Alabama 2024 Regular Session

Alabama House Bill HB21 Compare Versions

OldNewDifferences
1-HB21ENROLLED
1+HB21ENGROSSED
22 Page 0
33 HB21
4-LGGRYAY-3
4+LGGRYAY-2
55 By Representative Brown
66 RFD: Judiciary
77 First Read: 06-Feb-24
88 PFD: 01-Dec-23
99 1
1010 2
1111 3
1212 4
1313 5
14-6 HB21 Enrolled
14+6 HB21 Engrossed
1515 Page 1
1616 PFD: 01-Dec-23
17-Enrolled, An Act,
17+A BILL
18+TO BE ENTITLED
19+AN ACT
1820 Relating to consumer privacy; to require genetic
1921 testing companies to protect the confidentiality of customers'
2022 genetic information; to require customer consent for certain
2123 uses by genetic testing companies of genetic information; and
2224 to further provide a civil penalty for violations of this act
2325 to be enforced by the Attorney General.
2426 BE IT ENACTED BY THE LEGISLATURE OF ALABAMA:
2527 Section 1. This act shall be known as the "Alabama
2628 Genetic Data Privacy Act."
2729 Section 2. For purposes of this act, the following
2830 words have the following meanings:
2931 (1) BIOLOGICAL SAMPLE. Any human material known to
3032 contain DNA, including, but not limited to, tissue, saliva,
3133 blood, or urine.
3234 (2) CONSUMER. Any individual who is an Alabama
3335 resident.
3436 (3) CONTRACTOR. A person that contracts with a genetic
3537 testing company to provide a service necessary to the genetic
3638 testing company's consumer products or services which requires
3739 possession of a consumer's biological sample or genetic data,
38-including laboratory facilities for genetic testing.
39-(4) DEIDENTIFIED DATA. Genetic data possessed by a
40-genetic testing company that cannot be used to infer
41-information about, or otherwise be linked to, an identifiable
42-consumer and that either meets the requirements for
43-deidentification of genetic data set forth in 45 C.F.R.
44-164.514 or is subject to the following:
4540 1
4641 2
4742 3
4843 4
4944 5
5045 6
5146 7
5247 8
5348 9
5449 10
5550 11
5651 12
5752 13
5853 14
5954 15
6055 16
6156 17
6257 18
6358 19
6459 20
6560 21
6661 22
6762 23
6863 24
6964 25
7065 26
7166 27
72-28 HB21 Enrolled
67+28 HB21 Engrossed
7368 Page 2
74-164.514 or is subject to the following:
75-a. Administrative and technical measures put in place
76-by the genetic testing company to ensure that the data cannot
77-be associated with an identified consumer.
78-b. A public commitment by the genetic testing company
79-to undertake the following:
80-1. Maintain and use the data only in a deidentified
81-form.
82-2. Prohibit any attempts to reidentify the data.
83-3. Take legal action to enforce contractual obligations
84-that prohibit any recipient of the data from attempting to
85-reidentify the data.
69+possession of a consumer's biological sample or genetic data,
70+including laboratory facilities for genetic testing.
71+(4) DEIDENTIFIED DATA. Genetic data possessed by a
72+genetic testing company that cannot reasonably be linked to an
73+identifiable consumer.
8674 (5) DNA. Deoxyribonucleic acid.
8775 (6) EXPRESS CONSENT. A consumer's acknowledgment or
8876 permission, in writing or captured electronically, to a clear,
8977 meaningful, and prominent written notice regarding the
9078 collection, use, retention, or disclosure of the consumer's
9179 biological sample or genetic data for a specific purpose.
9280 (7) GENETIC DATA. a. Any data derived from analysis of
9381 a biological sample which concerns a consumer's genetic
9482 characteristics and which may include, but is not limited to,
9583 any of the following formats or sources:
9684 1. Raw data that results from sequencing all or a
9785 portion of a consumer's extracted DNA.
