<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" dms-id="H5DB1BA39755C451D87A28C002794E113" public-private="public" bill-type="olc"> 
<metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>109 HR 1069 IH: Notification of Risk to Personal Data Act</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2005-03-03</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form> 
<distribution-code display="yes">I</distribution-code> 
<congress>109th CONGRESS</congress> <session>1st Session</session> 
<legis-num>H. R. 1069</legis-num> 
<current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber> 
<action> 
<action-date date="20050303">March 3, 2005</action-date> 
<action-desc><sponsor name-id="B001253">Ms. Bean</sponsor> (for herself, <cosponsor name-id="E000287">Mr. Emanuel</cosponsor>, <cosponsor name-id="G000535">Mr. Gutierrez</cosponsor>, <cosponsor name-id="S000480">Ms. Slaughter</cosponsor>, <cosponsor name-id="V000128">Mr. Van Hollen</cosponsor>, <cosponsor name-id="T000326">Mr. Towns</cosponsor>, <cosponsor name-id="M000087">Mrs. Maloney</cosponsor>, <cosponsor name-id="L000563">Mr. Lipinski</cosponsor>, <cosponsor name-id="M000404">Mr. McDermott</cosponsor>, <cosponsor name-id="S001145">Ms. Schakowsky</cosponsor>, <cosponsor name-id="B001227">Mr. Brady of Pennsylvania</cosponsor>, and <cosponsor name-id="D000191">Mr. DeFazio</cosponsor>) introduced the following bill; which was referred to the <committee-name committee-id="HIF00">Committee on Energy and Commerce</committee-name>, and in addition to the Committees on <committee-name committee-id="HGO00">Government Reform</committee-name> and <committee-name committee-id="HBA00">Financial Services</committee-name>, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned</action-desc> 
</action> 
<legis-type>A BILL</legis-type> 
<official-title>To require Federal agencies, and persons engaged in interstate commerce, in possession of electronic data containing personal information, to disclose any unauthorized acquisition of such information, to amend the Gramm-Leach-Bliley Act to require financial institutions to disclose to customers and consumer reporting agencies any unauthorized access to personal information, to amend the Fair Credit Reporting Act to require consumer reporting agencies to implement a fraud alert with respect to any consumer when the agency is notified of any such unauthorized access, and for other purposes.</official-title> 
</form> 
<legis-body id="HF7ACC3BFBC2A4DD2A00049F66BD171A7" style="OLC"> 
<section id="H5A3230935B354DE0921EFA56404415C8" section-type="section-one" display-inline="no-display-inline"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Notification of Risk to Personal Data Act</short-title></quote>.</text></section> 
<section id="H6FF16C4944144E0CBF84C01B4379B2C2"><enum>2.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act, the following definitions shall apply:</text> 
<paragraph id="HFCA6B7CC10F540478323651E0200BD79"><enum>(1)</enum><header>Agency</header><text>The term <term>agency</term> has the same meaning given such term in <external-xref legal-doc="usc" parsable-cite="usc/5/551">section 551(1)</external-xref> of title 5, United States Code.</text></paragraph> 
<paragraph id="H2430952D33E5455B8F5BE44611D9A278"><enum>(2)</enum><header>Breach of security of the system</header><text>The term <term>breach of security of the system</term>—</text> 
<subparagraph id="H57F9AA22D3C242DA877B8650F7C60763"><enum>(A)</enum><text>means the compromise of the security, confidentiality, or integrity of computerized data that results in, or there is a reasonable basis to conclude has resulted in, the unauthorized acquisition or loss of, and access to, personal information maintained by the person or business; and</text></subparagraph> 
<subparagraph id="H400B3E270B124AFF9067F16958004937"><enum>(B)</enum><text>does not include good faith acquisition of personal information by an employee or agent of the person or business for the purposes of the person or business, if the personal information is not used or subject to further unauthorized disclosure.</text></subparagraph></paragraph> 
<paragraph id="H14BF9D84F7F44C95A41859CF6C4E7844"><enum>(3)</enum><header>Person</header><text>The term <term>person</term> has the same meaning given such term in <external-xref legal-doc="usc" parsable-cite="usc/5/551">section 551(2)</external-xref> of title 5, United States Code.</text></paragraph> 
