Oklahoma 2024 Regular Session

Oklahoma Senate Bill SB1337 Compare Versions

OldNewDifferences
11
22
3-SENATE FLOOR VERSION - SB1337 SFLR Page 1
4-(Bold face denotes Comm ittee Amendments) 1
3+Req. No. 3538 Page 1 1
54 2
65 3
76 4
87 5
98 6
109 7
1110 8
1211 9
1312 10
1413 11
1514 12
1615 13
1716 14
1817 15
1918 16
2019 17
2120 18
2221 19
2322 20
2423 21
2524 22
2625 23
2726 24
2827
29-SENATE FLOOR VERSION
30-February 20, 2024
28+STATE OF OKLAHOMA
3129
30+2nd Session of the 59th Legislature (2024)
3231
3332 COMMITTEE SUBSTITUTE
3433 FOR
35-SENATE BILL NO. 1337 By: Howard
34+SENATE BILL 1337 By: Howard
3635
3736
3837
3938
39+
40+COMMITTEE SUBSTITUTE
4041
4142 An Act relating to the Security Breach Notification
4243 Act; amending 24 O.S. 2021, Sections 162, 163, 164,
4344 165, and 166, which relate to definitions, duty to
4445 disclose breach, notice , enforcement, and
4546 application; modifying definitions; requiring notice
4647 of security breach of certain information; re quiring
4748 notice to Attorney General under certain
4849 circumstances; specifying contents of required
4950 notice; providing exemptions from certain notice
5051 requirements; requiring c onfidentiality of certain
5152 information submitted to Attorney General;
5253 authorizing Attorney General to promulgate rules;
5354 clarifying compliance with certa in notice
5455 requirements; modifying authorized civil penalties
5556 for certain violations; providing exemptions from
5657 certain liability; limit ing liability for violations
5758 under certain circumstances; modifying applicabil ity
5859 of act; updating statutory language; updating
5960 statutory references; and providing an effective
6061 date.
6162
6263
6364
6465
6566 BE IT ENACTED BY THE PEOPLE OF THE STATE OF OKLAHOMA:
6667 SECTION 1. AMENDATORY 24 O.S. 2021, Section 162, is
6768 amended to read as follows:
6869 Section 162. As used in the Security Breach Notification Act:
69-1. “Breach of the security of a system ” means the unauthorized
70-access and acquisition of unencrypted and unredacted computerized
7170
72-SENATE FLOOR VERSION - SB1337 SFLR Page 2
73-(Bold face denotes Comm ittee Amendments) 1
71+Req. No. 3538 Page 2 1
7472 2
7573 3
7674 4
7775 5
7876 6
7977 7
8078 8
8179 9
8280 10
8381 11
8482 12
8583 13
8684 14
8785 15
8886 16
8987 17
9088 18
9189 19
9290 20
9391 21
9492 22
9593 23
9694 24
9795
96+1. “Breach of the security of a system ” means the unauthorized
97+access and acquisition of unencrypted and unredacted computerized
9898 data that compromises the security or confidentiality of personal
9999 information maintained by an individual or enti ty as part of a
100100 database of personal information regarding multiple individua ls and
101101 that causes, or the individual or entity reasonably believes has
102102 caused or will cause, identity theft or ot her fraud to any resident
103103 of this state. Good faith acquisition of personal information by an
104104 employee or agent of an individual or entity for the purposes of the
105105 individual or the entity is not a breach of the security of the
106106 system, provided that the personal information is not use d for a
107107 purpose other than a lawful purpose of the individual or entity or
108108 subject to further unauthorized disclosure;
109109 2. “Entity” includes corporations , business trusts, estates,
110110 partnerships, limited partnerships, limited li ability partnerships,
111111 limited liability companies, associations, organizations, joint
112112 ventures, governments, governmental subdivisions, agencies, or
113113 instrumentalities, or any other legal entity, whether for profit or
114114 not-for-profit;
115115 3. “Encrypted” means transformation of data through the use of
116116 an algorithmic process i nto a form in which there is a low
117117 probability of assigni ng meaning without u se of a confidential
118118 process or key, or securing the information by anothe r method that
119119 renders the data elements unreadable or unusable;
120120
121-SENATE FLOOR VERSION - SB1337 SFLR Page 3
122-(Bold face denotes Comm ittee Amendments) 1
121+Req. No. 3538 Page 3 1
123122 2
124123 3
125124 4
126125 5
127126 6
128127 7
129128 8
130129 9
131130 10
132131 11
133132 12
134133 13
135134 14
136135 15
137136 16
138137 17
139138 18
140139 19
141140 20
142141 21
143142 22
144143 23
145144 24
146145
147146 4. “Financial institution” means any institution the business
148147 of which is engaging in financial activities as defined by 15
149148 U.S.C., Section 6809;
150149 5. “Individual” means a natural person;
