<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" bill-type="olc" dms-id="H12FCDB060128459A9214F2AF00001969" public-private="public">
<metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>110 HR 936 IH: Prevention of Fraudulent Access to
</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2007-02-08</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
	<form>
		<distribution-code display="yes">I</distribution-code>
		<congress>110th CONGRESS</congress>
		<session>1st Session</session>
		<legis-num>H. R. 936</legis-num>
		<current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber>
		<action>
			<action-date date="20070208">February 8, 2007</action-date>
			<action-desc><sponsor name-id="D000355">Mr. Dingell</sponsor> (for
			 himself, <cosponsor name-id="B000213">Mr. Barton of Texas</cosponsor>,
			 <cosponsor name-id="M000133">Mr. Markey</cosponsor>,
			 <cosponsor name-id="U000031">Mr. Upton</cosponsor>,
			 <cosponsor name-id="R000515">Mr. Rush</cosponsor>, <cosponsor name-id="S000822">Mr. Stearns</cosponsor>, <cosponsor name-id="S001145">Ms.
			 Schakowsky</cosponsor>, <cosponsor name-id="B000657">Mr. Boucher</cosponsor>,
			 <cosponsor name-id="G000309">Mr. Gordon of Tennessee</cosponsor>,
			 <cosponsor name-id="E000215">Ms. Eshoo</cosponsor>,
			 <cosponsor name-id="S001045">Mr. Stupak</cosponsor>,
			 <cosponsor name-id="G000410">Mr. Gene Green of Texas</cosponsor>,
			 <cosponsor name-id="D000197">Ms. DeGette</cosponsor>,
			 <cosponsor name-id="C001036">Mrs. Capps</cosponsor>,
			 <cosponsor name-id="D000482">Mr. Doyle</cosponsor>,
			 <cosponsor name-id="S001153">Ms. Solis</cosponsor>,
			 <cosponsor name-id="G000544">Mr. Gonzalez</cosponsor>,
			 <cosponsor name-id="I000026">Mr. Inslee</cosponsor>,
			 <cosponsor name-id="B001230">Ms. Baldwin</cosponsor>,
			 <cosponsor name-id="H000762">Ms. Hooley</cosponsor>,
			 <cosponsor name-id="M001142">Mr. Matheson</cosponsor>,
			 <cosponsor name-id="B001251">Mr. Butterfield</cosponsor>,
			 <cosponsor name-id="F000440">Mr. Fossella</cosponsor>,
			 <cosponsor name-id="T000459">Mr. Terry</cosponsor>,
			 <cosponsor name-id="B001248">Mr. Burgess</cosponsor>, and
			 <cosponsor name-id="E000179">Mr. Engel</cosponsor>) introduced the following
			 bill; which was referred to the <committee-name committee-id="HIF00">Committee
			 on Energy and Commerce</committee-name></action-desc>
		</action>
		<legis-type>A BILL</legis-type>
		<official-title>To prohibit fraudulent access to telephone
		  records.</official-title>
	</form>
	<legis-body id="HA06AB727D63B46C4AB56726F360039A9" style="OLC">
		<section display-inline="no-display-inline" id="HA9F7E23E61374F0B8342CDB289189023" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the
			 <quote><short-title>Prevention of Fraudulent Access to
			 Phone Records Act</short-title></quote>.</text>
		</section><title id="H8317387B81814D3B928D7333D6EFCDE7"><enum>I</enum><header>Federal Trade
			 Commission Provisions</header>
			<section id="H26B6D63756DD4E6AB1B2B55526311B30"><enum>101.</enum><header>Fraudulent
			 access to customer telephone records</header>
				<subsection id="HB849035EDBE14099972F289DC5D6A53"><enum>(a)</enum><header>Prohibition on
			 obtaining customer information by false pretenses</header><text display-inline="yes-display-inline">It shall be unlawful for any person to
			 obtain or attempt to obtain, or cause to be disclosed or attempt to cause to be
			 disclosed to any person, customer proprietary network information relating to
			 any other person by—</text>
					<paragraph id="H361B96D081514CBB81A665D0609B7F5"><enum>(1)</enum><text>making a false,
			 fictitious, or fraudulent statement or representation to an officer, employee,
			 or agent of a telecommunications carrier; or</text>
