National cyber insurance · A division of Thrive Risk Management CA License #6012320
California · CCPA statutory damages

California cyber insurance, built for CCPA statutory damages.

Cyber insurance built for the only state where a data breach carries automatic statutory damages — $100 to $750 per consumer per incident under the CCPA, no proof of actual harm required — plus two privacy regulators actively writing six- and seven-figure settlements.

Privacy-liability limits sized to §1798.150 statutory-damages math
Regulatory defense for CPPA & Attorney General proceedings
Breach-response coverage built for the 30-day notification clock

Request a California cyber Quote

Tell us about your business. A licensed advisor responds — no spam, no call center.

By submitting you consent to be contacted by Thrive Risk Management Insurance Solutions regarding your quote. No obligation.

HomeCalifornia cyber Insurance
California cyber, in plain terms

California is the hardest state in the country to have a data breach in. The CCPA, as amended by the CPRA, gives consumers a private right of action with statutory damages when unencrypted personal information is breached, a dedicated privacy agency now brings its own enforcement actions alongside the Attorney General, and since January 1, 2026 the state runs a hard 30-day clock on breach notification. Here is what that stack means for how your cyber policy should be structured.

CCPA/CPRA: two regulators, real fines

California’s core privacy statute is the California Consumer Privacy Act, Cal. Civ. Code §1798.100 et seq., as amended by the CPRA. It generally reaches for-profit businesses that clear an inflation-adjusted revenue threshold (roughly $25 million and climbing) or handle the personal information of 100,000 or more Californians — and it is enforced by two separate bodies: the Attorney General and the California Privacy Protection Agency (CPPA), the first standalone privacy regulator in the country. Administrative fines run up to $2,500 per violation and $7,500 per intentional violation or violation involving a minor’s data — and because each affected consumer can count as a violation, the arithmetic escalates fast.

This is no longer theoretical. In March 2025 the CPPA settled its first major action, requiring American Honda to pay $632,500 over defective privacy-rights processes, and followed with a $345,178 penalty against retailer Todd Snyder weeks later. In July 2025 the Attorney General announced the largest CCPA settlement to date — $1.55 million from Healthline.com — over ad-tracking that kept sharing health-related data after users opted out. The mandatory cure period is gone, so an investigation letter now leads straight to defense costs. That is the exposure your policy’s regulatory-defense coverage exists to absorb.

§1798.150: the breach lawsuit no other state allows

What truly sets California apart for a cyber underwriter is Civil Code §1798.150 — the CCPA’s private right of action for data breaches:

  • Statutory damages without proof of harm: when nonencrypted, nonredacted personal information is breached because a business failed to maintain reasonable security, each consumer can recover $100 to $750 per incident — or actual damages if greater — without proving a dollar of loss. A breach of 50,000 California records carries a theoretical statutory floor of $5 million before a single fraud occurs, which is why nearly every sizable California breach now draws a class action.
  • A hard 30-day notification clock: under Civil Code §1798.82, as amended by SB 446 effective January 1, 2026, affected residents must be notified within 30 calendar days of discovery, and when a breach affects more than 500 Californians a sample notice goes to the Attorney General within 15 days of consumer notice — where it is published on a searchable public list that plaintiff firms monitor.
  • Encryption as a legal firewall: §1798.150 applies only to breaches of unencrypted data — one of the few places where a security control directly eliminates a statutory cause of action, and a fact underwriters price for.

How your cyber insurance should be structured in California

Start with the third-party side: in most states, breach class actions must fight over actual damages, but §1798.150 hands California plaintiffs a statutory-damages formula, so your privacy-liability limit should be sized to your California record count, not to a generic benchmark. Regulatory coverage needs to respond to both the CPPA and the Attorney General — defense costs first, and fines and penalties where insurable by law. On the first-party side, the 30-day notification deadline means breach counsel, forensics, notification, and credit monitoring have to mobilize in days, so a policy with a strong pre-approved breach-response panel earns its premium. Finally, watch the fine print on wrongful-collection and pixel/ad-tech exclusions — the Healthline action and the wave of California tracking-technology suits land exactly there, and carriers have been narrowing that grant. We read those terms with you before you bind.

California cyber — Frequently Asked

Questions California operators ask.

Can I really be sued after a breach in California even if nobody suffers identity theft?
Yes — and that is the single most important thing to understand about California cyber exposure. Civil Code §1798.150 lets any consumer whose nonencrypted, nonredacted personal information is breached because of a failure to maintain reasonable security recover statutory damages of $100 to $750 per consumer per incident, with no requirement to prove actual financial harm. That formula is why California breaches convert to class actions at a rate no other state matches: the plaintiff’s firm does not need injured victims, just a record count. Two structural consequences follow. First, your privacy-liability limit should be benchmarked against the number of California records you hold, because the statutory floor scales with it. Second, encryption is not just an IT best practice here — §1798.150 only applies to unencrypted data, so encryption at rest and in transit can eliminate the cause of action entirely, and underwriters reward it. We size the third-party limit to that math rather than defaulting to a round number.
Does cyber insurance cover CCPA fines and a CPPA investigation?
Good policies cover much of it, but the details vary and matter. Most modern cyber forms include regulatory coverage that pays defense costs when the CPPA or the Attorney General opens an investigation or files an enforcement action arising from a privacy or security incident — and with the CPPA’s Honda ($632,500) and Todd Snyder ($345,178) actions in 2025 plus the Attorney General’s record $1.55 million Healthline settlement, that is a live exposure, not boilerplate. Fines and penalties themselves are typically covered only “where insurable by law,” an unsettled question that argues for carriers with favorable most-favorable-jurisdiction wording. The bigger trap is scope: several CPPA and AG actions arose from ad-tech tracking and mishandled opt-outs rather than from a hack, and some policies exclude “wrongful collection” claims — meaning a pixel or opt-out failure could fall outside coverage even while a breach would be covered. When we place California cyber, we check whether regulatory coverage is triggered by a privacy-law violation or only by a security failure, because in this state that difference is the whole game.
Doesn’t my general liability policy cover cyber attacks?
No — and this is the most expensive assumption in small-business insurance. General liability responds to bodily injury and physical damage to tangible property, and courts have generally held that electronic data is not tangible property. On top of that, standard GL policies now carry explicit exclusions for access to or disclosure of confidential or personal information, added across the market after early data-breach lawsuits. Commercial property policies have the same problem: they cover the server hardware, not the data on it or the income lost while your systems are locked. Cyber insurance exists as a separate line precisely because it covers what those policies deliberately carve out — breach response, ransomware, data restoration, and privacy lawsuits. If a client contract requires “cyber liability,” a GL certificate will not satisfy it.
What does a cyber insurance policy actually cover?
A modern policy has two sides. First-party coverage pays your own costs after an incident: forensics to determine what happened, breach counsel, the notification letters state law requires you to send, credit monitoring for affected people, ransomware and extortion response, business income lost during an outage, and the cost of restoring data. Third-party coverage defends and pays when others come after you: lawsuits from customers or employees whose data was exposed, claims that malware spread from your systems, regulatory investigations, and PCI assessments from the card brands. Most policies add crime-style endorsements for social engineering and funds-transfer fraud, where many real-world losses now occur. The Federal Trade Commission’s Data Breach Response guide shows how many moving parts a breach involves — a good cyber policy funds and coordinates essentially all of them.
Other States

cyber insurance in other states.

Need California cyber coverage that clears your contracts?

Tell us about your operation and your loss history — we’ll confirm we can write California and structure the limits to match.

Get a California Quote Call (818) 356-8150