🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
US-WA v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing18 sources retrieved model claude-sonnet-5 · 2026-08-06

Washington State, USA

US-WA schema gdpri-v2 trajectory: not yet assessedhybrid regimeoverlaps: AIC

Last updated · 10 categories · 25 claims · 27 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
25Claimsbaseline..claims[]
11Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Standing brief, as of 28 September 2026.

Lead Signal

Washington State's data-protection picture this cycle is defined not by new legislation but by the widening practical reach of an existing sectoral statute. The My Health My Data Act, RCW 19.373, remains Washington's flagship privacy instrument in the absence of any enacted comprehensive consumer-privacy law, and the activity surfacing this cycle sits at the boundary of what that Act's health-data definition actually covers when applied to commercial adtech practices. A pending class action against a Seattle-area cannabis retailer, filed in November 2025 and reported still pending as of May 2026, alleges that website tracking pixels and cookies transmitted personal information, including medical marijuana appointment and product-purchase details, to third parties without consent, raising the question of whether such data qualifies as consumer health data under RCW 19.373.010. Reports suggest this litigation, together with a parallel action against Amazon's advertising business, indicates enforcement activity reaching adtech-adjacent commercial defendants ahead of, rather than through, traditional healthcare defendants, though this pattern signal is not yet independently confirmed against a primary court-docket source.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Real, enforceable sectoral obligations exist (MHMDA, biometric law, breach notice) but there is no general omnibus statute or dedicated DPA — coverage is fragmented and health/biometric-centric.

Primary frameworkMy Health My Data Act (HB 1155); Washington Biometric Privacy Protection Act (RCW 19.375); Washington data-breach notification statute; federal FTC Act Section 5 baseline — no comprehensive consumer-privacy statute in force
Traffic-light rationale — AmberReal, enforceable sectoral obligations exist (MHMDA, biometric law, breach notice) but there is no general omnibus statute or dedicated DPA — coverage is fragmented and health/biometric-centric.

Sub-modules (5)

Regulator And AuthorityAmber

The WA AG enforces sectoral privacy statutes; there is no privacy-specific regulator or DPA.

Claims (1):

  • Washington State has no dedicated data-protection supervisory authority; the Washington State Attorney General enforces sectoral privacy statutes, including the My Health My Data Act, under its consumer-protection enforcement powers.

Act And InstrumentsAmber

Sectoral instruments (MHMDA, biometric law, breach law) exist; the comprehensive Washington Privacy Act never passed.

Claims (2):

  • Washington's data-protection landscape is sectoral rather than comprehensive, anchored by the My Health My Data Act (enacted 27 April 2023), the Washington Biometric Privacy Protection Act (RCW 19.375, effective 23 July 2017), and the state's general data-breach notification statute.
  • Washington never enacted a GDPR/CCPA-style comprehensive consumer privacy statute; the Washington Privacy Act, which served as a model for several other states' comprehensive privacy laws, failed repeatedly in the Washington legislature and was never signed into law.

Material ScopeAmber

MHMDA's broad definitions bring a wide range of data/entities into scope.

Claims (1):

  • The My Health My Data Act's broad definitions of 'consumer,' 'covered data' and 'health care services' bring a wide range of data types and entities into scope.

Territorial ScopeAmber

MHMDA applies extraterritorially to out-of-state businesses processing WA consumers' health data per AG guidance.

Claims (1):

  • The Washington Attorney General's My Health My Data Act FAQ specifically addresses the law's impact on businesses located outside Washington State, indicating extraterritorial application to entities processing Washington consumers' health data.

Regulator Registration And FilingAmber

No registration/filing regime; MHMDA requires a published consumer health data privacy policy instead.

