Session:   

Bill

Home - Bills - Bill - Authors - Dates - Keywords - Tags - Locations

Measure AB 1337
Authors Ward  
Subject Information Practices Act of 1977.
Relating To relating to information privacy.
Title An act to amend Sections 1798.3, 1798.16, 1798.17, 1798.19, 1798.20, 1798.24, 1798.24b, 1798.25, 1798.26, 1798.27, 1798.29, 1798.44, 1798.55, 1798.57, and 1798.68 of the Civil Code, relating to information privacy.
Last Action Dt 2025-05-23
State Amended Assembly
Status In Committee Process
Active? Y
Vote Required Majority
Appropriation No
Fiscal Committee Yes
Local Program Yes
Substantive Changes None
Urgency No
Tax Levy No
Leginfo Link Bill
Actions
2025-07-15     In committee: Set, first hearing. Failed passage. Reconsideration granted.
2025-06-11     Referred to Com. on JUD.
2025-06-03     In Senate. Read first time. To Com. on RLS. for assignment.
2025-06-02     Read third time. Passed. Ordered to the Senate. (Ayes 64. Noes 0. Page 1921.)
2025-05-27     Read second time. Ordered to third reading.
2025-05-23     Assembly Rule 63 suspended. (Ayes 51. Noes 16. Page 1644.)
2025-05-23     From committee: Amend, and do pass as amended. (Ayes 11. Noes 1.) (May 23).
2025-05-23     Read second time and amended. Ordered returned to second reading.
2025-04-30     In committee: Set, first hearing. Referred to suspense file.
2025-04-09     Re-referred to Com. on APPR.
2025-04-08     Read second time and amended.
2025-04-07     From committee: Amend, and do pass as amended and re-refer to Com. on APPR. (Ayes 12. Noes 0.) (April 1).
2025-03-17     Referred to Com. on P. & C.P.
2025-02-24     Read first time.
2025-02-22     From printer. May be heard in committee March 24.
2025-02-21     Introduced. To print.
Keywords
Tags
Versions
Amended Assembly     2025-05-23
Amended Assembly     2025-04-08
Introduced     2025-02-21
Last Version Text
<?xml version="1.0" ?>
<ns0:MeasureDoc xmlns:html="http://www.w3.org/1999/xhtml" xmlns:ns0="http://lc.ca.gov/legalservices/schemas/caml.1#" xmlns:ns3="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" version="1.0" xsi:schemaLocation="http://lc.ca.gov/legalservices/schemas/caml.1# xca.1.xsd">
	


	<ns0:Description>
		<ns0:Id>20250AB__133797AMD</ns0:Id>
		<ns0:VersionNum>97</ns0:VersionNum>
		<ns0:History>
			<ns0:Action>
				<ns0:ActionText>INTRODUCED</ns0:ActionText>
				<ns0:ActionDate>2025-02-21</ns0:ActionDate>
			</ns0:Action>
			<ns0:Action>
				<ns0:ActionText>AMENDED_ASSEMBLY</ns0:ActionText>
				<ns0:ActionDate>2025-04-08</ns0:ActionDate>
			</ns0:Action>
			<ns0:Action>
				<ns0:ActionText>AMENDED_ASSEMBLY</ns0:ActionText>
				<ns0:ActionDate>2025-05-23</ns0:ActionDate>
			</ns0:Action>
		</ns0:History>
		<ns0:LegislativeInfo>
			<ns0:SessionYear>2025</ns0:SessionYear>
			<ns0:SessionNum>0</ns0:SessionNum>
			<ns0:MeasureType>AB</ns0:MeasureType>
			<ns0:MeasureNum>1337</ns0:MeasureNum>
			<ns0:MeasureState>AMD</ns0:MeasureState>
		</ns0:LegislativeInfo>
		<ns0:AuthorText authorType="LEAD_AUTHOR">Introduced by Assembly Member Ward</ns0:AuthorText>
		<ns0:Authors>
			<ns0:Legislator>
				<ns0:Contribution>LEAD_AUTHOR</ns0:Contribution>
				<ns0:House>ASSEMBLY</ns0:House>
				<ns0:Name>Ward</ns0:Name>
			</ns0:Legislator>
		</ns0:Authors>
		<ns0:Title> An act to amend Sections 1798.3, 1798.16, 1798.17, 1798.19, 1798.20, 1798.24, 1798.24b, 1798.25, 1798.26, 1798.27, 1798.29, 1798.44, 1798.55, 1798.57, and 1798.68 of the Civil Code, relating to information privacy. </ns0:Title>
		<ns0:RelatingClause>information privacy</ns0:RelatingClause>
		<ns0:GeneralSubject>
			<ns0:Subject>Information Practices Act of 1977.</ns0:Subject>
		</ns0:GeneralSubject>
		<ns0:DigestText>
			<html:p>Existing law, the Information Practices Act of 1977, prescribes a set of requirements, prohibitions, and remedies applicable to agencies, as defined, with regard to their collection, storage, and disclosure of personal information, as defined. Existing law exempts from the provisions of the act counties, cities, any city and county, school districts, municipal corporations, districts, political subdivisions, and other local public agencies, as specified.</html:p>
			<html:p>This bill would recast those provisions to, among other things, remove that exemption for local agencies, and would revise and expand the definition of “personal information.” The bill would make other technical, nonsubstantive, and conforming changes. Because the bill would expand the duties of local officials, this bill would impose a state-mandated local program.</html:p>
			<html:p>Existing law requires an agency to establish rules of conduct for persons involved in the design, development, operation, disclosure, or maintenance of records containing personal information and instruct those persons with respect to specified rules relevant to the act.</html:p>
			<html:p>This bill would prohibit an agency from using records containing personal information for any purpose or purposes other than the purpose or purposes for which that personal information was collected, except as required or authorized by state
			 law.</html:p>
			<html:p>Existing law prohibits an agency from disclosing any personal information in a manner that would link the information disclosed to the individual to whom it pertains, except under specified circumstances.</html:p>
			<html:p>This bill would revise the circumstances that may allow the disclosure of personal information in a manner that could link the information disclosed to the individual to whom it pertains, and would make conforming changes.</html:p>
			<html:p>Existing law makes an intentional violation of any provision of the act, or of any rules or regulations adopted under the act, by an officer or employee of any agency a cause for discipline, including termination of employment. </html:p>
			<html:p>This bill would also make a negligent violation of the act a cause for discipline. </html:p>
			<html:p>Existing law provides that the intentional
			 disclosure of medical, psychiatric, or psychological information in violation of the disclosure provisions of the act, that is not otherwise permitted by law, is punishable as a misdemeanor if the wrongful disclosure results in economic loss or personal injury to the individual to whom the information pertains.</html:p>
			<html:p>This bill would remove the requirement that the wrongful disclosure result in economic loss or personal injury. Because the bill would expand the scope of an existing crime by deleting this condition, the bill would impose a state-mandated local program.</html:p>
			<html:p> Existing constitutional provisions require that a statute that limits the right of access to the meetings of public bodies or the writings of public officials and agencies be adopted with findings demonstrating the interest protected by the limitation and the need for protecting that interest.</html:p>
			<html:p>This bill
			 would make legislative findings to that effect.</html:p>
			<html:p> The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state. Statutory provisions establish procedures for making that reimbursement.</html:p>
			<html:p>This bill would provide that with regard to certain mandates no reimbursement is required by this act for a specified reason.</html:p>
			<html:p>With regard to any other mandates, this bill would provide that, if the Commission on State Mandates determines that the bill contains costs so mandated by the state, reimbursement for those costs shall be made pursuant to the statutory provisions noted above.</html:p>
		</ns0:DigestText>
		<ns0:DigestKey>
			<ns0:VoteRequired>MAJORITY</ns0:VoteRequired>
			<ns0:Appropriation>NO</ns0:Appropriation>
			<ns0:FiscalCommittee>YES</ns0:FiscalCommittee>
			<ns0:LocalProgram>YES</ns0:LocalProgram>
		</ns0:DigestKey>
		<ns0:MeasureIndicators>
			<ns0:ImmediateEffect>NO</ns0:ImmediateEffect>
			<ns0:ImmediateEffectFlags>
				<ns0:Urgency>NO</ns0:Urgency>
				<ns0:TaxLevy>NO</ns0:TaxLevy>
				<ns0:Election>NO</ns0:Election>
				<ns0:UsualCurrentExpenses>NO</ns0:UsualCurrentExpenses>
				<ns0:BudgetBill>NO</ns0:BudgetBill>
				<ns0:Prop25TrailerBill>NO</ns0:Prop25TrailerBill>
			</ns0:ImmediateEffectFlags>
		</ns0:MeasureIndicators>
	</ns0:Description>
	<ns0:Bill id="bill">
		<ns0:Preamble>The people of the State of California do enact as follows:</ns0:Preamble>
		<ns0:BillSection id="id_65ADE781-8F6F-43EF-8806-CC6DE1A6A05B">
			<ns0:Num>SECTION 1.</ns0:Num>
			<ns0:ActionLine action="IS_AMENDED" ns3:href="urn:caml:codes:CIV:caml#xpointer(%2Fcaml%3ALawDoc%2Fcaml%3ACode%2Fcaml%3ALawHeading%5B%40type%3D'DIVISION'%20and%20caml%3ANum%3D'3.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'PART'%20and%20caml%3ANum%3D'4.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'TITLE'%20and%20caml%3ANum%3D'1.8.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'CHAPTER'%20and%20caml%3ANum%3D'1.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'ARTICLE'%20and%20caml%3ANum%3D'2.'%5D%2Fcaml%3ALawSection%5Bcaml%3ANum%3D'1798.3.'%5D)" ns3:label="fractionType: LAW_SECTION" ns3:type="locator">
				Section 1798.3 of the 
				<ns0:DocName>Civil Code</ns0:DocName>
				 is amended to read:
			</ns0:ActionLine>
			<ns0:Fragment>
				<ns0:LawSection id="id_B6FCA011-76E7-45C9-A5EC-DEBEBD5884A6">
					<ns0:Num>1798.3.</ns0:Num>
					<ns0:LawSectionVersion id="id_98587AFC-E796-4B49-82B7-D5BC81ABD9F0">
						<ns0:Content>
							<html:p>As used in this chapter:</html:p>
							<html:p>
								(a)
								<html:span class="EnSpace"/>
								(1)
								<html:span class="EnSpace"/>
								The term “personal information” means any information that identifies, relates to, describes, or is capable of being associated with, a particular individual, including, but not limited to,
						all of the following:
							</html:p>
							<html:p>
								(A)
								<html:span class="EnSpace"/>
								Name, alias, postal address, unique personal identifier, online identifier, IP address, email address, account name, social security number, driver’s license number, passport number, or other identifier.
