Rhode Island 2025 Regular Session

Rhode Island Senate Bill S1037

Introduced
5/9/25  

Caption

Amends the Identity Theft Protection Act by eliminating current definitions and establishing new definitions. This act also raises the penalty provisions for violations.

Impact

The changes proposed in S1037 will significantly strengthen the obligations of state agencies and other entities that collect and manage personal data. By mandating risk-based information security programs and more stringent reporting requirements for data breaches, the bill aims to protect residents from identity theft. Agencies will be required to implement industry-recognized cybersecurity frameworks and maintain up-to-date security practices to guard against unauthorized access and disclosure of sensitive personal information.

Summary

Bill S1037 seeks to amend the Identity Theft Protection Act of 2015 in Rhode Island, focusing on enhancing protections against identity theft through improved security measures. The bill introduces new definitions pertaining to 'personally identifiable information' and aims to close loopholes by eliminating outdated definitions. It raises the penalties for violations, reflecting a more rigorous enforcement approach towards data privacy and security, particularly for state and municipal agencies handling personal data.

Contention

While the bill aims to bolster identity theft protection, some stakeholders may express concerns about the practical implications of enhanced compliance requirements. The increase in penalties for violations may lead to apprehension among smaller organizations regarding their ability to meet the new standards. Additionally, the formulation of specific definitions and classifications of data could potentially spark debates on what constitutes adequate protection, especially concerning the balance between security needs and personal privacy rights.

Companion Bills

No companion bills found.

Previously Filed As

RI H5639

Establishes the crime of attempted kidnapping of a minor.

RI S0950

Establishes the crime of attempted kidnapping of a minor.

RI S0552

RELATED TO CRIMINAL OFFENSES -- DISARMING A PEACE OFFICER

RI H6042

Exempts certain U.S. employees from having to obtain state licenses to carry a visible or concealed pistol or revolver.

RI H5890

Specifies that it is unlawful for any person under the age of eighteen (18) to possess a firearm.

RI S0294

Makes it unnecessary to prove that a person’s transmission of electronic communications be for the sole purpose of harassment before being found guilty of cyberstalking or cyberharassment.

RI H5924

Increases minimum sentence for first degree sexual assault and provides first 10 years of a sentence for first degree sexual assault not be subject to a suspension or deferment of sentence.

RI S0558

Adds a rebuttable defense if any person shall die or sustain a personal injury while committing robbery of the owner, lessor, or occupant of a motor vehicle and that the owner or occupant of the vehicle acted in self-defense.

Similar Bills

RI H6346

Amends the Identity Theft Protection Act by eliminating current definitions and establishing new definitions. This act also raises the penalty provisions for violations.

CA AB2777

Office of Information Security: Baseline Information Security Score.

NJ S3100

Requires businesses in financial essential infrastructure, and health care industries to develop cybersecurity plans and report cybersecurity incidents.

NJ A1981

Requires businesses in financial, essential infrastructure, and health care industries to develop cybersecurity plans.

NJ A2200

Requires businesses in financial, essential infrastructure, and health care industries to develop cybersecurity plans.

AL HB68

State government, Office of Information Technology, cybersecurity requirements, provided

CA AB2135

Information security.

KS HB2019

Implementing additional reporting requirements for information technology projects and state agencies, requiring additional information technology security training and status reports, requiring reporting of significant cybersecurity audits and changing the membership requirements, terms of members and the quorum requirements for the information technology executive council.