<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" dms-id="HCF989F9CFEA04D769400DB009000291C" public-private="public" bill-type="olc"> 
<metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>109 HR 3374 IH: Consumer Notification and Financial Data Protection Act of 2005</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2005-07-21</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form> 
<distribution-code display="yes">I</distribution-code> 
<congress>109th CONGRESS</congress> <session>1st Session</session> 
<legis-num>H. R. 3374</legis-num> 
<current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber> 
<action> 
<action-date date="20050721">July 21, 2005</action-date> 
<action-desc><sponsor name-id="L000553">Mr. LaTourette</sponsor> (for himself and <cosponsor name-id="H000762">Ms. Hooley</cosponsor>) introduced the following bill; which was referred to the <committee-name committee-id="HBA00">Committee on Financial Services</committee-name></action-desc> 
</action> 
<legis-type>A BILL</legis-type> 
<official-title>To provide for the uniform and timely notification of consumers whose sensitive financial personal information has been placed at risk by a breach of data security, to enhance data security safeguards, to provide appropriate consumer mitigation services, and for other purposes.</official-title> 
</form> 
<legis-body id="H2746F6ED667D4C22A40092EA9772E336" style="OLC"> 
<section id="HD641436B8AB447B694B14637573B10C4" section-type="section-one" display-inline="no-display-inline"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Consumer Notification and Financial Data Protection Act of 2005</short-title></quote>.</text></section> 
<section id="H7C89F8E5364C453B85AC3393C75068B0"><enum>2.</enum><header>Data security safeguards</header><text display-inline="no-display-inline">Each financial institution shall have an affirmative and continuing obligation to maintain reasonable policies and procedures to protect the security and confidentiality of sensitive financial personal information of any consumer that is maintained or received by or on behalf of such financial institution against any unauthorized use that is reasonably likely to result in harm or substantial inconvenience to such consumer.</text></section> 
<section id="H028262D6C9FB48C791F7B4084CEFB4D"><enum>3.</enum><header>Investigation and notice to regulators and law enforcement in case of breach of data security</header> 
<subsection id="H272A96F6E173440DB288624345CDE19D"><enum>(a)</enum><header>Duty to investigate</header> 
<paragraph id="H40B45A168EED4CF1B7C4C456C41C5153"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">Whenever any financial institution determines or becomes aware of information that would reasonably indicate that a breach of data security may have occurred or is reasonably likely to occur, or receives notice under subsection (c), the financial institution shall immediately conduct a reasonable investigation to—</text> 
<subparagraph id="H8944DA4C76A249EE8E6CFD63C22F00FE"><enum>(A)</enum><text display-inline="yes-display-inline">assess the nature and scope of the breach;</text></subparagraph> 
<subparagraph id="HC642990B53304271AF38BA6185F4B800"><enum>(B)</enum><text>identify the sensitive financial personal information involved; and</text></subparagraph> 
<subparagraph id="H14CADF41EAA14BA4ACFA02AF003F60A2"><enum>(C)</enum><text>determine if the breach is reasonably likely to result in harm or substantial inconvenience to any consumer to whom the information relates.</text></subparagraph></paragraph> 
<paragraph id="H616AC13D1DB543C1B8F6B8CEE7DACE8"><enum>(2)</enum><header>Factors to be considered</header><text display-inline="yes-display-inline">In determining, under paragraph (1), the likelihood that harm or substantial inconvenience may be caused to consumers, the financial institution shall consider all available relevant facts, including whether the information that was subject to the breach was unencrypted, or unredacted, or required technology to use that is not generally commercially available.</text></paragraph></subsection> 
<subsection id="H08C21A7BD4A04F7AA2F5D6AF6F724F11"><enum>(b)</enum><header>Investigation notices</header><text display-inline="yes-display-inline">If a financial institution determines after commencing an investigation under subsection (a) that a potential breach of data security may result in harm or substantial inconvenience to any consumer whose sensitive financial personal information was involved in such potential breach, the financial institution shall—</text> 
<paragraph id="HDE851DA017A44227A374E9C194D0BA78"><enum>(1)</enum><text display-inline="yes-display-inline">promptly notify the appropriate law enforcement agencies of the breach;</text></paragraph> 
