<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" bill-type="olc" dms-id="A1" public-private="public" star-print="no-star-print">

	<form display="yes">

		<distribution-code display="yes">II</distribution-code>

		<congress display="yes">109th CONGRESS</congress>

		<session display="yes">1st Session</session>

		<legis-num>S. 1216</legis-num>

		<current-chamber display="yes">IN THE SENATE OF THE UNITED

		  STATES</current-chamber>

		<action display="yes">

			<action-date date="20050609">June 9, 2005</action-date>

			<action-desc><sponsor name-id="S279">Mr. Corzine</sponsor> introduced

			 the following bill; which was read twice and referred to the

			 <committee-name committee-id="SSBK00">Committee on Banking, Housing, and Urban

			 Affairs</committee-name></action-desc>

		</action>

		<legis-type>A BILL</legis-type>

		<official-title display="yes">To require financial institutions and

		  financial service providers to notify customers of the unauthorized use of

		  personal financial information, and for other purposes.</official-title>

	</form>

	<legis-body display-enacting-clause="yes-display-enacting-clause" style="OLC">

		<section commented="no" display-inline="no-display-inline" id="S1" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the

			 <quote><short-title>Financial Privacy Breach Notification

			 Act of 2005</short-title></quote>.</text>

		</section><section commented="no" display-inline="no-display-inline" id="id03E19CDE99AB415E9C09F8DC94FBA899" section-type="subsequent-section"><enum>2.</enum><header>Timely notification of

			 unauthorized access to personal financial information</header><text display-inline="no-display-inline">Subtitle B of title V of the

			 Gramm-Leach-Bliley Act (<external-xref legal-doc="usc" parsable-cite="usc/15/6821">15 U.S.C. 6821</external-xref> et seq.) is

			 amended—</text>

			<paragraph commented="no" display-inline="no-display-inline" id="IDAA1913B5D6FC443CA223809518EA2C50"><enum>(1)</enum><text display-inline="yes-display-inline">by redesignating sections 526 and 527 as

			 sections 528 and 529, respectively; and</text>

			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDE2E717557E7F4B728B371E1E94172434"><enum>(2)</enum><text display-inline="yes-display-inline">by inserting after section 525 the

			 following:</text>

				<quoted-block display-inline="no-display-inline" id="ID540228AEE90F4A2BB1819E5410BD6FDB" style="OLC">

					<section commented="no" display-inline="no-display-inline" id="IDDF750C50A7384EBD00375930EFB08131" section-type="subsequent-section"><enum>526.</enum><header>Notification to

				customers of unauthorized access to personal financial information</header>

						<subsection commented="no" display-inline="no-display-inline" id="ID46A13471D8734BF98016E83DD4A1C248"><enum>(a)</enum><header>Definitions</header><text display-inline="yes-display-inline">In this section:</text>

							<paragraph commented="no" display-inline="no-display-inline" id="IDD98516B3D2BE414A823CF17FDC60C9BA"><enum>(1)</enum><header>Breach</header><text display-inline="yes-display-inline">The term <term>breach</term>—</text>

								<subparagraph commented="no" display-inline="no-display-inline" id="ID621DF0D76E8F496CAF6610EDDC0365FC"><enum>(A)</enum><text display-inline="yes-display-inline">means the unauthorized acquisition, or

				loss, of computerized data or paper records which compromises the security,

				confidentiality, or integrity of personal financial information maintained by

				or on behalf of a financial institution; and</text>

								</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDA312C616F1C74CAB97A07438B573D170"><enum>(B)</enum><text display-inline="yes-display-inline">does not include a good faith acquisition

				of personal financial information by an employee or agent of a financial

				institution for a business purpose of the institution, if the personal

				financial information is not subject to further unauthorized disclosure.</text>

								</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDD29BD33CBCD54013BB1CAFA97E716167"><enum>(2)</enum><header>personal

				financial information</header><text display-inline="yes-display-inline">The

				term <term>personal financial information</term> means the last name of an

				individual in combination with any 1 or more of the following data elements,

				when either the name or the data elements are not encrypted:</text>

								<subparagraph commented="no" display-inline="no-display-inline" id="ID8B7EAE02AB5345078D5E23F21CD7B7D1"><enum>(A)</enum><text display-inline="yes-display-inline">Social security number.</text>

