California 2017-2018 Regular Session

California Senate Bill SB327 Compare Versions

OldNewDifferences
1-Senate Bill No. 327 CHAPTER 886 An act to add Title 1.81.26 (commencing with Section 1798.91.04) to Part 4 of Division 3 of the Civil Code, relating to information privacy. [ Approved by Governor September 28, 2018. Filed with Secretary of State September 28, 2018. ] LEGISLATIVE COUNSEL'S DIGESTSB 327, Jackson. Information privacy: connected devices.Existing law requires a business to take all reasonable steps to dispose of customer records within its custody or control containing personal information when the records are no longer to be retained by the business by shredding, erasing, or otherwise modifying the personal information in those records to make it unreadable or undecipherable. Existing law also requires a business that owns, licenses, or maintains personal information about a California resident to implement and maintain reasonable security procedures and practices appropriate to the nature of the information, to protect the personal information from unauthorized access, destruction, use, modification, or disclosure. Existing law authorizes a customer injured by a violation of these provisions to institute a civil action to recover damages.This bill, beginning on January 1, 2020, would require a manufacturer of a connected device, as those terms are defined, to equip the device with a reasonable security feature or features that are appropriate to the nature and function of the device, appropriate to the information it may collect, contain, or transmit, and designed to protect the device and any information contained therein from unauthorized access, destruction, use, modification, or disclosure, as specified.This bill would become operative only if AB 1906 of the 201718 Regular Session is enacted and becomes effective.Digest Key Vote: MAJORITY Appropriation: NO Fiscal Committee: YES Local Program: NO Bill TextThe people of the State of California do enact as follows:SECTION 1. Title 1.81.26 (commencing with Section 1798.91.04) is added to Part 4 of Division 3 of the Civil Code, to read:TITLE 1.81.26. Security of Connected Devices1798.91.04. (a) A manufacturer of a connected device shall equip the device with a reasonable security feature or features that are all of the following:(1) Appropriate to the nature and function of the device.(2) Appropriate to the information it may collect, contain, or transmit.(3) Designed to protect the device and any information contained therein from unauthorized access, destruction, use, modification, or disclosure.(b) Subject to all of the requirements of subdivision (a), if a connected device is equipped with a means for authentication outside a local area network, it shall be deemed a reasonable security feature under subdivision (a) if either of the following requirements are met:(1) The preprogrammed password is unique to each device manufactured.(2) The device contains a security feature that requires a user to generate a new means of authentication before access is granted to the device for the first time. 1798.91.05. For the purposes of this title, the following terms have the following meanings:(a) Authentication means a method of verifying the authority of a user, process, or device to access resources in an information system.(b) Connected device means any device, or other physical object that is capable of connecting to the Internet, directly or indirectly, and that is assigned an Internet Protocol address or Bluetooth address.(c) Manufacturer means the person who manufactures, or contracts with another person to manufacture on the persons behalf, connected devices that are sold or offered for sale in California. For the purposes of this subdivision, a contract with another person to manufacture on the persons behalf does not include a contract only to purchase a connected device, or only to purchase and brand a connected device.(d) Security feature means a feature of a device designed to provide security for that device.(e) Unauthorized access, destruction, use, modification, or disclosure means access, destruction, use, modification, or disclosure that is not authorized by the consumer. 1798.91.06. (a) This title shall not be construed to impose any duty upon the manufacturer of a connected device related to unaffiliated third-party software or applications that a user chooses to add to a connected device.(b) This title shall not be construed to impose any duty upon a provider of an electronic store, gateway, marketplace, or other means of purchasing or downloading software or applications, to review or enforce compliance with this title.(c) This title shall not be construed to impose any duty upon the manufacturer of a connected device to prevent a user from having full control over a connected device, including the ability to modify the software or firmware running on the device at the users discretion.(d) This title shall not apply to any connected device the functionality of which is subject to security requirements under federal law, regulations, or guidance promulgated by a federal agency pursuant to its regulatory enforcement authority.(e) This title shall not be construed to provide a basis for a private right of action. The Attorney General, a city attorney, a county counsel, or a district attorney shall have the exclusive authority to enforce this title.(f) The duties and obligations imposed by this title are cumulative with any other duties or obligations imposed under other law, and shall not be construed to relieve any party from any duties or obligations imposed under other law.(g) This title shall not be construed to limit the authority of a law enforcement agency to obtain connected device information from a manufacturer as authorized by law or pursuant to an order of a court of competent jurisdiction.(h) A covered entity, provider of health care, business associate, health care service plan, contractor, employer, or any other person subject to the federal Health Insurance Portability and Accountability Act of 1996 (HIPAA) (Public Law 104-191) or the Confidentiality of Medical Information Act (Part 2.6 (commencing with Section 56) of Division 1) shall not be subject to this title with respect to any activity regulated by those acts.(i) This title shall become operative on January 1, 2020.SEC. 2. This act shall become operative only if Assembly Bill 1906 of the 201718 Regular Session is also enacted and becomes effective.
