{"id":17479,"date":"2024-01-29T12:40:42","date_gmt":"2024-01-29T17:40:42","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=17479"},"modified":"2024-07-16T11:16:52","modified_gmt":"2024-07-16T15:16:52","slug":"consumer-data-privacy-laws-in-the-us","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/consumer-data-privacy-laws-in-the-us\/","title":{"rendered":"The Ultimate Guide to 13 U.S. Data Privacy Laws (And What They Mean to Your Business)"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"h-it-seems-like-every-time-you-turn-around-new-u-s-data-privacy-laws-are-popping-up-the-united-states-is-an-expansive-country-made-up-of-50-individual-governing-states-many-of-which-are-taking-different-approaches-to-protecting-data-privacy-we-ll-explore-the-list-of-u-s-data-privacy-laws-by-state\">It seems like every time you turn around, new U.S. data privacy laws are popping up. The United States is an expansive country made up of 50 individual governing states, many of which are taking different approaches to protecting data privacy. We\u2019ll explore the list of U.S. data privacy laws by state.<\/h2>\n\n\n\n<p>There are dozens of <a href=\"https:\/\/www.thesslstore.com\/blog\/10-data-privacy-and-encryption-laws-every-business-needs-to-know\/\">data security and encryption laws<\/a> that have popped up globally over the past couple of decades. The same can be said regarding data privacy laws in the U.S. However, not all of them passed muster and continued on to be signed in their state or country. With the <a href=\"omagazine.com\/data-privacy\/the-data-privacy-disconnect-between-businesses-and-consumers\/\">increasing expectation of data privacy<\/a> amongst consumers, it makes sense that we\u2019d see an influx in these laws in the U.S.&nbsp;<\/p>\n\n\n\n<p>That\u2019s why this article will focus on the 13 data privacy laws in the U.S. that have been signed, and how they can (or will) impact your organization\u2019s data security systems and processes. &nbsp;<\/p>\n\n\n\n<p>If you\u2019re planning to read this article the whole way through, great! Just be sure to grab yourself a cup of coffee \u2014 you\u2019re going to be here a while. Otherwise, if you don\u2019t want to slog through all states\u2019 laws, select your state of interest in the Table of Contents list below.<\/p>\n\n\n\n<p>Let\u2019s hash it out.<span id=\"newline\"><\/span><\/p>\n\n\n<span style=\"--tl-form-height-m:150.25px;--tl-form-height-t:121.4583px;--tl-form-height-d:121.4583px;\" class=\"tl-placeholder-f-type-shortcode_12753 tl-preload-form\"><span><\/span><\/span>\n\n\n<div class=\"wp-block-yoast-seo-table-of-contents yoast-table-of-contents\"><h2>Table of Contents for U.S. Data Privacy Laws (Listed By State)<\/h2><ul><li><a href=\"#h-it-seems-like-every-time-you-turn-around-new-u-s-data-privacy-laws-are-popping-up-the-united-states-is-an-expansive-country-made-up-of-50-individual-governing-states-many-of-which-are-taking-different-approaches-to-protecting-data-privacy-we-ll-explore-the-list-of-u-s-data-privacy-laws-by-state\" data-level=\"2\">It seems like every time you turn around, new U.S. data privacy laws are popping up. The United States is an expansive country made up of 50 individual governing states, many of which are taking different approaches to protecting data privacy. We\u2019ll explore the list of U.S. data privacy laws by state.<\/a><\/li><li><a href=\"#h-why-we-have-state-laws-instead-of-a-federal-u-s-data-privacy-law\" data-level=\"2\">Why We Have State Laws Instead of a Federal (U.S.) Data Privacy Law<\/a><\/li><li><a href=\"#h-a-breakdown-of-the-13-u-s-data-privacy-laws-by-state\" data-level=\"2\">A Breakdown of the 13 U.S. Data Privacy Laws (By State)<\/a><ul><li><a href=\"#h-1-california-california-consumer-privacy-act-ccpa\" data-level=\"3\">1. California \u2014 California Consumer Privacy Act (CCPA)<\/a><\/li><li><a href=\"#h-2-colorado-privacy-act-cpa\" data-level=\"3\">2. Colorado Privacy Act (CPA)<\/a><\/li><li><a href=\"#h-3-connecticut-act-concerning-personal-data-privacy-and-online-monitoring-ctdpa\" data-level=\"3\">3. Connecticut \u2014 Act Concerning Personal Data Privacy and Online Monitoring (CTDPA)<\/a><\/li><li><a href=\"#h-4-delaware-personal-data-privacy-act-dpdpa\" data-level=\"3\">4. Delaware Personal Data Privacy Act (DPDPA)<\/a><\/li><li><a href=\"#h-5-florida-digital-bill-of-rights-fdbr\" data-level=\"3\">5. Florida Digital Bill of Rights (FDBR)<\/a><\/li><li><a href=\"#h-6-indiana-consumer-data-protection-act-icdpa\" data-level=\"3\">6. Indiana Consumer Data Protection Act (ICDPA)<\/a><\/li><li><a href=\"#h-7-iowa-consumer-data-protection-act-idpa\" data-level=\"3\">7. Iowa Consumer Data Protection Act (IDPA)<\/a><\/li><li><a href=\"#h-8-montana-consumer-data-privacy-act-mcdpa\" data-level=\"3\">8. Montana Consumer Data Privacy Act (MCDPA)<\/a><\/li><li><a href=\"#h-9-oregon-consumer-data-privacy-act-ocdpa\" data-level=\"3\">9. Oregon Consumer Data Privacy Act (OCDPA)<\/a><\/li><li><a href=\"#h-10-tennessee-information-protection-act-tipa\" data-level=\"3\">10. Tennessee Information Protection Act (TIPA)<\/a><\/li><li><a href=\"#h-11-texas-data-privacy-and-security-act-tdspa\" data-level=\"3\">11. Texas Data Privacy and Security Act (TDSPA)<\/a><\/li><li><a href=\"#h-12-utah-consumer-privacy-act-ucpa\" data-level=\"3\">12. Utah Consumer Privacy Act (UCPA)<\/a><\/li><li><a href=\"#virginia-cdpa\" data-level=\"3\">13. Virginia Consumer Data Privacy Act (CDPA)<\/a><\/li><\/ul><\/li><\/ul><\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-why-we-have-state-laws-instead-of-a-federal-u-s-data-privacy-law\">Why We Have State Laws Instead of a Federal (U.S.) Data Privacy Law<\/h2>\n\n\n\n<p>\u201cEverybody wants a federal privacy law,\u201d said Debra J Farber, a Privacy Tech Advisor and Strategist during a <a href=\"https:\/\/www.youtube.com\/watch?v=Z-CVZ9z1Mik\">podcast interview with privacy evangelist Robert Bateman<\/a>. \u201cThis is why we can\u2019t have nice things. It\u2019s because no one could agree what goes in that law. And the things that we can\u2019t agree on don\u2019t have anything to do with privacy itself.\u201d<\/p>\n\n\n\n<p>Frankly, she\u2019s right. There are many politicians from every state who want to have their say and stick their hands in the pot. (Ah, bureaucracy.) With that many egos and individual agendas, there\u2019s no way to have a consensus about what should or shouldn\u2019t be included in a federal law.<\/p>\n\n\n\n<p>So, for now, we\u2019ll focus on what individual states are doing with regard to laws that have been signed into law as of the writing of this article (January 2024).<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-a-breakdown-of-the-13-u-s-data-privacy-laws-by-state\">A Breakdown of the 13 U.S. Data Privacy Laws (By State)<\/h2>\n\n\n\n<p>For those of you who bothered skimming ahead and counting the listed pieces of legislation in the article, you might argue that there are 15 laws listed instead of 13. Our response? We\u2019re saying 13 because 2 of the pieces of legislation that we\u2019ll cover either amend or add to the CCPA specifically, so we\u2019re not giving them separate numbers in the overall list count.<\/p>\n\n\n\n<p>Anyhow, there\u2019s <em>way<\/em> too much information to dive in-depth into each of these laws. So, we\u2019ll try to just hit the highlights and identify the things you want (and need to know):<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>What each law is,<\/li>\n\n\n\n<li>What it does (in terms of consumer rights),<\/li>\n\n\n\n<li>Who it applies to, and<\/li>\n\n\n\n<li>How it impacts (or will impact) your business once in effect.&nbsp;<\/li>\n<\/ul>\n\n\n\n<p>Generally speaking, the majority of these laws cover many of the same things:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Requiring businesses to respond to authenticated consumer requests to exercise their rights under the law. Emphasis on <em>authenticated<\/em> requests. Many of the laws don\u2019t specify how the consumer is to be authenticated; rather, they just say that they must be authenticated by \u201creasonable means.\u201d<\/li>\n\n\n\n<li>Ensure that covered consumers or residents have the right to access, correct, delete, and opt out of sharing and\/or selling their personal data for certain uses.<\/li>\n\n\n\n<li>Require covered organizations to provide privacy notices on their websites that inform consumers or state residents about how they can exercise their rights under the respective law.<\/li>\n\n\n\n<li>Have specific requirements relating to the sharing and processing of de-identified data or pseudonymous data. (In many cases, however, this data is excluded from consumer data requests.)<\/li>\n\n\n\n<li>Require organizations to implement physical, technical and administrative security protections, controls and practices to <a href=\"https:\/\/www.thesslstore.com\/blog\/how-much-data-is-in-the-world-and-how-do-you-secure-it\/\">secure data<\/a>. Although many laws don&#8217;t explicitly mention encryption (e.g., SSL\/TLS encryption) as a security measure, it&#8217;s certainly something that would fall under the umbrella of &#8220;<a href=\"https:\/\/iapp.org\/news\/a\/the-evolution-of-reasonable-security-derived-from-ftc-orders-and-state-legal-developments\/\">reasonable security<\/a>.&#8221; Of course, if you&#8217;re using digital certificates to protect data in transit, then you&#8217;ll need to also ensure that you&#8217;re adhering to certificate management best practices. <\/li>\n\n\n\n<li>Prohibit the use of this data for discriminatory practices (charging different prices, denying goods or services, etc.)<\/li>\n\n\n\n<li>Protect the personal data of children and teenagers (although the ages often range from 13 to 16, depending on the specific law).<\/li>\n\n\n\n<li>Require businesses to establish appeal processes and, in some cases, establish \u201cuniversal mechanisms\u201d for opt-out requests.<\/li>\n<\/ul>\n\n\n\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link has-central-palette-2-background-color has-text-color has-background wp-element-button\" href=\"https:\/\/www.thesslstore.com\/products\/ssl.aspx\" style=\"border-radius:3px;color:#ffffff\">Shop SSL\/TLS Certificates<\/a><\/div>\n\n\n\n<p><\/p>\n\n\n\n<p>Here\u2019s a quick overview of the different laws and the rights they provide:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"531\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/us-data-privacy-laws-comparison-table-final-1024x531.png\" alt=\"U.S. data privacy laws graphic: This comparison table that shows the similarities and differences between data privacy laws by state. \" class=\"wp-image-17481\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/us-data-privacy-laws-comparison-table-final-1024x531.png 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/us-data-privacy-laws-comparison-table-final-300x156.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/us-data-privacy-laws-comparison-table-final-768x399.