1 | 1 | | S.B. No. 2105 |
---|
2 | 2 | | |
---|
3 | 3 | | |
---|
4 | 4 | | AN ACT |
---|
5 | 5 | | relating to the registration of and certain other requirements |
---|
6 | 6 | | relating to data brokers; providing a civil penalty and authorizing |
---|
7 | 7 | | a fee. |
---|
8 | 8 | | BE IT ENACTED BY THE LEGISLATURE OF THE STATE OF TEXAS: |
---|
9 | 9 | | SECTION 1. Subtitle A, Title 11, Business & Commerce Code, |
---|
10 | 10 | | is amended by adding Chapter 509 to read as follows: |
---|
11 | 11 | | CHAPTER 509. DATA BROKERS |
---|
12 | 12 | | Sec. 509.001. DEFINITIONS. In this chapter: |
---|
13 | 13 | | (1) "Biometric data" means data generated by automatic |
---|
14 | 14 | | measurements of an individual's biological patterns or |
---|
15 | 15 | | characteristics, including fingerprint, voiceprint, retina or iris |
---|
16 | 16 | | scan, information pertaining to an individual's DNA, or another |
---|
17 | 17 | | unique biological pattern or characteristic that is used to |
---|
18 | 18 | | identify a specific individual. |
---|
19 | 19 | | (2) "Child" means an individual younger than 13 years |
---|
20 | 20 | | of age. |
---|
21 | 21 | | (3) "Collect," in the context of data, means to |
---|
22 | 22 | | obtain, receive, access, or otherwise acquire the data by any |
---|
23 | 23 | | means, including by purchasing or renting the data. |
---|
24 | 24 | | (4) "Data broker" means a business entity whose |
---|
25 | 25 | | principal source of revenue is derived from the collecting, |
---|
26 | 26 | | processing, or transferring of personal data that the entity did |
---|
27 | 27 | | not collect directly from the individual linked or linkable to the |
---|
28 | 28 | | data. |
---|
29 | 29 | | (5) "Deidentified data" means data that cannot |
---|
30 | 30 | | reasonably be linked to an identified or identifiable individual or |
---|
31 | 31 | | to a device linked to that individual. |
---|
32 | 32 | | (6) "Employee" includes an individual who is a |
---|
33 | 33 | | director, officer, staff member, trainee, volunteer, or intern of |
---|
34 | 34 | | an employer or an individual working as an independent contractor |
---|
35 | 35 | | for an employer, regardless of whether the individual is paid, |
---|
36 | 36 | | unpaid, or employed on a temporary basis. The term does not include |
---|
37 | 37 | | an individual contractor who is a service provider. |
---|
38 | 38 | | (7) "Employee data" means information collected, |
---|
39 | 39 | | processed, or transferred by an employer if the information: |
---|
40 | 40 | | (A) is related to: |
---|
41 | 41 | | (i) a job applicant and was collected |
---|
42 | 42 | | during the course of the hiring and application process; |
---|
43 | 43 | | (ii) an employee who is acting in a |
---|
44 | 44 | | professional capacity for the employer, including the employee's |
---|
45 | 45 | | business contact information such as the employee's name, position, |
---|
46 | 46 | | title, business telephone number, business address, or business |
---|
47 | 47 | | e-mail address; |
---|
48 | 48 | | (iii) an employee's emergency contact |
---|
49 | 49 | | information; or |
---|
50 | 50 | | (iv) an employee or the employee's spouse, |
---|
51 | 51 | | dependent, covered family member, or beneficiary; and |
---|
52 | 52 | | (B) was collected, processed, or transferred |
---|
53 | 53 | | solely for: |
---|
54 | 54 | | (i) a purpose relating to the status of a |
---|
55 | 55 | | person described by Paragraph (A)(i) as a current or former job |
---|
56 | 56 | | applicant of the employer; |
---|
57 | 57 | | (ii) a purpose relating to the professional |
---|
58 | 58 | | activities of an employee described by Paragraph (A)(ii) on behalf |
---|
59 | 59 | | of the employer; |
---|
60 | 60 | | (iii) the purpose of having an emergency |
---|
61 | 61 | | contact on file for an employee described by Paragraph (A)(iii) and |
---|
62 | 62 | | for transferring the information in case of an emergency; and |
---|
63 | 63 | | (iv) the purpose of administering benefits |
---|
64 | 64 | | to which an employee described by Paragraph (A)(iv) is entitled or |
---|
65 | 65 | | to which another person described by that paragraph is entitled on |
---|
66 | 66 | | the basis of the employee's position with the employer. |
