Alabama 2024 Regular Session

Alabama Senate Bill SB213 Compare Versions

Only one version of the bill is available at this time.
OldNewDifferences
11 SB213INTRODUCED
22 Page 0
33 SB213
44 RRIDNMM-1
55 By Senators Orr, Allen
66 RFD: Fiscal Responsibility and Economic Development
77 First Read: 06-Mar-24
88 1
99 2
1010 3
1111 4
1212 5 RRIDNMM-1 03/06/2024 ZAK (L)cr 2024-402
1313 Page 1
1414 First Read: 06-Mar-24
1515 SYNOPSIS:
1616 Existing law provides for the confidentiality of
1717 certain personal information in certain contexts.
1818 This bill would provide that brokers of
1919 individual consumers' data must notify consumers of
2020 certain information on their website.
2121 This bill would provide that data brokers must
2222 register with the Secretary of State.
2323 This bill would provide that data brokers must
2424 protect consumers' data through specified security
2525 measures.
2626 This bill would require the Secretary of State
2727 to adopt rules and procedures to implement and
2828 administer the requirements of this bill.
2929 This bill would provide civil penalties for data
3030 brokers that violate these notification or registration
3131 requirements.
3232 This bill would provide that violations of the
3333 duty to protect consumers' data through specified
3434 security measures by data brokers constitute violations
3535 of the Deceptive Trade Practices Act.
3636 This bill would provide certain persons and
3737 information to which the requirements of this bill do
3838 not apply.
3939 Section 111.05 of the Constitution of Alabama of
4040 1
4141 2
4242 3
4343 4
4444 5
4545 6
4646 7
4747 8
4848 9
4949 10
5050 11
5151 12
5252 13
5353 14
5454 15
5555 16
5656 17
5757 18
5858 19
5959 20
6060 21
6161 22
6262 23
6363 24
6464 25
6565 26
6666 27
6767 28 SB213 INTRODUCED
6868 Page 2
6969 Section 111.05 of the Constitution of Alabama of
7070 2022, prohibits a general law whose purpose or effect
7171 would be to require a new or increased expenditure of
7272 local funds from becoming effective with regard to a
7373 local governmental entity without enactment by a 2/3
7474 vote unless: it comes within one of a number of
7575 specified exceptions; it is approved by the affected
7676 entity; or the Legislature appropriates funds, or
7777 provides a local source of revenue, to the entity for
7878 the purpose.
7979 The purpose or effect of this bill would be to
8080 require a new or increased expenditure of local funds
8181 within the meaning of the section. However, the bill
8282 does not require approval of a local governmental
8383 entity or enactment by a 2/3 vote to become effective
8484 because it comes within one of the specified exceptions
8585 contained in the section.
8686 A BILL
8787 TO BE ENTITLED
8888 AN ACT
8989 Relating to data privacy; to require consumer data
9090 brokers to publicly state certain information; to require data
9191 brokers to register with the Secretary of State; to require
9292 that data brokers protect data using specified security
9393 measures; to provide civil and criminal penalties for
9494 violations; to provide persons and information to which these
9595 29
9696 30
9797 31
9898 32
9999 33
100100 34
101101 35
102102 36
103103 37
104104 38
105105 39
106106 40
107107 41
108108 42
109109 43
110110 44
111111 45
112112 46
113113 47
114114 48
115115 49
116116 50
117117 51
118118 52
119119 53
120120 54
121121 55
122122 56 SB213 INTRODUCED
123123 Page 3
124124 violations; to provide persons and information to which these
125125 requirements do not apply; and in connection therewith would
126126 have as its purpose or effect the requirement of a new or
127127 increased expenditure of local funds within the meaning of
128128 Section 111.05 of the Constitution of Alabama of 2022.
129129 BE IT ENACTED BY THE LEGISLATURE OF ALABAMA:
130130 Section 1. For the purposes of this act, the following
131131 terms have the following meanings:
132132 (1) BIOMETRIC DATA. Data generated by automatic
133133 measurements of an individual's biological patterns or
134134 characteristics, including fingerprint, voiceprint, retina or
135135 iris scan, information pertaining to an individual's DNA, or
136136 another unique biological pattern or characteristic that is
137137 used to identify a specific individual.
