The California Consumer Privacy Act of 2018 (CCPA) grants to a consumer various rights with respect to personal information that is collected by a business, including the right to request that a business delete personal information about the consumer that the business has collected from the consumer. The California Privacy Rights Act of 2020, an initiative measure approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA. Existing law, the Insurance Information and Privacy Protection Act, establishes privacy standards for the collection, use, and disclosure of information gathered in connection with insurance transactions by insurance institutions, agents, and insurance-support organizations. The Insurance Information and Privacy Protection Act imposes various monetary penalties for violations of the act and makes a person who knowingly and willfully obtains information about an individual from an insurance institution, agent, or insurance-support organization under false pretenses guilty of a misdemeanor. On and after July 1, 2028, this bill would revise the Insurance Information and Privacy Protection Act to establish new standards for the processing and sharing of consumers' personal information by insurance licensees, surplus line insurers, reinsurers, and third-party service providers. The bill would authorize processing or sharing of a consumer's personal information for specified purposes, including sharing in connection with an insurance transaction. The bill would require a licensee, surplus line insurer, reinsurer, or third-party service provider to provide a clear and conspicuous privacy notice presented as a stand-alone document that includes specified information to a consumer within a specified period of time, and would prohibit the sharing of a consumer's personal information unless it is reasonably necessary and proportionate to achieve specified purposes related to an insurance transaction or another purpose that is fully disclosed to the consumer and to which the consumer has consented. The bill would also require a licensee to provide a privacy rights notice, as specified, to each consumer with whom the licensee has an ongoing business relationship. The bill would require a licensee, surplus line insurer, reinsurer, or third-party service provider to obtain a consumer's consent to take specified actions, and would set forth the means by which consent is obtained. The bill would authorize a licensee, surplus line insurer, or reinsurer to retain personal information, as specified, and would require a licensee, surplus line insurer, or reinsurer to develop a written records retention policy and schedule. The bill would require a licensee, surplus line insurer, or reinsurer to provide specified information to a consumer if it makes an adverse underwriting decision, and would provide a process by which a consumer may access, correct, amend, or delete any personal information about the consumer in the possession of the licensee, surplus line insurer, reinsurer, or its third-party service providers. The bill would require a contract between a licensee, surplus line insurer, or reinsurer and a third-party service provider to govern the processing and sharing of personal information performed on behalf of the licensee, surplus line insurer, or reinsurer. The bill would prohibit retaliation against a consumer because the consumer exercised or attempted to exercise their rights under the act. The bill would prohibit public disclosure of specified systems, processes, policies, procedures, and plans that are disclosed to the Insurance Commissioner. The bill would also make technical and conforming changes. This bill would authorize a penalty of at least $5,000, not to exceed $1,000,000 in the aggregate for multiple violations of the act. The bill would increase the fine if a cease and desist order is violated to at least $15,000 for each violation, and would increase a fine to at least $50,000 for each violation if the commissioner finds the violations to be a general business practice. Under the bill, a person who knowingly and willfully obtains information about a consumer from a licensee, surplus line insurer, reinsurer, or third-party service provider under false pretenses would be guilty of a misdemeanor, punishable by a fine of up to $50,000, imprisonment in a county jail for up to 6 months, or both, thus expanding the applicability of a crime and imposing a state-mandated local program. Existing constitutional provisions require that a statute that limits the right of access to the meetings of public bodies or the writings of public officials and agencies be adopted with findings demonstrating the interest protected by the limitation and the need for protecting that interest. This bill would make legislative findings to that effect. This bill would incorporate additional changes to Sections 791.07, 791.11, and 791.12 of the Insurance Code proposed by AB 1798 to be operative only if this bill and AB 1798 are enacted and this bill is enacted last. The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state. Statutory provisions establish procedures for making that reimbursement. This bill would provide that no reimbursement is required by this act for a specified reason.
