<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" dms-id="HA215C12868B54F3DAFE368C7622BEDB8" public-private="public" bill-type="olc"> 
<metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>109 HR 4127 IH: Data Accountability and Trust Act (DATA)</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2005-10-25</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form> 
<distribution-code display="yes">I</distribution-code> 
<congress>109th CONGRESS</congress> <session>1st Session</session> 
<legis-num>H. R. 4127</legis-num> 
<current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber> 
<action> 
<action-date date="20051025">October 25, 2005</action-date> 
<action-desc><sponsor name-id="S000822">Mr. Stearns</sponsor> (for himself, <cosponsor name-id="P000555">Ms. Pryce of Ohio</cosponsor>, <cosponsor name-id="U000031">Mr. Upton</cosponsor>, <cosponsor name-id="R000004">Mr. Radanovich</cosponsor>, <cosponsor name-id="B000220">Mr. Bass</cosponsor>, <cosponsor name-id="B001228">Mrs. Bono</cosponsor>, <cosponsor name-id="F000443">Mr. Ferguson</cosponsor>, and <cosponsor name-id="B001243">Mrs. Blackburn</cosponsor>) introduced the following bill; which was referred to the <committee-name committee-id="HIF00">Committee on Energy and Commerce</committee-name></action-desc> 
</action> 
<legis-type>A BILL</legis-type> 
<official-title>To protect consumers by requiring reasonable security policies and procedures to protect computerized data containing personal information, and to provide for nationwide notice in the event of a security breach.</official-title> 
</form> 
<legis-body id="H5DF83CD33709441F9D18BAE200BE8DA" style="OLC"> 
<section id="HB8AB8A9EE0454FE5992000D426607701" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Data Accountability and Trust Act (DATA)</short-title></quote>.</text></section> 
<section id="HA3FDA2483FFD4347831DF371F96EFE2F"><enum>2.</enum><header>Requirements for information security</header> 
<subsection id="H5832D8B394C748A3ABF3D6352407FCB"><enum>(a)</enum><header>General security policies and procedures</header> 
<paragraph id="HD776F138AFA045E5A9872766D8E73523"><enum>(1)</enum><header>Regulations</header><text>Not later than 1 year after the date of enactment of this Act, the Commission shall promulgate regulations to require each person engaged in interstate commerce that owns or possesses data in electronic form containing personal information to establish and implement policies and procedures regarding information security practices for the treatment and protection of personal information that are consistent with—</text> 
<subparagraph id="H6CDD3B21913F4361B86DCDA58F461DB"><enum>(A)</enum><text>the size of, and the nature, scope, and complexity of the activities engaged in by, such person;</text></subparagraph> 
<subparagraph id="HF92FB0A7948446CBB61D49DFCB6D767D"><enum>(B)</enum><text>the current state of the art in administrative, technical, and physical safeguards for protecting such information; and</text></subparagraph> 
<subparagraph id="HA99F31427CE4440196A61169AC3896C7"><enum>(C)</enum><text>the cost of implementing such safeguards.</text></subparagraph></paragraph> 
<paragraph id="H7D064791124E48E6AD885F83E0274DE9"><enum>(2)</enum><header>Requirements</header><text>Such regulations shall require the policies and procedures to include the following:</text> 
<subparagraph id="HDBAAEC89C43A49B4B76B5E84DF92ED63" commented="no"><enum>(A)</enum><text display-inline="yes-display-inline">A security policy with respect to the collection, use, sale, other dissemination, and maintenance of such personal information.</text> </subparagraph> 
<subparagraph id="HA9FEF4B4545F4914B762F776BD1CCA3"><enum>(B)</enum><text display-inline="yes-display-inline">The identification of an officer or other individual as the point of contact with responsibility for the management of information security.</text></subparagraph> 
<subparagraph id="H03B2C36B466149D981B2A01EE6405698" commented="no"><enum>(C)</enum><text display-inline="yes-display-inline">A process for identifying and assessing any reasonably foreseeable vulnerabilities in the system maintained by such person that contains such electronic data.</text></subparagraph> 
