EnglishEspañol
North Carolina flag

North Carolina

North Carolina Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 6 primary sources cited on this page. How we verify our legal content

North Carolina Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Frequently Asked Questions

How quickly must a business notify North Carolina residents of a data breach?

North Carolina requires notification without unreasonable delay under N.C. Gen. Stat. 75-65. There is no specific number of days. The timeline must account for law enforcement needs and the business's need to determine the scope of the breach and restore system security.

Can individuals sue a business in North Carolina for failing to provide breach notification?

Yes, but only if the individual was injured by the violation. N.C. Gen. Stat. 75-65(i) provides that no private right of action may be brought unless the individual is injured as a result of the violation. Where that threshold is met, the violation is an unfair and deceptive trade practice under N.C. Gen. Stat. 75-1.1 and the individual may sue under N.C. Gen. Stat. 75-16, where treble damages are mandatory once damages are assessed. Attorney's fees are not automatic: under N.C. Gen. Stat. 75-16.1 they are discretionary and require a finding that the violation was willful and that the business unreasonably refused to resolve the matter.

Does the North Carolina Attorney General need to be notified of every data breach?

Yes. The Consumer Protection Division of the NC Department of Justice must be notified of every breach affecting North Carolina residents, regardless of size. Consumer reporting agencies must also be notified when the breach affects more than 1,000 individuals.

Does encrypting data exempt a business from North Carolina breach notification?

Encryption provides a safe harbor only if the encryption key was not compromised during the breach. If both the encrypted data and the key were accessed, the safe harbor does not apply and the business must still notify affected individuals and the Attorney General.

What damages can a court award in a North Carolina data breach case?

Courts must award treble (triple) the actual damages assessed once a UDTP violation is found. The court may also award reasonable attorney's fees, but only on specific findings: to a prevailing plaintiff if the violation was willful and the business unreasonably refused to resolve the matter, or to a prevailing defendant if the suit was frivolous and malicious. This makes North Carolina one of the more plaintiff-friendly states for data breach litigation.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the encryption and personal-information citations, added the missing data elements and the three omitted notice-content requirements, and clarified that North Carolina law allows a private lawsuit over a breach notification failure only by an individual injured as a result of the violation.

Corrected the consumer-reporting-agency notification threshold to more than 1,000 residents, fixed a mis-cited statute for the UDTP-violation rule, removed an inaccurate description of what personal information triggers the law (adding passwords as a listed category), noted a 2025 technical-only amendment, added a fourth substitute-notice condition, and clarified that attorney's-fee awards are discretionary and can run to either side.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Removed two unsupported exemptions/carve-outs from N.C.'s data breach notification page. G.S. 75-16 (treble damages) contains no non-managerial-employee exception anywhere in its text -- it applies treble damages broadly to 'any other person, firm or corporation' with no employment-based limitation, and no supporting NC case law for such a carve-out was found. Separately, the full text of G.S. 75-65 (through subsection (j)) contains no HIPAA-covered-entity exemption; the only federal-compliance exemption in the statute is for financial institutions/credit unions following federal banking-regulator guidance (subsection (h), correctly described elsewhere on the page), so the standalone 'HIPAA Entities' exemption claim was removed as fabricated.

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. N.C. Gen. Stat. 75-65 - Protection from Security Breaches(ncleg.gov).gov
  2. N.C. Gen. Stat. 75-61 - Definitions(ncleg.gov).gov
  3. NC Chapter 75 Article 2A - Identity Theft Protection Act(ncleg.gov).gov
  4. NC Chapter 75 Article 1 - UDTP Act(ncleg.gov).gov
  5. NC DOJ - Security Breach Information(ncdoj.gov).gov
  6. NC DOJ - Report a Security Breach(ncdoj.gov).gov
  7. N.C. Gen. Stat. 14-113.20 - Identity theft (definition of identifying information incorporated by G.S. 75-61(10))(ncleg.gov)
  8. N.C. Gen. Stat. 75-16.1 - Attorney fee(ncleg.gov)
Share: