← California State Legislature · All bills
SB 446
Data breaches: customer notification.
Senate · Other
What this bill does
This bill would require that data breach disclosure to be made within 30 calendar days of discovery or notification of the data breach but would authorize an individual or business to delay the disclosure to accommodate the legitimate needs of law enforcement, as specified, or as necessary to determine the scope of the breach and restore the reasonable integrity of the data system. …
Read the full official summary
Existing law requires an individual or a business that conducts business in California, and that owns or licenses computerized data that includes personal information, to disclose a breach of the security of the system following discovery or notification of the breach in the security of the data to a resident of California whose unencrypted personal information was compromised, as specified, and requires that disclosure to be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement, as specified, or any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system.
This bill would require that data breach disclosure to be made within 30 calendar days of discovery or notification of the data breach but would authorize an individual or business to delay the disclosure to accommodate the legitimate needs of law enforcement, as specified, or as necessary to determine the scope of the breach and restore the reasonable integrity of the data system.
Existing law also requires an individual or business that is required to issue the security breach notification described above to more than 500 California residents as a result of a single breach of the security system to electronically submit a single sample copy of that security breach notification, excluding any personally identifiable information, to the Attorney General.
This bill would require that submission to the Attorney General to be made within 15 calendar days of notifying affected consumers of the security breach.
Official summary from the Legislative Counsel’s office, via OpenStates.
Floor votes (1)
May 28, 2025 — Third reading vote
Passed · 39 yes · 0 no · 1 other
Yes (39): Ben Allen, Marie Alvarado-Gil, Bob Archuleta, Jesse Arreguín, Angelique Ashby, Josh Becker, Catherine Blakespear, Christopher Cabaldon, Anna Caballero, Sabrina Cervantes, Steve Choi, Dave Cortese, Megan Dahle, María Elena Durazo, Lena Gonzalez, Tim Grayson, Shannon Grove, Melissa Hurtado, Brian Jones, John Laird, Monique Limón, Mike McGuire, Jerry McNerney, Caroline Menjivar, Roger Niello, Rosilicie Ochoa Bogh, Steve Padilla, Sasha Pérez, Laura Richardson, Susan Rubio, Kelly Seyarto, Lola Smallwood-Cuevas, Henry Stern, Tony Strickland, Tom Umberg, Suzette Valladares, Aisha Wahab, Akilah Weber Pierson, Scott Wiener
Other / no vote recorded (1): Eloise Reyes
Official motion wording
3rd Reading
Official record: leginfo.legislature.ca.gov