<subparagraph id="HC2614548C0654481BE16CF00E5004E09" commented="no"><enum>(D)</enum><text>A process for taking preventive and corrective action to mitigate against any vulnerabilities identified in the process required by subparagraph (C), which may include encryption of such data, implementing any changes to security practices and the architecture, installation, or implementation of network or operating software.</text></subparagraph> </paragraph> </subsection> 
<subsection id="HA1F766593B1846FCB6B3C502E23EBDB" commented="no"><enum>(b)</enum><header>Special requirements for information brokers</header> 
<paragraph id="H4FC9A6D33A00423280C663F1883CC6CD" commented="no"><enum>(1)</enum><header>Submission of policies to the FTC</header><text>The regulations promulgated under subsection (a) shall require information brokers to submit their security policies to the Commission on an annual basis.</text></paragraph> 
<paragraph id="HF6B7D5745CC547F091B16D005ED79454"><enum>(2)</enum><header>Post-breach audit</header><text>Following a breach of security of an information broker, the Commission shall conduct an audit of the information security practices of such information broker. The Commission may conduct additional audits, on an annual basis, for a maximum of 5 years following the breach of security or until the Commission determines that the security practices of the information broker are in compliance with the requirements of this section and are adequate to prevent further breaches of security.</text> </paragraph> 
<paragraph id="HE8EF74B371BA49C7805C35C5FD7E5814" commented="no"><enum>(3)</enum><header>Individual access to personal information</header> 
<subparagraph id="H40D95C99E5BA44C69242C2914FA402C4" commented="no"><enum>(A)</enum><header>Access to information</header><text>Each information broker shall—</text> 
<clause id="H5105CA593AD34DBABFF6E771B781150"><enum>(i)</enum><text>provide to each individual whose personal information it maintains, at the individual’s request at least one time per year and at no cost to the individual, a means for such individual to review any personal information of the individual maintained by the information broker and any other information about the individual maintained by the information broker; and</text></clause> 
<clause id="H76BB17826E9441A0BB177F6CB895D625"><enum>(ii)</enum><text>place a conspicuous notice on its Internet website (if the information broker maintains such a website) instructing individuals how to request access to the information required to be provided under clause (i).</text></clause></subparagraph> 
<subparagraph id="H9387AB58C4C7446E98E185002FC15443" commented="no"><enum>(B)</enum><header>Disputed information</header><text>Whenever an individual whose information the information broker maintains files a written request disputing the accuracy of any such information, unless there is reasonable grounds to believe such request is frivolous or irrelevant, the information broker shall clearly note in the database maintained by such information broker, and in any subsequent transmission of such information by such information broker, that such information is disputed by the individual to whom the information relates. Such note shall include either the individual’s statement disputing the accuracy of such information or a clear and concise summary thereof.</text></subparagraph> </paragraph> </subsection></section> 
<section id="HF8DAA0F6A0914B50A399AB14A5AFB862"><enum>3.</enum><header>Notification of information security breach</header> 
<subsection id="H19A253B21FD04FAFBEEB1852169BE3E5"><enum>(a)</enum><header>Nationwide Notification</header><text>Any person engaged in interstate commerce that owns or possesses data in electronic form containing personal information shall, following the discovery of a breach of security of the system maintained by such person that contains such data—</text> 
<paragraph id="HDAB3B5B4B5CA4A8DAB857C38BF5E88F6"><enum>(1)</enum><text>notify each individual of the United States whose personal information was acquired by an unauthorized person as a result of such a breach of security;</text></paragraph> 
<paragraph id="H57BAB4BAFE264A9E92EA567DF5ED6995"><enum>(2)</enum><text>notify the Commission;</text></paragraph> 
