New Mexico 2025 Regular Session

New Mexico House Bill HB307 Compare Versions

Only one version of the bill is available at this time.
OldNewDifferences
11 underscored material = new
22 [bracketed material] = delete
33 1
44 2
55 3
66 4
77 5
88 6
99 7
1010 8
1111 9
1212 10
1313 11
1414 12
1515 13
1616 14
1717 15
1818 16
1919 17
2020 18
2121 19
2222 20
2323 21
2424 22
2525 23
2626 24
2727 25
2828 HOUSE BILL 307
2929 57TH LEGISLATURE - STATE OF NEW MEXICO - FIRST SESSION, 2025
3030 INTRODUCED BY
3131 Pamelya Herndon and Angelica Rubio
3232 AN ACT
3333 RELATING TO INTERNET SERVICES; ENACTING THE INTERNET PRIVACY
3434 AND SAFETY ACT; ESTABLISHING REQUIREMENTS FOR SERVICE
3535 PROVIDERS; PROHIBITING CERTAIN USES OF CONSUMER DATA; PROVIDING
3636 RIGHTS TO CONSUMERS; ESTABLISHING LIMITATIONS ON PROCESSING OF
3737 CONSUMER DATA; PROHIBITING WAIVERS OF RIGHTS AND RETALIATORY
3838 DENIALS OF SERVICE; PROVIDING FOR INJUNCTIVE RELIEF AND CIVIL
3939 PENALTIES; PROVIDING FOR RULEMAKING.
4040 BE IT ENACTED BY THE LEGISLATURE OF THE STATE OF NEW MEXICO:
4141 SECTION 1. [NEW MATERIAL] SHORT TITLE.--This act may be
4242 cited as the "Internet Privacy and Safety Act".
4343 SECTION 2. [NEW MATERIAL] DEFINITIONS.--As used in the
4444 Internet Privacy and Safety Act:
4545 A. "actual knowledge" means a covered entity knows
4646 that a consumer is a minor based upon:
4747 .228900.4 underscored material = new
4848 [bracketed material] = delete
4949 1
5050 2
5151 3
5252 4
5353 5
5454 6
5555 7
5656 8
5757 9
5858 10
5959 11
6060 12
6161 13
6262 14
6363 15
6464 16
6565 17
6666 18
6767 19
6868 20
6969 21
7070 22
7171 23
7272 24
7373 25
7474 (1) the self-identified age provided by the
7575 minor, an age provided by a third party or an age or closely
7676 related proxy that the covered entity knows or has associated
7777 with, attributed to or derived or inferred for the consumer,
7878 including for the purposes of advertising, marketing or product
7979 development; or
8080 (2) the consumer's use of an online feature,
8181 product or service or a portion of such an online feature,
8282 product or service that is directed to children;
8383 B. "affiliate" means a legal entity that controls,
8484 is controlled by or is under common control with another legal
8585 entity;
8686 C. "biometric data" means the data about a consumer
8787 generated by measurements of the consumer's unique biological
8888 characteristics, such as a faceprint, a fingerprint, a
8989 voiceprint, a retina or an iris image or other biological
9090 characteristic, that can be used to uniquely identify the
9191 consumer. "Biometric data" does not include:
9292 (1) demographic data;
9393 (2) a donated portion of a human body stored
9494 on behalf of a potential recipient of a living cadaveric
9595 transplant and obtained or stored by a federally designated
9696 organ procurement agency, including an artery, a bone, an eye,
9797 an organ or tissue or blood or other fluid or serum;
9898 (3) a human biological sample used for valid
9999 .228900.4
100100 - 2 - underscored material = new
101101 [bracketed material] = delete
102102 1
103103 2
104104 3
105105 4
106106 5
107107 6
108108 7
109109 8
110110 9
111111 10
112112 11
113113 12
114114 13
115115 14
116116 15
117117 16
118118 17
119119 18
120120 19
121121 20
122122 21
123123 22
124124 23
125125 24
126126 25
127127 scientific testing or screening;
128128 (4) an image or film of the human anatomy used
129129 to diagnose, provide a prognosis for or treat an illness or
130130 other medical condition or to further validate scientific
131131 testing or screening, including an x-ray, a roentgen process,
132132 computed tomography, a magnetic resonance imaging image, a
133133 positron emission tomography scan or mammography;
134134 (5) information collected, used or stored for
135135 health care treatment, payment or operations pursuant to
136136 federal law governing health insurance;
137137 (6) information collected, used or disclosed
138138 for human subject research that is conducted in accordance with
139139 the federal policy for the protection of human research ethics
140140 laws or with internationally accepted clinical practice
141141 guidelines as determined by the state department of justice by
142142 rule;
143143 (7) a photograph or video, except "biometric
144144 data" includes data generated, captured or collected from the
145145 biological characteristics of a consumer;
146146 (8) a physical description, including height,
147147 weight, hair color, eye color or a tattoo description; or
148148 (9) a writing sample or written signature;
149149 D. "brokerage of personal data" means the exchange
150150 of personal data for monetary or other valuable consideration
151151 by a covered entity to a third party, but does not include:
152152 .228900.4
153153 - 3 - underscored material = new
154154 [bracketed material] = delete
155155 1
156156 2
157157 3
158158 4
159159 5
160160 6
161161 7
162162 8
163163 9
164164 10
165165 11
166166 12
167167 13
168168 14
169169 15
170170 16
171171 17
172172 18
173173 19
174174 20
175175 21
176176 22
177177 23
178178 24
179179 25
180180 (1) the disclosure of personal data to a
181181 service provider that processes the personal data on behalf of
182182 the covered entity;
183183 (2) the disclosure of personal data to a third
184184 party for purposes of providing an online feature, product or
185185 service requested by a consumer;
186186 (3) the disclosure or transfer of personal
187187 data to an affiliate of the covered entity;
188188 (4) with the consumer's affirmative consent,
189189 the disclosure of personal data where the consumer directs the
190190 covered entity to disclose the personal data or intentionally
