Data Breach Claims Under California Law
California's consumer privacy law lets residents sue a business if their nonencrypted personal information is accessed because the business failed to maintain reasonable security. A consumer can recover actual damages or statutory damages per incident, whichever is greater, but must generally give 30 days' written notice and a chance to cure first.
What the Law Provides
Direct Answer: Section 1798.150 allows a consumer whose nonencrypted personal information is accessed or disclosed because of a business's failure to maintain reasonable security to recover damages.
Recovery can be actual damages or statutory damages, whichever is greater, per consumer per incident. The statute originally set the range at $100 to $750, and the figures are adjusted over time, so check the current amounts. Only certain types of information are covered, and the law applies to businesses that meet the statute's thresholds.
Notice and Cure
Before suing for statutory damages, a consumer must give the business 30 days' written notice identifying the violation. If the business cures the violation and confirms it in writing within that period, statutory damages are not available, though the statute states that improving security after a breach is not a cure. The notice requirement does not apply to claims for actual financial damages only.
Class Actions and Other Options
Because a breach usually affects many people, claims are often brought as class actions, which are covered by their own procedures. Residents of other states may have different protections, since breach notification and private rights of action vary, so the law that applies depends on where you live and the nature of the breach. Keep the breach notice you received and records of any losses such as fraud or identity theft costs.
Frequently Asked Questions
Can I sue a company after a data breach in California?
How much can I recover?
Do I have to give notice first?
Does the law cover every kind of data?
What if I do not live in California?
What should I keep?
Can I get a data breach lawyer without paying upfront?
You May Also Be Interested In
Where this applies: Contingency fee rules are set state by state. Check your own state's rules before acting.
Sources for this page
Every rule stated above is based on the primary sources below. Each link goes to the legislation, court rule or regulator itself so you can check it. Last verified 18 September 2026.
- ABA Model Rule 1.5 (Fees)
Model, not law. Each state adopts its own version. Rule 1.5(d) bars contingency fees in most domestic relations matters and in criminal defence.
- Cornell LII — contingency fee
- Cal. Civ. Code § 1798.150 — Data breach private right of action
Consumers may recover statutory or actual damages, whichever is greater, where nonencrypted personal information is accessed because of a business's failure to maintain reasonable security; 30 days' written notice and opportunity to cure apply before suing for statutory damages.
Who wrote and checked this page
- Written and published by
- Edward & Amaury Solicitors (Edward & Amaury Ltd, company no. 12195443), regulated by the Solicitors Regulation Authority under no. 800525.
- Legal review
- This page has not yet been through independent legal review. It is written from the primary sources listed below, which you can check directly.
- Review dates
- Last reviewed 18 September 2026. Next review due 18 March 2027.
Fee rules change. California’s medical malpractice fee limits changed on 1 January 2023, and the QOCS rules in England and Wales changed on 6 April 2023. If you spot something out of date, tell us — we publish corrections.