Existing law creates a civil cause of action against any person who knowingly uses the name, voice, signature, photograph, or likeness of another person, without their consent, for specified purposes. When a photograph or likeness of an employee of the person using the photograph or likeness appearing in an advertisement or other publication is incidental and not essential to the purpose of the publication, existing law establishes a rebuttable presumption affecting the burden of producing evidence that failure to obtain the consent of an employee was not a knowing use of an employee's photograph or likeness. This bill would clarify that, for purposes of this cause of action, a voice or likeness includes a digital replica, defined to mean a computer-generated, highly realistic electronic representation that is readily identifiable as the voice or visual likeness of an individual in which the actual individual either did not actually perform or appear, or the actual individual did perform or appear, but the fundamental character of the performance or appearance has been materially altered. The bill would also remove the provisions establishing the rebuttable presumption when an employee's likeness or photograph appears in an advertisement or other publication. Existing law prohibits the false impersonation of another person in either their personal or official capacity with the intent to steal or defraud, as specified. This bill would clarify that false impersonation includes the use of a digital replica with the intent to impersonate another for purposes of these and other criminal provisions.
The Insurance Rate Reduction and Reform Act of 1988, an initiative measure enacted by Proposition 103, as approved by the voters at the November 8, 1988, statewide general election, prohibits specified insurance rates from being approved or remaining in effect that are excessive, inadequate, unfairly discriminatory, or otherwise in violation of the act. Under the act, rates and premiums for automobile insurance are determined based on specified factors, including the insured's driving safety record. Existing law authorizes the provisions of Proposition 103 to be amended by a statute that furthers the purposes of the act and is enacted by the Legislature with a 23 vote. This bill, the Consumer Driving Data Protection Act of 2026, would authorize a consumer to opt to use telematics to establish their driving record, thus amending Proposition 103. The bill would prohibit the use of telematics data for a purpose other than rating private passenger automobile insurance. The bill would require a rate application under which telematics would be used to establish an insured's driving record to include specified materials related to the insurer's telematics program. This bill would prohibit an insurer that uses telematics from taking specified actions, including conditioning eligibility for a discount upon participation in a telematics program, unless the discount is approved by the commissioner. The bill would also set forth consent and privacy requirements for the collection and use of telematics data. The bill would authorize the commissioner to impose specified penalties for violations of the bill's provisions, including civil penalties and suspension of an insurer's telematics program. The bill would declare that its provisions further the purposes of Proposition 103.
Existing law, the California Consumer Privacy Act of 2018 (CCPA) , grants a consumer various rights with respect to personal information that is collected or sold by a business, as defined, including the right to direct a business that sells or shares personal information about the consumer to third parties not to sell or share the consumer's personal information, as specified. Existing law, the California Privacy Rights Act of 2020, approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA and establishes the California Privacy Protection Agency and vests the agency with full administrative power, authority, and jurisdiction to enforce those provisions. Existing law requires a retail grocery store or grocery department within a general retail merchandise store that uses a point-of-sale system to have a clearly readable price indicated on 85% of the total number of packaged consumer commodities offered for sale, subject to specified exemptions. This bill would, subject to certain exceptions, prohibit a retailer from engaging in surveillance pricing. The bill would define "surveillance pricing" to mean offering or setting a customized price for a good for a specific consumer or group of consumers, based, in whole or in part, on personally identifiable information, as specified, and determined in whole or in part through the use of any technology, software, program, machine-based system, or computational process that uses statistical modeling, data analytics, artificial intelligence, or other data processing techniques. The bill would also define "surveillance pricing" to mean random variations in prices to different consumers using a website, mobile application, or comparable online technology. The bill would provide that its provisions do not limit or impair any consumer right or remedy available under any other state or federal law. The bill would declare that any waiver of these provisions is against public policy and is void and unenforceable. This bill would declare that its provisions further the purposes and intent of the California Privacy Rights Act of 2020.
Existing law establishes the Department of Consumer Affairs to, among other things, protect consumer interests and regulate specified businesses. Existing law requires a business that provides an online service, product, or feature likely to be accessed by children to comply with specified requirements, including configuring all default privacy settings provided to children to settings that offer a high level of privacy. Existing law prohibits an operator of an internet website, online service, online application, or mobile application directed to minors from marketing or advertising specified products or services to a minor. This bill would enact the California Children's Digital Educational Content Act of 2026, which would require a covered platform, as defined, to establish and maintain a walled garden. The bill would define a walled garden as a clearly designated and easily accessible section of a platform that is dedicated exclusively to educational children's content, as defined. The bill would require a walled garden to meet certain requirements, including that it be free from targeted advertising and be accessible to minors without an account. The bill would authorize the department to adopt regulations to implement these provisions. The bill would require a covered platform to annually submit a compliance report to the department and would authorize the department to conduct audits. The bill would impose specified administrative penalties for violation of its provisions.
