You are a California resident and want to confirm whether a breach notice matches the sample submitted to the state.
California requires notice in defined breach situations
The California Attorney General explains that businesses and state or local agencies must notify California residents when unencrypted personal information, as defined by state law, was acquired or reasonably believed to have been acquired by an unauthorized person. The exact statutory definitions and exceptions matter, so treat the Attorney General’s guidance and linked code as the source rather than relying on a generic fifty-state summary.
For a consumer, the practical value is understanding that the notice is part of a legal reporting framework, not merely a courtesy email.
Use the Attorney General’s public breach search
California publishes sample notices submitted to the Attorney General for incidents that meet the state’s submission threshold. Search by organization name and compare the sample with the letter or email you received.
A public sample may omit your personal details, but it can confirm the incident description, dates, data categories, and offered services.
Separate what the company must report from what you should do
State notification rules describe obligations for the organization. Your personal response still depends on what data about you was involved. An SSN exposure may justify freezes and credit review; a payment-card exposure calls for issuer action; health information may require medical-record review.
Do not treat the state notice deadline as a timetable for your own security actions.
Keep a copy of the sample notice with your own notice
If the public database contains a matching sample, save the page or PDF and note the date you checked it. This can help later if the organization updates its description of the breach or if you need to show where the incident information came from.
Do not upload your own sensitive documents to a public database when looking for verification.
Use official complaint channels for consumer issues
The Attorney General’s breach-reporting page distinguishes between the business submission process and consumer complaint options. Consumers should use the consumer route rather than attempting to submit the business breach-reporting form.
For questions about how the law applies to a specific legal claim, use a qualified attorney; this guide is limited to reading and response workflow.
Use the public notice database as a verification tool, not a victim list
California’s breach database publishes sample notices submitted by organizations that meet the state’s filing requirement. It does not tell you that every California customer of the organization was affected. Compare the dates, product, and data categories in the public sample with the notice sent to you and with information in your account.
If you find the organization in the database but never received a personal notice, contact the organization through its official incident channel to ask whether your information was involved. Do not provide extra sensitive data to a third-party breach tracker.
Read the statutory links when a precise legal question matters
The Attorney General’s page links to the California Civil Code sections governing breach notices. If you need to know the legal definition of personal information, the conditions that trigger notice, or the exact content requirements, use those current statutory sources. Summaries are useful for orientation but can omit exceptions or amendments.
This site does not decide whether a particular company violated California law. A compliance dispute requires the facts of the incident and, when necessary, legal advice.
Keep the state complaint process separate from your security response
A complaint to the Attorney General can document a concern about an organization, but it does not freeze your credit, replace a card, correct a medical record, or close a fraudulent account. Continue the relevant recovery work while any complaint is pending.
Save the complaint confirmation number with the breach record if you submit one. That makes the administrative history easier to follow later.
Example: checking a California notice against the state database
Suppose a health company sends you a breach letter that names an incident date, a vendor, and several data categories. Go to the California Attorney General’s data-breach search and look for the organization or the entity that submitted the notice. Open the public sample and compare the description, dates, types of information, and offered services with the document you received.
If the public sample matches, save or print it with your personal notice. If it differs in a meaningful way—such as a later incident window or additional data categories—check the company’s official incident page for an update and record the new information. A public sample is useful evidence, but it does not itself prove exactly which fields belonging to you were involved.
Then return to the practical response. If your notice names an SSN, use the SSN response workflow; if it names a payment card, contact the issuer; if it names medical information, inspect health records as appropriate. The California database helps verify the state reporting record. It does not replace the data-specific work you need to do.
- Search the Attorney General’s public breach list.
- Compare the public sample with your notice.
- Save both versions with dates.
- Use statutory links for precise legal questions.
- Use consumer complaint channels rather than the business reporting form.
Keep the state record with the personal response
If you use the California breach database to verify the incident, record the URL, organization name, and date you checked it. State databases can be updated, and a later reader should be able to understand which version you relied on. Keep that record beside your personal notice, freeze confirmations, bank case numbers, or medical corrections. The public filing documents the organization’s reporting; your incident folder documents what you did with the information that affected you.
Treat the California breach database as a verification tool, not a complete list
If the state database does not show the incident, that alone does not prove your notice is false. The public submission requirement depends on the circumstances described by California law, including the number of residents notified. Verify the notice with the organization directly and use the Attorney General’s consumer resources for questions about the state process.


