Aeronautics: unmanned aircraft systems; cybersecurity and data protection requirements for drones; provide for. Amends 2016 PA 436 (MCL 259.301 - 259.331) by adding sec. 16.
Impact
The legislation emphasizes the necessity of implementing various cybersecurity measures such as end-to-end encryption, multifactor authentication, and secure network operations protocols. Failure to comply with these provisions would result in disqualification from operating unmanned aircraft systems by public entities. Furthermore, regular security audits and certifications aligned with recognized cybersecurity standards will be mandatory to ensure ongoing compliance. This legislative change aims to mitigate the risks associated with drone operations, particularly concerning data privacy and cybersecurity vulnerabilities.
Summary
House Bill 5330 amends the Unmanned Aircraft Systems Act to introduce stringent cybersecurity and data protection requirements for small unmanned aircraft systems (drones) utilized by public entities and those contracting with them. The bill stipulates that a year after its passage, no entity may procure or operate such systems that do not adhere to specific guidelines regarding data collection, storage, and transmission. This means that entities must comply with federal and state privacy laws, and ensure data is kept within U.S. borders.
Contention
Discussions surrounding HB 5330 have centered on the balance between advancing technology and safeguarding public privacy and security. Advocates highlight the importance of protecting citizens' personal information from potential breaches, aligning with broader trends of enhancing data security legislation. Conversely, some stakeholders express concern that the regulatory burden could hinder the efficient adoption of drone technology in public services, potentially impacting operational capabilities due to stringent compliance costs and requirements.