Under the CCPA as amended by the CPRA, a startup asks whether it gets 30 days to fix a violation — does it?
answer
- right, or discretion?
- the CPRA removed something
- the agency may offer time
- one 30-day cure survives
- 1798.199.45 and 1798.150(b)
basics
~20 sUnder the CCPA as amended by the CPRA, not as of right: the Attorney General's mandatory 30-day cure is gone, the CPPA may offer time to cure at its discretion (1798.199.45), and only the breach lawsuit keeps a 30-day notice-and-cure (1798.150(b)).
solid answer
~50 sThe original 2018 CCPA gave a business **30 days to cure** after the Attorney General notified it of an alleged violation. The CPRA removed that guarantee: the Attorney General's civil-penalty section today, 1798.199.90, has no cure step. The **CPPA** may decide not to investigate a complaint or to **provide a time period to cure**, weighing **lack of intent** and **voluntary efforts to cure** before the agency's notice (1798.199.45(a)); that is discretion, not a right. The 30-day notice before a probable-cause proceeding (1798.199.50) is due process, not a cure window. The only statutory 30-day cure left is in the breach private right of action: before a consumer sues for **statutory damages**, they give 30 days' written notice, and a real cure blocks those damages, though adding security after a breach does not count (1798.150(b)). So the startup should fix the problem now and document it; good-faith cooperation lowers amounts (1798.199.100).
go deeper
Recall that the CPRA ended the guaranteed 30-day cure for Attorney General actions, and that cure is now at the CPPA's discretion.
Explain the factors in 1798.199.45 and why the probable-cause notice and the breach-lawsuit notice are different things.
Advise on remediation timing: fix before notice, document it, and never count on a post-breach fix to cure a lawsuit.
Build a compliance programme that detects and fixes violations itself, since the law now rewards voluntary cure rather than promising one.
## The short answer Under the CCPA as amended by the CPRA, **no business has a general right to 30 days to fix a violation**. There is one statutory notice-and-cure left, and it belongs to the breach private right of action. Everywhere else, time to cure is something the **California Privacy Protection Agency (CPPA)** *may* give, not something the business is owed. ## What changed | | Original CCPA (2018 text) | CCPA as amended by the CPRA | |---|---|---| | Attorney General action | business had 30 days after notice to cure before liability | **no cure step** in 1798.199.90 | | Administrative enforcement | no agency existed | CPPA **may** offer a cure period at its discretion (1798.199.45(a)) | | Breach private right of action | 30-day notice and cure before statutory damages | **still there**, and post-breach security is expressly **not** a cure (1798.150(b)) | The CPRA's amendments became operative on 2023-01-01. A compliance plan written around the old guaranteed cure is working from a rule that no longer exists. ## The CPPA's discretionary cure Civil Code **1798.199.45(a)** lets the agency, on a sworn complaint or its own initiative, investigate possible violations. It *may decide not to investigate a complaint or decide to provide a business with a time period to cure the alleged violation*, and in making either decision it may consider: 1. **Lack of intent** to violate the CCPA. 2. **Voluntary efforts** by the business to cure the alleged violation **before** being notified of the complaint. The regulations widen what the agency may weigh when deciding whether to pursue an investigation: *all facts it determines to be relevant*, including the **time since the requirement took effect** and **good-faith efforts to comply** (11 CCR 7301(b)). Two features matter. The word is *may*, so there is no entitlement. And the second factor rewards fixing problems **before** the agency calls, which is the opposite of waiting for a notice to start a clock. ## The 30-day windows that remain, and what they are - **Probable-cause notice (1798.199.50).** The agency cannot find probable cause unless the business was notified at least **30 days before** the agency considers the alleged violation, with a summary of the evidence and the right to attend with counsel. That is a due-process notice before a hearing, **not** a period in which fixing the problem erases liability. - **Breach lawsuit notice (1798.150(b)).** Before a consumer sues for **statutory damages**, individually or class-wide, they give **30 days' written notice**. If a cure is possible and the business actually cures and gives an express written statement that the violation is cured and will not recur, the statutory damages action is barred. **Implementing reasonable security after the breach is not a cure** of that breach, and no notice at all is needed for an individual suit solely for actual pecuniary damages. ## A timeline that shows the difference Suppose the startup discovers in March that its request web form has silently dropped requests to delete since January. 1. **March, before any complaint:** it fixes the form, processes the backlog and records what happened. Under 1798.199.45(a)(2) that is a voluntary effort to cure **before** notification, a factor the agency may weigh. 2. **June, a sworn complaint arrives:** the agency may decline to investigate or may offer a cure period, but it is not obliged to do either. 3. **Had the startup waited** for the complaint, the same fix would no longer count as a pre-notice effort, and the Attorney General could sue with no cure step at all. ## What the startup should actually do - **Fix now, not on notice.** Voluntary efforts before notification are a factor the agency may weigh (1798.199.45(a)(2)). - **Document the fix**: what was wrong, when it was found, what changed, and when. The same record supports good-faith arguments later. - **Cooperate.** The agency and any court must consider **good-faith cooperation** in setting a fine or penalty (1798.199.100). - **Do not rely on a cure for breaches.** Security that arrives after a breach does not cure it for the private action. ## Misconceptions - That every violation carries a guaranteed 30-day cure. - That the probable-cause notice is a cure window. - That a fix made after the agency calls erases liability. - That a post-breach security upgrade cures a 1798.150 claim.
- Under the CCPA, what may the CPPA weigh when deciding whether to give a business time to cure?Civil Code 1798.199.45(a) names **lack of intent** and **voluntary efforts to cure before notification**. When deciding whether to pursue an investigation, 11 CCR 7301(b) lets it weigh all relevant facts, including time since the requirement took effect and good-faith efforts to comply.
- Under the CCPA, does the 30-day notice before a CPPA probable-cause proceeding let the business avoid a fine by fixing the problem?No. Civil Code 1798.199.50 requires notice at least 30 days before the agency considers probable cause, with a summary of evidence and the right to counsel. It protects the business's right to be heard; nothing in it makes a fix within those 30 days a bar to liability.
saying these in an interview costs you the question
- Every CCPA violation comes with a guaranteed 30-day cure period.
- The Attorney General must still offer 30 days to cure before suing.
- The 30-day probable-cause notice is a chance to cure and avoid liability.
- Adding reasonable security after a breach cures a 1798.150 claim.
- Fixing a problem only after the agency's notice carries the same weight as fixing it first.