1 | 1 | | |
---|
2 | 2 | | |
---|
3 | 3 | | EXPLANATION: CAPITALS INDICATE MAT TER ADDED TO EXISTIN G LAW. |
---|
4 | 4 | | [Brackets] indicate matter deleted from existing law. |
---|
5 | 5 | | *hb0807* |
---|
6 | 6 | | |
---|
7 | 7 | | HOUSE BILL 807 |
---|
8 | 8 | | I3 3lr1109 |
---|
9 | 9 | | CF SB 698 |
---|
10 | 10 | | By: Delegate Love |
---|
11 | 11 | | Introduced and read first time: February 8, 2023 |
---|
12 | 12 | | Assigned to: Economic Matters |
---|
13 | 13 | | |
---|
14 | 14 | | A BILL ENTITLED |
---|
15 | 15 | | |
---|
16 | 16 | | AN ACT concerning 1 |
---|
17 | 17 | | |
---|
18 | 18 | | Consumer Protection – Online and Biometric Data Privacy 2 |
---|
19 | 19 | | |
---|
20 | 20 | | FOR the purpose of regulating the manner in which a controller or a processor in possession 3 |
---|
21 | 21 | | of a consumer’s personal data may process the consumer’s personal data; authorizing 4 |
---|
22 | 22 | | a consumer to exercise certain rights in regards to the consumer’s personal data; 5 |
---|
23 | 23 | | requiring a controller of personal data to establish a method for a consumer to 6 |
---|
24 | 24 | | exercise certain rights in regards to the consumer’s personal data; requiring a 7 |
---|
25 | 25 | | controller to comply with a request by a consumer to exercise a certain right in a 8 |
---|
26 | 26 | | certain manner, except under certain circumstances; authorizing a consumer to 9 |
---|
27 | 27 | | designate an authorized agent to act on the consumer’s behalf to opt out of the 10 |
---|
28 | 28 | | processing of the consumer’s personal data; requiring a controller to provide a 11 |
---|
29 | 29 | | consumer with a certain privacy notice; requiring a controller that uses a processor 12 |
---|
30 | 30 | | to process the personal data of consumers to enter into a contract with the processor 13 |
---|
31 | 31 | | that governs the processor’s data processing procedures; requiring a controller to 14 |
---|
32 | 32 | | conduct and document a data protection assessment for consumer data processing 15 |
---|
33 | 33 | | activities that present a heightened risk of harm to a consumer; regulating the use 16 |
---|
34 | 34 | | of biometric data, including requiring controllers in possession of biometric data to 17 |
---|
35 | 35 | | develop a policy, made available to the public, establishing a retention schedule and 18 |
---|
36 | 36 | | destruction guidelines for biometric data; authorizing an individual alleging a 19 |
---|
37 | 37 | | violation of this Act to bring a civil action against the offending controller under 20 |
---|
38 | 38 | | certain circumstances; making a violation of this Act an unfair, abusive, or deceptive 21 |
---|
39 | 39 | | trade practice that is subject to enforcement and penalties under the Maryland 22 |
---|
40 | 40 | | Consumer Protection Act; establishing the Task Force to Study Online Data Privacy; 23 |
---|
41 | 41 | | and generally relating to online and biometric data privacy. 24 |
---|
42 | 42 | | |
---|
43 | 43 | | BY repealing and reenacting, with amendments, 25 |
---|
44 | 44 | | Article – Commercial Law 26 |
---|
45 | 45 | | Section 13–301(14)(xxxv) and 13–408 27 |
---|
46 | 46 | | Annotated Code of Maryland 28 |
---|
47 | 47 | | (2013 Replacement Volume and 2022 Supplement) 29 |
---|
48 | 48 | | 2 HOUSE BILL 807 |
---|
49 | 49 | | |
---|
50 | 50 | | |
---|
51 | 51 | | BY repealing and reenacting, without amendments, 1 |
---|
52 | 52 | | Article – Commercial Law 2 |
---|
53 | 53 | | Section 13–301(14)(xxxvi) 3 |
---|
54 | 54 | | Annotated Code of Maryland 4 |
---|
55 | 55 | | (2013 Replacement Volume and 2022 Supplement) 5 |
---|
56 | 56 | | |
---|
57 | 57 | | BY adding to 6 |
---|
58 | 58 | | Article – Commercial Law 7 |
---|
59 | 59 | | Section 13–301(xxxvii); and 14–4501 through 14–4512 to be under the new subtitle 8 |
---|
60 | 60 | | “Subtitle 45. Online and Biometric Data Privacy Act” 9 |
---|
61 | 61 | | Annotated Code of Maryland 10 |
---|
62 | 62 | | (2013 Replacement Volume and 2022 Supplement) 11 |
---|
63 | 63 | | |
---|
64 | 64 | | SECTION 1. BE IT ENACTED BY THE GENERAL ASSE MBLY OF MARYLAND, 12 |
---|
65 | 65 | | That the Laws of Maryland read as follows: 13 |
---|
66 | 66 | | |
---|
67 | 67 | | Article – Commercial Law 14 |
---|
68 | 68 | | |
---|
69 | 69 | | 13–301. 15 |
---|
70 | 70 | | |
---|
71 | 71 | | Unfair, abusive, or deceptive trade practices include any: 16 |
---|
72 | 72 | | |
---|
73 | 73 | | (14) Violation of a provision of: 17 |
---|
74 | 74 | | |
---|
75 | 75 | | (xxxv) Section 11–210 of the Education Article; [or] 18 |
---|
76 | 76 | | |
---|
77 | 77 | | (xxxvi) Title 14, Subtitle 44 of this article; or 19 |
---|
78 | 78 | | |
---|
79 | 79 | | (XXXVII) TITLE 14, SUBTITLE 45 OF THIS ARTICLE; OR 20 |
---|
80 | 80 | | |
---|
81 | 81 | | 13–408. 21 |
---|
82 | 82 | | |
---|
83 | 83 | | (a) In addition to any action by the Division or Attorney General authorized by 22 |
---|
84 | 84 | | this title and any other action otherwise authorized by law, any person may bring an action 23 |
---|
85 | 85 | | to recover for injury or loss sustained by [him] THE PERSON as the result of a practice 24 |
---|
86 | 86 | | prohibited by this title. 25 |
---|
87 | 87 | | |
---|
88 | 88 | | (b) Any person who brings an action to recover for injury or loss under this section 26 |
---|
89 | 89 | | and who is awarded damages may also seek, and the court may award, reasonable 27 |
---|
90 | 90 | | attorney’s fees. 28 |
---|
91 | 91 | | |
---|
92 | 92 | | (c) If it appears to the satisfaction of the court, at any time, that an action is 29 |
---|
93 | 93 | | brought in bad faith or is of a frivolous nature, the court may order the offending party to 30 |
---|
94 | 94 | | pay to the other party reasonable attorney’s fees. 31 |
---|
95 | 95 | | HOUSE BILL 807 3 |
---|
96 | 96 | | |
---|
97 | 97 | | |
---|
98 | 98 | | (d) Notwithstanding any other provision of this section, a person may not bring 1 |
---|
99 | 99 | | an action under this section to recover for injuries sustained as a result of the professional 2 |
---|
100 | 100 | | services provided by a health care provider, as defined in § 3–2A–01 of the Courts Article. 3 |
---|
101 | 101 | | |
---|
102 | 102 | | SUBTITLE 45. ONLINE AND BIOMETRIC DATA PRIVACY ACT. 4 |
---|
103 | 103 | | |
---|
104 | 104 | | 14–4501. 5 |
---|
105 | 105 | | |
---|
106 | 106 | | (A) IN THIS SUBTITLE THE FOLLOWING WORDS HAVE THE MEANINGS 6 |
---|
107 | 107 | | INDICATED. 7 |
---|
108 | 108 | | |
---|
109 | 109 | | (B) “AFFILIATE” MEANS A PERSON THAT: 8 |
---|
110 | 110 | | |
---|
111 | 111 | | (1) SHARES COMMON BRANDIN G WITH ANOTHER PERSON; OR 9 |
---|
112 | 112 | | |
---|
113 | 113 | | (2) CONTROLS, IS CONTROLLED BY , OR IS UNDER COMMON C ONTROL 10 |
---|
114 | 114 | | WITH ANOTHER PERSON. 11 |
---|
115 | 115 | | |
---|
116 | 116 | | (C) “AUTHENTICATE ” MEANS TO USE REASONA BLE MEANS TO DETERMI NE 12 |
---|
117 | 117 | | THAT A REQUEST TO EX ERCISE A CONSUMER RIGHT IN ACCORDANCE WITH § 13 |
---|
118 | 118 | | 14–4504 OF THIS SUBTITLE IS BEING MADE BY , OR ON BEHALF OF , AN INDIVIDUAL 14 |
---|
119 | 119 | | WHO IS ENTITLED TO E XERCISE THE CONSUMER RIGHT . 15 |
---|
120 | 120 | | |
---|
121 | 121 | | (D) (1) “BIOMETRIC DATA ” MEANS DATA GENERATED BY AUTOMATIC 16 |
---|
122 | 122 | | MEASUREMENTS OF THE BIOLOGICAL CHARA CTERISTICS OF A CONSUMER THAT ARE 17 |
---|
123 | 123 | | USED TO IDENTIFY A S PECIFIC CONSUMER . 18 |
---|
124 | 124 | | |
---|
125 | 125 | | (2) “BIOMETRIC DATA ” INCLUDES: 19 |
---|
126 | 126 | | |
---|
127 | 127 | | (I) A FINGERPRINT ; 20 |
---|
128 | 128 | | |
---|
129 | 129 | | (II) A VOICE PRINT; 21 |
---|
130 | 130 | | |
---|
131 | 131 | | (III) EYE RETINAS OR IRISES; 22 |
---|
132 | 132 | | |
---|
133 | 133 | | (IV) BIOMETRIC SCANS CREAT ED FROM PHYSICAL OR DIGITAL 23 |
---|
134 | 134 | | PHOTOGRAPHS ; AND 24 |
---|
135 | 135 | | |
---|
136 | 136 | | (V) ANY OTHER UNIQUE BIOLOGICAL PA TTERNS OR 25 |
---|
137 | 137 | | CHARACTERISTICS . 26 |
---|
138 | 138 | | |
---|
139 | 139 | | (3) “BIOMETRIC DATA ” DOES NOT INCLUDE : 27 |
---|
140 | 140 | | |
---|
141 | 141 | | (I) A PHYSICAL OR DIGITAL PHOTOGRAPH ; 28 4 HOUSE BILL 807 |
---|
142 | 142 | | |
---|
143 | 143 | | |
---|
144 | 144 | | |
---|
145 | 145 | | (II) A VIDEO OR AN AUDIO RECORDING; OR 1 |
---|
146 | 146 | | |
---|
147 | 147 | | (III) INFORMATION COLLECTED , USED, OR STORED FOR HEALTH 2 |
---|
148 | 148 | | CARE TREATMENT , PAYMENT, OR OPERATIONS UNDER THE FEDERAL HEALTH 3 |
---|
149 | 149 | | INSURANCE PORTABILITY AND ACCOUNTABILITY ACT OF 1996. 4 |
---|
150 | 150 | | |
---|
151 | 151 | | (E) “BUSINESS ASSOCIATE ” HAS THE MEANING STATED I N THE FEDERAL 5 |
---|
152 | 152 | | HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT OF 1996. 6 |
---|
153 | 153 | | |
---|
154 | 154 | | (F) “CHILD” HAS THE MEANING STATED IN THE FEDERAL CHILDREN’S 7 |
---|
155 | 155 | | ONLINE PRIVACY PROTECTION ACT OF 1998. 8 |
---|
156 | 156 | | |
---|
157 | 157 | | (G) “CONFIDENTIAL DATA” MEANS INFORMATION THAT CAN BE USED TO 9 |
---|
158 | 158 | | UNIQUELY IDENTIFY A CONSUMER OR A CONS UMER’S ACCOUNT OR PROPERTY , 10 |
---|
159 | 159 | | INCLUDING: 11 |
---|
160 | 160 | | |
---|
161 | 161 | | (1) A GENETIC MARKER ; 12 |
---|
162 | 162 | | |
---|
163 | 163 | | (2) GENETIC TESTING INFOR MATION; 13 |
---|
164 | 164 | | |
---|
165 | 165 | | (3) A UNIQUE IDENTIFIER NU MBER TO LOCATE AN AC COUNT OR 14 |
---|
166 | 166 | | PROPERTY; 15 |
---|
167 | 167 | | |
---|
168 | 168 | | (4) AN ACCOUNT NUMBER ; 16 |
---|
169 | 169 | | |
---|
170 | 170 | | (5) A PERSONAL IDENTIFICAT ION NUMBER; 17 |
---|
171 | 171 | | |
---|
172 | 172 | | (6) A PASSCODE; 18 |
---|
173 | 173 | | |
---|
174 | 174 | | (7) A DRIVER’S LICENSE NUMBER ; AND 19 |
---|
175 | 175 | | |
---|
176 | 176 | | (8) A SOCIAL SECURITY NUMB ER. 20 |
---|
177 | 177 | | |
---|
178 | 178 | | (H) (1) “CONSENT” MEANS A SPECIFIC, DISCRETE, FREELY GIVEN , 21 |
---|
179 | 179 | | UNAMBIGUOUS , AND INFORMED AGREEME NT GIVEN BY A CONSUM ER WHO IS NOT 22 |
---|
180 | 180 | | UNDER ANY DURESS OR UNDUE INFLUENCE FROM A CONTROLLER OR PROC ESSOR 23 |
---|
181 | 181 | | TO ALLOW THE PROCESS ING OF THE CONSUMER ’S PERSONAL DATA FOR A 24 |
---|
182 | 182 | | PARTICULAR PURPOSE . 25 |
---|
183 | 183 | | |
---|
184 | 184 | | (2) “CONSENT” INCLUDES: 26 |
---|
185 | 185 | | |
---|
186 | 186 | | (I) A WRITTEN STATEMENT ; 27 HOUSE BILL 807 5 |
---|
187 | 187 | | |
---|
188 | 188 | | |
---|
189 | 189 | | |
---|
190 | 190 | | (II) A WRITTEN STATEMENT BY ELECTRONIC MEANS ; 1 |
---|
191 | 191 | | |
---|
192 | 192 | | (III) IN THE CONTEXT OF EMP LOYMENT, A RELEASE EXECUTED 2 |
---|
193 | 193 | | BY AN EMPLOYEE AS A CONDITION OF EMPLOYM ENT; AND 3 |
---|
194 | 194 | | |
---|
195 | 195 | | (IV) ANY OTHER UNAMBIGUOUS AF FIRMATIVE ACTION . 4 |
---|
196 | 196 | | |
---|
197 | 197 | | (3) “CONSENT” DOES NOT INCLUDE : 5 |
---|
198 | 198 | | |
---|
199 | 199 | | (I) ACCEPTANCE OF A GENER AL OR BROAD TERMS OF USE OR 6 |
---|
200 | 200 | | SIMILAR DOCUMENT THA T CONTAINS DESCRIPTI ONS OF PERSONAL DATA 7 |
---|
201 | 201 | | PROCESSING ALONG WIT H OTHER UNRELATED INFORMATIO N; 8 |
---|
202 | 202 | | |
---|
203 | 203 | | (II) HOVERING OVER , MUTING, PAUSING, OR CLOSING A PIECE 9 |
---|
204 | 204 | | OF CONTENT; OR 10 |
---|
205 | 205 | | |
---|
206 | 206 | | (III) AGREEMENT OBTAINED TH ROUGH THE USE OF DAR K 11 |
---|
207 | 207 | | PATTERNS. 12 |
---|
208 | 208 | | |
---|
209 | 209 | | (I) “CONTROL” MEANS: 13 |
---|
210 | 210 | | |
---|
211 | 211 | | (1) OWNERSHIP OF , OR THE POWER TO VOTE , MORE THAN 50% OF 14 |
---|
212 | 212 | | THE OUTSTANDING SHAR ES OF ANY CLASS OF V OTING SECURITY OF A COMPAN Y; 15 |
---|
213 | 213 | | |
---|
214 | 214 | | (2) CONTROL IN ANY MANNER OVER THE ELECTION OF A MAJORITY 16 |
---|
