D-01
Data Governance
Automated Processing Rights & Data Controls
Deployers must honor individuals' rights to know about, correct, and/or opt out of automated processing of their personal data for consequential decisions, and must restrict use of sensitive attributes in AI decision-making and minimize data collection to what the stated purpose requires.
Sub-obligations11
Bills236
Jurisdictions43
Enacted11
Show
Sort bills within section

11 sub-obligations of D-01

Click any row to jump to its bills below.
ID Sub-Obligation Enacted Live Failed Total
D-01.1 Right to know
Deployers must inform individuals that their personal data is being used in an automated decision-making system, including the categories of data used.
4Enacted 69Live 37Failed 110Total Jump →
D-01.2 Right to correct
Individuals have the right to correct inaccurate personal data used in automated decisions, and to have the correction reflected in pending and future decisions — not just in the underlying record.
2Enacted 36Live 10Failed 48Total Jump →
D-01.3 Right to opt out
Individuals have the right to opt out of automated processing of their personal data for consequential decisions.
2Enacted 40Live 24Failed 66Total Jump →
D-01.4 Data minimization
Data collected and generated in connection with AI systems — including behavioral data, inferences, and derived attributes — must be limited to what is necessary for the AI system's stated purpose. Secondary uses require separate justification.
11Enacted 202Live 72Failed 285Total Jump →
D-01.5 Sensitive attribute restrictions
AI systems may not use sensitive personal attributes (race, gender, religion, health status, sexual orientation, national origin, disability) as direct inputs to consequential automated decisions except where expressly permitted. Proxy variable restrictions also apply — systems may not be designed to infer sensitive attributes from non-sensitive proxies for use in consequential decisions.
1Enacted 31Live 11Failed 43Total Jump →
D-01.6 Age-Differentiated Parental Control and Privacy Tools
Operators must provide minor-specific and under-thirteen parental or guardian tools for managing privacy and account settings, including control over interaction data retention for personalization, use of personal data for AI training, and account deletion. Age assurance data must be minimized and immediately deleted upon determination.
2Enacted 11Live 6Failed 19Total Jump →
D-01.7 Biometric Data Pre-Collection Consent
Entities must provide written notice and obtain affirmative opt-in consent from individuals before collecting any biometric identifier, including specific notice of identifier type and collection purpose. Consent obtained from publicly available sources is insufficient unless the individual themselves made the data publicly available.
6Enacted 29Live 11Failed 46Total Jump →
D-01.8 Conversational data retention limits
Deployers of conversational AI systems and chatbots must not retain user interaction records — chat logs, transcripts, voice recordings, and derived interaction data — beyond a defined maximum retention period, and must securely destroy them at the end of that period. Continued retention is permitted only where required by law or under affirmative user consent for a defined period.
0Enacted 9Live 2Failed 11Total Jump →
D-01.9 Prohibition on sale of AI interaction data
Deployers of conversational AI systems and chatbots must not sell, lease, trade, or otherwise profit from disclosing user chat logs, transcripts, voice recordings, or other AI-interaction data. Narrow exceptions apply only for disclosures to service providers bound by equivalent restrictions under a data-processing contract.
0Enacted 12Live 6Failed 18Total Jump →
D-01.10 Biometric Data Retention and Destruction Policy
Deployers and Developers in possession of biometric data must develop, publicly disclose, and adhere to a written policy establishing a retention schedule and mandatory destruction timeline, and must permanently destroy biometric data once the purpose for collection has been satisfied.
0Enacted 4Live 2Failed 6Total Jump →
D-01.11 Biometric Data Security Standards
Deployers and Developers in possession of biometric data must store, transmit, and protect it using security measures that meet the reasonable standard of care within the entity's industry and that are at least as protective as the measures applied to the entity's other confidential and sensitive information.
0Enacted 9Live 2Failed 11Total Jump →
Bills That Map This Requirement 725 mappings
D-01.1
Right to know
Deployers must inform individuals that their personal data is being used in an automated decision-making system, including the categories of data used.
Enacted
4
Live
69
Failed
37
Total
110
CT
CT SB 4 (Consumer Privacy) § Section 17 (amending Conn. Gen. Stat. § 42-524(a))
Enacted eff 2026-10-01
Controllers, processors, and consumer health data controllers operating a facial recognition database must maintain a privacy policy that lets consumers (1) readily determine whether they are included in the FRT database and (2) submit a written request to be removed. The entity must grant or deny each removal request within 15 days and send a written notice to the consumer disclosing the decision, the reasons for it, and — if denied — contact information for the Connecticut Attorney General's office.
KY
Enacted eff 2027-07-01
Controllers must provide consumers with a reasonably accessible, clear, and meaningful privacy notice disclosing: (1) categories of personal data processed, (2) processing purposes, (3) how to exercise consumer rights and appeal decisions, (4) categories of data shared with third parties, and (5) categories of third-party recipients.
KY
Enacted eff 2027-07-01
Controllers must establish and describe in a privacy notice one or more secure and reliable means for consumers to submit rights requests, accounting for normal interaction channels, security, and authentication capability. Controllers must not require consumers to create a new account to exercise their rights.
NE
Enacted eff 2026-01-01
Covered online services must display an obvious sign to covered minors when precise geolocation information is being collected or used.
CA
CA SB 947 (Workplace ADS) § Lab. Code § 1522
Engrossed
Workers have the right to request, and employers must provide, a copy of the most recent 12 months of the worker's own data primarily used by an ADS to make a disciplinary, termination, or deactivation decision. Workers may make one such request every 12 months. When providing worker data, employers must anonymize all personal information of customers, other workers, and other individuals.
NY
NY SB 9267 (Consumer Camera Privacy Act) § Gen. Bus. Law § 390-f(4)
Engrossed
Manufacturers and operators must, upon request, provide the owner with all footage captured by the owner's networked camera device within 72 hours, regardless of subscription status, in a commonly used electronic format.
AZ
AZ HB 2737 (ChatBot Protection Act) § A.R.S. § 44-1383.01
Introduced
Chatbot providers must, upon request by a user, provide the user with access to their own chat logs in a downloadable and easy-to-read format. Providers must not discriminate or retaliate against a user who requests their chat logs.
CA
Introduced
Social media companies and deployers must allow consumers to request a copy of their personal information, contextual data, and social graph, and must fulfill the request within five business days in a format that is portable, readily usable, and transmittable to another platform or deployer without impediment.
CT
Introduced eff 2026-10-01
Deployers must, before collecting any personal data of an applicant or employee for processing in an automated employment-related decision process, provide written notice disclosing: (1) the purpose of the data collection, (2) the categories of personal data to be collected, (3) the data retention period, (4) the categories of persons who will have access to the data, and (5) information about the right to opt out of personal data processing under § 42-518.
GA
GA SB 495 (Age-Appropriate Design Code) § O.C.G.A. § 10-1-974
Introduced eff 2027-01-01
Covered entities offering algorithmic feeds to minors that use the minor's personal data must provide a prominent control surface letting the minor set content preferences (recommend/block), access and correct the personal data feeding the recommendation system, and ensure the system honors those preferences. The covered entity must also offer minors a follow-only feed option that ranks content solely from sources the minor affirmatively chose.
HI
Introduced
Deployers and developers must provide affected individuals with the right to access all personal characteristics analyzed, predicted, input, inferred, or collected by the algorithmic decision system and the right to challenge and correct inaccurate data, and must create reasonable, accessible, plain-language procedures for exercising these rights.
IA
Introduced eff 2025-07-01
Device companies must present a standalone agreement at smart device initialization that (1) notifies the user that AI is installed, (2) includes the device's statement of purpose if the AI accesses private data, (3) offers an option to uninstall the AI, and (4) provides an interactive form allowing the user to refuse AI access to each type of private data before it is accessed. This agreement must be separate from any terms of service or EULA.
IA
Introduced eff 2025-07-01
Device companies must update the initialization agreement and re-present it on each affected smart device whenever the statement of purpose changes, so that users who have not yet authorized or refused access under the new terms can do so.
IA
Introduced eff 2025-07-01
Developers must present a standalone agreement at initial application startup that (1) notifies the user that the application includes AI and accesses private data, (2) includes the application's statement of purpose, and (3) provides an interactive form allowing the user to refuse application access to each type of private data before it is accessed. This agreement must be separate from any terms of service or EULA.
IA
Introduced eff 2025-07-01
Developers must update the initialization agreement and re-present it on each affected smart device whenever the application's statement of purpose changes, so that users who have not yet authorized or refused access under the new terms can do so.
IA
Introduced
Employees have the right to request a copy of the most recent twelve months of their own data primarily used by an automated decision system to make a discipline, termination, or deactivation decision. Employers must provide the data upon request. Employees are limited to one request every twelve months.
IL
Introduced
Employers must allow employees and their exclusive bargaining representatives to view the data collected by any automated decision-making system that is collecting employee data.
IL
Introduced eff 2027-01-01
Entities must make available to consumers (1) a high-level privacy policy overview covering the entity's collection, use, and disclosure of neurotechnology data, and (2) a prominent, publicly available privacy notice covering data collection, consent, use, access, disclosure, transfer, security, retention, and deletion practices.
KY
Introduced
Social media companies and model operators must provide users who request a copy of their personal data with all personal data — including social graph and contextual data — in a format that is portable, readily usable, and allows unimpeded transfer to another social media company or model operator.
LA
Introduced
Employers must allow workers to access worker data collected, used by, or produced by an ADS and to correct errors in any input or output data used by or produced by the ADS or used as corroborating evidence by a human reviewer. Workers may designate an authorized representative to request data access on their behalf.
LA
Introduced
Employers must, upon a worker's request, provide a copy of the most recent twelve months of the worker's own data primarily used by an ADS to make a discipline, termination, or deactivation decision. Workers are limited to one such request per twelve-month period.
LA
Introduced
Chatbot providers must provide users the ability to access their own retained chat logs at any time in a downloadable, human-readable, and machine-readable format, and must not discriminate against users for exercising this right.
LA
Introduced
Covered insurers must, upon consumer request, identify data sources used in an insurance decision, allow consumers to dispute data accuracy, correct inaccurate data and reconsider the adverse action, and investigate data disputes within 30 days.
MA
Introduced
Covered entities must, upon verified request, provide individuals with the right to (1) access their covered data in human-readable and machine-readable formats, (2) correct inaccuracies and notify downstream recipients, (3) delete their covered data and notify downstream recipients, and (4) export their data portably — all within 45 days (extendable by 20 days), free of charge for the first two requests per year, and without using dark patterns or deceptive design to impede exercise of these rights.
MA
Introduced
Controllers must honor consumer rights to confirm and access personal data (including inferences), obtain third-party recipient lists, correct inaccuracies with downstream notification, delete personal data with downstream notification, and obtain a portable copy — responding within 45 days (extendable by 20 days) and providing at least two free responses per 12-month period.
MA
Introduced
Controllers must publish a clear and meaningful privacy notice — provided directly to consumers and publicly online — that discloses categories of personal and sensitive data collected, processing purposes per category, how to exercise consumer rights, categories of third-party data transfers, retention periods, and contact information, and must notify consumers before implementing material changes.
MA
Introduced
Employers must provide prior written notice to and obtain written consent from all candidates and employees subject to electronic monitoring, and must conspicuously post notice describing the monitoring purpose, data collected, schedule, ADS usage, retention, use in employment decisions, productivity assessments, storage, least-invasive justification, opt-out rights, and how to exercise rights under the chapter.
MA
Introduced
Employers must give prior written notice to and obtain written consent from all candidates and employees subject to electronic monitoring, and must post the notice in a conspicuous place readily available for viewing. The notice must include at minimum: (1) a description of the monitoring purpose; (2) a description of the specific employee data to be collected, stored, secured, and disposed of, and the activities, locations, communications, and job roles monitored; (3) the dates, times, and frequency of monitoring; (4) whether and how collected data will be used as input to an automated employment decision tool; (5) whether and how collected data will be used to make an employment decision; (6) whether and how data may be used in discipline, compliance, adjudications, or litigation; (7) whether data will be used for productivity assessment or standards-setting; (8) where data will be stored and how long retained; (9) an explanation of how the monitoring practice is the least invasive means available; (10) a statement of the employee's right to refuse sale, transfer, or disclosure of their data; and (11) a description of how the employee can exercise rights under this chapter.
MI
Introduced
Employers using an electronic monitoring tool or automated decisions tool must: (a) provide written notice to all covered individuals subject to the tool; (b) obtain written consent from each covered individual; (c) ensure that collected data is accurate and up to date; (d) allow covered individuals to correct inaccurate data about themselves; (e) use the tool in a narrowly tailored manner to accomplish only a permitted purpose; (f) use the tool through the least invasive means possible; (g) ensure the tool applies to the smallest number of covered individuals, collects the least amount of data, and is used no more frequently than necessary; and (h) ensure the tool does not collect any employee data when the employee is off duty.
MI
Introduced
Employers using an electronic monitoring tool or automated decisions tool must display a poster at the employer's place of business, in a conspicuous place accessible to employees, that provides notice of the use of the tool.
MI
Introduced
At least 30 days before implementing an electronic monitoring tool or automated decisions tool, employers must provide written notice of the tool's use to all employees. Employers must also include the notice in every job posting, post it on the employer's website, provide it directly to every applicant, and make it available in accessible formats accounting for the applicant's first language (if not English) and any disability. The notice must provide covered individuals with the ability to opt out. If a covered individual opts out, the employer must not use the tool for any employment-related decisions concerning that individual.
MI
Introduced
At least 30 days before implementing a monitoring or automated decisions tool, employers must give written notice to all employees, include it in every job posting, on the website, and directly to applicants in accessible language- and disability-appropriate formats, and must let workers opt out — and may not use the tool to make any employment-related decision about a worker who opts out.
MN
Introduced eff 2026-08-01
Any person using an automated decision system for pricing or wage decisions must develop and publish reasonable procedures to (1) ensure data accuracy, (2) allow consumers or workers to correct or challenge inaccurate data, and (3) allow consumers or workers to request and receive information about what data is considered and how the system uses it.
MN
Introduced eff 2026-08-01
Persons using an automated decision system for pricing or wage decisions must develop and publish reasonable procedures to (1) ensure data accuracy, (2) allow consumers or workers to correct or challenge data accuracy, and (3) provide consumers or workers with information about what data the system considers and how it uses that data.
MN
Introduced
Employers must obtain affirmative written consent from each job applicant or worker before subjecting them to an automated decision system. The worker must first receive the pre-use notice required under § 181.9922 before providing consent.
MN
Introduced
Employers must, within seven days of a worker's request, provide copies of: (1) any of the worker's data collected, used, or produced by an ADS; (2) any input or output data used or produced by the ADS; and (3) any corroborating evidence used by a human reviewer.
MN
Introduced
Employers must provide workers with copies of their monitored data and any corroborating evidence used by a human reviewer within seven days of receiving a request.
MN
Introduced
Persons using an automated decision system for wage- or price-setting must develop and publish reasonable procedures to (1) ensure data accuracy, (2) allow consumers or workers to correct or challenge inaccurate data, and (3) enable consumers or workers to request and receive information about what data is considered and how the system uses it.
MN
Introduced eff 2026-08-01
Persons using automated decision systems for wage or price decisions must develop and publish reasonable procedures to (1) ensure data accuracy, (2) allow consumers or workers to correct or challenge the accuracy of data used by the system, and (3) enable consumers or workers to request and receive information about what data the system considers and how it uses that data.
MN
Introduced eff 2027-01-01
Employers must provide workers with a copy of all of their data collected through electronic monitoring tools, and any corroborating evidence used by a human reviewer, within seven days of receiving a request.
MN
Introduced eff 2027-01-01
Employers must provide workers with copies of their data — including all worker data collected, used, or produced by the automated decision system, all input/output data, and any corroborating evidence used by a human reviewer — within seven days of a worker's request.
MO
Introduced
Employers must, within five calendar days of an employee's or former employee's request, provide in English and the employee's primary language: (1) a written description of applicable work performance standards, (2) personal work speed data for the prior ninety days, (3) aggregated work speed data for similar employees at the same site for the prior ninety days, and (4) any discipline notices from the prior year. Former employees are limited to one request.
NJ
Introduced
Employers, public entities, and vendors must ensure all employee and service beneficiary data is accurate and up to date, notify individuals of significant data changes, provide access to all held data, and allow written correction or removal requests at least annually. If a correction request is denied, the employer must provide a written explanation and retain the request and explanation for appeal purposes.
NJ
Introduced
Employers and employment agencies must publish on the employment section of their website in a clear and conspicuous manner their AEDT data retention policy, the types of data collected, and data sources. They must also post instructions for submitting written requests for this information and respond within 30 days, or explain why disclosure would violate law or interfere with a law enforcement investigation.
NY
Introduced
Employers must, upon worker request, provide a copy of the most recent 12 months of the worker's own data primarily used by an ADS for a discipline, termination, or deactivation decision. Workers may make one such request per 12-month period. Data provided must anonymize any customer, other worker, or individual personal information.
NY
NY AB 1417 (Algorithmic Rent Pricing) § Gen. Bus. Law § 344(3)
Introduced
Landlords must not share a tenant's personal data with any third party without the tenant's written consent.
NY
NY AB 1417 (Algorithmic Rent Pricing) § Gen. Bus. Law § 344(3)
Introduced
Landlords must disclose to each tenant the categories of personal data processed, sources of data collection, processing purposes, retention periods, and the identity and data practices of each third party with whom tenant data is shared — including whether the third party uses the data for targeted advertising.
NY
NY AB 3265 (AI Bill of Rights) § State Tech. Law § 506
Introduced
Designers, developers, and deployers of automated systems must seek and respect New York residents' decisions regarding the collection, use, access, transfer, and deletion of their data in all appropriate ways and to the fullest extent possible. Where honoring such decisions is not possible, alternative privacy-by-design safeguards must be implemented.
NY
NY AB 3265 (AI Bill of Rights) § State Tech. Law § 506
Introduced
Persons developing automated systems must use consent to justify data collection only where consent can be appropriately and meaningfully given. Consent requests must be brief, understandable in plain language, and give residents agency over data collection and its specific context of use. Existing practices of complex notice-and-choice for broad data use must be transformed to emphasize clarity and user comprehension.
NY
Introduced
Employers must ensure employee data used by an AEDT is accurate and kept up to date for three years. Current and former employees have the right to request and receive, at no cost and within 14 calendar days, a copy of their own data used by the AEDT, in English or the employee's primary language. Former employees are limited to one request per year. Employers that do not monitor the relevant data have no obligation to provide it.
NY
Introduced
Landlords must disclose to each tenant the categories of personal data processed, the sources of collection, the purposes of processing, retention periods, and the identity of each third party receiving the data — including, for each third party, the categories shared, the purposes, the retention period, and whether the data is used for targeted advertising.
NY
Introduced
Employers using authorized automated wage-setting systems must develop and publish reasonable procedures to (1) ensure the accuracy of all data considered by the automated decision system, (2) allow employees to correct or challenge data accuracy, and (3) enable employees to request and receive information about what data was considered and how the system used it to set their particular wages.
NY
Introduced
Employers must ensure employee data used by AEDTs is accurate and kept up to date for three years, and must provide current or former employees with a copy of their own data used by an AEDT within 14 calendar days of request, at no cost, in the employee's primary language.
NY
Introduced
Employers must ensure electronically monitored data used for employment decisions is accurate and up to date. Current and former employees have the right to request a copy of their own monitored data and aggregated peer data (former employees limited to one request per year). Employers must respond within seven calendar days at no cost to the employee, in the employee's primary language, and may not take adverse action against employees who make such requests.
NY
Introduced
Employers using automated decision systems for wage-setting under the safe harbor must develop and publish reasonable procedures, as specified by the attorney general, to (1) ensure data accuracy, (2) allow employees to correct or challenge data used by the system, and (3) enable employees to request and receive information about what data is considered and how the system used it to set their wages.
OK
OK HB 3547 (Parent Data Sovereignty) § 70 O.S. § 3-168.1(E)
Introduced eff 2026-11-01
State education agencies and local school districts must provide parents, within thirty days of request, a complete record of all data elements collected or maintained on their child and must honor requests to correct or delete inaccurate or unnecessary data.
OK
OK HB 3547 (Parent Data Sovereignty) § 70 O.S. § 3-168.1(E)
Introduced eff 2026-11-01
School districts and the State Department of Education must provide parents annual written notice listing all data elements collected on their child, the purpose of each, and all authorized data-sharing agreements.
PA
Introduced
Digital platforms must obtain clear, conspicuous opt-in consent — separate from terms of service — before deploying an AI simulation of a user after death or five years of inactivity, specifying the content categories, simulation duration, and whether private communications may be used, and must let the user revoke consent at any time; consent expires two years after death unless renewed by the estate.
RI
RI HB 7767 (AI in Employment) § R.I. Gen. Laws § 28-5.2-2
Introduced
Employers must give prior written notice to and obtain written acknowledgment from all candidates and employees subject to electronic monitoring, and must also post the notice in a conspicuous place readily available for viewing. The notice must include at minimum: (1) the purpose for which the monitoring tool will be used, (2) the specific employee data to be collected, stored, secured, and disposed of and the schedule therefor, plus the activities, locations, communications, and job roles to be monitored, (3) the dates, times, and frequency of monitoring, (4) whether and how data will be used as input in an ADS, (5) whether and how data will be used alone or with an ADS to make employment decisions, (6) whether and how data may be stored and used in discipline, internal compliance, adjudications, or litigation, (7) whether data will be used to assess productivity performance or set productivity standards and how, (8) where data will be stored and how long it will be retained, (9) an explanation of how the monitoring practice is the least invasive means available, (10) that the employee has the right to refuse the sale, transfer, or disclosure of their employee data, and (11) a clear and understandable description of how an employee can exercise their rights under the chapter.
SC
SC HB 5138 (Chatbot Protection Act) § S.C. Code § 39-80-20
Introduced
Chatbot providers must provide users with access to their own chat logs at any time upon request. Chat logs must be provided in a downloadable and easy-to-read format. Providers must not discriminate or retaliate against a user who requests their chat logs.
SC
SC SB 896 (Chatbot Protection Act) § S.C. Code § 39-80-20
Introduced
Chatbot providers must provide any user with access to their own chat logs at any time upon request. Chat logs must be delivered in a downloadable and easy-to-read format. Chatbot providers must not discriminate or retaliate against a user who requests their chat logs.
US
Introduced
Persons intending to use an automated decision system to inform worker wages must, at least 180 days before commencing such use, publicly publish in a conspicuous and accessible format reasonable procedures that include (1) a process for ensuring data accuracy, (2) disclosure to all affected workers of what data the system considers and how it uses that data when setting wages, and (3) a procedure for workers to correct or challenge data accuracy.
US
Introduced
Providers of covered online platforms must present minor users with a clear and conspicuous notice that the platform uses a personalized recommendation system to select content, displayed the first time the minor interacts with the system.
US
Introduced
Providers of covered online platforms must include in their terms and conditions a clear, accessible, and current description of (1) features, inputs, and parameters essential to the personalized recommendation system's operation, (2) how user-specific data is collected or inferred and the categories of such data, (3) all available user options to opt out, switch algorithms, modify their profile, or influence the system's inputs, and (4) each quantity the system is designed to optimize and its relative importance.
VA
Introduced
Developers must provide a publicly available mechanism for primary content owners to submit Training Data Verification Requests and must verify within 30 days whether the owner's content was ingested by or included in a generative AI training dataset.
VT
Introduced eff 2025-07-01
Employers must provide written notice to each employee at least 15 calendar days before commencing any form of electronic monitoring. The notice must be in plain, clear, and concise language in the employee's primary language and must include at minimum 14 enumerated items: the form of monitoring; its purpose and necessity; how data will be used including for employment decisions; the technologies used; the activities, locations, communications, and job roles monitored; any third-party monitors and contract terms; any non-employer data recipients and reasons; internal positions with data access; monitoring frequency, timing, and location; data retention periods and destruction schedules; how employees can access and correct data; a cover sheet summary; employee rights and available remedies; and complaint instructions. When monitoring tracks productivity or performance, additional disclosures of standards, measurement methods, and consequences are required. Updated notice must be provided for any significant changes. An exception to advance notice applies only when the employer has reasonable grounds to believe an employee is engaged in illegal conduct, rights violations, or creating a hostile work environment — and the monitoring must be narrowly tailored and otherwise compliant.
VT
Introduced eff 2025-07-01
Employers must annually provide each employee with a list of all electronic monitoring systems currently in use in relation to that employee. The list must be in the employee's primary language. A system is considered currently in use if the employer is currently using it, used it within the past 90 days, or intends to use it within the next 30 days.
VT
Introduced eff 2025-07-01
Employers must, within seven days of receiving a request, provide an employee with access to any data relating to that employee that was produced or utilized by electronic monitoring or an automated decision system used by the employer.
VT
VT HB 784 (Chatbot Regulation) § 9 V.S.A. § 4193b
Introduced eff 2026-07-01
Chatbot providers must provide users with access to any of their own retained chat logs at any time, in a portable, downloadable, human- and machine-readable format. Chatbot providers must not discriminate or retaliate against any user for exercising this access right.
WA
Introduced eff 2026-07-01
Employers must provide each affected employee with written notice at least 15 calendar days before commencing electronic monitoring, in the employee's primary language, covering the form, purpose, data use, technologies, employment-decision linkage, third-party access, retention period, data access and correction rights, and the employee's statutory rights. Updated notice must be provided upon any significant change. An exception applies where the employer has reasonable grounds to believe the employee is engaged in illegal conduct, rights violations, or hostile-work-environment behavior and monitoring is reasonably likely to produce evidence.
WA
Introduced eff 2026-07-01
Employers must annually provide each employee with a list of all electronic monitoring systems currently in use, recently used (within 90 days), or planned for use (within 30 days) in relation to that employee, in the employee's primary language.
WA
Introduced eff 2026-07-01
Employers must provide any employee, upon request, with all data relating to that employee that was produced or utilized by electronic monitoring or an automated decision system used by the employer.
WV
WV HB 5034 (Genomic Privacy) § W. Va. Code § 16-5EE-4
Introduced eff 2026-07-01
Entities must provide consumers with clear and complete information about the entity's policies and procedures for the collection, use, or disclosure of genetic data, including: (1) a high-level privacy policy overview covering basic, essential information about genetic data collection, use, and disclosure; and (2) a prominent, publicly available privacy notice covering, at minimum, data collection, consent, use, access, disclosure, transfer, security, and retention and deletion practices for genetic data.
AK
Failed
State agencies must give notice to an individual before transferring that individual's data to another state agency, unless the transfer is required by law.
CA
Failed
Workers have the right to request, and employers must provide, a copy of the most recent 12 months of the worker's own data primarily used by an ADS to make a discipline, termination, or deactivation decision. Workers are limited to one request every 12 months.
CO
Failed eff 2026-08-12
A person that uses a price or wage setting algorithm must develop and publish reasonable procedures for: (1) ensuring the accuracy of all data considered by the PWSA; (2) enabling workers to request and receive information regarding what data the PWSA considers and how it uses that data when setting particular wages; and (3) allowing workers to correct or challenge the accuracy of data considered by the PWSA.
HI
Failed
Covered entities must develop and maintain a clear, concise, one-page notice explaining how personal information is used in algorithmic determinations — including what data is collected, sources, service-provider sharing, the relationship between data and determinations, retention periods, and individual rights under the chapter. The notice must be continuously posted on the entity's website, mobile app, and physical locations, and must be sent to individuals before the first algorithmic information availability determination. The notice must be provided in English and any non-English language spoken by at least 500 state residents and updated within 30 days of any material change. A covered entity may rely on notice provided by a contracting covered entity for the same action.
HI
Failed
Covered entities must not use any personal information in an algorithmic eligibility determination unless the individual has first been provided notice consistent with § -4(a).
HI
Failed
Covered entities must develop, continuously post, and individually deliver a clear, concise notice — in English and all non-English languages spoken by at least 500 Hawaii residents — explaining what personal information is collected, generated, inferred, used, and retained; data sources; whether data is shared with service providers (and their names); the relationship between personal information and algorithmic determinations; data retention periods; and individual rights. The notice must be updated within 30 days of any change to collection or use practices. A covered entity may not use personal information in an algorithmic eligibility determination unless notice has been provided.
HI
Failed
Covered entities must develop and continuously publish a clear, concise, multilingual notice explaining how they use personal information in algorithmic eligibility and information-availability determinations — including data types collected, sources, sharing with service providers, the relationship between data and determinations, retention periods, and individual rights. The notice must be available on the entity's website, mobile application, and physical locations, and must be sent to individuals before the first algorithmic information-availability determination is made about them. Notice must be updated within 30 days of any material practice change.
HI
Failed
Covered entities must not use any individual's personal information in an algorithmic eligibility determination unless the covered entity has first provided the individual with notice consistent with the chapter's notice requirements.
NC
Failed
Operators must notify users and obtain their consent before using user data to inform algorithmic recommendations.
NC
Failed
Operators must provide full disclosure of how data will be used for algorithmic recommendations, including third-party use, in a notification separate and distinct from the platform's terms of service.
NC
Failed
Operators must provide a clear, accessible disclosure of no more than 500 words at a user's first use of the platform (or after six months of inactivity) explaining how the platform collects personal information, what personal information is collected, how it is used for every use case, and how users can exercise their rights, and must obtain consent before collecting any user data.
NC
Failed
Operators must, upon receipt of a verifiable consumer request through an accessible mechanism, provide a detailed disclosure of (1) categories of information collected, (2) sources of collection, (3) business or commercial purposes for collecting, selling, or sharing the information, (4) categories of third parties receiving disclosures, and (5) the specific pieces of personal information collected about the user.
NC
Failed
Operators must provide a clear, accessible disclosure of no more than 500 words at first use or after six months of inactivity explaining how personal information is collected, what is collected, how it is used for every use case, and how users can exercise their rights — and must obtain consent before collecting any user-related data.
NC
Failed
Operators must, upon receipt of a verifiable consumer request through an accessible mechanism, disclose the categories of information collected, categories of sources, business purposes for collection/sale/sharing, categories of third-party recipients, and specific pieces of personal information collected about the requesting user.
NC
Failed
Licensees must provide users with access to their personal data and provide users with the ability to delete their data upon request.
NC
Failed
Licensees must obtain explicit user consent for data collection and use, provide users with access to their personal data, and allow users to delete their data upon request.
NE
Failed eff 2026-04-17
Covered online services must provide an obvious sign to a covered minor whenever precise geolocation information is being collected or used.
NY
NY AB 10020 (Algorithmic Rent Pricing) § Gen. Bus. Law § 344(3)
Failed
Landlords must disclose to each tenant the categories of personal data processed, the sources of collection, the purposes of processing, the retention period for each data category, and the identity of each third-party data recipient together with the categories shared, sharing purposes, retention periods, and whether the third party uses the data for targeted advertising.
NY
NY AB 8129 (AI Bill of Rights) § State Tech. Law § 406
Failed
Designers, developers, and deployers must seek and respect New York residents' decisions regarding the collection, use, access, transfer, and deletion of their data to the fullest extent possible, and must implement alternative privacy-by-design safeguards where honoring those decisions is not feasible.
NY
Failed
Employers must provide prior written notice to all employees who may be subject to electronic monitoring and post that notice conspicuously, including descriptions of the monitoring purpose, specific data collected, activities and locations monitored, dates and frequency, whether data feeds into an AEDT, storage location and retention period, and why the monitoring method is the least invasive available. Notices stating monitoring may occur or that the employer reserves the right to monitor are insufficient.
NY
Failed
Employers conducting random or periodic electronic monitoring must inform affected employees of the specific events being monitored at the time monitoring takes place. Post-monitoring notice is permitted only when necessary to preserve the integrity of an investigation of illegal activity or protect immediate safety.
NY
Failed
Employers must ensure electronic monitoring data used in employment decisions is accurate and current. Current and former employees have the right to request a copy of their own monitoring data and aggregated data for similarly situated employees, at no cost, within seven calendar days of request. Former employees may make one request per year. Employers must not retaliate against employees for exercising data access rights. Information must be provided in the employee's primary language.
NY
Failed
Employers must give prior written notice to all employees who may be subject to electronic monitoring, and post the notice conspicuously, disclosing: the monitoring purpose, data collected, activities and locations monitored, monitoring schedule, whether data feeds into an AEDT or employment decisions, productivity-standard use, data storage location and retention period, and why the monitoring is the least invasive means available. Notices stating monitoring may occur or that the employer reserves the right to monitor are insufficient.
NY
Failed
Employers conducting random or periodic electronic monitoring must inform affected employees of the specific events being monitored at the time monitoring occurs. Post-hoc notice is permitted only if necessary to preserve the integrity of an investigation of illegal activity or protect immediate safety.
NY
Failed
Employers subject to Civil Rights Law § 52-e must ensure that prior written electronic monitoring notices given at hiring comply with the detailed notice requirements of Labor Law § 203-g(2), including all eight enumerated disclosure categories.
NY
NY SB 8209 (AI Bill of Rights) § State Tech. Law § 406
Failed
Designers, developers, and deployers must seek and respect residents' decisions regarding the collection, use, access, transfer, and deletion of their data. Where honoring those decisions is not possible, alternative privacy-by-design safeguards must be implemented.
NY
NY SB 8209 (AI Bill of Rights) § State Tech. Law § 406
Failed
Persons developing automated systems must use consent to justify data collection only where consent can be appropriately and meaningfully given, must make consent requests brief and understandable in plain language, and must transform existing complex notice-and-choice practices to emphasize clarity and user comprehension.
TX
TX HB 1709 (AI Governance) § Bus. & Com. Code § 541.051(b) (as amended)
Failed
Controllers must honor consumer requests to know whether their personal data is or will be used in any AI system and for what purposes.
TX
TX HB 1709 (AI Governance) § Bus. & Com. Code § 541.051(b) (as amended)
Failed
Controllers must include in their privacy notice an acknowledgement of the collection, use, and sharing of personal data for AI purposes, where applicable.
US
Failed
Online platforms that retain user personal information must provide users access to their personal information in a portable, usable, searchable electronic table format that allows transfer to another platform without hindrance.
US
Failed
Covered platforms must provide users with plain-language, conspicuous notice — separate from terms of service, at each login (unless affirmatively waived), and upon each terms-of-service modification — disclosing (1) the type of data collected, whether collection persists beyond the session, and how data will be used, and (2) the specific data shared with third parties, the names of those third parties, and each third party's country of origin.
US
Failed
Online platforms must disclose to users, in conspicuous, accessible, and plain language for each type of algorithmic process: (1) the categories of personal information collected or created, (2) how the information is collected, (3) how it is used in the algorithmic process, and (4) the method by which the process prioritizes, weights, or ranks data categories to determine content delivery. Disclosures must be available in every language the platform supports.
US
Failed
Covered entities must provide individuals with a clear and conspicuous disclosure that explains how their data will be used to train AI systems, states the individual's consent rights including the right to withhold consent without service impact, and offers instructions on how to grant or revoke consent.
US
Failed
Covered platforms must provide recurring notice to users — in plain language, separate from terms of service, at each login (unless the user affirmatively waives it), and whenever terms of service change — disclosing (1) the type of data collected, whether collection continues beyond the session, and how data will be used, and (2) the specific data shared with third parties, the identity of each third-party recipient, and the recipient's country of origin.
VT
Failed
Employers must provide each employee with written notice in the employee's primary language at least 15 calendar days before commencing electronic monitoring, covering twelve enumerated elements including form, purpose, data use, technologies, retention periods, and employee access/correction rights. Updated notice is required upon significant changes. Prior notice is not required where the employer has reasonable grounds to believe the employee is engaged in illegal, rights-violating, or hostile-work-environment conduct and monitoring is reasonably likely to produce evidence.
VT
Failed
Employers must annually provide each employee with a list, in the employee's primary language, of all electronic monitoring systems currently in use, recently used (within 90 days), or planned (within 30 days) in relation to that employee.
VT
Failed
Employers must, upon employee request, provide the employee with any data relating to that employee that was produced or utilized by electronic monitoring or an automated decision system.
D-01.2
Right to correct
Individuals have the right to correct inaccurate personal data used in automated decisions, and to have the correction reflected in pending and future decisions — not just in the underlying record.
Enacted
2
Live
36
Failed
10
Total
48
CO
Enacted eff 2026-05-14
Deployers must, upon request from a consumer who experienced an adverse outcome from a consequential decision materially influenced by a covered ADMT, provide instructions for requesting personal data and for correcting factually incorrect or materially inaccurate personal data used in the consequential decision, consistent with § 6-1-1306. The correction right does not extend to opinions, predictions, scores, or protected evaluations. The consumer-definition exceptions in § 6-1-1303(6)(b) and certain CPA exceptions do not apply to this data-correction right.
CT
CT SB 4 (Consumer Privacy) § Section 17 (amending Conn. Gen. Stat. § 42-524(a))
Enacted eff 2026-10-01
Controllers, processors, and consumer health data controllers operating a facial recognition database must maintain a privacy policy that lets consumers (1) readily determine whether they are included in the FRT database and (2) submit a written request to be removed. The entity must grant or deny each removal request within 15 days and send a written notice to the consumer disclosing the decision, the reasons for it, and — if denied — contact information for the Connecticut Attorney General's office.
CA
CA SB 947 (Workplace ADS) § Lab. Code § 1522
Engrossed
Workers have the right to request, and employers must provide, a copy of the most recent 12 months of the worker's own data primarily used by an ADS to make a disciplinary, termination, or deactivation decision. Workers may make one such request every 12 months. When providing worker data, employers must anonymize all personal information of customers, other workers, and other individuals.
NY
NY SB 9267 (Consumer Camera Privacy Act) § Gen. Bus. Law § 390-f(4)
Engrossed
Manufacturers and operators must, upon request, delete all footage and derivative data associated with an owner's networked camera device within 30 days.
GA
GA SB 495 (Age-Appropriate Design Code) § O.C.G.A. § 10-1-974
Introduced eff 2027-01-01
Covered entities offering algorithmic feeds to minors that use the minor's personal data must provide a prominent control surface letting the minor set content preferences (recommend/block), access and correct the personal data feeding the recommendation system, and ensure the system honors those preferences. The covered entity must also offer minors a follow-only feed option that ranks content solely from sources the minor affirmatively chose.
HI
Introduced
Deployers and developers must provide affected individuals with the right to access all personal characteristics analyzed, predicted, input, inferred, or collected by the algorithmic decision system and the right to challenge and correct inaccurate data, and must create reasonable, accessible, plain-language procedures for exercising these rights.
IL
Introduced eff 2027-01-01
Entities must provide consumers with the ability to (1) access their neurotechnology data, (2) request and obtain its destruction, and (3) revoke any previously provided consent. These rights may be waived for clinical research conducted under express informed written consent meeting specified conditions, including ICH-GCP compliance, a 14-day waiting period for secondary research use, separate consent, readable format, disclosure of data retention policies, and notice of rights waiver.
LA
Introduced
Employers must allow workers to access worker data collected, used by, or produced by an ADS and to correct errors in any input or output data used by or produced by the ADS or used as corroborating evidence by a human reviewer. Workers may designate an authorized representative to request data access on their behalf.
LA
Introduced
Covered insurers must, upon consumer request, identify data sources used in an insurance decision, allow consumers to dispute data accuracy, correct inaccurate data and reconsider the adverse action, and investigate data disputes within 30 days.
MA
Introduced
Covered entities must, upon verified request, provide individuals with the right to (1) access their covered data in human-readable and machine-readable formats, (2) correct inaccuracies and notify downstream recipients, (3) delete their covered data and notify downstream recipients, and (4) export their data portably — all within 45 days (extendable by 20 days), free of charge for the first two requests per year, and without using dark patterns or deceptive design to impede exercise of these rights.
MA
Introduced
Controllers must honor consumer rights to confirm and access personal data (including inferences), obtain third-party recipient lists, correct inaccuracies with downstream notification, delete personal data with downstream notification, and obtain a portable copy — responding within 45 days (extendable by 20 days) and providing at least two free responses per 12-month period.
MI
Introduced
Employers using an electronic monitoring tool or automated decisions tool must: (a) provide written notice to all covered individuals subject to the tool; (b) obtain written consent from each covered individual; (c) ensure that collected data is accurate and up to date; (d) allow covered individuals to correct inaccurate data about themselves; (e) use the tool in a narrowly tailored manner to accomplish only a permitted purpose; (f) use the tool through the least invasive means possible; (g) ensure the tool applies to the smallest number of covered individuals, collects the least amount of data, and is used no more frequently than necessary; and (h) ensure the tool does not collect any employee data when the employee is off duty.
MN
Introduced eff 2026-08-01
Any person using an automated decision system for pricing or wage decisions must develop and publish reasonable procedures to (1) ensure data accuracy, (2) allow consumers or workers to correct or challenge inaccurate data, and (3) allow consumers or workers to request and receive information about what data is considered and how the system uses it.
MN
Introduced eff 2026-08-01
Persons using an automated decision system for pricing or wage decisions must develop and publish reasonable procedures to (1) ensure data accuracy, (2) allow consumers or workers to correct or challenge data accuracy, and (3) provide consumers or workers with information about what data the system considers and how it uses that data.
MN
Introduced
Employers must honor worker requests to correct inaccurate data collected, used, or produced by an ADS. Upon receiving a correction request, the employer must investigate the dispute and, if the data is inaccurate: (1) promptly correct the data and inform the worker; (2) review and adjust any employment-related decisions partially or solely based on the inaccurate data and inform the worker; and (3) notify any third parties that shared or supplied the inaccurate data and direct them to correct it. If the employer determines the data is accurate, it must inform the worker of: the decision not to amend, the verification steps taken, and the supporting evidence.
MN
Introduced
Employers must investigate worker requests to correct monitored data, correct confirmed inaccuracies, adjust any employment-related decisions that relied on the inaccurate data, notify affected third parties, and — if the data is determined accurate — provide the worker with a written explanation of the verification steps and supporting evidence.
MN
Introduced
Persons using an automated decision system for wage- or price-setting must develop and publish reasonable procedures to (1) ensure data accuracy, (2) allow consumers or workers to correct or challenge inaccurate data, and (3) enable consumers or workers to request and receive information about what data is considered and how the system uses it.
MN
Introduced eff 2026-08-01
Persons using automated decision systems for wage or price decisions must develop and publish reasonable procedures to (1) ensure data accuracy, (2) allow consumers or workers to correct or challenge the accuracy of data used by the system, and (3) enable consumers or workers to request and receive information about what data the system considers and how it uses that data.
MN
Introduced eff 2027-01-01
Employers must investigate worker requests to correct monitoring data, correct confirmed inaccuracies, adjust employment decisions based on inaccurate data, notify affected third parties, and — if the data is found accurate — explain to the worker the decision, the verification steps, and the supporting evidence.
MN
Introduced eff 2027-01-01
Employers must investigate and, if data is found inaccurate, promptly correct any worker data used by the automated decision system, review and adjust any employment-related decisions based on the inaccurate data, and notify affected third parties. If the data is found accurate, the employer must inform the worker of the decision, the verification steps taken, and the supporting evidence.
NJ
Introduced
Employers, public entities, and vendors must ensure all employee and service beneficiary data is accurate and up to date, notify individuals of significant data changes, provide access to all held data, and allow written correction or removal requests at least annually. If a correction request is denied, the employer must provide a written explanation and retain the request and explanation for appeal purposes.
NJ
Introduced
Employers, public entities, and vendors must keep individual data accurate, notify individuals of significant changes, provide at least annual access and correction/removal rights, and retain written explanations of any denied correction for use in later appeals.
NY
Introduced
Employers must, upon worker request, provide a copy of the most recent 12 months of the worker's own data primarily used by an ADS for a discipline, termination, or deactivation decision. Workers may make one such request per 12-month period. Data provided must anonymize any customer, other worker, or individual personal information.
NY
NY AB 3265 (AI Bill of Rights) § State Tech. Law § 506
Introduced
Designers, developers, and deployers of automated systems must seek and respect New York residents' decisions regarding the collection, use, access, transfer, and deletion of their data in all appropriate ways and to the fullest extent possible. Where honoring such decisions is not possible, alternative privacy-by-design safeguards must be implemented.
NY
Introduced
Employers must ensure employee data used by an AEDT is accurate and kept up to date for three years. Current and former employees have the right to request and receive, at no cost and within 14 calendar days, a copy of their own data used by the AEDT, in English or the employee's primary language. Former employees are limited to one request per year. Employers that do not monitor the relevant data have no obligation to provide it.
NY
Introduced
Employers must investigate correction requests, and if the data is inaccurate, must (1) promptly correct it and inform the employee, (2) review and adjust employment decisions based on the inaccurate data and inform the employee, and (3) notify and direct correction by third parties with whom the data was shared. If the employer determines the data is accurate, it must inform the employee of that decision, the verification steps taken, and the supporting evidence.
NY
Introduced
Employers using authorized automated wage-setting systems must develop and publish reasonable procedures to (1) ensure the accuracy of all data considered by the automated decision system, (2) allow employees to correct or challenge data accuracy, and (3) enable employees to request and receive information about what data was considered and how the system used it to set their particular wages.
NY
Introduced
Employers must ensure employee data used by AEDTs is accurate and kept up to date for three years, and must provide current or former employees with a copy of their own data used by an AEDT within 14 calendar days of request, at no cost, in the employee's primary language.
NY
Introduced
Employers must investigate employee requests to correct inaccurate AEDT data and, if inaccuracy is confirmed, must (1) correct the data, (2) review and adjust any employment decisions based on the inaccurate data, and (3) notify and direct correction by third parties that shared or supplied the data. If the data is determined to be accurate, employers must explain the verification steps and supporting evidence.
NY
Introduced
Employers must ensure electronically monitored data used for employment decisions is accurate and up to date. Current and former employees have the right to request a copy of their own monitored data and aggregated peer data (former employees limited to one request per year). Employers must respond within seven calendar days at no cost to the employee, in the employee's primary language, and may not take adverse action against employees who make such requests.
NY
Introduced
Employers must provide employees with the opportunity to review and request correction of electronically monitored data both at collection and after. Upon receiving a correction request, employers must investigate, and if data is inaccurate, must (1) promptly correct it and inform the employee, (2) review and adjust any employment decisions based on the inaccurate data, and (3) notify and direct correction by any third parties that received or provided the data. If data is found accurate, the employer must explain the verification steps and evidence to the employee.
NY
Introduced
Employers using automated decision systems for wage-setting under the safe harbor must develop and publish reasonable procedures, as specified by the attorney general, to (1) ensure data accuracy, (2) allow employees to correct or challenge data used by the system, and (3) enable employees to request and receive information about what data is considered and how the system used it to set their wages.
OK
OK HB 3547 (Parent Data Sovereignty) § 70 O.S. § 3-168.1(E)
Introduced eff 2026-11-01
State education agencies and local school districts must provide parents, within thirty days of request, a complete record of all data elements collected or maintained on their child and must honor requests to correct or delete inaccurate or unnecessary data.
