California’s data breach notification requirements changed on January 1, 2026. Senate Bill 446 amended California Civil Code section 1798.82 by replacing the state’s former flexible timing standard with a specific deadline. Subject to limited exceptions, an individual or business covered by the statute must notify affected California residents within 30 calendar days after discovering or receiving notification of a qualifying data breach.
The deadline compresses incident response. Organizations cannot assume that notice may wait until every forensic question has been answered. Legal, cybersecurity, insurance, communications, and executive teams should be prepared to investigate, determine whether protected personal information was or is reasonably believed to have been acquired, draft the required notice, and document any basis for delay while the clock is running.
What Did California SB 446 Change?
Before SB 446, California generally required disclosure in the most expedient time possible and without unreasonable delay. The statute did not impose a fixed number of days. SB 446 replaced that open-ended timing standard with a measurable deadline: subject to the statute’s delay provisions, disclosure must be made within 30 calendar days of discovery or notification of the breach.
SB 446 also established a separate reporting deadline for larger incidents. When a single breach requires notice to more than 500 California residents, the notifying organization must electronically submit a sample copy of the consumer notice to the California Attorney General within 15 calendar days after notifying the affected consumers. Personally identifiable information must be excluded from the sample.
Who Must Follow California’s Data Breach Notification Law?
California Civil Code section 1798.82 applies to an individual or business that conducts business in California and owns or licenses computerized data containing personal information. Because this provision does not use the CCPA’s revenue and data-volume thresholds, a company should not assume it is exempt from breach-notification duties merely because it falls outside the CCPA’s general definition of a business.
The statute also covers data custodians. An individual or business that maintains computerized personal information it does not own must notify the owner or licensee immediately after discovery if the information was, or is reasonably believed to have been, acquired by an unauthorized person. Vendor contracts should require prompt incident reporting, cooperation, evidence preservation, and access to information needed for notices.
When Does the 30-Day Notification Period Begin?
The statutory period begins upon discovery or notification of the data breach, making internal escalation critical. If an employee, information-technology provider, or security vendor does not promptly report suspicious activity, the organization may lose valuable time.
Businesses should define discovery, authorize someone to activate the response plan, and preserve a chronology. It should record when suspicious activity was detected, when unauthorized acquisition was confirmed or reasonably suspected, which systems and data were affected, when counsel and insurers were contacted, and how notification decisions were made.
Can Notification Be Delayed?
The 30-day rule permits delay for legitimate law-enforcement needs or as necessary to determine the breach’s scope and restore the reasonable integrity of the data system. If a law-enforcement agency determines that notice would impede a criminal investigation, notice may be postponed until the agency determines that disclosure will no longer compromise the investigation.
These exceptions are not automatic extensions. An organization relying on one should document the reason, supporting facts, delay period, and work performed. Once the justification ends, notification should proceed promptly.
What Must a California Data Breach Notice Include?
California prescribes both the format and minimum content of a consumer notice. The notice must be written in plain language, use text no smaller than 10-point type, and be titled “Notice of Data Breach.” It must organize the required information under the headings “What Happened?” “What Information Was Involved?” “What We Are Doing,” “What You Can Do,” and “For More Information.”
The notice must provide the reporting party’s name and contact information; identify the types of personal information involved; include the date of the notice; give the known or estimated breach date or date range, if determinable; disclose a law-enforcement delay, if determinable; and generally describe the incident. If the breach exposed a Social Security number, driver’s-license number, or California identification-card number, the notice must include the toll-free telephone numbers and addresses of the major credit-reporting agencies. If the notifying party was the source of the breach and the affected information includes, or may include, a Social Security number or an identification number listed in subdivision (h)(1)(B), the statute also requires an offer of appropriate identity-theft prevention and mitigation services, if any, at no cost for at least 12 months, together with the information needed to use the offer.
What Information Is Protected?
The statute covers a California resident’s first name or first initial and last name when combined with specified sensitive data, including Social Security numbers, government-issued identification numbers, financial-account credentials, medical information, health-insurance information, authentication biometrics, automated license-plate recognition data, and genetic data. It also separately covers a username or email address combined with a password or security question and answer that permits access to an online account.
Encrypted data is not always outside the statute. Notification may still be required when an unauthorized person acquires, or is reasonably believed to have acquired, both encrypted personal information and an encryption key or security credential that could make the information readable or usable.
How Does SB 446 Relate to the CCPA?
SB 446 governs breach notification, while related statutes create security and litigation risks. Subject to statutory exceptions, California Civil Code section 1798.81.5 requires a business that owns, licenses, or maintains California residents’ personal information to implement and maintain reasonable security appropriate to the information. Section 1798.150 provides a limited private right of action when specified nonencrypted and nonredacted personal information, or an email address combined with account-access credentials, is subject to unauthorized access and exfiltration, theft, or disclosure because a business failed to implement and maintain reasonable security. The action is limited to the violations defined in section 1798.150 and does not arise from every CCPA violation.
Timely notice alone does not eliminate exposure. Regulators, consumers, insurers, and business partners may examine the organization’s safeguards, vendor-security obligations, evidence preservation, and response after discovery.
Practical Compliance Steps:
Update the written incident-response plan to incorporate the 30-day consumer deadline and the 15-day Attorney General reporting requirement.
Require employees and vendors to escalate suspected breaches immediately and identify a primary and backup response leader.
Prepare a California-compliant notice template using the required title, headings, font size, and content fields.
Create an incident chronology and decision log that documents discovery, investigation, containment, statutory analysis, and any reason for delayed notice.
Review cyber-insurance policies and vendor contracts for notice, consent, cooperation, forensic, and defense requirements.
Coordinate California obligations with the laws of every other affected jurisdiction because a multistate incident may trigger different deadlines and reporting rules.
Conclusion
California SB 446 replaces an open-ended timing standard with a deadline-driven process. Organizations handling California residents’ personal information should update response plans before an incident. After a potential breach is discovered, early coordination among legal, technical, insurance, and communications professionals can help preserve evidence, meet the new timelines, and reduce avoidable risk. Please contact our law firm should you have any questions.