2020 Consumer Data Privacy Legislation

9/13/2020

Alternative Text

In recent years, a number of events have converged to heighten consumer awareness of and concerns about privacy: implementation of the California Consumer Privacy Act of 2018 (CCPA), Europe’s General Data Protection Regulation (GDPR) and continuing security breaches of all types, as well as Americans' increasing use of the Internet for many different types of activities.  

More than 80% of Americans say they go online on a daily basis, according to the Pew Research Center. Of those, 28% go online almost constantly and 45% go online several times a day. Consumers are now more aware that businesses, social media sites and other websites may collect and share their personal information with third parties. They also hear more about security breaches, cyberattacks and unauthorized sharing of personal information.

Although state legislatures have addressed privacy issues in many different sectors for many years, 2019 saw several states introduce more comprehensive privacy legislation (such as CCPA) than compared to previous years, in addition to other types of legislation aimed at protecting consumer privacy online. Despite an increased number of bills, however, comprehensive legislation did not pass in 2019.

Privacy bills increased in 2020 compared to 2019, with additional comprehensive privacy bills as well. Additional legislation was introduced in 2020 to address the collection and use of biometric or facial recognition data by commercial entities. Very few bills have been enacted however, as the Covid-19 pandemic disrupted legislative sessions and dramatically changed priorities. 

The legislation identified below is limited to the regulation of privacy practices of commercial entities, online services or commercial websites, covering legislation related to the privacy of consumer data, including bills related to online privacy, collection of consumers' biometric data, data broker regulation and other miscellaneous consumer privacy issues. Legislation related to data breaches is not included here, and some additional types of privacy laws and legislation are covered separately in other NCSL resources

2020 Consumer Data Privacy Legislation

Bills were considered in at least 30 states and Puerto Rico in 2020. 

Arizona

AZ HB 2728
Status: Failed - Adjourned
Relates to biometric identifiers, relates to commercial purpose, relates to consent.

AZ HB 2729
Status: Failed - Adjourned
Relates to personal data, relates to processing, relates to security standards.

AZ HCR 2013
Status: Failed - Adjourned
Relates to consumer data, relates to privacy, relates to federal standard.

AZ SB 1614
Status: Failed - Adjourned
Relates to consumer data, relates to privacy.

California

CA AB 82
Status: Enacted
This bill would require data broker registration fees to be deposited in the Data Brokers' Registry Fund, which the bill would create in the State Treasury, to be available for expenditure by the Department of Justice, upon appropriation by the Legislature, to offset costs for an internet website where the information provided by data brokers is accessible to the public.

CA AB 713
Status: To Governor
Excepts from the Consumer Privacy Act information that was deidentified in accordance with specified federal law, was derived from medical information, protected health information, individually identifiable health information, or identifiable private information, consistent with specified federal policy. Prohibits a business or other person from reidentifying information that was deidentified, unless a specified exception is met.

CA AB 846
Status: To Governor
Requires the evaluation of peace officers by a physician and surgeon, or psychologist, include bias against race or ethnicity, gender, nationality, religion, disability, or sexual orientation. Requires every department or agency that employs peace officers to review the job descriptions used in the recruitment and hiring of those peace officers and to make changes that deemphasize the paramilitary aspects of the job and place more emphasis on community interaction and collaborative problem solving.

CA AB 873
Status: Failed--adjourned
Revises the definition of deidentified information for purposes of the Consumer Privacy Act to mean information that does not identify, and is not linkable, directly or indirectly, to a particular consumer. Specifies that personal information includes specified information that, among other things, is reasonably capable of being associated with, or could be reasonably linked, directly or indirectly, with a particular consumer or household.

CA AB 981
Status: Failed--adjourned
Eliminates a consumer's right to request a business to delete or not sell the consumer's personal information under the Consumer Privacy Act, if it is necessary to retain or share the consumer's personal information to complete an insurance transaction requested by the consumer.

CA AB 1138
Status: To Governor
Pohibits a person or business that conducts business in the state, and that operates a social media website or application, from allowing a person under a specified age to create an account with the website or application, unless the website or application obtains the consent of the person's parent or guardian before creating the account using a method that includes reasonable measures to ensure that the person giving their consent is the parent or legal guardian of such person.

CA AB 1281
Status: To Governor
Extends exemptions from the Consumer Privacy Act certain information collected by a business about a natural person in the course of that person acting as a job applicant, employee, owner, director, officer, medical staff member, or contractor and personal information reflecting a written or verbal communication or a transaction between a business and a consumer, until a specified date.

CA AB 1395
Status: Failed--adjourned
Prohibits a person or entity from providing the operation of a voice recognition feature within the state without prominently informing the user during the initial setup or installation of a smart speaker device. Prohibits any deidentified actual recordings or transcriptions collected or retained through the operation of a voice recognition feature by the manufacturer of a connected television or smart speaker device from being used for any advertising purpose or sold.

