<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Reported-in-House" dms-id="H5F7433F7FA084C4A851B8B2504DD24ED" public-private="public" key="H" bill-type="olc"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>118 HR 1165 RH: Data Privacy Act of 2023</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2024-12-05</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">IB</distribution-code><calendar display="yes">Union Calendar No. 673</calendar><congress display="yes">118th CONGRESS</congress><session display="yes">2d Session</session><legis-num display="yes">H. R. 1165</legis-num><associated-doc role="report" display="yes">[Report No. 118&#8211;822]</associated-doc><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action display="yes"><action-date date="20230224">February 24, 2023</action-date><action-desc><sponsor name-id="M001156">Mr. McHenry</sponsor> introduced the following bill; which was referred to the <committee-name committee-id="HBA00">Committee on Financial Services</committee-name></action-desc></action><action display="yes"><action-date date="20241205">December 5, 2024</action-date><action-desc>Reported with an amendment; committed to the Committee of the Whole House on the State of the Union and ordered to be printed</action-desc><action-instruction>Strike out all after the enacting clause and insert the part printed in italic</action-instruction><action-instruction>For text of introduced bill, see copy of bill as introduced on February 24, 2023</action-instruction></action><legis-type>A BILL</legis-type><official-title display="yes">To amend the Gramm-Leach-Bliley Act to modernize the protection of the nonpublic personal information of individuals with whom financial institutions have customer or consumer relationship, and for other purposes.</official-title></form><legis-body display-enacting-clause="yes-display-enacting-clause" changed="added" style="OLC" committee-id="HBA00" reported-display-style="italic" id="HCC0F6F1B5CAD432C9A4EC95C73E65FFE">
<section id="H3A889B5B09FF4D2EA393A965870F431C" section-type="section-one"><enum>1.</enum><header>Short title; table of contents</header>
<subsection id="H5EEE00DF34BC48EDBFB9569747C37E43"><enum>(a)</enum><header>Short title</header><text display-inline="yes-display-inline">This Act may be cited as the <quote><short-title>Data Privacy Act of 2023</short-title></quote>.</text></subsection> <subsection id="HFE69A1A5F8FE4B529E4D00FE7AEA40B5"><enum>(b)</enum><header>Table of contents</header><text>The table of contents for this Act is as follows:</text>
<toc container-level="legis-body-container" quoted-block="no-quoted-block" lowest-level="section" regeneration="yes-regeneration" lowest-bolded-level="division-lowest-bolded">
<toc-entry idref="H3A889B5B09FF4D2EA393A965870F431C" level="section">Sec. 1. Short title; table of contents.</toc-entry>
<toc-entry idref="H60AF55F1222643E588F8D1CF27CED6C3" level="section">Sec. 2. Protection of nonpublic personal information.</toc-entry>
<toc-entry idref="H16DB8481B6F94D22887BB43D7FBD98AD" level="section">Sec. 3. Obligations with respect to the collection and disclosure of nonpublic personal information.</toc-entry>
<toc-entry idref="H7EAB2DD078674D88A8FDBDBC8D16A127" level="section">Sec. 4. Disclosure of institution privacy policy.</toc-entry>
<toc-entry idref="HDBB153FB7A0847269BBC6DAEE90941C9" level="section">Sec. 5. Rulemaking.</toc-entry>
<toc-entry idref="HF471F090AA2D42349495C9661B769558" level="section">Sec. 6. Relation to State laws.</toc-entry>
<toc-entry idref="H81A7C75E6D9D4ABE87387200905ADEFC" level="section">Sec. 7. Obligations with respect to access and deletion of nonpublic personal information.</toc-entry>
<toc-entry idref="HB8ECC83E923748EA82BF4761907C208E" level="section">Sec. 8. Obligations with respect to the international sharing of nonpublic personal information.</toc-entry>
<toc-entry idref="HCA789F4BF52F4FC3AB58B91E33FF284D" level="section">Sec. 9. Definitions.</toc-entry>
<toc-entry idref="H4BECD4AD2B7B49DBA29396F276F7327A" level="section">Sec. 10. Repeal of expired provisions.</toc-entry>
<toc-entry idref="H347FDB33AB164803AF795774C13F86E3" level="section">Sec. 11. GAO Report.</toc-entry>
<toc-entry idref="H737B7F6BC20B4220BB3CCB4086BD2AAD" level="section">Sec. 12. Sense of Congress.</toc-entry>
<toc-entry idref="HC15C9EA2616C401F937020AF1BF0B55E" level="section">Sec. 13. Effective date.</toc-entry></toc></subsection></section>
<section id="H60AF55F1222643E588F8D1CF27CED6C3"><enum>2.</enum><header>Protection of nonpublic personal information</header><text display-inline="no-display-inline">Section 501 of the Gramm-Leach-Bliley Act (<external-xref legal-doc="usc" parsable-cite="usc/15/6801">15 U.S.C. 6801</external-xref>) is amended—</text> <paragraph id="HBBEFF4BD654940D6BA717F58AA884642" display-inline="no-display-inline"><enum>(1)</enum><text>in subsection (a)—</text>
<subparagraph id="H4CB13DE099304288AB9A070FE979FFBF"><enum>(A)</enum><text>by striking <quote>of its customers</quote> and inserting <quote>of individuals with whom such financial institution has a customer or consumer relationship</quote>; and</text></subparagraph> <subparagraph id="H0CAA6942877F4D4CBC534363C8B405A5"><enum>(B)</enum><text>by striking <quote>those customers' nonpublic personal information</quote> and inserting <quote>those individual’s nonpublic personal information</quote>; and</text></subparagraph></paragraph>
<paragraph id="H735D41763F0D4360BABB7227AA536377"><enum>(2)</enum><text display-inline="yes-display-inline">by adding at the end the following:</text> <quoted-block style="OLC" id="H8213AEB8EFF74A88BD678E551EF41FF7" display-inline="no-display-inline"> <subsection id="HA4734D368DFB4A81A2FC6015D867CC44"><enum>(c)</enum><header>Use of nonpublic personal information</header><text display-inline="yes-display-inline">Unless otherwise permitted under section 502(e), it shall be unlawful for a financial institution to willfully use nonpublic personal information without the consent of an individual with whom the financial institution has a customer or consumer relationship.</text></subsection><after-quoted-block>.</after-quoted-block></quoted-block></paragraph></section>
<section id="H16DB8481B6F94D22887BB43D7FBD98AD"><enum>3.</enum><header>Obligations with respect to the collection and disclosure of nonpublic personal information</header>
<subsection id="HA717BF7781964517857E77416023E0A8"><enum>(a)</enum><header>In general</header><text display-inline="yes-display-inline">Section 502 of the Gramm-Leach-Bliley Act (<external-xref legal-doc="usc" parsable-cite="usc/15/6802">15 U.S.C. 6802</external-xref>) is amended—</text> <paragraph id="H9D0DE084A1D741FAB2921FA2CB88F9C9"><enum>(1)</enum><text>in the heading, by striking <quote><header-in-text level="section" style="OLC">DISCLOSURES OF</header-in-text></quote> and inserting <quote><header-in-text level="section" style="OLC">THE COLLECTION AND DISCLOSURE OF NONPUBLIC</header-in-text></quote>;</text></paragraph>
