Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Data Privacy topic
No spam. Unsubscribe anytime.
Senate Committee on Institutions conducts straw vote to pursue replacing S.71 with S.93 after bill comparison
Summary
Committee members heard a line‑by‑line comparison from legislative counsel and held a straw vote to pursue a strike‑all amendment replacing S.71 with S.93; formal action was postponed for additional testimony and technical fixes.
Get email alerts on the Data Privacy topic
No spam. Unsubscribe anytime.
The Senate Committee on Institutions on March 13 conducted a straw vote to pursue a strike‑all amendment replacing S.71 with S.93 after Rick Seibel, of the Office of Legislative Counsel, summarized the substantive differences between the two data‑privacy bills.
Seibel told the committee the bills are "probably 90% the same. But that 10% is, pretty important," and walked members through differences in applicability thresholds, exemptions, consumer rights, data‑protection assessments and enforcement provisions.
The differences Seibel highlighted include applicability thresholds (S.71 applies to controllers processing personal data of more than 25,000 consumers or more than 12,500 consumers if 25% or more of gross revenue is derived from personal data, while S.93 raises those thresholds to 100,000 and 25,000, respectively); S.71 phases down its thresholds in later years while S.93 does not; exemptions (S.93 contains broader exemptions that would, for example, exempt all nonprofits and more higher‑education activities, whereas S.71 exempts some but not all nonprofits and contains narrower higher‑education language); and handling of sensitive data (S.71 bars processing of sensitive data except when strictly necessary to provide a product or service, while S.93 generally conditions processing on consent).
Seibel also identified differences on data‑protection assessments, retention and enforcement. S.71 directs controllers to retain assessments for at least three years and gives controllers more prescriptive monitoring duties; S.93 includes language that assessment requirements apply beginning July 1 and are not retroactive and does not contain the same explicit three‑year retention provision. On enforcement, Seibel said S.71 contains a private right of action, while S.93 does not and, until Jan. 1, 2027, requires the Attorney General to issue a notice of violation and offer a cure period before commencing enforcement proceedings.
Committee discussion referenced other provisions and federal interaction: S.71 contains more explicit protections for minors and references COPPA (the federal Children’s Online Privacy Protection Act), while S.93 defers some issues to federal law. Seibel noted differences on facial‑recognition and employee‑data carve‑outs and pointed to a duplicate subdivision in S.93 that he would correct if the committee moves that language forward.
After the discussion, the chair asked for a straw vote on adopting a strike‑all amendment to replace the text of S.71 with S.93. Committee members indicated support in the straw vote; the chair then said the committee would not take a final vote that day and deferred a formal vote to the next meeting to allow more testimony and to circulate corrected draft language.
The committee requested additional testimony and technical edits before a formal vote. Committee staff and Seibel said they would correct the duplication Seibel identified in S.93 and provide further detail on exemptions, assessment retention and how certain definitions (for example, “deidentified” and “consent”) differ between the bills.
What happens next: the committee will receive more testimony and a revised draft before a formal vote is taken. No formal passage, adoption or final tally was recorded in the transcript; members described the March 13 action as a procedural step toward replacing S.71 with S.93 and deferred final action to the following day.