<paragraph id="HC477AF4689CD40D1890227D9A4DDC24D"><enum>(4)</enum><header>Personal information</header><text>The term <term>personal information</term> means an individual’s last name in combination with any 1 or more of the following data elements, when either the name or the data elements are not encrypted:</text> 
<subparagraph id="HB8AF7D7CAE6744EAB3F055FC9185C20"><enum>(A)</enum><text>Social security number.</text></subparagraph> 
<subparagraph id="HF532A1A96B864E749B56877BD4D4DCC9"><enum>(B)</enum><text>Driver’s license number or State identification number.</text></subparagraph> 
<subparagraph id="HBAD8EF63E26846C28CCFE2620896DE47"><enum>(C)</enum><text>Account number, credit or debit card number, in combination with any required security code, access code, or password that would permit access to an individual’s financial account.</text></subparagraph></paragraph> 
<paragraph id="H1447752BDF4A4A77BA14B0ADDDACD7FD"><enum>(5)</enum><header>Substitute notice</header><text>The term <term>substitute notice</term> means—</text> 
<subparagraph id="H4E49F29223764A68969FAEBC14E2AE10"><enum>(A)</enum><text>e-mail notice, if the agency or person has an e-mail address for the subject persons;</text></subparagraph> 
<subparagraph id="H513330FED20141FB8426AA627DE1C4AB"><enum>(B)</enum><text>conspicuous posting of the notice on the Internet site of the agency or person, if the agency or person maintains an Internet site; or</text></subparagraph> 
<subparagraph id="HEF57DA8DF0B143118B41CBB73C015BC5"><enum>(C)</enum><text>notification to major media.</text></subparagraph></paragraph></section> 
<section id="HDB157D1928A94F8CB59DABFB5CEB76"><enum>3.</enum><header>Database security for agencies and nonfinancial institutions</header> 
<subsection id="HEFCDACBAC33E4F5FB11D4CA6BF7D3D"><enum>(a)</enum><header>Disclosure of security breach</header> 
<paragraph id="H9394289CCEAC406488E4E5A38C645E8C"><enum>(1)</enum><header>In general</header><text>Any agency, or person engaged in interstate commerce, that owns or licenses electronic data containing personal information shall, following the discovery of a breach of security of the system containing such data, notify—</text> 
<subparagraph id="H2EE89E257D00423700FED9E769935D38"><enum>(A)</enum><text>any resident of the United States whose unencrypted personal information was, or is reasonably believed to have been, lost or acquired by an unauthorized person; and</text></subparagraph> 
<subparagraph id="H65DCC888BA2D43CDBAA7259BE8CF877"><enum>(B)</enum><text display-inline="yes-display-inline">each consumer reporting agency described in section 603(p) of the <act-name parsable-cite="FCRA">Fair Credit Reporting Act</act-name> of such loss or unauthorized acquisition with respect to such consumer.</text></subparagraph></paragraph> 
<paragraph id="H72F8FD206745473BBD831E6F421324BE"><enum>(2)</enum><header>Notification of owner or licensee</header><text>Any agency, or person engaged in interstate commerce, in possession of electronic data containing personal information that the agency does not own or license shall notify the owner or licensee of the information if the personal information was, or is reasonably believed to have been, acquired by an unauthorized person through a breach of security of the system containing such data.</text></paragraph> 
<paragraph id="HA74DE6F665ED46D58284E810C8715C86"><enum>(3)</enum><header>Timeliness of notification</header><text>Except as provided in paragraph (4), all notifications required under paragraph (1) or (2) shall be made as expediently as possible and without unreasonable delay following—</text> 
<subparagraph id="HC8DA27E62E6C4BEE936172317F4788AB"><enum>(A)</enum><text>the discovery by the agency or person of a breach of security of the system; and</text></subparagraph> 
<subparagraph id="H46999FEA52AC43BFB300965E2E75F053"><enum>(B)</enum><text>any measures necessary to determine the scope of the breach, prevent further disclosures, and restore the reasonable integrity of the data system.</text></subparagraph></paragraph> 
<paragraph id="H948A4BBD95AE4B848EB07BFCF00B2BD"><enum>(4)</enum><header>Delay of notification authorized for law enforcement purposes</header><text>If a law enforcement agency determines that the notification required under this subsection would impede a criminal investigation, such notification may be delayed until such law enforcement agency determines that the notification will no longer compromise such investigation.</text></paragraph> 
