- H.R. 10171August 27, 2026
- H.R. 10156August 27, 2026
- H.R. 10172August 27, 2026
- H.R. 10160August 27, 2026
- H.R. 10181August 27, 2026
- H.R. 10176August 27, 2026
- H.Res. 1496August 27, 2026
- H.R. 10164August 27, 2026
- H.R. 10170August 27, 2026
- H.Res. 1494August 27, 2026
- H.R. 10163August 27, 2026
- H.R. 10157August 27, 2026
- AdministrationU.S. House
- AgricultureU.S. House
- Agriculture, Nutrition, And ForestryU.S. House
- AppropriationsU.S. House
- Armed ServicesU.S. House
- Banking, Housing, And Urban AffairsU.S. House
- BudgetU.S. House
- Commerce, Science, And TransportationU.S. House
- Education and WorkforceU.S. House
- Energy And CommerceU.S. House
- Energy And Natural ResourcesU.S. House
- Environment And Public WorksU.S. House
- EthicsU.S. House
- FinanceU.S. House
- Financial ServicesU.S. House
- Foreign AffairsU.S. House
- Foreign RelationsU.S. House
- Health, Education, Labor, And PensionsU.S. House
- Homeland SecurityU.S. House
- Homeland Security And Governmental Affa…U.S. House
- Indian AffairsU.S. House
- Indian and Insular AffairsU.S. House
- IntelligenceU.S. House
- JudiciaryU.S. House
- Natural ResourcesU.S. House
- Oversight And Government ReformU.S. House
- Permanent Select IntelligenceU.S. House
- RulesU.S. House
- Rules And AdministrationU.S. House
- Science, Space, And TechnologyU.S. House
- Select IntelligenceU.S. Senate
- Small BusinessU.S. House
- Small Business And EntrepreneurshipU.S. House
- Subcommittee on AviationU.S. House
- Subcommittee on Border Security and Enf…U.S. House
- Subcommittee on Coast Guard and Maritim…U.S. House
- Subcommittee on Commodity Markets, Digi…U.S. House
- Subcommittee on Conservation, Research,…U.S. House
- Subcommittee on Counterterrorism and In…U.S. House
- Subcommittee on Cybersecurity and Infra…U.S. House
- Subcommittee on Disability Assistance a…U.S. House
- Subcommittee on Economic Development, P…U.S. House
- Subcommittee on Economic OpportunityU.S. House
- Subcommittee on Emergency Management an…U.S. House
- Subcommittee on Energy and Mineral Reso…U.S. House
- Subcommittee on Federal LandsU.S. House
- Subcommittee on Forestry and Horticultu…U.S. House
- Subcommittee on General Farm Commoditie…U.S. House
- Subcommittee on HealthU.S. House
- Subcommittee on Highways and TransitU.S. House
- Subcommittee on Livestock, Dairy, and P…U.S. House
- Subcommittee on Nutrition and Foreign A…U.S. House
- Subcommittee on Oversight and Investiga…U.S. House
- Subcommittee on Oversight, Investigatio…U.S. House
- Subcommittee on Railroads, Pipelines, a…U.S. House
- Subcommittee on Transportation and Mari…U.S. House
- Subcommittee on Water Resources and Env…U.S. House
- Subcommittee on Water, Wildlife and Fis…U.S. House
- Transportation And InfrastructureU.S. House
- Veterans' AffairsU.S. House
- Ways And MeansU.S. House

SB 386
Louisiana Senate•Passed
Summary
SB 386, which provides for opting out of providing personal information on social media websites. (1/1/27), was introduced in the Senate on Feb 27, 2026 by Sen. Patrick Connick (R) with 11 co-sponsors. It last saw action on May 29, 2026: Effective date 1/1/2027.
Record
Text
SB 386 has 11 co-sponsors and 4 roll calls.
sb386/chaptered.txt2026 Regular Session ENROLLEDACT No. 502SENATE BILL NO. 386BY SENATORS CONNICK, BARROW, HENRY, JACKSON-ANDREWS, JENKINS,LUNEAU, MILLER, PRICE, SELDERS, STINE AND WOMACK ANDREPRESENTATIVE CHASSION1AN ACT2 To enact Chapter 20-B of Title 51 of the Louisiana Revised Statutes of 1950, to be3comprised of R.S. 51:1780.1 through 1780.5, relative to consumer data privacy;4creates the Louisiana Data Privacy Act; to provide for limitations and restrictions of5the use of certain data; to provide for duties of a controller and processor; to provide6for consumer rights regarding personal data; to provide for applicability and7exemptions; to provide for public notice; to provide for definitions and terms; to8provide for enforcement; and to provide for related matters.9 Be it enacted by the Legislature of Louisiana:10Section 1. Chapter 20-B of Title 51 of the Louisiana Revised Statutes of 1950,11 comprised of R.S. 51:1780.1 through 1780.5, is hereby enacted to read as follows:12CHAPTER 20-B. LOUISIANA DATA PRIVACY ACT13§1780.1. Definitions14As used in this Chapter, the following terms have the following15meanings:16(1) "Affiliate" means a legal entity that controls, is controlled by, or is17under common control with another legal entity or shares common branding18with another legal entity. For purposes of this Paragraph, "control" or19"controlled" means any of the following:20(a) The ownership of, or power to vote, more than fifty percent of the21outstanding shares of any class of voting security of a company.22(b) The control in any manner over the election of a majority of the23directors or of individuals exercising similar functions.24(c) The power to exercise controlling influence over the management of25a company.26(2) "Authenticate" means to verify through reasonable means that thePage 1 of 26Coding: Words which are struck through are deletions from existing law;words in boldface type and underscored are additions.SB NO. 386 ENROLLED1consumer who is entitled to exercise the consumer's rights pursuant to R.S.251:1780.3 is the same consumer exercising those consumer rights with respect3to the personal data at issue.4(3) "Biometric data" means data generated by automatic measurements5of an individual's biological characteristics that are used to identify a specific6individual. The term includes a fingerprint, voiceprint, eye retina or iris scan,7or other unique biological pattern or characteristic when such data is used to8identify the specific individual. The term does not include a physical or digital9photograph or data generated from a physical or digital photograph or a video10or audio recording or data generated from a video or audio recording, unless11such data is generated to identify a specific individual. The term does not12include information collected, used, or stored for health care treatment,13payment, or operations under the Health Insurance Portability and14Accountability Act of 1996, 42 U.S.C. 1320d et seq.15(4) "Business associate" has the same meaning assigned to the term by16the Health Insurance Portability and Accountability Act of 1996, 45 CFR Part17160.103.18(5) "Child" means an individual younger than thirteen years of age.19(6) "Consent" when referring to a consumer means a clear affirmative20act signifying a consumer's freely given, specific, informed, and unambiguous21agreement to process personal data relating to the consumer. The term includes22a written statement, including a statement written by electronic means, or any23other unambiguous affirmative action. The term does not include any of the24following:25(a) Acceptance in a general or broad terms of use or similar document26that contains descriptions of personal data processing along with other,27unrelated information.28(b) Hovering over, muting, pausing, or closing a given piece of content.29(c) Agreement obtained through the use of dark patterns.30(7) "Consumer" means an individual who is a resident of this