Tuesday, May 30, 2023

FYI: Montana Enacts Comprehensive Consumer Data Privacy Law

Montana Gov. Greg Gianforte recently signed into law the Montana Consumer Data Privacy Act, making Montana the ninth state to enact a comprehensive consumer data privacy law, following California, Virginia, Colorado, Utah, Connecticut, Iowa, Indiana, and Tennessee.

 

The new Montana law will take effect Oct. 1, 2024.

 

APPLICABILITY

 

The law applies to persons that conduct business in Montana or persons that produce products or services that are "targeted" to residents of Montana and:

 

- control or process the personal data of not less than 50,000 consumers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction; or

- control or process the personal data of not less than 25,000 consumers and derive more than 25% of gross revenue from the sale of personal data.

 

EXEMPTIONS

 

Importantly, the law exempts financial institutions and affiliates, or personal data subject to the Gramm-Leach-Bliley Act. Other exemptions include covered entities or business associates governed by the Health Insurance Portability and Accountability Act, and the use of personal information to the extent the activity is regulated by and authorized under the Fair Credit Reporting Act.

 

CONSUMER RIGHTS

 

Consumers are provided the right to:

 

- confirm whether a controller is processing the consumer's personal data and to access the personal data;

- correct inaccuracies in the consumer's personal data;

- delete personal data about the consumer;

- obtain a copy of the consumer's personal data previously provided by the consumer;

- opt out of the processing of personal data if the purpose is for targeted advertising, sale of the personal data, or profiling in furtherance of solely automated decisions that produce legal or similarly significant effects concerning the consumer.

 

SENSITIVE DATA

 

A controller may not process "sensitive data" without a consumer's consent.

 

"Sensitive data" includes:

 

- data revealing racial or ethnic origin, religious beliefs, a mental or physical health condition or diagnosis, information about a person's sex life, sexual orientation, or citizenship or immigration status;

- the processing of genetic or biometric data for the purpose of uniquely identifying an individual;

- personal data collected from a known child; or

- precise geolocation data.

 

CONTRACT REQUIREMENTS

 

A contract between a controller and a processor must include certain provisions to:

 

- ensure that each person processing personal data is subject to a duty of confidentiality with respect to the personal data;

- at the controller's direction, delete or return all personal data to the controller as requested;

- on the reasonable request of the controller, make available to the controller all information in the processor's possession necessary to demonstrate the processor's compliance;

- engage any subcontractor pursuant to a written contract that requires the subcontractor to meet the obligations of the processor with respect to the personal data; and

- allow and cooperate with reasonable assessments by the controller or the controller's designated assessor.

 

DATA PROTECTION ASSESSMENTS

 

A controller must conduct and document a data protection assessment if the processing involves:

 

- targeted advertising;

- the sale of personal data;

- certain profiling;

- sensitive data.

 

ENFORCEMENT

 

The Attorney General has the exclusive authority to enforce the law. Prior to taking any action, the Attorney General must provide a controller or processor 60 days to cure the violation. In the absence of a cure, civil penalties not to exceed $7,500 may be sought for each violation. The cure provision expires April 1, 2026.

 

IMPRESSION

 

The Montana law is very similar to the non-California data privacy laws recently enacted, so it should cause few additional compliance challenges.

 

For a chart comparing the state comprehensive data privacy acts, and more information and insight from Maurice Wutscher on data privacy and security laws and legislation, please click here.

 

 

 

Ralph T. Wutscher
Maurice Wutscher LLP
The Loop Center Building
105 W. Madison Street, 6th Floor
Chicago, Illinois 60602
Direct:  (312) 551-9320
Fax: (312) 284-4751

Mobile:  (312) 493-0874
Email: rwutscher@MauriceWutscher.com

 

Admitted to practice law in Illinois

 

 

 

Alabama   |   California   |   Florida   |   Illinois   |   Massachusetts   |   New Jersey   |   New York   |   Ohio   |   Pennsylvania   |   Tennessee   |   Texas   |   Washington, DC

 

 

NOTICE: We do not send unsolicited emails. If you received this email in error, or if you wish to be removed from our update distribution list, please simply reply to this email and state your intention. Thank you.


Our updates and webinar presentations are available on the internet, in searchable format, at:

 

Financial Services Law Updates

 

and

 

The Consumer Financial Services Blog

 

and

 

Webinars