Looking for a CFO? Learn more here!
All posts

CCPA and CPRA Breach Reporting Guide

Treat breaches as legal and financial events: confirm California coverage, data triggers, timing, vendor duties, and preserve incident records.
CCPA and CPRA Breach Reporting Guide
Copy link

If California resident data is exposed, I need to answer three questions fast: Does California’s breach law apply? What data was involved? And when do notices need to go out?

Here’s the short version:

  • California Civil Code § 1798.82 is the main breach notice rule.
  • CCPA and CPRA add privacy duties and legal risk if a breach ties back to weak security.
  • A company can fall outside CCPA/CPRA and still have to send breach notices under California law.
  • Notice usually turns on whether the exposed data includes items like:
    • Social Security numbers
    • Driver’s license or other government ID numbers
    • Financial account data with access codes
    • Medical or health insurance data
    • Login credentials
    • Biometric data
  • If data was encrypted and the key was not exposed, notice may not be required.
  • If more than 500 California residents get notice, a sample notice must also go to the California Attorney General.
  • Notice must go out “as soon as possible and without unreasonable delay.”
  • If a vendor is hit, I still need to run my own notice analysis and keep a full incident record.
  • Finance (often led by a fractional CFO), legal, and IT should track:
    • discovery date and time
    • response steps
    • legal decisions
    • notice drafts
    • vendor messages
    • breach costs in U.S. dollars

A simple way to think about it: one law drives notice, and the privacy laws add more risk around security and data handling. That means a breach is not just an IT event. It can affect legal exposure, board reporting, deal diligence, and cost tracking.

Quick comparison

Rule What it does Who it can cover
CA Civil Code § 1798.82 Breach notice duty Any person or business that owns, licenses, or maintains certain computerized personal data of California residents
CCPA / CPRA Privacy duties and breach-related liability For-profit businesses doing business in California that meet threshold tests

If I were building a response plan from this guide, I’d keep it simple: check coverage, confirm data type, test for encryption or other exceptions, send notice on time, and preserve every record.

Who Must Report and What Data Triggers Notice

CCPA/CPRA Coverage vs. California Breach Law Coverage

CCPA

After an incident, two separate rules come into play. CCPA/CPRA tells you whether the business falls under California privacy duties. § 1798.82 tells you whether a consumer breach notice must go out. That split matters because it affects notice duties, reserve pressure, and legal exposure.

CCPA/CPRA applies to for-profit businesses doing business in California that collect personal information from California residents and meet at least one of these thresholds in the prior calendar year:[2][6][7][8][9]

  • Annual gross revenue over about $25 million
  • Buying, selling, or sharing personal information of 100,000 or more California consumers or households
  • Getting 50% or more of annual revenue from selling or sharing personal information

§ 1798.82 is much broader. It applies to any person or business that owns, licenses, or maintains computerized personal information of California residents. There is no revenue threshold and no data-volume threshold.[1][3][4][5][10] So even a seed-stage startup that stores California customers' Social Security numbers can still face breach-notice duties under § 1798.82, even if it falls outside CCPA/CPRA.

CCPA/CPRA § 1798.82
Who it covers For-profit California businesses meeting revenue, volume, or data-sale thresholds Any person or business owning, licensing, or maintaining computerized personal information of California residents
Coverage basis Ongoing collection, use, sale, or sharing of personal information Unauthorized access to personal information

There’s one more point that often gets missed. If your company maintains the data but does not own or license it, your duty under § 1798.82 is to notify the data owner or licensee. That party then handles consumer notice.[1][11][5][13]

Once coverage is clear, the next step is simpler: check whether the exposed data fits California’s notice definition.

