Recent Bills
- H.R. 10171August 27, 2026
- H.R. 10156August 27, 2026
- H.R. 10172August 27, 2026
- H.R. 10160August 27, 2026
- H.R. 10181August 27, 2026
- H.R. 10176August 27, 2026
- H.Res. 1496August 27, 2026
- H.R. 10164August 27, 2026
- H.R. 10170August 27, 2026
- H.Res. 1494August 27, 2026
- H.R. 10163August 27, 2026
- H.R. 10157August 27, 2026
Committees
- AdministrationU.S. House
- AgricultureU.S. House
- Agriculture, Nutrition, And ForestryU.S. House
- AppropriationsU.S. House
- Armed ServicesU.S. House
- Banking, Housing, And Urban AffairsU.S. House
- BudgetU.S. House
- Commerce, Science, And TransportationU.S. House
- Education and WorkforceU.S. House
- Energy And CommerceU.S. House
- Energy And Natural ResourcesU.S. House
- Environment And Public WorksU.S. House
- EthicsU.S. House
- FinanceU.S. House
- Financial ServicesU.S. House
- Foreign AffairsU.S. House
- Foreign RelationsU.S. House
- Health, Education, Labor, And PensionsU.S. House
- Homeland SecurityU.S. House
- Homeland Security And Governmental Affa…U.S. House
- Indian AffairsU.S. House
- Indian and Insular AffairsU.S. House
- IntelligenceU.S. House
- JudiciaryU.S. House
- Natural ResourcesU.S. House
- Oversight And Government ReformU.S. House
- Permanent Select IntelligenceU.S. House
- RulesU.S. House
- Rules And AdministrationU.S. House
- Science, Space, And TechnologyU.S. House
- Select IntelligenceU.S. Senate
- Small BusinessU.S. House
- Small Business And EntrepreneurshipU.S. House
- Subcommittee on AviationU.S. House
- Subcommittee on Border Security and Enf…U.S. House
- Subcommittee on Coast Guard and Maritim…U.S. House
- Subcommittee on Commodity Markets, Digi…U.S. House
- Subcommittee on Conservation, Research,…U.S. House
- Subcommittee on Counterterrorism and In…U.S. House
- Subcommittee on Cybersecurity and Infra…U.S. House
- Subcommittee on Disability Assistance a…U.S. House
- Subcommittee on Economic Development, P…U.S. House
- Subcommittee on Economic OpportunityU.S. House
- Subcommittee on Emergency Management an…U.S. House
- Subcommittee on Energy and Mineral Reso…U.S. House
- Subcommittee on Federal LandsU.S. House
- Subcommittee on Forestry and Horticultu…U.S. House
- Subcommittee on General Farm Commoditie…U.S. House
- Subcommittee on HealthU.S. House
- Subcommittee on Highways and TransitU.S. House
- Subcommittee on Livestock, Dairy, and P…U.S. House
- Subcommittee on Nutrition and Foreign A…U.S. House
- Subcommittee on Oversight and Investiga…U.S. House
- Subcommittee on Oversight, Investigatio…U.S. House
- Subcommittee on Railroads, Pipelines, a…U.S. House
- Subcommittee on Transportation and Mari…U.S. House
- Subcommittee on Water Resources and Env…U.S. House
- Subcommittee on Water, Wildlife and Fis…U.S. House
- Transportation And InfrastructureU.S. House
- Veterans' AffairsU.S. House
- Ways And MeansU.S. House

SB 1815
Arizona Senate•Introduced
Summary
SB 1815, “Personal data; consumers; controllers; requirements”, was introduced in the Senate on Feb 9, 2026 by Sen. Lauren Kuby (D). It was referred to Regulatory Affairs and Government Efficiency, and last saw action on Feb 10, 2026: Senate read second time.
