California
SB354
SB354 - Insurance Information and Privacy Protection Act.
Source: Congress.gov ·
27,652 words in original text
Plain English summary not yet available
The full original text is available below. Check back soon as we process this bill.
Amended IN Assembly August 21, 2026 Amended IN Assembly August 13, 2026 Amended IN Assembly June 26, 2026 Amended IN Assembly June 11, 2026 Amended IN Assembly May 27, 2026 Amended IN Assembly April 15, 2026 Amended IN Senate May 23, 2025 Amended IN Senate May 01, 2025 Amended IN Senate April 03, 2025 Amended IN Senate March 18, 2025 CALIFORNIA LEGISLATURE— 2025–2026 REGULAR SESSION Senate Bill No. 354 Introduced by Senator Limón February 12, 2025 An act to add Section 791.30 to, and to repeal and add Article 6.6 (commencing with Section 791) of Chapter 1 of Part 2 of Division 1 of, the Insurance Code, relating to insurance. LEGISLATIVE COUNSEL'S DIGEST SB 354, as amended, Limón. Insurance Information and Privacy Protection Act. The California Consumer Privacy Act of 2018 (CCPA) grants to a consumer various rights with respect to personal information that is collected by a business, including the right to request that a business delete personal information about the consumer that the business has collected from the consumer. The California Privacy Rights Act of 2020, an initiative measure approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA. Existing law, the Insurance Information and Privacy Protection Act, establishes privacy standards for the collection, use, and disclosure of information gathered in connection with insurance transactions by insurance institutions, agents, and insurance-support organizations. The Insurance Information and Privacy Protection Act imposes various monetary penalties for violations of the act and makes a person who knowingly and willfully obtains information about an individual from an insurance institution, agent, or insurance-support organization under false pretenses guilty of a misdemeanor. On and after July 1, 2028, this bill would revise the Insurance Information and Privacy Protection Act to establish new standards for the collection, processing, retaining, or processing and sharing of consumers’ personal information by insurance licensees, surplus line insurers, reinsurers, and third-party service providers. The bill would authorize processing or sharing of a consumer’s personal information for specified purposes, including sharing in connection with an insurance transaction. The bill would require a licensee, surplus line insurer, reinsurer, or third-party service provider to provide a clear and conspicuous privacy notice presented as a stand-alone document that includes specified information to a consumer within a specified period of time, and would prohibit the sharing of a consumer’s personal information unless it is reasonably necessary and proportionate to achieve specified purposes related to an insurance transaction or another purpose that is fully disclosed to the consumer and to which the consumer has consented. The bill would also require a licensee to provide a privacy rights notice, as specified, to each consumer with whom the licensee has an ongoing business relationship. The bill would require a licensee, surplus line insurer, reinsurer, or third-party service provider to obtain a consumer’s consent to take specified actions, and would set forth the means by which consent is obtained. The bill would authorize a licensee, surplus line insurer, or reinsurer to retain personal information, as specified, and would require a licensee, surplus line insurer, or reinsurer to develop a written records retention policy and schedule. The bill would require a licensee, surplus line insurer, or reinsurer to provide specified information to a consumer if it makes an adverse underwriting decision, and would provide a process by which a consumer may access, correct, amend, or delete any personal information about the consumer in the possession of the licensee, surplus line insurer, reinsurer, or its third-party service providers. The bill would require a contract between a licensee, surplus line insurer, or reinsurer and a third-party service provider to govern the processing and sharing of personal information performed on behalf of the licensee, surplus line insurer, or reinsurer. The bill would prohibit retaliation against a consumer because the consumer exercised or attempted to exercise their rights under the act. The bill would prohibit public disclosure of specified systems, processes, policies, procedures, and plans that are disclosed to the Insurance Commissioner. The bill would also make technical and conforming changes. This bill would authorize a penalty of at least $5,000, not to exceed $1,000,000 in the aggregate for multiple violations of the act. The bill would increase the fine if a cease and desist order is violated to at least $15,000 for each violation, and would increase a fine to at least $50,000 for each violation if the commissioner finds the violations to be a general business practice. Under the bill, a person who