Mandated Timeframe
Without unreasonable delay
Violations
Up to $5,000 per violation
![]() |
![]() |
---|---|
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
---|
Breach Reporting Requirements
Consumer Notification Requirements
Vendor Notification of Breach
Vendor Specific Obligations
Vendor Mandated Contracts
Protection/Security
Employee Training
Vendor Protection/Security Program
Personal Information Protection
Data Disposal of Personal Information
Mandated Timeframe
Without unreasonable delay
Violations
Up to $5,000 per violation
![]() Reporting |
![]() Notifications |
---|---|
![]() Management |
![]() Contract Required |
![]() |
![]() |
![]() |
![]() |
---|
Breach Reporting Requirements
Consumer Notification Requirements
Vendor Notification of Breach
Vendor Specific Obligations
Vendor Mandated Contracts
Protection/Security
Employee Training
Vendor Protection/Security Program
Personal Information Protection
Data Disposal of Personal Information
Mandated Timeframe
Without unreasonable delay
Violations
Up to $5,000 per violation
![]() Reporting |
![]() Notifications |
---|---|
![]() Management |
![]() Contract Required |
![]() |
![]() |
![]() |
![]() |
---|
Breach Reporting Requirements
Consumer Notification Requirements
Vendor Notification of Breach
Vendor Specific Obligations
Vendor Mandated Contracts
Protection/Security
Employee Training
Vendor Protection/Security Program
Personal Information Protection
Data Disposal of Personal Information
“Personal information” means an individual’s first name or first initial and last name in combination with any of the following data elements, when the name and the data elements are not encrypted: social security number; driver’s license number; non-driver color photo identification card; financial account number, credit or debit card number in combination with required security code or password that would permit access to individual’s financial account; date of birth; maiden name; medical information; health insurance information; employer issued identification number with required security code or password; or digitized or electronic signature.
There are specific considerations when determining if a breach is reportable. If notification is required to more than 250 persons, the state Attorney General must be notified either by mail or email.
If your breach affects residents in other jurisdictions, those individuals must be notified based on the breach notification laws of the jurisdiction where they reside.
Vendors must notify Organizations upon discovery of a breach or suspected breach. The Organization is responsible for submitting any required regulatory reporting and consumer notifications.
North Dakota passed the Insurance Data Security Law, which includes requirements for insurance licensees to protect personal information and investigate and respond to data breaches. Effective July 1, 2021, licensees must comply with the breach notification requirements, including Commissioner notification within 3 business days.
Organizations may be fined or penalized for Vendor violations. In addition to monetary civil penalties, the Attorney General may obtain injunctive relief through an action in a district court.
North Dakota
Cookie | Duration | Description |
---|---|---|
cookielawinfo-checbox-analytics | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics". |
cookielawinfo-checbox-functional | 11 months | The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional". |
cookielawinfo-checbox-others | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other. |
cookielawinfo-checkbox-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
cookielawinfo-checkbox-performance | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance". |
viewed_cookie_policy | 11 months | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |