KY
Enacted eff 2027-07-01
Controllers must limit personal data collection to what is adequate, relevant, and reasonably necessary for the disclosed processing purposes.
KY
Enacted eff 2027-07-01
Controllers must not process personal data for purposes that are neither reasonably necessary to nor compatible with the purposes disclosed to the consumer, unless the controller obtains consumer consent.
NE
Enacted eff 2026-01-01
Covered online services must collect and use only the minimum amount of a covered minor's personal data necessary to provide the specific service elements with which the minor has knowingly engaged, and must not use such data for other purposes.
NE
Enacted eff 2026-01-01
Covered online services that collect personal data for age verification must use that data solely for age verification and must delete it immediately after verification is complete.
NE
Enacted eff 2026-01-01
Covered online services must retain a covered minor's personal data only as long as necessary to provide the specific service elements with which the minor has knowingly engaged.
NE
Enacted eff 2026-01-01
Covered online services must not profile a covered minor unless profiling is necessary to provide a service the minor has requested, and only with respect to the service aspects with which the minor is actively and knowingly engaged.
NE
Enacted eff 2026-04-14
Covered online services must collect and use only the minimum personal data necessary to provide the specific elements of the service with which the covered minor has knowingly engaged, must not use such data for other purposes, and must retain it only as long as necessary for that purpose.
NE
Enacted eff 2026-04-14
Covered online services must not profile covered minors unless profiling is necessary to provide a service the minor has requested, and only with respect to aspects of the service with which the minor is actively and knowingly engaged.
RI
Enacted eff 2026-06-22
Licensed professionals must maintain the confidentiality of all records and all communications between an individual seeking therapy or psychotherapy services and the licensed professional. Disclosure is permitted only as authorized under R.I. Gen. Laws § 40.1-5-26.
UT
Enacted eff 2027-01-01
Generation services must not require an individual to disclose personally identifiable information beyond what is reasonably necessary to verify the individual's identity and obtain valid consent.
VT
Enacted eff 2026-07-01
Suppliers of mental health chatbots must not sell or share with any third party any individually identifiable health information or user input of Vermont users. Limited exceptions apply for: (1) health care provider requests with user consent; (2) health plan requests at the user's request; and (3) sharing necessary for chatbot functionality with contractual partners, provided both parties comply with HIPAA privacy and security requirements (45 C.F.R. Parts 160 and 164) as if the supplier were a covered entity and the partner a business associate.
HI
Enrolled eff 2027-07-01
Operators must limit the collection, use, and retention of a minor's personal data to what is reasonably necessary to operate the conversational AI service and ensure safety and security, and must use heightened data minimization and security safeguards for a minor's sensitive data.
AZ
Engrossed
Commercial entities must ensure that any third party conducting anonymous age verification: (1) does not retain personal identifying information after age verification is complete; (2) does not use age verification personal identifying information for any other purpose; (3) keeps all age verification personal identifying information anonymous and does not share or communicate it to any person; and (4) protects age verification personal identifying information from unauthorized or illegal access, destruction, use, modification, or disclosure through reasonable security procedures and practices appropriate to the nature of the information.
CA
Engrossed
Deployers must limit collection, use, retention, and sharing of personal information from subjects of consequential decisions to what is reasonably necessary and proportionate to achieve the purposes for which the information was collected, or for another compatible disclosed purpose, and must not further process it in an incompatible manner.
CA
Engrossed
Businesses offering an artificial intelligence health model must comply with all CMIA confidentiality requirements as a deemed provider of health care, including maintaining the same standards of confidentiality required of health care providers with respect to medical information and limiting use of medical information to purposes necessary to provide health care services.
CA
Engrossed
Covered providers must not collect, use, or retain personal information from users of their disclosure verification tool, or from content submitted to the tool, beyond what is reasonably necessary for user authentication.
CA
Engrossed
Covered providers must not condition access to their GenAI system or disclosure verification tool on providing personal information beyond what is strictly necessary for the provenance-data consent purposes described in § 22757.2(a)(3)(B).
CA
Engrossed eff 2027-07-01
Operators must not sell, share, or use for any purpose not expressly authorized by this chapter the personal information of a child.
CA
Engrossed
AI use in psychotherapy records must comply with the confidentiality requirements of Civil Code § 56.104. No company or entity may share, sell, store, or train AI models on any data obtained from psychotherapy.
HI
Engrossed eff 3000-07-01
Providers must limit the collection, use, and retention of a minor's personal data to what is reasonably necessary to operate the AI companion system and ensure safety and security.
HI
Engrossed eff 3000-07-01
Providers must not collect or process sensitive data of a minor — including data revealing mental or emotional state, health information, or biometric identifiers — unless necessary for system safety or accessibility, and must apply heightened data minimization and security safeguards.
KS
Engrossed eff 2027-01-01
App store providers must limit collection and processing of age category data and verification data to what is necessary for age verification, parental consent, and compliance records, and must transmit age category data using industry-standard encryption.
KS
Engrossed eff 2027-01-01
Developers must not request age category data more than once per 12-month period for purposes of verifying the accuracy of age category data or continued account use within the age category.
MD
Engrossed eff 2026-10-01
Operators must limit the collection of personal data to what is reasonably necessary and proportionate to satisfy the requirements of this subtitle.
MI
Engrossed
Covered operators must use age-verification data collected under section 7(2)(a) solely to determine user age and must delete it immediately after the age-determination attempt, except where retention is required by other applicable laws.
MI
Engrossed
Covered operators must use parental-consent data collected under section 7(2)(b) solely to obtain verifiable parental consent and must delete it immediately after the consent attempt, except where retention is required by other applicable laws.
NJ
Engrossed
Business entities must not sell, lease, trade, share, or otherwise profit from information obtained through the business entity's use of a biometric surveillance system on a consumer. This is an absolute prohibition with no exceptions.
NY
Engrossed
Chatbot operators must not use age verification data for any purpose other than determining whether a user is a covered minor and must delete such data immediately after the verification attempt, except where retention is required by applicable law.
NY
Engrossed
Manufacturers and operators must not use footage captured by an owner's networked camera device for algorithm training, product development, or any purpose other than providing services directly requested by the owner, without separate affirmative consent.
NY
Engrossed
Manufacturers and operators must not retain footage captured by a networked camera device for more than 72 hours unless the owner has activated a paid subscription, completed affirmative owner setup, or affirmatively elected longer retention.
OK
Engrossed
Social media platforms must not (1) collect or retain personal information beyond what is necessary to provide the service or feature the minor is actively and knowingly engaged with, or (2) use a minor's personal information for any purpose other than the purpose for which it was collected, unless the platform demonstrates a compelling reason that the collection, retention, or use does not pose substantial harm or privacy risk to minors.
OK
Engrossed
Social media platforms must not collect precise geolocation data of minors unless strictly necessary for the requested service and only for the limited time necessary, and must provide an obvious sign to the minor for the duration of any geolocation data collection.
OK
Engrossed
Social media platforms must not use personal information collected for age estimation for any other purpose or retain it longer than necessary to estimate age, and the age estimate must be proportionate to the risks and data practices of the service.
OK
Engrossed
Social media companies must not retain any identifying information of an individual after access to the social media platform has been granted following reasonable age verification.
WA
Engrossed
Operators must not use personal information collected for age estimation for any other purpose and must delete it — other than the estimated age or age range — once age estimation is complete.
AK
Introduced eff 2027-01-01
Social media platforms must not collect or retain a known minor Alaska resident's personal data beyond the extent reasonably necessary to provide the social media platform to the minor, and must not collect, retain, or share precise location data of the minor.
AL
Introduced eff 2026-10-01
Covered entities must collect and store only information that does not conflict with a trusted party's best interests and that is (1) sufficient to fulfill a legitimate purpose of the covered entity, (2) relevant to the legitimate purpose of the covered entity, and (3) the minimum amount of information needed for the legitimate purpose of the covered entity.
AR
Introduced eff 2026-01-01
Healthcare insurers must ensure AI algorithms leverage federated data-sharing models to protect enrollee privacy, comply with FHIR and USCDI interoperability standards, align AI training and validation data with Trusted Exchange Framework privacy standards, and obtain explicit enrollee consent before using health data in AI development and validation.
AZ
Introduced
Chatbot providers must not process personal data to inform a chatbot output unless processing is necessary to fulfill an express request made by the user and the user has provided affirmative consent. Affirmative consent must meet the statutory standard: a clear affirmative act in response to a stand-alone disclosure, with an equally prominent option to decline, that cannot be inferred from inaction or continued use.
