How Long Breach Notification Actually Takes, Measured from California’s Register

The median incident in California’s official data-breach register took 135 days to travel from the breach itself to a report on the Attorney General’s public list — measured across 4,758 incidents from the register’s 5,266 rows as of 2026-08-20. 91.2% of incidents took longer than 30 days and 64% took longer than 90. The interval has also grown: among filings reported in 2013 the median was 62 days, and among those reported in 2025 it was 186 days — more than double, on a robust trend of about 10.2 days a year.

The interval includes the time it took to discover the breach, so it measures the full distance between an incident and its disclosure — not compliance with any statutory deadline.

Reviewed by · Updated

Related toolkits: ISO 27001 Complete Toolkit ($99) · SOC 2 Complete Toolkit ($99)

The headline numbers

California requires a copy of every breach notice affecting more than 500 California residents to go to the state Attorney General (Cal. Civ. Code § 1798.82(f)), and the AG publishes each one in a public register whose records begin in 2012. Parsing the register’s CSV export yields, for each incident that lists both dates, the number of days between the earliest reported breach date and the date the incident was reported to the AG.

The Attorney General publishes the rows but no interval statistic computed from them, and the two academic analyses that have tabulated this interval both stop at data from 2020 (see the method note). The figures below are computed from the official export on a dated snapshot, and the per-year table can be downloaded as CSV at the link in that note.

Breach-to-notification interval, California AG register (snapshot 2026-08-20)

PopulationIncidentsMedian intervalOver 30 daysOver 90 daysOver 1 year
All computable incidents (2012–present)4,758135 days91.2%64%13.5%
Last three full years (2023–2025)1,713159 days95.7%71.9%13.8%

Source: California Attorney General public data-breach register (CSV export), https://oag.ca.gov/privacy/databreach/list-export, snapshot 2026-08-20. Computed by ComplianceDocs; method below.

The interval has more than doubled — and the shape matters more than the multiple

The direction is the finding; the exact multiple is not. Among filings reported in 2013, the register's first full year, the median reached the Attorney General 62 days after the breach date. Among filings reported in 2025, the median was 186 days. That pair of years is 3×, but it compares two years rather than describing a trend, and it does not survive being drawn differently: pooling three years at each end (2013-2015 against 2023-2025) gives 69 days against 159, a ratio of 2.3×. Resampling the two endpoint years 20,000 times puts the ratio's 95% interval at 2.37–3.39.

What the register does support, in every way we drew it: the median has more than doubled, and the annual medians carry a robust trend of about 10.2 days a year — a slope no single year can swing. Read that, not a multiple.

The rise is also not a steady climb. 5 of the year-on-year steps in the table below go down, and most adjacent years cannot be told apart. Indexing by the year an incident actually occurred rather than the year it was reported — a different population, and the one most readers picture — the median runs 57 days for 2012 breaches and 144 days for 2022 breaches, with most of the movement arriving as a step in the late 2010s rather than accumulating evenly. Breach years after 2022 are left out of that reading because incidents slow to surface have not surfaced yet, which would drag the recent years artificially low.

One limit stays open, and naming it is better than rounding it away. Filings listing no usable breach date are excluded, and the exclusion rate is uneven: 24.9% of 2013 filings against 6.2% of 2025 filings. That falls hardest on the baseline year, and the export carries nothing that says which way those filings would move a median — if they simply ran longer than their year's typical case, the multiple would be materially smaller. Reading the underlying notices for a sample of them would settle it; a three-column export cannot.

Two forces plausibly drive the growth, and the register cannot separate them: breaches have become harder to discover (long-dwell intrusions, third-party and supply-chain incidents whose downstream victims learn late), and investigations before notification have become longer and more lawyered. Either way, the practical reading for an organization writing an incident-response plan is the same: the clock that matters runs from the breach, not from the day you notice it — and the public record says that distance is now measured in months.

