Description

Introduced Senate Bill 569 includes data protection requirements

The Senate Bill 569 for a Consumer Privacy Act (CPA) is introduced in the General Assembly of North Carolina. The Senate Bill also expands consumer rights. Specifically, the proposed CPA specifies the consumer's rights of knowledge and access; right of correction; right of deletion; right to opt-out; as well as a private right of action. For certain businesses, the bill foresees compliance requirements include the disclosure of the purpose of data collection; the duty to limit the collection of personal data; the obligation to provide clear accessible privacy notices to consumers and the duty to respond to consumer requests. It imposes these obligations on businesses that produce products or provide services to North Carolina residents and either control or process personal data of at least 100,000 consumers per year, or control or process personal data of at least 25,000 consumers and derives over 50% of gross revenue from the sale of personal data.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Data protection regulation
Regulated Economic Activity
cross-cutting
Implementation Level
subnational
Government Branch
legislature
Government Body
parliament

Complete timeline of this policy change

Hide details
2021-04-06
under deliberation

The Senate Bill 569 for a Consumer Privacy Act (CPA) is introduced in the General Assembly of North…

Key regulatory dimensions

Regulated subjects

The businesses, government agencies or individuals affected by this policy or regulatory change.
producer / supplier
1
Type Private organisation
Economic activity cross-cutting
Category All

Policy change by business practice

The detailed activities within the scope of this policy or regulatory change.
personal data (all forms): data collection
Regulatory tool
Risk or other impact assessment requirement
User right to rectification of personal data
User right to access personal data
Sanctions
TBR - Administrative
Regulated subjects
1
personal data (all forms): storage (any form)
Regulatory tool
Risk or other impact assessment requirement
User right to portability of personal data
User right to rectification of personal data
User right to access personal data
User right to deletion of personal data
User consent: Permit user opt-out
Sanctions
TBR - Administrative
Regulated subjects
1

Policy change by business practice

The detailed activities within the scope of this policy or regulatory change.

personal data (all forms): data collection

personal data (all forms): storage (any form)