Oklahoma 2025 Regular Session

Oklahoma Senate Bill SB626 Compare Versions

OldNewDifferences
11
22
3-SB626 HFLR Page 1
4-BOLD FACE denotes Committee Amendments. 1
3+ENGR. S. B. NO. 626 Page 1 1
54 2
65 3
76 4
87 5
98 6
109 7
1110 8
1211 9
1312 10
1413 11
1514 12
1615 13
1716 14
1817 15
1918 16
2019 17
2120 18
2221 19
2322 20
2423 21
2524 22
2625 23
2726 24
28-
29-HOUSE OF REPRESENTATIVES - FLOOR VERSION
30-
31-STATE OF OKLAHOMA
32-
33-1st Session of the 60th Legislature (2025)
3427
3528 ENGROSSED SENATE
3629 BILL NO. 626 By: Howard of the Senate
3730
3831 and
3932
4033 Pfeiffer of the House
4134
4235
4336
4437
4538 An Act relating to the Security Breach Notification
4639 Act; amending 24 O.S. 2021, Sections 162, 163, 164,
4740 165, and 166, which relate to definitions, duty to
4841 disclose breach, notice, enforcement, and
4942 application; modifying definitions; requiring notice
5043 of security breach of certain information; requiring
5144 notice to Attorney General under certain
5245 circumstances; specifying contents of required
5346 notice; providing exemptions from certain notice
5447 requirements; requiring confidentiality of certain
5548 information submitted to Attorney General;
5649 authorizing Attorney General to promulgate rules;
5750 clarifying compliance with certain notice
5851 requirements; modifying authorized civil penalties
5952 for certain violations; providing exemptions from
6053 certain liability; limiting liability for violations
6154 under certain circumstances; modifying applicability
6255 of act; updating statutory language; updating
6356 statutory references; and providing an effective
6457 date.
6558
6659
6760
6861
6962 BE IT ENACTED BY THE PEOPLE OF THE STATE OF OKLAHOMA:
7063 SECTION 1. AMENDATORY 24 O.S. 2021, Section 162, is
7164 amended to read as follows:
7265 Section 162. As used in the Security Breach Notification Act:
66+1. “Breach of the security of a system” means the unauthorized
67+access and acquisition of unencrypted and unredacted computerized
68+data that compromises the security or confidentiality of personal
7369
74-SB626 HFLR Page 2
75-BOLD FACE denotes Committee Amendments. 1
70+ENGR. S. B. NO. 626 Page 2 1
7671 2
7772 3
7873 4
7974 5
8075 6
8176 7
8277 8
8378 9
8479 10
8580 11
8681 12
8782 13
8883 14
8984 15
9085 16
9186 17
9287 18
9388 19
9489 20
9590 21
9691 22
9792 23
9893 24
9994
100-1. “Breach of the security of a system ” means the unauthorized
101-access and acquisition of unencrypted and unredacted computerized
102-data that compromises the security or confidenti ality of personal
10395 information maintained by an individual or entity as part of a
10496 database of personal inf ormation regarding multiple individuals and
10597 that causes, or the individual or entity reasonably believes has
10698 caused or will cause, identity theft or other fraud to any resident
10799 of this state. Good faith acquisition of personal information by an
108100 employee or agent of an individual or entity for the purposes of the
109101 individual or the entity is not a breach of the security of the
110102 system, provided that the personal information is not used for a
111103 purpose other than a lawful purpose of the individual or entity or
112104 subject to further unauthorized disclosure;
113105 2. “Entity” includes corporations, business trusts, estates,
114106 partnerships, limited partnerships, limited liability partnerships,
115107 limited liability companies, associations, organizations, joint
116108 ventures, governments, governmental subdivisions, agencies, or
117109 instrumentalities, or any other legal entity, whether for profit or
118110 not-for-profit;
119111 3. “Encrypted” means transformation of data through the use of
120112 an algorithmic process into a form in which there is a low
121113 probability of assigning meaning without use of a confidential
122114 process or key, or securing the information by another method that
123115 renders the data elements unreadable or unusable;
116+4. “Financial institution ” means any institution the business
117+of which is engaging in financial activities as defined by 15
118+U.S.C., Section 6809;
124119
125-SB626 HFLR Page 3
126-BOLD FACE denotes Committee Amendments. 1
120+ENGR. S. B. NO. 626 Page 3 1
127121 2
128122 3
129123 4
130124 5
131125 6
132126 7
133127 8
134128 9
135129 10
136130 11
137131 12
138132 13
139133 14
140134 15
141135 16
142136 17
143137 18
144138 19
145139 20
146140 21
147141 22
148142 23
149143 24
150144
151-4. “Financial institution ” means any institution the business
152-of which is engaging in financial activities as defined by 15
153-U.S.C., Section 6809;
154145 5. “Individual” means a natural person;
