The California Constitution authorizes the Legislature to exempt from taxation, in whole or in part, property that is used exclusively for religious, hospital, or charitable purposes, and is owned or held in trust by a nonprofit entity. Pursuant to that authority, existing law provides for a welfare exemption under which property used exclusively for an exempt purpose and owned and operated by specified entities, including foundations, limited liability companies, or corporations meeting certain statutory requirements is exempt from taxation. This bill would specify that for the purposes of the welfare exemption provisions above, "property used exclusively for religious, hospital, scientific, or charitable purposes" shall not include property, or any portion thereof, operated as a detention facility, as defined. The bill would declare that the above provision is declarative of, and not a change in, existing law.
The California Consumer Privacy Act of 2018 (CCPA) grants to a consumer various rights with respect to personal information that is collected by a business, including the right to delete personal information. The California Privacy Rights Act of 2020, approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA and establishes the California Privacy Protection Agency and vests the agency with full administrative power, authority, and jurisdiction to enforce the CCPA. The CCPA excludes from the definition of "personal information" publicly available information. Existing law defines "publicly available" for these purposes to include 3 types of information. One type is information that a business has a reasonable basis to believe is lawfully made available to the general public by the consumer or from widely distributed media. This bill would revise that part of the definition of "publicly available" by removing the condition that the business have a reasonable basis to believe the information is lawfully made available. The CCPA also includes in that definition of "publicly available" information made available by a person to whom the consumer has disclosed the information if the consumer has not restricted the information to a specific audience. This bill would delete that part of the definition of "publicly available." This bill would declare that its provisions further the purposes and intent of the California Privacy Rights Act of 2020.
Existing law requires the governing board of a school district that maintains one or more schools containing any of grades 7 to 12, inclusive, to establish a policy regarding participation in extracurricular and cocurricular activities by pupils in those grades as a condition for the receipt of specified school funding allocations. This bill, commencing with the 2027–28 school year, would prohibit a school district, county office of education, or charter school from excluding a pupil from participating in any extracurricular activity, including sports and clubs, due to the pupil not having or using addictive feeds, as defined. Existing law provides that parents and guardians of children enrolled in public schools have the right and should have the opportunity, as mutually supportive and respectful partners in the education of their children within the public schools, to be informed by the school, and to participate in the education of their children, as specified, including by, among other things, to be notified on a timely basis if their child is absent from school without permission. This bill, commencing with the 2027–28 school year, would prohibit a school district, county office of education, or charter school from using addictive feeds, as defined, as the only means of contacting pupils or pupils' parents or guardians.
Existing law prohibits a public agency, which includes the state, a city, a county, a city and county, or any agency or political subdivision of the state, a city, a county, or a city and county, including, but not limited to, a law enforcement agency, from selling, sharing, or transferring automated license plate recognition (ALPR) information, except to another public agency, and only as otherwise permitted by law. Existing law defines ALPR information as information or data collected through the use of an ALPR system. This bill would provide that "public agency" does not include a transportation agency, a public transit operator, or a local department of transportation or public works department, as specified. The bill would, beginning January 1, 2026, require new, updated, expansions of, or addendums of contractual agreements with ALPR vendors, manufacturers, or suppliers to mandate that no default access is provided to any national ALPR database and that an agency's collected scans are by default not accessible to any other agency, and would impose new requirements on sharing between California state law enforcement agencies. The bill would authorize a law enforcement agency to use ALPR information only for purposes of locating vehicles or persons when either are reasonably suspected of being involved in the commission of a public offense. The bill would prohibit a public agency from retaining ALPR information for more than 60 days after the date of collection if it does not match information on an authorized hot list, as defined, and as of January 1, 2026, would require a public agency to delete all ALPR information that has been held for more than 60 days and does not match information on an authorized hot list within 14 days. By imposing new requirements on public agencies, which include local agencies, this bill would impose a state-mandated local program. Existing law defines an ALPR operator as a person that operates an ALPR system, which does not include a transportation agency. Existing law defines an ALPR end-user a person that accesses or uses an ALPR system, which does not include, among other things, a transportation agency. This bill would additionally exclude from the definitions of "ALPR operator" and "ALPR end-user" a public transit operator, a local department of transportation or public works department, or an airport or airport operator, as provided. Existing law requires an ALPR operator and ALPR end-user to maintain reasonable security procedures and practices, including operational, administrative, technical, and physical safeguards, to protect ALPR information from unauthorized access, destruction, use, modification, or disclosure. This bill would require those security procedures and practices to include safeguards for managing which employees can see the data from their systems, as specified, and requiring data security training and data privacy training for all employees that access ALPR information. Existing law requires an ALPR operator and ALPR end-user to implement a usage and privacy policy that includes, among other things, a description of the job title or other designation of the employees and independent contractors who are authorized to access and use ALPR information. This bill would require the usage and privacy policy to identify what purpose employees and independent contractors access and use ALPR information for. The bill would also require the Department of Justice to, contingent upon an appropriation of sufficient funds, conduct annual random audits on a public agency that is an ALPR operator or ALPR end-user to determine whether they have implemented and are adhering to that usage and privacy policy. Existing law requires an ALPR operator that accesses or provides access to ALPR information to require that ALPR information only be used for the authorized purposes described in the usage and privacy policy and to maintain a record of that access that includes, among other things, the purpose for accessing the information. This bill would instead require that record of access maintained by the ALPR operator to include the case file number or task force name, as applicable, that justifies the search query, and would provide that no queries shall be allowed without a log entry with a valid and current case file number or task force name from the agency conducting the query. The bill would include findings that changes proposed by this bill address a matter of statewide concern rather than a municipal affair and, therefore, apply to all cities, including charter cities. The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state. Statutory provisions establish procedures for making that reimbursement. This bill would provide that, if the Commission on State Mandates determines that the bill contains costs mandated by the state, reimbursement for those costs shall be made pursuant to the statutory provisions noted above.
