<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" bill-type="olc" dms-id="H71B9DAD4AC634B8BA26C5FEAF5793B6C" public-private="public">
	<metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>113 HR 4400 IH: Data Accountability and Trust Act</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2014-04-04</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
		<distribution-code display="yes">I</distribution-code>
		<congress>113th CONGRESS</congress>
		<session>2d Session</session>
		<legis-num>H. R. 4400</legis-num>
		<current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber>
		<action>
			<action-date date="20140404">April 4, 2014</action-date>
			<action-desc><sponsor name-id="R000515">Mr. Rush</sponsor> (for himself, <cosponsor name-id="B000213">Mr. Barton</cosponsor>, <cosponsor name-id="C001084">Mr. Cicilline</cosponsor>, <cosponsor name-id="L000563">Mr. Lipinski</cosponsor>, <cosponsor name-id="M001166">Mr. McNerney</cosponsor>, and <cosponsor name-id="S001145">Ms. Schakowsky</cosponsor>) introduced the following bill; which was referred to the <committee-name committee-id="HIF00">Committee on Energy and Commerce</committee-name></action-desc>
		</action>
		<legis-type>A BILL</legis-type>
		<official-title>To protect consumers by requiring reasonable security policies and procedures to protect data
			 containing personal information, and to provide for nationwide notice in
			 the event of a security breach.</official-title>
	</form>
	<legis-body id="H0925065FDB744408A2137B8238D52236" style="OLC">
		<section id="H3EFFAB16096E42EC96AAFCD737C1D50D" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Data Accountability and Trust Act</short-title></quote>.</text>
		</section><section id="HE0CD988776D44708A1AA912CD4BFD2D8"><enum>2.</enum><header>Requirements for information security</header>
			<subsection id="H9A81736F924F4F71BE58AD19F517F126"><enum>(a)</enum><header>General security policies and procedures</header>
				<paragraph id="H0624827B719544FBBFDC67683F3B94D5"><enum>(1)</enum><header>Regulations</header><text>Not later than 1 year after the date of enactment of this Act, the Commission shall promulgate
			 regulations under <external-xref legal-doc="usc" parsable-cite="usc/5/553">section 553</external-xref> of title 5, United States Code, to require
			 each person engaged in interstate commerce that owns or possesses data
			 containing personal information, or contracts to have any third party
			 entity maintain such data for such person, to establish and implement
			 policies and procedures regarding information security practices for the
			 treatment and protection of personal information taking into
			 consideration—</text>
					<subparagraph id="H3AAECF3C210E419A9F112ABCBC9638BE"><enum>(A)</enum><text>the size of, and the nature, scope, and complexity of the activities engaged in by, such person;</text>
					</subparagraph><subparagraph id="HFD5A564B0ECE4BAEADF79D2D5E293A5C"><enum>(B)</enum><text>the current state of the art in administrative, technical, and physical safeguards for protecting
			 such information; and</text>
					</subparagraph><subparagraph id="HB6ADBCB50E354EE2ADDE56D6E7137393"><enum>(C)</enum><text>the cost of implementing such safeguards.</text>
					</subparagraph></paragraph><paragraph id="HB935BB8BBEFC4ECE841436D6FAAC5BB1"><enum>(2)</enum><header>Requirements</header><text>Such regulations shall require the policies and procedures to include the following:</text>
					<subparagraph commented="no" id="HA3AA1E3FE9994CAEAC85370E93A36971"><enum>(A)</enum><text display-inline="yes-display-inline">A security policy with respect to the collection, use, sale, other dissemination, and maintenance
			 of such personal information.</text>
					</subparagraph><subparagraph id="H10EAA73F6A29403DA1AB1E1AC4F05717"><enum>(B)</enum><text display-inline="yes-display-inline">The identification of an officer or other individual as the point of contact with responsibility
			 for the management of information security.</text>
					</subparagraph><subparagraph commented="no" id="H49DD7979B3E747B1BBC0550B36E58015"><enum>(C)</enum><text display-inline="yes-display-inline">A process for identifying and assessing any reasonably foreseeable vulnerabilities in the system or
			 systems maintained by such person that contains such data, which shall
			 include regular monitoring for a breach of security of such system or
			 systems.</text>
					</subparagraph><subparagraph commented="no" id="HF672F7728AE34366A1367676EF068E83"><enum>(D)</enum><text>A process for taking preventive and corrective action to mitigate against any vulnerabilities
			 identified in the process required by subparagraph (C), which may include
			 implementing any changes to security practices and the architecture,
			 installation, or implementation of network or operating software.</text>
					</subparagraph><subparagraph id="H560B61AA17BF44B2AF6B0824D6FB0BCC"><enum>(E)</enum><text>A process for disposing of data in electronic form containing personal information by shredding,
			 permanently erasing, or otherwise modifying the personal information
			 contained in such data to make such personal information permanently
			 unreadable or undecipherable.</text>
					</subparagraph><subparagraph commented="no" id="H7C0B4D0909194CE4A29220BACF02E98B"><enum>(F)</enum><text>A standard method or methods for the destruction of paper documents and other non-electronic data
			 containing personal information.</text>
					</subparagraph></paragraph><paragraph commented="no" id="H8A500EB679604A3B8F4266EC68E5F8EB"><enum>(3)</enum><header>Treatment of entities governed by other law</header><text display-inline="yes-display-inline">Any person who is in compliance with any other Federal law that requires such person to maintain
			 standards and safeguards for information security and protection of
			 personal information that, taken as a whole and as the Commission shall
			 determine in the rulemaking required under paragraph (1), provide
			 protections substantially similar to, or greater than, those required
			 under this subsection, shall be deemed to be in compliance with this
			 subsection.</text>
				</paragraph></subsection><subsection commented="no" id="H312950EB78D3454284CD5AE853B6FD25"><enum>(b)</enum><header>Special requirements for information brokers</header>
				<paragraph commented="no" id="H51E5A485D2E946378749F8B1CF734C35"><enum>(1)</enum><header>Submission of policies to the FTC</header><text display-inline="yes-display-inline">The regulations promulgated under subsection (a) shall require each information broker to submit
			 its security policies to the Commission in conjunction with a notification
			 of a breach of security under section 3 or upon request of the Commission.</text>
				</paragraph><paragraph id="H73E231A0465D491592268736E5513223"><enum>(2)</enum><header>Post-breach audit</header><text display-inline="yes-display-inline">For any information broker required to provide notification under section 3, the Commission may
			 conduct audits of the information security practices of such information
			 broker, or require the information broker to conduct independent audits of
			 such practices (by an independent auditor who has not audited such
			 information broker’s security practices during the preceding 5 years).</text>
				</paragraph><paragraph commented="no" display-inline="no-display-inline" id="H3837E12F55F24361A67B3D8C09111D58"><enum>(3)</enum><header>Accuracy of and individual access to personal information</header>
