No. SB 7024
Filed under Local Government.
OGSR/Cybersecurity, Information Technology, and Operational Technology Information; Providing an exemption from public records requirements for the cybersecurity, information technology, and operational technology information held by an agency; providing an exemption from public meetings requirements for any portion of a meeting that would reveal such information; providing for future legislative review and repeal of the exemptions; providing a statement of public necessity, etc.
Plain English Summary
AI-GENERATEDState agencies can now keep cybersecurity, IT, and operational technology records confidential. This prevents the public from seeing how agencies protect their systems. The exemption covers a wide range of technical data.
Agencies can close parts of public meetings if discussing these topics. Recordings and transcripts of those closed sessions are also kept confidential. This limits public oversight of agency cybersecurity practices.
The bill removes older, specific cybersecurity exemptions from various statutes. It consolidates these protections into one new, broader section. This simplifies the law but expands the scope of confidential information.
The new exemptions will automatically expire in 2031 unless the Legislature renews them. This sunset clause requires future legislative review of the confidentiality provisions. It ensures the exemptions are not permanent.
AIExpands the list of confidential records to include operational technology, login credentials, IP addresses, and insurance details.
AIRemoves redundant, agency-specific exemptions for the Department of State, DHSMV, and local utilities, consolidating them under the new general section.
AICreates a new statutory exemption from public records and meetings laws for specific cybersecurity, IT, and OT information held by state agencies.
AIAllows agencies to close portions of public meetings that would reveal exempt cybersecurity information and keeps the resulting recordings and transcripts confidential.
AIDelays the mandatory legislative review and potential repeal of the cybersecurity exemptions from 2026 to 2031.
AIRemoves the exemption for local utility network security and industrial control system information, retaining only the exemption for customer billing data.
AIRemoves previous statutory provisions that granted confidentiality to internal policies, audit results, and risk assessments, replacing them with the new, broader exemption.
AIRepeals two existing statutes, s. 627.352 and s. 1004.055, removing their legal requirements from the Florida Statutes.