9886 2. Genotypic and phenotypic information obtained from
9987 analyzing a consumer's raw sequence data.
10088 3. Health information self-reported by the consumer to
10189 a genetic testing company to be used by the company in
10290 connection with analyzing the consumer's raw sequence data or
91+for product development or scientific research.
92+b. Genetic data does not include deidentified data.
93+(8) GENETIC TESTING. Laboratory testing of a consumer's
94+biological sample to analyze DNA, including, but not limited
95+to, chromosomes and single nucleotide polymorphisms in order
96+to derive and interpret genetic data.
97+(9) GENETIC TESTING COMPANY or COMPANY. Any person,
10398 29
10499 30
105100 31
106101 32
107102 33
108103 34
109104 35
110105 36
111106 37
112107 38
113108 39
114109 40
115110 41
116111 42
117112 43
118113 44
119114 45
120115 46
121116 47
122117 48
123118 49
124119 50
125120 51
126121 52
127122 53
128123 54
129124 55
130-56 HB21 Enrolled
125+56 HB21 Engrossed
131126 Page 3
132-connection with analyzing the consumer's raw sequence data or
133-for product development or scientific research.
134-b. Genetic data does not include deidentified data.
135-(8) GENETIC TESTING. Laboratory testing of a consumer's
136-biological sample to analyze DNA, including, but not limited
137-to, chromosomes and single nucleotide polymorphisms in order
138-to derive and interpret genetic data.
139127 (9) GENETIC TESTING COMPANY or COMPANY. Any person,
140128 other than a health care provider, that directly solicits a
141129 biological sample from a consumer for analysis in order to
142130 provide products or services to the consumer which include
143131 disclosure of information that may include, but is not limited
144132 to, the following:
145133 a. The genetic link of the consumer to certain
146134 population groups based on ethnicity, geography, or
147135 anthropology.
148136 b. The probable relationship of the consumer to other
149137 individuals based on matching DNA for purposes that include
150138 genealogical research.
151139 c. Recommendations to the consumer for managing
152140 wellness which are based on physical or metabolic traits,
153141 lifestyle tendencies, or disease predispositions that are
154142 associated with genetic markers present in the consumer's DNA.
155143 (10) HEALTH CARE PROVIDER. Any hospital, as defined in
156144 Section 22-21-20, Code of Alabama 1975, licensed by the State
157145 Board of Health, and any physician, nurse, or other licensed
158146 medical practitioner, whether in individual, group,
159147 professional corporation, or professional association
160148 practice, which provides diagnostic services or treatment for
149+a patient of such hospital, physician, nurse, or other
150+licensed medical practitioner.
151+Section 3. (a)(1) A genetic testing company shall
152+prominently display to a consumer complete information
153+regarding the company's policies and procedures governing the
154+collection, use, maintenance, and disclosure of genetic data
155+in plain language which includes all of the following:
161156 57
162157 58
163158 59
164159 60
165160 61
166161 62
167162 63
168163 64
169164 65
170165 66
171166 67
172167 68
173168 69
174169 70
175170 71
176171 72
177172 73
178173 74
179174 75
180175 76
181176 77
182177 78
183178 79
184179 80
185180 81
186181 82
187182 83
188-84 HB21 Enrolled
183+84 HB21 Engrossed
189184 Page 4
190-practice, which provides diagnostic services or treatment for
191-a patient of such hospital, physician, nurse, or other
192-licensed medical practitioner.
193-Section 3. (a)(1) A genetic testing company shall
194-prominently display to a consumer complete information
195-regarding the company's policies and procedures governing the
196-collection, use, maintenance, and disclosure of genetic data
197185 in plain language which includes all of the following:
198186 a. A privacy policy overview that includes basic
199187 information about the company's collection, use, or disclosure
200188 of genetic data.
201189 b. A privacy policy notice that sets forth the complete
202190 text of the company's collection, consent, use, access,
203191 disclosure, transfer, security, retention, and deletion
204192 policies or practices.