					</paragraph><paragraph id="H170F2B1E57834A078974CEEC1E561B13"><enum>(2)</enum><text display-inline="yes-display-inline">providing any document or other information
			 to an officer, employee, or agent of a telecommunications carrier that the
			 person knows or should know to be forged, counterfeit, lost, stolen, or
			 fraudulently obtained, or to contain a false, fictitious, or fraudulent
			 statement or representation.</text>
					</paragraph></subsection><subsection commented="no" id="HCA61DE7A1E7841B3B9F16744BDE155E2"><enum>(b)</enum><header>Prohibition on
			 solicitation of a person to obtain customer information under false
			 pretenses</header><text display-inline="yes-display-inline">It shall be
			 unlawful to request a person to obtain from a telecommunications carrier
			 customer proprietary network information relating to any third person, if the
			 person making such a request knew or should have known that the person to whom
			 such a request is made will obtain or attempt to obtain such information in the
			 manner described in subsection (a).</text>
				</subsection><subsection id="H22DFBB9BEBAF4D4C98D6691E652D2329"><enum>(c)</enum><header>Prohibition on
			 sale or other disclosure of customer information obtained under false
			 pretenses</header><text display-inline="yes-display-inline">It shall be
			 unlawful for any person to sell or otherwise disclose to any person customer
			 proprietary network information relating to any other person if the person
			 selling or disclosing obtained such information in the manner described in
			 subsection (a).</text>
				</subsection></section><section commented="no" id="H6434CE95FE264336922C3C0339DDF675"><enum>102.</enum><header>Exemption</header><text display-inline="no-display-inline">No provision of section 101 shall be
			 construed so as to prevent any action by a law enforcement agency, or any
			 officer, employee, or agent of such agency, from obtaining or attempting to
			 obtain customer proprietary network information from a telecommunications
			 carrier in connection with the performance of the official duties of the
			 agency, in accordance with other applicable laws.</text>
			</section><section id="H8D21702C126244D1A26B34B7EA407859"><enum>103.</enum><header>Enforcement by
			 the Federal Trade Commission</header><text display-inline="no-display-inline">A
			 violation of section 101 shall be treated as a violation of a rule defining an
			 unfair or deceptive act or practice prescribed under section 18(a)(1)(B) of the
			 Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/57a">15 U.S.C. 57a(a)(1)(B)</external-xref>). The Federal Trade
			 Commission shall enforce this title in the same manner, by the same means, and
			 with the same jurisdiction as though all applicable terms and provisions of the
			 Federal Trade Commission Act were incorporated into and made a part of this
			 title.</text>
			</section><section id="HB1939CAC756B4456BDFAD099E9B334F"><enum>104.</enum><header>Definitions</header><text display-inline="no-display-inline">As used in this title—</text>
				<paragraph id="HC63FD628CB6C40F1A50400A819CF6085"><enum>(1)</enum><text>the term
			 <term>customer proprietary network information</term> has the meaning given
			 such term in section 222(j)(1) of the Communications Act of 1934 (47 U.S.C.
			 222(j)(1)) (as redesignated by section 203 of this Act);</text>
				</paragraph><paragraph id="H6BEED2CAEF494DE996FE6C1D7C264BA8"><enum>(2)</enum><text display-inline="yes-display-inline">the term <term>telecommunications
			 carrier</term>—</text>
					<subparagraph id="H850899F4A4D14F59AB2C063BE5B879A"><enum>(A)</enum><text>has the meaning
			 given such term in section 3(44) of the Communications Act of 1934 (47 U.S.C.
