1 | 1 | | |
---|
2 | 2 | | |
---|
3 | 3 | | |
---|
4 | 4 | | |
---|
5 | 5 | | 2023 -- H 5745 |
---|
6 | 6 | | ======== |
---|
7 | 7 | | LC000015 |
---|
8 | 8 | | ======== |
---|
9 | 9 | | S TATE OF RHODE IS LAND |
---|
10 | 10 | | IN GENERAL ASSEMBLY |
---|
11 | 11 | | JANUARY SESSION, A.D. 2023 |
---|
12 | 12 | | ____________ |
---|
13 | 13 | | |
---|
14 | 14 | | A N A C T |
---|
15 | 15 | | RELATING TO COMMERCI AL LAW -- RHODE ISLAND PERSONAL DATA AND |
---|
16 | 16 | | ONLINE PRIVACY PROTECTION ACT |
---|
17 | 17 | | Introduced By: Representative Joseph M. McNamara |
---|
18 | 18 | | Date Introduced: February 21, 2023 |
---|
19 | 19 | | Referred To: House Innovation, Internet, & Technology |
---|
20 | 20 | | |
---|
21 | 21 | | |
---|
22 | 22 | | It is enacted by the General Assembly as follows: |
---|
23 | 23 | | SECTION 1. Title 6 of the General Laws entitled "COMMERCIAL LAW — GENERAL 1 |
---|
24 | 24 | | REGULATORY PROVISIONS" is hereby amended by adding thereto the following chapter: 2 |
---|
25 | 25 | | CHAPTER 59 3 |
---|
26 | 26 | | RHODE ISLAND PERSONAL DATA AND ONLINE PRIVACY PROTECTION ACT 4 |
---|
27 | 27 | | 6-59-1. Short title. 5 |
---|
28 | 28 | | This act shall be known and may be cited as the "Rhode Island personal data and online 6 |
---|
29 | 29 | | privacy protection act." 7 |
---|
30 | 30 | | 6-59-2. Definitions. 8 |
---|
31 | 31 | | As used in this chapter, the following words and phrases shall have the following meanings, 9 |
---|
32 | 32 | | unless the context clearly indicates otherwise: 10 |
---|
33 | 33 | | (1) "Affiliate" means a legal entity that shares common branding with another legal entity 11 |
---|
34 | 34 | | or controls, is controlled by, or is under common control with, another legal entity. For the purposes 12 |
---|
35 | 35 | | of this definition, "control" or "controlled" means: 13 |
---|
36 | 36 | | (i) Ownership of, or the power to vote, more than fifty percent (50%) of the outstanding 14 |
---|
37 | 37 | | shares of any class of voting security of a company; 15 |
---|
38 | 38 | | (ii) Control in any manner over the election of a majority of the directors or of individua ls 16 |
---|
39 | 39 | | exercising similar functions; or 17 |
---|
40 | 40 | | (iii) The power to exercise controlling influence over the management of a company. 18 |
---|
41 | 41 | | |
---|
42 | 42 | | |
---|
43 | 43 | | LC000015 - Page 2 of 21 |
---|
44 | 44 | | (2) "Authenticate" means to use reasonable means to determine that a request to exercise 1 |
---|
45 | 45 | | any of the rights afforded under this chapter being made by, or on behalf of, the consumer who is 2 |
---|
46 | 46 | | entitled to exercise such consumer rights with respect to the personal data at issue. 3 |
---|
47 | 47 | | (3) "Biometric data" means data generated by automatic measurements of an individual's 4 |
---|
48 | 48 | | biological characteristics, such as a fingerprint, a voiceprint, eye retinas, irises or other unique 5 |
---|
49 | 49 | | biological patterns or characteristics that are used to identify a specific individual. "Biometric data" 6 |
---|
50 | 50 | | does not include: 7 |
---|
51 | 51 | | (i) A digital or physical photograph; 8 |
---|
52 | 52 | | (ii) An audio or video recording; or 9 |
---|
53 | 53 | | (iii) Any data generated from a digital or physical photograph, or an audio or video 10 |
---|
54 | 54 | | recording, unless such data is generated to identify a specific individual. 11 |
---|
55 | 55 | | (4) "Business associate" has the same meaning as provided in HIPAA. 12 |
---|
56 | 56 | | (5) "Child" has the same meaning as provided in COPPA. 13 |
---|
57 | 57 | | (6) "Consent" means a clear affirmative act signifying a consumer's freely given, specific, 14 |
---|
58 | 58 | | informed and unambiguous agreement to allow the processing of personal data relating to the 15 |
---|
59 | 59 | | consumer. "Consent" may include a written statement, including by electronic means, or any other 16 |
---|
60 | 60 | | unambiguous affirmative action. "Consent" does not include: 17 |
---|
61 | 61 | | (i) Acceptance of a general or broad terms of use or similar document that contains 18 |
---|
62 | 62 | | descriptions of personal data processing along with other, unrelated information; 19 |
---|
63 | 63 | | (ii) Hovering over, muting, pausing or closing a given piece of content; or 20 |
---|
64 | 64 | | (iii) Agreement obtained through the use of dark patterns. 21 |
---|
65 | 65 | | (7) "Consumer" means an individual who is a resident of the State of Rhode Island. 22 |
---|
66 | 66 | | "Consumer" does not include an individual acting in a commercial or employment context or as an 23 |
---|
67 | 67 | | employee, owner, director, officer or contractor of a company, partnership, sole proprietorship, 24 |
---|
68 | 68 | | nonprofit or government agency whose communications or transactions with the controller occur 25 |
---|
69 | 69 | | solely within the context of that individual's role with the company, partnership, sole proprietorship, 26 |
---|
70 | 70 | | nonprofit, or government agency. 27 |
---|
71 | 71 | | (8) "Controller" means an individual who, or legal entity that, alone or jointly with others 28 |
---|
72 | 72 | | determines the purpose and means of processing personal data. 29 |
---|
73 | 73 | | (9) "COPPA" means the Children's Online Privacy Protection Act of 1998, 15 U.S.C. §§ 30 |
---|
74 | 74 | | 6501 et seq., and the regulations, rules, guidance and exemptions adopted pursuant to said act, as 31 |
---|
75 | 75 | | said act and such regulations, rules, guidance and exemptions may be amended from time to time. 32 |
---|
76 | 76 | | (10) "Covered entity" has the same meaning as provided in HIPAA. 33 |
---|
77 | 77 | | (11) "Dark pattern" means a user interface designed or manipulated with the substantial 34 |
---|
78 | 78 | | |
---|
79 | 79 | | |
---|
80 | 80 | | LC000015 - Page 3 of 21 |
---|
81 | 81 | | effect of subverting or impairing user autonomy, decision-making or choice, and includes, but is 1 |
---|
82 | 82 | | not limited to, any practice the Federal Trade Commission refers to as a "dark pattern". 2 |
---|
83 | 83 | | (12) "Decisions that produce legal or similarly significant effects concerning the consumer" 3 |
---|
84 | 84 | | means decisions made by the controller that result in the provision or denial by the controller of 4 |
---|
85 | 85 | | financial or lending services, housing, insurance, education enrollment or opportunity, criminal 5 |
---|
86 | 86 | | justice, employment opportunities, health care services or access to essential goods or services. 6 |
---|
87 | 87 | | (13) "De-identified data" means data that cannot reasonably be used to infer information 7 |
---|
88 | 88 | | about, or otherwise be linked to, an identified or identifiable individual, or a device linked to such 8 |
---|
89 | 89 | | individual, if the controller that possesses such data takes reasonable measures to ensure that such 9 |
---|
90 | 90 | | data cannot be associated with an individual, publicly commits to process such data only in a de-10 |
---|
91 | 91 | | identified fashion and not attempt to re-identify such data, and contractually obligates any 11 |
---|
92 | 92 | | recipients of such data to satisfy the criteria set forth in this subsection. 12 |
---|
93 | 93 | | (14) "HIPAA" means the Health Insurance Portability and Accountability Act of 1996, 42 13 |
---|
94 | 94 | | U.S.C. § 1320d, as amended from time to time. 14 |
---|
95 | 95 | | (15) "Identified or identifiable individual" means an individual who can be readily 15 |
---|
96 | 96 | | identified, directly or indirectly. 16 |
---|
97 | 97 | | (16) "Institution of higher education" means any individual who, or school, board, 17 |
---|
98 | 98 | | association, limited liability company or corporation that, is licensed or accredited to offer one or 18 |
---|
99 | 99 | | more programs of higher learning leading to one or more degrees. 19 |
---|
100 | 100 | | (17) "Nonprofit organization" means any organization that is exempt from taxation under 20 |
---|
101 | 101 | | 26 U.S.C. §§ 501(c)(3), 501(c)(4), 501(c)(6) or 501(c)(12) of the Internal Revenue Code of 1986, 21 |
---|
102 | 102 | | or any subsequent corresponding internal revenue code of the United States, as amended from time 22 |
---|
103 | 103 | | to time. 23 |
---|
104 | 104 | | (18) "Personal data" means any information that is linked or reasonably linkable to an 24 |
---|
105 | 105 | | identified or identifiable individual. "Personal data" does not include de-identified data or publicly 25 |
---|
106 | 106 | | available information. 26 |
