19.300 - Electronic communication devices.

19.300.010 - Definitions.

The definitions in this section apply throughout this chapter unless the context clearly requires otherwise.

  1. "Affiliate" means any company that controls, is controlled by, or is under common control with another company. Affiliate may also include a supplier, distributor, business partner, or any entity that effects, administers, or enforces a government or business transaction.

  2. "Identification device" means an item that uses radio frequency identification technology or facial recognition technology.

  3. "Issued" means either:

    1. To have provided the identification device to a person; or

    2. To have placed, requested the placement, or be the intended beneficiary of the placement of, the identification device in a product, product packaging, or product inventory mechanism.

  4. "Person" means a natural person who resides in Washington.

  5. "Personal information" has the same meaning as in RCW 19.255.010.

  6. "Radio frequency identification" means the use of electromagnetic radiating waves or reactive field coupling in the radio frequency portion of the spectrum to communicate to or from a tag through a variety of modulation and encoding schemes to uniquely read the identity of a radio frequency tag or other data stored on it.

  7. "Remotely reading" means that no physical contact is required between the identification device and the mechanical device that captures data.

  8. "Unique personal identifier number" means a randomly assigned string of numbers or symbols that is encoded on the identification device and is intended to identify the identification device.

[ 2009 c 66 § 1; 2008 c 138 § 2; ]

19.300.020 - Identity theft or fraud—Penalty.

A person that intentionally scans another person's identification device remotely, without that person's prior knowledge and prior consent, for the purpose of fraud, identity theft, or for any other illegal purpose, shall be guilty of a class C felony.

[ 2008 c 138 § 3; ]

19.300.030 - Prohibited practices—Exceptions—Application of consumer protection act.

  1. Except as provided in subsection (2) of this section, a governmental or business entity may not remotely read an identification device using radio frequency identification technology for commercial purposes, unless that governmental or business entity, or one of their affiliates, is the same governmental or business entity that issued the identification device.

  2. This section does not apply to the following:

    1. Remotely reading or storing data from an identification device as part of a commercial transaction initiated by the person in possession of the identification device;

    2. Remotely reading or storing data from an identification device for triage or medical care during a disaster and immediate hospitalization or immediate outpatient care directly relating to a disaster;

    3. Remotely reading or storing data from an identification device by an emergency responder or health care professional for reasons relating to the health or safety of that person;

    4. Remotely reading or storing data from a person's identification device issued to a patient for emergency purposes;

    5. Remotely reading or storing data from an identification device of a person pursuant to court-ordered electronic monitoring;

    6. Remotely reading or storing data from an identification device of a person who is incarcerated in a correctional institution, juvenile detention facility, or mental health facility;

    7. Remotely reading or storing data from an identification device by law enforcement or government personnel who need to read a lost identification device when the owner is unavailable for notice, knowledge, or consent, or those parties specifically authorized by law enforcement or government personnel for the limited purpose of reading a lost identification device when the owner is unavailable for notice, knowledge, or consent;

    8. Remotely reading or storing data from an identification device by law enforcement personnel who need to read a person's identification device after an accident in which the person is unavailable for notice, knowledge, or consent;

    9. Remotely reading or storing data from an identification device by a person or entity that in the course of operating its own identification device system collects data from another identification device, provided that the inadvertently received data comports with all of the following:

      1. The data is not disclosed to any other party;

      2. The data is not used for any purpose; and

      3. The data is not stored or is promptly destroyed;

    10. Remotely reading or storing data from a person's identification device in the course of an act of good faith security research, experimentation, or scientific inquiry including, but not limited to, activities useful in identifying and analyzing security flaws and vulnerabilities;

    11. Remotely reading or storing data from an identification device by law enforcement personnel who need to scan a person's identification device pursuant to a search warrant; and

    12. Remotely reading or storing data from an identification device by a business if it is necessary to complete a transaction.

  3. The legislature finds that the practices covered by this section are matters vitally affecting the public interest for the purpose of applying the consumer protection act, chapter 19.86 RCW. A violation of this chapter is not reasonable in relation to the development and preservation of business and is an unfair or deceptive act in trade or commerce and an unfair method of competition for the purpose of applying the consumer protection act, chapter 19.86 RCW.

[ 2009 c 66 § 2; ]


Created by @tannewt. Contribute on GitHub.