CA AB 1416
Status: Failed--adjourned
Specifies that the State Consumer Privacy Act does not restrict a business's ability comply with any rules or regulations adopted pursuant to and in furtherance of state or federal laws. Establishes an exception to the act for a business that provides a consumer's personal information to a government agency solely for the purposes of carrying out a government program, if specified requirements are met.

CA AB 1665
Status: Failed--adjourned
Enacts the Athletic Training Practice Act. Establishes the California Board of Athletic Training within the Department of Consumer Affairs to exercise licensing, regulatory, and disciplinary functions. Prohibits a person from practicing as an athletic trainer or using certain titles or terms without being licensed by the board. Requires a licensed athletic trainer to practice only in collaboration with a physician and surgeon.

CA AB 2261
Status: Failed--adjourned
Requires a processor, as defined, that provides facial recognition services to, among other things, make available an application programming interface or other technical capability, chosen by the processor, to enable controllers or third parties to conduct legitimate, independent, and reasonable tests of those facial recognition services for accuracy and unfair performance differences across distinct subpopulations.

CA AB 2280
Status: Failed--adjourned
This bill would define " personal health record information" for purposes of the act to mean individually identifiable information, in electronic or physical form, about an individual' s mental or physical condition that is collected by an FDA-approved a commercial internet website, online service, or product that is used by an individual at the direction of a provider of health care with the primary purpose of collecting and that collects the individual' s individually identifiable personal health record information through a direct measurement of an individual' s mental or physical condition or through user input regarding an individual' s mental or physical condition. The bill would provide that a business that offers personal health record software or hardware to a consumer, in order to make information available to an individual or provider of health care at the request of the individual or provider of health care, for purposes of allowing the individual to manage their information, or for the diagnosis, treatment, or management of a medical condition of the individual, shall be deemed to be a provider of health care subject to the requirements of the Confidentiality of Medical Information Act.

CA AB 3212
Status: Failed--adjourned
Prohibits a person or business that conducts business in this state that operates a social media internet website or application that requires opt-in consent before selling a minor's personal information to obtain consent to sell the minor's personal information in a manner that is separate from the social media internet website's or application's general terms and conditions.

CA SB 108
Status: Failed--adjourned
Amends the Alcoholic Beverage Control Act. Prohibits a licensee from employing or continuing to employ an alcohol server without a valid alcohol server certification beginning on a specified date. Gives the Chief of Enforcement, and all investigators, inspectors, and deputies of the Bureau of Cannabis Control the authority of peace officers extending to any place in the state while engaged in exercising their powers or performing their duties imposed by investigating laws.

CA SB 980
Status: To Governor
Establishes the Genetic Information Privacy Act. Prohibits a direct to consumer genetic or illness testing services company from disclosing a person's genetic information to a third party without obtaining the person's prior written consent. Requires actions for relief to be prosecuted exclusively by a District Attorney, county counsel, city attorney, or city prosecutor.

CA 9
(Ballot Measure) Permits consumers to prevent businesses from sharing personal information, correct inaccurate personal information, and limit a business's use of such personal information as precise geolocation, race, ethnicity, religion, genetic data, union membership, private communications, and certain sexual orientation, health, and biometric information. Changes the criteria for which businesses must comply with these laws.

Connecticut

CT SB 134
Status: Failed - Adjourned
Concerns consumer privacy, requires businesses to disclose the proposed use of any personal information and to give consumers the right to discover what personal information the business possesses and to opt out of the sale of such information and to create a cause of action and penalties for violations of such requirements.

Florida

FL HB 963
Status: Failed
Relates to consumer data privacy, prohibits the use of personal data contained in public records for certain marketing, soliciting, and contact without the persons consent, provides definitions.

FL SB 1670
Status: Failed
Relates to consumer data privacy, prohibits the use of personal data contained in public records for certain marketing, soliciting, and contact without the persons consent, defines terms.

Hawaii

HI HB 761
Status: Failed--adjourned
Specifies that retailers may provide proof of purchase in electronic form to a member of a frequent shopper program, requires retailers who offer electronic proof of purchase to have reasonable safeguards to protect members' personal information.

HI HB 2572
Status: Failed--adjourned
Implements the recommendations of the Twenty-First Century Privacy Law Task Force.

HI SB 418
Status: Failed--adjourned
Requires a business to disclose the categories and specific pieces of identifying information collected about a consumer upon verifiable request from the consumer, discloses the identity of third parties to which the business has sold or transferred identifying information about a consumer upon verifiable request from the consumer.

HI SB 1534
Status: Failed--adjourned
Requires an event operator to disclose the number of tickets available for sale to the general public for an event, prohibits a place of entertainment that is funded by donations, public funds, or is tax exempt from entering into exclusive ticketing contracts, prohibits ticket sellers from disclosing ticket purchasers' personally identifiable information.

