veeto
Home
Bills
Feedback
hamburger
    Privacy PolicyResources
    © 2025 Veeto.
    SB-446
    Consumer Protection

    Data breaches: customer notification.

    Enrolled
    CA
    ∙
    2025-2026 Regular Session
    0
    0
    Track
    Track

    Key Takeaways

    • Requires businesses to notify California residents of data breaches within 30 days of discovery.
    • Mandates notification to the Attorney General within 15 days when breaches affect over 500 residents.
    • Establishes specific format requirements for data breach notices including plain language and clear headings.
    • Requires free identity theft prevention services for 12 months if social security or license numbers are exposed.

    Summary

    Senator Hurtado's data breach notification measure establishes specific timelines for California businesses to inform consumers and state officials when personal information is compromised. The legislation requires companies to notify affected California residents within 30 calendar days of discovering a data breach, though delays are permitted to accommodate law enforcement investigations or to determine the scope of the breach.

    For incidents affecting more than 500 California residents, businesses must submit a redacted sample of their breach notification to the Attorney General within 15 calendar days of informing consumers. The notifications must follow a standardized format with clear headings addressing what happened, what information was involved, and what actions are being taken in response. These notices must use plain language, maintain minimum text sizes, and include contact information for credit reporting agencies if sensitive identifiers like Social Security numbers were exposed.

    The measure preserves existing provisions allowing alternative notification methods when standard contact proves impractical or cost-prohibitive. Healthcare entities that comply with federal breach notification requirements under HIPAA are deemed to meet certain state notice obligations, though they remain subject to the new timeline requirements and other provisions of the law. The legislation maintains current definitions of personal information and security breaches while adding specific protocols for incidents involving online account credentials.

    Key Dates

    Vote on Assembly Floor
    Assembly Floor
    Vote on Assembly Floor
    SB 446 Hurtado Consent Calendar Second Day Regular Session
    Assembly Appropriations Hearing
    Assembly Committee
    Assembly Appropriations Hearing
    Do pass. To Consent Calendar
    Assembly Judiciary Hearing
    Assembly Committee
    Assembly Judiciary Hearing
    Do pass and be re-referred to the Committee on [Appropriations] with recommendation: To Consent Calendar
    Assembly Privacy And Consumer Protection Hearing
    Assembly Committee
    Assembly Privacy And Consumer Protection Hearing
    Do pass and be re-referred to the Committee on [Judiciary] with recommendation: To Consent Calendar
    Vote on Senate Floor
    Senate Floor
    Vote on Senate Floor
    Senate 3rd Reading SB446 Hurtado
    Senate Judiciary Hearing
    Senate Committee
    Senate Judiciary Hearing
    Do pass as amended, but first amend, and re-refer to the Committee on [Appropriations]
    Introduced
    Senate Floor
    Introduced
    Introduced. Read first time. To Com. on RLS. for assignment. To print.

    Contacts

    Profile
    Melissa HurtadoD
    Senator
    Bill Author
    Not Contacted
    Not Contacted
    0 of 1 row(s) selected.
    Page 1 of 1
    Select All Legislators
    Profile
    Melissa HurtadoD
    Senator
    Bill Author

    Get Involved

    Act Now!

    Email the authors or create an email template to send to all relevant legislators.

    Introduced By

    Melissa Hurtado
    Melissa HurtadoD
    California State Senator
    70% progression
    Bill has passed both houses in identical form and is being prepared for the Governor (8/28/2025)

    Latest Voting History

    View History
    August 28, 2025
    PASS
    Assembly Floor
    Vote on Assembly Floor
    AyesNoesNVRTotalResult
    740579PASS

    Key Takeaways

    • Requires businesses to notify California residents of data breaches within 30 days of discovery.
    • Mandates notification to the Attorney General within 15 days when breaches affect over 500 residents.
    • Establishes specific format requirements for data breach notices including plain language and clear headings.
    • Requires free identity theft prevention services for 12 months if social security or license numbers are exposed.

    Get Involved

    Act Now!

    Email the authors or create an email template to send to all relevant legislators.

    Introduced By

    Melissa Hurtado
    Melissa HurtadoD
    California State Senator

    Summary

    Senator Hurtado's data breach notification measure establishes specific timelines for California businesses to inform consumers and state officials when personal information is compromised. The legislation requires companies to notify affected California residents within 30 calendar days of discovering a data breach, though delays are permitted to accommodate law enforcement investigations or to determine the scope of the breach.

    For incidents affecting more than 500 California residents, businesses must submit a redacted sample of their breach notification to the Attorney General within 15 calendar days of informing consumers. The notifications must follow a standardized format with clear headings addressing what happened, what information was involved, and what actions are being taken in response. These notices must use plain language, maintain minimum text sizes, and include contact information for credit reporting agencies if sensitive identifiers like Social Security numbers were exposed.

    The measure preserves existing provisions allowing alternative notification methods when standard contact proves impractical or cost-prohibitive. Healthcare entities that comply with federal breach notification requirements under HIPAA are deemed to meet certain state notice obligations, though they remain subject to the new timeline requirements and other provisions of the law. The legislation maintains current definitions of personal information and security breaches while adding specific protocols for incidents involving online account credentials.

    70% progression
    Bill has passed both houses in identical form and is being prepared for the Governor (8/28/2025)

    Key Dates

    Vote on Assembly Floor
    Assembly Floor
    Vote on Assembly Floor
    SB 446 Hurtado Consent Calendar Second Day Regular Session
    Assembly Appropriations Hearing
    Assembly Committee
    Assembly Appropriations Hearing
    Do pass. To Consent Calendar
    Assembly Judiciary Hearing
    Assembly Committee
    Assembly Judiciary Hearing
    Do pass and be re-referred to the Committee on [Appropriations] with recommendation: To Consent Calendar
    Assembly Privacy And Consumer Protection Hearing
    Assembly Committee
    Assembly Privacy And Consumer Protection Hearing
    Do pass and be re-referred to the Committee on [Judiciary] with recommendation: To Consent Calendar
    Vote on Senate Floor
    Senate Floor
    Vote on Senate Floor
    Senate 3rd Reading SB446 Hurtado
    Senate Judiciary Hearing
    Senate Committee
    Senate Judiciary Hearing
    Do pass as amended, but first amend, and re-refer to the Committee on [Appropriations]
    Introduced
    Senate Floor
    Introduced
    Introduced. Read first time. To Com. on RLS. for assignment. To print.

    Latest Voting History

    View History
    August 28, 2025
    PASS
    Assembly Floor
    Vote on Assembly Floor
    AyesNoesNVRTotalResult
    740579PASS

    Contacts

    Profile
    Melissa HurtadoD
    Senator
    Bill Author
    Not Contacted
    Not Contacted
    0 of 1 row(s) selected.
    Page 1 of 1
    Select All Legislators
    Profile
    Melissa HurtadoD
    Senator
    Bill Author