<paragraph id="H2113C8D4CAC14EDFAB99F37192BDE0C9"><enum>(2)</enum><text>in subsection (a)—</text> <subparagraph id="H766DE725A8B24BAB9555D5CA53A7BE64"><enum>(A)</enum><text>by inserting before <quote>disclose</quote> the following: <quote>collect nonpublic personal information from an individual with whom such financial institution has a customer or consumer relationship or</quote>; and</text></subparagraph>
<subparagraph id="HAD00C2B1A1304F39A59A54D3D447FC38" commented="no"><enum>(B)</enum><text>by striking <quote>has provided to the consumer</quote> and inserting <quote>has provided to such individual</quote>; and </text></subparagraph></paragraph> <paragraph id="HCB452A9DCE5F4C64A15CBAC69ED2874F"><enum>(3)</enum><text>in subsection (b), by amending paragraph (1) to read as follows:</text>
<quoted-block style="OLC" id="H1D2E1F38645B46BBB88D1596042B6820" display-inline="no-display-inline">
<paragraph id="H9DFD3ED95D104590BAD5B95D8B5A37C2"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">A financial institution may not collect nonpublic personal information from an individual with whom such financial institution has a customer or consumer relationship or disclose nonpublic personal information to a nonaffiliated third party unless the individual with whom such financial institution has a consumer or customer relationship is given the opportunity, before the time that such information is initially collected or disclosed, to direct that such information not be collected or disclosed to such third party.</text></paragraph><after-quoted-block>;</after-quoted-block></quoted-block></paragraph> <paragraph id="H6BFF14D1354744E998578058E8056643"><enum>(4)</enum><text>in subsection (d)—</text>
<subparagraph id="H97FDF74471E24C399987BEBC4EE4D13C"><enum>(A)</enum><text>by striking <quote>of a consumer</quote> and inserting <quote>of an individual with whom such financial institution has a customer or consumer relationship</quote>; and </text></subparagraph> <subparagraph id="H392FD740D1C84D41BBD933D43209165F"><enum>(B)</enum><text>by striking <quote>telemarketing, direct mail marketing, or other marketing through electronic mail to the consumer</quote> and inserting <quote>marketing to the individual with whom such financial institution has a customer or consumer relationship, regardless of medium</quote>;</text></subparagraph></paragraph>
<paragraph id="H80E61D6C6CD947488F9E9814854DBF4D"><enum>(5)</enum><text>in subsection (e)—</text> <subparagraph id="HCC40C00460BD461C9E768611D4B7B95F"><enum>(A)</enum><text>in the heading, by striking <quote><header-in-text level="subsection" style="OLC">General</header-in-text></quote>;</text></subparagraph>
<subparagraph id="H73C8539067CC4E1D8F256073AB895F7A"><enum>(B)</enum><text>by striking <quote>Subsections (a) and (b) shall not prohibit the disclosure of nonpublic personal information</quote> and inserting <quote>The general collection and disclosure procedures provided in subsections (a) and (b) shall not prohibit or otherwise limit the collection or disclosure of nonpublic personal information</quote>;</text></subparagraph> <subparagraph id="HC32EC4FC64204465A5875E44A82D1598"><enum>(C)</enum><text>by striking paragraphs (1) and (2) and inserting the following:</text>
<quoted-block style="OLC" id="H1FE7CE435ECE4DDAB0FD1C55A4818227" display-inline="no-display-inline">
<paragraph id="H98EE333A513E4DE38D1EB82168DBCF62" commented="no"><enum>(1)</enum><text>if the collection or disclosure is—</text> <subparagraph id="H37EB810C18F5467A9C241650AEBAE08C" commented="no"><enum>(A)</enum><text display-inline="yes-display-inline">necessary to effect, administer, or enforce a transaction requested or authorized by the individual with whom the financial institution has a customer or consumer relationship;</text></subparagraph>
<subparagraph id="HD16741F7B26642ADA3FB82A522C2CB34"><enum>(B)</enum><text display-inline="yes-display-inline">in connection with servicing or processing a financial product or service requested or authorized by the individual with whom the financial institution has a customer or consumer relationship;</text></subparagraph> <subparagraph id="HC2FA99E20509498BA1999A534724F2B0"><enum>(C)</enum><text display-inline="yes-display-inline">with the consent or at the direction of the individual with whom the financial institution has a customer or consumer relationship, and the financial institution obtains, from such individual, evidence of such individual’s authorization for such collection or disclosure; or</text></subparagraph>
<subparagraph id="H01F1110C843C4708832EACC55733B200" commented="no"><enum>(D)</enum><text display-inline="yes-display-inline">in connection with—</text> <clause id="HDAC91739FA5F40FBB2E22C5333FD35B3" display-inline="no-display-inline"><enum>(i)</enum><text display-inline="yes-display-inline">maintaining or servicing the account, with such financial institution or with another entity as part of a private label or co-brand credit card program or an extension of credit on behalf of such entity, of an individual with whom such financial institution or entity has a customer or consumer relationship; or</text></clause>
<clause id="H1A9AB70D98264C158C8A91A99935B06A"><enum>(ii)</enum><text>a proposed or actual securitization, secondary market sale (including sales of servicing rights), or similar transaction related to an account or a transaction of the individual which whom such entity or financial institution has a customer or consumer relationship; or </text></clause></subparagraph></paragraph> <paragraph id="HDF68D703ECBB4DBAB7F8BED0B0979EF9"><enum>(2)</enum><text display-inline="yes-display-inline">to a nonaffiliated third party to perform services for, or functions on behalf of, the financial institution, including marketing of the financial institution's own products or services, or financial products or services offered pursuant to joint agreements between two or more financial institutions that comply with the requirements imposed by the regulations prescribed under section 504, if the financial institution fully discloses the providing of such information and enters into a contractual agreement with the third party that requires the third party to maintain the confidentiality of such information;</text></paragraph><after-quoted-block>;</after-quoted-block></quoted-block></subparagraph>
