<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public">

	<form>

		<distribution-code display="yes">II</distribution-code>

		<congress>109th CONGRESS</congress>

		<session>1st Session</session>

		<legis-num>S. 1789</legis-num>

		<current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber>

		<action>

			<action-date date="20050929">September 29, 2005</action-date>

			<action-desc><sponsor name-id="S161">Mr. Specter</sponsor> (for

			 himself, <cosponsor name-id="S057">Mr. Leahy</cosponsor>,

			 <cosponsor name-id="S221">Mrs. Feinstein</cosponsor>, and

			 <cosponsor name-id="S230">Mr. Feingold</cosponsor>) introduced the following

			 bill; which was read twice and referred to the

			 <committee-name committee-id="SSJU00">Committee on the

			 Judiciary</committee-name></action-desc>

		</action>

		<legis-type>A BILL</legis-type>

		<official-title>To prevent and mitigate identity theft, to ensure

		  privacy, to provide notice of security breaches, and to enhance criminal

		  penalties, law enforcement assistance, and other protections against security

		  breaches, fraudulent access, and misuse of personally identifiable

		  information.</official-title>

	</form>

	<legis-body>

		<section id="idA47571E6DAE44B7984E79D3D898E763E" section-type="section-one"><enum>1.</enum><header>Short title; table of

			 contents</header>

			<subsection id="IDc87f9d327baa427ea6b7bf79c88f5023"><enum>(a)</enum><header>Short

			 title</header><text>This Act may be cited as the <quote><short-title>Personal Data Privacy and Security Act of

			 2005</short-title></quote>.</text>

			</subsection><subsection id="id4AD6668978F1418AB24C94C1962DF104"><enum>(b)</enum><header>Table of

			 contents</header><text>The table of contents for this Act is as follows:</text>

				<toc>

					<toc-entry level="section">Sec. 1. Short title; table of

				contents.</toc-entry>

					<toc-entry idref="ID3a99fa5dde874d7abbbb86195b4f1976" level="section">Sec. 2. Findings.</toc-entry>

					<toc-entry idref="ID2cb86157d4344cf585e67049a45e1115" level="section">Sec. 3. Definitions.</toc-entry>

					<toc-entry idref="idB9E5C50426004F1A98B2FA27D5A2C46A" level="title">TITLE I—Enhancing punishment for identity theft and other

				violations of data privacy and security</toc-entry>

					<toc-entry idref="ID61e083d79c73471f84abe587faeefdc8" level="section">Sec. 101. Fraud and related criminal activity in connection

				with unauthorized access to personally identifiable information.</toc-entry>

					<toc-entry idref="id63126F2035C94E829418C6E150EE08C5" level="section">Sec. 102. Organized criminal activity in connection with

				unauthorized access to personally identifiable information.</toc-entry>

					<toc-entry idref="ID70a64b144d6247be93d4e8f09f04b114" level="section">Sec. 103. Concealment of security breaches involving sensitive

				personally identifiable information.</toc-entry>

					<toc-entry idref="ID4868ceaa18ae404f909aea47f5a379a8" level="section">Sec. 104. Aggravated fraud in connection with

				computers.</toc-entry>

					<toc-entry idref="idC4C20A02F98A4601AF7B6CFE40BF3C35" level="section">Sec. 105. Review and amendment of Federal sentencing guidelines

				related to fraudulent access to or misuse of digitized or electronic personally

				identifiable information.</toc-entry>

					<toc-entry idref="id7AE933BA8DCA42BE828EEAFB76777EF6" level="title">TITLE II—Assistance for state and local law enforcement combating

				crimes related to fraudulent, unauthorized, or other criminal use of personally

				identifiable information</toc-entry>

					<toc-entry idref="ID658dea62203e4e48853ba6c5949f6592" level="section">Sec. 201. Grants for State and local enforcement.</toc-entry>

					<toc-entry idref="ID57a283bdcc93459690dd9f4c0636c52e" level="section">Sec. 202. Authorization of appropriations.</toc-entry>

					<toc-entry idref="idB7F7E8794CAF4936BA0BB611DD93161F" level="title">TITLE III—Data brokers</toc-entry>

					<toc-entry idref="IDeccfb3aac4fd4b588b6e173e9e660124" level="section">Sec. 301. Transparency and accuracy of data

				collection.</toc-entry>

					<toc-entry idref="ID1c8011428bc24b24891956b4f7e6262d" level="section">Sec. 302. Enforcement.</toc-entry>

					<toc-entry level="section">Sec. 303. Relation to State

				laws.</toc-entry>

					<toc-entry idref="ID14ba6a6695f94105b011a272fdfadde0" level="section">Sec. 304. Effective date.</toc-entry>

					<toc-entry idref="id138193CF772D4A21983C5BAB2F03B469" level="title">TITLE IV—Privacy and security of personally identifiable

				information</toc-entry>

					<toc-entry idref="idB969701409E841279B2194E39DA6954F" level="subtitle">Subtitle A—Data privacy and security program</toc-entry>

					<toc-entry idref="id9AB3EE7075E9442AAC7653256781195F" level="section">Sec. 401. Purpose and applicability of data privacy and

				security program.</toc-entry>

					<toc-entry idref="ID5693f6a32a6442db906fdeee52d8b875" level="section">Sec. 402. Requirements for a personal data privacy and security

				program.</toc-entry>

					<toc-entry idref="ID5f321c3d88964c2fbff395285c6073fa" level="section">Sec. 403. Enforcement.</toc-entry>

					<toc-entry level="section">Sec. 404. Relation to State

				laws.</toc-entry>

					<toc-entry level="subtitle">Subtitle B—Security breach

				notification</toc-entry>

					<toc-entry level="section">Sec. 421. Right to notice of security

				breach.</toc-entry>

					<toc-entry level="section">Sec. 422. Notice procedures.</toc-entry>

					<toc-entry level="section">Sec. 423. Content of notice.</toc-entry>

					<toc-entry level="section">Sec. 424. Risk assessment and fraud

				prevention notice exemptions.</toc-entry>

					<toc-entry level="section">Sec. 425. Victim protection

				assistance.</toc-entry>

					<toc-entry level="section">Sec. 426. Enforcement.</toc-entry>

					<toc-entry level="section">Sec. 427. Relation to State

				laws.</toc-entry>

					<toc-entry level="section">Sec. 428. Study on securing personally

				identifiable information in the digital era.</toc-entry>

					<toc-entry level="section">Sec. 429. Reporting on risk assessment

				exemption.</toc-entry>

					<toc-entry level="section">Sec. 430. Authorization of

				appropriations.</toc-entry>

					<toc-entry level="section">Sec. 431. Reporting on risk assessment

				exemption.</toc-entry>

					<toc-entry level="section">Sec. 432. Effective date.</toc-entry>

					<toc-entry idref="id8314F1C7466A4B5EA597E466FA3259A8" level="title">TITLE V—Government access to and use of commercial

				data</toc-entry>

					<toc-entry idref="IDe80a8e1d714e420fa5bfe423fac8281f" level="section">Sec. 501. General Services Administration review of

				contracts.</toc-entry>

					<toc-entry idref="idCAE548F38BD64ECD90834972854E1CA7" level="section">Sec. 502. Requirement to audit information security practices

				of contractors and third party business entities.</toc-entry>

					<toc-entry idref="idB8E458C334C14BAD80F90A39D0FCEDB0" level="section">Sec. 503. Privacy impact assessment of government use of

				commercial information services containing personally identifiable

				information.</toc-entry>

					<toc-entry idref="id1055A56CF08341A09FA12FC834F96E1F" level="section">Sec. 504. Implementation of Chief Privacy Officer

				requirements.</toc-entry>

				</toc>

			</subsection></section><section id="ID3a99fa5dde874d7abbbb86195b4f1976"><enum>2.</enum><header>Findings</header><text display-inline="no-display-inline">Congress finds that—</text>

			<paragraph id="IDbd50cd8850ca4cd3a2b20db4c4a36920"><enum>(1)</enum><text>databases of

			 personally identifiable information are increasingly prime targets of hackers,

			 identity thieves, rogue employees, and other criminals, including organized and

			 sophisticated criminal operations;</text>

			</paragraph><paragraph id="ID03db461415d74169bcab72cba60e08ed"><enum>(2)</enum><text>identity theft is

			 a serious threat to the nation’s economic stability, homeland security, the

			 development of e-commerce, and the privacy rights of Americans;</text>

			</paragraph><paragraph id="ID86ea35f99abd4193b1da39379558087c"><enum>(3)</enum><text>over 9,300,000

			 individuals were victims of identity theft in America last year;</text>

			</paragraph><paragraph id="ID1c625ca80ddc434d9e1f7dae079aad9d"><enum>(4)</enum><text>security breaches

			 are a serious threat to consumer confidence, homeland security, e-commerce, and

			 economic stability;</text>

			</paragraph><paragraph id="ID6e69dbdf8ad14bb486524463249d8899"><enum>(5)</enum><text>it is important

			 for business entities that own, use, or license personally identifiable

			 information to adopt reasonable procedures to ensure the security, privacy, and

			 confidentially of that personally identifiable information;</text>

			</paragraph><paragraph id="ID355c3de5e3814b88954da33997b3aa85"><enum>(6)</enum><text>individuals whose

			 personal information has been compromised or who have been victims of identity

			 theft should receive the necessary information and assistance to mitigate their

			 damages and to restore the integrity of their personal information and

			 identities;</text>

			</paragraph><paragraph id="IDa83ec532458f410ab604968d164a5478"><enum>(7)</enum><text>data brokers have

			 assumed a significant role in providing identification, authentication, and

			 screening services, and related data collection and analyses for commercial,

			 nonprofit, and government operations;</text>

			</paragraph><paragraph id="IDc582b786f7f2435990d78d773b795bb1"><enum>(8)</enum><text>data misuse and

			 use of inaccurate data have the potential to cause serious or irreparable harm

			 to an individual’s livelihood, privacy, and liberty and undermine efficient and

			 effective business and government operations;</text>

			</paragraph><paragraph id="ID582f1ab874984f1baeec1e6d0eb33b89"><enum>(9)</enum><text>there is a need

			 to insure that data brokers conduct their operations in a manner that

			 prioritizes fairness, transparency, accuracy, and respect for the privacy of

			 consumers;</text>

			</paragraph><paragraph id="IDea1b485a5334493bab3bbce5ceeec1e6"><enum>(10)</enum><text>government

			 access to commercial data can potentially improve safety, law enforcement, and

			 national security; and</text>

			</paragraph><paragraph id="IDf949bf34f81c4bf4912a6019a364c472"><enum>(11)</enum><text>because

			 government use of commercial data containing personal information potentially

			 affects individual privacy, and law enforcement and national security

			 operations, there is a need for Congress to exercise oversight over government

			 use of commercial data.</text>

			</paragraph></section><section id="ID2cb86157d4344cf585e67049a45e1115"><enum>3.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act:</text>

			<paragraph id="id332573F632A94401B1DED8176EAA01E0"><enum>(1)</enum><header>Agency</header><text>The

			 term <term>agency</term> has the same meaning given such term in section 551 of

			 title 5, United States Code.</text>

			</paragraph><paragraph id="IDf72769f09dcb4f7ba90bcfc2fd831b76"><enum>(2)</enum><header>Affiliate</header><text>The

			 term <term>affiliate</term> means persons related by common ownership or by

			 corporate control.</text>

			</paragraph><paragraph id="ID27f5488104ca429ea9b7e2b98456f958"><enum>(3)</enum><header>Business

			 entity</header><text>The term <term>business entity</term> means any

			 organization, corporation, trust, partnership, sole proprietorship,

			 unincorporated association, venture established to make a profit, or nonprofit,

			 and any contractor, subcontractor, affiliate, or licensee thereof engaged in

			 interstate commerce.</text>

			</paragraph><paragraph id="ID73fd80cfde874bd78413fcbc4953fc56"><enum>(4)</enum><header>Identity

			 theft</header><text>The term <term>identity theft</term> means a violation of

			 section 1028 of title 18, United States Code, or any other similar provision of

			 applicable State law.</text>

			</paragraph><paragraph id="IDf9c3527a109f45318c836f593d34c0b3"><enum>(5)</enum><header>Data

			 broker</header><text>The term <quote>data broker</quote> means a business

			 entity which for monetary fees, dues, or on a cooperative nonprofit basis,

			 currently or regularly engages, in whole or in part, in the practice of

			 collecting, transmitting, or providing access to sensitive personally

			 identifiable information primarily for the purposes of providing such

			 information to nonaffiliated third parties on a nationwide basis on more than

			 5,000 individuals who are not the customers or employees of the business entity

			 or affiliate.</text>

			</paragraph><paragraph id="ID4ddf8e8ac4774912a93f26db45edc267"><enum>(6)</enum><header>Data

			 furnisher</header><text>The term <quote>data furnisher</quote> means any

			 agency, governmental entity, organization, corporation, trust, partnership,

			 sole proprietorship, unincorporated association, venture established to make a

			 profit, or nonprofit, and any contractor, subcontractor, affiliate, or licensee

			 thereof, that serves as a source of information for a data broker.</text>

			</paragraph><paragraph id="idD8CDB1539206495CAA26B37C12D61A9D"><enum>(7)</enum><header>personal

			 electronic record</header><text>The term <quote>personal electronic

			 record</quote> means data associated with an individual contained in a

			 database, networked or integrated databases, or other data system that holds

			 sensitive personally identifiable information of that individual and is

			 provided to non-affiliated third parties.</text>

			</paragraph><paragraph id="ID1e76acaab9154264a9c601a996657c7e"><enum>(8)</enum><header>Personally

			 identifiable information</header><text>The term <term>personally identifiable

			 information</term> means any information, or compilation of information, in

			 electronic or digital form serving as a means of identification, as defined by

			 section 1028(d)(7) of title 18, United State Code.</text>

			</paragraph><paragraph id="id848834213504426C8D6E9456CDFDB2F0"><enum>(9)</enum><header>Public record

			 source</header><text>The term <term>public record source</term> means any

			 agency, Federal court, or State court that maintains personally identifiable

			 information in records available to the public.</text>

			</paragraph><paragraph id="ID5214bc9bc9ba4d9890336645be2953a0"><enum>(10)</enum><header>Security

			 breach</header>

				<subparagraph id="id4941985E6DB0444AA70D40679B94CDEE"><enum>(A)</enum><header>In

			 General</header><text>The term <term>security breach</term> means compromise of

			 the security, confidentiality, or integrity of computerized data through

			 misrepresentation or actions that result in, or there is a reasonable basis to

			 conclude has resulted in, the unauthorized acquisition of and access to

			 sensitive personally identifiable information.</text>

				</subparagraph><subparagraph id="id42BD23F9788345B19DE038090B2A8DF8"><enum>(B)</enum><header>Exclusion</header><text>The

			 term <quote>security breach</quote> does not include—</text>

					<clause id="id223DB9A85EF744DA90FE6093C380F49C"><enum>(i)</enum><text>a

			 good faith acquisition of sensitive personally identifiable information by a

			 business entity or agency, or an employee or agent of a business entity or

			 agency, if the sensitive personally identifiable information is not subject to

			 further unauthorized disclosure; or</text>

					</clause><clause id="id9843C00276D14DFE9613D60FF0CE62D7"><enum>(ii)</enum><text>the release of a

			 public record not otherwise subject to confidentiality or nondisclosure

			 requirements.</text>

					</clause></subparagraph></paragraph><paragraph id="ID2f6c81920d734130a86113e5f7af0a6f"><enum>(11)</enum><header>Sensitive

			 personally identifiable information</header><text>The term <term>sensitive

			 personally identifiable information</term> means any information or compilation

			 of information, in electronic or digital form that includes:</text>

				<subparagraph id="id369E5601147A46C2B493FCAD2F1C0388"><enum>(A)</enum><text>An individual's

			 name in combination with any 1 of the following data elements:</text>

					<clause id="IDf0a3bb539d8a4566a0151b0d8e276e43"><enum>(i)</enum><text>A

			 non-truncated social security number, driver's license number, passport number,

			 or alien registration number.</text>

					</clause><clause id="ID025aa618eae945ac8cf8b29590c5b109"><enum>(ii)</enum><text>Any 2 of the

			 following:</text>

						<subclause id="idFF28ABD5BB6D4DF8806E599DAA9FE8B1"><enum>(I)</enum><text>Information that

			 relates to—</text>

							<item id="id69B39070FC6244068CB88683B6437801"><enum>(aa)</enum><text>the

			 past, present, or future physical or mental health or condition of an

			 individual;</text>

							</item><item id="id019DEF4F67D84D7687529BD340304F4A"><enum>(bb)</enum><text>the

			 provision of health care to an individual; or</text>

							</item><item id="id47472F3928A04EF0B71771832D7B29E3"><enum>(cc)</enum><text>the

			 past, present, or future payment for the provision of health care to an

			 individual.</text>

							</item></subclause><subclause id="id510565911A50442EA20C2706E73469EB"><enum>(II)</enum><text>Home address or

			 telephone number.</text>

						</subclause><subclause id="id221A03CC48C94EE49ABB227C9DEED072"><enum>(III)</enum><text>Mother's maiden

			 name, if identified as such.</text>

						</subclause><subclause id="id71D0A652BF424CFB81E76A5CFF65A55B"><enum>(IV)</enum><text>Month, day, and

			 year of birth.</text>

						</subclause></clause><clause id="id5FFB1647E12E4A1E893498AD7F03AD29"><enum>(iii)</enum><text>Unique

			 biometric data such as a finger print, voice print, a retina or iris image, or

			 any other unique physical representation.</text>

					</clause><clause id="id80192FFB2F8648A2B7F0CA6204FCC0EA"><enum>(iv)</enum><text>A

			 unique electronic identification number, user name, or routing code in

			 combination with the associated security code, access code, or password.</text>

					</clause><clause commented="no" display-inline="no-display-inline" id="ID53d3dd7fcefd4632acc9e26a5ff8ee92"><enum>(v)</enum><text>Any other

			 information regarding an individual determined appropriate by the Federal Trade

			 Commission.</text>

					</clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idE22E0599D884406CBBC64F53036A3652"><enum>(B)</enum><text>A financial

			 account number or credit or debit card number in combination with the required

			 security code, access code, or password.</text>

				</subparagraph></paragraph></section><title id="idB9E5C50426004F1A98B2FA27D5A2C46A"><enum>I</enum><header>Enhancing

			 punishment for identity theft and other violations of data privacy and

			 security</header>

			<section id="ID61e083d79c73471f84abe587faeefdc8"><enum>101.</enum><header>Fraud and

			 related criminal activity in connection with unauthorized access to personally

			 identifiable information</header><text display-inline="no-display-inline">Section 1030(a)(2) of title 18, United