<paragraph id="HA6BE510490714188BC52E84D3E50EFCD"><enum>(5)</enum><header>Methods of notice</header><text>An agency, or person engaged in interstate commerce, shall be in compliance with this subsection if it provides the resident, owner, or licensee, as appropriate, with—</text> 
<subparagraph id="HCD915AA4F7E64CD8AF0060CD44D8228D"><enum>(A)</enum><text>written notification;</text></subparagraph> 
<subparagraph id="HA113C646E5E24B659DCC7F275B7B28D"><enum>(B)</enum><text>e-mail notice, if the person or business has an e-mail address for the subject person; or</text></subparagraph> 
<subparagraph id="HD7D84BC8C460414683DD34EAC0853D35"><enum>(C)</enum><text>substitute notice, if—</text> 
<clause id="HA07B1B674EFE445BA10386ED00A3E32B"><enum>(i)</enum><text>the agency or person demonstrates that the cost of providing direct notice would exceed $250,000;</text></clause> 
<clause id="H5AFFA391BACA4CB794F711FE827552E0"><enum>(ii)</enum><text>the affected class of subject persons to be notified exceeds 500,000; or</text></clause> 
<clause id="HA8A0D4DCBA2C451A96E16283E348803E"><enum>(iii)</enum><text>the agency or person does not have sufficient contact information for those to be notified.</text></clause></subparagraph></paragraph> 
<paragraph id="H367E9C81CFEF4A309B700700CA8381A4"><enum>(6)</enum><header>Alternative notification procedures</header><text>Notwithstanding any other obligation under this subsection, an agency, or person engaged in interstate commerce, shall be deemed to be in compliance with this subsection if the agency or person—</text> 
<subparagraph id="HEC283390994F48D3BAD3BA2439E55183"><enum>(A)</enum><text>maintains its own reasonable notification procedures as part of an information security policy for the treatment of personal information; and</text></subparagraph> 
<subparagraph id="H62D74299615A4F4093B1EF2403B09EAB"><enum>(B)</enum><text>notifies subject persons in accordance with its information security policy in the event of a breach of security of the system.</text></subparagraph></paragraph> 
<paragraph id="H66E93D1B3352487680BA64A85FC4360"><enum>(7)</enum><header>Reasonable notification procedures</header><text>As used in paragraph (6), with respect to a breach of security of the system involving personal information described in section 2(4)(C), the term <term>reasonable notification procedures</term> means procedures that—</text> 
<subparagraph id="HC57377598E5449D69312C3E096105BE4"><enum>(A)</enum><text>use a security program reasonably designed to block unauthorized transactions before they are charged to the customer’s account; and</text></subparagraph> 
<subparagraph id="H336636D89BDF4F5185CBF9E6E0DD4D83"><enum>(B)</enum><text>provide for notice to be given by the owner or licensee of the database, or another party acting on behalf of such owner or licensee, after the security program indicates that the breach of security of the system has resulted in fraud or unauthorized transactions, but does not necessarily require notice in other circumstances.</text></subparagraph></paragraph> 
<paragraph id="H94F9830170794FFBBD96361722E46053"><enum>(8)</enum><header>Notice to information clearinghouse</header><text>In addition to any other notice requirement under this subsection, an agency or person engaged in interstate commerce shall—</text> 
<subparagraph id="HA7208877FDF1413BB33E942BE29D80B"><enum>(A)</enum><text>notify the information clearinghouse established by the Federal Trade Commission under section 7 upon the occurrence of any breach for which notice is required under paragraph (1); and</text></subparagraph> 
<subparagraph id="H7A1205AE568640D8862100005208AB14"><enum>(B)</enum><text>provide such information as the Commission may require with respect to the circumstances and manner of the breach and the system on which the breach occurred.</text></subparagraph></paragraph></subsection> 
<subsection id="HCA248BEB2B2F4FA6A298BC7F2EB2921"><enum>(b)</enum><header>Civil remedies</header> 
<paragraph id="HA54C40C22F704CABA8E19932F3D00AE"><enum>(1)</enum><header>Penalties</header><text>Any agency, or person engaged in interstate commerce, that violates this section shall be subject to a fine of not more than $5,000 per violation, to a maximum of $25,000 per day while such violations persist.</text></paragraph> 
<paragraph id="H321C72F9FE194CF2B754165726DD8F13"><enum>(2)</enum><header>Equitable relief</header><text>Any person engaged in interstate commerce that violates, proposes to violate, or has violated this section may be enjoined from further violations by a court of competent jurisdiction.</text></paragraph> 
