Texas 2021 - 87th Regular

Texas House Bill HB3741 Compare Versions

Only one version of the bill is available at this time.
OldNewDifferences
11 87R8183 MLH-F
22 By: Capriglione H.B. No. 3741
33
44
55 A BILL TO BE ENTITLED
66 AN ACT
77 relating to the personal identifying information collected,
88 processed, or maintained by certain businesses; imposing a civil
99 penalty.
1010 BE IT ENACTED BY THE LEGISLATURE OF THE STATE OF TEXAS:
1111 SECTION 1. Title 11, Business & Commerce Code, is amended by
1212 adding Subtitle C to read as follows:
1313 SUBTITLE C. PERSONAL IDENTIFYING INFORMATION
1414 CHAPTER 541. PERSONAL IDENTIFYING INFORMATION PROCESSED OR
1515 COLLECTED BY CERTAIN BUSINESSES
1616 SUBCHAPTER A. GENERAL PROVISIONS
1717 Sec. 541.001. DEFINITIONS. In this chapter:
1818 (1) "Business" means a for-profit entity, including a
1919 sole proprietorship, partnership, limited liability company,
2020 corporation, association, or other legal entity that is organized
2121 or operated for the profit or financial benefit of the entity's
2222 shareholders or other owners.
2323 (2) "Category one information" means personal
2424 identifying information that an individual may use in a personal,
2525 civic, or business setting, and includes:
2626 (A) a social security number;
2727 (B) a driver's license number, passport number,
2828 military identification number, or any other similar number issued
2929 on a government document and used to verify an individual's
3030 identity;
3131 (C) a financial account number, credit or debit
3232 card number, or any security code, access code, or password that is
3333 necessary to permit access to an individual's financial account;
3434 (D) unique biometric information, including a
3535 fingerprint, voice print, retina or iris image, or any other unique
3636 physical representation;
3737 (E) physical or mental health information,
3838 including health care information; and
3939 (F) the private communications or other
4040 user-created content of an individual that is not publicly
4141 available.
4242 (3) "Category two information" means personal
4343 identifying information that may present a privacy risk to an
4444 individual, including members of a constitutionally protected
4545 class, and includes:
4646 (A) racial or ethnic origin information;
4747 (B) religious affiliation or practice
4848 information;
4949 (C) age;
5050 (D) physical or mental impairment;
5151 (E) precise geolocation tracking data; and
5252 (F) unique genetic information.
5353 (4) "Category three information" means specific
5454 facets of personal identifying information and includes:
5555 (A) time of birth; and
5656 (B) political party or association.
5757 (5) "Collect" means:
5858 (A) buying, renting, gathering, obtaining,
5959 receiving, inferring, creating, or accessing any personal
6060 identifying information pertaining to an individual by any means;
6161 or
6262 (B) obtaining personal identifying information
6363 relating to an individual, actively or passively, or by observing
6464 the individual's behavior.
6565 (6) "Device" means any physical object capable of
6666 connecting to the Internet, directly or indirectly, or to another
6767 device and transmitting information.
6868 (7) "Geolocation tracking" means the use of
6969 geolocation technology to determine or record the position of a
7070 person, including the use of a global positioning system, web-based
7171 imagery, and cell tower triangulation.
7272 (8) "Personal identifying information" means a
7373 category of information relating to an identified or identifiable
7474 individual. The term does not include a specific category of
7575 personal identifying information that the attorney general exempts
7676 from this definition by rule. The term includes:
7777 (A) a social security number;
7878 (B) a driver's license number, passport number,
7979 military identification number, or any other similar number issued
8080 on a government document and used to verify an individual's
8181 identity;
8282 (C) a financial account number, credit or debit
8383 card number, or any security code, access code, or password that is
8484 necessary to permit access to an individual's financial account;
8585 (D) unique biometric information, including a
8686 fingerprint, voice print, retina or iris image, or any other unique
8787 physical representation;
8888 (E) physical or mental health information,
8989 including health care information;
9090 (F) the private communications or other
9191 user-created content of an individual that is not publicly
9292 available;
9393 (G) religious affiliation or practice
9494 information;
9595 (H) racial or ethnic origin information;
9696 (I) precise geolocation tracking data; and
9797 (J) unique genetic information.
