Existing law creates a civil cause of action against any person who knowingly uses the name, voice, signature, photograph, or likeness of another person, without their consent, for specified purposes. When a photograph or likeness of an employee of the person using the photograph or likeness appearing in an advertisement or other publication is incidental and not essential to the purpose of the publication, existing law establishes a rebuttable presumption affecting the burden of producing evidence that failure to obtain the consent of an employee was not a knowing use of an employee's photograph or likeness. This bill would clarify that, for purposes of this cause of action, a voice or likeness includes a digital replica, defined to mean a computer-generated, highly realistic electronic representation that is readily identifiable as the voice or visual likeness of an individual in which the actual individual either did not actually perform or appear, or the actual individual did perform or appear, but the fundamental character of the performance or appearance has been materially altered. The bill would also remove the provisions establishing the rebuttable presumption when an employee's likeness or photograph appears in an advertisement or other publication. Existing law prohibits the false impersonation of another person in either their personal or official capacity with the intent to steal or defraud, as specified. This bill would clarify that false impersonation includes the use of a digital replica with the intent to impersonate another for purposes of these and other criminal provisions.
The Insurance Rate Reduction and Reform Act of 1988, an initiative measure enacted by Proposition 103, as approved by the voters at the November 8, 1988, statewide general election, prohibits specified insurance rates from being approved or remaining in effect that are excessive, inadequate, unfairly discriminatory, or otherwise in violation of the act. Under the act, rates and premiums for automobile insurance are determined based on specified factors, including the insured's driving safety record. Existing law authorizes the provisions of Proposition 103 to be amended by a statute that furthers the purposes of the act and is enacted by the Legislature with a 23 vote. This bill, the Consumer Driving Data Protection Act of 2026, would authorize a consumer to opt to use telematics to establish their driving record, thus amending Proposition 103. The bill would prohibit the use of telematics data for a purpose other than rating private passenger automobile insurance. The bill would require a rate application under which telematics would be used to establish an insured's driving record to include specified materials related to the insurer's telematics program. This bill would prohibit an insurer that uses telematics from taking specified actions, including conditioning eligibility for a discount upon participation in a telematics program, unless the discount is approved by the commissioner. The bill would also set forth consent and privacy requirements for the collection and use of telematics data. The bill would authorize the commissioner to impose specified penalties for violations of the bill's provisions, including civil penalties and suspension of an insurer's telematics program. The bill would declare that its provisions further the purposes of Proposition 103.
Existing law, the California Consumer Privacy Act of 2018 (CCPA) , grants a consumer various rights with respect to personal information that is collected or sold by a business, as defined, including the right to direct a business that sells or shares personal information about the consumer to third parties not to sell or share the consumer's personal information, as specified. Existing law, the California Privacy Rights Act of 2020, approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA and establishes the California Privacy Protection Agency and vests the agency with full administrative power, authority, and jurisdiction to enforce those provisions. Existing law requires a retail grocery store or grocery department within a general retail merchandise store that uses a point-of-sale system to have a clearly readable price indicated on 85% of the total number of packaged consumer commodities offered for sale, subject to specified exemptions. This bill would, subject to certain exceptions, prohibit a retailer from engaging in surveillance pricing. The bill would define "surveillance pricing" to mean offering or setting a customized price for a good for a specific consumer or group of consumers, based, in whole or in part, on personally identifiable information, as specified, and determined in whole or in part through the use of any technology, software, program, machine-based system, or computational process that uses statistical modeling, data analytics, artificial intelligence, or other data processing techniques. The bill would also define "surveillance pricing" to mean random variations in prices to different consumers using a website, mobile application, or comparable online technology. The bill would provide that its provisions do not limit or impair any consumer right or remedy available under any other state or federal law. The bill would declare that any waiver of these provisions is against public policy and is void and unenforceable. This bill would declare that its provisions further the purposes and intent of the California Privacy Rights Act of 2020.
