The email or letter is carefully worded. It says a company "recently became aware of a security incident," that "some of your information may have been affected," and that they "take your privacy seriously." Somewhere in the middle, it tells you what was actually exposed: your name, your Social Security number, your date of birth, your driver's license number, perhaps your medical information.
What the notice rarely tells you is how urgent the situation is. Stolen personal data gets sold and used quickly. The steps you take in the first couple of days matter more than anything you do later.
What California Requires the Company to Tell You
California's data breach notification law, Cal. Civ. Code § 1798.82, requires any business that owns or licenses personal information of California residents to notify affected individuals when that information is acquired by an unauthorized person. The notice must be provided "in the most expedient time possible and without unreasonable delay," and it must include, among other things:
- The name and contact information of the business
- The types of personal information that were or are reasonably believed to have been breached
- The date, estimated date, or date range of the breach, if known
- Whether notification was delayed due to a law enforcement investigation
- A general description of the incident
- Toll-free numbers and addresses of the major credit reporting agencies, if the breach involved a Social Security number, driver's license number, or California ID number
If the breach exposed Social Security numbers or driver's license numbers, the business must also offer you identity theft prevention and mitigation services, such as credit monitoring, at no cost for at least twelve months. See Cal. Civ. Code § 1798.82(d)(2)(G).
A notice that is vague about what was taken, or that arrives months after the company discovered the breach, may itself reflect a violation.
The First 48 Hours
1. Read the notice carefully and save it
Identify exactly what data was exposed. The right response depends on it. Save the notice, the envelope or email headers, and note the date you received it.
2. Freeze your credit
If your Social Security number, date of birth, or driver's license number was exposed, place a security freeze at all three national credit bureaus — Equifax, Experian, and TransUnion. Freezes are free under federal law, take effect within one business day when requested online or by phone, and prevent new accounts from being opened in your name. This is the single most effective step against new-account fraud.
3. Place a fraud alert
A fraud alert is a lighter measure than a freeze and can be used alongside it. Contact any one bureau; it must notify the others. An initial alert lasts one year and requires lenders to verify your identity before extending credit.
4. Change passwords and enable two-factor authentication
If login credentials were exposed, change the password on that account immediately, and on any other account where you used the same or a similar password. Turn on two-factor authentication everywhere it is offered.
5. Watch for phishing
Breached data is often used to craft convincing fake emails and texts. Be suspicious of any message that references the breach and asks you to click a link, log in, or "verify" information — including messages that appear to come from the breached company.
6. Enroll in the credit monitoring offered
Accepting the free monitoring the company offers does not waive your legal rights. Read the enrollment terms to be sure, but generally you can accept the service and still pursue a claim.
Ongoing Monitoring
- Pull your credit reports from all three bureaus at annualcreditreport.com and review them for accounts you don't recognize.
- Review bank and card statements closely for several months.
- If your Social Security number was exposed, consider creating an account at ssa.gov to monitor your earnings record, and file your tax return early to reduce the risk of a fraudulent return being filed in your name.
- If medical information was exposed, review explanation-of-benefits statements from your insurer for services you didn't receive.
Document Everything
If you later decide to pursue a claim, you will need records. Keep:
- The breach notice itself
- Records of every protective step you took and when — freeze confirmations, alert confirmations, password changes
- Receipts for any out-of-pocket costs, including credit monitoring you paid for, postage, and travel
- A log of time you spent responding to the breach
- Evidence of any fraud that occurs: fraudulent charges, accounts opened, tax return problems
- Any suspicious emails, texts, or calls you receive that reference the breach or the exposed data
Your Legal Options
Companies that collect personal information have a legal duty to protect it, and California law provides remedies when they fail. We cover the specifics in a separate article on whether you can sue after a data breach. In brief: California's Consumer Privacy Act gives consumers a private right of action with statutory damages when certain kinds of personal information are breached because a business failed to maintain reasonable security. Negligence and other claims may also be available.
The Bottom Line
A breach notice is a signal to act, not just to worry. Freeze your credit, change your passwords, watch your accounts, and keep records of everything you do and every cost you incur. Those records protect you now and preserve your options later.
Think You Have a Case?
Lavian, P.C. represents consumers and everyday people. If you believe your rights have been violated, we offer a free case review — and you pay nothing unless we win.
Get a Free Case ReviewOr call (213) 212-3036