<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" bill-type="olc" dms-id="HD29D9D31F2554641AEC96297E20D4A92" key="H" public-private="public">
<metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>115 HR 5388 IH: Data Accountability and Trust Act</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2018-03-22</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">I</distribution-code>
<congress display="yes">115th CONGRESS</congress><session display="yes">2d Session</session>
<legis-num display="yes">H. R. 5388</legis-num>
<current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber>
<action display="yes">
<action-date date="20180322">March 22, 2018</action-date>
<action-desc><sponsor name-id="R000515">Mr. Rush</sponsor> introduced the following bill; which was referred to the <committee-name committee-id="HIF00">Committee on Energy and Commerce</committee-name></action-desc>
</action>
<legis-type>A BILL</legis-type>
<official-title display="yes">To require certain entities who collect and maintain personal information of individuals to secure such information and to provide notice to such individuals in the case of a breach of security involving such information, and for other purposes.</official-title>
</form> 
<legis-body id="H1545161310DF411385DF0ABD71545A33" style="OLC"> 
<section id="H561FEC6F36F644168F39ACEBA9C1DD1A" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Data Accountability and Trust Act</short-title></quote>.</text> </section> <section id="H8B00E976729D4588BCB9BFD3985C9509"><enum>2.</enum><header>Requirements for information security</header> <subsection id="H807271BFF7104727B3146C898E1A874E"><enum>(a)</enum><header>General security policies and procedures</header> <paragraph id="H792B599D75174363ACBDE8BCFEA46F5D"><enum>(1)</enum><header>Regulations</header><text>Not later than 1 year after the date of enactment of this Act, the Commission shall promulgate regulations under section 553 of title 5, United States Code, to require each covered entity to establish and implement policies and procedures regarding information security practices for the treatment and protection of personal information taking into consideration—</text> 
<subparagraph id="H5FDABA31D6F74056B85E37A277F59E4A"><enum>(A)</enum><text>the size of, and the nature, scope, and complexity of the activities engaged in by such covered entity;</text> </subparagraph> <subparagraph id="H6F68D890E97F4055935777E6F18370C5"><enum>(B)</enum><text>the sensitivity of any personal information at issue;</text> </subparagraph>
<subparagraph id="HB007117FE21642718D46D3214AD811BE"><enum>(C)</enum><text>the current state of the art in administrative, technical, and physical safeguards for protecting such information; and</text> </subparagraph> <subparagraph id="H2B904A3BD63D4D6CA593F6ADCAEE56DD"><enum>(D)</enum><text>the cost of implementing such safeguards.</text> </subparagraph></paragraph>
<paragraph id="HED69B59FB4C941B0BFB96BD76B98ED6E"><enum>(2)</enum><header>Requirements</header><text>Such regulations shall require the policies and procedures to include the following:</text> <subparagraph id="HF3AB9C9561D34686A0E499FCD9395985"><enum>(A)</enum><text>A written security policy with respect to the collection, use, sale, other dissemination, and maintenance of such personal information.</text> </subparagraph>
<subparagraph id="H536AAC73612F4872BEBB6BDA656A3D0F"><enum>(B)</enum><text>The identification of an officer or other individual as the point of contact with responsibility for the management of information security.</text> </subparagraph> <subparagraph id="H367804EAAB5340248A16CF66CD6C3B58"><enum>(C)</enum><text>A process for identifying and assessing any reasonably foreseeable vulnerabilities in the system or systems maintained by such covered entity that contains such data, which shall include regular monitoring for a breach of security of such system or systems.</text> </subparagraph>
<subparagraph id="HB09ED5B7B9214D619CCECD45E330B20E"><enum>(D)</enum><text>A process for taking preventive and corrective action to mitigate against any vul­ner­a­bil­i­ties identified in the process required by subparagraph (C), which may include implementing any changes to security practices and the architecture, installation, or implementation of network or operating software, and for regularly testing or otherwise monitoring the effectiveness of the safeguards’ key controls, systems, and procedures.</text> </subparagraph> <subparagraph id="H706B7B5308644621BA84E9F8D4515B6D"><enum>(E)</enum><text>A process for disposing of data containing personal information by shredding, permanently erasing, or otherwise modifying the personal information contained in such data to make such personal information permanently unreadable or undecipherable.</text> </subparagraph>
<subparagraph id="HFD1F123A3ED744CC8FC1112B238750CD"><enum>(F)</enum><text>A process for overseeing persons to whom personal information is disclosed, or who have access to internet-connected devices, by—</text> <clause id="H8DAD961C4C1D4859B2F76EC40BE1BBBB"><enum>(i)</enum><text>taking reasonable steps to select and retain persons that are capable of maintaining appropriate safeguards for the personal information or internet-connected devices at issue; and</text> </clause>
<clause id="H22CDBB6D646946D4AED506B03D5BC88F"><enum>(ii)</enum><text>requiring all such persons to implement and maintain such security measures.</text> </clause></subparagraph></paragraph> <paragraph id="H9579342F01B14353889CD8F63598CF53"><enum>(3)</enum><header>Treatment of entities governed by other Federal law</header><text>Any covered entity who is in compliance with any other Federal law that requires such covered entity to maintain standards and safeguards for information security and protection of personal information that, taken as a whole and as the Commission shall determine in the rulemaking required under this subsection, provide protections substantially similar to, or greater than, those required under this subsection, shall be deemed to be in compliance with this subsection.</text> </paragraph></subsection>
<subsection id="HC4C3A726C7F64809984161F2A80ECE32"><enum>(b)</enum><header>Special requirements for information brokers</header> 
