American Data Privacy and Protection Act
A BILL
To provide consumers with foundational data privacy rights, create strong oversight mechanisms, and establish meaningful enforcement.
Sec. 2 Definitions
In this Act:
Affirmative express consent—
In general— The term “affirmative express consent” means an affirmative act by an individual that clearly communicates the individual’s freely given, specific, and unambiguous authorization for an act or practice after having been informed, in response to a specific request from a covered entity that meets the requirements of subparagraph (B).
Request requirements— The requirements of this subparagraph with respect to a request from a covered entity to an individual are the following:
The request is provided to the individual in a clear and conspicuous standalone disclosure made through the primary medium used to offer the covered entity’s product or service, or only if the product or service is not offered in a medium that permits the making of the request under this paragraph, another medium regularly used in conjunction with the covered entity’s product or service.
The request includes a description of the processing purpose for which the individual’s consent is sought and—
clearly states the specific categories of covered data that the covered entity shall collect, process, and transfer necessary to effectuate the processing purpose; and
includes a prominent heading and is written in easy-to-understand language that would enable a reasonable individual to identify and understand the processing purpose for which consent is sought and the covered data to be collected, processed, or transferred by the covered entity for such processing purpose.
The request clearly explains the individual’s applicable rights related to consent.
The request is made in a manner reasonably accessible to and usable by individuals with disabilities.
The request is made available to the individual in each covered language in which the covered entity provides a product or service for which authorization is sought.
The option to refuse consent shall be at least as prominent as the option to accept, and the option to refuse consent shall take the same number of steps or fewer as the option to accept.
Processing or transferring any covered data collected pursuant to affirmative express consent for a different processing purpose than that for which affirmative express consent was obtained shall require affirmative express consent for the subsequent processing purpose.
Express consent required— A covered entity may not infer that an individual has provided affirmative express consent to an act or practice from the inaction of the individual or the individual’s continued use of a service or product provided by the covered entity.
Pretextual consent prohibited— A covered entity may not obtain or attempt to obtain the affirmative express consent of an individual through—
the use of any false, fictitious, fraudulent, or materially misleading statement or representation; or
the design, modification, or manipulation of any user interface with the purpose or substantial effect of obscuring, subverting, or impairing a reasonable individual’s autonomy, decision making, or choice to provide such consent or any covered data.
Authentication— The term “authentication” means the process of verifying an individual or entity for security purposes.
Biometric information—
In general— The term “biometric information” means any covered data generated from the technological processing of an individual’s unique biological, physical, or physiological characteristics that is linked or reasonably linkable to an individual, including—
fingerprints;
voice prints;
iris or retina scans;
facial or hand mapping, geometry, or templates; or
gait or personally identifying physical movements.
Exclusion— The term “biometric information” does not include—
a digital or physical photograph;
an audio or video recording; or
data generated from a digital or physical photograph, or an audio or video recording, that cannot be used to identify an individual.
Collect; collection— The terms “collect” and “collection” mean buying, renting, gathering, obtaining, receiving, accessing, or otherwise acquiring covered data by any means.
Commission— The term “Commission” means the Federal Trade Commission.
Control— The term “control” means, with respect to an entity—
ownership of, or the power to vote, more than 50 percent of the outstanding shares of any class of voting security of the entity;
control over the election of a majority of the directors of the entity (or of individuals exercising similar functions); or
the power to exercise a controlling influence over the management of the entity.
Covered algorithm— The term “covered algorithm” means a computational process that uses machine learning, natural language processing, artificial intelligence techniques, or other computational processing techniques of similar or greater complexity and that makes a decision or facilitates human decision-making with respect to covered data, including to determine the provision of products or services or to rank, order, promote, recommend, amplify, or similarly determine the delivery or display of information to an individual.
Covered data—
In general— The term “covered data” means information that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual, and may include derived data and unique persistent identifiers.
Exclusions— The term “covered data” does not include—
de-identified data;
employee data;
publicly available information; or
inferences made exclusively from multiple independent sources of publicly available information that do not reveal sensitive covered data with respect to an individual.