AZ
Introduced
Chatbot providers must not process a user's chat log to determine whether to display an advertisement, to determine which product or service to advertise, or to customize an advertisement for presentation to the user. This is a categorical prohibition — no consent mechanism can override it.
AZ
Introduced
Chatbot providers must not process an adult user's chat log and personal data for training purposes unless the chatbot provider first obtains affirmative consent from the user.
AZ
Introduced
Chatbot providers must not process a user's chat log and personal data to engage in profiling beyond what is necessary to fulfill an express request, and must not profile a user based on any classification or designation of the user's personality or behavioral characteristics beyond what is necessary to fulfill an express request made by the user.
AZ
Introduced
Chatbot providers must take the necessary physical, administrative, and technical measures to prevent de-identified data from being re-identified and to process, retain, and transfer de-identified data without any reasonable means of re-identification.
CA
Introduced
Employers and vendors acting on their behalf must collect and process worker data only as strictly necessary to administer the employment relationship and fulfill specific employment-related or legal obligations, and must not use worker data to train AI systems to replicate, automate, or replace a worker's job.
CT
Introduced eff 2025-10-01
Employers must limit electronic monitoring to six enumerated purposes (quality assurance, performance assessment, legal compliance, employee health and safety, facility/network security, and wage/benefit administration), narrowly tailor monitoring to the intended purpose in the least invasive manner, and maintain reasonable data security practices to protect employee information confidentiality.
CT
Introduced eff 2025-10-01
Employers must not require employees to wear a monitoring device or install an application on the employee's personal device for purposes of location tracking.
CT
Introduced eff 2025-10-01
Employers must not sell, transfer, or disclose employee information collected through electronic monitoring to any other person or entity, except where required by state or federal law or to comply with a high-risk AI impact assessment.
CT
Introduced eff 2025-10-01
Employers must not operate any electronic surveillance device or system for the purpose of recording or monitoring employees in personal-comfort areas (restrooms, locker rooms, lounges) or on any property owned or leased by an employee, including the employee's residence or vehicle.
GA
Introduced eff 2027-01-01
Covered entities must not collect, sell, share, or retain any consumer personal data that is not necessary to provide a service the consumer is actively and knowingly engaged with, and must not reuse previously collected personal data for any purpose other than the original collection purpose.
HI
Introduced
Providers must limit the collection, use, and retention of a minor's personal data to what is reasonably necessary to operate the AI companion system and ensure safety and security.
HI
Introduced
Providers must not collect or process sensitive data of a minor unless necessary for system safety or accessibility, and must apply heightened data minimization and security safeguards to any such collection.
IA
Introduced
Deployers must limit the collection and storage of user information collected by the chatbot to what is necessary to fulfill the deployer's stated purpose for making the chatbot publicly available.
IA
Introduced
Deployers must limit the collection and storage of user information collected by the public-facing chatbot to what is necessary to fulfill the deployer's purpose for making the chatbot publicly available.
IA
Introduced eff 2025-07-01
Device companies must not (1) allow AI to access types of private data not authorized in the initialization agreement, (2) use private data in ways not stated in the statement of purpose, or (3) maintain, disseminate, or delete transferred private data inconsistently with the statement of purpose.
IA
Introduced eff 2025-07-01
Developers must not (1) allow their application to access types of private data not authorized in the initialization agreement, (2) use private data in ways not stated in the application's statement of purpose, or (3) maintain, disseminate, or delete transferred private data inconsistently with the application's statement of purpose.
IA
Introduced
Deployers must limit the collection and storage of user information collected by the chatbot to what is necessary to fulfill the deployer's purpose for making the chatbot publicly available.
IA
Introduced
Employers must not use customer ratings as the sole or primary input data for an automated decision system to make employment-related decisions.
IA
Introduced
When providing employee data pursuant to this chapter, employers must anonymize the personal information of any customer, employee, or other individual contained in the data.
IA
Introduced
Private entities must not sell, lease, trade, or otherwise profit from an individual's biometric data.
ID
Introduced eff 2026-07-01
If a biometric identifier originally captured for the purpose of training an AI system is subsequently used for a commercial purpose not covered by the AI training or security/fraud exemptions in subsection (7), the person possessing the biometric identifier becomes subject to all of the statute's possession, destruction, and penalty provisions as if the identifier had been captured for a commercial purpose from the outset.
IL
Introduced eff 2027-01-01
Insurers that possess neurotechnology data (or genetic testing information) must not release it to third parties except as specifically authorized under the Act.
IL
Introduced eff 2027-01-01
Direct-to-consumer neurotechnology data providers must not share neurotechnology data, genetic test information, or other personally identifiable information about a consumer with any health or life insurance company without written consumer consent.
IL
Introduced eff 2027-01-01
Employers must not use neurotechnology data (or genetic information) in workplace wellness programs unless (1) health, genetic, or neurotechnology services are offered by the employer, (2) the employee provides written authorization, (3) only the employee and licensed health care professionals receive individually identifiable results, and (4) the employer receives only aggregate data. Employers must not penalize employees who decline to participate or disclose neurotechnology data.
IL
Introduced eff 2027-01-01
Entities must treat neurotechnology data and information derived from it as confidential and privileged, releasing it only to the measured individual and persons specifically authorized in writing by that individual.
IL
Introduced eff 2027-01-01
Entities must obtain separate express consent for (1) third-party transfers or disclosures (identifying the third party by name), (2) uses beyond the primary purpose and inherent contextual uses, and (3) post-purpose data retention; informed express consent for research disclosures; and express consent for marketing based on neurotechnology data, third-party marketing, and sale of neurotechnology data.
IL
Introduced eff 2027-01-01
Entities must not disclose neurotechnology data to law enforcement or any other government agency without a consumer's express consent unless pursuant to a search warrant or investigative subpoena issued on a finding of probable cause.
IL
Introduced eff 2027-01-01
Deployers must either (1) inform the user in writing that AI will retain training data indefinitely and obtain the user's express written consent before training on and retaining the user's covered information, or (2) set the default to prohibit training on user data and permit training only after the user is notified and affirmatively opts in.
IL
Introduced eff 2027-01-01
Deployers must not disclose a user's covered information to any third party unless the deployer first obtains express written consent from the user for that specific disclosure.
IL
Introduced eff 2027-01-01
Covered AI tool providers must not collect or retain any personal information from a person who uses the provenance label reading tool, except that voluntary contact information from feedback submitters may be retained. The reading tool must not output any personal provenance data detected in submitted content. Providers must not retain content submitted to the reading tool for longer than is necessary to comply with this Act.
IL
Introduced eff 2027-01-01
Large online platforms must not retain any personal provenance data from content shared on the platform.
IL
Introduced
School districts currently in possession of student biometric information must destroy that information within 30 days after the effective date of the Act and must provide certified documentation of the destruction to the State Board of Education.
IL
Introduced
School districts that have contracted with a third party to obtain, collect, or store student biometric information must, within 30 days after the effective date of the Act, require the third party to destroy all student biometric information in its possession and confirm the completion of the destruction in writing to the school district.
IL
Introduced
During the 30-day destruction period, school districts must not sell, lease, or otherwise disclose student biometric information to any person or entity, unless the individual with legal custody (or the student if 18 or older) consents or the disclosure is required by court order.
IL
Introduced
The Chicago school district, if currently in possession of student biometric information, must destroy that information within 30 days after the effective date of the Act and provide certified documentation of the destruction to the State Board of Education.
IL
Introduced
The Chicago school district, if it has contracted with a third party to obtain, collect, or store student biometric information, must within 30 days after the effective date of the Act require the third party to destroy the biometric information and confirm the destruction in writing to the district.
IL
Introduced
During the 30-day destruction period, the Chicago school district must not sell, lease, or otherwise disclose student biometric information to any person or entity, unless the individual with legal custody (or the student if 18 or older) consents or the disclosure is required by court order.
IL
Introduced
Operators must not sell or rent a student's information or data, including covered information or any other person's information collected by the operator for K–12 school purposes. An exception applies for corporate acquisitions if the successor entity complies with the Act regarding previously acquired student information.
IL
Introduced
Operators must not permit artificial intelligence to train on covered information unless the training is for K–12 school purposes or in furtherance of improving operability and functionality of the operator's service.
IL
Introduced
Operators must not disclose covered information to third parties for the purpose of training artificial intelligence that is not for K–12 school purposes, even where the disclosure would otherwise be permitted to improve operability and functionality of the operator's service.
