Indiana 2022 Regular Session

Indiana House Bill HB1261 Compare Versions

Only one version of the bill is available at this time.
OldNewDifferences
11
22 Introduced Version
33 HOUSE BILL No. 1261
44 _____
55 DIGEST OF INTRODUCED BILL
66 Citations Affected: IC 4-6-9-9; IC 24-15.
77 Synopsis: Consumer privacy. Requires businesses to disclose certain
88 information to consumers. Outlines different requests a consumer may
99 make with businesses regarding the consumer's personal information.
1010 Assigns enforcement of consumer privacy law to the Indiana division
1111 of consumer protection. Exempts certain government entities and
1212 certain types of information. Provides certain business exceptions.
1313 Effective: July 1, 2022.
1414 Hamilton
1515 January 10, 2022, read first time and referred to Committee on Commerce, Small Business
1616 and Economic Development.
1717 2022 IN 1261—LS 7000/DI 148 Introduced
1818 Second Regular Session of the 122nd General Assembly (2022)
1919 PRINTING CODE. Amendments: Whenever an existing statute (or a section of the Indiana
2020 Constitution) is being amended, the text of the existing provision will appear in this style type,
2121 additions will appear in this style type, and deletions will appear in this style type.
2222 Additions: Whenever a new statutory provision is being enacted (or a new constitutional
2323 provision adopted), the text of the new provision will appear in this style type. Also, the
2424 word NEW will appear in that style type in the introductory clause of each SECTION that adds
2525 a new provision to the Indiana Code or the Indiana Constitution.
2626 Conflict reconciliation: Text in a statute in this style type or this style type reconciles conflicts
2727 between statutes enacted by the 2021 Regular Session of the General Assembly.
2828 HOUSE BILL No. 1261
2929 A BILL FOR AN ACT to amend the Indiana Code concerning trade
3030 regulation.
3131 Be it enacted by the General Assembly of the State of Indiana:
3232 1 SECTION 1. IC 4-6-9-9 IS ADDED TO THE INDIANA CODE AS
3333 2 A NEW SECTION TO READ AS FOLLOWS [EFFECTIVE JULY 1,
3434 3 2022]: Sec. 9. (a) The division shall enforce the consumer privacy
3535 4 article (IC 24-15).
3636 5 (b) The division shall adopt rules under IC 4-22-2 to carry out
3737 6 IC 24-15.
3838 7 SECTION 2. IC 24-15 IS ADDED TO THE INDIANA CODE AS
3939 8 A NEW ARTICLE TO READ AS FOLLOWS [EFFECTIVE JULY 1,
4040 9 2022]:
4141 10 ARTICLE 15. CONSUMER PRIVACY
4242 11 Chapter 1. Applicability
4343 12 Sec. 1. This article applies to a person that does one (1) or more
4444 13 of the following:
4545 14 (1) Conducts business in Indiana.
4646 15 (2) Produces products or services that are marketed to
4747 16 Indiana residents.
4848 17 (3) Controls or processes personal data of either of the
4949 2022 IN 1261—LS 7000/DI 148 2
5050 1 following:
5151 2 (A) At least one hundred thousand (100,000) consumers
5252 3 during a calendar year.
5353 4 (B) At least twenty-five thousand (25,000) consumers
5454 5 during a calendar year and derives more than fifty percent
5555 6 (50%) of gross revenue from the sale of personal data.
5656 7 Sec. 2. The consumer rights and the business duties in this
5757 8 article must not adversely affect the rights and freedoms of other
5858 9 individuals.
5959 10 Sec. 3. This article does not require a business, service provider,
6060 11 or contractor to:
6161 12 (1) Reidentify or otherwise link information that, in the
6262 13 ordinary course of business, is not maintained in a manner
6363 14 that would cause the information to be considered personal
6464 15 information.
6565 16 (2) Retain any personal information about a consumer if the
6666 17 personal information would not be retained in the ordinary
6767 18 course of business.
6868 19 (3) Maintain information in an identifiable, linkable, or
6969 20 associable form, or collect, obtain, retain, or access any data
7070 21 or technology, as a means of linking or associating a verifiable
7171 22 consumer request with personal information.
7272 23 Chapter 2. Exemptions
7373 24 Sec. 1. This article does not apply to the following:
7474 25 (1) The executive, judicial, or legislative branch of state
7575 26 government, or any political subdivision.
7676 27 (2) A unit (as defined in IC 36-1-2-23).
7777 28 (3) The county office of any of the following:
7878 29 (A) Auditor.
7979 30 (B) Treasurer.
8080 31 (C) Recorder.
8181 32 (D) Surveyor.
8282 33 (F) Coroner.
8383 34 (G) Assessor.
8484 35 (4) The county sheriff's department.
8585 36 (5) A health care provider or a covered entity governed by
8686 37 federal privacy law, to the extent the provider or covered
8787 38 entity complies with the federal privacy law.
8888 39 Sec. 2. (a) This article does not apply to any of the following
8989 40 information:
9090 41 (1) Medical information or health records protected under
9191 42 IC 4-6-14.
9292 2022 IN 1261—LS 7000/DI 148 3
9393 1 (2) Personal information collected as part of a clinical trial or
9494 2 other biomedical research study if:
9595 3 (A) the information is not sold or shared; and
9696 4 (B) it is inconsistent that participants be informed of that
9797 5 use and provide consent.
9898 6 (3) Personal information that is collected, processed, sold, or
9999 7 disclosed subject to the following:
100100 8 (A) The federal Gramm-Leach-Bliley Act (P.L. 106-102),
101101 9 and implementing regulations.
