1 | 1 | | underscored material = new |
---|
2 | 2 | | [bracketed material] = delete |
---|
3 | 3 | | 1 |
---|
4 | 4 | | 2 |
---|
5 | 5 | | 3 |
---|
6 | 6 | | 4 |
---|
7 | 7 | | 5 |
---|
8 | 8 | | 6 |
---|
9 | 9 | | 7 |
---|
10 | 10 | | 8 |
---|
11 | 11 | | 9 |
---|
12 | 12 | | 10 |
---|
13 | 13 | | 11 |
---|
14 | 14 | | 12 |
---|
15 | 15 | | 13 |
---|
16 | 16 | | 14 |
---|
17 | 17 | | 15 |
---|
18 | 18 | | 16 |
---|
19 | 19 | | 17 |
---|
20 | 20 | | 18 |
---|
21 | 21 | | 19 |
---|
22 | 22 | | 20 |
---|
23 | 23 | | 21 |
---|
24 | 24 | | 22 |
---|
25 | 25 | | 23 |
---|
26 | 26 | | 24 |
---|
27 | 27 | | 25 |
---|
28 | 28 | | HOUSE BILL 410 |
---|
29 | 29 | | 57 |
---|
30 | 30 | | TH LEGISLATURE |
---|
31 | 31 | | - |
---|
32 | 32 | | |
---|
33 | 33 | | STATE |
---|
34 | 34 | | |
---|
35 | 35 | | OF |
---|
36 | 36 | | |
---|
37 | 37 | | NEW |
---|
38 | 38 | | |
---|
39 | 39 | | MEXICO |
---|
40 | 40 | | |
---|
41 | 41 | | - |
---|
42 | 42 | | FIRST SESSION |
---|
43 | 43 | | , |
---|
44 | 44 | | |
---|
45 | 45 | | 2025 |
---|
46 | 46 | | INTRODUCED BY |
---|
47 | 47 | | Linda Serrato |
---|
48 | 48 | | AN ACT |
---|
49 | 49 | | RELATING TO DATA; ENACTING THE CONSUMER INFORMATION AND DATA |
---|
50 | 50 | | PROTECTION ACT; PROVIDING PROCESSES FOR THE COLLECTION AND |
---|
51 | 51 | | PROTECTION OF DATA; PROVIDING EXCEPTIONS; PROVIDING |
---|
52 | 52 | | INVESTIGATIVE AUTHORITY; PROVIDING CIVIL PENALTIES. |
---|
53 | 53 | | BE IT ENACTED BY THE LEGISLATURE OF THE STATE OF NEW MEXICO: |
---|
54 | 54 | | SECTION 1. [NEW MATERIAL] SHORT TITLE.--This act may be |
---|
55 | 55 | | cited as the "Consumer Information and Data Protection Act". |
---|
56 | 56 | | SECTION 2. [NEW MATERIAL] DEFINITIONS.--As used in the |
---|
57 | 57 | | Consumer Information and Data Protection Act: |
---|
58 | 58 | | A. "affiliate" means a legal entity that shares |
---|
59 | 59 | | common branding with another legal entity or controls, is |
---|
60 | 60 | | controlled by or is under common control with another legal |
---|
61 | 61 | | entity. For the purposes of this subsection, "control" and |
---|
62 | 62 | | "controlled" mean: |
---|
63 | 63 | | .230052.1ms underscored material = new |
---|
64 | 64 | | [bracketed material] = delete |
---|
65 | 65 | | 1 |
---|
66 | 66 | | 2 |
---|
67 | 67 | | 3 |
---|
68 | 68 | | 4 |
---|
69 | 69 | | 5 |
---|
70 | 70 | | 6 |
---|
71 | 71 | | 7 |
---|
72 | 72 | | 8 |
---|
73 | 73 | | 9 |
---|
74 | 74 | | 10 |
---|
75 | 75 | | 11 |
---|
76 | 76 | | 12 |
---|
77 | 77 | | 13 |
---|
78 | 78 | | 14 |
---|
79 | 79 | | 15 |
---|
80 | 80 | | 16 |
---|
81 | 81 | | 17 |
---|
82 | 82 | | 18 |
---|
83 | 83 | | 19 |
---|
84 | 84 | | 20 |
---|
85 | 85 | | 21 |
---|
86 | 86 | | 22 |
---|
87 | 87 | | 23 |
---|
88 | 88 | | 24 |
---|
89 | 89 | | 25 |
---|
90 | 90 | | (1) ownership of, or the power to vote, more |
---|
91 | 91 | | than fifty percent of the outstanding shares of any class of |
---|
92 | 92 | | voting security of a company; |
---|
93 | 93 | | (2) control in any manner over the election of |
---|
94 | 94 | | a majority of the directors or of individuals exercising |
---|
95 | 95 | | similar functions; or |
---|
96 | 96 | | (3) the power to exercise controlling |
---|
97 | 97 | | influence over the management of a company; |
---|
98 | 98 | | B. "authenticate" means to use reasonable means to |
---|
99 | 99 | | determine that a request to exercise any of the rights afforded |
---|
100 | 100 | | under Section 3 of the Consumer Information and Data Protection |
---|
101 | 101 | | Act is being made by, or on behalf of, the consumer who is |
---|
102 | 102 | | entitled to exercise such consumer rights with respect to the |
---|
103 | 103 | | personal data at issue; |
---|
104 | 104 | | C. "biometric data" means data generated by |
---|
105 | 105 | | automatic measurements of an individual's biological |
---|
106 | 106 | | characteristics, such as a fingerprint, a voiceprint, eye |
---|
107 | 107 | | retinas, irises or other unique biological patterns or |
---|
108 | 108 | | characteristics that are used to identify a specific |
---|
109 | 109 | | individual. "Biometric data" does not include: |
---|
110 | 110 | | (1) a digital or physical photograph; |
---|
111 | 111 | | (2) an audio or video recording; or |
---|
112 | 112 | | (3) any data generated from a digital or |
---|
113 | 113 | | physical photograph, or an audio or video recording, unless |
---|
114 | 114 | | such data is generated to identify a specific individual; |
---|
115 | 115 | | .230052.1ms |
---|
116 | 116 | | - 2 - underscored material = new |
---|
117 | 117 | | [bracketed material] = delete |
---|
118 | 118 | | 1 |
---|
119 | 119 | | 2 |
---|
120 | 120 | | 3 |
---|
121 | 121 | | 4 |
---|
122 | 122 | | 5 |
---|
123 | 123 | | 6 |
---|
124 | 124 | | 7 |
---|
125 | 125 | | 8 |
---|
126 | 126 | | 9 |
---|
127 | 127 | | 10 |
---|
128 | 128 | | 11 |
---|
129 | 129 | | 12 |
---|
130 | 130 | | 13 |
---|
131 | 131 | | 14 |
---|
132 | 132 | | 15 |
---|
133 | 133 | | 16 |
---|
134 | 134 | | 17 |
---|
135 | 135 | | 18 |
---|
136 | 136 | | 19 |
---|
137 | 137 | | 20 |
---|
138 | 138 | | 21 |
---|
139 | 139 | | 22 |
---|
140 | 140 | | 23 |
---|
141 | 141 | | 24 |
---|
142 | 142 | | 25 |
---|
143 | 143 | | D. "business associate" has the same meaning as |
---|
144 | 144 | | provided in HIPAA; |
---|
145 | 145 | | E. "child" means a person under the age of |
---|
146 | 146 | | thirteen; |
---|
147 | 147 | | F. "consent" means a clear affirmative act |
---|
148 | 148 | | signifying a consumer's freely given, specific, informed and |
---|
149 | 149 | | unambiguous agreement to allow the processing of personal data |
---|
150 | 150 | | relating to the consumer. "Consent" may include a written |
---|
151 | 151 | | statement, including by electronic means, or any other |
---|
152 | 152 | | unambiguous affirmative action. "Consent" does not include: |
---|
153 | 153 | | (1) acceptance of a general or broad terms of |
---|
154 | 154 | | use or similar document that contains descriptions of personal |
---|
155 | 155 | | data processing along with other, unrelated information; |
---|
156 | 156 | | (2) hovering over, muting, pausing or closing |
---|
157 | 157 | | a given piece of content; or |
---|
158 | 158 | | (3) agreement obtained through the use of dark |
---|
159 | 159 | | patterns; |
---|
160 | 160 | | G. "consumer" means an individual who is a resident |
---|
161 | 161 | | of this state. "Consumer" does not include an individual |
---|
162 | 162 | | acting in a commercial or employment context or as an employee, |
---|
163 | 163 | | owner, director, officer or contractor of a company, |
---|
164 | 164 | | partnership, sole proprietorship, nonprofit or government |
---|
165 | 165 | | agency whose communications or transactions with the controller |
---|
166 | 166 | | occur solely within the context of that individual's role with |
---|
167 | 167 | | the company, partnership, sole proprietorship, nonprofit or |
---|
168 | 168 | | .230052.1ms |
---|
169 | 169 | | - 3 - underscored material = new |
---|
170 | 170 | | [bracketed material] = delete |
---|
171 | 171 | | 1 |
---|
172 | 172 | | 2 |
---|
173 | 173 | | 3 |
---|
174 | 174 | | 4 |
---|
175 | 175 | | 5 |
---|
176 | 176 | | 6 |
---|
177 | 177 | | 7 |
---|
178 | 178 | | 8 |
---|
179 | 179 | | 9 |
---|
180 | 180 | | 10 |
---|
181 | 181 | | 11 |
---|
182 | 182 | | 12 |
---|
183 | 183 | | 13 |
---|
184 | 184 | | 14 |
---|
185 | 185 | | 15 |
---|
186 | 186 | | 16 |
---|
187 | 187 | | 17 |
---|
188 | 188 | | 18 |
---|
189 | 189 | | 19 |
---|
190 | 190 | | 20 |
---|
191 | 191 | | 21 |
---|
192 | 192 | | 22 |
---|
193 | 193 | | 23 |
---|
194 | 194 | | 24 |
---|
195 | 195 | | 25 |
---|
196 | 196 | | government agency; |
---|
197 | 197 | | H. "consumer health data" means any personal data |
---|
198 | 198 | | that a controller uses to identify a consumer's physical or |
---|
199 | 199 | | mental health condition or diagnosis and includes, but is not |
---|
200 | 200 | | limited to, gender-affirming health data and reproductive or |
---|
201 | 201 | | sexual health data; |
---|
202 | 202 | | I. "controller" means a person who, alone or |
---|
203 | 203 | | jointly with others, determines the purpose and means of |
---|
204 | 204 | | processing personal data; |
---|
205 | 205 | | J. "covered entity" has the same meaning as |
---|
206 | 206 | | provided in HIPAA; |
---|
207 | 207 | | K. "dark pattern" means a user interface designed |
---|
208 | 208 | | or manipulated with the substantial effect of subverting or |
---|
209 | 209 | | impairing user autonomy, decision making or choice and includes |
---|
210 | 210 | | any practice the federal trade commission refers to as a "dark |
---|
211 | 211 | | pattern"; |
---|
212 | 212 | | L. "decisions that produce legal or similarly |
---|
213 | 213 | | significant effects concerning the consumer" means decisions |
---|
214 | 214 | | made by the controller that result in the provision or denial |
---|
215 | 215 | | by the controller of financial or lending services, housing, |
---|
216 | 216 | | insurance, education enrollment or opportunity, criminal |
---|
217 | 217 | | justice, employment opportunities, health care services or |
---|
218 | 218 | | access to essential goods or services; |
---|
219 | 219 | | M. "de-identified data" means data that cannot |
---|
220 | 220 | | reasonably be used to infer information about, or otherwise be |
---|
221 | 221 | | .230052.1ms |
---|
222 | 222 | | - 4 - underscored material = new |
---|
223 | 223 | | [bracketed material] = delete |
---|
224 | 224 | | 1 |
---|
225 | 225 | | 2 |
---|
226 | 226 | | 3 |
---|
227 | 227 | | 4 |
---|
228 | 228 | | 5 |
---|
229 | 229 | | 6 |
---|
230 | 230 | | 7 |
---|
231 | 231 | | 8 |
---|
232 | 232 | | 9 |
---|
233 | 233 | | 10 |
---|
234 | 234 | | 11 |
---|
235 | 235 | | 12 |
---|
236 | 236 | | 13 |
---|
237 | 237 | | 14 |
---|
238 | 238 | | 15 |
---|
239 | 239 | | 16 |
---|
240 | 240 | | 17 |
---|
241 | 241 | | 18 |
---|
242 | 242 | | 19 |
---|
243 | 243 | | 20 |
---|
244 | 244 | | 21 |
---|
245 | 245 | | 22 |
---|
246 | 246 | | 23 |
---|
247 | 247 | | 24 |
---|
248 | 248 | | 25 |
---|
249 | 249 | | linked to, an identified or identifiable individual, or a |
---|
250 | 250 | | device linked to such individual, if the controller that |
---|
251 | 251 | | possesses such data: |
---|
252 | 252 | | (1) takes reasonable measures to ensure that |
---|
253 | 253 | | such data cannot be associated with an individual; |
---|
254 | 254 | | (2) publicly commits to process such data only |
---|
255 | 255 | | in a de-identified fashion and not attempt to re-identify such |
---|
256 | 256 | | data; and |
---|
257 | 257 | | (3) contractually obligates any recipients of |
---|
258 | 258 | | such data to satisfy the criteria set forth in Paragraphs (1) |
---|
259 | 259 | | and (2) of this subsection; |
---|
260 | 260 | | N. "geofence" means any technology that uses global |
---|
261 | 261 | | positioning coordinates, cell tower connectivity, cellular |
---|
262 | 262 | | data, radio frequency identification, wireless fidelity |
---|
263 | 263 | | technology data or any other form of location detection, or any |
---|
264 | 264 | | combination of such coordinates, connectivity, data, |
---|
265 | 265 | | identification or other form of location detection, to |
---|
266 | 266 | | establish a virtual boundary; |
---|
267 | 267 | | O. "HIPAA" means the federal Health Insurance |
---|
268 | 268 | | Portability and Accountability Act of 1996, 42 USC 1320d et |
---|
269 | 269 | | seq.; |
---|
270 | 270 | | P. "identified or identifiable individual" means an |
---|
271 | 271 | | individual who can be readily identified, directly or |
---|
272 | 272 | | indirectly; |
---|
273 | 273 | | Q. "institution of higher education" means any |
---|
274 | 274 | | .230052.1ms |
---|
275 | 275 | | - 5 - underscored material = new |
---|
276 | 276 | | [bracketed material] = delete |
---|
277 | 277 | | 1 |
---|
278 | 278 | | 2 |
---|
279 | 279 | | 3 |
---|
