Email

rdd@dijuliolaw.com

Monday - Sunday

9:00am - 6:30pm

Cybersecurity Incident Response

Cybersecurity & Data Privacy Law

Data Breach & Incident Response Attorney — Los Angeles

Under Civil Code section 1798.82, a business must generally notify affected California residents within 30 calendar days of discovering a breach of their unencrypted personal information, and send the Attorney General a sample notice when more than 500 residents are notified. DiJulio Law Group directs breach response for Glendale and Los Angeles businesses.

The Short Answer

When must a California business notify people of a data breach?

Under Civil Code section 1798.82, as amended effective January 1, 2026, a business must notify California residents within 30 calendar days of discovering that their unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person, subject to limited delays the statute permits, such as for law enforcement. If more than 500 Californians are notified in a single breach, a sample copy of the notice must be submitted to the Attorney General within 15 calendar days.

Cybersecurity & Data Privacy Law

Directing a Breach Response Under California Law

Incident response is a legal process supported by technical work, not the reverse. Counsel directs the forensic investigation so that findings are developed under privilege where available, establishes what categories of data were actually affected, determines which notification obligations are triggered in which jurisdictions, and manages communications with insurers, regulators, and affected parties.

California's statute is precise about what counts. Notification turns on unencrypted personal information as defined by statute, on acquisition rather than mere access in some circumstances, and on specific content requirements for the notice itself. Over-notifying creates unnecessary litigation exposure; under-notifying creates regulatory and statutory exposure. The distinction requires knowing what the forensics actually established, not what they initially suggested.

Post-incident, the same facts frequently generate follow-on claims: statutory claims under California's privacy laws, contractual claims from business customers under data protection addenda, and vendor claims where a third party caused the incident. Those are handled through privacy and cybersecurity litigation, informed by the record built during response.

An incident rarely stays a technical problem. When affected individuals or business customers bring claims, the response record becomes the foundation of data privacy and cybersecurity litigation. The regulatory backdrop is covered on our cybersecurity and data privacy law page, and our analysis of the General Motors OnStar CCPA enforcement matter shows how California regulators approach the handling of consumer data.

Breach response also touches the rest of the business. Vendor and customer contracts allocate who pays for an incident, which is why the firm reviews data-protection terms as part of business contracts and transactions. Boards and owners answer for oversight under corporate governance principles, and a buyer evaluating a target with a history of incidents should address it in legal due diligence. Where the facts support it, claims against a responsible vendor are pursued through business litigation or breach of contract actions. The firm advises California companies across business and corporate law from its Glendale office; contact the firm if an incident is under way.

Civil Code § 1798.82

What California's Data Breach Notification Law Requires

California Civil Code section 1798.82 requires a business to notify California residents whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person. As amended effective January 1, 2026, notice is due within 30 calendar days of discovery or notification of the breach, subject to law enforcement and scoping delays.

The 30-day deadline replaced the earlier standard of notice "in the most expedient time possible and without unreasonable delay."

The statute also fixes the form of the notice. It must be written in plain language, titled "Notice of Data Breach," and organized under the headings "What Happened?", "What Information Was Involved?", "What We Are Doing," "What You Can Do," and "For More Information," in type no smaller than 10-point. At a minimum it must identify the business, list the types of personal information involved, give the date, estimated date, or date range of the breach if known, state whether notice was delayed by a law enforcement investigation, and describe the incident generally.

When a single breach requires notice to more than 500 California residents, a sample copy of the notice, without personal information, must be submitted electronically to the Attorney General within 15 calendar days of notifying consumers, through the Attorney General's data breach reporting page (opens in a new tab). Breaches exposing Social Security, driver's license, or California ID numbers carry added content requirements, including credit bureau contact information and, where the business was the source of the breach, an offer of identity theft prevention services at no cost for at least 12 months. Read the full text of Civil Code section 1798.82 (opens in a new tab) before drafting.

Ransomware

Who Handles Ransomware Response in California?

Ransomware response is usually led by counsel working with a forensic firm, the cyber insurer, and law enforcement. Counsel retains the forensic team so findings are developed under privilege where the law allows, determines whether data was acquired rather than only encrypted, manages insurer notice, and evaluates sanctions risk before any payment is considered.

Ongoing compliance obligations after the incident, including vendor contracts and security program changes, are handled through our cybersecurity and data privacy practice.

  • Contain and preserve: isolate affected systems without wiping them, and keep logs, the ransom note, and every communication with the threat actor.
  • Privilege: retain forensic vendors through counsel so their work supports legal advice, which also protects the record if the incident later becomes privacy and cybersecurity litigation.
  • Notification analysis: files encrypted in place are different from files copied out. Whether personal information was acquired generally drives whether Civil Code section 1798.82 notice is required.
  • Law enforcement: report the attack to the FBI through its Internet Crime Complaint Center (IC3) or to CISA, and document the report.
  • Insurer notice: cyber policies typically impose prompt-notice conditions and may require the carrier's consent before costs are incurred or any payment is made.
  • Sanctions: Treasury's Office of Foreign Assets Control has warned that ransomware payments to sanctioned persons can violate U.S. sanctions on a strict liability basis, and it treats a prompt, complete report to law enforcement and full cooperation as significant mitigating factors (OFAC updated ransomware advisory (opens in a new tab)).
Office

330 North Brand Boulevard, Suite 1280
Glendale, California 91203

Courts

Los Angeles County Superior Court, including the Glendale and Stanley Mosk courthouses.

Focus

Breach response, California privacy compliance, privacy litigation, and intellectual property disputes.

What We Handle

Incident Response Matters We Handle

For California businesses, professional practices, and organizations handling personal information.