Employee data defined— For purposes of subparagraph (B), the term “employee data” means—
information relating to a job applicant collected by a covered entity acting as a prospective employer of such job applicant in the course of the application, or hiring process, if such information is collected, processed, or transferred by the prospective employer solely for purposes related to the employee’s status as a current or former job applicant of such employer;
information processed by an employer relating to an employee who is acting in a professional capacity for the employer, provided that such information is collected, processed, or transferred solely for purposes related to such employee’s professional activities on behalf of the employer;
the business contact information of an employee, including the employee’s name, position or title, business telephone number, business address, or business email address that is provided to an employer by an employee who is acting in a professional capacity, if such information is collected, processed, or transferred solely for purposes related to such employee’s professional activities on behalf of the employer;
emergency contact information collected by an employer that relates to an employee of that employer, if such information is collected, processed, or transferred solely for the purpose of having an emergency contact on file for the employee and for processing or transferring such information in case of an emergency; or
information relating to an employee (or a spouse, dependent, other covered family member, or beneficiary of such employee) that is necessary for the employer to collect, process, or transfer solely for the purpose of administering benefits to which such employee (or spouse, dependent, other covered family member, or beneficiary of such employee) is entitled on the basis of the employee’s position with that employer.
Covered entity—
In general— The term “covered entity”—
means any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data and—
is subject to the Federal Trade Commission Act (15 U.S.C. 41 et seq.);
is a common carrier subject to the Communications Act of 1934 (47 U.S.C. 151 et seq.) and all Acts amendatory thereof and supplementary thereto; or
is an organization not organized to carry on business for its own profit or that of its members; and
includes any entity or person that controls, is controlled by, or is under common control with the covered entity.
Exclusions— The term “covered entity” does not include—
a Federal, State, Tribal, territorial, or local government entity such as a body, authority, board, bureau, commission, district, agency, or political subdivision of the Federal Government or a State, Tribal, territorial, or local government;
a person or an entity that is collecting, processing, or transferring covered data on behalf of a Federal, State, Tribal, territorial, or local government entity, in so far as such person or entity is acting as a service provider to the government entity; or
an entity that serves as a congressionally designated nonprofit, national resource center, and clearinghouse to provide assistance to victims, families, child-serving professionals, and the general public on missing and exploited children issues.
Non-application to service providers— An entity shall not be considered to be a covered entity for purposes of this Act in so far as the entity is acting as a service provider (as defined in paragraph (29)).
Covered language— The term “covered language” means the ten languages with the most users in the United States, according to the most recent United States Census.
Covered minor— The term “covered minor” means an individual under the age of 17.
De-identified data— The term “de-identified data” means information that does not identify and is not linked or reasonably linkable to a distinct individual or a device, regardless of whether the information is aggregated, and if the covered entity or service provider—
takes reasonable technical measures to ensure that the information cannot, at any point, be used to re-identify any individual or device that identifies or is linked or reasonably linkable to an individual;
publicly commits in a clear and conspicuous manner—
to process and transfer the information solely in a de-identified form without any reasonable means for re-identification; and
to not attempt to re-identify the information with any individual or device that identifies or is linked or reasonably linkable to an individual; and
contractually obligates any person or entity that receives the information from the covered entity or service provider—
to comply with all of the provisions of this paragraph with respect to the information; and
to require that such contractual obligations be included contractually in all subsequent instances for which the data may be received.
Derived data— The term “derived data” means covered data that is created by the derivation of information, data, assumptions, correlations, inferences, predictions, or conclusions from facts, evidence, or another source of information or data about an individual or an individual’s device.
Device— The term “device” means any electronic equipment capable of collecting, processing, or transferring covered data that is used by one or more individuals.
Employee— The term “employee” means an individual who is an employee, director, officer, staff member individual working as an independent contractor that is not a service provider, trainee, volunteer, or intern of an employer, regardless of whether such individual is paid, unpaid, or employed on a temporary basis.
Executive agency— The “Executive agency” has the meaning given such term in section 105 of title 5, United States Code.
First party advertising or marketing— The term “first party advertising or marketing” means advertising or marketing conducted by a first party either through direct communications with a user such as direct mail, email, or text message communications, or advertising or marketing conducted entirely within the first-party context, such as in a physical location operated by the first party, or on a web site or app operated by the first party.