HI SB 2451
Status: Failed--adjourned
Prohibits a third party from selling or using personal information about a consumer that has been sold to the third party by a business unless the consumer has received explicit notice, provides express written consent, and is provided an opportunity to exercise the right to opt out, specifies notification requirements for businesses.

HI SB 2185
Status: Failed--adjourned
Excludes violations of privacy in the first degree and certain violations of privacy in the second degree, from qualifying for deferred acceptance of a guilty plea or nolo contendere plea. Limits the government use of facial recognition systems, except in certain circumstances.

Idaho

ID HB 492
Status: Failed - Adjourned
Establishes certain obligations for users of facial recognition technology, certain rights for individuals whose facial recognition data has been collected, and certain obligations with respect to accountability for public agencies that collect or use facial recognition technology.

Illinois

IL HB 1426
Status: Pending
Amends the Citizen Privacy Protection Act, makes a technical change in a section concerning the short title.

IL HB 2736
Status: Pending
Creates the Right to Know Act, provides that an operator of a commercial website or online service that collects personally identifiable information through the Internet about individual customers residing in who use or visit its commercial website or online service shall notify those customers of certain specified information pertaining to its personal information sharing practices.

IL HB 2785
Status: Pending
Creates the Geolocation Privacy Protection Act, defines geolocation information, location-based application, private entity, and user, provides that a private entity may not collect, use, store, or disclose geolocation information from a location-based application on a user's device unless the private entity first receives the person's affirmative express consent after complying with specified notice requirements, provides exceptions, provides that a violation of the act constitutes an unlawful practice.

IL HB 2871
Status: Pending
Creates the Data Broker Registration Act, requires a data broker to annually register with the Secretary of State, defines data broker as a business or unit of a business, separately or together, that knowingly collects and sells or licenses to third parties the brokered personal information of a consumer with whom the business does not have a direct relationship.

IL HB 3051
Status: Pending
Creates the App Privacy Protection Act, requires an entity that owns, controls, or operates a web site, online service or software application to identify in its customer agreements or applicable terms whether third parties collect electronic information directly from the digital devices of individuals in who use or visit its web site, online service or software application, requires the disclosure of the names of those third parties and the categories of information collected.

IL HB 3130
Status: Pending
Amends the Genetic Information Privacy Act, includes direct to consumer commercial genetic testing in the definition of genetic testing.

IL HB 3357
Status: Pending
Creates the Data Privacy Act, provides only a short title.

IL HB 3358
Status: Pending
Creates the Data Transparency and Privacy Act, finds that individuals have a right to privacy and a personal property interest in information pertaining to the individual, provides that an entity that collects through the Internet personal information about individual consumers must make disclosures to the individual regarding the collection of the information, establishes that a consumer has a right to opt out of the sale of the consumer's information, creates certain exemptions.

IL HB 4975
Status: Pending
Amends the Personal Information Protection Act, creates an intellectual property right in persons for the continued use of the individual's personal information when there is a failure to cure a violation within thirty days or when a person's personal information cannot be certified to be fully retrieved from an entity engaging in an unauthorized acquisition or those to whom the individual's data was further conveyed.

IL HB 5288
Status: Pending
Creates the Data Privacy Act, provides for the regulation of the use and sale of data, defines terms, establishes consumer rights to copies of information held by persons who control and process data, provides for the correction of inaccurate data, provides for restrictions on the use of personal data, provides for the enforcement of the Act by the Attorney General, provides civil penalties, preempts home rule.

IL HB 5374
Status: Pending
Amends the Biometric Information Privacy Act, changes the term of written release to written consent, provides that the written policy that is developed by a private entity in possession of biometric identifiers shall be made available to the person from whom biometric information is to be collected or was collected, provides that an action brought under the act shall be commenced within one year after the cause of action accrued under certain circumstances.

IL HB 5603
Status: Pending
Creates the Consumer Privacy Act, provides that a consumer has the right to request that a business that collects the consumer's personal information disclose to that consumer the categories and specific pieces of personal information the business has collected, requires a business to, at or before the point of collection, inform a consumer as to the categories of personal information to be collected and the purposes for which the categories of personal information shall be used.

IL SB 413
Status: Pending
Amends the Citizen Privacy Protection Act, makes a technical change in a section concerning the short title.

IL SB 907
Status: Pending
Amends the Citizen Privacy Protection Act, makes a technical change in a section concerning the short title.

IL SB 2134
Status: Pending
Amends the Biometric Information Privacy Act, deletes language creating a private right of action, provides instead that any violation that results from the collection of biometric information by an employer for employment, human resources, fraud prevention, or security purposes is subject to the enforcement authority of the Department of Labor, provides that an employee or former employee may file a complaint with the Department alleging a violation.