Personal Information Categories That Trigger Notice

Not every exposure leads to a legal notice duty. Under § 1798.82, "personal information" has a narrower meaning for breach notice. The rule focuses on a person’s first name or first initial and last name combined with one or more of these data elements, when either the name or the element is unencrypted or unredacted:[15][16][17]

  • Social Security number
  • Driver's license number, California ID card number, passport, military ID, or other government ID
  • Financial account, credit card, or debit card number plus any needed security code, access code, or password that allows account access
  • Medical information, including history, condition, or treatment
  • Health insurance information, such as policy number, subscriber ID, or claims data
  • Biometric data used for authentication, like a fingerprint, retina, or iris image
  • Username or email address plus a password or security question and answer that allows access to an online account

That last item matters more than many teams expect. Credentials by themselves can trigger notice. If usernames or email addresses are exposed along with passwords or security-question answers, the incident is reportable.

The practical point is pretty direct: if your systems hold these data types with names, you can have breach-notice exposure under § 1798.82 whether or not the company meets CCPA/CPRA thresholds.[1][3][5][10]

Even then, the analysis doesn’t stop there. Encryption status and the way the access happened can still take notice off the table.

Encrypted Data, Unencrypted Data, and Employee-Access Exceptions

California law gives businesses an encryption safe harbor. If the compromised data was encrypted using security methods generally accepted in the information security field, and the encryption key was not compromised too, notice is generally not required.[1][11][5][12] If the key was also exposed, the data should be treated as unencrypted.[1][5][12]

There’s also an employee-access carveout. Good-faith access by an employee or agent, acting within the scope of their duties, is not a reportable breach unless the data is later used or disclosed in an improper way.[12]

If notice is triggered, the reporting clock starts right away.

When Notice Is Required, Who Gets It, and How Fast You Must Act

Events That Trigger a Reportable Breach

Once the data review and exception check show that notice may be required, move to triage right away. For finance and legal teams, the first issue is simple: does this incident start the notice clock?

Treat unusual network activity, account anomalies, or unauthorized software as possible signs of a breach. At this stage, look at scope, severity, and impact. What systems or records were affected? How far did it spread? What does the business stand to lose?

Some data types carry more notice risk than others. A breach involving Social Security numbers, login credentials, or financial data is more likely to trigger notice than exposure of non-sensitive records. Ransomware needs close review too. In many cases, file encryption and a ransom demand show up alongside data exfiltration. Legal counsel should confirm whether notice is required, who must receive it, and the deadline.

California Timing Rules and Reporting Deadlines

California Civil Code § 1798.82 requires notice as soon as possible and without unreasonable delay. Any delay should last only long enough to confirm the scope of the breach.

Required Notice Content and Recipients

While IT investigates, preserve evidence, document actions, and track approvals. That means:

  • Preserve system memory
  • Avoid rebooting or shutting down affected devices
  • Use secure out-of-band communication channels
  • Document every action with timestamps and authorization details
  • Record who approved each step

The notice itself should state what happened, when it happened, what data was exposed, whether the data was encrypted, and how affected people can protect themselves.

Send notice to affected residents and any other California recipient required by law. Those records then become the backbone of the response workflow that follows.

The Breach Reporting Workflow for Growth-Stage Companies

California Data Breach Response Workflow: 7 Steps for Growth-Stage Companies

California Data Breach Response Workflow: 7 Steps for Growth-Stage Companies

Most growth-stage companies don't have a dedicated privacy team. That's why a clear workflow matters. When the clock starts, people shouldn't be guessing who owns what.

Once notice may be triggered, the focus shifts to execution: who acts, in what order, and what records back it up.

For lean teams, a practical breach response usually moves through seven phases, with named owners across Security/IT, Legal/Privacy, Finance, Executive/Operations, and External Partners[18].

Step-by-Step Response: From Detection to Post-Incident Review

Use seven phases.

Detection and triage begins the moment someone spots unusual activity. Security or your managed service provider checks whether personal information tied to California residents may be involved. Legal should open an incident file right away and mark privileged communications. If California resident data may be involved, move at once to containment and legal hold.

Containment means isolating affected systems, revoking compromised credentials, and blocking malicious traffic while keeping forensic evidence intact.

Forensic investigation looks at what data was accessed, when it happened, who was involved, and whether encryption or redaction protections apply. If you bring in an outside forensic firm, route that work through legal counsel to help preserve privilege over the findings.