PA
Introduced
Social media platforms must, upon request from a qualified individual (parent/guardian or adult former-minor), provide the ability to correct or delete personal information collected from or about the individual when they were a minor, complete deletion within 30 days of the request, and provide written confirmation of deletion within 90 business days. Prior parental consent to collect is an absolute defense to enforcement of the deletion obligation.
US
Introduced
Persons intending to use an automated decision system to inform worker wages must, at least 180 days before commencing such use, publicly publish in a conspicuous and accessible format reasonable procedures that include (1) a process for ensuring data accuracy, (2) disclosure to all affected workers of what data the system considers and how it uses that data when setting wages, and (3) a procedure for workers to correct or challenge data accuracy.
VT
Introduced eff 2025-07-01
Employers must, within seven days of receiving an employee's request to correct potential errors, either: (1) correct the erroneous data and provide the employee with a plain-language notice explaining the correction steps taken, or (2) provide the employee with a notice explaining that the data was not corrected and describing the verification steps taken to assess accuracy.
WA
Introduced eff 2026-07-01
Employers must provide any employee, upon request, with all data relating to that employee that was produced or utilized by electronic monitoring or an automated decision system used by the employer.
WV
WV HB 5034 (Genomic Privacy) § W. Va. Code § 16-5EE-4
Introduced eff 2026-07-01
Entities must develop, implement, and maintain a comprehensive security program to protect consumer genetic data against unauthorized access, use, or disclosure. Entities must also provide consumers with a process to: (1) access their genetic data; (2) delete their genetic data; (3) revoke any consent previously provided; and (4) request and obtain the destruction of their biological sample.
CA
Failed
Workers have the right to request, and employers must provide, a copy of the most recent 12 months of the worker's own data primarily used by an ADS to make a discipline, termination, or deactivation decision. Workers are limited to one request every 12 months.
CO
Failed eff 2026-08-12
A person that uses a price or wage setting algorithm must develop and publish reasonable procedures for: (1) ensuring the accuracy of all data considered by the PWSA; (2) enabling workers to request and receive information regarding what data the PWSA considers and how it uses that data when setting particular wages; and (3) allowing workers to correct or challenge the accuracy of data considered by the PWSA.
NC
Failed
Operators must provide users with an accessible mechanism to alter, change, and delete categories of personal information used in the platform's algorithmic recommendation system at any time, must honor user selections by excluding deselected categories from recommendations, and must not discriminate against users for exercising these rights unless the data use is reasonably necessary for the feature or functionality.
NC
Failed
Operators must provide all users with an accessible mechanism to request correction of inaccurate personal information, must use commercially reasonable efforts to correct the information as directed, and must maintain a record of all correction requests.
NC
Failed
Operators must provide all users with an accessible mechanism to request correction of inaccurate personal information and must use commercially reasonable efforts to correct it upon receipt of a verifiable request. The platform must maintain a record of all correction requests.
NC
Failed
Licensees must provide users with access to their personal data and provide users with the ability to delete their data upon request.
NC
Failed
Licensees must obtain explicit user consent for data collection and use, provide users with access to their personal data, and allow users to delete their data upon request.
NY
Failed
Employers must provide employees the opportunity to review and request correction of electronic monitoring data used in employment decisions, both at the time of collection and after. Upon receiving a correction request, employers must investigate and, if data is inaccurate, promptly correct it, adjust any affected employment decisions, and notify third parties who received the inaccurate data. If data is found accurate, employers must explain the verification steps and supporting evidence.
NY
NY SB 8209 (AI Bill of Rights) § State Tech. Law § 406
Failed
Designers, developers, and deployers must seek and respect residents' decisions regarding the collection, use, access, transfer, and deletion of their data. Where honoring those decisions is not possible, alternative privacy-by-design safeguards must be implemented.
VT
Failed
Employers must, upon employee request, provide the employee with any data relating to that employee that was produced or utilized by electronic monitoring or an automated decision system.
D-01.3
Right to opt out
Individuals have the right to opt out of automated processing of their personal data for consequential decisions.
Enacted
2
Live
40
Failed
24
Total
66
KY
Enacted eff 2027-07-01
Controllers that sell personal data to third parties or process personal data for targeted advertising must clearly and conspicuously disclose such activity and the manner in which consumers may opt out.
VT
Enacted eff 2026-07-01
Any person who has collected, recorded, or shared neural data must honor an individual's written revocation of consent at any time. The revocation process must be at least as easy as initial consent. Upon receiving revocation, the person must destroy all records of the individual's neural data within 10 days. If consent to share is revoked, the person must immediately cease all third-party sharing and notify all third parties with whom the data was shared that consent has been revoked.
CA
CA AB 1018 (Automated Decision Systems) § Bus. & Prof. Code § 22756.2
Engrossed
Deployers must provide subjects with a reasonable opportunity to opt out of the use of a covered ADS before a consequential decision is finalized. A deployer may deny an opt-out request only if the deployer is subject to the Gramm-Leach-Bliley Act and the ADS makes a financial services decision, or if the subject is having a medical emergency; in either case the deployer must explain the basis for the denial.
IL
Engrossed
Covered entities must allow consumers to opt out of surveillance pricing and, upon request, provide the consumer with a non-personalized baseline price for the goods or services.
NY
NY SB 9267 (Consumer Camera Privacy Act) § Gen. Bus. Law § 390-f(4)
Engrossed
Manufacturers and operators must allow owners to revoke consent to any coordinated surveillance feature at any time, with revocation taking effect within 24 hours.
AZ
AZ HB 2737 (ChatBot Protection Act) § A.R.S. § 44-1383.01
Introduced
Chatbot providers must not discriminate or retaliate against a user for refusing to consent to the use of chat logs or personal data for training purposes, including by denying products or services, charging different prices or rates, or providing lower quality products or services.
CT
Introduced eff 2026-10-01
Deployers must, before collecting any personal data of an applicant or employee for processing in an automated employment-related decision process, provide written notice disclosing: (1) the purpose of the data collection, (2) the categories of personal data to be collected, (3) the data retention period, (4) the categories of persons who will have access to the data, and (5) information about the right to opt out of personal data processing under § 42-518.
GA
GA SB 495 (Age-Appropriate Design Code) § O.C.G.A. § 10-1-974
Introduced eff 2027-01-01
Covered entities offering algorithmic feeds to minors that use the minor's personal data must provide a prominent control surface letting the minor set content preferences (recommend/block), access and correct the personal data feeding the recommendation system, and ensure the system honors those preferences. The covered entity must also offer minors a follow-only feed option that ranks content solely from sources the minor affirmatively chose.
ID
ID HB 744 (Biometric Identifiers) § Idaho Code § 48-2101
Introduced eff 2026-07-01
Persons or entities possessing a biometric identifier captured for a commercial purpose must provide a method for the individual to revoke consent to the storage and transmission of the biometric identifier at any time. Upon receiving a revocation of consent, the person must immediately destroy the biometric identifier, unless maintaining it is required by another law.
IL
IL HB 5756 (Algorithmic Pricing Disclosure) § Algorithmic Pricing Transparency Act § 20
Introduced eff 2028-01-01
Covered entities must allow consumers to opt out of surveillance pricing and, upon request, must provide the consumer with a non-personalized baseline price for the goods or services.
IL
Introduced eff 2027-01-01
Entities must provide consumers with the ability to (1) access their neurotechnology data, (2) request and obtain its destruction, and (3) revoke any previously provided consent. These rights may be waived for clinical research conducted under express informed written consent meeting specified conditions, including ICH-GCP compliance, a 14-day waiting period for secondary research use, separate consent, readable format, disclosure of data retention policies, and notice of rights waiver.
IN
Introduced eff 2026-07-01
Employers that manage covered individuals through an automated decision system must allow each covered individual to opt out of automated management and instead be managed by a human manager who is able to make employment-related decisions with respect to that individual.
LA
Introduced
Chatbot providers must not discriminate against or retaliate against a user for refusing to consent to the use of chat logs or personal data for training purposes.
MA
Introduced
Covered entities and service providers must provide individuals with clear, conspicuous, easy-to-execute means to withdraw consent and to opt out of covered data transfers, at least as easy as the means to provide consent, and accessible near the privacy policy. Opt-out requests must be propagated to third parties, and no account creation may be required to exercise these rights.
MA
Introduced
Covered entities and service providers that engage in profiling for automated decisions producing legal or similarly significant effects must provide individuals with a clear, conspicuous opt-out mechanism and must honor opt-out designations in a commercially reasonable timeframe, including notifying downstream profiling and advertising partners of the individual's opt-out decision.
MA
Introduced
Covered entities and service providers must honor verified requests from authorized agents — including those designated via browser settings, extensions, or global device settings — to exercise data subject rights, withdraw consent, or opt out of data processing on an individual's behalf.
MA
Introduced
Controllers must allow consumers to opt out of collection and processing of personal data for targeted advertising, sale of personal data, and profiling in furtherance of solely automated decisions that produce legal or similarly significant effects.
MA
Introduced
Controllers must provide at least two secure mechanisms for consumers to exercise data rights, including a clear opt-out link on their website and, within 18 months of the effective date, support for consumer-initiated opt-out preference signals for targeted advertising and data sales. The opt-out signal overrides conflicting controller-specific settings.
MA
Introduced
Employers must not require employees or candidates to consent to the use of an automated employment decision tool as a condition of being considered for an employment decision, and must not discipline or disadvantage anyone who requests accommodation.
MD
MD HB 1399 (Consumer Reporting Algorithmic Systems) § Md. Code, Com. Law § 14-1228
Introduced eff 2026-10-01
Consumer reporting agencies must provide alternative, nonalgorithmic assessment options for consumers who opt out of automated decision making.
MI
Introduced
At least 30 days before implementing an electronic monitoring tool or automated decisions tool, employers must provide written notice of the tool's use to all employees. Employers must also include the notice in every job posting, post it on the employer's website, provide it directly to every applicant, and make it available in accessible formats accounting for the applicant's first language (if not English) and any disability. The notice must provide covered individuals with the ability to opt out. If a covered individual opts out, the employer must not use the tool for any employment-related decisions concerning that individual.
MI
Introduced
At least 30 days before implementing a monitoring or automated decisions tool, employers must give written notice to all employees, include it in every job posting, on the website, and directly to applicants in accessible language- and disability-appropriate formats, and must let workers opt out — and may not use the tool to make any employment-related decision about a worker who opts out.
MN
MN HF 3980 (Online Platform Algorithmic Transparency) § Minn. Stat. § 325M.35, subd. 4
Introduced
Covered online platforms must provide an accessible user interface enabling users to expressly communicate their preferences regarding the types of items recommended and blocked by the platform's algorithmic recommender systems, and must take all reasonable steps to ensure algorithmic output is consistent with those preferences.
MN
Introduced
Employers must allow workers to opt out of being subject to an automated decision system whenever reasonable alternatives to the ADS exist.
MN
Introduced
Employers must obtain affirmative written consent from workers before subjecting them to electronic monitoring, and must allow workers to opt out of monitoring when reasonable alternatives exist.
MN
MN SF 4380 (Online Platform Metrics) § Minn. Stat. § 325M.35, subd. 4
Introduced
Covered businesses must provide an accessible user interface enabling users to expressly and unambiguously specify the types of items recommended and blocked by the platform's algorithmic recommender systems, and must take all reasonable steps to ensure recommender output is consistent with those preferences.
MN
Introduced eff 2027-01-01
Employers must allow workers to opt out of electronic monitoring when reasonable alternatives to the monitoring tool exist.
MN
Introduced eff 2027-01-01
Employers must allow workers to opt out of being subject to an automated decision system when reasonable alternatives to its use exist.
MO
Introduced
Private entities must not charge different prices or rates for goods or services, or provide a different level of quality of goods or services, to any individual who exercises their rights under the Biometric Information Privacy Act.
NY
NY AB 3265 (AI Bill of Rights) § State Tech. Law § 506
Introduced
Designers, developers, and deployers of automated systems must seek and respect New York residents' decisions regarding the collection, use, access, transfer, and deletion of their data in all appropriate ways and to the fullest extent possible. Where honoring such decisions is not possible, alternative privacy-by-design safeguards must be implemented.
NY
Introduced
Employers must not require employees or candidates to consent to AEDT use as a condition of being considered for an employment decision, and must not discipline or disadvantage any employee or candidate who requests accommodation.
NY
Introduced
Employers must not require employees or candidates to consent to AEDT use as a condition of being considered for an employment decision, and must not discipline or disadvantage anyone for requesting accommodation.
OK
OK HB 3547 (Parent Data Sovereignty) § 70 O.S. § 3-168.1(E)
Introduced eff 2026-11-01
State education agencies and local school districts must allow parents to opt out of any nonessential data collection or data linkage and to opt out of inclusion in any research study, predictive analytics model, artificial intelligence training dataset, or cross-agency workforce linkage.
OK
OK HB 3547 (Parent Data Sovereignty) § 70 O.S. § 3-168.1(H)
Introduced eff 2026-11-01
The State Department of Education must develop a standardized Parent Data Opt-Out Form (electronic and paper). Upon receipt of a completed form, the local school district must exclude the student's records from longitudinal and cross-agency linkage, using only de-identified or aggregate data for state reporting. No student may be penalized, denied enrollment, or suffer academic disadvantage for opting out.
SC
SC HB 5138 (Chatbot Protection Act) § S.C. Code § 39-80-20
Introduced
Chatbot providers must not discriminate or retaliate against a user for refusing to consent to the use of chat logs or personal data for training purposes. Prohibited discrimination includes denying products or services, charging different prices or rates, or providing lower quality products or services.
SC
SC HB 5253 (AI in Education) § S.C. Code § 59-28-195(B)
Introduced
School entities must allow parents to revoke consent for any AI-based tool, assignment, or assessment at any time, and must ensure that a student who opts out is not academically penalized or denied access to core instructional content.
SC
SC SB 896 (Chatbot Protection Act) § S.C. Code § 39-80-20
Introduced
Chatbot providers must not discriminate or retaliate against a user for refusing to consent to the use of chat logs or personal data for training purposes, including by denying products or services, charging different prices, or providing lower quality products or services.
US
Introduced
Providers of covered online platforms must offer minor users an easy option to switch between the personalized recommendation system and an input-transparent algorithm.
US
Introduced
Providers of covered online platforms must offer minor users an option to limit the type or category of recommendations from the personalized recommendation system.
US
Introduced
Employers that manage a covered individual through an automated decision system must enable the individual to opt out of ADS-based management and be managed by a human manager who can make employment-related decisions.
VA
Introduced
Controllers must honor consumer opt-out requests transmitted via authorized third-party universal opt-out mechanisms (browser settings, extensions, global device settings). When an opt-out conflicts with a consumer's existing privacy settings or loyalty program, the controller must comply but may notify the consumer and allow confirmation of preferred settings. Controllers charging fees for opt-out mechanisms must disclose the fee.
VT
VT HB 784 (Chatbot Regulation) § 9 V.S.A. § 4193b
Introduced eff 2026-07-01
Chatbot providers must not discriminate or retaliate against any user — including by denying products or services, charging different prices, or providing lower-quality services — for refusing to consent to the use of chat logs or personal data for training purposes.
FL
FL SB 2 (AI Bill of Rights) § Fla. Stat. § 1006.1495
Failed eff 2026-07-01
Educational entities must provide parents of minor students an opportunity to opt out of the student's use of an AI instructional tool, aligned with existing parental opt-out policies, and public schools must offer an alternative instructional activity allowing the student to meet a comparative educational requirement without penalty.
FL
FL SB 482 (AI Bill of Rights) § Fla. Stat. § 1006.1495
Failed
Educational entities must provide the parent of a minor student with the opportunity to opt out of the student's use of an AI instructional tool. The opt-out process must align with the educational entity's existing policies for parental notice, consent, objection, or opt-out for instructional materials, digital tools, or online accounts. If a parent of a public school student opts out, the school district or public school must provide an alternative instructional activity that allows the student to meet a comparative educational requirement without penalty.
MD
MD HB 1477 (Consumer Reporting Algorithmic Systems) § Md. Code, Com. Law § 14–1228
Failed
Consumer reporting agencies must provide alternative, non-algorithmic assessment options for consumers who opt out of automated decision making.
MT
Failed
State or local government agencies must provide an alternative means of accessing services without the use of facial verification.
NC
Failed
Operators must notify users and obtain their consent before using user data to inform algorithmic recommendations.
NC
Failed
Operators must ensure the platform is fully functional for users who do not consent to having their user data used for algorithmic recommendations.
NC
Failed
Operators must not use personal information in algorithmic recommendations unless (1) the platform reasonably determines the user is not a minor and (2) the user has been notified and expressly consents through a standalone opt-in mechanism.
NC
Failed
Operators must provide users with an accessible mechanism to alter, change, and delete categories of personal information used in the platform's algorithmic recommendation system at any time, must honor user selections by excluding deselected categories from recommendations, and must not discriminate against users for exercising these rights unless the data use is reasonably necessary for the feature or functionality.
NC
Failed
Operators must not use personal information in algorithmic recommendations unless (1) the platform reasonably determines the user is not a minor and (2) the user has been notified and expressly consented through a dedicated opt-in mechanism.
NC
Failed
Operators must provide users with an accessible mechanism to alter, change, and delete the categories of personal information used in the platform's algorithmic recommendation systems, modifiable at any time, and must honor user selections by excluding specified categories from algorithmic recommendations. Operators must not discriminate against users for exercising these rights unless the data is reasonably necessary to the feature or functionality.
NV
Failed eff 2026-01-01
Social media platform operators that offer both an AI-training and non-AI-training search method must require users to affirmatively opt in before using the method whose search data trains an AI system, and must allow users who do not opt in to continue using the non-training method.
NY
NY AB 8129 (AI Bill of Rights) § State Tech. Law § 406
Failed
Designers, developers, and deployers must seek and respect New York residents' decisions regarding the collection, use, access, transfer, and deletion of their data to the fullest extent possible, and must implement alternative privacy-by-design safeguards where honoring those decisions is not feasible.
NY
Failed
Employers must not require employees or candidates to consent to AEDT use as a condition of being considered for an employment decision, and must not discipline or disadvantage anyone solely for requesting accommodation from AEDT evaluation.
NY
NY SB 8209 (AI Bill of Rights) § State Tech. Law § 406
Failed
Designers, developers, and deployers must seek and respect residents' decisions regarding the collection, use, access, transfer, and deletion of their data. Where honoring those decisions is not possible, alternative privacy-by-design safeguards must be implemented.
TX
TX HB 1709 (AI Governance) § Bus. & Com. Code § 541.051(b) (as amended)
Failed
Controllers must honor consumer requests to opt out of the sale of their personal data for use in AI systems prior to collection.
US
Failed
Employers that manage covered individuals through an automated decision system must allow those individuals to opt out of automated management and be managed by a human manager who can make employment-related decisions.
US
Failed
Online platforms using opaque algorithms must enable users to easily switch to an input-transparent algorithm and must not deny, charge different prices for, or condition service on a user's election to use the input-transparent option.
US
Failed
Covered platforms must obtain express consent from individuals before collecting any covered data (habits, traits, preferences, beliefs, or location), allow individuals to revoke that consent at any time, and delete any covered data upon individual request.
US
Failed
Employers must enable any covered individual managed through an automated decision system to opt out of such management and instead be managed by a human manager capable of making employment-related decisions.
US
Failed
Covered entities must not use, sell, or transfer any covered data collected from an individual to train an artificial intelligence system unless they first provide the individual with a clear and conspicuous disclosure of how the data will be used and obtain the individual's express informed consent.
US
Failed
Covered entities must (1) allow individuals to grant or revoke consent at any time through an accessible mechanism, (2) make the revoke option at least as prominent and requiring the same or fewer steps as the accept option, (3) obtain consent independently from terms of service, (4) not infer consent from action or inaction, (5) not condition services on consent, and (6) expunge all of an individual's covered data from AI training datasets upon revocation of consent.
US
Failed
Covered platforms must obtain express individual consent before collecting any covered data (habits, traits, preferences, beliefs, or location), must allow individuals to revoke consent at any time, and must delete all covered data upon individual request.
VA
Failed
State agencies must provide all individuals the right to opt out of the use of the automated decision system for employment decisions and must provide a process by which individuals with disabilities may seek accommodations for the automated decision system.
VA
Failed
Local government entities must provide all individuals the right to opt out of the use of the automated decision system for employment decisions and must provide a process by which individuals with disabilities may seek accommodations.
D-01.4
Data minimization
Data collected and generated in connection with AI systems — including behavioral data, inferences, and derived attributes — must be limited to what is necessary for the AI system's stated purpose. Secondary uses require separate justification.
Enacted
11
Live
202
Failed
72
Total
285
KY
Enacted eff 2027-07-01
Controllers must limit personal data collection to what is adequate, relevant, and reasonably necessary for the disclosed processing purposes.
KY
Enacted eff 2027-07-01
Controllers must not process personal data for purposes that are neither reasonably necessary to nor compatible with the purposes disclosed to the consumer, unless the controller obtains consumer consent.
NE
Enacted eff 2026-01-01
Covered online services must collect and use only the minimum amount of a covered minor's personal data necessary to provide the specific service elements with which the minor has knowingly engaged, and must not use such data for other purposes.
NE
Enacted eff 2026-01-01
Covered online services that collect personal data for age verification must use that data solely for age verification and must delete it immediately after verification is complete.
NE
Enacted eff 2026-01-01
Covered online services must retain a covered minor's personal data only as long as necessary to provide the specific service elements with which the minor has knowingly engaged.
NE
Enacted eff 2026-01-01
Covered online services must not profile a covered minor unless profiling is necessary to provide a service the minor has requested, and only with respect to the service aspects with which the minor is actively and knowingly engaged.
NE
Enacted eff 2026-04-14
Covered online services must collect and use only the minimum personal data necessary to provide the specific elements of the service with which the covered minor has knowingly engaged, must not use such data for other purposes, and must retain it only as long as necessary for that purpose.
NE
Enacted eff 2026-04-14
Covered online services must not profile covered minors unless profiling is necessary to provide a service the minor has requested, and only with respect to aspects of the service with which the minor is actively and knowingly engaged.
RI
RI SB 2197 (AI in Mental Health Care) § R.I. Gen. Laws § 40.1-5.5-4
Enacted eff 2026-06-22
Licensed professionals must maintain the confidentiality of all records and all communications between an individual seeking therapy or psychotherapy services and the licensed professional. Disclosure is permitted only as authorized under R.I. Gen. Laws § 40.1-5-26.
UT
UT HB 276 (AI Content Provenance & NCII) § Utah Code § 13-72b-201
Enacted eff 2027-01-01
Generation services must not require an individual to disclose personally identifiable information beyond what is reasonably necessary to verify the individual's identity and obtain valid consent.
VT
Enacted eff 2026-07-01
Suppliers of mental health chatbots must not sell or share with any third party any individually identifiable health information or user input of Vermont users. Limited exceptions apply for: (1) health care provider requests with user consent; (2) health plan requests at the user's request; and (3) sharing necessary for chatbot functionality with contractual partners, provided both parties comply with HIPAA privacy and security requirements (45 C.F.R. Parts 160 and 164) as if the supplier were a covered entity and the partner a business associate.
HI
Enrolled eff 2027-07-01
Operators must limit the collection, use, and retention of a minor's personal data to what is reasonably necessary to operate the conversational AI service and ensure safety and security, and must use heightened data minimization and security safeguards for a minor's sensitive data.
AZ
Engrossed
Commercial entities must ensure that any third party conducting anonymous age verification: (1) does not retain personal identifying information after age verification is complete; (2) does not use age verification personal identifying information for any other purpose; (3) keeps all age verification personal identifying information anonymous and does not share or communicate it to any person; and (4) protects age verification personal identifying information from unauthorized or illegal access, destruction, use, modification, or disclosure through reasonable security procedures and practices appropriate to the nature of the information.
