Existing law requires the Attorney General to publish model policies limiting assistance with immigration enforcement to the fullest extent possible consistent with federal and state law at public schools, public libraries, health facilities operated by the state or a political subdivision of the state, courthouses, Division of Labor Standards Enforcement facilities, the Agricultural Labor Relations Board, the Division of Workers Compensation, and shelters, and ensuring that they remain safe and accessible to all California residents, regardless of immigration status. Existing law requires the Attorney General to publish guidance, audit criteria, and training recommendations aimed at ensuring that any databases operated by state and local law enforcement agencies, including databases maintained for the agency by private vendors, are governed in a manner that limits the availability of information therein to the fullest extent practicable and consistent with federal and state law, to anyone or any entity for the purpose of immigration enforcement. Existing law, the California Values Act, prohibits California law enforcement agencies from using agency or department moneys or personnel to investigate, interrogate, detain, detect, or arrest persons for immigration enforcement purposes, including, among other things, providing personal information about an individual, making or intentionally participating in arrests based on civil immigration warrants, or performing the functions of an immigration officer, as specified. This bill would prohibit a state or local government agency from collecting immigration-related personally identifiable information unless it is explicitly required by law to do so and the collection is justified by a legitimate government purpose. The bill would prohibit a state or local government agency from sharing personally identifiable information with federal immigration enforcement agencies without a judicial warrant or court order. The bill would require any contract, agreement, or memorandum of understanding that facilitate data sharing between a state or local government agency and federal immigration enforcement authorities to comply with oversight mechanisms to ensure compliance with civil rights and privacy protections and be subject to review by the State Auditor, as described below. Because the bill would require local agencies to perform additional duties, it would impose a state-mandated local program. The bill would make these provisions enforceable by administrative action or by imposition of a civil penalty recovered by an action brought by the Attorney General. This bill would require the State Auditor to conduct audits of all state and local government agency data-sharing agreements at least every 2 years to ensure compliance with existing laws protecting privacy and civil rights. The bill would require the Office of the Attorney General to establish an oversight task force to review complaints and violations related to unauthorized data collection and sharing that would report to the Legislature annually on data privacy trends, risks, and policy recommendations. The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state. Statutory provisions establish procedures for making that reimbursement. This bill would provide that, if the Commission on State Mandates determines that the bill contains costs mandated by the state, reimbursement for those costs shall be made pursuant to the statutory provisions noted above.
(1) Existing law, the California Consumer Privacy Act of 2018 (CCPA) , grants a consumer various rights with respect to personal information, as defined, that is collected or sold by a business, as defined, including the right to direct a business that collects sensitive personal information about the consumer to limit its use, as prescribed. Existing law defines "sensitive personal information" to mean, among other things, personal information that reveals a consumer's precise geolocation. Existing law, the California Privacy Rights Act of 2020, approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA. This bill would prohibit a covered entity from collecting or processing the location information of an individual unless doing so is necessary to provide goods or services requested by that individual. The bill would impose various other restrictions on covered entities with regard to location information. The bill would define various terms for purposes of these provisions, including "location information" to mean information that pertains to or directly or indirectly reveals the present or past geographical location of an individual or device, as specified. This bill would require a covered entity to prominently display, at the point where location information is being captured, a notice to individuals stating that their location information is being collected, the name of the covered entity and service provider collecting the information, and a phone number and an internet website where the individual can obtain more information. The bill would require a covered entity to maintain and make available to the data subject a location privacy policy that includes specified information on data usage and management and is subject to a specified notice procedure. This bill would make a covered entity that violates these provisions liable for actual or statutory damages and other specified relief. The bill would authorize the Attorney General or other public prosecutors to bring an action to recover a civil penalty against a covered entity that violates these provisions. This bill would require a business, as defined by the CCPA, to comply with the above-described provisions. (2) Existing law, the Information Practices Act of 1977, prescribes a set of requirements, prohibitions, and remedies applicable to agencies, as defined, with regard to their collection, storage, and disclosure of personal information, as defined. This bill would prohibit a state or local agency, including an agency as defined under the Information Practices Act, from monetizing, as defined, location information. By imposing new requirements on local agencies, this bill would impose a state-mandated local program. (3) The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state. Statutory provisions establish procedures for making that reimbursement. This bill would provide that, if the Commission on State Mandates determines that the bill contains costs mandated by the state, reimbursement for those costs shall be made pursuant to the statutory provisions noted above. (4) The California Consumer Privacy Act of 2020 authorizes the Legislature to amend the act to further the purposes and intent of the act by a majority vote of both houses of the Legislature, as specified. This bill would declare that its provisions further the purposes and intent of the California Privacy Rights Act of 2020.
