What is SB 272?
Senate Bill 272 (SB 272) requires California local agencies (excluding local educational agencies) to create a catalog of enterprise systems that store information about the public, and to post this catalog on the agency’s website (or otherwise make it available upon request). The catalog must be updated at least annually.
SB 272 was approved on October 11, 2015 and originally added Government Code section 6270.5 to the California Public Records Act. Effective January 1, 2024, the California Public Records Act was reorganized and the SB 272 catalog requirements are now found in Government Code sections 7922.700–7922.725.
What is covered (definition of “enterprise system”)?
Under Government Code sections 7922.700–7922.725, an “enterprise system” is a software application or computer system that collects, stores, exchanges, and analyzes information that the agency uses and that is both:
- A multidepartmental system or a system that contains information collected about the public; and
- A system of record (a system that serves as an original source of data within an agency).
What is excluded?
This catalog does not include certain enterprise systems and catalog details, including those used for information security, infrastructure or mechanical/operational control, or information that would reveal vulnerabilities or otherwise increase the risk of attack on District information technology systems. The catalog lists only the systems required by law and does not, by itself, require disclosure of the specific records contained in those systems.
- Cybersecurity / information security systems (e.g., systems used to prevent, detect, or respond to cyber threats).
- Infrastructure and mechanical/operational control systems (including SCADA-type systems).
- Any catalog details that would reveal vulnerabilities or otherwise increase the risk of attack on District information technology systems.
This catalog does not include technical configuration details such as network diagrams, IP addresses, software versions, or security architecture.
What is required in the catalog?
For each enterprise system included in the catalog, the agency must disclose:
- Current system vendor
- Current system product
- System purpose
- Categories of data maintained in the system
- Department that serves as the system’s primary custodian
- How frequently the data is collected
- How frequently the data is updated
For the full text of the bill, see
https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=201520160SB272