0% found this document useful (0 votes)
73 views2 pages

State Comp Privacy Law Chart

This document tracks US state privacy legislation. It lists several states that have passed comprehensive consumer privacy bills, including California, Colorado, Connecticut, Virginia, and Utah. These bills generally provide consumers with rights like access, deletion, opt-out of sales, and non-discrimination for exercising their rights. They also require businesses to provide notice, obtain consent, conduct risk assessments, and limit data processing and usage. Michigan and New Jersey currently have active bills being considered as well.

Uploaded by

malagirlfriend
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
73 views2 pages

State Comp Privacy Law Chart

This document tracks US state privacy legislation. It lists several states that have passed comprehensive consumer privacy bills, including California, Colorado, Connecticut, Virginia, and Utah. These bills generally provide consumers with rights like access, deletion, opt-out of sales, and non-discrimination for exercising their rights. They also require businesses to provide notice, obtain consent, conduct risk assessments, and limit data processing and usage. Michigan and New Jersey currently have active bills being considered as well.

Uploaded by

malagirlfriend
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
You are on page 1/ 2

US State Privacy Legislation Tracker 2022

Comprehensive Consumer Privacy Bills


BUSINESS
CONSUMER RIGHTS
OBLIGATIONS

Prohibition on discrimination (exercising rights)


Right against automated decision making

Notice/transparency requirement
Opt-in default (requirement age)

Purpose/processing limitation
Right to opt out of sales

Private right of action


Right of rectification

Right of portability
Right of restriction

Risk assessments
Right of deletion
Right of access
LEGISLATIVE STATUTE/BILL
STATE PROCESS (HYPERLINKS) COMMON NAME
LAWS SIGNED (TO DATE)
California Consumer Privacy Act
CCPA X X X X L 16 X X
(2018; effective Jan. 1, 2020)
California
California Privacy Rights Act
Proposition 24 X X X S X X X L 16 X X X X
(2020; fully operative Jan. 1, 2023)
Colorado Privacy Act
Colorado SB 190 X X X P X X X~ S/13 X X X X
(2021; effective July 1, 2023)
Connecticut Data Privacy Act
Connecticut SB 6 X X X P X X X~ S/16 X X X X
(2022; effective July 1, 2023)
Virginia Consumer Data Protection Act
Virginia SB 1392 X X X P X X X~ S/13 X X X X
(2021; effective Jan. 1, 2023)
Utah Consumer Privacy Act
Utah SB 227 X X P X X 13 X X
(2022; effective Dec. 31, 2023)
ACTIVE BILLS
HB 5989 Consumer Privacy Act X X X P X X X~ S/18 X X X X
Michigan
SB 1182 Personal Data Privacy Act X X X P X X S/13 X X X X
New Jersey Disclosure and
A 505 X X X X X IN X X ALL X X X
Accountability Transparency Act
New Jersey
S 332 * X X X X X
A 1971 * X X X X X
Ohio HB 376 Ohio Personal Privacy Act X X X P X X 13 X X X
HB 1126 X X X L 16 X X
Pennsylvania HB 2202 Consumer Data Privacy Act X X X P X X X~ 16 X X X
HB 2257 Consumer Data Protection Act X X X P X X X~ S/18 X X X X
INACTIVE BILLS
HB 159 Consumer Data Privacy Act X X X X X 18 X X X
SB 116 Consumer Data Privacy Act X X X X X 18 X X X
Alaska
Alaska Consumer Information
HB 222 X X X S X X L 16 X X X
Protection Act
Arizona HB 2790 X X X X X X X X
SB 1864 Florida Privacy Protection Act X X X P X X S/16 X X X
Florida
HB 9 X X X X X L 18 X X X
Georgia SB 394 Georgia Computer Data Privacy Act X X X IN X ALL X X X
HB 2051 Hawaii Consumer Privacy Act X X X S X X * 16 X * X X
SB 2428 Consumer Data Protection Act X X X P X X X~ S/16 X X X X
Hawaii
SB 2797 Consumer Data Protection Act X X X P X X X~ S/16 X X X X
HB 2341 Consumer Data Protection Act X X X P X X X~ S/16 X X X X
HB 1261 X X X X X 16 X
Indiana
SB 358 X X X P X X X~ S/13 X X X X
HF 2506 X X P X X X~ 13 X X X
Iowa
SF 2208 X X X P X X X~ S/13 X X X X
SB 15 X X X X L S/18 X X X X
Kentucky
HB 586 X X X X 13 X X X
Louisiana HB 987 Louisiana Consumer Privacy Act X X X P X X 13 X X X
Maine LD 1982 Maine Consumer Privacy Act X X X X L 16 X X X
Maryland SB 11 Workgroup substituted for comprehensive bill
Massachusetts Information Privacy
S 2687 X X X S X X L 16 X X X X
and Security Act
Massachusetts Information Privacy
Massachusetts H 4514 X X X S X X L 16 X X X X
and Security Act
S 46 * Massachusetts Information Privacy Act X X X X X IN X X ALL X X X
H 142 * Massachusetts Information Privacy Act X X X X X IN X X ALL X X X
H 136 * X X X X X X X~ X X A X X
Minnesota HF 1492 Minnesota Consumer Data Privacy Act X X X P X X X~ S/13 X X X X
Mississippi SB 2330 Mississippi Consumer Data Privacy Act X X X L 16 X X
Nebraska LB 1188 Uniform Personal Data Protection Act X X * * * X X X X
A 680 New York Privacy Act X X X X X IN X L ALL X X X X
S 6701 New York Privacy Act X X X X X X L S X X X X
New York A 6042 Digital Fairness Act X X X IN X X ALL X A X X
S 567 X X X 16 X X
A 3709 X X X 16 X X
North Carolina S 569 Consumer Privacy Act X X X X X X~ X S X X X X
HB 1602 Oklahoma Computer Data Privacy Act X X X IN ALL X X
HB 3447 Uniform Personal Data Protection Act X X * * * X X X X
Oklahoma
Oklahoma Computer Data
HB 2969 X X X IN ALL X X X
Privacy Act of 2022
Rhode Island H 7917 Rhode Island Information Privacy Act X X X X X IN X ALL X X X
H 160 Only short-form bill available
Vermont
H 570 Only short-form bill available
HB 1433 People’s Privacy Act X X X X X IN X ALL X X X
SB 5062 Washington Privacy Act X X X P X X X~ S/13 X X X X
Washington Washington Foundational Data
HB 1850 Commission substituted for comprehensive bill *
Privacy Act
SB 5813 X X X X L 18 X A X X
West Virginia HB 4454 S X 16 X X
AB 957 X X X P X X X~ S/13 X X X X
SB 957 X X X P X X X~ S/13 X X X X
Wisconsin
AB 1050 X X X X L 16 X X
SB 977 X X X X L 16 X X
INTRODUCED
IN COMMITTEE
IN CROSS CHAMBER
IN CROSS COMMITTEE
PASSED
SIGNED