<paragraph id="H4444BB3C874D4BF8821E668FF0967B2E"><enum>(3)</enum><text display-inline="yes-display-inline">place a conspicuous notice on the Internet website of the person (if such person maintains such a website), which shall include a telephone number that the individual may use, at no cost to such individual, to contact the person to inquire about the security breach or the information the person maintained about that individual; and</text></paragraph> 
<paragraph id="H2345C22E30954E3A82740053A331D57F"><enum>(4)</enum><text>in the case of a breach of financial account information of a merchant, notify the financial institution that issued the account.</text></paragraph> </subsection> 
<subsection id="H5C32873806E24EEC96E0A6CBC0BCF8D"><enum>(b)</enum><header>Timeliness of notification</header><text>All notifications required under subsection (a) shall be made as promptly as possible and without unreasonable delay following the discovery of a breach of security of the system and any measures necessary to determine the scope of the breach, prevent further breach or unauthorized disclosures, and reasonably restore the integrity of the data system.</text></subsection> 
<subsection id="H3EA29AA78427493086F7EB001BFA2634"><enum>(c)</enum><header>Method and content of notification</header> 
<paragraph id="H4CA3E27F5D194FBB981344A0EA7BFE14" commented="no"><enum>(1)</enum><header>Direct notification</header> 
<subparagraph id="H0F4B0758660C4B9982E881F651808130" commented="no"><enum>(A)</enum><header>Method of notification</header><text display-inline="yes-display-inline">A person required to provide notification to individuals under subsection (a)(1) shall be in compliance with such requirement if the person provides conspicuous and clearly identified notification by one of the following methods (provided the selected method can reasonably be expected to reach the intended individual):</text> 
<clause id="HFFF5638D5D814766AFBB5CB8082BCD04" commented="no"><enum>(i)</enum><text>Written notification.</text></clause> 
<clause id="H803D646573EB4A7BB16631B761ED7347" commented="no"><enum>(ii)</enum><text>Email notification, if the individual has consented to receive such notification and the notification is provided in a manner that is consistent with the provisions permitting electronic transmission of notices under section 101 of the Electronic Signatures in Global Commerce Act (<external-xref legal-doc="usc" parsable-cite="usc/15/7001">15 U.S.C. 7001</external-xref>).</text></clause></subparagraph> 
<subparagraph id="H1E962132D04F4A96B72D7F6FEA71118E" commented="no"><enum>(B)</enum><header>Content of notification</header><text>Regardless of the method by which notification is provided to an individual under subparagraph (A), such notification shall include—</text> 
<clause id="HA9CA6384AD5B4DE38E66510879F0D3D" commented="no"><enum>(i)</enum><text>a description of the personal information that was acquired by an unauthorized person;</text></clause> 
<clause id="H5DC23BB61B8D4B679329C10833DD57A2" commented="no"><enum>(ii)</enum><text display-inline="yes-display-inline">a telephone number that the individual may use, at no cost to such individual, to contact the person to inquire about the security breach or the information the person maintained about that individual;</text></clause> 
<clause id="H730746D054514EB2A32D8FC070361CEF" commented="no"><enum>(iii)</enum><text display-inline="yes-display-inline">the toll-free contact telephone numbers and addresses for the major credit reporting agencies; and</text> </clause> 
<clause id="HED8C8F538BA04E6C8085F6FF7D806848" commented="no"><enum>(iv)</enum><text>a toll-free telephone number and Internet website address for the Commission whereby the individual may obtain information regarding identity theft.</text></clause> </subparagraph> </paragraph> 
<paragraph id="H6F6FDC0979854A4887A6AFC58795AF27" commented="no"><enum>(2)</enum><header>Substitute notification</header><text display-inline="yes-display-inline"><italic></italic></text> 
<subparagraph id="HB6E60A1C64104B47AFF8715F2BFE00B1"><enum>(A)</enum><header>Circumstances giving rise to substitute notification</header><text>A person required to provide notification to individuals under subsection (a)(1) may provide substitute notification in lieu of the direct notification required by paragraph (1) if such direct notification is not feasible due to—<italic></italic></text> 
