<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" bill-type="olc" dms-id="HD765039C94AC4259834C41A7E4E4B25" public-private="public">
<metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>110 HR 958 IH: Data Accountability and Trust
</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2007-02-08</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
	<form>
		<distribution-code display="yes">I</distribution-code>
		<congress>110th CONGRESS</congress>
		<session>1st Session</session>
		<legis-num>H. R. 958</legis-num>
		<current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber>
		<action>
			<action-date date="20070208">February 8, 2007</action-date>
			<action-desc><sponsor name-id="R000515">Mr. Rush</sponsor> (for
			 himself, <cosponsor name-id="S000822">Mr. Stearns</cosponsor>,
			 <cosponsor name-id="S001145">Ms. Schakowsky</cosponsor>,
			 <cosponsor name-id="D000355">Mr. Dingell</cosponsor>,
			 <cosponsor name-id="B000213">Mr. Barton of Texas</cosponsor>,
			 <cosponsor name-id="M000133">Mr. Markey</cosponsor>,
			 <cosponsor name-id="G000309">Mr. Gordon of Tennessee</cosponsor>,
			 <cosponsor name-id="E000215">Ms. Eshoo</cosponsor>,
			 <cosponsor name-id="S001045">Mr. Stupak</cosponsor>,
			 <cosponsor name-id="G000410">Mr. Gene Green of Texas</cosponsor>,
			 <cosponsor name-id="D000197">Ms. DeGette</cosponsor>,
			 <cosponsor name-id="C001036">Mrs. Capps</cosponsor>,
			 <cosponsor name-id="D000482">Mr. Doyle</cosponsor>,
			 <cosponsor name-id="S001153">Ms. Solis</cosponsor>,
			 <cosponsor name-id="G000544">Mr. Gonzalez</cosponsor>,
			 <cosponsor name-id="I000026">Mr. Inslee</cosponsor>,
			 <cosponsor name-id="B001230">Ms. Baldwin</cosponsor>,
			 <cosponsor name-id="H000762">Ms. Hooley</cosponsor>,
			 <cosponsor name-id="B001251">Mr. Butterfield</cosponsor>,
			 <cosponsor name-id="H000323">Mr. Hastert</cosponsor>,
			 <cosponsor name-id="B001228">Mrs. Bono</cosponsor>,
			 <cosponsor name-id="T000459">Mr. Terry</cosponsor>,
			 <cosponsor name-id="B001248">Mr. Burgess</cosponsor>, and
			 <cosponsor name-id="E000179">Mr. Engel</cosponsor>) introduced the following
			 bill; which was referred to the <committee-name committee-id="HIF00">Committee
			 on Energy and Commerce</committee-name></action-desc>
		</action>
		<legis-type>A BILL</legis-type>
		<official-title>To protect consumers by requiring reasonable security
		  policies and procedures to protect computerized data containing personal
		  information, and to provide for nationwide notice in the event of a security
		  breach.</official-title>
	</form>
	<legis-body id="HAB5E4E3A798E4C4E89CCB7B305B0E0F1" style="OLC">
		<section id="H3F153A3CDB834C5E9CB0768D87F7E16B" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the
			 <quote><short-title>Data Accountability and Trust
			 Act</short-title></quote>.</text>
		</section><section id="H78F0AB1C3BE3496ABFC2683F1EF32851"><enum>2.</enum><header>Requirements for
			 information security</header>
			<subsection id="H5D5EC07E5B834EEA832FB9FFA4478317"><enum>(a)</enum><header>General security
			 policies and procedures</header>
				<paragraph id="HEEA2FEF5BCA34654997780432FFBCD75"><enum>(1)</enum><header>Regulations</header><text>Not
			 later than 1 year after the date of enactment of this Act, the Commission shall
			 promulgate regulations under <external-xref legal-doc="usc" parsable-cite="usc/5/553">section 553</external-xref> of title 5, United States Code, to
			 require each person engaged in interstate commerce that owns or possesses data
			 in electronic form containing personal information, or contracts to have any
			 third party entity maintain such data for such person, to establish and
			 implement policies and procedures regarding information security practices for
			 the treatment and protection of personal informtion taking into
			 consideration—</text>
					<subparagraph id="HF1F0236AF3D04BE0AC651D9432A741C6"><enum>(A)</enum><text>the size of, and
			 the nature, scope, and complexity of the activities engaged in by, such
			 person;</text>
					</subparagraph><subparagraph id="H2796DF5331D1404D996B798ED1F304E9"><enum>(B)</enum><text>the current state
			 of the art in administrative, technical, and physical safeguards for protecting
			 such information; and</text>
					</subparagraph><subparagraph id="H563D167C7A2748B2B5C91B9C29F48469"><enum>(C)</enum><text>the cost of
			 implementing such safeguards.</text>
					</subparagraph></paragraph><paragraph id="HB61E52DC6AD04CE49E55E851DE2553D4"><enum>(2)</enum><header>Requirements</header><text>Such
			 regulations shall require the policies and procedures to include the
			 following:</text>
					<subparagraph commented="no" id="HCC3319F78E764836B56F51E26781F37D"><enum>(A)</enum><text display-inline="yes-display-inline">A security policy with respect to the
			 collection, use, sale, other dissemination, and maintenance of such personal
			 information.</text>
					</subparagraph><subparagraph id="H0FA149D8679D4F4FBB9FEB4409387CAD"><enum>(B)</enum><text display-inline="yes-display-inline">The identification of an officer or other
			 individual as the point of contact with responsibility for the management of
			 information security.</text>
					</subparagraph><subparagraph commented="no" id="H304268011D8645ACAE81DC6251C8874"><enum>(C)</enum><text display-inline="yes-display-inline">A process for identifying and assessing any
			 reasonably foreseeable vulnerabilities in the system maintained by such person
			 that contains such electronic data, which shall include regular monitoring for
			 a breach of security of such system.</text>
					</subparagraph><subparagraph commented="no" id="H553A1B4CC33B44F0AC19FF009B331575"><enum>(D)</enum><text>A process for
			 taking preventive and corrective action to mitigate against any vulnerabilities
			 identified in the process required by subparagraph (C), which may include
			 implementing any changes to security practices and the architecture,
			 installation, or implementation of network or operating software.</text>
					</subparagraph><subparagraph id="H842B7F10F2BF48D4B0B3D4385E70733B"><enum>(E)</enum><text>A process for
			 disposing of obsolete data in electronic form containing personal information
			 by shredding, permanently erasing, or otherwise modifying the personal
			 information contained in such data to make such personal information
			 permanently unreadable or undecipherable.</text>
					</subparagraph></paragraph><paragraph commented="no" id="H0164A71424E6453EA96DCC825EA3AE6C"><enum>(3)</enum><header>Treatment of
			 entities governed by other law</header><text display-inline="yes-display-inline">In promulgating the regulations under this
			 subsection, the Commission may determine to be in compliance with this
			 subsection any person who is required under any other Federal law to maintain
			 standards and safeguards for information security and protection of personal
			 information that provide equal or greater protection than those required under
			 this subsection.</text>
				</paragraph></subsection><subsection commented="no" id="H135FED1CDE774F8CA1D1BDA478C60534"><enum>(b)</enum><header>Destruction of
			 obsolete paper records containing personal information</header>
				<paragraph commented="no" id="H96915AC9F1384425A6425C2B7578DC23"><enum>(1)</enum><header>Study</header><text>Not
			 later than 1 year after the date of enactment of this Act, the Commission shall
			 conduct a study on the practicality of requiring a standard method or methods
