1 | 1 | | |
---|
2 | 2 | | |
---|
3 | 3 | | Req. No. 8440 Page 1 1 |
---|
4 | 4 | | 2 |
---|
5 | 5 | | 3 |
---|
6 | 6 | | 4 |
---|
7 | 7 | | 5 |
---|
8 | 8 | | 6 |
---|
9 | 9 | | 7 |
---|
10 | 10 | | 8 |
---|
11 | 11 | | 9 |
---|
12 | 12 | | 10 |
---|
13 | 13 | | 11 |
---|
14 | 14 | | 12 |
---|
15 | 15 | | 13 |
---|
16 | 16 | | 14 |
---|
17 | 17 | | 15 |
---|
18 | 18 | | 16 |
---|
19 | 19 | | 17 |
---|
20 | 20 | | 18 |
---|
21 | 21 | | 19 |
---|
22 | 22 | | 20 |
---|
23 | 23 | | 21 |
---|
24 | 24 | | 22 |
---|
25 | 25 | | 23 |
---|
26 | 26 | | 24 |
---|
27 | 27 | | |
---|
28 | 28 | | STATE OF OKLAHOMA |
---|
29 | 29 | | |
---|
30 | 30 | | 2nd Session of the 58th Legislature (2022) |
---|
31 | 31 | | |
---|
32 | 32 | | HOUSE BILL 2968 By: Walke |
---|
33 | 33 | | |
---|
34 | 34 | | |
---|
35 | 35 | | |
---|
36 | 36 | | |
---|
37 | 37 | | |
---|
38 | 38 | | AS INTRODUCED |
---|
39 | 39 | | |
---|
40 | 40 | | An Act relating to privacy of computer data; enacting |
---|
41 | 41 | | the Oklahoma Computer Data Privacy Act of 2022; |
---|
42 | 42 | | providing intent and construction; d efining terms; |
---|
43 | 43 | | prescribing that the Attorney General is responsible |
---|
44 | 44 | | for enforcement; providing disclosure requirements; |
---|
45 | 45 | | providing limitations; providing consumers the right |
---|
46 | 46 | | to opt out of data collection; providing consumers |
---|
47 | 47 | | the right to deletion of their i nformation; providing |
---|
48 | 48 | | exceptions to request for deletion of information; |
---|
49 | 49 | | providing consumers with the right to request for an |
---|
50 | 50 | | audit of their information; providing consumers with |
---|
51 | 51 | | the right to have their personal information |
---|
52 | 52 | | corrected; requiring business to not discriminate; |
---|
53 | 53 | | providing guidelines for implementation; providing |
---|
54 | 54 | | exemptions; preempting intermediate transactions from |
---|
55 | 55 | | circumventing regulations; providing waivers are void |
---|
56 | 56 | | and unenforceable; prohibiting bu sinesses from |
---|
57 | 57 | | modifying or manipulating user interfaces to obscure, |
---|
58 | 58 | | subvert or impair user autonomy, decision -making or |
---|
59 | 59 | | choice; providing severability of provisions; |
---|
60 | 60 | | providing for codification ; and providing an |
---|
61 | 61 | | effective date. |
---|
62 | 62 | | |
---|
63 | 63 | | |
---|
64 | 64 | | |
---|
65 | 65 | | |
---|
66 | 66 | | BE IT ENACTED BY THE PEOPLE OF THE STATE OF OKLAHOMA: |
---|
67 | 67 | | SECTION 1. NEW LAW A new section of law to be codified |
---|
68 | 68 | | in the Oklahoma Statutes as Section 20m-1 of Title 74, unless there |
---|
69 | 69 | | is created a duplication in numbering, reads as follows: |
---|
70 | 70 | | |
---|
71 | 71 | | Req. No. 8440 Page 2 1 |
---|
72 | 72 | | 2 |
---|
73 | 73 | | 3 |
---|
74 | 74 | | 4 |
---|
75 | 75 | | 5 |
---|
76 | 76 | | 6 |
---|
77 | 77 | | 7 |
---|
78 | 78 | | 8 |
---|
79 | 79 | | 9 |
---|
80 | 80 | | 10 |
---|
81 | 81 | | 11 |
---|
82 | 82 | | 12 |
---|
83 | 83 | | 13 |
---|
84 | 84 | | 14 |
---|
85 | 85 | | 15 |
---|
86 | 86 | | 16 |
---|
87 | 87 | | 17 |
---|
88 | 88 | | 18 |
---|
89 | 89 | | 19 |
---|
90 | 90 | | 20 |
---|
91 | 91 | | 21 |
---|
92 | 92 | | 22 |
---|
93 | 93 | | 23 |
---|
94 | 94 | | 24 |
---|
95 | 95 | | |
---|
96 | 96 | | This act shall be known and may be cited as the "Oklahoma |
---|
97 | 97 | | Computer Data Privacy Act of 2022". |
---|
98 | 98 | | SECTION 2. NEW LAW A new section of law to be codified |
---|
99 | 99 | | in the Oklahoma Statutes as Section 20m-2 of Title 74, unless there |
---|
100 | 100 | | is created a duplication in num bering, reads as follows: |
---|
101 | 101 | | The Oklahoma Legislature acknowledges the people 's |
---|
102 | 102 | | Constitutional right to privacy and further acknowledges that any |
---|
103 | 103 | | collection of Oklahoma citizens ' data without their knowledge and |
---|
104 | 104 | | consent is a violation of such right to privacy . This act is |
---|
105 | 105 | | intended to complement other d ata privacy laws, both state and |
---|
106 | 106 | | federal, and to the extent there is a conflict with a state law, the |
---|
107 | 107 | | law conferring the greatest privacy shall control. Further, the |
---|
108 | 108 | | Oklahoma Legislature has determined the provisions of this act are |
---|
109 | 109 | | the least restrictive possible. |
---|
110 | 110 | | SECTION 3. NEW LAW A new section of law to be codified |
---|
111 | 111 | | in the Oklahoma Statutes as Section 20m-3 of Title 74, unless there |
---|
112 | 112 | | is created a duplication in numbering, reads as follow s: |
---|
113 | 113 | | As used in this act: |
---|
114 | 114 | | 1. "Aggregate consumer information" means information that |
---|
115 | 115 | | relates to a group of consumers, from which individual consumer |
---|
116 | 116 | | identities have been removed, that is not linked or reasonably |
---|
117 | 117 | | linkable to any consumer or household, includ ing via a device. |
---|
118 | 118 | | Aggregate consumer informat ion does not mean one or more individual |
---|
119 | 119 | | consumer records that have been de -identified; |
---|
120 | 120 | | |
---|
121 | 121 | | Req. No. 8440 Page 3 1 |
---|
122 | 122 | | 2 |
---|
123 | 123 | | 3 |
---|
124 | 124 | | 4 |
---|
125 | 125 | | 5 |
---|
126 | 126 | | 6 |
---|
127 | 127 | | 7 |
---|
128 | 128 | | 8 |
---|
129 | 129 | | 9 |
---|
130 | 130 | | 10 |
---|
131 | 131 | | 11 |
---|
132 | 132 | | 12 |
---|
133 | 133 | | 13 |
---|
134 | 134 | | 14 |
---|
135 | 135 | | 15 |
---|
136 | 136 | | 16 |
---|
137 | 137 | | 17 |
---|
138 | 138 | | 18 |
---|
139 | 139 | | 19 |
---|
140 | 140 | | 20 |
---|
141 | 141 | | 21 |
---|
142 | 142 | | 22 |
---|
143 | 143 | | 23 |
---|
144 | 144 | | 24 |
---|
145 | 145 | | |
---|
146 | 146 | | 2. "Biometric information " means an individual's physiological, |
---|
147 | 147 | | biological or behavioral characteristics or an electronic |
---|
148 | 148 | | representation of such, including an individu al's deoxyribonucleic |
---|
149 | 149 | | acid (DNA), that can be used, singly or in combination with each |
---|
150 | 150 | | other or with other identifying data, to establish an individual's |
---|
151 | 151 | | identity. Biometric information includes, but is not lim ited to, |
---|
152 | 152 | | imagery of the iris, retina, fingerp rint, face, hand, palm, vein |
---|
153 | 153 | | patterns, and voice recordings from which an identifier template, |
---|
154 | 154 | | such as a faceprint, a minutiae template, or a voiceprint, can be |
---|
155 | 155 | | extracted, and keystroke patterns or rhythms, gait patterns or |
---|
156 | 156 | | rhythms, and sleep, health, or e xercise data that contain |
---|
157 | 157 | | identifying information; |
---|
158 | 158 | | 3. "Business" means: |
---|
159 | 159 | | a. a sole proprietorship, partnership, limited liability |
---|
160 | 160 | | company, corporation, association, or other legal |
---|
161 | 161 | | entity that collects consumers ' personal information, |
---|
162 | 162 | | or on the behalf of wh ich such information is |
---|
163 | 163 | | collected and that alone, or jointly with others, |
---|
164 | 164 | | determines the purposes and means of the processing of |
---|
165 | 165 | | consumers' personal information, that does business in |
---|
166 | 166 | | the State of Oklahoma, and that satisfies one or more |
---|
167 | 167 | | of the following thresholds: |
---|
168 | 168 | | |
---|
169 | 169 | | Req. No. 8440 Page 4 1 |
---|
170 | 170 | | 2 |
---|
171 | 171 | | 3 |
---|
172 | 172 | | 4 |
---|
173 | 173 | | 5 |
---|
174 | 174 | | 6 |
---|
175 | 175 | | 7 |
---|
176 | 176 | | 8 |
---|
177 | 177 | | 9 |
---|
178 | 178 | | 10 |
---|
179 | 179 | | 11 |
---|
180 | 180 | | 12 |