215 | 215 | | OF THE DIRECTORS OF A COMPANY OR OF INDIVIDUALS EX ERCISING A SIMILAR 17 |
---|
216 | 216 | | FUNCTION; OR 18 |
---|
217 | 217 | | |
---|
218 | 218 | | (3) THE POWER TO EXERCISE CONTROLLING INFLUENC E OVER THE 19 |
---|
219 | 219 | | MANAGEMENT OF A COMP ANY. 20 |
---|
220 | 220 | | |
---|
221 | 221 | | (J) (1) “CONSUMER” MEANS AN INDIVIDUAL WHO IS A RESIDENT OF THE 21 |
---|
222 | 222 | | STATE. 22 |
---|
223 | 223 | | |
---|
224 | 224 | | (2) “CONSUMER” DOES NOT INCLUDE AN INDIVIDUAL ACTING : 23 |
---|
225 | 225 | | |
---|
226 | 226 | | (I) IN A COMMERCIAL OR EMPLOY MENT CONTEXT ; OR 24 |
---|
227 | 227 | | |
---|
228 | 228 | | (II) AS AN EMPLOYEE , AN OWNER, A DIRECTOR, AN OFFICER, OR 25 |
---|
229 | 229 | | A CONTRACTOR OF A COMP ANY, A PARTNERSHIP , A SOLE PROPRIETORSHIP , A 26 |
---|
230 | 230 | | NONPROFIT ORGANIZATION , OR ANY GOVERNMENT AGENCY WH OSE 27 |
---|
231 | 231 | | COMMUNICATIONS OR TR ANSACTIONS WITH A CONTROLLER OCCUR ONLY WITHIN 28 6 HOUSE BILL 807 |
---|
232 | 232 | | |
---|
233 | 233 | | |
---|
234 | 234 | | THE CONTEXT OF TH E INDIVIDUAL’S ROLE WITH THE COMP ANY, PARTNERSHIP , 1 |
---|
235 | 235 | | SOLE PROPRIETORSHIP , NONPROFIT ORGANIZATION , OR GOVERNMENT AGENCY . 2 |
---|
236 | 236 | | |
---|
237 | 237 | | (K) “CONTROLLER ” MEANS A PERSON THAT , ALONE OR JOINTLY WIT H 3 |
---|
238 | 238 | | OTHERS, DETERMINES THE PURPO SE AND MEANS OF PROC ESSING PERSONAL DATA . 4 |
---|
239 | 239 | | |
---|
240 | 240 | | (L) “COVERED ENTITY ” HAS THE MEANING STATED IN THE FEDERAL 5 |
---|
241 | 241 | | HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT OF 1996. 6 |
---|
242 | 242 | | |
---|
243 | 243 | | (M) (1) “DARK PATTERN ” MEANS A USER INTERFA CE DESIGNED TO 7 |
---|
244 | 244 | | SUBVERT OR IMPAIR , OR MANIPULATE WITH T HE SUBSTANTIAL EFFEC T OF 8 |
---|
245 | 245 | | SUBVERTING OR IMPAIR ING, USER AUTONOMY , DECISION MAKING, OR CHOICE. 9 |
---|
246 | 246 | | |
---|
247 | 247 | | (2) “DARK PATTERN ” INCLUDES ANY PRACTICE THE FEDERAL 10 |
---|
248 | 248 | | TRADE COMMISSION REFERS TO AS A “DARK PATTERN ”. 11 |
---|
249 | 249 | | |
---|
250 | 250 | | (N) “DECISIONS THAT PRODUC E LEGAL OR SIMILARLY SIGNIFICANT 12 |
---|
251 | 251 | | EFFECTS CONCERNING THE CONSUMER ” MEANS DECISIONS MADE BY A 13 |
---|
252 | 252 | | CONTROLLER THAT RESU LT IN THE PROVISION OR DENIAL BY THE CON TROLLER OF: 14 |
---|
253 | 253 | | |
---|
254 | 254 | | (1) FINANCIAL OR LENDING SERVICES; 15 |
---|
255 | 255 | | |
---|
256 | 256 | | (2) HOUSING; 16 |
---|
257 | 257 | | |
---|
258 | 258 | | (3) INSURANCE; 17 |
---|
259 | 259 | | |
---|
260 | 260 | | (4) EDUCATION ENROLLMENT OR OPPORTUNITY ; 18 |
---|
261 | 261 | | |
---|
262 | 262 | | (5) CRIMINAL JUSTICE ; 19 |
---|
263 | 263 | | |
---|
264 | 264 | | (6) EMPLOYMENT OPPORTUNIT IES; 20 |
---|
265 | 265 | | |
---|
266 | 266 | | (7) HEALTH CARE SERVICES ; OR 21 |
---|
267 | 267 | | |
---|
268 | 268 | | (8) ACCESS TO ESSENTIAL G OODS OR SERVICES . 22 |
---|
269 | 269 | | |
---|
270 | 270 | | (O) “DE–IDENTIFIED DATA ” MEANS DATA THAT CANN OT REASONABLY BE 23 |
---|
271 | 271 | | USED TO INFER INFORM ATION ABOUT, OR OTHERWISE BE LINK ED TO: 24 |
---|
272 | 272 | | |
---|
273 | 273 | | (1) AN IDENTIFIED OR IDEN TIFIABLE INDIVIDUAL; OR 25 |
---|
274 | 274 | | |
---|
275 | 275 | | (2) A DEVICE LINKED TO AN IDENTIFIED OR IDE NTIFIABLE 26 |
---|
276 | 276 | | INDIVIDUAL. 27 HOUSE BILL 807 7 |
---|
277 | 277 | | |
---|
278 | 278 | | |
---|
279 | 279 | | |
---|
280 | 280 | | (P) “IDENTIFIED OR IDENTIF IABLE INDIVIDUAL ” MEANS A CONSUMER WHO 1 |
---|
281 | 281 | | CAN READILY BE IDENTIFIED, EITHER DIRECTLY OR INDIRECT LY. 2 |
---|
282 | 282 | | |
---|
283 | 283 | | (Q) (1) “PERSONAL DATA ” MEANS ANY INFORMATIO N THAT IS LINKED OR 3 |
---|
284 | 284 | | CAN BE REASONABLY LINKED TO AN IDENTIFIED OR IDENTIFIABLE INDIVID UAL. 4 |
---|
285 | 285 | | |
---|
286 | 286 | | (2) “PERSONAL DATA ” DOES NOT INCLUDE : 5 |
---|
287 | 287 | | |
---|
288 | 288 | | (I) DE–IDENTIFIED DATA ; OR 6 |
---|
289 | 289 | | |
---|
290 | 290 | | (II) PUBLICLY AVAILABLE IN FORMATION. 7 |
---|
291 | 291 | | |
---|
292 | 292 | | (R) (1) “PRECISE GEOLOCATION D ATA” MEANS INFORMATION DE RIVED 8 |
---|
293 | 293 | | FROM TECHNOLOGY THAT CAN PRECISELY AND AC CURATELY IDENTIFY THE 9 |
---|
294 | 294 | | SPECIFIC LOCATION OF A CONSUMER WITHIN A RADIUS OF 1,750 FEET. 10 |
---|
295 | 295 | | |
---|
296 | 296 | | (2) “PRECISE GEOLOCATION D ATA” INCLUDES GLOBAL POSITIONING 11 |
---|
297 | 297 | | SYSTEM LEVEL LATITUD E AND LONGITUDE COOR DINATES OR OTHER SIMILAR 12 |
---|
298 | 298 | | MECHANIS MS. 13 |
---|
299 | 299 | | |
---|
300 | 300 | | (3) “PRECISE GEOLOCATION D ATA” DOES NOT INCLUDE : 14 |
---|
301 | 301 | | |
---|
302 | 302 | | (I) THE CONTENT OF COMMUN ICATIONS DATA GENERATED BY 15 |
---|
303 | 303 | | OR CONNECTED TO AN ADVANCED UTILITY MET ERING INFRASTRUCTURE SYSTEM; 16 |
---|
304 | 304 | | OR 17 |
---|
305 | 305 | | |
---|
306 | 306 | | (II) EQUIPMENT USED BY A UTILITY COMPANY. 18 |
---|
307 | 307 | | |
---|
308 | 308 | | (S) (1) “PROCESS” MEANS AN OPERATION P ERFORMED BY MANUAL O R 19 |
---|
309 | 309 | | AUTOMATED MEANS ON P ERSONAL DATA . 20 |
---|
310 | 310 | | |
---|
311 | 311 | | (2) “PROCESS” INCLUDES COLLECTING, USING, STORING, 21 |
---|
312 | 312 | | DISCLOSING, ANALYZING, DELETING, OR MODIFYING PERSONA L DATA. 22 |
---|
313 | 313 | | |
---|
314 | 314 | | (T) “PROCESSOR” MEANS A PERSON THAT PROCESSES, STORES, OR 23 |
---|
315 | 315 | | OTHERWISE USES PERSONAL DATA ON BEH ALF OF A CONTROLLER . 24 |
---|
316 | 316 | | |
---|
317 | 317 | | (U) “PROFILING” MEANS AUTOMATED PROC ESSING PERFORMED ON 25 |
---|
318 | 318 | | PERSONAL DATA TO EVA LUATE, ANALYZE, OR PREDICT PERSONAL ASPECTS 26 |
---|
319 | 319 | | RELATED TO AN IDENTI FIED OR IDENTIFIABLE INDIVIDUAL’S ECONOMIC SITUATION , 27 |
---|
320 | 320 | | HEALTH, PERSONAL PREFERENCES , INTERESTS, RELIABILITY, BEHAVIOR, 28 |
---|
321 | 321 | | LOCATION, OR MOVEMENTS . 29 8 HOUSE BILL 807 |
---|
322 | 322 | | |
---|
323 | 323 | | |
---|
324 | 324 | | |
---|
325 | 325 | | (V) “PROTECTED HEALTH INFO RMATION” HAS THE MEANING STATED IN 1 |
---|
326 | 326 | | THE FEDERAL HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT OF 2 |
---|
327 | 327 | | 1996. 3 |
---|
328 | 328 | | |
---|
329 | 329 | | (W) “PUBLICLY AVAILABLE IN FORMATION” MEANS INFORMATION TH AT: 4 |
---|
330 | 330 | | |
---|
331 | 331 | | (1) IS LAWFULLY MADE AVAI LABLE THROUGH : 5 |
---|
332 | 332 | | |
---|
333 | 333 | | (I) FEDERAL, STATE, OR LOCAL GOVERNMENT RECORDS ; OR 6 |
---|
334 | 334 | | |
---|
335 | 335 | | (II) WIDELY DISTRIBUTED ME DIA; AND 7 |
---|
336 | 336 | | |
---|
337 | 337 | | (2) A CONTROLLER HAS A REA SONABLE BASIS TO BEL IEVE A 8 |
---|
338 | 338 | | CONSUMER HAS LAWFULL Y MADE AVAILABLE TO THE GENERAL PUBLIC . 9 |
---|
339 | 339 | | |
---|
340 | 340 | | (X) (1) “SALE OF PERSONAL DATA ” MEANS THE EXCHANGE O F PERSONAL 10 |
---|
341 | 341 | | DATA BY A CONTROLLER TO A THIRD PARTY FOR MONETARY OR OTHE R VALUABLE 11 |
---|
342 | 342 | | CONSIDERATION . 12 |
---|
343 | 343 | | |
---|
344 | 344 | | (2) “SALE OF PERSONAL DATA ” DOES NOT INCLUDE : 13 |
---|
345 | 345 | | |
---|
346 | 346 | | (I) THE DISCLOSURE OF P ERSONAL DATA TO A PR OCESSOR 14 |
---|
347 | 347 | | THAT PROCESSES PERSO NAL DATA ON BEHALF O F A CONTROLLER ; 15 |
---|
348 | 348 | | |
---|
349 | 349 | | (II) THE DISCLOSURE OF P ERSONAL DATA TO A THIRD PARTY 16 |
---|
350 | 350 | | FOR PURPOSES OF PROV IDING A PRODUCT OR S ERVICE REQUESTED BY THE 17 |
---|
351 | 351 | | CONSUMER ; 18 |
---|
352 | 352 | | |
---|
353 | 353 | | (III) THE DISCLOSURE OR TRA NSFER OF PERSONAL DA TA TO AN 19 |
---|
354 | 354 | | AFFILIATE OF THE CON TROLLER; 20 |
---|
355 | 355 | | |
---|
356 | 356 | | (IV) THE DISCLOSURE OF PER SONAL DATA WHERE THE 21 |
---|
357 | 357 | | CONSUMER : 22 |
---|
358 | 358 | | |
---|
359 | 359 | | 1. DIRECTS THE CONTROLLE R TO DISCLOSE THE 23 |
---|
360 | 360 | | PERSONAL DATA ; OR 24 |
---|
361 | 361 | | |
---|
362 | 362 | | 2. INTENTIONALLY USES TH E CONTROLLER TO 25 |
---|
363 | 363 | | INTERACT WITH A THIR D PARTY; 26 |
---|
364 | 364 | | |
---|
365 | 365 | | (V) THE DISCLOSURE OF PER SONAL DATA THAT THE 27 |
---|
366 | 366 | | CONSUMER : 28 HOUSE BILL 807 9 |
---|
367 | 367 | | |
---|
368 | 368 | | |
---|
369 | 369 | | |
---|
370 | 370 | | 1. INTENTIONALLY MADE AV AILABLE TO THE GENER AL 1 |
---|
371 | 371 | | PUBLIC THROUGH A CHANNEL OF MASS ME DIA; AND 2 |
---|
372 | 372 | | |
---|
373 | 373 | | 2. DID NOT RESTRICT TO A SPECIFIC AUDIENCE ; OR 3 |
---|
374 | 374 | | |
---|
375 | 375 | | (VI) THE DISCLOSURE OR TRA NSFER OF PERSONAL DA TA TO A 4 |
---|
376 | 376 | | THIRD PARTY AS AN AS SET THAT IS PART OF AN ACTUAL OR PROPOSED MERGER, 5 |
---|
377 | 377 | | ACQUISITION, BANKRUPTCY , OR OTHER TRANSACTION WHERE THE THIRD PARTY 6 |
---|
378 | 378 | | ASSUMES CONTROL OF A LL OR PART OF THE CO NTROLLER’S ASSETS. 7 |
---|
379 | 379 | | |
---|
380 | 380 | | (Y) “SENSITIVE DATA ” MEANS PERSONAL DATA OF A CONSUMER , THAT 8 |
---|
381 | 381 | | INCLUDES: 9 |
---|
382 | 382 | | |
---|
383 | 383 | | (1) DATA REVEALING : 10 |
---|
384 | 384 | | |
---|
385 | 385 | | (I) RACIAL OR ETHNIC ORIG IN; 11 |
---|
386 | 386 | | |
---|
387 | 387 | | (II) RELIGIOUS BELIEFS ; 12 |
---|
388 | 388 | | |
---|
389 | 389 | | (III) MENTAL OR PHYSICAL HEALTH C ONDITION OR DIAGNOS ES; 13 |
---|
390 | 390 | | |
---|
391 | 391 | | (IV) SEX LIFE; 14 |
---|
392 | 392 | | |
---|
393 | 393 | | (V) SEXUAL ORIENTATION ; OR 15 |
---|
394 | 394 | | |
---|
395 | 395 | | (VI) CITIZENSHIP OR IMMIGR ATION STATUS; 16 |
---|
396 | 396 | | |
---|
397 | 397 | | (2) GENETIC OR BIOMETRIC DATA FO R THE PURPOSE OF UNI QUELY 17 |
---|
398 | 398 | | IDENTIFYING A CONSUMER ; 18 |
---|
399 | 399 | | |
---|
400 | 400 | | (3) PERSONAL DATA COLLECT ED FROM A KNOWN CHILD ; OR 19 |
---|
401 | 401 | | |
---|
402 | 402 | | (4) PRECISE GEOLOCATION D ATA. 20 |
---|
403 | 403 | | |
---|
404 | 404 | | (Z) (1) “TARGETED ADVERTISING ” MEANS DISPLAYING 21 |
---|
405 | 405 | | ADVERTISEMENTS TO A CONSUMER WHERE THE A DVERTISEMENT IS SELE CTED 22 |
---|
406 | 406 | | BASED ON PERSONAL DA TA OBTAINED OR INFER RED FROM THE CONSUMER ’S 23 |
---|
407 | 407 | | ACTIVITIES OVER TIME AND ACROSS NONAFFILI ATED WEBSITES OR ONL INE 24 |
---|
408 | 408 | | APPLICATIONS IN ORDER TO PREDICT THE CONSUMER ’S PREFERENCES OR 25 |
---|
409 | 409 | | INTERESTS. 26 |
---|
410 | 410 | | |
---|
411 | 411 | | (2) “TARGETED ADVERTISING ” DOES NOT INCLUDE : 27 10 HOUSE BILL 807 |
---|
412 | 412 | | |
---|
413 | 413 | | |
---|
414 | 414 | | |
---|
415 | 415 | | (I) ADVERTISEMENTS BASED ON ACTIVITIES WITHIN A 1 |
---|
416 | 416 | | CONTROLLER ’S OWN WEBSITES OR ONLIN E APPLICATIONS ; 2 |
---|
417 | 417 | | |
---|
418 | 418 | | (II) ADVERTISEMENTS BASED ON THE CONTEXT OF A 3 |
---|
419 | 419 | | CONSUMER ’S SEARCH QUERY OR VISIT TO A WEBSITE OR ONLINE APPLICATIO N; 4 |
---|
420 | 420 | | |
---|
421 | 421 | | (III) ADVERTISEMENTS DIRECT ED TO A CONSUMER IN 5 |
---|
422 | 422 | | RESPONSE TO THE CONS UMER’S REQUEST FOR INFORM ATION OR FEEDBACK ; OR 6 |
---|
423 | 423 | | |
---|
424 | 424 | | (IV) PROCESSING PERSONAL D ATA SOLELY TO MEASUR E OR 7 |
---|
425 | 425 | | REPORT ADVERTISING F REQUENCY, PERFORMANCE , OR REACH. 8 |
---|
426 | 426 | | |
---|
427 | 427 | | (AA) “THIRD PARTY” MEANS A PERSON OTHER THAN A CONSUMER , A 9 |
---|
428 | 428 | | CONTROLLER , A PROCESSOR, OR AN AFFILIATE OF T HE CONTROLLER OR 10 |
---|
429 | 429 | | PROCESSOR. 11 |
---|
430 | 430 | | |
---|
431 | 431 | | (BB) (1) “TRADE SECRET” MEANS INFORMATION TH AT: 12 |
---|
432 | 432 | | |
---|
433 | 433 | | (I) DERIVES INDEPENDENT ECONOMIC VALUE, ACTUAL OR 13 |
---|
434 | 434 | | POTENTIAL, FROM NOT BEING GENER ALLY KNOWN TO , AND NOT BEING READIL Y 14 |
---|
435 | 435 | | ASCERTAINABLE BY PRO PER MEANS BY, OTHER PERSONS WHO COULD OBTAIN 15 |