1+Enrolled September 04, 2018 Passed IN Senate August 29, 2018 Passed IN Assembly August 28, 2018 Amended IN Assembly August 24, 2018 Amended IN Assembly August 06, 2018 Amended IN Senate January 11, 2018 Amended IN Senate May 26, 2017 Amended IN Senate May 17, 2017 Amended IN Senate March 20, 2017 CALIFORNIA LEGISLATURE 20172018 REGULAR SESSION Senate Bill No. 327Introduced by Senator Jackson(Principal coauthor: Assembly Member Irwin)February 13, 2017 An act to add Title 1.81.26 (commencing with Section 1798.91.04) to Part 4 of Division 3 of the Civil Code, relating to information privacy. LEGISLATIVE COUNSEL'S DIGESTSB 327, Jackson. Information privacy: connected devices.Existing law requires a business to take all reasonable steps to dispose of customer records within its custody or control containing personal information when the records are no longer to be retained by the business by shredding, erasing, or otherwise modifying the personal information in those records to make it unreadable or undecipherable. Existing law also requires a business that owns, licenses, or maintains personal information about a California resident to implement and maintain reasonable security procedures and practices appropriate to the nature of the information, to protect the personal information from unauthorized access, destruction, use, modification, or disclosure. Existing law authorizes a customer injured by a violation of these provisions to institute a civil action to recover damages.This bill, beginning on January 1, 2020, would require a manufacturer of a connected device, as those terms are defined, to equip the device with a reasonable security feature or features that are appropriate to the nature and function of the device, appropriate to the information it may collect, contain, or transmit, and designed to protect the device and any information contained therein from unauthorized access, destruction, use, modification, or disclosure, as specified.This bill would become operative only if AB 1906 of the 201718 Regular Session is enacted and becomes effective.Digest Key Vote: MAJORITY Appropriation: NO Fiscal Committee: YES Local Program: NO Bill TextThe people of the State of California do enact as follows:SECTION 1. Title 1.81.26 (commencing with Section 1798.91.04) is added to Part 4 of Division 3 of the Civil Code, to read:TITLE 1.81.26. Security of Connected Devices1798.91.04. (a) A manufacturer of a connected device shall equip the device with a reasonable security feature or features that are all of the following:(1) Appropriate to the nature and function of the device.(2) Appropriate to the information it may collect, contain, or transmit.(3) Designed to protect the device and any information contained therein from unauthorized access, destruction, use, modification, or disclosure.(b) Subject to all of the requirements of subdivision (a), if a connected device is equipped with a means for authentication outside a local area network, it shall be deemed a reasonable security feature under subdivision (a) if either of the following requirements are met:(1) The preprogrammed password is unique to each device manufactured.(2) The device contains a security feature that requires a user to generate a new means of authentication before access is granted to the device for the first time. 1798.91.05. For the purposes of this title, the following terms have the following meanings:(a) Authentication means a method of verifying the authority of a user, process, or device to access resources in an information system.(b) Connected device means any device, or other physical object that is capable of connecting to the Internet, directly or indirectly, and that is assigned an Internet Protocol address or Bluetooth address.(c) Manufacturer means the person who manufactures, or contracts with another person to manufacture on the persons behalf, connected devices that are sold or offered for sale in California. For the purposes of this subdivision, a contract with another person to manufacture on the persons behalf does not include a contract only to purchase a connected device, or only to purchase and brand a connected device.(d) Security feature means a feature of a device designed to provide security for that device.(e) Unauthorized access, destruction, use, modification, or disclosure means access, destruction, use, modification, or disclosure that is not authorized by the consumer. 1798.91.06. (a) This title shall not be construed to impose any duty upon the manufacturer of a connected device related to unaffiliated third-party software or applications that a user chooses to add to a connected device.(b) This title shall not be construed to impose any duty upon a provider of an electronic store, gateway, marketplace, or other means of purchasing or downloading software or applications, to review or enforce compliance with this title.(c) This title shall not be construed to impose any duty upon the manufacturer of a connected device to prevent a user from having full control over a connected device, including the ability to modify the software or firmware running on the device at the users discretion.(d) This title shall not apply to any connected device the functionality of which is subject to security requirements under federal law, regulations, or guidance promulgated by a federal agency pursuant to its regulatory enforcement authority.(e) This title shall not be construed to provide a basis for a private right of action. The Attorney General, a city attorney, a county counsel, or a district attorney shall have the exclusive authority to enforce this title.(f) The duties and obligations imposed by this title are cumulative with any other duties or obligations imposed under other law, and shall not be construed to relieve any party from any duties or obligations imposed under other law.(g) This title shall not be construed to limit the authority of a law enforcement agency to obtain connected device information from a manufacturer as authorized by law or pursuant to an order of a court of competent jurisdiction.(h) A covered entity, provider of health care, business associate, health care service plan, contractor, employer, or any other person subject to the federal Health Insurance Portability and Accountability Act of 1996 (HIPAA) (Public Law 104-191) or the Confidentiality of Medical Information Act (Part 2.6 (commencing with Section 56) of Division 1) shall not be subject to this title with respect to any activity regulated by those acts.(i) This title shall become operative on January 1, 2020.SEC. 2. This act shall become operative only if Assembly Bill 1906 of the 201718 Regular Session is also enacted and becomes effective.
