Georgia 2023-2024 Regular Session

Georgia Senate Bill SB161 Compare Versions

Only one version of the bill is available at this time.
OldNewDifferences
11 23 LC 47 2184
22 S. B. 161
33 - 1 -
44 Senate Bill 161
55 By: Senators Kennedy of the 18th, Gooch of the 51st, Dolezal of the 27th, Robertson of the
66 29th, Anavitarte of the 31st and others
77 A BILL TO BE ENTITLED
88 AN ACT
99 To amend Chapter 60 of Title 36 of the Official Code of Georgia Annotated, relating to
1010 1
1111 general provisions applicable to counties and municipal corporations, so as to ensure that2
1212 counties and municipalities are protected from cyber attacks directed at contractors and3
1313 suppliers by requiring certain provisions in county and municipal contracts; to amend4
1414 Chapter 25 of Title 50 of the Official Code of Georgia Annotated, relating to the Georgia5
1515 Technology Authority, so as to ensure that state agencies are protected from cyber attacks6
1616 directed at contractors and suppliers by requiring certain provisions in contracts entered into7
1717 by the state and its agencies; to provide for related matters; to repeal conflicting laws; and8
1818 for other purposes.9
1919 BE IT ENACTED BY THE GENERAL ASSEMBLY OF GEORGIA:10
2020 SECTION 1.11
2121 Chapter 60 of Title 36 of the Official Code of Georgia Annotated, relating to general12
2222 provisions applicable to counties and municipal corporations, is amended by adding a new13
2323 Code section to read as follows:14
2424 "36-60-30.
2525 15
2626 (a) As used in this Code section, the term:16 23 LC 47 2184
2727 S. B. 161
2828 - 2 -
2929 (1) 'Contractor' means any person entering a contractual relationship with a local17
3030 government that is either based upon a written contract or that provides a person with18
3131 electronic or physical access to any local government computer system, data systems, or19
3232 facility controlled or affiliated with such local government, and shall include all20
3333 subcontractors of such person.21
3434 (2) 'Data breach' means unauthorized access or disclosure of data under the contractor's22
3535 control or in the contractor's possession contrary to the terms of a contract between the23
3636 contractor and local government.24
3737 (3) 'Local government' means any county or municipality of this state.25
3838 (4) 'Person' means any natural person, partnership, corporation, trust, association, or any26
3939 other legal entity, other than the federal government or the state or a political subdivision,27
4040 agency, or authority thereof.28
4141 (5) 'Personally identifiable information' means an individual's first name, last name,29
4242 home address, personal phone numbers, date of birth, email addresses.30
4343 (b) The following requirements shall apply to all local government contracts entered into31
4444 or renewed after January 1, 2024, in this state:32
4545 (1) That the contractor shall remain compliant with the external data privacy program33
4646 outlined in this Code section, and upon written request by the local government, shall34
4747 provide any evidence demonstrating compliance via written response within seven days35
4848 or less;36
4949 (2) In the event of a data breach, the contractor shall use reasonable efforts to notify the37
5050 local government immediately of such data breach unless notification to an alternative38
5151 or additional entity is provided in the contract. The contractor shall take such actions as39
5252 may be necessary to preserve forensic evidence and eliminate the cause of the data40
5353 breach. The contractor shall give highest priority to immediately correcting any data41
5454 breach and shall devote such resources as may be required to accomplish that goal. The42
5555 contractor shall provide the local government with all information necessary to enable the43 23 LC 47 2184
5656 S. B. 161
5757 - 3 -
5858 local government to fully understand the nature and scope of the data breach, the scope44
5959 of such information being at the discretion of the local government; and45
6060 (3) The contractor shall enact an external data privacy program that shall include, at a46
6161 minimum, the following elements:47
6262 (A) The contractor shall perform, at a minimum, quarterly scans for each of its48
6363 employees' personally identifiable information:49
6464 (i) Across at least 350 known data brokers or people search websites, using such site's50
6565 public onsite search functionality; and51
6666 (ii) Using at least one major internet search engine, determine what information is52
6767 returned and easily obtainable using such search.53
6868 Such quarterly scans may be accomplished by manual effort or using an automated54
6969 service, so long as such scans are definitive;55
7070 (B) The contractor shall maintain a report of the information discovered from the scans56
7171 provided in subparagraph (A) of this paragraph. Using such information, the contractor57
7272 shall conduct an annual privacy risk assessment to evaluate its ongoing privacy policies58
7373 and security and access practices against standards identified in the contract based on59
7474 the data such contractor will have access to or otherwise handle pursuant to its contract60
7575 with the local government;61
7676 (C) The reports described in subparagraph (B) of this paragraph shall be maintained62
7777 by the contractor for a period of no less than three years, including after the conclusion63
7878 of the contract period, and shall be made available within seven days of a request from64
7979 the local government or alternative entity provided in the contract in the event a past65
8080 data breach is found to have occurred, of a suspected data breach, or of an actual data66
8181 breach described in subparagraph (A) of paragraph (2) of this Code section. The67
8282 contract between the local government and contractor may provide that the local68
8383 government maintain such records; and69 23 LC 47 2184
8484 S. B. 161
8585 - 4 -
8686 (D) The contractor shall certify to the local government that it conducts at least70
8787 annually a privacy training for such contractor's employees that includes information71
8888 on its external data privacy program, and the risks associated with data brokers and72
8989 external data privacy, including, but not limited to, that external data exposures are used73
9090 to craft highly targeted social engineering and spear phishing attacks. Such privacy74
9191 training shall not preclude or supplant any privacy training the contractor already75
9292 provides to its employees.76
9393 (c) Contractors shall certify to the local government that it maintains or otherwise includes77
9494 as part of its operations an external data privacy program no less stringent than the external78
9595 data privacy program as described in subparagraph (b)(3)(D) of this Code section. This79