					<subparagraph commented="no" id="H3D5DDAB3EDA4414088AC21ACAE29B9C7"><enum>(A)</enum><header>Accuracy</header>
						<clause id="H81CF871675A2479895DEA01C4D6B4AA3"><enum>(i)</enum><header>In general</header><text>Each information broker shall establish reasonable procedures to assure the maximum possible
			 accuracy of the personal information it collects, assembles, or maintains,
			 and any other information it collects, assembles, or maintains that
			 specifically identifies an individual, other than information which merely
			 identifies an individual’s name or address.</text>
						</clause><clause id="HEEFE5BD697D6457DA149CAC4F6536F06"><enum>(ii)</enum><header>Limited exception for fraud databases</header><text display-inline="yes-display-inline">The requirement in clause (i) shall not prevent the collection or maintenance of information that
			 may be inaccurate with respect to a particular individual when that
			 information is being collected or maintained solely—</text>
							<subclause id="H7D1D21B8B90B472A87B865659BBF610E"><enum>(I)</enum><text>for the purpose of indicating whether there may be a discrepancy or irregularity in the personal
			 information that is associated with an individual; and</text>
							</subclause><subclause id="H0D8D9A3CE74248CAB6D0078724AEBAD9"><enum>(II)</enum><text>to help identify, or authenticate the identity of, an individual, or to protect against or
			 investigate fraud or other unlawful conduct.</text>
							</subclause></clause></subparagraph><subparagraph commented="no" id="HD1C1A25094584BBA920B3AF0706D308B"><enum>(B)</enum><header>Consumer access to information</header>
						<clause commented="no" id="H09761895703943D28D952641A311072B"><enum>(i)</enum><header>Access</header><text>Each information broker shall—</text>
							<subclause commented="no" id="H54BF849DDF0F4D4B9CB61CDF7732E03A"><enum>(I)</enum><text display-inline="yes-display-inline">provide to each individual whose personal information it maintains, at the individual’s request at
			 least 1 time per year and at no cost to the individual, and after
			 verifying the identity of such individual, a means for the individual to
			 review any personal information regarding such individual maintained by
			 the information broker and any other information maintained by the
			 information broker that specifically identifies such individual, other
			 than information which merely identifies an individual’s name or address;
			 and</text>
							</subclause><subclause commented="no" id="HB644E26F418E47D4A07486EE0E709EAB"><enum>(II)</enum><text>place a conspicuous notice on its Internet website (if the information broker maintains such a
			 website) instructing individuals how to request access to the information
			 required to be provided under subclause (I), and, as applicable, how to
			 express a preference with respect to the use of personal information for
			 marketing purposes under clause (iii).</text>
							</subclause></clause><clause commented="no" id="H27EBB631E6854355B78EDF4CE7E638CA"><enum>(ii)</enum><header>Disputed information</header><text display-inline="yes-display-inline">Whenever an individual whose information the information broker maintains makes a written request
			 disputing the accuracy of any such information, the information broker,
			 after verifying the identity of the individual making such request and
			 unless there are reasonable grounds to believe such request is frivolous
			 or irrelevant, shall—</text>
							<subclause commented="no" display-inline="no-display-inline" id="HE76D41A61DA041499C0D0A14463E5DF0"><enum>(I)</enum><text>correct any inaccuracy; or</text>
							</subclause><subclause commented="no" id="H36C5D2607CC546FCB87A1FF548C9B823"><enum>(II)</enum>
								<item commented="no" display-inline="yes-display-inline" id="H54EB1A9A943B40FFAB311343D2D2F132"><enum>(aa)</enum><text>in the case of information that is public record information, inform the individual of the source
			 of the information, and, if reasonably available, where a request for
			 correction may be directed and, if the individual provides proof that the
			 public record has been corrected or that the information broker was
			 reporting the information incorrectly, correct the inaccuracy in the
			 information broker’s records; or</text>
								</item><item commented="no" id="HDEC3BF2B1D5E4DFE805C3D8F6C7834DE" indent="up1"><enum>(bb)</enum><text display-inline="yes-display-inline">in the case of information that is non-public information, note the information that is disputed,
			 including the individual’s statement disputing such information, and take
			 reasonable steps to independently verify such information under the
			 procedures outlined in subparagraph (A) if such information can be
			 independently verified.</text>
								</item></subclause></clause><clause commented="no" id="HFD2B75FA60E344D285FFEEB32F46AEEC"><enum>(iii)</enum><header>Alternative procedure for certain marketing information</header><text display-inline="yes-display-inline">In accordance with regulations issued under clause (v), an information broker that maintains any
			 information described in clause (i) which is used, shared, or sold by such
			 information broker for marketing purposes, may, in lieu of complying with
			 the access and dispute requirements set forth in clauses (i) and (ii),
			 provide each individual whose information it maintains with a reasonable
			 means of expressing a preference not to have his or her information used
			 for such purposes. If the individual expresses such a preference, the
			 information broker may not use, share, or sell the individual’s
			 information for marketing purposes.</text>
						</clause><clause id="H4DFE802A4BE542708460926CB95B3F74"><enum>(iv)</enum><header>Limitations</header><text>An information broker may limit the access to information required under clause (i)(I) and is not
			 required to provide notice to individuals as required under clause (i)(II)
			 in the following circumstances:</text>
							<subclause commented="no" id="H9F692AC0130C4107A536312E38F08933"><enum>(I)</enum><text>If access of the individual to the information is limited by law or legally recognized privilege.</text>
							</subclause><subclause commented="no" id="H917E0316A93A4DA1A83CE2954B556A99"><enum>(II)</enum><text>If the information is used for a legitimate governmental or fraud prevention purpose that would be
			 compromised by such access.</text>
							</subclause><subclause id="H8A5EFDD058C340A492966E04FBD243E8"><enum>(III)</enum><text display-inline="yes-display-inline">If the information consists of a published media record, unless that record has been included in a
			 report about an individual shared with a third party.</text>
							</subclause></clause><clause commented="no" id="HABAF6353A4CA4FE999F0DF80A3021557"><enum>(v)</enum><header>Rulemaking</header><text display-inline="yes-display-inline">Not later than 1 year after the date of the enactment of this Act, the Commission shall promulgate
			 regulations under <external-xref legal-doc="usc" parsable-cite="usc/5/553">section 553</external-xref> of title 5, United States Code, to carry out
			 this paragraph and to facilitate the purposes of this Act. In addition,
			 the Commission shall issue regulations, as necessary, under section 553 of
			 title 5, United States Code, on the scope of the application of the
			 limitations in clause (iv), including any additional circumstances in
			 which an information broker may limit access to information under such