			 153(44)); and</text>
					</subparagraph><subparagraph id="H36AF154F71764B0B8292CC9DC2D23C5"><enum>(B)</enum><text display-inline="yes-display-inline">includes any provider of real-time Internet
			 protocol-enabled voice communications; and</text>
					</subparagraph></paragraph><paragraph id="H9D9EAE8AFF2B4513BC00B383268195CF"><enum>(3)</enum><text display-inline="yes-display-inline">the term <term>real-time Internet
			 protocol-enabled voice communications</term> means any service that is treated
			 by the Federal Communications Commission as a telecommunications service
			 provided by a telecommunications carrier for purposes of section 222 of the
			 Communications Act of 1934 (<external-xref legal-doc="usc" parsable-cite="usc/47/222">47 U.S.C. 222</external-xref>) under regulations promulgated
			 pursuant to subsection (h) of such section.</text>
				</paragraph></section></title><title id="H9A2657FA12EF471AAE14B0002CE356F2"><enum>II</enum><header>Federal
			 Communications Commission Provisions</header>
			<section id="HEAA5E3BBCD8D41AFBDA3BDEB2CE686E8"><enum>201.</enum><header>Findings</header><text display-inline="no-display-inline">The Congress finds the following:</text>
				<paragraph id="H0DD7C6389ED748A6BAA046C643B993DE"><enum>(1)</enum><text display-inline="yes-display-inline">As our Nation’s communications networks
			 become more ubiquitous and increasingly sophisticated, more individuals and
			 industries will be using such networks in greater amounts to communicate and
			 conduct commercial transactions.</text>
				</paragraph><paragraph id="H40062900D55145A49300C753C2DCE91"><enum>(2)</enum><text>The ease of
			 gathering and compiling sensitive personal information as a result of such
			 communications is becoming more efficient and commonplace due to advances in
			 digital technology and the widespread use of the Internet.</text>
				</paragraph><paragraph id="H51DB8DDDEC8F4BB8A261E25BDD295050"><enum>(3)</enum><text>Ensuring the
			 privacy of sensitive individual telephone calling records, both wireline and
			 wireless, is of utmost importance. The information gathered and retained by
			 communications providers can convey details about intimate aspects of an
			 individual’s life, including who they call, when they call, the duration of
			 such calls, the frequency of their communications, information about their
			 purchases, informational inquiries, political or religious interests, or other
			 affiliations.</text>
				</paragraph><paragraph id="H0ABFCC5A704145D0899432FDC0622942"><enum>(4)</enum><text>Disclosure of
			 personal telephone records can also lead to harassment, intimidation, physical
			 harm, and identity theft.</text>
				</paragraph><paragraph id="HE23AAA58AE6D47239DD711DAD8F33EA"><enum>(5)</enum><text>The government has
			 a compelling interest in protecting sensitive personal information contained in
			 customer telephone records and ensuring that commercial interests adequately
			 protect such records in order to preserve individual freedom, safeguard
			 personal privacy, and ensure trust in electronic commerce.</text>
				</paragraph><paragraph id="HECABCB5F0B0E49FEB041B14DDB58E935"><enum>(6)</enum><text>Because customers
			 have a proprietary interest in their sensitive personal information, customers
			 should have some control over the use and disclosure of telephone calling
			 records.</text>
				</paragraph><paragraph id="H73B4135B58D84CFC83AB9600CD24BC9"><enum>(7)</enum><text>A
			 telecommunications carrier may use aggregated data it has obtained from its
			 customer databases to improve services, solicit new business, or market
			 additional services to its customers.</text>
				</paragraph><paragraph id="H586F2FF9A73149BCA1C7303F88D3D82B"><enum>(8)</enum><text>A
			 telecommunications carrier may communicate to all consumers in order to broadly
			 solicit new business, and may also target specific communications to its own
			 existing customers, without use or disclosure of detailed customer calling
			 records and thus without the threat of compromising customer privacy.</text>