---|
107 | 107 | | (19) "Precise geolocation data" means information derived from technology, including, but 27 |
---|
108 | 108 | | not limited to, global positioning system level latitude and longitude coordinates or other 28 |
---|
109 | 109 | | mechanisms, that directly identifies the specific location of an individual with precision and 29 |
---|
110 | 110 | | accuracy within a radius of one thousand seven hundred fifty feet (1750'). "Precise geolocation 30 |
---|
111 | 111 | | data" does not include the content of communications or any data generated by or connected to 31 |
---|
112 | 112 | | advanced utility metering infrastructure systems or equipment for use by a utility. 32 |
---|
113 | 113 | | (20) "Process" or "processing" means any operation or set of operations performed, 33 |
---|
114 | 114 | | whether by manual or automated means, on personal data or on sets of personal data, such as the 34 |
---|
115 | 115 | | |
---|
116 | 116 | | |
---|
117 | 117 | | LC000015 - Page 4 of 21 |
---|
118 | 118 | | collection, use, storage, disclosure, analysis, deletion or modification of personal data. 1 |
---|
119 | 119 | | (21) "Processor" means an individual who, or legal entity that, processes personal data on 2 |
---|
120 | 120 | | behalf of a controller. 3 |
---|
121 | 121 | | (22) "Profiling" means any form of automated processing performed on personal data to 4 |
---|
122 | 122 | | evaluate, analyze or predict personal aspects related to an identified or identifiable individua l's 5 |
---|
123 | 123 | | economic situation, health, personal preferences, interests, reliability, behavior, location or 6 |
---|
124 | 124 | | movements. 7 |
---|
125 | 125 | | (23) "Protected health information" has the same meaning as provided in HIPAA. 8 |
---|
126 | 126 | | (24) "Pseudonymous data" means personal data that cannot be attributed to a specific 9 |
---|
127 | 127 | | individual without the use of additional information, provided such additional information is kept 10 |
---|
128 | 128 | | separately and is subject to appropriate technical and organizational measures to ensure that the 11 |
---|
129 | 129 | | personal data is not attributed to an identified or identifiable individual. 12 |
---|
130 | 130 | | (25) "Publicly available information" means information that: 13 |
---|
131 | 131 | | (i) Is lawfully made available through federal, state or municipal government records or 14 |
---|
132 | 132 | | widely distributed media; and 15 |
---|
133 | 133 | | (ii) A controller has a reasonable basis to believe a consumer has lawfully made available 16 |
---|
134 | 134 | | to the general public. 17 |
---|
135 | 135 | | (26) "Sale of personal data" means the exchange of personal data for monetary or other 18 |
---|
136 | 136 | | valuable consideration by the controller to a third party. "Sale of personal data" does not include: 19 |
---|
137 | 137 | | (i) The disclosure of personal data to a processor that processes the personal data on behalf 20 |
---|
138 | 138 | | of the controller; 21 |
---|
139 | 139 | | (ii) The disclosure of personal data to a third party for purposes of providing a product or 22 |
---|
140 | 140 | | service requested by the consumer; 23 |
---|
141 | 141 | | (iii) The disclosure or transfer of personal data to an affiliate of the controller; 24 |
---|
142 | 142 | | (iv) The disclosure of personal data where the consumer directs the controller to disclose 25 |
---|
143 | 143 | | the personal data or intentionally uses the controller to interact with a third party; 26 |
---|
144 | 144 | | (v) The disclosure of personal data that the consumer intentionally made available to the 27 |
---|
145 | 145 | | general public via a channel of mass media, and did not restrict to a specific audience; and 28 |
---|
146 | 146 | | (vi) The disclosure or transfer of personal data to a third party as an asset that is part of a 29 |
---|
147 | 147 | | merger, acquisition, bankruptcy or other transaction, or a proposed merger, acquisition, bankruptcy 30 |
---|
148 | 148 | | or other transaction, in which the third party assumes control of all or part of the controller's assets. 31 |
---|
149 | 149 | | (27) "Sensitive data" means personal data that includes: 32 |
---|
150 | 150 | | (i) Data revealing racial or ethnic origin, religious beliefs, mental or physical health 33 |
---|
151 | 151 | | condition or diagnosis, sex life, sexual orientation or citizenship or immigration status; 34 |
---|
152 | 152 | | |
---|
153 | 153 | | |
---|
154 | 154 | | LC000015 - Page 5 of 21 |
---|
155 | 155 | | (ii) The processing of genetic or biometric data for the purpose of uniquely identifying an 1 |
---|
156 | 156 | | individual; 2 |
---|
157 | 157 | | (iii) Personal data collected from a known child; or 3 |
---|
158 | 158 | | (iv) Precise geolocation data. 4 |
---|
159 | 159 | | (28) "Targeted advertising" means displaying advertisements to a consumer where the 5 |
---|
160 | 160 | | advertisement is selected based on personal data obtained or inferred from that consumer's activities 6 |
---|
161 | 161 | | over time and across nonaffiliated Internet websites or online applications to predict such 7 |
---|
162 | 162 | | consumer's preferences or interests. "Targeted advertising" does not include: 8 |
---|
163 | 163 | | (i) Advertisements based on activities within a controller's own Internet websites or online 9 |
---|
164 | 164 | | applications; 10 |
---|
165 | 165 | | (ii) Advertisements based on the context of a consumer's current search query, visit to an 11 |
---|
166 | 166 | | Internet website or online application; 12 |
---|
167 | 167 | | (iii) Advertisements directed to a consumer in response to the consumer's request for 13 |
---|
168 | 168 | | information or feedback; or 14 |
---|
169 | 169 | | (iv) Processing personal data solely to measure or report advertising frequency, 15 |
---|
170 | 170 | | performance or reach. 16 |
---|
171 | 171 | | (29) "Third-party" means an individual or legal entity, such as a public authority, agency 17 |
---|
172 | 172 | | or body, other than the consumer, controller or processor or an affiliate of the processor or the 18 |
---|
173 | 173 | | controller. 19 |
---|
174 | 174 | | (30) "Trade secret" has the same meaning as provided in § 6-41-1. 20 |
---|
175 | 175 | | 6-59-3. Application of chapter. 21 |
---|
176 | 176 | | (a) The provisions of this chapter apply to persons that conduct business in this state or 22 |
---|
177 | 177 | | persons that produce products or services that are targeted to residents of this state and that during 23 |
---|
178 | 178 | | the preceding calendar year: 24 |
---|
179 | 179 | | (1) Controlled or processed the personal data of not less than one hundred thousand 25 |
---|
180 | 180 | | (100,000) consumers, excluding personal data controlled or processed solely for the purpose of 26 |
---|
181 | 181 | | completing a payment transaction; or 27 |
---|
182 | 182 | | (2) Controlled or processed the personal data of not less than twenty-five thousand (25,000) 28 |
---|
183 | 183 | | consumers and derived more than twenty-five percent (25%) of their gross revenue from the sale 29 |
---|
184 | 184 | | of personal data. 30 |
---|
185 | 185 | | 6-59-4. Limitations of chapter. 31 |
---|
186 | 186 | | (a) The provisions of this chapter do not apply to any: 32 |
---|
187 | 187 | | (1) Body, authority, board, bureau, commission, district or agency of this state or of any 33 |
---|
188 | 188 | | political subdivision of this state; 34 |
---|
189 | 189 | | |
---|
190 | 190 | | |
---|
191 | 191 | | LC000015 - Page 6 of 21 |
---|
192 | 192 | | (2) Nonprofit organization; 1 |
---|
193 | 193 | | (3) Institution of higher education; 2 |
---|
194 | 194 | | (4) National securities association that is registered under 15 U.S.C. § 78o-3 of the 3 |
---|
195 | 195 | | Securities Exchange Act of 1934, as amended from time to time; 4 |
---|
196 | 196 | | (5) Financial institution or data subject to Title V of the Gramm-Leach-Bliley Act, 15 5 |
---|
197 | 197 | | U.S.C. §§ 6801 et seq.; or 6 |
---|
198 | 198 | | (6) Covered entity or business associate, as defined in 45 C.F.R. 160.103. 7 |
---|
199 | 199 | | (b) The following information and data is exempt from the provisions of this chapter: 8 |
---|
200 | 200 | | (1) Protected health information under HIPAA; 9 |
---|
201 | 201 | | (2) Patient-identifying information for purposes of 42 U.S.C. § 290dd-2; 10 |
---|
202 | 202 | | (3) Identifiable private information for purposes of the federal policy for the protection of 11 |
---|
203 | 203 | | human subjects under 45 C.F.R. 46; 12 |
