California 2025-2026 Regular Session

California Senate Bill SB446

Introduced
 
Introduced
2/18/25  
Refer
2/26/25  
Report Pass
4/2/25  
Refer
4/3/25  
Report Pass
4/2/25  
Refer
4/3/25  
Engrossed
5/28/25  
Refer
6/5/25  
Report Pass
6/25/25  
Refer
6/25/25  
Report Pass
7/9/25  
Refer
7/9/25  
Report Pass
8/20/25  
Enrolled
8/28/25  
Chaptered
10/3/25  

Caption

An act to amend Section 1798.82 of the Civil Code, relating to personal information.

Summary

SB 446 amends California Civil Code Section 1798.82, the state’s data-breach notification law, to impose a firm outer deadline for notifying affected California residents after a breach is discovered or reported. Under the bill, notice must generally be provided within 30 calendar days, rather than simply “without unreasonable delay,” while still allowing delay when needed for legitimate law-enforcement purposes or to determine the scope of the breach and restore system integrity. The bill also retains and clarifies existing notice content requirements, including plain-language formatting, required headings, and information about the breach, the types of personal information involved, and consumer resources such as credit reporting agency contacts when sensitive identifiers are exposed. The bill also changes the timing for reporting larger breaches to the Attorney General. When a breach affects more than 500 California residents, the responsible business or individual must electronically submit a sample copy of the consumer notice to the Attorney General within 15 calendar days after notifying consumers, rather than under the prior timing framework. The statute continues to cover a broad range of personal information, including Social Security numbers, driver’s license and state ID numbers, financial account credentials, medical and health insurance information, biometric data, genetic data, and online account login credentials. It also preserves existing exceptions and alternative notice methods, including substitute notice and special rules for email-account breaches and HIPAA-covered entities. In practical terms, the bill tightens the state’s breach-notification timeline for businesses and other entities that maintain computerized personal information on California residents. It affects any business or individual conducting business in California that owns or licenses such data, and it reinforces obligations to notify consumers, data owners, and the Attorney General after a qualifying breach. Because the measure amends an existing statute rather than creating a new regulatory scheme, its impact is primarily to make the timing of breach disclosures more definite and to standardize the Attorney General submission deadline. The overall sentiment around SB 446 appears strongly favorable and noncontroversial. The voting record shows unanimous support at each recorded stage, including committee votes and floor action, and the bill ultimately passed on the consent calendar. There is no committee transcript in the provided materials showing substantive opposition or debate, which suggests the measure was viewed as a straightforward consumer-protection and administrative-timing update. No major points of contention are evident in the available record. The main policy choice in the bill is whether to replace the prior flexible “without unreasonable delay” standard with a fixed 30-day deadline, balanced by exceptions for law enforcement and incident investigation. Any potential concern would likely center on whether the deadline is too rigid for complex breaches, but the bill’s unanimous votes indicate that any such concerns did not generate visible opposition in the legislative process.

Impact

SB 446 amends Civil Code Section 1798.82 to require breach notices to California residents within 30 calendar days of discovery or notification, subject to limited delays for law enforcement or breach investigation, and to require sample notice submissions to the Attorney General within 15 calendar days after consumer notice for breaches affecting more than 500 residents. It updates the timing and administration of California’s data-breach notification requirements for businesses and other entities handling personal information, while leaving the underlying scope of covered personal information, notice content, and existing exceptions largely intact.

Sentiment

The bill appears to have enjoyed broad bipartisan and procedural support throughout the legislative process. Recorded votes were unanimous at each stage, and the bill advanced to chaptered status on the consent calendar, indicating little to no visible opposition. The absence of committee transcript material also suggests the measure was treated as a routine consumer-protection and reporting update rather than a contested policy change.

Contention

No significant contention is evident in the provided record. The only potentially debatable issue is the shift from a flexible “most expedient time possible and without unreasonable delay” standard to a fixed 30-day deadline for consumer notice, which could raise implementation concerns for complex breaches. However, the unanimous votes and consent-calendar passage indicate that any concerns about operational burden, law-enforcement needs, or investigation timing were either resolved through the bill’s exceptions or were not politically significant.

Companion Bills

No companion bills found.

Similar Bills

No similar bills found.