22
3- Senate Bill No. 327 CHAPTER 886 An act to add Title 1.81.26 (commencing with Section 1798.91.04) to Part 4 of Division 3 of the Civil Code, relating to information privacy. [ Approved by Governor September 28, 2018. Filed with Secretary of State September 28, 2018. ] LEGISLATIVE COUNSEL'S DIGESTSB 327, Jackson. Information privacy: connected devices.Existing law requires a business to take all reasonable steps to dispose of customer records within its custody or control containing personal information when the records are no longer to be retained by the business by shredding, erasing, or otherwise modifying the personal information in those records to make it unreadable or undecipherable. Existing law also requires a business that owns, licenses, or maintains personal information about a California resident to implement and maintain reasonable security procedures and practices appropriate to the nature of the information, to protect the personal information from unauthorized access, destruction, use, modification, or disclosure. Existing law authorizes a customer injured by a violation of these provisions to institute a civil action to recover damages.This bill, beginning on January 1, 2020, would require a manufacturer of a connected device, as those terms are defined, to equip the device with a reasonable security feature or features that are appropriate to the nature and function of the device, appropriate to the information it may collect, contain, or transmit, and designed to protect the device and any information contained therein from unauthorized access, destruction, use, modification, or disclosure, as specified.This bill would become operative only if AB 1906 of the 201718 Regular Session is enacted and becomes effective.Digest Key Vote: MAJORITY Appropriation: NO Fiscal Committee: YES Local Program: NO
3+ Enrolled September 04, 2018 Passed IN Senate August 29, 2018 Passed IN Assembly August 28, 2018 Amended IN Assembly August 24, 2018 Amended IN Assembly August 06, 2018 Amended IN Senate January 11, 2018 Amended IN Senate May 26, 2017 Amended IN Senate May 17, 2017 Amended IN Senate March 20, 2017 CALIFORNIA LEGISLATURE 20172018 REGULAR SESSION Senate Bill No. 327Introduced by Senator Jackson(Principal coauthor: Assembly Member Irwin)February 13, 2017 An act to add Title 1.81.26 (commencing with Section 1798.91.04) to Part 4 of Division 3 of the Civil Code, relating to information privacy. LEGISLATIVE COUNSEL'S DIGESTSB 327, Jackson. Information privacy: connected devices.Existing law requires a business to take all reasonable steps to dispose of customer records within its custody or control containing personal information when the records are no longer to be retained by the business by shredding, erasing, or otherwise modifying the personal information in those records to make it unreadable or undecipherable. Existing law also requires a business that owns, licenses, or maintains personal information about a California resident to implement and maintain reasonable security procedures and practices appropriate to the nature of the information, to protect the personal information from unauthorized access, destruction, use, modification, or disclosure. Existing law authorizes a customer injured by a violation of these provisions to institute a civil action to recover damages.This bill, beginning on January 1, 2020, would require a manufacturer of a connected device, as those terms are defined, to equip the device with a reasonable security feature or features that are appropriate to the nature and function of the device, appropriate to the information it may collect, contain, or transmit, and designed to protect the device and any information contained therein from unauthorized access, destruction, use, modification, or disclosure, as specified.This bill would become operative only if AB 1906 of the 201718 Regular Session is enacted and becomes effective.Digest Key Vote: MAJORITY Appropriation: NO Fiscal Committee: YES Local Program: NO
4+
5+ Enrolled September 04, 2018 Passed IN Senate August 29, 2018 Passed IN Assembly August 28, 2018 Amended IN Assembly August 24, 2018 Amended IN Assembly August 06, 2018 Amended IN Senate January 11, 2018 Amended IN Senate May 26, 2017 Amended IN Senate May 17, 2017 Amended IN Senate March 20, 2017
6+
7+Enrolled September 04, 2018
8+Passed IN Senate August 29, 2018
9+Passed IN Assembly August 28, 2018
10+Amended IN Assembly August 24, 2018
11+Amended IN Assembly August 06, 2018
12+Amended IN Senate January 11, 2018
13+Amended IN Senate May 26, 2017
14+Amended IN Senate May 17, 2017
15+Amended IN Senate March 20, 2017
16+
17+ CALIFORNIA LEGISLATURE 20172018 REGULAR SESSION
418
519 Senate Bill No. 327
6-CHAPTER 886
20+
21+Introduced by Senator Jackson(Principal coauthor: Assembly Member Irwin)February 13, 2017
22+
23+Introduced by Senator Jackson(Principal coauthor: Assembly Member Irwin)
24+February 13, 2017
725
826 An act to add Title 1.81.26 (commencing with Section 1798.91.04) to Part 4 of Division 3 of the Civil Code, relating to information privacy.