			 clause that the Commission determines to be appropriate.</text>
						</clause></subparagraph><subparagraph commented="no" id="H373B26912EF0462191B5BDD280F043DB"><enum>(C)</enum><header>FCRA regulated persons</header><text display-inline="yes-display-inline">Any information broker who is engaged in activities subject to the Fair Credit Reporting Act and
			 who is in compliance with sections 609, 610, and 611 of such Act (15
			 U.S.C. 1681g; 1681h; 1681i) with respect to information subject to such
			 Act, shall be deemed to be in compliance with this paragraph with respect
			 to such information.</text>
					</subparagraph></paragraph><paragraph commented="no" id="HAD2F95F7579B462FADEC019519AA03B3"><enum>(4)</enum><header>Requirement of audit log of accessed and transmitted information</header><text display-inline="yes-display-inline">Not later than 1 year after the date of the enactment of this Act, the Commission shall promulgate
			 regulations under <external-xref legal-doc="usc" parsable-cite="usc/5/553">section 553</external-xref> of title 5, United States Code, to require
			 information brokers to establish measures which facilitate the auditing or
			 retracing of any internal or external access to, or transmissions of, any
			 data containing personal information collected, assembled, or maintained
			 by such information broker.</text>
				</paragraph><paragraph commented="no" id="HB32A5295599A42F08D6CE1EDD84E5834"><enum>(5)</enum><header>Prohibition on pretexting by information brokers</header>
					<subparagraph commented="no" id="HF4CE8177E38F4BECB097C5068952C501"><enum>(A)</enum><header>Prohibition on obtaining personal information by false pretenses</header><text>It shall be unlawful for an information broker to obtain or attempt to obtain, or cause to be
			 disclosed or attempt to cause to be disclosed to any person, personal
			 information or any other information relating to any person by—</text>
						<clause commented="no" id="HDD71D680EB0F4452BEE9802B55B5547B"><enum>(i)</enum><text>making a false, fictitious, or fraudulent statement or representation to any person; or</text>
						</clause><clause commented="no" id="HE50291DAD78C4CF89D08B9C5424BEE23"><enum>(ii)</enum><text display-inline="yes-display-inline">providing any document or other information to any person that the information broker knows or
			 should know to be forged, counterfeit, lost, stolen, or fraudulently
			 obtained, or to contain a false, fictitious, or fraudulent statement or
			 representation.</text>
						</clause></subparagraph><subparagraph commented="no" id="H574D54B8EDC04ECC8E6FE9562035A003"><enum>(B)</enum><header>Prohibition on solicitation to obtain personal information under false pretenses</header><text display-inline="yes-display-inline">It shall be unlawful for an information broker to request a person to obtain personal information
			 or any other information relating to any other person, if the information
			 broker knew or should have known that the person to whom such a request is
			 made will obtain or attempt to obtain such information in the manner
			 described in subparagraph (A).</text>
					</subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="HFE61247F843D4CE29789E6CAAF35F028"><enum>(c)</enum><header>Exemption for certain service providers</header><text display-inline="yes-display-inline">Nothing in this section shall apply to a service provider for any electronic communication by a
			 third party that is transmitted, routed, or stored in intermediate or
			 transient storage by such service provider.</text>
			</subsection></section><section id="H66DCCF84B6824EE3B5EA7C11B9EBDF68"><enum>3.</enum><header>Notification of information security breach</header>
			<subsection id="H54116728DBD84995B5D53984A51E1284"><enum>(a)</enum><header>Nationwide Notification</header><text>Any person engaged in interstate commerce that owns or possesses data in electronic form containing
			 personal information shall, following the discovery of a breach of
			 security of the system maintained by such person that contains such data—</text>
				<paragraph id="H6C0E554897A64C1D8DE80C730D961B33"><enum>(1)</enum><text>notify each individual who is a citizen or resident of the United States whose personal information
			 was acquired or accessed as a result of such a breach of security; and</text>
				</paragraph><paragraph id="H19AB67EEF0A34D70A9E3333FB21D07E8"><enum>(2)</enum><text>notify the Commission.</text>
				</paragraph></subsection><subsection id="H3ABE8565BCF94153B54FB87B7E89B780"><enum>(b)</enum><header>Special Notification Requirements</header>
				<paragraph id="H4AAC02B911AA46D39EDA6B1EBA89026D"><enum>(1)</enum><header>Third party agents</header><text>In the event of a breach of security by any third party entity that has been contracted to maintain
			 or process data in electronic form containing personal information on
			 behalf of any other person who owns or possesses such data, such third
			 party entity shall be required to notify such person of the breach of
			 security. Upon receiving such notification from such third party, such
			 person shall provide the notification required under subsection (a).</text>
				</paragraph><paragraph commented="no" id="HD7748C3A5A2E419F8F52B9A933F9CB0F"><enum>(2)</enum><header>Service providers</header><text display-inline="yes-display-inline">If a service provider becomes aware of a breach of security of data in electronic form containing
			 personal information that is owned or possessed by another person that
			 connects to or uses a system or network provided by the service provider
			 for the purpose of transmitting, routing, or providing intermediate or
			 transient storage of such data, such service provider shall be required to
			 notify of such a breach of security only the person who initiated such
			 connection, transmission, routing, or storage if such person can be
			 reasonably identified. Upon receiving such notification from a service
			 provider, such person shall provide the notification required under
			 subsection (a).</text>
				</paragraph><paragraph id="H12C1E1FCF961413B804FA61A6F0FF069"><enum>(3)</enum><header>Coordination of notification with consumer reporting agencies</header><text display-inline="yes-display-inline">If a person is required to provide notification to more than 5,000 individuals under subsection
			 (a)(1), the person shall also notify the major consumer reporting agencies
			 of the timing and distribution of the notices. Such notice shall be given
			 to the consumer reporting agencies without unreasonable delay and, if it
			 will not delay notice to the affected individuals, prior to the
			 distribution of notices to the affected individuals.</text>
				</paragraph></subsection><subsection id="HD303D8FB1C8C4E3A975659C475FDD36E"><enum>(c)</enum><header>Timeliness of Notification</header>
				<paragraph commented="no" id="H256FC1FE2D0A4EAD9FFA6714A3D6D13E"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">Unless subject to a delay authorized under paragraph (2), a notification required under subsection
			 (a) shall be made not later than 60 days following the discovery of a
			 breach of security, unless the person providing notice can show that
			 providing notice within such a time frame is not feasible due to
			 extraordinary circumstances necessary to prevent further breach or
			 unauthorized disclosures, and reasonably restore the integrity of the data
			 system, in which case such notification shall be made as promptly as
