Exempts certain personal information and entities from certain requirements concerning notification and disclosure of personal data.*
What changed between versions
The bill's title and scope changed from exempting only 'insurance-support organizations' to covering 'privacy and disclosure requirements for certain entities and certain personal data,' reflecting a much broader set of exemptions.
A new exemption was added for information treated like protected health information (PHI) collected, used, or disclosed by a HIPAA covered entity or business associate when used in accordance with HIPAA and afforded all federal privacy protections and security safeguards.
A new exemption was added for human subjects research conducted in accordance with good clinical practice guidelines issued by the International Council for Harmonisation of Technical Requirements for Pharmaceuticals for Human Use (ICH).
A new exemption was added for a national securities association registered under section 15A of the Securities Exchange Act of 1934 (such as FINRA) and any rules or regulations promulgated thereunder.
An entirely new Section 2 was added that amends P.L.2023, c.266 to insert approximately 25 new definitions into the consumer privacy law, including: affiliate, biometric data, child, consent, consumer, controller, COPPA, dark pattern, decisions that produce legal or similarly significant effects, de-identified data, designated request address, personal data, precise geolocation data, process/processing, processor, profiling, publicly available information, sale, sensitive data, targeted advertising, third party, trade secret, and verified request.
The effective date provision was renumbered from Section 2 to Section 3 to accommodate the new definitions section inserted as Section 2.