North Carolina
North Carolina Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 6 primary sources cited on this page. How we verify our legal content

North Carolina requires businesses to notify affected residents of a data breach without unreasonable delay under the Identity Theft Protection Act, N.C. Gen. Stat. 75-65. No fixed-day deadline applies. The Consumer Protection Division of the Attorney General's Office must also receive notice of every qualifying breach.
If your business handles personal information belonging to North Carolina residents, a data breach triggers specific legal obligations under the state's Identity Theft Protection Act. N.C. Gen. Stat. 75-61 through 75-66 sets out who must be notified, what information triggers the duty, and how quickly you need to act. Enacted in 2005 and last substantively amended in 2009 (a 2025 update made only non-substantive technical and grammatical corrections), the law stands out for its enforcement mechanism: violations are treated as unfair and deceptive trade practices, exposing businesses to treble damages.
This guide covers the full scope of North Carolina's breach notification requirements, including what personal information triggers the law, who must be notified, the timeline, enforcement penalties, exemptions, and how the law interacts with the state's broader data privacy framework.
Who Must Comply With North Carolina's Breach Notification Law
North Carolina's breach notification law applies to any business that owns or licenses personal information of North Carolina residents. It also applies to any business conducting business in North Carolina that owns or licenses personal information in any form, whether computerized, paper, or otherwise.
The law distinguishes between data owners and data maintainers. If a third party maintains personal information that it does not own or license, that third party must notify the data owner or licensee of any security breach immediately following discovery. The data owner then takes on the responsibility of notifying affected consumers and the Attorney General.
This means out-of-state companies holding North Carolina residents' data are fully subject to the law. There is no exemption based on business location.
What Qualifies as a Security Breach
Under N.C. Gen. Stat. 75-61(14), a security breach is defined as an incident of unauthorized access to and acquisition of unencrypted and unredacted records or data containing personal information where:
- Illegal use of the personal information has occurred or is reasonably likely to occur, or
- The incident creates a material risk of harm to a consumer
This is a two-pronged trigger. Notification is required if either condition is met, not just when actual misuse has been confirmed.
Good Faith Exception
A good faith acquisition of personal information by an employee or agent of the business for a legitimate purpose does not constitute a security breach, provided that the personal information is not used for an unauthorized purpose and is not subject to further unauthorized disclosure.
The Encryption Safe Harbor
North Carolina provides a safe harbor for encrypted data, but with an important limitation. If the compromised data was encrypted and the encryption key was not also compromised, the incident does not qualify as a security breach. However, if the encryption key was accessed or acquired during the same breach, the safe harbor does not apply and full notification is required.

Encryption is defined under N.C. Gen. Stat. 75-61(8) as the use of an algorithmic process to transform data into a form in which the data is rendered unreadable or unusable without the use of a confidential process or key.
What Personal Information Triggers the Law
Under N.C. Gen. Stat. 75-61(10), personal information means a person's first name or first initial and last name in combination with "identifying information as defined in G.S. 14-113.20(b)." Subsection (10) itself contains no list. The enumerated data elements sit in N.C. Gen. Stat. 14-113.20(b), the criminal identity theft statute that the definition incorporates, which lists the following:
- Social Security or employer taxpayer identification numbers
- Driver's license, State identification card, or passport number
- Checking account number
- Savings account number
- Credit card number
- Debit card number
- Personal Identification (PIN) code
- Digital signatures
- Biometric data (fingerprints and other identifying data elements)
- Electronic identification numbers, email names or addresses, internet account numbers, or passwords, but for breach notification purposes only where the compromised item would permit access to a person's financial account or resources (G.S. 75-65(a))
- Parent's legal surname prior to marriage, subject to that same G.S. 75-65(a) carve-out
- Any other numbers or information that can be used to access a person's financial resources
Every category above must be combined with the person's first name or first initial and last name to qualify as personal information. North Carolina law does not recognize a standalone online-credential trigger that dispenses with the name requirement.
Personal information does not include publicly available directories or information lawfully made available to the general public.
Notification Timeline
North Carolina does not impose a fixed deadline measured in days. Instead, N.C. Gen. Stat. 75-65(a) requires notification "without unreasonable delay." The statute allows for delays that are:
- Consistent with the legitimate needs of law enforcement
- Necessary to determine sufficient contact information
- Necessary to determine the scope of the breach
- Necessary to restore the reasonable integrity, security, and confidentiality of the data system
Law enforcement may request a delay if notification would impede a criminal investigation. The request must come from a law enforcement agency, and the business may delay notification for a reasonable period of time.