Genetic information— The term “genetic information” means any covered data, regardless of its format, that concerns an individual’s genetic characteristics, including—
raw sequence data that results from the sequencing of the complete, or a portion of the, extracted deoxyribonucleic acid (DNA) of an individual; or
genotypic and phenotypic information that results from analyzing raw sequence data described in subparagraph (A).
Individual— The term “individual” means a natural person residing in the United States.
Knowledge—
In general— The term “knowledge” means—
with respect to a covered entity that is a covered high-impact social media company, the entity knew or should have known the individual was a covered minor;
with respect to a covered entity or service provider that is a large data holder, and otherwise is not a covered high-impact social media company, that the covered entity knew or acted in willful disregard of the fact that the individual was a covered minor; and
with respect to a covered entity or service provider that does not meet the requirements of clause (i) or (ii), actual knowledge.
Covered high-impact social media company— For purposes of this paragraph, the term “covered high-impact social media company” means a covered entity that provides any internet-accessible platform where—
such covered entity generates $3,000,000,000 or more in annual revenue;
such platform has 300,000,000 or more monthly active users for not fewer than 3 of the preceding 12 months on the online product or service of such covered entity; and
such platform constitutes an online product or service that is primarily used by users to access or share, user-generated content.
Large data holder—
In general— The term “large data holder” means a covered entity or service provider that, in the most recent calendar year—
had annual gross revenues of $250,000,000 or more; and
collected, processed, or transferred—
the covered data of more than 5,000,000 individuals or devices that identify or are linked or reasonably linkable to 1 or more individuals, excluding covered data collected and processed solely for the purpose of initiating, rendering, billing for, finalizing, completing, or otherwise collecting payment for a requested product or service; and
the sensitive covered data of more than 200,000 individuals or devices that identify or are linked or reasonably linkable to 1 or more individuals.
Exclusions— The term “large data holder” does not include any instance in which the covered entity or service provider would qualify as a large data holder solely on the basis of collecting or processing—
personal email addresses;
personal telephone numbers; or
log-in information of an individual or device to allow the individual or device to log in to an account administered by the covered entity or service provider.
Revenue— For purposes of determining whether any covered entity or service provider is a large data holder, the term “revenue”, with respect to any covered entity or service provider that is not organized to carry on business for its own profit or that of its members—
means the gross receipts the covered entity or service provider received, in whatever form, from all sources, without subtracting any costs or expenses; and
includes contributions, gifts, grants, dues or other assessments, income from investments, and proceeds from the sale of real or personal property.
Market research— The term “market research” means the collection, processing, or transfer of covered data as reasonably necessary and proportionate to investigate the market for or marketing of products, services, or ideas, where the covered data is not—
integrated into any product or service;
otherwise used to contact any individual or individual’s device; or
used to advertise or market to any individual or individual’s device.
Material— The term “material” means, with respect to an act, practice, or representation of a covered entity (including a representation made by the covered entity in a privacy policy or similar disclosure to individuals) involving the collection, processing, or transfer of covered data, that such act, practice, or representation is likely to affect a reasonable individual’s decision or conduct regarding a product or service.
Precise geolocation information—
In general— The term “precise geolocation information” means information that is derived from a device or technology that reveals the past or present physical location of an individual or device that identifies or is linked or reasonably linkable to 1 or more individuals, with sufficient precision to identify street level location information of an individual or device or the location of an individual or device within a range of 1,850 feet or less.
Exclusion— The term “precise geolocation information” does not include geolocation information identifiable or derived solely from the visual content of a legally obtained image, including the location of the device that captured such image.
Process— The term “process” means to conduct or direct any operation or set of operations performed on covered data, including analyzing, organizing, structuring, retaining, storing, using, or otherwise handling covered data.
Processing purpose— The term “processing purpose” means a reason for which a covered entity or service provider collects, processes, or transfers covered data that is specific and granular enough for a reasonable individual to understand the material facts of how and why the covered entity or service provider collects, processes, or transfers the covered data.
