Alabama 2025 Regular Session

Alabama House Bill HB283 Compare Versions

Only one version of the bill is available at this time.
OldNewDifferences
11 HB283INTRODUCED
22 Page 0
33 HB283
44 ZUVVKWR-1
55 By Representatives Shaw, Brown, Lipscomb, Moore (P), Lomax
66 RFD: Commerce and Small Business
77 First Read: 13-Feb-25
88 1
99 2
1010 3
1111 4
1212 5 ZUVVKWR-1 02/03/2025 THR (L)THR 2024-3028
1313 Page 1
1414 First Read: 13-Feb-25
1515 SYNOPSIS:
1616 This bill would authorize a consumer to confirm
1717 whether a controller is processing any of the
1818 consumer's personal data, correct any inaccuracies in
1919 the consumer's personal data, direct a controller to
2020 delete the consumer's personal data, obtain a copy of
2121 the consumer's personal data, and opt out of the
2222 processing of the consumer's data.
2323 This bill would require a controller to
2424 establish a secure and reliable method for a consumer
2525 to exercise the consumer's rights and to establish an
2626 appeals process.
2727 This bill would authorize a consumer to
2828 designate an authorized agent to exercise the
2929 consumer's rights.
3030 This bill would regulate the manner in which a
3131 controller may process consumer data.
3232 This bill would also regulate the processing of
3333 deidentified data.
3434 A BILL
3535 TO BE ENTITLED
3636 AN ACT
3737 1
3838 2
3939 3
4040 4
4141 5
4242 6
4343 7
4444 8
4545 9
4646 10
4747 11
4848 12
4949 13
5050 14
5151 15
5252 16
5353 17
5454 18
5555 19
5656 20
5757 21
5858 22
5959 23
6060 24
6161 25
6262 26
6363 27
6464 28 HB283 INTRODUCED
6565 Page 2
6666 AN ACT
6767 Relating to data privacy; to authorize a consumer to
6868 take certain actions regarding the consumer's personal data;
6969 to regulate the manner in which a controller may process
7070 personal data; and to regulate the processing of deidentified
7171 data.
7272 BE IT ENACTED BY THE LEGISLATURE OF ALABAMA:
7373 Section 1. For the purposes of this act, the following
7474 terms have the following meanings:
7575 (1) AFFILIATE. A legal entity that shares common
7676 branding with another legal entity or that controls, is
7777 controlled by, or is under common control with another legal
7878 entity.
7979 (2) AUTHENTICATE. To use reasonable methods to
8080 determine that a request to exercise any of the consumer
8181 rights afforded under Section 4 is being made by, or on behalf
8282 of, a consumer who is entitled to exercise those consumer
8383 rights with respect to the consumer's personal data at issue.
8484 (3) BIOMETRIC DATA. Data generated by automatic
8585 measurements of an individual's biological characteristics
8686 that are used to identify a specific individual, including,
8787 but not limited to, a fingerprint, voiceprint, retina, or
8888 iris. The term does not include any of the following:
8989 a. A digital or physical photograph.
9090 b. An audio or video recording.
9191 c. Any data generated from a. or b.
9292 (4) CHILD. An individual under 13 years of age.
9393 (5) CONSENT. A clear affirmative act signifying a
9494 29
9595 30
9696 31
9797 32
9898 33
9999 34
100100 35
101101 36
102102 37
103103 38
104104 39
105105 40
106106 41
107107 42
108108 43
109109 44
110110 45
111111 46
112112 47
113113 48
114114 49
115115 50
116116 51
117117 52
118118 53
119119 54
120120 55
121121 56 HB283 INTRODUCED
122122 Page 3
123123 (5) CONSENT. A clear affirmative act signifying a
124124 consumer's freely given, specific, informed, and unambiguous
125125 agreement to allow the processing of personal data relating to
126126 the consumer, including, but not limited to, a written
127127 statement or a statement by electronic means. The term does
128128 not include any of the following:
129129 a. Acceptance of a general or broad term of use or
130130 similar document that contains descriptions of personal data
131131 processing along with other unrelated information.
132132 b. Hovering over, muting, pausing, or closing a given
133133 piece of content.
134134 c. An agreement obtained using dark patterns.
135135 (6) CONSUMER. An individual who is a resident of this
136136 state. The term does not include an individual acting in a
137137 commercial or employment context or as an employee, owner,
138138 director, officer, or contractor of a company, partnership,
139139 sole proprietorship, nonprofit, or government agency whose
140140 communications or transactions with the controller occur
141141 solely within the context of that individual's role with the
142142 company, partnership, sole proprietorship, nonprofit, or
143143 government agency.
144144 (7) CONTROL. Any of the following:
145145 a. Ownership of or the power to vote more than 50
146146 percent of the outstanding shares of any class of voting
147147 security of a company.
148148 b. Control in any manner over the election of a
149149 majority of the directors or of individuals exercising similar
150150 functions.
151151 c. The power to exercise controlling influence over the
152152 57
153153 58
154154 59
155155 60
156156 61
157157 62
158158 63
159159 64
160160 65
161161 66
162162 67
163163 68
164164 69
165165 70
166166 71
167167 72
168168 73
169169 74
170170 75
171171 76
172172 77
173173 78
174174 79
175175 80
176176 81
177177 82
178178 83
179179 84 HB283 INTRODUCED
180180 Page 4
181181 c. The power to exercise controlling influence over the
182182 management of a company.
183183 (8) CONTROLLER. An individual or legal entity that,
184184 alone or jointly with others, determines the purposes and
185185 means of processing personal data.
186186 (9) DARK PATTERN. A user interface designed or
187187 manipulated with the effect of substantially subverting or
188188 impairing user autonomy, decision-making, or choice.
189189 (10) DEIDENTIFIED DATA. Data that cannot be used to
190190 reasonably infer information about or otherwise be linked to
191191 an identified or identifiable individual or a device linked to
192192 an identified or identifiable individual if the controller
193193 that possesses the data does all of the following:
194194 a. Takes reasonable measures to ensure that the data
195195 cannot be associated with an individual.
196196 b. Publicly commits to process the data in a
197197 deidentified fashion only and to not attempt to reidentify the
198198 data.
199199 c. Contractually obligates any recipients of the data
200200 to satisfy the criteria set forth in Section 10(a) and (b).
201201 (11) IDENTIFIABLE INDIVIDUAL. An individual who can be
202202 readily identified, directly or indirectly.
203203 (12) NONPROFIT ENTITY. As defined in Section
204204 10A-1-1.03, Code of Alabama 1975.
205205 (13) PERSONAL DATA. Any information that is linked or
206206 reasonably linkable to an identified or identifiable
207207 individual. The term does not include deidentified data or
208208 publicly available information.
209209 (14) PRECISE GEOLOCATION DATA. Information derived from
210210 85
211211 86
212212 87
213213 88
214214 89
215215 90
216216 91
217217 92
218218 93
219219 94
220220 95
221221 96
222222 97
223223 98
224224 99
225225 100
226226 101
227227 102
228228 103
229229 104
230230 105
231231 106
232232 107
233233 108
234234 109
235235 110
236236 111
237237 112 HB283 INTRODUCED
238238 Page 5
239239 (14) PRECISE GEOLOCATION DATA. Information derived from
240240 technology, including, but not limited to, global positioning
241241 system level latitude and longitude coordinates, which
242242 directly identifies the specific location of an individual
243243 with precision and accuracy within a radius of 1,750 feet. The
244244 term does not include the content of communications or any
245245 data generated by or connected to advanced utility metering
246246 infrastructure systems or equipment for use by a utility.