								</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID09ACC7891B7D4F49B23ED85CA752D309"><enum>(B)</enum><text display-inline="yes-display-inline">Driver’s license number or State

				identification number.</text>

								</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDCB9B5562672A4A51BB78C5DEDA20A5E7"><enum>(C)</enum><text display-inline="yes-display-inline">Account number, credit or debit card

				number, in combination with any required security code, access code, or

				password that would permit access to the financial account of an

				individual.</text>

								</subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="ID075E350F83DF4450B4BAD988BE15F081"><enum>(b)</enum><header>Notification to

				customers relating to unauthorized access of personal financial

				information</header>

							<paragraph commented="no" display-inline="no-display-inline" id="IDD3CD074032A344FFA58DE431709040C1"><enum>(1)</enum><header>Financial

				institution requirement</header><text display-inline="yes-display-inline">In

				any case in which there has been a breach of personal financial information at

				a financial institution, or such a breach is reasonably believed to have

				occurred, the financial institution shall promptly notify—</text>

								<subparagraph commented="no" display-inline="no-display-inline" id="ID7ADC1194A1164ED0B5909B93B27298AA"><enum>(A)</enum><text display-inline="yes-display-inline">each customer affected by the violation or

				suspected violation;</text>

								</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID094AB7D3AE9E484D9621D4157918DDB3"><enum>(B)</enum><text display-inline="yes-display-inline">each consumer reporting agency described in

				section 603(p) of the <act-name parsable-cite="FCRA">Fair Credit Reporting

				Act</act-name> (<external-xref legal-doc="usc" parsable-cite="usc/15/1681a">15

				U.S.C. 1681a</external-xref>); and</text>

								</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID2E52DD8C3FF440A8A7DE74132B0441D1"><enum>(C)</enum><text display-inline="yes-display-inline">appropriate law enforcement agencies, in

				any case in which the financial institution has reason to believe that the

				breach or suspected breach affects a large number of customers, including as

				described in subsection (e)(1)(C), subject to regulations of the Federal Trade

				Commission.</text>

								</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID652425DA07954B38979200EDE0879F9C"><enum>(2)</enum><header>Other

				entities</header><text display-inline="yes-display-inline">For purposes of

				paragraph (1), any person that maintains personal financial information for or

				on behalf of a financial institution shall promptly notify the financial

				institution of any case in which such customer information has been, or is

				reasonably believed to have been, breached.</text>

							</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="ID9AEA2E3772D0411DB3C05F7594195378"><enum>(c)</enum><header>Timeliness of

				notification</header><text display-inline="yes-display-inline">Notification

				required by this section shall be made—</text>

							<paragraph commented="no" display-inline="no-display-inline" id="ID991F454773FD4B42A52F802F37EB5DB5"><enum>(1)</enum><text display-inline="yes-display-inline">promptly and without unreasonable delay,

				upon discovery of the breach or suspected breach; and</text>

							</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDE3AC8948932B4B68B78D2D6636ACB28B"><enum>(2)</enum><text display-inline="yes-display-inline">consistent with—</text>

								<subparagraph commented="no" display-inline="no-display-inline" id="IDBE219DBC3F0747F8B4DDC5017E969BFF"><enum>(A)</enum><text display-inline="yes-display-inline">the legitimate needs of law enforcement, as

				provided in subsection (d); and</text>

								</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID224D2FDCC76F467D8D9454951C4F9920"><enum>(B)</enum><text display-inline="yes-display-inline">any measures necessary to determine the

				scope of the breach or restore the reasonable integrity of the information

				security system of the financial institution.</text>

								</subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="IDEB10EDCA5B274578A0276336A8041039"><enum>(d)</enum><header>Delays for law

				enforcement purposes</header><text display-inline="yes-display-inline">Notification required by this section may

				be delayed if a law enforcement agency determines that the notification would

				impede a criminal investigation, and in any such case, notification shall be

				made promptly after the law enforcement agency determines that it would not

				compromise the investigation.</text>

						</subsection><subsection commented="no" display-inline="no-display-inline" id="ID10651740C6664691BC35076CCE848226"><enum>(e)</enum><header>Form of

				notice</header><text display-inline="yes-display-inline">Notification required

				by this section may be provided—</text>

							<paragraph commented="no" display-inline="no-display-inline" id="ID25CD07C32296437A846DD054EF65ADA8"><enum>(1)</enum><text display-inline="yes-display-inline">to a customer—</text>

