In short
- Any business that owns, licenses or maintains personal information about California residents must use reasonable security appropriate to the nature of the information, and require it of vendors by contract.
- If a breach results from failing to do so, consumers can sue for $107 to $799 per consumer per incident, or actual damages.
- The Attorney General has said that failing to implement the CIS Controls that apply to your environment "constitutes a lack of reasonable security."
- Larger and data-intensive CCPA businesses now face mandatory annual cybersecurity audits, with first certifications due from April 1, 2028.
The reasonable-security duty
A business that "owns, licenses, or maintains" personal information about a California resident "shall implement and maintain reasonable security procedures and practices appropriate to the nature of the information" to protect it from unauthorized access, destruction, use, modification or disclosure (Civ. Code § 1798.81.5(b)). The CCPA contains a parallel duty for businesses it covers (Civ. Code § 1798.100(e)).
- Vendors: if you disclose personal information to a nonaffiliated third party under a contract, the contract must require that party to maintain reasonable security (§ 1798.81.5(c)).
- Covered data: a name combined with a Social Security number, a government ID number, a financial account number with its access code, medical or health insurance information, biometric data or genetic data; or a username or email address with its password or security question (§ 1798.81.5(d)).
- Exemptions: providers governed by California's medical privacy law (CMIA), HIPAA covered entities, and financial institutions subject to the California Financial Information Privacy Act, among others (§ 1798.81.5(e)). Those entities have their own security rules.
- Disposal: when you no longer keep customer records containing personal information, dispose of them by shredding, erasing, or otherwise making the information unreadable (Civ. Code § 1798.81).
Breach lawsuits under the CCPA
The CCPA's only private right of action is for data breaches. A consumer can sue if their nonencrypted and nonredacted personal information is subject to unauthorized access and exfiltration, theft or disclosure as a result of the business's failure to maintain reasonable security (Civ. Code § 1798.150(a)).
| Point | Rule |
|---|---|
| Statutory damages | $107 to $799 per consumer per incident, or actual damages, whichever is greater (the statutory $100–$750, adjusted for inflation from January 1, 2025) |
| Notice before suit | For statutory damages, the consumer must first give 30 days' written notice. If a cure is possible and the business cures and says so in writing, statutory damages aren't available. |
| What isn't a cure | "The implementation and maintenance of reasonable security procedures and practices ... following a breach does not constitute a cure with respect to that breach." |
Sources: Civ. Code § 1798.150(a)–(b); CalPrivacy monetary thresholds. The next inflation adjustment is due January 1, 2027.
What "reasonable" means: the CIS Controls
Neither statute defines "reasonable." The clearest official benchmark is the Attorney General's California Data Breach Report (February 2016). Its first recommendation:
"The 20 controls in the Center for Internet Security's Critical Security Controls define a minimum level of information security that all organizations that collect or maintain personal information should meet. The failure to implement all the Controls that apply to an organization's environment constitutes a lack of reasonable security."
The report also recommended offering multi-factor authentication on consumer-facing online accounts that contain sensitive personal information. This is Attorney General guidance, not a statute or regulation. The CIS Controls have since been revised; the current version is 8.1.
CalPrivacy cybersecurity audits
Regulations effective January 1, 2026 require an annual, independent cybersecurity audit from CCPA businesses whose processing presents significant risk to consumers' security (11 CCR § 7120). That means a business that either:
- got 50% or more of its annual revenue from selling or sharing personal information in the preceding year; or
- met the revenue threshold ($26,625,000 as adjusted) and in the preceding year processed the personal information of 250,000 or more consumers or households, or the sensitive personal information of 50,000 or more consumers.
| Annual gross revenue | First audit report and certification due |
|---|---|
| More than $100 million (2026 revenue) | April 1, 2028 |
| $50 million to $100 million (2027 revenue) | April 1, 2029 |
| Less than $50 million (2028 revenue) | April 1, 2030 |
After the first audit, audits are annual (11 CCR § 7121). The auditor must be qualified, objective and independent (internal auditors must report to an executive who isn't responsible for the cybersecurity program), and audit records must be kept for five years (11 CCR § 7122). A member of executive management certifies completion to CalPrivacy under penalty of perjury (11 CCR § 7124).
