New Mexico 2025 Regular Session

New Mexico Senate Bill SB420 Compare Versions

Only one version of the bill is available at this time.
OldNewDifferences
11 underscored material = new
22 [bracketed material] = delete
33 1
44 2
55 3
66 4
77 5
88 6
99 7
1010 8
1111 9
1212 10
1313 11
1414 12
1515 13
1616 14
1717 15
1818 16
1919 17
2020 18
2121 19
2222 20
2323 21
2424 22
2525 23
2626 24
2727 25
2828 SENATE BILL 420
2929 57
3030 TH LEGISLATURE
3131 -
3232
3333 STATE
3434
3535 OF
3636
3737 NEW
3838
3939 MEXICO
4040
4141 -
4242 FIRST SESSION
4343 ,
4444
4545 2025
4646 INTRODUCED BY
4747 Katy M. Duhigg and Angel M. Charley
4848 AN ACT
4949 RELATING TO INTERNET SERVICES; ENACTING THE COMMUNITY PRIVACY
5050 AND SAFETY ACT; ESTABLISHING REQUIREMENTS FOR SERVICE
5151 PROVIDERS; PROHIBITING CERTAIN USES OF CONSUMER DATA; PROVIDING
5252 RIGHTS TO CONSUMERS; ESTABLISHING LIMITATIONS ON PROCESSING OF
5353 CONSUMER DATA; PROHIBITING WAIVERS OF RIGHTS AND RETALIATORY
5454 DENIALS OF SERVICE; PROVIDING FOR INJUNCTIVE RELIEF AND CIVIL
5555 PENALTIES; PROVIDING FOR RULEMAKING.
5656 BE IT ENACTED BY THE LEGISLATURE OF THE STATE OF NEW MEXICO:
5757 SECTION 1. [NEW MATERIAL] SHORT TITLE.--This act may be
5858 cited as the "Community Privacy and Safety Act".
5959 SECTION 2. [NEW MATERIAL] DEFINITIONS.--As used in the
6060 Community Privacy and Safety Act:
6161 A. "actual knowledge" means a covered entity knows
6262 that a consumer is a minor based upon:
6363 .230898.1 underscored material = new
6464 [bracketed material] = delete
6565 1
6666 2
6767 3
6868 4
6969 5
7070 6
7171 7
7272 8
7373 9
7474 10
7575 11
7676 12
7777 13
7878 14
7979 15
8080 16
8181 17
8282 18
8383 19
8484 20
8585 21
8686 22
8787 23
8888 24
8989 25
9090 (1) the self-identified age provided by the
9191 minor, an age provided by a third party or an age or closely
9292 related proxy that the covered entity knows or has associated
9393 with, attributed to or derived or inferred for the consumer,
9494 including for the purposes of advertising, marketing or product
9595 development; or
9696 (2) the consumer's use of an online feature,
9797 product or service or a portion of such an online feature,
9898 product or service that is directed to children;
9999 B. "affiliate" means a legal entity that controls,
100100 is controlled by or is under common control with another legal
101101 entity;
102102 C. "biometric data" means the data about a consumer
103103 generated by measurements of the consumer's unique biological
104104 characteristics, such as a faceprint, a fingerprint, a
105105 voiceprint, a retina or an iris image or other biological
106106 characteristic, that can be used to uniquely identify the
107107 consumer. "Biometric data" does not include:
108108 (1) demographic data;
109109 (2) a donated portion of a human body stored
110110 on behalf of a potential recipient of a living cadaveric
111111 transplant and obtained or stored by a federally designated
112112 organ procurement agency, including an artery, a bone, an eye,
113113 an organ or tissue or blood or other fluid or serum;
114114 (3) a human biological sample used for valid
115115 .230898.1
116116 - 2 - underscored material = new
117117 [bracketed material] = delete
118118 1
119119 2
120120 3
121121 4
122122 5
123123 6
124124 7
125125 8
126126 9
127127 10
128128 11
129129 12
130130 13
131131 14
132132 15
133133 16
134134 17
135135 18
136136 19
137137 20
138138 21
139139 22
140140 23
141141 24
142142 25
143143 scientific testing or screening;
144144 (4) an image or film of the human anatomy used
145145 to diagnose, provide a prognosis for or treat an illness or
146146 other medical condition or to further validate scientific
147147 testing or screening, including an x-ray, a roentgen process,
148148 computed tomography, a magnetic resonance imaging image, a
149149 positron emission tomography scan or mammography;
150150 (5) information collected, used or stored for
151151 health care treatment, payment or operations pursuant to
152152 federal law governing health insurance;
153153 (6) information collected, used or disclosed
154154 for human subject research that is conducted in accordance with
155155 the federal policy for the protection of human research ethics
156156 laws or with internationally accepted clinical practice
157157 guidelines as determined by the state department of justice by
158158 rule;
159159 (7) a photograph or video, except "biometric
160160 data" includes data generated, captured or collected from the
161161 biological characteristics of a consumer;
162162 (8) a physical description, including height,
163163 weight, hair color, eye color or a tattoo description; or
164164 (9) a writing sample or written signature;
165165 D. "brokerage of personal data" means the exchange
166166 of personal data for monetary or other valuable consideration
167167 by a covered entity to a third party, but does not include:
168168 .230898.1
169169 - 3 - underscored material = new
170170 [bracketed material] = delete
171171 1
172172 2
173173 3
174174 4
175175 5
176176 6
177177 7
178178 8
179179 9
180180 10
181181 11
182182 12
183183 13
184184 14
185185 15
186186 16
187187 17
188188 18
189189 19
190190 20
191191 21
192192 22
193193 23
194194 24
195195 25
196196 (1) the disclosure of personal data to a
197197 service provider that processes the personal data on behalf of
198198 the covered entity;
199199 (2) the disclosure of personal data to a third
200200 party for purposes of providing an online feature, product or
201201 service requested by a consumer;
202202 (3) the disclosure or transfer of personal
203203 data to an affiliate of the covered entity;
204204 (4) with the consumer's affirmative consent,
205205 the disclosure of personal data where the consumer directs the
206206 covered entity to disclose the personal data or intentionally
207207 uses the covered entity to interact with a third party; or
208208 (5) the disclosure of publicly available
209209 information;
210210 E. "collect" means accessing, acquiring or
