6 | 5 | | A BILL TO BE ENTITLED |
---|
7 | 6 | | AN ACT |
---|
8 | 7 | | To amend Title 10 of the Official Code of Georgia Annotated, relating to commerce and |
---|
9 | 8 | | 1 |
---|
10 | 9 | | trade, so as to enact the "Georgia Consumer Privacy Protection Act"; to protect the privacy2 |
---|
11 | 10 | | of consumer personal data in this state; to provide for definitions; to provide for applicability;3 |
---|
12 | 11 | | to provide for exemptions for certain entities, data, and uses of data; to provide for consumer4 |
---|
13 | 12 | | rights regarding personal data; to provide for a consumer to exercise such rights by5 |
---|
14 | 13 | | submitting a request to a controller; to provide for a controller to promptly respond to such6 |
---|
15 | 14 | | requests; to provide for exemptions; to provide for responsibilities of processors and7 |
---|
16 | 15 | | controllers; to provide for notice and disclosure; to provide for security practices to protect8 |
---|
17 | 16 | | consumer personal data; to allow a controller to offer different goods or services under9 |
---|
18 | 17 | | certain conditions; to provide for limitations; to provide for statutory construction; to provide10 |
---|
19 | 18 | | for enforcement and penalties; to provide an affirmative defense; to prohibit the disclosure11 |
---|
20 | 19 | | of personal data of consumers to local governments unless pursuant to a subpoena or court12 |
---|
21 | 20 | | order; to provide for preemption of local regulation; to provide for related matters; to provide13 |
---|
22 | 21 | | an effective date; to repeal conflicting laws; and for other purposes.14 |
---|
23 | 22 | | BE IT ENACTED BY THE GENERAL ASSEMBLY OF GEORGIA:15 |
---|
24 | 23 | | S. B. 111 |
---|
25 | 24 | | - 1 - 25 LC 59 0079 |
---|
26 | 25 | | SECTION 1. |
---|
27 | 26 | | 16 |
---|
28 | 27 | | Title 10 of the Official Code of Georgia Annotated, relating to commerce and trade, is17 |
---|
29 | 28 | | amended by adding a new article to Chapter 1, relating to selling and other trade practices,18 |
---|
30 | 29 | | to read as follows:19 |
---|
31 | 30 | | "ARTICLE 37 |
---|
32 | 31 | | 20 |
---|
33 | 32 | | 10-1-960.21 |
---|
34 | 33 | | This article shall be known and may be cited as the 'Georgia Consumer Privacy Protection22 |
---|
35 | 34 | | Act.'23 |
---|
36 | 35 | | 10-1-961.24 |
---|
37 | 36 | | As used in this article, the term:25 |
---|
38 | 37 | | (1) 'Affiliate' means a legal entity that controls, is controlled by, or is under common26 |
---|
39 | 38 | | control with another legal entity or shares common branding with another legal entity. As27 |
---|
40 | 39 | | used in this paragraph, the term 'control' or 'controlled' means:28 |
---|
41 | 40 | | (A) Ownership of, or the power to vote, more than 50 percent of the outstanding shares29 |
---|
42 | 41 | | of a class of voting security of an entity;30 |
---|
43 | 42 | | (B) Control in any manner over the election of a majority of the directors or of31 |
---|
44 | 43 | | individuals exercising similar functions relative to an entity; or32 |
---|
45 | 44 | | (C) The power to exercise controlling influence over the management of an entity.33 |
---|
46 | 45 | | (2) 'Authenticate' means to verify using reasonable means that a consumer who is34 |
---|
47 | 46 | | entitled to exercise the rights in Code Section 10-1-963, is the same consumer who is35 |
---|
48 | 47 | | exercising such consumer rights with respect to the personal information at issue.36 |
---|
49 | 48 | | (3)(A) 'Biometric data' means data generated by automatic measurement of an37 |
---|
50 | 49 | | individual's biological characteristics, such as a fingerprint, voiceprint, eye retina or iris,38 |
---|
51 | 50 | | S. B. 111 |
---|
52 | 51 | | - 2 - 25 LC 59 0079 |
---|
53 | 52 | | or other unique biological patterns or characteristics that are used to identify a specific39 |
---|
54 | 53 | | individual.40 |
---|
55 | 54 | | (B) Such term shall not include:41 |
---|
56 | 55 | | (i) A physical or digital photograph, video recording, or audio recording or data42 |
---|
57 | 56 | | generated from a photograph or video or audio recording;43 |
---|
58 | 57 | | (ii) Information captured and converted to a mathematical representation, including44 |
---|
59 | 58 | | a numeric string or similar configuration, that cannot be used to recreate data45 |
---|
60 | 59 | | generated by automatic measurement of an individual's biological patterns or46 |
---|
61 | 60 | | characteristics used to identify the specific individual; or47 |
---|
62 | 61 | | (iii) Information collected, used, or stored for healthcare treatment, payment, or48 |
---|
63 | 62 | | operations under HIPAA.49 |
---|
64 | 63 | | (4) 'Business associate' shall have the same meaning as provided by HIPAA.50 |
---|
65 | 64 | | (5) 'Consent' means a clear affirmative act signifying a consumer's freely given, specific,51 |
---|
66 | 65 | | informed, and unambiguous agreement to process personal information relating to the52 |
---|
67 | 66 | | consumer. Such term may include a written statement, including a statement written by53 |
---|
68 | 67 | | electronic means, or an unambiguous affirmative action.54 |
---|
69 | 68 | | (6) 'Consumer' means an individual who is a resident of this state acting only in a55 |
---|
70 | 69 | | personal context. Such term shall not include an individual acting in a commercial or56 |
---|
71 | 70 | | employment context.57 |
---|
72 | 71 | | (7) 'Controller' means the person that, alone or jointly with others, determines the58 |
---|
73 | 72 | | purpose and means of processing personal information.59 |
---|
74 | 73 | | (8) 'Covered entity' shall have the same meaning as provided by HIPAA.60 |
---|
75 | 74 | | (9) 'Decisions that produce legal or similarly significant effects concerning the consumer'61 |
---|
76 | 75 | | means decisions made by the controller that result in the provision or denial by the62 |
---|
77 | 76 | | controller of financial or lending services, housing, insurance, education enrollment or63 |
---|
78 | 77 | | opportunity, criminal justice, employment opportunities, healthcare services, or access64 |
---|
79 | 78 | | to basic necessities, such as food and water.65 |
---|
80 | 79 | | S. B. 111 |
---|
81 | 80 | | - 3 - 25 LC 59 0079 |
---|
82 | 81 | | (10) 'De-identified data' means data that cannot reasonably be linked to an identified or66 |
---|
83 | 82 | | identifiable individual, or any device linked to such natural person.67 |
---|
84 | 83 | | (11) 'Health record' shall have the same meaning as set forth in paragraph (3) of Code68 |
---|
85 | 84 | | Section 31-33-1. Such term includes the substance of a communication made by an69 |
---|
86 | 85 | | individual to a healthcare facility described in or licensed pursuant to Title 31 in70 |
---|
87 | 86 | | confidence during or in connection with the provision of healthcare services or71 |
---|
88 | 87 | | information otherwise acquired by the healthcare entity about an individual in confidence72 |
---|
89 | 88 | | and in connection with the provision of healthcare services to the individual.73 |
---|
90 | 89 | | (12) 'HIPAA' means the federal Health Insurance Portability and Accountability Act of74 |
---|
91 | 90 | | 1996, as amended, 42 U.S.C. Section 1320d et seq.75 |
---|
92 | 91 | | (13) 'Identified or identifiable individual' means a natural person who can be readily76 |
---|
93 | 92 | | identified, whether directly or indirectly.77 |
---|
94 | 93 | | (14) 'Institution of higher education' means a public or private college or university in78 |
---|
95 | 94 | | this state.79 |
---|
96 | 95 | | (15) 'Known child' means an individual who the controller has actual knowledge is under80 |
---|
97 | 96 | | 13 years of age.81 |
---|
98 | 97 | | (16) 'NIST' means the National Institute of Standards and Technology privacy82 |
---|
99 | 98 | | framework entitled 'A Tool for Improving Privacy through Enterprise Risk Management83 |
---|
100 | 99 | | Version 1.0' or any subsequent version thereof.84 |
---|