CA
CA AB 1018 (Automated Decision Systems) § Bus. & Prof. Code § 22756.2
Engrossed
Deployers must limit collection, use, retention, and sharing of personal information from subjects of consequential decisions to what is reasonably necessary and proportionate to achieve the purposes for which the information was collected, or for another compatible disclosed purpose, and must not further process it in an incompatible manner.
CA
CA AB 1979 (Healthcare AI) § Civ. Code § 56.06
Engrossed
Businesses offering an artificial intelligence health model must comply with all CMIA confidentiality requirements as a deemed provider of health care, including maintaining the same standards of confidentiality required of health care providers with respect to medical information and limiting use of medical information to purposes necessary to provide health care services.
CA
CA SB 1000 (AI Transparency Act Amendments) § Bus. & Prof. Code § 22757.2
Engrossed
Covered providers must not collect, use, or retain personal information from users of their disclosure verification tool, or from content submitted to the tool, beyond what is reasonably necessary for user authentication.
CA
CA SB 1000 (AI Transparency Act Amendments) § Bus. & Prof. Code § 22757.2
Engrossed
Covered providers must not condition access to their GenAI system or disclosure verification tool on providing personal information beyond what is strictly necessary for the provenance-data consent purposes described in § 22757.2(a)(3)(B).
CA
CA SB 1119 (Companion Chatbot Child Safety) § Bus. & Prof. Code § 22613
Engrossed eff 2027-07-01
Operators must not sell, share, or use for any purpose not expressly authorized by this chapter the personal information of a child.
CA
CA SB 903 (AI in Psychotherapy) § Bus. & Prof. Code § 4989.85
Engrossed
AI use in psychotherapy records must comply with the confidentiality requirements of Civil Code § 56.104. No company or entity may share, sell, store, or train AI models on any data obtained from psychotherapy.
HI
HI HB 1782 (AI Companion Systems — Minor Safety) § HRS § 28-__ (Data practices related to minors)
Engrossed eff 3000-07-01
Providers must limit the collection, use, and retention of a minor's personal data to what is reasonably necessary to operate the AI companion system and ensure safety and security.
HI
HI HB 1782 (AI Companion Systems — Minor Safety) § HRS § 28-__ (Data practices related to minors)
Engrossed eff 3000-07-01
Providers must not collect or process sensitive data of a minor — including data revealing mental or emotional state, health information, or biometric identifiers — unless necessary for system safety or accessibility, and must apply heightened data minimization and security safeguards.
KS
Engrossed eff 2027-01-01
App store providers must limit collection and processing of age category data and verification data to what is necessary for age verification, parental consent, and compliance records, and must transmit age category data using industry-standard encryption.
KS
Engrossed eff 2027-01-01
Developers must not request age category data more than once per 12-month period for purposes of verifying the accuracy of age category data or continued account use within the age category.
MD
MD HB 952 (Companion Chatbots) § Md. Code, Com. Law § 14–1330(F)
Engrossed eff 2026-10-01
Operators must limit the collection of personal data to what is reasonably necessary and proportionate to satisfy the requirements of this subtitle.
MI
Engrossed
Covered operators must use age-verification data collected under section 7(2)(a) solely to determine user age and must delete it immediately after the age-determination attempt, except where retention is required by other applicable laws.
MI
Engrossed
Covered operators must use parental-consent data collected under section 7(2)(b) solely to obtain verifiable parental consent and must delete it immediately after the consent attempt, except where retention is required by other applicable laws.
NJ
Engrossed
Business entities must not sell, lease, trade, share, or otherwise profit from information obtained through the business entity's use of a biometric surveillance system on a consumer. This is an absolute prohibition with no exceptions.
NY
Engrossed
Chatbot operators must not use age verification data for any purpose other than determining whether a user is a covered minor and must delete such data immediately after the verification attempt, except where retention is required by applicable law.
NY
NY SB 9267 (Consumer Camera Privacy Act) § Gen. Bus. Law § 390-f(2)
Engrossed
Manufacturers and operators must not use footage captured by an owner's networked camera device for algorithm training, product development, or any purpose other than providing services directly requested by the owner, without separate affirmative consent.
NY
NY SB 9267 (Consumer Camera Privacy Act) § Gen. Bus. Law § 390-f(2)
Engrossed
Manufacturers and operators must not retain footage captured by a networked camera device for more than 72 hours unless the owner has activated a paid subscription, completed affirmative owner setup, or affirmatively elected longer retention.
OK
Engrossed
Social media platforms must not (1) collect or retain personal information beyond what is necessary to provide the service or feature the minor is actively and knowingly engaged with, or (2) use a minor's personal information for any purpose other than the purpose for which it was collected, unless the platform demonstrates a compelling reason that the collection, retention, or use does not pose substantial harm or privacy risk to minors.
OK
Engrossed
Social media platforms must not collect precise geolocation data of minors unless strictly necessary for the requested service and only for the limited time necessary, and must provide an obvious sign to the minor for the duration of any geolocation data collection.
OK
Engrossed
Social media platforms must not use personal information collected for age estimation for any other purpose or retain it longer than necessary to estimate age, and the age estimate must be proportionate to the risks and data practices of the service.
OK
Engrossed
Social media companies must not retain any identifying information of an individual after access to the social media platform has been granted following reasonable age verification.
WA
Engrossed
Operators must not use personal information collected for age estimation for any other purpose and must delete it — other than the estimated age or age range — once age estimation is complete.
AK
Introduced eff 2027-01-01
Social media platforms must not collect or retain a known minor Alaska resident's personal data beyond the extent reasonably necessary to provide the social media platform to the minor, and must not collect, retain, or share precise location data of the minor.
AL
Introduced eff 2026-10-01
Covered entities must collect and store only information that does not conflict with a trusted party's best interests and that is (1) sufficient to fulfill a legitimate purpose of the covered entity, (2) relevant to the legitimate purpose of the covered entity, and (3) the minimum amount of information needed for the legitimate purpose of the covered entity.
AR
AR HB 1297 (Healthcare AI Regulation) § Ark. Code § 23-63-2102
Introduced eff 2026-01-01
Healthcare insurers must ensure AI algorithms leverage federated data-sharing models to protect enrollee privacy, comply with FHIR and USCDI interoperability standards, align AI training and validation data with Trusted Exchange Framework privacy standards, and obtain explicit enrollee consent before using health data in AI development and validation.
AZ
AZ HB 2737 (ChatBot Protection Act) § A.R.S. § 44-1383.01
Introduced
Chatbot providers must not process personal data to inform a chatbot output unless processing is necessary to fulfill an express request made by the user and the user has provided affirmative consent. Affirmative consent must meet the statutory standard: a clear affirmative act in response to a stand-alone disclosure, with an equally prominent option to decline, that cannot be inferred from inaction or continued use.
AZ
AZ HB 2737 (ChatBot Protection Act) § A.R.S. § 44-1383.01
Introduced
Chatbot providers must not process a user's chat log to determine whether to display an advertisement, to determine which product or service to advertise, or to customize an advertisement for presentation to the user. This is a categorical prohibition — no consent mechanism can override it.
AZ
AZ HB 2737 (ChatBot Protection Act) § A.R.S. § 44-1383.01
Introduced
Chatbot providers must not process an adult user's chat log and personal data for training purposes unless the chatbot provider first obtains affirmative consent from the user.
AZ
AZ HB 2737 (ChatBot Protection Act) § A.R.S. § 44-1383.01
Introduced
Chatbot providers must not process a user's chat log and personal data to engage in profiling beyond what is necessary to fulfill an express request, and must not profile a user based on any classification or designation of the user's personality or behavioral characteristics beyond what is necessary to fulfill an express request made by the user.
AZ
AZ HB 2737 (ChatBot Protection Act) § A.R.S. § 44-1383.01
Introduced
Chatbot providers must take the necessary physical, administrative, and technical measures to prevent de-identified data from being re-identified and to process, retain, and transfer de-identified data without any reasonable means of re-identification.
CA
CA AB 2027 (Worker Data & AI) § Lab. Code § 1571
Introduced
Employers and vendors acting on their behalf must collect and process worker data only as strictly necessary to administer the employment relationship and fulfill specific employment-related or legal obligations, and must not use worker data to train AI systems to replicate, automate, or replace a worker's job.
CT
CT SB 1484 (AI Employee Protections) § Conn. Gen. Stat. § 31-48d
Introduced eff 2025-10-01
Employers must limit electronic monitoring to six enumerated purposes (quality assurance, performance assessment, legal compliance, employee health and safety, facility/network security, and wage/benefit administration), narrowly tailor monitoring to the intended purpose in the least invasive manner, and maintain reasonable data security practices to protect employee information confidentiality.
CT
CT SB 1484 (AI Employee Protections) § Conn. Gen. Stat. § 31-48d
Introduced eff 2025-10-01
Employers must not require employees to wear a monitoring device or install an application on the employee's personal device for purposes of location tracking.
CT
CT SB 1484 (AI Employee Protections) § Conn. Gen. Stat. § 31-48d
Introduced eff 2025-10-01
Employers must not sell, transfer, or disclose employee information collected through electronic monitoring to any other person or entity, except where required by state or federal law or to comply with a high-risk AI impact assessment.
CT
CT SB 1484 (AI Employee Protections) § Conn. Gen. Stat. § 31-48b(b)
Introduced eff 2025-10-01
Employers must not operate any electronic surveillance device or system for the purpose of recording or monitoring employees in personal-comfort areas (restrooms, locker rooms, lounges) or on any property owned or leased by an employee, including the employee's residence or vehicle.
GA
GA SB 495 (Age-Appropriate Design Code) § O.C.G.A. § 10-1-972
Introduced eff 2027-01-01
Covered entities must not collect, sell, share, or retain any consumer personal data that is not necessary to provide a service the consumer is actively and knowingly engaged with, and must not reuse previously collected personal data for any purpose other than the original collection purpose.
HI
HI SB 2788 (AI Companion System Safety for Minors) § HRS § 28-__ (Data practices related to minors)
Introduced
Providers must limit the collection, use, and retention of a minor's personal data to what is reasonably necessary to operate the AI companion system and ensure safety and security.
HI
HI SB 2788 (AI Companion System Safety for Minors) § HRS § 28-__ (Data practices related to minors)
Introduced
Providers must not collect or process sensitive data of a minor unless necessary for system safety or accessibility, and must apply heightened data minimization and security safeguards to any such collection.
IA
Introduced
Deployers must limit the collection and storage of user information collected by the chatbot to what is necessary to fulfill the deployer's stated purpose for making the chatbot publicly available.
IA
IA HF 2715 (Chatbot Safety & Minors) § Iowa Code § 554J.2
Introduced
Deployers must limit the collection and storage of user information collected by the public-facing chatbot to what is necessary to fulfill the deployer's purpose for making the chatbot publicly available.
IA
Introduced eff 2025-07-01
Device companies must not (1) allow AI to access types of private data not authorized in the initialization agreement, (2) use private data in ways not stated in the statement of purpose, or (3) maintain, disseminate, or delete transferred private data inconsistently with the statement of purpose.
IA
Introduced eff 2025-07-01
Developers must not (1) allow their application to access types of private data not authorized in the initialization agreement, (2) use private data in ways not stated in the application's statement of purpose, or (3) maintain, disseminate, or delete transferred private data inconsistently with the application's statement of purpose.
IA
Introduced
Deployers must limit the collection and storage of user information collected by the chatbot to what is necessary to fulfill the deployer's purpose for making the chatbot publicly available.
IA
Introduced
Employers must not use customer ratings as the sole or primary input data for an automated decision system to make employment-related decisions.
IA
Introduced
When providing employee data pursuant to this chapter, employers must anonymize the personal information of any customer, employee, or other individual contained in the data.
IA
IA SSB 3085 (Biometric Data) § Iowa Code § 554J.2
Introduced
Private entities must not sell, lease, trade, or otherwise profit from an individual's biometric data.
ID
ID HB 744 (Biometric Identifiers) § Idaho Code § 48-2101
Introduced eff 2026-07-01
If a biometric identifier originally captured for the purpose of training an AI system is subsequently used for a commercial purpose not covered by the AI training or security/fraud exemptions in subsection (7), the person possessing the biometric identifier becomes subject to all of the statute's possession, destruction, and penalty provisions as if the identifier had been captured for a commercial purpose from the outset.
IL
Introduced eff 2027-01-01
Insurers that possess neurotechnology data (or genetic testing information) must not release it to third parties except as specifically authorized under the Act.
IL
Introduced eff 2027-01-01
Direct-to-consumer neurotechnology data providers must not share neurotechnology data, genetic test information, or other personally identifiable information about a consumer with any health or life insurance company without written consumer consent.
IL
Introduced eff 2027-01-01
Employers must not use neurotechnology data (or genetic information) in workplace wellness programs unless (1) health, genetic, or neurotechnology services are offered by the employer, (2) the employee provides written authorization, (3) only the employee and licensed health care professionals receive individually identifiable results, and (4) the employer receives only aggregate data. Employers must not penalize employees who decline to participate or disclose neurotechnology data.
IL
Introduced eff 2027-01-01
Entities must treat neurotechnology data and information derived from it as confidential and privileged, releasing it only to the measured individual and persons specifically authorized in writing by that individual.
IL
Introduced eff 2027-01-01
Entities must obtain separate express consent for (1) third-party transfers or disclosures (identifying the third party by name), (2) uses beyond the primary purpose and inherent contextual uses, and (3) post-purpose data retention; informed express consent for research disclosures; and express consent for marketing based on neurotechnology data, third-party marketing, and sale of neurotechnology data.
IL
Introduced eff 2027-01-01
Entities must not disclose neurotechnology data to law enforcement or any other government agency without a consumer's express consent unless pursuant to a search warrant or investigative subpoena issued on a finding of probable cause.
IL
Introduced eff 2027-01-01
Deployers must either (1) inform the user in writing that AI will retain training data indefinitely and obtain the user's express written consent before training on and retaining the user's covered information, or (2) set the default to prohibit training on user data and permit training only after the user is notified and affirmatively opts in.
IL
Introduced eff 2027-01-01
Deployers must not disclose a user's covered information to any third party unless the deployer first obtains express written consent from the user for that specific disclosure.
IL
Introduced eff 2027-01-01
Covered AI tool providers must not collect or retain any personal information from a person who uses the provenance label reading tool, except that voluntary contact information from feedback submitters may be retained. The reading tool must not output any personal provenance data detected in submitted content. Providers must not retain content submitted to the reading tool for longer than is necessary to comply with this Act.
IL
Introduced eff 2027-01-01
Large online platforms must not retain any personal provenance data from content shared on the platform.
IL
Introduced
School districts currently in possession of student biometric information must destroy that information within 30 days after the effective date of the Act and must provide certified documentation of the destruction to the State Board of Education.
IL
Introduced
School districts that have contracted with a third party to obtain, collect, or store student biometric information must, within 30 days after the effective date of the Act, require the third party to destroy all student biometric information in its possession and confirm the completion of the destruction in writing to the school district.
IL
Introduced
During the 30-day destruction period, school districts must not sell, lease, or otherwise disclose student biometric information to any person or entity, unless the individual with legal custody (or the student if 18 or older) consents or the disclosure is required by court order.
IL
Introduced
The Chicago school district, if currently in possession of student biometric information, must destroy that information within 30 days after the effective date of the Act and provide certified documentation of the destruction to the State Board of Education.
IL
Introduced
The Chicago school district, if it has contracted with a third party to obtain, collect, or store student biometric information, must within 30 days after the effective date of the Act require the third party to destroy the biometric information and confirm the destruction in writing to the district.
IL
Introduced
During the 30-day destruction period, the Chicago school district must not sell, lease, or otherwise disclose student biometric information to any person or entity, unless the individual with legal custody (or the student if 18 or older) consents or the disclosure is required by court order.
IL
Introduced
Operators must not sell or rent a student's information or data, including covered information or any other person's information collected by the operator for K–12 school purposes. An exception applies for corporate acquisitions if the successor entity complies with the Act regarding previously acquired student information.
IL
Introduced
Operators must not permit artificial intelligence to train on covered information unless the training is for K–12 school purposes or in furtherance of improving operability and functionality of the operator's service.
IL
Introduced
Operators must not disclose covered information to third parties for the purpose of training artificial intelligence that is not for K–12 school purposes, even where the disclosure would otherwise be permitted to improve operability and functionality of the operator's service.
IL
Introduced
Operators must not permit their AI model to train on a student's covered information and retain the training data indefinitely unless the operator first (1) provides written notice to the student or parent that the AI model will retain training data indefinitely, and (2) obtains written consent from the student or parent. Absent this affirmative opt-in consent, indefinite retention of AI training data derived from student covered information is prohibited.
IN
Introduced eff 2026-07-01
Employers must ensure that the use of an automated decision system output is designed for the purpose of making the specific employment-related decision at issue. Output from systems designed for other purposes may not be repurposed for employment decisions.
KS
Introduced
Covered entities must protect the confidentiality of age information provided by users for age verification by limiting the collection, processing, use, and storage of such information to what is strictly necessary to verify a user's age, obtain verifiable parental consent, or maintain compliance records.
KY
KY HB 633 (Kentucky Kid's Code) § Section 2 (New Section of KRS 367.3611–367.3629)
Introduced
Covered online services must collect and use only the minimum amount of a covered minor's personal data necessary to provide the specific service elements the minor has knowingly engaged with, must not use the data for other purposes, and must retain it only as long as necessary for those elements.
KY
KY HB 633 (Kentucky Kid's Code) § Section 2 (New Section of KRS 367.3611–367.3629)
Introduced
Covered online services must not be required to collect personal data to comply with this section. Any personal data collected for age verification must not be used for other purposes and must be deleted after use for age verification.
LA
Introduced
Covered entities must (1) limit collection of personal data to what is minimally necessary for age verification or compliance, (2) prevent unauthorized access to age-verification data, (3) transmit age-verification data only using industry-standard encryption, (4) prohibit the sale, transfer, or sharing of age-verification data, and (5) retain verification data no longer than reasonably necessary.
LA
Introduced
Employers must not use an ADS to collect worker data for any purpose that was not disclosed in the pre-use written notice required under R.S. 23:972.
LA
Introduced
Employers must provide worker data in a manner that anonymizes the personal information of customers, other workers, and other individuals when required to share worker data under this Part.
LA
Introduced
AI technology companies in possession of deidentified data must (1) take reasonable measures to prevent reidentification, (2) maintain and use data in deidentified form, (3) contractually bind recipients to comply with these requirements, and (4) implement business processes to prevent inadvertent release of deidentified data.
LA
Introduced
Chatbot providers must not process personal data other than input data to inform chatbot outputs unless the processing is necessary to fulfill an express user request and the user has provided affirmative consent.
LA
Introduced
Chatbot providers must not process a user's chat logs for any advertising purpose, including determining whether to display ads, selecting ad categories, or customizing ad presentation.
LA
Introduced
Chatbot providers must obtain affirmative consent before using adult users' chat logs or personal data for training purposes, and must not engage in profiling beyond what is necessary to fulfill an express user request.
LA
Introduced
Chatbot providers must not use any classification or designation of a user's personality or behavioral characteristics created through profiling beyond what is necessary to fulfill an express user request.
LA
Introduced
Operators must not sell to or share with any third party any individually identifiable health information of a user or the user's input. Exceptions apply only when: (1) individually identifiable health information is requested by a healthcare provider with the user's consent, (2) information is provided to the user's health plan at the user's request, or (3) information is shared to ensure effective functionality of the chatbot with another party under contract with the operator. When sharing under any exception, the operator and the receiving entity must comply with all applicable HIPAA privacy and security provisions (45 CFR Parts 160 and 164, Subparts A and E) as if the operator were a covered entity and the receiving party a business associate.
LA
Introduced
Operators must not use a user's input to: (1) determine whether to display an advertisement for a product or service to the user (unless the advertisement is for the mental health chatbot itself), (2) determine a product, service, or category of product or service to advertise to the user, or (3) customize how an advertisement is presented to the user.
MA
Introduced
Covered entities and service providers must not collect or process sensitive covered data (including neural data) unless such collection or processing is strictly necessary to provide or maintain a specific product or service requested by the individual.
MA
Introduced
Controllers must limit collection of personal data to what is reasonably necessary and proportionate to provide the requested product or service, must not process data inconsistent with consumer expectations, and must not collect or process sensitive data unless strictly necessary to provide the requested product or service.
MA
Introduced
Controllers in possession of de-identified data must implement technical re-identification safeguards, publicly commit not to re-identify the data, contractually bind recipients to the same obligations, and monitor downstream compliance with those contractual commitments.
MA
Introduced
Controllers must extend all chapter protections for precise geolocation data to non-residents whose geolocation data reveals they are or were present in Massachusetts, treating such data identically to that of Massachusetts consumers.
MA
Introduced
Employers must not use employee data collected via electronic monitoring for any purpose other than those specified in the notice provided to employees.
MA
Introduced
Employee data collected for impact assessments must be processed and stored to protect privacy, comply with commissioner-specified retention and security requirements, and must not be shared with the employer or any other entity unless strictly necessary for completing the impact assessment.
MA
Introduced
Employers must not use an electronic monitoring tool to collect employee information unless the tool is primarily used for one of six enumerated legitimate purposes (facilitating essential job functions, ensuring quality, periodic performance assessment, legal compliance, health/safety/security, or wage/benefit administration). The tool's type and activated capabilities must be narrowly tailored to accomplish the stated purpose, customized and implemented in the manner least invasive to employees, limited to the smallest number of workers, collecting the least amount of data no more frequently than necessary, with data deleted once the purpose is achieved. Data not necessary for the stated purpose must not be disclosed to the employer and must be promptly disposed of by the vendor. Employee data must not be collected when the employee is off-duty. Necessary data must be stored consistent with the commonwealth's data and cyber privacy laws, promptly disposed of when no longer needed, and not used by the employer, vendor, or any third party for any unauthorized reason.
MA
Introduced
Employers must not use employee data collected via electronic monitoring for purposes other than those specified in the notice provided to employees.
MA
Introduced
Employers must not sell, transfer, or disclose employee data collected via electronic monitoring to any other entity unless required by federal or state law, or necessary to comply with an impact assessment of an automated employment decision tool.
MA
Introduced
Private entities must not disclose, redisclose, or otherwise disseminate any person's or customer's biometric identifier or biometric information unless one of the following applies: (1) the individual or their legally authorized representative provides written consent, (2) the disclosure completes a financial transaction requested or authorized by the individual, (3) the disclosure is required by state, federal, or municipal law, or (4) the disclosure is required by a valid warrant or subpoena from a court of competent jurisdiction.
MD
MD HB 1261 (AI Toy Safety) § Md. Code, Com. Law § 14-5104
Introduced eff 2026-07-01
Manufacturers must collect only the minimum child user data necessary for the core functionality of the artificial intelligence toy and must encrypt all collected child user data.
MI
Introduced
Employers must not use an electronic monitoring tool or automated decisions tool to collect a covered individual's data except for the following enumerated purposes: (a) to allow an employee to accomplish or facilitate an essential job function, (b) to monitor production processes or quality, (c) to periodically assess employee performance, (d) to ensure or facilitate compliance with state or federal labor or employment law, (e) to protect the health, safety, or security of covered individuals, (f) to administer wages and benefits using only data regarding the covered individual's work city and cost of living, or (g) to accomplish any other purpose that enables business operations as determined by the Department of Labor and Economic Opportunity.