---|
436 | 436 | | ECONOMIC VALUE FROM THE INFORMATION ’S DISCLOSURE OR USE ; AND 16 |
---|
437 | 437 | | |
---|
438 | 438 | | (II) IS THE SUBJECT OF EFF ORTS THAT ARE REASON ABLE 17 |
---|
439 | 439 | | UNDER THE CIRCUMSTAN CES TO MAINTAIN THE SECRECY OF THE INFORMATION . 18 |
---|
440 | 440 | | |
---|
441 | 441 | | (2) “TRADE SECRET ” INCLUDES A FORMULA , PATTERN, 19 |
---|
442 | 442 | | COMPILATION , PROGRAM, DEVICE, METHOD, TECHNIQUE, OR PROCESS. 20 |
---|
443 | 443 | | |
---|
444 | 444 | | 14–4502. 21 |
---|
445 | 445 | | |
---|
446 | 446 | | THIS SUBTITLE APPLIES TO A PERSON THAT : 22 |
---|
447 | 447 | | |
---|
448 | 448 | | (1) CONDUCTS BUSINESS IN THE STATE; OR 23 |
---|
449 | 449 | | |
---|
450 | 450 | | (2) (I) PRODUCES SERVICES OR PRODUCTS THAT ARE TARGETED 24 |
---|
451 | 451 | | TO RESIDENTS OF THE STATE; AND 25 |
---|
452 | 452 | | |
---|
453 | 453 | | (II) DURING THE IMMEDIATELY PRECEDING CALENDAR Y EAR: 26 |
---|
454 | 454 | | |
---|
455 | 455 | | 1. CONTROLLED OR PROCESS ED THE PERSONAL DATA 27 |
---|
456 | 456 | | OF AT LEAST 100,000 CONSUMERS ; OR 28 HOUSE BILL 807 11 |
---|
457 | 457 | | |
---|
458 | 458 | | |
---|
459 | 459 | | |
---|
460 | 460 | | 2. CONTROLLED OR PROCESS ED THE PERSONAL DATA 1 |
---|
461 | 461 | | OF AT LEAST 25,000 CONSUMERS AND DERIVE D MORE THAN 25% OF ITS GROSS 2 |
---|
462 | 462 | | REVENUE FROM TH E SALE OF PERSONAL D ATA. 3 |
---|
463 | 463 | | |
---|
464 | 464 | | 14–4503. 4 |
---|
465 | 465 | | |
---|
466 | 466 | | (A) THIS SUBTITLE DOES NO T APPLY TO: 5 |
---|
467 | 467 | | |
---|
468 | 468 | | (1) A POLITICAL SUBDIVISIO N OR A UNIT OF A POLIT ICAL 6 |
---|
469 | 469 | | SUBDIVISION OF THE STATE; 7 |
---|
470 | 470 | | |
---|
471 | 471 | | (2) A STATE COURT , CLERK OF THE COURT , JUDGE, OR 8 |
---|
472 | 472 | | COMMISSIONER ; 9 |
---|
473 | 473 | | |
---|
474 | 474 | | (3) A NATIONAL SECURITIES ASSOCIATION THAT IS REGISTERED 10 |
---|
475 | 475 | | UNDER 15 U.S.C. § 78O–3 OF THE FEDERAL SECURITIES EXCHANGE ACT OF 1934; 11 |
---|
476 | 476 | | |
---|
477 | 477 | | (4) A COVERED ENTITY OR BU SINESS ASSOCIATE ; 12 |
---|
478 | 478 | | |
---|
479 | 479 | | (5) A PERSON THAT CONTROLS OR PROCESSES PERSONA L DATA 13 |
---|
480 | 480 | | SOLELY FOR THE PURPO SE OF COMPLETING A P AYMENT TRANSACTION ; OR 14 |
---|
481 | 481 | | |
---|
482 | 482 | | (6) AN ENTITY, OR AN AFFILIATE OF A N ENTITY, SUBJECT TO AN D IN 15 |
---|
483 | 483 | | COMPLIANCE WITH THE FEDERAL GRAMM–LEACH–BLILEY ACT. 16 |
---|
484 | 484 | | |
---|
485 | 485 | | (B) THE FOLLOWING INFORMA TION AND DATA IS EXE MPT FROM THIS 17 |
---|
486 | 486 | | SUBTITLE: 18 |
---|
487 | 487 | | |
---|
488 | 488 | | (1) PROTECTED HEALTH INFO RMATION UNDER THE FEDERAL 19 |
---|
489 | 489 | | HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT OF 1996; 20 |
---|
490 | 490 | | |
---|
491 | 491 | | (2) PATIENT–IDENTIFYING INFORMAT ION FOR PURPOSES OF 42 21 |
---|
492 | 492 | | U.S.C. § 290DD–2; 22 |
---|
493 | 493 | | |
---|
494 | 494 | | (3) IDENTIFIABLE PRIVATE INFORMATION THAT IS USED FOR 23 |
---|
495 | 495 | | PURPOSES OF THE FEDE RAL POLICY FOR THE P ROTECTION OF HUMAN SUBJECTS 24 |
---|
496 | 496 | | UNDER 45 C.F.R. 46; 25 |
---|
497 | 497 | | |
---|
498 | 498 | | (4) IDENTIFIABLE PRIVATE INFORMATION THAT IS OTHERWISE 26 |
---|
499 | 499 | | INFORMATION COLLECTE D AS PART OF HUMAN S UBJECTS RESEARCH IN 27 |
---|
500 | 500 | | ACCORDANCE WITH THE GOOD CLINICAL PR ACTICE GUIDELINES IS SUED BY THE 28 12 HOUSE BILL 807 |
---|
501 | 501 | | |
---|
502 | 502 | | |
---|
503 | 503 | | INTERNATIONAL COUNCIL FOR HARMONISATION OF TECHNICAL REQUIREMENTS 1 |
---|
504 | 504 | | FOR PHARMACEUTICALS FOR HUMAN USE; 2 |
---|
505 | 505 | | |
---|
506 | 506 | | (5) INFORMATION COLLECTED AS PART OF A CLINICA L TRIAL 3 |
---|
507 | 507 | | SUBJECT TO THE FEDERAL POLICY FOR THE PROTECTION OF HUMAN SUBJECTS, 4 |
---|
508 | 508 | | ALSO KNOWN AS THE COMMON RULE, IN ACCORDANCE WITH G OOD CLINICAL 5 |
---|
509 | 509 | | PRACTICE GUIDELINES ISSUED BY THE INTERNATIONAL COUNCIL FOR 6 |
---|
510 | 510 | | HARMONISATION OF TECHNICAL REQUIREMENTS FOR PHARMACEUTICALS FOR 7 |
---|
511 | 511 | | HUMAN USE OR IN ACCORDANCE WIT H THE HUMAN SUBJECT PROTECTION 8 |
---|
512 | 512 | | REQUIREMENTS OF THE U.S. FOOD AND DRUG ADMINISTRATION ; 9 |
---|
513 | 513 | | |
---|
514 | 514 | | (6) INFORMATION AND DOCUM ENTS CREATED FOR PUR POSES OF THE 10 |
---|
515 | 515 | | FEDERAL HEALTH CARE QUALITY IMPROVEMENT ACT OF 1986; 11 |
---|
516 | 516 | | |
---|
517 | 517 | | (7) PATIENT SAFETY WORK P RODUCT FOR PURPOSES OF THE 12 |
---|
518 | 518 | | FEDERAL PATIENT SAFETY AND QUALITY IMPROVEMENT ACT OF 2005; 13 |
---|
519 | 519 | | |
---|
520 | 520 | | (8) INFORMATION DERIVED F ROM AN Y OF THE HEALTH CARE 14 |
---|
521 | 521 | | RELATED INFORMATION LISTED IN THIS SUBSE CTION THAT IS DE –IDENTIFIED IN 15 |
---|
522 | 522 | | ACCORDANCE WITH THE REQUIREMENTS FOR DE –IDENTIFICATION IN ACCORDANCE 16 |
---|
523 | 523 | | WITH THE FEDERAL HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT 17 |
---|
524 | 524 | | OF 1996; 18 |
---|
525 | 525 | | |
---|
526 | 526 | | (9) INFORMATIO N ORIGINATING FROM A ND INTERMINGLED TO B E 19 |
---|
527 | 527 | | INDISTINGUISHABLE FROM, OR INFORMATION TREAT ED IN THE SAME MANNE R AS, 20 |
---|
528 | 528 | | INFORMATION EXEMPT U NDER THIS SUBSECTION THAT IS MAINTAINED B Y A 21 |
---|
529 | 529 | | COVERED ENTITY OR BU SINESS ASSOCIATE , PROGRAM, OR QUALIFIED SERVICE 22 |
---|
530 | 530 | | ORGANIZATION , AS SPECIFIED IN 42 U.S.C. § 290DD–2; 23 |
---|
531 | 531 | | |
---|
532 | 532 | | (10) INFORMATION USED FOR PUBLIC HEALTH ACTIVI TIES AND 24 |
---|
533 | 533 | | PURPOSES AS AUTHORIZ ED BY THE FEDERAL HEALTH INSURANCE PORTABILITY 25 |
---|
534 | 534 | | AND ACCOUNTABILITY ACT OF 1996, COMMUNITY HEALTH ACT IVITIES, AND 26 |
---|
535 | 535 | | POPULATION HEALTH AC TIVITIES; 27 |
---|
536 | 536 | | |
---|
537 | 537 | | (11) THE COLLECTION , MAINTENANCE , DISCLOSURE, SALE, 28 |
---|
538 | 538 | | COMMUNICATION , OR USE OF PERSONAL I NFORMATION BEARING O N A CONSUMER ’S 29 |
---|
539 | 539 | | CREDITWORTHINESS , CREDIT STANDING , CREDIT CAPACITY , CHARACTER , GENERAL 30 |
---|
540 | 540 | | REPUTATION, PERSONAL CHARACTERISTICS , OR MODE OF LIVING TO OR FROM A 31 |
---|
541 | 541 | | CONSUMER REPORTING A GENCY IF USE OF THE INFORMATI ON IS LIMITED BY AND 32 |
---|
542 | 542 | | AUTHORIZED UNDER THE FEDERAL FAIR CREDIT REPORTING ACT; 33 |
---|
543 | 543 | | |
---|
544 | 544 | | (12) PERSONAL DATA COLLECT ED, PROCESSED, SOLD, OR DISCLOSED 34 |
---|
545 | 545 | | IN COMPLIANCE WITH THE FEDERAL DRIVER’S PRIVACY PROTECTION ACT OF 1994; 35 HOUSE BILL 807 13 |
---|
546 | 546 | | |
---|
547 | 547 | | |
---|
548 | 548 | | |
---|
549 | 549 | | (13) PERSONAL DATA REGULAT ED BY THE FEDERAL FAMILY 1 |
---|
550 | 550 | | EDUCATIONAL RIGHTS AND PRIVACY ACT; 2 |
---|
551 | 551 | | |
---|
552 | 552 | | (14) PERSONAL DATA COLLECT ED, PROCESSED, SOLD, OR DISCLOSED 3 |
---|
553 | 553 | | IN COMPLIANCE WITH T HE FEDERAL FARM CREDIT ACT; 4 |
---|
554 | 554 | | |
---|
555 | 555 | | (15) DATA PROCESSED OR MAI NTAINED: 5 |
---|
556 | 556 | | |
---|
557 | 557 | | (I) IN THE COURSE OF AN I NDIVIDUAL APPLYING T O, 6 |
---|
558 | 558 | | EMPLOYED BY , OR ACTING AS AN AGEN T OR INDEPENDENT CON TRACTOR OF A 7 |
---|
559 | 559 | | CONTROLLER , PROCESSOR, OR THIRD PARTY, TO THE EXTENT THAT T HE DATA IS 8 |
---|
560 | 560 | | COLLECTED AND USED W ITHIN THE CONTEXT OF THE ROLE; 9 |
---|
561 | 561 | | |
---|
562 | 562 | | (II) AS THE EMERGENCY CONT ACT INFORMATION OF A 10 |
---|
563 | 563 | | CONSUMER USED FOR EMERGENCY C ONTACT PURPOSES ; OR 11 |
---|
564 | 564 | | |
---|
565 | 565 | | (III) THAT IS NECESSARY TO RETAIN TO ADMINISTER BENEFITS 12 |
---|
566 | 566 | | FOR ANOTHER INDIVIDU AL RELATING TO THE CONSUMER WHO IS THE SUBJECT O F 13 |
---|
567 | 567 | | THE INFORMATION UNDE R ITEM (I) OF THIS ITEM AND USED FOR THE PUR POSES OF 14 |
---|
568 | 568 | | ADMINISTERING THE BENEFITS; AND 15 |
---|
569 | 569 | | |
---|
570 | 570 | | (16) PERSONAL DATA COLLECT ED, PROCESSED, SOLD, OR DISCLOSED 16 |
---|
571 | 571 | | IN RELATION TO PRICE , ROUTE, OR SERVICE BY AN AIR CARRIER SU BJECT TO THE 17 |
---|
572 | 572 | | FEDERAL AIRLINE DEREGULATION ACT TO THE EXTENT THIS SUBTITLE IS 18 |
---|
573 | 573 | | PREEMPTED BY THE FEDERAL AIRLINE DEREGULATION ACT. 19 |
---|
574 | 574 | | |
---|
575 | 575 | | 14–4504. 20 |
---|
576 | 576 | | |
---|
577 | 577 | | (A) A CONSUMER MAY EXERCISE THE FOL LOWING RIGHTS IN REL ATION TO 21 |
---|
578 | 578 | | THE CONSUMER ’S PERSONAL DATA : 22 |
---|
579 | 579 | | |
---|
580 | 580 | | (1) CONFIRM WHETHER A CONTROLLER IS PROCES SING THE 23 |
---|
581 | 581 | | CONSUMER ’S PERSONAL DATA ; 24 |
---|
582 | 582 | | |
---|
583 | 583 | | (2) IF A CONTROLLER IS PR OCESSING A CONSUMER ’S PERSONAL 25 |
---|
584 | 584 | | DATA, ACCESS THE PERSONAL DATA ; 26 |
---|
585 | 585 | | |
---|
586 | 586 | | (3) CORRECT INACCURACIES IN THE CONSUMER ’S PERSONAL DATA ; 27 |
---|
587 | 587 | | |
---|
588 | 588 | | (4) DELETE PERSONAL DATA PROVIDED BY , OR OBTAINED ABOUT , 28 |
---|
589 | 589 | | THE CONSUMER ; 29 |
---|
590 | 590 | | 14 HOUSE BILL 807 |
---|
591 | 591 | | |
---|
592 | 592 | | |
---|
593 | 593 | | (5) IF THE PROCESSING OF PERSONAL DATA IS DON E BY AUTOMATIC 1 |
---|
594 | 594 | | MEANS, OBTAIN A COPY OF THE CONSUM ER’S PERSONAL DATA PROC ESSED BY THE 2 |
---|
595 | 595 | | CONTROLLER IN A PORT ABLE AND, TO THE EXTENT TECHNI CALLY FEASIBLE , 3 |
---|
596 | 596 | | READILY USABLE FORMA T THAT ALLOWS THE CONSUMER TO EASILY TRANSMIT THE 4 |
---|
597 | 597 | | DATA TO ANOTHER CONT ROLLER; AND 5 |
---|
598 | 598 | | |
---|
599 | 599 | | (6) OPT OUT OF THE PROCES SING OF PERSONAL DAT A FOR PURPOSES 6 |
---|
600 | 600 | | OF: 7 |
---|
601 | 601 | | |
---|
602 | 602 | | (I) TARGETED ADVERTISING ; 8 |
---|
603 | 603 | | |
---|
604 | 604 | | (II) EXCEPT AS PROVIDED IN § 14–4507(D) OF THIS SUBTITLE , 9 |
---|
605 | 605 | | THE SALE OF PERSONAL DATA; OR 10 |
---|
606 | 606 | | |
---|
607 | 607 | | (III) PROFILING IN FURTHERA NCE OF SOLELY AUTOMA TED 11 |
---|
608 | 608 | | DECISIONS THAT PRODU CE LEGAL OR SIMILARL Y SIGNIFICANT EFFECT S 12 |
---|
609 | 609 | | CONCERNING THE CONSU MER. 13 |
---|
610 | 610 | | |
---|
611 | 611 | | (B) A CONTROLLER SHALL EST ABLISH A SECURE AND RELIABLE METHOD 14 |
---|
612 | 612 | | FOR A CONSUMER TO EX ERCISE A CONSUMER RI GHT UNDER THIS SECTION. 15 |
---|
613 | 613 | | |
---|
614 | 614 | | (C) (1) EXCEPT AS OTHERWISE P ROVIDED IN THIS SUBTITLE , A 16 |
---|
615 | 615 | | CONTROLLER SHALL COM PLY WITH A REQUEST B Y A CONSUMER TO EXER CISE A 17 |
---|
616 | 616 | | CONSUMER RIGHT LISTED IN THIS SECTI ON. 18 |
---|
617 | 617 | | |
---|
618 | 618 | | (2) (I) A CONTROLLER SHALL RES POND TO A CONSUMER REQUEST 19 |
---|
619 | 619 | | NOT LATER THAN 45 DAYS AFTER THE CONTROLLER RECEI VES THE CONSUMER 20 |
---|
620 | 620 | | REQUEST. 21 |
---|
621 | 621 | | |
---|
622 | 622 | | (II) A CONTROLLER MAY EXTEN D THE RESPONSE PERIO D BY AN 22 |
---|
623 | 623 | | ADDITIONAL 45 DAYS IF: 23 |
---|
624 | 624 | | |
---|
625 | 625 | | 1. IT IS NECESSARY TO COMPLETE THE REQU EST BASED 24 |
---|
626 | 626 | | ON THE COMPLEXITY AND N UMBER OF THE CONSUME R’S REQUESTS; AND 25 |
---|
627 | 627 | | |
---|
628 | 628 | | 2. THE CONTROLLER INFORM S THE CONSUMER OF THE 26 |
---|
629 | 629 | | EXTENSION AND THE REASON FOR T HE EXTENSION WITHIN THE INITIAL 45–DAY 27 |
---|
630 | 630 | | RESPONSE PERIOD . 28 |
---|
631 | 631 | | |
---|
632 | 632 | | (3) (I) IF A CONTROLLER DOES NOT TAKE ACTION REGARDIN G A 29 |
---|
633 | 633 | | CONSUMER ’S REQUEST, THE CONTROLLER SHALL : 30 |
---|
634 | 634 | | HOUSE BILL 807 15 |
---|
635 | 635 | | |
---|
636 | 636 | | |
---|
637 | 637 | | 1. NOTIFY THE CONSUMER THAT THE CONTROLLER 1 |
---|