			 for the destruction of obsolete paper documents and other non-electronic data
			 containing personal information by persons engaged in interstate commerce who
			 own or possess such paper documents and non-electronic data. The study shall
			 consider the cost, benefit, feasibility, and effect of a requirement of
			 shredding or other permanent destruction of such paper documents and
			 non-electronic data.</text>
				</paragraph><paragraph commented="no" id="H73F27C22B3914FF686A197B5FA928BFA"><enum>(2)</enum><header>Regulations</header><text>The
			 Commission may promulgate regulations under <external-xref legal-doc="usc" parsable-cite="usc/5/553">section 553</external-xref> of title 5, United
			 States Code, requiring a standard method or methods for the destruction of
			 obsolete paper documents and other non-electronic data containing personal
			 information by persons engaged in interstate commerce who own or possess such
			 paper documents and non-electronic data if the Commission finds that—</text>
					<subparagraph commented="no" id="H693992B61B6F4491963BE75B74CFEE19"><enum>(A)</enum><text>the improper
			 disposal of obsolete paper documents and other non-electronic data creates a
			 reasonable risk of identity theft, fraud, or other unlawful conduct;</text>
					</subparagraph><subparagraph commented="no" id="HE94EB2554913463FA634AB02935575DD"><enum>(B)</enum><text>such a requirement
			 would be effective in preventing identity theft, fraud, or other unlawful
			 conduct;</text>
					</subparagraph><subparagraph commented="no" id="HFB9737D7ACD14006904360B877B53DD3"><enum>(C)</enum><text display-inline="yes-display-inline">the benefit in preventing identity theft,
			 fraud, or other unlawful conduct would outweigh the cost to persons subject to
			 such a requirement; and</text>
					</subparagraph><subparagraph commented="no" id="H591630037618490091901730D4B7D01D"><enum>(D)</enum><text>compliance with
			 such a requirement would be practicable.</text>
					</subparagraph><continuation-text commented="no" continuation-text-level="paragraph">In enforcing any such regulations,
			 the Commission may determine to be in compliance with such regulations any
			 person who is required under any other Federal law to dispose of obsolete paper
			 documents and other non-electronic data containing personal information if such
			 other Federal law provides equal or greater protection or personal information
			 than the regulations promulgated under this subsection.</continuation-text></paragraph></subsection><subsection commented="no" id="H4DDE0801473E489F810079C3B103F2E5"><enum>(c)</enum><header>Special
			 requirements for information brokers</header>
				<paragraph commented="no" id="H66BC1BBDB10F4186AD9F7DA3FA7916FE"><enum>(1)</enum><header>Submission of
			 policies to the FTC</header><text display-inline="yes-display-inline">The
			 regulations promulgated under subsection (a) shall require information brokers
			 to submit their security policies to the Commission in conjunction with a
			 notification of a breach of security under section 3 or upon request of the
			 Commission.</text>
				</paragraph><paragraph id="HC751E6273B8E463190FE3CE29684789B"><enum>(2)</enum><header>Post-breach
			 audit</header><text display-inline="yes-display-inline">For any information
			 broker required to provide notification under section 3, the Commission shall
			 conduct an audit of the information security practices of such information
			 broker, or require the information broker to conduct an independent audit of
			 such practices (by an independent auditor who has not audited such information
			 broker’s security practices during the preceding 5 years). The Commission may
			 conduct or require additional audits for a period of 5 years following the
			 breach of security or until the Commission determines that the security
			 practices of the information broker are in compliance with the requirements of
			 this section and are adequate to prevent further breaches of security.</text>
				</paragraph><paragraph commented="no" display-inline="no-display-inline" id="H7313C8A9ECB8483A8B7FFECF97CDE8BC"><enum>(3)</enum><header>Verification of
			 and individual access to personal information</header>
					<subparagraph commented="no" id="H47008BF0BFC6418D80BD9016DE165ED6"><enum>(A)</enum><header>Verification</header><text>Each
			 information broker shall establish reasonable procedures to verify the accuracy
			 of the personal information it collects, assembles, or maintains, and any other
			 information it collects, assembles, or maintains that specifically identifies
			 an individual, other than information which merely identifies an individual’s
			 name or address.</text>
					</subparagraph><subparagraph commented="no" id="H51EA61B527E549D3820022DB13006789"><enum>(B)</enum><header>Consumer access
			 to information</header>
						<clause commented="no" id="H6EBB0D07FC554B528544E300F933003D"><enum>(i)</enum><header>Access</header><text>Each
			 information broker shall—</text>
							<subclause commented="no" id="H625DECB56B4B456D84DE4FA8154F5DA"><enum>(I)</enum><text display-inline="yes-display-inline">provide to each individual whose personal
			 information it maintains, at the individual’s request at least 1 time per year
			 and at no cost to the individual, and after verifying the identity of such
			 individual, a means for the individual to review any personal information
			 regarding such individual maintained by the information broker and any other
			 information maintained by the information broker that specifically identifies
			 such individual, other than information which merely identifies an individual’s
			 name or address; and</text>
							</subclause><subclause commented="no" id="HC5C9A56F9B40493093186167EE9382D0"><enum>(II)</enum><text>place a
			 conspicuous notice on its Internet website (if the information broker maintains
			 such a website) instructing individuals how to request access to the
			 information required to be provided under subclause (I).</text>
							</subclause></clause><clause commented="no" id="H8D4D03153E0749A48B133E99FE749F00"><enum>(ii)</enum><header>Disputed
			 information</header><text display-inline="yes-display-inline">Whenever an
			 individual whose information the information broker maintains makes a written
			 request disputing the accuracy of any such information, the information broker,
			 after verifying the identity of the individual making such request and unless
			 there are reasonable grounds to believe such request is frivolous or
			 irrelevant, shall—</text>
							<subclause commented="no" display-inline="no-display-inline" id="H21DCFCBD90314A33ACECAE88BCAD0034"><enum>(I)</enum><text>correct any
			 inaccuracy; or</text>
							</subclause><subclause commented="no" id="H7AD8707C6A7F4F6B80CAFF659E4317F0"><enum>(II)</enum><item commented="no" display-inline="yes-display-inline" id="HCFCE8FB77AB44068A0F022869483B088"><enum>(aa)</enum><text>in the case of
			 information that is public record information, inform the individual of the
			 source of the information, and, if reasonably available, where a request for
			 correction may be directed; or</text>
								</item><item commented="no" id="HD9E7713138FC4704AC00CF33B31C1E1E" indent="up1"><enum>(bb)</enum><text display-inline="yes-display-inline">in the case of information that is
			 non-public information, note the information that is disputed, including the