<clause id="HEC5357CAFE43423782EDEDF9BCC1F00" commented="no"><enum>(i)</enum><text display-inline="yes-display-inline">excessive cost to the person required to provide such notification relative to the resources of such person, as determined in accordance with the regulations issued by the Commission under paragraph (3)(A); or</text></clause> 
<clause id="H4458C2A184D942639300A6DB72E4D388" commented="no"><enum>(ii)</enum><text>lack of sufficient contact information for the individual required to be notified.</text></clause></subparagraph> 
<subparagraph id="H37C4EC1D59D640B0BC6C9F3BB95FF4FE" commented="no"><enum>(B)</enum><header>Content of substitute notification</header><text display-inline="yes-display-inline">Such substitute notification shall include notification in print and broadcast media, including major media in metropolitan and rural areas where the individuals whose personal information was acquired reside. Such notification shall include a telephone number where an individual can, at no cost to such individual, learn whether or not that individual’s personal information is included in the security breach.</text></subparagraph></paragraph> 
<paragraph id="H84BF133065A740ACA0D3B333473D01B" commented="no"><enum>(3)</enum><header>Federal Trade Commission Regulations and Guidance</header> 
<subparagraph id="H22BB272882B54D12B6B9EE30B7FCE57D" commented="no"><enum>(A)</enum><header>Regulations</header><text>Not later than 270 days after the date of enactment of this Act, the Commission shall, by regulation, establish criteria for determining the circumstances under which substitute notification may be provided under paragraph (2), including criteria for determining if notification under paragraph (1) is not feasible due to excessive cost to the person required to provide such notification relative to the resources of such person. </text></subparagraph> 
<subparagraph id="HEA5C1C3FAEB54E0DAAD93F370255267E" commented="no"><enum>(B)</enum><header>Guidance</header><text>In addition, the Commission shall provide and publish general guidance with respect to compliance with this section. Such guidance shall include—</text> 
<clause id="HDBD246497D4D47688D8D7F7872C81800" commented="no"><enum>(i)</enum><text>a description of written or email notification that complies with the requirements of paragraph (1); and</text></clause> 
<clause id="HA48E7FBED32E4D9DB9B70772665FE6CC" commented="no"><enum>(ii)</enum><text>guidance on the content of substitute notification under paragraph (2)(B), including the extent of notification to print and broadcast media that complies with the requirements of such paragraph.</text> </clause></subparagraph></paragraph> </subsection> 
<subsection id="H9D7C5E7CB56447A7900046209EAAEF86"><enum>(d)</enum><header>Other obligations following breach</header><text display-inline="yes-display-inline">A person required to provide notification under subsection (a) shall provide or arrange for the provision of, to each individual to whom notification is provided under subsection (c)(1) and at no cost to such individual, consumer credit reports from at least one of the major credit reporting agencies beginning not later than 2 months following a breach of security and continuing on a quarterly basis for a period of 2 years thereafter. The Commission shall, by regulation, provide alternative requirements under this subsection for persons who qualify to provide substitute notification under subsection (c)(2).</text> </subsection> 
<subsection id="H5198F001D39D4DF9985C565600199342" commented="no"><enum>(e)</enum><header>Website notice of Federal Trade Commission</header><text>The Commission shall place, in a clear and conspicuous location on its Internet website, a notice of any breach of security that is reported to the Commission under subsection (a)(2).</text></subsection></section> 
<section id="H2A60721C88E6450487E3641D1573A662"><enum>4.</enum><header>Enforcement by the Federal Trade Commission</header> 
<subsection id="HA991E0AE5B9D44B1B10040903C595F46" commented="no"><enum>(a)</enum><header>Unfair or deceptive acts or practices</header><text>A violation of section 2 or 3 shall be treated as a violation of a regulation under section 18(a)(1)(B) of the <act-name parsable-cite="FTCA">Federal Trade Commission Act</act-name> (15 U.S.C. 57<italic>a</italic>(a)(1)(B)) regarding unfair or deceptive acts or practices. </text></subsection> 