Existing law, the California Consumer Privacy Act of 2018 (CCPA) , grants a consumer various rights with respect to personal information that is collected or sold by a business. The CCPA defines various terms for these purposes. The California Privacy Rights Act of 2020 (CPRA) , approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA and establishes the California Privacy Protection Agency (agency) and vests the agency with full administrative power, authority, and jurisdiction to enforce the CCPA. Existing law requires, on or before January 1, 2026, and before each time thereafter that a generative artificial intelligence system or service, as defined, or a substantial modification to a generative artificial intelligence system or service, released on or after January 1, 2022, is made available to Californians for use, regardless of whether the terms of that use include compensation, a developer of the system or service to post on the developer's internet website documentation, as specified, regarding the data used to train the generative artificial intelligence system or service. This bill would impose a duty on a covered deployer, defined as a business that deploys a high-risk artificial intelligence system that processes personal information, to protect personal information held by the covered deployer, subject to certain requirements. In this regard, the bill would require a covered deployer whose high-risk artificial intelligence systems process personal information to develop, implement, and maintain a comprehensive information security program, as specified, that contains administrative, technical, and physical safeguards that are appropriate for, among other things, the covered deployer's size, scope, and type of business. The bill would require the program described above to meet specified requirements, including, among other things, that the program incorporates safeguards that are consistent with the safeguards for the protection of personal information and information of a similar character under applicable state or federal laws and regulations. Existing law, the Unfair Competition Law, establishes a statutory cause of action for unfair competition, including any unlawful, unfair, or fraudulent business act or practice and unfair, deceptive, untrue, or misleading advertising, and establishes remedies and penalties in that regard, including injunctive relief and civil penalties. This bill would specify that a violation of the above-described provisions relating to the duty of a covered deployer to protect information, including the requirement that a covered deployer maintain the comprehensive information security program described above, constitute a deceptive trade act or practice under that law. Existing law, the Administrative Procedure Act, governs the procedure for the adoption, amendment, or repeal of regulations by state agencies and for the review of those regulatory actions by the Office of Administrative Law. This bill would authorize the agency to adopt regulations pursuant to the act to implement these provisions, and would exempt, notwithstanding that provision, any regulations adopted by the agency to establish fees from the act. The bill would define various terms for these purposes. The California Privacy Rights Act of 2020 authorizes the Legislature to amend the act to further the purposes and intent of the act by a majority vote of both houses of the Legislature, as specified. This bill would declare that its provisions further the purposes and intent of the California Privacy Rights Act of 2020.
The Confidentiality of Medical Information Act governs the disclosure of medical information by an employer, a provider of health care, a health care service plan, or a contractor, as those terms are defined. The California Consumer Privacy Act of 2018 (CCPA) authorizes a consumer to direct a business, as defined, that collects sensitive personal information about the consumer to limit its use of the consumer's sensitive personal information, as specified, and defines "sensitive personal information" to include personal information that reveals a consumer's neural data. The CCPA also authorizes a consumer to request that a business delete any personal information about the consumer which the business has collected from the consumer, as prescribed. The California Privacy Rights Act of 2020, approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA and establishes the California Privacy Protection Agency and vests the agency with full administrative power, authority, and jurisdiction to enforce the CCPA. This bill would require, under the CCPA, a covered business to use neural data only for the purpose for which the neural data was collected and would require a covered business to delete neural data when the purpose for which the neural data was collected is accomplished. The bill would define "covered business" to mean a person who makes available a brain-computer interface to a person in this state and would define "brain-computer interface" to mean a system that allows direct communication and control between a person's brain and an external device. This bill would declare that its provisions further the purposes and intent of the California Privacy Rights Act of 2020.
The California Constitution authorizes the Legislature to exempt from taxation, in whole or in part, property that is used exclusively for religious, hospital, or charitable purposes, and is owned or held in trust by a nonprofit entity. Pursuant to that authority, existing law provides for a welfare exemption under which property used exclusively for an exempt purpose and owned and operated by specified entities, including foundations, limited liability companies, or corporations meeting certain statutory requirements is exempt from taxation. This bill would specify that for the purposes of the welfare exemption provisions above, "property used exclusively for religious, hospital, scientific, or charitable purposes" shall not include property, or any portion thereof, operated as a detention facility, as defined. The bill would declare that the above provision is declarative of, and not a change in, existing law.
The California Consumer Privacy Act of 2018 (CCPA) grants to a consumer various rights with respect to personal information that is collected by a business, including the right to delete personal information. The California Privacy Rights Act of 2020, approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA and establishes the California Privacy Protection Agency and vests the agency with full administrative power, authority, and jurisdiction to enforce the CCPA. The CCPA excludes from the definition of "personal information" publicly available information. Existing law defines "publicly available" for these purposes to include 3 types of information. One type is information that a business has a reasonable basis to believe is lawfully made available to the general public by the consumer or from widely distributed media. This bill would revise that part of the definition of "publicly available" by removing the condition that the business have a reasonable basis to believe the information is lawfully made available. The CCPA also includes in that definition of "publicly available" information made available by a person to whom the consumer has disclosed the information if the consumer has not restricted the information to a specific audience. This bill would delete that part of the definition of "publicly available." This bill would declare that its provisions further the purposes and intent of the California Privacy Rights Act of 2020.