			 individual’s statement disputing such information, and take reasonable steps to
			 independently verify such information under the procedures outlined in
			 subparagraph (A) if such information can be independently verified.</text>
								</item></subclause></clause><clause commented="no" id="HCB5E57CE45A143D7A19CE8689BEA3EB"><enum>(iii)</enum><header>Limitations</header><text>An
			 information broker may limit the access to information required under
			 subparagraph (B) in the following circumstances:</text>
							<subclause commented="no" id="H17CF5032571B44E98056B9E9391F2E96"><enum>(I)</enum><text>If access of the
			 individual to the information is limited by law or legally recognized
			 privilege.</text>
							</subclause><subclause commented="no" id="H6ACE9544CCB247C1924E00B84008DC"><enum>(II)</enum><text>If the information
			 is used for a legitimate governmental or fraud prevention purpose that would be
			 compromised by such access.</text>
							</subclause></clause><clause commented="no" id="H7989146DB4974CCA90D2C62C9DF3EFF8"><enum>(iv)</enum><header>Rulemaking</header><text display-inline="yes-display-inline">The Commission shall issue regulations, as
			 necessary, under <external-xref legal-doc="usc" parsable-cite="usc/5/553">section 553</external-xref> of title 5, United States Code, on the application
			 of the limitations in clause (iii).</text>
						</clause></subparagraph><subparagraph commented="no" id="HBA0710BF965F4C9D809C9B15EE09004B"><enum>(C)</enum><header>Treatment of
			 entities governed by other law</header><text display-inline="yes-display-inline">The Commission may promulgate rules (under
			 <external-xref legal-doc="usc" parsable-cite="usc/5/553">section 553</external-xref> of title 5, United States Code) to determine to be in compliance
			 with this paragraph any person who is a consumer reporting agency, as defined
			 in section 603(f) of the Fair Credit Reporting Act, with respect to those
			 products and services that are subject to and in compliance with the
			 requirements of that Act.</text>
					</subparagraph></paragraph><paragraph commented="no" id="HE0A9E317A9DA4B55A903B01175164891"><enum>(4)</enum><header>Requirement of
			 audit log of accessed and transmitted information</header><text display-inline="yes-display-inline">Not later than 1 year after the date of the
			 enactment of this Act, the Commission shall promulgate regulations under
			 <external-xref legal-doc="usc" parsable-cite="usc/5/553">section 553</external-xref> of title 5, United States Code, to require information brokers to
			 establish measures which facilitate the auditing or retracing of any internal
			 or external access to, or transmissions of, any data in electronic form
			 containing personal information collected, assembled, or maintained by such
			 information broker.</text>
				</paragraph><paragraph commented="no" id="HB28E4A6C876B45B7B479246F00A227B7"><enum>(5)</enum><header>Prohibition on
			 pretexting by information brokers</header>
					<subparagraph commented="no" id="HEBCADF956BBB482FB1651E456190135D"><enum>(A)</enum><header>Prohibition on
			 obtaining personal information by false pretenses</header><text>It shall be
			 unlawful for an information broker to obtain or attempt to obtain, or cause to
			 be disclosed or attempt to cause to be disclosed to any person, personal
			 information or any other information relating to any person by—</text>
						<clause commented="no" id="H9342580167BF449A80B7B5EF429131BD"><enum>(i)</enum><text>making a false,
			 fictitious, or fraudulent statement or representation to any person; or</text>
						</clause><clause commented="no" id="H4DADCCF08DAC49D2B53D75F73100602C"><enum>(ii)</enum><text display-inline="yes-display-inline">providing any document or other information
			 to any person that the information broker knows or should know to be forged,
			 counterfeit, lost, stolen, or fraudulently obtained, or to contain a false,
			 fictitious, or fraudulent statement or representation.</text>
						</clause></subparagraph><subparagraph commented="no" id="H492E94A4640246318BBC552860561EBA"><enum>(B)</enum><header>Prohibition on
			 solicitation to obtain personal information under false pretenses</header><text display-inline="yes-display-inline">It shall be unlawful for an information
			 broker to request a person to obtain personal information or any other
			 information relating to any other person, if the information broker knew or
			 should have known that the person to whom such a request is made will obtain or
			 attempt to obtain such information in the manner described in subsection
			 (a).</text>
					</subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="HA9EAB70FCB6543AA9CD9991DC665E5E"><enum>(d)</enum><header>Exemption for
			 telecommunications carrier, cable operator, information service, or interactive
			 computer service</header><text>Nothing in this section shall apply to any
			 electronic communication by a third party stored by a telecommunications
			 carrier, cable operator, or information service, as those terms are defined in
			 section 3 of the Communications Act of 1934 (<external-xref legal-doc="usc" parsable-cite="usc/47/153">47 U.S.C. 153</external-xref>), or an interactive
			 computer service, as such term is defined in section 230(f)(2) of such Act (47
			 U.S.C. 230(f)(2)).</text>
			</subsection></section><section id="H55676625016B4096BDDEC0CFFE00E0FE"><enum>3.</enum><header>Notification of
			 information security breach</header>
			<subsection id="HB235AD85E0094FF8A019D300CCD1C0E7"><enum>(a)</enum><header>Nationwide
			 Notification</header><text>Any person engaged in interstate commerce that owns
			 or possesses data in electronic form containing personal information shall,
			 following the discovery of a breach of security of the system maintained by
			 such person that contains such data—</text>
				<paragraph id="HC531B1A65C33413D977E48E577B47FB1"><enum>(1)</enum><text>notify each
			 individual who is a citizen or resident of the United States whose personal
			 information was acquired by an unauthorized person as a result of such a breach
			 of security; and</text>
				</paragraph><paragraph id="H82B51165C3DD442FA723381874BDA033"><enum>(2)</enum><text>notify the
			 Commission.</text>
				</paragraph></subsection><subsection id="HF376A3D1315E4ED7A78D2DE400A7EF61"><enum>(b)</enum><header>Special
			 notification requirement for certain entities</header>
				<paragraph id="H3B57D2DA55EF4335B670D48CB8B76E92"><enum>(1)</enum><header>Third party
			 agents</header><text>In the event of a breach of security by any third party
			 entity that has been contracted to maintain or process data in electronic form
			 containing personal information on behalf of any other person who owns or
			 possesses such data, such third party entity shall be required only to notify
			 such person of the breach of security. Upon receiving such notification from
			 such third party, such person shall provide the notification required under
			 subsection (a).</text>
				</paragraph><paragraph commented="no" id="H7A78CF63A9BD4073B4547ECB3883ECB6"><enum>(2)</enum><header>Telecommunications
			 carriers, cable operators, information services, and interactive computer
			 services</header><text display-inline="yes-display-inline">If a
			 telecommunications carrier, cable operator, or information service (as such
			 terms are defined in section 3 of the Communications Act of 1934 (47 U.S.C.
