California
California Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 8 primary sources cited on this page. How we verify our legal content

Under Cal. Civ. Code 1798.82, California requires businesses to notify affected residents within 30 calendar days of discovering a data breach. When a breach affects more than 500 residents, businesses must also notify the California Attorney General within 15 calendar days of sending consumer notices.
California's data breach notification law is the original. When a hacker stole personal information from 265,000 state employees in 2002, California responded by passing SB 1386, the nation's first law requiring businesses to tell consumers when their data had been compromised. Every other state eventually followed California's lead.
More than two decades later, California continues to set the pace. SB 446, signed by the Governor on October 3, 2025, and effective January 1, 2026, added the one thing the original law lacked: a hard deadline. Businesses now have exactly 30 calendar days to notify affected Californians after discovering a breach. For a deeper look at all of California's privacy protections, see our California Data Privacy Laws overview.
Who Must Comply
California's breach notification law applies to two groups under separate but parallel statutes.
Cal. Civ. Code 1798.82 covers any person or business that conducts business in California and owns or licenses computerized data containing personal information. You do not need to be based in California. If you hold personal data belonging to California residents, the law applies to you.
Cal. Civ. Code 1798.29 imposes similar requirements on state and local government agencies.
SB 446 amended only Civ. Code 1798.82, the statute covering businesses. Civ. Code 1798.29 was not amended by SB 446 and remains governed by the pre-existing standard: government agencies must notify affected residents "in the most expedient time possible and without unreasonable delay," with no specific numeric deadline, and the statute sets no specific deadline for submitting the sample copy to the Attorney General when more than 500 residents are affected.
What Triggers a Notification
Notification is required when unencrypted personal information has been "acquired, or reasonably believed to have been acquired, by an unauthorized person." Section 1798.82(g) defines the breach itself as the "unauthorized acquisition of computerized data" that compromises the security, confidentiality, or integrity of personal information, so mere unauthorized access or viewing is not automatically enough. What California does not require is any showing of harm. Once the acquisition standard is met, notification is mandatory whether or not any consumer can show an actual injury.
This sets California apart from roughly 30 other states that require a risk-of-harm analysis before notification is triggered.
What Counts as Personal Information
California defines personal information broadly under Section 1798.82(h). The law covers two categories.
Category 1: Name Plus a Data Element
A person's first name or first initial and last name combined with any of the following:
- Social Security number
- Driver's license or California identification card number
- Financial account number, credit card number, or debit card number (combined with any required security code, access code, or password)
- Medical information
- Health insurance information
- Unique biometric data generated from measurements of human body characteristics (fingerprints, retina images, iris scans) used to authenticate identity
- Information collected through an automated license plate recognition system
- Tax identification number
- Passport number
- Military identification number
- Unique identification number issued on a government document used to verify identity
- Genetic data
Category 2: Online Account Credentials
A username or email address combined with a password or security question and answer that would permit access to an online account.
The statute specifically excludes publicly available information lawfully obtained from government records.
The 30-Day Notification Deadline
Before SB 446, California required notification "in the most expedient time possible and without unreasonable delay." That vague standard allowed some companies to wait months, or even over a year, before telling affected consumers.
Effective January 1, 2026, the law now requires notification within 30 calendar days of discovering or being notified of the breach.

Two Exceptions to the 30-Day Rule
The deadline can be extended in two situations:
- Law enforcement delay. If a law enforcement agency determines that notification would impede a criminal investigation, the business may delay notification until the agency says otherwise.
- Scope and integrity assessment. A business may take additional time "as necessary to determine the scope of the breach and restore the reasonable integrity of the data system."
These exceptions existed under the old law and carry over to the new timeline. However, businesses should expect the Attorney General to scrutinize claims of extended investigation timelines more closely now that a hard deadline exists.
Attorney General Notification
When a breach affects more than 500 California residents, the business must electronically submit a sample copy of the breach notification to the California Attorney General. This sample must exclude personally identifiable information.
