<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Reported-in-Senate" dms-id="A1" public-private="public">
	<form>
		<distribution-code display="yes">II</distribution-code>
		<calendar>Calendar No. 180</calendar>
		<congress>110th CONGRESS</congress>
		<session>1st Session</session>
		<legis-num>S. 239</legis-num>
		<current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber>
		<action>
			<action-date date="20070110">January 10, 2007</action-date>
			<action-desc><sponsor name-id="S221">Mrs. Feinstein</sponsor>
			 introduced the following bill; which was read twice and referred to the
			 <committee-name committee-id="SSJU00">Committee on the
			 Judiciary</committee-name></action-desc>
		</action>
		<action>
			<action-date>May 31, 2007</action-date>
			<action-desc>Reported under authority of the order of the Senate of May
			 25, 2007, by <cosponsor name-id="S057">Mr. Leahy</cosponsor>, with an
			 amendment</action-desc>
			<action-instruction>Strike out all after the enacting clause and insert
			 the part printed in italic</action-instruction>
		</action>
		<legis-type>A BILL</legis-type>
		<official-title>To require Federal agencies, and persons engaged in
		  interstate commerce, in possession of data containing sensitive personally
		  identifiable information, to disclose any breach of such
		  information.</official-title>
	</form>
	<legis-body changed="added" id="HDC6DA60622634949931041F198906D38" reported-display-style="strikethrough">
		<section id="S1" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the
			 <quote><short-title>Notification of Risk to Personal Data
			 Act of 2007</short-title></quote>.</text>
		</section><section id="IDD2ACA3CB90DA47CE81E12285E7C35A21"><enum>2.</enum><header>Notice to
			 individuals</header>
			<subsection id="ID3F33A477BAC94287A6DDD4A57E0FAD65"><enum>(a)</enum><header>In
			 General</header><text>Any agency, or business entity engaged in interstate
			 commerce, that uses, accesses, transmits, stores, disposes of or collects
			 sensitive personally identifiable information shall, following the discovery of
			 a security breach of such information notify any resident of the United States
			 whose sensitive personally identifiable information has been, or is reasonably
			 believed to have been, accessed, or acquired.</text>
			</subsection><subsection id="ID70A3722DC3BF45BD9D5327F8C85BB9C8"><enum>(b)</enum><header>Obligation of
			 Owner or Licensee</header>
				<paragraph id="ID479DB372A34143D1ABE4B709DCAB8564"><enum>(1)</enum><header>Notice to owner
			 or licensee</header><text>Any agency, or business entity engaged in interstate
			 commerce, that uses, accesses, transmits, stores, disposes of, or collects
			 sensitive personally identifiable information that the agency or business
			 entity does not own or license shall notify the owner or licensee of the
			 information following the discovery of a security breach involving such
			 information.</text>
				</paragraph><paragraph id="ID6C5A20D606444C8F9C465FD85345F400"><enum>(2)</enum><header>Notice by owner,
			 licensee or other designated third party</header><text>Nothing in this Act
			 shall prevent or abrogate an agreement between an agency or business entity
			 required to give notice under this section and a designated third party,
			 including an owner or licensee of the sensitive personally identifiable
			 information subject to the security breach, to provide the notifications
			 required under subsection (a).</text>
				</paragraph><paragraph id="IDAB8DC7FB4F8C446AACFD37407820F825"><enum>(3)</enum><header>Business entity
			 relieved from giving notice</header><text>A business entity obligated to give
			 notice under subsection (a) shall be relieved of such obligation if an owner or
			 licensee of the sensitive personally identifiable information subject to the
			 security breach, or other designated third party, provides such
			 notification.</text>
				</paragraph></subsection><subsection id="ID11E22FD4BAFF47F38368E313A9D597C9"><enum>(c)</enum><header>Timeliness of
			 Notification</header>
				<paragraph id="IDCE91ECFB964E411A84A194DCE3196552"><enum>(1)</enum><header>In
			 general</header><text>All notifications required under this section shall be
			 made without unreasonable delay following the discovery by the agency or
			 business entity of a security breach.</text>
				</paragraph><paragraph id="IDF5E75DEA42CE4FFFA91B004D6CF28B78"><enum>(2)</enum><header>Reasonable
			 delay</header><text>Reasonable delay under this subsection may include any time
			 necessary to determine the scope of the security breach, prevent further
			 disclosures, and restore the reasonable integrity of the data system and
			 provide notice to law enforcement when required.</text>
				</paragraph><paragraph id="IDE419710D1C8E462889CC68C0EC8F9894"><enum>(3)</enum><header>Burden of
			 proof</header><text>The agency, business entity, owner, or licensee required to
			 provide notification under this section shall have the burden of demonstrating
			 that all notifications were made as required under this Act, including evidence
			 demonstrating the necessity of any delay.</text>
				</paragraph></subsection><subsection id="ID2444F519D1BB4B63A81969A4473FA4EE"><enum>(d)</enum><header>Delay of
			 Notification Authorized for Law Enforcement Purposes</header>
				<paragraph id="IDA1CA2490940041A2B7A8E22D8E738832"><enum>(1)</enum><header>In
			 general</header><text>If a Federal law enforcement agency determines that the
			 notification required under this section would impede a criminal investigation,
			 such notification shall be delayed upon written notice from such Federal law
			 enforcement agency to the agency or business entity that experienced the
			 breach.</text>
				</paragraph><paragraph id="IDFC22C51986C64712864A084037E4E56E"><enum>(2)</enum><header>Extended delay
			 of notification</header><text>If the notification required under subsection (a)
			 is delayed pursuant to paragraph (1), an agency or business entity shall give
			 notice 30 days after the day such law enforcement delay was invoked unless a
			 Federal law enforcement agency provides written notification that further delay
			 is necessary.</text>
				</paragraph><paragraph id="ID6EF9628C05B14EE19614066F6E756906"><enum>(3)</enum><header>Law enforcement
			 immunity</header><text>No cause of action shall lie in any court against any
			 law enforcement agency for acts relating to the delay of notification for law
			 enforcement purposes under this Act.</text>
				</paragraph></subsection></section><section id="ID623AB4BE641447F88D3E4E9F0CEA16D1"><enum>3.</enum><header>Exemptions</header>
			<subsection id="ID394B5516AAD84CA6AABF7C504B70A818"><enum>(a)</enum><header>Exemption for
			 National Security and Law Enforcement</header>
				<paragraph id="ID62008829E8FD48F59BE143DB1878BD4A"><enum>(1)</enum><header>In
			 general</header><text>Section 2 shall not apply to an agency if the agency
			 certifies, in writing, that notification of the security breach as required by
			 section 2 reasonably could be expected to—</text>
					<subparagraph id="ID75EF8EA3DABF4F59942504EB93600C71"><enum>(A)</enum><text>cause damage to
			 the national security; or</text>
					</subparagraph><subparagraph id="IDD2F24D79CE934C0C86D035284EAAFB3F"><enum>(B)</enum><text>hinder a law
			 enforcement investigation or the ability of the agency to conduct law
			 enforcement investigations.</text>
					</subparagraph></paragraph><paragraph id="IDCC08869675B941E3BD750A21421A846D"><enum>(2)</enum><header>Limits on
			 certifications</header><text>An agency may not execute a certification under
			 paragraph (1) to—</text>
					<subparagraph id="ID1113660EAA024BF4BC598953BCC82721"><enum>(A)</enum><text>conceal violations
			 of law, inefficiency, or administrative error;</text>
					</subparagraph><subparagraph id="IDDA17D0A1C92E4DC7882BDF4E799EC9EA"><enum>(B)</enum><text>prevent
			 embarrassment to a business entity, organization, or agency; or</text>
					</subparagraph><subparagraph id="IDC71A3952AFFA46F1BA6F43B42290FCA9"><enum>(C)</enum><text>restrain
			 competition.</text>
					</subparagraph></paragraph><paragraph id="IDFA23EF1C93264F06A407C6DCAD2399E7"><enum>(3)</enum><header>Notice</header><text>In
			 every case in which an agency issues a certification under paragraph (1), the
			 certification, accompanied by a description of the factual basis for the
			 certification, shall be immediately provided to the United States Secret
			 Service.</text>
				</paragraph></subsection><subsection id="ID624C9B98D6234DB28FD63AE68B97CB03"><enum>(b)</enum><header>Safe
			 Harbor</header><text>An agency or business entity will be exempt from the
			 notice requirements under section 2, if—</text>
				<paragraph id="ID8DDF6FD7E5474E8BA5116A7FE76CD256"><enum>(1)</enum><text>a risk assessment
			 concludes that there is no significant risk that the security breach has
			 resulted in, or will result in, harm to the individuals whose sensitive
			 personally identifiable information was subject to the security breach;</text>
				</paragraph><paragraph id="ID307D4098B18F4DA19CA5419B2438F2CA"><enum>(2)</enum><text>without
			 unreasonable delay, but not later than 45 days after the discovery of a
			 security breach, unless extended by the United States Secret Service, the
			 agency or business entity notifies the United States Secret Service, in
			 writing, of—</text>
					<subparagraph id="ID3FD432A8108C44FB9438ED7BEE880213"><enum>(A)</enum><text>the results of the
			 risk assessment; and</text>
					</subparagraph><subparagraph id="ID4B5E860B94714EC189B0FDB2E778A4EF"><enum>(B)</enum><text>its decision to
			 invoke the risk assessment exemption; and</text>
					</subparagraph></paragraph><paragraph id="IDC6E1C45B3F7044BF8BDE7BEF7ACB6D45"><enum>(3)</enum><text>the United States
			 Secret Service does not indicate, in writing, within 10 days from receipt of
			 the decision, that notice should be given.</text>
				</paragraph></subsection><subsection id="ID8B28E69F5F0E485DB32C08120FA7C098"><enum>(c)</enum><header>Financial Fraud
			 Prevention Exemption</header>
				<paragraph id="IDAADA810D9745425EB5C9A0E3735411B9"><enum>(1)</enum><header>In
			 general</header><text>A business entity will be exempt from the notice
			 requirement under section 2 if the business entity utilizes or participates in
			 a security program that—</text>
