Rhode Island 2026 Regular Session

Rhode Island Senate Bill S2638

Introduced
2/27/26  

Caption

RELATING TO CRIMINAL OFFENSES -- IDENTITY THEFT PROTECTION ACT OF 2015

Summary

S2638 updates Rhode Island’s Identity Theft Protection Act of 2015 to modernize the state’s data security and breach-notification rules. The bill requires municipal agencies, state agencies, and other persons or entities that store or handle Rhode Island residents’ personally identifiable information to maintain a risk-based information security program based on current, approved cybersecurity frameworks, with reasonable safeguards for data in transit and at rest. It also requires limits on retention, secure destruction of personal data, and written contractual protections when information is shared with third-party vendors. The bill revises and expands key definitions used in the chapter, including “personally identifiable information,” “classified data,” “cybersecurity incident,” and related terms such as medical, health insurance, and financial information. It also updates breach-notification rules, including shorter notice deadlines for state and municipal agencies and a 45-day deadline for private persons, plus required notice content, coordination with law enforcement, and notification to the attorney general, credit reporting agencies, ETSS, and, in some cases, labor unions. For state and municipal agencies, the bill adds a separate requirement to notify Rhode Island State Police within 24 hours of detecting a cybersecurity incident. The bill’s impact on state law is to broaden and clarify the obligations of public agencies and private entities that handle sensitive resident data, while aligning Rhode Island’s framework more closely with current cybersecurity and incident-response practices. It also increases civil penalties for reckless and knowing/willful violations and preserves compliance safe harbors for certain financial institutions and HIPAA-covered health entities that already follow federal breach-response rules. The act would take effect July 1, 2026. Overall, the sentiment reflected in the available record is cautious but supportive of strengthening cybersecurity protections. The bill was introduced with bipartisan sponsorship and referred to the Senate Artificial Intelligence & Emerging Tech Committee, where it received a 5-0 vote to be held for further study, suggesting interest in the proposal but a desire for additional review before advancement. The main points of contention are likely to involve the scope of the new definitions, the shortened notification timelines, the added reporting obligations to state police and ETSS, and the increased penalties for violations. Public agencies, municipalities, private businesses, and vendors that handle resident data may be concerned about compliance costs, operational burdens, and the practical ability to meet the new deadlines, while supporters are likely to emphasize stronger consumer protection, faster incident response, and clearer statewide cybersecurity standards.

Impact

The bill amends Chapter 11-49.3 of the Rhode Island General Laws by replacing and expanding definitions, imposing updated information-security and retention requirements, tightening breach-notification procedures, adding a 24-hour cybersecurity incident notice requirement for state and municipal agencies, and increasing civil penalties for violations. It affects state agencies, municipal agencies, private businesses, vendors, financial institutions, and health-care entities that handle Rhode Island residents’ personally identifiable information, while preserving compliance exceptions for certain federally regulated institutions and HIPAA-covered entities.

Sentiment

The available voting history suggests generally favorable but measured support for the bill’s cybersecurity goals. The Senate Committee on Artificial Intelligence & Emerging Tech voted 5-0 to hold the bill for further study, indicating no recorded opposition at that stage but also signaling that members wanted more time to evaluate the scope, implementation, and consequences of the proposal before moving it forward.

Contention

Likely areas of contention include whether the bill’s expanded definitions and security-program requirements are too broad, whether the 30-day and 45-day breach-notification deadlines are workable in real-world investigations, and whether the 24-hour reporting requirement to state police is too burdensome for public agencies. The higher per-record penalties may also draw concern from municipalities, businesses, and regulated entities, while consumer advocates and cybersecurity proponents are likely to support the stronger protections, faster notice, and clearer incident-response obligations.

Companion Bills

No companion bills found.

Previously Filed As

RI S1037

Amends the Identity Theft Protection Act by eliminating current definitions and establishing new definitions. This act also raises the penalty provisions for violations.

RI H6346

Amends the Identity Theft Protection Act by eliminating current definitions and establishing new definitions. This act also raises the penalty provisions for violations.

RI H5301

Expands responsibilities of agencies, persons or entities that store, own, collect, process, maintain, acquire, use, or licenses data, who experiences a security breach, include providing additional information to persons affected and law enforcement

RI S0545

Provides for tiered and reduced penalties for offenses of larceny, and shoplifting. Further provides that offenses of shoplifting or larceny would not be misdemeanors, repeals habitual offender provisions and other fraudulent offenses.

RI S0377

Establishes the “2025 Rhode Island Broadband Transparency and Consumer Protection Act."

RI H5817

Establishes the “2025 Rhode Island Broadband Transparency and Consumer Protection Act."

RI H6076

Establishes the fantasy sports consumer protection act.

RI S0304

Categorizes women by their biological identity at birth rather than their gender identity for purpose of organized sports.

RI H5842

Categorizes women by their biological identity at birth rather than their gender identity for purpose of organized sports.

RI S0307

Amends the comprehensive community-police relationship act of 2015 to require an annual study by an outside agency chosen by the department.

Similar Bills

ME LD2085

An Act to Include a Certain Emergency Communications Position at the Department of Public Safety in the 1998 Special Plan

ME LD579

An Act to Include Certain Nurses Under the 1998 Special Plan for Retirement

ME LD794

An Act to Include Judicial Marshals in the 1998 Special Plan for Retirement

ME LD137

An Act to Expand the 1998 Special Retirement Plan to Include Employees Who Work for the Office of Chief Medical Examiner

ME LD2067

An Act to Include Community Mental Health Workers Under the 1998 Special Plan for Retirement

US SB1198

Northern Rockies Ecosystem Protection Act

NJ S2602

"New Jersey Disclosure and Accountability Transparency Act (NJ DaTA)"; establishes certain requirements for disclosure and processing of personally identifiable information; establishes Office of Data Protection and Responsible Use in Division of Consumer Affairs.

NJ A1360

"New Jersey Disclosure and Accountability Transparency Act (NJ DaTA)"; establishes certain requirements for disclosure and processing of personally identifiable information; establishes Office of Data Protection and Responsible Use in Division of Consumer Affairs.