Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Data Breach Consumer Protection topic
No spam. Unsubscribe anytime.
Senate committee backs sending bill updating ‘personally identifiable information’ rules to amendment order
Summary
Senate Bill 1066, which would broaden Idaho’s definition of personally identifiable information (PII) and require affected entities to offer credit monitoring after certain data breaches, was sent to the fourteenth order for possible amendment by the Senate Commerce Committee on a voice vote.
Get email alerts on the Data Breach Consumer Protection topic
No spam. Unsubscribe anytime.
Senate Bill 1066, which would broaden Idaho’s definition of personally identifiable information (PII) and require affected entities to offer credit monitoring after certain data breaches, was sent to the fourteenth order for possible amendment by the Senate Commerce Committee on a voice vote.
Senator Ben Toews, state senator from District 4 and sponsor of the bill, told the committee, “This bill seeks to update, the definitions of personally identifiable information and to, deal with identity theft and protection for consumers.” He walked members through proposed additions to the PII definition that include passport numbers, other government-issued identification card numbers, usernames or email addresses combined with a password or security question, individual medical history or DNA profile, and “unique biometric data generated for authentication purposes.”
The measure would also require an agency, individual or commercial entity that has determined that misuse of PII belonging to an Idaho resident has occurred or is reasonably likely to occur to provide notice and to offer credit-monitoring services to affected people. Toews said the proposal aims to create accountability for entities that collect and hold PII and to give consumers a way to monitor how their information is used after a breach.
Members pressed the sponsor on cost and scope. “I’m worried that the state could be on, on the hook for quite a bit of money,” said Senator Ward Engelking, citing concerns about the bill’s fiscal note. Toews said the bill initially contemplated 36 months of monitoring but that he was “likely to move it down to 12 months,” a reduction he said would lower costs. He also described the $450 figure in the fiscal note as an industry average: “That $450 was like an industry average for how much it would cost per year times the 3 years. So that's how we came up with the 450.”
Committee members discussed whether the trigger should be limited to incidents that have already occurred rather than including situations where misuse is “reasonably likely to occur.” Toews described real-world ransomware incidents as examples where the “reasonably likely” language could capture breaches that clearly exposed data but where certainty about misuse was not immediate.
Toews outlined suggested amendments he planned to offer in amending order, including removing “health insurance policy number” from the PII definition, adding a consumer-fraud exemption clarifying that the definition of a breach would not include acquisition of data from sources other than systems maintained by the entity (for example, where an individual willingly provides data after being deceived), reducing the required monitoring period to 12 months, and adding a definition of “encryption” and a corresponding exemption for encrypted data.
The committee voted to send the bill to the fourteenth order for possible amendment. The committee also approved the minutes of its Feb. 6, 2025 meeting by voice vote during the same session.
Discussion points: members sought more detail on the fiscal impact and asked the sponsor to research how many Idaho entities or residents have been affected by breaches in recent years; sponsor agreed to provide that information if the bill proceeds to amendment. No final policy was adopted in committee; next steps are amendment work in the fourteenth order.
