State Data Breach Notification Letter
CALIFORNIA INCIDENT AND NOTICE DEVELOPMENT PACKET
DO NOT SEND OR FILE. Keep business, government, sector, contract, owner,
regulator, consumer, and institutional routes separate.
1. Incident, role, and jurisdiction map
| Item | Verified entry |
|---|---|
| Organization, incident, discovery date/time, and counsel | [________________________________] |
| Systems, vendors, locations, and incident period | [________________________________] |
| Owner, licensee, maintainer, processor, agency, employer, or other role | [________________________________] |
| California residents and other jurisdictions | [________________________________] |
| Sector, contract, insurer, regulator, and law-enforcement overlays | [________________________________] |
2. Current authority register
| Issue | Current primary authority/instruction | Operative text | Facts | Result |
|---|---|---|---|---|
| Covered entity/role and resident | [SOURCE] | “[QUOTE]” | [____] | [____] |
| Covered data and readable/protected status | [SOURCE] | “[QUOTE]” | [____] | [____] |
| Access, acquisition, disclosure, compromise, and exclusions | [SOURCE] | “[QUOTE]” | [____] | [____] |
| Consumer, owner, agency, regulator, and institutional notice | [SOURCE] | “[QUOTE]” | [____] | [____] |
| Timing, delay, method, content, format, translation, and sample | [SOURCE] | “[QUOTE]” | [____] | [____] |
| Enforcement, evidence, retention, and amendment status | [SOURCE] | “[QUOTE]” | [____] | [____] |
3. Population and investigation record
| Population | Residency | Data combination | Protection status | Access/acquisition finding | Count |
|---|---|---|---|---|---|
| [____] | [____] | [____] | [____] | [____] | [____] |
| Date | Event/finding | Evidence | Confidence/open issue |
|---|---|---|---|
| [____] | [____] | [____] | [____] |
Do not state “no evidence,” “no misuse,” or “no access” without documenting the
search, evidence limits, and reviewer.
4. Decision, deadline, and recipient control
| Route/population | Trigger and facts | Required? | Deadline | Recipient/method/form | Approver/proof |
|---|---|---|---|---|---|
| [____] | [____] | [YES/NO/UNRESOLVED] | [____] | [____] | [____] |
5. Consumer-notice workspace
What happened: [verified dates, facts, containment, and investigation status]
Information involved: [recipient-specific categories only]
What the organization has done: [completed and funded measures]
Steps/resources: [authority-approved, accurate, data-specific resources]
Optional services and contact: [provider, eligibility, terms, deadline, support]
Prepare separate owner, regulator, agency, institutional, law-enforcement, and
public communications. Preserve approved versions, recipient logic, delivery
evidence, returns, corrections, portal receipts, and source records.
☐ Qualified California privacy counsel approved every outgoing communication
About this template
- Last updated
- August 27, 2026
- Citations checked
- August 27, 2026
- Jurisdiction
- California
- Category
- Legal Letters & Correspondence
Formal legal letters create a written record, trigger response deadlines, and often preserve rights under a statute or contract. Cease-and-desist letters, notice letters, and formal responses all have their own expected format, and the language used can mean the difference between a quick resolution and a courtroom fight. Well-drafted correspondence also documents that you tried to resolve things reasonably, which matters if the dispute escalates later.
Not legal advice
This template is provided for informational purposes. We recommend having an attorney review any legal document before signing, especially for high-value or complex matters.
Checked against the law it cites
A reviewer verified this template's legal citations against the official source on August 27, 2026.
Draft your State Data Breach Notification Letter in the editor
Answer a few questions, let the AI editor draft each section from your answers, review it, and download Word and PDF. $99 one time, or $249 per month for every document and every Ezel app.