Security of Connected Devices (IoT security law)
IoT Security (SB 327)
Data security
Requires makers of internet-connected devices to build in reasonable security features suited to the device and the data it handles. A unique preprogrammed password per device, or forcing the user to set new credentials at first use, satisfies the rule for remote authentication, as does meeting a NIST-conforming labeling scheme.
- Where
- California
- Citation
- Cal. Civ. Code 1798.91.04-1798.91.06 (Title 1.81.26)
- Status
- In force
- In force since
- 2020-01-01
- Last amended
- 2023-01-01
- Enforced by
- California Attorney General, city attorneys, county counsel, and district attorneys (exclusive; 1798.91.06(e))
- People can sue
- No
- Penalties
- No penalty amount stated in the title; public enforcement only, no private right of action (1798.91.06(e)).
- Applies to
- Manufacturers of connected devices sold or offered for sale in California
Security duties
- Equip connected devices with reasonable security features appropriate to the device and its data.Cal. Civ. Code 1798.91.04(a)
- For devices with remote authentication, use a unique preprogrammed password per device or require the user to create new credentials before first access.Cal. Civ. Code 1798.91.04(b)
- Alternatively, meet the baseline criteria, conformity assessment, and label of a NIST-conforming labeling scheme.Cal. Civ. Code 1798.91.04(c)
Sources
- Official text
- Cal. Civ. Code 1798.91.04 (California Legislative Information)
- Cal. Civ. Code 1798.91.06 (operative Jan. 1, 2020; enforcement)
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Unverified: AB 2392 (Stats. 2022, Ch. 785) amendment presumed effective Jan. 1, 2023.
Research reference, not legal advice.