1 | 1 | | 88R10880 TYPED |
---|
2 | 2 | | By: Capriglione H.B. No. 1844 |
---|
3 | 3 | | |
---|
4 | 4 | | |
---|
5 | 5 | | A BILL TO BE ENTITLED |
---|
6 | 6 | | AN ACT |
---|
7 | 7 | | relating to the regulation of the collection, use, processing, and |
---|
8 | 8 | | treatment of consumers' personal data by certain business entities; |
---|
9 | 9 | | imposing a civil penalty. |
---|
10 | 10 | | BE IT ENACTED BY THE LEGISLATURE OF THE STATE OF TEXAS: |
---|
11 | 11 | | SECTION 1. Title 11, Business & Commerce Code, is amended by |
---|
12 | 12 | | adding Subtitle C to read as follows: |
---|
13 | 13 | | SUBTITLE C. CONSUMER DATA PROTECTION |
---|
14 | 14 | | CHAPTER 541. CONSUMER DATA PROTECTION |
---|
15 | 15 | | SUBCHAPTER A. GENERAL PROVISIONS |
---|
16 | 16 | | Sec. 541.001 SHORT TITLE. This chapter may be cited as the |
---|
17 | 17 | | Texas Data Privacy and Security Act. |
---|
18 | 18 | | Sec. 541.002. DEFINITIONS. In this chapter, unless a |
---|
19 | 19 | | different meaning is required by the context: |
---|
20 | 20 | | (1) "Affiliate" means a legal entity that controls, is |
---|
21 | 21 | | controlled by, or is under common control with another legal entity |
---|
22 | 22 | | or shares common branding with another legal entity. For purposes |
---|
23 | 23 | | of this subdivision, "control" or "controlled" means: |
---|
24 | 24 | | (A) the ownership of, or power to vote, more than |
---|
25 | 25 | | 50 percent of the outstanding shares of any class of voting security |
---|
26 | 26 | | of a company; |
---|
27 | 27 | | (B) the control in any manner over the election |
---|
28 | 28 | | of a majority of the directors or of individuals exercising similar |
---|
29 | 29 | | functions; or |
---|
30 | 30 | | (C) the power to exercise controlling influence |
---|
31 | 31 | | over the management of a company. |
---|
32 | 32 | | (2) "Authenticate" means to verify through reasonable |
---|
33 | 33 | | means that the consumer who is entitled to exercise the consumer's |
---|
34 | 34 | | rights under Subchapter B is the same consumer exercising those |
---|
35 | 35 | | consumer rights with respect to the personal data at issue. |
---|
36 | 36 | | (3) "Biometric data" "Biometric data" means data |
---|
37 | 37 | | generated by automatic measurements of an individual's biological |
---|
38 | 38 | | characteristics, such as fingerprint, voiceprint, eye retina or |
---|
39 | 39 | | iris, or other unique biological patterns or characteristics, that |
---|
40 | 40 | | are used to identify a specific individual. The term does not |
---|
41 | 41 | | include physical or digital photograph, a video or audio recording, |
---|
42 | 42 | | or data generated therefrom, or information collected, used, or |
---|
43 | 43 | | stored for health care treatment, payment, or operations under the |
---|
44 | 44 | | Health Insurance Portability and Accountability Act of 1996 (42 |
---|
45 | 45 | | U.S.C. Section 1320 et seq.) |
---|
46 | 46 | | (4) "Business associate" has the meaning assigned to |
---|
47 | 47 | | the term by the Health Insurance Portability and Accountability Act |
---|
48 | 48 | | of 1996 (42 U.S.C. Section 1320d et seq.). |
---|
49 | 49 | | (5) "Child" means an individual younger than 13 years |
---|
50 | 50 | | of age. |
---|
51 | 51 | | (6) "Consent," when referring to a consumer, means a |
---|
52 | 52 | | clear affirmative act signifying a consumer's freely given, |
---|
53 | 53 | | specific, informed, and unambiguous agreement to process personal |
---|
54 | 54 | | data relating to the consumer. The term includes a written |
---|
55 | 55 | | statement, including a statement written by electronic means, or |
---|
56 | 56 | | any other unambiguous affirmative action. "Consent" does not |
---|
57 | 57 | | include: |
---|
58 | 58 | | (A) acceptance of a general or broad terms of use |
---|
59 | 59 | | or similar document that contains descriptions of personal data |
---|
60 | 60 | | processing along with other, unrelated information; |
---|
61 | 61 | | (B) hovering over, muting, pausing or closing a |
---|
62 | 62 | | given piece of content; or |
---|
63 | 63 | | (C) agreement obtained through the use of dark |
---|
64 | 64 | | patterns. |
---|
65 | 65 | | (7) "Consumer" means an individual who is a resident |
---|
66 | 66 | | of this state acting only in an individual or household context. The |
---|
67 | 67 | | term does not include an individual acting in a commercial or |
---|
68 | 68 | | employment context. |
---|
69 | 69 | | (8) "Controller" means an individual or other person |
---|
70 | 70 | | that, alone or jointly with others, determines the purpose and |
---|
71 | 71 | | means of processing personal data. |
---|
72 | 72 | | (9) "Covered entity" has the meaning assigned to the |
---|
73 | 73 | | term by the Health Insurance Portability and Accountability Act of |
---|
74 | 74 | | 1996 (42 U.S.C. Section 1320d et seq.). |
---|
75 | 75 | | (10) "Dark pattern" means a user interface designed or |
---|
76 | 76 | | manipulated with the substantial effect of subverting or impairing |
---|
77 | 77 | | user autonomy, decision-making or choice, and includes, but is not |
---|
78 | 78 | | limited to, any practice the Federal Trade Commission refers to as a |
---|
79 | 79 | | "dark pattern". |
---|
80 | 80 | | (11) "Decision that produces a legal or similarly |
---|
81 | 81 | | significant effect concerning a consumer" means a decision made by |
---|
82 | 82 | | the controller that results in the provision or denial by the |
---|
83 | 83 | | controller of: |
---|
84 | 84 | | (A) financial and lending services; |
---|
85 | 85 | | (B) housing, insurance, or health care services; |
---|
86 | 86 | | (C) education enrollment; |
---|
87 | 87 | | (D) employment opportunities; |
---|
88 | 88 | | (E) criminal justice; or |
---|
89 | 89 | | (F) access to basic necessities, such as food and |
---|
90 | 90 | | water. |
---|
91 | 91 | | (12) "Deidentified data" means data that cannot |
---|
92 | 92 | | reasonably be linked to an identified or identifiable individual, |
---|
93 | 93 | | or a device linked to that individual. |
---|
94 | 94 | | (13) "Health care provider" has the meaning assigned |
---|
95 | 95 | | to the term by the Health Insurance Portability and Accountability |
---|
96 | 96 | | Act of 1996 (42 U.S.C. Section 1320d et seq.). |
---|
97 | 97 | | (14) "Health record" means any written, printed, or |
---|
98 | 98 | | electronically recorded material maintained by a health care |
---|
99 | 99 | | provider in the course of providing health care services to an |
---|
100 | 100 | | individual that concerns the individual and the services provided. |
---|
101 | 101 | | The term includes: |
---|
102 | 102 | | (A) the substance of any communication made by an |
---|
103 | 103 | | individual to a health care provider in confidence during or in |
---|
104 | 104 | | connection with the provision of health care services; or |
---|
105 | 105 | | (B) information otherwise acquired by the health |
---|
106 | 106 | | care provider about an individual in confidence and in connection |
---|
107 | 107 | | with health care services provided to the individual. |
---|
108 | 108 | | (15) "Identified or identifiable individual" means an |
---|
109 | 109 | | individual who can be readily identified, directly or indirectly. |
---|
110 | 110 | | (16) "Institution of higher education" means: |
---|
111 | 111 | | (A) an institution of higher education as defined |
---|
112 | 112 | | by Section 61.003, Education Code; or |
---|
113 | 113 | | (B) a private or independent institution of |
---|
114 | 114 | | higher education as defined by Section 61.003, Education Code. |
---|
115 | 115 | | (17) "Known child" means a child under circumstances |
---|
116 | 116 | | where a controller has actual knowledge of, or willfully |
---|
117 | 117 | | disregards, the child's age. |
---|
118 | 118 | | (18) "Nonprofit organization" means: |
---|
119 | 119 | | (A) a corporation organized under Chapters 20 and |
---|
120 | 120 | | 22, Business Organizations Code, and the provisions of Title 1, |
---|
121 | 121 | | Business Organizations Code, to the extent applicable to nonprofit |