<paragraph id="HE5E20DE4F6254A75B8FA5516A5B56EE2"><enum>(2)</enum><text>promptly notify the institution’s functional regulator;</text></paragraph> 
<paragraph id="H416DB02AD2F441F5A3169CA9026D72D9"><enum>(3)</enum><text>take reasonable measures to ensure and restore the security and confidentiality of the sensitive financial personal information involved in the breach;</text></paragraph> 
<paragraph id="H5229B18C909A43A3A8A5B601764D2C68" commented="no"><enum>(4)</enum><text display-inline="yes-display-inline">take reasonable measures to prevent further unauthorized access to or disclosure of any sensitive financial personal information and to restore the integrity of the data system; and</text></paragraph> 
<paragraph id="HF19598FF3EE043CBABE9785C2F225162" commented="no"><enum>(5)</enum><text display-inline="yes-display-inline">notify as appropriate and without unreasonable delay all critical third parties—</text> 
<subparagraph id="HBDB95F6D5CD947BFB11E00BDCD024938" commented="no"><enum>(A)</enum><text>whose involvement is necessary to investigate the breach of data security; or</text></subparagraph> 
<subparagraph id="H5ED12E8CC8B145448B9DBB0164F1C8AB" commented="no"><enum>(B)</enum><text>who will be required to undertake further action with respect to such information to protect such consumers from fraud or identity theft.</text></subparagraph></paragraph></subsection> 
<subsection id="H8D5ABD24223D4FDDBD5DC89BDC86CBBE"><enum>(c)</enum><header>Duty of financial contractors</header><text display-inline="yes-display-inline">Whenever any financial institution that maintains or receives sensitive personal financial information for or on behalf of another party determines, or has reason to believe, that a breach of data security has occurred with respect to such information, the financial institution shall—</text> 
<paragraph id="H67676407E47D41609978FDCDE20976B"><enum>(1)</enum><text>promptly notify the other party of the breach; </text></paragraph> 
<paragraph id="HE1A174E90CE74E278E62B8CE006C1C80"><enum>(2)</enum><text>conduct a joint investigation with the other party to determine the likelihood that such information will be misused against the consumers to whom the information relates in a manner that would cause harm or substantial inconvenience to such consumer; and</text></paragraph> 
<paragraph id="HFD82DC4EAA45457581C97A2FE778B00" commented="no"><enum>(3)</enum><text>unless the financial institution and third party determine, after conducting a reasonable investigation, that it is not reasonably likely that such information will be misused to commit financial fraud against any consumer to whom any of such sensitive financial personal information relates in a manner that would cause harm or substantial inconvenience to such consumer, provide joint notice under section 4 to such consumers.</text></paragraph></subsection></section> 
<section id="H809CD201A14B42788508CDED50BCF86"><enum>4.</enum><header>Notice to consumers of data security breach</header> 
<subsection id="H84FFD5748BDC442C94B1C809BD647DBE"><enum>(a)</enum><header>Notice required</header><text display-inline="yes-display-inline">If, after completing a reasonable investigation pursuant to section 3, a financial institution or a financial contractor pursuant to section 3(c) becomes aware that a breach of data security is reasonably likely to have occurred, with respect to sensitive financial personal information maintained or received by or on behalf of the institution, that creates a risk of harm or substantial inconvenience to consumers to whom the information relates, the financial institution shall, without unreasonable delay—</text> 
<paragraph id="H6E3B595F220247FF85E77194F9300A"><enum>(1)</enum><text display-inline="yes-display-inline">provide written notice, in accordance with this section, to each consumer whose sensitive financial personal information was involved in the breach of data security; and</text></paragraph> 
<paragraph id="HDE7E5811840A4CCD85B3E544FAB60C7"><enum>(2)</enum><text display-inline="yes-display-inline">if the financial institution determines that it is likely to be providing notice under paragraph (1) to 1,000 or more consumers for any breach of data security, provide written notice to—</text> 
<subparagraph id="H12DB9F994AB34C77871C27A4EC02048" commented="no" display-inline="no-display-inline"><enum>(A)</enum><text display-inline="yes-display-inline">each consumer reporting agency described in section 603(p) of the Fair Credit Reporting Act; and</text></subparagraph> 
<subparagraph id="H9BCA36F59BC44BB6976B7226652280A8" commented="no"><enum>(B)</enum><text display-inline="yes-display-inline">any other consumer reporting agency that the financial institution identifies, or expects to identify, in the notice provided to the consumer under paragraph (1).</text></subparagraph></paragraph></subsection> 