151150 6. “Personal information ” means the an individual’s first name
152151 or first initial and last name in combination with and linked to any
153152 one or more of the following data elements that r elate to a resident
154153 of this state, when the individual if any of the data elements are
155154 neither not encrypted, nor redacted, or otherwise altered by any
156155 method or technology in such a manner that the name or data elements
157156 are unreadable or are encr ypted, redacted, or otherwise altered by
158157 any method or technology but the keys to unencrypt, unredact, or
159158 otherwise read the data elem ents have been obtained th rough the
160159 breach of security:
161160 a. social security number,
162161 b. driver license number or state other unique
163162 identification card number issued in lieu of a driver
164163 license, or created or collected by a government
165164 entity,
166165 c. financial account number, or credit card o r debit card
167166 number, in combination with any required expiration
168167 date, security code, access code, or password that
169168 would permit access to the an individual’s financial
170169 accounts of a resident account,
171170
172-SENATE FLOOR VERSION - SB1337 SFLR Page 4
173-(Bold face denotes Comm ittee Amendments) 1
171+Req. No. 3538 Page 4 1
174172 2
175173 3
176174 4
177175 5
178176 6
179177 7
180178 8
181179 9
182180 10
183181 11
184182 12
185183 13
186184 14
187185 15
188186 16
189187 17
190188 18
191189 19
192190 20
193191 21
194192 22
195193 23
196194 24
197195
198196 d. unique electronic identifier or routing code in
199197 combination with any require d security code, access
200198 code, or password that would permit access to an
201199 individual’s financial account, or
202200 e. unique biometric data such as a fingerprint, retina or
203201 iris image, or other unique physical or digital
204202 representation of biometric data.
205203 The term does not include information that is lawfully obtained from
206204 publicly available information sources, or from federal, state or
207205 local government records lawfully made available to the general
208206 public;
209207 7. “Notice” means:
210208 a. written notice to the postal address in the records
211209 of the individual or entity,
212210 b. telephone notice,
213211 c. electronic notice, or
214212 d. substitute notice, if the individual or the entity
215213 required to provide notice demonstrates that the cost
216214 of providing notice will exceed Fifty Thousand Dollars
217215 ($50,000.00), or that the affected class of residents
218216 to be notified exceeds one hundr ed thousand (100,000)
219217 persons, or that the individual or the entity does not
220218 have sufficient contact inf ormation or consent t o
221219 provide notice as described in subparagraph a, b or c
222220
223-SENATE FLOOR VERSION - SB1337 SFLR Page 5
224-(Bold face denotes Comm ittee Amendments) 1
221+Req. No. 3538 Page 5 1
225222 2
226223 3
227224 4
228225 5
229226 6
230227 7
231228 8
232229 9
233230 10
234231 11
235232 12
236233 13
237234 14
238235 15
239236 16
240237 17
241238 18
242239 19
243240 20
244241 21
245242 22
246243 23
247244 24
248245
249246 of this paragraph. Substitute notice consists of any
250247 two of the following:
251248 (1) e-mail email notice if the individual or the
252249 entity has e-mail email addresses for the members
253250 of the affected class of residents,
254251 (2) conspicuous posting of the notice on the Internet
255252 web site website of the individual or the entity
256253 if the individual or the entity maint ains a
257254 public Internet web site website, or
258255 (3) notice to major stat ewide media; and
259256 8. “Reasonable safeguards” means policies and practices that
260257 ensure personal information is secure, taking into consideration an
261258 entity’s size and the type and amount of personal information . The
262259 term includes but is not limited to conducting r isk assessments,
263260 implementing technical and physica l layered defenses, employee
264261 training on handling personal information, and establishing an
265262 incident response plan ; and
266263 9. “Redact” means alteration or tru ncation of data such that no
267264 more than the following are accessible as par t of the personal
268265 information:
269266 a. five digits of a social security number, or
270267 b. the last four digits of a driver license number, state
271268 unique identification card number created or collected
272269 by a government entity, or account number.