			 possible.</text>
				</paragraph><paragraph commented="no" id="H4BB8CD424CC742118C08D2619DCFA434"><enum>(2)</enum><header>Delay of Notification Authorized for Law Enforcement or National Security Purposes</header>
					<subparagraph commented="no" id="H06A792343F62411BA3AA766049A85034"><enum>(A)</enum><header>Law enforcement</header><text>If a Federal, State, or local law enforcement agency determines that the notification required
			 under this section would impede a civil or criminal investigation, such
			 notification shall be delayed upon the written request of the law
			 enforcement agency for 30 days or such lesser period of time which the law
			 enforcement agency determines is reasonably necessary and requests in
			 writing. A law enforcement agency may, by a subsequent written request,
			 revoke such delay or extend the period of time set forth in the original
			 request made under this paragraph if further delay is necessary.</text>
					</subparagraph><subparagraph commented="no" id="H8B1FAE6BFB854977B45022F04D8A0866"><enum>(B)</enum><header>National security</header><text>If a Federal national security agency or homeland security agency determines that the notification
			 required under this section would threaten national or homeland security,
			 such notification may be delayed for a period of time which the national
			 security agency or homeland security agency determines is reasonably
			 necessary and requests in writing. A Federal national security agency or
			 homeland security agency may revoke such delay or extend the period of
			 time set forth in the original request made under this paragraph by a
			 subsequent written request if further delay is necessary.</text>
					</subparagraph></paragraph></subsection><subsection id="HFC941CC067044B9E8A8F696EC610EA4A"><enum>(d)</enum><header>Method and Content of Notification</header>
				<paragraph id="H75A71D2EF4DF4DEFA252CDF018966620"><enum>(1)</enum><header>Direct notification</header>
					<subparagraph id="H7F9F8BFA97C844D09056129FFB71D47E"><enum>(A)</enum><header>Method of notification</header><text>A person required to provide notification to individuals under subsection (a)(1) shall be in
			 compliance with such requirement if the person provides conspicuous and
			 clearly identified notification by one of the following methods (provided
			 the selected method can reasonably be expected to reach the intended
			 individual):</text>
						<clause id="H4E5A4FC5137149A7AC3DDE03041FF789"><enum>(i)</enum><text>Written notification.</text>
						</clause><clause id="H78A040EC4131479B833368D9BCEBB24A"><enum>(ii)</enum><text>Notification by email or other electronic means, if—</text>
							<subclause id="H5985CC0ED8B440648AC49E826D8CCFA3"><enum>(I)</enum><text>the person’s primary method of communication with the individual is by email or such other
			 electronic means; or</text>
							</subclause><subclause id="H786085E5F4204989B1E61CE48CA90CF3"><enum>(II)</enum><text>the individual has consented to receive such notification and the notification is provided in a
			 manner that is consistent with the provisions permitting electronic
			 transmission of notices under section 101 of the Electronic Signatures in
			 Global and National Commerce Act (<external-xref legal-doc="usc" parsable-cite="usc/15/7001">15 U.S.C. 7001</external-xref>).</text>
							</subclause></clause></subparagraph><subparagraph id="H2932B2CD458342DFAE001ECED5086DEF"><enum>(B)</enum><header>Content of notification</header><text>Regardless of the method by which notification is provided to an individual under subparagraph (A),
			 such notification shall include—</text>
						<clause id="H71E89AD5DA2A4A459B3FBA086128FAC8"><enum>(i)</enum><text>a description of the personal information that was acquired or accessed by an unauthorized person;</text>
						</clause><clause id="H594282BCB89747CEA70F5ED51CDBAC45"><enum>(ii)</enum><text>a telephone number that the individual may use, at no cost to such individual, to contact the
			 person to inquire about the breach of security or the information the
			 person maintained about that individual;</text>
						</clause><clause commented="no" id="HE19F1AC88E8849EA9767AC08CA37458C"><enum>(iii)</enum><text display-inline="yes-display-inline">notice that the individual is entitled to receive, at no cost to such individual, consumer credit
			 reports on a quarterly basis for a period of 2 years, or credit monitoring
			 or other service that enables consumers to detect the misuse of their
			 personal information for a period of 2 years, and instructions to the
			 individual on requesting such reports or service from the person, except
			 when the only information which has been the subject of the security
			 breach is the individual’s first name or initial and last name, or
			 address, or phone number, in combination with a credit or debit card
			 number, and any required security code;</text>
						</clause><clause id="HF442F7D2A400408EA696754976F07AAF"><enum>(iv)</enum><text>the toll-free contact telephone numbers and addresses for the major consumer reporting agencies;
			 and</text>
						</clause><clause id="H9B476E7609004638BDED2A0929EA0274"><enum>(v)</enum><text>a toll-free telephone number and Internet website address for the Commission whereby the individual
			 may obtain information regarding identity theft.</text>
						</clause></subparagraph></paragraph><paragraph id="HA5710F2728614CC5B26A127F19C8FAA9"><enum>(2)</enum><header>Substitute notification</header>
					<subparagraph id="HC046DA9423154BD4BF84157590C35057"><enum>(A)</enum><header>Circumstances giving rise to substitute notification</header><text>A person required to provide notification to individuals under subsection (a)(1) may provide
			 substitute notification in lieu of the direct notification required by
			 paragraph (1) if the person owns or possesses data in electronic form
			 containing personal information of fewer than 1,000 individuals and such
			 direct notification is not feasible due to—</text>
						<clause id="HF9EE2585C6164912BB6FDDA938386F1E"><enum>(i)</enum><text>excessive cost to the person required to provide such notification relative to the resources of
			 such person, as determined in accordance with the regulations issued by
			 the Commission under paragraph (3)(A); or</text>
						</clause><clause id="H39F9949BFB25479E914D7DA0EE66FEBA"><enum>(ii)</enum><text>lack of sufficient contact information for the individual required to be notified.</text>
						</clause></subparagraph><subparagraph id="HE2871C68258B452CBB7BD468F10FA2CC"><enum>(B)</enum><header>Form of substitute notification</header><text>Such substitute notification shall include—</text>
						<clause id="HBCFAD54B8701473695A459734482D7EA"><enum>(i)</enum><text>email notification to the extent that the person has email addresses of individuals to whom it is
			 required to provide notification under subsection (a)(1);</text>
						</clause><clause id="H5F8FE1B26AEC406F90DDD16E73006E06"><enum>(ii)</enum><text>a conspicuous notice on the Internet website of the person (if such person maintains such a
			 website); and</text>
						</clause><clause id="H45D0A046F0D04675A5BA6C485D8B795B"><enum>(iii)</enum><text>notification in print and to broadcast media, including major media in metropolitan and rural areas
			 where the individuals whose personal information was acquired reside.</text>
						</clause></subparagraph><subparagraph id="HD330CD0407394179B011BA71512225BB"><enum>(C)</enum><header>Content of substitute notice</header><text>Each form of substitute notice under this paragraph shall include—</text>
