SB 2088 North Dakota Senate · 69th Legislative Assembly (2025-26)

AN ACT to amend and reenact subsection 4 of section 26.1-02.2-01, sections 26.1-02.2-05 and 26.1-02.2-07, and subsection 1 of section 26.1-02.2-08 of the North Dakota Century Code, relating to data security requirements for insurance producers; and to repeal section 26.1-02.2-11 of the North Dakota Century Code, relating to implementation dates for certain data security requirements for insurance producers.

Summary
Relating to data security requirements for insurance producers; and to repeal section 26.1‑02.2‑11 of the North Dakota Century Code, relating to implementation dates for certain data security requirements for insurance producers.
Bill status signed all 5 stages cleared
Introduction
Jan 2025
Committee Review
Mar 2025
Senate Passage
Jan 2025
House Passage
Mar 2025
Signed into Law
Mar 2025
Introduced Jan 7, 2025 Signed Mar 26, 2025
Maddy AI version diff · 2 comparisons

What changed between versions

FIRST ENGROSSMENT Enrollment · 4 edits
MODERATE
The bill updates data security notification requirements for insurance producers in North Dakota, clarifying what constitutes a cybersecurity event and specifying exactly what information must be reported to the commissioner within three business days of a breach. The changes add specific details about third-party service provider notifications and expand the required content of breach reports to include more comprehensive information about the incident.
Scope change
The bill maintains its scope for insurance producers but clarifies applicability by adding specific provisions for third-party service provider cybersecurity events and updating the definition of cybersecurity events to exclude certain encrypted data acquisitions.
DEFINITION

Updated the definition of 'cybersecurity event' to clarify exclusions for encrypted data acquisitions where encryption keys were not compromised, and events where data was returned or destroyed without use.

REQUIREMENT

Added new subsections requiring licensees to specify when computation of deadlines begins for third-party service provider breaches, starting from the day after the licensee receives notification or gains actual knowledge.

Expanded the required content of cybersecurity event notifications to include more detailed information about the incident, third-party roles, and remediation efforts.

Added provisions clarifying that licensees must comply with third-party service provider notification requirements unless the provider has already notified the commissioner directly.

Floor votes · Senate Jan 31, 2025 · House Mar 18, 2025

How they voted

431
Passed · 3 other
Total votes 47
Jan 31, 2025
D Democratic5
4 Yea 1 Nay
80% Yea
R Republican42
39 Yea 3
92% Yea
Vote distribution
All Yea All Nay Mixed No data
Full legislative history

Actions timeline

Total actions
16
Key actions
8
Committee
4
Mar 27, 2025
Introduced
Filed with Secretary Of State 03/26
legislature
Mar 26, 2025
Signed into law
Signed by Governor 03/25
upper
Mar 18, 2025
Lower · Passed
Second reading, passed, yeas 93 nays 0
lower
Mar 17, 2025
Lower · Passed
Reported back, do pass, place on calendar 13 1 0
lower
Mar 17, 2025
Lower · Passed
Committee Hearing 11:00
lower
Feb 18, 2025
Introduced
Introduced, first reading, referred Industry, Business and Labor Committee
lower
Jan 31, 2025
Upper · Passed
Second reading, passed, yeas 43 nays 1
upper
Jan 30, 2025
Upper · Passed
Amendment adopted, placed on calendar
upper
Jan 29, 2025
Upper · Passed
Reported back amended, do pass, amendment placed on calendar 5 0 0
upper
Jan 22, 2025
Upper · Passed
Committee Hearing 09:00
upper
Jan 7, 2025
Introduced
Introduced, first reading, referred Industry and Business Committee
upper
0 primary · 0 co-sponsors

Sponsors

No sponsor information available.