1 | 1 | | 86R17033 TSR-D |
---|
2 | 2 | | By: Martinez Fischer H.B. No. 4518 |
---|
3 | 3 | | |
---|
4 | 4 | | |
---|
5 | 5 | | A BILL TO BE ENTITLED |
---|
6 | 6 | | AN ACT |
---|
7 | 7 | | relating to the privacy of a consumer's personal information |
---|
8 | 8 | | collected by certain businesses; imposing a civil penalty. |
---|
9 | 9 | | BE IT ENACTED BY THE LEGISLATURE OF THE STATE OF TEXAS: |
---|
10 | 10 | | SECTION 1. Title 11, Business & Commerce Code, is amended by |
---|
11 | 11 | | adding Subtitle C to read as follows: |
---|
12 | 12 | | SUBTITLE C. PRIVACY OF PERSONAL INFORMATION |
---|
13 | 13 | | CHAPTER 541. PRIVACY OF CONSUMER'S PERSONAL INFORMATION |
---|
14 | 14 | | SUBCHAPTER A. GENERAL PROVISIONS |
---|
15 | 15 | | Sec. 541.001. SHORT TITLE. This chapter may be cited as the |
---|
16 | 16 | | Texas Consumer Privacy Act. |
---|
17 | 17 | | Sec. 541.002. DEFINITIONS. In this chapter: |
---|
18 | 18 | | (1) "Aggregate consumer information" means |
---|
19 | 19 | | information that relates to a group or category of consumers from |
---|
20 | 20 | | which individual consumer identities have been removed and that is |
---|
21 | 21 | | not linked or reasonably linkable to a particular consumer or |
---|
22 | 22 | | household, including through a device. The term does not include |
---|
23 | 23 | | one or more individual consumer records that have been |
---|
24 | 24 | | deidentified. |
---|
25 | 25 | | (2) "Biometric information" means an individual's |
---|
26 | 26 | | physiological, biological, or behavioral characteristics that can |
---|
27 | 27 | | be used, alone or in combination with other characteristics or |
---|
28 | 28 | | other identifying data, to establish the individual's identity. |
---|
29 | 29 | | The term includes: |
---|
30 | 30 | | (A) deoxyribonucleic acid (DNA); |
---|
31 | 31 | | (B) an image of an iris, retina, fingerprint, |
---|
32 | 32 | | face, hand, palm, or vein pattern or a voice recording from which an |
---|
33 | 33 | | identifier template can be extracted such as a faceprint, minutiae |
---|
34 | 34 | | template, or voiceprint; |
---|
35 | 35 | | (C) keystroke patterns or rhythms; |
---|
36 | 36 | | (D) gait patterns or rhythms; and |
---|
37 | 37 | | (E) sleep, health, or exercise data that contains |
---|
38 | 38 | | identifying information. |
---|
39 | 39 | | (3) "Business" means a for-profit entity, including a |
---|
40 | 40 | | sole proprietorship, partnership, limited liability company, |
---|
41 | 41 | | corporation, association, or other legal entity that is organized |
---|
42 | 42 | | or operated for the profit or financial benefit of the entity's |
---|
43 | 43 | | shareholders or other owners. |
---|
44 | 44 | | (4) "Business purpose" means the use of personal |
---|
45 | 45 | | information for: |
---|
46 | 46 | | (A) the following operational purposes of a |
---|
47 | 47 | | business or service provider, provided that the use of the |
---|
48 | 48 | | information is reasonably necessary and proportionate to achieve |
---|
49 | 49 | | the operational purpose for which the information was collected or |
---|
50 | 50 | | processed or another operational purpose that is compatible with |
---|
51 | 51 | | the context in which the information was collected: |
---|
52 | 52 | | (i) auditing related to a current |
---|
53 | 53 | | interaction with a consumer and any concurrent transactions, |
---|
54 | 54 | | including counting ad impressions to unique visitors, verifying the |
---|
55 | 55 | | positioning and quality of ad impressions, and auditing compliance |
---|
56 | 56 | | with a specification or other standards for ad impressions; |
---|
57 | 57 | | (ii) detecting a security incident, |
---|
58 | 58 | | protecting against malicious, deceptive, fraudulent, or illegal |
---|
59 | 59 | | activity, and prosecuting those responsible for any illegal |
---|
60 | 60 | | activity described by this subparagraph; |
---|
61 | 61 | | (iii) identifying and repairing or removing |
---|
62 | 62 | | errors that impair the intended functionality of computer hardware |
---|
63 | 63 | | or software; |
---|
64 | 64 | | (iv) using personal information in the |
---|
65 | 65 | | short term or for a transient use, provided that the information is |
---|
66 | 66 | | not: |
---|
67 | 67 | | (a) disclosed to a third party; and |
---|
68 | 68 | | (b) used to build a profile about a |
---|
69 | 69 | | consumer or alter an individual consumer's experience outside of a |
---|
70 | 70 | | current interaction with the consumer, including the contextual |
---|
71 | 71 | | customization of an advertisement displayed as part of the same |
---|
72 | 72 | | interaction; |
---|
73 | 73 | | (v) performing a service on behalf of the |
---|
74 | 74 | | business or service provider, including: |
---|
75 | 75 | | (a) maintaining or servicing an |
---|
76 | 76 | | account, providing customer service, processing or fulfilling an |
---|
77 | 77 | | order or transaction, verifying customer information, processing a |
---|
78 | 78 | | payment, providing financing, providing advertising or marketing |
---|
79 | 79 | | services, or providing analytic services; or |
---|
80 | 80 | | (b) performing a service similar to a |
---|
81 | 81 | | service described by Sub-subparagraph (a) on behalf of the business |
---|
82 | 82 | | or service provider; |
---|
83 | 83 | | (vi) undertaking internal research for |
---|
84 | 84 | | technological development and demonstration; or |
---|
85 | 85 | | (vii) undertaking an activity to: |
---|
86 | 86 | | (a) verify or maintain the quality or |
---|
87 | 87 | | safety of a service or device that is owned by, manufactured by, |
---|
88 | 88 | | manufactured for, or controlled by the business; or |
---|
89 | 89 | | (b) improve, upgrade, or enhance a |
---|
90 | 90 | | service or device described by Sub-subparagraph (a); or |
---|
91 | 91 | | (B) another operational purpose for which notice |
---|
92 | 92 | | is given under this chapter. |
---|
93 | 93 | | (5) "Collect" means to buy, rent, gather, obtain, |
---|
94 | 94 | | receive, or access the personal information of a consumer by any |
---|
95 | 95 | | means, including by actively or passively receiving the information |
---|
96 | 96 | | from the consumer or by observing the consumer's behavior. |
---|
97 | 97 | | (6) "Commercial purpose" means a purpose that is |
---|
98 | 98 | | intended to result in a profit or other tangible benefit or the |
---|
99 | 99 | | advancement of a person's commercial or economic interests, such as |
---|
100 | 100 | | by inducing another person to buy, rent, lease, subscribe to, |
---|
101 | 101 | | provide, or exchange products, goods, property, information, or |
---|
102 | 102 | | services or by enabling or effecting, directly or indirectly, a |
---|
103 | 103 | | commercial transaction. The term does not include the purpose of |
---|
104 | 104 | | engaging in speech recognized by state or federal courts as |
---|
105 | 105 | | noncommercial speech, including political speech and journalism. |
---|
106 | 106 | | (7) "Consumer" means an individual who is a resident |
---|
107 | 107 | | of this state. |
---|
108 | 108 | | (8) "Deidentified information" means information that |
---|
109 | 109 | | cannot reasonably identify, relate to, describe, be associated |
---|
110 | 110 | | with, or be linked to, directly or indirectly, a particular |
---|
111 | 111 | | consumer. |
---|
112 | 112 | | (9) "Device" means any physical object capable of |
---|
113 | 113 | | connecting to the Internet, directly or indirectly, or to another |
---|
114 | 114 | | device. |
---|
115 | 115 | | (10) "Identifier" means data elements or other |
---|
116 | 116 | | information that alone or in conjunction with other information can |
---|
117 | 117 | | be used to identify a particular consumer, household, or device |
---|
118 | 118 | | that is linked to a particular consumer or household. |
---|
119 | 119 | | (11) "Person" means an individual, sole |
---|
120 | 120 | | proprietorship, firm, partnership, joint venture, syndicate, |
---|
121 | 121 | | business trust, company, corporation, limited liability company, |
---|
122 | 122 | | association, committee, and any other organization or group of |
---|
123 | 123 | | persons acting in concert. |
---|
124 | 124 | | (12) "Personal information" means information that |
---|
125 | 125 | | identifies, relates to, describes, can be associated with, or can |
---|
126 | 126 | | reasonably be linked to, directly or indirectly, a particular |
