. § 160.103. 30 |
---|
129 | 134 | | (28) Pseudonymous data. – Personal data that cannot be attributed to a specific 31 |
---|
130 | 135 | | individual without the use of additional information, if the additional 32 |
---|
131 | 136 | | information is (i) kept separately from the consumer's personal data and (ii) 33 |
---|
132 | 137 | | subject to appropriate technical and organizational measures to ensure that the 34 |
---|
133 | 138 | | personal data is not attributable to an identified or identifiable individual. 35 |
---|
134 | 139 | | (29) Publicly available information. – Information that a person (i) lawfully obtains 36 |
---|
135 | 140 | | from a record of a governmental entity, (ii) reasonably believes a consumer or 37 |
---|
136 | 141 | | widely distributed media has lawfully made available to the general public, or 38 |
---|
137 | 142 | | (iii) if the consumer has not restricted the information to a specific audience, 39 |
---|
138 | 143 | | obtains from a person to whom the consumer disclosed the information. 40 |
---|
139 | 144 | | (30) Right. – A consumer right described in G.S. 75F-4. 41 |
---|
140 | 145 | | (31) Sale, sell, or sold. – The exchange of personal data for monetary consideration 42 |
---|
141 | 146 | | by the controller to a third party. The terms do not include any of the 43 |
---|
142 | 147 | | following: 44 |
---|
143 | 148 | | a. A controller's disclosure of personal data to a processor who processes 45 |
---|
144 | 149 | | the personal data on behalf of the controller. 46 |
---|
145 | 150 | | b. A controller's disclosure of personal data to an affiliate of the 47 |
---|
146 | 151 | | controller. 48 |
---|
147 | 152 | | c. Considering the context in which the consumer provided the personal 49 |
---|
148 | 153 | | data to the controller, a controller's disclosure of personal data to a 50 General Assembly Of North Carolina Session 2025 |
---|
150 | 155 | | third party if the purpose is consistent with a consumer's reasonable 1 |
---|
151 | 156 | | expectations. 2 |
---|
152 | 157 | | d. The disclosure or transfer of personal data when a consumer directs a 3 |
---|
153 | 158 | | controller to disclose the personal data or interact with one or more 4 |
---|
154 | 159 | | third parties. 5 |
---|
155 | 160 | | e. A consumer's disclosure of personal data to a third party for the 6 |
---|
156 | 161 | | purpose of providing a product or service requested by the consumer 7 |
---|
157 | 162 | | or a parent or legal guardian of a child. 8 |
---|
158 | 163 | | f. The disclosure of information that the consumer intentionally makes 9 |
---|
159 | 164 | | available to the general public via a channel of mass media and does 10 |
---|
160 | 165 | | not restrict to a specific audience. 11 |
---|
161 | 166 | | g. A controller's transfer of personal data to a third party as an asset that 12 |
---|
162 | 167 | | is part of a proposed or actual merger, acquisition, or bankruptcy in 13 |
---|
163 | 168 | | which the third party assumes control of all or part of the controller's 14 |
---|
164 | 169 | | assets. 15 |
---|
165 | 170 | | (32) Sensitive data. – Personal data that reveals any of the following: 16 |
---|
166 | 171 | | a. An individual's (i) racial or ethnic origin, (ii) religious beliefs, (iii) 17 |
---|
167 | 172 | | sexual orientation, (iv) citizenship or immigration status, or (v) 18 |
---|
168 | 173 | | information regarding an individual's medical history, mental or 19 |
---|
169 | 174 | | physical health condition, or medical treatment or diagnosis by a 20 |
---|
170 | 175 | | health care professional. The term does not include personal data that 21 |
---|
171 | 176 | | reveals an individual's racial or ethnic origin if the personal data are 22 |
---|
172 | 177 | | processed by a video communication service. If the personal data are 23 |
---|
173 | 178 | | processed by a person licensed to provide health care under State or 24 |
---|
174 | 179 | | federal law, information regarding an individual's medical history, 25 |
---|
175 | 180 | | mental or physical health condition, or medical treatment or diagnosis 26 |
---|
176 | 181 | | by a health care professional, then the personal data is not sensitive 27 |
---|
177 | 182 | | data. 28 |
---|
178 | 183 | | b. The processing of genetic or biometric data if the processing is for the 29 |
---|
179 | 184 | | purpose of identifying a specific individual. 30 |
---|
180 | 185 | | c. Specific geolocation data. 31 |
---|
181 | 186 | | (33) Specific geological location. – Information derived from technology, 32 |
---|
182 | 187 | | including global positioning system level latitude and longitude coordinates, 33 |
---|
183 | 188 | | that directly identifies an individual's specific location, accurate within a 34 |
---|
184 | 189 | | radius of 1,750 feet or less. The term does not include (i) the content of a 35 |
---|
185 | 190 | | communication or (ii) any data generated by or connected to advanced utility 36 |
---|
186 | 191 | | metering infrastructure systems or equipment used by a utility. 37 |
---|
