1. When Does a Data Breach Trigger a Notification Duty?
Civil Code § 1798.82 does not make every cybersecurity incident reportable. The analysis starts with who holds the information, what data was affected, and whether an unauthorized person acquired or is reasonably believed to have acquired covered personal information.
Identify the Personal Information Involved
The statute covers specified combinations of identifying information, including a person's name with certain government identification numbers, financial account information, medical or health insurance information, biometric data, or genetic data.
A username or email address combined with credentials that permit account access can also qualify.
The incident team should identify the affected data fields rather than assume every event involving personal data requires notice. A broader data breach response may involve additional operational issues.
Unauthorized Acquisition Is the Core Trigger
A breach generally involves unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of covered personal information.
Certain good-faith acquisitions by an employee or agent are excluded when the information was obtained for a legitimate business purpose and was not used or disclosed without authorization.
Encryption Does Not Automatically Eliminate Notice
Encrypted information may still trigger notice if an unauthorized person acquired or is reasonably believed to have acquired both the data and the encryption key or security credential, and the information could become readable or usable.
The response team should therefore assess whether the compromised data remained effectively protected after the incident.
2. What Deadlines Apply after a Reportable Breach?

The 2026 rules impose distinct timing requirements for residents, data owners, and the Attorney General.
| Obligation | When It Applies | Timing |
|---|---|---|
| Resident notice | Covered breach involving residents | Within 30 calendar days of discovery or notification |
| Data owner notice | Business maintains data it does not own | Immediately following discovery when the statutory trigger is met |
| Attorney General submission | One breach requires notice to more than 500 residents | Within 15 calendar days after consumer notice |
Resident notice
- When It AppliesCovered breach involving residents
- TimingWithin 30 calendar days of discovery or notification
Data owner notice
- When It AppliesBusiness maintains data it does not own
- TimingImmediately following discovery when the statutory trigger is met
Attorney General submission
- When It AppliesOne breach requires notice to more than 500 residents
- TimingWithin 15 calendar days after consumer notice
The Consumer Notice Period Is Generally 30 Days
Required disclosure generally must occur within 30 calendar days after discovery or notification of the breach.
Vendor reporting and internal escalation dates therefore matter. Companies with data privacy compliance procedures should document discovery and assign responsibility for evaluating notice promptly.
Some Investigation Delays Are Permitted
Notice may be delayed for legitimate law-enforcement needs or when necessary to determine the scope of the breach and restore the reasonable integrity of the system.
If law enforcement determines that disclosure would impede a criminal investigation, notice may also be delayed until disclosure will no longer compromise that investigation.
An open investigation alone does not create an unlimited extension.
More Than 500 Residents Triggers an AG Filing
If one breach requires notice to more than 500 residents, the business must electronically submit one sample copy of the consumer notice to the Attorney General.
The submission must exclude personally identifiable information and generally must be made within 15 calendar days after affected consumers are notified.
3. What Must the Breach Notice Say and How Can It Be Delivered?
Section 1798.82 regulates both the substance and presentation of the notice. A general statement that a security incident occurred is not enough.
Follow the Required Notice Format
The notice must use plain language and the title “Notice of Data Breach.” Required headings include:
- What Happened?
- What Information Was Involved?
- What We Are Doing
- What You Can Do
- For More Information
The notice must identify the reporting business, provide contact information, describe the affected personal information, and state the breach date, estimated date, or date range when determinable.
It should also provide a general description of the incident when possible. The title and headings must be conspicuous, and the text may not be smaller than 10-point type.
Certain Data Can Add Requirements
If specified identification information was exposed, the notice may need to include contact information for the major credit reporting agencies.
When the statutory conditions are met, a business that was the source of the breach may also need to offer appropriate identity-theft prevention and mitigation services, if any, at no cost for at least 12 months.
Electronic and Substitute Notice Follow Separate Rules
Electronic notice may be used when applicable federal electronic-record requirements are satisfied.
Substitute notice is available only when statutory conditions are met, such as high direct-notice costs, a large affected class, or insufficient contact information. The business must then use the combination of methods specified by law.
HIPAA covered entities may also encounter a federal HITECH overlay. Compliance with applicable federal notice-content requirements can satisfy part of the state notice-content rule, but it does not eliminate the other duties under § 1798.82.
Broader compliance issues may require separate review under cybersecurity and data privacy.
4. Frequently Asked Questions
Does a Vendor Breach Require the Data Owner to Send Notice?
Possibly. A business maintaining covered personal information it does not own must notify the owner or licensee immediately following discovery when the statutory acquisition condition is satisfied.
The owner or licensee must then determine whether resident notification is required. Contractual vendor-reporting duties do not replace the statutory analysis.
Can a Breach Notice Be Sent to a Compromised Email Account?
Not always.
When the breach involves login credentials for an email account furnished by the business, notice generally cannot be sent only to that compromised address. Another authorized notice method or qualifying in-account notice may be required.
5. When Should a Privacy Attorney Review the Notification Decision?
Legal review becomes more important when unauthorized acquisition is uncertain, encrypted data and credentials were both affected, a vendor controls key forensic evidence, or residents in multiple states may be involved.
A privacy attorney can review the incident chronology, affected data, notification trigger, deadlines, proposed notice language, vendor responsibilities, and Attorney General submission requirements. Consumer claims or litigation should be assessed separately from the immediate breach-notification duties.
06 Oct, 2026