247247 (15) PROCESS. Any operation or set of operations,
248248 whether by manual or automated means, performed on personal
249249 data or on sets of personal data, including, but not limited
250250 to, the collection, use, storage, disclosure, analysis,
251251 deletion, or modification of personal data.
252252 (16) PROCESSOR. An individual or legal entity that
253253 processes personal data on behalf of a controller.
254254 (17) PROFILING. Any form of automated processing
255255 performed on personal data to evaluate, analyze, or predict
256256 personal aspects related to an identified or identifiable
257257 individual's economic situation, health, personal preferences,
258258 interests, reliability, behavior, location, or movements.
259259 (18) PSEUDONYMOUS DATA. Personal data that cannot be
260260 attributed to a specific individual without the use of
261261 additional information, provided the additional information is
262262 kept separately and is subject to appropriate technical and
263263 organizational measures to ensure that the personal data is
264264 not attributable to an identified or identifiable individual.
265265 (19) PUBLICLY AVAILABLE INFORMATION. Either of the
266266 following:
267267 a. Information that is lawfully made available through
268268 113
269269 114
270270 115
271271 116
272272 117
273273 118
274274 119
275275 120
276276 121
277277 122
278278 123
279279 124
280280 125
281281 126
282282 127
283283 128
284284 129
285285 130
286286 131
287287 132
288288 133
289289 134
290290 135
291291 136
292292 137
293293 138
294294 139
295295 140 HB283 INTRODUCED
296296 Page 6
297297 a. Information that is lawfully made available through
298298 federal, state, or local government records or widely
299299 distributed media.
300300 b. Information that a controller has a reasonable basis
301301 to believe a consumer has lawfully made available to the
302302 public.
303303 (20) SALE OF PERSONAL DATA. The exchange of personal
304304 data for monetary or other valuable consideration by a
305305 controller to a third party. The term does not include any of
306306 the following:
307307 a. The disclosure of personal data to a processor that
308308 processes the personal data on behalf of the controller.
309309 b. The disclosure of personal data to a third party for
310310 the purposes of providing a product or service requested by
311311 the consumer.
312312 c. The disclosure or transfer of personal data to an
313313 affiliate of the controller.
314314 d. The disclosure of personal data in which the
315315 consumer directs the controller to disclose the personal data
316316 or intentionally uses the controller to interact with a third
317317 party.
318318 e. The disclosure of personal data that the consumer
319319 intentionally made available to the public via a channel of
320320 mass media and did not restrict to a specific audience.
321321 f. The disclosure or transfer of personal data to a
322322 third party as an asset that is part of a merger, acquisition,
323323 bankruptcy, or other transaction, or a proposed merger,
324324 acquisition, bankruptcy, or other transaction in which the
325325 third party assumes control of all or part of the controller's
326326 141
327327 142
328328 143
329329 144
330330 145
331331 146
332332 147
333333 148
334334 149
335335 150
336336 151
337337 152
338338 153
339339 154
340340 155
341341 156
342342 157
343343 158
344344 159
345345 160
346346 161
347347 162
348348 163
349349 164
350350 165
351351 166
352352 167
353353 168 HB283 INTRODUCED
354354 Page 7
355355 third party assumes control of all or part of the controller's
356356 assets.
357357 (21) SENSITIVE DATA. Personal data that includes any of
358358 the following:
359359 a. Data revealing racial or ethnic origin, religious
360360 beliefs, a mental or physical health condition or diagnosis,
361361 information about an individual's sex life, sexual
362362 orientation, or citizenship or immigration status.
363363 b. The processing of genetic or biometric data for the
364364 purpose of uniquely identifying an individual.
365365 c. Personal data collected from a known child.
366366 d. Precise geolocation data.
367367 (22) SIGNIFICANT DECISION. A decision made by a
368368 controller that results in the controller's provision or
369369 denial of financial or lending services, housing, insurance,
370370 education enrollment or opportunity, criminal justice,
371371 employment opportunity, health care service, or access to
372372 necessities such as food or water.
373373 (23) TARGETED ADVERTISING. Displaying advertisements to
374374 a consumer in which the advertisement is selected based on
375375 personal data obtained or inferred from that consumer's
376376 activities over time and across nonaffiliated Internet
377377 websites or online applications to predict the consumer's
378378 preferences or interests. The term does not include any of the
379379 following:
380380 a. Advertisements based on activities within a
381381 controller's own Internet websites or online applications.
382382 b. Advertisements based on the context of a consumer's
383383 current search query or visit to any Internet website or
384384 169
385385 170
386386 171
387387 172
388388 173
389389 174
390390 175
391391 176
392392 177
393393 178
394394 179
395395 180
396396 181
397397 182
398398 183
399399 184
400400 185
401401 186
402402 187
403403 188
404404 189
405405 190
406406 191
407407 192
408408 193
409409 194
410410 195
411411 196 HB283 INTRODUCED
412412 Page 8
413413 current search query or visit to any Internet website or
414414 online application.
415415 c. Advertisements directed to a consumer in response to
416416 the consumer's request for information or feedback.
417417 d. Processing personal data solely to measure or report
418418 advertising frequency, performance, or reach.
419419 (24) THIRD PARTY. An individual or legal entity other
420420 than a consumer, controller, processor, or an affiliate of the
421421 controller or processor.
422422 (25) TRADE SECRET. As defined in Section 8-27-2, Code
423423 of Alabama 1975.
424424 Section 2. The provisions of this act apply to persons
425425 that conduct business in this state or persons that produce
426426 products or services that are targeted to residents of this
427427 state and that meet either of the following qualifications:
428428 (1) Control or process the personal data of more than
429429 50,000 consumers, excluding personal data controlled or
430430 processes solely for the purpose of completing a payment
431431 transaction.
432432 (2) Control or process the personal data of more than
433433 25,000 consumers and derive more than 25 percent of gross
434434 revenue from the sale of personal data.
435435 Section 3. (a) This act shall not apply to any of the
436436 following:
437437 (1) A political subdivision of the state.
438438 (2) A nonprofit organization.
439439 (3) A 2-year or 4-year institution of higher education.
440440 (4) A national securities association that is
441441 registered under 15 U.S.C. § 780.
442442 197
443443 198
444444 199
445445 200
446446 201
447447 202
448448 203
449449 204
450450 205
451451 206
452452 207
453453 208
454454 209
455455 210
456456 211
457457 212
458458 213
459459 214
460460 215
461461 216
462462 217
463463 218
464464 219
465465 220
466466 221
467467 222
468468 223
469469 224 HB283 INTRODUCED
470470 Page 9
471471 registered under 15 U.S.C. § 780.
472472 (5) A financial institution or an affiliate of a
473473 financial institution governed by 15 U.S.C. Chapter 94.
474474 (6) Personal data collected, processed, sold, or
475475 disclosed in accordance with 15 U.S.C. Chapter 94.
