Cybersecurity Policy Report, The Week in State Privacy and Cybersecurity Legislation—March 10-14, 2025, (Mar 18, 2025)
Organizations Mentioned:NetChoice, LLC
By WK Editorial Staff
Welcome to The Week in State Privacy and Cybersecurity Legislation, your weekly update on the latest developments in proposed and amended privacy and data security legislation across the 50 states and the District of Columbia, as well as a summary of what's on the schedule for the coming week. For comprehensive status and summaries of all state privacy and cybersecurity bills in play this year, please consult the State Privacy and Cybersecurity Legislation Tracker, located in the Spotlight Topics panel on the Wolters Kluwer Cybersecurity & Privacy dashboard.
Last week, legislators reviewed a comprehensive privacy proposal in Pennsylvania, the Arkansas state House approved a youth privacy protection bill, and California’s privacy regulator announced its first official enforcement decision, among other developments.
RECENT DEVELOPMENTS
House committee to consider privacy bill in Pennsylvania. The Pennsylvania state House Commerce Committee was scheduled to meet today to consider a bill that would establish a Consumer Data Privacy Act. The bill (H.B. 78, Reg Sess.), among other things, would allow consumers to opt out of the processing of their personal data for the purpose of targeted advertising or the sale of their personal data, in addition to giving consumers the right to correct their personal data and request that their data be deleted. The legislation also would impose several duties and responsibilities on data controllers, and provides for exclusive enforcement in the state attorney general (CPR, March 15).
Children’s privacy bill advanced by Arkansas House. On March 13, the Arkansas state House approved H.B. 1717, Reg Sess., a bill that would create the Arkansas Children and Teens’ Online Protection Act. Specifically, the bill seeks to extend online privacy protections to children and teens, prohibiting tech companies from collecting information from minors for targeted advertising and mandating clear disclosure about what information is collected, along with the ability for parents and teens to access, correct, or delete personal information upon request. The bill also would require operators of certain sites to implement “reasonable security measures” to protect the data of children and teens (CPR, March 14).
CPPA fines Honda for CCPA violations in first-of-its-kind order. The California Privacy Protection Agency announced a settlement order in which American Honda Motor Corp. agreed to pay a $632,500 fine and change its business practices to settle allegations that it violated the California Consumer Privacy Act (CCPA). The CPPA found that Honda, among other things, required Californians who sought to exercise their privacy rights to provide excessive amounts of personal data (CPR, March 12). The case, which represented the agency’s first publicly announced fine for violations of the CCPA, resulted from the agency’s ongoing review of the data privacy practices of connected vehicle manufacturers and related technologies.
California court grants injunction to NetChoice in “Kids Code” law. The U.S. District Court for the Northen District of California granted a second motion by NetChoice LLC on March 13 for an injunction preventing the California Age-Appropriate Design Code Act from taking effect. In its ruling, the court determined that the state law, enacted in 2022 to provide certain protections to children when they use the Internet, violates the First Amendment (CPR, March 14).
New York AG files complaint against insurers alleging data security lapses. New York Attorney General Letitia James (D.) filed a lawsuit on March 10 against several insurance companies affiliated with National General and the Allstate Corp., alleging that the companies failed to protect the personal information of New Yorkers, resulting in cyber attacks in 2020 and 2021. The complaint maintains that the two breaches resulted from National General’s failure to implement reasonable security measures, both before and after Allstate assumed control of its data security operations. The suit seeks penalties for National General’s security and notification failures, as well as an injunction to stop any continuing violations (CPR, March 10).
Oregon AG releases report on implementation of OCPA. Oregon Attorney General Dan Rayfield (D.) released a report on March 7 that detailed the results of the implementation of the Oregon Consumer Privacy Act (OCPA), which took effect on July 1, 2024. Oregon consumers filed 110 privacy complaints with the state Department of Justice in the six months since the enactment of the law, which the report said was significantly higher in Oregon than in other states with similar laws (CPR, March 10).
WHAT’S COMING UP
Indiana’s state House Commerce, Small Business, and Economic Development Committee will review S.B. 33, Reg Sess., a bill that would enact a genetic information privacy law similar to those enacted in several other states, on March 19. The bill was approved by the state Senate in February.
Also on March 19, the Texas state House Trade, Workforce & Economic Development Committee will meet to discuss H.B. 186, Reg Sess., which, if enacted, would prohibit social media use by individuals under 18, requiring age verification and allowing parents to request account deletions, with enforcement of any violation as a deceptive trade practice.
The Illinois state House Judiciary Committee will consider several items on March 20 seeking to amend provisions of the state’s Biometric Information Privacy Act (BIPA), including the following bills:
-- H.B. 2894, Reg Sess., which would add neural data to the definition of “biometric identifier” for purposes of BIPA;
-- H.B. 3292, Reg Sess., which would exempt vehicle safety technology from BIPA, allowing temporary use of biometric data for safety purposes without retaining it longer than necessary or using it to identify individuals; and
-- H.B. 2838, Reg Sess., which would amend BIPA to refine definitions, introduce exemptions for security-related biometric data use, establish a right of action for violations, and require private entities to develop data retention policies.
WHAT WE’RE TRACKING
Last Week:
Introduced Bills: 38
Enacted Bills: 2
Failed Bills: 0
2025 Total (including carryforward)
Introduced Bills: 475
Enacted Bills: 6
Failed Bills: 20
MainStory: CCPA DataBreach DataPrivacy DataSecurity StateLegislation LitigationEnforcement