102102 10 (B) The federal Farm Credit Act of 1971 (as amended in 12
103103 11 U.S.C. 2001-2279cc and implementing regulations, 12 CFR
104104 12 600, et seq.).
105105 13 (C) The federal Driver's Privacy Protection Act of 1994 (18
106106 14 U.S.C. Sec. 2721 et seq.).
107107 15 (4) Personal information collected by a business about the
108108 16 following individuals, including emergency contact
109109 17 information, that is used solely in the context of the
110110 18 individual's role, or former role, with the business:
111111 19 (A) A job applicant.
112112 20 (B) An employee.
113113 21 (C) An owner.
114114 22 (D) A director.
115115 23 (E) An officer.
116116 24 (F) A medical staff member.
117117 25 (G) An independent contractor.
118118 26 Sec. 3. This article does not apply to an activity involving
119119 27 personal information that bears on a consumer's credit worthiness,
120120 28 credit standing, credit capacity, character, general reputation,
121121 29 personal characteristics, or mode of living:
122122 30 (1) by a consumer reporting agency;
123123 31 (2) by a furnisher of information, who provides information
124124 32 for use in a consumer report; or
125125 33 (3) by a user of a consumer report;
126126 34 to the extent that the activity involving the information is subject
127127 35 to regulation under the Fair Credit Reporting Act (15 U.S.C. 1681
128128 36 et seq.), and the information is not collected, maintained, used,
129129 37 communicated, disclosed, or sold except as authorized by the Fair
130130 38 Credit Reporting Act.
131131 39 Sec. 4. The duties imposed on businesses in IC 24-15-4,
132132 40 IC 24-15-5, and IC 24-15-6 do not apply to household data.
133133 41 Chapter 3. Definitions
134134 42 Sec. 1. The definitions in this chapter apply throughout this
135135 2022 IN 1261—LS 7000/DI 148 4
136136 1 article.
137137 2 Sec. 2. "Aggregate consumer information" means information:
138138 3 (1) that relates to a group or category of consumers;
139139 4 (2) from which individual consumer identities have been
140140 5 removed; and
141141 6 (3) that is not linked or reasonably linkable to any consumer
142142 7 or household, including via a device.
143143 8 The term does not include one (1) or more individual consumer
144144 9 records that have been deidentified.
145145 10 Sec. 3. (a) "Biometric information" means an individual's
146146 11 physiological, biological, or behavioral characteristic used, or
147147 12 intended to be used, to establish the individual's identity.
148148 13 (b) The term includes:
149149 14 (1) a retina or iris scan;
150150 15 (2) a fingerprint;
151151 16 (3) a voiceprint;
152152 17 (4) a handprint;
153153 18 (5) a faceprint;
154154 19 (6) a keystroke pattern;
155155 20 (7) a gait pattern; and
156156 21 (8) sleep, health, or exercise data;
157157 22 from which identifying information about an individual can be
158158 23 extracted.
159159 24 Sec. 4. (a) "Business" means a person that:
160160 25 (1) collects, or on behalf of which is collected, consumers'
161161 26 personal information;
162162 27 (2) determines the purpose and means of processing a
163163 28 consumer's personal information;
164164 29 (3) provides goods or services in Indiana; and
165165 30 (4) satisfies at least one (1) of the following:
166166 31 (A) As of January 1 of the calendar year, had annual gross
167167 32 revenues in excess of twenty-five million dollars
168168 33 ($25,000,000) in the preceding calendar year.
169169 34 (B) Alone or combined, annually buys, sells, or shares the
170170 35 personal information of at least one hundred thousand
171171 36 (100,000) consumers, households, or devices.
172172 37 (C) Derives at least fifty percent (50%) of the person's
173173 38 annual revenues from selling or sharing personal
174174 39 information.
175175 40 (b) The term includes a person that is not described in
176176 41 subsection (a) and voluntarily certifies to the consumer protection
177177 42 division that the person is in compliance with and agrees to be
178178 2022 IN 1261—LS 7000/DI 148 5
179179 1 bound by this article.
180180 2 Sec. 5. "Business controller information" means the name of the
181181 3 owner, director, officer, or management employee of a business
182182 4 and the contact information, including a business title, for the
183183 5 owner, director, officer, or management employee.
184184 6 Sec. 6. (a) "Business purpose" means the use of personal
185185 7 information for:
186186 8 (1) the business's operational purposes;
187187 9 (2) other notified purposes;
188188 10 (3) the service provider or contractor's operational purposes
189189 11 if the use of personal information is reasonably necessary and
190190 12 proportionate to achieve the operational purpose for which
191191 13 the personal information was collected or processed; or
192192 14 (4) another operational purpose that is compatible with the
193193 15 context in which the personal information was collected.
194194 16 (b) The term includes the following:
195195 17 (1) Auditing related to counting ad impressions of unique
196196 18 visitors.
197197 19 (2) Helping to ensure security and integrity to the extent the
198198 20 use of the consumer's personal information is reasonably
199199 21 necessary and proportionate for these purposes.
200200 22 (3) Debugging to identify and repair errors that impair
201201 23 existing intended functionality.
202202 24 (4) Undertaking internal research for technological
203203 25 development and demonstration.
204204 26 (5) Undertaking activities to verify or maintain the quality or
205205 27 safety of a service or device that is owned, manufactured,
206206 28 manufactured for, or controlled by the business, and to
207207 29 improve, upgrade, or enhance the service or device that is
208208 30 owned by, manufactured by, manufactured for, or controlled
209209 31 by the business.