Record
Text
SB 1815 has no co-sponsors and has not gone to a roll call.
sb1815/introduced.txtREFERENCE TITLE: personal data; consumers; controllers; requirementsState of ArizonaSenateFifty-seventh LegislatureSecond Regular Session2026SB 1815Introduced bySenatorKubyANACTamending title 44, chapter 9, arizonarevised statutes, by adding article 27; relating to consumer data.(TEXT OF BILL BEGINS ON NEXT PAGE)Be it enacted by the Legislature of the State of Arizona:Section 1. Title 44, chapter 9, Arizona RevisedStatutes, is amended by adding article 27, to read:ARTICLE 27. consumer DATASTART_STATUTE44-1383. DefinitionsIn this article, unless the context otherwiserequires:1. "Affiliate" means alegal entity that controls, is controlled by or is under common control withanother legal entity or that shares common branding with another legal entity.�For the purposes of this paragraph, "control" or"controlled" includes any of the following:(a) Theownership of, or power to vote, more than fifty percent of the outstandingshares of any class of voting security of a company.(b) The controlin any manner over the election of a majority of the directors or of anindividual who exercises a similar function.(c) The powerto exercise controlling influence over the management of a company.2. "Artificial intelligencesystem":(a) Means anymachine-based system that, for any explicit or implicit objective, infersfrom the inputs the system receives how to generate outputs.(b) Includescontent, decisions, predictions or recommendations that can influence PHYSICALor virtual environments.3. "Authenticate" means toverify through reasonable means that the consumer who is authorized to file aconsumer request under section 44-1383.01 is the same consumer withrespect to the personal data.�4. "Biometric data":(a) Means datagenerated by automatic measurements of an individual's biologicalcharacteristics.�(b) Includesany of the following:(i) Afingerprint.(ii) Avoiceprint.(iii) An eyeretinal or iris scan.(iv) Any otherunique biological pattern or characteristic that is used to identify a specificindividual.�(c) Does notinclude any of the following:(i) A physicalor digital photograph or Data generated from a physical or digital photograph.(ii) A video oraudio recording or data generated from a video or audio recording.(iii) Anyinformation collected related to health care treatment or payment pursuant tothe health INSURANCE PORTABILITY and accountability act of 1996 (P.L. 104-191;110 Stat. 1936).5. "Child" means anindividual who is under sixteen years of age.6. "Consumer":(a) Means an individual who resides in this state.(b) Does not include an individual who is acting on behalf ofa business or as an employee.7. "Consumer consent":(a) Means aclear, affirmative act that signifies a consumer's freely given, specific,informed and unambiguous agreement to process personal data that relates to theconsumer.(b) Includes awritten or electronic statement.(c) Does notinclude:(i) Acceptanceof general or broad terms or an acceptance of a document that uses general orbroad terms and that contains descriptions of personal data processing alongwith other unrelated information.(ii) Acceptanceby hovering over, muting, pausing or closing a given piece of content.(iii) Anagreement that was obtained through the use of dark patterns.8. "Controller" means anindividual or person that individually or in concert with other individuals orpersons determines the purpose and means of processing personal data.9. "Dark patterns":(a) Means auser interface designed or manipulated with the effect of substantiallysubverting or impairing user autonomy, decision-making or choice.(b) Includesdigital design choices that:(i) Make itdifficult for a consumer to opt out.(ii) Manipulateor trick a consumer into actions that a consumer would otherwise not take.(iii) Coerce aconsumer to give up data privacy.10. "Deidentified data"means data that cannot reasonably be linked to an identified or identifiableindividual or a device linked to that individual.11. "Health care provider"has the meaning prescribed by the health insurance portability andaccountability act of 1996 (42 United States Code sec 1320d).12. "Health record":(a) Means anywritten, printed or electronically recorded material maintained by a healthcare provider in the course of providing health care services to an individualthat concerns the individual and the services provided.(b) Includeseither of the following:(i) Thesubstance of any communication made by an individual to a health care providerin confidence during or in connection with the provision of health careservices.(ii) Informationotherwise acquired by a health care provider about an individual in confidenceand in connection with health care services provided to the individual.13. "Identified or identifiableindividual" means a consumer who can be readily identified, directly orindirectly.14. "Institution of highereducation" means a community college as defined in section 15-1401or a UNIVERSITY under the jurisdiction of the Arizona board of regents.15. "known child" means achild under circumstances in which a controller has knowledge of the child'sage and wilfully disregards the child's age.16. "Personal data":(a) means anyinformation, including sensitive data, that is linked or reasonably linkable toan identified or identifiable individual.