North Carolina
North Carolina Biometric Privacy Laws: Collection, Consent & Penalties (2026)

North Carolina has no standalone biometric privacy law. The state's Identity Theft Protection Act (N.C. Gen. Stat. 75-65) protects biometric data only through breach notification rules: businesses face no consent requirement before collecting biometric identifiers, but must notify affected individuals if that data is compromised and face treble damages under the state's consumer protection statute.
North Carolina takes a different approach to biometric privacy than states like Illinois or Texas. Rather than enacting a dedicated biometric privacy statute, the state folds biometric data into its existing breach notification and consumer protection framework.
The result is a system where businesses face no up-front consent requirements for collecting biometric data, but they face serious consequences if that data is compromised in a breach. Those consequences include mandatory treble damages under the state's Unfair and Deceptive Trade Practices (UDTP) statute.
For an overview of North Carolina's broader privacy framework, see the parent guide to North Carolina Data Privacy Laws.
How North Carolina Law Defines Biometric Data
North Carolina's breach notification law at N.C. Gen. Stat. 75-65 defines "personal information" by reference to the identity theft statute at N.C. Gen. Stat. 14-113.20(b). That statute lists "identifying information" that includes:
- Biometric data
- Fingerprints
- Digital signatures
- Passwords
- Social Security numbers
- Driver's license numbers
- Financial account numbers

The statute lists "biometric data" and "fingerprints" as separate categories (items 11 and 12 in the list), which means the law covers both general biometric identifiers and fingerprints specifically.
Notably, North Carolina law does not further define what "biometric data" includes. Unlike states with dedicated biometric privacy laws, there is no statutory language specifying whether the term covers voiceprints, iris scans, facial geometry, or other biological measurements. This lack of specificity could create ambiguity in enforcement.
Breach Notification Requirements for Biometric Data
The Identity Theft Protection Act at N.C. Gen. Stat. 75-65 establishes breach notification obligations that apply when biometric data is compromised.
Who must comply. Any business that owns, licenses, or maintains personal information of North Carolina residents must provide notice following a security breach. This applies regardless of whether the business is located in North Carolina.
What triggers notification. A "security breach" is the unauthorized access to and acquisition of unencrypted and unredacted records containing personal information where illegal use has occurred or is reasonably likely, or where the breach creates a material risk of harm. If a breach exposes biometric data in combination with an individual's first name (or initial) and last name, notification is required.
Timing. Businesses must notify affected individuals "without unreasonable delay." North Carolina does not set a specific day count for consumer notification, but businesses must notify the NC Attorney General's Consumer Protection Division without unreasonable delay after providing notice to affected persons.
Notice content. The notification must include:
- A general description of the incident
- The type of personal information exposed
- Steps the business is taking to prevent further unauthorized access
- A contact telephone number
- Advice to monitor account statements and credit reports
- Contact information for major credit reporting agencies
- Contact information for the FTC and the NC Attorney General's Office
Large breaches. When a breach affects more than 1,000 people, the business must also notify all nationwide consumer reporting agencies of the timing, distribution, and content of the notice.

The UDTP Connection: Treble Damages and Private Right of Action
This is where North Carolina's approach becomes uniquely powerful for consumers. Section 75-65(i) explicitly states that a violation of the breach notification law is a violation of N.C. Gen. Stat. 75-1.1, the state's Unfair and Deceptive Trade Practices Act.
This connection triggers two significant remedies:
Treble damages. Under N.C. Gen. Stat. 75-16, any person injured by a UDTP violation can recover treble (triple) the actual damages. If a court finds $10,000 in damages from a biometric data breach, the judgment becomes $30,000.
Attorney fees. Under N.C. Gen. Stat. 75-16.1, the court may award reasonable attorney fees to the prevailing party when the violation was willful and there was an unwarranted refusal to resolve the matter.
Injury requirement. There is an important limitation. Section 75-65(i) provides that no private right of action may be brought unless the individual "is injured as a result of the violation." This means a consumer must show actual harm from the breach, not merely that the breach occurred.
No waiver. Any attempt to waive the protections of the Identity Theft Protection Act is void and unenforceable under Section 75-65(g). A business cannot require consumers to sign away their breach notification rights.
Attorney General Enforcement
The North Carolina Attorney General's Office plays a central role in biometric data protection through breach oversight.