<subsection id="H515B76D520594CD095E693F6AFD35CA8"><enum>(b)</enum><header>Content of notice</header><text display-inline="yes-display-inline">The notice provided to any consumer under subsection (a)(1) shall include the following information in a clear and conspicuous manner:</text> 
<paragraph id="HCD736FD885914E9CA2110040B07E8D8C"><enum>(1)</enum><text display-inline="yes-display-inline">A description of the nature and type of information that was, or is reasonably believed to have been, subject to the breach of data security.</text></paragraph> 
<paragraph id="HD7D793FAF2C84DBC84CEB3AECCC41B"><enum>(2)</enum><text display-inline="yes-display-inline">If known, the date, or a reasonable approximation of the period of time, on or within which sensitive financial personal information of the consumer was, or is reasonably believed to have been, acquired by an unauthorized person.</text></paragraph> 
<paragraph id="H6105E1F9B0014B5A85BF63164BC003F"><enum>(3)</enum><text display-inline="yes-display-inline">A description of the actions taken by the financial institution to restore the security and confidentiality of the data.</text></paragraph> 
<paragraph id="H450740F8D18D4495A6941B9F9E520193"><enum>(4)</enum><text display-inline="yes-display-inline">A toll-free telephone number where a consumer whose information was subject of the breach of data security may obtain additional information the breach of data security.</text></paragraph> 
<paragraph id="H52C1E7A49E62481B803BE2434E576056"><enum>(5)</enum><text display-inline="yes-display-inline">A summary of rights of consumer victims of fraud or identity theft, such as that prepared by the Federal Trade Commission under section 609(d) of the Fair Credit Reporting Act, including any additional appropriate information on how the consumer may—</text> 
<subparagraph id="H673CB1C9ADF347CCA200F911F248793D"><enum>(A)</enum><text>obtain a copy of a consumer report free of charge in accordance with section 612 of the Fair Credit Reporting Act;</text></subparagraph> 
<subparagraph id="HAEDA6563B4814A959BC97E3100DC3271"><enum>(B)</enum><text>place a fraud alert in any file relating to the consumer at a consumer reporting agency under section 605A of such Act to discourage unauthorized use; and</text></subparagraph> 
<subparagraph id="H79FB3317812546649D81AEFDD9E26884"><enum>(C)</enum><text display-inline="yes-display-inline">contact the Federal Trade Commission for more detailed information.</text></subparagraph></paragraph></subsection> 
<subsection id="H1B719B10ACE045C588D38CE9C883200"><enum>(c)</enum><header>Notice of identity theft</header><text display-inline="yes-display-inline">If a financial institution is required to provide a notice under subsection (a)(1) with respect to a breach of data security involving sensitive financial personal information relating to a consumer (other than financial account information described in section 9(5)(A)(v)), the notice required in this section with respect to such consumer shall include information on how the consumer may obtain mitigation services free of charge in accordance with section 5.</text></subsection> 
<subsection id="H4EAE37D180B74CED8B4CB1C4373018D8"><enum>(d)</enum><header>Delay of notice for law enforcement purposes</header><text display-inline="yes-display-inline">If a financial institution receives a written request, or an oral request indicating that a written request will be provided, from an appropriate law enforcement agency indicating that providing a particular notice to any consumer under this section would impede a criminal or civil investigation by that law enforcement agency, the financial institution shall delay, or in the case of a foreign law enforcement agency may delay, providing such notice until the law enforcement agency informs the financial institution that such notice will no longer impede the investigation or the law enforcement agency fails to confirm that a continued delay is necessary to avoid impeding such investigation.</text></subsection> 
<subsection id="HB14B94BFD0DA4779BB0388B38B45E845"><enum>(e)</enum><header>Electronic transmission of notice</header><text>The written notice required under this section to any consumer may be made by an electronic transmission only if—</text> 
<paragraph id="H893BD54594C74CA190AA4F178004208"><enum>(1)</enum><text display-inline="yes-display-inline">the consumer has provided prior consent to receive any such notice by electronic transmission; and</text></paragraph> 
<paragraph id="H0641CE7FC51047DF8F1C041DFF3CC9D3"><enum>(2)</enum><text>the notice is consistent with the provisions permitting electronic transmission of notices under section 101 of the Electronic Signatures in Global and National Commerce Act.</text></paragraph></subsection></section> 