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/us-data-privacy-laws-comparison-table-final.png 1480w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Image caption: A comparison table that shows an overview of some of the key consumer data privacy rights afforded by many of the state laws we talk about in this article. <\/em><\/figcaption><\/figure>\n\n\n\n<p>One of the interesting differences between many of the laws is how they define or categorize \u201cpersona\u201d and \u201csensitive\u201d data. For example, while most laws include \u201csexual orientation\u201d or \u201csex life\u201d as covered categories of sensitive data, some states (i.e., Delaware and Oregon) specifically mention nonbinary and transgender statuses in their definitions. &nbsp;<\/p>\n\n\n\n<p>Of course, there are also plenty of particulars each law includes in its requirements \u2014 and we can\u2019t cover all of them in this article. But we will briefly cover the key points of each law individually in the content below. To keep things easy, we\u2019ve organized the laws by state (and alphabetically for states that have more than one law we\u2019ve covered).<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"615\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/us-data-privacy-laws-state-state-map-1024x615.png\" alt=\"Data privacy laws in the U.S. graphic: This map breaks down the list of U.S. data privacy laws by state, showing which ones are in effect and which ones are not yet effective.\" class=\"wp-image-17482\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/us-data-privacy-laws-state-state-map-1024x615.png 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/us-data-privacy-laws-state-state-map-300x180.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/us-data-privacy-laws-state-state-map-768x461.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/us-data-privacy-laws-state-state-map-698x419.png 698w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/us-data-privacy-laws-state-state-map-400x240.png 400w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/us-data-privacy-laws-state-state-map-460x276.png 460w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/us-data-privacy-laws-state-state-map.png 1440w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Image caption: This map provides an overview of laws that are in effect, will soon be in effect, or have no laws signed or currently in effect. It does not include laws that are in progress but have not yet been signed. This map was created using <a href=\"https:\/\/www.mapchart.net\/usa.html\">MapChart.net&#8217;s generator tool<\/a>.<\/em><\/figcaption><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-1-california-california-consumer-privacy-act-ccpa\">1. California \u2014 California Consumer Privacy Act (CCPA)<\/h3>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignright size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"529\" height=\"861\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/CA-CCPA-CPRA-DELETE-ACT.jpg\" alt=\"An illustration of the state of California that lists the CCPA law and two amendments\" class=\"wp-image-17487\" style=\"width:208px;height:auto\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/CA-CCPA-CPRA-DELETE-ACT.jpg 529w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/CA-CCPA-CPRA-DELETE-ACT-184x300.jpg 184w\" sizes=\"auto, (max-width: 529px) 100vw, 529px\" \/><\/figure>\n<\/div>\n\n\n<h4 class=\"wp-block-heading\" id=\"h-what-it-is\">What It Is<\/h4>\n\n\n\n<p>The <a href=\"https:\/\/leginfo.legislature.ca.gov\/faces\/billTextClient.xhtml?bill_id=201720180AB375\">California Consumer Privacy Act<\/a> (Assembly Bill No. 375 [AB-375]) was enacted in 2018 and served as the first-of-its-kind legislation in the United States. Loosely based on the European Union\u2019s General Data Protection Regulation (GDPR), it serves to protect California consumers by supporting their rights regarding the processing, use, storage, and deletion of their personal data.<\/p>\n\n\n\n<p>While CCPA served as a starting point, many states have since shifted to data privacy and security laws modeled after <a href=\"#virginia-cdpa\">Virginia\u2019s state law<\/a>.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-what-it-does\">What It Does<\/h4>\n\n\n\n<p>The CCPA outlines several crucial rights of consumers (or their authorized representatives):<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Right to know what personal or biometric information a business collected about them in the previous 12 months (and how that information is collected, shared, or sold),<\/li>\n\n\n\n<li>Right to opt out of having their information collected and\/or sold,<\/li>\n\n\n\n<li>Right to delete data (with some exceptions), and<\/li>\n\n\n\n<li>Right to not be discriminated against or penalized for exercising their rights to delete or opt out of data collection, storage, or usage under the CCPA.<\/li>\n<\/ul>\n\n\n\n<p>Of course, this law doesn\u2019t only apply to data collected over the internet or via other electronic means; it also applies to all types of consumer data that businesses collect, regardless of how it\u2019s collected.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-who-the-law-applies-to\">Who the Law Applies To<\/h4>\n\n\n\n<p>Does the law apply to you? It depends. If you\u2019re an organization that meets one or more of the following thresholds, then yes:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Achieves $25+ million in annual gross revenues.<\/li>\n\n\n\n<li>Buys, receives, sells, or shares the personal info of 50,000+ consumers, households, or devices annually.<\/li>\n\n\n\n<li>Gets 50% of its annual revenues from the sales of consumers\u2019 personal data.<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-how-it-affects-your-business\">How It Affects Your Business<\/h4>\n\n\n\n<p>Now that we know what the law does and who it applies to, let\u2019s bring it all home to see what this means from a business\u2019s perspective. In a nutshell, you\u2019re expected to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Clearly disclose to California consumers what personal information is being collected, used, and stored (upon request);<\/li>\n\n\n\n<li>Provide a means for affected consumers to opt out with a \u201cDo Not Sell My Personal Information\u201d page on your site;<\/li>\n\n\n\n<li>Face non-compliance penalties or payments for damages caused by CCPA disclosure violations (intentional or otherwise);<\/li>\n\n\n\n<li>Disclose information to a consumer within 45 days of receiving a verifiable request (although not more than twice in a 12-month period).<\/li>\n<\/ul>\n\n\n\n<p>A couple of years after the CCPA was released, another piece of legislation was published that amended certain components of the law. That\u2019s what we\u2019re going to discuss next.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-california-privacy-rights-act-of-2020-cpra\">California Privacy Rights Act of 2020 (CPRA)<\/h4>\n\n\n\n<h5 class=\"wp-block-heading\" id=\"h-what-it-is-1\">What It Is<\/h5>\n\n\n\n<p>Before we go any further, let\u2019s quickly clarify one important point: although it\u2019s commonly referred to as such, CPRA is <em>not<\/em> a new <em>law<\/em>. Rather, it\u2019s strictly an <strong><em>amendment<\/em><\/strong> of the first law (CCPA), and as such, is often referred to as \u201c<a href=\"https:\/\/oag.ca.gov\/privacy\/ccpa\">CCPA, as amended<\/a>.\u201d It also sets the groundwork for establishing the California Privacy Protection Agency (CPPA) in 2020.<\/p>\n\n\n\n<p>Ugh. CCPA, CPPA, and CPRA. Gee, that\u2019s not confusing at all\u2026<\/p>\n\n\n\n<p>Now that we have all of that out of the way, let\u2019s continue with exploring this amendment.<\/p>\n\n\n\n<h5 class=\"wp-block-heading\" id=\"h-what-it-does-1\">What It Does<\/h5>\n\n\n\n<p>CPRA, which kicked into effect on January 1, 2023 (with a few provisions that kicked in on July 1, 2023), serves to amend the language of the 2018 CCPA and updates the state\u2019s civil code. In a nutshell, it was <a href=\"https:\/\/www.caprivacy.org\/your-privacy-rights\/\">passed as part of Proposition 24<\/a>, and gives consumers additional rights on top of those provided by CCPA:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Correct inaccurate personal information, and<\/li>\n\n\n\n<li>Limit the use and disclosure of their sensitive information. &nbsp;<\/li>\n<\/ul>\n\n\n\n<p>Does this mean that the CCPA requirements are no longer valid now that CPRA has kicked into effect? Not quite. While CPRA\u2019s amendments are now in effect, the non-amended CCPA requirements are also still in effect.<\/p>\n\n\n\n<h5 class=\"wp-block-heading\" id=\"h-who-the-law-applies-to-1\">Who the Law Applies To<\/h5>\n\n\n\n<p>As a business or organization that collects, uses, or stores the personal information of California consumers, this means you must abide by the rules of the CCPA, including the amendments specified in CPRA, if you meet at least one of the following criteria:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Your organization has $25+ million in annual gross revenues in the preceding calendar year;<\/li>\n\n\n\n<li>You buy, sell, or share the personal information of \u201c100,000 or more consumers or households\u201d (which doubles the CCPA\u2019s 50,000-consumer requirement and removes the \u201cdevices\u201d from that part of the language); and\/or<\/li>\n\n\n\n<li>Your organization derives at least 50% of its annual revenues from selling <em>or sharing<\/em> consumers\u2019 personal information. &nbsp;&nbsp;<\/li>\n<\/ul>\n\n\n\n<p>While this applies to many businesses, including data brokers, there are exemptions for certain businesses as stipulated under the state\u2019s <a href=\"http:\/\/leginfo.legislature.ca.gov\/faces\/codes_displayText.xhtml?lawCode=CIV&amp;division=3.&amp;title=1.81.48.&amp;part=4.&amp;chapter=&amp;article=\">Civil Code section 1798.99.80<\/a>.<\/p>\n\n\n\n<h5 class=\"wp-block-heading\" id=\"h-how-it-affects-your-business-1\">How It Affects Your Business<\/h5>\n\n\n\n<p>So, what does all of this mean for you? Businesses that control the collection of personal data shall \u201cat or before the point of collection,\u201d inform consumers about the following:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>What categories of information have been collected during the \u201capplicable period of time\u201d (no longer specifying 12 months),<\/li>\n\n\n\n<li>Why the data is being collected,<\/li>\n\n\n\n<li>Whether the information will be shared or sold, and<\/li>\n\n\n\n<li>How long the business will retain the personal info.<\/li>\n<\/ul>\n\n\n\n<p>For consumers who submit CPRA requests, businesses must provide, update, or delete the consumer\u2019s personal information within 45 days of receiving a verifiable request. If an extension is needed, the business must provide adequate notice to the customer within the first 45-day period.