476476 (7) A covered entity or business associate as defined
477477 in the privacy regulations of 45 C.F.R. § 160.13.
478478 (b) This act shall not apply to any of the following
479479 information or data:
480480 (1) Protected health information under the privacy
481481 regulations of the federal Health Insurance Portability and
482482 Accountability Act of 1996.
483483 (2) Patient-identifying information for the purposes of
484484 42 U.S.C. § 290dd2.
485485 (3) Identifiable private information for the purposes
486486 of 45 C.F.R. Part 46.
487487 (4) Identifiable private information that is otherwise
488488 collected as part of human subjects research pursuant to the
489489 good clinical practice guidelines issued by the International
490490 Council for Harmonisation of Technical Requirements for
491491 Pharmaceuticals for Human Use.
492492 (5) The protection of human subjects under 21 C.F.R.
493493 Parts 6, 50, and 56, or personal data used or shared in
494494 research as defined in the federal Health Insurance
495495 Portability and Accountability Act of 1996 and 45 C.F.R. §
496496 164.501, that is conducted in accordance with applicable law.
497497 (6) Information or documents created for the purposes
498498 of the federal Health Care Quality Improvement Act of 1986.
499499 (7) Patient safety work products for the purposes of
500500 225
501501 226
502502 227
503503 228
504504 229
505505 230
506506 231
507507 232
508508 233
509509 234
510510 235
511511 236
512512 237
513513 238
514514 239
515515 240
516516 241
517517 242
518518 243
519519 244
520520 245
521521 246
522522 247
523523 248
524524 249
525525 250
526526 251
527527 252 HB283 INTRODUCED
528528 Page 10
529529 (7) Patient safety work products for the purposes of
530530 the federal Patient Safety and Quality Improvement Act of
531531 2005.
532532 (8) Information derived from any of the health care
533533 related information listed in this subsection which is
534534 deidentified in accordance with the requirements for
535535 deidentification pursuant to the privacy regulations of the
536536 federal Health Insurance Portability and Accountability Act of
537537 1996.
538538 (9) Information derived from any of the health care
539539 related information listed in this subsection which is
540540 included in a limited data set as described in 45 C.F.R. §
541541 164.514(e), to the extent that the information is used,
542542 disclosed, and maintained in a manner specified in 45 C.F.R. §
543543 164.514(e).
544544 (10) Information originating from and intermingled to
545545 be indistinguishable with or information treated in the same
546546 manner as information exempt under this subsection which is
547547 maintained by a covered entity or business associate as
548548 defined in the privacy regulations of the federal Health
549549 Insurance Portability and Accountability Act of 1996 or a
550550 program or qualified service organization as specified in 42
551551 U.S.C. § 290dd-2.
552552 (11) Information used for public health activities and
553553 purposes as authorized by the federal Health Insurance
554554 Portability and Accountability Act of 1996, community health
555555 activities, and population health activities.
556556 (12) The collection, maintenance, disclosure, sale,
557557 communication, or use of any personal information bearing on a
558558 253
559559 254
560560 255
561561 256
562562 257
563563 258
564564 259
565565 260
566566 261
567567 262
568568 263
569569 264
570570 265
571571 266
572572 267
573573 268
574574 269
575575 270
576576 271
577577 272
578578 273
579579 274
580580 275
581581 276
582582 277
583583 278
584584 279
585585 280 HB283 INTRODUCED
586586 Page 11
587587 communication, or use of any personal information bearing on a
588588 consumer's credit worthiness, credit standing, credit
589589 capacity, character, general reputation, personal
590590 characteristics, or mode of living by a consumer reporting
591591 agency, furnisher, or user that provides information for use
592592 in a consumer report and by a user of a consumer report, but
593593 only to the extent that the activity is regulated by and
594594 authorized under the federal Fair Credit Reporting Act.
595595 (13) Personal data collected, processed, sold, or
596596 disclosed in compliance with the federal Driver's Privacy
597597 Protection Act of 1994.
598598 (14) Personal data regulated by the federal Family
599599 Educational Rights and Privacy Act of 1974.
600600 (15) Personal data collected, processed, sold, or
601601 disclosed in compliance with the federal Farm Credit Act of
602602 1971.
603603 (16) Data processed or maintained by an individual
604604 applying to, employed by, or acting as an agent or independent
605605 contractor of a controller, processor, or third party to the
606606 extent that the data is collected and used within the context
607607 of that role.
608608 (17) Data processed or maintained as the emergency
609609 contact information of an individual under this act and used
610610 for emergency contact purposes.
611611 (18) Data processed or maintained that is necessary to
612612 retain to administer benefits for another individual relating
613613 to the individual who is the subject of the information under
614614 this section and is used for the purposes of administering the
615615 benefits.
616616 281
617617 282
618618 283
619619 284
620620 285
621621 286
622622 287
623623 288
624624 289
625625 290
626626 291
627627 292
628628 293
629629 294
630630 295
631631 296
632632 297
633633 298
634634 299
635635 300
636636 301
637637 302
638638 303
639639 304
640640 305
641641 306
642642 307
643643 308 HB283 INTRODUCED
644644 Page 12
645645 benefits.
646646 (19) Personal data collected, processed, sold, or
647647 disclosed in relation to price, route, or service, as these
648648 terms are used in the federal Airline Deregulation Act of 1978
649649 by an air carrier subject to the act.
650650 (20) Data or information collected or processed to
651651 comply with or in accordance with state law.
652652 (c) Controllers and processors that comply with the
653653 verifiable parental consent requirements of the federal
654654 Children's Online Privacy Protection Act of 1998 are compliant
655655 with any obligation to obtain parental consent pursuant to
656656 this act.
657657 Section 4. (a) A consumer has the affirmative right to
658658 do all of the following:
659659 (1) Confirm whether a controller is processing the
660660 consumer's personal data and accessing any of the consumer's
661661 personal data under the control of the controller, unless
662662 confirmation or access would require the controller to reveal
663663 a trade secret.
664664 (2) Correct inaccuracies in the consumer's personal
665665 data, considering the nature of the personal data and the
666666 purposes of the processing of the consumer's personal data.
667667 (3) Direct a controller to delete the consumer's
668668 personal data.
669669 (4) Obtain a copy of the consumer's personal data
670670 previously provided by the consumer to a controller in a
671671 portable and, to the extent technically feasible, readily
672672 usable format that allows the consumer to transmit the
673673 personal data to another controller without hindrance when the
674674 309
675675 310
676676 311
677677 312
678678 313
679679 314
680680 315
681681 316
682682 317
683683 318
684684 319
685685 320
686686 321
687687 322
688688 323
689689 324
690690 325
691691 326
692692 327
693693 328
694694 329
695695 330
696696 331
697697 332
698698 333
699699 334
700700 335
701701 336 HB283 INTRODUCED
702702 Page 13
703703 personal data to another controller without hindrance when the
704704 processing is carried out by automated means, unless the
705705 provision of the data would require the controller to reveal a
706706 trade secret.
707707 (5) Opt out of the processing of the consumer's
708708 personal data for any of the following purposes:
709709 a. Targeted advertising.