---|
204 | 204 | | (4) Identifiable private information that is otherwise information collected as part of human 13 |
---|
205 | 205 | | subjects research pursuant to the good clinical practice guidelines issued by the International 14 |
---|
206 | 206 | | Council for Harmonization of Technical Requirements for Pharmaceuticals for Human Use; 15 |
---|
207 | 207 | | (5) The protection of human subjects under 21 C.F.R. Parts 6, 50 and 56, or personal data 16 |
---|
208 | 208 | | used or shared in research, as defined in 45 C.F.R. 164.501, that is conducted in accordance with 17 |
---|
209 | 209 | | the standards set forth in subsection (b)(5) of this section and subsections (b)(3) and (4) of this 18 |
---|
210 | 210 | | section, or other research conducted in accordance with applicable law; 19 |
---|
211 | 211 | | (6) Information and documents created for purposes of the Health Care Quality 20 |
---|
212 | 212 | | Improvement Act of 1986, 42 U.S.C. §§ 11101 et seq.; 21 |
---|
213 | 213 | | (7) Patient safety work product for purposes of the Patient Safety and Quality Improvement 22 |
---|
214 | 214 | | Act, 42 U.S.C. §§ 299b-21 et seq., as amended from time to time; 23 |
---|
215 | 215 | | (8) Information derived from any of the health care related information listed in this 24 |
---|
216 | 216 | | subsection that is de-identified in accordance with the requirements for de-identification pursuant 25 |
---|
217 | 217 | | to HIPAA; 26 |
---|
218 | 218 | | (9) Information originating from and intermingled to be indistinguishable with, or 27 |
---|
219 | 219 | | information treated in the same manner as, information exempt under this subsection that is 28 |
---|
220 | 220 | | maintained by a covered entity or business associate, program or qualified service organization, as 29 |
---|
221 | 221 | | specified in 42 U.S.C. § 290dd-2, as amended from time to time; 30 |
---|
222 | 222 | | (10) Information used for public health activities and purposes as authorized by HIPAA, 31 |
---|
223 | 223 | | community health activities and population health activities; 32 |
---|
224 | 224 | | (11) The collection, maintenance, disclosure, sale, communication or use of any personal 33 |
---|
225 | 225 | | information bearing on a consumer's credit worthiness, credit standing, credit capacity, character, 34 |
---|
226 | 226 | | |
---|
227 | 227 | | |
---|
228 | 228 | | LC000015 - Page 7 of 21 |
---|
229 | 229 | | general reputation, personal characteristics or mode of living by a consumer reporting agency, 1 |
---|
230 | 230 | | furnisher or user that provides information for use in a consumer report, and by a user of a consumer 2 |
---|
231 | 231 | | report, but only to the extent that such activity is regulated by and authorized under the Fair Credit 3 |
---|
232 | 232 | | Reporting Act, 15 U.S.C. §§ 1681 et seq., as amended from time to time; 4 |
---|
233 | 233 | | (12) Personal data collected, processed, sold or disclosed in compliance with the Driver's 5 |
---|
234 | 234 | | Privacy Protection Act of 1994, 18 U.S.C. §§ 2721 et seq., as amended from time to time; 6 |
---|
235 | 235 | | (13) Personal data regulated by the Family Educational Rights and Privacy Act, 20 U.S.C. 7 |
---|
236 | 236 | | §§ 1232g et seq., as amended from time to time; 8 |
---|
237 | 237 | | (14) Personal data collected, processed, sold or disclosed in compliance with the Farm 9 |
---|
238 | 238 | | Credit Act, 12 U.S.C. §§ 2001 et seq., as amended from time to time; 10 |
---|
239 | 239 | | (15) Data processed or maintained: 11 |
---|
240 | 240 | | (i) In the course of an individual applying to, employed by or acting as an agent or 12 |
---|
241 | 241 | | independent contractor of a controller, processor or third-party, to the extent that the data is 13 |
---|
242 | 242 | | collected and used within the context of that role; 14 |
---|
243 | 243 | | (ii) As the emergency contact information of an individual under this section used for 15 |
---|
244 | 244 | | emergency contact purposes; or 16 |
---|
245 | 245 | | (iii) That is necessary to retain to administer benefits for another individual relating to the 17 |
---|
246 | 246 | | individual who is the subject of the information, and is used for the purposes of administering such 18 |
---|
247 | 247 | | benefits; and 19 |
---|
248 | 248 | | (16) Personal data collected, processed, sold or disclosed in relation to price, route or 20 |
---|
249 | 249 | | service, as such terms are used in the Airline Deregulation Act, 49 U.S.C. §§ 40101 et seq., as 21 |
---|
250 | 250 | | amended from time to time, by an air carrier subject to said act, to the extent the provisions of this 22 |
---|
251 | 251 | | act are preempted by the Airline Deregulation Act, 49 U.S.C. § 41713, as amended from time to 23 |
---|
252 | 252 | | time. 24 |
---|
253 | 253 | | (c) Controllers and processors that comply with the verifiable parental consent 25 |
---|
254 | 254 | | requirements of COPPA shall be deemed compliant with any obligation to obtain parental consent 26 |
---|
255 | 255 | | pursuant to subsections (a) and (b) of this section, inclusive, of this chapter. 27 |
---|
256 | 256 | | 6-59-5. Consumer rights. 28 |
---|
257 | 257 | | (a) A consumer shall have the right to: 29 |
---|
258 | 258 | | (1) Confirm whether or not a controller is processing the consumer's personal data and 30 |
---|
259 | 259 | | access to such personal data, unless such confirmation or access would require the controller to 31 |
---|
260 | 260 | | reveal a trade secret; 32 |
---|
261 | 261 | | (2) Correct inaccuracies in the consumer's personal data, taking into account the nature of 33 |
---|
262 | 262 | | the personal data and the purposes of the processing of the consumer's personal data; 34 |
---|
263 | 263 | | |
---|
264 | 264 | | |
---|
265 | 265 | | LC000015 - Page 8 of 21 |
---|
266 | 266 | | (3) Delete personal data provided by, or obtained about, the consumer; 1 |
---|
267 | 267 | | (4) Obtain a copy of the consumer's personal data processed by the controller, in a portable 2 |
---|
268 | 268 | | and, to the extent technically feasible, readily usable format that allows the consumer to transmit 3 |
---|
269 | 269 | | the data to another controller without hindrance, where the processing is carried out by automated 4 |
---|
270 | 270 | | means, provided such controller shall not be required to reveal any trade secret; and 5 |
---|
271 | 271 | | (5) Opt out of the processing of the personal data for purposes of: 6 |
---|
272 | 272 | | (i) Targeted advertising; 7 |
---|
273 | 273 | | (ii) The sale of personal data, except as provided otherwise in this chapter; or 8 |
---|
274 | 274 | | (iii) Profiling in furtherance of solely automated decisions that produce legal or similarly 9 |
---|
275 | 275 | | significant effects concerning the consumer. 10 |
---|
276 | 276 | | (b) A consumer may exercise rights under this section by a secure and reliable means 11 |
---|
277 | 277 | | established by the controller and described to the consumer in the controller's privacy notice. A 12 |
---|
278 | 278 | | consumer may designate an authorized agent in accordance with this chapter to exercise the rights 13 |
---|
279 | 279 | | of such consumer to opt out of the processing of such consumer's personal data for purposes of this 14 |
---|
280 | 280 | | section on behalf of the consumer. In the case of processing personal data of a known child, the 15 |
---|
281 | 281 | | parent or legal guardian may exercise such consumer rights on the child's behalf. In the case of 16 |
---|
282 | 282 | | processing personal data concerning a consumer subject to a guardianship, conservatorship or other 17 |
---|
283 | 283 | | protective arrangement, the guardian or the conservator of the consumer may exercise such rights 18 |
---|
284 | 284 | | on the consumer's behalf. 19 |
---|
285 | 285 | | (c) Except as expressly otherwise provided in this chapter, a controller shall comply with 20 |
---|
286 | 286 | | a request by a consumer to exercise the consumer rights authorized by this chapter as follows: 21 |
---|
287 | 287 | | (1) A controller shall respond to the consumer without undue delay, but not later than forty-22 |
---|
288 | 288 | | five (45) days after receipt of the request. The controller may extend the response period by forty-23 |
---|
289 | 289 | | five (45) additional days when reasonably necessary, considering the complexity and number of 24 |
---|
290 | 290 | | the consumer's requests, provided the controller informs the consumer of any such extension within 25 |
---|