210210 32 Sec. 7. "Collects", "collected", or "collection" means:
211211 33 (1) buying;
212212 34 (2) renting;
213213 35 (3) gathering;
214214 36 (4) obtaining;
215215 37 (5) receiving; or
216216 38 (6) accessing;
217217 39 any personal information about a consumer, including by
218218 40 observing a consumer's behavior.
219219 41 Sec. 8. "Commercial credit reporting agency"means any person
220220 42 who, for monetary fees or dues or on a cooperative nonprofit basis,
221221 2022 IN 1261—LS 7000/DI 148 6
222222 1 provides commercial credit reports to third parties.
223223 2 Sec. 9. "Commercial purposes" means to advance a person's
224224 3 economic interests, such as by inducing another person to enable
225225 4 a commercial transaction.
226226 5 Sec. 10. (a) "Consent" means a freely given affirmative act that
227227 6 indicates:
228228 7 (1) a consumer;
229229 8 (2) a consumer's legal guardian;
230230 9 (3) a person who has power of attorney for the consumer; or
231231 10 (4) a person acting as a conservator for a consumer;
232232 11 agrees to having the consumer's personal information processed
233233 12 for a particular purpose.
234234 13 (b) The following do not constitute consent:
235235 14 (1) Accepting a general terms of use that contains descriptions
236236 15 of personal information processing along with other unrelated
237237 16 information.
238238 17 (2) Hovering over, muting, pausing, or closing a given piece of
239239 18 content.
240240 19 (3) Agreement obtained through use of dark patterns.
241241 20 Sec. 11. "Consumer" means an Indiana resident acting only in
242242 21 an individual or household context. The term does not include an
243243 22 individual acting in a commercial or employment context.
244244 23 Sec. 12. "Consumer report" and "consumer reporting agency"
245245 24 have the same meaning as set forth in the Fair Credit Reporting
246246 25 Act (15 U.S.C. 1681 et seq.).
247247 26 Sec. 13. "Contractor" means a person to whom the business
248248 27 makes available a consumer's personal information for a business
249249 28 purpose, under a written contract with the business.
250250 29 Sec. 14. "Controller" means the person that, alone or jointly
251251 30 with others, determines the purpose and means for processing
252252 31 personal data.
253253 32 Sec. 15. "Covered entity" has the meaning ascribed to that term
254254 33 in the federal Health Insurance Portability Act (HIPAA) (P.L.
255255 34 104-191).
256256 35 Sec. 16. "Dark pattern" means a user interface designed to trick
257257 36 the consumer. This term includes tricking a consumer into:
258258 37 (1) buying additional items; or
259259 38 (2) publicly sharing more information than the consumer
260260 39 intended to.
261261 40 Sec. 17. "Deidentified information" means data that cannot
262262 41 reasonably be linked to a particular consumer.
263263 42 Sec. 18. "Device" means any physical object that is capable of
264264 2022 IN 1261—LS 7000/DI 148 7
265265 1 connecting directly or indirectly to the Internet or to another
266266 2 device.
267267 3 Sec. 19. "Director" has the same meaning set forth in
268268 4 IC 23-1-37-2.
269269 5 Sec. 20. "Educational assessment" means a quiz, test, or other
270270 6 assessment, whether standardized or nonstandardized, that is used
271271 7 to do the following:
272272 8 (1) Evaluate students in, or for entry to the following:
273273 9 (A) A school corporation, charter school, or nonpublic
274274 10 school with one (1) or more employees providing
275275 11 instruction for students in kindergarten through grade 12.
276276 12 (B) A postsecondary educational institution that is
277277 13 accredited by an accrediting agency recognized by the
278278 14 United States Department of Education.
279279 15 (C) A vocational program.
280280 16 (D) A postgraduate program that is accredited by an
281281 17 accrediting agency recognized by the United States
282282 18 Department of Education.
283283 19 (2) Determine competency and eligibility to receive
284284 20 certification or licensure from a government agency or
285285 21 government certification body.
286286 22 Sec. 21. "Household" means multiple consumers who cohabitate
287287 23 with one another at the same residential address and share use of
288288 24 common devices or services.
289289 25 Sec. 22. (a) "Intentionally interact" means to deliberately:
290290 26 (1) interact with a person; or
291291 27 (2) disclose personal information;
292292 28 including visiting the person's Internet web site or purchasing a
293293 29 good or service from the person.
294294 30 (b) The term does not include:
295295 31 (1) hovering over;
296296 32 (2) muting;
297297 33 (3) pausing; or
298298 34 (4) closing;
299299 35 a given piece of content.
300300 36 Sec. 23. "Management employee" means an individual whose
301301 37 name and contact information is:
302302 38 (1) reported to or collected by a commercial credit reporting
303303 39 agency as the primary manager of a business; and
304304 40 (2) used solely within the context of the individual's role as the
305305 41 primary manager of the business.
306306 42 Sec. 24. "Ownership information" means the registered owner's
307307 2022 IN 1261—LS 7000/DI 148 8
308308 1 name and contact information.
309309 2 Sec. 25. (a) "Officer" means an individual elected or appointed
310310 3 by the board of directors of a business to manage the daily
311311 4 operations of the business.
312312 5 (b) The term includes the following:
313313 6 (1) A chief executive officer.
314314 7 (2) A president.
315315 8 (3) A secretary.
316316 9 (4) A treasurer.
317317 10 Sec. 26. "Person" means an individual or a legal entity.
