In this Act:
(1)
Affirmative express consent—
(A)
changed
In general— The term “affirmative express consent” means an affirmative act by an individual that clearly communicates the individual’s freely given, specific, informed, and unambiguous authorization for an act or practice, practice after having been informed, in response to a specific request from a covered entity that meets the requirements of subparagraph (B).
(B)
Request requirements— The requirements of this subparagraph with respect to a request from a covered entity to an individual are the following:
(i)
changed
The request is provided to the individual in a clear and conspicuous standalone disclosure made through the primary medium used to offer the covered entity’s product or service, or only if the product or service is not offered in a medium that permits the making of the request under this paragraph, another medium regularly used in conjunction with the covered entity’s product or service.
(ii)
changed
The request includes a description of the act or practice processing purpose for which the individual’s consent is sought and—
(I)
changed
clearly states the specific categories of covered data that the covered entity shall collect, process, and transfer for each act or practice;necessary to effectuate the processing purpose; and
(II)
removed
clearly distinguishes between any act or practice which is necessary to fulfill a request of the individual and any act or practice which is for another purpose; and
(II)
renumbered
was (3)(3)(4)(4)
includes a prominent heading and is written in easy-to-understand language that would enable a reasonable individual to identify and understand the processing purpose for which consent is sought and the covered data to be collected, processed, or transferred by the covered entity for such processing purpose.
(iii)
The request clearly explains the individual’s applicable rights related to consent.
(iv)
changed
The request shall be is made in a manner readily reasonably accessible to and usable by individuals with disabilities.
(v)
changed
The request shall be is made available to the public individual in each covered language in which the covered entity provides a product or service for which authorization is sought or in which the covered entity carries out any activity related to any product or service for which the covered data of the individual may be collected, processed, or transferred.sought.
(vi)
added
The option to refuse consent shall be at least as prominent as the option to accept, and the option to refuse consent shall take the same number of steps or fewer as the option to accept.
(vii)
added
Processing or transferring any covered data collected pursuant to affirmative express consent for a different processing purpose than that for which affirmative express consent was obtained shall require affirmative express consent for the subsequent processing purpose.
(C)
changed
Express consent required— A covered entity shall may not infer that an individual has provided affirmative express consent to an act or practice from the inaction of the individual or the individual’s continued use of a service or product provided by the covered entity.
(D)
changed
Pretextual consent prohibited— A covered entity shall may not obtain or attempt to obtain the affirmative express consent of an individual through—
(i)
the use of any false, fictitious, fraudulent, or materially misleading statement or representation; or
(ii)
the design, modification, or manipulation of any user interface with the purpose or substantial effect of obscuring, subverting, or impairing a reasonable individual’s autonomy, decision making, or choice to provide such consent or any covered data.
(2)
changed
Algorithm—Authentication— The term “algorithm” “authentication” means a computational process that uses machine learning, natural language processing, artificial intelligence techniques, or other computational processing techniques of similar or greater complexity that makes a decision or facilitate human decision making with respect to covered data, including to determine the provision of products or services or to rank, order, promote, recommend, amplify, or similarly determine the delivery or display process of information to verifying an individual.individual or entity for security purposes.
(3)
Biometric information—
(A)
changed
In general— The term “biometric information” means any covered data generated from the technological processing of an individual’s unique biological, physical, or physiological characteristics that is linked or reasonably linkable to an individual individual, including—
(iii)
iris or retina scans;
(iv)
changed
facial mapping or hand mapping, geometry, or templates; or
(v)
gait or personally identifying physical movements.
(B)
Exclusion— The term “biometric information” does not include—
(i)
a digital or physical photograph;
(ii)
an audio or video recording; or
(iii)
changed
data generated from a digital or physical photograph, or an audio or video recording recording, that cannot be used to identify an individual.
(4)
Collect; collection— The terms “collect” and “collection” mean buying, renting, gathering, obtaining, receiving, accessing, or otherwise acquiring covered data by any means.
(5)
Commission— The term “Commission” means the Federal Trade Commission.
(6)
removed
Common branding— The term “common branding” means a name, service mark, or trademark that is shared by 2 or more entities.
(6)
renumbered
was (9)
Control— The term “control” means, with respect to an entity—
(A)
renumbered
was (9)(3)
ownership of, or the power to vote, more than 50 percent of the outstanding shares of any class of voting security of the entity;
(B)
renumbered
was (9)(4)
control over the election of a majority of the directors of the entity (or of individuals exercising similar functions); or
(C)
renumbered
was (9)(5)
the power to exercise a controlling influence over the management of the entity.
(7)
added
Covered algorithm— The term “covered algorithm” means a computational process that uses machine learning, natural language processing, artificial intelligence techniques, or other computational processing techniques of similar or greater complexity and that makes a decision or facilitates human decision-making with respect to covered data, including to determine the provision of products or services or to rank, order, promote, recommend, amplify, or similarly determine the delivery or display of information to an individual.
(A)
changed
In general— The term “covered data” means information that identifies or is linked or reasonably linkable, alone or in combination with other information, to an individual or a device that identifies or is linked or reasonably linkable to an individual, and may include derived data and unique persistent identifiers.
(B)
Exclusions— The term “covered data” does not include—
(iii)
publicly available information; or
(iv)
inferences made exclusively from multiple independent sources of publicly available information that do not reveal sensitive covered data with respect to an individual.
(C)
Employee data defined— For purposes of subparagraph (B), the term “employee data” means—
(i)
changed
information relating to a job applicant collected by a covered entity acting as a prospective employer of such job applicant in the course of the application, or hiring process, provided that if such information is collected, processed, or transferred by the prospective employer solely for purposes related to the employee’s status as a current or former job applicant of such employer;
(ii)
changed
the business contact information of an employee, including the employee’s name, position or title, business telephone number, business address, or business email address that is provided to processed by an employer by relating to an employee who is acting in a professional capacity, capacity for the employer, provided that such information is collected, processed, or transferred solely for purposes related to such employee’s professional activities;activities on behalf of the employer;
(iii)
changed
emergency the business contact information collected by of an employer employee, including the employee’s name, position or title, business telephone number, business address, or business email address that relates is provided to an employer by an employee of that employer, provided that who is acting in a professional capacity, if such information is collected, processed, or transferred solely for the purpose of having an emergency contact purposes related to such employee’s professional activities on file for behalf of the employee; oremployer;
(iv)
added
emergency contact information collected by an employer that relates to an employee of that employer, if such information is collected, processed, or transferred solely for the purpose of having an emergency contact on file for the employee and for processing or transferring such information in case of an emergency; or
(v)
renumbered
was (10)(4)(6)
information relating to an employee (or a spouse, dependent, other covered family member, or beneficiary of such employee) that is necessary for the employer to collect, process, or transfer solely for the purpose of administering benefits to which such employee (or spouse, dependent, other covered family member, or beneficiary of such employee) is entitled on the basis of the employee’s position with that employer.
(A)
changed
In general— The term “covered entity”—
(i)
renumbered
was (11)(2)(2)
means any entity or any person, other than an individual acting in a non-commercial context, that alone or jointly with others determines the purposes and means of collecting, processing, or transferring covered data and—
(I)
renumbered
was (11)(2)(2)(2)
is subject to the Federal Trade Commission Act (15 U.S.C. 41 et seq.);
(II)
added
is a common carrier subject to the Communications Act of 1934 (47 U.S.C. 151 et seq.) and all Acts amendatory thereof and supplementary thereto; or
(III)
added
is an organization not organized to carry on business for its own profit or that of its members; and
(ii)
added
includes any entity or person that controls, is controlled by, or is under common control with the covered entity.
(II)
removed
is a common carrier subject to the Communications Act of 1934 (47 U.S.C. 151 et seq.) and all Acts amendatory thereof and supplementary thereto title II of the Communications Act of 1934 (47 U.S.C. 201–231) as currently enacted or subsequently amended; or
(III)
removed
is an organization not organized to carry on business for their own profit or that of their members; and
(ii)
removed
includes any entity or person that controls, is controlled by, or is under common control with another covered entity.
(B)
Exclusions— The term “covered entity” does not include—
(i)
changed
a governmental Federal, State, Tribal, territorial, or local government entity such as a body, authority, board, bureau, commission, district, agency, or political subdivision of the Federal, Federal Government or a State, Tribal, territorial, or local government; orgovernment;
(ii)
changed
a person or an entity that is collecting, processing, or transferring covered data on behalf of or a Federal, State, Tribal, territorial, or local government entity.entity, in so far as such person or entity is acting as a service provider to the government entity; or
(iii)
added
an entity that serves as a congressionally designated nonprofit, national resource center, and clearinghouse to provide assistance to victims, families, child-serving professionals, and the general public on missing and exploited children issues.
(C)
added
Non-application to service providers— An entity shall not be considered to be a covered entity for purposes of this Act in so far as the entity is acting as a service provider (as defined in paragraph (29)).
(10)
changed
De-identified data—Covered language— The term “de-identified data” “covered language” means information that does not identify and is not linked or reasonably linkable to an individual or an individual’s device, regardless of whether the information is aggregated, provided that ten languages with the covered entity—most users in the United States, according to the most recent United States Census.
(11)
added
Covered minor— The term “covered minor” means an individual under the age of 17.
(12)
added
De-identified data— The term “de-identified data” means information that does not identify and is not linked or reasonably linkable to a distinct individual or a device, regardless of whether the information is aggregated, and if the covered entity or service provider—
(A)
added
takes reasonable technical measures to ensure that the information cannot, at any point, be used to re-identify any individual or device that identifies or is linked or reasonably linkable to an individual;
(A)
removed
takes reasonable technical, administrative, and physical measures to ensure that the information cannot, at any point, be used to re-identify any individual or device;
(B)
renumbered
was (12)(4)
publicly commits in a clear and conspicuous manner—
(i)
renumbered
was (12)(4)(2)
to process and transfer the information solely in a de-identified form without any reasonable means for re-identification; and
(ii)
added
to not attempt to re-identify the information with any individual or device that identifies or is linked or reasonably linkable to an individual; and
(C)
added
contractually obligates any person or entity that receives the information from the covered entity or service provider—
(i)
added
to comply with all of the provisions of this paragraph with respect to the information; and
(ii)
added
to require that such contractual obligations be included contractually in all subsequent instances for which the data may be received.
(ii)
removed
to not attempt to re-identify the information with any individual or device; and
(C)
removed
contractually obligates any person or entity that receives the information from the covered entity to comply with all of the provisions of this paragraph.
