The Insurance Rate Reduction and Reform Act of 1988, an initiative measure enacted by Proposition 103, as approved by the voters at the November 8, 1988, statewide general election, prohibits specified insurance rates from being approved or remaining in effect that are excessive, inadequate, unfairly discriminatory, or otherwise in violation of the act. Under the act, rates and premiums for automobile insurance are determined based on specified factors, including the insured's driving safety record. Existing law authorizes the provisions of Proposition 103 to be amended by a statute that furthers the purposes of the act and is enacted by the Legislature with a 23 vote. This bill, the Consumer Driving Data Protection Act of 2026, would authorize a consumer to opt to use telematics to establish their driving record, thus amending Proposition 103. The bill would prohibit the use of telematics data for a purpose other than rating private passenger automobile insurance. The bill would require a rate application under which telematics would be used to establish an insured's driving record to include specified materials related to the insurer's telematics program. This bill would prohibit an insurer that uses telematics from taking specified actions, including conditioning eligibility for a discount upon participation in a telematics program, unless the discount is approved by the commissioner. The bill would also set forth consent and privacy requirements for the collection and use of telematics data. The bill would authorize the commissioner to impose specified penalties for violations of the bill's provisions, including civil penalties and suspension of an insurer's telematics program. The bill would declare that its provisions further the purposes of Proposition 103.
Existing law, the California Consumer Privacy Act of 2018 (CCPA) , grants a consumer various rights with respect to personal information that is collected or sold by a business, as defined, including the right to direct a business that sells or shares personal information about the consumer to third parties not to sell or share the consumer's personal information, as specified. Existing law, the California Privacy Rights Act of 2020, approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA and establishes the California Privacy Protection Agency and vests the agency with full administrative power, authority, and jurisdiction to enforce those provisions. Existing law requires a retail grocery store or grocery department within a general retail merchandise store that uses a point-of-sale system to have a clearly readable price indicated on 85% of the total number of packaged consumer commodities offered for sale, subject to specified exemptions. This bill would, subject to certain exceptions, prohibit a retailer from engaging in surveillance pricing. The bill would define "surveillance pricing" to mean offering or setting a customized price for a good for a specific consumer or group of consumers, based, in whole or in part, on personally identifiable information, as specified, and determined in whole or in part through the use of any technology, software, program, machine-based system, or computational process that uses statistical modeling, data analytics, artificial intelligence, or other data processing techniques. The bill would also define "surveillance pricing" to mean random variations in prices to different consumers using a website, mobile application, or comparable online technology. The bill would provide that its provisions do not limit or impair any consumer right or remedy available under any other state or federal law. The bill would declare that any waiver of these provisions is against public policy and is void and unenforceable. This bill would declare that its provisions further the purposes and intent of the California Privacy Rights Act of 2020.
Existing law establishes the Division of Labor Standards Enforcement within the Department of Industrial Relations. Existing law authorizes the division, which is headed by the Labor Commissioner, to enforce the Labor Code and all labor laws of the state, the enforcement of which is not specifically vested in any other officer, board, or commission. This bill would prohibit an employer from using a worker's personal information, as defined, to train an artificial intelligence system to replicate, automate, or replace a worker's job, and would prohibit an employer from selling, disclosing, or otherwise providing access to a worker's personal information to a third party for the purpose of training an artificial intelligence system to replicate, automate, or replace a worker's job. The bill would prohibit a vendor providing services to an employer under a contract from providing access to the personal information of an employer's worker to a third party or using the personal information of an employer's worker to train artificial intelligence, as specified. The bill would require a contract between an employer and vendor to include a requirement that the vendor implement and maintain reasonable security procedures to protect the worker's personal information from, among other things, unauthorized or illegal access. The bill would define terms for these provisions, including "employer" and "personal information." The bill would require the Labor Commissioner and authorize a public prosecutor to enforce these provisions. The bill would authorize a worker, or their exclusive representative, who suffered a violation of these provisions to bring a civil action for damages, injunctive relief, punitive damages, and attorney's fees and costs. The bill would establish a statutory penalty for a violation of these provisions of up to $500 for each violation. The bill would include findings that changes proposed by this bill address a matter of statewide concern rather than a municipal affair and, therefore, apply to all cities, including charter cities.