Publicly available information—
In general— The term “publicly available information” means any information that a covered entity or service provider has a reasonable basis to believe has been lawfully made available to the general public from—
Federal, State, or local government records, if the covered entity collects, processes, and transfers such information in accordance with any restrictions or terms of use placed on the information by the relevant government entity;
widely distributed media;
a website or online service made available to all members of the public, for free or for a fee, including where all members of the public, for free or for a fee, can log in to the website or online service;
a disclosure that has been made to the general public as required by Federal, State, or local law; or
the visual observation of the physical presence of an individual or a device in a public place, not including data collected by a device in the individual’s possession.
Clarifications; limitations—
Available to all members of the public— For purposes of this paragraph, information from a website or online service is not available to all members of the public if the individual who made the information available via the website or online service has restricted the information to a specific audience.
Other limitations— The term “publicly available information” does not include—
any obscene visual depiction (as defined in section 1460 of title 18, United States Code);
any inference made exclusively from multiple independent sources of publicly available information that reveals sensitive covered data with respect to an individual;
biometric information;
publicly available information that has been combined with covered data;
genetic information, unless otherwise made available by the individual to whom the information pertains as described in clause (ii) or (iii) of subparagraph (A); or
intimate images known to be nonconsensual.
Sensitive covered data—
In general— The term “sensitive covered data” means the following types of covered data:
A government-issued identifier, such as a Social Security number, passport number, or driver’s license number, that is not required by law to be displayed in public.
Any information that describes or reveals the past, present, or future physical health, mental health, disability, diagnosis, or healthcare condition or treatment of an individual.
A financial account number, debit card number, credit card number, or information that describes or reveals the income level or bank account balances of an individual, except that the last four digits of a debit or credit card number shall not be deemed sensitive covered data.
Biometric information.
Genetic information.
Precise geolocation information.
An individual’s private communications such as voicemails, emails, texts, direct messages, or mail, or information identifying the parties to such communications, voice communications, video communications, and any information that pertains to the transmission of such communications, including telephone numbers called, telephone numbers from which calls were placed, the time calls were made, call duration, and location information of the parties to the call, unless the covered entity or a service provider acting on behalf of the covered entity is the sender or an intended recipient of the communication. Communications are not private for purposes of this clause if such communications are made from or to a device provided by an employer to an employee insofar as such employer provides conspicuous notice that such employer may access such communications.
Account or device log-in credentials, or security or access codes for an account or device.
Information identifying the sexual behavior of an individual in a manner inconsistent with the individual’s reasonable expectation regarding the collection, processing, or transfer of such information.
Calendar information, address book information, phone or text logs, photos, audio recordings, or videos, maintained for private use by an individual, regardless of whether such information is stored on the individual’s device or is accessible from that device and is backed up in a separate location. Such information is not sensitive for purposes of this paragraph if such information is sent from or to a device provided by an employer to an employee insofar as such employer provides conspicuous notice that it may access such information.
A photograph, film, video recording, or other similar medium that shows the naked or undergarment-clad private area of an individual.
Information revealing the video content requested or selected by an individual collected by a covered entity that is not a provider of a service described in section 102(4). This clause does not include covered data used solely for transfers for independent video measurement.
Information about an individual when the covered entity or service provider has knowledge that the individual is a covered minor.
An individual’s race, color, ethnicity, religion, or union membership.
Information identifying an individual’s online activities over time and across third party websites or online services.
Any other covered data collected, processed, or transferred for the purpose of identifying the types of covered data listed in clauses (i) through (xv).
Rulemaking— The Commission may commence a rulemaking pursuant to section 553 of title 5, United States Code, to include in the definition of “sensitive covered data” any other type of covered data that may require a similar level of protection as the types of covered data listed in clauses (i) through (xvi) of subparagraph (A) as a result of any new method of collecting, processing, or transferring covered data.
Service provider—
In general— The term “service provider” means a person or entity that—
collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a Federal, State, Tribal, territorial, or local government entity; and
receives covered data from or on behalf of a covered entity or a Federal, State, Tribal, territorial, or local government entity.
Treatment with respect to service provider data— A service provider that receives service provider data from another service provider as permitted under this Act shall be treated as a service provider under this Act with respect to such data.
