Compliance · April 22, 2026

Data Breach Response: California Notification Rules

A data breach is a bad week for any business; a botched notification turns it into a bad year. California's breach notification statute — Civ. Code § 1798.82, the first of its kind in the nation — tells businesses exactly who must be notified, how quickly, and what the notice must contain, and it pairs with the CCPA's private right of action to give plaintiffs a ready-made lawsuit when security was lacking. Here is the framework, and the response sequence that can help keep a security incident from becoming a legal one.

When the notification duty triggers

The statute applies to any person or business doing business in California that owns or licenses computerized data containing personal information. The duty triggers when unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person. Two definitions do the work:

  • "Personal information" means a name combined with a Social Security number; driver's license, state ID, tax identification, passport, military identification, or other qualifying government-issued identification number; financial account or card number with access credentials; medical or health insurance information; biometric data; or genetic data — and, separately, a username or email address in combination with a password or security question that would permit access to an online account.
  • The encryption safe harbor: notification is not required if the data was encrypted — unless the encryption key or credentials were also compromised. This is the single strongest legal argument for encrypting data at rest.

Mere access is not automatically acquisition, and a genuine risk analysis is appropriate — but the phrase "reasonably believed to have been acquired" means doubt tends to resolve toward notice.

Who gets notified, and how fast

Notice must go to every affected California resident "in the most expedient time possible and without unreasonable delay" and, beginning January 1, 2026, no later than 30 calendar days after discovery or notification of the breach. Delay may be justified by the legitimate needs of law enforcement or measures necessary to determine scope and restore the reasonable integrity of the system, but not by drafting convenience or reputational hesitation. Two additional recipients matter:

  • The Attorney General must receive a sample copy of the notice within 15 calendar days after affected consumers are notified if more than 500 California residents are notified from a single breach. These submissions are published on the AG's public website — assume the press and plaintiffs' bar will read yours.
  • Data owners: if you maintain data you do not own (as a vendor or processor), you must notify the owner or licensee immediately upon discovery, and the owner then notifies individuals. Your customer contracts should already say who drafts, who pays, and who decides.

What the notice must say

Section 1798.82 prescribes the format and content: plain language, a title of "Notice of Data Breach," and organized headings — "What Happened," "What Information Was Involved," "What We Are Doing," "What You Can Do," and "For More Information." It must include the date or date range of the breach, the date of discovery, whether notification was delayed for law enforcement, and, where Social Security numbers or specified government-issued identification numbers were exposed, contact information for the credit reporting agencies. If the breach exposed Social Security numbers or specified government-issued identification numbers, the business that was the source of the breach must offer appropriate identity-theft prevention and mitigation services at no cost for at least 12 months. For breaches of online credentials, the statute directs a different notice channel — you cannot simply email the compromised account. Substitute notice (website posting plus statewide media plus email, when available) is permitted when the cost of notice would exceed $250,000, the affected class exceeds 500,000 people, or the business lacks sufficient contact information.

The liability layer: CCPA statutory damages

California is one of the few states where a breach carries built-in statutory damages. Under Civ. Code § 1798.150, a consumer whose nonencrypted, nonredacted personal information is subject to unauthorized access and exfiltration, theft, or disclosure as a result of a business's failure to maintain reasonable security procedures may sue for $100 to $750 per consumer per incident — no proof of actual loss required. Multiply by a customer database and the exposure is obvious. The practical takeaway: "reasonable security" is a legal standard you should be able to document before an incident — access controls, encryption, patching, vendor diligence, and an incident response plan all become Exhibit A in your defense.

The first 72 hours, in order

  1. Contain the incident and preserve forensic evidence — do not wipe and rebuild before imaging.
  2. Engage counsel early so the investigation is structured properly, and bring in forensics through counsel.
  3. Notify your cyber insurer promptly; late notice can jeopardize coverage.
  4. Determine scope: whose data, which fields, encrypted or not.
  5. Check every applicable regime — other states' statutes, HIPAA, contractual notice clauses to enterprise customers — since few incidents involve only Californians.
  6. Draft the statutory notice, notify affected residents within the applicable deadline, submit the AG sample within 15 calendar days after notifying residents if more than 500 residents are affected, and stand up the mitigation-services offer where required.

Building this sequence into a written incident response plan is a core piece of regulatory compliance, and your vendor agreements should allocate breach duties in advance through well-drafted business contracts.

Talk to a California business attorney

The middle of an incident is the worst time to learn the notification statute. Whether you are planning ahead or responding right now, prompt legal guidance protects both your customers and your company. Schedule a free consultation or call (949) 418-2113.

This article is attorney advertising and provides general information only. It is not legal advice and does not create an attorney–client relationship. Facts matter; consult a lawyer about your specific situation.

Free Consultation

Ready to move? Start with a free consultation.

Tell us what you're facing — a contract, a dispute, a debt, a decision. We will map the legal path in plain language, and you will leave the first call knowing your options.

Call Now Free Consultation