							</html:p>
							<html:p>
								(B)
								<html:span class="EnSpace"/>
								Vehicle registration information, including license plate numbers.
							</html:p>
							<html:p>
								(C)
								<html:span class="EnSpace"/>
								The contents of an individual’s mail, email, and text messages unless the agency is the intended recipient of the communication.
							</html:p>
							<html:p>
								(D)
								<html:span class="EnSpace"/>
								Characteristics of protected classifications.
							</html:p>
							<html:p>
								(E)
								<html:span class="EnSpace"/>
								Racial or ethnic origin, citizenship or immigration status, religious beliefs, political
						positions or affiliations, or union membership.
							</html:p>
							<html:p>
								(F)
								<html:span class="EnSpace"/>
								Biometric information.
							</html:p>
							<html:p>
								(G)
								<html:span class="EnSpace"/>
								Genetic data.
							</html:p>
							<html:p>
								(H)
								<html:span class="EnSpace"/>
								Precise geolocation data.
							</html:p>
							<html:p>
								(I)
								<html:span class="EnSpace"/>
								Audio, electronic, visual, thermal, olfactory, or similar information.
							</html:p>
							<html:p>
								(J)
								<html:span class="EnSpace"/>
								Insurance policy numbers.
							</html:p>
							<html:p>
								(K)
								<html:span class="EnSpace"/>
								Neural data.
							</html:p>
							<html:p>
								(L)
								<html:span class="EnSpace"/>
								Information concerning an individual’s health.
							</html:p>
							<html:p>
								(M)
								<html:span class="EnSpace"/>
								Information concerning an individual’s gender, sex life, or sexual orientation.
							</html:p>
							<html:p>
								(2)
								<html:span class="EnSpace"/>
								“Personal information” may exist in various formats, including, but not limited to, all of the following:
							</html:p>
							<html:p>
								(A)
								<html:span class="EnSpace"/>
								Physical formats, including paper documents, printed images, vinyl records, or videotapes.
							</html:p>
							<html:p>
								(B)
								<html:span class="EnSpace"/>
								Digital formats, including text, image, audio, or video files.
							</html:p>
							<html:p>
								(C)
								<html:span class="EnSpace"/>
								Abstract digital formats, including compressed or encrypted files, metadata, or artificial intelligence systems that are capable of outputting personal information.
							</html:p>
							<html:p>
								(b)
								<html:span class="EnSpace"/>
								The term “agency” means every state and local office, officer, department, division, bureau, board, commission, or other state agency, except that the term agency shall not include:
							</html:p>
							<html:p>
								(1)
								<html:span class="EnSpace"/>
								The California Legislature.
							</html:p>
							<html:p>
								(2)
								<html:span class="EnSpace"/>
								Any agency established under Article VI of the California Constitution.
							</html:p>
							<html:p>
								(3)
								<html:span class="EnSpace"/>
								The State Compensation Insurance Fund, except as to any records that contain personal information about the employees of the State Compensation Insurance Fund.
							</html:p>
							<html:p>
								(c)
								<html:span class="EnSpace"/>
								The term “disclose” means to disclose, release, transfer, disseminate, or otherwise communicate all or any part of any record orally, in writing, or by electronic or any other means to any person or
						entity.
							</html:p>
							<html:p>
								(d)
								<html:span class="EnSpace"/>
								The term “individual” means a natural person.
							</html:p>
							<html:p>
								(e)
								<html:span class="EnSpace"/>
								The term “maintain” includes maintain, acquire, use, or disclose.
							</html:p>
							<html:p>
								(f)
								<html:span class="EnSpace"/>
								The term “person” means any natural person, corporation, partnership, limited liability company, firm, or association.
							</html:p>
							<html:p>
								(g)
								<html:span class="EnSpace"/>
								The term “record” means any file or grouping of personal information that is maintained by an agency. 
							</html:p>
							<html:p>
								(h)
								<html:span class="EnSpace"/>
								The term “commercial purpose” means any purpose that has financial gain as a major objective. It does not include the gathering or dissemination of newsworthy facts by a publisher or broadcaster.
							</html:p>
							<html:p>
								(i)
								<html:span class="EnSpace"/>
								The term “regulatory agency” means the Department of Financial Protection and Innovation, the Department of Insurance, the Bureau of Real Estate, and agencies of the United States or of any other state responsible for regulating financial institutions.
							</html:p>
							<html:p>
								(j)
								<html:span class="EnSpace"/>
								The term “precise geolocation data” means any data that is derived from a device and that is used or intended to be used to locate an individual within a geographic area that is equal to or less than the area of a circle with a radius of 1,850 feet.
							</html:p>
							<html:p>
								(k)
								<html:span class="EnSpace"/>
								The term “neural data” means information that is generated by measuring the activity of an individual’s central or peripheral nervous system, and that is not inferred from nonneural information.
							</html:p>
						</ns0:Content>
					</ns0:LawSectionVersion>
				</ns0:LawSection>
			</ns0:Fragment>
		</ns0:BillSection>
		<ns0:BillSection id="id_289F1A49-F390-402D-BB3D-E8009AE60AC8">
			<ns0:Num>SEC. 2.</ns0:Num>
			<ns0:ActionLine action="IS_AMENDED" ns3:href="urn:caml:codes:CIV:caml#xpointer(%2Fcaml%3ALawDoc%2Fcaml%3ACode%2Fcaml%3ALawHeading%5B%40type%3D'DIVISION'%20and%20caml%3ANum%3D'3.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'PART'%20and%20caml%3ANum%3D'4.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'TITLE'%20and%20caml%3ANum%3D'1.8.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'CHAPTER'%20and%20caml%3ANum%3D'1.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'ARTICLE'%20and%20caml%3ANum%3D'5.'%5D%2Fcaml%3ALawSection%5Bcaml%3ANum%3D'1798.16.'%5D)" ns3:label="fractionType: LAW_SECTION" ns3:type="locator">
				Section 1798.16 of the 
				<ns0:DocName>Civil Code</ns0:DocName>
				 is amended to read:
			</ns0:ActionLine>
			<ns0:Fragment>
				<ns0:LawSection id="id_C039AEDF-E4DE-4420-8452-23567BD6211C">
					<ns0:Num>1798.16.</ns0:Num>
					<ns0:LawSectionVersion id="id_55050440-8E1C-4AB2-8357-556C8A26D4ED">
						<ns0:Content>
							<html:p>
								(a)
								<html:span class="EnSpace"/>
								Whenever an agency collects personal information, the agency shall maintain the source or sources of the information, unless the source is the data subject or has received a copy of the source document, including, but not limited to, the name of any source who is an individual acting in their own private or individual capacity. If the source is an agency, branch of the federal government, or other organization, such as a corporation or association, this requirement can be met by maintaining the name of the agency, branch of the federal government, or organization, as long as the smallest reasonably identifiable unit of that agency, branch of the federal government, or organization is named.
							</html:p>
							<html:p>
								(b)
								<html:span class="EnSpace"/>
								On or after July 1, 2001, unless otherwise authorized by the Department of Information Technology pursuant to Executive Order D-3-99, whenever an agency electronically collects personal information, as defined by Section 11015.5 of the Government Code, the agency shall retain the source or sources or any intermediate form of the information, if either are created or possessed by the agency, unless the source is the data subject that has requested that the information be discarded or the data subject has received a copy of the source document.
							</html:p>
							<html:p>
								(c)
								<html:span class="EnSpace"/>
								The agency shall maintain the source or sources of the information in a readily accessible form so as to be able to provide it to the data subject when they inspect any record pursuant to Section 1798.34. This section shall not apply
						if the source or sources are exempt from disclosure under the provisions of this chapter.