					<subparagraph id="ID03506207CBF64676864F108B5A042352"><enum>(A)</enum><text>is designed to
			 block the use of the sensitive personally identifiable information to initiate
			 unauthorized financial transactions before they are charged to the account of
			 the individual; and</text>
					</subparagraph><subparagraph id="IDB264142BCC304C65B617FB0B90AEA4FD"><enum>(B)</enum><text>provides for
			 notice to affected individuals after a security breach that has resulted in
			 fraud or unauthorized transactions.</text>
					</subparagraph></paragraph><paragraph id="IDD9901C70AA92494B8057E6FE899F43EC"><enum>(2)</enum><header>Limitation</header><text>The
			 exemption by this subsection does not apply if the information subject to the
			 security breach includes sensitive personally identifiable information in
			 addition to the sensitive personally identifiable information identified in
			 section 13.</text>
				</paragraph></subsection></section><section id="IDAA444D77B3234AE0B73767663B85134B"><enum>4.</enum><header>Methods of
			 notice</header><text display-inline="no-display-inline">An agency, or business
			 entity shall be in compliance with section 2 if it provides both:</text>
			<paragraph id="ID5EA70759AA53482F9F70F7C9B8C5CC0A"><enum>(1)</enum><header>Individual
			 notice</header>
				<subparagraph id="ID3F59CBC7352F4EBC8E44432713F3FE59"><enum>(A)</enum><text>Written
			 notification to the last known home mailing address of the individual in the
			 records of the agency or business entity;</text>
				</subparagraph><subparagraph id="IDF80C666B6AC04961B4D09AA44EB3DAD8"><enum>(B)</enum><text>telephone notice
			 to the individual personally; or</text>
				</subparagraph><subparagraph id="IDC7C0494FD2724D84A4C961134CFAD6D9"><enum>(C)</enum><text>e-mail notice, if
			 the individual has consented to receive such notice and the notice is
			 consistent with the provisions permitting electronic transmission of notices
			 under section 101 of the Electronic Signatures in Global and National Commerce
			 Act (15 U.S.C. 7001).</text>
				</subparagraph></paragraph><paragraph id="ID1F505577E5EC42B39A4F94639458BFAE"><enum>(2)</enum><header>Media
			 notice</header><text>Notice to major media outlets serving a State or
			 jurisdiction, if the number of residents of such State whose sensitive
			 personally identifiable information was, or is reasonably believed to have
			 been, acquired by an unauthorized person exceeds 5,000.</text>
			</paragraph></section><section id="IDB9CF554934F54894A24DA83EEF87B6A1"><enum>5.</enum><header>Content of
			 notification</header>
			<subsection id="ID5E726EA5E9D04AFC9C13299FB9DF96AA"><enum>(a)</enum><header>In
			 General</header><text>Regardless of the method by which notice is provided to
			 individuals under section 4, such notice shall include, to the extent
			 possible—</text>
				<paragraph id="ID8B99F4B1254D40659572E9436FC18F83"><enum>(1)</enum><text>a description of
			 the categories of sensitive personally identifiable information that was, or is
			 reasonably believed to have been, acquired by an unauthorized person;</text>
				</paragraph><paragraph id="IDAB7903F447D847FAA623380A2EAD5265"><enum>(2)</enum><text>a toll-free
			 number—</text>
					<subparagraph id="IDBC95CBA7C0634C0DA823DE194CA25B89"><enum>(A)</enum><text>that the
			 individual may use to contact the agency or business entity, or the agent of
			 the agency or business entity; and</text>
					</subparagraph><subparagraph id="ID212571B9EC3A43E4856148D9D49E3CF3"><enum>(B)</enum><text>from which the
			 individual may learn what types of sensitive personally identifiable
			 information the agency or business entity maintained about that individual;
			 and</text>
					</subparagraph></paragraph><paragraph id="ID9BFB854E0061424BB2ABBF154D67FF77"><enum>(3)</enum><text>the toll-free
			 contact telephone numbers and addresses for the major credit reporting
			 agencies.</text>
				</paragraph></subsection><subsection id="ID356B89F6633B4F96A8F777AB1232B985"><enum>(b)</enum><header>Additional
			 Content</header><text>Notwithstanding section 10, a State may require that a
			 notice under subsection (a) shall also include information regarding victim
			 protection assistance provided for by that State.</text>
			</subsection></section><section id="IDE0BF33103FBA44B5AE134D84F5B6F401"><enum>6.</enum><header>Coordination of
			 notification with credit reporting agencies</header><text display-inline="no-display-inline">If an agency or business entity is required
			 to provide notification to more than 1,000 individuals under section 2(a), the
			 agency or business entity shall also notify, without unreasonable delay, all
			 consumer reporting agencies that compile and maintain files on consumers on a
			 nationwide basis (as defined in section 603(p) of the
			 <act-name parsable-cite="FCRA">Fair Credit Reporting Act</act-name> (15 U.S.C.
			 1681a(p)) of the timing and distribution of the notices.</text>
		</section><section id="ID90628B930E544B30A8D22E04F3510B1C"><enum>7.</enum><header>Notice to law
			 enforcement</header>
			<subsection id="ID50CFD04D8D854588B7E90D938758F9E7"><enum>(a)</enum><header>Secret
			 Service</header><text>Any business entity or agency shall give notice of a
			 security breach to the United States Secret Service if—</text>
				<paragraph id="ID88C64B082CCE410D87703A6EB9487D57"><enum>(1)</enum><text>the number of
			 individuals whose sensitive personally identifying information was, or is
			 reasonably believed to have been acquired by an unauthorized person exceeds
			 10,000;</text>
				</paragraph><paragraph id="ID2A4FB13C0CC145E58F420312E36466E1"><enum>(2)</enum><text>the security
			 breach involves a database, networked or integrated databases, or other data
			 system containing the sensitive personally identifiable information of more
			 than 1,000,000 individuals nationwide;</text>
				</paragraph><paragraph id="IDBD46C3EA0FCA472783AA5805BE16DE2A"><enum>(3)</enum><text>the security
			 breach involves databases owned by the Federal Government; or</text>
				</paragraph><paragraph id="ID083CE6DE1A1546A292FB3071FF8215F5"><enum>(4)</enum><text>the security
			 breach involves primarily sensitive personally identifiable information of
			 employees and contractors of the Federal Government involved in national
			 security or law enforcement.</text>
				</paragraph></subsection><subsection id="ID86154CDEC31A48699C0EDECF2348ED10"><enum>(b)</enum><header>Notice to Other
			 Law Enforcement Agencies</header><text>The United States Secret Service shall
			 be responsible for notifying—</text>
				<paragraph id="ID028850A23285400EBC85BA4473E9A808"><enum>(1)</enum><text>the Federal Bureau
			 of Investigation, if the security breach involves espionage, foreign
			 counterintelligence, information protected against unauthorized disclosure for
			 reasons of national defense or foreign relations, or Restricted Data (as that
			 term is defined in section 11y of the <act-name parsable-cite="AEA54">Atomic
			 Energy Act of 1954</act-name> (42 U.S.C. 2014(y)), except for offenses
			 affecting the duties of the United States Secret Service under section 3056(a)
			 of title 18, United States Code;</text>
				</paragraph><paragraph id="ID62FAAEB260F54B319D5EB164FDA5B415"><enum>(2)</enum><text>the United States
			 Postal Inspection Service, if the security breach involves mail fraud;
			 and</text>
				</paragraph><paragraph id="IDEF933FF9027C419FAFEA6DE905712BCE"><enum>(3)</enum><text>the attorney
			 general of each State affected by the security breach.</text>
				</paragraph></subsection><subsection id="ID0CE575E4032C44CEA298A22174BCA59B"><enum>(c)</enum><header>14-Day
			 Rule</header><text>The notices to Federal law enforcement and the attorney
			 general of each State affected by a security breach required under this section
			 shall be delivered as promptly as possible, but not later than 14 days after
			 discovery of the events requiring notice.</text>
			</subsection></section><section id="ID061750C3D0214276931CFC1565BB7706"><enum>8.</enum><header>Enforcement</header>
			<subsection id="ID450B7B06349B4AF5ABEA8710D1EAEC7B"><enum>(a)</enum><header>Civil Actions by
			 the Attorney General</header><text>The Attorney General may bring a civil
			 action in the appropriate United States district court against any business
			 entity that engages in conduct constituting a violation of this Act and, upon
			 proof of such conduct by a preponderance of the evidence, such business entity
			 shall be subject to a civil penalty of not more than $1,000 per day per
			 individual whose sensitive personally identifiable information was, or is
			 reasonably believed to have been, accessed or acquired by an unauthorized
			 person, up to a maximum of $50,000 per person.</text>
			</subsection><subsection id="ID6BF79DCB80124D0482DDDF6C21900F65"><enum>(b)</enum><header>Injunctive
			 Actions by the Attorney General</header>
				<paragraph id="ID3CE3EA8617A342ADBB5F70A880DD99FB"><enum>(1)</enum><header>In
			 general</header><text>If it appears that a business entity has engaged, or is
			 engaged, in any act or practice constituting a violation of this Act, the
			 Attorney General may petition an appropriate district court of the United
			 States for an order—</text>
					<subparagraph id="ID5E57D5B8596F43398E29ACF09C4D3C12"><enum>(A)</enum><text>enjoining such act
			 or practice; or</text>
					</subparagraph><subparagraph id="ID4FE10282E2DC4C5D8D36F654074DCAFF"><enum>(B)</enum><text>enforcing
			 compliance with this Act.</text>
					</subparagraph></paragraph><paragraph id="ID26C57EA0B41E4369B6FFFA8BEF7CD31D"><enum>(2)</enum><header>Issuance of
			 order</header><text>A court may issue an order under paragraph (1), if the
			 court finds that the conduct in question constitutes a violation of this
			 Act.</text>
				</paragraph></subsection><subsection id="ID3CBBEAB3B595495CAE2D933642C0C470"><enum>(c)</enum><header>Other Rights and
			 Remedies</header><text>The rights and remedies available under this Act are
			 cumulative and shall not affect any other rights and remedies available under
			 law.</text>
			</subsection><subsection id="ID20F6B38B4CD7479C8F3C85D6C649EE74"><enum>(d)</enum><header>Fraud
			 Alert</header><text>Section 605A(b)(1) of the <act-name parsable-cite="FCRA">Fair Credit Reporting Act</act-name> (15 U.S.C.
