Civil law: liability: communication of cyber security-threat information.
Summary
Existing law requires a business that owns, licenses, or maintains personal information about a California resident to implement and maintain reasonable security procedures and practices appropriate to the nature of the information to protect the personal information from unauthorized access, destruction, use, modification, or disclosure. Existing law requires a person or business conducting business in California that owns or licenses computerized data that includes personal information, as defined, to disclose, as specified, a breach of the security of the system or data following discovery or notification of the security breach to any California resident whose personal information was, or is reasonably believed to have been, acquired by an unauthorized person, unless the information was encrypted. Existing law also requires a person or business that maintains computerized data that includes personal information that the person or business does not own to notify the owner or licensee of the information of any breach of the security of the data immediately following discovery, as specified. This bill would, until January 1, 2020, provide that there shall be no civil or criminal liability for, and no cause of action shall lie or be maintained against any private entity for the sharing or receiving of cyber security-threat information if the sharing or receiving is conducted, as specified. The immunity from liability would only apply if the communication is made without gross negligence, as specified. The bill would also prohibit a private entity that is engaged in sharing or receiving cyber security-threat information from using that information to gain an unfair competitive advantage and require that it, in good faith, make reasonable efforts to safeguard communications, comply with any lawful restriction placed on the communication, transfer the cyber security-threat information as expediently as possible while upholding reasonable protections, and ensure that appropriate anonymization and minimization of the information contained in the communication, as specified.
Bill status
failed
1 of 4 stages cleared
Introduction
Feb 2015
Committee Review
Floor Vote
Governor
Introduced Feb 25, 2015
Last action Feb 1, 2016
Floor votes
How they voted
No floor votes recorded yet.
Full legislative history
Actions timeline
Total actions
19
Key actions
5
Committee
12
May 12, 2015
Lower · Passed
In committee: Set, second hearing. Hearing canceled at the request of author.
lower
May 4, 2015
Committee
Re-referred to Com. on JUD.
lower
Apr 28, 2015
Lower · Passed
In committee: Set, first hearing. Hearing canceled at the request of author.
lower
Apr 22, 2015
Committee
From committee: Do pass and re-refer to Com. on JUD. (Ayes 11. Noes 0.) (April 21). Re-referred to Com. on JUD.
lower
Apr 20, 2015
Committee
Re-referred to Com. on P. & C.P.
lower
Apr 13, 2015
Committee
Re-referred to Coms. on P. & C.P. and JUD. pursuant to Assembly Rule 96.
lower
Apr 13, 2015
Lower · Passed
In committee: Hearing postponed by committee.
lower
Apr 13, 2015
Committee
Re-referred to Com. on JUD.
lower
Apr 6, 2015
Lower · Passed
In committee: Hearing postponed by committee.
lower
Apr 6, 2015
Committee
Re-referred to Com. on JUD.
lower
Mar 26, 2015
Committee
Referred to Coms. on JUD. and P. & C.P.
lower
Feb 26, 2015
Lower · Passed
From printer. May be heard in committee March 28.
lower
1 primary · 0 co-sponsors
Sponsors
Role
Legislator
Party
State
District
P
Jacqui Irwin
DDemocratic
Ask Maddy
·
AI policy assistant
Ask Maddy about AB 739
Scope: CA
Hi! I can help you understand AB 739. What would you like to know?
Try one of these
i
Maddy answers using official bill text and legislative records. Always verify before sharing.
Sources cited inline