California's amended breach law gives you 30 calendar days to notify affected residents once you discover an incident, down from an open-ended standard. Ohio gives you 45 days and a possible legal defense if your cybersecurity program already meets a recognized framework before the breach happens. If you operate in both states, California's shorter clock sets the pace for your entire response, no matter how your records are split.
As of January 1, 2026, California Civil Code Section 1798.82 requires you to notify affected residents within 30 calendar days of discovering a breach. That replaced the old "most expedient time possible and without unreasonable delay" language, which let businesses argue about what counted as reasonable for months after an incident closed out. The statute's current text is explicit on this point: the clock starts at discovery or notification, not at the end of your investigation, and not once legal counsel finally signs off on a draft letter.
Senate Bill 446 made the change, and California now sits alongside Colorado, Florida, Maine, New York, and Washington in setting a firm 30-day trigger, according to analysis from McDonald Hopkins. Thirty days sounds workable until you count what has to happen inside it: containment, forensic scoping, legal review, drafting the actual notice, printing and mailing it if you still have postal addresses on file, and coordinating with any vendor who touched the data. If a single incident affects more than 500 California residents, you also have to submit a sample notice to the state Attorney General within 15 calendar days of notifying individuals, which the California Attorney General's office confirms is a separate filing obligation layered on top of the consumer deadline, not a substitute for it.
The law still allows a delay when a law enforcement agency determines that notification would interfere with a criminal investigation, or when you genuinely need more time to determine the scope of the breach and restore the integrity of your systems. That exception is narrow in practice. It is not a general grace period, and it does not cover the time you spend deciding internally who is responsible for pulling the trigger on notification.
Missing the deadline does not require proof of harm before it becomes a problem. A notice that goes out on day 45 because your team was still finishing a forensic report is not a compliance nuance, it is the fact pattern regulators and plaintiffs' attorneys look at first when deciding whether to open an inquiry.
Ohio's Data Protection Act, codified at Ohio Revised Code Chapter 1354, does not touch your notification deadline at all. It gives you an affirmative defense against tort lawsuits claiming you failed to implement reasonable security controls, but only if you can show a documented cybersecurity program that reasonably conforms to a named framework, and only once litigation is already underway.
The safe harbor statute requires the program to include administrative, technical, and physical safeguards, scaled to your size, the sensitivity of what you hold, and the resources you reasonably have available. The qualifying frameworks named in Ohio Revised Code 1354.03 include the NIST Cybersecurity Framework, NIST SP 800-171, the FedRAMP security assessment framework, ISO/IEC 27000-series standards, the PCI Data Security Standard, HIPAA, and the Gramm-Leach-Bliley Act, among others, and the statute requires conformance to the current version of whichever one you rely on, not an older edition you adopted years ago. Separately, notification timing runs through a different statute entirely: Ohio Revised Code Section 1349.19 gives you up to 45 days after discovering a breach to notify affected residents, considerably more room than California now allows.
That gap between the two statutes is where businesses trip. A policy binder written for an audit two years ago does not establish that your program "reasonably conforms" to anything if nobody has touched it since. Securafy's Essential Care service exists for exactly this problem, keeping documented controls operating continuously instead of refreshed once a year right before a renewal or an insurance application.
You do not get to pick the friendlier deadline. When a single incident affects people in more than one state, you have to meet the strictest timeline that applies to any of them, and in a California-Ohio mix that is almost always California's 30 days.
This is the part most incident response plans miss. A business built around Ohio's 45-day window, and comfortable in that window because of an Ohio safe harbor claim, still has to move at California speed the moment even one affected person lives there. Picture a Columbus-based professional services firm with a dozen remote employees in California, a handful of California-based clients, and the rest of its records in Ohio. One ransomware incident that touches its HR system now runs on California's clock for the whole business, even though the vast majority of the affected records are Ohio-based. The safe harbor helps that firm defend a lawsuit later. It does nothing to extend the clock it is on right now.
| Requirement | California | Ohio |
|---|---|---|
| Consumer notification deadline | 30 calendar days from discovery (Civil Code 1798.82, effective January 1, 2026) | 45 days from discovery (Revised Code 1349.19) |
| Regulator notification | Sample notice to the Attorney General within 15 days of consumer notice, for breaches over 500 residents | No parallel filing requirement in the notification statute |
| Pre-2026 / current standard | Replaced "most expedient time possible... without unreasonable delay" | Still "most expedient time possible," capped at 45 days |
| Safe harbor available | No | Yes, under Revised Code Chapter 1354, if a qualifying program was already running |
Working out which state's clock governs your response is not something you want to figure out for the first time while a forensic firm is on the phone asking for a decision by end of day. It needs to happen now, while there is no pressure attached to the answer and no regulator watching how long the analysis takes.
Most of this starts with an honest picture of where your data actually sits and who can reach it, which is exactly what Securafy's cybersecurity assessment tool is built to surface before you are staring down a 30-day countdown instead of planning around one.
No. The statute requires the program to reasonably conform to a recognized framework in practice, and Ohio Revised Code 1354.03 goes as far as requiring conformance to "the entirety of the current version" of any regulatory framework you rely on, not a snapshot from whenever you last updated your documentation.
A 30-day or 45-day clock does not pause while you figure out who owns notification, whether your logging actually covers what a forensic investigator needs, or whether the framework you cited in a contract two years ago is still the one your controls reflect. Treating the safe harbor as a one-time compliance project instead of an ongoing program is the single most common way Ohio businesses lose the defense right when they need it most.
If you want the safe harbor to hold up, keep evidence, not just a document. Before you rely on it in a real incident, you should be able to produce all of the following without scrambling to assemble them after the fact:
Businesses that can produce that evidence quickly are in a materially different position than businesses that have to reconstruct it under deposition pressure months into a lawsuit.
Where your data lives should set your breach response timeline, not where your headquarters sits. California's 30-day rule and Ohio's 45-day window with its conditional safe harbor are two data points in a patchwork of state laws that keeps shifting, and neither one waits for the other to catch up. A business that only tracks its home state's requirement is exposed the moment it has customers, remote employees, or a vendor relationship that touches personal data anywhere else, and most small and mid-sized businesses hit that mark faster than they expect. A single SaaS vendor, a single remote hire, or a single client engagement in another state is enough to bring that state's deadline into play, and none of it requires you to open an office there.
If you are evaluating a new security vendor, a new cyber insurance policy, or a new managed provider specifically because of this exposure, Securafy's cybersecurity buyer's guide lays out the questions worth asking before you sign anything, including how a vendor's own documentation practices affect your compliance posture during an incident, not just your defenses before one.
Multi-state breach deadlines do not wait for your team to figure out which law applies while an incident is already in progress. If you cannot say today which state's clock governs your response, that gap is exactly where a 30-day window gets missed.
If your team is moving faster with AI than your guardrails are, start with structured training rather than another tool. Securafy AI University gives your people role-based AI training with security built into the material, not bolted on afterward.
If you would rather talk through your specific environment first, book a strategy call with Securafy and we will walk your current AI usage, exposure, and the fastest path to safe adoption.