Reasonable security for personal information (Customer Records)
Data Security (1798.81.5)
Data security
Requires businesses holding Californians' personal information (names with SSNs, ID numbers, financial account data, medical and health insurance data, biometrics, genetic data, or online credentials) to use reasonable security, and to require the same by contract of third parties they share it with.
- Where
- California
- Citation
- Cal. Civ. Code 1798.81.5
- Status
- In force
- In force since
- 2004-01-01
- Last amended
- 2022-01-01
- Enforced by
- California Attorney General; private plaintiffs
- People can sue
- Yes
- Penalties
- Injured customers may sue for damages and injunctive relief (1798.84). A breach caused by failing this duty can also support CCPA statutory damages under 1798.150.
- Applies to
- Businesses that own, license, or maintain personal information about California residents
- Exempts CMIA-regulated health providers, CalFIPA financial institutions, HIPAA covered entities, certain DMV data recipients, and businesses under stronger laws (1798.81.5(e))
Security duties
- Implement and maintain reasonable security procedures and practices appropriate to the nature of the information.Cal. Civ. Code 1798.81.5(b)
- Contractually require nonaffiliated third parties receiving the information to maintain reasonable security.Cal. Civ. Code 1798.81.5(c)
Sources
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Unverified: Original effective date (Jan. 1, 2004, AB 1950) is from background knowledge; leginfo shows the latest amendment (AB 825, effective Jan. 1, 2022).
Research reference, not legal advice.