June 29, 2026|Franchise Frontlines

Dougherty v. Bojangles Restaurants: North Carolina Business Court Sustains Most Employee Data-Breach Claims at the Pleading Stage

June 29, 2026  |  Superior Court of North Carolina, Wake County, Business Court  |  Not Reported in S.E. Rptr. (2026 WL 1864638; 2026 NCBC 60)

Executive Summary

In an unreported order, Special Superior Court Judge for Complex Business Cases Julianna T. Earp of the Superior Court of North Carolina, Wake County, Business Court, granted in part and denied in part a Rule 12(b)(6) motion to dismiss filed by Bojangles Restaurants, Inc., in a putative class action brought by former employees whose personally identifiable information and protected health information (PII/PHI) were exposed in a 2024 data breach. Applying North Carolina law, the court considered whether the plaintiffs’ seven causes of action—negligence, negligence per se, breach of implied contract, invasion of privacy, unjust enrichment, violation of the North Carolina Unfair and Deceptive Trade Practices Act (UDTPA), and declaratory judgment—stated claims on which relief could be granted. The plaintiffs argued that Bojangles, having required them to provide sensitive information as a condition of employment, owed and breached duties to safeguard it, while Bojangles argued that the complaint failed to plead a recognized duty, causation, actual damages, or the elements of the remaining theories. The court dismissed the negligence per se claim with prejudice—a claim the plaintiffs had abandoned, and which in any event could not rest on the Federal Trade Commission Act or HIPAA because, in the court’s view, “neither the FTC[A] … nor the HIPAA regulations are public safety laws”—and dismissed the invasion of privacy claim with prejudice. It denied dismissal of the negligence, breach of implied contract, unjust enrichment, UDTPA, and declaratory judgment claims, concluding that each was adequately pleaded under North Carolina’s liberal notice-pleading standard.

Relevant Background

Bojangles Restaurants, Inc. is, as the court described it, a “fast-food chain” incorporated in Delaware with a principal place of business in North Carolina and approximately 800 locations across 17 states. The plaintiffs are nine former Bojangles employees—citizens of North Carolina, South Carolina, Texas, and Tennessee—who, as a condition of employment, were required to provide their PII/PHI for payroll and other employment-related purposes. Bojangles’ privacy policy stated that it had “security policies and practices in place designed to protect” personal information and would make “commercially reasonable efforts for secure handling of th[e] information,” while, as the court noted, also stating that Bojangles “cannot guarantee [its] security measures.”

Between February 19 and March 12, 2024, the security of Bojangles’ computer systems was breached. The plaintiffs alleged that the breach was the work of Hunters International, a “Russian Ransomware-as-a-Service” entity that listed Bojangles on its dark-web “leak site” and claimed to have exfiltrated 294.8 GB of data, including names, Social Security numbers, driver’s license numbers, financial account information, and health and medical information. According to the complaint, Bojangles did not begin notifying affected individuals until November 19, 2024, and its notice acknowledged that recipients faced a “present, continuing, and significant risk” of identity theft. One plaintiff alleged an $80 fraudulent debit-card charge and several alleged a subsequent increase in spam and scam calls; the remaining plaintiffs alleged an increased risk of future harm, mitigation costs, and emotional injury.

The plaintiffs filed this action in Wake County Superior Court on December 23, 2025, and it was designated to the Business Court. As the court noted, an earlier version of the dispute had been dismissed for lack of standing by the United States District Court for the Western District of North Carolina; the Business Court took note of that federal reasoning but declined to hold the plaintiffs to the federal standing standard when assessing the sufficiency of their state-court pleading. Both sides agreed that North Carolina law governed, and the court applied that law in resolving Bojangles’ motion following a June 3, 2026 hearing.

Decision

The court applied North Carolina’s notice-pleading standard, under which a Rule 12(b)(6) motion “tests the legal sufficiency of the complaint” and dismissal is proper only where the complaint reveals no supporting law, an absence of facts sufficient to state a good claim, or a fact that necessarily defeats the claim. Two claims did not survive. The plaintiffs had abandoned their negligence per se theory, rendering the motion uncontested as to that claim, and the court separately reaffirmed its own precedent that “neither the FTC[A] … nor the HIPAA regulations are public safety laws” capable of supporting negligence per se; it dismissed the claim with prejudice. The court also dismissed the invasion of privacy claim with prejudice, holding that North Carolina does not recognize a claim for publication of private facts and that the plaintiffs failed to plead intrusion into seclusion—an intentional tort—because they alleged only that Bojangles permitted a breach of information they had “willingly provided,” not that Bojangles itself intentionally intruded into their private affairs.

