<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" bill-type="olc" dms-id="A1" public-private="public" star-print="no-star-print">

	<form display="yes">

		<distribution-code display="yes">II</distribution-code>

		<congress display="yes">109th CONGRESS</congress>

		<session display="yes">1st Session</session>

		<legis-num>S. 1594</legis-num>

		<current-chamber display="yes">IN THE SENATE OF THE UNITED

		  STATES</current-chamber>

		<action display="yes">

			<action-date date="20050729">July 29, 2005</action-date>

			<action-desc><sponsor name-id="S279">Mr. Corzine</sponsor> introduced

			 the following bill; which was read twice and referred to the

			 <committee-name committee-id="SSBK00">Committee on Banking, Housing, and Urban

			 Affairs</committee-name></action-desc>

		</action>

		<legis-type>A BILL</legis-type>

		<official-title display="yes">To require financial services providers to

		  maintain customer information security systems and to notify customers of

		  unauthorized access to personal information, and for other

		  purposes.</official-title>

	</form>

	<legis-body display-enacting-clause="yes-display-enacting-clause" style="OLC">

		<section commented="no" display-inline="no-display-inline" id="S1" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the

			 <quote><short-title>Financial Privacy Protection Act of

			 2005</short-title></quote>.</text>

		</section><section commented="no" display-inline="no-display-inline" id="id03E19CDE99AB415E9C09F8DC94FBA899" section-type="subsequent-section"><enum>2.</enum><header>Prevention of identity

			 theft; notification of unauthorized access to customer

			 information</header><text display-inline="no-display-inline">Subtitle B of

			 title V of the Gramm-Leach-Bliley Act (<external-xref legal-doc="usc" parsable-cite="usc/15/6821">15 U.S.C. 6821</external-xref> et seq.) is

			 amended—</text>

			<paragraph commented="no" display-inline="no-display-inline" id="id5A4493FDDED747E6ABF6557B15D53FC4"><enum>(1)</enum><text display-inline="yes-display-inline">by striking section 525;</text>

			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="idEC0EC55348D4429BBED45E9000401905"><enum>(2)</enum><text display-inline="yes-display-inline">by redesignating sections 522 through 524

			 as sections 523 through 525, respectively;</text>

			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="idBDAC05519CAF4F519EEE94FBCCBC3D90"><enum>(3)</enum><text display-inline="yes-display-inline">in section 525, as redesignated, by

			 striking <quote>section 522</quote> and inserting <quote>section 523</quote>;

			 and</text>

			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDE2E717557E7F4B728B371E1E94172434"><enum>(4)</enum><text display-inline="yes-display-inline">by inserting after section 521 the

			 following:</text>

				<quoted-block display-inline="no-display-inline" id="ID540228AEE90F4A2BB1819E5410BD6FDB" style="OLC">

					<section commented="no" display-inline="no-display-inline" id="IDDF750C50A7384EBD00375930EFB08131" section-type="subsequent-section"><enum>522.</enum><header>Prevention of

				identity theft; notification of unauthorized access to customer

				information</header>

						<subsection commented="no" display-inline="no-display-inline" id="id5EE0C4B118524E1D837028BBC0980961"><enum>(a)</enum><header>Customer

				information security system required</header>

							<paragraph commented="no" display-inline="no-display-inline" id="id5024335C3D93449791E48C438DBBC925"><enum>(1)</enum><header>In

				general</header><text display-inline="yes-display-inline">In accordance with

				regulations issued under paragraph (2), each financial institution shall

				develop and maintain a customer information security system, including

				policies, procedures, and controls designed to prevent any breach with respect

				to the customer information of the financial institution.</text>

							</paragraph><paragraph commented="no" display-inline="no-display-inline" id="idE38970499E35406EA69716628AA32009"><enum>(2)</enum><header>Regulations</header>