187 | 192 | | (34) Targeted advertising. – Displaying an advertisement to a consumer where the 38 |
---|
188 | 193 | | consumer is selected based upon personal data obtained from the consumer's 39 |
---|
189 | 194 | | activities over time and across nonaffiliated websites or online applications to 40 |
---|
190 | 195 | | predict the consumer's preferences and interests. The term does not include 41 |
---|
191 | 196 | | any advertising: 42 |
---|
192 | 197 | | a. Based upon a consumer's activities within the controller's website or 43 |
---|
193 | 198 | | online application or any affiliated website or online application. 44 |
---|
194 | 199 | | b. Based on the context of a consumer's current search query or visit to a 45 |
---|
195 | 200 | | website or online application. 46 |
---|
196 | 201 | | c. Directed to a consumer in response to the consumer's request for 47 |
---|
197 | 202 | | information, product, a service, or feedback. 48 |
---|
198 | 203 | | d. Processing personal data solely to measure or report advertising 49 |
---|
199 | 204 | | performance, reach, or frequency. 50 General Assembly Of North Carolina Session 2025 |
---|
201 | 206 | | (35) Third party. – A person other than the consumer, controller, or processor or 1 |
---|
202 | 207 | | an affiliate or contractor of the controller or processor. 2 |
---|
203 | 208 | | (36) Trade secret. – Information, including a formula, pattern, compilation, 3 |
---|
204 | 209 | | program, device, method, technique, or process that (i) derives independent 4 |
---|
205 | 210 | | economic value, actual or potential, from not being generally known to and 5 |
---|
206 | 211 | | not being readily ascertainable by proper means by other persons who can 6 |
---|
207 | 212 | | obtain economic value from the information's disclosure or use and (ii) is the 7 |
---|
208 | 213 | | subject of efforts that are reasonable under the circumstances to maintain the 8 |
---|
209 | 214 | | information's secrecy. 9 |
---|
210 | 215 | | "§ 75F-2. Applicability. 10 |
---|
211 | 216 | | (a) This Chapter applies to any controller or processor who: 11 |
---|
212 | 217 | | (1) Conducts business in this State or produces a product or service that is targeted 12 |
---|
213 | 218 | | to consumers who are residents of this State; 13 |
---|
214 | 219 | | (2) Has annual revenue of twenty-five million dollars ($25,000,000) or more; and 14 |
---|
215 | 220 | | (3) Satisfies one or more of the following thresholds: 15 |
---|
216 | 221 | | a. During a calendar year, controls or processes personal data of 100,000 16 |
---|
217 | 222 | | or more consumers; or 17 |
---|
218 | 223 | | b. Derives over fifty percent (50%) of the entity's gross revenue from the 18 |
---|
219 | 224 | | sale of personal data and controls or processes personal data of 25,000 19 |
---|
220 | 225 | | or more consumers. 20 |
---|
221 | 226 | | (b) This Chapter does not apply to any of the following: 21 |
---|
222 | 227 | | (1) A governmental entity or a third party under contract with a governmental 22 |
---|
223 | 228 | | entity when the third party is acting on behalf of the governmental entity. 23 |
---|
224 | 229 | | (2) A tribe. 24 |
---|
225 | 230 | | (3) An institution of higher education. 25 |
---|
226 | 231 | | (4) A nonprofit corporation. 26 |
---|
227 | 232 | | (5) A covered entity. 27 |
---|
228 | 233 | | (6) A business associate. 28 |
---|
229 | 234 | | (7) Information that meets the definition of one of the following: 29 |
---|
230 | 235 | | a. Protected health information for purposes of the federal Health 30 |
---|
231 | 236 | | Insurance Portability and Accountability Act of 1996, 42 U.S.C. § 31 |
---|
232 | 237 | | 1320d et seq., and related regulations. 32 |
---|
233 | 238 | | b. Patient identifying information for purposes of 42 C.F.R. Part 2. 33 |
---|
234 | 239 | | c. Identifiable private information for purposes of the federal Policy for 34 |
---|
235 | 240 | | the Protection of Human Subjects, 45 C.F.R. Part 46. 35 |
---|
236 | 241 | | d. Identifiable private information or personal data collected as part of 36 |
---|
237 | 242 | | human subjects research pursuant to or under the same standards as: 37 |
---|
238 | 243 | | 1. The good clinical practice guidelines issued by the 38 |
---|
239 | 244 | | International Council for Harmonisation; or 39 |
---|
240 | 245 | | 2. The Protection of Human Subjects under 21 C.F.R. Part 50 and 40 |
---|
241 | 246 | | Institutional Review Boards under 21 C.F.R. Part 56. 41 |
---|
242 | 247 | | e. Personal data used or shared in research conducted in accordance with 42 |
---|
243 | 248 | | one or more of the requirements described in sub-subdivision b. of this 43 |
---|
244 | 249 | | subdivision. 44 |
---|
245 | 250 | | f. Information and documents created for purposes of the federal Health 45 |
---|
246 | 251 | | Care Quality Improvement Act of 1986, 42 U.S.C. § 11101 et seq., and 46 |
---|
247 | 252 | | related regulations. 47 |
---|
248 | 253 | | g. Patient safety work product for purposes of 42 C.F.R. Part 3; or 48 |
---|
249 | 254 | | h. Information that is: 49 |
---|
250 | 255 | | 1. De-identified in accordance with the requirements for 50 |
