California law on the use and publication of Social Security numbers (SSNs) prohibits:1

  • Posting or publicly displaying an individual’s SSN in any manner. “Publicly posting” or “publicly displaying” means to intentionally communicate or otherwise make available to the general public.
  • Printing an individual’s SSN on any card required for the individual to access products or services. This can include your employee identification cards and badges.
  • Requiring an individual to transmit their SSN over the Internet, unless the connection is secure or the SSN is encrypted.
  • Requiring an individual to use their SSN to access a website, unless a password or unique PIN or other authentication device is also required to access the website. This restriction may require a change in systems used to access or transmit personnel, business, human resources or payroll information over the Internet or intranet.
  • Printing an individual’s SSN on any materials mailed to the individual, unless state or federal law requires the SSN to be on the document. Applications and forms sent by mail can include SSNs.
  • Printing an SSN on a postcard or other mailer not requiring an envelope or visible on the envelope or without the envelope being opened if the SSN can be mailed in an otherwise permissible manner.
  • Encoding or embedding a SSN in or on a card or document, including, but not limited to, using a bar code, chip, magnetic strip or other technology, in place of removing the SSN, as required by law.
  • All employers must print no more than the last four digits of an employee’s SSN on check stubs or similar documents or substitute some other identifying number.

The law does not prevent the collection, use or release of an SSN as required by state or federal law or the use of an SSN for internal verification or administrative purposes.

If you maintain computer personnel files or customer files that include names and SSNs, driver’s license numbers or account numbers and security codes that permit access to financial information, you must maintain the security of those data files. If a breach of security results in unauthorized acquisition of unencrypted data, you must give timely notification of the breach to any affected California resident.2

You must give this notice as quickly as possible, delayed only by the reasonable time necessary to discover the scope of the breach and to allow steps to restore the integrity of the data, consistent with the needs of law enforcement to investigate the breach.

You must give notice in written form or by electronic means that complies with the law. In cases requiring notice to more than 50,000 people or where the expense of actual notice exceeds $250,000, you can use other authorized means of giving notice, including the use of email, website postings and statewide media. You can maintain your own notification procedures as part of an overall information security policy, if it meets the timeliness requirements of the law. You must comply with your policies.

To ensure a uniform, statewide approach to this issue, this state law supersedes all local laws, rules and regulations.

California law also prohibits employers from taking adverse action against an employee because they update their Social Security number.3 See Employee Identification.


1. Civ. Code sec. 1798.85

2. Civ. Code sec. 1798.82

3. Lab. Code sec. 1024.6