Claims (1):

  • The My Health My Data Act does not require regulatory registration or filing with the Attorney General, but does require regulated entities to publish a consumer health data privacy policy disclosing categories of data collected, purposes, and third-party sharing.
Category narrative102 words

Washington State has no dedicated data-protection regulator and no comprehensive omnibus consumer-privacy statute. The Washington State Attorney General enforces sectoral privacy laws — principally the My Health My Data Act (HB 1155, 2023) and the Washington Biometric Privacy Protection Act (RCW 19.375, 2017) — under its general Consumer Protection Act authority. The influential Washington Privacy Act (WaPA), which served as a legislative template copied by Virginia, Colorado and other states, was itself never enacted in Washington despite multiple attempts (2019–2022). The federal FTC Act Section 5 unfair/deceptive-practices authority applies as a national baseline. This is a sectoral patchwork, not an omnibus regime.

Sources and claims (6)
  1. ConfirmedIAPP — Washington State has no dedicated data-protection supervisory authority; the Washington State Attorney General enforces sectoral privacy statutes, including the My Health My Data Act, under its consumer-protection enforcement powers.observed
  2. ConfirmedOneTrust DataGuidance — Washington's data-protection landscape is sectoral rather than comprehensive, anchored by the My Health My Data Act (enacted 27 April 2023), the Washington Biometric Privacy Protection Act (RCW 19.375, effective 23 July 2017), and the state's general data-breach notification statute.observed
  3. ConfirmedIAPP — Washington never enacted a GDPR/CCPA-style comprehensive consumer privacy statute; the Washington Privacy Act, which served as a model for several other states' comprehensive privacy laws, failed repeatedly in the Washington legislature and was never signed into law.observed
  4. ConfirmedIAPP — The My Health My Data Act's broad definitions of 'consumer,' 'covered data' and 'health care services' bring a wide range of data types and entities into scope.observed
  5. ProbableIAPP — The Washington Attorney General's My Health My Data Act FAQ specifically addresses the law's impact on businesses located outside Washington State, indicating extraterritorial application to entities processing Washington consumers' health data.observed
  6. ConfirmedIAPP — The My Health My Data Act does not require regulatory registration or filing with the Attorney General, but does require regulated entities to publish a consumer health data privacy policy disclosing categories of data collected, purposes, and third-party sharing.observed

#

Robust consent/necessity rules exist for health and biometric data specifically, but no general lawful-basis framework covers personal data broadly.

Primary frameworkMy Health My Data Act consent/necessity framework; Washington Biometric Privacy Protection Act (RCW 19.375)
Traffic-light rationale — AmberRobust consent/necessity rules exist for health and biometric data specifically, but no general lawful-basis framework covers personal data broadly.

Sub-modules (4)

Lawful BasesAmber

Consent-or-necessity standard under MHMDA; no general lawful-basis enumeration exists.

Claims (1):

  • The My Health My Data Act permits collection of consumer health data only on the basis of consumer consent or a defined necessity standard; Washington has no broader enumerated set of lawful bases for personal data generally.

Special CategoriesAmber

Consumer health data (including reproductive/gender-affirming care data) and biometric identifiers are treated as specially protected categories under two separate statutes.

Claims (2):

  • The My Health My Data Act treats broadly defined 'consumer health data' as a specially protected category, filling a gap left by HIPAA's narrower scope, which does not reach data from many apps, wearables, and non-covered entities.
  • Washington's Biometric Privacy Protection Act (RCW 19.375, effective 23 July 2017) separately imposes notice-and-consent requirements on private entities enrolling a person's biometric identifiers in a database for commercial purposes, and the MHMDA additionally treats biometric data as consumer health data subject to its own private right of action.

Pseudonymisation And AnonymisationAmber

MHMDA defines 'deidentified data' with litigation-risk uncertainty around the standard's application.

Claims (1):

  • The My Health My Data Act defines 'deidentified data' among its core terms, though the Act's broad definitions and private right of action create litigation risk around what qualifies as properly deidentified data.
Category narrative56 words

Washington has no general enumerated set of lawful bases for processing personal data akin to GDPR Art 6. Instead, the My Health My Data Act imposes a consent-or-necessity standard specific to consumer health data, with heightened written-authorization requirements for sale, and Washington's Biometric Privacy Protection Act imposes separate notice-and-consent duties for commercial enrollment of biometric identifiers.

