<?xml version="1.0" encoding="UTF-8"?>
<BillSummaries>
<item congress="114" measure-type="hr" measure-number="104" measure-id="id114hr104" originChamber="HOUSE" orig-publish-date="2015-01-06" update-date="2015-01-12">
<title>Cyber Privacy Fortification Act of 2015</title>
<summary summary-id="id114hr104v00" currentChamber="HOUSE" update-date="2015-01-12">
<action-date>2015-01-06</action-date>
<action-desc>Introduced in House</action-desc>
<summary-text><![CDATA[<p><b>Cyber Privacy Fortification Act of 2015</b></p> <p>Amends the federal criminal code to provide criminal penalties for intentional failures to provide required notices of a security breach involving sensitive personally identifiable information.&nbsp; Defines "sensitive personally identifiable information" as specified electronic or digital information.</p> <p>Defines "security breach" as a compromise of the security, confidentiality, or integrity of computerized data that there is reason to believe has resulted in improper access to sensitive personally identifiable information.</p> <p>Requires a person who owns or possesses data in electronic form containing a means of identification and who has knowledge of a major security breach of the system containing such data maintained by such person to provide prompt notice to the U.S. Secret Service or the Federal Bureau of Investigation.</p> <p>Defines "major security breach" as any security breach that involves: (1) a means of identification pertaining to at least 10,000 individuals that is reasonably believed to have been acquired, (2) databases owned by the federal government, or (3) a means of identification of federal employees or contractors involved in national security matters or law enforcement.</p> <p>Authorizes the Attorney General and any state attorney general to bring civil actions and obtain injunctive relief for violations of federal laws relating to data security. </p> <p>Requires federal agencies as part of their rulemaking process to prepare and make available to the public privacy impact assessments that describe the impact of certain proposed and final agency rules on the privacy of individuals.</p> <p>Sets forth authority for agencies to waive or delay certain privacy impact assessment requirements for emergencies and national security reasons. </p> <p>Directs federal agencies to periodically review promulgated rules that have a significant privacy impact on individuals or a privacy impact on a substantial number of individuals. Requires agencies to consider whether each such rule can be amended or rescinded in a manner that minimizes any such impact while remaining in accordance with applicable statutes. </p> <p>Provides access to judicial review to individuals adversely affected or aggrieved by final agency action on any such rule.</p>]]></summary-text>
</summary>
</item>
<dublinCore xmlns:dc="http://purl.org/dc/elements/1.1/">
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
<dc:contributor>Congressional Research Service, Library of Congress</dc:contributor>
<dc:description>This file contains bill summaries for federal legislation. A bill summary describes the most significant provisions of a piece of legislation and details the effects the legislative text may have on current law and federal programs. Bill summaries are authored by the Congressional Research Service (CRS) of the Library of Congress. As stated in Public Law 91-510 (2 USC 166 (d)(6)), one of the duties of CRS is "to prepare summaries and digests of bills and resolutions of a public general nature introduced in the Senate or House of Representatives". For more information, refer to the User Guide that accompanies this file.</dc:description>
</dublinCore>
</BillSummaries>