state actingPage 2 of 26Coding: Words which are struck through are deletions from existing law;words in boldface type and underscored are additions.SB NO. 386 ENROLLED1only in an individual or household context. The term does not include an2individual acting in a commercial or employment context.3(8) "Controller" means an individual or other person that, alone or4jointly with others, determines the purpose and means of processing personal5data.6(9) "Covered entity" has the meaning assigned to the term by the Health7Insurance Portability and Accountability Act of 1996, 42 U.S.C. 1320d et seq.8(10) "Dark pattern" means a user interface designed or manipulated9with the effect of substantially subverting or impairing user autonomy,10decision-making, or choice, and includes any practice the Federal Trade11Commission refers to as a dark pattern.12(11) "Decision that produces a legal or similarly significant effect13concerning a consumer" means a decision made by the controller that results14in the provision or denial by the controller of any of the following:15(a) Financial and lending services.16(b) Housing, insurance, or healthcare services.17(c) Education enrollment.18(d) Employment opportunities.19(e) Criminal justice.20(f) Access to basic necessities, such as food and water.21(12) "Deidentified data" means data that cannot reasonably be used to22infer information about, or otherwise be linked to an identified or identifiable23individual, or a device linked to that individual, if the controller or processor24that possesses such data does all of the following:25(a) Takes reasonable measures to ensure that such data cannot be26associated with an individual.27(b) Publicly commits to process such data only in a deidentified fashion28and attempt to reidentify such data.29(c) Contractually obligates any recipients of such data to satisfy the30criteria set forth in Subparagraphs (a) and (b) of this Paragraph.Page 3 of 26Coding: Words which are struck through are deletions from existing law;words in boldface type and underscored are additions.SB NO. 386 ENROLLED1(13) "Healthcare provider" has the meaning assigned to the term by the2Health Insurance Portability and Accountability Act of 1996, 42 U.S.C. 1320d3et seq.4(14) "Health record" means any written, printed, or electronically5recorded material maintained by a healthcare provider in the course of6providing healthcare services to an individual that concerns the individual and7the services provided. The term includes either one of the following items:8(a) The substance of any communication made by an individual to a9healthcare provider in confidence during or in connection with the provision of10healthcare services.11(b) Information otherwise acquired by the healthcare provider about an12individual in confidence and in connection with healthcare services provided to13the individual.14(15) "Identified or identifiable individual" means a consumer who can15be readily identified, directly or indirectly.16(16) "Institution of higher education" means either one of the following17items:18(a) An institution of higher education as defined by law.19(b) A private or independent institution of higher education as defined20by law.21(17) "Known child" means a child under circumstances where a22controller has actual knowledge of, or willfully disregards, the child's age.23(18) "Nonprofit organization" means any of the following:24(a) A corporation organized under the provisions of Chapter 2 of Title2512 of the Louisiana Revised Statutes of 1950, to the extent applicable to26nonprofit corporations.27(b) An organization exempt from federal taxation under Section 501(a)28of the Internal Revenue Code of 1986, as amended by being listed as an exempt29organization under Sections 501(c)(3), 501(c)(6), 501(c)(12), or 501(c)(19) of that30Code.Page 4 of 26Coding: Words which are struck through are deletions from existing law;words in boldface type and underscored are additions.SB NO. 386 ENROLLED1(c) A political organization.2(d) An organization that is exempt from federal taxation under Section3501(a) of the Internal Revenue Code of 1986, as amended by being listed as an4exempt organization under Section 501(c)(4) of that Code.5(19) "Personal data" means any information, including sensitive data,6that is linked or reasonably linkable to an identified or identifiable individual.7The term does not include deidentified data or publicly available information.8(20) "Political organization" means a party, committee, association,9fund, or other organization, regardless of whether incorporated, that is10organized and operated primarily for the purpose of influencing or attempting11to influence either of the following:12(a) The selection, nomination, election, or appointment of an individual13to a federal, state, or local public office or an office in a political organization,14regardless of whether the individual is selected, nominated, elected, or15appointed.16(b) The election of a presidential/vice-presidential elector, regardless of17whether the elector is selected, nominated, elected, or appointed.18(c) The outcome of any ballot measure, referendum, initiative, or recall19election at the federal, state, or local level.20(d) Any political, legislative, or public policy matter, including public21opinion relating thereto.22(21) "Precise geolocation data" means information derived from23technology, including global positioning system level latitude and longitude24coordinates or other mechanisms, that directly identifies the specific location of25an individual with precision and accuracy within a radius of one thousand seven26hundred fifty feet. The term does not include the content of communications, or27any data generated by or connected to an advanced utility metering28infrastructure system or to equipment for use by a utility.29(22) "Process" or "processing" means an operation or set of operations30performed, whether by manual or automated means, on personal data or on setsPage 5 of 26Coding: Words which are struck through are deletions from existing law;words in boldface type and underscored are additions.SB NO. 386 ENROLLED1of personal data, such as the collection, use, storage, disclosure, analysis,2deletion, or modification of personal data.3(23) "Processor" means a person that processes personal data on behalf4of a controller.5(24) "Profiling" means any form of solely automated processing6performed on personal data to evaluate, analyze, or predict personal aspects7related to an identified or identifiable individual's economic situation, health,8personal preferences, interests, reliability, behavior, location, or movements.9(25) "Protected health information" has the meaning assigned to the10term by the Health Insurance Portability and Accountability Act of 1996, 4211U.S.C. 1320d et seq.12(26) "Pseudonymous data" means any information that cannot be13attributed to a specific individual without the use of additional information,14provided that the additional information is kept separately and is subject to15appropriate technical and organizational measures to ensure that the personal16data is not attributed