Menstrual Data Privacy and Protection Act; enact
HB827 would create the “Menstrual Data Privacy and Protection Act” and add a new article to Georgia’s trade practices code governing the collection and use of menstrual and reproductive health data. The bill defines “menstrual data,” “entity,” and “explicit consent,” and requires entities such as apps, pharmacies, healthcare providers, clinics, hospitals, and retailers to obtain clear affirmative consent before collecting, processing, or sharing that data. It also limits use of the data to the specific purposes disclosed in the consent agreement and prohibits selling menstrual or reproductive health data to third parties altogether.
The bill further requires covered entities to adopt industry-standard security measures, including encryption, security audits, and vulnerability assessments, and to notify affected individuals and the Attorney General within 72 hours of a breach. Individuals would have the right to request deletion of their menstrual data, with entities required to comply within 30 days and ensure the data is not retained by partners. Covered entities must also publish public privacy policies and annual reports describing data practices, security measures, and breaches.
HB827 would expand Georgia consumer privacy and data protection law by creating specific statutory protections for menstrual and reproductive health information. It would impose new compliance obligations on businesses and healthcare-related entities that collect such data, restrict secondary uses such as marketing and targeted advertising without additional consent, and create a private right of action and Attorney General enforcement authority with civil penalties, injunctive relief, and damages. The bill would affect digital health apps, retailers, pharmacies, and medical providers that handle sensitive reproductive health information.
The bill text reflects a strong privacy-protection approach, with broad restrictions on collection, sharing, sale, and retention of menstrual data. Because there are no committee transcripts or recorded votes provided, there is no direct evidence of legislative debate or formal support/opposition in the available record. Based on the bill’s structure, its overall tone is protective of consumer privacy and reproductive health autonomy.
The main likely points of contention are the scope of the data restrictions and the compliance burden on covered entities. Businesses, app developers, pharmacies, and healthcare providers may object to the ban on selling menstrual data, the limits on marketing and targeted advertising, the 72-hour breach notice requirement, and the deletion mandate. Supporters would likely emphasize the sensitivity of menstrual and reproductive health information and the need to prevent misuse, surveillance, and unauthorized sharing. No specific disagreements are documented in the provided materials.