---|
122 | 122 | | corporations; |
---|
123 | 123 | | (B) an organization exempt from federal taxation |
---|
124 | 124 | | under Section 501(a), Internal Revenue Code of 1986, by being |
---|
125 | 125 | | listed as an exempt organization under Section 501(c)(3), |
---|
126 | 126 | | 501(c)(6), or 501(c)(12) of that code; |
---|
127 | 127 | | (C) a political organization; |
---|
128 | 128 | | (D) an organization that: |
---|
129 | 129 | | (i) is exempt from federal taxation under |
---|
130 | 130 | | Section 501(a), Internal Revenue Code of 1986, by being listed as an |
---|
131 | 131 | | exempt organization under Section 501(c)(4) of that code; and |
---|
132 | 132 | | (ii) is described by Section 701.052(a), |
---|
133 | 133 | | Insurance Code; or |
---|
134 | 134 | | (E) a subsidiary or affiliate of an entity |
---|
135 | 135 | | organized under Chapter 11, Utilities Code. |
---|
136 | 136 | | (19) "Personal data" means any information, including |
---|
137 | 137 | | pseudonymous data and sensitive data, that is linked or reasonably |
---|
138 | 138 | | linkable to an identified or identifiable individual. The term does |
---|
139 | 139 | | not include deidentified data or publicly available information. |
---|
140 | 140 | | (20) "Political organization" means a party, |
---|
141 | 141 | | committee, association, fund, or other organization, regardless of |
---|
142 | 142 | | whether incorporated, that is organized and operated primarily for |
---|
143 | 143 | | the purpose of influencing or attempting to influence: |
---|
144 | 144 | | (A) the selection, nomination, election, or |
---|
145 | 145 | | appointment of an individual to a federal, state, or local public |
---|
146 | 146 | | office or an office in a political organization, regardless of |
---|
147 | 147 | | whether the individual is selected, nominated, elected, or |
---|
148 | 148 | | appointed; or |
---|
149 | 149 | | (B) the election of a |
---|
150 | 150 | | presidential/vice-presidential elector, regardless of whether the |
---|
151 | 151 | | elector is selected, nominated, elected, or appointed. |
---|
152 | 152 | | (21) "Precise geolocation data" means information |
---|
153 | 153 | | derived from technology, including global positioning system level |
---|
154 | 154 | | latitude and longitude coordinates or other mechanisms, that |
---|
155 | 155 | | directly identifies the specific location of an individual with |
---|
156 | 156 | | precision and accuracy within a radius of 1,750 feet. The term does |
---|
157 | 157 | | not include the content of communications, or any data generated by |
---|
158 | 158 | | or connected to an advanced utility metering infrastructure system |
---|
159 | 159 | | or to equipment for use by a utility. |
---|
160 | 160 | | (22) "Process" or "processing" means an operation or |
---|
161 | 161 | | set of operations performed, whether by manual or automated means, |
---|
162 | 162 | | on personal data or on sets of personal data, such as the |
---|
163 | 163 | | collection, use, storage, disclosure, analysis, deletion, or |
---|
164 | 164 | | modification of personal data. |
---|
165 | 165 | | (23) "Processor" means a person that processes |
---|
166 | 166 | | personal data on behalf of a controller. |
---|
167 | 167 | | (24) "Profiling" means any form of automated |
---|
168 | 168 | | processing performed on personal data to evaluate, analyze, or |
---|
169 | 169 | | predict personal aspects related to an identified or identifiable |
---|
170 | 170 | | individual's economic situation, health, personal preferences, |
---|
171 | 171 | | interests, reliability, behavior, location, or movements. |
---|
172 | 172 | | (25) "Protected health information" has the meaning |
---|
173 | 173 | | assigned to the term by the Health Insurance Portability and |
---|
174 | 174 | | Accountability Act of 1996 (42 U.S.C. Section 1320d et seq.). |
---|
175 | 175 | | (26) "Pseudonymous data" means personal data that |
---|
176 | 176 | | cannot be attributed to a specific individual without the use of |
---|
177 | 177 | | additional information, provided that the additional information |
---|
178 | 178 | | is kept separately and is subject to appropriate technical and |
---|
179 | 179 | | organizational measures to ensure that the personal data is not |
---|
180 | 180 | | attributed to an identified or identifiable individual. |
---|
181 | 181 | | (27) "Publicly available information" means |
---|
182 | 182 | | information that is lawfully made available through government |
---|
183 | 183 | | records, or information that a business has a reasonable basis to |
---|
184 | 184 | | believe is lawfully made available to the general public through |
---|
185 | 185 | | widely distributed media, by a consumer, or by a person to whom a |
---|
186 | 186 | | consumer has disclosed the information, unless the consumer has |
---|
187 | 187 | | restricted the information to a specific audience. |
---|
188 | 188 | | (28) "Sale of personal data" means the sharing, |
---|
189 | 189 | | disclosing, or transferring of personal data for monetary or other |
---|
190 | 190 | | valuable consideration by the controller to a third party. The term |
---|
191 | 191 | | does not include: |
---|
192 | 192 | | (A) the disclosure of personal data to a |
---|
193 | 193 | | processor that processes the personal data on the controller's |
---|
194 | 194 | | behalf; |
---|
195 | 195 | | (B) the disclosure of personal data to a third |
---|
196 | 196 | | party for purposes of providing a product or service requested by |
---|
197 | 197 | | the consumer; |
---|
198 | 198 | | (C) the disclosure or transfer of personal data |
---|
199 | 199 | | to an affiliate of the controller; |
---|
200 | 200 | | (D) the disclosure of information that the |
---|
201 | 201 | | consumer: |
---|
202 | 202 | | (i) intentionally made available to the |
---|
203 | 203 | | general public through a mass media channel; and |
---|
204 | 204 | | (ii) did not restrict to a specific |
---|
205 | 205 | | audience; or |
---|
206 | 206 | | (E) the disclosure or transfer of personal data |
---|
207 | 207 | | to a third party as an asset that is part of a merger or acquisition. |
---|
208 | 208 | | (29) "Sensitive data" means a category of personal |
---|
209 | 209 | | data. The term includes: |
---|
210 | 210 | | (A) personal data revealing racial or ethnic |
---|
211 | 211 | | origin, religious beliefs, mental or physical health diagnosis, |
---|
212 | 212 | | sexual orientation, or citizenship or immigration status; |
---|
213 | 213 | | (B) genetic or biometric data that is processed |
---|
214 | 214 | | for the purpose of uniquely identifying an individual; |
---|
215 | 215 | | (C) personal data collected from a known child; |
---|
216 | 216 | | or |
---|
217 | 217 | | (D) precise geolocation data. |
---|
218 | 218 | | (30) "State agency" means a department, commission, |
---|
219 | 219 | | board, office, council, authority, or other agency in the executive |
---|
220 | 220 | | branch of state government that is created by the constitution or a |
---|
221 | 221 | | statute of this state, including a university system or institution |
---|
222 | 222 | | of higher education as defined by Section 61.003, Education Code. |
---|
223 | 223 | | (31) "Targeted advertising" means displaying to a |
---|
224 | 224 | | consumer an advertisement that is selected based on personal data |
---|
225 | 225 | | obtained from that consumer's activities over time and across |
---|
226 | 226 | | nonaffiliated websites or online applications to predict the |
---|
227 | 227 | | consumer's preferences or interests. The term does not include: |
---|
228 | 228 | | (A) an advertisement that: |
---|
229 | 229 | | (i) is based on activities within a |
---|
230 | 230 | | controller's own websites or online applications; |
---|
231 | 231 | | (ii) is based on the context of a consumer's |
---|
232 | 232 | | current search query, visit to a website, or online application; or |
---|
233 | 233 | | (iii) is directed to a consumer in response |
---|
234 | 234 | | to the consumer's request for information or feedback; or |