191191 uses the covered entity to interact with a third party; or
192192 (5) the disclosure of publicly available
193193 information;
194194 E. "collect" means accessing, acquiring or
195195 gathering personal data;
196196 F. "consumer" means a natural person who resides or
197197 is present in New Mexico, including those identified by a
198198 unique identifier;
199199 G. "contextual advertising" means displaying or
200200 presenting an advertisement that does not vary based on the
201201 identity of the recipient and is based solely on:
202202 (1) the immediate content of a web page or an
203203 online feature, product or service within which the
204204 advertisement appears;
205205 .228900.4
206206 - 4 - underscored material = new
207207 [bracketed material] = delete
208208 1
209209 2
210210 3
211211 4
212212 5
213213 6
214214 7
215215 8
216216 9
217217 10
218218 11
219219 12
220220 13
221221 14
222222 15
223223 16
224224 17
225225 18
226226 19
227227 20
228228 21
229229 22
230230 23
231231 24
232232 25
233233 (2) a specific request of a consumer for
234234 information or feedback if displayed in proximity to the
235235 results of such request for information; or
236236 (3) a consumer's association with a geographic
237237 area that is equal to or greater than the area of a circle with
238238 a radius of ten miles;
239239 H. "control" or "controlled" means:
240240 (1) ownership of or the power to vote more
241241 than fifty percent of the outstanding shares of a class of
242242 voting security of a covered entity;
243243 (2) control over the election of a majority of
244244 the directors or of individuals exercising similar functions of
245245 a covered entity; or
246246 (3) the power to exercise a controlling
247247 influence over the management of a covered entity;
248248 I. "covered entity" means a sole proprietorship,
249249 partnership, limited liability company, corporation,
250250 association, affiliate or other legal entity that:
251251 (1) is organized or operated for the profit or
252252 financial benefit of the entity's shareholders or other owners;
253253 (2) offers online features, products or
254254 services to consumers in New Mexico; and
255255 (3) alone or jointly with others, determines
256256 the purposes and means of:
257257 (a) collecting personal data directly
258258 .228900.4
259259 - 5 - underscored material = new
260260 [bracketed material] = delete
261261 1
262262 2
263263 3
264264 4
265265 5
266266 6
267267 7
268268 8
269269 9
270270 10
271271 11
272272 12
273273 13
274274 14
275275 15
276276 16
277277 17
278278 18
279279 19
280280 20
281281 21
282282 22
283283 23
284284 24
285285 25
286286 from consumers;
287287 (b) using personal data for targeted
288288 advertising; or
289289 (c) engaging in the brokerage of
290290 personal data;
291291 J. "dark pattern" means a user interface designed
292292 or manipulated with the purpose of subverting or impairing user
293293 autonomy, decision making or choice;
294294 K. "default" means a preselected option adopted by
295295 a covered entity for an online feature, product or service;
296296 L. "de-identified data" means data that does not
297297 identify and cannot be used to infer information about, or
298298 otherwise be linked to, an identified or identifiable consumer
299299 or a device linked to the consumer or that:
300300 (1) takes reasonable physical, administrative
301301 and technical measures to ensure that the data cannot be
302302 associated with a consumer or be used to identify a consumer or
303303 a device that identifies or is linked or reasonably linkable to
304304 a consumer;
305305 (2) publicly commits to process the data only
306306 in a de-identified fashion; and
307307 (3) contractually obligates a recipient of the
308308 data to satisfy the requirements established pursuant to this
309309 subsection;
310310 M. "derived data" means data that is created by the
311311 .228900.4
312312 - 6 - underscored material = new
313313 [bracketed material] = delete
314314 1
315315 2
316316 3
317317 4
318318 5
319319 6
320320 7
321321 8
322322 9
323323 10
324324 11
325325 12
326326 13
327327 14
328328 15
329329 16
330330 17
331331 18
332332 19
333333 20
334334 21
335335 22
336336 23
337337 24
338338 25
339339 derivation of assumptions, conclusions, correlations, evidence,
340340 data, inferences or predictions about a consumer or a
341341 consumer's device from facts, evidence or other sources of
342342 information;
343343 N. "expressly provided personal data":
344344 (1) means personal data provided by a consumer
345345 to a covered entity expressly for purposes of a profile-based
346346 feed to determine the order, relative prioritization, relative
347347 prominence or selection of information that is furnished to the
348348 consumer by the covered entity through an online product,
349349 service or feature and includes:
350350 (a) consumer-supplied filters, current
351351 precise geolocation information supplied by the consumer,
352352 resumption of a previous search, saved preferences and speech
353353 patterns provided by the consumer for the purpose of enabling
354354 the online product, service or feature to accept spoken input
355355 or selecting the language in which the consumer interacts with
356356 the online product, service or feature; and
357357 (b) data submitted to a covered entity
358358 by the consumer in order to receive particular information,
359359 such as the social media profiles followed by the consumer,
360360 video channels subscribed to by the consumer or other content
361361 or sources of content on the online feature, product or service
362362 the consumer has selected; and