to an identified or identifiable individual.17(27) "Publicly available information" means information that is lawfully18made available through government records, or information that a business has19a reasonable basis to believe is lawfully made available to the general public20through widely distributed media, by a consumer, or by a person to whom a21consumer has disclosed the information, unless the consumer has restricted the22information to a specific audience.23(28) "Sale of personal data" means the exchange of personal data for24monetary or other valuable consideration by the controller to a third party. The25term does not include any of the following:26(a) The disclosure of personal data to a processor that processes the27personal data on the controller's behalf.28(b) The disclosure of personal data to a third party for purposes of29providing a product or service requested by the consumer.30(c) The disclosure or transfer of personal data to an affiliate of thePage 6 of 26Coding: Words which are struck through are deletions from existing law;words in boldface type and underscored are additions.SB NO. 386 ENROLLED1controller.2(d) The disclosure of information that the consumer intentionally made3available to the general public through a mass media channel and did not4restrict to a specific audience.5(e) The disclosure of personal data directed by a consumer or made when6the consumer uses the controller to interact with a third party.7(f) The disclosure or transfer of personal data to a third party as an asset8that is part of a merger, acquisition, or similar activity, or a proposed merger,9acquisition, or similar activity.10(29) "Sensitive data" means a category of personal data. The term11includes any of the following:12(a) Personal data revealing racial or ethnic origin, religious beliefs,13mental or physical health diagnosis, sexuality, or citizenship or immigration14status.15(b) Genetic or biometric data that is processed for the purpose of16uniquely identifying an individual.17(c) Personal data collected from a known child.18(d) Precise geolocation data.19(30) "State agency" means a department, commission, board, office,20council, authority, or other agency in any branch of state government that is21created by the constitution or a statute of this state, including a university22system or institution of higher education as defined by law.23(31) "Targeted advertising" means displaying to a consumer an24advertisement that is selected based on personal data obtained or inferred from25that consumer's activities over time and across nonaffiliated websites or online26applications to predict the consumer's preferences or interests. The term does27not include an advertisement that is:28(a) Based on activities within a controller's own websites or online29applications.30(b) Based on the context of a consumer's current search query, visit toPage 7 of 26Coding: Words which are struck through are deletions from existing law;words in boldface type and underscored are additions.SB NO. 386 ENROLLED1a website, or online application.2(c) Directed to a consumer in response to the consumer's request for3information or feedback.4(d) The processing of personal data solely for measuring or reporting5advertising performance, reach, or frequency.6(32) "Third party" means a person, other than the consumer, the7controller, the processor, or an affiliate of the controller or processor.8(33) "Trade secret" means all forms and types of information, including9business, scientific, technical, economic, or engineering information, and any10formula, design, prototype, pattern, plan, compilation, program device,11program, code, device, method, technique, process, procedure, financial data,12or list of actual or potential customers or suppliers, whether tangible or13intangible and whether or how stored, compiled, or memorialized physically,14electronically, graphically, photographically, or in writing if:15(a) The owner of the trade secret has taken reasonable measures under16the circumstances to keep the information secret.17(b) The information derives independent economic value, actual or18potential, from not being generally known to, and not being readily19ascertainable through proper means by, another person who can obtain20economic value from the disclosure or use of the information.21§1780.2. Applicability; preemption22A. The provisions of this Chapter shall apply only to a person or entity23that does business in the state and that satisfies one or more of the following24thresholds:25(1) Has annual gross revenues in excess of twenty-five million dollars.26(2) Annually buys, receives for the business's commercial purposes, sells,27or shares for commercial purposes the personal information of seventy-five28thousand or more consumers, households, or devices.29(3) Derives fifty percent or more of its annual revenues from selling30consumers' personal information.Page 8 of 26Coding: Words which are struck through are deletions from existing law;words in boldface type and underscored are additions.SB NO. 386 ENROLLED1B. The provisions of this Chapter do not apply to any of the following2items:3(1) A state agency or a political subdivision of this state.4(2) A financial institution and its affiliates or data subject to Title V,5Gramm-Leach-Bliley Act, 15 U.S.C. 6801 et seq., and the rules and6implementing regulations promulgated thereunder.7(3) A covered entity or business associate governed by the privacy,8security, and breach notification rules issued by the United States Department9of Health and Human Services, 45 CFR Parts 160 and 164, established under10the Health Insurance Portability and Accountability Act of 1996, 42 U.S.C.111320d et seq.12(4) A nonprofit organization.13(5) An institution of higher education.14(6) An electric public utility as defined in R.S. 45:121.15(7) A person, association, partnership, or corporation registered with the16secretary of state as a conductor of public opinion polls pursuant to R.S. 14:325.17C. The following information is exempt from this Chapter:18(1) Protected health information under the Health Insurance Portability19and Accountability Act of 1996, 42 U.S.C. 1320d et seq.20(2) Health records.21(3) Patient identifying information for purposes of 42 U.S.C. 290dd-2.22(4) Identifiable private information:23(a) For purposes of the federal policy for the protection of human24subjects under 45 CFR Part 46.25(b) Collected as part of human subjects research under the good clinical26practice guidelines issued by The International Council for Harmonisation of27Technical Requirements for Pharmaceuticals for Human Use, otherwise known28as ICH, or of the protection of human subjects under 21 CFR Parts 50 and 56.29(c) That is personal data used or shared in research conducted in30accordance with the requirements set forth in this Chapter or other researchPage 9 of 26Coding: Words which are struck through are deletions from existing law;words in boldface type and underscored are additions.SB NO. 386 ENROLLED1conducted in accordance with applicable law.2(5) Information and documents created for purposes of the Health Care3Quality