Email

rdd@dijuliolaw.com

Monday - Sunday

9:00am - 6:30pm

Data Privacy & Cybersecurity Litigation

Cybersecurity & Data Privacy Law

Data Privacy Litigation Attorney — Los Angeles & California

California has the most active privacy litigation environment in the country. The exposure is frequently statutory and per-consumer, which means the number of records determines the number that matters.

The Short Answer

Can consumers sue a business over a data breach in California?

Yes. The California Consumer Privacy Act creates a private right of action allowing consumers to seek statutory damages when specified categories of unencrypted personal information are exposed through a business's failure to maintain reasonable security. Consumers also bring common law negligence and contract claims, and California's Invasion of Privacy Act is widely used against website tracking and session-recording technologies.

Cybersecurity & Data Privacy Law

Privacy Claims, Exposure, and Defense in California

Privacy litigation in California runs on statutory damages. Where a claim provides a fixed sum per consumer per incident, the aggregate exposure is a function of record count rather than demonstrable harm — which is why breach class actions are filed quickly and why the reasonable security analysis is the central battleground.

A second wave of California privacy litigation concerns technology on ordinary business websites: chat tools, session replay, analytics pixels, and advertising tags, challenged under the California Invasion of Privacy Act on the theory that data was intercepted or disclosed without adequate consent. These claims reach businesses that have never suffered a breach at all, and the defense usually turns on consent mechanics and how the technology actually functions.

Regulatory enforcement runs alongside private litigation, and the two interact. The Attorney General and the California Privacy Protection Agency both enforce CCPA and CPRA obligations, and public enforcement records frequently inform private claims — as the OnStar data privacy settlement illustrates. Defense coordinates with incident response work where a breach underlies the claim.

Office

330 North Brand Boulevard, Suite 1280
Glendale, California 91203

Courts

Los Angeles County Superior Court, including the Glendale and Stanley Mosk courthouses.

Focus

Breach response, California privacy compliance, privacy litigation, and intellectual property disputes.

What We Handle

Privacy Litigation Matters We Handle

For California businesses defending claims and for parties enforcing data-related contractual rights.

Breach Class Action Defense

Standing, reasonable security, causation, class certification, and the statutory damages framework governing CCPA private claims.

CIPA & Tracking Claims

Defense of wiretapping and pen register theories directed at chat, session replay, pixels, and analytics, focused on consent and how the technology operates.

Regulatory Investigations

Responding to inquiries from the Attorney General and the California Privacy Protection Agency, including cure opportunities where available.

Vendor & Processor Disputes

Enforcement of data protection addenda, security warranties, indemnity, and limitation of liability provisions between businesses.

Consumer Rights Disputes

Disputes over access, deletion, correction, and opt-out requests, and the verification and response requirements that apply to each.

Compliance Assessment

Privacy policy review, consent architecture, data mapping, and vendor terms — the work that reduces exposure before a claim is filed.

Situations We See

Privacy Claims That Reach Our Office

Composite examples drawn from the kinds of matters this practice handles. They illustrate common fact patterns and are not descriptions of specific client cases or predictions of any result.

01

The Pixel Demand Letter

A Los Angeles business receives a demand asserting that its website chat and analytics tools intercepted visitor communications. The defense turns on consent disclosure, how the vendor actually processes data, and the terms in the vendor agreement.

02

The Breach Class Action

Following a vendor compromise, a putative class action is filed asserting statutory damages for tens of thousands of records. The early questions are standing, whether the data was within the statutory categories, and whether security was reasonable.

03

The Deletion Request Dispute

A consumer asserts that deletion and opt-out requests were ignored. What the business can show about its intake, verification, and response process largely determines the outcome.

When to Get Advice

When Privacy Exposure Needs Counsel

  • You have received a privacy demand letter or been served with a class action.
  • A regulator has opened an inquiry into your data practices.
  • Your website uses chat, session replay, analytics, or advertising pixels.
  • A vendor incident has exposed data you collected.
  • Consumer rights requests are arriving faster than you can process them.
  • A business customer has asserted breach of a data protection addendum.
Practical Next Steps

What to Do First

  1. Preserve the technical record

    Vendor configurations, consent banner versions, and policy history change frequently. Preserve the state as of the relevant period immediately.

  2. Map the data

    What was collected, from whom, for how long, and shared with which vendors. Nearly every defense depends on answering this precisely.

  3. Evaluate cure and coverage

    Some claims permit a cure period, and many are covered under cyber or media policies. Both are time-sensitive and easily missed.

Common Questions

Data Privacy & Cybersecurity Litigation — Questions California Clients Ask

What California businesses ask when facing privacy claims, demands, or regulatory inquiries.

What types of lawsuits arise from data breaches in California?

Data breach litigation in California commonly takes the form of class actions asserting violations of the CCPA's private right of action, claims under the Customer Records Act (Civil Code §1798.82), negligence, breach of contract, and unjust enrichment. Regulatory enforcement actions by the California Privacy Protection Agency (CPPA) and Attorney General can run parallel to civil suits.

What is the CCPA private right of action?

The CCPA provides a private right of action for California residents whose unencrypted, unredacted personal information is subject to unauthorized access due to a business's failure to implement and maintain reasonable security. Affected consumers can recover statutory damages of $100 to $750 per consumer per incident (or actual damages, if greater) without proving actual harm.

What is standing in a data breach class action?

Standing requires that a plaintiff have suffered a concrete injury. In data breach cases, courts have accepted standing based on increased risk of identity theft, out-of-pocket mitigation costs, and diminution in the value of personal information. The CCPA private right of action specifically allows statutory damages without proof of actual injury, which is a lower barrier than many other theories.

What defenses are available to a business facing a data breach lawsuit?

Defenses can include challenges to standing, arguments that the business implemented reasonable security practices, evidence that the breach resulted from a sophisticated, unforeseeable attack, lack of causation between the breach and claimed damages, challenges to class certification, and reliance on contractual limitation of liability provisions.

What is a cyber insurance tender and how does it affect litigation?

A cyber insurance tender is the formal process of notifying your insurer of a covered incident and requesting defense and indemnification. Insurance carriers often have significant influence over litigation strategy and settlement decisions. Early and complete tender — following all notice obligations in the policy — is critical to maximizing available coverage.

How long does data breach litigation typically last?

Class actions can take several years from filing through settlement or trial. Early settlement is common in data breach cases because of the cost of litigation, the reputational risk of prolonged proceedings, and the business interest in certainty. Individual disputes involving smaller companies may resolve faster through negotiation or arbitration.

What is BIPA and does it apply to California businesses?

The Illinois Biometric Information Privacy Act (BIPA) is a state law that applies to the collection and use of biometric data (such as fingerprints or facial recognition) in Illinois. While it is an Illinois law, California employers and technology companies with Illinois-based employees or customers may face BIPA exposure in addition to their California obligations.

Can a business enforce an arbitration agreement against a class of data breach plaintiffs?

In many cases, yes — if the business's consumer agreements include a valid class action waiver and arbitration clause. Courts have generally enforced such clauses in data breach cases, though some jurisdictions have found them unenforceable in specific contexts. Whether an arbitration agreement can defeat class certification depends on its scope, enforceability, and applicable law.

Where We Practice

Local Representation

California privacy statutes reach businesses handling Californians' data, and claims are frequently filed in the Los Angeles County courts.

DiJulio Law Group

Talk to a Data Privacy Attorney

Privacy demands escalate quickly and cure windows are short. Bring the demand and your current privacy documentation.