280 | 280 | | 4 |
---|
281 | 281 | | 5 |
---|
282 | 282 | | 6 |
---|
283 | 283 | | 7 |
---|
284 | 284 | | 8 |
---|
285 | 285 | | 9 |
---|
286 | 286 | | 10 |
---|
287 | 287 | | 11 |
---|
288 | 288 | | 12 |
---|
289 | 289 | | 13 |
---|
290 | 290 | | 14 |
---|
291 | 291 | | 15 |
---|
292 | 292 | | 16 |
---|
293 | 293 | | 17 |
---|
294 | 294 | | 18 |
---|
295 | 295 | | 19 |
---|
296 | 296 | | 20 |
---|
297 | 297 | | 21 |
---|
298 | 298 | | 22 |
---|
299 | 299 | | 23 |
---|
300 | 300 | | 24 |
---|
301 | 301 | | 25 |
---|
302 | 302 | | individual who, or school, board, association, limited |
---|
303 | 303 | | liability company or corporation that, is licensed or |
---|
304 | 304 | | accredited to offer one or more programs of higher learning |
---|
305 | 305 | | leading to one or more degrees; |
---|
306 | 306 | | R. "mental health facility" means any health care |
---|
307 | 307 | | facility in which at least seventy percent of the health care |
---|
308 | 308 | | services provided in such facility are mental health services; |
---|
309 | 309 | | S. "nonprofit organization" means any organization |
---|
310 | 310 | | that is exempt from taxation under Section 501(c)(3), |
---|
311 | 311 | | 501(c)(4), 501(c)(6) or 501(c)(12) of the Internal Revenue Code |
---|
312 | 312 | | of 1986, or any subsequent corresponding Internal Revenue Code |
---|
313 | 313 | | of the United States, as amended from time to time; |
---|
314 | 314 | | T. "person" means an individual, association, |
---|
315 | 315 | | company, limited liability company, corporation, partnership, |
---|
316 | 316 | | sole proprietorship, trust or other legal entity; |
---|
317 | 317 | | U. "personal data" means any information that is |
---|
318 | 318 | | linked or reasonably linkable to an identified or identifiable |
---|
319 | 319 | | individual. "Personal data" does not include de-identified |
---|
320 | 320 | | data or publicly available information; |
---|
321 | 321 | | V. "precise geolocation data" means information |
---|
322 | 322 | | derived from technology, including global positioning system |
---|
323 | 323 | | level latitude and longitude coordinates or other mechanisms, |
---|
324 | 324 | | that directly identifies the specific location of an individual |
---|
325 | 325 | | with precision and accuracy within a radius of one thousand |
---|
326 | 326 | | seven hundred fifty feet. "Precise geolocation data" does not |
---|
327 | 327 | | .230052.1ms |
---|
328 | 328 | | - 6 - underscored material = new |
---|
329 | 329 | | [bracketed material] = delete |
---|
330 | 330 | | 1 |
---|
331 | 331 | | 2 |
---|
332 | 332 | | 3 |
---|
333 | 333 | | 4 |
---|
334 | 334 | | 5 |
---|
335 | 335 | | 6 |
---|
336 | 336 | | 7 |
---|
337 | 337 | | 8 |
---|
338 | 338 | | 9 |
---|
339 | 339 | | 10 |
---|
340 | 340 | | 11 |
---|
341 | 341 | | 12 |
---|
342 | 342 | | 13 |
---|
343 | 343 | | 14 |
---|
344 | 344 | | 15 |
---|
345 | 345 | | 16 |
---|
346 | 346 | | 17 |
---|
347 | 347 | | 18 |
---|
348 | 348 | | 19 |
---|
349 | 349 | | 20 |
---|
350 | 350 | | 21 |
---|
351 | 351 | | 22 |
---|
352 | 352 | | 23 |
---|
353 | 353 | | 24 |
---|
354 | 354 | | 25 |
---|
355 | 355 | | include the content of communications or any data generated by |
---|
356 | 356 | | or connected to advanced utility metering infrastructure |
---|
357 | 357 | | systems or equipment for use by a utility; |
---|
358 | 358 | | W. "process" means any operation or set of |
---|
359 | 359 | | operations performed, whether by manual or automated means, on |
---|
360 | 360 | | personal data or on sets of personal data, such as the |
---|
361 | 361 | | collection, use, storage, disclosure, analysis, deletion or |
---|
362 | 362 | | modification of personal data; |
---|
363 | 363 | | X. "processor" means a person who processes |
---|
364 | 364 | | personal data on behalf of a controller; |
---|
365 | 365 | | Y. "profiling" means any form of automated |
---|
366 | 366 | | processing performed on personal data to evaluate, analyze or |
---|
367 | 367 | | predict personal aspects related to an identified or |
---|
368 | 368 | | identifiable individual's economic situation, health, personal |
---|
369 | 369 | | preferences, interests, reliability, behavior, location or |
---|
370 | 370 | | movements; |
---|
371 | 371 | | Z. "protected health information" has the same |
---|
372 | 372 | | meaning as provided in HIPAA; |
---|
373 | 373 | | AA. "pseudonymous data" means personal data that |
---|
374 | 374 | | cannot be attributed to a specific individual without the use |
---|
375 | 375 | | of additional information; provided that such additional |
---|
376 | 376 | | information is kept separately and is subject to appropriate |
---|
377 | 377 | | technical and organizational measures to ensure that the |
---|
378 | 378 | | personal data is not attributed to an identified or |
---|
379 | 379 | | identifiable individual; |
---|
380 | 380 | | .230052.1ms |
---|
381 | 381 | | - 7 - underscored material = new |
---|
382 | 382 | | [bracketed material] = delete |
---|
383 | 383 | | 1 |
---|
384 | 384 | | 2 |
---|
385 | 385 | | 3 |
---|
386 | 386 | | 4 |
---|
387 | 387 | | 5 |
---|
388 | 388 | | 6 |
---|
389 | 389 | | 7 |
---|
390 | 390 | | 8 |
---|
391 | 391 | | 9 |
---|
392 | 392 | | 10 |
---|
393 | 393 | | 11 |
---|
394 | 394 | | 12 |
---|
395 | 395 | | 13 |
---|
396 | 396 | | 14 |
---|
397 | 397 | | 15 |
---|
398 | 398 | | 16 |
---|
399 | 399 | | 17 |
---|
400 | 400 | | 18 |
---|
401 | 401 | | 19 |
---|
402 | 402 | | 20 |
---|
403 | 403 | | 21 |
---|
404 | 404 | | 22 |
---|
405 | 405 | | 23 |
---|
406 | 406 | | 24 |
---|
407 | 407 | | 25 |
---|
408 | 408 | | BB. "publicly available information" means |
---|
409 | 409 | | information that: |
---|
410 | 410 | | (1) is lawfully made available through |
---|
411 | 411 | | federal, state or municipal government records or widely |
---|
412 | 412 | | distributed media; and |
---|
413 | 413 | | (2) a controller has a reasonable basis to |
---|
414 | 414 | | believe a consumer has lawfully made available to the general |
---|
415 | 415 | | public; |
---|
416 | 416 | | CC. "reproductive or sexual health care" means any |
---|
417 | 417 | | health care-related services or products rendered or provided |
---|
418 | 418 | | concerning a consumer's reproductive system or sexual well- |
---|
419 | 419 | | being, including any such service or product rendered or |
---|
420 | 420 | | provided concerning: |
---|
421 | 421 | | (1) an individual health condition, status, |
---|
422 | 422 | | disease, diagnosis, diagnostic test or treatment; |
---|
423 | 423 | | (2) a social, psychological, behavioral or |
---|
424 | 424 | | medical intervention; |
---|
425 | 425 | | (3) a surgery or procedure, including an |
---|
426 | 426 | | abortion; |
---|
427 | 427 | | (4) a use or purchase of a medication, |
---|
428 | 428 | | including, but not limited to, a medication used or purchased |
---|
429 | 429 | | for the purposes of an abortion; |
---|
430 | 430 | | (5) a bodily function, vital sign or symptom; |
---|
431 | 431 | | (6) a measurement of a bodily function, vital |
---|
432 | 432 | | sign or symptom; or |
---|
433 | 433 | | .230052.1ms |
---|
434 | 434 | | - 8 - underscored material = new |
---|
435 | 435 | | [bracketed material] = delete |
---|
436 | 436 | | 1 |
---|
437 | 437 | | 2 |
---|
438 | 438 | | 3 |
---|
439 | 439 | | 4 |
---|
440 | 440 | | 5 |
---|
441 | 441 | | 6 |
---|
442 | 442 | | 7 |
---|
443 | 443 | | 8 |
---|
444 | 444 | | 9 |
---|
445 | 445 | | 10 |
---|
446 | 446 | | 11 |
---|
447 | 447 | | 12 |
---|
448 | 448 | | 13 |
---|
449 | 449 | | 14 |
---|
450 | 450 | | 15 |
---|
451 | 451 | | 16 |
---|
452 | 452 | | 17 |
---|
453 | 453 | | 18 |
---|
454 | 454 | | 19 |
---|
455 | 455 | | 20 |
---|
456 | 456 | | 21 |
---|
457 | 457 | | 22 |
---|
458 | 458 | | 23 |
---|
459 | 459 | | 24 |
---|
460 | 460 | | 25 |
---|
461 | 461 | | (7) an abortion, including medical or |
---|
462 | 462 | | nonmedical services, products, diagnostics, counseling or |
---|
463 | 463 | | follow-up services for an abortion; |
---|
464 | 464 | | DD. "reproductive or sexual health facility" means |
---|
465 | 465 | | any health care facility in which at least seventy percent of |
---|
466 | 466 | | the health care-related services or products rendered or |
---|
467 | 467 | | provided in such facility are reproductive or sexual health |
---|
468 | 468 | | care; |
---|
469 | 469 | | EE. "sale of personal data" means the exchange of |
---|
470 | 470 | | personal data for monetary or other valuable consideration by |
---|
471 | 471 | | the controller to a third party. "Sale of personal data" does |
---|
472 | 472 | | not include: |
---|
473 | 473 | | (1) the disclosure of personal data to a |
---|
474 | 474 | | processor that processes the personal data on behalf of the |
---|
475 | 475 | | controller; |
---|
476 | 476 | | (2) the disclosure of personal data to a third |
---|
477 | 477 | | party for purposes of providing a product or service requested |
---|
478 | 478 | | by the consumer; |
---|
479 | 479 | | (3) the disclosure or transfer of personal |
---|
480 | 480 | | data to an affiliate of the controller; |
---|
481 | 481 | | (4) the disclosure of personal data where the |
---|
482 | 482 | | consumer directs the controller to disclose the personal data |
---|
483 | 483 | | or intentionally uses the controller to interact with a third |
---|
484 | 484 | | party; |
---|
485 | 485 | | (5) the disclosure of personal data that the |
---|
486 | 486 | | .230052.1ms |
---|
487 | 487 | | - 9 - underscored material = new |
---|
488 | 488 | | [bracketed material] = delete |
---|
489 | 489 | | 1 |
---|
490 | 490 | | 2 |
---|
491 | 491 | | 3 |
---|
492 | 492 | | 4 |
---|
493 | 493 | | 5 |
---|
494 | 494 | | 6 |
---|
495 | 495 | | 7 |
---|
496 | 496 | | 8 |
---|
497 | 497 | | 9 |
---|
498 | 498 | | 10 |
---|
499 | 499 | | 11 |
---|
500 | 500 | | 12 |
---|
501 | 501 | | 13 |
---|
502 | 502 | | 14 |
---|
503 | 503 | | 15 |
---|
504 | 504 | | 16 |
---|
505 | 505 | | 17 |
---|
506 | 506 | | 18 |
---|
507 | 507 | | 19 |
---|
508 | 508 | | 20 |
---|
509 | 509 | | 21 |
---|
510 | 510 | | 22 |
---|
511 | 511 | | 23 |
---|
512 | 512 | | 24 |
---|
513 | 513 | | 25 |
---|
514 | 514 | | consumer intentionally made available to the general public via |
---|
515 | 515 | | a channel of mass media and did not restrict to a specific |
---|
516 | 516 | | audience; or |
---|
517 | 517 | | (6) the disclosure or transfer of personal |
---|
518 | 518 | | data to a third party as an asset that is part of a merger, |
---|
519 | 519 | | acquisition, bankruptcy or other transaction, or a proposed |
---|
520 | 520 | | merger, acquisition, bankruptcy or other transaction, in which |
---|
521 | 521 | | the third party assumes control of all or part of the |
---|
522 | 522 | | controller's assets; |
---|
523 | 523 | | FF. "sensitive data" means personal data that |
---|
524 | 524 | | includes: |
---|
525 | 525 | | (1) data revealing racial or ethnic origin, |
---|
526 | 526 | | religious beliefs, mental or physical health condition or |
---|
527 | 527 | | diagnosis, sex life, sexual orientation or citizenship or |
---|
528 | 528 | | immigration status; |
---|
529 | 529 | | (2) consumer health data; |
---|
530 | 530 | | (3) the processing of genetic or biometric |
---|
531 | 531 | | data for the purpose of uniquely identifying an individual; |
---|
532 | 532 | | (4) personal data collected from a known |
---|
533 | 533 | | child; |
---|
534 | 534 | | (5) data concerning an individual's status as |
---|
535 | 535 | | a victim of crime; or |
---|
536 | 536 | | (6) precise geolocation data; |
---|
537 | 537 | | GG. "targeted advertising" means displaying |
---|
538 | 538 | | advertisements to a consumer where the advertisement is |
---|
539 | 539 | | .230052.1ms |
---|
540 | 540 | | - 10 - underscored material = new |
---|
541 | 541 | | [bracketed material] = delete |
---|
542 | 542 | | 1 |
---|
543 | 543 | | 2 |
---|
544 | 544 | | 3 |
---|