363363 (2) does not include:
364364 .228900.4
365365 - 7 - underscored material = new
366366 [bracketed material] = delete
367367 1
368368 2
369369 3
370370 4
371371 5
372372 6
373373 7
374374 8
375375 9
376376 10
377377 11
378378 12
379379 13
380380 14
381381 15
382382 16
383383 17
384384 18
385385 19
386386 20
387387 21
388388 22
389389 23
390390 24
391391 25
392392 (a) the history of a consumer's
393393 connected device of browsing, device inactions, financial
394394 transactions, geographical locations, physical activity or web
395395 searches; or
396396 (b) inferences about the consumer or the
397397 consumer's connected device, including inferences based on data
398398 described in Paragraph (1) of this subsection;
399399 O. "first party" means a consumer-facing covered
400400 entity with which the consumer intends or expects to interact;
401401 P. "first-party advertising" means advertising or
402402 marketing by a first party using first-party data and not other
403403 forms of personal data and carried out:
404404 (1) through direct communications with the
405405 consumer, such as direct mail, email or text message
406406 communications;
407407 (2) in a physical location operated by the
408408 first party; or
409409 (3) through display or presentation of an
410410 advertisement on the first party's own website, application or
411411 other online content that promotes that first party's product
412412 or service;
413413 Q. "first-party data" means personal data collected
414414 directly about a consumer by a first party, including data
415415 collected during a consumer visit or use of a website, a
416416 physical location or an online feature, product or service
417417 .228900.4
418418 - 8 - underscored material = new
419419 [bracketed material] = delete
420420 1
421421 2
422422 3
423423 4
424424 5
425425 6
426426 7
427427 8
428428 9
429429 10
430430 11
431431 12
432432 13
433433 14
434434 15
435435 16
436436 17
437437 18
438438 19
439439 20
440440 21
441441 22
442442 23
443443 24
444444 25
445445 operated by the first party;
446446 R. "minor" means a consumer who is under eighteen
447447 years of age;
448448 S. "personal data" means information, including
449449 derived data, that is linked or reasonably linkable, alone or
450450 in combination with other information, to an identified or
451451 identifiable consumer. "Personal data" does not include de-
452452 identified information or publicly available information;
453453 T. "precise geolocation" means data that is derived
454454 from a device and that is used or intended to be used to reveal
455455 the present or past geographical location of a consumer or a
456456 consumer's device within a geographic area that is equal to or
457457 smaller than the area of a circle with a radius of two thousand
458458 feet;
459459 U. "privacy-protective feed" means an algorithmic
460460 ranking system that does not use the personal data of a
461461 consumer to determine the order, relative prominence, relative
462462 prioritization or selection of information that is furnished to
463463 the consumer on an online feature, product or service except
464464 for expressly provided personal data;
465465 V. "profile-based feed" means an algorithmic
466466 ranking system that determines the order, relative prominence,
467467 relative prioritization, relative prominence or selection of
468468 information that is furnished to a consumer on an online
469469 feature, product or service based, in whole or part, on
470470 .228900.4
471471 - 9 - underscored material = new
472472 [bracketed material] = delete
473473 1
474474 2
475475 3
476476 4
477477 5
478478 6
479479 7
480480 8
481481 9
482482 10
483483 11
484484 12
485485 13
486486 14
487487 15
488488 16
489489 17
490490 18
491491 19
492492 20
493493 21
494494 22
495495 23
496496 24
497497 25
498498 personal data that is not expressly provided personal data;
499499 W. "process" or "processing" means automated or
500500 manual analysis, brokerage, collection, deletion, disclosure,
501501 modification, storage, use, transfer or other handling of
502502 personal data or sets of data;
503503 X. "profiling" means automated processing of
504504 personal data that uses personal data to evaluate certain
505505 aspects relating to a consumer, including analyzing or
506506 predicting aspects concerning the consumer's behavior, economic
507507 situation, health, interests, location, movement, performance
508508 at work, personal preferences or reliability. "Profiling" does
509509 not include the processing of data that does not result in an
510510 assessment or judgment about a consumer;
511511 Y. "publicly available information", except the
512512 information listed in Subsection Z of this section, means
513513 information that has been lawfully made available to the
514514 general public from:
515515 (1) federal, state or municipal government
516516 records;
517517 (2) widely distributed media, including
518518 personal data intentionally made available by a consumer to the
519519 general public such that the consumer does not retain a
520520 reasonable expectation of privacy in the personal data; or
521521 (3) a disclosure that has been made to the
522522 general public as required by federal, state or local law;
523523 .228900.4
524524 - 10 - underscored material = new
525525 [bracketed material] = delete
526526 1
527527 2
528528 3
529529 4
530530 5
531531 6
532532 7
533533 8
534534 9
535535 10
536536 11
537537 12
538538 13
539539 14
540540 15
541541 16
542542 17
543543 18
544544 19
545545 20
546546 21
547547 22
548548 23
549549 24
550550 25
551551 Z. "publicly available information" does not
552552 include:
553553 (1) an obscene visual depiction, as defined by
554554 state law;
555555 (2) personal data that is derived data from
556556 multiple independent sources of publicly available information
557557 that reveals sensitive personal data with respect to a
558558 consumer;
559559 (3) biometric data such that the consumer
560560 retained a reasonable expectation of privacy in the
561561 information;
562562 (4) personal data that is created through the
563563 combination of personal data with publicly available
564564 information;
565565 (5) genetic data, unless otherwise made
566566 publicly available by the consumer to whom the information
567567 pertains; or
568568 (6) information made available by a consumer
569569 on an online feature, product or service open to all members of
570570 the public, whether for a fee or for free, where the consumer
571571 has restricted the information to a specific audience in a
572572 manner that the consumer would retain a reasonable expectation
573573 of privacy for the information;
574574 AA. "sensitive personal data" means personal data
575575 that includes:
576576 .228900.4
577577 - 11 - underscored material = new
578578 [bracketed material] = delete
579579 1
580580 2
581581 3
582582 4
583583 5
584584 6
585585 7
586586 8
587587 9
588588 10
589589 11
590590 12
591591 13
592592 14
593593 15
594594 16
595595 17
596596 18
597597 19
598598 20
599599 21
600600 22
601601 23
602602 24
603603 25
604604 (1) biometric or genetic data;
605605 (2) data revealing citizenship, ethnic origin,
606606 immigration status or racial origin;
607607 (3) financial data, including a credit card
608608 number, a debit card number, a financial account number or
609609 information that describes or reveals the bank account balances
610610 or income level of a consumer, except that the last four digits
611611 of a debit or credit card number are not sensitive personal
612612 data;
613613 (4) genetic or biometric data;
614614 (5) a government-issued identifier, such as a
615615 social security number, passport number or driver's license
616616 number, that is not required by law to be displayed in public;
617617 (6) data describing or revealing the past,
618618 present or future mental or physical health of a consumer,
619619 including:
620620 (a) diagnosis;
621621 (b) disability;
622622 (c) health care condition; or
623623 (d) treatment;
624624 (7) data concerning the physical condition of
625625 a consumer, including childbirth, pregnancy or a condition
626626 related to childbirth or pregnancy;
627627 (8) information about a consumer's personal
628628 identity, including:
629629 .228900.4
630630 - 12 - underscored material = new
631631 [bracketed material] = delete
632632 1
633633 2
634634 3
635635 4
636636 5
637637 6
638638 7
639639 8
640640 9
641641 10
642642 11
643643 12
644644 13
645645 14
646646 15
647647 16
648648 17
649649 18
650650 19
651651 20
652652 21
653653 22
654654 23
655655 24
656656 25
657657 (a) ethnic or racial identity;
658658 (b) gender and gender identity;
659659 (c) sex;
660660 (d) sex life; or
661661 (e) sexual orientation;
662662 (9) precise geolocation;
663663 (10) religious affiliation; or
664664 (11) union membership;
665665 BB. "service provider" means a person who collects,
666666 processes, retains or transfers personal data on behalf of, and
667667 at the direction of, a covered entity or a service provider;
668668 CC. "targeted advertising" means displaying or
669669 presenting an online advertisement to a consumer or to a device
670670 identified by a unique persistent identifier or to a group of
671671 consumers or devices identified by unique persistent
672672 identifiers when the advertisement is selected based, in whole
673673 or in part, on known or predicted preferences, characteristics,
674674 behavior or interests associated with the consumer or a device
675675 identified by a unique persistent identifier. "Targeted
676676 advertising" does not include first-party advertising or
677677 contextual advertising; and
678678 DD. "third party" means a person or entity other
679679 than the consumer of the covered entity, the covered entity or
680680 a service provider for the covered entity.
681681 SECTION 3. [NEW MATERIAL] REQUIREMENTS FOR COVERED
682682 .228900.4
683683 - 13 - underscored material = new
684684 [bracketed material] = delete
685685 1
686686 2
687687 3
688688 4
689689 5
690690 6
691691 7
692692 8
693693 9
694694 10
695695 11
696696 12
697697 13
698698 14
699699 15
700700 16
701701 17
702702 18
703703 19
704704 20
705705 21
706706 22
707707 23
708708 24
709709 25
710710 ENTITIES--ONLINE PLATFORMS--CONSUMER OPTIONS--MINORS.--
711711 A. Except as provided in Subsection B of this
712712 section, a covered entity shall:
713713 (1) configure all default privacy settings on
714714 the covered entity's online platforms offering features,
715715 products or services to settings that offer the highest level
716716 of privacy;
717717 (2) publicly provide privacy information,
718718 terms of service, policies and community standards in a
719719 prominent, precise manner and use clear, easily understood
720720 language;
721721 (3) publicly provide prominent, accessible and
722722 responsive tools to help a consumer exercise the consumer's
723723 privacy rights and report concerns; and
724724 (4) establish, implement and maintain
725725 reasonable administrative, technical and physical data security
726726 practices to protect the confidentiality, integrity and
727727 accessibility of personal data appropriate to the volume and
728728 nature of the personal data at issue pursuant to guidelines
729729 established by the state department of justice by rule.