9898 (9) "Privacy risk" means potential adverse
9999 consequences to an individual or society at large arising from the
100100 processing of personal identifying information, including:
101101 (A) direct or indirect financial loss or economic
102102 harm;
103103 (B) physical harm;
104104 (C) psychological harm, including anxiety,
105105 embarrassment, fear, or other demonstrable mental trauma;
106106 (D) significant inconvenience or expenditure of
107107 time;
108108 (E) adverse outcomes or decisions with respect to
109109 an individual's eligibility for a right, benefit, or privilege in
110110 employment, including hiring, firing, promotion, demotion, or
111111 compensation;
112112 (F) credit or insurance harm, including denial of
113113 an application or obtaining less favorable terms related to
114114 housing, education, professional certification, or health care
115115 services;
116116 (G) stigmatization or reputational harm;
117117 (H) disruption and intrusion from unwanted
118118 commercial communications or contacts;
119119 (I) price discrimination; and
120120 (J) any other adverse consequence that affects an
121121 individual's private life, private family matters, actions or
122122 communications within an individual's home or similar physical,
123123 online, or digital location, if an individual has a reasonable
124124 expectation that personal identifying information will not be
125125 processed.
126126 (10) "Processing" means any operation or set of
127127 operations that are performed on personal identifying information
128128 or on sets of personal identifying information, including the
129129 collection, creation, generation, recording, organization,
130130 structuring, storage, adaptation, alteration, retrieval,
131131 consultation, use, disclosure, transfer, or dissemination of the
132132 information or otherwise making the information available.
133133 (11) "Third party" means a person engaged by a
134134 business to process, on behalf of the business, personal
135135 identifying information collected by the business.
136136 Sec. 541.002. APPLICABILITY. (a) This chapter applies
137137 only to a business that:
138138 (1) does business in this state;
139139 (2) has more than 50 employees;
140140 (3) collects the personal identifying information of
141141 more than 5,000 individuals, households, or devices or has that
142142 information collected on the business's behalf; and
143143 (4) satisfies one or more of the following thresholds:
144144 (A) has annual gross revenue in an amount that
145145 exceeds $25 million; or
146146 (B) derives 50 percent or more of the business's
147147 annual revenue by processing personal identifying information.
148148 (b) Except as provided by Subsection (c), this chapter
149149 applies only to personal identifying information that is:
150150 (1) collected over the Internet or any other digital
151151 network or through a computing device that is associated with or
152152 routinely used by an end user; and
153153 (2) linked or reasonably linkable to a specific end
154154 user.
155155 (c) This chapter does not apply to personal identifying
156156 information that is:
157157 (1) collected solely for facilitating the
158158 transmission, routing, or connections by which digital personal
159159 identifying information and other data is transferred between or
160160 among businesses; or
161161 (2) transmitted to and from the individual to whom the
162162 personal identifying information relates if the collector of the
163163 information does not access, review, or modify the content of the
164164 information, or otherwise perform or conduct any analytical,
165165 algorithmic, or machine learning processes on the information.
166166 Sec. 541.003. EXEMPTIONS. This chapter does not apply to:
167167 (1) publicly available information;
168168 (2) protected health information governed by Chapter
169169 181, Health and Safety Code, or collected by a covered entity or a
170170 business associate of a covered entity, as those terms are defined
171171 by 45 C.F.R. Section 160.103, that is governed by the privacy,
172172 security, and breach notification rules in 45 C.F.R. Parts 160 and
173173 164 adopted by the United States Department of Health and Human
174174 Services under the Health Insurance Portability and Accountability
175175 Act of 1996 (Pub. L. No. 104-191) and Title XIII of the American
176176 Recovery and Reinvestment Act of 2009 (Pub. L. No. 111-5);
177177 (3) personal identifying information collected by a
178178 consumer reporting agency, as defined by Section 20.01, if the
179179 information is to be:
180180 (A) reported in or used to generate a consumer
181181 report, as defined by Section 1681a(d) of the Fair Credit Reporting
182182 Act (15 U.S.C. Section 1681 et seq.); and
183183 (B) used solely for a purpose authorized under
184184 that Act;
185185 (4) personal identifying information processed in
186186 accordance with the Gramm-Leach-Bliley Act (Pub. L. No. 106-102)
187187 and its implementing regulations; or
188188 (5) education information that is not publicly
189189 available personally identifiable information under the Family
190190 Educational Rights and Privacy Act of 1974 (20 U.S.C. Section
191191 1232g) (34 C.F.R. Part 99).
192192 Sec. 541.004. RULES. The attorney general shall adopt
193193 rules necessary to implement, administer, and enforce this chapter.
194194 SUBCHAPTER B. CONSUMER RIGHTS
195195 Sec. 541.051. RIGHT TO KNOW: DISCLOSURE AND USE OF
196196 COLLECTED PERSONAL INFORMATION. An individual is entitled to
197197 request that a business that collects personal identifying
198198 information relating to the individual or someone for whom the
199199 individual is a legal representative or guardian disclose to the
200200 individual:
201201 (1) the personal identifying information that is being
202202 collected by the business, including the categories and specific
203203 items of information the business collects;
204204 (2) the sources from which the business collects the
205205 information;
206206 (3) the business's purpose in collecting the
207207 information; and
208208 (4) the names of third parties to which the
209209 information has been distributed or transferred by the business,
210210 including to names of any third parties that have purchased the
211211 information from the business.
