HB 5032, titled "Prevention of data center collection of citizen data," creates the Citizens' Data Center Transparency Act. It prohibits West Virginia data centers from facilitating warrantless collection of personal data by federal agencies (like the NSA) or others in ways violating the Fourth Amendment or West Virginia’s Constitution. The bill requires data center operators to annually report to the Joint Standing Committee on Technology and Infrastructure the types and amounts of data collected, how it’s used, and who the data is shared with (including government agencies or nonprofits). This law directly affects data center operators in West Virginia and aims to increase transparency around data handling practices.
HB 5551 requires West Virginia to continue issuing non-REAL ID compliant driver's licenses and ID cards, clearly marked "NOT FOR REAL ID ACT PURPOSES," which remain valid for all state purposes like driving and identity verification. The bill prohibits the state from collecting biometric data (such as facial scans or fingerprints), retaining copies of identity documents (like birth certificates or Social Security cards), or sharing personal information from these licenses with federal or interstate databases. It mandates that applicants be informed of their choice between REAL ID and non-REAL ID options and provided with a list of TSA-acceptable IDs, while banning digital IDs and requiring physical licenses for all purposes. The law also prohibits state agencies from entering agreements that conflict with these protections.
HB 5123, the Consumer Data Protection Act, gives West Virginia consumers new rights over their personal data held by businesses. It requires businesses meeting size thresholds (like $25 million in annual revenue or handling data from 50,000+ consumers) to let consumers access, delete, correct, or opt out of selling their information. The law prohibits businesses from discriminating against consumers who exercise these rights and allows individuals to sue for violations. The West Virginia Division of Consumer Protection will enforce the law and create rules for implementation.
HB 5034, the West Virginia Genomic Information Privacy Act of 2026, requires medical facilities, research organizations, and companies collecting genetic data to inform West Virginia residents about how their genetic information is gathered, used, and shared. The bill prohibits these entities from selling, transferring, or using genetic data for foreign adversaries (as defined by federal law) and mandates secure storage of such information. It also establishes a private right of action, allowing individuals to sue if their genetic privacy is violated.
HB 5427, the "Anti-Doxxing and Privacy Protection Act," prohibits publishing another person's personally identifiable information (PII) without consent when intending to harass, threaten, stalk, or cause harm. It directly affects individuals who engage in malicious doxxing (e.g., sharing home addresses, phone numbers, or location data to intimidate) and protects victims, including public officials, healthcare workers, and private citizens. Key provisions establish criminal penalties for violations, allow civil lawsuits for victims, and create procedures for redacting PII from public records when safety is at risk. The bill explicitly excludes lawful public records disclosures, judicial proceedings, and good-faith journalism to preserve constitutional protections.
HB 5138 requires law enforcement agencies to obtain a warrant before accessing most personal information held by internet and phone companies, such as names, addresses, payment details, and call records. It directly affects law enforcement agencies and telecommunications providers by mandating judicial oversight for these data requests during criminal investigations. The bill allows warrantless access only in specific emergencies (e.g., imminent risk of death, kidnapping, or human trafficking), with subscriber consent, or if the data is publicly accessible. This replaces current practices where such third-party records could often be obtained without a warrant.
HB 5567, the Biometric Information Privacy Act, requires private businesses (like retailers or tech companies) to create written policies for securely storing and permanently destroying customers' biometric data - such as fingerprints, facial scans, or voiceprints - within three years of the last interaction or when the data's purpose is fulfilled. It explicitly excludes health-related biometric data (covered under federal HIPAA) and common identifiers like Social Security numbers. The bill mandates that businesses obtain written consent before collecting biometric information and provides individuals with a legal right to sue if their data is mishandled. This law directly affects private entities using biometrics for identification, aiming to prevent irreversible identity theft risks by regulating how such sensitive data is managed.
HB 4843 prohibits businesses in West Virginia from using scanner technology to collect personal details like driver's license numbers, Social Security numbers, or medical history during consumer transactions - except for verifying age. The bill defines "scanner technology" as devices that capture license barcodes/magnetic strips, print age results, store transaction records, and transfer data, banning their use for collecting non-age PII. It directly affects retailers, bars, or any business using such scanners for age verification or data collection. Violations are classified as unfair or deceptive business practices under West Virginia law, creating enforceable penalties. The bill focuses solely on restricting specific scanner technology, not general data privacy rules.
HB 4868, the West Virginia Consumer Privacy Act of 2026, requires businesses like financial institutions, creditors, mortgage lenders, and brokers to obtain explicit "opt-in" consent from consumers before disclosing or selling their personal financial information. It directly affects West Virginia consumers who apply for credit or engage in financial transactions, granting them the right to know what data is shared and control its use. Key provisions mandate clear disclosure of data practices, prevent unauthorized sharing, and impose fines of up to $10,000 per violation for non-compliance. The bill aims to strengthen privacy protections against identity theft and deceptive practices by giving consumers active control over their financial information.
HB 4496 requires creators and distributors of AI-generated media (such as videos, audio, or images) to include clear, visible disclosures identifying the content as artificial intelligence-generated. This applies to any public-facing media created or materially altered by AI, mandating specific disclosures like a 3-second on-screen label for videos or a spoken statement for audio content. Exceptions include internal research, basic AI-assisted editing (e.g., spell-check), and privately shared personal content. Violations could result in civil penalties of up to $100,000 per day for organizations or $1,000 per day for individuals.