1 | 1 | | 89R4589 PRL-D |
---|
2 | 2 | | By: Hughes S.B. No. 726 |
---|
3 | 3 | | |
---|
4 | 4 | | |
---|
5 | 5 | | |
---|
6 | 6 | | |
---|
7 | 7 | | A BILL TO BE ENTITLED |
---|
8 | 8 | | AN ACT |
---|
9 | 9 | | relating to requiring operators of smart devices to provide |
---|
10 | 10 | | information to users about the collection of personal data. |
---|
11 | 11 | | BE IT ENACTED BY THE LEGISLATURE OF THE STATE OF TEXAS: |
---|
12 | 12 | | SECTION 1. Title 12, Business & Commerce Code, is amended by |
---|
13 | 13 | | adding Chapter 611 to read as follows: |
---|
14 | 14 | | CHAPTER 611. SMART DEVICE DATA COLLECTION TRANSPARENCY |
---|
15 | 15 | | Sec. 611.001. DEFINITIONS. In this chapter: |
---|
16 | 16 | | (1) "Personal data" means information relating to a |
---|
17 | 17 | | user's active or passive usage of a smart device. |
---|
18 | 18 | | (2) "Smart device" means a home appliance, consumer |
---|
19 | 19 | | electronic device, or wearable device that: |
---|
20 | 20 | | (A) connects to the Internet; |
---|
21 | 21 | | (B) collects and stores biometrics, data, |
---|
22 | 22 | | images, sound, video, or voice recordings in the course of its |
---|
23 | 23 | | operation; and |
---|
24 | 24 | | (C) has the ability to transmit data to the |
---|
25 | 25 | | device's manufacturer or retailer or to a third party, regardless |
---|
26 | 26 | | of whether this feature is enabled. |
---|
27 | 27 | | (3) "Smart device operator" means: |
---|
28 | 28 | | (A) the manufacturer of a smart device; or |
---|
29 | 29 | | (B) another person who: |
---|
30 | 30 | | (i) remotely operates, monitors, or updates |
---|
31 | 31 | | the smart device; |
---|
32 | 32 | | (ii) provides physical or digital services |
---|
33 | 33 | | to a user of a smart device; or |
---|
34 | 34 | | (iii) receives, or has the capacity to |
---|
35 | 35 | | receive, the personal data of the user of a smart device. |
---|
36 | 36 | | (4) "User" means an individual who: |
---|
37 | 37 | | (A) purchases a smart device; |
---|
38 | 38 | | (B) actively or passively uses a smart device; |
---|
39 | 39 | | (C) lives in a dwelling to which a smart device is |
---|
40 | 40 | | fixed, or where a smart device is regularly used; or |
---|
41 | 41 | | (D) wears a smart device. |
---|
42 | 42 | | Sec. 611.002. APPLICABILITY. (a) This chapter applies to a |
---|
43 | 43 | | smart device operator who: |
---|
44 | 44 | | (1) does business in this state; |
---|
45 | 45 | | (2) manufactures, sells, or operates a smart device in |
---|
46 | 46 | | this state; or |
---|
47 | 47 | | (3) processes or engages in the sale of personal data |
---|
48 | 48 | | captured by a smart device used in this state. |
---|
49 | 49 | | (b) This chapter does not apply to a state agency, a |
---|
50 | 50 | | political subdivision of this state, or a utility provider doing |
---|
51 | 51 | | business in this state. |
---|
52 | 52 | | Sec. 611.003. REQUIREMENT TO SUMMARIZE PERSONAL DATA |
---|
53 | 53 | | COLLECTION. (a) A smart device operator shall develop and offer to |
---|
54 | 54 | | users a mobile application that provides a user with information |
---|
55 | 55 | | regarding: |
---|
56 | 56 | | (1) the nature of the personal data collected by the |
---|
57 | 57 | | smart device; |
---|
58 | 58 | | (2) the purposes for which the personal data is |
---|
59 | 59 | | collected and stored; |
---|
60 | 60 | | (3) the methods by which a user's personal data is |
---|
61 | 61 | | captured, including the use of any audio, biometric, or video |
---|
62 | 62 | | recording devices; |
---|
63 | 63 | | (4) the personal data stored by the smart device |
---|
64 | 64 | | operator; |
---|
65 | 65 | | (5) whether the personal data is stored locally on the |
---|
66 | 66 | | smart device or transmitted to another location; |
---|
67 | 67 | | (6) the security and privacy policies governing the |
---|
68 | 68 | | storage of the personal data; |
---|
69 | 69 | | (7) the identity of all persons with the ability to |
---|
70 | 70 | | access the personal data; and |
---|
71 | 71 | | (8) the identity of all third parties with which a |
---|
72 | 72 | | user's personal data is shared, including whether the personal data |
---|
73 | 73 | | is anonymized before being shared with the third party. |
---|
74 | 74 | | (b) The mobile application must provide the user with |
---|
75 | 75 | | information updated at least once a month. |
---|
76 | 76 | | (c) The mobile application must allow a user to: |
---|
77 | 77 | | (1) view the information described by Subsection (a); |
---|
78 | 78 | | (2) stop the acquisition of personal data through the |
---|
79 | 79 | | smart device; and |
---|
80 | 80 | | (3) stop the use of any audio, biometric, or video |
---|
81 | 81 | | recording features on the smart device. |
---|
82 | 82 | | Sec. 611.004. USER NOTIFICATION. (a) On at least a |
---|
83 | 83 | | quarterly basis, a smart device operator shall notify each user for |
---|
84 | 84 | | which the operator has contact information of the availability of |
---|
85 | 85 | | the mobile application and the methods by which the application may |
---|
86 | 86 | | be used to customize personal data collection and sharing. |
---|
87 | 87 | | (b) The notification under Subsection (a) must: |
---|
88 | 88 | | (1) be sent to the user by text message, e-mail, or |
---|
89 | 89 | | regular mail; and |
---|
90 | 90 | | (2) be sent in a communication containing only the |
---|
91 | 91 | | notification required under Subsection (a). |
---|
92 | 92 | | SECTION 2. This Act takes effect September 1, 2025. |
---|