---|
67 | 67 | | (8) "Genetic data" means any data, regardless of |
---|
68 | 68 | | format, concerning an individual's genetic characteristics. The |
---|
69 | 69 | | term includes: |
---|
70 | 70 | | (A) raw sequence data derived from sequencing all |
---|
71 | 71 | | or a portion of an individual's extracted DNA; and |
---|
72 | 72 | | (B) genotypic and phenotypic information |
---|
73 | 73 | | obtained from analyzing an individual's raw sequence data. |
---|
74 | 74 | | (9) "Individual" means a natural person residing in |
---|
75 | 75 | | this state. |
---|
76 | 76 | | (10) "Known child" means a child under circumstances |
---|
77 | 77 | | where a data broker has actual knowledge of, or wilfully disregards |
---|
78 | 78 | | obtaining actual knowledge of, the child's age. |
---|
79 | 79 | | (11) "Personal data" means any information, including |
---|
80 | 80 | | sensitive data, that is linked or reasonably linkable to an |
---|
81 | 81 | | identified or identifiable individual. The term includes |
---|
82 | 82 | | pseudonymous data when the information is used by a controller or |
---|
83 | 83 | | processor in conjunction with additional information that |
---|
84 | 84 | | reasonably links the information to an identified or identifiable |
---|
85 | 85 | | individual. The term does not include deidentified data, employee |
---|
86 | 86 | | data, or publicly available information. |
---|
87 | 87 | | (12) "Precise geolocation data" means information |
---|
88 | 88 | | accessed on a device or technology that shows the past or present |
---|
89 | 89 | | physical location of an individual or the individual's device with |
---|
90 | 90 | | sufficient precision to identify street-level location information |
---|
91 | 91 | | of the individual or device in a range of not more than 1,850 feet. |
---|
92 | 92 | | The term does not include location information regarding an |
---|
93 | 93 | | individual or device identifiable or derived solely from the visual |
---|
94 | 94 | | content of a legally obtained image, including the location of a |
---|
95 | 95 | | device that captured the image. |
---|
96 | 96 | | (13) "Process," in the context of data, means an |
---|
97 | 97 | | operation or set of operations performed, whether by manual or |
---|
98 | 98 | | automated means, on personal data or on sets of personal data, such |
---|
99 | 99 | | as the collection, use, storage, disclosure, analysis, deletion, or |
---|
100 | 100 | | modification of personal data. |
---|
101 | 101 | | (14) "Publicly available information" means |
---|
102 | 102 | | information that: |
---|
103 | 103 | | (A) is lawfully made available through |
---|
104 | 104 | | government records; |
---|
105 | 105 | | (B) a business has a reasonable basis to believe |
---|
106 | 106 | | is lawfully available to the general public through widely |
---|
107 | 107 | | distributed media; or |
---|
108 | 108 | | (C) is lawfully made available by a consumer, or |
---|
109 | 109 | | by a person to whom a consumer has disclosed the information, unless |
---|
110 | 110 | | the consumer has restricted access to the information to a specific |
---|
111 | 111 | | audience. |
---|
112 | 112 | | (15) "Sensitive data" means: |
---|
113 | 113 | | (A) a government-issued identifier not required |
---|
114 | 114 | | by law to be available publicly, including: |
---|
115 | 115 | | (i) a social security number; |
---|
116 | 116 | | (ii) a passport number; or |
---|
117 | 117 | | (iii) a driver's license number; |
---|
118 | 118 | | (B) information that describes or reveals an |
---|
119 | 119 | | individual's mental or physical health diagnosis, condition, or |
---|
120 | 120 | | treatment; |
---|
121 | 121 | | (C) an individual's financial information, |
---|
122 | 122 | | except the last four digits of a debit or credit card number, |
---|
123 | 123 | | including: |
---|
124 | 124 | | (i) a financial account number; |
---|
125 | 125 | | (ii) a credit or debit card number; or |
---|
126 | 126 | | (iii) information that describes or reveals |
---|
127 | 127 | | the income level or bank account balances of the individual; |
---|
128 | 128 | | (D) biometric data; |
---|
129 | 129 | | (E) genetic data; |
---|
130 | 130 | | (F) precise geolocation data; |