---|
127 | 127 | | consumer or household. The term does not include publicly |
---|
128 | 128 | | available information. The term includes the following categories |
---|
129 | 129 | | of information if the information identifies, relates to, |
---|
130 | 130 | | describes, can be associated with, or can reasonably be linked to, |
---|
131 | 131 | | directly or indirectly, a particular consumer or household: |
---|
132 | 132 | | (A) an identifier, including a real name, alias, |
---|
133 | 133 | | mailing address, account name, date of birth, driver's license |
---|
134 | 134 | | number, unique identifier, social security number, passport |
---|
135 | 135 | | number, signature, telephone number, or other government-issued |
---|
136 | 136 | | identification number, or other similar identifier; |
---|
137 | 137 | | (B) an online identifier, including an |
---|
138 | 138 | | electronic mail address or Internet Protocol address, or other |
---|
139 | 139 | | similar identifier; |
---|
140 | 140 | | (C) a physical characteristic or description, |
---|
141 | 141 | | including a characteristic of a protected classification under |
---|
142 | 142 | | state or federal law; |
---|
143 | 143 | | (D) commercial information, including: |
---|
144 | 144 | | (i) a record of personal property; |
---|
145 | 145 | | (ii) a good or service purchased, obtained, |
---|
146 | 146 | | or considered; |
---|
147 | 147 | | (iii) an insurance policy number; or |
---|
148 | 148 | | (iv) other purchasing or consuming |
---|
149 | 149 | | histories or tendencies; |
---|
150 | 150 | | (E) biometric information; |
---|
151 | 151 | | (F) Internet or other electronic network |
---|
152 | 152 | | activity information, including: |
---|
153 | 153 | | (i) browsing or search history; and |
---|
154 | 154 | | (ii) other information regarding a |
---|
155 | 155 | | consumer's interaction with an Internet website, application, or |
---|
156 | 156 | | advertisement; |
---|
157 | 157 | | (G) geolocation data; |
---|
158 | 158 | | (H) audio, electronic, visual, thermal, |
---|
159 | 159 | | olfactory, or other similar information; |
---|
160 | 160 | | (I) professional or employment-related |
---|
161 | 161 | | information; |
---|
162 | 162 | | (J) education information that is not publicly |
---|
163 | 163 | | available personally identifiable information under the Family |
---|
164 | 164 | | Educational Rights and Privacy Act of 1974 (20 U.S.C. Section |
---|
165 | 165 | | 1232g) (34 C.F.R. Part 99); |
---|
166 | 166 | | (K) financial information, including a financial |
---|
167 | 167 | | institution account number, credit or debit card number, or |
---|
168 | 168 | | password or access code associated with a credit or debit card or |
---|
169 | 169 | | bank account; |
---|
170 | 170 | | (L) medical information; |
---|
171 | 171 | | (M) health insurance information; or |
---|
172 | 172 | | (N) inferences drawn from any of the information |
---|
173 | 173 | | listed under this subdivision to create a profile about a consumer |
---|
174 | 174 | | that reflects the consumer's preferences, characteristics, |
---|
175 | 175 | | psychological trends, predispositions, behavior, attitudes, |
---|
176 | 176 | | intelligence, abilities, or aptitudes. |
---|
177 | 177 | | (13) "Processing information" means performing any |
---|
178 | 178 | | operation or set of operations on personal data or on sets of |
---|
179 | 179 | | personal data, whether or not by automated means. |
---|
180 | 180 | | (14) "Publicly available information" means |
---|
181 | 181 | | information that is lawfully made available to the public from |
---|
182 | 182 | | federal, state, or local government records if the conditions |
---|
183 | 183 | | associated with making the information available are met. The term |
---|
184 | 184 | | does not include: |
---|
185 | 185 | | (A) biometric information of a consumer |
---|
186 | 186 | | collected by a business without the consumer's knowledge; |
---|
187 | 187 | | (B) data that is used for a purpose that is not |
---|
188 | 188 | | compatible with the purpose for which the data is: |
---|
189 | 189 | | (i) publicly maintained; or |
---|
190 | 190 | | (ii) maintained in and made available from |
---|
191 | 191 | | government records; or |
---|
192 | 192 | | (C) deidentified or aggregate consumer |
---|
193 | 193 | | information. |
---|
194 | 194 | | (15) "Service provider" means a for-profit entity as |
---|
195 | 195 | | described by Subdivision (3) that processes information on behalf |
---|
196 | 196 | | of a business and to which the business discloses, for a business |
---|
197 | 197 | | purpose, a consumer's personal information under a written |
---|
198 | 198 | | contract, provided that the contract prohibits the entity receiving |
---|
199 | 199 | | the information from retaining, using, or disclosing the |
---|
200 | 200 | | information for any purpose other than: |
---|
201 | 201 | | (A) providing the services specified in the |
---|
202 | 202 | | contract with the business; or |
---|
203 | 203 | | (B) for a purpose permitted by this chapter, |
---|
204 | 204 | | including for a commercial purpose other than providing those |
---|
205 | 205 | | specified services. |
---|
206 | 206 | | (16) "Third party" means a person who is not: |
---|
207 | 207 | | (A) a business to which this chapter applies that |
---|
208 | 208 | | collects personal information from consumers; or |
---|
209 | 209 | | (B) a person to whom the business discloses, for |
---|
210 | 210 | | a business purpose, a consumer's personal information under a |
---|
211 | 211 | | written contract, provided that the contract: |
---|
212 | 212 | | (i) prohibits the person receiving the |
---|
213 | 213 | | information from: |
---|
214 | 214 | | (a) selling the information; |
---|
215 | 215 | | (b) retaining, using, or disclosing |
---|
216 | 216 | | the information for any purpose other than providing the services |
---|
217 | 217 | | specified in the contract, including for a commercial purpose other |
---|
218 | 218 | | than providing those services; and |
---|
219 | 219 | | (c) retaining, using, or disclosing |
---|
220 | 220 | | the information outside of the direct business relationship between |
---|
221 | 221 | | the person and the business; and |
---|
222 | 222 | | (ii) includes a certification made by the |
---|
223 | 223 | | person receiving the personal information that the person |
---|
224 | 224 | | understands and will comply with the prohibitions under |
---|
225 | 225 | | Subparagraph (i). |
---|
226 | 226 | | (17) "Unique identifier" means a persistent |
---|
227 | 227 | | identifier that can be used over time and across different services |
---|
228 | 228 | | to recognize a consumer, a custodial parent or guardian, or any |
---|
229 | 229 | | minor children over which the parent or guardian has custody, or a |
---|
230 | 230 | | device that is linked to those individuals. The term includes: |
---|
231 | 231 | | (A) a device identifier; |
---|
232 | 232 | | (B) an Internet Protocol address; |
---|
233 | 233 | | (C) a cookie, beacon, pixel tag, mobile ad |
---|
234 | 234 | | identifier, or similar technology; |
---|
235 | 235 | | (D) a customer number, unique pseudonym, or user |
---|
236 | 236 | | alias; |
---|
237 | 237 | | (E) a telephone number; and |
---|
238 | 238 | | (F) another form of a persistent or probabilistic |
---|
239 | 239 | | identifier that can be used to identify a particular consumer or |
---|
240 | 240 | | device. |
---|
241 | 241 | | (18) "Verifiable consumer request" means a request: |
---|
242 | 242 | | (A) that is made by a consumer, a consumer on |
---|
243 | 243 | | behalf of the consumer's minor child, or a natural person or person |
---|
244 | 244 | | who is authorized by a consumer to act on the consumer's behalf; and |
---|
245 | 245 | | (B) that a business can reasonably verify, in |
---|
246 | 246 | | accordance with rules adopted under Section 541.009, was submitted |
---|
247 | 247 | | by: |
---|
248 | 248 | | (i) the consumer about whom the business |
---|
249 | 249 | | has collected personal information; or |
---|
250 | 250 | | (ii) the consumer on behalf of the |
---|
251 | 251 | | consumer's minor child about whom the business has collected |
---|
252 | 252 | | personal information. |
---|
253 | 253 | | Sec. 541.003. APPLICABILITY OF CHAPTER. (a) This chapter |
---|
254 | 254 | | applies only to: |
---|
255 | 255 | | (1) a business that: |
---|