211211 gathering personal data;
212212 F. "consumer" means a natural person who resides or
213213 is present in New Mexico, including those identified by a
214214 unique identifier;
215215 G. "contextual advertising" means displaying or
216216 presenting an advertisement that does not vary based on the
217217 identity of the recipient and is based solely on:
218218 (1) the immediate content of a web page or an
219219 online feature, product or service within which the
220220 advertisement appears;
221221 .230898.1
222222 - 4 - underscored material = new
223223 [bracketed material] = delete
224224 1
225225 2
226226 3
227227 4
228228 5
229229 6
230230 7
231231 8
232232 9
233233 10
234234 11
235235 12
236236 13
237237 14
238238 15
239239 16
240240 17
241241 18
242242 19
243243 20
244244 21
245245 22
246246 23
247247 24
248248 25
249249 (2) a specific request of a consumer for
250250 information or feedback if displayed in proximity to the
251251 results of such request for information; or
252252 (3) a consumer's association with a geographic
253253 area that is equal to or greater than the area of a circle with
254254 a radius of ten miles;
255255 H. "control" or "controlled" means:
256256 (1) ownership of or the power to vote more
257257 than fifty percent of the outstanding shares of a class of
258258 voting security of a covered entity;
259259 (2) control over the election of a majority of
260260 the directors or of individuals exercising similar functions of
261261 a covered entity; or
262262 (3) the power to exercise a controlling
263263 influence over the management of a covered entity;
264264 I. "covered entity" means a sole proprietorship,
265265 partnership, limited liability company, corporation,
266266 association, affiliate or other legal entity that:
267267 (1) is organized or operated for the profit or
268268 financial benefit of the entity's shareholders or other owners;
269269 (2) offers online features, products or
270270 services to consumers in New Mexico; and
271271 (3) alone or jointly with others, determines
272272 the purposes and means of:
273273 (a) collecting personal data directly
274274 .230898.1
275275 - 5 - underscored material = new
276276 [bracketed material] = delete
277277 1
278278 2
279279 3
280280 4
281281 5
282282 6
283283 7
284284 8
285285 9
286286 10
287287 11
288288 12
289289 13
290290 14
291291 15
292292 16
293293 17
294294 18
295295 19
296296 20
297297 21
298298 22
299299 23
300300 24
301301 25
302302 from consumers;
303303 (b) using personal data for targeted
304304 advertising; or
305305 (c) engaging in the brokerage of
306306 personal data;
307307 J. "dark pattern" means a user interface designed
308308 or manipulated with the purpose of subverting or impairing user
309309 autonomy, decision making or choice;
310310 K. "default" means a preselected option adopted by
311311 a covered entity for an online feature, product or service;
312312 L. "de-identified data" means data that does not
313313 identify and cannot be used to infer information about, or
314314 otherwise be linked to, an identified or identifiable consumer
315315 or a device linked to the consumer of the covered entity that
316316 possesses the data that:
317317 (1) takes reasonable physical, administrative
318318 and technical measures to ensure that the data cannot be
319319 associated with a consumer or be used to identify a consumer or
320320 a device that identifies or is linked or reasonably linkable to
321321 a consumer;
322322 (2) publicly commits to process the data only
323323 in a de-identified fashion; and
324324 (3) contractually obligates a recipient of the
325325 data to satisfy the requirements established pursuant to this
326326 subsection;
327327 .230898.1
328328 - 6 - underscored material = new
329329 [bracketed material] = delete
330330 1
331331 2
332332 3
333333 4
334334 5
335335 6
336336 7
337337 8
338338 9
339339 10
340340 11
341341 12
342342 13
343343 14
344344 15
345345 16
346346 17
347347 18
348348 19
349349 20
350350 21
351351 22
352352 23
353353 24
354354 25
355355 M. "derived data" means data that is created by the
356356 derivation of assumptions, conclusions, correlations, evidence,
357357 data, inferences or predictions about a consumer or a
358358 consumer's device from facts, evidence or other sources of
359359 information;
360360 N. "expressly provided personal data":
361361 (1) means personal data provided by a consumer
362362 to a covered entity expressly for purposes of a profile-based
363363 feed to determine the order, relative prioritization, relative
364364 prominence or selection of information that is furnished to the
365365 consumer by the covered entity through an online product,
366366 service or feature and includes:
367367 (a) consumer-supplied filters, current
368368 precise geolocation information supplied by the consumer,
369369 resumption of a previous search, saved preferences and speech
370370 patterns provided by the consumer for the purpose of enabling
371371 the online product, service or feature to accept spoken input
372372 or selecting the language in which the consumer interacts with
373373 the online product, service or feature; and
374374 (b) data submitted to a covered entity
375375 by the consumer in order to receive particular information,
376376 such as the social media profiles followed by the consumer,
377377 video channels subscribed to by the consumer or other content
378378 or sources of content on the online feature, product or service
379379 the consumer has selected; and
380380 .230898.1
381381 - 7 - underscored material = new
382382 [bracketed material] = delete
383383 1
384384 2
385385 3
386386 4
387387 5
388388 6
389389 7
390390 8
391391 9
392392 10
393393 11
394394 12
395395 13
396396 14
397397 15
398398 16
399399 17
400400 18
401401 19
402402 20
403403 21
404404 22
405405 23
406406 24
407407 25
408408 (2) does not include:
409409 (a) the history of a consumer's
410410 connected device of browsing, device inactions, financial
411411 transactions, geographical locations, physical activity or web