(1) The Confidentiality of Medical Information Act (CMIA) prohibits a provider of health care, a health care service plan, a contractor, or a corporation and its subsidiaries and affiliates from intentionally sharing, selling, using for marketing, or otherwise using any medical information, as defined, for any purpose not necessary to provide health care services to a patient, except as provided. Existing law makes a violation of these provisions that results in economic loss or personal injury punishable as a misdemeanor. Existing law deems a business that offers a mental health digital service or reproductive or sexual health digital service to a consumer for the purpose of allowing the individual to manage the individual's information, or for the diagnosis, treatment, or management of a medical condition of the individual, to be a provider of health care subject to the requirements of the CMIA. The bill would additionally deem a business that offers a health care chatbot, as defined, to a consumer for the above-described purposes to be a provider of health care subject to the requirements of the CMIA. Because the bill would expand the scope of a crime, it would impose a state-mandated local program. (2) Existing law requires a health facility, clinic, physician's office, or office of a group practice that uses generative artificial intelligence to generate written or verbal patient communications pertaining to patient clinical information, as defined, to ensure that those communications include both a disclaimer that indicates to the patient that a communication was generated by generative artificial intelligence, as specified, and clear instructions describing how a patient may contact a human health care provider, employee, or other appropriate person, except as specified. This bill would require a health facility, clinic, physician's office, or office of a group practice to take reasonable steps to ensure that a licensed health care professional, acting within their scope of practice, retains the ability to exercise independent professional judgment in their care of a patient whenever that care is informed by the output of a clinical decision support system, as defined. The bill would prohibit a health facility, clinic, physician's office, or office of a group practice from using or deploying a tool, system, or device that includes artificial intelligence to independently perform any clinical function that is required by law to be performed by a person with a professional license. The bill would make a violation of these provisions by a physician subject to the jurisdiction of the Medical Board of California or the Osteopathic Medical Board of California. The bill would also authorize the appropriate professional licensing board to pursue an injunction or restraining order to enforce these provisions to the extent that a violation constitutes the practice of a health care profession without a license. The bill would specify that these provisions do not apply to the use of automated decision systems for documentation and communication that does not involve the application of professional judgment, including automated messages to inform patients of updates to their health records. (3) The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state. Statutory provisions establish procedures for making that reimbursement. This bill would provide that no reimbursement is required by this act for a specified reason.
Existing law generally regulates the business of renting passenger vehicles to the public. The law prohibits a rental company from taking various actions, including requiring the purchase of a damage waiver, optional insurance, or another optional good or service, and using electronic surveillance technology to track a renter in order to impose fines or surcharges relating to the renter's use of a rental vehicle. This bill would require any privately owned vehicle rented by, or furnished to, any federal, state, or local law enforcement agency for the use of detaining, arresting, or transporting persons who have violated, or are suspected of having violated, any law, to display a temporary decal displaying the agency name and logo, as specified. The bill would authorize certain attorneys, including the Attorney General, to pursue a civil action against the entity renting the vehicle from the private owner for failure to comply with these provisions. The bill would require the rental car contract to include a term that compliance with state law is mandatory. The bill would exempt privately owned vehicles rented or otherwise furnished or loaned to a law enforcement agency for specified purposes and rental car contracts entered into prior to January 1, 2027, from these provisions. The bill would make related findings and declarations.
Existing law requires the Public Utilities Commission to appoint a chief internal auditor who holds office at the pleasure of the commission. Existing law makes the chief internal auditor responsible for the oversight of the internal audit unit. Existing law requires the chief internal auditor to plan, initiate, and perform audits of key financial, management, operational, and information technology functions within the commission to improve accountability and transparency to executive and state management, and to report their findings and recommendations directly to an audit subcommittee of the commission. This bill would instead require the Governor to appoint an Inspector General, subject to Senate confirmation, to be responsible for the oversight of the internal audit unit and would instead require the Inspector General to plan, initiate, and perform audits of key financial, management, operational, and information technology functions within the commission to improve accountability and transparency to executive and state management. The bill would also require the Inspector General to ensure, among other things, that the commission administers funds and programs in a prescribed manner, fulfills mandated requirements, develops an annual audit plan, administers an effective enterprise risk management program, and monitors reporting compliance. The bill would provide for the appointment and removal of the Inspector General, as specified. The bill would authorize the Inspector General to access and examine all records, files, documents, accounts, reports, correspondence, or other property of the commission and public utilities, and would require other entities that are regulated by the commission and participate in programs administered by the commission, upon request of the Inspector General, to provide or make available to the Inspector General for examination all relevant records, files, documents, accounts, reports, correspondence, or other property pertaining to participation in those programs, as specified. The bill would require the Inspector General to report specified information to the Governor and the Legislature, as provided.