<paragraph id="H9202849D176947A388CCA3BCC051FA91"><enum>(1)</enum><header>Submission of policies to the FTC</header><text>The regulations promulgated under subsection (a) shall require each information broker to submit its security policies to the Commission in conjunction with a notification of a breach of security under section 3 or upon request of the Commission.</text> </paragraph> <paragraph id="HB112291D117B41828EE27982C95C2420"><enum>(2)</enum><header>Post-breach audit</header><text>For any information broker required to provide notification under section 3, the Commission may conduct audits of the information security practices of such information broker, or require the information broker to conduct independent audits of such practices (by an independent auditor who has not audited such information broker’s security practices during the preceding 5 years).</text> </paragraph>
<paragraph id="H6BDE31476B284B43BC526A0ECED320D9"><enum>(3)</enum><header>Accuracy of and individual access to personal information</header> 
<subparagraph id="H332A593C2DD848B3B8CA41D5DF14A26E"><enum>(A)</enum><header>Accuracy</header> 
<clause id="H1675F58325EF4E99A422557039CED0B6"><enum>(i)</enum><header>In general</header><text>Each information broker shall establish reasonable procedures to assure the maximum possible accuracy of the personal information the information broker collects, assembles, or maintains, and any other information the information broker collects, assembles, or maintains that specifically identifies an individual, other than information which merely identifies an individual’s name or address.</text> </clause> <clause id="H87395A1A6A2B4AA8A7C7AB5AED2844BF"><enum>(ii)</enum><header>Limited exception for fraud databases</header><text>The requirement in clause (i) shall not prevent the collection or maintenance of information that may be inaccurate with respect to a particular individual when that information is being collected or maintained solely—</text> 
<subclause id="H6DFE8D045DE3444DB99027F16F550B8B"><enum>(I)</enum><text>for the purpose of indicating whether there may be a discrepancy or irregularity in the personal information that is associated with an individual; and</text> </subclause> <subclause id="HE561CAE8C7BF453585F90280397AFE8B"><enum>(II)</enum><text>to help identify, or authenticate the identity of, an individual, or to protect against or investigate fraud or other unlawful conduct.</text> </subclause></clause></subparagraph>
<subparagraph id="H9FA692F85F52464DAC77AC1DA7F9B632"><enum>(B)</enum><header>Consumer access to information</header><text>Each information broker shall—</text> <clause id="HB8B02C02468F4FB5B00A70D3B7B21E98"><enum>(i)</enum><text>provide to each individual whose personal information the information broker maintains, at the individual’s request at least once per year and at no cost to the individual, and after verifying the identity of such individual, a means for the individual to review any personal information regarding such individual maintained by the information broker and any other information maintained by the information broker that specifically identifies such individual, other than information which merely identifies an individual’s name or address; and</text> </clause>
<clause id="HCEE790A343A54FBF88C3C356CD2847FD"><enum>(ii)</enum><text>place a conspicuous notice on the Internet website of the information broker (if the information broker maintains such a website) instructing individuals how to request access to the information required to be provided under clause (i), and, as applicable, how to express a preference with respect to the use of personal information for marketing purposes under subparagraph (D).</text> </clause></subparagraph> <subparagraph id="H3D82FCE468AC4E2E98AC36387A1C80E4"><enum>(C)</enum><header>Disputed information</header><text>Whenever an individual whose information the information broker maintains makes a written request disputing the accuracy of any such information, the information broker, after verifying the identity of the individual making such request and unless there are reasonable grounds to believe such request is frivolous or irrelevant, shall—</text> 
<clause id="H5DC2D938F3D84A0E990519130470C8D4"><enum>(i)</enum><text>correct any inaccuracy; or</text> </clause> <clause id="H567181CD059B4F01A4C7A9F40BF75608"><enum>(ii)</enum><text display-inline="yes-display-inline">in the case of information that is—</text> 
<subclause id="H5F08C58AC1C8467FB3689D8C13E75193"><enum>(I)</enum><text>public record information, inform the individual of the source of the information, and, if reasonably available, where a request for correction may be directed and, if the individual provides proof that the public record has been corrected or that the information broker was reporting the information incorrectly, correct the inaccuracy in the information broker’s records; or</text> </subclause> <subclause id="H7591038438AF40ECBC474B7502584E29"><enum>(II)</enum><text display-inline="yes-display-inline">nonpublic information, note the information that is disputed, including the individual’s statement disputing such information, and take reasonable steps to independently verify such information under the procedures outlined in subparagraph (A) if such information can be independently verified.</text> </subclause></clause></subparagraph>
<subparagraph id="HBAE46E5607CA448DBF5250B9CCED1D4E"><enum>(D)</enum><header>Alternative procedure for certain marketing information</header><text>In accordance with regulations issued under subparagraph (F), an information broker that maintains any information described in subparagraph (A) which is used, shared, or sold by such information broker for marketing purposes, may, in lieu of complying with the access and dispute requirements set forth in subparagraphs (B) and (C), provide each individual whose information the information broker maintains with a reasonable means of expressing a preference not to have his or her information used for such purposes. If the individual expresses such a preference, the information broker may not use, share, or sell the individual’s information for marketing purposes.</text> </subparagraph> <subparagraph id="H2372CBCD29384E69B7C7E56592661CC5"><enum>(E)</enum><header>Limitations</header><text>An information broker may limit the access to information required under subparagraph (B)(i) and is not required to provide notice to individuals as required under subparagraph (B)(ii) in the following circumstances:</text> 