---|
235 | 235 | | (B) the processing of personal data solely for |
---|
236 | 236 | | measuring or reporting advertising performance, reach, or |
---|
237 | 237 | | frequency. |
---|
238 | 238 | | (32) "Third party" means a person, other than the |
---|
239 | 239 | | consumer, the controller, the processor, or an affiliate of the |
---|
240 | 240 | | controller or processor. |
---|
241 | 241 | | (33) "Trade secret" means all forms and types of |
---|
242 | 242 | | information, including business, scientific, technical, economic, |
---|
243 | 243 | | or engineering information, and any formula, design, prototype, |
---|
244 | 244 | | pattern, plan, compilation, program device, program, code, device, |
---|
245 | 245 | | method, technique, process, procedure, financial data, or list of |
---|
246 | 246 | | actual or potential customers or suppliers, whether tangible or |
---|
247 | 247 | | intangible and whether or how stored, compiled, or memorialized |
---|
248 | 248 | | physically, electronically, graphically, photographically, or in |
---|
249 | 249 | | writing if: |
---|
250 | 250 | | (A) the owner of the trade secret has taken |
---|
251 | 251 | | reasonable measures under the circumstances to keep the information |
---|
252 | 252 | | secret; and |
---|
253 | 253 | | (B) the information derives independent economic |
---|
254 | 254 | | value, actual or potential, from not being generally known to, and |
---|
255 | 255 | | not being readily ascertainable through proper means by, another |
---|
256 | 256 | | person who can obtain economic value from the disclosure or use of |
---|
257 | 257 | | the information. |
---|
258 | 258 | | Sec. 541.003. APPLICABILITY OF CHAPTER. (a) This chapter |
---|
259 | 259 | | applies only to a person that: |
---|
260 | 260 | | (1) conducts business in this state or produces a |
---|
261 | 261 | | product or service consumed by residents of this state; |
---|
262 | 262 | | (2) processes or engages in the sale of personal data; |
---|
263 | 263 | | and |
---|
264 | 264 | | (3) is not a small business as defined by the United |
---|
265 | 265 | | States Small Business Administration. |
---|
266 | 266 | | (b) This chapter does not apply to: |
---|
267 | 267 | | (1) a state agency or a political subdivision of this |
---|
268 | 268 | | state; |
---|
269 | 269 | | (2) a financial institution or data subject to Title |
---|
270 | 270 | | V, Gramm-Leach-Bliley Act (15 U.S.C. Section 6801 et seq.); |
---|
271 | 271 | | (3) a covered entity or business associate governed by |
---|
272 | 272 | | the privacy, security, and breach notification rules issued by the |
---|
273 | 273 | | United States Department of Health and Human Services, 45 C.F.R. |
---|
274 | 274 | | Parts 160 and 164, established under the Health Insurance |
---|
275 | 275 | | Portability and Accountability Act of 1996 (42 U.S.C. Section 1320d |
---|
276 | 276 | | et seq.), and the Health Information Technology for Economic and |
---|
277 | 277 | | Clinical Health Act (Division A, Title XIII, and Division B, Title |
---|
278 | 278 | | IV, Pub. L. No. 111-5); |
---|
279 | 279 | | (4) a nonprofit organization; or |
---|
280 | 280 | | (5) an institution of higher education. |
---|
281 | 281 | | Sec. 541.004. CERTAIN INFORMATION EXEMPT FROM CHAPTER. The |
---|
282 | 282 | | following information is exempt from this chapter: |
---|
283 | 283 | | (1) protected health information under the Health |
---|
284 | 284 | | Insurance Portability and Accountability Act of 1996 (42 U.S.C. |
---|
285 | 285 | | Section 1320d et seq.); |
---|
286 | 286 | | (2) health records; |
---|
287 | 287 | | (3) patient identifying information for purposes of 42 |
---|
288 | 288 | | U.S.C. Section 290dd-2; |
---|
289 | 289 | | (4) identifiable private information: |
---|
290 | 290 | | (A) for purposes of the federal policy for the |
---|
291 | 291 | | protection of human subjects under 45 C.F.R. Part 46; |
---|
292 | 292 | | (B) collected as part of human subjects research |
---|
293 | 293 | | in accordance with the good clinical practice guidelines issued by |
---|
294 | 294 | | The International Council for Harmonisation of Technical |
---|
295 | 295 | | Requirements for Pharmaceuticals for Human Use (ICH) or of the |
---|
296 | 296 | | protection of human subjects under 21 C.F.R. Parts 6, 50, and 56; or |
---|
297 | 297 | | (C) that is personal data used or shared in |
---|
298 | 298 | | research conducted in accordance with the requirements set forth in |
---|
299 | 299 | | this chapter or other research conducted in accordance with |
---|
300 | 300 | | applicable law; |
---|
301 | 301 | | (5) information and documents created for purposes of |
---|
302 | 302 | | the Health Care Quality Improvement Act of 1986 (42 U.S.C. Section |
---|
303 | 303 | | 11101 et seq.); |
---|
304 | 304 | | (6) patient safety work product for purposes of the |
---|
305 | 305 | | Patient Safety and Quality Improvement Act of 2005 (42 U.S.C. |
---|
306 | 306 | | Section 299b-21 et seq.); |
---|
307 | 307 | | (7) information derived from any of the health |
---|
308 | 308 | | care-related information listed in this section that is |
---|
309 | 309 | | deidentified in accordance with the requirements for |
---|
310 | 310 | | deidentification under the Health Insurance Portability and |
---|
311 | 311 | | Accountability Act of 1996 (42 U.S.C. Section 1320d et seq.); |
---|
312 | 312 | | (8) information originating from, and intermingled to |
---|
313 | 313 | | be indistinguishable with, or information treated in the same |
---|
314 | 314 | | manner as, information exempt under this section that is maintained |
---|
315 | 315 | | by a covered entity or business associate as defined by the Health |
---|
316 | 316 | | Insurance Portability and Accountability Act of 1996 (42 U.S.C. |
---|
317 | 317 | | Section 1320d et seq.) or by a program or a qualified service |
---|
318 | 318 | | organization as defined by 42 U.S.C. Section 290dd-2; |
---|
319 | 319 | | (9) information collected or used only for public |
---|
320 | 320 | | health activities and purposes as authorized by the Health |
---|
321 | 321 | | Insurance Portability and Accountability Act of 1996 (42 U.S.C. |
---|
322 | 322 | | Section 1320d et seq.); |
---|
323 | 323 | | (10) the collection, maintenance, disclosure, sale, |
---|
324 | 324 | | communication, or use of any personal information bearing on a |
---|
325 | 325 | | consumer's creditworthiness, credit standing, credit capacity, |
---|
326 | 326 | | character, general reputation, personal characteristics, or mode |
---|
327 | 327 | | of living by a consumer reporting agency or furnisher that provides |
---|
328 | 328 | | information for use in a consumer report, and by a user of a |
---|
329 | 329 | | consumer report, but only to the extent that the activity is |
---|
330 | 330 | | regulated by and authorized under the Fair Credit Reporting Act (15 |
---|
331 | 331 | | U.S.C. Section 1681 et seq.); |
---|
332 | 332 | | (11) personal data collected, processed, sold, or |
---|
333 | 333 | | disclosed in compliance with the Driver's Privacy Protection Act of |
---|
334 | 334 | | 1994 (18 U.S.C. Section 2721 et seq.); |
---|
335 | 335 | | (12) personal data regulated by the Family Educational |
---|
336 | 336 | | Rights and Privacy Act of 1974 (20 U.S.C. Section 1232g); |
---|
337 | 337 | | (13) personal data collected, processed, sold, or |
---|
338 | 338 | | disclosed in compliance with the Farm Credit Act of 1971 (12 U.S.C. |
---|
339 | 339 | | Section 2001 et seq.); |
---|
340 | 340 | | (14) data processed or maintained in the course of an |
---|
341 | 341 | | individual applying to, employed by, or acting as an agent or |
---|
342 | 342 | | independent contractor of a controller, processor, or third party, |
---|
343 | 343 | | to the extent that the data is collected and used within the context |
---|
344 | 344 | | of that role; |
---|
345 | 345 | | (15) data processed or maintained as the emergency |
---|
346 | 346 | | contact information of an individual under this chapter that is |
---|