<paragraph id="H8488DADDF88C4C85A4A861B39D00A681"><enum>(3)</enum><header>Other rights and remedies</header><text>The rights and remedies available under this subsection are cumulative and shall not affect any other rights and remedies available under law.</text></paragraph></subsection> 
<subsection id="HF31ECDC26ED5441DB5B35D29A737B780"><enum>(c)</enum><header>Enforcement</header><text>The Federal Trade Commission is authorized to enforce compliance with this section, including the assessment of fines under subsection (b)(1).</text></subsection> 
<subsection id="H5B3826E8E6D341AEA142E4C1D845AE31"><enum>(d)</enum><header>Coordination with other provisions of law</header><text>This section shall not apply with respect to a financial institution (as defined in section 509(3) of the Gramm-Leach-Bliley Act) that is subject to section 526 of such Act.</text></subsection></section> 
<section id="HAE9F368196384E71BBD231EC5CF66043" display-inline="no-display-inline" section-type="subsequent-section"><enum>4.</enum><header>Timely notification by financial institutions of unauthorized access to personal information</header><text display-inline="no-display-inline">Subtitle B of title V of the Gramm-Leach-Bliley Act (<external-xref legal-doc="usc" parsable-cite="usc/15/6821">15 U.S.C. 6821 et seq.</external-xref>) is amended—</text> 
<paragraph id="HC2DE5BB10DA74203BEB321D6B80330FF"><enum>(1)</enum><text>by redesignating sections 526 and 527 as sections 528 and 529, respectively; and</text></paragraph> 
<paragraph id="H672331A32ABB46F1AD739133E5095F11"><enum>(2)</enum><text>by inserting after section 525 the following:</text> 
<quoted-block id="H06536D5A15284EC5864D754F6CBDD36F"> 
<section id="H37D79634C024400FA273081648497964"><enum>526.</enum><header>Notification to customers of unauthorized access to personal information</header> 
<subsection id="H9FC79BDCE12745708D64DCB46BAEC95D"><enum>(a)</enum><header>Definitions</header><text>For purposes of this section, the following definitions shall apply:</text> 
<paragraph id="HFAD3C9FDDCDB413BAA98BAA00669F235"><enum>(1)</enum><header>Breach</header><text>The term <term>breach</term>—</text> 
<subparagraph id="HEF789F81CD254B4999AB03607976B0C1"><enum>(A)</enum><text>means unauthorized acquisition or loss of computerized data or paper records which compromises the security, confidentiality, or integrity of personal information maintained by or on behalf of a financial institution; and</text></subparagraph> 
<subparagraph id="H172407C8EEB54914A9D1DBC8C1BE751"><enum>(B)</enum><text>does not include a good faith acquisition of personal information by an employee or agent of a financial institution for a business purpose of the institution, if the personal information is not subject to further unauthorized disclosure; and</text></subparagraph></paragraph> 
<paragraph id="H285A7FCA308B47E6A12FE1CC1ED3520"><enum>(2)</enum><header>Personal information</header><text>With respect to a customer of a financial institution, the term <term>personal information</term> means the first name or first initial and last name of the customer, in combination with any 1 or more of the following data elements, when either the name or the data element is not encrypted:</text> 
<subparagraph id="HF0ABE238590649B8B433123E69F42220"><enum>(A)</enum><text>A social security number.</text></subparagraph> 
<subparagraph id="H7EAAD220C8864A37BAD071E11FCB1B66"><enum>(B)</enum><text>A driver’s license number or other officially recognized form of identification.</text></subparagraph> 
<subparagraph id="HB48EB4D4E83C4E698E83FB7ED0B4B72B"><enum>(C)</enum><text>A credit card number, debit card number, or any required security code, access code, or password that would permit access to financial account information relating to that customer.</text></subparagraph></paragraph></subsection> 
<subsection id="HBB5894152F64449D9F0379C553E01CE6"><enum>(b)</enum><header>Notification relating to breach of personal information</header> 
<paragraph id="HED098373DE5C43AF88AF6DCE757F9F07"><enum>(1)</enum><header>Financial institution requirement</header><text>In any case in which there has been a breach of personal information at a financial institution, or such a breach is reasonably believed to have occurred, the financial institution shall promptly notify—</text> 
<subparagraph id="H057D006BFBC4430FACD15262B16B8DCA"><enum>(A)</enum><text>each customer affected by the violation or suspected violation;</text></subparagraph> 
<subparagraph id="HAB77B8FD23DC4126A6FA7200739827AD"><enum>(B)</enum><text>each consumer reporting agency described in section 603(p) of the <act-name parsable-cite="FCRA">Fair Credit Reporting Act</act-name>;</text></subparagraph> 
