Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Consumer Data Privacy topic
No spam. Unsubscribe anytime.
Senate Institutions continues walkthrough of S.71 consumer data privacy bill
Summary
Legislative counsel Rick Sagal reviewed duties for controllers and processors under S.71, highlighting limits on collection, rules for minors’ data, required privacy notices, opt-out mechanisms and processor contracts; committee paused for floor session.
Get email alerts on the Consumer Data Privacy topic
No spam. Unsubscribe anytime.
The Senate Institutions Committee continued its line-by-line review Friday of S.71, “An act relating to consumer data privacy and online surveillance,” focusing on duties the draft law would impose on data controllers and processors.
The committee’s legislative counsel, Rick Sagal of the Office of Legislative Counsel, told members the bill would require controllers to “limit collections and processing of personal data” to what is reasonably necessary to provide a requested product or service, to maintain appropriate security practices, and to delete data according to a retention schedule when it is no longer necessary or when law requires removal.
Sagal said the bill would bar controllers from processing sensitive data except where “strictly necessary” to provide a requested product or service and would prohibit the sale of sensitive data. He also highlighted provisions aimed at minors: a controller that knows or “should have known” a consumer is a minor must take extra care to avoid high risk of harm, must give a conspicuous signal before collecting precise geolocation data from a minor, and may not process a minor’s personal data for targeted advertising or sell a minor’s personal data.
The draft defines “knows or should have known” by reference to information the controller has collected or inferred about age. Sagal noted the bill stops short of imposing a mandatory age‑verification requirement, saying courts have found states cannot compel affirmative age verification in some contexts.
Sagal reviewed notice and opt‑out requirements that would be required in a controller’s privacy notice. Among other items, the notice must describe, in a clear and conspicuous way, any processing used for targeted advertising, any sales of personal data to third parties, and any profiling that produces legally or similarly significant effects — and must provide a procedure by which a consumer may opt out of that processing. The bill would require controllers to post the privacy notice via a conspicuous hyperlink using the word “privacy” or “surveillance,” or to use another conspicuous medium if the controller does not operate a website.
On opt‑out mechanics Sagal said the bill allows a consumer or authorized agent to send a signal to a controller indicating a preference to opt out of sales or targeted advertising; the controller must honor that signal and must consider reasonable methods (including IP‑based estimates of residence) to authenticate residence for certain requests. If a consumer‑level opt‑out conflicts with a controller‑specific setting, the bill would require the controller to comply with the opt‑out while notifying the consumer of the conflict.
Sagal also described duties for processors: processing must follow a contract that specifies instructions, the nature and purpose of processing, types of data, confidentiality obligations, deletion or return of data at controller direction, and cooperation with the controller’s assessments. The bill would permit a controller, its designee, or an independent qualified party to assess a processor’s technical and organizational measures; processors that act in a way that determines purpose or means of processing could be treated as controllers for liability purposes.
Sagal noted the bill includes a data‑protection assessment requirement, a feature not present in every U.S. state privacy law, and cited New Jersey as an example of recent legislation that included such assessments. Committee members deferred further discussion because the chamber had to reconvene on the floor; the committee agreed to resume after the floor session and not to extend past the announced return time.
The hearing included questions from committee members about accessibility of notices, how to define an “average consumer” for usability tests, and whether the bill’s privacy notice and opt‑out mechanisms would be practicable for smaller entities. No formal votes or committee actions were taken during the portion of the session covered in the transcript.
Looking ahead, Sagal told members the committee would return to finish discussion of the remaining sections, including data protection assessments and enforcement provisions referenced elsewhere in the draft.