155146 6. “Personal information ” means the an individual’s first name
156147 or first initial and last name in combination with and linked to any
157148 one or more of the following data elements that relate to a resident
158149 of this state, when the individual if any of the data elements are
159150 neither not encrypted, nor redacted, or otherwise altered by any
160151 method or technology in such a manner that the name or data elements
161152 are unreadable or are encrypted, redacted, or otherwise altered by
162153 any method or technology but the keys to unencrypt, unredact, or
163154 otherwise read the data elements have been obtained through the
164155 breach of security:
165156 a. social security number,
166157 b. driver license number or state other unique
167158 identification card number issued in lieu of a driver
168159 license, or created or collected by a government
169160 entity,
170161 c. financial account number, or credit card or debit card
171162 number, in combination with any required expiration
172163 date, security code, access code, or password that
173164 would permit access to the an individual’s financial
174165 accounts of a resident account,
166+d. unique electronic identifier or routing code in
167+combination with any required security code, access
175168
176-SB626 HFLR Page 4
177-BOLD FACE denotes Committee Amendments. 1
169+ENGR. S. B. NO. 626 Page 4 1
178170 2
179171 3
180172 4
181173 5
182174 6
183175 7
184176 8
185177 9
186178 10
187179 11
188180 12
189181 13
190182 14
191183 15
192184 16
193185 17
194186 18
195187 19
196188 20
197189 21
198190 22
199191 23
200192 24
201193
202-d. unique electronic identifier or routing code in
203-combination with any required security code, access
204194 code, or password th at would permit access to an
205195 individual’s financial account, or
206196 e. unique biometric data such as a fingerprint, retina or
207197 iris image, or other unique physical or digital
208198 representation of biometric data to authenticate a
209199 specific individual.
210200 The term does not include information that is lawfully obtained from
211201 publicly available information sources, or from federal, state or
212202 local government records lawfully made available to the general
213203 public;
214204 7. “Notice” means:
215205 a. written notice to the postal address in the records
216206 of the individual or entity,
217207 b. telephone notice,
218208 c. electronic notice, or
219209 d. substitute notice, if the individual or the entity
220210 required to provide notice demonstrates that the cost
221211 of providing notice will exceed Fifty Thousand Dollars
222212 ($50,000.00), or that the affected class of residents
223213 to be notified exceeds one hundred thousand (100,000)
224214 persons, or that the individual or the entity does not
225215 have sufficient contact information or consent to
216+provide notice as described in subparagraph a, b , or c
226217
227-SB626 HFLR Page 5
228-BOLD FACE denotes Committee Amendments. 1
218+ENGR. S. B. NO. 626 Page 5 1
229219 2
230220 3
231221 4
232222 5
233223 6
234224 7
235225 8
236226 9
237227 10
238228 11
239229 12
240230 13
241231 14
242232 15
243233 16
244234 17
245235 18
246236 19
247237 20
248238 21
249239 22
250240 23
251241 24
252242
253-provide notice as described in subparagraph a, b , or c
254243 of this paragraph. Substitute notice consists of any
255244 two of the following:
256245 (1) e-mail email notice if the individual or the
257246 entity has e-mail email addresses for the members
258247 of the affected class of residents,
259248 (2) conspicuous posting of the notice o n the Internet
260249 web site website of the individual or the entity
261250 if the individual or the entity maintains a
262251 public Internet web site website, or
263252 (3) notice to major statewide media; and
264253 8. “Reasonable safeguards ” means policies and practices that
265254 ensure personal information is secure, taking into consideration an
266255 entity’s size and the type and amount of personal information. The
267256 term includes, but is not limited to, conducting risk assessments,
268257 implementing technical and physical layered defenses, employe e
269258 training on handling personal information, and establishing an
270259 incident response plan; and
271260 9. “Redact” means alteration or truncation of data such that no
272261 more than the following are accessible as part of the personal
273262 information:
274263 a. five digits of a social security number, or
264+b. the last four digits of a driver license number, state
265+unique identification card number created or collected
266+by a government entity, or account number.
