N.D. Cent. Code § 51-30-06

Current through the 2023 Legislative Sessions
Section 51-30-06 - Alternate compliance

Notwithstanding section 51-30-05, a person that maintains its own notification procedures as part of an information security policy for the treatment of personal information and is otherwise consistent with the timing requirements of this chapter is deemed to be in compliance with the notification requirements of this chapter if the person notifies subject individuals in accordance with its policies in the event of a breach of security of the system. A financial institution, trust company, or credit union that is subject to, examined for, and in compliance with the federal interagency guidance on response programs for unauthorized access to customer information and customer notice is in compliance with this chapter. A covered entity, business associate, or subcontractor subject to breach notification requirements under title 45, Code of Federal Regulations, subpart D, part 164, is considered to be in compliance with this chapter.

N.D.C.C. § 51-30-06

Amended by S.L. 2013, ch. 106 (HB 1435),§ 3, eff. 8/1/2013.