The Epic Gazette -- Digital Edition, News, Reports & Records, For a Curious World, Est'd MMVIII
Stanislaus County's Interactive News — From the Public, For the Public, Free Sponsored by Epic App Solutions
Privacy & Public Systems Desk Explainer // California Law Back to The Epic Gazette
Privacy & Public Systems Desk // Public-Law Explainer By Epic App Solutions
Privacy / Local Government / Website Security

Businesses Have Privacy Duties. Why Are Cities Still Outside Much of California's IPA?

The answer is stranger than it sounds — and it matters when a city hires an outside company to run a website containing resident accounts, email addresses, usernames and passwords.

First, a correction: California businesses do not simply “follow PIPA.” California has several different privacy and security laws. The Information Practices Act of 1977 generally governs state agencies, while businesses may have duties under laws such as Civil Code §1798.81.5 and, if they meet the statutory definition, the CCPA/CPRA.
Yes, There Is a Real Local-Government Gap

California's Information Practices Act — usually called the IPA — is a state privacy law governing how covered public agencies collect, maintain, use and disclose personal information.

But under the current statutory definition of “agency,” local agencies are excluded. That means cities, counties and other local entities are not presently subject to the entire IPA in the same way California state agencies are.

A private company maintaining California residents’ personal information can have an explicit “reasonable security” duty — while a city remains outside much of the state’s broad Information Practices Act.
That Does Not Mean Cities Have No Privacy Obligations

This is where the distinction matters. “The full IPA does not generally apply to local agencies” is very different from saying “cities can do whatever they want with data.”

California Civil Code §1798.29 specifically imposes security-breach notification requirements on agencies, and it expressly treats the following as personal information for that purpose:

Online-account credentials count. A username or email address combined with a password or security question and answer that permits access to an online account falls within the statute's breach-notification definition of personal information.

So if a municipal WordPress site has user accounts, the fact that those accounts are “basic” does not make the security issue meaningless. Email addresses and account credentials can trigger real legal consequences if unauthorized acquisition occurs.

Businesses Face an Explicit Reasonable-Security Rule

California Civil Code §1798.81.5 says a business that owns, licenses or maintains personal information about a California resident must implement and maintain reasonable security procedures and practices appropriate to the nature of the information.

The same section specifically includes a username or email address plus a password or security question/answer permitting account access within its definition of personal information.

Civil Code §1798.81.5Businesses maintaining covered California personal information must use reasonable security procedures and practices.
Civil Code §1798.29Government-agency breach notification requirements include online account credentials.
CCPA / CPRAQualifying businesses have broader consumer-privacy duties, including notice and security obligations. Not every small business automatically falls within the CCPA definition of a covered “business.”
So What Happens When a City Hires a Private Web Contractor?

That is the part local business owners and residents should pay attention to.

Imagine a city contracts with a private marketing or website company to manage a WordPress installation. The system contains resident or user accounts. The contractor may have administrator access, hosting access, database access, backup access or plugin-level access.

The useful questions are no longer “Is WordPress bad?” or “Is the contractor a marketing company?” The useful questions are:

ACCESS: Who has administrator, database, SFTP and hosting-panel credentials?
IDENTITY: Does every privileged user have an individual account, or are credentials shared?
MFA: Is multifactor authentication required for privileged users?
OFFBOARDING: Are former employees, freelancers and subcontractors removed immediately?
PATCHING: Are WordPress core, themes and plugins current and supported?
BACKUPS: Who can reach backups, and are they protected separately from the production site?
LOGGING: Can the city identify who changed what and when?
CONTRACT: Does the agreement define who may access city data and what happens when the relationship ends?
INCIDENT RESPONSE: Who determines whether a breach occurred, and who sends legally required notices?
The WordPress Username Table Is Not the Whole Story

A normal WordPress installation stores user information in the database and normally stores passwords as hashes, not plain text. Finding a hashed password by itself is not evidence of wrongdoing.

The stronger security questions concern the entire control environment: weak administrator passwords, shared admin accounts, unpatched plugins, unrestricted third-party access, poor backup security, missing MFA, weak logging, or a contractor relationship with no clear data-handling rules.

And California Lawmakers Apparently Know the Gap Exists

Assembly Bill 1337 is currently attempting to change the IPA framework so that local agencies would be brought into the law more broadly. The current bill text contains provisions that would become operative in 2028 and would change the statutory definition of covered agencies.

But as of August 2026, AB 1337 is still pending legislation — it is not current law.

Translation: California has already built meaningful privacy and security rules around businesses and state agencies, and it has breach-notification rules that reach local government. But the broader IPA structure still contains a local-agency carveout that lawmakers are actively considering changing.

Why This Matters for Local Reporting

A city website is not just a digital brochure when residents have accounts. Once a government website accepts logins, contact information, applications, forms, payments, submissions or other identifiable records, the security architecture becomes part of public accountability.

Residents should be able to ask:

That Is a Better Investigation Than Yelling “Privacy Violation”

Before accusing a vendor or city of breaking a law, establish the facts. Identify what data exists, who owns it, who maintains it, what access the contractor has, what the contract says, what controls are in place and whether an actual unauthorized disclosure or acquisition occurred.

If those answers are solid, good. If nobody can explain them, that is the story.

Public-sector technology should survive the same question we ask private vendors: Who has the keys, what can they reach, and what protects the people whose information is inside?
Primary California Sources
Civil Code §1798.81.5 Reasonable security for businesses maintaining covered personal information. California Legislature →
Civil Code §1798.29 Government security-breach notification, including online account credentials. California Legislature →
CCPA / CPRA Consumer privacy duties applying to qualifying businesses. California Legislature →
AB 1337 Pending proposal that would expand the Information Practices Act toward local agencies. Track the bill →

Editorial note: This article is general public-law and cybersecurity education, not legal advice and not an allegation that any named city or contractor violated California law. A legal conclusion requires the actual system facts, contractual terms, data involved and applicable statutes.

Document. Ask the Right Questions. Get the Facts First.

Access, data, controls, contract, logging, evidence — not accusations.

Public-Law Explainer // August 2026
Drop Us A Line

Don't have a business email, or just want to say something quick? This isn't the formal contact form — no company domain required, nothing but a message is needed.