North Carolina Data Breach Notification Law: Triggers and Penalties

The North Carolina data breach notification law, codified at N.C. Gen. Stat. 75-65, requires any business that owns or licenses the personal information of North Carolina residents to notify affected individuals after unauthorized access to that data, and to notify the state Attorney General and the nationwide credit bureaus when more than 1,000 people are affected at one time. A violation is treated as an unfair trade practice, which exposes the business to treble damages under Chapter 75.

1North Carolina General Assembly. NC Code 75-65 – Protection From Security Breaches

Who Has to Notify

The statute reaches two overlapping groups. It covers any business that owns or licenses personal information belonging to North Carolina residents, wherever the business is located, and it covers any business operating in North Carolina that holds personal information in any format, digital or paper.

1North Carolina General Assembly. NC Code 75-65 – Protection From Security Breaches

A separate duty applies to businesses that only maintain data belonging to someone else. A service provider or processor that discovers a breach of another company’s data must notify the owner or licensee immediately so the owner can handle notifications to individuals. Third-party vendors can’t wait for the data owner to figure things out on their own.

1North Carolina General Assembly. NC Code 75-65 – Protection From Security Breaches

What Data Triggers the Law

The obligation only fires when the incident involves “personal information” as defined in N.C. Gen. Stat. 75-61. That definition requires a person’s first name (or first initial) and last name combined with at least one identifying data element listed in the state’s identity theft statute, N.C. Gen. Stat. 14-113.20.

2North Carolina General Assembly. NC Code 75-61 – Definitions

Qualifying data elements include:

  • Social Security numbers, driver’s license or state ID numbers, and passport numbers
  • Checking, savings, credit card, and debit card account numbers
  • PINs, digital signatures, passwords, and electronic identification numbers
  • Fingerprints and other biometric identifiers
  • Any other number or information that can be used to access a person’s financial resources
3North Carolina General Assembly. NC Code 14-113.20 – Definitions

The breach statute specifically excludes email addresses, internet account names, and a parent’s pre-marriage surname from “personal information,” unless those items would allow access to a financial account.

1North Carolina General Assembly. NC Code 75-65 – Protection From Security Breaches

What Counts as a Security Breach

Not every unauthorized login qualifies. A “security breach” under N.C. Gen. Stat. 75-61 is unauthorized access to and acquisition of unencrypted, unredacted records containing personal information where illegal use has occurred, is reasonably likely, or where the incident creates a material risk of harm to a consumer. All three elements have to be present: access, acquisition, and a realistic threat of misuse.

2North Carolina General Assembly. NC Code 75-61 – Definitions

An employee or agent who accesses personal information in good faith for a legitimate business purpose does not trigger notification, as long as the data isn’t misused or disclosed further without authorization. Documentation matters here. If you can’t show the access was authorized and the data stayed in proper channels, the safe harbor won’t help.

2North Carolina General Assembly. NC Code 75-61 – Definitions

Encryption is the other big filter. If personal information was encrypted at the time of the breach and the encryption key was not compromised, the incident does not meet the statutory definition and no notification is required. If the encrypted data and the key or decryption process were both accessed, the statute treats it the same as unencrypted data. Key management is therefore as important as the encryption itself; storing the key next to the data eliminates the protection.

2North Carolina General Assembly. NC Code 75-61 – Definitions

When Notification Must Happen

North Carolina does not set a fixed deadline in days. The statute requires notification “without unreasonable delay,” allowing time to determine contact information, assess the scope of the breach, and restore the security of the data systems.

1North Carolina General Assembly. NC Code 75-65 – Protection From Security Breaches

That flexibility cuts both ways. There’s no bright-line safe harbor, so a company that spends months on an investigation it understood in weeks is exposed to enforcement. Move as quickly as the investigation allows, and document the reasons for any delay.

Law enforcement can request that notification be postponed if it would interfere with a criminal investigation or jeopardize national security. The request must be in writing, or the business must document it in writing at the time, including the officer’s name and agency. Once the hold lifts, notification proceeds without unreasonable delay.

1North Carolina General Assembly. NC Code 75-65 – Protection From Security Breaches

What the Notice Must Say

Subsection (d) of the statute requires the notice to be clear and conspicuous, and to include all of the following:

  • A general description of the incident
  • The types of personal information involved
  • The steps the business has taken to prevent further unauthorized access
  • A telephone number the person can call for more information, if one exists
  • Advice telling the person to review account statements and monitor free credit reports
  • Toll-free numbers and addresses for the major consumer reporting agencies
  • Toll-free numbers, addresses, and websites for the Federal Trade Commission and the North Carolina Attorney General’s Office, with a note that these agencies can help with identity theft prevention
4North Carolina General Assembly. NC Code 75-65 – Protection From Security Breaches

Leaving out any of these pieces creates both an enforcement risk and a practical problem, because it deprives affected people of the tools they need to protect themselves.

