EnglishEspañol
California flag

California

California Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 8 primary sources cited on this page. How we verify our legal content

California Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Frequently Asked Questions

When does California's 30-day breach notification deadline take effect?

SB 446 (Stats. 2025, Ch. 319) was signed by the Governor on October 3, 2025, and takes effect on January 1, 2026. Starting on that date, businesses must notify affected California residents within 30 calendar days of discovering or being notified of a data breach. The previous standard required notification in the most expedient time possible without unreasonable delay, but set no specific deadline.

Does every data breach in California require notification?

Not every breach triggers notification. The law applies only when unencrypted personal information (as defined in Cal. Civ. Code 1798.82(h)) is acquired, or reasonably believed to have been acquired, by an unauthorized person. If the breached data was encrypted using generally accepted methodology and the encryption key was not also compromised, notification is not required. However, California does not require any showing of harm. If unencrypted personal information was acquired, or is reasonably believed to have been acquired, by an unauthorized person, notification is mandatory regardless of whether actual harm occurred.

Can consumers sue businesses for data breaches in California?

Yes. Under the CCPA (Cal. Civ. Code 1798.150), consumers can bring a private lawsuit when a data breach results from a business's failure to implement and maintain reasonable security procedures. Statutory damages range from $107 to $799 per consumer per incident (CPI-adjusted as of January 1, 2025), or consumers can recover actual damages if greater. Before filing for statutory damages, consumers must give the business 30 days' written notice to cure the violation. This private right of action has led to significant class action litigation in California since the CCPA took effect in 2020.

What must a California breach notification letter include?

California prescribes both the format and content of breach notices. The notice must be titled Notice of Data Breach, written in plain language with at least 10-point type, and organized under five specific headings: What Happened, What Information Was Involved, What We Are Doing, What You Can Do, and For More Information. When SSNs or driver's license numbers are involved, the notice must include credit reporting agency contact information. If the notifying entity was the source of the breach and the breach exposed or may have exposed an SSN or a driver's license or California identification card number, any appropriate identity theft prevention and mitigation services it offers must be provided at no cost for at least 12 months.

When must a business notify the California Attorney General about a breach?

Businesses must notify the California Attorney General when a breach affects more than 500 California residents. Under SB 446, the AG must receive an electronic sample copy of the breach notification within 15 calendar days of notifying affected consumers. The sample must exclude personally identifiable information. The AG publishes all reported breaches in a searchable public database at oag.ca.gov.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the notification trigger to unauthorized acquisition rather than access, clarified that the free 12-month identity theft services offer applies only when a Social Security number or driver's license number was exposed, cited Civ. Code 1798.84(b) for the actual-damages remedy, removed an unsourced settlement statistic, and repointed a mislabeled California recording laws link.

We corrected an inaccurate claim that California's government-agency breach law (Civ. Code 1798.29) got the same new 30-day deadline as the business law, fixed the Attorney General notification threshold wording, updated the CCPA's private-right-of-action statutory damages figures to the current CPI-adjusted $107-$799 range, corrected an inaccurate description of the Blackbaud settlement, and added the 30-day minimum posting duration for substitute notice.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Cal. Civ. Code 1798.82 - Breach notification for businesses(leginfo.legislature.ca.gov).gov
  2. Cal. Civ. Code 1798.29 - Breach notification for government agencies(leginfo.legislature.ca.gov).gov
  3. SB 446 - Data breaches: customer notification (2025)(leginfo.legislature.ca.gov).gov
  4. SB 1386 - Original breach notification law (2002)(leginfo.legislature.ca.gov).gov
  5. Cal. Civ. Code 1798.150 - CCPA private right of action(leginfo.legislature.ca.gov).gov
  6. OAG Data Security Breach Reporting(oag.ca.gov).gov
  7. OAG Searchable Breach Database(oag.ca.gov).gov
  8. Blackbaud $6.75M Settlement(oag.ca.gov).gov
  9. Cal. Civ. Code 1798.84 - Civil remedies for violations of the customer records law(leginfo.legislature.ca.gov)
Share: