California 2025-2026 Regular Session

California Assembly Bill AB364 Compare Versions

OldNewDifferences
1-Amended IN Assembly March 24, 2025 Amended IN Assembly March 13, 2025 CALIFORNIA LEGISLATURE 20252026 REGULAR SESSION Assembly Bill No. 364Introduced by Assembly Member DeMaioFebruary 03, 2025 An act to amend Section 1798.100 of, and to add Section 1798.122 to, the Civil Code, relating to privacy.LEGISLATIVE COUNSEL'S DIGESTAB 364, as amended, DeMaio. Personal information: maintenance. The California Consumer Privacy Act of 2018 (CCPA) grants to a consumer various rights with respect to personal information, as defined, that is collected by a business, as defined, including the right to direct a business that sells or shares personal information about the consumer to third parties not to sell or share the consumers personal information, as specified. The CCPA requires a business that controls the collection of a consumers personal information to, at or before the point of collection, inform a consumer of, among other things, the categories of personal information to be collected, the purposes for which the categories of personal information are collected or used, and whether that information is sold or shared. The California Privacy Rights Act of 2020, approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA and establishes the California Privacy Protection Agency and vests the agency with full administrative power, authority, and jurisdiction to enforce the CCPA.This bill would enact the Stop Foreign Governments from Accessing Californians Sensitive Personal Information Act which would additionally require a business to disclose to a consumer if the business intends to maintain the consumers personal information outside of the United States. The bill would prohibit a business from maintaining a consumers personal information outside of the United States unless, among other things, the consumer explicitly consented to the business maintaining the consumers personal information outside of the United States. The bill would also prohibit a business from maintaining personal information that is health care information, financial information, or geolocation data in the custody of a foreign government or a third party that is owned or controlled by a foreign government.This bill would declare that its provisions further the purposes and intent of the California Privacy Rights Act of 2020.Digest Key Vote: MAJORITY Appropriation: NO Fiscal Committee: YES Local Program: NO Bill TextThe people of the State of California do enact as follows:SECTION 1. This act shall be known, and may be cited, as the Stop Foreign Governments from Accessing Californians Sensitive Personal Information Act.SECTION 1.SEC. 2. Section 1798.100 of the Civil Code is amended to read:1798.100. General Duties of Businesses that Collect Personal Information(a) A business that controls the collection of a consumers personal information shall, at or before the point of collection, inform a consumer of all of the following:(1) The categories of personal information to be collected, the purposes for which the categories of personal information are collected or used, and whether that personal information is sold or shared. A business shall not collect additional categories of personal information or use personal information collected for additional purposes that are incompatible with the disclosed purpose for which the personal information was collected without providing the consumer with notice consistent with this section.(2) If the business collects sensitive personal information, the categories of sensitive personal information to be collected and the purposes for which the categories of sensitive personal information are collected or used, and whether that information is sold or shared. A business shall not collect additional categories of sensitive personal information or use sensitive personal information collected for additional purposes that are incompatible with the disclosed purpose for which the sensitive personal information was collected without providing the consumer with notice consistent with this section.(3) The length of time the business intends to retain each category of personal information, including sensitive personal information, or if that is not possible, the criteria used to determine that period provided that a business shall not retain a consumers personal information or sensitive personal information for each disclosed purpose for which the personal information was collected for longer than is reasonably necessary for that disclosed purpose.(4) If the business intends to maintain the consumers personal information outside of the United States.(b) A business that, acting as a third party, controls the collection of personal information about a consumer may satisfy its obligation under subdivision (a) by providing the required information prominently and conspicuously on the homepage home page of its internet website. In addition, if a business acting as a third party controls the collection of personal information about a consumer on its premises, including in a vehicle, then the business shall, at or before the point of collection, inform consumers as to the categories of personal information to be collected and the purposes for which the categories of personal information are used, and whether that personal information is sold, in a clear and conspicuous manner at the location.(c) A business collection, use, retention, and sharing of a consumers personal information shall be reasonably necessary and proportionate to achieve the purposes for which the personal information was collected or processed, or for another disclosed purpose that is compatible with the context in which the personal information was collected, and not further processed in a manner that is incompatible with those purposes.(d) A business that collects a consumers personal information and that sells that personal information to, or shares it with, a third party or that discloses it to a service provider or contractor for a business purpose shall enter into an agreement with the third party, service provider, or contractor, that:(1) Specifies that the personal information is sold or disclosed by the business only for limited and specified purposes.(2) Obligates the third party, service provider, or contractor to comply with applicable obligations under this title and obligate those persons to provide the same level of privacy protection as is required by this title.(3) Grants the business rights to take reasonable and appropriate steps to help ensure that the third party, service provider, or contractor uses the personal information transferred in a manner consistent with the business obligations under this title.(4) Requires the third party, service provider, or contractor to notify the business if it makes a determination that it can no longer meet its obligations under this title.(5) Grants the business the right, upon notice, including under paragraph (4), to take reasonable and appropriate steps to stop and remediate unauthorized use of personal information.(e) A business that collects a consumers personal information shall implement reasonable security procedures and practices appropriate to the nature of the personal information to protect the personal information from unauthorized or illegal access, destruction, use, modification, or disclosure in accordance with Section 1798.81.5.(f) Nothing in this section shall require a business to disclose trade secrets, as specified in regulations adopted pursuant to paragraph (3) of subdivision (a) of Section 1798.185.SEC. 2.SEC. 3. Section 1798.122 is added to the Civil Code, to read:1798.122. (a) A business shall not maintain a consumers personal information outside of the United States unless all of the following are true:(1) The business has informed the consumer of potential risks associated with the business maintaining the consumers personal information outside of the United States.(2) The consumer explicitly consented to the business maintaining the consumers personal information outside of the United States.(3) The personal information is not health care information, financial information, or geolocation data.(b) A business shall not maintain personal information that is health care information, financial information, or geolocation data in the custody of a foreign government or a third party that is owned or controlled by a foreign government.SEC. 3.SEC. 4. The Legislature finds and declares that this act furthers the purposes and intent of the California Privacy Rights Act of 2020.