---|
181 | 181 | | 13 |
---|
182 | 182 | | 14 |
---|
183 | 183 | | 15 |
---|
184 | 184 | | 16 |
---|
185 | 185 | | 17 |
---|
186 | 186 | | 18 |
---|
187 | 187 | | 19 |
---|
188 | 188 | | 20 |
---|
189 | 189 | | 21 |
---|
190 | 190 | | 22 |
---|
191 | 191 | | 23 |
---|
192 | 192 | | 24 |
---|
193 | 193 | | |
---|
194 | 194 | | (1) has annual gross revenues in excess of Ten |
---|
195 | 195 | | Million Dollars ($10,000,000.00) in the preceding |
---|
196 | 196 | | calendar year, |
---|
197 | 197 | | (2) alone or in combination, annually buys, receives, |
---|
198 | 198 | | shares, or discloses for commercia l purposes, |
---|
199 | 199 | | alone or in combination, the pers onal information |
---|
200 | 200 | | of twenty-five thousand or more consumers, |
---|
201 | 201 | | households or devices, or |
---|
202 | 202 | | (3) derives fifty percent (50%) or more of its annual |
---|
203 | 203 | | revenues from sharing consumers ' personal |
---|
204 | 204 | | information, |
---|
205 | 205 | | b. any entity that controls or is controlled by a |
---|
206 | 206 | | business, as defined in subparagraph a of this |
---|
207 | 207 | | paragraph, and that shares common branding with the |
---|
208 | 208 | | business and with whom the business shares consumers ' |
---|
209 | 209 | | personal information. "Control" or "controlled" means |
---|
210 | 210 | | ownership of, or the power to vote, more than fifty |
---|
211 | 211 | | percent (50%) of the outstanding shares of any class |
---|
212 | 212 | | of voting security of a business; control in any |
---|
213 | 213 | | manner over the election of a majority of the |
---|
214 | 214 | | directors, or of individuals exercising similar |
---|
215 | 215 | | functions; or the power to exercise a controlling |
---|
216 | 216 | | influence over the management of a company. "Common |
---|
217 | 217 | | branding" means a shared name, service mark, or |
---|
218 | 218 | | |
---|
219 | 219 | | Req. No. 8440 Page 5 1 |
---|
220 | 220 | | 2 |
---|
221 | 221 | | 3 |
---|
222 | 222 | | 4 |
---|
223 | 223 | | 5 |
---|
224 | 224 | | 6 |
---|
225 | 225 | | 7 |
---|
226 | 226 | | 8 |
---|
227 | 227 | | 9 |
---|
228 | 228 | | 10 |
---|
229 | 229 | | 11 |
---|
230 | 230 | | 12 |
---|
231 | 231 | | 13 |
---|
232 | 232 | | 14 |
---|
233 | 233 | | 15 |
---|
234 | 234 | | 16 |
---|
235 | 235 | | 17 |
---|
236 | 236 | | 18 |
---|
237 | 237 | | 19 |
---|
238 | 238 | | 20 |
---|
239 | 239 | | 21 |
---|
240 | 240 | | 22 |
---|
241 | 241 | | 23 |
---|
242 | 242 | | 24 |
---|
243 | 243 | | |
---|
244 | 244 | | trademark, such that the average consumer would |
---|
245 | 245 | | understand that two or m ore entities are commonly |
---|
246 | 246 | | owned, |
---|
247 | 247 | | c. a joint venture or partnership composed of businesses |
---|
248 | 248 | | in which each business has at least a forty -percent- |
---|
249 | 249 | | interest. For purposes of this act, the joint venture |
---|
250 | 250 | | or partnership and each business that comprises the |
---|
251 | 251 | | joint venture or partnership shall separately be |
---|
252 | 252 | | considered a single business, except that personal |
---|
253 | 253 | | information in the possession of each business and |
---|
254 | 254 | | disclosed to the joint venture or partnership shall |
---|
255 | 255 | | not be shared with th e other businesses; |
---|
256 | 256 | | 4. "Collects", "collected", or "collection" means buying, |
---|
257 | 257 | | renting, gathering, obtaining, receiving, or accessing any pe rsonal |
---|
258 | 258 | | information pertaining to a consumer by any means. This includes |
---|
259 | 259 | | receiving information from the consumer, either actively or |
---|
260 | 260 | | passively, or by observing the consumer 's behavior; |
---|
261 | 261 | | 5. "Commercial purposes" means to advance a person 's commercial |
---|
262 | 262 | | or economic interests, such as by inducing another person to buy, |
---|
263 | 263 | | rent, lease, join, subscribe to, provide, or exchange products, |
---|
264 | 264 | | goods, property, information or services, or enabling or effecting, |
---|
265 | 265 | | directly or indirectly, a commercial transaction. Commercial |
---|
266 | 266 | | purposes do not include engaging in speech that state or federal |
---|
267 | 267 | | |
---|
268 | 268 | | Req. No. 8440 Page 6 1 |
---|
269 | 269 | | 2 |
---|
270 | 270 | | 3 |
---|
271 | 271 | | 4 |
---|
272 | 272 | | 5 |
---|
273 | 273 | | 6 |
---|
274 | 274 | | 7 |
---|
275 | 275 | | 8 |
---|
276 | 276 | | 9 |
---|
277 | 277 | | 10 |
---|
278 | 278 | | 11 |
---|
279 | 279 | | 12 |
---|
280 | 280 | | 13 |
---|
281 | 281 | | 14 |
---|
282 | 282 | | 15 |
---|
283 | 283 | | 16 |
---|
284 | 284 | | 17 |
---|
285 | 285 | | 18 |
---|
286 | 286 | | 19 |
---|
287 | 287 | | 20 |
---|
288 | 288 | | 21 |
---|
289 | 289 | | 22 |
---|
290 | 290 | | 23 |
---|
291 | 291 | | 24 |
---|
292 | 292 | | |
---|
293 | 293 | | courts have recognized as noncommercial speech, including political |
---|
294 | 294 | | speech and journalism. |
---|
295 | 295 | | 6. "Consumer" means a natural person who is an Oklahoma |
---|
296 | 296 | | resident. It does not include an employee or contractor of a |
---|
297 | 297 | | business acting in his or her role as an employee or contractor ; |
---|
298 | 298 | | 7. "De-identified" means information that cannot reasonably |
---|
299 | 299 | | identify, relate to, describe, reasonably be associated with, or |
---|
300 | 300 | | reasonably be linked, directly or indirectly, to a particular |
---|
301 | 301 | | consumer, provided that the business: |
---|
302 | 302 | | a. takes reasonable measures to ensure that the data |
---|
303 | 303 | | could not be reidentified, |
---|
304 | 304 | | b. publicly commits to maintain and use the data in a de - |
---|
305 | 305 | | identified fashion and not to attempt to reidentify |
---|
306 | 306 | | the data, and |
---|
307 | 307 | | c. contractually prohibits downstream r ecipients from |
---|
308 | 308 | | attempting to reidentify the data; |
---|
309 | 309 | | 8. "Designated methods for submitting requests " means a mailing |
---|
310 | 310 | | address, email address, Internet web page, Internet web portal, |
---|
311 | 311 | | telephone number, or other applicable c ontact information, whereby |
---|
312 | 312 | | consumers may submit a request under this act; |
---|
313 | 313 | | 9. "Device" means any physical object that is capable of |
---|
314 | 314 | | connecting to the Internet, directly or i ndirectly, or to another |
---|
315 | 315 | | device; |
---|
316 | 316 | | |
---|
317 | 317 | | Req. No. 8440 Page 7 1 |
---|
318 | 318 | | 2 |
---|
319 | 319 | | 3 |
---|
320 | 320 | | 4 |
---|
321 | 321 | | 5 |
---|
322 | 322 | | 6 |
---|
323 | 323 | | 7 |
---|
324 | 324 | | 8 |
---|
325 | 325 | | 9 |
---|
326 | 326 | | 10 |
---|
327 | 327 | | 11 |
---|
328 | 328 | | 12 |
---|
329 | 329 | | 13 |
---|
330 | 330 | | 14 |
---|
331 | 331 | | 15 |
---|
332 | 332 | | 16 |
---|
333 | 333 | | 17 |
---|
334 | 334 | | 18 |
---|
335 | 335 | | 19 |
---|
336 | 336 | | 20 |
---|
337 | 337 | | 21 |
---|
338 | 338 | | 22 |
---|
339 | 339 | | 23 |
---|
340 | 340 | | 24 |
---|
341 | 341 | | |
---|
342 | 342 | | 10. "Intentionally interacts " means when the consumer intends |
---|
343 | 343 | | to interact with a person via one or more deliberate interactions, |
---|
344 | 344 | | such as visiting the person 's website or purchasing a good or |
---|
345 | 345 | | service from the person. Hovering over, muting, pausing, or closing |
---|
346 | 346 | | a given piece of content, or using a communi cations service to |
---|
347 | 347 | | interact with a third -party website, does not constitute a |
---|
348 | 348 | | consumer's intent to interact with a person ; |
---|
349 | 349 | | 11. "Operational purpose" means the use of personal information |
---|