<subsection id="H97F3B3A336014E1D9B40D909CFE8178B" commented="no"><enum>(b)</enum><header>Powers of Commission</header><text>The Commission shall enforce this Act in the same manner, by the same means, and with the same jurisdiction, powers, and duties as though all applicable terms and provisions of the <act-name parsable-cite="FTCA">Federal Trade Commission Act</act-name> (<external-xref legal-doc="usc" parsable-cite="usc/15/41">15 U.S.C. 41 et seq.</external-xref>) were incorporated into and made a part of this Act. Any person who violates such regulations shall be subject to the penalties and entitled to the privileges and immunities provided in that Act. Nothing in this Act shall be construed to limit the authority of the Commission under any other provision of law.</text></subsection> </section> 
<section id="H4AC760F2679646F386852C04C8D4A7C0"><enum>5.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act the following definitions apply:</text> 
<paragraph id="H2D3136C3E7AC475C8E2F3CB536D56594" commented="no"><enum>(1)</enum><header>Breach of security</header><text>The term <term>breach of security</term> means the unauthorized acquisition of data in electronic form containing personal information that establishes a reasonable basis to conclude that there is a significant risk of identity theft to the individual to whom the personal information relates. The encryption of such data, combined with appropriate safeguards of the keys necessary to enable decryption of such data, shall establish a presumption that no such reasonable basis exists. Any such presumption may be rebutted by facts demonstrating that the method of encryption has been or is likely to be compromised.</text> </paragraph> 
<paragraph id="H4053E3B0048D4BC6BD004287C1BB5CA3"><enum>(2)</enum><header>Commission</header><text>The term <term>Commission</term> means the Federal Trade Commission.</text></paragraph> 
<paragraph id="HDDDCDC38954C461A96616C2700EF85C" commented="no"><enum>(3)</enum><header>Data in electronic form</header><text display-inline="yes-display-inline">The term <term>data in electronic form</term> means any data stored electronically or digitally on any computer system or other database and includes recordable tapes and other mass storage devices.</text></paragraph> 
<paragraph id="H5D46A1D2B1F7408790F27521A9E48CAC" commented="no"><enum>(4)</enum><header>Encryption</header><text>The term <term>encryption</term> means the protection of data in electronic form in storage or in transit using an encryption algorithm implemented within a validated cryptographic module that has been approved by the National Institute of Standards and Technology or another comparable standards body recognized by the Commission, rendering such data indecipherable in the absence of associated cryptographic keys necessary to enable decryption of such data. Such encryption must include appropriate management and safeguards of such keys to protect the integrity of the encryption.</text></paragraph> 
<paragraph id="H02E2B0BF939E42ABAE7CD7DCB2A4BF9" commented="no"><enum>(5)</enum><header>Identity theft</header><text display-inline="yes-display-inline">The term <term>identity theft</term> means the unauthorized assumption of another person’s identity for the purpose of engaging in commercial transactions under the name of such other person.</text></paragraph> 
<paragraph id="H4211CD0B795D47C1A5DBE72DF32F90CD" commented="no"><enum>(6)</enum><header>Information broker</header><text display-inline="yes-display-inline">The term <term>information broker</term> means a commercial entity whose business is to collect, assemble, or maintain personal information concerning individuals who are not customers of such entity for the sale or transmission of such information or the provision of access to such information to any third party, whether such collection, assembly, or maintenance of personal information is performed by the information broker directly, or by contract or subcontract with any other entity.</text></paragraph> 
<paragraph id="HEDA963841DB94253AE957C96FE582B00"><enum>(7)</enum><header>Personal information</header> 
<subparagraph id="H6E61BBA3FB9A4B02A4007BCA60F547DB"><enum>(A)</enum><header>Definition</header><text>The term <term>personal information</term> means an individual’s first and last name in combination with any 1 or more of the following data elements for that individual:</text> 
