| |||||||
|
|
AN ACT Amending sections 16-621, 26-157, 41-713 and 41-764, Arizona Revised Statutes; repealing sections 41-1306, 41-1307 and 41-3010.11, Arizona Revised Statutes; amending sections 41-1554, 41-1554.01, 41‑1554.02, 41-1554.03, 41‑1554.04 and 41-1554.06, Arizona Revised Statutes; amending title 41, chapter 32, article 1, Arizona Revised Statutes, by adding section 41-3507; amending section 41-3521, Arizona Revised Statutes; amending Laws 2006, chapter 350, section 20; making appropriations; relating to budget procedures for budget reconciliation. Sec. 23. Storage encryption of stored data; request for proposals; definitions; exemption A. On or before September 30, 2007, the government information technology agency shall issue a request for proposals to contract for solutions to encrypt stored data of personal information for all state agencies that maintain more than ten thousand records that contain personal information. Any state agency may elect to adopt and implement the encryption solutions that result from the request for proposals by notifying the government information technology agency. B. The proposed encryption solutions shall meet any standards prescribed by the government information technology agency. C. The government information technology agency shall require that all responsive proposals be submitted on or before November 30, 2007. D. The government information technology agency shall supervise the implementation of any contract that results from the request for proposals. E. For the purposes of this section: 1. "Encryption" means a security method in which readable data is scrambled using mathematical algorithms where only individuals who possess the correct secret keys are able to read the data. 2. "Personal information": (a) Means an individual's first name or first initial and last name in combination with any one or more of the following data elements, when either the name or the data elements are not encrypted: (i) Social security number. (ii) Driver license number or identification card number. (iii) Account number or credit or debit card number in combination with any required security code, access code or password that would permit access to an individual's financial account. (b) Does not include publicly available information that is lawfully made available to the general public from federal, state or local government records. Sec. 24. Retroactivity Section 41-764, Arizona Revised Statutes, as amended by this act, applies retroactively to from and after June 30, 2007. |
|