�(b) Includespseudonymous data when the data is used by a controller or processor inconjunction with additional information that reasonably links the data toidentified data or publicly available information or data.17. "Precise geolocationdata":(a) Meansinformation derived from technology that includes latitude and longitudecoordinates or other mechanisms and that directly identifies a specificlocation of an individual within a radius of one thousand seven hundred fiftyfeet.(b) Does notinclude the content of COMMUNICATIONS or any data generated by or connected toan advanced utility metering infrastructure system or equipment used by autility.18. "process" or"processing" means an operation or set of operations performed eithermanually or by automated means on personal data for the collection, use,storage, disclosure, analysis, deletion or modification of personal data.19. "Processor" means aperson that processes personal data on behalf of a controller.20. "profiling" meansprocessing personal data to evaluate, analyze or predict personal aspects thatare related to an identified or identifiable individual's economic situation,health, personal preferences, interests, reliability, behavior, location ormovements.21. "Protected healthinformation" has the meaning prescribed by the health insuranceportability and accountability act of 1996 (42 United States Code sec 1320d).22. "pseudonymous data"means any information that cannot be attributed to a specific individualwithout the use of additional information, provided that the additionalinformation is kept separately and is subject to appropriate technical andorganizational measures to ensure that the personal data is not attributed toan identified or identifiable individual.23. "publicly availableinformation":(a) Means anyinformation that a business has a reasonable basis to believe was lawfully madeavailable to the public through widely distributed media by a consumer or by aperson to whom the consumer has disclosed the information unless the consumerhas restricted the information to a specific audience.(b) Includespublic records as defined in section 41-161.24. "Sale of personaldata":(a) Meanssharing, disclosing or transferring personal data for monetary or othervaluable consideration by a controller to a third party.(b) Does notinclude any of the following:(i) Thedisclosure of personal data to a processor that processes personal data on thecontroller's behalf.(ii) Thedisclosure of personal data to a third party to provide a product or servicethat was requested by a consumer.(iii) Thedisclosure of information that the consumer intentionally made available to thegeneral public through a mass media channel and that the consumer did notrestrict to a specific audience.(iv) Thedisclosure or transfer of personal data to a third party as an asset that ispart of a merger or acquisition.25. "Sensitive data":(a) Means acategory of personal data.(b) Includesany of the following:(i) Personaldata that reveals an individual's race or ethnic origin, religion, mental orphysical health status, gender or citizenship or immigration status.(ii) Genetic orbiometric data that is processed for the purpose of uniquely identifying anindividual.(iii) Personaldata collected from a known child.(iv) Precisegeolocation data.26. "Targeted advertising":(a) Meansdisplaying an advertisement to a consumer based on personal data obtained fromthe consumer's activities across nonaffiliated websites or online applicationsto predict a consumer's preferences or interests.(b) Does notinclude an advertisement that:(i) Is based onactivities within a controller's own websites or online applications.(ii) Is basedon the context of a consumer's current search query, visit to a website oronline application.(iii) Isdirected to a consumer in response to the consumer's request for information orfeedback.(iv) Is basedon the processing of personal data solely for measuring or reportingADVERTISing performance, reach or frequency.27. "Third party" means aperson other than the consumer, the controller, the processor or an affiliateof the controller or processor.END_STATUTESTART_STATUTE44-1383.01. Consumer requests; controller responsibilities and response;personal data collectionA. A consumer may submit a consumerrequest to a controller for any of the following reasons:�1. To confirm whether a controller isprocessing a consumer's personal data and to allow the consumer to access thepersonal data.2. To correct inaccuracies in aconsumer's personal data, taking into account the nature of the personal dataand the purposes of the processing of the consumer's personal data.3. To delete personal data providedby the consumer or obtained about the consumer.4. If the data is available in adigital format, to obtain a copy of the consumer's personal DATA in a PORTABLEformat that the consumer previously provided to the controller.� To the extenttechnically feasible, the personal data must be in a usable format that allowsthe consumer to transmit the data to another controller without hindrance.5. To opt out of the controller'sprocessing or use of personal data for the purposes of:(a) Targetedadvertising.(b) The sale ofpersonal data.(c) Profilingin furtherance of a decision that produces a legal or similarly significanteffect concerning the consumer or the consumer's legal rights.B. A controller may authenticate theconsumer request by verifying the individual who made the request throughreasonable commercial means.� A consumer may request that ONLY that consumer'sconsumer data or personal data be removed and may not make a request foranother consumer unless authorized as an agent on behalf of the otherconsumer.