---|
251 | 256 | | de-identification set forth in 45 C.F.R. Part 164; and 51 General Assembly Of North Carolina Session 2025 |
---|
253 | 258 | | 2. Derived from any of the health care-related information listed 1 |
---|
254 | 259 | | above in this subdivision. 2 |
---|
255 | 260 | | (8) Information originating from, and intermingled to be indistinguishable with, 3 |
---|
256 | 261 | | information under subdivision (7) of this subsection that is maintained by a (i) 4 |
---|
257 | 262 | | health care facility or health care provider or (ii) program or a qualified service 5 |
---|
258 | 263 | | organization as defined in 42 C.F.R. § 2.11. 6 |
---|
259 | 264 | | (9) Information used only for public health activities and purposes as described 7 |
---|
260 | 265 | | in 45 C.F.R. § 164.512. 8 |
---|
261 | 266 | | (10) An activity: 9 |
---|
262 | 267 | | a. Subject to regulation under the federal Fair Credit Reporting Act, 15 10 |
---|
263 | 268 | | U.S.C. § 1681 et seq., by one of the following: 11 |
---|
264 | 269 | | 1. A consumer reporting agency, as defined in 15 U.S.C. § 1681a; 12 |
---|
265 | 270 | | 2. A furnisher of information, as set forth in 15 U.S.C. § 1681s-2, 13 |
---|
266 | 271 | | who provides information for use in a consumer report, as 14 |
---|
267 | 272 | | defined in 15 U.S.C. § 1681a; or 15 |
---|
268 | 273 | | 3. A user of a consumer report, as set forth in 15 U.S.C. § 1681b; 16 |
---|
269 | 274 | | and 17 |
---|
270 | 275 | | b. Involving the collection, maintenance, disclosure, sale, 18 |
---|
271 | 276 | | communication, or use of any personal data bearing on a consumer's 19 |
---|
272 | 277 | | credit worthiness, credit standing, credit capacity, character, general 20 |
---|
273 | 278 | | reputation, personal characteristics, or mode of living. 21 |
---|
274 | 279 | | (11) A financial institution or an affiliate of a financial institution governed by, or 22 |
---|
275 | 280 | | personal data collected, processed, sold, or disclosed in accordance with, Title 23 |
---|
276 | 281 | | V of the Gramm-Leach-Bliley Act, 15 U.S.C. § 6801 et seq., and related 24 |
---|
277 | 282 | | regulations. 25 |
---|
278 | 283 | | (12) Personal data collected, processed, sold, or disclosed in accordance with the 26 |
---|
279 | 284 | | federal Driver's Privacy Protection Act of 1994, 18 U.S.C. § 2721 et seq. 27 |
---|
280 | 285 | | (13) Personal data regulated by the federal Family Education Rights and Privacy 28 |
---|
281 | 286 | | Act, 20 U.S.C. § 1232g, and related regulations. 29 |
---|
282 | 287 | | (14) Personal data collected, processed, sold, or disclosed in accordance with the 30 |
---|
283 | 288 | | federal Farm Credit Act of 1971, 12 U.S.C. § 2001 et seq. 31 |
---|
284 | 289 | | (15) Data that are processed or maintained: 32 |
---|
285 | 290 | | a. In the course of an individual applying to, being employed by, or 33 |
---|
286 | 291 | | acting as an agent or independent contractor of a controller, processor, 34 |
---|
287 | 292 | | or third party to the extent the collection and use of the data are related 35 |
---|
288 | 293 | | to the individual's role; 36 |
---|
289 | 294 | | b. As the emergency contact information of an individual described in 37 |
---|
290 | 295 | | sub-subdivision a. of this subdivision and used for emergency contact 38 |
---|
291 | 296 | | purposes; or 39 |
---|
292 | 297 | | c. To administer benefits for another individual relating to an individual 40 |
---|
293 | 298 | | described in sub-subdivision a. of this subdivision and used for the 41 |
---|
294 | 299 | | purpose of administering the benefits. 42 |
---|
295 | 300 | | (16) An individual's processing of personal data for purely personal or household 43 |
---|
296 | 301 | | purposes. 44 |
---|
297 | 302 | | (17) An air carrier. 45 |
---|
298 | 303 | | (c) A controller is in compliance with any obligation to obtain parental consent under this 46 |
---|
299 | 304 | | Chapter if the controller complies with the verifiable parental consent mechanisms under the 47 |
---|
300 | 305 | | Children's Online Privacy Protection Act, 15 U.S.C. § 6501 et seq., and the act's implementing 48 |
---|
301 | 306 | | regulations and exemptions. 49 General Assembly Of North Carolina Session 2025 |
---|
303 | 308 | | (d) This Chapter does not require a person to take any action in conflict with the federal 1 |
---|
304 | 309 | | Health Insurance Portability and Accountability Act of 1996, 42 U.S.C. § 1320d et seq., or related 2 |
---|
305 | 310 | | regulations. 3 |
---|
306 | 311 | | "§ 75F-3. Preemption; reference to other laws. 4 |
---|
307 | 312 | | (a) This Chapter supersedes and preempts any ordinance, resolution, rule, or other 5 |
---|
308 | 313 | | regulation adopted by a local political subdivision of the State regarding the processing of 6 |
---|
309 | 314 | | personal data by a controller or processor. 7 |
---|
310 | 315 | | (b) Any reference to federal law in this Chapter includes any rules or regulations 8 |
---|
311 | 316 | | promulgated under the federal law. 9 |
---|
