<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" bill-type="olc" dms-id="H954FBF0DDF1C44C283CF9657EB60D7DF" public-private="public">
<metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>110 HR 1685 IH: Data Security Act of
</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2007-03-26</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
	<form>
		<distribution-code display="yes">I</distribution-code>
		<congress>110th CONGRESS</congress>
		<session>1st Session</session>
		<legis-num>H. R. 1685</legis-num>
		<current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber>
		<action>
			<action-date date="20070326">March 26, 2007</action-date>
			<action-desc><sponsor name-id="P000591">Mr. Price of Georgia</sponsor>
			 introduced the following bill; which was referred to the
			 <committee-name committee-id="HBA00">Committee on Financial
			 Services</committee-name>, and in addition to the Committees on
			 <committee-name committee-id="HGO00">Oversight and Government
			 Reform</committee-name> and <committee-name committee-id="HIF00">Energy and
			 Commerce</committee-name>, for a period to be subsequently determined by the
			 Speaker, in each case for consideration of such provisions as fall within the
			 jurisdiction of the committee concerned</action-desc>
		</action>
		<legis-type>A BILL</legis-type>
		<official-title>To protect information relating to consumers, to require
		  notice of security breaches, and for other purposes.</official-title>
	</form>
	<legis-body id="H4C30C8B5C7894381B1D22DC4046D9D66" style="OLC">
		<section display-inline="no-display-inline" id="H5513568BF25E48E0A53C62612C01A450" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the
			 <quote><short-title>Data Security Act of
			 2007</short-title></quote>.</text>
		</section><section id="HEADAC68A229A43E6B1E5968B214BA2FD"><enum>2.</enum><header>Definitions</header><text display-inline="no-display-inline">For purposes of this Act, the following
			 definitions shall apply:</text>
			<paragraph id="H31A12FCC51D04BB68DB6ABEF03F98111"><enum>(1)</enum><header>Affiliate</header><text>The
			 term <term>affiliate</term> means any company that controls, is controlled by,
			 or is under common control with another company.</text>
			</paragraph><paragraph id="HEC7252747167436A88EBC5A05474D4D5"><enum>(2)</enum><header>Agency</header><text>The
			 term <quote>agency</quote> has the same meaning given such term in section
			 551(1) of title 5, United States Code.</text>
			</paragraph><paragraph id="H2CFEE6751B8B482AB39D701C7B76083B"><enum>(3)</enum><header>Breach of data
			 security</header>
				<subparagraph id="HED35965472EA4478A95B8019E15EC457"><enum>(A)</enum><header>In
			 general</header><text>The term <term>breach of data security</term> means the
			 unauthorized acquisition of sensitive account information or sensitive personal
			 information.</text>
				</subparagraph><subparagraph id="H37AC547B23F94712A83F23AE53B88F3F"><enum>(B)</enum><header>Exception for
			 data that is not in usable form</header>
					<clause id="HA5C4C102191B4457B61FE031E2D07BFC"><enum>(i)</enum><header>In
			 general</header><text>The term <term>breach of data security</term> does not
			 include the unauthorized acquisition of sensitive account information or
			 sensitive personal information that is maintained or communicated in a manner
			 that is not usable—</text>
						<subclause id="H9AD8FC01755A45109C1454C6C37D85DF"><enum>(I)</enum><text>to commit identity
			 theft; or</text>
						</subclause><subclause id="HB00B8EEE73FA486489129908A6365706"><enum>(II)</enum><text>to make
			 fraudulent transactions on financial accounts.</text>
						</subclause></clause><clause id="H71FAAEC4B2F141B991609000862DE3C6"><enum>(ii)</enum><header>Rule of
			 Construction</header><text>For purposes of this subparagraph, information that
			 is maintained or communicated in a manner that is not usable includes any
			 information that is maintained or communicated in an encrypted, redacted,
			 altered, edited, or coded form.</text>
					</clause></subparagraph></paragraph><paragraph id="HF2B46CE7D9BA41848D95B996DADF31F3"><enum>(4)</enum><header>Commission</header><text>The
			 term <term>Commission</term> means the Federal Trade Commission.</text>
			</paragraph><paragraph id="H767A7086AF08476D8E006632F3954F74"><enum>(5)</enum><header>Consumer</header><text>The
			 term <term>consumer</term> means an individual.</text>
			</paragraph><paragraph id="HD17FFC9773914433A81D01F2E43398A0"><enum>(6)</enum><header>Consumer
			 reporting agency that compiles and maintains files on consumers on a nationwide
			 basis</header><text>The term <term>consumer reporting agency that compiles and
			 maintains files on consumers on a nationwide basis</term> has the same meaning
			 as in section 603(p) of the Fair Credit Reporting Act (15 U.S.C.