Notifying the Attorney General and the Credit Bureaus

When a breach affects more than 1,000 people at one time, the business must also notify the Consumer Protection Division of the Attorney General’s Office and all nationwide consumer reporting agencies. This additional notice must go out without unreasonable delay and must describe the timing, distribution method, and content of the notices sent to individuals.

1North Carolina General Assembly. NC Code 75-65 – Protection From Security Breaches

Subsection (e1) separately requires businesses to report breaches to the Attorney General’s Consumer Protection Division with details on the nature of the breach, the number of consumers affected, the steps taken to investigate, the steps taken to prevent recurrence, and information about the timing and content of the notice.

5UNC School of Government. A Guide to Local Government Data Breach Notification Requirements The North Carolina Department of Justice runs an online portal for these reports.6North Carolina DOJ. Security Breach Information

How the Notice Can Be Delivered

Notification can go out by written letter, telephone, or electronic notice. Electronic notice is only permitted if the business already has a relationship with the individual that includes electronic communications and if it complies with the federal electronic records law at 15 U.S.C. § 7001.

Substitute notice is available when the cost of direct notification would exceed $250,000, more than 500,000 people are affected, or the business lacks sufficient contact information. Substitute notice requires all three of the following:

  • Email notice to anyone whose email address the business has on file
  • Conspicuous posting on the business’s website
  • Notification to major statewide media outlets
5UNC School of Government. A Guide to Local Government Data Breach Notification Requirements

Substitute notice isn’t a cheaper alternative you can choose. One of the qualifying conditions has to actually exist before switching to this method.

Who Is Exempt

Financial institutions and credit unions that already comply with specific federal breach response guidance are deemed in compliance with N.C. Gen. Stat. 75-65. The exemption covers institutions subject to the Federal Interagency Guidance Response Programs for Unauthorized Access to Consumer Information (issued in 2005 by the Federal Reserve, FDIC, OCC, and OTS), and credit unions subject to the equivalent National Credit Union Administration guidance.

1North Carolina General Assembly. NC Code 75-65 – Protection From Security Breaches

The exemption is narrower than it looks. It does not broadly cover every entity subject to the Gramm-Leach-Bliley Act; it requires compliance with the specific interagency programs named in the statute. And there is no general exemption for HIPAA-covered healthcare providers. Healthcare entities in North Carolina should plan to comply with both the HIPAA breach notification rule and the state statute.

What Non-Compliance Costs

A violation of the breach notification law is automatically a violation of N.C. Gen. Stat. 75-1.1, which prohibits unfair or deceptive trade practices.1North Carolina General Assembly. NC Code 75-65 – Protection From Security Breaches Under N.C. Gen. Stat. 75-16, anyone injured by a Chapter 75 violation can sue and recover treble damages, meaning the court triples whatever actual damages the jury finds.

7North Carolina General Assembly. NC Code 75-16 – Civil Action by Person Injured; Treble Damages

One limit: a private individual cannot bring a lawsuit under this section unless they were actually injured as a result of the violation. A notification failure that causes no downstream harm won’t support a private treble damages claim. But a failure that leads to identity theft or financial fraud almost certainly will, and tripled damages add up quickly across a class of affected consumers.

1North Carolina General Assembly. NC Code 75-65 – Protection From Security Breaches

The Attorney General’s Office can also pursue enforcement directly through the Consumer Protection Division.

Federal Reporting That Still Applies

Complying with the state law does not eliminate federal reporting obligations. The FBI’s Internet Crime Complaint Center (IC3) accepts breach reports from businesses and specifically instructs filers to include the words “data breach” in the incident description.

8Internet Crime Complaint Center (IC3). Data Breach

Beginning in 2026, the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) requires covered entities in critical infrastructure sectors to report significant cyber incidents to the Cybersecurity and Infrastructure Security Agency within 72 hours, and ransomware payments within 24 hours. The clock starts when the organization first reasonably suspects a reportable incident, not when the forensic investigation concludes.

9Elisity. CIRCIA Healthcare Compliance Guide: New Regulations and Critical Controls for 2026

Businesses in healthcare, energy, financial services, or other critical infrastructure sectors should map out the overlapping state and federal reporting obligations before a breach happens. Sorting three different timelines during an active incident is how deadlines get missed.