3 | | - | ENGR. H. B. NO. 1030 Page 1 1 |
---|
4 | | - | 2 |
---|
5 | | - | 3 |
---|
6 | | - | 4 |
---|
7 | | - | 5 |
---|
8 | | - | 6 |
---|
9 | | - | 7 |
---|
10 | | - | 8 |
---|
11 | | - | 9 |
---|
12 | | - | 10 |
---|
13 | | - | 11 |
---|
14 | | - | 12 |
---|
15 | | - | 13 |
---|
16 | | - | 14 |
---|
17 | | - | 15 |
---|
18 | | - | 16 |
---|
19 | | - | 17 |
---|
20 | | - | 18 |
---|
21 | | - | 19 |
---|
22 | | - | 20 |
---|
23 | | - | 21 |
---|
24 | | - | 22 |
---|
25 | | - | 23 |
---|
26 | | - | 24 |
---|
27 | | - | |
---|
28 | | - | ENGROSSED HOUSE |
---|
29 | | - | BILL NO. 1030 By: West (Josh), Pae, Fugate, |
---|
30 | | - | Alonso-Sandoval, and Sims |
---|
31 | | - | of the House |
---|
32 | | - | |
---|
33 | | - | and |
---|
34 | | - | |
---|
35 | | - | Howard of the Senate |
---|
36 | | - | |
---|
37 | | - | |
---|
38 | | - | |
---|
39 | | - | |
---|
40 | | - | |
---|
41 | | - | |
---|
42 | | - | An Act relating to privacy of computer data; |
---|
43 | | - | enacting the Oklahoma Computer Data Privacy Act; |
---|
44 | | - | defining terms; providing for applicability of act |
---|
45 | | - | to certain businesses that collect consumers ' |
---|
46 | | - | personal information; providing exemptions; |
---|
47 | | - | prescribing complian ce with other laws and legal |
---|
48 | | - | proceedings; requiri ng act to be liberally |
---|
49 | | - | construed to align its effects with other laws |
---|
50 | | - | relating to privacy and protection of personal |
---|
51 | | - | information; providing for controlling effect of |
---|
52 | | - | federal law; providing for construction in event of |
---|
53 | | - | conflict with state law; providing for controlling |
---|
54 | | - | effect of law which provides greatest privacy or |
---|
55 | | - | protection to consumers; providing for preemption |
---|
56 | | - | of local law; providing consumers right to request |
---|
57 | | - | disclosure of certain information; providin g |
---|
58 | | - | consumers right to request deletion of certain |
---|
59 | | - | information; providing consumers the right to |
---|
60 | | - | request and receive a disclosure of personal |
---|
61 | | - | information sold or disclosed; providing consumers |
---|
62 | | - | right to opt in and out of the sale of personal |
---|
63 | | - | information; making legislative findings; providing |
---|
64 | | - | contracts or other agreement s purporting to waive |
---|
65 | | - | or limit a right, remedy o r means of enforcement |
---|
66 | | - | contrary to public policy; requiring businesses |
---|
67 | | - | collecting consumer data information inform |
---|
68 | | - | consumer of certain information collected; |
---|
| 3 | + | HB1030 HFLR Page 1 |
---|
| 4 | + | BOLD FACE denotes Committee Amendments. 1 |
---|
| 5 | + | 2 |
---|
| 6 | + | 3 |
---|
| 7 | + | 4 |
---|
| 8 | + | 5 |
---|
| 9 | + | 6 |
---|
| 10 | + | 7 |
---|
| 11 | + | 8 |
---|
| 12 | + | 9 |
---|
| 13 | + | 10 |
---|
| 14 | + | 11 |
---|
| 15 | + | 12 |
---|
| 16 | + | 13 |
---|
| 17 | + | 14 |
---|
| 18 | + | 15 |
---|
| 19 | + | 16 |
---|
| 20 | + | 17 |
---|
| 21 | + | 18 |
---|
| 22 | + | 19 |
---|
| 23 | + | 20 |
---|
| 24 | + | 21 |
---|
| 25 | + | 22 |
---|
| 26 | + | 23 |
---|
| 27 | + | 24 |
---|
| 28 | + | |
---|
| 29 | + | HOUSE OF REPRESENTATIVES - FLOOR VERSION |
---|
| 30 | + | |
---|
| 31 | + | STATE OF OKLAHOMA |
---|
| 32 | + | |
---|
| 33 | + | 1st Session of the 59th Legislature (2023) |
---|
| 34 | + | |
---|
| 35 | + | HOUSE BILL 1030 By: West (Josh) and Pae |
---|
| 36 | + | |
---|
| 37 | + | |
---|
| 38 | + | |
---|
| 39 | + | |
---|
| 40 | + | |
---|
| 41 | + | AS INTRODUCED |
---|
| 42 | + | |
---|
| 43 | + | An Act relating to privacy of computer data; enacting |
---|
| 44 | + | the Oklahoma Computer Data Privacy Act; defining |
---|
| 45 | + | terms; providing for applicability of act to certain |
---|
| 46 | + | businesses that collect consumers ' personal |
---|
| 47 | + | information; providing exemptions; prescribing |
---|
| 48 | + | compliance with other laws and legal proceedings; |
---|
| 49 | + | requiring act to be liberally constru ed to align its |
---|
| 50 | + | effects with other laws relating t o privacy and |
---|
| 51 | + | protection of personal information; providing for |
---|
| 52 | + | controlling effect of federal law; providing for |
---|
| 53 | + | construction in event of conflict with state law; |
---|
| 54 | + | providing for controlling effect of law which |
---|
| 55 | + | provides greatest privacy or protection to consumers; |
---|
| 56 | + | providing for preemption of l ocal law; providing |
---|
| 57 | + | consumers right to request disclosure of certain |
---|
| 58 | + | information; providin g consumers right to request |
---|
| 59 | + | deletion of certain information; providing consumers |
---|
| 60 | + | the right to request and receive a disclosure of |
---|
| 61 | + | personal information sold or disclosed; providing |
---|
| 62 | + | consumers right to opt in and out of the sale of |
---|
| 63 | + | personal information; making legislative findings; |
---|
| 64 | + | providing contracts or other agreement s purporting to |
---|
| 65 | + | waive or limit a right, remedy or mean s of |
---|
| 66 | + | enforcement contrary to public policy; requiring |
---|
| 67 | + | businesses collecting consumer data information |
---|
| 68 | + | inform consumer of certain information collected; |
---|
72 | | - | policies; requiring business es to designate and |
---|
73 | | - | make available methods for submitting verifiable |
---|
74 | | - | consumer request for certain information; requiring |
---|
75 | | - | |
---|
76 | | - | ENGR. H. B. NO. 1030 Page 2 1 |
---|
77 | | - | 2 |
---|
78 | | - | 3 |
---|
79 | | - | 4 |
---|
80 | | - | 5 |
---|
81 | | - | 6 |
---|
82 | | - | 7 |
---|
83 | | - | 8 |
---|
84 | | - | 9 |
---|
85 | | - | 10 |
---|
86 | | - | 11 |
---|
87 | | - | 12 |
---|
88 | | - | 13 |
---|
89 | | - | 14 |
---|
90 | | - | 15 |
---|
91 | | - | 16 |
---|
92 | | - | 17 |
---|
93 | | - | 18 |
---|
94 | | - | 19 |
---|
95 | | - | 20 |
---|
96 | | - | 21 |
---|
97 | | - | 22 |
---|
98 | | - | 23 |
---|
99 | | - | 24 |
---|
100 | | - | |
---|
101 | | - | businesses receiving verifiable consumer requests |
---|
102 | | - | reasonably verify identity of requesting consumer; |
---|
103 | | - | requiring businesses disclose required information |
---|
104 | | - | within a certain period; requiring businesses using |
---|
105 | | - | de-identified information not re-identify or |
---|
106 | | - | attempt to re-identify certain consumers; requiring |
---|
107 | | - | permission; prohibiting discrimination against |
---|
108 | | - | consumers for exercise of rights; authorizing |
---|
109 | | - | businesses to offer financial incentives to |
---|
110 | | - | consumers for collection, sale or disclosure of |
---|
111 | | - | personal information; pro hibiting division of |
---|
112 | | - | single transactions; requiring employee training |
---|
113 | | - | with respect to consumer inquiries; requiring |
---|
114 | | - | disclosure of certain rights, requirements and |
---|
115 | | - | information; providing civil penalties; authorizing |
---|
116 | | - | Oklahoma Attorney General to take certain actions |
---|
117 | | - | based on violations; authorizing Attorney General |
---|
118 | | - | to recover reasonable expenses incurred in |
---|
119 | | - | obtaining injunctive relief or civil pena lties; |
---|
120 | | - | directing Attorney General to deposit collected |
---|
121 | | - | penalties in a dedicated account in the General |
---|
122 | | - | Revenue Fund; providing certain immunities; |
---|
123 | | - | providing protections to servi ce providers; |
---|
124 | | - | providing for codification; and prov iding an |
---|
125 | | - | effective date. |
---|
| 72 | + | policies; requiring business es to designate and make |
---|
| 73 | + | available methods for submitting verifiable consumer |
---|
| 74 | + | request for certain information; requiring businesses |
---|
| 75 | + | receiving verifiable consumer requests reasonably |
---|
| 76 | + | |
---|
| 77 | + | HB1030 HFLR Page 2 |
---|
| 78 | + | BOLD FACE denotes Committee Amendments. 1 |
---|
| 79 | + | 2 |
---|
| 80 | + | 3 |
---|
| 81 | + | 4 |
---|
| 82 | + | 5 |
---|
| 83 | + | 6 |
---|
| 84 | + | 7 |
---|
| 85 | + | 8 |
---|
| 86 | + | 9 |
---|
| 87 | + | 10 |
---|
| 88 | + | 11 |
---|
| 89 | + | 12 |
---|
| 90 | + | 13 |
---|
| 91 | + | 14 |
---|
| 92 | + | 15 |
---|
| 93 | + | 16 |
---|
| 94 | + | 17 |
---|
| 95 | + | 18 |
---|
| 96 | + | 19 |
---|
| 97 | + | 20 |
---|
| 98 | + | 21 |
---|
| 99 | + | 22 |
---|
| 100 | + | 23 |
---|
| 101 | + | 24 |
---|
| 102 | + | |
---|
| 103 | + | verify identity of requesting consumer; requiring |
---|
| 104 | + | businesses disclose required information within a |
---|
| 105 | + | certain period; requiring businesses using de- |
---|
| 106 | + | identified information not re-identify or attempt to |