350 | 350 | | when reasonably necessa ry and proportionate to achieve one of the |
---|
351 | 351 | | following purposes, if such usage is limited to the first -party |
---|
352 | 352 | | relationship and customer experience: |
---|
353 | 353 | | a. debugging to identify and repair errors that impair |
---|
354 | 354 | | existing intended functionality, |
---|
355 | 355 | | b. undertaking internal research for technological |
---|
356 | 356 | | development, analytics, and product improvement, based |
---|
357 | 357 | | on information collected by the business, |
---|
358 | 358 | | c. undertaking activities to verify or maintain the |
---|
359 | 359 | | quality or safety of a service or device that is |
---|
360 | 360 | | owned, manufactured, manufactu red for, or controlled |
---|
361 | 361 | | by the business, or to improve, upgrade, or enhance |
---|
362 | 362 | | the service or device that is owned, manufactured, |
---|
363 | 363 | | manufactured for, or controlled by the business, |
---|
364 | 364 | | d. customization of content based on information |
---|
365 | 365 | | collected by the business, or |
---|
366 | 366 | | |
---|
367 | 367 | | Req. No. 8440 Page 8 1 |
---|
368 | 368 | | 2 |
---|
369 | 369 | | 3 |
---|
370 | 370 | | 4 |
---|
371 | 371 | | 5 |
---|
372 | 372 | | 6 |
---|
373 | 373 | | 7 |
---|
374 | 374 | | 8 |
---|
375 | 375 | | 9 |
---|
376 | 376 | | 10 |
---|
377 | 377 | | 11 |
---|
378 | 378 | | 12 |
---|
379 | 379 | | 13 |
---|
380 | 380 | | 14 |
---|
381 | 381 | | 15 |
---|
382 | 382 | | 16 |
---|
383 | 383 | | 17 |
---|
384 | 384 | | 18 |
---|
385 | 385 | | 19 |
---|
386 | 386 | | 20 |
---|
387 | 387 | | 21 |
---|
388 | 388 | | 22 |
---|
389 | 389 | | 23 |
---|
390 | 390 | | 24 |
---|
391 | 391 | | |
---|
392 | 392 | | e. customization of advertising or marketing ba sed on |
---|
393 | 393 | | information collected by the business; |
---|
394 | 394 | | 12. "Person" means an individual, proprietorship, firm, |
---|
395 | 395 | | partnership, joint venture, syndicate, business trust, company, |
---|
396 | 396 | | corporation, limited liability company, asso ciation, committee, and |
---|
397 | 397 | | any other organizatio n or group of persons acting in concert ; |
---|
398 | 398 | | 13. "Personal information " means information that identifies or |
---|
399 | 399 | | could reasonably be linked, directly or indirectly, with a |
---|
400 | 400 | | particular consumer, household, or consumer de vice. Personal |
---|
401 | 401 | | information does not include publicly available information. For |
---|
402 | 402 | | the purposes of this paragraph, publicly available means information |
---|
403 | 403 | | that is lawfully mad e available from federal, state or local |
---|
404 | 404 | | government records. Personal information do es not include consumer |
---|
405 | 405 | | information that is d e-identified or aggregate consumer information; |
---|
406 | 406 | | 14. "Processing" means any operation or set of operations that |
---|
407 | 407 | | are performed on personal information or on sets of personal |
---|
408 | 408 | | information, whether or not by automat ed means; |
---|
409 | 409 | | 15. "Service" or "services" means work, labor, and services, |
---|
410 | 410 | | including services furnished in connection with the production, sale |
---|
411 | 411 | | or repair of goods; |
---|
412 | 412 | | 16. "Service provider" means a person who processes personal |
---|
413 | 413 | | information on behalf of a busine ss and to which the business |
---|
414 | 414 | | discloses a consumer's personal information pursuant to a written or |
---|
415 | 415 | | electronic contract, provided that: |
---|
416 | 416 | | |
---|
417 | 417 | | Req. No. 8440 Page 9 1 |
---|
418 | 418 | | 2 |
---|
419 | 419 | | 3 |
---|
420 | 420 | | 4 |
---|
421 | 421 | | 5 |
---|
422 | 422 | | 6 |
---|
423 | 423 | | 7 |
---|
424 | 424 | | 8 |
---|
425 | 425 | | 9 |
---|
426 | 426 | | 10 |
---|
427 | 427 | | 11 |
---|
428 | 428 | | 12 |
---|
429 | 429 | | 13 |
---|
430 | 430 | | 14 |
---|
431 | 431 | | 15 |
---|
432 | 432 | | 16 |
---|
433 | 433 | | 17 |
---|
434 | 434 | | 18 |
---|
435 | 435 | | 19 |
---|
436 | 436 | | 20 |
---|
437 | 437 | | 21 |
---|
438 | 438 | | 22 |
---|
439 | 439 | | 23 |
---|
440 | 440 | | 24 |
---|
441 | 441 | | |
---|
442 | 442 | | a. the contract prohibits the person from retaining, |
---|
443 | 443 | | using, or disclosing the personal information for any |
---|
444 | 444 | | purpose other than for the specific purpose of |
---|
445 | 445 | | performing the services specified in the contract for |
---|
446 | 446 | | the business, including a prohibition on retaining, |
---|
447 | 447 | | using, or disclosing the personal information for a |
---|
448 | 448 | | commercial purpose other than providing the services |
---|
449 | 449 | | specified in the contract with the business, and |
---|
450 | 450 | | b. the service provider does not combine the personal |
---|
451 | 451 | | information which the service provider receives from , |
---|
452 | 452 | | or on behalf of, the business with personal |
---|
453 | 453 | | information which the service provider receives from , |
---|
454 | 454 | | or on behalf of, another person or persons, or |
---|
455 | 455 | | collects from its own interaction with consumers; |
---|
456 | 456 | | 17. "Share" means renting, releasing, disclosing, |
---|
457 | 457 | | disseminating, making available, transferring, or otherwise |
---|
458 | 458 | | communicating orally, in writing, or by electronic or other me ans, a |
---|
459 | 459 | | consumer's personal information by the business to a third party for |
---|
460 | 460 | | monetary or other valuable consideration, or otherwise for a |
---|
461 | 461 | | commercial purpose. For purposes of this act, a business does not |
---|
462 | 462 | | share personal information when: |
---|
463 | 463 | | a. a consumer uses or directs the business to |
---|
464 | 464 | | intentionally disclose personal information or uses |
---|
465 | 465 | | the business to intentionally interact with one or |
---|
466 | 466 | | |
---|
467 | 467 | | Req. No. 8440 Page 10 1 |
---|
468 | 468 | | 2 |
---|
469 | 469 | | 3 |
---|
470 | 470 | | 4 |
---|
471 | 471 | | 5 |
---|
472 | 472 | | 6 |
---|
473 | 473 | | 7 |
---|
474 | 474 | | 8 |
---|
475 | 475 | | 9 |
---|
476 | 476 | | 10 |
---|
477 | 477 | | 11 |
---|
478 | 478 | | 12 |
---|
479 | 479 | | 13 |
---|
480 | 480 | | 14 |
---|
481 | 481 | | 15 |
---|
482 | 482 | | 16 |
---|
483 | 483 | | 17 |
---|
484 | 484 | | 18 |
---|
485 | 485 | | 19 |
---|
486 | 486 | | 20 |
---|
487 | 487 | | 21 |
---|
488 | 488 | | 22 |
---|
489 | 489 | | 23 |
---|
490 | 490 | | 24 |
---|
491 | 491 | | |
---|
492 | 492 | | more third parties, provided the third party or |
---|
493 | 493 | | parties do not also share the personal information, |
---|
494 | 494 | | unless that disclosure wou ld be consistent with the |
---|
495 | 495 | | provisions of this act, |
---|
496 | 496 | | b. the business discloses the personal information of a |
---|
497 | 497 | | consumer with a service provider and the business has |
---|
498 | 498 | | provided notice that the information is being used or |
---|
499 | 499 | | disclosed in its terms and conditions cons istent with |
---|
500 | 500 | | Section 5 of this act, and |
---|
501 | 501 | | c. when a business transfers to a third party the |
---|
502 | 502 | | personal information of a consumer as an asset that is |
---|
503 | 503 | | part of a merger, acquisition, bankruptcy, or other |
---|
504 | 504 | | transaction in which the third party assumes control |
---|
505 | 505 | | of all or part of the business; provided that |
---|
506 | 506 | | information is used or disclosed consistently with |
---|
507 | 507 | | this act. A third party may not materially alter how |
---|
508 | 508 | | it uses or discloses the personal information of a |