312 | 317 | | "§ 75F-4. Consumer rights; access; deletion; portability; opt out of certain processing. 10 |
---|
313 | 318 | | (a) A consumer has the right to: 11 |
---|
314 | 319 | | (1) Confirm whether a controller is processing the consumer's personal data and 12 |
---|
315 | 320 | | access the consumer's personal data. 13 |
---|
316 | 321 | | (2) Delete the consumer's personal data that the consumer provided to the 14 |
---|
317 | 322 | | controller. 15 |
---|
318 | 323 | | (3) Obtain a copy of the consumer's personal data that the consumer previously 16 |
---|
319 | 324 | | provided to the controller, in a format that to the extent technically feasible, 17 |
---|
320 | 325 | | that is readily usable and allows the consumer to transmit the data to another 18 |
---|
321 | 326 | | controller without impediment where the processing is carried out by 19 |
---|
322 | 327 | | automated means. 20 |
---|
323 | 328 | | (4) Opt out of the processing of the consumer's personal data for purposes of 21 |
---|
324 | 329 | | targeted advertising or the sale of personal data. 22 |
---|
325 | 330 | | (b) Nothing in this section requires a person to cause a breach of security system. 23 |
---|
326 | 331 | | "§ 75F-5. Exercising consumer rights. 24 |
---|
327 | 332 | | (a) A consumer may exercise a right by submitting a request to a controller, by means 25 |
---|
328 | 333 | | prescribed by the controller, specifying the right the consumer intends to exercise. 26 |
---|
329 | 334 | | (b) In the case of processing personal data concerning a known child, the parent or legal 27 |
---|
330 | 335 | | guardian of the known child shall exercise a right on the child's behalf. 28 |
---|
331 | 336 | | (c) In the case of processing personal data concerning a consumer subject to 29 |
---|
332 | 337 | | guardianship, the guardian of the consumer shall exercise a right on the consumer's behalf. 30 |
---|
333 | 338 | | "§ 75F-6. Controller's response to requests. 31 |
---|
334 | 339 | | (a) Subject to the other provisions of this Chapter, a controller shall comply with a 32 |
---|
335 | 340 | | consumer's request under G.S. 75F-5 to exercise a right. 33 |
---|
336 | 341 | | (b) Within 45 days after the day on which a controller receives a request to exercise a 34 |
---|
337 | 342 | | right, the controller shall take action on the consumer's request and inform the consumer of any 35 |
---|
338 | 343 | | action taken on the consumer's request. 36 |
---|
339 | 344 | | (c) The controller may extend once the initial 45-day period by an additional 45 days if 37 |
---|
340 | 345 | | reasonably necessary due to the complexity of the request or the volume of the requests received 38 |
---|
341 | 346 | | by the controller. If a controller extends the initial 45-day period, before the initial 45-day period 39 |
---|
342 | 347 | | expires, the controller shall (i) inform the consumer of the extension, including the length of the 40 |
---|
343 | 348 | | extension, and (ii) provide the reasons the extension is reasonably necessary. 41 |
---|
344 | 349 | | (d) The 45-day period does not apply if the controller reasonably suspects the consumer's 42 |
---|
345 | 350 | | request is fraudulent and the controller is not able to authenticate the request before the 45-day 43 |
---|
346 | 351 | | period expires. 44 |
---|
347 | 352 | | (e) If, in accordance with this section, a controller chooses not to take action on a 45 |
---|
348 | 353 | | consumer's request, the controller shall within 45 days after the day on which the controller 46 |
---|
349 | 354 | | receives the request inform the consumer of the reasons for not taking action. 47 |
---|
350 | 355 | | (f) A controller may not charge a fee for information in response to a request, unless the 48 |
---|
351 | 356 | | request is the consumer's second or subsequent request during the same 12-month period. 49 |
---|
352 | 357 | | However, a controller may charge a reasonable fee to cover the administrative costs of complying 50 |
---|
353 | 358 | | with a request or refuse to act on a request if: 51 General Assembly Of North Carolina Session 2025 |
---|
355 | 360 | | (1) The request is excessive, repetitive, technically infeasible, or manifestly 1 |
---|
356 | 361 | | unfounded; 2 |
---|
357 | 362 | | (2) The controller reasonably believes the primary purpose in submitting the 3 |
---|
358 | 363 | | request was something other than exercising a right; or 4 |
---|
359 | 364 | | (3) The request, individually or as part of an organized effort, harasses, disrupts, 5 |
---|
360 | 365 | | or imposes undue burden on the resources of the controller's business. 6 |
---|
361 | 366 | | (g) A controller that charges a fee or refuses to act in accordance with this section bears 7 |
---|
362 | 367 | | the burden of demonstrating the request satisfied one or more of the criteria described in this 8 |
---|
363 | 368 | | section. 9 |
---|
364 | 369 | | (h) If a controller is unable to authenticate a consumer request to exercise a right 10 |
---|
365 | 370 | | described in G.S. 75F-4 using commercially reasonable efforts, the controller is not required to 11 |