412412 searches; or
413413 (b) inferences about the consumer or the
414414 consumer's connected device, including inferences based on data
415415 described in Paragraph (1) of this subsection;
416416 O. "first party" means a consumer-facing covered
417417 entity with which the consumer intends or expects to interact;
418418 P. "first-party advertising" means advertising or
419419 marketing by a first party using first-party data and not other
420420 forms of personal data and carried out:
421421 (1) through direct communications with the
422422 consumer, such as direct mail, email or text message
423423 communications;
424424 (2) in a physical location operated by the
425425 first party; or
426426 (3) through display or presentation of an
427427 advertisement on the first party's own website, application or
428428 other online content that promotes that first party's product
429429 or service;
430430 Q. "first-party data" means personal data collected
431431 directly about a consumer by a first party, including data
432432 collected during a consumer visit or use of a website, a
433433 .230898.1
434434 - 8 - underscored material = new
435435 [bracketed material] = delete
436436 1
437437 2
438438 3
439439 4
440440 5
441441 6
442442 7
443443 8
444444 9
445445 10
446446 11
447447 12
448448 13
449449 14
450450 15
451451 16
452452 17
453453 18
454454 19
455455 20
456456 21
457457 22
458458 23
459459 24
460460 25
461461 physical location or an online feature, product or service
462462 operated by the first party;
463463 R. "minor" means a consumer who is under eighteen
464464 years of age;
465465 S. "personal data" means information, including
466466 derived data, that is linked or reasonably linkable, alone or
467467 in combination with other information, to an identified or
468468 identifiable consumer. "Personal data" does not include de-
469469 identified information or publicly available information;
470470 T. "precise geolocation" means data that is derived
471471 from a device and that is used or intended to be used to reveal
472472 the present or past geographical location of a consumer or a
473473 consumer's device within a geographic area that is equal to or
474474 smaller than the area of a circle with a radius of two thousand
475475 feet;
476476 U. "privacy-protective feed" means an algorithmic
477477 ranking system that does not use the personal data of a
478478 consumer to determine the order, relative prominence, relative
479479 prioritization or selection of information that is furnished to
480480 the consumer on an online feature, product or service except
481481 for expressly provided personal data;
482482 V. "profile-based feed" means an algorithmic
483483 ranking system that determines the order, relative prominence,
484484 relative prioritization or selection of information that is
485485 furnished to a consumer on an online feature, product or
486486 .230898.1
487487 - 9 - underscored material = new
488488 [bracketed material] = delete
489489 1
490490 2
491491 3
492492 4
493493 5
494494 6
495495 7
496496 8
497497 9
498498 10
499499 11
500500 12
501501 13
502502 14
503503 15
504504 16
505505 17
506506 18
507507 19
508508 20
509509 21
510510 22
511511 23
512512 24
513513 25
514514 service based, in whole or part, on personal data that is not
515515 expressly provided personal data;
516516 W. "process" or "processing" means automated or
517517 manual analysis, brokerage, collection, deletion, disclosure,
518518 modification, storage, use, transfer or other handling of
519519 personal data or sets of data;
520520 X. "profiling" means automated processing of
521521 personal data that uses personal data to evaluate certain
522522 aspects relating to a consumer, including analyzing or
523523 predicting aspects concerning the consumer's behavior, economic
524524 situation, health, interests, location, movement, performance
525525 at work, personal preferences or reliability. "Profiling" does
526526 not include the processing of data that does not result in an
527527 assessment or judgment about a consumer;
528528 Y. "publicly available information", except the
529529 information listed in Subsection Z of this section, means
530530 information that has been lawfully made available to the
531531 general public from:
532532 (1) federal, state or municipal government
533533 records;
534534 (2) widely distributed media, including
535535 personal data intentionally made available by a consumer to the
536536 general public such that the consumer does not retain a
537537 reasonable expectation of privacy in the personal data; or
538538 (3) a disclosure that has been made to the
539539 .230898.1
540540 - 10 - underscored material = new
541541 [bracketed material] = delete
542542 1
543543 2
544544 3
545545 4
546546 5
547547 6
548548 7
549549 8
550550 9
551551 10
552552 11
553553 12
554554 13
555555 14
556556 15
557557 16
558558 17
559559 18
560560 19
561561 20
562562 21
563563 22
564564 23
565565 24
566566 25
567567 general public as required by federal, state or local law;
568568 Z. "publicly available information" does not
569569 include:
570570 (1) an obscene visual depiction, as defined by
571571 state law;
572572 (2) personal data that is derived data from
573573 multiple independent sources of publicly available information
574574 that reveals sensitive personal data with respect to a
575575 consumer;
576576 (3) biometric data such that the consumer
577577 retained a reasonable expectation of privacy in the
578578 information;
579579 (4) personal data that is created through the
580580 combination of personal data with publicly available
581581 information;
582582 (5) genetic data, unless otherwise made
583583 publicly available by the consumer to whom the information
584584 pertains; or
585585 (6) information made available by a consumer
586586 on an online feature, product or service open to all members of
587587 the public, whether for a fee or for free, where the consumer
588588 has restricted the information to a specific audience in a