9-
10- [ Approved by Governor September 28, 2018. Filed with Secretary of State September 28, 2018. ]
1127
1228 LEGISLATIVE COUNSEL'S DIGEST
1329
1430 ## LEGISLATIVE COUNSEL'S DIGEST
1531
1632 SB 327, Jackson. Information privacy: connected devices.
1733
1834 Existing law requires a business to take all reasonable steps to dispose of customer records within its custody or control containing personal information when the records are no longer to be retained by the business by shredding, erasing, or otherwise modifying the personal information in those records to make it unreadable or undecipherable. Existing law also requires a business that owns, licenses, or maintains personal information about a California resident to implement and maintain reasonable security procedures and practices appropriate to the nature of the information, to protect the personal information from unauthorized access, destruction, use, modification, or disclosure. Existing law authorizes a customer injured by a violation of these provisions to institute a civil action to recover damages.This bill, beginning on January 1, 2020, would require a manufacturer of a connected device, as those terms are defined, to equip the device with a reasonable security feature or features that are appropriate to the nature and function of the device, appropriate to the information it may collect, contain, or transmit, and designed to protect the device and any information contained therein from unauthorized access, destruction, use, modification, or disclosure, as specified.This bill would become operative only if AB 1906 of the 201718 Regular Session is enacted and becomes effective.
1935
2036 Existing law requires a business to take all reasonable steps to dispose of customer records within its custody or control containing personal information when the records are no longer to be retained by the business by shredding, erasing, or otherwise modifying the personal information in those records to make it unreadable or undecipherable. Existing law also requires a business that owns, licenses, or maintains personal information about a California resident to implement and maintain reasonable security procedures and practices appropriate to the nature of the information, to protect the personal information from unauthorized access, destruction, use, modification, or disclosure. Existing law authorizes a customer injured by a violation of these provisions to institute a civil action to recover damages.
2137
2238 This bill, beginning on January 1, 2020, would require a manufacturer of a connected device, as those terms are defined, to equip the device with a reasonable security feature or features that are appropriate to the nature and function of the device, appropriate to the information it may collect, contain, or transmit, and designed to protect the device and any information contained therein from unauthorized access, destruction, use, modification, or disclosure, as specified.
2339
2440 This bill would become operative only if AB 1906 of the 201718 Regular Session is enacted and becomes effective.
2541
2642 ## Digest Key
2743
2844 ## Bill Text
2945
3046 The people of the State of California do enact as follows:SECTION 1. Title 1.81.26 (commencing with Section 1798.91.04) is added to Part 4 of Division 3 of the Civil Code, to read:TITLE 1.81.26. Security of Connected Devices1798.91.04. (a) A manufacturer of a connected device shall equip the device with a reasonable security feature or features that are all of the following:(1) Appropriate to the nature and function of the device.(2) Appropriate to the information it may collect, contain, or transmit.(3) Designed to protect the device and any information contained therein from unauthorized access, destruction, use, modification, or disclosure.(b) Subject to all of the requirements of subdivision (a), if a connected device is equipped with a means for authentication outside a local area network, it shall be deemed a reasonable security feature under subdivision (a) if either of the following requirements are met:(1) The preprogrammed password is unique to each device manufactured.(2) The device contains a security feature that requires a user to generate a new means of authentication before access is granted to the device for the first time. 1798.91.05. For the purposes of this title, the following terms have the following meanings:(a) Authentication means a method of verifying the authority of a user, process, or device to access resources in an information system.(b) Connected device means any device, or other physical object that is capable of connecting to the Internet, directly or indirectly, and that is assigned an Internet Protocol address or Bluetooth address.(c) Manufacturer means the person who manufactures, or contracts with another person to manufacture on the persons behalf, connected devices that are sold or offered for sale in California. For the purposes of this subdivision, a contract with another person to manufacture on the persons behalf does not include a contract only to purchase a connected device, or only to purchase and brand a connected device.(d) Security feature means a feature of a device designed to provide security for that device.(e) Unauthorized access, destruction, use, modification, or disclosure means access, destruction, use, modification, or disclosure that is not authorized by the consumer. 1798.91.06. (a) This title shall not be construed to impose any duty upon the manufacturer of a connected device related to unaffiliated third-party software or applications that a user chooses to add to a connected device.(b) This title shall not be construed to impose any duty upon a provider of an electronic store, gateway, marketplace, or other means of purchasing or downloading software or applications, to review or enforce compliance with this title.(c) This title shall not be construed to impose any duty upon the manufacturer of a connected device to prevent a user from having full control over a connected device, including the ability to modify the software or firmware running on the device at the users discretion.