State Quick Hits: California Privacy Law Update—California Legislature Sends CIPA Reform, CCPA Amendments, Data Broker, and AI Bills to the Governor

5 min

California's legislature closed out August with a flurry of privacy and AI legislation, including a reform to the California Invasion of Privacy Act (CIPA) that could provide some relief to businesses facing website and app tracking claims. If Gov. Gavin Newsom signs these bills into law, the state's already complex data privacy framework established with the California Consumer Privacy Act (CCPA) will grow even more complicated.

These bills are the latest reminder that state privacy requirements continue to evolve quickly, even in states with long-standing consumer privacy laws. Businesses subject to the CCPA, data broker registration requirements, or other state AI and privacy laws should continue to review and update their compliance programs, consumer request workflows, vendor processes, and privacy disclosures as the state-law patchwork becomes increasingly complex.

 California Privacy and AI Legislation Heading to the Governor

  • SB 690: CIPA Litigation Reform for Website and App Claims. SB 690 would amend California's invasion of privacy law by limiting private litigation claims involving pen registers or trap-and-trace devices on internet websites, online applications, or mobile applications. The bill also states that this limitation would apply retroactively to certain pending claims filed within two years before the bill's operative date. SB 690, however, would not limit claims under California's wiretap (Cal. Penal Code § 631) or call recording (Cal. Penal Code § 632) statutes. If signed, SB 690 would take effect on January 1, 2027.
  • AB 1542: Restrictions on Sale or Sharing of Sensitive Personal Information. AB 1542 would amend the CCPA to prohibit a business, service provider, or contractor from selling or sharing sensitive personal information to a third party, subject to specified exceptions. If signed, AB 1542 would take effect on January 1, 2027.
  • SB 1050: Synthetic Performer Disclosures in Advertising. SB 1050 would make it an unlawful advertising practice to create and publish an advertisement that prominently includes a synthetic performer without a clear and conspicuous disclosure. The bill would also require certain advertising mediums to remove, disable access to, or stop disseminating an advertisement containing a synthetic performer after receiving a court order finding a violation or enjoining publication. If signed, SB 1050 would take effect on January 1, 2027.
  • SB 923: Expanded CCPA Deletion Rights and Online Request Methods. SB 923 would expand the CCPA's deletion right by allowing consumers to request deletion of personal information collected "from or about" them, including information obtained from third-party or other indirect sources. The bill would also require online-only businesses with a direct consumer relationship to provide an online method, such as a webform or online portal, for submitting CCPA requests, in addition to an email option. If signed, SB 923 would take effect on January 1, 2027.
  • AB 883: Shorter DROP Processing Timeline and New Enforcement Pathway. AB 883 would amend California's data broker law by shortening the timeframe for data brokers to access the state's Delete Request and Opt-Out Platform (DROP) and process deletion requests from at least once every 45 days to at least once every 30 days. The bill would also require elected officials and judges to be notified of their right to submit a deletion request through DROP, and would authorize the Attorney General, county counsel, or a city attorney to bring certain civil actions on behalf of elected officials or judges for alleged DROP-related deletion violations. If signed, AB 883 would take effect on January 1, 2027, with certain provisions operative on July 1, 2027.
  • SB 1000: Updates to California's AI Transparency Act. SB 1000 would amend the California AI Transparency Act by revising requirements governing provenance disclosures for AI-generated content. Among other changes, the bill would remove the current monthly-user threshold element from the definition of "covered provider," replace the required AI detection tool with a "disclosure verification tool," eliminate the requirement that covered providers offer users the option to include a manifest disclosure in AI-generated content, and require latent disclosures to indicate whether a generative AI system created or altered the content. If signed, SB 1000 would take effect on January 1, 2027.
  • AB 2561: Privacy Settings for Operating Systems and Applications. AB 2561 would prohibit an operating system or application from undoing a user's affirmative configuration of a privacy setting without the user's consent, subject to limited exceptions. The bill defines "privacy setting" to include user-configurable options that govern an application's collection, use, sharing, disclosure, retention, or processing of the user's personal information. If signed, AB 2561 would take effect on January 1, 2027.
  • SB 354: Insurance Information and Privacy Protection Act Reforms. SB 354 would revise California's Insurance Information and Privacy Protection Act beginning July 1, 2028. The bill would create new standards for the processing and sharing of personal information by insurance licensees, surplus line insurers, reinsurers, and third-party service providers, including privacy notices, consent requirements, consumer rights, retention policies, adverse underwriting disclosures, service provider contracting requirements, and penalties for violations. If signed, SB 354 would take effect on July 1, 2028.
  • AB 1609: Customer Service Chatbots. AB 1609 would prohibit large private businesses from representing that customer service chatbots are human and would require disclosures where a reasonable person could be misled into believing they are interacting with a human. The bill would also require covered businesses to provide a customer service feature that lets customers contact a human customer service agent during regular business hours, with specified timing and enforcement provisions. If signed, AB 1609 would take effect on January 1, 2027.

What California's Privacy and AI Bills Mean for Businesses

Companies should consider taking the following steps:

  • Review Deletion Workflows: Businesses should determine whether current systems can identify and delete personal information collected both directly from consumers and indirectly from third-party sources.
  • Confirm Consumer Rights Requests Mechanisms: Businesses should ensure that consumer request mechanisms such as preference centers, webforms, and email options satisfy applicable method-of-submission requirements.
  • Prepare for Abbreviated Deletion Timelines: For data brokers, assess readiness for a 30-day DROP access and processing cycle.
  • Evaluate AI and Chatbot Governance. Companies deploying AI systems, customer service chatbots, companion chatbots, or generative AI tools should review disclosure, risk assessment, audit, human-contact, and appeal processes.

Businesses should move quickly to update privacy compliance programs and adopt adaptable strategies for an increasingly complex patchwork of state privacy laws. If you need assistance reviewing or developing a privacy compliance program, contact the authors or visit Venable's Privacy and Data Security center to help ensure your organization is prepared.