			 1681c–1(b)(1)) is amended by inserting <quote>, or evidence that the consumer
			 has received notice that the consumer’s financial information has or may have
			 been compromised,</quote> after <quote>identity theft report</quote>.</text>
			</subsection></section><section id="ID6202C709812042579781CCBC8C9C3A26"><enum>9.</enum><header>Enforcement by
			 State attorneys general</header>
			<subsection id="IDDBCFA6278541493F9626E36EE18C1E2A"><enum>(a)</enum><header>In
			 General</header>
				<paragraph id="IDC72067C46B28408EB523433685ECFF53"><enum>(1)</enum><header>Civil
			 actions</header><text>In any case in which the attorney general of a State or
			 any State or local law enforcement agency authorized by the State attorney
			 general or by State statute to prosecute violations of consumer protection law,
			 has reason to believe that an interest of the residents of that State has been
			 or is threatened or adversely affected by the engagement of a business entity
			 in a practice that is prohibited under this Act, the State or the State or
			 local law enforcement agency on behalf of the residents of the agency’s
			 jurisdiction, may bring a civil action on behalf of the residents of the State
			 or jurisdiction in a district court of the United States of appropriate
			 jurisdiction or any other court of competent jurisdiction, including a State
			 court, to—</text>
					<subparagraph id="IDF6CF423926FD445D9B3319B18F28B077"><enum>(A)</enum><text>enjoin that
			 practice;</text>
					</subparagraph><subparagraph id="ID0C29EF56E0B3452CB0134F1E2063F583"><enum>(B)</enum><text>enforce compliance
			 with this Act; or</text>
					</subparagraph><subparagraph id="ID6ED397E3928242828DF2E6F7B339C7B4"><enum>(C)</enum><text>obtain civil
			 penalties of not more than $1,000 per day per individual whose sensitive
			 personally identifiable information was, or is reasonably believed to have
			 been, accessed or acquired by an unauthorized person, up to a maximum of
			 $50,000 per day.</text>
					</subparagraph></paragraph><paragraph id="IDCE3E132B3A5E41C38949784FE3A6B3B9"><enum>(2)</enum><header>Notice</header>
					<subparagraph id="ID14D432768E324FC6A636C3C90F130E2E"><enum>(A)</enum><header>In
			 general</header><text>Before filing an action under paragraph (1), the attorney
			 general of the State involved shall provide to the Attorney General of the
			 United States—</text>
						<clause id="ID40FA62D298B54119BA2A27D63D44639F"><enum>(i)</enum><text>written notice of
			 the action; and</text>
						</clause><clause id="ID7AF0A8A9B0C748DDBA7B0DD382ACA8DE"><enum>(ii)</enum><text>a copy of the
			 complaint for the action.</text>
						</clause></subparagraph><subparagraph id="IDEB0C9C0B0A41481887975027DD593CB8"><enum>(B)</enum><header>Exemption</header>
						<clause id="ID7C31B9B706264EF4B7323B75F1E891C6"><enum>(i)</enum><header>In
			 general</header><text>Subparagraph (A) shall not apply with respect to the
			 filing of an action by an attorney general of a State under this Act, if the
			 State attorney general determines that it is not feasible to provide the notice
			 described in such subparagraph before the filing of the action.</text>
						</clause><clause id="ID97ABC0D9D98049F99F8F0E7FEEDDBEA6"><enum>(ii)</enum><header>Notification</header><text>In
			 an action described in clause (i), the attorney general of a State shall
			 provide notice and a copy of the complaint to the Attorney General at the time
			 the State attorney general files the action.</text>
						</clause></subparagraph></paragraph></subsection><subsection id="IDE180632EF75243F8913834182D134666"><enum>(b)</enum><header>Federal
			 Proceedings</header><text>Upon receiving notice under subsection (a)(2), the
			 Attorney General shall have the right to—</text>
				<paragraph id="ID2A625D2B770644AAA5143F1EC1BC187E"><enum>(1)</enum><text>move to stay the
			 action, pending the final disposition of a pending Federal proceeding or
			 action;</text>
				</paragraph><paragraph id="ID2E577597C9A74ADBACFF0E90F697D1F4"><enum>(2)</enum><text>initiate an action
			 in the appropriate United States district court under section 8 and move to
			 consolidate all pending actions, including State actions, in such court;</text>
				</paragraph><paragraph id="IDA68747098B4B492088757875D99A4CA3"><enum>(3)</enum><text>intervene in an
			 action brought under subsection (a)(2); and</text>
				</paragraph><paragraph id="ID175E9929C81F4365AD3FB98D5ECFC03E"><enum>(4)</enum><text>file petitions for
			 appeal.</text>
				</paragraph></subsection><subsection id="IDA07D7783B6DA4F2AAB8C516484FFE886"><enum>(c)</enum><header>Pending
			 Proceedings</header><text>If the Attorney General has instituted a proceeding
			 or action for a violation of this Act or any regulations thereunder, no
			 attorney general of a State may, during the pendency of such proceeding or
			 action, bring an action under this Act against any defendant named in such
			 criminal proceeding or civil action for any violation that is alleged in that
			 proceeding or action.</text>
			</subsection><subsection id="IDFD8B4AD77D7845D2BEF42C95CD43D1AA"><enum>(d)</enum><header>Rule of
			 Construction</header><text>For purposes of bringing any civil action under
			 subsection (a), nothing in this Act regarding notification shall be construed
			 to prevent an attorney general of a State from exercising the powers conferred
			 on such attorney general by the laws of that State to—</text>
				<paragraph id="ID58EB79120D5A49138AEDBA3C06E9A9F8"><enum>(1)</enum><text>conduct
			 investigations;</text>
				</paragraph><paragraph id="ID507C7FE0961C4F5EAB310393C7A650AD"><enum>(2)</enum><text>administer oaths
			 or affirmations; or</text>
				</paragraph><paragraph id="IDD80BE26FADB4439E8B13910B5E676ED5"><enum>(3)</enum><text>compel the
			 attendance of witnesses or the production of documentary and other
			 evidence.</text>
				</paragraph></subsection><subsection id="ID78C300B398454A8AA5781293661816D6"><enum>(e)</enum><header>Venue; Service
			 of Process</header>
				<paragraph id="ID10C7FC8CA011413BB12364AED535C771"><enum>(1)</enum><header>Venue</header><text>Any
			 action brought under subsection (a) may be brought in—</text>
					<subparagraph id="ID9603ABB5CC72426284E9E84A63E182A3"><enum>(A)</enum><text>the district court
			 of the United States that meets applicable requirements relating to venue under
			 section 1391 of title 28, United States Code; or</text>
					</subparagraph><subparagraph id="IDA4A40C1207ED45EDAAB664602BC8B670"><enum>(B)</enum><text>another court of
			 competent jurisdiction.</text>
					</subparagraph></paragraph><paragraph id="ID96B19C2DD5AF45E4BB1FCBE600761EEB"><enum>(2)</enum><header>Service of
			 process</header><text>In an action brought under subsection (a), process may be
			 served in any district in which the defendant—</text>
					<subparagraph id="ID3D3AE82B017A4C8FB42C794A35F20DAD"><enum>(A)</enum><text>is an inhabitant;
			 or</text>
					</subparagraph><subparagraph id="ID48D8A623D15A481D8FDD5ACD1A990F1A"><enum>(B)</enum><text>may be
			 found.</text>
					</subparagraph></paragraph></subsection><subsection id="ID40BADD3370BC4B3198BFC537E5B33539"><enum>(f)</enum><header>No Private Cause
			 of Action</header><text>Nothing in this Act establishes a private cause of
			 action against a business entity for violation of any provision of this
			 Act.</text>
			</subsection></section><section id="ID7D1C677E7BC64503AEA49FD3D6B86A43"><enum>10.</enum><header>Effect on
			 Federal and State law</header><text display-inline="no-display-inline">The
			 provisions of this Act shall supersede any other provision of Federal law or
			 any provision of law of any State relating to notification of a security
			 breach, except as provided in section 5(b).</text>
		</section><section id="ID4451AFE6C743464E861F42952AFE9367"><enum>11.</enum><header>Authorization of
			 appropriations</header><text display-inline="no-display-inline">There are
			 authorized to be appropriated such sums as may be necessary to cover the costs
			 incurred by the United States Secret Service to carry out investigations and
			 risk assessments of security breaches as required under this Act.</text>
		</section><section id="ID24F73B084D88489A9FE573C5FCFB70E7"><enum>12.</enum><header>Reporting on
			 risk assessment exemptions</header><text display-inline="no-display-inline">The
			 United States Secret Service shall report to Congress not later than 18 months
			 after the date of enactment of this Act, and upon the request by Congress
			 thereafter, on—</text>
			<paragraph id="ID28A11EAB8D554602BE7E9D7103ED4344"><enum>(1)</enum><text>the number and
			 nature of the security breaches described in the notices filed by those
			 business entities invoking the risk assessment exemption under section 3(b) of
			 this Act and the response of the United States Secret Service to such notices;
			 and</text>
			</paragraph><paragraph id="IDE54E49D8DACB405D8C8E859486BAF1BB"><enum>(2)</enum><text>the number and
			 nature of security breaches subject to the national security and law
			 enforcement exemptions under section 3(a) of this Act.</text>
			</paragraph></section><section id="idCF26857767E24E7095D6F38079BDD56F"><enum>13.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act, the following definitions shall
			 apply:</text>
			<paragraph id="IDCDCD94320FAB4F52870EE0A85EF47DCF"><enum>(1)</enum><header>Agency</header><text>The
			 term <term>agency</term> has the same meaning given such term in section 551 of
			 title 5, United States Code.</text>
			</paragraph><paragraph id="ID3B65DFEE6C1249818B22C50F546CEBCA"><enum>(2)</enum><header>Affiliate</header><text>The