Improvement Act of 1986, 42 U.S.C. 11101 et seq.4(6) Patient safety work product for purposes of the Patient Safety and5Quality Improvement Act of 2005, 42 U.S.C. 299b-21 et seq.6(7) Information derived from any of the healthcare-related information7listed in this Section that is deidentified in accordance with the requirements for8deidentification under the Health Insurance Portability and Accountability Act9of 1996, 42 U.S.C. 1320d et seq.10(8) Information originating from, and intermingled to be11indistinguishable with, or information treated in the same manner as,12information exempt under this Section that is maintained by a covered entity13or business associate as defined by the Health Insurance Portability and14Accountability Act of 1996, 42 U.S.C. 1320d et seq., or by a program or a15qualified service organization as defined by 42 U.S.C. 290dd-2.16(9) Information that is included in a limited data set as described by 4517CFR 164.514(e), to the extent that the information is used, disclosed, and18maintained in the manner specified by 45 CFR 164.514(e).19(10) Information collected or used only for public health activities and20purposes as authorized by the Health Insurance Portability and Accountability21Act of 1996, 42 U.S.C. 1320d et seq.22(11) The collection, maintenance, disclosure, sale, communication, or use23of any personal information bearing on a consumer's creditworthiness, credit24standing, credit capacity, character, general reputation, personal25characteristics, or mode of living by a consumer reporting agency or furnisher26that provides information for use in a consumer report, and by a user of a27consumer report, but only to the extent that the activity is regulated by and28authorized under the Fair Credit Reporting Act, 15 U.S.C. 1681 et seq.29(12) Personal data collected, processed, sold, or disclosed in compliance30with the Driver's Privacy Protection Act of 1994, 18 U.S.C. 2721 et seq.Page 10 of 26Coding: Words which are struck through are deletions from existing law;words in boldface type and underscored are additions.SB NO. 386 ENROLLED1(13) Personal data regulated by the Family Educational Rights and2Privacy Act of 1974, 20 U.S.C. 1232g.3(14) Personal data collected, processed, sold, or disclosed in compliance4with the Farm Credit Act of 1971, 12 U.S.C. 2001 et seq.5(15) Data processed or maintained in the course of an individual6applying to, being employed by, or acting as an agent or independent contractor7of a controller, processor, or third party, to the extent that the data is collected8and used within the context of that role.9(16) Data processed or maintained as the emergency contact information10of an individual under this Chapter that is used for emergency contact11purposes.12(17) Data that is processed or maintained and is necessary to retain to13administer benefits for another individual that relates to an individual14described by R.S. 51:1780.1(15) and used for the purposes of administering15those benefits.16D. The provisions of this Chapter shall not apply to the processing of17personal data by a person in the course of a purely personal or household18activity.19E. A controller or processor that complies with the verifiable parental20consent requirements of the Children's Online Privacy Protection Act of 1998,2115 U.S.C. 6501 et seq., and its rules, regulations, and exemptions with respect22to data collected online is considered to be in compliance with any requirement23to obtain parental consent under this Chapter.24§1780.3. Consumer rights; requests; appeals25A.(1) A consumer is entitled to exercise the consumer rights authorized26by this Section at any time by submitting a request to a controller specifying the27consumer rights the consumer wishes to exercise. With respect to the processing28of personal data belonging to a known child, a parent or legal guardian of the29child may exercise the consumer rights on behalf of the child.30(2) A controller shall comply with an authenticated consumer request toPage 11 of 26Coding: Words which are struck through are deletions from existing law;words in boldface type and underscored are additions.SB NO. 386 ENROLLED1exercise the right to do any of the following:2(a) Confirm whether a controller is processing the consumer's personal3data and to access the personal data.4(b) Correct inaccuracies in the consumer's personal data, taking into5account the nature of the personal data and the purposes of the processing of6the consumer's personal data.7(c) Delete personal data provided by or obtained about the consumer.8(d) If the data is available in a digital format, obtain a copy of the9consumer's personal data that the consumer previously provided to the10controller in a portable and, to the extent technically feasible, readily usable11format that allows the consumer to transmit the data to another controller12without hindrance.13(e) Opt out of the processing of the personal data for purposes of:14(i) Targeted advertising.15(ii) The sale of personal data.16(iii) Profiling in furtherance of a decision that produces a legal or17similarly significant effect concerning the consumer.18(3) Nothing in this Section shall require the controller to reveal a trade19secret.20B.(1) Except as otherwise provided by this Chapter, a controller shall21comply with a request submitted by a consumer to exercise the consumer's22rights pursuant to Paragraph (A)(1) of this Section.23(2) A controller shall respond to the consumer request without undue24delay, which may not be later than the forty-fifth calendar day after the date of25receipt of the request. The controller may extend the response period once by26an additional forty-five days when reasonably necessary, taking into account the27complexity and number of the consumer's requests, so long as the controller28informs the consumer of the extension within the initial forty-five day response29period, together with the reason for the extension.30(3) If a controller declines to take action regarding the consumer'sPage 12 of 26Coding: Words which are struck through are deletions from existing law;words in boldface type and underscored are additions.SB NO. 386 ENROLLED1request, the controller shall inform the consumer without undue delay, which2may not be later than the forty-fifth calendar day after the date of receipt of the3request, of the justification for declining to take action and provide instructions4on how to appeal the decision in accordance with Subsection C of this Section.5(4) A controller shall provide information in response to a consumer6request free of charge, up to twice annually per consumer. If a request from a7consumer is manifestly unfounded, excessive, or repetitive, the controller may8charge the consumer a reasonable fee to cover the administrative costs of9complying with the request or may decline to act on the request. The controller10bears the burden of demonstrating for purposes of this Subsection that a11request is manifestly unfounded, excessive, or repetitive.12(5) If a controller is unable to authenticate the request using13commercially reasonable efforts, the controller is not required to comply with14a consumer request submitted pursuant to Subsection A of this Section and may15request that the consumer provide additional information reasonably necessary16to authenticate the consumer and the consumer's request.17(6) A controller that has obtained personal data about a consumer from18a source other than the consumer is considered in compliance with a consumer's19request to delete that personal data pursuant to Subparagraph (A)(2)(c) of this20Section by either of the following:21(a) Retaining a record of the deletion request and the minimum data22necessary for the purpose of ensuring the consumer's personal data remains23deleted from the business's records and not using the retained data for any24other purpose under this Chapter.25(b) Opting the consumer out of the processing of that personal data for26any purpose other than a purpose that is exempt under the provisions of this27Chapter.28C.