318318 11 Sec. 27. (a) "Personal information" means information that:
319319 12 (1) identifies;
320320 13 (2) relates to;
321321 14 (3) describes;
322322 15 (4) is reasonably capable of being associated with; or
323323 16 (5) could reasonably be linked with;
324324 17 a particular consumer or household.
325325 18 (b) The term includes the following:
326326 19 (1) Identifiers, including:
327327 20 (A) a real name;
328328 21 (B) an alias;
329329 22 (C) a postal address;
330330 23 (D) a unique personal identifier;
331331 24 (E) an online identifier;
332332 25 (F) an Internet protocol address;
333333 26 (G) an electronic mail address;
334334 27 (H) an account name;
335335 28 (I) a Social Security number;
336336 29 (J) a driver's license number; or
337337 30 (K) a passport number.
338338 31 (2) Characteristics of protected classifications under state or
339339 32 federal law.
340340 33 (3) Commercial information, including:
341341 34 (A) records of personal property;
342342 35 (B) products or services;
343343 36 (i) purchased;
344344 37 (ii) obtained; or
345345 38 (iii) considered; or
346346 39 (C) other purchasing tendencies or consuming histories.
347347 40 (4) Biometric information.
348348 41 (5) Internet or other electronic network activity information,
349349 42 including:
350350 2022 IN 1261—LS 7000/DI 148 9
351351 1 (A) browsing history;
352352 2 (B) search history; or
353353 3 (C) information regarding a consumer's interaction with:
354354 4 (i) an Internet web site;
355355 5 (ii) an application; or
356356 6 (iii) an advertisement.
357357 7 (6) Geolocation data.
358358 8 (7) Audio, electronic, visual, thermal, olfactory, or similar
359359 9 information.
360360 10 (8) Professional or employment related information.
361361 11 (9) Education information, defined as not publicly available
362362 12 personally identifiable information under the Family
363363 13 Educational Rights and Privacy Act (20 U.S.C. Sec. 1232g; 34
364364 14 CFR Part 99).
365365 15 (10) Inferences drawn from any of the information identified
366366 16 in this subsection to create a profile reflecting the consumer's:
367367 17 (A) preferences;
368368 18 (B) characteristics;
369369 19 (C) psychological trends;
370370 20 (D) predispositions;
371371 21 (E) behavior;
372372 22 (F) attitudes;
373373 23 (G) intelligence;
374374 24 (H) abilities; and
375375 25 (I) aptitudes.
376376 26 (11) Sensitive personal information.
377377 27 (c) The term does not include:
378378 28 (1) publicly available information;
379379 29 (2) consumer information that is deidentified; or
380380 30 (3) aggregate consumer information.
381381 31 For purposes of this subsection and section 34 of this chapter,
382382 32 "publicly available" means information that is lawfully made
383383 33 available from federal, state, or local government records. The
384384 34 term does not mean biometric information collected by a business
385385 35 about a consumer without the consumer's knowledge.
386386 36 Sec. 28. "Precise geolocation" means data:
387387 37 (1) that is derived from a device; and
388388 38 (2) that is used, or intended to be used, to locate a consumer
389389 39 within a geographic area that is equal to or less than the area
390390 40 of a circle with a radius of one thousand eight hundred and
391391 41 fifty (1,850) feet, except as prescribed by regulations.
392392 42 Sec. 29. "Probabilistic identifier" means the identification of a:
393393 2022 IN 1261—LS 7000/DI 148 10
394394 1 (1) consumer; or
395395 2 (2) device;
396396 3 that is more probable than not based on personal information.
397397 4 Sec. 30. "Processing" means an operation that is performed on
398398 5 personal data, whether or not by automated means.
399399 6 Sec. 31. "Research" means scientific and systematic study and
400400 7 observation, including:
401401 8 (1) basic research or applied research:
402402 9 (A) that is designed to contribute to scientific knowledge in
403403 10 the public interest; and
404404 11 (B) that adheres to all other applicable ethics and privacy
405405 12 laws; or
406406 13 (2) studies conducted in the public interest in the area of
407407 14 public health.
408408 15 Sec. 32. "Security and integrity" means the ability of the
409409 16 following:
410410 17 (1) Networks or information systems to detect security
411411 18 incidents that compromise the:
412412 19 (A) availability;
413413 20 (B) authenticity;
414414 21 (C) integrity; and
415415 22 (D) confidentiality;
416416 23 of stored or transmitted personal information.
417417 24 (2) Businesses to:
418418 25 (A) detect security incidents;
419419 26 (B) resist malicious, deceptive, fraudulent, or illegal
420420 27 actions; and
421421 28 (C) help prosecute those responsible for those actions.
422422 29 (3) Businesses to ensure the physical safety of natural persons.
423423 30 Sec. 33. (a) "Sell", "selling", "sale", or "sold", means any
424424 31 attempt to dispose of a consumer's personal information for
425425 32 monetary or other valuable consideration.
426426 33 (b) "Sell", "selling", "sale", or "sold" does not include when:
427427 34 (1) a consumer:
428428 35 (A) uses or directs the business to intentionally disclose
429429 36 personal information; or
430430 37 (B) uses the business to intentionally interact with a third
431431 38 party;
432432 39 (2) the business uses or shares an identifier to alert persons
433433 40 that the consumer has opted out of the sale of the consumer's
434434 41 personal information;
435435 42 (3) the business uses or shares an identifier to alert persons
436436 2022 IN 1261—LS 7000/DI 148 11
437437 1 that the consumer has limited the use of the consumer's
438438 2 sensitive personal information; or
439439 3 (4) the business transfers to a third party the personal
440440 4 information of a consumer as an asset that is part of a merger,
441441 5 acquisition, bankruptcy, or other transaction in which the
442442 6 third party assumes control of all or part of the business.