101 | 100 | | (17) 'Nonprofit organization' means an organization exempt from taxation under the85 |
---|
102 | 101 | | Internal Revenue Code, codified in 26 U.S.C. Sections 501-530.86 |
---|
103 | 102 | | (18) 'Person' means any individual or entity.87 |
---|
104 | 103 | | (19) 'Personal information' means information that is linked or reasonably linkable to an88 |
---|
105 | 104 | | identified or identifiable individual. Such term shall not include information that is89 |
---|
106 | 105 | | publicly available or de-identified.90 |
---|
107 | 106 | | (20)(A) 'Precise geolocation data' means information derived from technology,91 |
---|
108 | 107 | | including, but not limited to, global positioning system level latitude and longitude92 |
---|
109 | 108 | | S. B. 111 |
---|
110 | 109 | | - 4 - 25 LC 59 0079 |
---|
111 | 110 | | coordinates or other mechanisms, that directly identifies the specific location of a93 |
---|
112 | 111 | | natural person with precision and accuracy within a radius of 1,750 feet.94 |
---|
113 | 112 | | (B) Such term shall not include:95 |
---|
114 | 113 | | (i) The content of communications; or96 |
---|
115 | 114 | | (ii) Data generated by or connected to advanced utility metering infrastructure97 |
---|
116 | 115 | | systems or equipment for use by a utility.98 |
---|
117 | 116 | | (21) 'Process' or 'processing' means an operation or set of operations performed, whether99 |
---|
118 | 117 | | by manual or automated means, on personal information or on sets of personal100 |
---|
119 | 118 | | information, such as the collection, use, storage, disclosure, analysis, deletion, or101 |
---|
120 | 119 | | modification of personal information.102 |
---|
121 | 120 | | (22) 'Processor' means a person that processes personal information on behalf of a103 |
---|
122 | 121 | | controller.104 |
---|
123 | 122 | | (23) 'Profiling' means a form of automated processing performed on personal105 |
---|
124 | 123 | | information solely to evaluate, analyze, or predict personal aspects related to an identified106 |
---|
125 | 124 | | or identifiable individual's economic situation, health, personal preferences, interests,107 |
---|
126 | 125 | | reliability, behavior, location, or movements.108 |
---|
127 | 126 | | (24) 'Protected health information' shall have the same meaning as provided by HIPAA.109 |
---|
128 | 127 | | (25) 'Pseudonymous data' means personal information that cannot be attributed to a110 |
---|
129 | 128 | | specific individual without the use of additional information, so long as the additional111 |
---|
130 | 129 | | information is kept separately and is subject to appropriate technical and organizational112 |
---|
131 | 130 | | measures to ensure that the personal information is not attributed to an identified or113 |
---|
132 | 131 | | identifiable individual.114 |
---|
133 | 132 | | (26) 'Publicly available information' means information that is lawfully made available115 |
---|
134 | 133 | | through federal, state, or local government records, or information that a business has a116 |
---|
135 | 134 | | reasonable basis to believe is lawfully made available to the general public through117 |
---|
136 | 135 | | widely distributed media, by the consumer, or by a person to which the consumer has118 |
---|
137 | 136 | | S. B. 111 |
---|
138 | 137 | | - 5 - 25 LC 59 0079 |
---|
139 | 138 | | disclosed the information, unless the consumer has restricted the information to a specific119 |
---|
140 | 139 | | audience.120 |
---|
141 | 140 | | (27)(A) 'Sale of personal information' or 'sell personal information' means the121 |
---|
142 | 141 | | exchange of personal information for monetary or other valuable consideration by the122 |
---|
143 | 142 | | controller to a third party.123 |
---|
144 | 143 | | (B) Such term shall not include:124 |
---|
145 | 144 | | (i) The disclosure of personal information to a processor that processes the personal125 |
---|
146 | 145 | | information on behalf of the controller;126 |
---|
147 | 146 | | (ii) The disclosure of personal information to a third party for purposes of providing127 |
---|
148 | 147 | | a product or service requested by the consumer;128 |
---|
149 | 148 | | (iii) The disclosure or transfer of personal information to an affiliate of the controller;129 |
---|
150 | 149 | | (iv) The disclosure of information that the consumer:130 |
---|
151 | 150 | | (I) Intentionally made available to the general public via a channel of mass media;131 |
---|
152 | 151 | | and132 |
---|
153 | 152 | | (II) Did not restrict to a specific audience; or133 |
---|
154 | 153 | | (v) The disclosure or transfer of personal information to a third party as an asset that134 |
---|
155 | 154 | | is part of a merger, acquisition, bankruptcy, or other transaction in which the third135 |
---|
156 | 155 | | party assumes control of all or part of the controller's assets.136 |
---|
157 | 156 | | (28) 'Sensitive data' means a category of personal information that includes:137 |
---|
158 | 157 | | (A) Personal information revealing racial or ethnic origin, religious belief, mental or138 |
---|
159 | 158 | | physical health diagnosis, sexual orientation, or citizenship or immigration status;139 |
---|
160 | 159 | | (B) The processing of genetic data or biometric data for the purpose of uniquely140 |
---|
161 | 160 | | identifying an individual;141 |
---|
162 | 161 | | (C) The personal information collected from a known child; or142 |
---|
163 | 162 | | (D) Precise geolocation data.143 |
---|
164 | 163 | | (29) 'State agency' means an agency, institution, board, bureau, commission, council, or144 |
---|
165 | 164 | | instrumentality of the executive branch of state government of this state.145 |
---|
166 | 165 | | S. B. 111 |
---|
167 | 166 | | - 6 - 25 LC 59 0079 |
---|
168 | 167 | | (30)(A) 'Targeted advertising' means displaying to a consumer an advertisement that146 |
---|
169 | 168 | | is selected based on personal information obtained from such consumer's activities over147 |
---|
170 | 169 | | time and across nonaffiliated websites or online applications to predict the consumer's148 |
---|
171 | 170 | | preferences or interests.149 |
---|
172 | 171 | | (B) Such term shall not include:150 |
---|
173 | 172 | | (i) Advertisements based on activities within a controller's own websites or online151 |
---|
174 | 173 | | applications;152 |
---|
175 | 174 | | (ii) Advertisements based on the context of a consumer's current search query, visit153 |
---|
176 | 175 | | to a website, or online application;154 |
---|
177 | 176 | | (iii) Advertisements directed to a consumer in response to the consumer's request for155 |
---|
178 | 177 | | information or feedback; or156 |
---|
179 | 178 | | (iv) Personal information processed solely for measuring or reporting advertising157 |
---|
180 | 179 | | performance, reach, or frequency.158 |
---|
181 | 180 | | (31) 'Third party' means a person other than the consumer, controller, processor, or an159 |
---|
182 | 181 | | affiliate of the controller or processor.160 |
---|
183 | 182 | | (32) 'Trade secret' shall have the same meaning as set forth in Code Section 16-8-13.161 |
---|
184 | 183 | | 10-1-962.162 |
---|
185 | 184 | | (a) This article shall apply to a person that conducts business in this state by producing163 |
---|
186 | 185 | | products or services targeted to consumers of this state that exceeds $25 million in revenue164 |
---|
187 | 186 | | and that:165 |
---|
188 | 187 | | (1) Controls or processes personal information of at least 25,000 consumers and derives166 |
---|
189 | 188 | | more than 50 percent of gross revenue from the sale of personal information; or167 |
---|
190 | 189 | | (2) During a calendar year, controls or processes personal information of at least 175,000168 |
---|
191 | 190 | | consumers.169 |
---|
192 | 191 | | (b) This article shall not apply to:170 |
---|
193 | 192 | | (1) A person that is:171 |
---|
194 | 193 | | S. B. 111 |
---|
195 | 194 | | - 7 - 25 LC 59 0079 |
---|