			 1681a(p)).</text>
			</paragraph><paragraph id="HBD4D775C02BE4BC0A0DE48BC23FBF3E"><enum>(7)</enum><header>Covered
			 entity</header>
				<subparagraph id="H9BC4F3ADCCEF4AE8888579B899CD43B4"><enum>(A)</enum><header>In
			 general</header><text>The term <term>covered entity</term> means any—</text>
					<clause id="HD5E10B7FF3B44244805089B714279DB1"><enum>(i)</enum><text>entity, the
			 business of which is engaging in financial activities, as described in section
			 4(k) of the Bank Holding Company Act of 1956 (<external-xref legal-doc="usc" parsable-cite="usc/12/1843">12 U.S.C. 1843(k)</external-xref>);</text>
					</clause><clause id="H1DDC075EEAE94C5AB7B51D72A426B385"><enum>(ii)</enum><text>financial
			 institution, including any institution described in section 313.3(k) of title
			 16, Code of Federal Regulations, as in effect on the date of the enactment of
			 this Act;</text>
					</clause><clause id="HB91CBC083CD54CA9B7B3C490BEA399D7"><enum>(iii)</enum><text>entity that
			 maintains or otherwise possesses information that is subject to section 628 of
			 the Fair Credit Reporting Act (<external-xref legal-doc="usc" parsable-cite="usc/15/1681w">15 U.S.C. 1681w</external-xref>); or</text>
					</clause><clause id="H9445F253C8474D06865FEB26B3A0432E"><enum>(iv)</enum><text>other individual,
			 partnership, corporation, trust, estate, cooperative, association, or entity
			 that maintains or communicates sensitive account information or sensitive
			 personal information.</text>
					</clause></subparagraph><subparagraph id="H8E38199A452B452AB32BA91D39CD5EE"><enum>(B)</enum><header>Exception</header><text>The
			 term <quote>covered entity</quote> does not include any agency or any other
			 unit of Federal, State, or local government or any subdivision of such
			 unit.</text>
				</subparagraph></paragraph><paragraph id="H1A33DD2046544F6CB1C226CFB3D4AA49"><enum>(8)</enum><header>Financial
			 institution</header><text>The term <quote>financial institution</quote> has the
			 same meaning as in section 509 of the Gramm-Leach-Bliley Act (15 U.S.C.
			 6809).</text>
			</paragraph><paragraph id="H2116A000E92842A8A5A44E156DB12C65"><enum>(9)</enum><header>Sensitive
			 account information</header><text>The term <term>sensitive account
			 information</term> means a financial account number relating to a consumer,
			 including a credit card number or debit card number, in combination with any
			 security code, access code, password, or other personal identification
			 information required to access the financial account.</text>
			</paragraph><paragraph id="H1060ECDABD894C39006C56CB126754D0"><enum>(10)</enum><header>Sensitive
			 personal information</header>
				<subparagraph id="H144EB691C8A64C5BA765F0ACB4C67F1B"><enum>(A)</enum><header>In
			 general</header><text>The term <term>sensitive personal information</term>
			 means the first and last name, address, or telephone number of a consumer, in
			 combination with any of the following relating to such consumer:</text>
					<clause id="H15C3DCE513124A7787EC6E1C08589D5C"><enum>(i)</enum><text>Social security
			 account number.</text>
					</clause><clause id="H9ACD263FABFD4D1A8E5C5B9EC0006609"><enum>(ii)</enum><text>Driver’s license
			 number or equivalent State identification number.</text>
					</clause><clause id="H50DE85DF213D479396DA8C81D62536CD"><enum>(iii)</enum><text>Taxpayer
			 identification number.</text>
					</clause></subparagraph><subparagraph id="H53520856F4514EED8C008B3502715407"><enum>(B)</enum><header>Exception</header><text>The
			 term <term>sensitive personal information</term> does not include publicly
			 available information that is lawfully made available to the general public
			 from—</text>
					<clause id="HB2D0C47312474A1FBDE47DAA79B1C42"><enum>(i)</enum><text>Federal, State, or
			 local government records; or</text>
					</clause><clause id="H35B5FD4EA1CE44F888CAAD9CC03BBDA1"><enum>(ii)</enum><text>widely
			 distributed media.</text>
					</clause></subparagraph></paragraph><paragraph id="HCB41D2447E7049EE933D711BFB3ED83C"><enum>(11)</enum><header>Substantial
			 harm or inconvenience</header>
				<subparagraph id="H617DAA575B18425BAA6773353CFFCC8E"><enum>(A)</enum><header>In
			 general</header><text>The term <quote>substantial harm or inconvenience</quote>
			 means—</text>
					<clause id="H7A3EA16607754453AB9DD07180D1089D"><enum>(i)</enum><text>material financial
			 loss to, or civil or criminal penalties imposed on, a consumer, due to the
			 unauthorized use of sensitive account information or sensitive personal
			 information relating to such consumer; or</text>
					</clause><clause id="H0CE7E9BED6CF4A7BB93208C92363AD7E"><enum>(ii)</enum><text>the
			 need for a consumer to expend significant time and effort to correct erroneous
			 information relating to the consumer, including information maintained by a
			 consumer reporting agency, financial institution, or government entity, in
			 order to avoid material financial loss, increased costs, or civil or criminal
			 penalties, due to the unauthorized use of sensitive account information or
			 sensitive personal information relating to such consumer.</text>
					</clause></subparagraph><subparagraph id="H6CD04045A1054B6E87EF2663FD98EA9"><enum>(B)</enum><header>Exception</header><text>The