			 States Code, is amended—</text>

				<paragraph id="id167EF4DBD506403CB33EC942C15C857A"><enum>(1)</enum><text display-inline="yes-display-inline">in subparagraph (B), by striking

			 <quote>or</quote> after the semicolon;</text>

				</paragraph><paragraph id="id0B378F7E00F8435183BFDC9935046238"><enum>(2)</enum><text>in subparagraph

			 (C), by inserting <quote>or</quote> after the semicolon; and</text>

				</paragraph><paragraph id="id668C984F5F464EE0BF096DA0C22263C1"><enum>(3)</enum><text>by adding at the

			 end the following:</text>

					<quoted-block display-inline="no-display-inline" id="id3E71C5CA58D545CBB516BF9C700D5326" style="OLC">

						<subparagraph id="id8EFFE5D364F442A8B125D3A2837C70A6"><enum>(D)</enum><text>information

				contained in the databases or systems of a data broker, or in other personal

				electronic records, as such terms are defined in section 3 of the Personal Data

				Privacy and Security Act of

				2005;</text>

						</subparagraph><after-quoted-block>.</after-quoted-block></quoted-block>

				</paragraph></section><section id="id63126F2035C94E829418C6E150EE08C5"><enum>102.</enum><header>Organized

			 criminal activity in connection with unauthorized access to personally

			 identifiable information</header><text display-inline="no-display-inline">Section 1961(1) of title 18, United States

			 Code, is amended by inserting <quote>section 1030(a)(2)(D)(relating to fraud

			 and related activity in connection with unauthorized access to personally

			 identifiable information,</quote> before <quote>section 1084</quote>.</text>

			</section><section id="ID70a64b144d6247be93d4e8f09f04b114"><enum>103.</enum><header>Concealment of

			 security breaches involving sensitive personally identifiable

			 information</header>

				<subsection id="id25F83CAF43EC45BE8D42EE4F7CF85091"><enum>(a)</enum><header>In

			 general</header><text display-inline="yes-display-inline">Chapter 47 of title

			 18, United States Code, is amended by adding at the end the following:</text>

					<quoted-block act-name="" display-inline="no-display-inline" id="id2080910D48CA48739E1F132569D2FE09" style="USC">

						<section id="ID63bafa953e254711bc4cf1f2f3f2e802"><enum>1039.</enum><header>Concealment

				of security breaches involving sensitive personally identifiable

				information</header>

							<subsection id="idF01848EB765E4EB7816DD3CCD811D12C"><enum>(a)</enum><text display-inline="yes-display-inline">Whoever, having knowledge of a security

				breach and the obligation to provide notice of such breach to individuals under

				title IV of the Personal Data Privacy and Security Act of 2005, and having not

				otherwise qualified for an exemption from providing notice under section 422 of

				such Act, intentionally and willfully conceals the fact of such security breach

				which causes economic damages to 1 or more persons, shall be fined under this

				title or imprisoned not more than 5 years, or both.</text>

							</subsection><subsection id="id1FCDA535E7B043EFA418511FF7B52556"><enum>(b)</enum><text display-inline="yes-display-inline">For purposes of subsection (a), the term

				<quote>person</quote> means any individual, corporation, company, association,

				firm, partnership, society, or joint stock

				company.</text>

							</subsection></section><after-quoted-block>.</after-quoted-block></quoted-block>

				</subsection><subsection id="idE93AFC9E494546AAA07F96705A26C6C2"><enum>(b)</enum><header>Conforming and

			 technical amendments</header><text>The table of sections for chapter 47 of

			 title 18, United States Code, is amended by adding at the end the

			 following:</text>

					<toc>

						<toc-entry level="section"><quote>1039. Concealment of security

				breaches involving personally identifiable information.</quote>. </toc-entry>

					</toc>

				</subsection><subsection id="id23D73A3EC3054CE19B4D6DE22794B595"><enum>(c)</enum><header>Enforcement

			 authority</header><text>The United States Secret Service shall have the

			 authority to investigate offenses under this section.</text>

				</subsection></section><section id="ID4868ceaa18ae404f909aea47f5a379a8"><enum>104.</enum><header>Aggravated

			 fraud in connection with computers</header>

				<subsection id="id120B2EEC0ECA4CC48C181529F621EB40"><enum>(a)</enum><header>In

			 general</header><text display-inline="yes-display-inline">Chapter 47 of title

			 18, United States Code, is amended by adding after section 1030 the

			 following:</text>

					<quoted-block act-name="" display-inline="no-display-inline" id="idE47332D6CD974E25B8EDD6E5102EDA6B" style="USC">

						<section id="idF92FFB5B44394885A3BB23E6469A7F8F"><enum>1030A.</enum><header>Aggravated

				fraud in connection with computers </header>

							<subsection id="idE1B6555CF5864447BF77B3E6BEBDE80C"><enum>(a)</enum><header>In

				general</header><text>Whoever, during and in relation to any felony violation

				enumerated in subsection (c), knowingly obtains, accesses, or transmits,

				without lawful authority, a means of identification of another person may, in

				addition to the punishment provided for such felony, be sentenced to a term of

				imprisonment of up to 2 years.</text>

							</subsection><subsection id="id136452167BDC4DA8BAD0595A27A37D80"><enum>(b)</enum><header>Consecutive

				sentences</header><text>Notwithstanding any other provision of law, should a

				court in its discretion impose an additional sentence under subsection

				(a)—</text>

								<paragraph id="IDca8209d20e9145e9976c1a8d0b83e1aa"><enum>(1)</enum><text>no term of

				imprisonment imposed on a person under this section shall run concurrently,

				except as provided in paragraph (3), with any other term of imprisonment

				imposed on such person under any other provision of law, including any term of

				imprisonment imposed for the felony during which the means of identifications

				was obtained, accessed, or transmitted;</text>

								</paragraph><paragraph id="IDc70ec296b91841e1b9b6fd69680eda06"><enum>(2)</enum><text>in determining

				any term of imprisonment to be imposed for the felony during which the means of

				identification was obtained, accessed, or transmitted, a court shall not in any

				way reduce the term to be imposed for such crime so as to compensate for, or

				otherwise take into account, any separate term of imprisonment imposed or to be

				imposed for a violation of this section; and</text>

								</paragraph><paragraph id="IDa4cd2847e6a747fb83b873aa144b7fc9"><enum>(3)</enum><text>a term of

				imprisonment imposed on a person for a violation of this section may, in the

				discretion of the court, run concurrently, in whole or in part, only with

				another term of imprisonment that is imposed by the court at the same time on

				that person for an additional violation of this section.</text>

								</paragraph></subsection><subsection id="id7A3695AA73DC4904B2482F7AA4560D18"><enum>(c)</enum><header>Definition</header><text>For

				purposes of this section, the term <quote>felony violation enumerated in

				subsection (c)</quote> means any offense that is a felony violation of

				paragraphs (2) through (7) of section

				1030(a).</text>

							</subsection></section><after-quoted-block>.</after-quoted-block></quoted-block>

				</subsection><subsection id="id912A7E3E85FB4E3A9A3C088849CAA03E"><enum>(b)</enum><header>Conforming and

			 technical amendments</header><text>The table of sections for chapter 47 of

			 title 18, United States Code, is amended by inserting after the item relating

			 to section 1030 the following new item:</text>

					<toc>

						<toc-entry level="section"><quote>1030A. Aggravated fraud in

				connection with computers.</quote>. </toc-entry>

					</toc>

				</subsection></section><section id="idC4C20A02F98A4601AF7B6CFE40BF3C35"><enum>105.</enum><header>Review and

			 amendment of Federal sentencing guidelines related to fraudulent access to or

			 misuse of digitized or electronic personally identifiable information</header>

				<subsection id="ID2bd5bb5b497a4dda94d5f1f9bdf960b0"><enum>(a)</enum><header>Review and

			 amendment</header><text>Not later than 180 days after the date of enactment of

			 this Act, the United States Sentencing Commission, pursuant to its authority

			 under section 994 of title 28, United States Code, and in accordance with this

			 section, shall review and, if appropriate, amend the Federal sentencing

			 guidelines (including its policy statements) applicable to persons convicted of

			 using fraud to access, or misuse of, digitized or electronic personally

			 identifiable information, including identity theft or any offense under—</text>

					<paragraph id="IDf723d8a9c5df49b78c2acee27f8c18e1"><enum>(1)</enum><text>sections 1028,

			 1028A, 1030, 1030A, 2511, and 2701 of title 18, United States Code; or</text>

					</paragraph><paragraph id="ID26a03e40e13b4e5da8dfaa3a141277ec"><enum>(2)</enum><text>any other

			 relevant provision.</text>

					</paragraph></subsection><subsection id="IDb9eb2288b26340b29d08a02cb933d4cd"><enum>(b)</enum><header>Requirements</header><text>In

			 carrying out the requirements of this section, the United States Sentencing

			 Commission shall—</text>

					<paragraph id="ID41ee8258c25d405291ccf31ac075b733"><enum>(1)</enum><text>ensure that the

			 Federal sentencing guidelines (including its policy statements) reflect—</text>

						<subparagraph id="ID32704ac0c2f54849908376111e428a51"><enum>(A)</enum><text>the serious

			 nature of the offenses and penalties referred to in this Act;</text>

						</subparagraph><subparagraph id="ID81f4246e43e24dc4a6846d27df42d688"><enum>(B)</enum><text>the growing

			 incidences of theft and misuse of digitized or electronic personally

			 identifiable information, including identity theft; and</text>

						</subparagraph><subparagraph id="ID1931699b3c59400290df3ca80fa93542"><enum>(C)</enum><text>the need to

			 deter, prevent, and punish such offenses;</text>

						</subparagraph></paragraph><paragraph id="ID380a86f2614f45a398a3fbeef4243915"><enum>(2)</enum><text>consider the

			 extent to which the Federal sentencing guidelines (including its policy

			 statements) adequately address violations of the sections amended by this Act

			 to—</text>

						<subparagraph id="IDc01062d0e2cc4869b67211cfdef7bbe6"><enum>(A)</enum><text>sufficiently

			 deter and punish such offenses; and</text>

						</subparagraph><subparagraph id="IDc57b3a1aecd148588803acbfa6a5e73e"><enum>(B)</enum><text>adequately

			 reflect the enhanced penalties established under this Act;</text>

						</subparagraph></paragraph><paragraph id="ID88f7c314e9ab41c8aa53038855d5f683"><enum>(3)</enum><text>maintain

			 reasonable consistency with other relevant directives and sentencing

			 guidelines;</text>

					</paragraph><paragraph id="IDfdfbd554a5aa48d7b893afdd7ac30b64"><enum>(4)</enum><text>account for any

			 additional aggravating or mitigating circumstances that might justify

			 exceptions to the generally applicable sentencing ranges;</text>

					</paragraph><paragraph id="id1873C82E53004B8BB61A72CA2117B5EA"><enum>(5)</enum><text>consider whether

			 to provide a sentencing enhancement for those convicted of the offenses

			 described in subsection (a), if the conduct involves—</text>

						<subparagraph id="IDc976cfbfcbef4f55a30ed39839cca2d8"><enum>(A)</enum><text>the online sale

			 of fraudulently obtained or stolen personally identifiable information;</text>

						</subparagraph><subparagraph id="ID561da5449fac4ba58ca4fb6ebc5a4011"><enum>(B)</enum><text>the sale of

			 fraudulently obtained or stolen personally identifiable information to an

			 individual who is engaged in terrorist activity or aiding other individuals

			 engaged in terrorist activity; or</text>

						</subparagraph><subparagraph id="ID1e06665b9e24443a812b804fe18fe950"><enum>(C)</enum><text>the sale of

			 fraudulently obtained or stolen personally identifiable information to finance

			 terrorist activity or other criminal activities;</text>

						</subparagraph></paragraph><paragraph id="ID588a4a5bbb7f4a9c93a7b4de4c34fe84"><enum>(6)</enum><text>make any

			 necessary conforming changes to the Federal sentencing guidelines to ensure

			 that such guidelines (including its policy statements) as described in

			 subsection (a) are sufficiently stringent to deter, and adequately reflect

			 crimes related to fraudulent access to, or misuse of, personally identifiable

			 information; and</text>

					</paragraph><paragraph id="IDcd872ce7a7e84ffe9cf4eb230f654565"><enum>(7)</enum><text>ensure that the

			 Federal sentencing guidelines adequately meet the purposes of sentencing under

			 section 3553(a)(2) of title 18, United States Code.</text>

					</paragraph></subsection><subsection id="id9EDB15E299B349FE9E5212EBC50E595D"><enum>(c)</enum><header>Emergency

			 authority to sentencing commission</header><text>The United States Sentencing

			 Commission may, as soon as practicable, promulgate amendments under this

			 section in accordance with procedures established in section 21(a) of the

			 Sentencing Act of 1987 (28 U.S.C. 994 note) as though the authority under that

			 Act had not expired.</text>

				</subsection></section></title><title id="id7AE933BA8DCA42BE828EEAFB76777EF6"><enum>II</enum><header>Assistance for

			 state and local law enforcement combating crimes related to fraudulent,

			 unauthorized, or other criminal use of personally identifiable

			 information</header>

			<section id="ID658dea62203e4e48853ba6c5949f6592"><enum>201.</enum><header>Grants for

			 State and local enforcement</header>

				<subsection id="IDe11c2f2366374d49a2e44349e98f26db"><enum>(a)</enum><header>In

			 general</header><text>Subject to the availability of amounts provided in

			 advance in appropriations Acts, the Assistant Attorney General for the Office

			 of Justice Programs of the Department of Justice may award a grant to a State

			 to establish and develop programs to increase and enhance enforcement against

			 crimes related to fraudulent, unauthorized, or other criminal use of personally

			 identifiable information.</text>

				</subsection><subsection id="idEC522DF89D844052A7BE0ADCE4B297BE"><enum>(b)</enum><header>Application</header><text>A

			 State seeking a grant under subsection (a) shall submit an application to the

			 Assistant Attorney General for the Office of Justice Programs of the Department

			 of Justice at such time, in such manner, and containing such information as the

			 Assistant Attorney General may require.</text>

				</subsection><subsection id="ID93ee6021ddc44f139fb242f63926c3ed"><enum>(c)</enum><header>Use of grant

			 amounts</header><text>A grant awarded to a State under subsection (a) shall be

			 used by a State, in conjunction with units of local government within that

			 State, State and local courts, other States, or combinations thereof, to

			 establish and develop programs to—</text>

					<paragraph id="ID123408b1c76c4c36ae4f48c57f1b0484"><enum>(1)</enum><text>assist State and

			 local law enforcement agencies in enforcing State and local criminal laws

			 relating to crimes involving the fraudulent, unauthorized, or other criminal

			 use of personally identifiable information;</text>

					</paragraph><paragraph id="ID5f3f802e55f149e7bdbb9b5c66192f08"><enum>(2)</enum><text>assist State and

			 local law enforcement agencies in educating the public to prevent and identify

			 crimes involving the fraudulent, unauthorized, or other criminal use of

			 personally identifiable information;</text>

					</paragraph><paragraph id="ID73a70ad30052456896694999d66d5e08"><enum>(3)</enum><text>educate and train

