Rhode Island 2025 Regular Session

Rhode Island House Bill H5301

Introduced
2/5/25  

Caption

Expands responsibilities of agencies, persons or entities that store, own, collect, process, maintain, acquire, use, or licenses data, who experiences a security breach, include providing additional information to persons affected and law enforcement

Summary

H5301 amends Rhode Island’s Identity Theft Protection Act of 2015 to strengthen breach-notification requirements for state agencies, municipal agencies, and private entities that store or handle personal information. The bill requires covered entities to notify affected Rhode Island residents after a breach of security or unauthorized acquisition of personal information, and it sets specific deadlines for notice: generally no later than 30 calendar days for state and municipal agencies and 45 calendar days for private persons or entities, subject to law-enforcement delay when notification would impede an investigation. The bill also expands what must be included in breach notices. In addition to describing the incident and the type of information compromised, notices must explain remediation services, provide contact information for credit reporting agencies, remediation providers, and the attorney general, and describe how consumers can obtain a police report or request a security freeze. For state and municipal agencies, the bill requires longer-term remediation services, including at least five years of coverage for adults and coverage for minors until age 18 plus two additional years. It also requires cooperation with law enforcement and, in larger breaches affecting more than 500 Rhode Island residents, notice to the attorney general, the Department of Business Regulation, and major credit reporting agencies. The bill’s impact is to broaden and clarify the duties imposed on public agencies and other data holders following a data breach, while also increasing the amount of information and consumer assistance that must be provided to affected individuals. It reinforces existing liability for failure to notify and adds more detailed reporting obligations, especially for breaches involving large numbers of residents or public-sector data. The measure would take effect immediately upon passage. The overall sentiment reflected in the bill materials is protective of consumers and supportive of stronger identity-theft safeguards. The bill appears aimed at improving transparency, speeding notice, and ensuring that victims receive practical remediation resources after a breach. No committee transcript or recorded vote is available here, so there is no documented opposition or debate in the provided materials. The main points of contention suggested by the text are administrative burden and information-sharing limits. Covered entities may face tighter timelines, expanded notice content requirements, and added coordination duties with the attorney general, DBR, credit bureaus, and labor unions. At the same time, the bill preserves limits on disclosure of confidential business information and trade secrets, indicating an effort to balance breach transparency with privacy and business confidentiality concerns.

Impact

The bill amends Rhode Island General Laws chapter 11-49.3, the Identity Theft Protection Act of 2015, by revising section 11-49.3-4 on breach notification. It imposes shorter and more specific notification deadlines, expands required notice content to individuals and state oversight entities, and requires additional cooperation with law enforcement and, in some cases, labor unions. It also increases remediation expectations for state and municipal agencies, including extended credit-monitoring or similar services for adults and minors affected by a breach.

Sentiment

The available materials suggest a generally supportive, consumer-protection-oriented sentiment. The bill is framed as a response to data breaches and identity theft risks, with emphasis on faster notice, clearer disclosures, and more robust remediation for affected residents. Because there are no committee transcripts or votes included, there is no recorded public opposition or detailed debate in the provided record.

Contention

The likely areas of contention are the compliance costs and operational demands placed on agencies and data holders, especially the shortened notice windows, expanded reporting obligations, and required remediation services. Public agencies and private entities may view the bill as increasing administrative burden and potential liability. On the other hand, consumer advocates would likely support the stronger protections, while law enforcement and business interests may focus on the bill’s exceptions for delaying notice during investigations and its preservation of confidentiality for trade secrets and business information.

Companion Bills

No companion bills found.

Similar Bills

No similar bills found.