The answer is stranger than it sounds — and it matters when a city hires an outside company to run a website containing resident accounts, email addresses, usernames and passwords.
California's Information Practices Act — usually called the IPA — is a state privacy law governing how covered public agencies collect, maintain, use and disclose personal information.
But under the current statutory definition of “agency,” local agencies are excluded. That means cities, counties and other local entities are not presently subject to the entire IPA in the same way California state agencies are.
This is where the distinction matters. “The full IPA does not generally apply to local agencies” is very different from saying “cities can do whatever they want with data.”
California Civil Code §1798.29 specifically imposes security-breach notification requirements on agencies, and it expressly treats the following as personal information for that purpose:
Online-account credentials count. A username or email address combined with a password or security question and answer that permits access to an online account falls within the statute's breach-notification definition of personal information.
So if a municipal WordPress site has user accounts, the fact that those accounts are “basic” does not make the security issue meaningless. Email addresses and account credentials can trigger real legal consequences if unauthorized acquisition occurs.
California Civil Code §1798.81.5 says a business that owns, licenses or maintains personal information about a California resident must implement and maintain reasonable security procedures and practices appropriate to the nature of the information.
The same section specifically includes a username or email address plus a password or security question/answer permitting account access within its definition of personal information.
That is the part local business owners and residents should pay attention to.
Imagine a city contracts with a private marketing or website company to manage a WordPress installation. The system contains resident or user accounts. The contractor may have administrator access, hosting access, database access, backup access or plugin-level access.
The useful questions are no longer “Is WordPress bad?” or “Is the contractor a marketing company?” The useful questions are:
A normal WordPress installation stores user information in the database and normally stores passwords as hashes, not plain text. Finding a hashed password by itself is not evidence of wrongdoing.
The stronger security questions concern the entire control environment: weak administrator passwords, shared admin accounts, unpatched plugins, unrestricted third-party access, poor backup security, missing MFA, weak logging, or a contractor relationship with no clear data-handling rules.
Assembly Bill 1337 is currently attempting to change the IPA framework so that local agencies would be brought into the law more broadly. The current bill text contains provisions that would become operative in 2028 and would change the statutory definition of covered agencies.
But as of August 2026, AB 1337 is still pending legislation — it is not current law.
Translation: California has already built meaningful privacy and security rules around businesses and state agencies, and it has breach-notification rules that reach local government. But the broader IPA structure still contains a local-agency carveout that lawmakers are actively considering changing.
A city website is not just a digital brochure when residents have accounts. Once a government website accepts logins, contact information, applications, forms, payments, submissions or other identifiable records, the security architecture becomes part of public accountability.
Residents should be able to ask:
Before accusing a vendor or city of breaking a law, establish the facts. Identify what data exists, who owns it, who maintains it, what access the contractor has, what the contract says, what controls are in place and whether an actual unauthorized disclosure or acquisition occurred.
If those answers are solid, good. If nobody can explain them, that is the story.
Editorial note: This article is general public-law and cybersecurity education, not legal advice and not an allegation that any named city or contractor violated California law. A legal conclusion requires the actual system facts, contractual terms, data involved and applicable statutes.
Access, data, controls, contract, logging, evidence — not accusations.
Don't have a business email, or just want to say something quick? This isn't the formal contact form — no company domain required, nothing but a message is needed.