Skip to main content

What To Do If Your Business Experiences A Data Breach

By , Attorney at Law

I still recall when a colleague told me his website data had been accessed by an unauthorized person. He felt embarrassed, stressed, and worried about losing customers’ trust. If your business experiences a data breach, you may share those same feelings. Instead of panicking, consider some measured steps that can help you regain control and confidence.

1. Contain the Breach

Your first priority is to stop the bleeding. If you have an IT team, ask them to isolate affected systems and secure your network. If you’re a smaller operation, reach out to a trusted cybersecurity expert. Quick action prevents more data from escaping and keeps the damage from spreading.

2. Figure Out What Happened

Your next move is to investigate the breach. Identify which systems were compromised and the type of data involved—such as customer names, addresses, or payment details. Understanding the scope helps you craft a plan that fits your unique situation.

3. Notify the Right People

Notification is a legal duty with deadlines, not a public relations choice, and in California the duty sits in statute.

Cal. Civ. Code § 1798.82 requires a business that owns or licenses computerised data including personal information to notify any California resident whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorised person. The notice must go out in the most expedient time possible and without unreasonable delay, subject only to the legitimate needs of law enforcement and to the time needed to determine the scope of the breach and restore the integrity of the system. Since January 1, 2026 (SB 446), that outer standard is paired with a hard deadline: notice must go out within 30 calendar days of discovering the breach, and a long internal investigation is not by itself an excuse for missing it.

The statute also sets the content. The notice must be written in plain language, titled “Notice of Data Breach”, and organised under the headings “What Happened?”, “What Information Was Involved?”, “What We Are Doing”, “What You Can Do” and “For More Information”, in text no smaller than 10-point type. If the breach exposed a Social Security number, or a driver’s licence number, California identification card number, tax identification number, passport number, military identification number or other unique government-issued identification number, the business must offer at least twelve months of identity theft prevention and mitigation services at no cost.

If a single breach requires notice to more than 500 California residents, the business must also submit a sample copy of the notice, with personally identifiable information removed, to the California Attorney General within 15 calendar days of notifying the affected residents. If you merely maintain data owned by another business, § 1798.82(b) requires you to notify that owner immediately after discovery.

Separately, Cal. Civ. Code § 1798.150 gives consumers a private right of action where non-encrypted and non-redacted personal information is subject to unauthorised access and exfiltration, theft, or disclosure as a result of the business’s failure to maintain reasonable security procedures. Statutory damages are set at $100 to $750 per consumer per incident and adjusted for inflation every odd year; the figures in effect since January 1, 2025 are $107 to $799. Actual damages apply if greater, and the claim can be brought as a class action. A consumer must first give 30 days’ written notice, and a business that cures within that window and confirms it in writing blocks statutory damages, though adding security measures after the fact is generally not treated as curing a breach that already happened. That provision, not the regulatory penalty, is what turns a moderate breach into an existential number.

Other obligations may attach on top: contractual notice deadlines to enterprise customers, sector rules such as HIPAA, and other states’ notification statutes for residents outside California. Complying promptly also preserves credibility with customers when the news is unwelcome.

4. Offer Help to Affected Users

People feel scared or angry when their information leaks. Ease these worries by providing resources, like credit monitoring services or a dedicated hotline. By guiding them through the next steps, you show you care about their well-being. This gesture can soften the blow of a breach and help maintain goodwill.

5. Strengthen Security

After you patch the immediate holes, it’s time to make your defenses stronger. Update your passwords, install regular software patches, and review your network for weak spots. If you don’t have a crisis plan for future incidents, create one now. Breaches can happen to any business. A solid response strategy helps you bounce back faster.

6. Document Everything

Keep a clear record of what happened, when it happened, and how you responded. This documentation will help you explain your actions if regulators ask questions. It also offers a blueprint so you can avoid repeating past mistakes.

7. Address Common Concerns

“Will people trust me again?”

Trust can be rebuilt. Prompt notifications and genuine efforts to fix the problem prove you take data protection seriously.

“I don’t have an IT department. Am I sunk?”

Not necessarily. Cybersecurity firms and consultants can step in to help seal the breach and train your staff on safe practices.

“Will I get fined?”

It depends on the laws in your region and your industry. Taking quick, transparent action may help lower the risk of penalties.

A data breach can trigger legal obligations you might not fully understand. An attorney can help you navigate those responsibilities, advise on disclosure requirements, and guide you on practical safeguards to avoid more trouble. You don’t need to have all the answers yourself. Leaning on legal insight can save you from bigger headaches down the road.

A data breach is unsettling. You might feel like your entire operation is under siege. Yet how you handle that chaos speaks volumes. By containing the breach, being open with your customers, and strengthening your security measures, you can move forward. You may even discover that taking these steps leads to a safer, more resilient business in the long run.

Have a question about this topic?

Start with a free 30-minute discovery call. Most related work is available at a flat rate.

See flat-rate pricing

Fill out the form below and we'll get back to you shortly.

By submitting this form you agree to our Terms & Privacy Policy. Submitting this form does not create an attorney-client relationship.