Businesses must report security breaches involving biometric data to the Consumer Protection Division. The report must include:
- The nature of the breach
- The number of consumers affected
- Steps taken to investigate
- Steps taken to prevent future breaches
- Timing, distribution, and content of the consumer notice
The Attorney General can also bring enforcement actions under the UDTP statute for breach notification failures. In 2023, North Carolina received reports of over 2,033 data breaches affecting more than 4.9 million residents, demonstrating the scale of the state's breach notification enforcement activity.

No General Consent Requirement for Biometric Collection
Unlike Illinois (which requires written informed consent before collecting biometric data) or Texas (which requires notice and consent), North Carolina currently has no law requiring businesses to obtain consent before collecting, using, or storing biometric data.
This means:
- An employer can require fingerprint scans for timekeeping without specific notice or consent
- A retailer can use facial recognition technology without informing customers
- A business can store biometric data indefinitely with no retention limits
- There is no requirement to publish a biometric data policy
The only obligation arises if that biometric data is later compromised in a breach. At that point, the breach notification and UDTP frameworks activate.
Employer Use of Biometric Data
North Carolina does not have a law specifically regulating employer collection or use of biometric data. Employers routinely collect biometric information for several purposes:
Fingerprint-based background checks. North Carolina law authorizes fingerprint collection for criminal history record checks through the NC State Bureau of Investigation. Certain positions, particularly those involving work with children, require fingerprint-based background checks under state law.
Biometric timekeeping. Many North Carolina employers use fingerprint or hand-geometry scanners for employee time and attendance tracking. No state law requires consent for this practice.
Facility access. Fingerprint scanners, iris readers, and facial recognition systems used for building access are not regulated under any NC biometric-specific statute.
While state law does not impose consent requirements, employers should be aware that biometric data collected in the workplace is still subject to breach notification requirements if compromised. The treble damages available under the UDTP statute create a strong incentive for employers to secure biometric data properly.
Pending Legislation: The NC Personal Data Privacy Act (HB 462)
North Carolina legislators have been working on comprehensive privacy legislation. House Bill 462, introduced in the 2025 session, would create the NC Personal Data Privacy Act under a new Chapter 75F of the General Statutes.
If enacted, HB 462 would significantly change the biometric privacy landscape in North Carolina:
Biometric data definition. The bill defines biometric data as information generated by automatic measurements of an individual's unique biological characteristics, including fingerprints, voiceprints, eye retinas, irises, or other unique biological patterns used to identify or authenticate a specific individual. Photographs, video, and audio recordings would be excluded unless used to identify someone.
Sensitive data classification. Biometric data processed for identification would be classified as "sensitive data," the highest protection tier under the proposed law.
Opt-in consent. Businesses would need to obtain affirmative consent before processing biometric data for identification purposes.
Consumer rights. North Carolinians would gain the right to access, correct, delete, and obtain portable copies of their biometric data.
AG enforcement only. The bill does not include a private right of action. The Attorney General would have exclusive enforcement authority.
As of early 2026, HB 462 remains in committee and has not been enacted. A companion bill, Senate Bill 757, contains similar provisions.
How North Carolina Compares to Other States
North Carolina's approach to biometric privacy sits in the lower-middle tier of state protections:
Stronger than states with no protections. North Carolina's inclusion of biometric data in its breach notification law and the availability of treble damages through the UDTP statute provide more protection than states like Alabama or Mississippi, which have minimal biometric data protections.
Weaker than dedicated biometric privacy states. States with standalone biometric privacy laws, including Illinois, Texas, and Washington, require consent before collection, mandate retention and destruction policies, and (in Illinois's case) provide a private right of action that has generated billions in settlements.
Weaker than comprehensive privacy law states. States like Virginia, Colorado, and Kentucky have enacted comprehensive consumer privacy laws that classify biometric data as sensitive data requiring opt-in consent. North Carolina has not yet joined this group.
Notable strength: treble damages. One area where North Carolina stands out is the automatic treble damages available through the UDTP statute. Most states with comprehensive privacy laws cap penalties per violation and exclude private lawsuits entirely. North Carolina's approach allows individual consumers to sue and potentially recover three times their actual damages, plus attorney fees.
Sources and References
This article references North Carolina statutes and official state government publications. For the full text of the Identity Theft Protection Act, visit the NC General Assembly website. To report a data breach or file a complaint, contact the NC Attorney General's Consumer Protection Division.
This article provides general legal information about North Carolina biometric privacy laws. It is not legal advice. Consult a qualified attorney for guidance on your specific situation. Laws and regulations change frequently. Verify current requirements through official North Carolina government sources.