� A parent or legal guardian may submit a request on behalf of a childunder eighteen years of age.� The controller shall comply with an authenticatedconsumer request within a reasonable time pursuant to section 44-1383.04.C. If a controller is unable toauthenticate the request by using commercially reasonable means, the controlleris not required to comply with the consumer request and may request that theconsumer provide additional information that is reasonably necessary to verifythe identity of the consumer.D. a controller shall comply with aconsumer request without undue delay and not later than forty-five daysafter receiving a consumer request. The controller may extend the responseperiod once by an additional forty-five days based on reasonablenecessity, taking into consideration the complexity and number of consumerrequests the controller has to process.� The controller shall inform theconsumer of the time extension within the initial forty-five-dayresponse period and the reason for the extension.E. If a controller declines to takeaction regarding the consumer's request, the controller shall inform theconsumer without undue delay and not later than forty-five days afterreceiving the consumer request of the reasons for declining to take action andprovide instructions on how to appeal the decision pursuant to section 44-1383.02.F. A controller shall provideinformation in response to a consumer's request free of charge, at least twiceannually per consumer.� If a request from a consumer is manifestly unfounded,excessive or repetitive, the controller may charge the consumer a reasonablefee to cover the administrative costs for complying with the request or maydecline to act on the request.� The controller has the burden of showing thatthe request is manifestly unfounded, excessive or repetitive.G. If a controller has obtainedpersonal data about a consumer from a source other than the consumer and thecontroller receives a consumer request to delete the consumer's personal data,the controller shall delete the personal data and shall:1. Retain a record of the consumerrequest to delete the personal data.2. Retain the minimum amount of datathat is necessary to ensure that the consumer's personal data remains deletedfrom the business's records and shall not use the retained data for any otherpurposes.3. Opt out the consumer from anyprocessing of personal data for any purpose other than a purpose that is exemptunder this section.END_STATUTESTART_STATUTE44-1383.02. Consumer appeal process; controller requirementsA. A controller shall establish aprocess for a consumer to appeal the controller's decision to refuse to takeaction or about a prolonged delay, a denial of or an inability to AUTHENTICATEa consumer request.B. The appeals process must beconspicuously available and similar to the process for submitting a consumerrequest pursuant to section 44-1383.01.�C. A controller shall inform theconsumer in writing of any action taken or not taken in response to an appealnot later than SIXTY calendar days after receiving the appeal AND shall includea written explanation of the reason or reasons for the controller's decision.D. If a controller denies an appeal,the controller shall provide the consumer with information, including onlineinformation that explains HOW the consumer may contact the attorney general'soffice to submit a consumer fraud complaint as prescribed in chapter 10,article 7 of this title.END_STATUTESTART_STATUTE44-1383.03. Consumer contract; waiver prohibitionBeginning on January 1, 2027, any contract oramendment to a contract that waives or limits a consumer right provided underthis article is contrary to public policy and is void and unenforceable. END_STATUTESTART_STATUTE44-1383.04. Consumer requests; submissionA. A controller shall establish twoor more secure and reliable methods to allow consumers to exercise theirconsumer rights under this article.� The methods shall take into considerationall of the following:1. The manner in which consumersnormally interact with the controller.2. The necessity for secure andreliable communications of those requests.3. The ability of the controller toauthenticate the identity of the consumer making the request.B. A controller may not require aconsumer to create a new account to exercise consumer rights under this article, but may require aconsumer to use an existing account.C. Except as provided in subsection Dof this section, if a controller maintains a website, the controller shallprovide a mechanism on the website for consumers to submit consumer requests.�D. A controller that operatesexclusively online andthat has a direct relationship with the consumer from whom the controllercollects personal information is required to provide only an email address forthe submission of consumer requests.E. A consumer may designate anotherperson to serve as the consumer's authorized agent and act on the consumer'sbehalf to opt out of processing the consumer's personal data.� A consumer maydesignate an authorized agent by using a technology, including a link to aninternet website, an internet browser setting or extension or a global settingon an electronic device, that allows the consumer to indicate the consumer'sintent to opt out of the processing.� The controller shall provide a consumeror the authorized agent of the consumer with technology, links to an internetwebsite, internet browser settings or a global setting on an electronic devicethat would allow a consumer to opt out of processing personal data.