The court reached the opposite result on the negligence claim. Restating that a negligence claim requires “a legal duty; a breach thereof; and injury proximately caused by the breach,” the court held that the plaintiffs adequately alleged each element on this record. Relying on North Carolina data-breach decisions recognizing that “one in possession of another’s PII/PHI has a duty of care to safeguard and protect that information,” the court concluded that Bojangles’ collection and retention of employee information supported a duty to exercise reasonable care to protect it and to provide reasonably timely breach notice. It found causation adequately pleaded because foreseeability and proximate cause are ordinarily questions for the jury, and it found the alleged damages—diminished value of PII/PHI, mitigation time and cost, a fraudulent charge, and “pain and suffering”-type emotional harm—sufficient at the pleading stage, distinguishing such harm from the “severe emotional distress” required for an emotional-distress tort.

The court allowed the remaining claims to proceed. On breach of implied contract, it followed federal decisions applying North Carolina law holding that requiring an employee to provide PII as a condition of employment “vested in [the employer] an implicit obligation to adequately safeguard” it, and it treated Bojangles’ privacy-policy promise of “commercially reasonable efforts” as reinforcing that implied obligation, leaving meeting-of-the-minds and damages for the trier of fact. On unjust enrichment, the court distinguished its prior Weddle decision because these plaintiffs alleged they expected Bojangles to “use adequate cybersecurity measures to protect the PII/PHI” in exchange for it, and that Bojangles instead used “cheaper, ineffective security measures.” On the UDTPA claim, after the plaintiffs conceded at the hearing that they pursued only unfair—not deceptive—conduct, the court held that a “failure to implement and maintain reasonable data security measures may be unfair conduct” sufficient to survive dismissal. Finally, it held that the plaintiffs’ allegation of continuing inadequate security stated an actual controversy supporting declaratory relief.

Looking Forward

This order is a useful, if cautionary, data point for any employer that collects and retains workforce PII/PHI, and its reasoning may inform how courts approach similar claims against branded, multi-unit systems—including franchisors and their affiliates—that centralize human-resources, payroll, benefits, or onboarding data. Because the court applied North Carolina notice pleading and the ruling is unreported, it is persuasive at most and controls nothing outside its own record; any transfer to a franchise system would be by analogy, not command. Still, the through-line is worth noting for defense planning: the court treated the employment relationship itself, coupled with the employer’s collection of sensitive data, as enough to generate a common-law duty to safeguard that data and an implied contractual obligation to do the same, and it allowed negligence, implied-contract, unjust-enrichment, UDTPA, and declaratory-judgment theories to proceed in parallel from a single breach.

The mixed outcome also marks where, on this record, the pleading lines fell. The employer secured dismissal with prejudice of the negligence per se and invasion-of-privacy theories—the former because the court does not treat the FTC Act or HIPAA as public-safety statutes, the latter because a breach of information an employee “willingly provided” is not an intentional intrusion into seclusion. Those are meaningful defense arguments against the more aggressive labels. But defeating them did not end the case: the court let the core negligence, contract, quasi-contract, and unfair-practices claims go forward, a reminder that dismissing outlier theories may not, by itself, dispose of a well-pleaded employee data-breach action. Defense counsel weighing early dismissal in analogous matters may wish to calibrate expectations accordingly and consider which issues are better joined at summary judgment on a developed record.

For franchisors, employers, and branded systems, the practical takeaway is preparation and documentation. The court treated the reasonableness of a company’s data-security posture as the pivotal, fact-bound question—embedded in the negligence duty, the implied-contract obligation, and the UDTPA “unfair conduct” inquiry alike—which suggests that, in analogous cases, the adequacy of safeguards could become the central contested issue rather than a threshold one. Systems that concentrate employee data across many units may wish to maintain, periodically reassess, and document reasonable security measures; limit collection and retention to what is genuinely needed; and be prepared to demonstrate the safeguards in place before any incident and the timeliness of any breach notification. Building that record now is a defensible way to reduce the risk that a breach matures into a surviving class action, though outcomes will ultimately turn on each jurisdiction’s law and the particular facts of each system.


Thomas O’Connell is a Partner at Buchalter LLP and Chair of the firm’s Franchise Practice Group. For questions about this article or media inquiries, you can contact Tom at toconnell@buchalter.com.

This article is based solely on the opinion of the Court in this matter. The author has not conducted any independent investigation into the facts. For the avoidance of doubt, each statement related to the law and facts in this article is drawn from the Court’s opinion in this case. It was drafted with the assistance of an artificial intelligence system. AI systems can make mistakes, including in describing legal authority. Readers should independently confirm any legal authority before relying on it.

This communication is not intended to create, and does not create, an attorney-client relationship or any other legal relationship. No statement herein constitutes legal advice, nor should it be relied upon or interpreted as such. This communication is for general informational purposes only and is not a substitute for legal counsel. Readers should not act or refrain from acting based on any information provided without seeking appropriate legal advice specific to their situation. For more information, visit www.buchalter.com.

Practices