<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" dms-id="H6BBD05B2CAD04DB196033338C12FC671" public-private="public" bill-type="olc"> 
<metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>109 HR 3140 IH: Consumer Data Security and Notification Act of 2005</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2005-06-30</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form> 
<distribution-code display="yes">I</distribution-code> 
<congress>109th CONGRESS</congress> <session>1st Session</session> 
<legis-num>H. R. 3140</legis-num> 
<current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber> 
<action> 
<action-date date="20050630">June 30, 2005</action-date> 
<action-desc><sponsor name-id="B001253">Ms. Bean</sponsor> (for herself, <cosponsor name-id="D000602">Mr. Davis of Alabama</cosponsor>, <cosponsor name-id="F000339">Mr. Frank of Massachusetts</cosponsor>, <cosponsor name-id="M000087">Mrs. Maloney</cosponsor>, <cosponsor name-id="G000535">Mr. Gutierrez</cosponsor>, <cosponsor name-id="W000207">Mr. Watt</cosponsor>, <cosponsor name-id="A000022">Mr. Ackerman</cosponsor>, <cosponsor name-id="F000262">Mr. Ford</cosponsor>, <cosponsor name-id="C001038">Mr. Crowley</cosponsor>, <cosponsor name-id="C001049">Mr. Clay</cosponsor>, <cosponsor name-id="M000309">Mrs. McCarthy</cosponsor>, <cosponsor name-id="L000562">Mr. Lynch</cosponsor>, <cosponsor name-id="W001159">Ms. Wasserman Schultz</cosponsor>, and <cosponsor name-id="M001160">Ms. Moore of Wisconsin</cosponsor>) introduced the following bill; which was referred to the <committee-name committee-id="HBA00">Committee on Financial Services</committee-name></action-desc> 
</action> 
<legis-type>A BILL</legis-type> 
<official-title>To expand the protections for sensitive personal information in Federal law to cover the information collection and sharing practices of unregulated information brokers, to enhance information security requirements for consumer reporting agencies and information brokers, and to require consumer reporting agencies, financial institutions, and other entities to notify consumers of data security breaches involving sensitive consumer information, and for other purposes.</official-title> 
</form> 
<legis-body id="H1A87AACD890041F79600DFD52708858F" style="OLC"> 
<section id="H83DB168F1DAB483F93CBF6C9177CF4AC" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Consumer Data Security and Notification Act of 2005</short-title></quote>.</text></section> 
<section id="H48E9D3116A414F9C93F900002BDE8818"><enum>2.</enum><header>Amendments to the Fair Credit Reporting Act</header> 
<subsection id="H1EE5AF3E05B64D9792033829FCDE9959"><enum>(a)</enum><header>FCRA coverage of data brokers</header><text display-inline="yes-display-inline">Section 603(d) of the Fair Credit Reporting Act (<external-xref legal-doc="usc" parsable-cite="usc/15/1681a">15 U.S.C. 1681a(d)</external-xref>) is amended by adding at the end the following new paragraph:</text> 
<quoted-block id="HC280A5D6564F42B099EB00A3FFACB841" style="OLC"> 
<paragraph id="H2D54D0397B6C4D0EB285CF3B77183C65"><enum>(4)</enum><header>Communication of personally identifiable information by certain persons included</header><text>The term <term>consumer report</term> shall also include any written, oral, electronic, or other communication of any information by any person which, for monetary fees, dues or other compensation, regularly engages in whole or in part in the practice of assembling or evaluating personally identifiable information for the purpose of furnishing reports to third parties that includes the name of any consumer and any of the following information relating to such consumer:</text> 
<subparagraph id="H14942832EF184E5F9EDDBAA5F621E1DA"><enum>(A)</enum><text>Any Social Security account number.</text></subparagraph> 
<subparagraph id="H17D55511825649059EB8ABF071ABA2F0"><enum>(B)</enum><text>Any driver’s license number.</text></subparagraph> 
<subparagraph id="H7598D4BA9BC84F22A397E8322B7E236F"><enum>(C)</enum><text>Any other identification number issued by a State or the Federal Government.</text></subparagraph> 
<subparagraph id="HA1463A2EBA47471FB831750088205394"><enum>(D)</enum><text>Any bank, savings association, credit union, or investment account number.</text></subparagraph> 
<subparagraph id="HC9460BC754FA40BEBB7FA65DAD52B0CA"><enum>(E)</enum><text>Any credit card, or debit card account number.</text></subparagraph> 