638 | 638 | | WILL NOT TAKE ACTION ON THE REQUEST ; AND 2 |
---|
639 | 639 | | |
---|
640 | 640 | | 2. PROVIDE THE CONSUMER WITH: 3 |
---|
641 | 641 | | |
---|
642 | 642 | | A. THE JUSTIFICATION FOR DECLINING TO TAKE 4 |
---|
643 | 643 | | ACTION; AND 5 |
---|
644 | 644 | | |
---|
645 | 645 | | B. INSTRUCTIONS FOR HOW TO APPEAL THE DECISI ON. 6 |
---|
646 | 646 | | |
---|
647 | 647 | | (II) THE NOTIFICATION REQU IRED IN SUBPARAGRAPH (I) OF 7 |
---|
648 | 648 | | THIS PARAGRAPH SHALL BE: 8 |
---|
649 | 649 | | |
---|
650 | 650 | | 1. SENT TO THE CONSUMER NOT LATER THAN 45 DAYS 9 |
---|
651 | 651 | | AFTER THE CONTROLLER RECEI VES THE CONSUMER ’S REQUEST; AND 10 |
---|
652 | 652 | | |
---|
653 | 653 | | 2. IN WRITING. 11 |
---|
654 | 654 | | |
---|
655 | 655 | | (4) (I) EXCEPT AS PROVIDED IN THIS PARAGRAPH , A CONTROLLER 12 |
---|
656 | 656 | | SHALL PROVIDE A CONSUMER , FREE OF CHARGE , WITH THE INFORMATION THE 13 |
---|
657 | 657 | | CONSUMER REQUESTED . 14 |
---|
658 | 658 | | |
---|
659 | 659 | | (II) A CONTROLLER MAY NOT B E REQUIRED TO PROVID E A 15 |
---|
660 | 660 | | CONSUMER WITH THE INFORMATION REQUESTED MORE THAN TWICE DURING AN Y 16 |
---|
661 | 661 | | CONSECUTIVE 12–MONTH PERIOD . 17 |
---|
662 | 662 | | |
---|
663 | 663 | | (III) 1. IF REQUESTS FROM A CO NSUMER ARE UNFOUNDED , 18 |
---|
664 | 664 | | EXCESSIVE, OR REPETITIVE , A CONTROLLER MAY CHARG E THE CONSUMER A 19 |
---|
665 | 665 | | REASONABLE FEE TO CO VER THE ADMINISTRATI VE COSTS OF COMPLYIN G WITH THE 20 |
---|
666 | 666 | | REQUEST. 21 |
---|
667 | 667 | | |
---|
668 | 668 | | 2. THE CONTROLLER HAS THE BURDEN OF 22 |
---|
669 | 669 | | DEMONSTRATING THE UNFOUNDED , EXCESSIVE, OR REPETITIVE NATURE OF THE 23 |
---|
670 | 670 | | REQUEST. 24 |
---|
671 | 671 | | |
---|
672 | 672 | | (5) (I) IF A CONTROLLER IS UN ABLE TO AUTHENTICATE A 25 |
---|
673 | 673 | | REQUEST TO EXERCISE A CONSUMER RIGHT AFFORDED UNDER SUBSECTION (A)(1) 26 |
---|
674 | 674 | | THROUGH (5) OF THIS SECTION USING COMMERCIALLY R EASONABLE EFFORTS , THE 27 |
---|
675 | 675 | | CONTROLLER MAY NOT BE REQUIRED TO C OMPLY WITH THE REQUEST. 28 |
---|
676 | 676 | | |
---|
677 | 677 | | (II) IF A CONTROLLER IS NO T ABLE TO AUTHENTICA TE A 29 |
---|
678 | 678 | | REQUEST USING COMMER CIALLY REASONABLE EF FORTS, THE CONTROLLER SHALL 30 |
---|
679 | 679 | | NOTIFY THE CONSUME R THAT THE CONTROLLE R IS UNABLE TO AUTHE NTICATE THE 31 16 HOUSE BILL 807 |
---|
680 | 680 | | |
---|
681 | 681 | | |
---|
682 | 682 | | REQUEST UNTIL THE CONSUMER PROVIDES AD DITIONAL INFORMATION 1 |
---|
683 | 683 | | REASONABLY NECESSARY TO AUTHENTICATE THE CONSUMER AND THE 2 |
---|
684 | 684 | | CONSUMER ’S REQUEST. 3 |
---|
685 | 685 | | |
---|
686 | 686 | | (6) (I) A CONTROLLER IS NOT REQUIRED TO AUTHENTI CATE AN 4 |
---|
687 | 687 | | OPT–OUT REQUEST UNDER SUBSECTION (A)(6) OF THIS SECTION. 5 |
---|
688 | 688 | | |
---|
689 | 689 | | (II) A CONTROLLER MAY DENY AN OPT–OUT REQUEST UNDER 6 |
---|
690 | 690 | | SUBSECTION (A)(6) OF THIS SECTION IF THE CONTROLLER HA S A GOOD FAITH , 7 |
---|
691 | 691 | | REASONABLE , AND DOCUMENTED BELIE F THAT THE REQUEST IS FRAUDULEN T. 8 |
---|
692 | 692 | | |
---|
693 | 693 | | (III) IF A CONTROLLER DENIES AN OPT–OUT REQUEST UNDER 9 |
---|
694 | 694 | | SUBSECTION (A)(6) OF THIS SECTION BECAUSE THE CONTROLL ER BELIEVES THE 10 |
---|
695 | 695 | | REQUEST IS FRAUDULEN T, THE CONTROLLER SHALL NOTIFY THE PERSON WHO 11 |
---|
696 | 696 | | MADE THE REQUEST: 12 |
---|
697 | 697 | | |
---|
698 | 698 | | 1. THAT THE CONTROLLER BELIEVES THE REQUEST IS 13 |
---|
699 | 699 | | FRAUDULENT ; 14 |
---|
700 | 700 | | |
---|
701 | 701 | | 2. WHY THE CONTROLLER BELIEVES THE REQUEST IS 15 |
---|
702 | 702 | | FRAUDULENT ; AND 16 |
---|
703 | 703 | | |
---|
704 | 704 | | 3. THAT THE CONTROLLER WILL NOT COMPLY WITH THE 17 |
---|
705 | 705 | | REQUEST. 18 |
---|
706 | 706 | | |
---|
707 | 707 | | (7) A CONTROLLER THAT HAS OBTAINED PERSONAL DA TA ABOUT A 19 |
---|
708 | 708 | | CONSUMER FROM A SOUR CE OTHER THAN THE CO NSUMER IS IN COMPLIANCE WITH 20 |
---|
709 | 709 | | A CONSUMER ’S REQUEST TO DELETE THE DATA IN ACCORDANCE WITH SUBSECTION 21 |
---|
710 | 710 | | (A)(4) OF THIS SECTION BY: 22 |
---|
711 | 711 | | |
---|
712 | 712 | | (I) RETAINING A RECORD OF THE DELETION REQUEST AND TH E 23 |
---|
713 | 713 | | MINIMUM DATA NECESSA RY FOR THE PURPOSE O F ENSURING THE CONSU MER’S 24 |
---|
714 | 714 | | PERSONAL DATA : 25 |
---|
715 | 715 | | |
---|
716 | 716 | | 1. REMAINS DELETED FROM THE CONTROLLER ’S 26 |
---|
717 | 717 | | RECORDS; AND 27 |
---|
718 | 718 | | |
---|
719 | 719 | | 2. IS NOT BEING USED FOR ANY OTHER PURPOS E; OR 28 |
---|
720 | 720 | | |
---|
721 | 721 | | (II) OPTING THE CONSUMER O UT OF THE PROCESSING OF THE 29 |
---|
722 | 722 | | PERSONAL DATA FOR AN Y PURPOSE EXCEPT FOR THOSE EXEMPTED BY THIS 30 |
---|
723 | 723 | | SUBTITLE. 31 |
---|
724 | 724 | | HOUSE BILL 807 17 |
---|
725 | 725 | | |
---|
726 | 726 | | |
---|
727 | 727 | | (D) (1) A CONTROLLER SHALL EST ABLISH A PROCESS FOR A CONSUMER 1 |
---|
728 | 728 | | TO APPEAL A DECISION MADE UNDE R THIS SECTION. 2 |
---|
729 | 729 | | |
---|
730 | 730 | | (2) THE APPEAL PROCESS SHALL : 3 |
---|
731 | 731 | | |
---|
732 | 732 | | (I) BE CONSPICUOUSLY AVAILABL E TO A CONSUMER ; 4 |
---|
733 | 733 | | |
---|
734 | 734 | | (II) BE SIMILAR TO THE PROCES S FOR SUBMITTING REQ UESTS 5 |
---|
735 | 735 | | TO INITIATE ACTION IN ACCORDANCE WITH THIS SECTION; AND 6 |
---|
736 | 736 | | |
---|
737 | 737 | | (III) ENSURE THAT A CONSUME R CAN APPEAL A DECISIO N 7 |
---|
738 | 738 | | WITHIN A REASONABLE TIME AFTER THE CONSUM ER RECEIVES THE DECI SION. 8 |
---|
739 | 739 | | |
---|
740 | 740 | | (3) NOT LATER THAN 60 DAYS AFTER RECEIPT O F AN APPEAL , A 9 |
---|
741 | 741 | | CONTROLLER SHALL INF ORM THE CONSUMER IN WRITING OF ANY ACTIO N TAKEN OR 10 |
---|
742 | 742 | | NOT TAKEN IN RESPONS E TO THE APPEAL, INCLUDING A WRITTEN EXPLANATION OF 11 |
---|
743 | 743 | | THE REASONS FOR THE DECISIO N. 12 |
---|
744 | 744 | | |
---|
745 | 745 | | (4) IF AN APPEAL IS DENIED , THE CONTROLLER SHALL PROVIDE THE 13 |
---|
746 | 746 | | CONSUMER WITH AN ONL INE MECHANISM , IF AVAILABLE, THROUGH WHICH THE 14 |
---|
747 | 747 | | CONSUMER MAY CONTACT THE DIVISION TO SUBMIT A COMPLAIN T. 15 |
---|
748 | 748 | | |
---|
749 | 749 | | (E) NOTHING IN THIS SUBTI TLE MAY BE CONSTRUED TO REQU IRE A 16 |
---|
750 | 750 | | CONTROLLER OR A PROCESSOR TO COMPLY WITH AN AUTHENTICATE D CONSUMER 17 |
---|
751 | 751 | | REQUEST IF THE CONTR OLLER: 18 |
---|
752 | 752 | | |
---|
753 | 753 | | (1) IS NOT REASONABLY CAP ABLE OF ASSOCIATING THE REQUEST 19 |
---|
754 | 754 | | WITH THE PERSONAL DA TA OR IT WOULD BE UN REASONABLY BURDENSOM E FOR THE 20 |
---|
755 | 755 | | CONTROLLER TO ASSOCIATE T HE REQUEST WITH THE PERSONAL DATA ; 21 |
---|
756 | 756 | | |
---|
757 | 757 | | (2) DOES NOT USE THE PERS ONAL DATA TO RECOGNI ZE OR RESPOND 22 |
---|
758 | 758 | | TO THE CONSUMER WHO IS THE SUBJECT OF TH E PERSONAL DATA OR A SSOCIATE 23 |
---|
759 | 759 | | THE PERSONAL DATA WI TH OTHER PERSONAL DA TA ABOUT THE CONSUME R; AND 24 |
---|
760 | 760 | | |
---|
761 | 761 | | (3) EXCEPT AS OTHERWISE A LLOWED IN THIS SECTI ON, DOES NOT 25 |
---|
762 | 762 | | SELL OR OTHERWISE VO LUNTARILY DISCLOSE T HE PERSONAL DATA TO A THIRD 26 |
---|
763 | 763 | | PARTY. 27 |
---|
764 | 764 | | |
---|
765 | 765 | | (F) NOTHING IN THIS SECTI ON MAY BE CONSTRUED TO REQUIRE A 28 |
---|
766 | 766 | | CONTROLLER TO REVEAL A TRADE SECRET . 29 |
---|
767 | 767 | | |
---|
768 | 768 | | 14–4505. 30 |
---|
769 | 769 | | 18 HOUSE BILL 807 |
---|
770 | 770 | | |
---|
771 | 771 | | |
---|
772 | 772 | | (A) NOTHING IN THIS SUBTI TLE MAY BE CONSTRUED TO PROH IBIT A 1 |
---|
773 | 773 | | CONTROLLER OR PROCES SOR FROM: 2 |
---|
774 | 774 | | |
---|
775 | 775 | | (1) COMPLYING WITH FEDERA L, STATE, OR LOCAL LAWS ; 3 |
---|
776 | 776 | | |
---|
777 | 777 | | (2) COMPLYING WITH A CIVI L, CRIMINAL, OR REGULATORY INQUIR Y, 4 |
---|
778 | 778 | | INVESTIGATION , SUBPOENA, OR SUMMONS BY A FEDE RAL, STATE, OR LOCAL 5 |
---|
779 | 779 | | AUTHORITY; 6 |
---|
780 | 780 | | |
---|
781 | 781 | | (3) COOPERATING WITH LAW ENFORCEMENT AGENCIES 7 |
---|
782 | 782 | | CONCERNING CONDUCT O R ACTIVITY THAT THE CONTROLLER OR PROCES SOR 8 |
---|
783 | 783 | | REASONABLY AND IN GO OD FAITH BELIEVES MA Y VIOLATE A FEDERAL , STATE, OR 9 |
---|
784 | 784 | | LOCAL LAW; 10 |
---|
785 | 785 | | |
---|
786 | 786 | | (4) INVESTIGATING , ESTABLISHING , EXERCISING, PREPARING FOR , 11 |
---|
787 | 787 | | OR DEFENDING A LEGAL CLAIM; 12 |
---|
788 | 788 | | |
---|
789 | 789 | | (5) PROVIDING A PRODUCT O R SERVICE SPECIFICAL LY REQUESTED 13 |
---|
790 | 790 | | BY A CONSUMER ; 14 |
---|
791 | 791 | | |
---|
792 | 792 | | (6) PERFORMING UNDER A CO NTRACT TO WHICH A CO NSUMER IS A 15 |
---|
793 | 793 | | PARTY, INCLUDING FULFILLING THE TERMS OF A WRITTEN WARRANT Y; 16 |
---|
794 | 794 | | |
---|
795 | 795 | | (7) TAKING STEPS AT THE R EQUEST OF A CONSUMER BEFORE 17 |
---|
796 | 796 | | ENTERING INTO A CONT RACT; 18 |
---|
797 | 797 | | |
---|
798 | 798 | | (8) TAKING IMMEDIATE STEP S TO PROTECT AN INTE REST THAT IS 19 |
---|
799 | 799 | | ESSENTIAL FOR THE LI FE OR PHYSICAL SAFET Y OF A CONSUMER OR A NOTHER 20 |
---|
800 | 800 | | INDIVIDUAL; 21 |
---|
801 | 801 | | |
---|
802 | 802 | | (9) PREVENTING, DETECTING, PROTECTING AGAINST , OR 22 |
---|
803 | 803 | | RESPONDING TO A SECU RITY INCIDENT, IDENTITY THEFT , FRAUD, HARASSMENT , 23 |
---|
804 | 804 | | MALICIOUS OR DECEPTI VE ACTIVITY, OR ANY ILLEGAL ACTIV ITY; 24 |
---|
805 | 805 | | |
---|
806 | 806 | | (10) PRESERVING THE INTEGR ITY OR SECURITY OF A SYSTEM, OR 25 |
---|
807 | 807 | | INVESTIGATING, REPORTING, OR PROSECUT ING A PERSON RESPONSIBLE FOR THE 26 |
---|
808 | 808 | | ACTION; 27 |
---|
809 | 809 | | |
---|
810 | 810 | | (11) ENGAGING IN PUBLIC OR PEER–REVIEWED SCIENTIFIC OR 28 |
---|
811 | 811 | | STATISTICAL RESEARCH IN THE PUBLIC INTERE ST THAT: 29 |
---|
812 | 812 | | |
---|
813 | 813 | | (I) ADHERES TO ALL OTHER APPLICABLE ETHICS AN D PRIVACY 30 |
---|
814 | 814 | | LAWS; AND 31 HOUSE BILL 807 19 |
---|
815 | 815 | | |
---|
816 | 816 | | |
---|
817 | 817 | | |
---|
818 | 818 | | (II) IS APPROVED , MONITORED , AND GOVERNED BY AN 1 |
---|
819 | 819 | | INSTITUTIONAL REVIEW BOARD, OR A SIMILAR INDEPEN DENT OVERSIGHT ENTIT Y, 2 |
---|
820 | 820 | | THAT DETERMINES WHET HER: 3 |
---|
821 | 821 | | |
---|
822 | 822 | | 1. THE DELETION OF THE I NFORMATION IS LIKELY TO 4 |
---|
823 | 823 | | PROVIDE SUBSTANTIAL BENEFITS THAT DO NOT EXCLUSIVELY ACCRUE T O THE 5 |
---|
824 | 824 | | CONTROLLER ; 6 |
---|
825 | 825 | | |
---|
826 | 826 | | 2. THE EXPECTED BENEFITS OF THE RESEARCH 7 |
---|
827 | 827 | | OUTWEIGH THE PRIVACY RISKS; AND 8 |
---|
828 | 828 | | |
---|
829 | 829 | | 3. THE CONTROLLER HAS IM PLEMENTED REASONABLE 9 |
---|
830 | 830 | | SAFEGUARDS TO MITIGA TE PRIVACY RISKS ASS OCIATED WITH RESEARC H, 10 |
---|
831 | 831 | | INCLUDING ANY RISKS ASSOCIATED WITH RE –IDENTIFICATION ; 11 |
---|
832 | 832 | | |
---|
833 | 833 | | (12) ASSISTING ANOTHER CON TROLLER, PROCESSOR, OR 12 |
---|
834 | 834 | | THIRD PARTY WITH AN OBLIGA TION UNDER THIS SUBT ITLE; OR 13 |
---|
835 | 835 | | |
---|
836 | 836 | | (13) PROCESSING PERSONAL D ATA FOR REASONS OF P UBLIC 14 |
---|
837 | 837 | | INTEREST IN THE AREA OF PUBLIC HEALTH , COMMUNITY HEALTH , OR POPULATION 15 |
---|
838 | 838 | | HEALTH, IF THE PROCESSING IS : 16 |
---|
839 | 839 | | |
---|
840 | 840 | | (I) SUBJECT TO SUITABLE A ND SPECIFIC MEASURES TO 17 |
---|
841 | 841 | | SAFEGUARD THE RIGHTS OF A CONSUMER WHOSE PERSONAL DATA IS BEI NG 18 |
---|
842 | 842 | | PROCESSED; AND 19 |
---|
843 | 843 | | |
---|
844 | 844 | | (II) UNDER THE RESPONSIBIL ITY OF A PROFESSIONA L SUBJECT 20 |
---|
845 | 845 | | TO CONFIDENTIALITY O BLIGATIONS UNDER FED ERAL, STATE, OR LOCAL LAW. 21 |