710710 b. The sale of the consumer's personal data, except as
711711 provided in Section 6.
712712 c. Profiling in furtherance of solely automated
713713 decisions that produce legal or similarly significant effects
714714 concerning the consumer.
715715 (b) A controller shall establish a secure and reliable
716716 method for a consumer to exercise rights established by this
717717 section and shall describe the method in the controller's
718718 privacy notice.
719719 (c)(1) A consumer may designate an authorized agent in
720720 accordance with Section 5 to exercise the consumer's rights
721721 established by this section.
722722 (2) A parent or legal guardian of a known child may
723723 exercise the consumer's rights on behalf of the known child
724724 regarding the processing of personal data.
725725 (3) A guardian or conservator of a consumer may
726726 exercise the consumer's rights on behalf of the consumer
727727 regarding the processing of personal data.
728728 (d) Except as otherwise provided in this act, a
729729 controller shall comply with a request by a consumer to
730730 exercise the consumer's rights authorized by this section as
731731 follows:
732732 337
733733 338
734734 339
735735 340
736736 341
737737 342
738738 343
739739 344
740740 345
741741 346
742742 347
743743 348
744744 349
745745 350
746746 351
747747 352
748748 353
749749 354
750750 355
751751 356
752752 357
753753 358
754754 359
755755 360
756756 361
757757 362
758758 363
759759 364 HB283 INTRODUCED
760760 Page 14
761761 follows:
762762 (1)a. A controller shall respond to a consumer's
763763 request within 45 days of receipt of the request.
764764 b. A controller may extend the response period by 45
765765 additional days, when reasonably necessary considering the
766766 complexity and number of the consumer's requests, by notifying
767767 the consumer of the extension and the reason for the extension
768768 within the initial 45-day response period.
769769 (2) If a controller declines to act regarding a
770770 consumer's request, the controller shall inform the consumer
771771 of the justification for declining to act within 45 days of
772772 receipt of the request. The notification must also inform the
773773 consumer of the controller's process for appealing the
774774 decision.
775775 (3) Information provided in response to a consumer
776776 request must be provided by a controller, free of charge, once
777777 for each consumer during any 12-month period. If a consumer's
778778 requests are manifestly unfounded, excessive, technically
779779 infeasible, or repetitive, the controller may charge the
780780 consumer a reasonable fee to cover the administrative costs of
781781 complying with a request or decline to act on a request. The
782782 controller bears the burden of demonstrating the manifestly
783783 unfounded, excessive, technically infeasible, or repetitive
784784 nature of a request.
785785 (4) If a controller is unable to authenticate a
786786 consumer's request using commercially reasonable efforts, the
787787 controller shall not be required to comply with a request to
788788 initiate an action pursuant to this section and shall provide
789789 notice to the consumer that the controller is unable to
790790 365
791791 366
792792 367
793793 368
794794 369
795795 370
796796 371
797797 372
798798 373
799799 374
800800 375
801801 376
802802 377
803803 378
804804 379
805805 380
806806 381
807807 382
808808 383
809809 384
810810 385
811811 386
812812 387
813813 388
814814 389
815815 390
816816 391
817817 392 HB283 INTRODUCED
818818 Page 15
819819 notice to the consumer that the controller is unable to
820820 authenticate the request until the consumer provides
821821 additional information reasonably necessary to authenticate
822822 the consumer and the request. A controller is not required to
823823 authenticate an opt-out request, but a controller may deny an
824824 opt-out request if the controller has a good faith,
825825 reasonable, and documented belief that the request is
826826 fraudulent. If a controller denies an opt-out request because
827827 the controller believes the request is fraudulent, the
828828 controller shall send notice to the person who made the
829829 request disclosing that the controller believes the request is
830830 fraudulent and that the controller may not comply with the
831831 request.
832832 (5) A controller that has obtained personal data about
833833 a consumer from a source other than the consumer is in
834834 compliance with a consumer's request to delete the consumer's
835835 data if the controller has done either of the following:
836836 a. Retained a record of the deletion request and the
837837 minimum data necessary for the purpose of ensuring the
838838 consumer's personal data remains deleted from the controller's
839839 records and refrains from using the retained data for any
840840 other purpose.
841841 b. Opted the consumer out of the processing of the
842842 consumer's personal data for any purpose except for those
843843 exempted pursuant to this act.
844844 (e) A controller shall establish a process for a
845845 consumer to appeal the controller's refusal to act on a
846846 consumer's request. The appeal process must be conspicuously
847847 available. Within 60 days of receipt of an appeal, a
848848 393
849849 394
850850 395
851851 396
852852 397
853853 398
854854 399
855855 400
856856 401
857857 402
858858 403
859859 404
860860 405
861861 406
862862 407
863863 408
864864 409
865865 410
866866 411
867867 412
868868 413
869869 414
870870 415
871871 416
872872 417
873873 418
874874 419
875875 420 HB283 INTRODUCED
876876 Page 16
877877 available. Within 60 days of receipt of an appeal, a
878878 controller shall inform the consumer in writing of any action
879879 taken or not taken in response to the appeal, including a
880880 written explanation of the reason for the decision. If the
881881 appeal is denied, the controller shall provide the consumer
882882 with a method through which the consumer may contact the
883883 Attorney General to submit a complaint.
884884 Section 5. (a) A consumer may designate another person
885885 to serve as the consumer's authorized agent and act on the
886886 consumer's behalf to opt out of the processing of the
887887 consumer's personal data for one or more of the purposes
888888 specified in Section 4. The consumer may designate an
889889 authorized agent by way of technology, including, but not
890890 limited to, an Internet link, browser setting, browser
891891 extension, or global device setting indicating a consumer's
892892 intent to opt out of such processing.
893893 (b) A controller shall comply with an opt-out request
894894 received from an authorized agent if the controller is able to
895895 verify, with commercially reasonable effort, the identity of
896896 the consumer and the authorized agent's authority to act on
897897 the consumer's behalf.
898898 (c) An opt-out method must do both of the following:
899899 (1) Provide a clear and conspicuous link on the
900900 controller's Internet website to an Internet web page that
901901 enables a consumer or an agent of the consumer to opt out of
902902 the targeted advertising or sale of the consumer's personal
903903 data.
904904 (2) By no later than January 1, 2026, allow a consumer
905905 or an agent of the consumer to opt out of any processing of
906906 421
907907 422
908908 423
909909 424
910910 425
911911 426
912912 427
913913 428
914914 429
915915 430
916916 431
917917 432
918918 433
919919 434
920920 435
921921 436
922922 437
923923 438
924924 439
925925 440
926926 441
927927 442
928928 443
929929 444
930930 445
931931 446
932932 447
933933 448 HB283 INTRODUCED
934934 Page 17
935935 or an agent of the consumer to opt out of any processing of
936936 the consumer's personal data for the purposes of targeted
937937 advertising, or any sale of such personal data through an
938938 opt-out preference signal sent with the consumer's consent, to
939939 the controller by a platform, technology, or mechanism that
940940 does all of the following:
941941 a. May not unfairly disadvantage another controller.
942942 b. May not make use of a default setting, but require
943943 the consumer to make an affirmative, freely given, and
944944 unambiguous choice to opt out of any processing of a
945945 customer's personal data pursuant to this act.