							</html:p>
						</ns0:Content>
					</ns0:LawSectionVersion>
				</ns0:LawSection>
			</ns0:Fragment>
		</ns0:BillSection>
		<ns0:BillSection id="id_E3680089-D0A4-47DC-A676-788C0ABE1876">
			<ns0:Num>SEC. 3.</ns0:Num>
			<ns0:ActionLine action="IS_AMENDED" ns3:href="urn:caml:codes:CIV:caml#xpointer(%2Fcaml%3ALawDoc%2Fcaml%3ACode%2Fcaml%3ALawHeading%5B%40type%3D'DIVISION'%20and%20caml%3ANum%3D'3.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'PART'%20and%20caml%3ANum%3D'4.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'TITLE'%20and%20caml%3ANum%3D'1.8.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'CHAPTER'%20and%20caml%3ANum%3D'1.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'ARTICLE'%20and%20caml%3ANum%3D'5.'%5D%2Fcaml%3ALawSection%5Bcaml%3ANum%3D'1798.17.'%5D)" ns3:label="fractionType: LAW_SECTION" ns3:type="locator">
				Section 1798.17 of the 
				<ns0:DocName>Civil Code</ns0:DocName>
				 is amended to read:
			</ns0:ActionLine>
			<ns0:Fragment>
				<ns0:LawSection id="id_AC3D9395-0093-4949-999B-C5C31F43FEEA">
					<ns0:Num>1798.17.</ns0:Num>
					<ns0:LawSectionVersion id="id_5F250C99-C09A-4874-BD0C-9CF65D33DE78">
						<ns0:Content>
							<html:p>Each agency shall provide on or with any form used to collect personal information from individuals the notice specified in this section. When contact with the individual is of a regularly recurring nature, an initial notice followed by a periodic notice of not more than one-year intervals shall satisfy this requirement. This requirement is also satisfied by notification to individuals of the availability of the notice in annual tax-related pamphlets or booklets provided for them. The notice shall include all of the following:</html:p>
							<html:p>
								(a)
								<html:span class="EnSpace"/>
								The name of the agency and the division within the agency that is requesting the information.
							</html:p>
							<html:p>
								(b)
								<html:span class="EnSpace"/>
								The title, business address, and telephone number of the agency official who is responsible for the records and who shall, upon request, inform an individual regarding the location of the individual’s records and the categories of any persons who use the information in those records.
							</html:p>
							<html:p>
								(c)
								<html:span class="EnSpace"/>
								The authority, whether granted by statute, regulation, or executive order which authorizes the maintenance of the information.
							</html:p>
							<html:p>
								(d)
								<html:span class="EnSpace"/>
								With respect to each item of information, whether submission of such information is mandatory or voluntary.
							</html:p>
							<html:p>
								(e)
								<html:span class="EnSpace"/>
								The consequences, if any, of not providing all or any part of the requested information.
							</html:p>
							<html:p>
								(f)
								<html:span class="EnSpace"/>
								The purpose or purposes
						within the agency for which the information is to be used.
							</html:p>
							<html:p>
								(g)
								<html:span class="EnSpace"/>
								Any known or foreseeable disclosures which may be made of the information pursuant to subdivision (e) or (f) of Section 1798.24.
							</html:p>
							<html:p>
								(h)
								<html:span class="EnSpace"/>
								The individual’s right of access to records containing personal information which are maintained by the agency.
							</html:p>
							<html:p>This section does not apply to any enforcement document issued by an employee of a law enforcement agency in the performance of the employee’s duties wherein the violator is provided an exact copy of the document, or to accident reports whereby the parties of interest may obtain a copy of the report pursuant to Section 20012 of the Vehicle Code.</html:p>
							<html:p>The notice required by this section does not
						apply to agency requirements for an individual to provide the individual’s name, identifying number, photograph, address, or similar identifying information, if this information is used only for the purpose of identification and communication with the individual by the agency, except that requirements for an individual’s social security number shall conform with the provisions of the Federal Privacy Act of 1974 (Public Law 93-579).</html:p>
						</ns0:Content>
					</ns0:LawSectionVersion>
				</ns0:LawSection>
			</ns0:Fragment>
		</ns0:BillSection>
		<ns0:BillSection id="id_63EA2562-F73A-4DEB-B514-09A6EABBEBDC">
			<ns0:Num>SEC. 4.</ns0:Num>
			<ns0:ActionLine action="IS_AMENDED" ns3:href="urn:caml:codes:CIV:caml#xpointer(%2Fcaml%3ALawDoc%2Fcaml%3ACode%2Fcaml%3ALawHeading%5B%40type%3D'DIVISION'%20and%20caml%3ANum%3D'3.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'PART'%20and%20caml%3ANum%3D'4.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'TITLE'%20and%20caml%3ANum%3D'1.8.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'CHAPTER'%20and%20caml%3ANum%3D'1.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'ARTICLE'%20and%20caml%3ANum%3D'5.'%5D%2Fcaml%3ALawSection%5Bcaml%3ANum%3D'1798.19.'%5D)" ns3:label="fractionType: LAW_SECTION" ns3:type="locator">
				Section 1798.19 of the 
				<ns0:DocName>Civil Code</ns0:DocName>
				 is amended to read:
			</ns0:ActionLine>
			<ns0:Fragment>
				<ns0:LawSection id="id_628328E4-3DAD-4492-8875-96C703CD94F2">
					<ns0:Num>1798.19.</ns0:Num>
					<ns0:LawSectionVersion id="id_6A2B6826-D0BB-4D66-94DF-0EE69D67C0A3">
						<ns0:Content>
							<html:p>Each agency when it provides by contract for the operation or maintenance of records containing personal information to accomplish an agency function, shall cause, consistent with its authority, the requirements of this chapter to be applied to those records. For purposes of Article 10 (commencing with Section 1798.55), any contractor and any employee of the contractor, if the contract is agreed to on or after July 1, 1978, shall be considered to be an employee of an agency.</html:p>
						</ns0:Content>
					</ns0:LawSectionVersion>
				</ns0:LawSection>
			</ns0:Fragment>
		</ns0:BillSection>
		<ns0:BillSection id="id_BDF23FB9-B1EC-4941-B83B-CF1FD898D59E">
			<ns0:Num>SEC. 5.</ns0:Num>
			<ns0:ActionLine action="IS_AMENDED" ns3:href="urn:caml:codes:CIV:caml#xpointer(%2Fcaml%3ALawDoc%2Fcaml%3ACode%2Fcaml%3ALawHeading%5B%40type%3D'DIVISION'%20and%20caml%3ANum%3D'3.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'PART'%20and%20caml%3ANum%3D'4.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'TITLE'%20and%20caml%3ANum%3D'1.8.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'CHAPTER'%20and%20caml%3ANum%3D'1.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'ARTICLE'%20and%20caml%3ANum%3D'5.'%5D%2Fcaml%3ALawSection%5Bcaml%3ANum%3D'1798.20.'%5D)" ns3:label="fractionType: LAW_SECTION" ns3:type="locator">
				Section 1798.20 of the 
				<ns0:DocName>Civil Code</ns0:DocName>
				 is amended to read:
			</ns0:ActionLine>
			<ns0:Fragment>
				<ns0:LawSection id="id_B7DDBC6F-07F1-4F68-98A9-AD727E7C812E">
					<ns0:Num>1798.20.</ns0:Num>
					<ns0:LawSectionVersion id="id_B85F6A7D-6840-478C-A78D-3D53F6F13AEF">
						<ns0:Content>
							<html:p>
								(a)
								<html:span class="EnSpace"/>
								Each agency shall establish rules of conduct for persons involved in the design, development, operation, disclosure, or maintenance of records containing personal information and instruct each such person with respect to such rules and the requirements of this chapter, including any other rules and procedures adopted pursuant to this chapter and the remedies and penalties for noncompliance.
							</html:p>
							<html:p>
								(b)
								<html:span class="EnSpace"/>
								An agency shall not use records containing personal information for any purpose or purposes other than the purpose or purposes for which that personal information was collected, except as authorized or required by state law.
							</html:p>
						</ns0:Content>
					</ns0:LawSectionVersion>
				</ns0:LawSection>
			</ns0:Fragment>
		</ns0:BillSection>
		<ns0:BillSection id="id_76B73C0E-E168-4968-A609-63F04A9B8796">
			<ns0:Num>SEC. 6.</ns0:Num>
			<ns0:ActionLine action="IS_AMENDED" ns3:href="urn:caml:codes:CIV:caml#xpointer(%2Fcaml%3ALawDoc%2Fcaml%3ACode%2Fcaml%3ALawHeading%5B%40type%3D'DIVISION'%20and%20caml%3ANum%3D'3.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'PART'%20and%20caml%3ANum%3D'4.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'TITLE'%20and%20caml%3ANum%3D'1.8.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'CHAPTER'%20and%20caml%3ANum%3D'1.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'ARTICLE'%20and%20caml%3ANum%3D'6.'%5D%2Fcaml%3ALawSection%5Bcaml%3ANum%3D'1798.24.'%5D)" ns3:label="fractionType: LAW_SECTION" ns3:type="locator">
				Section 1798.24 of the 
				<ns0:DocName>Civil Code</ns0:DocName>
				 is amended to read:
			</ns0:ActionLine>
			<ns0:Fragment>
				<ns0:LawSection id="id_D4DAA0FD-9B0D-4D4C-8482-2F3A6433D0EF">
					<ns0:Num>1798.24.</ns0:Num>
					<ns0:LawSectionVersion id="id_C42CD024-BCAC-4151-8B59-6D4C7EF184CD">
						<ns0:Content>
							<html:p>An agency shall not disclose any personal information in a manner that could link the information disclosed to the individual to whom it pertains unless the information is disclosed, as follows:</html:p>
							<html:p>
								(a)
								<html:span class="EnSpace"/>
								To the individual to whom the information pertains.
