Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Data Privacy topic
No spam. Unsubscribe anytime.
Committee debates whether 'derived data' should be covered in S71 privacy draft
Summary
Members of the House Commerce & Economic Development committee pressed staff on whether algorithmically ‘derived’ information should be treated as consumer-owned personal data, raising concerns about correction, deletion burdens, and the limits of business compliance under S71.
Get email alerts on the Data Privacy topic
No spam. Unsubscribe anytime.
The House Committee on Commerce & Economic Development continued its review of a data-privacy draft (S71) on May 14, examining whether algorithmically derived information should be defined and protected as a consumer’s personal data.
Rick Seagel of the Office of Legislative Council walked the committee through the draft’s definition: “Data created by the derivation of information, assumptions, correlations, inferences, predictions, or conclusions from facts, evidence, or another source of information or data about a consumer's device,” Seagel said, describing how the draft treats derived outputs as part of the broader category of personal data.
Committee members repeatedly questioned whether that language implies consumer ownership or control over derived data, and whether the statute as written would require businesses to trace algorithmic outputs. One member asked bluntly who “owns derived data” and whether consumers would have a realistic path to correct or delete algorithmic inferences. Seagel and other members said the draft’s definition signals that derived outputs are treated as personal data for protection purposes but noted that the text does not presently create an explicit ownership regime.
Tony, a committee member who offered a mental model for the group, said he thinks of three tiers: necessary transactional data that typically requires no consent; personal data where consent is expected; and sensitive data that should trigger a higher consent threshold. “There’s necessary data to complete the transaction… personal data which you should … need consent for and then sensitive data which I think should be a higher bar of consent,” he said.
Other members raised practical concerns. A committee member challenged the premise that insurers currently use this kind of inferred data to underwrite policies and said, “if you don't want that to happen, then we should make a law to prevent that from happening.” The committee also heard that requiring businesses to reconstruct the provenance of algorithmic outputs could be infeasible; instead, staff suggested firms might be required only to delete data responsive to consumer requests rather than fully trace derivations.
Why this matters: Derived inferences can produce consequential outcomes (for example, inferred health risks or socioeconomic status) and members noted the potential for real-world harms if sloppy or biased derivations are used in automated decisions. The debate centers on how to balance consumer protections against technical and operational burdens on businesses.
The committee did not adopt a final position at the session and staff pointed members to publicly available redline drafts and prior versions (including Senate-passed S71 and related bills H208 and S93) for further comparison; the draft will return for additional review. The committee also signaled it will take time to clarify whether rules for correction, deletion, and the scope of obligations should differ for derived outputs compared with other personal data.

