California Data Breach Notification Requirements

If your business or agency suffers a data breach involving a California resident’s personal information, California’s data breach notification requirements give you 30 calendar days from discovery to tell the affected people what happened. That hard deadline takes effect January 1, 2026, under SB 446, replacing the older standard that only required notice “in the most expedient time possible.”1California Legislative Information. California Civil Code 1798.82 – Customer Records The same law dictates what the notice must say, how you can deliver it, when the Attorney General has to be brought in, and what enforcement looks like when a business gets it wrong.

Who Has to Comply

Two parallel statutes cover almost everyone who holds personal data on Californians. Civil Code Section 1798.82 reaches any person or business that conducts business in California and owns or licenses computerized personal information.1California Legislative Information. California Civil Code 1798.82 – Customer Records Section 1798.29 puts nearly identical rules on state and local government agencies.2California Legislative Information. California Civil Code 1798.29

The obligations follow the data, not the ownership relationship. If you maintain personal information for another organization, you must notify that data owner immediately after discovering a breach so the owner can handle consumer notification.

Encryption creates one meaningful carve-out. If the compromised data was encrypted and the encryption key was not also taken, notification is not required. If both the encrypted data and the key were acquired, you must notify as though the data were unencrypted from the start.1California Legislative Information. California Civil Code 1798.82 – Customer Records

What Counts as Personal Information

Not every data leak triggers the statute. “Personal information” means a person’s name (or first initial and last name) combined with at least one unencrypted data element in these categories:3California Legislative Information. California Civil Code 1798.81.5

  • Government-issued identifiers: Social Security number, driver’s license or California ID number, tax ID number, passport number, military ID number, or another unique government identifier used to verify identity.
  • Financial account data: an account, credit card, or debit card number paired with any security code, access code, or password that would unlock the account.
  • Medical and health information: medical records, health insurance information, or genetic data.
  • Biometric data: fingerprints, retina scans, iris images, or other biometric identifiers used to authenticate identity. An ordinary photograph does not count unless it is stored for facial recognition.

A separate category stands on its own and does not require a name: a username or email address paired with a password or with a security question and answer that would grant access to an online account.3California Legislative Information. California Civil Code 1798.81.5 Information already publicly available through government records is excluded.

The 30-Day Deadline and Its Two Exceptions

Starting January 1, 2026, notification to affected individuals must go out within 30 calendar days of discovering or being notified of the breach.1California Legislative Information. California Civil Code 1798.82 – Customer Records The Governor signed SB 446 on October 3, 2025, adding this fixed number in place of the open-ended prior standard.4California Legislative Information. SB 446 – Data Breaches: Customer Notification – Bill Status

Only two things justify going past 30 days. Law enforcement can ask you to hold off if notification would interfere with a criminal investigation; once the agency releases the hold, you must notify promptly. And you may take additional time genuinely required to determine what was compromised and restore the integrity of the affected system.1California Legislative Information. California Civil Code 1798.82 – Customer Records That second exception is not a blank check. The clock starts at discovery, and regulators will look closely at how any extra days were actually spent.

What the Notice Must Say

The notice must be written in plain language, titled “Notice of Data Breach,” and set out under five specific headings:1California Legislative Information. California Civil Code 1798.82 – Customer Records

  • What Happened: a general description of the breach and the date or estimated date range.
  • What Information Was Involved: the specific types of personal information compromised, named plainly (for example, “name and Social Security number”), not vague references like “your data.”
  • What We Are Doing: the steps taken to address the breach and prevent future incidents.
  • What You Can Do: recommended protective measures for the recipient.
  • For More Information: the entity’s name and contact information for follow-up questions.

The text must be at least 10-point type, and the headings must be displayed conspicuously.

Credit Bureau Contacts

When the breach exposed a Social Security number, driver’s license number, or California identification card number, the notice must include toll-free phone numbers and mailing addresses for the major credit reporting agencies.1California Legislative Information. California Civil Code 1798.82 – Customer Records That gives affected people the information they need to place a fraud alert.

Free Identity Theft Services

When the entity responsible for the breach is also the source of the compromised data and the breach involved sensitive identifiers like Social Security numbers, the entity must offer free identity theft prevention and mitigation services for at least 12 months. The notice must explain how to sign up.1California Legislative Information. California Civil Code 1798.82 – Customer Records

Notifying the Attorney General

When a single breach affects more than 500 California residents, the entity must also send a sample copy of the breach notice to the California Attorney General through the AG’s online portal. The sample copy must not include any personally identifiable information about affected individuals.5Office of the Attorney General. Data Security Breach Reporting

Under SB 446’s changes taking effect in 2026, this AG submission has its own separate deadline: 15 calendar days after the entity notifies affected consumers.6California Legislative Information. SB 446 – Data Breaches: Customer Notification The submission includes a detailed electronic form on the facts of the breach, the security measures in place at the time, and the entity’s response. The AG’s office publishes these submissions.

How to Deliver the Notice

The default methods are written notice by first-class mail to the individual’s last known address, or electronic notice if the entity already has an established method of electronic communication with that person or the person has expressly consented to electronic delivery.1California Legislative Information. California Civil Code 1798.82 – Customer Records Having someone’s email address is not the same as having their consent to receive legal notices there; the federal E-SIGN Act requires an affirmative agreement after clear disclosures about paper rights, withdrawal, and the technology needed to read the notice.7National Credit Union Administration. Electronic Signatures in Global and National Commerce Act (E-Sign Act)

Substitute Notice

Substitute notice is available only in three situations: individual notice would cost more than $250,000, the affected group exceeds 500,000 people, or the entity does not have enough contact information. When substitute notice applies, all three of the following are required:8California Legislative Information. California Civil Code 1798.82 – Customer Records

  • Email to every affected person for whom the entity has an email address.
  • A conspicuous posting of the notice on the entity’s homepage or first significant page for at least 30 days, using larger, contrasting, or visually distinct text.
  • Notification to major statewide media outlets.

Substitute notice is a fallback. The entity must actually meet one of the three qualifying conditions; choosing it because mailing letters is inconvenient will not hold up under review. Government agencies using substitute notice have one additional step: they must also notify the Office of Information Security within the Department of Technology.2California Legislative Information. California Civil Code 1798.29

Penalties and Lawsuits

Enforcement comes from two directions.

Attorney General Action

The Attorney General can seek injunctive relief against any business that violates the notification rules. Affected individuals can also file civil actions for damages under Civil Code Section 1798.84.9California Legislative Information. California Civil Code 1798.84 Past AG settlements have reached six and seven figures, particularly where a business concealed a breach or delayed notification.10Office of the Attorney General. Privacy Enforcement Actions

Private Right of Action Under the CCPA

Separately, the California Consumer Privacy Act lets consumers sue directly when a breach results from a business’s failure to maintain reasonable security practices. Statutory damages run from $100 to $750 per consumer per incident, or actual damages, whichever is greater.11California Legislative Information. California Civil Code 1798.150 Modest per-person, those numbers become substantial in a class action of thousands or millions. Courts weigh the seriousness of the misconduct, the number of violations, and the business’s financial condition to set the amount within that range.

Before filing for statutory damages, a consumer must send the business written notice identifying the specific violations and give it 30 days to cure. If the business cures the problem and provides a written statement that no further violations will occur, statutory damages are off the table for that incident. The statute is explicit that implementing better security after the breach does not count as curing the breach itself.11California Legislative Information. California Civil Code 1798.150 Consumers seeking only actual out-of-pocket damages can skip the 30-day notice.