138138 (2) CHILD. An individual younger than 13 years of age.
139139 (3) COLLECT. In the context of data, means to obtain,
140140 receive, access, or otherwise acquire data by any means,
141141 including by purchasing or renting the data.
142142 (4) DATA BROKER. A business entity whose principal
143143 source of revenue is derived from the collecting,
144144 processing, or transferring of personal data that the entity
145145 did not collect directly from the individual linked or
146146 linkable to the data.
147147 (5) DE-IDENTIFIED DATA. Data that cannot reasonably be
148148 linked to an identified or identifiable individual or to a
149149 device linked to that individual.
150150 (6) EMPLOYEE. An individual who is a director, officer,
151151 staff member, trainee, volunteer, or intern of an employer or
152152 an individual working as an independent contractor for an
153153 57
154154 58
155155 59
156156 60
157157 61
158158 62
159159 63
160160 64
161161 65
162162 66
163163 67
164164 68
165165 69
166166 70
167167 71
168168 72
169169 73
170170 74
171171 75
172172 76
173173 77
174174 78
175175 79
176176 80
177177 81
178178 82
179179 83
180180 84 SB213 INTRODUCED
181181 Page 4
182182 an individual working as an independent contractor for an
183183 employer, regardless of whether the individual is paid,
184184 unpaid, or employed on a temporary basis. The term does not
185185 include an individual contractor who is a service provider.
186186 (7) EMPLOYEE DATA. Information collected, processed, or
187187 transferred by an employer if the information satisfies both
188188 of the following:
189189 a. Is related to any of the following:
190190 1. A job applicant and was collected during the course
191191 of the hiring and application process.
192192 2. An employee who is acting in a professional capacity
193193 for the employer, including the employee's business contact
194194 information such as the employee's name, position, title,
195195 business telephone number, business address, or business
196196 e-mail address.
197197 3. An employee's emergency contact information.
198198 4. An employee or the employee's spouse, dependent,
199199 covered family member, or beneficiary.
200200 b. Was collected, processed, or transferred solely for
201201 any of the following:
202202 1. A purpose relating to the status of an individual
203203 described by subparagraph a.1. as a current or former job
204204 applicant of the employer.
205205 2. A purpose relating to the professional
206206 activities of an employee described by subparagraph a.2. on
207207 behalf of the employer.
208208 3. The purpose of having an emergency contact on file
209209 for an employee described by subparagraph a.3. and for
210210 transferring the information in case of an emergency.
211211 85
212212 86
213213 87
214214 88
215215 89
216216 90
217217 91
218218 92
219219 93
220220 94
221221 95
222222 96
223223 97
224224 98
225225 99
226226 100
227227 101
228228 102
229229 103
230230 104
231231 105
232232 106
233233 107
234234 108
235235 109
236236 110
237237 111
238238 112 SB213 INTRODUCED
239239 Page 5
240240 transferring the information in case of an emergency.
241241 4. The purpose of administering benefits
242242 to which an employee described by subparagraph a.4. is
243243 entitled or to which another individual described by that
244244 paragraph is entitled on the basis of the employee's position
245245 with the employer.
246246 (8) GENETIC DATA. Any data, regardless of
247247 format, concerning an individual's genetic characteristics.
248248 The term includes raw sequence data derived from sequencing
249249 all or a portion of an individual's extracted DNA and
250250 genotypic and phenotypic information obtained from analyzing
251251 an individual's raw sequence data.
252252 (9) KNOWN CHILD. A child under circumstances where a
253253 data broker has actual knowledge of, or willfully disregards
254254 obtaining actual knowledge of, the child's age.
255255 (10) PERSONAL DATA. Any information, including
256256 sensitive data, that is linked or reasonably linkable to a
257257 identified or identifiable individual. The term includes
258258 pseudonymous data when the information is used by a controller
259259 or processor in conjunction with additional information that
260260 reasonably links the information to an identified or
261261 identifiable individual. The term does not include
262262 de-identified data, employee data, or publicly available
263263 information.