730730 B. When a covered entity does not have actual
731731 knowledge that a consumer using the covered entity's online
732732 platform to access a feature, product or service is a minor,
733733 the covered entity shall establish settings on that online
734734 platform that:
735735 .228900.4
736736 - 14 - underscored material = new
737737 [bracketed material] = delete
738738 1
739739 2
740740 3
741741 4
742742 5
743743 6
744744 7
745745 8
746746 9
747747 10
748748 11
749749 12
750750 13
751751 14
752752 15
753753 16
754754 17
755755 18
756756 19
757757 20
758758 21
759759 22
760760 23
761761 24
762762 25
763763 (1) permit a consumer to disable notifications
764764 or disable notifications during specific periods of time;
765765 (2) permit a consumer to choose between a
766766 privacy-protective feed and a profile-based feed; and
767767 (3) permit a consumer to disable contact by
768768 unknown individuals unless the consumer first initiates the
769769 contact or provide a mechanism to screen contact by individuals
770770 with whom the consumer does not have a relationship.
771771 C. When a covered entity has actual knowledge that
772772 a consumer using the covered entity's online platform is a
773773 minor, the covered entity shall establish default settings on
774774 the platform:
775775 (1) that disable contact by unknown users
776776 unless the consumer first initiates the contact;
777777 (2) that disable notifications between the
778778 hours of 10:00 p.m. and 6:00 a.m. mountain time pursuant to
779779 federal law; and
780780 (3) that use a privacy-protective feed.
781781 SECTION 4. [NEW MATERIAL] PROHIBITED PRACTICES--CONSUMER
782782 OPT-IN OPTION.--A covered entity that provides an online
783783 feature, product or service that involves the processing of
784784 personal data shall not, and shall not instruct a service
785785 provider or third party, to:
786786 A. profile a consumer by default, unless profiling
787787 is necessary to provide the online feature, product or service
788788 .228900.4
789789 - 15 - underscored material = new
790790 [bracketed material] = delete
791791 1
792792 2
793793 3
794794 4
795795 5
796796 6
797797 7
798798 8
799799 9
800800 10
801801 11
802802 12
803803 13
804804 14
805805 15
806806 16
807807 17
808808 18
809809 19
810810 20
811811 21
812812 22
813813 23
814814 24
815815 25
816816 requested, and only with respect to the aspects of the online
817817 feature, product or service with which the consumer is actively
818818 and knowingly engaged;
819819 B. process the personal data of a consumer except
820820 as necessary to provide:
821821 (1) the specific online feature, product or
822822 service with which the consumer is actively and knowingly
823823 engaged, including any routine administrative, operational or
824824 account-servicing activity, such as billing, shipping,
825825 delivery, storage, accounting, security or fraud detection; or
826826 (2) a communication, that is not an
827827 advertisement, by the covered entity to the consumer that is
828828 reasonably anticipated within the context of the relationship
829829 between the covered entity and the consumer;
830830 C. process personal data for any reason other than
831831 a reason for which the personal data is collected;
832832 D. process a consumer's sensitive personal data
833833 unless the collection of that data is strictly necessary for
834834 the covered entity to provide the online feature, product or
835835 service requested and then only for the limited time that the
836836 collection of data is necessary to provide the online feature,
837837 product or service;
838838 E. process a consumer's precise geolocation
839839 information without providing an obvious signal to the consumer
840840 for the duration of that collection that precise geolocation
841841 .228900.4
842842 - 16 - underscored material = new
843843 [bracketed material] = delete
844844 1
845845 2
846846 3
847847 4
848848 5
849849 6
850850 7
851851 8
852852 9
853853 10
854854 11
855855 12
856856 13
857857 14
858858 15
859859 16
860860 17
861861 18
862862 19
863863 20
864864 21
865865 22
866866 23
867867 24
868868 25
869869 information is being collected;
870870 F. use dark patterns to cause a consumer to provide
871871 personal data beyond what is reasonably expected to provide the
872872 online feature, product or service, to forego privacy
873873 protections;
874874 G. allow a person to monitor a consumer's online
875875 activity or precise geolocation without providing an obvious
876876 signal to the consumer that the consumer is being monitored or
877877 tracked;
878878 H. process or transfer personal data in a manner
879879 that discriminates in or otherwise makes unavailable the equal
880880 enjoyment of goods or services on the basis of childbirth or
881881 condition related to pregnancy or childbirth, color,
882882 disability, gender, gender identity, mental health, national
883883 origin, physical health condition or diagnosis, race,
884884 religion, sex life or sexual orientation;
885885 I. process personal data for purposes of targeted
886886 advertising, first-party advertising or the brokerage of
887887 personal data without the consumer first opting in to those
888888 purposes by clear and conspicuous means and not through the use
889889 of dark patterns; or
890890 J. process sensitive personal data for purposes of
891891 targeted advertising, first-party advertising or the brokerage
892892 of personal data.