<subparagraph id="H15F859DB742942B4AB00F7F1068C3460"><enum>(C)</enum><text display-inline="yes-display-inline">the information clearinghouse established by the Federal Trade Commission under section 7 of the <short-title>Notification of Risk to Personal Data Act</short-title> (together with such information as the Commission may require with respect to the circumstances and manner of the breach and the system on which the breach occurred); and</text></subparagraph> 
<subparagraph id="H53AAAEF926E441DB80CD8657F5DC816E"><enum>(D)</enum><text>appropriate law enforcement agencies, in any case in which the financial institution has reason to believe that the breach or suspected breach affects a large number of customers, including as described in subsection (e)(1)(C), subject to regulations of the Federal Trade Commission.</text></subparagraph></paragraph> 
<paragraph id="H960FC3C587A54D3FB405C4371F265705"><enum>(2)</enum><header>Other entities</header><text>For purposes of paragraph (1), any person that maintains personal information for or on behalf of a financial institution shall promptly notify the financial institution of any case in which such customer information has been, or is reasonably believed to have been, breached.</text></paragraph></subsection> 
<subsection id="HA72C0F6104DA4DCE86BDF5582D8D7DA9"><enum>(c)</enum><header>Timing</header><text>Any notification required by this section shall be made—</text> 
<paragraph id="H8E2C06547C344D34BA1E62803012D870"><enum>(1)</enum><text>promptly and without unreasonable delay, upon discovery of the breach or suspected breach; and</text></paragraph> 
<paragraph id="HA39ABD162F294F2D9DBED618F1EF19F6"><enum>(2)</enum><text>consistent with—</text> 
<subparagraph id="HBF0CB856EEF04440B48FE76E7420C966"><enum>(A)</enum><text>the legitimate needs of law enforcement, as provided in subsection (d); and</text></subparagraph> 
<subparagraph id="H3536C5A454AE43C9A6A3B58E2543772E"><enum>(B)</enum><text>any measures necessary to determine the scope of the breach or restore the reasonable integrity of the information security system of the financial institution.</text></subparagraph></paragraph></subsection> 
<subsection id="H603652CAAEB3435B93B34F00BB5B6628"><enum>(d)</enum><header>Delays for law enforcement purposes</header><text>Any notification required by this section may be delayed if a law enforcement agency determines that the notification would impede a criminal investigation, and in any such case, notification shall be made promptly after the law enforcement agency determines that it would not compromise the investigation.</text></subsection> 
<subsection id="HF0B3EFA0C8B54F3BB68FFF308CA720E7"><enum>(e)</enum><header>Form of notice</header><text>Any notification required by this section may be provided—</text> 
<paragraph id="H60DB5396FC3C4EB4A9AEAEBC0070B670"><enum>(1)</enum><text>to a customer—</text> 
<subparagraph id="HB149D477C5024B70A199001691DFA996"><enum>(A)</enum><text>in writing;</text></subparagraph> 
<subparagraph id="H417222BF130649F3915E00923B4D9ED9"><enum>(B)</enum><text>in electronic form, if the notice provided is consistent with the provisions regarding electronic records and signatures set forth in section 101 of the Electronic Signatures in Global and National Commerce Act;</text></subparagraph> 
<subparagraph id="H5F8F3CD03243421DBB009DA771FC5900"><enum>(C)</enum><text>if the Federal Trade Commission determines that the number of all customers affected by, or the cost of providing notifications relating to, a single breach or suspected breach would make other forms of notification prohibitive, or in any case in which the financial institution certifies in writing to the Federal Trade Commission that it does not have sufficient customer contact information to comply with other forms of notification, in the form of—</text> 
<clause id="H33233DBF892B4DCBB3F63F5C90D35B4C"><enum>(i)</enum><text>an e-mail notice, if the financial institution has access to an e-mail address for the affected customer that it has reason to believe is accurate;</text></clause> 
<clause id="H66BBD9D517894F8485EAC24B53BCC955"><enum>(ii)</enum><text>a conspicuous posting on the Internet website of the financial institution, if the financial institution maintains such a website; or</text></clause> 
