California - Session 2025-2026
Title: Data breaches: customer notification.
Existing law requires an individual or a business that conducts business in California, and that owns or licenses computerized data that includes personal information, to disclose a breach of the security of the system following discovery or notification of the breach in the security of the data to a resident of California whose unencrypted personal information was compromised, as specified, and requires that disclosure to be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement, as specified, or any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system. This bill would require that data breach disclosure to be made within 30 calendar days of discovery or notification of the data breach but would authorize an individual or business to delay the disclosure to accommodate the legitimate needs of law enforcement, as specified, or as necessary to determine the scope of the breach and restore the reasonable integrity of the data system. Existing law also requires an individual or business that is required to issue the security breach notification described above to more than 500 California residents as a result of a single breach of the security system to electronically submit a single sample copy of that security breach notification, excluding any personally identifiable information, to the Attorney General. This bill would require that submission to the Attorney General to be made within 15 calendar days of notifying affected consumers of the security breach.
Tracking state legislation? Support LegiList with a small contribution. Independent, ad-free, and built by one developer.
| Date | Event | Detail |
|---|---|---|
| 2025-02-18 | Introduced | Bill introduced |
| 2025-10-03 | Status | enacted |
| 2025-10-03 | Latest Action | Chaptered by Secretary of State. Chapter 319, Statutes of 2025. |
| Bill | Title | Status |
|---|---|---|
| AB 2795 | Financial institutions: franchises, state funds, and securities. | in_committee |
| AB 1598 | Behavioral sciences. | in_committee |
| AB 1603 | Perfluoroalkyl and polyfluoroalkyl substances (PFAS): Department of Pesticide Regulation. | in_committee |
| AB 1609 | Customer service chatbots. | in_committee |
| AB 1659 | Juvenile court school pupils: joint transition planning policy: courses of study. | in_committee |
| AB 1677 | Public utilities: electrical and gas corporations: return on equity. | in_committee |
| AB 1679 | Local pop-up business program. | in_committee |
| AB 1715 | Public utilities: reporting. | unknown |