347 | 347 | | used for emergency contact purposes; or |
---|
348 | 348 | | (16) data that is processed or maintained and is |
---|
349 | 349 | | necessary to retain to administer benefits for another individual |
---|
350 | 350 | | that relates to an individual described by Subdivision (14) and |
---|
351 | 351 | | used for the purposes of administering those benefits. |
---|
352 | 352 | | Sec. 541.005. INAPPLICABILITY OF CHAPTER. This chapter |
---|
353 | 353 | | does not apply to the processing of personal data by a person in the |
---|
354 | 354 | | course of a purely personal or household activity. |
---|
355 | 355 | | Sec. 541.006. EFFECT OF COMPLIANCE WITH PARENTAL CONSENT |
---|
356 | 356 | | REQUIREMENTS UNDER CERTAIN FEDERAL LAW. A controller or processor |
---|
357 | 357 | | that complies with the verifiable parental consent requirements of |
---|
358 | 358 | | the Children's Online Privacy Protection Act (15 U.S.C. Section |
---|
359 | 359 | | 6501 et seq.) with respect to data collected online is considered to |
---|
360 | 360 | | be in compliance with any requirement to obtain parental consent |
---|
361 | 361 | | under this chapter. |
---|
362 | 362 | | SUBCHAPTER B. CONSUMER'S RIGHTS |
---|
363 | 363 | | Sec. 541.051. CONSUMER'S PERSONAL DATA RIGHTS; REQUEST TO |
---|
364 | 364 | | EXERCISE RIGHTS. (a) A consumer is entitled to exercise the |
---|
365 | 365 | | consumer rights authorized by this section at any time by |
---|
366 | 366 | | submitting a request to a controller specifying the consumer rights |
---|
367 | 367 | | the consumer wishes to exercise. With respect to the processing of |
---|
368 | 368 | | personal data belonging to a known child, a parent or legal guardian |
---|
369 | 369 | | of the child may exercise the consumer rights on behalf of the |
---|
370 | 370 | | child. |
---|
371 | 371 | | (b) A controller shall comply with an authenticated |
---|
372 | 372 | | consumer request to exercise the right to: |
---|
373 | 373 | | (1) confirm whether a controller is processing the |
---|
374 | 374 | | consumer's personal data and to access the personal data; |
---|
375 | 375 | | (2) correct inaccuracies in the consumer's personal |
---|
376 | 376 | | data, taking into account the nature of the personal data and the |
---|
377 | 377 | | purposes of the processing of the consumer's personal data; |
---|
378 | 378 | | (3) delete personal data provided by or obtained about |
---|
379 | 379 | | the consumer; |
---|
380 | 380 | | (4) if the data is available in a digital format, |
---|
381 | 381 | | obtain a copy of the consumer's personal data that the consumer |
---|
382 | 382 | | previously provided to the controller in a portable and, to the |
---|
383 | 383 | | extent technically feasible, readily usable format that allows the |
---|
384 | 384 | | consumer to transmit the data to another controller without |
---|
385 | 385 | | hindrance; or |
---|
386 | 386 | | (5) opt out of the processing of the personal data for |
---|
387 | 387 | | purposes of: |
---|
388 | 388 | | (A) targeted advertising; |
---|
389 | 389 | | (B) the sale of personal data; or |
---|
390 | 390 | | (C) profiling in furtherance of a decision that |
---|
391 | 391 | | produces a legal or similarly significant effect concerning the |
---|
392 | 392 | | consumer. |
---|
393 | 393 | | Sec. 541.052. CONTROLLER RESPONSE TO CONSUMER REQUEST. (a) |
---|
394 | 394 | | Except as otherwise provided by this chapter, a controller shall |
---|
395 | 395 | | comply with a request submitted by a consumer to exercise the |
---|
396 | 396 | | consumer's rights pursuant to Section 541.051 as provided by this |
---|
397 | 397 | | section. |
---|
398 | 398 | | (b) A controller shall respond to the consumer request |
---|
399 | 399 | | without undue delay, which may not be later than the 45th day after |
---|
400 | 400 | | the date of receipt of the request. The controller may extend the |
---|
401 | 401 | | response period once by an additional 45 days when reasonably |
---|
402 | 402 | | necessary, taking into account the complexity and number of the |
---|
403 | 403 | | consumer's requests, so long as the controller informs the consumer |
---|
404 | 404 | | of the extension within the initial 45-day response period, |
---|
405 | 405 | | together with the reason for the extension. |
---|
406 | 406 | | (c) If a controller declines to take action regarding the |
---|
407 | 407 | | consumer's request, the controller shall inform the consumer |
---|
408 | 408 | | without undue delay, which may not be later than the 45th day after |
---|
409 | 409 | | the date of receipt of the request, of the justification for |
---|
410 | 410 | | declining to take action and provide instructions on how to appeal |
---|
411 | 411 | | the decision in accordance with Section 541.053. |
---|
412 | 412 | | (d) A controller shall provide information in response to a |
---|
413 | 413 | | consumer request free of charge, up to twice annually per consumer. |
---|
414 | 414 | | If a request from a consumer is manifestly unfounded, excessive, or |
---|
415 | 415 | | repetitive, the controller may charge the consumer a reasonable fee |
---|
416 | 416 | | to cover the administrative costs of complying with the request or |
---|
417 | 417 | | may decline to act on the request. The controller bears the burden |
---|
418 | 418 | | of demonstrating for purposes of this subsection that a request is |
---|
419 | 419 | | manifestly unfounded, excessive, or repetitive. |
---|
420 | 420 | | (e) If a controller is unable to authenticate the request |
---|
421 | 421 | | using commercially reasonable efforts, the controller is not |
---|
422 | 422 | | required to comply with a consumer request submitted under Section |
---|
423 | 423 | | 541.051 and may request that the consumer provide additional |
---|
424 | 424 | | information reasonably necessary to authenticate the consumer and |
---|
425 | 425 | | the consumer's request. |
---|
426 | 426 | | (f) A controller that has obtained personal data about a |
---|
427 | 427 | | consumer from a source other than the consumer is considered in |
---|
428 | 428 | | compliance with a consumer's request to delete that personal data |
---|
429 | 429 | | pursuant to Section 541.051(b)(3) by: |
---|
430 | 430 | | (1) retaining a record of the deletion request and the |
---|
431 | 431 | | minimum data necessary for the purpose of ensuring the consumer's |
---|
432 | 432 | | personal data remains deleted from the business's records and not |
---|
433 | 433 | | using the retained data for any other purpose under this chapter; or |
---|
434 | 434 | | (2) opting the consumer out of the processing of that |
---|
435 | 435 | | personal data for any purpose other than a purpose that is exempt |
---|
436 | 436 | | under the provisions of this chapter. |
---|
437 | 437 | | Sec. 541.053. APPEAL. (a) A controller shall establish a |
---|
438 | 438 | | process for a consumer to appeal the controller's refusal to take |
---|
439 | 439 | | action on a request within a reasonable period of time after the |
---|
440 | 440 | | consumer's receipt of the decision under Section 541.052(c). |
---|
441 | 441 | | (b) The appeal process must be conspicuously available and |
---|
442 | 442 | | similar to the process for initiating action to exercise consumer |
---|
443 | 443 | | rights by submitting a request under Section 541.051. |
---|
444 | 444 | | (c) A controller shall inform the consumer in writing of any |
---|
445 | 445 | | action taken or not taken in response to an appeal under this |
---|
446 | 446 | | section not later than the 60th day after the date of receipt of the |
---|
447 | 447 | | appeal, including a written explanation of the reason or reasons |
---|
448 | 448 | | for the decision. |
---|
449 | 449 | | (d) If the controller denies an appeal, the controller shall |
---|
450 | 450 | | provide the consumer with an online mechanism, if available, or |
---|
451 | 451 | | another method through which the consumer may contact the attorney |
---|
452 | 452 | | general to submit a complaint. |
---|
453 | 453 | | Sec. 541.054. WAIVER OR LIMITATION OF CONSUMER RIGHTS |