knowingly and willfully obtains information about a consumer from a licensee, surplus line insurer, reinsurer, or third-party service provider under false pretenses would be guilty of a misdemeanor, punishable by a fine of up to $50,000, imprisonment in a county jail for up to 6 months, or both, thus expanding the applicability of a crime and imposing a state-mandated local program. Existing constitutional provisions require that a statute that limits the right of access to the meetings of public bodies or the writings of public officials and agencies be adopted with findings demonstrating the interest protected by the limitation and the need for protecting that interest. This bill would make legislative findings to that effect. This bill would incorporate additional changes to Sections 791.07, 791.11, and 791.12 of the Insurance Code proposed by AB 1798 to be operative only if this bill and AB 1798 are enacted and this bill is enacted last. The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state. Statutory provisions establish procedures for making that reimbursement. This bill would provide that no reimbursement is required by this act for a specified reason. Digest Key Vote: MAJORITY Appropriation: NO Fiscal Committee: YES Local Program: YES Bill Text The people of the State of California do enact as follows: SECTION 1. (a) The Legislature finds and declares all of the following: (1) In 1972, California voters amended the California Constitution to include the right of privacy among the “inalienable” rights of all people. Voters acted in response to the accelerating encroachment on personal freedom and security caused by increased data collection and usage in contemporary society. The amendment established a legal and enforceable constitutional right of privacy for every Californian. Fundamental to this right of privacy is the ability of individuals to control the use, including the sale, of their personal information. (2) A major milestone in consumer privacy occurred in 2018, when more than 629,000 California voters signed petitions to qualify the California Consumer Privacy Act of 2018 (CCPA) for the ballot. In response to the measure’s qualification, the Legislature enacted the CCPA into law. The CCPA gives California consumers the right to learn what information a business has collected about them, to delete their personal information, to stop businesses from selling their personal information, including using it to target them with advertisements that follow them as they browse the internet from one internet website to another, and to hold businesses accountable if they do not take reasonable steps to safeguard their personal information. (3) Even before the CCPA took effect, the Legislature considered many bills in 2019 to amend the law, some of which would have significantly weakened it. In response, the proponents of the CCPA qualified for the ballot Proposition 24, the California Privacy Rights Act of 2020, which expanded upon the rights granted under the CCPA, and expressly extended the application of the act to licensees. In November 2020, voters approved Proposition 24 by a significant margin, with nearly 9,400,000 votes cast in support. (4) Despite the mention of insurance business in Proposition 24, California’s insurance privacy laws, last adopted in 1980 and 2002, continue to be decades out of date and lag behind the broadly applicable privacy laws. These legacy laws are not suited to protect insurance consumers, given the data-intensive nature of the insurance business, and the increasingly complex manner in which insurance businesses collect and use information about consumers. (5) Privacy is vitally important in the context of the insurance business. More than almost any other industry, insurers require significant amounts of personal information from consumers to properly manage risks. Increasingly, insurance licensees are using sophisticated technologies to collect and process consumers’ personal information, which has increased the volume and sensitivity of personal information that licensees collect about consumers. Developments in insurance business structures have led to increasingly complex contracting arrangements between licensees and service providers, with the attendant risk in supply chain data breaches. However, California’s outdated insurance privacy laws have not kept pace with the changing insurance marketplace. There is a significant lack of oversight into how much data licensees collect, what purposes it can be used for, who it can be shared with, and how long it can be retained. (6) The absence of effective oversight leaves consumers vulnerable. Currently, consumers are presented with privacy notices that are confusing and uninformative, and may also be subject to the overcollection of their personal information, proliferation of that information to recipients not contemplated by the consumer, unwanted marketing contacts, fraud arising from data breaches, underwriting based on data that is stale or unrepresentative, or retaliation for exercising privacy rights, among other risks. (b) It is the