Privileged Investigation

Retaining and directing forensic vendors under counsel so investigative findings are developed within privilege to the extent California and federal law permit.

Notification Analysis

Determining whether statutory triggers are met, which states and regulators are implicated, and what the notice must contain and when it must issue.

Regulator Communications

Submissions to the California Attorney General, responses to inquiries from the California Privacy Protection Agency, and coordination with other state regulators.

Vendor & Contract Claims

Pursuing or defending claims against processors and service providers under data protection addenda, indemnity clauses, and security commitments.

Insurance Coordination

Timely notice to cyber carriers, panel counsel and vendor approval requirements, and preserving coverage for response costs and defense.

Post-Incident Remediation

Contract, policy, and vendor management changes that reduce recurrence and demonstrate a reasonable security program if the incident is later examined.

Situations We See

Incidents That Reach Our Office

Composite examples drawn from the kinds of matters this practice handles. They illustrate common fact patterns and are not descriptions of specific client cases or predictions of any result.

01

The Business Email Compromise

A finance mailbox is compromised and a fraudulent wire is sent. Beyond recovering the funds, the exposure is the mailbox contents: whether personal information sitting in years of email was accessible determines the notification analysis.

02

The Vendor's Breach

A payroll or IT vendor suffers an incident affecting a Los Angeles company's employee data. Notification obligations generally run to the business, while the recovery runs against the vendor under the contract.

03

The Ransomware Decision

Systems are encrypted and data is exfiltrated. Whether to pay, what was actually taken, what must be notified, and what to tell customers are legal decisions with regulatory and litigation consequences.

When to Get Advice

When to Call About an Incident

  • You have detected unauthorized access, encryption of systems, or data exfiltration.
  • A vendor has reported an incident affecting your data.
  • A forensic firm has been engaged without counsel directing the work.
  • You are unsure whether the incident triggers California notification duties.
  • A regulator or attorney general has made an inquiry.
  • Affected individuals or business customers have begun making demands.
Practical Next Steps

What to Do First

  1. Preserve and contain

    Preserve logs and images before remediation overwrites them. Containment and evidence preservation are not in conflict if sequenced correctly.

  2. Engage counsel before forensics

    Retaining the forensic vendor through counsel is what supports a privilege position. Reversing the order afterward is generally not possible.

  3. Notice the carrier immediately

    Cyber policies impose short notice periods and vendor approval requirements. Late notice or unapproved vendors can jeopardize coverage.

Case Studies

Related Case Studies

Court decisions and legal developments DiJulio Law Group has analyzed that bear on cybersecurity incident response matters. Each summary explains the law; none describes a firm client or result.

Common Questions

Cybersecurity Incident Response — Questions California Clients Ask

What California businesses ask in the first days after a security incident.

What does California's data breach notification law require?

Civil Code section 1798.82 requires a business to notify California residents when their unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person. Since January 1, 2026, notice is due within 30 calendar days of discovery, subject to law enforcement and scoping delays. The notice must be titled "Notice of Data Breach" and use the statutory headings, and if more than 500 residents are notified, a sample copy goes to the Attorney General within 15 calendar days.

What is the California Consumer Privacy Act (CCPA) and how does it relate to breach response?

The CCPA (as amended by the CPRA) gives California residents rights over their personal information and imposes obligations on covered businesses regarding data collection, use, and disclosure. Businesses that fail to implement reasonable security measures and suffer a breach exposing personal information may be subject to statutory damages of $100–$750 per consumer per incident under the CCPA's private right of action.

What should a business do immediately after discovering a cybersecurity incident?

Immediate steps include containing the incident to prevent further damage, preserving logs and forensic evidence, notifying legal counsel, evaluating notification obligations and their deadlines, retaining a qualified incident response firm, and reviewing applicable cyber insurance coverage. Prompt coordination between legal, technical, and executive stakeholders is critical.

What is attorney-client privilege in the context of a cyber incident investigation?

Engaging an attorney to direct the cybersecurity investigation and incident response can allow communications and investigative findings to be protected by attorney-client privilege. Retaining technical forensic experts through legal counsel — rather than directly — can help preserve these protections and reduce the risk that investigation findings become discoverable in subsequent litigation.

What cyber insurance coverage should California businesses carry?

Cyber liability policies typically cover first-party costs (breach notification, forensic investigation, business interruption, ransomware response) and third-party claims (lawsuits by affected individuals or regulatory actions). Coverage terms, exclusions, and sublimits vary significantly by policy. An attorney can help evaluate coverage and maximize recovery following an incident.

Who handles ransomware response in California?

Ransomware response is usually led by counsel coordinating a forensic firm, the cyber insurer, and law enforcement. Counsel retains investigators so findings are developed under privilege where the law allows, determines whether personal information was acquired and notice is required, handles insurer notice and consent requirements, and evaluates sanctions risk, because the Treasury Department's Office of Foreign Assets Control has warned that ransom payments to sanctioned persons can violate U.S. sanctions.

Can a business be held liable if it is hacked?

Yes. Businesses that fail to implement reasonable security measures can face liability under the CCPA, common law negligence, or breach of contract theories if a cybersecurity incident results in the compromise of customer, employee, or third-party personal information. The reasonableness standard considers the nature of the data held and accepted industry security practices.

What is CCPA/CPRA compliance and how does it reduce legal risk?

Compliance with the CCPA and CPRA (including having an updated privacy policy, honoring consumer rights requests, limiting data collection, implementing data security measures, and executing required vendor contracts) can reduce the risk of regulatory action and class litigation following a breach, and demonstrates that the business took reasonable steps to protect personal information.

DiJulio Law Group

Talk to a Data Privacy Attorney

If an incident is in progress, the sequence of the next few decisions matters more than any of them individually. Call the office directly.