---|
846 | 846 | | |
---|
847 | 847 | | (B) THE OBLIGATIONS IMPOS ED ON CONTROLLERS OR PROCESSORS UNDER 22 |
---|
848 | 848 | | THIS SUBTITLE MAY NO T RESTRICT A CONTROL LER’S OR PROCESSOR ’S ABILITY TO 23 |
---|
849 | 849 | | COLLECT, USE, OR RETAIN DATA FOR I NTERNAL USE TO : 24 |
---|
850 | 850 | | |
---|
851 | 851 | | (1) EFFECTUATE A PRODUCT RECALL; 25 |
---|
852 | 852 | | |
---|
853 | 853 | | (2) IDENTIFY AND REPAIR TECHNICAL ERRORS THA T IMPAIR 26 |
---|
854 | 854 | | EXISTING OR INTENDED FUNCTIONALITY ; OR 27 |
---|
855 | 855 | | |
---|
856 | 856 | | (3) PERFORM INTERNAL OPER ATIONS THAT ARE : 28 |
---|
857 | 857 | | 20 HOUSE BILL 807 |
---|
858 | 858 | | |
---|
859 | 859 | | |
---|
860 | 860 | | (I) REASONABLY ALIGNED WI TH THE EXPECTATIONS OF THE 1 |
---|
861 | 861 | | CONSUMER OR REASONAB LY ANTICIPATED BASED ON THE CONSUMER ’S EXISTING 2 |
---|
862 | 862 | | RELATIONSHIP WITH T HE CONTROLLER ; OR 3 |
---|
863 | 863 | | |
---|
864 | 864 | | (II) OTHERWISE COMPATIBLE WITH PROCESSING DATA IN 4 |
---|
865 | 865 | | FURTHERANCE OF THE P ROVISION OF A PRODUC T OR SERVICE SPECIFI CALLY 5 |
---|
866 | 866 | | REQUESTED BY A CONSU MER OR THE PERFORMAN CE OF A CONTRACT TO WHICH THE 6 |
---|
867 | 867 | | CONSUMER IS A PARTY . 7 |
---|
868 | 868 | | |
---|
869 | 869 | | (C) (1) NOTHING IN THIS SUBTI TLE MAY BE CONSTRUED TO PREV ENT A 8 |
---|
870 | 870 | | CONTROLLER OR PROCES SOR FROM PROVIDING P ERSONAL DATA ABOUT A 9 |
---|
871 | 871 | | CONSUMER TO A PERSON COVERED BY AN EVIDEN TIARY PRIVILEGE UNDE R THE 10 |
---|
872 | 872 | | LAWS OF THE STATE AS PART OF A PR IVILEGED COMMUNICATI ON. 11 |
---|
873 | 873 | | |
---|
874 | 874 | | (2) AN OBLIGATION IMPOSED ON A CO NTROLLER OR A PROCES SOR 12 |
---|
875 | 875 | | UNDER THIS SUBTITLE DOES NOT APPLY WHERE COMPLIANCE BY THE CO NTROLLER 13 |
---|
876 | 876 | | OR PROCESSOR WITH TH E SUBTITLE WOULD VIO LATE AN EVIDENTIARY PRIVILEGE 14 |
---|
877 | 877 | | UNDER THE LAWS OF TH E STATE. 15 |
---|
878 | 878 | | |
---|
879 | 879 | | (D) NOTHING IN THIS SUBTI TLE MAY BE CONSTRUED TO: 16 |
---|
880 | 880 | | |
---|
881 | 881 | | (1) IMPOSE AN OBLIGATION ON A CONTROLLER OR A PROCESSOR 17 |
---|
882 | 882 | | THAT ADVERSELY AFFEC TS THE RIGHTS OR FRE EDOMS OF ANY PERSON ; OR 18 |
---|
883 | 883 | | |
---|
884 | 884 | | (2) APPLY TO A PERSON ’S PROCESSING OF PERS ONAL DATA IN THE 19 |
---|
885 | 885 | | COURSE OF THE PERSON ’S PERSONAL OR HOUSEH OLD ACTIVITIES. 20 |
---|
886 | 886 | | |
---|
887 | 887 | | (E) IF A CONTROLLER PROCE SSES PERSONAL DATA I N ACCORDANCE WITH 21 |
---|
888 | 888 | | AN EXEMPTION UNDER T HIS SECTION, THE CONTROLLER SHALL DEMONSTRATE 22 |
---|
889 | 889 | | THAT THE PROCESSING : 23 |
---|
890 | 890 | | |
---|
891 | 891 | | (1) QUALIFIES FOR AN EXEM PTION; AND 24 |
---|
892 | 892 | | |
---|
893 | 893 | | (2) COMPLIES WITH THE REQ UIREMENTS IN SUBSECT ION (F) OF THIS 25 |
---|
894 | 894 | | SECTION. 26 |
---|
895 | 895 | | |
---|
896 | 896 | | (F) (1) PERSONAL DATA PROCESS ED BY A CONTROLLER I N ACCORDANCE 27 |
---|
897 | 897 | | WITH THIS SECTION MAY BE PROCESSED TO THE EXT ENT THAT THE PROCESS ING IS: 28 |
---|
898 | 898 | | |
---|
899 | 899 | | (I) REASONABLY NECESSARY AND PROPORTIONATE TO THE 29 |
---|
900 | 900 | | PURPOSES LISTED IN T HIS SECTION; AND 30 |
---|
901 | 901 | | HOUSE BILL 807 21 |
---|
902 | 902 | | |
---|
903 | 903 | | |
---|
904 | 904 | | (II) ADEQUATE, RELEVANT, AND LIMITED TO WHAT IS 1 |
---|
905 | 905 | | NECESSARY IN RELATIO N TO THE SPECIFIC PU RPOSES LISTED IN THI S SECTION. 2 |
---|
906 | 906 | | |
---|
907 | 907 | | (2) PERSONAL DATA COLLECT ED, USED, OR RETAINED IN 3 |
---|
908 | 908 | | ACCORDANCE WITH SUBS ECTION (B) OF THIS SECTION SHAL L: 4 |
---|
909 | 909 | | |
---|
910 | 910 | | (I) WHERE APPROPRIATE , TAKE INTO ACCOUNT THE NATURE 5 |
---|
911 | 911 | | AND PURPOSE OF THE C OLLECTION, USE, OR RETENTION ; AND 6 |
---|
912 | 912 | | |
---|
913 | 913 | | (II) BE SUBJECT TO REASONA BLE ADMINISTRATIVE , 7 |
---|
914 | 914 | | TECHNICAL, AND PHYSICAL MEASURE S TO: 8 |
---|
915 | 915 | | |
---|
916 | 916 | | 1. PROTECT THE CONFIDENT IALITY, INTEGRITY, AND 9 |
---|
917 | 917 | | ACCESSIBILITY OF THE PERSONAL DATA ; AND 10 |
---|
918 | 918 | | |
---|
919 | 919 | | 2. REDUCE REASONABLY FORESE EABLE RISKS OF HARM 11 |
---|
920 | 920 | | TO CONSUMERS RELATIN G TO THE COLLECTION , USE, OR RETENTION OF PERS ONAL 12 |
---|
921 | 921 | | DATA. 13 |
---|
922 | 922 | | |
---|
923 | 923 | | 14–4506. 14 |
---|
924 | 924 | | |
---|
925 | 925 | | (A) A CONSUMER MAY DESIGNA TE AN AUTHORIZED AGENT TO ACT ON THE 15 |
---|
926 | 926 | | CONSUMER ’S BEHALF TO OPT OUT OF THE PROCESSING OF THE CONSUMER ’S 16 |
---|
927 | 927 | | PERSONAL DATA FOR TH E PURPOSES SPECIFIED IN § 14–4504(A) OF THIS SUBTITLE. 17 |
---|
928 | 928 | | |
---|
929 | 929 | | (B) THE CONSUMER MAY DESI GNATE AN AUTHORIZED AGENT BY: 18 |
---|
930 | 930 | | |
---|
931 | 931 | | (1) AN INTERNET LINK OR A BR OWSER SETTING ON A CONTROLLER ’S 19 |
---|
932 | 932 | | WEBSITE; OR 20 |
---|
933 | 933 | | |
---|
934 | 934 | | (2) A BROWSER EXTENSION OR GLOBAL DEVICE SETTING ON A 21 |
---|
935 | 935 | | CONTROLLER ’S WEBSITE INDICATING THE CONSUMER ’S INTENT TO OPT OUT OF THE 22 |
---|
936 | 936 | | PROCESSING. 23 |
---|
937 | 937 | | |
---|
938 | 938 | | (C) A CONTROLLER SHALL COM PLY WITH AN OPT–OUT REQUEST RECEIVED 24 |
---|
939 | 939 | | FROM AN AUTHORIZED A GENT IF THE CONTROLL ER IS ABLE TO VERIFY , USING 25 |
---|
940 | 940 | | COMMERCIALLY REASONA BLE EFFORT S: 26 |
---|
941 | 941 | | |
---|
942 | 942 | | (1) THE IDENTITY OF THE C ONSUMER; AND 27 |
---|
943 | 943 | | |
---|
944 | 944 | | (2) THE AUTHORIZED AGENT ’S AUTHORITY TO ACT O N THE 28 |
---|
945 | 945 | | CONSUMER ’S BEHALF. 29 |
---|
946 | 946 | | 22 HOUSE BILL 807 |
---|
947 | 947 | | |
---|
948 | 948 | | |
---|
949 | 949 | | (D) THE FOLLOWING INDIVID UALS MAY EXERCISE TH E CONSUMER RIGHTS 1 |
---|
950 | 950 | | SPECIFIED IN THIS SUBTITLE ON BEHALF OF ANOTHER INDIVIDUAL W ITHOUT BEING 2 |
---|
951 | 951 | | DESIGNATED AS AN AUT HORIZED AGENT UNDER SUBSECTION (A) OF THIS SECTION: 3 |
---|
952 | 952 | | |
---|
953 | 953 | | (1) THE PARENT OR LEGAL G UARDIAN OF A KNOWN C HILD; 4 |
---|
954 | 954 | | |
---|
955 | 955 | | (2) IF A CONSUMER IS SUBJ ECT TO A GUARDIANSHI P, A 5 |
---|
956 | 956 | | CONSERVATORSHIP , OR ANY OTHER PROTECTIVE ARRANGEMENT , THE GUARDIAN 6 |
---|
957 | 957 | | OR CONSERVATOR OF TH E CONSUMER . 7 |
---|
958 | 958 | | |
---|
959 | 959 | | 14–4507. 8 |
---|
960 | 960 | | |
---|
961 | 961 | | (A) A CONTROLLER MAY NOT : 9 |
---|
962 | 962 | | |
---|
963 | 963 | | (1) SELL, LEASE, OR TRADE A CONSUMER ’S BIOMETRIC DATA ; 10 |
---|
964 | 964 | | |
---|
965 | 965 | | (2) EXCEPT AS OTHERWISE P ROVIDED IN THIS SUBT ITLE, UNLESS 11 |
---|
966 | 966 | | THE CONTROLLER OBTAI NS THE CONSUMER ’S CONSENT, PROCESS PERSONAL DAT A 12 |
---|
967 | 967 | | FOR A PURPOSE THAT I S NEITHER REASONABLY NECESSARY TO , NOR COMPATIBLE 13 |
---|
968 | 968 | | WITH, THE DISCLOSED PURPOS ES FOR WHICH THE PER SONAL DATA IS PROCES SED, 14 |
---|
969 | 969 | | AS DISCLOSED TO THE CONSUMER ; 15 |
---|
970 | 970 | | |
---|
971 | 971 | | (3) PROCESS SENSITIVE DAT A CONCERNING A CONSU MER WITHOUT 16 |
---|
972 | 972 | | OBTAINING THE CONSUM ER’S CONSENT; 17 |
---|
973 | 973 | | |
---|
974 | 974 | | (4) PROCESS SENSITIVE DAT A OF A KNOWN CHILD W ITHOUT 18 |
---|
975 | 975 | | PROCESSING THE DATA IN ACCORDANCE WITH T HE FEDERAL CHILDREN’S ONLINE 19 |
---|
976 | 976 | | PRIVACY PROTECTION ACT OF 1998; 20 |
---|
977 | 977 | | |
---|
978 | 978 | | (5) PROCESS PERSONAL DATA IN VIOLATION OF FEDE RAL, STATE, OR 21 |
---|
979 | 979 | | LOCAL LAW THAT PROHI BITS UNLAWFUL DISCRI MINATION AGAINST A C ONSUMER; 22 |
---|
980 | 980 | | OR 23 |
---|
981 | 981 | | |
---|
982 | 982 | | (6) PROCESS THE PERSONAL DATA OF A CONSUMER T HAT THE 24 |
---|
983 | 983 | | PROCESSOR KNOWS IS A T LEAST 13 YEARS OLD AND UNDER THE AGE OF 16 YEARS 25 |
---|
984 | 984 | | WITHOUT THE CONSUMER ’S CONSENT FOR PURPOS ES OF: 26 |
---|
985 | 985 | | |
---|
986 | 986 | | (I) TARGETED ADVERTISING ; OR 27 |
---|
987 | 987 | | |
---|
988 | 988 | | (II) SELLING THE CONSUMER ’S PERSONAL DATA . 28 |
---|
989 | 989 | | |
---|
990 | 990 | | (B) A CONTROLLER SHALL : 29 |
---|
991 | 991 | | HOUSE BILL 807 23 |
---|
992 | 992 | | |
---|
993 | 993 | | |
---|
994 | 994 | | (1) LIMIT THE COLLECTION OF PERSONAL DATA TO WHAT IS: 1 |
---|
995 | 995 | | |
---|
996 | 996 | | (I) ADEQUATE, RELEVANT, AND REASONABLY NECES SARY TO 2 |
---|
997 | 997 | | COLLECT FOR THE PURPOSES FOR WHI CH THE DATA IS PROCESSED ; AND 3 |
---|
998 | 998 | | |
---|
999 | 999 | | (II) DISCLOSED TO THE CONS UMER; 4 |
---|
1000 | 1000 | | |
---|
1001 | 1001 | | (2) ESTABLISH, IMPLEMENT, AND MAINTAIN REASONA BLE 5 |
---|
1002 | 1002 | | ADMINISTRATIVE , TECHNICAL, AND PHYSICAL DATA SE CURITY PRACTICES TO 6 |
---|
1003 | 1003 | | PROTECT THE CONFIDEN TIALITY, INTEGRITY, AND ACCESSIBILITY OF PERSONAL 7 |
---|
1004 | 1004 | | DATA APPROPRIATE TO THE VOLUME AND NATUR E OF THE PERSONAL DA TA AT 8 |
---|
1005 | 1005 | | ISSUE; 9 |
---|
1006 | 1006 | | |
---|
1007 | 1007 | | (3) PROVIDE AN EFFECTIVE MECHANISM FOR A CONS UMER TO 10 |
---|
1008 | 1008 | | REVOKE THE CONSU MER’S CONSENT UNDER THIS SECTION THAT IS AT L EAST AS 11 |
---|
1009 | 1009 | | EASY AS THE MECHANIS M BY WHICH THE CONSU MER PROVIDED THE CON SUMER’S 12 |
---|
1010 | 1010 | | CONSENT; AND 13 |
---|
1011 | 1011 | | |
---|
1012 | 1012 | | (4) IF CONSENT IS REVOKED, STOP PROCESSING THE DATA AS SOON 14 |
---|
1013 | 1013 | | AS PRACTICABLE , BUT NOT LATER THAN 15 DAYS AFTER THE RECEI PT OF THE 15 |
---|
1014 | 1014 | | REQUEST. 16 |
---|
1015 | 1015 | | |
---|
1016 | 1016 | | (C) A CONTROLLER IN POSSES SION OF BIOMETRIC DA TA SHALL STORE , 17 |
---|
1017 | 1017 | | TRANSMIT, AND PROTECT FROM DIS CLOSURE ALL BIOMETRI C DATA: 18 |
---|
1018 | 1018 | | |
---|
1019 | 1019 | | (1) USING THE REASONABLE STANDARD OF CARE WIT HIN THE 19 |
---|
1020 | 1020 | | CONTROLLER ’S INDUSTRY; AND 20 |
---|
1021 | 1021 | | |
---|
1022 | 1022 | | (2) IN A MANNER THAT IS A S PROTECTIVE AS OR M ORE PROTECTIVE 21 |
---|
1023 | 1023 | | THAN THE MANNER IN W HICH THE CONTROLLER STORES, TRANSMITS, AND 22 |
---|
1024 | 1024 | | PROTECTS OTHER CONFI DENTIAL OR SENSITIVE DATA. 23 |
---|
1025 | 1025 | | |
---|
1026 | 1026 | | (D) (1) EXCEPT AS PROVIDED IN PARAGRAPH (2) OF THIS SUBSECTION , A 24 |
---|
1027 | 1027 | | CONTROLLER THAT COLLEC TS BIOMETRIC DATA MA Y NOT COLLECT, USE, DISCLOSE, 25 |
---|
1028 | 1028 | | REDISCLOSE, OR OTHERWISE DISSEMI NATE A CONTROLLER ’S BIOMETRIC DATA 26 |
---|
1029 | 1029 | | UNLESS: 27 |
---|
1030 | 1030 | | |
---|
1031 | 1031 | | (I) THE CONTROLLER OR THE CONSUMER ’S AUTHORIZED 28 |
---|
1032 | 1032 | | AGENT GIVES CONSENT TO THE PARTICULAR CATEGORY OF COLLECTION , USE, 29 |
---|
1033 | 1033 | | DISCLOSURE, REDISCLOSURE , OR DISSEMINATION ; OR 30 |
---|
1034 | 1034 | | |
---|
1035 | 1035 | | (II) THE DISCLOSURE OR RED ISCLOSURE IS REQUIRE D: 31 |
---|
1036 | 1036 | | 24 HOUSE BILL 807 |
---|
1037 | 1037 | | |
---|
1038 | 1038 | | |
---|
1039 | 1039 | | 1. BY A VALID WARRANT OR SUBPOENA; 1 |
---|
1040 | 1040 | | |
---|
1041 | 1041 | | 2. TO COMPLY WITH FEDERA L, STATE, OR LOCAL LAWS , 2 |
---|
1042 | 1042 | | RULES, OR REGULATIONS ; OR 3 |
---|
1043 | 1043 | | |
---|
1044 | 1044 | | 3. TO COOPERATE WITH LAW ENFORCEMENT 4 |
---|
1045 | 1045 | | CONCERNING CONDUCT O R ACTIVITY THAT THE PRIVATE ENTITY OR TH E 5 |
---|
1046 | 1046 | | PROCESSOR REASONABLY AND IN GOOD FAITH BE LIEVES VIOLATES A FE DERAL, 6 |
---|
1047 | 1047 | | STATE, OR LOCAL LAW , RULE, OR REGULATION . 7 |
---|
1048 | 1048 | | |
---|
1049 | 1049 | | (2) (I) A CONTROLLER MAY COLLECT , USE, DISCLOSE, 8 |
---|
