Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Data Breach Notification topic

No spam. Unsubscribe anytime.

Lawmakers revisit data-breach notification bill as small-business groups warn about implementation burdens

2322310 · February 11, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Representative Phillips reintroduced a data-breach notification bill after recent public-sector breaches. The Northern Rhode Island Chamber urged caution for small businesses and defended a 45-day notification window.

Representative Phillips presented House Bill 5031, a reintroduction of a data-breach notification measure aimed at tightening when entities must tell the public about breaches. Phillips said the bill follows recent high-profile breaches and that he is working with several business groups to refine the language.

Phillips told the committee he was open to meeting with at least four private entities that expressed concerns about compliance burdens on smaller businesses. “I've had at least 4 entities that's reached out to me, and they have some concerns, some suggestions… I'm willing to sit with them,” he said.

Lynette (representing the Northern Rhode Island Chamber of Commerce) urged care in drafting and said previous iterations and compromise language evolved over multiple sessions. She noted that the current statutory framework distinguishes government entities and private businesses and that the 45-day notification period for businesses reflects time firms need to investigate and close security gaps before alerting customers. “In 2023, the General Assembly kind of split it into 2 pieces… For the businesses, it stayed at 45 days,” Lynette said.

Committee members discussed the particular challenges small businesses face, including paper records and limited IT capacity, and suggested education and best-practice outreach through chambers of commerce. Representative Morales and others noted that some breaches stem from low-tech vulnerabilities and said public education could complement any statutory changes. The committee did not take a final vote on HB 5031; staff and the sponsor agreed to continue stakeholder conversations and solicit written comments.

The committee closed the hearing without further action on the bill at this session.