� Acontroller shall comply with an opt out request that is received fromtechnologies acting as a consumer's authorized agent and that indicate theintent to opt out of processing of the consumer's personal data under thisarticle.� A controller is not required to verify a request to opt out throughan authorized agent, technology or a tool on the controller's website. END_STATUTESTART_STATUTE44-1383.05. Controller duties; consumer dataA. A controller shall:1. Limit the collection of personaldata to what is relevant and reasonably necessary in relation to the purposesfor which the personal data is processed as disclosed in a privacy notice madeavailable to the consumer at the time of collection.2. Protect the confidentiality,integrity and access to personal data by establishing, implementing andmaintaining reasonable administrative, technical and physical data securitypractices that are appropriate to the volume and nature of the controller's useof personal data.B. A controller may not:1. Except as otherwise provided inthis article, process personal data for a purpose that is not reasonablynecessary or compatible with the disclosed purpose for which the personal datais collected, as disclosed to the consumer in a privacy notice, unless thecontroller obtains consumer consent after providing the consumer a notice ofthe new purpose of collecting and processing the personal data.�2. Process personal data in violationof state or federal laws that prohibit unlawful discrimination againstconsumers.3. Discriminate against a consumerwho exercises any of the consumer rights contained in this article by doing anyof the following:(a) denyinggoods or services.(b) Chargingdifferent prices or rates for goods or services.(c) Providinggoods or services at a different level of quality.4. Process sensitive data of aconsumer without obtaining the consumer's consent or process the sensitive dataof a known child in violation of the children's online privacy protection actof 1998 (P.L. 105-277; 112 Stat. 2681; 15 united states code section6501).C. Subsection B, paragraph 3 of thissection may not be construed to require a controller to provide a product orservice that requires the personal data of a consumer that the controller doesnot collect or maintain or to prohibit a controller from offering a differentprice, rate, level, quality or selection of goods or services to a consumer,including offering goods or services for no fee, if the consumer has exercisedthe consumer's right to opt out under this article or the offer is related to aconsumer's voluntary participation in a bona fide loyalty, rewards, premiumfeatures, discounts or club card program. END_STATUTESTART_STATUTE44-1383.06. Privacy noticeA. A controller shall provide eachconsumer with a reasonably accessible and clearly written privacy notice thatincludes:1. The categories of personal datacollected and processed by the controller, including, if applicable, anysensitive data processed by the controller.2. The purposes for collecting andprocessing personal data.3. How the consumer may exercisetheir consumer right to opt out of personal data collection and processing andfile a consumer request to remove personal data pursuant to section 44-1383.01that includes the process by which a consumer may appeal a controller'sdecision pursuant to section 44-1383.02.4. If applicable, the categories ofpersonal data that the controller shares with third parties.5. If applicable, the categories ofthird parties with whom the controller shares personal data.6. A description of the methodsrequired under section 44-1383.01 that describes how a consumer maysubmit requests to exercise their consumer rights under this article.B. If a controller engages in thesale of personal data or processes personal data for targeted advertising, thecontroller shall clearly and conspicuously provide the following notice andinclude in the notice the manner in which the consumer may opt out of the saleof personal data or targeted advertising: "We may sell your personal dataor use your personal data for targeted advertising.� If you want to opt out ofthe sale of personal data or targeted advertising, you may [describe thespecific manner in which the consumer may opt out]."� The notice mustbe posted in the same location and in the same manner as the privacy noticedescribed in subsection A of this section.C. If a controller engages in thesale of sensitive data, the controller shall clearly and conspicuously providethe following notice specifying the type of sensitive data and include in thenotice the manner in which the consumer may opt out of the sale of sensitivedata:� "We may sell your [name the specific type of sensitive data,including biometric personal data]. if you want to opt out of the sale ofthe sensitive data, you may [describe the specific manner in which theconsumer may opt out]."