---|
131 | 131 | | (G) an individual's private communication that: |
---|
132 | 132 | | (i) if made using a device, is not made |
---|
133 | 133 | | using a device provided by the individual's employer that provides |
---|
134 | 134 | | conspicuous notice to the individual that the employer may access |
---|
135 | 135 | | communication made using the device; and |
---|
136 | 136 | | (ii) includes, unless the data broker is |
---|
137 | 137 | | the sender or an intended recipient of the communication: |
---|
138 | 138 | | (a) the individual's voicemails, |
---|
139 | 139 | | e-mails, texts, direct messages, or mail; |
---|
140 | 140 | | (b) information that identifies the |
---|
141 | 141 | | parties involved in the communications; and |
---|
142 | 142 | | (c) information that relates to the |
---|
143 | 143 | | transmission of the communications, including telephone numbers |
---|
144 | 144 | | called, telephone numbers from which calls were placed, the time |
---|
145 | 145 | | calls were made, call duration, and location information of the |
---|
146 | 146 | | parties to the call; |
---|
147 | 147 | | (H) a log-in credential, security code, or access |
---|
148 | 148 | | code for an account or device; |
---|
149 | 149 | | (I) information identifying the sexual behavior |
---|
150 | 150 | | of the individual in a manner inconsistent with the individual's |
---|
151 | 151 | | reasonable expectation regarding the collection, processing, or |
---|
152 | 152 | | transfer of the information; |
---|
153 | 153 | | (J) calendar information, address book |
---|
154 | 154 | | information, phone or text logs, photos, audio recordings, or |
---|
155 | 155 | | videos: |
---|
156 | 156 | | (i) maintained for private use by an |
---|
157 | 157 | | individual and stored on the individual's device or in another |
---|
158 | 158 | | location; and |
---|
159 | 159 | | (ii) not communicated using a device |
---|
160 | 160 | | provided by the individual's employer unless the employee was |
---|
161 | 161 | | provided conspicuous notice that the employer may access |
---|
162 | 162 | | communication made using the device; |
---|
163 | 163 | | (K) a photograph, film, video recording, or other |
---|
164 | 164 | | similar medium that shows the individual or a part of the individual |
---|
165 | 165 | | nude or wearing undergarments; |
---|
166 | 166 | | (L) information revealing the video content |
---|
167 | 167 | | requested or selected by an individual that is not: |
---|
168 | 168 | | (i) collected by a provider of broadcast |
---|
169 | 169 | | television service, cable service, satellite service, streaming |
---|
170 | 170 | | media service, or other video programming, as that term is defined |
---|
171 | 171 | | by 47 U.S.C. Section 613(h)(2); or |
---|
172 | 172 | | (ii) used solely for transfers for |
---|
173 | 173 | | independent video measurement; |
---|
174 | 174 | | (M) information regarding a known child; |
---|
175 | 175 | | (N) information revealing an individual's racial |
---|
176 | 176 | | or ethnic origin, color, religious beliefs, or union membership; |
---|
177 | 177 | | (O) information identifying an individual's |
---|
178 | 178 | | online activities over time accessing multiple Internet websites or |
---|
179 | 179 | | online services; or |
---|
180 | 180 | | (P) information collected, processed, or |
---|
181 | 181 | | transferred for the purpose of identifying information described by |
---|
182 | 182 | | this subdivision. |
---|
183 | 183 | | (16) "Service provider" means a person that receives, |
---|
184 | 184 | | collects, processes, or transfers personal data on behalf of, and |
---|
185 | 185 | | at the direction of, a business or governmental entity, including a |
---|
186 | 186 | | business or governmental entity that is another service provider, |
---|
187 | 187 | | in order for the person to perform a service or function with or on |
---|
188 | 188 | | behalf of the business or governmental entity. |
---|
189 | 189 | | (17) "Transfer," in the context of data, means to |
---|
190 | 190 | | disclose, release, share, disseminate, make available, sell, or |
---|
191 | 191 | | license the data by any means or medium. |
---|
192 | 192 | | Sec. 509.002. APPLICABILITY TO CERTAIN DATA. (a) Except as |