---|
| 107 | + | re-identify certain consumers; requiring permission; |
---|
| 108 | + | prohibiting discrimin ation against consumers for |
---|
| 109 | + | exercise of rights; authorizing businesses to offer |
---|
| 110 | + | financial incentives to consumers for collection, |
---|
| 111 | + | sale or disclosure of personal information; |
---|
| 112 | + | prohibiting division of single transactions; |
---|
| 113 | + | requiring employee training with respect to consumer |
---|
| 114 | + | inquiries; requiring disclosure of c ertain rights, |
---|
| 115 | + | requirements and informa tion; providing civil |
---|
| 116 | + | penalties; authorizing Oklahoma Attorney General to |
---|
| 117 | + | take certain actions based on violations; authorizing |
---|
| 118 | + | Attorney General to recover reasonable expenses |
---|
| 119 | + | incurred in obtaining injunc tive relief or civil |
---|
| 120 | + | penalties; directing Attorney General to deposit |
---|
| 121 | + | collected penalties in a dedicated account in the |
---|
| 122 | + | General Revenue Fund; providing certain immunities; |
---|
| 123 | + | providing protections to service providers; providing |
---|
| 124 | + | for codification; and prov iding an effective date. |
---|
| 125 | + | |
---|
167 | 168 | | 1. "Aggregate consumer information " means information that |
---|
168 | 169 | | relates to a group or ca tegory of consumers from which individu al |
---|
169 | 170 | | consumer identities have been removed and th at is not linked or |
---|
170 | 171 | | reasonably linkable to a particular consumer or household, including |
---|
171 | 172 | | through a device. The term does not include one or more individual |
---|
172 | 173 | | consumer records that have been de -identified; |
---|
173 | 174 | | 2. "Biometric information" means an individual's physiological, |
---|
174 | 175 | | biological or behavioral characteristics that can be used, alone or |
---|
175 | 176 | | in combination with other characteristics or other identifying data, |
---|
176 | 177 | | to establish the ind ividual's identity. The term includes: |
---|
177 | 178 | | a. an image of an iris, retina, fingerprint, face, hand, |
---|
178 | 179 | | palm or vein pattern or a voice recording f rom which |
---|
179 | 180 | | an identifier template can be extracted such as a |
---|
180 | 181 | | faceprint, minutiae template or voiceprint, |
---|
181 | 182 | | b. keystroke patterns or rhythms, |
---|
182 | 183 | | c. gait patterns or rhythms, and |
---|
183 | 184 | | d. sleep, health or exercise data that contains |
---|
184 | 185 | | identifying information; |
---|
185 | 186 | | 3. "Business" means a for-profit entity, including a sole |
---|
186 | 187 | | proprietorship, partnership, limited liability company, cor poration, |
---|
187 | 188 | | association or other legal entity that is organized or operated for |
---|
188 | 189 | | the profit or financial benefit of the entity's shareholders or |
---|
217 | 219 | | 4. "Business purpose" means the use of personal information |
---|
218 | 220 | | for: |
---|
219 | 221 | | a. the following operational purposes of a business or |
---|
220 | 222 | | service provider, provided that the use of the |
---|
221 | 223 | | information is reasonably necessary and proportionate |
---|
222 | 224 | | to achieve the operation al purpose for which th e |
---|
223 | 225 | | information was collected or processed or another |
---|
224 | 226 | | operational purpose that is compatible with the |
---|
225 | 227 | | context in which the information was collected: |
---|
226 | 228 | | (1) auditing related to a current interaction with a |
---|
227 | 229 | | consumer and any concurrent tran sactions, |
---|
228 | 230 | | including counting ad impressions of unique |
---|
229 | 231 | | visitors, verifying the positioning a nd quality |
---|
230 | 232 | | of ad impressions, and auditing compli ance with a |
---|
231 | 233 | | specification or other standards for ad |
---|
232 | 234 | | impressions, |
---|
233 | 235 | | (2) detecting a security incident, protecting again st |
---|
234 | 236 | | malicious, deceptive, fraudulent or illegal |
---|
235 | 237 | | activity, and prosecuting those responsible for |
---|
236 | 238 | | any illegal activity described by this division, |
---|
266 | 269 | | (4) using personal information in the short term or |
---|
267 | 270 | | for a transient use, provided that the |
---|
268 | 271 | | information is not: |
---|
269 | 272 | | (a) disclosed to a third party, and |
---|
270 | 273 | | (b) used to build a profile about a consumer or |
---|
271 | 274 | | alter an individual consumer 's experience |
---|
272 | 275 | | outside of a current interaction with the |
---|
273 | 276 | | consumer, including the contextual |
---|
274 | 277 | | customization of an adv ertisement displayed |
---|
275 | 278 | | as part of the same interact ion, |
---|
276 | 279 | | (5) performing a service on behalf of the business or |
---|
277 | 280 | | service provider, including: |
---|
278 | 281 | | (a) maintaining or servicing an account, |
---|
279 | 282 | | providing customer service, processing or |
---|
280 | 283 | | fulfilling an order or transactio n, |
---|
281 | 284 | | verifying customer information, processing a |
---|
282 | 285 | | payment, providing financing, providing |
---|
283 | 286 | | advertising or marketing services, or |
---|
284 | 287 | | providing analytic services, or |
---|
285 | 288 | | (b) performing a service simil ar to a service |
---|
286 | 289 | | described by subdivision (a) of this |
---|
315 | 319 | | (6) undertaking internal research for technological |
---|
316 | 320 | | development and demonstration, |
---|
317 | 321 | | (7) undertaking an activity to: |
---|
318 | 322 | | (a) verify or maintain the quali ty or safety of |
---|
319 | 323 | | a service or device that is owned by, |
---|
320 | 324 | | manufactured by, manufactured for or |
---|
321 | 325 | | controlled by the business , or |
---|
322 | 326 | | (b) improve, upgrade or enhance a service or |
---|
323 | 327 | | device described by subdivision (a) of this |
---|
324 | 328 | | division, or |
---|
325 | 329 | | (8) retention of employment data, or |
---|
326 | 330 | | b. another operational purpose for which notice is given |
---|
327 | 331 | | under this act, but specifically excepting cross- |
---|
328 | 332 | | context targeted advertising, unless the customer has |
---|
329 | 333 | | opted in to the same ; |
---|
330 | 334 | | 5. "Collect" means to buy, rent, gather, obtain, receive or |
---|
331 | 335 | | access the personal information of a consumer by any means, |
---|
332 | 336 | | including by actively or passively receiving the information from |
---|
333 | 337 | | the consumer or by observing the consumer's behavior; |
---|
334 | 338 | | 6. "Commercial purpose" means a purpose that is intended to |
---|
335 | 339 | | result in a profit or o ther tangible benefit or the advancement of a |
---|
336 | 340 | | person's commercial or economic interests, such as by inducing |
---|
365 | 370 | | enabling or effectin g, directly or indirectly, a commercial |
---|
366 | 371 | | transaction. The term does not include the purpose of engaging in |
---|
367 | 372 | | speech recognized by state or federal courts as noncommercial |
---|
368 | 373 | | speech, including political speech and journalism ; |
---|
369 | 374 | | 7. "Consumer" means an individual who is a resident of this |
---|
370 | 375 | | state; |
---|
371 | 376 | | 8. "De-identified information " means information that cannot |
---|
372 | 377 | | reasonably identify, re late to, describe, be associated with, or be |
---|
373 | 378 | | linked to, directly or indirectly, a particular consumer ; |
---|
374 | 379 | | 9. "Device" means any physical obje ct capable of connecting to |
---|
375 | 380 | | the Internet, directly or indirectly, o r to another device; |
---|
376 | 381 | | 10. "Genetic Information" mea ns any information, regardless of |
---|
377 | 382 | | its format, that concern s a consumer's genetic characteristics. |
---|
378 | 383 | | Genetic information includes, but is not limited to: |
---|
379 | 384 | | a. raw sequence data that result from sequencing of a |
---|
380 | 385 | | consumer's complete extracted or a portion of the |
---|
381 | 386 | | extracted DNA, |
---|
382 | 387 | | b. genotypic and phenotypic information that results from |
---|
383 | 388 | | analyzing the raw sequenc e data, and |
---|
384 | 389 | | c. self-reported health information that consu mer submits |
---|
385 | 390 | | to a company regarding the consumer's hea lth |
---|
386 | 391 | | conditions and that is used for scientific r esearch or |
---|
415 | 421 | | 11. "Identifier" means data elements or other information that |
---|
416 | 422 | | alone or in conjunction with other information can be used to |
---|
417 | 423 | | identify a particular consumer, h ousehold or device that is linked |
---|
418 | 424 | | to a particular consumer or household; |