264264 (11) PRECISE GEOLOCATION DATA. Information
265265 accessed on a device or technology that shows the past or
266266 present physical location of an individual or the individual's
267267 device with sufficient precision to identify street-level
268268 location information of the individual or device in a range of
269269 113
270270 114
271271 115
272272 116
273273 117
274274 118
275275 119
276276 120
277277 121
278278 122
279279 123
280280 124
281281 125
282282 126
283283 127
284284 128
285285 129
286286 130
287287 131
288288 132
289289 133
290290 134
291291 135
292292 136
293293 137
294294 138
295295 139
296296 140 SB213 INTRODUCED
297297 Page 6
298298 location information of the individual or device in a range of
299299 not more than 1,850 feet. The term does not include location
300300 information regarding an individual or device identifiable or
301301 derived solely from the visual content of a legally obtained
302302 image, including the location of a device that captured the
303303 image.
304304 (12) PROCESS. In the context of data, an
305305 operation or set of operations performed, whether by manual or
306306 automated means, on personal data or on sets of personal data,
307307 such as the collection, use, storage, disclosure, analysis,
308308 deletion, or modification of personal data.
309309 (13) PUBLICLY AVAILABLE INFORMATION. Information to
310310 which any of the following apply:
311311 a. Is lawfully made available through governmental
312312 records.
313313 b. A business has a reasonable basis to believe
314314 is lawfully available to the general public through widely
315315 distributed media.
316316 c. Is lawfully made available by a consumer, or
317317 by an individual to whom a consumer has disclosed the
318318 information, unless the consumer has restricted access to the
319319 information to a specific audience.
320320 (14) SENSITIVE DATA.
321321 a. A government-issued identifier not required by law
322322 to be publicly available, including any of the following:
323323 1. A Social Security number.
324324 2. A passport number.
325325 3. A driver license number.
326326 b. Information that describes or reveals an
327327 141
328328 142
329329 143
330330 144
331331 145
332332 146
333333 147
334334 148
335335 149
336336 150
337337 151
338338 152
339339 153
340340 154
341341 155
342342 156
343343 157
344344 158
345345 159
346346 160
347347 161
348348 162
349349 163
350350 164
351351 165
352352 166
353353 167
354354 168 SB213 INTRODUCED
355355 Page 7
356356 b. Information that describes or reveals an
357357 individual's mental or physical health diagnosis, condition,
358358 or treatment.
359359 c. An individual's financial information, except the
360360 last four digits of a debit or credit card number, including
361361 any of the following:
362362 1. A financial account number.
363363 2. A credit or debit card number.
364364 3. Information that describes or reveals the income
365365 level or bank account balances of the individual.
366366 d. Biometric data.
367367 e. Genetic data.
368368 f. Precise geolocation data.
369369 g. An individual's private communication, and that if
370370 made using a device, is not made using a device provided by
371371 the individual's employer that provides conspicuous notice to
372372 the individual that the employer may access communication made
373373 using the device. These communications include, unless the
374374 data broker is the sender or an intended recipient of the
375375 communication, all of the following:
376376 1. The individual's voicemails, e-mails, texts, direct
377377 messages, or mail.
378378 2. Information that identifies the parties involved in
379379 the communications.
380380 3. Information that relates to the transmission of the
381381 communications, including telephone numbers called, telephone
382382 numbers from which calls were placed, the time calls were
383383 made, call duration, and location information of the parties
384384 to the call.
385385 169
386386 170
387387 171
388388 172
389389 173
390390 174
391391 175
392392 176
393393 177
394394 178
395395 179
396396 180
397397 181
398398 182
399399 183
400400 184
401401 185
402402 186
403403 187
404404 188
405405 189
406406 190
407407 191
408408 192
409409 193
410410 194
411411 195
412412 196 SB213 INTRODUCED
413413 Page 8
414414 to the call.
415415 h. A log-in credential, security code, or access code
416416 for an account or device.
417417 i. Information identifying the sexual behavior of the
418418 individual in a manner inconsistent with the individual's
419419 reasonable expectation regarding the collection, processing,
420420 or transfer of the information.
421421 j. Calendar information, address book information,
422422 phone or text logs, photos, audio recordings, or videos that
423423 are both:
424424 1. Maintained for private use by an individual and
425425 stored on the individual's device or in another location.