(13)
renumbered
was (13)
Derived data— The term “derived data” means covered data that is created by the derivation of information, data, assumptions, correlations, inferences, predictions, or conclusions from facts, evidence, or another source of information or data about an individual or an individual’s device.
(12)
removed
Device— The term “device” means any electronic equipment capable of transmitting or receiving covered data that is designed for use by one or more individuals.
(13)
removed
Employee— The term “employee” means (regardless of whether such employee is paid, unpaid, or employed on a temporary basis) an employee, director, officer, staff member, an individual working as a contractor, trainee, volunteer, or intern of an employer.
(14)
changed
Executive agency—Device— The “Executive agency” has the meaning set forth in section 105 term “device” means any electronic equipment capable of title 5, United States Code.collecting, processing, or transferring covered data that is used by one or more individuals.
(15)
added
Employee— The term “employee” means an individual who is an employee, director, officer, staff member individual working as an independent contractor that is not a service provider, trainee, volunteer, or intern of an employer, regardless of whether such individual is paid, unpaid, or employed on a temporary basis.
(16)
added
Executive agency— The “Executive agency” has the meaning given such term in section 105 of title 5, United States Code.
(17)
added
First party advertising or marketing— The term “first party advertising or marketing” means advertising or marketing conducted by a first party either through direct communications with a user such as direct mail, email, or text message communications, or advertising or marketing conducted entirely within the first-party context, such as in a physical location operated by the first party, or on a web site or app operated by the first party.
(18)
renumbered
was (17)
Genetic information— The term “genetic information” means any covered data, regardless of its format, that concerns an individual’s genetic characteristics, including—
(A)
added
raw sequence data that results from the sequencing of the complete, or a portion of the, extracted deoxyribonucleic acid (DNA) of an individual; or
(B)
added
genotypic and phenotypic information that results from analyzing raw sequence data described in subparagraph (A).
(A)
removed
raw sequence data that results from the sequencing of an individual’s complete extracted or a portion of the extracted deoxyribonucleic acid (DNA); or
(B)
removed
genotypic and phenotypic information that results from analyzing the raw sequence data.
(19)
renumbered
was (18)
Individual— The term “individual” means a natural person residing in the United States.
(A)
added
In general— The term “knowledge” means—
(i)
added
with respect to a covered entity that is a covered high-impact social media company, the entity knew or should have known the individual was a covered minor;
(ii)
added
with respect to a covered entity or service provider that is a large data holder, and otherwise is not a covered high-impact social media company, that the covered entity knew or acted in willful disregard of the fact that the individual was a covered minor; and
(iii)
added
with respect to a covered entity or service provider that does not meet the requirements of clause (i) or (ii), actual knowledge.
(B)
added
Covered high-impact social media company— For purposes of this paragraph, the term “covered high-impact social media company” means a covered entity that provides any internet-accessible platform where—
(i)
added
such covered entity generates $3,000,000,000 or more in annual revenue;
(ii)
added
such platform has 300,000,000 or more monthly active users for not fewer than 3 of the preceding 12 months on the online product or service of such covered entity; and
(iii)
added
such platform constitutes an online product or service that is primarily used by users to access or share, user-generated content.
(21)
added
Large data holder—
(A)
added
In general— The term “large data holder” means a covered entity or service provider that, in the most recent calendar year—
(17)
removed
Large data holder— The term “large data holder” means a covered entity or service provider that, in the most recent calendar year—
(i)
renumbered
was (19)(3)
had annual gross revenues of $250,000,000 or more; and
(ii)
renumbered
was (19)(4)
collected, processed, or transferred—
(I)
added
the covered data of more than 5,000,000 individuals or devices that identify or are linked or reasonably linkable to 1 or more individuals, excluding covered data collected and processed solely for the purpose of initiating, rendering, billing for, finalizing, completing, or otherwise collecting payment for a requested product or service; and
(i)
removed
the covered data of more than 5,000,000 individuals or devices that identify or are linked or reasonably linkable to 1 or more individuals; and
(II)
renumbered
was (19)(4)(3)
the sensitive covered data of more than 200,000 individuals or devices that identify or are linked or reasonably linkable to 1 or more individuals.
(B)
added
Exclusions— The term “large data holder” does not include any instance in which the covered entity or service provider would qualify as a large data holder solely on the basis of collecting or processing—
(C)
removed
Exclusions— The term “large data holder” does not include any instance where the covered entity or service provider would qualify as a large data holder solely on account of collecting, or processing—
(i)
renumbered
was (19)(5)(3)
personal email addresses;
(ii)
renumbered
was (19)(5)(4)
personal telephone numbers; or
(iii)
renumbered
was (19)(5)(5)
log-in information of an individual or device to allow the individual or device to log in to an account administered by the covered entity or service provider.
(C)
added
Revenue— For purposes of determining whether any covered entity or service provider is a large data holder, the term “revenue”, with respect to any covered entity or service provider that is not organized to carry on business for its own profit or that of its members—
(i)
added
means the gross receipts the covered entity or service provider received, in whatever form, from all sources, without subtracting any costs or expenses; and
(ii)
added
includes contributions, gifts, grants, dues or other assessments, income from investments, and proceeds from the sale of real or personal property.
(D)
removed
Revenue— For purposes of this determining whether any covered entity or service provider is a large data holder, the term “revenue” as it relates to any covered entity or service provider that is not organized to carry on business for its own profit or that of its members, means the gross receipts the covered entity or service provider received in whatever form from all sources without subtracting any costs or expenses, and includes contributions, gifts, grants, dues or other assessments, income from investments, or proceeds from the sale of real or personal property.
(22)
renumbered
was (20)
Market research— The term “market research” means the collection, processing, or transfer of covered data as reasonably necessary and proportionate to investigate the market for or marketing of products, services, or ideas, where the covered data is not—
(A)
renumbered
was (20)(3)
integrated into any product or service;
(B)
renumbered
was (20)(4)
otherwise used to contact any individual or individual’s device; or
(C)
renumbered
was (20)(5)
used to advertise or market to any individual or individual’s device.
(23)
added
Material— The term “material” means, with respect to an act, practice, or representation of a covered entity (including a representation made by the covered entity in a privacy policy or similar disclosure to individuals) involving the collection, processing, or transfer of covered data, that such act, practice, or representation is likely to affect a reasonable individual’s decision or conduct regarding a product or service.
(24)
added
Precise geolocation information—
(A)
added
In general— The term “precise geolocation information” means information that is derived from a device or technology that reveals the past or present physical location of an individual or device that identifies or is linked or reasonably linkable to 1 or more individuals, with sufficient precision to identify street level location information of an individual or device or the location of an individual or device within a range of 1,850 feet or less.
(B)
added
Exclusion— The term “precise geolocation information” does not include geolocation information identifiable or derived solely from the visual content of a legally obtained image, including the location of the device that captured such image.
(25)
added
Process— The term “process” means to conduct or direct any operation or set of operations performed on covered data, including analyzing, organizing, structuring, retaining, storing, using, or otherwise handling covered data.
(26)
added
Processing purpose— The term “processing purpose” means a reason for which a covered entity or service provider collects, processes, or transfers covered data that is specific and granular enough for a reasonable individual to understand the material facts of how and why the covered entity or service provider collects, processes, or transfers the covered data.
(27)
added
Publicly available information—
(A)
added
In general— The term “publicly available information” means any information that a covered entity or service provider has a reasonable basis to believe has been lawfully made available to the general public from—
(i)
added
Federal, State, or local government records, if the covered entity collects, processes, and transfers such information in accordance with any restrictions or terms of use placed on the information by the relevant government entity;
(19)
removed
Material— The term “material” means with respect to an act, practice, or representation of a covered entity (including a representation made by the covered entity in a privacy policy or similar disclosure to individuals), involving the collection, processing, or transfer of covered data that such act, practice, or representation is likely to affect an individual’s decision or conduct regarding a product or service.
(20)
removed
Precise geolocation information—
(A)
removed
In general— The term “precise geolocation information” means information that reveals the past or present physical location of an individual, or device that identifies or is linked or reasonably linkable to 1 or more individuals, with sufficient precision to identify street level location information or an individual’s location within a range of 1,000 feet or less.
(B)
removed
Exclusion— The term “precise geolocation information” does not mean geolocation information identifiable solely from the visual content of an image.
(21)
removed
Process— The term “process” means to conduct or direct any operation or set of operations performed on covered data including analyzing, organizing, structuring, retaining, storing, using, or otherwise handling covered data.
(22)
removed
Processing purpose— The term “processing purpose” means a reason for which a covered entity collects, processes, or transfers covered data that is specific and granular enough for a reasonable individual to understand the material facts of how and why the covered entity collects, processes, or transfers the covered data.
(23)
removed
Publicly available information—
(A)
removed
In general— The term “publicly available information” means any information that a covered entity has a reasonable basis to believe has been lawfully made available to the general public from—
(i)
removed
Federal, State, or local government records provided that the covered entity collects, processes, and transfers such information in accordance with any restrictions or terms of use placed on the information by the relevant government entity;
(ii)
renumbered
was (25)(2)(4)
widely distributed media;
(iii)
added
a website or online service made available to all members of the public, for free or for a fee, including where all members of the public, for free or for a fee, can log in to the website or online service;
(iii)
removed
a website or online service made available to all members of the public, for free or for a fee, including where all members of the public can log-in to the website or online service;
(iv)
renumbered
was (25)(2)(6)
a disclosure that has been made to the general public as required by Federal, State, or local law; or
(v)
added
the visual observation of the physical presence of an individual or a device in a public place, not including data collected by a device in the individual’s possession.
(B)
added
Clarifications; limitations—
(v)
removed
a visual observation of an individual’s physical presence in a public place by another person, not including data collected by a device in the individual’s possession.
(B)
removed
Clarifications; limitations—
(i)
renumbered
was (25)(3)(2)
Available to all members of the public— For purposes of this paragraph, information from a website or online service is not available to all members of the public if the individual who made the information available via the website or online service has restricted the information to a specific audience.