						<clause id="H29674B52EFAD401A827BF65FDE70DB89"><enum>(i)</enum><text display-inline="yes-display-inline">notice that individuals whose personal information is included in the breach of security are
			 entitled to receive, at no cost to the individuals, consumer credit
			 reports on a quarterly basis for a period of 2 years, or credit monitoring
			 or other service that enables consumers to detect the misuse of their
			 personal information for a period of 2 years, and instructions on
			 requesting such reports or service from the person, except when the only
			 information which has been the subject of the security breach is the
			 individual’s first name or initial and last name, or address, or phone
			 number, in combination with a credit or debit card number, and any
			 required security code; and</text>
						</clause><clause id="H289C6CDB7DB24D85B5ABDE382ED28DEF"><enum>(ii)</enum><text>a telephone number by which an individual can, at no cost to such individual, learn whether that
			 individual’s personal information is included in the breach of security.</text>
						</clause></subparagraph></paragraph><paragraph id="HDAF2FFAD9E8C41ED816E6D7892E0B643"><enum>(3)</enum><header>Regulations and guidance</header>
					<subparagraph id="H1D69D78FD0D8435384F374CEABC16A13"><enum>(A)</enum><header>Regulations</header><text>Not later than 1 year after the date of enactment of this Act, the Commission shall, by regulation
			 under <external-xref legal-doc="usc" parsable-cite="usc/5/553">section 553</external-xref> of title 5, United States Code, establish criteria for
			 determining circumstances under which substitute notification may be
			 provided under paragraph (2), including criteria for determining if
			 notification under paragraph (1) is not feasible due to excessive costs to
			 the person required to provided such notification relative to the
			 resources of such person. Such regulations may also identify other
			 circumstances where substitute notification would be appropriate for any
			 person, including circumstances under which the cost of providing
			 notification exceeds the benefits to consumers.</text>
					</subparagraph><subparagraph id="HD359D3DC9E7F4BB281C82F745DA41630"><enum>(B)</enum><header>Guidance</header><text>In addition, the Commission shall provide and publish general guidance with respect to compliance
			 with this subsection. Such guidance shall include—</text>
						<clause commented="no" id="HA9EE1B9236B8461EBBF6FF07FE08AB16"><enum>(i)</enum><text>a description of written or email notification that complies with the requirements of paragraph
			 (1); and</text>
						</clause><clause commented="no" id="H094D728BF0F74FC89BD18A21717FA7D5"><enum>(ii)</enum><text>guidance on the content of substitute notification under paragraph (2), including the extent of
			 notification to print and broadcast media that complies with the
			 requirements of such paragraph.</text>
						</clause></subparagraph></paragraph></subsection><subsection commented="no" id="H77467D6C70D34D29A88C6093EF950A3E"><enum>(e)</enum><header>Other Obligations Following Breach</header>
				<paragraph commented="no" id="HE482C50621E14C86A554694217F67304"><enum>(1)</enum><header>In general</header><text>A person required to provide notification under subsection (a) shall, upon request of an individual
			 whose personal information was included in the breach of security, provide
			 or arrange for the provision of, to each such individual and at no cost to
			 such individual—</text>
					<subparagraph id="H8DF5EB4B9EC54EB0AAB01C922EC8AD53"><enum>(A)</enum><text>consumer credit reports from at least one of the major consumer reporting agencies beginning not
			 later than 60 days following the individual’s request and continuing on a
			 quarterly basis for a period of 2 years thereafter; or</text>
					</subparagraph><subparagraph id="HBF572183F99B4A8D81E945D32101288F"><enum>(B)</enum><text display-inline="yes-display-inline">a credit monitoring or other service that enables consumers to detect the misuse of their personal
			 information, beginning not later than 60 days following the individual’s
			 request and continuing for a period of 2 years.</text>
					</subparagraph></paragraph><paragraph commented="no" id="H726E4177F5BA4E6F970E599BB17F56D9"><enum>(2)</enum><header>Limitation</header><text>This subsection shall not apply if the only personal information which has been the subject of the
			 security breach is the individual’s first name or initial and last name,
			 or address, or phone number, in combination with a credit or debit card
			 number, and any required security code.</text>
				</paragraph><paragraph commented="no" id="H1D2AEB2ADC7A4F228C0BDDCD774CE2E7"><enum>(3)</enum><header>Rulemaking</header><text>As part of the Commission’s rulemaking described in subsection (d)(3), the Commission shall
			 determine the circumstances under which a person required to provide
			 notification under subsection (a)(1) shall provide or arrange for the
			 provision of free consumer credit reports or credit monitoring or other
			 service to affected individuals.</text>
				</paragraph></subsection><subsection id="H1DEB1A0015AA4CCE8F1CD8ADF14C1410"><enum>(f)</enum><header>Exemption</header>
				<paragraph id="H4C696DF742354BF5833D0754E3C7E8CD"><enum>(1)</enum><header>General exemption</header><text>A person shall be exempt from the requirements under this section if, following a breach of
			 security, such person determines that there is no reasonable risk of
			 identity theft, fraud, or other unlawful conduct.</text>
				</paragraph><paragraph id="H45656541DB314869B1E6B2AD02B93490"><enum>(2)</enum><header>Presumption</header>
					<subparagraph id="H45ECF806FEF54CEA993123E6CF62D134"><enum>(A)</enum><header>In general</header><text>If the data in electronic form containing personal information is rendered unusable, unreadable, or
			 indecipherable through encryption or other security technology or
			 methodology (if the method of encryption or such other technology or
			 methodology is generally accepted by experts in the information security
			 field), there shall be a presumption that no reasonable risk of identity
			 theft, fraud, or other unlawful conduct exists following a breach of
			 security of such data. Any such presumption may be rebutted by facts
			 demonstrating that the encryption or other security technologies or
			 methodologies in a specific case, have been or are reasonably likely to be
			 compromised.</text>
					</subparagraph><subparagraph commented="no" id="HDECF710CCC234B6D8425B3F309176ECB"><enum>(B)</enum><header>methodologies or technologies</header><text display-inline="yes-display-inline">Not later than 1 year after the date of the enactment of this Act and biannually thereafter, the
			 Commission shall issue rules (pursuant to <external-xref legal-doc="usc" parsable-cite="usc/5/553">section 553</external-xref> of title 5, United
			 States Code) or guidance to identify security methodologies or
			 technologies which render data in electronic form unusable, unreadable, or
			 indecipherable, that shall, if applied to such data, establish a
			 presumption that no reasonable risk of identity theft, fraud, or other
			 unlawful conduct exists following a breach of security of such data. Any
			 such presumption may be rebutted by facts demonstrating that any such
			 methodology or technology in a specific case has been or is reasonably