<subparagraph id="H42880557C5D14E37B9709151EB00D0A4"><enum>(F)</enum><text>Any password, access code, or security code relating to a bank, savings association, credit union, or investment account number or credit or debit card account number.</text></subparagraph></paragraph><after-quoted-block>.</after-quoted-block></quoted-block></subsection> 
<subsection id="H72CB807AE45145A4B3B747903884DE00"><enum>(b)</enum><header>Verification standards for users of consumer reports</header><text display-inline="yes-display-inline">Section 604(f) of the Fair Credit Reporting Act (<external-xref legal-doc="usc" parsable-cite="usc/15/1681b">15 U.S.C. 1681b(f)</external-xref>) is amended—</text> 
<paragraph id="H0D7C41C1524E4DE5BE8300A8E0251CA8"><enum>(1)</enum><text>by striking <quote>and</quote> at the end of paragraph (1); </text></paragraph> 
<paragraph id="H1F38534AAFAE4829881EC6D6B294B724"><enum>(2)</enum><text>by redesignating paragraph (2) as paragraph (3); and</text></paragraph> 
<paragraph id="HE4B7A3F88F294816B127ECB47F8D1FB7"><enum>(3)</enum><text>by inserting after paragraph (1) the following new paragraph:</text> 
<quoted-block id="H15AC9ECB707B41CF8800126F63DA1F75" style="OLC"> 
<paragraph id="H4E50017EB3FD4EDE9958F85DB6CBF716"><enum>(2)</enum><text>the identity of the person requesting the consumer report has been verified, pursuant to section 607(a), in accordance with procedures which the Commission shall prescribe in regulation; and</text></paragraph><after-quoted-block>.</after-quoted-block></quoted-block></paragraph></subsection> 
<subsection id="H520FC2A0106340A6831C236316104FC3"><enum>(c)</enum><header>Data Security Standards and Notification of Security Breaches</header> 
<paragraph id="H6481BFE6D9F14D2C9CB30044D4F5D4A"><enum>(1)</enum><header>In general</header><text>The Fair Credit Reporting Act (<external-xref legal-doc="usc" parsable-cite="usc/15/1681">15 U.S.C. 1681 et seq.</external-xref>) is amended by adding at the end the following new section:</text> 
<quoted-block style="OLC" id="H8F2AFD557CA64ACDBBAFD51CF1F9DA" display-inline="no-display-inline"> 
<section id="HF2B565599F8342FB87AA3BB3DCCD94B"><enum>630.</enum><header>Protection of nonpublic consumer information</header> 
<subsection id="H0781CA2C811E4D42A983BC9CB3963D3D"><enum>(a)</enum><header>In general</header><text>Notwithstanding any other provision of this title, each consumer reporting agency shall have an affirmative and continuing obligation to respect the privacy of consumers and to protect the security and confidentiality of consumers nonpublic personal information.</text></subsection> 
<subsection id="H3F96C3DB8C74495180D579C776296FF0"><enum>(b)</enum><header>Safeguards required</header><text>In furtherance of subsection (a), the Commission shall establish appropriate standards, by regulation, for consumer reporting agencies relating to administrative, technical, and physical safeguards—</text> 
<paragraph id="HB4CED0BD52E643B488227B38EDDC1182"><enum>(1)</enum><text>to insure the security and confidentiality of consumer records and information;</text></paragraph> 
<paragraph id="HED70D309D7764069A0A5A8AA85D084E"><enum>(2)</enum><text>to protect against any anticipated threats or hazards to the security of such records; and</text></paragraph> 
<paragraph id="H433FC874C8A04ABB80EF743600398EB8"><enum>(3)</enum><text>to protect against unauthorized access to or use of such records or information which could result in substantial harm or inconvenience to any customer.</text></paragraph></subsection> 
<subsection id="H79D83CB679654FCA97635340D6B8562"><enum>(c)</enum><header>Notification of data security breaches</header> 
<paragraph id="H2B57B175B2624773B35F18EDD4DC39E9"><enum>(1)</enum><header>In general</header><text>The regulations prescribed under subsection (b) shall include requirements for the notification of consumers following the discovery of a breach of security of any data system maintained by the consumer reporting agency in which sensitive consumer information was, or is reasonably believed to have been, acquired by an unauthorized person.</text></paragraph> 
<paragraph id="HC3D5DFA29EE84F6EBC323D68A9DFF486"><enum>(2)</enum><header>Content of regulations</header><text>The regulations prescribed under paragraph (1) shall include the following requirements or provisions:</text> 
<subparagraph id="H49AC09C9EA37405CBFA3EC36EDFFCCC"><enum>(A)</enum><text>A requirement that a consumer reporting agency provide written notice to a consumer whenever such agency becomes aware that sensitive personal information relating to the consumer has been, or is reasonably believed to have been, acquired by an unauthorized person, unless the consumer reporting agency, after appropriate investigation—</text> 