291 | 291 | | the initial forty-five (45) day response period and of the reason for the extension. 26 |
---|
292 | 292 | | (2) If a controller declines to take action regarding the consumer's request, the controller 27 |
---|
293 | 293 | | shall inform the consumer without undue delay, but not later than forty-five (45) days after receipt 28 |
---|
294 | 294 | | of the request, of the justification for declining to take action and instructions for how to appeal the 29 |
---|
295 | 295 | | decision. 30 |
---|
296 | 296 | | (3) Information provided in response to a consumer request shall be provided by a 31 |
---|
297 | 297 | | controller, free of charge, once per consumer during any twelve (12) month period. If requests from 32 |
---|
298 | 298 | | a consumer are manifestly unfounded, excessive or repetitive, the controller may charge the 33 |
---|
299 | 299 | | consumer a reasonable fee to cover the administrative costs of complying with the request or 34 |
---|
300 | 300 | | |
---|
301 | 301 | | |
---|
302 | 302 | | LC000015 - Page 9 of 21 |
---|
303 | 303 | | decline to act on the request. The controller bears the burden of demonstrating the manifestly 1 |
---|
304 | 304 | | unfounded, excessive or repetitive nature of the request. 2 |
---|
305 | 305 | | (4) If a controller is unable to authenticate a request to exercise any of the rights afforded 3 |
---|
306 | 306 | | under subsection (a) of this section using commercially reasonable efforts, the controller shall not 4 |
---|
307 | 307 | | be required to comply with a request to initiate an action pursuant to this section and shall provide 5 |
---|
308 | 308 | | notice to the consumer that the controller is unable to authenticate the request to exercise such right 6 |
---|
309 | 309 | | or rights until such consumer provides additional information reasonably necessary to authenticate 7 |
---|
310 | 310 | | such consumer and such consumer's request to exercise such right or rights. A controller shall not 8 |
---|
311 | 311 | | be required to authenticate an opt-out request, but a controller may deny an opt-out request if the 9 |
---|
312 | 312 | | controller has a good faith, reasonable and documented belief that such request is fraudulent. If a 10 |
---|
313 | 313 | | controller denies an opt-out request because the controller believes such request is fraudulent, the 11 |
---|
314 | 314 | | controller shall send a notice to the person who made such request disclosing that such controller 12 |
---|
315 | 315 | | believes such request is fraudulent, why such controller believes such request is fraudulent and that 13 |
---|
316 | 316 | | such controller shall not comply with such request. 14 |
---|
317 | 317 | | (5) A controller that has obtained personal data about a consumer from a source other than 15 |
---|
318 | 318 | | the consumer shall be deemed in compliance with a consumer's request to delete such data pursuant 16 |
---|
319 | 319 | | to this section by: 17 |
---|
320 | 320 | | (i) Retaining a record of the deletion request and the minimum data necessary for the 18 |
---|
321 | 321 | | purpose of ensuring the consumer's personal data remains deleted from the controller's records and 19 |
---|
322 | 322 | | not using such retained data for any other purpose pursuant to the provisions of this chapter; or 20 |
---|
323 | 323 | | (ii) Opting the consumer out of the processing of such personal data for any purpose except 21 |
---|
324 | 324 | | for those exempted pursuant to the provisions of this chapter. 22 |
---|
325 | 325 | | (d) A controller shall establish a process for a consumer to appeal the controller's refusal 23 |
---|
326 | 326 | | to take action on a request within a reasonable period of time after the consumer's receipt of the 24 |
---|
327 | 327 | | decision. The appeal process shall be conspicuously available and similar to the process for 25 |
---|
328 | 328 | | submitting requests to initiate action pursuant to this section. Not later than sixty (60) days after 26 |
---|
329 | 329 | | receipt of an appeal, a controller shall inform the consumer in writing of any action taken or not 27 |
---|
330 | 330 | | taken in response to the appeal, including a written explanation of the reasons for the decisions. If 28 |
---|
331 | 331 | | the appeal is denied, the controller shall also provide the consumer with an online mechanism, if 29 |
---|
332 | 332 | | available, or other method through which the consumer may contact the attorney general to submit 30 |
---|
333 | 333 | | a complaint. 31 |
---|
334 | 334 | | 6-59-6. Designation of agent. 32 |
---|
335 | 335 | | A consumer may designate another person to serve as the consumer's authorized agent, and 33 |
---|
336 | 336 | | act on such consumer's behalf, to opt-out of the processing of such consumer's personal data for 34 |
---|
337 | 337 | | |
---|
338 | 338 | | |
---|
339 | 339 | | LC000015 - Page 10 of 21 |
---|
340 | 340 | | one or more of the purposes specified in this chapter. The consumer may designate such authorized 1 |
---|
341 | 341 | | agent by way of, among other things, a technology, including, but not limited to, an Internet link 2 |
---|
342 | 342 | | or a browser setting, browser extension or global device setting, indicating such consumer's intent 3 |
---|
343 | 343 | | to opt-out of such processing. A controller shall comply with an opt-out request received from an 4 |
---|
344 | 344 | | authorized agent if the controller is able to verify, with commercially reasonable effort, the identity 5 |
---|
345 | 345 | | of the consumer and the authorized agent's authority to act on such consumer’s behalf. 6 |
---|
346 | 346 | | 6-59-7. Actions of controller. 7 |
---|
347 | 347 | | (a) A controller shall: 8 |
---|
348 | 348 | | (1) Limit the collection of personal data to what is adequate, relevant and reasonably 9 |
---|
349 | 349 | | necessary in relation to the purposes for which such data is processed, as disclosed to the consumer; 10 |
---|
350 | 350 | | (2) Except as otherwise provided in this chapter, not process personal data for purposes 11 |
---|
351 | 351 | | that are neither reasonably necessary to, nor compatible with, the disclosed purposes for which such 12 |
---|
352 | 352 | | personal data is processed, as disclosed to the consumer, unless the controller obtains the 13 |
---|
353 | 353 | | consumer's consent; 14 |
---|
354 | 354 | | (3) Establish, implement and maintain reasonable administrative, technical and physical 15 |
---|
355 | 355 | | data security practices to protect the confidentiality, integrity and accessibility of personal data 16 |
---|
356 | 356 | | appropriate to the volume and nature of the personal data at issue; 17 |
---|
357 | 357 | | (4) Not process sensitive data concerning a consumer without obtaining the consumer's 18 |
---|
358 | 358 | | consent, or, in the case of the processing of sensitive data concerning a known child, without 19 |
---|
359 | 359 | | processing such data in accordance with COPPA; 20 |
---|
360 | 360 | | (5) Not process personal data in violation of the laws of this state and federal laws that 21 |
---|
361 | 361 | | prohibit unlawful discrimination against consumers; 22 |
---|
362 | 362 | | (6) Provide an effective mechanism for a consumer to revoke the consumer's consent under 23 |
---|
363 | 363 | | this section that is at least as easy as the mechanism by which the consumer provided the consumer's 24 |
---|
364 | 364 | | consent and, upon revocation of such consent, cease to process the data as soon as practicable, but 25 |
---|
365 | 365 | | not later than fifteen (15) days after the receipt of such request; and 26 |
---|
366 | 366 | | (7) Not process the personal data of a consumer for purposes of targeted advertising, or sell 27 |
---|
367 | 367 | | the consumer's personal data without the consumer's consent, under circumstances where a 28 |
---|
368 | 368 | | controller has actual knowledge, and wilfully disregards, that the consumer is at least thirteen (13) 29 |
---|
369 | 369 | | years of age, but younger than sixteen (16) years of age. A controller shall not discriminate against 30 |
---|
370 | 370 | | a consumer for exercising any of the consumer rights contained in this chapter, including denying 31 |
---|
371 | 371 | | goods or services, charging different prices or rates for goods or services or providing a different 32 |
---|
372 | 372 | | level of quality of goods or services to the consumer. 33 |
---|
373 | 373 | | (b) Nothing in subsection (a) of this section shall be construed to require a controller to 34 |
---|
374 | 374 | | |
---|
375 | 375 | | |
---|
376 | 376 | | LC000015 - Page 11 of 21 |
