North Dakota · verified through August 25, 2026

North Dakota: law status and evidence context.

Law status, direct attached-library attribution, and public enforcement context are shown separately. A zero direct total does not mean no enforcement exists.

ND · 5 requirements mapped / control outcomes supported

Law status

No verified general comprehensive law

No comprehensive consumer privacy law verified (HB 1485 (2019) was a pending bill)

Official name / citation
n.a.
Status / effective date
Bill only
Principal enforcer
North Dakota Attorney General

Direct attached-library attribution

0 cases · $0

These totals are assigned solely by the attachment’s state heading. Shared multistate totals are not allocated in full to every state.

The attached library does not enumerate participant-level allocations for every multistate matter; shared settlement totals are presented once at the national level and are not duplicated into state totals.

Official law sources

Other generally applicable PII law

N.D.C.C. §§ 51-30-01 to 51-30-07, Notice of Security Breach for Personal Information - https://ndlegis.gov/cencode/t51c30.pdf

Public enforcement context

Tier 1

Google LLC

$391.5 million multistate settlement; North Dakota share stated as $4.1 million · November 29, 2022

North Dakota and 39 other AGs settled claims that Google recorded users' location even when location settings were turned off, and required transparency changes.

Legal basis: State consumer protection law (deceptive practices as to collection, retention and use of location data)

Official case source (opens in a new tab)

Mapped control outcomes

1 personal data inventory/data map; 3 downstream copy tracking; 6 opt-out propagation validation; 7 marketing/vendor provenance; 10 regulator audit evidence

Kestryl can evidence discovery and inventory of the personal-data elements implicated in sale/sharing and opt-out claims across structured data and unstructured attachments/images, and can generate audit rows/evidence packs showing which stores and copies were identified; structured-data remediation is limited to mask/vault/strip. It cannot alter source attachments/documents and cannot by itself demonstrate that opt-out or deletion obligations were legally satisfied.