SB 446 added a specific deadline: 15 calendar days after notifying affected consumers. Previously, no specific timeline existed for AG notification.
The AG maintains a searchable database of breach notifications that is publicly accessible. This public reporting creates additional accountability and reputational consequences for organizations that experience breaches.
Required Content of Breach Notices
California prescribes the format and content of breach notification letters more specifically than most states. Notices must be written in plain language using at least 10-point type and titled "Notice of Data Breach." The notice must present information under these required headings:
- What Happened (description of the breach incident and dates)
- What Information Was Involved (types of personal information compromised)
- What We Are Doing (steps the organization is taking in response)
- What You Can Do (actions the consumer can take to protect themselves)
- For More Information (contact details for the notifying entity)
Additional content requirements include:
- Toll-free phone numbers and addresses of major credit reporting agencies (when SSNs or driver's license numbers are involved)
- If the entity was the source of the breach and the breach exposed or may have exposed a Social Security number or a driver's license or California identification card number, an offer of appropriate identity theft prevention and mitigation services, if any are offered, at no cost for at least 12 months, along with the information needed to take up the offer (Civ. Code 1798.82(d)(2)(G))
- The name and contact information of the entity providing the notice
Methods of Notification
Organizations can notify affected individuals through:
- Written notice sent to the last known mailing address
- Electronic notice consistent with the federal E-SIGN Act
Substitute Notice
If the cost of direct notification exceeds $250,000, the affected class is larger than 500,000 people, or the organization does not have sufficient contact information, substitute notice is permitted. Substitute notice requires all three of the following:
- Email notice to affected individuals for whom the organization has an address
- Conspicuous posting on the organization's website for a minimum of 30 days
- Notification to major statewide media
Encryption Safe Harbor
California provides a safe harbor for encrypted data. Notification is not required if the breached personal information was encrypted using "generally accepted" encryption methodology, unless the encryption key or security credential was also acquired and could render the data readable or usable.
This safe harbor gives organizations a concrete incentive to encrypt personal information at rest and in transit. If encryption is properly implemented and keys are managed separately, a breach of the encrypted data alone does not trigger notification.
Enforcement and Penalties
California does not include a specific penalty provision in the breach notification statute itself. Instead, enforcement comes from multiple directions.
Attorney General Enforcement
The California Attorney General can bring civil actions for violations of the breach notification law under the state's unfair business practices statutes. The AG has been active in this area. Notable enforcement actions include a $6.75 million settlement with Blackbaud in 2024. Blackbaud, a South Carolina-based data-management software provider for nonprofit organizations, suffered a 2020 breach that exposed consumers' names, Social Security numbers, bank account information, and medical information. The settlement addressed Blackbaud's delayed and inaccurate breach notifications after it initially told customers no personal data had been accessed.

CCPA Private Right of Action (Cal. Civ. Code 1798.150)
The most significant enforcement mechanism comes from the California Consumer Privacy Act. Section 1798.150 gives individual consumers the right to sue when their unencrypted or unredacted personal information is exposed in a breach resulting from a business's "failure to implement and maintain reasonable security procedures and practices."
Consumers can recover:
- Statutory damages of $107 to $799 per consumer per incident
- Actual damages if they exceed the statutory amount
- Injunctive or declaratory relief
- Any other relief the court deems proper
The statute's original $100 to $750 range is adjusted for inflation every odd-numbered year by the California Privacy Protection Agency under Civ. Code 1798.199.95(d). The $107 to $799 figures above reflect the adjustment effective January 1, 2025.
Before filing suit for statutory damages, consumers must provide the business with 30 days' written notice. If the business cures the violation within that window and provides written confirmation, statutory damages are barred. However, actual damages claims do not require prior notice.
These statutory damages add up fast in class action litigation. A breach affecting 100,000 consumers could expose a business to $10.7 million to $79.9 million in statutory damages alone. Since the CCPA took effect in 2020, data breach class actions in California have increased substantially.