275267
276-SB626 HFLR Page 6
277-BOLD FACE denotes Committee Amendments. 1
268+ENGR. S. B. NO. 626 Page 6 1
278269 2
279270 3
280271 4
281272 5
282273 6
283274 7
284275 8
285276 9
286277 10
287278 11
288279 12
289280 13
290281 14
291282 15
292283 16
293284 17
294285 18
295286 19
296287 20
297288 21
298289 22
299290 23
300291 24
301292
302-b. the last four digits of a driver license number, state
303-unique identification card number created or collected
304-by a government entity, or account number.
305293 SECTION 2. AMENDATORY 24 O.S. 2021, Section 163, is
306294 amended to read as follows:
307295 Section 163. A. An individual or entity that owns or licenses
308296 computerized data that includes personal information shall disclose
309297 provide notice of any breach of the security of the system following
310298 discovery determination or notification of the breach of the
311299 security of the system to any resident of this state whose
312300 unencrypted and unredacted personal information was or is reasonably
313301 believed to have been accessed and acquired by an unauthorized
314302 person and that causes, or t he individual or entity reasonably
315303 believes has caused or will cause, identity theft or other fraud to
316304 any resident of this state. Except as provided in subsection D of
317305 this section or in order to take any measures necessary to determine
318306 the scope of the breach and to restore the reasonable integrity of
319307 the system, the disclosure shall be made without unreasonable delay.
320308 B. An individual or entity must disclose shall provide notice
321309 of the breach of the security of the system if encrypted or redacted
322310 information is accessed and acquired in an unencrypted or unredacted
323311 form or if the security breach involves a person with access to the
324312 encryption key and the individual or entity reasonably believes that
313+such breach has caused or will cause identity theft or other fraud
314+to any resident of this state.
315+C. An individual or entity that maintains computerized data
316+that includes personal information that the individual or entity
325317
326-SB626 HFLR Page 7
327-BOLD FACE denotes Committee Amendments. 1
318+ENGR. S. B. NO. 626 Page 7 1
328319 2
329320 3
330321 4
331322 5
332323 6
333324 7
334325 8
335326 9
336327 10
337328 11
338329 12
339330 13
340331 14
341332 15
342333 16
343334 17
344335 18
345336 19
346337 20
347338 21
348339 22
349340 23
350341 24
351342
352-such breach has caused or will cause identity theft or other fraud
353-to any resident of this state.
354-C. An individual or entity that maintains computerized data
355-that includes personal information that the ind ividual or entity
356343 does not own or license shall notify provide notice to the owner or
357344 licensee of the information of any breach of the security of the
358345 system as soon as practicable following discovery determination, if
359346 the personal information was or if the entity reasonably believes it
360347 was accessed and acquired by an unauthorized person.
361348 D. Notice required by this section may be delayed if a law
362349 enforcement agency determines and advises the individual or entity
363350 that the notice will impede a criminal or civil investigation or
364351 homeland or national security. Notice required by this section must
365352 be made without unreasonable delay after the law enforcement agency
366353 determines that notification will no longer impede the investigation
367354 or jeopardize national or homeland security.