			 likely to be compromised. In issuing such rules or guidance, the
			 Commission shall consult with relevant industries, consumer organizations,
			 and data security and identity theft prevention experts and established
			 standards setting bodies.</text>
					</subparagraph></paragraph><paragraph id="HB2EC51D905754C7E8762089D0BE2334E"><enum>(3)</enum><header>FTC guidance</header><text display-inline="yes-display-inline">Not later than 1 year after the date of the enactment of this Act the Commission shall issue
			 guidance regarding the application of the exemption in paragraph (1).</text>
				</paragraph></subsection><subsection id="H792517D3F61541AF9BCB4E415E74AE96"><enum>(g)</enum><header>Website Notice of Federal Trade Commission</header><text>If the Commission, upon receiving notification of any breach of security that is reported to the
			 Commission under subsection (a)(2), finds that notification of such a
			 breach of security via the Commission’s Internet website would be in the
			 public interest or for the protection of consumers, the Commission shall
			 place such a notice in a clear and conspicuous location on its Internet
			 website.</text>
			</subsection><subsection id="HFC6926458C944EC48685C9E974DE86FB"><enum>(h)</enum><header>FTC Study on Notification in Languages in Addition to English</header><text>Not later than 1 year after the date of enactment of this Act, the Commission shall conduct a study
			 on the practicality and cost effectiveness of requiring the notification
			 required by subsection (d)(1) to be provided in a language in addition to
			 English to individuals known to speak only such other language.</text>
			</subsection><subsection id="H7E48115AF9DC4112B0C1B39EB633FE82"><enum>(i)</enum><header>General rulemaking authority</header><text display-inline="yes-display-inline">The Commission may promulgate regulations necessary under <external-xref legal-doc="usc" parsable-cite="usc/5/553">section 553</external-xref> of title 5, United States
			 Code, to effectively enforce the requirements of this section.</text>
			</subsection><subsection commented="no" id="H7344C2AFE456454086964F1969493AA5"><enum>(j)</enum><header>Treatment of persons governed by other law</header><text display-inline="yes-display-inline">A person who is in compliance with any other Federal law that requires such person to provide
			 notification to individuals following a breach of security, and that,
			 taken as a whole, provides protections substantially similar to, or
			 greater than, those required under this section, as the Commission shall
			 determine by rule (under <external-xref legal-doc="usc" parsable-cite="usc/5/553">section 553</external-xref> of title 5, United States Code),
			 shall be deemed to be in compliance with this section.</text>
			</subsection></section><section id="HD2CA55C4C3B44C368EC63060D36FCB21"><enum>4.</enum><header>Application and Enforcement</header>
			<subsection commented="no" id="H58F5A9EC589D42DFBD1E62718C8A5908"><enum>(a)</enum><header>General application</header><text display-inline="yes-display-inline">The requirements of sections 2 and 3 shall only apply to those persons, partnerships, or
			 corporations over which the Commission has authority pursuant to section
			 5(a)(2) of the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/45">15 U.S.C. 45(a)(2)</external-xref>).</text>
			</subsection><subsection id="H25AF237CACF64E338E8262CF32F8DC65"><enum>(b)</enum><header>Enforcement by the Federal Trade Commission</header>
				<paragraph id="H8BE0C0313A284E4987CBECC74915B8E7"><enum>(1)</enum><header>Unfair or deceptive acts or practices</header><text>A violation of section 2 or 3 shall be treated as an unfair and deceptive act or practice in
			 violation of a regulation under section 18(a)(1)(B) of the Federal Trade
			 Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/57a">15 U.S.C. 57a(a)(1)(B)</external-xref>) regarding unfair or deceptive acts
			 or practices.</text>
				</paragraph><paragraph id="H8C2699E62893404DA5692EE34A81DB50"><enum>(2)</enum><header>Powers of commission</header><text>The Commission shall enforce this Act in the same manner, by the same means, and with the same
			 jurisdiction, powers, and duties as though all applicable terms and
			 provisions of the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/41">15 U.S.C. 41 et seq.</external-xref>) were
			 incorporated into and made a part of this Act. Any person who violates
			 such regulations shall be subject to the penalties and entitled to the
			 privileges and immunities provided in that Act.</text>
				</paragraph><paragraph id="H945575436B4946C99EB08A501BFF6E33"><enum>(3)</enum><header>Limitation</header><text>In promulgating rules under this Act, the Commission shall not require the deployment or use of any
			 specific products or technologies, including any specific computer
			 software or hardware.</text>
				</paragraph></subsection><subsection id="H4DC1FF6C29744FDC8B7C7FA76BB65503"><enum>(c)</enum><header>Enforcement by State Attorneys General</header>
				<paragraph id="H2FBD9F741C964D8693206983514B11FC"><enum>(1)</enum><header>Civil action</header><text>In any case in which the attorney general of a State, or an official or agency of a State, has
			 reason to believe that an interest of the residents of that State has been
			 or is threatened or adversely affected by any person who violates section
			 2 or 3 of this Act, the attorney general, official, or agency of the
			 State, as parens patriae, may bring a civil action on behalf of the
			 residents of the State in a district court of the United States of
			 appropriate jurisdiction—</text>
					<subparagraph id="H350464EDCAD84EB19AE41E3A08A1960F"><enum>(A)</enum><text>to enjoin further violation of such section by the defendant;</text>
					</subparagraph><subparagraph id="H67203B65A92C44319E700A8F8AE9C894"><enum>(B)</enum><text>to compel compliance with such section; or</text>
					</subparagraph><subparagraph id="HD19D3EF7BFFC48AC944CC84D2AF9F6C4"><enum>(C)</enum><text>to obtain civil penalties in the amount determined under paragraph (2).</text>
					</subparagraph></paragraph><paragraph id="H6BDF989C1568446C866248B42F9147EC"><enum>(2)</enum><header>Civil penalties</header>
					<subparagraph id="H039B9369A0EF41DB96BDEDF74D429154"><enum>(A)</enum><header>Calculation</header>
						<clause id="HC29F91F17BD745589F79C1650D25F94A"><enum>(i)</enum><header>Treatment of violations of section 2</header><text>For purposes of paragraph (1)(C) with regard to a violation of section 2, the amount determined
			 under this paragraph is the amount calculated by multiplying the number of
			 days that a person is not in compliance with such section by an amount not
			 greater than $11,000.</text>
						</clause><clause id="H7FCCDB71627745AE92A68ABDAE2BF111"><enum>(ii)</enum><header>Treatment of violations of section 3</header><text display-inline="yes-display-inline">For purposes of paragraph (1)(C) with regard to a violation of section 3, the amount determined
			 under this paragraph is the amount calculated by multiplying the number of
			 violations of such section by an amount not greater than $11,000. Each
			 failure to send notification as required under section 3 to a resident of
			 the State shall be treated as a separate violation.</text>
						</clause></subparagraph><subparagraph id="H575B684329FF419395E9455E2B809356"><enum>(B)</enum><header>Adjustment for inflation</header><text>Beginning on the date that the Consumer Price Index is first published by the Bureau of Labor