Sources and claims (5)
  1. ConfirmedIAPP — The My Health My Data Act permits collection of consumer health data only on the basis of consumer consent or a defined necessity standard; Washington has no broader enumerated set of lawful bases for personal data generally.observed
  2. ConfirmedIAPP — Under the My Health My Data Act, sharing consumer health data requires separate consent or satisfaction of the necessity standard, and selling consumer health data requires specific prior written and signed authorization from the consumer.observed
  3. ConfirmedIAPP — The My Health My Data Act treats broadly defined 'consumer health data' as a specially protected category, filling a gap left by HIPAA's narrower scope, which does not reach data from many apps, wearables, and non-covered entities.observed
  4. ConfirmedFederal Trade Commission — Washington's Biometric Privacy Protection Act (RCW 19.375, effective 23 July 2017) separately imposes notice-and-consent requirements on private entities enrolling a person's biometric identifiers in a database for commercial purposes, and the MHMDA additionally treats biometric data as consumer health data subject to its own private right of action.observed
  5. ProbableOneTrust DataGuidance — The My Health My Data Act defines 'deidentified data' among its core terms, though the Act's broad definitions and private right of action create litigation risk around what qualifies as properly deidentified data.observed

#

Meaningful rights exist but are scoped narrowly to consumer health data rather than personal data generally.

Primary frameworkMy Health My Data Act consumer rights (access, deletion, consent withdrawal)
Traffic-light rationale — AmberMeaningful rights exist but are scoped narrowly to consumer health data rather than personal data generally.

Sub-modules (5)

Access RightAmber

MHMDA grants a right to confirm and access whether/how health data is collected, shared or sold.

Claims (1):

  • The My Health My Data Act grants consumers the right to confirm whether a regulated entity is collecting, sharing, or selling their consumer health data, and to access that data.

Rectification And ErasureAmber

MHMDA grants rights to withdraw consent and to delete consumer health data.

Claims (1):

  • The My Health My Data Act grants consumers the right to access, delete, and withdraw consent from the collection, sharing, or sale of their health data.

Restriction And ObjectionRed

No general restriction/objection right beyond MHMDA's consent-withdrawal mechanism was identified.

Absence provenance: No statutory restriction-of-processing right beyond consent withdrawal identified for WA.. Searched: unavailable.

Data PortabilityRed

No statutory data-portability right exists under Washington law.

Absence provenance: No portability right identified in MHMDA or WA biometric law.. Searched: unavailable.

Deadlines And Response WindowsRed

No specific numeric statutory response-window for MHMDA rights requests was confirmed in available sources.

Absence provenance: Response-deadline specifics not located in T1/T2 sources retrieved.. Searched: unavailable.

Category narrative45 words

Data subject rights in Washington are confined to the health-data context under MHMDA: consumers have rights to confirm/access, withdraw consent, and delete consumer health data. There is no general right to restrict processing, no data-portability right, and no statutory deadline framework outside MHMDA's health-data scope.

Sources and claims (2)
  1. ConfirmedOneTrust DataGuidance — The My Health My Data Act grants consumers the right to confirm whether a regulated entity is collecting, sharing, or selling their consumer health data, and to access that data.observed
  2. ConfirmedIAPP — The My Health My Data Act grants consumers the right to access, delete, and withdraw consent from the collection, sharing, or sale of their health data.observed

#

Breach notification and MHMDA privacy-policy disclosure are binding; broader GDPR-style controller/processor accountability apparatus (DPIA, DPO, ROPA, security-measures mandates) is absent.

Primary frameworkWashington data-breach notification statute; My Health My Data Act privacy-policy disclosure duty
Traffic-light rationale — AmberBreach notification and MHMDA privacy-policy disclosure are binding; broader GDPR-style controller/processor accountability apparatus (DPIA, DPO, ROPA, security-measures mandates) is absent.

Sub-modules (7)

Accountability And DpiaRed

No general DPIA/accountability-principle statute identified for Washington.

Absence provenance: No DPIA trigger regime found outside MHMDA-specific duties.. Searched: unavailable.

Dpo RequirementsRed

No DPO appointment requirement identified under Washington law.