256 | 256 | | (A) does business in this state; |
---|
257 | 257 | | (B) collects consumers' personal information or |
---|
258 | 258 | | has that information collected on the business's behalf; |
---|
259 | 259 | | (C) alone or in conjunction with others, |
---|
260 | 260 | | determines the purpose for and means of processing consumers' |
---|
261 | 261 | | personal information; and |
---|
262 | 262 | | (D) satisfies one or more of the following |
---|
263 | 263 | | thresholds: |
---|
264 | 264 | | (i) has annual gross revenue in an amount |
---|
265 | 265 | | that exceeds $25 million, as adjusted by the attorney general in |
---|
266 | 266 | | accordance with the rules adopted under Section 541.009; |
---|
267 | 267 | | (ii) alone or in combination with others, |
---|
268 | 268 | | annually buys, sells, or receives or shares for commercial purposes |
---|
269 | 269 | | the personal information of 50,000 or more consumers, households, |
---|
270 | 270 | | or devices; or |
---|
271 | 271 | | (iii) derives 50 percent or more of the |
---|
272 | 272 | | business's annual revenue from selling consumers' personal |
---|
273 | 273 | | information; and |
---|
274 | 274 | | (2) an entity that controls or is controlled by a |
---|
275 | 275 | | business described by Subdivision (1) and that shares a service |
---|
276 | 276 | | mark, trademark, or shared name with the business. |
---|
277 | 277 | | (b) For purposes of Subsection (a)(2), "control" means the: |
---|
278 | 278 | | (1) ownership of, or power to vote, more than 50 |
---|
279 | 279 | | percent of the outstanding shares of any class of voting security of |
---|
280 | 280 | | a business; |
---|
281 | 281 | | (2) control in any manner over the election of a |
---|
282 | 282 | | majority of the directors or of individuals exercising similar |
---|
283 | 283 | | functions; or |
---|
284 | 284 | | (3) power to exercise a controlling influence over the |
---|
285 | 285 | | management of a company. |
---|
286 | 286 | | (c) For purposes of this chapter, a business sells a |
---|
287 | 287 | | consumer's personal information to another business or a third |
---|
288 | 288 | | party if the business sells, rents, discloses, disseminates, makes |
---|
289 | 289 | | available, transfers, or otherwise communicates, orally, in |
---|
290 | 290 | | writing, or by electronic or other means, the information to the |
---|
291 | 291 | | other business or third party for monetary or other valuable |
---|
292 | 292 | | consideration. |
---|
293 | 293 | | (d) For purposes of this chapter, a business does not sell a |
---|
294 | 294 | | consumer's personal information if: |
---|
295 | 295 | | (1) the consumer uses or directs the business to |
---|
296 | 296 | | intentionally disclose the information or uses the business to |
---|
297 | 297 | | intentionally interact with a third party, provided that the third |
---|
298 | 298 | | party does not sell the information, unless that disclosure is |
---|
299 | 299 | | consistent with this chapter; or |
---|
300 | 300 | | (2) the business: |
---|
301 | 301 | | (A) uses or shares an identifier of the consumer |
---|
302 | 302 | | to alert a third party that the consumer has opted out of the sale of |
---|
303 | 303 | | the information; |
---|
304 | 304 | | (B) uses or shares with a service provider a |
---|
305 | 305 | | consumer's personal information that is necessary to perform a |
---|
306 | 306 | | business purpose if: |
---|
307 | 307 | | (i) the business provided notice that the |
---|
308 | 308 | | information is being used or shared in the business's terms and |
---|
309 | 309 | | conditions consistent with Sections 541.054 and 541.102(a)(8); and |
---|
310 | 310 | | (ii) the service provider does not further |
---|
311 | 311 | | collect, sell, or use the information except as necessary to |
---|
312 | 312 | | perform the business purpose; or |
---|
313 | 313 | | (C) transfers to a third party a consumer's |
---|
314 | 314 | | personal information as an asset that is part of a merger, |
---|
315 | 315 | | acquisition, bankruptcy, or other transaction in which the third |
---|
316 | 316 | | party assumes control of all or part of the business, provided that |
---|
317 | 317 | | information is used or shared consistent with Sections 541.051, |
---|
318 | 318 | | 541.053, and 541.054(e). |
---|
319 | 319 | | (e) For purposes of Subsection (d)(1), an intentional |
---|
320 | 320 | | interaction occurs if the consumer does one or more deliberate acts |
---|
321 | 321 | | with the intent to interact with a third party. Placing a cursor |
---|
322 | 322 | | over, muting, pausing, or closing online content does not |
---|
323 | 323 | | constitute a consumer's intent to interact with a third party. |
---|
324 | 324 | | Sec. 541.004. EXEMPTIONS. (a) This chapter does not apply |
---|
325 | 325 | | to: |
---|
326 | 326 | | (1) publicly available information; |
---|
327 | 327 | | (2) protected health information governed by Chapter |
---|
328 | 328 | | 181, Health and Safety Code, or collected by a covered entity or a |
---|
329 | 329 | | business associate of a covered entity, as those terms are defined |
---|
330 | 330 | | by 45 C.F.R. Section 160.103, that is governed by the privacy, |
---|
331 | 331 | | security, and breach notification rules in 45 C.F.R. Parts 160 and |
---|
332 | 332 | | 164 adopted by the United States Department of Health and Human |
---|
333 | 333 | | Services under the Health Insurance Portability and Accountability |
---|
334 | 334 | | Act of 1996 (Pub. L. No. 104-191) and Title XIII of the American |
---|
335 | 335 | | Recovery and Reinvestment Act of 2009 (Pub. L. No. 111-5); |
---|
336 | 336 | | (3) a health care provider governed by Chapter 181, |
---|
337 | 337 | | Health and Safety Code, or a covered entity described by |
---|
338 | 338 | | Subdivision (2) to the extent that the provider or entity maintains |
---|
339 | 339 | | the personal information of a patient in the same manner as |
---|
340 | 340 | | protected health information described by that subdivision; |
---|
341 | 341 | | (4) information collected as part of a clinical trial |
---|
342 | 342 | | subject to the Federal Policy for the Protection of Human Subjects |
---|
343 | 343 | | in accordance with the good clinical practice guidelines issued by |
---|
344 | 344 | | the International Council for Harmonisation or the human subject |
---|
345 | 345 | | protection requirements of the United States Food and Drug |
---|
346 | 346 | | Administration; |
---|
347 | 347 | | (5) the sale of personal information to or by a |
---|
348 | 348 | | consumer reporting agency, as defined by Section 20.01, if the |
---|
349 | 349 | | information is to be: |
---|
350 | 350 | | (A) reported in or used to generate a consumer |
---|
351 | 351 | | report, as defined by Section 1681a(d) of the Fair Credit Reporting |
---|
352 | 352 | | Act (15 U.S.C. Section 1681 et seq.); and |
---|
353 | 353 | | (B) used solely for a purpose authorized under |
---|
354 | 354 | | that act; |
---|
355 | 355 | | (6) personal information collected, processed, sold, |
---|
356 | 356 | | or disclosed in accordance with: |
---|
357 | 357 | | (A) the Gramm-Leach-Bliley Act (Pub. L. No. |
---|
358 | 358 | | 106-102) and its implementing regulations; or |
---|
359 | 359 | | (B) the Driver's Privacy Protection Act of 1994 |
---|
360 | 360 | | (18 U.S.C. Section 2721 et seq.); |
---|
361 | 361 | | (7) deidentified or aggregate consumer information; |
---|
362 | 362 | | or |
---|
363 | 363 | | (8) a consumer's personal information collected or |
---|
364 | 364 | | sold by a business, if every aspect of the collection or sale |
---|
365 | 365 | | occurred wholly outside of this state. |
---|
366 | 366 | | (b) For purposes of Subsection (a)(8), the collection or |
---|
367 | 367 | | sale of a consumer's personal information occurs wholly outside of |
---|
368 | 368 | | this state if: |
---|
369 | 369 | | (1) the business collects that information while the |
---|
370 | 370 | | consumer is outside of this state; |
---|
371 | 371 | | (2) no part of the sale of the information occurs in |
---|
372 | 372 | | this state; and |
---|
373 | 373 | | (3) the business does not sell any personal |
---|
374 | 374 | | information of the consumer collected while the consumer is in this |
---|
375 | 375 | | state. |
---|
376 | 376 | | (c) For purposes of Subsection (b), the collection or sale |
---|
377 | 377 | | of a consumer's personal information does not occur wholly outside |