<section id="H80F00DF1E9A74C92B3EEB7BA53399069"><enum>5.</enum><header>Mitigation procedures</header> 
<subsection id="HAB4E0051688B4D42A8B4D1C9AFF585C"><enum>(a)</enum><header>Free file monitoring</header><text display-inline="yes-display-inline">Any financial institution that is required to provide notice to a consumer under section 4(a)(1) with respect to a breach of data security described in section 4(c) shall, if requested by the consumer before the end of the 90-day period beginning on the date of such notice, make available to the consumer, free of charge and for a 12-month period, a service that monitors nationwide credit activity regarding the consumer from a consumer reporting agency described in section 603(p) of the Fair Credit Reporting Act.</text></subsection> 
<subsection id="H5E84389425994F09950909D891EB4F82"><enum>(b)</enum><header>Joint rulemaking for safe harbor</header><text display-inline="yes-display-inline">The Federal Trade Commission, in consultation with the regulatory agencies described in section 8, shall develop regulations, which shall be prescribed by all functional regulatory agencies, that, in any case in which—</text> 
<paragraph id="HBD98641114394D0D938866ABF7B5BA3E"><enum>(1)</enum><text>free file monitoring is offered under subsection (a) to a consumer;</text></paragraph> 
<paragraph id="H7CDB5B808A9A40689C9067B895FFE284"><enum>(2)</enum><text>subsequent to the offer, another party misuses sensitive financial identity information on the consumer obtained through the breach of data security (that gave rise to such offer) to commit identity theft against the consumer; and</text></paragraph> 
<paragraph id="H66F7B19AB8914B8B8FBCCD546F59D01"><enum>(3)</enum><text>at the time of such breach the financial institution maintained reasonable policies and procedures to comply with subsection (a),</text></paragraph><continuation-text continuation-text-level="subsection">exempts the financial institution from any liability under State common law for any loss or harm to the consumer occurring after the end of a reasonable period beginning on the date of such offer, other than any direct pecuniary loss provided under such law, resulting from such misuse.</continuation-text></subsection></section> 
<section id="HB000F6F58AB549B4BFD0E3CB2EE40409" display-inline="no-display-inline" section-type="subsequent-section"><enum>6.</enum><header>Proper disposal of personal information</header> 
<subsection id="H2B7E078550094C718727ADC95F376E6"><enum>(a)</enum><header>In general</header><text display-inline="yes-display-inline">Before the end of the 6-month period beginning on the date of the enactment of this Act, the Federal Trade Commission shall prescribe regulations in final form requiring any financial institution which maintains or otherwise possesses sensitive financial personal information, or any compilation of such information, for a business purpose to properly dispose of any such information or compilation so that such information or compilation cannot practicably be read or reconstructed.</text></subsection> 
<subsection id="H0422941385C9406DA0BFD9A3B58800F3"><enum>(b)</enum><header>Rule of construction</header><text display-inline="yes-display-inline">No provision of this section shall be construed—</text> 
<paragraph id="H73C33C1551934687B669CB00119C90C7"><enum>(1)</enum><text display-inline="yes-display-inline">as requiring, or authorizing the Federal Trade Commission to require, any person to maintain or destroy any sensitive financial personal information that is not required to be maintained or destroyed under any other provision of Federal or State law; or </text></paragraph> 
<paragraph id="H1CF7B69F5CEE492A8919052BDED2C7F4"><enum>(2)</enum><text display-inline="yes-display-inline">as altering or affecting any requirement imposed under any other provision of Federal or State law to maintain or destroy sensitive financial personal information.</text></paragraph></subsection></section> 
<section id="HC1FE68AC19CA40F2B800A1FC43074304" display-inline="no-display-inline" section-type="subsequent-section"><enum>7.</enum><header>Relation to State law</header><text display-inline="no-display-inline">The provisions of this Act shall supersede any law, rule, or regulation of any State or political subdivision of any State that relates in any way to—</text> 
<paragraph id="HD96B77DA27124C899D4F5EEE6B81ABFD"><enum>(1)</enum><text display-inline="yes-display-inline">information security standards of financial institutions; or</text></paragraph> 