426426 2. Not communicated using a device provided by the
427427 individual's employer unless the employee was provided
428428 conspicuous notice that the employer may access communication
429429 made using the device.
430430 k. A photograph, film, video recording, or other
431431 similar medium that shows the individual or a part of the
432432 individual nude or wearing undergarments.
433433 l. Information revealing the video content requested or
434434 selected by an individual that is neither of the following:
435435 1. Collected by a provider of broadcast television
436436 service, cable service, satellite service, streaming media
437437 service, or other video programming, as that term is defined
438438 by 47 U.S.C. § 613.
439439 2. Used solely for transfers for independent video
440440 measurement.
441441 m. Information regarding a known child.
442442 n. Information revealing an individual's racial or
443443 197
444444 198
445445 199
446446 200
447447 201
448448 202
449449 203
450450 204
451451 205
452452 206
453453 207
454454 208
455455 209
456456 210
457457 211
458458 212
459459 213
460460 214
461461 215
462462 216
463463 217
464464 218
465465 219
466466 220
467467 221
468468 222
469469 223
470470 224 SB213 INTRODUCED
471471 Page 9
472472 n. Information revealing an individual's racial or
473473 ethnic origin, color, religious beliefs, or union membership.
474474 o. Information identifying an individual's online
475475 activities over time accessing multiple Internet websites or
476476 online services.
477477 p. Information collected, processed, or
478478 transferred for the purpose of identifying information
479479 described by this subdivision.
480480 (15) SERVICE PROVIDER. A person that receives,
481481 collects, processes, or transfers personal data on behalf of,
482482 and at the direction of, a business or governmental entity,
483483 including a business or governmental entity that is another
484484 service provider, in order for the person to perform a service
485485 or function with or on behalf of the business or governmental
486486 entity.
487487 (16) TRANSFER. In the context of data, to disclose,
488488 release, share, disseminate, make available, sell, or license
489489 the data by any means or medium.
490490 Section 2. (a) Except as provided by subsection (b),
491491 this act applies to personal data from an individual that is
492492 collected, transferred, or processed by a data broker.
493493 (b) This chapter does not apply to any of the following
494494 data:
495495 (1) De-identified data, if the data broker does all of
496496 the following:
497497 a. Takes reasonable technical measures to ensure that
498498 the data is not able to be used to identify an individual with
499499 whom the data is associated.
500500 b. Publicly commits to both of the following in a clear
501501 225
502502 226
503503 227
504504 228
505505 229
506506 230
507507 231
508508 232
509509 233
510510 234
511511 235
512512 236
513513 237
514514 238
515515 239
516516 240
517517 241
518518 242
519519 243
520520 244
521521 245
522522 246
523523 247
524524 248
525525 249
526526 250
527527 251
528528 252 SB213 INTRODUCED
529529 Page 10
530530 b. Publicly commits to both of the following in a clear
531531 and conspicuous manner:
532532 1. To process and transfer the data solely in a
533533 de-identified form without any reasonable means for
534534 reidentification.
535535 2. To not attempt to identify the information to an
536536 individual with whom the data is associated.
537537 c. Contractually obligates a person that receives the
538538 information from the provider to both of the following:
539539 1. Comply with this subsection with respect to the
540540 information.
541541 2. Include those contractual obligations in any
542542 subsequent transfer of the data to another person.
543543 (2) Employee data.
544544 (3) Publicly available information.
545545 (4) Inferences made exclusively from multiple
546546 independent sources of publicly available information that
547547 does not reveal sensitive data with respect to an individual.
548548 (5) Data subject to Title V of the Gramm-Leach-Bliley
549549 Act, 15 U.S.C. § 6801, et seq.
550550 Section 3. (a) Except as provided by subsection (b),
551551 this act applies only to a data broker that derives either of
552552 the following within a 12-month period:
553553 (1) More than 50 percent of the data broker's revenue
554554 from processing or transferring personal data that the data
555555 broker did not collect directly from the individuals to whom
556556 the data pertains.
