1 | 1 | | Stricken language would be deleted from and underlined language would be added to present law. |
---|
2 | 2 | | *ANS146* 02/18/2025 3:16:09 PM ANS146 |
---|
3 | 3 | | State of Arkansas 1 |
---|
4 | 4 | | 95th General Assembly A Bill 2 |
---|
5 | 5 | | Regular Session, 2025 SENATE BILL 258 3 |
---|
6 | 6 | | 4 |
---|
7 | 7 | | By: Senator C. Penzo 5 |
---|
8 | 8 | | By: Representative S. Meeks 6 |
---|
9 | 9 | | 7 |
---|
10 | 10 | | For An Act To Be Entitled 8 |
---|
11 | 11 | | AN ACT TO CREATE THE ARKANSAS DIGITAL RESPONSIBILITY, 9 |
---|
12 | 12 | | SAFETY, AND TRUST ACT; AND FOR OTHER PURPOSES. 10 |
---|
13 | 13 | | 11 |
---|
14 | 14 | | 12 |
---|
15 | 15 | | Subtitle 13 |
---|
16 | 16 | | TO CREATE THE ARKANSAS DIGITAL 14 |
---|
17 | 17 | | RESPONSIBILITY, SAFETY, AND TRUST ACT. 15 |
---|
18 | 18 | | 16 |
---|
19 | 19 | | BE IT ENACTED BY THE GENERAL ASSEMBLY OF THE STATE OF ARKANSAS: 17 |
---|
20 | 20 | | 18 |
---|
21 | 21 | | SECTION 1. Arkansas Code Title 4, is amended to add an additional 19 |
---|
22 | 22 | | chapter to read as follows: 20 |
---|
23 | 23 | | 21 |
---|
24 | 24 | | CHAPTER 120 22 |
---|
25 | 25 | | ARKANSAS DIGITAL RESPONSIBILITY, SAFETY, AND TRUST ACT 23 |
---|
26 | 26 | | 24 |
---|
27 | 27 | | Subchapter 1 — General Provisions 25 |
---|
28 | 28 | | 26 |
---|
29 | 29 | | 4-120-101. Title. 27 |
---|
30 | 30 | | This chapter shall be known and may be cited as the "Arkansas Digital 28 |
---|
31 | 31 | | Responsibility, Safety, and Trust Act". 29 |
---|
32 | 32 | | 30 |
---|
33 | 33 | | 4-120-102. Legislative findings. 31 |
---|
34 | 34 | | The General Assembly finds that: 32 |
---|
35 | 35 | | (1) Arkansans and Americans have long valued personal privacy as 33 |
---|
36 | 36 | | something that serves essential human needs of liberty, personal autonomy, 34 |
---|
37 | 37 | | seclusion, family, intimacy, and other relationships, and security; 35 |
---|
38 | 38 | | (2) Privacy safeguards foundational American values of self -36 SB258 |
---|
39 | 39 | | |
---|
40 | 40 | | 2 02/18/2025 3:16:09 PM ANS146 |
---|
41 | 41 | | government; 1 |
---|
42 | 42 | | (3) The United States and Arkansas have long protected aspects 2 |
---|
43 | 43 | | of personal privacy since the nation’s founding, including through the First, 3 |
---|
44 | 44 | | Third, Fourth, Fifth, Ninth, and Fourteenth Amendments to the United States 4 |
---|
45 | 45 | | Constitution and Article 2, §§ 2, 6, 8, 10, 15, 21, and 24 of the Arkansas 5 |
---|
46 | 46 | | Constitution; 6 |
---|
47 | 47 | | (4)(A) The United States has a history of leadership in privacy 7 |
---|
48 | 48 | | rights, passing some of the first privacy laws as early as the eighteenth 8 |
---|
49 | 49 | | century and adopting one (1) of the first national privacy and data 9 |
---|
50 | 50 | | protection laws globally in addition to the “fair information practice 10 |
---|
51 | 51 | | principles” that have influenced laws and privacy practices around the world. 11 |
---|
52 | 52 | | (B) In this information age of the twenty -first century, 12 |
---|
53 | 53 | | in the absence of ongoing federal leadership in privacy, Arkansas should join 13 |
---|
54 | 54 | | over twenty (20) other states in leading privacy protection; 14 |
---|
55 | 55 | | (5)(A) The expansion of computers, internet connectivity, mobile 15 |
---|
56 | 56 | | telephones, and other digital information and communications technology has 16 |
---|
57 | 57 | | magnified the risks to an individual's privacy that can occur from the 17 |
---|
58 | 58 | | collection, processing, storage, or dissemination of personal information. 18 |
---|
59 | 59 | | (B) The overwhelming majority of Arkansans and Americans 19 |
---|
60 | 60 | | have smartphones equipped with powerful computers, immense storage capacity, 20 |
---|
61 | 61 | | arrays of sensors, and the capacity to transmit information around the world 21 |
---|
62 | 62 | | instantaneously. 22 |
---|
63 | 63 | | (C) Some people use these devices continuously and use 23 |
---|
64 | 64 | | them to store a digital record of nearly every aspect of their lives. 24 |
---|
65 | 65 | | (D) Arkansans increasingly have other “smart devices” such 25 |
---|
66 | 66 | | as automobiles, televisions, home appliances, and wearable accessories that 26 |
---|
67 | 67 | | collect, process, and transmit information linked to Arkansans and their 27 |
---|
68 | 68 | | activities to entities around the world; 28 |
---|
69 | 69 | | (6)(A) The personal information of Arkansans and Americans has 29 |
---|
70 | 70 | | been used against them to steal their identities, open financial and credit 30 |
---|
71 | 71 | | accounts in their names, and do other personal and financial harm. 31 |
---|
72 | 72 | | (B) Troves of Arkansan and American personal information 32 |
---|
73 | 73 | | lie in the hands of state adversaries and criminals; 33 |
---|
74 | 74 | | (7) The aggregation of an increasing volume of data among many 34 |
---|
75 | 75 | | different entities expands the exposure to malicious actors in cyberspace and 35 |
---|
76 | 76 | | the availability of personal information to such actors; 36 SB258 |
---|
77 | 77 | | |
---|
78 | 78 | | 3 02/18/2025 3:16:09 PM ANS146 |
---|
79 | 79 | | (8)(A) The risks of harm from privacy violations are 1 |
---|
80 | 80 | | significant. 2 |
---|
81 | 81 | | (B) Unwanted or unexpected disclosure of personal 3 |
---|
82 | 82 | | information and loss of privacy can have devastating effects for individuals, 4 |
---|
83 | 83 | | including financial fraud and loss, identity theft, and the resulting loss of 5 |
---|
84 | 84 | | personal time and money, destruction of property, harassment, and even 6 |
---|
85 | 85 | | potential physical injury. 7 |
---|
86 | 86 | | (C) Other effects such as reputational or emotional damage 8 |
---|
87 | 87 | | can be equally or even more substantial; 9 |
---|
88 | 88 | | (9)(A) With the development of artificial intelligence and 10 |
---|
89 | 89 | | machine learning, the potential to use personal and other information in ways 11 |
---|
90 | 90 | | that replicate existing social problems has increased in scale. 12 |
---|
91 | 91 | | (B) Algorithms use personal and other information to guide 13 |
---|
92 | 92 | | decision-making related to critical issues, such as credit determination, 14 |
---|
93 | 93 | | housing advertisements, and hiring processes, and can result in differing 15 |
---|
94 | 94 | | accuracy rates; 16 |
---|
95 | 95 | | (10)(A) Individuals need to feel confident that data that 17 |
---|
96 | 96 | | relates to them will not be used or shared in ways that can harm themselves, 18 |
---|
97 | 97 | | their families, or society. 19 |
---|
98 | 98 | | (B) As such, organizations that collect, use, retain, and 20 |
---|
99 | 99 | | share personal information should be subject to meaningful and effective 21 |
---|
100 | 100 | | boundaries on such activities, obligated to take reasonable steps to protect 22 |
---|
101 | 101 | | the privacy and security of personal information, and required to mitigate 23 |
---|
102 | 102 | | privacy risks to the individuals whose data they steward; and 24 |
---|
103 | 103 | | (11)(A) The majority of governments around the world already 25 |
---|
104 | 104 | | impose such restrictions on businesses, but Arkansans do not yet have their 26 |
---|
105 | 105 | | right to privacy protected. 27 |
---|
106 | 106 | | (B) It is proper for the General Assembly to protect 28 |
---|
107 | 107 | | Arkansans’ privacy rights, enforce the rights against those who collect, use, 29 |
---|
108 | 108 | | retain, and share their personal information, and establish the legislative 30 |
---|
109 | 109 | | framework for responsible, safe, and trustworthy technology in Arkansas. 31 |
---|
110 | 110 | | 32 |
---|
111 | 111 | | 4-120-103. Definitions. 33 |
---|
112 | 112 | | As used in this chapter: 34 |
---|
113 | 113 | | (1) "Affiliate" means a legal entity that: 35 |
---|
114 | 114 | | (A) Controls, is controlled by, or is under common control 36 SB258 |
---|
115 | 115 | | |
---|
116 | 116 | | 4 02/18/2025 3:16:09 PM ANS146 |
---|
117 | 117 | | with another legal entity; or 1 |
---|
118 | 118 | | (B) Shares common branding with another legal entity; 2 |
---|
119 | 119 | | (2) "Algorithmic discrimination" means a condition in which the 3 |
---|
120 | 120 | | use of an artificial intelligence system results in an unlawful differential 4 |
---|
121 | 121 | | treatment or impact that disfavors an individual or group of individuals on 5 |
---|
122 | 122 | | the basis of the individual's or group of individuals' actual or perceived 6 |
---|
123 | 123 | | age, color, disability status, ethnicity, genetic information, national 7 |
---|
124 | 124 | | origin, race, religion, sex, veteran status, or other classification 8 |
---|
125 | 125 | | protected under the laws of this state or federal law; 9 |
---|
126 | 126 | | (3) "Artificial intelligence system" means a machine -based 10 |
---|
127 | 127 | | system that, for any explicit or implicit objective, infers from the inputs 11 |
---|
128 | 128 | | the system receives how to generate outputs, including content, decisions, 12 |
---|
129 | 129 | | predictions, or recommendations, that can influence physical or virtual 13 |
---|
130 | 130 | | environments; 14 |
---|
131 | 131 | | (4) "Authenticate" means to verify through reasonable means that 15 |
---|
132 | 132 | | the consumer who is entitled to exercise the consumer’s right is the same 16 |
---|
133 | 133 | | consumer exercising those consumer rights with respect to the personal data 17 |
---|
134 | 134 | | at issue; 18 |
---|
135 | 135 | | (5)(A) "Biometric data" means data generated by automatic 19 |
---|
136 | 136 | | measurements of an individual’s biological characteristics. 20 |
---|
137 | 137 | | (B) "Biometric data" includes a fingerprint, voiceprint, 21 |
---|
138 | 138 | | eye retina or iris scans, or other unique biological pattern or 22 |
---|
139 | 139 | | characteristic that is used to identify a specific individual. 23 |
---|
140 | 140 | | (C) "Biometric data" does not include a physical or 24 |
---|
141 | 141 | | digital photograph or data generated from a physical or digital photograph, a 25 |
---|
142 | 142 | | video or audio recording or data generated from a video or audio recording, 26 |
---|
143 | 143 | | or information collected, used, or stored for healthcare treatment, payment, 27 |
---|
144 | 144 | | or operations under the Health Insurance Portability and Accountability Act 28 |
---|
145 | 145 | | of 1996, 42 U.S.C. § 1320d et seq., as it existed on January 1, 2025; 29 |
---|
146 | 146 | | (6) "Business associate" means the same as defined in the Health 30 |
---|
147 | 147 | | Insurance Portability and Accountability Act of 1996, 42 U.S.C. § 1320d et 31 |
---|
148 | 148 | | seq., as it existed on January 1, 2025; 32 |
---|
149 | 149 | | (7) "Child" means an individual younger than thirteen (13) years 33 |
---|
150 | 150 | | of age; 34 |
---|
151 | 151 | | (8)(A) "Consent" means a clear affirmative act, if referring to 35 |
---|
152 | 152 | | a consumer, that signifies a consumer’s freely given, specific, informed, and 36 SB258 |
---|
153 | 153 | | |
---|
154 | 154 | | 5 02/18/2025 3:16:09 PM ANS146 |
---|
155 | 155 | | unambiguous agreement to process personal data relating to the consumer. 1 |
---|
156 | 156 | | (B) "Consent" includes a written statement, including a 2 |
---|
157 | 157 | | statement written by electronic means, or any other unambiguous affirmative 3 |
---|
158 | 158 | | action. 4 |
---|
159 | 159 | | (C) "Consent" does not include: 5 |
---|
160 | 160 | | (i) An acceptance of a general or broad terms of use 6 |
---|
161 | 161 | | or similar document that contains descriptions of personal data processing 7 |
---|
162 | 162 | | along with other unrelated information; 8 |
---|
163 | 163 | | (ii) The hovering over, muting, pausing, or closing 9 |
---|
164 | 164 | | a given piece of content; or 10 |
---|
165 | 165 | | (iii) An agreement obtained through the use of dark 11 |
---|
166 | 166 | | patterns; 12 |
---|
167 | 167 | | (9)(A) "Consumer" means an individual who is a resident of this 13 |
---|
168 | 168 | | state acting only in an individual or household context. 14 |
---|
169 | 169 | | (B) "Consumer" does not include an individual acting in a 15 |
---|
170 | 170 | | commercial or employment context; 16 |
---|
171 | 171 | | (10) "Consumer health data" means information about a person’s 17 |
---|
172 | 172 | | health collected by a person or entity not subject to the Health Insurance 18 |
---|
173 | 173 | | Portability and Accountability Act of 1996, 42 U.S.C. § 1320d et seq., as it 19 |
---|
174 | 174 | | existed on January 1, 2025, including information gathered from wearable 20 |
---|
175 | 175 | | fitness devices, mobile phones, applications promoting personal physical, 21 |
---|
176 | 176 | | dental, or mental health, nutrition trackers, and similar applications 22 |
---|
177 | 177 | | generally available to the public; 23 |
---|
178 | 178 | | (11) "Control" means: 24 |
---|
179 | 179 | | (A) The ownership of, or power to vote, more than 25 |
---|
180 | 180 | | fifty percent (50%) of the outstanding shares of any class of voting security 26 |
---|
181 | 181 | | of a company; 27 |
---|
182 | 182 | | (B) The control in any manner over the election of a 28 |
---|
183 | 183 | | majority of the directors or of individuals exercising similar functions; or 29 |
---|
184 | 184 | | (C) The power to exercise controlling influence over 30 |
---|
185 | 185 | | the management of a company; 31 |
---|
186 | 186 | | (12) "Controller" means an individual or other person that, 32 |
---|
187 | 187 | | alone or jointly with others, determines the purpose and means of processing 33 |
---|
188 | 188 | | personal data; 34 |
---|
189 | 189 | | (13) "Covered entity" has the same meaning as defined in the 35 |
---|
190 | 190 | | Health Insurance Portability and Accountability Act of 1996, 42 U.S.C. § 36 SB258 |
---|
191 | 191 | | |
---|
192 | 192 | | 6 02/18/2025 3:16:09 PM ANS146 |
---|
193 | 193 | | 1320d et seq., as it existed on January 1, 2025; 1 |
---|
194 | 194 | | (14)(A) "Dark pattern" means a user interface designed or 2 |
---|
195 | 195 | | manipulated with the effect of substantially subverting or impairing user 3 |
---|
196 | 196 | | autonomy, decision-making, or choice. 4 |
---|
197 | 197 | | (B) "Dark pattern" includes any practice that the Federal 5 |
---|
198 | 198 | | Trade Commission refers to as a dark pattern; 6 |
---|
199 | 199 | | (15) "Decision that produces a legal or similarly significant 7 |
---|
200 | 200 | | effect concerning a consumer" means a decision made by a controller that 8 |
---|
201 | 201 | | results in the provision or denial by the controller of: 9 |
---|
202 | 202 | | (A) Financial and lending services; 10 |
---|
203 | 203 | | (B) Housing, insurance, or healthcare services; 11 |
---|
204 | 204 | | (C) Education enrollment; 12 |
---|
205 | 205 | | (D) Employment opportunities; 13 |
---|
206 | 206 | | (E) Criminal justice; or 14 |
---|
207 | 207 | | (F) Access to basic necessities, such as food and water; 15 |
---|
208 | 208 | | (16) "Deidentified data" means data that cannot reasonably be 16 |
---|
209 | 209 | | linked to an identified or identifiable individual or a device linked to that 17 |
---|
210 | 210 | | individual; 18 |
---|
211 | 211 | | (17) "Deploy" means to use a high -risk artificial intelligence 19 |
---|