			 153)), or an interactive computer service (as such term is defined in section
			 230(f)(2) of such Act (<external-xref legal-doc="usc" parsable-cite="usc/47/230">47 U.S.C. 230(f)(2)</external-xref>)), becomes aware of a breach of
			 security during the transmission of data in electronic form containing personal
			 information that is owned or possessed by another person utilizing the means of
			 transmission of such telecommunications carrier, cable operator, information
			 service, or interactive computer service, such telecommunications carrier,
			 cable operator, information service, or interactive computer service shall be
			 required only to notify the person who initiated such transmission of such a
			 breach of security if such person can be reasonably identified. Upon receiving
			 such notification from a telecommunications carrier, cable operator,
			 information service, or interactive computer service, such person shall provide
			 the notification required under subsection (a).</text>
				</paragraph><paragraph commented="no" id="HD85BF57FBB9E451CB7009EA1EF531716"><enum>(3)</enum><header>Breach of health
			 information</header><text display-inline="yes-display-inline">If the Commission
			 receives a notification of a breach of security and determines that information
			 included in such breach is individually identifiable health information (as
			 such term is defined in section 1171(6) of the Social Security Act (42 U.S.C.
			 1320d(6)), the Commission shall send a copy of such notification to the
			 Secretary of Health and Human Services.</text>
				</paragraph></subsection><subsection id="HA5382E05DD9043B08EA3007F3809D9B7"><enum>(c)</enum><header>Timeliness of
			 notification</header><text>All notifications required under subsection (a)
			 shall be made as promptly as possible and without unreasonable delay following
			 the discovery of a breach of security of the system and consistent with any
			 measures necessary to determine the scope of the breach, prevent further breach
			 or unauthorized disclosures, and reasonably restore the integrity of the data
			 system.</text>
			</subsection><subsection id="HDEAEFA6302CB4ADCBFA3E89F4465683D"><enum>(d)</enum><header>Method and
			 content of notification</header>
				<paragraph commented="no" id="HE43B96C12D7742F2A19B95A8002F1215"><enum>(1)</enum><header>Direct
			 notification</header>
					<subparagraph commented="no" id="HC61406CEFE414085A36C551771ED7100"><enum>(A)</enum><header>Method of
			 notification</header><text display-inline="yes-display-inline">A person
			 required to provide notification to individuals under subsection (a)(1) shall
			 be in compliance with such requirement if the person provides conspicuous and
			 clearly identified notification by one of the following methods (provided the
			 selected method can reasonably be expected to reach the intended
			 individual):</text>
						<clause commented="no" id="H9818AC3D85B24EFF8676E61367A731AE"><enum>(i)</enum><text>Written
			 notification.</text>
						</clause><clause commented="no" id="HE4D23D77CC9B462ABB00B945E44E0217"><enum>(ii)</enum><text>Email
			 notification, if—</text>
							<subclause commented="no" id="H63B598F844834C5A8198C4FB26DD9FEE"><enum>(I)</enum><text>the person’s
			 primary method of communication with the individual is by email; or</text>
							</subclause><subclause id="HECC5F3D26DCA4949BA00DC32D1EAEDBA"><enum>(II)</enum><text>the individual
			 has consented to receive such notification and the notification is provided in
			 a manner that is consistent with the provisions permitting electronic
			 transmission of notices under section 101 of the Electronic Signatures in
			 Global Commerce Act (<external-xref legal-doc="usc" parsable-cite="usc/15/7001">15 U.S.C. 7001</external-xref>).</text>
							</subclause></clause></subparagraph><subparagraph commented="no" id="HE095E495EE874FC88F050001DB362C8B"><enum>(B)</enum><header>Content of
			 notification</header><text>Regardless of the method by which notification is
			 provided to an individual under subparagraph (A), such notification shall
			 include—</text>
						<clause commented="no" id="H425E6944071243489F14740299B15C44"><enum>(i)</enum><text>a description of
			 the personal information that was acquired by an unauthorized person;</text>
						</clause><clause commented="no" id="H3F1B0A3FABBA4363B800F1BB139C98B5"><enum>(ii)</enum><text display-inline="yes-display-inline">a telephone number that the individual may
			 use, at no cost to such individual, to contact the person to inquire about the
			 breach of security or the information the person maintained about that
			 individual;</text>
						</clause><clause commented="no" id="H37D8A14BA5A94CBB86DF1BA8B33887D5"><enum>(iii)</enum><text display-inline="yes-display-inline">notice that the individual is entitled to
			 receive, at no cost to such individual, consumer credit reports on a quarterly
			 basis for a period of 2 years, and instructions to the individual on requesting
			 such reports from the person;</text>
						</clause><clause id="HF089AC50E66240DA0062EEDAB38CD0E0"><enum>(iv)</enum><text>the
			 toll-free contact telephone numbers and addresses for the major credit
			 reporting agencies; and</text>
						</clause><clause commented="no" id="HA53AD1BE4BCC460FB920D876B8B4ADE4"><enum>(v)</enum><text>a toll-free
			 telephone number and Internet website address for the Commission whereby the
			 individual may obtain information regarding identity theft.</text>
						</clause></subparagraph></paragraph><paragraph commented="no" id="H02AAF8AB85B34502BE881CD5B2EE2BA4"><enum>(2)</enum><header>Substitute
			 notification</header>
					<subparagraph id="HD6C01E83E4FD4725AB437380D52900C2"><enum>(A)</enum><header>Circumstances
			 giving rise to substitute notification</header><text>A person required to
			 provide notification to individuals under subsection (a)(1) may provide
			 substitute notification in lieu of the direct notification required by
			 paragraph (1) if—<italic></italic></text>
						<clause id="H5262FA1F3C674A36B7A7C60036FFC59C"><enum>(i)</enum><text>the
			 person owns or possesses data in electronic form containing personal