IL
Introduced
Operators must not permit their AI model to train on a student's covered information and retain the training data indefinitely unless the operator first (1) provides written notice to the student or parent that the AI model will retain training data indefinitely, and (2) obtains written consent from the student or parent. Absent this affirmative opt-in consent, indefinite retention of AI training data derived from student covered information is prohibited.
IN
Introduced eff 2026-07-01
Employers must ensure that the use of an automated decision system output is designed for the purpose of making the specific employment-related decision at issue. Output from systems designed for other purposes may not be repurposed for employment decisions.
KS
Introduced
Covered entities must protect the confidentiality of age information provided by users for age verification by limiting the collection, processing, use, and storage of such information to what is strictly necessary to verify a user's age, obtain verifiable parental consent, or maintain compliance records.
KY
Introduced
Covered online services must collect and use only the minimum amount of a covered minor's personal data necessary to provide the specific service elements the minor has knowingly engaged with, must not use the data for other purposes, and must retain it only as long as necessary for those elements.
KY
Introduced
Covered online services must not be required to collect personal data to comply with this section. Any personal data collected for age verification must not be used for other purposes and must be deleted after use for age verification.
LA
Introduced
Covered entities must (1) limit collection of personal data to what is minimally necessary for age verification or compliance, (2) prevent unauthorized access to age-verification data, (3) transmit age-verification data only using industry-standard encryption, (4) prohibit the sale, transfer, or sharing of age-verification data, and (5) retain verification data no longer than reasonably necessary.
LA
Introduced
Employers must not use an ADS to collect worker data for any purpose that was not disclosed in the pre-use written notice required under R.S. 23:972.
LA
Introduced
Employers must provide worker data in a manner that anonymizes the personal information of customers, other workers, and other individuals when required to share worker data under this Part.
LA
Introduced
AI technology companies in possession of deidentified data must (1) take reasonable measures to prevent reidentification, (2) maintain and use data in deidentified form, (3) contractually bind recipients to comply with these requirements, and (4) implement business processes to prevent inadvertent release of deidentified data.
LA
Introduced
Chatbot providers must not process personal data other than input data to inform chatbot outputs unless the processing is necessary to fulfill an express user request and the user has provided affirmative consent.
LA
Introduced
Chatbot providers must not process a user's chat logs for any advertising purpose, including determining whether to display ads, selecting ad categories, or customizing ad presentation.
LA
Introduced
Chatbot providers must obtain affirmative consent before using adult users' chat logs or personal data for training purposes, and must not engage in profiling beyond what is necessary to fulfill an express user request.
LA
Introduced
Chatbot providers must not use any classification or designation of a user's personality or behavioral characteristics created through profiling beyond what is necessary to fulfill an express user request.
LA
Introduced
Operators must not sell to or share with any third party any individually identifiable health information of a user or the user's input. Exceptions apply only when: (1) individually identifiable health information is requested by a healthcare provider with the user's consent, (2) information is provided to the user's health plan at the user's request, or (3) information is shared to ensure effective functionality of the chatbot with another party under contract with the operator. When sharing under any exception, the operator and the receiving entity must comply with all applicable HIPAA privacy and security provisions (45 CFR Parts 160 and 164, Subparts A and E) as if the operator were a covered entity and the receiving party a business associate.
LA
Introduced
Operators must not use a user's input to: (1) determine whether to display an advertisement for a product or service to the user (unless the advertisement is for the mental health chatbot itself), (2) determine a product, service, or category of product or service to advertise to the user, or (3) customize how an advertisement is presented to the user.
MA
Introduced
Covered entities and service providers must not collect or process sensitive covered data (including neural data) unless such collection or processing is strictly necessary to provide or maintain a specific product or service requested by the individual.
MA
Introduced
Controllers must limit collection of personal data to what is reasonably necessary and proportionate to provide the requested product or service, must not process data inconsistent with consumer expectations, and must not collect or process sensitive data unless strictly necessary to provide the requested product or service.
MA
Introduced
Controllers in possession of de-identified data must implement technical re-identification safeguards, publicly commit not to re-identify the data, contractually bind recipients to the same obligations, and monitor downstream compliance with those contractual commitments.
MA
Introduced
Controllers must extend all chapter protections for precise geolocation data to non-residents whose geolocation data reveals they are or were present in Massachusetts, treating such data identically to that of Massachusetts consumers.
MA
Introduced
Employers must not use employee data collected via electronic monitoring for any purpose other than those specified in the notice provided to employees.
MA
Introduced
Employee data collected for impact assessments must be processed and stored to protect privacy, comply with commissioner-specified retention and security requirements, and must not be shared with the employer or any other entity unless strictly necessary for completing the impact assessment.
MA
Introduced
Employers must not use an electronic monitoring tool to collect employee information unless the tool is primarily used for one of six enumerated legitimate purposes (facilitating essential job functions, ensuring quality, periodic performance assessment, legal compliance, health/safety/security, or wage/benefit administration). The tool's type and activated capabilities must be narrowly tailored to accomplish the stated purpose, customized and implemented in the manner least invasive to employees, limited to the smallest number of workers, collecting the least amount of data no more frequently than necessary, with data deleted once the purpose is achieved. Data not necessary for the stated purpose must not be disclosed to the employer and must be promptly disposed of by the vendor. Employee data must not be collected when the employee is off-duty. Necessary data must be stored consistent with the commonwealth's data and cyber privacy laws, promptly disposed of when no longer needed, and not used by the employer, vendor, or any third party for any unauthorized reason.
MA
Introduced
Employers must not use employee data collected via electronic monitoring for purposes other than those specified in the notice provided to employees.
MA
Introduced
Employers must not sell, transfer, or disclose employee data collected via electronic monitoring to any other entity unless required by federal or state law, or necessary to comply with an impact assessment of an automated employment decision tool.
MA
Introduced
Private entities must not disclose, redisclose, or otherwise disseminate any person's or customer's biometric identifier or biometric information unless one of the following applies: (1) the individual or their legally authorized representative provides written consent, (2) the disclosure completes a financial transaction requested or authorized by the individual, (3) the disclosure is required by state, federal, or municipal law, or (4) the disclosure is required by a valid warrant or subpoena from a court of competent jurisdiction.
MD
Introduced eff 2026-07-01
Manufacturers must collect only the minimum child user data necessary for the core functionality of the artificial intelligence toy and must encrypt all collected child user data.
MI
Introduced
Employers must not use an electronic monitoring tool or automated decisions tool to collect a covered individual's data except for the following enumerated purposes: (a) to allow an employee to accomplish or facilitate an essential job function, (b) to monitor production processes or quality, (c) to periodically assess employee performance, (d) to ensure or facilitate compliance with state or federal labor or employment law, (e) to protect the health, safety, or security of covered individuals, (f) to administer wages and benefits using only data regarding the covered individual's work city and cost of living, or (g) to accomplish any other purpose that enables business operations as determined by the Department of Labor and Economic Opportunity.
MI
Introduced
Employers using an electronic monitoring tool or automated decisions tool must: (a) provide written notice to all covered individuals subject to the tool; (b) obtain written consent from each covered individual; (c) ensure that collected data is accurate and up to date; (d) allow covered individuals to correct inaccurate data about themselves; (e) use the tool in a narrowly tailored manner to accomplish only a permitted purpose; (f) use the tool through the least invasive means possible; (g) ensure the tool applies to the smallest number of covered individuals, collects the least amount of data, and is used no more frequently than necessary; and (h) ensure the tool does not collect any employee data when the employee is off duty.
MI
Introduced
Employers must retain data collected through an electronic monitoring tool or automated decisions tool for no more than 3 years after the purpose for using the tool is achieved, unless otherwise specified by a collective bargaining agreement. If the employer does not use any specific data of a covered individual, the employer must delete that data immediately.
MI
Introduced
Employers must not sell or license a covered individual's data collected through an electronic monitoring tool or automated decisions tool, including deidentified or aggregated data.
MI
Introduced
Employers must not share data collected through electronic monitoring or automated decision tools with the state or a local unit of government unless necessary to (a) provide information to the Department of Labor and Economic Opportunity, (b) comply with federal, state, or local law requirements, or (c) comply with a court-issued subpoena, warrant, or order.
MI
Introduced
Persons collecting covered information under a safe-harbor discount, cost-based pricing, or loyalty program must use that information solely for offering or administering the applicable program and must not use it for any other purpose, including profiling, targeted advertising, or individualized price setting.