IL SB 2149
Status: Pending
Creates the Right to Know Data Transparency and Privacy Act, provides that an operator of a commercial website or online service that collects personally identifiable information through the Internet about individual customers residing in who use or visit its commercial website or online service shall notify those customers of certain specified information pertaining to its personal information sharing practices, requires an operator to make available certain specified information upon disclosing.

IL SB 2263
Status: Pending
Creates the Data Privacy Act, provides for the regulation of the use and sale of data, defines terms, establishes consumer rights to copies of information held by persons who control and process data, provides for the correction of inaccurate data, provides for restrictions on the use of personal data, provides for the enforcement of the Act by the Attorney General, provides civil penalties, preempts home rule.

IL SB 2273
Status: Pending
Creates the Automatic Listening Exploitation Act, defines terms, provides that it is unlawful for a person who provides any smart service through a proprietary smart speaker to store or make a recording or transcript of any speech or sound captured by a smart speaker, or use any storage or recording or transcript of any voice interaction by a user with the voice user interface, or transmit such a recording or transcript to a third party, for any purpose, without obtaining express informed consent.

IL SB 2330
Status: Pending
Creates the Data Transparency and Privacy Act, provides that any business that processes personal information or deidentified information must, prior to processing, provide notice to the consumer to whom the information refers or belongs of specific information in the service agreement or somewhere readily accessible on the business' website or mobile application, establishes a right to know for consumers and prescribes types of information that they may request of businesses.

IL SB 3299
Status: Pending
Creates the Consumer Privacy Act, provides that a consumer has the right to request that a business that collects the consumer's personal information disclose to that consumer the categories and specific pieces of personal information the business has collected, requires a business to, at or before the point of collection, inform a consumer as to the categories of personal information to be collected and the purposes for which the categories of personal information shall be used.

IL SB 3414
Status: Pending
Creates the Protecting Household Privacy Act, provides that a law enforcement agency shall not obtain household electronic data or direct the acquisition of household electronic data from a private party or other third party, provides exceptions, provides that if a law enforcement agency obtains household electronic data under the act, the agency shall destroy all information obtained.

IL SB 3591
Status: Pending
Amends the Biometric Information Privacy Act, deletes language that a prevailing party may recover damages against a private entity that negligently violates the act for each violation of the act, provides instead that a prevailing party may recover liquidated damages of a specified amount or actual damages, whichever is greater, and that such damages for a negligent violation by a private entity shall be recovered only for a single collection of each aggrieved party's biometric identifier.

IL SB 3593
Status: Pending
Amends the Biometric Information Privacy Act, changes the term of written release to written consent, provides that the written policy that is developed by a private entity in possession of biometric identifiers shall be made available to the person from whom biometric information is to be collected or was collected, provides that an action brought under the act shall be commenced within one year after the cause of action accrued.

IL SB 3776
Status: Pending
Amends the Biometric Information Privacy Act, provides that a prevailing party may only recover liquidated damages of $1,000 or actual damages, whichever is greater, for negligent violation of the Act against a private entity offending party that is not a current or former employer of the prevailing party, provides that a prevailing party may only recover actual damages against a private entity offending party that is the current or former employer of the prevailing party.

Louisiana

LA HB 617
Status: Failed - Adjourned
Provides relative to the protection of personally identifiable information.

LA HB 654
Status: Failed - Adjourned
Provides relative to the protection of personally identifiable information.

LA HB 662
Status: Failed - Adjourned
Provides relative to facial recognition software.

Massachusetts

MA HB 243
Status: Pending
Relates to the protection of personal identity.

MA HB 349
Status: Pending
Regulates advertising on the internet.

MA HB 350
Status: Pending
Relates to the online collection of personal information from children and minors.

MA HB 382
Status: Pending
Relates to the collection, use, disclosure or dissemination of personal information from customers of telecommunications or internet service providers.

MA HB 1403
Status: Pending
Relates to the online privacy of minors.

MA SB 120
Status: Pending
Relates to consumer data privacy.

MA SB 1936
Status: Pending
Promotes net neutrality and consumer protection.

Maryland

MD HB 249
Status: Failed
Authorizes consumers to demand that a business not disclose the consumer's personal information to third parties and to exercise the right to opt out of third-party disclosure through a certain setting, including a browser setting, browser extension, or global device setting, prohibits a business from disclosing the personal information of a consumer to a third party if the business has certain knowledge of or willfully disregards the fact the consumer is under the age of 18.

MD HB 307
Status: Failed - Adjourned
Requires each private entity in possession of biometric identifiers or biometric information to develop a written policy, made available to the public, establishing a certain retention schedule and guidelines for permanently destroying biometric identifiers and biometric information, requires each private entity in possession of biometric identifiers or biometric information to comply with the private entity's retention and destruction policies except under certain circumstances.