<paragraph id="H4A32EA5F05CA4F67B04EE6D79CEE0413"><enum>(2)</enum><text display-inline="yes-display-inline">the notification of consumers by financial institutions with respect to any breach of the confidentiality or security of information maintained or received by or on behalf of the financial institutions.</text></paragraph></section> 
<section id="H80CD37F549574CE4AE07D7978262D995" display-inline="no-display-inline" section-type="subsequent-section"><enum>8.</enum><header>Administrative enforcement</header><text display-inline="no-display-inline">This Act and any regulation prescribed under this Act shall be enforced with respect to financial institutions and other persons to which this Act applies exclusively by the functional financial regulators, and by the chief law enforcement officer of a State, or an official or agency designated by a State (with respect to persons within the jurisdiction of such officer, official, or agency), as follows:</text> 
<paragraph id="HBE079C87A70B4433B8D3B14D17377EF"><enum>(1)</enum><text>Under section 8 of the Federal Deposit Insurance Act, in the case of—</text> 
<subparagraph id="H95D98C3D9D464A4EBB408BA024746D4D"><enum>(A)</enum><text>national banks, Federal branches and Federal agencies of foreign banks, and any subsidiaries of such entities (except brokers, dealers, persons providing insurance, investment companies, and investment advisers), by the Comptroller of the Currency;</text></subparagraph> 
<subparagraph id="HD62F3C3C071D46FD91AEC74D2DC08E00"><enum>(B)</enum><text>member banks of the Federal Reserve System (other than national banks), branches and agencies of foreign banks (other than Federal branches, Federal agencies, and insured State branches of foreign banks), commercial lending companies owned or controlled by foreign banks, organizations operating under section 25 or 25A of the Federal Reserve Act, and bank holding companies and their nonbank subsidiaries or affiliates (except brokers, dealers, persons providing insurance, investment companies, and investment advisers), by the Board of Governors of the Federal Reserve System;</text></subparagraph> 
<subparagraph id="H1D670CE75B734A94979C7DEAAC88098E"><enum>(C)</enum><text>banks insured by the Federal Deposit Insurance Corporation (other than members of the Federal Reserve System), insured State branches of foreign banks, and any subsidiaries of such entities (except brokers, dealers, persons providing insurance, investment companies, and investment advisers), by the Board of Directors of the Federal Deposit Insurance Corporation; and</text></subparagraph> 
<subparagraph id="H9ABB2E8F1ECC4C4986C892C850316522"><enum>(D)</enum><text>savings associations the deposits of which are insured by the Federal Deposit Insurance Corporation, and any subsidiaries of such savings associations (except brokers, dealers, persons providing insurance, investment companies, and investment advisers), by the Director of the Office of Thrift Supervision.</text></subparagraph></paragraph> 
<paragraph id="H8B4D8D9459554C0A815321F8476D52E0"><enum>(2)</enum><text>Under the Federal Credit Union Act, by the Board of the National Credit Union Administration with respect to any federally insured credit union, and any subsidiaries of such an entity.</text></paragraph> 
<paragraph id="HF7EF2E4900EB4E31965706EA8765C8B6"><enum>(3)</enum><text>Under the Securities Exchange Act of 1934, by the Securities and Exchange Commission with respect to any broker or dealer.</text></paragraph> 
<paragraph id="H2F8519D76BB34B0497B634C3009D6FAC"><enum>(4)</enum><text>Under the Investment Company Act of 1940, by the Securities and Exchange Commission with respect to investment companies.</text></paragraph> 
<paragraph id="HE8393EE8E2344F31A38D44B5B0CB00B8"><enum>(5)</enum><text>Under the Investment Advisers Act of 1940, by the Securities and Exchange Commission with respect to investment advisers registered with the Commission under such Act.</text></paragraph> 
<paragraph id="H00F04B331521482BAD6500B15D35A1FA"><enum>(6)</enum><text>Under State insurance law, in the case of any person engaged in the business of insurance, by the applicable State insurance authority of the State in which the person is domiciled.</text></paragraph> 
<paragraph id="HB407AC8C08ED401F85C02970BC6E969B"><enum>(7)</enum><text>Under the Federal Trade Commission Act, by the Federal Trade Commission for any other person that is not subject to the jurisdiction of any agency or authority under paragraphs (1) through (6) of this subsection.</text></paragraph></section> 
<section id="HC8D20B81BBAF43A896CD1771A6C2B054"><enum>9.</enum><header>Definitions</header><text display-inline="no-display-inline">For purposes of this Act, the following definitions shall apply:</text> 