(ii)
renumbered
was (25)(3)(3)
Other limitations— The term “publicly available information” does not include—
(I)
added
any obscene visual depiction (as defined in section 1460 of title 18, United States Code);
(II)
added
any inference made exclusively from multiple independent sources of publicly available information that reveals sensitive covered data with respect to an individual;
(I)
removed
any obscene visual depiction (as defined for purposes of section 1460 of title 18, United States Code);
(II)
removed
inferences made exclusively from multiple independent sources of publicly available information that do not reveal sensitive covered data with respect to an individual;
(III)
renumbered
was (25)(3)(3)(5)
biometric information;
(IV)
renumbered
was (25)(3)(3)(6)
publicly available information that has been combined with covered data;
(V)
added
genetic information, unless otherwise made available by the individual to whom the information pertains as described in clause (ii) or (iii) of subparagraph (A); or
(VI)
added
intimate images known to be nonconsensual.
(28)
added
Sensitive covered data—
(A)
added
In general— The term “sensitive covered data” means the following types of covered data:
(i)
added
A government-issued identifier, such as a Social Security number, passport number, or driver’s license number, that is not required by law to be displayed in public.
(V)
removed
genetic information; or
(VI)
removed
known nonconsensual intimate images.
(24)
removed
Sensitive covered data—
(A)
removed
In general— The term “sensitive covered data” means the following forms of covered data:
(i)
removed
A government-issued identifier, such as a social security number, passport number, or driver’s license number, that is not required by law to be displayed in public.
(ii)
renumbered
was (26)(2)(4)
Any information that describes or reveals the past, present, or future physical health, mental health, disability, diagnosis, or healthcare condition or treatment of an individual.
(iii)
added
A financial account number, debit card number, credit card number, or information that describes or reveals the income level or bank account balances of an individual, except that the last four digits of a debit or credit card number shall not be deemed sensitive covered data.
(iii)
removed
A financial account number, debit card number, credit card number, or information about income level or bank account balances.
(iv)
renumbered
was (26)(2)(6)
Biometric information.
(v)
renumbered
was (26)(2)(7)
Genetic information.
(vi)
renumbered
was (26)(2)(8)
Precise geolocation information.
(vii)
added
An individual’s private communications such as voicemails, emails, texts, direct messages, or mail, or information identifying the parties to such communications, voice communications, video communications, and any information that pertains to the transmission of such communications, including telephone numbers called, telephone numbers from which calls were placed, the time calls were made, call duration, and location information of the parties to the call, unless the covered entity or a service provider acting on behalf of the covered entity is the sender or an intended recipient of the communication. Communications are not private for purposes of this clause if such communications are made from or to a device provided by an employer to an employee insofar as such employer provides conspicuous notice that such employer may access such communications.
(vii)
removed
An individual’s private communications such as voicemails, emails, texts, direct messages, or mail, or information identifying the parties to such communications, voice communications, and any information that pertains to the transmission of such communications, including telephone numbers called, telephone numbers from which calls were placed, the time calls were made, call duration, and location information of the parties to the call, unless the covered entity is the sender or an intended recipient of the communication. Communications are not private for purposes of this paragraph if such communications are made from or to a device provided by an employer to an employee insofar as such employer provides conspicuous notice that it may access such communications.
(viii)
renumbered
was (26)(2)(10)
Account or device log-in credentials, or security or access codes for an account or device.
(ix)
added
Information identifying the sexual behavior of an individual in a manner inconsistent with the individual’s reasonable expectation regarding the collection, processing, or transfer of such information.
(x)
added
Calendar information, address book information, phone or text logs, photos, audio recordings, or videos, maintained for private use by an individual, regardless of whether such information is stored on the individual’s device or is accessible from that device and is backed up in a separate location. Such information is not sensitive for purposes of this paragraph if such information is sent from or to a device provided by an employer to an employee insofar as such employer provides conspicuous notice that it may access such information.
(ix)
removed
Information identifying the sexual orientation or sexual behavior of an individual in a manner inconsistent with the individual’s reasonable expectation regarding disclosure of such information.
(x)
removed
Calendar information, address book information, phone or text logs, photos, audio recordings, or videos maintained for private use by an individual, regardless of whether such information is stored on the individual’s device or in a separate location on an individual’s device, regardless of whether such information is backed up in a separate location.
(xi)
renumbered
was (26)(2)(13)
A photograph, film, video recording, or other similar medium that shows the naked or undergarment-clad private area of an individual.
(xii)
added
Information revealing the video content requested or selected by an individual collected by a covered entity that is not a provider of a service described in section 102(4). This clause does not include covered data used solely for transfers for independent video measurement.
(xiii)
added
Information about an individual when the covered entity or service provider has knowledge that the individual is a covered minor.
(xiv)
added
An individual’s race, color, ethnicity, religion, or union membership.
(xv)
added
Information identifying an individual’s online activities over time and across third party websites or online services.
(xvi)
added
Any other covered data collected, processed, or transferred for the purpose of identifying the types of covered data listed in clauses (i) through (xv).
(B)
added
Rulemaking— The Commission may commence a rulemaking pursuant to section 553 of title 5, United States Code, to include in the definition of “sensitive covered data” any other type of covered data that may require a similar level of protection as the types of covered data listed in clauses (i) through (xvi) of subparagraph (A) as a result of any new method of collecting, processing, or transferring covered data.
(29)
added
Service provider—
(A)
added
In general— The term “service provider” means a person or entity that—
(i)
added
collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity or a Federal, State, Tribal, territorial, or local government entity; and
(ii)
added
receives covered data from or on behalf of a covered entity or a Federal, State, Tribal, territorial, or local government entity.
(B)
added
Treatment with respect to service provider data— A service provider that receives service provider data from another service provider as permitted under this Act shall be treated as a service provider under this Act with respect to such data.
(30)
added
Service provider data— The term “service provider data” means covered data that is collected or processed by or has been transferred to a service provider by or on behalf of a covered entity, a Federal, State, Tribal, territorial, or local government entity, or another service provider for the purpose of allowing the service provider to whom such covered data is transferred to perform a service or function on behalf of, and at the direction of, such covered entity or Federal, State, Tribal, territorial, or local government entity.
(31)
added
State— The term “State” means any of the 50 States, the District of Columbia, the Commonwealth of Puerto Rico, the Virgin Islands of the United States, Guam, American Samoa, or the Commonwealth of the Northern Mariana Islands.
(32)
added
State privacy authority— The term “State privacy authority” means—
(xii)
removed
Information that reveals the video content or services requested or selected by an individual from a provider of broadcast television service, cable service, satellite service or streaming media service.
(xiii)
removed
Information about an individual when the covered entity knows that the individual is under the age of 17.
(xiv)
removed
Any other covered data collected, processed, or transferred for the purpose of identifying the above data types.
(B)
removed
Rulemaking— The Commission may commence a rulemaking pursuant to section 553 of title 5, United States Code, to include any additional category of covered data under this definition that may require a similar level of protection as the data listed in clauses (i) through (xvi) of subparagraph (A) as a result of any new method of collecting, processing, or transferring covered data.
(25)
removed
Service provider— The term “service provider” means a person or entity that collects, processes, or transfers covered data on behalf of, and at the direction of, a covered entity and which receives covered data from or on behalf of a covered entity pursuant to a written contract, provided that the contract meets the requirements of section 302.
(26)
removed
Service provider data— The term “service provider data” means covered data that is collected or processed by or has been transferred to a service provider by a covered entity for the purpose of allowing the service provider to perform a service or function on behalf of, and at the direction of, such covered entity.
(27)
removed
State— The term “State” means any of the 50 States, the District of Columbia, the Commonwealth of Puerto Rico, the Virgin Islands, Guam, American Samoa, the Northern Mariana Islands, or the Trust Territory of the Pacific Islands.
(28)
removed
State privacy authority—
(A)
removed
In general— The term “State Privacy Authority” means—
(A)
renumbered
was (30)(2)(3)
the chief consumer protection officer of a State; or
(B)
added
a State consumer protection agency with expertise in data protection, including the California Privacy Protection Agency.
(33)
added
Substantial privacy risk— The term “substantial privacy risk” means the collection, processing, or transfer of covered data in a manner that may result in any reasonably foreseeable substantial physical injury, economic injury, highly offensive intrusion into the privacy expectations of a reasonable individual under the circumstances, or discrimination on the basis of race, color, religion, national origin, sex, or disability.
(ii)
removed
a State consumer protection agency with expertise in data protection.
(29)
removed
Substantial privacy risk— The term “substantial privacy risk” means the collection, processing, or transfer of covered data in a manner that may result in any reasonably foreseeable material physical injury, economic injury, highly offensive intrusion into the reasonable privacy expectations of an individual under the circumstances, or discrimination on the basis of race, color, religion, national origin, sex, or disability.
(34)
renumbered
was (32)
Targeted advertising— The term “targeted advertising”—
(A)
added
means presenting to an individual or device identified by a unique identifier, or groups of individuals or devices identified by unique identifiers, an online advertisement that is selected based on known or predicted preferences, characteristics, or interests associated with the individual or a device identified by a unique identifier; and
(A)
removed
means displaying to an individual or device identified by a unique identifier an online advertisement or content that is selected based on known or predicted preferences, characteristics, or interests associated with the individual or a device identified by a unique identifier; and
(B)
renumbered
was (32)(4)
does not include—
(i)
renumbered
was (32)(4)(2)
advertising or marketing to an individual or an individual’s device in response to the individual’s specific request for information or feedback;
(ii)
added
contextual advertising, which is when an advertisement is displayed based on the content in which the advertisement appears and does not vary based on who is viewing the advertisement; or
(ii)
removed
contextual advertising, which is when an advertisement is displayed based on the content or location in which the advertisement appears and does not vary based on who is viewing the advertisement; or
(iii)
renumbered
was (32)(4)(4)
processing covered data solely for measuring or reporting advertising or content, performance, reach, or frequency, including independent measurement.
(35)
renumbered
was (33)
Third party— The term “third party”—
(A)
added
means any person or entity, including a covered entity, that—
(i)
added
collects, processes, or transfers covered data that the person or entity did not collect directly from the individual linked or linkable to such covered data; and
(A)
removed
means any person or entity that—
(i)
removed
collects, processes, or transfers third-party data; and
(ii)
renumbered
was (33)(3)(3)
is not a service provider with respect to such data; and
(B)
added
does not include a person or entity that collects covered data from another entity if the 2 entities are related by common ownership or corporate control, but only if a reasonable consumer’s reasonable expectation would be that such entities share information.
(36)
added
Third-party collecting entity—
(B)
removed
does not include a person or entity that collects covered data from another entity if the 2 entities are related by common ownership or corporate control and share common branding, unless one of those is a large data holder or those entities are each related to a large data holder through common ownership or corporate control.