273270
274-SENATE FLOOR VERSION - SB1337 SFLR Page 6
275-(Bold face denotes Comm ittee Amendments) 1
271+Req. No. 3538 Page 6 1
276272 2
277273 3
278274 4
279275 5
280276 6
281277 7
282278 8
283279 9
284280 10
285281 11
286282 12
287283 13
288284 14
289285 15
290286 16
291287 17
292288 18
293289 19
294290 20
295291 21
296292 22
297293 23
298294 24
299295
300296 SECTION 2. AMENDATORY 24 O.S. 2021, Section 163, is
301297 amended to read as follows:
302298 Section 163. A. An individual or entity that owns or licenses
303299 computerized data that includes personal informat ion shall disclose
304300 provide notice of any breach of the security of the system following
305301 discovery determination or notification of the breach of the
306302 security of the system to any resident of this state whose
307303 unencrypted and unredacted personal information was or is reasona bly
308304 believed to have been access ed and acquired by an unauthorized
309305 person and that causes, or the individual or entity reasona bly
310306 believes has caused or will cause, ident ity theft or other fraud to
311307 any resident of this state. Except as provided in subsection D of
312308 this section or in order to take any measures necessary to determine
313309 the scope of the breach and to restore the reasonable integrity of
314310 the system, the disclosure s hall be made without unreasonable delay.
315311 B. An individual or entity must disclose shall provide notice
316312 of the breach of the security of the system if encrypted or redacted
317313 information is accessed and acquired in an unenc rypted or unredacted
318314 form or if the security breach involves a person with access to the
319315 encryption key and the ind ividual or entity reasonably believes that
320316 such breach has caused or will cause identity theft or other fraud
321317 to any resident of this state.
322318 C. An individual or entity that ma intains computerized data
323319 that includes personal information that the individual or entity
324320
325-SENATE FLOOR VERSION - SB1337 SFLR Page 7
326-(Bold face denotes Comm ittee Amendments) 1
321+Req. No. 3538 Page 7 1
327322 2
328323 3
329324 4
330325 5
331326 6
332327 7
333328 8
334329 9
335330 10
336331 11
337332 12
338333 13
339334 14
340335 15
341336 16
342337 17
343338 18
344339 19
345340 20
346341 21
347342 22
348343 23
349344 24
350345
351346 does not own or license shall notify provide notice to the owner or
352347 licensee of the infor mation of any breach of the sec urity of the
353348 system as soon as practicable following discovery determination, if
354349 the personal information was or if the entity reasonably believes it
355350 was accessed and acquired by an unauthorized person.
356351 D. Notice required by this section may be delayed if a law
357352 enforcement agency determines and advi ses the individual or entity
358353 that the notice will impede a criminal or civil investigation or
359354 homeland or national security. Notice required by this section must
360355 be made without unre asonable delay after the law enforcement agen cy
361356 determines that notification will no longer impede the inve stigation
362357 or jeopardize national or homeland security.