(d) This title shall not apply to any connected device the functionality of which is subject to security requirements under federal law, regulations, or guidance promulgated by a federal agency pursuant to its regulatory enforcement authority.(e) This title shall not be construed to provide a basis for a private right of action. The Attorney General, a city attorney, a county counsel, or a district attorney shall have the exclusive authority to enforce this title.(f) The duties and obligations imposed by this title are cumulative with any other duties or obligations imposed under other law, and shall not be construed to relieve any party from any duties or obligations imposed under other law.(g) This title shall not be construed to limit the authority of a law enforcement agency to obtain connected device information from a manufacturer as authorized by law or pursuant to an order of a court of competent jurisdiction.(h) A covered entity, provider of health care, business associate, health care service plan, contractor, employer, or any other person subject to the federal Health Insurance Portability and Accountability Act of 1996 (HIPAA) (Public Law 104-191) or the Confidentiality of Medical Information Act (Part 2.6 (commencing with Section 56) of Division 1) shall not be subject to this title with respect to any activity regulated by those acts.(i) This title shall become operative on January 1, 2020.SEC. 2. This act shall become operative only if Assembly Bill 1906 of the 201718 Regular Session is also enacted and becomes effective.
3147
3248 The people of the State of California do enact as follows:
3349
3450 ## The people of the State of California do enact as follows:
3551
3652 SECTION 1. Title 1.81.26 (commencing with Section 1798.91.04) is added to Part 4 of Division 3 of the Civil Code, to read:TITLE 1.81.26. Security of Connected Devices1798.91.04. (a) A manufacturer of a connected device shall equip the device with a reasonable security feature or features that are all of the following:(1) Appropriate to the nature and function of the device.(2) Appropriate to the information it may collect, contain, or transmit.(3) Designed to protect the device and any information contained therein from unauthorized access, destruction, use, modification, or disclosure.(b) Subject to all of the requirements of subdivision (a), if a connected device is equipped with a means for authentication outside a local area network, it shall be deemed a reasonable security feature under subdivision (a) if either of the following requirements are met:(1) The preprogrammed password is unique to each device manufactured.(2) The device contains a security feature that requires a user to generate a new means of authentication before access is granted to the device for the first time. 1798.91.05. For the purposes of this title, the following terms have the following meanings:(a) Authentication means a method of verifying the authority of a user, process, or device to access resources in an information system.(b) Connected device means any device, or other physical object that is capable of connecting to the Internet, directly or indirectly, and that is assigned an Internet Protocol address or Bluetooth address.(c) Manufacturer means the person who manufactures, or contracts with another person to manufacture on the persons behalf, connected devices that are sold or offered for sale in California. For the purposes of this subdivision, a contract with another person to manufacture on the persons behalf does not include a contract only to purchase a connected device, or only to purchase and brand a connected device.(d) Security feature means a feature of a device designed to provide security for that device.(e) Unauthorized access, destruction, use, modification, or disclosure means access, destruction, use, modification, or disclosure that is not authorized by the consumer. 1798.91.06. (a) This title shall not be construed to impose any duty upon the manufacturer of a connected device related to unaffiliated third-party software or applications that a user chooses to add to a connected device.(b) This title shall not be construed to impose any duty upon a provider of an electronic store, gateway, marketplace, or other means of purchasing or downloading software or applications, to review or enforce compliance with this title.(c) This title shall not be construed to impose any duty upon the manufacturer of a connected device to prevent a user from having full control over a connected device, including the ability to modify the software or firmware running on the device at the users discretion.(d) This title shall not apply to any connected device the functionality of which is subject to security requirements under federal law, regulations, or guidance promulgated by a federal agency pursuant to its regulatory enforcement authority.(e) This title shall not be construed to provide a basis for a private right of action. The Attorney General, a city attorney, a county counsel, or a district attorney shall have the exclusive authority to enforce this title.(f) The duties and obligations imposed by this title are cumulative with any other duties or obligations imposed under other law, and shall not be construed to relieve any party from any duties or obligations imposed under other law.(g) This title shall not be construed to limit the authority of a law enforcement agency to obtain connected device information from a manufacturer as authorized by law or pursuant to an order of a court of competent jurisdiction.(h) A covered entity, provider of health care, business associate, health care service plan, contractor, employer, or any other person subject to the federal Health Insurance Portability and Accountability Act of 1996 (HIPAA) (Public Law 104-191) or the Confidentiality of Medical Information Act (Part 2.6 (commencing with Section 56) of Division 1) shall not be subject to this title with respect to any activity regulated by those acts.(i) This title shall become operative on January 1, 2020.
