Skip to content

Bills · 2019-2020 Regular Session

AB 871

Died at session end Official bill text Atom feed

Relating to: deletion of consumer personal data by controllers and providing a penalty.

Attorney general Consumer protection Data processing Legislature — Criminal penalties joint review committee on Privacy Trade practice

  1. Introduced, stopped here
  2. Passes Assembly, not reached
  3. Passes Senate, not reached
  4. Governor signs, not reached
  5. Law, not reached

Unfamiliar terms? Glossary

What this bill does

Plain-language analysis by the nonpartisan Legislative Reference Bureau

This bill generally requires controllers of consumers' personal data to delete a

consumer's personal data if the consumer requests deletion of that personal data.

Under the bill, a “controller” is a person that alone or jointly with others

determines the purposes and means of the processing of personal data. The bill

defines “personal data” as information relating to a consumer that allows the

consumer to be identified other than information lawfully made available from

federal, state, or local government records. The bill allows a consumer to request that

a controller delete personal data relating to the consumer, and the controller must

delete the personal data if certain conditions apply, such as the following: 1) it is no

longer necessary for the controller to process the consumer's personal data to

accomplish the purposes for which the personal data was collected or processed; or

2) the personal data is processed for direct marketing purposes. Under the bill, if a

controller is required to delete a consumer's personal data and has disclosed the

personal data, the controller must take reasonable steps based on the available

technology and implementation cost to notify other controllers that are processing

the personal data to delete the personal data, and other controllers so notified must

also delete the personal data.

Various exceptions are provided under the bill, and under certain conditions,

a controller is not required to delete personal data, such as if processing the personal

data is necessary for performing a contract with the consumer, detecting or stopping

a security incident, protecting against malicious, deceptive, fraudulent, or illegal

activity or prosecuting a person responsible for that activity, exercising the right of

free expression and information, complying with a legal obligation, or performing

certain tasks carried out in the public interest, or if the personal data is processed

by a political, philosophical, or religious nonprofit organization that processes only

personal data of members, former members, or persons who have regular contact

with the organization.

Also, under the bill, the attorney general may investigate violations and bring

actions for enforcement. A controller who violates the bill's personal data deletion

requirements is subject to a fine of up to $20,000,000 or of up to 4 percent of the

controller's total annual revenue, whichever is greater.

Because this bill creates a new crime or revises a penalty for an existing crime,

the Joint Review Committee on Criminal Penalties may be requested to prepare a

report.

Sponsors

Introduced by: Brostoff (D) , Dittrich (R) , Duchow (R) , Gundrum (R) , Knodl (R) , Kulp (R) , Macco (R) , Plumer (R) , Quinn (R) , Sortwell (R) , Steffen (R) , Thiesfeldt (R) , Wichgers (R) , Wittke (R) , Zimmerman (R)

1 cosponsors

Risser (D)

Full history

  1. Feb 10, 2020 · Assembly

    Introduced by Representatives Zimmerman, Macco, Quinn, Duchow, Wichgers, Plumer, Sortwell, Kulp, Dittrich, Thiesfeldt, Knodl, Gundrum, Brostoff, Wittke and Steffen; cosponsored by Senator Risser

  2. Feb 10, 2020 · Assembly

    Read first time and referred to Committee on Science and Technology

  3. Feb 12, 2020 · Assembly

    Public hearing held

  4. Apr 1, 2020 · Assembly

    Failed to pass pursuant to Senate Joint Resolution 1