946946 c. Must be consumer friendly and easy to use by the
947947 average consumer.
948948 d. Must be consistent with any federal or state law or
949949 regulation.
950950 e. Must allow the controller to accurately determine
951951 whether the consumer is a resident of the state and whether
952952 the consumer has made a legitimate request to opt out of any
953953 sale of a consumer's personal data or targeted advertising.
954954 (d)(1) If a consumer's decision to opt out of any
955955 processing of the consumer's personal data for the purposes of
956956 targeted advertising, or any sale of personal data, through an
957957 opt-out preference signal sent in accordance with this section
958958 conflicts with the consumer's existing controller-specific
959959 privacy setting or voluntary participation in a controller's
960960 bona fide loyalty, rewards, premium features, discounts, or
961961 club card program, the controller shall comply with the
962962 consumer's opt-out preference signal but may notify the
963963 consumer of the conflict and provide the choice to confirm
964964 449
965965 450
966966 451
967967 452
968968 453
969969 454
970970 455
971971 456
972972 457
973973 458
974974 459
975975 460
976976 461
977977 462
978978 463
979979 464
980980 465
981981 466
982982 467
983983 468
984984 469
985985 470
986986 471
987987 472
988988 473
989989 474
990990 475
991991 476 HB283 INTRODUCED
992992 Page 18
993993 consumer of the conflict and provide the choice to confirm
994994 controller-specific privacy settings or participation in such
995995 a program.
996996 (2) If a controller responds to consumer opt-out
997997 requests received in accordance with this section by informing
998998 the consumer of a charge for the use of any product or
999999 service, the controller shall present the terms of any
10001000 financial incentive offered pursuant to this section for the
10011001 retention, use, sale, or sharing of the consumer's personal
10021002 data.
10031003 Section 6. (a) A controller shall do all of the
10041004 following:
10051005 (1) Limit the collection of personal data to what is
10061006 adequate, relevant, and reasonably necessary in relation to
10071007 the purposes for which the personal data is processed, as
10081008 disclosed to the consumer.
10091009 (2) Establish, implement, and maintain reasonable
10101010 administrative, technical, and physical data security
10111011 practices to protect the confidentiality, integrity, and
10121012 accessibility of personal data appropriate to the volume and
10131013 nature of the personal data at issue.
10141014 (3) Provide an effective mechanism for a consumer to
10151015 revoke the consumer's consent under this act that is at least
10161016 as easy as the mechanism by which the consumer provided the
10171017 consumer's consent and, on revocation of the consent, cease to
10181018 process the personal data as soon as practicable, but within
10191019 45 days of receipt of the request.
10201020 (b) A controller may not do any of the following:
10211021 (1) Except as provided in this act, process personal
10221022 477
10231023 478
10241024 479
10251025 480
10261026 481
10271027 482
10281028 483
10291029 484
10301030 485
10311031 486
10321032 487
10331033 488
10341034 489
10351035 490
10361036 491
10371037 492
10381038 493
10391039 494
10401040 495
10411041 496
10421042 497
10431043 498
10441044 499
10451045 500
10461046 501
10471047 502
10481048 503
10491049 504 HB283 INTRODUCED
10501050 Page 19
10511051 (1) Except as provided in this act, process personal
10521052 data for purposes that are not reasonably necessary to or
10531053 compatible with the disclosed purposes for which the personal
10541054 data is processed as disclosed to the consumer unless the
10551055 controller obtains the consumer's consent.
10561056 (2) Process sensitive data concerning a consumer
10571057 without obtaining the consumer's consent or, in the case of
10581058 the processing of sensitive data concerning a known child,
10591059 without processing the sensitive data in accordance with the
10601060 federal Children's Online Privacy Protection Act of 1998.
10611061 (3) Process personal data in violation of the laws of
10621062 this state or federal laws that prohibit unlawful
10631063 discrimination against consumers.
10641064 (4) Process the personal data of a consumer for the
10651065 purposes of targeted advertising or sell a consumer's personal
10661066 data without the consumer's consent under circumstances in
10671067 which a controller has actual knowledge that the consumer is
10681068 at least 13 years of age but younger than 16 years of age.
10691069 (5) Discriminate against a consumer for exercising any
10701070 of the consumer rights contained in this act, including
10711071 denying goods or services, charging different prices or rates
10721072 for goods or services, or providing a different level of
10731073 quality of goods or services to the consumer.
10741074 (c) Nothing in subsections (a) or (b) may be construed
10751075 to require a controller to provide a product or service that
10761076 requires the personal data of a consumer that the controller
10771077 does not collect or maintain or prohibit a controller from
10781078 offering a different price, rate, level, quality, or selection
10791079 of goods or services to a consumer, including offering goods
10801080 505
10811081 506
10821082 507
10831083 508
10841084 509
10851085 510
10861086 511
10871087 512
10881088 513
10891089 514
10901090 515
10911091 516
10921092 517
10931093 518
10941094 519
10951095 520
10961096 521
10971097 522
10981098 523
10991099 524
11001100 525
11011101 526
11021102 527
11031103 528
11041104 529
11051105 530
11061106 531
11071107 532 HB283 INTRODUCED
11081108 Page 20
11091109 of goods or services to a consumer, including offering goods
11101110 or services for no fee, if the consumer has exercised his or
11111111 her right to opt out pursuant to this act or the offering is
11121112 in connection with a consumer's voluntary participation in a
11131113 bona fide loyalty, rewards, premium features, discounts, or
11141114 club card program.
11151115 (d) If a controller sells personal data to third
11161116 parties or processes personal data for targeted advertising,
11171117 the controller shall clearly and conspicuously disclose the
11181118 processing, as well as the way a consumer may exercise the
11191119 right to opt out of the processing.
11201120 (e) A controller shall provide consumers with a
11211121 reasonably accurate, clear, and meaningful privacy notice that
11221122 includes all of the following:
11231123 (1) The categories of personal data processed by the
11241124 controller.
11251125 (2) The purpose for processing personal data.
11261126 (3) The categories of personal data that the controller
11271127 shares with third parties, if any.
11281128 (4) The categories of third parties, if any, with which
11291129 the controller shares personal data.
11301130 (5) An active email address or other mechanism that the
11311131 consumer may use to contact the controller.
11321132 (6) How consumers may exercise their consumer rights,
11331133 including a consumer may appeal a controller's decision
11341134 regarding the consumer's request.
11351135 (f)(1) A controller shall establish and describe in a
11361136 privacy notice one or more secure and reliable means for
11371137 consumers to submit a request to exercise their consumer
11381138 533
11391139 534
11401140 535
11411141 536
11421142 537
11431143 538
11441144 539
11451145 540
11461146 541
11471147 542
11481148 543
11491149 544
11501150 545
11511151 546
11521152 547
11531153 548
11541154 549
11551155 550
11561156 551
11571157 552
11581158 553
11591159 554
11601160 555
11611161 556
11621162 557
11631163 558
11641164 559
11651165 560 HB283 INTRODUCED
11661166 Page 21
11671167 consumers to submit a request to exercise their consumer
11681168 rights pursuant to this act considering the ways in which
11691169 consumers normally interact with the controller, the need for
11701170 secure and reliable communication of consumer requests, and
11711171 the ability of the controller to verify the identity of the
11721172 consumer making the request.
