Skip to content
New field report2026 Litigation ReadinessDownload free
Collection and sale, not the breach that follows — California
Legal structure

Data Privacy Litigation (CCPA & Biometric) in California

An educational explainer on how data privacy litigation (ccpa & biometric) cases resolve in California courts — the deadlines, the venue rules, and the strategy you can war-game as a simulation.

California courts

Where this case gets filed

California consolidated its trial courts into a single, unified Superior Court in each of its 58 counties, which now handles all general civil litigation — there is no separate municipal or small-claims court, just divisions within the same Superior Court. Limited civil cases (generally $35,000 or less) and unlimited civil cases (above that threshold) are both filed in Superior Court but proceed under different procedural tracks.

Venue is generally proper in the county where the defendant resides at the time the action is filed, or, for many contract and injury claims, where the obligation was to be performed or the injury occurred. Real property disputes are venued where the property is located.

Deadlines

California statutes of limitations

  • Written contract: 4 years
  • Oral contract: 2 years
  • Personal injury: 2 years
  • Fraud: 3 years from discovery
  • Property damage: 3 years
  • Professional malpractice: Generally 1-3 years depending on the profession — confirm current statute

Governing rules: California Code of Civil Procedure.

The claims

What the two sides are actually fighting over

Biometric Privacy Violation (BIPA-Style Statutes)

  • Defendant collected, captured, or otherwise obtained a biometric identifier or biometric information
  • Defendant failed to provide required written notice and obtain informed written consent before collection
  • Defendant lacked, or failed to publish, a compliant data retention and destruction schedule
  • Defendant profited from, disclosed, or transferred the biometric data without a qualifying exception

Unlawful Sale or Disclosure of Personal Information (CCPA-Style Statutes)

  • Defendant is a business subject to the statute's collection, sale, or disclosure obligations
  • Defendant sold, shared, or disclosed personal information without honoring a required opt-out or notice
  • The consumer's data qualifies as personal information under the statute's definition
  • The claim falls within an enforceable private right of action or supports a derivative consumer-protection claim
Damages & fault

How California apportions fault and damages

California applies pure comparative negligence, meaning a plaintiff's recovery is reduced by their percentage of fault but is never entirely barred, even if they were mostly responsible. California does not impose a general statutory cap on punitive damages, though due-process reasonableness limits apply, and separate statutory caps exist in specific contexts like medical malpractice non-economic damages.

Strategic dynamics

Statutory and per-violation damages structures give these cases class-wide settlement leverage that can be disproportionate to any actual, provable harm, which is precisely what makes the threshold standing fight, whether a bare statutory violation is a concrete Article III injury, so consequential: it decides whether the case is ever resolved on the merits at all. Consent timing is the pivotal fact in biometric cases, since consent obtained after first collection generally does not cure the violation, and per-scan damages exposure scales directly with the size of the affected workforce or customer base, turning even a narrow compliance gap into significant aggregate exposure.

In Juricratic

How this area is war-gamed

  • Model the biometric consent sequence, notice given, written consent obtained, retention schedule published, as an ordered set of dials, and see which single missing step is enough to establish a violation.
  • Represent per-violation or per-scan statutory damages as a scaling function of class size so the settlement-pressure curve is visible before any actual-harm showing is made.
  • Play the Article III standing fight over a bare statutory violation from either seat to see whether the case even reaches the merits.
  • Swing the CCPA-style "sale versus service provider" characterization dial to see how a data-sharing arrangement moves between exempt and actionable.
Questions
What is the statute of limitations for a data privacy litigation (ccpa & biometric) claim in California?
It depends on the specific claim, but California's general limitations periods are: written contract claims — 4 years; fraud claims — 3 years from discovery. Every case has its own facts and possible tolling exceptions, so confirm the exact deadline against the current California Code of Civil Procedure before relying on it.
Which court hears a data privacy litigation (ccpa & biometric) case in California?
California consolidated its trial courts into a single, unified Superior Court in each of its 58 counties, which now handles all general civil litigation — there is no separate municipal or small-claims court, just divisions within the same Superior Court. Limited civil cases (generally $35,000 or less) and unlimited civil cases (above that threshold) are both filed in Superior Court but proceed under different procedural tracks.
Does California cap damages or use comparative negligence?
California applies pure comparative negligence, meaning a plaintiff's recovery is reduced by their percentage of fault but is never entirely barred, even if they were mostly responsible. California does not impose a general statutory cap on punitive damages, though due-process reasonableness limits apply, and separate statutory caps exist in specific contexts like medical malpractice non-economic damages.

This page is an educational explainer, not legal advice, and creates no attorney–client relationship. Juricratic is a simulation engine: every probability-like figure is a dial you set, not a calibrated prediction. Verify every rule, deadline, and figure against the authorities and orders that govern your matter.

Rehearse your data privacy litigation (ccpa & biometric) matter in California before you live it.

Juricratic models the whole matter as a solvable game — claims, elements, the bench, and the settlement window — and shows how the optimal line moves when the facts and dials do.

Request access
simulation, not prediction — not legal advice