				</paragraph><paragraph id="H5E49BB38B1724E5B836267472C284082"><enum>(9)</enum><text>The risk of
			 compromising customer privacy is raised and increased whenever additional
			 entities or persons are permitted use of, or access to, or receive disclosure
			 of, customer calling records beyond the carrier with which the customer has an
			 established business relationship.</text>
				</paragraph><paragraph id="H762B21BE8E2042C0A27C4050A348E300"><enum>(10)</enum><text>A
			 telecommunications carrier which obtains or possesses a customer’s calling
			 records has a duty to safeguard the confidentiality of such customer's personal
			 information. Detailed customer calling records describing the customer’s use of
			 telecommunications services should not be publicly available or offered for
			 commercial sale.</text>
				</paragraph></section><section id="H79B6D7D3C43540FA9E46B751FAD618A9"><enum>202.</enum><header>Expanded
			 protection for detailed customer records</header>
				<subsection id="H2CE3EEE6F96249779BAF3BC9F2140099"><enum>(a)</enum><header>Confidentiality
			 of Customer Information</header><text display-inline="yes-display-inline">Paragraph (1) of section 222(c) of the
			 Communications Act of 1934 (<external-xref legal-doc="usc" parsable-cite="usc/47/222">47 U.S.C. 222(c)(1)</external-xref>) is amended to read as
			 follows:</text>
					<quoted-block display-inline="no-display-inline" id="H4F52560CD31547019EDCC23437DC2250" style="OLC">
						<paragraph id="H8E0C19A9A7CE42B5A5E25CD5DD1FF7A7"><enum>(1)</enum><header>Privacy
				requirements for telecommunications carriers</header>
							<subparagraph id="H87D24D5C5DF24A7F83F503361501D897"><enum>(A)</enum><header>In
				general</header><text display-inline="yes-display-inline">Except as required by
				law or as permitted under the following provisions of this paragraph, a
				telecommunications carrier that receives or obtains individually identifiable
				customer proprietary network information (including detailed customer telephone
				records) by virtue of its provision of a telecommunications service shall only
				use, disclose, or permit access to such information or records in the provision
				by such carrier of—</text>
								<clause id="HA8A8D55981BB4931A31339CEB0097427"><enum>(i)</enum><text>the
				telecommunications service from which such information is derived; or</text>
								</clause><clause id="H089269E7B2C94F5DB3A5CC35008E0917"><enum>(ii)</enum><text>services
				necessary to, or used in, the provision of such telecommunications service,
				including the publishing of directories.</text>
								</clause></subparagraph><subparagraph id="H2684243618B0497BA787C0E68F36069B"><enum>(B)</enum><header>Requirements for
				disclosure of detailed information</header><text display-inline="yes-display-inline">A telecommunications carrier may only use
				detailed customer telephone records through, or disclose such records to, or
				permit access to such records by, a joint venture partner, independent
				contractor, or any other third party (other than an affiliate) if the customer
				has given express prior authorization for that use, disclosure, or access, and
				that authorization has not been withdrawn.</text>
							</subparagraph><subparagraph id="H49C4E82C5CD14A51B0771C4B51E24D02"><enum>(C)</enum><header>Requirements for
				affiliate use of both general and detailed information</header><text display-inline="yes-display-inline">A telecommunications carrier may not,
				except with the approval of a customer, use individually identifiable customer
				proprietary network information (including detailed customer telephone records)
				through, or disclose such information or records to, or permit access to such
				information or records by, an affiliate of such carrier in the provision by
				such affiliate of the services described in clause (i) or (ii) of
				<internal-xref idref="H87D24D5C5DF24A7F83F503361501D897" legis-path="(1)(A)">subparagraph (A)</internal-xref>.</text>
							</subparagraph><subparagraph id="H37C89F9F848140559C40F15BE6F1F77"><enum>(D)</enum><header>Requirements for