			 term <term>affiliate</term> means persons related by common ownership or by
			 corporate control.</text>
			</paragraph><paragraph id="ID3AB56CFCCF72480994695FCDEE2A1485"><enum>(3)</enum><header>Business
			 entity</header><text>The term <term>business entity</term> means any
			 organization, corporation, trust, partnership, sole proprietorship,
			 unincorporated association, venture established to make a profit, or nonprofit,
			 and any contractor, subcontractor, affiliate, or licensee thereof engaged in
			 interstate commerce.</text>
			</paragraph><paragraph id="ID0BDEB38A63064A99A431B8A8544A7636"><enum>(4)</enum><header>Personally
			 identifiable information</header><text>The term <term>personally identifiable
			 information</term> means any information, or compilation of information, in
			 electronic or digital form serving as a means of identification, as defined by
			 section 1028(d)(7) of title 18, United State Code.</text>
			</paragraph><paragraph id="ID3F44ECECC7B04CB0BD99542E0E24B950"><enum>(5)</enum><header>Security
			 breach</header>
				<subparagraph id="ID4F47C3A05F47433D895F6EE67C5221AE"><enum>(A)</enum><header>In
			 general</header><text>The term <term>security breach</term> means compromise of
			 the security, confidentiality, or integrity of computerized data through
			 misrepresentation or actions that result in, or there is a reasonable basis to
			 conclude has resulted in, acquisition of or access to sensitive personally
			 identifiable information that is unauthorized or in excess of
			 authorization.</text>
				</subparagraph><subparagraph id="ID8038F37CFB574B4DB62E14790D3BF3B2"><enum>(B)</enum><header>Exclusion</header><text>The
			 term <term>security breach</term> does not include—</text>
					<clause id="IDB172B23B78A84EC096EC0629C17BB4C0"><enum>(i)</enum><text>a good faith
			 acquisition of sensitive personally identifiable information by a business
			 entity or agency, or an employee or agent of a business entity or agency, if
			 the sensitive personally identifiable information is not subject to further
			 unauthorized disclosure; or</text>
					</clause><clause id="ID5F539F97BF654C319D061833B7B30634"><enum>(ii)</enum><text>the release of a
			 public record not otherwise subject to confidentiality or nondisclosure
			 requirements.</text>
					</clause></subparagraph></paragraph><paragraph id="ID416069DD723B48D4B31B03C57001F3FC"><enum>(6)</enum><header>Sensitive
			 personally identifiable information</header><text>The term <term>sensitive
			 personally identifiable information</term> means any information or compilation
			 of information, in electronic or digital form that includes—</text>
				<subparagraph id="ID45FB180ED28749478D97CC93CD92602E"><enum>(A)</enum><text>an individual’s
			 first and last name or first initial and last name in combination with any 1 of
			 the following data elements:</text>
					<clause id="ID60D9311A2AD24D1D9B2469BDC5A03F32"><enum>(i)</enum><text>A non-truncated
			 social security number, driver’s license number, passport number, or alien
			 registration number.</text>
					</clause><clause id="ID9BE2F23DB8D349B595AE1BB1C576FDC0"><enum>(ii)</enum><text>Any 2 of the
			 following:</text>
						<subclause id="IDCD691E3AD5454FAE9A48EBF6B730B7EF"><enum>(I)</enum><text>Home address or
			 telephone number.</text>
						</subclause><subclause id="ID914CD6DA00DC4B788386E220F86C9D5B"><enum>(II)</enum><text>Mother’s maiden
			 name, if identified as such.</text>
						</subclause><subclause id="ID81F990C240CD411D915130978D53BEFD"><enum>(III)</enum><text>Month, day, and
			 year of birth.</text>
						</subclause></clause><clause id="ID4694E0B3A4334167BDAAEC15C41BE45E"><enum>(iii)</enum><text>Unique biometric
			 data such as a finger print, voice print, a retina or iris image, or any other
			 unique physical representation.</text>
					</clause><clause id="IDE029748A68724F4ABCDCA325A81011F9"><enum>(iv)</enum><text>A unique account
			 identifier, electronic identification number, user name, or routing code in
			 combination with any associated security code, access code, or password that is
			 required for an individual to obtain money, goods, services or any other thing
			 of value; or</text>
					</clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID73222285CC544C2AAC75A9E00E6A37EB"><enum>(B)</enum><text>a financial
			 account number or credit or debit card number in combination with any security
			 code, access code or password that is required for an individual to obtain
			 money, goods, services or any other thing of value.</text>
				</subparagraph></paragraph></section><section commented="no" display-inline="no-display-inline" id="IDFE5A2A2B3B414F6683F72145B188B6CC" section-type="subsequent-section"><enum>14.</enum><header>Effective
			 date</header><text display-inline="no-display-inline">This Act shall take
			 effect on the expiration of the date which is 90 days after the date of
			 enactment of this Act.</text>
		</section></legis-body>
	<legis-body changed="added" display-enacting-clause="no-display-enacting-clause" reported-display-style="italic">
		<section id="id22B8E40CF2434B7194724E1C1E5DEA5E" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the
			 <quote><short-title>Notification of Risk to Personal Data
			 Act of 2007</short-title></quote>.</text>
		</section><section id="idEA93056FEEEF4EB08F0480B3B354E911"><enum>2.</enum><header>Notice to
			 individuals</header>
			<subsection id="idD2E262EA82BC4F0CB67EF423C08FB4B8"><enum>(a)</enum><header>In
			 General</header><text>Any agency, or business entity engaged in interstate
			 commerce, that uses, accesses, transmits, stores, disposes of or collects
			 sensitive personally identifiable information shall, following the discovery of
			 a security breach of such information notify any resident of the United States
			 whose sensitive personally identifiable information has been, or is reasonably
			 believed to have been, accessed, or acquired.</text>
			</subsection><subsection id="id46C95A116808498192AB23B231FDD442"><enum>(b)</enum><header>Obligation of Owner or
			 Licensee</header>
				<paragraph id="id7C158BD1D84149B39B358196C6F498AD"><enum>(1)</enum><header>Notice to owner or
			 licensee</header><text>Any agency, or business entity engaged in interstate
			 commerce, that uses, accesses, transmits, stores, disposes of, or collects
			 sensitive personally identifiable information that the agency or business
			 entity does not own or license shall notify the owner or licensee of the
			 information following the discovery of a security breach involving such
			 information.</text>
				</paragraph><paragraph id="idC5AA8C6F57064092B472B0BE10EC8843"><enum>(2)</enum><header>Notice by owner,
			 licensee or other designated third party</header><text>Nothing in this Act
			 shall prevent or abrogate an agreement between an agency or business entity
			 required to give notice under this section and a designated third party,
			 including an owner or licensee of the sensitive personally identifiable
			 information subject to the security breach, to provide the notifications
			 required under subsection (a).</text>
				</paragraph><paragraph id="idAE334E583E4246E3A278FF6189635AFD"><enum>(3)</enum><header>Business entity
			 relieved from giving notice</header><text>A business entity obligated to give
			 notice under subsection (a) shall be relieved of such obligation if an owner or
			 licensee of the sensitive personally identifiable information subject to the
			 security breach, or other designated third party, provides such
			 notification.</text>
				</paragraph></subsection><subsection id="id0C1DA7F894F74379B2285A11B2540FC4"><enum>(c)</enum><header>Timeliness of
			 Notification</header>
				<paragraph id="idAB5D79837B55401188D0A5F02F4022F3"><enum>(1)</enum><header>In
			 general</header><text>All notifications required under this section shall be
			 made without unreasonable delay following the discovery by the agency or
			 business entity of a security breach.</text>
				</paragraph><paragraph id="id49556A8B1A604198A5763BB9F6BB17A0"><enum>(2)</enum><header>Reasonable
			 delay</header><text>Reasonable delay under this subsection may include any time
			 necessary to determine the scope of the security breach, prevent further
			 disclosures, and restore the reasonable integrity of the data system and
			 provide notice to law enforcement when required.</text>
				</paragraph><paragraph id="idB9A74C27A9AD4EB3987BFF6779B26A40"><enum>(3)</enum><header>Burden of
			 proof</header><text>The agency, business entity, owner, or licensee required to
			 provide notification under this section shall have the burden of demonstrating
			 that all notifications were made as required under this Act, including evidence
			 demonstrating the reasons for any delay.</text>
				</paragraph></subsection><subsection id="id0B724AAAA5F34861AF1541E650CF0F56"><enum>(d)</enum><header>Delay of Notification
			 Authorized for Law Enforcement Purposes</header>
				<paragraph id="id4550927DB99248D0A39AA06B25426118"><enum>(1)</enum><header>In
			 general</header><text>If a Federal law enforcement agency determines that the
			 notification required under this section would impede a criminal investigation,
			 such notification shall be delayed upon written notice from such Federal law
			 enforcement agency to the agency or business entity that experienced the
			 breach.</text>
				</paragraph><paragraph id="id9D7DCDFF0BCD4390BBEAD18BA12DDEEA"><enum>(2)</enum><header>Extended delay of
			 notification</header><text>If the notification required under subsection (a) is
			 delayed pursuant to paragraph (1), an agency or business entity shall give
			 notice 30 days after the day such law enforcement delay was invoked unless a