							</html:p>
							<html:p>
								(b)
								<html:span class="EnSpace"/>
								With the prior written voluntary consent of the individual to whom the information pertains, but only if that consent has been obtained not more than 30 days before the disclosure, or in the time limit agreed to by the individual in the written consent.
							</html:p>
							<html:p>
								(c)
								<html:span class="EnSpace"/>
								To the duly appointed guardian or conservator of the individual or a person
						representing the individual if it can be proven with reasonable certainty through the possession of agency forms, documents, or correspondence that this person is the authorized representative of the individual to whom the information pertains.
							</html:p>
							<html:p>
								(d)
								<html:span class="EnSpace"/>
								To those officers, employees, attorneys, agents, or volunteers of the agency that have custody of the information if the disclosure is relevant and necessary in the ordinary course of the performance of their official duties and furthers the purpose for which the information was acquired.
							</html:p>
							<html:p>
								(e)
								<html:span class="EnSpace"/>
								To a person, or to another agency if the transfer is necessary for the transferee agency to perform its constitutional or statutory duties, and the use furthers the purpose for which the information was collected and the use or transfer is in accordance
						with Section 1798.25. With respect to information transferred from a law enforcement or regulatory agency, or information transferred to another law enforcement or regulatory agency, a use is compatible if the use of the information requested is needed in an investigation of unlawful activity under the jurisdiction of the requesting agency or for licensing, certification, or regulatory purposes by that agency.
							</html:p>
							<html:p>
								(f)
								<html:span class="EnSpace"/>
								To a branch of the federal government if authorized by state law.
							</html:p>
							<html:p>
								(g)
								<html:span class="EnSpace"/>
								Pursuant to the California
						Public Records Act (Division 10 (commencing with Section 7920.000) of Title 1 of the Government Code).
							</html:p>
							<html:p>
								(h)
								<html:span class="EnSpace"/>
								To a person who has provided the agency with advance, adequate written assurance that the information will be used solely for statistical research or reporting purposes, but only if the information to be disclosed is in a form that cannot identify any individual, and the written assurance includes a statement that the person will not attempt to reidentify the information.
							</html:p>
							<html:p>
								(i)
								<html:span class="EnSpace"/>
								Pursuant to a determination by the agency that maintains information that compelling circumstances exist that affect the health or safety of an individual, if upon the disclosure notification is transmitted to the individual to whom the information pertains at the individual’s last known address.
						Disclosure shall not be made if it is in conflict with other state or federal laws.
							</html:p>
							<html:p>
								(j)
								<html:span class="EnSpace"/>
								To the State Archives as a record that has sufficient historical or other value to warrant its continued preservation by the California state government, or for evaluation by the Director of General Services or the director’s designee to determine whether the record has further administrative, legal, or fiscal value.
							</html:p>
							<html:p>
								(k)
								<html:span class="EnSpace"/>
								To any person pursuant to a subpoena, court order, or other compulsory legal process if, before the disclosure, the agency reasonably attempts to notify the individual to whom the record pertains, and if the notification is not prohibited by law.
							</html:p>
							<html:p>
								 (
								<html:i>l</html:i>
								)
								<html:span class="EnSpace"/>
								Pursuant to Article 3 (commencing with Section 1800) of Chapter
						1 of Division 2 of the Vehicle Code.
							</html:p>
							<html:p>
								(m)
								<html:span class="EnSpace"/>
								For the sole purpose of verifying and paying government health care service claims made pursuant to Division 9 (commencing with Section 10000) of the Welfare and Institutions Code.
							</html:p>
							<html:p>
								(n)
								<html:span class="EnSpace"/>
								To another person or governmental organization to the extent necessary to obtain information from the person or governmental organization for an investigation by the agency of a failure to comply with a specific state law that the agency is responsible for enforcing.
							</html:p>
							<html:p>
								(o)
								<html:span class="EnSpace"/>
								To an adopted person and disclosure is limited to general background information pertaining to the adopted person’s biological parents, if the information does not include or reveal the identity of the biological parents.
							</html:p>
							<html:p>
								(p)
								<html:span class="EnSpace"/>
								To a child or a grandchild of an adopted person and disclosure is limited to medically necessary information pertaining to the adopted person’s biological parents. However, the information, or the process for obtaining the information, shall not include or reveal the identity of the biological parents. The State Department of Social Services shall adopt regulations governing the release of information pursuant to this subdivision. The regulations shall require licensed adoption agencies to provide the same services provided by the department as established by this subdivision.
							</html:p>
							<html:p>
								(q)
								<html:span class="EnSpace"/>
								To a committee of the Legislature or to a Member of the Legislature, or the Member of the Legislature’s staff if authorized in writing by the Member of the Legislature if the Member of the
						Legislature has permission to obtain the information from the individual to whom it pertains or if the Member of the Legislature provides reasonable assurance that the Member of the Legislature is acting on behalf of the individual.
							</html:p>
							<html:p>
								(r)
								<html:span class="EnSpace"/>
								(1)
								<html:span class="EnSpace"/>
								To the University of California, a nonprofit educational institution, an established nonprofit research institution performing health or social services research, the Cradle-to-Career Data System, for purposes consistent with the creation and execution of the Cradle-to-Career Data System Act pursuant to Article 2 (commencing with Section 10860) of Chapter 8.5 of Part 7 of Division 1 of Title 1 of the Education Code, or, in the case of education-related data, another nonprofit entity, conducting scientific research, if the request for information is approved by the Committee for the
						Protection of Human Subjects (CPHS) for the California Health and Human Services Agency (CHHSA) or an institutional review board, as authorized in paragraphs (5) and (6). The approval shall include a review and determination that all the following criteria have been satisfied:
							</html:p>
							<html:p>
								(A)
								<html:span class="EnSpace"/>
								The researcher has provided a plan sufficient to protect personal information from improper use and disclosures, including sufficient administrative, physical, and technical safeguards to protect personal information from reasonably anticipated threats to the security or confidentiality of the information.
							</html:p>
							<html:p>
								(B)
								<html:span class="EnSpace"/>
								The researcher has provided a sufficient plan to destroy or return all personal information as soon as it is no longer needed for the research project, unless the researcher has demonstrated an
						ongoing need for the personal information for the research project and has provided a long-term plan sufficient to protect the confidentiality of that information.
							</html:p>
							<html:p>
								(C)
								<html:span class="EnSpace"/>
								The researcher has provided sufficient written assurances that the personal information will not be reused or disclosed to any other person or entity, or used in any manner, not approved in the research protocol, except as required by law or for authorized oversight of the research project.
							</html:p>
							<html:p>
								(2)
								<html:span class="EnSpace"/>
								The CPHS shall enter into a written agreement with the Office of Cradle-to-Career Data, as defined in Section 10862 of the Education Code, to assist the managing entity of that office in its role as the institutional review board for the Cradle-to-Career Data System.
							</html:p>
							<html:p>
								(3)
								<html:span class="EnSpace"/>
								The
						CPHS or institutional review board shall, at a minimum, accomplish all of the following as part of its review and approval of the research project for the purpose of protecting personal information held in agency databases:
							</html:p>
							<html:p>
								(A)
								<html:span class="EnSpace"/>
								Determine whether the requested personal information is needed to conduct the research.
							</html:p>
							<html:p>
								(B)
								<html:span class="EnSpace"/>
								Permit access to personal information only if it is needed for the research project.
							</html:p>
							<html:p>
								(C)
								<html:span class="EnSpace"/>
								Permit access only to the minimum necessary personal information needed for the research project.
							</html:p>
							<html:p>
								(D)
								<html:span class="EnSpace"/>
								Require the assignment of unique subject codes that are not derived from personal information in lieu of social security numbers if the research can
						still be conducted without social security numbers.
							</html:p>
							<html:p>
								(E)
								<html:span class="EnSpace"/>
								If feasible, and if cost, time, and technical expertise permit, require the agency to conduct a portion of the data processing for the researcher to minimize the release of personal information.
							</html:p>
							<html:p>
								(4)
								<html:span class="EnSpace"/>
								Reasonable costs to the agency associated with the agency’s process of protecting personal information under the conditions of CPHS approval may be billed to the researcher, including, but not limited to, the agency’s costs for conducting a portion of the data processing for the researcher, removing personal information, encrypting or otherwise securing personal information, or assigning subject codes.
							</html:p>
							<html:p>
								(5)
								<html:span class="EnSpace"/>
								The CPHS may enter into written agreements to enable other institutional
						review boards to provide the data security approvals required by this subdivision, if the data security requirements set forth in this subdivision are satisfied.
							</html:p>
							<html:p>
								(6)
								<html:span class="EnSpace"/>
								Pursuant to paragraph (5), the CPHS shall enter into a written agreement with the institutional review board established pursuant to former Section 49079.6 of the Education Code. The agreement shall authorize, commencing July 1, 2010, or the date upon which the written agreement is executed, whichever is later, that board to provide the data security approvals required by this subdivision, if the data security requirements set forth in this subdivision and the act specified in subdivision (a) of Section 49079.5 of the Education Code are satisfied.
