LRB-5265/1
KP:cdc
2021 - 2022 LEGISLATURE
January 6, 2022 - Introduced by Representatives Brostoff, Hebl, Milroy,
Cabrera, Andraca, Anderson, Subeck and Sinicki, cosponsored by Senators
Larson, Carpenter, Roys and Smith. Referred to Committee on Energy and
Utilities.
AB807,1,3
1An Act to create 100.75 of the statutes;
relating to: privacy and security of
2customer information obtained by a broadband Internet access service provider
3and providing a penalty.
Analysis by the Legislative Reference Bureau
This bill generally prohibits a broadband Internet access service provider
(“provider”) from using, disclosing, or permitting access to a customer's proprietary
information unless the customer grants approval to the provider to use, disclose, or
permit access to that information. The bill defines “customer” as 1) a current or
former subscriber to broadband Internet access service who resides in this state; or
2) a person who resides in this state and uses broadband Internet access service that
is provided under an agreement between a current or former subscriber who resides
in this state and a provider. With certain exceptions described below, the bill requires
different types of approval for sensitive and nonsensitive customer proprietary
information. For sensitive information, the customer must grant express,
affirmative consent after receiving a notification that is required to accompany a
provider's request to use, disclose, or permit access to that information. Sensitive
information includes the following: 1) financial information; 2) health information;
3) information pertaining to a child; 4) a social security number; 5) precise
geolocation information; 6) content of communications; and 7) web browsing history
and smart phone or tablet computer application usage history.
For nonsensitive information, the customer must object to the provider's
request to use, disclose, or permit access to that information after the customer
receives a notification that is required to accompany the provider's request. Under
the bill, nonsensitive information is the following information that is not sensitive
information: 1) information that is linked or reasonably able to be linked to an
individual or a device; or 2) information that identifies an individual and that relates
to the quantity, technical configuration, type, destination, location, or amount of use
of broadband Internet access service.
Also, under the bill, a provider is prohibited from refusing to provide broadband
Internet access service because a customer or prospective customer does not grant
approval to the provider to use, disclose, or permit access to proprietary information.
The bill allows a provider to use, disclose, or permit access to both sensitive and
nonsensitive customer proprietary information without receiving the customer's
approval only for the following purposes: 1) to provide the broadband Internet access
service from which the information is derived; 2) to initiate, render, bill, or collect for
broadband Internet access service; 3) to protect the rights or property of a provider
or to protect users against fraudulent, abusive, or unlawful use of the service; 4) to
provide certain services to a customer during a real-time interaction with the
provider initiated by the customer; 5) to provide location information or nonsensitive
information in emergencies; or 6) as otherwise required or authorized by law.
Under the bill, when a provider requests approval to use, disclose, or permit
access to a customer's proprietary information, the provider's request must
accompany a notice that includes a specific description of the following: 1) the types
of customer proprietary information that the provider will collect from providing
broadband Internet access service, and how it will use the information; 2) the
circumstances under which the provider discloses or permits access to each type of
customer proprietary information that it collects; 3) the categories of entities to
which the provider discloses or permits to access the customer's proprietary
information and the purposes for which that information will be used by each
category of entity; and 4) the customer's rights to grant, deny, or withdraw approval
concerning the customer's proprietary information. The notice must also include
access to a mechanism that the customer can use to grant, deny, or withdraw
approval at any time.
The bill requires that when a provider makes a material change to its policies
concerning the privacy of customer proprietary information, the provider must give
to each customer a similar notice that also includes a specific description of the
changes made to the privacy policies. The bill also requires that all notices and
mechanisms used for granting, denying, or withdrawing approval be translated into
the language that the provider uses to transact business with a customer.
The bill requires providers to take reasonable security measures to protect
customer proprietary information from unauthorized use, disclosure, or access.
Further, when a breach of the provider's security occurs, the provider is required to
notify each affected customer within 30 days after learning of the breach unless the
provider reasonably determines that no harm to the customer is reasonably likely to
occur as a result. The notification must describe the information that is reasonably
believed to have been involved in the security breach and include information about
how to contact the provider to inquire about the security breach and how to contact
relevant government agencies. If the security breach creates a risk of financial harm,
the notification must also include information about steps that the customer can take
to guard against identity theft.