---|
454 | 454 | | PROHIBITED. Any provision of a contract or agreement that waives or |
---|
455 | 455 | | limits in any way a consumer right described by Sections 541.051, |
---|
456 | 456 | | 541.052, and 541.053 is contrary to public policy and is void and |
---|
457 | 457 | | unenforceable. |
---|
458 | 458 | | Sec. 541.055. METHODS FOR SUBMITTING CONSUMER REQUESTS. |
---|
459 | 459 | | (a) A controller shall establish two or more secure and reliable |
---|
460 | 460 | | methods to enable consumers to submit a request to exercise their |
---|
461 | 461 | | consumer rights under this chapter. The methods must take into |
---|
462 | 462 | | account: |
---|
463 | 463 | | (1) the ways in which consumers normally interact with |
---|
464 | 464 | | the controller; |
---|
465 | 465 | | (2) the necessity for secure and reliable |
---|
466 | 466 | | communications of those requests; and |
---|
467 | 467 | | (3) the ability of the controller to authenticate the |
---|
468 | 468 | | identity of the consumer making the request. |
---|
469 | 469 | | (b) A controller may not require a consumer to create a new |
---|
470 | 470 | | account to exercise the consumer's rights under this subchapter but |
---|
471 | 471 | | may require a consumer to use an existing account. |
---|
472 | 472 | | (c) Except as provided by Subsection (d), if the controller |
---|
473 | 473 | | maintains an Internet website, the controller must make the website |
---|
474 | 474 | | available to consumers to submit requests for information required |
---|
475 | 475 | | to be disclosed under this chapter. |
---|
476 | 476 | | (d) A controller that operates exclusively online and has a |
---|
477 | 477 | | direct relationship with a consumer from whom the controller |
---|
478 | 478 | | collects personal information is only required to provide an e-mail |
---|
479 | 479 | | address for the submission of requests described by Subsection (c). |
---|
480 | 480 | | SUBCHAPTER C. CONTROLLER AND PROCESSOR DATA-RELATED DUTIES AND |
---|
481 | 481 | | PROHIBITIONS |
---|
482 | 482 | | Sec. 541.101. CONTROLLER DUTIES; TRANSPARENCY. (a) A |
---|
483 | 483 | | controller: |
---|
484 | 484 | | (1) shall limit the collection of personal data to |
---|
485 | 485 | | what is adequate, relevant, and reasonably necessary in relation to |
---|
486 | 486 | | the purposes for which that personal data is processed, as |
---|
487 | 487 | | disclosed to the consumer; and |
---|
488 | 488 | | (2) for purposes of protecting the confidentiality, |
---|
489 | 489 | | integrity, and accessibility of personal data, shall establish, |
---|
490 | 490 | | implement, and maintain reasonable administrative, technical, and |
---|
491 | 491 | | physical data security practices that are appropriate to the volume |
---|
492 | 492 | | and nature of the personal data at issue. |
---|
493 | 493 | | (b) A controller may not: |
---|
494 | 494 | | (1) except as otherwise provided by this chapter, |
---|
495 | 495 | | process personal data for a purpose that is neither reasonably |
---|
496 | 496 | | necessary to nor compatible with the disclosed purpose for which |
---|
497 | 497 | | the personal data is processed, as disclosed to the consumer, |
---|
498 | 498 | | unless the controller obtains the consumer's consent; |
---|
499 | 499 | | (2) process personal data in violation of state and |
---|
500 | 500 | | federal laws that prohibit unlawful discrimination against |
---|
501 | 501 | | consumers; |
---|
502 | 502 | | (3) discriminate against a consumer for exercising any |
---|
503 | 503 | | of the consumer rights contained in this chapter, including by |
---|
504 | 504 | | denying goods or services, charging different prices or rates for |
---|
505 | 505 | | goods or services, or providing a different level of quality of |
---|
506 | 506 | | goods or services to the consumer; or |
---|
507 | 507 | | (4) process the sensitive data of a consumer without |
---|
508 | 508 | | obtaining the consumer's consent, or, in the case of processing the |
---|
509 | 509 | | sensitive data of a known child, without processing that data in |
---|
510 | 510 | | accordance with the Children's Online Privacy Protection Act (15 |
---|
511 | 511 | | U.S.C. Section 6501 et seq.). |
---|
512 | 512 | | (c) Subsection (b)(3) may not be construed to require a |
---|
513 | 513 | | controller to provide a product or service that requires the |
---|
514 | 514 | | personal data of a consumer that the controller does not collect or |
---|
515 | 515 | | maintain or to prohibit a controller from offering a different |
---|
516 | 516 | | price, rate, level, quality, or selection of goods or services to a |
---|
517 | 517 | | consumer, including offering goods or services for no fee, if the |
---|
518 | 518 | | consumer has exercised the consumer's right to opt out under |
---|
519 | 519 | | Section 541.051 or the offer is related to a consumer's voluntary |
---|
520 | 520 | | participation in a bona fide loyalty, rewards, premium features, |
---|
521 | 521 | | discounts, or club card program. |
---|
522 | 522 | | Sec. 541.102. PRIVACY NOTICE. A controller shall provide |
---|
523 | 523 | | consumers with a reasonably accessible and clear privacy notice |
---|
524 | 524 | | that includes: |
---|
525 | 525 | | (1) the categories of personal data processed by the |
---|
526 | 526 | | controller; |
---|
527 | 527 | | (a) if applicable, the categories must include |
---|
528 | 528 | | any sensitive data processed by the controller; |
---|
529 | 529 | | (2) the purpose for processing personal data; |
---|
530 | 530 | | (3) how consumers may exercise their consumer rights |
---|
531 | 531 | | under Subchapter B, including the process by which a consumer may |
---|
532 | 532 | | appeal a controller's decision with regard to the consumer's |
---|
533 | 533 | | request; |
---|
534 | 534 | | (4) if applicable, the categories of personal data |
---|
535 | 535 | | that the controller shares with third parties; |
---|
536 | 536 | | (5) if applicable, the categories of third parties |
---|
537 | 537 | | with whom the controller shares personal data; and |
---|
538 | 538 | | (6) a description of the methods required under |
---|
539 | 539 | | Section 541.055 through which consumers can submit requests to |
---|
540 | 540 | | exercise their consumer rights under this chapter. |
---|
541 | 541 | | Sec. 541.103. SALE OF DATA TO THIRD PARTIES AND PROCESSING |
---|
542 | 542 | | DATA FOR TARGETED ADVERTISING; DISCLOSURE. If a controller sells |
---|
543 | 543 | | personal data to third parties or processes personal data for |
---|
544 | 544 | | targeted advertising, the controller shall clearly and |
---|
545 | 545 | | conspicuously disclose such processing and the manner in which a |
---|
546 | 546 | | consumer may exercise the right to opt out of such processing. |
---|
547 | 547 | | Sec. 541.104. DUTIES OF PROCESSOR. (a) A processor shall |
---|
548 | 548 | | adhere to the instructions of a controller and shall assist the |
---|
549 | 549 | | controller in meeting or complying with the controller's duties or |
---|
550 | 550 | | requirements under this chapter, including: |
---|
551 | 551 | | (1) assisting the controller in responding to consumer |
---|
552 | 552 | | rights requests submitted under Section 541.051 by using |
---|
553 | 553 | | appropriate technical and organizational measures, as reasonably |
---|
554 | 554 | | practicable, taking into account the nature of processing and the |
---|
555 | 555 | | information available to the processor; |
---|
556 | 556 | | (2) assisting the controller with regard to complying |
---|
557 | 557 | | with the requirement relating to the security of processing |
---|
558 | 558 | | personal data and to the notification of a breach of security of the |
---|
559 | 559 | | processor's system under Chapter 521, taking into account the |
---|
560 | 560 | | nature of processing and the information available to the |
---|
561 | 561 | | processor; and |
---|
562 | 562 | | (3) providing necessary information to enable the |
---|
563 | 563 | | controller to conduct and document data protection assessments |