MI
Introduced
Persons must not augment or supplement personally identifiable information provided by a consumer for the purpose of receiving a discounted price with personally identifiable information obtained from a third party or by other means.
MI
Introduced
Employers must retain worker data collected via monitoring or automated decisions tools no longer than three years after the collection purpose is achieved, and must immediately delete any data they do not use.
MI
Introduced
Employers must not sell or license worker data (including deidentified or aggregated data) and must not share monitoring or automated-decision data with state or local government except to supply the department, comply with law, or respond to a subpoena, warrant, or order.
MN
Introduced
Any person who obtains biometric data must not sell, lease, or otherwise disclose it to another person, except where: (1) the individual consents to disclosure for identification purposes in the event of the individual's disappearance or death; (2) the disclosure completes a financial transaction the individual requested or authorized; (3) the disclosure is required or permitted by federal or state law; or (4) the disclosure is made by or to a law enforcement agency for a law enforcement purpose in response to a warrant.
MN
Introduced
Any person who obtains biometric data must delete and destroy it within a reasonable time, but no later than one year from the date the purpose for collecting the data expires. If a federal or state law requires a longer retention period, the data must be destroyed within a reasonable time but no later than one year after that statutory retention period expires. For employers who collect employee biometric data for security purposes, the collection purpose expires upon termination of the employment relationship.
MN
Introduced
Employers may use electronic monitoring tools only for six enumerated purposes (essential job functions, quality assurance, periodic performance assessment, legal compliance, health/safety/security, and wage/benefit administration), must specify the intended purpose, must narrowly tailor the tool's capabilities to that purpose, and must minimize the number of workers monitored and the frequency and volume of data collected.
MN
Introduced
Employers must not transfer, sell, or license worker data (including deidentified or aggregated data) to third parties unless the recipient is under contract to analyze the data, the contract prohibits resale, the recipient implements reasonable security procedures, and the recipient agrees to joint-and-several liability for data breaches. Employers must not share worker data with government unless required by law.
MN
Introduced
Employers and vendors must restrict worker data access to authorized personnel only, notify workers of data breach impacts as soon as possible, and — at the end of a vendor contract — vendors must return all worker data to the worker and employer in a user-friendly format and delete all remaining copies.
MN
Introduced
Any person who obtains biometric data must not sell, lease, or otherwise disclose the biometric data to another person, except where: (1) the individual consents to disclosure for identification in the event of disappearance or death; (2) the disclosure completes a financial transaction the individual requested or authorized; (3) the disclosure is required or permitted by federal or state law; or (4) the disclosure is made by or to a law enforcement agency for a law enforcement purpose in response to a warrant.
MN
Introduced
Any person who obtains biometric data must delete and destroy the biometric data within a reasonable time, but no later than one year from the date the purpose for collecting the data expires. If a federal or state law requires a longer retention period, the biometric data must be destroyed no later than one year from the date that retention period expires. For employers who collect employee biometric data for security purposes, the collection purpose expires upon termination of the employment relationship.
MN
Introduced eff 2027-01-01
Employers may only use electronic monitoring tools for three enumerated purposes (quality assurance, legal compliance, and safety/security), must specify the intended purpose, limit use to that purpose, narrowly tailor the tool's capabilities, and minimize the scope of data collection and the number of workers monitored.
MN
Introduced eff 2027-01-01
Employers must not transfer, sell, or license worker data (including deidentified or aggregated data) except to vendors under contract that prohibits resale, requires reasonable security, and imposes joint and several breach liability. Government sharing is prohibited absent a legal requirement. Employers and vendors must maintain data security, restrict access to authorized personnel, notify workers of breaches, and vendors must return all data and delete copies at contract end.
MO
Introduced
Private entities in possession of biometric identifiers or biometric information must not sell, lease, or trade any person's or customer's biometric identifier or biometric information.
MO
Introduced
Private entities in possession of biometric identifiers or biometric information must not disclose, redisclose, or otherwise disseminate any person's or customer's biometric identifier or biometric information unless one of four exceptions applies: (1) the person or their legally authorized representative provides written release to the disclosure; (2) the disclosure completes a financial transaction requested or authorized by the person or their representative; (3) the disclosure is required by state, federal, or municipal law; or (4) the disclosure is required pursuant to a valid warrant or subpoena issued by a court of competent jurisdiction.
MO
Introduced
Private entities must not condition the provision of any good or service on the collection, use, disclosure, transfer, sale, retention, or processing of a biometric identifier unless the biometric identifier is strictly necessary to provide the good or service.
MO
Introduced eff 2026-08-28
Covered entities must establish, implement, and maintain reasonable data security for age verification data, including: (1) limiting collection of personal data to what is minimally necessary to verify a user's age or maintain compliance; (2) protecting age verification data against unauthorized access; (3) transmitting such data only using industry-standard encryption protocols; (4) retaining such data no longer than reasonably necessary to verify age or maintain compliance; and (5) not sharing, transferring, or selling age verification data to any other entity.
MO
Introduced
Any verification or age-confirmation system used for compliance with this section must comply with data minimization and privacy-by-design principles.
MO
Introduced
Third parties must not retain or sell biometric, facial recognition, or identification data collected for compliance purposes under this section.
MO
Introduced
The statewide digital privacy agreement must incorporate and comply with state statutes governing data minimization, secondary use limitations, targeted advertising prohibitions, security safeguards, privacy notices, breach response, retention and deletion, and directory-information protections.
MO
Introduced
Vendors must not collect, store, or analyze biometric identifiers, behavioral or emotional signals, voiceprints or keystroke dynamics, or precise geolocation unless strictly necessary for the educational purpose and disclosed in the digital privacy agreement.
MO
Introduced
Vendors must ensure software does not display commercial or sponsored content, use session replay, heat-mapping, or behavioral analytics, create persistent identifiers, or track students outside the educational purpose.
MO
Introduced
Vendors must use encryption for data in transit and at rest, store and process all student data within the United States, disclose all subprocessors and obtain contracting entity approval before use, and prohibit background data collection when software is minimized or inactive.
MO
Introduced
Vendors must not use camera, microphone, or system-level access unless strictly necessary for the educational function and disclosed in the digital privacy agreement, and must not condition access, features, pricing, or support on any form of usage quota or screen-time expectation.
MO
Introduced eff 2026-08-28
Covered entities must establish, implement, and maintain reasonable data security for age verification data, including: (1) limiting collection of personal data to what is minimally necessary for age verification or compliance; (2) protecting age verification data against unauthorized access; (3) transmitting data only using industry-standard encryption; (4) retaining data no longer than reasonably necessary; and (5) not sharing, transferring, or selling age verification data to any other entity.
NJ
Introduced
Employers must not share an applicant's video interview except with a service provider whose expertise or technology is necessary to evaluate the applicant's fitness for the position.
NJ
Introduced
Employers and public entities must limit AEDS and EMT data collection and use to what is necessary for allowable purposes, use the least invasive means, collect data no more frequently than necessary, restrict access to authorized agents, and ensure that collected data is accessed only by authorized agents of the employer, the public entity, or the employee or their authorized representative.
NJ
Introduced
Employers, public entities, and vendors must not sell, license, transfer, disclose, or share employee, applicant, or service beneficiary data or AEDS outputs with any third party without uncoerced written consent, except to the individual, their authorized representative, or law enforcement when required by law. Applicant data must be destroyed upon the applicant's request. Vendors must return and delete all data when the contract terminates.
NJ
Introduced
Employers must not share an applicant's video interview except with a service provider whose expertise or technology is necessary to evaluate the applicant's fitness for the position.
NJ
Introduced
Employers must not share an applicant's video interview recording with anyone except a service provider whose expertise or technology is necessary to evaluate the applicant's fitness for the position.
NJ
Introduced
Employers, public entities, and vendors must restrict access to EMT- or AEDS-collected worker data to authorized agents of the employer or public entity and the affected employee or their authorized representative.
NJ
Introduced
Public entities and vendors must restrict access to data used by an ABSDS to authorized agents of the public entity and the affected service beneficiary.
NY
Introduced
Employers must not use an ADS to (1) violate any federal, state, or local labor, employment, health and safety, or civil rights law, (2) infer a worker's protected status under the New York Human Rights Law, (3) identify, profile, predict, or take adverse action against a worker for exercising legal rights, or (4) collect worker data for purposes not disclosed in the pre-use notice.