MD HB 752
Status: Failed
Prohibits a person from using a scanning device to scan or swipe an individual's identification card or a driver's license to obtain personal information, prohibits a person from retaining, selling, or transferring any information collected from scanning or swiping an individual's identification card or driver's license, provides that the Act does not prohibit a law enforcement officer from using a scanning device to record, retain, or transmit information if acting within their duties.

MD HB 784
Status: Failed
Requires certain businesses that collect a consumer's personal information to provide certain clear and conspicuous notices to the consumer at or before the point of collection, authorizes a consumer to submit a certain request for information to a certain business that collects the consumer's personal information, requires a certain business to comply with a certain request for information in a certain manner and within 45 days after receiving a verifiable consumer request.

MD HB 1065
Status: Failed - Adjourned
Prohibits a public service company and a contractor from sharing, disclosing, or otherwise making accessible to a third party a customer's personal information, subject to a certain exception, prohibits a public service company and a contractor from selling a customer's personal information, requires each public service company and contractor to use reasonable security procedures and practices to protect a customer's personal information from certain unauthorized actions.

MD HB 1578
Status: Failed - Adjourned
Expresses the sense of the General Assembly that facial recognition technology can present certain risks as well as provide a variety of benefits and that safeguards are necessary to allow the use of the technology in ways that benefit society, establishes certain requirements and certain prohibited actions relating to provision of facial recognition services by certain persons, prohibits certain governmental units from using facial recognition services under certain circumstances.

MD HB 1656
Status: Failed - Adjourned
Requires certain businesses that collect a consumer's personal information to provide certain clear and conspicuous notices to the consumer at or before the point of collection, authorizes a consumer to submit a certain request for information to a certain business that collects the consumer's personal information, requires a certain business to comply with a certain request for information in a certain manner and within a certain time, establishes the Consumer Privacy Fund.

MD SB 476
Status: Failed - Adjourned
Expresses the sense of the General Assembly that facial recognition technology can present certain risks as well as provide a variety of benefits and that safeguards are necessary to allow the use of the technology in ways that benefit society, establishes certain requirements and certain prohibited actions relating to provision of facial recognition services by certain persons, prohibits certain governmental units from using facial recognition services under certain circumstances.

MD SB 957
Status: Failed - Adjourned
Requires certain businesses that collect a consumer's personal information to provide certain clear and conspicuous notices to the consumer at or before the point of collection, authorizes a consumer to submit a certain request for information to a certain business that collects the consumer's personal information, requires a certain business to comply with a certain request for information in a certain manner and within a certain number of days after receiving a verifiable consumer request.

Maine

ME LR 2602
Status: Failed - Adjourned
Relates to an act to protect consumer privacy from providers of online content, applications or service.

ME LR 2878
Status: Failed - Adjourned
Relates to an act to expand protections for the privacy of online consumer information.

Michigan

MI HB 4658
Status: Pending
Regulates collection of personal information by scanning a machine readable, state issued driver's license or id card.

MI SB 172
Status: Enacted
Modifies requirements for insurers providing privacy policies to customers.

Minnesota

MN HB 112
Status: Failed - Adjourned
Relates to genetic information, modifies existing law on the use of genetic information by government entities, creates new consumer protection law regarding use of genetic information.

MN HB 1030
Status: Failed - Adjourned
Relates to telecommunications and data privacy, prohibits the collection of personal information absent a customer's express written approval.

MN HB 2917
Status: Failed - Adjourned
Relates to data privacy, requires controllers to provide, correct, or restrict processing of personal data upon a consumer's request, requires controllers to provide a privacy notice and document risk assessment, provides for liability and civil penalties, provides the attorney general with enforcement authority.

MN HB 2975
Status: Failed - Adjourned
Relates to data privacy, requires consent before providers share audio or video data with third parties.

MN HB 3096
Status: Failed - Adjourned
Relates to consumer data privacy, gives various rights to consumers regarding personal data, places data transparency obligations on businesses, creates a private right of action, provides for enforcement by the Attorney General.

MN HB 3936
Status: Failed - Adjourned
Relates to consumer data privacy, gives various rights to consumers regarding personal data, places obligations on businesses regarding consumer data, provides for enforcement by the attorney general, requires a report.

MN SB 433
Status: Failed - Adjourned
Relates to telecommunications, data privacy, prohibits collection of personal information absent customers express written approval.

MN SB 1553
Status: Failed - Adjourned
Relates to commerce, requires telecommunications service providers to comply with Internet privacy requirements, defines terms and modifying definitions, requires express approval of disclosure of personally identifiable information, increases civil liability threshold.

MN SB 2912
Status: Failed - Adjourned
Relates to data privacy, requires controllers to provide, correct, or restrict processing of personal data upon a consumer's request, requires controllers to provide a privacy notice and document risk assessment, provides for liability and civil penalties, provides the attorney general with enforcement authority.