557557 (2) Revenue from processing or transferring the
558558 personal data of more than 50,000 individuals that the data
559559 253
560560 254
561561 255
562562 256
563563 257
564564 258
565565 259
566566 260
567567 261
568568 262
569569 263
570570 264
571571 265
572572 266
573573 267
574574 268
575575 269
576576 270
577577 271
578578 272
579579 273
580580 274
581581 275
582582 276
583583 277
584584 278
585585 279
586586 280 SB213 INTRODUCED
587587 Page 11
588588 personal data of more than 50,000 individuals that the data
589589 broker did not collect directly from the individuals to whom
590590 the data pertains.
591591 (b) This chapter does not apply to any of the
592592 following:
593593 (1) A service provider, including a service provider
594594 that engages in the business of processing employee data for a
595595 third-party employer for the sole purpose of providing
596596 benefits to the third-party employer's employees.
597597 (2) A person that collects personal data from another
598598 person to which the person is related by common ownership or
599599 corporate control, provided a reasonable consumer would expect
600600 the persons to share data.
601601 (3) A federal, state, tribal, territorial, or local
602602 governmental entity, including a body, authority, board,
603603 bureau, commission, district, agency, or political subdivision
604604 of a governmental entity.
605605 (4) An entity that serves as a congressionally
606606 designated nonprofit, national resource center, or
607607 clearinghouse to provide assistance to victims, families,
608608 child-serving professionals, and the general public on missing
609609 and exploited children issues.
610610 (5) A consumer reporting agency or other entity that
611611 furnishes information for inclusion in a consumer credit
612612 report or obtains a consumer credit report, but only to the
613613 extent the entity engages in activity regulated or authorized
614614 by the Fair Credit Reporting Act, 15 U.S.C. § 1681, et seq.,
615615 including the collection, maintenance, disclosure, sale,
616616 communication, or use of any personal information bearing on a
617617 281
618618 282
619619 283
620620 284
621621 285
622622 286
623623 287
624624 288
625625 289
626626 290
627627 291
628628 292
629629 293
630630 294
631631 295
632632 296
633633 297
634634 298
635635 299
636636 300
637637 301
638638 302
639639 303
640640 304
641641 305
642642 306
643643 307
644644 308 SB213 INTRODUCED
645645 Page 12
646646 communication, or use of any personal information bearing on a
647647 consumer's creditworthiness, credit standing, credit capacity,
648648 character, general reputation, personal characteristics, or
649649 mode of living.
650650 (6) A financial institution subject to Title V of the
651651 Gramm-Leach-Bliley Act, 15 U.S.C. § 6801, et seq.
652652 Section 4. A data broker that maintains an Internet
653653 website or mobile application shall post a conspicuous notice
654654 on the website or application that complies with all of the
655655 following:
656656 (1) States that the entity maintaining the website or
657657 application is a data broker.
658658 (2) Is clear, not misleading, and readily accessible
659659 by the general public, including individuals with a
660660 disability.
661661 (3) Contains language provided by rule of the Secretary
662662 of State for inclusion in the notice.
663663 Section 5. (a) To conduct business in this state, a
664664 data broker that is subject to this act shall register by
665665 January 1, 2025, with the Secretary of State by filing a
666666 registration certificate and paying a registration fee of
667667 three hundred dollars ($300).
668668 (b) The registration certificate must include all of
669669 the following:
670670 (1) The legal name of the data broker.
671671 (2) A contact individual and the primary physical
672672 address, e-mail address, telephone number, and Internet
673673 website address for the data broker.
674674 (3) A description of the categories of data the data
675675 309
676676 310
677677 311
678678 312
679679 313
680680 314
681681 315
682682 316
683683 317
684684 318
685685 319
686686 320
687687 321
688688 322
689689 323
690690 324
691691 325
692692 326
693693 327
694694 328
695695 329
696696 330
697697 331
698698 332
699699 333
700700 334
701701 335
702702 336 SB213 INTRODUCED
703703 Page 13
704704 (3) A description of the categories of data the data
705705 broker processes and transfers.
706706 (4) A statement of whether or not the data broker
707707 implements a purchaser credentialing process.
708708 (5) If the data broker has actual knowledge that the
709709 data broker possesses personal data of a known child, both of
710710 the following:
711711 a. A statement detailing the data collection practices,
712712 databases, sales activities, and opt-out policies that are
713713 applicable to the personal data of a known child.