							</html:p>
							<html:p>
								(s)
								<html:span class="EnSpace"/>
								To an insurer if authorized by Chapter 5 (commencing with Section
						10900) of Division 4 of the Vehicle Code.
							</html:p>
							<html:p>
								(t)
								<html:span class="EnSpace"/>
								Pursuant to Section 450, 452, 8009, or 18396 of the Financial Code.
							</html:p>
							<html:p>
								(u)
								<html:span class="EnSpace"/>
								For the sole purpose of participation in interstate data sharing of prescription drug monitoring program information pursuant to the California Uniform Controlled Substances Act (Division 10 (commencing with Section 11000) of the Health and Safety Code), if disclosure is limited to prescription drug monitoring program information.
							</html:p>
							<html:p>This article does not require the disclosure of personal information to the individual to whom the information pertains if that information may otherwise be withheld as set forth in Section 1798.40.</html:p>
						</ns0:Content>
					</ns0:LawSectionVersion>
				</ns0:LawSection>
			</ns0:Fragment>
		</ns0:BillSection>
		<ns0:BillSection id="id_DABD9362-167D-4930-890E-CC0C42FB2300">
			<ns0:Num>SEC. 7.</ns0:Num>
			<ns0:ActionLine action="IS_AMENDED" ns3:href="urn:caml:codes:CIV:caml#xpointer(%2Fcaml%3ALawDoc%2Fcaml%3ACode%2Fcaml%3ALawHeading%5B%40type%3D'DIVISION'%20and%20caml%3ANum%3D'3.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'PART'%20and%20caml%3ANum%3D'4.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'TITLE'%20and%20caml%3ANum%3D'1.8.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'CHAPTER'%20and%20caml%3ANum%3D'1.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'ARTICLE'%20and%20caml%3ANum%3D'6.'%5D%2Fcaml%3ALawSection%5Bcaml%3ANum%3D'1798.24b.'%5D)" ns3:label="fractionType: LAW_SECTION" ns3:type="locator">
				Section 1798.24b of the 
				<ns0:DocName>Civil Code</ns0:DocName>
				 is amended to read:
			</ns0:ActionLine>
			<ns0:Fragment>
				<ns0:LawSection id="id_6FA04817-D771-4294-A026-07830E91F0BC">
					<ns0:Num>1798.24b.</ns0:Num>
					<ns0:LawSectionVersion id="id_583269EB-56D0-414B-A9AD-7D3460A40B40">
						<ns0:Content>
							<html:p>
								(a)
								<html:span class="EnSpace"/>
								Notwithstanding Section 1798.24, except subdivision (t) thereof, information shall be disclosed to the protection and advocacy agency designated by the Governor in this state pursuant to federal law to protect and advocate for the rights of people with disabilities, as described in Division 4.7 (commencing with Section 4900) of the Welfare and Institutions Code.
							</html:p>
							<html:p>
								(b)
								<html:span class="EnSpace"/>
								Information that shall be disclosed pursuant to this section includes all of the following information:
							</html:p>
							<html:p>
								(1)
								<html:span class="EnSpace"/>
								Name.
							</html:p>
							<html:p>
								(2)
								<html:span class="EnSpace"/>
								Address.
							</html:p>
							<html:p>
								(3)
								<html:span class="EnSpace"/>
								Telephone number.
							</html:p>
							<html:p>
								(4)
								<html:span class="EnSpace"/>
								Any other information necessary to identify that person whose consent is necessary for either of the following purposes:
							</html:p>
							<html:p>
								(A)
								<html:span class="EnSpace"/>
								To enable the protection and advocacy agency to exercise its authority and investigate incidents of abuse or neglect of people with disabilities.
							</html:p>
							<html:p>
								(B)
								<html:span class="EnSpace"/>
								To obtain access to records pursuant to Section 4903 of the Welfare and Institutions Code.
							</html:p>
						</ns0:Content>
					</ns0:LawSectionVersion>
				</ns0:LawSection>
			</ns0:Fragment>
		</ns0:BillSection>
		<ns0:BillSection id="id_09D4826B-CC7B-4169-804A-24ECC33E5549">
			<ns0:Num>SEC. 8.</ns0:Num>
			<ns0:ActionLine action="IS_AMENDED" ns3:href="urn:caml:codes:CIV:caml#xpointer(%2Fcaml%3ALawDoc%2Fcaml%3ACode%2Fcaml%3ALawHeading%5B%40type%3D'DIVISION'%20and%20caml%3ANum%3D'3.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'PART'%20and%20caml%3ANum%3D'4.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'TITLE'%20and%20caml%3ANum%3D'1.8.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'CHAPTER'%20and%20caml%3ANum%3D'1.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'ARTICLE'%20and%20caml%3ANum%3D'7.'%5D%2Fcaml%3ALawSection%5Bcaml%3ANum%3D'1798.25.'%5D)" ns3:label="fractionType: LAW_SECTION" ns3:type="locator">
				Section 1798.25 of the 
				<ns0:DocName>Civil Code</ns0:DocName>
				 is amended to read:
			</ns0:ActionLine>
			<ns0:Fragment>
				<ns0:LawSection id="id_AC07A345-B566-4589-9668-09A637615959">
					<ns0:Num>1798.25.</ns0:Num>
					<ns0:LawSectionVersion id="id_F03EFF2A-6920-4AD2-98D6-302B8579AC39">
						<ns0:Content>
							<html:p>
								(a)
								<html:span class="EnSpace"/>
								Each agency shall keep an accurate accounting of the date, nature, and purpose of each disclosure of a record made pursuant to subdivision (i), (k), or (n) of Section 1798.24. This accounting shall also be required for disclosures made pursuant to subdivision (e) or (f) of Section 1798.24 unless notice of the type of disclosure has been provided pursuant to Sections 1798.9 and 1798.10. The accounting shall also include the name, title, and business address of the person or agency to whom the disclosure was made.
							</html:p>
							<html:p>
								(b)
								<html:span class="EnSpace"/>
								Routine disclosures of information pertaining to crimes, offenders, and suspected offenders to law enforcement or regulatory agencies of federal, state, and local
						government shall be deemed to be disclosures pursuant to subdivision (e) of Section 1798.24 for the purpose of meeting this requirement.
							</html:p>
						</ns0:Content>
					</ns0:LawSectionVersion>
				</ns0:LawSection>
			</ns0:Fragment>
		</ns0:BillSection>
		<ns0:BillSection id="id_F973484B-270A-42D0-BF27-88DFC30DB608">
			<ns0:Num>SEC. 9.</ns0:Num>
			<ns0:ActionLine action="IS_AMENDED" ns3:href="urn:caml:codes:CIV:caml#xpointer(%2Fcaml%3ALawDoc%2Fcaml%3ACode%2Fcaml%3ALawHeading%5B%40type%3D'DIVISION'%20and%20caml%3ANum%3D'3.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'PART'%20and%20caml%3ANum%3D'4.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'TITLE'%20and%20caml%3ANum%3D'1.8.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'CHAPTER'%20and%20caml%3ANum%3D'1.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'ARTICLE'%20and%20caml%3ANum%3D'7.'%5D%2Fcaml%3ALawSection%5Bcaml%3ANum%3D'1798.26.'%5D)" ns3:label="fractionType: LAW_SECTION" ns3:type="locator">
				Section 1798.26 of the 
				<ns0:DocName>Civil Code</ns0:DocName>
				 is amended to read:
			</ns0:ActionLine>
			<ns0:Fragment>
				<ns0:LawSection id="id_42C24D05-911C-4C02-BC23-AB22D3C8E511">
					<ns0:Num>1798.26.</ns0:Num>
					<ns0:LawSectionVersion id="id_496B564D-D3FE-4BCD-BF4F-564819E19C4B">
						<ns0:Content>
							<html:p>With respect to the sale of information concerning the registration of any vehicle or the sale of information from the files of drivers’ licenses, the Department of Motor Vehicles shall, by regulation, establish administrative procedures under which any person making a request for information shall be required to identify themselves and state the reason for making the request. These procedures shall provide for the verification of the name and address of the person making a request for the information and the department may require the person to produce the information as it determines is necessary in order to ensure that the name and address of the person are their true name and address. These procedures may provide for a 10-day
						delay in the release of the requested information. These procedures shall also provide for notification to the person to whom the information relates, as to what information was provided and to whom it was provided. The department shall, by regulation, establish a reasonable period of time for which a record of all the foregoing shall be maintained.</html:p>
							<html:p>The procedures required by this subdivision do not apply to any governmental entity, any person who has applied for and has been issued a requester code by the department, or any court of competent jurisdiction.</html:p>
						</ns0:Content>
					</ns0:LawSectionVersion>
				</ns0:LawSection>
			</ns0:Fragment>
		</ns0:BillSection>
		<ns0:BillSection id="id_2A3F6AAD-1102-40E9-8585-0981902DAA4F">
			<ns0:Num>SEC. 10.</ns0:Num>
			<ns0:ActionLine action="IS_AMENDED" ns3:href="urn:caml:codes:CIV:caml#xpointer(%2Fcaml%3ALawDoc%2Fcaml%3ACode%2Fcaml%3ALawHeading%5B%40type%3D'DIVISION'%20and%20caml%3ANum%3D'3.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'PART'%20and%20caml%3ANum%3D'4.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'TITLE'%20and%20caml%3ANum%3D'1.8.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'CHAPTER'%20and%20caml%3ANum%3D'1.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'ARTICLE'%20and%20caml%3ANum%3D'7.'%5D%2Fcaml%3ALawSection%5Bcaml%3ANum%3D'1798.27.'%5D)" ns3:label="fractionType: LAW_SECTION" ns3:type="locator">
				Section 1798.27 of the 
				<ns0:DocName>Civil Code</ns0:DocName>
				 is amended to read:
			</ns0:ActionLine>
			<ns0:Fragment>
				<ns0:LawSection id="id_66B4CB29-C76B-4431-8065-84FBE5EE97FF">
					<ns0:Num>1798.27.</ns0:Num>
					<ns0:LawSectionVersion id="id_5E867BCE-02CF-450C-9A52-5480CA20AC7C">
						<ns0:Content>
							<html:p>Each agency shall retain the accounting made pursuant to Section 1798.25 for at least three years after the disclosure for which the accounting is made.</html:p>
