Employee Rights
What to Do if You Receive a Data Breach Letter in California
Reviewed by Michael Nourmand, a California-admitted attorney who handles the firm’s data breach and consumer privacy matters. Last updated July 28, 2026.
A data breach letter is the notice a California business is required to send after it exposes your personal information, and the firm’s California data breach practice covers how the resulting claims work, from the elements to the damages. The letter itself, though, rarely explains what to do next. Opening an envelope to learn that a company lost control of your Social Security number or medical records is unsettling, and it is easy to file the notice away and forget it.
A Quick Reference Guide to California Data Breach Letters
A California business must tell you within 30 calendar days when your unencrypted personal information is exposed, under Cal. Civ. Code § 1798.82, and that notice is often the first sign you may have a legal claim.
- What the letter is: A legally required notice that a business’s system exposed your personal information, not proof that your identity has been misused.
- Governing law: The breach-notification statute, § 1798.82, and the consumer private right of action, Cal. Civ. Code § 1798.150.
- Key deadline: A business must send notice within 30 calendar days of discovery under Senate Bill 446, effective January 1, 2026; your own time to sue depends on the claim.
- What a claim can be worth: Statutory damages of $100 to $750 per consumer per incident under § 1798.150, with no proof of financial loss required.
- First move: Place a free credit freeze and keep the letter, and do not sign away legal rights to accept the monitoring it offers.
- Where to verify it: Breaches affecting more than 500 California residents are reported to the state Attorney General and posted on a public list.
The data breach attorneys at The Nourmand Law Firm review breach notices for consumers and workers throughout California, from Los Angeles to the Central Valley.
That is the wrong instinct. A breach notice is the moment California law expects you to act, both to protect your identity and to preserve any claim you may have against the business that failed to safeguard your information. The Nourmand Law Firm reviews California breach notices at no charge and represents the people whose data was exposed, never the companies that lost it. This guide walks through what the letter means, the deadlines attached to it, and the steps worth taking in the days that follow.
What Is a Data Breach Notification Letter?
A data breach notification letter is a disclosure a business is legally required to send after it learns that personal information in its care was accessed by someone not authorized to have it. Under Cal. Civ. Code § 1798.82, the duty is triggered when unencrypted personal information is acquired in a breach, and the statute defines the covered information to include a name combined with a Social Security number, a driver’s license or state identification number, a financial account number, medical information, or health insurance information. When those elements are exposed, the business must notify each affected California resident.
The letter usually describes the incident in general terms, states the categories of information involved, and offers a period of free credit monitoring. What it does not do is explain your legal options, and it often reads as if enrolling in monitoring closes the matter. It does not. The notice connects the firm’s employment and consumer practice to your situation, because the same businesses that hold worker and customer data are the ones sending these letters.
What Does the Letter Mean for Your Legal Rights?
A breach notice can be the first evidence of a claim, because California is one of the few states that gives consumers a direct right to sue over a breach. Under Cal. Civ. Code § 1798.150, a consumer may recover statutory damages of $100 to $750 per incident, or actual damages if greater, when nonencrypted personal information is exposed because a business failed to maintain reasonable security. The claim does not require proof that money was lost, which is why a letter alone can matter.
Receiving a letter does not by itself decide whether a claim exists, but it starts the analysis. What information was exposed, whether the business had reasonable security in place, and how the breach happened all shape the case. Because a single breach can affect hundreds of thousands of Californians at once, these matters frequently proceed as class actions rather than individual suits.
What Deadlines Apply After a Data Breach Letter?
Two clocks matter, and they run in opposite directions. The business is under its own deadline: Senate Bill 446, effective January 1, 2026, requires notice within 30 calendar days of discovering or being notified of a breach, a firmer rule than the earlier standard of notice without unreasonable delay. A letter that arrives long after the incident can itself be a sign the business did not meet its duty.
The reader’s clock is the one to watch. Protective steps like a credit freeze should happen immediately, within days rather than weeks. The deadline to bring a legal claim is separate and depends on the theory pleaded, because one breach can support several claims with different limitations periods. For that reason the timing is worth reviewing promptly, rather than waiting to see whether the exposed data is misused first.
What Records Should You Keep After a Data Breach Letter?
Breach cases are proven with records that are easy to discard in the moment, so preservation begins the day the letter arrives. The items below are the ones that decide these matters.