589589 manner that the consumer would retain a reasonable expectation
590590 of privacy for the information;
591591 AA. "sensitive personal data" means personal data
592592 .230898.1
593593 - 11 - underscored material = new
594594 [bracketed material] = delete
595595 1
596596 2
597597 3
598598 4
599599 5
600600 6
601601 7
602602 8
603603 9
604604 10
605605 11
606606 12
607607 13
608608 14
609609 15
610610 16
611611 17
612612 18
613613 19
614614 20
615615 21
616616 22
617617 23
618618 24
619619 25
620620 that includes:
621621 (1) biometric or genetic data;
622622 (2) data revealing citizenship, ethnic origin,
623623 immigration status or racial origin;
624624 (3) financial data, including a credit card
625625 number, a debit card number, a financial account number or
626626 information that describes or reveals the bank account balances
627627 or income level of a consumer, except that the last four digits
628628 of a debit or credit card number are not sensitive personal
629629 data;
630630 (4) a government-issued identifier, such as a
631631 social security number, passport number or driver's license
632632 number, that is not required by law to be displayed in public;
633633 (5) data describing or revealing the past,
634634 present or future mental or physical health of a consumer,
635635 including:
636636 (a) diagnosis;
637637 (b) disability;
638638 (c) health care condition; or
639639 (d) treatment;
640640 (6) data concerning the physical condition of
641641 a consumer, including childbirth, pregnancy or a condition
642642 related to childbirth or pregnancy;
643643 (7) information about a consumer's personal
644644 identity, including:
645645 .230898.1
646646 - 12 - underscored material = new
647647 [bracketed material] = delete
648648 1
649649 2
650650 3
651651 4
652652 5
653653 6
654654 7
655655 8
656656 9
657657 10
658658 11
659659 12
660660 13
661661 14
662662 15
663663 16
664664 17
665665 18
666666 19
667667 20
668668 21
669669 22
670670 23
671671 24
672672 25
673673 (a) ethnic or racial identity;
674674 (b) gender and gender identity;
675675 (c) sex;
676676 (d) sex life; or
677677 (e) sexual orientation;
678678 (8) precise geolocation;
679679 (9) religious affiliation; or
680680 (10) union membership;
681681 BB. "service provider" means a person who collects,
682682 processes, retains or transfers personal data on behalf of, and
683683 at the direction of, a covered entity or a service provider;
684684 CC. "small business" means a covered entity or
685685 service provider that, for the period of the three preceding
686686 calendar years or for the period during which the covered
687687 entity or service provider has been in existence if that period
688688 is less than three years, meets the following criteria:
689689 (1) the covered entity or service provider did
690690 not annually process the personal data of more than fifteen
691691 thousand consumers during the period for any purpose other than
692692 initiating, rendering, billing for, finalizing, completing or
693693 otherwise collecting payment for a requested service or
694694 product; and
695695 (2) the covered entity or service provider did
696696 not engage in brokerage of personal data, except for purposes
697697 of initiating, rendering, billing for, finalizing, completing
698698 .230898.1
699699 - 13 - underscored material = new
700700 [bracketed material] = delete
701701 1
702702 2
703703 3
704704 4
705705 5
706706 6
707707 7
708708 8
709709 9
710710 10
711711 11
712712 12
713713 13
714714 14
715715 15
716716 16
717717 17
718718 18
719719 19
720720 20
721721 21
722722 22
723723 23
724724 24
725725 25
726726 or otherwise collecting payment for a requested service or
727727 product;
728728 DD. "targeted advertising" means displaying or
729729 presenting an online advertisement to a consumer or to a device
730730 identified by a unique persistent identifier or to a group of
731731 consumers or devices identified by unique persistent
732732 identifiers when the advertisement is selected based, in whole
733733 or in part, on known or predicted preferences, characteristics,
734734 behavior or interests associated with the consumer or a device
735735 identified by a unique persistent identifier. "Targeted
736736 advertising" does not include first-party advertising or
737737 contextual advertising; and
738738 EE. "third party" means a person or entity other
739739 than the consumer of the covered entity, the covered entity or
740740 a service provider for the covered entity.
741741 SECTION 3. [NEW MATERIAL] REQUIREMENTS FOR COVERED
742742 ENTITIES--ONLINE PLATFORMS--CONSUMER OPTIONS--MINORS.--
743743 A. Except as provided in Subsection B of this
744744 section, a covered entity shall:
745745 (1) configure all default privacy settings on
746746 the covered entity's online platforms offering features,
747747 products or services to settings that offer the highest level
748748 of privacy;
749749 (2) publicly provide privacy information,
750750 terms of service, policies and community standards in a
751751 .230898.1
752752 - 14 - underscored material = new
753753 [bracketed material] = delete
754754 1
755755 2
756756 3
757757 4
758758 5
759759 6
760760 7
761761 8
762762 9
763763 10
764764 11
765765 12
766766 13
767767 14
768768 15
769769 16
770770 17
771771 18
772772 19
773773 20
774774 21
775775 22
776776 23
777777 24
778778 25
779779 prominent, precise manner and use clear, easily understood
780780 language;
781781 (3) publicly provide prominent, accessible and
782782 responsive tools to help a consumer exercise the consumer's
783783 privacy rights and report concerns; and
784784 (4) establish, implement and maintain
785785 reasonable administrative, technical and physical data security
786786 practices to protect the confidentiality, integrity and
787787 accessibility of personal data appropriate to the volume and
788788 nature of the personal data at issue pursuant to guidelines
789789 established by the state department of justice by rule.
