Law / United States / California

Security of Connected Devices

Cal. Civ. Code sections 1798.91.04-1798.91.06 (Title 1.81.26, added by Stats. 2018, Ch. 860 (AB 1906) and Ch. 886 (SB 327); sections 1798.91.04 and 1798.91.05 amended by Stats. 2022, Ch. 785 (AB 2392))

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 1 January 2023.

A product security requirements rule binding private bodies.

As of 12 September 2026.

What it requires

  • This binds a manufacturer of a physical connected device, a device or other physical object capable of connecting to the internet, directly or indirectly, and assigned an internet protocol or Bluetooth address, that is sold or offered for sale in California; it does not by itself reach a developer who publishes only an app or other software with no connected device of its own, and it does not reach unaffiliated third-party software or apps a user chooses to add to someone else's device.
  • Equip the device with a security feature or features appropriate to its nature, function, and the information it may collect, contain, or transmit, designed to protect the device and that information from unauthorized access, destruction, use, modification, or disclosure.
  • Where the device authenticates outside a local area network, give each unit a unique preprogrammed password or require the user to generate a new means of authentication before first use; meeting a NIST-conforming Internet of Things cybersecurity labeling scheme's baseline criteria and conformity assessment is an alternative way to satisfy the duty.
  • The duty does not apply to a connected device already subject to security requirements under federal law, regulation, or federal agency guidance, or to an activity already regulated by HIPAA or California's Confidentiality of Medical Information Act.
  • There is no private right of action for a violation; only the Attorney General, a city attorney, a county counsel, or a district attorney may enforce this title.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Who enforces it

Enforcement body

The Attorney General, a city attorney, a county counsel, or a district attorney, given exclusive authority to enforce this title; the statute names no other regulator and no penalty amount of its own.

What it reaches

Obligation class

Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

A manufacturer of a connected device, any device or other physical object capable of connecting to the internet, directly or indirectly, and assigned an internet protocol or Bluetooth address, that is sold or offered for sale in California, must equip the device with a reasonable security feature or features appropriate to the device's nature and function and to the information it may collect, contain, or transmit, designed to protect the device and any information in it from unauthorized access, destruction, use, modification, or disclosure.

Where a connected device authenticates outside a local area network, the statute deems that duty met if the device's preprogrammed password is unique to each unit manufactured, or the device requires the user to generate a new means of authentication before first use; a manufacturer may instead satisfy the duty by meeting or exceeding the baseline criteria of a NIST-conforming Internet of Things cybersecurity labeling scheme and completing that scheme's conformity assessment.

The duty does not reach unaffiliated third-party software or applications a user chooses to add to someone else's connected device. It also imposes no duty on an app store, gateway, or marketplace to review or enforce compliance, nor on the manufacturer to prevent a user from modifying the device's own software or firmware. The title does not apply to a connected device already subject to security requirements under federal law, regulation, or federal agency guidance.

It also does not apply to a covered entity, health care provider, health plan, business associate, contractor, or employer as to an activity already regulated by HIPAA or California's Confidentiality of Medical Information Act. The statute creates no private right of action; the Attorney General, a city attorney, a county counsel, or a district attorney have the exclusive authority to enforce it, and the statute names no penalty amount of its own.

When LexLint raises it

  • distributes_software_product

Read the law

Official statute text, California Legislative Information, Civil Code Title 1.81.26

Back to the example  ·  Lint your app