							<html:p>Nothing in this section shall be construed to require retention of the original documents for a three-year period, providing that the agency can otherwise comply with the requirements of this section.</html:p>
						</ns0:Content>
					</ns0:LawSectionVersion>
				</ns0:LawSection>
			</ns0:Fragment>
		</ns0:BillSection>
		<ns0:BillSection id="id_EB10FB19-B027-43E7-B188-FCFDB150B6C3">
			<ns0:Num>SEC. 11.</ns0:Num>
			<ns0:ActionLine action="IS_AMENDED" ns3:href="urn:caml:codes:CIV:caml#xpointer(%2Fcaml%3ALawDoc%2Fcaml%3ACode%2Fcaml%3ALawHeading%5B%40type%3D'DIVISION'%20and%20caml%3ANum%3D'3.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'PART'%20and%20caml%3ANum%3D'4.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'TITLE'%20and%20caml%3ANum%3D'1.8.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'CHAPTER'%20and%20caml%3ANum%3D'1.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'ARTICLE'%20and%20caml%3ANum%3D'7.'%5D%2Fcaml%3ALawSection%5Bcaml%3ANum%3D'1798.29.'%5D)" ns3:label="fractionType: LAW_SECTION" ns3:type="locator">
				Section 1798.29 of the 
				<ns0:DocName>Civil Code</ns0:DocName>
				 is amended to read:
			</ns0:ActionLine>
			<ns0:Fragment>
				<ns0:LawSection id="id_BE9042ED-3B67-4109-A2D0-ED7B951562A6">
					<ns0:Num>1798.29.</ns0:Num>
					<ns0:LawSectionVersion id="id_16BD347F-75A5-465B-9871-8EB848ACB3C9">
						<ns0:Content>
							<html:p>
								(a)
								<html:span class="EnSpace"/>
								Any agency that owns or licenses computerized data that includes personal information shall disclose any breach of the security of the system following discovery or notification of the breach in the security of the data to any resident of California (1) whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person, or, (2) whose encrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person and the encryption key or security credential was, or is reasonably believed to have been, acquired by an unauthorized person and the agency that owns or licenses the encrypted information has a reasonable belief that the encryption key or
						security credential could render that personal information readable or usable. The disclosure shall be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement, as provided in subdivision (c), or any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system.
							</html:p>
							<html:p>
								(b)
								<html:span class="EnSpace"/>
								Any agency that maintains computerized data that includes personal information that the agency does not own shall notify the owner or licensee of the information of any breach of the security of the data immediately following discovery, if the personal information was, or is reasonably believed to have been, acquired by an unauthorized person.
							</html:p>
							<html:p>
								(c)
								<html:span class="EnSpace"/>
								The notification required by this section may be
						delayed if a law enforcement agency determines that the notification will impede a criminal investigation. The notification required by this section shall be made after the law enforcement agency determines that it will not compromise the investigation.
							</html:p>
							<html:p>
								(d)
								<html:span class="EnSpace"/>
								Any agency that is required to issue a security breach notification pursuant to this section shall meet all of the following requirements:
							</html:p>
							<html:p>
								(1)
								<html:span class="EnSpace"/>
								The security breach notification shall be written in plain language, shall be titled “Notice of Data Breach,” and shall present the information described in paragraph (2) under the following headings: “What Happened,” “What Information Was Involved,” “What We Are Doing,” “What You Can Do,” and “For More Information.” Additional information may be provided as a supplement to the
						notice.
							</html:p>
							<html:p>
								(A)
								<html:span class="EnSpace"/>
								The format of the notice shall be designed to call attention to the nature and significance of the information it contains.
							</html:p>
							<html:p>
								(B)
								<html:span class="EnSpace"/>
								The title and headings in the notice shall be clearly and conspicuously displayed.
							</html:p>
							<html:p>
								(C)
								<html:span class="EnSpace"/>
								The text of the notice and any other notice provided pursuant to this section shall be no smaller than 10-point type.
							</html:p>
							<html:p>
								(D)
								<html:span class="EnSpace"/>
								For a written notice described in paragraph (1) of subdivision (i), use of the model security breach notification form prescribed below or use of the headings described in this paragraph with the information described in paragraph (2), written in plain language, shall be deemed to be in compliance with this subdivision.
							</html:p>
							<html:table border="0" frame="box" rules="all" width="1050">
								<html:tbody>
									<html:tr>
										<html:td align="left" class="Left10Point" colspan="3" height="29" valign="top" width="10%">
											<html:span class="ThinSpace"/>
											<html:p>
												[NAME OF INSTITUTION / LOGO] 
												<html:span class="ThinSpace"/>
												<html:span class="SpacedLeaders"/>
												<html:span class="SpacedLeaders"/>
												<html:span class="ThinSpace"/>
												Date: [insert date]
											</html:p>
											<html:span class="ThinSpace"/>
										</html:td>
									</html:tr>
									<html:tr>
										<html:td align="left" colspan="3" width="100">
											<html:span class="ThinSpace"/>
											<html:p class="Center10Point">NOTICE OF DATA BREACH</html:p>
											<html:span class="ThinSpace"/>
										</html:td>
									</html:tr>
									<html:tr>
										<html:td colspan="2" height="60" width="100">
											<html:br/>
											<html:br/>
											<html:p class="Center10Point">What Happened?</html:p>
											<html:br/>
											<html:br/>
											<html:br/>
											 
										</html:td>
										<html:td height="60" width="581"/>
									</html:tr>
									<html:tr>
										<html:td colspan="2" height="50" width="100">
											<html:br/>
											<html:br/>
											<html:p class="Center10Point">What Information Was Involved?</html:p>
											<html:br/>
											<html:br/>
											<html:br/>
										</html:td>
										<html:td height="50" width="581"/>
									</html:tr>
									<html:tr>
										<html:td colspan="2" height="60" width="100">
											<html:br/>
											<html:br/>
											<html:p class="Center10Point">What We Are Doing.</html:p>
											<html:br/>
											<html:br/>
											<html:br/>
										</html:td>
										<html:td height="60" width="581"/>
									</html:tr>
									<html:tr>
										<html:td class="Right10Point" colspan="2" height="60" width="100">
											<html:br/>
											<html:br/>
											<html:p class="Center10Point">What You Can Do.</html:p>
											<html:br/>
											<html:br/>
											<html:br/>
											 
										</html:td>
										<html:td height="60" width="581"/>
									</html:tr>
									<html:tr>
										<html:td colspan="3" height="250" valign="top" width="100">
											<html:p class="Left10Point">Other Important Information.</html:p>
											<html:p class="Left10Point">[insert other important information]</html:p>
											<html:br/>
											<html:br/>
											<html:br/>
											<html:br/>
											<html:br/>
											<html:br/>
											<html:br/>
											<html:br/>
										</html:td>
									</html:tr>
									<html:tr>
										<html:td colspan="2" height="100" width="100">
											<html:br/>
											<html:p class="Left10Point">For More Information.</html:p>
											<html:br/>
											<html:br/>
										</html:td>
										<html:td height="100" width="600%">
											<html:p class="Left10Point">Call [telephone number] or go to [internet website]</html:p>
										</html:td>
									</html:tr>
								</html:tbody>
							</html:table>
							<html:br/>
							<html:p>
								(E)
								<html:span class="EnSpace"/>
								For an electronic notice described in paragraph (2) of subdivision (i), use of the headings described in this paragraph with the information described in paragraph (2), written in plain language, shall be deemed to be in compliance with this subdivision.
							</html:p>
							<html:p>
								(2)
								<html:span class="EnSpace"/>
								The security breach notification described in paragraph (1) shall include, at a minimum, the following information:
							</html:p>
							<html:p>
								(A)
								<html:span class="EnSpace"/>
								The name and contact information of the reporting agency subject to this section.
							</html:p>
							<html:p>
								(B)
								<html:span class="EnSpace"/>
								A list of the types of personal information that were or are reasonably believed to have been the subject of a breach.
							</html:p>
							<html:p>
								(C)
								<html:span class="EnSpace"/>
								If the information is possible to determine at the time the notice is provided, then any of the following: (i) the date of the breach, (ii) the estimated date of the breach, or (iii) the date range within which the breach occurred. The notification shall also include the date of the notice.
							</html:p>
							<html:p>
								(D)
								<html:span class="EnSpace"/>
								Whether the notification was delayed as a result of a law enforcement investigation, if that information is possible to determine at the time the notice is provided.
