17.2 Common Breach-Notification Elements
Key Takeaways
- A typical state breach statute keys off “personal information”: a resident’s first name or first initial and last name plus a data element (Social Security number, driver’s license, financial account with access code), now commonly expanded to medical information, health-insurance information, unique biometrics, tax or other government ID, and username-or-email plus password
- A “breach of the security of the system” is usually unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of that personal information; good-faith employee acquisition is commonly carved out if there is no further unauthorized use
- Notice runs to residents of that state, most expeditiously and without unreasonable delay; Cal. Civ. Code § 1798.82, as amended by SB 446 effective 1 January 2026, now requires disclosure within 30 calendar days of discovery or notification, subject to law-enforcement and scope/restore delays
- How-to-notify is a three-lane menu — written, electronic (E-SIGN-consistent), or substitute when cost, headcount, or missing contact data hits the statute’s math — and California’s letter must be titled “Notice of Data Breach” and use the statutory headings
- A second wave of notices is often required: a sample copy to the attorney general above a resident headcount (California: more than 500 residents, within 15 calendar days of notifying consumers), consumer-reporting-agency notice above a higher headcount in many states, and, in California, at least 12 months of identity-theft services when the business was the source and Social Security or government-ID numbers were exposed
The Common Skeleton
Every U.S. state now has a breach-notification statute. Body of Knowledge V.C PI1 tests the shared elements, not a fifty-state spreadsheet. Build every analysis in the same order: what counts as personal information, what counts as a breach, who must be told, when, how, what the letter must say, and who else (attorney general, consumer-reporting agencies, the data owner) gets a copy. California Civil Code § 1798.82 — as amended by Senate Bill 446, effective 1 January 2026 — is the exam’s working prototype because it is detailed, current, and official: https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=1798.82.
What Is “Personal Information” for Notice?
Breach “personal information” is not the full California Consumer Privacy Act (CCPA) “personal information” universe and is not HIPAA protected health information (PHI) unless the facts fit. The classic formula is a resident’s first name or first initial and last name, in combination with one or more data elements, when the name or the elements are not encrypted or redacted:
- Social Security number
- Driver’s license or state identification number
- Financial account, credit-card, or debit-card number plus any required access code or password
Statutes have expanded. California § 1798.82(h) now also lists tax identification number, passport number, military identification number, or another unique government ID commonly used to verify identity; medical information; health-insurance information; unique biometric data used to authenticate (a photograph is in only if used or stored for facial recognition); automated license-plate-recognition data; and genetic data. A second, name-free path treats a username or email address plus a password or security question and answer that would permit access to an online account as personal information by itself.
Publicly available government-record information is usually out. The exam trap is using the comprehensive-law definition of personal data to decide whether a breach letter is due. A hashed email used for ads can be CCPA personal information and still fail the breach statute’s name-plus-element (or credential) test.
What Is a “Security Breach”?
California’s definition is the common one. “Breach of the security of the system” means unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information. Good-faith acquisition by an employee or agent for a legitimate purpose is not a breach if the information is not used or subject to further unauthorized disclosure.
Two forks matter immediately.
Acquisition versus harm. California, like many states, is an acquisition-is-enough statute: if unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person, notice is due. Some states, including Utah, still ask whether misuse for identity theft or fraud has occurred or is reasonably likely — a harm threshold. Chapter 17.3 is where that split is tested by name.
Encryption and redaction. If the data were encrypted to the statute’s standard and the encryption key or security credential was not acquired, the incident often falls outside the notice duty. California now says so twice: unencrypted acquisition triggers notice, and encrypted acquisition also triggers notice if the key was taken and the owner reasonably believes the key could render the information readable. Encryption is a notice safe harbor. It is not a finding that security was reasonable, and it is not a defense to every comprehensive-law claim.
Who Must Be Told?
The primary audience is residents of that state whose personal information was, or is reasonably believed to have been, acquired. A national retailer does not send one federal consumer letter and stop. It maps the file to each state’s resident list. There is still no generally applicable federal consumer-breach statute for ordinary commercial databases; HIPAA, GLBA, and the FTC Safeguards Rule are sectoral overlays, not a fifty-state substitute.
A vendor that maintains data it does not own typically notifies the owner or licensee immediately, not the residents. California § 1798.82(b) is the model. The owner then decides resident notice. That third-party rule is an element of PI1 and a difference tested again in PI2.
When: “Without Unreasonable Delay,” Plus California’s 30 Days
The traditional timing phrase is most expediently / without unreasonable delay, consistent with the legitimate needs of law enforcement and the time needed to determine the scope of the breach and restore the reasonable integrity of the system. Many states have added a fixed outer bound (often 30, 45, or 60 days).
