US State Law California, USA

CCPA Private Right of Action: Breach Lawsuits Explained

When California consumers can sue under Civ. Code 1798.150: statutory damages of $100-$750 per consumer, the reasonable-security trigger, and defense strategy.

Regulation

Cal. Civ. Code 1798.150 (CCPA private right of action)

Max Penalty

Statutory damages of $100-$750 per consumer per incident, or actual damages if greater, plus injunctive relief

Enforcing Authority

California courts (private litigation); CPPA/AG enforce the rest of the CCPA

Official Source

cppa.ca.gov

Executive Summary

  • Section 1798.150 lets consumers sue only for data breaches: unauthorized access and exfiltration, theft, or disclosure of nonencrypted and nonredacted personal information resulting from failure to maintain reasonable security.
  • Statutory damages run $100 to $750 per consumer per incident without proving actual harm, which converts even mid-size breaches into eight-figure class exposure.
  • 'Personal information' here is the narrower breach-statute definition (Civ. Code 1798.81.5): name plus SSN, driver's license, financial account with access code, medical or health insurance info, biometric data, or credentials, not the CCPA's broad definition.
  • A 30-day cure notice is required before claiming statutory damages, but courts have held that a completed breach generally cannot be 'cured,' limiting the defense.
  • Encryption is the structural defense: the right attaches only to nonencrypted, nonredacted data, so strong encryption at rest removes the statutory-damages threat.

The CCPA’s most expensive sentence is one businesses rarely read until a breach: statutory damages of $100 to $750 per consumer per incident, no injury required. Section 1798.150 quietly federalized nothing and changed everything in California breach litigation, replacing the old fight over standing and damages with simple multiplication. Understanding its narrow trigger, and the encryption off-switch built into it, is the difference between a manageable incident and a bet-the-quarter class action.

ProvisionCal. Civ. Code 1798.150
TriggerBreach of nonencrypted, nonredacted PI due to unreasonable security
Damages$100-$750 per consumer per incident, statutory
Covered data1798.81.5 categories (SSN, DL, financial, medical, biometric, credentials)
Statute textCiv. Code 1798.150

How the claim works in practice

The narrow data definition is the first battleground. Email-plus-password breaches qualify (credentials); marketing-database breaches of names and emails alone generally do not. Plaintiffs plead broadly; early motions turn on whether the exfiltrated fields match 1798.81.5.

“Resulting from” makes security the merits. Unlike strict-liability statutes, 1798.150 requires the breach to result from failure to maintain reasonable security appropriate to the data. A documented, benchmarked program is both compliance and litigation defense; its absence, discoverable through post-incident forensics, is the plaintiff’s case.

The cure notice rarely saves defendants. Statutory-damages plaintiffs must give 30 days’ notice and an opportunity to cure. Businesses argue remediation; courts have reasoned that exposure of data cannot be undone, so the cure defense mostly helps against alleged ongoing security failures, not completed breaches. Actual-damages claims need no notice at all.

It stacks with everything else. The same incident triggers California’s breach-notification statute, AG scrutiny, CCPA administrative enforcement for related notice failures, and, for biometric data, potential BIPA-style claims if Illinois residents are involved. National incidents get a state-by-state overlay; the state enforcement tracker maps the public-enforcement side.

The engineering answer

Because the right attaches only to nonencrypted, nonredacted data, encryption is worth more than any policy: full encryption at rest for 1798.81.5 categories, tokenization of payment and SSN fields, and TLS everywhere effectively deletes the statutory-damages exposure even when attackers get in. Pair it with aggressive retention limits, data you deleted cannot be exfiltrated, and an inventory that knows where qualifying categories live. A free scan helps with the outer layer: what your public-facing systems collect and where they send it.

Frequently Asked Questions

Can consumers sue for any CCPA violation?

No. The private right covers only qualifying data breaches; opt-out failures, notice defects, and rights violations belong exclusively to the CPPA and Attorney General. Plaintiffs' lawyers sometimes plead other CCPA violations through California's Unfair Competition Law, but courts have generally rejected using the UCL to bootstrap non-breach CCPA claims because the statute reserves them to public enforcement.

What must a plaintiff actually prove?

Four elements: (1) their nonencrypted and nonredacted personal information (as defined in 1798.81.5), (2) was subject to unauthorized access and exfiltration, theft, or disclosure, (3) resulting from the business's violation of the duty to maintain reasonable security procedures, and (4) for statutory damages, that they served a 30-day written cure notice. No injury proof is needed for statutory damages, the provision's whole point.

What is 'reasonable security'?

The statute does not define it, but California's 2016 AG breach report declared the CIS Critical Security Controls the floor: failure to implement applicable controls 'constitutes a lack of reasonable security.' In litigation, plaintiffs benchmark against CIS/NIST and the business's own promises; multifactor authentication gaps, flat networks, and unpatched known CVEs are the recurring exhibits.

How does the exposure math work?

$100-$750 per consumer per incident, whichever of statutory or actual damages is greater. A breach touching 100,000 Californians' qualifying data carries a statutory range of $10M to $75M before defense costs, which is why post-2020 California breach class actions settle earlier and higher than their pre-CCPA equivalents. Courts weigh willfulness, duration, and wealth of the defendant when setting the per-consumer figure.

What should defense-minded compliance look like?

Encrypt qualifying data at rest and in transit (removes the claim), minimize retention of 1798.81.5 categories, document a security program mapped to CIS Controls (defeats the 'unreasonable security' element), segment and log so exfiltration can be disproven, and rehearse the cure-notice response window. Cyber insurance should be sized against per-consumer statutory math, not average breach cost studies.

Regulatory Crosswalk

CCPABIPAState breach notification laws

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.