<clause id="HE4A306FAC3174FE8A6ED8B34A9FC60A9"><enum>(i)</enum><text display-inline="yes-display-inline">reasonably concludes that misuse of the information is unlikely to occur;</text> </clause> 
<clause id="HC729D7378F964F74B089BE46602577D7"><enum>(ii)</enum><text>notifies the appropriate law enforcement agency of the data security breach; and</text></clause> 
<clause id="HA3A7219E5ECA4CA2834830CDB7EA2BAF"><enum>(iii)</enum><text>takes appropriate steps to remedy the security breach and safeguard the interests of affected consumers.</text></clause></subparagraph> 
<subparagraph id="HD3FB677EAF6C405DBF137E37F6FFD66"><enum>(B)</enum><text>A requirement that the notices required under paragraph (1) be provided by a consumer reporting agency without unreasonable delay following—</text> 
<clause id="H9C3DAF84E88F42EB8B4E50954E83BC72"><enum>(i)</enum><text>the discovery by such agency of a breach of security in the data system; and</text></clause> 
<clause id="H577FC9CC6E3544CE9D374844DC5BC84D"><enum>(ii)</enum><text>reasonable actions which the consumer reporting agency shall take to investigate the nature and intent of the breach, prevent further unauthorized access or disclosure, and restore the reasonable integrity of the data system.</text></clause></subparagraph> 
<subparagraph id="HF16C77D5252B4B95AACD56B418DC7C49"><enum>(C)</enum><text>A provision that allows for reasonable delay of such notification to the consumer under paragraph (1) upon the written request of a law enforcement agency which has determined that the notification required under paragraph (1) would seriously impede a criminal investigation.</text></subparagraph> 
<subparagraph id="HE95D97A8E79F4234009B848261ECA24F"><enum>(D)</enum><text>A provision that the written notice required under paragraph (1) may be made by an electronic transmission only if—</text> 
<clause id="H3554DB65204D46FC84922DDE41D5597C"><enum>(i)</enum><text>the consumer has provided prior consent to receive any such notice by electronic transmission; and</text></clause> 
<clause id="H17AB34B4DAE34BFCB2193B2E9FF1B9FF"><enum>(ii)</enum><text>the notice is consistent with the provisions permitting electronic transmission of notices under section 101 of the Electronic Signatures in Global and National Commerce Act.</text></clause></subparagraph> 
<subparagraph id="HCA7F647E69EB4C0897080049C5B88D9C"><enum>(E)</enum><text>A requirement that the notification provided to consumers include—</text> 
<clause id="HFDA95A5533F344EEA9B7A1FD31E14BAA"><enum>(i)</enum><text>the date on which the consumers nonpublic personal information was, or is reasonably believed to have been, acquired by an unauthorized person;</text></clause> 
<clause id="H90D5391CF6DA464D9B54BA833123627E"><enum>(ii)</enum><text>the specific information that was, or is reasonably believed to have been, acquired by an unauthorized person, including Social Security account numbers, bank or investment account numbers, credit or debit card account numbers, or any password or code relating to such accounts;</text></clause> 
<clause id="HA88603321DFC447385DF4D1FE4912FC6"><enum>(iii)</enum><text>the actions taken by the consumer reporting agency to address or remedy the security breach and prevent unauthorized use of nonpublic personal information;</text></clause> 
<clause id="H2FEA8A269D884E62B6FC5700FCD9B7B2" display-inline="no-display-inline"><enum>(iv)</enum><text display-inline="yes-display-inline">the summary of rights of consumer victims of fraud or identity theft prepared by the Federal Trade Commission under section 609(d) and information on how to contact the Commission for more detailed information; and</text></clause> 
<clause id="H69332EA8648945219EAC64F4B2422901"><enum>(v)</enum><text>the toll-free telephone number where consumers may obtain additional information about the security breach and an explanation of available options to protect their consumer file from unauthorized access.</text></clause></subparagraph></paragraph> 
<paragraph id="H34055F004FDB4F129C8B4CCE3F46EBF"><enum>(3)</enum><header>Treatment of encrypted information</header><text display-inline="yes-display-inline">For purposes of the regulations prescribed under paragraph (1), the Commission shall—</text> 