			 term <term>substantial harm or inconvenience</term> does not include—</text>
					<clause id="H47C129FB899D4449B0DA08AED57DD26"><enum>(i)</enum><text>changing a
			 financial account number or closing a financial account; or</text>
					</clause><clause commented="no" display-inline="no-display-inline" id="H8C3B54789C234520B8A2CF13C0BA82EE"><enum>(ii)</enum><text>harm or
			 inconvenience that does not result from identity theft or account fraud.</text>
					</clause></subparagraph></paragraph></section><section id="H03D814A15E0242A5A5B19FFB3ECD2453"><enum>3.</enum><header>Protection of
			 information and security breach notification</header>
			<subsection id="HC9ABE07912E246988200E5D9004390C5"><enum>(a)</enum><header>Security
			 procedures required</header>
				<paragraph id="H615A507CB2234D28B828C4032E7DBBE8"><enum>(1)</enum><header>In
			 general</header><text>Each covered entity shall implement, maintain, and
			 enforce reasonable policies and procedures to protect the confidentiality and
			 security of sensitive account information and sensitive personal information
			 which is maintained or is being communicated by or on behalf of a covered
			 entity, from the unauthorized use of such information that is reasonably likely
			 to result in substantial harm or inconvenience to the consumer to whom such
			 information relates.</text>
				</paragraph><paragraph id="HC27CC5AF12D1428B87D045EE25F3163D"><enum>(2)</enum><header>Limitation</header><text>Any
			 policy or procedure implemented or maintained under paragraph (1) shall be
			 appropriate to the—</text>
					<subparagraph id="HD59AF69036B54F66BCEDEB487FB47108"><enum>(A)</enum><text>size and
			 complexity of a covered entity;</text>
					</subparagraph><subparagraph id="HD074B5B93E6242708243F6A2329EBDE5"><enum>(B)</enum><text>nature and scope
			 of the activities of such entity; and</text>
					</subparagraph><subparagraph id="H6E141B68D2B349FFAA76018FF725E45"><enum>(C)</enum><text>sensitivity of the
			 consumer information to be protected.</text>
					</subparagraph></paragraph></subsection><subsection id="H6DBE1B9E16744F5BB70014B01971CB9"><enum>(b)</enum><header>Investigation
			 required</header>
				<paragraph id="HAF953A13E8DD4EC1BD51E7C678F100C5"><enum>(1)</enum><header>In
			 general</header><text>If a covered entity determines that a breach of data
			 security has or may have occurred in relation to sensitive account information
			 or sensitive personal information that is maintained or is being communicated
			 by, or on behalf of, such covered entity, the covered entity shall conduct an
			 investigation—</text>
					<subparagraph id="HE2C07B1679EB4BF0969943C0B068A200"><enum>(A)</enum><text>to assess the
			 nature and scope of the breach;</text>
					</subparagraph><subparagraph id="HBDB403B22A284AE5B1EBF10017D4349E"><enum>(B)</enum><text>to identify any
			 sensitive account information or sensitive personal information that may have
			 been involved in the breach; and</text>
					</subparagraph><subparagraph id="H638D4639B7CF4C29B0E300527FD6ADDF"><enum>(C)</enum><text>to determine if
			 such information is reasonably likely to be misused in a manner causing
			 substantial harm or inconvenience to the consumers to whom the information
			 relates.</text>
					</subparagraph></paragraph><paragraph id="HF9F42740AD624EC3001D00A459570584"><enum>(2)</enum><header>Neural networks
			 and information security programs</header><text>In determining the likelihood
			 of misuse of sensitive account information under paragraph (1)(C), a covered
			 entity shall consider whether any neural network or security program has
			 detected, or is likely to detect or prevent, fraudulent transactions resulting
			 from the breach of security.</text>
				</paragraph></subsection><subsection id="HAA2A28BE51AD467390EDAA005DDAC7C"><enum>(c)</enum><header>Notice
			 required</header><text>If a covered entity determines under subsection
			 (b)(1)(C) that sensitive account information or sensitive personal information
			 involved in a breach of data security is reasonably likely to be misused in a
			 manner causing substantial harm or inconvenience to the consumers to whom the
			 information relates, such covered entity, or a third party acting on behalf of
			 such covered entity, shall—</text>
				<paragraph id="H653C2C4D5D3940DF87DA4FDE272DDA24"><enum>(1)</enum><text>notify, in the
			 following order—</text>
					<subparagraph id="HDA263CCD79F24A2FA91F6CDE4DCC15E"><enum>(A)</enum><text>the appropriate
			 agency or authority identified in section 5;</text>
					</subparagraph><subparagraph id="H76C6D22B784E4A3994CF2ED87B7F7EF"><enum>(B)</enum><text>an appropriate law
			 enforcement agency;</text>
					</subparagraph><subparagraph id="HD56797CE7C9544148FB484A6F7D9A769"><enum>(C)</enum><text display-inline="yes-display-inline">any entity that owns, or is obligated on, a
			 financial account to which the sensitive account information relates, in the
			 case of a breach involving sensitive account information;</text>
					</subparagraph><subparagraph id="H7BC949D189354A00A8AB73B83C523249"><enum>(D)</enum><text display-inline="yes-display-inline">each consumer reporting agency that