Who Must Be Notified
Affected Individuals
Every person whose personal information was compromised must receive notification. The notice must be clear and conspicuous, and N.C. Gen. Stat. 75-65(d) requires it to include all seven of the following:
- A description of the incident in general terms
- A description of the type of personal information that was subject to the unauthorized access and acquisition
- A description of the general acts the business took to protect the personal information from further unauthorized access
- A telephone number for the business that the person may call for further information and assistance, if one exists
- Advice directing the person to remain vigilant by reviewing account statements and monitoring free credit reports
- The toll-free numbers and addresses for the major consumer reporting agencies
- Toll-free numbers, addresses, and website addresses for the Federal Trade Commission and the North Carolina Attorney General's Office, along with a statement that the individual can obtain information from these sources about preventing identity theft

Attorney General
The Consumer Protection Division of the North Carolina Department of Justice must be notified of every breach affecting North Carolina residents. The AG notification must include:
- The nature of the breach
- The number of consumers affected
- Steps taken to investigate the breach
- Steps taken to prevent a similar breach in the future
- Information regarding the timing, distribution, and content of the consumer notice
Consumer Reporting Agencies
When a breach affects more than 1,000 persons at one time, the business must also notify all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis. The CRA notification must include the timing, distribution, and content of the notice sent to affected individuals.
Methods of Notification
Businesses can provide notification through several methods:
- Written notice sent to the last known postal address
- Email notice if the affected person has consented to receive electronic communications
- Telephone notice provided directly to the affected person
Substitute Notice
Under N.C. Gen. Stat. 75-65(e)(4), substitute notice is available if the business demonstrates that:
- The cost of providing direct notice would exceed $250,000, or
- The affected class exceeds 500,000 persons
Either of those two triggers permits substitute notice to the entire affected class. Two further triggers exist, and the statute limits how far each one reaches:
- If the business does not have sufficient contact information or consent to give written, electronic, or telephonic notice, substitute notice is authorized for only those affected persons without sufficient contact information or consent
- If the business is unable to identify particular affected persons, substitute notice is authorized for only those unidentifiable affected persons
A business missing contact details for part of the affected class therefore cannot use that gap to substitute-notice everyone. Direct notice is still owed to every person it can reach.
Substitute notice must consist of all of the following: email notice (where the business has an email address), conspicuous posting on the business's website, and notification to major statewide media.

Enforcement and Penalties
North Carolina's enforcement mechanism is notably aggressive compared to most states. Under N.C. Gen. Stat. 75-65(i), a violation of the Identity Theft Protection Act is a violation of N.C. Gen. Stat. 75-1.1, which prohibits unfair or deceptive trade practices (UDTP).
This classification has significant consequences:
Private Right of Action
Under N.C. Gen. Stat. 75-16, any person injured by a violation of Chapter 75 may bring a civil action. If damages are assessed, the court must award treble the amount of actual damages.
That right is expressly limited by the breach notification statute itself. G.S. 75-65(i) has two sentences, and the second reads: "No private right of action may be brought by an individual for a violation of this section unless such individual is injured as a result of the violation." A consumer who was not notified but suffered no injury as a result of that failure has no claim under this section. Showing injury traceable to the notification failure, as distinct from injury caused by the breach itself, is the threshold that defeats most bare no-notice claims.
Treble Damages
The treble damages provision under G.S. 75-16 applies automatically when a court finds a UDTP violation and assesses damages. This triples whatever compensatory damages the jury awards. The statute's text contains no carve-out for non-managerial employees; treble-damages exposure applies to the business regardless of which employee's conduct caused the violation.
Attorney's Fees
Under N.C. Gen. Stat. 75-16.1, the court has discretion to award reasonable attorney's fees, but only on a specific finding: to a prevailing plaintiff if the business willfully violated the law and unreasonably refused to resolve the matter, or to a prevailing defendant if the plaintiff knew or should have known the suit was frivolous and malicious. This adds financial exposure for businesses that fail to comply, and it also discourages meritless breach-notification suits.
AG Enforcement
The North Carolina Attorney General can also bring enforcement actions under the UDTP statute, seeking injunctive relief, civil penalties, and restitution.