1+Amended IN Assembly March 13, 2025 CALIFORNIA LEGISLATURE 20252026 REGULAR SESSION Assembly Bill No. 364Introduced by Assembly Member DeMaioFebruary 03, 2025 An act relating to social media platforms. to amend Section 1798.100 of, and to add Section 1798.122 to, the Civil Code, relating to privacy.LEGISLATIVE COUNSEL'S DIGESTAB 364, as amended, DeMaio. Privacy. Personal information: maintenance.Existing law generally regulates social media platforms, including, among other laws, the Protecting Our Kids from Social Media Addiction Act that prohibits an operator of an addictive internet-based service or application, including a social media platform, from providing an addictive feed, as defined, to a minor user, except as prescribed. The California Consumer Privacy Act of 2018 (CCPA) grants to a consumer various rights with respect to personal information, as defined, that is collected by a business, as defined. defined, including the right to direct a business that sells or shares personal information about the consumer to third parties not to sell or share the consumers personal information, as specified. The CCPA requires a business that controls the collection of a consumers personal information to, at or before the point of collection, inform a consumer of, among other things, the categories of personal information to be collected, the purposes for which the categories of personal information are collected or used, and whether that information is sold or shared. The California Privacy Rights Act of 2020, approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA and establishes the California Privacy Protection Agency and vests the agency with full administrative power, authority, and jurisdiction to enforce the CCPA.This bill would additionally require a business to disclose to a consumer if the business intends to maintain the consumers personal information outside of the United States. The bill would prohibit a business from maintaining a consumers personal information outside of the United States unless, among other things, the consumer explicitly consented to the business maintaining the consumers personal information outside of the United States. The bill would also prohibit a business from maintaining personal information that is health care information, financial information, or geolocation data in the custody of a foreign government or a third party that is owned or controlled by a foreign government.This bill would declare that its provisions further the purposes and intent of the California Privacy Rights Act of 2020.This bill would express the intent of the Legislature to enact legislation that would relate to regulating social media, ecommerce, privacy, and information technology.Digest Key Vote: MAJORITY Appropriation: NO Fiscal Committee: NOYES Local Program: NO Bill TextThe people of the State of California do enact as follows:SECTION 1. Section 1798.100 of the Civil Code is amended to read:1798.100. General Duties of Businesses that Collect Personal Information(a) A business that controls the collection of a consumers personal information shall, at or before the point of collection, inform consumers a consumer of all of the following:(1) The categories of personal information to be collected and collected, the purposes for which the categories of personal information are collected or used used, and whether that personal information is sold or shared. A business shall not collect additional categories of personal information or use personal information collected for additional purposes that are incompatible with the disclosed purpose for which the personal information was collected without providing the consumer with notice consistent with this section.(2) If the business collects sensitive personal information, the categories of sensitive personal information to be collected and the purposes for which the categories of sensitive personal information are collected or used, and whether that information is sold or shared. A business shall not collect additional categories of sensitive personal information or use sensitive personal information collected for additional purposes that are incompatible with the disclosed purpose for which the sensitive personal information was collected without providing the consumer with notice consistent with this section.(3) The length of time the business intends to retain each category of personal information, including sensitive personal information, or if that is not possible, the criteria used to determine that period provided that a business shall not retain a consumers personal information or sensitive personal information for each disclosed purpose for which the personal information was collected for longer than is reasonably necessary for that disclosed purpose.(4) If the business intends to maintain the consumers personal information outside of the United States.(b) A business that, acting as a third party, controls the collection of personal information about a consumer may satisfy its obligation under subdivision (a) by providing the required information prominently and conspicuously on the homepage of its internet website. In addition, if a business acting as a third party controls the collection of personal information about a consumer on its premises, including in a vehicle, then the business shall, at or before the point of collection, inform consumers as to the categories of personal information to be collected and the purposes for which the categories of personal information are used, and whether that personal information is sold, in a clear and conspicuous manner at the location.(c) A business collection, use, retention, and sharing of a consumers personal information shall be reasonably necessary and proportionate to achieve the purposes for which the personal information was collected or processed, or for another disclosed purpose that is compatible with the context in which the personal information was collected, and not further processed in a manner that is incompatible with those purposes.(d) A business that collects a consumers personal information and that sells that personal information to, or shares it with, a third party or that discloses it to a service provider or contractor for a business purpose shall enter into an agreement with the third party, service provider, or contractor, that:(1) Specifies that the personal information is sold or disclosed by the business only for limited and specified purposes.(2) Obligates the third party, service provider, or contractor to comply with applicable obligations under this title and obligate those persons to provide the same level of privacy protection as is required by this title.(3) Grants the business rights to take reasonable and appropriate steps to help ensure that the third party, service provider, or contractor uses the personal information transferred in a manner consistent with the business obligations under this title.(4) Requires the third party, service provider, or contractor to notify the business if it makes a determination that it can no longer meet its obligations under this title.(5) Grants the business the right, upon notice, including under paragraph (4), to take reasonable and appropriate steps to stop and remediate unauthorized use of personal information.(e) A business that collects a consumers personal information shall implement reasonable security procedures and practices appropriate to the nature of the personal information to protect the personal information from unauthorized or illegal access, destruction, use, modification, or disclosure in accordance with Section 1798.81.5.(f) Nothing in this section shall require a business to disclose trade secrets, as specified in regulations adopted pursuant to paragraph (3) of subdivision (a) of Section 1798.185.SEC. 2. Section 1798.122 is added to the Civil Code, to read:1798.122. (a) A business shall not maintain a consumers personal information outside of the United States unless all of the following are true:(1) The business has informed the consumer of potential risks associated with the business maintaining the consumers personal information outside of the United States.(2) The consumer explicitly consented to the business maintaining the consumers personal information outside of the United States.(3) The personal information is not health care information, financial information, or geolocation data.(b) A business shall not maintain personal information that is health care information, financial information, or geolocation data in the custody of a foreign government or a third party that is owned or controlled by a foreign government.SEC. 3. The Legislature finds and declares that this act furthers the purposes and intent of the California Privacy Rights Act of 2020.SECTION 1.It is the intent of the Legislature to enact legislation that would relate to regulating social media, ecommerce, privacy, and information technology.
22
3- Amended IN Assembly March 24, 2025 Amended IN Assembly March 13, 2025 CALIFORNIA LEGISLATURE 20252026 REGULAR SESSION Assembly Bill No. 364Introduced by Assembly Member DeMaioFebruary 03, 2025 An act to amend Section 1798.100 of, and to add Section 1798.122 to, the Civil Code, relating to privacy.LEGISLATIVE COUNSEL'S DIGESTAB 364, as amended, DeMaio. Personal information: maintenance. The California Consumer Privacy Act of 2018 (CCPA) grants to a consumer various rights with respect to personal information, as defined, that is collected by a business, as defined, including the right to direct a business that sells or shares personal information about the consumer to third parties not to sell or share the consumers personal information, as specified. The CCPA requires a business that controls the collection of a consumers personal information to, at or before the point of collection, inform a consumer of, among other things, the categories of personal information to be collected, the purposes for which the categories of personal information are collected or used, and whether that information is sold or shared. The California Privacy Rights Act of 2020, approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA and establishes the California Privacy Protection Agency and vests the agency with full administrative power, authority, and jurisdiction to enforce the CCPA.This bill would enact the Stop Foreign Governments from Accessing Californians Sensitive Personal Information Act which would additionally require a business to disclose to a consumer if the business intends to maintain the consumers personal information outside of the United States. The bill would prohibit a business from maintaining a consumers personal information outside of the United States unless, among other things, the consumer explicitly consented to the business maintaining the consumers personal information outside of the United States. The bill would also prohibit a business from maintaining personal information that is health care information, financial information, or geolocation data in the custody of a foreign government or a third party that is owned or controlled by a foreign government.This bill would declare that its provisions further the purposes and intent of the California Privacy Rights Act of 2020.Digest Key Vote: MAJORITY Appropriation: NO Fiscal Committee: YES Local Program: NO
3+ Amended IN Assembly March 13, 2025 CALIFORNIA LEGISLATURE 20252026 REGULAR SESSION Assembly Bill No. 364Introduced by Assembly Member DeMaioFebruary 03, 2025 An act relating to social media platforms. to amend Section 1798.100 of, and to add Section 1798.122 to, the Civil Code, relating to privacy.LEGISLATIVE COUNSEL'S DIGESTAB 364, as amended, DeMaio. Privacy. Personal information: maintenance.Existing law generally regulates social media platforms, including, among other laws, the Protecting Our Kids from Social Media Addiction Act that prohibits an operator of an addictive internet-based service or application, including a social media platform, from providing an addictive feed, as defined, to a minor user, except as prescribed. The California Consumer Privacy Act of 2018 (CCPA) grants to a consumer various rights with respect to personal information, as defined, that is collected by a business, as defined. defined, including the right to direct a business that sells or shares personal information about the consumer to third parties not to sell or share the consumers personal information, as specified. The CCPA requires a business that controls the collection of a consumers personal information to, at or before the point of collection, inform a consumer of, among other things, the categories of personal information to be collected, the purposes for which the categories of personal information are collected or used, and whether that information is sold or shared. The California Privacy Rights Act of 2020, approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA and establishes the California Privacy Protection Agency and vests the agency with full administrative power, authority, and jurisdiction to enforce the CCPA.This bill would additionally require a business to disclose to a consumer if the business intends to maintain the consumers personal information outside of the United States. The bill would prohibit a business from maintaining a consumers personal information outside of the United States unless, among other things, the consumer explicitly consented to the business maintaining the consumers personal information outside of the United States. The bill would also prohibit a business from maintaining personal information that is health care information, financial information, or geolocation data in the custody of a foreign government or a third party that is owned or controlled by a foreign government.This bill would declare that its provisions further the purposes and intent of the California Privacy Rights Act of 2020.This bill would express the intent of the Legislature to enact legislation that would relate to regulating social media, ecommerce, privacy, and information technology.Digest Key Vote: MAJORITY Appropriation: NO Fiscal Committee: NOYES Local Program: NO
44
5- Amended IN Assembly March 24, 2025 Amended IN Assembly March 13, 2025
5+ Amended IN Assembly March 13, 2025
66
7-Amended IN Assembly March 24, 2025
87 Amended IN Assembly March 13, 2025
98
109 CALIFORNIA LEGISLATURE 20252026 REGULAR SESSION
1110
1211 Assembly Bill
1312
1413 No. 364
1514
1615 Introduced by Assembly Member DeMaioFebruary 03, 2025
1716
1817 Introduced by Assembly Member DeMaio
1918 February 03, 2025
2019
21- An act to amend Section 1798.100 of, and to add Section 1798.122 to, the Civil Code, relating to privacy.
20+ An act relating to social media platforms. to amend Section 1798.100 of, and to add Section 1798.122 to, the Civil Code, relating to privacy.
2221
2322 LEGISLATIVE COUNSEL'S DIGEST
2423
2524 ## LEGISLATIVE COUNSEL'S DIGEST
2625
27-AB 364, as amended, DeMaio. Personal information: maintenance.
26+AB 364, as amended, DeMaio. Privacy. Personal information: maintenance.
2827
29- The California Consumer Privacy Act of 2018 (CCPA) grants to a consumer various rights with respect to personal information, as defined, that is collected by a business, as defined, including the right to direct a business that sells or shares personal information about the consumer to third parties not to sell or share the consumers personal information, as specified. The CCPA requires a business that controls the collection of a consumers personal information to, at or before the point of collection, inform a consumer of, among other things, the categories of personal information to be collected, the purposes for which the categories of personal information are collected or used, and whether that information is sold or shared. The California Privacy Rights Act of 2020, approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA and establishes the California Privacy Protection Agency and vests the agency with full administrative power, authority, and jurisdiction to enforce the CCPA.This bill would enact the Stop Foreign Governments from Accessing Californians Sensitive Personal Information Act which would additionally require a business to disclose to a consumer if the business intends to maintain the consumers personal information outside of the United States. The bill would prohibit a business from maintaining a consumers personal information outside of the United States unless, among other things, the consumer explicitly consented to the business maintaining the consumers personal information outside of the United States. The bill would also prohibit a business from maintaining personal information that is health care information, financial information, or geolocation data in the custody of a foreign government or a third party that is owned or controlled by a foreign government.This bill would declare that its provisions further the purposes and intent of the California Privacy Rights Act of 2020.
28+Existing law generally regulates social media platforms, including, among other laws, the Protecting Our Kids from Social Media Addiction Act that prohibits an operator of an addictive internet-based service or application, including a social media platform, from providing an addictive feed, as defined, to a minor user, except as prescribed. The California Consumer Privacy Act of 2018 (CCPA) grants to a consumer various rights with respect to personal information, as defined, that is collected by a business, as defined. defined, including the right to direct a business that sells or shares personal information about the consumer to third parties not to sell or share the consumers personal information, as specified. The CCPA requires a business that controls the collection of a consumers personal information to, at or before the point of collection, inform a consumer of, among other things, the categories of personal information to be collected, the purposes for which the categories of personal information are collected or used, and whether that information is sold or shared. The California Privacy Rights Act of 2020, approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA and establishes the California Privacy Protection Agency and vests the agency with full administrative power, authority, and jurisdiction to enforce the CCPA.This bill would additionally require a business to disclose to a consumer if the business intends to maintain the consumers personal information outside of the United States. The bill would prohibit a business from maintaining a consumers personal information outside of the United States unless, among other things, the consumer explicitly consented to the business maintaining the consumers personal information outside of the United States. The bill would also prohibit a business from maintaining personal information that is health care information, financial information, or geolocation data in the custody of a foreign government or a third party that is owned or controlled by a foreign government.This bill would declare that its provisions further the purposes and intent of the California Privacy Rights Act of 2020.This bill would express the intent of the Legislature to enact legislation that would relate to regulating social media, ecommerce, privacy, and information technology.
3029
31- The California Consumer Privacy Act of 2018 (CCPA) grants to a consumer various rights with respect to personal information, as defined, that is collected by a business, as defined, including the right to direct a business that sells or shares personal information about the consumer to third parties not to sell or share the consumers personal information, as specified. The CCPA requires a business that controls the collection of a consumers personal information to, at or before the point of collection, inform a consumer of, among other things, the categories of personal information to be collected, the purposes for which the categories of personal information are collected or used, and whether that information is sold or shared. The California Privacy Rights Act of 2020, approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA and establishes the California Privacy Protection Agency and vests the agency with full administrative power, authority, and jurisdiction to enforce the CCPA.
30+Existing law generally regulates social media platforms, including, among other laws, the Protecting Our Kids from Social Media Addiction Act that prohibits an operator of an addictive internet-based service or application, including a social media platform, from providing an addictive feed, as defined, to a minor user, except as prescribed.
3231
33-This bill would enact the Stop Foreign Governments from Accessing Californians Sensitive Personal Information Act which would additionally require a business to disclose to a consumer if the business intends to maintain the consumers personal information outside of the United States. The bill would prohibit a business from maintaining a consumers personal information outside of the United States unless, among other things, the consumer explicitly consented to the business maintaining the consumers personal information outside of the United States. The bill would also prohibit a business from maintaining personal information that is health care information, financial information, or geolocation data in the custody of a foreign government or a third party that is owned or controlled by a foreign government.
32+
33+
34+ The California Consumer Privacy Act of 2018 (CCPA) grants to a consumer various rights with respect to personal information, as defined, that is collected by a business, as defined. defined, including the right to direct a business that sells or shares personal information about the consumer to third parties not to sell or share the consumers personal information, as specified. The CCPA requires a business that controls the collection of a consumers personal information to, at or before the point of collection, inform a consumer of, among other things, the categories of personal information to be collected, the purposes for which the categories of personal information are collected or used, and whether that information is sold or shared. The California Privacy Rights Act of 2020, approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA and establishes the California Privacy Protection Agency and vests the agency with full administrative power, authority, and jurisdiction to enforce the CCPA.
35+
36+This bill would additionally require a business to disclose to a consumer if the business intends to maintain the consumers personal information outside of the United States. The bill would prohibit a business from maintaining a consumers personal information outside of the United States unless, among other things, the consumer explicitly consented to the business maintaining the consumers personal information outside of the United States. The bill would also prohibit a business from maintaining personal information that is health care information, financial information, or geolocation data in the custody of a foreign government or a third party that is owned or controlled by a foreign government.
3437
3538 This bill would declare that its provisions further the purposes and intent of the California Privacy Rights Act of 2020.
39+
40+This bill would express the intent of the Legislature to enact legislation that would relate to regulating social media, ecommerce, privacy, and information technology.