(32)
removed
Third-party collecting entity—
(A)
renumbered
was (34)(2)
In general— The term “third-party collecting entity”—
(i)
added
means a covered entity whose principal source of revenue is derived from processing or transferring covered data that the covered entity did not collect directly from the individuals linked or linkable to the covered data; and
(ii)
added
does not include a covered entity insofar as such entity processes employee data collected by and received from a third party concerning any individual who is an employee of the third party for the sole purpose of such third party providing benefits to the employee.
(B)
added
Principal source of revenue defined— For purposes of this paragraph, the term “principal source of revenue” means, for the prior 12-month period, either—
(i)
removed
means a covered entity whose principal source of revenue is derived from processing or transferring the covered data that the covered entity did not collect directly from the individuals linked or linkable to the covered data; and
(ii)
removed
does not include a covered entity in so far as such entity processes employee data collected by and received from a third party concerning any individual who is an employee of the third party for the sole purpose of such third party providing benefits to the employee.
(B)
removed
Principal source of revenue defined— For purposes of this paragraph, “principal source of revenue” means, for the prior 12-month period, either—
(i)
renumbered
was (34)(3)(3)
more than 50 percent of all revenue of the covered entity; or
(ii)
added
obtaining revenue from processing or transferring the covered data of more than 5,000,000 individuals that the covered entity did not collect directly from the individuals linked or linkable to the covered data.
(C)
added
Non-application to service providers— An entity may not be considered to be a third-party collecting entity for purposes of this Act if the entity is acting as a service provider.
(37)
added
Third party data— The term “third party data” means covered data that has been transferred to a third party.
(38)
added
Transfer— The term “transfer” means to disclose, release, disseminate, make available, license, rent, or share covered data orally, in writing, electronically, or by any other means.
(39)
added
Unique persistent identifier— The term “unique identifier”—
(A)
added
means an identifier to the extent that such identifier is reasonably linkable to an individual or device that identifies or is linked or reasonably linkable to 1 or more individuals, including a device identifier, Internet Protocol address, cookie, beacon, pixel tag, mobile ad identifier, or similar technology, customer number, unique pseudonym, user alias, telephone number, or other form of persistent or probabilistic identifier that is linked or reasonably linkable to an individual or device; and
(B)
added
does not include an identifier assigned by a covered entity for the specific purpose of giving effect to an individual's exercise of affirmative express consent or opt-outs of the collection, processing, and transfer of covered data pursuant to section 204 or otherwise limiting the collection, processing, or transfer of such information.
(ii)
removed
obtaining revenue from processing or transferring the covered data of more than 5,000,000 individuals that the covered entity did not collect directly from the individuals to which the covered data pertains.
(C)
removed
Non-application to service providers— An entity shall not be considered to be a third-party collecting entity for purposes of this Act if the entity is acting as a service provider (as defined in this section).
(33)
removed
Third-party data— The term “third-party data” means covered data that has been transferred to a third party by a covered entity.
(34)
removed
Transfer— The term “transfer” means to disclose, release, share, disseminate, make available, or license in writing, electronically, or by any other means.
(35)
removed
Unique identifier— The term “unique identifier” means an identifier to the extent that such identifier is reasonably linkable to an individual or device that identifies or is linked or reasonably linkable to 1 or more individuals, including a device identifier, an Internet Protocol address, cookies, beacons, pixel tags, mobile ad identifiers, or similar technology, customer number, unique pseudonym, or user alias, telephone numbers, or other forms of persistent or probabilistic identifiers that are linked or reasonably linkable to an individual or device.
(40)
renumbered
was (38)
Widely distributed media— The term “widely distributed media” means information that is available to the general public, including information from a telephone book or online directory, a television, internet, or radio program, the news media, or an internet site that is available to the general public on an unrestricted basis, but does not include an obscene visual depiction (as defined in section 1460 of title 18, United States Code).
Sec. 101
Data minimization
(a)
changed
In general— A covered entity shall may not collect, process, or transfer covered data unless the collection, processing, or transfer is limited to what is reasonably necessary and proportionate to—
(1)
changed
provide, provide or maintain a specific product or service requested by the individual to whom the data pertains;pertains; or
(2)
changed
deliver effect a communication that is reasonably anticipated by the individual recipient within the context of the individual’s interactions with the covered entity; orpurpose permitted under subsection (b).
(3)
removed
effect a purpose expressly permitted under subsection (b).
(b)
changed
Permissible purposes— A covered entity or service provider may collect, process, or transfer covered data for any of the following purposes provided that if the covered entity or service provider can demonstrate that collection, processing, or transfer complies with all other applicable laws not preempted in section 404 and provisions of this Act and is limited to what is reasonably necessary and proportionate to such purpose:
(1)
changed
To initiate initiate, manage, or complete a transaction or fulfill an order for specific products or service specifically services requested by an individual, including any associated routine administrative administrative, operational, and account-servicing activity such as billing, shipping, delivery, storage, and accounting, including the collection, processing, or transferring of the last four digits of a credit card number.accounting.
(2)
changed
With respect to covered data previously collected in accordance with this Act, notwithstanding this exception, to process such data as necessary to perform system maintenance or diagnostics, to maintain a product or service for which such data was collected, to conduct internal research or analytics, to improve a product or service for which such data was collected and to perform inventory management or reasonable network management, to protect against spam, or to debug or repair errors that impair the functionality of a service or product for which such data was collected.exception—
(A)
added
to process such data as necessary to perform system maintenance or diagnostics;
(B)
added
to develop, maintain, repair, or enhance a product or service for which such data was collected;
(C)
added
to conduct internal research or analytics to improve a product or service for which such data was collected;
(D)
added
to perform inventory management or reasonable network management;
(E)
added
to protect against spam; or
(F)
added
to debug or repair errors that impair the functionality of a service or product for which such data was collected.
(3)
To authenticate users of a product or service.
(4)
changed
To prevent, detect, protect against, or respond to a security incident, or fulfill a product or service warranty. For purposes of this paragraph, security is defined as network security as well as intrusion, medical alerts, fire alarms, and access control security.warranty.
(5)
changed
To prevent, detect, protect against against, or respond to fraud, harassment, or illegal activity. a security incident. For the purposes of this paragraph, illegal activity means a violation of a Federal, State, or local law punishable security is defined as a felony network security and physical security and life safety, including an intrusion or misdemeanor that can directly harm another person.trespass, medical alerts, fire alarms, and access control security.
(6)
changed
To comply with prevent, detect, protect against, or respond to fraud, harassment, or illegal activity. For purposes of this paragraph, the term “illegal activity” means a legal obligation imposed by violation of a Federal, Tribal, Local, or State law, State, or to establish, exercise, local law punishable as a felony or defend legal claims.misdemeanor that can directly harm.
(7)
changed
To prevent an individual, comply with a legal obligation imposed by Federal, Tribal, local, or groups of individuals, from suffering harm where State law, or to investigate, establish, prepare for, exercise, or defend legal claims involving the covered entity or service provider believes in good faith that the individual, or groups of individuals, is at risk of death, serious physical injury, or other serious health risk.provider.
(8)
added
To prevent an individual, or group of individuals, from suffering harm where the covered entity or service provider believes in good faith that the individual, or group of individuals, is at risk of death, serious physical injury, or other serious health risk.
(9)
renumbered
was (3)(10)
To effectuate a product recall pursuant to Federal or State law.
(A)
renumbered
was (3)(11)(1)
To conduct a public or peer-reviewed scientific, historical, or statistical research project that—
(i)
added
is in the public interest; and
(ii)
added
adheres to all relevant laws and regulations governing such research, including regulations for the protection of human subjects, or is excluded from criteria of the institutional review board.
(B)
added
Not later than 18 months after the date of enactment of this Act, the Commission should issue guidelines to help covered entities ensure the privacy of affected users and the security of covered data, particularly as data is being transferred to and stored by researchers. Such guidelines should consider risks as they pertain to projects using covered data with special considerations for projects that are exempt under part 46 of title 45, Code of Federal Regulations (or any successor regulation) or are excluded from the criteria for institutional review board review.
(i)
removed
is in the public interest;
(ii)
removed
adheres to all relevant laws governing such research; and
(iii)
removed
adheres to the regulations for human subject research established under part 46 of title 45, Code of Federal Regulations (or a successor regulations).
(B)
removed
The Commission should set forth within 18 months of the enactment of this Act guidelines to help covered entities ensure the privacy of affected users and the security of covered data, particularly as data is being transferred to and stored by researchers.
(10)
removed
To deliver a communication at the direction of an individual between the communicating individual and one or more individuals or entities.
(11)
changed
With respect to covered data previously collected in accordance with this Act, notwithstanding this exception, to process such data as necessary To deliver a communication that is not an advertisement to provide first party marketing or advertising of products or services provided an individual, if the communication is reasonably anticipated by the individual within the context of the individual’s interactions with the covered entity.
(12)
changed
Otherwise complies with To deliver a communication at the requirements direction of this Act, including section 204(c), to provide a targeted advertisement.an individual between such individual and one or more individuals or entities.
(13)
added
To transfer assets to a third party in the context of a merger, acquisition, bankruptcy, or similar transaction when the third party assumes control, in whole or in part, of the covered entity’s assets, only if the covered entity, in a reasonable time prior to such transfer, provides each affected individual with—
(A)
added
a notice describing such transfer, including the name of the entity or entities receiving the individual’s covered data and their privacy policies as described in section 202; and
(B)
added
a reasonable opportunity to withdraw any previously given consents in accordance with the requirements of affirmative express consent under this Act related to the individual’s covered data and a reasonable opportunity to request the deletion of the individual’s covered data, as described in section 203.
(14)
added
To ensure the data security and integrity of covered data, as described in section 208.
(15)
added
With respect to covered data previously collected in accordance with this Act, a service provider acting at the direction of a government entity, or a service provided to a government entity by a covered entity, and only insofar as authorized by statute, to prevent, detect, protect against or respond to a public safety incident, including trespass, natural disaster, or national security incident. This paragraph does not permit, however, the transfer of covered data for payment or other valuable consideration to a government entity.
(16)
added
With respect to covered data collected in accordance with this Act, notwithstanding this exception, to process such data as necessary to provide first party advertising or marketing of products or services provided by the covered entity for individuals who are not-covered minors.