893893 SECTION 5. [NEW MATERIAL] RIGHTS OF ACCESS--CORRECTION--
894894 .228900.4
895895 - 17 - underscored material = new
896896 [bracketed material] = delete
897897 1
898898 2
899899 3
900900 4
901901 5
902902 6
903903 7
904904 8
905905 9
906906 10
907907 11
908908 12
909909 13
910910 14
911911 15
912912 16
913913 17
914914 18
915915 19
916916 20
917917 21
918918 22
919919 23
920920 24
921921 25
922922 DELETION.--
923923 A. Covered entities shall provide a consumer the
924924 right to:
925925 (1) access all the consumer's personal data
926926 that was processed by the covered entity or a service provider;
927927 (2) access all the information pertaining to
928928 the collection and processing of the consumer's personal
929929 information, including:
930930 (a) where or from whom the covered
931931 entity obtained personal data, such as whether the information
932932 was obtained from the consumer or a third party or from an
933933 online or offline source;
934934 (b) the types of third parties to which
935935 the covered entity has disclosed or will disclose personal
936936 data;
937937 (c) the purposes of the processing;
938938 (d) the categories of personal data
939939 concerned;
940940 (e) the names of third parties to which
941941 the covered entity had disclosed the personal data and a log
942942 showing when such disclosure happened; and
943943 (f) the period of retention of the
944944 personal data;
945945 (3) obtain the consumer's personal data
946946 processed by a covered entity in a structured, readily usable,
947947 .228900.4
948948 - 18 - underscored material = new
949949 [bracketed material] = delete
950950 1
951951 2
952952 3
953953 4
954954 5
955955 6
956956 7
957957 8
958958 9
959959 10
960960 11
961961 12
962962 13
963963 14
964964 15
965965 16
966966 17
967967 18
968968 19
969969 20
970970 21
971971 22
972972 23
973973 24
974974 25
975975 portable and machine-readable format;
976976 (4) transmit or cause the covered entity to
977977 transmit the consumer's personal data to another covered
978978 entity, where technically feasible;
979979 (5) request a covered entity to stop
980980 collecting and processing the consumer's personal data;
981981 (6) correct inaccurate personal data stored by
982982 covered entities; and
983983 (7) delete the consumer's personal data that
984984 is stored by covered entities, including from nonpublic
985985 profiles; provided that a covered entity that has collected
986986 personal data from a consumer is not required to delete
987987 information to the extent that the covered entity is exempt
988988 under Section 9 of the Internet Privacy and Safety Act.
989989 B. A covered entity shall provide a consumer with a
990990 reasonable means to exercise the consumer's rights pursuant to
991991 Subsection A of this section in a request form that is:
992992 (1) clear and conspicuous;
993993 (2) made available at no additional cost and
994994 with no transactional penalty to the consumer to whom the
995995 information pertains; and
996996 (3) in English or another language in which
997997 the covered entity communicates with the consumer to whom the
998998 information pertains.
999999 C. A covered entity shall comply with a consumer's
10001000 .228900.4
10011001 - 19 - underscored material = new
10021002 [bracketed material] = delete
10031003 1
10041004 2
10051005 3
10061006 4
10071007 5
10081008 6
10091009 7
10101010 8
10111011 9
10121012 10
10131013 11
10141014 12
10151015 13
10161016 14
10171017 15
10181018 16
10191019 17
10201020 18
10211021 19
10221022 20
10231023 21
10241024 22
10251025 23
10261026 24
10271027 25
10281028 request to exercise the consumer's rights pursuant to
10291029 Subsection A or B of this section within thirty days after
10301030 receiving a verifiable request; provided that:
10311031 (1) when the covered entity has a reasonable
10321032 doubt or cannot verify the identity of the consumer making a
10331033 request, the covered entity may request additional personal
10341034 information necessary for the specific purpose of confirming
10351035 the consumer's identity; and
10361036 (2) the covered entity shall not de-identify
10371037 the consumer's personal data for sixty days from the date on
10381038 which the covered entity receives a request for correction or
10391039 deletion from the consumer pursuant to this section.
10401040 SECTION 6. [NEW MATERIAL] DATA PROCESSING AGREEMENTS.--
10411041 A. A service provider that processes personal data
10421042 on behalf of a covered entity or another service provider or a
10431043 third party that receives personal data from a covered entity
10441044 shall enter into a written data processing agreement with the
10451045 covered entity ensuring that the data will continue to be
10461046 processed consistent with the Internet Privacy and Safety Act.
10471047 The agreement shall specify that:
10481048 (1) personal data received by service
10491049 providers or third parties shall be processed only for purposes
10501050 specified by the covered entity in the data processing
10511051 agreement, subject to the limitations of the Internet Privacy
10521052 and Safety Act;
10531053 .228900.4
10541054 - 20 - underscored material = new
10551055 [bracketed material] = delete
10561056 1
10571057 2
10581058 3
10591059 4
10601060 5
10611061 6
10621062 7
10631063 8
10641064 9
10651065 10
10661066 11
10671067 12
10681068 13
10691069 14
10701070 15
10711071 16
10721072 17
10731073 18
10741074 19
10751075 20
10761076 21
10771077 22
10781078 23
10791079 24
10801080 25
10811081 (2) service providers and third parties shall
10821082 only process personal data that is adequate, relevant and
10831083 necessary for the purposes for which the data was collected or
10841084 received;
10851085 (3) service providers and third parties shall
10861086 ensure that subcontractors comply with the same data protection
10871087 obligations as set forth in their data processing agreement
10881088 with the covered entity;
10891089 (4) service providers and third parties shall
10901090 establish, implement and maintain reasonable administrative,
10911091 technical and physical data security practices to protect the
10921092 confidentiality, integrity and accessibility of personal data
10931093 appropriate to the volume and nature of the personal data at
10941094 issue; and
10951095 (5) service providers shall adhere to the
10961096 instructions of a controller and shall assist the controller in
10971097 meeting the controller's obligations pursuant to the Internet
10981098 Privacy and Safety Act.
10991099 B. Prior to transferring personal data to a third
11001100 party located outside of New Mexico, covered entities shall
11011101 ensure that adequate data protection safeguards consistent with
11021102 the Internet Privacy and Safety Act are in place.
