California Data Security Law: Duties, Rights, and Penalties

California’s data security law requires for-profit businesses that meet certain size or data-processing thresholds to protect California residents’ personal information with reasonable security, honor a set of consumer privacy rights, and limit data collection to what is proportionate to a disclosed purpose. Violations can bring administrative fines of up to $7,500 each, and a data breach caused by inadequate security can trigger consumer lawsuits with statutory damages of $100 to $750 per person, per incident. The rules sit primarily in the California Consumer Privacy Act as amended by the California Privacy Rights Act, along with California Civil Code Section 1798.81.5’s separate reasonable-security mandate.1State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act

Which Businesses Are Covered

The CCPA applies to for-profit entities doing business in California that meet at least one of three thresholds:2California Legislative Information. California Civil Code 1798.140

  • Annual gross revenue above $25 million as of January 1 of the calendar year. The figure is adjusted for inflation and currently sits at $26,625,000.3California Privacy Protection Agency. Updated Monetary Thresholds in CCPA
  • Buying, selling, or sharing the personal information of 100,000 or more consumers or households annually, alone or in combination.
  • Deriving 50 percent or more of annual revenue from selling or sharing consumers’ personal information.

The law also reaches entities that share common branding with a qualifying business and receive consumer data from it, and joint ventures where each partner holds at least a 40 percent interest. Businesses below every threshold can voluntarily certify compliance with the California Privacy Protection Agency.2California Legislative Information. California Civil Code 1798.140

The Reasonable Security Duty

California Civil Code Section 1798.81.5 requires every business that owns, licenses, or maintains personal information about a California resident to implement and maintain reasonable security procedures appropriate to the nature of the information. The statute does not spell out a specific checklist. The standard is flexible and scales with the sensitivity of the data.4California Legislative Information. California Civil Code CIV 1798.81.5

When your business transfers personal information to a third party, contracts must require that third party to maintain the same reasonable security standards. This obligation drives breach liability under the CCPA’s private right of action: the question is not whether a breach happened, but whether the breach resulted from a security failure that fell below the reasonable bar.5California Legislative Information. California Civil Code 1798.150

Data Minimization and Retention

The CPRA added a proportionality standard that the original CCPA did not have. Collection, use, retention, and sharing of personal information must be reasonably necessary and proportionate to the purposes for which the data was collected or another compatible, disclosed purpose. Processing beyond what a consumer would reasonably expect is not allowed.6California Privacy Protection Agency. Applying Data Minimization to Consumer Requests

Retention criteria have to appear in your privacy policy, and specific retention periods or the criteria used to determine them must appear in the notice at collection. Collecting everything and figuring out what to do with it later no longer works. Data you hold without a documented need is both legal risk and enforcement exposure.

Consumer Rights You Must Honor

California residents can exercise a defined set of rights over their personal information, and covered businesses must respond to verified requests and explain those rights in their privacy notices.1State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act

  • Right to know the categories and specific pieces of personal information collected, the sources, the purposes, and any third parties who received it.
  • Right to delete personal information and to direct service providers to do the same. A business can refuse in limited circumstances, such as when the data must be kept for a legal obligation, but it must explain the denial.
  • Right to correct inaccurate personal information, effective January 1, 2023 under the CPRA. The business must use commercially reasonable efforts to make the fix.7California Privacy Protection Agency. California Consumer Privacy Act of 2018 – Section 1798.106
  • Right to opt out of the sale or sharing of personal information. The CPRA expanded this to cover “sharing” for cross-context behavioral advertising, not just sales for money.
  • Right to limit use of sensitive personal information to what is necessary to deliver the requested goods or services.
  • Right to non-discrimination when exercising any of these rights. No denial of service, no different pricing, no lower quality.

Businesses that sell or share personal information must place a clear, conspicuous “Do Not Sell or Share My Personal Information” link on the homepage. If sensitive personal information is used beyond what a consumer’s request requires, an additional “Limit the Use of My Sensitive Personal Information” link is required. Global Privacy Control signals sent by a consumer’s browser count as valid opt-out requests and must be honored.8State of California – Department of Justice – Office of the Attorney General. Global Privacy Control (GPC)

Sensitive Personal Information

The CPRA carved out a distinct category of sensitive personal information with heightened protection. Once a consumer sends a request to limit use, the business must stop using that data for any purpose beyond fulfilling the transaction unless the consumer later consents to more.9California Legislative Information. California Civil Code CIV 1798.121 The categories include:10California Privacy Protection Agency. What Is Personal Information?