205193 c. A clear and complete notice that the consumer's
206194 genetic data may be included in deidentified data shared or
207195 disclosed by the company to a third party for research in
208196 compliance with the U.S. Department of Health and Human
209197 Services policy for the protection of human subjects, 45
210198 C.F.R. Part 46.
211199 d. A clear description of how to file a complaint
212200 alleging a violation of this act.
213201 (2) A genetic testing company shall obtain the
214202 consumer's initial express consent for all of the following:
215203 a. Use of the biological sample and resulting genetic
216204 data to provide the product or service ordered by the
217205 consumer.
218206 b. Identification of who may have access to the
207+biological sample, genetic data, and test results, including a
208+contractor, in order to fulfill the consumer's order.
209+c. Permission to retain the biological sample and
210+genetic data for future testing for other products or services
211+offered by the company.
212+d. Acknowledgment that the company may seek express
213+consent in the future to transfer the biological sample or
219214 85
220215 86
221216 87
222217 88
223218 89
224219 90
225220 91
226221 92
227222 93
228223 94
229224 95
230225 96
231226 97
232227 98
233228 99
234229 100
235230 101
236231 102
237232 103
238233 104
239234 105
240235 106
241236 107
242237 108
243238 109
244239 110
245240 111
246-112 HB21 Enrolled
241+112 HB21 Engrossed
247242 Page 5
248-b. Identification of who may have access to the
249-biological sample, genetic data, and test results, including a
250-contractor, in order to fulfill the consumer's order.
251-c. Permission to retain the biological sample and
252-genetic data for future testing for other products or services
253-offered by the company.
254-d. Acknowledgment that the company may seek express
255243 consent in the future to transfer the biological sample or
256244 disclose the genetic data to a third party other than a
257245 contractor for a reason other than fulfillment of an order for
258246 the company's products or services.
247+e. Permission to market additional customized products
248+and services to the consumer through the company's online
249+account portal or electronic application provided to the
250+consumer.
259251 (3) A genetic testing company shall obtain the
260252 consumer's express consent every time the company does any of
261253 the following:
262254 a. Transferring the biological sample or disclosing the
263255 genetic data to a third party other than a contractor for a
264256 reason other than fulfillment of an order for the company's
265257 products or services.
266258 b. Using the biological sample or genetic data for a
267259 purpose other than the company's products or services ordered
268260 by the consumer.
269-c. Marketing to a consumer based on the consumer's
270-genetic data, or marketing to a consumer by a third party
271-based on the consumer having ordered or purchased a genetic
272-testing product or service. Marketing does not include the
273-provision of customized content or offers on websites or
274-through the applications or services provided by the
275-direct-to-consumer genetic testing company with the
276-first-party relationship to the consumer.
261+c. Sharing the consumer's name with a third party to
262+market the third party's products and services to the
263+consumer.
264+(4) A genetic testing company shall obtain the
265+consumer's informed consent to transfer the biological sample
266+or disclose the consumer's genetic data in compliance with 45
267+C.F.R. Part 46, in the following cases:
268+a. For independent research conducted by a third party.
269+b. For research conducted under the sponsorship of the
270+genetic testing company for the purpose of product or service
271+research and development, scientific publication, or promotion
277272 113
278273 114
279274 115
280275 116
281276 117
282277 118
283278 119
284279 120
285280 121
286281 122
287282 123
288283 124
289284 125
290285 126
291286 127
292287 128
293288 129
294289 130
295290 131
296291 132
297292 133
298293 134
299294 135
300295 136
301296 137
302297 138
303298 139
304-140 HB21 Enrolled
299+140 HB21 Engrossed
305300 Page 6
306-first-party relationship to the consumer.
307-(4) A genetic testing company shall obtain the
308-consumer's informed consent to transfer the biological sample
309-or disclose the consumer's genetic data in compliance with 45
310-C.F.R. Part 46, in the following cases:
311-a. For independent research conducted by a third party.
