The California Consumer Privacy Act of 2018 (CCPA) grants to a consumer various rights with respect to personal information that is collected by a business, including the right to delete personal information. The California Privacy Rights Act of 2020, approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA and establishes the California Privacy Protection Agency and vests the agency with full administrative power, authority, and jurisdiction to enforce the CCPA. The CCPA excludes from the definition of "personal information" publicly available information. Existing law defines "publicly available" for these purposes to include 3 types of information. One type is information that a business has a reasonable basis to believe is lawfully made available to the general public by the consumer or from widely distributed media. This bill would revise that part of the definition of "publicly available" by removing the condition that the business have a reasonable basis to believe the information is lawfully made available. The CCPA also includes in that definition of "publicly available" information made available by a person to whom the consumer has disclosed the information if the consumer has not restricted the information to a specific audience. This bill would delete that part of the definition of "publicly available." This bill would declare that its provisions further the purposes and intent of the California Privacy Rights Act of 2020.
Existing law, the California Emergency Services Act, establishes the California Cybersecurity Integration Center within the Office of Emergency Services to serve as the central organizing hub of state government's cybersecurity activities and to coordinate information sharing with various entities. Existing law also requires the Technology Recovery Plan element of the State Administrative Manual to ensure the inclusion of cybersecurity strategy incident response standards for each state agency to secure its critical infrastructure controls and information, as prescribed. This bill would require, on or before July 1, 2026, an operator, defined as a state agency responsible for operating, managing, overseeing, or controlling access to critical infrastructure, that deploys a covered artificial intelligence (AI) system, as defined, to establish a human oversight mechanism that ensures a human monitors the system's operations in real time and reviews and approves any plan or action proposed by the covered AI system before execution, except as provided. The bill would require the Department of Technology to develop specialized training in AI safety protocols and risk management techniques to oversight personnel. The bill would require oversight personnel for an operator to conduct an annual assessment of its covered AI systems, as specified, and to submit a summary of the findings to the department. The bill would make findings and declarations related to its provisions. The bill would preclude disclosure of specified information by the office. Existing constitutional provisions require that a statute that limits the right of access to the meetings of public bodies or the writings of public officials and agencies be adopted with findings demonstrating the interest protected by the limitation and the need for protecting that interest. This bill would make legislative findings to that effect.
Existing law, the California Consumer Privacy Act of 2018 (CCPA) , grants a consumer various rights with respect to personal information, as defined, that is collected or sold by a business, as defined, including the right to direct a business that collects sensitive personal information about the consumer to limit its use, as prescribed. Existing law defines "sensitive personal information" to mean, among other things, personal information that reveals a consumer's precise geolocation. Existing law, the California Privacy Rights Act of 2020, approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA. This bill would require a business that collects precise geolocation information to prominently display, when information is being collected, a notice to the consumer whose information is being collected that states certain information related to the collection of the information and its use by the business, including the goods or services requested by the consumer for which the business is collecting, processing, or disclosing the geolocation information and a description of how the business will process the geolocation information to carry out those purposes. This bill would prohibit a business that collects precise geolocation information from, among other things, retaining the information longer than necessary to provide the goods or services requested by the consumer or longer than one year after the consumer's last intentional interaction with the business, whichever is earlier. This bill would declare that its provisions further the purposes and intent of the California Privacy Rights Act of 2020.
Existing law requires the State Department of Education, on or before January 1, 2024, to develop a plan to expand mental health instruction in California public schools. This bill would require the department, on or before January 1, 2028, to develop a plan to expand digital wellness instruction in California public schools, as provided.
This measure would urge President Donald J. Trump and Congress to protect and maintain the historic investments made possible by the Bipartisan Infrastructure Law, the CHIPS and Science Act, and the Inflation Reduction Act of 2022.
Existing law establishes the Department of Industrial Relations in the Labor and Workforce Development Agency to administer and enforce various laws relating to employment and working conditions. This bill would require a business, as defined, to annually provide a notice to the department of all the workplace surveillance tools the employer is using in the workplace. The bill would require the notice to include, among other information, a list of the workplace surveillance tools being used that surveil employees and the categories of information being collected on employees by the workplace surveillance. The bill would also require a business to send the notice to employees and any union that represents employees of the business. The bill would make a business that violates these provisions subject to a civil penalty of $500 per violation. This bill would require the department to submit a report to the Legislature by January 1, 2029, compiling the above-described notices provided by businesses. The bill would require that the report include, among other requirements, a breakdown of notices by industry type.