				partner and contractor use of general information</header><text display-inline="yes-display-inline">A telecommunications carrier may not,
				except with the approval of the customer, use individually identifiable
				customer proprietary network information (other than detailed customer
				telephone records) through, or disclose such information to, or permit access
				to such information by, a joint venture partner or independent contractor in
				the provision by such partner or contractor of the services described in clause
				(i) or (ii) of
				<internal-xref idref="H87D24D5C5DF24A7F83F503361501D897" legis-path="(1)(A)">subparagraph (A).</internal-xref></text>
							</subparagraph><subparagraph id="HD8EA2E14CCA8427B9C42B3196F070079"><enum>(E)</enum><header>Access to
				wireless telephone numbers</header><text display-inline="yes-display-inline">A
				telecommunications carrier may not, except with prior express authorization
				from the customer, disclose the wireless telephone number of any customer or
				permit access to the wireless telephone number of any
				customer.</text>
							</subparagraph></paragraph><after-quoted-block>.</after-quoted-block></quoted-block>
				</subsection><subsection id="H87F613104A3C426BB82C6C3586A1294D"><enum>(b)</enum><header>Disclosure of
			 detailed information on request by customer</header><text>Section 222(c)(2) of
			 such Act is amended by inserting <quote>(including a detailed customer
			 telephone record)</quote> after <quote>customer proprietary network
			 information</quote>.</text>
				</subsection><subsection id="HA65C34C092804D7984F7AE63E51D313"><enum>(c)</enum><header>Aggregate
			 data</header><text>Section 222(c)(3) of such Act is amended by adding at the
			 end the following new sentence: <quote>Aggregation of data that is conducted by
			 a third party may be treated for purposes of this subsection as aggregation by
			 the carrier if such aggregation is conducted in a secure manner under the
			 control or supervision of the carrier.</quote>.</text>
				</subsection><subsection id="HB4812A32F3F94B3386EC672915C164F8"><enum>(d)</enum><header>Prohibition of
			 sale of general or detailed information</header><text>Section 222(c) of such
			 Act is further amended by adding at the end the following new paragraph:</text>
					<quoted-block display-inline="no-display-inline" id="H49DFA593CFB2498C96CFBC75B44DE9E5" style="OLC">
						<paragraph id="H8A747CB0253C4B0BA6D2CED8A3A317DB"><enum>(4)</enum><header>Prohibition of
				sale of general or detailed information</header><text display-inline="yes-display-inline">Except for the purposes for which use,
				disclosure, or access is permitted under subsection (d), it shall be unlawful
				for any person to sell, rent, lease, or otherwise make available for
				remuneration or other consideration the customer proprietary network
				information (including the detailed customer telephone records) of any
				customer.</text>
						</paragraph><after-quoted-block>.</after-quoted-block></quoted-block>
				</subsection><subsection id="HFBF422BF00B14CF1866FB9B380556D3D"><enum>(e)</enum><header>Exceptions to
			 limitations on disclosures of detailed information</header><text display-inline="yes-display-inline">Section
			 222(d) of such Act is amended—</text>
					<paragraph id="H00D08019E54F4795BBBEEC913247A8B4"><enum>(1)</enum><text>by striking
			 <quote>its agents</quote> and inserting <quote>its joint venture partners,
			 contractors, or agents</quote>; and</text>
					</paragraph><paragraph id="H51BD868486294A22A0233F75E2F5B2F2"><enum>(2)</enum><text display-inline="yes-display-inline">in paragraph (1), by inserting after
			 <quote>telecommunications services</quote> the following: <quote>, or provide
			 customer service with respect to telecommunications services to which the
			 customer subscribes</quote>.</text>
					</paragraph></subsection></section><section id="H95C0071AD54E4758ADE4EF6C31282762"><enum>203.</enum><header>Prevention by
			 telecommunications carriers of fraudulent access to phone records</header><text display-inline="no-display-inline">Section 222 of the Communications Act of