			 information of fewer than 1,000 individuals; and</text>
						</clause><clause id="HFA040DB2B7EF46F100B61D9F3724693C"><enum>(ii)</enum><text>such direct
			 notification is not feasible due to—</text>
							<subclause commented="no" id="HBD9D2B8D454C46DCB7798692268F4872"><enum>(I)</enum><text display-inline="yes-display-inline">excessive cost to the person required to
			 provide such notification relative to the resources of such person, as
			 determined in accordance with the regulations issued by the Commission under
			 paragraph (3)(A); or</text>
							</subclause><subclause commented="no" id="HE5A29CF4B9A441B180A5A7390039B953"><enum>(II)</enum><text>lack of
			 sufficient contact information for the individual required to be
			 notified.</text>
							</subclause></clause></subparagraph><subparagraph commented="no" id="HB30EBADA2C8A4107A500B1E8DF695D3"><enum>(B)</enum><header>Form of
			 substitute notification</header><text display-inline="yes-display-inline">Such
			 substitute notification shall include—</text>
						<clause commented="no" id="H70393A53733745A4A997D6933E9F9967"><enum>(i)</enum><text>email notification
			 to the extent that the person has email addresses of individuals to whom it is
			 required to provide notification under subsection (a)(1);</text>
						</clause><clause commented="no" id="H222CF04534724B5BA918B35E8657293D"><enum>(ii)</enum><text>a conspicuous
			 notice on the Internet website of the person (if such person maintains such a
			 website); and</text>
						</clause><clause id="HEE81831C4C5D44E189631306B4316071"><enum>(iii)</enum><text>notification in
			 print and to broadcast media, including major media in metropolitan and rural
			 areas where the individuals whose personal information was acquired
			 reside.</text>
						</clause></subparagraph><subparagraph commented="no" id="HDAE9CB67F5D34102BACA318CE111D230"><enum>(C)</enum><header>Content of
			 substitute notice</header><text display-inline="yes-display-inline">Each form
			 of substitute notice under this paragraph shall include—</text>
						<clause commented="no" id="HA41B024953C447B6976868DE14449F78"><enum>(i)</enum><text>notice that
			 individuals whose personal information is included in the breach of security
			 are entitled to receive, at no cost to the individuals, consumer credit reports
			 on a quarterly basis for a period of 2 years, and instructions on requesting
			 such reports from the person; and</text>
						</clause><clause commented="no" id="H81CD496E6E394B4BA933CE5EE1D03919"><enum>(ii)</enum><text display-inline="yes-display-inline">a telephone number by which an individual
			 can, at no cost to such individual, learn whether that individual’s personal
			 information is included in the breach of security.</text>
						</clause></subparagraph></paragraph><paragraph commented="no" id="H459C49F88E144B7FA4766B60A208001D"><enum>(3)</enum><header>Federal Trade
			 Commission Regulations and Guidance</header>
					<subparagraph commented="no" id="HBA1076AD8EA547FDA7B7C40096C1F5F2"><enum>(A)</enum><header>Regulations</header><text>Not
			 later than 1 year after the date of enactment of this Act, the Commission
			 shall, by regulations under <external-xref legal-doc="usc" parsable-cite="usc/5/553">section 553</external-xref> of title 5, United States Code,
			 establish criteria for determining the circumstances under which substitute
			 notification may be provided under paragraph (2), including criteria for
			 determining if notification under paragraph (1) is not feasible due to
			 excessive cost to the person required to provide such notification relative to
			 the resources of such person.</text>
					</subparagraph><subparagraph commented="no" id="HB50291D3F7F8481EAD76AB5D42FC515"><enum>(B)</enum><header>Guidance</header><text>In
			 addition, the Commission shall provide and publish general guidance with
			 respect to compliance with this section. Such guidance shall include—</text>
						<clause commented="no" id="H232F6050B7DC4F71A3FA90DFD929E116"><enum>(i)</enum><text>a description of
			 written or email notification that complies with the requirements of paragraph
			 (1); and</text>
						</clause><clause commented="no" id="H46FFCC59907E40D2009F7B052FD9127C"><enum>(ii)</enum><text>guidance on the
			 content of substitute notification under paragraph (2)(B), including the extent
			 of notification to print and broadcast media that complies with the
			 requirements of such paragraph.</text>
						</clause></subparagraph></paragraph></subsection><subsection id="H38407D754E5240E9A27000BE96E8CBDB"><enum>(e)</enum><header>Other
			 obligations following breach</header><text display-inline="yes-display-inline">A person required to provide notification
			 under subsection (a) shall, upon request of an individual whose personal
			 information was included in the breach of security, provide or arrange for the
			 provision of, to each such individual and at no cost to such individual,
			 consumer credit reports from at least one of the major credit reporting
			 agencies beginning not later than 2 months following the discovery of a breach
			 of security and continuing on a quarterly basis for a period of 2 years
			 thereafter.</text>
			</subsection><subsection commented="no" id="HD46DEBE7E95D4111859441F784BA611F"><enum>(f)</enum><header>Exemption</header>
				<paragraph commented="no" id="HC294E0642A3243E5BA2718BA3C6627AA"><enum>(1)</enum><header>General
			 exemption</header><text>A person shall be exempt from the requirements under
			 this section if, following a breach of security, such person determines that
			 there is no reasonable risk of identity theft, fraud, or other unlawful
			 conduct.</text>
				</paragraph><paragraph commented="no" id="HBEF9BEA4F6384D5BB543E802D9F1004F"><enum>(2)</enum><header>Presumptions</header>
					<subparagraph commented="no" id="H8445A37C0E3C48C4BC829222F5C2B426"><enum>(A)</enum><header>Encryption</header><text display-inline="yes-display-inline">The encryption of data in electronic form
			 shall establish a presumption that no reasonable risk of identity theft, fraud,
			 or other unlawful conduct exists following a breach of security of such data.