<clause id="H7C394EB3E02143AF850596CEA8A50493"><enum>(i)</enum><text>If access of the individual to the information is limited by law or legally recognized privilege.</text> </clause> <clause id="HAC8CDDE79350498B973F90AC93706B7E"><enum>(ii)</enum><text>If the information is used for a legitimate governmental or fraud prevention purpose that would be compromised by such access.</text> </clause>
<clause id="H11D1B4CDD9E04AE59590884839D60D65"><enum>(iii)</enum><text>If the information consists of a published media record, unless that record has been included in a report about an individual shared with a third party.</text> </clause></subparagraph> <subparagraph id="HE2638CCDDBF147A3939637D2B9FCD374"><enum>(F)</enum><header>Rulemaking</header><text>Not later than 1 year after the date of enactment of this Act, the Commission shall promulgate regulations under section 553 of title 5, United States Code, to carry out this paragraph and to facilitate the purposes of this Act. In addition, the Commission shall issue regulations, as necessary, under section 553 of title 5, United States Code, on the scope of the application of the limitations in subparagraph (E), including any additional circumstances in which an information broker may limit access to information under such clause that the Commission determines to be appropriate.</text> </subparagraph>
<subparagraph id="H43A889E46C454B9B8793FB7F9C78B8D2"><enum>(G)</enum><header>FCRA regulated persons</header><text>Any information broker who is engaged in activities subject to the Fair Credit Reporting Act and who is in compliance with sections 609, 610, and 611 of such Act (<external-xref legal-doc="usc" parsable-cite="usc/15/1681g">15 U.S.C. 1681g</external-xref>; 1681h; 1681i) with respect to information subject to such Act, shall be deemed to be in compliance with this paragraph with respect to such information.</text> </subparagraph></paragraph> <paragraph id="H2A567B042EFF48D08AE1664700704591"><enum>(4)</enum><header>Requirement of audit log of accessed and transmitted information</header><text>Not later than 1 year after the date of enactment of this Act, the Commission shall promulgate regulations under section 553 of title 5, United States Code, to require information brokers to establish measures which facilitate the auditing or retracing of any internal or external access to, or transmissions of, any data containing personal information collected, assembled, or maintained by such information broker.</text> </paragraph>
<paragraph id="HC27D382CF0324F5B9BD391FCE326B974"><enum>(5)</enum><header>Prohibition on pretexting by information brokers</header> 
<subparagraph id="H207BBC0C23DB4FEC9B57A3ABDBE707DA"><enum>(A)</enum><header>Prohibition on obtaining personal information by false pretenses</header><text>It shall be unlawful for an information broker to obtain or attempt to obtain, or cause to be disclosed or attempt to cause to be disclosed to any person, personal information or any other information relating to any person by—</text> <clause id="HA565A39A030B4E75823595A67777F42B"><enum>(i)</enum><text>making a false, fictitious, or fraudulent statement or representation to any person; or</text> </clause>
<clause id="HEDAFFF7D8C574F9BBE4F955D4AB9850A"><enum>(ii)</enum><text>providing any document or other information to any person that the information broker knows or should know to be forged, counterfeit, lost, stolen, or fraudulently obtained, or to contain a false, fictitious, or fraudulent statement or representation.</text> </clause></subparagraph> <subparagraph id="HCC5E80A426AB4047B6E0A488156BCB02"><enum>(B)</enum><header>Prohibition on solicitation to obtain personal information under false pretenses</header><text>It shall be unlawful for an information broker to request a person to obtain personal information or any other information relating to any other person, if the information broker knew or should have known that the person to whom such a request is made will obtain or attempt to obtain such information in the manner described in subparagraph (A).</text> </subparagraph></paragraph></subsection></section>
<section id="H3FD011C9DBF34A7AA668593060D223B2"><enum>3.</enum><header>Notification of information security breach</header> 
<subsection id="H8D9F4C9B52A44DFAA5D8219B1D5AF83D"><enum>(a)</enum><header>Individual notification</header> 
<paragraph id="HD02CFCAEC1B54BF180D213B07AEC6561"><enum>(1)</enum><header>In general</header><text>Each covered entity shall, following the discovery of a breach of security, notify each individual who is a citizen or resident of the United States whose personal information was, or is reasonably believed to have been, acquired or accessed by an unauthorized person, or used for an unauthorized purpose.</text> </paragraph> <paragraph id="H9719125522624894A28D50172052FC29"><enum>(2)</enum><header>Timeliness of notification</header> <subparagraph id="H469404EABB9C4518ABCFBEDF65011F82"><enum>(A)</enum><header>In general</header><text>Unless subject to a delay authorized under subparagraph (B), a notification required under paragraph (1) shall be made as expeditiously as practicable and without unreasonable delay, but not later than 30 days following the discovery of a breach of security.</text> </subparagraph>
<subparagraph id="H1388F57C8425404BA8CC50329FFF113F"><enum>(B)</enum><header>Delay of notification authorized for law enforcement or national security purposes</header> 
<clause id="H4FB8348F1D97412FBE785E7B09896B55"><enum>(i)</enum><header>Law enforcement</header><text>If a Federal or State law enforcement agency, including an attorney general of a State, determines that the notification required under this section would impede a civil or criminal investigation, such notification shall be delayed upon the written request of the law enforcement agency for 30 days or such lesser period of time which the law enforcement agency determines is reasonably necessary and requests in writing. Such law enforcement agency may, by a subsequent written request, revoke such delay or extend the period of time set forth in the original request made under this paragraph if further delay is necessary.</text> </clause> <clause id="HF4E848E4F4C04CE4848D533B96E29CBD"><enum>(ii)</enum><header>National security</header><text>If a Federal national security agency or homeland security agency determines that the notification required under this section would threaten national or homeland security, such notification may be delayed for a period of time which the national security agency or homeland security agency determines is reasonably necessary and requests in writing. A Federal national security agency or homeland security agency may revoke such delay or extend the period of time set forth in the original request made under this paragraph by a subsequent written request if further delay is necessary.</text> </clause></subparagraph></paragraph></subsection>