790790 B. When a covered entity does not have actual
791791 knowledge that a consumer using the covered entity's online
792792 platform to access a feature, product or service is a minor,
793793 the covered entity shall establish settings on that online
794794 platform that:
795795 (1) permit a consumer to disable notifications
796796 or disable notifications during specific periods of time;
797797 (2) permit a consumer to choose between a
798798 privacy-protective feed and a profile-based feed; and
799799 (3) permit a consumer to disable contact by
800800 unknown individuals unless the consumer first initiates the
801801 contact or provide a mechanism to screen contact by individuals
802802 with whom the consumer does not have a relationship.
803803 C. When a covered entity has actual knowledge that
804804 .230898.1
805805 - 15 - underscored material = new
806806 [bracketed material] = delete
807807 1
808808 2
809809 3
810810 4
811811 5
812812 6
813813 7
814814 8
815815 9
816816 10
817817 11
818818 12
819819 13
820820 14
821821 15
822822 16
823823 17
824824 18
825825 19
826826 20
827827 21
828828 22
829829 23
830830 24
831831 25
832832 a consumer using the covered entity's online platform is a
833833 minor, the covered entity shall establish default settings on
834834 the platform:
835835 (1) that disable contact by unknown users
836836 unless the consumer first initiates the contact;
837837 (2) that disable notifications between the
838838 hours of 10:00 p.m. and 6:00 a.m. mountain time pursuant to
839839 federal law; and
840840 (3) that use a privacy-protective feed.
841841 SECTION 4. [NEW MATERIAL] PROHIBITED PRACTICES--CONSUMER
842842 OPT-IN OPTION.--A covered entity that provides an online
843843 feature, product or service that involves the processing of
844844 personal data shall not, and shall not instruct a service
845845 provider or third party, to:
846846 A. profile a consumer by default, unless profiling
847847 is necessary to provide the online feature, product or service
848848 requested, and only with respect to the aspects of the online
849849 feature, product or service with which the consumer is actively
850850 and knowingly engaged;
851851 B. process the personal data of a consumer except
852852 as necessary to provide:
853853 (1) the specific online feature, product or
854854 service with which the consumer is actively and knowingly
855855 engaged, including any routine administrative, operational or
856856 account-servicing activity, such as billing, shipping,
857857 .230898.1
858858 - 16 - underscored material = new
859859 [bracketed material] = delete
860860 1
861861 2
862862 3
863863 4
864864 5
865865 6
866866 7
867867 8
868868 9
869869 10
870870 11
871871 12
872872 13
873873 14
874874 15
875875 16
876876 17
877877 18
878878 19
879879 20
880880 21
881881 22
882882 23
883883 24
884884 25
885885 delivery, storage, accounting, security or fraud detection; or
886886 (2) a communication, that is not an
887887 advertisement, by the covered entity to the consumer that is
888888 reasonably anticipated within the context of the relationship
889889 between the covered entity and the consumer;
890890 C. process personal data for any reason other than
891891 a reason for which the personal data is collected;
892892 D. process a consumer's sensitive personal data
893893 unless the collection of that data is strictly necessary for
894894 the covered entity to provide the online feature, product or
895895 service requested and then only for the limited time that the
896896 collection of data is necessary to provide the online feature,
897897 product or service;
898898 E. process a consumer's precise geolocation
899899 information without providing an obvious signal to the consumer
900900 for the duration of that collection that precise geolocation
901901 information is being collected;
902902 F. use dark patterns to cause a consumer to provide
903903 personal data beyond what is reasonably expected to provide the
904904 online feature, product or service, to forego privacy
905905 protections;
906906 G. allow a person to monitor a consumer's online
907907 activity or precise geolocation without providing an obvious
908908 signal to the consumer that the consumer is being monitored or
909909 tracked;
910910 .230898.1
911911 - 17 - underscored material = new
912912 [bracketed material] = delete
913913 1
914914 2
915915 3
916916 4
917917 5
918918 6
919919 7
920920 8
921921 9
922922 10
923923 11
924924 12
925925 13
926926 14
927927 15
928928 16
929929 17
930930 18
931931 19
932932 20
933933 21
934934 22
935935 23
936936 24
937937 25
938938 H. process or transfer personal data in a manner
939939 that discriminates in or otherwise makes unavailable the equal
940940 enjoyment of goods or services on the basis of childbirth or
941941 condition related to pregnancy or childbirth, color,
942942 disability, gender, gender identity, mental health, national
943943 origin, physical health condition or diagnosis, race,
944944 religion, sex life or sexual orientation;
945945 I. process personal data for purposes of targeted
946946 advertising, first-party advertising or the brokerage of
947947 personal data without the consumer first opting in to those
948948 purposes by clear and conspicuous means and not through the use
949949 of dark patterns; or
950950 J. process sensitive personal data for purposes of
951951 targeted advertising, first-party advertising or the brokerage
952952 of personal data.