			 compiles and maintains files on consumers on a nationwide basis, in the case of
			 a breach involving sensitive personal information relating to 1,000 or more
			 consumers; and</text>
					</subparagraph><subparagraph id="HFA57FAA2427E405484A021DDB8006140"><enum>(E)</enum><text>all consumers to
			 whom the sensitive account information or sensitive personal information
			 relates; and</text>
					</subparagraph></paragraph><paragraph id="H2B785D0C8D9A49FA00389221BFDB07B7"><enum>(2)</enum><text>take reasonable
			 measures to restore the security and confidentiality of the sensitive account
			 information or sensitive personal information involved in the breach.</text>
				</paragraph></subsection><subsection commented="no" id="H495FAD17852C4C64BD18D45AD9D5993"><enum>(d)</enum><header>Compliance</header>
				<paragraph commented="no" id="HC26C710308BD43EDA442AEBA30A7EB64"><enum>(1)</enum><header>In
			 general</header><text>A financial institution shall be deemed to be in
			 compliance with—</text>
					<subparagraph commented="no" id="HC4C14A991F6943888188067CD274B645"><enum>(A)</enum><text>subsection (a),
			 and any regulations prescribed under such subsection, if such institution
			 maintains policies and procedures to protect the confidentiality and security
			 of sensitive account information and sensitive personal information that are
			 subject to section 501(b) of the Gramm-Leach-Bliley Act (<external-xref legal-doc="usc" parsable-cite="usc/15/6801">15 U.S.C. 6801(b)</external-xref>) and
			 any regulations or guidance prescribed under that section that are applicable
			 to such institution; and</text>
					</subparagraph><subparagraph commented="no" id="H69688EBE45774B8491468142CBFAB174"><enum>(B)</enum><text>subsections (b)
			 and (c), and any regulations prescribed under such subsections, if such
			 institution—</text>
						<clause commented="no" id="HF6677B4479DD487FB824B3F7D985567B"><enum>(i)</enum><subclause commented="no" display-inline="yes-display-inline" id="H43956CD9C90649D881E58C9BAE2F773"><enum>(I)</enum><text>maintains policies and
			 procedures to investigate and provide notice to consumers of breaches of data
			 security that are subject to the investigation and notice requirements
			 established by regulations or guidance under section 501(b) of the
			 Gramm-Leach-Bliley Act (<external-xref legal-doc="usc" parsable-cite="usc/15/6801">15 U.S.C. 6801(b)</external-xref>) that are applicable to such
			 institution; or</text>
							</subclause><subclause commented="no" id="H693CEF8BE5FB458C808F596B6DDA7FB0" indent="up1"><enum>(II)</enum><text>is an affiliate of a bank holding
			 company that maintains policies and procedures to investigate and provide
			 notice to consumers of breaches of data security that are consistent with the
			 policies and procedures of a bank that is an affiliate of such institution, and
			 that bank’s policies and procedures are subject to the investigation and notice
			 requirements established by any regulations or guidance under section 501(b) of
			 the Gramm-Leach-Bliley Act (<external-xref legal-doc="usc" parsable-cite="usc/15/6801">15 U.S.C. 6801(b)</external-xref>) that are applicable to that
			 bank; and</text>
							</subclause></clause><clause commented="no" id="HF5F3B01F2030479980AECE98D9B1FC5C"><enum>(ii)</enum><text>provides for
			 notice to the entities described under subparagraphs (B), (C), and (D) of
			 subsection (c)(1), if notice is provided to consumers pursuant to the policies
			 and procedures of such institution described in clause (i).</text>
						</clause></subparagraph></paragraph><paragraph commented="no" id="H61C550A51EE34F79966787090255CB22"><enum>(2)</enum><header>Definitions</header><text>For
			 purposes of this subsection, the terms <quote>bank holding company</quote> and
			 <quote>bank</quote> shall have the same meaning given such terms under section
			 2 of the Bank Holding Company Act of 1956.</text>
				</paragraph><paragraph id="HF46A147CCD9C45288F51EEB889FB4BA5"><enum>(3)</enum><header>Harmonization of
			 GLBA</header>
					<subparagraph id="H523F72F87582476797128383FADF48E3"><enum>(A)</enum><header>In
			 general</header><text display-inline="yes-display-inline">To the extent that
			 compliance by any financial institution with the requirements of title V of the
			 Gramm-Leach-Bliley Act are deemed, pursuant to this subsection, to be
			 compliance with this section, and the requirements of such title, and any
			 regulations, guidelines, or orders issued or prescribed under such title,
			 differ in any way from this section, it is the sense of the Congress that the
			 applicable regulators shall make every appropriate effort as any relevant
			 regulations are prescribed, reviewed, or updated to reconcile such differences
			 to harmonize the corresponding requirements.</text>
					</subparagraph><subparagraph id="H36FEFC070BBC47A39B5674732E8DD81C"><enum>(B)</enum><header>Agencies that
			 have not fully implemented title v of the GLBA</header><text display-inline="yes-display-inline">Any Federal functional regulator (as
			 defined in section 509(2) of Gramm-Leach-Bliley Act) that has not issued or
			 prescribed regulations, guidelines, or orders that are required or permitted
			 under title V of the Gramm-Leach-Bliley Act and that set forth the requirements