---|
419 | 425 | | 12. "Internet service provider" means a person who provides a |
---|
420 | 426 | | mass-market retail service by wire or radio that provides the |
---|
421 | 427 | | capability to transmit d ata and to receive data from all o r |
---|
422 | 428 | | substantially all Internet endpoints, including any capabilities |
---|
423 | 429 | | that are incidental to and enable the operations of the service, |
---|
424 | 430 | | excluding dial-up Internet access service; |
---|
425 | 431 | | 13. "Person" means an individual, sole proprie torship, firm, |
---|
426 | 432 | | partnership, joint venture, syndicate, business trust, company, |
---|
427 | 433 | | corporation, limited liability company, association, committee and |
---|
428 | 434 | | any other organization or gro up of persons acting in concert; |
---|
429 | 435 | | 14. "Personal information " means information th at identifies, |
---|
430 | 436 | | relates to, describes, can be associated with or can reasonably be |
---|
431 | 437 | | linked to, directly or indir ectly, a particular consumer or |
---|
432 | 438 | | household. The term includes the following cat egories of |
---|
433 | 439 | | information if the information identifies, relates to, d escribes, |
---|
434 | 440 | | can be associated with or can reasonably be linked to, directly or |
---|
435 | 441 | | indirectly, a particular consumer or household: |
---|
465 | 472 | | passport number, signature, telephone number or other |
---|
466 | 473 | | government-issued identification number, or other |
---|
467 | 474 | | similar identifier, |
---|
468 | 475 | | b. an online identifier, including a n electronic mail |
---|
469 | 476 | | address or Internet Protocol address, or other si milar |
---|
470 | 477 | | identifier, |
---|
471 | 478 | | c. a physical characteristic or description, including a |
---|
472 | 479 | | characteristic of a protected class ification under |
---|
473 | 480 | | state or federal law, |
---|
474 | 481 | | d. commercial information, including: |
---|
475 | 482 | | (1) a record of personal property, |
---|
476 | 483 | | (2) a good or service purchased, ob tained or |
---|
477 | 484 | | considered, |
---|
478 | 485 | | (3) an insurance policy number, or |
---|
479 | 486 | | (4) other purchasing or consuming histories or |
---|
480 | 487 | | tendencies, |
---|
481 | 488 | | e. biometric information and genetic information, |
---|
482 | 489 | | f. Internet or other el ectronic network activity |
---|
483 | 490 | | information, including: |
---|
484 | 491 | | (1) browsing or search history, and |
---|
515 | 523 | | h. audio, electronic, visua l, thermal, olfactory or other |
---|
516 | 524 | | similar information, |
---|
517 | 525 | | i. professional or emplo yment-related information, |
---|
518 | 526 | | j. education information that is not publicly available |
---|
519 | 527 | | that includes personally identifiable information |
---|
520 | 528 | | under the federal Family Educational Rights and |
---|
521 | 529 | | Privacy Act of 1974, |
---|
522 | 530 | | k. financial information, including a financial |
---|
523 | 531 | | institution account number, credit or debit card |
---|
524 | 532 | | number, or password or access code associated with a |
---|
525 | 533 | | credit or debit card or bank account, |
---|
526 | 534 | | l. medical information, |
---|
527 | 535 | | m. health insurance information, or |
---|
528 | 536 | | n. inferences drawn from any of the information listed |
---|
529 | 537 | | under this paragraph to create a profile about a |
---|
530 | 538 | | consumer that reflects the consumer's preferences, |
---|
531 | 539 | | characteristics, psychological trends, |
---|
532 | 540 | | predispositions, behavior, attitudes, intelligence, |
---|
533 | 541 | | abilities or aptitudes; |
---|
565 | 574 | | information no longer a ttributable to a specific consumer withou t |
---|
566 | 575 | | the use of additional information, provided that the additional |
---|
567 | 576 | | information is kept separately and is subject to technical and |
---|
568 | 577 | | organizational measures t o ensure that the personal information is |
---|
569 | 578 | | not attributed to an identified or identifiable consumer ; |
---|
570 | 579 | | 17. "Publicly available information" means information that is |
---|
571 | 580 | | lawfully made available to the public from federal, state or local |
---|
572 | 581 | | government records or information received from widely distributed |
---|
573 | 582 | | media or by the consumer in the public domain. The term does not |
---|
574 | 583 | | include: |
---|
575 | 584 | | a. biometric information or genetic information of a |
---|
576 | 585 | | consumer collected by a business wit hout the |
---|
577 | 586 | | consumer's knowledge or consent, or |
---|
578 | 587 | | b. de-identified or aggregate consumer information; |
---|
579 | 588 | | 18. "Service provider" means a for-profit entity as described |
---|
580 | 589 | | by paragraph 3 of this section that processes information on behalf |
---|
581 | 590 | | of a business and to which t he business discloses, for a business |
---|
582 | 591 | | purpose, a consumer's personal information under a written contract, |
---|
583 | 592 | | provided that the contract prohibits the entity receiving the |
---|
614 | 624 | | b. for a purpose permitted by th is act, including for a |
---|
615 | 625 | | commercial purpose other than providing those |
---|
616 | 626 | | specified services; |
---|
617 | 627 | | 19. "Third party" means a person who is not: |
---|
618 | 628 | | a. a business to which this act applies that collects |
---|
619 | 629 | | personal information from consumers, or |
---|
620 | 630 | | b. a person to whom the bu siness discloses, for a |
---|
621 | 631 | | business purpose, a consumer's personal information |
---|
622 | 632 | | under a written contract, provided that the contract: |
---|
623 | 633 | | (1) prohibits the person receiving the information |
---|
624 | 634 | | from: |
---|
625 | 635 | | (a) selling the information, |
---|
626 | 636 | | (b) retaining, using or disclosing the |
---|
627 | 637 | | information for any purpose other than |
---|
628 | 638 | | providing the services specified in the |
---|
629 | 639 | | contract, including for a commercial purpose |
---|
630 | 640 | | other than providing t hose services, and |
---|
631 | 641 | | (c) retaining, using or disclosing the |
---|
632 | 642 | | information outside of the direct business |
---|
664 | 675 | | prohibitions under division (1) of this |
---|
665 | 676 | | subparagraph; |
---|
666 | 677 | | 20. "Unique identifier" means a persistent identifier that can |
---|
667 | 678 | | be used over time and across different services to re cognize a |
---|
668 | 679 | | consumer, a custodial parent or guardian , or any minor children over |
---|
669 | 680 | | which the parent or g uardian has custody, or a device that is linked |
---|
670 | 681 | | to those individuals. The term includes: |
---|
671 | 682 | | a. a device identifier, |
---|
672 | 683 | | b. an Internet Protocol address, |
---|
673 | 684 | | c. a cookie, beacon, pixel tag, mobile ad id entifier or |
---|
674 | 685 | | similar technology, |
---|
675 | 686 | | d. a customer number, unique pseu donym or user alias, |
---|
676 | 687 | | e. a telephone number, and |
---|
677 | 688 | | f. another form of a persistent or probabilistic |
---|
678 | 689 | | identifier that can be used to identify a particular |
---|
679 | 690 | | consumer or device; |
---|
680 | 691 | | 21. "Verifiable consumer request " means a request: |
---|
681 | 692 | | a. that is made by a consumer, a c onsumer on behalf of |
---|
682 | 693 | | the consumer's minor child, or a natural person or |
---|
713 | 725 | | consumer about whom the business has collected |
---|
714 | 726 | | personal information; and |
---|
715 | 727 | | 22. "Consent" means an act that clearly and conspicuously |
---|
716 | 728 | | communicates the individua l's authorization of an act or pra ctice |
---|
717 | 729 | | that is made in the absence of any mechanism in the user int erface |
---|
718 | 730 | | that has the purpose or substantial effect of obscurin g, subverting |
---|
719 | 731 | | or impairing decision-making or choice to obtain consent. |
---|
720 | 732 | | SECTION 3. NEW LAW A new section of law to be cod ified |
---|
721 | 733 | | in the Oklahoma Statutes as Section 901.3 of Title 17, unless there |
---|
722 | 734 | | is created a duplication in numbering , reads as follows: |
---|
723 | 735 | | A. This act applies only to: |
---|
724 | 736 | | 1. A business that: |
---|
725 | 737 | | a. does business in this state, |
---|
726 | 738 | | b. collects consumers' personal information or has that |
---|
727 | 739 | | information collected on the busines s's behalf, |
---|
728 | 740 | | c. alone or in conjunction with others, determine s the |
---|
729 | 741 | | purpose for and means of processing consumers' |
---|