---|
193 | 193 | | provided by Subsection (b), this chapter applies to personal data |
---|
194 | 194 | | from an individual that is collected, transferred, or processed by |
---|
195 | 195 | | a data broker. |
---|
196 | 196 | | (b) This chapter does not apply to the following data: |
---|
197 | 197 | | (1) deidentified data, if the data broker: |
---|
198 | 198 | | (A) takes reasonable technical measures to |
---|
199 | 199 | | ensure that the data is not able to be used to identify an |
---|
200 | 200 | | individual with whom the data is associated; |
---|
201 | 201 | | (B) publicly commits in a clear and conspicuous |
---|
202 | 202 | | manner: |
---|
203 | 203 | | (i) to process and transfer the data solely |
---|
204 | 204 | | in a deidentified form without any reasonable means for |
---|
205 | 205 | | reidentification; and |
---|
206 | 206 | | (ii) to not attempt to identify the |
---|
207 | 207 | | information to an individual with whom the data is associated; and |
---|
208 | 208 | | (C) contractually obligates a person that |
---|
209 | 209 | | receives the information from the provider: |
---|
210 | 210 | | (i) to comply with this subsection with |
---|
211 | 211 | | respect to the information; and |
---|
212 | 212 | | (ii) to require that those contractual |
---|
213 | 213 | | obligations be included in any subsequent transfer of the data to |
---|
214 | 214 | | another person; |
---|
215 | 215 | | (2) employee data; |
---|
216 | 216 | | (3) publicly available information; |
---|
217 | 217 | | (4) inferences made exclusively from multiple |
---|
218 | 218 | | independent sources of publicly available information that do not |
---|
219 | 219 | | reveal sensitive data with respect to an individual; or |
---|
220 | 220 | | (5) data subject to Title V, Gramm-Leach-Bliley Act |
---|
221 | 221 | | (15 U.S.C. Section 6801 et seq.). |
---|
222 | 222 | | Sec. 509.003. APPLICABILITY OF CHAPTER TO CERTAIN ENTITIES. |
---|
223 | 223 | | (a) Except as provided by Subsection (b), this chapter applies only |
---|
224 | 224 | | to a data broker that, in a 12-month period, derives: |
---|
225 | 225 | | (1) more than 50 percent of the data broker's revenue |
---|
226 | 226 | | from processing or transferring personal data that the data broker |
---|
227 | 227 | | did not collect directly from the individuals to whom the data |
---|
228 | 228 | | pertains; or |
---|
229 | 229 | | (2) revenue from processing or transferring the |
---|
230 | 230 | | personal data of more than 50,000 individuals that the data broker |
---|
231 | 231 | | did not collect directly from the individuals to whom the data |
---|
232 | 232 | | pertains. |
---|
233 | 233 | | (b) This chapter does not apply to: |
---|
234 | 234 | | (1) a service provider, including a service provider |
---|
235 | 235 | | that engages in the business of processing employee data for a |
---|
236 | 236 | | third-party employer for the sole purpose of providing benefits to |
---|
237 | 237 | | the third-party employer's employees; |
---|
238 | 238 | | (2) a person or entity that collects personal data |
---|
239 | 239 | | from another person or entity to which the person or entity is |
---|
240 | 240 | | related by common ownership or corporate control, provided a |
---|
241 | 241 | | reasonable consumer would expect the persons or entities to share |
---|
242 | 242 | | data; |
---|
243 | 243 | | (3) a federal, state, tribal, territorial, or local |
---|
244 | 244 | | governmental entity, including a body, authority, board, bureau, |
---|
245 | 245 | | commission, district, agency, or political subdivision of a |
---|
246 | 246 | | governmental entity; |
---|
247 | 247 | | (4) an entity that serves as a congressionally |
---|
248 | 248 | | designated nonprofit, national resource center, or clearinghouse |
---|
249 | 249 | | to provide assistance to victims, families, child-serving |
---|
250 | 250 | | professionals, and the general public on missing and exploited |
---|
251 | 251 | | children issues; |
---|
252 | 252 | | (5) a consumer reporting agency or other person or |
---|
253 | 253 | | entity that furnishes information for inclusion in a consumer |
---|
254 | 254 | | credit report or obtains a consumer credit report, but only to the |
---|
