SB-446
Consumer Protection

Data breaches: customer notification.

Enrolled
CA
2025-2026 Regular Session
0
0
Track

Key Takeaways

  • Requires businesses to notify California residents of data breaches within 30 days of discovery.
  • Mandates notification to the Attorney General within 15 days when breaches affect over 500 residents.
  • Establishes specific format requirements for data breach notices including plain language and clear headings.
  • Requires free identity theft prevention services for 12 months if social security or license numbers are exposed.

Summary

Senator Hurtado's data breach notification measure establishes specific timelines for California businesses to inform consumers and state officials when personal information is compromised. The legislation requires companies to notify affected California residents within 30 calendar days of discovering a data breach, though delays are permitted to accommodate law enforcement investigations or to determine the scope of the breach.

For incidents affecting more than 500 California residents, businesses must submit a redacted sample of their breach notification to the Attorney General within 15 calendar days of informing consumers. The notifications must follow a standardized format with clear headings addressing what happened, what information was involved, and what actions are being taken in response. These notices must use plain language, maintain minimum text sizes, and include contact information for credit reporting agencies if sensitive identifiers like Social Security numbers were exposed.

The measure preserves existing provisions allowing alternative notification methods when standard contact proves impractical or cost-prohibitive. Healthcare entities that comply with federal breach notification requirements under HIPAA are deemed to meet certain state notice obligations, though they remain subject to the new timeline requirements and other provisions of the law. The legislation maintains current definitions of personal information and security breaches while adding specific protocols for incidents involving online account credentials.

Key Dates

Vote on Assembly Floor
Assembly Floor
Vote on Assembly Floor
SB 446 Hurtado Consent Calendar Second Day Regular Session
Assembly Appropriations Hearing
Assembly Committee
Assembly Appropriations Hearing
Do pass. To Consent Calendar
Assembly Judiciary Hearing
Assembly Committee
Assembly Judiciary Hearing
Do pass and be re-referred to the Committee on [Appropriations] with recommendation: To Consent Calendar
Assembly Privacy And Consumer Protection Hearing
Assembly Committee
Assembly Privacy And Consumer Protection Hearing
Do pass and be re-referred to the Committee on [Judiciary] with recommendation: To Consent Calendar
Vote on Senate Floor
Senate Floor
Vote on Senate Floor
Senate 3rd Reading SB446 Hurtado
Senate Judiciary Hearing
Senate Committee
Senate Judiciary Hearing
Do pass as amended, but first amend, and re-refer to the Committee on [Appropriations]
Introduced
Senate Floor
Introduced
Introduced. Read first time. To Com. on RLS. for assignment. To print.

Contacts

Profile
Melissa HurtadoD
Senator
Bill Author
Not Contacted
Not Contacted
0 of 1 row(s) selected.
Page 1 of 1
Select All Legislators
Profile
Melissa HurtadoD
Senator
Bill Author

Get Involved

Act Now!

Email the authors or create an email template to send to all relevant legislators.

Introduced By

Melissa Hurtado
Melissa HurtadoD
California State Senator
70% progression
Bill has passed both houses in identical form and is being prepared for the Governor (8/28/2025)

Latest Voting History

August 28, 2025
PASS
Assembly Floor
Vote on Assembly Floor
AyesNoesNVRTotalResult
740579PASS

Key Takeaways

  • Requires businesses to notify California residents of data breaches within 30 days of discovery.
  • Mandates notification to the Attorney General within 15 days when breaches affect over 500 residents.
  • Establishes specific format requirements for data breach notices including plain language and clear headings.
  • Requires free identity theft prevention services for 12 months if social security or license numbers are exposed.

Get Involved

Act Now!

Email the authors or create an email template to send to all relevant legislators.

Introduced By

Melissa Hurtado
Melissa HurtadoD
California State Senator

Summary

Senator Hurtado's data breach notification measure establishes specific timelines for California businesses to inform consumers and state officials when personal information is compromised. The legislation requires companies to notify affected California residents within 30 calendar days of discovering a data breach, though delays are permitted to accommodate law enforcement investigations or to determine the scope of the breach.

For incidents affecting more than 500 California residents, businesses must submit a redacted sample of their breach notification to the Attorney General within 15 calendar days of informing consumers. The notifications must follow a standardized format with clear headings addressing what happened, what information was involved, and what actions are being taken in response. These notices must use plain language, maintain minimum text sizes, and include contact information for credit reporting agencies if sensitive identifiers like Social Security numbers were exposed.

The measure preserves existing provisions allowing alternative notification methods when standard contact proves impractical or cost-prohibitive. Healthcare entities that comply with federal breach notification requirements under HIPAA are deemed to meet certain state notice obligations, though they remain subject to the new timeline requirements and other provisions of the law. The legislation maintains current definitions of personal information and security breaches while adding specific protocols for incidents involving online account credentials.

70% progression
Bill has passed both houses in identical form and is being prepared for the Governor (8/28/2025)

Key Dates

Vote on Assembly Floor
Assembly Floor
Vote on Assembly Floor
SB 446 Hurtado Consent Calendar Second Day Regular Session
Assembly Appropriations Hearing
Assembly Committee
Assembly Appropriations Hearing
Do pass. To Consent Calendar
Assembly Judiciary Hearing
Assembly Committee
Assembly Judiciary Hearing
Do pass and be re-referred to the Committee on [Appropriations] with recommendation: To Consent Calendar
Assembly Privacy And Consumer Protection Hearing
Assembly Committee
Assembly Privacy And Consumer Protection Hearing
Do pass and be re-referred to the Committee on [Judiciary] with recommendation: To Consent Calendar
Vote on Senate Floor
Senate Floor
Vote on Senate Floor
Senate 3rd Reading SB446 Hurtado
Senate Judiciary Hearing
Senate Committee
Senate Judiciary Hearing
Do pass as amended, but first amend, and re-refer to the Committee on [Appropriations]
Introduced
Senate Floor
Introduced
Introduced. Read first time. To Com. on RLS. for assignment. To print.

Latest Voting History

August 28, 2025
PASS
Assembly Floor
Vote on Assembly Floor
AyesNoesNVRTotalResult
740579PASS

Contacts

Profile
Melissa HurtadoD
Senator
Bill Author
Not Contacted
Not Contacted
0 of 1 row(s) selected.
Page 1 of 1
Select All Legislators
Profile
Melissa HurtadoD
Senator
Bill Author