730 | 742 | | personal information, and |
---|
731 | 743 | | d. satisfies one or more of the following thresholds: |
---|
763 | 776 | | thousand or more consumers, h ouseholds or |
---|
764 | 777 | | devices, or |
---|
765 | 778 | | (3) derives twenty-five percent (25%) or more of the |
---|
766 | 779 | | business's annual revenue from se lling consumers' |
---|
767 | 780 | | personal information; and |
---|
768 | 781 | | 2. An entity that controls or is controlled by a bu siness |
---|
769 | 782 | | described by paragraph 1 of this subsection and that shares the same |
---|
770 | 783 | | or substantially similar brand name and/or common database for |
---|
771 | 784 | | consumers' personal information. For purposes of this paragraph, |
---|
772 | 785 | | "control" means the: |
---|
773 | 786 | | a. ownership of, or power to v ote, more than fifty |
---|
774 | 787 | | percent (50%) of the outstand ing shares of any class |
---|
775 | 788 | | of voting security of a bu siness, |
---|
776 | 789 | | b. control in any manner over the election of a major ity |
---|
777 | 790 | | of the directors or of individuals exercising similar |
---|
778 | 791 | | functions, or |
---|
779 | 792 | | c. power to exercise a controlling influence over the |
---|
780 | 793 | | management of a company. |
---|
813 | 827 | | C. For purposes of this act, a business does not sell a |
---|
814 | 828 | | consumer's personal information if: |
---|
815 | 829 | | 1. The consumer directs the busin ess to intentionally disclose |
---|
816 | 830 | | the information or u ses the business to intentionally interact with |
---|
817 | 831 | | a third party, provided that the third party does not sell the |
---|
818 | 832 | | information, unless that disclosure is consistent with this act; or |
---|
819 | 833 | | 2. The business: |
---|
820 | 834 | | a. uses or shares an identifier of the consumer to alert |
---|
821 | 835 | | a third party that the consumer has opted out of the |
---|
822 | 836 | | sale of the information, |
---|
823 | 837 | | b. uses or shares with a service provider a consumer's |
---|
824 | 838 | | personal information that is necessary to perform a |
---|
825 | 839 | | business purpose if: |
---|
826 | 840 | | (1) the business provided notice that the informatio n |
---|
827 | 841 | | is being used or shared in the business 's terms |
---|
828 | 842 | | and conditions consistent with Sections 13 and 17 |
---|
829 | 843 | | of this act, and |
---|
863 | 878 | | business, provided that information is used or sh ared |
---|
864 | 879 | | consistent with this act. |
---|
865 | 880 | | D. For purposes of paragraph 1 of subsection C of this section, |
---|
866 | 881 | | an intentional interaction occurs if the consumer does one or more |
---|
867 | 882 | | deliberate acts with the intent to interact with a third party. |
---|
868 | 883 | | Placing a cursor over, muting , pausing or closing online content |
---|
869 | 884 | | does not constitute a con sumer's intent to interact with a third |
---|
870 | 885 | | party. Instead, said deliberate act must be consent to such |
---|
871 | 886 | | interaction as defined herein. |
---|
872 | 887 | | SECTION 4. NEW LAW A new section of law to be codified |
---|
873 | 888 | | in the Oklahoma Statutes as Section 901.4 of Title 17, unless there |
---|
874 | 889 | | is created a duplication in numbering, reads as follows: |
---|
875 | 890 | | A. This act does not apply to: |
---|
876 | 891 | | 1. Publicly available informatio n; |
---|
877 | 892 | | 2. Medical information governed by state priva cy health laws or |
---|
878 | 893 | | protected health information that is collec ted by a covered entity |
---|
879 | 894 | | or business associate governed by the privacy, security and data |
---|
913 | 929 | | 3. A provider of health care, or a health plan, governed by |
---|
914 | 930 | | state privacy health laws or a covered entity go verned by the |
---|
915 | 931 | | privacy, security and data breach notification rules issued by the |
---|
916 | 932 | | United States Department of Health and Human Services, Parts 160 and |
---|
917 | 933 | | 164 of Title 45 of the Code of Federal Regulations, establis hed |
---|
918 | 934 | | pursuant to the federal Health Insurance Porta bility and |
---|
919 | 935 | | Accountability Act of 1996 (Public Law 104-191), to the extent the |
---|
920 | 936 | | provider or covered entity mainta ins, uses and discloses patient |
---|
921 | 937 | | information in the same manner as medical information or protec ted |
---|
922 | 938 | | health information as described in paragraph 2 of this subsection; |
---|
923 | 939 | | 4. A business associate of a covered entity governed by the |
---|
924 | 940 | | privacy, security and data breach notification rules issued by the |
---|
925 | 941 | | United States Department of Health and Human Services, Pa rts 160 and |
---|
926 | 942 | | 164 of Title 45 of the Code of Federal Regulations, established |
---|
927 | 943 | | pursuant to the federal Health Insurance Portability and |
---|
928 | 944 | | Accountability Act of 1996 ( Public Law 104-191) and the federal |
---|
929 | 945 | | Health Information Technology for Economic and Clinical Hea lth Act, |
---|
962 | 979 | | a. is de-identified in accordance with t he requirements |
---|
963 | 980 | | for de-identification set forth in Section 164.514 of |
---|
964 | 981 | | Part 164 of Title 45 of the Code of Federal |
---|
965 | 982 | | Regulations, and |
---|
966 | 983 | | b. is derived from patient information that was |
---|
967 | 984 | | originally collected, created, transmitted or |
---|
968 | 985 | | maintained by an entity regulat ed by the Health |
---|
969 | 986 | | Insurance Portability and Accountability Act of 1996 |
---|
970 | 987 | | or the Federal Policy fo r the Protection of Human |
---|
971 | 988 | | Subjects, also known as t he Common Rule. |
---|
972 | 989 | | Information that meets the requirements of subparagraph a or b |
---|
973 | 990 | | of this paragraph but is subsequ ently re-identified shall no longer |
---|
974 | 991 | | be eligible for the exemption in this paragraph and shall be subject |
---|
975 | 992 | | to applicable federal and state data pri vacy and security laws, |
---|
976 | 993 | | including, but not limited to, the Health Insurance Portability and |
---|
977 | 994 | | Accountability Act of 1996 and state medical privacy laws; |
---|
978 | 995 | | 6. Information that is collected, used or disclosed in |
---|
979 | 996 | | research, as defined in Section 164.501 of Title 45 of the Code of |
---|
1012 | 1030 | | Harmonization, or human subject protection requ irements of the |
---|
1013 | 1031 | | United States Food and Drug Adminis tration; |
---|
1014 | 1032 | | 7. The sale of personal information t o or by a consumer |
---|
1015 | 1033 | | reporting agency if the information is to be: |
---|
1016 | 1034 | | a. reported in or used to generate a consumer report, as |
---|
1017 | 1035 | | defined by Section 1681a(d) of the F air Credit |
---|
1018 | 1036 | | Reporting Act (15 U.S.C., Section 1681 et seq.), and |
---|
1019 | 1037 | | b. used solely for a purpose authoriz ed under that act; |
---|
1020 | 1038 | | 8. Personal information collected, proces sed, sold or disclosed |
---|
1021 | 1039 | | in accordance with: |
---|
1022 | 1040 | | a. the federal Gramm-Leach-Bliley Act of 1999 (Public Law |
---|
1023 | 1041 | | 106-102) and its implementing regulations, o r |
---|
1024 | 1042 | | b. the federal Driver's Privacy Protection Act o f 1994 |
---|
1025 | 1043 | | (18 U.S.C., Section 2721 et seq.); |
---|
1026 | 1044 | | 9. De-identified or aggregate consumer information; or |
---|
1027 | 1045 | | 10. A consumer's personal information collected or sold by a |
---|
1028 | 1046 | | business, if every aspect of the collection or sale occurred wholly |
---|
1029 | 1047 | | outside of this state. |
---|
1062 | 1081 | | has met the requirements of paragraphs 2 through 6 of subsection A |
---|
1063 | 1082 | | of this section, except for one or more of the following purposes: |
---|
1064 | 1083 | | 1. Treatment, payment or health care operations conducted by a |
---|
1065 | 1084 | | covered entity or business associate acting on behalf of, and at the |
---|
1066 | 1085 | | written direction of, the covered entity. For purposes of this |
---|
1067 | 1086 | | paragraph, "treatment", "payment", "health care operations " and |
---|
1068 | 1087 | | "covered entity" have the same meaning as defined in Section 164.501 |
---|
1069 | 1088 | | of Title 45 of the Code of Federal Regulations, and "business |
---|
1070 | 1089 | | associate" has the same meaning as defined in Section 160.103 of |
---|
1071 | 1090 | | Title 45 of the Code of Federal Regulations; |
---|
1072 | 1091 | | 2. Public health activities or purposes as described in Section |
---|
1073 | 1092 | | 164.512 of Title 45 of the Code of Federal Regulations; |
---|
1074 | 1093 | | 3. Research, as defined in Section 164.501 of T itle 45 of the |
