North Carolina
North Carolina Data Breach Notification Laws: Reporting Rules & Timelines (2026)

North Carolina requires businesses to notify affected residents of a data breach without unreasonable delay under the Identity Theft Protection Act, N.C. Gen. Stat. 75-65. No fixed-day deadline applies. The Consumer Protection Division of the Attorney General's Office must also receive notice of every qualifying breach.
If your business handles personal information belonging to North Carolina residents, a data breach triggers specific legal obligations under the state's Identity Theft Protection Act. N.C. Gen. Stat. 75-61 through 75-66 sets out who must be notified, what information triggers the duty, and how quickly you need to act. Enacted in 2005 and amended most recently in 2009, the law stands out for its enforcement mechanism: violations are treated as unfair and deceptive trade practices, exposing businesses to treble damages.
This guide covers the full scope of North Carolina's breach notification requirements, including what personal information triggers the law, who must be notified, the timeline, enforcement penalties, exemptions, and how the law interacts with the state's broader data privacy framework.
Who Must Comply With North Carolina's Breach Notification Law
North Carolina's breach notification law applies to any business that owns or licenses personal information of North Carolina residents. It also applies to any business conducting business in North Carolina that owns or licenses personal information in any form, whether computerized, paper, or otherwise.
The law distinguishes between data owners and data maintainers. If a third party maintains personal information that it does not own or license, that third party must notify the data owner or licensee of any security breach immediately following discovery. The data owner then takes on the responsibility of notifying affected consumers and the Attorney General.
This means out-of-state companies holding North Carolina residents' data are fully subject to the law. There is no exemption based on business location.
What Qualifies as a Security Breach
Under N.C. Gen. Stat. 75-61(14), a security breach is defined as an incident of unauthorized access to and acquisition of unencrypted and unredacted records or data containing personal information where:
- Illegal use of the personal information has occurred or is reasonably likely to occur, or
- The incident creates a material risk of harm to a consumer
This is a two-pronged trigger. Notification is required if either condition is met, not just when actual misuse has been confirmed.
Good Faith Exception
A good faith acquisition of personal information by an employee or agent of the business for a legitimate purpose does not constitute a security breach, provided that the personal information is not used for an unauthorized purpose and is not subject to further unauthorized disclosure.
The Encryption Safe Harbor
North Carolina provides a safe harbor for encrypted data, but with an important limitation. If the compromised data was encrypted and the encryption key was not also compromised, the incident does not qualify as a security breach. However, if the encryption key was accessed or acquired during the same breach, the safe harbor does not apply and full notification is required.

Encryption is defined under N.C. Gen. Stat. 75-61(6) as the use of an algorithmic process to transform data into a form in which the data is rendered unreadable or unusable without the use of a confidential process or key.
What Personal Information Triggers the Law
Under N.C. Gen. Stat. 75-61(10), personal information means a person's first name or first initial and last name in combination with any of the following:
- Social Security number
- Driver's license, State identification card, or passport number
- Checking account number
- Savings account number
- Credit card number
- Debit card number
- Personal Identification (PIN) code
- Digital signatures
- Biometric data (fingerprints and other identifying data elements)
- Any other numbers or information that can be used to access a person's financial resources
The definition also includes electronic identification numbers, email addresses, or internet account numbers in combination with passwords, security questions, or other credentials that would permit access to an online account.
Personal information does not include publicly available directories or information lawfully made available to the general public.
Notification Timeline
North Carolina does not impose a fixed deadline measured in days. Instead, N.C. Gen. Stat. 75-65(a) requires notification "without unreasonable delay." The statute allows for delays that are:
- Consistent with the legitimate needs of law enforcement
- Necessary to determine sufficient contact information
- Necessary to determine the scope of the breach
- Necessary to restore the reasonable integrity, security, and confidentiality of the data system
Law enforcement may request a delay if notification would impede a criminal investigation. The request must come from a law enforcement agency, and the business may delay notification for a reasonable period of time.