								<subparagraph commented="no" display-inline="no-display-inline" id="idDD23739C67504E3BB29A76A0AB5C549E"><enum>(A)</enum><header>In

				general</header><text display-inline="yes-display-inline">Each of the Federal

				functional regulators shall issue regulations regarding the policies,

				procedures, and controls required by paragraph (1) applicable to the financial

				institutions that are subject to their respective enforcement authority under

				section 523.</text>

								</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idB4B549D55F1E4F178273BFC589E96176"><enum>(B)</enum><header>Specific

				requirements</header><text display-inline="yes-display-inline">The regulations

				required by subparagraph (A) shall—</text>

									<clause commented="no" display-inline="no-display-inline" id="id814F2A48186340B7B3B7B2CA7E4F7A5D"><enum>(i)</enum><text display-inline="yes-display-inline">require the chief compliance officer or

				chief executive officer of a financial institution to personally attest that

				the customer information security system of the financial institution is in

				compliance with Federal and other applicable standards and is subject to an

				ongoing system of monitoring;</text>

									</clause><clause commented="no" display-inline="no-display-inline" id="id624014C4E067491387475BC12BDA8A36"><enum>(ii)</enum><text display-inline="yes-display-inline">require audits by the issuing agency (or

				submitted to the issuing agency by an independent auditor paid for by the

				financial institution to audit the financial institution on behalf of the

				issuing agency) of the customer information security system of a financial

				institution not less frequently than once every 5 years;</text>

									</clause><clause commented="no" display-inline="no-display-inline" id="id2DD5107F4848452C961ECE8FC5DF4363"><enum>(iii)</enum><text display-inline="yes-display-inline">require the imposition by the issuing

				agency of appropriate monetary penalties for failure to comply with applicable

				customer information security standards; and</text>

									</clause><clause commented="no" display-inline="no-display-inline" id="idCF943E49796C4DE78878CF960B630241"><enum>(iv)</enum><text display-inline="yes-display-inline">include such other requirements or

				restrictions as the issuing agency considers appropriate to carry out this

				section.</text>

									</clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idD2FD78CA494D49DF821ED3551232315A"><enum>(C)</enum><header>Effective

				date</header><text display-inline="yes-display-inline">Regulations issued under

				this paragraph shall become effective 6 months after the effective date of the

				<short-title>Financial Privacy Protection Act of

				2005</short-title>.</text>

								</subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="ID075E350F83DF4450B4BAD988BE15F081"><enum>(b)</enum><header>Notification to

				customers of unauthorized access to customer information</header>

							<paragraph commented="no" display-inline="no-display-inline" id="ID7ADC1194A1164ED0B5909B93B27298AA"><enum>(1)</enum><header>Financial

				institution requirement</header><text display-inline="yes-display-inline">In

				any case in which there has been a breach at a financial institution, or such a

				breach is reasonably believed to have occurred, the financial institution shall

				promptly notify—</text>

								<subparagraph commented="no" display-inline="no-display-inline" id="id10A1EE3A7BB048E9A561E11376D869FF"><enum>(A)</enum><text display-inline="yes-display-inline">each customer whose customer information

				was or is reasonably believed to have been accessed in connection with the

				breach or suspected breach;</text>

								</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id01E1631B5FB247868DD520F346C2A175"><enum>(B)</enum><text display-inline="yes-display-inline">the appropriate Federal functional

				regulator or regulators with respect to the financial institutions that are

				subject to their respective enforcement authority;</text>

								</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID094AB7D3AE9E484D9621D4157918DDB3"><enum>(C)</enum><text display-inline="yes-display-inline">each consumer reporting agency described in

				section 603(p) of the <act-name parsable-cite="FCRA">Fair Credit Reporting

				Act</act-name>; and</text>

								</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID2E52DD8C3FF440A8A7DE74132B0441D1"><enum>(D)</enum><text display-inline="yes-display-inline">appropriate law enforcement agencies, in

				any case in which the financial institution has reason to believe that the

				breach or suspected breach affects a large number of customers, including as

				described in paragraph (5)(A)(iii), subject to regulations of the Federal Trade

				Commission.</text>

								</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID652425DA07954B38979200EDE0879F9C"><enum>(2)</enum><header>Other

				entities</header><text display-inline="yes-display-inline">For purposes of

				paragraph (1), any person that maintains customer information for or on behalf

				of a financial institution shall promptly notify the financial institution of

				any case in which such customer information has been, or is reasonably believed

				to have been, breached.</text>

							</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID9AEA2E3772D0411DB3C05F7594195378"><enum>(3)</enum><header>Timeliness of

				notification</header><text display-inline="yes-display-inline">Notification

				required by this subsection shall be made—</text>

								<subparagraph commented="no" display-inline="no-display-inline" id="ID991F454773FD4B42A52F802F37EB5DB5"><enum>(A)</enum><text display-inline="yes-display-inline">promptly and without unreasonable delay,

				upon discovery of the breach or suspected breach; and</text>

								</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDE3AC8948932B4B68B78D2D6636ACB28B"><enum>(B)</enum><text display-inline="yes-display-inline">consistent with—</text>