<clause id="HFD077FC4766D41918297C3EBCF5095"><enum>(i)</enum><text>Social Security number.</text></clause> 
<clause id="H48FECE192D4E437BB09362D0444260DE"><enum>(ii)</enum><text>Driver’s license number or other State identification number.</text></clause> 
<clause id="HAA884F4C713C41638D00675102A21097"><enum>(iii)</enum><text>Financial account number, or credit or debit card number, and any required security code, access code, or password that is necessary to permit access to an individual’s financial account.</text></clause> </subparagraph> 
<subparagraph id="H9B85FA11C48248058523F319F8DAA87" commented="no"><enum>(B)</enum><header>Modified definition by rulemaking</header><text>The Commission may, by rule, modify the definition of <quote>personal information</quote> under subparagraph (A) to the extent that such modification is necessary to accommodate changes in technology or practices, will not unreasonably impede interstate commerce, and will accomplish the purposes of this Act.</text></subparagraph></paragraph> 
<paragraph id="H8A458958843042B891D3BE47C560661"><enum>(8)</enum><header>Person</header><text>The term <term>person</term> has the same meaning given such term in <external-xref legal-doc="usc" parsable-cite="usc/5/551">section 551(2)</external-xref> of title 5, United States Code.</text></paragraph></section> 
<section id="HD16E549297A5480C98073DE3DC898F6B"><enum>6.</enum><header>Effect on other laws</header> 
<subsection id="H054D10521D7E476192E1230471EE5EB5"><enum>(a)</enum><header>Preemption of State information security laws</header><text display-inline="yes-display-inline">This Act supersedes any provision of a statute, regulation, or rule of a State or political subdivision of a State that expressly—</text> 
<paragraph id="H5D5D1C24C75C4292A6CA56F1742FA9D7"><enum>(1)</enum><text display-inline="yes-display-inline">requires information security practices and treatment of personal information similar to any of those required under section 2; and</text></paragraph> 
<paragraph id="H3630E432B88D4095B07CFC0093446E00"><enum>(2)</enum><text>requires notification to individuals of a breach of security resulting in unauthorized acquisition of their personal information.</text></paragraph></subsection> 
<subsection id="H067F45C1BE984DDFB34C393034FCB7E3"><enum>(b)</enum><header>Additional preemption</header> 
<paragraph id="HD255646531DC41BEA0CF776194D375D1"><enum>(1)</enum><header>In general</header><text>No person other than the Attorney General of a State may bring a civil action under the laws of any State if such action is premised in whole or in part upon the defendant violating any provision of this Act. </text></paragraph> 
<paragraph id="HF9205D36525E43B6A79D6D96928CCB85"><enum>(2)</enum><header>Protection of consumer protection laws</header><text>This subsection shall not be construed to limit the enforcement of any State consumer protection law by an Attorney General of a State.</text></paragraph></subsection> 
<subsection id="H4390CC8867C8454D942D50CB6EA3CB34"><enum>(c)</enum><header>Protection of certain State laws</header><text>This Act shall not be construed to preempt the applicability of—</text> 
<paragraph id="HFDCD090F968F4B308CF657AD8DE49D13"><enum>(1)</enum><text>State trespass, contract, or tort law; or</text></paragraph> 
<paragraph id="H61B867BB51BB4DEF82087F00CC32592C"><enum>(2)</enum><text>other State laws to the extent that those laws relate to acts of fraud.</text></paragraph></subsection></section> 
<section id="HAB10178F1E0043CFABE95424BCC3E84D"><enum>7.</enum><header>Effective Date and Sunset</header> 
<subsection id="HD261B5916E014181A2307E337C15DD7C"><enum>(a)</enum><header>Effective Date</header><text display-inline="yes-display-inline">This Act shall take effect 1 year after the date of enactment of this Act.</text></subsection> 
<subsection id="H5BB85B648D5F4F91BF4F7497CB1C4FB5"><enum>(b)</enum><header>Sunset</header><text>This Act shall cease to be in effect on the date that is 10 years from the date of enactment of this Act.</text></subsection></section> 
<section id="H1708F3A0152F493BBABC0463FB3D0818"><enum>8.</enum><header>Authorization of Appropriations</header><text display-inline="no-display-inline">There is authorized to be appropriated to the Commission $1,000,000 for each of fiscal years 2006 through 2010 to carry out this Act.</text></section> 
</legis-body> 
</bill> 