312-b. For research conducted under the sponsorship of the
313-genetic testing company for the purpose of product or service
314301 research and development, scientific publication, or promotion
315302 of the company.
316303 (5)a. A genetic testing company shall provide a process
317304 for the consumer to do all of the following:
318305 1. Access the consumer's genetic data.
319306 2. Delete the consumer's account.
320307 3. Request the destruction of the consumer's biological
321308 sample and genetic data.
322309 4. Revoke any express or informed consent given.
323310 b. 1. If the consumer requests the destruction of the
324311 consumer's biological sample and genetic data, the company
325312 shall comply with the request as soon as reasonably possible,
326313 but no more than 30 days after the request is made.
327314 2. If the consumer revokes any express or informed
328315 consent given that resulted in the transfer of the consumer's
329316 biological sample or disclosure of the consumer's genetic data
330317 to a third party, the company shall secure the return of the
331318 biological sample and the genetic data as soon as reasonably
332319 possible, but no more than 60 days after the revocation is
333320 tendered.
334321 (b) A genetic testing company may disclose a consumer's
322+genetic data to any law enforcement agency pursuant to a valid
323+subpoena. When a law enforcement agency requests data from a
324+genetic testing company, the company shall not disclose the
325+existence of the subpoena or the fact of the company's
326+compliance.
327+(c) A genetic testing company may not do any of the
328+following without a consumer's express written consent:
335329 141
336330 142
337331 143
338332 144
339333 145
340334 146
341335 147
342336 148
343337 149
344338 150
345339 151
346340 152
347341 153
348342 154
349343 155
350344 156
351345 157
352346 158
353347 159
354348 160
355349 161
356350 162
357351 163
358352 164
359353 165
360354 166
361355 167
362-168 HB21 Enrolled
356+168 HB21 Engrossed
363357 Page 7
364-(b) A genetic testing company may disclose a consumer's
365-genetic data to any law enforcement agency pursuant to a valid
366-legal process. When a law enforcement agency requests data
367-from a genetic testing company, the company shall not disclose
368-the existence of the valid legal process or the fact of the
369-company's compliance specifically to the party to whom the
370-valid legal process pertains. Nothing in this subsection shall
371-prevent a company from publishing a transparency report that
372-details the number and types of law enforcement requests
373-received and the number of times categories of information are
374-shared, nor prevent a company from complying with other laws
375-or policies, including a company's privacy policy.
376-(c) A genetic testing company may not do any of the
377-following without a consumer's express written consent:
378358 (1) Disclose a consumer's genetic data to any person
379359 issuing health, life, disability, or long-term care insurance.
380360 (2) Disclose a consumer's genetic data to any employer
381361 or prospective employer of the consumer.
382362 Section 4. (a) A contract between the genetic testing
383363 company and a contractor shall prohibit the contractor from
384364 using, retaining, or disclosing any biological sample,
385365 extracted genetic material, genetic data, or information
386366 identifying the consumer for any purpose other than performing
387367 the service specified in the contract.
388368 (b) A contractor shall be subject to the same
389369 confidentiality obligation as the company, consistent with
390370 each express consent given or withheld by a consumer with
391371 respect to using, retaining, or disclosing the consumer's
372+biological sample, extracted genetic material, genetic data,
373+or information identifying the consumer.
374+Section 5. This act does not apply to any of the
375+following:
376+(1) A covered entity or business associate as those
377+terms are defined in 45 C.F.R. Parts 160 and 164.
378+(2) The collection, use, or retention of biological
379+samples or genetic data for noncommercial purposes, including
380+for research and instruction, by a public or private
381+institution of higher learning or any entity owned or operated
382+by a public or private institution of higher learning.
383+Section 6. (a) Any consumer may report a violation of
384+this act to the the Consumer Division of the Office of the
385+Attorney General.
