The California Consumer Privacy Act, as amended by the CPRA, gives California residents rights over personal information businesses hold about them. Its distinctive feature for litigators is a private right of action for breaches caused by a failure to maintain reasonable security, with statutory damages that do not require proving loss.
The provision that generates litigation
Most of the CCPA is a compliance regime enforced by regulators. One section is not: consumers may sue where certain unencrypted or unredacted personal information is subject to unauthorised access, exfiltration, theft or disclosure as a result of the business's failure to implement and maintain reasonable security procedures.
Two features make this the engine of California breach litigation. Statutory damages are available within a defined per-consumer range without proof of actual harm — which removes the standing and damages problems that sink many breach class actions. And the categories covered are narrower than "personal information" generally, so which data was involved determines whether the section applies at all.
"Reasonable security" is where the forensic work lands
The statute does not define it, which means it is litigated as a factual question about what the business actually did. In practice the assessment looks at recognised frameworks, at what controls were in place versus documented, and at what the organisation knew about its own gaps.
This is why post-incident investigations increasingly examine the security posture as well as the intrusion. The plaintiff's theory is rarely that the attack was sophisticated; it is that a known deficiency went unaddressed. Internal risk registers, penetration test reports, and unactioned audit findings become the central documents — and their existence is usually not in doubt, only their significance.
The corollary for defendants is that documented remediation of known findings is worth considerably more than an unblemished record nobody can evidence.
Encryption and redaction as the statutory gate
The private right of action reaches unencrypted and unredacted information. That makes encryption status a threshold legal fact, not merely a technical detail — and establishing it is a forensic question about what state the data was actually in when accessed.
The qualification matters: where an attacker held administrative credentials, data encrypted at rest may have been accessible in decrypted form, and the safe harbour is considerably narrower than the phrase "we encrypt our data" implies.
The 30-day cure provision
The original statute allowed a business 30 days to cure a violation after written notice, and the CPRA narrowed how that operates. It has never applied straightforwardly to a breach: the practical difficulty is that once data has been exfiltrated there is nothing to cure. Treating the notice period as a reliable off-ramp has not worked well for defendants.
Beyond California
A large majority of US states now have comprehensive privacy statutes, most modelled loosely on this one, and most without a private right of action. The compliance obligations therefore multiply across states while the litigation exposure remains concentrated in California — which is why breach class actions continue to be filed there, and why knowing which residents' data was involved is one of the first questions an incident response has to answer.
From our work
Dealing with ccpa in a live matter?
Our examiners and testifying experts work these questions for a living. Tell us what you're facing.
Reviewed by Law & Forensics. See our editorial standards.