368355 E. 1. An individual or entity required to provide notice in
369356 accordance with subsection A, B, or C of this section shall also
370357 provide notice to the Attorney General of such breach without
371358 unreasonable delay but in no event more than sixty (60) days after
372359 providing notice to impacted residents of this state as required by
373360 this section. The no tice shall include the date of the breach, the
374361 date of its determination, the nature of the breach, the type of
375362 personal information exposed, the number of residents of this state
363+affected, the estimated monetary impact of the breach to the extent
364+such impact can be determined, and any reasonable safeguards the
365+entity employs.
376366
377-SB626 HFLR Page 8
378-BOLD FACE denotes Committee Amendments. 1
367+ENGR. S. B. NO. 626 Page 8 1
379368 2
380369 3
381370 4
382371 5
383372 6
384373 7
385374 8
386375 9
387376 10
388377 11
389378 12
390379 13
391380 14
392381 15
393382 16
394383 17
395384 18
396385 19
397386 20
398387 21
399388 22
400389 23
401390 24
402391
403-affected, the estimated monetary impact of the breach to the extent
404-such impact can be determined, and any reasonable safeguards the
405-entity employs.
406392 2. A breach of a security system where fewer than five hundred
407393 (500) residents of this state are affected within a single breach
408394 shall be exempt from the notice requirements of parag raph 1 of this
409395 subsection.
410396 3. A breach of a security system maintained by a credit bureau
411397 where fewer than one thousand (1,000) residents of this state are
412398 affected within a single breach shall be exempt from the notice
413399 requirements of paragraph 1 of this subsection.
414400 F. Any personal information submitted to the Attorney General
415401 shall be kept confidential pursuant to Section 24A.12 of Title 51 of
416402 the Oklahoma Statutes.
417403 G. The Attorney General may promulgate rules as necessary to
418404 effectuate the provisions of this section.
419405 SECTION 3. AMENDATORY 24 O.S. 2021, Section 164, is
420406 amended to read as follows:
421407 Section 164. A. An individual or entity that maintains its own
422408 notification procedures as part of an information privacy or
423409 security policy for the treatment of personal information and that
424410 are consistent with the timing requirements of this act the Security
425411 Breach Notification Act shall be deemed to be in compliance with the
426412 notification requirements of this act subsection A, B, or C of
413+Section 163 of this title if it the individual or entity notifies
414+residents of this state in accordance with its procedures in the
415+event of a breach of security of the system.
427416
428-SB626 HFLR Page 9
429-BOLD FACE denotes Committee Amendments. 1
417+ENGR. S. B. NO. 626 Page 9 1
430418 2
431419 3
432420 4
433421 5
434422 6
435423 7
436424 8
437425 9
438426 10
439427 11
440428 12
441429 13
442430 14
443431 15
444432 16
445433 17
446434 18
447435 19
448436 20
449437 21
450438 22
451439 23
452440 24
453441
454-Section 163 of this title if it the individual or entity notifies
455-residents of this state in accordance with its procedures in the
456-event of a breach of security of the system.
457442 B. The following entities shall be deemed to be in compliance
458443 with the notification requirements of subsection A, B, or C of
459444 Section 163 of this title if such entities provide notice to the
460445 Attorney General as required by subsection E of Section 163 of this
461446 title:
462447 1. A financial institution that complies with the notification
463448 requirements prescribed by the Federal Gramm-Leach-Bliley Act and
464449 the federal Interagency Guidance on Response Programs for
465450 Unauthorized Access to Customer Information and Customer Notice is
466451 deemed to be in compliance with the provisions of this act. ;
467452 2. An entity that complies with the notification requirements
468453 prescribed by the Oklahoma Hospital Cybersecurity Protection Act of
469454 2023 or the Health Insurance Portability and Accountability Act of
470455 1996 (HIPAA); and
471456 3. An entity that complies with the notifica tion requirements
472457 or procedures pursuant to the rules, regulation regulations,
473458 procedures, or guidelines established by the primary or functional
474459 federal regulator of the entity shall be deemed to be in compliance
475460 with the provisions of this act .
