Tap any paragraph to write a margin note. Your notes collect in the Desk below the text and file under cases with @. The side-by-side margin rail opens on a larger screen.

Code · BILL · 117th Congress · S. 2499 (Introduced in Senate) — To establish data privacy and data security protections for consumers in the United States. · Sec. 103

Sec. 103. Individual control

653 words·~3 min read·/bill/117/s/2499/is/section-103·

A research copy — for the controlling text, always check the official state or federal source. Not legal advice.

Subject to paragraphs
(2)and
(3)and section 108, a covered entity shall provide an individual, immediately or as quickly as possible and in no case later than 90 days after receiving a verified request from the individual, with the right to reasonably— access— the covered data of the individual, or an accurate representation of the covered data of the individual, that is or has been processed by the covered entity or any service provider on behalf of the covered entity; if applicable, a list of categories of third parties and service providers to whom the covered entity has transferred the covered data of the individual; and if a covered entity transfers covered data, a description of the purpose for which the covered entity transferred the covered data of the individual to a service provider or third party; request that the covered entity— correct inaccuracies or incomplete information with respect to the covered data of the individual that is maintained by the covered entity; and notify any service provider or third party to which the covered entity transferred such covered data of the corrected information; request that the covered entity— either delete or deidentify covered data of the individual that is or has been maintained by the covered entity; and notify any service provider or third party to which the covered entity transferred such covered data of the individual’s request under clause (i), unless the transfer of such data to the third party was made at the direction of the individual; and to the extent that is technically feasible, provide covered data of the individual that is or has been generated and submitted to the covered entity by the individual and maintained by the covered entity in a portable, structured, and machine-readable format that is not subject to licensing restrictions. A covered entity shall— provide an individual with the opportunity to exercise the rights described in paragraph
(1)not less than twice in any 12-month period; and with respect to the first 2 times that an individual exercises the rights described in paragraph
(1)in any 12-month period, allow the individual to exercise such rights free of charge. A covered entity— shall not comply with a request to exercise the rights described in paragraph
(1)if the covered entity cannot verify— that the individual making the request is the individual to whom the covered data that is the subject of the request relates; or the individual’s assertion under paragraph (1)(B) that such information is inaccurate or incomplete; may decline to comply with a request that would— require the covered entity to retain any covered data for the sole purpose of fulfilling the request; be impossible or demonstrably impracticable to comply with; require the covered entity to combine, relink, or otherwise reidentify covered data that has been deidentified; result in the release of trade secrets, or other proprietary or confidential data or business practices; interfere with law enforcement, judicial proceedings, investigations, or reasonable efforts to guard against, detect, or investigate malicious or unlawful activity, or enforce contracts; require disproportionate effort, taking into consideration available technology, or would not be reasonably feasible on technical grounds; compromise the privacy, security, or other rights of the covered data of another individual; be excessive or abusive to another individual; or violate Federal or State law or the rights and freedoms of another individual, including under the Constitution of the United States; and may delete covered data instead of providing access and correction rights under subparagraphs
(A)and
(B)of paragraph
(1)if such covered data— is not sensitive covered data; and is used only for the purposes of contacting individuals with respect to marketing communications. Not later than 1 year after the date of enactment of this Act, the Commission shall promulgate regulations under section 553 of title 5, United States Code, establishing processes by which covered entities may verify requests to exercise rights described in subsection (a)(1).
★   the supreme law of the land   ★
Don't Tread on Me
E Pluribus Unum — out of many, one

"If you don't know your rights, you don't have any."

Marginalia · a citizen's law index
A research desk, not legal advice. Always read the cited source before relying on a summary.
Questions or an issue? support@self-law.org
disclaimerMarginalia is a research index, not a law firm. Nothing on this site is legal, tax, or financial advice and no attorney–client relationship is formed by using it. Statutes, regulations, and case law change; summaries, search results, AI output, and member posts may be incomplete, out of date, or wrong. Any interpretation drawn from material on this site should be validated by a licensed attorney in your jurisdiction before you act on it.