---|
564 | 564 | | under Section 541.105. |
---|
565 | 565 | | (b) A contract between a controller and a processor shall |
---|
566 | 566 | | govern the processor's data processing procedures with respect to |
---|
567 | 567 | | processing performed on behalf of the controller. The contract must |
---|
568 | 568 | | include: |
---|
569 | 569 | | (1) clear instructions for processing data; |
---|
570 | 570 | | (2) the nature and purpose of processing; |
---|
571 | 571 | | (3) the type of data subject to processing; |
---|
572 | 572 | | (4) the duration of processing; |
---|
573 | 573 | | (5) the rights and obligations of both parties; and |
---|
574 | 574 | | (6) a requirement that the processor shall: |
---|
575 | 575 | | (A) ensure that each person processing personal |
---|
576 | 576 | | data is subject to a duty of confidentiality with respect to the |
---|
577 | 577 | | data; |
---|
578 | 578 | | (B) at the controller's direction, delete or |
---|
579 | 579 | | return all personal data to the controller as requested after the |
---|
580 | 580 | | provision of the service is completed, unless retention of the |
---|
581 | 581 | | personal data is required by law; |
---|
582 | 582 | | (C) make available to the controller, on |
---|
583 | 583 | | reasonable request, all information in the processor's possession |
---|
584 | 584 | | necessary to demonstrate the processor's compliance with the |
---|
585 | 585 | | requirements of this chapter; |
---|
586 | 586 | | (D) allow, and cooperate with, reasonable |
---|
587 | 587 | | assessments by the controller or the controller's designated |
---|
588 | 588 | | assessor; and |
---|
589 | 589 | | (E) engage any subcontractor pursuant to a |
---|
590 | 590 | | written contract that requires the subcontractor to meet the |
---|
591 | 591 | | requirements of the processor with respect to the personal data. |
---|
592 | 592 | | (c) Notwithstanding the requirement described by Subsection |
---|
593 | 593 | | (b)(6)(D), a processor, in the alternative, may arrange for a |
---|
594 | 594 | | qualified and independent assessor to conduct an assessment of the |
---|
595 | 595 | | processor's policies and technical and organizational measures in |
---|
596 | 596 | | support of the requirements under this chapter using an appropriate |
---|
597 | 597 | | and accepted control standard or framework and assessment |
---|
598 | 598 | | procedure. The processor shall provide a report of the assessment |
---|
599 | 599 | | to the controller on request. |
---|
600 | 600 | | (d) This section may not be construed to relieve a |
---|
601 | 601 | | controller or a processor from the liabilities imposed on the |
---|
602 | 602 | | controller or processor by virtue of its role in the processing |
---|
603 | 603 | | relationship as described by this chapter. |
---|
604 | 604 | | (e) A determination of whether a person is acting as a |
---|
605 | 605 | | controller or processor with respect to a specific processing of |
---|
606 | 606 | | data is a fact-based determination that depends on the context in |
---|
607 | 607 | | which personal data is to be processed. A processor that continues |
---|
608 | 608 | | to adhere to a controller's instructions with respect to a specific |
---|
609 | 609 | | processing of personal data remains in the role of a processor. |
---|
610 | 610 | | Sec. 541.105. DATA PROTECTION ASSESSMENTS. (a) A |
---|
611 | 611 | | controller shall conduct and document a data protection assessment |
---|
612 | 612 | | of each of the following processing activities involving personal |
---|
613 | 613 | | data: |
---|
614 | 614 | | (1) the processing of personal data for purposes of |
---|
615 | 615 | | targeted advertising; |
---|
616 | 616 | | (2) the sale of personal data; |
---|
617 | 617 | | (3) the processing of personal data for purposes of |
---|
618 | 618 | | profiling, if the profiling presents a reasonably foreseeable risk |
---|
619 | 619 | | of: |
---|
620 | 620 | | (A) unfair or deceptive treatment of or unlawful |
---|
621 | 621 | | disparate impact on consumers; |
---|
622 | 622 | | (B) financial, physical, or reputational injury |
---|
623 | 623 | | to consumers; |
---|
624 | 624 | | (C) a physical or other intrusion on the solitude |
---|
625 | 625 | | or seclusion, or the private affairs or concerns, of consumers, if |
---|
626 | 626 | | the intrusion would be offensive to a reasonable person; or |
---|
627 | 627 | | (D) other substantial injury to consumers; |
---|
628 | 628 | | (4) the processing of sensitive data; and |
---|
629 | 629 | | (5) any processing activities involving personal data |
---|
630 | 630 | | that present a heightened risk of harm to consumers. |
---|
631 | 631 | | (b) A data protection assessment conducted under Subsection |
---|
632 | 632 | | (a) must: |
---|
633 | 633 | | (1) identify and weigh the direct or indirect benefits |
---|
634 | 634 | | that may flow from the processing to the controller, the consumer, |
---|
635 | 635 | | other stakeholders, and the public, against the potential risks to |
---|
636 | 636 | | the rights of the consumer associated with that processing, as |
---|
637 | 637 | | mitigated by safeguards that can be employed by the controller to |
---|
638 | 638 | | reduce the risks; and |
---|
639 | 639 | | (2) factor into the assessment: |
---|
640 | 640 | | (A) the use of deidentified data; |
---|
641 | 641 | | (B) the reasonable expectations of consumers; |
---|
642 | 642 | | (C) the context of the processing; and |
---|
643 | 643 | | (D) the relationship between the controller and |
---|
644 | 644 | | the consumer whose personal data will be processed. |
---|
645 | 645 | | (c) A controller shall make a data protection assessment |
---|
646 | 646 | | requested under Section 541.152(b) available to the attorney |
---|
647 | 647 | | general. |
---|
648 | 648 | | (d) A data protection assessment is confidential and exempt |
---|
649 | 649 | | from public inspection and copying under Chapter 552, Government |
---|
650 | 650 | | Code. Disclosure of a data protection assessment in compliance with |
---|
651 | 651 | | a request from the attorney general does not constitute a waiver of |
---|
652 | 652 | | attorney-client privilege or work product protection with respect |
---|
653 | 653 | | to the assessment and any information contained in the assessment. |
---|
654 | 654 | | (e) A single data protection assessment may address a |
---|
655 | 655 | | comparable set of processing operations that include similar |
---|
656 | 656 | | activities. |
---|
657 | 657 | | (f) A data protection assessment conducted by a controller |
---|
658 | 658 | | for the purpose of compliance with other laws or regulations may |
---|
659 | 659 | | constitute compliance with the requirements of this section if the |
---|
660 | 660 | | assessment has a reasonably comparable scope and effect. |
---|
661 | 661 | | Sec. 541.106. DEIDENTIFIED OR PSEUDONYMOUS DATA. (a) A |
---|
662 | 662 | | controller in possession of deidentified data shall: |
---|
663 | 663 | | (1) take reasonable measures to ensure that the data |
---|
664 | 664 | | cannot be associated with an individual; |
---|
665 | 665 | | (2) publicly commit to maintaining and using |
---|
666 | 666 | | deidentified data without attempting to reidentify the data; and |
---|
667 | 667 | | (3) contractually obligate any recipient of the |
---|
668 | 668 | | deidentified data to comply with the provisions of this chapter. |
---|
669 | 669 | | (b) This chapter may not be construed to require a |
---|
670 | 670 | | controller or processor to: |
---|
671 | 671 | | (1) reidentify deidentified data or pseudonymous |
---|
672 | 672 | | data; |
---|
673 | 673 | | (2) maintain data in identifiable form or obtain, |
---|
674 | 674 | | retain, or access any data or technology for the purpose of allowing |
---|
675 | 675 | | the controller or processor to associate a consumer request with |
---|
676 | 676 | | personal data; or |
---|
677 | 677 | | (3) comply with an authenticated consumer rights |
---|
678 | 678 | | request under Section 541.051, if the controller: |
---|