(17)
added
With respect to covered data previously collected in accordance with this Act, notwithstanding this exception and provided such collection, processing, and transferring otherwise complies with the requirements of this Act, including section 204(c), to provide targeted advertising.
(c)
Guidance— The Commission shall issue guidance regarding what is reasonably necessary and proportionate to comply with this section. Such guidance shall take into consideration—
(1)
changed
the size of, and the nature, scope, and complexity of the activities engaged in by by, the covered entity, including whether the covered entity is a large data holder, nonprofit organization, covered entities entity meeting the requirements of section 209, service provider, third party, or third-party collecting entity;
(2)
the sensitivity of covered data collected, processed, or transferred by the covered entity;
(3)
the volume of covered data collected, processed, or transferred by the covered entity; and
(4)
the number of individuals and devices to which the covered data collected, processed, or transferred by the covered entity relates.
(d)
changed
Deceptive marketing of a product or service— A covered entity, service provider, entity or third party is prohibited from engaging service provider may not engage in deceptive advertising or marketing with respect to a product or service provided offered to an individual.
(e)
added
Journalism— Nothing in this Act shall be construed to limit or diminish First Amendment freedoms guaranteed under the Constitution.
Sec. 203
Individual data ownership and control
(a)
changed
Access to, and correction, deletion, and portability of, covered data— Subject to In accordance with subsections (b) and (c), a covered entity shall provide an individual, after receiving a verified request from the individual, with the right to—
(A)
changed
the covered data, except covered data in back-up or archival systems, of the individual in a human-readable format that a reasonable individual can understand and download from the internet, the covered data (except covered data in a back-up or archival system) of the individual making the request that is collected, processed, or transferred by the covered entity or any service provider of the covered entity within the 24 months preceding the request;
(B)
changed
the name categories of any third party, if applicable, and an option for consumers to obtain the names of any such third party as well as and the categories of any service providers to whom the covered entity has transferred for consideration the covered data of the individual, as well as the categories of sources from which the covered data was collected; and
(C)
a description of the purpose for which the covered entity transferred the covered data of the individual to a third party or service provider;
(2)
changed
correct any verifiably material verifiable substantial inaccuracy or materially substantially incomplete information with respect to the covered data of the individual that is processed by the covered entity and instruct the covered entity to make reasonable efforts to notify any all third party, parties or service provider providers to which the covered entity transferred such covered data of the corrected information;
(3)
changed
delete covered data of the individual that is processed by the covered entity and instruct the covered entity to make reasonable efforts to notify any all third party, parties or service provider to which the covered entity transferred such covered data of the individual’s deletion request; and
(4)
changed
to the extent technically feasible, export covered data to the individual or directly to another entity, except for derived data, entity the covered data of the individual that is processed by the covered entity entity, including inferences linked or reasonably linkable to the individual but not including other derived data, without licensing restrictions that limit such transfers, transfers in—
(A)
a human-readable format that a reasonable individual can understand and download from the internet; and
(B)
a portable, structured, interoperable, and machine-readable format.
(b)
changed
Individual autonomy— A covered entity shall may not condition, effectively condition, attempt to condition, or attempt to effectively condition the exercise of any individual rights under this section a right described in subsection (a) through—
(1)
changed
through the use of any false, fictitious, fraudulent, or materially misleading statement or representation; or
(2)
changed
the design, modification, or manipulation of any user interface with the purpose or substantial effect of obscuring, subverting, or impairing a reasonable individual’s autonomy, decision making, or choice to exercise any such rights.right.
(1)
changed
In general— Subject to subsections (d) and (e)(1) (e), each request under subsection (a) shall be completed by any—
(A)
removed
large data holder within 45 days of verification of such request from an individual;
(A)
changed
covered entity that is not considered a large data holder or a covered entity described in section 209 within 60 45 days of verification of such request from an individual; orindividual, unless it is demonstrably impracticable or impracticably costly to verify such individual;
(B)
changed
covered entity as described in that is not a large data holder or a covered entity meeting the requirements of section 209 within 90 60 days of verification of such request from an individual.individual, unless it is demonstrably impracticable or impracticably costly to verify such individual; or
(C)
added
covered entity meeting the requirements of section 209 within 90 days of such request from an individual, unless it is demonstrably impracticable or impracticably costly to verify such individual.
(2)
changed
Extension— A response period set forth in this subsection may be extended once by 45 additional days when reasonably necessary, considering the complexity and number of the individual’s requests, so long as the covered entity informs the individual of any such extension within the initial 45-day response period, together with the reason for the extension.
(d)
Frequency and cost of access— A covered entity—
(1)
shall provide an individual with the opportunity to exercise each of the rights described in subsection (a); and
(A)
the first 2 times that an individual exercises any right described in subsection (a) in any 12-month period, shall allow the individual to exercise such right free of charge; and
(B)
any time beyond the initial 2 times described in subparagraph (A), may allow the individual to exercise such right for a reasonable fee for each request.
(e)
Verification and exceptions—
(1)
changed
Required exceptions— A covered entity shall may not permit an individual to exercise a right described in subsection (a), in whole or in part, if the covered entity—
(A)
cannot reasonably verify that the individual making the request to exercise the right is the individual whose covered data is the subject of the request or an individual authorized to make such a request on the individual’s behalf;
(B)
reasonably believes that the request is made to interfere with a contract between the covered entity and another individual;
(C)
changed
determines that the exercise of the right would require access to or correction of another individual’s sensitive covered data; ordata;
(D)
changed
reasonably believes that the exercise of the right would require the covered entity to engage in an unfair or deceptive practice under section 5 of the Federal Trade Commission Act (15 U.S.C. 45).45); or
(E)
added
reasonably believes that the request is made to further fraud, support criminal activity, or the exercise of the right presents a data security threat.
(2)
Additional information— If a covered entity cannot reasonably verify that a request to exercise a right described in subsection (a) is made by the individual whose covered data is the subject of the request (or an individual authorized to make such a request on the individual’s behalf), the covered entity—
(A)
may request that the individual making the request to exercise the right provide any additional information necessary for the sole purpose of verifying the identity of the individual; and
(B)
changed
shall may not process or transfer such additional information for any other purpose.
(3)
Permissive exceptions—
(A)
changed
In general— A covered entity may decline decline, with adequate explanation to the individual, to comply with a request to exercise a right described in subsection (a), in whole or in part, that would—
(i)
require the covered entity to retain any covered data collected for a single, one-time transaction, if such covered data is not processed or transferred by the covered entity for any purpose other than completing such transaction;
(ii)
changed
be impossible or demonstrably impracticable or prohibitively costly to comply with, and the covered entity shall provide a description to the requestor detailing the inability to comply with the request;
(iii)
require the covered entity to attempt to re-identify de-identified data;
(iv)
changed
result in require the release of trade secrets, covered entity to maintain covered data in an identifiable form or other privileged, collect, retain, or confidential business information;access any data in order to be capable of associating a verified individual request with covered data of such individual;
(v)
added
result in the release of trade secrets or other privileged or confidential business information;
(vi)
renumbered
was (6)(4)(2)(7)
require the covered entity to correct any covered data that cannot be reasonably verified as being inaccurate or incomplete;
(vii)
added
interfere with law enforcement, judicial proceedings, investigations, or reasonable efforts to guard against, detect, prevent, or investigate fraudulent, malicious, or unlawful activity, or enforce valid contracts;
(vi)
removed
interfere with law enforcement, judicial proceedings, investigations, or reasonable efforts to guard against, detect, or investigate malicious or unlawful activity, or enforce valid contracts;
(viii)
renumbered
was (6)(4)(2)(9)
violate Federal or State law or the rights and freedoms of another individual, including under the Constitution of the United States;
(viii)
removed
prevent a covered entity from being able to maintain a confidential record of deletion requests, maintained solely for the purpose of preventing covered data of an individual who has submitted a deletion request and requests that the covered entity no longer collect, process, or transfer such data;
(ix)
changed
fall within prevent a covered entity from being able to maintain a confidential record of deletion requests, maintained solely for the purpose of preventing covered data of an exception enumerated in individual from being recollected after the regulations promulgated by individual submitted a deletion request and requested that the Commission pursuant to paragraph (D); orcovered entity no longer collect, process, or transfer such data;
(x)
added
fall within an exception enumerated in the regulations promulgated by the Commission pursuant to subparagraph (D); or
(xi)
renumbered
was (6)(4)(2)(12)
with respect to requests for deletion—
(I)
renumbered
was (6)(4)(2)(12)(2)
unreasonably interfere with the provision of products or services by the covered entity to another person it currently serves;
(II)
renumbered
was (6)(4)(2)(12)(3)
delete covered data that relates to a public figure and for which the requesting individual has no reasonable expectation of privacy;
(III)
renumbered
was (6)(4)(2)(12)(4)
delete covered data reasonably necessary to perform a contract between the covered entity and the individual;
(IV)
added
delete covered data that the covered entity needs to retain in order to comply with professional ethical obligations;
(V)
added
delete covered data that the covered entity reasonably believes may be evidence of unlawful activity or an abuse of the covered entity’s products or services; or
(VI)
added
for private elementary and secondary schools as defined by State law and private institutions of higher education as defined by title I of the Higher Education Act of 1965, delete covered data that would unreasonably interfere with the provision of education services by or the ordinary operation of the school or institution.
(IV)
removed
delete covered data that the covered entity needs to retain in order to comply with professional ethical obligations; or
(V)
removed
delete covered data that the covered entity reasonably believes may be evidence of unlawful activity or an abuse of the covered entity’s products or services.
(B)
changed
Partial compliance— In a circumstance that would allow a denial pursuant to paragraph subparagraph (A), a covered entity shall partially comply with the remainder of the request if it is possible and not unduly burdensome to do so.
(C)
changed
Number of requests— For purposes of this paragraph, subparagraph (A)(ii), the receipt of a large number of verified requests, on its own, shall may not be considered to render compliance with a request demonstrably impossible.impracticable.
(D)
changed
Further exceptions— The Commission may, by regulation as described in subsection (f), (g), establish additional permissive exceptions necessary to protect the rights of individuals, alleviate undue burdens on covered entities, prevent unjust or unreasonable outcomes from the exercise of access, correction, deletion, or portability rights, or as otherwise necessary to fulfill the purposes of this section. In creating establishing such exceptions, the Commission should consider any relevant changes in technology, means for protecting privacy and other rights, and beneficial uses of covered data by covered entities.
