Skip to content

Cyber Liability by state

California data breach notification law and cyber insurance

Direct answer

What is California's data breach notification law?

California's breach notification law (Cal. Civ. Code sect. 1798.82) requires businesses to notify affected residents in the most expedient time possible and without unreasonable delay, and not later than 30 calendar days after discovery or notification of the breach after a breach of personal information.

Reviewed by Cornerstone Staff28 years of financial services state licensing experienceLast verified July 29, 2026

What the statute requires

California requires businesses to notify residents of breaches of unencrypted personal information within 30 days of discovery, and to send a copy of the notice to the Attorney General within 15 days of notifying consumers when more than 500 residents are affected. Cyber liability insurance commonly funds the forensics, legal review, and notification costs this statute drives, plus defense of regulatory and civil claims.

Consumer notification deadline
In the most expedient time possible and without unreasonable delay, and not later than 30 calendar days after discovery or notification of the breach
Regulator notice
Submit a copy of the notification to the California Attorney General within 15 days of notifying residents when a single breach requires notice to more than 500 California residents.
Safe harbor
Notification is not required if the compromised data was encrypted and the encryption key or security credential was not acquired.
Enforcement
Affected residents may bring a civil action to recover damages, and the Attorney General may seek injunctive relief for violations.

Statutes and sources

  • California Data Breach Notification Law

    Cal. Civ. Code sect. 1798.82

Regulator: California Attorney General . Last verified 2026-07-29 from the official source .

Get California coverage handled

Share a few details and an agent will respond within one business day.