			 State and local law enforcement officers and prosecutors to conduct

			 investigations and forensic analyses of evidence and prosecutions of crimes

			 involving the fraudulent, unauthorized, or other criminal use of personally

			 identifiable information;</text>

					</paragraph><paragraph id="ID67e0bafc7b9543f1913dd2b803c2b7bc"><enum>(4)</enum><text>assist State and

			 local law enforcement officers and prosecutors in acquiring computer and other

			 equipment to conduct investigations and forensic analysis of evidence of crimes

			 involving the fraudulent, unauthorized, or other criminal use of personally

			 identifiable information; and</text>

					</paragraph><paragraph id="ID827de869205241ab9dbfc2da8da354ae"><enum>(5)</enum><text>facilitate and

			 promote the sharing of Federal law enforcement expertise and information about

			 the investigation, analysis, and prosecution of crimes involving the

			 fraudulent, unauthorized, or other criminal use of personally identifiable

			 information with State and local law enforcement officers and prosecutors,

			 including the use of multi-jurisdictional task forces.</text>

					</paragraph></subsection><subsection id="IDf14e4dec11924a30a9f658aabc81743e"><enum>(d)</enum><header>Assurances and

			 eligibility</header><text>To be eligible to receive a grant under subsection

			 (a), a State shall provide assurances to the Attorney General that the

			 State—</text>

					<paragraph id="ID083c31bf4e6b414ca34108fe81a0a931"><enum>(1)</enum><text>has in effect

			 laws that penalize crimes involving the fraudulent, unauthorized, or other

			 criminal use of personally identifiable information, such as penal laws

			 prohibiting—</text>

						<subparagraph id="ID84eacf9998454eca9a183604d98575bf"><enum>(A)</enum><text>fraudulent

			 schemes executed to obtain personally identifiable information;</text>

						</subparagraph><subparagraph id="IDad8e3a9492244a7c82847fc181a86648"><enum>(B)</enum><text>schemes executed

			 to sell or use fraudulently obtained personally identifiable information;

			 and</text>

						</subparagraph><subparagraph id="IDfd97ae8f57574738a4b5bf342a6ae69b"><enum>(C)</enum><text>online sales of

			 personally identifiable information obtained fraudulently or by other illegal

			 means;</text>

						</subparagraph></paragraph><paragraph id="ID3fff5bdf4a6644b68a93e928cf15983c"><enum>(2)</enum><text>will provide an

			 assessment of the resource needs of the State and units of local government

			 within that State, including criminal justice resources being devoted to the

			 investigation and enforcement of laws related to crimes involving the

			 fraudulent, unauthorized, or other criminal use of personally identifiable

			 information; and</text>

					</paragraph><paragraph id="ID49af589de2de47e5b530cb5f1060240b"><enum>(3)</enum><text>will develop a

			 plan for coordinating the programs funded under this section with other

			 federally funded technical assistant and training programs, including directly

			 funded local programs such as the Local Law Enforcement Block Grant program

			 (described under the heading <quote>Violent Crime Reduction Programs, State and

			 Local Law Enforcement Assistance</quote> of the Departments of Commerce,

			 Justice, and State, the Judiciary, and Related Agencies Appropriations Act,

			 1998 (Public Law 105–119)).</text>

					</paragraph></subsection><subsection id="ID5ffc39c69366469fa60575861d50861b"><enum>(e)</enum><header>Matching

			 funds</header><text>The Federal share of a grant received under this section

			 may not exceed 90 percent of the total cost of a program or proposal funded

			 under this section unless the Attorney General waives, wholly or in part, the

			 requirements of this subsection.</text>

				</subsection></section><section id="ID57a283bdcc93459690dd9f4c0636c52e"><enum>202.</enum><header>Authorization

			 of appropriations</header>

				<subsection id="ID25feba6d720542ab8fc08893c6f61cd4"><enum>(a)</enum><header>In

			 general</header><text>There is authorized to be appropriated to carry out this

			 title $25,000,000 for each of fiscal years 2006 through 2009.</text>

				</subsection><subsection id="IDce529b4ad8804711983c4e6a48e4f386"><enum>(b)</enum><header>Limitations</header><text>Of

			 the amount made available to carry out this title in any fiscal year not more

			 than 3 percent may be used by the Attorney General for salaries and

			 administrative expenses.</text>

				</subsection><subsection id="ID854c8539514c4047980a110d695df691"><enum>(c)</enum><header>Minimum

			 amount</header><text>Unless all eligible applications submitted by a State or

			 units of local government within a State for a grant under this title have been

			 funded, the State, together with grantees within the State (other than Indian

			 tribes), shall be allocated in each fiscal year under this title not less than

			 0.75 percent of the total amount appropriated in the fiscal year for grants

			 pursuant to this title, except that the United States Virgin Islands, American

			 Samoa, Guam, and the Northern Mariana Islands each shall be allocated 0.25

			 percent.</text>

				</subsection><subsection id="IDfb1765d8a7dd479cafc476ebeed5bca5"><enum>(d)</enum><header>Grants to

			 Indian tribes</header><text>Notwithstanding any other provision of this title,

			 the Attorney General may use amounts made available under this title to make

			 grants to Indian tribes for use in accordance with this title.</text>

				</subsection></section></title><title id="idB7F7E8794CAF4936BA0BB611DD93161F"><enum>III</enum><header>Data

			 brokers</header>

			<section id="IDeccfb3aac4fd4b588b6e173e9e660124"><enum>301.</enum><header>Transparency

			 and accuracy of data collection</header>

				<subsection id="IDe05080b3ea064673a744a944c6d9ee91"><enum>(a)</enum><header>In

			 general</header><text>Data brokers engaging in interstate commerce are subject

			 to the requirements of this title for any product or service offered to third

			 parties that allows access, use, compilation, distribution, processing,

			 analyzing, or evaluation of sensitive personally identifiable

			 information.</text>

				</subsection><subsection id="id71ABA5E9FF8944288312518B7D3C8B6B"><enum>(b)</enum><header>limitation</header><text>Notwithstanding

			 any other paragraph of this title, this section shall not apply to—</text>

					<paragraph id="idE4668B72D4C94F1A8BB7A53FFD6BEAAE"><enum>(1)</enum><text>data brokers

			 engaging in interstate commerce for any offered product or service currently

			 subject to, and in compliance with, access and accuracy protections similar to

			 those under subsections (c) through (f) of this section under the Fair Credit

			 Reporting Act (Public Law 91–508), or the Gramm-Leach Bliley Act (Public Law

			 106–102);</text>

					</paragraph><paragraph id="idBE6452BE27A84596A846628E871EE083"><enum>(2)</enum><text>data brokers

			 engaging in interstate commerce for any offered product or service currently in

			 compliance with the requirements for such entities under the Health Insurance

			 Portability and Accountability Act (Public Law 104–191), and implementing

			 regulations;</text>

					</paragraph><paragraph id="id058543B3C7B4467085E594350E1353AF"><enum>(3)</enum><text>information in a

			 personal electronic record held by a data broker if—</text>

						<subparagraph id="id8C171FC8915E440292C433CBCB48DD53"><enum>(A)</enum><text>the data broker

			 maintains such information solely pursuant to a license agreement with another

			 business entity; and</text>

						</subparagraph><subparagraph id="idF7BAAEFC15A2458A9CD2D6A2EECE5F22"><enum>(B)</enum><text>the business

			 entity providing such information to the data broker pursuant to a license

			 agreement either complies with the provisions of this section or qualifies for

			 this exemption; and</text>

						</subparagraph></paragraph><paragraph id="idC4E33C12CEA8423AB288AC22DF1679E0"><enum>(4)</enum><text>information in a

			 personal record that—</text>

						<subparagraph id="idB6B392427A9543729A7D1EE848739164"><enum>(A)</enum><text>the data broker

			 has identified as inaccurate, but maintains for the purpose of aiding the data

			 broker in preventing inaccurate information from entering an individual's

			 personal electronic record; and</text>

						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id2207D6B31AE742BE9D1BD39C69EF63C2"><enum>(B)</enum><text>is not maintained

			 primarily for the purpose of transmitting or otherwise providing that

			 information, or assessments based on that information, to non-affiliated third

			 parties.</text>

						</subparagraph></paragraph></subsection><subsection id="ID265dd81f54a04aaea0aa4ed6284c6192"><enum>(c)</enum><header>Disclosures to

			 individuals</header>

					<paragraph id="idC3AD44CCB59F46E494C7C424D220CD8B"><enum>(1)</enum><header>In

			 general</header><text>A data broker shall, upon the request of an individual,

			 clearly and accurately disclose to such individual for a reasonable fee all

			 personal electronic records pertaining to that individual maintained for

			 disclosure to third parties in the ordinary course of business in the databases

			 or systems of the data broker at the time of the request.</text>

					</paragraph><paragraph id="idC177AF910684499489B81D330554E056"><enum>(2)</enum><header>Information on

			 how to correct inaccuracies</header><text>The disclosures required under

			 paragraph (1) shall also include guidance to individuals on the processes and

			 procedures for demonstrating and correcting any inaccuracies.</text>

					</paragraph></subsection><subsection id="ID19090d9d4ba04538ace70172b84f8719"><enum>(d)</enum><header>Creation of an

			 accuracy resolution process</header><text>A data broker shall develop and

			 publish on its website timely and fair processes and procedures for responding

			 to claims of inaccuracies, including procedures for correcting inaccurate

			 information in the personal electronic records it maintains on

			 individuals.</text>

				</subsection><subsection id="ID9cf3cda91a884c49890c309a02517db4"><enum>(e)</enum><header>Accuracy

			 resolution process</header>

					<paragraph id="ID0d279e6308514df3ab79394ee6646dcc"><enum>(1)</enum><header>Information

			 from a public record source</header>

						<subparagraph id="id625EDD6F21724D0CA79C31A941DDDBC3"><enum>(A)</enum><header>In

			 general</header><text>If an individual notifies a data broker of a dispute as

			 to the completeness or accuracy of information, and the data broker determines

			 that such information is derived from a public record source, the data broker

			 shall determine within 30 days whether the information in its system accurately

			 and completely records the information offered by the public record

			 source.</text>

						</subparagraph><subparagraph id="id68128AA750884D759E1A76114A921CAE"><enum>(B)</enum><header>Data broker

			 actions</header><text>If a data broker determines under subparagraph (A) that

			 the information in its systems—</text>

							<clause id="id06D910AB0D164D68903845967D458CA7"><enum>(i)</enum><text>does not

			 accurately and completely record the information offered by a public record

			 source, the data broker shall correct any inaccuracies or incompleteness, and

			 provide to such individual written notice of such changes; and</text>

							</clause><clause id="idF6D3927975F4497497A0087AE585D2E2"><enum>(ii)</enum><text>does accurately

			 and completely record the information offered by a public record source, the

			 data broker shall—</text>

								<subclause id="idEAD81956F4CD4A4698AF09C888F43EF5"><enum>(I)</enum><text>provide such

			 individual with the name, address, and telephone contact information of the

			 public record source; and</text>

								</subclause><subclause id="idFC484EF5DC7C450BA2C4C5FA054D86A4"><enum>(II)</enum><text>notify such

			 individual of the right to add for a period of 90 days to the personal

			 electronic record of the individual maintained by the data broker notice of the

			 dispute under subsection (f).</text>

								</subclause></clause></subparagraph></paragraph><paragraph id="idBBB3C147F9C644E28150237951B0A7BD"><enum>(2)</enum><header>Investigation

			 of disputed information not from a public record source</header><text>If the

			 completeness or accuracy of any nonpublic record source disclosed to an

			 individual under subsection (c) is disputed by the individual and such

			 individual notifies the data broker directly of such dispute, the data broker

			 shall, before the end of the 30-day period beginning on the date on which the

			 data broker receives the notice of the dispute—</text>

						<subparagraph id="id1A11BB9608B545A785FFBC340677010A"><enum>(A)</enum><text>investigate free

			 of charge and record the current status of the disputed information; or</text>

						</subparagraph><subparagraph id="id5ABEA019A030401A98C571ABE0FD3064"><enum>(B)</enum><text>delete the item

			 from the individuals data file in accordance with paragraph (8).</text>

						</subparagraph></paragraph><paragraph id="IDdd5de9a2f73a478198f5a22b3ae522cd"><enum>(3)</enum><header>Extension of

			 period to investigate</header><text>Except as provided in paragraph (4), the

			 30-day period described in paragraph (1) may be extended for not more than 15

			 additional days if a data broker receives information from the individual

			 during that 30-day period that is relevant to the investigation.</text>

					</paragraph><paragraph id="IDc8892c1b14b543fab9ebfaf86e24c51b"><enum>(4)</enum><header>Limitations on

			 extension of period to investigate</header><text>Paragraph (3) shall not apply

			 to any investigation in which, during the 30-day period described in paragraph

			 (1), the information that is the subject of the investigation is found to be

			 inaccurate or incomplete or a data broker determines that the information

			 cannot be verified.</text>

					</paragraph><paragraph id="IDa67ebe256597468fa70bd315c052c526"><enum>(5)</enum><header>Notice

			 identifying the data furnisher</header><text>If the completeness or accuracy of

			 any information disclosed to an individual under subsection (c) is disputed by

			 the individual, a data broker shall provide upon the request of the individual,

			 the name, business address, and telephone contact information of any data

			 furnisher who provided an item of information in dispute.</text>

					</paragraph><paragraph id="IDcff82324443a48cea2bb8cfab80523fb"><enum>(6)</enum><header>Determination

			 that dispute is frivolous or irrelevant</header>

						<subparagraph id="ID908d18c64c6a4174b5798d667ad22403"><enum>(A)</enum><header>In

			 general</header><text>Notwithstanding paragraphs (1) through (4), a data broker

			 may decline to investigate or terminate an investigation of information

			 disputed by an individual under those paragraphs if the data broker reasonably

			 determines that the dispute by the individual is frivolous or irrelevant,

			 including by reason of a failure by the individual to provide sufficient

			 information to investigate the disputed information.</text>

						</subparagraph><subparagraph id="IDf0c71360aad74dda9050677e887608ec"><enum>(B)</enum><header>Notice</header><text>Not

			 later than 5 business days after making any determination in accordance with

			 subparagraph (A) that a dispute is frivolous or irrelevant, a data broker shall

			 notify the individual of such determination by mail, or if authorized by the

			 individual, by any other means available to the data broker.</text>

						</subparagraph><subparagraph id="ID4924f256e2084311b1868c35553d8627"><enum>(C)</enum><header>Contents of

			 notice</header><text>A notice under subparagraph (B) shall include—</text>

							<clause id="idB4F2F21A4C7D46A6868CCE72BCADB669"><enum>(i)</enum><text>the

			 reasons for the determination under subparagraph (A); and</text>

							</clause><clause id="id5BD0DA3E5F264419A309E704BA2EA2E3"><enum>(ii)</enum><text>identification

			 of any information required to investigate the disputed information, which may

			 consist of a standardized form describing the general nature of such

			 information.</text>

							</clause></subparagraph></paragraph><paragraph id="ID9552efa6377d4516bf58487c36c5e443"><enum>(7)</enum><header>Consideration

			 of individual information</header><text>In conducting any investigation with

			 respect to disputed information in the personal electronic record of any

			 individual, a data broker shall review and consider all relevant information

			 submitted by the individual in the period described in paragraph (2) with

			 respect to such disputed information.</text>

					</paragraph><paragraph id="ID5125d224bfbd47459cb872f122565628"><enum>(8)</enum><header>Treatment of

			 inaccurate or unverifiable information</header>

						<subparagraph id="ID8e1d3ee81ab9433c9a2c15707066bab2"><enum>(A)</enum><header>In

			 general</header><text>If, after any review of public record information under

			 paragraph (1) or any investigation of any information disputed by an individual

			 under paragraphs (2) through (4), an item of information is found to be

			 inaccurate or incomplete or cannot be verified, a data broker shall promptly

			 delete that item of information from the individual’s personal electronic

			 record or modify that item of information, as appropriate, based on the results

			 of the investigation.</text>

						</subparagraph><subparagraph id="IDb77965b5351646b7af944dc9bda1c3ab"><enum>(B)</enum><header>Notice to

			 individuals of reinsertion of previously deleted information</header><text>If

			 any information that has been deleted from an individual’s personal electronic

			 record pursuant to subparagraph (A) is reinserted in the personal electronic

			 record of the individual, a data broker shall, not later than 5 days after

			 reinsertion, notify the individual of the reinsertion and identify any data

			 furnisher not previously disclosed in writing, or if authorized by the

			 individual for that purpose, by any other means available to the data broker,

			 unless such notification has been previously given under this

			 subsection.</text>

						</subparagraph><subparagraph id="IDfaec19d5917e4604b546a9fb456f556e"><enum>(C)</enum><header>Notice of

			 results of investigation of disputed information from a nonpublic record

			 source</header>

							<clause id="id71D2113B11C747D09B723AE8185474AB"><enum>(i)</enum><header>In

			 general</header><text>Not later than 5 business days after the completion of an

			 investigation under paragraph (2), a data broker shall provide written notice

			 to an individual of the results of the investigation, by mail or, if authorized

			 by the individual for that purpose, by other means available to the data

			 broker.</text>

							</clause><clause id="id631CD67E09FE469B89E04D08BEE6F9ED"><enum>(ii)</enum><header>Additional

			 requirement</header><text>Before the expiration of the 5-day period, as part

			 of, or in addition to such notice, a data broker shall, in writing, provide to

			 an individual—</text>

								<subclause id="IDb8fef9a422e849f192a9a66d9600e9ae"><enum>(I)</enum><text>a statement that

			 the investigation is completed;</text>

								</subclause><subclause id="ID432490b49750452c9be6e34173651d3f"><enum>(II)</enum><text>a report that is

			 based upon the personal electronic record of such individual as that personal

			 electronic record is revised as a result of the investigation;</text>

								</subclause><subclause id="ID30df3893746848a89af13631f4ad799b"><enum>(III)</enum><text>a notice that,

			 if requested by the individual, a description of the procedures used to

			 determine the accuracy and completeness of the information shall be provided to

			 the individual by the data broker, including the business name, address, and

			 telephone number of any data furnisher of information contacted in connection

			 with such information; and</text>

								</subclause><subclause id="ID7c0efaa99736407296d401cb01f3cf4a"><enum>(IV)</enum><text>a notice that