The bill also requires a provider to notify the Department of Agriculture, Trade
and Consumer Protection and the Department of Justice within seven business days
of learning about a breach of security affecting 5,000 or more customers unless the
provider reasonably determines that no harm to customers is reasonably likely to
occur as a result of the breach. If a breach of security affects fewer than 5,000
customers, the bill requires a provider to notify DATCP within 30 days after learning
about the breach. Under the bill, a provider is required to maintain records for two
years that contain information about the notifications made to customers about a
breach of security.
A broadband Internet access service provider that intentionally violates the bill
is subject to a criminal fine of up to $1,000, or up to three months in jail, or both.
Alternatively, a provider that violates the bill is subject to a civil forfeiture of up to
$50,000 for the first violation, and up to $100,000 for each subsequent violation.
Additionally, under the bill, any person or class of persons that is adversely affected
by a violation by a broadband Internet access service provider can sue the provider
for appropriate relief. The bill also authorizes 1) DATCP; 2) DOJ, after consulting
with DATCP; or 3) any district attorney, upon informing DATCP, to bring an action
to restrain by temporary or permanent injunction any violation of the bill.
For further information see the state fiscal estimate, which will be printed as
an appendix to this bill.
The people of the state of Wisconsin, represented in senate and assembly, do
enact as follows:
AB807,1
1Section
1. 100.75 of the statutes is created to read:
AB807,3,3
2100.75 Privacy and security of information obtained by an Internet
3service provider. (1) Definitions. In this section:
AB807,3,64
(a) “Breach of security” means any instance in which a person, without
5authorization or exceeding authorization, has gained access to, used, or disclosed
6customer proprietary information.
AB807,4,27
(b) 1. “Broadband Internet access service” means a mass-market retail service
8by wire or radio that provides the capability to transmit data and receive data from
9all or substantially all Internet endpoints, including any capabilities that are
1incidental to and enable the operation of the service, but excluding dial-up Internet
2access service.
AB807,4,53
2. “Broadband Internet access service” includes any service that the
4department finds is a functional equivalent of the service specified in subd. 1. or is
5used to evade the requirements under this section.
AB807,4,66
(c) “Customer” means any of the following:
AB807,4,87
1. A current or former subscriber to broadband Internet access service who
8resides in this state.
AB807,4,129
2. A person who resides in this state and uses or has used broadband Internet
10access service that is provided under an agreement between a current or former
11subscriber who resides in this state and a broadband Internet access service
12provider.
AB807,4,1413
(d) “Customer proprietary information” means any of the following
14information:
AB807,4,1815
1. Individually identifiable information that relates to the quantity, technical
16configuration, type, destination, location, or amount of use of a broadband Internet
17access service subscribed to by a customer of a provider of that service, and that is
18made available to the provider by the customer.
AB807,4,2019
2. Any information that is linked or reasonably able to be linked to an
20individual or a device.
AB807,4,2121
3. Content of a customer's communications.
AB807,4,2522
(e) “Material change” means any change that a customer, acting reasonably
23under the circumstances, would consider important to his or her decisions
24concerning his or her privacy, including any change to information required to be
25presented in the notice required under sub. (2) (b).
AB807,5,2
1(f) “Nonsensitive customer proprietary information” means customer
2proprietary information that is not sensitive customer proprietary information.
AB807,5,53
(g) “Opt-in approval” means the method for obtaining customer consent in
4which a provider obtains from the customer affirmative, express consent after the
5customer is provided appropriate notification of the provider's request for consent.
AB807,5,96
(h) “Opt-out approval” means the method for obtaining customer consent in
7which a customer is deemed to have consented if the customer has failed to object to
8a provider's request after the customer is provided with appropriate notification of
9the provider's request for consent.
AB807,5,1110
(i) “Prospective customer” means an applicant for broadband Internet access
11service who resides in this state.
AB807,5,1312
(j) “Sensitive customer proprietary information” means customer proprietary
13information that is any of the following:
AB807,5,1414
1. Financial information.
AB807,5,1515
2. Health information.
AB807,5,1616
3. Information pertaining to a child.
AB807,5,1717
4. A social security number.
AB807,5,1818
5. Precise geolocation information.
AB807,5,1919
6. Content of communications.
AB807,5,2120
7. Web browsing history, smart phone or tablet computer application usage
21history, and the functional equivalents of either.
