HB 827: Menstrual Data Privacy and Protection Act; enact
Última acción: 28 de marzo de 2025 · House Second Readers
A Georgia House bill would create new privacy rules for menstrual and reproductive health data collected by apps, pharmacies, and health providers, requiring explicit consent before collecting or sharing it and banning its sale.
Los resúmenes de abajo son traducciones de resúmenes en inglés escritos por un modelo de IA (claude-sonnet-5) a partir del texto del proyecto de ley; no forman parte de él. El proyecto de ley está en inglés. Cite el texto, no el resumen. El texto almacenado es la versión Introduced, la más reciente que tiene LegiScan.
El resumen en español de este proyecto de ley se está preparando. Mientras tanto se muestra el resumen en inglés.
En lenguaje claro
Right now, apps that track periods, pharmacies, and healthcare providers can collect menstrual and reproductive health data without any specific Georgia law governing consent, security, or sale of that information. This bill would create the "Menstrual Data Privacy and Protection Act" as a new article in Georgia's trade practices law (O.C.G.A. Title 10, Chapter 1). The bill would require any entity collecting menstrual data, from period-tracking apps to pharmacies to hospitals, to get explicit, informed consent before collecting, using, or sharing it, and would flatly ban selling such data to third parties. Entities would have to use industry-standard security measures, report data breaches within 72 hours, and delete a person's data within 30 days of a request. Entities must also publish a public privacy policy and an annual transparency report. Violations could bring civil penalties sought by the Attorney General or a lawsuit by the affected individual.
Qué hace el proyecto de ley
- Requires entities that collect menstrual data, including apps, pharmacies, clinics, and hospitals, to obtain explicit consent before collecting, processing, or sharing it.
- Bans the sale of menstrual or reproductive health data to third parties under any circumstances.
- Requires industry-standard security measures such as encryption, regular security audits, and vulnerability assessments for entities holding menstrual data.
- Requires entities to notify affected individuals and the Attorney General within 72 hours of a data breach involving menstrual data.
- Gives individuals the right to request deletion of their menstrual data, which entities must complete within 30 days.
- Sets civil penalties of up to $50,000 per violation (or $500 per affected person) sought by the Attorney General, and lets individuals sue for actual damages, statutory damages up to $2,500 per violation, and attorney's fees.
A quién afecta
Companies and individuals that collect menstrual data, including period-tracking apps and platforms, pharmacies and retailers selling menstrual products, healthcare providers, clinics, and hospitals. It also affects Georgians who use these products and services and whose reproductive health data is collected.
Por qué importa
Menstrual and reproductive health data can reveal sensitive personal information, including possible pregnancy status. This bill would give Georgians more control over that data, letting them demand its deletion and blocking its sale, while requiring companies to secure it and quickly disclose breaches.
Disposiciones clave
- New Code Section 10-1-960 defines key terms including 'entity,' 'explicit consent,' and 'menstrual data,' covering apps, pharmacies, retailers, and healthcare providers.
- Code Section 10-1-961 requires explicit consent before collecting, processing, or sharing menstrual data, limits use to the purposes consented to, and bans selling such data to third parties, with each instance a separate violation.
- Code Section 10-1-962 requires industry-standard security measures, 72-hour breach notification to individuals and the Attorney General, and data deletion within 30 days of a request.
- Code Section 10-1-963 requires entities to publish a public privacy policy and an annual report on data protection efforts and any breaches.
- Code Section 10-1-964 authorizes the Attorney General to seek injunctions, civil penalties up to $50,000 per violation or $500 per affected person, and lets individuals sue for actual damages, up to $2,500 in statutory damages per violation, and attorney's fees.
- Section 4 repeals any conflicting Georgia laws.
Del proyecto de ley
“No entity shall sell menstrual data or reproductive health data to third parties under any circumstances.”
“An entity shall notify affected individuals and the Attorney General within 72 hours of any data breach involving menstrual data.”
“Every individual shall have the right to request that any entity in possession of menstrual data belonging to such individual delete such menstrual data at any time.”
Cronología del estado
- House Second Readers (Cámara de Representantes)
- House First Readers (Cámara de Representantes)
- House Hopper (Cámara de Representantes)
Patrocinadores
- Mekyah McQueen (D, HD-061)
- Shea Roberts (D, HD-052)
- Tanya Miller (D, HD-062)
- Stacey Evans (D, HD-057)
- Inga Willis (D, HD-055)
- Park Cannon (D, HD-058)
Temas
- menstrual data privacy
- reproductive health data
- consumer data protection
- data breach notification
- health apps