Existing law establishes the Division of Labor Standards Enforcement within the Department of Industrial Relations. Existing law authorizes the division, which is headed by the Labor Commissioner, to enforce the Labor Code and all labor laws of the state, the enforcement of which is not specifically vested in any other officer, board, or commission. This bill would prohibit an employer from using a worker's personal information, as defined, to train an artificial intelligence system to replicate, automate, or replace a worker's job, and would prohibit an employer from selling, disclosing, or otherwise providing access to a worker's personal information to a third party for the purpose of training an artificial intelligence system to replicate, automate, or replace a worker's job. The bill would prohibit a vendor providing services to an employer under a contract from providing access to the personal information of an employer's worker to a third party or using the personal information of an employer's worker to train artificial intelligence, as specified. The bill would require a contract between an employer and vendor to include a requirement that the vendor implement and maintain reasonable security procedures to protect the worker's personal information from, among other things, unauthorized or illegal access. The bill would define terms for these provisions, including "employer" and "personal information." The bill would require the Labor Commissioner and authorize a public prosecutor to enforce these provisions. The bill would authorize a worker, or their exclusive representative, who suffered a violation of these provisions to bring a civil action for damages, injunctive relief, punitive damages, and attorney's fees and costs. The bill would establish a statutory penalty for a violation of these provisions of up to $500 for each violation. The bill would include findings that changes proposed by this bill address a matter of statewide concern rather than a municipal affair and, therefore, apply to all cities, including charter cities.
Existing law, the California Consumer Privacy Act of 2018 (CCPA) , imposes various obligations on businesses with respect to personal information, as defined. The California Privacy Rights Act of 2020, approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA. The CCPA requires a business to inform consumers of the categories of personal information to be collected and the purposes for which the categories of personal information are collected or used and whether that information is sold or shared. Existing law, the Student Online Personal Information Protection Act, prohibits an operator, as defined, from, among other things, disclosing a K–12 student's personal information, except as specified. Existing law, the Student Test Taker Privacy Protection Act, prohibits a business providing proctoring services in an educational setting from collecting, retaining, using, or disclosing personal information except to the extent necessary to provide those proctoring services and in other specified circumstances. This bill, beginning July 1, 2027, would require a business providing those proctoring services to a school district, county office of education, or charter school for classroom- or course-based exams to use end-to-end encryption, as defined, for those purposes. The bill would define "end-to-end encryption" for these purposes to mean a security method where data is encrypted on the sender's device and remains encrypted until it reaches the intended recipient's device and is unreadable by any other party, including the business providing proctoring services. The California Privacy Rights Act of 2020 authorizes the Legislature to amend the act to further the purposes and intent of the act by a majority vote of both houses of the Legislature, as specified. This bill would declare that its provisions further the purposes and intent of the California Privacy Rights Act of 2020.
The California Consumer Privacy Act of 2018 (CCPA) grants a consumer various rights with respect to personal information, as defined, that is collected or sold by a business, as defined, including the right to direct a business that collects sensitive personal information, as defined, about the consumer to limit its use, as prescribed. The California Privacy Rights Act of 2020, approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA. This bill would, under the CCPA, prohibit a business, service provider, or contractor from selling or sharing sensitive personal information to a third party, except as specified. This bill would declare that its provisions further the purposes and intent of the California Privacy Rights Act of 2020.
Existing law, the California Consumer Privacy Act of 2018 (CCPA) , grants to a consumer various rights with respect to personal information that is collected by a business. Among those rights, the CCPA includes the right to request that a business delete personal information that the business has collected from the consumer. This bill would expand that right to include requesting the deletion of any personal information that the business has collected about the consumer. If the business did not obtain the personal information from the consumer, the bill would allow the business to retain a record of the deletion request and the minimum data necessary to ensure the consumer's personal information remains deleted from its records and is not being used for any other purpose. The bill would make findings and declarations relating to these provisions. Existing law generally requires businesses to make certain methods of communication available for consumers to submit personal information requests, including requests for deletion and correction. If a business operates exclusively online and has a direct relationship with the consumer from whom it collects personal information, existing law requires the business to provide consumers an email address for submitting personal information requests. This bill would also require that business to make an online method, such as a web form or online portal, available to consumers for submitting personal information requests. Existing law, the California Privacy Rights Act of 2020, an initiative measure approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA. This bill would declare that its provisions further the purposes and intent of the California Privacy Rights Act of 2020.
Existing law requires an individual or a business that conducts business in California, and that owns or licenses computerized data that includes personal information, to disclose a breach of the security of the system following discovery or notification of the breach in the security of the data to a resident of California whose unencrypted personal information was compromised, as specified, and requires that disclosure to be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement, as specified, or any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system. This bill would require that data breach disclosure to be made within 30 calendar days of discovery or notification of the data breach but would authorize an individual or business to delay the disclosure to accommodate the legitimate needs of law enforcement, as specified, or as necessary to determine the scope of the breach and restore the reasonable integrity of the data system. Existing law also requires an individual or business that is required to issue the security breach notification described above to more than 500 California residents as a result of a single breach of the security system to electronically submit a single sample copy of that security breach notification, excluding any personally identifiable information, to the Attorney General. This bill would require that submission to the Attorney General to be made within 15 calendar days of notifying affected consumers of the security breach.
