Privacy Law Library

Security of Connected Devices (IoT security law)

IoT Security (SB 327)

Data security

Requires makers of internet-connected devices to build in reasonable security features suited to the device and the data it handles. A unique preprogrammed password per device, or forcing the user to set new credentials at first use, satisfies the rule for remote authentication, as does meeting a NIST-conforming labeling scheme.

Where
California
Citation
Cal. Civ. Code 1798.91.04-1798.91.06 (Title 1.81.26)
Status
In force
In force since
2020-01-01
Last amended
2023-01-01
Enforced by
California Attorney General, city attorneys, county counsel, and district attorneys (exclusive; 1798.91.06(e))
People can sue
No
Penalties
No penalty amount stated in the title; public enforcement only, no private right of action (1798.91.06(e)).
Applies to
  • Manufacturers of connected devices sold or offered for sale in California

Security duties

  • Equip connected devices with reasonable security features appropriate to the device and its data.Cal. Civ. Code 1798.91.04(a)
  • For devices with remote authentication, use a unique preprogrammed password per device or require the user to create new credentials before first access.Cal. Civ. Code 1798.91.04(b)
  • Alternatively, meet the baseline criteria, conformity assessment, and label of a NIST-conforming labeling scheme.Cal. Civ. Code 1798.91.04(c)

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Unverified: AB 2392 (Stats. 2022, Ch. 785) amendment presumed effective Jan. 1, 2023.

Research reference, not legal advice.