Existing law requires, beginning on January 1, 2028, a vehicle with connected vehicle service to clearly indicate to a person who is inside the vehicle when a person who is outside the vehicle has accessed, among other things, connected vehicle location access. For these purposes, existing law defines "connected vehicle service" to mean any capability, including through a software application that is designed to be operated on a mobile device, to remotely obtain data from, or send commands to, a vehicle, and "connected vehicle location access" to mean a type of connected vehicle service that allows a person, who is outside of a vehicle, to view or track the location of the vehicle, as specified. If a vehicle includes connected vehicle location access, existing law requires a covered provider, as defined, to provide a mechanism that can be used by a driver who is inside a vehicle to immediately disable connected vehicle location access. Existing law delays the operation of this requirement depending on whether the vehicle was manufactured prior to, or on or after, January 1, 2028. Unless otherwise provided, a violation of the Vehicle Code constitutes an infraction. This bill would, instead, limit the provisions above to specified vehicles with connected vehicle access. The bill would apply the requirement for a vehicle with connected vehicle service to indicate to a person inside the vehicle if connected vehicle location access is enabled to all vehicles beginning with the 2031 model year. The bill would make this requirement operative beginning with the 2031 model year, for 2028, 2029, and 2030 model year vehicles, as soon as practicable after the vehicle is sold unless technologically infeasible, and on or before July 1, 2027, for 2027 model year or older vehicles unless technologically infeasible. By establishing a new duty on vehicle manufacturers, this bill would expand the general crime applicable to provisions under the Vehicle Code, thereby imposing a state-mandated local program. The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state. Statutory provisions establish procedures for making that reimbursement. This bill would provide that no reimbursement is required by this act for a specified reason. This bill would declare that it is to take effect immediately as an urgency statute.
(1) Existing law, the Digital Financial Assets Law, prohibits a person, on or after July 1, 2026, from engaging in digital financial asset business activity, or holding itself out as being able to engage in digital financial asset business activity, with, or on behalf of, a resident, unless any of certain criteria are met, including that the person is licensed with the Department of Financial Protection and Innovation, as prescribed, or the person submits an application on or before July 1, 2026, and is awaiting approval or denial of that application. This bill would revise the above-described latter criterion to specify that the person submits a completed application, as provided. The Digital Financial Assets Law authorizes the Commissioner of Financial Protection and Innovation to issue a conditional license to an applicant who holds or maintains a license to conduct virtual currency business activity in the State of New York, as specified, provided the license was issued or approved no later than January 1, 2023. This bill would revise the above-described authorization to require that the license be issued or approved no later than January 1, 2025. (2) The Digital Financial Assets Law defines "digital financial asset business activity" to mean any of specified activities, including, among others, exchanging, transferring, or storing a digital financial asset, as specified, or exchanging one or more digital representations of value used within one or more online games, game platforms, or family of games, as provided. This bill would remove exchanging one or more digital representations of value used within one or more online games, game platforms, or family of games from the definition of "digital financial business activity." The bill would specify that a "digital financial asset" does not include, among other things, a transaction in which a merchant grants digital representations of value that primarily relate to an affinity or rewards program, as provided, or a digital representation of value issued by or on behalf of a publisher and used primarily within online games or game platforms and that is not otherwise a digital financial asset. The Digital Financial Assets Law declares that its provisions do not apply to specified activity, including by a person who does not receive compensation for providing digital financial asset products or services or for conducting financial asset business activity or that is engaged in testing products or services with the person's own funds. This bill would specify that the above-described exclusion includes a person who merely retains the ability to terminate, suspend, or interrupt a digital financial transaction solely to prevent unauthorized or fraudulent activity and who is not compensated for that service. The Digital Financial Assets Law prohibits a covered person from exchanging, transferring, or storing a digital financial asset that is a stablecoin or engaging in digital financial asset administration of a stablecoin, as specified, unless certain conditions are met. However, existing law authorizes a covered person to exchange, transfer, or store a stablecoin or engage in digital financial asset administration of that stablecoin, as specified, if the stablecoin is approved by the commissioner and complies with certain requirements, restrictions, or prohibitions established by the commissioner. This bill would repeal the above-described provisions related to stablecoins. (3) The Digital Financial Assets Law requires a licensee to submit an annual report, as provided, containing specified information, including a description of any data security breach or cybersecurity event of the