(1) Existing law, the Digital Financial Assets Law, prohibits a person, on or after July 1, 2026, from engaging in digital financial asset business activity, or holding itself out as being able to engage in digital financial asset business activity, with, or on behalf of, a resident, unless any of certain criteria are met, including that the person is licensed with the Department of Financial Protection and Innovation, as prescribed, or the person submits an application on or before July 1, 2026, and is awaiting approval or denial of that application. This bill would revise the above-described latter criterion to specify that the person submits a completed application, as provided. The Digital Financial Assets Law authorizes the Commissioner of Financial Protection and Innovation to issue a conditional license to an applicant who holds or maintains a license to conduct virtual currency business activity in the State of New York, as specified, provided the license was issued or approved no later than January 1, 2023. This bill would revise the above-described authorization to require that the license be issued or approved no later than January 1, 2025. (2) The Digital Financial Assets Law defines "digital financial asset business activity" to mean any of specified activities, including, among others, exchanging, transferring, or storing a digital financial asset, as specified, or exchanging one or more digital representations of value used within one or more online games, game platforms, or family of games, as provided. This bill would remove exchanging one or more digital representations of value used within one or more online games, game platforms, or family of games from the definition of "digital financial business activity." The bill would specify that a "digital financial asset" does not include, among other things, a transaction in which a merchant grants digital representations of value that primarily relate to an affinity or rewards program, as provided, or a digital representation of value issued by or on behalf of a publisher and used primarily within online games or game platforms and that is not otherwise a digital financial asset. The Digital Financial Assets Law declares that its provisions do not apply to specified activity, including by a person who does not receive compensation for providing digital financial asset products or services or for conducting financial asset business activity or that is engaged in testing products or services with the person's own funds. This bill would specify that the above-described exclusion includes a person who merely retains the ability to terminate, suspend, or interrupt a digital financial transaction solely to prevent unauthorized or fraudulent activity and who is not compensated for that service. The Digital Financial Assets Law prohibits a covered person from exchanging, transferring, or storing a digital financial asset that is a stablecoin or engaging in digital financial asset administration of a stablecoin, as specified, unless certain conditions are met. However, existing law authorizes a covered person to exchange, transfer, or store a stablecoin or engage in digital financial asset administration of that stablecoin, as specified, if the stablecoin is approved by the commissioner and complies with certain requirements, restrictions, or prohibitions established by the commissioner. This bill would repeal the above-described provisions related to stablecoins. (3) The Digital Financial Assets Law requires a licensee to submit an annual report, as provided, containing specified information, including a description of any data security breach or cybersecurity event of the licensee. Existing law requires a licensee to file with the department, as applicable, a report of, among other things, a change in the licensee's business for the conduct of its digital financial asset business activity with, or on behalf of, a resident that meets one of specified criteria, including that the proposed change might raise safety and soundness or operational concerns. This bill would revise the above-described annual report to instead include a description of any material data security breach or cybersecurity event of the licensee. The bill would revise the specified criteria in the requirement to file the above-described report of a change in the licensee's business to instead include that the proposed change might raise material safety and soundness or operational concerns. Before engaging in digital financial asset business activity with a resident, the Digital Financial Assets Law requires a covered person, defined as a person required to obtain a license pursuant to that law, to disclose, as provided, certain information, including the resident's right to at least 14 days' prior notice of specified changes that have a material impact on digital financial asset business activity with the resident, or the policies applicable to the resident's account. Existing law requires a covered exchange, as provided, to certify on a form provided by the department that the covered exchange has taken specified actions, except for any digital financial asset approved for listing on or before January 1, 2023. In a transaction for or with a resident, existing law prohibits the covered exchange from interjecting a third party between the covered exchange and the best market for the digital financial asset in a manner inconsistent with specified requirements. This bill would prohibit the 14-day notice requirement from applying to changes in terms, conditions, or policies that are reasonably necessary to address a risk of loss to the resident or covered person, to the extent that the change does not relate to the fee schedule. The bill would instead exclude from the above-described certification requirement a digital financial asset approved for listing on or before January 1, 2025. The bill would require a covered person to provide and make available an up-to-date description of the order execution practices of the covered person, as specified. The bill would exempt a transaction in which a resident receives stablecoin, as defined, in exchange for legal tender or bank or credit union credit from the above-described prohibition against interjecting a third party. The Digital Financial Assets Law requires an applicant, as provided, to create, and during licensure, maintain in a record specified policies and procedures. Existing law requires these policies and procedures be disclosed separately from other disclosures made available to a resident, as specified, except for, among other things, an adopted information security program or an operational security program. This bill would instead exclude from the above-described requirement to disclose separately from other disclosures programs with information that is sensitive to potential security risks, as specified. This bill would declare that it is to take effect immediately as an urgency statute.