---|
377 | 377 | | provide a product or service that requires the personal data of a consumer which the controller does 1 |
---|
378 | 378 | | not collect or maintain, or prohibit a controller from offering a different price, rate, level, quality 2 |
---|
379 | 379 | | or selection of goods or services to a consumer, including offering goods or services for no fee, if 3 |
---|
380 | 380 | | the offering is in connection with a consumer's voluntary participation in a bona fide loyalty, 4 |
---|
381 | 381 | | rewards, premium features, discounts or club card program. 5 |
---|
382 | 382 | | (c) A controller shall provide consumers with a reasonably accessible, clear and meaningful 6 |
---|
383 | 383 | | privacy notice that includes: 7 |
---|
384 | 384 | | (1) The categories of personal data processed by the controller; 8 |
---|
385 | 385 | | (2) The purpose for processing personal data; 9 |
---|
386 | 386 | | (3) How consumers may exercise their consumer rights, including how a consumer may 10 |
---|
387 | 387 | | appeal a controller's decision with regard to the consumer's request; 11 |
---|
388 | 388 | | (4) The categories of personal data that the controller shares with third parties, if any; 12 |
---|
389 | 389 | | (5) The categories of third parties, if any, with which the controller shares personal data; 13 |
---|
390 | 390 | | and 14 |
---|
391 | 391 | | (6) An active electronic mail address or other online mechanism that the consumer may 15 |
---|
392 | 392 | | use to contact the controller. 16 |
---|
393 | 393 | | (d) If a controller sells personal data to third parties or processes personal data for targeted 17 |
---|
394 | 394 | | advertising, the controller shall clearly and conspicuously disclose such processing, as well as the 18 |
---|
395 | 395 | | manner in which a consumer may exercise the right to opt out of such processing. 19 |
---|
396 | 396 | | (e) A controller shall establish, and shall describe in a privacy notice, one or more secure 20 |
---|
397 | 397 | | and reliable means for consumers to submit a request to exercise their consumer rights pursuant to 21 |
---|
398 | 398 | | the provisions of this chapter. Such means shall take into account the ways in which consumers 22 |
---|
399 | 399 | | normally interact with the controller, the need for secure and reliable communication of such 23 |
---|
400 | 400 | | requests and the ability of the controller to verify the identity of the consumer making the request. 24 |
---|
401 | 401 | | A controller shall not require a consumer to create a new account in order to exercise consumer 25 |
---|
402 | 402 | | rights, but may require a consumer to use an existing account. 26 |
---|
403 | 403 | | (f) The “secure and reliable means” referred to in subsection (e) of this section include: 27 |
---|
404 | 404 | | (1) Providing a clear and conspicuous link on the controller's Internet website to an Internet 28 |
---|
405 | 405 | | webpage that enables a consumer, or an agent of the consumer, to opt-out of the targeted advertising 29 |
---|
406 | 406 | | or sale of the consumer's personal data; and 30 |
---|
407 | 407 | | (2) Not later than January 1, 2025, allowing a consumer to opt out of any processing of the 31 |
---|
408 | 408 | | consumer's personal data for the purposes of targeted advertising, or any sale of such personal data, 32 |
---|
409 | 409 | | through an opt-out preference signal sent, with such consumer's consent, by a platform, technology 33 |
---|
410 | 410 | | or mechanism to the controller indicating such consumer's intent to opt-out of any such processing 34 |
---|
411 | 411 | | |
---|
412 | 412 | | |
---|
413 | 413 | | LC000015 - Page 12 of 21 |
---|
414 | 414 | | or sale. Such platform, technology or mechanism shall: 1 |
---|
415 | 415 | | (A) Not unfairly disadvantage another controller; 2 |
---|
416 | 416 | | (B) Not make use of a default setting, but, rather, require the consumer to make an 3 |
---|
417 | 417 | | affirmative, freely given and unambiguous choice to opt-out of any processing of such consumer's 4 |
---|
418 | 418 | | personal data pursuant to the provisions of this chapter; 5 |
---|
419 | 419 | | (C) Be consumer-friendly and easy to use by the average consumer; 6 |
---|
420 | 420 | | (D) Be as consistent as possible with any other similar platform, technology or mechanism 7 |
---|
421 | 421 | | required by any federal or state law or regulation; and 8 |
---|
422 | 422 | | (E) Enable the controller to accurately determine whether the consumer is a resident of this 9 |
---|
423 | 423 | | state and whether the consumer has made a legitimate request to opt-out of any sale of such 10 |
---|
424 | 424 | | consumer's personal data or targeted advertising. 11 |
---|
425 | 425 | | (g) If a consumer's decision to opt-out of any processing of the consumer's personal data 12 |
---|
426 | 426 | | for the purposes of targeted advertising, or any sale of such personal data, through an opt-out 13 |
---|
427 | 427 | | preference signal sent in accordance with the provisions of this section conflicts with the 14 |
---|
428 | 428 | | consumer's existing controller-specific privacy setting or voluntary participation in a controller's 15 |
---|
429 | 429 | | bona fide loyalty, rewards, premium features, discounts or club card program, the controller shall 16 |
---|
430 | 430 | | comply with such consumer's opt-out preference signal but may notify such consumer of such 17 |
---|
431 | 431 | | conflict and provide to such consumer the choice to confirm such controller-specific privacy setting 18 |
---|
432 | 432 | | or participation in such program. 19 |
---|
433 | 433 | | (h) If a controller responds to consumer opt‐out requests received pursuant to this 20 |
---|
434 | 434 | | subsection by informing the consumer of a charge for the use of any product or service, the 21 |
---|
435 | 435 | | controller shall present the terms of any financial incentive offered pursuant to this section for the 22 |
---|
436 | 436 | | retention, use, sale or sharing of the consumer's personal data. 23 |
---|
437 | 437 | | 6-59-8. Processor actions. 24 |
---|
438 | 438 | | (a) A processor shall adhere to the instructions of a controller and shall assist the controller 25 |
---|
439 | 439 | | in meeting the controller's obligations under the provisions of this chapter. Such assistance shall 26 |
---|
440 | 440 | | include: 27 |
---|
441 | 441 | | (1) Taking into account the nature of processing and the information available to the 28 |
---|
442 | 442 | | processor, by appropriate technical and organizational measures, insofar as is reasonably 29 |
---|
443 | 443 | | practicable, to fulfill the controller's obligation to respond to consumer rights requests; 30 |
---|
444 | 444 | | (2) Taking into account the nature of processing and the information available to the 31 |
---|
445 | 445 | | processor, by assisting the controller in meeting the controller's obligations in relation to the 32 |
---|
446 | 446 | | security of processing the personal data and in relation to the notification of a breach of security of 33 |
---|
447 | 447 | | the system of the processor, in order to meet the controller's obligations; and 34 |
---|
448 | 448 | | |
---|
449 | 449 | | |
---|
450 | 450 | | LC000015 - Page 13 of 21 |
---|
451 | 451 | | (3) Providing necessary information to enable the controller to conduct and document data 1 |
---|
452 | 452 | | protection assessments. 2 |
---|
453 | 453 | | (b) A contract between a controller and a processor shall govern the processor's data 3 |
---|
454 | 454 | | processing procedures with respect to processing performed on behalf of the controller. The 4 |
---|
455 | 455 | | contract shall be binding and clearly set forth instructions for processing data, the nature and 5 |
---|
456 | 456 | | purpose of processing, the type of data subject to processing, the duration of processing and the 6 |
---|
457 | 457 | | rights and obligations of both parties. The contract shall also require that the processor: 7 |
---|
458 | 458 | | (1) Ensure that each person processing personal data is subject to a duty of confidentiality 8 |
---|
459 | 459 | | with respect to the data; 9 |
---|
460 | 460 | | (2) At the controller's direction, delete or return all personal data to the controller as 10 |
---|
461 | 461 | | requested at the end of the provision of services, unless retention of the personal data is required 11 |
---|
462 | 462 | | by law; 12 |
---|
463 | 463 | | (3) Upon the reasonable request of the controller, make available to the controller all 13 |
---|
