<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" public-private="public">

	<form>

		<distribution-code>II</distribution-code>

		<congress>109th CONGRESS</congress>

		<session>1st Session</session>

		<legis-num>S. 115</legis-num>

		<current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber>

		<action>

			<action-date date="20050124">January 24, 2005</action-date>

			<action-desc><sponsor name-id="S221">Mrs. Feinstein</sponsor>

			 introduced the following bill; which was read twice and referred to the

			 <committee-name committee-id="SSJU00">Committee on the

			 Judiciary</committee-name></action-desc>

		</action>

		<legis-type>A BILL</legis-type>

		<official-title>To require Federal agencies, and persons engaged in

		  interstate commerce, in possession of electronic data containing personal

		  information, to disclose any unauthorized acquisition of such

		  information.</official-title>

	</form>

	<legis-body>

		<section id="ID9E4C477B18C84D0D93D4D5DA45DDEA68" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the

			 <quote><short-title>Notification of Risk to Personal Data

			 Act</short-title></quote>.</text>

		</section><section id="ID04ABDA3AA06445BFB9E2BA178B154892"><enum>2.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act, the following definitions shall

			 apply:</text>

			<paragraph id="IDE8BE4305C4114046BA8747407B1D2C13"><enum>(1)</enum><header>Agency</header><text>The

			 term <term>agency</term> has the same meaning given such term in section 551(1)

			 of title 5, United States Code.</text>

			</paragraph><paragraph id="IDA4C5422D4BEB43149390DB00B309D0C5"><enum>(2)</enum><header>Breach of

			 security of the system</header><text>The term <term>breach of security of the

			 system</term>—</text>

				<subparagraph id="IDFFF9A0F5738A4553836BDF822DE45E1D"><enum>(A)</enum><text>means the

			 compromise of the security, confidentiality, or integrity of computerized data

			 that results in, or there is a reasonable basis to conclude has resulted in,

			 the unauthorized acquisition of and access to personal information maintained

			 by the person or business; and</text>

				</subparagraph><subparagraph id="ID524B0CEC1A574925BEF68073AA4C5192"><enum>(B)</enum><text>does not include

			 good faith acquisition of personal information by an employee or agent of the

			 person or business for the purposes of the person or business, if the personal

			 information is not used or subject to further unauthorized disclosure.</text>

				</subparagraph></paragraph><paragraph id="ID3BD7BF1CAE5543A2904605036C6D0998"><enum>(3)</enum><header>Person</header><text>The

			 term <term>person</term> has the same meaning given such term in section 551(2)

			 of title 5, United States Code.</text>

			</paragraph><paragraph id="ID25899E3CA0234DAC81E992605E76F55F"><enum>(4)</enum><header>Personal

			 information</header><text>The term <term>personal information</term> means an

			 individual’s last name in combination with any 1 or more of the following data

			 elements, when either the name or the data elements are not encrypted:</text>

				<subparagraph id="ID456F512E956D48A0BF11A720BE947E50"><enum>(A)</enum><text>Social security

			 number.</text>

				</subparagraph><subparagraph id="IDFA0EEB00C5404490AD4C879855B301F0"><enum>(B)</enum><text>Driver’s license

			 number or State identification number.</text>

				</subparagraph><subparagraph id="IDB55E867AF53E4B3CAD7217937EA111A4"><enum>(C)</enum><text>Account number,

			 credit or debit card number, in combination with any required security code,

			 access code, or password that would permit access to an individual’s financial

			 account.</text>

				</subparagraph></paragraph><paragraph id="ID7458364F14D04163842B3BFAD47F1144"><enum>(5)</enum><header>Substitute

			 notice</header><text>The term <term>substitute notice</term> means—</text>

				<subparagraph id="IDA162028EA85A44FAA16655B8704B6460"><enum>(A)</enum><text>e-mail notice, if

			 the agency or person has an e-mail address for the subject persons;</text>

				</subparagraph><subparagraph id="ID3DDDD88F3BBF4FFCB464A9870009AFDD"><enum>(B)</enum><text>conspicuous

			 posting of the notice on the Internet site of the agency or person, if the

			 agency or person maintains an Internet site; or</text>

				</subparagraph><subparagraph id="ID0DE160948E2145299425738D009CE7E0"><enum>(C)</enum><text>notification to

			 major media.</text>

				</subparagraph></paragraph></section><section id="ID4E70210ACE054BD78535C6AD4163AC3B"><enum>3.</enum><header>Database