545 | 545 | | 4 |
---|
546 | 546 | | 5 |
---|
547 | 547 | | 6 |
---|
548 | 548 | | 7 |
---|
549 | 549 | | 8 |
---|
550 | 550 | | 9 |
---|
551 | 551 | | 10 |
---|
552 | 552 | | 11 |
---|
553 | 553 | | 12 |
---|
554 | 554 | | 13 |
---|
555 | 555 | | 14 |
---|
556 | 556 | | 15 |
---|
557 | 557 | | 16 |
---|
558 | 558 | | 17 |
---|
559 | 559 | | 18 |
---|
560 | 560 | | 19 |
---|
561 | 561 | | 20 |
---|
562 | 562 | | 21 |
---|
563 | 563 | | 22 |
---|
564 | 564 | | 23 |
---|
565 | 565 | | 24 |
---|
566 | 566 | | 25 |
---|
567 | 567 | | selected based on personal data obtained or inferred from that |
---|
568 | 568 | | consumer's activities over time and across nonaffiliated |
---|
569 | 569 | | internet websites or online applications to predict such |
---|
570 | 570 | | consumer's preferences or interests. "Targeted advertising" |
---|
571 | 571 | | does not include: |
---|
572 | 572 | | (1) advertisements based on activities within |
---|
573 | 573 | | a controller's own internet website or online applications; |
---|
574 | 574 | | (2) advertisements based on the context of a |
---|
575 | 575 | | consumer's current search query, visit to an internet website |
---|
576 | 576 | | or online application; |
---|
577 | 577 | | (3) advertisements directed to a consumer in |
---|
578 | 578 | | response to the consumer's request for information or feedback; |
---|
579 | 579 | | or |
---|
580 | 580 | | (4) processing personal data solely to measure |
---|
581 | 581 | | or report advertising frequency, performance or reach; and |
---|
582 | 582 | | HH. "third party" means a person, such as a public |
---|
583 | 583 | | authority, agency or body, other than the consumer, controller |
---|
584 | 584 | | or processor or an affiliate of the processor or the |
---|
585 | 585 | | controller. |
---|
586 | 586 | | SECTION 3. [NEW MATERIAL] SCOPE OF ACT--EXEMPTIONS.-- |
---|
587 | 587 | | A. The Consumer Information and Data Protection Act |
---|
588 | 588 | | applies to persons that conduct business in this state and |
---|
589 | 589 | | persons that produce products or services that are targeted to |
---|
590 | 590 | | residents of this state. |
---|
591 | 591 | | B. No person shall: |
---|
592 | 592 | | .230052.1ms |
---|
593 | 593 | | - 11 - underscored material = new |
---|
594 | 594 | | [bracketed material] = delete |
---|
595 | 595 | | 1 |
---|
596 | 596 | | 2 |
---|
597 | 597 | | 3 |
---|
598 | 598 | | 4 |
---|
599 | 599 | | 5 |
---|
600 | 600 | | 6 |
---|
601 | 601 | | 7 |
---|
602 | 602 | | 8 |
---|
603 | 603 | | 9 |
---|
604 | 604 | | 10 |
---|
605 | 605 | | 11 |
---|
606 | 606 | | 12 |
---|
607 | 607 | | 13 |
---|
608 | 608 | | 14 |
---|
609 | 609 | | 15 |
---|
610 | 610 | | 16 |
---|
611 | 611 | | 17 |
---|
612 | 612 | | 18 |
---|
613 | 613 | | 19 |
---|
614 | 614 | | 20 |
---|
615 | 615 | | 21 |
---|
616 | 616 | | 22 |
---|
617 | 617 | | 23 |
---|
618 | 618 | | 24 |
---|
619 | 619 | | 25 |
---|
620 | 620 | | (1) provide any employee or contractor with |
---|
621 | 621 | | access to consumer health data unless the employee or |
---|
622 | 622 | | contractor is subject to a contractual or statutory duty of |
---|
623 | 623 | | confidentiality; |
---|
624 | 624 | | (2) provide any processor with access to |
---|
625 | 625 | | consumer health data unless such person and processor comply |
---|
626 | 626 | | with Section 6 of the Consumer Information and Data Protection |
---|
627 | 627 | | Act; |
---|
628 | 628 | | (3) use a geofence to establish a virtual |
---|
629 | 629 | | boundary that is within one thousand seven hundred fifty feet |
---|
630 | 630 | | of any mental health facility or reproductive or sexual health |
---|
631 | 631 | | facility for the purpose of identifying, tracking, collecting |
---|
632 | 632 | | data from or sending any notification to a consumer regarding |
---|
633 | 633 | | the consumer's consumer health data; or |
---|
634 | 634 | | (4) sell, or offer to sell, consumer health |
---|
635 | 635 | | data without first obtaining the consumer's consent. |
---|
636 | 636 | | C. The provisions of the Consumer Information and |
---|
637 | 637 | | Data Protection Act shall not apply to any: |
---|
638 | 638 | | (1) body, authority, board, bureau, |
---|
639 | 639 | | commission, district or agency of the state or of any political |
---|
640 | 640 | | subdivision of the state; |
---|
641 | 641 | | (2) financial institution or data subject to |
---|
642 | 642 | | Title V of the federal Gramm-Leach-Bliley Act (15 U.S.C. |
---|
643 | 643 | | Section 6801 et seq.); |
---|
644 | 644 | | (3) covered entity or business associate |
---|
645 | 645 | | .230052.1ms |
---|
646 | 646 | | - 12 - underscored material = new |
---|
647 | 647 | | [bracketed material] = delete |
---|
648 | 648 | | 1 |
---|
649 | 649 | | 2 |
---|
650 | 650 | | 3 |
---|
651 | 651 | | 4 |
---|
652 | 652 | | 5 |
---|
653 | 653 | | 6 |
---|
654 | 654 | | 7 |
---|
655 | 655 | | 8 |
---|
656 | 656 | | 9 |
---|
657 | 657 | | 10 |
---|
658 | 658 | | 11 |
---|
659 | 659 | | 12 |
---|
660 | 660 | | 13 |
---|
661 | 661 | | 14 |
---|
662 | 662 | | 15 |
---|
663 | 663 | | 16 |
---|
664 | 664 | | 17 |
---|
665 | 665 | | 18 |
---|
666 | 666 | | 19 |
---|
667 | 667 | | 20 |
---|
668 | 668 | | 21 |
---|
669 | 669 | | 22 |
---|
670 | 670 | | 23 |
---|
671 | 671 | | 24 |
---|
672 | 672 | | 25 |
---|
673 | 673 | | governed by the privacy, security and breach notification rules |
---|
674 | 674 | | issued by the federal department of health and human services, |
---|
675 | 675 | | 45 C.F.R. Parts 160 and 164 established pursuant to HIPAA, and |
---|
676 | 676 | | the Health Information Technology for Economic and Clinical |
---|
677 | 677 | | Health Act (P.L. 111-5); |
---|
678 | 678 | | (4) nonprofit organization; or |
---|
679 | 679 | | (5) institution of higher education. |
---|
680 | 680 | | D. The following information and data are exempt |
---|
681 | 681 | | from the Consumer Information and Data Protection Act: |
---|
682 | 682 | | (1) protected health information under HIPAA; |
---|
683 | 683 | | (2) patient identifying information for |
---|
684 | 684 | | purposes of 42 U.S.C. Section 290dd-2; |
---|
685 | 685 | | (3) identifiable private information for |
---|
686 | 686 | | purposes of the federal policy for the protection of human |
---|
687 | 687 | | subjects under 45 C.F.R. Part 46; identifiable private |
---|
688 | 688 | | information that is otherwise information collected as part of |
---|
689 | 689 | | human subjects research pursuant to the good clinical practice |
---|
690 | 690 | | guidelines issued by the international council for |
---|
691 | 691 | | harmonization of technical requirements for pharmaceuticals for |
---|
692 | 692 | | human use; the protection of human subjects under 21 C.F.R. |
---|
693 | 693 | | Parts 6, 50 and 56; or personal data used or shared in research |
---|
694 | 694 | | conducted in accordance with the requirements set forth in the |
---|
695 | 695 | | Consumer Information and Data Protection Act or other research |
---|
696 | 696 | | conducted in accordance with applicable law; |
---|
697 | 697 | | (4) information and documents created for |
---|
698 | 698 | | .230052.1ms |
---|
699 | 699 | | - 13 - underscored material = new |
---|
700 | 700 | | [bracketed material] = delete |
---|
701 | 701 | | 1 |
---|
702 | 702 | | 2 |
---|
703 | 703 | | 3 |
---|
704 | 704 | | 4 |
---|
705 | 705 | | 5 |
---|
706 | 706 | | 6 |
---|
707 | 707 | | 7 |
---|
708 | 708 | | 8 |
---|
709 | 709 | | 9 |
---|
710 | 710 | | 10 |
---|
711 | 711 | | 11 |
---|
712 | 712 | | 12 |
---|
713 | 713 | | 13 |
---|
714 | 714 | | 14 |
---|
715 | 715 | | 15 |
---|
716 | 716 | | 16 |
---|
717 | 717 | | 17 |
---|
718 | 718 | | 18 |
---|
719 | 719 | | 19 |
---|
720 | 720 | | 20 |
---|
721 | 721 | | 21 |
---|
722 | 722 | | 22 |
---|
723 | 723 | | 23 |
---|
724 | 724 | | 24 |
---|
725 | 725 | | 25 |
---|
726 | 726 | | purposes of the federal Health Care Quality Improvement Act of |
---|
727 | 727 | | 1986 (42 U.S.C. Section 11101 et seq.); |
---|
728 | 728 | | (5) patient safety work product for purposes |
---|
729 | 729 | | of the federal Patient Safety and Quality Improvement Act of |
---|
730 | 730 | | 2005 (42 U.S.C. Section 299b-21 et seq.); |
---|
731 | 731 | | (6) information derived from any of the health |
---|
732 | 732 | | care-related information listed in this subsection that is de- |
---|
733 | 733 | | identified in accordance with the requirements for de- |
---|
734 | 734 | | identification pursuant to HIPAA; |
---|
735 | 735 | | (7) information originating from, and |
---|
736 | 736 | | intermingled to be indistinguishable with, or information |
---|
737 | 737 | | treated in the same manner as information exempt under this |
---|
738 | 738 | | subsection that is maintained by a covered entity or business |
---|
739 | 739 | | associate as defined by HIPAA or a program or a qualified |
---|
740 | 740 | | service organization as defined by 42 U.S.C. Section 290dd-2; |
---|
741 | 741 | | (8) information used only for public health |
---|
742 | 742 | | activities and purposes as authorized by HIPAA; |
---|
743 | 743 | | (9) the collection, maintenance, disclosure, |
---|
744 | 744 | | sale, communication or use of any personal information bearing |
---|
745 | 745 | | on a consumer's credit worthiness, credit standing, credit |
---|
746 | 746 | | capacity, character, general reputation, personal |
---|
747 | 747 | | characteristics or mode of living by a consumer reporting |
---|
748 | 748 | | agency or furnisher that provides information for use in a |
---|
749 | 749 | | consumer report and by a user of a consumer report but only to |
---|
750 | 750 | | the extent that such activity is regulated by and authorized |
---|
751 | 751 | | .230052.1ms |
---|
752 | 752 | | - 14 - underscored material = new |
---|
753 | 753 | | [bracketed material] = delete |
---|
754 | 754 | | 1 |
---|
755 | 755 | | 2 |
---|
756 | 756 | | 3 |
---|
757 | 757 | | 4 |
---|
758 | 758 | | 5 |
---|
759 | 759 | | 6 |
---|
760 | 760 | | 7 |
---|
761 | 761 | | 8 |
---|
762 | 762 | | 9 |
---|
763 | 763 | | 10 |
---|
764 | 764 | | 11 |
---|
765 | 765 | | 12 |
---|
766 | 766 | | 13 |
---|
767 | 767 | | 14 |
---|
768 | 768 | | 15 |
---|
769 | 769 | | 16 |
---|
770 | 770 | | 17 |
---|
771 | 771 | | 18 |
---|
772 | 772 | | 19 |
---|
773 | 773 | | 20 |
---|
774 | 774 | | 21 |
---|
775 | 775 | | 22 |
---|
776 | 776 | | 23 |
---|
777 | 777 | | 24 |
---|
778 | 778 | | 25 |
---|
779 | 779 | | under the federal Fair Credit Reporting Act (15 U.S.C. Section |
---|
780 | 780 | | 1681 et seq.); |
---|
781 | 781 | | (10) personal data collected, processed, sold |
---|
782 | 782 | | or disclosed in compliance with the federal Driver's Privacy |
---|
783 | 783 | | Protection Act of 1994 (18 U.S.C. Section 2721 et seq.); |
---|
784 | 784 | | (11) personal data regulated by the federal |
---|
785 | 785 | | Family Educational Rights and Privacy Act of 1974 (20 U.S.C. |
---|
786 | 786 | | Section 1232g et seq.); |
---|
787 | 787 | | (12) personal data collected, processed, sold |
---|
788 | 788 | | or disclosed in compliance with the federal Farm Credit Act of |
---|
789 | 789 | | 1971 (12 U.S.C. Section 2001 et seq.); and |
---|
790 | 790 | | (13) data processed or maintained: |
---|
791 | 791 | | (a) in the course of an individual |
---|
792 | 792 | | applying to, employed by or acting as an agent or independent |
---|
793 | 793 | | contractor of a controller, processor or third party, to the |
---|
794 | 794 | | extent that the data is collected and used within the context |
---|
795 | 795 | | of that role; |
---|
796 | 796 | | (b) as the emergency contact information |
---|
797 | 797 | | of an individual under the Consumer Information and Data |
---|
798 | 798 | | Protection Act used for emergency contact purposes; or |
---|
799 | 799 | | (c) that is necessary to retain to |
---|
800 | 800 | | administer benefits for another individual relating to the |
---|
801 | 801 | | individual under Subparagraph (a) of this paragraph and used |