1050 | 1050 | | REDISCLOSE, OR OTHERWISE DISSEMI NATE A CONSUMER ’S BIOMETRIC DATA 9 |
---|
1051 | 1051 | | WITHOUT COMPLYING WI TH PARAGRAPH (1) OF THIS SUBSECTION IF THE 10 |
---|
1052 | 1052 | | CONTROLLER : 11 |
---|
1053 | 1053 | | |
---|
1054 | 1054 | | 1. COLLECTS, USES, DISCLOSES, REDISCLOSES, OR 12 |
---|
1055 | 1055 | | OTHERWISE DISSEMINAT ES THE BIOMETRIC DATA FOR FRAUD PREVE NTION OR 13 |
---|
1056 | 1056 | | SECURITY PURPOSES ; AND 14 |
---|
1057 | 1057 | | |
---|
1058 | 1058 | | 2. SUBJECT TO SUBPARAGRAPH (III) OF THIS 15 |
---|
1059 | 1059 | | PARAGRAPH : 16 |
---|
1060 | 1060 | | |
---|
1061 | 1061 | | A. FOR A CONTROLLER THAT COLLECTS BIOMETRIC 17 |
---|
1062 | 1062 | | DATA AT A PHYSICAL P REMISES, POSTS CONSPICUOUS WR ITTEN NOTICE OF THE 18 |
---|
1063 | 1063 | | COLLECTION OF BIOMET RIC DATA AT EACH POINT OF E NTRY; AND 19 |
---|
1064 | 1064 | | |
---|
1065 | 1065 | | B. FOR A CONTROLLER THAT COLLECTS BIOMETRIC 20 |
---|
1066 | 1066 | | DATA OF A CONSUMER D URING AN ONLINE ENCO UNTER WITH THE CONSU MER, 21 |
---|
1067 | 1067 | | POSTS CONSPICUOUS WR ITTEN NOTICE OF THE COLLECTION OF BIOMET RIC DATA 22 |
---|
1068 | 1068 | | ON THE WEBSITE OF TH E CONTROLLER . 23 |
---|
1069 | 1069 | | |
---|
1070 | 1070 | | (II) 1. THE COLLECTION , USE, DISCLOSURE, 24 |
---|
1071 | 1071 | | REDISCLOSURE , OR OTHER DISSEMINATI ON OF BIOMETRIC DATA UNDER THIS 25 |
---|
1072 | 1072 | | SUBSECTION SHALL BE DIRECTLY TIED TO THE SERVICES BEING PROVI DED BY THE 26 |
---|
1073 | 1073 | | CONTROLLER . 27 |
---|
1074 | 1074 | | |
---|
1075 | 1075 | | 2. A CONTROLLER THAT COLLECTS , USES, DISCLOSES, 28 |
---|
1076 | 1076 | | REDISCLOSES, OR OTHERWISE DISSEMINATE S BIOMETRIC DATA UND ER THIS 29 |
---|
1077 | 1077 | | SUBSECTION MAY COLLE CT, USE, DISCLOSE, REDISCLOSE, OR OTHERWISE 30 |
---|
1078 | 1078 | | DISSEMINATE ONLY WHA T IS STRICTLY NECESS ARY FOR FRAUD PREVEN TION AND 31 |
---|
1079 | 1079 | | SECURITY PURPOSES . 32 |
---|
1080 | 1080 | | HOUSE BILL 807 25 |
---|
1081 | 1081 | | |
---|
1082 | 1082 | | |
---|
1083 | 1083 | | (III) THE NOTICE REQUIRED I N SUBPARAGRAPH (I) OF THIS 1 |
---|
1084 | 1084 | | PARAGRAPH SHALL INFORM CONSUME RS OF: 2 |
---|
1085 | 1085 | | |
---|
1086 | 1086 | | 1. THE CATEGORIES OF BIO METRIC DATA TO BE 3 |
---|
1087 | 1087 | | COLLECTED; AND 4 |
---|
1088 | 1088 | | |
---|
1089 | 1089 | | 2. THE PURPOSES FOR WHIC H THE CATEGORIES OF 5 |
---|
1090 | 1090 | | BIOMETRIC DATA WILL BE USED. 6 |
---|
1091 | 1091 | | |
---|
1092 | 1092 | | (E) A CONTROLLER MAY NOT DISCRIMINATE AGA INST A CONSUMER FOR 7 |
---|
1093 | 1093 | | EXERCISING A CONSUMER RIGHT AFF ORDED BY THIS SUBTITLE, INCLUDING: 8 |
---|
1094 | 1094 | | |
---|
1095 | 1095 | | (1) DENYING GOODS OR SERV ICES; 9 |
---|
1096 | 1096 | | |
---|
1097 | 1097 | | (2) CHARGING DIFFERENT PR ICES OR RATES FOR GO ODS OR 10 |
---|
1098 | 1098 | | SERVICES; OR 11 |
---|
1099 | 1099 | | |
---|
1100 | 1100 | | (3) PROVIDING A DIFFERENT LEVEL OF QUALITY OF GOODS OR 12 |
---|
1101 | 1101 | | SERVICES. 13 |
---|
1102 | 1102 | | |
---|
1103 | 1103 | | (F) NOTHING IN SUBSECTION (E) OF THIS SECTION MAY BE CONSTRUED TO : 14 |
---|
1104 | 1104 | | |
---|
1105 | 1105 | | (1) REQUIRE A CONTROLLER TO PROVIDE A PRODUCT OR SERVICE 15 |
---|
1106 | 1106 | | THAT REQUIRES THE PE RSONAL DATA OF A CON SUMER WHICH THE CONT ROLLER 16 |
---|
1107 | 1107 | | DOES NOT COLLECT OR MAINTAIN; OR 17 |
---|
1108 | 1108 | | |
---|
1109 | 1109 | | (2) PROHIBIT A CONTROLLER FROM OFFERING A DIFF ERENT PRICE, 18 |
---|
1110 | 1110 | | RATE, LEVEL, QUALITY, OR SELECTION OF GOOD S OR SERVICES TO A C ONSUMER, 19 |
---|
1111 | 1111 | | INCLUDING OFFERING G OODS OR SERVICES FOR NO FEE, IF THE OFFERING IS I N 20 |
---|
1112 | 1112 | | CONNECTION WITH A CO NSUMER’S VOLUNTARY PARTICIP ATION IN A BONA FIDE 21 |
---|
1113 | 1113 | | LOYALTY, REWARDS, PREMIUM FEATURES , DISCOUNTS, OR CLUB CARD PROGRAM . 22 |
---|
1114 | 1114 | | |
---|
1115 | 1115 | | (G) (1) IF A CONSUMER ’S DECISION TO OPT OU T OF THE PROCESSING OF 23 |
---|
1116 | 1116 | | THE CONSUMER ’S PERSONAL DATA FOR THE PURPOSES OF TARG ETED ADVERTISING 24 |
---|
1117 | 1117 | | OR THE SALE OF PERSONAL DAT A THROUGH AN OPT –OUT PREFERENCE SIGNA L 25 |
---|
1118 | 1118 | | SENT IN ACCORDANCE W ITH § 14–4508(B)(4)(II) OF THIS SUBTITLE CONFLICTS WITH 26 |
---|
1119 | 1119 | | THE CONSUMER ’S EXISTING CONTROLLE R–SPECIFIC PRIVACY SET TING OR 27 |
---|
1120 | 1120 | | VOLUNTARY PARTICIPAT ION IN A CONTROLLER ’S BONA FIDE LOYALTY , REWARDS, 28 |
---|
1121 | 1121 | | PREMIUM FEATURES , DISCOUNTS, OR CLUB CARD PROGRAM , THE CONTROLLER 29 |
---|
1122 | 1122 | | SHALL COMPLY WITH THE CONSUMER ’S OPT–OUT PREFERENCE SIGNA L. 30 |
---|
1123 | 1123 | | |
---|
1124 | 1124 | | (2) A CONTROLLER MAY: 31 |
---|
1125 | 1125 | | 26 HOUSE BILL 807 |
---|
1126 | 1126 | | |
---|
1127 | 1127 | | |
---|
1128 | 1128 | | (I) NOTIFY A CONSUMER OF THE CONFLICT BETWEEN AN 1 |
---|
1129 | 1129 | | OPT–OUT PREFERENCE SIGNA L AND A CONTROLLER ’S SPECIFIC PRIVACY S ETTING; 2 |
---|
1130 | 1130 | | AND 3 |
---|
1131 | 1131 | | |
---|
1132 | 1132 | | (II) PROVIDE TO THE CONSUMER THE CHOICE TO CONFIRM THE 4 |
---|
1133 | 1133 | | CONTROLLER –SPECIFIC PRIVACY SET TING OR PARTICIPATIO N IN THE PROGRAM . 5 |
---|
1134 | 1134 | | |
---|
1135 | 1135 | | (H) IF A CONTROLLER RESPO NDS TO A CONSUMER OP T–OUT REQUEST 6 |
---|
1136 | 1136 | | RECEIVED IN ACCORDAN CE WITH SUBSECTION (G) OF THIS SECTION BY INFORMING 7 |
---|
1137 | 1137 | | THE CONSUMER OF A CHARGE FOR THE USE O F ANY PRODUCT OR SER VICE, THE 8 |
---|
1138 | 1138 | | CONTROLLER SHALL PRE SENT THE TERMS OF AN Y FINANCIAL INCENTIV E OFFERED 9 |
---|
1139 | 1139 | | IN ACCORDANCE WITH S UBSECTION (F) OF THIS SECTION FOR THE RETENTION , USE, 10 |
---|
1140 | 1140 | | SALE, OR SHARING OF THE CO NSUMER’S PERSONAL DATA . 11 |
---|
1141 | 1141 | | |
---|
1142 | 1142 | | (I) A CONTROLLER OR A PROCESSOR THAT COMPL IES WITH THE 12 |
---|
1143 | 1143 | | VERIFIABLE PARENTAL CONSENT REQUIREMENTS OF THE FEDERAL CHILDREN’S 13 |
---|
1144 | 1144 | | ONLINE PRIVACY PROTECTION ACT IS CONSIDERED TO BE COMPLIANT WITH AN Y 14 |
---|
1145 | 1145 | | OBLIGATION TO OBTAIN PARENTAL CONSENT IN ACCORDANCE WITH THIS SUBTITLE. 15 |
---|
1146 | 1146 | | |
---|
1147 | 1147 | | (J) IF A CONTROLLER SELLS PERSONAL DATA TO THI RD PARTIES OR 16 |
---|
1148 | 1148 | | PROCESSES PERSONAL D ATA FOR TARGETED ADV ERTISING, THE CONTROLLER 17 |
---|
1149 | 1149 | | SHALL CLEARLY AND CO NSPICUOUSLY DISCLOSE : 18 |
---|
1150 | 1150 | | |
---|
1151 | 1151 | | (1) THE PROCESSING ; AND 19 |
---|
1152 | 1152 | | |
---|
1153 | 1153 | | (2) THE MANNER IN WHICH A CONSUMER MAY EXERCIS E THE RIGHT 20 |
---|
1154 | 1154 | | TO OPT OUT OF THE PROCESSIN G. 21 |
---|
1155 | 1155 | | |
---|
1156 | 1156 | | 14–4508. 22 |
---|
1157 | 1157 | | |
---|
1158 | 1158 | | (A) (1) A CONTROLLER SHALL PRO VIDE A CONSUMER WITH A 23 |
---|
1159 | 1159 | | REASONABLY ACCESSIBL E, CLEAR, AND MEANINGFUL PRIVA CY NOTICE THAT 24 |
---|
1160 | 1160 | | INCLUDES: 25 |
---|
1161 | 1161 | | |
---|
1162 | 1162 | | (I) FOR BIOMETRIC DATA PR OCESSED BY THE CONTR OLLER, A 26 |
---|
1163 | 1163 | | WRITTEN POLICY ESTAB LISHING A RETENTION SCHEDULE AND GUIDELI NES FOR 27 |
---|
1164 | 1164 | | PERMANENTLY DESTROYI NG BIOMETRIC DATA ; 28 |
---|
1165 | 1165 | | |
---|
1166 | 1166 | | (II) THE CATEGORIES OF PER SONAL DATA PROCESSED BY THE 29 |
---|
1167 | 1167 | | CONTROLLER ; 30 |
---|
1168 | 1168 | | |
---|
1169 | 1169 | | (III) THE PURPOSE S FOR PROCESSING PERSO NAL DATA; 31 |
---|
1170 | 1170 | | HOUSE BILL 807 27 |
---|
1171 | 1171 | | |
---|
1172 | 1172 | | |
---|
1173 | 1173 | | (IV) HOW A CONSUMER MAY EXERCIS E A CONSUMER RIGHT 1 |
---|
1174 | 1174 | | UNDER THIS SUBTITLE , INCLUDING HOW A CONS UMER MAY APPEAL A 2 |
---|
1175 | 1175 | | CONTROLLER ’S DECISION WITH REGA RD TO THE CONSUMER ’S REQUEST; 3 |
---|
1176 | 1176 | | |
---|
1177 | 1177 | | (V) THE CATEGORIES OF THI RD PARTIES WITH WHICH T HE 4 |
---|
1178 | 1178 | | CONTROLLER SHARES PE RSONAL DATA ; 5 |
---|
1179 | 1179 | | |
---|
1180 | 1180 | | (VI) THE CATEGORIES OF PER SONAL DATA THAT THE 6 |
---|
1181 | 1181 | | CONTROLLER SHARES WI TH THIRD PARTIES ; AND 7 |
---|
1182 | 1182 | | |
---|
1183 | 1183 | | (VII) AN ACTIVE E–MAIL ADDRESS OR OTHER ONL INE 8 |
---|
1184 | 1184 | | MECHANISM THAT A CONSUMER MAY USE TO CONTACT THE CONTROLL ER. 9 |
---|
1185 | 1185 | | |
---|
1186 | 1186 | | (2) THE PRIVACY NOTICE IN PARAGRAPH (1) OF THIS SUBSECTION 10 |
---|
1187 | 1187 | | SHALL BE MADE AVAILA BLE TO THE PUBLIC . 11 |
---|
1188 | 1188 | | |
---|
1189 | 1189 | | (B) (1) A CONTROLLER SHALL EST ABLISH AND DESCRIBE IN THE 12 |
---|
1190 | 1190 | | PRIVACY NOTICE ONE O R MORE SECURE AND RE LIABLE METHODS FOR A CONSUMER 13 |
---|
1191 | 1191 | | TO SUBMIT A REQUEST TO EXERCISE A CONSUMER RIGHT UND ER THIS SUBTITLE. 14 |
---|
1192 | 1192 | | |
---|
1193 | 1193 | | (2) THE METHOD A CONTROLLER CHOOSES TO SATISFY PARAGRAPH 15 |
---|
1194 | 1194 | | (1) OF THIS SUBSECTION SHALL TAKE INTO ACCO UNT: 16 |
---|
1195 | 1195 | | |
---|
1196 | 1196 | | (I) THE WAYS IN WHICH CON SUMERS NORMALLY INTE RACT 17 |
---|
1197 | 1197 | | WITH THE CONTROLLER ; 18 |
---|
1198 | 1198 | | |
---|
1199 | 1199 | | (II) THE NEED FOR SECURE A ND RELIABLE COMMUNIC ATION 19 |
---|
1200 | 1200 | | OF REQUESTS; AND 20 |
---|
1201 | 1201 | | |
---|
1202 | 1202 | | (III) THE ABILITY OF THE CO NTROLLER TO VERIFY T HE 21 |
---|
1203 | 1203 | | IDENTITY OF A CONSUMER MAKING THE REQUEST. 22 |
---|
1204 | 1204 | | |
---|
1205 | 1205 | | (3) (I) A CONTROLLER MAY NOT REQUIRE A CONSUM ER TO 23 |
---|
1206 | 1206 | | CREATE A NEW ACCOUNT IN ORDER TO EXERCISE A CONSUMER RIGHT . 24 |
---|
1207 | 1207 | | |
---|
1208 | 1208 | | (II) A CONTROLLER MAY REQUIRE A CONSUMER T O USE AN 25 |
---|
1209 | 1209 | | EXISTING ACCOUNT TO EXERCISE A CONSUM ER RIGHT. 26 |
---|
1210 | 1210 | | |
---|
1211 | 1211 | | (4) A CONTROLLER MAY CONSI DER THE FOLLOWING ME THODS TO 27 |
---|
1212 | 1212 | | SATISFY PARAGRAPH (1) OF THIS SUBSECTION : 28 |
---|
1213 | 1213 | | |
---|
1214 | 1214 | | (I) PROVIDING A CLEAR AND CONSPICUOUS LINK ON THE 29 |
---|
1215 | 1215 | | CONTROLLER ’S WEBSITE TO A WEBPAGE THAT ALLOWS A CONSUMER , OR AN 30 28 HOUSE BILL 807 |
---|
1216 | 1216 | | |
---|
1217 | 1217 | | |
---|
1218 | 1218 | | AUTHORIZED AGENT OF THE CONSUME R, TO OPT OUT OF THE TA RGETED 1 |
---|
1219 | 1219 | | ADVERTISING OR THE SALE OF THE CONSUMER ’S PERSONAL DATA ; OR 2 |
---|
1220 | 1220 | | |
---|
1221 | 1221 | | (II) ALLOWING A CONSUMER TO OPT OU T OF ANY PROCESSING 3 |
---|
1222 | 1222 | | OF THE CONSUMER ’S PERSONAL DATA F OR THE PURPOSES OF T ARGETED 4 |
---|
1223 | 1223 | | ADVERTISING, OR ANY SALE OF PERSO NAL DATA, THROUGH AN OPT –OUT 5 |
---|
1224 | 1224 | | PREFERENCE SIGNAL SE NT, WITH THE CONSUMER ’S CONSENT, BY A PLATFORM , A 6 |
---|
1225 | 1225 | | TECHNOLOGY , OR A MECHANISM TO THE CON TROLLER INDICATING THE 7 |
---|
1226 | 1226 | | CONSUMER ’S INTENT TO OPT OUT OF THE PROCESSING OR SALE . 8 |
---|
1227 | 1227 | | |
---|
1228 | 1228 | | (5) (I) A PLATFORM, A TECHNOLOGY , OR A MECHANISM USED IN 9 |
---|
1229 | 1229 | | ACCORDANCE WITH PARAGRAPH (4) OF THIS SUBSECTION SHALL: 10 |
---|
1230 | 1230 | | |
---|
1231 | 1231 | | 1. BE CONSUMER –FRIENDLY AND EASY TO USE BY THE 11 |
---|
1232 | 1232 | | AVERAGE CONSUMER ; 12 |
---|
1233 | 1233 | | |
---|
1234 | 1234 | | 2. BE AS CONSISTENT AS P OSSIBLE WITH ANY OT HER 13 |
---|
1235 | 1235 | | SIMILAR PLATFORM , TECHNOLOGY , OR MECHANISM REQUIRE D BY ANY FEDERAL OR 14 |
---|
1236 | 1236 | | STATE LAW OR REGULATI ON; AND 15 |
---|
1237 | 1237 | | |
---|
1238 | 1238 | | 3. ENABLE THE CONTROLLER TO ACCURATELY 16 |
---|
1239 | 1239 | | DETERMINE WHETHER TH E CONSUMER : 17 |
---|
1240 | 1240 | | |
---|
1241 | 1241 | | A. IS A RESIDENT OF THE STATE; AND 18 |
---|
1242 | 1242 | | |
---|