			 for compliance with such title, including with respect to providing notice of a
			 breach of data security, shall prescribe such regulations, guidelines, or
			 orders, as appropriate, before the end of the 12-month period beginning on the
			 date of the enactment of this Act, in a manner that—</text>
						<clause id="HA69B2DAFF7154B8B9C0102A8EDF4C754"><enum>(i)</enum><text>is
			 consistent with this section; and</text>
						</clause><clause id="H92A4A87323E446A080E30059490839F4"><enum>(ii)</enum><text>allows, to the
			 extent practical, consistent standards across holding companies with respect to
			 compliance with this section and section 501(b) of the Gramm-Leach-Bliley Act
			 that is deemed compliance under this subsection.</text>
						</clause></subparagraph><subparagraph id="H013EB60B67E040E400D102523B00CDC7"><enum>(C)</enum><header>Agencies that
			 have implemented title v of the GLBA</header><text display-inline="yes-display-inline">Any Federal functional regulator (as
			 defined in section 509(2) of Gramm-Leach-Bliley Act) that has issued or
			 prescribed regulations, guidelines, or orders that are required or permitted
			 under title V of the Gramm-Leach-Bliley Act and that set forth the requirements
			 for compliance with such title shall modify such regulations, guidelines, or
			 orders, as appropriate, before the end of the 12-month period beginning on the
			 date of the enactment of this Act, in a manner that—</text>
						<clause id="H574AC6531A4C438DA4A04003CAFC465"><enum>(i)</enum><text>is
			 consistent with this section; and</text>
						</clause><clause id="HBA69AA7F843E473485DED0D993FE0056"><enum>(ii)</enum><text>allows, to the
			 extent practical, consistent standards across holding companies with respect to
			 compliance with this section and section 501(b) of the Gramm-Leach-Bliley Act
			 that is deemed compliance under this subsection.</text>
						</clause></subparagraph><subparagraph id="HFD5AA69AB3F641C9B36DD369D004F049"><enum>(D)</enum><header>Coordination
			 under this section</header><text display-inline="yes-display-inline">To the
			 extent practical, any regulations, guidelines, standards, or orders issued or
			 prescribed under this section shall be issued or prescribed in a manner
			 that—</text>
						<clause id="HD6D20E2EDFCD4503A000C97D090298B0"><enum>(i)</enum><text>is
			 consistent with this section; and</text>
						</clause><clause id="HF3C662D309A14C499BBC7BBB5BC5E94F"><enum>(ii)</enum><text>allows, to the
			 extent practical, consistent standards across holding companies with respect to
			 compliance with this section and section 501(b) of the Gramm-Leach-Bliley Act
			 that is deemed compliance under this subsection.</text>
						</clause></subparagraph></paragraph></subsection><subsection id="H57102D1ABED946E1B19E728F21DC2264"><enum>(e)</enum><header>Treatment of
			 notice</header><text>A notice provided to any consumer under this section may
			 be the basis for a request by the consumer, or an individual acting on behalf
			 of or as a personal representative of a consumer, for an initial fraud alert
			 under section 605A(a)(1) of the Fair Credit Reporting Act.</text>
			</subsection></section><section id="H3DED31CF1B8345F193BEBE48256655B"><enum>4.</enum><header>Implementing
			 regulations</header>
			<subsection id="H3F2409A258B549CC983130635BB5B243"><enum>(a)</enum><header>In
			 general</header><text>Except as provided under section 6, the agencies and
			 authorities identified in section 5, with respect to the covered entities that
			 are subject to the respective enforcement authority of such agencies and
			 authorities, shall prescribe regulations to implement this Act.</text>
			</subsection><subsection id="HD1C38EC97C5D4817A5D585C8B6B2C413"><enum>(b)</enum><header>Coordination</header><text>Each
			 agency and authority required to prescribe regulations under subsection (a)
			 shall consult and coordinate with each other agency and authority identified in
			 section 5 so that, to the extent possible, the regulations prescribed by each
			 agency and authority are consistent and comparable.</text>
			</subsection><subsection id="H8D499C53746649F99341E0AEF064C7C3"><enum>(c)</enum><header>Method of
			 providing notice to consumers</header><text>The regulations required under
			 subsection (a) shall—</text>
				<paragraph id="HDBCD7F6FB19742A1BAEF2098BC78D500"><enum>(1)</enum><text>prescribe the
			 methods by which a covered entity shall notify a consumer of a breach of data
			 security under section 3; and</text>
				</paragraph><paragraph id="HC164845F917243029F86CCE865AA6629"><enum>(2)</enum><text>allow a covered
			 entity to provide such notice by—</text>
					<subparagraph id="H396C29259F3C42D5BF66B4CC61CEFC3B"><enum>(A)</enum><text>written,
			 telephonic, or e-mail notification; or</text>
					</subparagraph><subparagraph id="H5994A2D14DC540DA9174CF1559B488F7"><enum>(B)</enum><text>substitute
			 notification, if providing written, telephonic, or e-mail notification is not
			 feasible due to—</text>
						<clause id="H02F1335C5B32487FA75FE7351316723F"><enum>(i)</enum><text>lack
			 of sufficient contact information for the consumers that must be notified;
			 or</text>
