Back to the hub

Does the CCPA still have a cure period?

The CPRA removed the CCPA's mandatory 30-day cure period, effective January 1, 2023, so the California Privacy Protection Agency and Attorney General no longer must let a business fix a violation before fining it. One narrow cure step remains: a consumer must give 30 days' written notice before suing for data-breach statutory damages.

Applies to: Businesses subject to the CCPA and CPRA that want to know whether they get a chance to fix a violation before enforcement, and consumers weighing a data-breach claim under Section 1798.150.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Founding 30% off with code FOUNDING until 15 August 2026

Founders often assume that a first privacy mistake earns a warning and a grace period to fix it. Under the CCPA that assumption is now wrong. The 30-day cure period that businesses relied on in the early years is gone for agency enforcement, and only a single, narrow cure step survives for one kind of lawsuit. Here is what changed and what still applies.

Does the CCPA still have a cure period?

For enforcement by the California Privacy Protection Agency or the Attorney General, no. When the CCPA first took effect, a business that received notice of an alleged violation had 30 days to cure it before the state could seek penalties. That mandatory cure period no longer exists. The current text of Cal. Civ. Code Section 1798.155 sets out administrative fines and says nothing about a right to cure, which means the agency can move straight to a penalty for a first violation.

What changed when the CPRA took effect?

The California Privacy Rights Act, the ballot measure that amended the CCPA, removed the mandatory 30-day cure period effective January 1, 2023. In its place, whether to allow a cure is discretionary. The agency may weigh a business's lack of intent and any voluntary effort to fix the problem when it decides on a penalty, but a business no longer has an automatic right to that window. The practical effect is that compliance has to be in place before a complaint arrives, not assembled afterward.

The one cure step that remains

There is a single exception, and it sits in the consumer lawsuit path rather than agency enforcement. The CCPA gives consumers a private right of action only for certain data breaches. Under Cal. Civ. Code Section 1798.150(b), before a consumer files a statutory-damages claim, they must give the business 30 days' written notice identifying the provisions alleged to be violated. If a cure is possible and the business actually cures within those 30 days and provides a written statement that the problem is fixed and will not recur, the individual statutory-damages action cannot go forward. Adding reasonable security only after the breach does not, on its own, count as a cure.

What this means for your business

Treat the CCPA as a law you comply with continuously, not one you patch after a notice. That means having a process ready for the consumer rights you must honor, such as the right to know and the right to correct, before a complaint arrives. The exposure is real: administrative fines run up to $2,500 per violation, or $7,500 for an intentional violation or one involving a consumer under 16, and those figures are described on the fines and penalties page. Knowing whether the law even applies to you is the first step, and the California privacy overview explains the thresholds.

Next step

If you are not sure whether the CCPA reaches your business or where your gaps are, the free 2-minute Obligation Scan checks your profile against the California thresholds and flags the duties most likely to draw enforcement. The US state privacy laws hub sets the wider picture across states.

Compliance checklist

  • Do not assume you will get 30 days to fix a CCPA problem: since January 1, 2023 there is no mandatory cure period for agency enforcement.
  • Treat compliance as continuous, because the California Privacy Protection Agency can fine a first, uncured violation up to $2,500, or $7,500 if it is intentional or involves a consumer under 16.
  • If you receive a consumer's 30-day written notice about a data breach, act inside the window: an actual, written-confirmed cure can stop an individual statutory-damages claim under Section 1798.150(b).
  • Keep records of good-faith compliance efforts, since the agency may still consider voluntary cooperation and any cure when it decides on penalties.
  • Fix the root cause, not just the noticed instance, because adding reasonable security after a breach does not by itself count as a cure.

Sources

Last verified: 2026-08-06

Informational, not legal advice.