MI
Introduced
Employers using an electronic monitoring tool or automated decisions tool must: (a) provide written notice to all covered individuals subject to the tool; (b) obtain written consent from each covered individual; (c) ensure that collected data is accurate and up to date; (d) allow covered individuals to correct inaccurate data about themselves; (e) use the tool in a narrowly tailored manner to accomplish only a permitted purpose; (f) use the tool through the least invasive means possible; (g) ensure the tool applies to the smallest number of covered individuals, collects the least amount of data, and is used no more frequently than necessary; and (h) ensure the tool does not collect any employee data when the employee is off duty.
MI
Introduced
Employers must retain data collected through an electronic monitoring tool or automated decisions tool for no more than 3 years after the purpose for using the tool is achieved, unless otherwise specified by a collective bargaining agreement. If the employer does not use any specific data of a covered individual, the employer must delete that data immediately.
MI
Introduced
Employers must not sell or license a covered individual's data collected through an electronic monitoring tool or automated decisions tool, including deidentified or aggregated data.
MI
Introduced
Employers must not share data collected through electronic monitoring or automated decision tools with the state or a local unit of government unless necessary to (a) provide information to the Department of Labor and Economic Opportunity, (b) comply with federal, state, or local law requirements, or (c) comply with a court-issued subpoena, warrant, or order.
MI
Introduced
Persons collecting covered information under a safe-harbor discount, cost-based pricing, or loyalty program must use that information solely for offering or administering the applicable program and must not use it for any other purpose, including profiling, targeted advertising, or individualized price setting.
MI
Introduced
Persons must not augment or supplement personally identifiable information provided by a consumer for the purpose of receiving a discounted price with personally identifiable information obtained from a third party or by other means.
MI
Introduced
Employers must retain worker data collected via monitoring or automated decisions tools no longer than three years after the collection purpose is achieved, and must immediately delete any data they do not use.
MI
Introduced
Employers must not sell or license worker data (including deidentified or aggregated data) and must not share monitoring or automated-decision data with state or local government except to supply the department, comply with law, or respond to a subpoena, warrant, or order.
MN
MN HF 4005 (Biometric Data Consent & Safeguards) § Minn. Stat. § 325M.40, subd. 3
Introduced
Any person who obtains biometric data must not sell, lease, or otherwise disclose it to another person, except where: (1) the individual consents to disclosure for identification purposes in the event of the individual's disappearance or death; (2) the disclosure completes a financial transaction the individual requested or authorized; (3) the disclosure is required or permitted by federal or state law; or (4) the disclosure is made by or to a law enforcement agency for a law enforcement purpose in response to a warrant.
MN
MN HF 4005 (Biometric Data Consent & Safeguards) § Minn. Stat. § 325M.40, subd. 3
Introduced
Any person who obtains biometric data must delete and destroy it within a reasonable time, but no later than one year from the date the purpose for collecting the data expires. If a federal or state law requires a longer retention period, the data must be destroyed within a reasonable time but no later than one year after that statutory retention period expires. For employers who collect employee biometric data for security purposes, the collection purpose expires upon termination of the employment relationship.
MN
Introduced
Employers may use electronic monitoring tools only for six enumerated purposes (essential job functions, quality assurance, periodic performance assessment, legal compliance, health/safety/security, and wage/benefit administration), must specify the intended purpose, must narrowly tailor the tool's capabilities to that purpose, and must minimize the number of workers monitored and the frequency and volume of data collected.
MN
Introduced
Employers must not transfer, sell, or license worker data (including deidentified or aggregated data) to third parties unless the recipient is under contract to analyze the data, the contract prohibits resale, the recipient implements reasonable security procedures, and the recipient agrees to joint-and-several liability for data breaches. Employers must not share worker data with government unless required by law.
MN
Introduced
Employers and vendors must restrict worker data access to authorized personnel only, notify workers of data breach impacts as soon as possible, and — at the end of a vendor contract — vendors must return all worker data to the worker and employer in a user-friendly format and delete all remaining copies.
MN
MN SF 4351 (Biometric Data Consent) § Minn. Stat. § 325M.40, Subd. 3
Introduced
Any person who obtains biometric data must not sell, lease, or otherwise disclose the biometric data to another person, except where: (1) the individual consents to disclosure for identification in the event of disappearance or death; (2) the disclosure completes a financial transaction the individual requested or authorized; (3) the disclosure is required or permitted by federal or state law; or (4) the disclosure is made by or to a law enforcement agency for a law enforcement purpose in response to a warrant.
MN
MN SF 4351 (Biometric Data Consent) § Minn. Stat. § 325M.40, Subd. 3
Introduced
Any person who obtains biometric data must delete and destroy the biometric data within a reasonable time, but no later than one year from the date the purpose for collecting the data expires. If a federal or state law requires a longer retention period, the biometric data must be destroyed no later than one year from the date that retention period expires. For employers who collect employee biometric data for security purposes, the collection purpose expires upon termination of the employment relationship.
MN
Introduced eff 2027-01-01
Employers may only use electronic monitoring tools for three enumerated purposes (quality assurance, legal compliance, and safety/security), must specify the intended purpose, limit use to that purpose, narrowly tailor the tool's capabilities, and minimize the scope of data collection and the number of workers monitored.
MN
Introduced eff 2027-01-01
Employers must not transfer, sell, or license worker data (including deidentified or aggregated data) except to vendors under contract that prohibits resale, requires reasonable security, and imposes joint and several breach liability. Government sharing is prohibited absent a legal requirement. Employers and vendors must maintain data security, restrict access to authorized personnel, notify workers of breaches, and vendors must return all data and delete copies at contract end.
MO
Introduced
Private entities in possession of biometric identifiers or biometric information must not sell, lease, or trade any person's or customer's biometric identifier or biometric information.
MO
Introduced
Private entities in possession of biometric identifiers or biometric information must not disclose, redisclose, or otherwise disseminate any person's or customer's biometric identifier or biometric information unless one of four exceptions applies: (1) the person or their legally authorized representative provides written release to the disclosure; (2) the disclosure completes a financial transaction requested or authorized by the person or their representative; (3) the disclosure is required by state, federal, or municipal law; or (4) the disclosure is required pursuant to a valid warrant or subpoena issued by a court of competent jurisdiction.
MO
Introduced
Private entities must not condition the provision of any good or service on the collection, use, disclosure, transfer, sale, retention, or processing of a biometric identifier unless the biometric identifier is strictly necessary to provide the good or service.
MO
Introduced eff 2026-08-28
Covered entities must establish, implement, and maintain reasonable data security for age verification data, including: (1) limiting collection of personal data to what is minimally necessary to verify a user's age or maintain compliance; (2) protecting age verification data against unauthorized access; (3) transmitting such data only using industry-standard encryption protocols; (4) retaining such data no longer than reasonably necessary to verify age or maintain compliance; and (5) not sharing, transferring, or selling age verification data to any other entity.
MO
Introduced
Any verification or age-confirmation system used for compliance with this section must comply with data minimization and privacy-by-design principles.
MO
Introduced
Third parties must not retain or sell biometric, facial recognition, or identification data collected for compliance purposes under this section.
MO
Introduced
The statewide digital privacy agreement must incorporate and comply with state statutes governing data minimization, secondary use limitations, targeted advertising prohibitions, security safeguards, privacy notices, breach response, retention and deletion, and directory-information protections.
MO
Introduced
Vendors must not collect, store, or analyze biometric identifiers, behavioral or emotional signals, voiceprints or keystroke dynamics, or precise geolocation unless strictly necessary for the educational purpose and disclosed in the digital privacy agreement.
MO
Introduced
Vendors must ensure software does not display commercial or sponsored content, use session replay, heat-mapping, or behavioral analytics, create persistent identifiers, or track students outside the educational purpose.
MO
Introduced
Vendors must use encryption for data in transit and at rest, store and process all student data within the United States, disclose all subprocessors and obtain contracting entity approval before use, and prohibit background data collection when software is minimized or inactive.
MO
Introduced
Vendors must not use camera, microphone, or system-level access unless strictly necessary for the educational function and disclosed in the digital privacy agreement, and must not condition access, features, pricing, or support on any form of usage quota or screen-time expectation.
MO
Introduced eff 2026-08-28
Covered entities must establish, implement, and maintain reasonable data security for age verification data, including: (1) limiting collection of personal data to what is minimally necessary for age verification or compliance; (2) protecting age verification data against unauthorized access; (3) transmitting data only using industry-standard encryption; (4) retaining data no longer than reasonably necessary; and (5) not sharing, transferring, or selling age verification data to any other entity.
NJ
Introduced
Employers must not share an applicant's video interview except with a service provider whose expertise or technology is necessary to evaluate the applicant's fitness for the position.
NJ
Introduced
Employers and public entities must limit AEDS and EMT data collection and use to what is necessary for allowable purposes, use the least invasive means, collect data no more frequently than necessary, restrict access to authorized agents, and ensure that collected data is accessed only by authorized agents of the employer, the public entity, or the employee or their authorized representative.
NJ
Introduced
Employers, public entities, and vendors must not sell, license, transfer, disclose, or share employee, applicant, or service beneficiary data or AEDS outputs with any third party without uncoerced written consent, except to the individual, their authorized representative, or law enforcement when required by law. Applicant data must be destroyed upon the applicant's request. Vendors must return and delete all data when the contract terminates.
NJ
Introduced
Employers must not share an applicant's video interview except with a service provider whose expertise or technology is necessary to evaluate the applicant's fitness for the position.
NJ
Introduced
Employers must not share an applicant's video interview recording with anyone except a service provider whose expertise or technology is necessary to evaluate the applicant's fitness for the position.
NJ
Introduced
Employers, public entities, and vendors must restrict access to EMT- or AEDS-collected worker data to authorized agents of the employer or public entity and the affected employee or their authorized representative.
NJ
Introduced
Public entities and vendors must restrict access to data used by an ABSDS to authorized agents of the public entity and the affected service beneficiary.
NY
Introduced
Employers must not use an ADS to (1) violate any federal, state, or local labor, employment, health and safety, or civil rights law, (2) infer a worker's protected status under the New York Human Rights Law, (3) identify, profile, predict, or take adverse action against a worker for exercising legal rights, or (4) collect worker data for purposes not disclosed in the pre-use notice.
NY
Introduced
Chatbot operators must not use information collected for the purpose of determining whether a covered user is a covered minor for any purpose other than making that determination, and must delete such information immediately after the determination attempt, except where retention is required for compliance with applicable New York state or federal law.
NY
NY AB 10764 (Utility Billing Integrity Act) § Pub. Serv. Law § 65-c(11)
Introduced
Utilities must handle data used in anomaly detection systems in accordance with applicable state and federal privacy laws and must use such data solely for billing integrity and consumer protection purposes.
NY
NY AB 3265 (AI Bill of Rights) § State Tech. Law § 504
Introduced
Persons developing automated systems must protect New York residents from inappropriate or irrelevant data use in the design, development, and deployment of automated systems, and from the compounded harm of data reuse.
NY
NY AB 3265 (AI Bill of Rights) § State Tech. Law § 506
Introduced
Persons developing automated systems must implement built-in privacy protections by default, ensure that data collection conforms to reasonable expectations, and collect only strictly necessary data for the specific context.
NY
NY AB 3265 (AI Bill of Rights) § State Tech. Law § 506
Introduced
Persons developing automated systems must establish enhanced protections and restrictions for data and inferences related to sensitive domains. In sensitive domains, individual data and related inferences may only be used for necessary functions, safeguarded by ethical review and use prohibitions.
NY
Introduced
Employers must ensure that employee data collected for impact assessments is collected, processed, stored, and retained in a privacy-protective manner and in compliance with Commissioner-specified data retention and security requirements. Employee data provided to auditors must not be shared with the employer and must not be disclosed to any other person or entity unless strictly necessary for completing the assessment.
NY
NY AB 6031 (Biometric Privacy Act) § Gen. Bus. Law § 676-b
Introduced
Private entities in possession of biometric identifiers or biometric information must not disclose, redisclose, or otherwise disseminate the data unless one of four conditions is met: (1) the subject or their legally authorized representative consents; (2) the disclosure completes a financial transaction requested or authorized by the subject; (3) the disclosure is required by federal, state, or local law or municipal ordinance; or (4) the disclosure is required pursuant to a valid warrant or subpoena issued by a court of competent jurisdiction.
NY
Introduced
Employee data collected for impact assessments must be collected, processed, stored, and retained in a manner that protects employee privacy and complies with Commissioner-specified data retention and security requirements. Assessment data provided to auditors must not be shared with the employer or any other entity unless strictly necessary for the assessment.
NY
Introduced
Employers must limit electronic monitoring to enumerated lawful purposes, use the least invasive means strictly necessary, minimize the number of monitored workers and volume/frequency of data collection, delete data once the purpose is achieved, and must not use collected data for purposes beyond those specified in the employee notice.
NY
Introduced
Employers must not sell, transfer, or disclose employee data collected via electronic monitoring to any other entity, except where required by state or federal law or necessary to comply with an AEDT impact assessment.
NY
Introduced
Employee data collected for an impact assessment must be collected, processed, stored, and retained in a manner that protects employee privacy and complies with Commissioner-specified retention and security requirements. Data provided to auditors must not be shared with the employer or any other entity unless strictly necessary for completing the impact assessment.
OK
OK HB 3547 (Parent Data Sovereignty) § 70 O.S. § 3-168.1(D)
Introduced eff 2026-11-01
State education agencies, local school districts, and their contractors must treat student data solely as held in custodial capacity, must not claim proprietary or ownership interests in it, and must not sell, trade, or license any student data for commercial purposes.
OK
OK HB 3547 (Parent Data Sovereignty) § 70 O.S. § 3-168.1(F)
Introduced eff 2026-11-01
State education agencies and local school districts must not collect personally identifiable educational data unless expressly authorized by law and must obtain written parental consent before collecting political or religious beliefs, family income or tax data (beyond lunch eligibility), biometric/health/psychological data unrelated to special education, student social media identifiers or internet activity, or any data not directly necessary for instruction or accountability.
OK
OK HB 3547 (Parent Data Sovereignty) § 70 O.S. § 3-168.1(G)
Introduced eff 2026-11-01
State education agencies and local school districts must not transfer personally identifiable student data to any federal or state agency, private contractor, or nonprofit organization without written parental consent (or student consent if age eighteen or older), unless otherwise authorized by law.
OK
Introduced eff 2026-11-01
Deployers must collect and store only information that does not conflict with a trusting party's best interests. Information collected must be adequate (sufficient for a legitimate deployer purpose), relevant (linked to that legitimate purpose), and necessary (the minimum amount needed for that purpose).
OK
Introduced eff 2026-11-01
Artificial intelligence technology companies in possession of de-identified data must (1) take reasonable measures to prevent re-association with individuals, (2) maintain data in de-identified form and not attempt re-identification except to test the de-identification process, (3) contractually require recipients to comply with these restrictions, and (4) implement safeguards against inadvertent release.
OK
Introduced eff 2025-11-01
Social media platforms must not collect data from minor users unless the data is de-identified, must not use or process minor user data in a manner inconsistent with the best interests of the minor user, and must not display, send, or target advertisements to minor users or use data collected from minor users for advertising purposes.
PA
Introduced
Social media companies must not mine data related to a minor account holder, except for (1) age and location data for age-appropriate content recommendations, (2) data necessary to protect minors from harmful content, or (3) data that is adequate, relevant, and reasonably necessary for the disclosed processing purpose.
PA
Introduced
Social media platforms must not process a minor's precise geolocation information by default unless strictly necessary to provide a requested service, product, or feature and only for the duration necessary. When processing a minor's precise geolocation, the platform must provide a conspicuous signal to the minor for the duration of the processing.
PA
Introduced
Suppliers must not sell or share with any third party a consumer's individually identifiable health information or consumer input. Sharing is permitted only in two circumstances: (1) a health care provider requests access to the consumer's individually identifiable health information and the consumer provides written consent, or the consumer requests that a health plan receive access and provides written consent; or (2) the sharing is necessary for the chatbot's effective functionality with a contracted third party and the consumer provides written consent. When sharing under the functionality exception, the supplier and the third party must comply with all HIPAA security and privacy provisions (45 CFR Parts 160 and 164) as if the supplier were a HIPAA covered entity and the third party a business associate. Written consent must acknowledge that the consumer understands and agrees to the sharing.
PA
Introduced
Suppliers must not use consumer input to determine whether to display an advertisement (unless the advertisement is for the chatbot itself), determine what product, service, or category to advertise, or customize how an advertisement is presented to the consumer.
PA
Introduced
Covered providers must not collect or retain personal information from detection-tool users (except opt-in feedback contact info used only to improve the tool), must not retain submitted content beyond 24 hours absent express consent, and must not retain personal provenance data from submitted content.
PA
Introduced
Covered AI tool providers must not collect or retain personal information from users of the provenance-label reading tool (except voluntarily-submitted feedback contact info) and must not retain submitted content longer than necessary to comply with the act.
RI
RI HB 7767 (AI in Employment) § R.I. Gen. Laws § 28-5.2-2
Introduced
Employers must not use an electronic monitoring tool to collect employee information unless the tool is primarily used for one of six enumerated legitimate purposes: (1) accomplishing essential job functions, (2) ensuring quality of goods and services, (3) conducting periodic assessment of worker performance, (4) ensuring compliance with employment, labor, or other relevant laws, (5) protecting health, safety, or security of workers or security of employer facilities and networks, or (6) administering wages and benefits.
RI
RI HB 7767 (AI in Employment) § R.I. Gen. Laws § 28-5.2-2
Introduced
Employers must narrowly tailor the type and activated capabilities of any electronic monitoring tool to accomplish the employer's intended legitimate purpose. The tool must be customized and implemented in the manner least invasive to employees. Monitoring must be limited to the smallest number of workers, collect the least amount of data no more frequently than necessary, and data must be deleted once the purpose is achieved. Employee data not necessary for the legitimate purpose must not be disclosed to the employer and must be promptly disposed of by the vendor. Employee data must not be collected when the employee is off-duty. Data necessary for the legitimate purpose must be stored consistent with state data and cyber privacy laws, disposed of when no longer needed, and not used by the employer, vendor, or any third party for any other reason.
RI
RI HB 7767 (AI in Employment) § R.I. Gen. Laws § 28-5.2-2
Introduced
Employers must not use employee data collected via an electronic monitoring tool for purposes other than those specified in the notice provided to employees and candidates.
RI
RI HB 7767 (AI in Employment) § R.I. Gen. Laws § 28-5.2-2
Introduced
Employers must not sell, transfer, or disclose employee data collected via an electronic monitoring tool to any other entity unless required to do so under federal or state law, or necessary to comply with an impact assessment of an automated decision system used under this section.
RI
RI HB 7767 (AI in Employment) § R.I. Gen. Laws § 28-5.2-2
Introduced
Employers must not require employees to: (1) physically implant devices that collect or transmit data, including subcutaneous or clothing/accessory-incorporated devices, (2) install applications on personal devices that collect or transmit employee data, or wear or embed those devices, or (3) carry or use any device with location tracking enabled, unless the location tracking is conducted during work hours only and is strictly necessary to accomplish essential job functions and narrowly limited to only the activities and times required.
SC
SC HB 5138 (Chatbot Protection Act) § S.C. Code § 39-80-20
Introduced
Chatbot providers must not process personal data to inform a chatbot output unless (1) processing is necessary to fulfill an express request made by the user and (2) the user provides affirmative consent. Affirmative consent requires a clear affirmative act in response to a specific, stand-alone, accessible, multilingual disclosure with equally prominent accept and decline options; it cannot be inferred from inaction, continued use, or broad terms of use.
SC
SC HB 5138 (Chatbot Protection Act) § S.C. Code § 39-80-20
Introduced
Chatbot providers must not process a user's chat log to determine whether to display an advertisement, to determine what product or service to advertise, or to customize an advertisement for the user.
SC
SC HB 5138 (Chatbot Protection Act) § S.C. Code § 39-80-20
Introduced
Chatbot providers must not use an adult user's chat log and personal data for training purposes unless the chatbot provider first obtains affirmative consent from the user.
SC
SC HB 5138 (Chatbot Protection Act) § S.C. Code § 39-80-20
Introduced
Chatbot providers must not process a user's chat log and personal data for profiling beyond what is necessary to fulfill an express request, and must not profile a user based on personality traits or behavioral characteristics beyond what is necessary to fulfill the user's express request.
SC
SC HB 5138 (Chatbot Protection Act) § S.C. Code § 39-80-20
Introduced
Chatbot providers must take the necessary physical, administrative, and technical measures to prevent deidentified data from being reidentified and to process, retain, and transfer deidentified data without any reasonable means of reidentification.
SC
SC HB 5253 (AI in Education) § S.C. Code § 59-28-195(D)
Introduced
School entities must ensure that AI systems collect only the minimum student data necessary to achieve an approved educational purpose.
SC
SC HB 5253 (AI in Education) § S.C. Code § 59-28-195(D)
Introduced
School entities must ensure that student data collected through AI (1) remains the property of the student and parent, (2) is not sold, shared, licensed, or used for commercial advertising or profiling, and (3) is deleted within a defined period unless retention is required by law.
SC
SC SB 896 (Chatbot Protection Act) § S.C. Code § 39-80-20
Introduced
Chatbot providers must not process personal data to inform chatbot output unless the processing is necessary to fulfill an express request made by the user and the user has provided affirmative consent. Affirmative consent must be obtained via a clear, conspicuous, stand-alone disclosure in easily understandable language, accessible to users with disabilities, in each language the chatbot is offered, with the option to decline at least as prominent as the option to consent. Consent may not be inferred from inaction or continued use.
SC
SC SB 896 (Chatbot Protection Act) § S.C. Code § 39-80-20
Introduced
Chatbot providers must not process a user's chat log to determine whether to display an advertisement, to determine which product or service to advertise, or to customize an advertisement for presentation to a user. This is an absolute prohibition — no consent mechanism overrides it.
SC
SC SB 896 (Chatbot Protection Act) § S.C. Code § 39-80-20
Introduced
Chatbot providers must not process an adult user's chat log and personal data for training purposes unless the chatbot provider first obtains affirmative consent from the user.
SC
SC SB 896 (Chatbot Protection Act) § S.C. Code § 39-80-20
Introduced
Chatbot providers must not process a user's chat log and personal data for profiling beyond what is necessary to fulfill an express request, and must not profile a user based on personality traits or behavioral characteristics beyond what is necessary to fulfill an express user request.
SC
SC SB 896 (Chatbot Protection Act) § S.C. Code § 39-80-20
Introduced
Chatbot providers must take necessary physical, administrative, and technical measures to prevent deidentified data from being reidentified and must process, retain, and transfer deidentified data without any reasonable means of reidentification.
TN
TN SB 1998 (Algorithmic & Surveillance Pricing) § Tenn. Code Ann. § 47-18-3503
Introduced eff 2026-07-01
Food retail establishments must not collect or use the data of any person under 17 years of age for targeted advertising or personalized algorithmic pricing.
TX
TX HB 3755 (AI Biometric Identifiers) § Bus. & Com. Code § 503.001(f)
Introduced eff 2025-09-01
Entities that capture biometric identifiers for AI training, processing, or storage must not repurpose those identifiers to a separate commercial purpose; if they do, they become subject to the full biometric identifier statute's possession, destruction, and penalty provisions. The AI exemption does not apply when biometric identifiers are used for the purpose of uniquely identifying a specific individual.
TX
TX SB 2490 (Biometric Identifiers & AI) § Tex. Bus. & Com. Code § 503.001(f)
Introduced eff 2025-09-01
Persons who capture biometric identifiers for the commercial purpose of AI training, processing, or storage and who subsequently use those identifiers for a separate commercial purpose must comply with the statute's existing provisions for possession and destruction of biometric identifiers and are subject to the associated penalties.
