Breach notification

Cal. Civ. Code §§ 1798.29, 1798.82

California data breach notification statute

In force since July 1, 2003

Who it applies to

  • Any person or business that conducts business in California and owns or licenses computerised personal information
  • State agencies, under the parallel § 1798.29

Consumer rights

  • Access / know — not granted
  • Correction — not granted
  • Deletion / erasure — not granted
  • Portability — not granted
  • Opt out of sale / sharing — not granted
  • Opt out of targeted advertising — not granted
  • Opt out of profiling — not granted
  • Limit sensitive data use — not granted
  • Human review of automated decisions — not granted
  • Non-discrimination — not granted
  • Appeal a refusal — not granted
  • Private right of action — grantedSue directly, rather than relying on a regulator to enforce on your behalf.

Obligations

Consent model
Opt-out
Universal opt-out signal
Not required
Risk assessments
Not required
Data protection officer
Not required
Records of processing
Not required
Processor contract
Not required
Right to cure
None — enforcement may follow immediately
Data broker registration
Not required

Breach notification

To individuals
In the most expedient time possible and without unreasonable delay, consistent with the needs of law enforcement
To the regulator
A single sample copy of the notice to the Attorney General where more than 500 Californians are notified
What triggers it
Unauthorised acquisition of unencrypted computerised personal information — name plus an identifier such as SSN, licence number, financial account, medical or health-insurance information, or biometric data

Penalties

Headline
Civil action by affected individuals; injunctive relief
Private right of action
Yes — individuals can sue directly
Notes
A customer injured by a violation may bring a civil action to recover damages; any business that violates the section may be enjoined.

Exemptions

Data

  • Data encrypted where the encryption key was not also acquired

Amendment history

  1. January 1, 2016

    Encryption and content requirements

    Added a prescribed notice format and clarified the treatment of encrypted data whose key was also compromised.

Sources

Timeline

todayBreach notification in forceJuly 1, 2003Encryption and content requirementsJanuary 1, 2016