Existing law, the California Consumer Privacy Act of 2018 (CCPA) , imposes various obligations on businesses with respect to personal information, as defined. The California Privacy Rights Act of 2020, approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA. The CCPA requires a business to inform consumers of the categories of personal information to be collected and the purposes for which the categories of personal information are collected or used and whether that information is sold or shared. Existing law, the Student Online Personal Information Protection Act, prohibits an operator, as defined, from, among other things, disclosing a K–12 student's personal information, except as specified. Existing law, the Student Test Taker Privacy Protection Act, prohibits a business providing proctoring services in an educational setting from collecting, retaining, using, or disclosing personal information except to the extent necessary to provide those proctoring services and in other specified circumstances. This bill, beginning July 1, 2027, would require a business providing those proctoring services to a school district, county office of education, or charter school for classroom- or course-based exams to use end-to-end encryption, as defined, for those purposes. The bill would define "end-to-end encryption" for these purposes to mean a security method where data is encrypted on the sender's device and remains encrypted until it reaches the intended recipient's device and is unreadable by any other party, including the business providing proctoring services. The California Privacy Rights Act of 2020 authorizes the Legislature to amend the act to further the purposes and intent of the act by a majority vote of both houses of the Legislature, as specified. This bill would declare that its provisions further the purposes and intent of the California Privacy Rights Act of 2020.
The California Consumer Privacy Act of 2018 (CCPA) grants a consumer various rights with respect to personal information, as defined, that is collected or sold by a business, as defined, including the right to direct a business that collects sensitive personal information, as defined, about the consumer to limit its use, as prescribed. The California Privacy Rights Act of 2020, approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA. This bill would, under the CCPA, prohibit a business, service provider, or contractor from selling or sharing sensitive personal information to a third party, except as specified. This bill would declare that its provisions further the purposes and intent of the California Privacy Rights Act of 2020.
Existing law, the California Consumer Privacy Act of 2018 (CCPA) , grants to a consumer various rights with respect to personal information that is collected by a business. Among those rights, the CCPA includes the right to request that a business delete personal information that the business has collected from the consumer. This bill would expand that right to include requesting the deletion of any personal information that the business has collected about the consumer. If the business did not obtain the personal information from the consumer, the bill would allow the business to retain a record of the deletion request and the minimum data necessary to ensure the consumer's personal information remains deleted from its records and is not being used for any other purpose. The bill would make findings and declarations relating to these provisions. Existing law generally requires businesses to make certain methods of communication available for consumers to submit personal information requests, including requests for deletion and correction. If a business operates exclusively online and has a direct relationship with the consumer from whom it collects personal information, existing law requires the business to provide consumers an email address for submitting personal information requests. This bill would also require that business to make an online method, such as a web form or online portal, available to consumers for submitting personal information requests. Existing law, the California Privacy Rights Act of 2020, an initiative measure approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA. This bill would declare that its provisions further the purposes and intent of the California Privacy Rights Act of 2020.
Existing law requires an individual or a business that conducts business in California, and that owns or licenses computerized data that includes personal information, to disclose a breach of the security of the system following discovery or notification of the breach in the security of the data to a resident of California whose unencrypted personal information was compromised, as specified, and requires that disclosure to be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement, as specified, or any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system. This bill would require that data breach disclosure to be made within 30 calendar days of discovery or notification of the data breach but would authorize an individual or business to delay the disclosure to accommodate the legitimate needs of law enforcement, as specified, or as necessary to determine the scope of the breach and restore the reasonable integrity of the data system. Existing law also requires an individual or business that is required to issue the security breach notification described above to more than 500 California residents as a result of a single breach of the security system to electronically submit a single sample copy of that security breach notification, excluding any personally identifiable information, to the Attorney General. This bill would require that submission to the Attorney General to be made within 15 calendar days of notifying affected consumers of the security breach.