---|
509 | 509 | | consumer in a manner that is materially inconsistent |
---|
510 | 510 | | with the promises made at the time of collection ; |
---|
511 | 511 | | 18. "Third party" means a person who is not any of the |
---|
512 | 512 | | following: |
---|
513 | 513 | | a. the business with whom the consumer intentionally |
---|
514 | 514 | | interacts and that collects personal information from |
---|
515 | 515 | | |
---|
516 | 516 | | Req. No. 8440 Page 11 1 |
---|
517 | 517 | | 2 |
---|
518 | 518 | | 3 |
---|
519 | 519 | | 4 |
---|
520 | 520 | | 5 |
---|
521 | 521 | | 6 |
---|
522 | 522 | | 7 |
---|
523 | 523 | | 8 |
---|
524 | 524 | | 9 |
---|
525 | 525 | | 10 |
---|
526 | 526 | | 11 |
---|
527 | 527 | | 12 |
---|
528 | 528 | | 13 |
---|
529 | 529 | | 14 |
---|
530 | 530 | | 15 |
---|
531 | 531 | | 16 |
---|
532 | 532 | | 17 |
---|
533 | 533 | | 18 |
---|
534 | 534 | | 19 |
---|
535 | 535 | | 20 |
---|
536 | 536 | | 21 |
---|
537 | 537 | | 22 |
---|
538 | 538 | | 23 |
---|
539 | 539 | | 24 |
---|
540 | 540 | | |
---|
541 | 541 | | the consumer as part of the consumer 's current |
---|
542 | 542 | | interaction with the business under th is act, or |
---|
543 | 543 | | b. a service provider to whom the business discloses a |
---|
544 | 544 | | consumer's personal information pursuant to a written |
---|
545 | 545 | | contract, which includes a certification made by the |
---|
546 | 546 | | person receiving the personal informat ion that the |
---|
547 | 547 | | person understands the restricti ons created under this |
---|
548 | 548 | | act and will comply with them; and |
---|
549 | 549 | | 19. "Verifiable consumer request " means a request that is made |
---|
550 | 550 | | by a consumer, by a consumer on behalf of the consumer 's minor |
---|
551 | 551 | | child, or by a natural per son or a person registered with the |
---|
552 | 552 | | Secretary of State, authorized by the consumer to act on the |
---|
553 | 553 | | consumer's behalf, and that the business can reasonably verify. A |
---|
554 | 554 | | business is not obligated to provide any personal information to a |
---|
555 | 555 | | consumer pursuant to Section 8 of this act, to delete personal |
---|
556 | 556 | | information pursuant to Section 6 of this act, or to correct |
---|
557 | 557 | | inaccurate personal information pursuant to Section 9 of this act, |
---|
558 | 558 | | if the business cannot verify that the consumer making the request |
---|
559 | 559 | | is the consumer about w hom the business has collected personal |
---|
560 | 560 | | information or is a person authorized by the consumer to act on such |
---|
561 | 561 | | consumer's behalf. |
---|
562 | 562 | | SECTION 4. NEW LAW A new section of law to be codified |
---|
563 | 563 | | in the Oklahoma Statutes as Section 20m-4 of Title 74, unless there |
---|
564 | 564 | | is created a duplication i n numbering, reads as follows: |
---|
565 | 565 | | |
---|
566 | 566 | | Req. No. 8440 Page 12 1 |
---|
567 | 567 | | 2 |
---|
568 | 568 | | 3 |
---|
569 | 569 | | 4 |
---|
570 | 570 | | 5 |
---|
571 | 571 | | 6 |
---|
572 | 572 | | 7 |
---|
573 | 573 | | 8 |
---|
574 | 574 | | 9 |
---|
575 | 575 | | 10 |
---|
576 | 576 | | 11 |
---|
577 | 577 | | 12 |
---|
578 | 578 | | 13 |
---|
579 | 579 | | 14 |
---|
580 | 580 | | 15 |
---|
581 | 581 | | 16 |
---|
582 | 582 | | 17 |
---|
583 | 583 | | 18 |
---|
584 | 584 | | 19 |
---|
585 | 585 | | 20 |
---|
586 | 586 | | 21 |
---|
587 | 587 | | 22 |
---|
588 | 588 | | 23 |
---|
589 | 589 | | 24 |
---|
590 | 590 | | |
---|
591 | 591 | | The Attorney General shall be responsible for enforcing this |
---|
592 | 592 | | act. Any person, business, or service provider that violates this |
---|
593 | 593 | | act may be liable for a civil penalty of up to Seven Thousand Five |
---|
594 | 594 | | Hundred Dollars ($7,500.00) for each intentional violation and up to |
---|
595 | 595 | | Two Thousand Five Hundred D ollars ($2,500.00) for each unintentional |
---|
596 | 596 | | violation. The court may consider punitive damages in addition to |
---|
597 | 597 | | the statutorily provided damages if requested by the Attorney |
---|
598 | 598 | | General. Additionally, the Attorney General may seek injunctive |
---|
599 | 599 | | relief to prevent repe titive violations of this act. The Attorney |
---|
600 | 600 | | General shall be entitled to recover all reasonable fees and costs, |
---|
601 | 601 | | including any expert witne ss fees, if a prevailing party. Any funds |
---|
602 | 602 | | recovered under this statute shall be retained in a dedicated |
---|
603 | 603 | | revolving account for the Attorney General. |
---|
604 | 604 | | SECTION 5. NEW LAW A new section of law to be codified |
---|
605 | 605 | | in the Oklahoma Statutes as Sect ion 20m-5 of Title 74, unless there |
---|
606 | 606 | | is created a duplication in numbering, reads as follows: |
---|
607 | 607 | | A business covered by this act shall disclose the following |
---|
608 | 608 | | information to consumers in a clear and conspicuous manner in its |
---|
609 | 609 | | privacy policies, which shall be writ ten in plain language and shall |
---|
610 | 610 | | be available prior to any data collection, and shall be updated if |
---|
611 | 611 | | any terms or conditions change: |
---|
612 | 612 | | 1. The manner and method by which a consumer may exercise his |
---|
613 | 613 | | or her rights pursuant to Sections 6, 7, 8, and 9 of this act; |
---|
614 | 614 | | 2. The personal infor mation collected from consumers; |
---|
615 | 615 | | |
---|
616 | 616 | | Req. No. 8440 Page 13 1 |
---|
617 | 617 | | 2 |
---|
618 | 618 | | 3 |
---|
619 | 619 | | 4 |
---|
620 | 620 | | 5 |
---|
621 | 621 | | 6 |
---|
622 | 622 | | 7 |
---|
623 | 623 | | 8 |
---|
624 | 624 | | 9 |
---|
625 | 625 | | 10 |
---|
626 | 626 | | 11 |
---|
627 | 627 | | 12 |
---|
628 | 628 | | 13 |
---|
629 | 629 | | 14 |
---|
630 | 630 | | 15 |
---|
631 | 631 | | 16 |
---|
632 | 632 | | 17 |
---|
633 | 633 | | 18 |
---|
634 | 634 | | 19 |
---|
635 | 635 | | 20 |
---|
636 | 636 | | 21 |
---|
637 | 637 | | 22 |
---|
638 | 638 | | 23 |
---|
639 | 639 | | 24 |
---|
640 | 640 | | |
---|
641 | 641 | | 3. The reasons the business collects, discloses, or retains |
---|
642 | 642 | | personal information; |
---|
643 | 643 | | 4. Whether the business discloses personal information and, if |
---|
644 | 644 | | so, what information is disclosed and to whom ; |
---|
645 | 645 | | 5. Whether the business shares personal informatio n with |
---|
646 | 646 | | service providers and, if so, the categories of service providers ; |
---|
647 | 647 | | and |
---|
648 | 648 | | 6. The length of time that the business retains personal |
---|
649 | 649 | | information. |
---|
650 | 650 | | SECTION 6. NEW LAW A new section of la w to be codified |
---|
651 | 651 | | in the Oklahoma Statutes as Section 20m-6 of Title 74, unless there |
---|
652 | 652 | | is created a duplication in numbering, reads as follows: |
---|
653 | 653 | | A. A business covered by this act shall only collect and/or |
---|
654 | 654 | | share information with third parties that is reasonab ly necessary to |
---|
655 | 655 | | provide a good or service to a consumer who has requested the same |
---|
656 | 656 | | or is reasonably necessary for security purposes or fraud detection. |
---|
657 | 657 | | The monetization of personal information shall never be considered |
---|
658 | 658 | | reasonably necessary for any purpose . |
---|
659 | 659 | | B. A business covered by this a ct shall limit its use and |
---|
660 | 660 | | retention of a consumer 's personal information to that which is |
---|
661 | 661 | | reasonably necessary to provide a service or conduct an activity |
---|
662 | 662 | | that a consumer has requested or for a related operational purpose . |
---|