255 | 255 | | extent the person or entity engages in activity regulated or |
---|
256 | 256 | | authorized by the Fair Credit Reporting Act (15 U.S.C. Section 1681 |
---|
257 | 257 | | et seq.), including the collection, maintenance, disclosure, sale, |
---|
258 | 258 | | communication, or use of any personal information bearing on a |
---|
259 | 259 | | consumer's creditworthiness, credit standing, credit capacity, |
---|
260 | 260 | | character, general reputation, personal characteristics, or mode |
---|
261 | 261 | | of living; or |
---|
262 | 262 | | (6) a financial institution subject to Title V, |
---|
263 | 263 | | Gramm-Leach-Bliley Act (15 U.S.C. Section 6801 et seq.). |
---|
264 | 264 | | Sec. 509.004. NOTICE ON WEBSITE OR MOBILE APPLICATION. A |
---|
265 | 265 | | data broker that maintains an Internet website or mobile |
---|
266 | 266 | | application shall post a conspicuous notice on the website or |
---|
267 | 267 | | application that: |
---|
268 | 268 | | (1) states that the entity maintaining the website or |
---|
269 | 269 | | application is a data broker; |
---|
270 | 270 | | (2) is clear, not misleading, and readily accessible |
---|
271 | 271 | | by the general public, including individuals with a disability; and |
---|
272 | 272 | | (3) contains language provided by rule of the |
---|
273 | 273 | | secretary of state for inclusion in the notice. |
---|
274 | 274 | | Sec. 509.005. REGISTRATION. (a) To conduct business in |
---|
275 | 275 | | this state, a data broker to which this chapter applies shall |
---|
276 | 276 | | register with the secretary of state by filing a registration |
---|
277 | 277 | | statement and paying a registration fee of $300. |
---|
278 | 278 | | (b) The registration statement must include: |
---|
279 | 279 | | (1) the legal name of the data broker; |
---|
280 | 280 | | (2) a contact person and the primary physical address, |
---|
281 | 281 | | e-mail address, telephone number, and Internet website address for |
---|
282 | 282 | | the data broker; |
---|
283 | 283 | | (3) a description of the categories of data the data |
---|
284 | 284 | | broker processes and transfers; |
---|
285 | 285 | | (4) a statement of whether or not the data broker |
---|
286 | 286 | | implements a purchaser credentialing process; |
---|
287 | 287 | | (5) if the data broker has actual knowledge that the |
---|
288 | 288 | | data broker possesses personal data of a known child: |
---|
289 | 289 | | (A) a statement detailing the data collection |
---|
290 | 290 | | practices, databases, sales activities, and opt-out policies that |
---|
291 | 291 | | are applicable to the personal data of a known child; and |
---|
292 | 292 | | (B) a statement on how the data broker complies |
---|
293 | 293 | | with applicable federal and state law regarding the collection, |
---|
294 | 294 | | use, or disclosure of personal data from and about a child on the |
---|
295 | 295 | | Internet; and |
---|
296 | 296 | | (6) the number of security breaches the data broker |
---|
297 | 297 | | has experienced during the year immediately preceding the year in |
---|
298 | 298 | | which the registration is filed, and if known, the total number of |
---|
299 | 299 | | consumers affected by each breach. |
---|
300 | 300 | | (c) A registration of a data broker may include any |
---|
301 | 301 | | additional information or explanation the data broker chooses to |
---|
302 | 302 | | provide to the secretary of state concerning the data broker's data |
---|
303 | 303 | | collection practices. |
---|
304 | 304 | | (d) A registration certificate expires on the first |
---|
305 | 305 | | anniversary of its date of issuance. A data broker may renew a |
---|
306 | 306 | | registration certificate by filing a renewal application, in the |
---|
307 | 307 | | form prescribed by the secretary of state, and paying a renewal fee |
---|
308 | 308 | | in the amount of $300. |
---|
309 | 309 | | Sec. 509.006. REGISTRY OF DATA BROKERS. (a) The secretary |
---|
310 | 310 | | of state shall establish and maintain, on its Internet website, a |
---|
311 | 311 | | searchable, central registry of data brokers registered under |
---|
312 | 312 | | Section 509.005. |
---|
313 | 313 | | (b) The registry must include: |
---|