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-the-delete-act-of-2023\">The DELETE Act of 2023<\/h4>\n\n\n\n<h5 class=\"wp-block-heading\" id=\"h-what-it-is-2\">What It Is<\/h5>\n\n\n\n<p>Senate Bill 362 \u201c<a href=\"https:\/\/leginfo.legislature.ca.gov\/faces\/billNavClient.xhtml?bill_id=202320240SB362\">Data Broker Registration: Accessible Deletion Mechanism<\/a>,\u201d more commonly known as the Delete Act, is another piece of legislation that builds upon the CCPA. More specifically, it aims to streamline the process consumers must go through to exercise their CCPA rights. The goal is to establish a one-stop place where California residents can go to delete their personal data held by businesses quickly and easily.<\/p>\n\n\n\n<p>Senate Bill (S.B. 362) was signed into law on Oct. 10, 2023. The CPPA\u2019s deletion mechanism must be created by Jan. 1, 2026, and will involve a series of phased rollouts that span out to 2028. &nbsp;<\/p>\n\n\n\n<h5 class=\"wp-block-heading\" id=\"h-what-it-does-2\">What It Does<\/h5>\n\n\n\n<p>It shifts many of the responsibilities regarding the CCPA, CPRA, and data broker-related provisions to the California Privacy Protection Agency (CPPA).&nbsp; It also calls for the creation of an \u201caccessible deletion mechanism\u201d that enables California consumers to request all data brokers\u2019 (and their associated service providers or contractors) delete their data \u201cthrough a single verifiable consumer request.\u201d<\/p>\n\n\n\n<p>Basically, starting Jan. 1, 2026, the CPPA must have an established place for consumers to go (e.g., a single webpage) to submit a single request to have their information deleted.<\/p>\n\n\n\n<h5 class=\"wp-block-heading\" id=\"h-who-the-law-applies-to-2\">Who the Law Applies To<\/h5>\n\n\n\n<p>Data brokers, which are defined as \u201ca business that knowingly collects and sells to third parties the personal information of a consumer with whom the business does not have a direct relationship.\u201d All applicable data brokers must <a href=\"https:\/\/cppa.ca.gov\/faq.html\">register through the California Privacy Protection Agency<\/a> by no later than Jan. 31 following the year in which a business first meets the \u201cdata broker\u201d definition.<\/p>\n\n\n\n<h5 class=\"wp-block-heading\" id=\"h-how-it-affects-your-business-2\">How It Affects Your Business<\/h5>\n\n\n\n<p>If you\u2019re a data broker, then here are some of the ways that the bill will impact you starting on the following dates:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Jan. 31:<\/strong> Organizations that meet the definition of a data broker, on or before this date each year, must register with the CPPA and pay any registration fees. If you fail to register, you\u2019ll face administrative fines and will face administrative actions. There are additional reporting requirements that must be met before July 1 following each year your organization meets the definition of a data broker.<\/li>\n\n\n\n<li><strong>Starting Aug. 1, 2026:<\/strong> Every 45 days, you\u2019ll have to access the mechanism and process the deletions (with exceptions). The bill stipulates that the CPPA can charge a fee to access the mechanism. &nbsp;<\/li>\n\n\n\n<li><strong>Jan. 1, 2028:<\/strong> Starting on this date and every three years after, you\u2019ll undergo a third-party audit to verify your compliance and will be required to submit a report of said audit to the CPPA (upon written request).&nbsp;<\/li>\n<\/ul>\n\n\n\n<p>Data brokers who fail to meet the registration requirements will be fined at least $200 daily to cover any administrative and investigative expenses that will be incurred by the CPPA relating to the violation. A $200 fine also applies (deletion per request) for data brokers who fail to delete data as requested.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-2-colorado-privacy-act-cpa\">2. Colorado Privacy Act (CPA)<\/h3>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignright size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"529\" height=\"525\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/CO-CPA.jpg\" alt=\"An illustration of the state of Colorado that lists the CPA law\" class=\"wp-image-17488\" style=\"width:275px;height:auto\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/CO-CPA.jpg 529w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/CO-CPA-300x298.jpg 300w\" sizes=\"auto, (max-width: 529px) 100vw, 529px\" \/><\/figure>\n<\/div>\n\n\n<h4 class=\"wp-block-heading\" id=\"h-what-it-is-3\">What It Is<\/h4>\n\n\n\n<p>The <a href=\"https:\/\/leg.colorado.gov\/sites\/default\/files\/2021a_190_signed.pdf\">Colorado Privacy Act<\/a> (CPA), which was signed on July 7, 2021 as Senate Bill 21-190 (SB 21-190), took effect on July 1, 2023. According to the legislative text, the law aims to make Colorado \u201camong the states that empower consumers to protect their privacy and require companies to be responsible custodians of data as they continue to innovate[.]\u201d<\/p>\n\n\n\n<p>The CPA offers protection to Colorado consumers in non-professional contexts, meaning in their individual or household lives. (It doesn\u2019t offer the same protections for Colorado residents in their employment-related contexts.)<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-what-it-does-3\">What It Does<\/h4>\n\n\n\n<p>The Colorado CPA enables consumers to have greater control of the data that data controllers can collect, use, sell, and share. For example, it protects the following rights:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Know what personal information is being collected about them.<\/li>\n\n\n\n<li>Access to the data in an easy-to-access format.<\/li>\n\n\n\n<li>Make corrections to or delete any of the individuals\u2019 personal data.<\/li>\n\n\n\n<li>Opt out of the collection, use, and sale of data collected for \u201ctargeted advertising and certain types of profiling.\u201d<\/li>\n<\/ul>\n\n\n\n<p>But what exactly is considered \u201cpersonal data\u201d in this situation? It depends on the context. Generally speaking, any sensitive data linked (or reasonably linked) to a consumer that isn\u2019t de-identified, publicly available (i.e., government-provided information or information shared publicly by consumers), or collected via employment or business-to-business interactions.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-who-the-law-applies-to-3\">Who the Law Applies To<\/h4>\n\n\n\n<p><a href=\"https:\/\/coag.gov\/resources\/colorado-privacy-act\/#:~:text=Who%20is%20responsible%20for%20complying,have%20responsibilities%20under%20the%20CPA.\">The law applies to organizations<\/a>, including non-profits, that conduct business in CO and meet one or both of the following:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Control or process the personal data of 100,000 Colorado residents each calendar year, or<\/li>\n\n\n\n<li>Generates revenue or receives discounted services as the result of processing or selling 25,000 Colorado residents\u2019 personal data.<\/li>\n<\/ul>\n\n\n\n<p>It also applies to the vendors, contractors, or service providers who handle the sensitive consumer data provided by these organizations. However, there are exceptions for some depending on their compliance requirements (see \u00a76-1-1304 of the CPA) for additional info.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-how-it-affects-your-business-3\">How It Affects Your Business<\/h4>\n\n\n\n<p>There are many ways this law affects you if you\u2019re doing any business involving Colorado residents because it\u2019s focused on transparency and informed consent. As such, you must:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Be open about what you\u2019re collecting and using the data for and respond to residents\u2019 requests for information.<\/li>\n\n\n\n<li>Get affirmative consent from users in multiple circumstances and use the data for your specified purpose(s) only.<\/li>\n\n\n\n<li>Clearly define your role as a data collector or processor. If your organization qualifies as both, then it\u2019ll fall under the controller categorization by default.<\/li>\n\n\n\n<li>Carry out data protection assessments prior to selling or processing personal or sensitive data.<\/li>\n\n\n\n<li>Secure the data using \u201creasonable security practices.\u201d<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-3-connecticut-act-concerning-personal-data-privacy-and-online-monitoring-ctdpa\">3. Connecticut \u2014 Act Concerning Personal Data Privacy and Online Monitoring (CTDPA)<\/h3>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignright size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"529\" height=\"587\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/CT-CTDPA.jpg\" alt=\"An illustration of the state of Connecticut that lists the CTDPA law\" class=\"wp-image-17489\" style=\"width:256px;height:auto\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/CT-CTDPA.jpg 529w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/CT-CTDPA-270x300.jpg 270w\" sizes=\"auto, (max-width: 529px) 100vw, 529px\" \/><\/figure>\n<\/div>\n\n\n<h4 class=\"wp-block-heading\" id=\"h-what-it-is-4\">What It Is<\/h4>\n\n\n\n<p><a href=\"https:\/\/www.cga.ct.gov\/2022\/act\/Pa\/pdf\/2022PA-00015-R00SB-00006-PA.PDF\">Connecticut\u2019s Act Concerning Personal Data Privacy and Online Monitoring<\/a> (CTDPA) \u2014 This law, Senate Bill No. 6, was <a href=\"https:\/\/cga.ct.gov\/asp\/cgabillstatus\/cgabillstatus.asp?selBillType=Public+Act&amp;which_year=2022&amp;bill_num=15\">signed by Governor Ned Lamont<\/a> on May 10, 2022, and took effect July 1, 2023. Called the Public Act 22-15, this law offers a \u201c<a href=\"https:\/\/portal.ct.gov\/Office-of-the-Governor\/News\/Press-Releases\/2022\/06-2022\/Governor-Lamont-Signs-Legislation-Enacting-a-Comprehensive-Consumer-Data-Privacy-Law\">comprehensive series of protections for consumers<\/a> that provide them with greater ability to safeguard their personal data that is collected when they interact with companies online.\u201d<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-what-it-does-4\">What It Does<\/h4>\n\n\n\n<p>In a nutshell, the CTDPA outlines several crucial rights of Connecticut residents, including the rights to request the following with regard to the sale, processing, and\/or usage of their personal data for targeted marketing:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Access (in a usable format)<\/li>\n\n\n\n<li>Correct<\/li>\n\n\n\n<li>Delete<\/li>\n\n\n\n<li>Opt out<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-who-the-law-does-applies-to\">Who the Law Does Applies To<\/h4>\n\n\n\n<p>The law applies to businesses that control or process the personal data of<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>100,000+ consumers (except for data collected for completing payment transactions), or<\/li>\n\n\n\n<li>25,000+ consumers and also receive 25%+ gross revenue from the sale of that personal data.