SB 446 Starts the Clock: California's 30-Day Breach-Notification Deadline

California moved the goalposts — to a fixed date
California enacted the first state breach-notification law in 2002, and in October 2025 it moved again. Senate Bill 446 replaced the long-standing "most expedient time possible" standard with a fixed deadline. For breaches affecting more than 500 California residents, an organization must now notify affected Californians within 30 calendar days of discovery, and the Attorney General within 15 calendar days after consumers are notified.
The change sounds administrative. It is not. A vague "expedient" standard let organizations argue about reasonableness after the fact. A hard 30-day clock turns notification speed into a measurable compliance question — and the historical record, analyzed in the California Cybersecurity Risk Report 2027, suggests most organizations have not been operating anywhere near that pace.
The gap between the law and current practice
intSignal Research analyzed 1,536 breach notices filed with the California Attorney General. The median gap between a breach occurring and its notification was 174 days — about six months.
An important nuance: SB 446's clock runs from discovery, not from when the breach occurred, so a long occurrence-to-notice gap is not automatically a violation. But the early SB 446-era data still shows how far the gap has to close. Among 2026 breaches arising fully under the new regime, the median occurrence-to-notice gap was 70 days and 41.7 percent of notices arrived within 60 days — faster than the legacy pattern, yet only 13.6 percent arrived within 30 days of the breach occurring. The full 2026 cohort will be the first real benchmark of SB 446 compliance.
What a 30-day clock actually demands
The deadline is short. From the moment you discover a breach, 30 days is not much time to investigate, scope who was affected, and notify — while also meeting the 15-day Attorney General timeline that follows. Meeting it reliably requires capabilities that have to exist before the incident:
- Detection that finds breaches quickly. The clock only starts at discovery, so the organizations that struggle most are the ones that discover breaches late. Continuous monitoring — a managed SOC or MDR — is what prevents a breach from sitting undiscovered for months.
- Logging sufficient to scope a breach in days. You cannot notify accurately if you cannot reconstruct what data was accessed and whose. Adequate, retained logs are the raw material of a 30-day investigation.
- A tested incident-response plan. A written, rehearsed plan — with roles, decision points, and escalation defined — is the difference between 30 orderly days and 30 chaotic ones.
- Counsel and notification vendors identified in advance. Selecting breach counsel and a notification provider during an incident burns days you do not have. Identify them now.
Treat it as a design requirement, not a legal footnote
For any organization holding data on more than 500 Californians, incident-response readiness is now effectively a regulatory requirement, not a nice-to-have. And because your obligations attach even when the breach happens at a vendor, the 30-day clock is also a reason to demand shorter breach-notification terms in your vendor contracts, so a supplier's incident reaches you with time to act.
SB 446 rewards preparation and punishes improvisation. The businesses that will meet it comfortably are building the detection, logging, and response muscle now — before a breach date with their name on it appears in the register.
The figures in this article are drawn from the California Cybersecurity Risk Report 2027 by intSignal Research. This article is general information, not legal advice; confirm your specific obligations under SB 446 with counsel.


