Consumer Health Privacy Policy: MHMDA & State Laws

Standalone Consumer Health Privacy Policy for MHMDA, Nevada SB 370, and Connecticut rules: categories, consent, rights, sale authorization, and geofencing.

Compliance Framework

GSDSI operates under CCPA/CPRA, CAN-SPAM, TCPA, GDPR, and the evolving US state-privacy-act landscape (Virginia CDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Iowa ICDPA, Montana CDPA, Oregon OCPA, Texas TDPSA, Florida FDBR, and others). Consumer-report-adjacent products carry FCRA-ineligible labeling. Privacy-request handling meets the 45-day verification SLA required by California law.

Introduction

This Consumer Health Privacy Policy describes how Global Source Data Solutions, Inc. ("GSDSI," "we," "us," or "our") collects, uses, shares, and sells consumer health data, and how you can exercise related rights. It is a standalone notice, separate from our general Privacy Policy, and is provided to meet requirements under Washington's My Health My Data Act (MHMDA), Nevada SB 370, Connecticut's CTDPA health-data amendments, and similar state consumer-health laws.

Questions: privacy@gsdsi.com.

Scope and Relationship to Other Notices

This policy covers consumer health data (CHD) as defined by applicable state law. Under MHMDA, CHD is defined broadly and can include precise location information that could indicate a consumer's attempt to acquire or receive health services or supplies, and inferences drawn from that information to identify a consumer as seeking health services.

GSDSI is not a HIPAA covered entity or business associate for its standard public catalog. This policy is about state consumer-health regimes, not HIPAA PHI. For general privacy practices, see the Privacy Policy. To exercise rights, use the TrustSuperset privacy rights request form or Privacy Center.

Categories of Consumer Health Data We Process

Depending on the product and license, GSDSI may process the following categories of CHD or CHD-adjacent data:

  • Precise geolocation and mobility signals that could indicate visitation near or at health-care facilities, pharmacies, clinics, or similar points of interest, where such signals are in scope for a licensed product.
  • Inferences and audience segments used to build health-adjacent or wellness-interest audiences (for example, condition-affinity or wellness-category interest), where offered under separate license terms.
  • Related identifiers needed to associate the above signals with a device or individual record for permitted licensing (for example, mobile advertising IDs), subject to source contracts and law.

GSDSI does not offer diagnosis records, treatment notes, lab or imaging results, prescription fills, insurance claims, or other data sourced as HIPAA PHI on the public catalog.

Purposes for Collecting and Processing Consumer Health Data

We process CHD categories for the following purposes, where permitted by law and by our source and customer contracts:

  • Licensing privacy-governed location intelligence, measurement, and audience products to qualified enterprise buyers.
  • Operating, securing, and improving those products (quality, fraud prevention, suppression, and audit).
  • Honoring consumer rights requests, legal obligations, and contractual restrictions (including sensitive-place exclusions).
  • Internal analytics needed to deliver the licensed product, not to build unrestricted marketing profiles from GLBA nonpublic personal information (see the GLBA section of our Privacy Policy).

Sources of Consumer Health Data

CHD categories we process may come from:

  • Licensed mobility and location panels and related partner feeds under contract.
  • Inferences derived from permitted location or interest signals.
  • Information you or an authorized agent provide when exercising privacy rights or contacting us.

We do not name individual data suppliers in this public policy. Source categories and permitted-use boundaries are described further in our sourcing methodology and in customer agreements.

Sharing of Consumer Health Data and Third Parties

Where CHD is licensed or otherwise shared, categories shared may include precise geolocation or mobility-derived insights, health-adjacent inferences or segments, and associated identifiers needed for the licensed use.

Categories of third parties that may receive CHD (subject to contract and law):

  • Qualified enterprise customers (advertisers, measurement firms, analytics buyers, and similar) under written license.
  • Service providers and processors that support delivery, security, identity verification, or rights-request handling (including our DSR portal provider, TrustSuperset), under written contracts that limit use to our instructions.

Affiliates. As of the effective date of this policy, GSDSI does not share consumer health data with any corporate affiliate. If that changes, this policy will be updated to name each affiliate by company name before such sharing occurs, as required by MHMDA.

Where MHMDA or similar law requires it, GSDSI obtains prior opt-in consent for the collection of consumer health data, and obtains separate consent for the sharing of consumer health data. Collection consent and sharing consent are not treated as a single bundled consent.

Upstream partners that collect signals before transfer to GSDSI are contractually required to maintain lawful consent or another valid legal basis for the transfer and licensed use. Buyer customers that further process CHD are responsible for any additional consents their own use cases require.

Sale of Consumer Health Data

Under MHMDA, a sale of consumer health data requires a separate, signed written authorization from the consumer that meets statutory content requirements. That authorization is a higher bar than a general opt-out of sale under CCPA/CPRA.

GSDSI does not sell consumer health data unless it has obtained the consumer's valid signed written authorization for that sale, or another express statutory exception applies. Licensing of non-CHD products is described in the general Privacy Policy.

Geofencing Commitment

GSDSI does not operate geofences within 2,000 feet of a health-care facility's perimeter for the purpose of identifying, tracking, collecting data from, or sending messages or advertising materials to a consumer, consistent with MHMDA's geofencing prohibition (effective July 23, 2023).

Sensitive-place exclusion practices for licensed location products are also described in our sensitive-location compliance checklist.

Your Consumer Health Data Rights

Subject to applicable law and identity verification, you may:

  • Withdraw consent for our collection or sharing of your consumer health data, where processing is based on consent.
  • Access consumer health data we hold about you.
  • Delete consumer health data we hold about you, subject to lawful retention exceptions.

Submit requests through our TrustSuperset DSR portal (no account creation is required solely to opt out of sale or sharing under CCPA/CPRA). You may also use Privacy Center, Do Not Sell or Share, or email privacy@gsdsi.com.

California residents may also use mechanisms described in our Privacy Policy, including limit-sensitive-PI requests at Limit the Use of My Sensitive Personal Information.

Nevada SB 370 and Connecticut Health-Data Rules

In addition to Washington MHMDA, GSDSI treats the following as in-scope for this Consumer Health Privacy Policy where they apply to our processing:

  • Nevada SB 370 (consumer health data): regulated entities face civil penalties of up to $5,000 per violation under applicable Nevada enforcement.
  • Connecticut CTDPA health-data amendments: Connecticut may assess civil penalties of up to $7,500 per violation under applicable CTDPA enforcement for covered health-data violations.

Where these laws grant access, deletion, or consent rights that apply to GSDSI's processing, we honor them through the same DSR channels listed above. If a conflict arises among state rules, we apply the more protective consumer requirement for the covered data.

Contact

Privacy & Compliance Department, Global Source Data Solutions, Inc., 3410 Galt Ocean Dr., Fort Lauderdale, FL 33308, USA. Email: privacy@gsdsi.com.

EU/UK representative details appear in the Privacy Policy.

Changes to This Policy

We post updates on this page with a revised effective date. Effective date: July 21, 2026.