Who Must Be Notified
Affected Individuals
Every person whose personal information was compromised must receive notification. The notice must be clear and conspicuous and include:
- A description of the incident
- The type of personal information involved
- Steps the business has taken or plans to take regarding the breach
- Toll-free numbers, addresses, and website addresses for the Federal Trade Commission and the North Carolina Attorney General's Office
- A statement that the individual can obtain information from these sources about preventing identity theft

Attorney General
The Consumer Protection Division of the North Carolina Department of Justice must be notified of every breach affecting North Carolina residents. The AG notification must include:
- The nature of the breach
- The number of consumers affected
- Steps taken to investigate the breach
- Steps taken to prevent a similar breach in the future
- Information regarding the timing, distribution, and content of the consumer notice
Consumer Reporting Agencies
When a breach affects more than 1,000 persons at one time, the business must also notify all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis. The CRA notification must include the timing, distribution, and content of the notice sent to affected individuals.
Methods of Notification
Businesses can provide notification through several methods:
- Written notice sent to the last known postal address
- Email notice if the affected person has consented to receive electronic communications
- Telephone notice provided directly to the affected person
Substitute Notice
Substitute notice is available if the business can demonstrate that:
- The cost of providing direct notice would exceed $250,000, or
- The affected class exceeds 500,000 persons, or
- The business lacks sufficient contact information
Substitute notice must consist of all of the following: email notice (where the business has an email address), conspicuous posting on the business's website, and notification to major statewide media.

Enforcement and Penalties
North Carolina's enforcement mechanism is notably aggressive compared to most states. Under N.C. Gen. Stat. 75-66, a violation of the Identity Theft Protection Act is a violation of N.C. Gen. Stat. 75-1.1, which prohibits unfair or deceptive trade practices (UDTP).
This classification has significant consequences:
Private Right of Action
Under N.C. Gen. Stat. 75-16, any person injured by a violation of Chapter 75 may bring a civil action. If damages are assessed, the court must award treble the amount of actual damages. This means affected consumers can sue businesses directly for breach notification failures.
Treble Damages
The treble damages provision under G.S. 75-16 applies automatically when a court finds a UDTP violation and assesses damages. This triples whatever compensatory damages the jury awards. The statute's text contains no carve-out for non-managerial employees; treble-damages exposure applies to the business regardless of which employee's conduct caused the violation.
Attorney's Fees
Under N.C. Gen. Stat. 75-16.1, the court may award reasonable attorney's fees to the prevailing party. This further increases the financial exposure for businesses that fail to comply.
AG Enforcement
The North Carolina Attorney General can also bring enforcement actions under the UDTP statute, seeking injunctive relief, civil penalties, and restitution.
Exemptions
Federal Compliance Exemption
Financial institutions that maintain breach notification procedures in compliance with federal interagency guidance on response programs for unauthorized access to customer information under the Gramm-Leach-Bliley Act are exempt from the state breach notification requirements, provided they notify the AG as required.
Data Destruction Requirements
North Carolina also imposes obligations for the destruction of personal information records. Under N.C. Gen. Stat. 75-64, businesses must take reasonable measures to protect against unauthorized access to or use of personal information when destroying records. Acceptable methods include shredding, erasing, or otherwise making the information unreadable or undecipherable.
This article provides general legal information about North Carolina data privacy laws and breach notification requirements. It is not legal advice, and it does not create an attorney-client relationship. Data breach response involves time-sensitive obligations. Consult a qualified attorney licensed in North Carolina for guidance specific to your situation.
More North Carolina Laws
Frequently Asked Questions
How quickly must a business notify North Carolina residents of a data breach?
North Carolina requires notification without unreasonable delay under N.C. Gen. Stat. 75-65. There is no specific number of days. The timeline must account for law enforcement needs and the business's need to determine the scope of the breach and restore system security.
Can individuals sue a business in North Carolina for failing to provide breach notification?
Yes. North Carolina is one of the few states that provides a private right of action for breach notification failures. Violations are classified as unfair and deceptive trade practices under N.C. Gen. Stat. 75-1.1, and individuals can sue under N.C. Gen. Stat. 75-16 for treble damages plus attorney's fees.
Does the North Carolina Attorney General need to be notified of every data breach?
Yes. The Consumer Protection Division of the NC Department of Justice must be notified of every breach affecting North Carolina residents, regardless of size. Consumer reporting agencies must also be notified when the breach affects more than 1,000 individuals.