663 | 663 | | C. A business covered by this a ct shall apprise any consumer |
---|
664 | 664 | | whose data is collected that th e consumer has the right to opt out |
---|
665 | 665 | | |
---|
666 | 666 | | Req. No. 8440 Page 14 1 |
---|
667 | 667 | | 2 |
---|
668 | 668 | | 3 |
---|
669 | 669 | | 4 |
---|
670 | 670 | | 5 |
---|
671 | 671 | | 6 |
---|
672 | 672 | | 7 |
---|
673 | 673 | | 8 |
---|
674 | 674 | | 9 |
---|
675 | 675 | | 10 |
---|
676 | 676 | | 11 |
---|
677 | 677 | | 12 |
---|
678 | 678 | | 13 |
---|
679 | 679 | | 14 |
---|
680 | 680 | | 15 |
---|
681 | 681 | | 16 |
---|
682 | 682 | | 17 |
---|
683 | 683 | | 18 |
---|
684 | 684 | | 19 |
---|
685 | 685 | | 20 |
---|
686 | 686 | | 21 |
---|
687 | 687 | | 22 |
---|
688 | 688 | | 23 |
---|
689 | 689 | | 24 |
---|
690 | 690 | | |
---|
691 | 691 | | of personalized advertising and the business shall have the duty to |
---|
692 | 692 | | comply with the request promptly and free of charge. Such |
---|
693 | 693 | | notification shall be made in a clear and c onspicuous manner on the |
---|
694 | 694 | | business's homepage. |
---|
695 | 695 | | SECTION 7. NEW LAW A new section of law to be codified |
---|
696 | 696 | | in the Oklahoma Statutes as Section 20m-7 of Title 74, unless there |
---|
697 | 697 | | is created a duplication in numbering, reads as follows: |
---|
698 | 698 | | A. Consumers have the right to request that a business delete |
---|
699 | 699 | | any personal information retained by the business about the |
---|
700 | 700 | | consumer, and a business covered by this act shall inform consumers |
---|
701 | 701 | | of such right in accordanc e with Section 5 of this act. |
---|
702 | 702 | | B. Upon receipt of a verifiable consumer request to delete a |
---|
703 | 703 | | consumer's personal information, a business shall delete the |
---|
704 | 704 | | personal information from its records and advise any service |
---|
705 | 705 | | providers holding the consumer 's personal information to delete the |
---|
706 | 706 | | consumer's personal information as well. |
---|
707 | 707 | | C. If the consumer's personal information is necessary : |
---|
708 | 708 | | 1. To complete the transaction tha t was requested by the |
---|
709 | 709 | | consumer; |
---|
710 | 710 | | 2. To fulfill contractual obligations between the consumer and |
---|
711 | 711 | | the business; |
---|
712 | 712 | | 3. To detect or act upon secur ity threats, including malicious |
---|
713 | 713 | | or illegal activities, to prosecute individuals respo nsible for |
---|
714 | 714 | | security threats; |
---|
715 | 715 | | |
---|
716 | 716 | | Req. No. 8440 Page 15 1 |
---|
717 | 717 | | 2 |
---|
718 | 718 | | 3 |
---|
719 | 719 | | 4 |
---|
720 | 720 | | 5 |
---|
721 | 721 | | 6 |
---|
722 | 722 | | 7 |
---|
723 | 723 | | 8 |
---|
724 | 724 | | 9 |
---|
725 | 725 | | 10 |
---|
726 | 726 | | 11 |
---|
727 | 727 | | 12 |
---|
728 | 728 | | 13 |
---|
729 | 729 | | 14 |
---|
730 | 730 | | 15 |
---|
731 | 731 | | 16 |
---|
732 | 732 | | 17 |
---|
733 | 733 | | 18 |
---|
734 | 734 | | 19 |
---|
735 | 735 | | 20 |
---|
736 | 736 | | 21 |
---|
737 | 737 | | 22 |
---|
738 | 738 | | 23 |
---|
739 | 739 | | 24 |
---|
740 | 740 | | |
---|
741 | 741 | | 4. To ensure quality control functions ; |
---|
742 | 742 | | 5. To exercise constitutionally protected speech; |
---|
743 | 743 | | 6. To engage in public- or peer-reviewed research that adheres |
---|
744 | 744 | | to all applicable ethics and privacy laws; or |
---|
745 | 745 | | 7. To comply with legal obligations, |
---|
746 | 746 | | then the business shall have the right to reject such consumer 's |
---|
747 | 747 | | request and shall advise the consumer of the re ason why such request |
---|
748 | 748 | | was rejected. |
---|
749 | 749 | | SECTION 8. NEW LAW A new section of law to be codified |
---|
750 | 750 | | in the Oklahoma Statutes as Section 20m-8 of Title 74, unless there |
---|
751 | 751 | | is created a duplication in numbering, reads as follows: |
---|
752 | 752 | | After receiving a verifiable consumer request from a consumer |
---|
753 | 753 | | requesting to know what information is retained by a business about |
---|
754 | 754 | | the consumer, the business shall disclose the specific personal |
---|
755 | 755 | | information retained by the business about the consumer. Such |
---|
756 | 756 | | disclosure shall be in an electronic, portable , machine-readable, |
---|
757 | 757 | | and readily useable format to the consumer. Additionally, to the |
---|
758 | 758 | | extent the business has disclosed personal information of a consumer |
---|
759 | 759 | | to a third party or service provider, said business shall disclose, |
---|
760 | 760 | | in the same manner and method as previously des cribed, the names and |
---|
761 | 761 | | contact information of such third parties or service providers. |
---|
762 | 762 | | SECTION 9. NEW LAW A new section of law to be codified |
---|
763 | 763 | | in the Oklahoma Statutes as Section 20m-9 of Title 74, unless there |
---|
764 | 764 | | is created a duplicatio n in numbering, reads as follows: |
---|
765 | 765 | | |
---|
766 | 766 | | Req. No. 8440 Page 16 1 |
---|
767 | 767 | | 2 |
---|
768 | 768 | | 3 |
---|
769 | 769 | | 4 |
---|
770 | 770 | | 5 |
---|
771 | 771 | | 6 |
---|
772 | 772 | | 7 |
---|
773 | 773 | | 8 |
---|
774 | 774 | | 9 |
---|
775 | 775 | | 10 |
---|
776 | 776 | | 11 |
---|
777 | 777 | | 12 |
---|
778 | 778 | | 13 |
---|
779 | 779 | | 14 |
---|
780 | 780 | | 15 |
---|
781 | 781 | | 16 |
---|
782 | 782 | | 17 |
---|
783 | 783 | | 18 |
---|
784 | 784 | | 19 |
---|
785 | 785 | | 20 |
---|
786 | 786 | | 21 |
---|
787 | 787 | | 22 |
---|
788 | 788 | | 23 |
---|
789 | 789 | | 24 |
---|
790 | 790 | | |
---|
791 | 791 | | A business shall advise a consumer, in accordance with Section |
---|
792 | 792 | | 11 of this act that the consumer has the right to request correction |
---|
793 | 793 | | of inaccurate personal information, and a con sumer shall have the |
---|
794 | 794 | | right to require a busin ess to correct such inaccurate information. |
---|
795 | 795 | | Upon receipt of a verifiable consumer request, a business shall take |
---|
796 | 796 | | all reasonable steps to correct the inaccurate information, in |
---|
797 | 797 | | accordance with Section 11 of this act. |
---|
798 | 798 | | SECTION 10. NEW LAW A new section of law to be codified |
---|
799 | 799 | | in the Oklahoma Statutes as Section 20m-10 of Title 74, unless there |
---|
800 | 800 | | is created a duplication in numbering, reads as follows: |
---|
801 | 801 | | No business shall deny goods or services to a consumer by virtue |
---|
802 | 802 | | of the consumer's exercise of any rights in this act. Further, no |
---|
803 | 803 | | business shall charge a different price or provide a different |
---|
804 | 804 | | quality of service or good by virtue of the consumer 's exercise of |
---|
805 | 805 | | any rights under this act. Provided, a business may offer |
---|
806 | 806 | | discounted or free goods or services to a consumer if the consumer |
---|
807 | 807 | | voluntarily participates in a program that rewards consumers for |
---|
808 | 808 | | repeated transactions with the business and if the business does not |
---|
809 | 809 | | share the consumer's data with third parties. |
---|
810 | 810 | | SECTION 11. NEW LAW A new section of law to be codified |
---|
811 | 811 | | in the Oklahoma Statutes as Section 20m-11 of Title 74, unless there |
---|
812 | 812 | | is created a duplication in numbering, reads as follows: |
---|
813 | 813 | | A. A business covered by this act shall provide at least two |
---|
814 | 814 | | points of contact that are easily accessible and readily |
---|
815 | 815 | | |
---|
816 | 816 | | Req. No. 8440 Page 17 1 |
---|
817 | 817 | | 2 |
---|
818 | 818 | | 3 |
---|