<paragraph id="H71243B222C9747C99BC26E79C317E700"><enum>(1)</enum><header>Breach of data security</header><text display-inline="yes-display-inline">The term <quote>breach of data security</quote> means, with respect to sensitive financial personal information that is maintained, received, or communicated by or on behalf of any financial institution—</text> 
<subparagraph id="HD4FD274F60B84F42965472F1C202AEFF"><enum>(A)</enum><text>an unauthorized acquisition of such information that could be used to commit financial fraud; or</text></subparagraph> 
<subparagraph id="HD6BE01825D6A49A8824DA6F320FDA9A7"><enum>(B)</enum><text>an unusual pattern of misuse of such information to commit financial fraud.</text></subparagraph></paragraph> 
<paragraph id="H650259AE97304B46852729B44E7E70A"><enum>(2)</enum><header>Consumer</header><text>The term <quote>consumer</quote> means an individual. </text></paragraph> 
<paragraph id="H682362392DF048E28E931EAEC77B493D"><enum>(3)</enum><header>Financial institution</header><text>The term <quote>financial institution</quote> means—</text> 
<subparagraph id="H0955BEA117D442388D756740EC3B4160"><enum>(A)</enum><text>any person the business of which is engaging in activities that are financial in nature as described in or determined under section 4(k) of the Bank Holding Company Act;</text></subparagraph> 
<subparagraph id="HA16617384D8A46879FBDAA976604841F"><enum>(B)</enum><text display-inline="yes-display-inline">any entity that is primarily engaged in activities that are subject to the Fair Credit Reporting Act; and</text></subparagraph> 
<subparagraph id="H8B20F84C0858447C8868329213260083"><enum>(C)</enum><text display-inline="yes-display-inline">any person that is maintaining, receiving, or communicating sensitive financial personal information on an ongoing basis for the purposes of engaging in interstate commerce.</text></subparagraph></paragraph> 
<paragraph id="H7A34142B34E0400CA2DB162B8D5D2022"><enum>(4)</enum><header>Functional financial regulator</header><text>The term <quote>functional financial regulator</quote>—</text> 
<subparagraph id="HD75EC43E26D9493499C417B9EEF9BE14"><enum>(A)</enum><text>has the same meaning as in section 509(2) of the Gramm-Leach-Bliley Act; and</text></subparagraph> 
<subparagraph id="H7764FAD442B44162B2024253F9E2CEC3"><enum>(B)</enum><text>in the case of any financial institution that is described in paragraph (3)(B) that is not subject to the Gramm-Leach-Bliley Act, includes the appropriate regulator for such financial institution under section 621 of the Fair Credit Reporting Act.</text></subparagraph></paragraph> 
<paragraph id="HA862FFCA4AE44B0BABB9506F40008670"><enum>(5)</enum><header>Sensitive financial personal information</header> 
<subparagraph id="H206AE6BB7E8D4D8100F5FF023BCB73A7"><enum>(A)</enum><header>In general</header><text>The term <quote>sensitive financial personal information</quote> means information that is personal, sensitive, and nonpublic and contains an individual’s first and last name and either the individual’s address or telephone number and appears in combination with any of the following:</text> 
<clause id="HEC7F3A3DE5E24181A0FAC4637CEF1EAA"><enum>(i)</enum><text>Social Security number.</text></clause> 
<clause id="HAAC248E47B6242E6B6FB281B9D41937F"><enum>(ii)</enum><text>Driver’s license number or an equivalent State-issued identification number.</text></clause> 
<clause id="H4D7E5FD3BC5247C3B4F204ECC25F94D4"><enum>(iii)</enum><text display-inline="yes-display-inline">Taxpayer identification number.</text></clause> 
<clause id="H8B5EACF68C95491EB6446400B552E4F9" display-inline="no-display-inline"><enum>(iv)</enum><text>Any credit card or debit card account number.</text></clause> 
<clause id="H348AD98EDD97432296FE3E05874FF597"><enum>(v)</enum><text display-inline="yes-display-inline">Any bank, savings association, credit union, or investment account number, other than an account number described in clause (iv), in combination with any required security code, biometric code, password, or other means that would permit access to a consumer’s financial account.</text></clause></subparagraph> 
<subparagraph id="HFFB31B4B73A94CDE8222B19DFAD3EE3C"><enum>(B)</enum><header>Exclusions</header><text display-inline="yes-display-inline">The term <quote>sensitive financial personal information</quote> shall not include—</text> 
<clause id="HA4FF18D6F9444AC9BA7117DD5F7E982C"><enum>(i)</enum><text>any list, description or other grouping of individuals (and publicly available information pertaining to them) that is derived without using any sensitive personal information; or</text></clause> 
<clause id="HCB4F23BAC5AC47A6A33223F5008266FC"><enum>(ii)</enum><text>publicly available information that is lawfully made available to the general public from Federal, State or local government records.</text></clause></subparagraph></paragraph></section> 
</legis-body> 
</bill> 