---|
366 | 371 | | comply with the request and may request that the consumer provide additional information 12 |
---|
367 | 372 | | reasonably necessary to authenticate the request. 13 |
---|
368 | 373 | | "§ 75F-7. Responsibilities according to role. 14 |
---|
369 | 374 | | (a) A processor shall adhere to the controller's instructions, and taking into account the 15 |
---|
370 | 375 | | nature of the processing and information available to the processor, by appropriate technical and 16 |
---|
371 | 376 | | organizational measures, insofar as reasonably practicable, assist the controller in meeting the 17 |
---|
372 | 377 | | controller's obligations, including obligations related to the security of processing personal data 18 |
---|
373 | 378 | | and notification of a breach of security system. 19 |
---|
374 | 379 | | (b) Before a processor performs processing on behalf of a controller, the processor and 20 |
---|
375 | 380 | | controller shall enter into a contract that does all of the following: 21 |
---|
376 | 381 | | (1) Clearly sets forth instructions for processing personal data, the nature and 22 |
---|
377 | 382 | | purpose of the processing, the type of data subject to processing, the duration 23 |
---|
378 | 383 | | of the processing, and the parties' rights and obligations. 24 |
---|
379 | 384 | | (2) Requires the processor to ensure each person processing personal data is 25 |
---|
380 | 385 | | subject to a duty of confidentiality with respect to the personal data. 26 |
---|
381 | 386 | | (3) Requires the processor to engage any subcontractor pursuant to a written 27 |
---|
382 | 387 | | contract that requires the subcontractor to meet the same obligations as the 28 |
---|
383 | 388 | | processor with respect to the personal data. 29 |
---|
384 | 389 | | (c) Determining whether a person is acting as a controller or processor with respect to a 30 |
---|
385 | 390 | | specific processing of data is a fact-based determination that depends upon the context in which 31 |
---|
386 | 391 | | personal data are to be processed. A processor that adheres to a controller's instructions with 32 |
---|
387 | 392 | | respect to a specific processing of personal data remains a processor. 33 |
---|
388 | 393 | | "§ 75F-8. Responsibilities of contractors; transparency; purpose specification and data 34 |
---|
389 | 394 | | minimization; consent for secondary use; security; nondiscrimination. 35 |
---|
390 | 395 | | (a) A controller shall provide consumers with a reasonably accessible and clear privacy 36 |
---|
391 | 396 | | notice that includes all of the following: 37 |
---|
392 | 397 | | (1) The categories of personal data processed by the controller. 38 |
---|
393 | 398 | | (2) The purposes for which the categories of personal data are processed. 39 |
---|
394 | 399 | | (3) How consumers may exercise a right. 40 |
---|
395 | 400 | | (4) The categories of personal data that the controller shares with third parties, if 41 |
---|
396 | 401 | | any. 42 |
---|
397 | 402 | | (5) The categories of third parties, if any, with whom the controller shares 43 |
---|
398 | 403 | | personal data. 44 |
---|
399 | 404 | | If a controller sells a consumer's personal data to one or more third parties or engages in targeted 45 |
---|
400 | 405 | | advertising, the controller shall clearly and conspicuously disclose to the consumer the manner 46 |
---|
401 | 406 | | in which the consumer may exercise the right to opt out of the sale of the consumer's personal 47 |
---|
402 | 407 | | data or processing for targeted advertising. 48 |
---|
403 | 408 | | (b) A controller shall establish, implement, and maintain reasonable administrative, 49 |
---|
404 | 409 | | technical, and physical data security practices designed to protect the confidentiality and integrity 50 |
---|
405 | 410 | | of personal data and reduce reasonably foreseeable risks of harm to consumers relating to the 51 General Assembly Of North Carolina Session 2025 |
---|
407 | 412 | | processing of personal data. Considering the controller's business size, scope, and type, a 1 |
---|
408 | 413 | | controller shall use data security practices that are appropriate for the volume and nature of the 2 |
---|
409 | 414 | | personal data at issue. 3 |
---|
410 | 415 | | (c) Except as otherwise provided in this Chapter, a controller may not process sensitive 4 |
---|
411 | 416 | | data collected from a consumer without first presenting the consumer with clear notice and an 5 |
---|
412 | 417 | | opportunity to opt out of the processing, or in the case of the processing of personal data 6 |
---|
413 | 418 | | concerning a known child, processing the data in accordance with the federal Children's Online 7 |
---|
414 | 419 | | Privacy Protection Act, 15 U.S.C. § 6501 et seq., and the act's implementing regulations and 8 |
---|
415 | 420 | | exemptions. 9 |
---|
416 | 421 | | (d) A controller may not discriminate against a consumer for exercising a right by (i) 10 |
---|
417 | 422 | | denying a good or service to the consumer, (ii) charging the consumer a different price or rate 11 |