			 security</header>

			<subsection id="IDA19BA6060CB442CC9F50375841459EBA"><enum>(a)</enum><header>Disclosure of

			 security breach</header>

				<paragraph id="IDF033C0523221427FA5672285931CFA31"><enum>(1)</enum><header>In

			 general</header><text>Any agency, or person engaged in interstate commerce,

			 that owns or licenses electronic data containing personal information shall,

			 following the discovery of a breach of security of the system containing such

			 data, notify any resident of the United States whose unencrypted personal

			 information was, or is reasonably believed to have been, acquired by an

			 unauthorized person.</text>

				</paragraph><paragraph id="ID5899B85D2466423FAC5EA6CB421E48BF"><enum>(2)</enum><header>Notification of

			 owner or licensee</header><text>Any agency, or person engaged in interstate

			 commerce, in possession of electronic data containing personal information that

			 the agency does not own or license shall notify the owner or licensee of the

			 information if the personal information was, or is reasonably believed to have

			 been, acquired by an unauthorized person through a breach of security of the

			 system containing such data.</text>

				</paragraph><paragraph id="ID94DE951D4A344AAFA9909F7E81F2F170"><enum>(3)</enum><header>Timeliness of

			 notification</header><text>Except as provided in paragraph (4), all

			 notifications required under paragraph (1) or (2) shall be made as expediently

			 as possible and without unreasonable delay following—</text>

					<subparagraph id="ID68D780B191674467B7535891338F72BD"><enum>(A)</enum><text>the discovery by

			 the agency or person of a breach of security of the system; and</text>

					</subparagraph><subparagraph id="ID145C266BBC13445BB68E379D423408AC"><enum>(B)</enum><text>any measures

			 necessary to determine the scope of the breach, prevent further disclosures,

			 and restore the reasonable integrity of the data system.</text>

					</subparagraph></paragraph><paragraph id="ID3A13C01243A943458F191FDEDDF0EBB0"><enum>(4)</enum><header>Delay of

			 notification authorized for law enforcement purposes</header><text>If a law

			 enforcement agency determines that the notification required under this

			 subsection would impede a criminal investigation, such notification may be

			 delayed until such law enforcement agency determines that the notification will

			 no longer compromise such investigation.</text>

				</paragraph><paragraph id="ID9ED17A9905D64B0099B3424E35C0B2F3"><enum>(5)</enum><header>Methods of

			 notice</header><text>An agency, or person engaged in interstate commerce, shall

			 be in compliance with this subsection if it provides the resident, owner, or

			 licensee, as appropriate, with—</text>

					<subparagraph id="ID695ECCB2FDD942A0B500674BD610DE44"><enum>(A)</enum><text>written

			 notification;</text>

					</subparagraph><subparagraph id="ID69B23AA04FAF44BE0048FAD43175A963"><enum>(B)</enum><text>e-mail notice, if

			 the person or business has an e-mail address for the subject person; or</text>

					</subparagraph><subparagraph id="ID4029F90E15A742218B693F513071EFFD"><enum>(C)</enum><text>substitute

			 notice, if—</text>

						<clause id="ID0FDB3661897A43519327D451A8D25E00"><enum>(i)</enum><text>the

			 agency or person demonstrates that the cost of providing direct notice would

			 exceed $250,000;</text>

						</clause><clause id="IDEC48CA475D20481D892E8E81F768D8CD"><enum>(ii)</enum><text>the affected

			 class of subject persons to be notified exceeds 500,000; or</text>

						</clause><clause id="ID51D28F88478A489480F89066E656A9EE"><enum>(iii)</enum><text>the agency or

			 person does not have sufficient contact information for those to be

			 notified.</text>

						</clause></subparagraph></paragraph><paragraph id="ID64272B9B75E44A7BB100E44BE6DDD3C3"><enum>(6)</enum><header>Alternative

			 notification procedures</header><text>Notwithstanding any other obligation

			 under this subsection, an agency, or person engaged in interstate commerce,

			 shall be deemed to be in compliance with this subsection if the agency or

			 person—</text>

					<subparagraph id="IDFAE8969262504F98907BC3C344629645"><enum>(A)</enum><text>maintains its own

			 reasonable notification procedures as part of an information security policy

			 for the treatment of personal information; and</text>

					</subparagraph><subparagraph id="ID5FF1E0717AC3495CB410004BCE6DE949"><enum>(B)</enum><text>notifies subject

