Skip to content

Cyber Liability by state

North Carolina data breach notification law and cyber insurance

Direct answer

What is North Carolina's data breach notification law?

North Carolina's breach notification law (N.C. Gen. Stat. sect. 75-61 et seq.) requires businesses to notify affected residents without unreasonable delay after a breach of personal information. North Carolina requires businesses to notify affected residents and the Attorney General of breaches of unencrypted personal information without unreasonable delay.

Reviewed by Cornerstone Staff28 years of financial services state licensing experienceLast verified July 29, 2026

What the statute requires

North Carolina requires businesses to notify affected residents and the Attorney General of breaches of unencrypted personal information without unreasonable delay. Cyber liability insurance typically covers the forensics, notification, and legal review this statute requires.

Consumer notification deadline
Without unreasonable delay
Regulator notice
Notify the North Carolina Attorney General's Consumer Protection Division without unreasonable delay.
Credit bureau notice
Notify consumer reporting agencies when a breach requires notice to more than 1,000 residents.
Safe harbor
Notification is not required if the compromised data was encrypted and the confidential key was not acquired.
Enforcement
Violations are unfair or deceptive trade practices enforceable by the Attorney General, and affected residents may recover damages.

Statutes and sources

  • North Carolina Identity Theft Protection Act

    N.C. Gen. Stat. sect. 75-61 et seq.

Regulator: North Carolina Department of Justice . Last verified 2026-07-29 from the official source .

Get North Carolina coverage handled

Share a few details and an agent will respond within one business day.