196 | 195 | | (A) A financial institution or an affiliate of a financial institution subject to Title V of172 |
---|
197 | 196 | | the federal Gramm-Leach-Bliley Act, as amended, 15 U.S.C. Section 6801 et seq.;173 |
---|
198 | 197 | | (B) Licensed in this state under Title 33 as an insurance company and transacts174 |
---|
199 | 198 | | insurance business;175 |
---|
200 | 199 | | (C) Licensed in this state under Title 33 as an insurance producer;176 |
---|
201 | 200 | | (D) A covered entity or business associate governed by the privacy, security, and177 |
---|
202 | 201 | | breach notification rules issued by the United States Department of Health and Human178 |
---|
203 | 202 | | Services, 45 C.F.R. Parts 160 and 164 established pursuant to HIPAA, and the federal179 |
---|
204 | 203 | | Health Information Technology for Economic and Clinical Health Act (P.L. 111-5);180 |
---|
205 | 204 | | (E) An air carrier regulated by the secretary of transportation under 49 U.S.C. Section181 |
---|
206 | 205 | | 41712 and exempt from state regulations under 49 U.S.C. Section 41713(b)(1); or182 |
---|
207 | 206 | | (F) An entity subject to 42 U.S.C. Section 290dd-2;183 |
---|
208 | 207 | | (2) Data or personal information that is:184 |
---|
209 | 208 | | (A) Subject to Title V of the federal Gramm-Leach-Bliley Act, as amended, 15 U.S.C.185 |
---|
210 | 209 | | Section 6801 et seq.;186 |
---|
211 | 210 | | (B) Protected health information under HIPAA;187 |
---|
212 | 211 | | (C) Considered a health record for purposes of Title 31;188 |
---|
213 | 212 | | (D) Considered patient identifying information for purposes of 42 U.S.C.189 |
---|
214 | 213 | | Section 290dd-2;190 |
---|
215 | 214 | | (E) Processed for purposes of:191 |
---|
216 | 215 | | (i) Research conducted in accordance with the federal policy for the protection of192 |
---|
217 | 216 | | human subjects under 45 C.F.R. Part 46;193 |
---|
218 | 217 | | (ii) Human subjects research conducted in accordance with good clinical practice194 |
---|
219 | 218 | | guidelines issued by the International Council for Harmonization of Technical195 |
---|
220 | 219 | | Requirements for Pharmaceuticals for Human Use; or196 |
---|
221 | 220 | | (iii) Research conducted in accordance with the protection of human subjects under197 |
---|
222 | 221 | | 21 C.F.R. Parts 6, 50, and 56;198 |
---|
223 | 222 | | S. B. 111 |
---|
224 | 223 | | - 8 - 25 LC 59 0079 |
---|
225 | 224 | | (F) Created for purposes of the federal Health Care Quality Improvement Act of 1986,199 |
---|
226 | 225 | | as amended, 42 U.S.C. Section 11101 et seq.;200 |
---|
227 | 226 | | (G) Considered patient safety work product for purposes of the federal Patient Safety201 |
---|
228 | 227 | | and Quality Improvement Act, as amended, 42 U.S.C. Section 299b-21 et seq.;202 |
---|
229 | 228 | | (H) Derived from the healthcare related information listed in this subsection that is203 |
---|
230 | 229 | | de-identified in accordance with the requirements for de-identification pursuant to204 |
---|
231 | 230 | | HIPAA;205 |
---|
232 | 231 | | (I) Included in a limited data set as described in 45 C.F.R. 164.514(e), to the extent that206 |
---|
233 | 232 | | the information is used, disclosed, and maintained in the manner specified in207 |
---|
234 | 233 | | 45 C.F.R. 164.514(e);208 |
---|
235 | 234 | | (J) Originated from, and intermingled to be indistinguishable with, or information209 |
---|
236 | 235 | | treated in the same manner as, information exempt under this subsection that is210 |
---|
237 | 236 | | maintained by a covered entity or business associate as defined by HIPAA or a program211 |
---|
238 | 237 | | or a qualified service organization as defined by 42 U.S.C. Section 290dd-2;212 |
---|
239 | 238 | | (K) Used only for public health activities and purposes as authorized by HIPAA;213 |
---|
240 | 239 | | (L) Collected, maintained, disclosed, sold, communicated, or used, bearing upon a214 |
---|
241 | 240 | | consumer's credit worthiness, credit standing, credit capacity, character, general215 |
---|
242 | 241 | | reputation, personal characteristics, or mode of living, by a consumer reporting agency216 |
---|
243 | 242 | | or furnisher that provides information for use in a consumer report, and by a user of a217 |
---|
244 | 243 | | consumer report, but only to the extent that such activity is regulated by and authorized218 |
---|
245 | 244 | | under the federal Fair Credit Reporting Act, as amended, 15 U.S.C. Section 1681 et219 |
---|
246 | 245 | | seq.;220 |
---|
247 | 246 | | (M) Collected, processed, or disclosed in compliance with the federal Driver's Privacy221 |
---|
248 | 247 | | Protection Act of 1994, as amended, 18 U.S.C. Section 2721 et seq.;222 |
---|
249 | 248 | | (N) Regulated by the federal Family Educational Rights and Privacy Act (FERPA), as223 |
---|
250 | 249 | | amended, 20 U.S.C. Section 1232g et seq.;224 |
---|
251 | 250 | | S. B. 111 |
---|
252 | 251 | | - 9 - 25 LC 59 0079 |
---|
253 | 252 | | (O) Collected, processed, or disclosed in compliance with the federal Farm Credit Act,225 |
---|
254 | 253 | | as amended, 12 U.S.C. Section 2001 et seq.; or226 |
---|
255 | 254 | | (P) Maintained or used for purposes of compliance with the regulation of listed227 |
---|
256 | 255 | | chemicals under the federal Controlled Substances Act, as amended, 21 U.S.C.228 |
---|
257 | 256 | | Section 830;229 |
---|
258 | 257 | | (3) Nonprofit organizations that do not sell data;230 |
---|
259 | 258 | | (4) Any state agency, the judicial branch, the legislative branch, or any local government231 |
---|
260 | 259 | | of this state;232 |
---|
261 | 260 | | (5) Any institution of higher education that does not engage in the sale of personal233 |
---|
262 | 261 | | information;234 |
---|
263 | 262 | | (6) Any electric supplier as defined in Code Section 46-3-3 that does not engage in the235 |
---|
264 | 263 | | sale of personal information; or236 |
---|
265 | 264 | | (7) Data processed or maintained:237 |
---|
266 | 265 | | (A) In the course of an individual applying to, being employed by, or acting as an agent238 |
---|
267 | 266 | | or independent contractor of a controller, processor, or third party, to the extent that the239 |
---|
268 | 267 | | data is collected and used within the context of that role;240 |
---|
269 | 268 | | (B) As the emergency contact information of an individual employed by or acting as241 |
---|
270 | 269 | | an agent or independent contractor of a controller, processor, or third party for use as242 |
---|
271 | 270 | | emergency contact purposes with the consent of such individual; or243 |
---|
272 | 271 | | (C) As necessary to retain to administer benefits for an individual who qualifies for244 |
---|
273 | 272 | | benefits as part of the benefits provided to an individual employed by or acting as an245 |
---|
274 | 273 | | agent or independent contractor of a controller, processor, or third party.246 |
---|
275 | 274 | | (c) Controllers and processors that comply with the verifiable parental consent247 |
---|
276 | 275 | | requirements of the federal Children's Online Privacy Protection Act (COPPA), as248 |
---|
277 | 276 | | amended, 15 U.S.C. Section 6501 et seq., shall be deemed compliant with an obligation to249 |
---|
278 | 277 | | obtain parental consent under this article.250 |
---|
279 | 278 | | S. B. 111 |
---|
280 | 279 | | - 10 - 25 LC 59 0079 |
---|
281 | 280 | | (d) Nothing in this article shall require a controller, processor, third party, or consumer to251 |
---|
282 | 281 | | disclose trade secrets.252 |
---|
283 | 282 | | 10-1-963.253 |
---|
284 | 283 | | (a)(1) A consumer may invoke the consumer rights authorized pursuant to paragraph (2)254 |
---|
285 | 284 | | of this subsection at any time by submitting a request to a controller specifying the255 |
---|
286 | 285 | | consumer rights the consumer wishes to invoke. A known child's parent or legal guardian256 |
---|
287 | 286 | | may invoke the consumer rights authorized pursuant to paragraph (2) of this subsection257 |
---|