---|
802 | 802 | | for the purposes of administering those benefits. |
---|
803 | 803 | | SECTION 4. [NEW MATERIAL] CONSUMER RIGHTS.-- |
---|
804 | 804 | | .230052.1ms |
---|
805 | 805 | | - 15 - underscored material = new |
---|
806 | 806 | | [bracketed material] = delete |
---|
807 | 807 | | 1 |
---|
808 | 808 | | 2 |
---|
809 | 809 | | 3 |
---|
810 | 810 | | 4 |
---|
811 | 811 | | 5 |
---|
812 | 812 | | 6 |
---|
813 | 813 | | 7 |
---|
814 | 814 | | 8 |
---|
815 | 815 | | 9 |
---|
816 | 816 | | 10 |
---|
817 | 817 | | 11 |
---|
818 | 818 | | 12 |
---|
819 | 819 | | 13 |
---|
820 | 820 | | 14 |
---|
821 | 821 | | 15 |
---|
822 | 822 | | 16 |
---|
823 | 823 | | 17 |
---|
824 | 824 | | 18 |
---|
825 | 825 | | 19 |
---|
826 | 826 | | 20 |
---|
827 | 827 | | 21 |
---|
828 | 828 | | 22 |
---|
829 | 829 | | 23 |
---|
830 | 830 | | 24 |
---|
831 | 831 | | 25 |
---|
832 | 832 | | A. A consumer may invoke the consumer rights |
---|
833 | 833 | | authorized pursuant to this section at any time by submitting a |
---|
834 | 834 | | request to a controller specifying the consumer rights the |
---|
835 | 835 | | consumer wishes to invoke. A known child's parent or legal |
---|
836 | 836 | | guardian may invoke such consumer rights on behalf of the child |
---|
837 | 837 | | regarding processing personal data belonging to the known |
---|
838 | 838 | | child. A controller shall comply with an authenticated |
---|
839 | 839 | | consumer request to exercise the right: |
---|
840 | 840 | | (1) to confirm whether or not a controller is |
---|
841 | 841 | | processing the consumer's personal data and to access such |
---|
842 | 842 | | personal data; |
---|
843 | 843 | | (2) to correct inaccuracies in the consumer's |
---|
844 | 844 | | personal data, taking into account the nature of the personal |
---|
845 | 845 | | data and the purposes of the processing of the consumer's |
---|
846 | 846 | | personal data; |
---|
847 | 847 | | (3) to delete personal data provided by or |
---|
848 | 848 | | obtained about the consumer; |
---|
849 | 849 | | (4) to obtain a copy of the consumer's |
---|
850 | 850 | | personal data that the consumer previously provided to the |
---|
851 | 851 | | controller in a portable and, to the extent technically |
---|
852 | 852 | | feasible, readily usable format that allows the consumer to |
---|
853 | 853 | | transmit the data to another controller without hindrance, |
---|
854 | 854 | | where the processing is carried out by automated means; and |
---|
855 | 855 | | (5) to opt out of the processing of the |
---|
856 | 856 | | personal data for purposes of targeted advertising, the sale of |
---|
857 | 857 | | .230052.1ms |
---|
858 | 858 | | - 16 - underscored material = new |
---|
859 | 859 | | [bracketed material] = delete |
---|
860 | 860 | | 1 |
---|
861 | 861 | | 2 |
---|
862 | 862 | | 3 |
---|
863 | 863 | | 4 |
---|
864 | 864 | | 5 |
---|
865 | 865 | | 6 |
---|
866 | 866 | | 7 |
---|
867 | 867 | | 8 |
---|
868 | 868 | | 9 |
---|
869 | 869 | | 10 |
---|
870 | 870 | | 11 |
---|
871 | 871 | | 12 |
---|
872 | 872 | | 13 |
---|
873 | 873 | | 14 |
---|
874 | 874 | | 15 |
---|
875 | 875 | | 16 |
---|
876 | 876 | | 17 |
---|
877 | 877 | | 18 |
---|
878 | 878 | | 19 |
---|
879 | 879 | | 20 |
---|
880 | 880 | | 21 |
---|
881 | 881 | | 22 |
---|
882 | 882 | | 23 |
---|
883 | 883 | | 24 |
---|
884 | 884 | | 25 |
---|
885 | 885 | | personal data or profiling in furtherance of decisions that |
---|
886 | 886 | | produce legal or similarly significant effects concerning the |
---|
887 | 887 | | consumer. |
---|
888 | 888 | | B. A consumer may exercise rights under this |
---|
889 | 889 | | section by a secure and reliable means established by the |
---|
890 | 890 | | controller and described to the consumer in the controller's |
---|
891 | 891 | | privacy notice. In the case of processing personal data of a |
---|
892 | 892 | | known child, the parent or legal guardian may exercise such |
---|
893 | 893 | | consumer rights on the child's behalf. In the case of |
---|
894 | 894 | | processing personal data concerning a consumer subject to a |
---|
895 | 895 | | guardianship, conservatorship or other protective arrangement, |
---|
896 | 896 | | the guardian or the conservator of the consumer may exercise |
---|
897 | 897 | | such rights on the consumer's behalf. |
---|
898 | 898 | | C. Except as otherwise provided in the Consumer |
---|
899 | 899 | | Information and Data Protection Act, a controller shall comply |
---|
900 | 900 | | with a request by a consumer to exercise the consumer rights |
---|
901 | 901 | | authorized pursuant to Subsection A of this section as follows: |
---|
902 | 902 | | (1) a controller shall respond to the consumer |
---|
903 | 903 | | without undue delay, but in all cases within forty-five days of |
---|
904 | 904 | | receipt of the request submitted pursuant to the methods |
---|
905 | 905 | | described in Subsection A of this section. The response period |
---|
906 | 906 | | may be extended once by forty-five additional days when |
---|
907 | 907 | | reasonably necessary, taking into account the complexity and |
---|
908 | 908 | | number of the consumer's requests, so long as the controller |
---|
909 | 909 | | informs the consumer of any such extension within the initial |
---|
910 | 910 | | .230052.1ms |
---|
911 | 911 | | - 17 - underscored material = new |
---|
912 | 912 | | [bracketed material] = delete |
---|
913 | 913 | | 1 |
---|
914 | 914 | | 2 |
---|
915 | 915 | | 3 |
---|
916 | 916 | | 4 |
---|
917 | 917 | | 5 |
---|
918 | 918 | | 6 |
---|
919 | 919 | | 7 |
---|
920 | 920 | | 8 |
---|
921 | 921 | | 9 |
---|
922 | 922 | | 10 |
---|
923 | 923 | | 11 |
---|
924 | 924 | | 12 |
---|
925 | 925 | | 13 |
---|
926 | 926 | | 14 |
---|
927 | 927 | | 15 |
---|
928 | 928 | | 16 |
---|
929 | 929 | | 17 |
---|
930 | 930 | | 18 |
---|
931 | 931 | | 19 |
---|
932 | 932 | | 20 |
---|
933 | 933 | | 21 |
---|
934 | 934 | | 22 |
---|
935 | 935 | | 23 |
---|
936 | 936 | | 24 |
---|
937 | 937 | | 25 |
---|
938 | 938 | | forty-five-day response period, together with the reason for |
---|
939 | 939 | | the extension; |
---|
940 | 940 | | (2) if a controller declines to take action |
---|
941 | 941 | | regarding the consumer's request, the controller shall inform |
---|
942 | 942 | | the consumer without undue delay, but in all cases and at the |
---|
943 | 943 | | latest within forty-five days of receipt of the request, of the |
---|
944 | 944 | | justification for declining to take action and instructions for |
---|
945 | 945 | | how to appeal the decision pursuant to Subsection D of this |
---|
946 | 946 | | section; |
---|
947 | 947 | | (3) information provided in response to a |
---|
948 | 948 | | consumer request shall be provided by a controller free of |
---|
949 | 949 | | charge, up to twice annually per consumer. If requests from a |
---|
950 | 950 | | consumer are manifestly unfounded, excessive or repetitive, the |
---|
951 | 951 | | controller may charge the consumer a reasonable fee to cover |
---|
952 | 952 | | the administrative costs of complying with the request or |
---|
953 | 953 | | decline to act on the request. The controller bears the burden |
---|
954 | 954 | | of demonstrating the manifestly unfounded, excessive or |
---|
955 | 955 | | repetitive nature of the request; |
---|
956 | 956 | | (4) if a controller is unable to authenticate |
---|
957 | 957 | | the request using commercially reasonable efforts, the |
---|
958 | 958 | | controller shall not be required to comply with a request to |
---|
959 | 959 | | initiate an action under Subsection A of this section and may |
---|
960 | 960 | | request that the consumer provide additional information |
---|
961 | 961 | | reasonably necessary to authenticate the consumer and the |
---|
962 | 962 | | consumer's request; and |
---|
963 | 963 | | .230052.1ms |
---|
964 | 964 | | - 18 - underscored material = new |
---|
965 | 965 | | [bracketed material] = delete |
---|
966 | 966 | | 1 |
---|
967 | 967 | | 2 |
---|
968 | 968 | | 3 |
---|
969 | 969 | | 4 |
---|
970 | 970 | | 5 |
---|
971 | 971 | | 6 |
---|
972 | 972 | | 7 |
---|
973 | 973 | | 8 |
---|
974 | 974 | | 9 |
---|
975 | 975 | | 10 |
---|
976 | 976 | | 11 |
---|
977 | 977 | | 12 |
---|
978 | 978 | | 13 |
---|
979 | 979 | | 14 |
---|
980 | 980 | | 15 |
---|
981 | 981 | | 16 |
---|
982 | 982 | | 17 |
---|
983 | 983 | | 18 |
---|
984 | 984 | | 19 |
---|
985 | 985 | | 20 |
---|
986 | 986 | | 21 |
---|
987 | 987 | | 22 |
---|
988 | 988 | | 23 |
---|
989 | 989 | | 24 |
---|
990 | 990 | | 25 |
---|
991 | 991 | | (5) a controller that has obtained personal |
---|
992 | 992 | | data about a consumer from a source other than the consumer |
---|
993 | 993 | | shall be deemed in compliance with a consumer's request to |
---|
994 | 994 | | delete such data pursuant to Paragraph (2) of Subsection A of |
---|
995 | 995 | | this section by either: |
---|
996 | 996 | | (a) retaining a record of the deletion |
---|
997 | 997 | | request and the minimum data necessary for the purpose of |
---|
998 | 998 | | ensuring the consumer's personal data remains deleted from the |
---|
999 | 999 | | business's records and not using such retained data for any |
---|
1000 | 1000 | | other purpose pursuant to the provisions of the Consumer |
---|
1001 | 1001 | | Information and Data Protection Act; or |
---|
1002 | 1002 | | (b) opting the consumer out of the |
---|
1003 | 1003 | | processing of such personal data for any purpose except for |
---|
1004 | 1004 | | those exempted pursuant to the provisions of the Consumer |
---|
1005 | 1005 | | Information and Data Protection Act. |
---|
1006 | 1006 | | D. A controller shall establish a process for a |
---|
1007 | 1007 | | consumer to appeal the controller's refusal to take action on a |
---|
1008 | 1008 | | request within a reasonable period of time after the consumer's |
---|
1009 | 1009 | | receipt of the decision pursuant to Paragraph (2) of Subsection |
---|
1010 | 1010 | | C of this section. The appeal process shall be conspicuously |
---|
1011 | 1011 | | available and similar to the process for submitting requests to |
---|
1012 | 1012 | | initiate action pursuant to Subsection A of this section. |
---|
1013 | 1013 | | Within sixty days of receipt of an appeal, a controller shall |
---|
1014 | 1014 | | inform the consumer in writing of any action taken or not taken |
---|
1015 | 1015 | | in response to the appeal, including a written explanation of |
---|
1016 | 1016 | | .230052.1ms |
---|
1017 | 1017 | | - 19 - underscored material = new |
---|
1018 | 1018 | | [bracketed material] = delete |
---|
1019 | 1019 | | 1 |
---|
1020 | 1020 | | 2 |
---|
1021 | 1021 | | 3 |
---|
1022 | 1022 | | 4 |
---|
1023 | 1023 | | 5 |
---|
1024 | 1024 | | 6 |
---|
1025 | 1025 | | 7 |
---|
1026 | 1026 | | 8 |
---|
1027 | 1027 | | 9 |
---|
1028 | 1028 | | 10 |
---|
1029 | 1029 | | 11 |
---|
1030 | 1030 | | 12 |
---|
1031 | 1031 | | 13 |
---|
1032 | 1032 | | 14 |
---|
1033 | 1033 | | 15 |
---|
1034 | 1034 | | 16 |
---|
1035 | 1035 | | 17 |
---|
1036 | 1036 | | 18 |
---|
1037 | 1037 | | 19 |
---|
1038 | 1038 | | 20 |
---|
1039 | 1039 | | 21 |
---|
1040 | 1040 | | 22 |
---|
1041 | 1041 | | 23 |
---|
1042 | 1042 | | 24 |
---|
1043 | 1043 | | 25 |
---|
1044 | 1044 | | the reasons for the decisions. If the appeal is denied, the |
---|
1045 | 1045 | | controller shall also provide the consumer with an online |
---|
1046 | 1046 | | mechanism, if available, or other method through which the |
---|
1047 | 1047 | | consumer may contact the attorney general to submit a |
---|
1048 | 1048 | | complaint. |
---|
1049 | 1049 | | SECTION 5. [NEW MATERIAL] DATA CONTROLLER |
---|
1050 | 1050 | | RESPONSIBILITIES--TRANSPARENCY.-- |
---|
1051 | 1051 | | A. A controller shall: |
---|
1052 | 1052 | | (1) limit the collection of personal data to |
---|
1053 | 1053 | | what is adequate, relevant and reasonably necessary in relation |
---|