3753
3854 SECTION 1. Title 1.81.26 (commencing with Section 1798.91.04) is added to Part 4 of Division 3 of the Civil Code, to read:
3955
4056 ### SECTION 1.
4157
4258 TITLE 1.81.26. Security of Connected Devices1798.91.04. (a) A manufacturer of a connected device shall equip the device with a reasonable security feature or features that are all of the following:(1) Appropriate to the nature and function of the device.(2) Appropriate to the information it may collect, contain, or transmit.(3) Designed to protect the device and any information contained therein from unauthorized access, destruction, use, modification, or disclosure.(b) Subject to all of the requirements of subdivision (a), if a connected device is equipped with a means for authentication outside a local area network, it shall be deemed a reasonable security feature under subdivision (a) if either of the following requirements are met:(1) The preprogrammed password is unique to each device manufactured.(2) The device contains a security feature that requires a user to generate a new means of authentication before access is granted to the device for the first time. 1798.91.05. For the purposes of this title, the following terms have the following meanings:(a) Authentication means a method of verifying the authority of a user, process, or device to access resources in an information system.(b) Connected device means any device, or other physical object that is capable of connecting to the Internet, directly or indirectly, and that is assigned an Internet Protocol address or Bluetooth address.(c) Manufacturer means the person who manufactures, or contracts with another person to manufacture on the persons behalf, connected devices that are sold or offered for sale in California. For the purposes of this subdivision, a contract with another person to manufacture on the persons behalf does not include a contract only to purchase a connected device, or only to purchase and brand a connected device.(d) Security feature means a feature of a device designed to provide security for that device.(e) Unauthorized access, destruction, use, modification, or disclosure means access, destruction, use, modification, or disclosure that is not authorized by the consumer. 1798.91.06. (a) This title shall not be construed to impose any duty upon the manufacturer of a connected device related to unaffiliated third-party software or applications that a user chooses to add to a connected device.(b) This title shall not be construed to impose any duty upon a provider of an electronic store, gateway, marketplace, or other means of purchasing or downloading software or applications, to review or enforce compliance with this title.(c) This title shall not be construed to impose any duty upon the manufacturer of a connected device to prevent a user from having full control over a connected device, including the ability to modify the software or firmware running on the device at the users discretion.(d) This title shall not apply to any connected device the functionality of which is subject to security requirements under federal law, regulations, or guidance promulgated by a federal agency pursuant to its regulatory enforcement authority.(e) This title shall not be construed to provide a basis for a private right of action. The Attorney General, a city attorney, a county counsel, or a district attorney shall have the exclusive authority to enforce this title.(f) The duties and obligations imposed by this title are cumulative with any other duties or obligations imposed under other law, and shall not be construed to relieve any party from any duties or obligations imposed under other law.(g) This title shall not be construed to limit the authority of a law enforcement agency to obtain connected device information from a manufacturer as authorized by law or pursuant to an order of a court of competent jurisdiction.(h) A covered entity, provider of health care, business associate, health care service plan, contractor, employer, or any other person subject to the federal Health Insurance Portability and Accountability Act of 1996 (HIPAA) (Public Law 104-191) or the Confidentiality of Medical Information Act (Part 2.6 (commencing with Section 56) of Division 1) shall not be subject to this title with respect to any activity regulated by those acts.(i) This title shall become operative on January 1, 2020.
