Bill

Bill > S1037


RI S1037

RI S1037
Amends the Identity Theft Protection Act by eliminating current definitions and establishing new definitions. This act also raises the penalty provisions for violations.


summary

Introduced
05/09/2025
In Committee
06/05/2025
Crossed Over
06/10/2025
Passed
Dead
06/20/2025

Introduced Session

2025 Regular Session

Bill Summary

This act would amend the Identity Theft Protection Act of 2015. The act would eliminate the definitions for "classified data" and "personal information" and establish a definition for "personally identifiable information". This act would also add division of enterprise technology strategy and services (ETSS) or successor state agency, or successor to the chief digital officer to notification requirement provisions of the chapter. This act would raise the penalty provisions for violations. This act would take effect on July 1, 2025.

AI Summary

This bill amends the Identity Theft Protection Act of 2015 by comprehensively updating definitions and strengthening cybersecurity requirements for municipal and state agencies, as well as private entities handling sensitive information. The legislation replaces the term "personal information" with "personally identifiable information" and introduces a broader, more inclusive definition that encompasses direct and indirect identifiers, biometric data, and internet data. The bill mandates that agencies and organizations implement risk-based information security programs adhering to current industry best practices, with specific requirements for data protection, access management, and secure data destruction. It also establishes more rigorous notification procedures in the event of a data breach, requiring timely communication with affected individuals, the attorney general, and the division of enterprise technology strategy and services (ETSS). Additionally, the bill increases penalties for violations, with civil penalties ranging from $100 to $200 per record for reckless or willful breaches, and grants courts the discretion to impose additional sanctions. The legislation aims to enhance data protection, create more transparent breach notification processes, and provide stronger safeguards for individuals' sensitive information. The changes will take effect on July 1, 2025, giving organizations time to adapt to the new requirements.

Committee Categories

Business and Industry

Sponsors (10)

Last Action

Senate passed Sub A as amended (floor amendment) (on 06/10/2025)

bill text


bill summary

Loading...

bill summary

Loading...
Loading...