General Breach Notification Remedies
Separately from the CCPA, Cal. Civ. Code 1798.84(b) provides that any customer injured by a violation of California's customer records law, which includes the breach notification requirements in Section 1798.82, may bring a civil action to recover damages.
How California Compares to Other States
California's breach notification law stands out in several ways:
| Feature | California | Many Other States |
|---|---|---|
| First enacted | 2002 (first in nation) | 2003 to 2018 |
| Notification deadline | 30 days (as of Jan. 1, 2026) | Ranges from 30 to 90 days; some have no deadline |
| Harm threshold | None required | About 30 states require risk-of-harm showing |
| Private right of action | Yes, via CCPA 1798.150 | Most states lack a private right of action for breaches |
| Statutory damages | $107 to $799 per consumer | Few states provide statutory damages |
| Notice content format | Prescribed headings and format | Many states have minimal content rules |
| Identity theft services | Free for at least 12 months when the breach exposed an SSN or driver's license number | Not universally required |
| AG reporting deadline | 15 days after consumer notice | Varies widely |
The combination of no harm threshold, a private right of action with statutory damages, and prescribed notice content makes California's law one of the most protective in the country. For businesses, this also means California breaches carry higher legal and financial exposure than breaches under most other state laws.
Practical Steps for Compliance
Organizations handling California residents' personal information should take several steps to prepare for the 30-day deadline under SB 446:
Build an incident response plan. Thirty days moves fast when you factor in forensic investigation, legal review, and notice drafting. Organizations should have a breach response plan ready before a breach happens.
Encrypt personal information. The encryption safe harbor provides a meaningful defense. Implement generally accepted encryption for personal data at rest and in transit, and store encryption keys separately.

Maintain reasonable security. The CCPA private right of action applies only when a breach results from a failure to maintain reasonable security. Documenting your security practices can be the difference between facing and avoiding a class action.
Prepare template notices. California's prescribed notice format means you can draft template notices in advance. Having templates ready saves valuable time during the 30-day window.
Know your AG reporting obligations. If your organization serves more than 500 California residents, build the 15-day AG reporting deadline into your response timeline from day one.
For related protections covering biometric data in California, see our guide to California biometric privacy laws.
Sources and References
This article references California statutes and official government publications. For the full text of the breach notification law, visit Cal. Civ. Code 1798.82 and Cal. Civ. Code 1798.29 on the California Legislative Information website. For SB 446 bill text and history, see SB-446 Data breaches: customer notification. For Attorney General breach reporting requirements, visit the OAG Data Security Breach Reporting page. For the CCPA private right of action, see Cal. Civ. Code 1798.150.
This article provides general legal information about California data breach notification requirements. It is not legal advice. Consult a qualified attorney for guidance on your specific situation. Laws and regulations change frequently. Verify current requirements through official California government sources.
More California Laws
Frequently Asked Questions
When does California's 30-day breach notification deadline take effect?
SB 446 (Stats. 2025, Ch. 319) was signed by the Governor on October 3, 2025, and takes effect on January 1, 2026. Starting on that date, businesses must notify affected California residents within 30 calendar days of discovering or being notified of a data breach. The previous standard required notification in the most expedient time possible without unreasonable delay, but set no specific deadline.
Does every data breach in California require notification?
Not every breach triggers notification. The law applies only when unencrypted personal information (as defined in Cal. Civ. Code 1798.82(h)) is acquired, or reasonably believed to have been acquired, by an unauthorized person. If the breached data was encrypted using generally accepted methodology and the encryption key was not also compromised, notification is not required. However, California does not require any showing of harm. If unencrypted personal information was acquired, or is reasonably believed to have been acquired, by an unauthorized person, notification is mandatory regardless of whether actual harm occurred.
Can consumers sue businesses for data breaches in California?