314 | 314 | | (1) a search feature that allows a person searching |
---|
315 | 315 | | the registry to identify a specific data broker; and |
---|
316 | 316 | | (2) for each data broker, the information filed under |
---|
317 | 317 | | Section 509.005(b). |
---|
318 | 318 | | Sec. 509.007. PROTECTION OF PERSONAL DATA: COMPREHENSIVE |
---|
319 | 319 | | INFORMATION SECURITY PROGRAM. (a) A data broker conducting |
---|
320 | 320 | | business in this state has a duty to protect personal data held by |
---|
321 | 321 | | that data broker as provided by this section. |
---|
322 | 322 | | (b) A data broker shall develop, implement, and maintain a |
---|
323 | 323 | | comprehensive information security program that is written in one |
---|
324 | 324 | | or more readily accessible parts and contains administrative, |
---|
325 | 325 | | technical, and physical safeguards that are appropriate for: |
---|
326 | 326 | | (1) the data broker's size, scope, and type of |
---|
327 | 327 | | business; |
---|
328 | 328 | | (2) the amount of resources available to the data |
---|
329 | 329 | | broker; |
---|
330 | 330 | | (3) the amount of data stored by the data broker; and |
---|
331 | 331 | | (4) the need for security and confidentiality of |
---|
332 | 332 | | personal data stored by the data broker. |
---|
333 | 333 | | (c) The comprehensive information security program required |
---|
334 | 334 | | by this section must: |
---|
335 | 335 | | (1) incorporate safeguards that are consistent with |
---|
336 | 336 | | the safeguards for protection of personal data and information of a |
---|
337 | 337 | | similar character under state or federal laws and regulations |
---|
338 | 338 | | applicable to the data broker; |
---|
339 | 339 | | (2) include the designation of one or more employees |
---|
340 | 340 | | of the data broker to maintain the program; |
---|
341 | 341 | | (3) require the identification and assessment of |
---|
342 | 342 | | reasonably foreseeable internal and external risks to the security, |
---|
343 | 343 | | confidentiality, and integrity of any electronic, paper, or other |
---|
344 | 344 | | record containing personal data, and the establishment of a process |
---|
345 | 345 | | for evaluating and improving, as necessary, the effectiveness of |
---|
346 | 346 | | the current safeguards for limiting those risks, including by: |
---|
347 | 347 | | (A) requiring ongoing employee and contractor |
---|
348 | 348 | | education and training, including education and training for |
---|
349 | 349 | | temporary employees and contractors of the data broker, on the |
---|
350 | 350 | | proper use of security procedures and protocols and the importance |
---|
351 | 351 | | of personal data security; |
---|
352 | 352 | | (B) mandating employee compliance with policies |
---|
353 | 353 | | and procedures established under the program; and |
---|
354 | 354 | | (C) providing a means for detecting and |
---|
355 | 355 | | preventing security system failures; |
---|
356 | 356 | | (4) include security policies for the data broker's |
---|
357 | 357 | | employees relating to the storage, access, and transportation of |
---|
358 | 358 | | records containing personal data outside of the broker's physical |
---|
359 | 359 | | business premises; |
---|
360 | 360 | | (5) provide disciplinary measures for violations of a |
---|
361 | 361 | | policy or procedure established under the program; |
---|
362 | 362 | | (6) include measures for preventing a terminated |
---|
363 | 363 | | employee from accessing records containing personal data; |
---|
364 | 364 | | (7) provide policies for the supervision of |
---|
365 | 365 | | third-party service providers that include: |
---|
366 | 366 | | (A) taking reasonable steps to select and retain |
---|
367 | 367 | | third-party service providers that are capable of maintaining |
---|
368 | 368 | | appropriate security measures to protect personal data consistent |
---|
369 | 369 | | with applicable law; and |
---|
370 | 370 | | (B) requiring third-party service providers by |
---|
371 | 371 | | contract to implement and maintain appropriate security measures |
---|
372 | 372 | | for personal data; |
---|
373 | 373 | | (8) provide reasonable restrictions on physical |
---|