Existing law, the Electronic Communications Privacy Act, prohibits a government entity from compelling the production of, or access to, electronic communication information or electronic device information, as defined, without a search warrant, wiretap order, order for electronic reader records, or subpoena issued pursuant to specified conditions. Existing law authorizes a government entity to access electronic device information by means of physical interaction or electronic communication with the device in certain circumstances, including, pursuant to the specific consent of the authorized possessor of the device or if the government entity, in good faith, believes that an emergency involving danger of death or serious physical injury to a person requires access to the information. Existing law requires a government entity that obtains electronic information pursuant to an emergency involving danger of death or serious physical injury to a person, within 3 court days after obtaining the electronic information, to file with the appropriate court an application for a warrant or order setting forth the facts giving rise to the emergency. Existing law requires the court to promptly rule on the application and to destroy all information obtained upon a finding that the facts did not give rise to an emergency or upon rejecting the application on any other ground. This bill would additionally authorize a government entity to access electronic device information with the specific consent of an individual who locates a tracking or surveillance device, as defined, and the device is reasonably believed to have been used to track or record the individual without their permission. The bill would require a government entity that obtains information through this method, within 3 court days after obtaining the electronic information, to follow the above process for applying for a warrant or order from a court by setting forth the facts that describe the circumstances and would require the court to promptly rule on the application and order the immediate destruction of all information obtained upon a finding that the facts were not as described. Existing law authorizes an individual whose information is targeted by a warrant, order, or other legal process, or other specified recipients of a warrant, that is inconsistent with the act or the California or United States Constitution, to petition the issuing court to void or modify the warrant, order, or process, or to order the destruction of any information obtained in violation of the act or the California or United States Constitution. This bill would recast the provisions described above to authorize an individual whose information is sought or obtained by a government entity in a manner that is inconsistent with the act or the California or United States Constitution, or other specified recipients of a warrant, order, legal process, request, or demand seeking the individual's information, to petition a court to void or modify the warrant, order, other legal process, request, or demand to order the destruction of the information.
Existing law requires the governing board of a school district that maintains one or more schools containing any of grades 7 to 12, inclusive, to establish a policy regarding participation in extracurricular and cocurricular activities by pupils in those grades as a condition for the receipt of specified school funding allocations. This bill, commencing with the 2027–28 school year, would prohibit a school district, county office of education, or charter school from excluding a pupil from participating in any extracurricular activity, including sports and clubs, due to the pupil not having or using addictive feeds, as defined. Existing law provides that parents and guardians of children enrolled in public schools have the right and should have the opportunity, as mutually supportive and respectful partners in the education of their children within the public schools, to be informed by the school, and to participate in the education of their children, as specified, including by, among other things, to be notified on a timely basis if their child is absent from school without permission. This bill, commencing with the 2027–28 school year, would prohibit a school district, county office of education, or charter school from using addictive feeds, as defined, as the only means of contacting pupils or pupils' parents or guardians.