(1) A controller shall establish a process for a consumer to appeal the29controller's refusal to take action on a request within a reasonable period of30time after the consumer's receipt of the decisions pursuant to Paragraph (B)(3)Page 13 of 26Coding: Words which are struck through are deletions from existing law;words in boldface type and underscored are additions.SB NO. 386 ENROLLED1of this Section.2(2) The appeal process shall be conspicuously available and similar to the3process for initiating action to exercise consumer rights by submitting a request4pursuant to Subsection A of this Section.5(3) A controller shall inform the consumer in writing of any action taken6or not taken in response to an appeal under this Section not later than the7sixtieth calendar day after the date of receipt of the appeal, including a written8explanation of the reason or reasons for the decision.9(4) If the controller denies an appeal, the controller shall provide the10consumer with the online mechanism described by R.S. 51:1780.5(B)(2) through11which the consumer may contact the attorney general to submit a complaint.12D. Any provision of a contract or agreement that waives or limits in any13way a consumer right described in this Section is contrary to public policy and14is void and unenforceable.15E.(1) A controller shall establish two or more secure and reliable16methods to enable consumers to submit a request to exercise their consumer17rights under this Chapter. The methods shall take into account all of the18following:19(a) The ways in which consumers normally interact with the controller.20(b) The necessity for secure and reliable communications of those21requests.22(c) The ability of the controller to authenticate the identity of the23consumer making the request.24(2) A controller may not require a consumer to create a new account to25exercise the consumer's rights under this Chapter but may require a consumer26to use an existing account.27(3) Except as provided by R.S. 51:1780.1(28)(d), if the controller28maintains a website, the controller shall provide a mechanism on the website for29consumers to submit requests for information required to be disclosed under30this Chapter.Page 14 of 26Coding: Words which are struck through are deletions from existing law;words in boldface type and underscored are additions.SB NO. 386 ENROLLED1(4) A controller that operates exclusively online and has a direct2relationship with a consumer from whom the controller collects personal3information is only required to provide an email address for the submission of4requests described by Subparagraph(1)(c) of this Subsection.5(5) A consumer may designate another person to serve as the consumer's6authorized agent and act on the consumer's behalf to opt out of the processing7of the consumer's personal data pursuant to Items (A)(2)(e)(i) and (ii) of this8Section. A consumer may designate an authorized agent using a technology,9including a link to a website, an internet browser setting or extension, or a10global setting on an electronic device, that allows the consumer to indicate the11consumer's intent to opt out of the processing for targeted advertising, for sale12of personal data, or both. A controller shall comply with an opt-out request13received from an authorized agent under this Subsection if the controller is able14to verify, with commercially reasonable effort, the identity of the consumer and15the authorized agent's authority to act on the consumer's behalf. A controller16is not required to comply with an opt-out request received from an authorized17agent under this Subsection if any one of the following applies:18(a) The authorized agent does not communicate the request to the19controller in a clear and unambiguous manner.20(b) The controller is not able to verify, with commercially reasonable21effort, that the consumer is a resident of this state.22(c) The controller does not possess the ability to process the request.23(d) The controller does not process similar or identical requests the24controller receives from consumers for the purpose of complying with similar25or identical laws or regulations of another state.26(6) The technology described by this Subsection:27(a) Shall not unfairly disadvantage another controller.28(b) May not make use of a default setting, but shall require the consumer29to make an affirmative, freely given, and unambiguous choice to indicate the30consumer's intent to opt out of any processing of a consumer's personal data.Page 15 of 26Coding: Words which are struck through are deletions from existing law;words in boldface type and underscored are additions.SB NO. 386 ENROLLED1(c) Shall be consumer-friendly and easy to use by the average consumer.2§1780.4. Duties3A.(1) A controller:4(a) Shall limit the collection of personal data to what is adequate,5relevant, and reasonably necessary in relation to the purposes for which that6personal data is processed, as disclosed to the consumer.7(b) For purposes of protecting the confidentiality, integrity, and8accessibility of personal data, shall establish, implement, and maintain9reasonable administrative, technical, and physical data security practices that10are appropriate to the volume and nature of the personal data at issue.11(2) A controller shall not:12(a) Except as otherwise provided by this Chapter, process personal data13for a purpose that is neither reasonably necessary to nor compatible with the14disclosed purpose for which the personal data is processed, as disclosed to the15consumer, unless the controller obtains the consumer's consent.16(b) Process personal data in violation of state and federal laws that17prohibit unlawful discrimination against consumers.18(c) Discriminate against a consumer for exercising any of the consumer19rights contained in this Chapter, including by denying goods or services,20charging different prices or rates for goods or services, or providing a different21level of quality of goods or services to the consumer.22(d) Process the sensitive data of a consumer without obtaining the23consumer's consent, or, in the case of processing the sensitive data of a known24child, without processing that data in accordance with the rules, regulations,25and the exceptions of the Children's Online Privacy Protection Act of 1998, 1526U.S.C. 6501 et seq.27(3) This Subsection may not be construed to require a controller to28provide a product or service that requires the personal data of a consumer that29the controller does not collect or maintain or to prohibit a controller from30offering a different price, rate, level, quality, or selection of goods or services toPage 16 of 26Coding: Words which are struck through are deletions from existing law;words in boldface type and underscored are additions.SB NO. 386 ENROLLED1a consumer, including offering goods or services for no fee, if the consumer has2exercised the consumer's right to opt out pursuant to R.S. 51:1780.3(A) or the3offer is related to a consumer's voluntary participation in a bona fide loyalty,4rewards, premium features, discounts, or club card program.5B.