An act to amend Sections 791, 791.01, 791.02, 791.03, 791.04, 791.045, 791.05, 791.06, 791.07, 791.08, 791.09, 791.10, 791.11, 791.12, 791.14, 791.15, 791.16, 791.17, 791.18, 791.19, 791.20, 791.21, 791.22, and 791.29 of, to add Sections 791.046, 791.099, 791.24, 791.32, 791.33, 791.34, 791.35, 791.36, 791.37, 791.38, 791.39, and 791.40 to, to repeal Section 791.23 of, and to repeal and add Section 791.13 of, the Insurance Code, relating to insurance.
SB 354 would create the Insurance Consumer Privacy Protection Act of 2025 and substantially rewrite California’s insurance privacy framework. The bill replaces and expands the Insurance Information and Privacy Protection Act to impose detailed rules on how insurance licensees, reinsurers, surplus line insurers, and their third-party service providers collect, use, retain, share, and delete consumers’ personal information. It requires clear privacy notices, annual privacy rights notices, and accessible methods for consumers to request access, correction, amendment, or deletion of their information. It also limits processing to purposes tied to an insurance transaction or other consumer-authorized purpose, requires affirmative consent for many non-insurance uses, restricts sales of personal information, and bars retaliation against consumers who exercise their privacy rights.
The bill also adds retention, security, and vendor-management requirements. Licensees would have to adopt written records-retention policies, review records at least annually, delete or deidentify information when it is no longer needed, and maintain safeguards to protect nonpublic information. Contracts with third-party service providers would have to spell out processing limits, confidentiality obligations, security standards, breach reporting, deletion timelines, and subcontractor requirements. The bill further addresses adverse underwriting decisions by requiring insurers to disclose the reasons and supporting information, and it limits the use of certain information in underwriting decisions. It also creates enforcement tools for the Insurance Commissioner, including examinations, hearings, cease-and-desist orders, civil penalties, and license suspension or revocation for serious or repeated violations.
In practical terms, SB 354 would significantly expand state regulation of insurance data practices and would preempt inconsistent state laws while preserving federal health-information rules and the California Privacy Rights Act. It would apply to a broad range of insurance-related entities and would create new consumer rights and compliance duties for insurers and related vendors. The bill also expands the misdemeanor for obtaining information under false pretenses and authorizes substantial fines for violations, making the measure both a privacy bill and an enforcement bill.
The overall sentiment reflected in the voting history appears generally supportive but not unanimous. The bill advanced through committee with majority support, including a 28-10 Senate third-reading vote, suggesting broad agreement with the goal of modernizing insurance privacy protections. At the same time, the bill was placed on the suspense file in Appropriations, indicating concern about fiscal or implementation impacts, and the recorded no votes show that some members were not comfortable with the scope of the changes or their costs.
The main points of contention are likely the breadth of the privacy restrictions, the compliance burden on insurers and third-party vendors, the size of the penalties, and the extent to which the bill reaches marketing, research, automated decisionmaking, and cross-border data sharing. Another likely issue is the bill’s confidentiality provisions, which limit public access to certain materials submitted to the Insurance Commissioner. Supporters frame the bill as a needed modernization of outdated insurance privacy law, while opponents or skeptics appear to have focused on cost, operational complexity, and regulatory reach.
SB 354 would overhaul the Insurance Code’s existing insurance privacy provisions by replacing older disclosure-based rules with a comprehensive data-governance regime for insurance licensees and their third-party service providers. It would add new statutory sections governing notice, consent, access, correction, deletion, retention, security safeguards, breach reporting, vendor contracts, anti-retaliation protections, and enforcement. It also would amend numerous existing sections to align them with the new framework, repeal outdated provisions, and create new penalties and misdemeanor liability for false-pretenses access to consumer information. The bill would affect insurers, producers, surplus line insurers, reinsurers, insurance support organizations, and vendors that process insurance-related personal information, while carving out or limiting application for certain HIPAA- and GLBA-regulated entities and preserving CPRA and protected-health-information rules.
The bill appears to have received generally favorable treatment in committee and on the floor, with multiple do-pass votes and a strong Senate third-reading vote, indicating that many legislators supported the goal of strengthening insurance consumer privacy. The fact that it was amended several times and placed on the Appropriations suspense file suggests that members also had concerns about cost, implementation, and the scope of the regulatory changes. Overall, the sentiment is best characterized as supportive of privacy protections but cautious about the bill’s breadth and fiscal effects.
The most notable areas of contention are the bill’s expansive restrictions on how insurers may process and share personal information, especially for marketing, research, automated decisionmaking, and international transfers. Insurers and vendors may view the consent, retention, contract, and notice requirements as operationally burdensome, while consumer advocates are likely to support them as necessary safeguards. The bill’s large civil penalties, expanded misdemeanor provision, and confidentiality rules for materials submitted to the Insurance Commissioner also likely drew scrutiny, particularly from members concerned about enforcement severity, transparency, and administrative cost.