Skip to Main Content

Keeping you informed

What Does an Employer Owe Current and Former Employees After a Data Breach? North Carolina Court Case Could Provide Clarity.

    Client Alerts
  • September 23, 2026

Starting a new job routinely requires employees to disclose some of their most sensitive personal information, including Social Security numbers. But does an employer that requires that information assume a legal duty to protect it or enter into an implied contract to do so? And if the information is compromised in a data breach, can a delay in notifying affected current and former employees support claims against the employer?

Those were among the questions the North Carolina Business Court recently considered in Dougherty v. Bojangles Restaurants Inc. In ruling on Bojangles' motion to dismiss, the court allowed five of the seven claims brought by former Bojangles employees to proceed beyond the pleading stage. The ruling illustrates that, under the circumstances alleged, an employer’s possession and handling of employee data may support a negligence claim. It also suggests that an implied-contract claim may survive dismissal when an employer requires employees to provide sensitive personal data as a condition of employment and makes specific representations about protecting that data.

For North Carolina businesses, the decision is an important reminder to ensure that privacy-policy language aligns with actual security practices and that incident-response plans address notification as well as remediation.

Case Background

Bojangles, a Delaware-incorporated fast-food chain headquartered in North Carolina with roughly 800 locations across 17 states, suffered a data breach between February 19 and March 12, 2024. According to the complaint, the ransomware group Hunters International infiltrated Bojangles' systems, listed the company on its dark-web leak site, and claimed to have exfiltrated nearly 295 gigabytes of data. The plaintiffs alleged that the stolen data included the names, Social Security numbers, driver’s license and passport numbers, financial account information, and health insurance and medical information of more than 100 current and former employees. Bojangles notified affected individuals of the breach on November 19, 2024.

Nine former Bojangles employees filed suit against the company in Wake County Superior Court. They claimed the breach left them exposed to an ongoing risk of identity theft and fraud, forced them to spend time and money monitoring their credit and financial accounts, and, in at least one case, led to an actual fraudulent charge on a debit card. Several plaintiffs also alleged a jump in spam calls and scam attempts after the breach. Based on those harms, they asserted several legal claims, including negligence, breach of implied contract, invasion of privacy, and violations of North Carolina's unfair trade practices law. Bojangles moved to dismiss the case in its entirety. The North Carolina Business Court dismissed negligence per se as abandoned, and dismissed invasion of privacy on the merits. The other five claims survived.

The Court's Reasoning

Two Western District of North Carolina decisions guided parts of the opinion, both involving employer data-breach claims based on employees being required to provide personal information as a condition of employment. The 2018 case Curry v. Schletter Inc. informed the court’s negligence-duty analysis. Relying in part on Curry, the court concluded that the plaintiffs had adequately alleged a duty to safeguard their information and notify them of the breach within a reasonable time. The court found the roughly eight months between the breach and Bojangles' notice relevant to that analysis. Another case from 2024, Capiau v. Ascendum Mach. Inc., informed the court’s analysis of whether the plaintiffs adequately pleaded negligence damages. Applying North Carolina’s notice-pleading standard, the court found their combined allegations sufficient to survive dismissal. Those allegations included mitigation costs, diminished data value, emotional distress, increased scam activity, and, for one plaintiff, an alleged fraudulent charge.

Capiau also supported the implied contract claim. Bojangles' privacy policy promised "commercially reasonable efforts" to protect personal information, while also disclaiming any guarantee, and the court found that language sufficient at the pleading stage when paired with the allegation that employees had to provide the data as a condition of employment. The court quoted Capiau directly on that point: "the requirement that Plaintiff provide Defendant his PII vested in Defendant an implicit obligation to adequately safeguard [it]."

Capiau also supported the unjust enrichment and Unfair and Deceptive Trade Practices Act (UDTPA) claims, although the court analyzed those claims separately. For unjust enrichment, the plaintiffs alleged that they provided their data expecting Bojangles to use adequate cybersecurity measures, but that Bojangles instead avoided those obligations by using less costly and less effective measures. For the UDTPA claim, the court relied on Capiau for the narrower principle that an alleged failure to implement and maintain reasonable cybersecurity may qualify as "unfair" conduct, even without an allegation of fraud. Unlike the first four claims, however, the declaratory judgment claim did not rely on Curry or Capiau.

The court found an ongoing controversy in the allegation that Bojangles still possesses the plaintiffs' data and continues to maintain inadequate security, despite claiming to have reviewed its policies and enhanced certain controls after the breach. On a separate procedural point, the court declined to follow a federal court's earlier dismissal of a related version of this case for lack of Article III standing. The Business Court emphasized that it was applying North Carolina’s state-court pleading standard for damages, not the federal standing standard.

Taken together, the court’s claim-specific analyses show how allegations concerning an employer’s mandatory collection of employee data, stated security practices, response to a breach, and continued retention of compromised information can support multiple theories at the pleading stage. Whether the plaintiffs can prove those allegations and ultimately establish liability remains unresolved.

What This Means for North Carolina Businesses

The North Carolina Business Court’s decision offers four practical takeaways for North Carolina businesses that collect and retain employee personal information.

  • Review privacy-policy promises against actual security practices: The court concluded that Bojangles’ privacy policy, which promised "commercially reasonable efforts" to protect personal information, could support an implied-contract claim at the pleading stage when paired with the allegation that employees were required to provide their data. Businesses should confirm that their privacy-policy language accurately reflects the security measures they use in practice.
     
  • Build notification into incident-response planning: The court allowed the negligence claim to proceed based in part on the allegation that Bojangles did not notify affected individuals until roughly eight months after the breach ended. Although the court did not decide that the delay was unreasonable, the opinion underscores the importance of addressing notification promptly. Incident-response plans should assign responsibility for evaluating notice obligations, track applicable deadlines, document notification decisions, and account for both current and former employees.
     
  • Review the retention and protection of former employees' data: The court allowed the declaratory judgment claim to proceed based on allegations that Bojangles continued to possess the former employees’ data while maintaining inadequate security. Businesses should identify what employee data they retain after employment ends, why and for how long they retain it, and what safeguards apply throughout the retention period.
     
  • Evaluate state-court exposure separately from federal standing: An earlier federal action arising from the same breach was dismissed for lack of Article III standing, but the Business Court applied North Carolina’s state-court pleading standard and allowed five claims to proceed. Businesses should not assume that a federal standing dismissal eliminates potential state-court exposure arising from the same incident.

For more information, please contact us or your regular Parker Poe contact. Click here to subscribe to our latest alerts and insights.