11031103 SECTION 7. [NEW MATERIAL] PROHIBITION ON WAIVING OF
11041104 RIGHTS AND RETALIATORY DENIAL OF SERVICE.--
11051105 A. A covered entity shall not retaliate against a
11061106 .228900.4
11071107 - 21 - underscored material = new
11081108 [bracketed material] = delete
11091109 1
11101110 2
11111111 3
11121112 4
11131113 5
11141114 6
11151115 7
11161116 8
11171117 9
11181118 10
11191119 11
11201120 12
11211121 13
11221122 14
11231123 15
11241124 16
11251125 17
11261126 18
11271127 19
11281128 20
11291129 21
11301130 22
11311131 23
11321132 24
11331133 25
11341134 consumer for exercising a right guaranteed by the Internet
11351135 Privacy and Safety Act, or a rule promulgated under that act,
11361136 including charging different prices or rates for goods and
11371137 services, denying goods or services or providing a different
11381138 level of quality of goods or services.
11391139 B. A provision of a contract, an agreement or terms
11401140 of service shall not waive, limit or otherwise undermine the
11411141 rights conferred under the Internet Privacy and Safety Act or
11421142 other applicable data protection laws.
11431143 C. A provision within a contract or an agreement
11441144 between a covered entity and a consumer that is invalid or
11451145 unenforceable pursuant to the Internet Privacy and Safety Act
11461146 shall not affect the validity or enforceability of the
11471147 remaining provisions of the contract or agreement.
11481148 SECTION 8. [NEW MATERIAL] VIOLATIONS--ENFORCEMENT--
11491149 PENALTIES--CLAIMS FOR VIOLATIONS.--Upon promulgation of rules
11501150 by the state department of justice to implement the Internet
11511151 Privacy and Safety Act:
11521152 A. a covered entity that violates the provisions of
11531153 that act shall be:
11541154 (1) subject to injunctive relief to cease or
11551155 correct the violation;
11561156 (2) liable for a civil penalty of not more
11571157 than two thousand five hundred dollars ($2,500) per affected
11581158 consumer for each negligent violation; and
11591159 .228900.4
11601160 - 22 - underscored material = new
11611161 [bracketed material] = delete
11621162 1
11631163 2
11641164 3
11651165 4
11661166 5
11671167 6
11681168 7
11691169 8
11701170 9
11711171 10
11721172 11
11731173 12
11741174 13
11751175 14
11761176 15
11771177 16
11781178 17
11791179 18
11801180 19
11811181 20
11821182 21
11831183 22
11841184 23
11851185 24
11861186 25
11871187 (3) liable for a civil penalty of not more
11881188 than seven thousand five hundred dollars ($7,500) per affected
11891189 consumer for each intentional violation; and
11901190 B. a consumer who claims to have suffered a
11911191 deprivation of the rights secured under that act may maintain
11921192 an action to establish liability and recover damages or
11931193 equitable or injunctive relief in district court.
11941194 SECTION 9. [NEW MATERIAL] EXCEPTIONS.--
11951195 A. A covered entity that is in compliance with
11961196 federal privacy laws shall be deemed to be in compliance with
11971197 the requirements of the Internet Privacy and Safety Act solely
11981198 and exclusively with respect to data subject to the
11991199 requirements of federal law.
12001200 B. An online feature, product or service that is
12011201 regulated pursuant to federal information security law shall be
12021202 deemed to be in compliance with the requirements of the
12031203 Internet Privacy and Safety Act solely and exclusively with
12041204 respect to data subject to the requirements of federal law.
12051205 C. The Internet Privacy and Safety Act does not
12061206 apply to the delivery or use of a physical product to the
12071207 extent the product is not an online feature, product or
12081208 service.