288 | 287 | | on behalf of the such known child regarding processing personal information belonging258 |
---|
289 | 288 | | to the known child.259 |
---|
290 | 289 | | (2) A controller shall comply with an authenticated consumer request to exercise the260 |
---|
291 | 290 | | right to:261 |
---|
292 | 291 | | (A) Confirm whether a controller is processing the consumer's personal information262 |
---|
293 | 292 | | and to access such personal information;263 |
---|
294 | 293 | | (B) Correct inaccuracies in the consumer's personal information, taking into account264 |
---|
295 | 294 | | the nature of the personal information and the purposes of the processing of such265 |
---|
296 | 295 | | consumer's personal information;266 |
---|
297 | 296 | | (C) Delete personal information provided by or obtained about the consumer. A267 |
---|
298 | 297 | | controller shall not be required to delete information that it maintains or uses as268 |
---|
299 | 298 | | aggregate or de-identified data; provided, that such data in the possession of the269 |
---|
300 | 299 | | controller is not linked to a specific consumer. A controller that obtained personal270 |
---|
301 | 300 | | information about a consumer from a source other than the consumer shall be in271 |
---|
302 | 301 | | compliance with a consumer's request to delete such personal information by:272 |
---|
303 | 302 | | (i) Retaining a record of the deletion request and the minimum information necessary273 |
---|
304 | 303 | | for the purpose of ensuring that the consumer's personal information remains deleted274 |
---|
305 | 304 | | from the controller's records and by not using such retained personal information for275 |
---|
306 | 305 | | any purpose prohibited under this article; or276 |
---|
307 | 306 | | S. B. 111 |
---|
308 | 307 | | - 11 - 25 LC 59 0079 |
---|
309 | 308 | | (ii) Opting the consumer out of the processing of such personal information for any277 |
---|
310 | 309 | | purposes other than those exempted under this article.278 |
---|
311 | 310 | | (D) Obtain a copy of the consumer's personal information that the consumer previously279 |
---|
312 | 311 | | provided to the controller in a portable and, to the extent technically feasible, readily280 |
---|
313 | 312 | | usable format that allows the consumer to transmit such personal information to another281 |
---|
314 | 313 | | controller without hindrance, where the processing is carried out by automated means;282 |
---|
315 | 314 | | or283 |
---|
316 | 315 | | (E) Opt out of a controller's processing of personal information for purposes of:284 |
---|
317 | 316 | | (i) Engaging in the sale of personal information about the consumer;285 |
---|
318 | 317 | | (ii) Targeted advertising; or286 |
---|
319 | 318 | | (iii) Profiling in furtherance of decisions that produce legal or similarly significant287 |
---|
320 | 319 | | effects concerning the consumer.288 |
---|
321 | 320 | | (b) Except as otherwise provided in this article, a controller shall comply with an289 |
---|
322 | 321 | | authenticated request by a consumer to exercise the consumer rights authorized pursuant290 |
---|
323 | 322 | | to paragraph (2) of subsection (a) of this Code section as follows:291 |
---|
324 | 323 | | (1) A controller shall respond to the consumer without undue delay, but in all cases292 |
---|
325 | 324 | | within 45 days of receipt of a request submitted pursuant to subsection (a) of this Code293 |
---|
326 | 325 | | section. The response period may be extended once by 45 additional days when294 |
---|
327 | 326 | | reasonably necessary, taking into account the complexity and number of the consumer's295 |
---|
328 | 327 | | requests, so long as the controller informs the consumer of the extension within the initial296 |
---|
329 | 328 | | 45 day response period, together with the reason for the extension;297 |
---|
330 | 329 | | (2) If a controller declines to take action regarding the consumer's request, then the298 |
---|
331 | 330 | | controller shall inform the consumer without undue delay, but in all cases within 45 days299 |
---|
332 | 331 | | of receipt of the request, of the justification for declining to take action and instructions300 |
---|
333 | 332 | | for how to appeal the decision pursuant to subsection (c) of this Code section;301 |
---|
334 | 333 | | (3) Information provided in response to a consumer request shall be provided by a302 |
---|
335 | 334 | | controller free of charge, up to twice annually per consumer. If requests from a consumer303 |
---|
336 | 335 | | S. B. 111 |
---|
337 | 336 | | - 12 - 25 LC 59 0079 |
---|
338 | 337 | | are manifestly unfounded, technically infeasible, excessive, or repetitive, then the304 |
---|
339 | 338 | | controller may charge the consumer a reasonable fee to cover the administrative costs of305 |
---|
340 | 339 | | complying with the request or decline to act on the request. The controller bears the306 |
---|
341 | 340 | | burden of demonstrating the manifestly unfounded, technically infeasible, excessive, or307 |
---|
342 | 341 | | repetitive nature of the request; and308 |
---|
343 | 342 | | (4) If a controller is unable to authenticate the request using commercially reasonable309 |
---|
344 | 343 | | efforts, then the controller shall not be required to comply with a request to initiate an310 |
---|
345 | 344 | | action under subsection (a) of this Code section and may request that the consumer311 |
---|
346 | 345 | | provide additional information reasonably necessary to authenticate the consumer and the312 |
---|
347 | 346 | | consumer's request.313 |
---|
348 | 347 | | (c)(1) A controller shall establish a process for a consumer to appeal the controller's314 |
---|
349 | 348 | | refusal to take action on a request within a reasonable period of time after the consumer's315 |
---|
350 | 349 | | receipt of the decision pursuant to paragraph (2) of subsection (b) of this Code section. 316 |
---|
351 | 350 | | The appeal process shall be:317 |
---|
352 | 351 | | (A) Made available to the consumer in a conspicuous manner;318 |
---|
353 | 352 | | (B) Available at no cost to the consumer; and319 |
---|
354 | 353 | | (C) Similar to the process for submitting requests to initiate action pursuant to320 |
---|
355 | 354 | | subsection (a) of this Code section.321 |
---|
356 | 355 | | (2) Within 60 days of receipt of an appeal, a controller shall inform the consumer in322 |
---|
357 | 356 | | writing of action taken or not taken in response to the appeal, including a written323 |
---|
358 | 357 | | explanation of the reasons for the decision. If the appeal is denied, the controller shall324 |
---|
359 | 358 | | then also provide the consumer with an online mechanism, if available, or other method325 |
---|
360 | 359 | | through which the consumer may contact the Attorney General to submit a complaint.326 |
---|
361 | 360 | | 10-1-964.327 |
---|
362 | 361 | | (a) A controller shall:328 |
---|
363 | 362 | | S. B. 111 |
---|
364 | 363 | | - 13 - 25 LC 59 0079 |
---|
365 | 364 | | (1) Limit the collection of personal information to what is adequate, relevant, and329 |
---|
366 | 365 | | reasonably necessary in relation to the purposes for which the data is processed, as330 |
---|
367 | 366 | | disclosed to the consumer;331 |
---|
368 | 367 | | (2) Except as otherwise provided in this article, not process personal information for332 |
---|
369 | 368 | | purposes that are beyond what is reasonably necessary to and compatible with the333 |
---|
370 | 369 | | disclosed purposes for which the personal information is processed, as disclosed to the334 |
---|
371 | 370 | | consumer, unless the controller obtains the consumer's consent;335 |
---|
372 | 371 | | (3) Establish, implement, and maintain reasonable administrative, technical, and physical336 |
---|
373 | 372 | | data security practices, as described in Code Section 10-1-973, to protect the337 |
---|
374 | 373 | | confidentiality, integrity, and accessibility of personal information. The data security338 |