Median breach-to-notification interval by report year (California AG register)

Report yearIncidentsMedian interval (days)Share over 30 days
20131276272.4%
20141416075.9%
20151548883.1%
201621480.578.5%
201727110081.2%
2018240125.586.7%
201923014592.6%
202036214293.9%
202144313095%
202243816197.5%
202360812594.9%
2024578174.597.1%
202552718695.3%
2026 (partial year)32715094.5%

Year = the year the incident was reported to the AG. The current year is a partial year and its figures will move.

What the interval does — and does not — measure

The interval runs from the earliest breach date an organization reported to the date its notice reached the Attorney General. That span includes the time it took to discover the incident, the forensic investigation, and the notification process itself. It is therefore a measure of the full occurrence-to-disclosure distance — not a measure of whether anyone missed a legal deadline.

California’s consumer-notice clock is now fixed: Cal. Civ. Code § 1798.82(a)(2), as amended by Stats. 2025, ch. 319 (SB 446), requires disclosure “within 30 calendar days of discovery or notification of the data breach,” with allowances for law-enforcement holds and the time needed to determine the scope of the breach (statute text read from leginfo.legislature.ca.gov on the snapshot date).

Regulated sectors run their own clocks — HIPAA’s breach rule requires individual notice “without unreasonable delay and in no case later than 60 calendar days after discovery” (45 CFR § 164.404(b), current eCFR text). The same amendment also puts a clock on the Attorney General copy itself: § 1798.82(f) requires the sample copy to be submitted “within 15 calendar days of notifying affected consumers,” which runs from the consumer notice rather than from discovery.

Because the register records breach dates rather than discovery dates or consumer-notice dates, none of these deadlines can be tested against it — and nearly all of the register predates the amendment in any case.

Why a second register does not settle this

The caveat above is the first question any careful reader asks of this number, and California's structured export cannot answer it: there is no discovery-date column, so the two halves of the interval — not knowing, and not telling — cannot be separated from the export. They are not unobtainable here, only expensive: researchers have recovered discovery dates for this register by reading the individual notice letters behind the rows (Xu and Nguyen, cited in the method note, did exactly that).

Washington State's register does publish a discovery date, and we have tabulated it the same way at /learn/breach-discovery-to-notification-washington: there, the median interval from the day an organization recorded becoming aware of a breach to the day it notified the state is 67 days across 1,615 filings.

What that second register does not provide is corroboration, and it is worth saying why, because the assumption is easy to make. Matching organization names across the two registers, 53.5% of Washington's filings name an organization that also appears in this one, and of the matched pairs carrying an occurrence date on both sides, 91% carry the identical date. A breach large enough to clear one state's threshold usually clears the other's, so the same incident is filed in both places.

Two state registers are substantially one body of self-reported data, and reading agreement between them as independent confirmation — or pooling several of them without accounting for the overlap — counts some incidents more than once.

Locate your own response time in the register

For a team pressure-testing an incident-response plan, the register doubles as a benchmark population: given the full breach-to-notification distance your last incident or tabletop exercise produced (discovery time included, same as the register), the shares above locate it. The all-time median is 135 days, and 159 days across 2023–2025.

This is a performance benchmark against the published register, not a compliance measure — the register cannot say whether any incident met a legal clock, and neither can this table. Writing the plan that produces a shorter distance is covered in our guide to writing an incident response plan at /learn/how-to-write-incident-response-plan.

Where a given breach-to-notification distance falls in the register

If the full distance was under…Faster than (all incidents, 2012–present)Faster than (2023–2025)
60 days77.1%84.5%
90 days64%71.9%
1 year13.5%13.8%

"Faster than" = the share of computable register incidents whose interval exceeded that threshold. The interval includes time-to-discovery on both sides of the comparison.

For journalists: quotable findings and media kit

Quotable, with the caveat attached: “The median incident in California’s official data-breach register took 135 days to travel from the breach itself to a report on the Attorney General’s public list — and the 62-day median of 2013 had become 186 days by 2025. The interval includes the time it took to discover the breach, so it measures disclosure distance, not legal compliance.”

