When, Not If: California’s Mandatory Protocol for Data Breaches

Words are funny things.

If you are asked what your California firm will do IF your data is breached, then you’re tempted to say that the question doesn’t apply because your firm’s data will NEVER be breached. After all you have multiple security certifications, which means your data is 100% protected…right?

Google Gemini.

Tell that to Cushman & Wakefield, The Moody Bible Institute of Chicago, Station Casinos, UCLA Health, or any of a myriad of firms that reported data breaches in accordance with California law. Or better still, check with the companies that failed to report data breaches under California law.

But if you are asked what your California firm will do WHEN your data is breached, then you will be forced to develop an action plan. Which is a good thing.

Six items in your data breach action plan

The first thing in your action plan should hopefully be obvious: secure the breach! Revoke compromised access credentials. Preserve digital evidence for forensic investigation.

Second, determine the damage. Was any unencrypted personally identifiable information (PII) or protected health information (PHI) leaked? Or pretty much the same thing: were any decryption keys leaked with encrypted data?

Third, notify.

  • Under California SB 446, a firm must notify affected California residents within 30 calendar days of discovering or being alerted to the breach.
  • The notice must be in plain language, formatted for high visibility (at least 10-point font), and titled explicitly: “Notice of Data Breach.”
  • The notice must include five mandated headings:  What Happened⁠, What Information Was Involved⁠, What We Are Doing⁠, What You Can Do⁠, and For More Information⁠.
  • If certain PII is breached, you must offer at least 12 months of free identity theft prevention/mitigation services and provide instructions on how to enroll.
Google Gemini.

Fourth, notify. You’re not done notifying yet. If the breach affects more than 500 California residents, the firm must electronically submit a sample copy of the notification letter (with PII redacted) to the California Attorney General’s portal within 15 calendar days of notifying individuals.

Fifth, notify. If PHI was breached, add the California Department of Public Health (CDPH) to your notification list.

Sixth, notify. If you manage third party data, notify the data owner. (And the data owner will need to perform all the notifications above. The fun of third-party risk management.)

Can Bredemarket help you prepare your action plan?

Yes.

I’m not a lawyer.

But I am a writer.

And I write processes, including privacy processes.

Talk to me.

Leave a Comment