AB 739 California Assembly · 2015-2016 Regular Session

Civil law: liability: communication of cyber security-threat information.

Summary
Existing law requires a business that owns, licenses, or maintains personal information about a California resident to implement and maintain reasonable security procedures and practices appropriate to the nature of the information to protect the personal information from unauthorized access, destruction, use, modification, or disclosure. Existing law requires a person or business conducting business in California that owns or licenses computerized data that includes personal information, as defined, to disclose, as specified, a breach of the security of the system or data following discovery or notification of the security breach to any California resident whose personal information was, or is reasonably believed to have been, acquired by an unauthorized person, unless the information was encrypted. Existing law also requires a person or business that maintains computerized data that includes personal information that the person or business does not own to notify the owner or licensee of the information of any breach of the security of the data immediately following discovery, as specified. This bill would, until January 1, 2020, provide that there shall be no civil or criminal liability for, and no cause of action shall lie or be maintained against any private entity for the sharing or receiving of cyber security-threat information if the sharing or receiving is conducted, as specified. The immunity from liability would only apply if the communication is made without gross negligence, as specified. The bill would also prohibit a private entity that is engaged in sharing or receiving cyber security-threat information from using that information to gain an unfair competitive advantage and require that it, in good faith, make reasonable efforts to safeguard communications, comply with any lawful restriction placed on the communication, transfer the cyber security-threat information as expediently as possible while upholding reasonable protections, and ensure that appropriate anonymization and minimization of the information contained in the communication, as specified.
Bill status failed 1 of 4 stages cleared
Introduction
Feb 2015
Committee Review
Floor Vote
Governor
Introduced Feb 25, 2015 Last action Feb 1, 2016
Floor votes

How they voted

No floor votes recorded yet.
Full legislative history

Actions timeline

Total actions
19
Key actions
5
Committee
12
May 12, 2015
Lower · Passed
In committee: Set, second hearing. Hearing canceled at the request of author.
lower
May 4, 2015
Committee
Re-referred to Com. on JUD.
lower
Apr 28, 2015
Lower · Passed
In committee: Set, first hearing. Hearing canceled at the request of author.
lower
Apr 22, 2015
Committee
From committee: Do pass and re-refer to Com. on JUD. (Ayes 11. Noes 0.) (April 21). Re-referred to Com. on JUD.
lower
Apr 20, 2015
Committee
Re-referred to Com. on P. & C.P.
lower
Apr 13, 2015
Committee
Re-referred to Coms. on P. & C.P. and JUD. pursuant to Assembly Rule 96.
lower
Apr 13, 2015
Lower · Passed
In committee: Hearing postponed by committee.
lower
Apr 13, 2015
Committee
Re-referred to Com. on JUD.
lower
Apr 6, 2015
Lower · Passed
In committee: Hearing postponed by committee.
lower
Apr 6, 2015
Committee
Re-referred to Com. on JUD.
lower
Mar 26, 2015
Committee
Referred to Coms. on JUD. and P. & C.P.
lower
Feb 26, 2015
Lower · Passed
From printer. May be heard in committee March 28.
lower
1 primary · 0 co-sponsors

Sponsors

Role
Legislator
Party
State
District
P
Photo of Jacqui Irwin
Jacqui Irwin
DDemocratic
CA
42