			 the individual has the right to request notifications under subsection

			 (f).</text>

								</subclause></clause></subparagraph><subparagraph id="ID830226c3fc6443ba9860567d4af28d7d"><enum>(D)</enum><header>Description of

			 investigation procedures</header><text>Not later than 15 days after receiving a

			 request from an individual for a description referred to in subparagraph

			 (C)(ii)(III), a data broker shall provide to the individual such a

			 description.</text>

						</subparagraph><subparagraph id="ID8eb1dc504b7a4688b59ef787a9e74450"><enum>(E)</enum><header>Expedited

			 dispute resolution</header><text>If by no later than 3 business days after the

			 date on which a data broker receives notice of a dispute from an individual of

			 information in the personal electronic record of such individual in accordance

			 with paragraph (2), a data broker resolves such dispute in accordance with

			 subparagraph (A) by the deletion of the disputed information, then the data

			 broker shall not be required to comply with subsections (e) and (f) with

			 respect to that dispute if the data broker provides to the individual, by

			 telephone or other means authorized by the individual, prompt notice of the

			 deletion.</text>

						</subparagraph></paragraph></subsection><subsection id="ID60e9584212db4d36935375077c457601"><enum>(f)</enum><header>Notice of

			 dispute</header>

					<paragraph id="id6008CC273B0A4A16BA8DE7DE3BCB8549"><enum>(1)</enum><header>In

			 general</header><text>If the completeness or accuracy of any information

			 disclosed to an individual under subsection (c) is disputed and unless there is

			 a reasonable ground to believe that such dispute is frivolous or irrelevant, an

			 individual may request that the data broker indicate notice of the dispute for

			 a period of—</text>

						<subparagraph id="idEC55B52CB0954AC8B416B0CE7DB056D3"><enum>(A)</enum><text>30 days for

			 information from a nonpublic record source; and</text>

						</subparagraph><subparagraph id="idC330C3E4996842E8AC8B86CBE70F3753"><enum>(B)</enum><text>90 days for

			 information from a public record source.</text>

						</subparagraph></paragraph><paragraph id="id587EA04AADF74BB78BFB196EB24791AF"><enum>(2)</enum><header>Compliance</header><text>A

			 data broker shall be deemed in compliance with the requirements under paragraph

			 (1) by either—</text>

						<subparagraph id="id3ADACEF5C1894E6E97F875F3924811B0"><enum>(A)</enum><text>allowing the

			 individual to file a brief statement setting forth the nature of the dispute

			 under paragraph (3); or</text>

						</subparagraph><subparagraph id="id8FCC407E3A11472097D2851DF8702A57"><enum>(B)</enum><text>using an

			 alternative notice method that—</text>

							<clause id="id849F123C269A4AD3A52B0776DC2734B2"><enum>(i)</enum><text>clearly flags the

			 disputed information for third parties accessing the information; and</text>

							</clause><clause id="idC77AFAAF2456477A9118E3237E8521CB"><enum>(ii)</enum><text>provides a means

			 for third parties to obtain further information regarding the nature of the

			 dispute.</text>

							</clause></subparagraph></paragraph><paragraph id="id0AEDEAB28984415F9EB86C1D0734462D"><enum>(3)</enum><header>Contents of

			 statement</header><text>A data broker may limit statements made under paragraph

			 (2)(A) to not more than 100 words if it provides an individual with assistance

			 in writing a clear summary of the dispute or until the dispute is

			 resolved.</text>

					</paragraph></subsection><subsection id="id03EF05DB073F4780A08A5FFA7B8545BD"><enum>(g)</enum><header>Additional

			 requirements</header><text>The Federal Trade Commission may exempt certain

			 classes of data brokers from this title in a rulemaking process pursuant to

			 section 553 of title 5, United States Code.</text>

				</subsection></section><section id="ID1c8011428bc24b24891956b4f7e6262d"><enum>302.</enum><header>Enforcement</header>

				<subsection id="IDfdf7ea47510b46018984fae9f35fe4a9"><enum>(a)</enum><header>Civil

			 penalties</header>

					<paragraph id="ID77b7e92dbb9045eeaa92a2a504783729"><enum>(1)</enum><header>Penalties</header><text>Any

			 data broker that violates the provisions of section 301 shall be subject to

			 civil penalties of not more than $1,000 per violation per day, with a maximum

			 of $15,000 per day, while such violations persist.</text>

					</paragraph><paragraph id="IDc04de66b19024774b5f98345e40a93ac"><enum>(2)</enum><header>Intentional or

			 willful violation</header><text>A data broker that intentionally or willfully

			 violates the provisions of section 301 shall be subject to additional penalties

			 in the amount of $1,000 per violation per day, with a maximum of an additional

			 $15,000 per day, while such violations persist.</text>

					</paragraph><paragraph id="ID950b5eb68a9f4e0bbb5750a95e12d446"><enum>(3)</enum><header>Equitable

			 relief</header><text>A data broker engaged in interstate commerce that violates

			 this section may be enjoined from further violations by a court of competent

			 jurisdiction.</text>

					</paragraph><paragraph id="ID0413ef81c1e94b5383fb876cf3774edc"><enum>(4)</enum><header>Other rights

			 and remedies</header><text>The rights and remedies available under this

			 subsection are cumulative and shall not affect any other rights and remedies

			 available under law.</text>

					</paragraph></subsection><subsection id="id9DD6A175887344D386D9F94E7409DCED"><enum>(b)</enum><header>Injunctive

			 actions by the Attorney General</header>

					<paragraph id="idF953EBE8802F449B8F64F73E3C5652F3"><enum>(1)</enum><header>In

			 general</header><text>Whenever it appears that a data broker to which this

			 title applies has engaged, is engaged, or is about to engage, in any act or

			 practice constituting a violation of this title, the Attorney General may bring

			 a civil action in an appropriate district court of the United States to—</text>

						<subparagraph id="id83C1E1EE65A44F05871FBDA523D18F1D"><enum>(A)</enum><text>enjoin such act

			 or practice;</text>

						</subparagraph><subparagraph id="idF6A3DFF2FFAA4892820D61CF07117E0B"><enum>(B)</enum><text>enforce

			 compliance with this title;</text>

						</subparagraph><subparagraph id="id756BB37D9D584D8DBFB5C43F1B36F48A"><enum>(C)</enum><text>obtain

			 damages—</text>

							<clause id="id338BB1FA40E8435FA4C8285BAA93B113"><enum>(i)</enum><text>in

			 the sum of actual damages, restitution, and other compensation on behalf of the

			 affected residents of a State; and</text>

							</clause><clause id="id744251AD0A68486289BD569879719943"><enum>(ii)</enum><text>punitive

			 damages, if the violation is willful or intentional; and</text>

							</clause></subparagraph><subparagraph id="id3F4C5A746A3548D28B475F92FF9D4B3F"><enum>(D)</enum><text>obtain such other

			 relief as the court determines to be appropriate.</text>

						</subparagraph></paragraph><paragraph id="id7FAAA5C70BFA47F9865C53BC092F0CB6"><enum>(2)</enum><header>Other

			 injunctive relief</header><text>Upon a proper showing in the action under

			 paragraph (1), the court shall grant a permanent injunction or a temporary

			 restraining order without bond.</text>

					</paragraph></subsection><subsection id="ID0cc935df13884fafa539854a43455951"><enum>(c)</enum><header>State

			 enforcement</header>

					<paragraph id="IDd887f71cae944e0d908a31989dc6df22"><enum>(1)</enum><header>Civil

			 actions</header><text>In any case in which the attorney general of a State has

			 reason to believe that an interest of the residents of that State has been or

			 is threatened or adversely affected by an act or practice that violates this

			 title, the State may bring a civil action on behalf of the residents of that

			 State in a district court of the United States of appropriate jurisdiction, or

			 any other court of competent jurisdiction, to—</text>

						<subparagraph id="ID5568efe9f4f44f6da842c1b6a63161dd"><enum>(A)</enum><text>enjoin that act

			 or practice;</text>

						</subparagraph><subparagraph id="ID61815e49cd0b4e50b5237515619ba2bc"><enum>(B)</enum><text>enforce

			 compliance with this title;</text>

						</subparagraph><subparagraph id="ID17e4c47f47ae4260ba9409c1d883d47c"><enum>(C)</enum><text>obtain—</text>

							<clause id="id64FCAF5AA50D4CAEBB220A5731545058"><enum>(i)</enum><text>damages in the

			 sum of actual damages, restitution, or other compensation on behalf of affected

			 residents of the State; and</text>

							</clause><clause id="id809BEC60E1C64DEA944ABC7EFA07397D"><enum>(ii)</enum><text>punitive

			 damages, if the violation is willful or intentional; or</text>

							</clause></subparagraph><subparagraph id="ID6b238dbe64564aba8111ee5d46ded61e"><enum>(D)</enum><text>obtain such other

			 legal and equitable relief as the court may consider to be appropriate.</text>

						</subparagraph></paragraph><paragraph id="ID7290fbddbcf344bda6a114cdc8239dc2"><enum>(2)</enum><header>Notice</header>

						<subparagraph id="id9B4507B13316426DAA04E68070BD039C"><enum>(A)</enum><header>In

			 general</header><text>Before filing an action under this subsection, the

			 attorney general of the State involved shall provide to the Attorney

			 General—</text>

							<clause id="id809CB295C03C4B0BADF0B8478E558DA3"><enum>(i)</enum><text>a

			 written notice of that action; and</text>

							</clause><clause id="idAF8CE86D861E4A4EB22F7D68D3D3B1AF"><enum>(ii)</enum><text>a

			 copy of the complaint for that action.</text>

							</clause></subparagraph><subparagraph id="idEE00A3DFCF7B4A498D4AFA93833FADD1"><enum>(B)</enum><header>Exception</header><text>Subparagraph

			 (A) shall not apply with respect to the filing of an action by an attorney

			 general of a State under this subsection, if the attorney general of a State

			 determines that it is not feasible to provide the notice described in this

			 subparagraph before the filing of the action.</text>

						</subparagraph><subparagraph id="id46E8DD94C42E46D9A59A98F32A7BE9F1"><enum>(C)</enum><header>Notification

			 when practicable</header><text>In an action described under subparagraph (B),

			 the attorney general of a State shall provide the written notice and the copy

			 of the complaint to the Attorney General as soon after the filing of the

			 complaint as practicable.</text>

						</subparagraph></paragraph><paragraph id="id2B2DD5B8C1754633AF3BAE51CCA60A68"><enum>(3)</enum><header>Attorney

			 General authority</header><text>Upon receiving notice under paragraph (2), the

			 Attorney General shall have the right to—</text>

						<subparagraph id="idFDCC43E9F5EE4A2C9C8C1549350EE924"><enum>(A)</enum><text>move to stay the

			 action, pending the final disposition of a pending Federal proceeding or action

			 as described in paragraph (4);</text>

						</subparagraph><subparagraph id="idEC965CB28F3D4AC68ABD21A48C74F25F"><enum>(B)</enum><text>intervene in an

			 action brought under paragraph (1); and</text>

						</subparagraph><subparagraph id="id35C714E3352C4A3784936FE4161BCEE5"><enum>(C)</enum><text>file petitions

			 for appeal.</text>

						</subparagraph></paragraph><paragraph id="id8D0AB2F639FE4AD897224B165CC96698"><enum>(4)</enum><header>Pending

			 proceedings</header><text>If the Attorney General has instituted a proceeding

			 or action for a violation of this title or any regulations thereunder, no

			 attorney general of a State may, during the pendency of such proceeding or

			 action, bring an action under this subsection against any defendant named in

			 such criminal proceeding or civil action for any violation that is alleged in

			 that proceeding or action.</text>

					</paragraph><paragraph id="IDcdc5b6a41278463baadf9d054f9765b1"><enum>(5)</enum><header>Rule of

			 construction</header><text>For purposes of bringing any civil action under

			 paragraph (1), nothing in this title shall be construed to prevent an attorney

			 general of a State from exercising the powers conferred on the attorney general

			 by the laws of that State to—</text>

						<subparagraph id="id73F3BD1F4CFA45619316D4B5F0F3FE9E"><enum>(A)</enum><text>conduct

			 investigations;</text>

						</subparagraph><subparagraph id="id8197748E226A420ABEF52A07D20E8496"><enum>(B)</enum><text>administer oaths

			 and affirmations; or</text>

						</subparagraph><subparagraph id="idB5EB6260CF4345B89FA57E2FB6D01DF0"><enum>(C)</enum><text>compel the

			 attendance of witnesses or the production of documentary and other

			 evidence.</text>

						</subparagraph></paragraph><paragraph id="id787BB8B04B0D4CEDAA88932E19597466"><enum>(6)</enum><header>Venue; service

			 of process</header>

						<subparagraph id="id07B4836BF02549CD8BDA9501354E2C38"><enum>(A)</enum><header>Venue</header><text>Any

			 action brought under this subsection may be brought in the district court of

			 the United States that meets applicable requirements relating to venue under

			 section 1931 of title 28, United States Code.</text>

						</subparagraph><subparagraph id="id17155495E48541E2B3EAFD9114D67039"><enum>(B)</enum><header>Service of

			 process</header><text>In an action brought under this subsection process may be

			 served in any district in which the defendant—</text>

							<clause id="idA2A6BB0B43B24BAD8392506F4A3D8303"><enum>(i)</enum><text>is

			 an inhabitant; or</text>

							</clause><clause commented="no" display-inline="no-display-inline" id="id3EFCC1069BCB4A328EE03FD3B09D34AC"><enum>(ii)</enum><text>may be

			 found.</text>

							</clause></subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="id13A064D32D6441F382D64EB146D7928D"><enum>(d)</enum><header>No private

			 cause of action</header><text>Nothing in this title establishes a private cause

			 of action against a data broker for violation of any provision of this

			 title.</text>

				</subsection></section><section commented="no" display-inline="no-display-inline" id="idBB183622651046E4AF84B055157BC19A"><enum>303.</enum><header>Relation to

			 State laws</header><text display-inline="no-display-inline">No requirement or

			 prohibition may be imposed under the laws of any State with respect to any

			 subject matter regulated under section 301, relating to individual access to,

			 and correction of, personal electronic records held by databrokers.</text>

			</section><section id="ID14ba6a6695f94105b011a272fdfadde0"><enum>304.</enum><header>Effective

			 date</header><text display-inline="no-display-inline">This title shall take

			 effect 180 days after the date of enactment of this Act and shall be

			 implemented pursuant to a State by State rollout schedule set by the Federal

			 Trade Commission, but in no case shall full implementation and effect of this

			 title occur later than 1 year and 180 days after the date of enactment of this

			 Act.</text>

			</section></title><title id="id138193CF772D4A21983C5BAB2F03B469"><enum>IV</enum><header>Privacy and

			 security of personally identifiable information</header>

			<subtitle id="idB969701409E841279B2194E39DA6954F"><enum>A</enum><header>Data privacy and

			 security program</header>

				<section id="id9AB3EE7075E9442AAC7653256781195F"><enum>401.</enum><header>Purpose and

			 applicability of data privacy and security program</header>

					<subsection id="ID5421e92137ff47019751add36a2838f2"><enum>(a)</enum><header>Purpose</header><text>The

			 purpose of this subtitle is to ensure standards for developing and implementing

			 administrative, technical, and physical safeguards to protect the privacy,

			 security, confidentiality, integrity, storage, and disposal of sensitive

			 personally identifiable information.</text>

					</subsection><subsection id="IDb7719eac3a244f9cb4dd8cb90890f655"><enum>(b)</enum><header>In

			 general</header><text>A business entity engaging in interstate commerce that

			 involves collecting, accessing, transmitting, using, storing, or disposing of

			 sensitive personally identifiable information in electronic or digital form on

			 10,000 or more United States persons is subject to the requirements for a data

			 privacy and security program under section 402 for protecting sensitive

			 personally identifiable information.</text>

					</subsection><subsection id="IDaf912e9ec5e04f21b758000178d60783"><enum>(c)</enum><header>Limitations</header><text>Notwithstanding

			 any other obligation under this subtitle, this subtitle does not apply

			 to—</text>

						<paragraph id="idB6CE38DA1914481C815D0D2B16B2C3AE"><enum>(1)</enum><text>financial

			 institutions—</text>

							<subparagraph id="id2F01E638FD314AFFBE058E2E9DAE6D86"><enum>(A)</enum><text>subject to the

			 data security requirements and implementing regulations under the

			 Gramm-Leach-Bliley Act (15 U.S.C. 6801 et seq.); and</text>

							</subparagraph><subparagraph id="id973B1599A2B34E48A3FB231FFD1648F0"><enum>(B)</enum><text>subject

			 to—</text>

								<clause id="id3B750B21B15540809CADE3FDFFBDE93F"><enum>(i)</enum><text>examinations for

			 compliance with the requirements of this Act by 1 or more Federal or State

			 functional regulators (as defined in section 509 of the Gramm-Leach-Bliley Act

			 (15 U.S.C. 6809)); or</text>

								</clause><clause id="id2073781F778A496094246CC606C51F03"><enum>(ii)</enum><text>compliance with

			 part 314 of title 16, Code of Federal Regulations; or</text>

								</clause></subparagraph></paragraph><paragraph id="id21F025CC9E404A878CB8E071668097EE"><enum>(2)</enum><text><quote>covered

			 entities</quote> subject to the Health Insurance Portability and Accountability

			 Act of 1996 (42 U.S.C. 1301 et seq.), including the data security requirements

			 and implementing regulations of that Act.</text>

						</paragraph></subsection><subsection id="id78159FB3D70D4044BD3A94C58B7731B2"><enum>(d)</enum><header>Safe

