









第1节  第1.81.26章(自第1798.91.04节开始)被添加到“民法典” 第3部分第4编,内容如下:

第1.81.26章 联网设备的安全性

1798.91.04 (a)联网设备的制造商应为设备配备合理的安全特征,包括:







1798.91.05  就本章而言,下列术语定义如下:






1798.91.06 (a)当用户选择在联网设备上增加独立第三方的软件或应用程序时,本章不得解释为对该联网设备的制造商施加任何义务。









第2节 只有当2017-2018年度例会的众议院第1906号议案通过并生效后,本法才能实施。

(翻译&编辑:张云丹   校对:谢永江)


Senate Bill No. 327

Passed the Senate August 29, 2018

Passed the Assembly August 28, 2018

An act to add Title 1.81.26 (commencing with Section 1798.91.04) to Part 4 of Division 3 of the Civil Code, relating to information privacy.

legislative counsel’s digest

SB 327, Jackson. Information privacy: connected devices.

Existing law requires a business to take all reasonable steps to dispose of customer records within its custody or control containing personal information when the records are no longer to be retained by the business by shredding, erasing, or otherwise modifying the personal information in those records to make it unreadable or undecipherable. Existing law also requires a business that owns, licenses, or maintains personal information about a California resident to implement and maintain reasonable security procedures and practices appropriate to the nature of the information, to protect the personal information from unauthorized access, destruction, use, modification, or disclosure. Existing law authorizes a customer injured by a violation of these provisions to institute a civil action to recover damages.

This bill, beginning onJanuary 1, 2020, would require a manufacturer of a connected device, as thoseterms are defined, to equip the device with a reasonable security feature orfeatures that are appropriate to the nature and function of the device,appropriate to the information it may collect, contain, or transmit, anddesigned to protect the device and any information contained therein fromunauthorized access, destruction, use, modification, or disclosure, asspecified.

This bill would becomeoperative only if AB 1906 of the 2017–18 Regular Session is enacted and becomeseffective.

Thepeople of the State of California do enact as follows:

SECTION 1. Title 1.81.26 (commencing with Section 1798.91.04) isadded to Part 4 of Division 3 of the Civil Code, to read:


1798.91.04. (a) A manufacturer of a connected device shall equipthe device with a reasonable security feature or features that are all of thefollowing:

  (1)  Appropriate to the nature and function of the device.

  (2)  Appropriate to the information it may collect, contain, ortransmit.

 (3) Designed to protect the device and any information containedtherein from unauthorized access, destruction, use, modification, ordisclosure.

(b) Subject to all of the requirements ofsubdivision (a), if a connected device is equipped with a means forauthentication outside a local area network, it shall be deemed a reasonablesecurity feature under subdivision (a) if either of the following requirementsare met:

  (1)  The preprogrammed password is unique to each device manufactured.

  (2)  The device contains a security feature that requires a user togenerate a new means of authentication before access is granted to the devicefor the first time.

1798.91.05. For the purposes of this title, the following termshave the following meanings:

(a)  “Authentication” means a method ofverifying the authority of a user, process, or device to access resources in aninformation system.

(b)  “Connected device” means any device, orother physical object that is capable of connecting to the Internet, directlyor indirectly, and that is assigned an Internet Protocol address or Bluetoothaddress.

(c)  “Manufacturer” means the person whomanufactures, or contracts with another person to manufacture on the person’sbehalf, connected devices that are sold or offered for sale in California. Forthe purposes of this subdivision, a contract with another person to manufactureon the person’s behalf does not include a contract only to purchase a connecteddevice, or only to purchase and brand a connected device.

(d)  “Security feature” means a feature of adevice designed to provide security for that device.

(e)  “Unauthorized access, destruction, use,modification, or disclosure” means access, destruction, use, modification, ordisclosure thatis not authorized by the consumer.

1798.91.06. (a) This title shall not be construed to impose anyduty upon the manufacturer of a connected device related to unaffiliatedthird-party software or applications that a user chooses to add to a connecteddevice.

(b) This title shall not be construed toimpose any duty upon a provider of an electronic store, gateway, marketplace,or other means of purchasing or downloading software or applications, to reviewor enforce compliance with this title.

(c)  This title shall not be construed toimpose any duty upon the manufacturer of a connected device to prevent a userfrom having full control over a connected device, including the ability tomodify the software or firmware running on the device at the user’s discretion.

(d)  This title shall not apply to anyconnected device the functionality of which is subject to security requirementsunder federal law, regulations, or guidance promulgated by a federal agencypursuant to its regulatory enforcement authority.

(e)  This title shall not be construed toprovide a basis for a private right of action. The Attorney General, a cityattorney, a county counsel, or a district attorney shall have the exclusiveauthority to enforce this title.

(f)  The duties and obligations imposed bythis title are cumulative with any other duties or obligations imposed underother law, and shall not be construed to relieve any party from any duties orobligations imposed under other law.

(g) This title shall not be construed tolimit the authority of a law enforcement agency to obtain connected deviceinformation from a manufacturer as authorized by law or pursuant to an order ofa court of competent jurisdiction.

(h) A covered entity, provider of healthcare, business associate, health care service plan, contractor, employer, orany other person subject to the federal Health Insurance Portability andAccountability Act of 1996 (HIPAA) (Public Law 104-191) or the Confidentialityof Medical Information Act (Part 2.6 (commencing with Section 56) of Division1) shall not be subject to this title with respect to any activity regulated bythose acts.

(i)  This title shall become operative onJanuary 1, 2020. 

SEC. 2. This act shall become operative only if Assembly Bill 1906 of the2017–18 Regular Session is also enacted and becomes effective.

声明:本文来自北邮互联网治理与法律研究中心,版权归作者所有。文章内容仅代表作者独立观点,不代表安全内参立场,转载目的在于传递更多信息。如有侵权,请联系 anquanneican@163.com。