---|
418 | 423 | | for a good or service, or (iii) providing the consumer a different level of quality of a good or 12 |
---|
419 | 424 | | service. Nothing in this subsection prohibits a controller from offering a different price, rate, 13 |
---|
420 | 425 | | level, quality, or selection of a good or service to a consumer, including offering a good or service 14 |
---|
421 | 426 | | for no fee or at a discount, if the consumer has opted out of targeted advertising or the offer is 15 |
---|
422 | 427 | | related to the consumer's voluntary participation in a bona fide loyalty, rewards, premium 16 |
---|
423 | 428 | | features, discounts, or club card program. 17 |
---|
424 | 429 | | (e) A controller is not required to provide a product, service, or functionality to a 18 |
---|
425 | 430 | | consumer if the consumer's personal data are, or the processing of the consumer's personal data 19 |
---|
426 | 431 | | is, reasonably necessary for the controller to provide the consumer the product, service, or 20 |
---|
427 | 432 | | functionality and the consumer does not provide the consumer's personal data to the controller 21 |
---|
428 | 433 | | or allow the controller to process the consumer's personal data. Any provision of a contract that 22 |
---|
429 | 434 | | purports to waive or limit a consumer's right under this Chapter is void. 23 |
---|
430 | 435 | | "§ 75F-9. Processing de-identified data or pseudonymous data. 24 |
---|
431 | 436 | | (a) The provisions of this Chapter do not require a controller or processor to do any of 25 |
---|
432 | 437 | | the following: 26 |
---|
433 | 438 | | (1) Reidentify de-identified data or pseudonymous data. 27 |
---|
434 | 439 | | (2) Maintain data in identifiable form or obtain, retain, or access any data or 28 |
---|
435 | 440 | | technology for the purpose of allowing the controller or processor to associate 29 |
---|
436 | 441 | | a consumer request with personal data. 30 |
---|
437 | 442 | | (3) Comply with an authenticated consumer request to exercise a right described 31 |
---|
438 | 443 | | in G.S. 75F-4, if the controller: 32 |
---|
439 | 444 | | a. Is not reasonably capable of associating the request with the personal 33 |
---|
440 | 445 | | data or it would be unreasonably burdensome for the controller to 34 |
---|
441 | 446 | | associate the request with the personal data; 35 |
---|
442 | 447 | | b. Does not (i) use the personal data to recognize or respond to the 36 |
---|
443 | 448 | | consumer who is the subject of the personal data or (ii) associate the 37 |
---|
444 | 449 | | personal data with other personal data about the consumer; and 38 |
---|
445 | 450 | | c. Does not sell or other otherwise disclose the personal data to any third 39 |
---|
446 | 451 | | party other than a processor, except as otherwise permitted in this 40 |
---|
447 | 452 | | section. 41 |
---|
448 | 453 | | (b) The rights described in G.S. 75F-4(a)(1) through (a)(3) do not apply to pseudonymous 42 |
---|
449 | 454 | | data if a controller demonstrates that any information necessary to identify a consumer is kept 43 |
---|
450 | 455 | | separately and subject to appropriate technical and organizational measures to ensure the 44 |
---|
451 | 456 | | personal data are not attributed to an identified individual or an identifiable individual. 45 |
---|
452 | 457 | | (c) A controller who uses pseudonymous data or de-identified data shall take reasonable 46 |
---|
453 | 458 | | steps to ensure the controller complies with any contractual obligations to which the 47 |
---|
454 | 459 | | pseudonymous data or de-identified data are subject and promptly addresses any breach of a 48 |
---|
455 | 460 | | contractual obligation. 49 |
---|
456 | 461 | | "§ 75F-10. Limitations. 50 General Assembly Of North Carolina Session 2025 |
---|
458 | 463 | | (a) The requirements described in this Chapter do not restrict a controller's or processor's 1 |
---|
459 | 464 | | ability to do any of the following: 2 |
---|
460 | 465 | | (1) Comply with a State, federal, or local law, rule, or regulation. 3 |
---|
461 | 466 | | (2) Comply with a civil, criminal, or regulatory inquiry, investigation, subpoena, 4 |
---|
462 | 467 | | or summons by a federal, State, local, or other governmental entity. 5 |
---|
463 | 468 | | (3) Cooperate with a law enforcement agency concerning activity that the 6 |
---|
464 | 469 | | controller or processor reasonably and in good faith believes may violate 7 |
---|
465 | 470 | | federal, State, or local laws, rules, or regulations. 8 |
---|
466 | 471 | | (4) Investigate, establish, exercise, prepare for, or defend a legal claim. 9 |
---|
467 | 472 | | (5) Provide a product or service requested by a consumer or a parent or legal 10 |
---|
468 | 473 | | guardian of a child. 11 |
---|
469 | 474 | | (6) Perform a contract to which the consumer or the parent or legal guardian of a 12 |
---|
470 | 475 | | child is a party, including fulfilling the terms of a written warranty or taking 13 |
---|
471 | 476 | | steps at the request of the consumer or parent or legal guardian before entering 14 |
