North Carolina employers should know where employee data lives, who can reach it, how long it is kept, and who starts the response clock after a suspected breach. A June 29, 2026 Business Court order did not decide liability, but it allowed several claims based on an alleged employee-data breach to move into the next stage of litigation.
What did the North Carolina court decide?
In Dougherty v. Bojangles Restaurants, Inc., former employees allege that personal identifying information and protected health information was exposed during a breach from February 19 through March 12, 2024. At the motion-to-dismiss stage, the court accepts well-pleaded allegations for purposes of testing whether the claims are legally sufficient. It does not decide disputed facts or liability.
The court allowed claims for negligence, breach of implied contract, unjust enrichment, violation of North Carolina's unfair-trade law, and declaratory judgment to proceed. It dismissed claims for negligence per se and invasion of privacy with prejudice. The order also said the employees had adequately alleged that Bojangles owed a duty to protect their data and to provide notice within a reasonable timeframe.
The ruling is not a verdict or a finding that Bojangles violated the law. It means the surviving claims are legally sufficient to move forward and can be tested with evidence.
What does the ruling mean for North Carolina employers?
Citadel-HQ analysis: workforce data often spreads across more systems than customer data. Payroll providers, benefits administrators, applicant trackers, scheduling tools, background-check services, email, shared drives, and old exports can each hold information that creates lasting risk. Former-worker records matter too. A business can close an account without removing every copy held elsewhere.
Written statements also matter. The court considered allegations about the company's privacy policy and promises to use commercially reasonable security efforts. A policy should describe what the organization actually does. Aspirational language that is not matched by operations can become part of a later dispute.
When must a North Carolina employer give data-breach notice?
North Carolina General Statute 75-65 requires covered businesses to notify affected people of a qualifying breach without unreasonable delay. The statute allows time needed for specified investigation and restoration steps and recognizes documented law-enforcement delays. It also requires a business that holds North Carolina residents' data for someone else to notify the owner or licensee immediately after discovery, subject to the law-enforcement provision.
That does not create one universal deadline for every event. The facts, the data involved, the relationship between the parties, other state laws, and sector rules can change the analysis. A response plan should route notice decisions to qualified counsel while technical responders preserve evidence and determine scope.
What should North Carolina employers do now?
- Inventory payroll, benefits, health-plan, applicant, background-check, scheduling, and former-worker records.
- Name a business owner for each system and record the vendor, contract, access method, retention period, and deletion process.
- Remove unused accounts and restrict sensitive records to people who need them for current work.
- Require multi-factor authentication for administrators, HR staff, and vendors with sensitive access.
- Compare privacy notices, handbooks, and contracts with the controls that are actually in place.
- Test backups and evidence-preservation procedures separately. A usable backup does not replace an investigation record.
- Write the first-day call list for IT, HR, leadership, privacy counsel, cyber insurance, and incident-response support.
- Practice documenting discovery time, containment actions, data-scope decisions, and the reason for notification timing.
This article provides general operational information and is not legal advice. If you suspect a breach, preserve evidence and involve qualified incident-response and privacy counsel promptly.
Direct sources
Where the facts came from.
- Dougherty v. Bojangles Restaurants, Inc., 2026 NCBC 60North Carolina Judicial Branch
- 2026 NCBC 60, Order and Opinion on Defendant's Motion to DismissNorth Carolina Judicial Branch
- Russian hackers obtained massive data files on Bojangles workers, new filing showsThe Charlotte Observer
- North Carolina General Statute 75-65: Protection from security breachesNorth Carolina General Assembly
- Security Breach InformationNorth Carolina Department of Justice
- Data Breach Response: A Guide for BusinessFederal Trade Commission
Questions answered
What readers are asking.
What did the Bojangles data breach ruling decide?
The June 29, 2026 order allowed claims for negligence, breach of implied contract, unjust enrichment, unfair trade practices, and declaratory judgment to proceed. It did not decide that the allegations are true or that Bojangles is liable.
When must a North Carolina employer give data-breach notice?
North Carolina General Statute 75-65 requires covered businesses to notify affected people of a qualifying breach without unreasonable delay. Investigation, restoration, law-enforcement needs, other laws, and the facts of the incident can affect timing.
What employee data should North Carolina employers protect?
Start with Social Security numbers, bank and payroll details, driver's license information, tax records, benefits and health information, background checks, and credentials for payroll or HR systems.
Should a business delete former-employee data?
A business should keep former-employee records only as long as a legitimate business or legal requirement calls for them, then dispose of them securely. Qualified counsel should set the retention rule because different records can have different requirements.
What should an employer do after discovering a possible data breach?
Preserve evidence, contain access without wiping affected systems, notify the incident-response team and insurer, determine what information was involved, document decisions, and obtain qualified legal advice about notification duties.