			 Harbor</header><text>A business entity shall be deemed in compliance with the

			 privacy and security program requirements under section 402 if the business

			 entity complies with or provides protection equal to industry standards, as

			 identified by the Federal Trade Commission, that are applicable to the type of

			 sensitive personally identifiable information involved in the ordinary course

			 of business of such business entity.</text>

					</subsection></section><section id="ID5693f6a32a6442db906fdeee52d8b875"><enum>402.</enum><header>Requirements

			 for a personal data privacy and security program</header>

					<subsection id="IDe44596fc79db4092b316001803881eb7"><enum>(a)</enum><header>Personal data

			 privacy and security program</header><text>Unless otherwise limited under

			 section 401(c), a business entity subject to this subtitle shall comply with

			 the following safeguards and any others identified by the Federal Trade

			 Commission in a rulemaking process pursuant to section 553 of title 5, United

			 States Code, to protect the privacy and security of sensitive personally

			 identifiable information:</text>

						<paragraph id="ID1700e1d016f6495b952aa37376545319"><enum>(1)</enum><header>Scope</header><text>A

			 business entity shall implement a comprehensive personal data privacy and

			 security program that includes administrative, technical, and physical

			 safeguards appropriate to the size and complexity of the business entity and

			 the nature and scope of its activities.</text>

						</paragraph><paragraph id="IDbf3e846409134d2280181f860f2603e3"><enum>(2)</enum><header>Design</header><text>The

			 personal data privacy and security program shall be designed to—</text>

							<subparagraph id="ID99c9a6f0bd0d4a04addd24fecd737ee0"><enum>(A)</enum><text>ensure the

			 privacy, security, and confidentiality of personal electronic records;</text>

							</subparagraph><subparagraph id="IDb017ea66a4a3454da23426a7817c10bd"><enum>(B)</enum><text>protect against

			 any anticipated vulnerabilities to the privacy, security, or integrity of

			 personal electronic records; and</text>

							</subparagraph><subparagraph id="ID9f26c5947df8427e9789f1e930f3bafb"><enum>(C)</enum><text>protect against

			 unauthorized access to use of personal electronic records that could result in

			 substantial harm or inconvenience to any individual.</text>

							</subparagraph></paragraph><paragraph id="ID956e1d56ea3446e180ba3b42d7e2ec67"><enum>(3)</enum><header>Risk

			 assessment</header><text>A business entity shall—</text>

							<subparagraph id="ID3cc8d7810e8f4714a705351002fb4783"><enum>(A)</enum><text>identify

			 reasonably foreseeable internal and external vulnerabilities that could result

			 in unauthorized access, disclosure, use, or alteration of sensitive personally

			 identifiable information or systems containing sensitive personally

			 identifiable information;</text>

							</subparagraph><subparagraph id="ID353b206af29a4c84a8380cf8c2283fac"><enum>(B)</enum><text>assess the

			 likelihood of and potential damage from unauthorized access, disclosure, use,

			 or alteration of sensitive personally identifiable information; and</text>

							</subparagraph><subparagraph id="ID33549e9e9e5046499a3f7c0b2ae63b4e"><enum>(C)</enum><text>assess the

			 sufficiency of its policies, technologies, and safeguards in place to control

			 and minimize risks from unauthorized access, disclosure, use, or alteration of

			 sensitive personally identifiable information.</text>

							</subparagraph></paragraph><paragraph id="ID705f43bfa8694f82bfcd99cf3c87bed3"><enum>(4)</enum><header>Risk management

			 and control</header><text>Each business entity shall—</text>

							<subparagraph id="idB3D1A10E41E74035B5948664A64EB652"><enum>(A)</enum><text>design its

			 personal data privacy and security program to control the risks identified

			 under paragraph (3); and</text>

							</subparagraph><subparagraph id="id42D1A39F755E443E935EA4B2C4FF113A"><enum>(B)</enum><text>adopt measures

			 commensurate with the sensitivity of the data as well as the size, complexity,

			 and scope of the activities of the business entity that—</text>

								<clause id="IDef48e3ace0b74ee984c751493bffdfb1"><enum>(i)</enum><text>control access to

			 systems and facilities containing sensitive personally identifiable

			 information, including controls to authenticate and permit access only to

			 authorized individuals;</text>

								</clause><clause id="ID439b19bdfbf74c679ac3221bba9057c5"><enum>(ii)</enum><text>detect actual

			 and attempted fraudulent, unlawful, or unauthorized access, disclosure, use, or

			 alteration of sensitive personally identifiable information, including by

			 employees and other individuals otherwise authorized to have access; and</text>

								</clause><clause id="ID9c3d8b25a17541c98f533375f8dc303c"><enum>(iii)</enum><text>protect

			 sensitive personally identifiable information during use, transmission,

			 storage, and disposal by encryption or other reasonable means (including as

			 directed for disposal of records under section 628 of the Fair Credit Reporting

			 Act (15 U.S.C. 1681w) and the implementing regulations of such Act as set forth

			 in section 682 of title 16, Code of Federal Regulations).</text>

								</clause></subparagraph></paragraph></subsection><subsection id="ID6580e32338ff46138d992c0609ac947c"><enum>(b)</enum><header>Training</header><text>Each

			 business entity subject to this subtitle shall take steps to ensure employee

			 training and supervision for implementation of the data security program of the

			 business entity.</text>

					</subsection><subsection id="IDadc6f7197b1a4160b7f492bb85bd1ea5"><enum>(c)</enum><header>Vulnerability

			 testing</header>

						<paragraph id="id7B41208F6D5F43C39DD8232F641DC697"><enum>(1)</enum><header>In

			 general</header><text>Each business entity subject to this subtitle shall take

			 steps to ensure regular testing of key controls, systems, and procedures of the

			 personal data privacy and security program to detect, prevent, and respond to

			 attacks or intrusions, or other system failures.</text>

						</paragraph><paragraph id="idC119407B572447C98484012EE3F09E3E"><enum>(2)</enum><header>Frequency</header><text>The

			 frequency and nature of the tests required under paragraph (1) shall be

			 determined by the risk assessment of the business entity under subsection

			 (a)(3).</text>

						</paragraph></subsection><subsection id="ID8b3ac9c4d91d47aa8c52cd174729f673"><enum>(d)</enum><header>Relationship to

			 service providers</header><text>In the event a business entity subject to this

			 subtitle engages service providers not subject to this subtitle, such business

			 entity shall—</text>

						<paragraph id="IDcc97c88c09824d1cb88aef26aec04111"><enum>(1)</enum><text>exercise

			 appropriate due diligence in selecting those service providers for

			 responsibilities related to sensitive personally identifiable information, and

			 take reasonable steps to select and retain service providers that are capable

			 of maintaining appropriate safeguards for the security, privacy, and integrity

			 of the sensitive personally identifiable information at issue; and</text>

						</paragraph><paragraph id="IDac5ccd8449764e59b1660bdff2c177f1"><enum>(2)</enum><text>require those

			 service providers by contract to implement and maintain appropriate measures

			 designed to meet the objectives and requirements governing entities subject to

			 this section, section 401, and subtitle B.</text>

						</paragraph></subsection><subsection id="IDc023fa1ae63e49eca60328f46c15c6eb"><enum>(e)</enum><header>Periodic

			 assessment and personal data privacy and security

			 modernization</header><text>Each business entity subject to this subtitle shall

			 on a regular basis monitor, evaluate, and adjust, as appropriate its data

			 privacy and security program in light of any relevant changes in—</text>

						<paragraph id="id7B8EF50E08E14F65A4DF4C887614FD71"><enum>(1)</enum><text>technology;</text>

						</paragraph><paragraph id="id04C25DB2254A46899A66FFE98EE17FA4"><enum>(2)</enum><text>the sensitivity

			 of personally identifiable information;</text>

						</paragraph><paragraph id="id50F8A1324042443C99E76F2A541A3A84"><enum>(3)</enum><text>internal or

			 external threats to personally identifiable information; and</text>

						</paragraph><paragraph id="id0BA5E3DD25DB4462894A0CEDF6515FB6"><enum>(4)</enum><text>the changing

			 business arrangements of the business entity, such as—</text>

							<subparagraph id="id311F2BBA795449E086D5006CEC3C2913"><enum>(A)</enum><text>mergers and

			 acquisitions;</text>

							</subparagraph><subparagraph id="id14936CFBAEFE42F4AB900DCB43F034D0"><enum>(B)</enum><text>alliances and

			 joint ventures;</text>

							</subparagraph><subparagraph id="idE07238FE05364DF2894983D4AA5E9520"><enum>(C)</enum><text>outsourcing

			 arrangements;</text>

							</subparagraph><subparagraph id="id990765DA7EAE484CBFAB8331FCCF9D0A"><enum>(D)</enum><text>bankruptcy;

			 and</text>

							</subparagraph><subparagraph id="id2D81463C59CF45BE94967C312105F1A1"><enum>(E)</enum><text>changes to

			 sensitive personally identifiable information systems.</text>

							</subparagraph></paragraph></subsection><subsection id="ID3b3aa52ec1be4719954a93ab713ff73b"><enum>(f)</enum><header>Implementation

			 time line</header><text>Not later than 1 year after the date of enactment of

			 this Act, a business entity subject to the provisions of this subtitle shall

			 implement a data privacy and security program pursuant to this subtitle.</text>

					</subsection></section><section id="ID5f321c3d88964c2fbff395285c6073fa"><enum>403.</enum><header>Enforcement</header>

					<subsection id="ID4a1203708e004384a481a1c7a4566b78"><enum>(a)</enum><header>Civil

			 penalties</header>

						<paragraph id="idCBB68F386B0F4D95AC4989E9C51B0C12"><enum>(1)</enum><header>In

			 general</header><text>Any business entity that violates the provisions of

			 sections 401 or 402 shall be subject to civil penalties of not more than $5,000

			 per violation per day, with a maximum of $35,000 per day, while such violations

			 persist.</text>

						</paragraph><paragraph id="ID6c9e3029206840478e35e8a71a69054c"><enum>(2)</enum><header>Intentional or

			 willful violation</header><text>A business entity that intentionally or

			 willfully violates the provisions of sections 401 or 402 shall be subject to

			 additional penalties in the amount of $5,000 per violation per day, with a

			 maximum of an additional $35,000 per day, while such violations persist.</text>

						</paragraph><paragraph id="ID62dc1e10374a494f94d854be306e9af7"><enum>(3)</enum><header>Equitable

			 relief</header><text>A business entity engaged in interstate commerce that

			 violates this section may be enjoined from further violations by a court of

			 competent jurisdiction.</text>

						</paragraph><paragraph id="ID47d7f48ff89147bd9e684361f2e0c77f"><enum>(4)</enum><header>Other rights

			 and remedies</header><text>The rights and remedies available under this section

			 are cumulative and shall not affect any other rights and remedies available

			 under law</text>

						</paragraph></subsection><subsection id="id09D96FAB648E422CB7BC384F4E203DF9"><enum>(b)</enum><header>Injunctive

			 actions by the Attorney General</header>

						<paragraph id="id952E8F0426B748E185AEBC6BC5E36574"><enum>(1)</enum><header>In

			 general</header><text>Whenever it appears that a business entity or agency to

			 which this subtitle applies has engaged, is engaged, or is about to engage, in

			 any act or practice constituting a violation of this subtitle, the Attorney

			 General may bring a civil action in an appropriate district court of the United

			 States to—</text>

							<subparagraph id="id1FF4591F220F450C8F29FF7703BAE6D0"><enum>(A)</enum><text>enjoin such act

			 or practice;</text>

							</subparagraph><subparagraph id="id52FF5E73741A489DBC2C21E7408DA4BA"><enum>(B)</enum><text>enforce

			 compliance with this subtitle; and</text>

							</subparagraph><subparagraph id="id1587C48F4BA94DF7861F3373DCD95DD5"><enum>(C)</enum><text>obtain

			 damages—</text>

								<clause id="id253613DA247249889432B79E474C9A1D"><enum>(i)</enum><text>in

			 the sum of actual damages, restitution, and other compensation on behalf of the

			 affected residents of a State; and</text>

								</clause><clause id="id13B11E0C2AD64531A2689C73A0217FEA"><enum>(ii)</enum><text>punitive

			 damages, if the violation is willful or intentional; and</text>

								</clause></subparagraph><subparagraph id="idC32FE5FDB69E4281B1742B43B3AB4240"><enum>(D)</enum><text>obtain such other

			 relief as the court determines to be appropriate.</text>

							</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id9E188A106BB1457ABCAD1623E374A5EE"><enum>(2)</enum><header>Other

			 injunctive relief</header><text>Upon a proper showing in the action under

			 paragraph (1), the court shall grant a permanent injunction or a temporary

			 restraining order without bond.</text>

						</paragraph></subsection><subsection id="ID02ae805648c1498aa9217e9c46961734"><enum>(c)</enum><header>State

			 enforcement</header>

						<paragraph id="IDcf8362cefa0749f092bfca6cd2cac173"><enum>(1)</enum><header>Civil

			 actions</header><text>In any case in which the attorney general of a State has

			 reason to believe that an interest of the residents of that State has been or

			 is threatened or adversely affected by an act or practice that violates this

			 subtitle, the State may bring a civil action on behalf of the residents of that

			 State in a district court of the United States of appropriate jurisdiction, or

			 any other court of competent jurisdiction, to—</text>

							<subparagraph id="ID4d964a8ec1454cdf955afa68ee93fe07"><enum>(A)</enum><text>enjoin that act

			 or practice;</text>

							</subparagraph><subparagraph id="ID902912db88b141b89b1a1bb628b47f4f"><enum>(B)</enum><text>enforce

			 compliance with this subtitle;</text>

							</subparagraph><subparagraph id="idECE71A3FEF1149FA94203C71C4BA4CC8"><enum>(C)</enum><text>obtain—</text>

								<clause id="idC7DDE671A91A4F08B9F372DFEAEBFA91"><enum>(i)</enum><text>damages in the

			 sum of actual damages, restitution, or other compensation on behalf of affected

			 residents of the State; and</text>

								</clause><clause commented="no" display-inline="no-display-inline" id="idAD988127897E44E798DCAAE4E6518683"><enum>(ii)</enum><text>punitive

			 damages, if the violation is willful or intentional; or</text>

								</clause></subparagraph><subparagraph id="ID01102203db0243c380b92d246b38e184"><enum>(D)</enum><text>obtain such other

			 legal and equitable relief as the court may consider to be appropriate.</text>

							</subparagraph></paragraph><paragraph id="id29B0311AB47C4376B82A3C836644EB1F"><enum>(2)</enum><header>Notice</header>

							<subparagraph id="id48D1A18D322546F2B726468DC24666C4"><enum>(A)</enum><header>In

			 general</header><text>Before filing an action under this subsection, the

			 attorney general of the State involved shall provide to the Attorney

			 General—</text>

								<clause id="id4C2709A4996041DD83EF31944B2810B0"><enum>(i)</enum><text>a

			 written notice of that action; and</text>

								</clause><clause id="id19B08F4BE71048E0962A3C91CB418632"><enum>(ii)</enum><text>a

			 copy of the complaint for that action.</text>

								</clause></subparagraph><subparagraph id="idDE1817B880884A7E99989EC835121847"><enum>(B)</enum><header>Exception</header><text>Subparagraph

			 (A) shall not apply with respect to the filing of an action by an attorney

			 general of a State under this subsection, if the attorney general of a State

			 determines that it is not feasible to provide the notice described in this

			 subparagraph before the filing of the action.</text>

							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idF7D51ADFC8B1449CB90A506DA78B7242"><enum>(C)</enum><header>Notification

			 when practicable</header><text>In an action described under subparagraph (B),

			 the attorney general of a State shall provide the written notice and the copy

			 of the complaint to the Attorney General as soon after the filing of the

			 complaint as practicable.</text>

							</subparagraph></paragraph><paragraph id="idAF8580F1441E4E1ABA6C7AE3D21FBD8A"><enum>(3)</enum><header>Attorney