---|
1075 | 1094 | | Code of Federal Regulations, that is conducted in accordance with |
---|
1076 | 1095 | | Part 46 of Title 45 of the Code of Federal Regulations and the |
---|
1077 | 1096 | | Federal Policy for the Protection of Human Subjects, also known as |
---|
1078 | 1097 | | the Common Rule; |
---|
1111 | 1131 | | return or destruction of the information that was re -identified upon |
---|
1112 | 1132 | | completion of the contract; and |
---|
1113 | 1133 | | 5. If otherwise required by law. |
---|
1114 | 1134 | | C. In accordance with paragraphs 2 through 6 of subsection A of |
---|
1115 | 1135 | | this section, information re-identified pursuant to this section |
---|
1116 | 1136 | | shall be subject to applicable federal and state da ta privacy and |
---|
1117 | 1137 | | security laws, including, but not limited to, the Health Insurance |
---|
1118 | 1138 | | Portability and Accountability Act of 1996 and state health pri vacy |
---|
1119 | 1139 | | laws. |
---|
1120 | 1140 | | D. Beginning January 1, 202 4, any contract for the sale or |
---|
1121 | 1141 | | license of de-identified information tha t has met the requirements |
---|
1122 | 1142 | | of paragraphs 2 through 6 of subsection A of this section, where one |
---|
1123 | 1143 | | of the parties is a person residing or doing busi ness in the state, |
---|
1124 | 1144 | | shall include the following, or substantially similar, provisions: |
---|
1125 | 1145 | | 1. A statement that the de-identified information being sold or |
---|
1126 | 1146 | | licensed includes de-identified patient information; |
---|
1127 | 1147 | | 2. A statement that re-identification, and attempte d re- |
---|
1128 | 1148 | | identification, of the de -identified information by the purchaser or |
---|
1160 | 1181 | | unless the third party is cont ractually bound by the same or |
---|
1161 | 1182 | | stricter restrictions and conditions. |
---|
1162 | 1183 | | E. For purposes of this section, "re-identify" means the |
---|
1163 | 1184 | | process of reversal of de-identification techniques, including, but |
---|
1164 | 1185 | | not limited to, the addition of specific pieces of informatio n or |
---|
1165 | 1186 | | data elements that can, individually or in combination, be used to |
---|
1166 | 1187 | | uniquely identify an individual or usage. |
---|
1167 | 1188 | | F. For purposes of paragraph 1 0 of subsection A of this |
---|
1168 | 1189 | | section, the collection or sale of a consumer's personal information |
---|
1169 | 1190 | | occurs wholly outside of this state if: |
---|
1170 | 1191 | | 1. The business collects that information while the consumer is |
---|
1171 | 1192 | | outside of this state; |
---|
1172 | 1193 | | 2. No part of the sale of the in formation occurs in this state; |
---|
1173 | 1194 | | and |
---|
1174 | 1195 | | 3. The business does not sell any personal information of the |
---|
1175 | 1196 | | consumer collected while the consumer is in this state. |
---|
1176 | 1197 | | G. For purposes of subsection F of this section, the collection |
---|
1177 | 1198 | | or sale of a consumer 's personal information does not occur wholly |
---|
1178 | 1199 | | outside of this state if a business stores a consumer 's personal |
---|
1210 | 1232 | | 1. "Business associate" has the same meaning as defined in |
---|
1211 | 1233 | | Section 160.103 of Title 45 of the Code of Federal Regulations; |
---|
1212 | 1234 | | 2. "Covered entity" has the same meaning as defined in Section |
---|
1213 | 1235 | | 160.103 of Title 45 of the Code of Federal Regulations; |
---|
1214 | 1236 | | 3. "Identifiable private information" has the same meaning as |
---|
1215 | 1237 | | defined in Section 46.102 of Title 45 of the Code of Federal |
---|
1216 | 1238 | | Regulations; |
---|
1217 | 1239 | | 4. "Individually identifiable health information " has the same |
---|
1218 | 1240 | | meaning as defined in Section 160.103 of Title 45 of the Code of |
---|
1219 | 1241 | | Federal Regulations; |
---|
1220 | 1242 | | 5. "Medical information" means any individually identifiable |
---|
1221 | 1243 | | information, in elect ronic or physical form, in possession of or |
---|
1222 | 1244 | | derived from a provider of health care, health care servi ce plan, |
---|
1223 | 1245 | | pharmaceutical company, or contractor regarding a pa tient's medical |
---|
1224 | 1246 | | history, mental or physical condition, or treatment; |
---|
1225 | 1247 | | 6. "Patient information" means identifiable private |
---|
1226 | 1248 | | information, protected health information, individually identifiable |
---|
1227 | 1249 | | health information, or medical information; |
---|
1259 | 1282 | | SECTION 5. NEW LAW A new section o f law to be codified |
---|
1260 | 1283 | | in the Oklahoma Statutes as Section 901.5 of Title 17, unless there |
---|
1261 | 1284 | | is created a duplication in numbering, reads as follows: |
---|
1262 | 1285 | | A right or obligation under this a ct does not apply to the |
---|
1263 | 1286 | | extent that the exercise of the right or performanc e of the |
---|
1264 | 1287 | | obligation infringes on a noncommercial activity of: |
---|
1265 | 1288 | | 1. A publisher, editor, reporter or other person connected with |
---|
1266 | 1289 | | or employed by a newspaper, magazine or other publication of general |
---|
1267 | 1290 | | circulation, including a periodical , newsletter, pamphlet or report; |
---|
1268 | 1291 | | 2. A radio or television station that holds a license issued by |
---|
1269 | 1292 | | the Federal Communicat ions Commission; |
---|
1270 | 1293 | | 3. A nonprofit that provides programing to radio or television |
---|
1271 | 1294 | | networks; or |
---|
1272 | 1295 | | 4. An entity that provides an information service, including a |
---|
1273 | 1296 | | press association or wire service. |
---|
1274 | 1297 | | SECTION 6. NEW LAW A new section of law to be c odified |
---|
1275 | 1298 | | in the Oklahoma Statute s as Section 901.6 of Title 17, unl ess there |
---|
1276 | 1299 | | is created a duplication in numbering, reads as follows: |
---|
1277 | 1300 | | This act does not: |
---|
1307 | 1331 | | (2) a civil, criminal or regulatory inquiry, |
---|
1308 | 1332 | | investigation, subpoena or summons by a federal, |
---|
1309 | 1333 | | state or local authority, |
---|
1310 | 1334 | | b. cooperate with a law enforceme nt agency concerning |
---|
1311 | 1335 | | conduct or activity th at the business, a service |
---|
1312 | 1336 | | provider of the business or a third party reasonably |
---|
1313 | 1337 | | and in good faith believes may violate other |
---|
1314 | 1338 | | applicable federal, state or local laws, |
---|
1315 | 1339 | | c. pursue or defend against a legal claim, |
---|
1316 | 1340 | | d. detect a security incident; protect against malicious, |
---|
1317 | 1341 | | deceptive, fraudulent or illegal activity; or |
---|
1318 | 1342 | | prosecute those responsible for any illegal activity |
---|
1319 | 1343 | | described by this paragraph, or |
---|
1320 | 1344 | | e. assist another party with any of the foregoing; or |
---|
1321 | 1345 | | 2. Require a business to violate an evidentiary privilege u nder |
---|
1322 | 1346 | | federal or state law or prevent a business from disclosin g to a |
---|
1323 | 1347 | | person covered by an evi dentiary privilege the personal inf ormation |
---|
1324 | 1348 | | of a consumer as part of a privileged communication. |
---|
1325 | 1349 | | SECTION 7. NEW LAW A new section of law to be codified |
---|
1326 | 1350 | | in the Oklahoma Statutes as Section 901.7 of Titl e 17, unless there |
---|
1327 | 1351 | | is created a duplication in numbering, reads as follows: |
---|
1357 | 1382 | | B. To the extent of a conflict between a provision of this act |
---|
1358 | 1383 | | and a provision of federal law, including a regulation or an |
---|
1359 | 1384 | | interpretation of federal law, federal law contro ls and conflicting |
---|
1360 | 1385 | | requirements or other provisions of this a ct do not apply. Further, |
---|
1361 | 1386 | | should the federal government pass compr ehensive data privacy |
---|
1362 | 1387 | | regulations that conflict with the provisions herein, federal l aw |
---|
1363 | 1388 | | shall prevail. |
---|
1364 | 1389 | | C. To the extent of a co nflict between a provision of this act |
---|
1365 | 1390 | | and another statute of this state with respect to the privacy or |
---|
1366 | 1391 | | protection of consumers ' personal information, the provision of law |
---|
1367 | 1392 | | that affords the greatest privacy or prot ection to consumers |
---|
1368 | 1393 | | prevails. |
---|
1369 | 1394 | | SECTION 8. NEW LAW A new section of law to be codif ied |
---|
1370 | 1395 | | in the Oklahoma Statutes as Section 901.8 of Title 17, unless there |
---|
1371 | 1396 | | is created a duplication in numbering, reads as follows: |
---|
1372 | 1397 | | This act preempts and supersedes any ordinance, order or rule |
---|
