Revises provisions relating to the processing of certain data. (BDR 52-505)
What changed between versions
Title and summary changed from focusing on 'use of certain online products and services by minors' to 'processing of certain data' to reflect broader data protection focus
New section 32.5 requires controllers with de-identified data to commit not to re-identify it and contractually bind recipients to comply with the same requirements
Section 33 expanded to prohibit further processing of children's data for purposes other than those disclosed to the child, unless necessary and compatible with the original purpose
Section 33 now requires controllers to disclose to children the purposes of additional processing when collecting their data with intent to process further
Section 34 now requires data protection assessments for each processing activity directed at children, with provisions for submitting assessments to the Attorney General
Section 32 exemptions now include 'activities' in addition to entities and types of data
Section 27 definition of 'controller' now explicitly includes determining 'the purpose and means of processing personal data'
New provisions clarify that disclosing data protection assessments to the Attorney General does not waive evidentiary privileges
Reprint date changed from May 26, 2025 to June 2, 2025, indicating additional amendments were adopted