← Back to blog

30 Days to Notify: California Data Breach Law for Businesses, CPPA 2026

September 1, 2026
30 Days to Notify: California Data Breach Law for Businesses, CPPA 2026

California businesses must notify affected residents when unencrypted personal information, or encrypted information plus the keys to decrypt it, is acquired or reasonably believed to have been acquired by an unauthorized person. The clock starts at discovery, not investigation's end, and notice generally must go out within 30 calendar days under Cal. Civ. Code § 1798.82. If the incident affects more than 500 California residents, you must also file a sample notice with the California Attorney General.


TL;DR:

  • Businesses must act within 30 days of discovering or reasonably believing a breach, even if the investigation is incomplete.
  • Encryption only provides safe harbor if keys are protected and not compromised; losing control over keys invalidates the safe harbor.
  • Breach notification must include specific information such as what happened, data involved, and remedial actions, organized under mandated headings.
  • Vendors and third-party processors must notify their clients immediately upon breach discovery, which triggers the client’s own 30-day obligation.
  • In incidents affecting over 500 Californians, a sample notice must be filed with the Attorney General within 15 days of consumer notification.

Table of Contents

California Data Breach Law Requirements at a Glance

Before drafting a single sentence of notice language, confirm where you actually stand. Compliance officers and IT leads who treat this as a checklist, rather than an afterthought bolted onto incident response, avoid the scramble that turns a 30-day deadline into a missed one.

  • Confirm whether the exposed data qualifies as "personal information" under §1798.82's definition, not a looser internal standard.
  • Start the 30-calendar-day clock the moment you discover or reasonably believe unauthorized acquisition occurred.
  • Draft the required notice headings and minimum content before you need them, not after.
  • If more than 500 California residents are affected by a single incident, prepare a PII-excluded sample notice for the Attorney General and file it within 15 days of consumer notice.
  • Pick a notice method—mail, electronic, or substitute notice—that fits your contact data and incident scale.

Who Has to Notify Under California's Breach Law?

The statute covers any business or state or local agency that owns or licenses computerized data containing personal information about a California resident. That's a wide net. It catches a five-person medical billing firm in Encino as readily as a statewide retailer, and it applies regardless of where your servers physically sit.

"Discovery" is the trigger, and California's Civil Code treats it strictly. The 30-day clock starts the moment you know, or reasonably should know, that unauthorized acquisition happened, not when your forensic report is finished. Businesses often want to wait for a complete picture before saying anything. The law doesn't allow that. You notify with what you know and follow up with supplemental notices as the investigation develops.

Third-party processors face a separate rule. A service provider or contractor that maintains data but doesn't own or license it must notify the data's owner or licensee immediately upon discovering a breach, without waiting for its own root-cause analysis. If your managed service provider, payroll vendor, or SaaS platform gets breached, your own 30-day clock effectively starts the moment they tell you, so contract language that delays that notification puts your compliance timeline at risk before you even know there's a problem.

Breach discovery to notification timeline

What the Required Breach Notice Must Say

California doesn't leave notice content to guesswork. The Attorney General's guidance confirms notices must be written in plain language, titled "Notice of Data Breach," and organized under specific headings.

  1. What Happened? A factual, non-technical description of the incident.
  2. What Information Was Involved? The categories of personal information exposed, plus the date or date range if known.
  3. What We Are Doing. Remediation steps taken and, if your business was the source of the breach, any identity-theft mitigation services offered.
  4. What You Can Do. Practical steps recipients can take, such as placing a fraud alert or credit freeze.
  5. For More Information. Contact details and links to resources like the credit bureaus.

Credential-only breaches, where only a username and password were exposed, get special treatment. You can satisfy notice requirements by directing the affected person to promptly change their password and security questions, rather than mailing a full notice, provided you don't have to notify by mail for other reasons. If your contact information is incomplete or the cost of individual notice would be disproportionate, substitute notice provisions may apply instead.

Pro Tip: Draft your five notice headings as a template before an incident happens. Trying to write "What We Are Doing" from scratch on day 25 of a 30-day clock is how deadlines get missed.

Does Encryption Protect You From Notification Duties?

Encryption is a genuine safe harbor under California law, but it's narrower than most IT teams assume. If personal information is encrypted and rendered unusable, unreadable, or indecipherable, you generally don't owe notification. The moment an attacker also gets the encryption keys or credentials, that safe harbor disappears. Treat the incident as if the data were never encrypted at all.

