Recent Bills
- H.R. 10171August 27, 2026
- H.R. 10156August 27, 2026
- H.R. 10172August 27, 2026
- H.R. 10160August 27, 2026
- H.R. 10181August 27, 2026
- H.R. 10176August 27, 2026
- H.Res. 1496August 27, 2026
- H.R. 10164August 27, 2026
- H.R. 10170August 27, 2026
- H.Res. 1494August 27, 2026
- H.R. 10163August 27, 2026
- H.R. 10157August 27, 2026
Committees
- AdministrationU.S. House
- AgricultureU.S. House
- Agriculture, Nutrition, And ForestryU.S. House
- AppropriationsU.S. House
- Armed ServicesU.S. House
- Banking, Housing, And Urban AffairsU.S. House
- BudgetU.S. House
- Commerce, Science, And TransportationU.S. House
- Education and WorkforceU.S. House
- Energy And CommerceU.S. House
- Energy And Natural ResourcesU.S. House
- Environment And Public WorksU.S. House
- EthicsU.S. House
- FinanceU.S. House
- Financial ServicesU.S. House
- Foreign AffairsU.S. House
- Foreign RelationsU.S. House
- Health, Education, Labor, And PensionsU.S. House
- Homeland SecurityU.S. House
- Homeland Security And Governmental Affa…U.S. House
- Indian AffairsU.S. House
- Indian and Insular AffairsU.S. House
- IntelligenceU.S. House
- JudiciaryU.S. House
- Natural ResourcesU.S. House
- Oversight And Government ReformU.S. House
- Permanent Select IntelligenceU.S. House
- RulesU.S. House
- Rules And AdministrationU.S. House
- Science, Space, And TechnologyU.S. House
- Select IntelligenceU.S. Senate
- Small BusinessU.S. House
- Small Business And EntrepreneurshipU.S. House
- Subcommittee on AviationU.S. House
- Subcommittee on Border Security and Enf…U.S. House
- Subcommittee on Coast Guard and Maritim…U.S. House
- Subcommittee on Commodity Markets, Digi…U.S. House
- Subcommittee on Conservation, Research,…U.S. House
- Subcommittee on Counterterrorism and In…U.S. House
- Subcommittee on Cybersecurity and Infra…U.S. House
- Subcommittee on Disability Assistance a…U.S. House
- Subcommittee on Economic Development, P…U.S. House
- Subcommittee on Economic OpportunityU.S. House
- Subcommittee on Emergency Management an…U.S. House
- Subcommittee on Energy and Mineral Reso…U.S. House
- Subcommittee on Federal LandsU.S. House
- Subcommittee on Forestry and Horticultu…U.S. House
- Subcommittee on General Farm Commoditie…U.S. House
- Subcommittee on HealthU.S. House
- Subcommittee on Highways and TransitU.S. House
- Subcommittee on Livestock, Dairy, and P…U.S. House
- Subcommittee on Nutrition and Foreign A…U.S. House
- Subcommittee on Oversight and Investiga…U.S. House
- Subcommittee on Oversight, Investigatio…U.S. House
- Subcommittee on Railroads, Pipelines, a…U.S. House
- Subcommittee on Transportation and Mari…U.S. House
- Subcommittee on Water Resources and Env…U.S. House
- Subcommittee on Water, Wildlife and Fis…U.S. House
- Transportation And InfrastructureU.S. House
- Veterans' AffairsU.S. House
- Ways And MeansU.S. House

SB 1790
Arizona Senate•Introduced
Summary
SB 1790, “Personal data collection; business; requirements”, was introduced in the Senate on Feb 9, 2026 by Sen. Lauren Kuby (D) with 3 co-sponsors. It was referred to Regulatory Affairs and Government Efficiency, and last saw action on Feb 10, 2026: Senate read second time.
Record
Text
SB 1790 has 3 co-sponsors.