<subsection id="HFB51B3914CEE4CE0A00A8C68131CDECF"><enum>(b)</enum><header>Coordination of notification with credit reporting agencies</header><text>If a covered entity is required to provide notification to more than 5,000 individuals under subsection (a)(1), the covered entity shall also notify the major consumer reporting agencies that compile and maintain files on consumers on a nationwide basis, of the timing and distribution of the notifications. Such notification shall be given to the credit reporting agencies without unreasonable delay and, if such notification will not delay notification to the affected individuals, prior to the distribution of notifications to the affected individuals.</text> </subsection> <subsection id="HEA42C6C8A92143CB80E5D3120EDBA61E"><enum>(c)</enum><header>Method and content of notification</header> <paragraph id="H211C4A6486364AA0870F56C2C343715C"><enum>(1)</enum><header>General notification</header><text>A covered entity required to provide notification to individuals under subsection (a)(1) shall be in compliance with such requirement if the covered entity provides conspicuous and clearly identified notification by one of the following methods (provided the selected method can reasonably be expected to reach the intended individual):</text> 
<subparagraph id="H6BE6165B992D417498626D909939E29E"><enum>(A)</enum><text>Written notification to the last known home mailing address of the individual in the records of the covered entity.</text> </subparagraph> <subparagraph id="HF2FC6A5F90874CCB9188420254B4C9B4"><enum>(B)</enum><text>Notification by email or other electronic means, if—</text> 
<clause id="H077D78761B334F71AB64365406284897"><enum>(i)</enum><text>the covered entity’s primary method of communication with the individual is by email or such other electronic means; or</text> </clause> <clause id="H9D4C6A09A70949B483F4076A78F90ED7"><enum>(ii)</enum><text>the individual has consented to receive such notification and the notification is provided in a manner that is consistent with the provisions permitting electronic transmission of notifications under section 101 of the Electronic Signatures in Global Commerce Act (<external-xref legal-doc="usc" parsable-cite="usc/15/7001">15 U.S.C. 7001</external-xref>).</text> </clause></subparagraph></paragraph>
<paragraph id="HD68E07C7353A4076BA1FCC81BB7487B1"><enum>(2)</enum><header>Website notification</header><text>The covered entity shall also provide conspicuous notification on the Internet website of the covered entity (if such covered entity maintains such a website) for a period of not less than 90 days.</text> </paragraph> <paragraph id="H7E3957BF633E4CC48A230100DFD22F81"><enum>(3)</enum><header>Media notification</header><text>If the number of residents of a State whose personal information was, or is reasonably believed to have been acquired or accessed by an unauthorized person, or used for an unauthorized purpose exceeds 5,000, the covered entity shall also provide notification in print and to broadcast media, including major media in metropolitan and rural areas where the individuals whose personal information was, or is reasonably believed to have been, acquired or accessed by an unauthorized person, or used for an unauthorized purpose, reside.</text> </paragraph>
<paragraph id="H310F9163424947D4831EA4B94CFB9179"><enum>(4)</enum><header>Content of notification</header> 
<subparagraph id="HAC5D1DF296BB4AD881376ECFE077C813"><enum>(A)</enum><header>In general</header><text>Regardless of the method by which notification is provided to an individual under paragraphs (1), (2), and (3), such notification shall include—</text> <clause id="HD020D467FA0F48AC923566349166ED0E"><enum>(i)</enum><text>a description of the personal information that was, or is reasonably believed to have been, acquired or accessed by an unauthorized person, or used for an unauthorized purpose;</text> </clause>
<clause id="H8467F26ADA224994BAC84A341DAFEB92"><enum>(ii)</enum><text>a telephone number that the individual may use, at no cost to such individual, to contact the covered entity, or agent of the covered entity, to inquire about the breach of security or the information the covered entity maintained about that individual;</text> </clause> <clause id="H4CA96D38B6CD40379D3B63557C3DDDB1"><enum>(iii)</enum><text>notification that the individual is entitled to receive, at no cost to such individual, consumer credit reports on a quarterly basis for a period of 5 years, or credit monitoring or other service that enables consumers to detect the misuse of their personal information for a period of 5 years, and instructions to the individual on requesting such reports or service from the covered entity;</text> </clause>
<clause id="H0CE6188D0A3B4B989EAC694ED0A58587"><enum>(iv)</enum><text>the toll-free contact telephone numbers and addresses for the major credit reporting agencies; and</text> </clause> <clause id="HB95F8A53AFDA4D2D9C5B72BDE0008671"><enum>(v)</enum><text>a toll-free telephone number and Internet website address for the Commission whereby the individual may obtain information regarding identity theft.</text> </clause></subparagraph>
<subparagraph id="HD38484EDAF2E4856917B16155D5ADC76"><enum>(B)</enum><header>Direct business relationship</header><text>Regardless of whether the covered entity or a designated third party provides notification under this subsection, such notification shall identify the covered entity that has a direct business relationship with the individual.</text> </subparagraph></paragraph> <paragraph commented="no" id="H977389A5824C4D87B7898F537B943817"><enum>(5)</enum><header>Regulations for substitute notification</header><text>Not later than 1 year after the date of enactment of this Act, the Commission shall, by regulation under section 553 of title 5, United States Code—</text> 
