15.3 Cure Periods and Penalties

Key Takeaways

  • A right-to-cure is a statutory pause: the attorney general (or, in California’s limited PRA, the consumer) must give notice and a period — often 30 days — to fix the violation before a penalty action proceeds
  • Oregon’s 30-day Oregon Consumer Privacy Act cure expired 1 January 2026; the Oregon Department of Justice now states the Attorney General may proceed directly to a civil investigative demand or lawsuit
  • California has no general cure for CPRA administrative enforcement by the CPPA or the Attorney General; Civil Code § 1798.150 still gives a 30-day notice-and-cure only before certain security-incident private actions, and implementing security after a breach is not a cure
  • Virginia-style comprehensive laws commonly authorize the attorney general — and only the attorney general — to seek about $7,500 per violation after a standing 30-day cure; Indiana and Kentucky, effective 1 January 2026, follow that pattern
  • Who sues is the other half of the question: most comprehensive state laws are attorney-general-only; California adds CPPA administrative fines ($2,500 / $7,500) and a $100–$750 CCPA security PRA; MHMD and GIPA add private rights
Last updated: August 2026

What a Cure Period Actually Is

A right to cure is not forgiveness and not a statute of limitations. It is a mandatory or discretionary pause: the enforcer must tell the controller which provisions it thinks were violated and give a fixed number of days to fix them and, usually, to send back an express written statement that the violation has been cured. If the controller cures in time, the penalty action does not launch. If it does not cure, or if it breaches the written statement, the attorney general files. CIPP/US tests three things: whether a cure still exists in 2026, how long it is, and who gets to sue after it runs.

Cure periods were a political compromise in the first wave of comprehensive state privacy laws. They are not immortal. Several sunsets were written into the statutes on purpose. Studying a 2023 outline that still lists “Oregon 30 days” as current law is an exam miss.

Oregon’s Sunset — Official as of 2026

The Oregon Consumer Privacy Act (OCPA), ORS 646A.570–646A.589, originally required the Attorney General to give controllers a 30-day notice and opportunity to cure. That provision expired 1 January 2026. The Oregon Department of Justice’s official business FAQ is blunt: as of 1 January 2026, the Attorney General is no longer required to give controllers notice and an opportunity to cure regardless of the nature of the OCPA violation, and the Attorney General can proceed directly to an enforcement action such as serving a civil investigative demand or filing a lawsuit. Official page: https://www.doj.state.or.us/consumer-protection/for-businesses/privacy-law-faqs-for-businesses/.

The OCPA still has no private right of action. Losing the cure does not create one. It means the first letter from Salem can be a demand, not a coaching memo. The same 1 January 2026 package (Oregon HB 2008) also turned on universal-opt-out recognition, an under-16 sale ban, and a precise-geolocation sale restriction. Do not collapse those amendments into “Oregon just lost its cure.” They are separate 2026 facts.

California: No General Administrative Cure; a Narrow PRA Cure

California is the other sunset story, and it is older. The original CCPA gave the Attorney General a 30-day cure before an administrative action. That general administrative cure sunset 1 January 2023. The California Privacy Rights Act (CPRA) did not restore a general cure for California Privacy Protection Agency (CPPA) or Attorney General enforcement. As of 2026 there is no “we have 30 days after every CPPA letter” rule.

Administrative money is still large. Cal. Civ. Code § 1798.155 authorizes an administrative fine of not more than $2,500 for each violation, or $7,500 for each intentional violation or each violation involving the personal information of consumers whom the business has actual knowledge are under 16. Those fines are per violation, and “violation” is not defined as “per company, per year.”

Consumers still cannot sue for a missed access request or a broken “Do Not Sell or Share” link. The only CCPA private right of action is § 1798.150, and it is a security claim. A consumer whose nonencrypted and nonredacted personal information — using the tight § 1798.81.5 definition, not the full CCPA definition — is subject to unauthorized access and exfiltration, theft, or disclosure as a result of the business’s failure to implement reasonable security procedures and practices may sue for the greater of actual damages or statutory damages of $100 to $750 per consumer per incident, plus injunctive or declaratory relief.

Before filing that PRA, the consumer must give the business 30 days’ written notice identifying the specific statutory provisions. If the violation can actually be cured and the business cures it within 30 days and provides an express written statement that the violations have been cured and that no further violations will occur, the consumer may not bring an action for statutory damages. Two limits matter. First, this cure is only for the § 1798.150 lawsuit. It is not a general CPRA administrative cure. Second, the statute says that implementation and maintenance of reasonable security procedures and practices following a breach does not constitute a cure with respect to that breach. Turning encryption on after the laptop is gone does not erase the PRA.