819 | 819 | | 4 |
---|
820 | 820 | | 5 |
---|
821 | 821 | | 6 |
---|
822 | 822 | | 7 |
---|
823 | 823 | | 8 |
---|
824 | 824 | | 9 |
---|
825 | 825 | | 10 |
---|
826 | 826 | | 11 |
---|
827 | 827 | | 12 |
---|
828 | 828 | | 13 |
---|
829 | 829 | | 14 |
---|
830 | 830 | | 15 |
---|
831 | 831 | | 16 |
---|
832 | 832 | | 17 |
---|
833 | 833 | | 18 |
---|
834 | 834 | | 19 |
---|
835 | 835 | | 20 |
---|
836 | 836 | | 21 |
---|
837 | 837 | | 22 |
---|
838 | 838 | | 23 |
---|
839 | 839 | | 24 |
---|
840 | 840 | | |
---|
841 | 841 | | identifiable by which a consumer may make the requests permitted |
---|
842 | 842 | | under this act, at least one of which must be the business 's |
---|
843 | 843 | | website, unless a business covered by this act does not have a |
---|
844 | 844 | | website, in which case the busine ss must provide a telephone number |
---|
845 | 845 | | as one of the two methods by which a co nsumer may contact the |
---|
846 | 846 | | business. |
---|
847 | 847 | | B. Any disclosure and/or delivery of information from a |
---|
848 | 848 | | business to a consumer under this act must be provided free of |
---|
849 | 849 | | charge and within forty-five (45) days of receipt of a verifiable |
---|
850 | 850 | | consumer request. If it is not reasonably possible to provide the |
---|
851 | 851 | | information within forty-five (45) days, the business may extend the |
---|
852 | 852 | | deadline by forty-five (45) days by providing notice to the consumer |
---|
853 | 853 | | of such election and the basis for the same . |
---|
854 | 854 | | C. If personal information is collected by a business to verify |
---|
855 | 855 | | the consumer's identity, then that personal information is limited |
---|
856 | 856 | | in usage solely to the verification process and shall thereafter be |
---|
857 | 857 | | permanently deleted. |
---|
858 | 858 | | D. A business is not obligated to provide the inf ormation |
---|
859 | 859 | | identified in Section 8 of this act more than twice during any |
---|
860 | 860 | | twelve-month period for each consumer . |
---|
861 | 861 | | E. A business or service provider shall implement and maintain |
---|
862 | 862 | | reasonable security procedures and practices, including |
---|
863 | 863 | | administrative, physical, and technical safeguards, appropriate to |
---|
864 | 864 | | the nature of the information and the purposes for which the |
---|
865 | 865 | | |
---|
866 | 866 | | Req. No. 8440 Page 18 1 |
---|
867 | 867 | | 2 |
---|
868 | 868 | | 3 |
---|
869 | 869 | | 4 |
---|
870 | 870 | | 5 |
---|
871 | 871 | | 6 |
---|
872 | 872 | | 7 |
---|
873 | 873 | | 8 |
---|
874 | 874 | | 9 |
---|
875 | 875 | | 10 |
---|
876 | 876 | | 11 |
---|
877 | 877 | | 12 |
---|
878 | 878 | | 13 |
---|
879 | 879 | | 14 |
---|
880 | 880 | | 15 |
---|
881 | 881 | | 16 |
---|
882 | 882 | | 17 |
---|
883 | 883 | | 18 |
---|
884 | 884 | | 19 |
---|
885 | 885 | | 20 |
---|
886 | 886 | | 21 |
---|
887 | 887 | | 22 |
---|
888 | 888 | | 23 |
---|
889 | 889 | | 24 |
---|
890 | 890 | | |
---|
891 | 891 | | personal information will be used, to protect consumers ' personal |
---|
892 | 892 | | information from unauthorized use, disclo sure, access, destruction, |
---|
893 | 893 | | or modification. |
---|
894 | 894 | | SECTION 12. NEW LAW A new section of law to be codified |
---|
895 | 895 | | in the Oklahoma Statutes as Section 20m-12 of Title 74, unless there |
---|
896 | 896 | | is created a duplication in numbering, reads as follows: |
---|
897 | 897 | | A. The obligations imposed on businesses by this act shall not |
---|
898 | 898 | | restrict a business's or service provider 's ability to: |
---|
899 | 899 | | 1. Comply with federal, state, or local laws ; |
---|
900 | 900 | | 2. Comply with a civil, criminal, or regulato ry inquiry, |
---|
901 | 901 | | investigation, subpoena, or summons b y federal, state, or local |
---|
902 | 902 | | authorities; |
---|
903 | 903 | | 3. Cooperate with law enforcement agencies concerning conduct |
---|
904 | 904 | | or activity that the business, service provider, or third party |
---|
905 | 905 | | reasonably and in good faith believes ma y violate federal, state, or |
---|
906 | 906 | | local law; |
---|
907 | 907 | | 4. Exercise or defend legal claims ; |
---|
908 | 908 | | 5. Collect, use, retain, share, or disclose consumer |
---|
909 | 909 | | information that is de -identified or in the aggregate de rived from |
---|
910 | 910 | | personal information; and |
---|
911 | 911 | | 6. Collect or share a consumer 's personal information if every |
---|
912 | 912 | | aspect of that commercial conduct takes place wholly outside of the |
---|
913 | 913 | | State of Oklahoma. For purposes of this act, commercial conduct |
---|
914 | 914 | | takes place wholly outside of the State of Oklahoma if a business |
---|
915 | 915 | | |
---|
916 | 916 | | Req. No. 8440 Page 19 1 |
---|
917 | 917 | | 2 |
---|
918 | 918 | | 3 |
---|
919 | 919 | | 4 |
---|
920 | 920 | | 5 |
---|
921 | 921 | | 6 |
---|
922 | 922 | | 7 |
---|
923 | 923 | | 8 |
---|
924 | 924 | | 9 |
---|
925 | 925 | | 10 |
---|
926 | 926 | | 11 |
---|
927 | 927 | | 12 |
---|
928 | 928 | | 13 |
---|
929 | 929 | | 14 |
---|
930 | 930 | | 15 |
---|
931 | 931 | | 16 |
---|
932 | 932 | | 17 |
---|
933 | 933 | | 18 |
---|
934 | 934 | | 19 |
---|
935 | 935 | | 20 |
---|
936 | 936 | | 21 |
---|
937 | 937 | | 22 |
---|
938 | 938 | | 23 |
---|
939 | 939 | | 24 |
---|
940 | 940 | | |
---|
941 | 941 | | collected that informatio n while the consumer was present outside of |
---|
942 | 942 | | the State of Oklahoma, no part of the sharing of the consumer 's |
---|
943 | 943 | | personal information occurred in the State of Oklahoma, and no |
---|
944 | 944 | | personal information was collected while the consumer was present in |
---|
945 | 945 | | the State of Oklahoma is shared. This paragraph shall not permit a |
---|
946 | 946 | | business from storing, including on a device, personal information |
---|
947 | 947 | | about a consumer when the consumer is present in the S tate of |
---|
948 | 948 | | Oklahoma and then later collecting that personal information when |
---|
949 | 949 | | the consumer and stored personal information is located outside of |
---|
950 | 950 | | the State of Oklahoma. |
---|
951 | 951 | | B. Nothing in this act shall require a business to violate an |
---|
952 | 952 | | evidentiary privilege under Oklahoma law or federal law , or prevent |
---|
953 | 953 | | a business from providing the personal info rmation of a consumer who |
---|
954 | 954 | | is covered by an evident iary privilege under Oklahoma law as part of |
---|
955 | 955 | | a privileged communication. |
---|
956 | 956 | | C. 1. This act shall not apply to any of the following: |
---|
957 | 957 | | a. protected health information that is collected by a |
---|
958 | 958 | | covered entity or bu siness associate governed by the |
---|
959 | 959 | | privacy, security, and breach notification rules |
---|
960 | 960 | | issued by the United States Department of Health and |
---|
961 | 961 | | Human Services, Parts 160 and 164 of Title 45 of the |
---|
962 | 962 | | Code of Federal Regulations, established pursuant to |
---|
963 | 963 | | the Health Insurance Portability and Accountability |
---|
964 | 964 | | Act of 1996 (Public Law 104-191) and the Health |
---|
965 | 965 | | |
---|
966 | 966 | | Req. No. 8440 Page 20 1 |
---|
967 | 967 | | 2 |
---|
968 | 968 | | 3 |
---|
969 | 969 | | 4 |
---|
970 | 970 | | 5 |
---|
971 | 971 | | 6 |
---|
972 | 972 | | 7 |
---|
973 | 973 | | 8 |
---|
974 | 974 | | 9 |
---|
975 | 975 | | 10 |
---|
976 | 976 | | 11 |
---|
977 | 977 | | 12 |
---|
978 | 978 | | 13 |
---|
979 | 979 | | 14 |
---|
980 | 980 | | 15 |
---|
981 | 981 | | 16 |
---|
982 | 982 | | 17 |
---|
983 | 983 | | 18 |
---|
984 | 984 | | 19 |
---|
985 | 985 | | 20 |