363358 E. 1. An individual or entity required to pro vide notice in
364359 accordance with subsection A, B, or C of this section shall also
365360 provide notice to the Attorney General o f such breach without
366361 unreasonable delay but in no event more than sixty (60) days after
367362 providing notice to impacted resi dents of this state as requir ed by
368363 this section. The notice shall include the date of the breach, the
369364 date of its determination, the nature of the breach, the type o f
370365 personal information exposed, the number of residents of this st ate
371366 affected, the estimated monetary impact of the br each to the extent
372367 such impact can be determined, and any reasonable safeguards the
373368 entity employs.
374369
375-SENATE FLOOR VERSION - SB1337 SFLR Page 8
376-(Bold face denotes Comm ittee Amendments) 1
370+Req. No. 3538 Page 8 1
377371 2
378372 3
379373 4
380374 5
381375 6
382376 7
383377 8
384378 9
385379 10
386380 11
387381 12
388382 13
389383 14
390384 15
391385 16
392386 17
393387 18
394388 19
395389 20
396390 21
397391 22
398392 23
399393 24
400394
401395 2. A breach of a security system where fewer than five hundred
402396 (500) residents of this state are affected within a single brea ch
403397 shall be exempt from the n otice requirements of paragraph 1 of this
404398 subsection.
405399 3. A breach of a security system maintained by a credit bureau
406400 where fewer than one thousand (1,000) residents of this state are
407401 affected within a single breach shall be exempt from the notice
408402 requirements of paragraph 1 of this subsection.
409403 F. Any personal information submitted t o the Attorney Gener al
410404 shall be kept confidential pursuant to Section 24A.12 of Title 51 of
411405 the Oklahoma Statutes .
412406 G. The Attorney General may promulgate rules as necessary to
413407 effectuate the provisions of this se ction.
414408 SECTION 3. AMENDATORY 24 O.S. 2021, Section 164, is
415409 amended to read as follows:
416410 Section 164. A. An individual or entity that maintains its own
417411 notification procedures as part of an inf ormation privacy or
418412 security policy for the treatment of personal information an d that
419413 are consistent with the timing requirements of this act the Security
420414 Breach Notification Act shall be deemed to be in compliance with the
421415 notification requirements of this act subsection A, B, or C of
422416 Section 163 of this title if it the individual or entity notifies
423417 residents of this state in accordance with its proc edures in the
424418 event of a breach of security of the system.
425419
426-SENATE FLOOR VERSION - SB1337 SFLR Page 9
427-(Bold face denotes Comm ittee Amendments) 1
420+Req. No. 3538 Page 9 1
428421 2
429422 3
430423 4
431424 5
432425 6
433426 7
434427 8
435428 9
436429 10
437430 11
438431 12
439432 13
440433 14
441434 15
442435 16
443436 17
444437 18
445438 19
446439 20
447440 21
448441 22
449442 23
450443 24
451444
452445 B. The following entities shall be deemed to be in compliance
453446 with the notification requirements of subsection A, B, or C of
454447 Section 163 of this title if such entities provide the notice to the
455448 Attorney General as required by subsection E of Section 163 of this
456449 title:
457450 1. A financial institution that c omplies with the notification
458-requirements prescribed by the Federal Gramm-Leach-Bliley Act and
459-the federal Interagency Guidance on Response Programs for
460-Unauthorized Access to Custome r Information and Customer Notice is
461-deemed to be in compliance with the provisions of this act. ;
451+requirements prescribed by the Federal federal Interagency Guidance
452+on Response Programs for Unauthorized Access to Custome r Information
453+and Customer Notice is deemed to be in compliance with the
454+provisions of this act. ;
462455 2. An entity that complies with the notification requirements
463456 prescribed by the Okla homa Hospital Cybersecurity Protection Act of
464457 2023 or the Health Insurance Portability a nd Accountability Act of
465458 1996 (HIPAA); and
466459 3. An entity that complies with the notifica tion requirements
467460 or procedures pursuant t o the rules, regulation regulations,
468461 procedures, or guidelines established by the primary or functional
469462 federal regulator of the entity shall be deemed to be in compliance
470463 with the provisions of this act .
