Why North Carolina Doesn't Need OneTrust — And What It Needs Instead
A sequenced approach to privacy maturity in state government

Every few months, another "Best Data Privacy Platforms" listicle circulates with the same cast: OneTrust, BigID, TrustArc, Securiti. They're built for a specific problem — a company with a website, a data broker relationship, and a CCPA or GDPR obligation that generates a steady stream of consumer deletion requests.
State government doesn't have that problem. Not because privacy doesn't matter in the public sector — it matters enormously — but because the shape of the problem is different, and importing a commercial privacy stack without recognizing that difference is how well-funded privacy programs end up solving the wrong thing well.
North Carolina is a useful case study, because the gap is visible: neither NCDIT nor NCDHHS runs a commercial privacy governance platform. What they run instead is a mix of policy offices, point security tools (Tanium, Crowdstrike statewide, BitSight at DHHS), and manual, form-driven processes. That's often read as a maturity gap. I'd argue it's closer to accidental correctness — the state hasn't spent money solving a problem it doesn't have. But that also means there's a real opportunity for whoever leads privacy strategy next to build something purpose-fit rather than defaulting to whatever the private sector is buying.
The Mismatch
Commercial privacy platforms were built around a specific regulatory trigger: consumer data subject access requests (DSARs) under GDPR- and CCPA-style laws. Someone emails a company, says "tell me what you have on me and delete it," and the company has 45 days to comply across every system that might hold that person's data. That volume and deadline pressure is what created the market for automated discovery, identity verification, and DSAR fulfillment workflows.
North Carolina has no comprehensive consumer privacy law generating that obligation. What it has instead is:
Public records law (NCGS Chapter 132) — a transparency mechanism that runs in the opposite direction of a DSAR. It's about extracting more disclosure from government, not restricting or deleting personal data. There's no deadline, no residency requirement, and critically, no companion "right to deletion" — agencies are obligated to retain records, not erase them on request.
Sector-specific access rights — HIPAA governs DHHS-adjacent health data, FERPA governs DPI's education records, CJI rules govern law enforcement data, tax secrecy statutes govern DOR. Each has its own access and correction process. None of them route through a unified DSAR mechanism.
Worth noting: a bill exists that would change this. House Bill 462 (the "NC Personal Data Privacy Act") would enact a new GS Chapter 75F giving consumers DSAR-style rights — access, correction, deletion, opt-out — for businesses processing 35,000+ consumers' data or deriving 20%+ of revenue from data sales. But it's been stuck in the House Commerce and Economic Development Committee since April 2025 and hasn't advanced. It isn't law, and there's no guarantee it becomes one. It's a useful signal of where the legislature's attention is, and worth monitoring, but the operating reality today is the one described above.
So a platform built to automate DSAR fulfillment is solving a problem NC doesn't currently have, while the problem NC does have — reconciling privacy obligations across half a dozen incompatible statutory regimes, often within the same legacy system — isn't what these platforms were designed for.
What NC Actually Has
Three things worth naming, because they're easy to undervalue because they aren't a recognizable commercial product:
A policy foundation. NC adopted the Fair Information Practice Principles statewide in 2022 and stood up an Office of Privacy & Data Protection within NCDIT. That's a real governance asset — most states haven't done this. It's underleveraged, not absent.
Point tooling that solves adjacent problems well. Tanium gives statewide endpoint visibility. CrowdStrike, alongside Cloudflare for edge protection, provides next-gen endpoint protection across every executive branch agency. BitSight, provides DHHS continuous third-party and organizational cyber risk scoring. None of these are a privacy platform, but all three are closer to the pattern NC actually needs — continuous, exposure-based monitoring — than a consent-management platform would be.
Privacy-by-architecture, built into the data-sharing layer itself. The most genuinely purpose-built privacy tool in NC state government isn't badged as a privacy product at all. NC eLink, built by the Government Data Analytics Center (GDAC), links records across more than 50 administrative systems spanning 10+ agencies — and does it by matching individuals to a generated unique ID rather than passing raw PII between systems, so cross-agency matching happens without exposing the underlying identifiers. That's privacy-preserving design baked into infrastructure, which is arguably a more durable pattern than bolting a commercial privacy layer on top of legacy systems after the fact. The catch is that NC eLink solves data linking privacy, not data governance broadly — it doesn't classify, discover, or monitor exposure the way a DSPM tool would.
