Super Lawyers - Michael Nourmand
Best Lawyers
Super Lawyers - James A. De Sario
Consumer Attorneys
Lawyers of Distinction
Consumer Attorneys of California
Daily Journal
Los Angeles County Bar Association
Newsweek Showcase
Newsweek Top Attorneys

California’s New 30-Day Data Breach Notification Deadline

The Nourmand Law Firm, APC

Last updated July 28, 2026 · Reviewed by Michael Nourmand

A California law that took effect January 1, 2026 now requires businesses to disclose a data breach within 30 calendar days of discovering it, replacing an older standard that let companies take as long as they reasonably needed. Senate Bill 446 amended the state’s breach-notification statute, Cal. Civ. Code § 1798.82, and the change reaches anyone whose personal information a California business collects or holds.

The practical effect is a faster warning. A company that discovers a breach now has a fixed 30-day window to notify each affected California resident, so a notice that arrives months after an incident is a sign the business may have missed its legal deadline. That timing also shapes your options, because California is one of the few states that lets a consumer sue over a breach directly.

What Senate Bill 446 Changed for California Breach Notices

A data breach notification is the letter or email a business must send when it learns that unencrypted personal information in its systems was accessed by someone not authorized to see it. Before Senate Bill 446, § 1798.82 required that notice go out “in the most expedient time possible and without unreasonable delay,” a standard vague enough that some companies waited months. The amended statute sets a hard number.

Under Senate Bill 446, effective January 1, 2026, a California business that discovers a data breach must notify each affected resident within 30 calendar days. Limited extensions still exist where law enforcement asks a company to hold notice, or where the business needs time to identify who was affected, but the default is now a firm deadline rather than an open one. The Nourmand Law Firm represents California consumers and workers whose personal information is exposed in these breaches, and the firm’s California data breach practice explains how the resulting claims work.

Why Does a Late Data Breach Letter Matter Now?

The deadline gives the notice letter a second job. It has always told you what was exposed, but under the new rule its timing also shows whether the business complied with the law. A letter dated well beyond 30 days after the company learned of the breach raises a direct question about whether the notification duty was met, and that question can support a claim on its own.

Late notice compounds the harm, which is the reason the Legislature tightened the rule. Every extra week that a person does not know their Social Security or financial account number is circulating is a week they cannot place a credit freeze, watch their accounts, or catch fraud early. The 30-day deadline exists to close that gap, and a business that ignores it leaves its customers and employees exposed for longer than California law now allows.

What Can You Recover After a California Data Breach?

Notification is only part of the picture. Under Cal. Civ. Code § 1798.150, a consumer whose nonencrypted personal information is exposed because a business failed to maintain reasonable security may recover statutory damages of $100 to $750 per incident, or actual damages if they are greater. The claim does not require proof that any money was lost, which is why exposure alone can matter.

Because a single breach usually affects thousands or hundreds of thousands of Californians at once, these cases often proceed as class actions rather than individual suits. The Nourmand Law Firm has recovered between $1.35 million and $7.25 million in past class action cases, and it applies that group-litigation experience to breaches that expose large California populations. Cases are handled on a no recovery, no fee basis.

What Should You Do When a Breach Notice Arrives?

Treat the letter as a prompt to act, not a formality to file away. The most important steps happen in the first days, while the exposed information is fresh and the deadlines are still open. The detailed sequence, from placing a credit freeze to preserving the letter, is set out in the firm’s guide on what to do after a data breach letter.

Two moves are worth doing immediately. Place a free security freeze with all three credit bureaus, which blocks new accounts from being opened in your name. Then confirm the incident against the California Attorney General’s public breach list, where breaches affecting more than 500 residents are posted, so you can see the company’s own account of what happened and when.

Questions About California’s New Breach Notice Deadline

How Soon Must a California Business Report a Data Breach?

Within 30 calendar days of discovering the breach, under Senate Bill 446 and Cal. Civ. Code § 1798.82, effective January 1, 2026. Narrow extensions apply for law enforcement or to determine the scope of the breach, but the earlier open-ended “without unreasonable delay” standard no longer controls.

Does a Breach Notice Mean I Automatically Have a Case?

No. A notice means your information was exposed, not that a claim is guaranteed. Whether one exists turns on what data was involved and whether the business maintained reasonable security. Under Cal. Civ. Code § 1798.150, a consumer can sue when nonencrypted personal information is exposed through that kind of security failure.

How Much Can I Recover if My Information Was Breached?

Statutory damages run from $100 to $750 per consumer per incident under Cal. Civ. Code § 1798.150, or actual damages if they are greater. No proof of an out-of-pocket loss is required for the statutory amount, and documented losses such as fraud and credit repair can be recovered on top.

Contact The Nourmand Law Firm About a Breach Notice

If you received a data breach letter, or learned that a company holding your information was breached, The Nourmand Law Firm can review the notice and the timing at no charge. The firm represents the California consumers and workers whose data was exposed, never the businesses that lost it, and works in English and Spanish. Contact The Nourmand Law Firm at 800-700-WAGE (9243) or through its contact page to have your situation reviewed on a no recovery, no fee basis.

Client Reviews

When I was fired, my employer failed to pay me all the wages that I earned. I hired The Nourmand Law Firm, they did the best and resolved my case very fast. I highly recommend them, they know what they are doing.

A.G.

I am very grateful to the attorneys because they helped me quickly and always kept me informed in every aspect of my case. I would recommend them to other people.

E.S.

Thank you very much for getting me a great settlement. You guys are the best. I will give your number out to anyone who ask me if I know any good lawyers. G-D bless you and have a merry Christmas and a bless new year.

T.W.

Contact Us

  1. 1 Free Consultation
  2. 2 No Recovery, No Fee
  3. 3 Se Habla Español
Fill out the contact form or call us at 800-700-WAGE (9243)  to schedule your free consultation.

Get In Touch