veeto
Home
Bills
Influence
Feedback
hamburger
    Privacy PolicyResources
    © 2025 Veeto.
    SB-446
    Consumer Protection

    Data breaches: customer notification.

    Engrossed
    CA
    ∙
    2025-2026 Regular Session
    0
    0
    Track
    Track

    Key Takeaways

    • Requires businesses to notify California residents of data breaches within 30 days of discovery.
    • Mandates notification to the Attorney General within 15 days when breaches affect over 500 residents.
    • Requires breach notifications to include detailed information about the incident and protection measures.
    • Allows delayed notification only for law enforcement needs or to determine breach scope.

    Summary

    Senator Hurtado's data breach notification measure establishes specific timelines for California businesses to inform consumers and regulators about security incidents. Under the proposal, organizations must notify affected California residents within 30 calendar days of discovering a data breach, while retaining flexibility to delay disclosure for law enforcement needs or to determine the breach's scope.

    The legislation also requires businesses to submit sample breach notifications to the Attorney General within 15 calendar days of informing consumers when incidents affect more than 500 California residents. These notifications must follow a standardized format with plain language headers covering what happened, what information was involved, response measures, and guidance for affected individuals.

    The measure maintains existing requirements for notification content, including breach timing details, types of compromised data, and whether law enforcement investigations caused any delays. Organizations must continue providing identity theft prevention services at no cost for 12 months when social security numbers or driver's license information is exposed. Alternative notification methods remain available when standard notice would exceed $250,000 or affect more than 500,000 people.

    Key Dates

    Next Step
    Referred to the Assembly Standing Committee on Judiciary
    Next Step
    Assembly Committee
    Referred to the Assembly Standing Committee on Judiciary
    Hearing scheduled for , State Capitol, Room 437
    Assembly Privacy And Consumer Protection Hearing
    Assembly Committee
    Assembly Privacy And Consumer Protection Hearing
    Do pass and be re-referred to the Committee on [Judiciary] with recommendation: To Consent Calendar
    Vote on Senate Floor
    Senate Floor
    Vote on Senate Floor
    Senate 3rd Reading SB446 Hurtado
    Senate Judiciary Hearing
    Senate Committee
    Senate Judiciary Hearing
    Do pass as amended, but first amend, and re-refer to the Committee on [Appropriations]
    Introduced
    Senate Floor
    Introduced
    Introduced. Read first time. To Com. on RLS. for assignment. To print.

    Contacts

    Profile
    Ash KalraD
    Assemblymember
    Committee Member
    Not Contacted
    Not Contacted
    Profile
    Rebecca Bauer-KahanD
    Assemblymember
    Committee Member
    Not Contacted
    Not Contacted
    Profile
    Melissa HurtadoD
    Senator
    Bill Author
    Not Contacted
    Not Contacted
    Profile
    Isaac BryanD
    Assemblymember
    Committee Member
    Not Contacted
    Not Contacted
    Profile
    Damon ConnollyD
    Assemblymember
    Committee Member
    Not Contacted
    Not Contacted
    0 of 13 row(s) selected.
    Page 1 of 3
    Select All Legislators
    Profile
    Ash KalraD
    Assemblymember
    Committee Member
    Profile
    Rebecca Bauer-KahanD
    Assemblymember
    Committee Member
    Profile
    Melissa HurtadoD
    Senator
    Bill Author
    Profile
    Isaac BryanD
    Assemblymember
    Committee Member
    Profile
    Damon ConnollyD
    Assemblymember
    Committee Member
    Profile
    Diane DixonR
    Assemblymember
    Committee Member
    Profile
    Bill EssayliR
    Assemblymember
    Committee Member
    Profile
    Blanca PachecoD
    Assemblymember
    Committee Member
    Profile
    Diane PapanD
    Assemblymember
    Committee Member
    Profile
    Kate SanchezR
    Assemblymember
    Committee Member
    Profile
    Rick ZburD
    Assemblymember
    Committee Member
    Profile
    John HarabedianD
    Assemblymember
    Committee Member
    Profile
    Catherine StefaniD
    Assemblymember
    Committee Member

    Get Involved

    Act Now!

    Email the authors or create an email template to send to all relevant legislators.

