Standalone Consumer Health Privacy Policy for MHMDA, Nevada SB 370, and Connecticut rules: categories, consent, rights, sale authorization, and geofencing.
GSDSI operates under CCPA/CPRA, CAN-SPAM, TCPA, GDPR, and the evolving US state-privacy-act landscape (Virginia CDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Iowa ICDPA, Montana CDPA, Oregon OCPA, Texas TDPSA, Florida FDBR, and others). Consumer-report-adjacent products carry FCRA-ineligible labeling. Privacy-request handling meets the 45-day verification SLA required by California law.
This Consumer Health Privacy Policy describes how Global Source Data Solutions, Inc. ("GSDSI," "we," "us," or "our") collects, uses, shares, and sells consumer health data, and how you can exercise related rights. It is a standalone notice, separate from our general Privacy Policy, and is provided to meet requirements under Washington's My Health My Data Act (MHMDA), Nevada SB 370, Connecticut's CTDPA health-data amendments, and similar state consumer-health laws.
Questions: privacy@gsdsi.com.
This policy covers consumer health data (CHD) as defined by applicable state law. Under MHMDA, CHD is defined broadly and can include precise location information that could indicate a consumer's attempt to acquire or receive health services or supplies, and inferences drawn from that information to identify a consumer as seeking health services.
GSDSI is not a HIPAA covered entity or business associate for its standard public catalog. This policy is about state consumer-health regimes, not HIPAA PHI. For general privacy practices, see the Privacy Policy. To exercise rights, use the TrustSuperset privacy rights request form or Privacy Center.
Depending on the product and license, GSDSI may process the following categories of CHD or CHD-adjacent data:
GSDSI does not offer diagnosis records, treatment notes, lab or imaging results, prescription fills, insurance claims, or other data sourced as HIPAA PHI on the public catalog.
We process CHD categories for the following purposes, where permitted by law and by our source and customer contracts:
CHD categories we process may come from:
We do not name individual data suppliers in this public policy. Source categories and permitted-use boundaries are described further in our sourcing methodology and in customer agreements.
Where CHD is licensed or otherwise shared, categories shared may include precise geolocation or mobility-derived insights, health-adjacent inferences or segments, and associated identifiers needed for the licensed use.
Categories of third parties that may receive CHD (subject to contract and law):
Affiliates. As of the effective date of this policy, GSDSI does not share consumer health data with any corporate affiliate. If that changes, this policy will be updated to name each affiliate by company name before such sharing occurs, as required by MHMDA.
Where MHMDA or similar law requires it, GSDSI obtains prior opt-in consent for the collection of consumer health data, and obtains separate consent for the sharing of consumer health data. Collection consent and sharing consent are not treated as a single bundled consent.
Upstream partners that collect signals before transfer to GSDSI are contractually required to maintain lawful consent or another valid legal basis for the transfer and licensed use. Buyer customers that further process CHD are responsible for any additional consents their own use cases require.
Under MHMDA, a sale of consumer health data requires a separate, signed written authorization from the consumer that meets statutory content requirements. That authorization is a higher bar than a general opt-out of sale under CCPA/CPRA.
GSDSI does not sell consumer health data unless it has obtained the consumer's valid signed written authorization for that sale, or another express statutory exception applies. Licensing of non-CHD products is described in the general Privacy Policy.
GSDSI does not operate geofences within 2,000 feet of a health-care facility's perimeter for the purpose of identifying, tracking, collecting data from, or sending messages or advertising materials to a consumer, consistent with MHMDA's geofencing prohibition (effective July 23, 2023).
Sensitive-place exclusion practices for licensed location products are also described in our sensitive-location compliance checklist.
Subject to applicable law and identity verification, you may:
Submit requests through our TrustSuperset DSR portal (no account creation is required solely to opt out of sale or sharing under CCPA/CPRA). You may also use Privacy Center, Do Not Sell or Share, or email privacy@gsdsi.com.
California residents may also use mechanisms described in our Privacy Policy, including limit-sensitive-PI requests at Limit the Use of My Sensitive Personal Information.
In addition to Washington MHMDA, GSDSI treats the following as in-scope for this Consumer Health Privacy Policy where they apply to our processing:
Where these laws grant access, deletion, or consent rights that apply to GSDSI's processing, we honor them through the same DSR channels listed above. If a conflict arises among state rules, we apply the more protective consumer requirement for the covered data.
Privacy & Compliance Department, Global Source Data Solutions, Inc., 3410 Galt Ocean Dr., Fort Lauderdale, FL 33308, USA. Email: privacy@gsdsi.com.
EU/UK representative details appear in the Privacy Policy.
We post updates on this page with a revised effective date. Effective date: July 21, 2026.