Legal analysis is where legal decides whether the incident must be reported under California law and whether any exceptions apply.

Notice drafting and approvals comes next. Legal prepares the notice, and executives sign off on timing, messaging, and escalation.

Remediation focuses on fixing the weak point and tightening controls.

After closure, run a post-incident review with security, legal, finance, and executive leadership. Document what worked, what failed, and what needs to change before the next event.

How to Handle Vendor and Service Provider Breaches

If the source is a cloud vendor, SaaS tool, payroll provider, or payment processor, the company still owns its duties under California law. That includes doing its own California notice analysis, no matter who caused the incident.

Open an internal incident record right away, even if the vendor hasn't given you the full story yet. Ask for a written incident report that covers:

  • Systems affected
  • Categories and approximate number of impacted California residents
  • Whether the data was encrypted
  • The event timeline

Don't assume the vendor will handle consumer notices for you. Unless legal confirms in writing that the vendor's notice meets California's statutory rules, treat consumer notification as your job[19].

Under CCPA/CPRA, service provider and contractor agreements should include breach notice terms and security duties so the business can meet its own legal requirements if a vendor is hit[18][20]. The table below separates business, service provider, and third-party duties[20]:

Role Consumer Notice Responsibility Obligation to Notify Other Parties Use-of-Data Restrictions Typical Cost Responsibility
Business Primary responsibility for notifying affected California residents and, when required, the Attorney General Notify the Attorney General when more than 500 residents are notified Determines purposes and means of processing Notification, remediation, and regulatory costs
Service Provider / Contractor Notify the business promptly after discovery; no direct consumer notices unless contractually required Must notify the business without undue delay Restricted to processing only as directed by the business Depends on contract terms and breach cause
Third Party No direct consumer notice obligation unless separately required Must notify the business if it cannot comply with CCPA/CPRA Subject to contractual and statutory limits on data use Depends on contract terms and facts

For payroll providers, the contract should spell this out clearly: if the breach comes from the vendor's own security failure, the vendor covers reasonable notice and remediation costs. If the incident comes from the company's own misconfiguration, the company remains on the hook. Those terms shape how finance models exposure.

At the same time, finance should begin tracking breach costs under a separate incident code.

As soon as an incident is opened, finance should create a dedicated cost center or project code in the general ledger. Every expense should be tagged to that code from day one, in U.S. dollars, with clear descriptions that tie each entry to the incident ID. Track outside counsel, forensics, notice costs, remediation, recovery, and any settlement or penalty exposure[21][22].

Legal and finance should also co-own the decision log. This should be a dated record of major calls, including when the incident was discovered, when it was classified as reportable, who approved notice language, and when notices were sent. That log needs to support reserves, audit review, and exit diligence[21].

The last piece is preserving the records that support notice, defense, and board reporting.

Records to Keep and a Closing Checklist

After notice goes out, the record set becomes the proof set. In plain English, your documents need to show what happened, when it happened, and what your team did next. If the records are clean and organized, they help show that the company acted with care.

Here are the core records finance and legal teams should keep after any reportable incident:

Record Category What to Capture Why It Matters
Discovery date and time Exact date/time, discoverer, and discovery method Ties directly to California's notification clock under Cal. Civ. Code § 1798.82[1][5][23]
Incident timeline Chronological record of key response actions and approvals Shows regulators and buyers that response was orderly and timely
Forensic findings Reports, system logs, root-cause analysis, chain-of-custody notes Supports litigation defense and demonstrates reasonable security procedures
Data categories affected Which personal information types were involved (e.g., SSNs, financial account numbers) and estimated California resident count Determines whether notice is required and what content it must include[1][5][23]
Legal analysis Written memo from counsel on whether the event is reportable, exceptions considered, and the final decision Protects privilege and documents decision-making rationale
Draft and final notices All versions sent to residents, the AG, and any other regulators Proves statutory content requirements were met
AG submission and confirmation Sample notice filed electronically with the California AG when more than 500 residents are notified, plus the submission receipt The AG posting makes breach timing and content visible publicly[14][29][31]
Delivery proof Email logs, mailing invoices, web posting screenshots, and media notice records Demonstrates that notice actually reached the required recipients
Board and leadership updates Decks, written briefings, and meeting minutes where the breach was discussed Supports governance oversight and diligence review
Vendor communications Incident notices from vendors, contracts, security addenda, remediation correspondence Supports indemnity claims and proves vendor oversight
Breach-related cost log All costs in dollars by category: forensics, legal, notification, credit monitoring, and remediation Feeds insurance claims, investor analysis, and M&A valuation discussions

