Bills · 2019-2020 Regular Session
Relating to: deletion of consumer personal data by controllers and providing a penalty.
Attorney general Consumer protection Data processing Legislature — Criminal penalties joint review committee on Privacy Trade practice
- Introduced, stopped here
- Passes Assembly, not reached
- Passes Senate, not reached
- Governor signs, not reached
- Law, not reached
Unfamiliar terms? Glossary
What this bill does
Plain-language analysis by the nonpartisan Legislative Reference Bureau
This bill generally requires controllers of consumers' personal data to delete a
consumer's personal data if the consumer requests deletion of that personal data.
Under the bill, a “controller” is a person that alone or jointly with others
determines the purposes and means of the processing of personal data. The bill
defines “personal data” as information relating to a consumer that allows the
consumer to be identified other than information lawfully made available from
federal, state, or local government records. The bill allows a consumer to request that
a controller delete personal data relating to the consumer, and the controller must
delete the personal data if certain conditions apply, such as the following: 1) it is no
longer necessary for the controller to process the consumer's personal data to
accomplish the purposes for which the personal data was collected or processed; or
2) the personal data is processed for direct marketing purposes. Under the bill, if a
controller is required to delete a consumer's personal data and has disclosed the
personal data, the controller must take reasonable steps based on the available
technology and implementation cost to notify other controllers that are processing
the personal data to delete the personal data, and other controllers so notified must
also delete the personal data.
Various exceptions are provided under the bill, and under certain conditions,
a controller is not required to delete personal data, such as if processing the personal
data is necessary for performing a contract with the consumer, detecting or stopping
a security incident, protecting against malicious, deceptive, fraudulent, or illegal
activity or prosecuting a person responsible for that activity, exercising the right of
free expression and information, complying with a legal obligation, or performing
certain tasks carried out in the public interest, or if the personal data is processed
by a political, philosophical, or religious nonprofit organization that processes only
personal data of members, former members, or persons who have regular contact
with the organization.
Also, under the bill, the attorney general may investigate violations and bring
actions for enforcement. A controller who violates the bill's personal data deletion
requirements is subject to a fine of up to $20,000,000 or of up to 4 percent of the
controller's total annual revenue, whichever is greater.
Because this bill creates a new crime or revises a penalty for an existing crime,
the Joint Review Committee on Criminal Penalties may be requested to prepare a
report.
Sponsors
Full history
- Feb 10, 2020 · Assembly
Introduced by Representatives Zimmerman, Macco, Quinn, Duchow, Wichgers, Plumer, Sortwell, Kulp, Dittrich, Thiesfeldt, Knodl, Gundrum, Brostoff, Wittke and Steffen; cosponsored by Senator Risser
- Feb 10, 2020 · Assembly
Read first time and referred to Committee on Science and Technology
- Feb 12, 2020 · Assembly
Public hearing held
- Apr 1, 2020 · Assembly
Failed to pass pursuant to Senate Joint Resolution 1