212 | 212 | | system; 20 |
---|
213 | 213 | | (18) "Deployer" means a person doing business in this state that 21 |
---|
214 | 214 | | deploys a high-risk artificial intelligence system; 22 |
---|
215 | 215 | | (19) "Developer" means a person doing business in this state 23 |
---|
216 | 216 | | that develops or intentionally and substantially modifies an artificial 24 |
---|
217 | 217 | | intelligence system; 25 |
---|
218 | 218 | | (20) "Full-time equivalent employee" means one (1) or more 26 |
---|
219 | 219 | | employees whose average weekly work hours exceed thirty -five (35) hours; 27 |
---|
220 | 220 | | (21)(A) "Health record" means a written, printed, or 28 |
---|
221 | 221 | | electronically recorded material maintained by a healthcare provider in the 29 |
---|
222 | 222 | | course of providing healthcare services to an individual that concerns the 30 |
---|
223 | 223 | | individual and the services provided. 31 |
---|
224 | 224 | | (B) "Health record" includes: 32 |
---|
225 | 225 | | (i) The substance of any communication made by an 33 |
---|
226 | 226 | | individual to a healthcare provider in confidence during or in connection 34 |
---|
227 | 227 | | with the provision of healthcare services; or 35 |
---|
228 | 228 | | (ii) Information otherwise acquired by the 36 SB258 |
---|
229 | 229 | | |
---|
230 | 230 | | 7 02/18/2025 3:16:09 PM ANS146 |
---|
231 | 231 | | healthcare provider about an individual in confidence and in connection with 1 |
---|
232 | 232 | | healthcare services provided to the individual; 2 |
---|
233 | 233 | | (22) "Healthcare provider" means the same as defined in the 3 |
---|
234 | 234 | | Health Insurance Portability and Accountability Act of 1996, 42 U.S.C. § 4 |
---|
235 | 235 | | 1320d et seq., as it existed on January 1, 2025; 5 |
---|
236 | 236 | | (23) "Healthcare services" has the same meaning as provided in 6 |
---|
237 | 237 | | 42 U.S.C. § 234(d)(2), as it existed on January 1, 2025; 7 |
---|
238 | 238 | | (24)(A) "High-risk artificial intelligence system" means an 8 |
---|
239 | 239 | | artificial intelligence system that, when deployed, makes, or is a 9 |
---|
240 | 240 | | substantial factor in making, a decision that produces a legal or similarly 10 |
---|
241 | 241 | | significant effect concerning a consumer. 11 |
---|
242 | 242 | | (B) "High-risk artificial intelligence system" does not 12 |
---|
243 | 243 | | include an artificial intelligence system if the artificial intelligence 13 |
---|
244 | 244 | | system is intended to: 14 |
---|
245 | 245 | | (i) Perform a narrow or procedural task; 15 |
---|
246 | 246 | | (ii) Detect decision -making patterns or deviations 16 |
---|
247 | 247 | | from prior decision-making patterns and is not intended to replace or 17 |
---|
248 | 248 | | influence a previously completed human assessment without sufficient human 18 |
---|
249 | 249 | | review; or 19 |
---|
250 | 250 | | (iii) Perform tasks that do not make, or are not a 20 |
---|
251 | 251 | | substantial factor in making, a decision that produces a legal or similarly 21 |
---|
252 | 252 | | significant effect concerning a consumer, including without limitation: 22 |
---|
253 | 253 | | (a) Anti-fraud technology that does not use 23 |
---|
254 | 254 | | facial recognition technology; 24 |
---|
255 | 255 | | (b) Anti-malware, anti-virus, artificial-25 |
---|
256 | 256 | | intelligence-enabled video games, calculators, cybersecurity, databases, data 26 |
---|
257 | 257 | | storage, firewall, internet domain registration, internet website loading, 27 |
---|
258 | 258 | | networking, spam- and robocall-filtering, spell-checking, spreadsheets, web 28 |
---|
259 | 259 | | caching, web hosting or any similar technology, or technology that 29 |
---|
260 | 260 | | communicates with consumers in natural language for the purpose of providing 30 |
---|
261 | 261 | | users with information, making referrals or recommendations, and answering 31 |
---|
262 | 262 | | questions; and 32 |
---|
263 | 263 | | (c) Is subject to an accepted use policy that 33 |
---|
264 | 264 | | prohibits generating content that is discriminatory or harmful, unless such 34 |
---|
265 | 265 | | technologies, when deployed, make or are a substantial factor in making, a 35 |
---|
266 | 266 | | decision that produces a legal or similarly significant effect concerning a 36 SB258 |
---|
267 | 267 | | |
---|
268 | 268 | | 8 02/18/2025 3:16:09 PM ANS146 |
---|
269 | 269 | | consumer; 1 |
---|
270 | 270 | | (25) "Identified" means a consumer who can be readily 2 |
---|
271 | 271 | | identified, directly or indirectly; 3 |
---|
272 | 272 | | (26) "Institution of higher education" means: 4 |
---|
273 | 273 | | (A) A vocational or technical school governed by Arkansas 5 |
---|
274 | 274 | | Code Title 6, Subtitle 4; or 6 |
---|
275 | 275 | | (B) A postsecondary or higher education institution 7 |
---|
276 | 276 | | governed by Arkansas Code Title 6, Subtitle 5; 8 |
---|
277 | 277 | | (27)(A) "Intentional and substantial modification" means a 9 |
---|
278 | 278 | | deliberate change made to an artificial intelligence system that results in 10 |
---|
279 | 279 | | any new reasonably foreseeable risk of algorithmic discrimination. 11 |
---|
280 | 280 | | (B) "Intentional and substantial modification" does not 12 |
---|
281 | 281 | | include a change made to a high -risk artificial intelligence system, or the 13 |
---|
282 | 282 | | performance of a high -risk artificial intelligence system, if: 14 |
---|
283 | 283 | | (i) The high-risk artificial intelligence system 15 |
---|
284 | 284 | | continues to learn after the high -risk artificial intelligence system is 16 |
---|
285 | 285 | | offered, sold, leased, licensed, given, otherwise made available to a 17 |
---|
286 | 286 | | deployer, or is deployed; 18 |
---|
287 | 287 | | (ii) The change is made to the high -risk artificial 19 |
---|
288 | 288 | | intelligence system as a result of any learning described in subdivision 20 |
---|
289 | 289 | | (27)(B)(i) of this section; 21 |
---|
290 | 290 | | (iii) The change was predetermined by the deployer, 22 |
---|
291 | 291 | | or a third party contracted by the deployer, when the deployer or third party 23 |
---|
292 | 292 | | completed an initial impact assessment of the high -risk artificial 24 |
---|
293 | 293 | | intelligence system under § 4 -120-603; and 25 |
---|
294 | 294 | | (iv) The change is included in technical 26 |
---|
295 | 295 | | documentation for the high -risk artificial intelligence system; 27 |
---|
296 | 296 | | (28) "Known child" means a child under circumstances where a 28 |
---|
297 | 297 | | controller has actual knowledge of, or willfully disregards, the child’s age; 29 |
---|
298 | 298 | | (29) "Nonprofit organization" means: 30 |
---|
299 | 299 | | (A) A corporation governed by Arkansas Code Title 4, 31 |
---|
300 | 300 | | Chapter 28 or Chapter 33 to extent applicable to nonprofit corporations; 32 |
---|
301 | 301 | | (B) An organization exempt from federal taxation as 33 |
---|
302 | 302 | | a nonprofit entity under § 501(a) of the Internal Revenue Code, by being 34 |
---|
303 | 303 | | listed as an exempt organization under §§ 501(c)(3), 501(c)(4), 501(c)(6), 35 |
---|
304 | 304 | | 501(c)(12), or 501(c)(19) of the Internal Revenue Code; or 36 SB258 |
---|
305 | 305 | | |
---|
306 | 306 | | 9 02/18/2025 3:16:09 PM ANS146 |
---|
307 | 307 | | (C) A political organization; 1 |
---|
308 | 308 | | (30)(A) "Personal data" means any information, including 2 |
---|
309 | 309 | | sensitive data, that is linked or reasonably linkable to an identified or 3 |
---|
310 | 310 | | identifiable individual. 4 |
---|
311 | 311 | | (B) "Personal data" includes pseudonymous data when the 5 |
---|
312 | 312 | | data is used by a controller or processor in conjunction with additional 6 |
---|
313 | 313 | | information that reasonably links the data to an identified or identifiable 7 |
---|
314 | 314 | | individual. 8 |
---|
315 | 315 | | (C) "Personal data" does not include deidentified data or 9 |
---|
316 | 316 | | publicly available information; 10 |
---|
317 | 317 | | (31) "Political organization" means a party, committee, 11 |
---|
318 | 318 | | association, fund, or other organization, regardless of whether incorporated, 12 |
---|
319 | 319 | | that is organized and operated primarily for the purpose of influencing or 13 |
---|
320 | 320 | | attempting to influence: 14 |
---|
321 | 321 | | (A) The selection, nomination, election, or 15 |
---|
322 | 322 | | appointment of an individual to federal, state, or local public office or an 16 |
---|
323 | 323 | | office in a political organization, regardless of whether the individual is 17 |
---|
324 | 324 | | ultimately selected, nominated, elected, or appointed; or 18 |
---|
325 | 325 | | (B) The election of a presidential or vice -19 |
---|
326 | 326 | | presidential elector, regardless of whether the elector is ultimately 20 |
---|
327 | 327 | | selected, nominated, elected, or appointed; 21 |
---|
328 | 328 | | (32)(A) "Precise geolocation data" means information derived 22 |
---|
329 | 329 | | from technology, including Global Positioning System level latitude and 23 |
---|
330 | 330 | | longitude coordinates or other mechanisms, that directly identifies the 24 |
---|
331 | 331 | | specific location of an individual with precision and accuracy within a 25 |
---|
332 | 332 | | radius of one thousand seven hundred fifty feet (1,750'). 26 |
---|
333 | 333 | | (B) "Precise geolocation data" does not include the 27 |
---|
334 | 334 | | content of communications or any data generated by or connected to an 28 |
---|
335 | 335 | | advanced utility metering infrastructure system or to equipment for use by a 29 |
---|
336 | 336 | | utility; 30 |
---|
337 | 337 | | (33) "Process" means an operation or set of operations 31 |
---|
338 | 338 | | performed, whether by manual or automated means, on personal data or on sets 32 |
---|
339 | 339 | | of personal data, such as the collection, use, storage, disclosure, analysis, 33 |
---|
340 | 340 | | deletion, or modification of personal data; 34 |
---|
341 | 341 | | (34) "Processor" means a person who processes personal data on 35 |
---|
342 | 342 | | behalf of a controller; 36 SB258 |
---|
343 | 343 | | |
---|
344 | 344 | | 10 02/18/2025 3:16:09 PM ANS146 |
---|
345 | 345 | | (35) "Profiling" means a form of automated processing performed 1 |
---|
346 | 346 | | on personal data to evaluate, analyze, or predict personal aspects related to 2 |
---|
347 | 347 | | an identified or identifiable individual’s economic situation, health, 3 |
---|
348 | 348 | | personal preferences, interests, reliability, behavior, location, or 4 |
---|
349 | 349 | | movements; 5 |
---|
350 | 350 | | (36) "Protected health information" means the same as defined 6 |
---|
351 | 351 | | under the Health Insurance Portability and Accountability Act of 1996, 42 7 |
---|
352 | 352 | | U.S.C. § 1320d et seq., as it existed on January 1, 2025; 8 |
---|
353 | 353 | | (37) "Pseudonymous data" means any information that cannot be 9 |
---|
354 | 354 | | attributed to a specific individual without the use of additional 10 |
---|
355 | 355 | | information, provided that the additional information is kept separately and 11 |
---|
356 | 356 | | is subject to appropriate technical and organizational measures to ensure 12 |
---|
357 | 357 | | that the personal data is not attributed to an identified or identifiable 13 |
---|
358 | 358 | | individual; 14 |
---|
359 | 359 | | (38) "Publicly available information" means information that is 15 |
---|
360 | 360 | | lawfully made available through government records, or information that a 16 |
---|
361 | 361 | | business has a reasonable basis to believe is lawfully made available to the 17 |
---|
362 | 362 | | general public through widely distributed media, by a consumer, or by a 18 |
---|
363 | 363 | | person to whom a consumer has disclosed the information, unless the consumer 19 |
---|
364 | 364 | | has restricted the information to a specific audience; 20 |
---|
365 | 365 | | (39)(A) "Sale of personal data" means the sharing, disclosing, 21 |
---|
366 | 366 | | or transferring of personal data for monetary or other valuable consideration 22 |
---|
367 | 367 | | by a controller to a third party. 23 |
---|
368 | 368 | | (B) "Sale of personal data" does not include: 24 |
---|
369 | 369 | | (i) The disclosure of personal data to a processor 25 |
---|
370 | 370 | | that processes the personal data on the controller’s behalf; 26 |
---|
371 | 371 | | (ii) The disclosure of personal data to a third 27 |
---|
372 | 372 | | party for purposes of providing a product or service requested by the 28 |
---|
373 | 373 | | consumer; 29 |
---|
374 | 374 | | (iii) The disclosure or transfer of personal data to 30 |
---|
375 | 375 | | an affiliate of a controller; 31 |
---|
376 | 376 | | (iv) The disclosure of information that the 32 |
---|
377 | 377 | | consumer: 33 |
---|
378 | 378 | | (a) Intentionally made available to the 34 |
---|
379 | 379 | | general public through a mass media channel; and 35 |
---|
380 | 380 | | (b) Did not restrict to a specific audience; 36 SB258 |
---|
381 | 381 | | |
---|
382 | 382 | | 11 02/18/2025 3:16:09 PM ANS146 |
---|
383 | 383 | | or 1 |
---|
384 | 384 | | (v) The disclosure or transfer of personal data to a 2 |
---|
385 | 385 | | third party as an asset that is part of a merger or acquisition; 3 |
---|
386 | 386 | | (40)(A) "Sensitive data" means a category of personal data. 4 |
---|
387 | 387 | | (B) "Sensitive data" includes: 5 |
---|
388 | 388 | | (i) Personal data revealing racial or ethnic origin, 6 |
---|
389 | 389 | | religious beliefs, mental or physical health diagnosis, sexuality, or 7 |
---|
390 | 390 | | citizenship or immigration status; 8 |
---|
391 | 391 | | (ii) Genetic or biometric data that is processed for 9 |
---|
392 | 392 | | the purpose of uniquely identifying an individual; 10 |
---|
393 | 393 | | (iii) Personal data collected from a known child; 11 |
---|
394 | 394 | | (iv) Precise geolocation data; or 12 |
---|
395 | 395 | | (v) Data concerning personal or political 13 |
---|
396 | 396 | | affiliations, credentials to access online financial, healthcare, or other 14 |
---|
397 | 397 | | accounts that could be used to access a means of communication, Social 15 |
---|
398 | 398 | | Security number, driver's license number, or other government -issued 16 |
---|
399 | 399 | | identification number; 17 |
---|
400 | 400 | | (41) "State agency" means a department, commission, board, 18 |
---|
401 | 401 | | office, council, authority, or other agency in any branch of state government 19 |
---|
402 | 402 | | that is created by the Arkansas Constitution or a statute of this state, 20 |
---|
403 | 403 | | including a university system or institution of higher education as governed 21 |
---|
404 | 404 | | by Arkansas Code Title 6, Subtitles 4 or 5 that receives state funding or has 22 |
---|
405 | 405 | | directors appointed by the Governor; 23 |
---|
406 | 406 | | (42) "Substantial factor" means a factor that: 24 |
---|
407 | 407 | | (A) Assists in making a decision that produces a legal or 25 |
---|
408 | 408 | | similarly significant effect concerning a consumer; 26 |
---|
409 | 409 | | (B) Is capable of altering the outcome of a decision that 27 |
---|
410 | 410 | | produces a legal or similarly significant effect concerning a consumer; 28 |
---|