			 Any such presumption may be rebutted by facts demonstrating that the encryption
			 has been or is reasonably likely to be compromised.</text>
					</subparagraph><subparagraph commented="no" id="HB3ACFE4DEFDA4D80BAAF51C79800AF62"><enum>(B)</enum><header>Additional
			 methodologies or technologies</header><text>Not later than 270 days after the
			 date of the enactment of this Act, the Commission shall, by rule pursuant to
			 <external-xref legal-doc="usc" parsable-cite="usc/5/553">section 553</external-xref> of title 5, United States Code, identify any additional security
			 methodology or technology, other than encryption, which renders data in
			 electronic form unreadable or indecipherable, that shall, if applied to such
			 data, establish a presumption that no reasonable risk of identity theft, fraud,
			 or other unlawful conduct exists following a breach of security of such data.
			 Any such presumption may be rebutted by facts demonstrating that any such
			 methodology or technology has been or is reasonably likely to be compromised.
			 In promulgating such a rule, the Commission shall consult with relevant
			 industries, consumer organizations, and data security and identity theft
			 prevention experts and established standards setting bodies.</text>
					</subparagraph></paragraph><paragraph commented="no" id="HBCDEAA7E0F994F28A5B5755D3DD7BA44"><enum>(3)</enum><header>FTC
			 guidance</header><text display-inline="yes-display-inline">Not later than 1
			 year after the date of the enactment of this Act, the Commission shall issue
			 guidance regarding the application of the exemption in paragraph (1).</text>
				</paragraph></subsection><subsection commented="no" id="H16BF3601BD914D69B6DCC8ACB1B08E0"><enum>(g)</enum><header>Website notice of
			 Federal Trade Commission</header><text display-inline="yes-display-inline">If
			 the Commission, upon receiving notification of any breach of security that is
			 reported to the Commission under subsection (a)(2), finds that notification of
			 such a breach of security via the Commission’s Internet website would be in the
			 public interest or for the protection of consumers, the Commission shall place
			 such a notice in a clear and conspicuous location on its Internet
			 website.</text>
			</subsection><subsection commented="no" id="HBB922545EE0948A981234EE4BA26A798"><enum>(h)</enum><header>FTC study on
			 notification in languages in addition to English</header><text display-inline="yes-display-inline">Not later than 1 year after the date of
			 enactment of this Act, the Commission shall conduct a study on the practicality
			 and cost effectiveness of requiring the notification required by subsection
			 (d)(1) to be provided in a language in addition to English to individuals known
			 to speak only such other language.</text>
			</subsection></section><section commented="no" id="HE867AEE2B02F42ABB33792A291BA8B53"><enum>4.</enum><header>Enforcement</header>
			<subsection commented="no" id="H395B24BA968646028FAB77C95B9F1D8B"><enum>(a)</enum><header>Enforcement by
			 the Federal Trade Commission</header>
				<paragraph commented="no" id="H9FA59C72E7F6484497FDF40BBD275CD"><enum>(1)</enum><header>Unfair or
			 deceptive acts or practices</header><text>A violation of section 2 or 3 shall
			 be treated as an unfair and deceptive act or practice in violation of a
			 regulation under section 18(a)(1)(B) of the <act-name parsable-cite="FTCA">Federal Trade Commission Act</act-name> (15 U.S.C.
			 57<italic>a</italic>(a)(1)(B)) regarding unfair or deceptive acts or
			 practices.</text>
				</paragraph><paragraph commented="no" id="H3F37DA1A8564494990AD267E4BE3919E"><enum>(2)</enum><header>Powers of
			 Commission</header><text>The Commission shall enforce this Act in the same
			 manner, by the same means, and with the same jurisdiction, powers, and duties
			 as though all applicable terms and provisions of the
			 <act-name parsable-cite="FTCA">Federal Trade Commission Act</act-name> (15
			 U.S.C. 41 et seq.) were incorporated into and made a part of this Act. Any
			 person who violates such regulations shall be subject to the penalties and
			 entitled to the privileges and immunities provided in that Act.</text>
				</paragraph><paragraph commented="no" id="H406629C0C9764216858612140000CE88"><enum>(3)</enum><header>Limitation</header><text>In
			 promulgating rules under this Act, the Commission shall not require the
			 deployment or use of any specific products or technologies, including any
			 specific computer software or hardware.</text>
				</paragraph></subsection><subsection commented="no" id="H77AA4756F9BD43998555F7D4038810B9"><enum>(b)</enum><header>Enforcement by
			 State attorneys general</header>
				<paragraph commented="no" id="H4096CFC646E249E8B1B608B1261C7054"><enum>(1)</enum><header>Civil
			 action</header><text>In any case in which the attorney general of a State, or
			 an official or agency of a State, has reason to believe that an interest of the
			 residents of that State has been or is threatened or adversely affected by any
			 person who violates section 2 or 3 of this Act, the attorney general, official,
			 or agency of the State, as parens patriae, may bring a civil action on behalf
			 of the residents of the State in a district court of the United States of
			 appropriate jurisdiction—</text>
					<subparagraph commented="no" id="H339B1EF917E24645AF5151BBE77B11F"><enum>(A)</enum><text>to enjoin further
			 violation of such section by the defendant;</text>
					</subparagraph><subparagraph commented="no" id="HF08195F3F352435AB1F8B424EB522E70"><enum>(B)</enum><text>to compel
			 compliance with such section; or</text>
					</subparagraph><subparagraph commented="no" id="H52D0D9FE57EA4EAE873524251CA280AD"><enum>(C)</enum><text>to obtain civil
			 penalties in the amount determined under paragraph (2).</text>
					</subparagraph></paragraph><paragraph commented="no" id="H60A803B869284611939CEFB18DE8C04C"><enum>(2)</enum><header>Civil
			 penalties</header>
					<subparagraph commented="no" id="HF28E815367974EC2B8FDA11178EFADED"><enum>(A)</enum><header>Calculation</header>
						<clause commented="no" id="H8EA6609638634FF39629C240545760F1"><enum>(i)</enum><header>Treatment of
			 violations of section 2</header><text>For purposes of paragraph (1)(C) with
			 regard to a violation of section 2, the amount determined under this paragraph
			 is the amount calculated by multiplying the number of violations of such
			 section by an amount not greater than $11,000. Each day that a person is not in
			 compliance with the requirements of such section shall be treated as a separate
			 violation. The maximum civil penalty calculated under this clause shall not
			 exceed $5,000,000.</text>
						</clause><clause commented="no" id="HA6AFA96E5F9C47D1A431CD086877F3F"><enum>(ii)</enum><header>Treatment of
			 violations of section 3</header><text display-inline="yes-display-inline">For
			 purposes of paragraph (1)(C) with regard to a violation of section 3, the
			 amount determined under this paragraph is the amount calculated by multiplying
			 the number of violations of such section by an amount not greater than $11,000.