<subparagraph id="H9D06B86BFDA140C9BB067410DE7D99E1"><enum>(D)</enum><text>in paragraph (3)—</text> <clause id="HFF208969DE9D467F8E7CA79903FD972E"><enum>(i)</enum><text>in subparagraph (A)—</text>
<subclause id="H0097F014381A47CB9ED3CBB49F7463BD"><enum>(I)</enum><text>by striking <quote>or security </quote> and inserting <quote>, security, or integrity</quote>;</text></subclause> <subclause id="HA2415CBD6A95491780630C8505B1417F" commented="no"><enum>(II)</enum><text>by striking <quote>pertaining to the consumer</quote> and inserting <quote>pertaining to the individual with whom the financial institution has a customer or consumer relationship</quote>;</text></subclause>
<subclause id="HA70BFE62BFF14157A08B4E365DD85ADA"><enum>(III)</enum><text>by inserting before the semicolon the following: <quote>, as well as the systems, processes, and services that handle such records</quote>; </text></subclause></clause> <clause id="H0CB83F4D3A09436BBF3592D953698411"><enum>(ii)</enum><text>in subparagraph (B), by inserting after <quote>fraud,</quote> the following: <quote>identity theft,</quote>;</text></clause>
<clause id="HD6BAF74E098B4761ABF641D49950F30F" commented="no"><enum>(iii)</enum><text>in subparagraph (C), by striking <quote>for resolving customer disputes or inquiries</quote> and inserting <quote>for resolving disputes or inquires relating to individuals with whom the financial institution has a customer or consumer relationship</quote>;</text></clause> <clause id="H434DD8E7EC0E42D4A79744A0286DAA36" commented="no"><enum>(iv)</enum><text>in subparagraph (D), by striking <quote>relating to the consumer</quote> and inserting <quote>relating to the individual with whom the financial institution has a customer or consumer relationship</quote>; and</text></clause>
<clause id="H33D55F86192249EF86074E217C0E28E2" commented="no"><enum>(v)</enum><text>in subparagraph (E), by striking <quote>behalf of the consumer</quote> and inserting <quote>behalf of the individual with whom the financial institution has a customer or consumer relationship</quote>; and</text></clause></subparagraph> <subparagraph id="H99B75B8D82994A4DB8E820C85D09677D"><enum>(E)</enum><text>in paragraph (7)—</text>
<clause id="HDE7258C345C34834BB51FCF852AD2293"><enum>(i)</enum><text>by striking <quote>or exchange</quote> and inserting <quote>exchange, or similar transaction</quote>;</text></clause> <clause id="H6A530DEAA3A0486E8EA609DF1F184F8A" commented="no"><enum>(ii)</enum><text>by striking <quote>consumers of such business or unit</quote> and inserting <quote>individuals with whom such business or unit have a customer or consumer relationship</quote>; and</text></clause>
<clause id="H38145AEEC7D94AA4BE0D4C57316F1185"><enum>(iii)</enum><text>by inserting <quote>collection or</quote> before <quote>disclosure</quote>; </text></clause></subparagraph></paragraph> <paragraph id="H612D2E8D13474E9CBE94BB1F49BF7149" commented="no"><enum>(6)</enum><text>by adding at the end the following:</text>
<quoted-block style="OLC" id="H7873D470CF7A41F6A2D3F53FCCEDED42" display-inline="no-display-inline">
<subsection id="H79CFA025559149FABEE43C1C190AD48E" commented="no"><enum>(f)</enum><header>Notification to nonaffiliates when sharing is terminated</header>
<paragraph id="HBA373ACD17EE43D4906B3BCADB976E95" commented="no"><enum>(1)</enum><header>In general</header><text>If a financial institution is required to terminate sharing nonpublic personal information, of an individual with whom such financial institution has a customer or consumer relationship, with a nonaffiliated third party—</text> <subparagraph id="H0C7C5736F4664D5EA5AC54718B9DA767" commented="no"><enum>(A)</enum><text display-inline="yes-display-inline">the financial institution shall notify the nonaffiliated third party that the sharing has been terminated and that such nonaffiliated third party may not share any nonpublic information of the individual already received from the financial institution; and</text></subparagraph>
<subparagraph id="HDB56B2F154684592AF21503241EEBC47" commented="no"><enum>(B)</enum><text display-inline="yes-display-inline">upon receipt of a notice described under subparagraph (A), the nonaffiliated third party may not share any nonpublic information of such individual already received from the financial institution.</text></subparagraph></paragraph> <paragraph id="HF3881F9DDBEB42648B954133EB75DC1E" commented="no"><enum>(2)</enum><header>Rulemaking</header><text display-inline="yes-display-inline">The agencies referred to in section 504 shall issue rules to establish the requirements for notices under paragraph (1), including the form of such notices, taking into account any privacy risks posed by such notices.</text></paragraph></subsection>
<subsection id="HB82B023C3A2541D8A452FDC20BB1B9C1" commented="no"><enum>(g)</enum><header>Requirements with respect to the collection of account credentials</header><text display-inline="yes-display-inline">A financial institution may not collect from an individual with whom such financial institution has a customer or consumer relationship account credentials such individual uses to access an account at a nonaffiliated third party that is a financial institution unless, prior to collecting the account credentials—</text> <paragraph id="H51745DA53B3D4533828DEE43673BB603" commented="no"><enum>(1)</enum><text display-inline="yes-display-inline">the financial institution clearly and conspicuously discloses to the individual, in a form permitted by the regulations prescribed under section 504—</text>
<subparagraph id="H325935EFA9544FA485E92C6FA38A66B2"><enum>(A)</enum><text>that the financial institution is collecting such account credentials;</text></subparagraph> <subparagraph id="H9A2A8A3A093D45DB91DD4D422D1E2A1F"><enum>(B)</enum><text>how such credentials will be used by the financial institution; and</text></subparagraph>
<subparagraph id="H6E42B4B81D0541EB8FC265E8044C286C"><enum>(C)</enum><text>whether such credentials may be disclosed to a nonaffiliated third party; and</text></subparagraph></paragraph> <paragraph id="HAFAB1D406B694EE2AC27859CFBC788D5" commented="no"><enum>(2)</enum><text display-inline="yes-display-inline">such individual is given an opportunity to direct that such credentials not be collected or to direct that such credentials not be disclosed to any nonaffiliated third party.</text></paragraph></subsection><after-quoted-block>.</after-quoted-block></quoted-block></paragraph></subsection>