411 | 411 | | (C) Is generated by an artificial intelligence system; and 29 |
---|
412 | 412 | | (D) Includes any use of an artificial intelligence system 30 |
---|
413 | 413 | | to generate any content, decision, prediction, or recommendation concerning a 31 |
---|
414 | 414 | | consumer that is used as a basis to make a decision that produces a legal or 32 |
---|
415 | 415 | | similarly significant effect concerning a consumer; 33 |
---|
416 | 416 | | (43)(A) "Targeted advertising" means displaying to a consumer an 34 |
---|
417 | 417 | | advertisement that is selected based on personal data obtained from that 35 |
---|
418 | 418 | | consumer’s activities over time and across nonaffiliated websites or online 36 SB258 |
---|
419 | 419 | | |
---|
420 | 420 | | 12 02/18/2025 3:16:09 PM ANS146 |
---|
421 | 421 | | applications to predict the consumer’s preferences or interests. 1 |
---|
422 | 422 | | (B) "Targeted advertising" does not include an 2 |
---|
423 | 423 | | advertisement that: 3 |
---|
424 | 424 | | (i) Is based on activities within a controller’s own 4 |
---|
425 | 425 | | websites or online applications; 5 |
---|
426 | 426 | | (ii) Is based on the context of a consumer’s current 6 |
---|
427 | 427 | | search query, visit to a website, or online application; 7 |
---|
428 | 428 | | (iii) Is directed to a consumer in response to the 8 |
---|
429 | 429 | | consumer’s request for information or feedback; or 9 |
---|
430 | 430 | | (iv) Is used for the processing of personal data 10 |
---|
431 | 431 | | solely for measuring or reporting advertising performance, reach, or 11 |
---|
432 | 432 | | frequency; 12 |
---|
433 | 433 | | (44) "Third party" means a person, other than the consumer, the 13 |
---|
434 | 434 | | controller, the processor, or an affiliate of the controller or processor; 14 |
---|
435 | 435 | | and 15 |
---|
436 | 436 | | (45) "Trade secret" means all forms and types of information, 16 |
---|
437 | 437 | | including business, scientific, technical, economic, or engineering 17 |
---|
438 | 438 | | information, and any formula, design, prototype, pattern, plan, compilation, 18 |
---|
439 | 439 | | program device, program, code, device, method, technique, process, procedure, 19 |
---|
440 | 440 | | financial data, or list of actual or potential customers or suppliers, 20 |
---|
441 | 441 | | whether tangible or intangible and irrespective of how stored, compiled, or 21 |
---|
442 | 442 | | memorialized physically, electronically, graphically, photographically, or in 22 |
---|
443 | 443 | | writing if: 23 |
---|
444 | 444 | | (A) The owner of the trade secret has taken reasonable 24 |
---|
445 | 445 | | measures under the circumstances to keep the information secret; and 25 |
---|
446 | 446 | | (B) The information derives independent economic value, 26 |
---|
447 | 447 | | actual or potential, from not being generally known to, and not being readily 27 |
---|
448 | 448 | | ascertainable through proper means by, another person who can obtain economic 28 |
---|
449 | 449 | | value from the disclosure or use of the information. 29 |
---|
450 | 450 | | 30 |
---|
451 | 451 | | 4-120-104. Applicability. 31 |
---|
452 | 452 | | (a) This chapter applies only to a person that: 32 |
---|
453 | 453 | | (1) Conducts business in this state or produces a product or 33 |
---|
454 | 454 | | service consumed by residents of this state; 34 |
---|
455 | 455 | | (2) Processes or engages in the sale of personal data; and 35 |
---|
456 | 456 | | (3) Is not a small business as defined by the United States 36 SB258 |
---|
457 | 457 | | |
---|
458 | 458 | | 13 02/18/2025 3:16:09 PM ANS146 |
---|
459 | 459 | | Small Business Administration, as it existed on January 1, 2025, except to 1 |
---|
460 | 460 | | the extent that § 4-120-302(a) applies to a person described by this section. 2 |
---|
461 | 461 | | (b) This chapter shall only apply to nonprofit organizations whose 3 |
---|
462 | 462 | | annual receipts in any of the preceding five (5) calendar years exceeded 4 |
---|
463 | 463 | | fifteen million dollars ($15,000,000). 5 |
---|
464 | 464 | | (c) Notwithstanding subsections (a) and (b) of this section, an 6 |
---|
465 | 465 | | employer who employs fifty (50) or more full -time equivalent employees and 7 |
---|
466 | 466 | | uses a person’s data to train a high -risk artificial intelligence system, 8 |
---|
467 | 467 | | including when a high -risk artificial intelligence system continues learning 9 |
---|
468 | 468 | | based on the person’s data, § 4 -120-601 et seq. applies if the person: 10 |
---|
469 | 469 | | (1) Uses a high-risk artificial intelligence system outside the 11 |
---|
470 | 470 | | scope of the intended uses that are disclosed to the person; or 12 |
---|
471 | 471 | | (2) Fails to make available to consumers any impact assessment 13 |
---|
472 | 472 | | that a developer of a high -risk artificial intelligence system has completed 14 |
---|
473 | 473 | | and provided to the deployer. 15 |
---|
474 | 474 | | 16 |
---|
475 | 475 | | 4-120-105. Exemptions. 17 |
---|
476 | 476 | | Except as provided under § 4 -120-601 et seq., this chapter does not 18 |
---|
477 | 477 | | apply to: 19 |
---|
478 | 478 | | (1) A state agency or political subdivision of this state; 20 |
---|
479 | 479 | | (2) A financial institution or data subject to Title V, Gramm -21 |
---|
480 | 480 | | Leach-Bliley Act, Pub. L. No. 106 -102; 22 |
---|
481 | 481 | | (3) A covered entity or business associate governed by the 23 |
---|
482 | 482 | | privacy, security, and breach notification rules issued by the United States 24 |
---|
483 | 483 | | Department of Health and Human Services, 45 C.F.R. Parts 160 and 164, 25 |
---|
484 | 484 | | established under the Health Insurance Portability and Accountability Act of 26 |
---|
485 | 485 | | 1996, 42 U.S.C. § 1320d et seq., as it existed on January 1, 2025, and the 27 |
---|
486 | 486 | | Health Information Technology for Economic and Clinical Health Act, Division 28 |
---|
487 | 487 | | A, Title XIII, and Division B, Title IV, Pub. L. No. 111 -5; 29 |
---|
488 | 488 | | (4) An institution of higher education; 30 |
---|
489 | 489 | | (5) An electric utility governed by Arkansas Code Title 23, 31 |
---|
490 | 490 | | Chapter 18; 32 |
---|
491 | 491 | | (6) Protected health information under the Health Insurance 33 |
---|
492 | 492 | | Portability and Accountability Act of 1996, 42 U.S.C. § 1320d et seq., as it 34 |
---|
493 | 493 | | existed on January 1, 2025; 35 |
---|
494 | 494 | | (7) Health records; 36 SB258 |
---|
495 | 495 | | |
---|
496 | 496 | | 14 02/18/2025 3:16:09 PM ANS146 |
---|
497 | 497 | | (8) Patient identifying information for purposes of 42 U.S.C. § 1 |
---|
498 | 498 | | 290dd-2; 2 |
---|
499 | 499 | | (9) Identifiable private information: 3 |
---|
500 | 500 | | (A) For purposes of the federal policy for the protection 4 |
---|
501 | 501 | | of human subjects under 45 C.F.R. Part 46, as it existed on January 1, 2025; 5 |
---|
502 | 502 | | (B) Collected as part of human subjects research under the 6 |
---|
503 | 503 | | good clinical practice guidelines issued by the International Council for 7 |
---|
504 | 504 | | Harmonisation of Technical Requirements for Pharmaceuticals for Human Use or 8 |
---|
505 | 505 | | of the protection of human subjects under 21 C.F.R. Parts 50 and 56, as it 9 |
---|
506 | 506 | | existed on January 1, 2025; or 10 |
---|
507 | 507 | | (C) That is personal data used or shared in research 11 |
---|
508 | 508 | | conducted according to the requirements stated in this chapter or other 12 |
---|
509 | 509 | | research conducted according to applicable law; 13 |
---|
510 | 510 | | (10) Information and documents created for purposes of the 14 |
---|
511 | 511 | | Health Care Quality Improvement Act of 1986, 42 U.S.C. § 11101 et seq., as it 15 |
---|
512 | 512 | | existed on January 1, 2025; 16 |
---|
513 | 513 | | (11) Patient safety work product for purposes of the Patient 17 |
---|
514 | 514 | | Safety and Quality Improvement Act of 2005, 42 U.S.C. § 299b -21 et seq., as 18 |
---|
515 | 515 | | it existed on January 1, 2025; 19 |
---|
516 | 516 | | (12) Information derived from any of the healthcare -related 20 |
---|
517 | 517 | | information listed in this section that is deidentified according to the 21 |
---|
518 | 518 | | requirements for deidentification under the Health Insurance Portability and 22 |
---|
519 | 519 | | Accountability Act of 1996, 42 U.S.C. § 1320d et seq., as it existed on 23 |
---|
520 | 520 | | January 1, 2025; 24 |
---|
521 | 521 | | (13) Information originating from, intermingled to be 25 |
---|
522 | 522 | | indistinguishable with, or information treated in the same manner as 26 |
---|
523 | 523 | | information exempt under this section that is maintained by a covered entity 27 |
---|
524 | 524 | | or business associate as defined by the Health Insurance Portability and 28 |
---|
525 | 525 | | Accountability Act of 1996, 42 U.S.C. Section 1320d et seq., or by a program 29 |
---|
526 | 526 | | or a qualified service organization as defined by 42 U.S.C. Section 290dd -2; 30 |
---|
527 | 527 | | (14) Information that is included in a limited data set as 31 |
---|
528 | 528 | | described by 45 C.F.R. Section 164.514(e), as it existed on January 1, 2025, 32 |
---|
529 | 529 | | to the extent that the information is used, disclosed, and maintained in the 33 |
---|
530 | 530 | | manner specified by 45 C.F.R. Section 164.514(e), as it existed on January 1, 34 |
---|
531 | 531 | | 2025; 35 |
---|
532 | 532 | | (15) Information collected or used only for public health 36 SB258 |
---|
533 | 533 | | |
---|
534 | 534 | | 15 02/18/2025 3:16:09 PM ANS146 |
---|
535 | 535 | | activities and purposes as authorized by the Health Insurance Portability and 1 |
---|
536 | 536 | | Accountability Act of 1996, 42 U.S.C. § 1320d et seq., as it existed on 2 |
---|
537 | 537 | | January 1, 2025; 3 |
---|
538 | 538 | | (16) The collection, maintenance, disclosure, sale, 4 |
---|
539 | 539 | | communication, or use of any personal information bearing on a consumer’s 5 |
---|
540 | 540 | | creditworthiness, credit standing, credit capacity, character, general 6 |
---|
541 | 541 | | reputation, personal characteristics, or mode of living by a consumer 7 |
---|
542 | 542 | | reporting agency or furnisher that provides information for use in a consumer 8 |
---|
543 | 543 | | report, and by a user of the consumer report, but only to the extent that the 9 |
---|
544 | 544 | | activity is regulated by and authorized under the Fair Credit Reporting Act, 10 |
---|
545 | 545 | | 15 U.S.C. §§ 1681-1681t, as it existed on January 1, 2025; 11 |
---|
546 | 546 | | (17) Personal data collected, processed, sold, or disclosed in 12 |
---|
547 | 547 | | compliance with the Driver’s Privacy Protection Act of 1994, 18 U.S.C. § 2721 13 |
---|
548 | 548 | | et seq., as it existed on January 1, 2025; 14 |
---|
549 | 549 | | (18) Personal data regulated by the Family Educational Rights 15 |
---|
550 | 550 | | and Privacy Act of 1974, 20 U.S.C. § 1232g, as it existed on January 1, 2025; 16 |
---|
551 | 551 | | (19) Personal data collected, processed, sold, or disclosed in 17 |
---|
552 | 552 | | compliance with the Farm Credit Act of 1971, 12 U.S.C. § 2001 et seq., as it 18 |
---|
553 | 553 | | existed on January 1, 2025; 19 |
---|
554 | 554 | | (20) Data processed or maintained in the course of an individual 20 |
---|
555 | 555 | | applying to, being employed by, or acting as an agent or independent 21 |
---|
556 | 556 | | contractor of a controller, processor, or third party, to the extent that the 22 |
---|
557 | 557 | | data is collected and used within the context of that role, except as 23 |
---|
558 | 558 | | specifically provided in § 4 -120-602; 24 |
---|
559 | 559 | | (21) Data processed or maintained as the emergency contact 25 |
---|
560 | 560 | | information of an individual under this chapter that is used only for 26 |
---|
561 | 561 | | emergency contact purposes; 27 |
---|
562 | 562 | | (22) Data that is processed or maintained and is necessary to 28 |
---|
563 | 563 | | retain to administer benefits for another individual that relates to an 29 |
---|
564 | 564 | | individual described in subdivision (20) of this section and used only for 30 |
---|
565 | 565 | | the purposes of administering those benefits; or 31 |
---|
566 | 566 | | (23) The processing of personal data by a person in the course 32 |
---|
567 | 567 | | of a purely personal or household activity. 33 |
---|
568 | 568 | | 34 |
---|
569 | 569 | | 4-120-106. Construction of chapter — Exceptions. 35 |
---|
570 | 570 | | (a) This chapter shall not be construed: 36 SB258 |
---|
571 | 571 | | |
---|
572 | 572 | | 16 02/18/2025 3:16:09 PM ANS146 |
---|
573 | 573 | | (1) To restrict a controller’s or processor’s ability to: 1 |
---|
574 | 574 | | (A) Comply with state laws or rules, or federal or local 2 |
---|
575 | 575 | | laws, rules, or regulations; 3 |
---|
576 | 576 | | (B) Comply with a civil, criminal, or regulatory inquiry, 4 |
---|
577 | 577 | | investigation, subpoena, or summons by federal, state, local, or other 5 |
---|
578 | 578 | | governmental authorities; 6 |
---|
579 | 579 | | (C) Investigate, establish, exercise, prepare for, or 7 |
---|
580 | 580 | | defend legal claims; 8 |
---|
581 | 581 | | (D) Provide a product or service specifically requested by 9 |
---|
582 | 582 | | a consumer or the parent or guardian of a child, perform a contract to which 10 |
---|
583 | 583 | | the consumer is a party, including fulfilling the terms of a written 11 |
---|
584 | 584 | | warranty, or take steps at the request of the consumer before entering into a 12 |
---|
585 | 585 | | contract; 13 |
---|
586 | 586 | | (E) Take immediate steps to protect an interest that is 14 |
---|
587 | 587 | | essential for the life or physical safety of the consumer or of another 15 |
---|
588 | 588 | | individual and in which the processing cannot be manifestly based on another 16 |
---|
589 | 589 | | legal basis; 17 |
---|
590 | 590 | | (F) Prevent, detect, protect against, or respond to 18 |
---|
591 | 591 | | security incidents, identity theft, fraud, harassment, malicious or deceptive 19 |
---|
592 | 592 | | activities, or any illegal activity; 20 |
---|
593 | 593 | | (G) Preserve the integrity or security of systems and 21 |
---|
594 | 594 | | investigate, report, or prosecute those responsible for breaches of system 22 |
---|
595 | 595 | | security; 23 |
---|
596 | 596 | | (H) Engage in public or peer -reviewed scientific or 24 |
---|
597 | 597 | | statistical research in the public interest that adheres to all other 25 |
---|
598 | 598 | | applicable ethics and privacy laws and is approved, monitored, and governed 26 |
---|
599 | 599 | | by an institutional review board or similar independent oversight entity that 27 |
---|
600 | 600 | | determines: 28 |
---|
601 | 601 | | (i) If the deletion of the information is likely to 29 |
---|
602 | 602 | | provide substantial benefits that do not exclusively accrue to the 30 |
---|
603 | 603 | | controller; 31 |
---|
604 | 604 | | (ii) Whether or not the expected benefits of the 32 |
---|
605 | 605 | | research outweigh the privacy risks; and 33 |
---|
606 | 606 | | (iii) If the controller has implemented reasonable 34 |
---|
607 | 607 | | safeguards to mitigate privacy risks associated with research, including any 35 |
---|
608 | 608 | | risks associated with reidentification; or 36 SB258 |