443443 7 Sec. 34. (a) "Sensitive personal information" means:
444444 8 (1) personal information that reveals:
445445 9 (A) a consumer's Social Security, driver's license, state
446446 10 identification card, or passport number;
447447 11 (B) a consumer's:
448448 12 (i) account login;
449449 13 (ii) financial account;
450450 14 (iii) debit card; or
451451 15 (iv) credit card number;
452452 16 with any required security or access code, password, or
453453 17 credentials allowing access to an account;
454454 18 (C) a consumer's precise geolocation;
455455 19 (D) a consumer's racial or ethnic origin, religious or
456456 20 philosophical beliefs, or union membership;
457457 21 (E) the contents of a consumer's mail, electronic mail, and
458458 22 text messages, unless the business is the intended recipient
459459 23 of the communication; or
460460 24 (F) a consumer's genetic data;
461461 25 (2) biometric information processed to uniquely identifying a
462462 26 consumer;
463463 27 (3) personal information concerning a consumer's health; or
464464 28 (4) personal information concerning a consumer's sex life or
465465 29 sexual orientation.
466466 30 (b) The term does not include information that is publicly
467467 31 available.
468468 32 Sec. 35. "Service" or "services" means work, labor, and
469469 33 services, including services furnished in connection with the sale or
470470 34 repair of goods.
471471 35 Sec. 36. “Service provider" means a person that processes
472472 36 information on behalf of a business and to which the business
473473 37 discloses a consumer's personal information for a business purpose
474474 38 under a written contract.
475475 39 Sec. 37. (a) "Share," "shared," or "sharing" means
476476 40 communicating a consumer's personal information by the business
477477 41 to a third party for cross context behavioral advertising, whether
478478 42 or not for monetary or other valuable consideration. This also
479479 2022 IN 1261—LS 7000/DI 148 12
480480 1 includes transactions for the benefit of a business in which no
481481 2 money is exchanged.
482482 3 Sec. 38. "Third party" means a person who is not any of the
483483 4 following:
484484 5 (1) The business with whom the consumer intentionally
485485 6 interacts.
486486 7 (2) A service provider to the business.
487487 8 (3) A contractor.
488488 9 Sec. 39. "Vehicle information" means the vehicle identification
489489 10 number, make, model, year, and odometer reading.
490490 11 Sec. 40. "Verifiable consumer request" means a request that the
491491 12 business can verify, using commercially reasonable methods, to be
492492 13 the consumer about whom the business has collected personal
493493 14 information.
494494 15 Sec. 41. "Verifiable consumer requestor" means the following
495495 16 persons who may submit a verifiable consumer request:
496496 17 (1) The consumer.
497497 18 (2) The consumer on behalf of the consumer's minor child.
498498 19 (3) The consumer's agent.
499499 20 (4) A person who has the power of attorney for the consumer.
500500 21 (5) A conservator for the consumer.
501501 22 Chapter 4. Right to Access
502502 23 Sec. 1. (a) Except as provided in section 3 of this chapter, upon
503503 24 receipt of a verifiable consumer request about a consumer from a
504504 25 verifiable consumer requestor, a business shall disclose the
505505 26 following:
506506 27 (1) The categories of personal information the business has
507507 28 collected about the consumer.
508508 29 (2) The consumer's right to request the specific pieces of
509509 30 personal information the business has collected about the
510510 31 consumer.
511511 32 (3) The categories of sources described in subdivisions (1) and
512512 33 (2) from which the personal information is collected.
513513 34 (4) The business's purpose for collecting, selling, or sharing
514514 35 personal information.
515515 36 (5) The categories of third parties to whom the business
516516 37 discloses personal information.
517517 38 (b) A verifiable consumer requestor shall submit a verifiable
518518 39 consumer request through one (1) of the following:
519519 40 (1) A business's mailing address.
520520 41 (2) A business's electronic mail address.
521521 42 (3) A business's Internet web page.
522522 2022 IN 1261—LS 7000/DI 148 13
523523 1 (4) A business's toll free telephone number.
524524 2 (5) Another method of contact for a business that is approved
525525 3 by the consumer protection division.
526526 4 (c) A business is not obligated to provide information to a
527527 5 verifiable consumer requestor who submits a request if the
528528 6 business cannot verify that the verifiable consumer requestor
529529 7 making the request is either:
530530 8 (1) the consumer about whom the business has collected
531531 9 information; or
532532 10 (2) a person authorized by the consumer to act on the
533533 11 consumer's behalf.
534534 12 Sec. 2. (a) A business that sells or shares a consumer's personal
535535 13 information, or that discloses a consumer's personal information
536536 14 for a business purpose, shall disclose, upon receipt of a verifiable
537537 15 consumer request:
538538 16 (1) the categories of personal information that the business
539539 17 sold or shared about the consumer, including the categories of
540540 18 third parties to whom the personal information was sold or
541541 19 shared; and
542542 20 (2) the categories of personal information that the business
543543 21 disclosed for a business purpose, including the categories of
544544 22 persons to whom the personal information was disclosed for
545545 23 a business purpose.
546546 24 (b) If a business has not sold or shared a consumer's personal
547547 25 information, the business shall disclose that fact upon receipt of a
548548 26 verifiable consumer request from a verifiable consumer requestor.
549549 27 (c) A third party shall not sell personal information about a
550550 28 consumer that has been sold to, or shared with, the third party by
551551 29 a business unless the consumer has received explicit notice and is
552552 30 provided an opportunity to opt out.