NY
Introduced
Chatbot operators must not use information collected for the purpose of determining whether a covered user is a covered minor for any purpose other than making that determination, and must delete such information immediately after the determination attempt, except where retention is required for compliance with applicable New York state or federal law.
NY
Introduced
Utilities must handle data used in anomaly detection systems in accordance with applicable state and federal privacy laws and must use such data solely for billing integrity and consumer protection purposes.
NY
Introduced
Persons developing automated systems must protect New York residents from inappropriate or irrelevant data use in the design, development, and deployment of automated systems, and from the compounded harm of data reuse.
NY
Introduced
Persons developing automated systems must implement built-in privacy protections by default, ensure that data collection conforms to reasonable expectations, and collect only strictly necessary data for the specific context.
NY
Introduced
Persons developing automated systems must establish enhanced protections and restrictions for data and inferences related to sensitive domains. In sensitive domains, individual data and related inferences may only be used for necessary functions, safeguarded by ethical review and use prohibitions.
NY
Introduced
Employers must ensure that employee data collected for impact assessments is collected, processed, stored, and retained in a privacy-protective manner and in compliance with Commissioner-specified data retention and security requirements. Employee data provided to auditors must not be shared with the employer and must not be disclosed to any other person or entity unless strictly necessary for completing the assessment.
NY
Introduced
Private entities in possession of biometric identifiers or biometric information must not disclose, redisclose, or otherwise disseminate the data unless one of four conditions is met: (1) the subject or their legally authorized representative consents; (2) the disclosure completes a financial transaction requested or authorized by the subject; (3) the disclosure is required by federal, state, or local law or municipal ordinance; or (4) the disclosure is required pursuant to a valid warrant or subpoena issued by a court of competent jurisdiction.
NY
Introduced
Employee data collected for impact assessments must be collected, processed, stored, and retained in a manner that protects employee privacy and complies with Commissioner-specified data retention and security requirements. Assessment data provided to auditors must not be shared with the employer or any other entity unless strictly necessary for the assessment.
NY
Introduced
Employers must limit electronic monitoring to enumerated lawful purposes, use the least invasive means strictly necessary, minimize the number of monitored workers and volume/frequency of data collection, delete data once the purpose is achieved, and must not use collected data for purposes beyond those specified in the employee notice.
NY
Introduced
Employers must not sell, transfer, or disclose employee data collected via electronic monitoring to any other entity, except where required by state or federal law or necessary to comply with an AEDT impact assessment.
NY
Introduced
Employee data collected for an impact assessment must be collected, processed, stored, and retained in a manner that protects employee privacy and complies with Commissioner-specified retention and security requirements. Data provided to auditors must not be shared with the employer or any other entity unless strictly necessary for completing the impact assessment.
OK
Introduced eff 2026-11-01
State education agencies, local school districts, and their contractors must treat student data solely as held in custodial capacity, must not claim proprietary or ownership interests in it, and must not sell, trade, or license any student data for commercial purposes.
OK
Introduced eff 2026-11-01
State education agencies and local school districts must not collect personally identifiable educational data unless expressly authorized by law and must obtain written parental consent before collecting political or religious beliefs, family income or tax data (beyond lunch eligibility), biometric/health/psychological data unrelated to special education, student social media identifiers or internet activity, or any data not directly necessary for instruction or accountability.
OK
Introduced eff 2026-11-01
State education agencies and local school districts must not transfer personally identifiable student data to any federal or state agency, private contractor, or nonprofit organization without written parental consent (or student consent if age eighteen or older), unless otherwise authorized by law.
OK
Introduced eff 2026-11-01
Deployers must collect and store only information that does not conflict with a trusting party's best interests. Information collected must be adequate (sufficient for a legitimate deployer purpose), relevant (linked to that legitimate purpose), and necessary (the minimum amount needed for that purpose).
OK
Introduced eff 2026-11-01
Artificial intelligence technology companies in possession of de-identified data must (1) take reasonable measures to prevent re-association with individuals, (2) maintain data in de-identified form and not attempt re-identification except to test the de-identification process, (3) contractually require recipients to comply with these restrictions, and (4) implement safeguards against inadvertent release.
OK
Introduced eff 2025-11-01
Social media platforms must not collect data from minor users unless the data is de-identified, must not use or process minor user data in a manner inconsistent with the best interests of the minor user, and must not display, send, or target advertisements to minor users or use data collected from minor users for advertising purposes.
PA
Introduced
Social media companies must not mine data related to a minor account holder, except for (1) age and location data for age-appropriate content recommendations, (2) data necessary to protect minors from harmful content, or (3) data that is adequate, relevant, and reasonably necessary for the disclosed processing purpose.
PA
Introduced
Social media platforms must not process a minor's precise geolocation information by default unless strictly necessary to provide a requested service, product, or feature and only for the duration necessary. When processing a minor's precise geolocation, the platform must provide a conspicuous signal to the minor for the duration of the processing.
PA
Introduced
Suppliers must not sell or share with any third party a consumer's individually identifiable health information or consumer input. Sharing is permitted only in two circumstances: (1) a health care provider requests access to the consumer's individually identifiable health information and the consumer provides written consent, or the consumer requests that a health plan receive access and provides written consent; or (2) the sharing is necessary for the chatbot's effective functionality with a contracted third party and the consumer provides written consent. When sharing under the functionality exception, the supplier and the third party must comply with all HIPAA security and privacy provisions (45 CFR Parts 160 and 164) as if the supplier were a HIPAA covered entity and the third party a business associate. Written consent must acknowledge that the consumer understands and agrees to the sharing.
PA
Introduced
Suppliers must not use consumer input to determine whether to display an advertisement (unless the advertisement is for the chatbot itself), determine what product, service, or category to advertise, or customize how an advertisement is presented to the consumer.
PA
Introduced
Covered providers must not collect or retain personal information from detection-tool users (except opt-in feedback contact info used only to improve the tool), must not retain submitted content beyond 24 hours absent express consent, and must not retain personal provenance data from submitted content.
PA
Introduced
Covered AI tool providers must not collect or retain personal information from users of the provenance-label reading tool (except voluntarily-submitted feedback contact info) and must not retain submitted content longer than necessary to comply with the act.
RI
Introduced
Employers must not use an electronic monitoring tool to collect employee information unless the tool is primarily used for one of six enumerated legitimate purposes: (1) accomplishing essential job functions, (2) ensuring quality of goods and services, (3) conducting periodic assessment of worker performance, (4) ensuring compliance with employment, labor, or other relevant laws, (5) protecting health, safety, or security of workers or security of employer facilities and networks, or (6) administering wages and benefits.
RI
Introduced
Employers must narrowly tailor the type and activated capabilities of any electronic monitoring tool to accomplish the employer's intended legitimate purpose. The tool must be customized and implemented in the manner least invasive to employees. Monitoring must be limited to the smallest number of workers, collect the least amount of data no more frequently than necessary, and data must be deleted once the purpose is achieved. Employee data not necessary for the legitimate purpose must not be disclosed to the employer and must be promptly disposed of by the vendor. Employee data must not be collected when the employee is off-duty. Data necessary for the legitimate purpose must be stored consistent with state data and cyber privacy laws, disposed of when no longer needed, and not used by the employer, vendor, or any third party for any other reason.
RI
Introduced
Employers must not use employee data collected via an electronic monitoring tool for purposes other than those specified in the notice provided to employees and candidates.
RI
Introduced
Employers must not sell, transfer, or disclose employee data collected via an electronic monitoring tool to any other entity unless required to do so under federal or state law, or necessary to comply with an impact assessment of an automated decision system used under this section.
RI
Introduced
Employers must not require employees to: (1) physically implant devices that collect or transmit data, including subcutaneous or clothing/accessory-incorporated devices, (2) install applications on personal devices that collect or transmit employee data, or wear or embed those devices, or (3) carry or use any device with location tracking enabled, unless the location tracking is conducted during work hours only and is strictly necessary to accomplish essential job functions and narrowly limited to only the activities and times required.
SC
Introduced
Chatbot providers must not process personal data to inform a chatbot output unless (1) processing is necessary to fulfill an express request made by the user and (2) the user provides affirmative consent. Affirmative consent requires a clear affirmative act in response to a specific, stand-alone, accessible, multilingual disclosure with equally prominent accept and decline options; it cannot be inferred from inaction, continued use, or broad terms of use.
SC
Introduced
Chatbot providers must not process a user's chat log to determine whether to display an advertisement, to determine what product or service to advertise, or to customize an advertisement for the user.
