Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Data Security topic

No spam. Unsubscribe anytime.

Committee approves breach-notification bill with business defenses; passes 5-2

2320393 · February 13, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Senate Bill 626, which would require entities that experience security breaches affecting Oklahoma residents to notify the Attorney General and consumers and that creates civil penalties, passed the Senate Technology & Telecommunications Committee 5-2 after debate about penalties, thresholds and business defenses.

Senate Bill 626, a security-breach notification bill sponsored by Senator Howard, was approved by the Oklahoma Senate Technology & Telecommunications Committee on a 5-2 vote after questions and debate about penalties, thresholds and protections for businesses.

The bill would require an entity that owns or licenses computerized data containing personal information about Oklahoma residents to provide notice of a breach after a "determination" that the breach caused or will cause identity theft or fraud, and to notify the Attorney General within 60 days after notifying affected consumers. The sponsor told the committee the requirement is intended to let the Attorney General detect patterns of attacks and respond to systemic threats.

The bill preserves defenses for entities that use "reasonable safeguards"; the sponsor said entities that have reasonable safeguards and that timely notify the Attorney General would be exempt from civil penalties. The Attorney General's office estimated additional implementation costs measured in the tens of thousands: the sponsor cited figures of roughly $31,000 in the first partial year and about $62,000 for a full year to cover staff to process reports.

Committee members raised several concerns. Senator Bullard said he could not support the bill because it could punish businesses that were victims of criminal cyberattacks; he and Senator Gillespie voted no. Senators also questioned how the statute treats breaches the entity did not "know" about and who decides the magnitude of a breach for penalty calculations. The sponsor said the bill uses "determination" rather than "discovery" so entities can investigate whether an attempted attack actually resulted in a breach before being required to notify.

The bill sets different numeric thresholds and carve-outs: notice to the Attorney General applies when a specified number of Oklahoma residents are affected (the bill uses 500 as a state-level threshold and 1,000 where federal reporting regimes already apply); entities subject to HIPAA are exempt from duplicative state reporting. The sponsor told the committee that entities impacting fewer than 500 Oklahoma residents are not required to notify the Attorney General and therefore would not be subject to the state civil-penalty provisions.

After debate and closing remarks from the sponsor, the committee approved SB 626 on a roll-call vote reported as 5 ayes and 2 nays.

Votes at a glance Senate Bill 626 (Security Breach Notification Act): Passed committee, tally reported 5 ayes, 2 nays.

What's next SB 626 proceeds to the full Senate for further consideration.