More North Carolina Laws
Frequently Asked Questions
Does North Carolina have a biometric privacy law?
North Carolina does not have a standalone biometric privacy law like Illinois BIPA. Instead, biometric data is protected through the state's Identity Theft Protection Act (N.C. Gen. Stat. 75-65), which requires businesses to notify individuals when a data breach compromises their biometric information. Violations are treated as unfair and deceptive trade practices, which carry treble damages.
Can my employer collect my fingerprints without consent in North Carolina?
Yes. North Carolina does not currently require employers to obtain consent before collecting biometric data such as fingerprints, facial scans, or iris images. Employers can use biometric timekeeping systems, fingerprint-based access controls, and similar technologies without specific notice or consent requirements. However, the employer must provide breach notification and could face treble damages if that biometric data is later compromised.
What damages can I recover if my biometric data is exposed in a breach in North Carolina?
If you can show actual injury from a biometric data breach, you may sue under the Unfair and Deceptive Trade Practices Act (N.C. Gen. Stat. 75-1.1) and recover treble (triple) your actual damages. You may also recover attorney fees if the violation was willful. However, you must demonstrate that you were injured as a result of the breach, not merely that the breach occurred.
Do businesses need to report biometric data breaches to the North Carolina Attorney General?
Yes. Under N.C. Gen. Stat. 75-65, any business that notifies affected individuals of a security breach must also report the breach to the Consumer Protection Division of the NC Attorney General's Office. The report must describe the nature of the breach, the number of affected consumers, investigative steps taken, and the content of the consumer notice.
Will North Carolina pass a comprehensive biometric privacy law?
North Carolina has pending legislation that would strengthen biometric privacy protections. House Bill 462, the NC Personal Data Privacy Act, was introduced in 2025 and would classify biometric data as sensitive data requiring opt-in consent. A companion Senate Bill 757 contains similar provisions. As of early 2026, neither bill has been enacted, but biometric privacy legislation remains an active topic in the General Assembly.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Governing law re-checked for recent changes
The Law Behind This Article
This article rests on 6 statutory provisions held in our own legal record, each retrieved from the official source. Tap a section to read the operative text.
North Carolina General Statutes, Chapter 14: Criminal Law.
§ 14-113.20Identity theftIn forcecited in 3 of our articles
(a) A person who knowingly obtains, possesses, or uses identifying information of another person, living or dead, with the intent to fraudulently represent that the person is the other person for the purposes of making financial or credit transactions in the other person's name, to obtain anything of value, benefit, or advantage, or for the purpose of avoiding legal consequences is guilty of a felony punishable as provided in G.S. 14-113.22(a). (b) The term "identifying information" as used in this Article includes the following: (1) Social security or employer taxpayer identification numbers. (2) Drivers license, State identification card, or passport numbers. (3) Checking account numbers. (4) Savings account numbers. (5) Credit card numbers. (6) Debit card numbers. (7) Personal Identification (PIN) Code as defined in G.S. 14-113.8(6). (8) Electronic identification numbers, email names or addresses, internet account numbers, or internet identification names. (9) Digital signatures. (10) Any other numbers or information that can be used to access a person's financial resources. (11) Biometric data. (12) Fingerprints. (13) Passwords.
Official text (excerpt) · as of 2026-07-29 · Read the full section at ncleg.gov
Also relied on in: North Carolina Data Privacy Laws: Consumer Rights & Protections (2026), North Carolina Employee Monitoring Laws: Workplace Surveillance and Social Media (2026)
North Carolina General Statutes, Chapter 75: Monopolies, Trusts and Consumer Protection.
§ 75-1.1Methods of competition, acts and practices regulated; legislative policyIn forcecited in 2 of our articles
(a) Unfair methods of competition in or affecting commerce, and unfair or deceptive acts or practices in or affecting commerce, are declared unlawful. (b) For purposes of this section, "commerce" includes all business activities, however denominated, but does not include professional services rendered by a member of a learned profession. (c) Nothing in this section shall apply to acts done by the publisher, owner, agent, or employee of a newspaper, periodical or radio or television station, or other advertising medium in the publication or dissemination of an advertisement, when the owner, agent or employee did not have knowledge of the false, misleading or deceptive character of the advertisement and when the newspaper, periodical or radio or television station, or other advertising medium did not have a direct financial interest in the sale or distribution of the advertised product or service. (d) Any party claiming to be exempt from the provisions of this section shall have the burden of proof with respect to such claim.