953953 SECTION 5. [NEW MATERIAL] RIGHTS OF ACCESS--CORRECTION--
954954 DELETION.--
955955 A. Covered entities shall provide a consumer the
956956 right to:
957957 (1) access all the consumer's personal data
958958 that was processed by the covered entity or a service provider;
959959 (2) access all the information pertaining to
960960 the collection and processing of the consumer's personal
961961 information, including:
962962 (a) where or from whom the covered
963963 .230898.1
964964 - 18 - underscored material = new
965965 [bracketed material] = delete
966966 1
967967 2
968968 3
969969 4
970970 5
971971 6
972972 7
973973 8
974974 9
975975 10
976976 11
977977 12
978978 13
979979 14
980980 15
981981 16
982982 17
983983 18
984984 19
985985 20
986986 21
987987 22
988988 23
989989 24
990990 25
991991 entity obtained personal data, such as whether the information
992992 was obtained from the consumer or a third party or from an
993993 online or offline source;
994994 (b) the types of third parties to which
995995 the covered entity has disclosed or will disclose personal
996996 data;
997997 (c) the purposes of the processing;
998998 (d) the categories of personal data
999999 concerned;
10001000 (e) the names of third parties to which
10011001 the covered entity had disclosed the personal data and a log
10021002 showing when such disclosure happened; and
10031003 (f) the period of retention of the
10041004 personal data;
10051005 (3) obtain the consumer's personal data
10061006 processed by a covered entity in a structured, readily usable,
10071007 portable and machine-readable format;
10081008 (4) transmit or cause the covered entity to
10091009 transmit the consumer's personal data to another covered
10101010 entity, where technically feasible;
10111011 (5) request a covered entity to stop
10121012 collecting and processing the consumer's personal data;
10131013 (6) correct inaccurate personal data stored by
10141014 covered entities; and
10151015 (7) delete the consumer's personal data that
10161016 .230898.1
10171017 - 19 - underscored material = new
10181018 [bracketed material] = delete
10191019 1
10201020 2
10211021 3
10221022 4
10231023 5
10241024 6
10251025 7
10261026 8
10271027 9
10281028 10
10291029 11
10301030 12
10311031 13
10321032 14
10331033 15
10341034 16
10351035 17
10361036 18
10371037 19
10381038 20
10391039 21
10401040 22
10411041 23
10421042 24
10431043 25
10441044 is stored by covered entities, including from nonpublic
10451045 profiles; provided that a covered entity that has collected
10461046 personal data from a consumer is not required to delete
10471047 information to the extent that the covered entity is exempt
10481048 under Section 9 of the Community Privacy and Safety Act.
10491049 B. A covered entity shall provide a consumer with a
10501050 reasonable means to exercise the consumer's rights pursuant to
10511051 Subsection A of this section in a request form that is:
10521052 (1) clear and conspicuous;
10531053 (2) made available at no additional cost and
10541054 with no transactional penalty to the consumer to whom the
10551055 information pertains; and
10561056 (3) in English or another language in which
10571057 the covered entity communicates with the consumer to whom the
10581058 information pertains.
10591059 C. A covered entity shall comply with a consumer's
10601060 request to exercise the consumer's rights pursuant to
10611061 Subsection A or B of this section within thirty days after
10621062 receiving a verifiable request; provided that:
10631063 (1) when the covered entity has a reasonable
10641064 doubt or cannot verify the identity of the consumer making a
10651065 request, the covered entity may request additional personal
10661066 information necessary for the specific purpose of confirming
10671067 the consumer's identity; and
10681068 (2) the covered entity shall not de-identify
10691069 .230898.1
10701070 - 20 - underscored material = new
10711071 [bracketed material] = delete
10721072 1
10731073 2
10741074 3
10751075 4
10761076 5
10771077 6
10781078 7
10791079 8
10801080 9
10811081 10
10821082 11
10831083 12
10841084 13
10851085 14
10861086 15
10871087 16
10881088 17
10891089 18
10901090 19
10911091 20
10921092 21
10931093 22
10941094 23
10951095 24
10961096 25
10971097 the consumer's personal data for sixty days from the date on
10981098 which the covered entity receives a request for correction or
10991099 deletion from the consumer pursuant to this section.
11001100 SECTION 6. [NEW MATERIAL] DATA PROCESSING AGREEMENTS.--
11011101 A. A service provider that processes personal data
11021102 on behalf of a covered entity or another service provider or a
11031103 third party that receives personal data from a covered entity
11041104 shall enter into a written data processing agreement with the
11051105 covered entity ensuring that the data will continue to be
11061106 processed consistent with the Community Privacy and Safety Act.
11071107 The agreement shall specify that:
11081108 (1) personal data received by service
11091109 providers or third parties shall be processed only for purposes
11101110 specified by the covered entity in the data processing
11111111 agreement, subject to the limitations of the Community Privacy
11121112 and Safety Act;
11131113 (2) service providers and third parties shall
11141114 only process personal data that is adequate, relevant and
11151115 necessary for the purposes for which the data was collected or
11161116 received;
11171117 (3) service providers and third parties shall
11181118 ensure that subcontractors comply with the same data protection
11191119 obligations as set forth in their data processing agreement
11201120 with the covered entity;
11211121 (4) service providers and third parties shall
11221122 .230898.1
11231123 - 21 - underscored material = new
11241124 [bracketed material] = delete
11251125 1
11261126 2
11271127 3
11281128 4
11291129 5
11301130 6
11311131 7
11321132 8
11331133 9
11341134 10
11351135 11
11361136 12
11371137 13
11381138 14
11391139 15
11401140 16
11411141 17
11421142 18
11431143 19
11441144 20
11451145 21
11461146 22
11471147 23
11481148 24
11491149 25
11501150 establish, implement and maintain reasonable administrative,
11511151 technical and physical data security practices to protect the
11521152 confidentiality, integrity and accessibility of personal data
11531153 appropriate to the volume and nature of the personal data at
11541154 issue; and
11551155 (5) service providers shall adhere to the
11561156 instructions of a covered entity and shall assist the covered
11571157 entity in meeting the covered entity's obligations pursuant to
11581158 the Community Privacy and Safety Act.