<subparagraph commented="no" id="HA8D7B8AF8A9549B38D426F0257D30B22"><enum>(A)</enum><text>establish criteria for determining circumstances under which substitute notification may be provided in lieu of direct notification required by paragraph (1), including criteria for determining if notification under paragraph (1) is not feasible due to excessive costs to the covered entity required to provided such notification relative to the resources of such covered entity; and</text> </subparagraph> <subparagraph commented="no" id="H453DEEBCE1F34580986F4038D8B49744"><enum>(B)</enum><text>establish the form and content of substitute notification.</text> </subparagraph></paragraph></subsection>
<subsection id="HF074D58254B3412EA7D10A512EE32A45"><enum>(d)</enum><header>Notification for law enforcement and other purposes</header><text>A covered entity shall, as expeditiously as practicable and without unreasonable delay, but not later than 14 days following the discovery of a breach of security, provide notification of the breach to—</text> <paragraph id="H57EF46CDB4944BFFAE8CF7BDD2769CA2"><enum>(1)</enum><text>the Commission;</text> </paragraph>
<paragraph id="H7C83100AE1CA4DD6B1C4C04C2EB575E3"><enum>(2)</enum><text>the Federal Bureau of Investigation;</text> </paragraph> <paragraph id="HCE6219290D574B7BACEF480A8A420DA2"><enum>(3)</enum><text>the Secret Service;</text> </paragraph>
<paragraph id="H3DA0BDB43DFE4DB28769D429B2684B5D"><enum>(4)</enum><text>for common carriers, the Federal Communications Commission;</text> </paragraph> <paragraph id="H3F909300E7D948908725E85274E34006"><enum>(5)</enum><text display-inline="yes-display-inline">the Consumer Financial Protection Bureau; and</text> </paragraph>
<paragraph id="H47101C56B42F4413AC821555CFCC38C5"><enum>(6)</enum><text>the attorney general of each State in which the personal information of a resident or residents of the State was, or is reasonably believed to have been, acquired or accessed by an unauthorized person, or used for an unauthorized purpose.</text> </paragraph></subsection> <subsection id="HD8671CC00D20438CA8A98328764DD184"><enum>(e)</enum><header>Other obligations following breach</header> <paragraph id="H8AA1D4EED6494035A9D950B6A67095CC"><enum>(1)</enum><header>In general</header><text>A covered entity required to provide notification under subsection (a) shall, upon request of an individual whose personal information was included in the breach of security, provide or arrange for the provision of, to each such individual and at no cost to such individual—</text> 
<subparagraph id="H7CD329039BE24403B049967E4F343C28"><enum>(A)</enum><text>consumer credit reports from the major credit reporting agencies beginning not later than 60 days following the individual’s request and continuing on a quarterly basis for a period of 5 years thereafter; or</text> </subparagraph> <subparagraph id="H19EB96C9C0E3447F9F13D523FF845652"><enum>(B)</enum><text>a credit monitoring or other service that enables consumers to detect the misuse of their personal information, beginning not later than 60 days following the individual’s request and continuing for a period of 5 years.</text> </subparagraph></paragraph>
<paragraph id="H7979458E8F9943A8B6B0FCC20F3F23F7"><enum>(2)</enum><header>Rulemaking</header><text>As part of the Commission’s rulemaking described in subsection (c)(5), the Commission shall determine the circumstances under which a covered entity required to provide notification under subsection (a) shall provide or arrange for the provision of free consumer credit reports or credit monitoring or other service to affected individuals.</text> </paragraph></subsection> <subsection id="H3D008A16ADAC4D67868ECFC67EFB3FE9"><enum>(f)</enum><header>Website notification of Federal Trade Commission</header><text>If the Commission, upon receiving notification of any breach of security that is reported to the Commission under subsection (d)(1), finds that notification of such a breach of security via the Commission’s Internet website would be in the public interest or for the protection of consumers, the Commission shall place such a notification in a clear and conspicuous location on its Internet website.</text> </subsection>
<subsection id="H5790584E738743F3BE71BC72445BD8EF"><enum>(g)</enum><header>Website notification of State attorneys general</header><text>If a State attorney general, upon receiving notification of any breach of security that is reported to the Commission under subsection (d)(5), finds that notification of such a breach of security through the State attorney general’s Internet website would be in the public interest or for the protection of consumers, the State attorney general shall place such a notification in a clear and conspicuous location on its Internet website.</text> </subsection> <subsection id="HA050BCE57C0B4535BD5934BBAAEF3163"><enum>(h)</enum><header>FTC study on notification in languages in addition to English</header><text>Not later than 1 year after the date of enactment of this Act, the Commission shall conduct a study on the practicality and cost effectiveness of requiring the notification required by subsection (c)(1) to be provided in a language in addition to English to individuals known to speak only such other language.</text> </subsection>
<subsection id="HD2F55AF79CD943789A716C6C8184C084"><enum>(i)</enum><header>Education and outreach for small businesses</header><text>The Commission shall conduct education and outreach for small business concerns on data security practices and how to prevent hacking and other unauthorized access to, acquisition of, or use of data maintained by such small business concerns.</text> </subsection> <subsection id="H01C97171A3BF4D9FB1BED4E840BA9D86"><enum>(j)</enum><header>Website on data security best practices</header><text>The Commission shall establish and maintain an Internet website containing non-binding best practices for businesses regarding data security and how to prevent hacking and other unauthorized access to, acquisition of, or use of data maintained by such businesses.</text> </subsection>
<subsection id="HD850A1DFF5174218A74AC8B2F3061F72"><enum>(k)</enum><header>General rulemaking authority</header> 