			 Federal law enforcement agency provides written notification that further delay
			 is necessary.</text>
				</paragraph><paragraph id="idD06FEABFE3D14125AF2AC2939BE398B4"><enum>(3)</enum><header>Law enforcement
			 immunity</header><text>No cause of action shall lie in any court against any
			 law enforcement agency for acts relating to the delay of notification for law
			 enforcement purposes under this Act.</text>
				</paragraph></subsection></section><section id="id4CF1E210AEFC4D0D86F7DF1133CA3865"><enum>3.</enum><header>Exemptions</header>
			<subsection id="idF30B49722F784049A3E795AEE99EDF75"><enum>(a)</enum><header>Exemption for National
			 Security and Law Enforcement</header>
				<paragraph id="idC9D62C391A2746DC940DB101A7D996CD"><enum>(1)</enum><header>In
			 general</header><text>Section 2 shall not apply to an agency or business entity
			 if the agency or business entity certifies, in writing, that notification of
			 the security breach as required by section 2 reasonably could be expected
			 to—</text>
					<subparagraph id="idEC67FFFE4AE24BE38D849C18CD1D8CC6"><enum>(A)</enum><text>cause damage to the
			 national security; or</text>
					</subparagraph><subparagraph id="idC0E751C6E7CD45BCB243DE087E82CB2D"><enum>(B)</enum><text>hinder a law enforcement
			 investigation or the ability of the agency to conduct law enforcement
			 investigations.</text>
					</subparagraph></paragraph><paragraph id="id102DD2A679504400B463D9B9B47A98F7"><enum>(2)</enum><header>Limits on
			 certifications</header><text>An agency or business entity may not execute a
			 certification under paragraph (1) to—</text>
					<subparagraph id="idBBE9E008F15F45CD958E68934F458941"><enum>(A)</enum><text>conceal violations of
			 law, inefficiency, or administrative error;</text>
					</subparagraph><subparagraph id="id6DBB23C867CC4A349ACFC47793C58E6F"><enum>(B)</enum><text>prevent embarrassment to
			 a business entity, organization, or agency; or</text>
					</subparagraph><subparagraph id="id8009FBD7BE4E4C6CBDD393BF3EA5F3B2"><enum>(C)</enum><text>restrain
			 competition.</text>
					</subparagraph></paragraph><paragraph id="id59FD809D9D1542EE9F246F21121242EC"><enum>(3)</enum><header>Notice</header><text>In
			 every case in which an agency or business entity issues a certification under
			 paragraph (1), the certification, accompanied by a description of the factual
			 basis for the certification, shall be immediately provided to the United States
			 Secret Service.</text>
				</paragraph><paragraph id="ID03a548d7bf3d433693c4ab2b1bde7280"><enum>(4)</enum><header>Secret service review
			 of certifications</header>
					<subparagraph id="ID1602d3c72ed54448a19dbf73919739f8"><enum>(A)</enum><header>In
			 general</header><text>The United States Secret Service may review a
			 certification provided by an agency under paragraph (3), and shall review a
			 certification provided by a business entity under paragraph (3), to determine
			 whether an exemption under paragraph (1) is merited. Such review shall be
			 completed not later than 10 business days after the date of receipt of the
			 certification, except as provided in paragraph (5)(C).</text>
					</subparagraph><subparagraph id="IDe602279f6bae4c49be04bb7c236a80cd"><enum>(B)</enum><header>Notice</header><text>Upon
			 completing a review under subparagraph (A) the United States Secret Service
			 shall immediately notify the agency or business entity, in writing, of its
			 determination of whether an exemption under paragraph (1) is merited.</text>
					</subparagraph><subparagraph id="IDb2f94c610bf4422ead6561388120e2cd"><enum>(C)</enum><header>Exemption</header><text>The
			 exemption under paragraph (1) shall not apply if the United States Secret
			 Service determines under this paragraph that the exemption is not
			 merited.</text>
					</subparagraph></paragraph><paragraph id="IDf148dfa1623544b0a9caa32d0c71db86"><enum>(5)</enum><header>Additional authority of
			 the secret service</header>
					<subparagraph id="ID6517c455849e4249b1b05f812b7277c4"><enum>(A)</enum><header>In
			 general</header><text>In determining under paragraph (4) whether an exemption
			 under paragraph (1) is merited, the United States Secret Service may request
			 additional information from the agency or business entity regarding the basis
			 for the claimed exemption, if such additional information is necessary to
			 determine whether the exemption is merited.</text>
					</subparagraph><subparagraph id="ID431a29e012304bc493848737c25210e5"><enum>(B)</enum><header>Required
			 compliance</header><text>Any agency or business entity that receives a request
			 for additional information under subparagraph (A) shall cooperate with any such
			 request.</text>
					</subparagraph><subparagraph id="ID0b31ef44ccc14992880aa9343f54477c"><enum>(C)</enum><header>Timing</header><text>If
			 the United States Secret Service requests additional information under
			 subparagraph (A), the United States Secret Service shall notify the agency or
			 business entity not later than 10 business days after the date of receipt of
			 the additional information whether an exemption under paragraph (1) is
			 merited.</text>
					</subparagraph></paragraph></subsection><subsection id="idBCDDD5549241425AABFC3C14281C03A1"><enum>(b)</enum><header>Safe harbor</header>
				<paragraph id="id36B7B5C078384924BFADECD3BCA67F1D"><enum>(1)</enum><header>In
			 general</header><text>An agency or business entity shall be exempt from the
			 notice requirements under section 2, if—</text>
					<subparagraph id="ID156359b897734909bb90e9e75a30b116"><enum>(A)</enum><text>a risk assessment
			 concludes that there is no significant risk that a security breach has resulted
			 in, or will result in, harm to the individual whose sensitive personally
			 identifiable information was subject to the security breach;</text>
					</subparagraph><subparagraph id="id53589D15D0DB468CB11D5E76E251A862"><enum>(B)</enum><text>without unreasonable
			 delay, but not later than 45 days after the discovery of a security breach
			 (unless extended by the United States Secret Service), the agency or business
			 entity notifies the United States Secret Service, in writing, of—</text>
						<clause id="id60711ADD0591494792C5C0FE14AC0640"><enum>(i)</enum><text>the results of the risk
			 assessment; and</text>
						</clause><clause id="id7F555300ECDC4C10BD60D853379CBF01"><enum>(ii)</enum><text>its decision to invoke
			 the risk assessment exemption; and</text>
						</clause></subparagraph><subparagraph id="id463F5724D15C4567B0CCB4193FD65E04"><enum>(C)</enum><text>the United States Secret
			 Service does not indicate, in writing, and not later than 10 business days
			 after the date of receipt of the decision described in subparagraph (B)(ii),
			 that notice should be given.</text>
					</subparagraph></paragraph><paragraph id="id6E5B875D35A2479F8E572FB367D8202A"><enum>(2)</enum><header>Presumptions</header><text>There
			 shall be a presumption that no significant risk of harm to the individual whose
			 sensitive personally identifiable information was subject to a security breach
			 if such information—</text>
					<subparagraph id="id7261B6C05F82413BABA497FD6E68AB61"><enum>(A)</enum><text>was encrypted; or</text>
					</subparagraph><subparagraph id="id7F2703711BA84E97B6C9D1824EFEEAEC"><enum>(B)</enum><text>was rendered
			 indecipherable through the use of best practices or methods, such as redaction,
			 access controls, or other such mechanisms, that are widely accepted as an
			 effective industry practice, or an effective industry standard.</text>
					</subparagraph></paragraph></subsection><subsection id="idC41B8677D8FA4D05824CACE96A776D43"><enum>(c)</enum><header>Financial fraud
			 prevention exemption</header>
				<paragraph id="id3ABB9DE7791944368389DED8F6138953"><enum>(1)</enum><header>In
			 general</header><text>A business entity will be exempt from the notice
			 requirement under section 2 if the business entity utilizes or participates in
			 a security program that—</text>
					<subparagraph id="id7BD40360F74742EF9276CE7179E3E9AE"><enum>(A)</enum><text>is designed to block the
			 use of the sensitive personally identifiable information to initiate
			 unauthorized financial transactions before they are charged to the account of
			 the individual; and</text>
					</subparagraph><subparagraph id="idF27444F27B1E4942AB8A1CAB4B1DBAC1"><enum>(B)</enum><text>provides for notice to
			 affected individuals after a security breach that has resulted in fraud or
			 unauthorized transactions.</text>
					</subparagraph></paragraph><paragraph id="id1E73AC2CA4C84D109FAD3C0E851D11E1"><enum>(2)</enum><header>Limitation</header><text>The
			 exemption by this subsection does not apply if—</text>
					<subparagraph id="IDccaaf79f9bff4a8f9888923e16126157"><enum>(A)</enum><text>the information subject
			 to the security breach includes sensitive personally identifiable information,
			 other than a credit card number or credit card security code, of any type;
			 or</text>
					</subparagraph><subparagraph id="IDb394dee646e848a78e2de26b9fe14d6e"><enum>(B)</enum><text>the information subject
			 to the security breach includes both the individual’s credit card number and
			 the individual’s first and last name.</text>
					</subparagraph></paragraph></subsection></section><section id="id044DF1A844054EA2B2816CEBD65F6126"><enum>4.</enum><header>Methods of
			 notice</header><text display-inline="no-display-inline">An agency, or business
			 entity shall be in compliance with section 2 if it provides both:</text>
			<paragraph id="idF3351E9AF4BD4B6AB4AF3DAB394952B6"><enum>(1)</enum><header>Individual
			 notice</header>