			 persons in accordance with its information security policy in the event of a

			 breach of security of the system.</text>

					</subparagraph></paragraph><paragraph id="ID723023B18BBE4052BFFE81D66F1E1609"><enum>(7)</enum><header>Reasonable

			 notification procedures</header><text>As used in paragraph (6), with respect to

			 a breach of security of the system involving personal information described in

			 section 2(4)(C), the term <term>reasonable notification procedures</term> means

			 procedures that—</text>

					<subparagraph id="IDFCD8C04572844BC3B5FE67CD04648E67"><enum>(A)</enum><text>use a security

			 program reasonably designed to block unauthorized transactions before they are

			 charged to the customer’s account;</text>

					</subparagraph><subparagraph id="IDD8D1743CF00F498990279D9DBDE65667"><enum>(B)</enum><text>provide for

			 notice to be given by the owner or licensee of the database, or another party

			 acting on behalf of such owner or licensee, after the security program

			 indicates that the breach of security of the system has resulted in fraud or

			 unauthorized transactions, but does not necessarily require notice in other

			 circumstances; and</text>

					</subparagraph><subparagraph id="ID71AE1B5022744037BE49CD1DEAC5D0BD"><enum>(C)</enum><text>are subject to

			 examination for compliance with the requirements of this Act by 1 or more

			 Federal functional regulators (as defined in section 509 of the Gramm-Leach

			 Bliley Act (<external-xref legal-doc="usc" parsable-cite="usc/15/6809">15

			 U.S.C. 6809</external-xref>)), with respect to the operation of the security

			 program and the notification procedures.</text>

					</subparagraph></paragraph></subsection><subsection id="ID7B1FA878C8B84D3BB3D95726E630F501"><enum>(b)</enum><header>Civil

			 remedies</header>

				<paragraph id="ID833BFF69219743AF8F38650900000077"><enum>(1)</enum><header>Penalties</header><text>Any

			 agency, or person engaged in interstate commerce, that violates this section

			 shall be subject to a fine of not more than $5,000 per violation, to a maximum

			 of $25,000 per day while such violations persist.</text>

				</paragraph><paragraph id="ID69434E1E6D094EE78F5E28F7CBAE1038"><enum>(2)</enum><header>Equitable

			 relief</header><text>Any person engaged in interstate commerce that violates,

			 proposes to violate, or has violated this section may be enjoined from further

			 violations by a court of competent jurisdiction.</text>

				</paragraph><paragraph id="ID051DFCF22E9A4023810433A0ADA1AC5C"><enum>(3)</enum><header>Other rights

			 and remedies</header><text>The rights and remedies available under this

			 subsection are cumulative and shall not affect any other rights and remedies

			 available under law.</text>

				</paragraph></subsection><subsection id="ID7EF96FCE72AA4F3E89A7194FB768BF2E"><enum>(c)</enum><header>Enforcement</header><text>The

			 Federal Trade Commission is authorized to enforce compliance with this section,

			 including the assessment of fines under subsection (b)(1).</text>

			</subsection></section><section id="ID4C95D762CFEC44DFADDF13B6B6832B49"><enum>4.</enum><header>Enforcement by

			 State attorneys general</header>

			<subsection id="ID4E326962B9924260952B56A77D130920"><enum>(a)</enum><header>In

			 general</header>

				<paragraph id="IDA3AB64B027B1444195CB00309F21A127"><enum>(1)</enum><header>Civil

			 actions</header><text>In any case in which the attorney general of a State has

			 reason to believe that an interest of the residents of that State has been or

			 is threatened or adversely affected by the engagement of any person in a

			 practice that is prohibited under this Act, the State, as parens patriae, may

			 bring a civil action on behalf of the residents of the State in a district

			 court of the United States of appropriate jurisdiction to—</text>

					<subparagraph id="ID1701083CCA624B41939519794BDB007C"><enum>(A)</enum><text>enjoin that

			 practice;</text>

					</subparagraph><subparagraph id="IDA3F57209FA51460EACEACEC9CEE81074"><enum>(B)</enum><text>enforce

			 compliance with this Act;</text>

					</subparagraph><subparagraph id="ID69D04AA823D04D67BCCCE19EA4E9791C"><enum>(C)</enum><text>obtain damage,

			 restitution, or other compensation on behalf of residents of the State;

			 or</text>

					</subparagraph><subparagraph id="IDFB89D907AAD94C21AB393777BB4FEF68"><enum>(D)</enum><text>obtain such other

			 relief as the court may consider to be appropriate.</text>

					</subparagraph></paragraph><paragraph id="ID0AC8FB0BEC1C499A89F9B0755B115C52"><enum>(2)</enum><header>Notice</header>

