HB 827: Menstrual Data Privacy and Protection Act; enact
Versión Introduced, la más reciente que tiene LegiScan · Última acción: 28 de marzo de 2025 · Introduced
El texto tal como lo tiene LegiScan, leído del PDF que publica la legislatura, sin los números de línea del margen, los encabezados ni los pies de página. Aquí los saltos de línea se unen en párrafos; no se cambia ninguna palabra. El texto está en inglés.
Las palabras subrayadas son las que el proyecto de ley agrega a la ley vigente y las tachadas son las que elimina, tal como las muestra el proyecto impreso.
House Bill 827
By: Representatives McQueen of the 61st, Roberts of the 52nd, Miller of the 62nd, Evans of the 57th, Willis of the 55th, and others
A BILL TO BE ENTITLED
AN ACT
To amend Chapter 1 of Title 10 of the Official Code of Georgia Annotated, relating to selling and other trade practices, so as to enact the "Menstrual Data Privacy and Protection Act"; to provide for definitions; to require explicit consent; to provide for security, notification of data breaches, and deletion of data; to provide for violations; to provide for reporting; to provide for relief; to provide for related matters; to provide for legislative purpose; to repeal conflicting laws; and for other purposes.
BE IT ENACTED BY THE GENERAL ASSEMBLY OF GEORGIA:
SECTION 1.
This Act shall be known and may be cited as the "Menstrual Data Privacy and Protection Act."
SECTION 2.
The purpose of this Act is to safeguard the privacy and security of menstrual and reproductive health data collected by applications, devices, pharmacies, healthcare providers, and other entities. This legislation ensures that individuals retain control over their sensitive personal information and protects against misuse, unauthorized sharing, and data breaches involving such information.
SECTION 3.
Chapter 1 of Title 10 of the Official Code of Georgia Annotated, relating to selling and other trade practices, is amended by enacting a new article to read as follows: "ARTICLE 37
10-1-960.
As used in this article, the term:
(1) 'Entity' means any organization, business, or individual collecting menstrual data, including, but not limited to, digital applications and platforms, pharmacies and retail establishments, healthcare providers, clinics, and hospitals.
(2) 'Explicit consent' means a clear and affirmative agreement provided by an individual after being fully informed of the specific purpose for menstrual data collection and usage.
(3) 'Menstrual data' means any information related to an individual's menstrual cycle, reproductive health, or related bodily functions collected by an entity, including, but not limited to, menstrual tracking applications and devices, pharmacies and healthcare providers, and online or in-person retail purchases of menstrual products.
10-1-961.
(a) An entity shall obtain explicit consent from an individual before collecting, processing, or sharing menstrual data belonging to such individual.
(b) Menstrual data may only be used by an entity for specific purposes provided in an explicit consent agreement. No entity shall use such menstrual data for unrelated purposes, including marketing or targeted advertising, without obtaining explicit consent to such effect.
(c) No entity shall sell menstrual data or reproductive health data to third parties under any circumstances.
(d) Each instance of an entity collecting, processing, or sharing the menstrual data of an individual without obtaining such individual's explicit consent, using an individual's menstrual data for purposes not provided in an explicit consent agreement with such individual, or selling menstrual data belonging to an individual shall constitute a separate violation.
10-1-962.
(a) An entity shall implement industry standard security measures, including, but not limited to, data encryption during storage and transmission, regular security audits, and vulnerability assessments.
(b) An entity shall notify affected individuals and the Attorney General within 72 hours of any data breach involving menstrual data.
(c) Every individual shall have the right to request that any entity in possession of menstrual data belonging to such individual delete such menstrual data at any time. An entity shall comply with menstrual data deletion requests within 30 days and notify the requesting individual when the data at issue has been deleted. Deleted menstrual data shall not be retained in any form by the entity or its partners.
(d) Each instance of an entity failing to implement the security measures provided in subsection (a) of this Code section, to notify an individual affected by a data breach involving such individual's menstrual data as provided in subsection (b) of this Code section, or to delete menstrual data following the procedures provided in subsection (c) of this Code section shall constitute a separate violation.
10-1-963.
(a) Each entity shall publish on a website accessible to the public a privacy policy detailing the types of menstrual data it collects, the purposes for which such data is used, and any third parties with whom such data may be shared.
(b) Each entity shall publish on a website accessible to the public an annual report summarizing data protection measures it has implemented, any data breaches or incidents it has reported during the year, and any efforts it has made to comply with the provisions of this article.
10-1-964.
(a) Whenever it may appear to the Attorney General that an entity has violated the provisions of this article, the Attorney General may seek, and any superior court of competent jurisdiction may grant, any or all of the following relief:
(1) A temporary restraining order or temporary or permanent injunction;
(2) A civil penalty of up to $50,000.00 per violation or $500.00 per affected individual, whichever is greater;
(3) A declaratory judgment; or
(4) Other relief as the court deems just and equitable, including, but not limited to, reasonable attorney's fees and costs.
(b) Any individual whose menstrual data is collected, processed, shared, or sold in violation of the provisions of this article may bring a civil action against the violating entity in any court having jurisdiction over such entity seeking any or all of the following relief:
(1) Actual damages;
(2) Statutory damages of up to $2,500 per violation; or
(3) Reasonable attorney's fees and costs."
SECTION 4.
All laws and parts of laws in conflict with this Act are repealed.