Existing law authorizes designated health care services providers, employees, volunteers, and patients, and individuals who face threats of violence or violence or harassment from the public because of their affiliation with a designated health care services facility, to complete an application to be approved by the Secretary of State for the purposes of enabling state and local agencies to respond to requests for public records without disclosing a program participant's residence address contained in any public record and otherwise provide for confidentiality of identity for that person, subject to specified conditions. Existing law defines "designated health care services" to mean gender-affirming health care services or reproductive health care services. Under existing law, any person who makes a false statement in an application is guilty of a misdemeanor. Existing law prohibits a person, business, or association from knowingly publicly posting or publicly displaying, disclosing, or distributing on internet websites or on social media, the personal information or image of any designated health care services patient, provider, or assistant, or other individuals residing at the same home address, with the intent to incite a third person to cause imminent great bodily harm to the person identified in the posting or display, or to a coresident of that person, as specified, or to threaten the person identified in the posting or display, or a coresident of that person, as specified. Existing law additionally prohibits a person, business, or association from soliciting, selling, or trading on the internet or social media the personal information or image of a designated health care services patient, provider, or assistant with the intent described above. Existing law establishes a cause of action for injunctive or declarative relief for a violation of these prohibitions. Existing law prohibits a person from posting on the internet or social media, with the intent that another person imminently use that information to commit a crime involving violence or a threat of violence against a designated health care services patient, provider, or assistant, or other individuals residing at the same home address, the personal information or image of a reproductive health care services patient, provider, or assistant, or other individuals residing at the same home address. This bill would, commencing October 1, 2027, similarly establish an address confidentiality program for a designated immigration support services provider, employee, or volunteer, as defined, who faces threats of violence or harassment from the public because of their affiliation with a designated immigration support services facility. This bill would additionally prohibit a person, business, or association from soliciting, selling, or trading on the internet the personal information or image of a designated immigration support services provider, employee, or volunteer with the intent described above. The bill would also, among other things, prohibit a person from posting on the internet the personal information or image of a designated immigration support services provider, employee, or volunteer, or other individuals residing at the same home address, with the specific intent that another person imminently use that information to commit a crime involving violence or a threat of violence that is likely to occur against such an individual. The bill would define various terms for these purposes. By imposing new duties on local agencies and creating new crimes, this bill would create a state-mandated local program. Existing constitutional provisions require that a statute that limits the right of access to the meetings of public bodies or the writings of public officials and agencies be adopted with findings demonstrating the interest protected by the limitation and the need for protecting that interest. This bill would make legislative findings to that effect. The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state. Statutory provisions establish procedures for making that reimbursement. This bill would provide that with regard to certain mandates no reimbursement is required by this act for a specified reason. With regard to any other mandates, this bill would provide that, if the Commission on State Mandates determines that the bill contains costs so mandated by the state, reimbursement for those costs shall be made pursuant to the statutory provisions noted above.
This measure would urge President Donald J. Trump and Congress to protect and maintain the historic investments made possible by the Bipartisan Infrastructure Law, the CHIPS and Science Act, and the Inflation Reduction Act of 2022.
Existing law establishes the Department of Industrial Relations in the Labor and Workforce Development Agency to administer and enforce various laws relating to employment and working conditions. This bill would require a business, as defined, to annually provide a notice to the department of all the workplace surveillance tools the employer is using in the workplace. The bill would require the notice to include, among other information, a list of the workplace surveillance tools being used that surveil employees and the categories of information being collected on employees by the workplace surveillance. The bill would also require a business to send the notice to employees and any union that represents employees of the business. The bill would make a business that violates these provisions subject to a civil penalty of $500 per violation. This bill would require the department to submit a report to the Legislature by January 1, 2029, compiling the above-described notices provided by businesses. The bill would require that the report include, among other requirements, a breakdown of notices by industry type.