sb1790/introduced.txtREFERENCE TITLE: personal data collection; business; requirementsState of ArizonaSenateFifty-seventh LegislatureSecond Regular Session2026SB 1790Introduced bySenatorsKuby: Hatathlie;� Representatives Garcia, M�rquezANACTamending title 44, Arizona RevisedStatutes, by adding chapter 42; relating to commerce.(TEXT OF BILL BEGINS ON NEXT PAGE)Be it enacted by the Legislature of the State of Arizona:Section 1. Title 44, Arizona Revised Statutes,is amended by adding chapter 42, to read:CHAPTER 42DATA BROKERSARTICLE 1. GENERAL PROVISIONSSTART_STATUTE44-8041. DefinitionsIn this chapter, unless the context otherwiserequires:1. "Biometric data" meansdata generated by automatic measurements of an individual's biological patternsor characteristics, including fingerprint, voiceprint, retina or iris scan,information pertaining to an individual's Deoxyribonucleic acid or other uniquebiological pattern or characteristic that is used to identify a specificindividual.2. "Child" means anindividual who is less than sixteen years of age.3. "Collect" in the contextof data, means to obtain, receive, access or otherwise acquire the data by anymeans, including by purchasing or renting the data.4. "Data broker" means abusiness entity that collects, processes or transfers personal data that thebusiness entity did not collect directly from the individual who is linked orlinkable to the data.5. "Deidentified data"means data that cannot reasonably be linked to an identified or identifiableindividual or to a device linked to that individual.6. "Employee":(a) Includes anindividual who is a director, officer, staff member, trainee, volunteer orintern of an employer or an individual who is working as an independentcontractor for an employer, regardless of whether the individual is paid,unpaid or employed on a temporary basis.(b) Does notinclude an individual contractor who is a service provider.7. "Employee data" meansinformation collected, processed or transferred by an employer if theinformation is related to any of the following:(a) A jobapplicant and is collected during the course of the hiring and applicationprocess and is collected, processed or transferred solely relating to thestatus of the employee as a current or former job applicant of the employer.(b) An employeewho is acting in a professional capacity for the employer, including theemployee's business contact information such as the employee's name, position,title, business telephone number, business address or business email address,and is collected, processed or transferred solely relating to the professionalactivities of the employee on behalf of the employer.(c) Anemployee's emergency contact information and is collected, processed ortransferred solely for the purpose of having an emergency contact on file forthe purpose of transferring the information in case of an emergency.(d) An employeeor the employee's spouse, dependent, covered family member or beneficiary andis collected, processed or transferred solely for The purpose of administeringbenefits to which the employee described is entitled or to which another persondescribed by this subdivision is entitled on the basis of the employee'sposition with the employer.8. "Genetic data":(a) Means anydata, regardless of format, concerning an individual's genetic characteristics.(b) Includesboth:(i) Rawsequence data derived from sequencing all or a portion of an individual'sextracted DNA.(ii) Genotypicand phenotypic information obtained from analyzing an individual's raw sequencedata.9. "Individual" means anatural person who resides in this state.10. "known child" means achild under circumstances in which a data broker has knowledge of, or wilfullydisregards obtaining knowledge of, or should know, or reasonably should haVEknown of, the child's age.11."Personal data":(a) Means anyinformation, including sensitive data, that is linked or reasonably linkable toan identified or identifiable individual.(b) Includespseudonymous data if the information is used by a controller or processor inconjunction with additional information that reasonably links the informationto an identified or identifiable individual.(c) Does notinclude deidentified data, employee data or publicly available information.12. "Precise geolocationdata":(a) Meansinformation accessed on a device or technology that shows the past or presentphysical location of an individual or the individual's device with sufficientprecision to identify ground level location information of the individual or devicein a range of not more than one thousand eight hundred fifty feet.(b) Does notinclude location information regarding an individual or device that isidentifiable or derived solely from the visual content of a legally obtainedimage, including the location of a device that captured the image.13. "Process" in thecontext of data, means an operation or set of operations that are performed,whether by manual or automated means, on personal data or on sets of personaldata, such as the collection, use, storage, disclosure, analysis, deletion ormodification of personal data.14. "Publicly availableinformation" means information that is any of the following:(a) Is lawfullymade available through government records.(b) a businesshas a reasonable basis to believe is lawfully available to the general publicthrough widely distributed media.(c) Is lawfullymade available by a consumer, or by a person to whom a consumer has disclosedthe information, unless the consumer has restricted access to the informationfor a specific audience.15. "Sensitive data" means:(a) agovernment-issued identifier that is not required by law to be publiclyavailable, including:(i) a socialsecurity number.(ii) a passportnumber.(iii) a driverlicense number.(b) informationthat describes or reveals an individual's mental or physical health diagnosis,condition or treatment.