An act relating to data brokers and personal information
What changed between versions
The definition of 'biometric data' differs between versions: one uses the standard 'can be used to identify an individual' while the other requires the data to be 'linked or reasonably linkable to an individual.' The latter is a narrower, more specific standard that could exclude certain biometric data from the law's coverage.
The definition of 'business' differs: one version explicitly includes 'controller, consumer health data controller, processor, or a commercial entity' while the other limits it to 'a commercial entity.' The broader version would extend the law's obligations to entities acting in data protection roles (controllers and processors) even if they are not traditional commercial entities.
Penalties for failure to register as a data broker differ significantly: one version imposes a $50 per day civil penalty capped at $10,000 per year, while the other imposes a $200 per day administrative fine with no stated annual cap. The latter also adds separate penalties for incomplete registration ($1,000 per day after 30 days) and materially incorrect information ($25,000 flat penalty plus $1,000 per day if uncorrected).
The passed version explicitly states the act takes effect on July 1, 2025. The enacted version's effective date is not shown in the visible portion of the diff.
The enacted version corrects typographical errors present in the passed version: 'e-mail email' is corrected to 'e-mail' and 'Internet internet' is corrected to 'Internet.'
Document formatting differs substantially: the enacted version uses chapter number 'No. 138' with a 41-page layout, while the passed version uses bill number 'H.211' with an 80-page layout including line numbering and repeated page headers.