464 | 464 | | information in its possession necessary to demonstrate the processor's compliance with the 14 |
---|
465 | 465 | | obligations in the provisions of this chapter; 15 |
---|
466 | 466 | | (4) After providing the controller an opportunity to object, engage any subcontractor 16 |
---|
467 | 467 | | pursuant to a written contract that requires the subcontractor to meet the obligations of the processor 17 |
---|
468 | 468 | | with respect to the personal data; and 18 |
---|
469 | 469 | | (5) Allow, and cooperate with, reasonable assessments by the controller or the controller's 19 |
---|
470 | 470 | | designated assessor, or the processor may arrange for a qualified and independent assessor to 20 |
---|
471 | 471 | | conduct an assessment of the processor's policies and technical and organizational measures in 21 |
---|
472 | 472 | | support of the obligations under the provisions of this chapter, using an appropriate and accepted 22 |
---|
473 | 473 | | control standard or framework and assessment procedure for such assessments. The processor shall 23 |
---|
474 | 474 | | provide a report of such assessment to the controller upon request. 24 |
---|
475 | 475 | | (c) Nothing in this section shall be construed to relieve a controller or processor from the 25 |
---|
476 | 476 | | liabilities imposed on the controller or processor by virtue of such controller's or processor's role 26 |
---|
477 | 477 | | in the processing relationship, as described in the provisions of this chapter. 27 |
---|
478 | 478 | | (d) Determining whether a person is acting as a controller or processor with respect to a 28 |
---|
479 | 479 | | specific processing of data is a fact-based determination that depends upon the context in which 29 |
---|
480 | 480 | | personal data is to be processed. A person who is not limited in such person's processing of personal 30 |
---|
481 | 481 | | data pursuant to a controller's instructions, or who fails to adhere to such instructions, is a controller 31 |
---|
482 | 482 | | and not a processor with respect to a specific processing of data. A processor that continues to 32 |
---|
483 | 483 | | adhere to a controller's instructions with respect to a specific processing of personal data remains a 33 |
---|
484 | 484 | | processor. If a processor begins, alone or jointly with others, determining the purposes and means 34 |
---|
485 | 485 | | |
---|
486 | 486 | | |
---|
487 | 487 | | LC000015 - Page 14 of 21 |
---|
488 | 488 | | of the processing of personal data, the processor is a controller with respect to such processing and 1 |
---|
489 | 489 | | may be subject to an enforcement action under this chapter. 2 |
---|
490 | 490 | | 6-59-9. Further actions required of controller -- Data protection assessment. 3 |
---|
491 | 491 | | (a) A controller shall conduct and document a data protection assessment for each of the 4 |
---|
492 | 492 | | controller's processing activities that presents a heightened risk of harm to a consumer. For the 5 |
---|
493 | 493 | | purposes of this section, processing that presents a heightened risk of harm to a consumer includes: 6 |
---|
494 | 494 | | (1) The processing of personal data for the purposes of targeted advertising; 7 |
---|
495 | 495 | | (2) The sale of personal data; 8 |
---|
496 | 496 | | (3) The processing of personal data for the purposes of profiling, where such profiling 9 |
---|
497 | 497 | | presents a reasonably foreseeable risk of: 10 |
---|
498 | 498 | | (i) Unfair or deceptive treatment of, or unlawful disparate impact on, consumers; 11 |
---|
499 | 499 | | (ii) Financial, physical or reputational injury to consumers; 12 |
---|
500 | 500 | | (iii) A physical or other intrusion upon the solitude or seclusion, or the private affairs or 13 |
---|
501 | 501 | | concerns, of consumers, where such intrusion would be offensive to a reasonable person; or 14 |
---|
502 | 502 | | (iv) Other substantial injury to consumers; and 15 |
---|
503 | 503 | | (4) The processing of sensitive data. 16 |
---|
504 | 504 | | (b) Data protection assessments conducted pursuant to subsection (a) of this section shall 17 |
---|
505 | 505 | | identify and weigh the benefits that may flow, directly and indirectly, from the processing to the 18 |
---|
506 | 506 | | controller, the consumer, other stakeholders and the public against the potential risks to the rights 19 |
---|
507 | 507 | | of the consumer associated with such processing, as mitigated by safeguards that can be employed 20 |
---|
508 | 508 | | by the controller to reduce such risks. The controller shall factor into any such data protection 21 |
---|
509 | 509 | | assessment the use of de-identified data and the reasonable expectations of consumers, as well as 22 |
---|
510 | 510 | | the context of the processing and the relationship between the controller and the consumer whose 23 |
---|
511 | 511 | | personal data will be processed. 24 |
---|
512 | 512 | | (c) The attorney general may require that a controller disclose any data protection 25 |
---|
513 | 513 | | assessment that is relevant to an investigation conducted by the attorney general, and the controller 26 |
---|
514 | 514 | | shall make the data protection assessment available to the attorney general. The attorney general 27 |
---|
515 | 515 | | may evaluate the data protection assessment for compliance with the responsibilities set forth in 28 |
---|
516 | 516 | | the provisions of this chapter. Data protection assessments shall be confidential and shall be exempt 29 |
---|
517 | 517 | | from disclosure under the Freedom of Information Act and shall not be deemed to be a public record 30 |
---|
518 | 518 | | pursuant to chapter 2 of title 38. To the extent any information contained in a data protection 31 |
---|
519 | 519 | | assessment disclosed to the attorney general includes information subject to attorney-client 32 |
---|
520 | 520 | | privilege or work product protection, such disclosure shall not constitute a waiver of such privilege 33 |
---|
521 | 521 | | or protection. 34 |
---|
522 | 522 | | |
---|
523 | 523 | | |
---|
524 | 524 | | LC000015 - Page 15 of 21 |
---|
525 | 525 | | (d) A single data protection assessment may address a comparable set of processing 1 |
---|
526 | 526 | | operations that include similar activities. 2 |
---|
527 | 527 | | (e) If a controller conducts a data protection assessment for the purpose of complying with 3 |
---|
528 | 528 | | another applicable law or regulation, the data protection assessment shall be deemed to satisfy the 4 |
---|
529 | 529 | | requirements established in this section if such data protection assessment is reasonably similar in 5 |
---|
530 | 530 | | scope and effect to the data protection assessment that would otherwise be conducted pursuant to 6 |
---|
531 | 531 | | this section. 7 |
---|
532 | 532 | | (f) Data protection assessment requirements shall apply to processing activities created or 8 |
---|
533 | 533 | | generated after July 1, 2023, and are not retroactive. 9 |
---|
534 | 534 | | 6-59-10. Handling requirements for de-identified data. 10 |
---|
535 | 535 | | (a) Any controller in possession of de-identified data shall: 11 |
---|
536 | 536 | | (1) Take reasonable measures to ensure that the data cannot be associated with an 12 |
---|
537 | 537 | | individual; 13 |
---|
538 | 538 | | (2) Publicly commit to maintaining and using de-identified data without attempting to re-14 |
---|
539 | 539 | | identify the data; and 15 |
---|
540 | 540 | | (3) Contractually obligate any recipients of the de-identified data to comply with all 16 |
---|
541 | 541 | | provisions of the provisions of this chapter. 17 |
---|
542 | 542 | | (b) Nothing in the provisions of this chapter shall be construed to: 18 |
---|
543 | 543 | | (1) Require a controller or processor to re-identify de-identified data or pseudonymous 19 |
---|
544 | 544 | | data; or 20 |
---|
545 | 545 | | (2) Maintain data in identifiable form, or collect, obtain, retain or access any data or 21 |
---|
546 | 546 | | technology, in order to be capable of associating an authenticated consumer request with personal 22 |
---|
547 | 547 | | data. 23 |
---|
548 | 548 | | (c) Nothing in the provisions of this chapter shall be construed to require a controller or 24 |
---|
549 | 549 | | processor to comply with an authenticated consumer rights request if the controller: 25 |
---|
550 | 550 | | (1) Is not reasonably capable of associating the request with the personal data or it would 26 |
---|
551 | 551 | | be unreasonably burdensome for the controller to associate the request with the personal data; 27 |
