SESSION WATCH
Superseded — its companion passed HOUSE · SESSION 2026

No. HB 7023

OGSR/Cybersecurity
Send via email
SPONSOR
Government Operations Subcommittee; Conerly
FILED BY
William Conerly — District 72, Republican [search donations]
EFFECTIVE
upon becoming a law
COMPANION
SB 7024 — HB 7023 was set aside and its companion carried the policy

Filed under Local Government.

PROVIDED SUMMARY

OGSR/Cybersecurity; Revises, creates, & removes public records exemptions relating to specified cybersecurity process, practices, information, & reports, certain login credentials & information, & other cypersecurity-related information & meetings; provides statement of public necessity.

Full bill text →

Plain English Summary

AI-GENERATED
Makes cybersecurity records confidential at every government agency, not just some.

One exemption now covers cybersecurity records at every state and local government agency, replacing several narrower, agency-specific secrecy laws. Login credentials, geolocation and access logs from public-facing web portals, and cybersecurity risk assessments become confidential everywhere, not just at the few agencies singled out.

Cybersecurity records used to be guaranteed to Florida's Auditor General, the Chief Inspector General, and the FDLE Cybercrime Office by name. That automatic right is repealed; the records may now be shared with another agency only at the holding agency's discretion.

The exemption also gets easier to claim: withholding a record now only requires that release could help an attacker, not that it would. That is a lower bar than the current law sets for treating cybersecurity information as secret.

A separate protection for a utility customer's detailed meter-usage data survives but, for the first time, gets a hard expiration date and must be reviewed by 2027. Two unrelated statutes are repealed outright with no replacement text shown.

KEY PROVISIONS
§ 1 Extends the login-credentials exemption to every government agency majors. 119.0725

AIDefines 'login credentials' for the first time in this section and makes them confidential for any agency, replacing four separate exemptions that previously covered only the Department of State's e-filing system, campaign-finance e-filing, the Ethics Commission's disclosure system, and the highway safety department's records.

“information used to authenticate a user's identity or otherwise authorize access when logging into a computer, computer system, computer network, electronic device” bill text, line 93 →
§ 2 Extends portal-tracking-data secrecy to every government agency majors. 119.0725

AIMakes IP addresses, geolocation data, and the timestamps of a person's visits to any agency's public-facing web portal confidential everywhere; this protection previously existed only for the highway safety department's own portal, under a section this bill repeals.

“geolocation data, and other information that describes the location, computer, computer system, or computer network from which a user accesses a public-facing portal” bill text, line 139 →
§ 3 Widens the cybersecurity risk-assessment exemption beyond state agencies majors. 119.0725

AIMoves the confidentiality protection for risk assessments, audits, and evaluations of a cybersecurity program out of the state-agency-only cybersecurity statute and into the general public-records exemption, extending it to county, municipal, and other local agencies for the first time.

“Portions of risk assessments, evaluations, audits, and other reports of an agency's cybersecurity program” bill text, line 132 →
§ 4 Repeals state cybersecurity overseers' guaranteed access to these records majors. 282.318

AIDeletes the requirement that risk-assessment, audit, and internal-policy records be automatically available to the Auditor General, the Cybercrime Office of FDLE, the Florida Digital Service, and the Chief Inspector General; no replacement guarantee for these offices appears anywhere in the new language.

“shall be available to the Auditor General, the Cybercrime Office of the Department of Law Enforcement, the Florida Digital Service within the department” bill text, line 413 →
§ 5 Lowers the bar for treating cybersecurity information as exempt moderates. 119.0725

AIChanges the standard from disclosure that 'would facilitate' unauthorized access to disclosure that merely 'could facilitate' it, letting agencies withhold records based on a possibility of harm rather than a demonstrated likelihood of one.

“the disclosure of such information could facilitate unauthorized access to or unauthorized modification, disclosure, or destruction” bill text, line 128 →
§ 6 Adds a sunset-review date to the utility customer meter-data exemption moderates. 119.0713

AIStrips the two cybersecurity-specific paragraphs out of the local-government-utility exemption, leaving only the customer meter-data and billing protection; that protection is now subject to the Open Government Sunset Review Act for the first time and expires October 2, 2027 absent reenactment.

“This subsection is subject to the Open Government Sunset Review Act”
TIMELINE
3/9/2026
Laid on Table; Companion bill(s) passed, see SB 7024 (Ch. 2026-120 )
2/3/2026
Added to Second Reading Calendar
2/3/2026
Bill released to House Calendar
2/3/2026
Reported out of State Affairs Committee
2/3/2026
Favorable by State Affairs Committee
1/30/2026
Added to State Affairs Committee agenda
1/28/2026
Now in State Affairs Committee
1/28/2026
Reported out of Information Technology Budget & Policy Subcommittee
1/28/2026
Favorable by Information Technology Budget & Policy Subcommittee
1/26/2026
Added to Information Technology Budget & Policy Subcommittee agenda
1/19/2026
Now in Information Technology Budget & Policy Subcommittee
1/19/2026
Referred to State Affairs Committee
1/19/2026
Referred to Information Technology Budget & Policy Subcommittee
1/15/2026
1st Reading (Original Filed Version)
1/15/2026
Filed
9 EARLIER →
STATUTES IT CHANGES
s. 119.0725
+326 / −92
s. 15.16
+1 / −129
s. 24.1051
+3 / −66
s. 101.5607
+2 / −2
s. 106.0706
+1 / −33
s. 112.31446
+0 / −35
STAFF ANALYSES