9696 external data privacy program shall not preclude or supplant any similar program already80
9797 provided.81
9898 (d) This Code section shall not apply to any intergovernmental contracts or agreements a82
9999 local government enters with another local government, the federal government, the state,83
100100 or a political subdivision, agency, or authority thereof."84
101101 SECTION 2.85
102102 Chapter 25 of Title 50 of the Official Code of Georgia Annotated, relating to the Georgia86
103103 Technology Authority, is amended by revising Code Section 50-25-7.3, which is reserved,87
104104 as follows:88
105105 "50-25-7.3. 89
106106 (a) As used in this Code section, the term:90
107107 (1) 'Contractor' means any person entering a contractual relationship with the authority91
108108 that is either based upon a written contract or that provides a person with electronic or92
109109 physical access to any state or agency computer system, data systems, or facility93
110110 controlled or affiliated with the State of Georgia or one or more of its agencies, and shall94
111111 include all subcontractors of such person.95 23 LC 47 2184
112112 S. B. 161
113113 - 5 -
114114 (2) 'Data breach' means unauthorized access or disclosure of data under the contractor's96
115115 control or in the contractor's possession contrary to the terms of a contract between the97
116116 contractor and the agency or authority.98
117117 (3) 'Person' means any natural person, partnership, corporation, trust, association, or any99
118118 other legal entity, other than the federal government or the state or a political subdivision,100
119119 agency, or authority thereof.101
120120 (4) 'Personally identifiable information' means an individual's first name, last name,102
121121 home address, personal phone numbers, date of birth, email addresses.103
122122 (b) The authority shall, pursuant to its authorization under this chapter, apply the following104
123123 contractual requirements applicable to contractors, vendors, suppliers, and other entities105
124124 contracting or renewing a contract with an agency after January 1, 2024, apply which shall106
125125 include the following:107
126126 (1) That the contractor shall remain compliant with the external data privacy program108
127127 outlined in this Code section, and upon written request by either the authority or the109
128128 agency, shall provide any evidence demonstrating compliance via written response within110
129129 seven days or less;111
130130 (2) In the event of a data breach, the contractor shall use reasonable efforts to notify the112
131131 authority and the agency immediately of such data breach unless notification to an113
132132 alternative or additional entity is provided in the contract. The contractor shall take such114
133133 actions as may be necessary to preserve forensic evidence and eliminate the cause of the115
134134 data breach. The contractor shall give highest priority to immediately correcting any data116
135135 breach and shall devote such resources as may be required to accomplish that goal. The117
136136 contractor shall provide the authority and the agency with all information necessary to118
137137 enable the authority and the agency to fully understand the nature and scope of the data119
138138 breach, the scope of such information being at the discretion of the authority; and120 23 LC 47 2184
139139 S. B. 161
140140 - 6 -
141141 (3) The contractor shall enact an external data privacy program that shall include, at a121
142142 minimum, the following elements:122
143143 (A) The contractor shall perform, at a minimum, quarterly scans for each of its123
144144 employees' personally identifiable information:124
145145 (i) Across at least 350 known data brokers or people search websites, using such site's125
146146 public onsite search functionality; and126
147147 (ii) Using at least one major internet search engine, determine what information is127
148148 returned and easily obtainable using such search.128
149149 Such quarterly scans may be accomplished by manual effort or using an automated129
150150 service, so long as such scans are definitive;130
151151 (B) The contractor shall maintain a report of the information discovered from the scans131
152152 provided in subparagraph (A) of this paragraph. Using such information, the contractor132
153153 shall conduct an annual privacy risk assessment to evaluate its ongoing privacy policies133
154154 and security and access practices against standards identified in the contract based on134
155155 the data such contractor will have access to or otherwise handle pursuant to its contract135
156156 with the local government;136
157157 (C) The reports described in subparagraph (B) of this paragraph shall be maintained137
158158 by the contractor for a period of no less than three years, including after the conclusion138
159159 of the contract period, and shall be made available within seven days of a request from139
160160 the local government or alternative entity provided in the contract in the event a past140
161161 data breach is found to have occurred, of a suspected data breach, or of an actual data141
162162 breach described in subparagraph (A) of paragraph (2) of this Code section. The142
163163 contract between the agency or the authority and contractor may provide that the143
164164 agency or the authority maintain such records; and144
165165 (D) The contractor shall certify to the authority and the agency that it conducts at least145
166166 annually a privacy training for such contractor's employees that includes information146
167167 on its external data privacy program, and the risks associated with data brokers and147 23 LC 47 2184
168168 S. B. 161
169169 - 7 -
170170 external data privacy, including, but not limited to, that external data exposures are used148
171171 to craft highly targeted social engineering and spear phishing attacks. Such privacy149
172172 training shall not preclude or supplant any privacy training the contractor already150
173173 provides to its employees.151
174174 (c) Contractors shall certify to the authority and the agency that it maintains or otherwise152
175175 includes as part of its operations an external data privacy program no less stringent than the153
176176 external data privacy program as described in subparagraph (b)(3)(D) of this Code section.154
177177 This external data privacy program shall not preclude or supplant any similar program155
178178 already provided.156
179179 (d) This Code section shall not apply to any intergovernmental contracts or agreements an157
180180 agency enters with another agency, the federal government, the state, or a local158
181181 government, political subdivision, agency, or authority thereof. Reserved."159
182182 SECTION 3.160
183183 All laws and parts of laws in conflict with this Act are repealed.161