---|
552 | 552 | | (2) Does not use the personal data to recognize or respond to the specific consumer who is 28 |
---|
553 | 553 | | the subject of the personal data, or associate the personal data with other personal data about the 29 |
---|
554 | 554 | | same specific consumer; and 30 |
---|
555 | 555 | | (3) Does not sell the personal data to any third-party or otherwise voluntarily disclose the 31 |
---|
556 | 556 | | personal data to any third-party other than a processor, except as otherwise permitted in this section. 32 |
---|
557 | 557 | | (d) The rights afforded under this chapter shall not apply to pseudonymous data in cases 33 |
---|
558 | 558 | | where the controller is able to demonstrate that any information necessary to identify the consumer 34 |
---|
559 | 559 | | |
---|
560 | 560 | | |
---|
561 | 561 | | LC000015 - Page 16 of 21 |
---|
562 | 562 | | is kept separately and is subject to effective technical and organizational controls that prevent the 1 |
---|
563 | 563 | | controller from accessing such information. 2 |
---|
564 | 564 | | (e) A controller that discloses pseudonymous data or de-identified data shall exercise 3 |
---|
565 | 565 | | reasonable oversight to monitor compliance with any contractual commitments to which the 4 |
---|
566 | 566 | | pseudonymous data or de-identified data is subject and shall take appropriate steps to address any 5 |
---|
567 | 567 | | breaches of those contractual commitments. 6 |
---|
568 | 568 | | 6-59-11. Actions that are not restricted. 7 |
---|
569 | 569 | | (a) Nothing in the provisions of this chapter shall be construed to restrict a controller's or 8 |
---|
570 | 570 | | processor's ability to: 9 |
---|
571 | 571 | | (1) Comply with federal, state or municipal ordinances or regulations; 10 |
---|
572 | 572 | | (2) Comply with a civil, criminal or regulatory inquiry, investigation, subpoena or 11 |
---|
573 | 573 | | summons by federal, state, municipal or other governmental authorities; 12 |
---|
574 | 574 | | (3) Cooperate with law enforcement agencies concerning conduct or activity that the 13 |
---|
575 | 575 | | controller or processor reasonably and in good faith believes may violate federal, state or municipal 14 |
---|
576 | 576 | | ordinances or regulations; 15 |
---|
577 | 577 | | (4) Investigate, establish, exercise, prepare for or defend legal claims; 16 |
---|
578 | 578 | | (5) Provide a product or service specifically requested by a consumer; 17 |
---|
579 | 579 | | (6) Perform under a contract to which a consumer is a party, including fulfilling the terms 18 |
---|
580 | 580 | | of a written warranty; 19 |
---|
581 | 581 | | (7) Take steps at the request of a consumer prior to entering into a contract; 20 |
---|
582 | 582 | | (8) Take immediate steps to protect an interest that is essential for the life or physical safety 21 |
---|
583 | 583 | | of the consumer or another individual, and where the processing cannot be manifestly based on 22 |
---|
584 | 584 | | another legal basis; 23 |
---|
585 | 585 | | (9) Prevent, detect, protect against or respond to security incidents, identity theft, fraud, 24 |
---|
586 | 586 | | harassment, malicious or deceptive activities or any illegal activity, preserve the integrity or 25 |
---|
587 | 587 | | security of systems or investigate, report or prosecute those responsible for any such action; 26 |
---|
588 | 588 | | (10) Engage in public or peer-reviewed scientific or statistical research in the public interest 27 |
---|
589 | 589 | | that adheres to all other applicable ethics and privacy laws and is approved, monitored and governed 28 |
---|
590 | 590 | | by an institutional review board that determines, or similar independent oversight entities that 29 |
---|
591 | 591 | | determine whether the deletion of the information is likely to provide substantial benefits that do 30 |
---|
592 | 592 | | not exclusively accrue to the controller, the expected benefits of the research outweigh the privacy 31 |
---|
593 | 593 | | risks, and whether the controller has implemented reasonable safeguards to mitigate privacy risks 32 |
---|
594 | 594 | | associated with research, including any risks associated with re-identification; 33 |
---|
595 | 595 | | (11) Assist another controller, processor or third party with any of the obligations under 34 |
---|
596 | 596 | | |
---|
597 | 597 | | |
---|
598 | 598 | | LC000015 - Page 17 of 21 |
---|
599 | 599 | | the provisions of this chapter; or 1 |
---|
600 | 600 | | (12) Process personal data for reasons of public interest in the area of public health, 2 |
---|
601 | 601 | | community health or population health, but solely to the extent that such processing is subject to 3 |
---|
602 | 602 | | suitable and specific measures to safeguard the rights of the consumer whose personal data is being 4 |
---|
603 | 603 | | processed, and under the responsibility of a professional subject to confidentiality obligations under 5 |
---|
604 | 604 | | federal, state or local law. 6 |
---|
605 | 605 | | (b) The obligations imposed on controllers or processors under the provisions of this 7 |
---|
606 | 606 | | chapter shall not restrict a controller's or processor's ability to collect, use or retain data for internal 8 |
---|
607 | 607 | | use to: 9 |
---|
608 | 608 | | (1) Conduct internal research to develop, improve or repair products, services or 10 |
---|
609 | 609 | | technology; 11 |
---|
610 | 610 | | (2) Effectuate a product recall; 12 |
---|
611 | 611 | | (3) Identify and repair technical errors that impair existing or intended functionality; or 13 |
---|
612 | 612 | | (4) Perform internal operations that are reasonably aligned with the expectations of the 14 |
---|
613 | 613 | | consumer or reasonably anticipated based on the consumer's existing relationship with the 15 |
---|
614 | 614 | | controller, or are otherwise compatible with processing data in furtherance of the provision of a 16 |
---|
615 | 615 | | product or service specifically requested by a consumer or the performance of a contract to which 17 |
---|
616 | 616 | | the consumer is a party. 18 |
---|
617 | 617 | | (c) The obligations imposed on controllers or processors under the provisions of this 19 |
---|
618 | 618 | | chapter shall not apply where compliance by the controller or processor with said sections would 20 |
---|
619 | 619 | | violate an evidentiary privilege under the laws of this state. Nothing in the provisions of this chapter 21 |
---|
620 | 620 | | shall be construed to prevent a controller or processor from providing personal data concerning a 22 |
---|
621 | 621 | | consumer to a person covered by an evidentiary privilege under the laws of the state as part of a 23 |
---|
622 | 622 | | privileged communication. 24 |
---|
623 | 623 | | (d) A controller or processor that discloses personal data to a processor or third-party 25 |
---|
624 | 624 | | controller in accordance with the provisions of this chapter shall not be deemed to have violated 26 |
---|
625 | 625 | | said sections if the processor or third-party controller that receives and processes such personal data 27 |
---|
626 | 626 | | violates said sections, provided, at the time the disclosing controller or processor disclosed such 28 |
---|
627 | 627 | | personal data, the disclosing controller or processor did not have actual knowledge that the 29 |
---|
628 | 628 | | receiving processor or third-party controller would violate said sections. A third-party controller or 30 |
---|
629 | 629 | | processor receiving personal data from a controller or processor in compliance with the provisions 31 |
---|
630 | 630 | | of this chapter is likewise not in violation of said sections for the transgressions of the controller or 32 |
---|
631 | 631 | | processor from which such third-party controller or processor receives such personal data. 33 |
---|
632 | 632 | | (e) Nothing in the provisions of this chapter shall be construed to impose any obligation on 34 |
---|
633 | 633 | | |
---|
634 | 634 | | |
---|
635 | 635 | | LC000015 - Page 18 of 21 |
---|
636 | 636 | | a controller or processor that adversely affects the rights or freedoms of any person, including, but 1 |
---|
637 | 637 | | not limited to, the rights of any person to freedom of speech or freedom of the press guaranteed in 2 |
---|
638 | 638 | | the First Amendment to the United States Constitution, or apply to any person's processing of 3 |
---|
639 | 639 | | personal data in the course of such person's purely personal or household activities. 4 |
---|