476461 SECTION 4. AMENDATORY 24 O.S. 2021, Section 165, is
477462 amended to read as follows:
463+Section 165. A. A violation of this act the Security Breach
464+Notification Act that results in injury or loss to residents of this
465+state may be enforced by the Attorney General or a district attorney
478466
479-SB626 HFLR Page 10
480-BOLD FACE denotes Committee Amendments. 1
467+ENGR. S. B. NO. 626 Page 10 1
481468 2
482469 3
483470 4
484471 5
485472 6
486473 7
487474 8
488475 9
489476 10
490477 11
491478 12
492479 13
493480 14
494481 15
495482 16
496483 17
497484 18
498485 19
499486 20
500487 21
501488 22
502489 23
503490 24
504491
505-Section 165. A. A violation of this act the Security Breach
506-Notification Act that results in injury or loss to residents of this
507-state may be enforced by the Attorney General or a district attorney
508492 in the same manner as an unlawful practice under the Oklahoma
509493 Consumer Protection Act.
510494 B. Except as provided in subsection C D of this section, the
511495 Attorney General or a district attorney shall have exclusive
512496 authority to bring an action and may obtain either actual damages
513497 for a violation of this act or the Security Breach Notification Act
514498 and a civil penalty not to exceed One Hundred Fifty Thousand Dollars
515499 ($150,000.00) per breach of the security of the system or series of
516500 breaches of a similar nature that are discovered determined in a
517501 single investigation . Civil penalties shall be based upon the
518502 magnitude of the breach, the extent to which the behavior of the
519503 individual or entity contributed to the breach, and a ny failure to
520504 provide the notice required by Section 163 of this title .
521505 C. 1. An individual or entity that uses reasonable safeguards
522506 and provides notice as required by Section 163 or 164 of this title
523507 shall not be subject to civil penalties and may use such compliance
524508 as an affirmative defense in a civil action filed under the Security
525509 Breach Notification Act.
526510 2. An individual or entity that fails to use reasonable
527511 safeguards but provides notice as required by Section 163 or 164 of
528512 this title shall not be subject to the civil penalty set forth in
513+subsection B of this section but shall be subject to actual damages
514+and a civil penalty of Seventy-five Thousand Dollars ($75,000.00) .
529515
530-SB626 HFLR Page 11
531-BOLD FACE denotes Committee Amendments. 1
516+ENGR. S. B. NO. 626 Page 11 1
532517 2
533518 3
534519 4
535520 5
536521 6
537522 7
538523 8
539524 9
540525 10
541526 11
542527 12
543528 13
544529 14
545530 15
546531 16
547532 17
548533 18
549534 19
550535 20
551536 21
552537 22
553538 23
554539 24
555540
556-subsection B of this section but shall be subject to actual damages
557-and a civil penalty of Seventy-five Thousand Dollars ($75,000.00) .
558541 C. D. A violation of this act the Security Breach Notification
559542 Act by a state-chartered or state-licensed financial institution
560543 shall be enforceable exclusively by the primary state regulator of
561544 the financial institution.
562545 SECTION 5. AMENDATORY 24 O.S. 2021, Section 166, is
563546 amended to read as follows:
564547 Section 166. This act The Security Breach Notification Act
565548 shall apply to the discovery determination or notification of a
566549 breach of the security of the system that occurs on or after
567550 November 1, 2008 January 1, 2026.
568551 SECTION 6. This act shall become effective January 1, 2026.
552+Passed the Senate the 27th day of March, 2025.
569553
570-COMMITTEE REPORT BY: COMMITTEE ON APPROPRIATIONS AND BUDGET , dated
571-04/17/2025 – DO PASS.
554+
555+
556+ Presiding Officer of the Senate
557+
558+
559+Passed the House of Representatives the ____ day of __________,
560+2025.
561+
562+
563+
564+ Presiding Officer of the House
565+ of Representatives
566+