California
SB361
SB361 - Data brokers: data collection and deletion.
Source: Congress.gov ·
3,239 words in original text
Plain English summary not yet available
The full original text is available below. Check back soon as we process this bill.
Senate Bill No. 361 CHAPTER 466 An act to amend Sections 1798.99.82, 1798.99.84, and 1798.99.86 of the Civil Code, relating to privacy. [ Approved by Governor October 08, 2025. Filed with Secretary of State October 08, 2025. ] LEGISLATIVE COUNSEL'S DIGEST SB 361, Becker. Data brokers: data collection and deletion. The California Consumer Privacy Act of 2018 (CCPA) grants a consumer various rights with respect to personal information that is collected or sold by a business, including the right to request that a business disclose specified information that has been collected about the consumer, to request that a business delete personal information about the consumer that the business has collected from the consumer, and to direct a business not to sell or share the consumer’s personal information, as specified. The CCPA defines various terms for these purposes. The California Privacy Rights Act of 2020 (CPRA), approved by the voters as Proposition 24 at the November 3, 2020, statewide general election, amended, added to, and reenacted the CCPA and establishes the California Privacy Protection Agency (agency) and vests the agency with full administrative power, authority, and jurisdiction to enforce the CCPA. Existing law requires a data broker to register with the agency, and defines “data broker” to mean a business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship, subject to specified exceptions. Existing law requires a data broker, in registering with the agency, to pay a registration fee in an amount determined by the agency and provide specified information, including, among other things, the name of the data broker and its primary physical, email, and internet website addresses, and whether the data broker collects the personal information of minors, consumers’ precise geolocation, or consumers’ reproductive health care data. This bill would require a data broker to provide additional information to the agency, including whether the data broker collects consumers’ names, dates of birth, ZIP Codes, email addresses, phone numbers, login or account information, various government identification numbers, mobile advertising, connected television, or vehicle identification numbers, citizenship data, union membership status, sexual orientation status, gender identity and gender expression data, biometric data, and up to 3, but no fewer than one, of the most common types of personal information that the data broker collects, as provided. The bill would also require a data broker to provide information regarding whether, in the past year, the data broker shared or sold consumers’ data to a foreign actor, as defined, the federal government, other state governments, law enforcement, as provided, or a developer of a GenAI system, as defined. The bill would make changes to the administrative fines and costs that apply to data brokers who fail to register. Existing law requires, beginning January 1, 2026, the California Privacy Protection Agency to establish an accessible deletion mechanism that, among other things, allows a consumer, through a single verifiable consumer request, to request that every data broker that maintains any personal information delete any personal information related to that consumer held by the data broker or associated service provider or contractor. Existing law requires, beginning August 1, 2026, a data broker to access the accessible deletion mechanism at least once every 45 days and, among other things, process a denied request to delete personal information as an opt-out of the sale or sharing of the consumer’s personal information under the CCPA, as specified. This bill would require a data broker to process the above-described denied request within 45 days of receiving the request. Existing law requires the agency to create a page on its internet website where registration information provided by data brokers and the accessible deletion mechanism is accessible to the public. This bill would prohibit the agency from making accessible to the public on its internet website information regarding whether the data broker collects consumers’ names, dates of birth, zip codes, email addresses, phone numbers, mobile advertising, connected television, or vehicle identification numbers, and the most common types of personal information that it collects. This bill would declare that it furthers the purposes and intent of the CPRA for specified reasons. Digest Key Vote: MAJORITY Appropriation: NO Fiscal Committee: YES Local Program: NO Bill Text The people of the State of California do enact as follows: SECTION 1. Section 1798.99.82 of the Civil Code is amended to read: 1798.99.82. (a) On or before January 31 following each year in which a business meets the definition of data broker as provided in this title, the business shall register with the California Privacy Protection Agency pursuant to