Privacy Law Library

Reasonable security for personal information (Customer Records)

Data Security (1798.81.5)

Data security

Requires businesses holding Californians' personal information (names with SSNs, ID numbers, financial account data, medical and health insurance data, biometrics, genetic data, or online credentials) to use reasonable security, and to require the same by contract of third parties they share it with.

Where
California
Citation
Cal. Civ. Code 1798.81.5
Status
In force
In force since
2004-01-01
Last amended
2022-01-01
Enforced by
California Attorney General; private plaintiffs
People can sue
Yes
Penalties
Injured customers may sue for damages and injunctive relief (1798.84). A breach caused by failing this duty can also support CCPA statutory damages under 1798.150.
Applies to
  • Businesses that own, license, or maintain personal information about California residents
  • Exempts CMIA-regulated health providers, CalFIPA financial institutions, HIPAA covered entities, certain DMV data recipients, and businesses under stronger laws (1798.81.5(e))

Security duties

  • Implement and maintain reasonable security procedures and practices appropriate to the nature of the information.Cal. Civ. Code 1798.81.5(b)
  • Contractually require nonaffiliated third parties receiving the information to maintain reasonable security.Cal. Civ. Code 1798.81.5(c)

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Unverified: Original effective date (Jan. 1, 2004, AB 1950) is from background knowledge; leginfo shows the latest amendment (AB 825, effective Jan. 1, 2022).

Research reference, not legal advice.