MN SB 4247
Status: Failed - Adjourned
Relates to consumer data privacy, gives various rights to consumers regarding personal data, places obligations on businesses regarding consumer data, provides for enforcement by the attorney general, requires a report.

Missouri

MO HB 2375
Status: Failed - Adjourned
Changes the law regarding consumer protection and law enforcement by limiting the use of a person's biometric data.

Mississippi

MS SB 2548
Status: Failed
Creates the Mississippi Consumer Data Privacy Act, authorizes consumers to request that businesses disclose certain information, authorizes consumers to request that businesses delete personal information collected by businesses, requires businesses to disclose certain information to consumers, to inform consumers of their right to request that personal information be deleted, and to delete personal information collected about consumers upon request.

Nebraska

NE L 746
Status: Failed--adjourned
Adopts the Nebraska Consumer Data Privacy Act.

New Hampshire

NH HB 536
Status: Pending
Prohibits businesses from using, disclosing, or retaining biometric information about an individual.

NH HB 1236
Status: Pending
Establishes a cause of action for violations of an individual's expectation of privacy in personal information.

NH HB 1417
Status: Pending
Expands the prohibition against collecting biometric data to private entities.

NH HB 1466
Status: Failed
Establishes an exemption to the prohibition against scanning, recording, retaining, or storing information collected from drivers' licenses.

NH HB 1680
Status: Pending
Grants consumers the right to request that a business disclose the type of personal information it collects, the purpose for which it is collected, and the categories of third parties with which it is shared, authorizes consumers to opt out of the sale of their personal information, establishes a private right of action and provides for further enforcement by the attorney general.

NH SB 316
Status: Pending
Establishes criminal penalties for failure to protect another person's personal information.

New Jersey

NJ AB 1181
Status: Pending
Requires commercial Internet website and online service operators to conspicuously post their privacy policy.

NJ AB 2188
Status: Pending
Requires commercial Internet websites and online services to notify customers of the collection and disclosure of personally identifiable information and allow customers to opt out.

NJ AB 2340
Status: Pending
Prohibits commercial mobile service providers from disclosing customer's geolocation data to third parties.

NJ AB 2489
Status: Pending
Prohibits commercial mobile service providers and mobile application developers from disclosing customer's location data to third parties.

NJ AB 3072
Status: Pending
Concerns the Consumer Electronic Voice Recognition Information Act, prohibits operation of voice recognition feature on connected device before informing user of voice recognition feature during initial setup or installation of connected device.

NJ AB 3255
Status: Pending
Requires certain businesses to notify customers of certain information concerning the collection and sale of personally identifiable information and to allow customers to opt-in to collection and sale.

NJ AB 3283
Status: Pending
Relates to state Disclosure and Accountability Transparency Act (DATA), establishes certain requirements for disclosure and processing of personally identifiable information, establishes Office of Data Protection and Responsible Use in Division of Consumer Affairs.

NJ AB 3525
Status: Pending
Requires consumer reporting agencies to increase protection of consumers' personal information.

NJ SB 236
Status: Failed
Requires commercial Internet websites and online services to notify customers of collection and disclosure of personally identifiable information and allows customers to opt out.

NJ SB 269
Status: Pending
Requires certain businesses to notify data subjects of collection of personally identifiable information, establishes certain security standards.

NJ SB 1223
Status: Pending
Prohibits retail sales establishment from storing certain magnetic-stripe data, requires reimbursement for costs incurred by financial institution due to breach of security.

NJ SB 1257
Status: Pending
Requires commercial Internet websites and online services to notify consumers of collection and disclosure of personally identifiable information, allows consumers to opt out.

NJ SB 1317
Status: Pending
Requires consumer reporting agencies to increase protection of consumers' personal information.

New York

NY AB 235
Status: Pending
Relates to prohibiting private entities from using biometric data for any advertising, detailing, marketing, promotion, or any other activity that is intended to be used to influence business volume, sales or market share or to evaluate the effectiveness of marketing practices or marketing personnel.

NY AB 431
Status: Pending
Bans the sale of employment data reports without written consumer consent, provides such employment data reports shall include, but not be limited to, payroll and earnings information, hours worked, consumer history and health insurance information.

NY AB 1911
Status: Pending
Establishes the biometric privacy act, requires private entities in possession of biometric identifiers or biometric information to develop a written policy establishing a retention schedule and guidelines for permanently destroying biometric identifiers and biometric information when the initial purpose for collecting or obtaining such identifiers or information has been satisfied or within three years of the individual's last interaction with the private entity, whichever occurs first.

NY AB 2775
Status: Pending
Prohibits any person from disclosing health care information or personal information to a person who engages in the business of accessing and compiling information for commercial purposes or whose use of such information will be in connection with the marketing of a product or service without the explicit written authorization of the data subject.