� The notice must be posted in the samelocation and in the samer manner as the privacy notice described in subsectionA of this section.D. The privacy notice must be Postedonline through a conspicuous link using the word "privacy" on thecontroller's website home page or on a mobile application's app store page ordownload page.E. A controller that maintains anapplication on a mobile or other device shall also include a link to theprivacy notice in the application's setting.F. A controller that does not operatea WEBSITE shall make the privacy notice conspicuously available to consumersthrough a medium regularly used by the controller to interact with consumers,for instance, if a controller interacts with a consumer offline, an offlineversion of the privacy notice must be available to the consumer.G. To enable a consumer to exercisethe right to opt out of processing as described in this article, the controllermust:1. Provide the disclosures requiredby subsections B and C OF THIS SECTION.2. Provide a clear, conspicuousmethod for each or all of the opt out purposes, as applicable, either directlyor through a link, in a clear and conspicuous and readily accessible locationoutside of the privacy notice.H. To enable a consumer to exercisethe right to opt out of processing personal data for the purpose of profilingin furtherance of a decision that produces a legal or similarly significanteffect concerning the consumer, the controller shall provide a clear andconspicuous method for consumers to exercise the right to opt out of processingpersonal data for such profiling at or before the time such processing occurs.END_STATUTESTART_STATUTE44-1383.07. Sale of data for targeted advertising; disclosure; opt outIf a controller sells personal data for targetedadvertising, the controller shall clearly and conspicuously disclose theprocess and the manner in which a consumer may EXERCISE THE RIGHT TO opt out ofthat process. END_STATUTESTART_STATUTE44-1383.08. Duties of processor; contracts between controller and processorA. A processor shall adhere to theinstructions of a controller and shall assist the controller in meeting or complyingwith the controller's duties or requirements under this article, including:1. Assisting the controller inresponding to consumer RIGHTS' requests submitted under section 44-1383.01by using appropriate technical and organizational measures, as reasonablypracticable, taking into consideration the nature of processing and theinformation available to the processor.2. Assisting the controller incomplying with the security requirements when processing personal data and, IFAPPLICABLE, PERSONAL DATA collected, STORED AND PROCESSED BY AN ARTIFICIALINTELLIGENCE SYSTEM, AND notifying the controller of any breach of security inthe processor's system.3. Providing necessary information toenable the controller to conduct and document data protection assessments undersection 44-1383.09.B. A contract between a controllerand a processor SHALL govern the rights and responsibilities of the dataprocessing procedures that are performed on behalf of the controller.� Thecontract must include all of the following:1. Clear instructions for processingpersonal data.2. The nature and purpose ofprocessing personal data.3. The type of SPECIFIC personal datasubject to processing.4. The duration of processing.5. The rights and obligations of thecontroller and the processor.6. A requirement that the processor:(a) Ensure thateach person that is processing personal data is subject to a duty ofconfidentiality with respect to the personal data.(b) At thecontroller's direction, delete or return all personal data to the controller asREQUESTED after the service is completed, unless retention of the personal datais required by law.(c) Makeavailable to the controller, on reasonable request, all information in theprocessor's possession that is necessary to demonstrate the processor'scompliance with the requirements of this article.(d) Allow andcooperate with reasonable assessments by the controller or the controller'sdesignated assessor.(e) Engage anysubcontractor pursuant to a written contract that requires the subcontractor tomeet the requirements of the processor with respect to the processing ofpersonal data.C. Notwithstanding subsection B,paragraph 6, subdivision (e) of this section, a processormay ARRANGE for a qualified and independent assessor to conduct an assessmentof the processor's policies, technical capabilities and organizationalstructures to serve as a processor.� The processor shall provide a report ofthe assessment to the controller on request.D. This section does not relieve acontroller or a processor from any liability in violation of this article.�E. Whether a person is acting as acontroller or processor is a fact-based question taking into consideration thecontract between the controller and processor and how the data is processed.� Aprocessor that continues to adhere to a controller's instructions whenprocessing personal data remains in the role of a processor. END_STATUTESTART_STATUTE44-1383.09. Data protection assessmentsA. A controller shall conduct anddocument a data protection assessment of each of the following activities:1. The processing of personal datafor the purposes of targeted advertising.2. The processing of personal datafor sale.3. The processing of personal datafor the purposes of profiling if the profiling presents a reasonablyFORESEEABLE risk of any of the following:(a) unfair ordeceptive treatment or unlawful disparate impact on consumers.(b) Financial,physical or reputational injury to consumers.(c) Invasion ofprivacy that would be offensive to a reasonable person.(d) Othersubstantial injury to consumers.(e) Theprocessing of sensitive personal data.(f) Anyprocessing activities that involves personal data and that presents aheightened risk of harm to consumers.B. A data protection assessmentconducted under subsection a of this section shall DO BOTH OF THE FOLLOWING:1. Identify and weigh the direct orindirect benefits that may flow from the processing to the controller, theconsumer, other stakeholders and the public against the potential risks to therights of the consumer associated with that processing as mitigated bysafeguards that can be employed by the controller to reduce the risks.2. Take into consideration ALL OF THEFOLLOWING:(a) The use ofdeidentified data.