<subsection id="H0B3D59E40E4B492696976C679F4495D6"><enum>(b)</enum><header>Conforming amendment</header><text display-inline="yes-display-inline">Section 509(3)(D) of the Gramm-Leach-Bliley Act (<external-xref legal-doc="usc" parsable-cite="usc/15/6809">15 U.S.C. 6809(3)(D)</external-xref>) is amended by striking <quote>section 502(e)(1)(C)</quote> and inserting <quote>section 502(e)(1)(D)(ii)</quote>.</text></subsection></section> <section id="H7EAB2DD078674D88A8FDBDBC8D16A127"><enum>4.</enum><header>Disclosure of institution privacy policy</header><text display-inline="no-display-inline">Section 503 of the Gramm-Leach-Bliley Act (<external-xref legal-doc="usc" parsable-cite="usc/15/6803">15 U.S.C. 6803</external-xref>) is amended—</text>
<paragraph id="HC420DADD46B84816B903573FFEFC38C8"><enum>(1)</enum><text>in subsection (a)—</text> <subparagraph id="H1A440CFD7AC84AABAB3B7994BFE10BB5"><enum>(A)</enum><text>by striking <quote>customer relationship with a consumer</quote> and inserting <quote>customer or consumer relationship</quote>;</text></subparagraph>
<subparagraph id="H24DB76BCD54E4A7687854D742EF1B0BF"><enum>(B)</enum><text display-inline="yes-display-inline">by striking <quote>clear and conspicuous disclosure to such consumer</quote> and inserting <quote>clear and conspicuous disclosure to such individual with whom such financial institution has a customer or consumer relationship</quote>;</text></subparagraph> <subparagraph id="HEB0E30351D1A4074A31AEA813BCAB83E" commented="no"><enum>(C)</enum><text>by redesignating paragraphs (1), (2), and (3) as paragraphs (2), (3), and (4), respectively; </text></subparagraph>
<subparagraph id="HD9B8BA1FA45543B8B3550239C8F4B3EB"><enum>(D)</enum><text>by inserting before paragraph (2), as so redesignated, the following:</text> <quoted-block style="OLC" id="H7D62436AA9C740E69F6D18D27BBE34F1" display-inline="no-display-inline"> <paragraph id="H9F6BE6ECD9044BDAAF8EFA233406AE82" commented="no"><enum>(1)</enum><text display-inline="yes-display-inline">collecting nonpublic personal information;</text></paragraph><after-quoted-block>;</after-quoted-block></quoted-block></subparagraph>
<subparagraph id="H13C56A3DD8244CB49EF1FB0D407AEBB2" commented="no"><enum>(E)</enum><text display-inline="yes-display-inline">in paragraph (3), as so redesignated, by striking <quote>have ceased to be customers of</quote> and inserting <quote>have ceased to have a customer or consumer relationship with</quote>; and</text></subparagraph> <subparagraph id="HEBA9BC039C014979A9ED7C18601B7B41" commented="no"><enum>(F)</enum><text display-inline="yes-display-inline">in paragraph (4), as so redesignated, by striking <quote>personal information of consumers</quote> and inserting <quote>personal information of individuals with whom such financial institution has a customer or consumer relationship</quote>; </text></subparagraph></paragraph>
<paragraph id="H5483E9A5D5E04476A720CD680512A169"><enum>(2)</enum><text>by redesignating subsections (b) through (f) as subsections (c) through (g), respectively;</text></paragraph> <paragraph id="H5D30AA879AC64017A60A6BF59A991BFA"><enum>(3)</enum><text>by inserting after subsection (a) the following:</text>
<quoted-block style="OLC" id="H7BDDA065FF794CB488BBC012BD06EF7F" display-inline="no-display-inline">
<subsection id="HBDA8EA4719C04B7FAA88673AA90503EA"><enum>(b)</enum><header>Disclosure upon request</header><text display-inline="yes-display-inline">Upon the request of an individual with whom a financial institution has a customer or consumer relationship, a financial institution shall provide such individual with a copy of the disclosures required by subsection (a) in writing or in electronic or other form as permitted by the regulations prescribed under section 504.</text></subsection><after-quoted-block>; and</after-quoted-block></quoted-block></paragraph> <paragraph id="H5D8A47779C2E42C7826157B85E159864"><enum>(4)</enum><text>in subsection (d), as so redesignated—</text>
<subparagraph id="H72514EAE0E3346C080C37E691BC9431D"><enum>(A)</enum><text>in paragraph (1)—</text> <clause id="H291B1CAB521242F8A48ADC35E324BB40"><enum>(i)</enum><text>by inserting <quote>collecting or</quote> before <quote>disclosing nonpublic</quote>; and</text></clause>
<clause id="HB4067FE587274D9B9992DC08E3ECCE4D"><enum>(ii)</enum><text>by striking subparagraph (B) and inserting the following:</text> <quoted-block style="OLC" id="HBA53A408A164414CB25EAD6CE806A6A8" display-inline="no-display-inline"> <subparagraph id="H73A79820427F44CFB706F29583194510"><enum>(B)</enum><text display-inline="yes-display-inline">the purpose for which the financial institution collects the nonpublic personal information of individuals with whom the financial institution has a customer or consumer relationship, as well as how the information will be used;</text></subparagraph><after-quoted-block>;</after-quoted-block></quoted-block></clause></subparagraph>
<subparagraph id="H95E499DDF82E48AE847BBC85A635E3BF"><enum>(B)</enum><text>in paragraph (2), by inserting before the semicolon the following: <quote>, provided in a manner that provides individuals with whom the financial institution has a customer or consumer relationship a meaningful understanding of the information that is collected</quote>; </text></subparagraph> <subparagraph id="H7414CC43C46344FF8311C1F12C63894D"><enum>(C)</enum><text>in paragraph (3), by striking <quote>and</quote> at the end;</text></subparagraph>
<subparagraph id="HF4876863A7784F7FB6C4221DD6C6DCA4"><enum>(D)</enum><text>in paragraph (4), by striking the period at the end and inserting a semicolon; and</text></subparagraph> <subparagraph id="H4DE08DADA5ED4A0FAF2AD0DE75AA00B9"><enum>(E)</enum><text>by adding at the end the following:</text>
<quoted-block style="OLC" id="H0DC2BD373399432EAC2094CF08613526" display-inline="no-display-inline">
<paragraph id="H813486779D994D748E4B9BBD4F02606A" commented="no"><enum>(5)</enum><text display-inline="yes-display-inline">if the financial institution collects nonpublic personal information for any purpose other than to provide a specific product or service such an individual is seeking—</text> <subparagraph id="H4C892CBCD69045D88CAFAE9CC15D4C5B" commented="no"><enum>(A)</enum><text>a description of such information;</text></subparagraph>
<subparagraph id="HE8A6B60E3C9744EEB8BFA31F13CEEAB0" commented="no"><enum>(B)</enum><text>the purpose for which such information is collected; and</text></subparagraph> <subparagraph id="HEDAEDF2B0A904BA79FF18D7D7BA85AD2" commented="no"><enum>(C)</enum><text display-inline="yes-display-inline">the right of such individual to opt out of having such nonpublic personal information collected or disclosed to a nonaffiliated third party, and the manner in which such individual may make such opt out election;</text></subparagraph></paragraph>