---|
378 | 378 | | of this state if a business stores a consumer's personal |
---|
379 | 379 | | information, including on a device, when the consumer is in this |
---|
380 | 380 | | state and subsequently collects or sells that stored information |
---|
381 | 381 | | when the consumer and the information are outside of this state. |
---|
382 | 382 | | Sec. 541.005. CERTAIN RIGHTS AND OBLIGATIONS NOT AFFECTED. |
---|
383 | 383 | | A right or obligation under this chapter does not apply to the |
---|
384 | 384 | | extent that the exercise of the right or performance of the |
---|
385 | 385 | | obligation: |
---|
386 | 386 | | (1) adversely affects a right of another consumer; or |
---|
387 | 387 | | (2) infringes on a noncommercial activity of: |
---|
388 | 388 | | (A) a publisher, editor, reporter, or other |
---|
389 | 389 | | person connected with or employed by a newspaper, magazine, or |
---|
390 | 390 | | other publication of general circulation, including a periodical |
---|
391 | 391 | | newsletter, pamphlet, or report; |
---|
392 | 392 | | (B) a radio or television station that holds a |
---|
393 | 393 | | license issued by the Federal Communications Commission; or |
---|
394 | 394 | | (C) an entity that provides an information |
---|
395 | 395 | | service, including a press association or wire service. |
---|
396 | 396 | | Sec. 541.006. COMPLIANCE WITH OTHER LAWS; LEGAL |
---|
397 | 397 | | PROCEEDINGS. This chapter does not: |
---|
398 | 398 | | (1) restrict a business's ability to: |
---|
399 | 399 | | (A) comply with: |
---|
400 | 400 | | (i) applicable federal, state, or local |
---|
401 | 401 | | laws; or |
---|
402 | 402 | | (ii) a civil, criminal, or regulatory |
---|
403 | 403 | | inquiry, investigation, subpoena, or summons by a federal, state, |
---|
404 | 404 | | or local authority; |
---|
405 | 405 | | (B) cooperate with a law enforcement agency |
---|
406 | 406 | | concerning conduct or activity that the business, a service |
---|
407 | 407 | | provider of the business, or a third party reasonably and in good |
---|
408 | 408 | | faith believes may violate other applicable federal, state, or |
---|
409 | 409 | | local laws; or |
---|
410 | 410 | | (C) pursue or defend against a legal claim; or |
---|
411 | 411 | | (2) require a business to violate an evidentiary |
---|
412 | 412 | | privilege under federal or state law or prevent a business from |
---|
413 | 413 | | disclosing to a person covered by an evidentiary privilege the |
---|
414 | 414 | | personal information of a consumer as part of a privileged |
---|
415 | 415 | | communication. |
---|
416 | 416 | | Sec. 541.007. CONSTRUCTION; RELATION TO OTHER STATE AND |
---|
417 | 417 | | FEDERAL LAW. (a) This chapter shall be liberally construed to |
---|
418 | 418 | | effect its purposes and to harmonize, to the extent possible, with |
---|
419 | 419 | | other laws of this state relating to the privacy or protection of |
---|
420 | 420 | | personal information. |
---|
421 | 421 | | (b) To the extent of a conflict between a provision of this |
---|
422 | 422 | | chapter and a provision of federal law, including a regulation or an |
---|
423 | 423 | | interpretation of federal law, federal law controls and conflicting |
---|
424 | 424 | | requirements or other provisions of this chapter do not apply. |
---|
425 | 425 | | (c) To the extent of a conflict between a provision of this |
---|
426 | 426 | | chapter and another statute of this state with respect to the |
---|
427 | 427 | | privacy or protection of consumers' personal information, the |
---|
428 | 428 | | provision of law that affords the greatest privacy or protection to |
---|
429 | 429 | | consumers prevails. |
---|
430 | 430 | | Sec. 541.008. PREEMPTION OF LOCAL LAW. This chapter |
---|
431 | 431 | | preempts and supersedes any ordinance, order, or rule adopted by a |
---|
432 | 432 | | political subdivision of this state relating to the collection or |
---|
433 | 433 | | sale by a business of a consumer's personal information. |
---|
434 | 434 | | Sec. 541.009. RULES. (a) The attorney general shall adopt |
---|
435 | 435 | | rules necessary to implement, administer, and enforce this chapter. |
---|
436 | 436 | | (b) The rules adopted under Subsection (a) must establish: |
---|
437 | 437 | | (1) procedures for the adjustment of the monetary |
---|
438 | 438 | | threshold under Section 541.003(a)(1)(D) in January of every |
---|
439 | 439 | | odd-numbered year to reflect any increase in the consumer price |
---|
440 | 440 | | index; |
---|
441 | 441 | | (2) procedures governing the determination of, |
---|
442 | 442 | | submission of, and compliance with a verifiable consumer request |
---|
443 | 443 | | for information with the goal of minimizing administrative burdens |
---|
444 | 444 | | on consumers and businesses subject to this chapter by taking into |
---|
445 | 445 | | account available technology and security concerns, including: |
---|
446 | 446 | | (A) treating as a verifiable consumer request a |
---|
447 | 447 | | request submitted through a password-protected online account |
---|
448 | 448 | | maintained by the consumer with the business while logged into the |
---|
449 | 449 | | account; and |
---|
450 | 450 | | (B) providing a mechanism for a request submitted |
---|
451 | 451 | | by a consumer who does not maintain an account with the business; |
---|
452 | 452 | | (3) procedures to facilitate and govern the submission |
---|
453 | 453 | | of and compliance with a request to opt out of the sale of personal |
---|
454 | 454 | | information under Section 541.054; |
---|
455 | 455 | | (4) guidelines for the development of a recognizable |
---|
456 | 456 | | and uniform opt-out logo or button for use on businesses' Internet |
---|
457 | 457 | | websites in a manner that promotes consumer awareness of the |
---|
458 | 458 | | opportunity to opt out of the sale of personal information; and |
---|
459 | 459 | | (5) procedures and guidelines, including any |
---|
460 | 460 | | necessary exceptions, to ensure that the notices and information |
---|
461 | 461 | | businesses are required to provide under this chapter, including |
---|
462 | 462 | | information regarding financial incentive offerings, are: |
---|
463 | 463 | | (A) provided in a manner that is easily |
---|
464 | 464 | | understood by the average consumer; |
---|
465 | 465 | | (B) accessible by consumers with disabilities; |
---|
466 | 466 | | and |
---|
467 | 467 | | (C) available in the languages primarily used by |
---|
468 | 468 | | consumers to interact with businesses. |
---|
469 | 469 | | (c) The attorney general may adopt other rules necessary to |
---|
470 | 470 | | further the purposes of this chapter, including rules as necessary |
---|
471 | 471 | | to: |
---|
472 | 472 | | (1) update the categories of personal information |
---|
473 | 473 | | listed under Section 541.002(12) and the definition of identifier |
---|
474 | 474 | | under Section 541.002 to account for privacy concerns, |
---|
475 | 475 | | implementation obstacles, or changes in technology and data |
---|
476 | 476 | | collection methods; |
---|
477 | 477 | | (2) update the designated methods for submitting |
---|
478 | 478 | | requests to facilitate a consumer's ability to obtain information |
---|
479 | 479 | | from a business under Section 541.103; and |
---|
480 | 480 | | (3) establish any exceptions necessary to comply with |
---|
481 | 481 | | federal law or other laws of this state, including laws relating to |
---|
482 | 482 | | trade secrets and intellectual property rights. |
---|
483 | 483 | | Sec. 541.010. ATTORNEY GENERAL OPINION. A business or a |
---|
484 | 484 | | third party may seek an opinion from the attorney general for |
---|
485 | 485 | | guidance on how to comply with this chapter. |
---|
486 | 486 | | Sec. 541.011. USE OF PERSONAL INFORMATION IN RESEARCH. For |
---|
487 | 487 | | purposes of this chapter, "research" means scientific, systematic |
---|
488 | 488 | | study and observation, including basic research or applied research |
---|
489 | 489 | | that is in the public interest and that adheres to all other |
---|
490 | 490 | | applicable ethics and privacy laws or studies conducted in the |
---|
491 | 491 | | public interest in the area of public health. Research with |
---|
492 | 492 | | personal information that may have been collected from a consumer |
---|
493 | 493 | | in the course of the consumer's interactions with a business's |
---|
