LRB-5849/1
KP:cjs
2021 - 2022 LEGISLATURE
February 9, 2022 - Introduced by Senators Larson,
Carpenter, Roys, Agard and
Smith, cosponsored by Representatives Brostoff, Hebl,
Anderson, Sinicki,
Shelton, Stubbs and Cabrera. Referred to Committee on Government
Operations, Legal Review and Consumer Protection.
SB977,1,2
1An Act to create 134.985 of the statutes;
relating to: the privacy of consumer
2data, granting rule-making authority, and providing a penalty.
Analysis by the Legislative Reference Bureau
Generally, this bill establishes requirements for businesses related to personal
information collected about consumers. The bill's requirements apply to
“businesses,” which is defined in the bill to mean a sole proprietorship, limited
liability company, corporation, association, or other entity operated for profit that
satisfies all of the following: 1) collects consumers' personal information or alone or
jointly with others determines the purposes and means of the processing of personal
information; 2) does business in this state; and 3) either has annual gross revenues
exceeding $25,000,000; buys, receives, sells, or shares the personal information of
50,000 or more consumers annually; or derives 50 percent or more of its annual
revenues from selling consumers' personal information. The bill defines “
personal
information” as information that identifies, relates to, describes, or is capable of
being associated or linked with a particular consumer or household other than
certain information that is lawfully made available from federal, state, or local
government records.
The bill requires a business to disclose certain information to consumers if the
business has an online privacy policy or a Wisconsin-specific description of
consumers' privacy rights, including the following: 1) information about how a
consumer can make a request for a copy of the personal information collected about
the consumer; 2) the categories of personal information collected by the business in
the past twelve months; 3) the categories of sources from which the business collected
personal information in the past twelve months; 4) the business's purposes for
collecting consumers' personal information; and 5) if the business sells consumers'
personal information, the purpose for selling the personal information. If the
business has an Internet site but not an online privacy policy or a Wisconsin-specific
description of consumers' privacy rights, the business must disclose the above
information on the Internet site.
Under the bill, a consumer may request a business to disclose certain
information if the business collects personal information about the consumer,
including the following: 1) the categories of personal information about the
consumer collected by the business in the past twelve months; 2) the categories of
sources from which the business collected personal information about the consumer
in the past twelve months; 3) the purposes for collecting the personal information
about the consumer; 4) if the business has sold the consumer's personal information
in the past twelve months, the purpose for selling the personal information; and 5)
the specific pieces of personal information about the consumer that the business
collected in the past twelve months. In addition, the business must deliver this
information within 45 days or within 90 days if the longer duration is reasonably
necessary and the business notifies the consumer about the delay within 45 days.
The business must disclose the information in a portable and readily useable format.
A consumer may request this information twice in a twelve-month period.
A consumer may request a business that sells the consumer's personal
information to disclose certain information, including the categories of personal
information collected about the consumer in the past twelve months, the categories
of personal information about the consumer that the business sold in the past twelve
months, and the categories of personal information about the consumer sold to each
third party in the past twelve months. The business must disclose the information
in a portable and readily useable format and within 45 days or within 90 days if the
longer duration is reasonably necessary.
The bill also requires a business, before collecting a consumer's personal
information, to inform the consumer about the categories of personal information
that the business will collect and the purpose for which the business will use the
personal information collected. Under the bill, in order for a business to sell a
consumer's personal information, certain requirements apply, including the
following: 1) if the business has an Internet site, it must provide a link titled “Do Not
Sell My Personal Information” that enables consumers to object to the selling of the
consumer's personal information; 2) if the business has an online privacy policy, the
business must include the link described above in that policy; 3) a business may not
sell the personal information if a consumer is 16 or older and the consumer directs
the business not to sell the consumer's personal information; 4) a business may sell
the personal information of a consumer aged 13 to 16 only if the consumer
affirmatively authorizes selling the personal information; 5) a business may sell the
personal information of a consumer under the age of 13 only if the consumer's parent
or guardian affirmatively authorizes it; and 6) a third party must notify a consumer
before selling the consumer's personal information. A business must also implement
reasonable security procedures to protect the personal information of consumers.
The bill also requires that if a consumer requests that a business delete the
personal information that the business has collected about the consumer, the
business must delete that personal information. The bill provides certain exceptions
to that requirement, including the cases in which it is necessary for the business to
maintain the personal information to do any of the following: 1) complete a
transaction or contract with a consumer; 2) detect security incidents; 3) identify
errors; 4) exercise free speech or ensure the right of another consumer to exercise free
speech; 5) comply with a legal obligation; or 6) otherwise use the personal
information internally in a lawful manner.
The bill provides that a business may not discriminate against a consumer
because the consumer requests information about the business's collection or sale of
personal information, requests the business not to sell the consumer's personal
information, or requests that the business delete the consumer's personal
information. Under the bill, a business is allowed to charge a consumer a different
price or provide a different level of services if the difference is reasonably related to
the value provided to the consumer by the consumer's personal data, and a business
may offer financial incentives to a consumer for collecting the consumer's personal
information, subject to certain requirements described in the bill.
The bill requires the Department of Justice to promulgate various rules to
implement the bill's requirements. The bill also authorizes businesses to request
advice from the attorney general on how to comply with the bill's requirements and
requires the attorney general to respond to those requests.