553553 31 (d) If a third party materially alters the manner in which the
554554 32 third party uses or shares the consumer's personal information in
555555 33 a manner that is materially inconsistent with the promises made at
556556 34 the time of collection, the third party shall give the consumer prior
557557 35 notice of the new or changed practice.
558558 36 Sec. 3. (a) A business is not required to disclose an educational
559559 37 assessment, or a consumer's specific responses to the educational
560560 38 assessment, if consumer access would provide an advantage to:
561561 39 (1) the verifiable consumer requestor who submitted the
562562 40 verifiable consumer request; or
563563 41 (2) another individual.
564564 42 (b) A business that refuses a verified consumer requestor's
565565 2022 IN 1261—LS 7000/DI 148 14
566566 1 verified consumer request under this section shall notify the
567567 2 verified consumer requestor that the business is acting under
568568 3 subsection (a).
569569 4 Chapter 5. Right to Delete
570570 5 Sec. 1. (a) A business that collects personal information about a
571571 6 consumer shall inform the consumer of the consumer's right to
572572 7 request the deletion of the consumer's personal information.
573573 8 (b) Except as otherwise provided, a business that receives a
574574 9 verifiable consumer request about a consumer from a verifiable
575575 10 consumer requestor to delete the consumer's personal information
576576 11 shall:
577577 12 (1) delete the consumer's personal information from the
578578 13 business's records;
579579 14 (2) notify the business's service providers or contractors to
580580 15 delete the consumer's personal information from their
581581 16 records; and
582582 17 (3) notify all third parties to whom the business has sold or
583583 18 shared the personal information to delete the consumer's
584584 19 personal information unless notifying all third parties is
585585 20 impossible.
586586 21 (c) Except as otherwise provided, a business may maintain a
587587 22 confidential record of deletion requests:
588588 23 (1) to prevent the consumer's personal information from
589589 24 being sold;
590590 25 (2) to ensure compliance with laws; and
591591 26 (3) for other purposes permitted under this article.
592592 27 Sec. 2. A service provider or contractor shall cooperate with a
593593 28 business in responding to a verifiable consumer request and, at the
594594 29 direction of the business, shall:
595595 30 (1) delete or enable the business to delete the requested
596596 31 personal information;
597597 32 (2) notify any of the service provider's or contractor's own
598598 33 service providers or contractors to delete personal
599599 34 information about the consumer collected, used, processed, or
600600 35 retained by the service provider or the contractor; and
601601 36 (3) notify all service providers, contractors, or third parties
602602 37 who may have accessed personal information from or through
603603 38 the service provider to delete the consumer's personal
604604 39 information, unless notifying all service providers,
605605 40 contractors, or third parties is impossible.
606606 41 Sec. 3. A service provider or contractor is not required to
607607 42 comply with a deletion request submitted by a verifiable consumer
608608 2022 IN 1261—LS 7000/DI 148 15
609609 1 requestor directly to the service provider or contractor to the
610610 2 extent that the service provider or contractor has collected, used,
611611 3 processed, or retained the consumer's personal information in the
612612 4 service provider's or contractor's role as a service provider or
613613 5 contractor to the business.
614614 6 Sec. 4. A business, service provider, or contractor acting under
615615 7 a contract with another business, service provider, or contractor
616616 8 is not required to delete the consumer's personal information
617617 9 under this chapter if it is reasonably necessary to maintain the
618618 10 consumer's personal information to do the following:
619619 11 (1) Complete the transaction for which the personal
620620 12 information was collected.
621621 13 (2) Fulfill the terms of a written warranty or product recall
622622 14 conducted under federal law.
623623 15 (3) Provide a good or service requested by the consumer or
624624 16 reasonably anticipated by the consumer within the context of
625625 17 a business's ongoing business relationship with the consumer.
626626 18 (4) Help to ensure security and integrity to the extent the use
627627 19 of the consumer's personal information is reasonably
628628 20 necessary to ensure security and integrity.
629629 21 (5) Identify and repair errors that impair existing intended
630630 22 functionality.
631631 23 (6) Exercise free speech, ensure the right of another consumer
632632 24 to exercise that consumer's right of free speech, or exercise
633633 25 another right provided for by law.
634634 26 (7) Engage in public or peer reviewed research that conforms
635635 27 or adheres to all other applicable ethics and privacy laws, if
636636 28 the consumer has provided informed consent, and the
637637 29 business's deletion of the information is likely to:
638638 30 (A) render impossible; or
639639 31 (B) seriously impair;
640640 32 the ability to complete the research.
641641 33 (8) Enable solely internal uses that are:
642642 34 (A) reasonably aligned with the expectations of the
643643 35 consumer based on the consumer's relationship with the
644644 36 business; and
645645 37 (B) compatible with the context in which the consumer
646646 38 provided the information.
647647 39 (9) Comply with a legal obligation.
648648 40 Sec. 5. (a) Law enforcement agencies may direct a business not
649649 41 to delete a consumer's personal information if the law enforcement
650650 42 agency:
651651 2022 IN 1261—LS 7000/DI 148 16
652652 1 (1) is actively investigating the consumer; and
653653 2 (2) has an active case number for the investigation.
654654 3 (b) Upon receiving a request under subsection (a), a business
655655 4 must not delete the consumer's personal information for at least
656656 5 ninety (90) days to allow the law enforcement agency to obtain a
657657 6 court issued subpoena, order, or warrant for the consumer's
658658 7 personal information.