			 1934 (<external-xref legal-doc="usc" parsable-cite="usc/47/222">47 U.S.C. 222</external-xref>) is further amended—</text>
				<paragraph id="HC0EA6C2D3CB941CCA89CC9146648C0A1"><enum>(1)</enum><text>by redesignating
			 subsection (h) as subsection (j);</text>
				</paragraph><paragraph id="HE62AF654608049C49696D2215161089F"><enum>(2)</enum><text>by inserting after
			 subsection (g) the following new subsections:</text>
					<quoted-block display-inline="no-display-inline" id="H059DA7A99F0E49E7B544FDAB2100628F" style="OLC">
						<subsection id="H097F118E49784785A47FACE4ED75C7C9"><enum>(h)</enum><header>Prevention of
				fraudulent access to phone records</header>
							<paragraph id="H83B2476B204C4F6A9271C8357200E187"><enum>(1)</enum><header>Regulations</header><text display-inline="yes-display-inline">Within 180 days after the date of enactment
				of the <short-title>Prevention of Fraudulent Access to
				Phone Records Act</short-title>, the Commission shall prescribe regulations
				adopting more stringent security standards for customer proprietary network
				information (including detailed customer telephone records) to detect and
				prevent violations of this section. The Commission—</text>
								<subparagraph id="HDE47E4BDE9B44BD7B887B060EE608591"><enum>(A)</enum><text>shall prescribe
				regulations—</text>
									<clause id="H8DF11E9C4895406491F11656A01FE661"><enum>(i)</enum><text display-inline="yes-display-inline">to require timely notice (written or
				electronic) to each customer upon breach of the regulations under this section
				with respect to customer proprietary network information relating to that
				customer;</text>
									</clause><clause id="HCC63CA0AEEE64AFAB16E1691EB25328F"><enum>(ii)</enum><text>to require timely
				notice to the Commission upon breach of the regulations under this section with
				respect to customer proprietary network information relating to any
				customer;</text>
									</clause><clause id="H4B80F5908D394D1B857B7FD241A9AA7"><enum>(iii)</enum><text display-inline="yes-display-inline">to require periodic audits by the
				Commission of telecommunication carriers and their agents to determine
				compliance with this section;</text>
									</clause><clause display-inline="no-display-inline" id="HA9C3B175B88D49818F6DEF20424DE1C"><enum>(iv)</enum><text>to require
				telecommunications carriers and their agents to maintain records—</text>
										<subclause id="HCA2B9D496D224D53BF1FBD534D88A06F"><enum>(I)</enum><text>of each time
				customer proprietary network information is requested or accessed by, or
				disclosed to, a person purporting to be the customer or to be acting at the
				request or direction of the customer; and</text>
										</subclause><subclause id="HC38E88D3DEE5441B98C5E7CC69895CE6"><enum>(II)</enum><text>if such access or
				disclosure was granted to such a person, of how the person’s identity or
				authority was verified;</text>
										</subclause></clause><clause id="HA46514FE68484AF0AAB8E6C0945F4D53"><enum>(v)</enum><text display-inline="yes-display-inline">to require telecommunications carriers to
				establish a security policy that includes appropriate standards relating to
				administrative, technical, and physical safeguards to ensure the security and
				confidentiality of customer proprietary network information;</text>
									</clause><clause id="H9C5FAF298E7F4C3BB22BD5BBBE8F189"><enum>(vi)</enum><text display-inline="yes-display-inline">to prohibit any telecommunications carrier
				from obtaining or attempting to obtain, or causing to be disclosed or
				attempting to cause to be disclosed to that carrier or its agent or employee,
				customer proprietary network information relating to any customer of another
				carrier—</text>
										<subclause id="HCCBC3FE4DC1B4576BD4527542B64121D"><enum>(I)</enum><text>by using a false,
				fictitious, or fraudulent statement or representation to an officer, employee,
				or agent of another telecommunications carrier; or</text>