---|
609 | 609 | | |
---|
610 | 610 | | 17 02/18/2025 3:16:09 PM ANS146 |
---|
611 | 611 | | (I) Assist another controller, processor, or third party 1 |
---|
612 | 612 | | with any of the requirements under this section; 2 |
---|
613 | 613 | | (2) As imposing a requirement on controllers and processors that 3 |
---|
614 | 614 | | adversely affects the rights or freedoms of any person, including the right 4 |
---|
615 | 615 | | of free speech; or 5 |
---|
616 | 616 | | (3) As requiring a controller, processor, third party, or 6 |
---|
617 | 617 | | consumer to disclose a trade secret. 7 |
---|
618 | 618 | | (b) If personal data is subject to reasonable administrative, 8 |
---|
619 | 619 | | technical, and physical measures to protect the confidentiality, integrity, 9 |
---|
620 | 620 | | and accessibility of the personal data and to reduce reasonably foreseeable 10 |
---|
621 | 621 | | risks of harm to consumers relating to the collection, use, or retention of 11 |
---|
622 | 622 | | personal data, the requirements imposed on controllers and processors under 12 |
---|
623 | 623 | | this chapter may not restrict a controller’s or processor’s ability to 13 |
---|
624 | 624 | | collect, use, or retain data to: 14 |
---|
625 | 625 | | (1) Conduct internal research to develop, improve, or repair 15 |
---|
626 | 626 | | products, services, or technology; 16 |
---|
627 | 627 | | (2) Effect a product recall; 17 |
---|
628 | 628 | | (3) Identify and repair technical errors that impair existing or 18 |
---|
629 | 629 | | intended functionality; or 19 |
---|
630 | 630 | | (4) Perform internal operations that: 20 |
---|
631 | 631 | | (A) Are reasonably aligned with the expectations of the 21 |
---|
632 | 632 | | consumer; 22 |
---|
633 | 633 | | (B) Are reasonably anticipated based on the consumer’s 23 |
---|
634 | 634 | | existing relationship with the controller; or 24 |
---|
635 | 635 | | (C) Are otherwise compatible with processing data in 25 |
---|
636 | 636 | | furtherance of the provision of a product or service specifically requested 26 |
---|
637 | 637 | | by a consumer or the performance of a contract to which the consumer is a 27 |
---|
638 | 638 | | party. 28 |
---|
639 | 639 | | (c) A controller or processor that processes personal data under an 29 |
---|
640 | 640 | | exemption in this subchapter bears the burden of demonstrating that the 30 |
---|
641 | 641 | | processing of the personal data: 31 |
---|
642 | 642 | | (1) Qualifies for the exemption; and 32 |
---|
643 | 643 | | (2) Complies with the requirements of § 4 -120-306, § 4-120-405; 33 |
---|
644 | 644 | | and § 4-120-106(b). 34 |
---|
645 | 645 | | (d) The processing of personal data by an entity for the purposes 35 |
---|
646 | 646 | | described by this chapter does not solely make the entity a controller with 36 SB258 |
---|
647 | 647 | | |
---|
648 | 648 | | 18 02/18/2025 3:16:09 PM ANS146 |
---|
649 | 649 | | respect to the processing of the data. 1 |
---|
650 | 650 | | (e) This chapter supersedes and preempts an ordinance, resolution, 2 |
---|
651 | 651 | | rule, or other regulation adopted by a political subdivision regarding the 3 |
---|
652 | 652 | | processing of personal data by a controller or processor. 4 |
---|
653 | 653 | | (f) A controller or processor that complies with the verifiable 5 |
---|
654 | 654 | | parental consent requirements of the Children’s Online Privacy Protection Act 6 |
---|
655 | 655 | | of 1998, 15 U.S.C. § 6501 et seq., as it existed on January 1, 2025, with 7 |
---|
656 | 656 | | respect to data collected online is considered to be in compliance with any 8 |
---|
657 | 657 | | requirement to obtain parental consent under this chapter. 9 |
---|
658 | 658 | | 10 |
---|
659 | 659 | | 4-120-107. Requirements for small businesses and nonprofit 11 |
---|
660 | 660 | | organizations. 12 |
---|
661 | 661 | | (a) A person that is a small business as described by § 4 -120-13 |
---|
662 | 662 | | 104(a)(3) or a nonprofit organized as described by § 4 -120-104(b) shall not 14 |
---|
663 | 663 | | engage in the sale of personal data without receiving prior consent from the 15 |
---|
664 | 664 | | consumer. 16 |
---|
665 | 665 | | (b) A person who violates this section is subject to the penalty under 17 |
---|
666 | 666 | | § 4-120-701 et seq. 18 |
---|
667 | 667 | | 19 |
---|
668 | 668 | | Subchapter 2 — Consumer Rights 20 |
---|
669 | 669 | | 21 |
---|
670 | 670 | | 4-120-201. Consumer’s personal data rights — Request to exercise 22 |
---|
671 | 671 | | rights. 23 |
---|
672 | 672 | | (a)(1) A consumer is entitled to exercise the consumer rights under 24 |
---|
673 | 673 | | this subchapter at any time by submitting a request to a controller 25 |
---|
674 | 674 | | specifying the consumer rights the consumer wishes to exercise. 26 |
---|
675 | 675 | | (2) With respect to the processing of personal data belonging to 27 |
---|
676 | 676 | | a known child, a parent or legal guardian of the child may exercise the 28 |
---|
677 | 677 | | consumer rights on behalf of the child. 29 |
---|
678 | 678 | | (b) A controller shall comply with an authenticated consumer request 30 |
---|
679 | 679 | | to exercise the right to: 31 |
---|
680 | 680 | | (1) Confirm whether a controller is processing the consumer’s 32 |
---|
681 | 681 | | personal data and to access the personal data; 33 |
---|
682 | 682 | | (2) Correct inaccuracies in the consumer’s personal data, taking 34 |
---|
683 | 683 | | into account the nature of the personal data and the purposes of the 35 |
---|
684 | 684 | | processing of the consumer’s personal data; 36 SB258 |
---|
685 | 685 | | |
---|
686 | 686 | | 19 02/18/2025 3:16:09 PM ANS146 |
---|
687 | 687 | | (3) Delete personal data provided by or obtained about the 1 |
---|
688 | 688 | | consumer; 2 |
---|
689 | 689 | | (4) If the data is available in a digital format, obtain a copy 3 |
---|
690 | 690 | | of the consumer’s personal data that the consumer previously provided to the 4 |
---|
691 | 691 | | controller in a portable and, to the extent technically feasible, readily 5 |
---|
692 | 692 | | usable format that allows the consumer to transmit the data to another 6 |
---|
693 | 693 | | controller without hindrance; or 7 |
---|
694 | 694 | | (5) Opt out of the processing of the personal data for the 8 |
---|
695 | 695 | | purpose of: 9 |
---|
696 | 696 | | (A) Targeted advertising; 10 |
---|
697 | 697 | | (B) The sale of personal data; or 11 |
---|
698 | 698 | | (C) Profiling in furtherance of a decision that produces a 12 |
---|
699 | 699 | | legal or similarly significant effect concerning the consumer. 13 |
---|
700 | 700 | | 14 |
---|
701 | 701 | | 4-120-202. Waiver or limitation of consumer rights prohibited. 15 |
---|
702 | 702 | | A provision of a contract or agreement that waives or limits a consumer 16 |
---|
703 | 703 | | right described by §§ 4 -120-201, 4-120-204, and 4-120-205 is contrary to 17 |
---|
704 | 704 | | public policy and is void. 18 |
---|
705 | 705 | | 19 |
---|
706 | 706 | | 4-120-203. Methods for submitting consumer requests. 20 |
---|
707 | 707 | | (a)(1) A controller shall establish two (2) or more secure and 21 |
---|
708 | 708 | | reliable methods to enable consumers to submit a request to exercise their 22 |
---|
709 | 709 | | consumer rights under this chapter. 23 |
---|
710 | 710 | | (2) The methods shall take into account: 24 |
---|
711 | 711 | | (A) The ways in which consumers normally interact with the 25 |
---|
712 | 712 | | controller; 26 |
---|
713 | 713 | | (B) The necessity for secure and reliable communications 27 |
---|
714 | 714 | | of any request under subdivision (a)(1) of this section; and 28 |
---|
715 | 715 | | (C) The ability of the controller to authenticate the 29 |
---|
716 | 716 | | identity of the consumer making the request. 30 |
---|
717 | 717 | | (b) A controller may not require a consumer to create a new account to 31 |
---|
718 | 718 | | exercise the consumer’s rights under this chapter but may require a consumer 32 |
---|
719 | 719 | | to use an existing account. 33 |
---|
720 | 720 | | (c) Except as provided by subsection (d) of this section, if the 34 |
---|
721 | 721 | | controller maintains a website, the controller shall provide a mechanism on 35 |
---|
722 | 722 | | the website for consumers to submit requests for information required to be 36 SB258 |
---|
723 | 723 | | |
---|
724 | 724 | | 20 02/18/2025 3:16:09 PM ANS146 |
---|
725 | 725 | | disclosed under this chapter. 1 |
---|
726 | 726 | | (d) A controller that operates exclusively online and has a direct 2 |
---|
727 | 727 | | relationship with a consumer from whom the controller collects personal 3 |
---|
728 | 728 | | information is only required to provide an email address for the submission 4 |
---|
729 | 729 | | of requests described by subsection (c) of this section. 5 |
---|
730 | 730 | | (e)(1) A consumer may designate: 6 |
---|
731 | 731 | | (A) Another person to serve as the consumer’s authorized 7 |
---|
732 | 732 | | agent and act on the consumer’s behalf to opt out of the processing of the 8 |
---|
733 | 733 | | consumer’s personal data under § 4 -120-201(b)(5)(A) and (B); or 9 |
---|
734 | 734 | | (B) An authorized agent using a technology, including a 10 |
---|
735 | 735 | | link to a website, a browser setting or an extension, or a global setting on 11 |
---|
736 | 736 | | an electronic device, which allows the consumer to indicate the consumer’s 12 |
---|
737 | 737 | | intent to opt out of the processing of the consumer's personal data. 13 |
---|
738 | 738 | | (2) A controller shall comply with an opt -out request received 14 |
---|
739 | 739 | | from an authorized agent under this section if the controller is able to 15 |
---|
740 | 740 | | verify, with commercially reasonable effort, the identity of the consumer and 16 |
---|
741 | 741 | | the authorized agent’s authority to act on the consumer’s behalf. 17 |
---|
742 | 742 | | (3) A controller is not required to comply with an opt -out 18 |
---|
743 | 743 | | request received from an authorized agent under this subsection if: 19 |
---|
744 | 744 | | (A) The authorized agent does not communicate the request 20 |
---|
745 | 745 | | to the controller in a clear and unambiguous manner; 21 |
---|
746 | 746 | | (B) The controller is not able to verify, with 22 |
---|
747 | 747 | | commercially reasonable effort, that the consumer is a resident of this 23 |
---|
748 | 748 | | state; 24 |
---|
749 | 749 | | (C) The controller does not possess the ability to process 25 |
---|
750 | 750 | | the request; or 26 |
---|
751 | 751 | | (D) The controller does not process similar or identical 27 |
---|
752 | 752 | | requests the controller receives from consumers for the purpose of complying 28 |
---|
753 | 753 | | with similar or identical laws or regulations of another state. 29 |
---|
754 | 754 | | (f) A technology described under subsection (e) of this section: 30 |
---|
755 | 755 | | (1) Shall not: 31 |
---|
756 | 756 | | (A) Unfairly disadvantage another controller; or 32 |
---|
757 | 757 | | (B) Make use of a default setting, but must require the 33 |
---|
758 | 758 | | consumer to consent and indicate the consumer’s intent to opt out of any 34 |
---|
759 | 759 | | processing of a consumer’s personal data; and 35 |
---|
760 | 760 | | (2) Shall be consumer -friendly and easy to use by the average 36 SB258 |
---|
761 | 761 | | |
---|
762 | 762 | | 21 02/18/2025 3:16:09 PM ANS146 |
---|
763 | 763 | | consumer. 1 |
---|
764 | 764 | | 2 |
---|
765 | 765 | | 4-120-204. Controller response to consumer request. 3 |
---|
766 | 766 | | (a) Except as otherwise provided by this chapter, a controller shall 4 |
---|
767 | 767 | | comply with a request submitted by a consumer to exercise the consumer’s 5 |
---|
768 | 768 | | rights under § 4-120-201 as provided by this section. 6 |
---|
769 | 769 | | (b)(1) A controller shall respond to the consumer request without 7 |
---|
770 | 770 | | undue delay, which may not be later than the forty -fifth day after the date 8 |
---|
771 | 771 | | of receipt of the request. 9 |
---|
772 | 772 | | (2) The controller may extend the response period once by an 10 |
---|
773 | 773 | | additional forty-five (45) days when reasonably necessary, taking into 11 |
---|
774 | 774 | | account the complexity and number of the consumer’s requests, so long as the 12 |
---|
775 | 775 | | controller informs the consumer of the extension within the initial forty -13 |
---|
776 | 776 | | five-day response period, together with the reason for the extension. 14 |
---|
777 | 777 | | (c) If a controller declines to take action regarding the consumer’s 15 |
---|
778 | 778 | | request, the controller shall inform the consumer without undue delay, which 16 |
---|
779 | 779 | | shall not be later than the forty -fifth day after the date of receipt of the 17 |
---|
780 | 780 | | request, of the justification for declining to take action and provide 18 |
---|
781 | 781 | | instructions on how to appeal the decision according to § 4 -120-205. 19 |
---|
782 | 782 | | (d)(1) A controller shall provide information in response to a 20 |
---|
783 | 783 | | consumer request free of charge, at least twice annually per consumer. 21 |
---|
784 | 784 | | (2)(A) If a request from a consumer is manifestly unfounded, 22 |
---|
785 | 785 | | excessive, or repetitive, the controller may charge the consumer a reasonable 23 |
---|
786 | 786 | | fee to cover the administrative costs of complying with the request. 24 |
---|
787 | 787 | | (B) The controller bears the burden of demonstrating for 25 |
---|
788 | 788 | | purposes of this subsection that a request is manifestly unfounded, 26 |
---|
789 | 789 | | excessive, or repetitive. 27 |
---|
790 | 790 | | (e) If a controller is unable to authenticate the request using 28 |
---|
791 | 791 | | commercially reasonable efforts, the controller is not required to comply 29 |
---|
792 | 792 | | with a consumer request submitted under § 4 -120-201 and may request that the 30 |
---|
793 | 793 | | consumer provide additional information reasonably necessary to authenticate 31 |
---|
794 | 794 | | the consumer and the consumer’s request. 32 |
---|
795 | 795 | | (f) A controller that has obtained personal data about a consumer from 33 |
---|
796 | 796 | | a source other than the consumer is considered in compliance with a 34 |
---|
797 | 797 | | consumer’s request to delete the consumer's personal data under § 4 -120-35 |
---|
798 | 798 | | 201(b)(3) by: 36 SB258 |
---|
799 | 799 | | |
---|
800 | 800 | | 22 02/18/2025 3:16:09 PM ANS146 |
---|
801 | 801 | | (1) Retaining a record of the deletion request and the minimum 1 |
---|
802 | 802 | | data necessary for the purpose of ensuring the consumer’s personal data 2 |
---|
803 | 803 | | remains deleted form the business’s records and not using the retained data 3 |
---|
804 | 804 | | for any other purpose under this chapter; or 4 |
---|
805 | 805 | | (2) Opting the consumer out of the processing of that personal 5 |
---|
806 | 806 | | data for any purpose other than a purpose that is exempt under the provisions 6 |
---|
807 | 807 | | of this chapter. 7 |
---|
808 | 808 | | 8 |
---|
809 | 809 | | 4-120-205. Appeal. 9 |
---|
810 | 810 | | (a) A controller shall establish a process for a consumer to appeal 10 |
---|
811 | 811 | | the controller’s refusal to take action on the consumer's request under § 4 -11 |
---|
812 | 812 | | 120-204(c). 12 |