<paragraph id="H24F79CD531C6480EBE1045205971B5DC" commented="no"><enum>(6)</enum><text display-inline="yes-display-inline">the data retention policies of the financial institution, including—</text> <subparagraph id="H0C093FB6BB044523B40440809AF733CB"><enum>(A)</enum><text>the period of time for which the financial institution retains the nonpublic personal information relating to such individual; or</text></subparagraph>
<subparagraph id="H42497C3AA60E494AB7E568F571E997D8"><enum>(B)</enum><text>the criteria used by the financial institution to determine the period of time for which such information is retained;</text></subparagraph></paragraph> <paragraph id="H861E84B39F5845CCB48733739DA6275D" commented="no"><enum>(7)</enum><text display-inline="yes-display-inline">the right of such individual to direct the financial institution to terminate the sharing of nonpublic personal information with a nonaffiliated third party, and the manner in which such individual may make such direction;</text></paragraph>
<paragraph id="H6A0A7F46FD564F2EAF255E39D1414DA2" commented="no"><enum>(8)</enum><text display-inline="yes-display-inline">the right of such individual to request that the financial institution provide the individual with a list of all nonpublic personal information relating to the individual held by the financial institution, and the manner in which the individual may make such request; and</text></paragraph> <paragraph id="H8A2A8436A172422D9F4B139863BA6348" commented="no"><enum>(9)</enum><text display-inline="yes-display-inline">the right of such individual to direct the financial institution to delete nonpublic personal information of the individual held by the financial institution (subject to the exceptions provided under section 502A(b)(3)), and the manner in which the individual may make such direction.</text></paragraph><after-quoted-block>; </after-quoted-block></quoted-block></subparagraph></paragraph>
<paragraph id="HFF83575C9EE84B489894565DF58FD031" commented="no"><enum>(5)</enum><text>in subsection (f), as so redesignated—</text> <subparagraph id="H32879AEAAD68414FB213355881558001" commented="no"><enum>(A)</enum><text>in paragraph (2)(A), by striking <quote>to consumers</quote> and inserting <quote>to individuals with whom a financial institution has a customer or consumer relationship</quote>; and </text></subparagraph>
<subparagraph id="H24A4D1EDBF914CC1839CF66161564ACB" commented="no"><enum>(B)</enum><text>in paragraph (2)(C), by striking <quote>enable consumers</quote> and inserting <quote>enable individuals with whom a financial institution has a customer or consumer relationship</quote>; and</text></subparagraph></paragraph> <paragraph id="H394EC642240D41539DB18AAFC3ACFCBA" commented="no"><enum>(6)</enum><text>in subsection (g), as so redesignated, by striking <quote>sent to consumers</quote> and inserting <quote>sent to individuals with whom a financial institution has a customer or consumer relationship</quote>. </text></paragraph></section>
<section id="HDBB153FB7A0847269BBC6DAEE90941C9"><enum>5.</enum><header>Rulemaking</header><text display-inline="no-display-inline">Section 504 of the Gramm-Leach-Bliley Act (<external-xref legal-doc="usc" parsable-cite="usc/15/6804">15 U.S.C. 6804</external-xref>) is amended—</text> <paragraph id="H998EDCA6607B49AAB77B6575CBF36137"><enum>(1)</enum><text>in subsection (a)(1)—</text>
<subparagraph id="HC832714EF2364A30BA42F95996811A31"><enum>(A)</enum><text>by striking subparagraph (D) and inserting the following:</text> <quoted-block style="OLC" id="H6A22B4EF81D6493FBE62552330380BA8" display-inline="no-display-inline"> <subparagraph id="H088E601BDADA4124BA6F5754E10A25B8"><enum>(D)</enum><header>Insurance</header> <clause id="H3C918F1FF52844C6A838A3DC2CA56889"><enum>(i)</enum><header>In general</header><text display-inline="yes-display-inline">With respect to any person engaged in providing insurance, the applicable State insurance authority of the State in which the person is domiciled shall issue regulations as may be necessary to carry out the purposes of this subtitle, subject to section 505(c).</text></clause>
<clause id="H36B5CAFD528C451AB8E5471C8E358726"><enum>(ii)</enum><header>Limitation</header><text>Regulations issued by a State insurance authority under this subparagraph may be no more restrictive for a person engaged in providing insurance than those regulations issued by the agencies coordinating for consistency and comparability under paragraph (2).</text></clause></subparagraph><after-quoted-block>; and</after-quoted-block></quoted-block></subparagraph></paragraph> <paragraph id="HA276B224DAE948DB99A5A86CE35BFA91"><enum>(2)</enum><text>by adding at the end the following:</text>
<quoted-block style="OLC" id="H3143EB0DA251459DA14B7942BB2CB216" display-inline="no-display-inline">
<subsection id="H8ECB22E9B77B460495030E6EE80A00A0"><enum>(c)</enum><header>Consideration of compliance costs</header><text display-inline="yes-display-inline">When prescribing rules under this subtitle, agencies shall take into account the compliance cost such rules will impose on small institutions.</text></subsection><after-quoted-block>.</after-quoted-block></quoted-block></paragraph></section> <section id="HF471F090AA2D42349495C9661B769558"><enum>6.</enum><header>Relation to State laws</header><text display-inline="no-display-inline">Section 507 of the Gramm-Leach-Bliley Act (<external-xref legal-doc="usc" parsable-cite="usc/15/6807">15 U.S.C. 6807</external-xref>) is amended to read as follows:</text>
<quoted-block style="OLC" id="H3C0D56CFA2C2454385BDC9F837860C5A" display-inline="no-display-inline">
<section id="H8C84459A770F4E888814663AFCA47954"><enum>507.</enum><header>Relation to State laws</header><text display-inline="no-display-inline">This subtitle and the amendments made by this subtitle supersede any statute or rule of a State or political subdivision thereof that regulates the obligations of a financial institution with respect to—</text> <paragraph id="H4448F035E481431BA6750F7C5130A424"><enum>(1)</enum><text>the collection or disclosure of personal information;</text></paragraph>
<paragraph id="H443D1EE1B88448518621F68150CD1316"><enum>(2)</enum><text display-inline="yes-display-inline">the disclosure of the financial institution’s privacy policy or information about the financial institution’s privacy policies and practices;</text></paragraph> <paragraph id="H643A2BDCEF13483F9DF79840255A7E1E"><enum>(3)</enum><text display-inline="yes-display-inline">the access to, deletion of, or other individual privacy rights with respect to personal information; or</text></paragraph>