659659 8 (c) For good cause and only to the extent necessary for
660660 9 investigatory purposes, a law enforcement agency may direct the
661661 10 business not to delete the consumer's personal information for an
662662 11 additional ninety (90) day period.
663663 12 (d) Except as provided in subsection (e), a business that has
664664 13 received direction from law enforcement under this section shall
665665 14 not use the consumer's personal information for any purpose other
666666 15 than retaining it to produce to law enforcement in response to a
667667 16 court issued subpoena, order, or warrant.
668668 17 (e) If a verified consumer requestor's deletion request is subject
669669 18 to an exemption from deletion under this article, a business that
670670 19 has received direction from law enforcement under this section
671671 20 may continue to use the consumer's personal information for
672672 21 purposes of the exemption.
673673 22 (f) A business that refuses a verified consumer requestor's
674674 23 verified consumer request under this section shall notify the
675675 24 verified consumer requestor that:
676676 25 (1) it is acting under this section; and
677677 26 (2) the particular subsection that it is relying on to refuse the
678678 27 verified consumer requestor's verified request.
679679 28 Chapter 6. Right to Correct
680680 29 Sec. 1. A business that receives a verifiable consumer request to
681681 30 correct inaccurate personal information shall use commercially
682682 31 reasonable efforts to correct the inaccurate personal information
683683 32 as directed by the consumer.
684684 33 Chapter 7. Right to Opt Out of Sale or Sharing
685685 34 Sec. 1. At any time, a consumer is entitled to opt out of sale or
686686 35 sharing by prohibiting a business from selling or sharing the
687687 36 consumer's personal information.
688688 37 Sec. 2. (a) A business that sells or shares a consumer's personal
689689 38 information with a third party shall provide notice to the consumer
690690 39 that:
691691 40 (1) the consumer's personal information may be sold or
692692 41 shared; and
693693 42 (2) the consumer has the right to opt out of sale or sharing of
694694 2022 IN 1261—LS 7000/DI 148 17
695695 1 their personal information.
696696 2 (b) Except as provided in subsection (c), a business must not sell
697697 3 or share a consumer's personal information if the business has
698698 4 actual knowledge that the consumer is less than sixteen (16) years
699699 5 of age.
700700 6 (c) A business may sell or share a consumer's personal
701701 7 information knowing that the consumer is less than sixteen (16)
702702 8 years of age if:
703703 9 (1) the consumer, if the consumer is at least thirteen (13) years
704704 10 of age but less than sixteen (16) years of age; or
705705 11 (2) the consumer's parent or guardian, if the consumer is less
706706 12 than thirteen (13) years of age;
707707 13 has affirmatively authorized the sale or sharing of the consumer's
708708 14 personal information.
709709 15 (d) A business that willfully disregards the consumer's age shall
710710 16 be deemed to have had actual knowledge of the consumer's age.
711711 17 (e) A business that receives direction from a consumer not to sell
712712 18 or share the consumer's personal information shall not sell or
713713 19 share the consumer's personal information, unless the consumer
714714 20 subsequently provides consent.
715715 21 Chapter 8. Right to Restrict
716716 22 Sec. 1. At any time, a consumer may limit a business's use of the
717717 23 consumer's sensitive personal information:
718718 24 (1) to that which is necessary to perform the services or
719719 25 provide the goods reasonably expected by an average
720720 26 consumer who requests those goods or services;
721721 27 (2) to perform the services in IC 24-15-3-6(b)(2),
722722 28 IC 24-15-3-6(b)(4), and IC 24-15-3-6(b)(5); and
723723 29 (3) as otherwise authorized under this article.
724724 30 Chapter 9. Business Exceptions
725725 31 Sec. 1. A business's duties under this article do not restrict the
726726 32 business's ability to do the following:
727727 33 (1) Comply with federal, state, or local laws.
728728 34 (2) Comply with a court order or subpoena to provide
729729 35 information.
730730 36 (3) Comply with a civil, criminal, or regulatory inquiry,
731731 37 investigation, subpoena, or summons by federal, state, or local
732732 38 authorities.
733733 39 (4) Cooperate with law enforcement agencies concerning
734734 40 conduct or activity that the business, service provider, or
735735 41 third party reasonably and in good faith believes may violate
736736 42 federal, state, or local law.
737737 2022 IN 1261—LS 7000/DI 148 18
738738 1 (5) Cooperate with a government agency request for
739739 2 emergency access to a consumer's personal information if a
740740 3 natural person is at risk or danger of death or serious physical
741741 4 injury if:
742742 5 (A) the request is approved by a high ranking agency
743743 6 officer for emergency access to a consumer's personal
744744 7 information;
745745 8 (B) the request is based on the agency's good faith
746746 9 determination that it has a lawful basis to access the
747747 10 information on a nonemergency basis; or
748748 11 (C) the agency agrees to petition a court for an appropriate
749749 12 order within three (3) days and to destroy the information
750750 13 if that order is not granted.
751751 14 (6) Exercise or defend legal claims.
752752 15 (7) Collect, use, retain, sell, share, or disclose a consumer's
753753 16 personal information that is:
754754 17 (A) deidentified; or
755755 18 (B) aggregate consumer information.
756756 19 (8) Collect, sell, or share a consumer's personal information
757757 20 if every aspect of that commercial conduct takes place wholly
758758 21 outside of Indiana.
759759 22 Sec. 2. A business's duties under this article shall not:
760760 23 (1) apply where compliance by the business would violate an
761761 24 evidentiary privilege under state law; and
762762 25 (2) prevent a business from providing the personal
763763 26 information of a consumer to a person covered by an
764764 27 evidentiary privilege under state law as part of a privileged
765765 28 communication.