374 | 374 | | access to records containing personal data, including by requiring |
---|
375 | 375 | | the records containing the data to be stored in a locked facility, |
---|
376 | 376 | | storage area, or container; |
---|
377 | 377 | | (9) include regular monitoring to ensure that the |
---|
378 | 378 | | program is operating in a manner reasonably calculated to prevent |
---|
379 | 379 | | unauthorized access to or unauthorized use of personal data and, as |
---|
380 | 380 | | necessary, upgrading information safeguards to limit the risk of |
---|
381 | 381 | | unauthorized access to or unauthorized use of personal data; |
---|
382 | 382 | | (10) require the regular review of the scope of the |
---|
383 | 383 | | program's security measures that must occur: |
---|
384 | 384 | | (A) at least annually; and |
---|
385 | 385 | | (B) whenever there is a material change in the |
---|
386 | 386 | | data broker's business practices that may reasonably affect the |
---|
387 | 387 | | security or integrity of records containing personal data; |
---|
388 | 388 | | (11) require the documentation of responsive actions |
---|
389 | 389 | | taken in connection with any incident involving a breach of |
---|
390 | 390 | | security, including a mandatory post-incident review of each event |
---|
391 | 391 | | and the actions taken, if any, to make changes in business practices |
---|
392 | 392 | | relating to protection of personal data in response to that event; |
---|
393 | 393 | | and |
---|
394 | 394 | | (12) to the extent technically feasible, include the |
---|
395 | 395 | | following procedures and protocols with respect to computer system |
---|
396 | 396 | | security requirements or procedures and protocols providing a |
---|
397 | 397 | | higher degree of security, for the protection of personal data: |
---|
398 | 398 | | (A) the use of secure user authentication |
---|
399 | 399 | | protocols that include each of the following features: |
---|
400 | 400 | | (i) controlling user log-in credentials and |
---|
401 | 401 | | other identifiers; |
---|
402 | 402 | | (ii) using a reasonably secure method of |
---|
403 | 403 | | assigning and selecting passwords or using unique identifier |
---|
404 | 404 | | technologies, which may include biometrics or token devices; |
---|
405 | 405 | | (iii) controlling data security passwords |
---|
406 | 406 | | to ensure that the passwords are kept in a location and format that |
---|
407 | 407 | | do not compromise the security of the data the passwords protect; |
---|
408 | 408 | | (iv) restricting access to only active |
---|
409 | 409 | | users and active user accounts; and |
---|
410 | 410 | | (v) blocking access to user credentials or |
---|
411 | 411 | | identification after multiple unsuccessful attempts to gain |
---|
412 | 412 | | access; |
---|
413 | 413 | | (B) the use of secure access control measures |
---|
414 | 414 | | that include: |
---|
415 | 415 | | (i) restricting access to records and files |
---|
416 | 416 | | containing personal data to only employees or contractors who need |
---|
417 | 417 | | access to that personal data to perform the job duties of the |
---|
418 | 418 | | employees or contractors; and |
---|
419 | 419 | | (ii) assigning to each employee or |
---|
420 | 420 | | contractor with access to a computer containing personal data |
---|
421 | 421 | | unique identification and a password, which may not be a |
---|
422 | 422 | | vendor-supplied default password, or using another protocol |
---|
423 | 423 | | reasonably designed to maintain the integrity of the security of |
---|
424 | 424 | | the access controls to personal data; |
---|
425 | 425 | | (C) encryption of: |
---|
426 | 426 | | (i) transmitted records and files |
---|
427 | 427 | | containing personal data that will travel across public networks; |
---|
428 | 428 | | and |
---|
429 | 429 | | (ii) data containing personal data that is |
---|
430 | 430 | | transmitted wirelessly; |
---|
431 | 431 | | (D) reasonable monitoring of systems for |
---|
432 | 432 | | unauthorized use of or access to personal data; |
---|
433 | 433 | | (E) encryption of all personal data stored on |
---|
434 | 434 | | laptop computers or other portable devices; |
---|
435 | 435 | | (F) for files containing personal data on a |