										</subclause><subclause id="HF314E005FFA24E80B95E5805D7871FD3"><enum>(II)</enum><text>by making a
				false, fictitious, or fraudulent statement or representation to a customer of
				another telecommunications carrier; and</text>
										</subclause></clause><clause commented="no" id="H512A12328A4E4AABAE22C96710027D1D"><enum>(vii)</enum><text display-inline="yes-display-inline">only for the purposes of this section, to
				treat as a telecommunications service provided by a telecommunications carrier
				any real-time Internet protocol-enabled voice communications offered by any
				person to the public, or such classes of users as to be effectively available
				to the public, that allows a user to originate traffic to, or terminate traffic
				from, the public switched telephone network; and</text>
									</clause></subparagraph><subparagraph id="HA71774F2E7CD4F54A42C48DC6E686248"><enum>(B)</enum><text>shall consider
				prescribing regulations—</text>
									<clause id="H6A7C30D752B14546A41B1248F21B1E96"><enum>(i)</enum><text>to
				require telecommunications carriers to institute customer-specific identifiers
				in order to access customer proprietary network information;</text>
									</clause><clause id="HD9B34E248DF64351A1C0C85D45D04768"><enum>(ii)</enum><text display-inline="yes-display-inline">to require encryption of customer
				proprietary network information data or other safeguards to better secure such
				data; and</text>
									</clause><clause id="H6E33EE1FC7E94032B2FCCE81252E4739"><enum>(iii)</enum><text display-inline="yes-display-inline">to require deletion of customer proprietary
				network information data after a reasonable period of time if such data is no
				longer necessary for the purpose for which it was collected or for the purpose
				of an exception contained in section (d), and there are no pending requests for
				access to such information.</text>
									</clause></subparagraph></paragraph><paragraph id="HFDF8C34A3764491690787898F1F82FB6"><enum>(2)</enum><header>Reports</header>
								<subparagraph id="H0B2171602C4948FDB84F1708F4A3175B"><enum>(A)</enum><header>Assessment and
				recommendations</header><text display-inline="yes-display-inline">Within 12
				months after the date on which the Commission’s regulations under
				<internal-xref idref="H83B2476B204C4F6A9271C8357200E187" legis-path="(h)(1)">paragraph (1)</internal-xref> are prescribed, and again not
				later than 3 years later, the Commission shall submit to the Committee on
				Energy and Commerce of the House of Representatives and the Committee on
				Commerce, Science, and Transportation of the Senate a report containing—</text>
									<clause id="HBBF6DB22ADE64027BB4493E9B7E166AD"><enum>(i)</enum><text>an
				assessment of the efficacy and adequacy of the regulations and remedies
				provided in accordance with this subsection in protecting customer proprietary
				network information;</text>
									</clause><clause id="H67B10983D56248E798BD3EE900BB3D"><enum>(ii)</enum><text display-inline="yes-display-inline">an assessment of the efficacy and adequacy
				of telecommunications carriers' safeguards to secure such data, security plans,
				and notification procedures; and</text>
									</clause><clause id="HF00DF27F9288415A81EE00C07C802E95"><enum>(iii)</enum><text display-inline="yes-display-inline">any recommendations for additional
				legislative or regulatory action to address threats to the privacy of customer
				information.</text>
									</clause></subparagraph><subparagraph id="H10EAB52C650E49569D19C100997B32D"><enum>(B)</enum><header>Annual
				Report</header><text>The Federal Communications Commission shall submit to
				Congress an annual report containing—</text>
									<clause id="HF43E56914D94410D8048D05D00C49453"><enum>(i)</enum><text>the number and
				disposition of all enforcement actions taken pursuant to this subsection;
				and</text>
									</clause><clause id="H7DFAA043E3754E5BAED1F2443E6C2809"><enum>(ii)</enum><text display-inline="yes-display-inline">the number and type of notifications
				received under