Existing law establishes the Department of Consumer Affairs to, among other things, protect consumer interests and regulate specified businesses. Existing law requires a business that provides an online service, product, or feature likely to be accessed by children to comply with specified requirements, including configuring all default privacy settings provided to children to settings that offer a high level of privacy. Existing law prohibits an operator of an internet website, online service, online application, or mobile application directed to minors from marketing or advertising specified products or services to a minor. This bill would enact the California Children's Digital Educational Content Act of 2026, which would require a covered platform, as defined, to establish and maintain a walled garden. The bill would define a walled garden as a clearly designated and easily accessible section of a platform that is dedicated exclusively to educational children's content, as defined. The bill would require a walled garden to meet certain requirements, including that it be free from targeted advertising and be accessible to minors without an account. The bill would authorize the department to adopt regulations to implement these provisions. The bill would require a covered platform to annually submit a compliance report to the department and would authorize the department to conduct audits. The bill would impose specified administrative penalties for violation of its provisions.
Existing law establishes the Division of Labor Standards Enforcement within the Department of Industrial Relations. Existing law authorizes the division, which is headed by the Labor Commissioner, to enforce the Labor Code and all labor laws of the state, the enforcement of which is not specifically vested in any other officer, board, or commission. This bill would prohibit an employer from using a worker's personal information, as defined, to train an artificial intelligence system to replicate, automate, or replace a worker's job, and would prohibit an employer from selling, disclosing, or otherwise providing access to a worker's personal information to a third party for the purpose of training an artificial intelligence system to replicate, automate, or replace a worker's job. The bill would prohibit a vendor providing services to an employer under a contract from providing access to the personal information of an employer's worker to a third party or using the personal information of an employer's worker to train artificial intelligence, as specified. The bill would require a contract between an employer and vendor to include a requirement that the vendor implement and maintain reasonable security procedures to protect the worker's personal information from, among other things, unauthorized or illegal access. The bill would define terms for these provisions, including "employer" and "personal information." The bill would require the Labor Commissioner and authorize a public prosecutor to enforce these provisions. The bill would authorize a worker, or their exclusive representative, who suffered a violation of these provisions to bring a civil action for damages, injunctive relief, punitive damages, and attorney's fees and costs. The bill would establish a statutory penalty for a violation of these provisions of up to $500 for each violation. The bill would include findings that changes proposed by this bill address a matter of statewide concern rather than a municipal affair and, therefore, apply to all cities, including charter cities.
Existing law, the California Consumer Privacy Act of 2018 (CCPA) , imposes various obligations on businesses with respect to personal information, as defined. The California Privacy Rights Act of 2020, approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA. The CCPA requires a business to inform consumers of the categories of personal information to be collected and the purposes for which the categories of personal information are collected or used and whether that information is sold or shared. Existing law, the Student Online Personal Information Protection Act, prohibits an operator, as defined, from, among other things, disclosing a K–12 student's personal information, except as specified. Existing law, the Student Test Taker Privacy Protection Act, prohibits a business providing proctoring services in an educational setting from collecting, retaining, using, or disclosing personal information except to the extent necessary to provide those proctoring services and in other specified circumstances. This bill, beginning July 1, 2027, would require a business providing those proctoring services to a school district, county office of education, or charter school for classroom- or course-based exams to use end-to-end encryption, as defined, for those purposes. The bill would define "end-to-end encryption" for these purposes to mean a security method where data is encrypted on the sender's device and remains encrypted until it reaches the intended recipient's device and is unreadable by any other party, including the business providing proctoring services. The California Privacy Rights Act of 2020 authorizes the Legislature to amend the act to further the purposes and intent of the act by a majority vote of both houses of the Legislature, as specified. This bill would declare that its provisions further the purposes and intent of the California Privacy Rights Act of 2020.
