{"id":421,"date":"2021-08-04T11:19:14","date_gmt":"2021-08-04T15:19:14","guid":{"rendered":"https:\/\/pbacyber.com\/?p=421"},"modified":"2021-08-04T11:19:14","modified_gmt":"2021-08-04T15:19:14","slug":"model-data-privacy-bill-approved-what-the-updpa-could-do-for-state-legislatures-across-the-country","status":"publish","type":"post","link":"https:\/\/pbacyber.com\/index.php\/2021\/08\/04\/model-data-privacy-bill-approved-what-the-updpa-could-do-for-state-legislatures-across-the-country\/","title":{"rendered":"Model Data Privacy Bill Approved: What the UPDPA Could Do for State Legislatures Across the Country"},"content":{"rendered":"<p>By Krishna Jani, Flaster Greenberg<\/p>\n<p>&nbsp;<\/p>\n<p>In July 2021, the Uniform Law Commission (ULC) voted to approve the <a href=\"https:\/\/www.uniformlaws.org\/HigherLogic\/System\/DownloadDocumentFile.ashx?DocumentFileKey=bb7e5654-86aa-ebf8-dd85-b89c0dea4bc5&amp;forceDialog=0\">Uniform Personal Data Protection Act<\/a> (UPDPA). The UPDPA is a model data privacy bill designed to provide a template for states to introduce to their own legislatures, and ultimately, adopt as binding law.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>The UPDPA <\/strong><\/p>\n<p>The UPDPA would govern how business entities collect, control, and process the personal and sensitive personal data of individuals. This model bill has been in the works since 2019 and includes the input of advisors, observers, the Future of Privacy Forum, and other stakeholders. This is significant because the ULC has set forth other model laws, such as the <a href=\"https:\/\/www.uniformlaws.org\/acts\/ucc\">Uniform Commercial Code<\/a>, which have largely been adopted across the states.<\/p>\n<p>&nbsp;<\/p>\n<p>Interestingly, the model bill is much narrower than some of the recent state privacy laws that have been passed, such as the <a href=\"https:\/\/www.flastergreenberg.com\/newsroom-alerts-Cybersecurity_and_Data_Privacy_Legislative_Updates.html\">California Privacy Rights Act<\/a> and Virginia\u2019s Consumer Data Protection Act. Namely, the model bill would provide individuals with fewer, and more limited, rights including the right to copy and correct personal data. The bill does not include the right of individuals to delete their data or the right to request the transmission of their personal data to another entity.\u00a0 The bill also does not provide for a private cause of action under the UPDPA itself, but would not affect a given state\u2019s preexisting consumer protection law if that law authorizes a private right of action. If passed, the law would, consequently, be enforced by a state\u2019s attorney general.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Applicability <\/strong><\/p>\n<p>The UPDPA would apply to the activities of a controller or processor that conducts business in the state or produces products or provides services purposefully directed to residents of this state and:<\/p>\n<ul>\n<li>during a calendar year maintains personal data about more than [50,000] data subjects who are residents of this state, excluding data subjects whose data is collected or maintained solely to complete a payment transaction;<\/li>\n<li>earns more than [50] percent of its gross annual revenue during a calendar year from maintaining personal data from data subjects as a controller or processor;<\/li>\n<li>is a processor acting on behalf of a controller the processor knows or has reason to know satisfies paragraph (1) or (2); or<\/li>\n<li>maintains personal data, unless it processes the personal data solely using compatible data practices.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p>The UPDPA defines \u201cpersonal data\u201d as a record that identifies or describes a data subject by a direct identifier or is pseudonymized data. The term does not include deidentified data. The bill also defines \u201csensitive data\u201d as a category of data separate and apart from mere \u201cpersonal data.\u201d \u201cSensitive data\u201d includes such information as geolocation in real time, diagnosis or treatment for a disease or health condition, and genetic sequencing information, among other categories of data.<\/p>\n<p>&nbsp;<\/p>\n<p>The law would not apply to state agencies or political subdivisions of the state, or to publicly available information. There are other carve-outs, as well.<\/p>\n<p>&nbsp;<\/p>\n<p>Notably, the model bill also contains several different levels of \u201cdata practices,\u201d broken down into three subcategories: (1) a compatible data practice; (2) an incompatible data practice; and (3) a prohibited data practice. Each subcategory of data practice comes with a specific mandate about the level of consent required\u2014or not required\u2014to process certain data. For example, a controller or processor may engage in a compatible data practice without the data subject\u2019s consent with the expectation that a compatible data practice is consistent with the \u201cordinary expectations of data subjects or is likely to benefit data subjects substantially.\u201d Section 7 of the model bill goes on to list a series of factors that apply to determine whether processing is a compatible data practice, and consists of such considerations as the data subject\u2019s relationship to the controller and the extent to which the practice advances the economic, health, or other interests of the data subject. An incompatible data practice, by contrast, allows data subjects to withhold consent to the practice (an \u201copt-out\u201d right) for personal data and cannot be used to process sensitive data without affirmative express consent in a signed record for each practice (an \u201copt-in\u201d right). Lastly, a prohibited data practice is one in which a controller may not engage. Data practices that are likely to subject the data subject to specific and significant financial, physical, or reputational harm, for instance, are considered \u201cprohibited data practices.\u201d<\/p>\n<p>&nbsp;<\/p>\n<p>The model bill has built in a balancing test meant to gauge the amount of benefit or harm conferred upon a data subject by a controller\u2019s given data practice, and then limits that practice accordingly.<\/p>\n<p><strong>\u00a0<\/strong><\/p>\n<p><strong>What\u2019s Next<\/strong><\/p>\n<p>After final amendments, the UPDPA will be ready to be introduced to state legislatures by January 2022. This means that versions of this bill can, and likely will be, adopted by several states over the next couple of years\u2014and perhaps, eventually, lead to some degree of uniformity among the states\u2019 privacy laws.<\/p>\n<p>&nbsp;<\/p>\n<hr \/>\n<p><a href=\"https:\/\/www.flastergreenberg.com\/people-Krishna_Jani.html\" target=\"_blank\" rel=\"noopener noreferrer\">Krishna A. Jani<\/a>\u00a0is a member of Flaster Greenberg\u2019s Litigation Department focusing her practice on complex commercial litigation. She is also a member of the firm\u2019s cybersecurity and data privacy law practice groups.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>By Krishna Jani, Flaster Greenberg &nbsp; In July 2021, the Uniform Law Commission (ULC) voted to approve the Uniform Personal Data Protection Act (UPDPA). The UPDPA is a model data privacy bill designed to provide a template for states to introduce to their own legislatures, and ultimately, adopt as binding law. &nbsp; The UPDPA The <br \/><a class=\"read-more-button\" href=\"https:\/\/pbacyber.com\/index.php\/2021\/08\/04\/model-data-privacy-bill-approved-what-the-updpa-could-do-for-state-legislatures-across-the-country\/\">Read More &raquo;<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[4,23,41],"tags":[],"_links":{"self":[{"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/posts\/421"}],"collection":[{"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/comments?post=421"}],"version-history":[{"count":1,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/posts\/421\/revisions"}],"predecessor-version":[{"id":422,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/posts\/421\/revisions\/422"}],"wp:attachment":[{"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/media?parent=421"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/categories?post=421"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pbacyber.com\/index.php\/wp-json\/wp\/v2\/tags?post=421"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}