						</clause><clause id="H0EB3E82483F94A8DAEA03901F2AB0000"><enum>(ii)</enum><text>excessive cost to
			 the covered entity.</text>
						</clause></subparagraph></paragraph></subsection><subsection id="H5505BB21E4614984B17B44EB5EC21E00"><enum>(d)</enum><header>Content of
			 consumer notice</header><text>The regulations required under subsection (a)
			 shall—</text>
				<paragraph id="H529FB5824EA44CA8A943A55FF6E2E4DA"><enum>(1)</enum><text>prescribe the
			 content that shall be included in a notice of a breach of data security that is
			 required to be provided to consumers under section 3; and</text>
				</paragraph><paragraph id="H45D02D46D71D4D6D8D4423C859E7E1F2"><enum>(2)</enum><text>require such
			 notice to include—</text>
					<subparagraph id="HE22FDC09AC424B178F883662234845EA"><enum>(A)</enum><text>a description of
			 the type of sensitive account information or sensitive personal information
			 involved in the breach of data security;</text>
					</subparagraph><subparagraph id="H23072DA648FD4022AE00AB8026614564"><enum>(B)</enum><text display-inline="yes-display-inline">if known, the date, or a reasonable
			 approximation of the period of time, on or within which the breach of data
			 security occurred;</text>
					</subparagraph><subparagraph id="H59AC86249460491C959963A3C9C306AC"><enum>(C)</enum><text>a general
			 description of the actions taken by the covered entity to restore the security
			 and confidentiality of the sensitive account information or sensitive personal
			 information involved in the breach of data security; and</text>
					</subparagraph><subparagraph id="HCD9BCAAFCED54A05B57D00D76E05E567"><enum>(D)</enum><text display-inline="yes-display-inline">the summary of rights of victims of
			 identity theft prepared by the Commission under section 609(d) of the Fair
			 Credit Reporting Act (<external-xref legal-doc="usc" parsable-cite="usc/15/1681g">15 U.S.C. 1681g</external-xref>), if the breach of data security involves
			 sensitive personal information, including any additional appropriate
			 information on how the consumer may place an initial fraud alert in any file
			 relating to the consumer at a consumer reporting agency under section
			 605A(a)(1) of such Act.</text>
					</subparagraph></paragraph></subsection><subsection id="HA21F9CE4938A4A40BF0012C2B2671FCB"><enum>(e)</enum><header>Timing of
			 notice</header><text>The regulations required under subsection (a) shall
			 establish standards for when a covered entity shall provide any notice required
			 under section 3.</text>
			</subsection><subsection id="HAC1FFFA139B74BDC9337DB93E7006205"><enum>(f)</enum><header>Law enforcement
			 delay</header><text>The regulations required under subsection (a) shall allow a
			 covered entity to delay providing notice of a breach of data security to
			 consumers under section 3 if a law enforcement agency requests such a delay in
			 writing.</text>
			</subsection><subsection id="H0D02547588374F77BBE983CDF8915B32"><enum>(g)</enum><header>Service
			 providers</header><text>The regulations required under subsection (a)
			 shall—</text>
				<paragraph id="HE7D4AC6F56454B57BCDEF308B706C3B6"><enum>(1)</enum><text>require any party
			 that maintains or communicates sensitive account information or sensitive
			 personal information on behalf of a covered entity to provide notice to that
			 covered entity if such party determines that a breach of data security has, or
			 may have, occurred with respect to such information; and</text>
				</paragraph><paragraph id="H56AAC0892DA0490C9F921188ABB6AB00"><enum>(2)</enum><text>ensure that there
			 is only 1 notification responsibility with respect to a breach of data
			 security.</text>
				</paragraph></subsection><subsection id="H793C686F2C094171AE89D005EAD500E5"><enum>(h)</enum><header>Timing of
			 regulations</header><text>The regulations required under subsection (a)
			 shall—</text>
				<paragraph id="H2A7BCA89E74B471A93A89B17B8B24F00"><enum>(1)</enum><text>be issued in final
			 form not later than 6 months after the date of enactment of this Act;
			 and</text>
				</paragraph><paragraph id="H8822499D8EC34C06A5B2DE4F514CDFC"><enum>(2)</enum><text>take effect not
			 later than 6 months after the date on which they are issued in final
			 form.</text>
				</paragraph></subsection></section><section id="H48C864A57D6E4612A5A6C3A333DF5409"><enum>5.</enum><header>Administrative
			 enforcement</header>
			<subsection id="H9C8EE0713D474A0E979487510022FC6C"><enum>(a)</enum><header>In
			 general</header><text>Section 3, and the regulations required under section 4,
			 shall be enforced exclusively under—</text>
				<paragraph id="H24721C49FC544A46952903FEC82563F4"><enum>(1)</enum><text>section 8 of the
			 Federal Deposit Insurance Act (<external-xref legal-doc="usc" parsable-cite="usc/12/1818">12 U.S.C. 1818</external-xref>), in the case of—</text>
					<subparagraph id="H196F95D7CD26439A91F0CEA67682086F"><enum>(A)</enum><text>a national bank, a
			 Federal branch or Federal agency of a foreign bank, or any subsidiary thereof
			 (other than a broker, dealer, person providing insurance, investment company,
			 or investment adviser), by the Office of the Comptroller of the
			 Currency;</text>