<\/li>\n<\/ul>\n\n\n\n<p>Another group of organizations that are categorized as covered businesses are service providers that maintain or provide services involving the use of protected personal data.<\/p>\n\n\n\n<p>Organizations that don\u2019t necessarily fall under the purview of this law include governments, nonprofits financial institutions, and healthcare entities (among others). There are plenty of exceptions to read about based on compliance reasons and other considerations.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-how-it-affects-your-business-4\">How It Affects Your Business<\/h4>\n\n\n\n<p>The new law outlines the requirements that covered entities must abide by regarding the collecting, managing, processing, storing, and deleting of Connecticut residents\u2019 personal data. For example:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Limit the amount of data to what\u2019s \u201cadequate, relevant and reasonably necessary\u201d for your intended disclosed purpose.<\/li>\n\n\n\n<li>Respond to verified CTDPA requests \u201cwithout undue delay\u201d as long as it\u2019s within 45 days after the request was received. (You can request an extension, though, in some cases.)<\/li>\n\n\n\n<li>Implement and maintain technical and physical security measures that protect CT residents\u2019 private data and access to it.<\/li>\n<\/ul>\n\n\n\n<p>There are set requirements for controllers and processors alike. A contract is called for to govern how a processor handles the data on behalf of the controller. The controller must specify the instructions and guidance, and object to anything questionable.<\/p>\n\n\n\n<p>If you violate the CTDPA, you also may face civil penalties (up to $5,000 per violation) and have to pay potential injunctive relief or reparations.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-4-delaware-personal-data-privacy-act-dpdpa\">4. Delaware Personal Data Privacy Act (DPDPA)<\/h3>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignright size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"529\" height=\"715\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/DE-DPDPA.jpg\" alt=\"An illustration of the state of Delaware that lists the DPDPA law\" class=\"wp-image-17490\" style=\"width:264px;height:auto\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/DE-DPDPA.jpg 529w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/DE-DPDPA-222x300.jpg 222w\" sizes=\"auto, (max-width: 529px) 100vw, 529px\" \/><\/figure>\n<\/div>\n\n\n<h4 class=\"wp-block-heading\" id=\"h-what-it-is-5\">What It Is<\/h4>\n\n\n\n<p><a href=\"https:\/\/legis.delaware.gov\/json\/BillDetail\/GenerateHtmlDocumentEngrossment?engrossmentId=35877&amp;docTypeId=6\">Delaware Personal Data Privacy Act (DPDPA)<\/a> \u2014 The bill, known otherwise as <a href=\"https:\/\/legis.delaware.gov\/BillDetail\/140388\">Delaware House Bill 154 (H.B. 154)<\/a>, was signed by Gov. John Carney on Sept. 11, 2023 and will kick into effect on Jan. 1, 2025.<\/p>\n\n\n\n<p>Like several other states\u2019 data privacy laws, the DPDPA protects data for household and personal purposes \u2014 meaning those not collected and processed for employment- and commercial-related use cases. It also doesn\u2019t allow affected Delaware residents any private rights to action, meaning they don\u2019t have the right to sue organizations that violate their rights under this law.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-what-it-does-5\">What It Does<\/h4>\n\n\n\n<p>The DPDPA outlines several crucial rights of consumers regarding the collection and processing of their personal data in non-employment-related contexts (except for data that would reveal a controller\u2019s trade secrets). For example, consumers can:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Verify and access any personal data that a controller possesses and processes.<\/li>\n\n\n\n<li>Obtain an easily accessible copy of the personal data a controller has.<\/li>\n\n\n\n<li>Obtain a \u201clist of the categories of third parties\u201d that the controller has disclosed data to.<\/li>\n\n\n\n<li>Correct any inaccurate information that may exist within the resident\u2019s personal data.<\/li>\n\n\n\n<li>Request a controller delete their personal data outright.<\/li>\n\n\n\n<li>Opt out of having their data processed for profiling and targeted advertising.<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-who-the-law-applies-to-4\">Who the Law Applies To<\/h4>\n\n\n\n<p>The law applies to individuals and organizations that targeted Delaware residents the previous year and meet one or both of the following criteria:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Conducts business that controls or processes the data of at least 35,000 Delaware consumers, OR<\/li>\n\n\n\n<li>Conducts business that controls or processes the data of at least 10,000 consumers and also derives 20%+ of its gross revenue from its sales.<\/li>\n<\/ul>\n\n\n\n<p>Of course, there are some exceptions in terms of businesses that the law doesn\u2019t apply to (regulatory and state administrative bodies, financial institutions, national securities associations, etc.). However, the rules (surprisingly) don\u2019t apply in the case of higher education institutions and most (though not all) non-profits. Be sure to read the law\u2019s text for additional information.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-how-it-affects-your-business-5\">How It Affects Your Business<\/h4>\n\n\n\n<p>Much like the CCPA, organizations categorized as controllers and processors each have lists of requirements to abide by. For example, controllers can\u2019t discriminate against residents who exercise their data privacy rights by offering different prices, different quality of goods or services, etc. They\u2019re also required to provide consumers with a way to revoke their consent and submit opt-out requests, if they so choose.<\/p>\n\n\n\n<p>Of course, if you work for the Delaware Department of Justice, you\u2019ll need to begin public education and outreach at least six months prior to the law\u2019s effective date. (That July 1, 2024 outreach\/educaiton deadline is right around the corner, so you better get started now!)<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-5-florida-digital-bill-of-rights-fdbr\">5. Florida Digital Bill of Rights (FDBR)<\/h3>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignright size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"529\" height=\"715\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/FL-FDBR.jpg\" alt=\"An illustration of the state of Florida that lists the FDBR law\" class=\"wp-image-17491\" style=\"width:255px;height:auto\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/FL-FDBR.jpg 529w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/FL-FDBR-222x300.jpg 222w\" sizes=\"auto, (max-width: 529px) 100vw, 529px\" \/><\/figure>\n<\/div>\n\n\n<h4 class=\"wp-block-heading\" id=\"h-what-it-is-6\">What It Is<\/h4>\n\n\n\n<p><a href=\"https:\/\/flsenate.gov\/Session\/Bill\/2023\/262\/BillText\/er\/HTML\">Florida Digital Bill of Rights (FDBR)<\/a> \u2014 The state\u2019s digital rights bill (Senate Bill 262 [S.B. 262]) was signed into law by Governor Ron DeSantis on June 6, 2023 and is set to take effect starting July 1, 2024. This one, in particular, hits close to home for us here at The SSL Store, since we\u2019re based in St. Petersburg, Florida (i.e., about 1.5 hours west of Orlando).<\/p>\n\n\n\n<p>This law largely targets \u201cBig Tech\u201d companies rather than midsize businesses, meaning that it applies to significantly fewer businesses than other states\u2019 data privacy laws. (We\u2019ll explain that more in a bit.)<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-what-it-does-6\">What It Does<\/h4>\n\n\n\n<p>The FDBR outlines several rights of state consumers:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Gives them greater access to and control of their personal data (to access it, delete it, etc.), which includes biometric and geolocation data.<\/li>\n\n\n\n<li>Prohibits the use of covered personal data for discriminatory practices that can affect a consumer\u2019s ability to buy a home, get a job, or obtain health insurance.<\/li>\n\n\n\n<li>Enables consumers to opt out of having their data sold or processed for profiling and targeted advertising.<\/li>\n<\/ul>\n\n\n\n<p>One of the most interesting components of this bill is that it aims to inform state consumers about how search engines (e.g., Google) manipulate search results to prioritize or deprioritize results based on \u201cpolitical partisanship or political ideology\u201d or monetary considerations. As part of the new law, any applicable controllers operating a search engine also must clearly describe what parameters are considered in determining search engine rankings.<\/p>\n\n\n\n<p>Want to opt out of your voice (via voice recognition), biometric data, or location being collected? <a href=\"https:\/\/www.flgov.com\/2023\/06\/06\/governor-ron-desantis-signs-legislation-to-create-a-digital-bill-of-rights-for-floridians\/\">You can do that under the law<\/a> with just a few notable exceptions.<\/p>\n\n\n\n<p>However, something the law doesn\u2019t do is establish a private cause of action (meaning that consumers can\u2019t enforce their rights or seek punitive damages or other remedies under the law).<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-who-the-law-applies-to-5\">Who the Law Applies To<\/h4>\n\n\n\n<p>Truthfully, this law is blatantly targeting the \u201cBig Tech\u201d companies. Why do we say that? The law applies to for-profit organizations that conduct business within Florida, collect and determine the purpose of processing consumers\u2019 personal data, and make $1+ billion in global gross revenues each year, in addition to meeting one or more of the following:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Gets at least 50 percent of its global gross annual revenues from online ads (including targeted advertising),<\/li>\n\n\n\n<li>Includes a cloud-based consumer smart speak and voice command component that uses \u201chands free verbal activation), excluding those associated with motor vehicles, OR<\/li>\n\n\n\n<li>Operates an app store (or another type of digital distribution platform) containing 250,000+ unique software apps users can install.&nbsp;<\/li>\n<\/ul>\n\n\n\n<p>Yeah\u2026 As you can see, with these stipulations, small and mid-size businesses don\u2019t meet such criteria.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-how-it-affects-your-business-6\">How It Affects Your Business<\/h4>\n\n\n\n<p>Unless you work for one of those mega tech firms (i.e., the \u201cGoogles\u201d of the world), it really doesn\u2019t impact your business.