			 Each failure to send notification as required under section 3 to a resident of
			 the State shall be treated as a separate violation. The maximum civil penalty
			 calculated under this clause shall not exceed $5,000,000.</text>
						</clause></subparagraph><subparagraph commented="no" id="HBE5D0CA79D7543AFACC6791EAB6E8D0"><enum>(B)</enum><header>Adjustment for
			 inflation</header><text display-inline="yes-display-inline">Beginning on the
			 date that the Consumer Price Index is first published by the Bureau of Labor
			 Statistics that is after 1 year after the date of enactment of this Act, and
			 each year thereafter, the amounts specified in clauses (i) and (ii) of
			 subparagraph (A) shall be increased by the percentage increase in the Consumer
			 Price Index published on that date from the Consumer Price Index published the
			 previous year.</text>
					</subparagraph></paragraph><paragraph commented="no" id="H261F7CA54CB64740B6C5FADA88EBC820"><enum>(3)</enum><header>Intervention by
			 the FTC</header>
					<subparagraph commented="no" id="H6D00591DFC9546AA802183E5290535BA"><enum>(A)</enum><header>Notice and
			 intervention</header><text>The State shall provide prior written notice of any
			 action under paragraph (1) to the Commission and provide the Commission with a
			 copy of its complaint, except in any case in which such prior notice is not
			 feasible, in which case the State shall serve such notice immediately upon
			 instituting such action. The Commission shall have the right—</text>
						<clause commented="no" id="HDCF624ADA59B4C9AAA90B0B0D300B641"><enum>(i)</enum><text>to intervene in
			 the action;</text>
						</clause><clause commented="no" id="HAAD1872DF8214F60852E39FBD56659BE"><enum>(ii)</enum><text>upon so
			 intervening, to be heard on all matters arising therein; and</text>
						</clause><clause commented="no" id="HCB6A6F536F2D4741917C6F8823D32CB"><enum>(iii)</enum><text>to file petitions
			 for appeal.</text>
						</clause></subparagraph><subparagraph commented="no" id="HB8A1B6E1A7664E519DA68D906946744C"><enum>(B)</enum><header>Limitation on
			 State action while Federal action is pending</header><text display-inline="yes-display-inline">If the Commission has instituted a civil
			 action for violation of this Act, no State attorney general, or official or
			 agency of a State, may bring an action under this subsection during the
			 pendency of that action against any defendant named in the complaint of the
			 Commission for any violation of this Act alleged in the complaint.</text>
					</subparagraph></paragraph><paragraph commented="no" id="H2FE39B2E6C7B4B25B65854006BF1BDDE"><enum>(4)</enum><header>Construction</header><text>For
			 purposes of bringing any civil action under paragraph (1), nothing in this Act
			 shall be construed to prevent an attorney general of a State from exercising
			 the powers conferred on the attorney general by the laws of that State
			 to—</text>
					<subparagraph commented="no" id="H6D944B7FD8F645F08805AAC8708441F7"><enum>(A)</enum><text>conduct
			 investigations;</text>
					</subparagraph><subparagraph commented="no" id="H799B1DE148AC452EA34469FAFE15B8C"><enum>(B)</enum><text>administer oaths or
			 affirmations; or</text>
					</subparagraph><subparagraph commented="no" id="HB1E72E9E0BD94B22A5DDAC9C26AE87C0"><enum>(C)</enum><text>compel the
			 attendance of witnesses or the production of documentary and other
			 evidence.</text>
					</subparagraph></paragraph></subsection><subsection commented="no" id="H8E3F3FCF0C8A4F41B66066D418280042"><enum>(c)</enum><header>Affirmative
			 Defense for a violation of section 3</header><text>It shall be an affirmative
			 defense to an enforcement action brought under subsection (a), or a civil
			 action brought under subsection (b), based on a violation of section 3, that
			 all of the personal information contained in the data in electronic form that
			 was acquired as a result of a breach of security of the defendant is public
			 record information that is lawfully made available to the general public from
			 Federal, State, or local government records and was acquired by the defendant
			 from such records.</text>
			</subsection></section><section id="HA841EC255F18470587E0381BAD822324"><enum>5.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act the following definitions
			 apply:</text>
			<paragraph commented="no" id="H82098EE37FA848EBBBCD3C4464AD4D28"><enum>(1)</enum><header>Breach of
			 security</header><text>The term <term>breach of security</term> means the
			 unauthorized acquisition of data in electronic form containing personal
			 information.</text>
			</paragraph><paragraph id="HD75F8B9B6B0A4D760034BD551B0628DE"><enum>(2)</enum><header>Commission</header><text>The
			 term <term>Commission</term> means the Federal Trade Commission.</text>
			</paragraph><paragraph commented="no" id="H9AD6E40DCE054EC190BC92ED462490EF"><enum>(3)</enum><header>Data in
			 electronic form</header><text display-inline="yes-display-inline">The term
			 <term>data in electronic form</term> means any data stored electronically or
			 digitally on any computer system or other database and includes recordable
			 tapes and other mass storage devices.</text>
			</paragraph><paragraph commented="no" id="H6DA4599D3D7941EC859D14D4279B9D7B"><enum>(4)</enum><header>Encryption</header><text>The
			 term <term>encryption</term> means the protection of data in electronic form in
			 storage or in transit using an encryption technology that has been adopted by
			 an established standards setting body which renders such data indecipherable in
			 the absence of associated cryptographic keys necessary to enable decryption of
			 such data. Such encryption must include appropriate management and safeguards
			 of such keys to protect the integrity of the encryption.</text>
			</paragraph><paragraph commented="no" id="H4711B7CD22A84B08822EC22F31E4D3F7"><enum>(5)</enum><header>Identity
			 theft</header><text display-inline="yes-display-inline">The term <term>identity
			 theft</term> means the unauthorized use of another person’s personal
			 information for the purpose of engaging in commercial transactions under the
			 name of such other person.</text>
			</paragraph><paragraph commented="no" id="H58F58D20A622408D007BD1EDE5BC14D5"><enum>(6)</enum><header>Information
			 broker</header><text display-inline="yes-display-inline">The term
			 <term>information broker</term> means a commercial entity whose business is to
			 collect, assemble, or maintain personal information concerning individuals who
			 are not current or former customers of such entity in order to sell such
