HB 2793 — Cybersecurity; care and disposal of customer records, security for connected devices.
Last action — Left in Commerce and Labor
-
✓Introduced
-
2In Committee
-
3Passed House of Delegates
-
4Passed Senate
-
5To Executive
-
6Enacted
This bill died with 2019 Regular Session. It reached “In Committee” and never advanced before the session ended, so it can no longer move — a new version would have to be reintroduced in the current session.
This bill is no longer active — its legislative session has ended, so there are no live odds of enactment. It would have to be reintroduced in the current session to move again.
Summary
Requires any business to take all reasonable steps to dispose of, or arrange for the disposal of, customer records within its custody or control containing personal information when the records are no longer to be retained by the business by shredding, erasing, or otherwise modifying the personal information in those records to make it unreadable or undecipherable. The measure requires any business that owns or licenses personal information about a customer to implement and maintain reasonable security procedures and practices appropriate to the nature of the information in order to protect the personal information from unauthorized access, destruction, use, modification, or disclosure. The measure also requires a manufacturer of a device or other physical object that is capable of connecting directly or indirectly to the Internet to (i) equip the device with reasonable security features, (ii) demonstrate conformity with industry standards for cybersecurity and resiliency, (iii) provide an opt-in forum or registration capability to allow consumers to know when a vulnerability or breach is discovered, (iv) make patch notification and end-of-life support events easily obtainable by registered users of the manufacturer's connected devices, and (v) when it is aware of existing vulnerabilities that put more than 500 users at risk, notify the office of the Chief Information Officer of the Commonwealth and provide remediation steps to consumers without unreasonable delay. The bill has a delayed effective date of January 1, 2020.
Bill Text
- House: Presented and ordered printed 19104706D View text Current html January 18, 2019
Action History
-
Left in Commerce and Labor
-
Assigned C & L sub: Subcommittee #1
-
Referred to Committee on Commerce and Labor
-
Presented and ordered printed 19104706D
Sponsors
- Hala S. Ayala · Primary
Sponsorship breakdown
Export CSV (upgrade) →1 sponsors · 0 co-sponsors · 147 not signed on · 1 voted No
Sponsors (1)
Co-sponsors (0)
None.
Not signed on (147)
147 members have not signed on to this bill.
Show all 147 →"Not signed on" means a member has not sponsored or co-sponsored this bill — it does not imply opposition. Members flagged Voted No have a recorded No vote on this bill.
Votes
| Party | Yea | Nay | Present | Not Voting |
|---|---|---|---|---|
| Unaffiliated | 5 | 2 | 0 | 0 |
| Total | 5 | 2 | 0 | 0 |
| % of votes cast | 71% | 29% | 0% | 0% |
How each member voted (7)
| Member | Party | Vote |
|---|---|---|
| Byron | — | Yea |
| Mullin | — | Nay |
| Ransone | — | Yea |
| Israel D. O'Quinn | — | Yea |
| Lamont Bagby | — | Nay |
| Michael J. Webert | — | Yea |
| Terry G. Kilgore | — | Yea |
Subjects
Frequently asked questions
- What does HB 2793 do?
- Requires any business to take all reasonable steps to dispose of, or arrange for the disposal of, customer records within its custody or control containing personal information when the records are no longer to be retained by the business by shredding, erasing, or otherwise modifying the personal information in those records to make it unreadable or undecipherable. The measure requires any business that owns or licenses personal information about a customer to implement and maintain reasonable security procedures and practices appropriate to the nature of the information in order to protect the personal information from unauthorized access, destruction, use, modification, or disclosure. The measure also requires a manufacturer of a device or other physical object that is capable of connecting directly or indirectly to the Internet to (i) equip the device with reasonable security features, (ii) demonstrate conformity with industry standards for cybersecurity and resiliency, (iii) provide an opt-in forum or registration capability to allow consumers to know when a vulnerability or breach is discovered, (iv) make patch notification and end-of-life support events easily obtainable by registered users of the manufacturer's connected devices, and (v) when it is aware of existing vulnerabilities that put more than 500 users at risk, notify the office of the Chief Information Officer of the Commonwealth and provide remediation steps to consumers without unreasonable delay. The bill has a delayed effective date of January 1, 2020.
- Who sponsors HB 2793?
- HB 2793 is sponsored by Ayala, Hala S..
- What is the current status of HB 2793?
- This bill died with 2019 Regular Session. It reached “In Committee” and never advanced before the session ended, so it can no longer move — a new version would have to be reintroduced in the current session.
- Where can I track HB 2793?
- Track HB 2793 free on One Click Politics — get push/email alerts when it moves.
Make your voice heard on HB 2793
Find the representatives who decide this bill and tell them where you stand — for yourself, or mobilize your whole list in one click with One Click Politics advocacy software.
Stay ahead of HB 2793
Last checked for changes 3 months ago · updated continuously
One Click Politics tracks every bill in Congress and all 50 states.
Track this bill →