11591159 B. Prior to transferring personal data to a third
11601160 party located outside of New Mexico, covered entities shall
11611161 ensure that adequate data protection safeguards consistent with
11621162 the Community Privacy and Safety Act are in place.
11631163 SECTION 7. [NEW MATERIAL] PROHIBITION ON WAIVING OF
11641164 RIGHTS AND RETALIATORY DENIAL OF SERVICE.--
11651165 A. A covered entity shall not retaliate against a
11661166 consumer for exercising a right guaranteed by the Community
11671167 Privacy and Safety Act, or a rule promulgated under that act,
11681168 including charging different prices or rates for goods and
11691169 services, denying goods or services or providing a different
11701170 level of quality of goods or services.
11711171 B. A provision of a contract, an agreement or terms
11721172 of service shall not waive, limit or otherwise undermine the
11731173 rights conferred under the Community Privacy and Safety Act or
11741174 other applicable data protection laws.
11751175 .230898.1
11761176 - 22 - underscored material = new
11771177 [bracketed material] = delete
11781178 1
11791179 2
11801180 3
11811181 4
11821182 5
11831183 6
11841184 7
11851185 8
11861186 9
11871187 10
11881188 11
11891189 12
11901190 13
11911191 14
11921192 15
11931193 16
11941194 17
11951195 18
11961196 19
11971197 20
11981198 21
11991199 22
12001200 23
12011201 24
12021202 25
12031203 C. A provision within a contract or an agreement
12041204 between a covered entity and a consumer that is invalid or
12051205 unenforceable pursuant to the Community Privacy and Safety Act
12061206 shall not affect the validity or enforceability of the
12071207 remaining provisions of the contract or agreement.
12081208 SECTION 8. [NEW MATERIAL] VIOLATIONS--ENFORCEMENT--
12091209 PENALTIES--CLAIMS FOR VIOLATIONS.--Upon promulgation of rules
12101210 by the state department of justice to implement the Community
12111211 Privacy and Safety Act:
12121212 A. a covered entity that violates the provisions of
12131213 that act shall be:
12141214 (1) subject to injunctive relief to cease or
12151215 correct the violation;
12161216 (2) liable for a civil penalty of not more
12171217 than two thousand five hundred dollars ($2,500) per affected
12181218 consumer for each negligent violation; and
12191219 (3) liable for a civil penalty of not more
12201220 than seven thousand five hundred dollars ($7,500) per affected
12211221 consumer for each intentional violation;
12221222 B. a consumer who claims to have suffered a
12231223 deprivation of the rights secured under the Community Privacy
12241224 and Safety Act may maintain an action to establish liability
12251225 and recover damages or equitable or injunctive relief in
12261226 district court; and
12271227 C. for a period of three years immediately
12281228 .230898.1
12291229 - 23 - underscored material = new
12301230 [bracketed material] = delete
12311231 1
12321232 2
12331233 3
12341234 4
12351235 5
12361236 6
12371237 7
12381238 8
12391239 9
12401240 10
12411241 11
12421242 12
12431243 13
12441244 14
12451245 15
12461246 16
12471247 17
12481248 18
12491249 19
12501250 20
12511251 21
12521252 22
12531253 23
12541254 24
12551255 25
12561256 following the date of enactment of the Community Privacy and
12571257 Safety Act, an action under this section shall not be
12581258 maintained against a small business unless the maintaining
12591259 party first provides the small business with a notice
12601260 reasonably describing the alleged violation or deprivation of
12611261 rights under that act and providing a sixty-day opportunity to
12621262 cure. If the small business fails to cure the violation within
12631263 sixty days of receipt of the notice of violation, an action may
12641264 be maintained pursuant to this section without further notice.
12651265 SECTION 9. [NEW MATERIAL] EXCEPTIONS.--
12661266 A. A covered entity that is in compliance with
12671267 federal privacy laws shall be deemed to be in compliance with
12681268 the requirements of the Community Privacy and Safety Act solely
12691269 and exclusively with respect to data subject to the
12701270 requirements of federal law; provided that a covered entity
12711271 that is in compliance with the federal Children's Online
12721272 Privacy Protection Act of 1998 shall be in compliance with the
12731273 requirements of the Community Privacy and Safety Act only to
12741274 the extent that compliance with that act is inconsistent with
12751275 the federal Children's Online Privacy Protection Act of 1998.
12761276 B. An online feature, product or service that is
12771277 regulated pursuant to federal information security law shall be
12781278 deemed to be in compliance with the requirements of the
12791279 Community Privacy and Safety Act solely and exclusively with
12801280 respect to data subject to the requirements of federal law.
12811281 .230898.1
12821282 - 24 - underscored material = new
12831283 [bracketed material] = delete
12841284 1
12851285 2
12861286 3
12871287 4
12881288 5
12891289 6
12901290 7
12911291 8
12921292 9
12931293 10
12941294 11
12951295 12
12961296 13
12971297 14
12981298 15
12991299 16
13001300 17
13011301 18
13021302 19
13031303 20
13041304 21
13051305 22
13061306 23
13071307 24
13081308 25
13091309 C. The Community Privacy and Safety Act does not
13101310 apply to the delivery or use of a physical product to the
13111311 extent the product is not an online feature, product or
13121312 service.