<paragraph id="H008423E35AD7464CB38E5728600CFA09"><enum>(1)</enum><header>In general</header><text>The Commission may promulgate regulations necessary under section 553 of title 5, United States Code, to effectively enforce the requirements of this section.</text> </paragraph> <paragraph id="H71CC19B03D3E46B69C017CD555C5356B"><enum>(2)</enum><header>Limitation</header><text>In promulgating rules under this Act, the Commission shall not require the deployment or use of any specific products or technologies, including any specific computer software or hardware.</text> </paragraph></subsection>
<subsection id="H8A1CF16530F54F45BC825E0DC0C34B8C"><enum>(l)</enum><header>Treatment of persons governed by other law</header><text>A covered entity who is in compliance with any other Federal law that requires such covered entity to provide notification to individuals following a breach of security, shall be deemed to be in compliance with this section with respect to activities and information covered under such Federal law.</text> </subsection></section> <section id="H97C7C6C632964CF8B5162AF52A23B8D8"><enum>4.</enum><header>Application and enforcement</header> <subsection id="H65EB500433A547BD8F75EB74A7C87D10"><enum>(a)</enum><header>Enforcement by the federal Trade Commission</header> <paragraph id="HC6A46E5B1B98402E98C6DD0A39C33FCE"><enum>(1)</enum><header>Unfair or deceptive acts or practices</header><text>A violation of section 2 or 3 shall be treated as an unfair and deceptive act or practice in violation of a regulation under section 18(a)(1)(B) of the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/57a">15 U.S.C. 57a(a)(1)(B)</external-xref>) regarding unfair or deceptive acts or practices and shall be subject to enforcement by the Commission under that Act with respect to any covered entity. All of the functions and powers of the Commission under the Federal Trade Commission Act are available to the Commission to enforce compliance by any person with the requirements imposed under this title, irrespective of whether that person is engaged in commerce or meets any other jurisdictional tests under the Federal Trade Commission Act.</text> </paragraph>
<paragraph id="H499769B54D764C3DB918FCDC3ACCF796"><enum>(2)</enum><header>Coordination with Federal Communications Commission</header><text>Where enforcement relates to entities subject to the authority of the Federal Communications Commission, enforcement actions by the Commission will be coordinated with the Federal Communications Commission.</text> </paragraph> <paragraph id="H452F314DBD314B61A32EA082B55C2ABF"><enum>(3)</enum><header>Coordination with Consumer Financial Protection Bureau</header><text>Where enforcement relates to financial information or information associated with the provision of financial products or services, enforcement actions by the Commission will be coordinated with the Consumer Financial Protection Bureau.</text> </paragraph></subsection>
<subsection id="H76BA06456E4E4C31A471BC4CEBE901DB"><enum>(b)</enum><header>Enforcement by State attorneys general</header> 
<paragraph commented="no" id="H5757331383904F8090F0BB8AE4BC867F"><enum>(1)</enum><header>In general</header><text>If the chief law enforcement officer of a State, or an official or agency designated by a State, has reason to believe that any covered entity has violated or is violating section 2 or 3 of this Act, the attorney general, official, or agency of the State, in addition to any authority it may have to bring an action in State court under its consumer protection law, may bring a civil action in any appropriate United States district court or in any other court of competent jurisdiction, including a State court, to—</text> <subparagraph commented="no" id="HEFD2DF94E0324CF99E32BE3DBA0D71EB"><enum>(A)</enum><text>enjoin further such violation by the defendant;</text> </subparagraph>
<subparagraph commented="no" id="H11E7ACD5956B43E58AE227A39A1FCA02"><enum>(B)</enum><text>enforce compliance with this such section;</text> </subparagraph> <subparagraph commented="no" id="HF6C509D12D7C4BF882FA2F5EBE3ABFF0"><enum>(C)</enum><text>obtain civil penalties in the amount determined under paragraph (2); and</text> </subparagraph>
<subparagraph commented="no" id="HA14A4C5EDCF549DBA81788F1D3763F38"><enum>(D)</enum><text>obtain damages, restitution, or other compensation on behalf of residents of the State.</text> </subparagraph></paragraph> <paragraph id="HD3095C255CF344AEA402C89355EC54DB"><enum>(2)</enum><header>Civil penalties</header> <subparagraph id="HAA17373D744E4B768B228A15C2902DEB"><enum>(A)</enum><header>Calculation</header> <clause id="HD55B677EB614404E8E698C4324F237D4"><enum>(i)</enum><header>Treatment of violations of section 2</header><text display-inline="yes-display-inline">For purposes of paragraph (1)(C) with regard to a violation of section 2, the amount determined under this paragraph is the amount calculated by multiplying the number of days that a covered entity is not in compliance with such section by an amount to be determined by the Commission. Such amount determined by the Commission shall be adjusted as described in the Federal Civil Penalties Inflation Adjustment Act of 1990 (<external-xref legal-doc="public-law" parsable-cite="pl/101/410">Public Law 101–410</external-xref>; <external-xref legal-doc="usc" parsable-cite="usc/28/2461">28 U.S.C. 2461</external-xref> note).</text> </clause>
<clause id="HEB2E91912A204180BB20E03C8A6CF25D"><enum>(ii)</enum><header>Treatment of violations of section 3</header><text display-inline="yes-display-inline">For purposes of paragraph (1)(C) with regard to a violation of section 3, the amount determined under this paragraph is the amount calculated by multiplying the number of violations of such section by an amount to be determined by the Commission. Each failure to send notification as required under section 3 to a citizen or resident of the United States shall be treated as a separate violation.</text> </clause></subparagraph> <subparagraph id="HD38F81C7B7874227A0BE2E96F8C915F6"><enum>(B)</enum><header>Adjustment for inflation</header><text>Beginning on the date that the Consumer Price Index is first published by the Bureau of Labor Statistics that is after 1 year after the date of enactment of this Act, and each year thereafter, the amounts specified in clauses (i) and (ii) of subparagraph (A) shall be increased by the percentage increase in the Consumer Price Index published on that date from the Consumer Price Index published the previous year.</text> </subparagraph></paragraph>
