Drop45 › DROP guides

California data breach notification: what the law actually requires

California's data breach notification statute predates the Delete Act by two decades and runs on its own timeline. If your business holds personal information on California residents, here's who has to notify, when, and what triggers the duty.

Where the law comes from

California's breach notification duty traces back to SB 1386 (2002), the first data breach notification law in the country, later codified at Cal. Civ. Code § 1798.82 (for businesses) and § 1798.29 (for state agencies). It has been amended repeatedly since — most recently to expand what counts as "personal information" and to add the California Attorney General reporting duty. It is a completely separate statute from the CCPA/CPRA and from the Delete Act (SB 362), even though all three sit in the same corner of California privacy law.

Who must notify

Civil Code § 1798.82 applies to "any person or business conducting business in California" that owns or licenses computerized data including personal information — not just companies headquartered in the state. If you have California customers, employees, or users in a database, the duty can reach you regardless of where you're incorporated. It also covers businesses that merely maintain data on behalf of another business: a processor that gets breached has to notify the data's owner "immediately following discovery," even though it isn't the one sending notice to consumers.

What counts as personal information

The statute's definition is narrower than the CCPA's. It's triggered by an individual's first name or initial plus last name, combined with one or more of:

Encrypted data generally falls outside the duty — the statute is about unauthorized acquisition of unencrypted personal information, or encrypted data where the encryption key was also compromised.

What triggers the notification duty

Notification is required once a business discovers, or is notified of, a breach of the security of the system resulting in unauthorized acquisition of unencrypted personal information. "Acquisition" is broader than "access" — an intruder who merely viewed data without confirmed copying may or may not trigger the duty depending on the facts, which is why breach counsel typically gets involved early to make that call.

Notification deadline

California doesn't set a fixed day count like some states. The statute requires disclosure "in the most expedient time possible and without unreasonable delay," subject to two carve-outs: the time law enforcement needs to determine that notice won't impede a criminal investigation, and the time needed to determine the scope of the breach and restore system integrity. In practice, most breach counsel treats 30-45 days as the outer edge of "without unreasonable delay" absent a documented law-enforcement hold.

The Attorney General reporting threshold

TriggerRequirementAuthority
Breach affects 500+ California residentsSubmit a sample copy of the notice (with personal details redacted) to the California Attorney GeneralCiv. Code § 1798.82(f)
Breach affects fewer than 500 California residentsNotify affected individuals directly; no AG filing requiredCiv. Code § 1798.82
Breach affects 500,000+ residents nationally, or costs exceed $250,000Substitute notice (email, website posting, statewide media) permitted instead of individual lettersCiv. Code § 1798.82(j)

The Attorney General publishes submitted sample notices on a public breach report page, which means a 500+ resident breach becomes a matter of public record — a meaningful reputational consideration on top of the legal one.

What the notice has to say

Section 1798.82 prescribes specific content: the name and contact information of the reporting entity, the categories of personal information breached, the date (or date range) of the breach, and a general description of the incident. Notices covering breach of login credentials must also tell the recipient to change their password and security questions, or take other steps to protect the affected account.

How this relates to CCPA and CPRA

Breach notification and consumer privacy compliance are governed by different statutes with different regulators, but they overlap in one important way: the CPRA gave California consumers a private right of action (Civ. Code § 1798.150) for breaches of certain unencrypted, nonencrypted personal information caused by a business's failure to maintain reasonable security procedures — on top of the AG notification duty above. A business already building out CCPA/CPRA compliance processes should treat breach-notification readiness as part of the same program, not a separate project, since the private-right-of-action exposure sits directly downstream of the same underlying security failure.

The data-broker connection

Every data broker holding a copy of your business's customer or employee records is another potential breach vector — and under Civil Code § 1798.82, a breach at a broker that maintains your data on your behalf still triggers a notification obligation for you as the data owner once the broker discloses it. California's Delete Act DROP program exists precisely to shrink that exposure: instead of sending an opt-out request to each of the 500+ brokers on the state registry individually, DROP lets you submit one deletion request that fans out broker-side. Fewer brokers holding your data means fewer places a breach can originate, and fewer parties who could trigger a notification duty on your behalf. See California Delete Act regulations and dates and SB 362, the Delete Act for how the deletion mechanics work.

FAQ

Does encrypting data eliminate the notification duty?

Generally yes, unless the encryption key itself was also acquired in the breach — in which case the data is treated as if it were unencrypted.

Is there a minimum number of affected people before notification is required at all?

No. Individual notice to affected California residents is required regardless of headcount; the 500-resident threshold only triggers the additional Attorney General filing.

Does this law replace CCPA/CPRA breach obligations?

No — they're separate statutes that can both apply to the same incident. Breach notification is triggered by unauthorized acquisition of specific data elements; CCPA/CPRA governs broader data-handling and consumer-rights obligations, with its own private right of action for security failures.

Fewer brokers holding your data, fewer breach vectors. Drop45 matches your business against California's data broker registry and helps you file DROP deletion requests in one pass. Get Drop45 →