---|
813 | 813 | | (b) The appeal process must be conspicuously available and similar to 13 |
---|
814 | 814 | | the process for initiating action to exercise consumer rights by submitting a 14 |
---|
815 | 815 | | request under § 4-120-201. 15 |
---|
816 | 816 | | (c) A controller shall inform the consumer in writing of any action 16 |
---|
817 | 817 | | taken or not taken in response to an appeal under this section not later than 17 |
---|
818 | 818 | | the sixtieth day after the date of receipt of the appeal, including a written 18 |
---|
819 | 819 | | explanation of the reason or reasons for the decision. 19 |
---|
820 | 820 | | (d) If the controller denies an appeal, the controller shall provide 20 |
---|
821 | 821 | | the consumer with the contact information of the Attorney General to submit a 21 |
---|
822 | 822 | | complaint. 22 |
---|
823 | 823 | | 23 |
---|
824 | 824 | | Subchapter 3 — Controller Responsibilities 24 |
---|
825 | 825 | | 25 |
---|
826 | 826 | | 4-120-301. Notice of privacy practices. 26 |
---|
827 | 827 | | (a) A controller shall provide consumers with a reasonably accessible 27 |
---|
828 | 828 | | and clear privacy notice that includes: 28 |
---|
829 | 829 | | (1) The categories of personal data processed by the controller, 29 |
---|
830 | 830 | | including, if applicable, any sensitive data processed by the controller; 30 |
---|
831 | 831 | | (2) The purpose for processing personal data; 31 |
---|
832 | 832 | | (3) How consumers may exercise their consumer rights under § 4 -32 |
---|
833 | 833 | | 120-201 et seq., including the process by which a consumer may appeal a 33 |
---|
834 | 834 | | controller’s decision with regard to the consumer’s request; 34 |
---|
835 | 835 | | (4) If applicable, the categories of personal data that the 35 |
---|
836 | 836 | | controller shares with third parties; 36 SB258 |
---|
837 | 837 | | |
---|
838 | 838 | | 23 02/18/2025 3:16:09 PM ANS146 |
---|
839 | 839 | | (5) If applicable, the categories of third parties with whom the 1 |
---|
840 | 840 | | controller shares personal data; and 2 |
---|
841 | 841 | | (6) A description of the methods required under § 4 -120-201 3 |
---|
842 | 842 | | through which consumers can submit requests to exercise their consumer rights 4 |
---|
843 | 843 | | under this chapter. 5 |
---|
844 | 844 | | (b)(1) If a controller engages in the sale of personal data that is 6 |
---|
845 | 845 | | sensitive data, the controller shall include the following notice: 7 |
---|
846 | 846 | | "NOTICE: We may sell your sensitive personal data.". 8 |
---|
847 | 847 | | (2) The notice required under subdivision (b)(1) of this section 9 |
---|
848 | 848 | | shall be posted in the same location and in the same manner as the privacy 10 |
---|
849 | 849 | | notice described by subsection (a) of this section. 11 |
---|
850 | 850 | | (c)(1) If a controller engages in the sale of personal data that is 12 |
---|
851 | 851 | | biometric data, the controller shall include the following notice: 13 |
---|
852 | 852 | | “NOTICE: We may sell your biometric personal data.”. 14 |
---|
853 | 853 | | (2) The notice required under subdivision (c)(1) of this section 15 |
---|
854 | 854 | | shall be posted in the same location and in the same manner as the privacy 16 |
---|
855 | 855 | | notice described by subsection (a) of this section. 17 |
---|
856 | 856 | | (d)(1) If a controller sells personal data to third parties or 18 |
---|
857 | 857 | | processes personal data for targeted advertising, the controller shall 19 |
---|
858 | 858 | | clearly and conspicuously disclose the sale or process. 20 |
---|
859 | 859 | | (2) The controller shall provide the manner in which a consumer 21 |
---|
860 | 860 | | may exercise the right to opt out of the sale or process under subdivision 22 |
---|
861 | 861 | | (d)(1) of this section. 23 |
---|
862 | 862 | | 24 |
---|
863 | 863 | | 4-120-302. Lawful basis of processing. 25 |
---|
864 | 864 | | (a) A person described under § 4 -120-104 shall not engage in the sale 26 |
---|
865 | 865 | | of personal data that is sensitive data without receiving prior consent from 27 |
---|
866 | 866 | | the consumer. 28 |
---|
867 | 867 | | (b) A person described under § 4 -120-104 shall not otherwise process 29 |
---|
868 | 868 | | the personal information of a resident of this state without: 30 |
---|
869 | 869 | | (1) An identifiable, good faith, and legitimate interest in 31 |
---|
870 | 870 | | processing the personal data that is publicly disclosed to consumers in the 32 |
---|
871 | 871 | | notice required under § 4 -120-301(a)(2) and not outweighed by the rights and 33 |
---|
872 | 872 | | freedoms of consumers; 34 |
---|
873 | 873 | | (2) The consent of the individual consumer; 35 |
---|
874 | 874 | | (3) A contract which requires the processing of personal data; 36 SB258 |
---|
875 | 875 | | |
---|
876 | 876 | | 24 02/18/2025 3:16:09 PM ANS146 |
---|
877 | 877 | | (4) A legal obligation to process the personal data; or 1 |
---|
878 | 878 | | (5) An overriding necessity to process the personal data of a 2 |
---|
879 | 879 | | person for the limited purpose of protecting the person's vital interests. 3 |
---|
880 | 880 | | (c) A person that is not a covered entity or business associate as 4 |
---|
881 | 881 | | defined by the Health Insurance Portability and Accountability Act of 1996, 5 |
---|
882 | 882 | | 42 U.S.C. § 1320d et seq., as it existed on January 1, 2025, shall not 6 |
---|
883 | 883 | | collect or share any consumer health data except: 7 |
---|
884 | 884 | | (1) With consent from the consumer for cash collection for a 8 |
---|
885 | 885 | | specified purpose; or 9 |
---|
886 | 886 | | (2) To the extent necessary to provide a product or service that 10 |
---|
887 | 887 | | the consumer to whom the consumer health data relates has requested from the 11 |
---|
888 | 888 | | person. 12 |
---|
889 | 889 | | (d) Consent required under subsection (c) of this section shall be 13 |
---|
890 | 890 | | obtained before the collection or sharing, as applicable, of any consumer 14 |
---|
891 | 891 | | health data, and the request for consent shall clearly and conspicuously 15 |
---|
892 | 892 | | disclose: 16 |
---|
893 | 893 | | (1) The categories of consumer health data collected or shared; 17 |
---|
894 | 894 | | (2) The purpose of the collection or sharing of the consumer 18 |
---|
895 | 895 | | health data, including the specific ways in which it will be used; 19 |
---|
896 | 896 | | (3) The categories of entities with whom the consumer health 20 |
---|
897 | 897 | | data is shared; and 21 |
---|
898 | 898 | | (4) How the consumer can withdraw consent from future collection 22 |
---|
899 | 899 | | or sharing of the consumer’s health data. 23 |
---|
900 | 900 | | (e) A controller shall not process the sensitive data of a consumer 24 |
---|
901 | 901 | | without obtaining the consumer’s consent or, in the case of processing the 25 |
---|
902 | 902 | | sensitive data of a known child, without processing that data according to 26 |
---|
903 | 903 | | the Children’s Online Privacy Protection Act of 1998, 15 U.S.C. § 6501 et 27 |
---|
904 | 904 | | seq., as it existed on January 1, 2025. 28 |
---|
905 | 905 | | 29 |
---|
906 | 906 | | 4-120-303. Dark patterns. 30 |
---|
907 | 907 | | (a) A controller that collects personal information via a website, 31 |
---|
908 | 908 | | mobile application, or similar technology shall not utilize dark patterns in 32 |
---|
909 | 909 | | its user interfaces. 33 |
---|
910 | 910 | | (b) A lawful basis for processing personal data described under § 4 -34 |
---|
911 | 911 | | 120-302 obtained by use of a dark pattern is void. 35 |
---|
912 | 912 | | 36 SB258 |
---|
913 | 913 | | |
---|
914 | 914 | | 25 02/18/2025 3:16:09 PM ANS146 |
---|
915 | 915 | | 4-120-304. Data minimization. 1 |
---|
916 | 916 | | (a) A controller shall limit the collection of personal data to what 2 |
---|
917 | 917 | | is adequate, relevant, and reasonably necessary in relation to the purposes 3 |
---|
918 | 918 | | for which that personal data is processed, as disclosed to the consumer. 4 |
---|
919 | 919 | | (b) A controller in possession of deidentified data shall: 5 |
---|
920 | 920 | | (1) Take reasonable measures to ensure that the data cannot be 6 |
---|
921 | 921 | | associated with an individual; 7 |
---|
922 | 922 | | (2) Publicly commit to maintaining and using deidentified data 8 |
---|
923 | 923 | | without attempting to reidentify the data; and 9 |
---|
924 | 924 | | (3) Contractually obligate any recipient of the deidentified 10 |
---|
925 | 925 | | data to comply with this section. 11 |
---|
926 | 926 | | (c) This section does not require a controller to: 12 |
---|
927 | 927 | | (1) Reidentify deidentified data or pseudonymous data; 13 |
---|
928 | 928 | | (2) Maintain data in identifiable form or obtain, retain, or 14 |
---|
929 | 929 | | access any data or technology for the purpose of allowing the controller or 15 |
---|
930 | 930 | | processor to associate a consumer request with personal data; or 16 |
---|
931 | 931 | | (3) Comply with an authenticated consumer rights request under § 17 |
---|
932 | 932 | | 4-120-201, if the controller: 18 |
---|
933 | 933 | | (A) Is not reasonably capable of associating the request 19 |
---|
934 | 934 | | with the personal data or it would be unreasonably burdensome for the 20 |
---|
935 | 935 | | controller to associate the request with the personal data; 21 |
---|
936 | 936 | | (B) Does not use the personal data to recognize or respond 22 |
---|
937 | 937 | | to the specific consumer who is the subject of the personal data or associate 23 |
---|
938 | 938 | | the personal data with other personal data about the same consumer; and 24 |
---|
939 | 939 | | (C) Does not sell the personal data to a third party or 25 |
---|
940 | 940 | | otherwise voluntarily disclose the personal data to a third party other than 26 |
---|
941 | 941 | | a processor, except as otherwise permitted by this section. 27 |
---|
942 | 942 | | (d) A controller that discloses pseudonymous data or deidentified data 28 |
---|
943 | 943 | | shall exercise reasonable oversight to monitor compliance with any 29 |
---|
944 | 944 | | contractual commitments to which the pseudonymous data or deidentified data 30 |
---|
945 | 945 | | is subject and shall take appropriate steps to address any breach of the 31 |
---|
946 | 946 | | contractual commitments. 32 |
---|
947 | 947 | | (e) This section shall not be construed to require a controller to 33 |
---|
948 | 948 | | provide a product or service that requires the personal data of a consumer 34 |
---|
949 | 949 | | that the controller does not collect or maintain or to prohibit a controller 35 |
---|
950 | 950 | | from offering a different price, rate, level, quality, or selection of goods 36 SB258 |
---|
951 | 951 | | |
---|
952 | 952 | | 26 02/18/2025 3:16:09 PM ANS146 |
---|
953 | 953 | | or services to a consumer, including offering goods or services for no fee, 1 |
---|
954 | 954 | | if the consumer has exercised the consumer’s right to opt out under § 4 -120-2 |
---|
955 | 955 | | 201 or the offer is related to a consumer’s voluntary participation in a bona 3 |
---|
956 | 956 | | fide loyalty, rewards, premium features, discounts, or club card program. 4 |
---|
957 | 957 | | 5 |
---|
958 | 958 | | 4-120-305. Data security. 6 |
---|
959 | 959 | | A controller, for purposes of protecting the confidentiality, 7 |
---|
960 | 960 | | integrity, and accessibility of personal data, shall establish, implement, 8 |
---|
961 | 961 | | and maintain reasonable administrative, technical, and physical data security 9 |
---|
962 | 962 | | practices that are appropriate to the volume and nature of the personal data 10 |
---|
963 | 963 | | at issue. 11 |
---|
964 | 964 | | 12 |
---|
965 | 965 | | 4-120-306. Purpose limitation. 13 |
---|
966 | 966 | | Personal data processed by a controller under this chapter: 14 |
---|
967 | 967 | | (1) Shall not be processed for any purpose other than a purpose 15 |
---|
968 | 968 | | listed in this chapter unless otherwise allowed by this chapter; 16 |
---|
969 | 969 | | (2) May be processed to the extent that the processing of data 17 |
---|
970 | 970 | | is: 18 |
---|
971 | 971 | | (A) Reasonably necessary and proportionate to the purposes 19 |
---|
972 | 972 | | listed in this chapter; and 20 |
---|
973 | 973 | | (B) Adequate, relevant, and limited to what is necessary 21 |
---|
974 | 974 | | in relation to the specific purposes listed in this chapter; and 22 |
---|
975 | 975 | | (3) Except as otherwise provided by this subchapter, a 23 |
---|
976 | 976 | | controller shall not process personal data for a purpose that is neither 24 |
---|
977 | 977 | | reasonably necessary to nor compatible with the purpose for which the 25 |
---|
978 | 978 | | personal data is processed, as disclosed to the consumer, unless the 26 |
---|
979 | 979 | | controller obtains the consumer’s consent. 27 |
---|
980 | 980 | | 28 |
---|
981 | 981 | | 4-120-307. Sale of data to third parties and processing data for 29 |
---|
982 | 982 | | targeted advertising — Disclosure. 30 |
---|
983 | 983 | | If a controller sells personal data to third parties or processes 31 |
---|
984 | 984 | | personal data for targeted advertising, the controller shall clearly and 32 |
---|
985 | 985 | | conspicuously disclose the process and the manner in which a consumer may 33 |
---|
986 | 986 | | exercise the right to opt out of that process. 34 |
---|
987 | 987 | | 35 |
---|
988 | 988 | | 4-120-308. Data protection assessments. 36 SB258 |
---|
989 | 989 | | |
---|
990 | 990 | | 27 02/18/2025 3:16:09 PM ANS146 |
---|
991 | 991 | | (a) A controller shall conduct and document a data protection 1 |
---|
992 | 992 | | assessment of each of the following processing activities involving personal 2 |
---|
993 | 993 | | data: 3 |
---|
994 | 994 | | (1) The processing of personal data for purposes of targeted 4 |
---|
995 | 995 | | advertising; 5 |
---|
996 | 996 | | (2) The sale of personal data; 6 |
---|
997 | 997 | | (3) The processing of personal data for purposes of profiling if 7 |
---|
998 | 998 | | the profiling presents a reasonably foreseeable risk of: 8 |
---|
999 | 999 | | (A) Unfair or deceptive treatment of or unlawful disparate 9 |
---|
1000 | 1000 | | impact on consumers; 10 |
---|
1001 | 1001 | | (B) Financial, physical, or reputational injury to 11 |
---|
1002 | 1002 | | consumers; 12 |
---|
1003 | 1003 | | (C) A physical or other intrusion on the solitude or 13 |
---|
1004 | 1004 | | seclusion, or the private affairs or concerns, of consumers, if the intrusion 14 |
---|
1005 | 1005 | | would be offensive to a reasonable person; or 15 |
---|
1006 | 1006 | | (D) Other substantial injury to consumers; 16 |
---|
1007 | 1007 | | (4) The processing of sensitive data; and 17 |
---|
1008 | 1008 | | (5) Any processing activities involving personal data that 18 |
---|
1009 | 1009 | | present a heightened risk of harm to consumers. 19 |
---|
1010 | 1010 | | (b) A data protection assessment conducted under subsection (a) of 20 |
---|
1011 | 1011 | | this section shall: 21 |
---|
1012 | 1012 | | (1) Identify and weigh the direct or indirect benefits that may 22 |
---|
1013 | 1013 | | flow from the processing to the controller, the consumer, other stakeholders, 23 |
---|
1014 | 1014 | | and the public against the potential risks to the rights of the consumer 24 |
