Site icon CCIS – California Consortium for Independent Study

Changes in Law 2022 – Technology

Stack of books with laptop on wooden table

Stack of books with laptop on wooden table

Local Educational Agencies (LEAs) must report cybersecurity attacks.

Incidents of cyber attacks on LEAs had already been increasing in recent years, but the COVID-19 Pandemic (and, more specifically, the rapid deployment of remote/online learning) only served to make schools more vulnerable to cyber events. Even as children have returned to in-classroom learning, news of increasingly concerning cyber incidents have continued to surface. Just last month (September, 2022) the Los Angeles Unified School District (LAUSD) suffered a major ransomeware attack – a version of cyberattack where data is stolen and then ransomed for some form of payment – and student and staff information was likely compromised.

Due in no small part to events like the one experienced at LAUSD, now more than ever, policymakers in Sacramento have taken an interest in school cybersecurity. To that end, this year, Assemblymember Rudy Salas (D-Bakersfield) authored AB 2355. The bill, which sunsets on January 1, 2027, requires LEAs to report cyberattacks that affect more than 500 pupils or personnel to the California Cybersecurity Integration Center (Cal-CSIC). It further defines a “cyberattack” to mean either:

  1. Any alteration, deletion, damage, or destruction of a computer system, computer network, computer program, or data caused by unauthorized access.
  2. The unauthorized denial of access to legitimate users of a computer system, computer network, computer program, or data.

The provisions of the bill also include a requirement for Cal-CSIC to establish a database that tracks reports of cyberattacks submitted by LEAs, and further requires Cal-CSIC to annually, by January 1, provide a report to the Governor and the relevant policy committees of the Legislature summarizing the types and number of cyberattacks on LEAs and the types and number of data breaches affecting LEAs that have been reported to the Attorney General.

Understanding that this bill imposes yet another reporting requirement on LEAs, the hope is that having a centralized database detailing these incidents will shine a light on the types of cyberattacks that we know LEAs are dealing with, further opening the eyes of representatives in Sacramento. This database and reporting, combined with more and more headline-grabbing attacks like the one on LAUSD, could eventually lead to some dedicated state-level resources for schools to bolster their cybersecurity programs and defenses.

State takes aim at online platforms and services accessed by kids.

Over the past several years, California has taken steps to greatly increase the security of all consumers, but in particular, minors, online. For instance, in 2018, the Legislature passed, and voters approved, the California Consumer Privacy Act (CCPA). The CCPA was further refined by a subsequent ballot measure and a handful of pieces of legislation in the years that followed. However, much of those efforts focused on the collection, sale, and use of consumer data, rather than focusing on the products and platforms themselves.

AB 2273, jointly authored by Assemblymembers Buffy Wicks (D-Richmond), Jordan Cunningham (R- San Luis Obispo), and Cottie Petrie-Norris (D-Costa Mesa), establishes the California Age-Appropriate Design Code Act. Modeled after recently enacted law in the United Kingdom, the bill institutes a series of obligations and restrictions on businesses that provide an online service, product, or feature likely to be accessed by a child. The bill additionally establishes a working group to evaluate best practices for the implementation of the bill’s provisions.

Set to take effect on January 1, 2024, you can find detailed provisions of the new restrictions and obligations listed in the bill, below. This bill also likely signals an intent of policymakers in Sacramento to continue looking at ways to address how children interact with online materials and platforms – particularly in the context of child mental health. Look for more bills on this issue to surface in the coming years.


The Governor signed the following technology bills:

Capitol Advisors Group has produced a set of comprehensive client briefs detailing new education laws that were passed by the Legislature and signed into law by Governor Newsom in 2022. Each brief is organized by subject area and includes an executive summary highlighting major changes we think you should know about. Bills signed by the Governor take effect on January 1, 2023, unless the bill specifically states otherwise.

Exit mobile version