<subparagraph id="H21326FE372854C91B94D091988B55F55"><enum>(A)</enum><text display-inline="yes-display-inline">permit a consumer reporting agency, in connection with any determination pursuant to paragraph (2)(A)(i), to reasonably conclude that misuse of information is unlikely to occur where the sensitive consumer information acquired, or believed to have been acquired, by an unauthorized person consists of information that has been encrypted in a manner consistent with standards set forth under subparagraph (B); </text></subparagraph> 
<subparagraph id="H652CF79974024AF79D081F9C3B9CFA9B"><enum>(B)</enum><text>identify appropriate standards for encryption of personal and financial information for purposes of subparagraph (A), taking into consideration the Advanced Encryption Standard adopted by the National Institute of Standards and Technology for use by the Federal Government; and </text></subparagraph> 
<subparagraph id="HA6214B5643864AB0A9632C00C8E839D2"><enum>(C)</enum><text>establish appropriate criteria for determining whether information that has been encrypted has been accessed by an unauthorized person, and whether misuse of such information is likely to occur and notification is required pursuant to this section.</text></subparagraph></paragraph> </subsection></section><after-quoted-block>.</after-quoted-block></quoted-block></paragraph> 
<paragraph id="HC7EC0B840EF54C5D9821FBB00F26D08"><enum>(2)</enum><header>Clerical amendment</header><text>The table of contents for the Fair Credit Reporting Act is amended by inserting after the item relating to section 129 the following new item:</text> 
<quoted-block style="OLC" id="HADA432666390410596FC7B19BACB044B" display-inline="no-display-inline"> 
<toc regeneration="no-regeneration"> 
<toc-entry level="section">630. Protection of nonpublic consumer information</toc-entry></toc><after-quoted-block>.</after-quoted-block></quoted-block></paragraph></subsection> 
<subsection id="H6D7DEC99EABA47DBA664CE4058DE28F1"><enum>(d)</enum><header>Use of consumer reports for private investigations</header> 
<paragraph id="H4A109A23B1DE4187B73672574B35BCFD"><enum>(1)</enum><header>In general</header><text>Section 604(a)(3) of the Fair Credit Reporting Act (15 U.S.C.1681b(a)(3)) is amended—</text> 
<subparagraph id="H13740E817F8F4FCF831511F12F1FAE44"><enum>(A)</enum><text>by striking <quote>or</quote> at the end of subparagraph (E);</text></subparagraph> 
<subparagraph id="HD2433095D3714470932D822900BDAF6C"><enum>(B)</enum><text>by redesignating subparagraph (F) as subparagraph (G); and</text></subparagraph> 
<subparagraph id="H634C65F0E7FA4EB3AAD51BBB0028F664"><enum>(C)</enum><text>by inserting after subparagraph (E) the following new paragraph:.</text> 
<quoted-block style="OLC" id="HA7E450B4D451409E8F32095583117425" display-inline="no-display-inline"> 
<subparagraph id="HC9A0392BA48848F2854828CF7589C82B"><enum>(F)</enum><text>is a duly licensed private investigator who intends to use the consumer report only in connection with a lawful investigation within the scope of the investigator’s license and for no other purpose; or</text></subparagraph><after-quoted-block>.</after-quoted-block></quoted-block></subparagraph></paragraph> 
<paragraph id="H52511DCA98BD4BDFA6C39BBFAFCA07DA"><enum>(2)</enum><header>Technical and conforming amendment</header><text>Section 603(k)(1)(B)(iv)(I) of the Fair Credit Reporting Act (<external-xref legal-doc="usc" parsable-cite="usc/15/1681a">15 U.S.C. 1681a(k)(1)(B)(iv)(I)</external-xref>) is amended by striking <quote>604(a)(3)(F)(ii)</quote> and inserting <quote>604(a)(3)(G)(ii)</quote>.</text></paragraph> </subsection> 
<subsection id="H986B43E74FDF49859947BB8FFD70005"><enum>(e)</enum><header>Regulations</header><text>The Federal Trade Commission shall prescribe such regulations as the Commission determines to be necessary to implement the amendments made by this section and such regulations shall be published in final form before the end of the 6-month period beginning on the date of the enactment of this Act.</text></subsection></section> 
<section id="H66B81869596448E0B62055429357F318"><enum>3.</enum><header>Amendments to Title V of the Gramm-Leach-Bliley Act</header> 
<subsection id="H71E273B929134AC5A0BB94CB9F926F13"><enum>(a)</enum><header>Notification of security breaches</header><text display-inline="yes-display-inline">Section 501 of the Gramm-Leach-Bliley Act (<external-xref legal-doc="usc" parsable-cite="usc/15/6801">15 U.S.C. 6801</external-xref>) is amended by adding at the end the following new subsection:</text> 
<quoted-block id="HA5388CF5896A4B7E81F7332D2F8D9C07" style="OLC"> 
<subsection id="HEC0DD36EA27D496D9F39A3B93DC4AFF"><enum>(c)</enum><header>Notification of data security breaches</header> 