									<clause commented="no" display-inline="no-display-inline" id="IDBE219DBC3F0747F8B4DDC5017E969BFF"><enum>(i)</enum><text display-inline="yes-display-inline">the legitimate needs of law enforcement, as

				provided in paragraph (4); and</text>

									</clause><clause commented="no" display-inline="no-display-inline" id="ID224D2FDCC76F467D8D9454951C4F9920"><enum>(ii)</enum><text display-inline="yes-display-inline">any measures necessary to determine the

				scope of the breach or restore the reasonable integrity of the customer

				information security system of the financial institution.</text>

									</clause></subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDEB10EDCA5B274578A0276336A8041039"><enum>(4)</enum><header>Delays for law

				enforcement purposes</header><text display-inline="yes-display-inline">Notification required by this subsection

				may be delayed if a law enforcement agency determines that the notification

				would seriously impede a criminal investigation, and in any such case,

				notification shall be made promptly after the law enforcement agency determines

				that it would not compromise the investigation.</text>

							</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID10651740C6664691BC35076CCE848226"><enum>(5)</enum><header>Form of

				notice</header><text display-inline="yes-display-inline">Notification required

				by this subsection may be provided—</text>

								<subparagraph commented="no" display-inline="no-display-inline" id="ID25CD07C32296437A846DD054EF65ADA8"><enum>(A)</enum><text display-inline="yes-display-inline">to a customer—</text>

									<clause commented="no" display-inline="no-display-inline" id="IDE55E26E4CB6A401C94008794BC60C6A5"><enum>(i)</enum><text display-inline="yes-display-inline">in writing;</text>

									</clause><clause commented="no" display-inline="no-display-inline" id="ID110ED1A5516E4438AB00E32415B4E9F9"><enum>(ii)</enum><text display-inline="yes-display-inline">in electronic form, if the notice provided

				is consistent with the provisions regarding electronic records and signatures

				set forth in section 101 of the Electronic Signatures in Global and National

				Commerce Act;</text>

									</clause><clause commented="no" display-inline="no-display-inline" id="IDF117F8392EE74C8CA82CADA0A36000FE"><enum>(iii)</enum><text display-inline="yes-display-inline">if the number of people affected by the

				breach exceeds 500,000 or the cost of notification exceeds $500,000, or a

				higher number or numbers determined by the Federal Trade Commission, such that

				the cost of providing notifications relating to a single breach or suspected

				breach would make other forms of notification prohibitive, or in any case in

				which the financial institution certifies in writing to the Federal Trade

				Commission that it does not have sufficient customer contact information to

				comply with other forms of notification with respect to some customers, then

				for those customers, in the form of—</text>

										<subclause commented="no" display-inline="no-display-inline" id="ID6BE930A736B7465685771500BDB008B1"><enum>(I)</enum><text display-inline="yes-display-inline">a conspicuous posting on the Internet

				website of the financial institution, if the financial institution maintains

				such a website; and</text>

										</subclause><subclause commented="no" display-inline="no-display-inline" id="ID1A9138B9677E4C64B88E2542F0328C26"><enum>(II)</enum><text display-inline="yes-display-inline">notification through major media in all

				major cities and regions in which the customers whose customer information is

				suspected to have been breached reside, that a breach has occurred, or is

				suspected, that compromises the security, confidentiality, or integrity of

				customer information of the financial institution; or</text>

										</subclause></clause><clause commented="no" display-inline="no-display-inline" id="IDB76112272E1B42E3A737FC1B521C6E68"><enum>(iv)</enum><text display-inline="yes-display-inline">in such additional forms as the Federal