Absence provenance: No DPO mandate found.. Searched: unavailable.

Ropa RequirementsAmber

MHMDA's mandatory published consumer health data privacy policy functions as a public-facing analogue to a record of processing.

Claims (1):

  • The My Health My Data Act requires regulated entities to maintain and publish a consumer health data privacy policy disclosing categories of data collected, sources, purposes, and third parties with whom data is shared.

Joint Controller ArrangementsRed

No joint-controller concept defined in Washington law.

Absence provenance: GDPR-style joint-controller concept not present in WA sectoral statutes.. Searched: unavailable.

Security MeasuresRed

No general Washington statute mandates specific technical/organizational security measures beyond breach-notification triggers.

Absence provenance: No standalone security-measures mandate identified.. Searched: unavailable.

Breach NotificationAmber

Washington maintains a general data-breach notification statute, amended over time to strengthen requirements.

Claims (1):

  • Washington maintains a general data-breach notification statute requiring entities to notify affected state residents (and, above certain thresholds, the Attorney General) following breaches of specified personal information; the law has been amended over time to strengthen notification requirements.

Retention And DisposalRed

No specific statutory retention limit for general personal data was identified.

Absence provenance: No retention/disposal cap identified beyond MHMDA disclosure duties.. Searched: unavailable.

Category narrative49 words

There is no general accountability/DPIA, DPO, ROPA, joint-controller, or security-measures regime in Washington law outside sector-specific requirements. Washington's general data-breach notification statute requires notification of breaches of specified personal information, and MHMDA requires regulated entities to publish a consumer health data privacy policy that functions as a quasi-ROPA disclosure.

Sources and claims (2)
  1. ProbableNational Association of Attorneys General — Washington maintains a general data-breach notification statute requiring entities to notify affected state residents (and, above certain thresholds, the Attorney General) following breaches of specified personal information; the law has been amended over time to strengthen notification requirements.observed
  2. ConfirmedOneTrust DataGuidance — The My Health My Data Act requires regulated entities to maintain and publish a consumer health data privacy policy disclosing categories of data collected, sources, purposes, and third parties with whom data is shared.observed

#

Five of six sub-modules represent a genuine regulatory gap; only one MHMDA-derived proxy mechanism exists.

Primary frameworkMy Health My Data Act sale/sharing authorization requirement (partial proxy only)
Traffic-light rationale — RedFive of six sub-modules represent a genuine regulatory gap; only one MHMDA-derived proxy mechanism exists.

Sub-modules (6)

Transfer MechanismsAmber

MHMDA's consent/authorization rules for sharing/selling health data function as the state's primary transfer control.

Claims (1):

  • Washington State has no dedicated cross-border data-transfer mechanism regime; the My Health My Data Act's consent/authorization requirements for sharing and selling consumer health data function as the state's primary control on transfers of that data to third parties, wherever located.

Adequacy ReceivedRed

Not applicable/no finding — Washington is a US state, not a jurisdiction subject to adequacy determinations.

Absence provenance: Adequacy-decision concept inapplicable to sub-federal US jurisdiction; no equivalent mechanism found.. Searched: unavailable.

Adequacy GrantedRed

Not applicable — no WA-specific adequacy-granting mechanism exists.

Absence provenance: No adequacy-granting mechanism found.. Searched: unavailable.

Sccs And BcrsRed

No SCC/BCR framework exists under Washington law.

Absence provenance: No SCC/BCR-equivalent mechanism found.. Searched: unavailable.

Transfer Impact AssessmentRed

No TIA requirement identified under Washington law.

Absence provenance: No TIA obligation found.. Searched: unavailable.

Data LocalisationRed

No data-localisation mandate identified under Washington law.

Absence provenance: No localisation mandate found.. Searched: unavailable.

Category narrative44 words

Washington has no state-level adequacy, SCC, BCR, transfer-impact-assessment, or data-localisation regime. The only WA-specific control affecting data transfers is MHMDA's consent/authorization requirement for 'sharing' and 'selling' consumer health data, which functions as a de facto transfer gate for that data category regardless of destination.