				<internal-xref idref="HCC63CA0AEEE64AFAB16E1691EB25328F" legis-path="(h)(1)(A)(ii)">paragraph (1)(A)(ii)</internal-xref> and the
				methodology, including the basis for the selection of carriers to be audited,
				and the results of each audit conducted under
				<internal-xref idref="H4B80F5908D394D1B857B7FD241A9AA7" legis-path="(h)(1)(A)(iii)">paragraph (1)(A)(iii)</internal-xref>.</text>
									</clause></subparagraph></paragraph><paragraph id="HC8791C57B8854F9EACD645A8CF3EB296"><enum>(3)</enum><header>Dual regulation
				prohibited</header><text display-inline="yes-display-inline">Any person that is
				treated as a telecommunications carrier providing a telecommunications service
				with respect to the offering of real-time Internet protocol-enabled voice
				communications by the regulations prescribed under
				<internal-xref idref="H512A12328A4E4AABAE22C96710027D1D" legis-path="(h)(1)(A)(vii)">paragraph (1)(A)(vii)</internal-xref> shall not be
				subject to the provisions of section 631 with respect to the offering of such
				communications.</text>
							</paragraph></subsection><subsection display-inline="no-display-inline" id="H0D8E58F8D08F4A2380BF7793ADB5B349"><enum>(i)</enum><header>Forfeiture
				penalties</header>
							<paragraph id="H42690B06A17F422EBC55B8EFAB82035"><enum>(1)</enum><header>Increased
				penalties</header><text>In any case in which the violator is determined by the
				Commission under section 503(b)(1) to have violated this section or the
				regulations thereunder, section 503(b)(2)(B) shall be applied—</text>
								<subparagraph id="HF593D494A760441FA1C0BBAB87A9CB8F"><enum>(A)</enum><text>by substituting
				<quote>$300,000</quote> for <quote>$100,000</quote>; and</text>
								</subparagraph><subparagraph id="H775D52F803B44ADFB99703348FD856BC"><enum>(B)</enum><text>by substituting
				<quote>$3,000,000</quote> for <quote>$1,000,000</quote>.</text>
								</subparagraph></paragraph><paragraph display-inline="no-display-inline" id="HC6BB40BE23EB40E99FECA1E9A15C782"><enum>(2)</enum><header>No first
				warnings</header><text>Paragraph (5) of section 503(b) shall not apply to the
				determination of forfeiture liability under such section with respect to a
				violation of this section or the regulations thereunder by any
				telecommunications carrier or any agent of such a
				carrier.</text>
							</paragraph></subsection><after-quoted-block>;
				and</after-quoted-block></quoted-block>
				</paragraph><paragraph id="H8E1F4859DD034403BF058C51E9346845"><enum>(3)</enum><text>in subsection (g),
			 by striking <quote>subsection (i)(3)(A)</quote> and inserting <quote>subsection
			 (j)(3)(A)</quote>.</text>
				</paragraph></section><section id="HAAB65E81AA3547C389ADD200D28F2DB3"><enum>204.</enum><header>Definitions</header><text display-inline="no-display-inline">Subsection (j) of section 222 of the
			 Communications Act of 1934 (<external-xref legal-doc="usc" parsable-cite="usc/47/222">47 U.S.C. 222(j)</external-xref>), as redesignated by section
			 203(1) of this Act, is amended by adding at the end the following new
			 paragraphs:</text>
				<quoted-block display-inline="no-display-inline" id="HBCE6FD19731F41D9A0508D3F3775882C" style="OLC">
					<paragraph id="H03C89C57E0BD48A2A6006F3F011C45D7"><enum>(8)</enum><header>Detailed
				customer telephone record</header><text display-inline="yes-display-inline">The
				term <term>detailed customer telephone record</term> means customer proprietary
				network information that contains the specific and detailed destinations,
				locations, duration, time, and date of telecommunications to or from a
				customer, as typically contained in the bills for such service. Such term does
				not mean aggregate data or subscriber list information.</text>
					</paragraph><paragraph id="HEF495C0F123A44E2BE8C1610AB8FB28B"><enum>(9)</enum><header>Wireless
				telephone number</header><text>The term <term>wireless telephone number</term>
				means the telephone number of a subscriber to a commercial mobile
				service.</text>
					</paragraph><after-quoted-block>.</after-quoted-block></quoted-block>
			</section></title></legis-body>
</bill>