				Trade Commission may by rule prescribe; and</text>

									</clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID91B90A983C134B7CA1245F198B7F9C67"><enum>(B)</enum><text display-inline="yes-display-inline">to consumer reporting agencies and law

				enforcement agencies (where appropriate), in such form as the Federal Trade

				Commission shall by rule prescribe.</text>

								</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID77011EF129B945978CBB39AD3CE223A9"><enum>(6)</enum><header>Content of

				notification</header><text display-inline="yes-display-inline">Each

				notification to a customer under this subsection shall include—</text>

								<subparagraph commented="no" display-inline="no-display-inline" id="ID1488BAF155244D61BE9F27D395FC993D"><enum>(A)</enum><text display-inline="yes-display-inline">a statement that—</text>

									<clause commented="no" display-inline="no-display-inline" id="IDA270B2FF3C6645E58376E2DC1CF03481"><enum>(i)</enum><text display-inline="yes-display-inline">credit reporting agencies have been

				notified of the relevant breach or suspected breach; and</text>

									</clause><clause commented="no" display-inline="no-display-inline" id="ID22571AE06EAE4DBB96C7638D33B4BF58"><enum>(ii)</enum><text display-inline="yes-display-inline">notwithstanding any other provision of law,

				the customer may elect to place a fraud alert in the file of the consumer to

				make creditors aware of the breach or suspected breach, and to inform creditors

				that the express authorization of the customer is required for any new issuance

				or extension of credit (in accordance with section 605A of the

				<act-name parsable-cite="FCRA">Fair Credit Reporting Act</act-name>);

				and</text>

									</clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDF618F2FC3E8A45ECA2F2AF35AF93A735"><enum>(B)</enum><text display-inline="yes-display-inline">such other information as the Federal Trade

				Commission determines is appropriate.</text>

								</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDE20FE5B77CC94E2DBD6048FB8DC4C17D"><enum>(7)</enum><header>Compliance</header><text display-inline="yes-display-inline">Notwithstanding paragraph (5), a financial

				institution shall be deemed to be in compliance with this subsection,

				if—</text>

								<subparagraph commented="no" display-inline="no-display-inline" id="IDC312ACF6DF2547058DC4B8B5F73E4EFF"><enum>(A)</enum><text display-inline="yes-display-inline">the financial institution has established a

				comprehensive customer information security system that is consistent with the

				standards prescribed by the appropriate Federal functional regulator under

				subsection (a);</text>

								</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID6C8028363C684E98B3647FEDB368AA2E"><enum>(B)</enum><text display-inline="yes-display-inline">the financial institution notifies affected

				customers and consumer reporting agencies in accordance with its own internal

				information security policies in the event of a breach or suspected breach;

				and</text>

								</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID460708CD29C04484B0E936E54B5BE4F4"><enum>(C)</enum><text display-inline="yes-display-inline">such internal security policies incorporate

				notification procedures that are consistent with the requirements of this

				subsection and the rules of the Federal Trade Commission under this

				subsection.</text>

								</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDFB79D9B367D145CB844769A65F47036D"><enum>(8)</enum><header>Rules of

				construction</header>

								<subparagraph commented="no" display-inline="no-display-inline" id="ID689D88F920D0484A8B28AE2753CB6552"><enum>(A)</enum><header>In

				general</header><text display-inline="yes-display-inline">Compliance with this

				subsection by a financial institution shall not be construed to be a violation

				of any provision of subtitle A, or any other provision of Federal or State law

				prohibiting the disclosure of financial information to third parties.</text>

								</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID594839EE5AE04ACB8C21DEB704786978"><enum>(B)</enum><header>Limitation</header><text display-inline="yes-display-inline">Except as specifically provided in this

				subsection, nothing in this subsection requires or authorizes a financial

				institution to disclose information that it is otherwise prohibited from

				disclosing under subtitle A or any other applicable provision of Federal or

				State law.</text>

								</subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="ID4228CC62CFF14BAD93FA3000B0D100A9"><enum>(c)</enum><header>Civil

				penalties</header>

							<paragraph commented="no" display-inline="no-display-inline" id="ID935E846B36944118972CFF6377EA29A6"><enum>(1)</enum><header>Damages</header><text display-inline="yes-display-inline">Any customer adversely affected by an act

