How Long Breach Notification Actually Takes, Measured from California’s Register
The median incident in California’s official data-breach register took 135 days to travel from the breach itself to a report on the Attorney General’s public list — measured across 4,757 incidents from the register’s 5,265 rows as of 2026-08-19. 91.1% of incidents took longer than 30 days and 64% took longer than 90. The interval is also growing: the 62-day median of 2013 had become 186 days by 2025. The interval includes the time it took to discover the breach, so it measures the full distance between an incident and its disclosure — not compliance with any statutory deadline.
Reviewed by Dor Israel, Founder · Updated
The headline numbers
California requires a copy of every breach notice affecting more than 500 California residents to go to the state Attorney General (Cal. Civ. Code § 1798.82(f)), and the AG publishes each one in a public register whose records begin in 2012. Parsing the register’s CSV export yields, for each incident that lists both dates, the number of days between the earliest reported breach date and the date the incident was reported to the AG.
No published dataset tabulates this interval, which is why this page exists. The figures below are computed from the official export, and the per-year table can be downloaded as CSV at the link in the method note.
Breach-to-notification interval, California AG register (snapshot 2026-08-19)
| Population | Incidents | Median interval | Over 30 days | Over 90 days | Over 1 year |
|---|---|---|---|---|---|
| All computable incidents (2012–present) | 4,757 | 135 days | 91.1% | 64% | 13.5% |
| Last three full years (2023–2025) | 1,713 | 159 days | 95.7% | 71.9% | 13.8% |
Source: California Attorney General public data-breach register (CSV export), https://oag.ca.gov/privacy/databreach/list-export, snapshot 2026-08-19. Computed by ComplianceDocs; method below.
The interval has roughly tripled since 2013
The trend is the finding. In 2013, the first full year of the register, the median incident was reported 62 days after the breach date. By 2025 the median was 186 days.
Two forces plausibly drive the growth, and the register cannot separate them: breaches have become harder to discover (long-dwell intrusions, third-party and supply-chain incidents whose downstream victims learn late), and investigations before notification have become longer and more lawyered. Either way, the practical reading for an organization writing an incident-response plan is the same: the clock that matters runs from the breach, not from the day you notice it — and the public record says that distance is now measured in months.
Median breach-to-notification interval by report year (California AG register)
| Report year | Incidents | Median interval (days) | Share over 30 days |
|---|---|---|---|
| 2013 | 127 | 62 | 72.4% |
| 2014 | 141 | 60 | 75.9% |
| 2015 | 154 | 88 | 83.1% |
| 2016 | 214 | 81 | 78.5% |
| 2017 | 271 | 100 | 81.2% |
| 2018 | 240 | 126 | 86.7% |
| 2019 | 230 | 145 | 92.6% |
| 2020 | 362 | 142 | 93.9% |
| 2021 | 443 | 130 | 95% |
| 2022 | 438 | 161 | 97.5% |
| 2023 | 608 | 125 | 94.9% |
| 2024 | 578 | 175 | 97.1% |
| 2025 | 527 | 186 | 95.3% |
| 2026 (partial year) | 326 | 151 | 94.5% |
Year = the year the incident was reported to the AG. The current year is a partial year and its figures will move.
What the interval does — and does not — measure
The interval runs from the earliest breach date an organization reported to the date its notice reached the Attorney General. That span includes the time it took to discover the incident, the forensic investigation, and the notification process itself. It is therefore a measure of the full occurrence-to-disclosure distance — not a measure of whether anyone missed a legal deadline.
California’s consumer-notice clock is now fixed: Cal. Civ. Code § 1798.82(a)(2), as amended by Stats. 2025, ch. 319 (SB 446), requires disclosure “within 30 calendar days of discovery or notification of the data breach,” with allowances for law-enforcement holds and the time needed to determine the scope of the breach (statute text read from leginfo.legislature.ca.gov on the snapshot date).
Regulated sectors run their own clocks — HIPAA’s breach rule requires individual notice “without unreasonable delay and in no case later than 60 calendar days after discovery” (45 CFR § 164.404(b), current eCFR text). Because the register records breach dates rather than discovery dates, neither deadline can be tested against it — and nearly all of the register predates the 30-day amendment in any case.
