California law on the use and publication of Social Security numbers (SSNs) prohibits:1
The law does not prevent the collection, use or release of an SSN as required by state or federal law or the use of an SSN for internal verification or administrative purposes.
If you maintain computer personnel files or customer files that include names and SSNs, driver’s license numbers or account numbers and security codes that permit access to financial information, you must maintain the security of those data files. If a breach of security results in unauthorized acquisition of unencrypted data, you must give timely notification of the breach to any affected California resident.2
You must give this notice as quickly as possible, delayed only by the reasonable time necessary to discover the scope of the breach and to allow steps to restore the integrity of the data, consistent with the needs of law enforcement to investigate the breach.
You must give notice in written form or by electronic means that complies with the law. In cases requiring notice to more than 50,000 people or where the expense of actual notice exceeds $250,000, you can use other authorized means of giving notice, including the use of email, website postings and statewide media. You can maintain your own notification procedures as part of an overall information security policy, if it meets the timeliness requirements of the law. You must comply with your policies.
To ensure a uniform, statewide approach to this issue, this state law supersedes all local laws, rules and regulations.
California law also prohibits employers from taking adverse action against an employee because they update their Social Security number.3 See Employee Identification.
1. Civ. Code sec. 1798.85
2. Civ. Code sec. 1798.82
3. Lab. Code sec. 1024.6