Sec. 7. Deidentified and pseudonymous data
333 words·~2 min read·
/bill/119/hr/8413/ih/section-7·A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
A controller in possession of deidentified data shall— take reasonable measures to ensure the data cannot be associated with an individual; publicly commit to maintain and use deidentified data without attempting to re-identify the data; and contractually obligate any recipient of the deidentified data to comply with each requirement of this Act. A controller that discloses deidentified or pseudonymous data shall exercise reasonable oversight to monitor compliance with any contractual commitment to which the deidentified or pseudonymous data is subject and shall take appropriate steps to address any breach of such contractual commitment.
An assertion of any consumer right described under section 2 does not apply to pseudonymous data for a case in which the controller is able to demonstrate any information necessary to identify the consumer is kept separately and is subject to appropriate administrative and technical measures to ensure that the personal data is not attributed to an identified or identifiable natural person. Nothing in this Act may be construed to require a controller or processor to— re-identify deidentified data or pseudonymous data; or maintain data in identifiable form, or collect, obtain, retain, or access any data or technology, in order to be capable of associating a consumer request with personal data.
Nothing in this Act may be construed to require a controller or processor to comply with an assertion of any consumer right described under section 2 if— the controller is not reasonably capable of associating the request with the personal data or it would be unduly burdensome for the controller to associate the request with the personal data; the controller does not use the personal data to recognize or respond to the specific consumer who is the subject of the personal data, or associate the personal data with other personal data about the same specific consumer; and the controller does not sell the personal data to another controller or otherwise voluntarily disclose the personal data to any entity other than a processor, except as otherwise permitted in this section.