Skip to the main content.
Featured resource

Ban the Box Guide

Our new Ban the Box Guide makes it easier than ever to decipher the patchwork of fair chance laws across the country. Check the map to quickly identify what laws apply to you.

Visit the guide ›

Verified Credentials is a leading background screening company. Since 1984, we’ve helped validate and secure relationships through the use of our comprehensive screening solutions. We offer a wide variety of background checks, verifications, and innovative screening tools.

Get to know us ›

Accredited background screening solutions

PBSA Accredited

Our accreditation confirms that our policies, processes, and employee training meet rigorous industry compliance standards.

Learn about our solutions ›

1 min read

California Amends Data Breach Notification Requirements

California was the first state to enact a data breach notification law in 2003, requiring businesses to notify individuals when their personal information had been compromised. With new guidelines on AI regulations approved on October 1, 2025, followed by updated data breach notification requirements, California appears to be preparing to raise the bar again for data protection standards in the new year. 

On October 3, 2025, Governor Gavin Newsom signed Senate Bill 446, creating reporting changes to the state’s data breach notification statute. The updates focus on clearer deadlines and reporting requirements for businesses handling the personal information of California residents. 

 

A quick overview of changes to California’s data breach notification status

Previously, businesses were required to notify affected individuals of data breaches “without unreasonable delay,” setting an unclear notification standard. As previously written, the law left significant room for interpretation and employer discretion, leading to inconsistent timelines and even the possibility of putting consumers at greater risk.  

What has changed 

Under the amendment, definitions for personal information remain the same. SB 446 takes effect on January 1, 2026, primarily focusing on requiring businesses to comply with new reporting timeline standards:  

  • Standardized timeline for notifying the Attorney General: Under SB 446, a single electronic sample copy of the consumer notice must be submitted to the Attorney General if a breach affects over 500 California residents: 
    • Within 15 days of notifying affected consumers 
    • Excluding any personally identifiable information 
  • Consumer reporting timeline clarification: The new regulations also provide clarity on consumer reporting timelines, stating that data breaches must be reported within 30 calendar days of discovery. 

Exceptions 

The amendment does acknowledge that the new 30-day timeline is not always possible and allows two exceptions: 

  1. To accommodate the legitimate needs of law enforcement. 
  2. When necessary, to determine the scope of the breach and restore the reasonable integrity of the data system. 

To learn more about the changes made to the California data breach notification statute, take a closer look here.

 

Why this matters beyond California

Although SB 446 applies specifically to residents in the state, California has been known to set the precedent for privacy and data protection laws, such as the first statewide data breach notification law in 2003, the California Consumer Privacy Act in 2018, and the California Privacy Rights Act in 2020. HR professionals in all states should pay attention, as similar requirements could potentially emerge in other jurisdictions. Employers with operations involving California resident or employee consumer data should consult with their legal counsel to determine how these changes may impact their business.

 

 

This content is for informational purposes only and shall not constitute legal opinion or advice. Consult your legal counsel to ensure compliance.

Washington’s New Background Check Requirements Take Effect July 2026

In July 2025, we covered Washington State’s increased regulations for employer access to criminal background checks with House Bill 1747. While the...

Read More

Connecticut Issues A 2026 Memorandum on Artificial Intelligence

The national attention drawn to guarding against the misuse of Artificial Intelligence only seems to be intensifying, and for a good reason. AI can...

Read More

E-Verify Updates for Employers: 2025-2026 Changes to Enact

If you are already required to use E-Verify, you have probably heard there have been some recent adjustments and new changes around the corner....

Read More

1 min read

Updates to New York’s Data Breach Notification Law Explained

In December 2024, New York Governor Kathy Hochul signed two bills amending the state’s current data breach notification law. Senate Bill S2659B and...

Read More

1 min read

Saddle Up, Montana: Original 2024 State Privacy Laws Get a Makeover in 2025

Montana implemented the Montana Consumer Data Privacy Act (MCDPA) on October 1, 2024. The law regulates businesses that produce products or services...

Read More

1 min read

Kaiser Foundation Hospitals FCRA $4M Class Action Settlement

Kaiser Foundation Hospitals or Kaiser Foundation Health Plan (“Kaiser”) have agreed to pay more than $4 million as part of a settlement resolving a...

Read More