Florida governor Ron DeSantis signed the Digital Bill of Rights into law on June 6, 2023, joining the wave of US states with comprehensive state privacy laws.
Which businesses does this law apply to?
The law applies to "controllers" which are defined as companies that sell to customers in the state of Florida, make in excess of $1 billion in global annual revenue and:
- Derive 50% or more of its revenue from targeted advertising worldwide
- Operate a consumer smart speaker and voice component service with an integrated virtual assistant connected to the cloud
- Operate an app store that offers at least 250,000 different software applications for consumers to download
What are the key highlights of the law?
Let’s take a look at how the Florida Digital Bill of Rights defines consent, sensitive data, the “sale” of personal data, consumer rights, and data protection impact assessments.
Consent
Florida’s law defines consent as a “clear affirmative act signifying a consumer’s freely given, specific, informed, and unambiguous agreement to allow the processing of personal data”, similar to most other state laws.
It explicitly mentions that the following methods of obtaining consent are not considered valid:
- Accepting a broad terms of use document that includes personal data processing along with other unrelated information
- Performing an action that is not clear and unambiguous, i.e. hovering over, pausing, closing, or muting any piece of content
- Agreements via dark patterns
Sensitive Personal Information (SPI)
SPI under Florida’s latest act includes the following categories of personal data:
- Racial or ethnic origin
- Religious beliefs
- Health data (mental and physical)
- Sexual orientation
- Citizenship status
- Genetic / Biometric data
- Children’s data
- Geolocation
Florida’s Act requires businesses to have consent in place in order to process sensitive data, via a separate opt-out mechanism. In the case of children between the ages of 13 and 18, an affirmative authorization needs to take place, i.e. an opt-in mechanism.
Consumer Rights
The Florida Digital Bill of Rights lays out the following consumer rights:
- Right to access – Consumers are entitled to verify and access their data that is under processing by the data controller
- Right to correction – Consumers have the right to rectify any inaccuracies in their personal data
- Right to deletion – Consumers have the right to delete any personal data that relates to them
- Right to portability – Consumers have the right to obtain a copy of their data, in a portable format that is “readily usable”, allowing them to transfer this data to another controller without any issues
- Right to opt out of targeted advertising, behavioral profiling, and the sale of personal data
- Right to opt out of data collection via voice recognition features
Regarding rights request responses, controllers have a 45-day timeline to respond to any consumer requests – this can be extended for an extra 15 days if deemed “reasonably necessary”. In the case of an extension, controllers still need to inform consumers that the response deadline has been pushed out.
Controllers are also required to answer requests at least twice a year from consumers, free of charge. The law states that if these requests are found to be “unfounded, excessive, or repetitive” then businesses can charge a “reasonable fee” in order to process these requests.
Sale of Personal Data
The Florida Technology Transparency Act defines the sale of personal data as, “the sharing, disclosing, or transferring of personal data for monetary or other valuable consideration by controller to a third party”.
There are some caveats with this definition. It does not include the following:
- Information disclosed to a processor who processes data on the controller’s behalf
- Information disclosed to a third-party for providing a product/service to the consumer
- Information disclosed as a part to a third-party as part of a merger or an acquisition
- Information that the consumer has intentionally made available to the general public
Data Retention Schedules
Data controllers and processors are required to define retention schedules for the personal data that is collected or processed based on the nature and purpose of data collection. If no retention schedule is defined, then personal data must be deleted 2 years after the last customer interaction with the business.
Privacy Notices and Disclosures
The law states that privacy notices must be updated on an annual basis and be “reasonably accessible and clear”. This notice must include the following:
- The categories of personal data being processed (including any sensitive data)
- The purpose of processing this personal data
- The mechanism for customers to exercise their rights (including the appeal process)
- The categories of personal data being shared with third parties
- The categories of third parties that personal data is being shared with
- A clear, separate section in the notice that calls out the sale of sensitive data, including biometric data, if the controller is involved in the sale of this information
- The process for which customers can opt out of targeted advertising and profiling
Data Protection Assessments (DPA)
Florida’s law requires data controllers to conduct DPAs in the following cases:
- If data is being processed for targeted advertising
- If personal data is being sold
- If sensitive data is being processed
- If processing personal data has a “reasonable and foreseeable risk” of
- Treating customers unfairly, or engaging in deceptive practices
- Any sort of injury to customers including financial, physical, or reputational
- Any sort of intrusion on a customer’s privacy, to the extent that it would be considered “offensive to a reasonable person”
The law further states that these assessments must identify and weigh the benefits against the potential risks of the current data workflows with all stakeholders – the controller, processor, consumer, and other parties involved.
What does this mean for your organization?
Florida’s Digital Bill of Rights is currently set to go into effect on July 1, 2024. This means organizations that fall under its purview have less than a year to ensure that the appropriate compliance measures are in place across your data infrastructure and workflows.
How can OneTrust help with compliance?
OneTrust can help your organization introduce the right business workflows and data policies that help keep you compliant with all applicable privacy regulations. For more information on what you can do to stay on top of the US privacy landscape, take a look at how to operationalize privacy compliance, with OneTrust Privacy Management. Request a demo to see what works for your business today.