(c) Anindividual's financial information, except the last four digits of a debit orcredit card number, including:(i) a financialaccount number.(ii) a creditor debit card number.(iii) Informationthat describes or reveals the income level or bank account balances of theindividual.(iv) transactionhistory.(v) electronicpayment numbers or histories.(vi) accountsrelated to digital payment networks.(vii) mobilepayment SERVICES or similar types of services or networks.(viii) paymentof health care services or related debt collection.(d) Biometricdata.(e) Geneticdata.(f) Precisegeolocation data.(g) Anindividual's private communication that:(i) If madeusing a device, the device is not provided by the individual's employer anddoes not provide conspicuous notice to the individual that the employer mayaccess communication made using the device.(ii) Includes,unless the data broker is the sender or an intended recipient of thecommunication, any form of messages sent from a communication system and theindividual's voicemails, emails, texts, direct messages or mail, informationthat identifies the parties involved in the communications and information thatrelates to the transmission of the communications, including telephone numberscalled, telephone numbers from which calls are placed, the time calls are made,call duration and location information of the parties to the call.(h) a log-incredential, security code or access code for an account or device.(i) informationidentifying the sexual behavior of the individual.(j) Calendarinformation, address book information, phone or text logs, photos, audio recordingsor videos that both:(i) Aremaintained for private use by an individual and stored on the individual'sdevice or in another location.(ii) are notcommunicated using a device provided by the individual's employer. This itemdoes not apply if the employee communicates on a device provided by theemployer and the employer notifies the employee that the employer may accesscommunication made using the device.(k) aphotograph, film, video recording or other similar medium that shows theindividual or a part of the individual nude or wearing undergarments.(l) informationrevealing the video content requested or selected by an individual.(m) Informationregarding a known child.(n) Informationrevealing an individual's racial or ethnic origin, color, sex, gender,citizenship, immigration status, religious beliefs or union membership.(o) Informationidentifying an individual's online activities accessing multiple Internetwebsites or online services.(p) Informationcollected, processed or transferred for the purpose of identifying informationdescribed by this paragraph.16. "Service provider"means a person that is bound by contractual obligations or an agreementreceives, collects, processes or transfers personal data on behalf of and onlyat the direction of a business or governmental entity, including a business orgovernmental entity that is another service provider, so the person may performa service or function with or on behalf of the business or governmental entityand to the extent a person processes personal data for the person's own purposes,the person is not acting as a service provider.17. "Transfer" means todisclose, release, share, disseminate, make available, sell or license data byany means or medium. END_STATUTESTART_STATUTE44-8042. Applicability to dataA. Except as provided in Subsection bof this section, this chapter applies to personal data that is collected,transferred or processed from an individual by a data broker.b. This chapter does not apply to thefollowing data:1. Deidentified data, if the databroker:(a) Takesreasonable technical measures to ensure that the data is not able to be used toidentify an individual with whom the data is associated.(b) Publiclycommits in a clear and conspicuous manner to both:(i) Process andtransfer the data solely in a deidentified form without any reasonable meansfor reidentification.(ii) Notattempt to identify the information to an individual with whom the data isassociated.(c) Contractuallyobligates a person that receives the information from the provider to both:(i) Comply withthis paragraph with respect to the information.(ii) Requirethat the contractual obligations be included in any subsequent transfer of thedata to another person.2. Employee data.3. Publicly available information.4. Inferences made exclusively frommultiple independent sources of publicly available information that do notreveal sensitive data with respect to an individual. END_STATUTESTART_STATUTE44-8043. Applicability to entitiesA. Except as provided in Subsection bof this section, this chapter applies only to a data broker that, in atwelve-month period, makes either:1. More than fifty percent of thedata broker's revenue directly from processing or transferring personal datathat is not collected by the data broker directly from the individuals to whomthe data pertains.2. Revenue directly from processingor transferring the personal data of more than fifty thousand individuals ifthe data broker does not collect the data directly from the individuals to whomthe data pertains.B. This chapter does not apply to:1. A service provider, including aservice provider that engages in the business of processing employee data foran employer for the sole purpose of providing benefits to the employer'semployees.2. A federal, state, tribal,territorial or local governmental entity, including a body, authority, board,bureau, commission, district, agency or political subdivision of a governmentalentity.3. An entity that serves as acongressionally designated nonprofit, national resource center or clearinghouseto provide assistance to victims, families, child-serving professionals and thegeneral public on missing and