679 | 679 | | (A) is not reasonably capable of associating the |
---|
680 | 680 | | request with the personal data or it would be unreasonably |
---|
681 | 681 | | burdensome for the controller to associate the request with the |
---|
682 | 682 | | personal data; |
---|
683 | 683 | | (B) does not use the personal data to recognize |
---|
684 | 684 | | or respond to the specific consumer who is the subject of the |
---|
685 | 685 | | personal data or associate the personal data with other personal |
---|
686 | 686 | | data about the same specific consumer; and |
---|
687 | 687 | | (C) does not sell the personal data to any third |
---|
688 | 688 | | party or otherwise voluntarily disclose the personal data to any |
---|
689 | 689 | | third party other than a processor, except as otherwise permitted |
---|
690 | 690 | | by this section. |
---|
691 | 691 | | (c) The consumer rights under Sections 541.051(b)(1)-(4) |
---|
692 | 692 | | and controller duties under Section 541.101 do not apply to |
---|
693 | 693 | | pseudonymous data in cases in which the controller is able to |
---|
694 | 694 | | demonstrate any information necessary to identify the consumer is |
---|
695 | 695 | | kept separately and is subject to effective technical and |
---|
696 | 696 | | organizational controls that prevent the controller from accessing |
---|
697 | 697 | | the information. |
---|
698 | 698 | | (d) A controller that discloses pseudonymous data or |
---|
699 | 699 | | deidentified data shall exercise reasonable oversight to monitor |
---|
700 | 700 | | compliance with any contractual commitments to which the |
---|
701 | 701 | | pseudonymous data or deidentified data is subject and shall take |
---|
702 | 702 | | appropriate steps to address any breach of the contractual |
---|
703 | 703 | | commitments. |
---|
704 | 704 | | SUBCHAPTER D. ENFORCEMENT |
---|
705 | 705 | | Sec. 541.151. ENFORCEMENT AUTHORITY EXCLUSIVE. The |
---|
706 | 706 | | attorney general has exclusive authority to enforce this chapter. |
---|
707 | 707 | | Sec. 541.152. INVESTIGATIVE AUTHORITY. (a) If the |
---|
708 | 708 | | attorney general has reasonable cause to believe that a person has |
---|
709 | 709 | | engaged in, is engaging in, or is about to engage in a violation of |
---|
710 | 710 | | this chapter, the attorney general may issue a civil investigative |
---|
711 | 711 | | demand. The procedures established for the issuance of a civil |
---|
712 | 712 | | investigative demand under Section 15.10 apply to the same extent |
---|
713 | 713 | | and manner to the issuance of a civil investigative demand under |
---|
714 | 714 | | this section. |
---|
715 | 715 | | (b) The attorney general may request, pursuant to a civil |
---|
716 | 716 | | investigative demand issued under Subsection (a), that a controller |
---|
717 | 717 | | disclose any data protection assessment that is relevant to an |
---|
718 | 718 | | investigation conducted by the attorney general. The attorney |
---|
719 | 719 | | general may evaluate the data protection assessment for compliance |
---|
720 | 720 | | with the requirements set forth in Sections 541.101, 541.102, and |
---|
721 | 721 | | 541.103. |
---|
722 | 722 | | Sec. 541.153. NOTICE OF VIOLATION OF CHAPTER; OPPORTUNITY |
---|
723 | 723 | | TO CURE. Before bringing an action under Section 541.154, the |
---|
724 | 724 | | attorney general shall notify a person in writing, not later than |
---|
725 | 725 | | the 30th day before bringing the action, identifying the specific |
---|
726 | 726 | | provisions of this chapter the attorney general alleges have been |
---|
727 | 727 | | or are being violated. The attorney general may not bring an action |
---|
728 | 728 | | against the person if: |
---|
729 | 729 | | (1) within the 30-day period, the person cures the |
---|
730 | 730 | | identified violation; and |
---|
731 | 731 | | (2) the person provides the attorney general a written |
---|
732 | 732 | | statement that the alleged violation has been cured and that no |
---|
733 | 733 | | further violations will occur. |
---|
734 | 734 | | Sec. 541.154. CIVIL PENALTY; INJUNCTION. (a) A person who |
---|
735 | 735 | | violates this chapter following the cure period described by |
---|
736 | 736 | | Section 541.153 or who breaches a written statement provided to the |
---|
737 | 737 | | attorney general under that section is liable for a civil penalty in |
---|
738 | 738 | | an amount not to exceed $7,500 for each violation. |
---|
739 | 739 | | (b) The attorney general may bring an action in the name of |
---|
740 | 740 | | this state to: |
---|
741 | 741 | | (1) recover a civil penalty under this section; |
---|
742 | 742 | | (2) restrain or enjoin the person from violating this |
---|
743 | 743 | | chapter; or |
---|
744 | 744 | | (3) recover the civil penalty and seek injunctive |
---|
745 | 745 | | relief. |
---|
746 | 746 | | (c) The attorney general may recover reasonable attorney's |
---|
747 | 747 | | fees and other reasonable expenses incurred in investigating and |
---|
748 | 748 | | bringing an action under this section. |
---|
749 | 749 | | (d) The attorney general shall deposit a civil penalty |
---|
750 | 750 | | collected under this section in the state treasury to the credit of |
---|
751 | 751 | | the general revenue fund. |
---|
752 | 752 | | Sec. 541.155. NO PRIVATE RIGHT OF ACTION. This chapter may |
---|
753 | 753 | | not be construed to create a private right of action for a violation |
---|
754 | 754 | | of this chapter or any other chapter. |
---|
755 | 755 | | SUBCHAPTER E. CONSTRUCTION Of CHAPTER; EXEMPTIONS FOR CERTAIN USES |
---|
756 | 756 | | OF CONSUMER PERSONAL DATA |
---|
757 | 757 | | Sec. 541.201. CONSTRUCTION OF CHAPTER. (a) This chapter |
---|
758 | 758 | | may not be construed to restrict a controller's or processor's |
---|
759 | 759 | | ability to: |
---|
760 | 760 | | (1) comply with federal, state, or local laws, rules, |
---|
761 | 761 | | or regulations; |
---|
762 | 762 | | (2) comply with a civil, criminal, or regulatory |
---|
763 | 763 | | inquiry, investigation, subpoena, or summons by federal, state, |
---|
764 | 764 | | local, or other governmental authorities; |
---|
765 | 765 | | (3) investigate, establish, exercise, prepare for, or |
---|
766 | 766 | | defend legal claims; |
---|
767 | 767 | | (4) provide a product or service specifically |
---|
768 | 768 | | requested by a consumer or the parent or guardian of a child, |
---|
769 | 769 | | perform a contract to which the consumer is a party, including |
---|
770 | 770 | | fulfilling the terms of a written warranty, or take steps at the |
---|
771 | 771 | | request of the consumer before entering into a contract; |
---|
772 | 772 | | (5) take immediate steps to protect an interest that |
---|
773 | 773 | | is essential for the life or physical safety of the consumer or of |
---|
774 | 774 | | another individual and in which the processing cannot be manifestly |
---|
775 | 775 | | based on another legal basis; |
---|
776 | 776 | | (6) prevent, detect, protect against, or respond to |
---|
777 | 777 | | security incidents, identity theft, fraud, harassment, malicious |
---|
778 | 778 | | or deceptive activities, or any illegal activity; |
---|
779 | 779 | | (7) preserve the integrity or security of systems or |
---|
780 | 780 | | investigate, report, or prosecute those responsible for breaches of |
---|
781 | 781 | | system security; |
---|
782 | 782 | | (8) engage in public or peer-reviewed scientific or |
---|
783 | 783 | | statistical research in the public interest that adheres to all |
---|
784 | 784 | | other applicable ethics and privacy laws and is approved, |
---|
785 | 785 | | monitored, and governed by an institutional review board or similar |
---|
786 | 786 | | independent oversight entity that determines: |
---|
787 | 787 | | (A) if the deletion of the information is likely |
---|
788 | 788 | | to provide substantial benefits that do not exclusively accrue to |
---|
789 | 789 | | the controller; |
---|
790 | 790 | | (B) whether the expected benefits of the research |
---|
791 | 791 | | outweigh the privacy risks; and |