Verify California against the current code, not a 2018 outline. SB 446 amended § 1798.82 effective 1 January 2026. Subdivision (a)(2)(A) now says the disclosure “shall be made within 30 calendar days of discovery or notification of the data breach.” Subdivision (a)(2)(B) still allows delay to accommodate law enforcement under subdivision (c), or as necessary to determine the scope of the breach and restore the reasonable integrity of the data system. Law-enforcement delay lasts only until the agency determines that notice will not compromise the investigation. The old open-ended “without unreasonable delay” sentence is no longer the whole California clock.
HIPAA remains a different clock: notice to affected individuals without unreasonable delay and no later than 60 days; 500 or more individuals → the Secretary of Health and Human Services without unreasonable delay / ≤60 days; fewer than 500 → the annual HHS log; 500 or more residents of a state → media. Do not import the HIPAA 60-day figure into § 1798.82.
How: Written, Electronic, Substitute
California § 1798.82(j) is the national template.
- Written notice.
- Electronic notice consistent with the federal E-SIGN Act, 15 U.S.C. § 7001.
- Substitute notice if the business demonstrates that the cost would exceed $250,000, that the affected class exceeds 500,000, or that it lacks sufficient contact information. Substitute notice is all of: email where an address exists, conspicuous website posting for at least 30 days, and notice to major statewide media.
Two credential-specific lanes sit beside that menu. If only online-account credentials (not name-plus-element data) were taken, the business may send an electronic notice that tells the resident to change the password and protect other accounts that reuse it. If the breached credentials are for an email account the business itself furnishes, the business may not send the notice to that same email address.
A business that already has notification procedures in its information-security policy is deemed compliant if those procedures meet the statute’s timing rules. That is not a license to ignore the 30-day clock.
What the Letter Must Say — and Who Else Gets a Copy
California’s letter must be in plain language, titled “Notice of Data Breach,” no smaller than 10-point type, and must present the required facts under the headings “What Happened?”, “What Information Was Involved?”, “What We Are Doing,”, “What You Can Do,”, and “For More Information.” Minimum content includes the business’s name and contact information; the types of personal information involved; the date, estimated date, or date range of the breach if it can be determined, plus the date of the notice; whether notice was delayed for law enforcement; a general description of the incident; and, if a Social Security number or a driver’s-license or California identification number was exposed, the toll-free numbers and addresses of the major credit-reporting agencies. If the notifying business was the source of the breach and the exposed data include the Social Security or government-ID elements in (h)(1)(A)–(B), it must offer appropriate identity-theft prevention and mitigation services at no cost for not less than 12 months, with everything the resident needs to enroll.
Attorney-general notice. If a single incident requires notice to more than 500 California residents, the business must electronically submit a single sample copy of the notice, stripped of personally identifiable information, to the California Attorney General within 15 calendar days of notifying affected consumers. That 15-day AG clock is new with SB 446. It is not the same as the 30-day resident clock.
Consumer-reporting-agency notice. Many states require a separate notice to nationwide consumer-reporting agencies (CRAs) once a headcount — often 1,000 residents — is crossed. California’s prototype instead puts CRA contact data in the resident letter. Utah’s later amendment, taught in 17.3, is a clean 1,000-resident CRA trigger.
Private right of action and credit monitoring are not universal. California’s § 1798.150 security PRA ($100–$750 per consumer per incident after a 30-day PRA notice) is a comprehensive-law / reasonable-security claim, not an automatic add-on to every § 1798.82 letter. Other states may require or encourage credit monitoring; many do not create a consumer lawsuit at all.
Scenario. On 2 February 2026 a retailer discovers that an attacker exported an unencrypted file of California names plus driver’s-license numbers. The key was never at issue because the file was plaintext. Resident letters are due within 30 calendar days of 2 February unless a documented law-enforcement or scope/restore delay applies. The letter uses the statutory title and headings, lists driver’s-license numbers as the data element, and offers 12 months of identity-theft services because the retailer was the source and a government ID was exposed. If 620 California residents are affected, a sample copy goes to the Attorney General within 15 calendar days of sending the resident letters. Encrypting the database on 10 February does not erase the notice duty and does not cure a § 1798.150 claim.
Exam traps
- Breach “personal information” is the tight name-plus-element (or credential) definition, not the full CCPA definition.
- California’s resident clock is now 30 calendar days, not an unbounded “reasonableness” slogan.
- The Attorney General sample is due 15 days after consumer notice, and only when more than 500 California residents are notified.
- Encryption defeats notice only if the key was not taken.
- A vendor generally notifies the owner, not the residents.
A retailer discovers on 3 March 2026 that unencrypted names and California driver’s-license numbers of 620 California residents were exported. There is no law-enforcement hold. Which timing statement matches current Cal. Civ. Code § 1798.82?
Which description of how and what to tell California residents matches § 1798.82?
A cloud vendor that does not own a hospital’s patient-billing file learns that an attacker copied the file. The file contained names and Social Security numbers. The vendor’s incident-response plan says “send California resident letters ourselves because we hold the servers.” Which statement is correct under the common state-law model reflected in § 1798.82?