Security breach notification (businesses)
Breach Notification (1798.82)
Breach notification
Requires notice to California residents when their unencrypted personal information (or encrypted data with a compromised key) is, or is reasonably believed to have been, acquired by an unauthorized person. SB 446 (2025) added a firm 30-calendar-day deadline from January 1, 2026.
- Where
- California
- Citation
- Cal. Civ. Code 1798.82
- Status
- In force
- In force since
- 2003-07-01
- Last amended
- 2026-01-01
- Enforced by
- California Attorney General; private plaintiffs
- People can sue
- Yes
- Penalties
- Injured customers may sue for damages and injunctive relief (1798.84); AG enforcement under the Unfair Competition Law.
- Applies to
- Individuals and businesses conducting business in California that own or license computerized data including personal information (1798.82(a))
- Those that maintain data they do not own must notify the owner (1798.82(b))
- State agencies are covered by the parallel Civ. Code 1798.29
Breach duties
- Notify affected California residents within 30 calendar days of discovery or notification of a breach, subject to law-enforcement delay or time needed to determine scope and restore the system.Cal. Civ. Code 1798.82(a)(2), (c) · From 2026-01-01
- A business that maintains data it does not own must notify the owner or licensee immediately after discovery.Cal. Civ. Code 1798.82(b)
- Notices must be titled 'Notice of Data Breach', use prescribed headings, be in at least 10-point type, and include listed content.Cal. Civ. Code 1798.82(d)(1)-(2)
- If the business was the source of a breach exposing SSNs, driver's license, or state ID numbers, offer at least 12 months of free identity theft prevention and mitigation services.Cal. Civ. Code 1798.82(d)(2)(G)
- If more than 500 California residents are notified, submit a sample notice to the Attorney General within 15 calendar days of notifying consumers.Cal. Civ. Code 1798.82(f)
- Covered data includes name plus SSN, ID numbers, financial account data, medical or health insurance data, biometric data, ALPR data, or genetic data, and online account credentials.Cal. Civ. Code 1798.82(h)
Sources
- Official text
- Cal. Civ. Code 1798.82 (California Legislative Information)
- California Attorney General: Submit Data Security Breach
- SB 446 (2025) bill history
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Unverified: Original effective date (July 1, 2003, SB 1386) is from background knowledge.
Research reference, not legal advice.