<paragraph id="H1EE87A2E9AC949AAA73536DFC7902F14"><enum>(4)</enum><text display-inline="yes-display-inline">the international sharing of personal information.</text></paragraph></section><after-quoted-block>.</after-quoted-block></quoted-block></section> <section id="H81A7C75E6D9D4ABE87387200905ADEFC"><enum>7.</enum><header>Obligations with respect to access and deletion of nonpublic personal information</header> <subsection id="H41F306B82A0348908D0E41B56ACF6483"><enum>(a)</enum><header>In general</header><text display-inline="yes-display-inline">Title V of the Gramm-Leach-Bliley Act (<external-xref legal-doc="usc" parsable-cite="usc/15/6801">15 U.S.C. 6801 et seq.</external-xref>) is amended by inserting after section 502 the following:</text>
<quoted-block style="OLC" id="HC5239CB64ACF47AC9B1322F87E690727" display-inline="no-display-inline">
<section id="HA02D577E39BB4F93882DAA0C490444BE"><enum>502A.</enum><header>Obligations with respect to access and deletion of nonpublic personal information</header>
<subsection id="H985FFE87B5414BA49393F3F432197089"><enum>(a)</enum><header>Access to information</header>
<paragraph id="HC2740664D501487782E042C9CA2A84E0"><enum>(1)</enum><header>In general</header><text>Upon an authorized request from an individual with whom a financial institution has a customer or consumer relationship, a financial institution shall disclose—</text> <subparagraph id="HF3C2EA246964477996F7976A359FBC3B"><enum>(A)</enum><text>any nonpublic personal information relating to such individual held by the financial institution;</text></subparagraph>
<subparagraph id="H10BAF43283DC4E51A4D66B83038D72E1"><enum>(B)</enum><text display-inline="yes-display-inline">the list of categories of nonaffiliated third parties with whom the financial institution shares nonpublic personal information relating to such individual; and</text></subparagraph> <subparagraph id="H418A9BD5A2444930B1E70BE74BD841A5"><enum>(C)</enum><text display-inline="yes-display-inline">the list of categories of nonaffiliated third parties from whom the financial institution has received nonpublic personal information relating to such individual.</text></subparagraph></paragraph>
<paragraph id="H2F7860A36B8E45B38E847C7A2045BB88"><enum>(2)</enum><header>Format</header><text>Disclosures described under paragraph (1) shall be in a structured, commonly used, and machine-readable format.</text></paragraph> <paragraph id="H314BA27B7520405184C830160A217773"><enum>(3)</enum><header>Exception</header><text display-inline="yes-display-inline">For purposes of subparagraphs (B) and (C) of paragraph (1), a financial institution is not required to disclose a nonaffiliated third party with whom the financial institution shares or receives nonpublic personal information relating to such individual pursuant to an exception described under any of paragraphs (3) through (8) of section 502(e).</text></paragraph></subsection>
<subsection id="HD522217541704ED4AA1E0FCA02FB1097"><enum>(b)</enum><header>Deletion of information</header>
<paragraph id="H1DBBB75CA02E409E9DC6F846B94ADB25"><enum>(1)</enum><header>In general</header><text>Upon an authorized request from an individual with whom a financial institution has a customer or consumer relationship, a financial institution shall delete any nonpublic personal information relating to such individual held by the financial institution.</text></paragraph> <paragraph id="HCEBCBD0012724F08812393F4F2E461BF"><enum>(2)</enum><header>Certain inactive accounts</header><text display-inline="yes-display-inline">If such individual has not used a product or service provided by a financial institution for 1 year, the financial institution shall—</text>
<subparagraph id="H30DBA70C1CD84C6F92695012FD5EE98F"><enum>(A)</enum><text>notify such individual that such individual has the right to request the deletion of any nonpublic personal information relating to such individual held by the financial institution, and provide such individual with clear instructions on how to make such request; and</text></subparagraph> <subparagraph id="H27FA3D056AA949F2B596C12DE6B6EDFC"><enum>(B)</enum><text>for each additional 1-year period with respect to which such person continues to not use a product or service of the financial institution, resend the notice described under subparagraph (A).</text></subparagraph></paragraph>
<paragraph id="HEB1DB1E1832C409EA4CE6E65C63D9C08"><enum>(3)</enum><header>Exception</header>
<subparagraph id="H3991F52A1D294BBDAE649855958F5FB5"><enum>(A)</enum><header>In general</header><text>This subsection shall not require a financial institution to delete nonpublic personal information if—</text> <clause id="H9CE1F8E809FC4C829E8788A8CEAAA12B"><enum>(i)</enum><text>the financial institution is otherwise required by law to retain the nonpublic personal information;</text></clause>
<clause id="H78044844668E423E912C612CCEA29180"><enum>(ii)</enum><text>the nonpublic personal information may be necessary to respond to a dispute under the Fair Credit Reporting Act; or</text></clause> <clause id="H4EA569307F0F42DABB7D0906529F026B"><enum>(iii)</enum><text display-inline="yes-display-inline">the nonpublic personal information may be necessary to retain for a purpose described in an exception under section 502(e).</text></clause></subparagraph>
<subparagraph id="HEB227F9ECD81484CB1E95C92E2B4E5F3"><enum>(B)</enum><header>Limitation on retained nonpublic personal information</header><text display-inline="yes-display-inline">With respect to nonpublic personal information that a financial institution would be required to delete under this subsection but for the application of this paragraph, the financial institution may only use such nonpublic personal information for the applicable purpose described under subparagraph (A).</text></subparagraph></paragraph></subsection> <subsection id="HC7495E4F3FBC45248DB2625DF900CF04"><enum>(c)</enum><header>Timing</header><text display-inline="yes-display-inline">A financial institution that receives an authorized request, under this section, from an individual with whom such financial institution has a customer or consumer relationship, shall respond within 45 business days.</text></subsection>
<subsection id="HD2D1D89F92D24990B31D7D27EFF2DB12"><enum>(d)</enum><header>Rulemaking</header><text display-inline="yes-display-inline">Not later than the end of the 1-year period beginning on the date of enactment of this section, each agency or authority described in section 504 shall issue rules to carry out this section with respect to the financial institutions subject to its jurisdiction.</text></subsection></section><after-quoted-block>.</after-quoted-block></quoted-block></subsection> <subsection id="HB386AD69A5AD4EEEADA7E87AA6E85B1A"><enum>(b)</enum><header>Clerical amendment</header><text display-inline="yes-display-inline">The table of contents in section 1(b) of the Gramm-Leach-Bliley Act is amended by inserting after the item relating to section 502 the following:</text>