Exemptions
Federal Compliance Exemption
Under N.C. Gen. Stat. 75-65(h), a financial institution that is subject to and in compliance with the Federal Interagency Guidance Response Programs for Unauthorized Access to Consumer Information and Customer Notice, issued March 7, 2005 by the Board of Governors of the Federal Reserve System, the Federal Deposit Insurance Corporation, the Office of the Comptroller of the Currency, and the Office of Thrift Supervision, is deemed to be in compliance with this section. The same subsection gives a parallel safe harbor to a credit union that is subject to and in compliance with the National Credit Union Administration's Final Guidance on Response Programs for Unauthorized Access to Member Information and Member Notice, issued April 14, 2005. Revisions, additions, or substitutions to either guidance are covered as well.
The statute attaches no separate condition to this safe harbor. A qualifying institution is deemed compliant with the whole section, which already includes the Attorney General notification duty in subsection (e1).
Data Destruction Requirements
North Carolina also imposes obligations for the destruction of personal information records. Under N.C. Gen. Stat. 75-64, businesses must take reasonable measures to protect against unauthorized access to or use of personal information when destroying records. Acceptable methods include shredding, erasing, or otherwise making the information unreadable or undecipherable.
This article provides general legal information about North Carolina data privacy laws and breach notification requirements. It is not legal advice, and it does not create an attorney-client relationship. Data breach response involves time-sensitive obligations. Consult a qualified attorney licensed in North Carolina for guidance specific to your situation.
More North Carolina Laws
Frequently Asked Questions
How quickly must a business notify North Carolina residents of a data breach?
North Carolina requires notification without unreasonable delay under N.C. Gen. Stat. 75-65. There is no specific number of days. The timeline must account for law enforcement needs and the business's need to determine the scope of the breach and restore system security.
Can individuals sue a business in North Carolina for failing to provide breach notification?
Yes, but only if the individual was injured by the violation. N.C. Gen. Stat. 75-65(i) provides that no private right of action may be brought unless the individual is injured as a result of the violation. Where that threshold is met, the violation is an unfair and deceptive trade practice under N.C. Gen. Stat. 75-1.1 and the individual may sue under N.C. Gen. Stat. 75-16, where treble damages are mandatory once damages are assessed. Attorney's fees are not automatic: under N.C. Gen. Stat. 75-16.1 they are discretionary and require a finding that the violation was willful and that the business unreasonably refused to resolve the matter.
Does the North Carolina Attorney General need to be notified of every data breach?
Yes. The Consumer Protection Division of the NC Department of Justice must be notified of every breach affecting North Carolina residents, regardless of size. Consumer reporting agencies must also be notified when the breach affects more than 1,000 individuals.
Does encrypting data exempt a business from North Carolina breach notification?
Encryption provides a safe harbor only if the encryption key was not compromised during the breach. If both the encrypted data and the key were accessed, the safe harbor does not apply and the business must still notify affected individuals and the Attorney General.
What damages can a court award in a North Carolina data breach case?
Courts must award treble (triple) the actual damages assessed once a UDTP violation is found. The court may also award reasonable attorney's fees, but only on specific findings: to a prevailing plaintiff if the violation was willful and the business unreasonably refused to resolve the matter, or to a prevailing defendant if the suit was frivolous and malicious. This makes North Carolina one of the more plaintiff-friendly states for data breach litigation.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the encryption and personal-information citations, added the missing data elements and the three omitted notice-content requirements, and clarified that North Carolina law allows a private lawsuit over a breach notification failure only by an individual injured as a result of the violation.
Corrected the consumer-reporting-agency notification threshold to more than 1,000 residents, fixed a mis-cited statute for the UDTP-violation rule, removed an inaccurate description of what personal information triggers the law (adding passwords as a listed category), noted a 2025 technical-only amendment, added a fourth substitute-notice condition, and clarified that attorney's-fee awards are discretionary and can run to either side.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Removed two unsupported exemptions/carve-outs from N.C.'s data breach notification page. G.S. 75-16 (treble damages) contains no non-managerial-employee exception anywhere in its text -- it applies treble damages broadly to 'any other person, firm or corporation' with no employment-based limitation, and no supporting NC case law for such a carve-out was found. Separately, the full text of G.S. 75-65 (through subsection (j)) contains no HIPAA-covered-entity exemption; the only federal-compliance exemption in the statute is for financial institutions/credit unions following federal banking-regulator guidance (subsection (h), correctly described elsewhere on the page), so the standalone 'HIPAA Entities' exemption claim was removed as fabricated.