1373 | 1398 | | adopted by a political subdivision of this state relating to the |
---|
1374 | 1399 | | collection or sale by a busines s of a consumer's personal |
---|
1375 | 1400 | | information. |
---|
1407 | 1433 | | including basic research or applied research that is in the public |
---|
1408 | 1434 | | interest and that adheres to all other a pplicable ethics and privacy |
---|
1409 | 1435 | | laws or studies conducted in the publ ic interest in the area of |
---|
1410 | 1436 | | public health. Research with personal information that ma y have |
---|
1411 | 1437 | | been collected from a consumer in th e course of the consumer's |
---|
1412 | 1438 | | interactions with a business 's service or device for other purpose s |
---|
1413 | 1439 | | must: |
---|
1414 | 1440 | | 1. Be compatible with the business purpose for which the |
---|
1415 | 1441 | | personal information was collected; |
---|
1416 | 1442 | | 2. Be subsequently pseudonymized and de-identified, or de- |
---|
1417 | 1443 | | identified and in the aggregate, such that the information canno t |
---|
1418 | 1444 | | reasonably identify, relate t o, describe, be capable of being |
---|
1419 | 1445 | | associated with, or be linked, directly or indirectly, to a |
---|
1420 | 1446 | | particular consumer; |
---|
1421 | 1447 | | 3. Be made subject to technical safeguards that prohibit re- |
---|
1422 | 1448 | | identification of the consumer to whom the informa tion may pertain; |
---|
1423 | 1449 | | 4. Be subject to business processes that specif ically prohibit |
---|
1424 | 1450 | | re-identification of the information; |
---|
1457 | 1484 | | 9. Be subjected by the business conducting the research to |
---|
1458 | 1485 | | additional security controls th at limit access to the research dat a |
---|
1459 | 1486 | | to only those individuals in a business as are necessary to carry |
---|
1460 | 1487 | | out the research purpose. |
---|
1461 | 1488 | | SECTION 10. NEW LAW A new section of law to be codified |
---|
1462 | 1489 | | in the Oklahoma Statutes as Section 901.10 of Title 17, unless there |
---|
1463 | 1490 | | is created a duplication in numbering, reads as follows: |
---|
1464 | 1491 | | A. A consumer is entitled to request that a business that |
---|
1465 | 1492 | | collects the consumer 's personal information disclose to the |
---|
1466 | 1493 | | consumer the categories and specific items of personal inf ormation |
---|
1467 | 1494 | | the business has collected . |
---|
1468 | 1495 | | B. To receive the disclosure of information under subsection A |
---|
1469 | 1496 | | of this section, a consumer must submit to the business a veri fiable |
---|
1470 | 1497 | | consumer request using a method designated by the busin ess under |
---|
1471 | 1498 | | Section 18 of this act. |
---|
1472 | 1499 | | C. On receipt of a verifiable c onsumer request under this |
---|
1473 | 1500 | | section, a business shall disclose to the consumer in the time and |
---|
1474 | 1501 | | manner provided by Section 20 of this act: |
---|
1507 | 1535 | | 3. The business or commercial purpose for collecting or selling |
---|
1508 | 1536 | | the personal information; and |
---|
1509 | 1537 | | 4. Each category of third parties with whom the busine ss shares |
---|
1510 | 1538 | | the personal information. |
---|
1511 | 1539 | | D. This section does not require a business to: |
---|
1512 | 1540 | | 1. Retain a consume r's personal information that w as collected |
---|
1513 | 1541 | | for a one-time transaction if the information is not sold or |
---|
1514 | 1542 | | retained in the ordinary course of business; o r |
---|
1515 | 1543 | | 2. Re-identify or otherwise link any dat a that, in the ordinary |
---|
1516 | 1544 | | course of business, is not maintained in a manner that would be |
---|
1517 | 1545 | | considered personal information. |
---|
1518 | 1546 | | SECTION 11. NEW LAW A new section of law to be codified |
---|
1519 | 1547 | | in the Oklahoma Statutes as Section 901.11 of Title 17, unless there |
---|
1520 | 1548 | | is created a duplication in numbering, reads as f ollows: |
---|
1521 | 1549 | | A. A consumer is entit led to request that a business that |
---|
1522 | 1550 | | collects the consumer's personal information delete any personal |
---|
1523 | 1551 | | information the business has collected from the consumer by |
---|
1557 | 1586 | | provider's records in the time provided for in Secti on 20 of this |
---|
1558 | 1587 | | act. |
---|
1559 | 1588 | | C. A business or servic e provider of the business is not |
---|
1560 | 1589 | | required to comply with a ve rifiable consumer request recei ved under |
---|
1561 | 1590 | | this section if the busin ess or service provider needs to retain the |
---|
1562 | 1591 | | consumer's personal information to: |
---|
1563 | 1592 | | 1. Complete the transaction for which the infor mation was |
---|
1564 | 1593 | | collected; |
---|
1565 | 1594 | | 2. Provide a good or service requested by the consumer in the |
---|
1566 | 1595 | | context of the ongoing business relationshi p between the business |
---|
1567 | 1596 | | and consumer; |
---|
1568 | 1597 | | 3. Perform under a contract between the busines s and the |
---|
1569 | 1598 | | consumer; |
---|
1570 | 1599 | | 4. Detect a security incident; protect against malicious, |
---|
1571 | 1600 | | deceptive, fraudulent or illegal activity; or prosecute those |
---|
1572 | 1601 | | responsible for any illegal ac tivity described by this paragraph; |
---|
1606 | 1636 | | 8. Engage in public or pe er-reviewed scientific, historical or |
---|
1607 | 1637 | | statistical research tha t is in the public interest and that adheres |
---|
1608 | 1638 | | to all other applicab le ethics and privacy laws, provided that: |
---|
1609 | 1639 | | a. the business's deletion of the informat ion is likely |
---|
1610 | 1640 | | to render impossible or serio usly impair the |
---|
1611 | 1641 | | achievement of that research, and |
---|
1612 | 1642 | | b. the consumer has previously provided to the business |
---|
1613 | 1643 | | informed consent to re tain the information for such |
---|
1614 | 1644 | | use. |
---|
1615 | 1645 | | D. Where a business, service provider or third party has made a |
---|
1616 | 1646 | | consumer's personal information public, said business, service |
---|
1617 | 1647 | | provider or third party shall: |
---|
1618 | 1648 | | 1. Take all reasonable ste ps, including technical measures, t o |
---|
1619 | 1649 | | erase the personal information that the business, service provider |
---|
1620 | 1650 | | or third party made public, taking into account available t echnology |
---|
1621 | 1651 | | and the cost of implementation; and |
---|
1655 | 1686 | | A. A consumer is entitled to r equest that a business that |
---|
1656 | 1687 | | sells, or discloses for a business purpose, the consumer's personal |
---|
1657 | 1688 | | information disclose to the cons umer: |
---|
1658 | 1689 | | 1. The categories of personal information the business |
---|
1659 | 1690 | | collected about the con sumer; |
---|
1660 | 1691 | | 2. The categories of personal infor mation about the consumer |
---|
1661 | 1692 | | the business sold, or disclosed for a business purpose; and |
---|
1662 | 1693 | | 3. The categories of third parties to who m the personal |
---|
1663 | 1694 | | information was sold or disclosed. |
---|
1664 | 1695 | | B. To receive the disclosure of in formation under subsection A |
---|
1665 | 1696 | | of this section, a consumer must submit to the business a verifiable |
---|
1666 | 1697 | | consumer request using a method design ated by the business under |
---|
1667 | 1698 | | Section 18 of this act. |
---|
1668 | 1699 | | C. On receipt of a verifiable consumer request under this |
---|
1669 | 1700 | | section, a business shall disclose to the consumer in the time and |
---|
1670 | 1701 | | manner provided by Section 20 of this act : |
---|
1704 | 1736 | | category of information under paragraph 14 of Section 2 of this act |
---|
1705 | 1737 | | sold to each third party; and |
---|
1706 | 1738 | | 3. The categories of third parties to whom the business |
---|
1707 | 1739 | | disclosed for a business purpose the consumer's personal information |
---|
1708 | 1740 | | during the twelve (12) months preceding the date of the request by |
---|
1709 | 1741 | | reference to each enumerated category of information under paragraph |
---|
1710 | 1742 | | 14 of Section 2 of this act disclosed to each third party. |
---|
1711 | 1743 | | D. A business shall provide the information described by |
---|
1712 | 1744 | | paragraphs 2 and 3 of subsection C of this s ection in two separate |
---|
1713 | 1745 | | lists. |
---|
1714 | 1746 | | E. A business that did not sell, or disclose for a business |
---|
1715 | 1747 | | purpose, the consumer's personal information during the twelve (12) |
---|
1716 | 1748 | | months preceding the date of receiving the consumer's verifiable |
---|
