Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Breaking News: California Passes First Internet of Things (“IoT”) Law

By Griffen Thorne on October 3, 2018
Email this postTweet this postLike this postShare this post on LinkedIn
cannabis marijuana IOT
Cannabis things included.

Two years ago, we published a series of posts about the cannabis industry’s embrace of the Internet of Things (“IoT”)—the network of physical objects connected through the Internet—for use in everything from garden sensors to dispensers. In that same series, we also discussed some of the potential legal risks and ramifications of using the IoT in the cannabis business—particularly some of the privacy and security risks inherent in the IoT.

Just last week, California Governor Jerry Brown approved of SB-327, the first information security law in the U.S. specifically targeting the IoT. SB-327 takes effect on January 1, 2020, and will require manufacturers of connected devices—essentially, devices in the IoT—to equip them with “reasonable” security measures. These security measures must be appropriate to the nature of the devices and information they collect and contain, and must be designed to protect the devices from unauthorized access, destruction, use, modification, or disclosure. SB-327 also requires devices that can be accessed outside of a local area network either to be equipped with a unique password or to allow a user to generate its own password.

It’s important to emphasize that SB-327 does not impose any requirements on users of IoT devices, but rather to manufacturers. So, for many businesses in the cannabis space that rely on the IoT, no real changes in operations may be necessary. Both plant-touching and ancillary marijuana companies that manufacture qualifying devices, on the other hand, may need to re-do or even re-invent their products.

It’s also important to note that the law applies to more than just California manufacturers. It applies so long as a business manufactures—either itself or through a contracting third party—qualifying devices that will be sold or offered for sale in California. Crucially, there is no threshold for product sales in California. Consequently, any manufacturer, anywhere, could be subject to SB-327.

Complying with SB-327 may be as simple as assigning randomly generated passwords to each device or re-tooling software or firmware to provide more robust security protection. But for some manufacturers—especially of devices that gather or contain sensitive information—compliance may be more involved and may require a ground-up reinvention. Consultation with counsel is always the best step towards compliance.

Photo of Griffen Thorne Griffen Thorne

Griffen is an attorney in Harris Bricken’s Los Angeles office, where he focuses his practice on advisory, litigation, and regulatory matters across a wide variety of industries. His litigation practice includes patent, trademark, trade secret, copyright, entertainment, false advertising, unfair competition, and complex…

Griffen is an attorney in Harris Bricken’s Los Angeles office, where he focuses his practice on advisory, litigation, and regulatory matters across a wide variety of industries. His litigation practice includes patent, trademark, trade secret, copyright, entertainment, false advertising, unfair competition, and complex commercial disputes throughout the United States. In that capacity, Griffen has argued (and won) many dispositive and other motions, participated as a member of trial and arbitration teams, and argued before the California Court of Appeals.

In addition to litigation, Griffen’s practice also includes trademark prosecution and non-litigation enforcement of intellectual property rights. Griffen is a Certified Information Privacy Professional in the United States (“CIPP/US”) and Europe (“CIPP/E”), and he assists clients in data breach counseling and response, compliance with privacy laws, and drafting website privacy policies.

Prior to beginning his legal career, Griffen studied music at the University of California, Berkeley, and attended law school at Loyola University of Chicago, where he was the Editor-in-Chief of the Loyola University Chicago Law Journal.

In his free time, Griffen enjoys traveling and studying languages.

Read more about Griffen ThorneEmailGriffen's Linkedin ProfileGriffen's Twitter Profile
Show more Show less
  • Posted in:
    Privacy and Cybersecurity
  • Organization:
    Harris Sliwoski

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo