Does the CCPA have a private right of action?
Yes, but only for data breaches. California Civil Code section 1798.150 lets a consumer sue when nonencrypted, nonredacted personal information is exposed because a business failed to maintain reasonable security. Statutory damages run from $107 to $799 per consumer per incident, as adjusted, or actual damages, whichever is greater.
Applies to: Businesses subject to the CCPA that hold personal information about California consumers, and that would face consumer litigation rather than only agency enforcement if that information is breached.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanMost of the CCPA is enforced by a regulator. One section is not. Section 1798.150 gives consumers their own cause of action, and it is narrow on purpose: it covers a security breach, and nothing else.
What the claim actually covers
Under Section 1798.150(a)(1), a consumer can sue when their nonencrypted and nonredacted personal information, as defined in subparagraph (A) of paragraph (1) of subdivision (d) of Section 1798.81.5, is subject to unauthorized access and exfiltration, theft, or disclosure as a result of the business's violation of the duty to implement and maintain reasonable security procedures and practices appropriate to the nature of the information. The same right covers an email address in combination with a password or security question and answer that would permit access to the account.
Two words carry most of the weight. "Nonencrypted" and "nonredacted" mean encrypted data that leaks is outside the claim. That is why encryption at rest is a legal control in California, not just an engineering preference.
What a consumer can recover
Section 1798.150(a)(1) allows damages of not less than $100 and not greater than $750 per consumer per incident, or actual damages, whichever is greater, plus injunctive or declaratory relief and any other relief the court deems proper. Those dollar figures are adjusted under Section 1798.199.95(d); the current published range is $107 to $799 per consumer per incident, effective January 1, 2025.
Per consumer, per incident, is the part that matters commercially. A breach touching a hundred thousand California records is not a single claim. Section 1798.150(a)(2) then tells the court what to weigh in setting statutory damages: the nature and seriousness of the misconduct, the number of violations, the persistence and length of the misconduct, willfulness, and the defendant's assets, liabilities, and net worth.
The 30-day notice, and why post-breach fixes do not cure
Before bringing a statutory-damages claim, individually or class-wide, a consumer must give the business 30 days' written notice identifying the specific provisions alleged to be violated. If a cure is possible and the business actually cures within those 30 days and provides an express written statement that the violations are cured and will not recur, no statutory-damages action may be initiated.
Section 1798.150(b) then closes the obvious loophole: implementing and maintaining reasonable security procedures after a breach does not constitute a cure with respect to that breach. And if the business breaks its own written statement, the consumer can sue to enforce it and pursue statutory damages for each breach of that statement. No notice at all is required where a consumer sues solely for actual pecuniary damages.
How this sits next to agency enforcement
Administrative fines under Section 1798.155 are a separate track run by the California Privacy Protection Agency, and the CCPA cure period works differently there. Note also that several statutory exemptions, including the Fair Credit Reporting Act, Gramm-Leach-Bliley, and Driver's Privacy Protection Act carve-outs, expressly do not apply to Section 1798.150. Data that is otherwise outside the CCPA can still be inside the breach claim.
Next step
Reasonable security is judged against the nature of the information you hold, so the first question is what you actually hold and which law reaches it. The free 2-minute Obligation Scan checks whether the CCPA applies to your business and lists the duties that follow. The California privacy overview covers the thresholds, and the US state privacy laws hub shows which other states pair a breach claim with their privacy rules.
Compliance checklist
- Know which data triggers the claim: nonencrypted and nonredacted personal information as defined in Section 1798.81.5(d)(1)(A), or an email address with a password or security question that opens the account.
- Treat encryption and redaction as the practical defense, because the cause of action reaches only nonencrypted, nonredacted data.
- Document your reasonable security procedures and practices now, since the claim turns on a failure to implement and maintain them.
- Expect a 30-day written notice before any statutory-damages claim, and understand that fixing security after a breach does not count as a cure for that breach.
- Remember that no notice is required when a consumer sues only for actual pecuniary damages.
Sources
- California Consumer Privacy Act of 2018, Cal. Civ. Code Section 1798.150 (personal information security breaches), statute text published by the California Privacy Protection Agency, effective 01/01/2026
- Updated Monetary Thresholds in CCPA (Civ. Code Section 1798.199.95(d) adjustment, effective January 1, 2025), California Privacy Protection Agency
Last verified: 2026-08-19
Informational, not legal advice.