				or practice that violates this section may institute a civil action to recover

				damages arising from that violation.</text>

							</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID2671ABF467EE4A029386C2851F5DF93F"><enum>(2)</enum><header>Injunctions</header><text display-inline="yes-display-inline">Actions of a financial institution in

				violation or potential violation of this section may be enjoined.</text>

							</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDF464ACEF22354044A4D95721878CD5A6"><enum>(3)</enum><header>Cumulative

				effect</header><text display-inline="yes-display-inline">The rights and

				remedies available under this section are in addition to any other rights and

				remedies available under any other provision of applicable State or Federal

				law.</text>

							</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="IDd887f71cae944e0d908a31989dc6df22"><enum>(d)</enum><header>Civil actions

				by state attorneys general</header>

							<paragraph commented="no" display-inline="no-display-inline" id="id7DAB70C10A834396AA5E9705E58BB5D4"><enum>(1)</enum><header>Authority of

				state attorneys general</header><text display-inline="yes-display-inline">In

				any case in which the attorney general of a State has reason to believe that an

				interest of the residents of that State has been or is threatened or adversely

				affected by an act or practice that violates this section, the State may bring

				a civil action on behalf of the residents of that State in a district court of

				the United States of appropriate jurisdiction, or any other court of competent

				jurisdiction—</text>

								<subparagraph commented="no" display-inline="no-display-inline" id="ID5568efe9f4f44f6da842c1b6a63161dd"><enum>(A)</enum><text display-inline="yes-display-inline">to enjoin that act or practice;</text>

								</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID61815e49cd0b4e50b5237515619ba2bc"><enum>(B)</enum><text display-inline="yes-display-inline">to enforce compliance with this

				section;</text>

								</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID17e4c47f47ae4260ba9409c1d883d47c"><enum>(C)</enum><text display-inline="yes-display-inline">to obtain—</text>

									<clause commented="no" display-inline="no-display-inline" id="id64FCAF5AA50D4CAEBB220A5731545058"><enum>(i)</enum><text display-inline="yes-display-inline">damages in the sum of actual damages,

				restitution, or other compensation on behalf of affected residents of the

				State; and</text>

									</clause><clause commented="no" display-inline="no-display-inline" id="id809BEC60E1C64DEA944ABC7EFA07397D"><enum>(ii)</enum><text display-inline="yes-display-inline">punitive damages, if the violation is

				willful or intentional; or</text>

									</clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID6b238dbe64564aba8111ee5d46ded61e"><enum>(D)</enum><text display-inline="yes-display-inline">obtain such other legal and equitable

				relief as the court may consider to be appropriate.</text>

								</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDcdc5b6a41278463baadf9d054f9765b1"><enum>(2)</enum><header>Rule of

				construction</header><text display-inline="yes-display-inline">For purposes of

				bringing any civil action under paragraph (1), nothing in this section shall be

				construed to prevent an attorney general of a State from exercising the powers

				conferred on the attorney general by the laws of that State—</text>

								<subparagraph commented="no" display-inline="no-display-inline" id="id73F3BD1F4CFA45619316D4B5F0F3FE9E"><enum>(A)</enum><text display-inline="yes-display-inline">to conduct investigations;</text>

								</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id8197748E226A420ABEF52A07D20E8496"><enum>(B)</enum><text display-inline="yes-display-inline">to administer oaths and affirmations;

				or</text>

								</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idB5EB6260CF4345B89FA57E2FB6D01DF0"><enum>(C)</enum><text display-inline="yes-display-inline">to compel the attendance of witnesses or

				the production of documentary and other evidence.</text>

								</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id07B4836BF02549CD8BDA9501354E2C38"><enum>(3)</enum><header>Venue</header><text display-inline="yes-display-inline">Any action brought under this subsection

				may be brought in the district court of the United States that meets applicable

				requirements relating to venue under section 1931 of title 28, United States

				Code.</text>

							</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id17155495E48541E2B3EAFD9114D67039"><enum>(4)</enum><header>Service of

				process</header><text display-inline="yes-display-inline">In an action brought

				under this subsection, process may be served in any district in which the

				defendant—</text>

								<subparagraph commented="no" display-inline="no-display-inline" id="idA2A6BB0B43B24BAD8392506F4A3D8303"><enum>(A)</enum><text display-inline="yes-display-inline">is an inhabitant; or</text>