					</subparagraph><subparagraph id="HF78A196A6D664FCD885EC3F09C2B8546"><enum>(B)</enum><text>a member bank of
			 the Federal Reserve System (other than a national bank), a branch or agency of
			 a foreign bank (other than a Federal branch, Federal agency, or insured State
			 branch of a foreign bank), a commercial lending company owned or controlled by
			 a foreign bank, an organization operating under section 25 or 25A of the
			 Federal Reserve Act (<external-xref legal-doc="usc" parsable-cite="usc/12/601">12 U.S.C. 601</external-xref>,604), or a bank holding company and its
			 nonbank subsidiary or affiliate (other than a broker, dealer, person providing
			 insurance, investment company, or investment adviser), by the Board of
			 Governors of the Federal Reserve System;</text>
					</subparagraph><subparagraph id="HE57991DE789D41B9BB1900E500AF775E"><enum>(C)</enum><text>a bank, the
			 deposits of which are insured by the Federal Deposit Insurance Corporation
			 (other than a member of the Federal Reserve System), an insured State branch of
			 a foreign bank, or any subsidiary thereof (other than a broker, dealer, person
			 providing insurance, investment company, or investment adviser), by the Board
			 of Directors of the Federal Deposit Insurance Corporation; and</text>
					</subparagraph><subparagraph id="H77A67EE9A3354A61A7CC39D59056557"><enum>(D)</enum><text>a savings
			 association, the deposits of which are insured by the Federal Deposit Insurance
			 Corporation, or any subsidiary thereof (other than a broker, dealer, person
			 providing insurance, investment company, or investment adviser), by the
			 Director of the Office of Thrift Supervision;</text>
					</subparagraph></paragraph><paragraph id="HE246378866E349B6BA96EFBBC66BF2EF"><enum>(2)</enum><text>the Federal Credit
			 Union Act (<external-xref legal-doc="usc" parsable-cite="usc/12/1751">12 U.S.C. 1751 et seq.</external-xref>), by the National Credit Union Administration
			 Board with respect to any federally insured credit union;</text>
				</paragraph><paragraph id="H26DE305912E64FBCAD692B291CB09CE6"><enum>(3)</enum><text>the Securities
			 Exchange Act of 1934 (15 U.S.C.78a et seq.), by the Securities and Exchange
			 Commission with respect to any broker or dealer;</text>
				</paragraph><paragraph id="H9D8F8EA3FADB4683B3AF95AE78FF8EE1"><enum>(4)</enum><text>the Investment
			 Company Act of 1940 (<external-xref legal-doc="usc" parsable-cite="usc/15/80a-1">15 U.S.C. 80a–1 et seq.</external-xref>), by the Securities and Exchange
			 Commission with respect to any investment company;</text>
				</paragraph><paragraph id="HDCA140445F4044E9B6552E4E9FEF30E3"><enum>(5)</enum><text>the Investment
			 Advisers Act of 1940 (<external-xref legal-doc="usc" parsable-cite="usc/15/80b-1">15 U.S.C. 80b–1 et seq.</external-xref>), by the Securities and Exchange
			 Commission with respect to any investment adviser registered with the
			 Securities and Exchange Commission under that Act;</text>
				</paragraph><paragraph id="HDD0EA2B23DB54DF481D928AECD255CEC"><enum>(6)</enum><text>the Commodity
			 Exchange Act (<external-xref legal-doc="usc" parsable-cite="usc/7/1">7 U.S.C. 1 et seq.</external-xref>), by the Commodity Futures Trading Commission
			 with respect to any futures commission merchant, commodity trading advisor,
			 commodity pool operator, or introducing broker;</text>
				</paragraph><paragraph id="HAFCCC912FC7C4ECAA08CB2F02BFC8FB4"><enum>(7)</enum><text>the provisions of
			 title XIII of the Housing and Community Development Act of 1992 (12 U.S.C. 4501
			 et seq.), by the Director of Federal Housing Enterprise Oversight (and any
			 successor to such functional regulatory agency) with respect to the Federal
			 National Mortgage Association, the Federal Home Loan Mortgage Corporation, and
			 any other entity or enterprise (as defined in that title) subject to the
			 jurisdiction of such functional regulatory agency under that title, including
			 any affiliate of any such enterprise;</text>
				</paragraph><paragraph id="H1D9142E8CAC54DD3003245E5CAC20145"><enum>(8)</enum><text>State insurance
			 law, in the case of any person engaged in providing insurance, by the
			 applicable State insurance authority of the State in which the person is
			 domiciled; and</text>
				</paragraph><paragraph id="H55FC5AB60BCE4DC08DB06EB7EA7E3899"><enum>(9)</enum><text>the Federal Trade
			 Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/41">15 U.S.C. 41 et seq.</external-xref>), by the Commission for any other covered
			 entity that is not subject to the jurisdiction of any agency or authority
			 described under paragraphs (1) through (8).</text>
				</paragraph></subsection><subsection id="HDC901FA274574221A8C26B08D5D8E77F"><enum>(b)</enum><header>Extension of
			 Federal Trade Commission enforcement authority</header><text>The authority of
			 the Commission to enforce compliance with section 3, and the regulations
			 required under section 4, under subsection (a)(8) shall—</text>
				<paragraph id="H786B4671B92C42EFBCBB088EDC232E00"><enum>(1)</enum><text>notwithstanding
			 the Federal Aviation Act of 1958 (49 U.S.C. App. 1301 et seq.), include the
			 authority to enforce compliance by air carriers and foreign air carriers;
			 and</text>
