Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Data Privacy topic

No spam. Unsubscribe anytime.

House Business Committee sends bill updating personally identifiable information rules to the floor

2664378 · March 17, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The House Business Committee voted to send Senate Bill 1066, as amended, to the House floor with a due-pass recommendation. The bill updates definitions of personally identifiable information, adds an encryption definition and requires entities responsible for breaches to provide at least 12 months of credit monitoring.

The House Business Committee on March 17 voted to send Senate Bill 1066, as amended, to the House floor with a due-pass recommendation after a brief hearing and committee discussion.

Senator Ben Toews, R.-District 4, told the committee the bill "is pretty simple. It's really updating the personally identifiable information definitions within code." He said the measure also "provides accountability for those who collect and store personally identifiable information" and was amended in the Senate to address industry concerns.

The bill would update the statutory definitions of personally identifiable information to explicitly include items such as username, email, password and payer identification number, according to Toews. It also adds a definition of "encryption" and clarifies that a breach determination does not apply to information that is not stored by the commercial entity.

On the bill's accountability provisions, Toews said the amended language would require an entity that fails to take reasonable precautions and experiences a breach to "offer no less than 12 months of credit monitoring services." Toews said he originally drafted the requirement at 36 months but reduced it to 12 to align with common industry practice.

Committee members asked several clarifying questions about the scope and mechanics of the proposal. Representative Burch asked why the bill limits a breach to unencrypted data; Toews responded that the assumption in the language is that encrypted data is secure and therefore outside the breach definition in those circumstances. Representative Ehlers asked how the "reasonably likely to occur" standard would apply; Toews described scenarios such as compromised usernames and passwords or observable data flows indicating possible exposure.

Toews said he contacted the Attorney General's office while preparing a fiscal note and found "very few" relevant breaches involving state agencies in the last five years and could not identify a precise number of affected individuals. He also said he believes the majority of state-held personally identifiable information would already be encrypted.

Representative Wheeler moved to send the bill to the floor with a due-pass recommendation. The motion carried; Representative Marmon was recorded as voting no. The committee recorded no public testimony on the measure.

The committee chair and Toews said Representative Ehlers plans to carry the bill on the floor.

The committee hearing lasted about 16 minutes and focused on definition updates, encryption, the credit-monitoring requirement and how existing state practices interact with the proposed language.