No. HB 7023
Filed under Local Government.
OGSR/Cybersecurity; Revises, creates, & removes public records exemptions relating to specified cybersecurity process, practices, information, & reports, certain login credentials & information, & other cypersecurity-related information & meetings; provides statement of public necessity.
Plain English Summary
AI-GENERATEDOne exemption now covers cybersecurity records at every state and local government agency, replacing several narrower, agency-specific secrecy laws. Login credentials, geolocation and access logs from public-facing web portals, and cybersecurity risk assessments become confidential everywhere, not just at the few agencies singled out.
Cybersecurity records used to be guaranteed to Florida's Auditor General, the Chief Inspector General, and the FDLE Cybercrime Office by name. That automatic right is repealed; the records may now be shared with another agency only at the holding agency's discretion.
The exemption also gets easier to claim: withholding a record now only requires that release could help an attacker, not that it would. That is a lower bar than the current law sets for treating cybersecurity information as secret.
A separate protection for a utility customer's detailed meter-usage data survives but, for the first time, gets a hard expiration date and must be reviewed by 2027. Two unrelated statutes are repealed outright with no replacement text shown.
AIDefines 'login credentials' for the first time in this section and makes them confidential for any agency, replacing four separate exemptions that previously covered only the Department of State's e-filing system, campaign-finance e-filing, the Ethics Commission's disclosure system, and the highway safety department's records.
AIMakes IP addresses, geolocation data, and the timestamps of a person's visits to any agency's public-facing web portal confidential everywhere; this protection previously existed only for the highway safety department's own portal, under a section this bill repeals.
AIMoves the confidentiality protection for risk assessments, audits, and evaluations of a cybersecurity program out of the state-agency-only cybersecurity statute and into the general public-records exemption, extending it to county, municipal, and other local agencies for the first time.
AIDeletes the requirement that risk-assessment, audit, and internal-policy records be automatically available to the Auditor General, the Cybercrime Office of FDLE, the Florida Digital Service, and the Chief Inspector General; no replacement guarantee for these offices appears anywhere in the new language.
AIChanges the standard from disclosure that 'would facilitate' unauthorized access to disclosure that merely 'could facilitate' it, letting agencies withhold records based on a possibility of harm rather than a demonstrated likelihood of one.
AIStrips the two cybersecurity-specific paragraphs out of the local-government-utility exemption, leaving only the customer meter-data and billing protection; that protection is now subject to the Open Government Sunset Review Act for the first time and expires October 2, 2027 absent reenactment.