<paragraph id="H5EC8934B51844051B8629F855B1EBC77"><enum>(1)</enum><header>In general</header><text>In establishing standards pursuant to subsection (b), each agency or authority described in section 505(a) shall require, in regulation, that a financial institution notify customers following the discovery of a breach of security of any data system maintained by the financial institution in which nonpublic personal information was, or is reasonably believed to have been, acquired by an unauthorized person.</text></paragraph> 
<paragraph id="H78FCBDF184854BE69EB51F0006AAEE9E"><enum>(2)</enum><header>Content of regulations</header><text display-inline="yes-display-inline">The regulations prescribed under paragraph (1) shall include the following requirements or provisions:</text> 
<subparagraph id="H2C820E4B8B364707B2B0798DB632C7CA"><enum>(A)</enum><text>A requirement that a financial institution provide written notice to a customer whenever the institution becomes aware that sensitive personal information relating to the customer has been, or is reasonably believed to have been, acquired by an unauthorized person, unless the financial institution, after appropriate investigation, reasonably concludes that misuse of the information is unlikely to occur, and—</text> 
<clause id="HA3C444A054F3425B9162751EBA4E6531"><enum>(i)</enum><text>promptly notifies its primary Federal financial regulatory agency of the data security breach;</text></clause> 
<clause id="H5FC19465471F47DE9318ED558E91E675"><enum>(ii)</enum><text>notifies the appropriate law enforcement agency of the data security breach; and</text></clause> 
<clause id="H9B4C54874B1A4F8B87FDCC9EFA073367"><enum>(iii)</enum><text>takes appropriate steps to remedy the security breach and safeguard the interests of affected customers, including monitoring the affected customers accounts for unusual or suspicious activity.</text></clause></subparagraph> 
<subparagraph id="H1A8A39FB3D154D7CAD779700651CF871"><enum>(B)</enum><text display-inline="yes-display-inline">A requirement that the notice required under paragraph (1) be provided by a financial institution without unreasonable delay following—</text> 
<clause id="H7B44F285F3E4410C958FB37E0075F25F"><enum>(i)</enum><text display-inline="yes-display-inline">the discovery by the financial institution of a breach of security in the data system; </text></clause> 
<clause id="H3549BAC65EDA47B586015035FFBDEF54"><enum>(ii)</enum><text>reasonable investigation of the nature and scope of the security breach, including identification of the customer information systems and specific customer information or accounts that may have been accessed; </text></clause> 
<clause id="H1532BC7D193848C493DC6C19421EB248"><enum>(iii)</enum><text>notification of the primary Federal financial regulatory agency for the financial institution; </text></clause> 
<clause id="HF0206A18395444C694E7573F5F8D3FD"><enum>(iv)</enum><text>notification of appropriate law enforcement agencies; and </text></clause> 
<clause id="H09A05E6DDE2C42D8B6A7B731E66300C7"><enum>(v)</enum><text>reasonable measures to prevent further unauthorized access or disclosure and to restore the reasonable integrity of the data system.</text></clause></subparagraph> 
<subparagraph id="H18007682783340EB945440308353BF57"><enum>(C)</enum><text display-inline="yes-display-inline">A provision establishing minimum standards for investigations of the nature and scope of security breaches, including any limitation on the duration of such investigations that the agency or authority may consider appropriate to prevent substantial harm or inconvenience to any customer;</text> </subparagraph> 
<subparagraph id="H24EA9DDB5AB041EDA212D5DFFE7556DC"><enum>(D)</enum><text display-inline="yes-display-inline">A provision that allows for reasonable delay of such notification upon the written request of a law enforcement agency which has determined that the notification required under paragraph (1) would seriously impede a criminal investigation;</text></subparagraph> 
<subparagraph id="HFCEF87EF42BD4F2CA36C1B00B315E068"><enum>(E)</enum><text display-inline="yes-display-inline">A provision that the written notice required under paragraph (1) may be made by an electronic transmission only if—</text> 
<clause id="HCE71D07F804740ABBC567EE667522CAE"><enum>(i)</enum><text>the customer has provided prior consent to receive any such notice by electronic transmission; and</text></clause> 
<clause id="H27CEC05882384B329B22A488721C6736"><enum>(ii)</enum><text>the notice is consistent with the provisions permitting electronic transmission of notices under section 101 of the Electronic Signatures in Global and National Commerce Act.</text></clause></subparagraph> 