714714 b. A statement as to how the data broker complies with
715715 applicable federal and state law regarding the collection,
716716 use, or disclosure of personal data from and about a child on
717717 the Internet.
718718 (6) The number of security breaches the data broker has
719719 experienced during the year immediately preceding the year in
720720 which the registration is filed and, if known, the total
721721 number of consumers affected by each breach.
722722 (c) The registration certificate may include any
723723 additional information or explanation the data broker chooses
724724 to provide to the Secretary of State concerning the data
725725 broker's data collection practices.
726726 (d) A registration certificate expires on the first
727727 anniversary of its date of issuance and every year thereafter.
728728 A data broker may renew a registration certificate by filing a
729729 renewal application, in the form prescribed by the Secretary
730730 of State, and paying a renewal fee of three hundred dollars
731731 ($300).
732732 Section 6. (a) The Secretary of State shall establish
733733 337
734734 338
735735 339
736736 340
737737 341
738738 342
739739 343
740740 344
741741 345
742742 346
743743 347
744744 348
745745 349
746746 350
747747 351
748748 352
749749 353
750750 354
751751 355
752752 356
753753 357
754754 358
755755 359
756756 360
757757 361
758758 362
759759 363
760760 364 SB213 INTRODUCED
761761 Page 14
762762 Section 6. (a) The Secretary of State shall establish
763763 and maintain, on its Internet website, a searchable, central
764764 registry of data brokers registered pursuant to Section 5.
765765 (b) The registry must include both of the following:
766766 (1) A search feature that allows an individual
767767 searching the registry to identify a specific data broker.
768768 (2) For each data broker, the information filed under
769769 Section 5(b).
770770 Section 7. (a) A data broker conducting business in
771771 this state has a duty to protect personal data held by the
772772 data broker in accordance with this section.
773773 (b) A data broker shall develop, implement, and
774774 maintain a comprehensive information security program that is
775775 written in one or more readily accessible parts and employs
776776 administrative, technical, and physical safeguards that are
777777 appropriate for:
778778 (1) The data broker's size, scope, and type of
779779 business;
780780 (2) The amount of resources available to the data
781781 broker;
782782 (3) The amount of data stored by the data broker; and
783783 (4) The need for security and confidentiality of the
784784 personal data stored by the data broker.
785785 (c) The comprehensive information security program
786786 required by this section must:
787787 (1) Incorporate safeguards that are consistent with the
788788 safeguards for protection of personal data and information of
789789 a similar character under state or federal laws and rules
790790 applicable to the data broker;
791791 365
792792 366
793793 367
794794 368
795795 369
796796 370
797797 371
798798 372
799799 373
800800 374
801801 375
802802 376
803803 377
804804 378
805805 379
806806 380
807807 381
808808 382
809809 383
810810 384
811811 385
812812 386
813813 387
814814 388
815815 389
816816 390
817817 391
818818 392 SB213 INTRODUCED
819819 Page 15
820820 applicable to the data broker;
821821 (2) Include the designation of one or more employees of
822822 the data broker to maintain the program;
823823 (3) Require the identification and assessment of
824824 reasonably foreseeable internal and external risks to the
825825 security, confidentiality, and integrity of any electronic,
826826 paper, or other record containing personal data, and the
827827 establishment of a process for evaluating and improving, as
828828 necessary, the effectiveness of the current safeguards for
829829 limiting those risks, including:
830830 a. Requiring ongoing employee and contractor education
831831 and training, including education and training for temporary
832832 employees and contractors of the data broker, on the proper
833833 use of security procedures and protocols and the importance of
834834 personal data security;
835835 b. Mandating employee compliance with policies and
836836 procedures established under the program; and
837837 c. Providing a means for detecting and preventing
838838 security system failures;
839839 (4) Include security policies for the data broker's
840840 employees relating to the storage, access, and transportation
841841 of records containing personal data outside of the broker's
842842 physical business premises;
843843 (5) Provide disciplinary measures for violations of a
844844 policy or procedure established under the program;
845845 (6) Include measures for preventing a terminated
846846 employee from accessing records containing personal data;
847847 (7) Provide policies for the supervision of third-party
848848 service providers that include:
849849 393
850850 394
851851 395
852852 396
853853 397
854854 398
855855 399
856856 400
857857 401
858858 402
859859 403
860860 404
861861 405
862862 406
863863 407
864864 408
865865 409
866866 410
867867 411
868868 412
869869 413
870870 414
871871 415
872872 416
873873 417
874874 418
875875 419
876876 420 SB213 INTRODUCED
877877 Page 16