<clause id="HD370E016B2C54A4283B3001440C4F885"><enum>(iii)</enum><text>notification through the media that a breach of personal information has occurred or is suspected that compromises the security, confidentiality, or integrity of customer information of the financial institution; or</text></clause></subparagraph> 
<subparagraph id="H39C164A5B8B04746903F7E305C5800CC"><enum>(D)</enum><text>in such other form as the Federal Trade Commission may by rule prescribe; and</text></subparagraph></paragraph> 
<paragraph id="HED251BF839FF4BC692D0AF686B1EBEB2"><enum>(2)</enum><text>to consumer reporting agencies and law enforcement agencies (where appropriate), in such form as the Federal Trade Commission may prescribe, by rule.</text></paragraph></subsection> 
<subsection id="HCBAC982B22CE4FF9BA71F8108F3CF2FD"><enum>(f)</enum><header>Content of notification</header><text>Each notification to a customer under subsection (b) shall include—</text> 
<paragraph id="H9B08289CE67A446CB7314DB100D22BCB"><enum>(1)</enum><text>a statement that—</text> 
<subparagraph id="H811B690402B1466E0037E66637384C95"><enum>(A)</enum><text>credit reporting agencies have been notified of the relevant breach or suspected breach; and</text></subparagraph> 
<subparagraph id="H952C755879374DDC8E6FE35C1500A571"><enum>(B)</enum><text>the credit report and file of the customer will contain a fraud alert to make creditors aware of the breach or suspected breach, and to inform creditors that the express authorization of the customer is required for any new issuance or extension of credit (in accordance with section 605(g) of the <act-name parsable-cite="FCRA">Fair Credit Reporting Act</act-name>); and</text></subparagraph></paragraph> 
<paragraph id="H5D98DBBC0ECB410397B5A2FF379D8541"><enum>(2)</enum><text>such other information as the Federal Trade Commission determines is appropriate.</text></paragraph></subsection> 
<subsection id="H67322E4D63D9400E9F42FD9D292EE56F"><enum>(g)</enum><header>Compliance</header><text>Notwithstanding subsection (e), a financial institution shall be deemed to be in compliance with this section if—</text> 
<paragraph id="H486C3285354244DB86466822B6B6DBFF"><enum>(1)</enum><text>the financial institution has established a comprehensive information security program that is consistent with the standards prescribed by the appropriate regulatory body under section 501(b);</text></paragraph> 
<paragraph id="H7E44CBD1DEE84FA0985800EFD088D42"><enum>(2)</enum><text>the financial institution notifies affected customers and consumer reporting agencies in accordance with its own internal information security policies in the event of a breach or suspected breach of personal information; and</text></paragraph> 
<paragraph id="HD61DADA1BC0B4827A321F999DB290011"><enum>(3)</enum><text>such internal security policies incorporate notification procedures that are consistent with the requirements of this section and the rules of the Federal Trade Commission under this section.</text></paragraph></subsection> 
<subsection id="HDF20EFC6C74C4EDA00C1AC77B009F34"><enum>(h)</enum><header>Civil penalties</header> 
<paragraph id="H2A8479C1EFC04C9D994903D1EA567CE0"><enum>(1)</enum><header>Damages</header><text>Any customer injured by a violation of this section may institute a civil action to recover damages arising from that violation.</text></paragraph> 
<paragraph id="H06C19AF59DA2429B8B3686EAF9D56930"><enum>(2)</enum><header>Injunctions</header><text>Actions of a financial institution in violation or potential violation of this section may be enjoined.</text></paragraph> 
<paragraph id="HC1A44968183B4F73A1F8002BB09376E6"><enum>(3)</enum><header>Cumulative effect</header><text>The rights and remedies available under this section are in addition to any other rights and remedies available under applicable law.</text></paragraph></subsection> 
<subsection id="H190048F1F60247AF9CE70245F41B32"><enum>(i)</enum><header>Rules of construction</header> 
<paragraph id="H762DFA58A37C437982BD7579900B634"><enum>(1)</enum><header>In general</header><text>Compliance with this section by a financial institution shall not be construed to be a violation of any provision of subtitle A, or any other provision of Federal or State law prohibiting the disclosure of financial information to third parties.</text></paragraph> 
<paragraph id="H6D1A1B25373E4CD786A5219BB4F29216"><enum>(2)</enum><header>Limitation</header><text>Except as specifically provided in this section, nothing in this section requires or authorizes a financial institution to disclose information that it is otherwise prohibited from disclosing under subtitle A or any other provision of Federal or State law.</text></paragraph> 