Virginia-Style $7,500 and Attorney-General-Only Suits

The Virginia Consumer Data Protection Act (VCDPA), Va. Code § 59.1-584, is the template a dozen later statutes copied. The Attorney General has exclusive authority to enforce. Nothing in the chapter creates a private right of action. Before initiating an action, the Attorney General must provide a controller or processor 30 days’ written notice identifying the specific provisions alleged to have been violated. If the controller cures and provides an express written statement, the action stops. If it does not, the Attorney General may seek an injunction and civil penalties of up to $7,500 for each violation. Virginia’s Attorney General restated that 30-day cure and $7,500 figure in an official March 2026 consumer-rights release. Virginia’s cure is a standing cure, not a sunset.

IAPP’s 5 January 2026 state-law roundup is the official study pointer for the three comprehensive laws that became applicable that day. Indiana and Kentucky follow the Virginia coverage thresholds and include a 30-day cure and the usual attorney-general enforcement package. Rhode Island is the contrast case in that same IAPP piece: among the “most glaring items not included” are recognition of universal opt-out mechanisms, enhanced children’s provisions, and the right to cure. Official IAPP news: https://iapp.org/news/a/new-year-new-rules-us-state-privacy-requirements-coming-online-as-2026-begins.

Iowa still uses a longer 90-day cure. Utah and Texas still use standing 30-day cures. Connecticut’s 60-day cure expired 1 January 2025. Colorado’s earlier 60-day opportunity, which applied only if the Attorney General determined a cure was possible, is no longer a mandatory standing right. Treat those as archetypes, not as a claim that a third-party “20-state chart” is itself an official text.

Who Sues — The Other Half of Every Penalty Question

Penalty math is useless if you name the wrong plaintiff.

Archetype (as of August 2026)ExampleCureWho suesMoney
Standing 30-day AG cureVirginia VCDPA; Indiana and Kentucky (effective 1 Jan 2026)30 days after AG notice, still in forceAttorney general onlyAbout $7,500 per violation
Longer standing cureIowa90 daysAttorney general onlyStatute-specific civil penalty
Sunset / expiredOregon OCPA (30-day expired 1 Jan 2026); Connecticut (60-day expired 1 Jan 2025)None remainingAttorney general onlyOregon proceeds under its enforcement / unlawful-trade-practices tools
Never / no general administrative cureCalifornia CPRA administrative; Rhode Island (IAPP: no cure in the statute)None for agency enforcementCPPA and California AG; Rhode Island AGCalifornia $2,500 / $7,500; other states vary
Limited consumer-PRA cureCal. Civ. Code § 1798.15030-day written notice before a security PRA; post-breach security is not a cureConsumer (security incident only)$100–$750 per consumer per incident
Sectoral private right, no comprehensive-law cureMHMD via Washington CPA; Illinois GIPANot a VCDPA-style cureConsumer / classCPA remedies; GIPA $2,500 / $15,000

Scenario A. A controller ignores Oregon opt-out requests in March 2026. The Department of Justice is not required to send a 30-day cure letter first. It may issue a civil investigative demand or sue. Oregon consumers still cannot file an OCPA class action.

Scenario B. The same company’s unencrypted California driver’s-license file is exfiltrated because it never encrypted laptops. The CPPA can open an administrative matter with no general cure clock. Separately, each affected California consumer can send a § 1798.150 notice. Buying disk encryption on day 10 does not cure that breach. Statutory exposure is $100 to $750 per consumer per incident if the PRA elements are met.

Scenario C. A Virginia controller gets a 30-day VCDPA notice in 2026, fixes the dark-pattern opt-out flow, and sends the express written statement. The Attorney General does not file. A Virginia resident still has no private VCDPA claim.

Exam traps

  • Oregon’s 30-day cure is gone as of 1 January 2026. Do not recite it as current law.
  • California’s $100–$750 figure is a consumer security PRA, not the CPPA’s administrative fine table.
  • Implementing security after a California breach is expressly not a § 1798.150 cure.
  • “$7,500 per violation” is the Virginia-style attorney-general civil penalty. It is not a consumer checkbook and not California’s only number.
  • Most comprehensive state laws remain attorney-general-only. Private rights live in California’s narrow security PRA and in sectoral statutes such as MHMD and GIPA.
Loading diagram...
2026 Cure and Penalty Archetypes
Test Your Knowledge

A controller that meets the Oregon Consumer Privacy Act thresholds receives no advance letter and is served with a civil investigative demand in March 2026 for alleged opt-out failures. Which statement is correct?

A
B
C
D
Test Your Knowledge

After an unencrypted theft of California driver’s-license numbers, affected consumers send the 30-day notice required by Cal. Civ. Code § 1798.150. On day 12 the business encrypts its remaining laptops and argues the claim is cured. The CPPA also opens an administrative investigation. Which statement is correct?

A
B
C
D
Test Your Knowledge

A Virginia controller receives a VCDPA notice of violation from the Attorney General in 2026. Separately, a Virginia resident wants to file a class action for the same alleged sale-without-opt-out. Which statement matches Va. Code § 59.1-584?

A
B
C
D