<\/p>\n\n\n\n<p>However, if you are one of those big tech companies, then you should know the following:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Violations may result in civil penalties of up to $50,000 per violation. However, these fines may be tripled in certain instances:<ul><li>Processing of known children\u2019s personal data.<\/li><\/ul><ul><li>Failing to correct or delete a consumer\u2019s data.<\/li><\/ul>\n<ul class=\"wp-block-list\">\n<li>Selling consumer data after a consumer has opted out.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<p>The law also sets additional requirements and limitations, which include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Getting consent before processing data.<\/li>\n\n\n\n<li>Limiting what personal data you can collect to what\u2019s reasonably necessary and relevant in its purpose.<\/li>\n\n\n\n<li>Providing \u201creasonable administrative, technical, and physical data security practices\u201d to protect the covered personal data.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-6-indiana-consumer-data-protection-act-icdpa\">6. Indiana Consumer Data Protection Act (ICDPA)<\/h3>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignright size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"529\" height=\"715\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/IN-ICDPA.jpg\" alt=\"An illustration of the state of Indiana that lists the ICDPA law\" class=\"wp-image-17492\" style=\"width:268px;height:auto\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/IN-ICDPA.jpg 529w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/IN-ICDPA-222x300.jpg 222w\" sizes=\"auto, (max-width: 529px) 100vw, 529px\" \/><\/figure>\n<\/div>\n\n\n<h4 class=\"wp-block-heading\" id=\"h-what-it-is-7\">What It Is<\/h4>\n\n\n\n<p>Senate Bill 5, also known as the <a href=\"https:\/\/iga.in.gov\/pdf-documents\/123\/2023\/senate\/bills\/SB0005\/SB0005.05.ENRH.pdf\">Indiana Consumer Data Protection Act<\/a> (ICDPA), was <a href=\"https:\/\/iga.in.gov\/legislative\/2023\/bills\/senate\/5\/details\">signed into law by Gov. Eric Holcomb<\/a> on May 1, 2023. It\u2019s legislation that aims to give control of personal data back to Indiana state residents by attesting to their rights and also outlining the responsibilities of controllers and processors that handle consumer data.<\/p>\n\n\n\n<p>The new law is set to take effect on Jan. 1, 2026. (Yeah, we know, that\u2019s a lengthy rollout period \u2014 it\u2019s actually the furthest out on the calendar when compared to other states\u2019 similar laws that we\u2019ve covered in this article.)<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-what-it-does-7\">What It Does<\/h4>\n\n\n\n<p>The <a href=\"https:\/\/legiscan.com\/IN\/text\/SB0005\/id\/2779850\">ICDPA<\/a> outlines several crucial rights of consumers as well as exemptions to what personal data can (or can\u2019t) be collected, processed, stored, or deleted. In Indiana, this views state residents from a strictly personal\/household perspective; the law doesn\u2019t apply to personal data used in employment or commercial contexts.<\/p>\n\n\n\n<p>Much like other data privacy laws in the U.S., the ICDPA also enables consumers to do the following:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Confirm what data, if any, a controller is processing and have access to it.<\/li>\n\n\n\n<li>Receive a copy (or representational summary) of the data.<\/li>\n\n\n\n<li>Correct any inaccurate information within those records.<\/li>\n\n\n\n<li>Delete personal data they don\u2019t want the controller to have or process (with some exceptions).<\/li>\n\n\n\n<li>Opt out from having their data sold or processed for targeted advertising or profiling.<\/li>\n<\/ul>\n\n\n\n<p>However, unlike several other U.S. data privacy laws, there is no private right of action for Indiana residents.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-who-the-law-applies-to-6\">Who the Law Applies To<\/h4>\n\n\n\n<p>The law applies to anyone who conducts business in Indiana or produces products or services targeting state residents who meets the following requirements:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Processes or controls 100,000+ Indiana residents\u2019 personal data, or<\/li>\n\n\n\n<li>Processes or controls the personal data of 25,000+ Indiana residents whose revenues (at least 50%) are derived from sales of that data.<\/li>\n<\/ul>\n\n\n\n<p>As with many of the other passed data protection laws, the ICDPA also notes many categories of organizations that are exempt from this rule. Most notably, state authorities, public utilities, healthcare organizations, etc.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-how-it-affects-your-business-7\">How It Affects Your Business<\/h4>\n\n\n\n<p>If you\u2019re collecting and\/or processing data for the purposes of employment (i.e., checking to see if someone has anything questionable in their background), then this law doesn\u2019t necessarily apply to you.<\/p>\n\n\n\n<p>Indiana is one of the states requiring controllers and processors to agree on how consumer data gets processed and outlines the rights and responsibilities of each party. They literally have to have a contractual agreement that spells it out.<\/p>\n\n\n\n<p>As a data controller, you must respond to a consumer\u2019s authenticated request \u201cwithout undue delay\u201d and no later than 45 days after receiving their request (although they can be granted up to a 45-day extension so long as they inform the consumer).<\/p>\n\n\n\n<p>The law affords businesses a 30-day cure period for alleged violations. However, violations that go unaddressed beyond that period may result in injunctions and civil penalties costing upwards of $7,500 per violation, as well as investigative and legal-related costs.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-7-iowa-consumer-data-protection-act-idpa\">7. Iowa Consumer Data Protection Act (IDPA)<\/h3>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignright size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"529\" height=\"553\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/IA-ICDPA.jpg\" alt=\"An illustration of the state of Iowa that lists the ICDPA law\" class=\"wp-image-17493\" style=\"width:266px;height:auto\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/IA-ICDPA.jpg 529w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/IA-ICDPA-287x300.jpg 287w\" sizes=\"auto, (max-width: 529px) 100vw, 529px\" \/><\/figure>\n<\/div>\n\n\n<h4 class=\"wp-block-heading\" id=\"h-what-it-is-8\">What It Is<\/h4>\n\n\n\n<p><a href=\"https:\/\/www.legis.iowa.gov\/docs\/publications\/LGE\/90\/SF262.pdf\">Iowa Consumer Data Protection Act<\/a> (called either the ICDPA or IDPA, depending on the source) aims to outline the rights of Iowa residents and the responsibilities of businesses that control or process their data. The bill was signed into law by Gov. Kim Reynolds on March 28, 2023 and is set to go into effect Jan. 1, 2025.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-what-it-does-8\">What It Does<\/h4>\n\n\n\n<p>Much like the Montana Consumer Data Privacy Act we\u2019ll cover next, the Iowa data privacy law outlines the types of personal data that are protected, including \u201cprecise geolocation data,\u201d which identifies a person\u2019s location within a radius of 1,750 feet (minus data relating to utilities). It outlines several crucial rights of consumers, including the rights to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Confirm what data is being processed and get access to it.<\/li>\n\n\n\n<li>Obtain an accessible copy of said personal data (with some notable exceptions).<\/li>\n\n\n\n<li>Request the controller delete their data.<\/li>\n\n\n\n<li>Opt out of having their data sold or processed for targeted advertising. However, the law doesn\u2019t give consumers the right to opt out of having their data used for profiling.<\/li>\n<\/ul>\n\n\n\n<p>Something else the law doesn\u2019t do is give consumers the ability to exercise a private right of action. So, if someone plans to sue under the law regarding violations to their data, then they\u2019re out of luck.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-who-the-law-applies-to-7\">Who the Law Applies To<\/h4>\n\n\n\n<p>Something interesting to note is that Iowa\u2019s CDPA is one of the only data privacy laws in the U.S. that doesn\u2019t specify a jurisdictional threshold regarding businesses\u2019 (non-data sale related) annual gross revenues. Rather, it specifies that the law applies to data controllers or processors that conduct business in Iowa or create products or services targeting state residents. Furthermore, applicable organizations also must either control or process the following:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Personal data of 100,000+ Iowa residents, OR<\/li>\n\n\n\n<li>Personal data of 25,000+ residents and derives more than 50% of their gross revenue from personal data sales.<\/li>\n<\/ul>\n\n\n\n<p>As with other U.S. data privacy laws, there are exceptions in terms of businesses that are subject to the law. You can read more about those exceptions in Section 2, 715D.2.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-how-it-affects-your-business-8\">How It Affects Your Business<\/h4>\n\n\n\n<p>As per other U.S. data privacy laws, there are certain data privacy and security expectations that data controllers and processors must meet. For example, controllers must respond to consumers\u2019 requests in a reasonable amount of time (\u201cwithout undue delay\u201d). In this case, you have up to 90 days to respond to consumers\u2019 requests regarding their data rights under the law (with the option of a 45-day extension in some cases). If you deny consumers\u2019 requests to correct, delete, or opt out of sharing\/selling their data, then you must provide them with a means to appeal your decision.<\/p>\n\n\n\n<p>The law also affords businesses a 90-day cure period to fix alleged violations; businesses that fail to do so may face injunctions or civil penalties from the state\u2019s attorney general costing upwards of $7,500 per violation. The funds received from such actions are to be placed in a \u201cconsumer education and litigation fund.\u201d<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-8-montana-consumer-data-privacy-act-mcdpa\">8. Montana Consumer Data Privacy Act (MCDPA)<\/h3>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignright size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"529\" height=\"553\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/MT-MCDPA.jpg\" alt=\"An illustration of the state of Montana that lists the MCDPAA law\" class=\"wp-image-17494\" style=\"width:273px;height:auto\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/MT-MCDPA.jpg 529w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/MT-MCDPA-287x300.jpg 287w\" sizes=\"auto, (max-width: 529px) 100vw, 529px\" \/><\/figure>\n<\/div>\n\n\n<h4 class=\"wp-block-heading\" id=\"h-what-it-is-9\">What It Is<\/h4>\n\n\n\n<p>The <a href=\"https:\/\/leg.mt.gov\/bills\/2023\/billpdf\/SB0384.pdf\">Montana Consumer Data Privacy Act<\/a> (often cited as MCDPA or MTCDPA) is the state\u2019s new consumer data privacy law that protects consumer rights and outlines the responsibilities of businesses that control or process their data. Formed as Senate Bill 384 (S.B. 384), the act was signed into law on May 19, 2023 by Gov. Greg Gianforte and is set to become effective on Oct. 1, 2024.