(1) A controller shall provide consumers with a reasonably accessible6and clear privacy notice that includes all of the following:7(a) The categories of personal data processed by the controller,8including, if applicable, any sensitive data processed by the controller.9(b) The purpose for processing personal data.10(c) A process on how consumers may exercise their consumer rights11pursuant to R.S. 51:1780.3, including the process by which a consumer may12appeal a controller's decision with regard to the consumer's request.13(d) If applicable, the categories of personal data that the controller sells14to third parties.15(e) If applicable, the categories of third parties with whom the controller16sells personal data.17(f) A description of the methods required pursuant to R.S. 51:1780.3(E)18through which consumers can submit requests to exercise their consumer rights19under this Chapter.20(2) If a controller engages in the sale of personal data that is sensitive, the21controller shall post the following notice in the same manner as the privacy22notice described in Subsection B of this Section:23"NOTICE: We may sell your sensitive personal data."24(3) If a controller engages in the sale of personal data that is biometric25data, the controller shall post the following notice in the same manner as the26privacy notice described in Subsection B of this Section:27"NOTICE: We may sell your biometric personal data."28C. If a controller sells personal data to third parties or processes29personal data for targeted advertising, the controller shall clearly and30conspicuously disclose that process and the manner in which a consumer mayPage 17 of 26Coding: Words which are struck through are deletions from existing law;words in boldface type and underscored are additions.SB NO. 386 ENROLLED1exercise the right to opt out of that process.2D.(1) A processor shall adhere to the instructions of a controller and3shall assist the controller in meeting or complying with the controller's duties4or requirements under this Chapter, including:5(a) Taking into account the nature of processing and the information6available to the processor, by using appropriate technical and organizational7measures, insofar as this is reasonably practicable, to fulfill the controller's8obligation to respond to consumer rights requests submitted pursuant to R.S.951:1780.3(A).10(b) Taking into account the nature of processing and the information11available to the processor, by assisting the controller in meeting the controller's12obligations in relation to the security of processing personal data, and in13relation to the notification of a breach of security of the processor's system14pursuant to R.S. 51:3071 et seq.15(c) Providing necessary information to enable the controller to conduct16and document data protection assessments under Subsection E of this Section.17(2) A contract between a controller and a processor shall govern the18processor's data processing procedures with respect to processing performed19on behalf of the controller. The contract shall include all of the following:20(a) Clear instructions for processing data.21(b) The nature and purpose of processing.22(c) The type of data subject to processing.23(d) The duration of processing.24(e) The rights and obligations of both parties.25(f) A requirement that the processor shall do all of the following:26(i) Ensure that each person processing personal data is subject to a duty27of confidentiality with respect to the data.28(ii) At the controller's direction, delete or return all personal data to the29controller as requested after the provision of the service is completed, unless30retention of the personal data is required by law.Page 18 of 26Coding: Words which are struck through are deletions from existing law;words in boldface type and underscored are additions.SB NO. 386 ENROLLED1(iii) Make available to the controller, on reasonable request, all2information in the processor's possession necessary to demonstrate the3processor's compliance with the requirements of this Chapter.4(iv) Allow, and cooperate with, reasonable assessments by the controller5or the controller's designated assessor.6(v) Engage any subcontractor pursuant to a written contract that7requires the subcontractor to meet the requirements of the processor with8respect to the personal data.9(3) Notwithstanding any other provisions of this Chapter, a processor,10in the alternative, may arrange for a qualified and independent assessor to11conduct an assessment of the processor's policies and technical and12organizational measures in support of the requirements under this Chapter13using an appropriate and accepted control standard or framework and14assessment procedure. The processor shall provide a report of the assessment15to the controller on request.16(4) This Section shall not be construed to relieve a controller or a17processor from the liabilities imposed on the controller or processor by virtue18of its role in the processing relationship as described by this Chapter.19(5) A determination of whether a person is acting as a controller or20processor with respect to a specific processing of data is a fact-based21determination that depends on the context in which personal data is to be22processed. A processor that continues to adhere to a controller's instructions23with respect to a specific processing of personal data remains in the role of a24processor.25E.