---|
436 | 436 | | system that is connected to the Internet, the use of reasonably |
---|
437 | 437 | | current firewall protection and operating system security patches |
---|
438 | 438 | | that are reasonably designed to maintain the integrity of the |
---|
439 | 439 | | personal data; and |
---|
440 | 440 | | (G) the use of: |
---|
441 | 441 | | (i) a reasonably current version of system |
---|
442 | 442 | | security agent software that must include malware protection and |
---|
443 | 443 | | reasonably current patches and virus definitions; or |
---|
444 | 444 | | (ii) a version of system security agent |
---|
445 | 445 | | software that is supportable with current patches and virus |
---|
446 | 446 | | definitions and is set to receive the most current security updates |
---|
447 | 447 | | on a regular basis. |
---|
448 | 448 | | Sec. 509.008. CIVIL PENALTY. (a) A data broker that |
---|
449 | 449 | | violates Section 509.004 or 509.005 is liable to this state for a |
---|
450 | 450 | | civil penalty as prescribed by this section. |
---|
451 | 451 | | (b) A civil penalty imposed against a data broker under this |
---|
452 | 452 | | section: |
---|
453 | 453 | | (1) subject to Subdivision (2), may not be in an amount |
---|
454 | 454 | | less than the total of: |
---|
455 | 455 | | (A) $100 for each day the entity is in violation |
---|
456 | 456 | | of Section 509.004 or 509.005; and |
---|
457 | 457 | | (B) the amount of unpaid registration fees for |
---|
458 | 458 | | each year the entity failed to register in violation of Section |
---|
459 | 459 | | 509.005; and |
---|
460 | 460 | | (2) may not exceed $10,000 assessed against the same |
---|
461 | 461 | | data broker in a 12-month period. |
---|
462 | 462 | | (c) The attorney general may bring an action to recover a |
---|
463 | 463 | | civil penalty imposed under this section. The attorney general may |
---|
464 | 464 | | recover reasonable attorney's fees and court costs incurred in |
---|
465 | 465 | | bringing the action. |
---|
466 | 466 | | Sec. 509.009. DECEPTIVE TRADE PRACTICE. A violation of |
---|
467 | 467 | | Section 509.007 by a data broker constitutes a deceptive trade |
---|
468 | 468 | | practice in addition to the practices described by Subchapter E, |
---|
469 | 469 | | Chapter 17, and is actionable under that subchapter. |
---|
470 | 470 | | Sec. 509.010. RULES. The secretary of state shall adopt |
---|
471 | 471 | | rules as necessary to implement this chapter. |
---|
472 | 472 | | SECTION 2. Not later than December 1, 2023, the secretary of |
---|
473 | 473 | | state shall adopt rules necessary to facilitate registration by a |
---|
474 | 474 | | data broker under Section 509.005, Business & Commerce Code, as |
---|
475 | 475 | | added by this Act, including by incorporating into the rules |
---|
476 | 476 | | adequate time for a data broker to comply with Chapter 509, Business & |
---|
477 | 477 | | Commerce Code, as added by this Act, following the adoption of the |
---|
478 | 478 | | rules. |
---|
479 | 479 | | SECTION 3. Chapter 509, Business & Commerce Code, as added |
---|
480 | 480 | | by this Act, applies only to the collection, processing, or |
---|
481 | 481 | | transfer of personal data by a data broker on or after December 1, |
---|
482 | 482 | | 2023. |
---|
483 | 483 | | SECTION 4. This Act takes effect September 1, 2023. |
---|
484 | 484 | | ______________________________ ______________________________ |
---|
485 | 485 | | President of the Senate Speaker of the House |
---|
486 | 486 | | I hereby certify that S.B. No. 2105 passed the Senate on |
---|
487 | 487 | | May 3, 2023, by the following vote: Yeas 29, Nays 2. |
---|
488 | 488 | | ______________________________ |
---|
489 | 489 | | Secretary of the Senate |
---|
490 | 490 | | I hereby certify that S.B. No. 2105 passed the House on |
---|
491 | 491 | | May 24, 2023, by the following vote: Yeas 117, Nays 21, |
---|
492 | 492 | | one present not voting. |
---|
493 | 493 | | ______________________________ |
---|
494 | 494 | | Chief Clerk of the House |
---|
495 | 495 | | Approved: |
---|
496 | 496 | | ______________________________ |
---|
497 | 497 | | Date |
---|
498 | 498 | | ______________________________ |
---|
499 | 499 | | Governor |
---|