Also citable: 91.2% of the register’s 4,758 computable incidents took longer than 30 days from breach to report, and 64% took longer than 90 — again including discovery time.

The charts below are publication-ready (SVG, source credit rendered in), the per-year dataset is downloadable as CSV, and the full methodology is on this page. For a cut of the data by sector or year, or to check a figure before publication, write to support@compliancedocshq.com.

Method, exclusions and the dataset

Every row of the official CA AG breach-register CSV export was parsed on the as-of date. The interval for a row runs from the FIRST date listed in "Date(s) of Breach (if known)" to the "Reported Date" date, in days. This interval includes the time the organization took to DISCOVER the breach, so it measures the full occurrence-to-notification distance and is not a measure of compliance with any statutory deadline. Rows excluded and counted: no parseable breach date, no parseable report date, negative intervals (report date precedes breach date - data-entry artifacts), and intervals over 10 years.

Of the register’s 5,266 rows at the snapshot date: 4,758 yielded a computable interval; 489 listed no parseable breach date; 0 listed no parseable report date; 18 were excluded as negative intervals; and 1 were excluded as implausible intervals over 10 years. Incidents listing a date range are measured from the range’s first date, which makes the interval an upper-bound reading for multi-date incidents.

Prior work on this interval, so this page is not read as claiming more than it does: Xu and Nguyen (arXiv:2209.07306, 2022) computed breach-to-notification and its components from this same register using data through 2020, reporting a median of 102 days occurrence to notification; Avanzi, Tan, Taylor and Wong (arXiv:2310.04786, 2024) analyzed eight state registers jointly, California among them, on the same axis and likewise found California's delay lengthening after 2017. Neither the measurement nor the idea originates here. What this page contributes is a current dated snapshot, a per-year series, and a downloadable table.

Our per-year figures do not match theirs exactly, and we would rather show that than smooth it over: for 2013 Xu and Nguyen report a median of 69.5 days where we compute 62, and for 2017 they report 114.5 where we compute 100. The per-year minima and maxima agree exactly across 2013–2020, so both analyses are reading substantially the same rows; the gap is in inclusion rules and in how each treats filings that list a date range rather than a single day.

We have not reconciled it line by line, and until someone does, treat differences of roughly ten percent between published tabulations of this register as expected rather than as one of them being wrong.

The per-year aggregate table is available as a CSV dataset at /datasets/ca-breach-notification-intervals.csv and may be cited with attribution to ComplianceDocs and the California Attorney General’s register as the underlying source. This page reports the register as published; it is not legal advice.

Charts, dataset and reuse

The charts and the underlying tabulated dataset on this page are published under CC BY 4.0: reuse them in your own article, report or deck, with attribution to ComplianceDocs — a link back to this page is the attribution form we ask for. The underlying government register is public information; the license covers this tabulation and these charts.

Line chart of the median days from breach to notification by report year in the California AG register, rising overall across the period with several years that fall back below the year before them
Median breach-to-notification interval by report year, California AG register. · Download SVG
Line chart: share of California register breaches taking over 90 days from breach to notification, by report year
Share of incidents exceeding 90 days from breach to notification, by report year. · Download SVG

Dataset: Breach-to-notification intervals by report year (CSV; snapshot-dated, methodology above).

Cite this data

ComplianceDocs, “Breach-to-notification intervals, California AG data-breach register,” https://compliancedocshq.com/learn/breach-notification-time-statistics. Underlying register as named in the method note.