Yes. Under the CCPA (Cal. Civ. Code 1798.150), consumers can bring a private lawsuit when a data breach results from a business's failure to implement and maintain reasonable security procedures. Statutory damages range from $107 to $799 per consumer per incident (CPI-adjusted as of January 1, 2025), or consumers can recover actual damages if greater. Before filing for statutory damages, consumers must give the business 30 days' written notice to cure the violation. This private right of action has led to significant class action litigation in California since the CCPA took effect in 2020.
What must a California breach notification letter include?
California prescribes both the format and content of breach notices. The notice must be titled Notice of Data Breach, written in plain language with at least 10-point type, and organized under five specific headings: What Happened, What Information Was Involved, What We Are Doing, What You Can Do, and For More Information. When SSNs or driver's license numbers are involved, the notice must include credit reporting agency contact information. If the notifying entity was the source of the breach and the breach exposed or may have exposed an SSN or a driver's license or California identification card number, any appropriate identity theft prevention and mitigation services it offers must be provided at no cost for at least 12 months.
When must a business notify the California Attorney General about a breach?
Businesses must notify the California Attorney General when a breach affects more than 500 California residents. Under SB 446, the AG must receive an electronic sample copy of the breach notification within 15 calendar days of notifying affected consumers. The sample must exclude personally identifiable information. The AG publishes all reported breaches in a searchable public database at oag.ca.gov.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the notification trigger to unauthorized acquisition rather than access, clarified that the free 12-month identity theft services offer applies only when a Social Security number or driver's license number was exposed, cited Civ. Code 1798.84(b) for the actual-damages remedy, removed an unsourced settlement statistic, and repointed a mislabeled California recording laws link.
We corrected an inaccurate claim that California's government-agency breach law (Civ. Code 1798.29) got the same new 30-day deadline as the business law, fixed the Attorney General notification threshold wording, updated the CCPA's private-right-of-action statutory damages figures to the current CPI-adjusted $107-$799 range, corrected an inaccurate description of the Blackbaud settlement, and added the 30-day minimum posting duration for substitute notice.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
California Civil Code
§ 1798.82In forcecited in 3 of our articles
(a) (1) An individual or business that conducts business in California, and that owns or licenses computerized data that includes personal information, shall disclose a breach of the security of the system following discovery or notification of the breach in the security of the data to a resident of California whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person, or whose encrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person and the encryption key or security credential was, or is reasonably believed to have been, acquired by an unauthorized person, and the person or business that owns or licenses the encrypted information has a reasonable belief that the encryption key or security credential could render that personal information readable or usable. (2) (A) Subject to subparagraph (B), the disclosure required by this subdivision shall be made within 30 calendar days of discovery or notification of the data breach.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at leginfo.legislature.ca.gov
Cited in 39 court opinionsMost recently applied by a court: 2026
In the courts (editorial summary, independently checked):The breach notice duty is enforced through unfair competition suits. In People v. Experian Data Corp. (2024), a case of first impression, the Court of Appeal held the San Diego City Attorney may invoke the discovery rule to delay accrual of a claim whose predicate violation was Experian failing to give notice under Section 1798.82(a).
Leading cases:
- People v. Experian Data Corp. (California Court of Appeal 2024)✓The San Diego City Attorney sued Experian under the unfair competition law for failing to promptly notify consumers of a data breach as Section 1798.82 requires; the court held the discovery rule can delay accrual of that non-fraud enforcement action and reversed.
- Bank of America Corp. v. Superior Court (California Court of Appeal 2011, 198 Cal. App. 4th 862)“…ssue notice of default) (6th cause of action); violation of Civil Code section 1798.82 (requiring disclosure to consumer of da…”
- Eisenhower Medical Center v. Superior Court (California Court of Appeal 2014, 226 Cal. App. 4th 430)“…of action for violation of the Customer Records Act (CRA) (Civ.Code, § 1798.82), which requires notification to consum…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: California Data Privacy Laws: CCPA, CPRA & Consumer Rights (2026), California Biometric Privacy Laws: Collection, Consent & Penalties (2026)
§ 1798.29In forcecited in 2 of our articles
(a) Any agency that owns or licenses computerized data that includes personal information shall disclose any breach of the security of the system following discovery or notification of the breach in the security of the data to any resident of California (1) whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person, or, (2) whose encrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person and the encryption key or security credential was, or is reasonably believed to have been, acquired by an unauthorized person and the agency that owns or licenses the encrypted information has a reasonable belief that the encryption key or security credential could render that personal information readable or usable. The disclosure shall be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement, as provided in subdivision (c), or any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at leginfo.legislature.ca.gov
Cited in 4 court opinionsMost recently applied by a court: 2024
Leading cases:
- Beeman v. Anthem Prescription Management, LLC (California Supreme Court 2013, 58 Cal. 4th 329)“…usiness maintaining computerized personal information data (Civ. Code, §§ 1798.29, 1798.82), or the nature and investment…”
- Sifuentes v. X Corp. (District Court, N.D. California 2024)“…4 (9) Violations of California Civil Code sections 1798.29 and 1798.82, (id. at ¶¶ 90-97), 5…”
- Damner v. Facebook Incorporated (District Court, N.D. California 2020)“…enant of good faith and 8 fair dealing; (7) violation of Cal. Civ. Code § 1798.29; and (8) fraudulent and negligent 9…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 1798.150In forcecited in 5 of our articles
Personal Information Security Breaches (a) (1) Any consumer whose nonencrypted and nonredacted personal information, as defined in subparagraph (A) of paragraph (1) of subdivision (d) of Section 1798.81.5, or whose email address in combination with a password or security question and answer that would permit access to the account is subject to an unauthorized access and exfiltration, theft, or disclosure as a result of the business’ violation of the duty to implement and maintain reasonable security procedures and practices appropriate to the nature of the information to protect the personal information may institute a civil action for any of the following: (A) To recover damages in an amount not less than one hundred dollars ($100) and not greater than seven hundred and fifty ($750) per consumer per incident or actual damages, whichever is greater. The amounts in this subdivision shall be adjusted pursuant to subdivision (d) of Section 1798.199.95. (B) Injunctive or declaratory relief. (C) Any other relief the court deems proper.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at leginfo.legislature.ca.gov
Cited in 41 court opinionsMost recently applied by a court: 2025
Leading cases:
- Jarman v. HCR ManorCare, Inc. (California Supreme Court 2020, 267 Cal. Rptr. 3d 696)“…of the harm, as it has done in other contexts. (See, e.g., Civ. Code, § 1798.150, subd. (a)(2).) These deficiencie…”
- Untitled California Attorney General Opinion (California Attorney General Reports 2022)“…ubd. (c). 48 Civ. Code, § 1798.155, subd. (b). 49 Civ. Code, § 1798.150. 50 Initiative Measure (Prop. 24)…”
- Hajny v. Volkswagen Group of America CA1/1 (California Court of Appeal 2024)“…750 without having to prove causation and actual damages. (Civ. Code, § 1798.150, subd. (a)(1)(A).) No other state provi…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: What Is CCPA? California Consumer Privacy Act Explained (2026), GDPR vs CCPA: Key Differences Explained (2026), How to File a Data Privacy Complaint (2026)
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Cal. Civ. Code 1798.82 - Breach notification for businesses(leginfo.legislature.ca.gov).gov
- Cal. Civ. Code 1798.29 - Breach notification for government agencies(leginfo.legislature.ca.gov).gov
- SB 446 - Data breaches: customer notification (2025)(leginfo.legislature.ca.gov).gov
- SB 1386 - Original breach notification law (2002)(leginfo.legislature.ca.gov).gov
- Cal. Civ. Code 1798.150 - CCPA private right of action(leginfo.legislature.ca.gov).gov
- OAG Data Security Breach Reporting(oag.ca.gov).gov
- OAG Searchable Breach Database(oag.ca.gov).gov
- Blackbaud $6.75M Settlement(oag.ca.gov).gov
- Cal. Civ. Code 1798.84 - Civil remedies for violations of the customer records law(leginfo.legislature.ca.gov)