CALIFORNIA

CALIFORNIA Data Breach Notification Law

Cal. Civ. Code § 1798.82 (notification, as amended by SB 446, eff. Jan 1, 2026); Cal. Civ. Code § 1798.150 (CCPA private right of action)

California has the nation's strongest consumer data breach laws. As of January 1, 2026, SB 446 requires notification within a hard 30-day deadline from discovery (Cal. Civ. Code § 1798.82). The CCPA (Cal. Civ. Code § 1798.150) provides a private right of action with statutory damages of $100–$750 per consumer per incident when a company's failure to implement reasonable security exposes unencrypted personal information — no proof of actual harm required.

Notification Deadline
30 days
30 days from discovery (Cal. Civ. Code § 1798.82, as amended by SB 446, eff. Jan 1, 2026)
⚖️
Private Right of Action
Yes
CCPA provides statutory damages of $100–$750 per consumer per incident under Cal. Civ. Code § 1798.150
💰
Statutory Damages
$100–$750 per consumer per incident under the CCPA (Cal. Civ. Code § 1798.150) when unencrypted personal information is accessed due to the company's failure to implement reasonable security. Statutory damages may be awarded without proof of actual harm.
🏛
AG Notification Required
Yes
AG notification required when 500+ CA residents affected

What This Law Covers

CALIFORNIA's breach notification law requires businesses and government agencies that maintain personal information about CALIFORNIA residents to notify affected individuals when that information is subject to unauthorized access or acquisition. "Personal information" typically includes Social Security numbers, driver's license numbers, financial account numbers, and in many states has been expanded to cover medical data, biometric data, online credentials, and tax IDs.

What the Company Must Tell You

A compliant breach notification to CALIFORNIA residents must include:

  • A description of the breach — what happened and when
  • The types of personal information that were involved
  • What the company is doing to investigate and contain the breach
  • Steps you can take to protect yourself (e.g., credit freeze, fraud alert)
  • Contact information so you can ask questions

Your Right to Sue

CALIFORNIA provides a private right of action, meaning consumers can file lawsuits directly under the state's breach notification or privacy law — without waiting for the attorney general to act. CCPA provides statutory damages of $100–$750 per consumer per incident under Cal. Civ. Code § 1798.150

Statutory damages: $100–$750 per consumer per incident under the CCPA (Cal. Civ. Code § 1798.150) when unencrypted personal information is accessed due to the company's failure to implement reasonable security. Statutory damages may be awarded without proof of actual harm.

Attorney General Notification

Companies that experience a breach affecting CALIFORNIA residents are required to notify the CALIFORNIA Attorney General in addition to the affected individuals.

AG notification required when 500+ CA residents affected

Legal Disclaimer

This reference is for general educational purposes only and does not constitute legal advice. Last reviewed: 2026-01-01. Laws change frequently — always verify against the current official statute and consult a licensed attorney for advice specific to your situation.

Look up breaches affecting CALIFORNIA residents

Search our database for companies that filed breach notifications with the CALIFORNIA attorney general.

Legal Disclaimer

The information on this page is provided for general informational purposes only and does not constitute legal advice. Laws change frequently — always verify the current statute with the official state source or consult a licensed attorney in your jurisdiction before taking any action. This site is not a law firm and does not create an attorney-client relationship.

Made with AI in Macaly