US
Introduced
Covered entities must limit the collection, processing, use, and storage of age verification information to what is strictly necessary to verify a user's age, obtain verifiable parental consent, or maintain compliance records.
US
Introduced
Providers of covered platforms must not conduct market or product-focused research on users known to be minors unless the research is solely to improve platform privacy, security, transparency, or safety, or is necessary for legal compliance.
US
Introduced
Covered entities must perform ongoing testing and evaluation of privacy risks and privacy-enhancing measures of each automated decision system or augmented critical decision process, including data minimization practices, retention periods, information security measures, use of privacy-enhancing technologies, and current and future impacts on consumer privacy, safety, and security.
US
Introduced
Covered entities must limit the collection, processing, use, and storage of age verification information to what is strictly necessary to verify a user's age, obtain verifiable parental consent, or maintain compliance records.
US
Introduced
Covered entities must (1) limit collection of age-verification personal data to what is minimally necessary, (2) protect such data against unauthorized access using industry-standard encryption, (3) retain the data no longer than reasonably necessary for verification or compliance, and (4) not share, transfer, or sell age-verification data to any other entity.
US
Introduced
Deployers must not process any personal data of a known-minor user to generate, personalize, or otherwise affect an output unless the data was collected during the current session within the maximum permitted period of use to be established by FTC regulation.
US
Introduced
Deployers must not process any personal data of a known-minor user for the purpose of profiling that user.
US
Introduced
Deployers must not process or transfer a known-minor user's personal data for the purpose of training a covered algorithm, except for testing and identifying risks of harm to users or addressing identified risks of harm.
US
Introduced
Deployers must not process any input data provided by a known-minor user for any purpose other than (1) generating outputs within the current session's FTC-established temporal window, (2) testing and identifying risks of harm, or (3) addressing identified risks of harm.
US
Introduced
Covered entities that voluntarily collect personal data for compliance with this Act must not use that data for any other purpose and must not retain it longer than necessary for compliance or to demonstrate compliance.
VA
Introduced
Controllers with actual knowledge or willful disregard that a consumer is an adolescent (ages 13–15) must not process the adolescent's personal data for targeted advertising, sale, or consequential profiling, and must not process it beyond what is reasonably necessary or for undisclosed purposes, without obtaining consent from the adolescent. Precise geolocation collection from adolescents requires necessity, consent, and a visible collection indicator.
VT
Introduced eff 2025-07-01
Employers must not engage in electronic monitoring of employees unless the monitoring serves one of seven enumerated purposes (assisting essential job functions, monitoring production, ensuring legal compliance, protecting health/safety/security, securing property, periodic performance assessment, or tracking time/output for compensation). The specific monitoring form must be necessary and used exclusively for the stated purpose, must be the least invasive means available, must be applied to the smallest number of employees and collect the smallest amount of data no more frequently than necessary, and must be restricted so that only authorized persons access the data and use it only for the noticed purpose and duration.
VT
Introduced eff 2025-07-01
Employers must not require employees to install monitoring applications on personal devices or wear/attach/embed monitoring devices on clothing unless the monitoring is necessary for the employee's essential job function and limited to the times and activities necessary for those functions. Location tracking must be disabled outside essential-job-function activity times. Employers must not under any circumstances require an employee to physically implant a device on the employee's body for monitoring purposes.
VT
Introduced eff 2025-07-01
Employers, any person that develops, operates, or maintains electronic monitoring or an ADS on an employer's behalf, and any person who collects, stores, analyzes, interprets, disseminates, or otherwise uses monitoring or ADS data must implement reasonable security procedures and practices appropriate to the nature of the data to protect employees' personal information from unauthorized or illegal access, destruction, use, modification, or disclosure.
VT
Introduced eff 2025-07-01
Any person that develops, operates, or maintains electronic monitoring or an ADS on an employer's behalf, and any person who collects, stores, analyzes, or uses monitoring or ADS data, must upon termination of the contract with the employer: (1) return all data and ADS outputs to the employer, and (2) destroy all data and ADS outputs in the person's possession.
VT
Introduced eff 2025-07-01
Providers must use reasonable care to avoid any heightened risk of harm to a minor caused by processing of personal data in the course of providing the social media platform to minors, where heightened risk includes unfair or deceptive treatment, financial or physical injury, unintended disclosure, or intrusion upon seclusion.
VT
Introduced eff 2025-07-01
Providers must limit the use of a minor's personal identifying information to the purpose for which the information was collected.
VT
VT HB 784 (Chatbot Regulation) § 9 V.S.A. § 4193b
Introduced eff 2026-07-01
Chatbot providers must not process personal data other than input data to inform chatbot outputs unless the processing is necessary to fulfill an express user request and the user has provided affirmative consent.
VT
VT HB 784 (Chatbot Regulation) § 9 V.S.A. § 4193b
Introduced eff 2026-07-01
Chatbot providers must not process a known or reasonably known minor user's chat log or personal data without the affirmative consent of that user's parent or legal guardian. Chatbot providers must not process a known or reasonably known minor user's chat log or personal data for training purposes under any circumstances — parental consent does not override this prohibition.
VT
VT HB 784 (Chatbot Regulation) § 9 V.S.A. § 4193b
Introduced eff 2026-07-01
Chatbot providers must not process an adult user's chat log or personal data for training purposes unless the provider first obtains the user's affirmative consent.
VT
VT HB 784 (Chatbot Regulation) § 9 V.S.A. § 4193b
Introduced eff 2026-07-01
Chatbot providers must not process a user's chat log or personal data for profiling, nor use any personality or behavioral classification derived from profiling, beyond what is necessary to fulfill an express user request.
WA
Introduced eff 2026-07-01
Employers must limit electronic monitoring to five enumerated purposes (assisting essential job functions, monitoring production, ensuring legal compliance, protecting health/safety, or tracking time/output for compensation), and must use the least invasive means with the smallest scope and number of employees necessary, restricting data access to authorized persons for the noticed purpose and duration only.
WA
Introduced eff 2026-07-01
Employers must not require employees to install monitoring applications on personal devices or wear monitoring devices unless the monitoring is necessary for essential job functions and limited to only the times and activities required. Location tracking must be disabled outside of work-activity periods.
WV
WV HB 5034 (Genomic Privacy) § W. Va. Code § 16-5EE-4
Introduced eff 2026-07-01
Entities must develop, implement, and maintain a comprehensive security program to protect consumer genetic data against unauthorized access, use, or disclosure. Entities must also provide consumers with a process to: (1) access their genetic data; (2) delete their genetic data; (3) revoke any consent previously provided; and (4) request and obtain the destruction of their biological sample.
WV
WV HB 5034 (Genomic Privacy) § W. Va. Code § 16-5EE-4
Introduced eff 2026-07-01
Entities must not store genetic data or biological samples of West Virginia residents within the territorial boundaries of any country sanctioned by the United States Office of Foreign Asset Control or designated as a foreign adversary under 15 CFR 7.4(a). Genetic data or biometric data of West Virginia residents may only be transferred or stored outside the United States with the consent of the resident.
WV
WV HB 5567 (Biometric Information Privacy) § W. Va. Code § 15-17-3
Introduced
Private entities in possession of biometric identifiers or biometric information must not sell, lease, trade, or otherwise profit from a person's or customer's biometric identifier or biometric information.
WV
WV HB 5567 (Biometric Information Privacy) § W. Va. Code § 15-17-3
Introduced
Private entities in possession of biometric identifiers or biometric information must not disclose, redisclose, or otherwise disseminate a person's or customer's biometric identifier or biometric information except in four circumstances: (1) the subject or legally authorized representative consents; (2) the disclosure completes a financial transaction requested or authorized by the subject or representative; (3) disclosure is required by state or federal law or municipal ordinance; or (4) disclosure is required by a valid warrant or subpoena.
AK
Failed
State agencies must obtain an individual's consent before soliciting or acquiring sensitive personal data about the individual for use by an AI system making consequential decisions.
AK
Failed
State agencies may not transfer data about an individual to another state agency without the individual's consent, unless required by law.
AK
Failed
State agencies must obtain an individual's consent before soliciting or acquiring sensitive personal data from or about the individual for use in a generative AI system making consequential decisions.
CA
Failed
Employers must not use an ADS to collect worker data for any purpose that was not disclosed in the pre-use notice required under Chapter 2.
CA
Failed
When providing worker data pursuant to this part, employers must anonymize the personal information of customers, other workers, and other individuals contained in or associated with that data.
CO
Failed eff 2026-12-01
Covered businesses must not collect, sell, share, or retain personal data of a covered minor that is not necessary to provide an online gaming service, product, or feature with which the covered minor is actively and knowingly engaged.
CO
Failed eff 2026-12-01
Covered businesses must not use previously collected personal data of a covered minor for any purpose other than the purpose for which it was originally collected, unless the use is necessary to comply with an obligation under Part 19.
FL
FL SB 1746 (Surveillance Pricing) § Fla. Stat. § 501.003
Failed
Persons relying on a statutory safe harbor (cost-based pricing differences, opt-in mailing list/payment-method discounts, broadly defined group discounts for teachers/veterans/seniors/students, or affirmative-enrollment loyalty programs) must: (1) clearly and conspicuously disclose the eligibility criteria, available discounts, and earning conditions BEFORE collecting any covered information; (2) offer the discount uniformly to all consumers meeting the disclosed criteria; and (3) use any covered information collected solely to administer the specific discount, cost-based pricing, or loyalty program, and not for profiling, targeted advertising, or individualized price setting.
FL
FL SB 2 (AI Bill of Rights) § Fla. Stat. § 501.9986
Failed eff 2026-07-01
AI technology companies must not sell or disclose users' personal information unless the data is deidentified, except where the sale or disclosure is specifically authorized by federal law.
FL
FL SB 2 (AI Bill of Rights) § Fla. Stat. § 501.9986
Failed eff 2026-07-01
AI technology companies in possession of deidentified data must (1) take reasonable measures to ensure the data cannot be associated with a user, (2) maintain and use the data in deidentified form and not attempt to reidentify it (except to test their own deidentification processes), (3) contractually require recipients of deidentified data to comply with the same obligations, and (4) implement business processes to prevent inadvertent release.
FL
FL SB 482 (AI Bill of Rights) § Fla. Stat. § 501.9986
Failed
AI technology companies must not sell or disclose personal information of users unless the information is deidentified data. Disclosures specifically authorized by federal law are not prohibited.
FL
FL SB 482 (AI Bill of Rights) § Fla. Stat. § 501.9986
Failed
AI technology companies in possession of deidentified data must: (1) take reasonable measures to ensure the data cannot be associated with a user; (2) maintain and use the data in deidentified form and not attempt to reidentify it, except solely to test the adequacy of their deidentification processes; (3) contractually obligate any recipient of deidentified data to comply with these same requirements; and (4) implement business processes to prevent inadvertent release of deidentified data. Companies may demonstrate compliance by maintaining a risk management program validated against a recognized framework aligned with the NIST AI RMF and ISO 42001, including controls for deidentification, contractual flow-down, non-reidentification, inadvertent release prevention, monitoring, and auditing.
FL
FL SB 702 (Provenance of Digital Content) § Fla. Stat. § 501.9741(4)
Failed
Provenance data embedded in synthetic content must not include personal identifying information or any unique device, system, or service information reasonably capable of being associated with a particular user, unless the user directs its inclusion.
MA
Failed
Companies must delete or de-identify any data collected from individuals once it is no longer needed for the intended purpose of the model.
ME
Failed eff 2026-04-29
Deployers must collect and store only user information that does not conflict with the user's safety and well-being. Deployers may not collect or store information except to fulfill a legitimate purpose, and only to the extent the information is (1) relevant to that legitimate purpose and (2) the minimum amount necessary to fulfill it.
MN
Failed
Agencies must conduct facial recognition surveillance under a covered court order in a way that minimizes the acquisition, retention, and dissemination of information about individuals who are not targets of the court order.
MN
MN HF 465 (Facial Recognition Technology) § Minn. Stat. § 626A.51
Failed
Agencies must conduct all facial recognition surveillance under a covered court order in a manner that minimizes the acquisition, retention, and dissemination of information about individuals other than those for whom there was probable cause.
MT
Failed
Third-party vendors must develop and publish a retention schedule and destruction guidelines for facial biometric data, permanently destroying data when the initial collection purpose is satisfied. Data may be retained beyond this point only with the individual's affirmative authorization, and must be permanently destroyed within one year of the individual's last interaction with the vendor.
MT
Failed
Third-party vendors must not give, sell, lease, or trade an individual's facial biometric data without affirmative authorization from the individual.
NC
Failed
Operators must provide all users with an accessible mechanism to request deletion of personal information, must complete deletion requests unless the data falls within enumerated exceptions (transaction completion, security, debugging, free speech, legal compliance, scientific research, or aligned internal uses), and must maintain a confidential record of all deletion requests.
NC
Failed
Covered platforms must apply the highest privacy settings by default for all users reasonably likely to be children and must implement strict data minimization — limiting collection to what is necessary, deleting data when no longer needed, prohibiting commercial data use unless strictly necessary, honoring minor right-to-be-forgotten requests, prohibiting profiling and behavioral advertising targeting children, providing child-friendly privacy information and controls, mandating transparency about personal data use, restricting geolocation data collection, and imposing data-broker restrictions for children's information.
NC
Failed
Operators must provide all users with an accessible mechanism to request deletion of personal information and must complete the deletion unless the information is reasonably necessary for transaction completion, security, debugging, free speech, regulatory compliance, scientific research, or aligned internal uses. The platform must maintain a confidential record of all deletion requests.
NC
Failed
Covered platforms must collect and store only information that does not conflict with a trusting party's best interests. Information collected must be (i) adequate — sufficient to fulfill a legitimate purpose of the platform; (ii) relevant — having a relevant link to that legitimate purpose; and (iii) necessary — the minimum amount of information needed for that legitimate purpose.
NC
Failed
Covered platforms must be loyal gatekeepers of personal information from trusting parties, including avoiding conflicts to the best interests of trusting parties when allowing government or other third-party access to trusting parties and their data.
NC
Failed
Covered platforms must ensure that all user-related data collected through conversations between users and chatbots or through third-party cookies undergoes a process of de-identification prior to storage and analysis.
NC
Failed
Covered platforms must collect and store only information that does not conflict with a trusting party's best interests, and such information must be adequate (sufficient for a legitimate purpose), relevant (linked to that purpose), and necessary (the minimum needed for that purpose).
NC
Failed
Covered platforms must act as loyal gatekeepers of trusting parties' personal information, avoiding conflicts with trusting parties' best interests when allowing government or other third-party access to their data.
NC
Failed
Covered platforms must de-identify all user-related data collected through chatbot conversations or third-party cookies prior to storage and analysis.
NC
Failed
Covered platforms must take reasonable care to prohibit the incorporation of any sensitive personal information derived from chatbot use into aggregate datasets used to train any chatbot or generative AI system.
NE
Failed eff 2026-04-17
Covered online services must collect and use only the minimum amount of a covered minor's personal data necessary to provide the specific service elements the minor has knowingly engaged with, and must not use that data for purposes other than those for which it was collected.
NE
Failed eff 2026-04-17
Covered online services must retain a covered minor's personal data only as long as necessary to provide the specific service elements the minor has knowingly engaged with.
NE
Failed eff 2026-04-17
Covered online services must not profile a covered minor unless profiling is necessary to provide a service the minor has requested, and only with respect to the aspects of the service the minor is actively and knowingly engaged with.
NE
Failed eff 2028-01-01
Covered platforms must collect and store only information that does not conflict with the trusting party's best interests and that is relevant and necessary to fulfilling the platform's legitimate purpose.
NE
Failed eff 2028-01-01
Covered platforms must avoid conflicts with the best interests of trusting parties when allowing government or other third-party access to trusting party data.
NE
Failed
Entities must not disclose an individual's biometric data except with the individual's written consent, when required by law, pursuant to a court warrant or subpoena, in a criminal proceeding, or in a civil enforcement action under this act.
NH
Failed
Covered businesses must not collect, sell, share, or retain any personal data of a covered minor that is not necessary to provide the online service, product, or feature with which the minor is actively and knowingly engaged, and must not repurpose previously collected personal data of a covered minor for any purpose other than the original collection purpose.
NJ
Failed
Business entities must not sell, lease, trade, share, or otherwise profit from information obtained through the use of a biometric surveillance system on a consumer.
NV
Failed eff 2026-01-01
Insurers must not use health data collected about an insured to train an AI system developed by the insurer without first providing a clear and conspicuous disclosure that health data may be used for AI training and obtaining the insured's affirmative, voluntary consent.
NY
NY AB 8129 (AI Bill of Rights) § State Tech. Law § 404
Failed
Persons developing automated systems must protect New York residents from inappropriate or irrelevant data use in the design, development, and deployment of those systems, and from the compounded harm of data reuse.
NY
NY AB 8129 (AI Bill of Rights) § State Tech. Law § 406
Failed
Designers, developers, and deployers must build privacy protections into automated systems by default, ensure data collection conforms to reasonable expectations, and collect only strictly necessary data for the specific context.
NY
Failed
Employers must not use an electronic monitoring tool to collect employee data unless the tool is primarily intended for an enumerated permissible purpose (essential job functions, quality assurance, performance assessment, legal compliance, health/safety, or wage administration), is strictly necessary and exclusively used for that purpose, is the least invasive means available, and is limited to the smallest number of workers and least amount of data necessary.
NY
Failed
Employers must destroy employee data collected via electronic monitoring when the initial collection purpose has been satisfied or when the employment relationship ends, unless the employee provides written and informed consent to continued retention.
NY
Failed
Employers must not use employee data collected via electronic monitoring for any purpose other than those specified in the prior written notice provided to employees.
NY
Failed
Sensitive employee data collected for bias audits must be collected, processed, stored, and retained in a manner that protects employee privacy. Audit data must not be shared with the employer and must not be shared with any other entity unless strictly necessary for audit completion.
NY
Failed
Employers must limit use of electronic monitoring tools to seven enumerated purposes and must ensure the specific tool is strictly necessary, exclusively used for that purpose, the least invasive means available, limited to the smallest number of workers, and that data is collected no more frequently than necessary and deleted once the purpose is achieved.
NY
Failed
Employers must not use employee data collected via electronic monitoring for any purpose other than those specified in the notice provided to employees.
NY
Failed
Employers must not sell, transfer, or disclose employee data collected via electronic monitoring to any other entity unless required by state or federal law or necessary to comply with an AEDT impact assessment under § 1012.
NY
Failed
Employee data collected for impact assessments must be collected, processed, stored, and retained in a manner protecting employee privacy and in compliance with commissioner-specified security requirements. Data provided to auditors must not be shared with the employer or any other entity unless strictly necessary for the impact assessment.
NY
Failed
Employers may use electronic monitoring tools to collect employee data only if the tool serves one of seven enumerated purposes, is strictly necessary and the least invasive means to accomplish that purpose, and is limited to the smallest number of workers and least amount of data necessary.
NY
Failed
Employers must destroy employee data collected via electronic monitoring when the initial collection purpose has been satisfied or when the employment relationship ends, unless the employee provides written and informed consent to continued retention.
NY
Failed
Employers must not use employee data collected via electronic monitoring for any purpose other than those specified in the prior written notice provided to employees.
NY
Failed
Employers must not sell, transfer, or disclose employee data collected via electronic monitoring to any other entity, unless required by state or federal law or necessary to comply with an AEDT bias audit.
NY
Failed
Sensitive employee data collected for a bias audit must be collected, processed, stored, and retained in a manner that protects employee privacy. Audit data must not be shared with the employer and must not be disclosed to any person or entity unless strictly necessary for the bias audit.
NY
NY SB 8209 (AI Bill of Rights) § State Tech. Law § 404
Failed
Persons developing automated systems must ensure that only appropriate and relevant data is used in the design, development, and deployment of those systems, and must prevent compounded harm from data reuse.
NY
NY SB 8209 (AI Bill of Rights) § State Tech. Law § 406
Failed
Persons developing automated systems must implement privacy protections by default, ensure data collection conforms to reasonable expectations, and collect only strictly necessary data for the specific context.
RI
RI HB 6286 (Generative AI Models) § R.I. Gen. Laws § 6-59-3
Failed
Companies must delete or de-identify any data collected from individuals when it is no longer needed for the intended purpose of the model.
TX
TX HB 1709 (AI Governance) § Bus. & Com. Code § 541.051(b) (as amended)
Failed
Controllers must establish, implement, and maintain reasonable administrative, technical, and physical data security practices appropriate to the volume and nature of data collected, stored, and processed by AI systems.
TX
Failed
Employers must not share an applicant's AEDT assessment with any person other than those whose knowledge and skill are necessary to ensure the tool is correctly processing the applicant's data.
TX
Failed
Employers must, within 30 days of using an AEDT to assess an applicant, (1) make all reasonable efforts to destroy hard copies and erase electronic data files of the assessment, and (2) instruct any person with whom the assessment was shared to do the same. Recipients must comply as soon as practicable.
US
Failed
Covered entities must perform ongoing testing and evaluation of privacy risks and privacy-enhancing measures, including documenting data minimization practices, information security measures (including privacy-enhancing technologies), data retention duration, and current and potential impacts on consumer privacy, safety, and security.
US
Failed
Covered entities must perform ongoing testing and evaluation of privacy risks and privacy-enhancing measures, including assessing data minimization practices, information security measures, privacy-enhancing technologies used, and current and potential impacts on consumer privacy, safety, and security.
US
Failed
Each agency must include a reference to any associated AI governance charter in its Privacy Act system of records notices for systems trained on, using, or producing individual records, and must establish policies ensuring the security, confidentiality, and integrity of records that federal AI systems use, produce, or modify.
US
Failed
Covered entities must perform ongoing testing and evaluation of the privacy risks and privacy-enhancing measures of each automated decision system or augmented critical decision process, including assessing data minimization practices, data retention duration, information security measures, privacy-enhancing technologies used, and current and potential impacts on consumer privacy, safety, and security.
US
Failed
Covered entities must perform ongoing testing and evaluation of privacy risks and privacy-enhancing measures, including data minimization practices, data retention duration, information security measures (e.g., differential privacy, de-identification), and current and potential future impacts on consumer privacy, safety, and security.
VA
Failed
State agencies must ensure that staff who handle personal data collected by the automated decision system and the storage of such data do so in accordance with federal and state law and all agency data agreements and privacy policies.
VA
Failed
Local government entities must ensure that staff who handle personal data collected by the automated decision system and the storage of such data do so in accordance with federal and state law and all entity data agreements and privacy policies.
VA
VA HB 758 (AI Chatbots & Minors) § Va. Code § 59.1-615
Failed
Deployers must collect and store only information that does not conflict with the user's best interests. Information collected must be (i) adequate — sufficient to fulfill a legitimate purpose; (ii) relevant — having a relevant link to that legitimate purpose; and (iii) necessary — the minimum amount needed for that legitimate purpose.
WI
WI AB 1161 (Minors Online Privacy) § Wis. Stat. § 100.80(5)
Failed eff 2027-01-01
Covered businesses must not collect, sell, share, or retain any personal data of a covered minor that is not necessary to provide an online service, product, or feature with which the minor is actively and knowingly engaged.
WI
WI AB 1161 (Minors Online Privacy) § Wis. Stat. § 100.80(5)
Failed eff 2027-01-01
Covered businesses must not use previously collected personal data of a covered minor for any purpose other than the purpose for which the data was originally collected, unless necessary to comply with an obligation under this section.
WI
WI SB 758 (Social Media Minors) § Wis. Stat. § 134.07(2)
Failed eff 2026-03-23
Social media platforms must not gather, use, sell, offer, or retain data relating to a minor's use of or interaction with the platform, except data necessary to establish and maintain the minor's account or to comply with the section's requirements.