Sources and claims (1)
  1. ProbableIAPP — Washington State has no dedicated cross-border data-transfer mechanism regime; the My Health My Data Act's consent/authorization requirements for sharing and selling consumer health data function as the state's primary control on transfers of that data to third parties, wherever located.observed

#

Strong health-sector overlay exists; other sectors rely entirely on federal law with no WA-specific supplement identified.

Primary frameworkMy Health My Data Act (health-sector overlay)
Traffic-light rationale — AmberStrong health-sector overlay exists; other sectors rely entirely on federal law with no WA-specific supplement identified.

Sub-modules (7)

Financial Sector OverlayRed

No WA-specific financial-sector privacy overlay identified; federal GLBA applies as baseline.

Absence provenance: No state financial-sector overlay found.. Searched: unavailable.

Health Sector OverlayGreen

MHMDA fills HIPAA gaps for non-covered health-data collectors.

Claims (1):

  • The My Health My Data Act was enacted specifically to close gaps left by the federal HIPAA framework, which does not reach a substantial share of health-related data collected by non-covered entities such as wearables, apps and consumer-facing health platforms.

Telecoms And EprivacyRed

No WA-specific telecoms/ePrivacy overlay identified.

Absence provenance: No telecoms/ePrivacy overlay found.. Searched: unavailable.

Employment DataRed

No WA-specific employment-data privacy overlay identified.

Absence provenance: No employment-data overlay found (unlike Colorado's biometric amendment).. Searched: unavailable.

Credit And ScoringRed

No WA-specific credit/scoring privacy overlay identified; federal FCRA applies as baseline.

Absence provenance: No state credit-scoring overlay found.. Searched: unavailable.

EducationRed

No WA-specific education-sector privacy overlay identified.

Absence provenance: No education-sector overlay found.. Searched: unavailable.

InsuranceRed

No WA-specific insurance-sector privacy overlay identified.

Absence provenance: No insurance-sector overlay found.. Searched: unavailable.

Category narrative54 words

The My Health My Data Act is Washington's flagship sectoral overlay, enacted specifically to close gaps left by HIPAA for non-covered health-data collectors (apps, wearables, websites). No WA-specific overlays for financial services, telecoms/ePrivacy, employment, credit-scoring, education, or insurance were identified beyond generally applicable federal sectoral law (GLBA, FCRA, etc., addressed at the US-federal JID).

Sources and claims (1)
  1. ConfirmedIAPP — The My Health My Data Act was enacted specifically to close gaps left by the federal HIPAA framework, which does not reach a substantial share of health-related data collected by non-covered entities such as wearables, apps and consumer-facing health platforms.observed

#

Indirect adtech controls exist only through MHMDA's health-data sale/sharing rules; no general commercial-privacy adtech regime exists.

Primary frameworkMy Health My Data Act sale/sharing authorization requirement (health-data scope only)
Traffic-light rationale — AmberIndirect adtech controls exist only through MHMDA's health-data sale/sharing rules; no general commercial-privacy adtech regime exists.

Sub-modules (6)

Cookies And TrackersAmber

MHMDA's 'sell' definition can capture third-party cookie/pixel-based sharing of health-derived data.

Claims (1):

  • The My Health My Data Act's broad definition of 'sell' can capture disclosure of health-derived data gathered via third-party cookies, pixels, and tags to service providers, triggering the Act's prior-authorization requirement.

Dark PatternsRed

No WA-specific dark-pattern prohibition identified.

Absence provenance: No dark-pattern statute found.. Searched: unavailable.

Opt Out SignalsRed

No WA-specific universal opt-out signal (GPC-equivalent) mandate identified.

Absence provenance: No opt-out-signal mandate found.. Searched: unavailable.

Clean Rooms And DcrRed

No WA-specific clean-room/data-collaboration-room rule identified.

Absence provenance: No clean-room rule found.. Searched: unavailable.

Cross Context AdvertisingRed

No CCPA-style 'sale'/'share' cross-context advertising regime exists generally; only MHMDA's health-data-specific sale rule applies.

Absence provenance: No general cross-context advertising regime found.. Searched: unavailable.