			 Statistics that is after 1 year after the date of enactment of this Act,
			 and each year thereafter, the amounts specified in clauses (i) and (ii) of
			 subparagraph (A) shall be increased by the percentage increase in the
			 Consumer Price Index published on that date from the Consumer Price Index
			 published the previous year.</text>
					</subparagraph><subparagraph id="H4743273C227E49B29A7F2AFF4BBDA16D"><enum>(C)</enum><header>Maximum total liability</header><text display-inline="yes-display-inline">Notwithstanding the number of actions which may be brought against a person under this subsection,
			 the maximum civil penalty for which any person may be liable under this
			 subsection shall not exceed—</text>
						<clause id="H9C6EAB0689834F2EB7175B2117FB7201"><enum>(i)</enum><text>$5,000,000 for each violation of section 2; and</text>
						</clause><clause id="H8FF408347CEC4F72A9973FAEA6EC71EC"><enum>(ii)</enum><text>$5,000,000 for all violations of section 3 resulting from a single breach of security.</text>
						</clause></subparagraph></paragraph><paragraph id="H043B25D167F44C01976028A90C2C2B81"><enum>(3)</enum><header>Intervention by the FTC</header>
					<subparagraph id="H3F3AB9BD157B4578A3BBC79AB91668C2"><enum>(A)</enum><header>Notice and intervention</header><text>The State shall provide prior written notice of any action under paragraph (1) to the Commission
			 and provide the Commission with a copy of its complaint, except in any
			 case in which such prior notice is not feasible, in which case the State
			 shall serve such notice immediately upon instituting such action. The
			 Commission shall have the right—</text>
						<clause id="H445F19FCC02C42D0B00995854E571FB6"><enum>(i)</enum><text>to intervene in the action;</text>
						</clause><clause id="H93E2B3BABC3C405BB8B39DA61C4B4DAA"><enum>(ii)</enum><text>upon so intervening, to be heard on all matters arising therein; and</text>
						</clause><clause id="H028A190E4EBB4E71BF3C12024C293FC3"><enum>(iii)</enum><text>to file petitions for appeal.</text>
						</clause></subparagraph><subparagraph id="H9020351AAC4741FA9707969CC562DA38"><enum>(B)</enum><header>Limitation on state action while federal action is pending</header><text>If the Commission has instituted a civil action for violation of this Act, no State attorney
			 general, or official or agency of a State, may bring an action under this
			 subsection during the pendency of that action against any defendant named
			 in the complaint of the Commission for any violation of this Act alleged
			 in the complaint.</text>
					</subparagraph></paragraph><paragraph id="H1E3334F804ED4A4FA34C1ED99BAC8A33"><enum>(4)</enum><header>Construction</header><text>For purposes of bringing any civil action under paragraph (1), nothing in this Act shall be
			 construed to prevent an attorney general of a State from exercising the
			 powers conferred on the attorney general by the laws of that State to—</text>
					<subparagraph id="HF90C6A924AA144779C14A37241850913"><enum>(A)</enum><text>conduct investigations;</text>
					</subparagraph><subparagraph id="HCE9763CC7CAE4880859D278E45A6CDB8"><enum>(B)</enum><text>administer oaths or affirmations; or</text>
					</subparagraph><subparagraph id="HC45C279992214D5C875E91E3FA27B01C"><enum>(C)</enum><text>compel the attendance of witnesses or the production of documentary and other evidence.</text>
					</subparagraph></paragraph></subsection><subsection id="H98DD774F02EA4699987892A5F9CB8D98"><enum>(d)</enum><header>Affirmative Defense for a Violation of section 3</header>
				<paragraph id="H5EA4783D72794B22BE8747726601E825"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">It shall be an affirmative defense to an enforcement action brought under subsection (b), or a
			 civil action brought under subsection (c), based on a violation of section
			 3, that all of the personal information contained in the data in
			 electronic form that was acquired or accessed as a result of a breach of
			 security of the defendant is public record information that is lawfully
			 made available to the general public from Federal, State, or local
			 government records and was acquired by the defendant from such records.</text>
				</paragraph><paragraph commented="no" id="HD39BA8445EAA4FAAB4EBB7DD114B4139"><enum>(2)</enum><header>No effect on other requirements</header><text>Nothing in this subsection shall be construed to exempt any person from the requirement to notify
			 the Commission of a breach of security as required under section 3(a).</text>
				</paragraph></subsection></section><section id="HFA3E3EA9A8074F1BAB26CF8E4D6AAE55"><enum>5.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act, the following definitions apply:</text>
			<paragraph id="H3C127A29188D430AA4882BA0341C1957"><enum>(1)</enum><header>Breach of security</header><text display-inline="yes-display-inline">The term <term>breach of security</term> means the unauthorized acquisition of data in electronic form containing personal information.</text>
			</paragraph><paragraph id="HDA8915188E114A95AA9957FFB03A4085"><enum>(2)</enum><header>Commission</header><text>The term <term>Commission</term> means the Federal Trade Commission.</text>
			</paragraph><paragraph id="HF43697196ADC4F52BBB14ED80DD25AD8"><enum>(3)</enum><header>Consumer reporting agency</header><text display-inline="yes-display-inline">The term <term>consumer reporting agency</term> has the meaning given the term <term>consumer reporting agency that compiles and maintains files on consumers on a nationwide basis</term> in section 603(p) of the Fair Credit Reporting Act (<external-xref legal-doc="usc" parsable-cite="usc/15/1681a">15 U.S.C. 1681a(p)</external-xref>).</text>
			</paragraph><paragraph id="H67E80C82B5FF49C999914489A5907302"><enum>(4)</enum><header>Data in electronic form</header><text>The term <term>data in electronic form</term> means any data stored electronically or digitally on any computer system or other database and
			 includes recordable tapes and other mass storage devices.</text>
			</paragraph><paragraph id="HBE8D8E1586A648F5B969895640A8FAC7"><enum>(5)</enum><header>Encryption</header><text>The term <term>encryption</term> means the protection of data in electronic form in storage or in transit using an encryption
			 technology that has been adopted by an established standards setting body
			 which renders such data indecipherable in the absence of associated
			 cryptographic keys necessary to enable decryption of such data. Such
			 encryption must include appropriate management and safeguards of such keys
			 to protect the integrity of the encryption.</text>
			</paragraph><paragraph id="H4161A3300ED745E39E459B3546CB85F3"><enum>(6)</enum><header>Identity theft</header><text>The term <term>identity theft</term> means the unauthorized use of another person’s personal information for the purpose of engaging in
			 commercial transactions under the name of such other person.</text>
			</paragraph><paragraph id="H67E755F9F72041FE961908F5B9AAB952"><enum>(7)</enum><header>Information broker</header><text>The term <term>information broker</term>—</text>
				<subparagraph id="HC87C206CBA564ADA97708AD7ECE4F37A"><enum>(A)</enum><text>means a commercial entity whose business is to collect, assemble, or maintain personal information
			 concerning individuals who are not current or former customers of such
			 entity in order to sell such information or provide access to such