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
North Carolina General Statutes, Chapter 75: Monopolies, Trusts and Consumer Protection.
§ 75-65Protection from security breachesIn forcecited in 4 of our articles
(a) Any business that owns or licenses personal information of residents of North Carolina or any business that conducts business in North Carolina that owns or licenses personal information in any form (whether computerized, paper, or otherwise) shall provide notice to the affected person that there has been a security breach following discovery or notification of the breach. The disclosure notification shall be made without unreasonable delay, consistent with the legitimate needs of law enforcement, as provided in subsection (c) of this section, and consistent with any measures necessary to determine sufficient contact information, determine the scope of the breach and restore the reasonable integrity, security, and confidentiality of the data system. For the purposes of this section, personal information shall not include electronic identification numbers, email names or addresses, internet account numbers, internet identification names, parent's legal surname prior to marriage, or a password unless this information would permit access to a person's financial account or resources.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at ncleg.gov
Cited in 2 court opinions in our collectionLatest citing opinion in our collection: 2025
Opinions citing this section in our collection:
- Rogers v. Keffer, Inc. (District Court, E.D. North Carolina 2017, 243 F. Supp. 3d 650)“…TPA for failing to notify the victim of a security breach. N.C. Gen. Stat. § 75-65 . “Any business that maintains or posse…”
- Rhodes v. Navy Federal Credit Union (District Court, E.D. North Carolina 2025)“…n. Stat. § 53-176; 5) “financial privacy violation,” under N.C. Gen. Stat. § 75-65; and 6) intentional infliction of emot…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: North Carolina Data Privacy Laws: Consumer Rights & Protections (2026), North Carolina Employee Monitoring Laws: Workplace Surveillance and Social Media (2026), North Carolina Biometric Privacy Laws: Collection, Consent & Penalties (2026)
§ 75-61DefinitionsIn forcecited in 3 of our articles
The following definitions apply in this Article: (1) "Business". - A sole proprietorship, partnership, corporation, association, or other group, however organized and whether or not organized to operate at a profit. The term includes a financial institution organized, chartered, or holding a license or authorization certificate under the laws of this State, any other state, the United States, or any other country, or the parent or the subsidiary of any such financial institution. Business shall not include any government or governmental subdivision or agency. (2) "Consumer". - An individual. (3) "Consumer report" or "credit report". - Any written, oral, or other communication of any information by a consumer reporting agency bearing on a consumer's creditworthiness, credit standing, credit capacity, character, general reputation, personal characteristics, or mode of living which is used or expected to be used or collected in whole or in part for the purpose of serving as a factor in establishing the consumer's eligibility for any of the following: a. Credit to be used primarily for personal, family, or household purposes. b. Employment purposes. c.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at ncleg.gov
Cited in 4 court opinions in our collectionLatest citing opinion in our collection: 2025
Opinions citing this section in our collection:
- Fisher v. Commc'n Workers of Am. (North Carolina Business Court 2008, 2008 NCBC 18)“…nized and whether or not organized to operate at a profit.” N.C. Gen. Stat. § 75-61(1) (2007). {48} A business does not…”
- DiCesare v. Charlotte-Mecklenburg Hosp. Auth. (Supreme Court of North Carolina 2020)“…chase of electricity or other municipal utilities) and N.C.G.S. § 75-61(9) (adopting a separate definition of…”
- Rogers v. Keffer, Inc. (District Court, E.D. North Carolina 2017, 243 F. Supp. 3d 650)“…s and is not subject to further unauthorized disclosure. N.C. Gen. Stat. § 75-61 (14). A plaintiff must bring a claim fo…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- N.C. Gen. Stat. 75-65 - Protection from Security Breaches(ncleg.gov).gov
- N.C. Gen. Stat. 75-61 - Definitions(ncleg.gov).gov
- NC Chapter 75 Article 2A - Identity Theft Protection Act(ncleg.gov).gov
- NC Chapter 75 Article 1 - UDTP Act(ncleg.gov).gov
- NC DOJ - Security Breach Information(ncdoj.gov).gov
- NC DOJ - Report a Security Breach(ncdoj.gov).gov
- N.C. Gen. Stat. 14-113.20 - Identity theft (definition of identifying information incorporated by G.S. 75-61(10))(ncleg.gov)
- N.C. Gen. Stat. 75-16.1 - Attorney fee(ncleg.gov)