(f)
changed
Regulations—Large data holder metrics reporting— Within two years of the date of enactment of this Act, the Commission may promulgate regulations, pursuant to section 553 of title 5, United States Code (5 U.S.C. 553), as necessary to establish processes by which A large data holder that is a covered entities are to comply with entity shall, for each calendar year in which it was a large data holder, do the provisions of this section. Such regulations shall take into consideration—following:
(1)
changed
the size of, and the nature, scope, and complexity of the activities engaged in by the covered entity, including whether Compile the covered entity is a large data holder, nonprofit organization, covered entities meeting following metrics for the requirements of section 209, service provider, third party, or third-party collecting entity;prior calendar year:
(A)
added
The number of verified access requests under subsection (a)(1).
(B)
added
The number of verified deletion requests under subsection (a)(3).
(C)
added
The number of requests to opt-out of covered data transfers under section 204(b).
(D)
added
The number of requests to opt-out of targeted advertising under section 204(c).
(E)
added
The number of requests in each of subparagraphs (A) through (D) that such large data holder (i) complied with in whole or in part and (ii) denied.
(F)
added
The median or mean number of days within which such large data holder substantively responded to the requests in each of subparagraphs (A) through (D).
(2)
added
Disclose by July 1 of each applicable calendar year the information compiled in paragraph (1) within such large data holder’s privacy policy required under section 202 or on the publicly accessible website of such large data holder that is accessible from a hyperlink included in the privacy policy.
(g)
added
Regulations— Not later than 2 years after the date of enactment of this Act, the Commission shall promulgate regulations, pursuant to section 553 of title 5, United States Code, as necessary to establish processes by which covered entities are to comply with the provisions of this section. Such regulations shall take into consideration—
(1)
added
the size of, and the nature, scope, and complexity of the activities engaged in by the covered entity, including whether the covered entity is a large data holder, nonprofit organization, covered entity meeting the requirements of section 209, third party, or third-party collecting entity;
(2)
renumbered
was (7)(4)
the sensitivity of covered data collected, processed, or transferred by the covered entity;
(3)
added
the volume of covered data collected, processed, or transferred by the covered entity;
(4)
added
the number of individuals and devices to which the covered data collected, processed, or transferred by the covered entity relates; and
(5)
added
after consulting the National Institute of Standards and Technology, standards for ensuring the deletion of covered data under this Act where appropriate.
(h)
added
Accessibility— A covered entity shall facilitate the ability of individuals to make requests under subsection (a) in any covered language in which the covered entity provides a product or service. The mechanisms by which a covered entity enables individuals to make requests under subsection (a) shall be readily accessible and usable by with individuals with disabilities.
(3)
removed
the volume of covered data collected, processed, or transferred by the covered entity; and
(4)
removed
the number of individuals and devices to which the covered data collected, processed, or transferred by the covered entity relates.
(g)
removed
Accessibility— A covered entity shall facilitate the ability for individuals to make requests under this section in any of the ten languages with the most users in the United States, according to the most recent U.S. Census, if the covered entity provides service in such language. The mechanisms by which a covered entity enables individuals to make requests under this section shall be readily accessible and usable by with disabilities.
Sec. 207
Civil rights and algorithms
(a)
Civil rights protections—
(1)
In general— A covered entity or a service provider may not collect, process, or transfer covered data in a manner that discriminates in or otherwise makes unavailable the equal enjoyment of goods or services on the basis of race, color, religion, national origin, sex, or disability.
(2)
Exceptions— This subsection shall not apply to—
(A)
the collection, processing, or transfer of covered data for the purpose of—
(i)
a covered entity’s or a service provider’s self-testing to prevent or mitigate unlawful discrimination; or
(ii)
diversifying an applicant, participant, or customer pool; or
(B)
any private club or group not open to the public, as described in section 201(e) of the Civil Rights Act of 1964 (42 U.S.C. 2000a(e)).
(b)
FTC enforcement assistance—
(1)
In general— Whenever the Commission obtains information that a covered entity or service provider may have collected, processed, or transferred covered data in violation of subsection (a), the Commission shall transmit such information as allowable under Federal law to any Executive agency with authority to initiate enforcement actions or proceedings relating to such violation.
(2)
Annual report— Not later than 3 years after the date of enactment of this Act, and annually thereafter, the Commission shall submit to Congress a report that includes a summary of—
(A)
changed
the types of information the Commission transmitted to Federal Executive agencies under paragraph (1) during the previous 1-year period; and
(B)
how such information relates to Federal civil rights laws.
(3)
Technical assistance— In transmitting information under paragraph (1), the Commission may consult and coordinate with, and provide technical and investigative assistance, as appropriate, to such Executive agency.
(4)
changed
Cooperation with other agencies— The Commission may implement this subsection by executing agreements or memoranda of understanding with the appropriate Federal Executive agencies.
(c)
changed
Algorithm Covered algorithm impact and evaluation—
(1)
changed
Algorithm Covered algorithm impact assessment—
(A)
changed
Impact assessment— Notwithstanding any other provision of law, not later than 2 years after the date of enactment of this Act, and annually thereafter, a large data holder that uses an a covered algorithm in a manner that may cause potential poses a consequential risk of harm to an individual, individual or group of individuals, and uses such covered algorithm solely or in part, to collect, process, or transfer covered data must shall conduct an impact assessment of such algorithm in accordance with subparagraph (B).
(B)
Impact assessment scope— The impact assessment required under subparagraph (A) shall provide the following:
(i)
changed
A detailed description of the design process and methodologies of the covered algorithm.
(ii)
changed
A statement of the purpose, proposed uses, purpose and foreseeable capabilities outside of the articulated proposed use uses of the covered algorithm.
(iii)
changed
A detailed description of the data used by the covered algorithm, including the specific categories of data that will be processed as input and any data used to train the model that the covered algorithm relies on.on, if applicable.
(iv)
changed
A description of the outputs produced by the covered algorithm.
(v)
changed
An assessment of the necessity and proportionality of the covered algorithm in relation to its stated purpose, including reasons for the superiority of the algorithm over nonautomated decision-making methods.purpose.
(vi)
changed
A detailed description of steps the large data holder has taken or will take to mitigate potential harms from the covered algorithm to an individual or group of individuals, including potential harms related to—
(I)
changed
any individual under the age of 17;covered minors;
(II)
making or facilitating advertising for, or determining access to, or restrictions on the use of housing, education, employment, healthcare, insurance, or credit opportunities;
(III)
changed
determining access to, or restrictions on the use of, any place of public accommodation, particularly as such harms relate to the protected characteristics of individuals, including race, color, religion, national origin, sex, or disability; ordisability;
(IV)
changed
disparate impact on the basis of individuals’ race, color, religion, national origin, sex, or disability status.status; or
(V)
added
disparate impact on the basis of individuals’ political party registration status.
(2)
changed
Algorithm design evaluation— Notwithstanding any other provision of law, not later than 2 years after the date of enactment of this Act, a covered entity or service provider that knowingly develops an algorithm, a covered algorithm that is designed to, solely or in part, to collect, process, or transfer covered data or publicly available information in furtherance of a consequential decision shall prior to deploying the covered algorithm in interstate commerce evaluate the design, structure, and inputs of the covered algorithm, including any training data used to develop the covered algorithm, to reduce the risk of the potential harms identified under paragraph (1)(B).
(3)
Other considerations—
(A)
changed
Focus— In complying with paragraph paragraphs (1) or and (2), a covered entity and a service provider may focus the impact assessment or evaluation on any covered algorithm, or portions of an a covered algorithm, that will be put to use and may reasonably contribute to the risk of the potential harms identified under paragraph (1)(B).
(B)
removed
External, independent auditor or researcher— To the extent possible, a covered entity and a service provider shall utilize an external, independent auditor or researcher to conduct an impact assessment under paragraph (1) or an evaluation under paragraph (2).
(C)
removed
Availability—
(i)
renumbered
was (4)(4)(4)(2)
In general— A covered entity and a service provider—
(I)
added
shall, not later than 30 days after completing an impact assessment or evaluation, submit the impact assessment or evaluation conducted under paragraph (1) or (2) to the Commission;
(I)
removed
shall, not later than 30 days after completing an impact assessment or evaluation, submit the impact assessment and evaluation conducted under paragraphs (1) and (2) to the Commission;
(II)
renumbered
was (4)(4)(4)(2)(4)
shall, upon request, make such impact assessment and evaluation available to Congress; and
(III)
renumbered
was (4)(4)(4)(2)(5)
may make a summary of such impact assessment and evaluation publicly available in a place that is easily accessible to individuals.
(ii)
added
Trade secrets— Covered entities and service providers may redact and segregate any trade secret (as defined in section 1839 of title 18, United States Code) or other confidential or proprietary information from public disclosure under this subparagraph and the Commission shall abide by its obligations under section 6(f) of the Federal Trade Commission Act (15 U.S.C. 46(f)) in regard to such information.
(C)
added
Enforcement— The Commission may not use any information obtained solely and exclusively through a covered entity or a service provider’s disclosure of information to the Commission in compliance with this section for any purpose other than enforcing this Act with the exception of enforcing consent orders, including the study and report provisions in paragraph (6). This subparagraph does not preclude the Commission from providing this information to Congress in response to a subpoena.
(ii)
removed
Trade secrets— Covered entities and service providers must make all submissions under this section to the Commission in unredacted form, but a covered entity and a service provider may redact and segregate any trade secrets (as defined in section 1839 of title 18, United States Code) from public disclosure under this subparagraph.
(D)
removed
Enforcement— The Commission may not use any information obtained solely and exclusively through a covered entity or a service provider’s disclosure of information to the Commission in compliance with this section for any purpose other than enforcing this Act, including the study and report provisions in paragraph 6 of this section. This provision shall not preclude the Commission from providing this information to Congress in response to a subpoena or official Congressional request.
(4)
Guidance— Not later than 2 years after the date of enactment of this Act, the Commission shall, in consultation with the Secretary of Commerce, or their respective designees, publish guidance regarding compliance with this section.
(5)
Rulemaking and exemption— The Commission shall have authority under section 553 of title 5, United States Code, to promulgate regulations as necessary to establish processes by which a large data holder—
(A)
changed
shall submit an impact assessment to the Commission under paragraph (3)(C)(i)(I); (3)(B)(i)(I); and
(B)
changed
may exclude from this subsection any covered algorithm that presents low or minimal consequential risk for potential for harms of harm to individuals (as identified under paragraph (1)(B)).an individual or group of individuals.