(1) A controller shall conduct and document a data protection26assessment of each of the following processing activities involving personal data:27(a) The processing of personal data for purposes of targeted advertising.28(b) The sale of personal data.29(c) The processing of personal data for purposes of profiling, if the30profiling presents a reasonably foreseeable risk of any of the following:Page 19 of 26Coding: Words which are struck through are deletions from existing law;words in boldface type and underscored are additions.SB NO. 386 ENROLLED1(i) Unfair or deceptive treatment of or unlawful disparate impact on2consumers.3(ii) Financial, physical, or reputational injury to consumers.4(iii) A physical or other intrusion on the solitude or seclusion, or the5private affairs or concerns, of consumers, if the intrusion would be offensive to6a reasonable person.7(iv) Other substantial injury to consumers.8(d) The processing of sensitive data.9(e) Any processing activities involving personal data that present a10heightened risk of harm to consumers.11(2) A data protection assessment conducted pursuant to Paragraph (1)12of this Subsection shall do both of the following:13(a) Identify and weigh the direct or indirect benefits that may flow from14the processing to the controller, the consumer, other stakeholders, and the15public, against the potential risks to the rights of the consumer associated with16that processing, as mitigated by safeguards that can be employed by the17controller to reduce the risks.18(b) Factor into the assessment all of the following:19(i) The use of deidentified data.20(ii) The reasonable expectations of consumers.21(iii) The context of the processing.22(iv) The relationship between the controller and the consumer whose23personal data will be processed.24(3) A controller shall make a data protection assessment requested25pursuant to R.S. 51:1780.5(C)(2) available to the attorney general pursuant to26a civil investigative demand pursuant to R.S. 51:1780.5(C).27(4) A data protection assessment is confidential and exempt from public28inspection and copying pursuant to this Section. Disclosure of a data protection29assessment in compliance with a request from the attorney general does not30constitute a waiver of attorney-client privilege or work product protection withPage 20 of 26Coding: Words which are struck through are deletions from existing law;words in boldface type and underscored are additions.SB NO. 386 ENROLLED1respect to the assessment and any information contained in the assessment.2(5) A single data protection assessment may address a comparable set of3processing operations that include similar activities.4(6) A data protection assessment conducted by a controller for the5purpose of compliance with other laws or regulations may constitute compliance6with the requirements of this Section if the assessment has a reasonably7comparable scope and effect.8(7) Data protection assessments are required for processing activities as9of January 1, 2027, and are not retroactive.10F.(1) A controller in possession of deidentified data shall do all of the11following:12(a) Take reasonable measures to ensure that the data cannot be13associated with an individual.14(b) Publicly commit to maintaining and using deidentified data without15attempting to reidentify the data.16(c) Contractually obligate any recipient of the deidentified data to17comply with the provisions of this Chapter.18(2) This Chapter shall not be construed to require a controller or19processor to do any of the following:20(a) Reidentify deidentified data or pseudonymous data.21(b) Maintain data in identifiable form or obtain, retain, or access any22data or technology for the purpose of allowing the controller or processor to23associate a consumer request with personal data.24(c) Comply with an authenticated consumer rights request under R.S.2551:1780.3(A), if the controller is all of the following:26(i) Is not reasonably capable of associating the request with the personal27data or it would be unreasonably burdensome for the controller to associate the28request with the personal data.29(ii) Does not use the personal data to recognize or respond to the specific30consumer who is the subject of the personal data or associate the personal dataPage 21 of 26Coding: Words which are struck through are deletions from existing law;words in boldface type and underscored are additions.SB NO. 386 ENROLLED1with other personal data about the same specific consumer.2(iii) Does not sell the personal data to any third party or otherwise3voluntarily disclose the personal data to any third party other than a processor,4except as otherwise permitted by this Section.5G. This Section shall not prevent a controller or processor's ability to6prevent, detect, protect against or respond to security incidents, identity theft,7fraud, harassment, malicious or deceptive activity, or illegal activity; preserve8the integrity or security of systems; or investigate, report, or prosecute those9responsible for such actions.10H. This Chapter shall not be construed to limit a controller or11processor's ability to do any of the following:12(1) Comply with federal, state, or local laws, rules, or regulations.13(2) Comply with a civil, criminal, or regulatory inquiry, investigation,14subpoena, or summons by federal, state, local, or other governmental15authorities.16(3) Investigate, establish, exercise, prepare for, or defend legal claims.17(4) Provide a product or service specifically requested by a consumer or18the parent or guardian of a child, perform a contract to which the consumer is19a party, including fulfilling the terms of a written warranty, or taking steps at20the request of the consumer before entering into a contract.21(5) Take immediate steps to protect against an interest that is essential22for the life or physical safety of the consumer or of another individual and in23which the processing cannot be manifestly based on another legal basis.24(6) Engage in public or peer-reviewed scientific or statistical research in25the public interest that adheres to all other applicable ethics and privacy laws26and is approved, monitored, and governed by an institutional review board or27similarly independent oversight entity that determines all of the following has28occurred:29(a) If the deletion of the information is likely to provide benefits that do30not exclusively accrue to the controller.Page 22 of 26Coding: Words which are struck through are deletions from existing law;words in boldface type and underscored are additions.SB NO. 386 ENROLLED1(b) Whether the expected benefits of the research outweigh the privacy2risks.3(c) If the controller has implemented reasonable safeguards to mitigate4privacy risks associated with research, including any risks associated with5reidentification.6(7) Assist another controller, processor, or third party with any of the7requirements pursuant to this Subsection.8(8) Cooperate with law enforcement agencies concerning conduct or9activity that the controller or processor reasonably and in good faith believes10may violate federal, state, or local laws, rules, or regulations.11I. The obligations imposed on controllers or processors pursuant to this12Chapter shall not restrict a controller's or processor's ability to collect, use, or13retain data for internal use to do any of the following:14(1) Conduct internal research to develop, improve, or repair products,15service, or technology.16(2) Effectuate a product recall.17(3) Identify and repair technical errors that impair existing or intended18functionality.19(4) Perform internal operations that are reasonably aligned with the20expectations of the consumer or reasonably anticipated based on the consumer's21existing relationship with the controller, or are otherwise compatible with22processing data in furtherance of the provisions of a product or service23specifically requested by a consumer or the performance of a contract to which24the consumer is a party.25J. The obligations imposed on controllers or processors pursuant to this26Chapter shall not apply where compliance by the controller or processor with27said Sections would violate an evidentiary privilege pursuant to the laws of this28state. Nothing in this Chapter shall be construed to prevent a controller or29processor from providing personal data concerning a consumer to a person30covered by an evidentiary privilege pursuant to the laws of the state as part ofPage 23 of 26Coding: Words which are struck through are deletions from existing law;words in boldface type and underscored are additions.SB NO. 386 ENROLLED1a privileged communication.2K. Nothing in this Chapter shall be construed to impose any obligation3on a controller or processor that adversely affects the rights or freedoms of any4person, including but not limited to the rights of any person to freedom of5speech or freedom of the press guaranteed in the First Amendment to the6United States Constitution.7L.