<subparagraph id="H06543A0D312E4F80863E40A06043F2BB"><enum>(F)</enum><text display-inline="yes-display-inline">A requirement that the notification provided to consumers include—</text> 
<clause id="H6727FC4D3D584C85BE92C15EF804F3AA"><enum>(i)</enum><text>the date on which the customers nonpublic personal information was, or is reasonably believed to have been, acquired by an unauthorized person;</text></clause> 
<clause id="H9E2EC93D50324953A3F1B9FD887C9940"><enum>(ii)</enum><text>the specific information that was, or is reasonably believed to have been, acquired by an unauthorized person, including Social Security account numbers, bank or investment account numbers, credit or debit card account numbers, or any password or code relating to such accounts;</text></clause> 
<clause id="H0B524F0FE56646E7BEC329AF86C6A676"><enum>(iii)</enum><text>the actions taken by the financial institution to address or remedy the security breach and prevent unauthorized use of nonpublic customer information;</text></clause> 
<clause id="H7BECB96FE8B3425E892F109174041DDA"><enum>(iv)</enum><text display-inline="yes-display-inline">the summary of rights of consumer victims of fraud or identity theft prepared by the Federal Trade Commission under section 609(d) of the Fair Credit Reporting Act and information on how to contact the Commission for more detailed information; and</text></clause> 
<clause id="H74673A84C93547C38710FB6899B13423"><enum>(v)</enum><text>the toll-free telephone number where customers may obtain additional information about the security breach and explanations of available options to protect their consumer file from unauthorized access.</text></clause></subparagraph> 
<subparagraph id="H209E2A51F95843BDB5B46439FB316300"><enum>(G)</enum><text>A requirement concerning any other action or disclosure that the agency or authority determines necessary or appropriate to carry out the intent of this subsection.</text></subparagraph></paragraph> 
<paragraph id="HD36152F3A74D45C484BE76027C27A340"><enum>(3)</enum><header>Certain persons treated as financial institutions for this subsection</header> 
<subparagraph id="HEC8671CF3E4945E7B733E04FD7F24100"><enum>(A)</enum><header>In general</header><text display-inline="yes-display-inline">For purposes of this subsection (and sections 504, 505, and 507 to the extent applicable with respect to this subsection), the term <term>financial institution</term> includes any person or organization that, in the regular course of business, collects and maintains written or electronic files containing individually identifiable information on customer transactions, including any bank, savings association, or credit union account number, credit card or debt card number, and any other payment account number, or any password, access code, or security code pertaining to any such account or any credit card or debit card.</text></subparagraph> 
<subparagraph id="HF808326CF2504477B02FE4CBA856B721"><enum>(B)</enum><header>Notification</header><text>A person or organization described in subparagraph (A) that is required to provide written notice pursuant to regulations prescribed under paragraph (1), shall, promptly notify the appropriate law enforcement agency of the data security breach, and provide notification, as appropriate—</text> 
<clause id="HCBF2E65211284C02A9FDA300A9D8BE64"><enum>(i)</enum><text>to the customer whose payment account information has been, or is reasonably believed to have been, acquired by an unauthorized person, and such notification includes all applicable disclosures required by paragraph (2)(F); </text></clause> 
<clause id="HD4F27F9B24D643B0A78D0037466883B1"><enum>(ii)</enum><text>to the financial institution which is the holder of the customer’s bank, savings association, or credit union account, credit card or debit card account, or other payment account which has been, or is reasonably believed to have been, acquired by an unauthorized person, which shall be in such form and include such information as required by regulation; or </text></clause> 
<clause id="HEEF2467E4AB34482AD5E89FC7BCDD0A8"><enum>(iii)</enum><text>to the financial intermediary or network used to effect the credit transaction, electronic fund transfer, or other form of payment on behalf of the customer whose payment account information has been, or is reasonably believed to have been, acquired by an unauthorized person, which shall include the information required by subparagraph (C) and such other information as required by regulation.</text></clause></subparagraph> 