exploited children issues.4. A consumer reporting agency orother person that furnishes information for inclusion in a consumer creditreport or obtains a consumer credit report, but only to the extent that theconsumer reporting agency or the person engages in activity regulated orauthorized by the Fair Credit Reporting Act (15 United States Code Sections1681 through 1681x), including the collection,maintenance, disclosure, sale, communication or use of any personal informationbearing on a consumer's creditworthiness, credit standing, credit capacity,character, general reputation, personal characteristics or mode of living.END_STATUTESTART_STATUTE44-8044. Notice on website or mobile applicationA data broker that maintains an Internet websiteor mobile application shall post a conspicuous notice on the website orapplication that:1. States that the entity maintainingthe website or application is a data broker.2. Is clear, not misleading andreadily accessible by the general public, including individuals with adisability.3. Contains language as prescribed bythe secretary of state in rule for inclusion in the notice.4. Informs a consumer how to exerciseany consumer rights the consumer may have under this chapter, which is KNOWN ASthe arizona consumer data protection act, or Chapter 10, article 7 of thistitle. END_STATUTESTART_STATUTE44-8045. Registration; fees; renewalA. To conduct business in this state,a data broker must register with the secretary of state by filing aregistration statement and paying a registration fee in an amount to bedetermined by the secretary of state.b. The registration statement mustinclude:1. The legal name of the data broker.2. A contact person and the primaryphysical address, email address, telephone number and website address for thedata broker.3. A description of the categories ofdata that the data broker processes and transfers.4. A statement of whether the databroker implements a purchaser credentialing process.5. If the data broker has knowledge,should have knowledge or reasonably should have knowledge, that the data brokerpossesses sensitive data, including personal data of a known child:(a) A statementdetailing the data collection practices, databases, sales activities and optout policies that are applicable to the personal data.(b) A statementon how the data broker complies with applicable federal and state lawsregarding the collection, use or disclosure of sensitive data, includingpersonal data from and about a child on the Internet.6. The number of security breachesthe data broker has experienced during the year immediately preceding the yearin which the registration is filed, and if known, the total number of consumersaffected by each breach.C. A registration of a data brokermay include any additional information or explanation the data broker choosesto provide to the secretary of state concerning the data broker's datacollection practices.D. A registration certificate expireson the first anniversary of the registration certificate's date of issuance.� Adata broker may renew a registration certificate by filing a renewalapplication, in the form prescribed by the secretary of state, and paying arenewal fee in an amount determined by the secretary of state. END_STATUTESTART_STATUTE44-8046. Registry of data brokersThe secretary of state shall establish andmaintain on the secretary of state's website a searchable, central registry ofdata brokers registered under Section 44-8045.� The registry mustinclude:1. A search feature that allows aperson that is searching the registry to identify a specific data broker.2. For each data broker, theinformation prescribed in Section 44-8045, subsection b. END_STATUTESTART_STATUTE44-8047. Protection of personal dataA. A data broker that is conductingbusiness in this state shall protect personal data that the data broker holds.b. A data broker shall develop,implement and maintain a comprehensive information security plan that iswritten in one or more readily accessible parts and contains administrative,technical and physical safeguards that are appropriate for all of thefollowing:1. the data broker's size, scope andtype of business.2. the amount of resources availableto the data broker.3. the amount of data stored by thedata broker.4. the need for security andconfidentiality of personal data stored by the data broker.c. The comprehensive informationsecurity plan required by this section must:1. Incorporate safeguards that areconsistent with the safeguards for protection of personal data and informationof a similar character under state or federal laws applicable to the databroker.2. include the designation of one ormore employees of the data broker to maintain the plan.3. require the identification andassessment of reasonably foreseeable internal and external risks to thesecurity, confidentiality and integrity of any electronic, paper or otherrecord containing personal data and the establishment of a process forevaluating and improving, as necessary, the effectiveness of the currentsafeguards for limiting those risks, including by:(a) requiringongoing employee and contractor education and training, including education andtraining for temporary employees and contractors of the data broker, on theproper use of security procedures and protocols and the importance of personaldata security.(b) mandatingemployee compliance with policies and procedures established under the plan.(c) providing ameans for detecting and preventing security system failures.4. include security policies for thedata broker's employees relating to the storage, access and transportation ofrecords containing personal data outside of the broker's physical businesspremises.5. provide disciplinary measures forviolations of a policy or procedure established under the plan.6. include measures for preventing aterminated employee from accessing records containing personal data.7. provide policies for thesupervision of third-party service providers that include:(a) takingreasonable steps to select and retain third-party service providers that arecapable of maintaining appropriate security measures to protect personal dataconsistent with applicable law.