STAND. COM. REP. NO.  1065-22

 

Honolulu, Hawaii

                , 2022

 

RE:   S.B. No. 2292

      S.D. 1

      H.D. 1

 

 

 

 

Honorable Scott K. Saiki

Speaker, House of Representatives

Thirty-First State Legislature

Regular Session of 2022

State of Hawaii

 

Sir:

 

     Your Committee on Higher Education & Technology, to which was referred S.B. No. 2292, S.D. 1, entitled:

 

"A BILL FOR AN ACT RELATING TO PRIVACY,"

 

begs leave to report as follows:

 

     The purpose of this measure is to modernize the definition of "personal information" for the purposes of notifying affected persons of data and security breaches.

 

     Your Committee received testimony in support of this measure from the Office of Enterprise Technology Services; Hawaiian Electric Company, Inc.; Hawaii Pacific Health; and one individual.  Your Committee received testimony in opposition to this measure from Verizon, CTIA, RELX Group, and the Consumer Data Industry Association.  Your Committee received comments on this measure from the Office of Consumer Protection, Hawaii Insurers Council, Hawaii Bankers Association, State Privacy & Security Coalition, Hawaii Financial Services Association, Hawaii Credit Union League, and Hawaii Association of Health Plans.

 

     Your Committee finds that House Concurrent Resolution No. 225, H.D. 1, S.D. 1, Regular Session of 2019, convened the Twenty-First Century Privacy Law Task Force, whose membership consisted of individuals in government and the private sector having an interest or expertise in privacy law in the digital era.  Your Committee further finds that following significant inquiry and discussion, the Twenty-First Century Privacy Law Task Force recommended that the outdated definition of "personal information" in chapter 487N, Hawaii Revised Statutes, which requires the public to be notified of data breaches, be updated and expanded.  This measure will help ensure that individuals are protected from data breaches that may place an individual at risk of identity theft or may compromise the individual's personal safety.

 

     Your Committee has amended this measure by:

 

     (1)  Clarifying the definition of "identifier" to include an individual's mobile phone number or an email address specific to the individual;

 

     (2)  Modifying the definition of "specified data element" to include an individual's Social Security Number, either in its entirety or the last four or more digits; and

 

     (3)  Making technical, nonsubstantive amendments for the purposes of clarity, consistency, and style.

 

     As affirmed by the record of votes of the members of your Committee on Higher Education & Technology that is attached to this report, your Committee is in accord with the intent and purpose of S.B. No. 2292, S.D. 1, as amended herein, and recommends that it pass Second Reading in the form attached hereto as S.B. No. 2292, S.D. 1, H.D. 1, and be referred to your Committee on Consumer Protection & Commerce.

 

 

Respectfully submitted on behalf of the members of the Committee on Higher Education & Technology,

 

 

 

 

____________________________

GREGG TAKAYAMA, Chair