{"id":2921,"date":"2018-10-12T14:03:00","date_gmt":"2018-10-12T20:03:00","guid":{"rendered":"https:\/\/trustarc.com\/?post_type=resource&#038;p=2921"},"modified":"2024-12-17T10:05:30","modified_gmt":"2024-12-17T16:05:30","slug":"california-cybersecurity-bills-s-b-327-a-b-1906","status":"publish","type":"resource","link":"https:\/\/trustarc.com\/resource\/california-cybersecurity-bills-s-b-327-a-b-1906\/","title":{"rendered":"California Companion Privacy and Cybersecurity Bills \u2013 S.B. 327 and A.B. 1906"},"content":{"rendered":"\t\t<section id=\"block_e242a206a96a4b1523f9eb46e7f0de12\" class=\"resource-intro intro-simple\">\n\t\t\t<div class=\"container\">\n\t\t\t\t\t\t\t\t\t<strong class=\"sub-title block uppercase\">Articles<\/strong>\n\t\t\t\t\t\t\t\t\t\t<h1>California Companion Privacy and Cybersecurity Bills \u2013 S.B. 327 and A.B. 1906<\/h1>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\n\n\t<section id=\"block_15df3ca3451dabd3237ecef5fafc2d6c\" class=\"columns-content\">\n\t\t<div class=\"container\">\n\t\t\t<div class=\"left\">\n\t\t\t\t\t\t<div class=\"person-wrap\">\n\t\t\t<span>\t\t\t\t\t\t\t<div class=\"img-holder\">\n\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"110\" height=\"110\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/people-placeholder-lt-blue.png\" class=\"attachment-full size-full wp-post-image\" alt=\"\" \/>\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<div class=\"text-holder\">\n\t\t\t\t\t\t\t\t\t\t\t<strong class=\"block name\">Annie Greenley-Giudici<\/strong>\n\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/span>\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t<div class=\"middle\">\n\t\t\t\t<div class=\"content\">\n\t\t\t\t\t<h2>Bills regulate cybersecurity standards for California internet of things (IoT) devices<\/h2>\n<p>On September 28, 2018 California Gov. Jerry Brown signed into law two companion bills that regulate cybersecurity standards for Internet of Things (IoT) devices sold in California.<\/p>\n<p><a href=\"https:\/\/leginfo.legislature.ca.gov\/faces\/billTextClient.xhtml?bill_id=201720180SB327\">S.B. 327<\/a>\u00a0and\u00a0<a href=\"https:\/\/leginfo.legislature.ca.gov\/faces\/billTextClient.xhtml?bill_id=201720180AB1906\">A.B. 1906<\/a>\u00a0(the \u201cBills\u201d) require that manufacturers of connected devices sold in California outfit their products with \u201creasonable\u201d security features by January 1, 2020, the same date the\u00a0<a href=\"https:\/\/trustarc.com\/regulations\/ccpa-cpra\/\">California Consumer Privacy Act<\/a>\u00a0will also take effect.<\/p>\n<p>The Bills require a manufacturer of a connected device to \u201cequip the device with a reasonable security feature or features that are appropriate to the nature and function of the device, appropriate to the information it may collect, contain, or transmit, and designed to protect the device and any information contained therein from unauthorized access, destruction, use, modification, or disclosure, as specified.\u201d<\/p>\n<p>The legislation offers examples of a \u201creasonable\u201d security feature, such as making the pre-programmed passwords unique to each device manufactured and requiring a new means of authentication before access can be granted to the device for the first time.<\/p>\n<p>Under the new law, \u201cmanufacturer\u201d means the person who manufactures (or contracts with another person to manufacture on the person\u2019s behalf) connected devices that are sold or offered for sale in California.<\/p>\n<p>A \u201ccontract with another person to manufacture\u201d on the person\u2019s behalf does not include a contract only to purchase a connected device or only to purchase and brand a connected device.<\/p>\n<p>The scope of coverage of the new law applies to the person who manufactures or contracts with someone to manufacture the connected device for sale or offered for sale in California.<\/p>\n<p>For example, an electronic retailer such as Best Buy, does not have an obligation to review or enforce compliance with the bills.