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-what-it-does-9\">What It Does<\/h4>\n\n\n\n<p>As with other privacy laws in the U.S., the MCDPA outlines several crucial consumer rights for Montana residents acting in a private (non-commercial or employment) capacity:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Confirm if their data is being processed by the controller and have access to it.<\/li>\n\n\n\n<li>Obtain an accessible copy of the consumer\u2019s personal data (with limited exceptions).<\/li>\n\n\n\n<li>Delete the personal data consumer\u2019s personal data that the controller possesses.<\/li>\n\n\n\n<li>Opt out of the sale of their data.<\/li>\n<\/ul>\n\n\n\n<p>Like many of the other U.S. data privacy laws, the Montana law doesn\u2019t provide a private right of action for consumers. Be sure to read the bill\u2019s text to learn more.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-who-the-law-applies-to-8\">Who the Law Applies To<\/h4>\n\n\n\n<p>The law applies to entities that do business within the state and handle Montana residents\u2019 personal data. But that\u2019s not all \u2014 they also must control or process:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>50,000+ Montana consumers\u2019 personal data, minus that which is used to complete payment transactions, OR<\/li>\n\n\n\n<li>25,000+ Montana consumers\u2019 data and get at least one-quarter of all gross revenue for its sales.<\/li>\n<\/ul>\n\n\n\n<p>Unlike some other related laws in other states (e.g., Florida, California, etc.), Montana didn\u2019t include any specific financial thresholds for organizations that meet these requirements.<\/p>\n\n\n\n<p>As with all of the other U.S. data privacy and consumer laws discussed in this article, there are exceptions to the rules. The laws don\u2019t apply to many categories of organizations based on their roles and the reasons why they collect and\/or process the data. &nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-how-it-affects-your-business-9\">How It Affects Your Business<\/h4>\n\n\n\n<p>In addition to some of the common requirements outlined toward the beginning of the article, processors and controllers have additional responsibilities mentioned in the law. For example, applicable businesses are required to perform and document data protection assessments (DPAs) when selling or processing consumer personal data for profiling or targeting ads.<\/p>\n\n\n\n<p>Montana is one of the U.S. states that requires the establishment of a universal opt-out mechanism, platform, or technology of some kind to allow consumers to put the <em>kibosh<\/em> on controllers processing their data. Businesses are required to implement this type of opt-out measure by <em>no later than Jan. 1, 2025<\/em>. But what if their opt-out submission conflicts with their existing privacy settings? Then the opt-out preference takes precedence.<\/p>\n\n\n\n<p>The law states that data controllers have up to 90 days to respond to a consumer\u2019s request for data modifications, deletions, or to opt-out of having their data processed or sold. They also must provide a conspicuous appeals process to consumers and have 60 days to respond once they receive an authenticated appeal request.<\/p>\n\n\n\n<p>If a controller or processor sends Montana consumers\u2019 personal data to another party (i.e., a third-party controller or another processor), they\u2019re not to be held liable for violations conducted by that other party, and vice versa. Basically, it\u2019s a way to hold one party blameless for the violating actions of the other.<\/p>\n\n\n\n<p>Lastly, any violations of the law are enforced by the state\u2019s attorney general. Any violations must be corrected within 60 days of notification; if they don\u2019t, the AG will issue a \u201cnotice of violation\u201d and has the right to take action. However, it\u2019s not specified what that action entails or what a maximum damage amount would cost (if anything).<\/p>\n\n\n\n<p>Be sure to read the bill for more detailed information if you do business with Montana residents.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-9-oregon-consumer-data-privacy-act-ocdpa\">9. Oregon Consumer Data Privacy Act (OCDPA)<\/h3>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignright size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"529\" height=\"553\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/OR-OCDPA.jpg\" alt=\"An illustration of the state of Oregon that lists the OCDPA law\" class=\"wp-image-17495\" style=\"width:278px;height:auto\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/OR-OCDPA.jpg 529w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/OR-OCDPA-287x300.jpg 287w\" sizes=\"auto, (max-width: 529px) 100vw, 529px\" \/><\/figure>\n<\/div>\n\n\n<h4 class=\"wp-block-heading\" id=\"h-what-it-is-10\">What It Is<\/h4>\n\n\n\n<p><a href=\"https:\/\/olis.oregonlegislature.gov\/liz\/2023R1\/Downloads\/MeasureDocument\/SB619\/Enrolled\">Oregon Consumer Data Privacy Act (OCDPA)<\/a> \u2014 Senate Bill 619 was signed into law by Gov. Tina Kotek on July 18, 2023. It will become effective July 1, 2024 and, unlike some other states\u2019 similar laws, will apply to most non-profits starting July 1 of the following year. &nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-what-it-does-10\">What It Does<\/h4>\n\n\n\n<p>The OCDPA outlines consumer rights that must be exercised via whatever method the controller specifies in their privacy notice. Consumer rights include the ability to request the following:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Get confirmation about the categories of personal data relating to the consumer that a controller is processing or has processed.<\/li>\n\n\n\n<li>Update and correct any inaccurate information included in their personal data that the controller has or is processing.<\/li>\n\n\n\n<li>Demand that the business controlling their personal data must delete it, regardless of whether they gave the information themselves or it was obtained via a third party.<\/li>\n\n\n\n<li>Require a business to provide a copy of their data in an easily accessible format.<\/li>\n\n\n\n<li>Opt out of having their information sold or processed for use in targeting ads and profiling.<\/li>\n<\/ul>\n\n\n\n<p>The law also outlines opt-in requirements for individuals ages 13-15 when it comes to processing their personal data for targeted advertising and profiling or selling it.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-who-the-law-applies-to-9\">Who the Law Applies To<\/h4>\n\n\n\n<p>Initially, the law applies to for-profit entities only. This includes persons and businesses that collect or process personal data that identifies (or can reasonably be connected to) an Oregon resident for the purpose of conducting business or producing products\/services targeting them. Additionally, they must either control or process:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>100,000+ Oregon residents\u2019 personal data (minus payment-related transactions), OR<\/li>\n\n\n\n<li>25,000+ Oregon residents\u2019 personal data that constitutes more than 25% of its gross revenue sales.<\/li>\n<\/ul>\n\n\n\n<p>Much like Montana and unlike other states\u2019 laws, Oregon doesn\u2019t specify any financial thresholds for organizations that meet these requirements in their consumer data privacy law. And while it does have exceptions in terms of entities that the law doesn\u2019t apply to (such as government entities and higher education institutions), the law will apply to most non-profit organizations beginning July 1, 2025.&nbsp;<\/p>\n\n\n\n<p>Much like the majority of the laws covered in this article, Oregon\u2019s law doesn\u2019t provide a private right of action for consumers to go after companies for violations. Instead, only the state\u2019s attorney general can take action. &nbsp;&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-how-it-affects-your-business-10\">How It Affects Your Business<\/h4>\n\n\n\n<p>Businesses that fall under the purview of this law must make it easy to find their privacy notice on their website. They also must provide a means to enable consumers to exercise their rights and revoke previously given consent under the law.<\/p>\n\n\n\n<p>As a data controller, once you receive an authenticated request from a consumer exercising their rights, you have up to 45 days to respond. This applies to correcting, deleting, or making other changes to their processed or sold data. This also includes revoking the data (within 15 days of request receipt). However, when it comes to disclosing which third parties they collected and disclosed the consumers\u2019 personal data to for processing, the controller has the option to specify which third party (or parties) to talk about.<\/p>\n\n\n\n<p>It&#8217;s important to note that in Oregon\u2019s law, the \u201csale\u201d of business includes \u201cthe exchange of personal data for monetary or other valuable consideration by the Controller with a third party.\u201d Meaning, if a controller is compensated by other non-monetary means for handing off Oregon consumers\u2019 personal data to a third party, it could constitute a sale of data (with some important exemptions).<\/p>\n\n\n\n<p>Oregon\u2019s AG will notify businesses of violations and provide a 30-day period to cure (fix) the issue. Any violations of the law after that 30-day cure period may result in civil penalties of up to $7,500 per violation.&nbsp; The AG has up to five years to bring an action under sections 1-9 of the act.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-10-tennessee-information-protection-act-tipa\">10. Tennessee Information Protection Act (TIPA)<\/h3>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignright size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"529\" height=\"401\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/TN-TIPA.jpg\" alt=\"An illustration of the state of Tennessee that lists the TIPA law\" class=\"wp-image-17496\" style=\"width:263px;height:auto\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/TN-TIPA.jpg 529w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/TN-TIPA-300x227.jpg 300w\" sizes=\"auto, (max-width: 529px) 100vw, 529px\" \/><\/figure>\n<\/div>\n\n\n<h4 class=\"wp-block-heading\" id=\"h-what-it-is-11\">What It Is<\/h4>\n\n\n\n<p><a href=\"https:\/\/www.capitol.tn.gov\/Bills\/113\/Bill\/HB1181.pdf\">The Tennessee Information Protection Act<\/a> (TIPA) \u2014 <a href=\"https:\/\/wapp.capitol.tn.gov\/apps\/BillInfo\/Default.aspx?BillNumber=SB0073\">Signed into law<\/a> by Tennessee Gov. Bill Lee on May 11, 2023, the law is set to kick into effect July 1, 2025. (It was originally set to take effect July 1, 2025, but the date was amended in May 2023.)