SC
Introduced
Chatbot providers must not use an adult user's chat log and personal data for training purposes unless the chatbot provider first obtains affirmative consent from the user.
SC
Introduced
Chatbot providers must not process a user's chat log and personal data for profiling beyond what is necessary to fulfill an express request, and must not profile a user based on personality traits or behavioral characteristics beyond what is necessary to fulfill the user's express request.
SC
Introduced
Chatbot providers must take the necessary physical, administrative, and technical measures to prevent deidentified data from being reidentified and to process, retain, and transfer deidentified data without any reasonable means of reidentification.
SC
Introduced
School entities must ensure that AI systems collect only the minimum student data necessary to achieve an approved educational purpose.
SC
Introduced
School entities must ensure that student data collected through AI (1) remains the property of the student and parent, (2) is not sold, shared, licensed, or used for commercial advertising or profiling, and (3) is deleted within a defined period unless retention is required by law.
SC
Introduced
Chatbot providers must not process personal data to inform chatbot output unless the processing is necessary to fulfill an express request made by the user and the user has provided affirmative consent. Affirmative consent must be obtained via a clear, conspicuous, stand-alone disclosure in easily understandable language, accessible to users with disabilities, in each language the chatbot is offered, with the option to decline at least as prominent as the option to consent. Consent may not be inferred from inaction or continued use.
SC
Introduced
Chatbot providers must not process a user's chat log to determine whether to display an advertisement, to determine which product or service to advertise, or to customize an advertisement for presentation to a user. This is an absolute prohibition — no consent mechanism overrides it.
SC
Introduced
Chatbot providers must not process an adult user's chat log and personal data for training purposes unless the chatbot provider first obtains affirmative consent from the user.
SC
Introduced
Chatbot providers must not process a user's chat log and personal data for profiling beyond what is necessary to fulfill an express request, and must not profile a user based on personality traits or behavioral characteristics beyond what is necessary to fulfill an express user request.
SC
Introduced
Chatbot providers must take necessary physical, administrative, and technical measures to prevent deidentified data from being reidentified and must process, retain, and transfer deidentified data without any reasonable means of reidentification.
TN
Introduced eff 2026-07-01
Food retail establishments must not collect or use the data of any person under 17 years of age for targeted advertising or personalized algorithmic pricing.
TX
Introduced eff 2025-09-01
Entities that capture biometric identifiers for AI training, processing, or storage must not repurpose those identifiers to a separate commercial purpose; if they do, they become subject to the full biometric identifier statute's possession, destruction, and penalty provisions. The AI exemption does not apply when biometric identifiers are used for the purpose of uniquely identifying a specific individual.
TX
Introduced eff 2025-09-01
Persons who capture biometric identifiers for the commercial purpose of AI training, processing, or storage and who subsequently use those identifiers for a separate commercial purpose must comply with the statute's existing provisions for possession and destruction of biometric identifiers and are subject to the associated penalties.
US
Introduced
Covered entities must limit the collection, processing, use, and storage of age verification information to what is strictly necessary to verify a user's age, obtain verifiable parental consent, or maintain compliance records.
US
Introduced
Providers of covered platforms must not conduct market or product-focused research on users known to be minors unless the research is solely to improve platform privacy, security, transparency, or safety, or is necessary for legal compliance.
US
Introduced
Covered entities must perform ongoing testing and evaluation of privacy risks and privacy-enhancing measures of each automated decision system or augmented critical decision process, including data minimization practices, retention periods, information security measures, use of privacy-enhancing technologies, and current and future impacts on consumer privacy, safety, and security.
US
Introduced
Covered entities must limit the collection, processing, use, and storage of age verification information to what is strictly necessary to verify a user's age, obtain verifiable parental consent, or maintain compliance records.
US
Introduced
Covered entities must (1) limit collection of age-verification personal data to what is minimally necessary, (2) protect such data against unauthorized access using industry-standard encryption, (3) retain the data no longer than reasonably necessary for verification or compliance, and (4) not share, transfer, or sell age-verification data to any other entity.
US
Introduced
Deployers must not process any personal data of a known-minor user to generate, personalize, or otherwise affect an output unless the data was collected during the current session within the maximum permitted period of use to be established by FTC regulation.
US
Introduced
Deployers must not process any personal data of a known-minor user for the purpose of profiling that user.
US
Introduced
Deployers must not process or transfer a known-minor user's personal data for the purpose of training a covered algorithm, except for testing and identifying risks of harm to users or addressing identified risks of harm.
US
Introduced
Deployers must not process any input data provided by a known-minor user for any purpose other than (1) generating outputs within the current session's FTC-established temporal window, (2) testing and identifying risks of harm, or (3) addressing identified risks of harm.
US
Introduced
Covered entities that voluntarily collect personal data for compliance with this Act must not use that data for any other purpose and must not retain it longer than necessary for compliance or to demonstrate compliance.
VA
Introduced
Controllers with actual knowledge or willful disregard that a consumer is an adolescent (ages 13–15) must not process the adolescent's personal data for targeted advertising, sale, or consequential profiling, and must not process it beyond what is reasonably necessary or for undisclosed purposes, without obtaining consent from the adolescent. Precise geolocation collection from adolescents requires necessity, consent, and a visible collection indicator.
VT
Introduced eff 2025-07-01
Employers must not engage in electronic monitoring of employees unless the monitoring serves one of seven enumerated purposes (assisting essential job functions, monitoring production, ensuring legal compliance, protecting health/safety/security, securing property, periodic performance assessment, or tracking time/output for compensation). The specific monitoring form must be necessary and used exclusively for the stated purpose, must be the least invasive means available, must be applied to the smallest number of employees and collect the smallest amount of data no more frequently than necessary, and must be restricted so that only authorized persons access the data and use it only for the noticed purpose and duration.
VT
Introduced eff 2025-07-01
Employers must not require employees to install monitoring applications on personal devices or wear/attach/embed monitoring devices on clothing unless the monitoring is necessary for the employee's essential job function and limited to the times and activities necessary for those functions. Location tracking must be disabled outside essential-job-function activity times. Employers must not under any circumstances require an employee to physically implant a device on the employee's body for monitoring purposes.
VT
Introduced eff 2025-07-01
Employers, any person that develops, operates, or maintains electronic monitoring or an ADS on an employer's behalf, and any person who collects, stores, analyzes, interprets, disseminates, or otherwise uses monitoring or ADS data must implement reasonable security procedures and practices appropriate to the nature of the data to protect employees' personal information from unauthorized or illegal access, destruction, use, modification, or disclosure.
VT
Introduced eff 2025-07-01
Any person that develops, operates, or maintains electronic monitoring or an ADS on an employer's behalf, and any person who collects, stores, analyzes, or uses monitoring or ADS data, must upon termination of the contract with the employer: (1) return all data and ADS outputs to the employer, and (2) destroy all data and ADS outputs in the person's possession.
VT
Introduced eff 2025-07-01
Providers must use reasonable care to avoid any heightened risk of harm to a minor caused by processing of personal data in the course of providing the social media platform to minors, where heightened risk includes unfair or deceptive treatment, financial or physical injury, unintended disclosure, or intrusion upon seclusion.
VT
Introduced eff 2025-07-01
Providers must limit the use of a minor's personal identifying information to the purpose for which the information was collected.
VT
Introduced eff 2026-07-01
Chatbot providers must not process personal data other than input data to inform chatbot outputs unless the processing is necessary to fulfill an express user request and the user has provided affirmative consent.
VT
Introduced eff 2026-07-01
Chatbot providers must not process a known or reasonably known minor user's chat log or personal data without the affirmative consent of that user's parent or legal guardian. Chatbot providers must not process a known or reasonably known minor user's chat log or personal data for training purposes under any circumstances — parental consent does not override this prohibition.
VT
Introduced eff 2026-07-01
Chatbot providers must not process an adult user's chat log or personal data for training purposes unless the provider first obtains the user's affirmative consent.
VT
Introduced eff 2026-07-01
Chatbot providers must not process a user's chat log or personal data for profiling, nor use any personality or behavioral classification derived from profiling, beyond what is necessary to fulfill an express user request.
WA
Introduced eff 2026-07-01
Employers must limit electronic monitoring to five enumerated purposes (assisting essential job functions, monitoring production, ensuring legal compliance, protecting health/safety, or tracking time/output for compensation), and must use the least invasive means with the smallest scope and number of employees necessary, restricting data access to authorized persons for the noticed purpose and duration only.