								</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id3EFCC1069BCB4A328EE03FD3B09D34AC"><enum>(B)</enum><text display-inline="yes-display-inline">may be

				found.</text>

								</subparagraph></paragraph></subsection></section><after-quoted-block>.</after-quoted-block></quoted-block>

			</paragraph></section><section commented="no" display-inline="no-display-inline" id="id3CE7C9C08F2B4A239B189E8671CA47E3" section-type="subsequent-section"><enum>3.</enum><header>Definitions</header><text display-inline="no-display-inline">Section 527 of the Gramm-Leach-Bliley Act

			 (15 U.S.C. 6827) is amended—</text>

			<paragraph commented="no" display-inline="no-display-inline" id="id9CD3F668115443ACA622C0A6826F159A"><enum>(1)</enum><text display-inline="yes-display-inline">by redesignating paragraph (4) as paragraph

			 (6);</text>

			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="idCD8DA64AB117440F8A3BFDC86ADD2926"><enum>(2)</enum><text display-inline="yes-display-inline">by redesignating paragraphs (1) through (3)

			 as paragraphs (2) through (4), respectively;</text>

			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id8EF975E9CBB64EA08067C2E899173C2B"><enum>(3)</enum><text display-inline="yes-display-inline">by inserting before paragraph (2), as

			 redesignated, the following:</text>

				<quoted-block display-inline="no-display-inline" id="id8865148228CF4DC39823B904ACE88849" style="OLC">

					<paragraph commented="no" display-inline="no-display-inline" id="IDD98516B3D2BE414A823CF17FDC60C9BA"><enum>(1)</enum><header>Breach</header><text display-inline="yes-display-inline">The term <term>breach</term>—</text>

						<subparagraph commented="no" display-inline="no-display-inline" id="ID621DF0D76E8F496CAF6610EDDC0365FC"><enum>(A)</enum><text display-inline="yes-display-inline">means the unauthorized acquisition,

				disclosure, or loss of computerized data or paper records which compromises the

				security, confidentiality, or integrity of customer information, including

				activities proscribed under section 521; and</text>

						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDA312C616F1C74CAB97A07438B573D170"><enum>(B)</enum><text display-inline="yes-display-inline">does not include a good faith acquisition

				of customer information by an employee or agent of a financial institution for

				a business purpose of the institution, if the customer information is not

				subject to further unauthorized

				disclosure.</text>

						</subparagraph></paragraph><after-quoted-block>;

				</after-quoted-block></quoted-block>

			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id87D11A6B0E844E64B525039534052EA7"><enum>(4)</enum><text display-inline="yes-display-inline">in paragraph (2), as redesignated—</text>

				<subparagraph commented="no" display-inline="no-display-inline" id="id8893EDE95C304BFC890B6FD160FFAC9D"><enum>(A)</enum><text display-inline="yes-display-inline">by striking <quote>person) to whom</quote>

			 and inserting the following: "person)—</text>

					<quoted-block display-inline="no-display-inline" id="id27CD68300A954D7494C47D56A1F8F114" style="OLC">

						<subparagraph commented="no" display-inline="no-display-inline" id="id778B2E38846740DABE8D01A590EF1035"><enum>(A)</enum><text display-inline="yes-display-inline">to

				whom</text>

						</subparagraph><after-quoted-block>;

				and</after-quoted-block></quoted-block>

				</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id18D8738A370E49558ECD2297EE765109"><enum>(B)</enum><text display-inline="yes-display-inline">by striking the period at the end and

			 inserting the following:</text>

					<quoted-block display-inline="yes-display-inline" id="idA2FB450BD023451AA4B46882C382ED39" style="OLC">

						<text>;

			 and</text><subparagraph commented="no" display-inline="no-display-inline" id="id69FB474DA8C7442896046681F629810A"><enum>(B)</enum><text display-inline="yes-display-inline">with respect to whom the financial

				institution maintains information in any form, regardless of whether the

				financial institution is providing a product or service to or on behalf of that

				person.</text>

						</subparagraph><after-quoted-block>;