the requirements of this section. (b) In registering with the California Privacy Protection Agency, as described in subdivision (a), a data broker shall do all of the following: (1) Pay a registration fee in an amount determined by the California Privacy Protection Agency, not to exceed the reasonable costs of establishing and maintaining the informational internet website described in Section 1798.99.84 and the reasonable costs of establishing, maintaining, and providing access to the accessible deletion mechanism described in Section 1798.99.86. Registration fees shall be deposited in the Data Brokers’ Registry Fund, created within the State Treasury pursuant to Section 1798.99.81, and used for the purposes outlined in this paragraph. (2) Provide the following information: (A) The name of the data broker and its primary physical, email, and internet website addresses. (B) The metrics compiled pursuant to paragraphs (1) and (2) of subdivision (a) of Section 1798.99.85. (C) Whether the data broker collects the personal information of minors. (D) Whether the data broker collects consumers’ names, dates of birth, ZIP Codes, email addresses, or phone numbers. (E) Whether the data broker collects consumers’ account login or account number in combination with any required security code, access code, or password that would permit access to a consumer’s account with a third party. (F) Whether the data broker collects consumers’ drivers’ license number, California identification card number, tax identification number, social security number, passport number, military identification number, or other unique identification number issued on a government document commonly used to verify the identity of a specific individual. (G) Whether the data broker collects consumers’ mobile advertising identification numbers, connected television identification numbers, or vehicle identification numbers (VIN). (H) Whether the data broker collects consumers’ citizenship data, including immigration status. (I) Whether the data broker collects consumers’ union membership status. (J) Whether the data broker collects consumers’ sexual orientation status. (K) Whether the data broker collects consumers’ gender identity and gender expression data. (L) Whether the data broker collects consumers’ biometric data. (M) Whether the data broker collects consumers’ precise geolocation. (N) Whether the data broker collects consumers’ reproductive health care data. (O) Whether the data broker has shared or sold consumers’ data to a foreign actor in the past year. (P) Whether the data broker has shared or sold consumers’ data to the federal government in the past year. (Q) Whether the data broker has shared or sold consumers’ data to other state governments in the past year. (R) Whether the data broker has shared or sold consumers’ data to law enforcement in the past year, unless that data was shared pursuant to a subpoena or court order. (S) Whether the data broker has shared or sold consumers’ data to a developer of a GenAI system or model in the past year. (T) Up to three, but no fewer than one, of the most common types of personal information that the data broker collects, if the data broker does not collect the information described in subparagraphs (D) and (G). (U) Beginning January 1, 2029, whether the data broker has undergone an audit as described in subdivision (e) of Section 1798.99.86, and, if so, the most recent year that the data broker has submitted a report resulting from the audit and any related materials to the California Privacy Protection Agency. (V) A link to a page on the data broker’s internet website that does both of the following: (i) Details how consumers may exercise their privacy rights by doing all of the following: (I) Deleting personal information, as described in Section 1798.105. (II) Correcting inaccurate personal information, as described in Section 1798.106. (III) Learning what personal information is being collected and how to access that personal information, as described in Section 1798.110. (IV) Learning what personal information is being sold or shared and to whom, as described in Section 1798.115. (V) Learning how to opt out of the sale or sharing of personal information, as described in Section 1798.120. (VI) Learning how to limit the use and disclosure of sensitive personal information, as described in Section 1798.121. (ii) Does not make use of any dark patterns. (W) Whether and to what extent the data broker or any of its subsidiaries is regulated by any of the following: (i) The federal Fair Credit Reporting Act (15 U.S.C. Sec. 1681 et seq.). (ii) The Gramm-Leach-Bliley Act (Public Law 106-102) and implementing regulations. (iii) The Insurance Information and Privacy Protection Act (Article 6.6 (commencing with Section 791) of Chapter 1 of Part 2 of Division 1 of the Insurance Code). (iv) The Confidentiality of Medical Information Act (Part 2.6 (commencing with Section 56) of Division 1) or the privacy, security, and breach notification rules issued by the United States Department of Health and Human Services, Parts 160 and 164 of Title 45 of the