Existing law prohibits a public agency, which includes the state, a city, a county, a city and county, or any agency or political subdivision of the state, a city, a county, or a city and county, including, but not limited to, a law enforcement agency, from selling, sharing, or transferring automated license plate recognition (ALPR) information, except to another public agency, and only as otherwise permitted by law. Existing law defines ALPR information as information or data collected through the use of an ALPR system. This bill would provide that "public agency" does not include a transportation agency, a public transit operator, or a local department of transportation or public works department, as specified. The bill would, beginning January 1, 2026, require new, updated, expansions of, or addendums of contractual agreements with ALPR vendors, manufacturers, or suppliers to mandate that no default access is provided to any national ALPR database and that an agency's collected scans are by default not accessible to any other agency, and would impose new requirements on sharing between California state law enforcement agencies. The bill would authorize a law enforcement agency to use ALPR information only for purposes of locating vehicles or persons when either are reasonably suspected of being involved in the commission of a public offense. The bill would prohibit a public agency from retaining ALPR information for more than 60 days after the date of collection if it does not match information on an authorized hot list, as defined, and as of January 1, 2026, would require a public agency to delete all ALPR information that has been held for more than 60 days and does not match information on an authorized hot list within 14 days. By imposing new requirements on public agencies, which include local agencies, this bill would impose a state-mandated local program. Existing law defines an ALPR operator as a person that operates an ALPR system, which does not include a transportation agency. Existing law defines an ALPR end-user a person that accesses or uses an ALPR system, which does not include, among other things, a transportation agency. This bill would additionally exclude from the definitions of "ALPR operator" and "ALPR end-user" a public transit operator, a local department of transportation or public works department, or an airport or airport operator, as provided. Existing law requires an ALPR operator and ALPR end-user to maintain reasonable security procedures and practices, including operational, administrative, technical, and physical safeguards, to protect ALPR information from unauthorized access, destruction, use, modification, or disclosure. This bill would require those security procedures and practices to include safeguards for managing which employees can see the data from their systems, as specified, and requiring data security training and data privacy training for all employees that access ALPR information. Existing law requires an ALPR operator and ALPR end-user to implement a usage and privacy policy that includes, among other things, a description of the job title or other designation of the employees and independent contractors who are authorized to access and use ALPR information. This bill would require the usage and privacy policy to identify what purpose employees and independent contractors access and use ALPR information for. The bill would also require the Department of Justice to, contingent upon an appropriation of sufficient funds, conduct annual random audits on a public agency that is an ALPR operator or ALPR end-user to determine whether they have implemented and are adhering to that usage and privacy policy. Existing law requires an ALPR operator that accesses or provides access to ALPR information to require that ALPR information only be used for the authorized purposes described in the usage and privacy policy and to maintain a record of that access that includes, among other things, the purpose for accessing the information. This bill would instead require that record of access maintained by the ALPR operator to include the case file number or task force name, as applicable, that justifies the search query, and would provide that no queries shall be allowed without a log entry with a valid and current case file number or task force name from the agency conducting the query. The bill would include findings that changes proposed by this bill address a matter of statewide concern rather than a municipal affair and, therefore, apply to all cities, including charter cities. The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state. Statutory provisions establish procedures for making that reimbursement. This bill would provide that, if the Commission on State Mandates determines that the bill contains costs mandated by the state, reimbursement for those costs shall be made pursuant to the statutory provisions noted above.
The California Consumer Privacy Act of 2018 (CCPA) grants a consumer various rights with respect to personal information that is collected or sold by a business, including the right to request that a business disclose specified information that has been collected about the consumer, to request that a business delete personal information about the consumer that the business has collected from the consumer, and to direct a business not to sell or share the consumer's personal information, as specified. The CCPA defines various terms for these purposes. The California Privacy Rights Act of 2020 (CPRA) , approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA and establishes the California Privacy Protection Agency (agency) and vests the agency with full administrative power, authority, and jurisdiction to enforce the CCPA. Existing law requires a data broker to register with the agency, and defines "data broker" to mean a business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship, subject to specified exceptions. Existing law requires a data broker, in registering with the agency, to pay a registration fee in an amount determined by the agency and provide specified information, including, among other things, the name of the data broker and its primary physical, email, and internet website addresses, and whether the data broker collects the personal information of minors, consumers' precise geolocation, or consumers' reproductive health care data. This bill would require a data broker to provide additional information to the agency, including whether the data broker collects consumers' names, dates of birth, ZIP Codes, email addresses, phone numbers, login or account information, various government identification numbers, mobile advertising, connected television, or vehicle identification numbers, citizenship data, union membership status, sexual orientation status, gender identity and gender expression data, biometric data, and up to 3, but no fewer than one, of the most common types of personal information that the data broker collects, as provided. The bill would also require a data broker to provide information regarding whether, in the past year, the data broker shared or sold consumers' data to a foreign actor, as defined, the federal government, other state governments, law enforcement, as provided, or a developer of a GenAI system, as defined. The bill would make changes to the administrative fines and costs that apply to data brokers who fail to register. Existing law requires, beginning January 1, 2026, the California Privacy Protection Agency to establish an accessible deletion mechanism that, among other things, allows a consumer, through a single verifiable consumer request, to request that every data broker that maintains any personal information delete any personal information related to that consumer held by the data broker or associated service provider or contractor. Existing law requires, beginning August 1, 2026, a data broker to access the accessible deletion mechanism at least once every 45 days and, among other things, process a denied request to delete personal information as an opt-out of the sale or sharing of the consumer's personal information under the CCPA, as specified. This bill would require a data broker to process the above-described denied request within 45 days of receiving the request. Existing law requires the agency to create a page on its internet website where registration information provided by data brokers and the accessible deletion mechanism is accessible to the public. This bill would prohibit the agency from making accessible to the public on its internet website information regarding whether the data broker collects consumers' names, dates of birth, zip codes, email addresses, phone numbers, mobile advertising, connected television, or vehicle identification numbers, and the most common types of personal information that it collects. This bill would declare that it furthers the purposes and intent of the CPRA for specified reasons.