What Is the California Customer Records Act?

The California Customer Records Act, codified at Civil Code sections 1798.80 through 1798.84, requires any business that handles California residents’ personal information to maintain reasonable security, dispose of records securely once they are no longer needed, and notify affected residents within 30 days of a data breach. Injured customers can sue directly. Unlike the California Consumer Privacy Act, the law applies regardless of a company’s size or revenue.

Which Businesses Have to Comply

The Act reaches any individual or business that conducts business in California and owns or licenses computerized data containing personal information about California residents.1California Legislative Information. California Civil Code CIV 1798.82 The security obligations in Section 1798.81.5 also reach businesses that merely maintain such information. The statute clarifies that “own” and “license” include information a business keeps in an internal customer account or uses in transactions with the person the information relates to, while “maintain” covers information a business holds but does not own or license.2California Legislative Information. California Civil Code CIV 1798.81.5

There is no minimum size threshold. A five-person shop that keeps customer names and credit card numbers is subject to the same core obligations as a multinational. The only real limit is geographic: the business must conduct business in California, and the data must belong to California residents.

What Counts as Personal Information

The Act uses two definitions, and the difference matters for what obligation you are analyzing.

For security requirements and breach notification, “personal information” means a person’s first name or first initial and last name combined with at least one of the following unencrypted data elements:2California Legislative Information. California Civil Code CIV 1798.81.5

  • Social Security number
  • Driver’s license or California ID card number
  • Financial account number combined with a security code, access code, or password that would allow access to the account
  • Medical information
  • Health insurance information

A username or email address combined with a password or a security question and answer that would permit access to an online account also qualifies.2California Legislative Information. California Civil Code CIV 1798.81.5 Information lawfully available from public government records is excluded.

The broader definition in Section 1798.80(e) covers any information that identifies, relates to, describes, or can be associated with a particular individual. That wider definition governs the disposal requirement in Section 1798.81, which is why disposal obligations sweep in a larger set of records than breach notification does.

Reasonable Security Obligations

Section 1798.81.5 sets the core duty: a business that owns, licenses, or maintains personal information about a California resident must implement and maintain reasonable security procedures and practices appropriate to the nature of the information.2California Legislative Information. California Civil Code CIV 1798.81.5 The statute does not prescribe specific technologies. What counts as reasonable depends on the sensitivity of the data, the size of the business, and the tools available.

The obligation extends beyond a company’s own walls. When a business discloses personal information to a third party under contract, the contract must require the third party to implement and maintain reasonable security measures of its own.2California Legislative Information. California Civil Code CIV 1798.81.5 You cannot outsource the data and shed the duty.

Secure Disposal of Records

Once customer records containing personal information are no longer needed, a business must take reasonable steps to dispose of them by shredding, erasing, or otherwise making the personal information unreadable or undecipherable.3California Legislative Information. California Civil Code 1798.81 The statute does not distinguish paper from electronic media, but the practical application is straightforward: shred paper, and wipe or physically destroy drives and backup media.

This is where quiet compliance failures accumulate. Old filing cabinets full of applications, retired hard drives in a closet, backup tapes from a decommissioned system — the disposal rule reaches all of them once retention is no longer needed.

Breach Notification Within 30 Days

A business that owns or licenses computerized data containing personal information must notify any California resident whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person.1California Legislative Information. California Civil Code CIV 1798.82 Notification must go out within 30 calendar days of discovering the breach or being notified of it.

Only two circumstances justify delay: a law enforcement determination that notice would impede a criminal investigation, or additional time reasonably necessary to determine the scope of the breach and restore the integrity of the data system. When either justification ends, notice must go out promptly.

A business that merely maintains personal information it does not own has a different duty. It must notify the owner or licensee immediately after discovering the breach, rather than notifying consumers directly.1California Legislative Information. California Civil Code CIV 1798.82

What the Notice Must Say

The statute prescribes a specific format. The notice must be written in plain language, titled “Notice of Data Breach,” set in at least 10-point type, and organized under five clearly and conspicuously displayed headings: “What Happened,” “What Information Was Involved,” “What We Are Doing,” “What You Can Do,” and “For More Information.”1California Legislative Information. California Civil Code CIV 1798.82

At a minimum, the notice must include the name and contact information of the reporting business, a list of the types of personal information involved, the date or estimated date range of the breach if known, whether notification was delayed because of a law enforcement investigation, and a general description of the incident.4California Legislative Information. California Code Civil Code 1798.82 The business may also describe steps taken to protect affected individuals.

