California
For California, statute citation is Cal. Civ. Code § 1798.82; individual notice deadline is within 30 calendar days of discovery or notification of the data breach; individual notice hard deadline (days) is 30; ag / regulator notice deadline is within 15 calendar days of notifying affected consumers of the security breach; ag notice resident-count trigger is 500 California residents, recorded from its source on 2026-08-18.
- State
- California verified
- Statute citation
- Cal. Civ. Code § 1798.82
- Individual notice deadline
- within 30 calendar days of discovery or notification of the data breach
- Individual notice hard deadline (days)
- 30 our reading
- AG / regulator notice deadline
- within 15 calendar days of notifying affected consumers of the security breach verified
- AG notice resident-count trigger
- 500 California residents verified
- Encryption safe harbor
- yes our reading
- Notes
- GLBA-regulated entities and HIPAA-covered entities are not expressly exempted by this section. The safe harbor covers unencrypted personal information — encrypted personal information is outside the definition of breach unless the encryption key was also acquired. our reading
Verified
Review by
Values marked our reading are our classification of what the source says — the source does not print them in those words. The quote below is the evidence for each one; judge it yourself.
What the source says
500 California residents as a result of a single breach of the security system shall electronically submit a single sample copy of that security breach notification, excluding any personally identifiable information, to the Attorney General within 15 calendar days of notifying affected consumers of the security breach.
— leginfo.legislature.ca.gov, retrieved 2026-08-18
Source
- leginfo.legislature.ca.govhttps://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?sectionNum=1798.82.&lawCode=CIV