12091209 SECTION 10. [NEW MATERIAL] LIMITATIONS.--Nothing in the
12101210 Internet Privacy and Safety Act shall be interpreted or
12111211 construed to:
12121212 .228900.4
12131213 - 23 - underscored material = new
12141214 [bracketed material] = delete
12151215 1
12161216 2
12171217 3
12181218 4
12191219 5
12201220 6
12211221 7
12221222 8
12231223 9
12241224 10
12251225 11
12261226 12
12271227 13
12281228 14
12291229 15
12301230 16
12311231 17
12321232 18
12331233 19
12341234 20
12351235 21
12361236 22
12371237 23
12381238 24
12391239 25
12401240 A. impose liability in a manner that is
12411241 inconsistent with federal law;
12421242 B. apply to information processed by local, state,
12431243 or federal government or municipal corporations; or
12441244 C. restrict a covered entity's or service
12451245 provider's ability to:
12461246 (1) comply with federal or New Mexico law;
12471247 (2) comply with a civil or criminal subpoena
12481248 or summons, except as prohibited by New Mexico law;
12491249 (3) cooperate with law enforcement agencies
12501250 concerning conduct or activity that the covered entity or
12511251 service provider reasonably and in good faith believes may
12521252 violate federal, state or municipal ordinances or regulations;
12531253 (4) investigate, establish, exercise, prepare
12541254 for or defend legal claims to the extent that the regulated
12551255 data is relevant to the parties' claims;
12561256 (5) take immediate steps to protect the life
12571257 or physical safety of a consumer or another individual in an
12581258 emergency, and where the processing cannot be manifestly based
12591259 on another legal basis; provided that a consumer's access to
12601260 health care services lawful in the state of New Mexico shall
12611261 not constitute an emergency;
12621262 (6) prevent, detect, protect against or
12631263 respond to security incidents relating to network security or
12641264 physical security, including an intrusion or trespass, medical
12651265 .228900.4
12661266 - 24 - underscored material = new
12671267 [bracketed material] = delete
12681268 1
12691269 2
12701270 3
12711271 4
12721272 5
12731273 6
12741274 7
12751275 8
12761276 9
12771277 10
12781278 11
12791279 12
12801280 13
12811281 14
12821282 15
12831283 16
12841284 17
12851285 18
12861286 19
12871287 20
12881288 21
12891289 22
12901290 23
12911291 24
12921292 25
12931293 alert or request for a medical response, fire alarm or request
12941294 for a fire response, or access control;
12951295 (7) prevent, detect, protect against or
12961296 respond to identity theft, fraud, harassment, malicious or
12971297 deceptive activities or illegal activity targeted at or
12981298 involving the covered entity or service provider or its
12991299 services, preserve the integrity or security of systems or
13001300 investigate, report or prosecute those responsible for any such
13011301 action;
13021302 (8) assist another covered entity, service
13031303 provider or third party with any of the obligations in the
13041304 Internet Privacy and Safety Act;
13051305 (9) transfer assets to a third party in the
13061306 context of a merger, acquisition, bankruptcy or similar
13071307 transaction when the third party assumes control, in whole or
13081308 in part, of the covered entity's assets, only if the covered
13091309 entity, in a reasonable time prior to the transfer, provides an
13101310 affected consumer with a notice describing the transfer,
13111311 including the name of the entity receiving the consumer's
13121312 regulated health data and the applicable privacy policies of
13131313 such entity; or
13141314 (10) transfer assets to a third party in the
13151315 context of a merger, acquisition, bankruptcy or similar
13161316 transaction when the third party assumes control, in whole or
13171317 in part, of the covered entity's assets, only if the covered
13181318 .228900.4
13191319 - 25 - underscored material = new
13201320 [bracketed material] = delete
13211321 1
13221322 2
13231323 3
13241324 4
13251325 5
13261326 6
13271327 7
13281328 8
13291329 9
13301330 10
13311331 11
13321332 12
13331333 13
13341334 14
13351335 15
13361336 16
13371337 17
13381338 18
13391339 19
13401340 20
13411341 21
13421342 22
13431343 23
13441344 24
13451345 25
13461346 entity, in a reasonable time prior to the transfer, provides an
13471347 affected consumer with a reasonable opportunity to:
13481348 (a) withdraw previously provided consent
13491349 or opt-ins related to the consumer's personal data;
13501350 (b) request the deletion of the
13511351 consumer's regulated health data;
13521352 (c) meet federal law requirements for
13531353 data used or collected for medical research; or
13541354 (d) with respect to personal data
13551355 previously collected in accordance with the Internet Privacy
13561356 and Safety Act, process that regulated health data solely for
13571357 the purpose that the regulated health data becomes
13581358 de-identified data.
13591359 SECTION 11. [NEW MATERIAL] STATE DEPARTMENT OF JUSTICE--
13601360 RULEMAKING--REPORTS.--
13611361 A. On or before April 1, 2026, the state department
13621362 of justice shall promulgate rules for the implementation of the
13631363 Internet Privacy and Safety Act.
13641364 B. On or before November 30, 2026 and on or before
13651365 November 30 in each subsequent year, the state department of
13661366 justice shall provide a report to the interim legislative
13671367 committee that is tasked with examining internet-related
13681368 issues. The report shall:
13691369 (1) compare the requirements of the then-
13701370 current federal laws and regulations with the requirements of
13711371 .228900.4
13721372 - 26 - underscored material = new
13731373 [bracketed material] = delete
13741374 1
13751375 2
13761376 3
13771377 4
13781378 5
13791379 6
13801380 7
13811381 8
13821382 9
13831383 10
13841384 11
13851385 12
13861386 13
13871387 14
13881388 15
13891389 16
13901390 17
13911391 18
13921392 19
13931393 20
13941394 21
13951395 22
13961396 23
13971397 24
13981398 25
13991399 the Internet Privacy and Safety Act and the rules promulgated
14001400 pursuant to Subsection A of this section on entities offering
14011401 online features, products or services concerning data privacy
14021402 and the protection of minors; and
14031403 (2) provide recommendations for statutory
14041404 changes needed to conform state law with federal law.
14051405 - 27 -
14061406 .228900.4