41+
42+
3643
3744 ## Digest Key
3845
3946 ## Bill Text
4047
41-The people of the State of California do enact as follows:SECTION 1. This act shall be known, and may be cited, as the Stop Foreign Governments from Accessing Californians Sensitive Personal Information Act.SECTION 1.SEC. 2. Section 1798.100 of the Civil Code is amended to read:1798.100. General Duties of Businesses that Collect Personal Information(a) A business that controls the collection of a consumers personal information shall, at or before the point of collection, inform a consumer of all of the following:(1) The categories of personal information to be collected, the purposes for which the categories of personal information are collected or used, and whether that personal information is sold or shared. A business shall not collect additional categories of personal information or use personal information collected for additional purposes that are incompatible with the disclosed purpose for which the personal information was collected without providing the consumer with notice consistent with this section.(2) If the business collects sensitive personal information, the categories of sensitive personal information to be collected and the purposes for which the categories of sensitive personal information are collected or used, and whether that information is sold or shared. A business shall not collect additional categories of sensitive personal information or use sensitive personal information collected for additional purposes that are incompatible with the disclosed purpose for which the sensitive personal information was collected without providing the consumer with notice consistent with this section.(3) The length of time the business intends to retain each category of personal information, including sensitive personal information, or if that is not possible, the criteria used to determine that period provided that a business shall not retain a consumers personal information or sensitive personal information for each disclosed purpose for which the personal information was collected for longer than is reasonably necessary for that disclosed purpose.(4) If the business intends to maintain the consumers personal information outside of the United States.(b) A business that, acting as a third party, controls the collection of personal information about a consumer may satisfy its obligation under subdivision (a) by providing the required information prominently and conspicuously on the homepage home page of its internet website. In addition, if a business acting as a third party controls the collection of personal information about a consumer on its premises, including in a vehicle, then the business shall, at or before the point of collection, inform consumers as to the categories of personal information to be collected and the purposes for which the categories of personal information are used, and whether that personal information is sold, in a clear and conspicuous manner at the location.(c) A business collection, use, retention, and sharing of a consumers personal information shall be reasonably necessary and proportionate to achieve the purposes for which the personal information was collected or processed, or for another disclosed purpose that is compatible with the context in which the personal information was collected, and not further processed in a manner that is incompatible with those purposes.(d) A business that collects a consumers personal information and that sells that personal information to, or shares it with, a third party or that discloses it to a service provider or contractor for a business purpose shall enter into an agreement with the third party, service provider, or contractor, that:(1) Specifies that the personal information is sold or disclosed by the business only for limited and specified purposes.(2) Obligates the third party, service provider, or contractor to comply with applicable obligations under this title and obligate those persons to provide the same level of privacy protection as is required by this title.(3) Grants the business rights to take reasonable and appropriate steps to help ensure that the third party, service provider, or contractor uses the personal information transferred in a manner consistent with the business obligations under this title.(4) Requires the third party, service provider, or contractor to notify the business if it makes a determination that it can no longer meet its obligations under this title.(5) Grants the business the right, upon notice, including under paragraph (4), to take reasonable and appropriate steps to stop and remediate unauthorized use of personal information.(e) A business that collects a consumers personal information shall implement reasonable security procedures and practices appropriate to the nature of the personal information to protect the personal information from unauthorized or illegal access, destruction, use, modification, or disclosure in accordance with Section 1798.81.5.(f) Nothing in this section shall require a business to disclose trade secrets, as specified in regulations adopted pursuant to paragraph (3) of subdivision (a) of Section 1798.185.SEC. 2.SEC. 3. Section 1798.122 is added to the Civil Code, to read:1798.122. (a) A business shall not maintain a consumers personal information outside of the United States unless all of the following are true:(1) The business has informed the consumer of potential risks associated with the business maintaining the consumers personal information outside of the United States.(2) The consumer explicitly consented to the business maintaining the consumers personal information outside of the United States.(3) The personal information is not health care information, financial information, or geolocation data.(b) A business shall not maintain personal information that is health care information, financial information, or geolocation data in the custody of a foreign government or a third party that is owned or controlled by a foreign government.SEC. 3.SEC. 4. The Legislature finds and declares that this act furthers the purposes and intent of the California Privacy Rights Act of 2020.
48+The people of the State of California do enact as follows:SECTION 1. Section 1798.100 of the Civil Code is amended to read:1798.100. General Duties of Businesses that Collect Personal Information(a) A business that controls the collection of a consumers personal information shall, at or before the point of collection, inform consumers a consumer of all of the following:(1) The categories of personal information to be collected and collected, the purposes for which the categories of personal information are collected or used used, and whether that personal information is sold or shared. A business shall not collect additional categories of personal information or use personal information collected for additional purposes that are incompatible with the disclosed purpose for which the personal information was collected without providing the consumer with notice consistent with this section.(2) If the business collects sensitive personal information, the categories of sensitive personal information to be collected and the purposes for which the categories of sensitive personal information are collected or used, and whether that information is sold or shared. A business shall not collect additional categories of sensitive personal information or use sensitive personal information collected for additional purposes that are incompatible with the disclosed purpose for which the sensitive personal information was collected without providing the consumer with notice consistent with this section.(3) The length of time the business intends to retain each category of personal information, including sensitive personal information, or if that is not possible, the criteria used to determine that period provided that a business shall not retain a consumers personal information or sensitive personal information for each disclosed purpose for which the personal information was collected for longer than is reasonably necessary for that disclosed purpose.(4) If the business intends to maintain the consumers personal information outside of the United States.(b) A business that, acting as a third party, controls the collection of personal information about a consumer may satisfy its obligation under subdivision (a) by providing the required information prominently and conspicuously on the homepage of its internet website. In addition, if a business acting as a third party controls the collection of personal information about a consumer on its premises, including in a vehicle, then the business shall, at or before the point of collection, inform consumers as to the categories of personal information to be collected and the purposes for which the categories of personal information are used, and whether that personal information is sold, in a clear and conspicuous manner at the location.(c) A business collection, use, retention, and sharing of a consumers personal information shall be reasonably necessary and proportionate to achieve the purposes for which the personal information was collected or processed, or for another disclosed purpose that is compatible with the context in which the personal information was collected, and not further processed in a manner that is incompatible with those purposes.(d) A business that collects a consumers personal information and that sells that personal information to, or shares it with, a third party or that discloses it to a service provider or contractor for a business purpose shall enter into an agreement with the third party, service provider, or contractor, that:(1) Specifies that the personal information is sold or disclosed by the business only for limited and specified purposes.(2) Obligates the third party, service provider, or contractor to comply with applicable obligations under this title and obligate those persons to provide the same level of privacy protection as is required by this title.(3) Grants the business rights to take reasonable and appropriate steps to help ensure that the third party, service provider, or contractor uses the personal information transferred in a manner consistent with the business obligations under this title.(4) Requires the third party, service provider, or contractor to notify the business if it makes a determination that it can no longer meet its obligations under this title.(5) Grants the business the right, upon notice, including under paragraph (4), to take reasonable and appropriate steps to stop and remediate unauthorized use of personal information.(e) A business that collects a consumers personal information shall implement reasonable security procedures and practices appropriate to the nature of the personal information to protect the personal information from unauthorized or illegal access, destruction, use, modification, or disclosure in accordance with Section 1798.81.5.(f) Nothing in this section shall require a business to disclose trade secrets, as specified in regulations adopted pursuant to paragraph (3) of subdivision (a) of Section 1798.185.SEC. 2. Section 1798.122 is added to the Civil Code, to read:1798.122. (a) A business shall not maintain a consumers personal information outside of the United States unless all of the following are true:(1) The business has informed the consumer of potential risks associated with the business maintaining the consumers personal information outside of the United States.(2) The consumer explicitly consented to the business maintaining the consumers personal information outside of the United States.(3) The personal information is not health care information, financial information, or geolocation data.(b) A business shall not maintain personal information that is health care information, financial information, or geolocation data in the custody of a foreign government or a third party that is owned or controlled by a foreign government.SEC. 3. The Legislature finds and declares that this act furthers the purposes and intent of the California Privacy Rights Act of 2020.SECTION 1.It is the intent of the Legislature to enact legislation that would relate to regulating social media, ecommerce, privacy, and information technology.
4249
4350 The people of the State of California do enact as follows:
4451
4552 ## The people of the State of California do enact as follows:
4653
47-SECTION 1. This act shall be known, and may be cited, as the Stop Foreign Governments from Accessing Californians Sensitive Personal Information Act.
54+SECTION 1. Section 1798.100 of the Civil Code is amended to read:1798.100. General Duties of Businesses that Collect Personal Information(a) A business that controls the collection of a consumers personal information shall, at or before the point of collection, inform consumers a consumer of all of the following:(1) The categories of personal information to be collected and collected, the purposes for which the categories of personal information are collected or used used, and whether that personal information is sold or shared. A business shall not collect additional categories of personal information or use personal information collected for additional purposes that are incompatible with the disclosed purpose for which the personal information was collected without providing the consumer with notice consistent with this section.(2) If the business collects sensitive personal information, the categories of sensitive personal information to be collected and the purposes for which the categories of sensitive personal information are collected or used, and whether that information is sold or shared. A business shall not collect additional categories of sensitive personal information or use sensitive personal information collected for additional purposes that are incompatible with the disclosed purpose for which the sensitive personal information was collected without providing the consumer with notice consistent with this section.(3) The length of time the business intends to retain each category of personal information, including sensitive personal information, or if that is not possible, the criteria used to determine that period provided that a business shall not retain a consumers personal information or sensitive personal information for each disclosed purpose for which the personal information was collected for longer than is reasonably necessary for that disclosed purpose.(4) If the business intends to maintain the consumers personal information outside of the United States.(b) A business that, acting as a third party, controls the collection of personal information about a consumer may satisfy its obligation under subdivision (a) by providing the required information prominently and conspicuously on the homepage of its internet website. In addition, if a business acting as a third party controls the collection of personal information about a consumer on its premises, including in a vehicle, then the business shall, at or before the point of collection, inform consumers as to the categories of personal information to be collected and the purposes for which the categories of personal information are used, and whether that personal information is sold, in a clear and conspicuous manner at the location.(c) A business collection, use, retention, and sharing of a consumers personal information shall be reasonably necessary and proportionate to achieve the purposes for which the personal information was collected or processed, or for another disclosed purpose that is compatible with the context in which the personal information was collected, and not further processed in a manner that is incompatible with those purposes.(d) A business that collects a consumers personal information and that sells that personal information to, or shares it with, a third party or that discloses it to a service provider or contractor for a business purpose shall enter into an agreement with the third party, service provider, or contractor, that:(1) Specifies that the personal information is sold or disclosed by the business only for limited and specified purposes.(2) Obligates the third party, service provider, or contractor to comply with applicable obligations under this title and obligate those persons to provide the same level of privacy protection as is required by this title.(3) Grants the business rights to take reasonable and appropriate steps to help ensure that the third party, service provider, or contractor uses the personal information transferred in a manner consistent with the business obligations under this title.(4) Requires the third party, service provider, or contractor to notify the business if it makes a determination that it can no longer meet its obligations under this title.(5) Grants the business the right, upon notice, including under paragraph (4), to take reasonable and appropriate steps to stop and remediate unauthorized use of personal information.(e) A business that collects a consumers personal information shall implement reasonable security procedures and practices appropriate to the nature of the personal information to protect the personal information from unauthorized or illegal access, destruction, use, modification, or disclosure in accordance with Section 1798.81.5.(f) Nothing in this section shall require a business to disclose trade secrets, as specified in regulations adopted pursuant to paragraph (3) of subdivision (a) of Section 1798.185.