Direct MarketingAmber

MHMDA's sale-authorization requirement constrains health-data-driven direct marketing.

Claims (1):

  • By restricting the sale of consumer health data absent specific consumer authorization, the My Health My Data Act indirectly constrains health-data-driven direct marketing and advertising practices in Washington.
Category narrative28 words

Washington has no dedicated cookie-consent, dark-pattern, opt-out-signal, or clean-room statute. MHMDA's broad 'sell' definition indirectly reaches health-data monetization via third-party cookies/pixels/tags and constrains health-data-driven direct marketing absent authorization.

no periodic updates on record for this sub-brief

Sources and claims (2)
  1. ProbableIAPP — The My Health My Data Act's broad definition of 'sell' can capture disclosure of health-derived data gathered via third-party cookies, pixels, and tags to service providers, triggering the Act's prior-authorization requirement.observed
  2. ProbableIAPP — By restricting the sale of consumer health data absent specific consumer authorization, the My Health My Data Act indirectly constrains health-data-driven direct marketing and advertising practices in Washington.observed

#

Biometric and facial-recognition governance is comparatively mature; general algorithmic/ADM/AI-risk-assessment and genetic-data governance is absent.

Primary frameworkWashington Biometric Privacy Protection Act (RCW 19.375); SB 6280 facial-recognition regulation; MHMDA biometric-as-health-data treatment
Traffic-light rationale — AmberBiometric and facial-recognition governance is comparatively mature; general algorithmic/ADM/AI-risk-assessment and genetic-data governance is absent.

Sub-modules (6)

Profiling RestrictionsRed

No WA-specific profiling-restriction statute identified.

Absence provenance: No profiling-restriction analogue found.. Searched: unavailable.

Automated Decision Making TransparencyRed

No WA-specific ADM-transparency statute identified.

Absence provenance: No ADM-transparency statute found.. Searched: unavailable.

Ai Risk AssessmentsRed

No WA-specific AI-risk-assessment statute (unlike Colorado's AI Act) identified.

Absence provenance: No AI-risk-assessment statute found for WA.. Searched: unavailable.

Biometric RegimeGreen

RCW 19.375 imposes notice-and-consent duties for commercial biometric-identifier enrollment; MHMDA separately treats biometric data as consumer health data.

Claims (1):

  • The Washington Biometric Privacy Protection Act (RCW 19.375, effective 23 July 2017) is one of the earliest state biometric statutes in the U.S., cited by the FTC as an example of state biometric regulation, and the My Health My Data Act separately treats biometric data as consumer health data subject to its private right of action.

Genetic DataRed

No standalone WA genetic-data statute identified; genetic data is not explicitly confirmed as a distinct MHMDA/biometric-law category in sources retrieved.

Absence provenance: Explicit genetic-data provisions not confirmed distinct from general biometric/health-data definitions.. Searched: unavailable.

State Surveillance CarveoutsAmber

SB 6280 (2020) regulates public and private facial-recognition technology use in Washington.

Claims (1):

  • In 2020, the Washington Legislature passed SB 6280, establishing regulations governing public and private-sector use of facial-recognition technology in the state.
Category narrative69 words

Washington's Biometric Privacy Protection Act (RCW 19.375, 2017) was one of only three state biometric statutes for years and is cited by the FTC as an early state biometric-privacy model. MHMDA additionally treats biometric data as consumer health data subject to its private right of action. SB 6280 (2020) governs public/private facial-recognition technology use. No WA-specific profiling-restriction, ADM-transparency, AI-risk-assessment, or genetic-data statute (comparable to Colorado's AI Act) was identified.

Sources and claims (2)
  1. ConfirmedFederal Trade Commission — The Washington Biometric Privacy Protection Act (RCW 19.375, effective 23 July 2017) is one of the earliest state biometric statutes in the U.S., cited by the FTC as an example of state biometric regulation, and the My Health My Data Act separately treats biometric data as consumer health data subject to its private right of action.observed
  2. ConfirmedIAPP — In 2020, the Washington Legislature passed SB 6280, establishing regulations governing public and private-sector use of facial-recognition technology in the state.observed

#

This is a legitimate, explicit regulatory gap: no WA-specific children's/vulnerable-groups privacy statute was located in this research.

