Skip to the main content.
Making screening easy for candidates

CVC - Mega Menu-01

With Verified Credentials' mobile-first candidate experience, you meet candidates where it's most convenient. Learn how easy we make it.

See how it works ›

Featured resource

Adverse Action Guide_Menu

Gain clarity about your compliance responsibilities with our new Adverse Action Guide! Use the interactive map to learn what regulations apply in your area.

Visit the guide ›

Verified Credentials is a leading background screening company. Since 1984, we’ve helped validate and secure relationships through the use of our comprehensive screening solutions. We offer a wide variety of background checks, verifications, and innovative screening tools.

Get to know us ›

Accredited background screening solutions

Logo-PBSA-Accreditation-120x98

Our accreditation confirms that our policies, processes, and employee training meet rigorous industry compliance standards.

Learn about our solutions ›

1 min read

California Amends Data Breach Notification Requirements

California was the first state to enact a data breach notification law in 2003, requiring businesses to notify individuals when their personal information had been compromised. With new guidelines on AI regulations approved on October 1, 2025, followed by updated data breach notification requirements, California appears to be preparing to raise the bar again for data protection standards in the new year. 

On October 3, 2025, Governor Gavin Newsom signed Senate Bill 446, creating reporting changes to the state’s data breach notification statute. The updates focus on clearer deadlines and reporting requirements for businesses handling the personal information of California residents. 

 

A quick overview of changes to California’s data breach notification status

Previously, businesses were required to notify affected individuals of data breaches “without unreasonable delay,” setting an unclear notification standard. As previously written, the law left significant room for interpretation and employer discretion, leading to inconsistent timelines and even the possibility of putting consumers at greater risk.  

What has changed 

Under the amendment, definitions for personal information remain the same. SB 446 takes effect on January 1, 2026, primarily focusing on requiring businesses to comply with new reporting timeline standards:  

  • Standardized timeline for notifying the Attorney General: Under SB 446, a single electronic sample copy of the consumer notice must be submitted to the Attorney General if a breach affects over 500 California residents: 
    • Within 15 days of notifying affected consumers 
    • Excluding any personally identifiable information 
  • Consumer reporting timeline clarification: The new regulations also provide clarity on consumer reporting timelines, stating that data breaches must be reported within 30 calendar days of discovery. 

Exceptions 

The amendment does acknowledge that the new 30-day timeline is not always possible and allows two exceptions: 

  1. To accommodate the legitimate needs of law enforcement. 
  2. When necessary, to determine the scope of the breach and restore the reasonable integrity of the data system. 

To learn more about the changes made to the California data breach notification statute, take a closer look here.

 

Why this matters beyond California

Although SB 446 applies specifically to residents in the state, California has been known to set the precedent for privacy and data protection laws, such as the first statewide data breach notification law in 2003, the California Consumer Privacy Act in 2018, and the California Privacy Rights Act in 2020. HR professionals in all states should pay attention, as similar requirements could potentially emerge in other jurisdictions. Employers with operations involving California resident or employee consumer data should consult with their legal counsel to determine how these changes may impact their business.

 

 

This content is for informational purposes only and shall not constitute legal opinion or advice. Consult your legal counsel to ensure compliance.

California Amends Data Breach Notification Requirements

California was the first state to enact a data breach notification law in 2003, requiring businesses to notify individuals when their personal...

Read More

The Massachusetts Wage Transparency Act Is in Effect: Here’s What Employers and Employees Should Know

On July 31, 2024, Massachusetts Governor Maura Healey signed the state’s salary range transparency legislation, An Act Relative to Salary Range Tr...

Read More

Minnesota’s Medical Cannabis Law Amended

Minnesota’s medical cannabis law has long set boundaries prohibiting employers, landlords, and schools from discriminating against individuals based...

Read More

The Massachusetts Wage Transparency Act Is in Effect: Here’s What Employers and Employees Should Know

On July 31, 2024, Massachusetts Governor Maura Healey signed the state’s salary range transparency legislation, An Act Relative to Salary Range Tr...

Read More

Minnesota’s Medical Cannabis Law Amended

Minnesota’s medical cannabis law has long set boundaries prohibiting employers, landlords, and schools from discriminating against individuals based...

Read More

Minnesota Consumer Data Privacy Act Now in Effect: Details Employers Need to Know

In 2024, we covered both Minnesota’s and Rhode Island’s Data Privacy Acts. While Rhode Island’s law will not go into effect until 2026, Minnesota’s...

Read More