---|
472 | 477 | | into the contract with the consumer. 15 |
---|
473 | 478 | | (7) Take immediate steps to protect an interest that is essential for the life or 16 |
---|
474 | 479 | | physical safety of the consumer or of another individual. 17 |
---|
475 | 480 | | (8) Detect, prevent, protect against, or respond to a security incident, identity 18 |
---|
476 | 481 | | theft, fraud, harassment, malicious or deceptive activity, or any illegal activity 19 |
---|
477 | 482 | | or investigate, report, or prosecute a person responsible for an action described 20 |
---|
478 | 483 | | in this subdivision. 21 |
---|
479 | 484 | | (9) Preserve the integrity or security of systems or investigate, report, or prosecute 22 |
---|
480 | 485 | | a person responsible for harming or threatening the integrity or security of 23 |
---|
481 | 486 | | systems. 24 |
---|
482 | 487 | | (10) If the controller discloses the processing in a notice described in G.S. 75F-8, 25 |
---|
483 | 488 | | engage in public or peer-reviewed scientific, historical, or statistical research 26 |
---|
484 | 489 | | in the public interest that adheres to all other applicable ethics and privacy 27 |
---|
485 | 490 | | laws. 28 |
---|
486 | 491 | | (11) Assist another person with an obligation described in this subsection. 29 |
---|
487 | 492 | | (12) Process personal data to do any of the following: 30 |
---|
488 | 493 | | a. Conduct internal analytics or other research to develop, improve, or 31 |
---|
489 | 494 | | repair a controller's or processor's product, service, or technology. 32 |
---|
490 | 495 | | b. Identify and repair technical errors that impair existing or intended 33 |
---|
491 | 496 | | functionality. 34 |
---|
492 | 497 | | c. Effectuate a product recall. 35 |
---|
493 | 498 | | (13) Process personal data to perform an internal operation that is (i) reasonably 36 |
---|
494 | 499 | | aligned with the consumer's expectations based on the consumer's existing 37 |
---|
495 | 500 | | relationship with the controller or (ii) otherwise compatible with processing 38 |
---|
496 | 501 | | to aid the controller or processor in providing a product or service specifically 39 |
---|
497 | 502 | | requested by a consumer or a parent or legal guardian of a child or the 40 |
---|
498 | 503 | | performance of a contract to which the consumer or a parent or legal guardian 41 |
---|
499 | 504 | | of a child is a party. 42 |
---|
500 | 505 | | (14) Retain a consumer's email address to comply with the consumer's request to 43 |
---|
501 | 506 | | exercise a right. 44 |
---|
502 | 507 | | (b) This Chapter does not apply if a controller's or processor's compliance with this 45 |
---|
503 | 508 | | Chapter: 46 |
---|
504 | 509 | | (1) Violates an evidentiary privilege under North Carolina law. 47 |
---|
505 | 510 | | (2) As part of a privileged communication, prevents a controller or processor from 48 |
---|
506 | 511 | | providing personal data concerning a consumer to a person covered by an 49 |
---|
507 | 512 | | evidentiary privilege under North Carolina law. 50 |
---|
508 | 513 | | (3) Adversely affects the privacy or other rights of any person. 51 General Assembly Of North Carolina Session 2025 |
---|
510 | 515 | | (c) A controller or processor is not in violation of this Chapter if: 1 |
---|
511 | 516 | | (1) The controller or processor discloses personal data to a third-party controller 2 |
---|
512 | 517 | | or processor in compliance with this Chapter. 3 |
---|
513 | 518 | | (2) The third party processes the personal data in violation of this Chapter. 4 |
---|
514 | 519 | | (3) The disclosing controller or processor did not have actual knowledge of the 5 |
---|
515 | 520 | | third party's intent to commit a violation of this Chapter. 6 |
---|
516 | 521 | | (d) If a controller processes personal data under an exemption described in subsection (a) 7 |
---|
517 | 522 | | of this section, the controller bears the burden of demonstrating that the processing qualifies for 8 |
---|
518 | 523 | | the exemption. 9 |
---|
519 | 524 | | (e) Nothing in this Chapter requires a controller, processor, third party, or consumer to 10 |
---|
520 | 525 | | disclose a trade secret. 11 |
---|
521 | 526 | | "§ 75F-11. No private cause of action. 12 |
---|
522 | 527 | | A violation of this Chapter does not provide a basis for, nor is a violation of this Chapter 13 |
---|
523 | 528 | | subject to, a private right of action under this Chapter or any other law. 14 |
---|
524 | 529 | | "§ 75F-12. Enforcement. 15 |
---|
525 | 530 | | (a) The Division shall establish and administer a system to receive consumer complaints 16 |
---|
526 | 531 | | regarding a controller's or processor's alleged violation of this Chapter. 17 |
---|
527 | 532 | | (b) The Division may investigate a consumer complaint to determine whether the 18 |
---|
528 | 533 | | controller or processor violated or is violating this Chapter. 19 |
---|
529 | 534 | | "§ 75F-13. Enforcement powers of the Attorney General. 20 |
---|
530 | 535 | | (a) The Attorney General has the exclusive authority to enforce this Chapter. Upon 21 |