Delivery and Substitute Notice

Notice can be delivered by written mail or by electronic notice consistent with the federal E-Sign Act. Substitute notice is allowed when direct notice would cost more than $250,000, when the affected group exceeds 500,000 people, or when the business lacks sufficient contact information.1California Legislative Information. California Civil Code CIV 1798.82 Substitute notice requires all three of the following: email to anyone whose address the business has, a conspicuous posting on the business’s website for at least 30 days, and notification to major statewide media outlets.

Filing With the Attorney General

If a single breach requires notice to more than 500 California residents, the business must also submit a sample copy of the notification to the California Attorney General’s office, with personally identifiable information removed.5State of California – Department of Justice – Office of the Attorney General. Data Security Breach Reporting That filing is separate from the notices sent to consumers.

The Encryption Safe Harbor and Its Limit

A breach of encrypted data does not trigger notification, but only when the encryption key or security credential was not also acquired or reasonably believed to have been acquired.1California Legislative Information. California Civil Code CIV 1798.82 If both the encrypted data and the key were compromised, the safe harbor is gone and the full notification duty applies.

The statute defines encrypted data as data rendered unusable, unreadable, or undecipherable to an unauthorized person through a security technology or methodology generally accepted in the information security field.1California Legislative Information. California Civil Code CIV 1798.82 Outdated methods that no longer meet industry standards would not qualify.

Penalties and the Private Right of Action

Any customer injured by a violation of the Act can sue the business directly under Section 1798.84.6California Legislative Information. California Civil Code CIV 1798.84 Affected consumers do not need to wait for a government agency to act.

The statute also fixes civil penalty amounts for violations of Section 1798.83, which governs disclosure of customer information shared with third parties for marketing. A customer can recover up to $3,000 per violation if the violation was willful, intentional, or reckless, and up to $500 per violation otherwise.6California Legislative Information. California Civil Code CIV 1798.84 Prevailing plaintiffs can also recover attorney’s fees and costs.

Courts can issue injunctions against any business that violates or proposes to violate the Act.6California Legislative Information. California Civil Code CIV 1798.84 Any contractual provision that waives a customer’s rights under the Act is void. Remedies under the Act are cumulative with other remedies available under law, so a plaintiff can pursue claims under this Act and other applicable statutes at the same time.

How It Differs From the CCPA

Both statutes sit in the same title of the Civil Code and both deal with personal information, but they do different work. The Customer Records Act governs data security, secure disposal, and breach notification, and it applies to any business that handles California residents’ personal data. The California Consumer Privacy Act governs how businesses collect, use, share, and sell personal information, and it applies only to for-profit entities that meet at least one of three thresholds: annual gross revenue over $26,625,000, buying or selling data on 100,000 or more consumers, or deriving 50 percent or more of annual revenue from selling or sharing personal information.7California Privacy Protection Agency. Does My Business Need To Comply With The CCPA

A small business below every CCPA threshold still has Customer Records Act duties if it holds customer records with personal information. Compliance with one law does not automatically satisfy the other.

Overlap With Federal Law

Federal compliance does not excuse California obligations. The Gramm-Leach-Bliley Act, which governs financial institutions, does not preempt state laws that provide greater consumer protection. Under 15 U.S.C. § 6807, a state law is not considered inconsistent with GLBA if it affords individuals greater protection than the federal standard. Because the Customer Records Act imposes breach notification deadlines, a specific notice format, and disposal requirements beyond what GLBA requires, financial institutions generally have to comply with both.

HIPAA works the same way. Its privacy rule is a floor, not a ceiling. A state law that provides greater privacy protections or greater individual rights than HIPAA is not preempted.8U.S. Department of Health & Human Services (HHS.gov). Preemption of State Law California’s 30-day notification deadline and prescribed notice format add obligations HIPAA does not impose, so covered entities handling California residents’ health data need to satisfy both frameworks.

Treat federal compliance as a baseline. Layer California’s specific requirements on top, with particular attention to the 30-day notification deadline, the mandatory notice format, and the record disposal rules.