(b) requiringthird-party service providers by contract to implement and maintain appropriatesecurity and privacy measures for personal data.8. provide reasonable restrictions onphysical access to records containing personal data, including by requiring therecords containing the data to be stored in a locked facility, storage area orcontainer.9. include regular monitoring toensure that the plan is operating in a manner reasonably calculated to preventunauthorized access to or unauthorized use of personal data and, as necessary,upgrading information safeguards to limit the risk of unauthorized access to orunauthorized use of personal data.10. require the regular review of thescope of the plan's security measures that must occur both:(a) at leastannually.(b) wheneverthere is a material change in the data broker's business practices that mayreasonably affect the security and privacy or integrity of records containingpersonal data.11. require the documentation ofresponsive actions taken in connection with any incident involving a breach ofsecurity, including a mandatory post-incident review of each event and theactions taken, if any, to make changes in business practices relating toprotection of personal data in response to that event.12. to the extent technicallyfeasible, include the following procedures and protocols with respect tocomputer system security requirements or procedures and protocols providing ahigher degree of security for the protection of personal data:(a) the use ofsecure user authentication protocols that include each of the followingfeatures:(i) controllinguser login credentials and other identifiers.(ii) using areasonably secure method of assigning and selecting passwords or using uniqueidentifier technologies, including biometrics or token devices.(iii) controllingdata security passwords to ensure that the passwords are kept in a location andformat that do not compromise the security of the data that the passwordsprotect.(iv) restrictingaccess to only active users and active user accounts.(v) blockingaccess to user credentials or identification after multiple unsuccessfulattempts to gain access.(b) the use ofsecure access control measures, including:(i) restrictingaccess to records and files containing personal data to only employees orcontractors who need access to that personal data to perform the job duties ofthe employees or contractors.(ii) assigningto each employee or contractor who has access to a computer containing personaldata a unique identification and a password that may not be a vendor-supplieddefault password or using another protocol reasonably designed to maintain theintegrity of the security of the access controls to personal data.(c) encryptionof:(i) transmittedrecords and files containing personal data that travels across public networks.(ii) datacontaining personal data that is transmitted wirelessly.(d) reasonablemonitoring of systems for unauthorized use of or access to personal data.(e) encryptionof all personal data stored on laptop computers or other portable devices.(f) for filescontaining personal data on a system that is connected to the Internet, the useof reasonably current firewall protection and operating system security patchesthat are reasonably designed to maintain the integrity of the personal data.(g) the use ofeither:(i) areasonably current version of system security agent software that must includemalware protection and reasonably current patches and virus definitions.(ii) a versionof system security agent software that is supportable with current patches andvirus definitions and is set to receive the most current security updates on aregular basis. END_STATUTESTART_STATUTE44-8048. Violation; civil penalty; attorney general actionA. Adata broker that violates Section 44-8044 or 44-8045 is subject to a civilpenalty as follows:1. $100for each day that the violation continues.2. An amount equal to the amount ofunpaid registration fees for each year that the entity fails to register inviolation of Section 44-8045.3. An amount not to exceed $10,000 ina twelve-month period.B. The attorney general may bring anaction to recover a civil penalty imposed under this section.� The attorneygeneral may recover reasonable attorney fees and court costs incurred inbringing the action. END_STATUTESTART_STATUTE44-8049. Unfair trade practiceA violation of Section 44-8047 constitutes anunfair trade practice pursuant to section 44-1522. END_STATUTESTART_STATUTE44-8050. RulemakingTHe secretary of state may adopt rules pursuantto title 41, chapter 6 to carry out this chapter. END_STATUTESec. 2. Short titleThis act may be cited as the"Arizona Consumer Data Protection Act".
Personal data collection; business; requirements
Sponsors
Sen. Lauren Kuby (D) sponsors SB 1790, and 3 members have co-sponsored it.
Committees
SB 1790 went before 2 committees: Regulatory Affairs and Government Efficiency and Rules.
Regulatory Affairs and Government Efficiency

Regulatory Affairs and Government Efficiency
Referred to · Feb 9, 2026
History
SB 1790 has taken 4 actions since Feb 9, 2026, the latest on Feb 10, 2026.
| Chamber | Action | |||
|---|---|---|---|---|
Feb 10, 2026 | Senate | Senate read second time | ||
Feb 9, 2026 | Senate | Introduced in Senate and read first time | ||
Feb 9, 2026 | Senate | Assigned to Senate RAGE Committee | ||
Feb 9, 2026 | Senate | Assigned to Senate RULES Committee |
Votes
SB 1790 has not gone to a roll call.
Source: apps.azleg.gov · legiscan.com