---|
1015 | 1015 | | associated with that processing as mitigated by safeguards that can be 25 |
---|
1016 | 1016 | | employed by the controller to reduce the risks; and 26 |
---|
1017 | 1017 | | (2) Factor into the assessment: 27 |
---|
1018 | 1018 | | (A) The use of deidentified data; 28 |
---|
1019 | 1019 | | (B) The reasonable expectations of consumers; 29 |
---|
1020 | 1020 | | (C) The context of the processing; and 30 |
---|
1021 | 1021 | | (D) The relationship between the controller and the 31 |
---|
1022 | 1022 | | consumer whose personal data will be processed. 32 |
---|
1023 | 1023 | | (c) A controller shall make a data protection assessment requested 33 |
---|
1024 | 1024 | | under § 4-120-701 et seq. available to the Attorney General under an Attorney 34 |
---|
1025 | 1025 | | General’s subpoena under § 25 -16-705. 35 |
---|
1026 | 1026 | | (d)(1) A data protection assessment is confidential and exempt from 36 SB258 |
---|
1027 | 1027 | | |
---|
1028 | 1028 | | 28 02/18/2025 3:16:09 PM ANS146 |
---|
1029 | 1029 | | public inspection and copying under the Freedom of Information Act of 1967, § 1 |
---|
1030 | 1030 | | 25-19-101 et seq. 2 |
---|
1031 | 1031 | | (2) Disclosure of a data protection assessment in compliance 3 |
---|
1032 | 1032 | | with a request from the Attorney General does not constitute a waiver of 4 |
---|
1033 | 1033 | | attorney-client privilege or work product protection with respect to the 5 |
---|
1034 | 1034 | | assessment and any information contained in the assessment. 6 |
---|
1035 | 1035 | | (e) A single data protection assessment may address a comparable set 7 |
---|
1036 | 1036 | | of processing operations that include similar activities. 8 |
---|
1037 | 1037 | | (f) A data protection assessment conducted by a controller for the 9 |
---|
1038 | 1038 | | purpose of compliance with other laws or regulations may constitute 10 |
---|
1039 | 1039 | | compliance with the requirements of this section if the assessment has a 11 |
---|
1040 | 1040 | | reasonably comparable scope and effect. 12 |
---|
1041 | 1041 | | 13 |
---|
1042 | 1042 | | 4-120-309. Pseudonymous data. 14 |
---|
1043 | 1043 | | The consumer rights under § 4 -120-201 and controller duties under this 15 |
---|
1044 | 1044 | | subchapter do not apply to pseudonymous data in cases in which the controller 16 |
---|
1045 | 1045 | | is able to demonstrate any information necessary to identify the consumer is 17 |
---|
1046 | 1046 | | kept separately and is subject to effective technical and organizational 18 |
---|
1047 | 1047 | | controls that prevent the controller from accessing the information. 19 |
---|
1048 | 1048 | | 20 |
---|
1049 | 1049 | | 4-120-310. Miscellaneous prohibitions. 21 |
---|
1050 | 1050 | | A controller shall not: 22 |
---|
1051 | 1051 | | (1) Process personal data in violation of state and federal laws 23 |
---|
1052 | 1052 | | that prohibit unlawful discrimination against consumers; or 24 |
---|
1053 | 1053 | | (2) Discriminate against a consumer for exercising any of the 25 |
---|
1054 | 1054 | | consumer rights contained in this chapter, including by denying goods or 26 |
---|
1055 | 1055 | | services, charging different prices or rates for goods or services, or 27 |
---|
1056 | 1056 | | providing a different level of quality of goods or services to the consumer. 28 |
---|
1057 | 1057 | | 29 |
---|
1058 | 1058 | | Subchapter 4 — Processor Responsibilities 30 |
---|
1059 | 1059 | | 31 |
---|
1060 | 1060 | | 4-120-401. Compliance with contractual obligations. 32 |
---|
1061 | 1061 | | (a) A processor shall adhere to the instructions of a controller and 33 |
---|
1062 | 1062 | | shall assist the controller in meeting or complying with the controller’s 34 |
---|
1063 | 1063 | | duties or requirements under this chapter, including without limitation: 35 |
---|
1064 | 1064 | | (1) Assisting the controller in responding to consumer rights 36 SB258 |
---|
1065 | 1065 | | |
---|
1066 | 1066 | | 29 02/18/2025 3:16:09 PM ANS146 |
---|
1067 | 1067 | | requests submitted under § 4 -120-201 by using appropriate technical and 1 |
---|
1068 | 1068 | | organizational measures, as reasonably practicable, taking into account the 2 |
---|
1069 | 1069 | | nature of processing and the information available to the processor; 3 |
---|
1070 | 1070 | | (2) Assisting the controller with regard to complying with the 4 |
---|
1071 | 1071 | | requirement relating to the security of processing personal data and to the 5 |
---|
1072 | 1072 | | notification of a breach of security of the processor’s system, taking into 6 |
---|
1073 | 1073 | | account the nature of processing and the information available to the 7 |
---|
1074 | 1074 | | processor; and 8 |
---|
1075 | 1075 | | (3) Providing necessary information to enable the controller to 9 |
---|
1076 | 1076 | | conduct and document data protection assessments under § 4 -120-308. 10 |
---|
1077 | 1077 | | (b)(1) A contract between a controller and a processor shall govern 11 |
---|
1078 | 1078 | | the processor’s data processing procedures with respect to processing 12 |
---|
1079 | 1079 | | performed on behalf of the controller. 13 |
---|
1080 | 1080 | | (2) The contract shall include: 14 |
---|
1081 | 1081 | | (A) Clear instructions for processing data; 15 |
---|
1082 | 1082 | | (B) The nature and purpose of processing; 16 |
---|
1083 | 1083 | | (C) The type of data subject to processing; 17 |
---|
1084 | 1084 | | (D) The duration of processing; 18 |
---|
1085 | 1085 | | (E) The rights and obligations of both parties; and 19 |
---|
1086 | 1086 | | (F) A requirement that the processor shall: 20 |
---|
1087 | 1087 | | (i) Ensure that each person processing personal data 21 |
---|
1088 | 1088 | | is subject to a duty of confidentiality with respect to the data; 22 |
---|
1089 | 1089 | | (ii) At the controller’s direction, delete or return 23 |
---|
1090 | 1090 | | all personal data to the controller as requested after the provision of the 24 |
---|
1091 | 1091 | | service is completed, unless retention of the personal data is required by 25 |
---|
1092 | 1092 | | law; 26 |
---|
1093 | 1093 | | (iii) Make available to the controller, on 27 |
---|
1094 | 1094 | | reasonable request, all information in the processor’s possession necessary 28 |
---|
1095 | 1095 | | to demonstrate the processor’s compliance with the requirements of this 29 |
---|
1096 | 1096 | | chapter; 30 |
---|
1097 | 1097 | | (iv) Allow, and cooperate with, reasonable 31 |
---|
1098 | 1098 | | assessments by the controller or the controller’s designated assessor; and 32 |
---|
1099 | 1099 | | (v) Engage a subcontractor under a written contract 33 |
---|
1100 | 1100 | | that requires the subcontractor to meet the requirements of the processor 34 |
---|
1101 | 1101 | | with respect to the personal data. 35 |
---|
1102 | 1102 | | (c)(1) Notwithstanding the requirement described by subdivision 36 SB258 |
---|
1103 | 1103 | | |
---|
1104 | 1104 | | 30 02/18/2025 3:16:09 PM ANS146 |
---|
1105 | 1105 | | (b)(2)(F) of this section, a processor, in the alternative, may arrange for a 1 |
---|
1106 | 1106 | | qualified and independent assessor to conduct an assessment of the 2 |
---|
1107 | 1107 | | processor’s policies and technical and organizational measures in support of 3 |
---|
1108 | 1108 | | the requirements under this chapter using an appropriate and accepted control 4 |
---|
1109 | 1109 | | standard or framework and assessment procedure. 5 |
---|
1110 | 1110 | | (2) The processor shall provide a report of the assessment to 6 |
---|
1111 | 1111 | | the controller on request. 7 |
---|
1112 | 1112 | | (d) This section does not relieve a controller or a processor from the 8 |
---|
1113 | 1113 | | liabilities imposed on the controller or processor by virtue of its role in 9 |
---|
1114 | 1114 | | the processing relationship as described by this chapter. 10 |
---|
1115 | 1115 | | (e)(1) A determination of whether a person is acting as a controller 11 |
---|
1116 | 1116 | | or processor with respect to a specific processing of data is a fact -based 12 |
---|
1117 | 1117 | | determination that depends on the context in which personal data is to be 13 |
---|
1118 | 1118 | | processed. 14 |
---|
1119 | 1119 | | (2) A processor that continues to adhere to a controller’s 15 |
---|
1120 | 1120 | | instructions with respect to a specific processing of personal data remains 16 |
---|
1121 | 1121 | | in the role of a processor. 17 |
---|
1122 | 1122 | | 18 |
---|
1123 | 1123 | | 4-120-402. Notice of privacy practices. 19 |
---|
1124 | 1124 | | A processor shall provide consumers with a reasonably accessible and 20 |
---|
1125 | 1125 | | clear privacy notice that includes: 21 |
---|
1126 | 1126 | | (1) The categories of personal data processed by the processor, 22 |
---|
1127 | 1127 | | including, if applicable, any sensitive data processed by the processor; 23 |
---|
1128 | 1128 | | (2) The purpose for processing personal data; 24 |
---|
1129 | 1129 | | (3) If applicable, the categories of personal data that the 25 |
---|
1130 | 1130 | | processor shares with third parties; and 26 |
---|
1131 | 1131 | | (4) If applicable, the categories of third parties with whom the 27 |
---|
1132 | 1132 | | processor shares personal data. 28 |
---|
1133 | 1133 | | 29 |
---|
1134 | 1134 | | 4-120-403. Data minimization at collection. 30 |
---|
1135 | 1135 | | (a) A processor shall limit the collection of personal data from a 31 |
---|
1136 | 1136 | | controller to what is adequate, relevant, and reasonably necessary in 32 |
---|
1137 | 1137 | | relation to the purposes for which the personal data is processed, as 33 |
---|
1138 | 1138 | | disclosed to the consumer. 34 |
---|
1139 | 1139 | | (b) A processor in possession of deidentified data shall: 35 |
---|
1140 | 1140 | | (1) Take reasonable measures to ensure that the data cannot be 36 SB258 |
---|
1141 | 1141 | | |
---|
1142 | 1142 | | 31 02/18/2025 3:16:09 PM ANS146 |
---|
1143 | 1143 | | associated with an individual; 1 |
---|
1144 | 1144 | | (2) Publicly commit to maintaining and using deidentified data 2 |
---|
1145 | 1145 | | without attempting to reidentify the data; and 3 |
---|
1146 | 1146 | | (3) Contractually obligate any recipient of the deidentified 4 |
---|
1147 | 1147 | | data to comply with this chapter. 5 |
---|
1148 | 1148 | | (c) This chapter does not require a processor to: 6 |
---|
1149 | 1149 | | (1) Reidentify deidentified data or pseudonymous data; 7 |
---|
1150 | 1150 | | (2) Maintain data in identifiable form or obtain, retain, or 8 |
---|
1151 | 1151 | | access any data or technology for the purpose of allowing the processor to 9 |
---|
1152 | 1152 | | associate a consumer request with personal data; or 10 |
---|
1153 | 1153 | | (3) Comply with an authenticated consumer rights request under § 11 |
---|
1154 | 1154 | | 4-120-201 et seq., if the processor: 12 |
---|
1155 | 1155 | | (A) Is not reasonably capable of associating the request 13 |
---|
1156 | 1156 | | with the personal data or it would be unreasonably burdensome for the 14 |
---|
1157 | 1157 | | processor to associate the request with the personal data; 15 |
---|
1158 | 1158 | | (B) Does not use the personal data to recognize or respond 16 |
---|
1159 | 1159 | | to the specific consumer who is the subject of the personal data or associate 17 |
---|
1160 | 1160 | | the personal data with other personal data about the same consumer; and 18 |
---|
1161 | 1161 | | (C) Does not sell the personal data to any third party or 19 |
---|
1162 | 1162 | | otherwise voluntarily disclose the personal data to any third party other 20 |
---|
1163 | 1163 | | than a processor, except as otherwise permitted by this section. 21 |
---|
1164 | 1164 | | (d) The consumer rights under § 4 -120-201 and processor duties under 22 |
---|
1165 | 1165 | | this subchapter do not apply to pseudonymous data in cases in which the 23 |
---|
1166 | 1166 | | processor is able to demonstrate any information necessary to identify the 24 |
---|
1167 | 1167 | | consumer is kept separately and is subject to effective technical and 25 |
---|
1168 | 1168 | | organizational controls that prevent the controller from accessing the 26 |
---|
1169 | 1169 | | information. 27 |
---|
1170 | 1170 | | (e) A processor that discloses pseudonymous data or deidentified data 28 |
---|
1171 | 1171 | | shall exercise reasonable oversight to monitor compliance with any 29 |
---|
1172 | 1172 | | contractual commitments to which the pseudonymous data or deidentified data 30 |
---|
1173 | 1173 | | is subject and shall take appropriate steps to address any breach of the 31 |
---|
1174 | 1174 | | contractual commitments. 32 |
---|
1175 | 1175 | | 33 |
---|
1176 | 1176 | | 4-120-404. Data security. 34 |
---|
1177 | 1177 | | A processor, for purposes of protecting the confidentiality, integrity, 35 |
---|
1178 | 1178 | | and accessibility of personal data, shall establish, implement, and maintain 36 SB258 |
---|
1179 | 1179 | | |
---|
1180 | 1180 | | 32 02/18/2025 3:16:09 PM ANS146 |
---|
1181 | 1181 | | reasonable administrative, technical, and physical data security practices 1 |
---|
1182 | 1182 | | that are appropriate to the volume and nature of the personal data at issue. 2 |
---|
1183 | 1183 | | 3 |
---|
1184 | 1184 | | 4-120-405. Purpose limitation. 4 |
---|
1185 | 1185 | | (a) Personal data processed by a processor under this chapter shall 5 |
---|
1186 | 1186 | | not be processed for any purpose other than a purpose listed in this chapter 6 |
---|
1187 | 1187 | | unless otherwise allowed by this chapter. 7 |
---|
1188 | 1188 | | (b) Personal data under subsection (a) of this section processed by a 8 |
---|
1189 | 1189 | | processor under this subchapter may be processed to the extent that the 9 |
---|
1190 | 1190 | | processing of data is: 10 |
---|
1191 | 1191 | | (1) Reasonably necessary and proportionate to the purposes 11 |
---|
1192 | 1192 | | listed in this chapter; and 12 |
---|
1193 | 1193 | | (2) Adequate, relevant, and limited to what is necessary in 13 |
---|
1194 | 1194 | | relation to the purposes of this chapter. 14 |
---|
1195 | 1195 | | 15 |
---|
1196 | 1196 | | 4-120-406. Data retention. 16 |
---|
1197 | 1197 | | (a) A processor shall follow the instructions of the controller in the 17 |
---|
1198 | 1198 | | retention and deletion of personal data. 18 |
---|
1199 | 1199 | | (b) If the controller does not provide the processor instructions, a 19 |
---|
1200 | 1200 | | processor shall delete all personal data within ninety (90) days of ceasing 20 |
---|
1201 | 1201 | | processing the data for the controller unless law, statute, or regulation 21 |
---|
1202 | 1202 | | requires a longer retention period. 22 |
---|
1203 | 1203 | | 23 |
---|
1204 | 1204 | | 4-120-407. Assisting controllers in honoring data subject rights. 24 |
---|
1205 | 1205 | | (a) If a controller gives a processor notice that the controller has 25 |
---|
1206 | 1206 | | received a consumer request regarding personal data the processed by the 26 |
---|
1207 | 1207 | | processor for the controller, the processor shall follow the instructions of 27 |
---|
1208 | 1208 | | the controller in complying with the consumer’s request. 28 |
---|
1209 | 1209 | | (b) If a processor receives a request from a consumer regarding data 29 |
---|
1210 | 1210 | | received from a controller, the processor shall: 30 |
---|
1211 | 1211 | | (1) Notify the controller that they have received a consumer 31 |