1054 | 1054 | | to the purposes for which such data is processed, as disclosed |
---|
1055 | 1055 | | to the consumer; |
---|
1056 | 1056 | | (2) except as otherwise provided in the |
---|
1057 | 1057 | | Consumer Information and Data Protection Act, not process |
---|
1058 | 1058 | | personal data for purposes that are neither reasonably |
---|
1059 | 1059 | | necessary to nor compatible with the disclosed purposes for |
---|
1060 | 1060 | | which such personal data is processed, as disclosed to the |
---|
1061 | 1061 | | consumer, unless the controller obtains the consumer's consent; |
---|
1062 | 1062 | | (3) establish, implement and maintain |
---|
1063 | 1063 | | reasonable administrative, technical and physical data security |
---|
1064 | 1064 | | practices to protect the confidentiality, integrity and |
---|
1065 | 1065 | | accessibility of personal data. Data security practices shall |
---|
1066 | 1066 | | be appropriate to the volume and nature of the personal data at |
---|
1067 | 1067 | | issue; |
---|
1068 | 1068 | | (4) not process personal data in violation of |
---|
1069 | 1069 | | .230052.1ms |
---|
1070 | 1070 | | - 20 - underscored material = new |
---|
1071 | 1071 | | [bracketed material] = delete |
---|
1072 | 1072 | | 1 |
---|
1073 | 1073 | | 2 |
---|
1074 | 1074 | | 3 |
---|
1075 | 1075 | | 4 |
---|
1076 | 1076 | | 5 |
---|
1077 | 1077 | | 6 |
---|
1078 | 1078 | | 7 |
---|
1079 | 1079 | | 8 |
---|
1080 | 1080 | | 9 |
---|
1081 | 1081 | | 10 |
---|
1082 | 1082 | | 11 |
---|
1083 | 1083 | | 12 |
---|
1084 | 1084 | | 13 |
---|
1085 | 1085 | | 14 |
---|
1086 | 1086 | | 15 |
---|
1087 | 1087 | | 16 |
---|
1088 | 1088 | | 17 |
---|
1089 | 1089 | | 18 |
---|
1090 | 1090 | | 19 |
---|
1091 | 1091 | | 20 |
---|
1092 | 1092 | | 21 |
---|
1093 | 1093 | | 22 |
---|
1094 | 1094 | | 23 |
---|
1095 | 1095 | | 24 |
---|
1096 | 1096 | | 25 |
---|
1097 | 1097 | | state and federal laws that prohibit unlawful discrimination |
---|
1098 | 1098 | | against consumers. A controller shall not discriminate against |
---|
1099 | 1099 | | a consumer for exercising any of the consumer rights contained |
---|
1100 | 1100 | | in the Consumer Information and Data Protection Act, including |
---|
1101 | 1101 | | denying goods or services, charging different prices or rates |
---|
1102 | 1102 | | for goods or services or providing a different level of quality |
---|
1103 | 1103 | | of goods and services to the consumer. However, nothing in |
---|
1104 | 1104 | | this subsection shall be construed to require a controller to |
---|
1105 | 1105 | | provide a product or service that requires the personal data of |
---|
1106 | 1106 | | a consumer that the controller does not collect or maintain or |
---|
1107 | 1107 | | to prohibit a controller from offering a different price, rate, |
---|
1108 | 1108 | | level, quality or selection of goods or services to a consumer, |
---|
1109 | 1109 | | including offering goods or services for no fee, if the |
---|
1110 | 1110 | | consumer has exercised the consumer's right to opt out pursuant |
---|
1111 | 1111 | | to Section 4 of the Consumer Information and Data Protection |
---|
1112 | 1112 | | Act or the offer is related to a consumer's voluntary |
---|
1113 | 1113 | | participation in a bona fide loyalty, rewards, premium |
---|
1114 | 1114 | | features, discounts or club card program; and |
---|
1115 | 1115 | | (5) not process sensitive data concerning a |
---|
1116 | 1116 | | consumer without obtaining the consumer's consent or, in the |
---|
1117 | 1117 | | case of the processing of sensitive data concerning a known |
---|
1118 | 1118 | | child, without processing such data in accordance with the |
---|
1119 | 1119 | | federal Children's Online Privacy Protection Act of 1998 (15 |
---|
1120 | 1120 | | U.S.C. Section 6501 et seq.). |
---|
1121 | 1121 | | B. Any provision of a contract or agreement of any |
---|
1122 | 1122 | | .230052.1ms |
---|
1123 | 1123 | | - 21 - underscored material = new |
---|
1124 | 1124 | | [bracketed material] = delete |
---|
1125 | 1125 | | 1 |
---|
1126 | 1126 | | 2 |
---|
1127 | 1127 | | 3 |
---|
1128 | 1128 | | 4 |
---|
1129 | 1129 | | 5 |
---|
1130 | 1130 | | 6 |
---|
1131 | 1131 | | 7 |
---|
1132 | 1132 | | 8 |
---|
1133 | 1133 | | 9 |
---|
1134 | 1134 | | 10 |
---|
1135 | 1135 | | 11 |
---|
1136 | 1136 | | 12 |
---|
1137 | 1137 | | 13 |
---|
1138 | 1138 | | 14 |
---|
1139 | 1139 | | 15 |
---|
1140 | 1140 | | 16 |
---|
1141 | 1141 | | 17 |
---|
1142 | 1142 | | 18 |
---|
1143 | 1143 | | 19 |
---|
1144 | 1144 | | 20 |
---|
1145 | 1145 | | 21 |
---|
1146 | 1146 | | 22 |
---|
1147 | 1147 | | 23 |
---|
1148 | 1148 | | 24 |
---|
1149 | 1149 | | 25 |
---|
1150 | 1150 | | kind that purports to waive or limit in any way consumer rights |
---|
1151 | 1151 | | pursuant to the Consumer Information and Data Protection Act |
---|
1152 | 1152 | | shall be deemed contrary to public policy and shall be void and |
---|
1153 | 1153 | | unenforceable. |
---|
1154 | 1154 | | C. A controller shall provide consumers with a |
---|
1155 | 1155 | | reasonably accessible, clear and meaningful privacy notice that |
---|
1156 | 1156 | | includes: |
---|
1157 | 1157 | | (1) the categories of personal data processed |
---|
1158 | 1158 | | by the controller; |
---|
1159 | 1159 | | (2) the purpose for processing personal data; |
---|
1160 | 1160 | | (3) how consumers may exercise their consumer |
---|
1161 | 1161 | | rights, including how a consumer may appeal a controller's |
---|
1162 | 1162 | | decision with regard to the consumer's request; |
---|
1163 | 1163 | | (4) the categories of personal data that the |
---|
1164 | 1164 | | controller shares with third parties, if any; |
---|
1165 | 1165 | | (5) the categories of third parties, if any, |
---|
1166 | 1166 | | with which the controller shares personal data; and |
---|
1167 | 1167 | | (6) an active electronic mail address or other |
---|
1168 | 1168 | | online mechanism that the consumer may use to contact the |
---|
1169 | 1169 | | controller. |
---|
1170 | 1170 | | D. If a controller sells personal data to third |
---|
1171 | 1171 | | parties or processes personal data for targeted advertising, |
---|
1172 | 1172 | | the controller shall clearly and conspicuously disclose such |
---|
1173 | 1173 | | processing, as well as the manner in which a consumer may |
---|
1174 | 1174 | | exercise the right to opt out of such processing. |
---|
1175 | 1175 | | .230052.1ms |
---|
1176 | 1176 | | - 22 - underscored material = new |
---|
1177 | 1177 | | [bracketed material] = delete |
---|
1178 | 1178 | | 1 |
---|
1179 | 1179 | | 2 |
---|
1180 | 1180 | | 3 |
---|
1181 | 1181 | | 4 |
---|
1182 | 1182 | | 5 |
---|
1183 | 1183 | | 6 |
---|
1184 | 1184 | | 7 |
---|
1185 | 1185 | | 8 |
---|
1186 | 1186 | | 9 |
---|
1187 | 1187 | | 10 |
---|
1188 | 1188 | | 11 |
---|
1189 | 1189 | | 12 |
---|
1190 | 1190 | | 13 |
---|
1191 | 1191 | | 14 |
---|
1192 | 1192 | | 15 |
---|
1193 | 1193 | | 16 |
---|
1194 | 1194 | | 17 |
---|
1195 | 1195 | | 18 |
---|
1196 | 1196 | | 19 |
---|
1197 | 1197 | | 20 |
---|
1198 | 1198 | | 21 |
---|
1199 | 1199 | | 22 |
---|
1200 | 1200 | | 23 |
---|
1201 | 1201 | | 24 |
---|
1202 | 1202 | | 25 |
---|
1203 | 1203 | | E. A controller shall establish, and shall describe |
---|
1204 | 1204 | | in a privacy notice, one or more secure and reliable means for |
---|
1205 | 1205 | | consumers to submit a request to exercise their consumer rights |
---|
1206 | 1206 | | under the Consumer Information and Data Protection Act. Such |
---|
1207 | 1207 | | means shall take into account the ways in which consumers |
---|
1208 | 1208 | | normally interact with the controller, the need for secure and |
---|
1209 | 1209 | | reliable communication of such requests and the ability of the |
---|
1210 | 1210 | | controller to authenticate the identity of the consumer making |
---|
1211 | 1211 | | the request. Controllers shall not require a consumer to |
---|
1212 | 1212 | | create a new account in order to exercise consumer rights |
---|
1213 | 1213 | | pursuant to Section 4 of the Consumer Information and Data |
---|
1214 | 1214 | | Protection Act but may require a consumer to use an existing |
---|
1215 | 1215 | | account. |
---|
1216 | 1216 | | F. Subject to the consent requirement established |
---|
1217 | 1217 | | by Section 4 of the Consumer Information and Data Protection |
---|
1218 | 1218 | | Act, no controller shall process any personal data collected |
---|
1219 | 1219 | | from a known child: |
---|
1220 | 1220 | | (1) for the purposes of targeted advertising, |
---|
1221 | 1221 | | the sale of such personal data or profiling in furtherance of |
---|
1222 | 1222 | | decisions that produce legal or similarly significant effects |
---|
1223 | 1223 | | concerning a consumer; |
---|
1224 | 1224 | | (2) unless such processing is reasonably |
---|
1225 | 1225 | | necessary to provide the online service, product or feature; |
---|
1226 | 1226 | | (3) for any processing purpose other than the |
---|
1227 | 1227 | | processing purpose that the controller disclosed at the time |
---|
1228 | 1228 | | .230052.1ms |
---|
1229 | 1229 | | - 23 - underscored material = new |
---|
1230 | 1230 | | [bracketed material] = delete |
---|
1231 | 1231 | | 1 |
---|
1232 | 1232 | | 2 |
---|
1233 | 1233 | | 3 |
---|
1234 | 1234 | | 4 |
---|
1235 | 1235 | | 5 |
---|
1236 | 1236 | | 6 |
---|
1237 | 1237 | | 7 |
---|
1238 | 1238 | | 8 |
---|
1239 | 1239 | | 9 |
---|
1240 | 1240 | | 10 |
---|
1241 | 1241 | | 11 |
---|
1242 | 1242 | | 12 |
---|
1243 | 1243 | | 13 |
---|
1244 | 1244 | | 14 |
---|
1245 | 1245 | | 15 |
---|
1246 | 1246 | | 16 |
---|
1247 | 1247 | | 17 |
---|
1248 | 1248 | | 18 |
---|
1249 | 1249 | | 19 |
---|
1250 | 1250 | | 20 |
---|
1251 | 1251 | | 21 |
---|
1252 | 1252 | | 22 |
---|
1253 | 1253 | | 23 |
---|
1254 | 1254 | | 24 |
---|
1255 | 1255 | | 25 |
---|
1256 | 1256 | | such controller collected such personal data or that is |
---|
1257 | 1257 | | reasonably necessary for and compatible with such disclosed |
---|
1258 | 1258 | | purpose; or |
---|
1259 | 1259 | | (4) for longer than is reasonably necessary to |
---|
1260 | 1260 | | provide the online service, product, or feature. |
---|
1261 | 1261 | | G. Subject to the consent requirement established |
---|
1262 | 1262 | | by Section 4 of the Consumer Information and Data Protection |
---|
1263 | 1263 | | Act, no controller shall collect precise geolocation data from |
---|
1264 | 1264 | | a known child unless: |
---|
1265 | 1265 | | (1) such precise geolocation data is |
---|
1266 | 1266 | | reasonably necessary for the controller to provide an online |
---|
1267 | 1267 | | service, product or feature and, if such data is necessary to |
---|
1268 | 1268 | | provide such online service, product or feature, such |
---|
1269 | 1269 | | controller shall only collect such data for the time necessary |
---|
1270 | 1270 | | to provide such online service, product or feature; and |
---|
1271 | 1271 | | (2) the controller provides to the known child |
---|
1272 | 1272 | | a signal indicating that such controller is collecting such |
---|
1273 | 1273 | | precise geolocation data, which signal shall be available to |
---|
1274 | 1274 | | such known child for the entire duration of such collection. |
---|
1275 | 1275 | | H. No controller shall engage in the activities |
---|
1276 | 1276 | | described in Subsections F and G of Section 4 of the Consumer |
---|
1277 | 1277 | | Information and Data Protection Act unless the controller |
---|
1278 | 1278 | | obtains consent from the child's parent or legal guardian in |
---|
1279 | 1279 | | accordance with the federal Children's Online Privacy |
---|
1280 | 1280 | | Protection Act of 1998 (15 U.S.C. Section 6501 et seq.). |
---|
1281 | 1281 | | .230052.1ms |
---|
1282 | 1282 | | - 24 - underscored material = new |
---|
1283 | 1283 | | [bracketed material] = delete |
---|
1284 | 1284 | | 1 |
---|
1285 | 1285 | | 2 |
---|
1286 | 1286 | | 3 |
---|
1287 | 1287 | | 4 |
---|