4855
49-SECTION 1. This act shall be known, and may be cited, as the Stop Foreign Governments from Accessing Californians Sensitive Personal Information Act.
50-
51-SECTION 1. This act shall be known, and may be cited, as the Stop Foreign Governments from Accessing Californians Sensitive Personal Information Act.
56+SECTION 1. Section 1798.100 of the Civil Code is amended to read:
5257
5358 ### SECTION 1.
5459
55-SECTION 1.SEC. 2. Section 1798.100 of the Civil Code is amended to read:1798.100. General Duties of Businesses that Collect Personal Information(a) A business that controls the collection of a consumers personal information shall, at or before the point of collection, inform a consumer of all of the following:(1) The categories of personal information to be collected, the purposes for which the categories of personal information are collected or used, and whether that personal information is sold or shared. A business shall not collect additional categories of personal information or use personal information collected for additional purposes that are incompatible with the disclosed purpose for which the personal information was collected without providing the consumer with notice consistent with this section.(2) If the business collects sensitive personal information, the categories of sensitive personal information to be collected and the purposes for which the categories of sensitive personal information are collected or used, and whether that information is sold or shared. A business shall not collect additional categories of sensitive personal information or use sensitive personal information collected for additional purposes that are incompatible with the disclosed purpose for which the sensitive personal information was collected without providing the consumer with notice consistent with this section.(3) The length of time the business intends to retain each category of personal information, including sensitive personal information, or if that is not possible, the criteria used to determine that period provided that a business shall not retain a consumers personal information or sensitive personal information for each disclosed purpose for which the personal information was collected for longer than is reasonably necessary for that disclosed purpose.(4) If the business intends to maintain the consumers personal information outside of the United States.(b) A business that, acting as a third party, controls the collection of personal information about a consumer may satisfy its obligation under subdivision (a) by providing the required information prominently and conspicuously on the homepage home page of its internet website. In addition, if a business acting as a third party controls the collection of personal information about a consumer on its premises, including in a vehicle, then the business shall, at or before the point of collection, inform consumers as to the categories of personal information to be collected and the purposes for which the categories of personal information are used, and whether that personal information is sold, in a clear and conspicuous manner at the location.(c) A business collection, use, retention, and sharing of a consumers personal information shall be reasonably necessary and proportionate to achieve the purposes for which the personal information was collected or processed, or for another disclosed purpose that is compatible with the context in which the personal information was collected, and not further processed in a manner that is incompatible with those purposes.(d) A business that collects a consumers personal information and that sells that personal information to, or shares it with, a third party or that discloses it to a service provider or contractor for a business purpose shall enter into an agreement with the third party, service provider, or contractor, that:(1) Specifies that the personal information is sold or disclosed by the business only for limited and specified purposes.(2) Obligates the third party, service provider, or contractor to comply with applicable obligations under this title and obligate those persons to provide the same level of privacy protection as is required by this title.(3) Grants the business rights to take reasonable and appropriate steps to help ensure that the third party, service provider, or contractor uses the personal information transferred in a manner consistent with the business obligations under this title.(4) Requires the third party, service provider, or contractor to notify the business if it makes a determination that it can no longer meet its obligations under this title.(5) Grants the business the right, upon notice, including under paragraph (4), to take reasonable and appropriate steps to stop and remediate unauthorized use of personal information.(e) A business that collects a consumers personal information shall implement reasonable security procedures and practices appropriate to the nature of the personal information to protect the personal information from unauthorized or illegal access, destruction, use, modification, or disclosure in accordance with Section 1798.81.5.(f) Nothing in this section shall require a business to disclose trade secrets, as specified in regulations adopted pursuant to paragraph (3) of subdivision (a) of Section 1798.185.
60+1798.100. General Duties of Businesses that Collect Personal Information(a) A business that controls the collection of a consumers personal information shall, at or before the point of collection, inform consumers a consumer of all of the following:(1) The categories of personal information to be collected and collected, the purposes for which the categories of personal information are collected or used used, and whether that personal information is sold or shared. A business shall not collect additional categories of personal information or use personal information collected for additional purposes that are incompatible with the disclosed purpose for which the personal information was collected without providing the consumer with notice consistent with this section.(2) If the business collects sensitive personal information, the categories of sensitive personal information to be collected and the purposes for which the categories of sensitive personal information are collected or used, and whether that information is sold or shared. A business shall not collect additional categories of sensitive personal information or use sensitive personal information collected for additional purposes that are incompatible with the disclosed purpose for which the sensitive personal information was collected without providing the consumer with notice consistent with this section.(3) The length of time the business intends to retain each category of personal information, including sensitive personal information, or if that is not possible, the criteria used to determine that period provided that a business shall not retain a consumers personal information or sensitive personal information for each disclosed purpose for which the personal information was collected for longer than is reasonably necessary for that disclosed purpose.(4) If the business intends to maintain the consumers personal information outside of the United States.(b) A business that, acting as a third party, controls the collection of personal information about a consumer may satisfy its obligation under subdivision (a) by providing the required information prominently and conspicuously on the homepage of its internet website. In addition, if a business acting as a third party controls the collection of personal information about a consumer on its premises, including in a vehicle, then the business shall, at or before the point of collection, inform consumers as to the categories of personal information to be collected and the purposes for which the categories of personal information are used, and whether that personal information is sold, in a clear and conspicuous manner at the location.(c) A business collection, use, retention, and sharing of a consumers personal information shall be reasonably necessary and proportionate to achieve the purposes for which the personal information was collected or processed, or for another disclosed purpose that is compatible with the context in which the personal information was collected, and not further processed in a manner that is incompatible with those purposes.(d) A business that collects a consumers personal information and that sells that personal information to, or shares it with, a third party or that discloses it to a service provider or contractor for a business purpose shall enter into an agreement with the third party, service provider, or contractor, that:(1) Specifies that the personal information is sold or disclosed by the business only for limited and specified purposes.(2) Obligates the third party, service provider, or contractor to comply with applicable obligations under this title and obligate those persons to provide the same level of privacy protection as is required by this title.(3) Grants the business rights to take reasonable and appropriate steps to help ensure that the third party, service provider, or contractor uses the personal information transferred in a manner consistent with the business obligations under this title.(4) Requires the third party, service provider, or contractor to notify the business if it makes a determination that it can no longer meet its obligations under this title.(5) Grants the business the right, upon notice, including under paragraph (4), to take reasonable and appropriate steps to stop and remediate unauthorized use of personal information.(e) A business that collects a consumers personal information shall implement reasonable security procedures and practices appropriate to the nature of the personal information to protect the personal information from unauthorized or illegal access, destruction, use, modification, or disclosure in accordance with Section 1798.81.5.(f) Nothing in this section shall require a business to disclose trade secrets, as specified in regulations adopted pursuant to paragraph (3) of subdivision (a) of Section 1798.185.