								<subparagraph commented="no" display-inline="no-display-inline" id="IDE55E26E4CB6A401C94008794BC60C6A5"><enum>(A)</enum><text display-inline="yes-display-inline">in written notification;</text>

								</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID110ED1A5516E4438AB00E32415B4E9F9"><enum>(B)</enum><text display-inline="yes-display-inline">in electronic form, if the notice provided

				is consistent with the provisions regarding electronic records and signatures

				set forth in section 101 of the Electronic Signatures in Global and National

				Commerce Act (<external-xref legal-doc="usc" parsable-cite="usc/15/7001">15

				U.S.C. 7001</external-xref>);</text>

								</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDF117F8392EE74C8CA82CADA0A36000FE"><enum>(C)</enum><text display-inline="yes-display-inline">if the Federal Trade Commission determines

				that the number of all customers affected by, or the cost of providing

				notifications relating to, a single breach or suspected breach would make other

				forms of notification prohibitive, or in any case in which the financial

				institution certifies in writing to the Federal Trade Commission that it does

				not have sufficient customer contact information to comply with other forms of

				notification, in the form of—</text>

									<clause commented="no" display-inline="no-display-inline" id="IDC4ADA5676E024F648842F30000373333"><enum>(i)</enum><text display-inline="yes-display-inline">an e-mail notice, if the financial

				institution has access to an e-mail address for the affected customer that it

				has reason to believe is accurate;</text>

									</clause><clause commented="no" display-inline="no-display-inline" id="ID6BE930A736B7465685771500BDB008B1"><enum>(ii)</enum><text display-inline="yes-display-inline">a conspicuous posting on the Internet

				website of the financial institution, if the financial institution maintains

				such a website; or</text>

									</clause><clause commented="no" display-inline="no-display-inline" id="ID1A9138B9677E4C64B88E2542F0328C26"><enum>(iii)</enum><text display-inline="yes-display-inline">notification through the media that a

				breach of personal financial information has occurred or is suspected that

				compromises the security, confidentiality, or integrity of customer information

				of the financial institution; or</text>

									</clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDB76112272E1B42E3A737FC1B521C6E68"><enum>(D)</enum><text display-inline="yes-display-inline">in such other form as the Federal Trade

				Commission may by rule prescribe; and</text>

								</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID91B90A983C134B7CA1245F198B7F9C67"><enum>(2)</enum><text display-inline="yes-display-inline">to consumer reporting agencies and law

				enforcement agencies (where appropriate), in such form as the Federal Trade

				Commission may prescribe, by rule.</text>

							</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="ID77011EF129B945978CBB39AD3CE223A9"><enum>(f)</enum><header>Content of

				notification</header><text display-inline="yes-display-inline">Each

				notification to a customer under subsection (b) shall include—</text>

							<paragraph commented="no" display-inline="no-display-inline" id="ID1488BAF155244D61BE9F27D395FC993D"><enum>(1)</enum><text display-inline="yes-display-inline">a statement that—</text>

								<subparagraph commented="no" display-inline="no-display-inline" id="IDA270B2FF3C6645E58376E2DC1CF03481"><enum>(A)</enum><text display-inline="yes-display-inline">credit reporting agencies have been

				notified of the relevant breach or suspected breach; and</text>

								</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID22571AE06EAE4DBB96C7638D33B4BF58"><enum>(B)</enum><text display-inline="yes-display-inline">the credit report and file of the customer

				will contain a fraud alert to make creditors aware of the breach or suspected

				breach, and to inform creditors that the express authorization of the customer

				is required for any new issuance or extension of credit (in accordance with

				section 605(g) of the <act-name parsable-cite="FCRA">Fair Credit Reporting

				Act</act-name>); and</text>

								</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDF618F2FC3E8A45ECA2F2AF35AF93A735"><enum>(2)</enum><text display-inline="yes-display-inline">such other information as the Federal Trade

