California’s data breach notification law requires any business or state agency holding personal information on California residents to notify affected people after a breach, generally within 30 calendar days of discovery for businesses, using a notice written to a specific format the statute dictates. The rules live in Civil Code Section 1798.82 for businesses and Section 1798.29 for state agencies, and getting them wrong opens the door to lawsuits under the California Consumer Privacy Act at $107 to $799 per consumer, per incident.
Who Has to Notify
If your company collects personal information on California residents, you are covered by Section 1798.82 regardless of where your business is physically located.1California Legislative Information. California Code CIV 1798.82 – Personal Information Breach Notification State agencies fall under the parallel Section 1798.29.2California Legislative Information. California Code CIV 1798.29 – Notice of Data Breach
Service providers, cloud hosts, payroll processors, and other vendors that hold data belonging to another company have a different duty. They don’t notify individuals. They must notify the data owner or licensee immediately after discovering the breach, and the owner then handles consumer notification.1California Legislative Information. California Code CIV 1798.82 – Personal Information Breach Notification
What Triggers the Duty to Notify
Not every security incident triggers notification. The statute requires two things: an unauthorized acquisition of computerized data, and the involvement of specific categories of personal information. Unauthorized access without acquisition may not be enough. The data has to have been obtained, or reasonably believed to have been obtained, by someone who wasn’t supposed to have it.1California Legislative Information. California Code CIV 1798.82 – Personal Information Breach Notification
The information involved has to be a California resident’s first name (or first initial) and last name in combination with at least one of these sensitive elements:
- Social Security number
- Driver’s license or California ID number
- Financial account, credit card, or debit card number combined with a security code, access code, or password that would allow access to the account
- Medical or health insurance information
- Biometric data used for authentication, such as fingerprints or retina scans
- Tax identification numbers
- Unique identification numbers on a government document, such as a passport
A separate trigger applies to online credentials. A username or email address breached alongside a password, or a security question and answer that would grant account access, requires notification even without a name attached.2California Legislative Information. California Code CIV 1798.29 – Notice of Data Breach Publicly available information from government records doesn’t count.
The 30-Day Deadline
For businesses, Section 1798.82 sets a hard deadline: notification must go out within 30 calendar days of discovering the breach or being notified of it.1California Legislative Information. California Code CIV 1798.82 – Personal Information Breach Notification The clock can be extended for a legitimate law enforcement investigation or for the time needed to determine the breach’s scope and restore the system, but 30 days is the default. If you rely on a delay, be prepared to document why.
State agencies operate under a looser standard, “the most expedient time possible and without unreasonable delay,” with the same law enforcement carve-out.2California Legislative Information. California Code CIV 1798.29 – Notice of Data Breach There’s no bright line, but 30 days is a reasonable working benchmark.
When a breach affects more than 500 California residents, the organization also has to electronically submit a sample copy of the notification to the California Attorney General. For businesses, that AG submission is due within 15 calendar days of notifying affected consumers.1California Legislative Information. California Code CIV 1798.82 – Personal Information Breach Notification The sample should exclude personally identifiable information about individual consumers.3State of California – Department of Justice – Office of the Attorney General. Data Security Breach Reporting
What the Notice Has to Say
California dictates the format, not just the timing. Every breach notification must be written in plain language, titled “Notice of Data Breach,” and organized under five mandatory headings: “What Happened,” “What Information Was Involved,” “What We Are Doing,” “What You Can Do,” and “For More Information.”2California Legislative Information. California Code CIV 1798.29 – Notice of Data Breach A freeform letter drafted without checking the statute is a common compliance failure.
At a minimum, the notification has to include:
- Contact information for the reporting agency or business
- The types of personal information reasonably believed to have been compromised
- The date or estimated date range of the breach, if known
- The date of the notice itself
- Whether the notification was delayed by a law enforcement investigation
- A general description of the breach incident
Toll-free numbers for credit reporting agencies and advice on self-protective steps are technically optional, but skipping them tends to invite consumer complaints and lawsuits.2California Legislative Information. California Code CIV 1798.29 – Notice of Data Breach When a breach involves online credentials, the notice must direct affected people to change those credentials promptly.
