Maryland 2025 Regular Session

Maryland House Bill HB1365 Compare Versions

Only one version of the bill is available at this time.
OldNewDifferences
11
22
33 EXPLANATION: CAPITALS INDICATE MAT TER ADDED TO EXISTIN G LAW.
44 [Brackets] indicate matter deleted from existing law.
55 *hb1365*
66
77 HOUSE BILL 1365
88 I3 5lr3142
99
1010 By: Delegate Harrison
1111 Introduced and read first time: February 7, 2025
1212 Assigned to: Economic Matters
1313
1414 A BILL ENTITLED
1515
1616 AN ACT concerning 1
1717
1818 Commercial Law – Online Data Privacy – Limits on Data Collection 2
1919
2020 FOR the purpose of altering certain requirements for a controller relating to the collection 3
2121 of personal data; and generally relating to the collection and processing of personal 4
2222 data. 5
2323
2424 BY repealing and reenacting, without amendments, 6
2525 Article – Commercial Law 7
2626 Section 14–4701(a), (k), and (w) 8
2727 Annotated Code of Maryland 9
2828 (2013 Replacement Volume and 2024 Supplement) 10
2929 (As enacted by Chapter 454 of the Acts of the General Assembly of 2024) 11
3030
3131 BY repealing and reenacting, with amendments, 12
3232 Article – Commercial Law 13
3333 Section 14–4707(b)(1) 14
3434 Annotated Code of Maryland 15
3535 (2013 Replacement Volume and 2024 Supplement) 16
3636 (As enacted by Chapter 454 of the Acts of the General Assembly of 2024) 17
3737
3838 SECTION 1. BE IT ENACTED BY THE GENERAL ASSEMBLY OF MARYLAND, 18
3939 That the Laws of Maryland read as follows: 19
4040
4141 Article – Commercial Law 20
4242
4343 14–4701. 21
4444
4545 (a) In this subtitle the following words have the meanings indicated. 22
4646
4747 (k) “Controller” means a person that, alone or jointly with others, determines the 23
4848 purpose and means of processing personal data. 24 2 HOUSE BILL 1365
4949
5050
5151
5252 (w) (1) “Personal data” means any information that is linked or can be 1
5353 reasonably linked to an identified or identifiable consumer. 2
5454
5555 (2) “Personal data” does not include: 3
5656
5757 (i) De–identified data; or 4
5858
5959 (ii) Publicly available information. 5
6060
6161 14–4707. 6
6262
6363 (b) (1) A controller shall: 7
6464
6565 (i) Limit the collection of personal data to what is ADEQUATE, 8
6666 RELEVANT, AND reasonably necessary [and proportionate to provide or maintain a specific 9
6767 product or service requested by the consumer to whom the data pertains] IN RELATION TO 10
6868 THE PURPOSES FOR WHI CH THE DATA IS PROCE SSED, AS DISCLOSED TO THE 11
6969 CONSUMER ; 12
7070
7171 (ii) Establish, implement, and maintain reasonable administrative, 13
7272 technical, and physical data security practices to protect the confidentiality, integrity, and 14
7373 accessibility of personal data appropriate to the volume and nature of the personal data at 15
7474 issue; and 16
7575
7676 (iii) Provide an effective mechanism for a consumer to revoke the 17
7777 consumer’s consent under this section that is at least as easy as the mechanism by which 18
7878 the consumer provided the consumer’s consent. 19
7979
8080 SECTION 2. AND BE IT FURTHER ENACTED, That this Act shall take effect 20
8181 October 1, 2025, the effective dates of Chapters 424 and 425 of the Acts of the General 21
8282 Assembly of 2024. If the effective dates of Chapters 424 and 425 are amended, this Act shall 22
8383 take effect on the taking effect of Chapters 424 and 425. 23