1717 | 1749 | | consumer request under this sect ion shall disclose that fact to the |
---|
1718 | 1750 | | consumer. |
---|
1753 | 1786 | | business shall comply with a direction n ot to sell that is received |
---|
1754 | 1787 | | under this subsection. |
---|
1755 | 1788 | | B. To exercise the right to opt out specified in subsection A |
---|
1756 | 1789 | | of this section, a consumer shall sub mit to the business a |
---|
1757 | 1790 | | verifiable consumer r equest using a method designated by the |
---|
1758 | 1791 | | business under Section 18 of this act. |
---|
1759 | 1792 | | C. A business that sells consumers' personal information to a |
---|
1760 | 1793 | | third party shall provide on the business's Internet website: |
---|
1761 | 1794 | | 1. Notice to consumers that: |
---|
1762 | 1795 | | a. the information may be sold, |
---|
1763 | 1796 | | b. identifies the categories of persons to whom the |
---|
1764 | 1797 | | information will or could be so ld, and |
---|
1765 | 1798 | | c. consumers have the right to opt in to the sale via |
---|
1766 | 1799 | | consent; and |
---|
1803 | 1837 | | F. A third party to whom a business has sold the personal |
---|
1804 | 1838 | | information of a consumer ma y not sell the information unless the |
---|
1805 | 1839 | | consumer receives explicit n otice of the potential sale and is |
---|
1806 | 1840 | | provided the opportunity to, and in fact does, consent to the sale |
---|
1807 | 1841 | | as provided by this section. |
---|
1808 | 1842 | | G. A business may not require a consu mer to create an account |
---|
1809 | 1843 | | with the business to opt in to the sale of the consumer's personal |
---|
1810 | 1844 | | information. |
---|
1811 | 1845 | | H. A business or service provider shall implement an d maintain |
---|
1812 | 1846 | | reasonable security procedures a nd practices, including |
---|
1813 | 1847 | | administrative, physical and te chnical safeguards appropriate to the |
---|
1814 | 1848 | | nature of the information and the purposes for which the personal |
---|
1815 | 1849 | | information will be used, to protect consumers ' personal information |
---|
1816 | 1850 | | from unauthorized use, discl osure, access, destruction or |
---|
1853 | 1888 | | monetary gain and manipulation by private ventures in utilization of |
---|
1854 | 1889 | | private data. |
---|
1855 | 1890 | | C. The Legislature of the State of Oklahoma further finds that |
---|
1856 | 1891 | | the protection of individuals within Oklahoma and their data is a |
---|
1857 | 1892 | | core governmental functio n in order to protect the health, s afety |
---|
1858 | 1893 | | and welfare of individuals within Oklahoma. |
---|
1859 | 1894 | | D. The Legislature of the Stat e of Oklahoma further finds that |
---|
1860 | 1895 | | the terms and conditions set forth in this act are the least |
---|
1861 | 1896 | | restrictive alternative necessary to protect i ndividuals within |
---|
1862 | 1897 | | Oklahoma and their rights and that the use of a strictly "opt-out" |
---|
1863 | 1898 | | method for data privacy is inef fectual and poses an immediate risk |
---|
1864 | 1899 | | to the health, safety and welfare of individuals within Oklahoma. |
---|
1891 | 1900 | | SECTION 15. NEW LAW A new section of law to be cod ified |
---|
1892 | 1901 | | in the Oklahoma Statutes as Section 901.15 of Title 17, unless there |
---|
1893 | 1902 | | is created a duplication in numbering, reads as f ollows: |
---|
1894 | 1903 | | A. A provision of a contract or other agreement that purp orts |
---|
1895 | 1904 | | to waive or limit a right, remedy or means of enforcement und er this |
---|
1896 | 1905 | | act is contrary to public policy and is void. |
---|
1897 | 1906 | | B. This section does not p revent a consumer from: |
---|
1898 | 1907 | | 1. Declining to request information from a business; |
---|
1899 | 1908 | | 2. Declining to consent to a business's sale of the consumer 's |
---|
1900 | 1909 | | personal information; or |
---|
1901 | 1910 | | 3. Authorizing a business to sell the consumer's personal |
---|
1902 | 1911 | | information after previously o pting out. |
---|
1903 | 1939 | | SECTION 16. NEW LAW A new section of law to be codified |
---|
1904 | 1940 | | in the Oklahoma Stat utes as Section 901.16 of Title 17, unless there |
---|
1905 | 1941 | | is created a duplication in numbering, reads as follows: |
---|
1906 | 1942 | | A. After the effective date of this act, a business shall not |
---|
1907 | 1943 | | collect a consumer's personal information directly from the consumer |
---|
1908 | 1944 | | prior to notifying the consumer of each category of personal |
---|
1909 | 1945 | | information to be colle cted and for what purposes information will |
---|
1910 | 1946 | | be used, as well as obtaining the consumer's consent to opt in to |
---|
1911 | 1947 | | collection, which may be provided electronically by the consumer, to |
---|
1912 | 1948 | | collect a consumer's personal information. |
---|
1913 | 1949 | | B. A business may not collect an additional category of |
---|
1914 | 1950 | | personal information directly from the consumer or use personal |
---|
1941 | 1951 | | information collected for an additio nal purpose unless the business |
---|
1942 | 1952 | | provides notice to the consumer of the additional category or |
---|
1943 | 1953 | | purpose in accordance with s ubsection A of this section. |
---|
1944 | 1954 | | C. If a third party that assumes control of all or part of a |
---|
1945 | 1955 | | business as described by subparagraph c of paragraph 2 of subsection |
---|
1946 | 1956 | | C of Section 3 of this act materially alters the practices of the |
---|
1947 | 1957 | | business in how personal infor mation is used or shared, and the |
---|
1948 | 1958 | | practices are materially inconsistent with a notice provi ded to a |
---|
1949 | 1959 | | consumer under subsection A or B of this section, the third party |
---|
1950 | 1960 | | must notify the consumer of the third party 's new or changed |
---|
1951 | 1961 | | practices in a conspicuous manner that allows the consumer to easily |
---|
1952 | 1989 | | exercise a right provided under this act before the third-party |
---|
1953 | 1990 | | collector uses or shares the p ersonal information. |
---|
1954 | 1991 | | D. Subsection C of this section does not authorize a business |
---|
1955 | 1992 | | to make a material, retroactive change or other change to a |
---|
1956 | 1993 | | business's privacy policy in a manner that would be a deceptive |
---|
1957 | 1994 | | trade practice actionable under Oklahoma law. |
---|
1958 | 1995 | | SECTION 17. NEW LAW A new section of law to be codified |
---|
1959 | 1996 | | in the Oklahoma Statutes as Section 901.17 of Title 17, unless there |
---|
1960 | 1997 | | is created a duplication in numbering, reads as follows: |
---|
1961 | 1998 | | A. A business that collects, sells or for a business purpose |
---|
1962 | 1999 | | discloses a consumer's personal information shall disclose the |
---|
1963 | 2000 | | following information in the business's online privacy polic y or |
---|
1964 | 2001 | | other notice of the business's policies: |
---|
1991 | 2002 | | 1. A description of a consumer 's rights under Sections 10, 11, |
---|
1992 | 2003 | | 12, 13 and 16 of this act and designated methods for submitting a |
---|
1993 | 2004 | | verifiable consumer request under this act; |
---|
1994 | 2005 | | 2. For a business that collects per sonal information ab out |
---|
1995 | 2006 | | consumers, a description of the consumer's right to request the |
---|
1996 | 2007 | | deletion of the consumer's personal information; |
---|
1997 | 2008 | | 3. Separate lists containing the categories of consumers ' |
---|
1998 | 2009 | | personal information describe d by paragraph 14 of Section 2 of this |
---|
1999 | 2010 | | act that, during the twelve (12) months preceding the date the |
---|
2000 | 2011 | | business updated the information as required by subsection C of this |
---|
2001 | 2012 | | section, the business: |
---|
2051 | 2090 | | C. A business must update the information required by |
---|
2052 | 2091 | | subsection A of this section at least once each yea r. |
---|
2053 | 2092 | | SECTION 18. NEW LAW A new section of law to be codified |
---|
2054 | 2093 | | in the Oklahoma Statutes as Section 901.18 of Title 17, unless there |
---|
2055 | 2094 | | is created a duplication in numbering, reads as follows: |
---|
2056 | 2095 | | A. A business shall designate and make availabl e to consumers, |
---|
2057 | 2096 | | in a form that is reasonably accessible, at least two methods for |
---|
2058 | 2097 | | submitting a verifiable consumer request for infor mation required to |
---|
2059 | 2098 | | be disclosed or deleted under this act. The methods must incl ude, |
---|
2060 | 2099 | | at a minimum: |
---|
2061 | 2100 | | 1. A toll-free telephone number that a consumer may call to |
---|
2062 | 2101 | | submit the request; and |
---|