Does encrypting data exempt a business from North Carolina breach notification?
Encryption provides a safe harbor only if the encryption key was not compromised during the breach. If both the encrypted data and the key were accessed, the safe harbor does not apply and the business must still notify affected individuals and the Attorney General.
What damages can a court award in a North Carolina data breach case?
Courts must award treble (triple) the actual damages assessed, plus the court may award reasonable attorney's fees to the prevailing party. This makes North Carolina one of the most plaintiff-friendly states for data breach litigation.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Removed two unsupported exemptions/carve-outs from N.C.'s data breach notification page. G.S. 75-16 (treble damages) contains no non-managerial-employee exception anywhere in its text -- it applies treble damages broadly to 'any other person, firm or corporation' with no employment-based limitation, and no supporting NC case law for such a carve-out was found. Separately, the full text of G.S. 75-65 (through subsection (j)) contains no HIPAA-covered-entity exemption; the only federal-compliance exemption in the statute is for financial institutions/credit unions following federal banking-regulator guidance (subsection (h), correctly described elsewhere on the page), so the standalone 'HIPAA Entities' exemption claim was removed as fabricated.
Governing law re-checked for recent changes
The Law Behind This Article
This article rests on 2 statutory provisions held in our own legal record, each retrieved from the official source. Tap a section to read the operative text.
North Carolina General Statutes, Chapter 75: Monopolies, Trusts and Consumer Protection.
§ 75-61DefinitionsIn forcecited in 3 of our articles
The following definitions apply in this Article: (1) "Business". - A sole proprietorship, partnership, corporation, association, or other group, however organized and whether or not organized to operate at a profit. The term includes a financial institution organized, chartered, or holding a license or authorization certificate under the laws of this State, any other state, the United States, or any other country, or the parent or the subsidiary of any such financial institution. Business shall not include any government or governmental subdivision or agency. (2) "Consumer". - An individual. (3) "Consumer report" or "credit report". - Any written, oral, or other communication of any information by a consumer reporting agency bearing on a consumer's creditworthiness, credit standing, credit capacity, character, general reputation, personal characteristics, or mode of living which is used or expected to be used or collected in whole or in part for the purpose of serving as a factor in establishing the consumer's eligibility for any of the following: a. Credit to be used primarily for personal, family, or household purposes. b. Employment purposes. c.
Official text (excerpt) · as of 2026-07-29 · Read the full section at ncleg.gov
Also relied on in: North Carolina Data Privacy Laws: Consumer Rights & Protections (2026), North Carolina Biometric Privacy Laws: Collection, Consent & Penalties (2026)
§ 75-65Protection from security breachesIn forcecited in 4 of our articles
(a) Any business that owns or licenses personal information of residents of North Carolina or any business that conducts business in North Carolina that owns or licenses personal information in any form (whether computerized, paper, or otherwise) shall provide notice to the affected person that there has been a security breach following discovery or notification of the breach. The disclosure notification shall be made without unreasonable delay, consistent with the legitimate needs of law enforcement, as provided in subsection (c) of this section, and consistent with any measures necessary to determine sufficient contact information, determine the scope of the breach and restore the reasonable integrity, security, and confidentiality of the data system. For the purposes of this section, personal information shall not include electronic identification numbers, email names or addresses, internet account numbers, internet identification names, parent's legal surname prior to marriage, or a password unless this information would permit access to a person's financial account or resources.
Official text (excerpt) · as of 2026-07-29 · Read the full section at ncleg.gov
Also relied on in: North Carolina Employee Monitoring Laws: Workplace Surveillance and Social Media (2026)
Search our full record of US law — 1.79 million sections, every state + federal →
Sources and References
- N.C. Gen. Stat. 75-65 - Protection from Security Breaches(ncleg.gov).gov
- N.C. Gen. Stat. 75-61 - Definitions(ncleg.gov).gov
- NC Chapter 75 Article 2A - Identity Theft Protection Act(ncleg.gov).gov
- NC Chapter 75 Article 1 - UDTP Act(ncleg.gov).gov
- NC DOJ - Security Breach Information(ncdoj.gov).gov
- NC DOJ - Report a Security Breach(ncdoj.gov).gov