---|
1212 | 1212 | | data rights request; 32 |
---|
1213 | 1213 | | (2) Notify the consumer that they have forwarded the request to 33 |
---|
1214 | 1214 | | the controller; and 34 |
---|
1215 | 1215 | | (3) Follow the instructions of the controller in complying with 35 |
---|
1216 | 1216 | | the consumer’s request. 36 SB258 |
---|
1217 | 1217 | | |
---|
1218 | 1218 | | 33 02/18/2025 3:16:09 PM ANS146 |
---|
1219 | 1219 | | 1 |
---|
1220 | 1220 | | Subchapter 5 — Special Data Types 2 |
---|
1221 | 1221 | | 3 |
---|
1222 | 1222 | | 4-120-501. Biometrics. 4 |
---|
1223 | 1223 | | (a)(1) A person in possession of biometric data shall develop a 5 |
---|
1224 | 1224 | | written policy, made available to the public, establishing a retention 6 |
---|
1225 | 1225 | | schedule and guidelines for permanently destroying biometric data when the 7 |
---|
1226 | 1226 | | initial purpose for collecting or obtaining the biometric data has been 8 |
---|
1227 | 1227 | | satisfied or within three (3) years, whichever occurs first. 9 |
---|
1228 | 1228 | | (2) Absent a valid warrant or subpoena issued by a court of 10 |
---|
1229 | 1229 | | competent jurisdiction, a private entity in possession of biometric data must 11 |
---|
1230 | 1230 | | comply with the private entity's established retention schedule and 12 |
---|
1231 | 1231 | | destruction guidelines. 13 |
---|
1232 | 1232 | | (b) A private entity shall not collect, capture, purchase, receive 14 |
---|
1233 | 1233 | | through trade, or otherwise obtain a person’s or a consumer’s biometric data, 15 |
---|
1234 | 1234 | | unless the private entity first: 16 |
---|
1235 | 1235 | | (1) Informs a consumer or the consumer’s legally authorized 17 |
---|
1236 | 1236 | | representative in writing that biometric data is being collected or stored; 18 |
---|
1237 | 1237 | | (2) Informs a consumer or the consumer’s legally authorized 19 |
---|
1238 | 1238 | | representative in writing of the specific purpose and length of term for 20 |
---|
1239 | 1239 | | which biometric data is being collected, stored, and used; and 21 |
---|
1240 | 1240 | | (3) Receives a written release executed by a consumer. 22 |
---|
1241 | 1241 | | (c) A person in possession of biometric data shall not: 23 |
---|
1242 | 1242 | | (1) Sell, lease, trade, or otherwise profit from a person’s or a 24 |
---|
1243 | 1243 | | consumer’s biometric data; or 25 |
---|
1244 | 1244 | | (2) Disclose, redisclose, or otherwise disseminate a person’s or 26 |
---|
1245 | 1245 | | a consumer’s biometric data unless: 27 |
---|
1246 | 1246 | | (A) The subject of the biometric data or the subject’s 28 |
---|
1247 | 1247 | | legally authorized representative consents to the disclosure, redisclosure, 29 |
---|
1248 | 1248 | | or dissemination; 30 |
---|
1249 | 1249 | | (B) The disclosure, redisclosure, or dissemination 31 |
---|
1250 | 1250 | | completes a financial transaction requested or authorized by the subject of 32 |
---|
1251 | 1251 | | the biometric data or the subject’s legally authorized representative; 33 |
---|
1252 | 1252 | | (C) The disclosure, redisclosure, or dissemination is 34 |
---|
1253 | 1253 | | required by state or federal law or an ordinance by a local government; or 35 |
---|
1254 | 1254 | | (D) The disclosure is required under a valid warrant or 36 SB258 |
---|
1255 | 1255 | | |
---|
1256 | 1256 | | 34 02/18/2025 3:16:09 PM ANS146 |
---|
1257 | 1257 | | subpoena issued by a court of competent jurisdiction. 1 |
---|
1258 | 1258 | | 2 |
---|
1259 | 1259 | | Subchapter 6 — Responsible Artificial Intelligence 3 |
---|
1260 | 1260 | | 4 |
---|
1261 | 1261 | | 4-120-601. Developer duties. 5 |
---|
1262 | 1262 | | (a) A developer of a high -risk artificial intelligence system shall 6 |
---|
1263 | 1263 | | use reasonable care to protect consumers from any known or reasonably 7 |
---|
1264 | 1264 | | foreseeable risks of algorithmic discrimination arising from the intended and 8 |
---|
1265 | 1265 | | contracted uses of the high -risk artificial intelligence system. 9 |
---|
1266 | 1266 | | (b) A developer of a high -risk artificial intelligence system shall 10 |
---|
1267 | 1267 | | make available to the deployer, another developer of the high -risk artificial 11 |
---|
1268 | 1268 | | intelligence system, or the Attorney General upon the Attorney General’s 12 |
---|
1269 | 1269 | | request subject to a civil investigative demand: 13 |
---|
1270 | 1270 | | (1) A general statement describing the reasonably foreseeable 14 |
---|
1271 | 1271 | | uses and known harmful or inappropriate uses of the high -risk artificial 15 |
---|
1272 | 1272 | | intelligence system; 16 |
---|
1273 | 1273 | | (2) Documentation disclosing: 17 |
---|
1274 | 1274 | | (A) High-level summaries of the type of data used to train 18 |
---|
1275 | 1275 | | the high-risk artificial intelligence system; 19 |
---|
1276 | 1276 | | (B) Known or reasonably foreseeable limitations of the 20 |
---|
1277 | 1277 | | high-risk artificial intelligence system, including known or reasonably 21 |
---|
1278 | 1278 | | foreseeable risks of algorithmic discrimination arising from the intended 22 |
---|
1279 | 1279 | | uses of the high-risk artificial intelligence system; 23 |
---|
1280 | 1280 | | (C) The purpose of the high -risk artificial intelligence 24 |
---|
1281 | 1281 | | system; 25 |
---|
1282 | 1282 | | (D) The intended benefits and uses of the high-risk 26 |
---|
1283 | 1283 | | artificial intelligence system; and 27 |
---|
1284 | 1284 | | (E) All other information necessary to allow the deployer 28 |
---|
1285 | 1285 | | to complete an impact assessment under § 4 -120-603; 29 |
---|
1286 | 1286 | | (3) Documentation describing: 30 |
---|
1287 | 1287 | | (A) The method by which the high -risk artificial 31 |
---|
1288 | 1288 | | intelligence system was evaluated for performance and mitigation of 32 |
---|
1289 | 1289 | | algorithmic discrimination before the high -risk artificial intelligence 33 |
---|
1290 | 1290 | | system was offered, sold, leased, licensed, given, or otherwise made 34 |
---|
1291 | 1291 | | available to the deployer; 35 |
---|
1292 | 1292 | | (B) The data governance measures used to cover the 36 SB258 |
---|
1293 | 1293 | | |
---|
1294 | 1294 | | 35 02/18/2025 3:16:09 PM ANS146 |
---|
1295 | 1295 | | training datasets and the measures used to examine the suitability of data 1 |
---|
1296 | 1296 | | sources, possible biases, and appropriate mitigation; 2 |
---|
1297 | 1297 | | (C) The intended outputs of the high -risk artificial 3 |
---|
1298 | 1298 | | intelligence system; 4 |
---|
1299 | 1299 | | (D) The measures the developer has taken to mitigate known 5 |
---|
1300 | 1300 | | or reasonably foreseeable risks of algorithmic discrimination that may arise 6 |
---|
1301 | 1301 | | from the reasonably foreseeable deployment of the high -risk artificial 7 |
---|
1302 | 1302 | | intelligence system; and 8 |
---|
1303 | 1303 | | (E) The method by which the high -risk artificial 9 |
---|
1304 | 1304 | | intelligence system should be used, should not be used, and be monitored by 10 |
---|
1305 | 1305 | | an individual when the high -risk artificial intelligence system is used to 11 |
---|
1306 | 1306 | | make, or is a substantial factor in making, a decision that produces a legal 12 |
---|
1307 | 1307 | | or similarly significant effect concerning a consumer; and 13 |
---|
1308 | 1308 | | (4) Any additional documentation that is reasonably necessary to 14 |
---|
1309 | 1309 | | assist the deployer in understanding the outputs and monitor the performance 15 |
---|
1310 | 1310 | | of the high-risk artificial intelligence system for risks of algorithmic 16 |
---|
1311 | 1311 | | discrimination. 17 |
---|
1312 | 1312 | | (c) Except as provided in subsection (g) of this section, a developer 18 |
---|
1313 | 1313 | | that offers, sells, leases, licenses, gives, or otherwise makes available to 19 |
---|
1314 | 1314 | | a deployer or other developer a high -risk artificial intelligence system 20 |
---|
1315 | 1315 | | shall make available to the deployer or other developer, to the extent 21 |
---|
1316 | 1316 | | feasible, the documentation and information, through artifacts such as model 22 |
---|
1317 | 1317 | | cards, dataset cards, or other impact assessments, necessary for a deployer, 23 |
---|
1318 | 1318 | | or for a third party contracted by a deployer, to complete an impact 24 |
---|
1319 | 1319 | | assessment under § 4 -120-603. 25 |
---|
1320 | 1320 | | (d) A developer shall make available, in a manner that is clear and 26 |
---|
1321 | 1321 | | readily available on the developer’s website or in a public use case 27 |
---|
1322 | 1322 | | inventory, a statement summarizing: 28 |
---|
1323 | 1323 | | (1) The types of high -risk artificial intelligence systems that 29 |
---|
1324 | 1324 | | the developer has developed or intentionally and substantially modified and 30 |
---|
1325 | 1325 | | currently makes available to a deployer or other developer; and 31 |
---|
1326 | 1326 | | (2) How the developer manages known or reasonably foreseeable 32 |
---|
1327 | 1327 | | risks of algorithmic discrimination that may arise from the development or 33 |
---|
1328 | 1328 | | intentional and substantial modification of the types of high -risk artificial 34 |
---|
1329 | 1329 | | intelligence systems described according to subsection (d)(1) of this 35 |
---|
1330 | 1330 | | section. 36 SB258 |
---|
1331 | 1331 | | |
---|
1332 | 1332 | | 36 02/18/2025 3:16:09 PM ANS146 |
---|
1333 | 1333 | | (e) A developer shall update the statement described in subsection (d) 1 |
---|
1334 | 1334 | | of this section: 2 |
---|
1335 | 1335 | | (1) As necessary to ensure that the statement remains accurate; 3 |
---|
1336 | 1336 | | and 4 |
---|
1337 | 1337 | | (2) No later than ninety (90) days after the developer 5 |
---|
1338 | 1338 | | intentionally and substantially modifies any high -risk artificial 6 |
---|
1339 | 1339 | | intelligence system described in subdivision (d)(1) of this section. 7 |
---|
1340 | 1340 | | (f) A developer of a high -risk artificial intelligence system shall 8 |
---|
1341 | 1341 | | disclose to the Attorney General and to all known deployers or other 9 |
---|
1342 | 1342 | | developers of the high -risk artificial intelligence system any known or 10 |
---|
1343 | 1343 | | reasonably foreseeable risks of algorithmic discrimination arising from the 11 |
---|
1344 | 1344 | | intended uses of the high -risk artificial intelligence system without 12 |
---|
1345 | 1345 | | unreasonable delay but no later than ninety (90) days after the date on 13 |
---|
1346 | 1346 | | which: 14 |
---|
1347 | 1347 | | (1) The developer discovers through the developer’s ongoing 15 |
---|
1348 | 1348 | | testing and analysis that the developer’s high -risk artificial intelligence 16 |
---|
1349 | 1349 | | system has been deployed and has caused or is reasonably likely to have 17 |
---|
1350 | 1350 | | caused algorithmic discrimination; or 18 |
---|
1351 | 1351 | | (2) The developer receives from a deployer a credible report 19 |
---|
1352 | 1352 | | that the high-risk artificial intelligence system has been deployed and has 20 |
---|
1353 | 1353 | | caused algorithmic discrimination. 21 |
---|
1354 | 1354 | | (g)(1) This section shall not require a developer to disclose a trade 22 |
---|
1355 | 1355 | | secret, information protected from disclosure by state or federal law, or 23 |
---|
1356 | 1356 | | information that would create a security risk to the developer, except to the 24 |
---|
1357 | 1357 | | Attorney General. 25 |
---|
1358 | 1358 | | (2) In a disclosure to the Attorney General, the developer may 26 |
---|
1359 | 1359 | | designate the statement or documentation as including proprietary information 27 |
---|
1360 | 1360 | | or a trade secret. 28 |
---|
1361 | 1361 | | 29 |
---|
1362 | 1362 | | 4-120-602. Deployer duties. 30 |
---|
1363 | 1363 | | (a)(1) A deployer of a high -risk artificial intelligence system shall 31 |
---|
1364 | 1364 | | use reasonable care to protect consumers from any known or reasonably 32 |
---|
1365 | 1365 | | foreseeable risks of algorithmic discrimination. 33 |
---|
1366 | 1366 | | (2) In any enforcement action brought by the Attorney General 34 |
---|
1367 | 1367 | | under § 4-120-701 et seq., there is a rebuttable presumption that a deployer 35 |
---|
1368 | 1368 | | of a high-risk artificial intelligence system used reasonable care as 36 SB258 |
---|
1369 | 1369 | | |
---|
1370 | 1370 | | 37 02/18/2025 3:16:09 PM ANS146 |
---|
1371 | 1371 | | required under this section if the deployer complied with this section. 1 |
---|
1372 | 1372 | | (b)(1) A deployer of high -risk artificial intelligence systems shall 2 |
---|
1373 | 1373 | | implement a risk management policy and program to govern the deployer’s 3 |
---|
1374 | 1374 | | deployment of one (1) or more high -risk artificial intelligence systems. 4 |
---|
1375 | 1375 | | (2) The risk management policy and program shall specify and 5 |
---|
1376 | 1376 | | incorporate principles, processes, and personnel that the deployer uses to 6 |
---|
1377 | 1377 | | identify, document, and mitigate known or reasonably foreseeable risks of 7 |
---|
1378 | 1378 | | algorithmic discrimination. 8 |
---|
1379 | 1379 | | (3) The risk management policy and program shall be an 9 |
---|
1380 | 1380 | | interactive process planned, implemented, and regularly and systematically 10 |
---|
1381 | 1381 | | reviewed and updated over the lifecycle of a high -risk artificial 11 |
---|
1382 | 1382 | | intelligence system, requiring regular, systematic review, and updates. 12 |
---|
1383 | 1383 | | (4) A risk management policy and program implemented and 13 |
---|
1384 | 1384 | | maintained under this subdivision (b)(1) of this section shall be reasonable 14 |
---|
1385 | 1385 | | considering: 15 |
---|
1386 | 1386 | | (A) The guidance and standards stated in the latest 16 |
---|
1387 | 1387 | | version of the Artificial Intelligence Risk Management Framework published by 17 |
---|
1388 | 1388 | | the National Institute of Standards and Technology of the United States 18 |
---|
1389 | 1389 | | Department of Commerce, Standard ISO/IEC 42001 of the International 19 |
---|
1390 | 1390 | | Organization for Standardization, or another nationally or internationally 20 |
---|
1391 | 1391 | | recognized risk management framework for artificial intelligence systems, if 21 |
---|
1392 | 1392 | | the standards are substantially equivalent to or more stringent than the 22 |
---|
1393 | 1393 | | requirements of this subchapter; 23 |
---|
1394 | 1394 | | (B) The size and complexity of the deployer; 24 |
---|
1395 | 1395 | | (C) The nature and scope of the high -risk artificial 25 |
---|
1396 | 1396 | | intelligence systems deployed by the deployer, including the intended uses of 26 |
---|
1397 | 1397 | | the high-risk artificial intelligence systems; and 27 |
---|
1398 | 1398 | | (D) The sensitivity and volume of data processed in 28 |
---|
1399 | 1399 | | connection with the high -risk artificial intelligence systems deployed by the 29 |
---|
1400 | 1400 | | deployer. 30 |
---|
1401 | 1401 | | (c) A deployer or other developer that deploys, offers, sells, leases, 31 |
---|
1402 | 1402 | | licenses, gives, or otherwise makes available an artificial intelligence 32 |
---|
1403 | 1403 | | system that is intended to interact with consumers shall ensure the 33 |
---|