<subparagraph id="H519E5CDA4EE84FD39287D6EDF0DC6CBF"><enum>(C)</enum><header>Response of financial intermediary or network upon receiving notice</header><text> A financial intermediary or network that receives notice of a data security breach pursuant to subparagraph (B)(iii) shall promptly communicate to the financial institution which is the holder of the bank, savings association, or credit union account, credit card or debit card account, or other payment account with respect to which such breach occurred, all necessary information pertaining to the data security breach, which shall include the date on which the breach is reasonably believed to have occurred and the name and location of the person or organization responsible for maintaining the data system where the security breach occurred.</text></subparagraph> 
<subparagraph id="H25A4F6DD9ED84698A8CE8CA798866C9"><enum>(D)</enum><header>Response of financial institution that holds customer’s account upon receiving notice</header><text>A financial institution that receives notice of a data security breach pursuant to subparagraphs (B)(ii) or (C) may communicate to any customer whose bank, savings association, or credit union account, credit card or debit card account, or other payment account is identified as having been, or is reasonably believed to have been, acquired by an unauthorized person, any information it receives relating to the security breach, including the date on which the breach is reasonably believed to have occurred and the name and location of the person or organization responsible for maintaining the data system where the security breach occurred. </text></subparagraph> 
<subparagraph id="HDC7C1AB71BFC4A63940000CA589F996D"><enum>(E)</enum><header>Financial intermediary or network defined</header><text display-inline="yes-display-inline">For purposes of this paragraph, the term <quote>financial intermediary or network</quote> means a credit card association, electronic fund transfer network, or other system, clearinghouse, or network utilized by any creditor, credit card issuer, financial institution, or money transmitting business, to effect a credit transaction, electronic fund transfer, or other money transmitting, check clearing, or payment service.</text></subparagraph></paragraph> 
<paragraph id="HAE03F954A5EA43F68B869514F1B6BCB"><enum>(4)</enum><header>Treatment of encrypted information</header><text display-inline="yes-display-inline">The regulations prescribed under paragraph (1) shall—</text> 
<subparagraph id="H6B9A5EC554914E8A8B216F615D8E0042"><enum>(A)</enum><text display-inline="yes-display-inline">permit a financial institution, in connection with any determination pursuant to paragraph (2)(A), to reasonably conclude that misuse of information is unlikely to occur where the sensitive consumer information acquired, or believed to have been acquired, by an unauthorized person consists of information that has been encrypted in a manner consistent with standards set forth under subparagraph (B); </text></subparagraph> 
<subparagraph id="HB561484C21674BA2883BACDA002D575E"><enum>(B)</enum><text>identify appropriate standards for encryption of personal and financial information for purposes of subparagraph (A), taking into consideration the Advanced Encryption Standard adopted by the National Institute of Standards and Technology for use by the Federal Government; and </text></subparagraph> 
<subparagraph id="H1539AFF1EBE64A0F806D00239B6B66FD"><enum>(C)</enum><text>establish appropriate criteria for determining whether information that has been encrypted has been accessed by an unauthorized person, and whether misuse of such information is likely to occur and notification is required pursuant to this section.</text></subparagraph></paragraph> </subsection><after-quoted-block>.</after-quoted-block></quoted-block></subsection> 
<subsection id="H314000F8833D4388B7745B43B50695A4"><enum>(b)</enum><header>Regulations</header><text display-inline="yes-display-inline">The agencies and authorities described in section 505(a) of the Gramm-Leach-Bliley Act shall, in the manner prescribed in section 504 of such Act, prescribe such regulations as the agencies and authorities determine to be necessary to implement the amendments made by this section and such regulations shall be published in final form before the end of the 6-month period beginning on the date of the enactment of this Act.</text></subsection></section> 
</legis-body> 
</bill> 