878878 service providers that include:
879879 a. Taking reasonable steps to select and retain
880880 third-party service providers that are capable of maintaining
881881 appropriate security measures to protect personal data
882882 consistent with applicable law; and
883883 b. Requiring third-party service providers, by
884884 contract, to implement and maintain appropriate security
885885 measures for personal data;
886886 (8) Provide reasonable restrictions on physical access
887887 to records containing personal data, including requiring the
888888 records containing the data to be stored in a locked facility,
889889 storage area, or container;
890890 (9) Include regular monitoring to ensure that the
891891 program is operating in a manner reasonably calculated to
892892 prevent unauthorized access to or unauthorized use of personal
893893 data and, as necessary, upgrading information safeguards to
894894 limit the risk of unauthorized access to or unauthorized use
895895 of personal data;
896896 (10)a. Require the regular review of the scope of the
897897 program's security measures;
898898 b. A review of the scope of the program's security
899899 measures must occur at least annually and anytime there is a
900900 material change in the data broker's business practices that
901901 may reasonably affect the security or integrity of records
902902 containing personal data;
903903 (11) Require the documentation of responsive actions
904904 taken in connection with any incident involving a breach of
905905 security, including a mandatory post-incident review of each
906906 event and the actions taken, if any, to make changes in
907907 421
908908 422
909909 423
910910 424
911911 425
912912 426
913913 427
914914 428
915915 429
916916 430
917917 431
918918 432
919919 433
920920 434
921921 435
922922 436
923923 437
924924 438
925925 439
926926 440
927927 441
928928 442
929929 443
930930 444
931931 445
932932 446
933933 447
934934 448 SB213 INTRODUCED
935935 Page 17
936936 event and the actions taken, if any, to make changes in
937937 business practices relating to the protection of personal data
938938 in response to that event; and
939939 (12) To the extent feasible, include the following
940940 procedures and protocols with respect to computer system
941941 security requirements or procedures and protocols providing a
942942 higher degree of security, for the protection of personal
943943 data:
944944 a. Using secure user authentication protocols that
945945 include:
946946 1. Controlling user log-in credentials and other
947947 identifiers;
948948 2. Using a reasonably secure method of assigning and
949949 selecting passwords or using unique identifier technologies,
950950 which may include biometrics or token devices;
951951 3. Controlling data security passwords to ensure that
952952 the passwords are kept in a location and format that do not
953953 compromise the security of the data the passwords protect;
954954 4. Restricting access to only active users and active
955955 user accounts; and
956956 5. Blocking access to user credentials or
957957 identification after multiple unsuccessful attempts to gain
958958 access;
959959 b. Using secure access control measures that include:
960960 1. Restricting access to records containing personal
961961 data to only employees or contractors who need access to the
962962 personal data to perform their job duties; and
963963 2. Assigning to each employee or contractor with access
964964 to a computer containing personal data a unique identification
965965 449
966966 450
967967 451
968968 452
969969 453
970970 454
971971 455
972972 456
973973 457
974974 458
975975 459
976976 460
977977 461
978978 462
979979 463
980980 464
981981 465
982982 466
983983 467
984984 468
985985 469
986986 470
987987 471
988988 472
989989 473
990990 474
991991 475
992992 476 SB213 INTRODUCED
993993 Page 18
994994 to a computer containing personal data a unique identification
995995 and password, which may not be a vendor-supplied default
996996 password, or using another protocol reasonably designed to
997997 maintain the integrity of the security of the access controls
998998 to personal data;
999999 c. Encryption of:
10001000 1. Transmitted records containing personal data that
10011001 will travel across public networks; and
10021002 2. Data containing personal data that is transmitted
10031003 wirelessly;
10041004 d. Reasonable monitoring of systems for unauthorized
10051005 use of or access to personal data;
10061006 e. Encryption of all personal data stored on laptop
10071007 computers or other portable devices;
10081008 f. For records containing personal data on a system
10091009 that is connected to the Internet, using reasonably current
10101010 firewall protection and operating system security patches that
10111011 are reasonably designed to maintain the integrity of the
10121012 personal data; and
10131013 g. Using:
10141014 1. A reasonably current version of system security
10151015 agent software that must include malware protection and
10161016 reasonably current patches and virus definitions; or
10171017 2. A version of system security agent software that is
10181018 supportable with current patches and virus definitions and is
10191019 set to receive the most current security updates on a regular
10201020 basis.