1243 | 1243 | | B. HAS MADE A LEGITIMATE REQUEST TO OPT OUT O F 19 |
---|
1244 | 1244 | | ANY SALE OF THE CONSUMER ’S PERSONAL DATA OR T ARGETED ADVERTISING . 20 |
---|
1245 | 1245 | | |
---|
1246 | 1246 | | (II) A PLATFORM, A TECHNOLOGY , OR A MECHANISM USED IN 21 |
---|
1247 | 1247 | | ACCORDANCE WITH PARAGRAPH (4) OF THIS SUBSECTION : 22 |
---|
1248 | 1248 | | |
---|
1249 | 1249 | | 1. SHALL REQUIRE THE CON SUMER TO MAKE AN 23 |
---|
1250 | 1250 | | AFFIRMATIVE, FREELY GIVEN , AND UNAMBIGUOUS CHOI CE TO OPT OUT OF THE 24 |
---|
1251 | 1251 | | PROCESSING OF THE CO NSUMER’S PERSONAL DATA IN ACCORDANCE WITH THIS 25 |
---|
1252 | 1252 | | SUBTITLE; AND 26 |
---|
1253 | 1253 | | |
---|
1254 | 1254 | | 2. MAY NOT: 27 |
---|
1255 | 1255 | | |
---|
1256 | 1256 | | A. UNFAIRLY DISADVANTAGE ANOTHER CONTROLLER ; 28 |
---|
1257 | 1257 | | OR 29 |
---|
1258 | 1258 | | |
---|
1259 | 1259 | | B. MAKE USE OF A DEFAULT SETTING . 30 |
---|
1260 | 1260 | | HOUSE BILL 807 29 |
---|
1261 | 1261 | | |
---|
1262 | 1262 | | |
---|
1263 | 1263 | | (C) (1) THIS SUBSECTION APPLI ES ONLY TO A CONTROLLER THAT 1 |
---|
1264 | 1264 | | COLLECTS THE BIOMETRIC DATA OF CONSUMERS . 2 |
---|
1265 | 1265 | | |
---|
1266 | 1266 | | (2) EXCEPT AS PROVIDED IN PARAGRAPH S (4) AND (5) OF THIS 3 |
---|
1267 | 1267 | | SUBSECTION, A CONTROLLER IN POSSESSION OF BIO METRIC DATA SHALL DE VELOP 4 |
---|
1268 | 1268 | | A WRITTEN POLICY , MADE AVAILABLE TO TH E PUBLIC, ESTABLISHING A RETEN TION 5 |
---|
1269 | 1269 | | SCHEDULE AND GUIDELI NES FOR PERMANENTLY DESTROYING BIOMETRIC DATA ON 6 |
---|
1270 | 1270 | | THE EARLIEST OF THE FOLLOWING: 7 |
---|
1271 | 1271 | | |
---|
1272 | 1272 | | (I) THE DATE ON WHICH THE INITIAL PURPOSE FOR 8 |
---|
1273 | 1273 | | COLLECTING OR OBTAIN ING THE BIOMETRIC DA TA HAS BEEN SATISFIE D; 9 |
---|
1274 | 1274 | | |
---|
1275 | 1275 | | (II) WITHIN 3 YEARS AFTER THE CONSUMER ’S LAST 10 |
---|
1276 | 1276 | | INTERACTION WITH THE CONTROLLER IN POSSESSION OF THE BIOMETRIC DATA ; OR 11 |
---|
1277 | 1277 | | |
---|
1278 | 1278 | | (III) WITHIN 30 DAYS AFTER THE CONTROLLER RECEIVES A 12 |
---|
1279 | 1279 | | VERIFIED REQUEST TO DELETE THE BIOMETRIC DATA SUBMITTED BY TH E 13 |
---|
1280 | 1280 | | CONSUMER OR THE CONSUMER ’S AUTHORIZED AGENT . 14 |
---|
1281 | 1281 | | |
---|
1282 | 1282 | | (3) ABSENT A VALID WARRAN T OR SUBPOENA ISSUED BY A COURT OF 15 |
---|
1283 | 1283 | | COMPETENT JURISDICTI ON, A CONTROLLER IN POSSESSION OF BIO METRIC DATA 16 |
---|
1284 | 1284 | | SHALL COMPLY WIT H THE RETENTION SCHE DULE AND DESTRUCTION GUIDELINES 17 |
---|
1285 | 1285 | | DEVELOPED UNDER PARA GRAPH (2) OF THIS SUBSECTION . 18 |
---|
1286 | 1286 | | |
---|
1287 | 1287 | | (4) A CONTROLLER IN POSSESSION OF BIO METRIC DATA FOR FRAU D 19 |
---|
1288 | 1288 | | PREVENTION OR SECURI TY PURPOSES IS NOT R EQUIRED TO DESTROY A 20 |
---|
1289 | 1289 | | CONSUMER ’S BIOMETRIC DATA IN ACCORDANCE WITH PARAGR APH (2)(II) AND (III) 21 |
---|
1290 | 1290 | | OF THIS SUBSECTION I F THE CONSUMER IS PART OF THE STATE VOLUNTARY 22 |
---|
1291 | 1291 | | EXCLUSION PROGRAM. 23 |
---|
1292 | 1292 | | |
---|
1293 | 1293 | | (5) A CONTROLLER MAY NOT BE REQUIRED TO MAKE PUBLICLY 24 |
---|
1294 | 1294 | | AVAILABLE A WRITTEN POLICY DEVELOPED UND ER THIS SUBSECTION IF: 25 |
---|
1295 | 1295 | | |
---|
1296 | 1296 | | (I) THE CONTROLLER COLLECTS B IOMETRIC DATA ONLY FROM 26 |
---|
1297 | 1297 | | THE CONTROLLER ’S EMPLOYEES; AND 27 |
---|
1298 | 1298 | | |
---|
1299 | 1299 | | (II) THE BIOMETRIC DATA I S USED SOLELY FOR IN TERNAL 28 |
---|
1300 | 1300 | | COMPANY OPERATIONS . 29 |
---|
1301 | 1301 | | |
---|
1302 | 1302 | | 14–4509. 30 |
---|
1303 | 1303 | | |
---|
1304 | 1304 | | (A) (1) IF A CONTROLLER USES A PR OCESSOR TO PROCESS T HE 31 |
---|
1305 | 1305 | | PERSONAL DATA OF CON SUMERS, THE CONTROLLER AND T HE PROCESSOR SHALL 32 30 HOUSE BILL 807 |
---|
1306 | 1306 | | |
---|
1307 | 1307 | | |
---|
1308 | 1308 | | ENTER INTO A CONTRAC T THAT GOVERNS THE PROCESSOR ’S DATA PROCESSING 1 |
---|
1309 | 1309 | | PROCEDURES WITH RESP ECT TO PROCESSING PE RFORMED ON BEHALF OF THE 2 |
---|
1310 | 1310 | | CONTROLLER . 3 |
---|
1311 | 1311 | | |
---|
1312 | 1312 | | (2) THE CONTRACT SHALL PR OVIDE CLEAR INSTRUCT IONS FOR: 4 |
---|
1313 | 1313 | | |
---|
1314 | 1314 | | (I) PROCESSING DATA ; 5 |
---|
1315 | 1315 | | |
---|
1316 | 1316 | | (II) THE NATURE AND PURPOS E OF PROCESSING ; 6 |
---|
1317 | 1317 | | |
---|
1318 | 1318 | | (III) THE TYPE OF DATA SUBJ ECT TO PROCESSING ; 7 |
---|
1319 | 1319 | | |
---|
1320 | 1320 | | (IV) THE DURATION OF PROCE SSING; AND 8 |
---|
1321 | 1321 | | |
---|
1322 | 1322 | | (V) THE RIGHTS AND OBLIGA TIONS OF THE CONTROLLER AN D 9 |
---|
1323 | 1323 | | THE PROCESSOR . 10 |
---|
1324 | 1324 | | |
---|
1325 | 1325 | | (3) THE CONTRACT SHALL RE QUIRE THAT THE PROCE SSOR: 11 |
---|
1326 | 1326 | | |
---|
1327 | 1327 | | (I) ENSURE THAT EACH PERS ON PROCESSING PERSON AL DATA 12 |
---|
1328 | 1328 | | IS SUBJECT TO A DUTY OF CONFIDENTIALITY W ITH RESPECT TO THE D ATA; 13 |
---|
1329 | 1329 | | |
---|
1330 | 1330 | | (II) UNLESS RETENTION OF T HE PERSONAL DATA IS REQUIRED 14 |
---|
1331 | 1331 | | BY LAW, AT THE CONTROLLER ’S DIRECTION, DELETE OR RETURN ALL PERSONAL 15 |
---|
1332 | 1332 | | DATA TO THE CONTROLL ER AS REQUESTED AT T HE END OF THE PROVIS ION OF 16 |
---|
1333 | 1333 | | SERVICE; 17 |
---|
1334 | 1334 | | |
---|
1335 | 1335 | | (III) MAKE AVAILABLE TO THE CONTROLLER ALL INFOR MATION 18 |
---|
1336 | 1336 | | IN THE PROCESSOR ’S POSSESSION NECESSARY TO DEMONST RATE THE PROCESSOR ’S 19 |
---|
1337 | 1337 | | COMPLIANCE WITH THE OBLIGATIONS IN THIS SUBTITLE; 20 |
---|
1338 | 1338 | | |
---|
1339 | 1339 | | (IV) AFTER PROVIDING THE C ONTROLLER AN OPPORTU NITY TO 21 |
---|
1340 | 1340 | | OBJECT, REQUIRE A SUBCONTRACTOR TO SIGN A CONTRACT A GREEING TO M EET 22 |
---|
1341 | 1341 | | THE OBLIGATIONS OF T HE PROCESSOR WITH R ESPECT TO THE PERSON AL DATA; AND 23 |
---|
1342 | 1342 | | |
---|
1343 | 1343 | | (V) ALLOW AND COOPERATE W ITH REASONABLE ASSES SMENTS 24 |
---|
1344 | 1344 | | BY THE CONTROLLER , THE CONTROLLER ’S DESIGNATED ASSESSO R, OR A QUALIFIED 25 |
---|
1345 | 1345 | | AND INDEPENDENT ASSE SSOR TO ASSESS THE PROCESSOR ’S POLICIES AND 26 |
---|
1346 | 1346 | | TECHNICAL AND ORGANI ZATIONAL ME ASURES TO COMPLY WITH THE OBLIGATIONS 27 |
---|
1347 | 1347 | | UNDER THIS SUBTITLE . 28 |
---|
1348 | 1348 | | HOUSE BILL 807 31 |
---|
1349 | 1349 | | |
---|
1350 | 1350 | | |
---|
1351 | 1351 | | (4) (I) ON REQUEST, THE PROCESSOR SHALL PROVIDE A REPORT 1 |
---|
1352 | 1352 | | OF AN ASSESSMENT REQUIRED BY PARAGRAP H (3)(V) OF THIS SUBSECTION TO THE 2 |
---|
1353 | 1353 | | CONTROLLER . 3 |
---|
1354 | 1354 | | |
---|
1355 | 1355 | | (II) AN ASSESSMENT CONDUCT ED IN ACCORDANCE WIT H 4 |
---|
1356 | 1356 | | PARAGRAPH (3)(V) OF THIS SUBSECTION S HALL BE CONDUCTED US ING AN 5 |
---|
1357 | 1357 | | APPROPRIATE AND ACCE PTED CONTROL STANDAR D OR FRAMEWORK AND 6 |
---|
1358 | 1358 | | ASSESSMENT PROCEDURE FOR THE ASSESSMENTS . 7 |
---|
1359 | 1359 | | |
---|
1360 | 1360 | | (B) A PROCESSOR SHALL ADHE RE TO THE INSTRUCTIO NS OF A 8 |
---|
1361 | 1361 | | CONTROLLER AND SHALL ASSIST THE CONTROLLER IN MEETIN G THE 9 |
---|
1362 | 1362 | | CONTROLLER ’S OBLIGATIONS UNDER THIS SUBTITLE, INCLUDING: 10 |
---|
1363 | 1363 | | |
---|
1364 | 1364 | | (1) TAKING INTO ACCOUNT T HE NATURE OF PROCESS ING AND THE 11 |
---|
1365 | 1365 | | INFORMATION AVAILABL E TO THE PROCESSOR BY FULFILLING THE CONTROLLER ’S 12 |
---|
1366 | 1366 | | OBLIGATION TO RESPON D TO CONSUMER RIGHTS REQUESTS; 13 |
---|
1367 | 1367 | | |
---|
1368 | 1368 | | (2) TAKING INTO ACCOUNT T HE NATURE OF PROCESS ING AND THE 14 |
---|
1369 | 1369 | | INFORMATION AVAILABL E TO THE PROCESSOR , BY ASSISTING THE CON TROLLER IN 15 |
---|
1370 | 1370 | | MEETING THE CONTROLL ER’S OBLIGATIONS IN REL ATION TO THE SECURIT Y OF 16 |
---|
1371 | 1371 | | PROCESSING PERSONAL DATA AND THE NOTIFIC ATION OF A BREACH OF SECURITY 17 |
---|
1372 | 1372 | | OF THE SYSTEM OF THE PROCESSOR, AS DEFINED IN § 14–3504 OF THIS TITLE, IN 18 |
---|
1373 | 1373 | | ORDER TO MEET THE CO NTROLLER’S OBLIGATIONS; AND 19 |
---|
1374 | 1374 | | |
---|
1375 | 1375 | | (3) PROVIDING NECESSARY I NFORMATION TO ENABLE THE 20 |
---|
1376 | 1376 | | CONTROLLER TO CONDUC T AND DOCUMENT DATA PROTECTION ASSESSMENTS . 21 |
---|
1377 | 1377 | | |
---|
1378 | 1378 | | (C) NOTHING IN THIS SECTI ON MAY BE CONSTRUED TO RELI EVE A 22 |
---|
1379 | 1379 | | CONTROLLER OR A PROCESSOR FROM THE L IABILITIES IMPOSED O N THE 23 |
---|
1380 | 1380 | | CONTROLLER OR PROCES SOR BY VIRTUE OF THE CONTROLLER ’S OR PROCESSOR ’S 24 |
---|
1381 | 1381 | | ROLE IN THE PROCESSI NG RELATIONSHIP . 25 |
---|
1382 | 1382 | | |
---|
1383 | 1383 | | (D) (1) THE DETERMINATION OF WHETHER A PERSON IS ACTING AS A 26 |
---|
1384 | 1384 | | CONTROLLER OR A PROCESSOR WITH RESPE CT TO A SPECIFIC PRO CESSING OF DATA 27 |
---|
1385 | 1385 | | IS A FACT–BASED DETERMINATION THAT DEPENDS UPON TH E CONTEXT IN WHICH 28 |
---|
1386 | 1386 | | PERSONAL DATA IS BEING PROCESSED. 29 |
---|
1387 | 1387 | | |
---|
1388 | 1388 | | (2) A PERSON IS CONSIDERED TO BE A C ONTROLLER IF THE PER SON: 30 |
---|
1389 | 1389 | | |
---|
1390 | 1390 | | (I) IS NOT LIMITED IN THE PERSON’S PROCESSING OF SPEC IFIC 31 |
---|
1391 | 1391 | | PERSONAL DATA IN ACC ORDANCE WITH A CONTR OLLER’S INSTRUCTIONS ; OR 32 |
---|
1392 | 1392 | | 32 HOUSE BILL 807 |
---|
1393 | 1393 | | |
---|
1394 | 1394 | | |
---|
1395 | 1395 | | (II) FAILS TO FOLLOW A CON TROLLER’S INSTRUCTIONS 1 |
---|
1396 | 1396 | | REGARDING THE SPECIF IC PROCESSING OF PERSONAL DATA . 2 |
---|
1397 | 1397 | | |
---|
1398 | 1398 | | (3) IF A PROCESSOR, ALONE OR JOINTLY WIT H OTHERS, DETERMINES 3 |
---|
1399 | 1399 | | THE PURPOSES AND MEA NS OF THE PROCESSING OF PERSONAL DATA , THE 4 |
---|
1400 | 1400 | | PROCESSOR: 5 |
---|
1401 | 1401 | | |
---|
1402 | 1402 | | (I) IS A CONTROLLER WITH RESPECT TO THE PROCESSING; AND 6 |
---|
1403 | 1403 | | |
---|
1404 | 1404 | | (II) MAY BE SUBJECT TO AN ENFORCEMENT ACTION U NDER 7 |
---|
1405 | 1405 | | THIS SUBTITLE. 8 |
---|
1406 | 1406 | | |
---|
1407 | 1407 | | 14–4510. 9 |
---|
1408 | 1408 | | |
---|
1409 | 1409 | | (A) IN THIS SECTION , “PROCESSING ACTIVITIES THAT PRESENT A 10 |
---|
1410 | 1410 | | HEIGHTENED RISK OF H ARM TO A CONSUMER ” MEANS: 11 |
---|
1411 | 1411 | | |
---|
1412 | 1412 | | (1) THE PROCESSING OF PER SONAL DATA FOR THE P URPOSES OF 12 |
---|
1413 | 1413 | | TARGETED ADVERTISING; 13 |
---|
1414 | 1414 | | |
---|
1415 | 1415 | | (2) THE SALE OF PERSONAL DATA; 14 |
---|
1416 | 1416 | | |
---|
1417 | 1417 | | (3) THE PROCESSING OF SEN SITIVE DATA; AND 15 |
---|
1418 | 1418 | | |
---|
1419 | 1419 | | (4) THE PROCESSING OF PER SONAL DATA FOR THE P URPOSES OF 16 |
---|
1420 | 1420 | | PROFILING, IN WHICH THE PROFILING PRESENTS A REASONABLY FORESEEAB LE 17 |
---|
1421 | 1421 | | RISK OF: 18 |
---|
1422 | 1422 | | |
---|
1423 | 1423 | | (I) UNFAIR, ABUSIVE, OR DECEPTIVE TREATMENT OF A 19 |
---|
1424 | 1424 | | CONSUMER ; 20 |
---|
1425 | 1425 | | |
---|
1426 | 1426 | | (II) HAVING AN UNLAWFUL DISPARATE I MPACT ON A 21 |
---|
1427 | 1427 | | CONSUMER ; 22 |
---|
1428 | 1428 | | |
---|
1429 | 1429 | | (III) FINANCIAL, PHYSICAL, OR REPUTATIONAL INJU RY TO A 23 |
---|
1430 | 1430 | | CONSUMER ; 24 |
---|
1431 | 1431 | | |
---|
1432 | 1432 | | (IV) A PHYSICAL OR OTHER IN TRUSION ON THE SOLIT UDE OR 25 |
---|
1433 | 1433 | | SECLUSION OR THE PRI VATE AFFAIRS OR CONC ERNS OF A CONSUMER INTO WHICH 26 |
---|
1434 | 1434 | | THE INTRUSION WOULD BE O FFENSIVE TO A REASON ABLE PERSON; OR 27 |
---|
1435 | 1435 | | |
---|
1436 | 1436 | | (V) OTHER SUBSTANTIAL INJ URY TO A CONSUMER . 28 |
---|
1437 | 1437 | | HOUSE BILL 807 33 |
---|
1438 | 1438 | | |
---|
1439 | 1439 | | |