Traffic-light rationale — Not assessedThis is a legitimate, explicit regulatory gap: no WA-specific children's/vulnerable-groups privacy statute was located in this research.

Sub-modules (5)

Age VerificationRed

No WA-specific age-verification statute identified.

Absence provenance: No age-verification statute found.. Searched: unavailable.

Minor Profiling BansRed

No WA-specific minor-profiling ban identified.

Absence provenance: No minor-profiling ban found (unlike Colorado/Connecticut amendments).. Searched: unavailable.

Education SettingsRed

No WA-specific education-settings privacy rule identified.

Absence provenance: No education-settings rule found.. Searched: unavailable.

Dependent AdultsRed

No WA-specific dependent-adults data-protection provision identified.

Absence provenance: No dependent-adults provision found.. Searched: unavailable.

Category narrative57 words

No Washington state-specific statute establishing an age-of-consent threshold, parental-consent mechanism, minor-profiling ban, education-settings privacy rule, or dependent-adults protection was identified for the general privacy domain (as distinct from federal COPPA, which is addressed at the US-federal JID). Washington has no comprehensive privacy statute of the kind that in other states (e.g., Colorado, Connecticut) carries children's-privacy duty-of-care amendments.

#

A strong private right of action and CPA enforcement mechanism exist and are actively used by plaintiffs; documented state AG enforcement activity and regulator capacity data are thin.

Primary frameworkMy Health My Data Act private right of action under Washington's Consumer Protection Act
Traffic-light rationale — AmberA strong private right of action and CPA enforcement mechanism exist and are actively used by plaintiffs; documented state AG enforcement activity and regulator capacity data are thin.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

AG enforcement operates via the Consumer Protection Act; MHMDA violations are deemed to satisfy CPA elements automatically for private claims.

Claims (1):

  • Violations of the My Health My Data Act are enforceable both by the Washington Attorney General and by private plaintiffs under the state's Consumer Protection Act, which for private MHMDA claims dispenses with the CPA's usual requirement that plaintiffs prove the violation is an unfair/deceptive act, since any MHMDA violation is deemed to satisfy those elements.

Enforcement Activity IndexRed

No documented WA AG enforcement actions or fines under MHMDA were identified as of August 2026.

Absence provenance: Search returned only AG FAQ guidance, no enforcement-action or fine records.. Searched: unavailable.

Regulator Funding And CapacityRed

No data on WA AG office budget/headcount specific to privacy enforcement was identified.

Absence provenance: No funding/capacity data found.. Searched: unavailable.

Collective Redress And Class ActionsAmber

MHMDA is cited among newer state privacy statutes driving a surge in privacy class-action litigation.

Claims (1):

  • Washington's My Health My Data Act is cited among the newer state privacy statutes, alongside the CCPA and New Jersey's Daniel's Law, that plaintiffs increasingly use as grounds for privacy class-action litigation amid an overall surge in U.S. data-privacy lawsuits.

Private Right Of ActionAmber

MHMDA contains a broad, low-threshold private right of action with treble-damages exposure.

Claims (1):

  • The My Health My Data Act contains a broad private right of action enforceable under Washington's Consumer Protection Act, authorizing consumers to sue for a violation of any provision of the Act without a mitigating cure period, with potential recovery of actual damages, litigation costs, attorney's fees, and treble damages upon proof of injury.

Recent Developments 180DAmber

No WA-specific MHMDA enforcement development within the last 180 days was identified; the most relevant recent development is the FTC's July 2026 federal Section 5 suit against Hims & Hers (joined by Utah and California), evidencing continued national health-privacy enforcement under the federal baseline applicable in Washington.

