Cyber insurance built for the only state where a data breach carries automatic statutory damages — $100 to $750 per consumer per incident under the CCPA, no proof of actual harm required — plus two privacy regulators actively writing six- and seven-figure settlements.
California is the hardest state in the country to have a data breach in. The CCPA, as amended by the CPRA, gives consumers a private right of action with statutory damages when unencrypted personal information is breached, a dedicated privacy agency now brings its own enforcement actions alongside the Attorney General, and since January 1, 2026 the state runs a hard 30-day clock on breach notification. Here is what that stack means for how your cyber policy should be structured.
California’s core privacy statute is the California Consumer Privacy Act, Cal. Civ. Code §1798.100 et seq., as amended by the CPRA. It generally reaches for-profit businesses that clear an inflation-adjusted revenue threshold (roughly $25 million and climbing) or handle the personal information of 100,000 or more Californians — and it is enforced by two separate bodies: the Attorney General and the California Privacy Protection Agency (CPPA), the first standalone privacy regulator in the country. Administrative fines run up to $2,500 per violation and $7,500 per intentional violation or violation involving a minor’s data — and because each affected consumer can count as a violation, the arithmetic escalates fast.
This is no longer theoretical. In March 2025 the CPPA settled its first major action, requiring American Honda to pay $632,500 over defective privacy-rights processes, and followed with a $345,178 penalty against retailer Todd Snyder weeks later. In July 2025 the Attorney General announced the largest CCPA settlement to date — $1.55 million from Healthline.com — over ad-tracking that kept sharing health-related data after users opted out. The mandatory cure period is gone, so an investigation letter now leads straight to defense costs. That is the exposure your policy’s regulatory-defense coverage exists to absorb.
What truly sets California apart for a cyber underwriter is Civil Code §1798.150 — the CCPA’s private right of action for data breaches:
Start with the third-party side: in most states, breach class actions must fight over actual damages, but §1798.150 hands California plaintiffs a statutory-damages formula, so your privacy-liability limit should be sized to your California record count, not to a generic benchmark. Regulatory coverage needs to respond to both the CPPA and the Attorney General — defense costs first, and fines and penalties where insurable by law. On the first-party side, the 30-day notification deadline means breach counsel, forensics, notification, and credit monitoring have to mobilize in days, so a policy with a strong pre-approved breach-response panel earns its premium. Finally, watch the fine print on wrongful-collection and pixel/ad-tech exclusions — the Healthline action and the wave of California tracking-technology suits land exactly there, and carriers have been narrowing that grant. We read those terms with you before you bind.
Tell us about your operation and your loss history — we’ll confirm we can write California and structure the limits to match.