<\/p>\n\n\n\n<p>This law appears to be more favorably aligned with businesses\u2019 interests than with consumers\u2019 when compared to some other U.S. data privacy laws (such as California\u2019s CCPA with its CPRA amendment).&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-what-it-does-11\">What It Does<\/h4>\n\n\n\n<p>TIPA outlines several crucial rights of consumers that protect their personal, non-deidentified or publicly available data when acting as private individuals (not as employees or in other contexts):<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Confirm what info the controller is processing, what categories of data it\u2019s sold, and what categories of third-party organizations the data has been sold to.<\/li>\n\n\n\n<li>Ensure they have access to the data.<\/li>\n\n\n\n<li>Get a portable copy of the data held by the controller that the consumer can use to transmit to another controller.<\/li>\n\n\n\n<li>Make any corrections necessary to amend inaccuracies with specific considerations.<\/li>\n\n\n\n<li>Request the controller delete their identifiable personal data.<\/li>\n<\/ul>\n\n\n\n<p>Much like many others, the Tennessee law doesn\u2019t give consumers a private right of action or the ability to launch a class action lawsuit for violations. However, \u201cappropriate relief may be awarded to each identified consumers affected by this regulation, regardless of whether actual damages were suffered\u201d and the court reserves the right to award treble damages.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-who-the-law-applies-to-10\">Who the Law Applies To<\/h4>\n\n\n\n<p>The law applies to businesses and individuals who do provide products and services targeting state residents and meet one of the following conditions:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Control or process personal data relating to 100,000+ consumers within a calendar year, OR<\/li>\n\n\n\n<li>Control or process personal data of 25,000+ consumers and get &gt;50% of their gross revenue by selling it.<\/li>\n<\/ol>\n\n\n\n<p>However, much like many other states\u2019 laws, some entities are exempt based on their roles, legislative authority, and other considerations. Read more about the law to explore those entities.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-how-it-affects-your-business-11\">How It Affects Your Business<\/h4>\n\n\n\n<p>The law outlines specific requirements for businesses regarding data security standards and protections for identifiable data. It also imposes obligations about clearly disclosing how and why the information is needed, along with how it\u2019ll be used and who the information is shared with. It also requires businesses to provide an appeals process to consumers who wish to appeal a business\u2019s decision to deny their request to exercise their rights.<\/p>\n\n\n\n<p>Want some good news? Businesses that maintain a written privacy program that \u201creasonably conforms to\u201d the latest version of the National Institute of Standards and Technology (NIST) privacy framework get to enjoy an \u201caffirmative defense.\u201d (A bit of a \u201csafe harbor,\u201d if you will.) This means that if there\u2019s a violation, as long as they comply with said written policy, a controller or processor may potentially avoid issues relating to TIPA violations.<\/p>\n\n\n\n<p>TIPA also provides a 60-day cure period and has no sunset date as of the time of writing this article. However, for uncured violations, injunctive relief, declaratory judgment, or a civil penalty (of up to $15,000 per violation) may apply depending on the situation. However, the quasi \u201csafe harbor\u201d we mentioned earlier may mean that you may have some protection as well if you fail to cure within that 60-day period.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-11-texas-data-privacy-and-security-act-tdspa\">11. Texas Data Privacy and Security Act (TDSPA)<\/h3>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignright size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"529\" height=\"697\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/TX-TDPSA.jpg\" alt=\"An illustration of the state of Texas that lists the TDPSA law\" class=\"wp-image-17497\" style=\"width:267px;height:auto\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/TX-TDPSA.jpg 529w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/TX-TDPSA-228x300.jpg 228w\" sizes=\"auto, (max-width: 529px) 100vw, 529px\" \/><\/figure>\n<\/div>\n\n\n<h4 class=\"wp-block-heading\" id=\"h-what-it-is-12\">What It Is<\/h4>\n\n\n\n<p><a href=\"https:\/\/capitol.texas.gov\/tlodocs\/88R\/billtext\/pdf\/HB00004F.pdf#navpanes=0\">Texas Data Privacy and Security Act<\/a> (TDPSA) \u2014 The Lone Star\u2019s Governor, Greg Abbott, <a href=\"https:\/\/capitol.texas.gov\/BillLookup\/History.aspx?LegSess=88R&amp;Bill=HB4\">signed the data privacy bill into law<\/a> (HB-4) on June 18 2023. It\u2019s set to go into effect July 1, 2024. A specific portion (Chapter 541, Business &amp; Commerce Code) won\u2019t be effective until the following year.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-what-it-does-12\">What It Does<\/h4>\n\n\n\n<p>The TDPSA gives consumers a way to exercise limited control over their data in terms of how it can be accessed, processed, sold, or used. It outlines several crucial rights of consumers, such as the ability to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Confirm whether their personal data is being processed and that they have access to it.<\/li>\n\n\n\n<li>Delete personal data that\u2019s been collected on the consumer.<\/li>\n\n\n\n<li>Gain access to their personal data in a portable, accessible format.<\/li>\n\n\n\n<li>Opt out of having their data processed for sale, profiling, or targeted advertising.<\/li>\n<\/ul>\n\n\n\n<p>As with most of other data privacy law in the U.S., the TDPSA doesn\u2019t give consumers a private right of action in response to violations.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-who-the-law-applies-to-11\">Who the Law Applies To<\/h4>\n\n\n\n<p>The law applies to individuals and businesses who meet the following criteria:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Provide products and services aimed at Texas residents.<\/li>\n\n\n\n<li>Process or engage in selling residents\u2019 personal data.<\/li>\n\n\n\n<li>Is not a small business (unless they have specific consent from the consumer)<\/li>\n<\/ul>\n\n\n\n<p>It doesn\u2019t set revenue restrictions or qualifiers like some other U.S. data privacy laws do in other states.<\/p>\n\n\n\n<p>Some types of entities and organizations are exempt based on certain factors such as their roles and responsibilities, as well as other interacting laws and regulations. We won\u2019t get into all of that here, but you can read more about the law to explore those types of entities in bill\u2019s text.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-how-it-affects-your-business-12\">How It Affects Your Business<\/h4>\n\n\n\n<p>The law outlines key considerations and requirements that business controllers and processors must implement and adhere to. For example, section 541.104 outlines that data processors and controllers must have a contractual relationship that spells out key specifications.&nbsp;<\/p>\n\n\n\n<p>The TDPSA requires businesses that meet the law\u2019s data collector requirements to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Gain clear, unambiguous consent from the consumer regarding the processing and use of their personal data.<\/li>\n\n\n\n<li>Provide a mechanism on their websites for consumers to submit their requests to exercise their rights.<\/li>\n\n\n\n<li>Recognize opt-out preference indicators starting Jan. 1, 2025.<\/li>\n\n\n\n<li>Provide specific disclosures when engaging in the sale of Texas consumers\u2019 biometric or otherwise personal data.<\/li>\n<\/ul>\n\n\n\n<p>Unlike pretty much all of the other data security laws we\u2019ve read, Texas\u2019 specifies the precise language to use for those notices, e.g.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>&#8220;NOTICE: We may sell your sensitive personal data.&#8221;<\/li>\n\n\n\n<li>&#8220;NOTICE: We may sell your biometric personal data.&#8221;<\/li>\n<\/ul>\n\n\n\n<p>Controllers are required to carry out and document a confidential data protection assessment regarding sale and processing activities relating to personal data. For specifics on these requirements, read the law in full.<\/p>\n\n\n\n<p>Enforcement of any violations is up to the state\u2019s attorney general. Failures to comply with the requirements by the 30-day cure period (and for new violations thereafter) may result in a civil penalty of up to $7,500 per violation. The attorney general also may seek injunctive relief if necessary.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-12-utah-consumer-privacy-act-ucpa\">12. Utah Consumer Privacy Act (UCPA)<\/h3>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignright size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"529\" height=\"697\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/UT-UCPA.jpg\" alt=\"An illustration of the state of Utah that lists the UCPA law\" class=\"wp-image-17498\" style=\"width:250px;height:auto\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/UT-UCPA.jpg 529w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/UT-UCPA-228x300.jpg 228w\" sizes=\"auto, (max-width: 529px) 100vw, 529px\" \/><\/figure>\n<\/div>\n\n\n<h4 class=\"wp-block-heading\" id=\"h-what-it-is-13\">What It Is<\/h4>\n\n\n\n<p><a href=\"https:\/\/le.utah.gov\/xcode\/Title13\/Chapter61\/C13-61_2022050420231231.pdf\">Utah Consumer Privacy Act (UCPA)<\/a> \u2014 Utah will close out the year 2023 with their new data privacy law, which took effect Dec. 31, 2023. It was signed into law by Utah Governor Spencer J. Cox on March 24, 2022.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-what-it-does-13\">What It Does<\/h4>\n\n\n\n<p>The UCPA outlines some crucial rights of consumers that they can exercise:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Confirm if a controller is processing their data and that the consumer has access to that information.<\/li>\n\n\n\n<li>Reserve the right to delete their personal data that the consumer provided to the controller.<\/li>\n\n\n\n<li>Access their data through means that are portable, accessible, and transmittable.<\/li>\n\n\n\n<li>Opt out of having their data processed for sale and targeted advertising.<\/li>\n<\/ul>\n\n\n\n<p>However, it doesn\u2019t offer any recourse in terms of a private right of action. As a consumer, you also can\u2019t opt out of having your data used for profiling or even make any corrections to inaccurate information.