skip to content

Under the CCPA, an unencrypted database breach exposes California residents' names, email addresses and passwords — can they sue, and for what damages?

level: seniorimportance: must knowfreq 50%

answer

  1. the one door consumers can open
  2. which data, and why it leaked
  3. reasonable security is the hinge
  4. per consumer per incident
  5. 30 days' written notice first

basics

~20 s

Under the CCPA, yes if specified unencrypted data, or an email plus a password permitting account access, was stolen or disclosed because security was unreasonable: $107-$799 per consumer per incident (2025 adjustment) or actual damages (Civil Code 1798.150).

solid answer

~50 s

Civil Code **1798.150** is the CCPA's only private right of action. A consumer can sue when their **nonencrypted and nonredacted** personal information of the kinds listed in Civil Code 1798.81.5(d)(1)(A), or their **email address with a password or security question and answer that would permit access to the account**, suffers **unauthorized access and exfiltration, theft, or disclosure** *as a result of* the business failing to maintain **reasonable security**. Here the email-plus-password branch fits if the passwords would let someone into the accounts. Remedies: statutory damages of **$100-$750** per consumer per incident in the statute's text, **$107-$799** after the 2025 CPI adjustment, or actual damages if greater, plus injunctive or declaratory relief. Before suing for **statutory** damages, individually or as a class, the consumer must give **30 days' written notice**; a genuine cure blocks statutory damages, but adding security after the breach is **not** a cure.

go deeper

for a junior

Recall that the CCPA lets consumers sue only for breaches caused by unreasonable security, with statutory damages per consumer per incident.

for a middle

Explain the two data branches, the causation requirement, and the 2025-adjusted $107-$799 range against the $100-$750 base.

for a senior

Walk through the 30-day notice and cure, why post-breach security is not a cure, and when no notice is needed.

for a principal

Use the per-consumer arithmetic to justify security investment where California residents' credentials and identifiers concentrate.

## The only private right of action Most of the CCPA as amended by the CPRA is enforced by the **California Privacy Protection Agency** and the **Attorney General**. Consumers get one door of their own: Civil Code **1798.150**, *Personal Information Security Breaches*. Subdivision (c) closes every other door: the cause of action applies **only** to the breaches defined in subdivision (a) and *shall not be based on violations of any other section* of the CCPA. ## Which data qualifies 1798.150(a)(1) has two branches: | Branch | Data | Condition in the text | |---|---|---| | 1 | personal information as defined in Civil Code **1798.81.5(d)(1)(A)**, a separate California data-security statute | must be **nonencrypted and nonredacted** | | 2 | a consumer's **email address in combination with a password or security question and answer** | must be such that it **would permit access to the account** | Names on their own are not enough for branch 2; the email-and-password pairing is what the text names. In the scenario, names, emails and passwords together fit branch 2 if the passwords would let an attacker into the accounts, and the name data may matter for branch 1 depending on what else was stored with it. The two conditions point at concrete engineering levers. Branch 1 reaches only **nonencrypted and nonredacted** data, so encrypting or redacting the listed elements narrows it. Branch 2 turns on whether the stored password or security answer **would permit access to the account**, so how credentials are stored bears directly on whether a leaked table fits the text. ## What must have gone wrong Two more elements must be present: 1. **An incident**: the data was subject to *unauthorized access and exfiltration, theft, or disclosure*. 2. **Causation by a security failure**: the incident happened *as a result of the business's violation of the duty to implement and maintain reasonable security procedures and practices appropriate to the nature of the information*. A breach alone is not the claim; the claim is a breach **caused by unreasonable security**. How the security failed, and how the incident is run, are separate engineering subjects; for the CCPA the question is whether the security was reasonable for the data held. ## Damages and other relief Under 1798.150(a)(1) a consumer may recover: - **statutory damages** of not less than $100 and not more than $750 **per consumer per incident**, as printed in the statute, which the CPPA adjusted to **$107-$799** effective 2025-01-01 under 1798.199.95(d); or **actual damages**, whichever is greater; - **injunctive or declaratory relief**; - any other relief the court deems proper. In setting statutory damages, the court considers the circumstances, including the **nature and seriousness** of the misconduct, the **number of violations**, its **persistence** and **duration**, the **willfulness** of the conduct, and the defendant's **assets, liabilities and net worth** (1798.150(a)(2)). ## The 30-day notice and cure Subdivision (b) adds a gate before **statutory** damages: 1. Before suing for statutory damages, individually or class-wide, the consumer gives the business **30 days' written notice** identifying the provisions allegedly violated. 2. If a cure is possible and the business **actually cures** within the 30 days and gives an **express written statement** that the violations are cured and will not recur, no action for statutory damages may be brought. 3. **Implementing reasonable security after the breach does not cure that breach.** 4. **No notice** is needed for an individual action **solely for actual pecuniary damages**. 5. If the business breaches its written statement, the consumer may sue to enforce it and seek statutory damages for each breach of the statement. ## Why the money usually sits here The regulators price each violation; this section prices **each consumer per incident**. With a class of 500,000 California residents, the adjusted statutory floor alone is 500,000 x $107 = **$53.5 million**, and the adjusted ceiling is 500,000 x $799 = **$399.5 million**, before any actual damages argument. That arithmetic is why, for many businesses, the breach lawsuit carries more financial weight than the regulators' per-violation ceilings. ## Misconceptions - Believing any CCPA violation supports a consumer class action. - Believing consumers must prove financial loss to recover; statutory damages exist precisely so they need not. - Believing a post-breach security upgrade within 30 days cures the claim. - Quoting $100-$750 as the current range without saying it is the statutory base.

  • Under the CCPA, the business encrypts the database two weeks after the breach and tells the consumer. Is that a cure under 1798.150(b)?
    No. Civil Code 1798.150(b) says implementing and maintaining reasonable security **following a breach does not constitute a cure** with respect to that breach. The notice-and-cure gate can block statutory damages only where a real cure of the noticed violation is possible.
  • Under the CCPA, a consumer wants only their out-of-pocket losses. Must they send the 30-day notice first?
    No. 1798.150(b) requires no prior notice for an individual action **solely for actual pecuniary damages**. The 30-day notice is a precondition only for statutory damages, whether individual or class-wide.
  • Under the CCPA, can a consumer use 1798.150 to sue a business for ignoring their deletion request?
    No. 1798.150(c) limits the cause of action to the breaches defined in subdivision (a) and says it shall not be based on violations of any other section. The deletion failure is for the CPPA or the Attorney General.

saying these in an interview costs you the question

  • Any CCPA violation lets consumers bring a class action for statutory damages.
  • Consumers must prove actual financial loss to recover under 1798.150.
  • Encrypting the data after the breach cures it within the 30 days.
  • Every breach triggers 1798.150, whatever security the business maintained.
  • Statutory breach damages are still $100 to $750 per consumer per incident.