WI
Failed eff 2027-01-01
Covered businesses must not collect, sell, share, or retain any personal data of a covered minor that is not necessary to provide the online service, product, or feature with which the covered minor is actively and knowingly engaged.
WI
Failed eff 2027-01-01
Covered businesses must not use previously collected personal data of a covered minor for any purpose other than the purpose for which it was originally collected, unless necessary to comply with this section.
D-01.5
Sensitive attribute restrictions
AI systems may not use sensitive personal attributes (race, gender, religion, health status, sexual orientation, national origin, disability) as direct inputs to consequential automated decisions except where expressly permitted. Proxy variable restrictions also apply — systems may not be designed to infer sensitive attributes from non-sensitive proxies for use in consequential decisions.
Enacted
1
Live
31
Failed
11
Total
43
KY
Enacted eff 2027-07-01
Controllers must not process personal data in violation of antidiscrimination laws and must not discriminate against consumers for exercising their data privacy rights, subject to a safe harbor for bona fide loyalty and rewards programs.
CT
CT SB 1484 (AI Employee Protections) § Conn. Gen. Stat. § 31-48d
Introduced eff 2025-10-01
Employers must not use electronic monitoring to threaten employee health or safety, monitor employees who are not performing work-related tasks, collect medical history, collect biometric identifiers, obtain protected-class information, or punish employees for engaging in protected activity.
ID
ID HB 744 (Biometric Identifiers) § Idaho Code § 48-2101
Introduced eff 2026-07-01
Persons or entities possessing a biometric identifier captured for a commercial purpose must not sell, lease, or otherwise disclose the biometric identifier to another person, except where: (1) the individual consents for identification in the event of the individual's disappearance or death; (2) the disclosure completes a financial transaction the individual requested or authorized; (3) the disclosure is required or permitted by state or federal law; or (4) the disclosure is made by or to a law enforcement agency for a law enforcement purpose in response to a warrant.
IL
Introduced
Employers that use predictive data analytics in employment decisions must not consider an applicant's race or zip code (when used as a proxy for race) to reject an applicant in recruiting, hiring, promotion, renewal of employment, selection for training or apprenticeship, discharge, discipline, tenure, or terms, privileges, or conditions of employment.
IL
Introduced
Persons or entities that rely partially or fully on predictive data analytics to determine a consumer's creditworthiness must not use information that assigns specific risk factors to the consumer's race or zip code resulting in rejection of credit or other adverse credit-related action.
IL
Introduced
Auto insurers must not refuse, renew, place, or price a policy — through any classification plan, rating tier, scoring model, or algorithm — using sex, marital status, race, creed, national origin, religion, age, occupation, education, home ownership, credit information, prior-insurance status, price elasticity of demand, ZIP code (or smaller geography), or income/wealth. Years of driving experience remains permissible.
IL
Introduced
Auto insurers must not use territory or any other geographic characteristic in underwriting decisions (sell, refuse, cancel, non-renew, or terms), and any permitted territorial rating factor must not change the premium by more than 25% from what would otherwise be charged.
IL
Introduced eff 2027-01-01
Insurers must not seek or use neurotechnology data (or genetic testing information) for nontherapeutic purposes in connection with accident and health insurance policies, except where the individual voluntarily submits data that is favorable to the individual.
IL
Introduced eff 2027-01-01
Insurers must not use or disclose protected health information that is neurotechnology data (or genetic information) for underwriting purposes, including eligibility determinations, premium computation, pre-existing condition exclusions, or contract creation or renewal. Exception: long-term care policies excluding nursing home fixed indemnity plans.
IL
Introduced eff 2027-01-01
Employers, employment agencies, labor organizations, and licensing agencies must not solicit, request, require, or purchase neurotechnology data of a person or family member, or require the use of a neurotechnology, as a condition of employment, preemployment application, labor organization membership, or licensure.
IL
Introduced eff 2027-01-01
Employers, employment agencies, labor organizations, and licensing agencies must not take adverse employment actions (termination, modified terms, segregation, or classification) against any person because of genetic testing, genetic information, or neurotechnology data relating to the employee or family member.
IL
Introduced eff 2027-01-01
Agreements offering employment, labor organization membership, licensure, or pay or benefits in return for an individual using a neurotechnology or taking a genetic test are prohibited.
IL
Introduced eff 2027-01-01
Employers must not use neurotechnology data (or genetic information) in workplace wellness programs unless (1) health, genetic, or neurotechnology services are offered by the employer, (2) the employee provides written authorization, (3) only the employee and licensed health care professionals receive individually identifiable results, and (4) the employer receives only aggregate data. Employers must not penalize employees who decline to participate or disclose neurotechnology data.
IL
Introduced eff 2027-01-01
No person may knowingly sell to or interpret for an employer, employment agency, labor organization, or licensing agency (or its employees, agents, or members) a genetic test or neurotechnology data of an employee, member, license holder, or prospective employee, member, or license holder, except under defined statutory exceptions.
LA
Introduced
Covered insurers must not use credit scores, protected-class characteristics, social media or online behavioral data, or consumer purchasing data as input variables in algorithmic decision systems for homeowners insurance underwriting or rating in Louisiana, regardless of actuarial justification.
LA
Introduced
For commercial lines insurance, covered insurers must not use protected-class characteristics as ADS input variables. Other enumerated presumptive proxy variables may be used only upon demonstration to the Commissioner of actuarial justification and absence of disparate impact.
MA
Introduced
Covered entities and service providers must not process sensitive covered data (including neural data) for the purposes of targeted advertising.
MA
Introduced
Controllers must not sell precise geolocation data, must not sell or transfer other sensitive data without affirmative consent (or COPPA compliance for children), and must establish and maintain reasonable administrative, technical, and physical data security practices including a retention schedule requiring deletion when data is no longer necessary.
MA
Introduced
Covered entities must not use biometric data to help make decisions that produce legal effects or similarly significant effects concerning end users. Prohibited decisions include denial or degradation of financial or lending services, housing, insurance, educational enrollment, criminal justice, employment opportunities, health care services, and access to basic necessities such as food and water.
MD
MD HB 995 (Behavioral Health AI Use) § Health Occ. § 1–231(C)
Introduced eff 2026-10-01
Behavioral health care providers using AI for administrative support tasks must (1) ensure compliance with all applicable federal and state patient confidentiality and health records security laws, and (2) execute a written agreement with the AI system owner ensuring that protected health information will be kept confidential and that information accessed through the AI may not be used to train any AI system.
MI
Introduced
Employers using electronic monitoring tools or automated decisions tools must not: (a) collect health, medical, lifestyle, or wellness information; qualified characteristics; or information related to workplace activities (including HR information, productivity data, workplace communications, device usage, geolocation, audio-video or sensor data including biometric recognition, automated tool inputs/outputs linked to individuals, or online activity); (b) identify, punish, or obtain data about a covered individual engaged in activity protected under state or federal labor or employment law; or (c) monitor bathrooms, locker rooms, changing areas, breakrooms, smoking areas, cafeterias, lounges, lactation areas, or prayer areas — including monitoring frequency of use of those areas and monitoring a workplace in an employee's residence, personal vehicle, or personal property.
MN
Introduced
Employers must not use an automated decision system that uses individualized worker data to set compensation unless the employer can demonstrate that: (1) the input data is directly related to the worker's ability to complete the task (e.g., education, training, experience, seniority); (2) the inputs are clearly communicated to the worker so the worker knows compensation is a function of those attributes; and (3) the ADS is used either no more than once per six-month period per worker, or only in conjunction with a meaningful change in work duties such as hiring or promotion.
MN
Introduced
Employers must not use electronic monitoring tools to infer sensitive personal attributes (immigration status, religious/political beliefs, health/reproductive status, emotional state, neural data, sexual orientation, disability, criminal record, or credit history), to make predictions unrelated to essential job functions, to identify or retaliate against workers exercising legal rights, to deploy facial/gait/emotion recognition, to monitor off-duty workers or private areas, to monitor worker residences or personal vehicles, or to collect data for undisclosed purposes.
MN
Introduced eff 2027-01-01
Employers must not use an automated decision system with individualized worker data to set compensation unless (1) the input data is directly related to the worker's ability to complete the task, (2) the inputs are clearly communicated to the worker, and (3) the system is used no more than once per six months per worker or only upon a meaningful change in work duties.
NJ
Introduced
Employers, public entities, and vendors must not transfer or disclose biometric, health, or wellness data to third parties or government entities except as required by law; must not use such data in employment or public-benefit decisions; and must delete such data for applicants not hired, former employees after employment ends, and former service beneficiaries after services end.
NJ
Introduced
Employers, public entities, and vendors must not disclose biometric, health, or wellness data to third parties or government except as required by law, must not use such data in employment or benefit decisions, and must not retain it after employment ends or the beneficiary stops receiving services.
NY
Introduced
Employers must not use an ADS to (1) violate any federal, state, or local labor, employment, health and safety, or civil rights law, (2) infer a worker's protected status under the New York Human Rights Law, (3) identify, profile, predict, or take adverse action against a worker for exercising legal rights, or (4) collect worker data for purposes not disclosed in the pre-use notice.
NY
NY AB 3265 (AI Bill of Rights) § State Tech. Law § 506
Introduced
Persons developing automated systems must establish enhanced protections and restrictions for data and inferences related to sensitive domains. In sensitive domains, individual data and related inferences may only be used for necessary functions, safeguarded by ethical review and use prohibitions.
VA
Introduced
Controllers with actual knowledge or willful disregard that a consumer is an adolescent (ages 13–15) must not process the adolescent's personal data for targeted advertising, sale, or consequential profiling, and must not process it beyond what is reasonably necessary or for undisclosed purposes, without obtaining consent from the adolescent. Precise geolocation collection from adolescents requires necessity, consent, and a visible collection indicator.
VT
Introduced eff 2025-07-01
Employers must not use any automated decision system outputs regarding an employee's physical or mental health in relation to an employment-related decision.
WA
Introduced eff 2026-07-01
Employers must not use any automated decision system outputs regarding an employee's physical or mental health in relation to an employment-related decision.
WV
WV HB 5034 (Genomic Privacy) § W. Va. Code § 16-5EE-5
Introduced eff 2026-07-01
Entities must not disclose a consumer's genetic data to any entity offering health insurance, life insurance, or long-term care insurance, or to any employer of the consumer, without the consumer's express consent.
CA
Failed
Developers must not use a minor's sensitive personal information to train an artificial intelligence system or service.
HI
Failed
Covered entities must not make algorithmic eligibility determinations or algorithmic information availability determinations on the basis of actual or perceived race, color, religion, national origin, sex, gender identity or expression, sexual orientation, familial status, source of income, or disability in a manner that segregates, discriminates, or makes important life opportunities unavailable. Practices with discriminatory effect are also prohibited (disparate-impact standard). An exception applies for affirmative action plans adopted under state or federal law.
NC
Failed
Covered platforms must take reasonable care to prohibit the incorporation or inclusion of any sensitive personal information derived from a user during the use of a chatbot into an aggregate dataset used to train any chatbot or generative artificial intelligence system.
NY
NY AB 8129 (AI Bill of Rights) § State Tech. Law § 406
Failed
Designers, developers, and deployers must establish enhanced protections for data and inferences in sensitive domains, restricting their use to necessary functions safeguarded by ethical review and use prohibitions.
NY
Failed
Sensitive employee data collected for a bias audit must be collected, processed, stored, and retained in a manner that protects employee privacy. Audit data must not be shared with the employer and must not be disclosed to any person or entity unless strictly necessary for the bias audit.
NY
NY SB 8209 (AI Bill of Rights) § State Tech. Law § 406
Failed
Persons developing automated systems must establish enhanced protections for data and inferences related to sensitive domains, limiting use to necessary functions and safeguarding through ethical review and use prohibitions.
TX
TX HB 1709 (AI Governance) § Bus. & Com. Code § 551.054
Failed
No person may develop or deploy an AI system with the specific purpose of inferring or interpreting sensitive personal attributes (race, political opinions, religious beliefs, ethnic orientation, mental health diagnosis, or sex) using biometric identifiers, except for labeling or filtering lawfully acquired biometric data.
TX
Failed
Employers must not use an automated employment decision tool that includes, as a factor in the assessment of applicant fitness for any employment purpose, the applicant's protected-class status under state or federal law or the applicant's residential zip code.
US
Failed
Online platforms must not use algorithmic processes, design features, or personal-information processing for advertising, marketing, or contracting for housing, employment, credit, insurance, healthcare, or education opportunities in a manner that discriminates or makes opportunities unavailable on the basis of protected characteristics.
US
Failed
Online platforms must not use algorithmic processes or process personal information for advertising, marketing, or offering housing, employment, credit, insurance, healthcare, or education opportunities in a manner that discriminates or makes opportunities unavailable based on protected characteristics including race, color, ethnicity, religion, national origin, sex, gender, gender identity, sexual orientation, familial status, biometric information, or disability status.
VT
Failed
Employers must not use any automated decision system outputs regarding an employee's physical or mental health in connection with an employment-related decision.
D-01.6
Age-Differentiated Parental Control and Privacy Tools
Operators must provide minor-specific and under-thirteen parental or guardian tools for managing privacy and account settings, including control over interaction data retention for personalization, use of personal data for AI training, and account deletion. Age assurance data must be minimized and immediately deleted upon determination.
Enacted
2
Live
11
Failed
6
Total
19
CO
Enacted eff 2027-01-01
Operators must comply with Part 13 of Article 1 of Title 6 (Colorado's minor privacy protections) regarding the privacy and data of minor account holders and minor users.
NE
Enacted eff 2026-04-14
Covered online services must collect and use only the minimum personal data necessary to provide the specific elements of the service with which the covered minor has knowingly engaged, must not use such data for other purposes, and must retain it only as long as necessary for that purpose.
AZ
Engrossed
Commercial entities must ensure that any third party conducting anonymous age verification: (1) does not retain personal identifying information once age has been verified; (2) does not use age-verification personal identifying information for any other purpose; (3) keeps all age-verification personal identifying information anonymous and does not share it with any person; and (4) protects age-verification personal identifying information from unauthorized access, destruction, use, modification, or disclosure through reasonable security procedures appropriate to the nature of the information.
GA
GA SB 495 (Age-Appropriate Design Code) § O.C.G.A. § 10-1-976
Introduced eff 2027-01-01
When conducting age assurance, covered entities and processors must: (1) collect only data strictly necessary to determine age status; (2) immediately delete the data on minor determination, retaining only the age-status outcome; (3) not reuse, combine, or disclose age-assurance data outside the processor relationship; and (4) provide a consumer appeals process for age-status determinations.
MA
Introduced
Controllers must provide an effective consent revocation mechanism at least as easy as the consent mechanism, cease processing within 15 days of revocation, must not use minor personal data for targeted or first-party advertising or sales when the controller knows or willfully disregards the consumer is a minor, and must not discriminate or retaliate against consumers exercising their data rights.
MD
MD HB 1261 (AI Toy Safety) § Md. Code, Com. Law § 14-5104
Introduced eff 2026-07-01
Manufacturers must provide parents or legal guardians with the ability to easily access, review, download, and delete all child user data and to disable data collection without disabling the core functionality of the artificial intelligence toy.
MO
Introduced eff 2026-08-28
Covered entities must protect the confidentiality of age-verification information by limiting its collection, processing, use, and storage to what is strictly necessary for age verification, obtaining parental consent, or maintaining compliance records.
PA
Introduced
Social media platforms must not use personalized recommendation systems for minor users unless the minor has affirmatively opted in to the use of search and watch history for recommendations.
SC
Introduced
When conducting age verification, covered entities must (1) collect only age verification data strictly necessary to verify age, (2) use that data only for age verification, (3) not sell, rent, share, or disclose it to any third party except a service provider performing age verification under a contract prohibiting further disclosure, (4) not combine it with any other personal data about the user, (5) delete it within 24 hours of completing verification (except that the entity may retain a record that the user is a minor), and (6) provide a simple process for a user to appeal or correct an age-verification decision.
SC
Introduced
Covered entities must, when conducting age verification: (1) collect only the age verification data strictly necessary to verify age; (2) use age verification data only for age verification; (3) not sell, rent, share, or disclose age verification data to any third party except a service provider performing age verification under a contract prohibiting further disclosure; (4) not combine age verification data with any other personal data about the user; (5) delete age verification data within 24 hours of completing verification (except the entity may retain a record that the user has been verified as a minor); and (6) provide a simple process for a user to appeal or correct an age-verification decision.
US
Introduced
Covered entities must provide parents with the ability to set the number of inputs or period of time the chatbot may use a child or teen's personal data and inputs to generate outputs, after which such data must be deleted from chatbot memory.
US
Introduced
Covered entities must provide parents with pre-set tiered options for governing data retention settings that balance protectiveness and chatbot effectiveness.
VA
VA HB 635 (AI Chatbots Act) § Va. Code § 59.1-618
Introduced eff 2027-01-01
Operators must not train the underlying model of a companion chatbot with a minor's inputs unless the minor's parent or guardian has affirmatively provided written consent to the operator to use the minor's personal information for that specific purpose.
NC
Failed
Commercial entities must ensure that third-party anonymous age verification providers (1) do not retain personal identifying information after verification is complete, (2) do not use such information for any other purpose, (3) keep all verification information anonymous and do not share it, and (4) protect it through reasonable security procedures appropriate to the nature of the information.
NC
Failed
Covered platforms must apply the highest privacy settings by default for all users reasonably likely to be children and must implement strict data minimization — limiting collection to what is necessary, deleting data when no longer needed, prohibiting commercial data use unless strictly necessary, honoring minor right-to-be-forgotten requests, prohibiting profiling and behavioral advertising targeting children, providing child-friendly privacy information and controls, mandating transparency about personal data use, restricting geolocation data collection, and imposing data-broker restrictions for children's information.
NE
Failed eff 2026-04-17
Covered online services that collect personal data for age verification must not use that data for any other purpose. The bill removes the prior requirement to delete age-verification data after use.
NH
Failed
Covered businesses and processors must, during age assurance, (1) collect only data strictly necessary for age assurance, (2) immediately delete all personal data collected for age assurance upon determining whether the user is a covered minor (retaining only the age-range result), (3) not use or combine age-assurance data for any other purpose, (4) not disclose age-assurance data to non-processor third parties, and (5) implement a review process for users to appeal their age determination.
UT
UT HB 438 (AI Companion Chatbot Safety) § Utah Code § 13-72b-301
Failed eff 2026-05-06
Suppliers must provide Utah users with readily accessible and easy-to-use options to delete their account (if applicable) and any personal data or highly sensitive information associated with the account or otherwise reasonably retrievable by the supplier.
WI
Failed eff 2027-01-01
Covered businesses must not permit any individual, including a parent, to monitor a covered minor's online activity or track the minor's location without providing a conspicuous signal to the covered minor when monitoring or tracking occurs.
D-01.7
Biometric Data Pre-Collection Consent
Entities must provide written notice and obtain affirmative opt-in consent from individuals before collecting any biometric identifier, including specific notice of identifier type and collection purpose. Consent obtained from publicly available sources is insufficient unless the individual themselves made the data publicly available.
Enacted
6
Live
29
Failed
11
Total
46
KY
Enacted eff 2027-07-01
Controllers must obtain consumer consent before processing sensitive data, or in the case of data from a known child, process the data in accordance with the federal Children's Online Privacy Protection Act.
KY
Enacted eff 2027-07-01
Controllers must obtain consumer consent before collecting automatic content recognition data.
TX
TX HB 149 (Responsible AI Governance) § Bus. & Com. Code § 503.001
Enacted eff 2026-01-01
Entities must not treat the existence of an individual's biometric identifiers in publicly available images or media on the Internet as evidence of the individual's informed consent for capture or storage of those identifiers for a commercial purpose, unless the individual themselves made the image or media publicly available.
TX
TX HB 149 (Responsible AI Governance) § Bus. & Com. Code § 503.001
Enacted eff 2026-01-01
If a biometric identifier originally captured for AI training purposes is subsequently used for a commercial purpose outside the security and fraud-prevention exemptions, the person possessing the identifier must comply with all biometric identifier possession and destruction requirements of § 503.001, including informed consent and retention limitations, and is subject to associated penalties.
VT
Enacted eff 2026-07-01
Any person must, before collecting or recording an individual's neural data gathered from a brain-computer interface, provide the individual with a written notice explaining how the neural data will be used and obtain written informed consent from the individual.
VT
Enacted eff 2026-07-01
Any person must, before sharing an individual's neural data gathered from a brain-computer interface with a third party, provide the individual with a written request identifying the third party by name and address and the purposes of sharing, and obtain written informed consent from the individual to share.
NY
NY SB 1422 (Biometric Privacy Act) § Gen. Bus. Law § 676-b
Engrossed
Private entities must not collect, capture, purchase, receive through trade, or otherwise obtain any person's biometric identifier or biometric information unless the entity first: (1) informs the subject or their legally authorized representative in writing that a biometric identifier or biometric information is being collected or stored; (2) informs the subject or their legally authorized representative in writing of the specific purpose and length of term for which the biometric data is being collected, stored, and used; and (3) receives a written release executed by the subject or the subject's legally authorized representative.
NY
NY SB 9267 (Consumer Camera Privacy Act) § Gen. Bus. Law § 390-f(2)
Engrossed
Manufacturers and operators must not enable any coordinated surveillance feature as a default setting; coordinated surveillance features may be offered only upon the owner's affirmative opt-in consent, obtained separately from general terms of service.
IA
IA SSB 3085 (Biometric Data) § Iowa Code § 554J.2
Introduced
Private entities must not collect, capture, purchase, or otherwise obtain an individual's biometric data unless, prior to receiving it, the entity provides written notice to the subject (or their legal representative) that (1) the entity intends to collect their biometric data, and (2) the purposes and length of time for which the entity intends to retain it.
ID
ID HB 744 (Biometric Identifiers) § Idaho Code § 48-2101
Introduced eff 2026-07-01
Any person must provide written notice to an individual and obtain the individual's affirmative consent before capturing the individual's biometric identifier (retina or iris scan, fingerprint, voiceprint, or record of hand or face geometry) for a commercial purpose. Consent cannot be inferred from the mere existence of an image or other media containing one or more biometric identifiers on the internet or other publicly available source, unless the individual themselves made the image or media publicly available.
IL
Introduced eff 2027-01-01
Entities must obtain initial express consent from the consumer, parent, guardian, or power of attorney before collecting, using, or disclosing neurotechnology data, including a clear description of intended uses, categories of individuals with access, and how data may be shared.
IL
Introduced eff 2027-01-01
Entities must obtain separate express consent for (1) third-party transfers or disclosures (identifying the third party by name), (2) uses beyond the primary purpose and inherent contextual uses, and (3) post-purpose data retention; informed express consent for research disclosures; and express consent for marketing based on neurotechnology data, third-party marketing, and sale of neurotechnology data.
IL
Introduced
Operators must not permit their AI model to train on a student's covered information and retain the training data indefinitely unless the operator first (1) provides written notice to the student or parent that the AI model will retain training data indefinitely, and (2) obtains written consent from the student or parent. Absent this affirmative opt-in consent, indefinite retention of AI training data derived from student covered information is prohibited.
MA
Introduced
Covered entities and service providers must not transfer an individual's sensitive covered data (including neural data) to a third party unless the individual provides affirmative consent before each specific transfer, or the transfer falls within narrow exceptions for federal legal obligations or imminent injury.