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-who-the-law-applies-to-12\">Who the Law Applies To<\/h4>\n\n\n\n<p>The law applies to any controller and processor who:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Does business within the state of Utah.<\/li>\n\n\n\n<li>Provides products or services targeting Utah residents.<\/li>\n\n\n\n<li>Has $25 million+ in annual revenue.<\/li>\n\n\n\n<li>Meets one of the following thresholds:<ul><li>Processes personal data of 100,000+ consumers, OR<\/li><\/ul>\n<ul class=\"wp-block-list\">\n<li>Gets &gt;50% of its gross revenue from sale of data and controls or processes the data of 25,000 consumers.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<p>As with virtually every other U.S. data privacy law, there are always exceptions to the rule. Some examples of entities that the law doesn\u2019t apply to include government institutions and contractors, non-profits, higher education institutions, and a bunch of others outlined in the bill. Of course, there are also plenty of specific categories of activities that don\u2019t fall under the law. Read more about all of those exceptions in the bill. &nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-how-it-affects-your-business-13\">How It Affects Your Business<\/h4>\n\n\n\n<p>As a data controller, your job is to inform consumers about your data collection activities and provide the means to exercise their rights under the law. Part of this involves providing consumers with a \u201creasonably accessible and clear privacy notice\u201d that informs them about pertinent info regarding what\u2019s being collected and how it\u2019s being used.<\/p>\n\n\n\n<p>You must respond to authenticated consumer requests within 45 days of request receipt. However, you have the option of extending that period by another 45 days, if need be, but you must inform the consumer about the extension.<\/p>\n\n\n\n<p>However, unlike other states\u2019 similar laws, Utah\u2019s doesn\u2019t require data controllers to provide an appeals process for consumers whose requests are denied.<\/p>\n\n\n\n<p>For businesses that violate the law, there\u2019s a 30-day cure period from when they receive a violation notice from the state\u2019s attorney general. If they fail to cure within the prescribed time, they may be fined up to $7,500 per violation. The funds just go into a fund that\u2019s used for investigations, attorney fees, consumer education, etc. If the fund exceeds $4 million at the end of the fiscal year, the money is then transferred into the state\u2019s General Fund.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"virginia-cdpa\">13. Virginia Consumer Data Privacy Act (CDPA)<\/h3>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignright size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"529\" height=\"489\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/VA-VACDPA-v2.jpg\" alt=\"An illustration of the state of Virginia that lists the CDPA law\" class=\"wp-image-17499\" style=\"width:253px;height:auto\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/VA-VACDPA-v2.jpg 529w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/VA-VACDPA-v2-300x277.jpg 300w\" sizes=\"auto, (max-width: 529px) 100vw, 529px\" \/><\/figure>\n<\/div>\n\n\n<h4 class=\"wp-block-heading\">What It Is<\/h4>\n\n\n\n<p>The <a href=\"https:\/\/law.lis.virginia.gov\/vacodefull\/title59.1\/chapter53\/\">Virginia Consumer Data Privacy Act<\/a> (CDPA, sometimes called the VACDPA) was signed by Gov. Ralph Northam on March 2, 2021. The law, which took effect Jan. 1, 2023, was the second such comprehensive consumer data privacy law that was launched by a state (following California\u2019s CCPA).<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">What It Does<\/h4>\n\n\n\n<p>The CDPA affords consumers with several critical rights when it comes to the privacy and usage of their personal data:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Confirm whether a controller is processing their data and that the consumer has access to it.<\/li>\n\n\n\n<li>Correct inaccuracies within the data.<\/li>\n\n\n\n<li>Obtain a copy of their data in a readily accessible format.<\/li>\n\n\n\n<li>Opt out of having their data being sold or processed for:<ul><li>Targeted advertising<\/li><\/ul>\n<ul class=\"wp-block-list\">\n<li>Profiling<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>Delete any data that they (or someone else) provided about the consumer.<\/li>\n<\/ul>\n\n\n\n<p>Unsurprisingly, the law doesn\u2019t provide a private right of action for consumers whose rights are violated.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Who the Law Applies To<\/h4>\n\n\n\n<p>The law applies to any individuals who conduct business within the Commonwealth of Virginia or who provides products\/services targeting residents during a calendar and meet one of the following criteria:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Control or process 100,000+ consumers\u2019 personal date, OR<\/li>\n\n\n\n<li>Control or process the personal data of 25,000+ consumers AND get &lt;50% of their cross revenue from its sales.<\/li>\n<\/ul>\n\n\n\n<p>As far as exempt entities go, they\u2019re the usual gang \u2014 government entities, financial institutions, nonprofits, higher education institutions, etc. Unsurprisingly, data used for a litany of specified purposes and use cases also would be exempt from this law.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">How It Affects Your Business<\/h4>\n\n\n\n<p>Applicable businesses must get the consumer\u2019s content. They also must comply with an authenticated consumer\u2019s request to exercise their rights. Although businesses are expected to reply without undue delay, they technically have up to 45 days of receipt of an authenticated consumer request to respond.<\/p>\n\n\n\n<p>If the decision is to deny their request, you must inform the consumer within that period and provide a justification for why and info on how to file an appeal. An appeal decision must be communicated to the consumer within 60 days of receipt of the appeal request. Appeal denials also must include information about how the consumer may submit a formal online complaint to the Attorney General.&nbsp;<\/p>\n\n\n\n<p>Data controllers must establish a contract with processors that governs their actions regarding the personal data they handle. They\u2019re also required to \u201cconduct and document a data protection assessment\u201d regarding how personal data is processed for sale, targeted advertising, and profiling, any activities that could increase potential harm.<\/p>\n\n\n\n<p>Any violations of the law can result in the attorney general launching a civil investigation. There\u2019s a 30-day cure period for businesses to fix the violation. If the violation extends beyond that period, the AG may seek injunctive action or civil penalties upwards of $7,500 per violation. (Any penalties recovered go into the state\u2019s Regulatory, Consumer Advocacy, Litigation, and Enforcement Revolving Trust Fund.)<\/p>\n\n\n<span style=\"--tl-form-height-m:801.312px;--tl-form-height-t:638.344px;--tl-form-height-d:638.344px;\" class=\"tl-placeholder-f-type-shortcode_12763 tl-preload-form\"><span><\/span><\/span>\n\n\n<h2 class=\"wp-block-heading\">How Soon Can We Expect to See These Laws in Effect?<\/h2>\n\n\n\n<p>That\u2019s a good question. There isn\u2019t one date when all of these laws will roll out; rather, some laws are already in effect while others will roll out over the next couple of years. Here\u2019s a quick overview of what this looks like in a timeline:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"410\" height=\"1024\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/us-data-privacy-laws-thesslstore-2-410x1024.jpg\" alt=\"An illustration that shows a timeline of U.S. data privacy laws by state and when they became effective (or will become effective)\" class=\"wp-image-17502\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/us-data-privacy-laws-thesslstore-2-410x1024.jpg 410w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/us-data-privacy-laws-thesslstore-2-120x300.jpg 120w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/us-data-privacy-laws-thesslstore-2-768x1920.jpg 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/us-data-privacy-laws-thesslstore-2-819x2048.jpg 819w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/us-data-privacy-laws-thesslstore-2-scaled.jpg 1024w\" sizes=\"auto, (max-width: 410px) 100vw, 410px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Final Thoughts on Data Privacy Laws in the U.S.<\/h2>\n\n\n\n<p>We\u2019re living in interesting times. We live in a world where information is virtually at our fingertips; and that includes sensitive, personally identifiable information. And when it comes to drawing a line between the rights of U.S. consumers and the desires and needs of businesses to use that data, it\u2019s nothing short of a battleground.&nbsp;<\/p>\n\n\n\n<p>There\u2019s plenty to know about the specifics of each law, if you have the free time (and attention span) to dedicate to learning more about them. However, we understand that most of our readers are too busy to do that, so we hope you\u2019ve found this article useful and informative.<\/p>\n\n\n\n<p>Of course, the laws covered in this article aren\u2019t the only U.S. laws that have been proposed considered at some point. There are other states that have proposed legislation that have stalled, failed, or are currently under consideration \u2014 New York, Illinois, South Carolina, Ohio, just to name a few. And we\u2019ll keep our eyes out for any movement with regard to new data and consumer privacy laws that may result.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>It seems like every time you turn around, new U.S. data privacy laws are popping up. The United States is an expansive country made up of 50 individual governing states,&#8230;<\/p>\n","protected":false},"author":17,"featured_media":17485,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[13107,16],"tags":[11309,13265],"class_list":["post-17479","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-beyond-hashed-out","category-hashing-out-cyber-security","tag-laws","tag-u-s-data-privacy-laws","post-with-tags"],"views":11054,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2024\/01\/us-data-privacy-laws-feature-final.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/17479","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/17"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=17479"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/17479\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/17485"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=17479"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=17479"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=17479"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}