				</after-quoted-block></quoted-block>

				</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id6D329029BF384C4FB2699F6F92F33B12"><enum>(5)</enum><text display-inline="yes-display-inline">in paragraph (3), as redesignated—</text>

				<subparagraph commented="no" display-inline="no-display-inline" id="id2DE023DAF933433DBA531421DACFD57E"><enum>(A)</enum><text display-inline="yes-display-inline">by striking <quote>institution' means

			 any</quote> and inserting the

			 following:</text>

					<quoted-block display-inline="yes-display-inline" id="idDE12575402B04509B136617C9402331D" style="OLC">

						<text>institution'—</text><subparagraph commented="no" display-inline="no-display-inline" id="idEFBE374D56AC4471B378E4F084045FB9"><enum>(A)</enum><text display-inline="yes-display-inline">means

				any</text>

						</subparagraph><after-quoted-block>; </after-quoted-block></quoted-block>

				</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idDA2B60924A9248B5B387CB8BE55083BF"><enum>(B)</enum><text display-inline="yes-display-inline">by inserting <quote>(regardless of whether

			 the financial institution is providing any product or service to or on behalf

			 of that customer)</quote> before <quote>and is identified</quote>; and</text>

				</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id9109338DA9874F28991303210075A690"><enum>(C)</enum><text display-inline="yes-display-inline">by striking the period at the end and

			 inserting the following:</text>

					<quoted-block display-inline="yes-display-inline" id="id45ACEFD473854A178CB0E67C0E4F2E92" style="OLC">

						<text>;

			 and</text><subparagraph commented="no" display-inline="no-display-inline" id="id47F36F722B044627A109E679193B44B7"><enum>(B)</enum><text display-inline="yes-display-inline">for purposes of section 522, includes the

				last name of an individual in combination with any 1 or more of the following

				data elements, when either the name or the data elements are not

				encrypted:</text>

							<clause commented="no" display-inline="no-display-inline" id="ID8B7EAE02AB5345078D5E23F21CD7B7D1"><enum>(i)</enum><text display-inline="yes-display-inline">Social security number.</text>

							</clause><clause commented="no" display-inline="no-display-inline" id="ID09ACC7891B7D4F49B23ED85CA752D309"><enum>(ii)</enum><text display-inline="yes-display-inline">Driver’s license number or State

				identification number.</text>

							</clause><clause commented="no" display-inline="no-display-inline" id="IDCB9B5562672A4A51BB78C5DEDA20A5E7"><enum>(iii)</enum><text display-inline="yes-display-inline">Account number, credit or debit card

				number, or any required security code, access code, or password that would

				permit access to a financial account of the individual.</text>

							</clause><clause commented="no" display-inline="no-display-inline" id="id9FF8D93BE3744A1B92FFC3D1779E1C11"><enum>(iv)</enum><text display-inline="yes-display-inline">Such other information as the Federal

				functional regulators determine is appropriate with respect to the financial

				institutions that are subject to their respective enforcement

				authority.</text>

							</clause></subparagraph><after-quoted-block>;

				and</after-quoted-block></quoted-block>

				</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id74BA9B291E94485C9B5EEC60F219BF09"><enum>(6)</enum><text display-inline="yes-display-inline">by inserting before paragraph (6), as

			 redesignated, the following:</text>

				<quoted-block display-inline="no-display-inline" id="id266FFD931825444FAC891DA1E5B7B64D" style="OLC">

					<paragraph commented="no" display-inline="no-display-inline" id="id7763213F995546C98E0D0084F167121A"><enum>(5)</enum><header>Federal

				functional regulator</header><text display-inline="yes-display-inline">The term

				<quote>Federal functional regulator</quote> has the same meaning as in section

				509, and includes the Federal Trade

				Commission.</text>

					</paragraph><after-quoted-block>.</after-quoted-block></quoted-block>

			</paragraph></section><section commented="no" display-inline="no-display-inline" id="id5187A0B6BA5E440EAB256F5499C91054" section-type="subsequent-section"><enum>4.</enum><header>Inclusion of fraud

			 alerts in consumer credit reports</header><text display-inline="no-display-inline">Section 605A of the

			 <act-name parsable-cite="FCRA">Fair Credit Reporting Act</act-name>

			 (<external-xref legal-doc="usc" parsable-cite="usc/15/1681c">15 U.S.C.