					<subparagraph id="IDE44754D9FA394117A918128D9E3E80A4"><enum>(A)</enum><header>In

			 general</header><text>Before filing an action under paragraph (1), the attorney

			 general of the State involved shall provide to the Attorney General—</text>

						<clause id="ID9E0DEFE2BCEA420F85DA56737C50F4BF"><enum>(i)</enum><text>written notice of

			 the action; and</text>

						</clause><clause id="IDE365DE3F9F2C41948DB5DF003400D800"><enum>(ii)</enum><text>a

			 copy of the complaint for the action.</text>

						</clause></subparagraph><subparagraph id="ID0CEA663D2ABA49D293CCE31BF097018E"><enum>(B)</enum><header>Exemption</header>

						<clause id="ID27FA47FA1E92406982DE1DDFAFB73494"><enum>(i)</enum><header>In

			 general</header><text>Subparagraph (A) shall not apply with respect to the

			 filing of an action by an attorney general of a State under this subsection, if

			 the State attorney general determines that it is not feasible to provide the

			 notice described in such subparagraph before the filing of the action.</text>

						</clause><clause id="ID74FC7E4BE0784097AF66CA566BDC351E"><enum>(ii)</enum><header>Notification</header><text>In

			 an action described in clause (i), the attorney general of a State shall

			 provide notice and a copy of the complaint to the Attorney General at the time

			 the State attorney general files the action.</text>

						</clause></subparagraph></paragraph></subsection><subsection id="IDA0226CA9E9C84452A7F453CE5D56EFEF"><enum>(b)</enum><header>Construction</header><text>For

			 purposes of bringing any civil action under subsection (a), nothing in this Act

			 shall be construed to prevent an attorney general of a State from exercising

			 the powers conferred on such attorney general by the laws of that State

			 to—</text>

				<paragraph id="IDBD1ADD63A9FE47CB82BE90708CC31958"><enum>(1)</enum><text>conduct

			 investigations;</text>

				</paragraph><paragraph id="IDD7718550D31F42ADB7CA6CA3BE41E27B"><enum>(2)</enum><text>administer oaths

			 or affirmations; or</text>

				</paragraph><paragraph id="IDC2B7F55C97CF41698990B6886B2C721D"><enum>(3)</enum><text>compel the

			 attendance of witnesses or the production of documentary and other

			 evidence.</text>

				</paragraph></subsection><subsection id="ID965459DCF6384B00007521CB5F1400B5"><enum>(c)</enum><header>Venue; service

			 of process</header>

				<paragraph id="ID51350E9DB3774E5DA518CECC30EF01A6"><enum>(1)</enum><header>Venue</header><text>Any

			 action brought under subsection (a) may be brought in the district court of the

			 United States that meets applicable requirements relating to venue under

			 section 1391 of title 28, United States Code.</text>

				</paragraph><paragraph id="ID8D5CC7C5FED14028A2E74F09DE5C3E23"><enum>(2)</enum><header>Service of

			 process</header><text>In an action brought under subsection (a), process may be

			 served in any district in which the defendant—</text>

					<subparagraph id="ID816F652A4DC144989583560000EF4F47"><enum>(A)</enum><text>is an inhabitant;

			 or</text>

					</subparagraph><subparagraph id="ID74C312FCF6BA4A05AC601C883F22E3D4"><enum>(B)</enum><text>may be

			 found.</text>

					</subparagraph></paragraph></subsection></section><section id="IDC952649A097942F6BB593CFCBF772BC5"><enum>5.</enum><header>Effect on State

			 law</header><text display-inline="no-display-inline">The provisions of this Act

			 shall supersede any inconsistent provisions of law of any State or unit of

			 local government relating to the notification of any resident of the United

			 States of any breach of security of an electronic database containing such

			 resident’s personal information (as defined in this Act), except as provided

			 under sections 1798.82 and 1798.29 of the California Civil Code.</text>

		</section><section id="ID4F2DF9321CA34286A574E31D6C99AF80"><enum>6.</enum><header>Effective

			 date</header><text display-inline="no-display-inline">This Act shall take

			 effect on the expiration of the date which is 6 months after the date of

			 enactment of this Act.</text>

		</section></legis-body>

</bill>