1288 | 1288 | | 5 |
---|
1289 | 1289 | | 6 |
---|
1290 | 1290 | | 7 |
---|
1291 | 1291 | | 8 |
---|
1292 | 1292 | | 9 |
---|
1293 | 1293 | | 10 |
---|
1294 | 1294 | | 11 |
---|
1295 | 1295 | | 12 |
---|
1296 | 1296 | | 13 |
---|
1297 | 1297 | | 14 |
---|
1298 | 1298 | | 15 |
---|
1299 | 1299 | | 16 |
---|
1300 | 1300 | | 17 |
---|
1301 | 1301 | | 18 |
---|
1302 | 1302 | | 19 |
---|
1303 | 1303 | | 20 |
---|
1304 | 1304 | | 21 |
---|
1305 | 1305 | | 22 |
---|
1306 | 1306 | | 23 |
---|
1307 | 1307 | | 24 |
---|
1308 | 1308 | | 25 |
---|
1309 | 1309 | | SECTION 6. [NEW MATERIAL] RESPONSIBILITIES OF CONTROLLER |
---|
1310 | 1310 | | AND PROCESSOR.-- |
---|
1311 | 1311 | | A. A processor shall adhere to the instructions of |
---|
1312 | 1312 | | a controller and shall assist the controller in meeting its |
---|
1313 | 1313 | | obligations under the Consumer Information and Data Protection |
---|
1314 | 1314 | | Act. Such assistance shall include: |
---|
1315 | 1315 | | (1) taking into account the nature of |
---|
1316 | 1316 | | processing and the information available to the processor, by |
---|
1317 | 1317 | | appropriate technical and organizational measures, insofar as |
---|
1318 | 1318 | | this is reasonably practicable, to fulfill the controller's |
---|
1319 | 1319 | | obligation to respond to consumer rights requests pursuant to |
---|
1320 | 1320 | | Section 4 of the Consumer Information and Data Protection Act; |
---|
1321 | 1321 | | (2) taking into account the nature of |
---|
1322 | 1322 | | processing and the information available to the processor, by |
---|
1323 | 1323 | | assisting the controller in meeting the controller's |
---|
1324 | 1324 | | obligations in relation to the security of processing the |
---|
1325 | 1325 | | personal data and in relation to the notification of a breach |
---|
1326 | 1326 | | of security of the system of the processor pursuant to the |
---|
1327 | 1327 | | Consumer Information and Data Protection Act in order to meet |
---|
1328 | 1328 | | the controller's obligations; and |
---|
1329 | 1329 | | (3) providing necessary information to enable |
---|
1330 | 1330 | | the controller to conduct and document data protection |
---|
1331 | 1331 | | assessments pursuant to the Consumer Information and Data |
---|
1332 | 1332 | | Protection Act. |
---|
1333 | 1333 | | B. A contract between a controller and a processor |
---|
1334 | 1334 | | .230052.1ms |
---|
1335 | 1335 | | - 25 - underscored material = new |
---|
1336 | 1336 | | [bracketed material] = delete |
---|
1337 | 1337 | | 1 |
---|
1338 | 1338 | | 2 |
---|
1339 | 1339 | | 3 |
---|
1340 | 1340 | | 4 |
---|
1341 | 1341 | | 5 |
---|
1342 | 1342 | | 6 |
---|
1343 | 1343 | | 7 |
---|
1344 | 1344 | | 8 |
---|
1345 | 1345 | | 9 |
---|
1346 | 1346 | | 10 |
---|
1347 | 1347 | | 11 |
---|
1348 | 1348 | | 12 |
---|
1349 | 1349 | | 13 |
---|
1350 | 1350 | | 14 |
---|
1351 | 1351 | | 15 |
---|
1352 | 1352 | | 16 |
---|
1353 | 1353 | | 17 |
---|
1354 | 1354 | | 18 |
---|
1355 | 1355 | | 19 |
---|
1356 | 1356 | | 20 |
---|
1357 | 1357 | | 21 |
---|
1358 | 1358 | | 22 |
---|
1359 | 1359 | | 23 |
---|
1360 | 1360 | | 24 |
---|
1361 | 1361 | | 25 |
---|
1362 | 1362 | | shall govern the processor's data processing procedures with |
---|
1363 | 1363 | | respect to processing performed on behalf of the controller. |
---|
1364 | 1364 | | The contract shall be binding and clearly set forth |
---|
1365 | 1365 | | instructions for processing data, the nature and purpose of |
---|
1366 | 1366 | | processing, the type of data subject to processing, the |
---|
1367 | 1367 | | duration of processing and the rights and obligations of both |
---|
1368 | 1368 | | parties. The contract shall also include requirements that the |
---|
1369 | 1369 | | processor shall: |
---|
1370 | 1370 | | (1) ensure that each person processing |
---|
1371 | 1371 | | personal data is subject to a duty of confidentiality with |
---|
1372 | 1372 | | respect to the data; |
---|
1373 | 1373 | | (2) at the controller's direction, delete or |
---|
1374 | 1374 | | return all personal data to the controller as requested at the |
---|
1375 | 1375 | | end of the provision of services, unless retention of the |
---|
1376 | 1376 | | personal data is required by law; |
---|
1377 | 1377 | | (3) upon the reasonable request of the |
---|
1378 | 1378 | | controller, make available to the controller all information in |
---|
1379 | 1379 | | its possession necessary to demonstrate the processor's |
---|
1380 | 1380 | | compliance with the obligations in the Consumer Information and |
---|
1381 | 1381 | | Data Protection Act; |
---|
1382 | 1382 | | (4) allow, and cooperate with, reasonable |
---|
1383 | 1383 | | assessments by the controller or the controller's designated |
---|
1384 | 1384 | | assessor; alternatively, the processor may arrange for a |
---|
1385 | 1385 | | qualified and independent assessor to conduct an assessment of |
---|
1386 | 1386 | | the processor's policies and technical and organizational |
---|
1387 | 1387 | | .230052.1ms |
---|
1388 | 1388 | | - 26 - underscored material = new |
---|
1389 | 1389 | | [bracketed material] = delete |
---|
1390 | 1390 | | 1 |
---|
1391 | 1391 | | 2 |
---|
1392 | 1392 | | 3 |
---|
1393 | 1393 | | 4 |
---|
1394 | 1394 | | 5 |
---|
1395 | 1395 | | 6 |
---|
1396 | 1396 | | 7 |
---|
1397 | 1397 | | 8 |
---|
1398 | 1398 | | 9 |
---|
1399 | 1399 | | 10 |
---|
1400 | 1400 | | 11 |
---|
1401 | 1401 | | 12 |
---|
1402 | 1402 | | 13 |
---|
1403 | 1403 | | 14 |
---|
1404 | 1404 | | 15 |
---|
1405 | 1405 | | 16 |
---|
1406 | 1406 | | 17 |
---|
1407 | 1407 | | 18 |
---|
1408 | 1408 | | 19 |
---|
1409 | 1409 | | 20 |
---|
1410 | 1410 | | 21 |
---|
1411 | 1411 | | 22 |
---|
1412 | 1412 | | 23 |
---|
1413 | 1413 | | 24 |
---|
1414 | 1414 | | 25 |
---|
1415 | 1415 | | measures in support of the obligations under the Consumer |
---|
1416 | 1416 | | Information and Data Protection Act using an appropriate and |
---|
1417 | 1417 | | accepted control standard or framework and assessment procedure |
---|
1418 | 1418 | | for such assessments. The processor shall provide a report of |
---|
1419 | 1419 | | such assessment to the controller upon request; and |
---|
1420 | 1420 | | (5) engage any subcontractor pursuant to a |
---|
1421 | 1421 | | written contract in accordance with this section that requires |
---|
1422 | 1422 | | the subcontractor to meet the obligations of the processor with |
---|
1423 | 1423 | | respect to the personal data. |
---|
1424 | 1424 | | C. Nothing in this section shall be construed to |
---|
1425 | 1425 | | relieve a controller or a processor from the liabilities |
---|
1426 | 1426 | | imposed on it by virtue of its role in the processing |
---|
1427 | 1427 | | relationship as defined by the Consumer Information and Data |
---|
1428 | 1428 | | Protection Act. |
---|
1429 | 1429 | | D. Determining whether a person is acting as a |
---|
1430 | 1430 | | controller or processor with respect to a specific processing |
---|
1431 | 1431 | | of data is a fact-based determination that depends upon the |
---|
1432 | 1432 | | context in which personal data is to be processed. A processor |
---|
1433 | 1433 | | that continues to adhere to a controller's instructions with |
---|
1434 | 1434 | | respect to a specific processing of personal data remains a |
---|
1435 | 1435 | | processor. |
---|
1436 | 1436 | | SECTION 7. [NEW MATERIAL] DATA PROTECTION ASSESSMENTS.-- |
---|
1437 | 1437 | | A. A controller shall conduct and document a data |
---|
1438 | 1438 | | protection assessment of each of the following processing |
---|
1439 | 1439 | | activities involving personal data: |
---|
1440 | 1440 | | .230052.1ms |
---|
1441 | 1441 | | - 27 - underscored material = new |
---|
1442 | 1442 | | [bracketed material] = delete |
---|
1443 | 1443 | | 1 |
---|
1444 | 1444 | | 2 |
---|
1445 | 1445 | | 3 |
---|
1446 | 1446 | | 4 |
---|
1447 | 1447 | | 5 |
---|
1448 | 1448 | | 6 |
---|
1449 | 1449 | | 7 |
---|
1450 | 1450 | | 8 |
---|
1451 | 1451 | | 9 |
---|
1452 | 1452 | | 10 |
---|
1453 | 1453 | | 11 |
---|
1454 | 1454 | | 12 |
---|
1455 | 1455 | | 13 |
---|
1456 | 1456 | | 14 |
---|
1457 | 1457 | | 15 |
---|
1458 | 1458 | | 16 |
---|
1459 | 1459 | | 17 |
---|
1460 | 1460 | | 18 |
---|
1461 | 1461 | | 19 |
---|
1462 | 1462 | | 20 |
---|
1463 | 1463 | | 21 |
---|
1464 | 1464 | | 22 |
---|
1465 | 1465 | | 23 |
---|
1466 | 1466 | | 24 |
---|
1467 | 1467 | | 25 |
---|
1468 | 1468 | | (1) the processing of personal data for |
---|
1469 | 1469 | | purposes of targeted advertising; |
---|
1470 | 1470 | | (2) the sale of personal data; |
---|
1471 | 1471 | | (3) the processing of personal data for |
---|
1472 | 1472 | | purposes of profiling, where such profiling presents a |
---|
1473 | 1473 | | reasonably foreseeable risk of: |
---|
1474 | 1474 | | (a) unfair or deceptive treatment of, or |
---|
1475 | 1475 | | unlawful disparate impact on, consumers; |
---|
1476 | 1476 | | (b) financial, physical or reputational |
---|
1477 | 1477 | | injury to consumers; |
---|
1478 | 1478 | | (c) a physical or other intrusion upon |
---|
1479 | 1479 | | the solitude or seclusion, or the private affairs or concerns, |
---|
1480 | 1480 | | of consumers, where such intrusion would be offensive to a |
---|
1481 | 1481 | | reasonable person; or |
---|
1482 | 1482 | | (d) other substantial injury to |
---|
1483 | 1483 | | consumers; |
---|
1484 | 1484 | | (4) the processing of sensitive data; and |
---|
1485 | 1485 | | (5) any processing activities involving |
---|
1486 | 1486 | | personal data that present a heightened risk of harm to |
---|
1487 | 1487 | | consumers. |
---|
1488 | 1488 | | B. Data protection assessments conducted pursuant |
---|
1489 | 1489 | | to Subsection A of this section shall identify and weigh the |
---|
1490 | 1490 | | benefits that may flow, directly and indirectly, from the |
---|
1491 | 1491 | | processing to the controller, the consumer, other stakeholders |
---|
1492 | 1492 | | and the public against the potential risks to the rights of the |
---|
1493 | 1493 | | .230052.1ms |
---|
1494 | 1494 | | - 28 - underscored material = new |
---|
1495 | 1495 | | [bracketed material] = delete |
---|
1496 | 1496 | | 1 |
---|
1497 | 1497 | | 2 |
---|
1498 | 1498 | | 3 |
---|
1499 | 1499 | | 4 |
---|
1500 | 1500 | | 5 |
---|
1501 | 1501 | | 6 |
---|
1502 | 1502 | | 7 |
---|
1503 | 1503 | | 8 |
---|
1504 | 1504 | | 9 |
---|
1505 | 1505 | | 10 |
---|
1506 | 1506 | | 11 |
---|
1507 | 1507 | | 12 |
---|
1508 | 1508 | | 13 |
---|
1509 | 1509 | | 14 |
---|
1510 | 1510 | | 15 |
---|
1511 | 1511 | | 16 |
---|
1512 | 1512 | | 17 |
---|
1513 | 1513 | | 18 |
---|
1514 | 1514 | | 19 |
---|
1515 | 1515 | | 20 |
---|
1516 | 1516 | | 21 |
---|
1517 | 1517 | | 22 |
---|
1518 | 1518 | | 23 |
---|
1519 | 1519 | | 24 |
---|
1520 | 1520 | | 25 |
---|
1521 | 1521 | | consumer associated with such processing, as mitigated by |
---|
1522 | 1522 | | safeguards that can be employed by the controller to reduce |
---|
1523 | 1523 | | such risks. The use of de-identified data and the reasonable |
---|
1524 | 1524 | | expectations of consumers, as well as the context of the |
---|
1525 | 1525 | | processing and the relationship between the controller and the |
---|
1526 | 1526 | | consumer whose personal data will be processed, shall be |
---|
1527 | 1527 | | factored into this assessment by the controller. |
---|
1528 | 1528 | | C. The attorney general may request, pursuant to a |
---|
1529 | 1529 | | civil investigative demand, that a controller disclose any data |
---|
1530 | 1530 | | protection assessment that is relevant to an investigation |
---|
1531 | 1531 | | conducted by the attorney general, and the controller shall |
---|
1532 | 1532 | | make the data protection assessment available to the attorney |
---|
1533 | 1533 | | general. The attorney general may evaluate the data protection |
---|
1534 | 1534 | | assessment for compliance with the responsibilities set forth |
---|
