California 2017-2018 Regular Session

California Assembly Bill AB1859

Introduced
1/10/18  
Introduced
1/10/18  
Refer
1/29/18  
Report Pass
4/18/18  
Report Pass
4/18/18  
Refer
4/23/18  
Report Pass
5/2/18  
Report Pass
5/2/18  
Engrossed
5/31/18  
Engrossed
5/31/18  
Refer
6/4/18  
Refer
6/13/18  
Report Pass
6/27/18  
Refer
6/27/18  
Refer
6/27/18  
Refer
8/6/18  
Refer
8/6/18  
Report Pass
8/17/18  
Enrolled
8/29/18  
Enrolled
8/29/18  
Chaptered
9/19/18  
Chaptered
9/19/18  
Passed
9/19/18  

Caption

Customer records.

Impact

The legislation is expected to significantly strengthen data security practices within consumer credit reporting agencies operating in California, thereby enhancing the protection of personal consumer information. By instituting a requirement for timely action on known vulnerabilities, AB1859 reinforces existing consumer protection laws and establishes clearer responsibilities for agencies that manage sensitive data. These changes are anticipated to bolster public confidence in the safeguards in place for personal data, ultimately leading to improved compliance with privacy standards.

Summary

Assembly Bill No. 1859, introduced by Assemblymember Chau, focuses on enhancing consumer protection regarding the maintenance and security of personal data held by consumer credit reporting agencies. The bill introduces a new section to the Civil Code, requiring these agencies to take appropriate measures when they discover security vulnerabilities in their systems that pose a significant risk to consumer data. Specifically, it mandates timely software updates and the implementation of compensating controls to mitigate breaches until updates can be finalized.

Sentiment

The sentiment surrounding AB1859 was generally supportive among consumer advocacy groups who view it as a vital step toward addressing weaknesses in current data security protocols. However, there are concerns from industry stakeholders about the potential burden of compliance, particularly regarding the quick turnaround times mandated for addressing vulnerabilities. While many see the bill as a necessary improvement, some entities worry that the increased obligations may lead to operational challenges.

Contention

Notably, conflict arose regarding the speed at which consumer credit reporting agencies must act to correct identified vulnerabilities. Critics of the bill argue that the imposed timelines could be unrealistic and may not accommodate the complexities associated with implementing software updates and related security measures. The provisions, while well-intentioned, raised questions about the feasibility of complying without risking operational disruptions or financial penalties—for instance, if an agency fails to meet the prescribed deadlines for addressing security threats.

Companion Bills

No companion bills found.

Previously Filed As

CA AB1712

Personal information: data breaches.

CA AB1667

Department of Technology: California Cybersecurity Awareness and Education Council.

CA SB696

Notaries public.

CA SB484

Escrow agents: customer contact centers.

CA AB743

Remote online notaries public.

CA SB1047

Safe and Secure Innovation for Frontier Artificial Intelligence Models Act.

CA AB2478

Incarcerated persons: health records.

CA SB1274

Vital records: adoptees’ birth certificates.

CA AB1394

Commercial sexual exploitation: child sexual abuse material: civil actions.

CA AB39

Digital financial asset businesses: regulatory oversight.

Similar Bills

CA AB1035

COVID-19 emergency: small businesses: immunity from civil liability.

CA AB1130

Personal information: data breaches.

CA AB825

Personal information: data breaches: genetic data.

CA AB2301

Personal information: data breaches: genetic information.

CA AB2004

Medical test results: verification credentials.

CA AB1330

Personal information: privacy: breach.

CA AB1711

Privacy: breach.

CA AB346

Privacy: breach.