212212 Sec. 541.052. RIGHT TO HAVE INACCURATE INFORMATION
213213 CORRECTED. Subject to Section 541.153, an individual is entitled
214214 to request that a business that collects personal identifying
215215 information related to the individual or someone for whom the
216216 individual is a legal representative or guardian correct any
217217 inaccurate information collected or maintained by the business that
218218 relates to the individual or the person for whom the individual is a
219219 legal representative or guardian.
220220 Sec. 541.053. RIGHT TO ACCESS AND OBTAIN INFORMATION.
221221 Subject to Section 541.154, an individual is entitled to:
222222 (1) access and obtain personal identifying
223223 information related to the individual or someone for whom the
224224 individual is a legal representative or guardian that is collected
225225 by a business; and
226226 (2) at the option of the individual, transfer personal
227227 identifying information from one business to another business,
228228 including in connection with the sale of that information under a
229229 contract described by Subchapter C.
230230 Sec. 541.054. RIGHT TO DELETION OF SENSITIVE PERSONAL
231231 INFORMATION. Subject to Section 541.155, an individual is entitled
232232 to request that a business delete sensitive personal information
233233 collected by the business that relates to that individual or
234234 someone for whom the individual is a legal representative or
235235 guardian.
236236 SUBCHAPTER C. CONTRACTS WITH INDIVIDUALS
237237 Sec. 541.101. DEFINITION. In this subchapter, "data
238238 stream" means the continuous transmission of an individual's
239239 personal identifying information through online activity or with a
240240 device connected to the Internet that can be used by the business to
241241 provide for the monetization of the information, customer
242242 relationship management, or continuous identification of an
243243 individual for commercial purposes.
244244 Sec. 541.102. APPLICABILITY. This subchapter applies only
245245 to a contract between a business and an individual under which, as a
246246 term of the contract, the individual allows the business to
247247 collect, store, or use the individual's personal identifying
248248 information.
249249 Sec. 541.103. CONSIDERATION UNDER CONTRACT. (a) An
250250 individual may provide the individual's data stream or information
251251 obtained by the individual under Section 541.154 as consideration
252252 under a contract.
253253 (b) A business may provide consideration in the form of
254254 money or other incentive, including as an incentive to purchase
255255 goods or services, under a contract that is reasonably related to
256256 the value of the information or access offered by the individual
257257 under the contract. This subsection does not prohibit a business
258258 from differentiating the consideration offered to individuals
259259 based on information or access offered by individuals, including
260260 offering different individuals different prices or rates for goods
261261 or services or providing different levels of quality for goods or
262262 services based on the information and access offered by
263263 individuals.
264264 Sec. 541.104. CONTRACT REQUIREMENTS. (a) A contract
265265 subject to this subchapter:
266266 (1) must clearly state the terms, including the
267267 duration, of the contract; and
268268 (2) may not:
269269 (A) require that the individual exclusively
270270 contract with the business or otherwise restrict the individual's
271271 ability to sell the individual's personal identifying information;
272272 and
273273 (B) prevent the individual from receiving or
274274 considering alternative offers to purchase the individual's
275275 personal identifying information.
276276 (b) A contract provision that violates Subsection (a)(2) is
277277 void and unenforceable.
278278 SUBCHAPTER D. BUSINESS DUTIES
279279 Sec. 541.151. RESTRICTIONS ON USE OF PERSONAL IDENTIFYING
280280 INFORMATION. (a) Subject to the requirements of this section, a
281281 business may collect and process category one and category two
282282 information.
283283 (b) A business may not:
284284 (1) sell, transfer, or communicate category two
285285 information to any third party; or
286286 (2) collect or process category three information.
287287 (c) Without the express written consent of the individual, a
288288 business may not:
289289 (1) perform geolocation tracking of an individual,
290290 including for purposes of contact tracing; or
291291 (2) sell data relating to an individual that is
292292 collected from geolocation tracking.
293293 (d) A business shall protect and properly secure all
294294 personal identifying information collected by or in the possession
295295 of the business.
296296 Sec. 541.152. NOTICE REQUIRED. (a) A business in a
297297 conspicuous manner shall provide a notice that includes a
298298 reasonably full and complete description of the business's
299299 practices governing the processing of personal identifying
300300 information before collecting personal identifying information.
301301 The notice must include:
302302 (1) the categories of personal identifying
303303 information processed by the business;
304304 (2) details on the type of processing used by the
305305 business;
306306 (3) the purposes for which the business processes
307307 personal identifying information; and
308308 (4) the involvement of any third party in processing
309309 personal identifying information on behalf of the business.