A - risk assesments for limited purposes only


IN - opt-in consent requirement
L - private right of action limited to certain violations only
P - right to opt-out of processing for profiling/targeted advertising purposes
S - sensitive data
X - right or obligation exists
~ - right to opt out of certain automated decision making
* - see notes

* Hawaii HB 2051 - Bill requires the Department of Commerce and Consumer Affairs to adopt rules governing opt-out rights for automated decision
making and risk assessment obligations.
* Nebraska LB 1188 and Oklahoma HB 3447 - Bills are based on the Uniform Law Commission’s model privacy bill, the UPDPA. This model bill
does not require consent for processing that “is consistent with the ordinary expectations of data subjects or is likely to benefit data subjects
substantially;” consent is required for processing that is an “incompatible data practice,” and certain types of processing are prohibited.
* New Jersey S 332 and A 1971 - Bills are limited to commercial Internet websites and online services only.
* Washington HB 1850 - Bill contingent upon enactment of the WPA (SB 5062).
* Massachusetts S 46, H 142 and H 136 - Bills replaced by the MIPSA (S 2687/H 4514).

The most recent version of the IAPP’s US State Privacy Legislation Tracker can be found here.
IAPP has previous editions of the Tracker for 2021, 2020, and 2018-2019.

↓ TERMS IN CHART ↓ Last updated: 10/7/2022


US State Privacy Legislation Tracker 2022
Comprehensive Consumer Privacy Bills

TERMS USED IN CHART


The US State Privacy Legislation Tracker chart contains terms regarding the legislative process, consumer rights and
business obligations. To better understand these terms and how IAPP is using them in the chart, see below.

LEGISLATIVE PROCESS
Each state legislature has a unique legislative calendar and different legislative procedures.
This set of columns generalizes those different legislative procedures into six categories:
Introduced — A bill has been introduced on a legislative chamber floor but has not yet moved into committee.
In Committee — A bill is moving through the various committees in its chamber of origin.
In Cross Chamber — A bill has passed a vote in its chamber of origin and moved to the opposite chamber of the
legislature (e.g., a state house of representatives passed a bill and it moved to the state senate).
In Cross Committee — A bill is moving through the various committees in its non-originating chamber.
Passed — Both chambers of the legislature have passed the bill.
Signed — The governor signed the bill and it is now law.

CONSUMER RIGHTS
Right of access — The right for a consumer to access from a business/data controller the information or categories
of information collected about a consumer, the information or categories of information shared with third parties,
or the specific third parties or categories of third parties to which the information was shared; or, some combination
of similar information.
Right of rectification — The right for a consumer to request that incorrect or outdated personal information be
corrected but not deleted.
Right of deletion — The right for a consumer to request deletion of personal information about the consumer
under certain conditions.
Right of restriction — The right for a consumer to restrict a business’s ability to process personal information
about the consumer.
Right of portability — The right for a consumer to request personal information about the consumer be disclosed
in a common file format.
Right to opt-out of sales — The right for a consumer to opt out of the sale of personal information about the
consumer to third parties.
Right against automated decision making — A prohibition against a business making decisions about a
consumer based solely on an automated process without human input.
Private right of action — The right for a consumer to seek civil damages from a business for violations of a statute.

BUSINESS OBLIGATIONS
Opt-in default (requirement age) — A restriction placed on a business to treat consumers under a certain age
with an opt-in default for the sale of their personal information.
Notice/transparency requirement — An obligation placed on a business to provide notice to consumers about
certain data practices, privacy operations, and/or privacy programs.
Risk assessments — An obligation placed on a business to conduct formal risk assessments of privacy and/or
security projects or procedures.
Prohibition on discrimination (exercising rights) — A prohibition against a business treating a consumer who
exercises a consumer right differently than a consumer who does not exercise a right.
Purpose/processing limitation — An EU General Data Protection Regulation–style restrictive structure that
prohibits the collection/processing of personal information except for a specific purpose.

↑ BACK TO CHART ↑ Last updated: 10/7/2022

You might also like