(A)
changed
Study— The Commission, in consultation with the Secretary of Commerce or the Secretary’s designee, shall conduct a study, to review any impact assessment or evaluation submitted under this paragraph. subsection. Such study shall include an examination of—
(i)
changed
best practices for the assessment and evaluation of covered algorithms; and
(ii)
changed
methods to reduce the risk of harm to individuals that may be related to the use of covered algorithms.
(i)
changed
Initial report— Not later than 3 years after the date of enactment of this Act, the Commission, in consultation with the Secretary of Commerce or the Secretary’s designee, shall submit to Congress a report containing the results of the study conducted under subsection (a), subparagraph (A), together with recommendations for such legislation and administrative action as the Commission determines appropriate.
(ii)
Additional reports— Not later than 3 years after submission of the initial report under clause (i), and as the Commission determines necessary thereafter, the Commission shall submit to Congress an updated version of such report.
Sec. 302
Service providers and third parties
(a)
Service providers— A service provider—
(1)
changed
shall adhere to the instructions of a covered entity and only collect, process, and transfer service provider data to the extent strictly necessary and proportionate to provide a service requested by the covered entity. This entity, as set out in the contract required by subsection (b), and this paragraph shall does not require a service provider to collect collect, process, or process transfer covered data if the service provider would not otherwise do so;
(2)
changed
shall may not collect, process, or transfer service provider data if the service provider has actual knowledge that the a covered entity violated this Act with respect to such data;
(3)
changed
shall assist a covered entity in fulfilling the covered entity’s obligation to respond responding to a request made by an individual rights requests pursuant to under section 203, 203 or 204, by appropriate technical and organizational measures, taking into account the nature of the processing and the information reasonably available to the service provider;either—
(A)
added
providing appropriate technical and organizational measures, taking into account the nature of the processing and the information reasonably available to the service provider, for the covered entity to comply with such request for service provider data; or
(B)
added
fulfilling a request by a covered entity to execute an individual rights request that the covered entity has determined should be complied with, by either—
(i)
added
complying with the request pursuant to the covered entity’s instructions; or
(ii)
added
providing written verification to the covered entity that it does not hold covered data related to the request, that complying with the request would be inconsistent with its legal obligations, or that the request falls within an exception to section 203 or 204;
(4)
changed
may engage another service provider for purposes of processing service provider data on behalf of a covered entity only after providing the that covered entity that is directing the services or functions of the service provider with respect to such service provider data with notice, notice and pursuant to a written contract that requires such other service provider to satisfy the obligations of the service provider with respect to such service provider data;data, including that the other service provider be treated as a service provider under this Act;
(5)
changed
shall shall, upon the reasonable request of the covered entity, make available to the covered entity information necessary to demonstrate the service provider’s compliance of the service provider with the obligations in requirements of this Act, which may include making available a report of an independent assessment arranged by the service provider on terms agreed to by the parties service provider and the covered entity, providing information necessary to enable the covered entity to conduct and document a privacy impact assessment required by subsection (d) or (e) of section 301, and making available the report required under section 207(c)(2) as applicable;207(c)(2);
(6)
shall, at the covered entity’s direction, delete or return all covered data to the covered entity as requested at the end of the provision of services, unless retention of the covered data is required by law;
(7)
changed
shall not transfer service provider data develop, implement, and maintain reasonable administrative, technical, and physical safeguards that are designed to any person with protect the exception security and confidentiality of another service provider without the affirmative express consent, obtained by the covered entity with the direct relationship to the individual that is directing the services or functions of data the service provider processes consistent with respect to the service provider data, of the individual to whom the service provider data is linked or reasonably linkable;section 208; and
(8)
changed
shall develop, implement, allow and maintain cooperate with, reasonable administrative, technical, assessments by the covered entity or the covered entity’s designated assessor; alternatively, the service provider may arrange for a qualified and physical safeguards that are designed independent assessor to protect conduct an assessment of the security service provider’s policies and confidentiality technical and organizational measures in support of the obligations under this Act using an appropriate and accepted control standard or framework and assessment procedure for such assessments. The service provider shall provide a report of such assessment to the covered data it processes consistent with section 208; andentity upon request.
(b)
added
Contracts Between Covered Entities and Service Providers—
(1)
added
Requirements— A person or entity may only act as a service provider pursuant to a written contract between the covered entity and the service provider, or a written contract between one service provider and a second service provider as described under subsection (a)(4), if the contract—
(A)
added
sets forth the data processing procedures of the service provider with respect to collection, processing, or transfer performed on behalf of the covered entity or service provider;
(9)
removed
shall be exempt from the requirements of section 202(d) with respect to service provider data but shall provide direct notification regarding material changes to its privacy policy to each covered entity with which it provides services or functions as a service provider, in each language that the privacy policy is made available. Compliance with this provision does not alleviate any obligations the service provider has to the covered entity to which it provides services or functions as a service provider.
(b)
removed
Contracts between covered entities and service providers— A person or entity may act as a service provider pursuant to a written contract between the covered entity and the service provider, or a written contract between one service provider and a second service provider as permitted in section 302(a)(4), provided that the contract—
(1)
removed
governs the service provider’s data processing procedures with respect to processing or transfer performed on behalf of the covered entity or service provider;
(B)
renumbered
was (3)(4)
clearly sets forth—
(i)
added
instructions for collecting, processing, or transferring data;
(ii)
added
the nature and purpose of collecting, processing, or transferring;
(iii)
added
the type of data subject to collecting, processing, or transferring;
(A)
removed
instructions for processing data;
(B)
removed
the nature and purpose of processing;
(C)
removed
the type of data subject to processing;
(iv)
renumbered
was (3)(4)(5)
the duration of processing; and
(v)
added
the rights and obligations of both parties, including a method by which the service provider shall notify the covered entity of material changes to its privacy practices;
(C)
added
does not relieve a covered entity or a service provider of any requirement or liability imposed on such covered entity or service provider under this Act; and
(E)
removed
the rights and obligations of both parties;
(3)
removed
does not relieve a covered entity or a service provider of an obligation under this Act; and
(D)
renumbered
was (3)(6)
prohibits—
(i)
renumbered
was (3)(6)(2)
collecting, processing, or transferring covered data in contravention to subsection (a); and
(ii)
added
combining service provider data with covered data which the service provider receives from or on behalf of another person or persons or collects from the interaction of the service provider with an individual, provided that such combining is not necessary to effectuate a purpose described in paragraphs (1) through (15) of section 101(b) and is otherwise permitted under the contract required by this subsection.
(2)
added
Contract terms— Each service provider shall retain copies of previous contracts entered into in compliance with this subsection with each covered entity to which it provides requested products or services.
(B)
removed
combining service provider data with covered data which the service provider receives from or on behalf of another person or persons or collects from its own interaction with an individual. The contract may, subject to agreement with the service provider, permit a covered entity to monitor the service provider’s compliance with the contract through measures including, but not limited to, ongoing manual reviews and automated scans, and regular assessments, audits, or other technical and operational testing at least once every 12 months.
(c)
changed
Relationship between covered entities Between Covered Entities and service providers—Service Providers—
(1)
changed
Determining whether a person is acting as a covered entity or service provider with respect to a specific processing of covered data is a fact-based determination that depends upon the context in which such data is processed.
(2)
changed
A covered entity or service provider person that transfers is not limited in its processing of covered data pursuant to a service provider, in compliance with the requirements instructions of this Act, a covered entity, or that fails to adhere to such instructions, is a covered entity and not liable for a violation service provider with respect to a specific processing of this Act by the covered data. A service provider that continues to whom such adhere to the instructions of a covered entity with respect to a specific processing of covered data was transferred, this Act provided that, at remains a service provider. If a service provider begins, alone or jointly with others, determining the time purposes and means of transferring such the processing of covered data, the it is a covered entity or and not a service provider did not know or have reason with respect to know that the service provider would likely commit a violation processing of this Act.such data.
(3)
changed
A covered entity that transfers covered data to a service provider or a service provider that receives transfers covered data to a covered entity or another service provider, in compliance with the requirements of this Act Act, is not in liable for a violation of this Act as a result of a violation by a the service provider or covered entity to whom such covered data was transferred, if at the time of transferring such covered data, the covered entity or service provider from which it receives such did not have actual knowledge that the service provider or covered data.entity would violate this Act.
(4)
added
A covered entity or service provider that receives covered data in compliance with the requirements of this Act is not in violation of this Act as a result of a violation by a covered entity or service provider from which such data was received.
(d)
Third parties— A third party—
(1)
changed
shall not process third-party third party data for a processing purpose other than, in the case of sensitive covered data, the processing purpose for which the individual gave affirmative express consent or to effect a purpose enumerated in paragraph (1), (3), or (5) of section 101(b) and, in the case of non-sensitive data, the processing purpose for which the covered entity made a disclosure pursuant to section 204(b)(4);202(b)(4); and
(2)
changed
for purposes of paragraph (1), may reasonably rely on representations made by the covered entity that transferred the third-party data, provided that third party data if the third party conducts reasonable due diligence on the representations of the covered entity and finds those representations to be credible; andcredible.
(3)
removed
shall be exempt from the requirements of section 204 with respect to third-party data, but shall otherwise have the same responsibilities and obligations as a covered entity with respect to such data under all other provisions of this Act.
(e)
Additional obligations on covered entities—
(1)
In general— A covered entity or service provider shall exercise reasonable due diligence in—
(A)
selecting a service provider; and
(B)
deciding to transfer covered data to a third party.
(2)
changed
Guidance— Not later than 2 years after the date of enactment of this Act, the Commission shall publish guidance regarding compliance with this subsection, taking into consideration the burdens on small- large data holders, covered entities who are not large data holders, and medium-sized covered entities.entities meeting the requirements of section 209.
(f)
added
Rule of construction— Solely for the purposes of this section, the requirements for service providers to contract with, assist, and follow the instructions of covered entities shall be read to include requirements to contract with, assist, and follow the instructions of a government entity if the service provider is providing a service to a government entity.
Sec. 404
Relationship to Federal and State laws
(a)
Federal law preservation—
(1)
changed
In general— Nothing in this Act or a regulation promulgated under this Act shall may be construed to limit—
(A)
the authority of the Commission, or any other Executive agency, under any other provision of law;
(B)
changed
any requirement for a common carrier subject to section 64.2011 of title 47, Code of Federal Regulations, Regulations (or any successor regulation) regarding information security breaches; or
(C)
changed
any other provision of Federal law unless specifically authorized by law, except as otherwise provided in this Act.