WA
Introduced eff 2026-07-01
Employers must not require employees to install monitoring applications on personal devices or wear monitoring devices unless the monitoring is necessary for essential job functions and limited to only the times and activities required. Location tracking must be disabled outside of work-activity periods.
WV
Introduced eff 2026-07-01
Entities must develop, implement, and maintain a comprehensive security program to protect consumer genetic data against unauthorized access, use, or disclosure. Entities must also provide consumers with a process to: (1) access their genetic data; (2) delete their genetic data; (3) revoke any consent previously provided; and (4) request and obtain the destruction of their biological sample.
WV
Introduced eff 2026-07-01
Entities must not store genetic data or biological samples of West Virginia residents within the territorial boundaries of any country sanctioned by the United States Office of Foreign Asset Control or designated as a foreign adversary under 15 CFR 7.4(a). Genetic data or biometric data of West Virginia residents may only be transferred or stored outside the United States with the consent of the resident.
WV
Introduced
Private entities in possession of biometric identifiers or biometric information must not sell, lease, trade, or otherwise profit from a person's or customer's biometric identifier or biometric information.
WV
Introduced
Private entities in possession of biometric identifiers or biometric information must not disclose, redisclose, or otherwise disseminate a person's or customer's biometric identifier or biometric information except in four circumstances: (1) the subject or legally authorized representative consents; (2) the disclosure completes a financial transaction requested or authorized by the subject or representative; (3) disclosure is required by state or federal law or municipal ordinance; or (4) disclosure is required by a valid warrant or subpoena.
AK
Failed
State agencies must obtain an individual's consent before soliciting or acquiring sensitive personal data about the individual for use by an AI system making consequential decisions.
AK
Failed
State agencies may not transfer data about an individual to another state agency without the individual's consent, unless required by law.
AK
Failed
State agencies must obtain an individual's consent before soliciting or acquiring sensitive personal data from or about the individual for use in a generative AI system making consequential decisions.
CA
Failed
Employers must not use an ADS to collect worker data for any purpose that was not disclosed in the pre-use notice required under Chapter 2.
CA
Failed
When providing worker data pursuant to this part, employers must anonymize the personal information of customers, other workers, and other individuals contained in or associated with that data.
CO
Failed eff 2026-12-01
Covered businesses must not collect, sell, share, or retain personal data of a covered minor that is not necessary to provide an online gaming service, product, or feature with which the covered minor is actively and knowingly engaged.
CO
Failed eff 2026-12-01
Covered businesses must not use previously collected personal data of a covered minor for any purpose other than the purpose for which it was originally collected, unless the use is necessary to comply with an obligation under Part 19.
FL
Failed
Persons relying on a statutory safe harbor (cost-based pricing differences, opt-in mailing list/payment-method discounts, broadly defined group discounts for teachers/veterans/seniors/students, or affirmative-enrollment loyalty programs) must: (1) clearly and conspicuously disclose the eligibility criteria, available discounts, and earning conditions BEFORE collecting any covered information; (2) offer the discount uniformly to all consumers meeting the disclosed criteria; and (3) use any covered information collected solely to administer the specific discount, cost-based pricing, or loyalty program, and not for profiling, targeted advertising, or individualized price setting.
FL
Failed eff 2026-07-01
AI technology companies must not sell or disclose users' personal information unless the data is deidentified, except where the sale or disclosure is specifically authorized by federal law.
FL
Failed eff 2026-07-01
AI technology companies in possession of deidentified data must (1) take reasonable measures to ensure the data cannot be associated with a user, (2) maintain and use the data in deidentified form and not attempt to reidentify it (except to test their own deidentification processes), (3) contractually require recipients of deidentified data to comply with the same obligations, and (4) implement business processes to prevent inadvertent release.
FL
Failed
AI technology companies must not sell or disclose personal information of users unless the information is deidentified data. Disclosures specifically authorized by federal law are not prohibited.
FL
Failed
AI technology companies in possession of deidentified data must: (1) take reasonable measures to ensure the data cannot be associated with a user; (2) maintain and use the data in deidentified form and not attempt to reidentify it, except solely to test the adequacy of their deidentification processes; (3) contractually obligate any recipient of deidentified data to comply with these same requirements; and (4) implement business processes to prevent inadvertent release of deidentified data. Companies may demonstrate compliance by maintaining a risk management program validated against a recognized framework aligned with the NIST AI RMF and ISO 42001, including controls for deidentification, contractual flow-down, non-reidentification, inadvertent release prevention, monitoring, and auditing.
FL
Failed
Provenance data embedded in synthetic content must not include personal identifying information or any unique device, system, or service information reasonably capable of being associated with a particular user, unless the user directs its inclusion.
MA
Failed
Companies must delete or de-identify any data collected from individuals once it is no longer needed for the intended purpose of the model.
ME
Failed eff 2026-04-29
Deployers must collect and store only user information that does not conflict with the user's safety and well-being. Deployers may not collect or store information except to fulfill a legitimate purpose, and only to the extent the information is (1) relevant to that legitimate purpose and (2) the minimum amount necessary to fulfill it.
MN
Failed
Agencies must conduct facial recognition surveillance under a covered court order in a way that minimizes the acquisition, retention, and dissemination of information about individuals who are not targets of the court order.
MN
Failed
Agencies must conduct all facial recognition surveillance under a covered court order in a manner that minimizes the acquisition, retention, and dissemination of information about individuals other than those for whom there was probable cause.
MT
Failed
Third-party vendors must develop and publish a retention schedule and destruction guidelines for facial biometric data, permanently destroying data when the initial collection purpose is satisfied. Data may be retained beyond this point only with the individual's affirmative authorization, and must be permanently destroyed within one year of the individual's last interaction with the vendor.
MT
Failed
Third-party vendors must not give, sell, lease, or trade an individual's facial biometric data without affirmative authorization from the individual.
NC
Failed
Operators must provide all users with an accessible mechanism to request deletion of personal information, must complete deletion requests unless the data falls within enumerated exceptions (transaction completion, security, debugging, free speech, legal compliance, scientific research, or aligned internal uses), and must maintain a confidential record of all deletion requests.
NC
Failed
Covered platforms must apply the highest privacy settings by default for all users reasonably likely to be children and must implement strict data minimization — limiting collection to what is necessary, deleting data when no longer needed, prohibiting commercial data use unless strictly necessary, honoring minor right-to-be-forgotten requests, prohibiting profiling and behavioral advertising targeting children, providing child-friendly privacy information and controls, mandating transparency about personal data use, restricting geolocation data collection, and imposing data-broker restrictions for children's information.
NC
Failed
Operators must provide all users with an accessible mechanism to request deletion of personal information and must complete the deletion unless the information is reasonably necessary for transaction completion, security, debugging, free speech, regulatory compliance, scientific research, or aligned internal uses. The platform must maintain a confidential record of all deletion requests.
NC
Failed
Covered platforms must collect and store only information that does not conflict with a trusting party's best interests. Information collected must be (i) adequate — sufficient to fulfill a legitimate purpose of the platform; (ii) relevant — having a relevant link to that legitimate purpose; and (iii) necessary — the minimum amount of information needed for that legitimate purpose.
NC
Failed
Covered platforms must be loyal gatekeepers of personal information from trusting parties, including avoiding conflicts to the best interests of trusting parties when allowing government or other third-party access to trusting parties and their data.
NC
Failed
Covered platforms must ensure that all user-related data collected through conversations between users and chatbots or through third-party cookies undergoes a process of de-identification prior to storage and analysis.
NC
Failed
Covered platforms must collect and store only information that does not conflict with a trusting party's best interests, and such information must be adequate (sufficient for a legitimate purpose), relevant (linked to that purpose), and necessary (the minimum needed for that purpose).
NC
Failed
Covered platforms must act as loyal gatekeepers of trusting parties' personal information, avoiding conflicts with trusting parties' best interests when allowing government or other third-party access to their data.
NC
Failed
Covered platforms must de-identify all user-related data collected through chatbot conversations or third-party cookies prior to storage and analysis.
NC
Failed
Covered platforms must take reasonable care to prohibit the incorporation of any sensitive personal information derived from chatbot use into aggregate datasets used to train any chatbot or generative AI system.
NE
Failed eff 2026-04-17
Covered online services must collect and use only the minimum amount of a covered minor's personal data necessary to provide the specific service elements the minor has knowingly engaged with, and must not use that data for purposes other than those for which it was collected.