1535 | 1535 | | in Subsection A of this section. Data protection assessments |
---|
1536 | 1536 | | shall be confidential and exempt from public inspection and |
---|
1537 | 1537 | | copying under the Inspection of Public Records Act. The |
---|
1538 | 1538 | | disclosure of a data protection assessment pursuant to a |
---|
1539 | 1539 | | request from the attorney general shall not constitute a waiver |
---|
1540 | 1540 | | of attorney-client privilege or work product protection with |
---|
1541 | 1541 | | respect to the assessment and any information contained in the |
---|
1542 | 1542 | | assessment. |
---|
1543 | 1543 | | D. A single data protection assessment may address |
---|
1544 | 1544 | | a comparable set of processing operations that include similar |
---|
1545 | 1545 | | activities. |
---|
1546 | 1546 | | .230052.1ms |
---|
1547 | 1547 | | - 29 - underscored material = new |
---|
1548 | 1548 | | [bracketed material] = delete |
---|
1549 | 1549 | | 1 |
---|
1550 | 1550 | | 2 |
---|
1551 | 1551 | | 3 |
---|
1552 | 1552 | | 4 |
---|
1553 | 1553 | | 5 |
---|
1554 | 1554 | | 6 |
---|
1555 | 1555 | | 7 |
---|
1556 | 1556 | | 8 |
---|
1557 | 1557 | | 9 |
---|
1558 | 1558 | | 10 |
---|
1559 | 1559 | | 11 |
---|
1560 | 1560 | | 12 |
---|
1561 | 1561 | | 13 |
---|
1562 | 1562 | | 14 |
---|
1563 | 1563 | | 15 |
---|
1564 | 1564 | | 16 |
---|
1565 | 1565 | | 17 |
---|
1566 | 1566 | | 18 |
---|
1567 | 1567 | | 19 |
---|
1568 | 1568 | | 20 |
---|
1569 | 1569 | | 21 |
---|
1570 | 1570 | | 22 |
---|
1571 | 1571 | | 23 |
---|
1572 | 1572 | | 24 |
---|
1573 | 1573 | | 25 |
---|
1574 | 1574 | | E. Data protection assessments conducted by a |
---|
1575 | 1575 | | controller for the purpose of compliance with other laws or |
---|
1576 | 1576 | | regulations may comply under this section if the assessments |
---|
1577 | 1577 | | have a reasonably comparable scope and effect. |
---|
1578 | 1578 | | F. Data protection assessment requirements shall |
---|
1579 | 1579 | | apply to processing activities created or generated after the |
---|
1580 | 1580 | | effective date of the Consumer Information and Data Protection |
---|
1581 | 1581 | | Act and are not retroactive. |
---|
1582 | 1582 | | SECTION 8. [NEW MATERIAL] PROCESSING DE-IDENTIFIED |
---|
1583 | 1583 | | DATA.-- |
---|
1584 | 1584 | | A. The controller in possession of de-identified |
---|
1585 | 1585 | | data shall: |
---|
1586 | 1586 | | (1) take reasonable measures to ensure that |
---|
1587 | 1587 | | the data cannot be associated with a natural person; |
---|
1588 | 1588 | | (2) publicly commit to maintaining and using |
---|
1589 | 1589 | | de-identified data without attempting to re-identify the data; |
---|
1590 | 1590 | | and |
---|
1591 | 1591 | | (3) contractually obligate any recipients of |
---|
1592 | 1592 | | the de-identified data to comply with all provisions of the |
---|
1593 | 1593 | | Consumer Information and Data Protection Act. |
---|
1594 | 1594 | | B. Nothing in the Consumer Information and Data |
---|
1595 | 1595 | | Protection Act shall be construed to require a controller or |
---|
1596 | 1596 | | processor to re-identify de-identified data or pseudonymous |
---|
1597 | 1597 | | data or maintain data in identifiable form, or collect, obtain, |
---|
1598 | 1598 | | retain or access any data or technology, in order to be capable |
---|
1599 | 1599 | | .230052.1ms |
---|
1600 | 1600 | | - 30 - underscored material = new |
---|
1601 | 1601 | | [bracketed material] = delete |
---|
1602 | 1602 | | 1 |
---|
1603 | 1603 | | 2 |
---|
1604 | 1604 | | 3 |
---|
1605 | 1605 | | 4 |
---|
1606 | 1606 | | 5 |
---|
1607 | 1607 | | 6 |
---|
1608 | 1608 | | 7 |
---|
1609 | 1609 | | 8 |
---|
1610 | 1610 | | 9 |
---|
1611 | 1611 | | 10 |
---|
1612 | 1612 | | 11 |
---|
1613 | 1613 | | 12 |
---|
1614 | 1614 | | 13 |
---|
1615 | 1615 | | 14 |
---|
1616 | 1616 | | 15 |
---|
1617 | 1617 | | 16 |
---|
1618 | 1618 | | 17 |
---|
1619 | 1619 | | 18 |
---|
1620 | 1620 | | 19 |
---|
1621 | 1621 | | 20 |
---|
1622 | 1622 | | 21 |
---|
1623 | 1623 | | 22 |
---|
1624 | 1624 | | 23 |
---|
1625 | 1625 | | 24 |
---|
1626 | 1626 | | 25 |
---|
1627 | 1627 | | of associating an authenticated consumer request with personal |
---|
1628 | 1628 | | data. |
---|
1629 | 1629 | | C. Nothing in the Consumer Information and Data |
---|
1630 | 1630 | | Protection Act shall be construed to require a controller or |
---|
1631 | 1631 | | processor to comply with an authenticated consumer rights |
---|
1632 | 1632 | | request, pursuant to Section 4 of the Consumer Information and |
---|
1633 | 1633 | | Data Protection Act, if all of the following are true: |
---|
1634 | 1634 | | (1) the controller is not reasonably capable |
---|
1635 | 1635 | | of associating the request with the personal data or it would |
---|
1636 | 1636 | | be unreasonably burdensome for the controller to associate the |
---|
1637 | 1637 | | request with the personal data; |
---|
1638 | 1638 | | (2) the controller does not use the personal |
---|
1639 | 1639 | | data to recognize or respond to the specific consumer who is |
---|
1640 | 1640 | | the subject of the personal data or associate the personal data |
---|
1641 | 1641 | | with other personal data about the same specific consumer; and |
---|
1642 | 1642 | | (3) the controller does not sell the personal |
---|
1643 | 1643 | | data to any third party or otherwise voluntarily disclose the |
---|
1644 | 1644 | | personal data to any third party other than a processor, except |
---|
1645 | 1645 | | as otherwise permitted in this section. |
---|
1646 | 1646 | | D. The consumer rights contained in Section 4 of |
---|
1647 | 1647 | | the Consumer Information and Data Protection Act shall not |
---|
1648 | 1648 | | apply to pseudonymous data in cases where the controller is |
---|
1649 | 1649 | | able to demonstrate any information necessary to identify the |
---|
1650 | 1650 | | consumer is kept separately and is subject to effective |
---|
1651 | 1651 | | technical and organizational controls that prevent the |
---|
1652 | 1652 | | .230052.1ms |
---|
1653 | 1653 | | - 31 - underscored material = new |
---|
1654 | 1654 | | [bracketed material] = delete |
---|
1655 | 1655 | | 1 |
---|
1656 | 1656 | | 2 |
---|
1657 | 1657 | | 3 |
---|
1658 | 1658 | | 4 |
---|
1659 | 1659 | | 5 |
---|
1660 | 1660 | | 6 |
---|
1661 | 1661 | | 7 |
---|
1662 | 1662 | | 8 |
---|
1663 | 1663 | | 9 |
---|
1664 | 1664 | | 10 |
---|
1665 | 1665 | | 11 |
---|
1666 | 1666 | | 12 |
---|
1667 | 1667 | | 13 |
---|
1668 | 1668 | | 14 |
---|
1669 | 1669 | | 15 |
---|
1670 | 1670 | | 16 |
---|
1671 | 1671 | | 17 |
---|
1672 | 1672 | | 18 |
---|
1673 | 1673 | | 19 |
---|
1674 | 1674 | | 20 |
---|
1675 | 1675 | | 21 |
---|
1676 | 1676 | | 22 |
---|
1677 | 1677 | | 23 |
---|
1678 | 1678 | | 24 |
---|
1679 | 1679 | | 25 |
---|
1680 | 1680 | | controller from accessing such information. |
---|
1681 | 1681 | | E. A controller that discloses pseudonymous data or |
---|
1682 | 1682 | | de-identified data shall exercise reasonable oversight to |
---|
1683 | 1683 | | monitor compliance with any contractual commitments to which |
---|
1684 | 1684 | | the pseudonymous data or de-identified data is subject and |
---|
1685 | 1685 | | shall take appropriate steps to address any breaches of those |
---|
1686 | 1686 | | contractual commitments. |
---|
1687 | 1687 | | SECTION 9. [NEW MATERIAL] LIMITATIONS.-- |
---|
1688 | 1688 | | A. Nothing in the Consumer Information and Data |
---|
1689 | 1689 | | Protection Act shall be construed to restrict a controller's or |
---|
1690 | 1690 | | processor's ability to: |
---|
1691 | 1691 | | (1) comply with federal, state or local laws, |
---|
1692 | 1692 | | rules or regulations; |
---|
1693 | 1693 | | (2) comply with a civil, criminal or |
---|
1694 | 1694 | | regulatory inquiry, investigation, subpoena or summons by |
---|
1695 | 1695 | | federal, state, local or other governmental authorities; |
---|
1696 | 1696 | | (3) cooperate with law enforcement agencies |
---|
1697 | 1697 | | concerning conduct or activity that the controller or processor |
---|
1698 | 1698 | | reasonably and in good faith believes may violate federal, |
---|
1699 | 1699 | | state or local laws, rules or regulations; |
---|
1700 | 1700 | | (4) investigate, establish, exercise, prepare |
---|
1701 | 1701 | | for or defend legal claims; |
---|
1702 | 1702 | | (5) provide a product or service specifically |
---|
1703 | 1703 | | requested by a consumer, perform a contract to which the |
---|
1704 | 1704 | | consumer is a party, including fulfilling the terms of a |
---|
1705 | 1705 | | .230052.1ms |
---|
1706 | 1706 | | - 32 - underscored material = new |
---|
1707 | 1707 | | [bracketed material] = delete |
---|
1708 | 1708 | | 1 |
---|
1709 | 1709 | | 2 |
---|
1710 | 1710 | | 3 |
---|
1711 | 1711 | | 4 |
---|
1712 | 1712 | | 5 |
---|
1713 | 1713 | | 6 |
---|
1714 | 1714 | | 7 |
---|
1715 | 1715 | | 8 |
---|
1716 | 1716 | | 9 |
---|
1717 | 1717 | | 10 |
---|
1718 | 1718 | | 11 |
---|
1719 | 1719 | | 12 |
---|
1720 | 1720 | | 13 |
---|
1721 | 1721 | | 14 |
---|
1722 | 1722 | | 15 |
---|
1723 | 1723 | | 16 |
---|
1724 | 1724 | | 17 |
---|
1725 | 1725 | | 18 |
---|
1726 | 1726 | | 19 |
---|
1727 | 1727 | | 20 |
---|
1728 | 1728 | | 21 |
---|
1729 | 1729 | | 22 |
---|
1730 | 1730 | | 23 |
---|
1731 | 1731 | | 24 |
---|
1732 | 1732 | | 25 |
---|
1733 | 1733 | | written warranty, or take steps at the request of the consumer |
---|
1734 | 1734 | | prior to entering into a contract; |
---|
1735 | 1735 | | (6) take immediate steps to protect an |
---|
1736 | 1736 | | interest that is essential for the life or physical safety of |
---|
1737 | 1737 | | the consumer or of another natural person and where the |
---|
1738 | 1738 | | processing cannot be manifestly based on another legal basis; |
---|
1739 | 1739 | | (7) prevent, detect, protect against or |
---|
1740 | 1740 | | respond to security incidents, identity theft, fraud, |
---|
1741 | 1741 | | harassment, malicious or deceptive activities or any illegal |
---|
1742 | 1742 | | activity; preserve the integrity or security of systems; or |
---|
1743 | 1743 | | investigate, report or prosecute those responsible for any such |
---|
1744 | 1744 | | action; |
---|
1745 | 1745 | | (8) engage in public or peer-reviewed |
---|
1746 | 1746 | | scientific or statistical research in the public interest that |
---|
1747 | 1747 | | adheres to all other applicable ethics and privacy laws and is |
---|
1748 | 1748 | | approved, monitored and governed by an institutional review |
---|
1749 | 1749 | | board or similar independent oversight entities that determine: |
---|
1750 | 1750 | | (a) if the deletion of the information |
---|
1751 | 1751 | | is likely to provide substantial benefits that do not |
---|
1752 | 1752 | | exclusively accrue to the controller; |
---|
1753 | 1753 | | (b) the expected benefits of the |
---|
1754 | 1754 | | research outweigh the privacy risks; and |
---|
1755 | 1755 | | (c) if the controller has implemented |
---|
1756 | 1756 | | reasonable safeguards to mitigate privacy risks associated with |
---|
1757 | 1757 | | research, including any risks associated with re- |
---|
1758 | 1758 | | .230052.1ms |
---|
1759 | 1759 | | - 33 - underscored material = new |
---|
1760 | 1760 | | [bracketed material] = delete |
---|
1761 | 1761 | | 1 |
---|
1762 | 1762 | | 2 |
---|
1763 | 1763 | | 3 |
---|
1764 | 1764 | | 4 |
---|
1765 | 1765 | | 5 |
---|
1766 | 1766 | | 6 |
---|
1767 | 1767 | | 7 |
---|
1768 | 1768 | | 8 |
---|
1769 | 1769 | | 9 |
---|
1770 | 1770 | | 10 |
---|
1771 | 1771 | | 11 |
---|
1772 | 1772 | | 12 |
---|
1773 | 1773 | | 13 |
---|
1774 | 1774 | | 14 |
---|
1775 | 1775 | | 15 |
---|
1776 | 1776 | | 16 |
---|
1777 | 1777 | | 17 |
---|
1778 | 1778 | | 18 |
---|
1779 | 1779 | | 19 |
---|
1780 | 1780 | | 20 |
---|
1781 | 1781 | | 21 |
---|
1782 | 1782 | | 22 |
---|
1783 | 1783 | | 23 |
---|
1784 | 1784 | | 24 |
---|
1785 | 1785 | | 25 |
---|
1786 | 1786 | | identification; or |