10211021 (d) A violation of this section by a data broker
10221022 constitutes a violation of the Deceptive Trade Practices Act,
10231023 477
10241024 478
10251025 479
10261026 480
10271027 481
10281028 482
10291029 483
10301030 484
10311031 485
10321032 486
10331033 487
10341034 488
10351035 489
10361036 490
10371037 491
10381038 492
10391039 493
10401040 494
10411041 495
10421042 496
10431043 497
10441044 498
10451045 499
10461046 500
10471047 501
10481048 502
10491049 503
10501050 504 SB213 INTRODUCED
10511051 Page 19
10521052 constitutes a violation of the Deceptive Trade Practices Act,
10531053 Chapter 19 of Title 8, Code of Alabama 1975, and shall be
10541054 subject to the same penalties as provided therein.
10551055 Section 8. (a) A data broker that violates Section 4 or
10561056 5 shall be assessed the following civil penalties by the
10571057 Secretary of State:
10581058 (1) One hundred dollars ($100) for each day the entity
10591059 is in violation.
10601060 (2) The amount of unpaid registration fees for each
10611061 year the entity fails to register as required by Section 5.
10621062 (b) A civil penalty assessed pursuant to this section
10631063 may not exceed ten thousand dollars ($10,000) against a single
10641064 data broker during a 12-month period.
10651065 (c) The Attorney General may bring an action to recover
10661066 any civil penalty assessed under this section and may recover
10671067 reasonable attorney fees and court costs incurred in bringing
10681068 the action.
10691069 (d)(1) All penalties collected pursuant to this act
10701070 shall be deposited into the Consumer Privacy Protection Fund
10711071 which is created in the State Treasury. The fund shall be
10721072 administered by the Secretary of State for the purpose of
10731073 implementing and administering this act.
10741074 (2) No money shall be withdrawn or expended from this
10751075 fund for any purpose unless the monies have been appropriated
10761076 by the Legislature and allocated pursuant to this act. Any
10771077 monies appropriated shall be budgeted and allocated pursuant
10781078 to the Budget Management Act in accordance with Article 4,
10791079 commencing with Section 41-4-80 of Chapter 4 of Title 41, Code
10801080 of Alabama 1975, and only in the amounts provided by the
10811081 505
10821082 506
10831083 507
10841084 508
10851085 509
10861086 510
10871087 511
10881088 512
10891089 513
10901090 514
10911091 515
10921092 516
10931093 517
10941094 518
10951095 519
10961096 520
10971097 521
10981098 522
10991099 523
11001100 524
11011101 525
11021102 526
11031103 527
11041104 528
11051105 529
11061106 530
11071107 531
11081108 532 SB213 INTRODUCED
11091109 Page 20
11101110 of Alabama 1975, and only in the amounts provided by the
11111111 Legislature in the general appropriations act or other
11121112 appropriations act.
11131113 Section 9. The Secretary of State shall adopt rules as
11141114 necessary to implement this act.
11151115 Section 10. This act does not apply to the collection,
11161116 processing, or transfer of personal data by a data broker
11171117 before January 1, 2025.
11181118 Section 11. Although this bill would have as its
11191119 purpose or effect the requirement of a new or increased
11201120 expenditure of local funds, the bill is excluded from further
11211121 requirements and application under Section 111.05 of the
11221122 Constitution of Alabama of 2022, because the bill defines a
11231123 new crime or amends the definition of an existing crime.
11241124 Section 12. This act shall become effective on October
11251125 1, 2024.
11261126 533
11271127 534
11281128 535
11291129 536
11301130 537
11311131 538
11321132 539
11331133 540
11341134 541
11351135 542
11361136 543
11371137 544
11381138 545
11391139 546
11401140 547