Privacy Law Library

Security breach notification (businesses)

Breach Notification (1798.82)

Breach notification

Requires notice to California residents when their unencrypted personal information (or encrypted data with a compromised key) is, or is reasonably believed to have been, acquired by an unauthorized person. SB 446 (2025) added a firm 30-calendar-day deadline from January 1, 2026.

Where
California
Citation
Cal. Civ. Code 1798.82
Status
In force
In force since
2003-07-01
Last amended
2026-01-01
Enforced by
California Attorney General; private plaintiffs
People can sue
Yes
Penalties
Injured customers may sue for damages and injunctive relief (1798.84); AG enforcement under the Unfair Competition Law.
Applies to
  • Individuals and businesses conducting business in California that own or license computerized data including personal information (1798.82(a))
  • Those that maintain data they do not own must notify the owner (1798.82(b))
  • State agencies are covered by the parallel Civ. Code 1798.29

Breach duties

  • Notify affected California residents within 30 calendar days of discovery or notification of a breach, subject to law-enforcement delay or time needed to determine scope and restore the system.Cal. Civ. Code 1798.82(a)(2), (c) · From 2026-01-01
  • A business that maintains data it does not own must notify the owner or licensee immediately after discovery.Cal. Civ. Code 1798.82(b)
  • Notices must be titled 'Notice of Data Breach', use prescribed headings, be in at least 10-point type, and include listed content.Cal. Civ. Code 1798.82(d)(1)-(2)
  • If the business was the source of a breach exposing SSNs, driver's license, or state ID numbers, offer at least 12 months of free identity theft prevention and mitigation services.Cal. Civ. Code 1798.82(d)(2)(G)
  • If more than 500 California residents are notified, submit a sample notice to the Attorney General within 15 calendar days of notifying consumers.Cal. Civ. Code 1798.82(f)
  • Covered data includes name plus SSN, ID numbers, financial account data, medical or health insurance data, biometric data, ALPR data, or genetic data, and online account credentials.Cal. Civ. Code 1798.82(h)

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Unverified: Original effective date (July 1, 2003, SB 1386) is from background knowledge.

Research reference, not legal advice.