---|
375 | 374 | | practices shall be appropriate to the volume and nature of the personal information at339 |
---|
376 | 375 | | issue;340 |
---|
377 | 376 | | (4) Not be required to delete information that it maintains or uses as aggregate or341 |
---|
378 | 377 | | de-identified data, provided that such data in the possession of the business is not linked342 |
---|
379 | 378 | | to a specific consumer;343 |
---|
380 | 379 | | (5) Not process personal information in violation of state and federal laws that prohibit344 |
---|
381 | 380 | | unlawful discrimination against consumers. A controller shall not discriminate against345 |
---|
382 | 381 | | a consumer for exercising the consumer rights contained in this article, including denying346 |
---|
383 | 382 | | goods or services, charging different prices or rates for goods or services, or providing347 |
---|
384 | 383 | | a different level of quality of goods and services to the consumer. However, this348 |
---|
385 | 384 | | paragraph shall not require a controller to provide a product or service that requires the349 |
---|
386 | 385 | | personal information of a consumer that the controller does not collect or maintain, or350 |
---|
387 | 386 | | prohibit a controller from offering a different price, rate, level, quality, or selection of351 |
---|
388 | 387 | | goods or services to a consumer, including offering goods or services for no fee, if the352 |
---|
389 | 388 | | consumer has exercised the right to opt out pursuant to subparagraph (E) of paragraph (2)353 |
---|
390 | 389 | | of subsection (a) of Code Section 10-1-963 or the offer is related to a consumer's354 |
---|
391 | 390 | | S. B. 111 |
---|
392 | 391 | | - 14 - 25 LC 59 0079 |
---|
393 | 392 | | voluntary participation in a bona fide loyalty, rewards, premium features, discounts, or355 |
---|
394 | 393 | | club card program; and356 |
---|
395 | 394 | | (6) Not process sensitive data concerning a consumer without obtaining the consumer's357 |
---|
396 | 395 | | consent, or, in the case of the processing of sensitive data concerning a known child,358 |
---|
397 | 396 | | without processing the data in accordance with the federal Children's Online Privacy359 |
---|
398 | 397 | | Protection Act, as amended, 15 U.S.C. Section 6501 et seq., and its implementing360 |
---|
399 | 398 | | regulations.361 |
---|
400 | 399 | | (b) A provision of a contract or agreement that purports to waive or limit the consumer362 |
---|
401 | 400 | | rights described in Code Section 10-1-963 is contrary to public policy and is void and363 |
---|
402 | 401 | | unenforceable.364 |
---|
403 | 402 | | (c) A controller shall provide a reasonably accessible, clear, and meaningful privacy notice365 |
---|
404 | 403 | | that includes:366 |
---|
405 | 404 | | (1) The categories of personal information processed by the controller;367 |
---|
406 | 405 | | (2) The purpose for processing personal information;368 |
---|
407 | 406 | | (3) How consumers may exercise their consumer rights pursuant to Code369 |
---|
408 | 407 | | Section 10-1-963, including how a consumer may appeal a controller's decision with370 |
---|
409 | 408 | | regard to the consumer's request;371 |
---|
410 | 409 | | (4) The categories of personal information that the controller sells to third parties, if any;372 |
---|
411 | 410 | | and373 |
---|
412 | 411 | | (5) The categories of third parties, if any, with whom the controller engages in the sale374 |
---|
413 | 412 | | of personal information.375 |
---|
414 | 413 | | (d) If a controller engages in the sale of personal information to third parties or processes376 |
---|
415 | 414 | | personal information for targeted advertising, then the controller shall clearly and377 |
---|
416 | 415 | | conspicuously disclose the processing, as well as the manner in which a consumer may378 |
---|
417 | 416 | | exercise the right to opt out of the processing.379 |
---|
418 | 417 | | S. B. 111 |
---|
419 | 418 | | - 15 - 25 LC 59 0079 |
---|
420 | 419 | | (e)(1) A controller shall provide, and shall describe in a privacy notice, one or more380 |
---|
421 | 420 | | secure and reliable means for a consumer to submit a request to exercise the consumer381 |
---|
422 | 421 | | rights described in Code Section 10-1-963. Such means shall take into account the:382 |
---|
423 | 422 | | (A) Ways in which a consumer normally interacts with the controller;383 |
---|
424 | 423 | | (B) Need for secure and reliable communication of such requests; and384 |
---|
425 | 424 | | (C) Ability of a controller to authenticate the identity of the consumer making the385 |
---|
426 | 425 | | request.386 |
---|
427 | 426 | | (2) A controller shall not require a consumer to create a new account in order to exercise387 |
---|
428 | 427 | | the consumer rights described in Code Section 10-1-963, but may require a consumer to388 |
---|
429 | 428 | | use an existing account.389 |
---|
430 | 429 | | 10-1-965.390 |
---|
431 | 430 | | (a) A processor shall adhere to the instructions of a controller and shall assist the controller391 |
---|
432 | 431 | | in meeting its obligations under this article. The assistance provided by the processor shall392 |
---|
433 | 432 | | include:393 |
---|
434 | 433 | | (1) Taking into account the nature of processing and the information available to the394 |
---|
435 | 434 | | processor, by appropriate technical and organizational measures, insofar as reasonably395 |
---|
436 | 435 | | practicable, to fulfill the controller's obligation to respond to consumer rights requests396 |
---|
437 | 436 | | pursuant to Code Section 10-1-963; and397 |
---|
438 | 437 | | (2) Providing necessary information to enable the controller to conduct and document398 |
---|
439 | 438 | | data protection assessments pursuant to Code Section 10-1-966.399 |
---|
440 | 439 | | (b) A contract between a controller and a processor governs the processor's data processing400 |
---|
441 | 440 | | procedures with respect to processing performed on behalf of the controller. The contract401 |
---|
442 | 441 | | shall be binding and shall clearly set forth instructions for processing data, the nature and402 |
---|
443 | 442 | | purpose of processing, the type of data subject to processing, the duration of processing,403 |
---|
444 | 443 | | and the rights and obligations of both parties. The contract shall also include requirements404 |
---|
445 | 444 | | that the processor shall:405 |
---|
446 | 445 | | S. B. 111 |
---|
447 | 446 | | - 16 - 25 LC 59 0079 |
---|
448 | 447 | | (1) Ensure that each person processing personal information is subject to a duty of406 |
---|
449 | 448 | | confidentiality with respect to the data;407 |
---|
450 | 449 | | (2) At the controller's direction, delete or return all personal information to the controller408 |
---|
451 | 450 | | as requested at the end of the provision of services, unless retention of the personal409 |
---|
452 | 451 | | information is required by law;410 |
---|
453 | 452 | | (3) Upon the reasonable request of the controller, make available to the controller all411 |
---|
454 | 453 | | information in its possession necessary to demonstrate the processor's compliance with412 |
---|
455 | 454 | | the obligations in this article;413 |
---|
456 | 455 | | (4) Allow, and cooperate with, reasonable assessments by the controller or the414 |
---|
457 | 456 | | controller's designated assessor; alternatively, the processor may arrange for a qualified415 |
---|
458 | 457 | | and independent assessor to conduct an assessment of the processor's policies and416 |
---|
459 | 458 | | technical and organizational measures in support of the obligations under this article417 |
---|
460 | 459 | | using an appropriate and accepted control standard or framework and assessment418 |
---|
461 | 460 | | procedure for the assessments. The processor shall provide a report of each assessment419 |
---|
462 | 461 | | to the controller upon request; and420 |
---|
463 | 462 | | (5) Engage a subcontractor pursuant to a written contract in that requires the421 |
