Blog

Washington state passes broad health data bill

Julie Rubash, Chief Privacy Counsel
April 11, 2023

Want to receive these weekly privacy recaps in your inbox? Sign up for our privacy newsletter, A Little Privacy, Please.

EUROPE


ICO Fines TikTok for UK GDPR Violations

The UK Information Commissioner’s Office (ICO) announced a 12.7 pound million fine based on allegations that TikTok used children’s data without parental consent, failed to carry out adequate checks to identify and remove underage children from its platform, and failed to provide easy-to-understand information about how user data was collected, used and shared. 

CONTEXT

The UK Age Appropriate Design Code, which went into effect in September 2021, sets out specific protections for children’s personal data in compliance with the provisions of the UK GDPR.

According to the ICO’s explanation of the Code “if you don’t conform to the standards in this code, you are likely to find it more difficult to demonstrate that your processing is fair and complies with the GDPR and PECR.”

Of particular relevance for this case, the code standards require that covered companies “either establish age with a level of certainty that is appropriate to the risks to the the rights and freedoms of children that arise from your data processing, or apply the standards in this code to all your users instead.”  

UNITED STATES

Washington State Passes Broad Health Data Bill

HB1155, a bill addressing the collection, sharing, and selling of consumer health data, has passed both the Washington House and (with amendments) the Senate.

If the amendments are approved by the House, and the bill is signed by the Governor, the My Health My Data Act will go into effect March 31, 2024. 

TAKEAWAY

Among other requirements, the law would require consent (specific to each purpose) for the collection or sharing of “Consumer health data”, which is broadly defined to include not only information that directly identifies a consumer’s physical or mental health, but also information derived or extrapolated from nonhealth information, including from algorithms or machine learning.    

Texas Passes Comprehensive Privacy Bill Through One Chamber

The Texas House passed HB4, a bill largely resembling the Virginia Consumer Data Protection Act. The bill will now move to the Senate for consideration.

TAKEAWAY

This is the seventh state to pass comprehensive privacy legislation through one chamber in 2023, with only one state so far this year, Iowa, signing such a bill into law. 

Want more of the privacy highlights that matter to adtech and martech? Sign up for our privacy newsletter, A Little Privacy, Please.

A Little Privacy, Please weekly recaps are provided for general, informational purposes only, do not constitute legal advice, and should not be relied upon for legal decision-making. Please consult an attorney to determine how legal updates may impact you or your business.

Latest Blog Posts

FTC and Sensitive Location Data; New Pen Register Class Actions

December 9, 2024

FTC takes action against the sale of sensitive data...

California CPPA Issues Notice of Proposed Rulemaking

November 25, 2024

News out of California this week. The CPPA moved...

Mitigating risk under the Video Privacy Protection Act (VPPA)

November 23, 2024

Because VPPA is just one of many tools being...

Latest White Papers

E-book: Enterprise Guide To Cookie management & Tracker List Curation

July 1, 2024

How to review the tracking tech on your websites...

Benchmark Report: US Privacy Compliance

August 19, 2022

The current state of publisher compliance with CCPA, and...

Keep in touch

Sign up for our newsletter to keep up with privacy news for adtech and martech,
plus occasional company news.

Let's explore what we can do together.

We'll be in touch within 48 hours

[contact-form-7 id="593" title="Schedule a Demo"]