licensee. Existing law requires a licensee to file with the department, as applicable, a report of, among other things, a change in the licensee's business for the conduct of its digital financial asset business activity with, or on behalf of, a resident that meets one of specified criteria, including that the proposed change might raise safety and soundness or operational concerns. This bill would revise the above-described annual report to instead include a description of any material data security breach or cybersecurity event of the licensee. The bill would revise the specified criteria in the requirement to file the above-described report of a change in the licensee's business to instead include that the proposed change might raise material safety and soundness or operational concerns. Before engaging in digital financial asset business activity with a resident, the Digital Financial Assets Law requires a covered person, defined as a person required to obtain a license pursuant to that law, to disclose, as provided, certain information, including the resident's right to at least 14 days' prior notice of specified changes that have a material impact on digital financial asset business activity with the resident, or the policies applicable to the resident's account. Existing law requires a covered exchange, as provided, to certify on a form provided by the department that the covered exchange has taken specified actions, except for any digital financial asset approved for listing on or before January 1, 2023. In a transaction for or with a resident, existing law prohibits the covered exchange from interjecting a third party between the covered exchange and the best market for the digital financial asset in a manner inconsistent with specified requirements. This bill would prohibit the 14-day notice requirement from applying to changes in terms, conditions, or policies that are reasonably necessary to address a risk of loss to the resident or covered person, to the extent that the change does not relate to the fee schedule. The bill would instead exclude from the above-described certification requirement a digital financial asset approved for listing on or before January 1, 2025. The bill would require a covered person to provide and make available an up-to-date description of the order execution practices of the covered person, as specified. The bill would exempt a transaction in which a resident receives stablecoin, as defined, in exchange for legal tender or bank or credit union credit from the above-described prohibition against interjecting a third party. The Digital Financial Assets Law requires an applicant, as provided, to create, and during licensure, maintain in a record specified policies and procedures. Existing law requires these policies and procedures be disclosed separately from other disclosures made available to a resident, as specified, except for, among other things, an adopted information security program or an operational security program. This bill would instead exclude from the above-described requirement to disclose separately from other disclosures programs with information that is sensitive to potential security risks, as specified. This bill would declare that it is to take effect immediately as an urgency statute.
Existing law requires every videogame retailer to post a sign, within the retail establishment in a prominent area, providing information to consumers about a videogame rating system or notifying consumers that a rating system is available to aid in the selection of a game and to make available to consumers, upon request, information that explains the videogame rating system. Existing law, subject to certain exceptions, prohibits a seller of a digital good, including a digital application or game, from advertising or offering for sale a digital good to a purchaser with the terms "buy," "purchase," or any other term that a reasonable person would understand to confer an unrestricted ownership interest in the digital good, or alongside an option for a time-limited rental, unless the seller receives at the time of each transaction an affirmative acknowledgment from the purchaser, or the seller provides to the consumer before executing each transaction a clear and conspicuous statement, as specified. Existing law defines "digital application or game" to mean any application or game that a person accesses and manipulates using a specialized electronic gaming device, computer, mobile device, tablet, or other device with a display screen, including any add-ons or additional content for that application or game. This bill, with regard to digital games first available for purchase or rereleased for purchase on or after January 1, 2028, and subject to certain exceptions, would require a digital game operator to communicate specified information to purchasers and prospective purchasers of a digital game 60 days before the operator ceases to provide services necessary for the ordinary use of the game. The bill would, beginning on the date an operator ceases to provide services necessary for the ordinary use of the game, require the operator to provide the purchaser with, among other things, an alternate version of, a patch or update to, or a refund for, the game, as provided, and prohibit the operator from selling, leasing, or otherwise distributing a version of the game that cannot be used by a purchaser independent of services controlled by the operator. The bill would authorize the Attorney General or a district attorney to bring a civil action for a violation of these provisions.
This bill designates February 26, 2026, as "Introduce a Girl to Engineering Day" to highlight the importance of encouraging young women to pursue careers in engineering. The measure serves as a commemorative resolution rather than creating new laws or funding requirements. It does not alter existing policies or directly affect government operations, but instead establishes a specific date for awareness and celebration.