				Commission determines is appropriate.</text>

							</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="IDE20FE5B77CC94E2DBD6048FB8DC4C17D"><enum>(g)</enum><header>Compliance</header><text display-inline="yes-display-inline">Notwithstanding subsection (e), a financial

				institution shall be deemed to be in compliance with this section, if—</text>

							<paragraph commented="no" display-inline="no-display-inline" id="IDC312ACF6DF2547058DC4B8B5F73E4EFF"><enum>(1)</enum><text display-inline="yes-display-inline">the financial institution has established a

				comprehensive information security program that is consistent with the

				standards prescribed by the appropriate regulatory body under section

				501(b);</text>

							</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID6C8028363C684E98B3647FEDB368AA2E"><enum>(2)</enum><text display-inline="yes-display-inline">the financial institution notifies affected

				customers and consumer reporting agencies in accordance with its own internal

				information security policies in the event of a breach or suspected breach of

				personal financial information; and</text>

							</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID460708CD29C04484B0E936E54B5BE4F4"><enum>(3)</enum><text display-inline="yes-display-inline">such internal security policies incorporate

				notification procedures that are consistent with the requirements of this

				section and the rules of the Federal Trade Commission under this

				section.</text>

							</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="ID4228CC62CFF14BAD93FA3000B0D100A9"><enum>(h)</enum><header>Civil

				penalties</header>

							<paragraph commented="no" display-inline="no-display-inline" id="ID935E846B36944118972CFF6377EA29A6"><enum>(1)</enum><header>Damages</header><text display-inline="yes-display-inline">Any customer injured by a violation of this

				section may institute a civil action to recover damages arising from that

				violation.</text>

							</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID2671ABF467EE4A029386C2851F5DF93F"><enum>(2)</enum><header>Injunctions</header><text display-inline="yes-display-inline">Actions of a financial institution in

				violation or potential violation of this section may be enjoined.</text>

							</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDF464ACEF22354044A4D95721878CD5A6"><enum>(3)</enum><header>Cumulative

				effect</header><text display-inline="yes-display-inline">The rights and

				remedies available under this section are in addition to any other rights and

				remedies available under applicable law.</text>

							</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="IDFB79D9B367D145CB844769A65F47036D"><enum>(i)</enum><header>Rules of

				construction</header>

							<paragraph commented="no" display-inline="no-display-inline" id="ID689D88F920D0484A8B28AE2753CB6552"><enum>(1)</enum><header>In

				general</header><text display-inline="yes-display-inline">Compliance with this

				section by a financial institution shall not be construed to be a violation of

				any provision of subtitle (A), or any other provision of Federal or State law

				prohibiting the disclosure of financial information to third parties.</text>

							</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID594839EE5AE04ACB8C21DEB704786978"><enum>(2)</enum><header>Limitation</header><text display-inline="yes-display-inline">Except as specifically provided in this

				section, nothing in this section requires or authorizes a financial institution

				to disclose information that it is otherwise prohibited from disclosing under

				subtitle A or any other provision of Federal or State law.</text>

							</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="id3E2CBA483644469E8D6606EF2481799D"><enum>(j)</enum><header>Enforcement</header><text display-inline="yes-display-inline">The Federal Trade Commission is authorized

				to enforce compliance with this section, including the assessment of fines for

				violations of subsection

				(b)(1).</text>

						</subsection></section><after-quoted-block>.</after-quoted-block></quoted-block>

			</paragraph></section><section commented="no" display-inline="no-display-inline" id="id1D708F265C8E41E2BA482CC48B1CB325" section-type="subsequent-section"><enum>3.</enum><header>Effective

			 date</header><text display-inline="no-display-inline">This Act shall take

			 effect on the expiration of the date which is 6 months after the date of

			 enactment of this Act.</text>

		</section></legis-body>

</bill>

