Close this menu

NetChoice Testimony in Opposition to Wyoming’s Personal Data Ownership Act

27LSO-0140 would make Wyoming the only state to treat all personal data as property that can never be sold and can only be licensed on a short statutory clock. That regime would apply to every business, nonprofit, and employer in the state, regardless of size, and even to out-of-state companies. It would be enforced through no-harm lawsuits carrying statutory damages of up to $15,000 per person, which would saddle Wyoming businesses with compliance costs and litigation risk found nowhere else in the country.

NetChoice Testimony in Opposition Wyoming Personal Data Ownership Act

September 28, 2026

Dear Co-Chairs Rothfuss, Singh and Members of the Select Committee on Blockchain, Financial Technology and Digital Innovation Technology:

On behalf of NetChoice, we respectfully submit this testimony in opposition to 27LSO-0140, the Wyoming Personal Data Ownership Act. NetChoice is a trade association working to make the internet safe for free enterprise and free expression. We share the Committee’s interest in giving Wyoming residents meaningful control over their personal information. But this draft goes far beyond any privacy framework enacted in the United States.

The draft deems all personal data to be property that can never be transferred and can only be licensed on a short statutory clock. It would impose that regime on every business, nonprofit, and employer in the state regardless of size. And it would enforce the regime through a private right of action that requires no proof of harm and carries statutory damages of up to $15,000 per person. The Committee’s own legislative staff caution that the approach “may have unintended consequences.” We agree, and we urge the Committee not to advance it.

Wyoming Would Abandon the Framework Every Other Privacy State Has Adopted

Roughly two dozen states have enacted comprehensive consumer privacy laws, including Colorado, Montana and Utah. They differ in detail, but they share one foundation. Consumers receive defined rights: to know what data a business holds, to access, correct and delete it, to opt in before sensitive data is used, and to opt out of sales and targeted advertising. Businesses receive corresponding obligations. No state has made personal data into property, and none has needed to. A consumer does not need to hold title to information to have a statutory right to delete it.

That common structure lets a business build one privacy program and adapt it state by state. 27LSO-0140 cannot be folded into such a program. It replaces opt-out rights with a ban on ever transferring ownership. It covers employee data that other states generally exclude. It drops the applicability thresholds other states use. And it trades attorney general enforcement for private lawsuits. Every business serving Wyoming customers would need a separate compliance system for Wyoming residents alone. That adds cost without giving residents more practical control than their neighbors in Colorado, Montana and Utah already enjoy.

The draft also runs against principles adopted through the American Legislative Exchange Council (ALEC). ALEC’s model resolution on consumer privacy favors a single federal standard over a 50-state patchwork (American Legislative Exchange Council, Resolution for a Single Federal Standard for Consumer Privacy (model policy)). This draft would be the most divergent piece of that patchwork. NetChoice has long shared that view and has urged Congress to adopt one national privacy standard. A patchwork forces businesses that serve customers across state lines to reconcile conflicting definitions, rights, and deadlines, and to build separate compliance programs for each state. Those costs fall hardest on small businesses and startups, which lack large legal departments. Consumers lose too, because their protections change depending on where they live or which company they happen to use. Each new outlier law makes the patchwork harder to navigate. 

The Bill Reaches Every Wyoming Business, Not Just Technology Companies

Although this draft comes from a committee focused on technology, its obligations fall on the entire Wyoming economy. The bill defines a “data custodian” as any person that processes the personal data of a Wyoming resident. It defines “processing” to include merely collecting, storing or using that data. Unlike comprehensive privacy laws in other states, the draft contains no revenue threshold, no minimum number of consumers and no exemption for small businesses or nonprofits.

In practice, a hardware store with a customer mailing list is a data custodian under this bill. So is a feed supplier that keeps ranch accounts, a dental office, a community bank, a hunting outfitter or a church with a membership roll. Every employer in the state is separately made a data custodian with respect to its own employees.  Each of these entities would owe statutory duties to every Wyoming resident whose name, phone number or email it holds, and each could be sued by any one of them. These are not the companies the Committee set out to regulate. But under this draft, they are the businesses least able to absorb the cost of compliance.

The employment provisions show how far the draft departs from existing law. Other state privacy laws generally exclude employee data or treat it separately. This draft lets an employee demand deletion “at any time.”  That demand could reach performance reviews, disciplinary files and workplace investigation records. The exceptions for litigation holds and records-retention policies may not clearly apply before a dispute arises. Employers would be left to guess whether they must destroy records they may later need to defend themselves.

Treating Personal Data as Inalienable Property Upends Ordinary Commerce

The bill declares that all personal data belongs to the person it describes, and that this ownership can never be sold or transferred. Businesses may use the data only under a written license that expires after 12 or 24 months and must then be renewed with fresh consent. That creates an odd kind of property: something a person owns but is never allowed to sell.

This model does not fit how ordinary businesses serve their customers. Records from a purchase must be deleted within 90 days, which complicates warranties, returns and repeat orders. Customer data cannot be kept for more than three years. When a business is sold or merged, all of its permissions to use customer data end automatically, and the buyer must seek new permission from every customer. For a Wyoming family business owner planning to sell and retire, one of the company’s most valuable assets would lose much of its value overnight.