---|
1787 | 1787 | | (9) assist another controller, processor or |
---|
1788 | 1788 | | third party with any of the obligations under this subsection. |
---|
1789 | 1789 | | B. The obligations imposed on controllers or |
---|
1790 | 1790 | | processors under the Consumer Information and Data Protection |
---|
1791 | 1791 | | Act shall not restrict a controller's or processor's ability to |
---|
1792 | 1792 | | collect, use or retain data to: |
---|
1793 | 1793 | | (1) conduct internal research to develop, |
---|
1794 | 1794 | | improve or repair products, services or technology; |
---|
1795 | 1795 | | (2) effectuate a product recall; |
---|
1796 | 1796 | | (3) identify and repair technical errors that |
---|
1797 | 1797 | | impair existing or intended functionality; or |
---|
1798 | 1798 | | (4) perform internal operations that are |
---|
1799 | 1799 | | reasonably aligned with the expectations of the consumer or |
---|
1800 | 1800 | | reasonably anticipated based on the consumer's existing |
---|
1801 | 1801 | | relationship with the controller or are otherwise compatible |
---|
1802 | 1802 | | with processing data in furtherance of the provision of a |
---|
1803 | 1803 | | product or service specifically requested by a consumer or the |
---|
1804 | 1804 | | performance of a contract to which the consumer is a party. |
---|
1805 | 1805 | | C. The obligations imposed on controllers or |
---|
1806 | 1806 | | processors under the Consumer Information and Data Protection |
---|
1807 | 1807 | | Act shall not apply where compliance by the controller or |
---|
1808 | 1808 | | processor with that act would violate an evidentiary privilege |
---|
1809 | 1809 | | under the laws of the state. Nothing in that act shall be |
---|
1810 | 1810 | | construed to prevent a controller or processor from providing |
---|
1811 | 1811 | | .230052.1ms |
---|
1812 | 1812 | | - 34 - underscored material = new |
---|
1813 | 1813 | | [bracketed material] = delete |
---|
1814 | 1814 | | 1 |
---|
1815 | 1815 | | 2 |
---|
1816 | 1816 | | 3 |
---|
1817 | 1817 | | 4 |
---|
1818 | 1818 | | 5 |
---|
1819 | 1819 | | 6 |
---|
1820 | 1820 | | 7 |
---|
1821 | 1821 | | 8 |
---|
1822 | 1822 | | 9 |
---|
1823 | 1823 | | 10 |
---|
1824 | 1824 | | 11 |
---|
1825 | 1825 | | 12 |
---|
1826 | 1826 | | 13 |
---|
1827 | 1827 | | 14 |
---|
1828 | 1828 | | 15 |
---|
1829 | 1829 | | 16 |
---|
1830 | 1830 | | 17 |
---|
1831 | 1831 | | 18 |
---|
1832 | 1832 | | 19 |
---|
1833 | 1833 | | 20 |
---|
1834 | 1834 | | 21 |
---|
1835 | 1835 | | 22 |
---|
1836 | 1836 | | 23 |
---|
1837 | 1837 | | 24 |
---|
1838 | 1838 | | 25 |
---|
1839 | 1839 | | personal data concerning a consumer to a person covered by an |
---|
1840 | 1840 | | evidentiary privilege under the laws of the state as part of a |
---|
1841 | 1841 | | privileged communication. |
---|
1842 | 1842 | | D. A controller or processor that discloses |
---|
1843 | 1843 | | personal data to a third-party controller or processor, in |
---|
1844 | 1844 | | compliance with the requirements of the Consumer Information |
---|
1845 | 1845 | | and Data Protection Act, is not in violation of that act if the |
---|
1846 | 1846 | | third-party controller or processor that receives and processes |
---|
1847 | 1847 | | such personal data is in violation of that act; provided that, |
---|
1848 | 1848 | | at the time of disclosing the personal data, the disclosing |
---|
1849 | 1849 | | controller or processor did not have actual knowledge that the |
---|
1850 | 1850 | | recipient intended to commit a violation. A third-party |
---|
1851 | 1851 | | controller or processor receiving personal data from a |
---|
1852 | 1852 | | controller or processor in compliance with the requirements of |
---|
1853 | 1853 | | that act is likewise not in violation of that act for the |
---|
1854 | 1854 | | transgressions of the controller or processor from which it |
---|
1855 | 1855 | | receives such personal data. |
---|
1856 | 1856 | | E. Nothing in the Consumer Information and Data |
---|
1857 | 1857 | | Protection Act shall be construed as an obligation imposed on |
---|
1858 | 1858 | | controllers and processors that adversely affects the rights or |
---|
1859 | 1859 | | freedoms of any persons, such as exercising the right of free |
---|
1860 | 1860 | | speech pursuant to the first amendment to the United States |
---|
1861 | 1861 | | constitution, or applies to the processing of personal data by |
---|
1862 | 1862 | | a person in the course of a purely personal or household |
---|
1863 | 1863 | | activity. |
---|
1864 | 1864 | | .230052.1ms |
---|
1865 | 1865 | | - 35 - underscored material = new |
---|
1866 | 1866 | | [bracketed material] = delete |
---|
1867 | 1867 | | 1 |
---|
1868 | 1868 | | 2 |
---|
1869 | 1869 | | 3 |
---|
1870 | 1870 | | 4 |
---|
1871 | 1871 | | 5 |
---|
1872 | 1872 | | 6 |
---|
1873 | 1873 | | 7 |
---|
1874 | 1874 | | 8 |
---|
1875 | 1875 | | 9 |
---|
1876 | 1876 | | 10 |
---|
1877 | 1877 | | 11 |
---|
1878 | 1878 | | 12 |
---|
1879 | 1879 | | 13 |
---|
1880 | 1880 | | 14 |
---|
1881 | 1881 | | 15 |
---|
1882 | 1882 | | 16 |
---|
1883 | 1883 | | 17 |
---|
1884 | 1884 | | 18 |
---|
1885 | 1885 | | 19 |
---|
1886 | 1886 | | 20 |
---|
1887 | 1887 | | 21 |
---|
1888 | 1888 | | 22 |
---|
1889 | 1889 | | 23 |
---|
1890 | 1890 | | 24 |
---|
1891 | 1891 | | 25 |
---|
1892 | 1892 | | F. Personal data processed by a controller pursuant |
---|
1893 | 1893 | | to this section shall not be processed for any purpose other |
---|
1894 | 1894 | | than those expressly listed in this section unless otherwise |
---|
1895 | 1895 | | allowed by the Consumer Information and Data Protection Act. |
---|
1896 | 1896 | | Personal data processed by a controller pursuant to this |
---|
1897 | 1897 | | section may be processed to the extent that such processing is: |
---|
1898 | 1898 | | (1) reasonably necessary and proportionate to |
---|
1899 | 1899 | | the purposes listed in this section; and |
---|
1900 | 1900 | | (2) adequate, relevant and limited to what is |
---|
1901 | 1901 | | necessary in relation to the specific purposes listed in this |
---|
1902 | 1902 | | section. Personal data collected, used or retained pursuant to |
---|
1903 | 1903 | | Subsection B of this section shall, where applicable, take into |
---|
1904 | 1904 | | account the nature and purpose or purposes of such collection, |
---|
1905 | 1905 | | use or retention. Such data shall be subject to reasonable |
---|
1906 | 1906 | | administrative, technical and physical measures to protect the |
---|
1907 | 1907 | | confidentiality, integrity and accessibility of the personal |
---|
1908 | 1908 | | data and to reduce reasonably foreseeable risks of harm to |
---|
1909 | 1909 | | consumers relating to such collection, use or retention of |
---|
1910 | 1910 | | personal data. |
---|
1911 | 1911 | | G. If a controller processes personal data pursuant |
---|
1912 | 1912 | | to an exemption in this section, the controller bears the |
---|
1913 | 1913 | | burden of demonstrating that such processing qualifies for the |
---|
1914 | 1914 | | exemption and complies with the requirements in Subsection F of |
---|
1915 | 1915 | | this section. |
---|
1916 | 1916 | | H. Processing personal data for the purposes |
---|
1917 | 1917 | | .230052.1ms |
---|
1918 | 1918 | | - 36 - underscored material = new |
---|
1919 | 1919 | | [bracketed material] = delete |
---|
1920 | 1920 | | 1 |
---|
1921 | 1921 | | 2 |
---|
1922 | 1922 | | 3 |
---|
1923 | 1923 | | 4 |
---|
1924 | 1924 | | 5 |
---|
1925 | 1925 | | 6 |
---|
1926 | 1926 | | 7 |
---|
1927 | 1927 | | 8 |
---|
1928 | 1928 | | 9 |
---|
1929 | 1929 | | 10 |
---|
1930 | 1930 | | 11 |
---|
1931 | 1931 | | 12 |
---|
1932 | 1932 | | 13 |
---|
1933 | 1933 | | 14 |
---|
1934 | 1934 | | 15 |
---|
1935 | 1935 | | 16 |
---|
1936 | 1936 | | 17 |
---|
1937 | 1937 | | 18 |
---|
1938 | 1938 | | 19 |
---|
1939 | 1939 | | 20 |
---|
1940 | 1940 | | 21 |
---|
1941 | 1941 | | 22 |
---|
1942 | 1942 | | 23 |
---|
1943 | 1943 | | 24 |
---|
1944 | 1944 | | 25 |
---|
1945 | 1945 | | expressly identified in Subsection A of this section shall not |
---|
1946 | 1946 | | solely make an entity a controller with respect to such |
---|
1947 | 1947 | | processing. |
---|
1948 | 1948 | | SECTION 10. [NEW MATERIAL] INVESTIGATIVE AUTHORITY.-- |
---|
1949 | 1949 | | Whenever the attorney general has reasonable cause to believe |
---|
1950 | 1950 | | that any person has engaged in, is engaging in or is about to |
---|
1951 | 1951 | | engage in any violation of the Consumer Information and Data |
---|
1952 | 1952 | | Protection Act, the attorney general is empowered to issue a |
---|
1953 | 1953 | | civil investigative demand. |
---|
1954 | 1954 | | SECTION 11. [NEW MATERIAL] ENFORCEMENT--CIVIL |
---|
1955 | 1955 | | PENALTIES.-- |
---|
1956 | 1956 | | A. The attorney general shall have exclusive |
---|
1957 | 1957 | | authority to enforce the provisions of the Consumer Information |
---|
1958 | 1958 | | and Data Protection Act. |
---|
1959 | 1959 | | B. Prior to initiating any action under the |
---|
1960 | 1960 | | Consumer Information and Data Protection Act, the attorney |
---|
1961 | 1961 | | general shall provide a controller or processor thirty days' |
---|
1962 | 1962 | | written notice identifying the specific provisions of the |
---|
1963 | 1963 | | Consumer Information and Data Protection Act the attorney |
---|
1964 | 1964 | | general alleges have been or are being violated. If within the |
---|
1965 | 1965 | | thirty-day period the controller or processor cures the noticed |
---|
1966 | 1966 | | violation and provides the attorney general an express written |
---|
1967 | 1967 | | statement that the alleged violations have been cured and that |
---|
1968 | 1968 | | no further violations shall occur, no action shall be initiated |
---|
1969 | 1969 | | against the controller or processor. |
---|
1970 | 1970 | | .230052.1ms |
---|
1971 | 1971 | | - 37 - underscored material = new |
---|
1972 | 1972 | | [bracketed material] = delete |
---|
1973 | 1973 | | 1 |
---|
1974 | 1974 | | 2 |
---|
1975 | 1975 | | 3 |
---|
1976 | 1976 | | 4 |
---|
1977 | 1977 | | 5 |
---|
1978 | 1978 | | 6 |
---|
1979 | 1979 | | 7 |
---|
1980 | 1980 | | 8 |
---|
1981 | 1981 | | 9 |
---|
1982 | 1982 | | 10 |
---|
1983 | 1983 | | 11 |
---|
1984 | 1984 | | 12 |
---|
1985 | 1985 | | 13 |
---|
1986 | 1986 | | 14 |
---|
1987 | 1987 | | 15 |
---|
1988 | 1988 | | 16 |
---|
1989 | 1989 | | 17 |
---|
1990 | 1990 | | 18 |
---|
1991 | 1991 | | 19 |
---|
1992 | 1992 | | 20 |
---|
1993 | 1993 | | 21 |
---|
1994 | 1994 | | 22 |
---|
1995 | 1995 | | 23 |
---|
1996 | 1996 | | 24 |
---|
1997 | 1997 | | 25 |
---|
1998 | 1998 | | C. If a controller or processor continues to |
---|
1999 | 1999 | | violate the Consumer Information and Data Protection Act |
---|
2000 | 2000 | | following the cure period in Subsection B of this section or |
---|
2001 | 2001 | | breaches an express written statement provided to the attorney |
---|
2002 | 2002 | | general under that subsection, the attorney general may |
---|
2003 | 2003 | | initiate an action and may seek an injunction to restrain any |
---|
2004 | 2004 | | violations of that act and civil penalties of up to ten |
---|
2005 | 2005 | | thousand dollars ($10,000) for each violation under that act. |
---|
2006 | 2006 | | D. The attorney general may recover reasonable |
---|
2007 | 2007 | | expenses incurred in investigating and preparing the case, |
---|
2008 | 2008 | | including attorney fees, in any action initiated under the |
---|
2009 | 2009 | | Consumer Information and Data Protection Act. |
---|
2010 | 2010 | | E. Nothing in the Consumer Information and Data |
---|
2011 | 2011 | | Protection Act shall be construed as providing the basis for, |
---|
2012 | 2012 | | or be subject to, a private right of action for violations of |
---|
2013 | 2013 | | that act or under any other law. |
---|
2014 | 2014 | | - 38 - |
---|
2015 | 2015 | | .230052.1ms |
---|