Insurance Agencies (California)
Licensed California insurance agents and brokers
Binding framework
California breach notification (Cal. Civ. Code § 1798.29 / § 1798.82); CCPA/CPRA if revenue and data thresholds are met; CDI licensing rules
California insurance agents face state breach-notification and privacy obligations, but California has not adopted the NAIC Insurance Data Security Model Law (#668) that applies in roughly 28 other states.
Key obligations (summary)
- California data breach notification when personal information is compromised
- CCPA privacy and security obligations when statutory thresholds apply
- CDI email and license disclosure requirements for licensed agents
How Legacy Core fits
Legacy Core helps agents document cybersecurity readiness, strengthen security practices, and provide verifiable evidence of their commitment through an independent trust credential and public registry. Legacy Core credentials support readiness documentation. They are not legal opinions or certifications of regulatory compliance, and they do not demonstrate compliance with SB 354 or other pending legislation.
Developing legislation (not current law)
SB 354: Passed Legislature, awaiting Governor
SB 354 passed the California Legislature on August 28, 2026 and is awaiting action by the Governor. It is not currently an operative compliance requirement. If enacted, it would address areas including information safeguards, privacy notices, data handling, retention, third-party relationships, and consumer information rights for insurance licensees and their vendors.
Do not claim
- · NAIC Model Law #668 is current law in California
- · Legacy Core satisfies NAIC ISP requirements
- · Legacy Core credential demonstrates compliance with SB 354
Primary sources
Confidence: HIGH. Last reviewed 2026-09-02.
Ready for the credentialing pathway?
See the short conversion page for insurance agencies (california), or start the free Trust Audit.