NY AB 3308
Status: Pending
Regulates the collection, disclosure and dissemination of personal information acquired by a provider of on line computer services in order to ensure the privacy of subscriber information and wage patterns.

NY AB 3612
Status: Pending
Requires internet service providers to provide customers with a copy of their privacy policy and to obtain written and explicit permission from a customer prior to sharing, using, selling or providing to a third party any sensitive information of such customer.

NY AB 3739
Status: Pending
Amends the General Business Law, restricts the disclosure of personal information by businesses.

NY AB 3818
Status: Pending
Relates to establishing the Online Consumer Protection Act, defines terms, provides that an advertising network shall post clear and conspicuous notice on the home page of its own website about its privacy policy and its data collection and use practices related to its advertising delivery activities, makes related provisions.

NY AB 5306
Status: Pending
Relates to the use of voice recognition features on certain products.

NY AB 6351
Status: Pending
Grants a consumer a right to request a business to disclose the categories and specific pieces of personal information that it collects about the consumer, the categories of sources from which that information is collected, the business purposes for collecting or selling the information, and the categories of third parties with which the information is shared.

NY AB 7268
Status: Pending
Requires express and affirmative consent prior to collection, storage or transmittal of any personal information obtained from the installation or use of a smart home connected system by certain persons.

NY AB 7736
Status: Pending
Establishes the "It's Your Data Act" for the purposes of providing protections and transparency in the collection, use, retention, and sharing of personal information.

NY AB 8113
Status: Pending
Requires manufacturers of smart speakers to obtain signed written permission from users before storing voice recordings.

NY AB 8526
Status: Pending
Enacts the NY Privacy Act to require companies to disclose their methods of deidentifying personal information, to place special safeguards around data sharing, and to allow consumers to obtain the names of all entities with whom their information is shared, creates a special account to fund a new Office of Privacy and Data Protection.

NY SB 224
Status: Pending
Amends the General Business Law, restricts the disclosure of personal information by businesses.

NY SB 518
Status: Pending
Prohibits the disclosure of personally identifiable information by an internet service provider without the express written approval of the consumer.

NY SB 1180
Status: Pending
Prohibits internet service providers from disclosing personally identifiable information where a consumer requests that his or her information not be disseminated, defines terms, makes exceptions, imposes a civil penalty.

NY SB 1203
Status: Pending
Establishes the biometric privacy act, requires private entities in possession of biometric identifiers or biometric information to develop a written policy establishing a retention schedule and guidelines for permanently destroying biometric identifiers and biometric information when the initial purpose for collecting or obtaining such identifiers or information has been satisfied or within three years of the individual's last interaction with the private entity, whichever occurs first.

NY SB 1204
Status: Pending
Relates to the use of voice recognition features in certain products.

NY SB 1464
Status: Pending
Requires that internet service provider requirements keep all customer information confidential unless written consent is provided by the customer.

NY SB 2323
Status: Pending
Relates to establishing the online consumer protection act, defines terms, provides that an advertising network shall post clear and conspicuous notice on the home page of its own website about its privacy policy and its data collection and use practices related to its advertising delivery activities, makes related provisions.

NY SB 2398
Status: Pending
Amends the General Business Law, relates to the personal information of a credit or debit card holder, adds zip code, e-mail address and home, cell and work telephone Numbers to the personal information protected.

NY SB 2500
Status: Pending
Relates to prohibiting private entities from using biometric data for any advertising, detailing, marketing, promotion, or any other activity that is intended to be used to influence business volume, sales or market share or to evaluate the effectiveness of marketing practices or marketing personnel.

NY SB 3147
Status: Pending
Requires retailers to post warning signs of the tracking of customers through cell phones or other electronic devices, provides for civil penalties.

NY SB 3970
Status: Pending
Bans the sale of employment data reports without written consumer consent, provides such employment data reports shall include, but not be limited to, payroll and earnings information, hours worked, consumer history and health insurance information.

NY SB 4411
Status: Pending
Grants a consumer a right to request a business to disclose the categories and specific pieces of personal information that it collects about the consumer, the categories of sources from which that information is collected, the business purposes for collecting or selling the information, and the categories of third parties with which the information is shared.

NY SB 5245
Status: Pending
Relates to the sale of personal information by an internet service provider.

NY SB 5642
Status: Pending
Enacts the NY Privacy Act to require companies to disclose their methods of deidentifying personal information, to place special safeguards around data sharing, and to allow consumers to obtain the names of all entities with whom their information is shared, creates a special account to fund a new Office of Privacy and Data Protection.

NY SB 6848
Status: Pending
Relates to requiring registration of data brokers and directing the attorney general to maintain a website of such registrations.

NY SB 7641
Status: Pending
Requires manufacturers of smart speakers to obtain signed written permission from users before storing voice recordings.