471464 SECTION 4. AMENDATORY 24 O.S. 2021, Section 165, is
472465 amended to read as follows:
473466 Section 165. A. A violation of this act the Security Breach
474467 Notification Act that results in injury or loss to residents of this
475468 state may be enforced by the Attorney General or a district attorney
476469
477-SENATE FLOOR VERSION - SB1337 SFLR Page 10
478-(Bold face denotes Comm ittee Amendments) 1
470+Req. No. 3538 Page 10 1
479471 2
480472 3
481473 4
482474 5
483475 6
484476 7
485477 8
486478 9
487479 10
488480 11
489481 12
490482 13
491483 14
492484 15
493485 16
494486 17
495487 18
496488 19
497489 20
498490 21
499491 22
500492 23
501493 24
502494
503495 in the same manner as an unlawful practice under t he Oklahoma
504496 Consumer Protection Act.
505497 B. Except as provided in subsection C D of this section, the
506498 Attorney General or a district attorney shall have exclu sive
507499 authority to bring an action and may obtain either actual damages
508500 for a violation of this act or the Security Breach Notification Act
509501 and a civil penalty not to exceed One Hundre d Fifty Thousand Dollars
510502 ($150,000.00) per breach of the security of the system or series of
511503 breaches of a similar natu re that are discovered determined in a
512504 single investigation or Two Thousand Dollars ($2,000.00) for each
513505 resident of the state for each breach, whichever is greater, or a
514506 combination of such actual damages and civil penalty. Civil
515507 penalties shall be based upon the magnitude of the breach, the
516508 extent to which the behavio r of the individual or entity contributed
517509 to the breach, and any failure to provide the notice required by
518510 Section 163 of this title.
519511 C. 1. An individual or entity that uses reasonable safeguards
520512 and provides notice as re quired by Section 163 or 164 of this title
521513 shall not be subject to civil penalties and may use such compliance
522514 as an affirmative defense in a civil a ction filed under the Security
523515 Breach Notification Act.
524516 2. An individual or entity that fails to use reasonable
525517 safeguards but provides notice as required by Section 163 or 164 of
526518 this title shall not be subject to the civil penalty set forth in
527519
528-SENATE FLOOR VERSION - SB1337 SFLR Page 11
529-(Bold face denotes Comm ittee Amendments) 1
520+Req. No. 3538 Page 11 1
530521 2
531522 3
532523 4
533524 5
534525 6
535526 7
536527 8
537528 9
538529 10
539530 11
540531 12
541532 13
542533 14
543534 15
544535 16
545536 17
546537 18
547538 19
548539 20
549540 21
550541 22
551542 23
552543 24
553544
554545 subsection B of this section. Such individuals or entities shall be
555546 subject to a civil pe nalty of One Hundred Dollars ($100. 00) for each
556547 resident of this state for each breach not to exceed a total penalt y
557548 of One Hundred Thousand Dollars ($10 0,000.00).
558549 C. D. A violation of this act the Security Breach Notification
559550 Act by a state-chartered or state-licensed financial institution
560551 shall be enforceable exc lusively by the primary state regulator of
561552 the financial institution.
562553 SECTION 5. AMENDATORY 24 O.S. 2021, Section 166, is
563554 amended to read as follows:
564555 Section 166. This act The Security Breach Notification Act
565556 shall apply to the discovery determination or notification of a
566557 breach of the security of the system th at occurs on or after
567558 November 1, 2008 January 1, 2025.
568559 SECTION 6. This act shall become effective January 1, 2025.
569-COMMITTEE REPORT BY: COMMITTEE ON JUDICIARY
570-February 20, 2024 - DO PASS AS AMENDED BY CS
560+
561+59-2-3538 TEK 2/20/2024 5:37:46 PM