5661
57-SECTION 1.SEC. 2. Section 1798.100 of the Civil Code is amended to read:
62+1798.100. General Duties of Businesses that Collect Personal Information(a) A business that controls the collection of a consumers personal information shall, at or before the point of collection, inform consumers a consumer of all of the following:(1) The categories of personal information to be collected and collected, the purposes for which the categories of personal information are collected or used used, and whether that personal information is sold or shared. A business shall not collect additional categories of personal information or use personal information collected for additional purposes that are incompatible with the disclosed purpose for which the personal information was collected without providing the consumer with notice consistent with this section.(2) If the business collects sensitive personal information, the categories of sensitive personal information to be collected and the purposes for which the categories of sensitive personal information are collected or used, and whether that information is sold or shared. A business shall not collect additional categories of sensitive personal information or use sensitive personal information collected for additional purposes that are incompatible with the disclosed purpose for which the sensitive personal information was collected without providing the consumer with notice consistent with this section.(3) The length of time the business intends to retain each category of personal information, including sensitive personal information, or if that is not possible, the criteria used to determine that period provided that a business shall not retain a consumers personal information or sensitive personal information for each disclosed purpose for which the personal information was collected for longer than is reasonably necessary for that disclosed purpose.(4) If the business intends to maintain the consumers personal information outside of the United States.(b) A business that, acting as a third party, controls the collection of personal information about a consumer may satisfy its obligation under subdivision (a) by providing the required information prominently and conspicuously on the homepage of its internet website. In addition, if a business acting as a third party controls the collection of personal information about a consumer on its premises, including in a vehicle, then the business shall, at or before the point of collection, inform consumers as to the categories of personal information to be collected and the purposes for which the categories of personal information are used, and whether that personal information is sold, in a clear and conspicuous manner at the location.(c) A business collection, use, retention, and sharing of a consumers personal information shall be reasonably necessary and proportionate to achieve the purposes for which the personal information was collected or processed, or for another disclosed purpose that is compatible with the context in which the personal information was collected, and not further processed in a manner that is incompatible with those purposes.(d) A business that collects a consumers personal information and that sells that personal information to, or shares it with, a third party or that discloses it to a service provider or contractor for a business purpose shall enter into an agreement with the third party, service provider, or contractor, that:(1) Specifies that the personal information is sold or disclosed by the business only for limited and specified purposes.(2) Obligates the third party, service provider, or contractor to comply with applicable obligations under this title and obligate those persons to provide the same level of privacy protection as is required by this title.(3) Grants the business rights to take reasonable and appropriate steps to help ensure that the third party, service provider, or contractor uses the personal information transferred in a manner consistent with the business obligations under this title.(4) Requires the third party, service provider, or contractor to notify the business if it makes a determination that it can no longer meet its obligations under this title.(5) Grants the business the right, upon notice, including under paragraph (4), to take reasonable and appropriate steps to stop and remediate unauthorized use of personal information.(e) A business that collects a consumers personal information shall implement reasonable security procedures and practices appropriate to the nature of the personal information to protect the personal information from unauthorized or illegal access, destruction, use, modification, or disclosure in accordance with Section 1798.81.5.(f) Nothing in this section shall require a business to disclose trade secrets, as specified in regulations adopted pursuant to paragraph (3) of subdivision (a) of Section 1798.185.
5863
59-### SECTION 1.SEC. 2.
60-
61-1798.100. General Duties of Businesses that Collect Personal Information(a) A business that controls the collection of a consumers personal information shall, at or before the point of collection, inform a consumer of all of the following:(1) The categories of personal information to be collected, the purposes for which the categories of personal information are collected or used, and whether that personal information is sold or shared. A business shall not collect additional categories of personal information or use personal information collected for additional purposes that are incompatible with the disclosed purpose for which the personal information was collected without providing the consumer with notice consistent with this section.(2) If the business collects sensitive personal information, the categories of sensitive personal information to be collected and the purposes for which the categories of sensitive personal information are collected or used, and whether that information is sold or shared. A business shall not collect additional categories of sensitive personal information or use sensitive personal information collected for additional purposes that are incompatible with the disclosed purpose for which the sensitive personal information was collected without providing the consumer with notice consistent with this section.(3) The length of time the business intends to retain each category of personal information, including sensitive personal information, or if that is not possible, the criteria used to determine that period provided that a business shall not retain a consumers personal information or sensitive personal information for each disclosed purpose for which the personal information was collected for longer than is reasonably necessary for that disclosed purpose.(4) If the business intends to maintain the consumers personal information outside of the United States.(b) A business that, acting as a third party, controls the collection of personal information about a consumer may satisfy its obligation under subdivision (a) by providing the required information prominently and conspicuously on the homepage home page of its internet website. In addition, if a business acting as a third party controls the collection of personal information about a consumer on its premises, including in a vehicle, then the business shall, at or before the point of collection, inform consumers as to the categories of personal information to be collected and the purposes for which the categories of personal information are used, and whether that personal information is sold, in a clear and conspicuous manner at the location.(c) A business collection, use, retention, and sharing of a consumers personal information shall be reasonably necessary and proportionate to achieve the purposes for which the personal information was collected or processed, or for another disclosed purpose that is compatible with the context in which the personal information was collected, and not further processed in a manner that is incompatible with those purposes.(d) A business that collects a consumers personal information and that sells that personal information to, or shares it with, a third party or that discloses it to a service provider or contractor for a business purpose shall enter into an agreement with the third party, service provider, or contractor, that:(1) Specifies that the personal information is sold or disclosed by the business only for limited and specified purposes.(2) Obligates the third party, service provider, or contractor to comply with applicable obligations under this title and obligate those persons to provide the same level of privacy protection as is required by this title.(3) Grants the business rights to take reasonable and appropriate steps to help ensure that the third party, service provider, or contractor uses the personal information transferred in a manner consistent with the business obligations under this title.(4) Requires the third party, service provider, or contractor to notify the business if it makes a determination that it can no longer meet its obligations under this title.(5) Grants the business the right, upon notice, including under paragraph (4), to take reasonable and appropriate steps to stop and remediate unauthorized use of personal information.(e) A business that collects a consumers personal information shall implement reasonable security procedures and practices appropriate to the nature of the personal information to protect the personal information from unauthorized or illegal access, destruction, use, modification, or disclosure in accordance with Section 1798.81.5.(f) Nothing in this section shall require a business to disclose trade secrets, as specified in regulations adopted pursuant to paragraph (3) of subdivision (a) of Section 1798.185.
62-
63-1798.100. General Duties of Businesses that Collect Personal Information(a) A business that controls the collection of a consumers personal information shall, at or before the point of collection, inform a consumer of all of the following:(1) The categories of personal information to be collected, the purposes for which the categories of personal information are collected or used, and whether that personal information is sold or shared. A business shall not collect additional categories of personal information or use personal information collected for additional purposes that are incompatible with the disclosed purpose for which the personal information was collected without providing the consumer with notice consistent with this section.(2) If the business collects sensitive personal information, the categories of sensitive personal information to be collected and the purposes for which the categories of sensitive personal information are collected or used, and whether that information is sold or shared. A business shall not collect additional categories of sensitive personal information or use sensitive personal information collected for additional purposes that are incompatible with the disclosed purpose for which the sensitive personal information was collected without providing the consumer with notice consistent with this section.(3) The length of time the business intends to retain each category of personal information, including sensitive personal information, or if that is not possible, the criteria used to determine that period provided that a business shall not retain a consumers personal information or sensitive personal information for each disclosed purpose for which the personal information was collected for longer than is reasonably necessary for that disclosed purpose.(4) If the business intends to maintain the consumers personal information outside of the United States.(b) A business that, acting as a third party, controls the collection of personal information about a consumer may satisfy its obligation under subdivision (a) by providing the required information prominently and conspicuously on the homepage home page of its internet website. In addition, if a business acting as a third party controls the collection of personal information about a consumer on its premises, including in a vehicle, then the business shall, at or before the point of collection, inform consumers as to the categories of personal information to be collected and the purposes for which the categories of personal information are used, and whether that personal information is sold, in a clear and conspicuous manner at the location.(c) A business collection, use, retention, and sharing of a consumers personal information shall be reasonably necessary and proportionate to achieve the purposes for which the personal information was collected or processed, or for another disclosed purpose that is compatible with the context in which the personal information was collected, and not further processed in a manner that is incompatible with those purposes.(d) A business that collects a consumers personal information and that sells that personal information to, or shares it with, a third party or that discloses it to a service provider or contractor for a business purpose shall enter into an agreement with the third party, service provider, or contractor, that:(1) Specifies that the personal information is sold or disclosed by the business only for limited and specified purposes.(2) Obligates the third party, service provider, or contractor to comply with applicable obligations under this title and obligate those persons to provide the same level of privacy protection as is required by this title.(3) Grants the business rights to take reasonable and appropriate steps to help ensure that the third party, service provider, or contractor uses the personal information transferred in a manner consistent with the business obligations under this title.(4) Requires the third party, service provider, or contractor to notify the business if it makes a determination that it can no longer meet its obligations under this title.(5) Grants the business the right, upon notice, including under paragraph (4), to take reasonable and appropriate steps to stop and remediate unauthorized use of personal information.(e) A business that collects a consumers personal information shall implement reasonable security procedures and practices appropriate to the nature of the personal information to protect the personal information from unauthorized or illegal access, destruction, use, modification, or disclosure in accordance with Section 1798.81.5.(f) Nothing in this section shall require a business to disclose trade secrets, as specified in regulations adopted pursuant to paragraph (3) of subdivision (a) of Section 1798.185.