			 General authority</header><text>Upon receiving notice under paragraph (2), the

			 Attorney General shall have the right to—</text>

							<subparagraph id="idAD9B19B4C54247F8A80BB470F81C0644"><enum>(A)</enum><text>move to stay the

			 action, pending the final disposition of a pending Federal proceeding or action

			 as described in paragraph (4);</text>

							</subparagraph><subparagraph id="idE3BCB8F9FDB24A6688DA592526102BE2"><enum>(B)</enum><text>intervene in an

			 action brought under paragraph (1); and</text>

							</subparagraph><subparagraph id="idD675AD00EB0F4687B3FD6C4FF4E073A7"><enum>(C)</enum><text>file petitions

			 for appeal.</text>

							</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="idEF955D595846479196A8C8D5D13CF829"><enum>(4)</enum><header>Pending

			 proceedings</header><text>If the Attorney General has instituted a proceeding

			 or action for a violation of this title or any regulations thereunder, no

			 attorney general of a State may, during the pendency of such proceeding or

			 action, bring an action under this subsection against any defendant named in

			 such criminal proceeding or civil action for any violation that is alleged in

			 that proceeding or action.</text>

						</paragraph><paragraph id="IDca36c4de516f4ef183e4087cd213d56f"><enum>(5)</enum><header>Rule of

			 construction</header><text>For purposes of bringing any civil action under

			 paragraph (1) nothing in this title shall be construed to prevent an attorney

			 general of a State from exercising the powers conferred on the attorney general

			 by the laws of that State to—</text>

							<subparagraph id="idE6EB0346347B42FAA53C4F9E512D7F3B"><enum>(A)</enum><text>conduct

			 investigations;</text>

							</subparagraph><subparagraph id="idDCF233C5DA1C4F9B91E07073922AC6A9"><enum>(B)</enum><text>administer oaths

			 and affirmations; or</text>

							</subparagraph><subparagraph id="idF2314C1DD1354FF5A76704299B66EB51"><enum>(C)</enum><text>compel the

			 attendance of witnesses or the production of documentary and other

			 evidence.</text>

							</subparagraph></paragraph><paragraph id="idD69D960D6D304009962C6D0179D26383"><enum>(6)</enum><header>Venue; service

			 of process</header>

							<subparagraph id="idFED206234C5C4FF8BD84F81608B7C4C1"><enum>(A)</enum><header>Venue</header><text>Any

			 action brought under this subsection may be brought in the district court of

			 the United States that meets applicable requirements relating to venue under

			 section 1931 of title 28, United States Code.</text>

							</subparagraph><subparagraph id="idE29174FEEA054F8C822CF1137E752FAC"><enum>(B)</enum><header>Service of

			 process</header><text>In an action brought under this subsection process may be

			 served in any district in which the defendant—</text>

								<clause id="id5F4847EADB1E4A30A59F6A66A91D8F0D"><enum>(i)</enum><text>is

			 an inhabitant; or</text>

								</clause><clause id="id2917C7D674944A908C1D92A458E4A44B"><enum>(ii)</enum><text>may be

			 found.</text>

								</clause></subparagraph></paragraph></subsection><subsection id="id50A71B6AEBA74B87A9B7052F2D77CE12"><enum>(d)</enum><header>No private

			 cause of action</header><text>Nothing in this title establishes a private cause

			 of action against a business entity for violation of any provision of this

			 subtitle.</text>

					</subsection></section><section id="idF8813A768CEC49BE96DBFF58E67BCD25"><enum>404.</enum><header>Relation to

			 State laws</header>

					<subsection commented="no" display-inline="no-display-inline" id="id604A4A699BD941F7A1F5E6A0CCCF9F89"><enum>(a)</enum><header>In

			 general</header><text>No State may—</text>

						<paragraph commented="no" display-inline="no-display-inline" id="idF6A310AD0246448A96F97F05CC071917"><enum>(1)</enum><text>require an entity

			 described in section 401(c) to comply with this subtitle or any regulation

			 promulgated thereunder; and</text>

						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="idEE19C30EA53C41EC88A7C41A4D01B1A0"><enum>(2)</enum><text>require an entity

			 in compliance with the safe harbor established under section 401(d), to comply

			 with any other provision of this subtitle.</text>

						</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="idCAF5576AAAF942B59807FA98559E7D01"><enum>(b)</enum><header>Effect of

			 subtitle A</header><text>Except as provided in subsection (a), this subtitle

			 does not annul, alter, affect, or exempt any person subject to the provisions

			 of this subtitle from complying with the laws of any State with respect to

			 security programs for sensitive personally identifiable information, except to

			 the extent that those laws are inconsistent with any provisions of this

			 subtitle, and then only to the extent of such inconsistency.</text>

					</subsection></section></subtitle><subtitle id="idB1F43A151366485884B09C079E7744C2"><enum>B</enum><header>Security Breach

			 Notification</header>

				<section id="ID3d6241472d4a4860bc4a8264168b3d0c"><enum>421.</enum><header>Notice to

			 Individuals</header>

					<subsection id="ID8c5b1a155f9b41aaaa773ffb9f585429"><enum>(a)</enum><header>In

			 general</header><text>Any agency, or business entity engaged in interstate

			 commerce, that uses, accesses, transmits, stores, disposes of or collects

			 sensitive personally identifiable information shall, following the discovery of

			 a security breach maintained by the agency or business entity that contains

			 such information, notify any resident of the United States whose sensitive

			 personally identifiable information was subject to the security breach.</text>

					</subsection><subsection id="ID5a91623670414a3f8daa518b7eccc095"><enum>(b)</enum><header>Obligation of

			 owner or licensee</header>

						<paragraph id="id5C62A57A5E224E98BBC0AB606A49EAB0"><enum>(1)</enum><header>Notice to owner

			 or licensee</header><text>Any agency, or business entity engaged in interstate

			 commerce, that uses, accesses, transmits, stores, disposes of, or collects

			 sensitive personally identifiable information that the agency or business

			 entity does not own or license shall notify the owner or licensee of the

			 information following the discovery of a security breach containing such

			 information.</text>

						</paragraph><paragraph id="id773EE1D687D74C23A6E70B19676153E6"><enum>(2)</enum><header>Notice by

			 owner, licensee or other designated third party</header><text>Noting in this

			 subtitle shall prevent or abrogate an agreement between an agency or business

			 entity required to give notice under this section and a designated third party,

			 including an owner or licensee of the sensitive personally identifiable

			 information subject to the security breach, to provide the notifications

			 required under subsection (a).</text>

						</paragraph><paragraph id="id06C1D554EFCE49C49289B73ED4049C84"><enum>(3)</enum><header>Business entity

			 relieved from giving notice</header><text>A business entity obligated to give

			 notice under subsection (a) shall be relieved of such obligation if an owner or

			 licensee of the sensitive personally identifiable information subject to the

			 security breach, or other designated third party, provides such

			 notification.</text>

						</paragraph></subsection><subsection id="IDdca8a5c0195f407c90eedee6920090b8"><enum>(c)</enum><header>Timeliness of

			 notification</header>

						<paragraph id="id963293A370664B858521D190CF4C56F5"><enum>(1)</enum><header>In

			 general</header><text>All notifications required under this section shall be

			 made without unreasonable delay following—</text>

							<subparagraph id="IDa4d5cd62503744f38a09eb891f58e071"><enum>(A)</enum><text>the discovery by

			 the agency or business entity of a security breach; and</text>

							</subparagraph><subparagraph id="ID91721fe938924083bc229d59593a6f7f"><enum>(B)</enum><text>any measures

			 necessary to determine the scope of the breach, prevent further disclosures,

			 and restore the reasonable integrity of the data system.</text>

							</subparagraph></paragraph><paragraph id="IDd5e6993954d54b71bbaf53ed5e6b56de"><enum>(2)</enum><header>Burden of

			 proof</header><text>The agency, business entity, owner, or licensee required to

			 provide notification under this section shall have the burden of demonstrating

			 that all notifications were made as required under this subtitle, including

			 evidence demonstrating the necessity of any delay.</text>

						</paragraph></subsection><subsection id="ID2976ef18787d4a1f99bb9e5ef26a9b6f"><enum>(d)</enum><header>Delay of

			 notification authorized for law enforcement purposes</header>

						<paragraph id="idCDA0AC8173AC47EE8DC580A96D6BD248"><enum>(1)</enum><header>In

			 general</header><text>If a law enforcement agency determines that the

			 notification required under this section would impede a criminal investigation,

			 such notification may be delayed upon the written request of the law

			 enforcement agency.</text>

						</paragraph><paragraph id="id351C81BB787444A19E1172A340508F4F"><enum>(2)</enum><header>Extended delay

			 of notification</header><text>If the notification required under subsection (a)

			 is delayed pursuant to paragraph (1), an agency or business entity shall give

			 notice 30 days after the day such law enforcement delay was invoked unless a

			 law enforcement agency provides written notification that further delay is

			 necessary.</text>

						</paragraph></subsection></section><section id="idD2F1C50E06A24CA8A0C699664A5E1AB6"><enum>422.</enum><header>Exemptions</header>

					<subsection id="IDd1a72ee1b8db4cd1ba61e16238073f8e"><enum>(a)</enum><header>Exemption for

			 national security and law enforcement</header>

						<paragraph id="ID9a254c883ef84478ba9d50f0343ab923"><enum>(1)</enum><header>In

			 general</header><text>Section 421 shall not apply to an agency if the head of

			 the agency certifies, in writing, that notification of the security breach as

			 required by section 421 reasonably could be expected to—</text>

							<subparagraph id="ID135d8c66f9fd44ba99d599277fa44ba1"><enum>(A)</enum><text>cause damage to

			 the national security; or</text>

							</subparagraph><subparagraph id="ID3aaf991b94814532a598e1771a61202e"><enum>(B)</enum><text>hinder a law

			 enforcement investigation or the ability of the agency to conduct law

			 enforcement investigations.</text>

							</subparagraph></paragraph><paragraph id="ID5ff07be0759649b481ee706de06a8088"><enum>(2)</enum><header>Limits on

			 certifications</header><text>The head of an agency may not execute a

			 certification under paragraph (1) to—</text>

							<subparagraph id="IDaf785ebaee1a417cb7b38fec19e3dd60"><enum>(A)</enum><text>conceal

			 violations of law, inefficiency, or administrative error;</text>

							</subparagraph><subparagraph id="ID7d3e82b3796e463aa1fdfe668010218a"><enum>(B)</enum><text>prevent

			 embarrassment to a business entity, organization, or agency; or</text>

							</subparagraph><subparagraph id="ID431bf438236f4007ac204c4f0d16d564"><enum>(C)</enum><text>restrain

			 competition.</text>

							</subparagraph></paragraph><paragraph id="IDf1f8c2743ae14147a196a989e952f26e"><enum>(3)</enum><header>Notice</header><text>In

			 every case in which a head of an agency issues a certification under paragraph

			 (1), the certification, accompanied by a concise description of the factual

			 basis for the certification, shall be immediately provided to the

			 Congress.</text>

						</paragraph></subsection><subsection id="IDf97ab0947f1c4db486e5f8e0d877508d"><enum>(b)</enum><header>Risk assessment

			 exemption</header><text>An agency or business entity will be exempt from the

			 notice requirements under section 421, if—</text>

						<paragraph id="id6782ADC8851E4569855AF3C252546E01"><enum>(1)</enum><text>a risk assessment

			 concludes that there is no significant risk that the security breach has

			 resulted in, or will result in, harm to the individuals whose sensitive

			 personally identifiable information was subject to the security breach;</text>

						</paragraph><paragraph id="id76E72A97C9164B359AA24E999629885A"><enum>(2)</enum><text>without

			 unreasonable delay, but not later than 45 days after the discovery of a

			 security breach, unless extended by the United States Secret Service, the

			 business entity notifies the United States Secret Service, in writing,

			 of—</text>

							<subparagraph id="id1C468F26B2824203A67FF9B2A4BE6214"><enum>(A)</enum><text>the results of

			 the risk assessment;</text>

							</subparagraph><subparagraph id="id9BE7C59776D147AF80CB84020CA1F0A2"><enum>(B)</enum><text>its decision to

			 invoke the risk assessment exemption; and</text>

							</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="idBEB2209A24A94DB0AD072D07AF46B3E0"><enum>(3)</enum><text>the United States

			 Secret Service does not indicate, in writing, within 10 days from receipt of

			 the decision, that notice should be given.</text>

						</paragraph></subsection><subsection id="ID6a5f039b165d4caca9288ce88abc1790"><enum>(c)</enum><header>Financial fraud

			 prevention exemption</header>

						<paragraph id="idA7C338338E8E402F946E8DEB325FA8D3"><enum>(1)</enum><header>In

			 general</header><text>A business entity will be exempt from the notice

			 requirement under section 421 if the business entity utilizes or participates

			 in a security program that—</text>

							<subparagraph id="id4E24D7C123D8494CBE95BD86C4947CE9"><enum>(A)</enum><text>is designed to

			 block the use of the sensitive personally identifiable information to initiate

			 unauthorized financial transactions before they are charged to the account of

			 the individual; and</text>

							</subparagraph><subparagraph id="IDedf6fb4e0a2a459096cd63bd3b1f3822"><enum>(B)</enum><text>provides for

			 notice after a security breach that has resulted in fraud or unauthorized

			 transactions.</text>

							</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id81387B055306439196696D7FE5E676BE"><enum>(2)</enum><header>Limitation</header><text>The

			 exemption by this subsection does not apply if the information subject to the

			 security breach includes, in addition to an account number, sensitive

			 personally identifiable information.</text>

						</paragraph></subsection></section><section id="ID57fa5ae6554247ca904675d04f28a128"><enum>423.</enum><header>Methods of

			 notice</header><text display-inline="no-display-inline">An agency, or business

			 entity shall be in compliance with section 421 if it provides:</text>

					<paragraph id="ID767f291900694946ba69773ff084128d"><enum>(1)</enum><header>Individual

			 notice</header>

						<subparagraph id="idBF382CDEEBBE4CD089C44F556C71A53D"><enum>(A)</enum><text>Written

			 notification to the last known home mailing address of the individual in the

			 records of the agency or business entity; or</text>

						</subparagraph><subparagraph id="IDd9ce7370611743848270f8a0276708ff"><enum>(B)</enum><text>E-mail notice, if

			 the individual has consented to receive such notice and the notice is

			 consistent with the provisions permitting electronic transmission of notices

			 under section 101 of the Electronic Signatures in Global and National Commerce

			 Act (15 U.S.C. 7001).</text>

						</subparagraph></paragraph><paragraph id="ID0b8bd341f653493990fbe6d9898ebd0f"><enum>(2)</enum><header>Media

			 notice</header><text>If more than 5,000 residents of a State or jurisdiction

			 are impacted, notice to major media outlets serving that State or

			 jurisdiction.</text>

					</paragraph></section><section id="ID7f7691929a2d45118c8c81ff227b8e0a"><enum>424.</enum><header>Content of

			 notification</header>

					<subsection id="idD87AC7ACF04F45DB96260886EE19F7E9"><enum>(a)</enum><header>In

			 general</header><text>Regardless of the method by which notice is provided to

			 individuals under section 423, such notice shall include, to the extent

			 possible—</text>

						<paragraph id="id66C735920DED4792AB2765445C0C0FA8"><enum>(1)</enum><text>a description of

			 the categories of sensitive personally identifiable information that was, or is

			 reasonably believed to have been, acquired by an unauthorized person;</text>

						</paragraph><paragraph id="ID9033cace7baa4eaa8a02e6b8b6ac24b4"><enum>(2)</enum><text>a toll-free

			 number—</text>

							<subparagraph id="ID881b6effe37047d8a97600f604663b00"><enum>(A)</enum><text>that the

			 individual may use to contact the agency or business entity, or the agent of

			 the agency or business entity; and</text>

							</subparagraph><subparagraph id="ID7fef877362fa45f9b77294447b0c870e"><enum>(B)</enum><text>from which the

			 individual may learn—</text>

								<clause id="IDc2083004b06a47cf8f2ba92a520dac2b"><enum>(i)</enum><text>what types of

			 sensitive personally identifiable information the agency or business entity

			 maintained about that individual or about individuals in general; and</text>

								</clause><clause id="ID145655c6d4fc49b2822860bcc6c5acf2"><enum>(ii)</enum><text>whether or not

			 the agency or business entity maintained sensitive personally identifiable

			 information about that individual; and</text>

								</clause></subparagraph></paragraph><paragraph id="ID7701ecbc5e1f4573b9dc56f03ef3ce84"><enum>(3)</enum><text>the toll-free

			 contact telephone numbers and addresses for the major credit reporting

			 agencies.</text>

						</paragraph></subsection><subsection id="idDC2BEFAC5B9746B4B970A9E84458D802"><enum>(b)</enum><header>Additional

			 content</header><text>Notwithstanding section 429, a State may require that a

			 notice under subsection (a) shall also include information regarding victim

			 protection assistance provided for by that State.</text>

					</subsection></section><section id="IDc478d5e537a04419839ab9fb004f4bd1"><enum>425.</enum><header>Coordination

			 of notification with credit reporting agencies</header><text display-inline="no-display-inline">If an agency or business entity is required

			 to provide notification to more than 1,000 individuals under section 421(a),

			 the agency or business entity shall also notify, without unreasonable delay,

			 all consumer reporting agencies that compile and maintain files on consumers on

			 a nationwide basis (as defined in section 603(p) of the Fair Credit Reporting

			 Act (15 U.S.C. 1681a(p)) of the timing and distribution of the notices.</text>

				</section><section id="id8216D56C048A4F15B2AFED6AFE035962"><enum>426.</enum><header>Notice to law

			 enforcement</header>

					<subsection id="id0A615FAFC0A54042B7A75E41E75BF7BC"><enum>(a)</enum><header>Secret

			 service</header><text>Any business entity or agency required to give notice

			 under section 421 shall also give notice to the United States Secret Service if

			 the security breach impacts—</text>

						<paragraph id="id74B38F0D3D474BF1A417544AAC4BBD93"><enum>(1)</enum><text>more than 10,000

			 individuals nationwide;</text>

						</paragraph><paragraph id="id76FE34D44CD04992A207507EB8823D01"><enum>(2)</enum><text>a database,

			 networked or integrated databases, or other data system associated with the

			 sensitive personally identifiable information on more than 1,000,000

			 individuals nationwide;</text>

						</paragraph><paragraph id="id361BE5ED0ADD40A6AA16E9B7251CD1FF"><enum>(3)</enum><text>databases owned

			 by the Federal Government; or</text>

						</paragraph><paragraph id="id28BCDFC52B8E4F8BA1F807CAADBAA7F5"><enum>(4)</enum><text>primarily

			 sensitive personally identifiable information of employees and contractors of

			 the Federal Government involved in national security or law enforcement.</text>

						</paragraph></subsection><subsection id="id320BA0B9156F497FB4DA04D74F6E7BD6"><enum>(b)</enum><header>Notice to other

			 law enforcement agencies</header><text>The United States Secret Service shall

			 be responsible for notifying—</text>

						<paragraph id="id881FE155E4C245EAA2B9EF1AFDE19909"><enum>(1)</enum><subparagraph commented="no" display-inline="yes-display-inline" id="id96F53CB5487B4B4CA9C0422FEF2A0C0D"><enum>(A)</enum><text>the Federal Bureau of

			 Investigation, if the security breach involves espionage, foreign

			 counterintelligence, information protected against unauthorized disclosure for

			 reasons of national defense or foreign relations, or Restricted Data (as that

			 term is defined in section 11y of the Atomic Energy Act of 1954 (42 U.S.C.