				<subparagraph id="idF8E35A3DD7CD45BBA92822BE71169C6F"><enum>(A)</enum><text>Written notification to
			 the last known home mailing address of the individual in the records of the
			 agency or business entity;</text>
				</subparagraph><subparagraph id="id4129576F9A3540159A5E0A6FCC81AD8D"><enum>(B)</enum><text>telephone notice to the
			 individual personally; or</text>
				</subparagraph><subparagraph id="idD2BBA243098B4A8C959BA6B75F246D18"><enum>(C)</enum><text>e-mail notice, if the
			 individual has consented to receive such notice and the notice is consistent
			 with the provisions permitting electronic transmission of notices under section
			 101 of the Electronic Signatures in Global and National Commerce Act (15 U.S.C.
			 7001).</text>
				</subparagraph></paragraph><paragraph id="id054BFA79C9564CCC86B680D6B7FF30D6"><enum>(2)</enum><header>Media
			 notice</header><text>Notice to major media outlets serving a State or
			 jurisdiction, if the number of residents of such State whose sensitive
			 personally identifiable information was, or is reasonably believed to have
			 been, acquired by an unauthorized person exceeds 5,000.</text>
			</paragraph></section><section id="idDF26D460B503452BA171B9900FAF5A05"><enum>5.</enum><header>Content of
			 notification</header>
			<subsection id="id8564F7F787C541808ABD5096BC25B276"><enum>(a)</enum><header>In
			 General</header><text>Regardless of the method by which notice is provided to
			 individuals under section 4, such notice shall include, to the extent
			 possible—</text>
				<paragraph id="idF2E8E915AF3D4EDBA194CF5BC0B85CD0"><enum>(1)</enum><text>a description of the
			 categories of sensitive personally identifiable information that was, or is
			 reasonably believed to have been, acquired by an unauthorized person;</text>
				</paragraph><paragraph id="id62C97F87F7C6414EBF5BFA58E8A86892"><enum>(2)</enum><text>a toll-free
			 number—</text>
					<subparagraph id="idD75D900B5FF84A278DE40E24B73794E1"><enum>(A)</enum><text>that the individual may
			 use to contact the agency or business entity, or the agent of the agency or
			 business entity; and</text>
					</subparagraph><subparagraph id="id5C184ED6989D4A3F8DB1D72038730C35"><enum>(B)</enum><text>from which the individual
			 may learn what types of sensitive personally identifiable information the
			 agency or business entity maintained about that individual; and</text>
					</subparagraph></paragraph><paragraph id="id7451A0BC21F945279A51B89A9DC8E5BC"><enum>(3)</enum><text>the toll-free contact
			 telephone numbers and addresses for the major credit reporting agencies.</text>
				</paragraph></subsection><subsection id="id29AB0E87A105487081B0B53304882A4E"><enum>(b)</enum><header>Additional
			 Content</header><text>Notwithstanding section 10, a State may require that a
			 notice under subsection (a) shall also include information regarding victim
			 protection assistance provided for by that State.</text>
			</subsection></section><section id="id9B29BDF393FA46E99F967A3C99CE3608"><enum>6.</enum><header>Coordination of
			 notification with credit reporting agencies</header><text display-inline="no-display-inline">If an agency or business entity is required
			 to provide notification to more than 5,000 individuals under section 2(a), the
			 agency or business entity shall also notify all consumer reporting agencies
			 that compile and maintain files on consumers on a nationwide basis (as defined
			 in section 603(p) of the <act-name parsable-cite="FCRA">Fair Credit Reporting
			 Act</act-name> (15 U.S.C. 1681a(p)) of the timing and distribution of the
			 notices. Such notice shall be given to the consumer credit reporting agencies
			 without unreasonable delay and, if it will not delay notice to the affected
			 individuals, prior to the distribution of notices to the affected
			 individuals.</text>
		</section><section id="id3A76272160C24CCC94D335D29D696D70"><enum>7.</enum><header>Notice to law
			 enforcement</header>
			<subsection id="id9DCC813E0DCC42C3AF8F14082A47F39F"><enum>(a)</enum><header>Secret
			 Service</header><text>Any business entity or agency shall notify the United
			 States Secret Service of the fact that a security breach has occurred
			 if—</text>
				<paragraph id="id83787FC3E1C34CD69E965DA2E56DE267"><enum>(1)</enum><text>the number of individuals
			 whose sensitive personally identifying information was, or is reasonably
			 believed to have been acquired by an unauthorized person exceeds 10,000;</text>
				</paragraph><paragraph id="id394E75506B534C3CA84B38A08E5BCEB5"><enum>(2)</enum><text>the security breach
			 involves a database, networked or integrated databases, or other data system
			 containing the sensitive personally identifiable information of more than
			 1,000,000 individuals nationwide;</text>
				</paragraph><paragraph id="id19E7E43DE3E74FC38CFAE6832616A882"><enum>(3)</enum><text>the security breach
			 involves databases owned by the Federal Government; or</text>
				</paragraph><paragraph id="idB507BDE7583B4262844D3F7C44304C35"><enum>(4)</enum><text>the security breach
			 involves primarily sensitive personally identifiable information of individuals
			 known to the agency or business entity to be employees and contractors of the
			 Federal Government involved in national security or law enforcement.</text>
				</paragraph></subsection><subsection id="idC03C797F93724D75964B7F15AD810D15"><enum>(b)</enum><header>Notice to other law
			 enforcement agencies</header><text>The United States Secret Service shall be
			 responsible for notifying—</text>
				<paragraph id="id8C9CDFDE3DCB42DBADEBEFB6B8728AC6"><enum>(1)</enum><text>the Federal Bureau of
			 Investigation, if the security breach involves espionage, foreign
			 counterintelligence, information protected against unauthorized disclosure for
			 reasons of national defense or foreign relations, or Restricted Data (as that
			 term is defined in section 11y of the <act-name parsable-cite="AEA54">Atomic
			 Energy Act of 1954</act-name> (42 U.S.C. 2014(y)), except for offenses
			 affecting the duties of the United States Secret Service under section 3056(a)
			 of title 18, United States Code;</text>
				</paragraph><paragraph id="id21D53D4AE5154EECB50E6362BA1224B5"><enum>(2)</enum><text>the United States Postal
			 Inspection Service, if the security breach involves mail fraud; and</text>
				</paragraph><paragraph id="id601E31496F164FEB9CF980735D39F8E9"><enum>(3)</enum><text>the attorney general of
			 each State affected by the security breach.</text>
				</paragraph></subsection><subsection id="ID88f7ca432bca4bac8757ee3308e087b5"><enum>(c)</enum><header>Timing of
			 notices</header><text>The notices required under this section shall be
			 delivered as follows:</text>
				<paragraph id="IDd1eb1239b6cd444e8efb5cb3010a1411"><enum>(1)</enum><text>Notice under subsection
			 (a) shall be delivered as promptly as possible, but not later than 14 days
			 after discovery of the events requiring notice.</text>
				</paragraph><paragraph id="ID64e262c1b4f44e1a829d5bf1c7fa80bf"><enum>(2)</enum><text>Notice under subsection
			 (b) shall be delivered not later than 14 days after the United States Secret
			 Service receives notice of a security breach from an agency or business
			 entity.</text>
				</paragraph></subsection></section><section id="id7CC73545ABB048DBA2B1872F8BFBBFF1"><enum>8.</enum><header>Enforcement</header>
			<subsection id="id12765D730A9343D89C74CA1C0A56F1E4"><enum>(a)</enum><header>Civil actions by the
			 Attorney General</header><text>The Attorney General may bring a civil action in
			 the appropriate United States district court against any business entity that
			 engages in conduct constituting a violation of this Act and, upon proof of such
			 conduct by a preponderance of the evidence, such business entity shall be
			 subject to a civil penalty of not more than $1,000 per day per individual whose
			 sensitive personally identifiable information was, or is reasonably believed to
			 have been, accessed or acquired by an unauthorized person, up to a maximum of
			 $1,000,000 per violation, unless such conduct is found to be willful or
			 intentional.</text>
			</subsection><subsection id="id0EDB12B5CAA54E8CBD89886E678EF568"><enum>(b)</enum><header>Injunctive actions by
			 the Attorney General</header>
				<paragraph id="id4383365926FF4942870AAE40E95C0DA8"><enum>(1)</enum><header>In
			 general</header><text>If it appears that a business entity has engaged, or is
			 engaged, in any act or practice constituting a violation of this Act, the
			 Attorney General may petition an appropriate district court of the United
			 States for an order—</text>
					<subparagraph id="idDE35B3CE43B74E75B699BF4FD4B4D86D"><enum>(A)</enum><text>enjoining such act or
			 practice; or</text>
					</subparagraph><subparagraph id="id4AD83B990BDB420F8FC563FA02BBADA4"><enum>(B)</enum><text>enforcing compliance with
			 this Act.</text>
					</subparagraph></paragraph><paragraph id="id0BEFA247E33B464F8F33887CC0EB5163"><enum>(2)</enum><header>Issuance of
			 order</header><text>A court may issue an order under paragraph (1), if the
			 court finds that the conduct in question constitutes a violation of this
			 Act.</text>
				</paragraph></subsection><subsection id="idE1981FCD83864F4DA783730E7F678306"><enum>(c)</enum><header>Other rights and
			 remedies</header><text>The rights and remedies available under this Act are
			 cumulative and shall not affect any other rights and remedies available under
			 law.</text>
			</subsection><subsection id="id7D3B0E9140CB4E5680B5939E9B11B987"><enum>(d)</enum><header>Fraud
			 alert</header><text>Section 605A(b)(1) of the <act-name parsable-cite="FCRA">Fair Credit Reporting Act</act-name> (15 U.S.C.