Official text (excerpt) · as of 2026-07-29 · Read the full section at ncleg.gov
Also relied on in: North Carolina Lemon Law (2026): How to Qualify & Get a Refund
§ 75-16Civil action by person injured; treble damagesIn force
If any person shall be injured or the business of any person, firm or corporation shall be broken up, destroyed or injured by reason of any act or thing done by any other person, firm or corporation in violation of the provisions of this Chapter, such person, firm or corporation so injured shall have a right of action on account of such injury done, and if damages are assessed in such case judgment shall be rendered in favor of the plaintiff and against the defendant for treble the amount fixed by the verdict.
Official text (excerpt) · as of 2026-07-29 · Read the full section at ncleg.gov
§ 75-16.1Attorney feeIn force
In any suit instituted by a person who alleges that the defendant violated G.S. 75-1.1, the presiding judge may, in his discretion, allow a reasonable attorney fee to the duly licensed attorney representing the prevailing party, such attorney fee to be taxed as a part of the court costs and payable by the losing party, upon a finding by the presiding judge that: (1) The party charged with the violation has willfully engaged in the act or practice, and there was an unwarranted refusal by such party to fully resolve the matter which constitutes the basis of such suit; or (2) The party instituting the action knew, or should have known, the action was frivolous and malicious.
Official text (excerpt) · as of 2026-07-29 · Read the full section at ncleg.gov
§ 75-61DefinitionsIn forcecited in 3 of our articles
The following definitions apply in this Article: (1) "Business". - A sole proprietorship, partnership, corporation, association, or other group, however organized and whether or not organized to operate at a profit. The term includes a financial institution organized, chartered, or holding a license or authorization certificate under the laws of this State, any other state, the United States, or any other country, or the parent or the subsidiary of any such financial institution. Business shall not include any government or governmental subdivision or agency. (2) "Consumer". - An individual. (3) "Consumer report" or "credit report". - Any written, oral, or other communication of any information by a consumer reporting agency bearing on a consumer's creditworthiness, credit standing, credit capacity, character, general reputation, personal characteristics, or mode of living which is used or expected to be used or collected in whole or in part for the purpose of serving as a factor in establishing the consumer's eligibility for any of the following: a. Credit to be used primarily for personal, family, or household purposes. b. Employment purposes. c.
Official text (excerpt) · as of 2026-07-29 · Read the full section at ncleg.gov
Also relied on in: North Carolina Data Breach Notification Laws: Reporting Rules & Timelines (2026)
§ 75-65Protection from security breachesIn forcecited in 4 of our articles
(a) Any business that owns or licenses personal information of residents of North Carolina or any business that conducts business in North Carolina that owns or licenses personal information in any form (whether computerized, paper, or otherwise) shall provide notice to the affected person that there has been a security breach following discovery or notification of the breach. The disclosure notification shall be made without unreasonable delay, consistent with the legitimate needs of law enforcement, as provided in subsection (c) of this section, and consistent with any measures necessary to determine sufficient contact information, determine the scope of the breach and restore the reasonable integrity, security, and confidentiality of the data system. For the purposes of this section, personal information shall not include electronic identification numbers, email names or addresses, internet account numbers, internet identification names, parent's legal surname prior to marriage, or a password unless this information would permit access to a person's financial account or resources.
Official text (excerpt) · as of 2026-07-29 · Read the full section at ncleg.gov
Search our full record of US law — 1.79 million sections, every state + federal →
Sources and References
- N.C. Gen. Stat. 75-65 - Protection from security breaches(ncleg.gov).gov
- N.C. Gen. Stat. 14-113.20 - Identity theft identifying information definitions(ncleg.gov).gov
- N.C. Gen. Stat. 75-1.1 - Unfair and Deceptive Trade Practices Act(ncleg.gov).gov
- N.C. Gen. Stat. 75-16 - Treble damages provision(ncleg.gov).gov
- N.C. Gen. Stat. 75-16.1 - Attorney fee provision(ncleg.gov).gov
- NC DOJ Security Breach Information(ncdoj.gov).gov
- NC Attorney General 2023 Data Breach Report(ncdoj.gov).gov
- NC SBI Fingerprinting(ncsbi.gov).gov
- House Bill 462 - NC Personal Data Privacy Act(ncleg.gov).gov
- Senate Bill 757 - Consumer Privacy Act(ncleg.gov).gov
- N.C. Gen. Stat. 75-61 - Article 2A Definitions(ncleg.gov).gov