---|
464 | 463 | | subcontractor to meet the obligations of the processor with respect to the personal422 |
---|
465 | 464 | | information.423 |
---|
466 | 465 | | (c) Nothing in this Code section shall relieve a controller or a processor from the liabilities424 |
---|
467 | 466 | | imposed on it by virtue of its role in the processing relationship as described in425 |
---|
468 | 467 | | subsection (b) of this Code section.426 |
---|
469 | 468 | | (d) Determining whether a person is acting as a controller or processor with respect to a427 |
---|
470 | 469 | | specific processing of data is a fact based determination that depends upon the context in428 |
---|
471 | 470 | | which personal information is to be processed. A processor that continues to adhere to a429 |
---|
472 | 471 | | controller's instructions with respect to a specific processing of personal information430 |
---|
473 | 472 | | remains a processor.431 |
---|
474 | 473 | | S. B. 111 |
---|
475 | 474 | | - 17 - 25 LC 59 0079 |
---|
476 | 475 | | 10-1-966.432 |
---|
477 | 476 | | (a) A controller shall conduct and document a data protection assessment of each of the433 |
---|
478 | 477 | | following processing activities involving personal information:434 |
---|
479 | 478 | | (1) The processing of personal information for purposes of targeted advertising;435 |
---|
480 | 479 | | (2) The sale of personal information;436 |
---|
481 | 480 | | (3) The processing of personal information for purposes of profiling, where the profiling437 |
---|
482 | 481 | | presents a reasonably foreseeable risk of:438 |
---|
483 | 482 | | (A) Unfair or deceptive treatment of, or unlawful disparate impact on, consumers;439 |
---|
484 | 483 | | (B) Financial, physical, or reputational injury to consumers;440 |
---|
485 | 484 | | (C) A physical or other intrusion upon the solitude or seclusion, or the private affairs441 |
---|
486 | 485 | | or concerns, of consumers, where the intrusion would be offensive to a reasonable442 |
---|
487 | 486 | | person; or443 |
---|
488 | 487 | | (D) Other substantial injury to consumers;444 |
---|
489 | 488 | | (4) The processing of sensitive data; and445 |
---|
490 | 489 | | (5) Processing activities involving personal information that present a heightened risk446 |
---|
491 | 490 | | of harm to consumers.447 |
---|
492 | 491 | | (b) Data protection assessments conducted pursuant to subsection (a) of this Code section448 |
---|
493 | 492 | | shall identify and weigh the benefits that may flow, directly and indirectly, from the449 |
---|
494 | 493 | | processing to the controller, the consumer, other stakeholders, and the public against the450 |
---|
495 | 494 | | potential risks to the rights of the consumer associated with the processing, as mitigated by451 |
---|
496 | 495 | | safeguards that can be employed by the controller to reduce the risks. The use of452 |
---|
497 | 496 | | de-identified data and the reasonable expectations of consumers, as well as the context of453 |
---|
498 | 497 | | the processing and the relationship between the controller and the consumer whose454 |
---|
499 | 498 | | personal information will be processed, shall be factored into this assessment by the455 |
---|
500 | 499 | | controller.456 |
---|
501 | 500 | | (c) The Attorney General may request pursuant to a civil investigative demand that a457 |
---|
502 | 501 | | controller disclose a data protection assessment that is relevant to an investigation458 |
---|
503 | 502 | | S. B. 111 |
---|
504 | 503 | | - 18 - 25 LC 59 0079 |
---|
505 | 504 | | conducted by the Attorney General, and the controller shall make the data protection459 |
---|
506 | 505 | | assessment available to the Attorney General. The Attorney General shall evaluate the data460 |
---|
507 | 506 | | protection assessment for compliance with the responsibilities set forth in Code461 |
---|
508 | 507 | | Section 10-1-964. The disclosure of a data protection assessment pursuant to a request462 |
---|
509 | 508 | | from the Attorney General shall not constitute a waiver of attorney-client privilege or work463 |
---|
510 | 509 | | product protection with respect to the assessment and information contained in the464 |
---|
511 | 510 | | assessment. Such data protection assessments shall be confidential and shall not be open465 |
---|
512 | 511 | | to public inspection and copying under Article 4 of Chapter 18 of Title 50, relating to open466 |
---|
513 | 512 | | records.467 |
---|
514 | 513 | | (d) A single data protection assessment may address a comparable set of processing468 |
---|
515 | 514 | | operations that include similar activities.469 |
---|
516 | 515 | | (e) A data protection assessment conducted by a controller for the purpose of compliance470 |
---|
517 | 516 | | with other laws, rules, or regulations may comply with this Code section if such data471 |
---|
518 | 517 | | protection assessment have a reasonably comparable scope and effect.472 |
---|
519 | 518 | | (f) The data protection assessment requirements in this article shall apply only to473 |
---|
520 | 519 | | processing activities created or generated on or after July 1, 2026.474 |
---|
521 | 520 | | 10-1-967.475 |
---|
522 | 521 | | (a) A controller in possession of de-identified data shall:476 |
---|
523 | 522 | | (1) Take reasonable measures to ensure that the data cannot be associated with a natural477 |
---|
524 | 523 | | person;478 |
---|
525 | 524 | | (2) Publicly commit to maintaining and using de-identified data without attempting to479 |
---|
526 | 525 | | reidentify the data; and480 |
---|
527 | 526 | | (3) Contractually obligate recipients of the de-identified data to comply with this article.481 |
---|
528 | 527 | | (b) Nothing in this Code section shall require a controller or processor to:482 |
---|
529 | 528 | | (1) Reidentify de-identified data or pseudonymous data;483 |
---|
530 | 529 | | S. B. 111 |
---|
531 | 530 | | - 19 - 25 LC 59 0079 |
---|
532 | 531 | | (2) Maintain data in identifiable form, or collect, obtain, retain, or access data or484 |
---|
533 | 532 | | technology, in order to be capable of associating an authenticated consumer request with485 |
---|
534 | 533 | | personal information; or486 |
---|
535 | 534 | | (3) Comply with an authenticated consumer rights request, pursuant to Code487 |
---|
536 | 535 | | Section 10-1-963, if:488 |
---|
537 | 536 | | (A) The controller is not reasonably capable of associating the request with the489 |
---|
538 | 537 | | personal information or it would be unreasonably burdensome for the controller to490 |
---|
539 | 538 | | associate the request with the personal information;491 |
---|
540 | 539 | | (B) The controller does not use the personal information to recognize or respond to the492 |
---|
541 | 540 | | specific consumer who is the subject of the personal information, or associate the493 |
---|
542 | 541 | | personal information with other personal information about the same specific494 |
---|
543 | 542 | | consumer; and495 |
---|
544 | 543 | | (C) The controller does not engage in the sale of personal information to a third party496 |
---|
545 | 544 | | or otherwise voluntarily disclose the personal information to a third party other than a497 |
---|
546 | 545 | | processor, except as otherwise permitted in this Code section.498 |
---|
547 | 546 | | (c) The consumer rights described in Code Sections 10-1-963 and 10-1-964 shall not apply499 |
---|
548 | 547 | | to pseudonymous data in cases where the controller is able to demonstrate information500 |
---|
549 | 548 | | necessary to identify the consumer is kept separately and is subject to effective technical501 |
---|
550 | 549 | | and organizational controls that prevent the controller from accessing that information.502 |
---|
551 | 550 | | (d) A controller that discloses pseudonymous data or de-identified data shall exercise503 |
---|
552 | 551 | | reasonable oversight to monitor compliance with contractual commitments to which the504 |