13131313 SECTION 10. [NEW MATERIAL] LIMITATIONS.--Nothing in the
13141314 Community Privacy and Safety Act shall be interpreted or
13151315 construed to:
13161316 A. impose liability in a manner that is
13171317 inconsistent with federal law;
13181318 B. apply to information processed by local, state
13191319 or federal government or municipal corporations; or
13201320 C. restrict a covered entity's or service
13211321 provider's ability to:
13221322 (1) comply with federal or New Mexico law;
13231323 (2) comply with a civil or criminal subpoena
13241324 or summons, except as prohibited by New Mexico law;
13251325 (3) cooperate with law enforcement agencies
13261326 concerning conduct or activity that the covered entity or
13271327 service provider reasonably and in good faith believes may
13281328 violate federal, state or municipal ordinances or regulations;
13291329 (4) investigate, establish, exercise, prepare
13301330 for or defend legal claims to the extent that the personal data
13311331 is relevant to the parties' claims;
13321332 (5) take immediate steps to protect the life
13331333 or physical safety of a consumer or another individual in an
13341334 .230898.1
13351335 - 25 - underscored material = new
13361336 [bracketed material] = delete
13371337 1
13381338 2
13391339 3
13401340 4
13411341 5
13421342 6
13431343 7
13441344 8
13451345 9
13461346 10
13471347 11
13481348 12
13491349 13
13501350 14
13511351 15
13521352 16
13531353 17
13541354 18
13551355 19
13561356 20
13571357 21
13581358 22
13591359 23
13601360 24
13611361 25
13621362 emergency, and where the processing cannot be manifestly based
13631363 on another legal basis; provided that a consumer's access to
13641364 health care services lawful in the state of New Mexico shall
13651365 not constitute an emergency;
13661366 (6) prevent, detect, protect against or
13671367 respond to security incidents relating to network security or
13681368 physical security, including an intrusion or trespass, medical
13691369 alert or request for a medical response, fire alarm or request
13701370 for a fire response, or access control;
13711371 (7) prevent, detect, protect against or
13721372 respond to identity theft, fraud, harassment, malicious or
13731373 deceptive activities or illegal activity targeted at or
13741374 involving the covered entity or service provider or its
13751375 services, preserve the integrity or security of systems or
13761376 investigate, report or prosecute those responsible for any such
13771377 action;
13781378 (8) assist another covered entity, service
13791379 provider or third party with any of the obligations in the
13801380 Community Privacy and Safety Act;
13811381 (9) transfer assets to a third party in the
13821382 context of a merger, acquisition, bankruptcy or similar
13831383 transaction when the third party assumes control, in whole or
13841384 in part, of the covered entity's assets, only if the covered
13851385 entity, in a reasonable time prior to the transfer, provides an
13861386 affected consumer with notice describing the transfer,
13871387 .230898.1
13881388 - 26 - underscored material = new
13891389 [bracketed material] = delete
13901390 1
13911391 2
13921392 3
13931393 4
13941394 5
13951395 6
13961396 7
13971397 8
13981398 9
13991399 10
14001400 11
14011401 12
14021402 13
14031403 14
14041404 15
14051405 16
14061406 17
14071407 18
14081408 19
14091409 20
14101410 21
14111411 22
14121412 23
14131413 24
14141414 25
14151415 including the name of the entity receiving the consumer's
14161416 personal data and the applicable privacy policies of the
14171417 entity, and a reasonable opportunity to:
14181418 (a) withdraw previously provided consent
14191419 or opt-ins related to the consumer's personal data; and
14201420 (b) request the deletion of the
14211421 consumer's personal data;
14221422 (10) meet federal law requirements for data
14231423 used or collected for medical research; or
14241424 (11) process personal data previously
14251425 collected in accordance with the Community Privacy and Safety
14261426 Act, solely for the purpose of the personal data becoming
14271427 de-identified data.
14281428 SECTION 11. [NEW MATERIAL] STATE DEPARTMENT OF JUSTICE--
14291429 RULEMAKING--REPORTS.--
14301430 A. On or before April 1, 2026, the state department
14311431 of justice shall promulgate rules for the implementation of the
14321432 Community Privacy and Safety Act.
14331433 B. On or before November 30, 2026 and on or before
14341434 November 30 in each subsequent year, the state department of
14351435 justice shall provide a report to the interim legislative
14361436 committee that is tasked with examining internet-related
14371437 issues. The report shall:
14381438 (1) compare the requirements of the then-
14391439 current federal laws and regulations with the requirements of
14401440 .230898.1
14411441 - 27 - underscored material = new
14421442 [bracketed material] = delete
14431443 1
14441444 2
14451445 3
14461446 4
14471447 5
14481448 6
14491449 7
14501450 8
14511451 9
14521452 10
14531453 11
14541454 12
14551455 13
14561456 14
14571457 15
14581458 16
14591459 17
14601460 18
14611461 19
14621462 20
14631463 21
14641464 22
14651465 23
14661466 24
14671467 25
14681468 the Community Privacy and Safety Act and the rules promulgated
14691469 pursuant to Subsection A of this section on entities offering
14701470 online features, products or services concerning data privacy
14711471 and the protection of minors; and
14721472 (2) provide recommendations for statutory
14731473 changes needed to conform state law with federal law.
14741474 - 28 -
14751475 .230898.1