Existing law generally provides protections for minors on the internet, including the California Age-Appropriate Design Code Act that, among other things, requires a business that provides an online service, product, or feature likely to be accessed by children to do certain things, including estimate the age of child users with a reasonable level of certainty appropriate to the risks that arise from the data management practices of the business or apply the privacy and data protections afforded to children to all consumers and prohibits an online service, product, or feature from, among other things, using dark patterns to lead or encourage children to provide personal information beyond what is reasonably expected to provide that online service, product, or feature or to forego privacy protections. This bill, beginning January 1, 2027, would require, among other things related to age verification with respect to software applications, an operating system provider, as defined, to provide an accessible interface at account setup that requires an account holder, as defined, to indicate the birth date, age, or both, of the user of that device for the purpose of providing a signal regarding the user's age bracket to applications available in a covered application store and to provide a developer, as defined, who has requested a signal with respect to a particular user with a digital signal via a reasonably consistent real-time application programming interface regarding whether a user is in any of several age brackets, as prescribed. The bill would require a developer to request a signal with respect to a particular user from an operating system provider or a covered application store when the application is downloaded and launched. This bill would prohibit an operating system provider or a covered application store from using data collected from a third party in an anticompetitive manner, as specified. This bill would punish noncompliance with a civil penalty to be enforced by the Attorney General, as prescribed. This bill would declare its provisions to be severable.
The California Consumer Privacy Act of 2018 (CCPA) grants a consumer various rights with respect to personal information that is collected or sold by a business, including the right to request that a business disclose specified information that has been collected about the consumer, to request that a business delete personal information about the consumer that the business has collected from the consumer, and to direct a business not to sell or share the consumer's personal information, as specified. The CCPA defines various terms for these purposes. The California Privacy Rights Act of 2020 (CPRA) , approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA and establishes the California Privacy Protection Agency (agency) and vests the agency with full administrative power, authority, and jurisdiction to enforce the CCPA. Existing law requires a data broker to register with the agency, and defines "data broker" to mean a business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship, subject to specified exceptions. Existing law requires a data broker, in registering with the agency, to pay a registration fee in an amount determined by the agency and provide specified information, including, among other things, the name of the data broker and its primary physical, email, and internet website addresses, and whether the data broker collects the personal information of minors, consumers' precise geolocation, or consumers' reproductive health care data. This bill would require a data broker to provide additional information to the agency, including whether the data broker collects consumers' names, dates of birth, ZIP Codes, email addresses, phone numbers, login or account information, various government identification numbers, mobile advertising, connected television, or vehicle identification numbers, citizenship data, union membership status, sexual orientation status, gender identity and gender expression data, biometric data, and up to 3, but no fewer than one, of the most common types of personal information that the data broker collects, as provided. The bill would also require a data broker to provide information regarding whether, in the past year, the data broker shared or sold consumers' data to a foreign actor, as defined, the federal government, other state governments, law enforcement, as provided, or a developer of a GenAI system, as defined. The bill would make changes to the administrative fines and costs that apply to data brokers who fail to register. Existing law requires, beginning January 1, 2026, the California Privacy Protection Agency to establish an accessible deletion mechanism that, among other things, allows a consumer, through a single verifiable consumer request, to request that every data broker that maintains any personal information delete any personal information related to that consumer held by the data broker or associated service provider or contractor. Existing law requires, beginning August 1, 2026, a data broker to access the accessible deletion mechanism at least once every 45 days and, among other things, process a denied request to delete personal information as an opt-out of the sale or sharing of the consumer's personal information under the CCPA, as specified. This bill would require a data broker to process the above-described denied request within 45 days of receiving the request. Existing law requires the agency to create a page on its internet website where registration information provided by data brokers and the accessible deletion mechanism is accessible to the public. This bill would prohibit the agency from making accessible to the public on its internet website information regarding whether the data broker collects consumers' names, dates of birth, zip codes, email addresses, phone numbers, mobile advertising, connected television, or vehicle identification numbers, and the most common types of personal information that it collects. This bill would declare that it furthers the purposes and intent of the CPRA for specified reasons.
The California Consumer Privacy Act of 2018 (CCPA) grants a consumer various rights with respect to personal information that is collected or sold by a business, as defined, including the right to direct a business that sells or shares personal information about the consumer to third parties not to sell or share the consumer's personal information, as specified. The California Privacy Rights Act of 2020, approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA and establishes the California Privacy Protection Agency and vests the agency with full administrative power, authority, and jurisdiction to enforce the CCPA. This bill would, beginning January 1, 2027, prohibit a business from developing or maintaining a browser, as defined, that does not include functionality configurable by a consumer that enables the browser to send an opt-out preference signal, as defined, to businesses with which the consumer interacts through the browser, as prescribed. The bill would require a business that develops or maintains a browser to make clear to a consumer in its public disclosures how the opt-out preference signal works and the intended effect of the opt-out preference signal. The bill would grant a business that develops or maintains a browser that includes this functionality immunity from liability for a violation of those provisions by a business that receives the opt-out preference signal. The bill would authorize the agency to adopt regulations as necessary to implement and administer those provisions. This bill would declare that its provisions further the purposes and intent of the California Privacy Rights Act of 2020.