AN ACT Relating to performance measures, duties, and reporting requirements for the office of privacy and data protection;
Bill Description
Concerning performance measures, duties, and reporting requirements for the office of privacy and data protection.
What this bill does Powered by Legitron
This bill amends RCW 43.105.369 to create an office of privacy and data protection within "the agency" and requires the agency director to appoint a chief privacy officer who will serve as the director of that office. The change is an administrative and procedural one: it establishes a new office and position and adds duties and reporting requirements for state privacy oversight; it does not create a new criminal offense or change penalties.
The chief privacy officer and office are charged with annual privacy reviews and annual privacy training for state agencies and employees, articulating privacy principles and best practices, coordinating data protection with the agency, and participating with the agency in review of major state agency projects involving personally identifiable information, including projects using artificial intelligence. As a resource to local governments and the public, the office must develop and promote best practices for collecting and storing personally identifiable information, provide or establish training programs for local governments, and educate consumers about how personally identifiable information is used on mobile and digital networks and measures to protect it. The office must prepare performance reports to the legislature (the statute text requires a report by December 1, 2016, and every four years thereafter) and must establish and track specified performance measures such as improvements after trainings, coordination with experts, public contacts, training results, technical assistance requests, staff continuing education, and counts of privacy analyses and impact assessments.
Affected parties named in the text include the office of privacy and data protection, the director and chief privacy officer, state agencies and employees, local governments, consumers, and the legislature. Important terms such as "the agency" and "director" are referenced but not defined in the extracted text, and portions of prior statutory language appear marked for deletion or change; how the December 1, 2016 reporting date is intended to operate in the 2026 context and how the amendments interact with other cross-referenced provisions are not clear from the provided excerpts. The bill was read for the first time on January 21, 2026, passed the House on February 11, 2026, and passed the Senate on February 28, 2026.
Why it matters Powered by Legitron
If enacted, the state would create a centralized office and a chief privacy officer inside an unspecified agency to act as the main adviser and reviewer for handling personally identifiable information. State agencies would face new recurring responsibilities: annual privacy reviews and trainings, and regular involvement of the office in major projects that use personal data or artificial intelligence. That will likely mean agencies must spend staff time to comply, adapt project schedules to include privacy reviews, and potentially incur modest new costs to implement recommended controls and respond to technical assistance requests.
Local governments and the public would get training, best-practice guidance, and consumer education, which could reduce their privacy risks but will also require time to participate in trainings or seek help. The agency that houses the office would need to hire the chief privacy officer and support staff, creating new administrative costs and ongoing reporting duties to the legislature; however, the bill text does not say which agency is responsible for hosting the office or how it will be funded, and the reporting deadline shown (December 1, 2016, and every four years thereafter) appears inconsistent with the bill’s 2026 dates, leaving timing and implementation details unclear.