(b) Thereasonable expectations of consumers.(c) The contextof the processing.(d) Therelationship between the controller and the consumer whose personal data willbe processed.C. A controller shall provide a copyof the data protection assessment to the attorney general on request ORPURSUANT TO A CIVIL INVESTIGATION DEMAND. disclosure of a dataprotection assessment in compliance with a request from the attorney generaldoes not constitute a waiver of attorney-client privilege or work productprotection with respect to the assessment and any information that is containedin the assessment.D. A data protection assessment isconfidential and not a public record under title 39, chapter 1, article 2.E. A single data protectionassessment IS PERMISSIBLE if the single data protection assessment iscomparable to other processing operations THAT INCLUDE similar activities.F. A data protection assessmentconducted by a controller for the purposes of compliance with other laws orregulations constitutes compliance with the requirements of this SECTION if theassessment has a reasonably comparable scope and effect. END_STATUTESTART_STATUTE44-1383.10. Deidentified or pseudonymous dataA. A controller that is in possessionof deidentified data shall:1. Take reasonable MEASURES to ensurethat the deidentified data cannot be associated with any individual.2. PUblicly commit ON THECONTROLLER'S WEBSITE OR IN A PRIVACY NOTICE to maintaining and usingdeidentified data without attempting to reidentify the deidentified data.3. Contractually obligate anyrecipient of the deidentified data to comply with this article.B. This section does not require acontroller or processor to:1. Reidentify deidentified data orpseudonymous data.2. Maintain deidentified data orpseudonymous data in identifiable form or to obtain, retain or access any dataor technology for the purposes of allowing the controller or processor toassociate a consumer request with personal data.3. Comply with an authenticatedconsumer request under section 44-1383.01 if the controller:(a) Is notreasonably capable of associating the request with the personal data or itwould be unreasonably burdensome for the controller to associate the requestwith the personal data.(b) Does notuse the personal data to recognize or respond to the specific consumer who isthe subject of the personal data or associate the personal data with otherpersonal data about the same specific consumer.C. The consumer rights under thisarticle do not apply to pseudonymous data in cases in which the controller isable to demonstrate any information necessary to identify the consumer is keptseparately and is subject to effective technical and organizational controlsthat prevent the controller from accessing the INFORMATION.D. A controller that disclosespseudonymous data or deidentified data shall exercise reasonable oversight tomonitor compliance and shall take appropriate steps to address any breakdown inmaintaining COMPLIANCE If personal data a controller claims is deidentified orpseudonymous is reidentified and used in a manner that violates this ARTICLE, apresumption will exist that the controller or processor maintaining thereidentified data is responsible for any violation or breach of the personal data.END_STATUTESTART_STATUTE44-1383.11. Sale of personal data; prohibitionA controller or processor may not sell aconsumer's sensitive data without receiving prior consumer WRITTEN consent. END_STATUTESTART_STATUTE44-1383.12. Attorney general; website; filing of complaintsThe attorney general shall post on the attorneygeneral's website both of the following:1. information relating to:(a) Theresponsibilities of a controller pursuant to this article.(b) Theresponsibilities of a processor pursuant to this article.(c) Aconsumer's options regarding how to submit a consumer request to a controllerpursuant to section 44-1386.01 and how to file an appeal if a consumer'sRIGHTS WERE denied pursuant to section 44-1386.02.2. An online mechanism through whicha consumer may submit a complaint under this article to the attorney general.END_STATUTESTART_STATUTE44-1383.13. Attorney general; violations; right to cure; civil penaltyA. An act or practice in violation ofthis article constitutes an unlawful practice pursuant to section 44-1522.�The attorney general may investigate and take appropriate action pursuant tochapter 10, article 7 of this title.� The attorney general may promulgate rulesfor the purpose of carrying out this ARTICLE, particularly the details of howto provide a privacy notice and opt out methods, how to respond to rightsrequests and how to determine whether secondary processing is compatible withthe purpose of processing indicated in the privacy notice.B. Before bringing an action pursuantto chapter 10, article 7 of this title, the attorney general shall notify acontroller in writing not more than thirty days before filing the action andshall identify the specific provisions of this article that the attorneygeneral alleges have been violated.� The attorney general may not bring anaction against the controller if both of the following apply:1. The controller cures theidentified violation within thirty days after notification from the attorneygeneral.2. The controller provides theattorney general with a written statement that the controller:(a) Cured thealleged violation.