<\/p>\n<h2>First state law to address IoT security<\/h2>\n<p><strong>According to\u00a0<a href=\"https:\/\/www.gartner.com\/imagesrv\/books\/iot\/iotEbook_digital.pdf\">Gartner<\/a><\/strong><strong>, an estimated 20 billion devices will be online by 2020<\/strong>. As the first state or federal law to address IoT security, the California legislation will effectively become a standard for manufacturers of these devices.<\/p>\n<p>Currently, the IoT industry is largely self-regulated and governed by best practices as well as the Federal Trade Commission enforcement actions and guidance under its broad authority to police deceptive security practices.<\/p>\n<p>As companies increasingly rely on data to drive business, it is key to incorporate Privacy by Design practices, international laws like the GDPR, and forthcoming domestic legislation into privacy programs.<\/p>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\t<div class=\"right sm\">\n\t\t\t\t<div class=\"share-it\">\n\t\t\t\t\t<strong class=\"title block uppercase\">Follow us<\/strong>\n\t\t\t\t\t<div class=\"soc-list\">\n\t\t\t\t\t\t<a href=\"https:\/\/www.linkedin.com\/company\/trustarc\/\" target=\"_blank\"><img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/li-dark.svg\" alt=\"\" \/><\/a>\n\t\t\t\t\t\t<a href=\"\nhttps:\/\/twitter.com\/TrustArc\" target=\"_blank\"><img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/tw-dark.svg\" alt=\"\" \/><\/a>\n\t\t\t\t\t\t<a href=\"javascript:;\" id=\"copy-url\"><img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/link-dark.svg\" alt=\"\" \/><\/a>\n\t\t\t\t\t\t<span class=\"copied\" style=\"display:none;\">Link Copied!<\/span>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t<div class=\"key-topics\">\n\t\t\t\t\t\t<strong class=\"title block uppercase\">Key Topics<\/strong>\n\t\t\t\t\t\t<ul>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<li><a href=\"https:\/\/trustarc.com\/topic-resource\/cyber-security\/\" class=\"badge\">Cyber Security<\/a><\/li>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<div class=\"cta-area\">\n\t\t\t\t\t<p>Get the latest resources sent to your inbox<\/p>\n\t\t\t\t\t<a href=\"\/subscription-center\/\" class=\"cta\">Subscribe<\/a>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\t<\/section>\n\t","protected":false},"excerpt":{"rendered":"<p>S.B. 327 and A.B. 1906 (the \u201cBills\u201d) require that manufacturers of connected devices sold in California outfit their products with &#8220;reasonable&#8221; security features by January 1, 2020, the same date the California Consumer Privacy Act will also take effect.<\/p>\n","protected":false},"featured_media":1687,"template":"","topic-resource":[62],"type-resource":[6],"class_list":["post-2921","resource","type-resource","status-publish","has-post-thumbnail","hentry","topic-resource-cyber-security","type-resource-articles"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.4 (Yoast SEO v27.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>California Companion Privacy and Cybersecurity Bills \u2013 S.B. 327 and A.B. 1906 | TrustArc<\/title>\n<meta name=\"description\" content=\"S.B. 327 and A.B. 1906 (the \u201cBills\u201d) require that manufacturers of connected devices sold in California outfit their products with &quot;reasonable&quot; security features by January 1, 2020, the same date the California Consumer Privacy Act will also take effect.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/trustarc.com\/resource\/california-cybersecurity-bills-s-b-327-a-b-1906\/\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/california-cybersecurity-bills-s-b-327-a-b-1906\\\/\",\"url\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/california-cybersecurity-bills-s-b-327-a-b-1906\\\/\",\"name\":\"California Companion Privacy and Cybersecurity Bills \u2013 S.B. 327 and A.B. 1906 | TrustArc\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/california-cybersecurity-bills-s-b-327-a-b-1906\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/california-cybersecurity-bills-s-b-327-a-b-1906\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/trustarc.com\\\/wp-content\\\/uploads\\\/2024\\\/02\\\/res-feat-city-purple.png\",\"datePublished\":\"2018-10-12T20:03:00+00:00\",\"dateModified\":\"2024-12-17T16:05:30+00:00\",\"description\":\"S.B. 327 and A.B. 1906 (the \u201cBills\u201d) require that manufacturers of connected devices sold in California outfit their products with \\\"reasonable\\\" security features by January 1, 2020, the same date the California Consumer Privacy Act will also take effect.