Existing law establishes the California Privacy Protection Agency (CPPA) to enforce various laws protecting the privacy of individuals. If a business knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship, existing law requires the business to register with the CPPA as a data broker, except as specified. Existing law requires the CPPA to establish an accessible deletion mechanism that allows a consumer to request that every data broker delete any personal information related to that consumer held by the data broker or associated service provider or contractor, as prescribed. Existing law requires, beginning August 1, 2026, a data broker to access that deletion mechanism at least once every 45 days and, among other things, process all deletion requests and delete all personal information related to the consumers making the requests, as specified. This bill would change the above-described 45-day period to a 30-day period and make conforming changes. This bill would require the Secretary of State, certain local government officials, the Judicial Council, and the State Bar of California to notify any state elected official, local elected official, or judge, as applicable, that the person may submit a request to delete that person's personal information through the above-described accessible deletion mechanism, as prescribed. By imposing additional duties on local government officials, this bill would impose a state-mandated local program. This bill would authorize the Attorney General, a county counsel, or a city attorney to bring a civil action, on behalf of an elected official or judge, against a data broker who violates certain personal information deletion requirements, as prescribed. This bill would make its provisions relating to the notice and enforcement of requests for deletion of personal information of elected officials and judges operative on July 1, 2027. The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state. Statutory provisions establish procedures for making that reimbursement. This bill would provide that, if the Commission on State Mandates determines that the bill contains costs mandated by the state, reimbursement for those costs shall be made pursuant to the statutory provisions noted above.
The California Consumer Privacy Act of 2018 (CCPA) grants to a consumer various rights with respect to personal information, as defined, that is collected by a business, as defined, including the right to direct a business that sells or shares personal information about the consumer to third parties not to sell or share the consumer's personal information, as specified. The CCPA requires a business that controls the collection of a consumer's personal information to, at or before the point of collection, inform a consumer of, among other things, the categories of personal information to be collected, the purposes for which the categories of personal information are collected or used, and whether that information is sold or shared. The California Privacy Rights Act of 2020, approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA and establishes the California Privacy Protection Agency and vests the agency with full administrative power, authority, and jurisdiction to enforce the CCPA. This bill would enact the Stop Foreign Governments from Accessing Californians' Sensitive Personal Information Act which would additionally require a business to disclose to a consumer if the business intends to maintain the consumer's personal information outside of the United States. The bill would prohibit a business from maintaining a consumer's personal information outside of the United States unless, among other things, the consumer explicitly consented to the business maintaining the consumer's personal information outside of the United States. The bill would also prohibit a business from maintaining personal information that is health care information, financial information, or geolocation data in the custody of a foreign government or a third party that is owned or controlled by a foreign government. This bill would declare that its provisions further the purposes and intent of the California Privacy Rights Act of 2020.
Existing law requires a law enforcement agency, as defined, to obtain specific approval of a governing body prior to acquiring military equipment, as specified. Existing law defines "military equipment" to include an unmanned, remotely piloted, powered aerial or ground vehicle. This bill would prohibit a law enforcement agency from purchasing, on or after January 1, 2027, an uncrewed, remotely piloted, powered aerial or ground vehicle unless the vehicle contains an option to turn off any data collection programs that are not necessary for the vehicle to function and the law enforcement agency uses an American data storage company, as defined, to house all data collected, including, but not limited to, video and photographic images, as specified, or both. For uncrewed, remotely piloted, powered aerial or ground vehicles purchased on or after January 1, 2026, and before January 1, 2027, the bill would require a law enforcement agency to use an American data storage company. For uncrewed aerial or ground vehicles owned or possessed by a law enforcement agency prior to January 1, 2026, the bill would require the law enforcement agency to use an American data storage company after the current contract to house the data expires. The bill would require contracts entered into pursuant to these provisions with an American data storage company to prohibit the American data storage company from using, selling, renting, trading, or otherwise sharing this data with any other entity.