<paragraph id="H45DCF72D81814EF3A6AD5278AC7F5C6B"><enum>(3)</enum><header>No new recordkeeping obligation</header><text>No provision of this section shall be construed as creating an obligation on the part of a financial institution to obtain, retain, or maintain information or records that are not otherwise required to be obtained, retained, or maintained in the ordinary course of business of the financial institution or under other applicable law.</text></paragraph></subsection></section><after-quoted-block>.</after-quoted-block></quoted-block></paragraph></section> 
<section id="HD2ABC262D05A4C3780FA859400DDF384"><enum>5.</enum><header>Inclusion of fraud alerts in consumer credit reports</header><text display-inline="no-display-inline">Section 605A(a) of the Fair Credit Reporting Act (<external-xref legal-doc="usc" parsable-cite="usc/15/1681c-1">15 U.S.C. 1681c–1(a)</external-xref>) is amended by adding at the end the following new paragraph:</text> 
<quoted-block style="OLC" id="HA085A9F592E64C91B067FCA703E61E47" display-inline="no-display-inline"> 
<paragraph id="H07C4AC1DB65D42B18F55A7F2A6B700F7"><enum>(3)</enum><header>Treatment of notice of a breach as a request from the consumer for an initial alert</header><text display-inline="yes-display-inline">A consumer reporting agency described in section 603(p) shall take the action required under paragraph (1) with respect to any consumer and the file of any consumer upon receiving notice of a breach of personal information with respect to such consumer from—</text> 
<subparagraph id="H6F025721DBAD49AEB7527D81A308FB8"><enum>(A)</enum><text display-inline="yes-display-inline">an agency or person engaged in interstate commerce pursuant to section 3(a) of the <short-title>Notification of Risk to Personal Data Act</short-title>; or</text></subparagraph> 
<subparagraph id="H21ACA675345849D08BE214F7FAAF38D6"><enum>(B)</enum><text>a financial institution pursuant to section 526(b)(1)(B) of the Gramm-Leach-Bliley Act .</text></subparagraph></paragraph><after-quoted-block>.</after-quoted-block></quoted-block></section> 
<section id="HF0C0F3D7AB9545BDA36D25C9F7007423"><enum>6.</enum><header>Enforcement by State attorneys general</header> 
<subsection id="HA7FE80BCBE12481E90A38EF111C7E8BE"><enum>(a)</enum><header>In general</header> 
<paragraph id="H7A33D2B8A7BE40B3AD64BFECE39642F"><enum>(1)</enum><header>Civil actions</header><text>In any case in which the attorney general of a State has reason to believe that an interest of the residents of that State has been or is threatened or adversely affected by the engagement of any person in a practice that is prohibited under this Act or the amendments made by this Act, the State, as parens patriae, may bring a civil action on behalf of the residents of the State in a district court of the United States of appropriate jurisdiction to—</text> 
<subparagraph id="HF8E714EFE4B8429190A9743C71BA0096"><enum>(A)</enum><text>enjoin that practice;</text></subparagraph> 
<subparagraph id="HBB524FB321FA4A6BB85F63007339DE3B"><enum>(B)</enum><text>enforce compliance with this Act;</text></subparagraph> 
<subparagraph id="H0560880623C34122ABA192B659EF38D7"><enum>(C)</enum><text>obtain damage, restitution, or other compensation on behalf of residents of the State; or</text></subparagraph> 
<subparagraph id="HF60FFF4A2D96470CAD66254326A057AB"><enum>(D)</enum><text>obtain such other relief as the court may consider to be appropriate.</text></subparagraph></paragraph> 
<paragraph id="HF515ADBA472241E6919B6E90F9780951"><enum>(2)</enum><header>Notice</header> 
<subparagraph id="H1AB0BA0F3F754651944FB6B3AB5F7031"><enum>(A)</enum><header>In general</header><text>Before filing an action under paragraph (1), the attorney general of the State involved shall provide to the Attorney General (or the Federal functional regulator, in the case of a financial institution (as such terms are defined in section 509 of the Gramm-Leach-Bliley Act))—</text> 
<clause id="H73E11EC4DA464C87A580522F8BB6A3A3"><enum>(i)</enum><text>written notice of the action; and</text></clause> 
<clause id="H79DE984530AA429CB5C5C26D006D17C0"><enum>(ii)</enum><text>a copy of the complaint for the action.</text></clause></subparagraph> 
<subparagraph id="HB2EA14760AB84340847BFF78A7EEFED5"><enum>(B)</enum><header>Exemption</header> 