4359
4460 TITLE 1.81.26. Security of Connected Devices1798.91.04. (a) A manufacturer of a connected device shall equip the device with a reasonable security feature or features that are all of the following:(1) Appropriate to the nature and function of the device.(2) Appropriate to the information it may collect, contain, or transmit.(3) Designed to protect the device and any information contained therein from unauthorized access, destruction, use, modification, or disclosure.(b) Subject to all of the requirements of subdivision (a), if a connected device is equipped with a means for authentication outside a local area network, it shall be deemed a reasonable security feature under subdivision (a) if either of the following requirements are met:(1) The preprogrammed password is unique to each device manufactured.(2) The device contains a security feature that requires a user to generate a new means of authentication before access is granted to the device for the first time. 1798.91.05. For the purposes of this title, the following terms have the following meanings:(a) Authentication means a method of verifying the authority of a user, process, or device to access resources in an information system.(b) Connected device means any device, or other physical object that is capable of connecting to the Internet, directly or indirectly, and that is assigned an Internet Protocol address or Bluetooth address.(c) Manufacturer means the person who manufactures, or contracts with another person to manufacture on the persons behalf, connected devices that are sold or offered for sale in California. For the purposes of this subdivision, a contract with another person to manufacture on the persons behalf does not include a contract only to purchase a connected device, or only to purchase and brand a connected device.(d) Security feature means a feature of a device designed to provide security for that device.(e) Unauthorized access, destruction, use, modification, or disclosure means access, destruction, use, modification, or disclosure that is not authorized by the consumer. 1798.91.06. (a) This title shall not be construed to impose any duty upon the manufacturer of a connected device related to unaffiliated third-party software or applications that a user chooses to add to a connected device.(b) This title shall not be construed to impose any duty upon a provider of an electronic store, gateway, marketplace, or other means of purchasing or downloading software or applications, to review or enforce compliance with this title.(c) This title shall not be construed to impose any duty upon the manufacturer of a connected device to prevent a user from having full control over a connected device, including the ability to modify the software or firmware running on the device at the users discretion.(d) This title shall not apply to any connected device the functionality of which is subject to security requirements under federal law, regulations, or guidance promulgated by a federal agency pursuant to its regulatory enforcement authority.(e) This title shall not be construed to provide a basis for a private right of action. The Attorney General, a city attorney, a county counsel, or a district attorney shall have the exclusive authority to enforce this title.(f) The duties and obligations imposed by this title are cumulative with any other duties or obligations imposed under other law, and shall not be construed to relieve any party from any duties or obligations imposed under other law.(g) This title shall not be construed to limit the authority of a law enforcement agency to obtain connected device information from a manufacturer as authorized by law or pursuant to an order of a court of competent jurisdiction.(h) A covered entity, provider of health care, business associate, health care service plan, contractor, employer, or any other person subject to the federal Health Insurance Portability and Accountability Act of 1996 (HIPAA) (Public Law 104-191) or the Confidentiality of Medical Information Act (Part 2.6 (commencing with Section 56) of Division 1) shall not be subject to this title with respect to any activity regulated by those acts.(i) This title shall become operative on January 1, 2020.
4561
4662 TITLE 1.81.26. Security of Connected Devices
4763
4864 TITLE 1.81.26. Security of Connected Devices
4965
5066 1798.91.04. (a) A manufacturer of a connected device shall equip the device with a reasonable security feature or features that are all of the following:(1) Appropriate to the nature and function of the device.(2) Appropriate to the information it may collect, contain, or transmit.(3) Designed to protect the device and any information contained therein from unauthorized access, destruction, use, modification, or disclosure.(b) Subject to all of the requirements of subdivision (a), if a connected device is equipped with a means for authentication outside a local area network, it shall be deemed a reasonable security feature under subdivision (a) if either of the following requirements are met:(1) The preprogrammed password is unique to each device manufactured.(2) The device contains a security feature that requires a user to generate a new means of authentication before access is granted to the device for the first time.
5167
5268
5369
5470 1798.91.04. (a) A manufacturer of a connected device shall equip the device with a reasonable security feature or features that are all of the following:
5571
5672 (1) Appropriate to the nature and function of the device.
5773
5874 (2) Appropriate to the information it may collect, contain, or transmit.
5975
6076 (3) Designed to protect the device and any information contained therein from unauthorized access, destruction, use, modification, or disclosure.
6177
6278 (b) Subject to all of the requirements of subdivision (a), if a connected device is equipped with a means for authentication outside a local area network, it shall be deemed a reasonable security feature under subdivision (a) if either of the following requirements are met:
6379
6480 (1) The preprogrammed password is unique to each device manufactured.
6581
6682 (2) The device contains a security feature that requires a user to generate a new means of authentication before access is granted to the device for the first time.
6783
6884 1798.91.05. For the purposes of this title, the following terms have the following meanings:(a) Authentication means a method of verifying the authority of a user, process, or device to access resources in an information system.(b) Connected device means any device, or other physical object that is capable of connecting to the Internet, directly or indirectly, and that is assigned an Internet Protocol address or Bluetooth address.(c) Manufacturer means the person who manufactures, or contracts with another person to manufacture on the persons behalf, connected devices that are sold or offered for sale in California. For the purposes of this subdivision, a contract with another person to manufacture on the persons behalf does not include a contract only to purchase a connected device, or only to purchase and brand a connected device.(d) Security feature means a feature of a device designed to provide security for that device.(e) Unauthorized access, destruction, use, modification, or disclosure means access, destruction, use, modification, or disclosure that is not authorized by the consumer.
