Texas 2021 - 87th Regular

Texas House Bill HB4164 Compare Versions

Only one version of the bill is available at this time.
OldNewDifferences
11 87R7858 MLH-D
22 By: Capriglione H.B. No. 4164
33
44
55 A BILL TO BE ENTITLED
66 AN ACT
77 relating to the authority of individuals over the personal
88 identifying information collected, processed, or maintained about
99 the individuals and certain others by certain businesses.
1010 BE IT ENACTED BY THE LEGISLATURE OF THE STATE OF TEXAS:
1111 SECTION 1. Title 11, Business & Commerce Code, is amended by
1212 adding Subtitle C to read as follows:
1313 SUBTITLE C. PERSONAL IDENTIFYING INFORMATION
1414 CHAPTER 541. PERSONAL IDENTIFYING INFORMATION PROCESSED OR
1515 COLLECTED BY CERTAIN BUSINESSES
1616 SUBCHAPTER A. GENERAL PROVISIONS
1717 Sec. 541.001. DEFINITIONS. In this chapter:
1818 (1) "Business" means a for-profit entity, including a
1919 sole proprietorship, partnership, limited liability company,
2020 corporation, association, or other legal entity that is organized
2121 or operated for the profit or financial benefit of the entity's
2222 shareholders or other owners.
2323 (2) "Personal identifying information" means a
2424 category of information relating to an identified or identifiable
2525 individual. The term does not include a specific category of
2626 personal identifying information that the attorney general exempts
2727 from this definition by rule. The term includes:
2828 (A) a social security number;
2929 (B) a driver's license number, passport number,
3030 military identification number, or any other similar number issued
3131 on a government document and used to verify an individual's
3232 identity;
3333 (C) a financial account number, credit or debit
3434 card number, or any security code, access code, or password that is
3535 necessary to permit access to an individual's financial account;
3636 (D) unique biometric information, including a
3737 fingerprint, voice print, retina or iris image, or any other unique
3838 physical representation;
3939 (E) physical or mental health information,
4040 including health care information;
4141 (F) the private communications or other
4242 user-created content of an individual that is not publicly
4343 available;
4444 (G) religious affiliation or practice
4545 information;
4646 (H) racial or ethnic origin information;
4747 (I) precise geolocation tracking data; and
4848 (J) unique genetic information.
4949 (3) "Processing" means any operation or set of
5050 operations that are performed on personal identifying information
5151 or on sets of personal identifying information, including the
5252 collection, creation, generation, recording, organization,
5353 structuring, storage, adaptation, alteration, retrieval,
5454 consultation, use, disclosure, transfer, or dissemination of the
5555 information or otherwise making the information available.
5656 (4) "Third party" means a person engaged by a business
5757 to process, on behalf of the business, personal identifying
5858 information collected by the business.
5959 Sec. 541.002. APPLICABILITY. (a) This chapter applies
6060 only to a business that:
6161 (1) does business in this state;
6262 (2) has more than 50 employees;
6363 (3) collects the personal identifying information of
6464 more than 5,000 individuals, households, or devices or has that
6565 information collected on the business's behalf; and
6666 (4) satisfies one or more of the following thresholds:
6767 (A) has annual gross revenue in an amount that
6868 exceeds $25 million; or
6969 (B) derives 50 percent or more of the business's
7070 annual revenue by processing personal identifying information.
7171 (b) Except as provided by Subsection (c), this chapter
7272 applies only to personal identifying information that is:
7373 (1) collected over the Internet or any other digital
7474 network or through a computing device that is associated with or
7575 routinely used by an end user; and
7676 (2) linked or reasonably linkable to a specific end
7777 user.
7878 (c) This chapter does not apply to personal identifying
7979 information that is:
8080 (1) collected solely for facilitating the
8181 transmission, routing, or connections by which digital personal
8282 identifying information and other data is transferred between or
8383 among businesses; or
8484 (2) transmitted to and from the individual to whom the
8585 personal identifying information relates if the collector of the
8686 information does not access, review, or modify the content of the
8787 information, or otherwise perform or conduct any analytical,
8888 algorithmic, or machine learning processes on the information.
8989 Sec. 541.003. EXEMPTIONS. This chapter does not apply to:
9090 (1) publicly available information;
9191 (2) protected health information governed by Chapter
9292 181, Health and Safety Code, or collected by a covered entity or a
9393 business associate of a covered entity, as those terms are defined
9494 by 45 C.F.R. Section 160.103, that is governed by the privacy,
9595 security, and breach notification rules in 45 C.F.R. Parts 160 and
9696 164 adopted by the United States Department of Health and Human
9797 Services under the Health Insurance Portability and Accountability
9898 Act of 1996 (Pub. L. No. 104-191) and Title XIII of the American
9999 Recovery and Reinvestment Act of 2009 (Pub. L. No. 111-5);
100100 (3) personal identifying information collected by a
101101 consumer reporting agency, as defined by Section 20.01, if the
102102 information is to be:
103103 (A) reported in or used to generate a consumer
104104 report, as defined by Section 1681a(d) of the Fair Credit Reporting
105105 Act (15 U.S.C. Section 1681 et seq.); and
106106 (B) used solely for a purpose authorized under
107107 that Act;
108108 (4) personal identifying information processed in
109109 accordance with the Gramm-Leach-Bliley Act (Pub. L. No. 106-102)
110110 and its implementing regulations; or
111111 (5) education information that is not publicly
112112 available personally identifiable information under the Family
113113 Educational Rights and Privacy Act of 1974 (20 U.S.C. Section
114114 1232g) (34 C.F.R. Part 99).
