Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Data Breach topic
No spam. Unsubscribe anytime.
Committee adds biometric identifiers to personal‑information definition and keeps 45‑day AG notification window
Summary
HB 19‑43 expands Arkansas’s definition of personal information to include biometric data and requires businesses to notify the Attorney General of breaches affecting 1,000 or more people within 45 days; the committee passed the bill after discussion about the 45‑day timeframe.
Get email alerts on the Data Breach topic
No spam. Unsubscribe anytime.
The Senate Insurance & Commerce Committee passed HB 19‑43, a consumer‑protection bill that expands the statutory definition of personal information to include modern biometric identifiers and sets a breach notification requirement.
Representative Kavanaugh, presenting the bill (brought by the Attorney General’s office), said the bill adds items such as fingerprints, facial recognition, retinal and iris scans, hand geometry, voice analysis and DNA to the list of personal information and defines a security breach as one affecting 1,000 individuals. "Once that breach is found out, they have 45 days to allow to let the AG's office know about it," Kavanaugh said, explaining the reporting timeline.
Members discussed whether 45 days was an appropriate notification window; the chair and other senators expressed support for keeping the period in the draft and noted national discussion among insurance regulators. The committee voted to pass the measure (motion by Senator Chesterfield; second Senator Johnson) with no opposition recorded in committee.
Why it matters: Sponsors said expanding the definition reflects technological changes and clarifies when businesses must report large breaches to the state's Attorney General.
Next steps: The committee approved the bill; the transcript does not record a floor schedule or vote tally.