(1) Existing law, the Digital Financial Assets Law, prohibits a person, on or after July 1, 2026, from engaging in digital financial asset business activity, or holding itself out as being able to engage in digital financial asset business activity, with, or on behalf of, a resident, unless any of certain criteria are met, including that the person is licensed with the Department of Financial Protection and Innovation, as prescribed, or the person submits an application on or before July 1, 2026, and is awaiting approval or denial of that application. This bill would revise the above-described latter criterion to specify that the person submits a completed application, as provided. The Digital Financial Assets Law authorizes the Commissioner of Financial Protection and Innovation to issue a conditional license to an applicant who holds or maintains a license to conduct virtual currency business activity in the State of New York, as specified, provided the license was issued or approved no later than January 1, 2023. This bill would revise the above-described authorization to require that the license be issued or approved no later than January 1, 2025. (2) The Digital Financial Assets Law defines "digital financial asset business activity" to mean any of specified activities, including, among others, exchanging, transferring, or storing a digital financial asset, as specified, or exchanging one or more digital representations of value used within one or more online games, game platforms, or family of games, as provided. This bill would remove exchanging one or more digital representations of value used within one or more online games, game platforms, or family of games from the definition of "digital financial business activity." The bill would specify that a "digital financial asset" does not include, among other things, a transaction in which a merchant grants digital representations of value that primarily relate to an affinity or rewards program, as provided, or a digital representation of value issued by or on behalf of a publisher and used primarily within online games or game platforms and that is not otherwise a digital financial asset. The Digital Financial Assets Law declares that its provisions do not apply to specified activity, including by a person who does not receive compensation for providing digital financial asset products or services or for conducting financial asset business activity or that is engaged in testing products or services with the person's own funds. This bill would specify that the above-described exclusion includes a person who merely retains the ability to terminate, suspend, or interrupt a digital financial transaction solely to prevent unauthorized or fraudulent activity and who is not compensated for that service. The Digital Financial Assets Law prohibits a covered person from exchanging, transferring, or storing a digital financial asset that is a stablecoin or engaging in digital financial asset administration of a stablecoin, as specified, unless certain conditions are met. However, existing law authorizes a covered person to exchange, transfer, or store a stablecoin or engage in digital financial asset administration of that stablecoin, as specified, if the stablecoin is approved by the commissioner and complies with certain requirements, restrictions, or prohibitions established by the commissioner. This bill would repeal the above-described provisions related to stablecoins. (3) The Digital Financial Assets Law requires a licensee to submit an annual report, as provided, containing specified information, including a description of any data security breach or cybersecurity event of the licensee. Existing law requires a licensee to file with the department, as applicable, a report of, among other things, a change in the licensee's business for the conduct of its digital financial asset business activity with, or on behalf of, a resident that meets one of specified criteria, including that the proposed change might raise safety and soundness or operational concerns. This bill would revise the above-described annual report to instead include a description of any material data security breach or cybersecurity event of the licensee. The bill would revise the specified criteria in the requirement to file the above-described report of a change in the licensee's business to instead include that the proposed change might raise material safety and soundness or operational concerns. Before engaging in digital financial asset business activity with a resident, the Digital Financial Assets Law requires a covered person, defined as a person required to obtain a license pursuant to that law, to disclose, as provided, certain information, including the resident's right to at least 14 days' prior notice of specified changes that have a material impact on digital financial asset business activity with the resident, or the policies applicable to the resident's account. Existing law requires a covered exchange, as provided, to certify on a form provided by the department that the covered exchange has taken specified actions, except for any digital financial asset approved for listing on or before January 1, 2023. In a transaction for or with a resident, existing law prohibits the covered exchange from interjecting a third party between the covered exchange and the best market for the digital financial asset in a manner inconsistent with specified requirements. This bill would prohibit the 14-day notice requirement from applying to changes in terms, conditions, or policies that are reasonably necessary to address a risk of loss to the resident or covered person, to the extent that the change does not relate to the fee schedule. The bill would instead exclude from the above-described certification requirement a digital financial asset approved for listing on or before January 1, 2025. The bill would require a covered person to provide and make available an up-to-date description of the order execution practices of the covered person, as specified. The bill would exempt a transaction in which a resident receives stablecoin, as defined, in exchange for legal tender or bank or credit union credit from the above-described prohibition against interjecting a third party. The Digital Financial Assets Law requires an applicant, as provided, to create, and during licensure, maintain in a record specified policies and procedures. Existing law requires these policies and procedures be disclosed separately from other disclosures made available to a resident, as specified, except for, among other things, an adopted information security program or an operational security program. This bill would instead exclude from the above-described requirement to disclose separately from other disclosures programs with information that is sensitive to potential security risks, as specified. This bill would declare that it is to take effect immediately as an urgency statute.