\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/trustarc.com\\\/resource\\\/california-cybersecurity-bills-s-b-327-a-b-1906\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/california-cybersecurity-bills-s-b-327-a-b-1906\\\/#primaryimage\",\"url\":\"https:\\\/\\\/trustarc.com\\\/wp-content\\\/uploads\\\/2024\\\/02\\\/res-feat-city-purple.png\",\"contentUrl\":\"https:\\\/\\\/trustarc.com\\\/wp-content\\\/uploads\\\/2024\\\/02\\\/res-feat-city-purple.png\",\"width\":610,\"height\":152},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/#website\",\"url\":\"https:\\\/\\\/trustarc.com\\\/\",\"name\":\"TrustArc\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/trustarc.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"California Companion Privacy and Cybersecurity Bills \u2013 S.B. 327 and A.B. 1906 | TrustArc","description":"S.B. 327 and A.B. 1906 (the \u201cBills\u201d) require that manufacturers of connected devices sold in California outfit their products with \"reasonable\" security features by January 1, 2020, the same date the California Consumer Privacy Act will also take effect.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/trustarc.com\/resource\/california-cybersecurity-bills-s-b-327-a-b-1906\/","twitter_misc":{"Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/trustarc.com\/resource\/california-cybersecurity-bills-s-b-327-a-b-1906\/","url":"https:\/\/trustarc.com\/resource\/california-cybersecurity-bills-s-b-327-a-b-1906\/","name":"California Companion Privacy and Cybersecurity Bills \u2013 S.B. 327 and A.B. 1906 | TrustArc","isPartOf":{"@id":"https:\/\/trustarc.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/trustarc.com\/resource\/california-cybersecurity-bills-s-b-327-a-b-1906\/#primaryimage"},"image":{"@id":"https:\/\/trustarc.com\/resource\/california-cybersecurity-bills-s-b-327-a-b-1906\/#primaryimage"},"thumbnailUrl":"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/res-feat-city-purple.png","datePublished":"2018-10-12T20:03:00+00:00","dateModified":"2024-12-17T16:05:30+00:00","description":"S.B. 327 and A.B. 1906 (the \u201cBills\u201d) require that manufacturers of connected devices sold in California outfit their products with \"reasonable\" security features by January 1, 2020, the same date the California Consumer Privacy Act will also take effect.","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/trustarc.com\/resource\/california-cybersecurity-bills-s-b-327-a-b-1906\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/trustarc.com\/resource\/california-cybersecurity-bills-s-b-327-a-b-1906\/#primaryimage","url":"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/res-feat-city-purple.png","contentUrl":"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/res-feat-city-purple.png","width":610,"height":152},{"@type":"WebSite","@id":"https:\/\/trustarc.com\/#website","url":"https:\/\/trustarc.com\/","name":"TrustArc","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/trustarc.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/resource\/2921","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/resource"}],"about":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/types\/resource"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/media\/1687"}],"wp:attachment":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/media?parent=2921"}],"wp:term":[{"taxonomy":"topic-resource","embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/topic-resource?post=2921"},{"taxonomy":"type-resource","embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/type-resource?post=2921"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}