11731173 (2) A controller may not require a consumer to create a
11741174 new account to exercise consumer rights but may require a
11751175 consumer to use an existing account.
11761176 Section 7. (a) A processor shall adhere to the
11771177 instructions of a controller and shall assist the controller
11781178 in meeting the controller's obligations under this act,
11791179 including, but not limited to, all of the following:
11801180 (1) Considering the nature of processing and the
11811181 information available to the processor by appropriate
11821182 technical and organizational measures as much as reasonably
11831183 practicable to fulfill the controller's obligation to respond
11841184 to consumer rights requests.
11851185 (2) Considering the nature of processing and the
11861186 information available to the processor by assisting the
11871187 controller in meeting the controller's obligations in relation
11881188 to the security of processing the personal data and in
11891189 relation to the notification of a breach of security of the
11901190 system of the processor to meet the controller's obligations.
11911191 (3) Providing necessary information to enable the
11921192 controller to conduct and document data protection
11931193 assessments.
11941194 (b) A contract between a controller and a processor
11951195 must govern the processor's data processing procedures with
11961196 561
11971197 562
11981198 563
11991199 564
12001200 565
12011201 566
12021202 567
12031203 568
12041204 569
12051205 570
12061206 571
12071207 572
12081208 573
12091209 574
12101210 575
12111211 576
12121212 577
12131213 578
12141214 579
12151215 580
12161216 581
12171217 582
12181218 583
12191219 584
12201220 585
12211221 586
12221222 587
12231223 588 HB283 INTRODUCED
12241224 Page 22
12251225 must govern the processor's data processing procedures with
12261226 respect to processing performed on behalf of the controller.
12271227 The contract must be binding and clearly set forth
12281228 instructions for processing data, the nature and purpose of
12291229 processing, the type of data subject to processing, the
12301230 duration of processing, and the rights and obligations of both
12311231 parties. The contract must also require that the processor do
12321232 all of the following:
12331233 (1) Ensure that each person processing personal data is
12341234 subject to a duty of confidentiality with respect to the
12351235 personal data.
12361236 (2) At the controller's direction, delete or return all
12371237 personal data to the controller as requested at the end of the
12381238 provision of services, unless retention of the personal data
12391239 is required by law.
12401240 (3) Upon the reasonable request of the controller, make
12411241 available to the controller all information in the processor's
12421242 possession necessary to demonstrate the processor's compliance
12431243 with the obligations in this act.
12441244 (4) Engage any subcontractor pursuant to a written
12451245 contract that requires the subcontractor to meet the
12461246 obligations of the processor with respect to the personal
12471247 data.
12481248 (5) Allow and cooperate with reasonable assessments by
12491249 the controller or the controller's designated assessor, or the
12501250 processor may arrange for a qualified and independent assessor
12511251 to assess the processor's policies and technical and
12521252 organizational measures in support of the obligations under
12531253 this act using an appropriate and accepted control standard or
12541254 589
12551255 590
12561256 591
12571257 592
12581258 593
12591259 594
12601260 595
12611261 596
12621262 597
12631263 598
12641264 599
12651265 600
12661266 601
12671267 602
12681268 603
12691269 604
12701270 605
12711271 606
12721272 607
12731273 608
12741274 609
12751275 610
12761276 611
12771277 612
12781278 613
12791279 614
12801280 615
12811281 616 HB283 INTRODUCED
12821282 Page 23
12831283 this act using an appropriate and accepted control standard or
12841284 framework and assessment procedure for the assessments. The
12851285 processor shall provide a report of the assessment to the
12861286 controller on request.
12871287 (c) Nothing in this section may be construed to relieve
12881288 a controller or processor from the liabilities imposed on the
12891289 controller or processor by virtue of the controller's or
12901290 processor's role in the processing relationship as described
12911291 in this act.
12921292 (d) Determining whether a person is acting as a
12931293 controller or processor with respect to a specific processing
12941294 of data is a fact-based determination that depends on the
12951295 following context in which personal data is to be processed:
12961296 (1) A person who is not limited in the processing of
12971297 personal data pursuant to a controller's instructions or who
12981298 fails to adhere to a controller's instructions is a controller
12991299 and not a processor with respect to a specific processing of
13001300 data.
13011301 (2) A processor that continues to adhere to a
13021302 controller's instructions with respect to a specific
13031303 processing of personal data remains a processor.
13041304 (3) If a processor begins, alone or jointly with
13051305 others, determining the purposes and means of the processing
13061306 of personal data, the processor is a controller with respect
13071307 to the processing and may be subject to an enforcement action
13081308 under this act.
13091309 Section 8. (a) A controller shall conduct and document
13101310 a data protection assessment for each of the controller's
13111311 processing activities that presents a heightened risk of harm
13121312 617
13131313 618
13141314 619
13151315 620
13161316 621
13171317 622
13181318 623
13191319 624
13201320 625
13211321 626
13221322 627
13231323 628
13241324 629
13251325 630
13261326 631
13271327 632
13281328 633
13291329 634
13301330 635
13311331 636
13321332 637
13331333 638
13341334 639
13351335 640
13361336 641
13371337 642
13381338 643
13391339 644 HB283 INTRODUCED
13401340 Page 24
13411341 processing activities that presents a heightened risk of harm
13421342 to a consumer. For the purposes of this section, processing
13431343 that presents risk of harm to a consumer includes, but is not
13441344 limited to, all of the following:
13451345 (1) The processing of personal data for the purposes of
13461346 targeted advertising.
13471347 (2) The sale of personal data.
13481348 (3) The processing of personal data for the purposes of
13491349 profiling in which the profiling presents a reasonably
13501350 foreseeable risk of any of the following:
13511351 a. Unfair or deceptive treatment of or unlawful
13521352 disparate impact on consumers.
13531353 b. Financial, physical, or reputational injury to
13541354 consumers.
13551355 c. A physical or other form of intrusion on the
13561356 solitude or seclusion or the private affairs or concerns of
13571357 consumers in which the intrusion would be offensive to a
13581358 reasonable person.
13591359 d. Other substantial injury to consumers.
13601360 (4) The processing of sensitive data.
13611361 (b)(1) Data protection assessments conducted pursuant
13621362 to subsection (a) must identify and weigh the benefits that
13631363 may flow, directly or indirectly, from the processing to the
13641364 controller, the consumer, other stakeholders, and the public
13651365 against the potential risks to the rights of the consumer
13661366 associated with the processing as mitigated by safeguards that
13671367 may be employed by the controller to reduce these risks.
13681368 (2) The controller shall factor into any data
13691369 protection assessment the use of deidentified data and the
13701370 645
13711371 646
13721372 647
13731373 648
13741374 649
13751375 650
13761376 651
13771377 652
13781378 653
13791379 654
13801380 655
13811381 656
13821382 657
13831383 658
13841384 659
13851385 660
13861386 661
13871387 662
13881388 663
13891389 664
13901390 665
13911391 666
13921392 667
13931393 668
13941394 669
13951395 670
13961396 671
13971397 672 HB283 INTRODUCED
13981398 Page 25
13991399 protection assessment the use of deidentified data and the
14001400 reasonable expectations of consumers, as well as the context
14011401 of the processing and the relationship between the controller
14021402 and the consumer whose personal data will be processed.