				</paragraph><paragraph id="H6EA7E6534D1E400C97A98E024D5059D6"><enum>(2)</enum><text>notwithstanding
			 the Packers and Stockyards Act (<external-xref legal-doc="usc" parsable-cite="usc/7/181">7 U.S.C. 181 et seq.</external-xref>), include the authority to
			 enforce compliance by persons, partnerships, and corporations subject to the
			 provisions of that Act.</text>
				</paragraph></subsection><subsection id="HC95C5D20747A48F9AFB4ADB87D98DF00"><enum>(c)</enum><header>No private right
			 of Action</header>
				<paragraph id="HBBC7EBF63EBB42BABE899D4330369620"><enum>(1)</enum><header>In
			 general</header><text>This Act, and the regulations prescribed under this Act,
			 may not be construed to provide a private right of action, including a class
			 action with respect to any act or practice regulated under this Act.</text>
				</paragraph><paragraph id="H20D1305251CF47E88BE23F163134EB05"><enum>(2)</enum><header>Civil and
			 criminal Actions</header><text>No civil or criminal action relating to any act
			 or practice governed under this Act, or the regulations prescribed under this
			 Act, shall be commenced or maintained in any State court or under State law,
			 including a pendent State claim to an action under Federal law.</text>
				</paragraph></subsection></section><section id="H84C160BCAD724FD1A69729FD37C71C3F"><enum>6.</enum><header>Protection of
			 information at Federal agencies</header>
			<subsection id="H2F18F79BC93A4ABBBBB802D5B568D430"><enum>(a)</enum><header>Data security
			 standards</header><text>Each agency shall implement appropriate standards
			 relating to administrative, technical, and physical safeguards—</text>
				<paragraph id="H0AB5731FDA1F4EB9859EAEAD9DCAE16B"><enum>(1)</enum><text>to insure the
			 security and confidentiality of the sensitive account information and sensitive
			 personal information that is maintained or is being communicated by, or on
			 behalf of, that agency;</text>
				</paragraph><paragraph id="HE9F14CB9DD054EA8BCCED02D93BA13E"><enum>(2)</enum><text>to
			 protect against any anticipated threats or hazards to the security of such
			 information; and</text>
				</paragraph><paragraph id="H95B382CEF7CC4835B2BC5B556099008E"><enum>(3)</enum><text>to protect against
			 misuse of such information, which could result in substantial harm or
			 inconvenience to a consumer.</text>
				</paragraph></subsection><subsection id="H52882AA82C274DA98702E1D958A879C"><enum>(b)</enum><header>Security breach
			 notification standards</header><text>Each agency shall implement appropriate
			 standards providing for notification of consumers when such agency determines
			 that sensitive account information or sensitive personal information that is
			 maintained or is being communicated by, or on behalf of, such agency—</text>
				<paragraph id="HFC3F3E0F948044D0B833F305D520067"><enum>(1)</enum><text>has been acquired
			 without authorization; and</text>
				</paragraph><paragraph id="HBFE633DA85944886005680C626C14246"><enum>(2)</enum><text>is reasonably
			 likely to be misused in a manner causing substantial harm or inconvenience to
			 the consumers to whom the information relates.</text>
				</paragraph></subsection></section><section id="HE3762702B1C34FE1B0EC5B54B3564F9E"><enum>7.</enum><header>Relation to State
			 law</header><text display-inline="no-display-inline">No requirement or
			 prohibition may be imposed under the laws of any State with respect to the
			 responsibilities of any person to—</text>
			<paragraph id="HC07AD9B2991446A68BB3B4F4DBA07E45"><enum>(1)</enum><text>protect the
			 security of information relating to consumers that is maintained or
			 communicated by, or on behalf of, such person;</text>
			</paragraph><paragraph id="H8349D24FC21B43E68063EAB6B916E308"><enum>(2)</enum><text>safeguard
			 information relating to consumers from potential misuse;</text>
			</paragraph><paragraph id="HE61D2130C0E54B03BCA979E6EA65191"><enum>(3)</enum><text>investigate or
			 provide notice of the unauthorized access to information relating to consumers,
			 or the potential misuse of such information for fraudulent, illegal, or other
			 purposes; or</text>
			</paragraph><paragraph id="HBD2F375E94504BEAB7B054EAB7C50505"><enum>(4)</enum><text>mitigate any loss
			 or harm resulting from the unauthorized access or misuse of information
			 relating to consumers.</text>
			</paragraph></section><section id="HA85955F7806E4973BA32F635E4F1FF69"><enum>8.</enum><header>Delayed effective
			 date for certain provisions</header>
			<subsection id="H30DC32627CB147B1BCE3D8D5CD8F5001"><enum>(a)</enum><header>Covered
			 entities</header><text display-inline="yes-display-inline">Sections 3 and 7
			 shall take effect on the later of—</text>
				<paragraph id="H7F100F06B6654A619EFFAB1B4B08D04F"><enum>(1)</enum><text>1
			 year after the date of the enactment of this Act; or</text>
				</paragraph><paragraph id="H94142122A4DD4D55A671D199E211D9F"><enum>(2)</enum><text>the effective date
			 of the final regulations required under section 4.</text>
				</paragraph></subsection><subsection id="HFB8EC299B8BD4951AF2C23E09243A390"><enum>(b)</enum><header>Agencies</header><text>Section
			 6 shall take effect 1 year after the date of enactment of this Act.</text>
			</subsection></section></legis-body>
</bill>