Embed a chart

Copy and paste — the snippet credits the source for you:

<a href="https://compliancedocshq.com/learn/breach-notification-time-statistics"><img src="https://compliancedocshq.com/charts/ca-breach-lag-median-by-year.svg" alt="Line chart of the median days from breach to notification by report year in the California AG register, rising overall across the period with several years that fall back below the year before them" width="720" style="max-width:100%;height:auto"></a>
<p>Source: <a href="https://compliancedocshq.com/learn/breach-notification-time-statistics">ComplianceDocs — How Long Breach Notification Actually Takes, Measured from California’s Register</a></p>

Frequently asked questions

How long do companies take to report a data breach?
Measured from 4,758 incidents in California’s official breach register (snapshot 2026-08-20), the median interval from the breach itself to notification of the state Attorney General is 135 days all-time, and 159 days across 2023–2025. The interval includes the time taken to discover the breach.
Is breach notification getting faster or slower?
Slower, and by more than a factor of two. Among filings reported in 2013 the median breach-to-notification interval was 62 days; among those reported in 2025 it was 186 days, and the annual medians carry a robust trend of about 10.2 days a year. A precise multiple is not supportable — pooling three years at each end gives 2.3× against 3× for the single-year pair — and the rise is a step in the late 2010s rather than a steady climb, with 5 year-on-year steps falling. The median moved much more than the average (135 days versus a mean of 199.9), so the shift sits in the faster half of the distribution. The register also cannot separate slower discovery from longer pre-notification investigation.
What share of breaches take more than 30 days to report?
91.2% of all computable incidents in the California register exceeded 30 days from breach date to AG notification, and 64% exceeded 90 days. In the last three full years (2023–2025) the over-30-day share was 95.7%.
What is the legal deadline to report a data breach in California?
Since the SB 446 amendment (Stats. 2025, ch. 319), Cal. Civ. Code § 1798.82(a)(2) requires consumer disclosure “within 30 calendar days of discovery or notification of the data breach,” subject to law-enforcement holds and the time needed to determine the breach’s scope. A copy must go to the Attorney General when a single breach affects more than 500 California residents (§ 1798.82(f)). HIPAA’s breach rule separately requires individual notice “without unreasonable delay and in no case later than 60 calendar days after discovery” (45 CFR § 164.404(b)). This page is statistical reporting, not legal advice.
Where does this data come from?
Every figure is computed from the CSV export of the California Attorney General’s public data-breach register (https://oag.ca.gov/privacy/databreach/list-export), snapshot 2026-08-20. The computation method and every exclusion are stated on this page, and the per-year aggregates are downloadable as CSV.

Related guides: HIPAA · SOC 2

Toolkits that help

ISO/IEC 27001:2022

ISO 27001 Complete Toolkit

All 24 policies and procedures plus the risk register, 93-control Statement of Applicability and audit evidence checklist.

SOC 2 Trust Services Criteria

SOC 2 Complete Toolkit

22 policies plus the risk register, full Trust Services Criteria mapping and audit evidence checklist — built for startups facing their first SOC 2.

HIPAA Security & Privacy Rules

HIPAA Compliance Toolkit — Medical Practices

18 editable HIPAA policies plus the Security Risk Assessment workbook and audit evidence checklist, written for small medical practices and clinics.

EU GDPR

GDPR Compliance Pack for Small Business

14 editable GDPR documents — privacy notices, DSAR procedure, DPIA, breach response, processor DPA checklist — plus a pre-filled Records of Processing Activities (Art. 30) workbook and evidence checklist.

Related articles

Get new templates and guides by email

An occasional email when we publish a new free template, guide, or dataset. Unsubscribe any time.

← All articles

Professional editable templates — general information only, not legal, audit, tax, or certification advice, and no professional or advisory relationship is created. No purchase makes an organization compliant or certified. Review each document with qualified counsel, your compliance professional, or your auditor before relying on it. ISO, IEC, SOC 2, AICPA, HIPAA, NIST, GDPR, the EU AI Act, IRS and FTC are referenced descriptively only; ComplianceDocs (ExpertEngine LLC) is independent and is not affiliated with, endorsed by, or certified by any standards body, regulator, or audit firm.