14031403 (c)(1) The Attorney General may require that a
14041404 controller disclose any data protection assessment that is
14051405 relevant to an investigation conducted by the Attorney
14061406 General, and the controller shall make the data protection
14071407 assessment available to the Attorney General.
14081408 (2) The Attorney General may evaluate the data
14091409 protection assessment for compliance with the responsibilities
14101410 set forth in this act.
14111411 (3) Data protection assessments are confidential and
14121412 are exempt from disclosure under Article 3 of Chapter 12 of
14131413 Title 36, Code of Alabama 1975.
14141414 (4) To the extent any information contained in a data
14151415 protection assessment disclosed to the Attorney General
14161416 includes information subject to attorney-client privilege or
14171417 work product protection, the disclosure may not constitute a
14181418 waiver of the privilege or protection.
14191419 (d) A single data protection assessment may address a
14201420 comparable set of processing operations that include similar
14211421 activities.
14221422 (e) If a controller conducts a data protection
14231423 assessment for the purpose of complying with another
14241424 applicable law or regulation, the data protection assessment
14251425 must be considered to satisfy the requirements established in
14261426 this section if the data protection assessment is reasonably
14271427 similar in scope and the effect to the data protection
14281428 673
14291429 674
14301430 675
14311431 676
14321432 677
14331433 678
14341434 679
14351435 680
14361436 681
14371437 682
14381438 683
14391439 684
14401440 685
14411441 686
14421442 687
14431443 688
14441444 689
14451445 690
14461446 691
14471447 692
14481448 693
14491449 694
14501450 695
14511451 696
14521452 697
14531453 698
14541454 699
14551455 700 HB283 INTRODUCED
14561456 Page 26
14571457 similar in scope and the effect to the data protection
14581458 assessment that would otherwise be conducted pursuant to this
14591459 section.
14601460 (f) Data protection assessment requirements shall apply
14611461 to processing activities created or generated after January 1,
14621462 2026, and are not retroactive.
14631463 Section 9. (a) Any controller in possession of
14641464 deidentified data shall do all of the following:
14651465 (1) Take reasonable measures to ensure that the
14661466 identified data cannot be associated with an individual.
14671467 (2) Publicly commit to maintaining and using
14681468 deidentified data without attempting to reidentify the
14691469 deidentified data.
14701470 (3) Contractually obligate any recipients of the
14711471 deidentified data to comply with all provisions of this act.
14721472 (b) Nothing in this act may be construed to do either
14731473 of the following:
14741474 (1) Require a controller or processor to reidentify
14751475 deidentified data or pseudonymous data.
14761476 (2) Maintain data in identifiable form or collect,
14771477 obtain, retain, or access any data or technology to be capable
14781478 of associating an authenticated consumer request with personal
14791479 data.
14801480 (c) Nothing in this act may be construed to require a
14811481 controller or processor to comply with an authenticated
14821482 consumer rights request if the controller:
14831483 (1) Is not reasonably capable of associating the
14841484 request with the personal data or it would be unreasonably
14851485 burdensome for the controller to associate the request with
14861486 701
14871487 702
14881488 703
14891489 704
14901490 705
14911491 706
14921492 707
14931493 708
14941494 709
14951495 710
14961496 711
14971497 712
14981498 713
14991499 714
15001500 715
15011501 716
15021502 717
15031503 718
15041504 719
15051505 720
15061506 721
15071507 722
15081508 723
15091509 724
15101510 725
15111511 726
15121512 727
15131513 728 HB283 INTRODUCED
15141514 Page 27
15151515 burdensome for the controller to associate the request with
15161516 the personal data;
15171517 (2) Does not use the personal data to recognize or
15181518 respond to the specific consumer who is the subject of the
15191519 personal data or associate the personal data with other
15201520 personal data about the same specific consumer; and
15211521 (3) Does not sell the personal data to any third party
15221522 or otherwise voluntarily disclose the personal data to any
15231523 third party other than a processor, except as otherwise
15241524 permitted in this section.
15251525 (d) The rights afforded under Section 4 may not apply
15261526 to pseudonymous data in cases in which the controller is able
15271527 to demonstrate that any information necessary to identify the
15281528 consumer is kept separately and is subject to effective
15291529 technical and organizational controls that prevent the
15301530 controller from accessing the information.
15311531 (e) A controller that discloses pseudonymous data or
15321532 deidentified data shall exercise reasonable oversight to
15331533 monitor compliance with any contractual commitments to which
15341534 the pseudonymous data or deidentified data is subject and
15351535 shall take appropriate steps to address any breaches of those
15361536 contractual commitments.
15371537 Section 10. (a) Nothing in this act may be construed to
15381538 restrict a controller's or processor's ability to do any of
15391539 the following:
15401540 (1) Comply with federal, state, or local ordinances or
15411541 regulations.
15421542 (2) Comply with a civil, criminal, or regulatory
15431543 inquiry, investigation, subpoena, or summons by federal,
15441544 729
15451545 730
15461546 731
15471547 732
15481548 733
15491549 734
15501550 735
15511551 736
15521552 737
15531553 738
15541554 739
15551555 740
15561556 741
15571557 742
15581558 743
15591559 744
15601560 745
15611561 746
15621562 747
15631563 748
15641564 749
15651565 750
15661566 751
15671567 752
15681568 753
15691569 754
15701570 755
15711571 756 HB283 INTRODUCED
15721572 Page 28
15731573 inquiry, investigation, subpoena, or summons by federal,
15741574 state, local, or other government authority.
15751575 (3) Cooperate with law enforcement agencies concerning
15761576 conduct or activity that the controller or processor
15771577 reasonably and in good faith believes may violate federal,
15781578 state, or local ordinances, rules, or regulations.
15791579 (4) Investigate, establish, exercise, prepare for, or
15801580 defend legal claims.
15811581 (5) Provide a product or service specifically requested
15821582 by a consumer.
15831583 (6) Perform under a contract to which a consumer is a
15841584 party, including fulfilling the terms of a written warranty.
15851585 (7) Take steps at the request of a consumer prior to
15861586 entering a contract.
15871587 (8) Take immediate steps to protect an interest that is
15881588 essential for the life or physical safety of the consumer or
15891589 another individual and when the processing cannot be
15901590 manifestly based on another legal basis.
15911591 (9) Prevent, detect, protect against, or respond to
15921592 security incidents; identify theft, fraud, harassment,
15931593 malicious or deceptive activities, or any illegal activity;
15941594 preserve the integrity or security of systems; or investigate,
15951595 report, or prosecute those responsible for any of these
15961596 actions.