The bill also never says who owns information about more than one person, such as a joint bank account, a shared household device or a family photo. If one person demands deletion and another wants the data kept, the bill offers no answer. 

The Anti-Circumvention and AI Provisions Make Compliance Unknowable

Section 34-31-102(c) of the draft instructs courts to disregard the form, label or characterization of any contract, affiliate relationship or transaction structure and to evaluate conduct according to its “substance and practical effect.” Under this standard, a business can no longer rely on the express terms of its own agreements to determine whether it is in compliance. Liability would turn instead on a court’s after-the-fact assessment of a transaction’s practical effect. This introduces a degree of uncertainty that is difficult to reconcile with the stable, predictable legal environment that has made Wyoming an attractive place to form and grow a business.

Section 34-31-102(d) compounds that uncertainty by extending the chapter to any person that uses, deploys or “makes available” an artificial intelligence or automated system that processes personal data. The provision is not limited to advanced AI. By its terms, it reaches the ordinary software on which Wyoming businesses depend, including point-of-sale systems, scheduling and customer-management tools, email platforms and fraud-prevention services. The bill further classifies the training of an AI or automated system on personal data as “commercial exploitation” subjecting that activity to the chapter’s most restrictive licensing requirements.

Regulating Businesses Beyond Wyoming’s Borders Invites a Commerce Clause Challenge

The Commerce Clause grants Congress the power to regulate interstate commerce and, by implication, limits the power of states to burden it. Courts will strike down a state law when its burden on interstate commerce clearly outweighs the benefits to the state (Pike v. Bruce Church, Inc., 397 U.S. 137, 142 (1970)).

27LSO-0140 is not confined to Wyoming. It defines a “data custodian” as any person that processes a Wyoming resident’s personal data “regardless of the location of the person or of any direct relationship with the data owner” (§ 34-31-103(a)(xi)). It also provides that any violation constitutes an injury to the property of a Wyoming resident, wherever the conduct occurs (§ 34-31-104(d)). A company in Denver or Salt Lake City with no Wyoming operations and no relationship with a Wyoming resident could become subject to the bill’s licensing, retention, deletion and litigation requirements simply because data relating to a Wyoming resident passes through its systems.

The resulting burden on interstate commerce would be substantial. The bill’s coverage turns on whether an individual was domiciled in Wyoming when the data was collected or when a right is asserted. Businesses processing data across state lines often have no way to know that. A national business would have two choices. It could apply Wyoming’s regime to all of its data, effectively exporting Wyoming law to every other state. Or it could build systems to identify and segregate Wyoming residents’ data. Either way, it would have to operate a property-and-licensing framework that conflicts with the consumer-protection model every other privacy state has adopted.

That burden is not necessary to protect Wyoming residents. Comprehensive privacy laws in other states generally apply to businesses that operate in the state or target its residents. LSO staff likewise suggested that the Committee consider adding a Wyoming nexus requirement to reduce the risk of constitutional challenge. Without one, the bill invites litigation that Wyoming taxpayers would fund, while businesses operate under years of uncertainty about whether the law can be enforced at all.

The Private Right of Action Invites Costly, Open-Ended Litigation

The bill allows any Wyoming resident to sue any person for any violation of the chapter (§ 34-31-117(a)). A plaintiff need not show physical harm or economic loss, because the bill deems unauthorized processing itself to be the injury (§ 34-31-104(e)). Where a court finds a violation knowing or reckless, the bill authorizes statutory damages of up to $15,000 per data owner per action, depending on the tier of data involved. A prevailing plaintiff may also recover the defendant’s profits or the “fair license value” of the data, plus attorney fees. The bill forbids businesses from requiring arbitration.

This is the opposite of the approach in ALEC’s Private Enforcement of Consumer Protection Statutes Act (American Legislative Exchange Council, Private Enforcement of Consumer Protection Statutes Act (model policy)). That model limits private suits to people who relied on an unlawful practice and suffered an ascertainable loss of money or property. LSO staff made a similar point about subsection (e). They noted it may give personal data broader remedies than other forms of property receive, and they asked whether proof requirements or damages limits should apply.

Because damages are calculated per person, exposure grows with every customer a business serves. A class of just 1,000 Wyoming customers whose financial or health information is at issue could carry up to $10 million in statutory damages before attorney fees. Combined with the undefined and open-ended standards discussed above, this structure will reward litigation over good-faith disagreements about what the law requires. Large national companies can absorb that risk. Wyoming’s small employers cannot.

Wyoming residents deserve clear privacy protectives, and Wyoming businesses deserve rules they can understand and follow. 27LSO-0140 provides neither. NetChoice respectfully urges the Committee not to advance this draft. If the Committee wishes to pursue consumer privacy legislation, we encourage it to build on frameworks already in effect in other states. We welcome the chance to serve as a resource to the Committee on any of these issues, and we thank you for the opportunity to share our views.

Amy Bos 
Vice President Government Affairs, NetChoice

The views of NetChoice expressed here do not necessarily represent the views of all NetChoice members.