494 | 494 | | service or device for other purposes must be: |
---|
495 | 495 | | (1) compatible with the business purpose for which the |
---|
496 | 496 | | personal information was collected; |
---|
497 | 497 | | (2) subsequently pseudonymized and deidentified, or |
---|
498 | 498 | | deidentified and in the aggregate, such that the information cannot |
---|
499 | 499 | | reasonably identify, relate to, describe, be capable of being |
---|
500 | 500 | | associated with, or be linked, directly or indirectly, to a |
---|
501 | 501 | | particular consumer; |
---|
502 | 502 | | (3) made subject to technical safeguards that prohibit |
---|
503 | 503 | | reidentification of the consumer to whom the information may |
---|
504 | 504 | | pertain; |
---|
505 | 505 | | (4) subject to business processes that specifically |
---|
506 | 506 | | prohibit reidentification of the information; |
---|
507 | 507 | | (5) made subject to business processes to prevent |
---|
508 | 508 | | inadvertent release of deidentified information; |
---|
509 | 509 | | (6) protected from any reidentification attempts; |
---|
510 | 510 | | (7) used solely for research purposes that are |
---|
511 | 511 | | compatible with the context in which the personal information was |
---|
512 | 512 | | collected; |
---|
513 | 513 | | (8) not used for any commercial purpose; and |
---|
514 | 514 | | (9) subjected by the business conducting the research |
---|
515 | 515 | | to additional security controls that limit access to the research |
---|
516 | 516 | | data to only those individuals in a business as are necessary to |
---|
517 | 517 | | carry out the research purpose. |
---|
518 | 518 | | SUBCHAPTER B. CONSUMER'S RIGHTS |
---|
519 | 519 | | Sec. 541.051. RIGHT TO DISCLOSURE OF PERSONAL INFORMATION |
---|
520 | 520 | | COLLECTED. (a) A consumer is entitled to request that a business |
---|
521 | 521 | | that collects the consumer's personal information disclose to the |
---|
522 | 522 | | consumer the categories and specific items of personal information |
---|
523 | 523 | | the business has collected. |
---|
524 | 524 | | (b) To receive the disclosure of information under |
---|
525 | 525 | | Subsection (a), a consumer must submit to the business a verifiable |
---|
526 | 526 | | consumer request using a method designated by the business under |
---|
527 | 527 | | Section 541.103. |
---|
528 | 528 | | (c) On receipt of a verifiable consumer request under this |
---|
529 | 529 | | section, a business shall disclose to the consumer in the time and |
---|
530 | 530 | | manner provided by Section 541.105: |
---|
531 | 531 | | (1) each enumerated category and item within each |
---|
532 | 532 | | category of personal information under Section 541.002(12) that the |
---|
533 | 533 | | business collected about the consumer during the 12 months |
---|
534 | 534 | | preceding the date of the request; |
---|
535 | 535 | | (2) each category of sources from which the |
---|
536 | 536 | | information was collected; |
---|
537 | 537 | | (3) the business or commercial purpose for collecting |
---|
538 | 538 | | or selling the personal information; and |
---|
539 | 539 | | (4) each category of third parties with whom the |
---|
540 | 540 | | business shares the personal information. |
---|
541 | 541 | | (d) This section does not require a business to: |
---|
542 | 542 | | (1) retain a consumer's personal information that was |
---|
543 | 543 | | collected for a one-time transaction if the information is not sold |
---|
544 | 544 | | or retained in the ordinary course of business; or |
---|
545 | 545 | | (2) reidentify or otherwise link any data that, in the |
---|
546 | 546 | | ordinary course of business, is not maintained in a manner that |
---|
547 | 547 | | would be considered personal information. |
---|
548 | 548 | | Sec. 541.052. RIGHT TO DELETION OF PERSONAL INFORMATION |
---|
549 | 549 | | COLLECTED. (a) A consumer is entitled to request that a business |
---|
550 | 550 | | that collects the consumer's personal information delete any |
---|
551 | 551 | | personal information the business has collected from the consumer |
---|
552 | 552 | | by submitting a verifiable consumer request using a method |
---|
553 | 553 | | designated by the business under Section 541.103. |
---|
554 | 554 | | (b) Except as provided by Subsection (c), on receipt of a |
---|
555 | 555 | | verifiable consumer request under this section, a business shall |
---|
556 | 556 | | delete from the business's records any personal information |
---|
557 | 557 | | collected from the consumer and direct a service provider of the |
---|
558 | 558 | | business to delete the information from the provider's records. |
---|
559 | 559 | | (c) A business or service provider of the business is not |
---|
560 | 560 | | required to comply with a verifiable consumer request received |
---|
561 | 561 | | under this section if the business or service provider needs to |
---|
562 | 562 | | retain the consumer's personal information to: |
---|
563 | 563 | | (1) complete the transaction for which the information |
---|
564 | 564 | | was collected; |
---|
565 | 565 | | (2) provide a good or service requested by the |
---|
566 | 566 | | consumer or reasonably anticipated to be requested by the consumer |
---|
567 | 567 | | in the context of the ongoing business relationship between the |
---|
568 | 568 | | business and consumer; |
---|
569 | 569 | | (3) perform under a contract between the business and |
---|
570 | 570 | | the consumer; |
---|
571 | 571 | | (4) detect a security incident, protect against |
---|
572 | 572 | | malicious, deceptive, fraudulent, or illegal activity, or |
---|
573 | 573 | | prosecute those responsible for any illegal activity described by |
---|
574 | 574 | | this subdivision; |
---|
575 | 575 | | (5) identify and repair or remove errors from computer |
---|
576 | 576 | | hardware or software that impair its intended functionality; |
---|
577 | 577 | | (6) exercise free speech or ensure the right of |
---|
578 | 578 | | another consumer to exercise the right of free speech or another |
---|
579 | 579 | | right afforded by law; |
---|
580 | 580 | | (7) comply with Chapter 1289 (H.B. 2268), Acts of the |
---|
581 | 581 | | 83rd Legislature, Regular Session, 2013, or a legal obligation; |
---|
582 | 582 | | (8) engage in public or peer-reviewed scientific, |
---|
583 | 583 | | historical, or statistical research that is in the public interest |
---|
584 | 584 | | and that adheres to all other applicable ethics and privacy laws |
---|
585 | 585 | | provided that: |
---|
586 | 586 | | (A) the business's deletion of the information is |
---|
587 | 587 | | likely to render impossible or seriously impair the achievement of |
---|
588 | 588 | | that research; and |
---|
589 | 589 | | (B) the consumer has provided to the business |
---|
590 | 590 | | informed consent to retain the information; or |
---|
591 | 591 | | (9) use the information internally: |
---|
592 | 592 | | (A) so long as the use is reasonably aligned with |
---|
593 | 593 | | the expectations of the consumer based on the consumer's |
---|
594 | 594 | | relationship with the business; or |
---|
595 | 595 | | (B) in a manner that is lawful and compatible |
---|
596 | 596 | | with the context in which the consumer provided the information. |
---|
597 | 597 | | Sec. 541.053. RIGHT TO DISCLOSURE OF PERSONAL INFORMATION |
---|
598 | 598 | | SOLD OR DISCLOSED. (a) A consumer is entitled to request that a |
---|
599 | 599 | | business that sells, or discloses for a business purpose, the |
---|
600 | 600 | | consumer's personal information disclose to the consumer: |
---|
601 | 601 | | (1) the categories of personal information the |
---|
602 | 602 | | business collected about the consumer; |
---|
603 | 603 | | (2) the categories of personal information about the |
---|
604 | 604 | | consumer the business sold, or disclosed for a business purpose; |
---|
605 | 605 | | and |
---|
606 | 606 | | (3) the categories of third parties to whom the |
---|
607 | 607 | | personal information was sold or disclosed. |
---|
608 | 608 | | (b) To receive the disclosure of information under |
---|
609 | 609 | | Subsection (a), a consumer must submit to the business a verifiable |
---|
610 | 610 | | consumer request using a method designated by the business under |
---|
611 | 611 | | Section 541.103. |
---|
612 | 612 | | (c) On receipt of a verifiable consumer request under this |
---|