310310 (b) The notice required by Subsection (a) must be:
311311 (1) clear, drafted in plain language, and easy to
312312 understand; and
313313 (2) located in a prominent location at the business
314314 and on the business's Internet website if the business has an
315315 Internet website.
316316 Sec. 541.153. DUTY TO MAINTAIN ACCURATE INFORMATION. (a) A
317317 business must ensure that the personal identifying information the
318318 business maintains is accurate.
319319 (b) A business shall clearly and conspicuously publish an
320320 e-mail address, fax number, or mailing address to enable an
321321 individual to dispute the accuracy of the personal identifying
322322 information collected or maintained by the business.
323323 (c) If a business receives a dispute regarding the accuracy
324324 of personal identifying information that relates to the individual
325325 or someone for whom the individual is a legal representative or
326326 guardian from the individual, the business shall, unless the
327327 business conducts an investigation and determines the information
328328 is accurate, promptly correct the inaccurate information. The
329329 individual making the dispute may provide supplementary
330330 information when necessary to correct inaccurate personal
331331 identifying information.
332332 (d) The business may not charge a fee to remove, correct, or
333333 modify inaccurate personal identifying information under this
334334 section.
335335 (e) A business shall provide written notice to the
336336 individual who disputed the accuracy of the personal identifying
337337 information of the actions it has taken in response to the dispute
338338 not later than the fifth business day after the date on which the
339339 dispute was received.
340340 Sec. 541.154. ACCESS TO INFORMATION; DATA PORTABILITY. (a)
341341 A business shall allow an individual to promptly and reasonably
342342 obtain:
343343 (1) confirmation of whether personal identifying
344344 information concerning the individual or someone for whom the
345345 individual is a legal representative or guardian is processed by
346346 the business;
347347 (2) a description of the categories of personal
348348 identifying information processed by the business;
349349 (3) an explanation in plain language of the specific
350350 types of personal identifying information collected by the
351351 business;
352352 (4) a description of the inferences the business has
353353 drawn about the individual or someone for whom the individual is a
354354 personal representative or guardian from the information collected
355355 by the business; and
356356 (5) access to the individual's personal identifying
357357 information, including in accordance with Subsection (b), a copy of
358358 the individual's personal identifying information in a portable and
359359 transferable format.
360360 (b) On request of an individual, a business shall without
361361 undue delay provide the individual with all personal identifying
362362 information collected by the business that relates to the
363363 individual or someone for whom the individual is a legal
364364 representative or guardian. The business shall provide the
365365 requested information to an individual under this section in a
366366 portable, readily usable format that may be transferred, including
367367 in connection with the sale of the information, by the individual to
368368 another business.
369369 Sec. 541.155. DELETION OF PERSONAL IDENTIFYING
370370 INFORMATION. (a) If an individual who maintains an account with a
371371 business closes the account, the business shall:
372372 (1) stop processing the individual's personal
373373 identifying information on the date the individual closes the
374374 account; and
375375 (2) not later than the one-year anniversary of the
376376 date the account is closed, permanently delete the individual's
377377 personal identifying information unless retention of the
378378 information is required by other law or is necessary to comply with
379379 other law.
380380 (b) If an individual makes a request for a business to
381381 delete personal identifying information under this section, and
382382 that business has provided the personal identifying information to
383383 a third party, the business shall notify the third party of the
384384 individual's request. The third party shall delete the individual's
385385 personal identifying information not later than the one-year
386386 anniversary of the date the third party received the notification
387387 under this subsection.
388388 SUBCHAPTER E. ENFORCEMENT
389389 Sec. 541.201. CIVIL PENALTY. (a) A business that violates
390390 this chapter or a third party that violates Section 541.155(b) is
391391 liable to this state for a civil penalty in an amount of not more
392392 than $10,000 for each violation, not to exceed a total amount of $1
393393 million.
394394 (b) The attorney general may bring an action in the name of
395395 the state against the business or third party to recover the civil
396396 penalty imposed under this section.
397397 (c) The attorney general is entitled to recover reasonable
398398 expenses, including reasonable attorney's fees, court costs, and
399399 investigatory costs, incurred in bringing an action under this
400400 section.
401401 Sec. 541.202. BUSINESS IMMUNITY FROM LIABILITY. A business
402402 that is in compliance with this chapter and engages a third party to
403403 process on behalf of the business personal identifying information
404404 collected by the business may not be held liable for a violation of
405405 Section 541.155(b) by the third party if the business does not have
406406 actual knowledge or a reasonable belief that the third party
407407 intends to violate that section.
408408 Sec. 541.203. NO PRIVATE CAUSE OF ACTION. This chapter does
409409 not create a private cause of action.
410410 SECTION 2. (a) Except as provided by Subsection (b) of this
411411 section, this Act takes effect September 1, 2021.
412412 (b) Sections 541.054 and 541.155, Business & Commerce Code,
413413 as added by this Act, take effect January 1, 2022.