intent of the Legislature that this act addresses the gaps in consumer protections and gives the Insurance Commissioner and the Department of Insurance powerful tools to protect consumer privacy, as follows: (1) Data minimization: ensures that licensees are only collecting personal information related to the insurance transaction requested by reasonable and proportionate to the purposes disclosed to the consumer. (2) Record retention and destruction: ensures that licensees securely destroy personal information that is no longer needed. (3) Oversight of third-party service provider arrangements: ensures that contractual arrangements between licensees and vendors provide for the security of consumers’ personal information, and that the information will only be used for the service provided by the licensee. (4) Opt in: ensures that consumers’ personal information will primarily be used to provide the insurance product requested by the consumer, and will not be used for other purposes without the express consent of in ways that are reasonable and proportionate to the purposes disclosed to the consumer. (5) Limitation on sensitive personal information: ensures that consumers’ sensitive personal information will only be used to provide the insurance product requested by the consumer. (6) Notices to consumers: includes reasonable notice requirements to provide consumers with meaningful information about what information is collected, how it is used, to whom it is disclosed, and what rights the consumer has under the law. (7) Transparency: ensures that consumers understand how their personal information will be used and have the opportunity to control the use processing and sharing of their personal information for purposes other than the an insurance transaction. (8) Governance processes and procedures on data use: ensures that licensees establish and follow protocols to protect consumers’ personal information and provide data breach notifications. (9) Access and nonretaliation: ensures that consumers have reasonable access to their privacy rights and are not penalized for exercising those rights. (c) By enacting this act, the Legislature intends to provide consumers with reasonable privacy protections that address the demands of an information-intensive insurance business climate. (d) The Legislature finds and declares that this act furthers the purpose and intent of the California Privacy Rights Act of 2020. SEC. 2. Article 6.6 (commencing with Section 791) is added to Chapter 1 of Part 2 of Division 1 of the Insurance Code, to read: Article 6.6. Insurance Information and Privacy Protection Act 791. The purpose of this article is to establish standards for the collection, processing, retaining, or sharing, use, storage, disclosure, analysis, deletion, retention, or modification of personal information, collectively known as “processing,” “processing” and “sharing” of consumers’ personal information by licensees, surplus line insurers, reinsurers, and their third-party service providers to maintain a balance between the need for information by those conducting the business of insurance and consumers’ need for fairness and protection in the processing or sharing of consumers’ personal information. These standards address the need to do all of the following: (a) Protect consumers’ personal information processed or shared by licensees, surplus line insurers, reinsurers, or their third-party service providers. (b) Inform consumers of the categories of personal information that are processed. processed or shared. (c) Inform consumers of the categories of sources from which consumers’ personal information is collected, and identify recipients when that information is shared. (d) Permit consumers to choose whether or not to opt in to the sharing of their personal information by licensees, surplus line insurers, or reinsurers for purposes other than insurance transactions in certain circumstances. (e) Permit individual consumers to request access to their personal information to verify or dispute the accuracy of the information. (f) Inform consumers of the reasons for adverse underwriting decisions. (g) Require data minimization practices for all licensees, surplus line insurers, reinsurers, and their third-party service providers in the processing of consumers’ personal information. (h) Provide accountability for the improper processing or sharing of consumers’ personal information by licensees, surplus line insurers, reinsurers, and their third-party service providers in violation of this article. 791.01. (a) (1) The obligations imposed by this article shall apply to a licensee, surplus line insurer, or reinsurer. (2) The obligations imposed by this article shall apply to a licensee’s, surplus line insurer’s, or reinsurer’s third-party service providers to th
[Text truncated for display. Full text available on Congress.gov.]
Important: This plain English summary was generated by AI and is provided for informational purposes only.
It is not legal advice. Always consult the official bill text on Congress.gov
or a qualified attorney for legal matters.