15971597 (10) Engage in public or peer-reviewed scientific or
15981598 statistical research in the public interest that adheres to
15991599 all other applicable ethics and privacy laws and is approved,
16001600 monitored, and governed by an institutional review board that
16011601 determines or similar independent oversight entities that
16021602 757
16031603 758
16041604 759
16051605 760
16061606 761
16071607 762
16081608 763
16091609 764
16101610 765
16111611 766
16121612 767
16131613 768
16141614 769
16151615 770
16161616 771
16171617 772
16181618 773
16191619 774
16201620 775
16211621 776
16221622 777
16231623 778
16241624 779
16251625 780
16261626 781
16271627 782
16281628 783
16291629 784 HB283 INTRODUCED
16301630 Page 29
16311631 determines or similar independent oversight entities that
16321632 determine all of the following:
16331633 a. Whether the deletion of the information is likely to
16341634 provide substantial benefits that do not exclusively accrue to
16351635 the controller.
16361636 b. The expected benefits of the research outweigh the
16371637 privacy risks.
16381638 c. Whether the controller has implemented reasonable
16391639 safeguards to mitigate privacy risks associated with research,
16401640 including any risks associated with reidentification.
16411641 (11) Assist another controller, processor, or third
16421642 party with any of the obligations under this act.
16431643 (12) Process personal data for reasons of public
16441644 interest in public health, community health, or population
16451645 health, but solely to the extent that the processing does both
16461646 of the following:
16471647 a. Subject to suitable and specific measures to
16481648 safeguard the rights of the consumer whose personal data is
16491649 being processed.
16501650 b. Under the responsibility of a professional subject
16511651 to confidentiality obligations under federal, state, or local
16521652 law.
16531653 (b) The obligations imposed on controllers or
16541654 processors under this act may not restrict a controller's or
16551655 processor's ability to collect, use, or retain personal data
16561656 for internal use to do any of the following:
16571657 (1) Conduct internal research to develop, improve, or
16581658 repair products, services, or technology.
16591659 (2) Effectuate a product recall.
16601660 785
16611661 786
16621662 787
16631663 788
16641664 789
16651665 790
16661666 791
16671667 792
16681668 793
16691669 794
16701670 795
16711671 796
16721672 797
16731673 798
16741674 799
16751675 800
16761676 801
16771677 802
16781678 803
16791679 804
16801680 805
16811681 806
16821682 807
16831683 808
16841684 809
16851685 810
16861686 811
16871687 812 HB283 INTRODUCED
16881688 Page 30
16891689 (2) Effectuate a product recall.
16901690 (3) Identify and repair technical errors that impair
16911691 existing or intended functionality.
16921692 (4) Perform internal operations that are reasonably
16931693 aligned with the expectations of the consumer or reasonably
16941694 anticipated based on the consumer's existing relationship with
16951695 the controller or are otherwise compatible with processing
16961696 data in furtherance of the provision of a product or service
16971697 specifically requested by a consumer or the performance of a
16981698 contract to which the consumer is a party.
16991699 (c) The obligations imposed on controllers or
17001700 processors under this act may not apply when compliance by the
17011701 controller with this act would violate an evidentiary
17021702 privilege under the laws of this state. Nothing in this act
17031703 may be construed to prevent a controller or processor from
17041704 providing personal data concerning a consumer to a person
17051705 covered by an evidentiary privilege under the laws of this
17061706 state as part of a privileged communication.
17071707 (d)(1) If, at the time a controller or processor
17081708 discloses personal data to a processor or third-party
17091709 controller in accordance with this act, the controller or
17101710 processor did not have actual knowledge that the processor or
17111711 third-party controller would violate this act, then the
17121712 controller or processor may not be considered to have violated
17131713 this act.
17141714 (2) A receiving processor or third-party controller
17151715 receiving personal data from a disclosing controller or
17161716 processor in compliance with this act is likewise not in
17171717 violation of this act for the transgressions of the disclosing
17181718 813
17191719 814
17201720 815
17211721 816
17221722 817
17231723 818
17241724 819
17251725 820
17261726 821
17271727 822
17281728 823
17291729 824
17301730 825
17311731 826
17321732 827
17331733 828
17341734 829
17351735 830
17361736 831
17371737 832
17381738 833
17391739 834
17401740 835
17411741 836
17421742 837
17431743 838
17441744 839
17451745 840 HB283 INTRODUCED
17461746 Page 31
17471747 violation of this act for the transgressions of the disclosing
17481748 controller or processor from which the receiving processor or
17491749 third-party controller receives the personal data.
17501750 (e) Nothing in this act may be construed to do either
17511751 of the following:
17521752 (1) Impose any obligation on a controller or processor
17531753 that adversely effects the rights or freedoms of any person.
17541754 (2) Apply to a person's processing of personal data
17551755 during the person's personal or household activities.
17561756 (f) Personal data processed by a controller pursuant to
17571757 this section may be processed to the extent that the
17581758 processing is both of the following:
17591759 (1) Reasonably necessary and proportionate to the
17601760 purposes listed in this section.
17611761 (2) Adequate, relevant, and limited to what is
17621762 necessary in relation to the specific purposes listed in this
17631763 section. The controller or processor must, when applicable,
17641764 consider the nature and purpose of the collection, use, or
17651765 retention of the personal data collected, used, or retained
17661766 pursuant to this section. The personal data must be subject to
17671767 reasonable administrative, technical, and physical measures to
17681768 protect the confidentiality, integrity, and accessibility of
17691769 the personal data and to reduce reasonably foreseeable risks
17701770 of harm to consumers relating to the collection, use, or
17711771 retention of personal data.
17721772 (g) If a controller processes personal data pursuant to
17731773 an exemption in this section, the controller bears the burden
17741774 of demonstrating that the processing qualifies for the
17751775 exemption and complies with the requirements in this section.
17761776 841
17771777 842
17781778 843
17791779 844
17801780 845
17811781 846
17821782 847
17831783 848
17841784 849
17851785 850
17861786 851
17871787 852
17881788 853
17891789 854
17901790 855
17911791 856
17921792 857
17931793 858
17941794 859
17951795 860
17961796 861
17971797 862
17981798 863
17991799 864
18001800 865
18011801 866
18021802 867
18031803 868 HB283 INTRODUCED
18041804 Page 32
18051805 exemption and complies with the requirements in this section.
18061806 (h) Processing personal data for the purposes expressly
18071807 identified in this section may not solely make a legal entity
18081808 a controller with respect to the processing.
18091809 Section 11. (a) The Attorney General has exclusive
18101810 authority to enforce violations of this act.
18111811 (b)(1) The Attorney General, prior to initiating any
18121812 action for a violation of any provision of this act, shall
18131813 issue a notice of violation to the controller.
18141814 (2) If the controller fails to correct the violation
18151815 within 60 days of receipt of the notice of violation, the
18161816 Attorney General may bring an action pursuant to this section.
18171817 (3) If within the 60-day period the controller corrects
18181818 the noticed violation and provides the Attorney General an
18191819 express written statement that the alleged violations have
18201820 been corrected and that no such further violations will occur,
18211821 no action may be initiated against the controller.
18221822 (c) Nothing in this act may be construed as providing
18231823 the basis for or be subject to a private right of action for
18241824 violations of this act or any other law.
18251825 Section 12. This act shall become effective on October
18261826 1, 2025.
18271827 869
18281828 870
18291829 871
18301830 872
18311831 873
18321832 874
18331833 875
18341834 876
18351835 877
18361836 878
18371837 879
18381838 880
18391839 881
18401840 882
18411841 883
18421842 884
18431843 885
18441844 886
18451845 887
18461846 888
18471847 889