(1) Personal data processed by a controller pursuant to this Section8may be processed to the extent that such processing is both of the following:9(a) Reasonably necessary and proportionate to the purposes listed in this10Section.11(b) Adequate, relevant, and limited to what is necessary in relation to the12specific purposes listed in this Section.13(2) Personal data collected, used, or retained pursuant to Subsection I of14this Section shall, where applicable, take into account the nature and purpose15or purposes of such collection, use, or retention. Such data shall be subject to16reasonable administrative, technical, and physical measures to protect the17confidentiality, integrity, and accessibility of the personal data and to reduce18reasonably foreseeable risks of harm to consumers relating to such collection,19use, or retention of personal data.20M. If a controller processes personal data pursuant to an exemption in21this Section, the controller bears the burden of demonstrating that such22processing qualifies for the exemption and complies with the requirements in23Subsection L of this Section.24N. Processing personal data for the purposes expressly identified in25Subsections G through I of this Section shall not solely make a legal entity a26controller with respect to such processing.27O.(1) The consumer rights pursuant to R.S. 51:1780.3(A)(2)(a) through28(e) and controller duties pursuant to this Section do not apply to pseudonymous29data in cases in which the controller is able to demonstrate any information30necessary to identify the consumer is kept separately and is subject to effectivePage 24 of 26Coding: Words which are struck through are deletions from existing law;words in boldface type and underscored are additions.SB NO. 386 ENROLLED1technical and organizational controls that prevent the controller from accessing2the information.3(2) A controller that discloses pseudonymous data or deidentified data4shall exercise reasonable oversight to monitor compliance with any contractual5commitments to which the pseudonymous data or deidentified data is subject6and shall take appropriate steps to address any breach of the contractual7commitments.8P.(1) A person or entity described by R.S. 51:1780.2(A)(3) may not9engage in the sale of personal data that is sensitive data without receiving prior10consent from the consumer.11(2) A person who violates this Section is subject to the penalty under R.S.1251:1780.5.13§1780.5. Enforcement14A. The attorney general shall enforce the provisions of this Chapter.15B. The attorney general shall post on his website, information relating16to the responsibilities of a controller and a processor and consumer rights17pursuant to this Chapter.18C. Any violation of the provisions of this Chapter shall constitute an19unfair and deceptive trade practice pursuant to the Unfair Trade Practices and20Consumer Protection Law, R.S. 51:1401 et seq., excluding private rights of21action as provided in R.S. 51:1409 and 1409.1. Notwithstanding any other22provision of law to the contrary, any monies received related to the attorney23general's enforcement of this Chapter shall be used by the attorney general for24consumer protection efforts or to promote consumer protection and education.25D. Beginning January 1, 2027, and ending July 31, 2027, before bringing26an action pursuant to this Section, the attorney general shall notify a person in27writing, not later than the thirtieth calendar day before initiating an28investigation, identifying the specific provisions of this Chapter the attorney29general alleges is being violated. The attorney general shall not initiate an30investigation against the person if the person does all of the following:Page 25 of 26Coding: Words which are struck through are deletions from existing law;words in boldface type and underscored are additions.SB NO. 386 ENROLLED1(1) Cures the alleged violation identified by the attorney general within2the thirty-day period.3(2) Provides the attorney general with a written statement that the4person cured the alleged violation.5(3) Submits supportive documentation to the attorney general to show6how the privacy violation was cured.7(4) Changes are made to the internal policy, if necessary, to ensure that8no such further violations occur.9Section 2. This Act shall become effective on January 1, 2027.PRESIDENT OF THE SENATESPEAKER OF THE HOUSE OF REPRESENTATIVESGOVERNOR OF THE STATE OF LOUISIANAAPPROVED:Page 26 of 26Coding: Words which are struck through are deletions from existing law;words in boldface type and underscored are additions.
Provides for opting out of providing personal information on social media websites. (1/1/27)
Sponsors
Sen. Patrick Connick (R) sponsors SB 386, and 11 members have co-sponsored it.

Sen. · R–8 · Sponsor

Sen. · D–15 · Co-sponsor

Sen. · R–9 · Co-sponsor

Sen. · D–34 · Co-sponsor

Sen. · D–39 · Co-sponsor

Sen. · D–29 · Co-sponsor

Sen. · R–19 · Co-sponsor

Sen. · D–2 · Co-sponsor

Sen. · D–14 · Co-sponsor

Sen. · R–27 · Co-sponsor
Committees
SB 386 went before 2 committees: Commerce, Consumer Protection, and International Affairs and Commerce.

History
SB 386 has taken 19 actions since Feb 27, 2026, the latest on May 29, 2026.
| Chamber | Action | |||
|---|---|---|---|---|
May 29, 2026 | Senate | Signed by the Governor. Becomes Act No. 502. | ||
May 29, 2026 | Senate | Effective date 1/1/2027. | ||
May 25, 2026 | House | Signed by the Speaker of the House. | ||
May 21, 2026 | Senate | Enrolled. Signed by the President of the Senate. | ||
May 21, 2026 | Senate | Sent to the Governor by the Secretary of the Senate. |
Votes
SB 386 went to 4 roll calls across both chambers, the latest on May 20, 2026 at 34–0.
| Chamber | Question | Yea | Nay | |||
|---|---|---|---|---|---|---|
May 20, 2026 | Senate | Senate Vote on SB 386 CONCUR (#1044) | 34 | 0 | ||
May 18, 2026 | House | House Vote on SB 386 FINAL PASSAGE (#1341) | 94 | 0 | ||
Apr 8, 2026 | Senate | Senate Vote on SB 386 FINAL PASSAGE (#284) | 36 | 0 | ||
Apr 8, 2026 | Senate | Senate Vote on SB 386 CO-AUTHORS (#285) | 10 | 0 |
Source: legis.la.gov · legiscan.com