Service provider data— The term “service provider data” means covered data that is collected or processed by or has been transferred to a service provider by or on behalf of a covered entity, a Federal, State, Tribal, territorial, or local government entity, or another service provider for the purpose of allowing the service provider to whom such covered data is transferred to perform a service or function on behalf of, and at the direction of, such covered entity or Federal, State, Tribal, territorial, or local government entity.
State— The term “State” means any of the 50 States, the District of Columbia, the Commonwealth of Puerto Rico, the Virgin Islands of the United States, Guam, American Samoa, or the Commonwealth of the Northern Mariana Islands.
State privacy authority— The term “State privacy authority” means—
the chief consumer protection officer of a State; or
a State consumer protection agency with expertise in data protection, including the California Privacy Protection Agency.
Substantial privacy risk— The term “substantial privacy risk” means the collection, processing, or transfer of covered data in a manner that may result in any reasonably foreseeable substantial physical injury, economic injury, highly offensive intrusion into the privacy expectations of a reasonable individual under the circumstances, or discrimination on the basis of race, color, religion, national origin, sex, or disability.
Targeted advertising— The term “targeted advertising”—
means presenting to an individual or device identified by a unique identifier, or groups of individuals or devices identified by unique identifiers, an online advertisement that is selected based on known or predicted preferences, characteristics, or interests associated with the individual or a device identified by a unique identifier; and
does not include—
advertising or marketing to an individual or an individual’s device in response to the individual’s specific request for information or feedback;
contextual advertising, which is when an advertisement is displayed based on the content in which the advertisement appears and does not vary based on who is viewing the advertisement; or
processing covered data solely for measuring or reporting advertising or content, performance, reach, or frequency, including independent measurement.
Third party— The term “third party”—
means any person or entity, including a covered entity, that—
collects, processes, or transfers covered data that the person or entity did not collect directly from the individual linked or linkable to such covered data; and
is not a service provider with respect to such data; and
does not include a person or entity that collects covered data from another entity if the 2 entities are related by common ownership or corporate control, but only if a reasonable consumer’s reasonable expectation would be that such entities share information.
Third-party collecting entity—
In general— The term “third-party collecting entity”—
means a covered entity whose principal source of revenue is derived from processing or transferring covered data that the covered entity did not collect directly from the individuals linked or linkable to the covered data; and
does not include a covered entity insofar as such entity processes employee data collected by and received from a third party concerning any individual who is an employee of the third party for the sole purpose of such third party providing benefits to the employee.
Principal source of revenue defined— For purposes of this paragraph, the term “principal source of revenue” means, for the prior 12-month period, either—
more than 50 percent of all revenue of the covered entity; or
obtaining revenue from processing or transferring the covered data of more than 5,000,000 individuals that the covered entity did not collect directly from the individuals linked or linkable to the covered data.
Non-application to service providers— An entity may not be considered to be a third-party collecting entity for purposes of this Act if the entity is acting as a service provider.
Third party data— The term “third party data” means covered data that has been transferred to a third party.
Transfer— The term “transfer” means to disclose, release, disseminate, make available, license, rent, or share covered data orally, in writing, electronically, or by any other means.
Unique persistent identifier— The term “unique identifier”—
means an identifier to the extent that such identifier is reasonably linkable to an individual or device that identifies or is linked or reasonably linkable to 1 or more individuals, including a device identifier, Internet Protocol address, cookie, beacon, pixel tag, mobile ad identifier, or similar technology, customer number, unique pseudonym, user alias, telephone number, or other form of persistent or probabilistic identifier that is linked or reasonably linkable to an individual or device; and
does not include an identifier assigned by a covered entity for the specific purpose of giving effect to an individual's exercise of affirmative express consent or opt-outs of the collection, processing, and transfer of covered data pursuant to section 204 or otherwise limiting the collection, processing, or transfer of such information.
Widely distributed media— The term “widely distributed media” means information that is available to the general public, including information from a telephone book or online directory, a television, internet, or radio program, the news media, or an internet site that is available to the general public on an unrestricted basis, but does not include an obscene visual depiction (as defined in section 1460 of title 18, United States Code).