S2638 updates Rhode Island’s Identity Theft Protection Act of 2015 to modernize the state’s data security and breach-notification rules. The bill requires municipal agencies, state agencies, and other persons or entities that store or handle Rhode Island residents’ personally identifiable information to maintain a risk-based information security program based on current, approved cybersecurity frameworks, with reasonable safeguards for data in transit and at rest. It also requires limits on retention, secure destruction of personal data, and written contractual protections when information is shared with third-party vendors.
The bill revises and expands key definitions used in the chapter, including “personally identifiable information,” “classified data,” “cybersecurity incident,” and related terms such as medical, health insurance, and financial information. It also updates breach-notification rules, including shorter notice deadlines for state and municipal agencies and a 45-day deadline for private persons, plus required notice content, coordination with law enforcement, and notification to the attorney general, credit reporting agencies, ETSS, and, in some cases, labor unions. For state and municipal agencies, the bill adds a separate requirement to notify Rhode Island State Police within 24 hours of detecting a cybersecurity incident.
The bill’s impact on state law is to broaden and clarify the obligations of public agencies and private entities that handle sensitive resident data, while aligning Rhode Island’s framework more closely with current cybersecurity and incident-response practices. It also increases civil penalties for reckless and knowing/willful violations and preserves compliance safe harbors for certain financial institutions and HIPAA-covered health entities that already follow federal breach-response rules. The act would take effect July 1, 2026.
Overall, the sentiment reflected in the available record is cautious but supportive of strengthening cybersecurity protections. The bill was introduced with bipartisan sponsorship and referred to the Senate Artificial Intelligence & Emerging Tech Committee, where it received a 5-0 vote to be held for further study, suggesting interest in the proposal but a desire for additional review before advancement.
The main points of contention are likely to involve the scope of the new definitions, the shortened notification timelines, the added reporting obligations to state police and ETSS, and the increased penalties for violations. Public agencies, municipalities, private businesses, and vendors that handle resident data may be concerned about compliance costs, operational burdens, and the practical ability to meet the new deadlines, while supporters are likely to emphasize stronger consumer protection, faster incident response, and clearer statewide cybersecurity standards.
The bill amends Chapter 11-49.3 of the Rhode Island General Laws by replacing and expanding definitions, imposing updated information-security and retention requirements, tightening breach-notification procedures, adding a 24-hour cybersecurity incident notice requirement for state and municipal agencies, and increasing civil penalties for violations. It affects state agencies, municipal agencies, private businesses, vendors, financial institutions, and health-care entities that handle Rhode Island residents’ personally identifiable information, while preserving compliance exceptions for certain federally regulated institutions and HIPAA-covered entities.
The available voting history suggests generally favorable but measured support for the bill’s cybersecurity goals. The Senate Committee on Artificial Intelligence & Emerging Tech voted 5-0 to hold the bill for further study, indicating no recorded opposition at that stage but also signaling that members wanted more time to evaluate the scope, implementation, and consequences of the proposal before moving it forward.
Likely areas of contention include whether the bill’s expanded definitions and security-program requirements are too broad, whether the 30-day and 45-day breach-notification deadlines are workable in real-world investigations, and whether the 24-hour reporting requirement to state police is too burdensome for public agencies. The higher per-record penalties may also draw concern from municipalities, businesses, and regulated entities, while consumer advocates and cybersecurity proponents are likely to support the stronger protections, faster notice, and clearer incident-response obligations.