---|
553 | 552 | | pseudonymous data or de-identified data is subject and shall take appropriate steps to505 |
---|
554 | 553 | | address breaches of those contractual commitments.506 |
---|
555 | 554 | | 10-1-968.507 |
---|
556 | 555 | | (a) Nothing in this article shall restrict a controller's or processor's ability to:508 |
---|
557 | 556 | | (1) Comply with federal, state, or local laws, rules, or regulations;509 |
---|
558 | 557 | | S. B. 111 |
---|
559 | 558 | | - 20 - 25 LC 59 0079 |
---|
560 | 559 | | (2) Comply with a civil, criminal, or regulatory inquiry, investigation, subpoena, or510 |
---|
561 | 560 | | summons by federal, state, local, or other governmental authorities;511 |
---|
562 | 561 | | (3) Cooperate with law enforcement agencies concerning conduct or activity that the512 |
---|
563 | 562 | | controller or processor reasonably and in good faith believes may violate federal, state,513 |
---|
564 | 563 | | or local laws, rules, or regulations;514 |
---|
565 | 564 | | (4) Investigate, establish, exercise, prepare for, or defend legal claims;515 |
---|
566 | 565 | | (5) Provide a product or service specifically requested by a consumer or the parent or516 |
---|
567 | 566 | | legal guardian of a known child, perform a contract to which the consumer is a party,517 |
---|
568 | 567 | | including fulfilling the terms of a written warranty, or take steps at the request of the518 |
---|
569 | 568 | | consumer prior to entering into a contract;519 |
---|
570 | 569 | | (6) Take immediate steps to protect an interest that is essential for the life or physical520 |
---|
571 | 570 | | safety of the consumer or of another natural person, and where the processing cannot be521 |
---|
572 | 571 | | manifestly based on another legal basis;522 |
---|
573 | 572 | | (7) Prevent, detect, protect against, or respond to security incidents, identity theft, fraud,523 |
---|
574 | 573 | | harassment, malicious or deceptive activity, or illegal activity; preserve the integrity or524 |
---|
575 | 574 | | security of systems; or investigate, report, or prosecute those responsible for such action;525 |
---|
576 | 575 | | (8) Engage in public reviewed or peer reviewed scientific or statistical research in the526 |
---|
577 | 576 | | public interest that adheres to all other applicable ethics and privacy laws and is527 |
---|
578 | 577 | | approved, monitored, and governed by an institutional review board, or similar528 |
---|
579 | 578 | | independent oversight entity that determines whether:529 |
---|
580 | 579 | | (A) Deletion of the information is likely to provide substantial benefits that do not530 |
---|
581 | 580 | | exclusively accrue to the controller;531 |
---|
582 | 581 | | (B) The expected benefits of the research outweigh the privacy risks; and532 |
---|
583 | 582 | | (C) The controller has implemented reasonable safeguards to mitigate privacy risks533 |
---|
584 | 583 | | associated with research, including risks associated with reidentification; or534 |
---|
585 | 584 | | (9) Assist another controller, processor, or third party with the obligations under this535 |
---|
586 | 585 | | article.536 |
---|
587 | 586 | | S. B. 111 |
---|
588 | 587 | | - 21 - 25 LC 59 0079 |
---|
589 | 588 | | (b) The obligations imposed on controllers or processors under this article shall not restrict537 |
---|
590 | 589 | | a controller's or processor's ability to collect, use, or retain data to:538 |
---|
591 | 590 | | (1) Conduct internal research to develop, improve, or repair products, services, or539 |
---|
592 | 591 | | technology;540 |
---|
593 | 592 | | (2) Effectuate a product recall;541 |
---|
594 | 593 | | (3) Identify and repair technical errors that impair existing or intended functionality;542 |
---|
595 | 594 | | (4) Authenticate an individual for the purpose of allowing access to a secure location or543 |
---|
596 | 595 | | facility; or 544 |
---|
597 | 596 | | (5) Perform internal operations that are reasonably aligned with the expectations of the545 |
---|
598 | 597 | | consumer or reasonably anticipated based on the consumer's existing relationship with546 |
---|
599 | 598 | | the controller or are otherwise compatible with processing data in furtherance of the547 |
---|
600 | 599 | | provision of a product or service specifically requested by a consumer or the performance548 |
---|
601 | 600 | | of a contract to which the consumer is a party.549 |
---|
602 | 601 | | (c) The obligations imposed on controllers or processors under this article shall not apply550 |
---|
603 | 602 | | where compliance with this article by the controller or processor would violate an551 |
---|
604 | 603 | | evidentiary privilege under the laws of this state. Nothing in this article shall prevent a552 |
---|
605 | 604 | | controller or processor from providing personal information concerning a consumer to a553 |
---|
606 | 605 | | person covered by an evidentiary privilege under the laws of this state as part of a554 |
---|
607 | 606 | | privileged communication.555 |
---|
608 | 607 | | (d)(1) A controller or processor that discloses personal information to a third-party556 |
---|
609 | 608 | | controller or processor, in compliance with the requirements of this article, shall not be557 |
---|
610 | 609 | | in violation of this article if:558 |
---|
611 | 610 | | (A) The third-party controller or processor that receives and processes the personal559 |
---|
612 | 611 | | information is in violation of this article; and560 |
---|
613 | 612 | | (B) At the time of disclosing the personal information, the disclosing controller or561 |
---|
614 | 613 | | processor did not have actual knowledge that the recipient intended to commit a562 |
---|
615 | 614 | | violation.563 |
---|
616 | 615 | | S. B. 111 |
---|
617 | 616 | | - 22 - 25 LC 59 0079 |
---|
618 | 617 | | (2) A third-party controller or processor receiving personal information from a controller564 |
---|
619 | 618 | | or processor in compliance with the requirements of this article is likewise not in565 |
---|
620 | 619 | | violation of this article for the violations of the controller or processor from which it566 |
---|
621 | 620 | | receives such personal information.567 |
---|
622 | 621 | | (e) This article shall not impose an obligation on controllers and processors that adversely568 |
---|
623 | 622 | | affects the rights or freedoms of a person, such as exercising the right of free speech569 |
---|
624 | 623 | | pursuant to the First Amendment to the United States Constitution, or that applies to the570 |
---|
625 | 624 | | processing of personal information by a person in the course of a purely personal activity.571 |
---|
626 | 625 | | (f) A controller shall not process personal information for purposes other than those572 |
---|
627 | 626 | | expressly listed in this Code section unless otherwise allowed by this article. Personal573 |
---|
628 | 627 | | information processed by a controller pursuant to this Code section may be processed to574 |
---|
629 | 628 | | the extent that the processing is:575 |
---|
630 | 629 | | (1) Reasonably necessary and proportionate to the purposes listed in this section; and576 |
---|
631 | 630 | | (2) Adequate, relevant, and limited to what is necessary in relation to the specific577 |
---|
632 | 631 | | purposes listed in this section. Personal information collected, used, or retained pursuant578 |
---|
633 | 632 | | to subsection (b) of this Code section shall, where applicable, take into account the nature579 |
---|
634 | 633 | | and purpose or purposes of the collection, use, or retention. The data shall be subject to580 |
---|
635 | 634 | | reasonable administrative, technical, and physical measures to protect the confidentiality,581 |
---|
636 | 635 | | integrity, and accessibility of the personal information and to reduce reasonably582 |
---|
637 | 636 | | foreseeable risks of harm to consumers relating to the collection, use, or retention of583 |
---|
638 | 637 | | personal information.584 |
---|
