California Data Breach Notification Law
Cal. Civ. Code § 1798.82 (notification, as amended by SB 446, eff. Jan 1, 2026); Cal. Civ. Code § 1798.150 (CCPA private right of action)
California has the nation's strongest consumer data breach laws. As of January 1, 2026, SB 446 requires notification within a hard 30-day deadline from discovery (Cal. Civ. Code § 1798.82). The CCPA (Cal. Civ. Code § 1798.150) provides a private right of action with statutory damages of $100–$750 per consumer per incident when a company's failure to implement reasonable security exposes unencrypted personal information — no proof of actual harm required.
What This Law Covers
California's breach notification law requires businesses and government agencies that maintain personal information about California residents to notify affected individuals when that information is subject to unauthorized access or acquisition. "Personal information" typically includes Social Security numbers, driver's license numbers, financial account numbers, and in many states has been expanded to cover medical data, biometric data, online credentials, and tax IDs.
What the Company Must Tell You
A compliant breach notification to California residents must include:
- ✓A description of the breach — what happened and when
- ✓The types of personal information that were involved
- ✓What the company is doing to investigate and contain the breach
- ✓Steps you can take to protect yourself (e.g., credit freeze, fraud alert)
- ✓Contact information so you can ask questions
Your Right to Sue
California provides a private right of action, meaning consumers can file lawsuits directly under the state's breach notification or privacy law — without waiting for the attorney general to act. CCPA provides statutory damages of $100–$750 per consumer per incident under Cal. Civ. Code § 1798.150
Statutory damages: $100–$750 per consumer per incident under the CCPA (Cal. Civ. Code § 1798.150) when unencrypted personal information is accessed due to the company's failure to implement reasonable security. Statutory damages may be awarded without proof of actual harm.
Attorney General Notification
Companies that experience a breach affecting California residents are required to notify the California Attorney General in addition to the affected individuals.
AG notification required when 500+ CA residents affected
Legal Disclaimer
This reference is for general educational purposes only and does not constitute legal advice. Last reviewed: 2026-01-01. Laws change frequently — always verify against the current official statute and consult a licensed attorney for advice specific to your situation.
Look up breaches affecting California residents
Search our database for companies that filed breach notifications with the California attorney general.
Legal Disclaimer
The information on this page is provided for general informational purposes only and does not constitute legal advice. Laws change frequently — always verify the current statute with the official state source or consult a licensed attorney in your jurisdiction before taking any action. This site is not a law firm and does not create an attorney-client relationship.