613 | 613 | | section, a business shall disclose to the consumer in the time and |
---|
614 | 614 | | manner provided by Section 541.105: |
---|
615 | 615 | | (1) each enumerated category of personal information |
---|
616 | 616 | | under Section 541.002(12) that the business collected about the |
---|
617 | 617 | | consumer during the 12 months preceding the date of the request; |
---|
618 | 618 | | (2) the categories of third parties to whom the |
---|
619 | 619 | | business sold the consumer's personal information during the 12 |
---|
620 | 620 | | months preceding the date of the request, by reference to each |
---|
621 | 621 | | enumerated category of information under Section 541.002(12) sold |
---|
622 | 622 | | to each third party; and |
---|
623 | 623 | | (3) the categories of third parties to whom the |
---|
624 | 624 | | business disclosed for a business purpose the consumer's personal |
---|
625 | 625 | | information during the 12 months preceding the date of the request, |
---|
626 | 626 | | by reference to each enumerated category of information under |
---|
627 | 627 | | Section 541.002(12) disclosed to each third party. |
---|
628 | 628 | | (d) A business shall provide the information described by |
---|
629 | 629 | | Subsections (c)(2) and (3) in two separate lists. |
---|
630 | 630 | | (e) A business that did not sell, or disclose for a business |
---|
631 | 631 | | purpose, the consumer's personal information during the 12 months |
---|
632 | 632 | | preceding the date of receiving the consumer's verifiable consumer |
---|
633 | 633 | | request under this section shall disclose that fact to the |
---|
634 | 634 | | consumer. |
---|
635 | 635 | | Sec. 541.054. RIGHT TO OPT OUT OF SALE OF PERSONAL |
---|
636 | 636 | | INFORMATION. (a) A consumer is entitled at any time to opt out of |
---|
637 | 637 | | the sale of the consumer's personal information by a business to |
---|
638 | 638 | | third parties by directing the business not to sell the |
---|
639 | 639 | | information. A consumer may authorize another person solely to opt |
---|
640 | 640 | | out of the sale of the consumer's personal information on the |
---|
641 | 641 | | consumer's behalf. Except as provided by Subsection (c), a |
---|
642 | 642 | | business shall comply with a direction not to sell that is received |
---|
643 | 643 | | under this subsection. |
---|
644 | 644 | | (b) A business that sells to a third party consumers' |
---|
645 | 645 | | personal information shall provide on the business's Internet |
---|
646 | 646 | | website's home page: |
---|
647 | 647 | | (1) notice to consumers that: |
---|
648 | 648 | | (A) the information may be sold; and |
---|
649 | 649 | | (B) consumers have the right to opt out of the |
---|
650 | 650 | | sale; and |
---|
651 | 651 | | (2) a clear and conspicuous link that: |
---|
652 | 652 | | (A) enables a consumer, or a person authorized by |
---|
653 | 653 | | the consumer, to opt out of the sale of the consumer's personal |
---|
654 | 654 | | information; and |
---|
655 | 655 | | (B) is titled "DO NOT SELL MY PERSONAL |
---|
656 | 656 | | INFORMATION." |
---|
657 | 657 | | (c) A business may not sell to a third party the personal |
---|
658 | 658 | | information of a consumer who opts out of the sale of that |
---|
659 | 659 | | information under this section before the first anniversary of the |
---|
660 | 660 | | date the consumer opted out, unless the consumer provides express |
---|
661 | 661 | | authorization for the business to sell the consumer's personal |
---|
662 | 662 | | information. After the period prescribed by this subsection |
---|
663 | 663 | | expires, a business may request that the consumer consent to the |
---|
664 | 664 | | sale of the consumer's personal information by the business. |
---|
665 | 665 | | (d) A business may use any personal information collected |
---|
666 | 666 | | from the consumer in connection with the consumer's opting out |
---|
667 | 667 | | under this section solely to comply with this section. |
---|
668 | 668 | | (e) A third party to whom a business has sold the personal |
---|
669 | 669 | | information of a consumer may not sell the information unless the |
---|
670 | 670 | | consumer receives explicit notice of the potential sale and is |
---|
671 | 671 | | provided the opportunity to exercise the right to opt out of the |
---|
672 | 672 | | sale as provided by this section. |
---|
673 | 673 | | (f) Notwithstanding Subsection (b), a business is not |
---|
674 | 674 | | required to provide the link required by that subsection on the |
---|
675 | 675 | | Internet website the business makes available to the public if the |
---|
676 | 676 | | business: |
---|
677 | 677 | | (1) provides the required link on a separate and |
---|
678 | 678 | | additional Internet website that is maintained by the business and |
---|
679 | 679 | | dedicated to consumers; and |
---|
680 | 680 | | (2) takes reasonable steps to ensure that consumers |
---|
681 | 681 | | are directed to the website described by Subdivision (1) instead of |
---|
682 | 682 | | the website the business makes available to the public. |
---|
683 | 683 | | (g) A business may not require a consumer to create an |
---|
684 | 684 | | account with the business to opt out of the sale of the consumer's |
---|
685 | 685 | | personal information. |
---|
686 | 686 | | Sec. 541.055. RIGHT TO OPT IN FOR SALE OF PERSONAL |
---|
687 | 687 | | INFORMATION OF CERTAIN MINORS. (a) The requirement for consent to |
---|
688 | 688 | | sell a consumer's personal information under this section may be |
---|
689 | 689 | | referred to as the consumer's "right to opt in." |
---|
690 | 690 | | (b) A business may not sell a consumer's personal |
---|
691 | 691 | | information if the business has actual knowledge that the consumer |
---|
692 | 692 | | is younger than 16 years of age unless: |
---|
693 | 693 | | (1) for a consumer who is at least 13 years of age but |
---|
694 | 694 | | younger than 16 years of age, the business receives express |
---|
695 | 695 | | authorization to sell the consumer's personal information from the |
---|
696 | 696 | | consumer; or |
---|
697 | 697 | | (2) for a consumer who is younger than 13 years of age, |
---|
698 | 698 | | the business receives express authorization to sell the consumer's |
---|
699 | 699 | | personal information from the consumer's parent or legal guardian. |
---|
700 | 700 | | (c) A business that wilfully disregards the age of a |
---|
701 | 701 | | consumer whose personal information the business sells to a third |
---|
702 | 702 | | party is considered to have actual knowledge of the consumer's age. |
---|
703 | 703 | | Sec. 541.056. WAIVER OR LIMITATION PROVISION VOID. (a) A |
---|
704 | 704 | | provision of a contract or other agreement that purports to waive or |
---|
705 | 705 | | limit a right, remedy, or means of enforcement under this chapter is |
---|
706 | 706 | | contrary to public policy and is void. |
---|
707 | 707 | | (b) This section does not prevent a consumer from: |
---|
708 | 708 | | (1) declining to request information from a business; |
---|
709 | 709 | | (2) declining to opt out of a business's sale of the |
---|
710 | 710 | | consumer's personal information; or |
---|
711 | 711 | | (3) authorizing a business to sell the consumer's |
---|
712 | 712 | | personal information after previously opting out. |
---|
713 | 713 | | SUBCHAPTER C. BUSINESS RIGHTS AND OBLIGATIONS |
---|
714 | 714 | | Sec. 541.101. NOTIFICATION OF COLLECTION REQUIRED. (a) A |
---|
715 | 715 | | business that collects a consumer's personal information shall, at |
---|
716 | 716 | | or before the point of collection, notify the consumer of each |
---|
717 | 717 | | category of personal information to be collected and the purposes |
---|
718 | 718 | | for which the category of information will be used. |
---|
719 | 719 | | (b) A business may not collect an additional category of |
---|
720 | 720 | | personal information or use personal information collected for an |
---|
721 | 721 | | additional purpose unless the business provides notice to the |
---|
722 | 722 | | consumer of the additional category or purpose in accordance with |
---|
723 | 723 | | Subsection (a). |
---|
724 | 724 | | (c) If a third party that assumes control of all or part of a |
---|
725 | 725 | | business as described by Section 541.003(d)(2)(C) materially |
---|
726 | 726 | | alters the practices of the business in how personal information is |
---|