64-
65-1798.100. General Duties of Businesses that Collect Personal Information(a) A business that controls the collection of a consumers personal information shall, at or before the point of collection, inform a consumer of all of the following:(1) The categories of personal information to be collected, the purposes for which the categories of personal information are collected or used, and whether that personal information is sold or shared. A business shall not collect additional categories of personal information or use personal information collected for additional purposes that are incompatible with the disclosed purpose for which the personal information was collected without providing the consumer with notice consistent with this section.(2) If the business collects sensitive personal information, the categories of sensitive personal information to be collected and the purposes for which the categories of sensitive personal information are collected or used, and whether that information is sold or shared. A business shall not collect additional categories of sensitive personal information or use sensitive personal information collected for additional purposes that are incompatible with the disclosed purpose for which the sensitive personal information was collected without providing the consumer with notice consistent with this section.(3) The length of time the business intends to retain each category of personal information, including sensitive personal information, or if that is not possible, the criteria used to determine that period provided that a business shall not retain a consumers personal information or sensitive personal information for each disclosed purpose for which the personal information was collected for longer than is reasonably necessary for that disclosed purpose.(4) If the business intends to maintain the consumers personal information outside of the United States.(b) A business that, acting as a third party, controls the collection of personal information about a consumer may satisfy its obligation under subdivision (a) by providing the required information prominently and conspicuously on the homepage home page of its internet website. In addition, if a business acting as a third party controls the collection of personal information about a consumer on its premises, including in a vehicle, then the business shall, at or before the point of collection, inform consumers as to the categories of personal information to be collected and the purposes for which the categories of personal information are used, and whether that personal information is sold, in a clear and conspicuous manner at the location.(c) A business collection, use, retention, and sharing of a consumers personal information shall be reasonably necessary and proportionate to achieve the purposes for which the personal information was collected or processed, or for another disclosed purpose that is compatible with the context in which the personal information was collected, and not further processed in a manner that is incompatible with those purposes.(d) A business that collects a consumers personal information and that sells that personal information to, or shares it with, a third party or that discloses it to a service provider or contractor for a business purpose shall enter into an agreement with the third party, service provider, or contractor, that:(1) Specifies that the personal information is sold or disclosed by the business only for limited and specified purposes.(2) Obligates the third party, service provider, or contractor to comply with applicable obligations under this title and obligate those persons to provide the same level of privacy protection as is required by this title.(3) Grants the business rights to take reasonable and appropriate steps to help ensure that the third party, service provider, or contractor uses the personal information transferred in a manner consistent with the business obligations under this title.(4) Requires the third party, service provider, or contractor to notify the business if it makes a determination that it can no longer meet its obligations under this title.(5) Grants the business the right, upon notice, including under paragraph (4), to take reasonable and appropriate steps to stop and remediate unauthorized use of personal information.(e) A business that collects a consumers personal information shall implement reasonable security procedures and practices appropriate to the nature of the personal information to protect the personal information from unauthorized or illegal access, destruction, use, modification, or disclosure in accordance with Section 1798.81.5.(f) Nothing in this section shall require a business to disclose trade secrets, as specified in regulations adopted pursuant to paragraph (3) of subdivision (a) of Section 1798.185.
64+1798.100. General Duties of Businesses that Collect Personal Information(a) A business that controls the collection of a consumers personal information shall, at or before the point of collection, inform consumers a consumer of all of the following:(1) The categories of personal information to be collected and collected, the purposes for which the categories of personal information are collected or used used, and whether that personal information is sold or shared. A business shall not collect additional categories of personal information or use personal information collected for additional purposes that are incompatible with the disclosed purpose for which the personal information was collected without providing the consumer with notice consistent with this section.(2) If the business collects sensitive personal information, the categories of sensitive personal information to be collected and the purposes for which the categories of sensitive personal information are collected or used, and whether that information is sold or shared. A business shall not collect additional categories of sensitive personal information or use sensitive personal information collected for additional purposes that are incompatible with the disclosed purpose for which the sensitive personal information was collected without providing the consumer with notice consistent with this section.(3) The length of time the business intends to retain each category of personal information, including sensitive personal information, or if that is not possible, the criteria used to determine that period provided that a business shall not retain a consumers personal information or sensitive personal information for each disclosed purpose for which the personal information was collected for longer than is reasonably necessary for that disclosed purpose.(4) If the business intends to maintain the consumers personal information outside of the United States.(b) A business that, acting as a third party, controls the collection of personal information about a consumer may satisfy its obligation under subdivision (a) by providing the required information prominently and conspicuously on the homepage of its internet website. In addition, if a business acting as a third party controls the collection of personal information about a consumer on its premises, including in a vehicle, then the business shall, at or before the point of collection, inform consumers as to the categories of personal information to be collected and the purposes for which the categories of personal information are used, and whether that personal information is sold, in a clear and conspicuous manner at the location.(c) A business collection, use, retention, and sharing of a consumers personal information shall be reasonably necessary and proportionate to achieve the purposes for which the personal information was collected or processed, or for another disclosed purpose that is compatible with the context in which the personal information was collected, and not further processed in a manner that is incompatible with those purposes.(d) A business that collects a consumers personal information and that sells that personal information to, or shares it with, a third party or that discloses it to a service provider or contractor for a business purpose shall enter into an agreement with the third party, service provider, or contractor, that:(1) Specifies that the personal information is sold or disclosed by the business only for limited and specified purposes.(2) Obligates the third party, service provider, or contractor to comply with applicable obligations under this title and obligate those persons to provide the same level of privacy protection as is required by this title.(3) Grants the business rights to take reasonable and appropriate steps to help ensure that the third party, service provider, or contractor uses the personal information transferred in a manner consistent with the business obligations under this title.(4) Requires the third party, service provider, or contractor to notify the business if it makes a determination that it can no longer meet its obligations under this title.(5) Grants the business the right, upon notice, including under paragraph (4), to take reasonable and appropriate steps to stop and remediate unauthorized use of personal information.(e) A business that collects a consumers personal information shall implement reasonable security procedures and practices appropriate to the nature of the personal information to protect the personal information from unauthorized or illegal access, destruction, use, modification, or disclosure in accordance with Section 1798.81.5.(f) Nothing in this section shall require a business to disclose trade secrets, as specified in regulations adopted pursuant to paragraph (3) of subdivision (a) of Section 1798.185.
6665
6766
6867
6968 1798.100. General Duties of Businesses that Collect Personal Information
7069
71-(a) A business that controls the collection of a consumers personal information shall, at or before the point of collection, inform a consumer of all of the following:
70+(a) A business that controls the collection of a consumers personal information shall, at or before the point of collection, inform consumers a consumer of all of the following:
7271
73-(1) The categories of personal information to be collected, the purposes for which the categories of personal information are collected or used, and whether that personal information is sold or shared. A business shall not collect additional categories of personal information or use personal information collected for additional purposes that are incompatible with the disclosed purpose for which the personal information was collected without providing the consumer with notice consistent with this section.