<clause id="HCE48FB244B144619BEDFC9AB2EA24304"><enum>(i)</enum><header>In general</header><text>Subparagraph (A) shall not apply with respect to the filing of an action by an attorney general of a State under this subsection, if the State attorney general determines that it is not feasible to provide the notice described in such subparagraph before the filing of the action.</text></clause> 
<clause id="H1071FC51AD664125914B9001BD3DD4BA"><enum>(ii)</enum><header>Notification</header><text>In an action described in clause (i), the attorney general of a State shall provide notice and a copy of the complaint to the Attorney General or the Federal functional regulator at the time the State attorney general files the action.</text></clause></subparagraph></paragraph></subsection> 
<subsection id="HDA9A3C54E7D2416E9E11ED1800ED6CAC"><enum>(b)</enum><header>Construction</header><text>For purposes of bringing any civil action under subsection (a), nothing in this Act shall be construed to prevent an attorney general of a State from exercising the powers conferred on such attorney general by the laws of that State to—</text> 
<paragraph id="H70045CA8E5E5467BAC74725C51057DE7"><enum>(1)</enum><text>conduct investigations;</text></paragraph> 
<paragraph id="H0BB9E272914B4D70A7BE8BD1C2BB5D"><enum>(2)</enum><text>administer oaths or affirmations; or</text></paragraph> 
<paragraph id="HE4E9C002751742CB9F4F7616A47BE9E"><enum>(3)</enum><text>compel the attendance of witnesses or the production of documentary and other evidence.</text></paragraph></subsection> 
<subsection id="H7F65E5334A724FCD9B97009EFC6958E0"><enum>(c)</enum><header>Venue; service of process</header> 
<paragraph id="H993740A725FC4EFFB54EFC4BC4DBC3C4"><enum>(1)</enum><header>Venue</header><text>Any action brought under subsection (a) may be brought in the district court of the United States that meets applicable requirements relating to venue under <external-xref legal-doc="usc" parsable-cite="usc/28/1391">section 1391</external-xref> of title 28, United States Code.</text></paragraph> 
<paragraph id="H57E60A65AB3841A9A700C413210D06C"><enum>(2)</enum><header>Service of process</header><text>In an action brought under subsection (a), process may be served in any district in which the defendant—</text> 
<subparagraph id="HD64056D917784CFE99BC7F686C6D9FAE"><enum>(A)</enum><text>is an inhabitant; or</text></subparagraph> 
<subparagraph id="H29D73EC1087F429582BDF8DCA223144B"><enum>(B)</enum><text>may be found.</text></subparagraph></paragraph></subsection></section> 
<section id="HDEC743BE2CB444A7B29625958F9EA056"><enum>7.</enum><header>Federal information clearinghouse</header> 
<subsection id="H963F56C3BD9E43D392D9FC62915C28CF"><enum>(a)</enum><header>In general</header><text>The Federal Trade Commission shall establish and maintain a clearinghouse to collect and analyze information submitted under section 3(a)(7) of this Act and section 526(b)(1)(C) of the Gramm-Leach-Bliley Act.</text></subsection> 
<subsection id="HED676CF95D564958AA3D399E63607DBD"><enum>(b)</enum><header>Annual report</header><text>The Federal Trade Commission, in consultation with the Federal functional regulators, shall submit an annual report to the Congress containing—</text> 
<paragraph id="H1170C1A0D659464596FDDE006516A688"><enum>(1)</enum><text>containing a summary of the types of breaches that have occurred during the period covered by the report and an identification of trends in the manner in which unauthorized access to and acquisition of personal information is being accomplished; and</text></paragraph> 
<paragraph id="HB1626F4D8FA64A0FBC82FA0047244703"><enum>(2)</enum><text>such recommendations for administrative or legislative action as the Commission or any Federal functional regulator may determine to be appropriate.</text></paragraph></subsection></section> 
<section id="H2221C030781A4CC797E5AFB88B5296AC"><enum>8.</enum><header>Effect on State law</header><text display-inline="no-display-inline">The provisions of this Act shall supersede any inconsistent provisions of law of any State or unit of local government relating to the notification of any resident of the United States of any breach of security of an electronic database containing such resident’s personal information (as defined in this Act), except as provided under sections 1798.82 and 1798.29 of the California Civil Code.</text></section> 
<section id="H8E8509D1D70943A98F364834F38F48E"><enum>9.</enum><header>Effective date</header><text display-inline="no-display-inline">This Act, and the amendments made by this Act, shall take effect at the end of the 6-month period beginning on the date of the enactment of this Act.</text></section> 
</legis-body> 
</bill> 