			 information to any nonaffiliated third party in exchange for
			 consideration, whether such collection, assembly, or maintenance of
			 personal information is performed by the information broker directly, or
			 by contract or subcontract with any other entity; and</text>
				</subparagraph><subparagraph commented="no" id="H23DD2D7BFCFA4A9E8B4D6EDEADF88DBA"><enum>(B)</enum><text display-inline="yes-display-inline">does not include a commercial entity to the extent that such entity processes information collected
			 by and received from a nonaffiliated third party concerning individuals
			 who are current or former customers or employees of such third party to
			 enable such third party to (1) provide benefits for its employees or (2)
			 directly transact business with its customers.</text>
				</subparagraph></paragraph><paragraph id="HA5F98066FD4444D48212586EF7DF4C08"><enum>(8)</enum><header>Personal information</header>
				<subparagraph id="H92C3E6AACCB649C78A6297A10B3CCCF8"><enum>(A)</enum><header>Definition</header><text>The term <term>personal information</term> means an individual’s first name or initial and last name, or address, or phone number, in
			 combination with any 1 or more of the following data elements for that
			 individual:</text>
					<clause id="HC248E41C7FD248C5AF49770EAEA497E0"><enum>(i)</enum><text>Social Security number.</text>
					</clause><clause id="HC1A52C2D30404B1491FD97A964739843"><enum>(ii)</enum><text>Driver’s license number, passport number, military identification number, or other similar number
			 issued on a government document used to verify identity.</text>
					</clause><clause id="H2137844D2CED46E687C20DAC5A19D02D"><enum>(iii)</enum><text>Financial account number, or credit or debit card number, and any required security code, access
			 code, or password that is necessary to permit access to an individual’s
			 financial account.</text>
					</clause></subparagraph><subparagraph id="H6F31EB49A1414A609D4EC968AFAEFC65"><enum>(B)</enum><header>Modified definition by rulemaking</header><text display-inline="yes-display-inline">The Commission may, by rule promulgated under <external-xref legal-doc="usc" parsable-cite="usc/5/553">section 553</external-xref> of title 5, United States Code, modify
			 the definition of <quote>personal information</quote> under subparagraph (A)—</text>
					<clause id="HF76A21587F67433B9FF885BA2D2D0670"><enum>(i)</enum><text display-inline="yes-display-inline">for the purpose of section 2 to the extent that such modification will not unreasonably impede
			 interstate commerce, and will accomplish the purposes of this Act; or</text>
					</clause><clause id="H73C4D7685752483D81E3B137F7472B84"><enum>(ii)</enum><text>for the purpose of section 3, to the extent that such modification is necessary to accommodate
			 changes in technology or practices, will not unreasonably impede
			 interstate commerce, and will accomplish the purposes of this Act.</text>
					</clause></subparagraph></paragraph><paragraph id="H652C42A180C64D10B8F8E7C27B61266A"><enum>(9)</enum><header>Public record information</header><text>The term <term>public record information</term> means information about an individual which has been obtained originally from records of a
			 Federal, State, or local government entity that are available for public
			 inspection.</text>
			</paragraph><paragraph id="H1C0307B6DBC54B8D8B75CDADDDC88940"><enum>(10)</enum><header>Non-public information</header><text>The term <term>non-public information</term> means information about an individual that is of a private nature and neither available to the
			 general public nor obtained from a public record.</text>
			</paragraph><paragraph id="H4E82AF74A4D04639BEDA3593833FEFC7"><enum>(11)</enum><header>Service provider</header><text display-inline="yes-display-inline">The term <term>service provider</term> means an entity that provides to a user transmission, routing, intermediate and transient storage,
			 or connections to its system or network, for electronic communications,
			 between or among points specified by such user of material of the user’s
			 choosing, without modification to the content of the material as sent or
			 received. Any such entity shall be treated as a service provider under
			 this Act only to the extent that it is engaged in the provision of such
			 transmission, routing, intermediate and transient storage or connections.</text>
			</paragraph></section><section id="HBF90E9A0763343D68CC47AAA9F8C73B6"><enum>6.</enum><header>Effect on other laws</header>
			<subsection id="H991D90E8A321480C9C9E448383A8BEE0"><enum>(a)</enum><header>Preemption of State Information Security Laws</header><text>This Act supersedes any provision of a statute, regulation, or rule of a State or political
			 subdivision of a State, with respect to those entities covered by the
			 regulations issued pursuant to this Act, that expressly—</text>
				<paragraph id="H7BA4538DFEAA41B78687171725D0C3D7"><enum>(1)</enum><text>requires information security practices and treatment of data containing personal information
			 similar to any of those required under section 2; and</text>
				</paragraph><paragraph id="HD644A277E2A646DBBCB76B71860D1336"><enum>(2)</enum><text>requires notification to individuals of a breach of security resulting in unauthorized access to or
			 acquisition of data in electronic form containing personal information.</text>
				</paragraph></subsection><subsection id="H75A838F2767E42F89A1E5AC247F99424"><enum>(b)</enum><header>Additional Preemption</header>
				<paragraph id="HE63FA39D1425485B85D596CA36184BD1"><enum>(1)</enum><header>In general</header><text>No person other than a person specified in section 4(c) may bring a civil action under the laws of
			 any State if such action is premised in whole or in part upon the
			 defendant violating any provision of this Act.</text>
				</paragraph><paragraph id="H046220CFF12B485FAA8C6440F9A01504"><enum>(2)</enum><header>Protection of consumer protection laws</header><text>This subsection shall not be construed to limit the enforcement of any State consumer protection
			 law by an attorney general of a State.</text>
				</paragraph></subsection><subsection id="H7CE52CD4AD8B41498663A7BBD6C28296"><enum>(c)</enum><header>Protection of Certain State Laws</header><text>This Act shall not be construed to preempt the applicability of—</text>
				<paragraph id="HA1730CA2D0464A06BFB0A2FE4B3187A5"><enum>(1)</enum><text>State trespass, contract, or tort law; or</text>
				</paragraph><paragraph id="H06C597633C8A41AFAE810D08F8271ECB"><enum>(2)</enum><text>other State laws to the extent that those laws relate to acts of fraud.</text>
				</paragraph></subsection><subsection id="H97D199D3970A47C8B250FF145A660EB0"><enum>(d)</enum><header>Preservation of FTC Authority</header><text>Nothing in this Act may be construed in any way to limit or affect the Commission’s authority under
			 any other provision of law.</text>
			</subsection></section><section commented="no" id="HAADE691DD609479EA32B70F625FFDD8A"><enum>7.</enum><header>Effective date</header><text display-inline="no-display-inline">This Act shall take effect 1 year after the date of enactment of this Act.</text>
		</section><section id="H215C698DD718411F89785B6D777F886A"><enum>8.</enum><header>Authorization of appropriations</header><text display-inline="no-display-inline">There is authorized to be appropriated to the Commission $1,000,000 for each of fiscal years 2011
			 through 2016 to carry out this Act.</text>
		</section></legis-body>
</bill>