<paragraph id="HAF63E15819F747848FD50293A90DA1D9"><enum>(3)</enum><header>Notice and intervention by the FTC</header> 
<subparagraph id="H0BE689B07EF04DBC8CB0BA06FFC7C941"><enum>(A)</enum><text>The attorney general of a State shall provide prior written notice of any action under paragraph (1) to the Commission and provide the Commission with a copy of the complaint in the action, except in any case in which such prior notice is not feasible, in which case the attorney general shall serve such notice immediately upon instituting such action. The Commission shall have the right—</text> <clause id="H442A5437381546D3B8832FEC7FF073D0"><enum>(i)</enum><text>to intervene in the action;</text> </clause>
<clause id="H27F2583212F54025838807A5E702B6E6"><enum>(ii)</enum><text>upon so intervening, to be heard on all matters arising therein; and</text> </clause> <clause id="H48F679D7D7674C3A8D72921B2FBAC21B"><enum>(iii)</enum><text>to file petitions for appeal.</text> </clause></subparagraph>
<subparagraph id="HEBBE9337605F406BACA355A81D1AF791"><enum>(B)</enum><header>Limitation on State action while Federal action is pending</header><text>If the Commission has instituted a civil action for violation of this Act, no State attorney general, or official or agency of a State, may bring an action under this subsection during the pendency of that action against any defendant named in the complaint of the Commission for any violation of this Act alleged in the complaint.</text> </subparagraph></paragraph> <paragraph id="HC68D2A17886C46FD898C16D99680B1C8"><enum>(4)</enum><header>Relationship with State-law claims</header><text>If the attorney general of a State has authority to bring an action under State law directed at acts or practices that also violate this Act, the attorney general may assert the State-law claim and a claim under this Act in the same civil action.</text> </paragraph></subsection></section>
<section id="H64871AB38487485EA78015C14B2697C9"><enum>5.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act:</text> <paragraph id="HBE2F4AB6F065412E87F8AE20504CEA90"><enum>(1)</enum><header>Breach of security</header><text>The term <term>breach of security</term> means unauthorized access to, acquisition of, sale of, or use of data containing personal information.</text> </paragraph>
<paragraph id="H068FE0BC0BB04CCA9B2C4D016EFEA8E7"><enum>(2)</enum><header>Commission</header><text>The term <term>Commission</term> means the Federal Trade Commission.</text> </paragraph> <paragraph id="H8ABBAE7BAC4D4C8EB11CE27FA6678493"><enum>(3)</enum><header>Covered entity</header><text>The term <term>covered entity</term> means—</text> 
<subparagraph id="HC7FE89B91BEB40B38C381C253CE1160C"><enum>(A)</enum><text>any organization, corporation, trust, partnership, sole proprietorship, unincorporated association, or venture over which the Commission has authority pursuant to section 5(a)(2) of the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/45">15 U.S.C. 45(a)(2)</external-xref>);</text> </subparagraph> <subparagraph id="H3659E9D4116F40E39063FC45D2195943"><enum>(B)</enum><text>notwithstanding section 5(a)(2) of the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/45">15 U.S.C. 45(a)(2)</external-xref>), common carriers subject to the Communications Act of 1934 (<external-xref legal-doc="usc" parsable-cite="usc/47/151">47 U.S.C. 151</external-xref> et seq.); and</text> </subparagraph>
<subparagraph id="HAC61B18A636A43AE92B303EB85AE0C19"><enum>(C)</enum><text>notwithstanding sections 4 and 5(a)(2) of the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/44">15 U.S.C. 44</external-xref> and 45(a)(2)), any non-profit organization, including any organization described in <external-xref legal-doc="usc" parsable-cite="usc/26/501">section 501(c)</external-xref> of the Internal Revenue Code of 1986 that is exempt from taxation under <external-xref legal-doc="usc" parsable-cite="usc/26/501">section 501(a)</external-xref> of the Internal Revenue Code of 1986.</text> </subparagraph></paragraph> <paragraph id="H0AC0ECAA73FD4B23A6CF4178D3E0F165"><enum>(4)</enum><header>Personal information</header> <subparagraph id="H495994C21A41444897008F1B98F3CB4B"><enum>(A)</enum><header>Definition</header><text>The term <term>personal information</term> means any information or compilation of information that includes any of the following:</text> 
<clause id="H4A206BFAFC694E60ACC9A2CB4CE68413"><enum>(i)</enum><text>An individual’s first name or initial and last name in combination with any of the following data elements for that individual:</text> <subclause id="H6480D949104447CC9E8B480D8F1EE57B"><enum>(I)</enum><text>Home address or telephone number.</text> </subclause>
<subclause id="HB931CAC0AD9C4EB1A3CB16A90D35ED63"><enum>(II)</enum><text>Mother’s maiden name.</text> </subclause> <subclause id="H48D2ABE5802041A6A986CE425D88C705"><enum>(III)</enum><text>Month, day, and year of birth.</text> </subclause>
<subclause id="H3042D3218A07482BB74AE2ED11B010E3"><enum>(IV)</enum><text>User name or electronic mail address.</text> </subclause></clause> <clause id="H1DEF1F04AC1F44119FBB5FB2041311DA"><enum>(ii)</enum><text>Driver’s license number, passport number, military identification number, alien registration number, or other similar number issued on a government document used to verify identity.</text> </clause>
<clause id="H4019B82BF5AA4909BBDEFF2130124BD6"><enum>(iii)</enum><text>Unique account identifier, including a financial account number, or credit or debit card number, electronic identification number, user name, or routing code.</text> </clause> <clause id="HCAD6917109F947F0862AEF760C454499"><enum>(iv)</enum><text>Partial or complete Social Security number.</text> </clause>
<clause id="H3E6641E007A74467A2BD4C7FE3BB251E"><enum>(v)</enum><text>Unique biometric or genetic data such as a fingerprint, voice print, a retina or iris image, or any other unique physical representations.</text> </clause> <clause id="H21B25C81E3714D508B31775DFAA0A994"><enum>(vi)</enum><text>Information that could be used to access an individual’s account, such as user name and password or e-mail address and password.</text> </clause>
<clause id="H97613B7FA23B4B4E991497E73656E155"><enum>(vii)</enum><text>Any two or more of the following data elements:</text> <subclause id="HB6ED9BF20FAE42D49C8047BB2B1C4E36"><enum>(I)</enum><text>An individual’s first and last name or first initial and last name.</text> </subclause>