---|
1440 | 1440 | | (B) A CONTROLLER SHALL CONDUCT AND DOCUMENT A DATA PROTECTION 1 |
---|
1441 | 1441 | | ASSESSMENT FOR EACH OF THE CONTROLLER ’S PROCESSING ACTIVIT IES THAT 2 |
---|
1442 | 1442 | | PRESENT A HEIGHTENED RISK OF HARM TO A CO NSUMER. 3 |
---|
1443 | 1443 | | |
---|
1444 | 1444 | | (C) (1) A DATA PROTECTION ASSES SMENT CONDUCTED IN ACCORDANCE 4 |
---|
1445 | 1445 | | WITH THIS SECTION SHALL IDENTIFY AND WEIGH THE BENEFITS OF THE 5 |
---|
1446 | 1446 | | PROCESSING TO THE CO NTROLLER, THE CONSUMER , OTHER STAKEHOLDERS , AND 6 |
---|
1447 | 1447 | | THE PUBLIC AGAINST T HE POTENTIAL RISKS T O THE RIGHTS OF THE CONSUMER 7 |
---|
1448 | 1448 | | ASSOCIATED WITH THE PROCESSING. 8 |
---|
1449 | 1449 | | |
---|
1450 | 1450 | | (2) THE CONTROLLER SHALL FACTOR INTO A DATA P ROTECTION 9 |
---|
1451 | 1451 | | ASSESSMENT : 10 |
---|
1452 | 1452 | | |
---|
1453 | 1453 | | (I) THE USE OF DE–IDENTIFIED DATA ; 11 |
---|
1454 | 1454 | | |
---|
1455 | 1455 | | (II) THE REASONABLE EXPECT ATIONS OF CONSUMERS ; 12 |
---|
1456 | 1456 | | |
---|
1457 | 1457 | | (III) THE CONTEXT OF THE PR OCESSING; 13 |
---|
1458 | 1458 | | |
---|
1459 | 1459 | | (IV) THE RELATIONSHIP BETW EEN THE CONT ROLLER AND THE 14 |
---|
1460 | 1460 | | CONSUMER WHOSE PERSO NAL DATA WILL BE PRO CESSED; AND 15 |
---|
1461 | 1461 | | |
---|
1462 | 1462 | | (V) THE SAFEGUARDS THAT C AN BE EMPLOYED BY TH E 16 |
---|
1463 | 1463 | | CONTROLLER TO REDUCE THE RISKS AGAINST CO NSUMERS ASSOCIATED W ITH THE 17 |
---|
1464 | 1464 | | PROCESSING. 18 |
---|
1465 | 1465 | | |
---|
1466 | 1466 | | (D) (1) THE DIVISION MAY REQUIRE THAT A C ONTROLLER MAKE 19 |
---|
1467 | 1467 | | AVAILABLE TO THE DIVISION A DATA PROTECTION AS SESSMENT THAT IS REL EVANT 20 |
---|
1468 | 1468 | | TO AN INVESTIGATION CONDUCTED BY THE DIVISION. 21 |
---|
1469 | 1469 | | |
---|
1470 | 1470 | | (2) THE DIVISION MAY EVALUATE A DATA PROTECTION ASSE SSMENT 22 |
---|
1471 | 1471 | | FOR COMPLIANCE WITH THE RESPONSIBILITIES ESTABLISHED IN THIS SUBTITLE. 23 |
---|
1472 | 1472 | | |
---|
1473 | 1473 | | (E) A SINGLE DATA PROTECTI ON ASSESSMENT MAY ADDRE SS A 24 |
---|
1474 | 1474 | | COMPARABLE SET OF PR OCESSING OPERATIONS THAT INCLUDE SIMILAR 25 |
---|
1475 | 1475 | | ACTIVITIES. 26 |
---|
1476 | 1476 | | |
---|
1477 | 1477 | | (F) IF A CONTROLLER CONDU CTS A DATA PROTECTIO N ASSESSMENT FOR 27 |
---|
1478 | 1478 | | THE PURPOSE OF COMPL YING WITH ANOTHER LA W OR REGULATION , THE DATA 28 |
---|
1479 | 1479 | | PROTECTION ASSESSMEN T SHALL SATISFY THE REQUIREM ENTS ESTABLISHED IN 29 |
---|
1480 | 1480 | | THIS SECTION IF THE DATA PROTECTION ASSE SSMENT IS REASONABLY SIMILAR IN 30 |
---|
1481 | 1481 | | SCOPE AND EFFECT TO THE DATA PROTECTION ASSESSMENT THAT WOUL D 31 |
---|
1482 | 1482 | | OTHERWISE BE CONDUCT ED IN ACCORDANCE WITH THIS SECTION. 32 34 HOUSE BILL 807 |
---|
1483 | 1483 | | |
---|
1484 | 1484 | | |
---|
1485 | 1485 | | |
---|
1486 | 1486 | | (G) A DATA PROTECTION A SSESSMENT SHALL BE C ONFIDENTIAL AND 1 |
---|
1487 | 1487 | | EXEMPT FROM DISCLOSU RE UNDER THE MARYLAND PUBLIC INFORMATION ACT. 2 |
---|
1488 | 1488 | | |
---|
1489 | 1489 | | 14–4511. 3 |
---|
1490 | 1490 | | |
---|
1491 | 1491 | | (A) NOTHING IN THIS SECTI ON MAY BE CONSTRUED TO : 4 |
---|
1492 | 1492 | | |
---|
1493 | 1493 | | (1) REQUIRE A CONTROLLER OR A PROCESSOR TO RE –IDENTIFY 5 |
---|
1494 | 1494 | | DE–IDENTIFIED DATA ; 6 |
---|
1495 | 1495 | | |
---|
1496 | 1496 | | (2) MAINTAIN DATA IN AN IDENTIFIABLE FORM ; OR 7 |
---|
1497 | 1497 | | |
---|
1498 | 1498 | | (3) COLLECT, OBTAIN, RETAIN, OR ACCESS ANY DATA O R 8 |
---|
1499 | 1499 | | TECHNOLOGY IN ORDER TO BE CAPABLE OF ASS OCIATING AN AUTHENTI CATED 9 |
---|
1500 | 1500 | | CONSUMER REQUEST WIT H PERSONAL DATA . 10 |
---|
1501 | 1501 | | |
---|
1502 | 1502 | | (B) A CONTROLLER IN POSSES SION OF DE–IDENTIFIED DATA SHALL: 11 |
---|
1503 | 1503 | | |
---|
1504 | 1504 | | (1) TAKE REASONABLE MEASU RES TO ENSURE THAT T HE DATA 12 |
---|
1505 | 1505 | | CANNOT BE ASSOCIATED WITH A CONSUMER ; 13 |
---|
1506 | 1506 | | |
---|
1507 | 1507 | | (2) PUBLICLY COMMIT TO MA INTAINING AND USING DE–IDENTIFIED 14 |
---|
1508 | 1508 | | DATA WITHOUT ATTEMPT ING TO RE–IDENTIFY THE DATA ; AND 15 |
---|
1509 | 1509 | | |
---|
1510 | 1510 | | (3) CONTRACTUALLY OBLIGAT E A RECIPIEN T OF DE–IDENTIFIED 16 |
---|
1511 | 1511 | | DATA TO COMPLY WITH ITEMS (1) AND (2) OF THIS SUBSECTION . 17 |
---|
1512 | 1512 | | |
---|
1513 | 1513 | | (C) A CONTROLLER THAT DISC LOSES DE–IDENTIFIED DATA SHAL L: 18 |
---|
1514 | 1514 | | |
---|
1515 | 1515 | | (1) EXERCISE REASONABLE O VERSIGHT TO MONITOR COMPLIANCE 19 |
---|
1516 | 1516 | | WITH A CONTRACTUAL COMMITME NT TO WHICH THE DE –IDENTIFIED DATA IS 20 |
---|
1517 | 1517 | | SUBJECT; AND 21 |
---|
1518 | 1518 | | |
---|
1519 | 1519 | | (2) IF NECESSARY, TAKE APPROPRIATE STEP S TO ADDRESS A BREAC H 22 |
---|
1520 | 1520 | | OF A CONTRACTUAL COMMITME NT. 23 |
---|
1521 | 1521 | | |
---|
1522 | 1522 | | (D) A CONTROLLER THAT POSS ESSES THE DE–IDENTIFIED DATA SHALL: 24 |
---|
1523 | 1523 | | |
---|
1524 | 1524 | | (1) TAKE REASONABLE MEASU RES TO ENSURE THAT T HE DATA 25 |
---|
1525 | 1525 | | CANNOT BE ASSOCIATED WITH A CONSUMER ; 26 |
---|
1526 | 1526 | | |
---|
1527 | 1527 | | (2) PUBLICLY COMMIT TO : 27 HOUSE BILL 807 35 |
---|
1528 | 1528 | | |
---|
1529 | 1529 | | |
---|
1530 | 1530 | | |
---|
1531 | 1531 | | (I) PROCESS THE DATA ONLY IN A DE–IDENTIFIED MANNER ; 1 |
---|
1532 | 1532 | | AND 2 |
---|
1533 | 1533 | | |
---|
1534 | 1534 | | (II) NOT ATTEMPT TO RE –IDENTIFY THE DATA ; AND 3 |
---|
1535 | 1535 | | |
---|
1536 | 1536 | | (3) CONTRACTUALLY OBLIGAT E A RECIPIENT OF THE DATA TO 4 |
---|
1537 | 1537 | | SATISFY THE CRITERIA IN ITEMS (1) AND (2) OF THIS SUBSECTION . 5 |
---|
1538 | 1538 | | |
---|
1539 | 1539 | | 14–4512. 6 |
---|
1540 | 1540 | | |
---|
1541 | 1541 | | (A) EXCEPT AS PROVIDED IN SUBSECTION (B) OF THIS SECTION , A 7 |
---|
1542 | 1542 | | VIOLATION OF THIS SU BTITLE IS: 8 |
---|
1543 | 1543 | | |
---|
1544 | 1544 | | (1) AN UNFAIR, ABUSIVE, OR DECEPTIVE TRADE PRACTICE WITHI N 9 |
---|
1545 | 1545 | | THE MEANING OF TITLE 13 OF THIS ARTICLE; AND 10 |
---|
1546 | 1546 | | |
---|
1547 | 1547 | | (2) SUBJECT TO THE ENFORC EMENT AND PENALTY PR OVISIONS 11 |
---|
1548 | 1548 | | CONTAINED IN TITLE 13 OF THIS ARTICLE, EXCEPT FOR § 13–408 OF THIS ARTICLE. 12 |
---|
1549 | 1549 | | |
---|
1550 | 1550 | | (B) IN ADDITION TO THE RE MEDIES AVAILABLE IN SUBSECTION (A) OF THIS 13 |
---|
1551 | 1551 | | SECTION, A CONSUMER WHO IS AFFECTED BY A VIOLATION OF § 14–4507(A)(1) OF 14 |
---|
1552 | 1552 | | THIS SUBTITLE MAY BR ING AN ACTION AGAINS T THE CONTROLLER IN ACCORDANCE 15 |
---|
1553 | 1553 | | WITH § 13–408 OF THIS ARTICLE. 16 |
---|
1554 | 1554 | | |
---|
1555 | 1555 | | SECTION 2. AND BE IT FURTHER ENACTED, That: 17 |
---|
1556 | 1556 | | |
---|
1557 | 1557 | | (a) There is a Task Force to Study Online Data Privacy. 18 |
---|
1558 | 1558 | | |
---|
1559 | 1559 | | (b) The Task Force consists of the following members: 19 |
---|
1560 | 1560 | | |
---|
1561 | 1561 | | (1) two members of the Senate of Maryland, appointed by the President of 20 |
---|
1562 | 1562 | | the Senate; 21 |
---|
1563 | 1563 | | |
---|
1564 | 1564 | | (2) two members of the House of Delegates, appointed by the Speaker of 22 |
---|
1565 | 1565 | | the House; 23 |
---|
1566 | 1566 | | |
---|
1567 | 1567 | | (3) the Attorney General, or the Attorney General’s designee; 24 |
---|
1568 | 1568 | | |
---|
1569 | 1569 | | (4) the following members, appointed by the Governor: 25 |
---|
1570 | 1570 | | |
---|
1571 | 1571 | | (i) one representative of the business sector; 26 |
---|
1572 | 1572 | | |
---|
1573 | 1573 | | (ii) one representative of the academic sector; 27 |
---|
1574 | 1574 | | 36 HOUSE BILL 807 |
---|
1575 | 1575 | | |
---|
1576 | 1576 | | |
---|
1577 | 1577 | | (iii) one representative from a consumer advocacy group; and 1 |
---|
1578 | 1578 | | |
---|
1579 | 1579 | | (iv) two attorneys with experience in privacy law. 2 |
---|
1580 | 1580 | | |
---|
1581 | 1581 | | (c) The Governor shall designate the chair of the Task Force. 3 |
---|
1582 | 1582 | | |
---|
1583 | 1583 | | (d) The State agencies represented on the Task Force shall provide staff for the 4 |
---|
1584 | 1584 | | Task Force. 5 |
---|
1585 | 1585 | | |
---|
1586 | 1586 | | (e) A member of the Task Force: 6 |
---|
1587 | 1587 | | |
---|
1588 | 1588 | | (1) may not receive compensation as a member of the Task Force; but 7 |
---|
1589 | 1589 | | |
---|
1590 | 1590 | | (2) is entitled to reimbursement for expenses under the Standard State 8 |
---|
1591 | 1591 | | Travel Regulations, as provided in the State budget. 9 |
---|
1592 | 1592 | | |
---|
1593 | 1593 | | (f) The Task Force shall: 10 |
---|
1594 | 1594 | | |
---|
1595 | 1595 | | (1) study and make recommendations regarding: 11 |
---|
1596 | 1596 | | |
---|
1597 | 1597 | | (i) information sharing among health care and social care providers; 12 |
---|
1598 | 1598 | | |
---|
1599 | 1599 | | (ii) algorithmic decision–making and the proper use of data to reduce 13 |
---|
1600 | 1600 | | bias in algorithmic decision–making; 14 |
---|
1601 | 1601 | | |
---|
1602 | 1602 | | (iii) requiring an operator, upon a parent’s request, to delete the 15 |
---|
1603 | 1603 | | account of a child and cease to collect, use or maintain, in retrievable form, the child’s 16 |
---|
1604 | 1604 | | personal data on the operator’s website or online service directed to children, and provide 17 |
---|
1605 | 1605 | | parents with an accessible, reasonable, and verifiable means to make the request; 18 |
---|
1606 | 1606 | | |
---|
1607 | 1607 | | (iv) methods of verifying the age of a child who creates a social media 19 |
---|
1608 | 1608 | | account; 20 |
---|
1609 | 1609 | | |
---|
1610 | 1610 | | (v) issues concerning data colocation, including the impact that the 21 |
---|
1611 | 1611 | | provisions of Section 1 of this Act may have on third parties that provide data storage and 22 |
---|
1612 | 1612 | | colocation services; 23 |
---|
1613 | 1613 | | |
---|
1614 | 1614 | | (vi) issues surrounding additional persons or groups that are subject 24 |
---|
1615 | 1615 | | to the provisions of Section 1 of this Act; and 25 |
---|
1616 | 1616 | | |
---|
1617 | 1617 | | (vii) other topics concerning online data privacy; and 26 |
---|
1618 | 1618 | | |
---|
1619 | 1619 | | (2) make recommendations for future data privacy legislation. 27 |
---|
1620 | 1620 | | |
---|
1621 | 1621 | | (g) On or before June 1, 2024, the Task Force shall report its findings and 28 |
---|
1622 | 1622 | | recommendations to the Governor and, in accordance with § 2–1257 of the State 29 HOUSE BILL 807 37 |
---|
1623 | 1623 | | |
---|
1624 | 1624 | | |
---|
1625 | 1625 | | Government Article, the Senate Finance Committee and the House Economic Matters 1 |
---|
1626 | 1626 | | Committee. 2 |
---|
1627 | 1627 | | |
---|
1628 | 1628 | | SECTION 3. AND BE IT FURTHER ENACTED, That § 14–4510 of the Commercial 3 |
---|
1629 | 1629 | | Law Article, as enacted by Section 1 of this Act, shall be construed to apply only 4 |
---|
1630 | 1630 | | prospectively and may not be applied or interpreted to have any effect on or application to 5 |
---|
1631 | 1631 | | any personal data processing activities before the effective date of this Act. 6 |
---|
1632 | 1632 | | |
---|
1633 | 1633 | | SECTION 4. AND BE IT FURTHER ENACTED, That this Act shall take effect 7 |
---|
1634 | 1634 | | October 1, 2023. Section 2 of this Act shall remain effective for a period of 2 years and, at 8 |
---|
1635 | 1635 | | the end of September 30, 2025, Section 2 of this Act, with no further action required by the 9 |
---|
1636 | 1636 | | General Assembly, shall be abrogated and of no further force and effect. 10 |
---|