Legacy Core

Regulatory context

Insurance Agencies (California)

Licensed California insurance agents and brokers

Binding framework

California breach notification (Cal. Civ. Code § 1798.29 / § 1798.82); CCPA/CPRA if revenue and data thresholds are met; CDI licensing rules

California insurance agents face state breach-notification and privacy obligations, but California has not adopted the NAIC Insurance Data Security Model Law (#668) that applies in roughly 28 other states.

Key obligations (summary)

  • California data breach notification when personal information is compromised
  • CCPA privacy and security obligations when statutory thresholds apply
  • CDI email and license disclosure requirements for licensed agents

How Legacy Core fits

Legacy Core helps agents document cybersecurity readiness, strengthen security practices, and provide verifiable evidence of their commitment through an independent trust credential and public registry. Legacy Core credentials support readiness documentation. They are not legal opinions or certifications of regulatory compliance, and they do not demonstrate compliance with SB 354 or other pending legislation.

Developing legislation (not current law)

  • SB 354: Passed Legislature, awaiting Governor

    SB 354 passed the California Legislature on August 28, 2026 and is awaiting action by the Governor. It is not currently an operative compliance requirement. If enacted, it would address areas including information safeguards, privacy notices, data handling, retention, third-party relationships, and consumer information rights for insurance licensees and their vendors.

Do not claim

  • · NAIC Model Law #668 is current law in California
  • · Legacy Core satisfies NAIC ISP requirements
  • · Legacy Core credential demonstrates compliance with SB 354

Primary sources

Confidence: HIGH. Last reviewed 2026-09-02.

Ready for the credentialing pathway?

See the short conversion page for insurance agencies (california), or start the free Trust Audit.

Boundary

What a Legacy Core credential does not attest to

A Trust Badge documents demonstrated readiness against a dated Standards Release (assessment basis: NIST CSF 2.0 and CIS Controls v8). It is not a substitute for industry-specific legal or regulatory obligations.

  • FTC Safeguards Rule or WISP compliance (CPAs / tax preparers)
  • HIPAA compliance or OCR audit readiness (medical / dental)
  • ABA or State Bar ethics sign-off (attorneys)
  • SEC Regulation S-P compliance (investment advisers)
  • NAIC Insurance Data Security Model Law (including in California, not adopted)
  • CCPA cybersecurity audits (threshold-gated regulation)
  • Cyber insurance approval or claim guarantee
  • Penetration test, SOC 2, CMMC, or government endorsement

Legacy Core is aligned with NIST CSF 2.0 and CIS Controls v8. Legacy Core is not affiliated with, endorsed by, or accredited by NIST, CIS, or any government agency. Tracking a framework does not constitute a determination of legal or regulatory compliance. Legacy Core supports cybersecurity readiness and trust-building and does not provide legal advice. Businesses should consult qualified legal or compliance professionals regarding requirements specific to their industry and operations.

Industry-specific obligations by vertical: Regulatory context guides

Insurance Agencies (California): Regulatory Context | Legacy Core | Legacy Core