What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
A data breach notice tells you that an organization believes your personal information was involved, or may have been involved, in a security incident. It should explain what happened, what information may be affected, and where to get more details. The exact information a company must disclose—and whether it must notify you at all—depends on the law that applies. The examples below cover the EU GDPR and California, not every jurisdiction.
What a data breach notice tells you
Receiving a notice means the organization believes your information was involved or potentially involved in an incident. It does not, by itself, establish that someone used your information fraudulently or that every recipient faces the same level of risk.
A useful notice explains the incident and the categories of information that may be involved, along with what the organization knows, what it has done or plans to do, and how you can contact it for more information. The required details vary by jurisdiction.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →How the GDPR and California rules compare
The GDPR and California law have different triggers, timing rules, and notice requirements. The table summarizes the specific examples addressed here; it is not a universal checklist.
#1 Best Overall
| Question | EU GDPR | California business notices |
|---|---|---|
| When must individuals be notified? | When the breach is likely to result in a high risk to people’s rights and freedoms. GDPR Article 34 | A covered business must notify a California resident if qualifying personal information was acquired, or is reasonably believed to have been acquired, by an unauthorized person. The law also addresses encrypted information if a key or credential may make it readable or usable. California Civil Code §1798.82, 2025 text |
| When must the notice be sent? | “Without undue delay” after the applicable individual-notice threshold is met. GDPR Article 34(1) | The statute requires disclosure following discovery or notification, subject to statutory delay rules. The notice-content provisions do not establish one universal numerical deadline. California Civil Code §1798.82, 2025 text |
| What must the individual notice include? | A plain-language description of the breach’s nature, a contact point, likely consequences, and measures taken or proposed. GDPR Article 34(2) | Plain language; the reporting person or business’s name and contact information; the types of information involved; breach or estimated breach dates or date range when determinable; the notice date; and, when determinable, whether notice was delayed because of a law-enforcement investigation. The statute also requires the title “Notice of Data Breach” and prescribed headings. California Civil Code §1798.82, 2025 text |
| Is there a separate regulator report? | Yes. A supervisory-authority report under Article 33 is separate from telling affected individuals. It is generally due within 72 hours where feasible, unless the breach is unlikely to create a risk to people’s rights and freedoms. GDPR Article 33 | The California Attorney General says a sample notice must be submitted when a covered entity sends notice to more than 500 California residents. California Attorney General reporting guidance |
What the GDPR requires for an individual notice
Under Article 34, the organization must communicate the breach to affected individuals when it is likely to result in a high risk to their rights and freedoms. The communication should use “clear and plain language” and describe the nature of the breach, provide a contact point, explain likely consequences, and identify measures taken or proposed to address it.
Article 34 includes exceptions. For example, individual communication may not be required if protective measures made the affected data unintelligible to unauthorized people. The GDPR’s individual-notice test is distinct from its regulator-reporting rule: Article 33 generally requires notice to the supervisory authority within 72 hours where feasible unless the breach is unlikely to create a risk to people’s rights and freedoms.
What California requires in a business notice
California Civil Code §1798.82 sets out notice requirements for covered businesses. The 2025 text reproduced by Justia calls for plain language, specified identifying and contact details, the types of information involved, and dates related to the breach and notice when those dates can be determined. It also addresses disclosure of a law-enforcement investigation delay when determinable, and requires the title “Notice of Data Breach” and prescribed headings.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteThe California Attorney General’s reporting guidance says a sample notice must be submitted when a covered entity notifies more than 500 California residents. This is a separate step from sending notice to the affected people.
How to read a notice you receive
- Check which information categories are named. A notice should identify the kinds of information that may be involved; the notice does not necessarily mean every listed item was accessed or misused.
- Look for the organization’s explanation and contact point. Use the contact details in the notice to ask what is known about your information and where to find updates.
- Separate confirmed facts from possible exposure. Pay attention to whether the notice says information was confirmed as involved or may have been involved, and to any explanation of the organization’s response.
- Do not assume a particular remedy is legally guaranteed. The cited rules do not establish a universal requirement to provide identity-theft monitoring, compensation, or a fixed period of free service.
Why requirements differ
Notice duties depend on jurisdiction, the type of organization and information, and the legal threshold for notifying individuals. GDPR Article 34 uses a high-risk threshold for communicating with individuals; California’s statute uses its own covered-business and personal-information rules. Neither example supplies a complete account of every U.S. state, federal sector, or country. The California statutory link above is a third-party reproduction of 2025 code text, so it should not be treated as a substitute for checking the official code where legal reliance is needed.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