(b) Notifiedthe consumer that the consumer's request was addressed if the consumer'scontact information was made available to the controller.(c) Provideddocumentation to show how the alleged violation was cured.(d) Madechanges to internal policies, if necessary, to ensure that further violationswill not occur.C. A PERSON, controller, PROCESSOR ORTHIRD-PARTY AGENT that violates this article following the cure period orthat breaches a written statement provided to the attorney general under thissection is liable for a civil penalty in an amount of not more than $7,500 foreach violation.D. The attorney general may bring acivil action IN THE NAME OF THIS STATE to:1. Recover a civil penalty under thissection.2. Restrain or enjoin the personCONTROLLER, PROCESSOR OR THIRD-PARTY AGENT from violating this article.3. Seek injunctive relief.E. The attorney general may recoverreasonable attorney fees.�F. This article does not establish aprivate right of action.END_STATUTESTART_STATUTE44-1383.14. Collection, use, or retention of personal dataA. The requirements imposed oncontrollers and processors under this article may not restrict a controller'sor processor's ability to collect, use or retain personal data to:1. Conduct internal research todevelop, improve or repair products, services or technology.2. Effect a product recall.3. Identify and repair technicalerrors that impair existing or intended functionality.4. Perform internal operations thatare all of the following:(a) Reasonablyaligned with the expectations of the consumer.(b) Reasonablyanticipated based on the consumer's existing relationship with the controller.(c) Otherwisecompatible with processing personal data in furtherance of the provision of aproduct or service specifically requested by a consumer or the performance of acontract to which the consumer is a party.� Whether processing is compatibledepends on the context of the relationship with the consumer, the necessity ofthe processing to providE the specific product or service requested and theconsumer's expectations of the use of personal data in the context of therelationship and the product or service requested.B. A controller or processor is notrequired to comply with a requirement of this section if compliance wouldviolate an evidentiary privilege under THE LAWS OF THIS STATE. END_STATUTESTART_STATUTE44-1383.15. Disclosure of personal data to third-party controller orprocessorA. A controller or processor thatdiscloses personal data to a third-party controller or processor incompliance with this article does not violate this article if the third-partycontroller or processor receives and processes the personal data in violationof this article and if the disclosing controller or processor did not haveknowledge, REASONABLY SHOULD HAVE KNOWN OR A REASONABLE EXPECTATION that thethird-party controller or processor intended to commit a violation.B. A third-party controller orprocessor that receives personal data from a controller or processor incompliance with this article does not violate this article for acts that mayhave occurred before disclosure to the third-party controller orprocessor. END_STATUTESTART_STATUTE44-1383.16. Processing of personal data by controller, processor orthird-party processorA. Personaldata that is processed by a controller under this article may not be processedfor any other purpose.� A controller may process Personal data if:1. The processing of personal data isreasonably necessary and proportionate to the purposes provided in thisarticle.2. The processing of personal data isrelevant and limited to what is necessary in relation to the specific purposesprovided in this article.B. The personal data that iscollected, used or retained must be in compliance with thisarticle. A controller shall use appropriate reasonable,administrative, technical and physical MEASURES to protect the confidentiality,integrity and accessibility of personal data and to reduce reasonablyFORESEEABLE risks of harm to consumers relating to the collection, use orretention of personal data.C. A controller that processespersonal data under an exemption in this article shall BEAR THE BURDEN TOdemonstrate that the PROCESSING OF THE personal data qualifies for theexemption AND IS IN COMPLIANCE WITH THIS ARTICLE.D. The processing of personal data bya processor or third-party processor does not make the processor or third-partyprocessor a controller WITH RESPECT TO THE PROCESSING OF THE DATA. END_STATUTESTART_STATUTE44-1383.17. Scope of the article; preemptionThis article supersedes and preempts anyORDINANCE, resolution, rule or other regulation adopted by a politicalsubdivision regarding the processing of personal data by a controller orprocessor.END_STATUTE
Personal data; consumers; controllers; requirements
Sponsors
Sen. Lauren Kuby (D) sponsors SB 1815 alone.
Committees
SB 1815 went before 2 committees: Regulatory Affairs and Government Efficiency and Rules.
Regulatory Affairs and Government Efficiency

Regulatory Affairs and Government Efficiency
Referred to · Feb 9, 2026
History
SB 1815 has taken 4 actions since Feb 9, 2026, the latest on Feb 10, 2026.
| Chamber | Action | |||
|---|---|---|---|---|
Feb 10, 2026 | Senate | Senate read second time | ||
Feb 9, 2026 | Senate | Introduced in Senate and read first time | ||
Feb 9, 2026 | Senate | Assigned to Senate RAGE Committee | ||
Feb 9, 2026 | Senate | Assigned to Senate RULES Committee |
Votes
SB 1815 has not gone to a roll call.
Source: apps.azleg.gov · legiscan.com