#
Real, enforceable sectoral obligations exist (MHMDA, biometric law, breach notice) but there is no general omnibus statute or dedicated DPA — coverage is fragmented and health/biometric-centric.
Sub-modules (5)
Regulator And AuthorityAmber
The WA AG enforces sectoral privacy statutes; there is no privacy-specific regulator or DPA.
Claims (1):
- Washington State has no dedicated data-protection supervisory authority; the Washington State Attorney General enforces sectoral privacy statutes, including the My Health My Data Act, under its consumer-protection enforcement powers.
Act And InstrumentsAmber
Sectoral instruments (MHMDA, biometric law, breach law) exist; the comprehensive Washington Privacy Act never passed.
Claims (2):
- Washington's data-protection landscape is sectoral rather than comprehensive, anchored by the My Health My Data Act (enacted 27 April 2023), the Washington Biometric Privacy Protection Act (RCW 19.375, effective 23 July 2017), and the state's general data-breach notification statute.
- Washington never enacted a GDPR/CCPA-style comprehensive consumer privacy statute; the Washington Privacy Act, which served as a model for several other states' comprehensive privacy laws, failed repeatedly in the Washington legislature and was never signed into law.
Material ScopeAmber
MHMDA's broad definitions bring a wide range of data/entities into scope.
Claims (1):
- The My Health My Data Act's broad definitions of 'consumer,' 'covered data' and 'health care services' bring a wide range of data types and entities into scope.
Territorial ScopeAmber
MHMDA applies extraterritorially to out-of-state businesses processing WA consumers' health data per AG guidance.
Claims (1):
- The Washington Attorney General's My Health My Data Act FAQ specifically addresses the law's impact on businesses located outside Washington State, indicating extraterritorial application to entities processing Washington consumers' health data.
Regulator Registration And FilingAmber
No registration/filing regime; MHMDA requires a published consumer health data privacy policy instead.
Claims (1):
- The My Health My Data Act does not require regulatory registration or filing with the Attorney General, but does require regulated entities to publish a consumer health data privacy policy disclosing categories of data collected, purposes, and third-party sharing.
Sources and claims (6)
- ConfirmedIAPP — Washington State has no dedicated data-protection supervisory authority; the Washington State Attorney General enforces sectoral privacy statutes, including the My Health My Data Act, under its consumer-protection enforcement powers.observed
- ConfirmedOneTrust DataGuidance — Washington's data-protection landscape is sectoral rather than comprehensive, anchored by the My Health My Data Act (enacted 27 April 2023), the Washington Biometric Privacy Protection Act (RCW 19.375, effective 23 July 2017), and the state's general data-breach notification statute.observed
- ConfirmedIAPP — Washington never enacted a GDPR/CCPA-style comprehensive consumer privacy statute; the Washington Privacy Act, which served as a model for several other states' comprehensive privacy laws, failed repeatedly in the Washington legislature and was never signed into law.observed
- ConfirmedIAPP — The My Health My Data Act's broad definitions of 'consumer,' 'covered data' and 'health care services' bring a wide range of data types and entities into scope.observed
- ProbableIAPP — The Washington Attorney General's My Health My Data Act FAQ specifically addresses the law's impact on businesses located outside Washington State, indicating extraterritorial application to entities processing Washington consumers' health data.observed
- ConfirmedIAPP — The My Health My Data Act does not require regulatory registration or filing with the Attorney General, but does require regulated entities to publish a consumer health data privacy policy disclosing categories of data collected, purposes, and third-party sharing.observed