SB 7020 Florida Senate · 2025 Regular Session

OGSR/Agency Cybersecurity Information

Summary
OGSR/Agency Cybersecurity Information; Amending a provision which provides exemptions from public records requirements for agency cybersecurity information held by a state agency and exemptions from public meetings requirements for portions of meetings which would reveal confidential and exempt information; amending a provision which provides exemptions from public records and public meetings requirements for portions of risk assessments, evaluations, external audits, and other reports of a state agency’s cybersecurity program for the data, information, and information technology resources of that state agency which are held by a state agency and for portions of a public meeting which would reveal such confidential and exempt records; extending the date of the scheduled repeal of such exemptions, etc.
Bill status signed all 5 stages cleared
Introduction
Mar 2025
Committee Review
Apr 2025
Senate Passage
Apr 2025
House Passage
Apr 2025
Signed into Law
May 2025
Introduced Mar 19, 2025 Signed May 16, 2025
Maddy AI version diff · 2 comparisons

What changed between versions

S 7020 er S 7020 pb · 5 edits
MODERATE
This bill updates Florida's cybersecurity privacy laws by extending the sunset date for exemptions that protect sensitive cybersecurity information from public disclosure, clarifying definitions of key terms like 'breach' and 'critical infrastructure', and adding new protections for certain cybersecurity reports and meeting portions.
Scope change
The bill expands the scope of protected information to include more detailed cybersecurity incident reports and meeting transcripts, while also clarifying which entities can access confidential cybersecurity information.
TIMELINE

Extended the sunset date for public records exemptions from October 2, 2026 to October 2, 2027, giving agencies more time before these privacy protections expire.

DEFINITION

Added clear definitions for 'breach', 'critical infrastructure', 'cybersecurity', 'data', 'incident', 'information technology', and 'operational technology' to ensure consistent understanding of protected terms.

REQUIREMENT

Added new subsections requiring that exempt meeting portions must be recorded and transcribed, with transcripts remaining confidential unless a court determines the meeting exceeded its scope.

Added new provisions allowing agencies to report cybersecurity incidents in aggregate form rather than individually, protecting specific incident details from public disclosure.

ELIGIBILITY

Modified which entities can access confidential cybersecurity information, adding the Cybercrime Office of the Department of Law Enforcement and the Florida Digital Service within the Department of Management Services.

Floor votes · Senate Apr 3, 2025 · House Apr 29, 2025

How they voted

370
Passed · 1 other
Total votes 38
Apr 3, 2025
D Democratic10
10 Yea
100% Yea
I Independent1
1 Yea
100% Yea
R Republican27
26 Yea 1
96% Yea
Vote distribution
All Yea All Nay Mixed No data
Full legislative history

Actions timeline

Total actions
27
Key actions
7
Committee
6
May 16, 2025
Signed into law
Approved by Governor
legislature
Apr 29, 2025
Lower · Passed
Passed; YEAS 116, NAYS 0
lower
Apr 28, 2025
Committee
Bill referred to House Calendar
lower
Apr 3, 2025
Upper · Passed
Passed; YEAS 37 NAYS 0
upper
Mar 26, 2025
Upper · Passed
Favorable by- Rules; YEAS 21 NAYS 3
upper
Mar 21, 2025
Upper · Passed
On Committee agenda-- Rules, 03/26/25, 9:00 am, 412 Knott Building
upper
Mar 19, 2025
Introduced
Introduced
upper
Mar 19, 2025
Committee
Referred to Rules
upper
Mar 18, 2025
Upper · Passed
Submitted as Committee Bill and Reported Favorably by Governmental Oversight and Accountability; YEAS 8 NAYS 0
upper
Mar 13, 2025
Upper · Passed
On Committee agenda-- Governmental Oversight and Accountability, 03/18/25, 3:30 pm, 110 Senate Building
upper
0 primary · 1 co-sponsor

Sponsors

No sponsor information available.