727 | 727 | | used or shared, and the practices are materially inconsistent with |
---|
728 | 728 | | a notice provided to a consumer under Subsection (a) or (b), the |
---|
729 | 729 | | third party must notify the consumer of the third party's new or |
---|
730 | 730 | | changed practices before the third party uses or shares the |
---|
731 | 731 | | personal information in a conspicuous manner that allows the |
---|
732 | 732 | | consumer to easily exercise a right provided under this chapter. |
---|
733 | 733 | | (d) Subsection (c) does not authorize a business to make a |
---|
734 | 734 | | material, retroactive change or other change to a business's |
---|
735 | 735 | | privacy policy in a manner that would be a deceptive trade practice |
---|
736 | 736 | | actionable under Subchapter E, Chapter 17. |
---|
737 | 737 | | Sec. 541.102. ONLINE PRIVACY POLICY OR POLICY NOTICE. (a) |
---|
738 | 738 | | A business that collects, sells, or for a business purpose |
---|
739 | 739 | | discloses a consumer's personal information shall disclose the |
---|
740 | 740 | | following information in the business's online privacy policy or |
---|
741 | 741 | | other notice of the business's policies: |
---|
742 | 742 | | (1) a description of a consumer's rights under |
---|
743 | 743 | | Sections 541.051, 541.053, and 541.107 and designated methods for |
---|
744 | 744 | | submitting a verifiable consumer request for information under this |
---|
745 | 745 | | chapter; |
---|
746 | 746 | | (2) for a business that collects personal information |
---|
747 | 747 | | about consumers, a description of the consumer's right to request |
---|
748 | 748 | | the deletion of the consumer's personal information; |
---|
749 | 749 | | (3) separate lists containing the categories of |
---|
750 | 750 | | consumers' personal information described by Section 541.002(12) |
---|
751 | 751 | | that, during the 12 months preceding the date the business updated |
---|
752 | 752 | | the information as required by Subsection (b), the business: |
---|
753 | 753 | | (A) collected; |
---|
754 | 754 | | (B) sold, if applicable; or |
---|
755 | 755 | | (C) disclosed for a business purpose, if |
---|
756 | 756 | | applicable; |
---|
757 | 757 | | (4) the categories of sources from which the |
---|
758 | 758 | | information under Subdivision (3) is collected; |
---|
759 | 759 | | (5) the business or commercial purposes for collecting |
---|
760 | 760 | | personal information; |
---|
761 | 761 | | (6) if the business does not sell consumers' personal |
---|
762 | 762 | | information or disclose the information for a business or |
---|
763 | 763 | | commercial purpose, a statement of that fact; |
---|
764 | 764 | | (7) the categories of third parties to whom the |
---|
765 | 765 | | business sells or discloses personal information; |
---|
766 | 766 | | (8) if the business sells consumers' personal |
---|
767 | 767 | | information, the Internet link required by Section 541.054(b); and |
---|
768 | 768 | | (9) if applicable, the financial incentives offered to |
---|
769 | 769 | | consumers under Section 541.108. |
---|
770 | 770 | | (b) If a business described by Subsection (a) does not have |
---|
771 | 771 | | an online privacy policy or other notice of the business's |
---|
772 | 772 | | policies, the business shall make the information required under |
---|
773 | 773 | | Subsection (a) available to consumers on the business's Internet |
---|
774 | 774 | | website or another website the business maintains that is dedicated |
---|
775 | 775 | | to consumers in this state. |
---|
776 | 776 | | (c) A business must update the information required by |
---|
777 | 777 | | Subsection (a) at least once each year. |
---|
778 | 778 | | Sec. 541.103. METHODS TO SUBMIT VERIFIABLE CONSUMER |
---|
779 | 779 | | REQUEST. (a) A business shall designate and make available to |
---|
780 | 780 | | consumers, in a form that is reasonably accessible, at least two |
---|
781 | 781 | | methods for submitting a verifiable consumer request for |
---|
782 | 782 | | information required to be disclosed or deleted under Subchapter B. |
---|
783 | 783 | | The methods must include, at a minimum: |
---|
784 | 784 | | (1) a toll-free telephone number that a consumer may |
---|
785 | 785 | | call to submit the request; and |
---|
786 | 786 | | (2) the business's Internet website at which the |
---|
787 | 787 | | consumer may submit the request, if the business maintains an |
---|
788 | 788 | | Internet website. |
---|
789 | 789 | | (b) The methods designated under Subsection (a) may also |
---|
790 | 790 | | include: |
---|
791 | 791 | | (1) a mailing address; |
---|
792 | 792 | | (2) an electronic mail address; |
---|
793 | 793 | | (3) another Internet web page or portal; |
---|
794 | 794 | | (4) other contact information; or |
---|
795 | 795 | | (5) any consumer-friendly method approved by the |
---|
796 | 796 | | attorney general under Section 541.009. |
---|
797 | 797 | | (c) A business may not require a consumer to create an |
---|
798 | 798 | | account with the business to submit a verifiable consumer request. |
---|
799 | 799 | | Sec. 541.104. VERIFICATION OF CONSUMER REQUEST. (a) A |
---|
800 | 800 | | business that receives a consumer request under Section 541.051 or |
---|
801 | 801 | | 541.053 shall promptly take steps to reasonably verify, in |
---|
802 | 802 | | accordance with rules adopted under Section 541.009, that: |
---|
803 | 803 | | (1) the consumer who is the subject of the request is a |
---|
804 | 804 | | consumer about whom the business has collected, sold, or for a |
---|
805 | 805 | | business purpose disclosed personal information; and |
---|
806 | 806 | | (2) the request is made by: |
---|
807 | 807 | | (A) the consumer; |
---|
808 | 808 | | (B) a consumer on behalf of the consumer's minor |
---|
809 | 809 | | child; or |
---|
810 | 810 | | (C) a person authorized to act on the consumer's |
---|
811 | 811 | | behalf. |
---|
812 | 812 | | (b) A business may use any personal information collected |
---|
813 | 813 | | from the consumer in connection with the business's verification of |
---|
814 | 814 | | a request under this section solely to verify the request. |
---|
815 | 815 | | (c) A business that is unable to verify a consumer request |
---|
816 | 816 | | under this section is not required to comply with the request. |
---|
817 | 817 | | Sec. 541.105. DISCLOSURE REQUIREMENTS. (a) Not later than |
---|
818 | 818 | | the 45th day after the date a business receives a verifiable |
---|
819 | 819 | | consumer request under Section 541.051 or 541.053, the business |
---|
820 | 820 | | shall disclose free of charge to the consumer the information |
---|
821 | 821 | | required to be disclosed under those sections. |
---|
822 | 822 | | (b) A business may extend the time in which to comply with |
---|
823 | 823 | | Subsection (a) once by an additional 45 days if reasonably |
---|
824 | 824 | | necessary or by an additional 90 days after taking into account the |
---|
825 | 825 | | number and complexity of verifiable consumer requests received by |
---|
826 | 826 | | the business. A business that extends the time in which to comply |
---|
827 | 827 | | with Subsection (a) shall notify the consumer of the extension and |
---|
828 | 828 | | reason for the delay within the period prescribed by that |
---|
829 | 829 | | subsection. |
---|
830 | 830 | | (c) The disclosure required by Subsection (a) must: |
---|
831 | 831 | | (1) cover personal information collected, sold, or |
---|
832 | 832 | | disclosed for a business purpose, as applicable, during the 12 |
---|
833 | 833 | | months preceding the date the business receives the request; and |
---|
834 | 834 | | (2) be made in writing and delivered to the consumer: |
---|
835 | 835 | | (A) by mail or electronically, at the consumer's |
---|
836 | 836 | | option, if the consumer does not have an account with the business; |
---|
837 | 837 | | or |
---|
838 | 838 | | (B) through the consumer's account with the |
---|
839 | 839 | | business. |
---|
840 | 840 | | (d) An electronic disclosure under Subsection (c) must be in |
---|
841 | 841 | | a readily accessible format that allows the consumer to |
---|
842 | 842 | | electronically transmit the information to another person or |
---|
843 | 843 | | entity. |
---|
844 | 844 | | (e) A business is not required to make the disclosure |
---|
845 | 845 | | required by Subsection (a) to the same consumer more than twice in a |
---|