A signal of where DHHS might go next. A mid-2025 RFI for a "Data Analytics Platform Solution" shows DHHS actively scoping broader data infrastructure, with PHI/PII handling, role-based access, and SOC 2 alignment written into the requirements. It hasn't resulted in an award, so it isn't a tool in production — but it's the first indication that a NC agency might be shopping for something closer to a real data governance platform, rather than continuing to rely on policy and point tools alone. Worth watching, and worth a new CPO getting in front of before the requirements get locked in around analytics use cases rather than privacy ones.
What NC Got Right: The AI Governance Playbook
While privacy has been handled piecemeal, NC's AI governance shows what a deliberate build looks like:
Executive Order 24 (2025) established a single Council and a single hub — the AI Accelerator, housed in NCDIT — rather than letting AI governance fragment across agencies from the start
Oversight teams in every agency, reporting into that central structure, so cross-agency visibility was designed in rather than retrofitted
A risk-assessment tool that already existed — the Privacy Threshold Analysis — was adopted as the framework's backbone instead of commissioning something new
A public roadmap (July 2026) with 17 goals gives the program a visible, accountable shape
All of it runs through one statute (NCGS 143B-1376), so authority was never in question
This is the model: centralize authority first, reuse what already works, publish the plan. Privacy governance in NC hasn't followed this pattern yet — but it's a proven template sitting one floor over.
The Sequencing That Matters
If I were advising a new Chief Privacy Officer walking into this environment, I'd resist the instinct to close the "we don't have BigID" gap in year one. The better sequence:
1. Authority and taxonomy before tooling. Privacy in NC is fragmented across agency lines — NCDIT, DHHS, DPI each govern their own IT. Before any tool adds value, someone needs the mandate to see across those silos, and a classification taxonomy that actually reflects NC's statutory patchwork (HIPAA here, FERPA there, CJI somewhere else) rather than the generic PII/PHI/PCI categories a commercial platform ships with by default.
2. AI governance as the flagship — and NC has already laid the foundation. This is where the regulatory and reputational pressure is moving fastest — the EU AI Act's enforcement, Colorado's AI Act, and a growing expectation that any organization deploying AI can show a model inventory and a use-case risk assessment. Unlike the privacy side, NC isn't starting from zero here: Governor Stein's Executive Order 24 (2025) created an AI Leadership Council and housed an AI Accelerator within NCDIT, with oversight teams stood up in every state agency. The state already has a Responsible Use of AI Framework built around a Privacy Threshold Analysis (PTA) as its risk-assessment tool, a Generative AI use policy governing employee use of public tools, and — as of July 2026 — a 17-goal Statewide AI Strategic Roadmap. Notably, the framework's authority runs through the same statute (NCGS 143B-1376) that gives the State CIO responsibility for privacy and security across all executive branch IT — meaning AI governance and privacy governance are already legally connected in NC in a way most states haven't managed. A new CPO's opportunity isn't to invent an AI governance program; it's to plug into the Accelerator/Council structure and use the PTA as the connective tissue between AI risk and the data classification taxonomy work happening in parallel.
3. DSPM as the technical backbone — once the taxonomy exists. Data Security Posture Management tools — continuous discovery plus exposure mapping, rather than consent workflows — are a much closer fit to NC's actual risk: old systems nobody's audited access on, not a wave of citizen deletion requests. But DSPM only delivers value once someone has defined what "sensitive" means agency by agency. Buying the tool before doing that work just produces a very expensive, very confident list of false positives.
The Bigger Point
The privacy tooling market was built for a specific problem, and it's very good at that problem. State government's problem is different — not smaller, just structured differently: fragmented statutory authority, legacy systems, transparency obligations that pull against privacy obligations, and (for now) no DSAR volume driving urgency.
The states that get this right won't be the ones that buy what everyone else bought. They'll be the ones that built a governance structure that matches their actual statutory reality, then layered technology in behind it — in the order the problem actually demands, not the order a vendor's sales deck suggests.
NC's AI governance structure — EO 24, the Accelerator, the PTA, the Roadmap — is early proof this approach works. The privacy side of the house deserves the same deliberate sequencing, not a rush to buy what the AI side didn't need to.



Comments