Code of Federal Regulations, established pursuant to the federal Health Insurance Portability and Accountability Act of 1996 (Public Law 104-191). (X) Any additional information or explanation the data broker chooses to provide concerning its data collection practices. (c) A data broker that fails to register as required by this section is liable for administrative fines and costs in an administrative action brought by the California Privacy Protection Agency as follows: (1) An administrative fine of two hundred dollars ($200) for each day the data broker fails to register as required by this section. (2) An amount equal to the fees that were due during the period it failed to register. (3) Reasonable expenses incurred by the California Privacy Protection Agency in the investigation and administration of the action. (d) A data broker required to register under this title that fails to comply with the requirements of Section 1798.99.86 is liable for administrative fines and costs in an administrative action brought by the California Privacy Protection Agency as follows: (1) An administrative fine of two hundred dollars ($200) for each deletion request for each day the data broker fails to delete information as required by Section 1798.99.86. (2) Reasonable expenses incurred by the California Privacy Protection Agency in the investigation and administration of the action. (e) Any penalties, fines, fees, and expenses recovered in an action prosecuted under subdivision (c) or (d) shall be deposited in the Data Brokers’ Registry Fund, created within the State Treasury pursuant to Section 1798.99.81, with the intent that they be used to fully offset costs incurred by the state courts and the California Privacy Protection Agency in connection with this title. (f) For purposes of this section, the following definitions apply: (1) (A) “Foreign actor” means either of the following: (i) The government of a foreign adversary country. (ii) A partnership, association, corporation, organization, or other combination of persons organized under the laws of or having its principal place of business in a foreign adversary country. (B) For purposes of subparagraph (A), “foreign adversary country” has the same meaning as “covered nation” as defined in Section 4872 of Title 10 of the United States Code. (2) “Developer of a GenAI system” means a business, person, partnership, corporation, or other entity that designs, codes, produces, or substantially modifies a GenAI system. (3) “Generative artificial intelligence system” or “GenAI system” means an artificial intelligence that can generate derived synthetic content, including text, images, video, and audio, that emulates the structure and characteristics of the system’s training data. SEC. 2. Section 1798.99.84 of the Civil Code is amended to read: 1798.99.84. (a) The California Privacy Protection Agency shall create a page on its internet website where the registration information provided by data brokers described in paragraph (2) of subdivision (b) of Section 1798.99.82, except as provided in subdivision (b), and the accessible deletion mechanism described in Section 1798.99.86 shall be accessible to the public. (b) Information provided by a data broker pursuant to subparagraphs (D), (G), and (T) of paragraph (2) of subdivision (b) of Section 1798.99.82 shall not be made accessible to the public on the California Privacy Protection Agency’s internet website. SEC. 3. Section 1798.99.86 of the Civil Code is amended to read: 1798.99.86. (a) By January 1, 2026, the California Privacy Protection Agency shall establish an accessible deletion mechanism that does all of the following: (1) Implements and maintains reasonable security procedures and practices, including, but not limited to, administrative, physical, and technical safeguards appropriate to the nature of the information and the purposes for which the personal information will be used and to protect consumers’ personal information from unauthorized use, disclosure, access, destruction, or modification. (2) Allows a consumer, through a single verifiable consumer request, to request that every data broker that maintains any personal information delete any personal information related to that consumer held by the data broker or associated service provider or contractor. (3) Allows a consumer to selectively exclude specific data brokers from a request made under paragraph (2). (4) Allows a consumer to make a request to alter a previous request made under this subdivision after at least 45 days have passed since the consumer last made a request under this subdivision. (b) The accessible deletion mechanism established pursuant to subdivision (a) shall meet all of the following requirements: (1) The accessible deletion mechanism shall allow a consumer to request the deletion of all perso
[Text truncated for display. Full text available on Congress.gov.]
Important: This plain English summary was generated by AI and is provided for informational purposes only.
It is not legal advice. Always consult the official bill text on Congress.gov
or a qualified attorney for legal matters.