---|
986 | 986 | | 21 |
---|
987 | 987 | | 22 |
---|
988 | 988 | | 23 |
---|
989 | 989 | | 24 |
---|
990 | 990 | | |
---|
991 | 991 | | Information Technology for Economic and Clinical |
---|
992 | 992 | | Health Act (Public Law 111 -5), |
---|
993 | 993 | | b. a covered entity governed by the privacy, security, |
---|
994 | 994 | | and breach notification rules issued by the United |
---|
995 | 995 | | States Department of Health and Hum an Services, Parts |
---|
996 | 996 | | 160 and 164 of Title 45 of the Code of Federal |
---|
997 | 997 | | Regulations, established pursuant to the Health |
---|
998 | 998 | | Insurance Portability and Accountability Act of 1996 |
---|
999 | 999 | | (Public Law 104-191), to the extent the provider or |
---|
1000 | 1000 | | covered entity maintains patient info rmation in the |
---|
1001 | 1001 | | same manner as medical information or protected health |
---|
1002 | 1002 | | information as described in subparagraph a of this |
---|
1003 | 1003 | | paragraph, and |
---|
1004 | 1004 | | c. personal information collected as part of a clinical |
---|
1005 | 1005 | | trial subject to the Federal Policy for the Protection |
---|
1006 | 1006 | | of Human Subjects, also known as the Common Rule, |
---|
1007 | 1007 | | pursuant to good clinical practice guidelines issued |
---|
1008 | 1008 | | by the International Council for Harmonisation of |
---|
1009 | 1009 | | Technical Requirements for Human Use or pursuant to |
---|
1010 | 1010 | | human subject protection requirements of the United |
---|
1011 | 1011 | | States Food and Drug Administration. |
---|
1012 | 1012 | | 2. For purposes of this subsection, the definition of "medical |
---|
1013 | 1013 | | information" means any individually identifiable information, in |
---|
1014 | 1014 | | electronic or physical form, in possession of or derived from a |
---|
1015 | 1015 | | |
---|
1016 | 1016 | | Req. No. 8440 Page 21 1 |
---|
1017 | 1017 | | 2 |
---|
1018 | 1018 | | 3 |
---|
1019 | 1019 | | 4 |
---|
1020 | 1020 | | 5 |
---|
1021 | 1021 | | 6 |
---|
1022 | 1022 | | 7 |
---|
1023 | 1023 | | 8 |
---|
1024 | 1024 | | 9 |
---|
1025 | 1025 | | 10 |
---|
1026 | 1026 | | 11 |
---|
1027 | 1027 | | 12 |
---|
1028 | 1028 | | 13 |
---|
1029 | 1029 | | 14 |
---|
1030 | 1030 | | 15 |
---|
1031 | 1031 | | 16 |
---|
1032 | 1032 | | 17 |
---|
1033 | 1033 | | 18 |
---|
1034 | 1034 | | 19 |
---|
1035 | 1035 | | 20 |
---|
1036 | 1036 | | 21 |
---|
1037 | 1037 | | 22 |
---|
1038 | 1038 | | 23 |
---|
1039 | 1039 | | 24 |
---|
1040 | 1040 | | |
---|
1041 | 1041 | | provider of health care, health ca re service plan, pharmaceutical |
---|
1042 | 1042 | | company, or contractor regarding a patient's medical history, mental |
---|
1043 | 1043 | | or physical condition, or treatment. "Individually identifiable" |
---|
1044 | 1044 | | means that the medical information inclu des or contains any element |
---|
1045 | 1045 | | of personal identifyi ng information sufficient to allow |
---|
1046 | 1046 | | identification of the individual, such as the patient's name, |
---|
1047 | 1047 | | address, electronic mail address, telephone number, or Social |
---|
1048 | 1048 | | Security number, or other information that, alon e or in combination |
---|
1049 | 1049 | | with other publicly available information, reveals the individual's |
---|
1050 | 1050 | | identity. Furthermore, the definitions of "business associate", |
---|
1051 | 1051 | | "covered entity", and "protected health information " in Section |
---|
1052 | 1052 | | 160.103 of Title 45 of the Code of Fede ral Regulations shall apply. |
---|
1053 | 1053 | | D. This act shall not apply to activity involving the |
---|
1054 | 1054 | | collection, maintenance, disclosure, sale, communication, or use of |
---|
1055 | 1055 | | any personal information bearing on a consumer 's credit worthiness, |
---|
1056 | 1056 | | credit standing, credit capacity, ch aracter, general reputation, |
---|
1057 | 1057 | | personal characteris tics, or mode of living by a consumer reporting |
---|
1058 | 1058 | | agency, as defined by subdivision (f) of Section 1681a of Title 15 |
---|
1059 | 1059 | | of the United States Code, by a furnisher of information, as set |
---|
1060 | 1060 | | forth in Section 1681s -2 of Title 15 of the United States Code, who |
---|
1061 | 1061 | | provides information for use in a consumer report, as defined in |
---|
1062 | 1062 | | subdivision (d) of Section 1681a of Title 15 of the United States |
---|
1063 | 1063 | | Code, and by a user of a consumer report as set forth in Section |
---|
1064 | 1064 | | 1681b of Title 15 of the United States Code. This subsection shall |
---|
1065 | 1065 | | |
---|
1066 | 1066 | | Req. No. 8440 Page 22 1 |
---|
1067 | 1067 | | 2 |
---|
1068 | 1068 | | 3 |
---|
1069 | 1069 | | 4 |
---|
1070 | 1070 | | 5 |
---|
1071 | 1071 | | 6 |
---|
1072 | 1072 | | 7 |
---|
1073 | 1073 | | 8 |
---|
1074 | 1074 | | 9 |
---|
1075 | 1075 | | 10 |
---|
1076 | 1076 | | 11 |
---|
1077 | 1077 | | 12 |
---|
1078 | 1078 | | 13 |
---|
1079 | 1079 | | 14 |
---|
1080 | 1080 | | 15 |
---|
1081 | 1081 | | 16 |
---|
1082 | 1082 | | 17 |
---|
1083 | 1083 | | 18 |
---|
1084 | 1084 | | 19 |
---|
1085 | 1085 | | 20 |
---|
1086 | 1086 | | 21 |
---|
1087 | 1087 | | 22 |
---|
1088 | 1088 | | 23 |
---|
1089 | 1089 | | 24 |
---|
1090 | 1090 | | |
---|
1091 | 1091 | | only apply to the extent that such activity involving the |
---|
1092 | 1092 | | collection, maintenance, disclosure, sale, communication, or use of |
---|
1093 | 1093 | | such information by that agency, furnisher, or user is subject to |
---|
1094 | 1094 | | regulation under the Fair Credit Reporting Act, Section 1681 et seq. |
---|
1095 | 1095 | | of Title 15 of the United States Code and the information is not |
---|
1096 | 1096 | | collected, maintained, disclosed, sold, communicated, or used except |
---|
1097 | 1097 | | as authorized by the Fair Credit Reporting Act. |
---|
1098 | 1098 | | E. This act shall not apply to personal information collected, |
---|
1099 | 1099 | | processed, sold, or disclosed pursuant to the federal Gramm -Leach- |
---|
1100 | 1100 | | Bliley Act (Public Law 106 -102), and implementing regulations. |
---|
1101 | 1101 | | F. This act shall not apply to personal information collected, |
---|
1102 | 1102 | | processed, sold, or disclosed pursuant to the Driver 's Privacy |
---|
1103 | 1103 | | Protection Act of 1994 (18 U.S.C. Sec. 2721 et seq.) ; |
---|
1104 | 1104 | | G. Notwithstanding a business 's obligations to respond to and |
---|
1105 | 1105 | | honor consumer rights requ ests pursuant to this title: |
---|
1106 | 1106 | | 1. If a business does not take action o n the request of a |
---|
1107 | 1107 | | consumer, the business shall i nform the consumer, without delay and |
---|
1108 | 1108 | | at the latest within the time period permitted by this act, of the |
---|
1109 | 1109 | | reasons for not taking action and any rights the consumer may have |
---|
1110 | 1110 | | to appeal the decision to the busin ess; |
---|
1111 | 1111 | | 2. If requests from a consumer are manifest ly unfounded or |
---|
1112 | 1112 | | excessive, in particular because of his or her repetitive character, |
---|
1113 | 1113 | | a business may either charge a reasonable fee, taking into account |
---|
1114 | 1114 | | the administrative costs of providing the information o r |
---|
1115 | 1115 | | |
---|
1116 | 1116 | | Req. No. 8440 Page 23 1 |
---|
1117 | 1117 | | 2 |
---|
1118 | 1118 | | 3 |
---|
1119 | 1119 | | 4 |
---|
1120 | 1120 | | 5 |
---|
1121 | 1121 | | 6 |
---|
1122 | 1122 | | 7 |
---|
1123 | 1123 | | 8 |
---|
1124 | 1124 | | 9 |
---|
1125 | 1125 | | 10 |
---|
1126 | 1126 | | 11 |
---|
1127 | 1127 | | 12 |
---|
1128 | 1128 | | 13 |
---|
1129 | 1129 | | 14 |
---|
1130 | 1130 | | 15 |
---|
1131 | 1131 | | 16 |
---|
1132 | 1132 | | 17 |
