California Statutory Damages (CCPA/CPRA)
Last reviewed:
In 2020 California became the first state to let consumers recover statutory damages for breaches: $100 to $750 per incident where the breach resulted from failure to implement and maintain reasonable security. A 30-day cure period can bar statutory damages. Enacted via the CCPA, updated by the CPRA.
Because actual damages are hard to prove in breaches, California created statutory damages - dispensing with the need to prove loss. Consumers may recover $100 to $750 per incident, actual damages, or other remedies, where the breach resulted from the business's failure to implement and maintain reasonable security procedures and practices.
A consumer seeking statutory damages must give the business a chance to cure. If the business successfully cures within 30 days, the consumer cannot pursue statutory damages. Note: simply implementing reasonable security after the breach does not count as a cure.
This framework was passed in the CCPA private right of action and updated in the CPRA (Chapter 6). It ties recovery to California's data breach notification law definition of personal information.
Key terms - quick answers
What is “Statutory damages”?
What is “CCPA”?
What is “CPRA”?
What is “30-day cure period”?
Keep going - free
Every study note on this site is free. So are these: