Cosmetics Companies Face Dual Compliance Challenge Under MoCRA And State Data Privacy Laws

The Modernization of Cosmetics Regulation Act of 2022, known as MoCRA, introduced sweeping changes to how cosmetics are regulated across the United States.

Among its core requirements, MoCRA aligned cosmetics adverse-event record-keeping and reporting obligations with existing over-the-counter drug standards.

Cosmetics manufacturers, distributors, and packers must now report consumer claims of serious adverse events directly to the U.S. Food and Drug Administration.

Qualifying serious adverse events include death, life-threatening conditions, inpatient hospitalization, persistent or significant disability, congenital anomaly or birth defect, infection, and significant disfigurement.

MoCRA also requires cosmetics businesses to retain records of any adverse event, defined as any negative health-related event, for a minimum of six years.

Because MoCRA took effect before most state privacy laws were enacted, cosmetics companies must now carefully assess their obligations under both regulatory frameworks simultaneously.

Information gathered to satisfy MoCRA requirements can include sensitive personal data such as a customer’s name, sex, date of birth, preexisting medical conditions, and reported adverse health events.

State laws including the California Consumer Privacy Act and Washington’s My Health My Data Act may contain exemptions for legally required data collection, but those provisions are statute-specific and do not automatically place all such data outside privacy law scope.

Washington’s My Health My Data Act broadly covers consumer health data linked to a consumer that identifies physical or mental health status, which may include skin conditions and adverse-event information suggesting an underlying health condition.

Where applicable, that law requires explicit consent before collecting or sharing consumer health data, along with a separate privacy notice describing what data is collected, how it is used, and with whom it is shared.

Some comprehensive state privacy laws also require organisations to clearly disclose their data collection, use, retention, and sharing practices and limit processing to what is reasonably necessary and proportionate to disclosed purposes.

Data minimisation is particularly important when cosmetics companies share MoCRA-related information with third-party vendors, and companies should assess whether hashing or removing certain personal identifiers is feasible.

Contracts with third parties that collect or process adverse event data should include appropriate privacy and data processing terms to ensure downstream compliance obligations are met.

State laws may also impose additional requirements when personal data collected for MoCRA compliance is shared with a parent company or affiliated entity, even where common branding exists between those organisations.

Complying with MoCRA’s mandatory reporting and recordkeeping obligations does not eliminate the need to review how adverse-event data is collected, used, retained, and shared under applicable state privacy laws.

Cosmetics companies should therefore review their intake processes, privacy disclosures, vendor and affiliate arrangements, and data minimisation practices to ensure that information collected for MoCRA compliance is handled lawfully across all relevant jurisdictions.