Claims (1):

  • In July 2026, the FTC, joined by Utah and California, filed suit against telehealth provider Hims & Hers alleging deceptive and unlawful sharing of consumers' sensitive health data, illustrating continued active federal Section 5 enforcement in the health-privacy space that forms part of the baseline regulatory backdrop applicable in Washington absent state-specific AG action in this window.
Category narrative122 words

The My Health My Data Act's most consequential enforcement feature is its broad private right of action, enforceable under Washington's Consumer Protection Act, which dispenses with the CPA's usual burden of proving an unfair/deceptive act for MHMDA violations and allows treble damages upon proof of injury. Washington data-privacy litigation (including MHMDA-based claims) has grown amid a broader national surge in privacy class actions. No documented WA Attorney General enforcement actions or fines specifically under MHMDA were identified as of this research; federal FTC Section 5 enforcement in the health-privacy space (e.g., the July 2026 Hims & Hers suit, joined by Utah and California, not Washington) illustrates continued federal-baseline enforcement activity applicable nationally, including in Washington, absent state-specific AG action in this window.

no periodic updates on record for this sub-brief

Sources and claims (4)
  1. ConfirmedIAPP — Violations of the My Health My Data Act are enforceable both by the Washington Attorney General and by private plaintiffs under the state's Consumer Protection Act, which for private MHMDA claims dispenses with the CPA's usual requirement that plaintiffs prove the violation is an unfair/deceptive act, since any MHMDA violation is deemed to satisfy those elements.observed
  2. ProbableIAPP — Washington's My Health My Data Act is cited among the newer state privacy statutes, alongside the CCPA and New Jersey's Daniel's Law, that plaintiffs increasingly use as grounds for privacy class-action litigation amid an overall surge in U.S. data-privacy lawsuits.observed
  3. ConfirmedIAPP — The My Health My Data Act contains a broad private right of action enforceable under Washington's Consumer Protection Act, authorizing consumers to sue for a violation of any provision of the Act without a mitigating cure period, with potential recovery of actual damages, litigation costs, attorney's fees, and treble damages upon proof of injury.observed
  4. ConfirmedFederal Trade Commission — In July 2026, the FTC, joined by Utah and California, filed suit against telehealth provider Hims & Hers alleging deceptive and unlawful sharing of consumers' sensitive health data, illustrating continued active federal Section 5 enforcement in the health-privacy space that forms part of the baseline regulatory backdrop applicable in Washington absent state-specific AG action in this window.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct20.0
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Washington State, USA
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 25 claim(s) (25 category placement(s)), 27 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrectification and erasure
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

All 10 modules populated. regulator_and_framework, lawful_processing_and_special_data, data_subject_rights (access/erasure), controller_processor_duties (breach/ropa), sectoral_watch (health), adtech (cookies/marketing), algorithmic_biometric (biometric/surveillance), and enforcement_and_redress (PRA/collective redress/regulator powers/recent developments) rely on a mix of T1 anchors (FTC Act, FTC biometric policy statement, FTC Hims & Hers press release, WA AG/NAAG seed anchors) and T2 secondary reporting (IAPP, OneTrust DataGuidance) describing the MHMDA, RCW 19.375, and SB 6280. cross_border_and_adequacy and children_and_vulnerable_groups rely almost entirely on absent_field_provenance given the confirmed absence of state-level frameworks in those areas. No primary full-text of RCW 19.255 (breach notification) or RCW 19.375 (biometric) was independently fetched beyond citations in T1 FTC documents and the seed anchor; this is flagged as a gap.

Unresolved questions (4):

  • The exact current text, notification-deadline thresholds, and most recent amendment history of the Washington data breach notification statute (RCW 19.255) were not independently verified against primary statutory text within allowlisted sources.
  • Whether Washington has any state-specific rules for employment data, credit/scoring, education, insurance, or telecoms/ePrivacy beyond generally applicable federal sectoral law was not confirmed.
  • No documented Washington Attorney General enforcement actions, settlements, or fines under the My Health My Data Act were identified as of August 2026 — unclear whether this reflects an absence of enforcement activity or a research/allowlist gap.
  • Whether RCW 19.375 (Biometric Privacy Protection Act) has been amended since 2022 was not confirmed; no 2024-2026 amendment was located.

Escalate to primary-source review: yes