These files matter long after the incident itself. At exit, buyers often ask for breach history, incident logs, and cyber insurance claims. Missing records tend to get treated as red flags in diligence.[24][25][26][27]

Keep breach records for the full limitations period, plus any longer contract or insurance retention period. Store them in encrypted, role-based repositories. It also helps to separate privileged legal analysis from factual records, so diligence can move forward without waiving privilege.

Conclusion: Key Rules Companies Should Not Miss

Once the file is closed, the record package should still be audit-ready.

The takeaway is simple: determine whether covered data was accessed or acquired, notify the right parties on time, and keep a complete record of each step.[5][28][30][21]

For founders and CFOs, breach reporting should sit inside financial governance and exit prep, not get pushed off as an IT cleanup job. Teams that handle incidents cleanly, document each action, and track breach costs inside FP&A are in a much better spot when regulators, investors, or buyers start asking hard questions. For growth-stage companies getting ready to scale, raise capital, or pursue an exit, that kind of discipline can make a big difference. Phoenix Strategy Group works with growth-stage companies on this kind of financial and strategic readiness, helping teams build the governance infrastructure that stands up to investor and regulatory scrutiny.

FAQs

Does a small company still have to send California breach notices?

Yes. Company size does not matter. If an unauthorized person gets unencrypted personal information, the organization has to send breach notices.

In California, the notice must go out without unreasonable delay and no later than 30 days after the breach is discovered.

If the breach affects more than 500 California residents, the company also has to electronically send a sample notice to the California Attorney General.

What kinds of exposed data trigger notice under California law?

Under California law, notice is required when unencrypted personal information is acquired, or when there’s a reasonable belief that an unauthorized person acquired it. Unauthorized access by itself doesn’t trigger notice.

The data covered by this rule can include:

  • Biometric identifiers
  • Medical or health information
  • Online account credentials
  • Other types of personal information

What should we do first if a vendor caused the breach?

First, contain the breach right away so it doesn't spread. Isolate affected systems by disconnecting them from the network, but do not shut down or reboot the machines. Doing that can wipe volatile evidence.

At the same time, document the vendor’s access and remediation steps, activate your incident response team, work with legal counsel, and record every investigative action with exact timestamps.

Related Blog Posts

Founder to Freedom Weekly
Zero guru BS. Real founders, real exits, real strategies - delivered weekly.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Our blog

Founders' Playbook: Build, Scale, Exit

We've built and sold companies (and made plenty of mistakes along the way). Here's everything we wish we knew from day one.
2026 Operating Expense Benchmarks for Growth Firms
3 min read

2026 Operating Expense Benchmarks for Growth Firms

OpEx benchmarks for growth firms: spending by revenue band, S&M, G&A, payroll intensity, and revenue-per-employee.
Read post
How to Prevent Investor-Founder Misalignment
3 min read

How to Prevent Investor-Founder Misalignment

Put clear targets, reporting rules, and decision rights on paper before funding stress breaks trust.
Read post
CCPA and CPRA Breach Reporting Guide
3 min read

CCPA and CPRA Breach Reporting Guide

Treat breaches as legal and financial events: confirm California coverage, data triggers, timing, vendor duties, and preserve incident records.
Read post
Top 8 Audit Trail Metrics for Compliance
3 min read

Top 8 Audit Trail Metrics for Compliance

Metrics turn logs into audit-ready evidence—track eight measures to prove completeness, timeliness, integrity, and retention.
Read post

Get the systems and clarity to build something bigger - your legacy, your way, with the freedom to enjoy it.