AB 1859 California Assembly · 2017-2018 Regular Session

Customer records.

Summary
Existing law regulating consumer credit reporting agencies provides as its purpose to require, among other things, that these agencies adopt reasonable procedures for meeting the needs of commerce for consumer credit in a manner that is fair and equitable to the consumer with regard to the confidentiality of such information and in a manner that will best protect the interests of the people of the state. Existing law requires a person or business that owns or licenses computerized data that includes personal information to disclose any breach of the security of the system following discovery or notification of the breach in the security of the data to any resident of California whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person, or, whose encrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person and the encryption key or security credential was, or is reasonably believed to have been, acquired by an unauthorized person and the agency that owns or licenses the encrypted information has a reasonable belief that the encryption key or security credential could render that personal information readable or useable. Existing law requires the disclosure to be made in the most expedient time possible and without unreasonable delay, as specified. Existing law authorizes any customer who is injured by a violation of these provisions to institute a civil action to recover damages. This bill would require a consumer credit reporting agency that owns, licenses, or maintains personal information about a California resident, or a 3rd party that maintains personal information about a California resident on behalf of a consumer credit reporting agency, that knows, or reasonably should know, that a computer system it owns, operates, or maintains, and for which it controls the security protocols, is subject to a security vulnerability that poses a significant risk to the security of computerized data within the system that contains personal information, to take certain measures to protect that data, including implementing software updates, if it knows or reasonably should know that a software update is available to address the security vulnerability, and employing reasonable compensating controls to reduce the risk of a breach caused by computer system vulnerability until the software update is complete, as specified.
Bill status signed all 5 stages cleared
Introduction
Jan 2018
Committee Review
Aug 2018
Assembly Passage
May 2018
Senate Passage
Aug 2018
Signed into Law
Sep 2018
Introduced Jan 10, 2018 Signed Sep 19, 2018
Floor votes · Senate Aug 27, 2018 · Assembly May 31, 2018

How they voted

39–0
Passed · 1 other
Total votes 40
Aug 27, 2018
D Democratic26
26 Yea
100% Yea
R Republican14
13 Yea 1
92% Yea
Vote distribution
All Yea All Nay Mixed No data
Full legislative history

Actions timeline

Total actions
28
Key actions
11
Committee
8
Amendments
5
Sep 19, 2018
Signed into law
Approved by the Governor.
legislature
Aug 29, 2018
Lower · Passed
Senate amendments concurred in. To Engrossing and Enrolling. (Ayes 80. Noes 0. Page 6830.).
lower
Aug 27, 2018
Senate · Passed
Senate Vote: pass (39-0-1)
senate
Aug 27, 2018
Introduced
In Assembly. Concurrence in Senate amendments pending. May be considered on or after August 29 pursuant to Assembly Rule 77.
lower
Aug 22, 2018
Upper · Passed
Read third time and amended. Ordered to second reading.
upper
Aug 17, 2018
Upper · Passed
From committee: Amend, and do pass as amended. (Ayes 5. Noes 2.) (August 16).
upper
Aug 6, 2018
Committee
In committee: Referred to APPR. suspense file.
upper
Jun 27, 2018
Upper · Passed
From committee: Do pass and re-refer to Com. on APPR. (Ayes 5. Noes 2.) (June 26). Re-referred to Com. on APPR.
upper
Jun 13, 2018
Committee
Referred to Coms. on JUD. and APPR.
upper
May 31, 2018
Assembly · Passed
Assembly Vote: pass (55-15-5)
assembly
May 2, 2018
Lower · Passed
From committee: Amend, and do pass as amended. (Ayes 8. Noes 2.) (May 1).
lower
Apr 23, 2018
Committee
Re-referred to Com. on JUD.
lower
Apr 18, 2018
Lower · Passed
From committee: Amend, and do pass as amended and re-refer to Com. on JUD. (Ayes 9. Noes 1.) (April 17).
lower
Apr 2, 2018
Lower · Passed
In committee: Hearing postponed by committee.
lower
Jan 29, 2018
Committee
Referred to Coms. on P. & C.P. and JUD.
lower
Jan 11, 2018
Lower · Passed
From printer. May be heard in committee February 10.
lower
1 primary · 0 co-sponsors

Sponsors

Role
Legislator
Party
State
District
P
Photo of Ed Chau
Ed Chau
DDemocratic
CA
49