    Introduced By

    Melissa Hurtado
    Melissa HurtadoD
    California State Senator
    40% progression
    Bill has passed all readings in its first house and is ready to move to the other house (5/28/2025)

    Latest Voting History

    View History
    June 24, 2025
    PASS
    Assembly Committee
    Assembly Privacy And Consumer Protection Hearing
    AyesNoesNVRTotalResult
    150015PASS

    Key Takeaways

    • Requires businesses to notify California residents of data breaches within 30 days of discovery.
    • Mandates notification to the Attorney General within 15 days when breaches affect over 500 residents.
    • Requires breach notifications to include detailed information about the incident and protection measures.
    • Allows delayed notification only for law enforcement needs or to determine breach scope.

    Get Involved

    Act Now!

    Email the authors or create an email template to send to all relevant legislators.

    Introduced By

    Melissa Hurtado
    Melissa HurtadoD
    California State Senator

    Summary

    Senator Hurtado's data breach notification measure establishes specific timelines for California businesses to inform consumers and regulators about security incidents. Under the proposal, organizations must notify affected California residents within 30 calendar days of discovering a data breach, while retaining flexibility to delay disclosure for law enforcement needs or to determine the breach's scope.

    The legislation also requires businesses to submit sample breach notifications to the Attorney General within 15 calendar days of informing consumers when incidents affect more than 500 California residents. These notifications must follow a standardized format with plain language headers covering what happened, what information was involved, response measures, and guidance for affected individuals.

    The measure maintains existing requirements for notification content, including breach timing details, types of compromised data, and whether law enforcement investigations caused any delays. Organizations must continue providing identity theft prevention services at no cost for 12 months when social security numbers or driver's license information is exposed. Alternative notification methods remain available when standard notice would exceed $250,000 or affect more than 500,000 people.

    40% progression
    Bill has passed all readings in its first house and is ready to move to the other house (5/28/2025)

    Key Dates

    Next Step
    Referred to the Assembly Standing Committee on Judiciary
    Next Step
    Assembly Committee
    Referred to the Assembly Standing Committee on Judiciary
    Hearing scheduled for , State Capitol, Room 437
    Assembly Privacy And Consumer Protection Hearing
    Assembly Committee
    Assembly Privacy And Consumer Protection Hearing
    Do pass and be re-referred to the Committee on [Judiciary] with recommendation: To Consent Calendar
    Vote on Senate Floor
    Senate Floor
    Vote on Senate Floor
    Senate 3rd Reading SB446 Hurtado
    Senate Judiciary Hearing
    Senate Committee
    Senate Judiciary Hearing
    Do pass as amended, but first amend, and re-refer to the Committee on [Appropriations]
    Introduced
    Senate Floor
    Introduced
    Introduced. Read first time. To Com. on RLS. for assignment. To print.

    Latest Voting History

    View History
    June 24, 2025
    PASS
    Assembly Committee
    Assembly Privacy And Consumer Protection Hearing
    AyesNoesNVRTotalResult
    150015PASS

    Contacts

    Profile
    Ash KalraD
    Assemblymember
    Committee Member
    Not Contacted
    Not Contacted
    Profile
    Rebecca Bauer-KahanD
    Assemblymember
    Committee Member
    Not Contacted
    Not Contacted
    Profile
    Melissa HurtadoD
    Senator
    Bill Author
    Not Contacted
    Not Contacted
    Profile
    Isaac BryanD
    Assemblymember
    Committee Member
    Not Contacted
    Not Contacted
    Profile
    Damon ConnollyD
    Assemblymember
    Committee Member
    Not Contacted
    Not Contacted
    0 of 13 row(s) selected.
    Page 1 of 3
    Select All Legislators
    Profile
    Ash KalraD
    Assemblymember
    Committee Member
    Profile
    Rebecca Bauer-KahanD
    Assemblymember
    Committee Member
    Profile
    Melissa HurtadoD
    Senator
    Bill Author
    Profile
    Isaac BryanD
    Assemblymember
    Committee Member
    Profile
    Damon ConnollyD
    Assemblymember
    Committee Member
    Profile
    Diane DixonR
    Assemblymember
    Committee Member
    Profile
    Bill EssayliR
    Assemblymember
    Committee Member
    Profile
    Blanca PachecoD
    Assemblymember
    Committee Member
    Profile
    Diane PapanD
    Assemblymember
    Committee Member
    Profile
    Kate SanchezR
    Assemblymember
    Committee Member
    Profile
    Rick ZburD
    Assemblymember
    Committee Member
    Profile
    John HarabedianD
    Assemblymember
    Committee Member
    Profile
    Catherine StefaniD
    Assemblymember
    Committee Member