For years, the honest answer to "can I sue over a data breach?" was "maybe, but it's hard." Courts frequently dismissed breach cases on the theory that a consumer whose data was stolen, but who had not yet suffered identity theft, had no concrete injury to sue over. Companies lost your data, apologized, and moved on.
California changed the calculus. The California Consumer Privacy Act, as amended by the California Privacy Rights Act, created a private right of action specifically for data breaches — with statutory damages that do not depend on proving you lost money.
The Private Right of Action
Under Cal. Civ. Code § 1798.150(a), a consumer whose nonencrypted and nonredacted personal information is subject to unauthorized access and exfiltration, theft, or disclosure as a result of a business's failure to implement and maintain reasonable security procedures and practices may bring a civil action. The consumer may recover:
- Statutory damages of not less than $100 and not greater than $750 per consumer per incident, or actual damages, whichever is greater
- Injunctive or declaratory relief
- Any other relief the court deems proper
The statute also authorizes the state's privacy agency to adjust these dollar amounts periodically for inflation, so the figures may be higher by the time a given claim is brought.
Three features make this provision unusually powerful. First, the damages are statutory: you do not need to prove the breach cost you a specific amount. Second, they are per consumer, so a breach affecting a million Californians creates exposure of a hundred million dollars at the floor. Third, the statute explicitly authorizes the action "individually or on a class-wide basis," resolving a threshold question that often bogs down other kinds of claims.
What "Personal Information" Means Here
The private right of action does not cover every category of data. It applies to "personal information" as defined in California's breach notification statute, Cal. Civ. Code § 1798.81.5(d)(1)(A) — a narrower definition than the CCPA's general one. It covers an individual's first name or initial and last name in combination with any of the following, when either the name or the data element is not encrypted or redacted:
- Social Security number
- Driver's license, California ID, tax ID, passport, military ID, or other government-issued identification number
- Financial account, credit card, or debit card number in combination with any code or password that would permit access to the account
- Medical information
- Health insurance information
- Unique biometric data used to authenticate identity, such as a fingerprint or retina image
- Genetic data
It also covers a username or email address in combination with a password or security question that would permit access to an online account. A breach that exposed only names and email addresses, without more, generally does not trigger the statutory damages provision, though other claims may still be available.
"Reasonable Security"
The claim requires that the breach resulted from the business's failure to implement and maintain reasonable security procedures and practices appropriate to the nature of the information. This is the same duty imposed by Cal. Civ. Code § 1798.81.5(b), which requires businesses that own or license personal information about Californians to protect it with reasonable security.
The statute does not define "reasonable," and that is where breach cases are litigated. Evidence that a company ignored known vulnerabilities, failed to patch software, stored sensitive data without encryption, lacked multifactor authentication, retained data it no longer needed, or fell short of common industry frameworks all bears on the question. The company's own breach notice frequently contains admissions about what went wrong.
The Thirty-Day Notice Requirement
Before filing an action seeking statutory damages, the consumer must give the business thirty days' written notice identifying the specific provisions the consumer alleges were violated. See Cal. Civ. Code § 1798.150(b). If the business "actually cures" the violation within thirty days and provides a written statement that it has done so and that no further violations will occur, statutory damages are not available.
The CPRA amendments closed what had been a significant loophole. The statute now provides that implementing and maintaining reasonable security after a breach does not constitute a cure with respect to that breach. In other words, a company cannot avoid liability for the breach that already happened by promising to do better. The notice requirement does not apply to actions seeking only actual damages.
Other Claims
The CCPA private right of action is the sharpest tool, but breach cases in California routinely include other claims that can reach data outside the statute's definition or businesses outside its scope:
- Negligence, based on the duty to protect personal information
- Breach of implied contract, where the business collected your data as part of a transaction and implicitly promised to protect it
- Unfair Competition Law, Cal. Bus. & Prof. Code § 17200, for unlawful or unfair business practices
- California's Customer Records Act, Cal. Civ. Code § 1798.84, which provides a private right of action for violations of the state's data security and breach notification requirements
- Confidentiality of Medical Information Act, Cal. Civ. Code § 56 and following, when medical information is involved, with its own nominal damages provision
What Recovery Looks Like
Breach cases are usually resolved as class actions. Settlements typically provide some combination of cash payments to class members, reimbursement for documented out-of-pocket losses and time spent, extended credit or identity monitoring, and commitments by the company to improve its security. The statutory damages provision has substantially increased the settlement value of California breach cases because it gives plaintiffs a credible damages floor.
Statute of Limitations
The CCPA does not specify a limitations period for the private right of action, and the applicable period may depend on how the claim is characterized. Negligence claims in California generally carry a two-year period; UCL claims carry four years. Given the uncertainty, the prudent course is to act promptly after receiving a breach notice.
The Bottom Line
If a California business exposed your Social Security number, financial account credentials, medical information, or similar sensitive data because it failed to secure them, you very likely have a claim — and one that carries statutory damages whether or not the thief has used your data yet. Save the breach notice, document your response, and get advice about the thirty-day notice requirement before the timeline gets away from you.
Think You Have a Case?
Lavian, P.C. represents consumers and everyday people. If you believe your rights have been violated, we offer a free case review — and you pay nothing unless we win.
Get a Free Case ReviewOr call (213) 212-3036