(2)
added
Antitrust savings clause—
(A)
added
Full application of the antitrust law— Nothing in this Act may be construed to modify, impair or supersede the operation of the antitrust law or any other provision of law.
(B)
added
No immunity from the antitrust law— Nothing in the regulatory regime adopted by this Act shall be construed as operating to limit any law deterring anticompetitive conduct or diminishing the need for full application of the antitrust law. Nothing in this Act explicitly or implicitly precludes the application of the antitrust law.
(C)
added
Definition of antitrust law— For purposes of this section, the term antitrust law has the same meaning as in subsection (a) of the first section of the Clayton Act (15 U.S.C. 12), except that such term includes section 5 of the Federal Trade Commission Act (15 U.S.C. 45) to the extent that such section 5 applies to unfair methods of competition.
(2)
removed
Applicability of other privacy requirements— A covered entity that is required to comply with title V of the Gramm-Leach-Bliley Act (15 U.S.C. 6801 et seq.), the Health Information Technology for Economic and Clinical Health Act (42 U.S.C. 17931 et seq.), part C of title XI of the Social Security Act (42 U.S.C. 1320d et seq.), the Fair Credit Reporting Act (15 U.S.C. 1681 et seq.), the Family Educational Rights and Privacy Act (20 U.S.C. 1232g; part 99 of title 34, Code of Federal Regulations), or the regulations promulgated pursuant to section 264(c) of the Health Insurance Portability and Accountability Act of 1996 (42 U.S.C. 1320d–2 note), and is in compliance with the data privacy requirements of such regulations, part, title, or Act (as applicable), shall be deemed to be in compliance with the related requirements of this title, except for section 208, with respect to data subject to the requirements of such regulations, part, title, or Act. Not later than 1 year after the date of enactment of this Act, the Commission shall issue guidance describing the implementation of this paragraph.
(3)
changed
Applicability of other data security privacy requirements— A covered entity that is required to comply with title V of the Gramm-Leach-Bliley Act (15 U.S.C. 6801 et seq.), the Health Information Technology for Economic and Clinical Health Act (42 U.S.C. 17931 et seq.), part C of title XI of the Social Security Act (42 U.S.C. 1320d et seq.), the Fair Credit Reporting Act (15 U.S.C. 1681 et seq.), the Family Educational Rights and Privacy Act (20 U.S.C. 1232g; part 99 of title 34, Code of Federal Regulations) to the extent such covered entity is a school as defined in 20 U.S.C. 1232g(a)(3) or 34 C.F.R. 99.1(a), section 444 of the General Education Provisions Act (commonly known as the “Family Educational Rights and Privacy Act of 1974”) (20 U.S.C. 1232g) and part 99 of title 34, Code of Federal Regulations (or any successor regulation), the Confidentiality of Alcohol and Drug Abuse Patient Records at 42 U.S.C. 290dd-2 and its implementing regulations at 42 CFR part 2, the Genetic Information Non-discrimination Act (GINA), or the regulations promulgated pursuant to section 264(c) of the Health Insurance Portability and Accountability Act of 1996 (42 U.S.C. 1320d–2 note), and is in compliance with the information security data privacy requirements of such regulations, part, title, or Act (as applicable), shall be deemed to be in compliance with the related requirements of this Act, except for section 208 208, solely and exclusively with respect to data subject to the requirements of such regulations, part, title, or Act. Not later than 1 year after the date of enactment of this Act, the Commission shall issue guidance describing the implementation of this paragraph.
(4)
added
Applicability of other data security requirements— A covered entity that is required to comply with title V of the Gramm-Leach-Bliley Act (15 U.S.C. 6801 et seq.), the Health Information Technology for Economic and Clinical Health Act (42 U.S.C. 17931 et seq.), part C of title XI of the Social Security Act (42 U.S.C. 1320d et seq.), or the regulations promulgated pursuant to section 264(c) of the Health Insurance Portability and Accountability Act of 1996 (42 U.S.C. 1320d–2 note), and is in compliance with the information security requirements of such regulations, part, title, or Act (as applicable), shall be deemed to be in compliance with the requirements of section 208, solely and exclusively with respect to data subject to the requirements of such regulations, part, title, or Act. Not later than 1 year after the date of enactment of this Act, the Commission shall issue guidance describing the implementation of this paragraph.
(b)
Preemption of State laws—
(1)
changed
In general— No State or political subdivision of a State may adopt, maintain, enforce, prescribe, or continue in effect any law, regulation, rule, standard, requirement, or other provision having the force and effect of law of any State, or political subdivision of a State, covered by the provisions of this Act, or a rule, regulation, or requirement promulgated under this Act.
(2)
changed
State law preservation— Paragraph (1) shall may not be construed to preempt, displace, or supplant the following State laws, rules, regulations, or requirements:
(A)
changed
Consumer protection laws of general applicability applicability, such as laws regulating deceptive, unfair, or unconscionable practices.practices, except that the fact of a violation of this Act or a regulation promulgated under this Act may not be pleaded as an element of any violation of such a law.
(C)
changed
Laws Provisions of laws, in so far as, that govern the privacy rights or other protections of employees, employee information, students, or student information.
(D)
Laws that address notification requirements in the event of a data breach.
(E)
Contract or tort law.
(F)
changed
Criminal laws governing fraud, theft, including identity theft, unauthorized access to information or electronic devices, or unauthorized use of information, malicious behavior, or similar provisions, or laws of criminal procedure.laws.
(G)
changed
Criminal or civil Civil laws regarding cyberstalking, cyberbullying, nonconsensual pornography, governing fraud, theft (including identity theft), unauthorized access to information or sexual harassment.electronic devices, unauthorized use of information, malicious behavior, or similar provisions of law.
(H)
added
Civil laws regarding cyberstalking, cyberbullying, nonconsensual pornography, sexual harassment, child abuse material, child pornography, child abduction or attempted child abduction, coercion or enticement of a child for sexual activity, or child sex trafficking.
(I)
renumbered
was (3)(3)(10)
Public safety or sector specific laws unrelated to privacy or security.
(I)
removed
Laws that address public records, criminal justice information systems, arrest records, mug shots, conviction records, or non-conviction records.
(J)
changed
Laws that Provisions of law, insofar as such provisions address banking public records, financial criminal justice information systems, arrest records, tax mug shots, conviction records, Social Security numbers, credit cards, credit reporting and investigations, credit repair, credit clinics, or check-cashing services.non-conviction records.
(K)
changed
Laws that solely Provisions of law, insofar as such provisions address facial recognition or facial recognition technologies, electronic surveillance, wiretapping, banking records, financial records, tax records, Social Security numbers, credit cards, consumer and credit reporting and investigations, credit repair, credit clinics, or telephone monitoring.check-cashing services.
(L)
changed
The Biometric Information Privacy Act (740 ICLS 14 et seq.) and the Genetic Information Privacy Act (410 ILCS et seq.).Provisions of law, insofar as such provisions address facial recognition or facial recognition technologies, electronic surveillance, wiretapping, or telephone monitoring.
(M)
changed
Laws to address unsolicited email messages, telephone solicitation, or caller ID.The Biometric Information Privacy Act (740 ICLS 14 et seq.) and the Genetic Information Privacy Act (410 ILCS 513 et seq.).
(N)
changed
Laws that Provisions of laws, in so far as, such provisions to address health information, medical information, medical records, HIV status, unsolicited email or HIV testing.text messages, telephone solicitation, or caller identification.
(O)
changed
Laws that address the confidentiality Provisions of library records.laws, in so far as, such provisions address health information, medical information, medical records, HIV status, or HIV testing.
(P)
changed
Section 1798.150 Provisions of the California Civil Code (as amended on November 3, 2020, by initiative Proposition 24, section 16).laws, in so far as, such provisions pertain to public health activities, reporting, data, or services.
(Q)
added
Provisions of law, insofar as such provisions address the confidentiality of library records.
(R)
added
Section 1798.150 of the California Civil Code (as amended on November 3, 2020 by initiative Proposition 24, Section 16).
(S)
added
Laws pertaining to the use of encryption as a means of providing data security.
(3)
changed
Nonapplication of FCC privacy laws and regulations to covered entities—CPPA enforcement— Notwithstanding any other provision provisions of law, sections 222, 338(i), and 631 the California Privacy Protection Agency established under 1798.199.10(a) of the Communications California Privacy Rights Act of 1934, as amended (47 U.S.C. 222, 338(i), and 551), and any regulation promulgated by may enforce this Act, in the Federal Communications Commission under such sections, shall not apply to any covered entity with respect to same manner, it would otherwise enforce the collecting, processing, or transferring of covered data under this Act.California Consumer Privacy Act, Section 1798.1050 et. seq.
(4)
added
Nonapplication of fcc privacy laws and regulations to certain covered entities— Notwithstanding any other provision of law, sections 222, 338(i), and 631 of the Communications Act of 1934 (47 U.S.C. 222; 338(i); 551), and any regulations and orders promulgated by the Federal Communications Commission under any such section, do not apply to any covered entity with respect to the collection, processing, transfer, or security of covered data or its equivalent, and the related privacy and data security activities of a covered entity that would otherwise be regulated under such sections shall be governed exclusively by the provisions of this Act, except for—
(A)
added
any emergency services, as defined in section 7 of the Wireless Communications and Public Safety Act of 1999 (47 U.S.C. 615b);
(B)
added
subsections (b) and (g) of section 222 of the Communications Act of 1934 (47 U.S.C. 222); and
(C)
added
any obligation of an international treaty related to the exchange of traffic implemented and enforced by the Federal Communications Commission.
(c)
changed
Preservation of common law or statutory causes of action for civil relief— Nothing in this Act, nor any amendment, standard, rule, requirement, assessment, law, or regulation promulgated under this Act, shall may be construed to preempt, displace, or supplant any Federal or State common law rights or remedies, or any statute creating a remedy for civil relief, including any cause of action for personal injury, wrongful death, property damage, or other financial, physical, reputational, or psychological injury based in negligence, strict liability, products liability, failure to warn, an objectively offensive intrusion into the private affairs or concerns of the individual, or any other legal theory of liability under any Federal or State common law, or any State statutory law, except that the fact of a violation of this Act shall not be pleaded as an element of any such cause of action.law.