The audit assesses, where applicable, 18 components (11 CCR § 7123(c)), including:
- multi-factor authentication (phishing-resistant for personnel) and strong passwords;
- encryption at rest and in transit;
- least-privilege access and privileged-access management;
- inventories of personal information, hardware and software;
- secure configuration, patching, vulnerability scanning and penetration testing;
- logging, network monitoring and data-loss prevention;
- training at onboarding and annually;
- oversight of service providers and contractors;
- retention schedules and secure disposal; and
- a written, tested incident-response plan, plus business continuity and backups.
An audit prepared for another purpose, such as one using the NIST Cybersecurity Framework 2.0, can be used if it meets all the requirements on its own or with supplementation (11 CCR § 7123(f)).
The HIPAA Security Rule
HIPAA covered entities and business associates must protect electronic protected health information with administrative, physical and technical safeguards (45 CFR §§ 164.308, 164.310, 164.312). The foundation is a documented risk analysis: "an accurate and thorough assessment of the potential risks and vulnerabilities" to that information (§ 164.308(a)(1)(ii)(A)).
Status of the proposed overhaul: HHS proposed major Security Rule changes in January 2025. As of this review, no final rule has been published, and the current federal regulatory agenda lists it as a long-term action. The existing rule remains in force.
Checklist
- A written information security program, scaled to the sensitivity of your data.Civ. Code §§ 1798.81.5(b), 1798.100(e)
- An inventory of where personal information lives, and of the hardware and software that touch it.11 CCR § 7123(c)(4)
- A gap assessment against the CIS Controls that apply to your environment.AG 2016 Data Breach Report, Rec. 1
- Multi-factor authentication for staff and for consumer accounts holding sensitive data.11 CCR § 7123(c)(1); AG 2016 Report, Rec. 2
- Encryption at rest and in transit. It also protects the breach-notice safe harbor.11 CCR § 7123(c)(2); Civ. Code § 1798.82(a)
- Least-privilege access, with prompt removal of access when people leave.11 CCR § 7123(c)(3)
- Patching, vulnerability scanning and periodic penetration testing.11 CCR § 7123(c)(5)–(6)
- Reasonable-security clauses in vendor contracts, and actual oversight of vendors.Civ. Code § 1798.81.5(c); 11 CCR § 7123(c)(15)
- Retention schedules and secure disposal.Civ. Code § 1798.81
- A written, tested incident-response plan.11 CCR § 7123(c)(17); 45 CFR § 164.308(a)(6)
- For HIPAA entities: a current, documented risk analysis and risk-management plan.45 CFR § 164.308(a)(1)(ii)(A)–(B)
- If you meet § 7120, a calendar for your first audit certification (April 1, 2028, 2029 or 2030).11 CCR §§ 7120–7124
Related guides
- Topic guideData breachesCalifornia data breach response: the 30-day notice deadline under SB 446, Attorney General filings, CDPH 15-business-day reports, HIPAA and FTC timelines, and an incident response checklist.
- Law explainerCalifornia's breach notice law after SB 446: 30 days, and what the notice must sayCivil Code 1798.82 as amended by SB 446: the 30-calendar-day deadline, AG filing within 15 days, the encryption safe harbor, required headings, and substitute notice.
Official sources
- Civil Code § 1798.81.5, § 1798.81, § 1798.150
- California Data Breach Report (2016) (California Attorney General)
- 11 Cal. Code Regs. §§ 7120–7124 (CalPrivacy)
- HIPAA Security Rule, 45 CFR Part 164, Subpart C (eCFR)