| AB 700 and SB 1386 Civil Code Section 1798.25 et seq. |
|
|---|---|
| CITATION | Civil Code § 1798.25 - 1798.29 |
| SUMMARY |
Protects against unauthorized access of computerized data compromising the security, integrity, or confidentiality of personal information. Requires notification if it is determined that personal information has been or will be misused. Notification may be delayed if it will impede law enforcement investigation. Allows substitute notice if the breach affects more than 500,000 people, or would cost more than two hundred fifty thousand dollars ($250,000). |
| DATA COVERED |
When not encrypted, a person's first name or initial and last name combined with:
|
| INDUSTRY | Applies to any person or business that conducts business in California and owns, licenses, or maintains computerized data including personal information. Any agency that owns, licenses or maintains computerized data including personal information. |
| PENALTIES | Act does not provide penalties for violations. |
| Consumer Report Security Freeze Law of 2003 | |
|---|---|
| CITATION | Civil Code Section 1785.10 - 1785.19.5 |
| SUMMARY |
An agency is required to notify individuals following the discovery of the breach of security of the data on any resident of California whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person. Good faith acquisition of personal information by an employee or agent of the agency for the purposes of the agency is not a breach of the security of the system, provided that the personal information is not used or subject to further unauthorized disclosure. Substitute notice is allowed if the agency demonstrates that the cost of providing notice would exceed two hundred fifty thousand dollars ($250,000), or that the affected class of subject persons to be notified exceeds 500,000, or the agency does not have sufficient contact information. |
| DATA COVERED |
The law covers ‘Unencrypted Personal Information.’ Personal information means an individual's first name or first initial and last name in combination with any one or more of the following data elements, when either the name or the data elements are not encrypted:
|
| INDUSTRY | Any person or business that conducts business in California, and that owns or licenses computerized data that includes personal information. |
| PENALTIES | Act does not provide penalties for violations. |
| Civil Code § 1798.80 – 1798.84 | |
|---|---|
| CITATION | California Civil Code § 1798.80 - 1798.84 |
| ENACTED | 2003 |
| SUMMARY | The law establishes requirements for adequate protection and security to be provided for personal information. Any person or business that conducts business in California, and that owns or licenses computerized data that includes personal information, shall disclose any breach of the security of the system following discovery or notification of the breach in the security of the data to any resident of California whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person. |
| DATA COVERED |
The law covers "Personal Information" which means any information that identifies, relates to, describes, or is capable of being associated with, a particular individual, including, but not limited to,
Substitute notice, is allowed if the person or business demonstrates that the cost of providing notice would exceed two hundred fifty thousand dollars ($250,000), or that the affected class of subject persons to be notified exceeds 500,000, or the person or business does not have sufficient contact information. The law also establishes requirements for the use of personal information in connection with direct marketing. |
| INDUSTRY | Applies to a "Business" that owns or licenses personal information about a resident of California. A “business” means a sole proprietorship, partnership, corporation, association, or other group, however organized and whether or not organized to operate at a profit, including a financial institution organized, chartered, or holding a license or authorization certificate under the law of this state, any other state, the United States, or of any other country, or the parent or the subsidiary of a financial institution. The term includes an entity that disposes of records. |
| PENALTIES | A prevailing plaintiff in any action commenced under Section 1798.83 is also entitled to recover his or her reasonable attorney's fees and costs. |