---|
792 | 792 | | (C) if the controller has implemented reasonable |
---|
793 | 793 | | safeguards to mitigate privacy risks associated with research, |
---|
794 | 794 | | including any risks associated with reidentification; or |
---|
795 | 795 | | (9) assist another controller, processor, or third |
---|
796 | 796 | | party with any of the requirements under this subsection. |
---|
797 | 797 | | (b) This chapter may not be construed to prevent a |
---|
798 | 798 | | controller or processor from providing personal data concerning a |
---|
799 | 799 | | consumer to a person covered by an evidentiary privilege under the |
---|
800 | 800 | | laws of this state as part of a privileged communication. |
---|
801 | 801 | | (c) This chapter may not be construed as imposing a |
---|
802 | 802 | | requirement on controllers and processors that adversely affects |
---|
803 | 803 | | the rights or freedoms of any person, including the right of free |
---|
804 | 804 | | speech. |
---|
805 | 805 | | (d) This chapter may not be construed as requiring a |
---|
806 | 806 | | controller, processor, third party, or consumer to disclose a trade |
---|
807 | 807 | | secret. |
---|
808 | 808 | | Sec. 541.202. COLLECTION, USE, OR RETENTION OF DATA FOR |
---|
809 | 809 | | CERTAIN PURPOSES. (a) The requirements imposed on controllers and |
---|
810 | 810 | | processors under this chapter may not restrict a controller's or |
---|
811 | 811 | | processor's ability to collect, use, or retain data to: |
---|
812 | 812 | | (1) conduct internal research to develop, improve, or |
---|
813 | 813 | | repair products, services, or technology; |
---|
814 | 814 | | (2) effect a product recall; |
---|
815 | 815 | | (3) identify and repair technical errors that impair |
---|
816 | 816 | | existing or intended functionality; or |
---|
817 | 817 | | (4) perform internal operations that: |
---|
818 | 818 | | (A) are reasonably aligned with the expectations |
---|
819 | 819 | | of the consumer; |
---|
820 | 820 | | (B) are reasonably anticipated based on the |
---|
821 | 821 | | consumer's existing relationship with the controller; or |
---|
822 | 822 | | (C) are otherwise compatible with processing |
---|
823 | 823 | | data in furtherance of the provision of a product or service |
---|
824 | 824 | | specifically requested by a consumer or the performance of a |
---|
825 | 825 | | contract to which the consumer is a party. |
---|
826 | 826 | | (b) A requirement imposed on a controller or processor under |
---|
827 | 827 | | this chapter does not apply if compliance with the requirement by |
---|
828 | 828 | | the controller or processor, as applicable, would violate an |
---|
829 | 829 | | evidentiary privilege under the laws of this state. |
---|
830 | 830 | | Sec. 541.203. DISCLOSURE OF PERSONAL DATA TO THIRD-PARTY |
---|
831 | 831 | | CONTROLLER OR PROCESSOR. (a) A controller or processor that |
---|
832 | 832 | | discloses personal data to a third-party controller or processor, |
---|
833 | 833 | | in compliance with the requirements of this chapter, does not |
---|
834 | 834 | | violate this chapter if the third-party controller or processor |
---|
835 | 835 | | that receives and processes that personal data is in violation of |
---|
836 | 836 | | this chapter, provided that, at the time of the data's disclosure, |
---|
837 | 837 | | the disclosing controller or processor did not have actual |
---|
838 | 838 | | knowledge that the recipient intended to commit a violation. |
---|
839 | 839 | | (b) A third-party controller or processor receiving |
---|
840 | 840 | | personal data from a controller or processor in compliance with the |
---|
841 | 841 | | requirements of this chapter does not violate this chapter for the |
---|
842 | 842 | | transgressions of the controller or processor from which the |
---|
843 | 843 | | third-party controller or processor receives the personal data. |
---|
844 | 844 | | Sec. 541.204. PROCESSING OF CERTAIN PERSONAL DATA BY |
---|
845 | 845 | | CONTROLLER OR OTHER PERSON. (a) Personal data processed by a |
---|
846 | 846 | | controller under this subchapter may not be processed for any |
---|
847 | 847 | | purpose other than a purpose listed in this subchapter unless |
---|
848 | 848 | | otherwise allowed by this chapter. Personal data processed by a |
---|
849 | 849 | | controller under this subchapter may be processed to the extent |
---|
850 | 850 | | that the processing of the data is: |
---|
851 | 851 | | (1) reasonably necessary and proportionate to the |
---|
852 | 852 | | purposes listed in this subchapter; and |
---|
853 | 853 | | (2) adequate, relevant, and limited to what is |
---|
854 | 854 | | necessary in relation to the specific purposes listed in this |
---|
855 | 855 | | subchapter. |
---|
856 | 856 | | (b) Personal data collected, used, or retained under |
---|
857 | 857 | | Section 541.202(a) must, where applicable, take into account the |
---|
858 | 858 | | nature and purpose of such collection, use, or retention. The |
---|
859 | 859 | | personal data described by this subsection is subject to reasonable |
---|
860 | 860 | | administrative, technical, and physical measures to protect the |
---|
861 | 861 | | confidentiality, integrity, and accessibility of the personal data |
---|
862 | 862 | | and to reduce reasonably foreseeable risks of harm to consumers |
---|
863 | 863 | | relating to the collection, use, or retention of personal data. |
---|
864 | 864 | | (c) A controller that processes personal data under an |
---|
865 | 865 | | exemption in this subchapter bears the burden of demonstrating that |
---|
866 | 866 | | the processing of the personal data qualifies for the exemption and |
---|
867 | 867 | | complies with the requirements of Subsections (a) and (b). |
---|
868 | 868 | | (d) The processing of personal data by an entity for the |
---|
869 | 869 | | purposes described by Section 541.201 does not solely make the |
---|
870 | 870 | | entity a controller with respect to the processing of the data. |
---|
871 | 871 | | Sec. 541.205. LOCAL PREEMPTION. This chapter supersedes |
---|
872 | 872 | | and preempts any ordinance, resolution, rule, or other regulation |
---|
873 | 873 | | adopted by a local political subdivision regarding the processing |
---|
874 | 874 | | of personal data by a controller or processor. |
---|
875 | 875 | | SECTION 2. (a) The Department of Information Resources, |
---|
876 | 876 | | under the management of the chief privacy officer, shall review the |
---|
877 | 877 | | implementation of the requirements of Chapter 541, Business & |
---|
878 | 878 | | Commerce Code, as added by this Act. |
---|
879 | 879 | | (b) Not later than March 1, 2024, the Department of |
---|
880 | 880 | | Information Resources shall create an online portal available on |
---|
881 | 881 | | the department's Internet website for members of the public to |
---|
882 | 882 | | provide feedback and recommend changes to Chapter 541, Business & |
---|
883 | 883 | | Commerce Code, as added by this Act. The online portal must remain |
---|
884 | 884 | | open for receiving feedback from the public for at least 90 days. |
---|
885 | 885 | | (c) Not later than January 1, 2025, the Department of |
---|
886 | 886 | | Information Resources shall make available to the public a report |
---|
887 | 887 | | detailing the status of the implementation of the requirements of |
---|
888 | 888 | | Chapter 541, Business & Commerce Code, as added by this Act, and any |
---|
889 | 889 | | recommendations to the legislature regarding changes to that law. |
---|
890 | 890 | | (d) This section expires September 1, 2025. |
---|
891 | 891 | | SECTION 3. The provisions of this Act are hereby declared |
---|
892 | 892 | | severable, and if any provision of this Act or the application of |
---|
893 | 893 | | such provision to any person or circumstance is declared invalid |
---|
894 | 894 | | for any reason, such declaration shall not affect the validity of |
---|
895 | 895 | | the remaining portions of this Act. |
---|
896 | 896 | | SECTION 4. This Act takes effect September 1, 2023. |
---|