Req. No. 7687 Page 1 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 STATE OF OKLAHOMA 1st Session of the 58th Legislature (2021) COMMITTEE SUBSTITUTE FOR HOUSE BILL NO. 2350 By: Lawson COMMITTEE SUBSTITUTE An Act relating to state government data systems; creating the Task Force on State Data Storage and Retrieval Systems; providing for membership; requiring organizational meeting; providing for selection of chair and vice -chair; requiring notice of meetings; authorizing meetings; providing for quorum; providing for staff assistance; imposing duties on Task Force; requiring reports; specifying content of reports; providing for codification; providing an effective date; and declaring an emergency. BE IT ENACTED BY THE PEOPLE OF THE STATE OF OKLAHOMA: SECTION 1. NEW LAW A ne w section of law to be codified in the Oklahoma Statutes as Section 25001 of Title 74, unless there is created a duplication in numbering, reads as follows: A. There is hereby created the Task Force on State Data Storage and Retrieval Systems. B. The Task Force shall be composed of the following persons appointed or selected as follows: Req. No. 7687 Page 2 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 1. One person appointed by the Governor who shall be the Chief Information Officer or a designee of the Chief Information Officer; 2. Three persons selected by the Speak er of the Oklahoma House of Representatives; 3. Three persons selected by the President Pro Tempore of the Oklahoma State Senate; 4. Two persons selected by the Director of the Office of Management and Enterprise Services; 5. One person selected by the following state governmental entities: a. the Oklahoma Tax Commission, b. the Department of Human Services, c. the State Department of Health, d. the Oklahoma Department of Mental Health and Substance Abuse Services, e. the Oklahoma Corporation Commission, f. the Oklahoma Securities Commission, g. the Oklahoma Banking Commissioner, h. the Oklahoma State Bureau of Investigation, i. the Oklahoma Bureau of Narcotics and Dangerous Drugs Control, j. the Oklahoma Employment Security Commission, k. the Oklahoma Department of Public Safety, l. the Oklahoma Department of Corrections, Req. No. 7687 Page 3 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 m. the Office of Juvenile Affairs, n. the State Election Board, o. the Oklahoma Department of Veterans Affairs, and p. the Oklahoma Health Care Authority. C. The Task Force shall hold a n organizational meeting not later than sixty (60) days from the effective date of this act. D. The Task Force shall select from among its membership a chair and vice-chair. Neither the Chief Information Officer nor the appointees of the Oklahoma Office of Management and Enterprise Services shall be eligible to serve as chair or vice -chair. E. The Task Force shall post notices of its meetings on a website maintained by the Oklahoma House of Representatives and the Oklahoma State Senate, but shall not be subject to the requirements of the Oklahoma Open Meeting Act. F. The Task Force shall be authorized to meet as often as required in order to perform the duties imposed upon it, but shall meet no less than two times each calendar year. A majority of the members present at a meeting shall constitute a quorum in order to take any official action, including the adoption of an annual report. G. Staff assistance for the Task Force shall be provided by the Oklahoma House of Representatives, the Oklahoma State Senate, and the Chief Information Officer. Req. No. 7687 Page 4 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 H. The Task Force shall submit an annual report regarding the storage of personal information related to individual persons, including personally identifiable information (PII) as well as any other data stored on persons by any state governmental entity (hereafter referred to as "Citizen Data"), to the Governor, the Speaker of the Oklahoma House of Representatives, and the President Pro Tempore of the Oklahoma State Senate not later than December 31 of each calendar year. Each annual report shall at a minimum contain: 1. An overview of the data maintained by all state governmental entities, including: a. an analysis of duplication of Citizen Data across entities, b. an analysis of vulnerabilities and threats to t he safety and security of Citizen Data; 2. An analysis of opportunities to consolidate duplicated Citizen Data into the central data repository, including: a. recommendations for data migration to take advantage of any such opportunities, b. an estimate of costs related to moving the data from the source entity, and c. a discussion of any state or federal data privacy laws that may impact access to data in the central data repository; Req. No. 7687 Page 5 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 3. Recommendations for the maintenance, upgrade, security enhancement, or capacity expansion of the central data repository, including hardware, software, network, and other infrastructure upgrades and improvements. I. Additionally, the Task Force shall gather information and make recommendations in its initial report regard ing: 1. The ability of executive agencies, boards, commissions, departments or other state governmental entities, including institutions within The Oklahoma State System of Higher Education, to access information about a person or business entity from oth er agencies, boards, commissions, departments or state governmental entities and whether such access is consistent with industry data privacy standards and any state or federal data privacy laws; 2. The security features the hardware and software systems currently responsible for entry of and storage of such information and whether there are actions that should be taken to improve data entry and storage, including data privacy; 3. The feasibility of integrating state government data storage related to personal information or information regarding business entities or other lawfully recognized entities; and 4. Such other aspects of state computer data entry, storage, access, retrieval and privacy as the Task Force deems to be relevant. Req. No. 7687 Page 6 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 J. The initial repo rt of the Task Force shall be submitted to the Governor, the Speaker of the Oklahoma House of Representatives, the President Pro Tempore of the Oklahoma State Senate not later than December 31, 2022. K. Each annual report shall contain specific recommenda tions related to the functionality of the state data entry, storage and retrieval systems with particular emphasis on the ability for different state governmental entities to have access to relevant information about natural persons in order to deliver a h igher quality service to such persons and to business entities or other lawfully recognized entities consistent with technological standards governing data storage, retrieval and data privacy requirements. SECTION 2. This act shall become effective July 1, 2021. SECTION 3. It being immediately necessary for the preservation of the public peace, health or safety, an emergency is hereby declared to exist, by reason whereof this act shall take effect and be in full force from and after its passage and approval. 58-1-7687 JBH 02/23/21