SB 364 updates Michigan's criminal procedure code to clarify jurisdiction rules for prosecuting identity theft cases. It specifies that identity theft violations under the Identity Theft Protection Act (2004 PA 452) and related laws can be prosecuted in three locations: where the crime occurred, where stolen data was used, or where the victim lives. The bill also ensures that if multiple identity theft violations are charged, any jurisdiction can handle all charges together, preventing fragmented prosecutions. This change directly affects prosecutors and courts handling identity theft cases under the listed statutes.
Senate Bill 360 amends Michigan's existing Identity Theft Protection Act. The bill revises and expands several key definitions, including what constitutes a "breach of the security of a database" and various types of "personal information" and "personal identifying information." These updates clarify the scope of protected data and the circumstances under which a security breach occurs, directly affecting Michigan residents and entities that handle their personal information. Additionally, the bill introduces new sections and repeals others, indicating a comprehensive update to the act's provisions.
SB 549 amends Michigan's Insurance Code to strengthen data security requirements for insurers handling personal information. It requires insurers to notify Michigan residents if their unencrypted personal data (like Social Security numbers or financial account details) was accessed by unauthorized parties, or if encrypted data was accessed with the encryption key. The law also mandates that insurers notify data owners if a breach affects information they own but the insurer maintains. These notifications must be provided without unreasonable delay after determining the breach could cause substantial harm or identity theft. The bill directly affects Michigan residents whose data is held by insurers and the insurers themselves, who must now follow specific breach notification protocols.
Senate Bill 284, the "digital age assurance act," aims to protect minors by regulating online content and requiring age verification. It mandates that device manufacturers, operating systems, and app stores estimate a user's age and provide a digital age signal to websites and online services. Websites and applications that offer mature content must then use these signals to block access for individuals under 18 or provide disclaimers and parental supervision tools. The bill also requires application stores to obtain parental consent for users under 16 to download apps and offers options for parental supervision tools. The Michigan Department of the Attorney General is responsible for enforcing this act.
SB 359 creates Michigan's "Personal Data Privacy Act," giving residents (consumers) new rights over their personal data collected by businesses. It requires companies to clearly disclose data practices, implement a universal "opt-out" for data sharing, and register as data brokers if selling consumer information. The law specifically prohibits deceptive practices like "dark patterns" and protects sensitive data including health information (such as gender-affirming or reproductive care) and precise location data. Businesses must follow new standards for handling data, with civil penalties for violations.
HB 4263 prohibits sellers from using automated programs to bypass purchase limits during online ticket sales for concerts, sports events, and other public entertainment events requiring admission fees. It bans circumventing security systems that enforce ticket limits, electronic queues, or fraud checks, targeting practices like bot-driven bulk purchases. The law directly affects ticket sellers (who must implement these security measures) and buyers attempting to use automated tools to bypass restrictions. This creates new requirements for online ticket sales to ensure fair access to event tickets.
HB 4429, the "Digital Age Assurance Act," requires device makers, operating systems, and app stores to verify user age and restrict access to mature content (sexually explicit material defined under federal law) for minors. It mandates that companies block mature content for users under 18, obtain parental consent for users under 16 before app downloads, and provide parental control tools for managing minors' online activity. Online services must also block mature content when they know a user is under 18 and display disclaimers for non-mature content. The Attorney General enforces the law, allowing 45 days to fix violations before imposing civil penalties up to $10,000 per violation.
SB 198, the "Motor Vehicle Dealer Data Collection Act," regulates how auto dealers, manufacturers, and third-party vendors collect, share, and use sensitive customer and business data. It requires dealers to obtain specific written consent before sharing "protected dealer data" (including consumer personal/financial information, vehicle diagnostics, and business operations data) with vendors or integrators, and prohibits cyber ransom demands to unlock this data. The law specifically excludes publicly available data and data required for manufacturer transactions (like safety recalls or vehicle sales). It directly affects auto dealers, their data vendors, and authorized integrators by imposing new consent rules and security standards for handling customer information.