- The letter and its envelope: They fix what the business says was exposed and when it claims to have learned of the breach, which is central to whether the 30-day notice duty was met.
- Every monitoring or settlement offer: Keep the enrollment terms and any document that asks you to agree to arbitration or release claims, because those terms can affect your right to sue.
- Your credit reports and account statements: Pull reports from all three bureaus and save bank, card, and medical statements so any later fraud can be traced back to this exposure.
- Proof of misuse: Fraud alerts, unfamiliar accounts, tax-filing rejections, and unexpected medical bills document real harm that adds to any statutory recovery.
- A running log: Note the hours and out-of-pocket costs spent resolving problems, which are recoverable as actual damages.
How The Nourmand Law Firm Helps After a Data Breach
The Nourmand Law Firm reviews the letter, identifies what information was exposed, and assesses whether the business met its security and notification duties, all before any fee is owed. The firm represents the people whose information was compromised, never the companies that lost it, which is the same consumer-side and worker-side posture it has held for more than 20 years. That experience includes class action recoveries reported between $1.35 million and $7.25 million, the kind of group litigation most large breaches call for. Its record in these matters is set out in the firm’s reported case results.
Cases are handled on a no recovery, no fee basis, so responding to a breach does not add a legal bill to a household already spending time and money to protect itself. The firm serves clients statewide, with particular attention to blue-collar, Central Valley, and Inland Empire communities whose data is collected by employers and vendors.
If a breach notice left you unsure whether it is worth pursuing, The Nourmand Law Firm reviews California data breach letters at no charge and takes cases on a no recovery, no fee basis.
What to Do in the First Days After a Data Breach Letter
The window right after a letter arrives is when a person can do the most to limit the damage and keep their options open. These steps are worth taking in order.
- Read the letter closely. Identify exactly which categories of information were exposed, since a Social Security or financial account number calls for more aggressive steps than an email address alone.
- Freeze your credit. Place a free security freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted for free when you need credit.
- Enroll carefully. Sign up for the offered monitoring, but read the terms first and do not accept language that gives up your right to sue.
- Confirm the breach. Check the California Attorney General’s public list of reported breaches to see the business’s own filing, since breaches affecting more than 500 residents are posted there.
- Watch your accounts. Review bank, card, and medical statements for charges or services you did not authorize, and set fraud alerts.
- Get the timing reviewed. Have the applicable deadlines checked before they pass, especially if you are considering a claim. The firm’s intake is available in English and Spanish.
Frequently Asked Questions About Data Breach Letters
Does a Data Breach Letter Mean My Identity Was Stolen?
No. A notification letter means a business believes your personal information was exposed, not that it has been misused. Exposure and identity theft are different stages. California law requires notice at the exposure stage precisely so a person can act before misuse occurs, which is why a freeze and monitoring matter even when nothing has gone wrong yet.
Should I Accept the Free Credit Monitoring Offered in the Letter?
Enrolling in monitoring is usually worthwhile, but read the terms first. Some offers ask the recipient to agree to arbitration or to release claims in exchange for the service. Accepting monitoring should not require giving up the right to sue, and the enrollment terms should be reviewed before clicking accept.
How Long Do I Have to Act After a Data Breach Letter?
Protective steps like a credit freeze should happen right away. The deadline to bring a legal claim depends on the theory pleaded, because one breach can support several claims with different limitations periods, so the timing should be reviewed promptly rather than left until misuse appears.
What if the Letter Says the Data Was Encrypted?
Encryption can limit a business’s duties, but not always. Under Civil Code section 1798.82, notice is still required where the encryption key or credential is believed to have been taken along with the data. The private right of action under section 1798.150 turns on nonencrypted, nonredacted information, so whether data was truly protected is a fact worth confirming.
Related Practice Areas
- Consumer class actions, the group-litigation framework most large data breach cases use to hold a company accountable to everyone it harmed at once.
- Identity theft and consumer fraud, for recovering losses when exposed data is used to open accounts or file fraudulent claims.
- Workplace data and employee privacy, covering breaches of payroll, benefits, and HR records held by employers and their vendors.
A data breach letter is worth acting on, and reviewing it costs nothing. The Nourmand Law Firm represents the California consumers and workers whose information was exposed, not the companies that failed them, statewide and in English and Spanish, on a no recovery, no fee basis with a free consultation. Call 800-700-WAGE (9243) or reach the firm through its contact page to have your breach notice reviewed.