1404 | 1404 | | disclosure to each consumer who interacts with the artificial intelligence 34 |
---|
1405 | 1405 | | system that the consumer is interacting with an artificial intelligence 35 |
---|
1406 | 1406 | | system, unless under the circumstances it would be obvious to a reasonable 36 SB258 |
---|
1407 | 1407 | | |
---|
1408 | 1408 | | 38 02/18/2025 3:16:09 PM ANS146 |
---|
1409 | 1409 | | person that the person is interacting with an artificial intelligence system. 1 |
---|
1410 | 1410 | | (d) If a deployer deploys a high -risk artificial intelligence system 2 |
---|
1411 | 1411 | | and subsequently discovers that the high -risk artificial intelligence system 3 |
---|
1412 | 1412 | | has caused algorithmic discrimination, the deployer, without unreasonable 4 |
---|
1413 | 1413 | | delay, but no later than ninety (90) days after the date of the discovery, 5 |
---|
1414 | 1414 | | shall send to the Attorney General a notice disclosing the discovery. 6 |
---|
1415 | 1415 | | 7 |
---|
1416 | 1416 | | 4-120-603. Artificial intelligence impact assessments. 8 |
---|
1417 | 1417 | | (a) Except as provided in subsections (d) and (e) of this section: 9 |
---|
1418 | 1418 | | (1) A deployer, or a third party contracted by the deployer, 10 |
---|
1419 | 1419 | | that deploys a high-risk artificial intelligence system shall complete an 11 |
---|
1420 | 1420 | | impact assessment for the high -risk artificial intelligence system; and 12 |
---|
1421 | 1421 | | (2) A deployer, or a third party contracted by the deployer, 13 |
---|
1422 | 1422 | | shall complete an impact assessment for a deployed high -risk artificial 14 |
---|
1423 | 1423 | | intelligence system at least annually and within ninety (90) days after any 15 |
---|
1424 | 1424 | | intentional and substantial modification to the high -risk artificial 16 |
---|
1425 | 1425 | | intelligence system is made available. 17 |
---|
1426 | 1426 | | (b) An impact assessment completed under this subsection shall 18 |
---|
1427 | 1427 | | include, at a minimum, and to the extent reasonably known by or available to 19 |
---|
1428 | 1428 | | the deployer: 20 |
---|
1429 | 1429 | | (1) A statement by the deployer disclosing the purpose, intended 21 |
---|
1430 | 1430 | | use cases, deployment context of, and benefits afforded by the high -risk 22 |
---|
1431 | 1431 | | artificial intelligence system; 23 |
---|
1432 | 1432 | | (2) An analysis of whether the deployment of the high -risk 24 |
---|
1433 | 1433 | | artificial intelligence system poses any known or reasonably foreseeable 25 |
---|
1434 | 1434 | | risks of algorithmic discrimination and, if so, the nature of the algorithmic 26 |
---|
1435 | 1435 | | discrimination and the steps that have been taken to mitigate the risks; 27 |
---|
1436 | 1436 | | (3) A description of the categories of data the high -risk 28 |
---|
1437 | 1437 | | artificial intelligence system processes as inputs and the outputs the high -29 |
---|
1438 | 1438 | | risk artificial intelligence system produces; 30 |
---|
1439 | 1439 | | (4) If the deployer used data to customize the high -risk 31 |
---|
1440 | 1440 | | artificial intelligence system, an overview of the categories of data the 32 |
---|
1441 | 1441 | | deployer used to customize the high -risk artificial intelligence system; 33 |
---|
1442 | 1442 | | (5) Any metrics used to evaluate the performance and known 34 |
---|
1443 | 1443 | | limitations of the high -risk artificial intelligence system; 35 |
---|
1444 | 1444 | | (6) A description of any transparency measures taken concerning 36 SB258 |
---|
1445 | 1445 | | |
---|
1446 | 1446 | | 39 02/18/2025 3:16:09 PM ANS146 |
---|
1447 | 1447 | | the high-risk artificial intelligence system, including any measures taken to 1 |
---|
1448 | 1448 | | disclose to a consumer that the high -risk artificial intelligence system is 2 |
---|
1449 | 1449 | | in use when the high -risk artificial intelligence system is in use; and 3 |
---|
1450 | 1450 | | (7) A description of the post -deployment monitoring and user 4 |
---|
1451 | 1451 | | safeguards provided concerning the high -risk artificial intelligence system, 5 |
---|
1452 | 1452 | | including the oversight, use, and learning process established by the 6 |
---|
1453 | 1453 | | deployer to address issues arising rom the deployment of the high -risk 7 |
---|
1454 | 1454 | | artificial intelligence system. 8 |
---|
1455 | 1455 | | (c) In addition to the information required under subsection (b) of 9 |
---|
1456 | 1456 | | this section, an impact assessment completed under this section following an 10 |
---|
1457 | 1457 | | intentional and substantial modification to a high -risk artificial 11 |
---|
1458 | 1458 | | intelligence system must include a statement disclosing the extent to which 12 |
---|
1459 | 1459 | | the high-risk artificial intelligence system was used in a manner that was 13 |
---|
1460 | 1460 | | consistent with, or varied from, the developer’s intended uses of the high -14 |
---|
1461 | 1461 | | risk artificial intelligence system. 15 |
---|
1462 | 1462 | | (d) A single impact assessment may address a comparable set of high -16 |
---|
1463 | 1463 | | risk artificial intelligence systems deployed by a deployer. 17 |
---|
1464 | 1464 | | (e) If a deployer or a third party contracted by the deployer 18 |
---|
1465 | 1465 | | completes an impact assessment for the purpose of complying with another 19 |
---|
1466 | 1466 | | applicable law or regulation, the impact assessment satisfies the 20 |
---|
1467 | 1467 | | requirements established in this section if the impact assessment is 21 |
---|
1468 | 1468 | | reasonably similar in scope and effect to the impact assessment that would 22 |
---|
1469 | 1469 | | otherwise be completed under this section. 23 |
---|
1470 | 1470 | | (f) A deployer shall maintain the most recently completed impact 24 |
---|
1471 | 1471 | | assessment for a high -risk artificial intelligence system as required under 25 |
---|
1472 | 1472 | | this section, all records concerning each impact assessment, and all prior 26 |
---|
1473 | 1473 | | impact assessments, if any, for at least three (3) years following the final 27 |
---|
1474 | 1474 | | deployment of the high -risk artificial intelligence system. 28 |
---|
1475 | 1475 | | (g) On the effective date of this chapter, and at least annually 29 |
---|
1476 | 1476 | | thereafter, a deployer, or a third party contracted by the deployer, shall 30 |
---|
1477 | 1477 | | review the deployment of each high -risk artificial intelligence system 31 |
---|
1478 | 1478 | | deployed by the deployer to ensure that the high -risk artificial intelligence 32 |
---|
1479 | 1479 | | system is not causing algorithmic discrimination. 33 |
---|
1480 | 1480 | | 34 |
---|
1481 | 1481 | | 4-120-604. Consumer rights. 35 |
---|
1482 | 1482 | | Deployers of high-risk artificial intelligence systems shall provide 36 SB258 |
---|
1483 | 1483 | | |
---|
1484 | 1484 | | 40 02/18/2025 3:16:09 PM ANS146 |
---|
1485 | 1485 | | consumers: 1 |
---|
1486 | 1486 | | (1) Notice that the deployer has deployed a high -risk artificial 2 |
---|
1487 | 1487 | | intelligence system to make, or be a substantial factor in making, a decision 3 |
---|
1488 | 1488 | | that produces a legal or similarly significant effect concerning the 4 |
---|
1489 | 1489 | | consumer; 5 |
---|
1490 | 1490 | | (2) A statement disclosing the purpose of the high -risk 6 |
---|
1491 | 1491 | | artificial intelligence system, the nature of the decision that produces a 7 |
---|
1492 | 1492 | | legal or similarly significant effect concerning the consumer, the contact 8 |
---|
1493 | 1493 | | information for the deployer, a description in plain language of the high -9 |
---|
1494 | 1494 | | risk artificial intelligence system, and instructions on how to access the 10 |
---|
1495 | 1495 | | statement required by subdivision (8) of this section; 11 |
---|
1496 | 1496 | | (3) The right to opt out of the processing of personal data 12 |
---|
1497 | 1497 | | concerning the consumer for purposes of profiling in furtherance of a 13 |
---|
1498 | 1498 | | decision that produces a legal or similarly significant effect concerning the 14 |
---|
1499 | 1499 | | consumer; 15 |
---|
1500 | 1500 | | (4) If a high-risk artificial intelligence system makes an 16 |
---|
1501 | 1501 | | adverse decision that produces a legal or similarly significant effect 17 |
---|
1502 | 1502 | | concerning the consumer, a statement disclosing the principal reason or 18 |
---|
1503 | 1503 | | reasons for the adverse decision, including without limitation: 19 |
---|
1504 | 1504 | | (A) The degree to which, and manner in which, the high -20 |
---|
1505 | 1505 | | risk artificial intelligence system contributed to the decision; 21 |
---|
1506 | 1506 | | (B) The type of data that was processed by the high -risk 22 |
---|
1507 | 1507 | | artificial intelligence system in making the decision; and 23 |
---|
1508 | 1508 | | (C) The source or sources of the data described in 24 |
---|
1509 | 1509 | | subdivision (4)(B) of this section; 25 |
---|
1510 | 1510 | | (5) An opportunity to correct any incorrect personal data that 26 |
---|
1511 | 1511 | | the high-risk artificial intelligence system processed in making, or as a 27 |
---|
1512 | 1512 | | substantial factor in making, the decision; 28 |
---|
1513 | 1513 | | (6) An opportunity to appeal the adverse decision concerning the 29 |
---|
1514 | 1514 | | consumer arising from the deployment of the high -risk artificial intelligence 30 |
---|
1515 | 1515 | | system, which allows for human review if technically feasible unless 31 |
---|
1516 | 1516 | | providing the opportunity for appeal is not in the best interests of the 32 |
---|
1517 | 1517 | | consumer, including in instances in which any delay might pose a risk to the 33 |
---|
1518 | 1518 | | life or safety of the consumer; 34 |
---|
1519 | 1519 | | (7) Notices, statements, and documents required by this 35 |
---|
1520 | 1520 | | subchapter directly to the consumer in plain language and in a format that is 36 SB258 |
---|
1521 | 1521 | | |
---|
1522 | 1522 | | 41 02/18/2025 3:16:09 PM ANS146 |
---|
1523 | 1523 | | accessible to consumers with disabilities consistent with the requirements of 1 |
---|
1524 | 1524 | | the Americans with Disabilities Act of 1990, 42 U.S.C. § 12101 et seq., as it 2 |
---|
1525 | 1525 | | existed on January 1, 2025; and 3 |
---|
1526 | 1526 | | (8) A statement on the deployer’s website that is clear, readily 4 |
---|
1527 | 1527 | | available, and periodically updated that summarizes: 5 |
---|
1528 | 1528 | | (A) The types of high -risk artificial intelligence systems 6 |
---|
1529 | 1529 | | that are currently deployed by the deployer; 7 |
---|
1530 | 1530 | | (B) How the deployer manages known or reasonably 8 |
---|
1531 | 1531 | | foreseeable risks of algorithmic discrimination that may arise from the 9 |
---|
1532 | 1532 | | deployment of each high -risk artificial intelligence system described 10 |
---|
1533 | 1533 | | pursuant to this subdivision; and 11 |
---|
1534 | 1534 | | (C) In detail, the nature, source, and extent of the 12 |
---|
1535 | 1535 | | information collected and used by the deployer. 13 |
---|
1536 | 1536 | | 14 |
---|
1537 | 1537 | | Subchapter 7 — Enforcement 15 |
---|
1538 | 1538 | | 16 |
---|
1539 | 1539 | | 4-120-701. Attorney General. 17 |
---|
1540 | 1540 | | The Attorney General has exclusive authority to enforce this chapter. 18 |
---|
1541 | 1541 | | 19 |
---|
1542 | 1542 | | 4-120-702. Procedures. 20 |
---|
1543 | 1543 | | The Attorney General shall post on the Attorney General’s website: 21 |
---|
1544 | 1544 | | (1) Information relating to: 22 |
---|
1545 | 1545 | | (A) The responsibilities of a controller under this 23 |
---|
1546 | 1546 | | chapter; 24 |
---|
1547 | 1547 | | (B) The responsibilities of a processor under this 25 |
---|
1548 | 1548 | | chapter; 26 |
---|
1549 | 1549 | | (C) The responsibilities of a deployer and developer of a 27 |
---|
1550 | 1550 | | high-risk artificial intelligence system; and 28 |
---|
1551 | 1551 | | (D) A consumer’s rights under this chapter; and 29 |
---|
1552 | 1552 | | (2) An online mechanism through which a consumer may submit a 30 |
---|
1553 | 1553 | | complaint under this chapter to the Attorney General. 31 |
---|
1554 | 1554 | | 32 |
---|
1555 | 1555 | | 4-120-703. Remedies. 33 |
---|
1556 | 1556 | | (a)(1) If the Attorney General has reasonable cause to believe that a 34 |
---|
1557 | 1557 | | person has engaged in or is engaging in a violation of this chapter, the 35 |
---|
1558 | 1558 | | Attorney General may issue an Attorney General’s subpoena. 36 SB258 |
---|
1559 | 1559 | | |
---|
1560 | 1560 | | 42 02/18/2025 3:16:09 PM ANS146 |
---|
1561 | 1561 | | (2) The procedures established for the issuance of an Attorney 1 |
---|
1562 | 1562 | | General’s subpoena under § 25 -16-705 apply to the same extent and manner to 2 |
---|
1563 | 1563 | | the issuance of an Attorney General’s subpoena under this section. 3 |
---|
1564 | 1564 | | (b)(1) The Attorney General may request, under an Attorney General’s 4 |
---|
1565 | 1565 | | subpoena issued under subdivision (a)(1) of this section, that a person 5 |
---|
1566 | 1566 | | governed by this chapter disclose to any data protection assessment or 6 |
---|
1567 | 1567 | | artificial intelligence impact assessment that is relevant to an 7 |
---|
1568 | 1568 | | investigation conducted by the Attorney General. 8 |
---|
1569 | 1569 | | (2) The Attorney General may evaluate the data protection 9 |
---|
1570 | 1570 | | assessment for compliance with the requirements under § 4 -120-308 or the 10 |
---|
1571 | 1571 | | artificial intelligence impact assessment for compliance with the 11 |
---|
1572 | 1572 | | requirements under § 4 -120-603. 12 |
---|
1573 | 1573 | | (c) A violation of this chapter is an unfair and deceptive act or 13 |
---|
1574 | 1574 | | practice, as defined by the Deceptive Trade Practices Act, § 4 -88-101 et seq. 14 |
---|
1575 | 1575 | | (d) All remedies, penalties, and authority granted to the Attorney 15 |
---|
1576 | 1576 | | General under the Deceptive Trade Practices Act, § 4 -88-101 et seq., shall be 16 |
---|
1577 | 1577 | | available to the Attorney General for the enforcement of this chapter. 17 |
---|
1578 | 1578 | | 18 |
---|
1579 | 1579 | | 4-120-704. Private right of action. 19 |
---|
1580 | 1580 | | This chapter does not provide a basis for, or being subject to, a 20 |
---|
1581 | 1581 | | private right of action for a violation of this chapter or any other law. 21 |
---|
1582 | 1582 | | 22 |
---|
1583 | 1583 | | Section 2. DO NOT CODIFY. Effective date. 23 |
---|
1584 | 1584 | | (a) Sections 4-120-101 et seq. through sections § 4-120-401 et seq. 24 |
---|
1585 | 1585 | | are effective on January 1, 2026. 25 |
---|
1586 | 1586 | | (b) Section 4-120-601 et seq. is effective on July 1, 2026. 26 |
---|
1587 | 1587 | | (c)(1) To the extent § 4 -120-701 et seq. applies to the enforcement of 27 |
---|
1588 | 1588 | | § 4-120-101 et seq. — § 4-120-401 et seq. , it is effective on April 1, 2026. 28 |
---|
1589 | 1589 | | (2) To the extent § 4 -120-701 et seq. applies to the enforcement 29 |
---|
1590 | 1590 | | of § 4-120-601 et seq., it is effective on October 1, 2026. 30 |
---|
1591 | 1591 | | 31 |
---|
1592 | 1592 | | 32 |
---|
1593 | 1593 | | 33 |
---|
1594 | 1594 | | 34 |
---|
1595 | 1595 | | 35 |
---|
1596 | 1596 | | 36 |
---|