392386 169
393387 170
394388 171
395389 172
396390 173
397391 174
398392 175
399393 176
400394 177
401395 178
402396 179
403397 180
404398 181
405399 182
406400 183
407401 184
408402 185
409403 186
410404 187
411405 188
412406 189
413407 190
414408 191
415409 192
416410 193
417411 194
418412 195
419-196 HB21 Enrolled
413+196 HB21 Engrossed
420414 Page 8
421-respect to using, retaining, or disclosing the consumer's
422-biological sample, extracted genetic material, genetic data,
423-or information identifying the consumer.
424-Section 5. This act does not apply to any of the
425-following:
426-(1) A covered entity or business associate as those
427-terms are defined in 45 C.F.R. Parts 160 and 164.
428-(2) The collection, use, or retention of biological
429-samples or genetic data for noncommercial purposes, including
430-for research and instruction, by a public or private
431-institution of higher learning or any entity owned or operated
432-by a public or private institution of higher learning.
433-(3) Biological samples or genetic data lawfully
434-obtained by law enforcement pursuant to a criminal
435-investigation.
436-Section 6. (a) Any consumer may report a violation of
437-this act to the the Consumer Division of the Office of the
438415 Attorney General.
439416 (b) The Consumer Division of the Office of the Attorney
440417 General may enforce this act by a civil action in circuit
441418 court to enjoin any practice or conduct in violation of this
442419 act or to recover a civil penalty of up to three thousand
443420 dollars ($3,000) for each violation.
444421 (c) Any civil penalty and costs may be waived if the
445422 genetic testing company or contractor has made full
446423 restitution or has paid actual damages to any consumer who has
447424 been injured by a violation of this act.
448425 (d) In any settlement of a claim or civil action
449426 resulting from a violation of this act, the Office of the
427+Attorney General shall receive reasonable attorney fees and
428+costs.
429+Section 7. This act shall become effective on October
430+1, 2024.
450431 197
451432 198
452433 199
453434 200
454435 201
455436 202
456437 203
457438 204
458439 205
459440 206
460441 207
461442 208
462443 209
463444 210
464-211
445+211 HB21 Engrossed
446+Page 9
447+1, 2024.
448+House of Representatives
449+Read for the first time and referred
450+to the House of Representatives
451+committee on Judiciary
452+................06-Feb-23
453+Read for the second time and placed
454+on the calendar:
455+ 3 amendments
456+................14-Feb-24
457+Read for the third time and passed
458+as amended
459+Yeas 102
460+Nays 0
461+Abstains 0
462+................20-Feb-24
463+John Treadwell
464+Clerk
465465 212
466466 213
467467 214
468468 215
469469 216
470470 217
471471 218
472472 219
473473 220
474474 221
475475 222
476476 223
477-224 HB21 Enrolled
478-Page 9
479-resulting from a violation of this act, the Office of the
480-Attorney General shall receive reasonable attorney fees and
481-costs.
482-Section 7. This act shall become effective on October
483-1, 2024.
477+224
484478 225
485479 226
486480 227
487-228 HB21 Enrolled
488-Page 10
489-1, 2024.
490-________________________________________________
491-Speaker of the House of Representatives
492-________________________________________________
493-President and Presiding Officer of the Senate
494-House of Representatives
495-I hereby certify that the within Act originated in and
496-was passed by the House 20-Feb-24, as amended.
497-John Treadwell
498-Clerk
499-Senate 08-May-24 Amended and Passed
500-House 08-May-24 Concurred in Senate
501-Amendment
481+228
502482 229
503483 230
504484 231
505485 232
506-233
507-234
508-235
509-236
510-237
511-238
512-239
513-240
514-241
515-242
516-243
517-244
518-245
519-246
520-247
521-248
522-249
523-250
524-251
525-252
526-253
527-254
528-255
529-256
530-257
531-258
532-259
533-260
534-261