The California Consumer Privacy Act of 2018 (CCPA) grants a consumer various rights with respect to personal information, as defined, that is collected or sold by a business, as defined, including the right to direct a business that collects sensitive personal information, as defined, about the consumer to limit its use, as prescribed. The California Privacy Rights Act of 2020, approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA. This bill would, under the CCPA, prohibit a business, service provider, or contractor from selling or sharing sensitive personal information to a third party, except as specified. This bill would declare that its provisions further the purposes and intent of the California Privacy Rights Act of 2020.
Existing law, the California Consumer Privacy Act of 2018 (CCPA) , grants to a consumer various rights with respect to personal information that is collected by a business. Among those rights, the CCPA includes the right to request that a business delete personal information that the business has collected from the consumer. This bill would expand that right to include requesting the deletion of any personal information that the business has collected about the consumer. If the business did not obtain the personal information from the consumer, the bill would allow the business to retain a record of the deletion request and the minimum data necessary to ensure the consumer's personal information remains deleted from its records and is not being used for any other purpose. The bill would make findings and declarations relating to these provisions. Existing law generally requires businesses to make certain methods of communication available for consumers to submit personal information requests, including requests for deletion and correction. If a business operates exclusively online and has a direct relationship with the consumer from whom it collects personal information, existing law requires the business to provide consumers an email address for submitting personal information requests. This bill would also require that business to make an online method, such as a web form or online portal, available to consumers for submitting personal information requests. Existing law, the California Privacy Rights Act of 2020, an initiative measure approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA. This bill would declare that its provisions further the purposes and intent of the California Privacy Rights Act of 2020.
Existing law requires an individual or a business that conducts business in California, and that owns or licenses computerized data that includes personal information, to disclose a breach of the security of the system following discovery or notification of the breach in the security of the data to a resident of California whose unencrypted personal information was compromised, as specified, and requires that disclosure to be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement, as specified, or any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system. This bill would require that data breach disclosure to be made within 30 calendar days of discovery or notification of the data breach but would authorize an individual or business to delay the disclosure to accommodate the legitimate needs of law enforcement, as specified, or as necessary to determine the scope of the breach and restore the reasonable integrity of the data system. Existing law also requires an individual or business that is required to issue the security breach notification described above to more than 500 California residents as a result of a single breach of the security system to electronically submit a single sample copy of that security breach notification, excluding any personally identifiable information, to the Attorney General. This bill would require that submission to the Attorney General to be made within 15 calendar days of notifying affected consumers of the security breach.
Existing law establishes the California Privacy Protection Agency (CPPA) to enforce various laws protecting the privacy of individuals. If a business knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship, existing law requires the business to register with the CPPA as a data broker, except as specified. Existing law requires the CPPA to establish an accessible deletion mechanism that allows a consumer to request that every data broker delete any personal information related to that consumer held by the data broker or associated service provider or contractor, as prescribed. Existing law requires, beginning August 1, 2026, a data broker to access that deletion mechanism at least once every 45 days and, among other things, process all deletion requests and delete all personal information related to the consumers making the requests, as specified. This bill would change the above-described 45-day period to a 30-day period and make conforming changes. This bill would require the Secretary of State, certain local government officials, the Judicial Council, and the State Bar of California to notify any state elected official, local elected official, or judge, as applicable, that the person may submit a request to delete that person's personal information through the above-described accessible deletion mechanism, as prescribed. By imposing additional duties on local government officials, this bill would impose a state-mandated local program. This bill would authorize the Attorney General, a county counsel, or a city attorney to bring a civil action, on behalf of an elected official or judge, against a data broker who violates certain personal information deletion requirements, as prescribed. This bill would make its provisions relating to the notice and enforcement of requests for deletion of personal information of elected officials and judges operative on July 1, 2027. The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state. Statutory provisions establish procedures for making that reimbursement. This bill would provide that, if the Commission on State Mandates determines that the bill contains costs mandated by the state, reimbursement for those costs shall be made pursuant to the statutory provisions noted above.