			 information or provide access to such information to any nonaffiliated third
			 party in exchange for consideration, whether such collection, assembly, or
			 maintenance of personal information is performed by the information broker
			 directly, or by contract or subcontract with any other entity.</text>
			</paragraph><paragraph id="H2C4705EB6630441EA83D347D3F6560C5"><enum>(7)</enum><header>Personal
			 information</header>
				<subparagraph id="HD48A5A1CD72448629EB15D9EEBE1C57F"><enum>(A)</enum><header>Definition</header><text>The
			 term <term>personal information</term> means an individual’s first name or
			 initial and last name, or address, or phone number, in combination with any 1
			 or more of the following data elements for that individual:</text>
					<clause id="HC2095FCE03634F45AF7FD4E24EAEE6BE"><enum>(i)</enum><text>Social Security
			 number.</text>
					</clause><clause id="HCA9E8C8C06574966A5E5F4100FBDB1"><enum>(ii)</enum><text>Driver’s license
			 number or other State identification number.</text>
					</clause><clause id="H5D4BD378EA2A4896A6FBC4BCF6D4A0E8"><enum>(iii)</enum><text>Financial
			 account number, or credit or debit card number, and any required security code,
			 access code, or password that is necessary to permit access to an individual’s
			 financial account.</text>
					</clause></subparagraph><subparagraph commented="no" id="H1A7A0765FDAA4131826658035BA1C430"><enum>(B)</enum><header>Modified
			 definition by rulemaking</header><text>The Commission may, by rule, modify the
			 definition of <quote>personal information</quote> under subparagraph (A) to the
			 extent that such modification is necessary to accommodate changes in technology
			 or practices, will not unreasonably impede interstate commerce, and will
			 accomplish the purposes of this Act.</text>
				</subparagraph></paragraph><paragraph id="H2D42EC5604004208B73D6D00F92E9E93"><enum>(8)</enum><header>Person</header><text>The
			 term <term>person</term> has the same meaning given such term in section 551(2)
			 of title 5, United States Code.</text>
			</paragraph><paragraph commented="no" id="H515698BF67194BFC9F74945CBC5535B7"><enum>(9)</enum><header>Public record
			 information</header><text>The term <term>public record information</term> means
			 information about an individual which has been obtained originally from records
			 of a Federal, State, or local government entity that are available for public
			 inspection.</text>
			</paragraph><paragraph commented="no" id="HDFE97D661BB44998BE1F849B49254914"><enum>(10)</enum><header>Non-public
			 information</header><text>The term <term>non-public information</term> means
			 information about an individual that is of a private nature and neither
			 available to the general public nor obtained from a public record.</text>
			</paragraph></section><section id="H4AAFA2A2E0104AD2B7DA85509624DEE1"><enum>6.</enum><header>Effect on other
			 laws</header>
			<subsection id="H28425B8B75644754005638564BC54B40"><enum>(a)</enum><header>Preemption of
			 State information security laws</header><text display-inline="yes-display-inline">This Act supersedes any provision of a
			 statute, regulation, or rule of a State or political subdivision of a State,
			 with respect to those entities covered by the regulations issued pursuant to
			 this Act, that expressly—</text>
				<paragraph id="HA6AFFA3E65B04D5ABE45C3A4236D7ED5"><enum>(1)</enum><text display-inline="yes-display-inline">requires information security practices and
			 treatment of data in electronic form containing personal information similar to
			 any of those required under section 2; and</text>
				</paragraph><paragraph id="H51055CBDD11440B9AD28CA7775D5FFDB"><enum>(2)</enum><text>requires
			 notification to individuals of a breach of security resulting in unauthorized
			 acquisition of data in electronic form containing personal information.</text>
				</paragraph></subsection><subsection id="H6616EB78130B4634BDADF4D50304A818"><enum>(b)</enum><header>Additional
			 preemption</header>
				<paragraph id="H624702BF4C104930959B42D1E903319B"><enum>(1)</enum><header>In
			 general</header><text>No person other than the Attorney General of a State may
			 bring a civil action under the laws of any State if such action is premised in
			 whole or in part upon the defendant violating any provision of this Act.</text>
				</paragraph><paragraph id="H8D7AC57E59D947F0AD6EAC5368EFF39D"><enum>(2)</enum><header>Protection of
			 consumer protection laws</header><text>This subsection shall not be construed
			 to limit the enforcement of any State consumer protection law by an Attorney
			 General of a State.</text>
				</paragraph></subsection><subsection id="H3C0A228F792046F29FAE328320F5C09B"><enum>(c)</enum><header>Protection of
			 certain State laws</header><text>This Act shall not be construed to preempt the
			 applicability of—</text>
				<paragraph id="H89433C58470148B3B1DF7DD2ECD77338"><enum>(1)</enum><text>State trespass,
			 contract, or tort law; or</text>
				</paragraph><paragraph id="H88A6439529014E62BD6485F680E96B66"><enum>(2)</enum><text>other State laws
			 to the extent that those laws relate to acts of fraud.</text>
				</paragraph></subsection><subsection commented="no" id="HC915E3E52B254E68A749059071CC4EFC"><enum>(d)</enum><header>Preservation of
			 FTC Authority</header><text display-inline="yes-display-inline">Nothing in this
			 Act may be construed in any way to limit or affect the Commission's authority
			 under any other provision of law, including the authority to issue advisory
			 opinions (under part 1 of volume 16 of the Code of Federal Regulations), policy
			 statements, or guidance regarding this Act.</text>
			</subsection></section><section id="H9C2A60DE76CC424995FD3BD9B95E2E77"><enum>7.</enum><header>Effective Date
			 and Sunset</header>
			<subsection id="H6BFF4A48B27E4927B7B68482C6792000"><enum>(a)</enum><header>Effective
			 Date</header><text display-inline="yes-display-inline">This Act shall take
			 effect 1 year after the date of enactment of this Act.</text>
			</subsection><subsection id="H98BCF27DB4A54170BD1C9BCB3DD434A"><enum>(b)</enum><header>Sunset</header><text>This
			 Act shall cease to be in effect on the date that is 10 years from the date of
			 enactment of this Act.</text>
			</subsection></section><section id="HE64F229D49AA4AADACCC5013CE0009D8"><enum>8.</enum><header>Authorization of
			 Appropriations</header><text display-inline="no-display-inline">There is
			 authorized to be appropriated to the Commission $1,000,000 for each of fiscal
			 years 2008 through 2012 to carry out this Act.</text>
		</section></legis-body>
</bill>