639 | 638 | | (g) If a controller processes personal information pursuant to an exemption in this Code585 |
---|
640 | 639 | | section, then the controller bears the burden of demonstrating that the processing qualifies586 |
---|
641 | 640 | | for the exemption and complies with subsection (f) of this Code section.587 |
---|
642 | 641 | | (h) Processing personal information for the purposes expressly identified in any of the588 |
---|
643 | 642 | | paragraphs (1) through (9) of subsection of (a) of this Code section shall not solely make589 |
---|
644 | 643 | | an entity a controller with respect to the processing.590 |
---|
645 | 644 | | S. B. 111 |
---|
646 | 645 | | - 23 - 25 LC 59 0079 |
---|
647 | 646 | | 10-1-969.591 |
---|
648 | 647 | | Nothing in this article shall be construed to conflict with the specific requirements:592 |
---|
649 | 648 | | (1) Related to the management of health records under Title 31; or593 |
---|
650 | 649 | | (2) Included in federal law.594 |
---|
651 | 650 | | 10-1-970.595 |
---|
652 | 651 | | (a) A provision of a contract or agreement that waives or limits a consumer's rights under596 |
---|
653 | 652 | | this article, including, but not limited to, a right to a remedy or means of enforcement, is597 |
---|
654 | 653 | | contrary to public policy, void, and unenforceable.598 |
---|
655 | 654 | | (b) Nothing in this article shall prevent a consumer from declining to request information599 |
---|
656 | 655 | | from a controller, declining to opt out of a controller's sale of the consumer's personal600 |
---|
657 | 656 | | information, or authorizing a controller to sell the consumer's personal information after601 |
---|
658 | 657 | | previously opting out.602 |
---|
659 | 658 | | 10-1-971.603 |
---|
660 | 659 | | If the Attorney General has reasonable cause to believe that an individual, controller, or604 |
---|
661 | 660 | | processor has engaged in, is engaging in, or is about to engage in a violation of this article,605 |
---|
662 | 661 | | then the Attorney General may issue a civil investigative demand.606 |
---|
663 | 662 | | 10-1-972.607 |
---|
664 | 663 | | (a) The Attorney General shall have exclusive authority to enforce this article.608 |
---|
665 | 664 | | (b) The Attorney General may develop reasonable cause to believe that a controller or609 |
---|
666 | 665 | | processor is in violation of this article, based on the Attorney General's own inquiry or on610 |
---|
667 | 666 | | consumer or public complaints. Prior to initiating an action under this article, the Attorney611 |
---|
668 | 667 | | General shall provide a controller or processor 60 days' written notice identifying the612 |
---|
669 | 668 | | specific provisions of this article the Attorney General alleges have been or are being613 |
---|
670 | 669 | | violated. If within the 60 day period, the controller or processor cures the noticed violation614 |
---|
671 | 670 | | S. B. 111 |
---|
672 | 671 | | - 24 - 25 LC 59 0079 |
---|
673 | 672 | | and provides the Attorney General an express written statement that the alleged violations615 |
---|
674 | 673 | | have been cured and that no such further violations shall occur, then the Attorney General616 |
---|
675 | 674 | | shall not initiate an action against the controller or processor.617 |
---|
676 | 675 | | (c) If a controller or processor continues to violate this article following the cure period618 |
---|
677 | 676 | | provided for in subsection (b) of this Code section or breaches an express written statement619 |
---|
678 | 677 | | provided to the Attorney General under subsection (b) of this Code section, then the620 |
---|
679 | 678 | | Attorney General may bring an action in a court of competent jurisdiction seeking any of621 |
---|
680 | 679 | | the following relief:622 |
---|
681 | 680 | | (1) Declaratory judgment that the act or practice violates this article;623 |
---|
682 | 681 | | (2) Injunctive relief, including preliminary and permanent injunctions, to prevent an624 |
---|
683 | 682 | | additional violation of and compel compliance with this article;625 |
---|
684 | 683 | | (3) Civil penalties, as described in subsection (d) of this Code section;626 |
---|
685 | 684 | | (4) Reasonable attorney's fees and investigative costs; or627 |
---|
686 | 685 | | (5) Other relief the court determines appropriate.628 |
---|
687 | 686 | | (d)(1) A court may impose a civil penalty of up to $7,500.00 for each violation of this629 |
---|
688 | 687 | | article.630 |
---|
689 | 688 | | (2) If the court finds the controller or processor willfully or knowingly violated this631 |
---|
690 | 689 | | article, then the court may, in its discretion, award treble damages.632 |
---|
691 | 690 | | (e) A violation of this article shall not serve as the basis for, or be subject to, a private right633 |
---|
692 | 691 | | of action, including a class action lawsuit, under this article or any other law.634 |
---|
693 | 692 | | (f) The Attorney General may recover reasonable expenses incurred in investigating and635 |
---|
694 | 693 | | preparing a case, including attorney's fees, in an action initiated under this article.636 |
---|
695 | 694 | | 10-1-973.637 |
---|
696 | 695 | | (a) A controller or processor shall have an affirmative defense to a cause of action for a638 |
---|
697 | 696 | | violation of this article if the controller or processor creates, maintains, and complies with639 |
---|
698 | 697 | | a written privacy program that:640 |
---|
699 | 698 | | S. B. 111 |
---|
700 | 699 | | - 25 - 25 LC 59 0079 |
---|
701 | 700 | | (1)(A) Reasonably conforms to the NIST or comparable privacy framework designed641 |
---|
702 | 701 | | to safeguard consumer privacy; and642 |
---|
703 | 702 | | (B) Is updated to reasonably conform with a subsequent revision to the NIST or643 |
---|
704 | 703 | | comparable privacy framework within two years of the publication date stated in the644 |
---|
705 | 704 | | most recent revision to the NIST or comparable privacy framework; and645 |
---|
706 | 705 | | (2) Provides a person with the substantive rights required by this article.646 |
---|
707 | 706 | | (b) The scale and scope of a controller or processor's privacy program under subsection (a)647 |
---|
708 | 707 | | of this Code section shall be appropriate if it is based on all of the following factors:648 |
---|
709 | 708 | | (1) The size and complexity of the controller or processor's business;649 |
---|
710 | 709 | | (2) The nature and scope of the activities of the controller or processor;650 |
---|
711 | 710 | | (3) The sensitivity of the personal information processed;651 |
---|
712 | 711 | | (4) The cost and availability of tools to improve privacy protections and data652 |
---|
713 | 712 | | governance; and653 |
---|
714 | 713 | | (5) Compliance with a comparable state or federal law, if applicable.654 |
---|
715 | 714 | | 10-1-974.655 |
---|
716 | 715 | | (a) A municipality, county, or consolidated government shall not require a controller or656 |
---|
717 | 716 | | processor to disclose personal information of consumers, unless pursuant to a subpoena or657 |
---|
718 | 717 | | court order.658 |
---|
719 | 718 | | (b) This article shall supersede and preempt any conflicting provisions of any ordinances,659 |
---|
720 | 719 | | resolutions, regulations, or the equivalent adopted by any municipality, county, or660 |
---|
721 | 720 | | consolidated government in this state regarding the processing of personal information by661 |
---|
722 | 721 | | controllers or processors."662 |
---|
723 | 722 | | SECTION 2.663 |
---|
724 | 723 | | This Act shall become effective on July 1, 2026, and shall apply to contracts entered into,664 |
---|
725 | 724 | | amended, or renewed on or after such date.665 |
---|
726 | 725 | | S. B. 111 |
---|
727 | 726 | | - 26 - 25 LC 59 0079 |
---|
728 | 727 | | SECTION 3. |
---|
729 | 728 | | 666 |
---|
730 | 729 | | All laws and parts of laws in conflict with this Act are repealed.667 |
---|
731 | 730 | | S. B. 111 |
---|
732 | 731 | | - 27 - |
---|