			 2014(y)), except for offenses affecting the duties of the United States Secret

			 Service under section 3056(a) of title 18, United States Code; and</text>

							</subparagraph><subparagraph id="id118A83C2837D4209878EAD5248DA4D68" indent="up1"><enum>(B)</enum><text>the United States Postal Inspection

			 Service, if the security breach involves mail fraud; and</text>

							</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="idE954AFDF71FD4DD391CD5F0925B6ACCA"><enum>(2)</enum><text>the attorney

			 general of each State affected by the security breach.</text>

						</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="id838A179712FF455F87ADFC636BEA7B71"><enum>(c)</enum><header>30-day

			 rule</header><text>The notices to Federal law enforcement and the attorney

			 general of each State affected by a security breach required under this section

			 shall be delivered without unreasonable delay, but not later than 30 days after

			 discovery of the events requiring notice.</text>

					</subsection></section><section id="ID9a27040fe7384f3f85aa78bd124f3ca7"><enum>427.</enum><header>Civil

			 remedies</header>

					<subsection id="ID65d57f54ad0b45098c166fbffdaaae96"><enum>(a)</enum><header>Penalties</header><text>Any

			 agency, or business entity engaged in interstate commerce, that violates this

			 subtitle shall be subject to a fine of—</text>

						<paragraph id="ID968189d4e34a41a391e0d6276834e108"><enum>(1)</enum><text>not more than

			 $1,000 per individual per day whose sensitive personally identity information

			 was, or is reasonably believed to have been, acquired by an unauthorized

			 person; or</text>

						</paragraph><paragraph id="ID67452b0c289c4d30802fa9529212e149"><enum>(2)</enum><text>not more than

			 $50,000 per day while the failure to give notice under this subtitle

			 persists.</text>

						</paragraph></subsection><subsection id="ID1ee5d346572d49f287bda02ce802107c"><enum>(b)</enum><header>Equitable

			 relief</header><text>Any agency or business entity that violates, proposes to

			 violate, or has violated this subtitle may be enjoined from further violations

			 by a court of competent jurisdiction.</text>

					</subsection><subsection id="ID0112b50a28e842ed9a1e3565de572b8a"><enum>(c)</enum><header>Other rights

			 and remedies</header><text>The rights and remedies available under this

			 subtitle are cumulative and shall not affect any other rights and remedies

			 available under law.</text>

					</subsection><subsection id="IDe26827a2ed574676ac9b0e85d8c38889"><enum>(d)</enum><header>Fraud

			 alert</header><text>Section 605A(b)(1) of the Fair Credit Reporting Act (15

			 U.S.C. 1681c–1(b)(1)) is amended by inserting <quote>, or evidence that the

			 consumer has received notice that the consumer's financial information has or

			 may have been compromised,</quote> after <quote>identity theft

			 report</quote>.</text>

					</subsection><subsection id="id57A7FCB00743490286635C49051718E9"><enum>(e)</enum><header>Injunctive

			 actions by the attorney general</header><text>Whenever it appears that a

			 business entity or agency to which this subtitle applies has engaged, is

			 engaged, or is about to engage, in any act or practice constituting a violation

			 of this subtitle, the Attorney General may bring a civil action in an

			 appropriate district court of the United States to—</text>

						<paragraph id="idDBC93CDC9F55407D8489F478A53DA296"><enum>(1)</enum><text>enjoin such act

			 or practice;</text>

						</paragraph><paragraph id="id0F5076CFAC1D4566BCAF48218A31487B"><enum>(2)</enum><text>enforce

			 compliance with this subtitle;</text>

						</paragraph><paragraph id="id0489B8892F804029B1D1EDE176EC6279"><enum>(3)</enum><text>obtain

			 damages—</text>

							<subparagraph id="idCDD595E7234E41E588CDA0C16B179EC7"><enum>(A)</enum><text>in the sum of

			 actual damages, restitution, and other compensation on behalf of the affected

			 residents of a State; and</text>

							</subparagraph><subparagraph id="id475AFFFDD0A340AC95B2EBA75923D783"><enum>(B)</enum><text>punitive damages,

			 if the violation is willful or intentional; and</text>

							</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id427FCE81E030417E9EBD5B45EB4ED972"><enum>(4)</enum><text>obtain such other

			 relief as the court determines to be appropriate.</text>

						</paragraph></subsection></section><section id="IDaaee9e4101c4482393ec8811c46a36d7"><enum>428.</enum><header>Enforcement by

			 State Attorneys General</header>

					<subsection id="ID6f4aabc6452c479a99914f49bb14bcbe"><enum>(a)</enum><header>In

			 general</header>

						<paragraph id="ID31e2b26776be446ebf551d080d758fdf"><enum>(1)</enum><header>Civil

			 actions</header><text>In any case in which the attorney general of a State, or

			 any State or local law enforcement agency authorized by the State attorney

			 general or by State statute to prosecute violations of consumer protection law,

			 has reason to believe that an interest of the residents of that State has been

			 or is threatened or adversely affected by the engagement of any agency or

			 business entity in a practice that is prohibited under this subtitle, the

			 State, as parens patriae on behalf of the residents of the State, or the State

			 or local law enforcement agency on behalf of the residents of the agency’s

			 jurisdiction, may bring a civil action on behalf of the residents of the State

			 or jurisdiction in a district court of the United States of appropriate

			 jurisdiction or any other court of competent jurisdiction, including a State

			 court, to—</text>

							<subparagraph id="IDb067ed8ac7134c1cabf9c8e4f439cacc"><enum>(A)</enum><text>enjoin that

			 practice;</text>

							</subparagraph><subparagraph id="ID72b12d9199f343b4879967bf16bb6aed"><enum>(B)</enum><text>enforce

			 compliance with this subtitle;</text>

							</subparagraph><subparagraph id="ID611d8e3b4445470c82a4d8ac165c24e3"><enum>(C)</enum><text>obtain damages,

			 restitution, or other compensation on behalf of residents of the State;

			 or</text>

							</subparagraph><subparagraph id="IDf391003c5540421f8c3e507d0e517b7b"><enum>(D)</enum><text>obtain such other

			 relief as the court may consider to be appropriate.</text>

							</subparagraph></paragraph><paragraph id="ID25b49e2ba0fe47d0ac2cdfb53dec5f3b"><enum>(2)</enum><header>Notice</header>

							<subparagraph id="ID5bbaa97e3537480488ee17abd147eace"><enum>(A)</enum><header>In

			 general</header><text>Before filing an action under paragraph (1), the attorney

			 general of the State involved shall provide to the Attorney General of the

			 United States—</text>

								<clause id="IDb86c9f3c0ea94102abdaac07254c27fc"><enum>(i)</enum><text>written notice of

			 the action; and</text>

								</clause><clause id="IDff7b4b530d7e4850ad7e7e371cfa903d"><enum>(ii)</enum><text>a

			 copy of the complaint for the action.</text>

								</clause></subparagraph><subparagraph id="IDf724c74ba4f54de7a9e0eafb0ac862bd"><enum>(B)</enum><header>Exemption</header>

								<clause id="IDdb2c05f26a6e4129ad1ea3fc8808612c"><enum>(i)</enum><header>In

			 general</header><text>Subparagraph (A) shall not apply with respect to the

			 filing of an action by an attorney general of a State under this subtitle, if

			 the State attorney general determines that it is not feasible to provide the

			 notice described in such subparagraph before the filing of the action.</text>

								</clause><clause id="ID08b59bbf3efb4b4fbb679d68d58889d6"><enum>(ii)</enum><header>Notification</header><text>In

			 an action described in clause (i), the attorney general of a State shall

			 provide notice and a copy of the complaint to the Attorney General at the time

			 the State attorney general files the action.</text>

								</clause></subparagraph></paragraph></subsection><subsection id="id2EEE695674E743FFAEED844E9DE4B2BF"><enum>(b)</enum><header>Federal

			 proceedings</header><text>Upon receiving notice under subsection (a)(2), the

			 Attorney General shall have the right to—</text>

						<paragraph id="id463BE71E1D0342889534C1E5EF18AEEF"><enum>(1)</enum><text>move to stay the

			 action, pending the final disposition of a pending Federal proceeding or

			 action;</text>

						</paragraph><paragraph id="id8FC7134A7BDF4CAEB0CD300775676813"><enum>(2)</enum><text>intervene in an

			 action brought under subsection (a)(2); and</text>

						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="idF08400DB50B54684AD730D4AA73B4D0A"><enum>(3)</enum><text>file petitions

			 for appeal.</text>

						</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="idC7DA2145BC2F48D4AC834A326288FD86"><enum>(c)</enum><header>Pending

			 proceedings</header><text>If the Attorney General has instituted a proceeding

			 or action for a violation of this subtitle or any regulations thereunder, no

			 attorney general of a State may, during the pendency of such proceeding or

			 action, bring an action under this subtitle against any defendant named in such

			 criminal proceeding or civil action for any violation that is alleged in that

			 proceeding or action.</text>

					</subsection><subsection id="ID1d25f80b70dc4cbbafe0e4df9529e665"><enum>(d)</enum><header>Construction</header><text display-inline="yes-display-inline">For purposes of bringing any civil action

			 under subsection (a), nothing in this subtitle regarding notification shall be

			 construed to prevent an attorney general of a State from exercising the powers

			 conferred on such attorney general by the laws of that State to—</text>

						<paragraph id="ID804a780a3d414a7caebeb785d1d7d5ce"><enum>(1)</enum><text>conduct

			 investigations;</text>

						</paragraph><paragraph id="ID16524b555a2c48c581bad20427543e33"><enum>(2)</enum><text>administer oaths

			 or affirmations; or</text>

						</paragraph><paragraph id="ID974d36fefb4248c9a5f31da127877bac"><enum>(3)</enum><text>compel the

			 attendance of witnesses or the production of documentary and other

			 evidence.</text>

						</paragraph></subsection><subsection id="IDde563d50eb274c8891db6224c4ca8926"><enum>(e)</enum><header>Venue; service

			 of process</header>

						<paragraph id="IDc9f737faffed45f79c1fb6967f2c71d0"><enum>(1)</enum><header>Venue</header><text>Any

			 action brought under subsection (a) may be brought in—</text>

							<subparagraph id="ID1ba3385aec594702b8bb9ec6355afb18"><enum>(A)</enum><text>the district

			 court of the United States that meets applicable requirements relating to venue

			 under section 1391 of title 28, United States Code; or</text>

							</subparagraph><subparagraph id="IDa2e879a151304c27b0528463def92f57"><enum>(B)</enum><text>another court of

			 competent jurisdiction.</text>

							</subparagraph></paragraph><paragraph id="ID422d254539804ffeb7a5632cbcb64308"><enum>(2)</enum><header>Service of

			 process</header><text>In an action brought under subsection (a), process may be

			 served in any district in which the defendant—</text>

							<subparagraph id="ID7fb7064b3a834481a8f4c4f31e4efbcb"><enum>(A)</enum><text>is an inhabitant;

			 or</text>

							</subparagraph><subparagraph id="ID10fd884f419d4cfc9a9d5f6d23d64247"><enum>(B)</enum><text>may be

			 found.</text>

							</subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="idF0085C05F61C4823930E8ABC2E62BE8E"><enum>(f)</enum><header>No private

			 cause of action</header><text display-inline="yes-display-inline">Nothing in

			 this subtitle establishes a private cause of action against a data broker for

			 violation of any provision of this subtitle.</text>

					</subsection></section><section id="ID7efbc91dec2f4abda18af9ad36ed9621"><enum>429.</enum><header>Effect on

			 Federal and State law</header>

					<subsection id="id9EAF9CC4332D4D42845D9EE13C2159C8"><enum></enum><text>The provisions

			 of this subtitle shall supersede any other provision of Federal law or any

			 provision of law of any State relating to notification of a security breach,

			 except as provided in section 424(b).</text>

					</subsection></section><section id="idDD4B1CF0CE66456D877A8704779D82EA"><enum>430.</enum><header>Authorization

			 of appropriations</header><text display-inline="no-display-inline">There are

			 authorized to be appropriated such sums as may be necessary to cover the costs

			 incurred by the United States Secret Service to carry out investigations and

			 risk assessments of security breaches as required under this subtitle.</text>

				</section><section id="id7ED6665FFC984CD196BD6C2B1728BFCE"><enum>431.</enum><header>Reporting on

			 risk assessment exemption</header><text display-inline="no-display-inline">The

			 United States Secret Service shall report to Congress not later than 18 months

			 after the date of enactment of this Act, and upon the request by Congress

			 thereafter, on the number and nature of the security breaches described in the

			 notices filed by those business entities invoking the risk assessment exemption

			 under section 422(b) and the response of the United States Secret Service to

			 those notices.</text>

				</section><section commented="no" display-inline="no-display-inline" id="ID6af81efa92564cf0aa27700bc66f0d3f" section-type="subsequent-section"><enum>432.</enum><header>Effective

			 date</header><text display-inline="no-display-inline">This subtitle shall take

			 effect on the expiration of the date which is 90 days after the date of

			 enactment of this Act.</text>

				</section></subtitle></title><title id="id8314F1C7466A4B5EA597E466FA3259A8"><enum>V</enum><header>Government access

			 to and use of commercial data</header>

			<section id="IDe80a8e1d714e420fa5bfe423fac8281f"><enum>501.</enum><header>General

			 Services Administration review of contracts</header>

				<subsection id="id31E355AB3C8A4C5590951E8D83E46006"><enum>(a)</enum><header>In

			 general</header><text>In considering contract awards totaling more than

			 $500,000 and entered into after the date of enactment of this Act with data

			 brokers, the Administrator of the General Services Administration shall

			 evaluate—</text>

					<paragraph id="id5526F8A36E624BFC831393AB7DA51A49"><enum>(1)</enum><text>the data privacy

			 and security program of a data broker to ensure the privacy and security of

			 data containing personally identifiable information, including whether such

			 program adequately addresses privacy and security threats created by malicious

			 software or code, or the use of peer-to-peer file sharing software;</text>

					</paragraph><paragraph id="id75D17AC6F2FE43BC8BF9EA2A3B575CA7"><enum>(2)</enum><text>the compliance of

			 a data broker with such program;</text>

					</paragraph><paragraph id="id7ED942D2EF9048CE823A77B8CE0A1ED6"><enum>(3)</enum><text>the extent to

			 which the databases and systems containing personally identifiable information

			 of a data broker have been compromised by security breaches; and</text>

					</paragraph><paragraph id="idD2FFC837446B4DC5B272880846E3B1B1"><enum>(4)</enum><text>the response by a

			 data broker to such breaches, including the efforts by such data broker to

			 mitigate the impact of such breaches.</text>

					</paragraph></subsection><subsection id="id6821C561DA6A49C59CD250719BF1CCCB"><enum>(b)</enum><header>Compliance safe

			 harbor</header><text>The data privacy and security program of a data broker

			 shall be deemed sufficient for the purposes of subsection (a), if the data

			 broker complies with or provides protection equal to industry standards, as

			 identified by the Federal Trade Commission, that are applicable to the type of

			 personally identifiable information involved in the ordinary course of business

			 of such data broker.</text>

				</subsection><subsection commented="no" display-inline="no-display-inline" id="id716228CED1E1428D8D45D7A77CD30C66"><enum>(c)</enum><header>Penalties</header><text>In

			 awarding contracts with data brokers for products or services related to

			 access, use, compilation, distribution, processing, analyzing, or evaluating

			 personally identifiable information, the Administrator of the General Services

			 Administration shall—</text>

					<paragraph commented="no" display-inline="no-display-inline" id="idE3DD3B17BA61425CB05B2FAD57E9CA9F"><enum>(1)</enum><text>include monetary

			 or other penalties—</text>

						<subparagraph commented="no" display-inline="no-display-inline" id="idD4A75D9460C1410588429BED0344DC89"><enum>(A)</enum><text>for failure to

			 comply with subtitles A and B of title IV of this Act; or</text>

						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id78EE99CC02B047C9B569309845324310"><enum>(B)</enum><text>if a contractor

			 knows or has reason to know that the personally identifiable information being

			 provided is inaccurate, and provides such inaccurate information; and</text>

						</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id653BDF2429684EE1BC315155AE7A99D9"><enum>(2)</enum><text>require a data

			 broker that engages service providers not subject to subtitle A of title IV for

			 responsibilities related to sensitive personally identifiable information

			 to—</text>

						<subparagraph commented="no" display-inline="no-display-inline" id="idC1513198682D422C92C45217128BC45C"><enum>(A)</enum><text>exercise

			 appropriate due diligence in selecting those service providers for

			 responsibilities related to personally identifiable information;</text>

						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id5550285C94DE4929BF4FF6E89CE8D0A5"><enum>(B)</enum><text>take reasonable

			 steps to select and retain service providers that are capable of maintaining

			 appropriate safeguards for the security, privacy, and integrity of the

			 personally identifiable information at issue; and</text>

						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id8295DCF1DA1D461188B8322A769666AE"><enum>(C)</enum><text>require such

			 service providers, by contract, to implement ad maintain appropriate measures

			 designed to meet the objectives and requirements in title IV.</text>

						</subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="id3653EDC93BC048C4B2893AEBAF5C88F8"><enum>(d)</enum><header>Limitation</header><text>The

			 penalties under subsection (c) shall not apply to a data broker providing

			 information that is accurately and completely recorded from a public record

			 source.</text>

				</subsection></section><section commented="no" display-inline="no-display-inline" id="idCAE548F38BD64ECD90834972854E1CA7"><enum>502.</enum><header>Requirement to

			 audit information security practices of contractors and third party business

			 entities</header><text display-inline="no-display-inline">Section 3544(b) of

			 title 44, United States Code, is amended—</text>

				<paragraph commented="no" display-inline="no-display-inline" id="id047AD61C39814E87B85F9839DD319714"><enum>(1)</enum><text display-inline="yes-display-inline">in paragraph (7)(C)(iii), by striking