When You Can Use Substitute Notice
Direct notification to every affected person isn’t always feasible. Substitute notice is allowed when any one of three conditions applies: the cost of individual notification would exceed $250,000, the affected class exceeds 500,000 people, or the business doesn’t have enough contact information to reach affected individuals.1California Legislative Information. California Code CIV 1798.82 – Personal Information Breach Notification
Substitute notice isn’t lighter. It requires all three of the following:
- Email notification to every affected person for whom the business has an email address
- Conspicuous website posting for at least 30 days, with a homepage link in larger or contrasting type
- Notification to major statewide media
Document the reason you couldn’t do individual notification. If the AG or a plaintiff challenges the choice, you’ll need to show one of the three qualifying conditions actually existed.
When Notification Isn’t Required
Encrypted Data
If the breached data was encrypted and the encryption key or security credential was not also compromised, notification generally isn’t required. Both statutes limit the duty to situations involving unencrypted personal information, or encrypted data taken along with the key that could render it readable.1California Legislative Information. California Code CIV 1798.82 – Personal Information Breach Notification Encryption is the single most reliable shield, but it disappears the moment the key is exposed, so key management logging matters as much as the encryption itself.
Good-Faith Employee Access
An employee or agent who accidentally accesses personal information while doing their job doesn’t trigger notification, as long as the information isn’t misused or further disclosed without authorization.1California Legislative Information. California Code CIV 1798.82 – Personal Information Breach Notification This is narrower than it sounds. A customer service rep who opens the wrong account is covered. An employee who emails a spreadsheet of Social Security numbers to a personal address is not, because the information has moved outside the scope of the job.
Penalties for Non-Compliance
Consumer Lawsuits Under the CCPA
The biggest financial exposure comes from Civil Code Section 1798.150. Any consumer whose unencrypted personal information is breached because a business failed to maintain reasonable security can sue for statutory damages of $100 to $750 per consumer per incident, or actual damages, whichever is greater.4California Legislative Information. California Code CIV 1798.150 – Personal Information Civil Action Those figures were inflation-adjusted in 2025 to $107 to $799 per consumer per incident, and the adjusted amounts remain in effect through 2026.5California Privacy Protection Agency. California Privacy Protection Agency Announces 2025 Increases for CCPA Fines and Penalties Even at the low end, a breach affecting a hundred thousand consumers is a ten-million-dollar problem.
Before suing for statutory damages, a consumer has to give the business 30 days’ written notice identifying the alleged violation. If the business actually cures the problem and provides a written statement saying so, the statutory damages claim is blocked. But the statute specifically says that implementing reasonable security after a breach doesn’t count as curing the breach itself.4California Legislative Information. California Code CIV 1798.150 – Personal Information Civil Action Most breach-related claims survive the notice period.
Attorney General Enforcement
The California Attorney General can bring enforcement actions against organizations that violate notification requirements, seeking injunctive relief and damages. Class action lawsuits from affected consumers frequently follow, particularly for breaches affecting hundreds of thousands of residents.
How Federal Rules Fit In
Complying with California’s notification law does not satisfy federal breach obligations, and complying with federal rules does not satisfy California. If you fall under one of the sector-specific regimes below, both clocks run at once.
Financial institutions covered by the Gramm-Leach-Bliley Act Safeguards Rule must notify the FTC of a security breach involving 500 or more consumers as soon as possible and no later than 30 days after discovery.6Federal Trade Commission. Safeguards Rule Notification Requirement Now in Effect Covered entities include mortgage brokers, tax preparation firms, collection agencies, payday lenders, and non-federally insured credit unions, not just banks.
Publicly traded companies must file a Form 8-K within four business days after determining they have experienced a material cybersecurity incident, describing the nature, scope, and timing of the incident and its material impact.7U.S. Securities and Exchange Commission. Form 8-K
Healthcare providers and their business associates covered by HIPAA’s Breach Notification Rule have 60 calendar days from discovery to notify affected individuals of a breach of unsecured protected health information. HIPAA doesn’t exempt them from California’s 30-day deadline, which arrives first.
Getting Ready Before You Need To
The 30-day clock starts on discovery, and forensic investigation alone often consumes most of it. Companies that haven’t pre-identified their outside counsel, forensic vendor, and notification platform routinely miss the deadline. Pre-approved notification letter templates, drafted with the five required headings baked in, save days of drafting and review in the middle of an incident.
Document everything from the moment a potential breach is identified. California allows delay for investigation, but the burden is on the organization to show any delay was reasonable. Contemporaneous records of when the breach was discovered, what steps you took, and why you delayed notification (if you did) are what defend the timeline later. If law enforcement asks you to hold off, get that request in writing.
And encrypt personal information at rest and in transit. Encryption with sound key management is the one measure that can take a breach outside the notification statute entirely, and it’s cheaper than any of the alternatives once a breach occurs.