MA
Introduced
Covered entities must not: (1) process or transfer biometric data in any manner not consented to by the end user; (2) sell biometric data to a third party; (3) disclose biometric data except as consistent with the duties of loyalty, care, and confidentiality; or (4) disclose or share biometric data with any other person unless that person enters into a contract imposing on them the same duties of care, loyalty, and confidentiality toward the end user as are imposed on the covered entity. Consent must be freely given, specific, informed, and unambiguous for a narrowly defined purpose; bundled terms of use and passive interactions do not constitute consent.
MA
Introduced
Covered entities must not (1) process or transfer biometric data in any manner not consented to by the end user, (2) sell biometric data to any third party, (3) disclose biometric data to any person or entity except as consistent with the duties of loyalty, care, and confidentiality, or (4) disclose or share biometric data with any person unless that person enters into a contract imposing the same duties of care, loyalty, and confidentiality toward the end user as are imposed on the covered entity. Consent must be freely given, specific, informed, and unambiguous for a narrowly defined purpose — acceptance of general terms of use does not qualify.
MA
Introduced
Private entities must, before collecting, capturing, purchasing, receiving through trade, or otherwise obtaining any biometric identifier or biometric information, (1) provide written notice to the individual or their legally authorized representative that a biometric identifier or biometric information is being collected or stored, (2) provide written notice of the specific purpose and length of term for which the biometric identifier or biometric information is being collected, stored, and used, and (3) obtain informed written consent from the individual or their legally authorized representative. Written consent may be obtained electronically.
MN
MN HF 3408 (Surveillance-Based Pricing) § Minn. Stat. § 325D.141, subd. 2
Introduced
Retail food stores that use biometric data for voluntary identity verification must (1) provide written notice to the consumer that biometric data is being collected, stored, or used, (2) disclose in writing the specific purpose and retention period, (3) disclose in writing the circumstances under which data is shared with law enforcement, (4) obtain a written release from the consumer authorizing collection, storage, or use, and (5) not sell or share biometric data with any third party.
MN
MN HF 4005 (Biometric Data Consent & Safeguards) § Minn. Stat. § 325M.40, subd. 2
Introduced
Any person must obtain an individual's consent before collecting biometric data from that individual. Consent must be received prior to the collection occurring.
MN
MN SF 4199 (Surveillance-Based Pricing) § Minn. Stat. § 325D.141, subd. 2
Introduced
Retail food stores that use biometric data for voluntary consumer identity verification must (1) inform the consumer in writing that biometric data is being collected, stored, or used, (2) disclose the specific purpose, retention period, and law enforcement sharing circumstances in writing, (3) obtain a written release authorizing collection, and (4) not sell or share biometric data with third parties.
MN
MN SF 4351 (Biometric Data Consent) § Minn. Stat. § 325M.40, Subd. 2
Introduced
Any person must obtain an individual's consent before collecting biometric data from that individual. Consent must be received prior to the collection event.
MN
Introduced eff 2027-01-01
Employers must obtain affirmative written consent from each worker or job applicant before subjecting them to an electronic monitoring tool.
MO
Introduced
Private entities must, before collecting, capturing, purchasing, receiving through trade, or otherwise obtaining any person's biometric identifier or biometric information: (1) inform the person or their legally authorized representative in writing that a biometric identifier or biometric information is being collected or stored; (2) inform the person or their representative of the specific purpose and length of term for which the biometric data is being collected, stored, and used; and (3) receive a written release executed by the person or their representative. A valid written release may not be secured through a general release or user agreement.
MO
Introduced
Vendors must not collect, store, or analyze biometric identifiers, behavioral or emotional signals, voiceprints or keystroke dynamics, or precise geolocation unless strictly necessary for the educational purpose and disclosed in the digital privacy agreement.
NJ
Introduced
Business entities must provide clear and conspicuous notice to consumers before using any biometric surveillance system on them at the entity's physical premises, and must use the system only for a lawful purpose. Notice may be provided by posting a sign at the perimeter of the surveilled area. Use without notice is an unlawful practice.
NY
NY AB 6031 (Biometric Privacy Act) § Gen. Bus. Law § 676-b
Introduced
Private entities must provide written notice and obtain a written release from the individual (or their legally authorized representative) before collecting, capturing, purchasing, receiving through trade, or otherwise obtaining any biometric identifier or biometric information. The written notice must inform the subject (1) that a biometric identifier or biometric information is being collected or stored, and (2) of the specific purpose and length of term for which the data is being collected, stored, and used.
OK
OK HB 3547 (Parent Data Sovereignty) § 70 O.S. § 3-168.1(F)
Introduced eff 2026-11-01
State education agencies and local school districts must not collect personally identifiable educational data unless expressly authorized by law and must obtain written parental consent before collecting political or religious beliefs, family income or tax data (beyond lunch eligibility), biometric/health/psychological data unrelated to special education, student social media identifiers or internet activity, or any data not directly necessary for instruction or accountability.
SC
SC HB 5253 (AI in Education) § S.C. Code § 59-28-195(D)
Introduced
School entities and vendors must not collect, store, or analyze biometric data — including facial recognition data, voiceprints, or emotional analysis — without case-specific written parental consent.
US
Introduced
Any person must obtain express, prior consent — a clear, affirmative, freely given, informed, and unambiguous act — from an individual before appropriating, using, collecting, processing, selling, or otherwise exploiting that individual's covered data, including for AI training or AI-generated outputs that imitate, replicate, or are substantially derived from the individual's data. Consent is invalid if obtained through coercion, deception, or as a condition of service beyond what is reasonably necessary.
US
Introduced
Any person sharing covered data with third parties must specifically and clearly disclose each third party to the individual at the time consent is sought, in a standalone disclosure presented distinctly and separately from any privacy policy, terms of service, or other general agreement. The disclosure must be affirmatively presented so the individual sees and acknowledges it. Consent obtained solely through inclusion in general documents or via non-specific or passive disclosure is invalid.
VA
VA HB 2021 (Fair Voice Purchasing Act) § Va. Code § 59.1-608
Introduced
Virtual assistant licensees and licensors must obtain freely given, specific, informed, and unambiguous affirmative consent from the user (or a user-authorized designee) before enabling voice purchasing on a smart speaker or smart display device. Consent may not be obtained through a user agreement or as a condition of operating the virtual assistant.
VT
VT SB 207 (Surveillance Pricing) § 9 V.S.A. § 4193b
Introduced eff 2026-07-01
A person using a permitted equal-terms discount who gathers personally identifiable information in connection with that discount must (1) provide the consumer with clear and conspicuous written notice of the specific intended purposes for the PII before using it and (2) obtain the consumer's written affirmative consent for each stated purpose before using the PII.
WV
WV HB 5034 (Genomic Privacy) § W. Va. Code § 16-5EE-4
Introduced eff 2026-07-01
Entities must obtain initial express consent from the consumer, parent, guardian, or power of attorney before collecting, using, or disclosing the consumer's genetic data. The consent must: (1) clearly describe the entity's use of the genetic data collected through the genetic testing product or service; (2) specify the categories of individuals within the entity that have access to test results; and (3) specify how the entity may share the genetic data.
WV
WV HB 5034 (Genomic Privacy) § W. Va. Code § 16-5EE-4
Introduced eff 2026-07-01
Entities must obtain separate express consent from the consumer for each of the following: (1) transferring or disclosing genetic data or biological samples to any third party other than the entity's processors, including disclosure of the named third-party recipient; (2) using genetic data beyond the primary purpose of the genetic testing product or service; (3) retaining biological samples after completing the initial testing service; (4) transferring genetic data to third parties for research purposes or publication (informed express consent required); and (5) marketing to the consumer based on genetic data, third-party marketing based on the consumer's purchase of genetic testing, or sale of the consumer's genetic data for valuable consideration.
WV
WV HB 5567 (Biometric Information Privacy) § W. Va. Code § 15-17-3
Introduced
Private entities must provide written notice and obtain a written release from the individual (or the individual's legally authorized representative) before collecting, capturing, purchasing, receiving through trade, or otherwise obtaining any biometric identifier or biometric information. The written notice must inform the subject that a biometric identifier or biometric information is being collected or stored and must specify the purpose and length of term for which it will be collected, stored, and used.
MA
Failed
Companies must obtain informed consent from individuals before collecting, using, or disclosing their data for model training or operation.
MD
Failed
Employers — including State and local government units — must not use a facial recognition service to create a facial template during an applicant's interview for employment unless the applicant has signed a consent waiver.
MD
Failed
Employers must obtain consent via a signed waiver that states in plain language the applicant's name, the interview date, that the applicant consents to facial recognition use during the interview, and whether the applicant read the consent waiver.
MN
MN HF 2532 (Biometric Privacy) § Minn. Stat. § 325E.80, subd. 2
Failed
Private entities must, before collecting any biometric identifier or biometric information, (1) provide written notice to the subject that biometric data is being collected or stored, (2) disclose in writing the specific purpose and duration of collection, storage, and use, and (3) obtain a written release from the subject or their legally authorized representative.
MT
Failed
State or local government agencies must notify individuals at the time of image capture that their image may be used with a facial recognition service.
MT
Failed
Third-party vendors contracted by government agencies must provide written notice to individuals that facial biometric data is being collected, disclose the specific purpose and retention period, and obtain written consent before collecting, storing, or using facial biometric data.
NC
Failed
Licensees must obtain explicit user consent for data collection and use before collecting or using user data through the chatbot.
NE
Failed
Entities must, before collecting or possessing biometric data, (1) provide written notice to the individual or their legally authorized representative that biometric data will be collected, including the specific purpose and duration of collection, and (2) obtain written consent from the individual or their representative.
NJ
Failed
Business entities must provide clear and conspicuous notice to consumers before using a biometric surveillance system on them at the business's physical premises, and must use the system only for a lawful purpose. Notice may be satisfied by posting a sign at the perimeter of the surveilled area.
RI
RI HB 6286 (Generative AI Models) § R.I. Gen. Laws § 6-59-3
Failed
Companies must obtain informed consent from individuals before collecting, using, or disclosing their data.
TX
TX HB 1709 (AI Governance) § Bus. & Com. Code § 503.001(c-3) (as amended)
Failed
Persons who capture biometric identifiers for AI training are exempt from CUBI requirements unless the processing is for uniquely identifying an individual; if such biometric data is subsequently used for a commercial purpose, full CUBI compliance (including possession, destruction, and penalty provisions) re-applies.
D-01.8
Conversational data retention limits
Deployers of conversational AI systems and chatbots must not retain user interaction records — chat logs, transcripts, voice recordings, and derived interaction data — beyond a defined maximum retention period, and must securely destroy them at the end of that period. Continued retention is permitted only where required by law or under affirmative user consent for a defined period.
Enacted
0
Live
9
Failed
2
Total
11
OK
Engrossed
Commercial entities and third-party vendors must not retain any identifying information supplied for age verification, except for audit and testing purposes, and in no case for longer than 30 days after platform access is granted.
AZ
AZ HB 2737 (ChatBot Protection Act) § A.R.S. § 44-1383.01
Introduced
Chatbot providers must not retain a user's chat log for more than ten years, unless retention is necessary to comply with this article or otherwise required by law.
LA
Introduced
Chatbot providers must not retain a user's chat log for more than ten years, unless retention is necessary to comply with this Chapter or is otherwise required by law.
MN
Introduced eff 2027-01-01
Employers must destroy all worker data collected, used, or produced by an automated decision system no later than 37 months after its most recent collection, production, or use, unless the worker has provided written and informed consent to continued retention.
NJ
Introduced
Employers and public entities must retain accurate records for at least three years and destroy collected data no later than 37 months after collection unless the individual has given uncoerced written consent to retain it.
PA
Introduced
Covered providers must not collect or retain personal information from detection-tool users (except opt-in feedback contact info used only to improve the tool), must not retain submitted content beyond 24 hours absent express consent, and must not retain personal provenance data from submitted content.
SC
SC HB 5138 (Chatbot Protection Act) § S.C. Code § 39-80-20
Introduced
Chatbot providers must not retain a user's chat log for more than ten years, unless retention is necessary to comply with this chapter or otherwise required by law.
SC
SC SB 896 (Chatbot Protection Act) § S.C. Code § 39-80-20
Introduced
Chatbot providers must not retain a user's chat log for more than ten years, unless retention is necessary to comply with this chapter or otherwise required by law.
VT
VT HB 784 (Chatbot Regulation) § 9 V.S.A. § 4193b
Introduced eff 2026-07-01
Chatbot providers must not retain a user's chat log for longer than 10 years, unless retention is necessary to comply with this subchapter or otherwise required by law.
NC
Failed
Covered platforms operating chatbots in healthcare, financial services, the legal field, government services, mental health support, education, or any domain primarily processing or storing sensitive personal information must utilize self-destructing messages with a predetermined destruction period of 30 days after data acquisition.
NC
Failed
Covered platforms operating chatbots in healthcare, financial services, legal, government services, mental health support, education, or any domain primarily processing or storing sensitive personal information must implement self-destructing messages with a 30-day destruction period after data acquisition.
D-01.9
Prohibition on sale of AI interaction data
Deployers of conversational AI systems and chatbots must not sell, lease, trade, or otherwise profit from disclosing user chat logs, transcripts, voice recordings, or other AI-interaction data. Narrow exceptions apply only for disclosures to service providers bound by equivalent restrictions under a data-processing contract.
Enacted
0
Live
12
Failed
6
Total
18
AZ
AZ HB 2737 (ChatBot Protection Act) § A.R.S. § 44-1383.01
Introduced
Chatbot providers must not sell a user's chat logs. This is a categorical prohibition with no consent override. The sell definition excludes disclosures to service providers processing on behalf of the chatbot provider, disclosures directed by users with affirmative consent, and disclosures of data users intentionally made public without audience restrictions.
LA
Introduced
AI technology companies must not sell or disclose personal information of users unless the information has been deidentified, except as required by law.
LA
Introduced
Chatbot providers must not sell a user's chat logs.
MD
MD HB 1261 (AI Toy Safety) § Md. Code, Com. Law § 14-5104
Introduced eff 2026-07-01
Manufacturers must not (1) sell, lease, or transfer child user data to third parties, (2) use child user data to train unrelated AI models or systems, (3) use child user data for targeted advertising, or (4) retain child user data for more than 12 months without renewed parental consent.
NJ
Introduced
Employers, public entities, and vendors must not sell, license, transfer, disclose, or share EMT-collected data or AEDS outputs to third parties without the individual's uncoerced written consent, must destroy applicant information on request, and vendors must return and delete all data on contract termination.
OK
Introduced eff 2026-11-01
Artificial intelligence technology companies must not sell or disclose personal information of users unless the information is de-identified data.
PA
Introduced
Suppliers must not sell or share individually identifiable health information or user input of Pennsylvania users with third parties, except (1) health care provider requests with user consent, (2) health plan requests at the user's request, or (3) sharing with contracted functionality partners who comply with HIPAA privacy and security requirements as if the supplier were a covered entity and the partner a business associate.
SC
SC HB 5138 (Chatbot Protection Act) § S.C. Code § 39-80-20
Introduced
Chatbot providers must not sell a user's chat logs. Sale includes exchanging personal data or input data for monetary or other valuable consideration or making it available to a third party for consideration, but excludes processor disclosures, user-directed disclosures with affirmative consent, and data the user intentionally made public without audience restrictions.
SC
SC HB 5253 (AI in Education) § S.C. Code § 59-28-195(D)
Introduced
School entities must ensure that student data collected through AI (1) remains the property of the student and parent, (2) is not sold, shared, licensed, or used for commercial advertising or profiling, and (3) is deleted within a defined period unless retention is required by law.
SC
SC SB 896 (Chatbot Protection Act) § S.C. Code § 39-80-20
Introduced
Chatbot providers must not sell a user's chat logs.
VT
VT HB 784 (Chatbot Regulation) § 9 V.S.A. § 4193b
Introduced eff 2026-07-01
Chatbot providers must not process a user's chat log to determine whether to display an advertisement, to select a product or service to advertise, or to customize an advertisement or its presentation to the user.
VT
VT HB 784 (Chatbot Regulation) § 9 V.S.A. § 4193b
Introduced eff 2026-07-01
Chatbot providers must not sell a user's chat logs.
MN
MN HF 2532 (Biometric Privacy) § Minn. Stat. § 325E.80, subd. 2
Failed
Private entities must not sell, lease, trade, or otherwise profit from any person's biometric identifier or biometric information.
NE
Failed
Entities must not sell, lease, trade, or directly profit from biometric data in their possession.
NJ
Failed
Business entities must not sell, lease, trade, share, or otherwise profit from information obtained through their use of a biometric surveillance system on a consumer.
UT
UT HB 438 (AI Companion Chatbot Safety) § Utah Code § 13-72b-301
Failed eff 2026-05-06
Suppliers must not sell to any third party any highly sensitive information (personal finances, legal matters, individually identifiable health information) of a Utah user.
UT
UT HB 438 (AI Companion Chatbot Safety) § Utah Code § 13-72b-301
Failed eff 2026-05-06
Suppliers must not sell to any third party any personal data or highly sensitive information of a minor Utah user.
UT
UT HB 452 (Mental Health Chatbots) § Utah Code § 13-72a-201
Failed
Suppliers must not sell or share with any third party any individually identifiable health information or user input of a Utah user, except (1) health information requested by a health care provider with user consent, (2) health information provided to the user's health plan at the user's request, or (3) health information shared with a contracted functionality partner where both parties comply with HIPAA-equivalent privacy and security provisions as if the supplier were a covered entity and the partner a business associate.
D-01.10
Biometric Data Retention and Destruction Policy
Deployers and Developers in possession of biometric data must develop, publicly disclose, and adhere to a written policy establishing a retention schedule and mandatory destruction timeline, and must permanently destroy biometric data once the purpose for collection has been satisfied.
Enacted
0
Live
4
Failed
2
Total
6
NY
NY SB 1422 (Biometric Privacy Act) § Gen. Bus. Law § 676-b
Engrossed
Private entities in possession of biometric identifiers or biometric information must develop a written policy, made available to the public, establishing a retention schedule and guidelines for permanently destroying biometric identifiers and biometric information. Destruction must occur within a reasonable time, but no later than 60 days after the data is no longer necessary for the permissible purpose identified in the notice or for which the individual provided authorization, or within three years of the individual's last interaction with the private entity, whichever occurs first. The entity must comply with its established retention schedule and destruction guidelines absent a valid warrant or subpoena.
IA
IA SSB 3085 (Biometric Data) § Iowa Code § 554J.2
Introduced
Private entities in possession of biometric data must develop a written policy establishing a retention and destruction schedule for biometric data. The policy must be publicly available. Biometric data must not be retained for more than three years after the subject's last interaction with the entity or until the collection purpose has been accomplished, whichever is longer.
ID
ID HB 744 (Biometric Identifiers) § Idaho Code § 48-2101
Introduced eff 2026-07-01
Persons or entities possessing a biometric identifier captured for a commercial purpose must destroy the biometric identifier within a reasonable time, but no later than one year after the date the purpose for collecting the identifier expires. If the biometric identifier is used in connection with an instrument or document required by another law to be maintained for a longer period, the person must destroy it within a reasonable time but no later than one year after the date the instrument or document is no longer required to be maintained by law. Where an employer collects biometric identifiers for security purposes, the purpose is presumed to expire upon termination of the employment relationship.
MA
Introduced
Private entities in possession of biometric identifiers or biometric information must develop and make publicly available a written policy establishing a retention schedule and guidelines for permanently destroying biometric identifiers and biometric information. Destruction must occur when the initial purpose for collection has been satisfied or within one year of the individual's last interaction with the private entity, whichever comes first. The entity must comply with its retention and destruction policy absent a valid court order, warrant, subpoena, or governmental agency request.
MN
MN HF 2532 (Biometric Privacy) § Minn. Stat. § 325E.80, subd. 2
Failed
Private entities in possession of biometric identifiers or biometric information must develop and make publicly available a written policy establishing a retention schedule and guidelines for permanently destroying biometric data when the initial collection purpose has been satisfied or within three years of the individual's last interaction, whichever occurs first.
NE
Failed
Entities must develop and make publicly available a written retention schedule and destruction policy for biometric data. Biometric data must be permanently destroyed at the earliest of: (1) satisfaction of the initial collection purpose, (2) three months after the last interaction with the individual, or (3) expiration of the individual's written consent. Entities must comply with their published schedule unless retention is required by a court warrant or subpoena.
D-01.11
Biometric Data Security Standards
Deployers and Developers in possession of biometric data must store, transmit, and protect it using security measures that meet the reasonable standard of care within the entity's industry and that are at least as protective as the measures applied to the entity's other confidential and sensitive information.
Enacted
0
Live
9
Failed
2
Total
11
NY
NY SB 1422 (Biometric Privacy Act) § Gen. Bus. Law § 676-b
Engrossed
Private entities in possession of biometric identifiers or biometric information must store, transmit, and protect from disclosure all biometric data using the reasonable standard of care within the entity's industry, and must protect biometric data in a manner that is the same as or more protective than the manner in which the entity protects other confidential and sensitive information.
IA
IA SSB 3085 (Biometric Data) § Iowa Code § 554J.2
Introduced
Private entities must store, transmit, and protect biometric data using reasonable methods that are widely accepted within the entity's industry and that are equivalent to or more protective than the manner in which the entity protects passwords and other account-access information.
ID
ID HB 744 (Biometric Identifiers) § Idaho Code § 48-2101
Introduced eff 2026-07-01
Persons or entities possessing a biometric identifier captured for a commercial purpose must store, transmit, and protect the biometric identifier from disclosure using reasonable care, in a manner that is the same as or more protective than the manner in which the person stores, transmits, and protects any other confidential information the person possesses.
MA
Introduced
Covered entities must secure biometric data from unauthorized access in a manner that is at least as protective as the manner in which they secure other confidential and sensitive data, and must not engage in harmful data practices (processing or transfer that causes or is likely to cause financial, physical, reputational injury, offensive intrusion upon seclusion, or other substantial injury).
MA
Introduced
Private entities must store, transmit, and protect from disclosure all biometric identifiers and biometric information using (1) the reasonable standard of care within the entity's industry, and (2) protections that are the same as or more protective than those the entity applies to other confidential and sensitive information.
MN
MN HF 4005 (Biometric Data Consent & Safeguards) § Minn. Stat. § 325M.40, subd. 3
Introduced
Any person who obtains biometric data must store, transmit, and protect the data from disclosure using reasonable care, in a manner that is at least as protective as the manner in which the person stores, transmits, and protects other confidential information in its possession.
MN
MN SF 4351 (Biometric Data Consent) § Minn. Stat. § 325M.40, Subd. 3
Introduced
Any person who obtains biometric data must store, transmit, and protect from disclosure the biometric data using reasonable care and in a manner that is at least as protective as the manner in which the person stores, transmits, and protects other confidential information the person possesses.
NJ
Introduced
Employers and public entities must maintain reasonable administrative and physical data-security practices, notify the Department and affected individuals of any breach within 48 hours, and bear joint-and-several liability with vendors for fraud or theft enabled by a security failure.
NY
NY AB 6031 (Biometric Privacy Act) § Gen. Bus. Law § 676-b
Introduced
Private entities in possession of biometric identifiers or biometric information must store, transmit, and protect from disclosure all such data using at least the reasonable standard of care within the entity's industry, and in a manner that is the same as or more protective than the manner in which the entity stores, transmits, and protects other confidential and sensitive information.
NE
Failed
Entities that collect or possess biometric data must do so in a manner that is secure (protected from loss, corruption, and unauthorized disclosure) and portable (capable of being transferred to another entity at the individual's request).
NE
Failed
Entities must store, transmit, and protect biometric data from disclosure using (1) the reasonable standard of care within their industry or profession, and (2) protections at least as strong as those applied to other confidential and sensitive data.