Pennsylvania

PA HB 1049
Status: Pending
Provides for consumer data privacy, provides for rights of consumers and duties of businesses relating to the collection of personal information and for duties of the Attorney General.

Rhode Island

RI HB 7778
Status: Pending
Creates the Transparency and Privacy Protection Act to require online service providers and commercial websites that collect, store, and sell personally identifiable information, to disclose what categories of personally identifiable information they collect and to what third parties they sell the information.

RI SB 2430
Status: Pending
Creates the Consumer Privacy Protection Act, requires businesses that collect, maintain or sell personal information to notify consumers and disclose the information and the businesses' use of the information, provides that consumers may opt out and have personal information deleted.

South Carolina

SC HB 4812
Status: Pending
Enacts the Biometric Data Privacy Act, provides certain requirements for a business that collects a consumer's biometric information, allows the consumer to request that a business delete the collected biometric information and to prohibit the sale of biometric information, establishes certain standards of care for a business that collects biometric information, establishes a procedure for a consumer to opt out of the sale of biometric information.

South Dakota

SD SB 185
Status: Failed
Regulates the use of facial recognition technology.

Tennessee

TN SB 1841
Status: Failed - Adjourned
Prohibits a direct-to-consumer genetic testing business entity from sharing personally identifiable genetic test data or other personally identifiable information about a consumer with a third party without the express written consent of the consumer or a subpoena or court order.

Utah

UT SB 249
Status: Failed
Enacts the Utah Consumer Privacy Act.

Virginia

VA HB 473
Status: Pending - Carryover
Relates to personal data, relates to Virginia Privacy Act, gives consumers the right to access their data and determine if it has been sold to a data broker, requires a controller, defined in the bill as a person that, alone or jointly with others, determines the purposes and means of the processing of personal data, to facilitate requests to exercise consumer rights regarding access, correction, deletion, restriction of processing, data portability, objection, and profiling.

VA HB 955
Status: Pending - Carryover
Relates to children's online privacy protection, prohibits any person who operates a website for commercial purposes and who collects or maintains personal information from or about the users of or visitors to such website or online service from releasing personal information collected from minor for any purpose, except where the personal information is provided to a person other than an operator that provides support for the internal operations of the website, online service, or online application.

VA SB 101
Status: Enacted
Relates to scanning information from driver's license, allows a merchant to scan the machine readable zone of an individual's Department of Motor Vehicles issued identification card or driver's license in order to verify authenticity of such or to verify the identity of the individual when the individual requests a service pursuant to a membership or a service agreement, allows the merchant to conduct such a scan for identity verification.

VA SB 641
Status: Pending - Carryover
Relates to civil action, relates to sale of personal data, requires a person that disseminates, obtains, maintains, or collects personal data about a consumer for a fee to implement security practices to protect the confidentiality of a consumer's personal data, obtain express consent of a blank of a minor before selling the personal data of such minor, provide access to consumers to their own personal data that is held by the entity, and refrain from maintaining or selling data.

Vermont

VT HB 157
Status: Pending
Relates to adopting minimum security standards for connected devices.

VT HB 899
Status: Pending
Relates to promoting consumer protection in data and technology.

Washington

WA HB 1503
Status: Failed--adjourned
Concerns registration and consumer protection obligations of data brokers.

WA HB 1854
Status: Failed--adjourned
Protects consumer data.

WA HB 2046
Status: Failed--adjourned
Increases consumer data transparency.

WA HB 2742
Status: Failed--adjourned
Concerns the management and oversight of personal data.

WA HB 2759
Status: Failed--adjourned
Creates a consumer data bill of rights.

WA SB 5376
Status: Failed--adjourned
Protects consumer data.

WA SB 5377
Status: Failed--adjourned
Concerns data sales and governance.

WA SB 6281
Status: Failed--adjourned
Concerns the management and oversight of personal data.

Wisconsin

WI AB 870
Status: Failed
Relates to consumer access to personal data processed by a controller, provides a penalty.

WI AB 871
Status: Failed
Relates to the deletion of consumer personal data by controllers, provides a penalty.

WI AB 872
Status: Failed
Restricts controllers from using consumer personal data, provides a penalty.

WI SB 851
Status: Failed
Concerns the privacy of consumer data, grants rule making authority, provides a penalty.

West Virginia

WV HB 4106
Status: Failed--adjourned
Relates to the Biometric Information Privacy Act.

WV HB 4898
Status: Failed--adjourned
Imposes a general data mining service tax on commercial data operators.

WV SB 260
Status: Failed--adjourned
Collects of personal information by retail establishments for certain purposes.

Puerto Rico

PR SB 1231
Status: Pending
Creates the Law for the Protection of Digital Privacy in order to protect the personal information of consumers and guarantee the right to privacy in the digital era.

 

State Net logo

LexisNexis Terms and Conditions

Additional Resources