Method, exclusions and the dataset
Every row of the official CA AG breach-register CSV export was parsed on the as-of date. The interval for a row runs from the FIRST date listed in "Date(s) of Breach (if known)" to the "Reported Date" date, in days. This interval includes the time the organization took to DISCOVER the breach, so it measures the full occurrence-to-notification distance and is not a measure of compliance with any statutory deadline. Rows excluded and counted: no parseable breach date, no parseable report date, negative intervals (report date precedes breach date - data-entry artifacts), and intervals over 10 years.
Of the register’s 5,265 rows at the snapshot date: 4,757 yielded a computable interval; 489 listed no parseable breach date; 0 listed no parseable report date; 18 were excluded as negative intervals; and 1 were excluded as implausible intervals over 10 years. Incidents listing a date range are measured from the range’s first date, which makes the interval an upper-bound reading for multi-date incidents.
The per-year aggregate table is available as a CSV dataset at /datasets/ca-breach-notification-intervals.csv and may be cited with attribution to ComplianceDocs and the California Attorney General’s register as the underlying source. This page reports the register as published; it is not legal advice.
Frequently asked questions
- How long do companies take to report a data breach?
- Measured from 4,757 incidents in California’s official breach register (snapshot 2026-08-19), the median interval from the breach itself to notification of the state Attorney General is 135 days all-time, and 159 days across 2023–2025. The interval includes the time taken to discover the breach.
- Is breach notification getting faster or slower?
- Slower. In the California register, the median breach-to-notification interval grew from 62 days in 2013 to 186 days in 2025. The register cannot separate slower discovery from longer pre-notification investigations, but the total distance has roughly tripled.
- What share of breaches take more than 30 days to report?
- 91.1% of all computable incidents in the California register exceeded 30 days from breach date to AG notification, and 64% exceeded 90 days. In the last three full years (2023–2025) the over-30-day share was 95.7%.
- What is the legal deadline to report a data breach in California?
- Since the SB 446 amendment (Stats. 2025, ch. 319), Cal. Civ. Code § 1798.82(a)(2) requires consumer disclosure “within 30 calendar days of discovery or notification of the data breach,” subject to law-enforcement holds and the time needed to determine the breach’s scope. A copy must go to the Attorney General when a single breach affects more than 500 California residents (§ 1798.82(f)). HIPAA’s breach rule separately requires individual notice “without unreasonable delay and in no case later than 60 calendar days after discovery” (45 CFR § 164.404(b)). This page is statistical reporting, not legal advice.
- Where does this data come from?
- Every figure is computed from the CSV export of the California Attorney General’s public data-breach register (https://oag.ca.gov/privacy/databreach/list-export), snapshot 2026-08-19. The computation method and every exclusion are stated on this page, and the per-year aggregates are downloadable as CSV.
Toolkits that help
ISO 27001 Complete Toolkit
All 24 policies and procedures plus the risk register, 93-control Statement of Applicability and audit evidence checklist.
SOC 2 Complete Toolkit
22 policies plus the risk register, full Trust Services Criteria mapping and audit evidence checklist — built for startups facing their first SOC 2.
HIPAA Compliance Toolkit — Medical Practices
18 editable HIPAA policies plus the Security Risk Assessment workbook and audit evidence checklist, written for small medical practices and clinics.
GDPR Compliance Pack for Small Business
14 editable GDPR documents — privacy notices, DSAR procedure, DPIA, breach response, processor DPA checklist — plus a pre-filled Records of Processing Activities (Art. 30) workbook and evidence checklist.
Related articles
- How Many Documents Each Compliance Framework Actually Requires
- How Long Compliance Documentation Actually Takes
- Compliance Documentation Benchmarks: What a Policy Library Actually Contains
- 2026 Compliance Template Pricing Index
- Compliance Questions, Answered
Get new templates and guides by email
An occasional email when we publish a new free template, guide, or dataset. Unsubscribe any time.