6985
7086
7187
7288 1798.91.05. For the purposes of this title, the following terms have the following meanings:
7389
7490 (a) Authentication means a method of verifying the authority of a user, process, or device to access resources in an information system.
7591
7692 (b) Connected device means any device, or other physical object that is capable of connecting to the Internet, directly or indirectly, and that is assigned an Internet Protocol address or Bluetooth address.
7793
7894 (c) Manufacturer means the person who manufactures, or contracts with another person to manufacture on the persons behalf, connected devices that are sold or offered for sale in California. For the purposes of this subdivision, a contract with another person to manufacture on the persons behalf does not include a contract only to purchase a connected device, or only to purchase and brand a connected device.
7995
8096 (d) Security feature means a feature of a device designed to provide security for that device.
8197
8298 (e) Unauthorized access, destruction, use, modification, or disclosure means access, destruction, use, modification, or disclosure that is not authorized by the consumer.
8399
84100 1798.91.06. (a) This title shall not be construed to impose any duty upon the manufacturer of a connected device related to unaffiliated third-party software or applications that a user chooses to add to a connected device.(b) This title shall not be construed to impose any duty upon a provider of an electronic store, gateway, marketplace, or other means of purchasing or downloading software or applications, to review or enforce compliance with this title.(c) This title shall not be construed to impose any duty upon the manufacturer of a connected device to prevent a user from having full control over a connected device, including the ability to modify the software or firmware running on the device at the users discretion.(d) This title shall not apply to any connected device the functionality of which is subject to security requirements under federal law, regulations, or guidance promulgated by a federal agency pursuant to its regulatory enforcement authority.(e) This title shall not be construed to provide a basis for a private right of action. The Attorney General, a city attorney, a county counsel, or a district attorney shall have the exclusive authority to enforce this title.(f) The duties and obligations imposed by this title are cumulative with any other duties or obligations imposed under other law, and shall not be construed to relieve any party from any duties or obligations imposed under other law.(g) This title shall not be construed to limit the authority of a law enforcement agency to obtain connected device information from a manufacturer as authorized by law or pursuant to an order of a court of competent jurisdiction.(h) A covered entity, provider of health care, business associate, health care service plan, contractor, employer, or any other person subject to the federal Health Insurance Portability and Accountability Act of 1996 (HIPAA) (Public Law 104-191) or the Confidentiality of Medical Information Act (Part 2.6 (commencing with Section 56) of Division 1) shall not be subject to this title with respect to any activity regulated by those acts.(i) This title shall become operative on January 1, 2020.
85101
86102
87103
88104 1798.91.06. (a) This title shall not be construed to impose any duty upon the manufacturer of a connected device related to unaffiliated third-party software or applications that a user chooses to add to a connected device.
89105
90106 (b) This title shall not be construed to impose any duty upon a provider of an electronic store, gateway, marketplace, or other means of purchasing or downloading software or applications, to review or enforce compliance with this title.
91107
92108 (c) This title shall not be construed to impose any duty upon the manufacturer of a connected device to prevent a user from having full control over a connected device, including the ability to modify the software or firmware running on the device at the users discretion.
93109
94110 (d) This title shall not apply to any connected device the functionality of which is subject to security requirements under federal law, regulations, or guidance promulgated by a federal agency pursuant to its regulatory enforcement authority.
95111
96112 (e) This title shall not be construed to provide a basis for a private right of action. The Attorney General, a city attorney, a county counsel, or a district attorney shall have the exclusive authority to enforce this title.
97113
98114 (f) The duties and obligations imposed by this title are cumulative with any other duties or obligations imposed under other law, and shall not be construed to relieve any party from any duties or obligations imposed under other law.
99115
100116 (g) This title shall not be construed to limit the authority of a law enforcement agency to obtain connected device information from a manufacturer as authorized by law or pursuant to an order of a court of competent jurisdiction.
101117
102118 (h) A covered entity, provider of health care, business associate, health care service plan, contractor, employer, or any other person subject to the federal Health Insurance Portability and Accountability Act of 1996 (HIPAA) (Public Law 104-191) or the Confidentiality of Medical Information Act (Part 2.6 (commencing with Section 56) of Division 1) shall not be subject to this title with respect to any activity regulated by those acts.
103119
104120 (i) This title shall become operative on January 1, 2020.
105121
106122 SEC. 2. This act shall become operative only if Assembly Bill 1906 of the 201718 Regular Session is also enacted and becomes effective.
107123
108124 SEC. 2. This act shall become operative only if Assembly Bill 1906 of the 201718 Regular Session is also enacted and becomes effective.
109125
110126 SEC. 2. This act shall become operative only if Assembly Bill 1906 of the 201718 Regular Session is also enacted and becomes effective.
111127
112128 ### SEC. 2.