			 1681c–1(b)(1)) is amended by inserting <quote>, or evidence that the consumer
			 has received notice that the consumer’s financial information has or may have
			 been compromised,</quote> after <quote>identity theft report</quote>.</text>
			</subsection></section><section id="idA3446BC98EC44D44801CB30531941B3F"><enum>9.</enum><header>Enforcement by State
			 attorneys general</header>
			<subsection id="id03D0A9CEF9E343DA87744E58A1E2DED7"><enum>(a)</enum><header>In general</header>
				<paragraph id="id9C20753C364F421289A323AC0D77A26C"><enum>(1)</enum><header>Civil
			 actions</header><text>In any case in which the attorney general of a State or
			 any State or local law enforcement agency authorized by the State attorney
			 general or by State statute to prosecute violations of consumer protection law,
			 has reason to believe that an interest of the residents of that State has been
			 or is threatened or adversely affected by the engagement of a business entity
			 in a practice that is prohibited under this Act, the State or the State or
			 local law enforcement agency on behalf of the residents of the agency’s
			 jurisdiction, may bring a civil action on behalf of the residents of the State
			 or jurisdiction in a district court of the United States of appropriate
			 jurisdiction or any other court of competent jurisdiction, including a State
			 court, to—</text>
					<subparagraph id="idA80F8B1F347C4DBAAE6519030ECF6BB7"><enum>(A)</enum><text>enjoin that
			 practice;</text>
					</subparagraph><subparagraph id="idEA1CD4C9848348DE974F8750296FF8DF"><enum>(B)</enum><text>enforce compliance with
			 this Act; or</text>
					</subparagraph><subparagraph id="id33604A45076F48C69A025A2EC89607C2"><enum>(C)</enum><text>obtain civil penalties of
			 not more than $1,000 per day per individual whose sensitive personally
			 identifiable information was, or is reasonably believed to have been, accessed
			 or acquired by an unauthorized person, up to a maximum of $1,000,000 per
			 violation, unless such conduct is found to be willful or intentional.</text>
					</subparagraph></paragraph><paragraph id="idBB82E75F44AF478ABDC057F6B0FCDBF1"><enum>(2)</enum><header>Notice</header>
					<subparagraph id="idE38ADB6BE6A04BF6B6C2C8847126F8C6"><enum>(A)</enum><header>In
			 general</header><text>Before filing an action under paragraph (1), the attorney
			 general of the State involved shall provide to the Attorney General of the
			 United States—</text>
						<clause id="id5D5E7BBF0F54477AB8ED5DDCAF6B6A84"><enum>(i)</enum><text>written notice of the
			 action; and</text>
						</clause><clause id="id04B58A922FD74E7E8C902012A2C75E01"><enum>(ii)</enum><text>a copy of the complaint
			 for the action.</text>
						</clause></subparagraph><subparagraph id="id74E7C2757A734A759E58E5A091256EF3"><enum>(B)</enum><header>Exemption</header>
						<clause id="id5BA1A0142EE94C469589EA19E58EC155"><enum>(i)</enum><header>In
			 general</header><text>Subparagraph (A) shall not apply with respect to the
			 filing of an action by an attorney general of a State under this Act, if the
			 State attorney general determines that it is not feasible to provide the notice
			 described in such subparagraph before the filing of the action.</text>
						</clause><clause id="idF91F0ABFC9284300AAC5584E9F0AAC0F"><enum>(ii)</enum><header>Notification</header><text>In
			 an action described in clause (i), the attorney general of a State shall
			 provide notice and a copy of the complaint to the Attorney General at the time
			 the State attorney general files the action.</text>
						</clause></subparagraph></paragraph></subsection><subsection id="id6C2D2008627D495792F7C6726631A44C"><enum>(b)</enum><header>Federal
			 proceedings</header><text>Upon receiving notice under subsection (a)(2), the
			 Attorney General shall have the right to—</text>
				<paragraph id="idA3139A36B69347D381D7A7CE84DD71A1"><enum>(1)</enum><text>move to stay the action,
			 pending the final disposition of a pending Federal proceeding or action;</text>
				</paragraph><paragraph id="id3211A522853D4037AF5AB649AA1CC9F3"><enum>(2)</enum><text>initiate an action in the
			 appropriate United States district court under section 8 and move to
			 consolidate all pending actions, including State actions, in such court;</text>
				</paragraph><paragraph id="id7D72F42B81D44B7387CC395F95FC3EA4"><enum>(3)</enum><text>intervene in an action
			 brought under subsection (a)(2); and</text>
				</paragraph><paragraph id="id9CF43A0F82C040A5B86EC90EAB00EB71"><enum>(4)</enum><text>file petitions for
			 appeal.</text>
				</paragraph></subsection><subsection id="id79F631FE9ABA47EBA61B0C794989C688"><enum>(c)</enum><header>Pending
			 proceedings</header><text>If the Attorney General has instituted a proceeding
			 or action for a violation of this Act or any regulations thereunder, no
			 attorney general of a State may, during the pendency of such proceeding or
			 action, bring an action under this Act against any defendant named in such
			 criminal proceeding or civil action for any violation that is alleged in that
			 proceeding or action.</text>
			</subsection><subsection id="idE5F75E54BF194C1FB8C6AE513CCDEB4B"><enum>(d)</enum><header>Rule of
			 construction</header><text>For purposes of bringing any civil action under
			 subsection (a), nothing in this Act regarding notification shall be construed
			 to prevent an attorney general of a State from exercising the powers conferred
			 on such attorney general by the laws of that State to—</text>
				<paragraph id="id5D4714C9F5EC44049D02AAC5376FB6D2"><enum>(1)</enum><text>conduct
			 investigations;</text>
				</paragraph><paragraph id="id64484CFE376E43C8B440647F3A3A0B57"><enum>(2)</enum><text>administer oaths or
			 affirmations; or</text>
				</paragraph><paragraph id="idB339440990F54CA98DBF366BF261649A"><enum>(3)</enum><text>compel the attendance of
			 witnesses or the production of documentary and other evidence.</text>
				</paragraph></subsection><subsection id="id16880649E7D04705AE8A55BDFEDECE76"><enum>(e)</enum><header>Venue; service of
			 process</header>
				<paragraph id="idD6904BED3FF945F1941F86F38C6B7B30"><enum>(1)</enum><header>Venue</header><text>Any
			 action brought under subsection (a) may be brought in—</text>
					<subparagraph id="idF0B924230D58430B9EFAB5AE169073DE"><enum>(A)</enum><text>the district court of the
			 United States that meets applicable requirements relating to venue under
			 section 1391 of title 28, United States Code; or</text>
					</subparagraph><subparagraph id="id88D4919FCD0A460EBCF03817F2B7B69A"><enum>(B)</enum><text>another court of
			 competent jurisdiction.</text>
					</subparagraph></paragraph><paragraph id="idDE7F44A22E334EE698D31289F01A6882"><enum>(2)</enum><header>Service of
			 process</header><text>In an action brought under subsection (a), process may be
			 served in any district in which the defendant—</text>
					<subparagraph id="id6223B2F513B6425085E075FBAF55EAED"><enum>(A)</enum><text>is an inhabitant;
			 or</text>
					</subparagraph><subparagraph id="id2BDC9E2352CE4D23AAC0FED18D9A2B54"><enum>(B)</enum><text>may be found.</text>
					</subparagraph></paragraph></subsection><subsection id="idDA36CE70D154493493B762EC53F24D55"><enum>(f)</enum><header>No private cause of
			 action</header><text>Nothing in this Act establishes a private cause of action
			 against a business entity for violation of any provision of this Act.</text>
			</subsection></section><section id="id513B66C23BE447CB953218AD7189C428"><enum>10.</enum><header>Effect on Federal and
			 State law</header><text display-inline="no-display-inline">The provisions of
			 this Act shall supersede any other provision of Federal law or any provision of
			 law of any State relating to notification by a business entity engaged in
			 interstate commerce or an agency of a security breach, except as provided in
			 section 5(b).</text>
		</section><section id="id29A954BBBF994D27986AE0061D82D148"><enum>11.</enum><header>Authorization of
			 appropriations</header><text display-inline="no-display-inline">There are