AB807,5,2422
(k) “Subscriber” means a person who enters into an agreement for the provision
23of broadband Internet access services with a provider of broadband Internet access
24services. “Subscriber” does not include a person who resells services.
AB807,6,4
1(2) Notice requirements. (a)
When notice required. 1. A broadband Internet
2access service provider shall make a notice available at all times to customers about
3its policies concerning the privacy of the information that the provider obtains about
4customers.
AB807,6,75
2. A broadband Internet access service provider shall notify a prospective
6customer, at the point of sale, prior to a purchase of service, about its policies
7concerning the privacy of information that the provider obtains about customers.
AB807,6,98
(b)
Contents. A broadband Internet access service provider shall include all of
9the following in the notice provided to customers under par. (a):
AB807,6,1210
1. A specific description of the types of customer proprietary information that
11the broadband Internet access service provider collects from providing broadband
12Internet access service and how it uses that information.
AB807,6,1513
2. A specific description of the circumstances under which the broadband
14Internet access service provider discloses or permits access to each type of customer
15proprietary information that it collects.
AB807,6,1916
3. A specific description of the categories of entities to which the broadband
17Internet access service provider discloses or permits to access customer proprietary
18information and the purposes for which that information will be used by each
19category of entities.
AB807,6,2220
4. A specific description of the customer's rights to grant, deny, or withdraw
21approval concerning the customer's proprietary information, including each of the
22following:
AB807,6,2523
a. A statement that the customer's denial or withdrawal of approval to use,
24disclose, or permit access to customer proprietary information will not affect the
25provision of any broadband Internet access services to the customer.
AB807,7,3
1b. A statement that any grant, denial, or withdrawal of approval for the use,
2disclosure, or permission of access to customer proprietary information is valid until
3the customer affirmatively revokes the grant, denial, or withdrawal.
AB807,7,54
c. A statement that the customer has the right to deny or withdraw approval
5to use, disclose, or permit access to customer proprietary information at any time.
AB807,7,66
5. Access to a mechanism required under sub. (3) (d) 3.
AB807,7,117
(c)
Material changes to a privacy policy. A broadband Internet access service
8provider shall provide a notice, through electronic mail or another means of prompt
9communication agreed upon by the customer, to a customer of a material change to
10its policies concerning the privacy of information that the provider obtains about the
11customer. The notice shall include all of the following:
AB807,7,1612
1. A specific description of the changes made to the provider's privacy policies,
13including any changes to what customer proprietary information the provider
14collects; how the provider uses, discloses, or permits access to that information; the
15categories of entities to which it discloses or permits access to customer proprietary
16information; and which, if any, changes are retroactive.
AB807,7,1717
2. The description required under par. (b) 4.
AB807,7,1818
3. Access to a mechanism required under sub. (3) (d) 3.
AB807,7,2219
(d)
When translation required. If a broadband Internet access service provider
20transacts business with a customer in a language other than English, the provider
21shall translate the contents of the notices required under pars. (b) and (c) into the
22language through which the provider transacts business with the customer.
AB807,7,25
23(3) Customer approval. (a)
Opt-in approval required. Except as provided
24under par. (c), a broadband Internet access service provider may not do any of the
25following unless the provider obtains opt-in approval from the customer:
AB807,8,2
11. Use, disclose, or permit access to any of the customer's sensitive customer
2proprietary information.
AB807,8,53
2. Use, disclose, or permit access to any of the customer's proprietary
4information previously collected by the provider for which the customer has not
5previously granted approval under this paragraph or par. (b).
AB807,8,96
(b)
Opt-out approval required. 1. Except as provided under subd. 2. or par. (c),
7a broadband Internet access service provider may not use, disclose, or permit access
8to any of a customer's nonsensitive customer proprietary information unless the
9provider obtains opt-out approval from the customer.
AB807,8,1210
2. A broadband Internet access service provider may obtain opt-in approval
11from a customer to use, disclose, or permit access to any of the customer's
12nonsensitive customer proprietary information.
AB807,8,1613
(c)
Permissible use without customer approval. A broadband Internet access
14service provider may use, disclose, or permit access to customer proprietary
15information without approval from the customer under par. (a) or (b) only for the
16following purposes:
AB807,8,1917
1. To provide the broadband Internet access service from which the information
18is derived, or in its provision of services necessary to, or used in, the provision of that
19service.
AB807,8,2020
2. To initiate, render, bill, or collect for broadband Internet access service.