<quoted-block style="OLC" id="H948846A5D9264981B96FF6A9F927FDA1" display-inline="no-display-inline">
<toc regeneration="no-regeneration">
<toc-entry level="section">Sec. 502A. Obligations with respect to access and deletion of nonpublic personal information.</toc-entry></toc><after-quoted-block>.</after-quoted-block></quoted-block></subsection></section>
<section id="HB8ECC83E923748EA82BF4761907C208E" commented="no"><enum>8.</enum><header>Obligations with respect to the international sharing of nonpublic personal information</header>
<subsection id="HACC0431FCB384ABB9D6363FC751B186F" commented="no"><enum>(a)</enum><header>In general</header><text display-inline="yes-display-inline">Title V of the Gramm-Leach-Bliley Act (<external-xref legal-doc="usc" parsable-cite="usc/15/6801">15 U.S.C. 6801 et seq.</external-xref>), as amended by section 10, is further amended by inserting after section 502A the following:</text> <quoted-block style="OLC" id="HE879766F9DF5483A8297596F6D2C5842" display-inline="no-display-inline"> <section id="HF2AAE0860AFC4123AF5D15D3E5C78084" commented="no"><enum>502B.</enum><header>Obligations with respect to the international sharing of nonpublic personal information</header> <subsection id="H010FEEC1AABF4770B3D18538E7142F3D" commented="no"><enum>(a)</enum><header>In general</header><text display-inline="yes-display-inline">A financial institution may not share with a foreign government nonpublic personal information relating to an individual with whom such financial institution has a customer or consumer relationship.</text></subsection>
<subsection id="H65387019A6F84E2090501303112AB089" commented="no"><enum>(b)</enum><header>Law enforcement exception</header><text display-inline="yes-display-inline">Subsection (a) shall not apply to the sharing of the nonpublic personal information relating to such an individual with a foreign government authority if such sharing is—</text> <paragraph id="H460A294435A84AB6AD7C9E0187D2CFAF" commented="no"><enum>(1)</enum><text>done for legitimate law enforcement purposes; or</text></paragraph>
<paragraph id="H08B34352FCAB4A0EBEBDF269C6EAE74F" commented="no"><enum>(2)</enum><text display-inline="yes-display-inline">to a foreign government authority having jurisdiction over the financial institution for examination, compliance, or other purposes as authorized by law.</text></paragraph></subsection></section><after-quoted-block>.</after-quoted-block></quoted-block></subsection> <subsection id="H5AB58BC570C0459A8E6AB69DE955E96F" commented="no"><enum>(b)</enum><header>Clerical amendment</header><text display-inline="yes-display-inline">The table of contents in section 1(b) of the Gramm-Leach-Bliley Act, as amended by section 10, is further amended by inserting after the item relating to section 502A the following:</text>
<quoted-block style="OLC" display-inline="no-display-inline" id="H7DCEDD5BD3884986A3EC9D5BB1782B4C">
<toc regeneration="no-regeneration">
<toc-entry level="section">Sec. 502B. Obligations with respect to the international sharing of nonpublic personal information</toc-entry></toc><after-quoted-block>.</after-quoted-block></quoted-block></subsection></section>
<section id="HCA789F4BF52F4FC3AB58B91E33FF284D"><enum>9.</enum><header>Definitions</header><text display-inline="no-display-inline">Section 509 of the Gramm-Leach-Bliley Act (<external-xref legal-doc="usc" parsable-cite="usc/15/6809">15 U.S.C. 6809</external-xref>) is amended—</text> <paragraph id="HF59AAEBBF12F48B38A8EC95AF48D6E60"><enum>(1)</enum><text>in paragraph (3)(A), by inserting before the period at the end the following: <quote>and includes a data aggregator</quote>;</text></paragraph>
<paragraph id="H3BF4A1104D6844AC9209A8831E7F53BC" commented="no"><enum>(2)</enum><text>in paragraph (4), by striking <quote>personally identifiable financial information</quote> and inserting <quote>information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual and is</quote>;</text></paragraph> <paragraph id="HED6153D03EA54DEBA1E9D3CCBEE410B6"><enum>(3)</enum><text>in paragraph (7), by inserting <quote>collection or</quote> before <quote>disclosure</quote> each place such term appears;</text></paragraph>
<paragraph id="H891D5FD0C14741998FA04265892DAE19"><enum>(4)</enum><text>by striking paragraph (9); </text></paragraph> <paragraph id="H721251AC1C56491FB5BFD9D00A07607E"><enum>(5)</enum><text>by amending paragraph (11) to read as follows:</text>
<quoted-block style="OLC" id="HB7211474977541478EE371F9FCE1BEDD" display-inline="no-display-inline">
<paragraph id="H8F46BEEFA261443A92124DC6E70DFAEC"><enum>(11)</enum><header>Customer or consumer relationship</header>
<subparagraph id="HBEEF69C4FE8447249465F2C0C403F73C"><enum>(A)</enum><header>In general</header><text>The term <quote>customer or consumer relationship</quote> means a customer relationship or a consumer relationship. </text></subparagraph> <subparagraph id="H4FAE6BE6712442A997A90BBD673D662E"><enum>(B)</enum><header>Customer relationship</header><text>The term <quote>customer relationship</quote> shall have the meaning given the term in rules issued pursuant to section 504.</text></subparagraph>
<subparagraph id="HD05525E4536A44B3BCC72AD9D5AF05A4"><enum>(C)</enum><header>Consumer Relationship</header><text display-inline="yes-display-inline">The term <quote>consumer relationship</quote> shall have the meaning given the term in rules issued pursuant to section 504 and such meaning shall—</text> <clause id="H2063AC60DB704E9AB9305E170E9F2F23"><enum>(i)</enum><text display-inline="yes-display-inline">include situations in which a financial institution obtains nonpublic information from an individual with whom the financial institution does not have a customer relationship; and</text></clause>
<clause id="HA0DEBACAB752465D8C1705DCD3CEA529"><enum>(ii)</enum><text display-inline="yes-display-inline">deem a financial institution to no longer to be in a consumer relationship with an individual at such time as the financial institution no longer collects, controls, possesses, transmits, or maintains any nonpublic personal information of such individual.</text></clause></subparagraph> <subparagraph id="HE0F9EDF0C3934EFD9DFBD9028E05BF7E" commented="no"><enum>(D)</enum><header>Treatment of certain transactions</header><text>When the terms <quote>customer relationship</quote> and <quote>consumer relationship</quote> are defined by rule, it shall be specified that the following transactions do not, by themselves, establish a consumer relationship or a consumer relationship:</text>