Existing law vests the Public Utilities Commission with regulatory jurisdiction over public utilities, including electrical corporations and gas corporations, while local publicly owned electric utilities are under the direction of their governing boards. Existing law requires every public utility to furnish and maintain adequate, efficient, just, and reasonable service, instrumentalities, equipment, and facilities, as are necessary to promote the safety, health, comfort, and convenience of its customers, its employees, and the public. This bill would require the commission, on or before January 1, 2028, to adopt standards for an electrical or gas corporation's use of artificial intelligence models, as provided. The bill would require the commission to direct an electrical or gas corporation to file a plan that demonstrates the corporation's compliance with those standards. The bill would authorize the commission to prohibit an electrical or gas corporation's use of an artificial intelligence model if the commission finds that deployment of the artificial intelligence model would negatively impact the provision of safe, affordable, and reliable electrical or gas service. The bill would require each community choice aggregator and local publicly owned electric utility to adopt a policy regarding its use of an artificial intelligence model that is consistent with the standards. Under existing law, a violation of an order, decision, rule, direction, demand, or requirement of the commission is a crime. Because a violation of a commission action implementing those requirements would be a crime, this bill would impose a state-mandated local program. Additionally, by imposing new duties on local publicly owned electric utilities, the bill would impose a state-mandated local program. The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state. Statutory provisions establish procedures for making that reimbursement. This bill would provide that no reimbursement is required by this act for specified reasons.
Existing law vests the Public Utilities Commission (PUC) with regulatory authority over public utilities, including electrical corporations. Existing law authorizes the PUC to fix the rates and charges for every public utility and requires that those rates and charges be just and reasonable. This bill would require the PUC to establish a special rate structure for data centers, as defined, taking transmission level electrical service with an estimated peak demand of at least 75 megawatts of electricity to, among other things, protect other customers of electrical corporations, prohibit cost shifts to those other customers, and require data centers to pay for the electrical corporations' upfront costs of transmission or distribution infrastructure upgrades necessary for the provision of electrical service to the data centers. The bill would require the construction of data centers subject to the special rate structure to comply with certain labor requirements. Existing law establishes the policy of the state that eligible renewable energy resources and zero-carbon resources supply 90% of all retail sales of electricity to California end-use customers by December 31, 2035, 95% by December 31, 2040, and 100% by December 31, 2045. Existing law requires the PUC, the State Energy Resources Conservation and Development Commission, and the State Air Resources Board, in consultation with all California balancing authorities, to annually issue a joint report related to meeting that state policy. This bill would require that the joint report also includes the impacts of data centers subject to the special rate structure on the state's ability to achieve the above-described state policy. Under existing law, a violation of the Public Utilities Act or an order, decision, rule, direction, demand, or requirement of the PUC is a crime. Because the provisions of the bill would be part of the act and a violation of a PUC action implementing the bill's requirements would be a crime, this bill would impose a state-mandated local program. The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state. Statutory provisions establish procedures for making that reimbursement. This bill would provide that no reimbursement is required by this act for a specified reason.