			 <quote>and</quote> after the semicolon;</text>

				</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id248F978EAA0F4799932E36AED53E3344"><enum>(2)</enum><text display-inline="yes-display-inline">in paragraph (8), by striking the period

			 and inserting <quote>; and</quote>; and</text>

				</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id73B06CE9592B4E5EB4DB00F63BEBEDA8"><enum>(3)</enum><text display-inline="yes-display-inline">by adding at the end the following:</text>

					<quoted-block display-inline="no-display-inline" id="id25CA42715B7849D380103B47B8B85826" style="OLC">

						<paragraph commented="no" display-inline="no-display-inline" id="id6C3EFD46AF144E249D8F30895F903D60"><enum>(9)</enum><text display-inline="yes-display-inline">procedures for evaluating and auditing the

				information security practices of contractors or third party business entities

				supporting the information systems or operations of the agency involving

				personally identifiable information (as that term is defined in section 3 of

				the <short-title>Personal Data Privacy and Security Act of

				2005</short-title>) and ensuring remedial action to address any significant

				deficiencies.</text>

						</paragraph><after-quoted-block>.</after-quoted-block></quoted-block>

				</paragraph></section><section commented="no" display-inline="no-display-inline" id="idB8E458C334C14BAD80F90A39D0FCEDB0"><enum>503.</enum><header>Privacy impact

			 assessment of government use of commercial information services containing

			 personally identifiable information</header>

				<subsection id="IDdd15a5bae993472488774147fe03b5af"><enum>(a)</enum><header>In

			 general</header><text>Section 208(b)(1) of the E-Government Act of 2002 (44

			 U.S.C. 3501 note) is amended—</text>

					<paragraph id="IDe08c5f85fc2448588ae55b8bb6b4ca47"><enum>(1)</enum><text>in subparagraph

			 (A)(i), by striking <quote>or</quote>; and</text>

					</paragraph><paragraph id="ID52f5cb13d156463d9c7d5b1acd315f28"><enum>(2)</enum><text>in subparagraph

			 (A)(ii), by striking the period and inserting <quote>; or</quote>; and</text>

					</paragraph><paragraph id="id34BA8988A9B44728872380BFB8E0DF66"><enum>(3)</enum><text>by inserting

			 after clause (ii) the following:</text>

						<quoted-block display-inline="no-display-inline" id="idBFA518D784BD4645A1E1566B2823AFE2" style="OLC">

							<clause id="IDf1b36c5794af4ea3817657ffcf9d8fae"><enum>(iii)</enum><text>purchasing or

				subscribing for a fee to personally identifiable information from a data broker

				(as such terms are defined in section 3 of the

				<short-title>Personal Data Privacy and Security Act of

				2005</short-title>).</text>

							</clause><after-quoted-block>.</after-quoted-block></quoted-block>

					</paragraph></subsection><subsection id="ID87fa6d627664464db2dfe94405565b22"><enum>(b)</enum><header>Limitation</header><text>Notwithstanding

			 any other provision of law, commencing 1 year after the date of enactment of

			 this Act, no Federal department or agency may enter into a contract with a data

			 broker to access for a fee any database consisting primarily of personally

			 identifiable information concerning United States persons (other than news

			 reporting or telephone directories) unless the head of such department or

			 agency—</text>

					<paragraph id="IDcc11f04a4d544ac793bb6df8c65b15c2"><enum>(1)</enum><text>completes a

			 privacy impact assessment under section 208 of the E-Government Act of 2002 (44

			 U.S.C. 3501 note), which shall subject to the provision in that Act pertaining

			 to sensitive information, include a description of—</text>

						<subparagraph id="id7524FA8407684D61A29A82F009FAD24E"><enum>(A)</enum><text>such

			 database;</text>

						</subparagraph><subparagraph id="id33E9B1B4DEC44916ABA9D6A8B08031EA"><enum>(B)</enum><text>the name of the

			 data broker from whom it is obtained; and</text>

						</subparagraph><subparagraph id="id2459A77DF0694FCF8A93FB0ACB42E06D"><enum>(C)</enum><text>the amount of the

			 contract for use;</text>

						</subparagraph></paragraph><paragraph id="ID2ce2424ed9144696b37b8fe1e83d4e0a"><enum>(2)</enum><text>adopts

			 regulations that specify—</text>

						<subparagraph id="IDfc56d79a542e47b3b38c993a9af70e0a"><enum>(A)</enum><text>the personnel

			 permitted to access, analyze, or otherwise use such databases;</text>

						</subparagraph><subparagraph id="IDc4fd6f41f10a417681070223398dc79e"><enum>(B)</enum><text>standards

			 governing the access, analysis, or use of such databases;</text>

						</subparagraph><subparagraph id="ID1053bd46791e44c3b68d57d3f5f7b1d4"><enum>(C)</enum><text>any standards

			 used to ensure that the personally identifiable information accessed, analyzed,

			 or used is the minimum necessary to accomplish the intended legitimate purpose

			 of the Federal department or agency;</text>

						</subparagraph><subparagraph id="ID7035425ef4714021972c2c269edd01dd"><enum>(D)</enum><text>standards

			 limiting the retention and redisclosure of personally identifiable information

			 obtained from such databases;</text>

						</subparagraph><subparagraph id="IDb11b7b39a29d4a7c9d1a881bb1813db4"><enum>(E)</enum><text>procedures

			 ensuring that such data meet standards of accuracy, relevance, completeness,

			 and timeliness;</text>

						</subparagraph><subparagraph id="IDa2b7ad5e56f5428d8432d53c7b6f7df4"><enum>(F)</enum><text>the auditing and

			 security measures to protect against unauthorized access, analysis, use, or

			 modification of data in such databases;</text>

						</subparagraph><subparagraph id="ID30ea156f3b5746c0b18347a284324ce7"><enum>(G)</enum><text>applicable

			 mechanisms by which individuals may secure timely redress for any adverse

			 consequences wrongly incurred due to the access, analysis, or use of such

			 databases;</text>

						</subparagraph><subparagraph id="ID0b3e488ad4454a4abd6b7e044f1a256d"><enum>(H)</enum><text>mechanisms, if

			 any, for the enforcement and independent oversight of existing or planned

			 procedures, policies, or guidelines; and</text>

						</subparagraph><subparagraph id="IDf2a558a5f86945c9a399c70d5e14a0f9"><enum>(I)</enum><text>an outline of

			 enforcement mechanisms for accountability to protect individuals and the public

			 against unlawful or illegitimate access or use of databases; and</text>

						</subparagraph></paragraph><paragraph id="ID4255f43d3e2842a988861bcc1a0d34f1"><enum>(3)</enum><text>incorporates into

			 the contract or other agreement totaling more than $500,000, provisions—</text>

						<subparagraph id="ID44bcc37cc6fa4938b911bb5cf01d2237"><enum>(A)</enum><text>providing for

			 penalties—</text>

							<clause id="IDcd07dec58cce44a8bda13a24aaf2c2a7"><enum>(i)</enum><text>for

			 failure to comply with title IV of this Act; or</text>

							</clause><clause id="idB618D7461D8B4D2BA443320A848C8FBB"><enum>(ii)</enum><text>if

			 the entity knows or has reason to know that the personally identifiable

			 information being provided to the Federal department or agency is inaccurate,

			 and provides such inaccurate information.</text>

							</clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idD539AF1486FA424E9A4C379E6F3448F3"><enum>(B)</enum><text>requiring a data

			 broker that engages service providers not subject to subtitle A of title IV for

			 responsibilities related to sensitive personally identifiable information

			 to—</text>

							<clause commented="no" display-inline="no-display-inline" id="id6ED17559FA624A2EACF24E3ED8360F34"><enum>(i)</enum><text>exercise

			 appropriate due diligence in selecting those service providers for

			 responsibilities related to personally identifiable information;</text>

							</clause><clause commented="no" display-inline="no-display-inline" id="id13DB28B12C3448E393426B6C4F219FC8"><enum>(ii)</enum><text>take reasonable

			 steps to select and retain service providers that are capable of maintaining

			 appropriate safeguards for the security, privacy, and integrity of the

			 personally identifiable information at issue; and</text>

							</clause><clause commented="no" display-inline="no-display-inline" id="id5375DF74A1FB4A92AC8CE0CE6DEBE676"><enum>(iii)</enum><text>require such

			 service providers, by contract, to implement ad maintain appropriate measures

			 designed to meet the objectives and requirements in title IV.</text>

							</clause></subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="idBA809617FFE540E6BFB7BFE83112C963"><enum>(c)</enum><header>Limitation on

			 penalties</header><text>The penalties under paragraph (3)(A) shall not apply to

			 a data broker providing information that is accurately and completely recorded

			 from a public record source.</text>

				</subsection><subsection id="ID04a7ec6b958d43a0bc922ef1d6dc9f02"><enum>(d)</enum><header>Individual

			 screening programs</header>

					<paragraph id="idC63CC0D209DF46F98AC964D69F12B999"><enum>(1)</enum><header>In

			 general</header><text>Notwithstanding any other provision of law, commencing

			 one year after the date of enactment of this Act, no Federal department or

			 agency may use commercial databases or contract with a data broker to implement

			 an individual screening program unless such program is—</text>

						<subparagraph id="ID7b02ef246bf7466a80f09d6821d4518a"><enum>(A)</enum><text>congressionally

			 authorized; and</text>

						</subparagraph><subparagraph id="IDc3334f25e8554912b5a1966ad268ba95"><enum>(B)</enum><text>subject to

			 regulations developed by notice and comment that—</text>

							<clause id="ID67290e377d73422cafbf3bae5d90d600"><enum>(i)</enum><text>establish a

			 procedure to enable individuals, who suffer an adverse consequence because the

			 screening system determined that they might pose a security threat, to appeal

			 such determination and correct information contained in the system;</text>

							</clause><clause id="ID95b4e0af9da844f395e8f198f1f3afca"><enum>(ii)</enum><text>ensure that

			 Federal and commercial databases that will be used to establish the identity of

			 individuals or otherwise make assessments of individuals under the system will

			 not produce a large number of false positives or unjustified adverse

			 consequences;</text>

							</clause><clause id="IDc4a4599409ae43da9e6e802f006e156c"><enum>(iii)</enum><text>ensure the

			 efficacy and accuracy of all of the search tools that will be used and ensure

			 that the department or agency can make an accurate predictive assessment of

			 those who may constitute a threat;</text>

							</clause><clause id="ID903fa7a4285546c184006f9d960cd215"><enum>(iv)</enum><text>establish an

			 internal oversight board to oversee and monitor the manner in which the system

			 is being implemented;</text>

							</clause><clause id="IDbfcaacbe5e9e4347ac829301c6cd29cc"><enum>(v)</enum><text>establish

			 sufficient operational safeguards to reduce the opportunities for abuse;</text>

							</clause><clause id="ID865c2af269a34783a0a16838456652e5"><enum>(vi)</enum><text>implement

			 substantial security measures to protect the system from unauthorized

			 access;</text>

							</clause><clause id="ID631d401e20724426b82200bb5c71b654"><enum>(vii)</enum><text>adopt policies

			 establishing the effective oversight of the use and operation of the system;

			 and</text>

							</clause><clause id="ID982808f5f6e24affbefbc82e4c98f835"><enum>(viii)</enum><text>ensure that

			 there are no specific privacy concerns with the technological architecture of

			 the system; and</text>

							</clause></subparagraph><subparagraph id="id4294468E410642C189E91C305EF5F90B"><enum>(C)</enum><text>coordinated with

			 the Terrorist Screening Center or any such successor organization.</text>

						</subparagraph></paragraph><paragraph id="idCF99A1D52DB342D28F03C990E2923318"><enum>(2)</enum><header>Definition</header><text>As

			 used in this subsection, the term <quote>individual screening

			 program</quote>—</text>

						<subparagraph id="id236F44C39B71424CB57510ABFE604543"><enum>(A)</enum><text>means a system

			 that relies on personally identifiable information from commercial databases

			 to—</text>

							<clause id="idBDEB7522199940E4AB0CEF57F777C4D3"><enum>(i)</enum><text>evaluate all or

			 most individuals seeking to exercise a particular right or privilege under

			 Federal law; and</text>

							</clause><clause id="id71B31571407A4B6FA62681C986588082"><enum>(ii)</enum><text>determine

			 whether such individuals are on a terrorist watch list or otherwise pose a

			 security threat; and</text>

							</clause></subparagraph><subparagraph id="idAEC057ECB7374384951FAED087038B0B"><enum>(B)</enum><text>does not include

			 any program or system to grant security clearances.</text>

						</subparagraph></paragraph></subsection><subsection id="ID37a0a0125a3043cf82028bea0f86738c"><enum>(e)</enum><header>Study of

			 government use</header>

					<paragraph id="ID7f2dcf7bc65a45b6858a1b5eadeb451f"><enum>(1)</enum><header>Scope of

			 study</header><text>Not later than 180 days after the date of enactment of this

			 Act, the Comptroller General of the United States shall conduct a study and

			 audit and prepare a report on Federal agency use of data brokers or commercial

			 databases containing personally identifiable information, including the impact

			 on privacy and security, and the extent to which Federal contracts include

			 sufficient provisions to ensure privacy and security protections, and penalties

			 for failures in privacy and security practices.</text>

					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID95d5160629794417b05367480fc44571"><enum>(2)</enum><header>Report</header><text>A

			 copy of the report required under paragraph (1) shall be submitted to

			 Congress.</text>

					</paragraph></subsection></section><section commented="no" display-inline="no-display-inline" id="id1055A56CF08341A09FA12FC834F96E1F"><enum>504.</enum><header>Implementation

			 of Chief Privacy Officer requirements</header>

				<subsection id="ID25d0e324e1cb4b128ea190112d4f8e37"><enum>(a)</enum><header>Designation of

			 the Chief Privacy Officer</header><text>Pursuant to the requirements under

			 section 522 of the Transportation, Treasury, Independent Agencies, and General

			 Government Appropriations Act, 2005 (division H of Public Law 108–447; 118

			 Stat. 3199) that each agency designate a Chief Privacy Officer, the Department

			 of Justice shall implement such requirements by designating a department-wide

			 Chief Privacy Officer, whose primary role shall be to fulfill the duties and

			 responsibilities of Chief Privacy Officer and who shall report directly to the

			 Deputy Attorney General.</text>

				</subsection><subsection id="ID54cd683ee5f34dbc8db0aec728976302"><enum>(b)</enum><header>Duties and

			 responsibilities of Chief Privacy Officer</header><text>In addition to the

			 duties and responsibilities outlined under section 522 of the Transportation,

			 Treasury, Independent Agencies, and General Government Appropriations Act, 2005

			 (division H of Public Law 108–447; 118 Stat. 3199), the Department of Justice

			 Chief Privacy Officer shall—</text>

					<paragraph id="ID895ef86d2ced48fab86dee6cbbf5a279"><enum>(1)</enum><text>oversee the

			 Department of Justice’s implementation of the requirements under section 603 to

			 conduct privacy impact assessments of the use of commercial data containing

			 personally identifiable information by the Department;</text>

					</paragraph><paragraph id="IDe3fe72c238144c03a12e73c352d4bfd3"><enum>(2)</enum><text>promote the use

			 of law enforcement technologies that sustain privacy protections, and assure

			 that the implementation of such technologies relating to the use, collection,

			 and disclosure of personally identifiable information preserve the privacy and

			 security of such information; and</text>

					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID687c8749cffb40bbb96b92b562511dd1"><enum>(3)</enum><text>coordinate with

			 the Privacy and Civil Liberties Oversight Board, established in the

			 Intelligence Reform and Terrorism Prevention Act of 2004 (Public Law 108–458),

			 in implementing paragraphs (1) and (2) of this subsection.</text>

					</paragraph></subsection></section></title></legis-body>

</bill>