2137 | 2151 | | B. A business may use any personal information collected from |
---|
2138 | 2152 | | the consumer in connection with the busi ness's verification of a |
---|
2139 | 2153 | | request under this section solely to verify the request. |
---|
2140 | 2154 | | C. A business that is unable to verify a consumer request und er |
---|
2141 | 2155 | | this section is not required to comply with the request. |
---|
2142 | 2156 | | SECTION 20. NEW LAW A new sec tion of law to be codified |
---|
2143 | 2157 | | in the Oklahoma Statutes as Section 901.20 of Title 17, unless there |
---|
2144 | 2158 | | is created a duplication in numbering, reads as follows: |
---|
2145 | 2159 | | A. Not later than forty-five (45) days after the date a |
---|
2146 | 2160 | | business receives a verifiable consume r request under Section 10, |
---|
2147 | 2161 | | 11, 12 or 13 of this ac t, the business shall disclose free of charge |
---|
2148 | 2162 | | to the consumer the information required to be disclose d under those |
---|
2149 | 2163 | | sections or take the requested action s, as applicable. |
---|
2186 | 2201 | | 1. Cover personal information collected, sold or disclosed for |
---|
2187 | 2202 | | a business purpose, as applicable, during the twelve (12) months |
---|
2188 | 2203 | | preceding the date the busine ss receives the requ est; and |
---|
2189 | 2204 | | 2. Be made in writing and delivered to the consumer : |
---|
2190 | 2205 | | a. by mail or electronically, at the cons umer's option, |
---|
2191 | 2206 | | if the consumer does not have an account with the |
---|
2192 | 2207 | | business, or |
---|
2193 | 2208 | | b. through the consumer 's account with the business. |
---|
2194 | 2209 | | D. An electronic dis closure under subsection C of this section |
---|
2195 | 2210 | | must be in a readily accessible format that allows the consum er to |
---|
2196 | 2211 | | electronically transmit the information to another person or entity. |
---|
2197 | 2212 | | E. A business is not requ ired to make the disclosure required |
---|
2198 | 2213 | | by subsection A of this section to the same consumer more than once |
---|
2199 | 2214 | | in a twelve-month period. |
---|
2236 | 2252 | | request under this sect ion, of the reasons for the ref usal and the |
---|
2237 | 2253 | | rights the consumer may have to appeal that decision. |
---|
2238 | 2254 | | SECTION 21. NEW LAW A new section of law to be codified |
---|
2239 | 2255 | | in the Oklahoma Statutes as Section 901.2 1 of Title 17, unless there |
---|
2240 | 2256 | | is created a duplication in numbering, re ads as follows: |
---|
2241 | 2257 | | A. A business that uses de-identified information may not re - |
---|
2242 | 2258 | | identify or attempt to re-identify a consumer who is the subject of |
---|
2243 | 2259 | | de-identified information without obtaining the consumer 's consent |
---|
2244 | 2260 | | or authorization. |
---|
2245 | 2261 | | B. A business that uses de-identified information shall |
---|
2246 | 2262 | | implement: |
---|
2247 | 2263 | | 1. Technical safeguards and business processes to prohibit re- |
---|
2248 | 2264 | | identification of the consumer to whom the information may pertain; |
---|
2249 | 2265 | | and |
---|
2286 | 2303 | | 1. Denying a good or service to the consumer; |
---|
2287 | 2304 | | 2. Charging the consumer a different price or rate for a good |
---|
2288 | 2305 | | or service, including denying the use of a discount or other benefit |
---|
2289 | 2306 | | or imposing a penalty; |
---|
2290 | 2307 | | 3. Providing a different level or quality of a good or service |
---|
2291 | 2308 | | to the consumer; or |
---|
2292 | 2309 | | 4. Suggesting that the consumer will be char ged a different |
---|
2293 | 2310 | | price or rate for, or provi ded a different level or quality of, a |
---|
2294 | 2311 | | good or service. |
---|
2295 | 2312 | | B. This section does not prohibit a business from offering or |
---|
2296 | 2313 | | charging a consumer a different p rice or rate for a good or service, |
---|
2297 | 2314 | | or offering or providing to the consumer a different level or |
---|
2298 | 2315 | | quality of a good or service, if the difference is reasonably |
---|
2299 | 2343 | | related to the value provided to the consumer by the consumer's |
---|
2300 | 2344 | | data. |
---|
2301 | 2345 | | SECTION 23. NEW LAW A new section of law to be codified |
---|
2302 | 2346 | | in the Oklahoma Statutes as Section 901.2 3 of Title 17, unless there |
---|
2303 | 2347 | | is created a duplication in numbering, reads as follows: |
---|
2304 | 2348 | | A. Subject to subsection B of this section, a business may |
---|
2305 | 2349 | | offer a financial incentive to a consumer, including a payment as |
---|
2306 | 2350 | | compensation, for the collection, sale or disclosure of the |
---|
2307 | 2351 | | consumer's personal information. |
---|
2308 | 2352 | | B. A business may enroll a customer in a financial incentive |
---|
2309 | 2353 | | program only if the business pro vides to the consume r a clear |
---|
2336 | 2354 | | description of the material terms of the program an d obtains the |
---|
2337 | 2355 | | consumer's prior opt-in consent, which: |
---|
2338 | 2356 | | 1. Contains a clear description of those material terms; and |
---|
2339 | 2357 | | 2. May be revoked by the co nsumer at any time. |
---|
2340 | 2358 | | C. A business may not use fina ncial incentive practices that |
---|
2341 | 2359 | | are unjust, unreasonable, coer cive or usurious in nature. |
---|
2342 | 2360 | | SECTION 24. NEW LAW A new section of law to be codified |
---|
2343 | 2361 | | in the Oklahoma Statutes as Section 9 01.24 of Title 17, unless there |
---|
2344 | 2362 | | is created a duplication in numbering, reads as follows: |
---|
2345 | 2363 | | A. A business may not divide a single transaction into more |
---|
2346 | 2364 | | than one transaction with the intent to avoid the requirements of |
---|
2347 | 2365 | | this act. |
---|
2384 | 2403 | | SECTION 25. NEW LAW A new section of law to be codified |
---|
2385 | 2404 | | in the Oklahoma Statutes as Section 901.2 5 of Title 17, unless there |
---|
2386 | 2405 | | is created a duplication in numbering, reads as follows: |
---|
2387 | 2406 | | A business shall ensure that each person responsible for |
---|
2388 | 2407 | | handling consumer inquiries about the business's privacy practices |
---|
2389 | 2408 | | or compliance with this act is informed of the requirements of this |
---|
2390 | 2409 | | act and of how to direct a consumer in exercising any of the rights |
---|
2391 | 2410 | | to which a consumer is entitled under this a ct. |
---|
2392 | 2411 | | SECTION 26. NEW LAW A new section of law to be codified |
---|
2393 | 2412 | | in the Oklahoma Statutes as Section 901.2 6 of Title 17, unless there |
---|
2394 | 2413 | | is created a duplication in numbering, reads as follows: |
---|
2395 | 2414 | | A. A person who violates this a ct is liable to this state for |
---|
2396 | 2415 | | injunctive relief and/or a civil penalty in an amo unt not to exceed: |
---|
2397 | 2443 | | 1. Two Thousand Five Hundred Dollars ($2, 500.00) for each |
---|
2398 | 2444 | | violation; or |
---|
2399 | 2445 | | 2. Seven Thousand Five Hundred Dollars ($7,500.00) for each |
---|
2400 | 2446 | | violation, if the violation is intentional. |
---|
2401 | 2447 | | B. The Oklahoma Attorney General is entitled to recover |
---|
2402 | 2448 | | reasonable expenses, including reasonable attorney fees, court costs |
---|
2403 | 2449 | | and investigatory costs, incurred in obtaining injunctive relief or |
---|
2404 | 2450 | | civil penalties, or both, under this section. Amounts collected |
---|
2405 | 2451 | | under this section shall be deposite d in a dedicated acc ount in the |
---|
2406 | 2452 | | General Revenue Fund and shall be appropriated only for the purposes |
---|
2407 | 2453 | | of the administration and enforcement of this act. |
---|
2434 | 2454 | | SECTION 27. NEW LAW A new section of law to be cod ified |
---|
2435 | 2455 | | in the Oklahoma Statutes as Section 901.27 of Title 17, unless there |
---|
2436 | 2456 | | is created a duplication in numbering , reads as follows: |
---|
2437 | 2457 | | A business that disclos es to a third party, or discloses for a |
---|
2438 | 2458 | | business purpose to a service provider, a consumer 's personal |
---|
2439 | 2459 | | information in compliance with this act may not be held liable for a |
---|
2440 | 2460 | | violation of this act by the third party o r service provider if the |
---|
2441 | 2461 | | business does not have actual knowledge or a reasonable belief that |
---|
2442 | 2462 | | the third party or service provider intends to vio late this act. |
---|
2443 | 2463 | | SECTION 28. NEW LAW A new section of law to be codified |
---|
2444 | 2464 | | in the Oklahoma Statutes as Section 901.28 of Title 17, unless there |
---|
2445 | 2465 | | is created a duplication in numbering, reads as follows: |
---|