Go to integrated search

California Data Breach Notification Law Deadlines and Duties

Practice Area:Others
Jurisdiction:California

California data breach notification law sets specific duties for determining when notice is required and when it must be sent.

Businesses must assess whether compromised information triggers notice, identify affected residents, and calculate consumer and Attorney General deadlines. The analysis also requires the correct notice content, delivery method, and any permitted delay.



1. When Does a Data Breach Trigger a Notification Duty?


Civil Code § 1798.82 does not make every cybersecurity incident reportable. The analysis starts with who holds the information, what data was affected, and whether an unauthorized person acquired or is reasonably believed to have acquired covered personal information.


Identify the Personal Information Involved

The statute covers specified combinations of identifying information, including a person's name with certain government identification numbers, financial account information, medical or health insurance information, biometric data, or genetic data.

A username or email address combined with credentials that permit account access can also qualify.

The incident team should identify the affected data fields rather than assume every event involving personal data requires notice. A broader data breach response may involve additional operational issues.

Unauthorized Acquisition Is the Core Trigger

A breach generally involves unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of covered personal information.

Certain good-faith acquisitions by an employee or agent are excluded when the information was obtained for a legitimate business purpose and was not used or disclosed without authorization.

Encryption Does Not Automatically Eliminate Notice

Encrypted information may still trigger notice if an unauthorized person acquired or is reasonably believed to have acquired both the data and the encryption key or security credential, and the information could become readable or usable.

The response team should therefore assess whether the compromised data remained effectively protected after the incident.


2. What Deadlines Apply after a Reportable Breach?


Diagram: Decision path from breach discovery to resident notice, with a permitted delay branch and an additional Attorney General filing for breaches affecting more than 500 residents.
Diagram: Decision path from breach discovery to resident notice, with a permitted delay branch and an additional Attorney General filing for breaches affecting more than 500 residents.

The 2026 rules impose distinct timing requirements for residents, data owners, and the Attorney General.

ObligationWhen It AppliesTiming
Resident noticeCovered breach involving residentsWithin 30 calendar days of discovery or notification
Data owner noticeBusiness maintains data it does not ownImmediately following discovery when the statutory trigger is met
Attorney General submissionOne breach requires notice to more than 500 residentsWithin 15 calendar days after consumer notice

Resident notice

  • When It AppliesCovered breach involving residents
  • TimingWithin 30 calendar days of discovery or notification

Data owner notice

  • When It AppliesBusiness maintains data it does not own
  • TimingImmediately following discovery when the statutory trigger is met

Attorney General submission

  • When It AppliesOne breach requires notice to more than 500 residents
  • TimingWithin 15 calendar days after consumer notice

The Consumer Notice Period Is Generally 30 Days

Required disclosure generally must occur within 30 calendar days after discovery or notification of the breach.

Vendor reporting and internal escalation dates therefore matter. Companies with data privacy compliance procedures should document discovery and assign responsibility for evaluating notice promptly.

Some Investigation Delays Are Permitted

Notice may be delayed for legitimate law-enforcement needs or when necessary to determine the scope of the breach and restore the reasonable integrity of the system.

If law enforcement determines that disclosure would impede a criminal investigation, notice may also be delayed until disclosure will no longer compromise that investigation.

An open investigation alone does not create an unlimited extension.

More Than 500 Residents Triggers an AG Filing

If one breach requires notice to more than 500 residents, the business must electronically submit one sample copy of the consumer notice to the Attorney General.

The submission must exclude personally identifiable information and generally must be made within 15 calendar days after affected consumers are notified.


3. What Must the Breach Notice Say and How Can It Be Delivered?


Section 1798.82 regulates both the substance and presentation of the notice. A general statement that a security incident occurred is not enough.


Follow the Required Notice Format

The notice must use plain language and the title “Notice of Data Breach.” Required headings include:

  • What Happened?
  • What Information Was Involved?
  • What We Are Doing
  • What You Can Do
  • For More Information

The notice must identify the reporting business, provide contact information, describe the affected personal information, and state the breach date, estimated date, or date range when determinable.

It should also provide a general description of the incident when possible. The title and headings must be conspicuous, and the text may not be smaller than 10-point type.

Certain Data Can Add Requirements

If specified identification information was exposed, the notice may need to include contact information for the major credit reporting agencies.

When the statutory conditions are met, a business that was the source of the breach may also need to offer appropriate identity-theft prevention and mitigation services, if any, at no cost for at least 12 months.

Electronic and Substitute Notice Follow Separate Rules

Electronic notice may be used when applicable federal electronic-record requirements are satisfied.

Substitute notice is available only when statutory conditions are met, such as high direct-notice costs, a large affected class, or insufficient contact information. The business must then use the combination of methods specified by law.

HIPAA covered entities may also encounter a federal HITECH overlay. Compliance with applicable federal notice-content requirements can satisfy part of the state notice-content rule, but it does not eliminate the other duties under § 1798.82.

Broader compliance issues may require separate review under cybersecurity and data privacy.


4. Frequently Asked Questions


Does a Vendor Breach Require the Data Owner to Send Notice?

Possibly. A business maintaining covered personal information it does not own must notify the owner or licensee immediately following discovery when the statutory acquisition condition is satisfied.

The owner or licensee must then determine whether resident notification is required. Contractual vendor-reporting duties do not replace the statutory analysis.

Can a Breach Notice Be Sent to a Compromised Email Account?

Not always.

When the breach involves login credentials for an email account furnished by the business, notice generally cannot be sent only to that compromised address. Another authorized notice method or qualifying in-account notice may be required.



5. When Should a Privacy Attorney Review the Notification Decision?


Legal review becomes more important when unauthorized acquisition is uncertain, encrypted data and credentials were both affected, a vendor controls key forensic evidence, or residents in multiple states may be involved.

A privacy attorney can review the incident chronology, affected data, notification trigger, deadlines, proposed notice language, vendor responsibilities, and Attorney General submission requirements. Consumer claims or litigation should be assessed separately from the immediate breach-notification duties.


06 Oct, 2026


The information provided in this article is for general informational purposes only and does not constitute legal advice. Prior results do not guarantee a similar outcome. Reading or relying on the contents of this article does not create an attorney-client relationship with our firm. For advice regarding your specific situation, please consult a qualified attorney licensed in your jurisdiction.
Certain informational content on this website may utilize technology-assisted drafting tools and is subject to attorney review.

Related practices


Online Consultation
Phone Consultation