This website uses cookies

Read our Privacy policy and Terms of use for more information.

A North Carolina Business Court judge has allowed most claims in an employee data-breach case against Bojangles to move forward. The order does not decide that Bojangles is liable, but it gives every North Carolina employer a practical reason to review how it stores employee data, what it promises about security, and how it would handle breach notification.

The useful takeaway is not that every breach becomes a lawsuit. It is that employee information deserves the same operational attention as customer and patient data. Payroll records, direct-deposit details, benefits files, background checks, and old personnel exports can remain sensitive for years. When those records are spread across internal systems and outside vendors, a business needs to know who is responsible before something goes wrong.

What happened

The case is Dougherty v. Bojangles Restaurants, Inc. Former employees allege that personal and health information was exposed in a breach that occurred from February 19 through March 12, 2024. The June 29, 2026 order says the court was evaluating whether the complaint stated legally sufficient claims, not deciding whether the allegations were true.

The judge denied Bojangles' request to dismiss claims for negligence, breach of implied contract, unjust enrichment, violation of North Carolina's unfair-trade law, and declaratory judgment. Claims for negligence per se and invasion of privacy were dismissed with prejudice. The surviving claims can proceed, but they remain allegations.

According to the complaint summarized in the order, workers were required to provide personal information for payroll and other employment purposes. The plaintiffs also pointed to the company's privacy language and alleged that breach notices did not begin until November 19, 2024. Those details mattered to the claims about reasonable care, an implied agreement to safeguard the information, and timely notice. They are still allegations that must be tested with evidence.

What the court did not decide

This was a motion-to-dismiss ruling. At this stage, the court asks whether the complaint contains legally sufficient allegations. It does not decide which side has the better evidence, whether every claimed injury was caused by the breach, or what security measures were actually reasonable under the circumstances. The order lets several claims move forward. It is not a verdict, settlement, or final ruling that Bojangles violated the law.

Why this matters in North Carolina

Citadel-HQ analysis: employee data is not only an HR recordkeeping issue. If you require workers to provide Social Security numbers, bank details, benefits information, or health information, your security practices, retention decisions, written promises, and response timeline may all be examined after a breach. The order specifically found the employees had adequately alleged a duty to protect their data and to notify them within a reasonable timeframe.

Citadel-HQ analysis: the hardest part is often finding every copy of the data. Payroll providers hold bank information. Benefits administrators hold health and dependent records. Managers may download spreadsheets during open enrollment. Old applicant systems may retain identification or background-check information. Without a current map, the business cannot quickly determine what was exposed, who needs to respond, or whether a vendor completed deletion.

North Carolina law separately requires covered businesses to notify affected people of a qualifying breach without unreasonable delay, subject to the law's investigation, restoration, and law-enforcement provisions. Whether a particular incident triggers that duty is a legal question that depends on the facts.

Where a small employer can start

Start with the records that would create the most harm if exposed: Social Security numbers, direct-deposit and tax information, identification, benefits and health records, background checks, and payroll or HR credentials. For each category, record where it lives, which vendor receives it, who can access it, how long it is retained, and how deletion is confirmed. Unknown is an acceptable first answer. It shows where the work begins.

What to do this week

  • List every system and vendor that holds employee or former-employee data, including payroll, benefits, scheduling, background checks, and health-plan records.

  • Set a written retention rule. If a record no longer has a business or legal purpose, dispose of it securely instead of keeping it indefinitely.

  • Check who can reach sensitive HR data. Remove stale accounts, limit access by job role, and require multi-factor authentication for administrators and vendors.

  • Read your privacy notices, handbook language, vendor contracts, and cyber-insurance conditions. Make sure your written promises match your actual controls.

  • Run a one-hour breach drill with IT, HR, leadership, legal counsel, and your insurance contact. Decide who preserves evidence, contacts investigators, evaluates notice duties, and communicates with workers.

  • Prepare a notification checklist before an incident. Record discovery time, scope decisions, law-enforcement guidance, affected data types, and the reason for each timing decision.

Keep the exercise concrete. Pick one realistic scenario, such as a payroll account takeover or a vendor reporting unauthorized access. Walk through the first business day. Who disables access without destroying evidence? Who calls the cyber insurer? Who obtains logs and a written timeline? Who records the notification decisions? For every unanswered question, assign an owner and a deadline.

Citadel-HQ operator note

Do not wait for an incident to discover that no one owns the employee-data inventory or notification clock. A short, documented review now is more useful than another generic security policy. The goal is not a perfect binder. It is a current map, named decision-makers, and a response process the business can use under pressure. This briefing is practical information, not legal advice. Use North Carolina privacy counsel for decisions about a real incident.

Direct sources

Keep Reading