							</html:p>
							<html:p>
								(E)
								<html:span class="EnSpace"/>
								A general description of the breach incident, if that information is possible to determine at the time the notice is provided.
							</html:p>
							<html:p>
								(F)
								<html:span class="EnSpace"/>
								The toll-free telephone numbers and addresses of the major credit reporting agencies, if the breach exposed a social
						security number or a driver’s license or California identification card number.
							</html:p>
							<html:p>
								(3)
								<html:span class="EnSpace"/>
								At the discretion of the agency, the security breach notification may also include any of the following:
							</html:p>
							<html:p>
								(A)
								<html:span class="EnSpace"/>
								Information about what the agency has done to protect individuals whose information has been breached.
							</html:p>
							<html:p>
								(B)
								<html:span class="EnSpace"/>
								Advice on steps that people whose information has been breached may take to protect themselves.
							</html:p>
							<html:p>
								(e)
								<html:span class="EnSpace"/>
								Any agency that is required to issue a security breach notification pursuant to this section to more than 500 California residents as a result of a single breach of the security system shall electronically submit a single sample copy of that security breach notification,
						excluding any personally identifiable information, to the Attorney General. A single sample copy of a security breach notification shall not be deemed to be within Article 1 (commencing with Section 7923.600) of Chapter 1 of Part 5 of Division 10 of Title 1 of the Government Code.
							</html:p>
							<html:p>
								(f)
								<html:span class="EnSpace"/>
								For purposes of this section, “breach of the security of the system” means unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information maintained by the agency. Good faith acquisition of personal information by an employee or agent of the agency for the purposes of the agency is not a breach of the security of the system, provided that the personal information is not used or subject to further unauthorized disclosure.
							</html:p>
							<html:p>
								(g)
								<html:span class="EnSpace"/>
								For
						purposes of this section, “personal information” means either of the following:
							</html:p>
							<html:p>
								(1)
								<html:span class="EnSpace"/>
								“Personal information” as defined in subdivision (a) of Section 1798.3.
							</html:p>
							<html:p>
								(2)
								<html:span class="EnSpace"/>
								A username or email address, in combination with a password or security question and answer that would permit access to an online account.
							</html:p>
							<html:p>
								(h)
								<html:span class="EnSpace"/>
								(1)
								<html:span class="EnSpace"/>
								For purposes of this section, “personal information” does not include publicly available information that is lawfully made available to the general public from federal, state, or local government records.
							</html:p>
							<html:p>
								(2)
								<html:span class="EnSpace"/>
								For purposes of this section, “medical information” means any information regarding an individual’s medical history, mental or physical condition, or medical treatment or diagnosis by a health care
						professional.
							</html:p>
							<html:p>
								(3)
								<html:span class="EnSpace"/>
								For purposes of this section, “health insurance information” means an individual’s health insurance policy number or subscriber identification number, any unique identifier used by a health insurer to identify the individual, or any information in an individual’s application and claims history, including any appeals records.
							</html:p>
							<html:p>
								(4)
								<html:span class="EnSpace"/>
								For purposes of this section, “encrypted” means rendered unusable, unreadable, or indecipherable to an unauthorized person through a security technology or methodology generally accepted in the field of information security.
							</html:p>
							<html:p>
								(5)
								<html:span class="EnSpace"/>
								For purposes of this section, “genetic data” means any data, regardless of its format, that results from the analysis of a biological sample of an
						individual, or from another source enabling equivalent information to be obtained, and concerns genetic material. Genetic material includes, but is not limited to, deoxyribonucleic acids (DNA), ribonucleic acids (RNA), genes, chromosomes, alleles, genomes, alterations or modifications to DNA or RNA, single nucleotide polymorphisms (SNPs), uninterpreted data that results from analysis of the biological sample or other source, and any information extrapolated, derived, or inferred therefrom.
							</html:p>
							<html:p>
								(i)
								<html:span class="EnSpace"/>
								For purposes of this section, “notice” may be provided by one of the following methods:
							</html:p>
							<html:p>
								(1)
								<html:span class="EnSpace"/>
								Written notice.
							</html:p>
							<html:p>
								(2)
								<html:span class="EnSpace"/>
								Electronic notice, if the notice provided is consistent with the provisions regarding electronic records and
						signatures set forth in Section 7001 of Title 15 of the United States Code.
							</html:p>
							<html:p>
								(3)
								<html:span class="EnSpace"/>
								Substitute notice, if the agency demonstrates that the cost of providing notice would exceed two hundred fifty thousand dollars ($250,000), or that the affected class of subject persons to be notified exceeds 500,000, or the agency does not have sufficient contact information. Substitute notice shall consist of all of the following:
							</html:p>
							<html:p>
								(A)
								<html:span class="EnSpace"/>
								Email notice when the agency has email addresses for the subject persons.
							</html:p>
							<html:p>
								(B)
								<html:span class="EnSpace"/>
								Conspicuous posting, for a minimum of 30 days, of the notice on the agency’s internet website, if the agency maintains one. For purposes of this subparagraph, conspicuous posting on the agency’s internet website means providing a
						link to the notice on the home page or first significant page after entering the internet website that is in larger type than the surrounding text, or in contrasting type, font, or color to the surrounding text of the same size, or set off from the surrounding text of the same size by symbols or other marks that call attention to the link.
							</html:p>
							<html:p>
								(C)
								<html:span class="EnSpace"/>
								Notification to major statewide media and the Office of
						Information Security within the Department of Technology.
							</html:p>
							<html:p>
								(4)
								<html:span class="EnSpace"/>
								In the case of a breach of the security of the system involving personal information defined in paragraph (2) of subdivision (g) for an online account, and no other personal information defined in paragraph (1) of subdivision (g), the agency may comply with this section by providing the security breach notification in electronic or other form that directs the person whose personal information has been breached to promptly change the person’s password and security question or answer, as applicable, or to take other steps appropriate to protect the online account with the agency and all other online accounts for which the person uses the same username or email address and password or security question or answer.
							</html:p>
							<html:p>
								(5)
								<html:span class="EnSpace"/>
								In the case of a breach of the security of the system involving personal information defined in paragraph (2) of subdivision (g) for login credentials of an email account furnished by the agency, the agency shall not comply with this section by providing the security breach notification to that email address, but may, instead, comply with this section by providing notice by another method described in this subdivision or by clear and conspicuous notice delivered to the resident online when the resident is connected to the online account from an Internet Protocol address or online location from which the agency knows the resident customarily accesses the account.
							</html:p>
							<html:p>
								(j)
								<html:span class="EnSpace"/>
								Notwithstanding subdivision (i), an agency that maintains its own notification procedures as part of an information security policy for the treatment of personal
						information and is otherwise consistent with the timing requirements of this part shall be deemed to be in compliance with the notification requirements of this section if it notifies subject persons in accordance with its policies in the event of a breach of security of the system.
							</html:p>
							<html:p>
								(k)
								<html:span class="EnSpace"/>
								For purposes of this section, “encryption key” and “security credential” mean the confidential key or process designed to render the data usable, readable, and decipherable.
							</html:p>
							<html:p>
								(l)
								<html:span class="EnSpace"/>
								Notwithstanding any other law, the State Bar of California shall comply with this section. This subdivision shall not be construed to apply other provisions of this chapter to the State Bar.