766766 29 Sec. 3. (a) A business may, depending on the complexity of the
767767 30 verifiable consumer request and number of other verifiable
768768 31 consumer requests, extend its response time period by up to ninety
769769 32 (90) days total when necessary. The business shall inform the
770770 33 verifiable consumer requestor of any such extension within
771771 34 forty-five (45) days of receipt of the verified consumer request,
772772 35 together with the reasons for the delay.
773773 36 (b) If the business chooses not to take action on the verifiable
774774 37 consumer requestor's verifiable consumer request, the business
775775 38 shall immediately notify the verifiable consumer requestor of the
776776 39 reasons for not taking action and any rights the verifiable
777777 40 consumer requestor may have to appeal the decision to the
778778 41 business. The notice under this subdivision must occur within the
779779 42 permitted response time period.
780780 2022 IN 1261—LS 7000/DI 148 19
781781 1 (c) If a verifiable consumer requestor's verifiable consumer
782782 2 request is manifestly unfounded or excessive, a business may
783783 3 either:
784784 4 (1) charge a reasonable fee, taking into account the
785785 5 administrative costs of providing the information or
786786 6 communication or taking the action requested; or
787787 7 (2) refuse to act on the request and notify the verifiable
788788 8 consumer requestor of the reason for refusing the verifiable
789789 9 consumer request.
790790 10 The business bears the burden of proving that a verified consumer
791791 11 request is manifestly unfounded or excessive.
792792 12 Sec. 4. (a) A business that discloses a consumer's personal
793793 13 information to a service provider or contractor is not liable if:
794794 14 (1) the service provider or contractor uses the consumer's
795795 15 personal information in violation of this article; and
796796 16 (2) at the time of disclosing the personal information, the
797797 17 business does not have:
798798 18 (A) actual knowledge; or
799799 19 (B) reason to believe;
800800 20 that the service provider or contractor intends to commit such
801801 21 a violation.
802802 22 (b) A service provider or contractor is not liable for a business
803803 23 that it provides services to if the business violates this article.
804804 24 (c) A business that discloses a consumer's personal information
805805 25 to a third party under a written contract is not liable if:
806806 26 (1) the third party uses it in violation of this article; and
807807 27 (2) at the time of disclosing the personal information, the
808808 28 business does not have:
809809 29 (A) actual knowledge; or
810810 30 (B) reason to believe;
811811 31 that the third party intends to commit the violation.
812812 32 Sec. 5. (a) A verifiable consumer request for:
813813 33 (1) access to specific pieces of personal information, under
814814 34 IC 24-15-4-1;
815815 35 (2) deletion of a consumer's personal information, under
816816 36 IC 24-15-5-2; or
817817 37 (3) correction of inaccurate personal information, under
818818 38 IC 24-15-6-1;
819819 39 does not extend to personal information about the consumer that
820820 40 belongs to, or that the business maintains on behalf of, another
821821 41 individual.
822822 42 (b) A business:
823823 2022 IN 1261—LS 7000/DI 148 20
824824 1 (1) may rely on representations made in a verifiable consumer
825825 2 request;
826826 3 (2) is under no legal requirement to seek out other persons
827827 4 that may have rights to personal information; and
828828 5 (3) is under no legal obligation to take any action under this
829829 6 article in the event of a dispute between or among persons
830830 7 claiming rights to personal information in the business's
831831 8 possession.
832832 9 Sec. 6. The right to deletion (IC 24-15-5) and the right to opt out
833833 10 of sale or sharing (IC 24-15-7) shall not apply to the following:
834834 11 (1) A business's use, disclosure, or sale of particular pieces of
835835 12 a consumer's personal information if the consumer has
836836 13 consented to the business's use, disclosure, or sale of that
837837 14 information to produce a physical item, including a school
838838 15 yearbook containing the consumer's photograph if:
839839 16 (A) the business has incurred significant expense in
840840 17 reliance on the consumer's consent;
841841 18 (B) compliance with the consumer's request to opt out of
842842 19 the sale of the consumer's personal information or to delete
843843 20 the consumer's personal information would not be
844844 21 commercially reasonable; and
845845 22 (C) the business complies with the consumer's request as
846846 23 soon as it is commercially reasonable to do so.
847847 24 (2) A commercial credit reporting agency's collection,
848848 25 processing, sale, or disclosure of business controller
849849 26 information to the extent the commercial credit reporting
850850 27 agency uses the business controller information solely to:
851851 28 (A) identify the relationship of a consumer to a business
852852 29 that the consumer owns; or
853853 30 (B) contact the consumer only in the consumer's role as the
854854 31 owner, director, officer, or management employee of the
855855 32 business.
856856 33 (3) Vehicle information or ownership information retained or
857857 34 shared between:
858858 35 (A) a new motor vehicle dealer (as defined in
859859 36 IC 9-32-2-18.3); and
860860 37 (B) the vehicle's manufacturer (as defined in IC 9-13-2-97);
861861 38 for a vehicle repair covered by a vehicle warranty or a recall
862862 39 conducted under 49 U.S.C. 30118-30120 if the information is
863863 40 not used for any other purpose.
864864 41 Chapter 10. Enforcement
865865 42 Sec. 1. The division of consumer protection, created under
866866 2022 IN 1261—LS 7000/DI 148 21
867867 1 IC 4-6-9, shall enforce this article.
868868 2022 IN 1261—LS 7000/DI 148