Law / United States / California

Customer Records Act, Reasonable Security Procedures

Cal. Civ. Code section 1798.81.5, as amended by AB 825 (2021, Ch. 527)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 1 January 2022.

A security baseline statutes rule binding private bodies.

As of 12 September 2026.

What it requires

  • This binds a business that owns, licenses, or maintains personal information about a California resident, and by contract extends the same duty to a nonaffiliated third party the business discloses that information to; it exempts a health care provider, plan, or contractor already regulated by the Confidentiality of Medical Information Act, a financial institution subject to the California Financial Information Privacy Act, a HIPAA covered entity as to HIPAA-regulated activity, and a business already subject to state or federal law providing greater protection on the same subject, deemed compliant with this duty instead.
  • Implement and maintain reasonable security procedures and practices appropriate to the nature of the personal information you own, license, or maintain, to protect it from unauthorized access, destruction, use, modification, or disclosure.
  • Covered personal information reaches a name paired with a Social Security, driver's license, state ID, passport, military ID, or tax ID number, a financial account or payment card number with its access code, medical or health insurance information, unique biometric data used to authenticate a person, genetic data, or a username or email address paired with a password or security question that unlocks an online account.
  • A customer injured by a violation of this duty may bring a civil action for damages under Civil Code section 1798.84(b); where the violation is a breach of nonencrypted or nonredacted personal information, the CCPA/CPRA's own statutory-damages private right of action, Civil Code section 1798.150, is a separate and further remedy, researched as this jurisdiction's privacy row.

If you get it wrong

Criminal exposureNo

Private right of actionYes

Who enforces it

Enforcement body

Civil Code 1798.81.5 names no dedicated regulator. Civil Code 1798.84(b), within the same title, gives an injured customer a civil action for damages.

What it reaches

Obligation class

Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

A business that owns, licenses, or maintains personal information about a California resident must implement and maintain reasonable security procedures and practices appropriate to the nature of the information, to protect it from unauthorized access, destruction, use, modification, or disclosure; where the business instead discloses that information to a nonaffiliated third party by contract, it must require the same standard of the third party by contract.

Covered personal information reaches a California resident's name paired with a Social Security, driver's license, state identification, passport, military identification, or tax identification number, a financial account or payment card number together with its access code, medical information, health insurance information, unique biometric data used to authenticate a specific individual, genetic data, or a username or email address paired with a password or security question that would permit access to an online account.

The duty exempts a health care provider, health plan, or contractor already regulated by the Confidentiality of Medical Information Act, a financial institution subject to the California Financial Information Privacy Act, a HIPAA covered entity as to HIPAA-regulated medical privacy and security rules, an entity receiving Vehicle Code confidentiality-protected information, and a business already subject to state or federal law that provides greater protection to personal information on the same subject, which is deemed compliant instead.

Civil Code section 1798.84(b), within the same Customer Records title, gives a customer injured by a violation of this duty a civil action to recover damages, with no statutory cap of its own. The $500 to $3,000 per-violation civil penalty that section 1798.84(c) provides is reserved, by its own terms, for a violation of section 1798.83's Shine the Light disclosure duty rather than a violation of this section.

Where the violation is a breach of nonencrypted or nonredacted personal information, the CCPA/CPRA's own statutory-damages private right of action, Civil Code section 1798.150, is a further and separate remedy, already researched as this jurisdiction's privacy row.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • serves_minors
  • operates_social_platform
  • ships_mobile_app
  • distributes_software_product

Read the law

Official statute text, California Legislative Information, Civil Code Title 1.81

Back to the example  ·  Lint your app