							</html:p>
						</ns0:Content>
					</ns0:LawSectionVersion>
				</ns0:LawSection>
			</ns0:Fragment>
		</ns0:BillSection>
		<ns0:BillSection id="id_0FD96698-FD4F-46CC-A843-1E244473DF29">
			<ns0:Num>SEC. 12.</ns0:Num>
			<ns0:ActionLine action="IS_AMENDED" ns3:href="urn:caml:codes:CIV:caml#xpointer(%2Fcaml%3ALawDoc%2Fcaml%3ACode%2Fcaml%3ALawHeading%5B%40type%3D'DIVISION'%20and%20caml%3ANum%3D'3.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'PART'%20and%20caml%3ANum%3D'4.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'TITLE'%20and%20caml%3ANum%3D'1.8.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'CHAPTER'%20and%20caml%3ANum%3D'1.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'ARTICLE'%20and%20caml%3ANum%3D'8.'%5D%2Fcaml%3ALawSection%5Bcaml%3ANum%3D'1798.44.'%5D)" ns3:label="fractionType: LAW_SECTION" ns3:type="locator">
				Section 1798.44 of the 
				<ns0:DocName>Civil Code</ns0:DocName>
				 is amended to read:
			</ns0:ActionLine>
			<ns0:Fragment>
				<ns0:LawSection id="id_9642D46B-CEED-4A12-942E-FB599DCBC31F">
					<ns0:Num>1798.44.</ns0:Num>
					<ns0:LawSectionVersion id="id_3B1C8DE4-3A51-4D98-B726-BABE70BB6557">
						<ns0:Content>
							<html:p>This article applies to the rights of an individual to whom personal information pertains and not to the authority or right of any other person, agency, agency of another state, or branch of the federal government to obtain this information.</html:p>
						</ns0:Content>
					</ns0:LawSectionVersion>
				</ns0:LawSection>
			</ns0:Fragment>
		</ns0:BillSection>
		<ns0:BillSection id="id_02F54236-7130-4B11-8E9B-5325A1E0E052">
			<ns0:Num>SEC. 13.</ns0:Num>
			<ns0:ActionLine action="IS_AMENDED" ns3:href="urn:caml:codes:CIV:caml#xpointer(%2Fcaml%3ALawDoc%2Fcaml%3ACode%2Fcaml%3ALawHeading%5B%40type%3D'DIVISION'%20and%20caml%3ANum%3D'3.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'PART'%20and%20caml%3ANum%3D'4.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'TITLE'%20and%20caml%3ANum%3D'1.8.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'CHAPTER'%20and%20caml%3ANum%3D'1.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'ARTICLE'%20and%20caml%3ANum%3D'10.'%5D%2Fcaml%3ALawSection%5Bcaml%3ANum%3D'1798.55.'%5D)" ns3:label="fractionType: LAW_SECTION" ns3:type="locator">
				Section 1798.55 of the 
				<ns0:DocName>Civil Code</ns0:DocName>
				 is amended to read:
			</ns0:ActionLine>
			<ns0:Fragment>
				<ns0:LawSection id="id_0EFBB002-1007-4316-8B95-3DAFBF56C600">
					<ns0:Num>1798.55.</ns0:Num>
					<ns0:LawSectionVersion id="id_4A80EB24-7EBD-4FB5-82AE-D0B6B0AE5D89">
						<ns0:Content>
							<html:p>The intentional or negligent violation of any provision of this chapter or of any rules or regulations adopted thereunder, by an officer or employee of any agency shall constitute a cause for discipline, including termination of employment.</html:p>
						</ns0:Content>
					</ns0:LawSectionVersion>
				</ns0:LawSection>
			</ns0:Fragment>
		</ns0:BillSection>
		<ns0:BillSection id="id_4D48B7DF-EEE2-46A9-97FC-10DDEB64A0BD">
			<ns0:Num>SEC. 14.</ns0:Num>
			<ns0:ActionLine action="IS_AMENDED" ns3:href="urn:caml:codes:CIV:caml#xpointer(%2Fcaml%3ALawDoc%2Fcaml%3ACode%2Fcaml%3ALawHeading%5B%40type%3D'DIVISION'%20and%20caml%3ANum%3D'3.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'PART'%20and%20caml%3ANum%3D'4.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'TITLE'%20and%20caml%3ANum%3D'1.8.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'CHAPTER'%20and%20caml%3ANum%3D'1.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'ARTICLE'%20and%20caml%3ANum%3D'10.'%5D%2Fcaml%3ALawSection%5Bcaml%3ANum%3D'1798.57.'%5D)" ns3:label="fractionType: LAW_SECTION" ns3:type="locator">
				Section 1798.57 of the 
				<ns0:DocName>Civil Code</ns0:DocName>
				 is amended to read:
			</ns0:ActionLine>
			<ns0:Fragment>
				<ns0:LawSection id="id_064D2B08-4A26-4DF9-A545-6CAF636B48BB">
					<ns0:Num>1798.57.</ns0:Num>
					<ns0:LawSectionVersion id="id_61904169-E92C-466E-94D1-9F26B9712D04">
						<ns0:Content>
							<html:p>Except for disclosures which are otherwise required or permitted by law, the intentional disclosure of medical, psychiatric, or psychological information in violation of the disclosure provisions of this chapter is punishable as a misdemeanor.</html:p>
						</ns0:Content>
					</ns0:LawSectionVersion>
				</ns0:LawSection>
			</ns0:Fragment>
		</ns0:BillSection>
		<ns0:BillSection id="id_D02B9D3B-3B05-4222-90C4-53DC865A7CC0">
			<ns0:Num>SEC. 15.</ns0:Num>
			<ns0:ActionLine action="IS_AMENDED" ns3:href="urn:caml:codes:CIV:caml#xpointer(%2Fcaml%3ALawDoc%2Fcaml%3ACode%2Fcaml%3ALawHeading%5B%40type%3D'DIVISION'%20and%20caml%3ANum%3D'3.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'PART'%20and%20caml%3ANum%3D'4.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'TITLE'%20and%20caml%3ANum%3D'1.8.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'CHAPTER'%20and%20caml%3ANum%3D'1.'%5D%2Fcaml%3ALawHeading%5B%40type%3D'ARTICLE'%20and%20caml%3ANum%3D'11.'%5D%2Fcaml%3ALawSection%5Bcaml%3ANum%3D'1798.68.'%5D)" ns3:label="fractionType: LAW_SECTION" ns3:type="locator">
				Section 1798.68 of the 
				<ns0:DocName>Civil Code</ns0:DocName>
				 is amended to read:
			</ns0:ActionLine>
			<ns0:Fragment>
				<ns0:LawSection id="id_9CBAD55B-68C9-4957-8C6A-94670938DC2B">
					<ns0:Num>1798.68.</ns0:Num>
					<ns0:LawSectionVersion id="id_DBF8DE9B-E2B2-4668-967F-C863F885A5C7">
						<ns0:Content>
							<html:p>
								(a)
								<html:span class="EnSpace"/>
								Information which is permitted to be disclosed under the provisions of subdivision (e) or (f) of Section 1798.24 shall be provided when requested by a district attorney.
							</html:p>
							<html:p>A district attorney may petition a court of competent jurisdiction to require disclosure of information when an agency fails or refuses to provide the requested information within 10 working days of a request. The court may require the agency to permit inspection unless the public interest or good cause in withholding such records clearly outweighs the public interest in disclosure.</html:p>
							<html:p>
								(b)
								<html:span class="EnSpace"/>
								Disclosure of information to a district attorney under
						the provisions of this chapter shall effect no change in the status of the records under any other provision of law.
							</html:p>
						</ns0:Content>
					</ns0:LawSectionVersion>
				</ns0:LawSection>
			</ns0:Fragment>
		</ns0:BillSection>
		<ns0:BillSection id="id_8841B602-C6D7-406F-A297-E9635DDAD49F">
			<ns0:Num>SEC. 16.</ns0:Num>
			<ns0:Content>
				<html:p>The Legislature finds and declares that Sections 1 and 6 of this act, which amend Sections 1798.3 and 1798.24 of the Civil Code, imposes a limitation on the public’s right of access to the meetings of public bodies or the writings of public officials and agencies within the meaning of Section 3 of Article I of the California Constitution. Pursuant to that constitutional provision, the Legislature makes the following findings to demonstrate the interest protected by this limitation and the need for protecting that interest:</html:p>
				<html:p>By modernizing provisions of the Information Practices Act of 1977 to address the effects of advances in information technology on
				the scope and sensitivity of personal information collected, maintained, and disseminated by state agencies, this act balances the right to access information concerning the conduct of the people’s business with the individual right to privacy.</html:p>
			</ns0:Content>
		</ns0:BillSection>
		<ns0:BillSection id="id_C675EDA1-4E96-426B-99EE-45F6392B89F7">
			<ns0:Num>SEC. 17.</ns0:Num>
			<ns0:Content>
				<html:p>
					No reimbursement is required by this act pursuant to Section 6 of Article XIII
					<html:span class="ThinSpace"/>
					B of the California Constitution for certain costs that may be incurred by a local agency or school district because, in that regard, this act creates a new crime or infraction, eliminates a crime or infraction, or changes the penalty for a crime or infraction, within the meaning of Section 17556 of the Government Code, or changes the definition of a crime within the meaning of Section 6 of Article XIII
					<html:span class="ThinSpace"/>
					B of the California Constitution.
				</html:p>
				<html:p>However, if the Commission on State Mandates determines that this act contains other costs
				mandated by the state, reimbursement to local agencies and school districts for those costs shall be made pursuant to Part 7 (commencing with Section 17500) of Division 4 of Title 2 of the Government Code.</html:p>
			</ns0:Content>
		</ns0:BillSection>
	</ns0:Bill>
</ns0:MeasureDoc>
Last Version Text Digest Existing law, the Information Practices Act of 1977, prescribes a set of requirements, prohibitions, and remedies applicable to agencies, as defined, with regard to their collection, storage, and disclosure of personal information, as defined. Existing law exempts from the provisions of the act counties, cities, any city and county, school districts, municipal corporations, districts, political subdivisions, and other local public agencies, as specified. Existing law requires an agency to establish rules of conduct for persons involved in the design, development, operation, disclosure, or maintenance of records containing personal information and instruct those persons with respect to specified rules relevant to the act. This bill would prohibit an agency from using records containing personal information for any purpose or purposes other than the purpose or purposes for which that personal information was collected, except as required or authorized by state law. Existing law prohibits an agency from disclosing any personal information in a manner that would link the information disclosed to the individual to whom it pertains, except under specified circumstances. This bill would revise the circumstances that may allow the disclosure of personal information in a manner that could link the information disclosed to the individual to whom it pertains, and would make conforming changes. Existing law makes an intentional violation of any provision of the act, or of any rules or regulations adopted under the act, by an officer or employee of any agency a cause for discipline, including termination of employment. This bill would also make a negligent violation of the act a cause for discipline. Existing law provides that the intentional disclosure of medical, psychiatric, or psychological information in violation of the disclosure provisions of the act, that is not otherwise permitted by law, is punishable as a misdemeanor if the wrongful disclosure results in economic loss or personal injury to the individual to whom the information pertains. Existing constitutional provisions require that a statute that limits the right of access to the meetings of public bodies or the writings of public officials and agencies be adopted with findings demonstrating the interest protected by the limitation and the need for protecting that interest. This bill would make legislative findings to that effect. This bill would provide that with regard to certain mandates no reimbursement is required by this act for a specified reason.