640 | 640 | | (f) Personal data processed by a controller pursuant to this section may be processed to the 5 |
---|
641 | 641 | | extent that such processing is: 6 |
---|
642 | 642 | | (1) Reasonably necessary and proportionate to the purposes listed in this section; and 7 |
---|
643 | 643 | | (2) Adequate, relevant and limited to what is necessary in relation to the specific purposes 8 |
---|
644 | 644 | | listed in this section. Personal data collected, used or retained pursuant to this section shall, where 9 |
---|
645 | 645 | | applicable, take into account the nature and purpose or purposes of such collection, use or retention. 10 |
---|
646 | 646 | | Such data shall be subject to reasonable administrative, technical and physical measures to protect 11 |
---|
647 | 647 | | the confidentiality, integrity and accessibility of the personal data and to reduce reasonably 12 |
---|
648 | 648 | | foreseeable risks of harm to consumers relating to such collection, use or retention of personal data. 13 |
---|
649 | 649 | | (g) If a controller processes personal data pursuant to an exemption in this section, the 14 |
---|
650 | 650 | | controller bears the burden of demonstrating that such processing qualifies for the exemption and 15 |
---|
651 | 651 | | complies with the requirements in subsection (f) of this section. 16 |
---|
652 | 652 | | (h) Processing personal data for the purposes expressly identified in this section shall not 17 |
---|
653 | 653 | | solely make a legal entity a controller with respect to such processing. 18 |
---|
654 | 654 | | 6-59-12. Enforcement by attorney general. 19 |
---|
655 | 655 | | (a) The attorney general shall have exclusive authority to enforce the provisions of this 20 |
---|
656 | 656 | | chapter. 21 |
---|
657 | 657 | | (b) During the period beginning on July 1, 2023, and ending on December 31, 2024, the 22 |
---|
658 | 658 | | attorney general shall, prior to initiating any action for a violation of any provisions of this chapter, 23 |
---|
659 | 659 | | issue a notice of violation to the controller if the attorney general determines that a cure is possible. 24 |
---|
660 | 660 | | If the controller fails to cure such violation within sixty (60) days of receipt of the notice of 25 |
---|
661 | 661 | | violation, the attorney general may bring an action pursuant to this section. 26 |
---|
662 | 662 | | (c) Not later than February 1, 2025, the attorney general shall submit a report, to the house 27 |
---|
663 | 663 | | and senate judiciary committees containing: 28 |
---|
664 | 664 | | (1) The number of notices of violation the attorney general has issued; 29 |
---|
665 | 665 | | (2) The nature of each violation; 30 |
---|
666 | 666 | | (3) The number of violations that were cured during the sixty (60) day cure period; and 31 |
---|
667 | 667 | | (4) Any other matter the attorney general deems relevant for the purposes of such report. 32 |
---|
668 | 668 | | (d) Beginning on January 1, 2025, the attorney general may, in determining whether to 33 |
---|
669 | 669 | | grant a controller or processor the opportunity to cure an alleged violation as permitted under this 34 |
---|
670 | 670 | | |
---|
671 | 671 | | |
---|
672 | 672 | | LC000015 - Page 19 of 21 |
---|
673 | 673 | | section, consider: 1 |
---|
674 | 674 | | (1) The number of violations; 2 |
---|
675 | 675 | | (2) The size and complexity of the controller or processor; 3 |
---|
676 | 676 | | (3) The nature and extent of the controller's or processor's processing activities; 4 |
---|
677 | 677 | | (4) The substantial likelihood of injury to the public; 5 |
---|
678 | 678 | | (5) The safety of persons or property; and 6 |
---|
679 | 679 | | (6) Whether such alleged violation was likely caused by human or technical error. 7 |
---|
680 | 680 | | (e) Nothing in this chapter shall be construed as providing the basis for, or be subject to, a 8 |
---|
681 | 681 | | private right of action for violations of said sections or any other law. 9 |
---|
682 | 682 | | (f) A violation of the requirements of the provisions of this chapter shall constitute an unfair 10 |
---|
683 | 683 | | sales and deceptive trade practice for purposes of chapters 13 and 13.1 of title 6, and shall be 11 |
---|
684 | 684 | | enforced solely by the attorney general. 12 |
---|
685 | 685 | | 6-59-13. Joint study commission. 13 |
---|
686 | 686 | | (a) Not later than September 1, 2023, the general assembly shall convene a joint study 14 |
---|
687 | 687 | | commission to: 15 |
---|
688 | 688 | | (1) Study information sharing among health care providers and social care providers and 16 |
---|
689 | 689 | | make recommendations to eliminate health disparities and inequities across sectors; 17 |
---|
690 | 690 | | (2) Study algorithmic decision-making and make recommendations concerning the proper 18 |
---|
691 | 691 | | use of data to reduce bias in such decision-making; 19 |
---|
692 | 692 | | (3) Make recommendations as to legislation that would require an operator, as defined in 20 |
---|
693 | 693 | | the Children's Online Privacy Protection Act, 15 U.S.C. §§ 6501 et seq., as amended from time to 21 |
---|
694 | 694 | | time, to, upon a parent's request, delete the account of a child and cease to collect, use or maintain, 22 |
---|
695 | 695 | | in retrievable form, the child's personal data on the operator's Internet website or online service 23 |
---|
696 | 696 | | directed to children, and provide parents with an accessible, reasonable and verifiable means to 24 |
---|
697 | 697 | | make such a request; 25 |
---|
698 | 698 | | (4) Any means available to verify the age of a child who creates a social media account; 26 |
---|
699 | 699 | | (5) Issues concerning data colocation, including, but not limited to, the impact that the 27 |
---|
700 | 700 | | provisions of this chapter have on third parties that provide data storage and colocation services; 28 |
---|
701 | 701 | | (6) Recommend any legislation that would expand the provisions of this chapter to include 29 |
---|
702 | 702 | | additional persons or groups; and 30 |
---|
703 | 703 | | (7) Other topics concerning data privacy. 31 |
---|
704 | 704 | | (b) The chairpersons of the house and senate judiciary committees shall serve as the 32 |
---|
705 | 705 | | chairpersons of the study commission, and shall jointly appoint the members of the joint study 33 |
---|
706 | 706 | | commission. Such members shall include, but need not be limited to: 34 |
---|
707 | 707 | | |
---|
708 | 708 | | |
---|
709 | 709 | | LC000015 - Page 20 of 21 |
---|
710 | 710 | | (1) Representatives from business, academia, consumer advocacy groups, small and large 1 |
---|
711 | 711 | | companies and the office of the attorney general; 2 |
---|
712 | 712 | | (2) Members of the senate and the house of representatives; and 3 |
---|
713 | 713 | | (3) Attorneys and other professionals with experience and expertise in privacy law. 4 |
---|
714 | 714 | | (c) The speaker of the house and the president of the senate shall provide staffing and space 5 |
---|
715 | 715 | | to the study commission as determined to be needed. 6 |
---|
716 | 716 | | (d) Not later than January 1, 2024, the study commission shall submit a report on its 7 |
---|
717 | 717 | | findings and recommendations to the house and senate judiciary committees. The study 8 |
---|
718 | 718 | | commission shall terminate on the date that it submits such report or January 1, 2024 whichever is 9 |
---|
719 | 719 | | later. 10 |
---|
720 | 720 | | SECTION 2. This act shall take effect on July 1, 2023. 11 |
---|
721 | 721 | | ======== |
---|
722 | 722 | | LC000015 |
---|
723 | 723 | | ======== |
---|
724 | 724 | | |
---|
725 | 725 | | |
---|
726 | 726 | | LC000015 - Page 21 of 21 |
---|
727 | 727 | | EXPLANATION |
---|
728 | 728 | | BY THE LEGISLATIVE COUNCIL |
---|
729 | 729 | | OF |
---|
730 | 730 | | A N A C T |
---|
731 | 731 | | RELATING TO COMMERCI AL LAW -- RHODE ISLAND PERSONA L DATA AND |
---|
732 | 732 | | ONLINE PRIVACY PROTECTION ACT |
---|
733 | 733 | | *** |
---|
734 | 734 | | This act would establish the Rhode Island personal data and online privacy protection act. 1 |
---|
735 | 735 | | The act would provide for the protection of personal data of individuals which is collected by 2 |
---|
736 | 736 | | certain commercial enterprises, including persons and enterprises that conduct business in the state. 3 |
---|
737 | 737 | | The attorney general would be charged with enforcement of this act. 4 |
---|
738 | 738 | | This act would take effect of July 1, 2023. 5 |
---|
739 | 739 | | ======== |
---|
740 | 740 | | LC000015 |
---|
741 | 741 | | ======== |
---|