<clause id="H93482F04E239445CB2D35A670F721F5D" commented="no"><enum>(i)</enum><text>The use of an automated teller machine.</text></clause> <clause id="H5EFDE24EFA34445FB42253510F3F7DDE" commented="no"><enum>(ii)</enum><text>The use of a credit card or debit card to make a purchase.</text></clause>
<clause id="HE4763BB7814D404899A87C97BB84E087" commented="no"><enum>(iii)</enum><text>Such other similar transactions as the agencies determine appropriate.</text></clause></subparagraph></paragraph><after-quoted-block>; and</after-quoted-block></quoted-block></paragraph> <paragraph id="H15F3864B44C7463FA4069DD77B1A523B"><enum>(6)</enum><text>by adding at the end the following:</text>
<quoted-block style="OLC" id="H16D4A23396A04C13AA365F4236638093" display-inline="no-display-inline">
<paragraph id="H5922885079384DA1BA0E539503D32551"><enum>(12)</enum><header>Account credentials</header><text display-inline="yes-display-inline">The term <quote>account credentials</quote> means nonpublic personal information that an individual with whom a financial institution has a customer or consumer relationship uses to access an account of the individual at such financial institution, including a username, password, or an answer to a security question.</text></paragraph> <paragraph id="HE8AD551A1DFD47EC8B396F83D4E93EC5"><enum>(13)</enum><header>Data aggregator</header><text>The term <quote>data aggregator</quote>—</text>
<subparagraph id="HED5EF3A086C3450FA72E1AB8C7AB91F1"><enum>(A)</enum><text display-inline="yes-display-inline">means any person that operates a commercial business or enterprise for the business purpose of accessing, aggregating, collecting, selling, or sharing nonpublic personal information about financial accounts or transactions relating to an individual; and</text></subparagraph> <subparagraph id="HB822F782F5C24FE8BC081FF29DC9334E"><enum>(B)</enum><text>does not include—</text>
<clause id="H006FFF6E3D03402983AF642682F0B2F9"><enum>(i)</enum><text>a service provider acting at the express instruction of a financial institution that accesses, aggregates, collects, or shares nonpublic personal information about an individual with whom such financial institution has a customer or consumer relationship in accordance with paragraphs (1), (2), (3)(A), (3)(B), (3)(C), (3)(D), or (6) of section 502(e); or</text></clause> <clause id="H5D148A8BD54546F09331CF4D1F5BBB89"><enum>(ii)</enum><text>an attorney or accountant acting on behalf of an individual with whom such attorney or accountant has a customer or consumer relationship, in accordance with section 502(e)(3)(E).</text></clause></subparagraph></paragraph>
<paragraph id="H1EE59C59C931476BB9A7D0D6EA54B515"><enum>(14)</enum><header>Person engaged in providing insurance</header><text display-inline="yes-display-inline">The term <quote>person engaged in providing insurance</quote> means a person that engages in the business of insurance, as that term is defined in section 1002 of the Dodd-Frank Wall Street Reform and Consumer Protection Act (<external-xref legal-doc="usc" parsable-cite="usc/12/5481">12 U.S.C. 5481</external-xref>).</text></paragraph><after-quoted-block>.</after-quoted-block></quoted-block></paragraph></section> <section id="H4BECD4AD2B7B49DBA29396F276F7327A"><enum>10.</enum><header>Repeal of expired provisions</header><text display-inline="no-display-inline">The Gramm-Leach-Bliley Act is amended—</text>
<paragraph id="HD384025CBB7B4E6A98E082F8A04A91F3"><enum>(1)</enum><text>by striking section 508 (<external-xref legal-doc="usc" parsable-cite="usc/15/6808">15 U.S.C. 6808</external-xref>); and</text></paragraph> <paragraph id="H3E5FFA7E967D4105900067D5B5C3A1F0"><enum>(2)</enum><text display-inline="yes-display-inline">in the table of contents in section 1(b), by striking the item relating to section 508.</text></paragraph></section>
<section id="H347FDB33AB164803AF795774C13F86E3" display-inline="no-display-inline" section-type="subsequent-section"><enum>11.</enum><header>GAO report</header>
<subsection id="H679D18F9D9134A07B3579B952AEE8930"><enum>(a)</enum><header>In general</header><text display-inline="yes-display-inline">The Comptroller General of the United States shall, not later than 1 year after the date of the enactment of this Act, submit to the Congress a report that assesses—</text> <paragraph id="H1A9216B4D4D1431DBD28E16B45BF92EC"><enum>(1)</enum><text display-inline="yes-display-inline">whether the safeguard standards promulgated pursuant to section 501 of the Gramm-Leach-Bliley Act, including protecting against unauthorized disclosure, are effective in protecting individuals with whom financial institutions have a customer or consumer relationship; and </text></paragraph>
<paragraph id="HA4D63E41E7014C44A94D9FAB67B7A544"><enum>(2)</enum><text display-inline="yes-display-inline">whether the enforcement regime with respect to those standards are effective in protecting customers and consumers, and whether additional remedies are necessary.</text></paragraph></subsection> <subsection id="H3B4130C08F034161972A1C5F83EEAB9A"><enum>(b)</enum><header>Definitions</header><text display-inline="yes-display-inline">In this section, the terms <quote>customer or consumer relationship</quote> and <quote>financial institution</quote> have the meaning given those terms, respectively, under section 509 of the Gramm-Leach-Bliley Act (<external-xref legal-doc="usc" parsable-cite="usc/15/6809">15 U.S.C. 6809</external-xref>), as amended by section 9.</text></subsection></section>
<section id="H737B7F6BC20B4220BB3CCB4086BD2AAD"><enum>12.</enum><header>Sense of Congress</header><text display-inline="no-display-inline">It is the sense of the Congress that the Federal agencies implementing the Gramm-Leach-Bliley Act should implement such Act, to the extent possible, in a technology-agnostic manner so as to ensure it can adapt to different business models and technologies.</text></section> <section id="HC15C9EA2616C401F937020AF1BF0B55E"><enum>13.</enum><header>Effective date</header><text display-inline="no-display-inline">The amendments made by this Act shall take effect on the date that is the earlier of—</text>
<paragraph id="H5AEF6A328A8C42198C3B10E6AB834E9F"><enum>(1)</enum><text>the date that is one year after the date on which all rulemaking required under this Act is complete; or </text></paragraph> <paragraph id="H46862FFDCC9B41BF803FD50D3E616040"><enum>(2)</enum><text>the date that is 2 years after the date of the enactment of this Act.</text></paragraph></section>
</legis-body><endorsement display="no">
<action-date><?xm-replace_text {action-date}?></action-date>
<action-desc><?xm-replace_text {action-description}?></action-desc></endorsement></bill>

