What changed. SB 446 (Stats. 2025, ch. 319, signed October 3, 2025) replaced the old standard, "in the most expedient time possible and without unreasonable delay," with a 30-calendar-day deadline, and added a 15-day deadline for the Attorney General filing. Both took effect January 1, 2026.
Who must notify
Any "individual or business that conducts business in California, and that owns or licenses computerized data that includes personal information" (Civ. Code § 1798.82(a)(1)). A business that maintains data it doesn't own, such as a vendor or service provider, must instead notify the owner or licensee immediately following discovery (§ 1798.82(b)).
The law is about computerized data. Paper records are covered by other laws, including the medical-information rules for health providers.
What triggers notice
Notice is required when a California resident's unencrypted personal information "was, or is reasonably believed to have been, acquired by an unauthorized person" (§ 1798.82(a)(1)). A breach is "unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information." Good-faith acquisition by an employee or agent for business purposes is not a breach if the information isn't further misused (§ 1798.82(g)).
"Personal information" for this purpose
A first name or initial and last name, combined with any of the following, when either the name or the data element is unencrypted (§ 1798.82(h)(1)):
- Social Security number;
- driver's license, California ID, tax ID, passport, military ID or other government ID number;
- account, credit or debit card number with any required code or password;
- medical information, or health insurance information;
- unique biometric data used to authenticate identity;
- information from an automated license plate recognition system; or
- genetic data.
Or, with no name needed: a username or email address with a password or security question and answer that would permit access to an online account (§ 1798.82(h)(2)).
The encryption safe harbor
Encrypted data triggers notice only if the encryption key or security credential was, or is reasonably believed to have been, also acquired, and you reasonably believe it could make the data readable or usable (§ 1798.82(a)(1)). Encryption must use a technology or method "generally accepted in the field of information security" (§ 1798.82(i)).
The deadline
"Subject to subparagraph (B), the disclosure required by this subdivision shall be made within 30 calendar days of discovery or notification of the data breach."
Civ. Code § 1798.82(a)(2)(A)
Two delays are allowed (§ 1798.82(a)(2)(B), (c)):
- Law enforcement: if a law enforcement agency determines that notice would impede a criminal investigation. Notify promptly once the agency says notice won't compromise the investigation.
- Scope and restoration: "as necessary to determine the scope of the breach and restore the reasonable integrity of the data system." The statute sets no outer limit, and it hasn't been tested. Don't count on it as an extension.
What the notice must say
The notice must be written in plain language, titled "Notice of Data Breach," and organized under these headings (§ 1798.82(d)(1)):
| Heading | Content |
|---|---|
| What Happened? | A general description of the incident; the date, estimated date or date range of the breach, if it can be determined; the date of the notice; and whether notice was delayed for law enforcement. |
| What Information Was Involved? | The types of personal information that were, or are reasonably believed to have been, involved. |
| What We Are Doing | Optional detail on what you've done to protect the people affected. Where required, the identity-theft protection offer. |
| What You Can Do | Optional advice on steps the person can take. For Social Security, driver's license or California ID numbers, the toll-free numbers and addresses of the major credit reporting agencies. |
| For More Information | Your name and contact information. |
The placement of items under each heading above is illustrative. The required content is listed in § 1798.82(d)(2), and optional content in (d)(3). Format rules: the title and headings must be clearly and conspicuously displayed, the text must be no smaller than 10-point type, and the design must call attention to the notice. Using the model form in the statute is deemed to comply (§ 1798.82(d)(1)).
Identity-theft protection
If you were the source of the breach and it exposed, or may have exposed, a Social Security number or a driver's license, California ID, tax ID, passport, military ID or other government ID number, the notice must offer appropriate identity-theft prevention and mitigation services at no cost for at least 12 months (§ 1798.82(d)(2)(G)).
Filing with the Attorney General
If you notify more than 500 California residents as a result of a single breach, you must electronically submit one sample copy of the notice, without personal information, to the Attorney General within 15 calendar days of notifying affected consumers (§ 1798.82(f)). Use the AG's online submission form. Submitted notices appear on the AG's public list of data breaches.
How to deliver notice
- Written notice, or electronic notice consistent with the federal E-SIGN Act (§ 1798.82(j)(1)–(2)).
- Substitute notice if the cost would exceed $250,000, more than 500,000 people are affected, or you lack sufficient contact information. It requires all of: email where you have addresses; a conspicuous posting on your website for at least 30 days; and notice to major statewide media (§ 1798.82(j)(3)).
- Credential-only breaches may be notified electronically, directing people to change their password or security question. If the compromised credentials are for an email account you provide, don't send the notice to that account (§ 1798.82(j)(4)–(5)).
HIPAA covered entities
A covered entity that fully complies with the HITECH Act's notice requirements is deemed to comply with § 1798.82's content and format requirements. That safe harbor doesn't exempt it from the rest of the section, including the 30-day deadline and the Attorney General filing (§ 1798.82(e)).
Official sources
- Civil Code § 1798.82 (California Legislative Information)
- SB 446 (Stats. 2025, ch. 319), bill history and text
- Submit a data security breach sample notice (California Attorney General)
- Topic guideData breachesCalifornia data breach response: the 30-day notice deadline under SB 446, Attorney General filings, CDPH 15-business-day reports, HIPAA and FTC timelines, and an incident response checklist.
- Topic guideSecurity policies and controlsCalifornia's reasonable-security duty (Civ. Code 1798.81.5), CCPA breach lawsuits, the AG's CIS Controls benchmark, the HIPAA Security Rule, and CalPrivacy cybersecurity audit deadlines.