<subclause id="H3FE6D04FE82144339596CBCE961C4F51"><enum>(II)</enum><text>A unique account identifier, including a financial account number or credit or debit card number, electronic identification number, user name, or routing code.</text> </subclause> <subclause id="H9A6DEA11C3A44EFBBD70C16F57E07E42"><enum>(III)</enum><text>Any security code, access code, or password, or source code that could be used to generate such codes or passwords.</text> </subclause></clause>
<clause id="HFF49541F40204979A79FC4374DCDF815"><enum>(viii)</enum><text>Information generated or derived from the operation or use of an electronic communications device that is sufficient to identify the street name and name of the city or town in which the device is located.</text> </clause> <clause id="H08AA1BBC401D42CFB1DA50C081483A94"><enum>(ix)</enum><text>Any information regarding an individual’s medical history, mental or physical condition, medical treatment or diagnosis by a health care professional, or the provision of health care to the individual, including health information provided to a website or mobile application.</text> </clause>
<clause id="HED545A078D714B799AD8E4ACA45099CF"><enum>(x)</enum><text>A health insurance policy number or subscriber identification number and any unique identifier used by a health insurer to identify the individual, or any information in an individual’s health insurance application and claims history, including any appeals records.</text> </clause> <clause id="H0611F947957A4FF0A80B3693B432C69F"><enum>(xi)</enum><text>Digitized or other electronic signature.</text> </clause>
<clause id="H0EFD1CAED82F42CA9145428B6BADD90F"><enum>(xii)</enum><text>Nonpublic communications or other user-created content such as emails, photographs, or videos.</text> </clause> <clause id="H18AB9F63AAEB4A0990C3ED092DB14999"><enum>(xiii)</enum><text>Any record or information concerning payroll, income, financial accounts, mortgages, loans, lines of credit, utility bills, accumulated purchases, or any other information regarding financial assets, obligations, or spending habits.</text> </clause>
<clause id="H6DBB5D12AD33486C91BD07E30C3B5E2B"><enum>(xiv)</enum><text>Any additional element the Commission defines as personal information.</text> </clause></subparagraph> <subparagraph id="HBEC2AB5428C64E1DA52C2F6D750A5185"><enum>(B)</enum><header>Modified definition by rulemaking</header><text>The Commission may, by rule promulgated under section 553 of title 5, United States Code, modify the definition of <quote>personal information</quote> under subparagraph (A).</text> </subparagraph></paragraph>
<paragraph id="H7F4DD93BCB9748D29F18446DB3C86B9D"><enum>(5)</enum><header>State</header><text>The term <term>State</term> means each of the several States, the District of Columbia, the Commonwealth of Puerto Rico, Guam, American Samoa, the United States Virgin Islands, the Commonwealth of the Northern Mariana Islands, any other territory or possession of the United States, and each federally recognized Indian tribe.</text> </paragraph></section> <section id="HFB31FEF65204431AB7ED4507342904D7"><enum>6.</enum><header>Effect on other laws</header> <subsection id="HCCAFF70C719D4E0BB64938505F73A33B"><enum>(a)</enum><header>Effect on State data security and breach notification laws</header><text>This Act supersedes any provision of a statute or regulation of a State or political subdivision of a State, with respect to a covered entity, that expressly—</text> 
<paragraph id="H56C60570C06C4E20926F5225B7FE6740"><enum>(1)</enum><text>requires information security practices for the treatment and protection of personal information similar to any of those required under section 2; or</text> </paragraph> <paragraph id="H84E752580D854447BA8C8F5BAB0B6E81"><enum>(2)</enum><text>requires notification to individuals of a breach of security of personal information.</text> </paragraph></subsection>
<subsection id="H5D034021C0B44E7BACE8313DFE53E8DD"><enum>(b)</enum><header>Effect on other State laws</header><text>Nothing in this Act shall be construed to—</text> <paragraph id="H92C61286094F401289BA07D1D8B9FDCE"><enum>(1)</enum><text>preempt or limit any provision of any law, rule, regulation, requirement, standard, or other provision having the force and effect of law of any State, including any State consumer protection law, any State law relating to acts of fraud or deception, and any State trespass, contract, or tort law;</text> </paragraph>
<paragraph id="H122304AE74284917A8E0790FBC201E5E"><enum>(2)</enum><text>prevent or limit the attorney general of a State from exercising the powers conferred upon the attorney general by the laws of the State, including conducting investigations, administering oaths or affirmations, or compelling the attendance of witnesses or the production of documentary and other evidence; or</text> </paragraph> <paragraph id="H269BA3366F744C339F8D68FADF5C9D91"><enum>(3)</enum><text>preempt or limit any provision of any law, rule, regulation, requirement, standard, or other provision having the force and effect of law of any State with respect to any person that is not a covered entity.</text> </paragraph></subsection>
<subsection id="HFA3EAB688B84434A9D3074F8FD969198"><enum>(c)</enum><header>Preservation of authority</header> 
<paragraph id="H5811CB60F18F41F4873E4600A5441AC9"><enum>(1)</enum><header>Federal Trade Commission</header><text>Nothing in this Act may be construed in any way to limit the Commission’s authority under any other provision of law.</text> </paragraph> <paragraph id="HA01E0B15FCBF46A590F31ABD3935ECC7"><enum>(2)</enum><header>Federal Communications Commission</header><text>Nothing in this Act may be construed in any way to limit or affect the Federal Communication Commission’s authority under any other provision of law.</text> </paragraph>
<paragraph id="HCA5A89737985432D81F8F74F9E1280D9"><enum>(3)</enum><header>Consumer Financial Protection Bureau</header><text>Nothing in this Act may be construed in any way to limit or affect the Consumer Financial Protection Bureau’s authority under any other provision of law.</text> </paragraph></subsection></section> <section id="H14187A4702C64624857AC181CD56E2B7"><enum>7.</enum><header>Effective date</header><text display-inline="no-display-inline">This Act shall take effect 90 days after the date of enactment of this Act.</text> </section>
</legis-body>
</bill> 


