Breach notification
Cal. Civ. Code §§ 1798.29, 1798.82California data breach notification statute
In force since July 1, 2003
Who it applies to
- Any person or business that conducts business in California and owns or licenses computerised personal information
- State agencies, under the parallel § 1798.29
Consumer rights
- Access / know — not granted
- Correction — not granted
- Deletion / erasure — not granted
- Portability — not granted
- Opt out of sale / sharing — not granted
- Opt out of targeted advertising — not granted
- Opt out of profiling — not granted
- Limit sensitive data use — not granted
- Human review of automated decisions — not granted
- Non-discrimination — not granted
- Appeal a refusal — not granted
- Private right of action — grantedSue directly, rather than relying on a regulator to enforce on your behalf.
Obligations
- Consent model
- Opt-out
- Universal opt-out signal
- Not required
- Risk assessments
- Not required
- Data protection officer
- Not required
- Records of processing
- Not required
- Processor contract
- Not required
- Right to cure
- None — enforcement may follow immediately
- Data broker registration
- Not required
Breach notification
- To individuals
- In the most expedient time possible and without unreasonable delay, consistent with the needs of law enforcement
- To the regulator
- A single sample copy of the notice to the Attorney General where more than 500 Californians are notified
- What triggers it
- Unauthorised acquisition of unencrypted computerised personal information — name plus an identifier such as SSN, licence number, financial account, medical or health-insurance information, or biometric data
Penalties
- Headline
- Civil action by affected individuals; injunctive relief
- Private right of action
- Yes — individuals can sue directly
- Notes
- A customer injured by a violation may bring a civil action to recover damages; any business that violates the section may be enjoined.
Exemptions
Data
- Data encrypted where the encryption key was not also acquired
Amendment history
January 1, 2016
Encryption and content requirements
Added a prescribed notice format and clarified the treatment of encrypted data whose key was also compromised.
Sources
- PrimaryStatuteCal. Civ. Code § 1798.82 — breach notification
- PrimaryBreach registryAttorney General — reported California data breaches