			 1681c–1</external-xref>) is amended–</text>

			<paragraph commented="no" display-inline="no-display-inline" id="id9DCBBDAC2AF3411B8A36EF3267FF7B78"><enum>(1)</enum><text display-inline="yes-display-inline">in subsection (b)(1), by inserting

			 <quote>or proof of a notification of a breach or suspected breach under section

			 522(b)(1)(C) of the Gramm-Leach-Bliley Act</quote> after <quote>theft

			 report</quote>; and</text>

			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="idA7E4B35FDE2343EBBE4B7E882F625E6A"><enum>(2)</enum><text display-inline="yes-display-inline">by adding at the end the following:</text>

				<quoted-block display-inline="no-display-inline" id="id93CB0F8020E241A2B77FDA859C040D11" style="OLC">

					<subsection commented="no" display-inline="no-display-inline" id="ID7887c74e66f249d8898ddab4d8087c38"><enum>(i)</enum><header>No adverse

				action based solely on fraud alert</header><text display-inline="yes-display-inline">It shall be a violation of this title for

				the user of a consumer report to take any adverse action with respect to a

				consumer based solely on the inclusion of a fraud alert, extended alert, or

				active duty alert in the file of that consumer, as required by this

				subsection.</text>

					</subsection><after-quoted-block>.</after-quoted-block></quoted-block>

			</paragraph></section><section commented="no" display-inline="no-display-inline" id="id0BE7A68F168B46F4887A95C39EBCF135" section-type="subsequent-section"><enum>5.</enum><header>Studies and reports on

			 improving protection of customer information</header>

			<subsection commented="no" display-inline="no-display-inline" id="id63F886D02FE94B6CA54644FA3847C9BD"><enum>(a)</enum><header>Alternative

			 information storage methods</header>

				<paragraph commented="no" display-inline="no-display-inline" id="id84E88AE76DD54A48969F426A5FCE3AD1"><enum>(1)</enum><header>Study</header><text display-inline="yes-display-inline">The Federal Trade Commission shall conduct

			 a study of alternative technologies, including biometrics, that may be used by

			 financial institutions and other businesses to enhance the safeguarding of the

			 customer information of financial institutions and other sensitive personal

			 information. Such study shall include an analysis of how to ensure that such

			 information does not become widespread or subject to theft.</text>

				</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id9A208687899541239A8A9AB32936C5D9"><enum>(2)</enum><header>Report to

			 congress</header><text display-inline="yes-display-inline">The Commission shall

			 submit a report to the Congress on the results of the study conducted under

			 paragraph (1) not later than 6 months after the date of enactment of this

			 Act.</text>

				</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="id826CC1BB900347F4BE8C827D97EE06F4"><enum>(b)</enum><header>Transportation

			 of customer information</header>

				<paragraph commented="no" display-inline="no-display-inline" id="idD80AE5676FC54A2A8BA3DAF4EBCAD061"><enum>(1)</enum><header>Study</header><text display-inline="yes-display-inline">The Comptroller General of the United

			 States, in consultation with the Federal functional regulators and appropriate

			 law enforcement agencies, shall conduct a study of the cross country transport

			 of the customer information of financial institutions and other sensitive

			 personal information by or on behalf of financial institutions and other

			 businesses.</text>

				</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id3B21E70376434FAE8B7F862566F680F2"><enum>(2)</enum><header>Report to

			 congress</header><text display-inline="yes-display-inline">The Comptroller

			 General shall submit a report to the Congress on the results of the study

			 conducted under paragraph (1) not later than 6 months after the date of

			 enactment of this Act, including any recommendations on ways that financial

			 institutions may best reduce the risk of compromise, breach, or loss of the

			 customer information of financial institutions and other sensitive personal

			 information during transport.</text>

				</paragraph></subsection></section><section commented="no" display-inline="no-display-inline" id="id748BDB16AEA04FC4AFADE3F77D071DDB" section-type="subsequent-section"><enum>6.</enum><header>Effective

			 date</header><text display-inline="no-display-inline">This Act and the

			 amendments made by this Act shall take effect 6 months after the date of

			 enactment of this Act.</text>

		</section></legis-body>

</bill>