NE
Failed eff 2026-04-17
Covered online services must retain a covered minor's personal data only as long as necessary to provide the specific service elements the minor has knowingly engaged with.
NE
Failed eff 2026-04-17
Covered online services must not profile a covered minor unless profiling is necessary to provide a service the minor has requested, and only with respect to the aspects of the service the minor is actively and knowingly engaged with.
NE
Failed eff 2028-01-01
Covered platforms must collect and store only information that does not conflict with the trusting party's best interests and that is relevant and necessary to fulfilling the platform's legitimate purpose.
NE
Failed eff 2028-01-01
Covered platforms must avoid conflicts with the best interests of trusting parties when allowing government or other third-party access to trusting party data.
NE
Failed
Entities must not disclose an individual's biometric data except with the individual's written consent, when required by law, pursuant to a court warrant or subpoena, in a criminal proceeding, or in a civil enforcement action under this act.
NH
Failed
Covered businesses must not collect, sell, share, or retain any personal data of a covered minor that is not necessary to provide the online service, product, or feature with which the minor is actively and knowingly engaged, and must not repurpose previously collected personal data of a covered minor for any purpose other than the original collection purpose.
NJ
Failed
Business entities must not sell, lease, trade, share, or otherwise profit from information obtained through the use of a biometric surveillance system on a consumer.
NV
Failed eff 2026-01-01
Insurers must not use health data collected about an insured to train an AI system developed by the insurer without first providing a clear and conspicuous disclosure that health data may be used for AI training and obtaining the insured's affirmative, voluntary consent.
NY
Failed
Persons developing automated systems must protect New York residents from inappropriate or irrelevant data use in the design, development, and deployment of those systems, and from the compounded harm of data reuse.
NY
Failed
Designers, developers, and deployers must build privacy protections into automated systems by default, ensure data collection conforms to reasonable expectations, and collect only strictly necessary data for the specific context.
NY
Failed
Employers must not use an electronic monitoring tool to collect employee data unless the tool is primarily intended for an enumerated permissible purpose (essential job functions, quality assurance, performance assessment, legal compliance, health/safety, or wage administration), is strictly necessary and exclusively used for that purpose, is the least invasive means available, and is limited to the smallest number of workers and least amount of data necessary.
NY
Failed
Employers must destroy employee data collected via electronic monitoring when the initial collection purpose has been satisfied or when the employment relationship ends, unless the employee provides written and informed consent to continued retention.
NY
Failed
Employers must not use employee data collected via electronic monitoring for any purpose other than those specified in the prior written notice provided to employees.
NY
Failed
Sensitive employee data collected for bias audits must be collected, processed, stored, and retained in a manner that protects employee privacy. Audit data must not be shared with the employer and must not be shared with any other entity unless strictly necessary for audit completion.
NY
Failed
Employers must limit use of electronic monitoring tools to seven enumerated purposes and must ensure the specific tool is strictly necessary, exclusively used for that purpose, the least invasive means available, limited to the smallest number of workers, and that data is collected no more frequently than necessary and deleted once the purpose is achieved.
NY
Failed
Employers must not use employee data collected via electronic monitoring for any purpose other than those specified in the notice provided to employees.
NY
Failed
Employers must not sell, transfer, or disclose employee data collected via electronic monitoring to any other entity unless required by state or federal law or necessary to comply with an AEDT impact assessment under § 1012.
NY
Failed
Employee data collected for impact assessments must be collected, processed, stored, and retained in a manner protecting employee privacy and in compliance with commissioner-specified security requirements. Data provided to auditors must not be shared with the employer or any other entity unless strictly necessary for the impact assessment.
NY
Failed
Employers may use electronic monitoring tools to collect employee data only if the tool serves one of seven enumerated purposes, is strictly necessary and the least invasive means to accomplish that purpose, and is limited to the smallest number of workers and least amount of data necessary.
NY
Failed
Employers must destroy employee data collected via electronic monitoring when the initial collection purpose has been satisfied or when the employment relationship ends, unless the employee provides written and informed consent to continued retention.
NY
Failed
Employers must not use employee data collected via electronic monitoring for any purpose other than those specified in the prior written notice provided to employees.
NY
Failed
Employers must not sell, transfer, or disclose employee data collected via electronic monitoring to any other entity, unless required by state or federal law or necessary to comply with an AEDT bias audit.
NY
Failed
Sensitive employee data collected for a bias audit must be collected, processed, stored, and retained in a manner that protects employee privacy. Audit data must not be shared with the employer and must not be disclosed to any person or entity unless strictly necessary for the bias audit.
NY
Failed
Persons developing automated systems must ensure that only appropriate and relevant data is used in the design, development, and deployment of those systems, and must prevent compounded harm from data reuse.
NY
Failed
Persons developing automated systems must implement privacy protections by default, ensure data collection conforms to reasonable expectations, and collect only strictly necessary data for the specific context.
RI
Failed
Companies must delete or de-identify any data collected from individuals when it is no longer needed for the intended purpose of the model.
TX
Failed
Controllers must establish, implement, and maintain reasonable administrative, technical, and physical data security practices appropriate to the volume and nature of data collected, stored, and processed by AI systems.
TX
Failed
Employers must not share an applicant's AEDT assessment with any person other than those whose knowledge and skill are necessary to ensure the tool is correctly processing the applicant's data.
TX
Failed
Employers must, within 30 days of using an AEDT to assess an applicant, (1) make all reasonable efforts to destroy hard copies and erase electronic data files of the assessment, and (2) instruct any person with whom the assessment was shared to do the same. Recipients must comply as soon as practicable.
US
Failed
Covered entities must perform ongoing testing and evaluation of privacy risks and privacy-enhancing measures, including documenting data minimization practices, information security measures (including privacy-enhancing technologies), data retention duration, and current and potential impacts on consumer privacy, safety, and security.
US
Failed
Covered entities must perform ongoing testing and evaluation of privacy risks and privacy-enhancing measures, including assessing data minimization practices, information security measures, privacy-enhancing technologies used, and current and potential impacts on consumer privacy, safety, and security.
US
Failed
Each agency must include a reference to any associated AI governance charter in its Privacy Act system of records notices for systems trained on, using, or producing individual records, and must establish policies ensuring the security, confidentiality, and integrity of records that federal AI systems use, produce, or modify.
US
Failed
Covered entities must perform ongoing testing and evaluation of the privacy risks and privacy-enhancing measures of each automated decision system or augmented critical decision process, including assessing data minimization practices, data retention duration, information security measures, privacy-enhancing technologies used, and current and potential impacts on consumer privacy, safety, and security.
US
Failed
Covered entities must perform ongoing testing and evaluation of privacy risks and privacy-enhancing measures, including data minimization practices, data retention duration, information security measures (e.g., differential privacy, de-identification), and current and potential future impacts on consumer privacy, safety, and security.
VA
Failed
State agencies must ensure that staff who handle personal data collected by the automated decision system and the storage of such data do so in accordance with federal and state law and all agency data agreements and privacy policies.
VA
Failed
Local government entities must ensure that staff who handle personal data collected by the automated decision system and the storage of such data do so in accordance with federal and state law and all entity data agreements and privacy policies.
VA
Failed
Deployers must collect and store only information that does not conflict with the user's best interests. Information collected must be (i) adequate — sufficient to fulfill a legitimate purpose; (ii) relevant — having a relevant link to that legitimate purpose; and (iii) necessary — the minimum amount needed for that legitimate purpose.
WI
Failed eff 2027-01-01
Covered businesses must not collect, sell, share, or retain any personal data of a covered minor that is not necessary to provide an online service, product, or feature with which the minor is actively and knowingly engaged.
WI
Failed eff 2027-01-01
Covered businesses must not use previously collected personal data of a covered minor for any purpose other than the purpose for which the data was originally collected, unless necessary to comply with an obligation under this section.
WI
Failed eff 2026-03-23
Social media platforms must not gather, use, sell, offer, or retain data relating to a minor's use of or interaction with the platform, except data necessary to establish and maintain the minor's account or to comply with the section's requirements.
WI
Failed eff 2027-01-01
Covered businesses must not collect, sell, share, or retain any personal data of a covered minor that is not necessary to provide the online service, product, or feature with which the covered minor is actively and knowingly engaged.
WI
Failed eff 2027-01-01
Covered businesses must not use previously collected personal data of a covered minor for any purpose other than the purpose for which it was originally collected, unless necessary to comply with this section.