846 | 846 | | 12-month period. |
---|
847 | 847 | | (f) Notwithstanding Subsection (a), if a consumer's |
---|
848 | 848 | | verifiable consumer request is manifestly baseless or excessive, in |
---|
849 | 849 | | particular because of repetitiveness, a business may charge a |
---|
850 | 850 | | reasonable fee after taking into account the administrative costs |
---|
851 | 851 | | of compliance or refusal to comply with the request. The business |
---|
852 | 852 | | has the burden of demonstrating that a request is manifestly |
---|
853 | 853 | | baseless or excessive. |
---|
854 | 854 | | (g) A business that does not comply with a consumer's |
---|
855 | 855 | | verifiable consumer request under Subsection (a) shall notify the |
---|
856 | 856 | | consumer, within the time the business is required to respond to a |
---|
857 | 857 | | request under this section, of the reasons for the refusal and the |
---|
858 | 858 | | rights the consumer may have to appeal that decision. |
---|
859 | 859 | | Sec. 541.106. DEIDENTIFIED INFORMATION. (a) A business |
---|
860 | 860 | | that uses deidentified information may not reidentify or attempt to |
---|
861 | 861 | | reidentify a consumer who is the subject of deidentified |
---|
862 | 862 | | information without obtaining the consumer's consent or |
---|
863 | 863 | | authorization. |
---|
864 | 864 | | (b) A business that uses deidentified information shall |
---|
865 | 865 | | implement: |
---|
866 | 866 | | (1) technical safeguards and business processes to |
---|
867 | 867 | | prohibit reidentification of the consumer to whom the information |
---|
868 | 868 | | may pertain; and |
---|
869 | 869 | | (2) business processes to prevent inadvertent release |
---|
870 | 870 | | of deidentified information. |
---|
871 | 871 | | (c) This chapter may not be construed to require a business |
---|
872 | 872 | | to reidentify or otherwise link information that is not maintained |
---|
873 | 873 | | in a manner that would be considered personal information. |
---|
874 | 874 | | Sec. 541.107. DISCRIMINATION PROHIBITED. (a) A business may |
---|
875 | 875 | | not discriminate against a consumer because the consumer exercised |
---|
876 | 876 | | a right under this chapter, including by: |
---|
877 | 877 | | (1) denying a good or service to the consumer; |
---|
878 | 878 | | (2) charging the consumer a different price or rate |
---|
879 | 879 | | for a good or service, including denying the use of a discount or |
---|
880 | 880 | | other benefit or imposing a penalty; |
---|
881 | 881 | | (3) providing a different level or quality of a good or |
---|
882 | 882 | | service to the consumer; or |
---|
883 | 883 | | (4) suggesting that the consumer will be charged a |
---|
884 | 884 | | different price or rate for, or provided a different level or |
---|
885 | 885 | | quality of, a good or service. |
---|
886 | 886 | | (b) This section does not prohibit a business from offering |
---|
887 | 887 | | or charging a consumer a different price or rate for a good or |
---|
888 | 888 | | service, or offering or providing to the consumer a different level |
---|
889 | 889 | | or quality of a good or service, if the difference is reasonably |
---|
890 | 890 | | related to the value provided to the consumer by the consumer's |
---|
891 | 891 | | data. |
---|
892 | 892 | | Sec. 541.108. FINANCIAL INCENTIVES. (a) Subject to |
---|
893 | 893 | | Subsection (b), a business may offer a financial incentive to a |
---|
894 | 894 | | consumer, including a payment as compensation, for the collection, |
---|
895 | 895 | | sale, or disclosure of the consumer's personal information. |
---|
896 | 896 | | (b) A business may enroll a customer in a financial |
---|
897 | 897 | | incentive program only if the business provides to the consumer a |
---|
898 | 898 | | clear description of the material terms of the program and obtains |
---|
899 | 899 | | the consumer's prior opt-in consent, which: |
---|
900 | 900 | | (1) contains a clear description of those material |
---|
901 | 901 | | terms; and |
---|
902 | 902 | | (2) may be revoked by the consumer at any time. |
---|
903 | 903 | | (c) A business may not use financial incentive practices |
---|
904 | 904 | | that are unjust, unreasonable, coercive, or usurious in nature. |
---|
905 | 905 | | Sec. 541.109. CERTAIN ACTIONS TO AVOID REQUIREMENTS |
---|
906 | 906 | | PROHIBITED. (a) A business may not divide a single transaction into |
---|
907 | 907 | | more than one transaction with the intent to avoid the requirements |
---|
908 | 908 | | of this chapter. |
---|
909 | 909 | | (b) For purposes of this chapter, two or more substantially |
---|
910 | 910 | | similar or related transactions are considered a single transaction |
---|
911 | 911 | | if the transactions: |
---|
912 | 912 | | (1) are entered into contemporaneously; and |
---|
913 | 913 | | (2) have at least one common party. |
---|
914 | 914 | | (c) A court shall disregard any intermediate transactions |
---|
915 | 915 | | conducted by a business with the intent to avoid the requirements of |
---|
916 | 916 | | this chapter, including the disclosure of information by a business |
---|
917 | 917 | | to a third party to avoid complying with the requirements under this |
---|
918 | 918 | | chapter applicable to a sale of the information. |
---|
919 | 919 | | Sec. 541.110. INFORMATION REQUIRED. A business shall |
---|
920 | 920 | | ensure that each person responsible for handling consumer inquiries |
---|
921 | 921 | | about the business's privacy practices or compliance with this |
---|
922 | 922 | | chapter is informed of the requirements of this chapter and of how |
---|
923 | 923 | | to direct a consumer in exercising any of the rights to which a |
---|
924 | 924 | | consumer is entitled under this chapter. |
---|
925 | 925 | | SUBCHAPTER D. REMEDIES |
---|
926 | 926 | | Sec. 541.151. CIVIL PENALTY; INJUNCTION. (a) A person who |
---|
927 | 927 | | violates this chapter is liable to this state for a civil penalty in |
---|
928 | 928 | | an amount not to exceed: |
---|
929 | 929 | | (1) $2,500 for each violation; or |
---|
930 | 930 | | (2) $7,500 for each violation, if the violation is |
---|
931 | 931 | | intentional. |
---|
932 | 932 | | (b) If it appears to the attorney general that a person is |
---|
933 | 933 | | engaging in, has engaged in, or is about to engage in conduct that |
---|
934 | 934 | | violates this chapter, the attorney general may give notice to the |
---|
935 | 935 | | person of the alleged violation. If the person fails to cure the |
---|
936 | 936 | | alleged violation before the 30th day after the date notice is |
---|
937 | 937 | | given, the attorney general may bring an action in the name of the |
---|
938 | 938 | | state against the person to restrain the violation by a temporary |
---|
939 | 939 | | restraining order or by a permanent or temporary injunction or to |
---|
940 | 940 | | recover the civil penalty imposed under this section, or both. |
---|
941 | 941 | | (c) The attorney general is entitled to recover reasonable |
---|
942 | 942 | | expenses, including reasonable attorney's fees, court costs, and |
---|
943 | 943 | | investigatory costs, incurred in obtaining injunctive relief or |
---|
944 | 944 | | civil penalties, or both, under this section. Amounts collected |
---|
945 | 945 | | under this section shall be deposited in a dedicated account in the |
---|
946 | 946 | | general revenue fund and may be appropriated only for the purposes |
---|
947 | 947 | | of the administration and enforcement of this chapter. |
---|
948 | 948 | | Sec. 541.152. BUSINESS IMMUNITY FROM LIABILITY. A business |
---|
949 | 949 | | that discloses to a third party, or discloses for a business purpose |
---|
950 | 950 | | to a service provider, a consumer's personal information in |
---|
951 | 951 | | compliance with this chapter may not be held liable for a violation |
---|
952 | 952 | | of this chapter by the third party or service provider if the |
---|
953 | 953 | | business does not have actual knowledge or a reasonable belief that |
---|
954 | 954 | | the third party or service provider intends to violate this |
---|
955 | 955 | | chapter. |
---|
956 | 956 | | Sec. 541.153. SERVICE PROVIDER IMMUNITY FROM LIABILITY. A |
---|
957 | 957 | | business's service provider may not be held liable for a violation |
---|
958 | 958 | | of this chapter by the business. |
---|
959 | 959 | | SECTION 2. This Act takes effect September 1, 2020. |
---|