72+(1) The categories of personal information to be collected and collected, the purposes for which the categories of personal information are collected or used used, and whether that personal information is sold or shared. A business shall not collect additional categories of personal information or use personal information collected for additional purposes that are incompatible with the disclosed purpose for which the personal information was collected without providing the consumer with notice consistent with this section.
7473
7574 (2) If the business collects sensitive personal information, the categories of sensitive personal information to be collected and the purposes for which the categories of sensitive personal information are collected or used, and whether that information is sold or shared. A business shall not collect additional categories of sensitive personal information or use sensitive personal information collected for additional purposes that are incompatible with the disclosed purpose for which the sensitive personal information was collected without providing the consumer with notice consistent with this section.
7675
7776 (3) The length of time the business intends to retain each category of personal information, including sensitive personal information, or if that is not possible, the criteria used to determine that period provided that a business shall not retain a consumers personal information or sensitive personal information for each disclosed purpose for which the personal information was collected for longer than is reasonably necessary for that disclosed purpose.
7877
7978 (4) If the business intends to maintain the consumers personal information outside of the United States.
8079
81-(b) A business that, acting as a third party, controls the collection of personal information about a consumer may satisfy its obligation under subdivision (a) by providing the required information prominently and conspicuously on the homepage home page of its internet website. In addition, if a business acting as a third party controls the collection of personal information about a consumer on its premises, including in a vehicle, then the business shall, at or before the point of collection, inform consumers as to the categories of personal information to be collected and the purposes for which the categories of personal information are used, and whether that personal information is sold, in a clear and conspicuous manner at the location.
80+(b) A business that, acting as a third party, controls the collection of personal information about a consumer may satisfy its obligation under subdivision (a) by providing the required information prominently and conspicuously on the homepage of its internet website. In addition, if a business acting as a third party controls the collection of personal information about a consumer on its premises, including in a vehicle, then the business shall, at or before the point of collection, inform consumers as to the categories of personal information to be collected and the purposes for which the categories of personal information are used, and whether that personal information is sold, in a clear and conspicuous manner at the location.
8281
8382 (c) A business collection, use, retention, and sharing of a consumers personal information shall be reasonably necessary and proportionate to achieve the purposes for which the personal information was collected or processed, or for another disclosed purpose that is compatible with the context in which the personal information was collected, and not further processed in a manner that is incompatible with those purposes.
8483
8584 (d) A business that collects a consumers personal information and that sells that personal information to, or shares it with, a third party or that discloses it to a service provider or contractor for a business purpose shall enter into an agreement with the third party, service provider, or contractor, that:
8685
8786 (1) Specifies that the personal information is sold or disclosed by the business only for limited and specified purposes.
8887
8988 (2) Obligates the third party, service provider, or contractor to comply with applicable obligations under this title and obligate those persons to provide the same level of privacy protection as is required by this title.
9089
9190 (3) Grants the business rights to take reasonable and appropriate steps to help ensure that the third party, service provider, or contractor uses the personal information transferred in a manner consistent with the business obligations under this title.
9291
9392 (4) Requires the third party, service provider, or contractor to notify the business if it makes a determination that it can no longer meet its obligations under this title.
9493
9594 (5) Grants the business the right, upon notice, including under paragraph (4), to take reasonable and appropriate steps to stop and remediate unauthorized use of personal information.
9695
9796 (e) A business that collects a consumers personal information shall implement reasonable security procedures and practices appropriate to the nature of the personal information to protect the personal information from unauthorized or illegal access, destruction, use, modification, or disclosure in accordance with Section 1798.81.5.
9897
9998 (f) Nothing in this section shall require a business to disclose trade secrets, as specified in regulations adopted pursuant to paragraph (3) of subdivision (a) of Section 1798.185.
10099
101-SEC. 2.SEC. 3. Section 1798.122 is added to the Civil Code, to read:1798.122. (a) A business shall not maintain a consumers personal information outside of the United States unless all of the following are true:(1) The business has informed the consumer of potential risks associated with the business maintaining the consumers personal information outside of the United States.(2) The consumer explicitly consented to the business maintaining the consumers personal information outside of the United States.(3) The personal information is not health care information, financial information, or geolocation data.(b) A business shall not maintain personal information that is health care information, financial information, or geolocation data in the custody of a foreign government or a third party that is owned or controlled by a foreign government.
100+SEC. 2. Section 1798.122 is added to the Civil Code, to read:1798.122. (a) A business shall not maintain a consumers personal information outside of the United States unless all of the following are true:(1) The business has informed the consumer of potential risks associated with the business maintaining the consumers personal information outside of the United States.(2) The consumer explicitly consented to the business maintaining the consumers personal information outside of the United States.(3) The personal information is not health care information, financial information, or geolocation data.(b) A business shall not maintain personal information that is health care information, financial information, or geolocation data in the custody of a foreign government or a third party that is owned or controlled by a foreign government.
102101
103-SEC. 2.SEC. 3. Section 1798.122 is added to the Civil Code, to read:
102+SEC. 2. Section 1798.122 is added to the Civil Code, to read:
104103
105-### SEC. 2.SEC. 3.
104+### SEC. 2.
106105
107106 1798.122. (a) A business shall not maintain a consumers personal information outside of the United States unless all of the following are true:(1) The business has informed the consumer of potential risks associated with the business maintaining the consumers personal information outside of the United States.(2) The consumer explicitly consented to the business maintaining the consumers personal information outside of the United States.(3) The personal information is not health care information, financial information, or geolocation data.(b) A business shall not maintain personal information that is health care information, financial information, or geolocation data in the custody of a foreign government or a third party that is owned or controlled by a foreign government.
108107
109108 1798.122. (a) A business shall not maintain a consumers personal information outside of the United States unless all of the following are true:(1) The business has informed the consumer of potential risks associated with the business maintaining the consumers personal information outside of the United States.(2) The consumer explicitly consented to the business maintaining the consumers personal information outside of the United States.(3) The personal information is not health care information, financial information, or geolocation data.(b) A business shall not maintain personal information that is health care information, financial information, or geolocation data in the custody of a foreign government or a third party that is owned or controlled by a foreign government.
110109
111110 1798.122. (a) A business shall not maintain a consumers personal information outside of the United States unless all of the following are true:(1) The business has informed the consumer of potential risks associated with the business maintaining the consumers personal information outside of the United States.(2) The consumer explicitly consented to the business maintaining the consumers personal information outside of the United States.(3) The personal information is not health care information, financial information, or geolocation data.(b) A business shall not maintain personal information that is health care information, financial information, or geolocation data in the custody of a foreign government or a third party that is owned or controlled by a foreign government.
112111
113112
114113
115114 1798.122. (a) A business shall not maintain a consumers personal information outside of the United States unless all of the following are true:
116115
117116 (1) The business has informed the consumer of potential risks associated with the business maintaining the consumers personal information outside of the United States.
118117
119118 (2) The consumer explicitly consented to the business maintaining the consumers personal information outside of the United States.
120119
121120 (3) The personal information is not health care information, financial information, or geolocation data.
122121
123122 (b) A business shall not maintain personal information that is health care information, financial information, or geolocation data in the custody of a foreign government or a third party that is owned or controlled by a foreign government.
124123
125-SEC. 3.SEC. 4. The Legislature finds and declares that this act furthers the purposes and intent of the California Privacy Rights Act of 2020.
124+SEC. 3. The Legislature finds and declares that this act furthers the purposes and intent of the California Privacy Rights Act of 2020.
126125
127-SEC. 3.SEC. 4. The Legislature finds and declares that this act furthers the purposes and intent of the California Privacy Rights Act of 2020.
126+SEC. 3. The Legislature finds and declares that this act furthers the purposes and intent of the California Privacy Rights Act of 2020.
128127
129-SEC. 3.SEC. 4. The Legislature finds and declares that this act furthers the purposes and intent of the California Privacy Rights Act of 2020.
128+SEC. 3. The Legislature finds and declares that this act furthers the purposes and intent of the California Privacy Rights Act of 2020.
130129
131-### SEC. 3.SEC. 4.
130+### SEC. 3.
131+
132+
133+
134+It is the intent of the Legislature to enact legislation that would relate to regulating social media, ecommerce, privacy, and information technology.