---|
531 | 536 | | referral from the Division, the Attorney General may initiate an enforcement action against a 22 |
---|
532 | 537 | | controller or processor for a violation of this Chapter. 23 |
---|
533 | 538 | | (b) At least 45 days before the day on which the Attorney General initiates an 24 |
---|
534 | 539 | | enforcement action against a controller or processor, the Attorney General shall provide the 25 |
---|
535 | 540 | | controller or processor with the following: 26 |
---|
536 | 541 | | (1) Written notice identifying each provision of this Chapter the Attorney General 27 |
---|
537 | 542 | | alleges the controller or processor has violated or is violating. 28 |
---|
538 | 543 | | (2) An explanation of the basis for each allegation. 29 |
---|
539 | 544 | | (c) The Attorney General may not initiate an action if the controller or processor: 30 |
---|
540 | 545 | | (1) Cures the noticed violation within 45 days after the day on which the 31 |
---|
541 | 546 | | controller or processor receives the written notice described in subsection (b) 32 |
---|
542 | 547 | | of this section. 33 |
---|
543 | 548 | | (2) Provides the Attorney General an express written statement that the violation 34 |
---|
544 | 549 | | has been cured and no further violation of the cured violation will occur. 35 |
---|
545 | 550 | | (d) The Attorney General may initiate an action against a controller or processor who (i) 36 |
---|
546 | 551 | | fails to cure a violation after receiving the notice described in subsection (b) of this section or (ii) 37 |
---|
547 | 552 | | after curing a noticed violation and providing a written statement in accordance with subsection 38 |
---|
548 | 553 | | (b) of this section, continues to violate this Chapter. 39 |
---|
549 | 554 | | (e) In an action described in subsection (d) of this section, the Attorney General may 40 |
---|
550 | 555 | | recover actual damages to the consumer; and for each violation described in subsection (d) of 41 |
---|
551 | 556 | | this section, an amount not to exceed seven thousand five hundred dollars ($7,500). 42 |
---|
552 | 557 | | (f) All money received from an action under this Chapter shall be deposited into the 43 |
---|
553 | 558 | | Consumer Privacy Account established in G.S. 75F-14. 44 |
---|
554 | 559 | | (g) If more than one controller or processor are involved in the same processing in 45 |
---|
555 | 560 | | violation of this Chapter, the liability for the violation shall be allocated among the controllers or 46 |
---|
556 | 561 | | processors in proportion to the comparative fault of each controller or processor. 47 |
---|
557 | 562 | | "§ 75F-14. Consumer Privacy Account. 48 |
---|
558 | 563 | | (a) There is created a restricted account known as the "Consumer Privacy Account." The 49 |
---|
559 | 564 | | account shall be funded by money received through civil enforcement actions under this Chapter. 50 General Assembly Of North Carolina Session 2025 |
---|
561 | 566 | | (b) Upon appropriation by the General Assembly, the account funds may be used by the 1 |
---|
562 | 567 | | Attorney General for these purposes: 2 |
---|
563 | 568 | | (1) Investigation and administrative costs incurred by the Division in 3 |
---|
564 | 569 | | investigating consumer complaints alleging violations of this Chapter. 4 |
---|
565 | 570 | | (2) Recovery of costs and attorney fees accrued by the Attorney General in 5 |
---|
566 | 571 | | enforcing this Chapter. 6 |
---|
567 | 572 | | (3) Providing consumer and business education regarding consumer rights under 7 |
---|
568 | 573 | | this Chapter and compliance with the provisions of this Chapter for controllers 8 |
---|
569 | 574 | | and processors. 9 |
---|
570 | 575 | | (c) If the balance in the account exceeds four million dollars ($4,000,000) at the close of 10 |
---|
571 | 576 | | any fiscal year, the State Budget Director shall transfer the amount that exceeds four million 11 |
---|
572 | 577 | | dollars ($4,000,000) into the General Fund. 12 |
---|
573 | 578 | | "§ 75F-15. Attorney General report. 13 |
---|
574 | 579 | | (a) The Attorney General and the Division shall compile a report evaluating the liability 14 |
---|
575 | 580 | | and enforcement provisions of this Chapter, including the effectiveness of the Attorney General's 15 |
---|
576 | 581 | | and the Division's efforts to enforce this Chapter and summarizing the data protected and not 16 |
---|
577 | 582 | | protected by this Chapter, including, with reasonable detail, a list of the types of information that 17 |
---|
578 | 583 | | are publicly available from State, local, and federal government sources. 18 |
---|
579 | 584 | | (b) The Attorney General and the Division may update the report as new information 19 |
---|
580 | 585 | | becomes available. 20 |
---|
581 | 586 | | (c) The Attorney General and the Division shall submit the report to the Joint Legislative 21 |
---|
582 | 587 | | Oversight Commission on Governmental Operations by July 1, 2027." 22 |
---|
583 | 588 | | SECTION 3. This act becomes effective January 1, 2026. 23 |
---|