---|
1133 | 1133 | | 18 |
---|
1134 | 1134 | | 19 |
---|
1135 | 1135 | | 20 |
---|
1136 | 1136 | | 21 |
---|
1137 | 1137 | | 22 |
---|
1138 | 1138 | | 23 |
---|
1139 | 1139 | | 24 |
---|
1140 | 1140 | | |
---|
1141 | 1141 | | communication or taking the action requested, o r refuse to act on |
---|
1142 | 1142 | | the request and notify the consumer of the reason for refusing the |
---|
1143 | 1143 | | request. The business shall bear the burden of demonstrating that |
---|
1144 | 1144 | | any verifiable consumer request is manifestly unfounde d or |
---|
1145 | 1145 | | excessive. |
---|
1146 | 1146 | | H. A business that discloses per sonal information to a service |
---|
1147 | 1147 | | provider in compliance with this act shall select as service |
---|
1148 | 1148 | | providers entities that are capable of adhering to the restrictions |
---|
1149 | 1149 | | set forth in this act, and enforce compliance i n adhering to these |
---|
1150 | 1150 | | restrictions, through effecti ve enforceable contractual obligations |
---|
1151 | 1151 | | and regular evaluation of compliance. A service provider shall not |
---|
1152 | 1152 | | be liable under this title for the obligations of a business for |
---|
1153 | 1153 | | which it provides services as set forth in this act; provided that |
---|
1154 | 1154 | | the service provider shall be liable for its own violations of this |
---|
1155 | 1155 | | act. |
---|
1156 | 1156 | | I. This act shall not be constru ed to require a business to: |
---|
1157 | 1157 | | 1. Comply with a verifiable consumer request to access, delete, |
---|
1158 | 1158 | | or correct personal info rmation pursuant to Sections 7, 8, or 9 of |
---|
1159 | 1159 | | this act if all of the following are true: |
---|
1160 | 1160 | | a. (1) the business is not reasonably capable of linking |
---|
1161 | 1161 | | or associating the request with the personal |
---|
1162 | 1162 | | information, or |
---|
1163 | 1163 | | |
---|
1164 | 1164 | | Req. No. 8440 Page 24 1 |
---|
1165 | 1165 | | 2 |
---|
1166 | 1166 | | 3 |
---|
1167 | 1167 | | 4 |
---|
1168 | 1168 | | 5 |
---|
1169 | 1169 | | 6 |
---|
1170 | 1170 | | 7 |
---|
1171 | 1171 | | 8 |
---|
1172 | 1172 | | 9 |
---|
1173 | 1173 | | 10 |
---|
1174 | 1174 | | 11 |
---|
1175 | 1175 | | 12 |
---|
1176 | 1176 | | 13 |
---|
1177 | 1177 | | 14 |
---|
1178 | 1178 | | 15 |
---|
1179 | 1179 | | 16 |
---|
1180 | 1180 | | 17 |
---|
1181 | 1181 | | 18 |
---|
1182 | 1182 | | 19 |
---|
1183 | 1183 | | 20 |
---|
1184 | 1184 | | 21 |
---|
1185 | 1185 | | 22 |
---|
1186 | 1186 | | 23 |
---|
1187 | 1187 | | 24 |
---|
1188 | 1188 | | |
---|
1189 | 1189 | | (2) it would be unreasonably burdensome for the |
---|
1190 | 1190 | | business to link or associate the request wit h |
---|
1191 | 1191 | | the personal information , |
---|
1192 | 1192 | | b. the business does not use the information to recognize |
---|
1193 | 1193 | | or respond to the specific consumer who is the subject |
---|
1194 | 1194 | | of the personal information or link or associate the |
---|
1195 | 1195 | | personal information with other personal information |
---|
1196 | 1196 | | about the same specific consumer, and |
---|
1197 | 1197 | | c. the business does not share the personal information |
---|
1198 | 1198 | | to any third party, or otherwise voluntarily disclose |
---|
1199 | 1199 | | the personal information to any third party other than |
---|
1200 | 1200 | | a service provider except as otherwise permitted in |
---|
1201 | 1201 | | this subsection. |
---|
1202 | 1202 | | 2. Maintain information in identifiable, linkable or associable |
---|
1203 | 1203 | | form, or to collect, obtain, retain, or access any data or |
---|
1204 | 1204 | | technology, in order to be capable of linking or associating a |
---|
1205 | 1205 | | verifiable consumer request with personal information. |
---|
1206 | 1206 | | J. Nothing herein shall apply to the publication of newsworthy |
---|
1207 | 1207 | | information to the public, or to the collection or editing of |
---|
1208 | 1208 | | information for that purpose. |
---|
1209 | 1209 | | SECTION 13. NEW LAW A new section of law to be codified |
---|
1210 | 1210 | | in the Oklahoma Statutes as Secti on 20m-13 of Title 74, unless there |
---|
1211 | 1211 | | is created a duplication in numbering, reads as follows: |
---|
1212 | 1212 | | |
---|
1213 | 1213 | | Req. No. 8440 Page 25 1 |
---|
1214 | 1214 | | 2 |
---|
1215 | 1215 | | 3 |
---|
1216 | 1216 | | 4 |
---|
1217 | 1217 | | 5 |
---|
1218 | 1218 | | 6 |
---|
1219 | 1219 | | 7 |
---|
1220 | 1220 | | 8 |
---|
1221 | 1221 | | 9 |
---|
1222 | 1222 | | 10 |
---|
1223 | 1223 | | 11 |
---|
1224 | 1224 | | 12 |
---|
1225 | 1225 | | 13 |
---|
1226 | 1226 | | 14 |
---|
1227 | 1227 | | 15 |
---|
1228 | 1228 | | 16 |
---|
1229 | 1229 | | 17 |
---|
1230 | 1230 | | 18 |
---|
1231 | 1231 | | 19 |
---|
1232 | 1232 | | 20 |
---|
1233 | 1233 | | 21 |
---|
1234 | 1234 | | 22 |
---|
1235 | 1235 | | 23 |
---|
1236 | 1236 | | 24 |
---|
1237 | 1237 | | |
---|
1238 | 1238 | | If a series of steps or transactions were component parts of a |
---|
1239 | 1239 | | single transaction intended from the beginning to b e taken with the |
---|
1240 | 1240 | | intention of avoiding the reach of this title, a court shall |
---|
1241 | 1241 | | disregard the intermediate steps or transactions for purposes of |
---|
1242 | 1242 | | effectuating the purposes of this title. |
---|
1243 | 1243 | | SECTION 14. NEW LAW A new section of law to be co dified |
---|
1244 | 1244 | | in the Oklahoma Statutes as Section 20m-14 of Title 74, unless there |
---|
1245 | 1245 | | is created a duplication in numbering, reads as follows: |
---|
1246 | 1246 | | Any provision of a contract or agreement of any kind, including |
---|
1247 | 1247 | | an arbitration agreement, that purports to waive or limit i n any way |
---|
1248 | 1248 | | rights under this title, including, but not limited to, any right to |
---|
1249 | 1249 | | a remedy or means of enforcement, shall be deemed contrary to public |
---|
1250 | 1250 | | policy and shall be void and unenforceable. |
---|
1251 | 1251 | | SECTION 15. NEW LAW A new section of law to be codified |
---|
1252 | 1252 | | in the Oklahoma Statutes as Sectio n 20m-15 of Title 74, unless there |
---|
1253 | 1253 | | is created a duplication in numbering, reads as follows: |
---|
1254 | 1254 | | It shall be unlawful for any company to design, modify, or |
---|
1255 | 1255 | | manipulate a user interface with the purpose or substant ial effect |
---|
1256 | 1256 | | of obscuring, subverting, or impairing user autonomy, decision - |
---|
1257 | 1257 | | making, or choice, as further defined by regulation. |
---|
1258 | 1258 | | SECTION 16. The provisions of this act are severable and if any |
---|
1259 | 1259 | | part or provision shall be held void the decision of the court so |
---|
1260 | 1260 | | holding shall not affect or impa ir any of the remaining parts or |
---|
1261 | 1261 | | provisions of this act. |
---|
1262 | 1262 | | |
---|
1263 | 1263 | | Req. No. 8440 Page 26 1 |
---|
1264 | 1264 | | 2 |
---|
1265 | 1265 | | 3 |
---|
1266 | 1266 | | 4 |
---|
1267 | 1267 | | 5 |
---|
1268 | 1268 | | 6 |
---|
1269 | 1269 | | 7 |
---|
1270 | 1270 | | 8 |
---|
1271 | 1271 | | 9 |
---|
1272 | 1272 | | 10 |
---|
1273 | 1273 | | 11 |
---|
1274 | 1274 | | 12 |
---|
1275 | 1275 | | 13 |
---|
1276 | 1276 | | 14 |
---|
1277 | 1277 | | 15 |
---|
1278 | 1278 | | 16 |
---|
1279 | 1279 | | 17 |
---|
1280 | 1280 | | 18 |
---|
1281 | 1281 | | 19 |
---|
1282 | 1282 | | 20 |
---|
1283 | 1283 | | 21 |
---|
1284 | 1284 | | 22 |
---|
1285 | 1285 | | 23 |
---|
1286 | 1286 | | 24 |
---|
1287 | 1287 | | |
---|
1288 | 1288 | | SECTION 17. This act shall become effective November 1, 202 3. |
---|
1289 | 1289 | | |
---|
1290 | 1290 | | 58-2-8440 JL 09/09/21 |
---|