Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Data Privacy topic

No spam. Unsubscribe anytime.

Senate Commerce Committee sends bill redefining PII and requiring credit monitoring after breaches to amendment order

2331893 · February 13, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The Senate Commerce Committee voted to send Senate Bill 10‑66 to the fourteenth order for possible amendment after sponsor Sen. Ben Toews described updates to the definition of personally identifiable information and a new requirement that entities offer credit monitoring when breaches occur or are reasonably likely to occur.

At a meeting of the Senate Commerce Committee, members voted to send Senate Bill 10‑66 to the fourteenth order for possible amendment after the bill sponsor described expanded definitions of personally identifiable information and a new requirement that entities offer consumer credit‑monitoring services following certain breaches.

"This bill seeks to update the definitions of personally identifiable information and to deal with identity theft and protection for consumers," said Senator Ben Toews, state senator from District 4 and sponsor of Senate Bill 10‑66. Toews walked the committee through proposed additions to the PII definition, naming passport numbers, other government–issued identification numbers, usernames or email addresses paired with a password or security question, individual medical history or DNA profiles, health insurance policy numbers and unique biometric data used for authentication.

The bill would also require an "agency, individual, or commercial entity that has determined that the misuse of PII about an Idaho resident has occurred or is reasonably likely to occur" to provide notice and offer credit monitoring services to affected people. Toews said the draft originally provided 36 months of monitoring but that he planned to move in amendment to reduce that period to 12 months to limit costs.

Committee members pressed the sponsor on fiscal concerns. "I'm worried that the state could be on, on the hook for quite a bit of money," said Senator Ward Engelking, citing the bill's fiscal note and an industry‑average figure used in the draft. Toews said the $450 figure in the fiscal note represented an industry average cost per person for three years of credit monitoring; he explained that lowering the monitoring period to 12 months would reduce estimated costs.

Toews described additional amendments he planned to offer if the bill reaches the amending order: removing health insurance policy numbers from the PII definition, adding a consumer‑fraud exemption clarifying that breaches do not include data acquired from sources other than a covered entity's own systems or its service providers, and adding a definition of encryption that would clarify what protections qualify as an exemption.

Senators also discussed the draft's language requiring response when misuse is "reasonably likely to occur," with Toews noting real examples—such as ransomware incidents—where access to data would reasonably suggest a risk even if actual misuse is not yet confirmed. Toews said he would research that threshold further before finalizing amendment language.

At the sponsor's request, Senator Nichols moved that the committee send Senate Bill 10‑66 to the fourteenth order for possible amendment; Senator Lenny seconded. The committee adopted the motion by voice vote and the motion carried. The bill will return to the committee at the amending order for further work and potential changes.

Committee members asked the sponsor to gather additional fiscal detail on past breaches, the number of agencies or datasets that might be affected, and a clearer estimate of potential state costs before final amendment. Toews said he would provide that information to the committee prior to amendment.