Key custody matters more than most breach plans acknowledge. Rotate keys on a schedule, isolate key storage from the data it protects, and treat any suspected key compromise as an immediate notification trigger rather than something to investigate first.

Separated encryption keys protecting data vault

Two other exceptions matter. Law enforcement can request a delay if notification would impede a criminal investigation, but you must resume notice promptly once law enforcement confirms delay is no longer necessary. And good-faith acquisition of data by an employee acting within the scope of employment isn't a breach at all, as long as it isn't followed by unauthorized disclosure.

How Do You File a Sample Notice With the Attorney General?

When a single incident affects more than 500 California residents, filing isn't optional. A single sample copy of the notice, stripped of all personally identifiable information, goes to the Attorney General's office within 15 days of when you send consumer notices.

  • Submit through the Attorney General's online security breach reporting form, not by mail or email.
  • Exclude names, account numbers, and any other data that could identify a specific resident.
  • Choose your consumer notice method carefully: written notice, electronic notice, or substitute notice if direct notice would cost a high amount, affect a very large number of people, or if you lack sufficient contact information.

A statute tells you what to do. It doesn't tell you how to move fast enough to do it. Here's the operational sequence that keeps a breach from becoming a compliance failure on top of a security failure.

  1. Contain and preserve. Isolate affected systems, snapshot logs before they rotate out, and rotate compromised credentials or keys immediately; see these data loss prevention tips for Mac users for device-level best practices.
  2. Assess the legal trigger. Determine whether the exposed data meets §1798.82's definition of personal information and whether encryption keys were also compromised.
  3. Check third-party obligations. If a vendor or contractor was involved, confirm who owns the notification duty and how fast they're required to tell you.
  4. Draft early, not last. Start writing the five required notice headings as soon as you have a partial picture. Waiting for a final forensic report burns days you don't have.
  5. Notify and file. Send consumer notices within 30 calendar days of discovery, and file the AG sample notice within 15 days of that if more than 500 Californians are affected.
  6. Document everything. Keep a timestamped log of when you learned what, and every decision made along the way.

Bring in outside forensic firms and breach counsel early, particularly for incidents involving regulated data like health or financial records, where cloud infrastructure compliance questions and evidence preservation get complicated fast. Law enforcement involvement makes sense when the incident looks like organized criminal activity, but don't treat it as a substitute for your own notification clock.

Pro Tip: A documented decision log, showing exactly when you knew what and why you notified when you did, is often the difference between a routine filing and a regulatory inquiry.

What's Changing in California Privacy Law for 2026?

The California Privacy Protection Agency is now the primary enforcement body shaping how breach readiness intersects with broader privacy compliance. Its 2026 rulemaking expands into cybersecurity audits, risk assessments, and rules governing automated decision-making technology, all of which touch how businesses document and defend their security posture before a breach ever happens.

SB-446 reaffirms the 30-day notification requirement while adjusting procedural details businesses need to fold into their incident-response plans. If your privacy policy, vendor contracts, or breach playbook were last updated before this cycle, they're due for a review against the current CCPA compliance framework. Vendor agreements in particular deserve a fresh look. This affects the notification timelines contractors owe you under the amended statute.

Why Most Breach Plans Fail Before the Breach Happens

The gap in California breach compliance isn't usually the legal knowledge. Most compliance officers can recite the 30-day rule in their sleep. The gap is operational: nobody has actually drafted the five required headings in advance, nobody knows who owns the AG filing, and nobody has tested whether their "immediate" notification clause with vendors means anything in practice.

I'd argue the encryption safe harbor gets more attention than it deserves relative to key management. Businesses invest heavily in encrypting data at rest, then treat key rotation as a background IT task instead of the actual legal safeguard it is. If your keys are as exposed as your data, encryption bought you nothing. The safe harbor lives or dies on key custody discipline, not on the fact that encryption exists somewhere in your stack.

— Alex

Get Help Building a California Breach Response Plan

Securetechie gives Southern California businesses something most breach plans lack until it's too late: a team that already knows your infrastructure before an incident happens. Instead of scrambling to explain your network to an outside forensics firm on day one of a 30-day clock, you're working with people who monitor your systems around the clock and can move straight to containment.

Securetechie

Securetechie's cybersecurity solutions include incident response planning built around California's specific notification requirements, not a generic template. If your incident-response plan hasn't been stress-tested against the 30-day rule, schedule a breach readiness assessment with Securetechie and find out where the gaps are before an attacker does.

This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.

Sources