  • Government identifiers such as Social Security numbers, passport numbers, driver’s licenses, and state IDs.
  • Account log-in credentials combined with access codes or passwords.
  • Precise geolocation.
  • Racial or ethnic origin, citizenship or immigration status, religious or philosophical beliefs, and union membership.
  • Contents of emails, texts, and other private messages not directed to the business.
  • Biometric, genetic, and neural data.
  • Health information, sex life, and sexual orientation.

Penalties

Administrative Fines

The California Privacy Protection Agency can impose administrative fines of up to $2,500 per violation. Intentional violations, and violations involving personal information of a consumer the business knows is under 16, carry fines of up to $7,500 per violation. Both amounts adjust periodically for inflation.11California Legislative Information. California Civil Code 1798.155

Fines are assessed per violation, not per enforcement action. A business that mishandles opt-out requests for thousands of consumers faces a calculation that multiplies by each affected person. The math escalates quickly.

Consumer Lawsuits for Data Breaches

Consumers can sue when their unencrypted, unredacted personal information is exposed in a breach caused by the business’s failure to maintain reasonable security. Statutory damages run from $100 to $750 per consumer per incident, or actual damages, whichever is greater. Courts weigh the seriousness of the misconduct, the number of violations, how long it persisted, and the business’s financial position.5California Legislative Information. California Civil Code 1798.150

Before suing for statutory damages, a consumer must give the business 30 days’ written notice identifying the provisions allegedly violated. If the business actually cures the violation within that window and provides a written statement that it will not recur, the consumer cannot pursue statutory damages for that breach. Implementing security measures after a breach does not count as curing the breach that already happened. If the business later violates its written assurance, the consumer can sue to enforce it and collect damages for every subsequent violation.5California Legislative Information. California Civil Code 1798.150

Enforcement and the End of the Guaranteed Cure Period

The CPRA created the California Privacy Protection Agency and gave it rulemaking authority, administrative enforcement power, and audit authority.12California Legislative Information. California Civil Code 1798.185 The Attorney General also retains authority to bring enforcement actions.

One change matters more than any other for day-to-day compliance: the CPRA eliminated the mandatory 30-day cure period that used to apply to enforcement actions. Under the original CCPA, the Attorney General had to give businesses 30 days to fix a violation before pursuing penalties. That safety net is gone. The CPPA now has discretion to offer a cure period and can consider lack of intent and voluntary remediation, but no window is guaranteed. If you discover a compliance gap, act on it before someone else does.

What Is Exempt

Two federal frameworks pull certain data out of the CCPA’s reach. Protected health information governed by HIPAA, and medical information governed by California’s Confidentiality of Medical Information Act, is exempt from the CCPA. Personal information collected under the federal Gramm-Leach-Bliley Act, its regulations, or California’s Financial Information Privacy Act is also exempt.13California Legislative Information. California Civil Code 1798.145

The GLBA exemption comes with an important limit. It does not extend to the private right of action for data breaches under Section 1798.150. A financial institution that suffers a breach caused by inadequate security can still face consumer lawsuits for statutory damages even though the rest of the CCPA does not apply to its GLBA-covered data.

Both exemptions apply at the data level, not the entity level. A hospital that collects HIPAA-governed patient records and also runs a gift shop with a loyalty program has to comply with the CCPA for the loyalty program data even though the patient data is exempt.

One more boundary worth naming: the CCPA’s temporary exemptions for employee data (covering employees, job applicants, contractors, and their emergency contacts) and business-to-business transaction data expired on December 31, 2022. Since January 1, 2023, both categories are fully subject to the CCPA. Employers must provide CCPA disclosures to their own workforce, honor deletion and correction requests from employees and applicants, and apply the same data minimization standards to HR records that they apply to customer records.1State of California – Department of Justice – Office of the Attorney General. California Consumer Privacy Act