115115 Sec. 541.004. RULES. The attorney general shall adopt
116116 rules necessary to implement, administer, and enforce this chapter.
117117 SUBCHAPTER B. AUTHORITY OF INDIVIDUALS TO ACCESS AND DELETE CERTAIN
118118 INFORMATION
119119 Sec. 541.051. ACCESS TO INFORMATION; DATA PORTABILITY. (a)
120120 An individual is entitled to:
121121 (1) access and obtain personal identifying
122122 information related to the individual or someone for whom the
123123 individual is a legal representative or guardian that is collected
124124 by a business; and
125125 (2) at the option of the individual, transfer personal
126126 identifying information from one business to another business,
127127 including in connection with the sale of that information under a
128128 contract described by Subchapter C.
129129 (b) A business shall allow an individual to promptly and
130130 reasonably obtain:
131131 (1) confirmation of whether personal identifying
132132 information concerning the individual or someone for whom the
133133 individual is a legal representative or guardian is processed by
134134 the business;
135135 (2) a description of the categories of personal
136136 identifying information processed by the business;
137137 (3) an explanation in plain language of the specific
138138 types of personal identifying information collected by the
139139 business;
140140 (4) a description of the inferences the business has
141141 drawn about the individual or someone for whom the individual is a
142142 personal representative or guardian from the information collected
143143 by the business; and
144144 (5) access to the individual's personal identifying
145145 information, including in accordance with Subsection (c), a copy of
146146 the individual's personal identifying information in a portable and
147147 transferable format.
148148 (c) On request of an individual, a business shall without
149149 undue delay provide the individual with all personal identifying
150150 information collected by the business that relates to the
151151 individual or someone for whom the individual is a legal
152152 representative or guardian. The business shall provide the
153153 requested information to an individual under this section in a
154154 portable, readily usable format that may be transferred, including
155155 in connection with the sale of the information, by the individual to
156156 another business.
157157 Sec. 541.052. DELETION OF PERSONAL IDENTIFYING
158158 INFORMATION. (a) An individual is entitled to request that a
159159 business delete personal identifying information collected by the
160160 business that relates to that individual or someone for whom the
161161 individual is a legal representative or guardian.
162162 (b) If an individual who maintains an account with a
163163 business closes the account, the business shall:
164164 (1) stop processing the individual's personal
165165 identifying information on the date the individual closes the
166166 account; and
167167 (2) not later than the one-year anniversary of the
168168 date the account is closed, permanently delete the individual's
169169 personal identifying information unless retention of the
170170 information is required by other law or is necessary to comply with
171171 other law.
172172 (c) If an individual makes a request for a business to
173173 delete personal identifying information under this section, and
174174 that business has provided the personal identifying information to
175175 a third party, the business shall notify the third party of the
176176 individual's request. The third party shall delete the individual's
177177 personal identifying information not later than the one-year
178178 anniversary of the date the third party received the notification
179179 under this subsection.
180180 SUBCHAPTER C. CONTRACTS WITH INDIVIDUALS
181181 Sec. 541.101. DEFINITION. In this subchapter, "data
182182 stream" means the continuous transmission of an individual's
183183 personal identifying information through online activity or with a
184184 device connected to the Internet that can be used by the business to
185185 provide for the monetization of the information, customer
186186 relationship management, or continuous identification of an
187187 individual for commercial purposes.
188188 Sec. 541.102. APPLICABILITY. This subchapter applies only
189189 to a contract between a business and an individual under which, as a
190190 term of the contract, the individual allows the business to
191191 collect, store, or use the individual's personal identifying
192192 information.
193193 Sec. 541.103. CONSIDERATION UNDER CONTRACT. (a) An
194194 individual may provide the individual's data stream or information
195195 obtained by the individual under Section 541.051 as consideration
196196 under a contract.
197197 (b) A business may provide consideration in the form of
198198 money or other incentive, including as an incentive to purchase
199199 goods or services, under a contract that is reasonably related to
200200 the value of the information or access offered by the individual
201201 under the contract. This subsection does not prohibit a business
202202 from differentiating the consideration offered to individuals
203203 based on information or access offered by individuals, including
204204 offering different individuals different prices or rates for goods
205205 or services or providing different levels of quality for goods or
206206 services based on the information and access offered by
207207 individuals.
208208 Sec. 541.104. CONTRACT REQUIREMENTS. (a) A contract
209209 subject to this subchapter:
210210 (1) must clearly state the terms, including the
211211 duration, of the contract; and
212212 (2) may not:
213213 (A) require that the individual exclusively
214214 contract with the business or otherwise restrict the individual's
215215 ability to sell the individual's personal identifying information;
216216 and
217217 (B) prevent the individual from receiving or
218218 considering alternative offers to purchase the individual's
219219 personal identifying information.
220220 (b) A contract provision that violates Subsection (a)(2) is
221221 void and unenforceable.
222222 SECTION 2. (a) Except as provided by Subsection (b) of this
223223 section, this Act takes effect September 1, 2021.
224224 (b) Section 541.052, Business & Commerce Code, as added by
225225 this Act, takes effect January 1, 2022.