			 authorized to be appropriated such sums as may be necessary to cover the costs
			 incurred by the United States Secret Service to carry out investigations and
			 risk assessments of security breaches as required under this Act.</text>
		</section><section id="id8C6C78DC9375443DB4E804EA4E9021A1"><enum>12.</enum><header>Reporting on risk
			 assessment exemptions</header>
			<subsection id="id7C400914BE6042AE997B9D75625C16AE"><enum>(a)</enum><header>In
			 general</header><text display-inline="yes-display-inline">The United States
			 Secret Service shall report to Congress not later than 18 months after the date
			 of enactment of this Act, and upon the request by Congress thereafter,
			 on—</text>
				<paragraph id="id243E368A92BA444E9E5416A7E2CD96C3"><enum>(1)</enum><text>the number and nature of
			 the security breaches described in the notices filed by those business entities
			 invoking the risk assessment exemption under section 3(b) of this Act and the
			 response of the United States Secret Service to such notices; and</text>
				</paragraph><paragraph id="id16E3465E18AC49EE90E6166EC67DA64C"><enum>(2)</enum><text>the number and nature of
			 security breaches subject to the national security and law enforcement
			 exemptions under section 3(a) of this Act.</text>
				</paragraph></subsection><subsection id="id7FEF13018A6B4ACCA51971B6E3A955A5"><enum>(b)</enum><header>Report</header><text>Any
			 report submitted under subsection (a) shall not disclose the contents of any
			 risk assessment provided to the United States Secret Service under this
			 Act.</text>
			</subsection></section><section id="idEEF2FAA3508B4279969DE9C8F39CE9BB"><enum>13.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act, the following definitions shall
			 apply:</text>
			<paragraph id="id40069EE7532A4822A6F42316DC9DCF61"><enum>(1)</enum><header>Agency</header><text>The
			 term <term>agency</term> has the same meaning given such term in section 551 of
			 title 5, United States Code.</text>
			</paragraph><paragraph id="idDB41308A71A84D10897C18F76FF6F094"><enum>(2)</enum><header>Affiliate</header><text>The
			 term <term>affiliate</term> means persons related by common ownership or by
			 corporate control.</text>
			</paragraph><paragraph id="id8648254B691C4DE59500C28D0DD77A96"><enum>(3)</enum><header>Business
			 entity</header><text>The term <term>business entity</term> means any
			 organization, corporation, trust, partnership, sole proprietorship,
			 unincorporated association, venture established to make a profit, or nonprofit,
			 and any contractor, subcontractor, affiliate, or licensee thereof engaged in
			 interstate commerce.</text>
			</paragraph><paragraph id="IDc28f8875335c4c30a351e34bb3d4d1c0"><enum>(4)</enum><header>Encrypted</header><text>The
			 term <term>encrypted</term>—</text>
				<subparagraph id="IDa329d62a7c6446ee803d721a8dc95ead"><enum>(A)</enum><text>means the protection of
			 data in electronic form, in storage or in transit, using an encryption
			 technology that has been adopted by an established standards setting body which
			 renders such data indecipherable in the absence of associated cryptographic
			 keys necessary to enable decryption of such data; and</text>
				</subparagraph><subparagraph id="ID26d3d226c83e4623b24529020b5280e6"><enum>(B)</enum><text>includes appropriate
			 management and safeguards of such cryptographic keys so as to protect the
			 integrity of the encryption.</text>
				</subparagraph></paragraph><paragraph id="id56FA40FA14294C2390C2227446370B22"><enum>(5)</enum><header>Personally identifiable
			 information</header><text>The term <term>personally identifiable
			 information</term> means any information, or compilation of information, in
			 electronic or digital form serving as a means of identification, as defined by
			 section 1028(d)(7) of title 18, United State Code.</text>
			</paragraph><paragraph id="id1E89750AD7474EB98D8D11BD9082E241"><enum>(6)</enum><header>Security
			 breach</header>
				<subparagraph id="idF3BF03EFF4C9415AB580247A789178DB"><enum>(A)</enum><header>In
			 general</header><text>The term <term>security breach</term> means compromise of
			 the security, confidentiality, or integrity of computerized data through
			 misrepresentation or actions that result in, or there is a reasonable basis to
			 conclude has resulted in, acquisition of or access to sensitive personally
			 identifiable information that is unauthorized or in excess of
			 authorization.</text>
				</subparagraph><subparagraph id="id6549E95277844F1DAFF723AE986CFE2C"><enum>(B)</enum><header>Exclusion</header><text>The
			 term <term>security breach</term> does not include—</text>
					<clause id="id941AD42EE44C4D23870DFB2CC97B6610"><enum>(i)</enum><text>a good faith acquisition
			 of sensitive personally identifiable information by a business entity or
			 agency, or an employee or agent of a business entity or agency, if the
			 sensitive personally identifiable information is not subject to further
			 unauthorized disclosure; or</text>
					</clause><clause id="id097B6DF0965046AB887B908D38493775"><enum>(ii)</enum><text>the release of a public
			 record not otherwise subject to confidentiality or nondisclosure
			 requirements.</text>
					</clause></subparagraph></paragraph><paragraph id="id390183035D4F449C91335548A635DE5C"><enum>(7)</enum><header>Sensitive personally
			 identifiable information</header><text>The term <term>sensitive personally
			 identifiable information</term> means any information or compilation of
			 information, in electronic or digital form that includes—</text>
				<subparagraph id="idCEB4B31C65BD4E269A1A46697ECD9F5B"><enum>(A)</enum><text>an individual’s first and
			 last name or first initial and last name in combination with any 1 of the
			 following data elements:</text>
					<clause id="idF11EE7B09608428C91BEF2CC1EF33C10"><enum>(i)</enum><text>A non-truncated social
			 security number, driver’s license number, passport number, or alien
			 registration number.</text>
					</clause><clause id="id4E39342EB8B9496E8E6548A74A6B1928"><enum>(ii)</enum><text>Any 2 of the
			 following:</text>
						<subclause id="id1FABB1DE8C384F32B4FF2DC0674F4F9C"><enum>(I)</enum><text>Home address or telephone
			 number.</text>
						</subclause><subclause id="idA889DB1DC8704C0FB133A050D617315F"><enum>(II)</enum><text>Mother’s maiden name, if
			 identified as such.</text>
						</subclause><subclause id="id1A61C07FA3E04079867D9FB891407BCD"><enum>(III)</enum><text>Month, day, and year of
			 birth.</text>
						</subclause></clause><clause id="id90686653D1D64332B6044139335CA17A"><enum>(iii)</enum><text>Unique biometric data
			 such as a finger print, voice print, a retina or iris image, or any other
			 unique physical representation.</text>
					</clause><clause id="idC45101592F884D20B879B82EE59515B5"><enum>(iv)</enum><text>A unique account
			 identifier, electronic identification number, user name, or routing code in
			 combination with any associated security code, access code, or password that is
			 required for an individual to obtain money, goods, services or any other thing
			 of value; or</text>
					</clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id89D366ACFC11457EBD2F6A2FCF57338D"><enum>(B)</enum><text>a financial account
			 number or credit or debit card number in combination with any security code,
			 access code or password that is required for an individual to obtain credit,
			 withdraw funds, or engage in a financial transaction.</text>
				</subparagraph></paragraph></section><section commented="no" display-inline="no-display-inline" id="id12CE6BD914B940788BBB680F0FD487F9" section-type="subsequent-section"><enum>14.</enum><header>Effective
			 date</header><text display-inline="no-display-inline">This Act shall take
			 effect on the expiration of the date which is 90 days after the date of
			 enactment of this Act.</text>
		</section></legis-body>
	<endorsement>
		<action-date>May 31, 2007</action-date>
		<action-desc>Reported with an amendment</action-desc>
	</endorsement>
</bill>
