Ca_Law

statute | California

Civil Code - CIV - CIV § 1798.29

Summary

(a) Any agency that owns or licenses computerized data that includes personal information shall disclose any breach of the security of the system following discovery or notification of the breach in the security of the data to any resident of California (1) whose unencrypted pers

Text

Retrieval chunks

  • #1 | Civil Code - CIV - CIV § 1798.29

    (a) Any agency that owns or licenses computerized data that includes personal information shall disclose any breach of the security of the system following discovery or notification of the breach in the security of the data to any resident of California (1) whose unencrypted personal information was, or is reasonably…

  • #2

    The title and headings in the notice shall be clearly and conspicuously displayed. (C) The text of the notice and any other notice provided pursuant to this section shall be no smaller than 10-point type. (D) For a written notice described in paragraph (1) of subdivision (i), use of the model security breach notif…

  • #3

    Advice on steps that people whose information has been breached may take to protect themselves. (e) Any agency that is required to issue a security breach notification pursuant to this section to more than 500 California residents as a result of a single breach of the security system shall electronically submit a si…

  • #4

    (2) A username or email address, in combination with a password or security question and answer that would permit access to an online account. (h) (1) For purposes of this section, “personal information” does not include publicly available information that is lawfully made available to the general public from fede…

  • #5

    Email notice when the agency has an email address for the subject persons. (B) Conspicuous posting, for a minimum of 30 days, of the notice on the agency’s internet website, if the agency maintains one. For purposes of this subparagraph, conspicuous posting on the agency’s internet website means providing a link to …

  • #6

    Notwithstanding subdivision (i), an agency that maintains its own notification procedures as part of an information security policy for the treatment of personal information and is otherwise consistent with the timing requirements of this part shall be deemed to be in compliance with the notification requirements of t…