Additionally, a provision in a contract is void and unenforceable if it would
waive or limit one or more of the bill's requirements. The bill also provides a
consumer with a private cause of action against a business if the business does not
implement reasonable security procedures to protect the consumer's personal
information and the personal information is subject to unauthorized access. A
business, service provider, or person that violates the bill is subject to a forfeiture of
up to $2,500 for each violation and a forfeiture of up to $7,500 for each intentional
violation.
For further information see the state fiscal estimate, which will be printed as
an appendix to this bill.
The people of the state of Wisconsin, represented in senate and assembly, do
enact as follows:
SB977,1
1Section
1. 134.985 of the statutes is created to read:
SB977,3,2
2134.985 Consumer data. (1) Definitions. In this section:
SB977,4,23
(a) “Aggregate consumer information” means information that relates to a
4group or category of consumers, from which individual consumer identities have
1been removed, and that is not linked or reasonably linkable to any consumer or
2household.
SB977,4,93
(b) “Biometric information” means an individual's physiological, biological, or
4behavioral characteristics, including deoxyribonucleic acid, that can be used singly
5or in combination with each other or with other identifying data to establish
6individual identity. “Biometric information” includes imagery of the iris, retina,
7fingerprint, face, hand, palm, vein patterns, voice recordings, keystroke patterns or
8rhythms, gait patterns or rhythms, and sleep, health, or exercise data that contain
9identifying information.
SB977,4,1010
(c) “Business” means any of the following:
SB977,4,1611
1. A sole proprietorship, partnership, limited liability company, corporation,
12association, or other legal entity that is organized or operated for the profit or
13financial benefit of its shareholders or other owners, that collects consumers'
14personal information or, on the behalf of consumers, alone or jointly with others
15determines the purposes and means of the processing of consumers' personal
16information, that does business in this state, and that satisfies any of the following:
SB977,4,1717
a. Has annual gross revenues exceeding $25,000,000.
SB977,4,2018
b. Annually, alone or jointly with others buys, receives for commercial
19purposes, sells, or shares for commercial purposes the personal information of 50,000
20or more consumers, households, or devices.
SB977,4,2221
c. Derives 50 percent or more of its annual revenues from selling consumers'
22personal information.
SB977,4,2423
2. An entity that controls or is controlled by an entity described in subd. 1. and
24that shares a name, service mark, or trademark with that entity.
SB977,5,6
1(d) “Business purpose” means a use of personal information for a business's or
2a service provider's operational purposes or other notified purposes that is
3reasonably necessary and proportionate to achieving the operational purpose for
4which the personal information was collected or processed or for another operational
5purpose that is compatible with the context in which the personal information was
6collected.
SB977,5,97
(e) “Collect” means to gather, obtain, receive, buy, rent, or access personal
8information pertaining to a consumer by any means, including by receiving
9information from the consumer or by observing the consumer's behavior.
SB977,5,1010
(f) “Consumer” means an individual who is a resident of this state.
SB977,5,1111
(g) “Deidentified” means information to which all of the following apply:
SB977,5,1412
1. The information does not reasonably identify, relate to, or describe a
13consumer and is not capable of being associated with or linked to an individual
14consumer.
SB977,5,1715
2. Technical safeguards and business processes implemented by the person
16possessing the information prohibit identifying an individual consumer to whom the
17information pertains.
SB977,5,1918
(h) “Device” means an object that is capable of directly or indirectly connecting
19to the Internet or to another device.
SB977,5,2420
(i) 1. “Personal information” means information that identifies, relates to,
21describes, or is capable of being associated or linked with a particular consumer or
22household. “Personal information” includes all of the following that identify, relate
23to, describe, or are capable of being associated or linked with a particular individual
24consumer or household:
SB977,6,3
1a. Identifiers such as a real name, alias, postal address, unique personal
2identifier, online identifier, Internet Protocol address, e-mail address, account
3name, social security number, driver's license number, or passport number.
SB977,6,64
b. A signature, telephone number, state identification card number, insurance
5policy number, employment history, bank account number, credit card number, or
6debit card number or medical information or health insurance information.
SB977,6,77
c. Characteristics of protected classifications under state or federal law.
SB977,6,108
d. Commercial information such as records of personal property, records of
9products or services purchased, obtained, or considered, or other purchasing or
10consuming histories or tendencies.
SB977,6,1111
e. Biometric information.
SB977,6,1412
f. Internet or other electronic network activity information, including browsing
13history, search history, and information regarding a consumer's interaction with an
14Internet site, application, or advertisement.
SB977,6,1515
g. Geolocation data.
SB977,6,1616
h. Audio, electronic, visual, thermal, olfactory, or similar information.
SB977,6,1717
i. Professional or employment-related information.
SB977,6,2018
j. Education information that is not publicly available personally identifiable
19information under the federal Family Educational Rights and Privacy Act,
20 USC
201232g.
SB977,6,2321
k. Inferences drawn from personal information that create a profile about a
22consumer reflecting the consumer's preferences, characteristics, psychological
23trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.
SB977,7,224
2. “Personal information” does not include information that is lawfully made
25available from federal, state, or local government records if the information is used
1for a purpose that is compatible with the purpose for which the information is
2maintained and made available.