<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Reported-in-Senate" public-private="public">
	<form>
		<distribution-code display="yes">II</distribution-code>
		<calendar>Calendar No. 168</calendar>
		<congress>110th CONGRESS</congress>
		<session>1st Session</session>
		<legis-num>S. 495</legis-num>
		<associated-doc role="report">[Report No. 110–70]</associated-doc>
		<current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber>
		<action>
			<action-date date="20070206">February 6, 2007</action-date>
			<action-desc><sponsor name-id="S057">Mr. Leahy</sponsor> (for himself,
			 <cosponsor name-id="S161">Mr. Specter</cosponsor>, <cosponsor name-id="S230">Mr. Feingold</cosponsor>, <cosponsor name-id="S270">Mr.
			 Schumer</cosponsor>, <cosponsor name-id="S313">Mr. Sanders</cosponsor>,
			 <cosponsor name-id="S307">Mr. Brown</cosponsor>, and <cosponsor name-id="S308">Mr. Cardin</cosponsor>) introduced the following bill; which was
			 read twice and referred to the
			 <committee-name added-display-style="italic" committee-id="SSJU00" deleted-display-style="strikethrough">Committee on the
			 Judiciary</committee-name></action-desc>
		</action>
		<action stage="Reported-in-Senate">
			<action-date date="20070523">May 23, 2007</action-date>
			<action-desc>Reported by <sponsor name-id="S057">Mr. Leahy</sponsor>,
			 with amendments</action-desc>
			<action-instruction>Omit the part struck through and insert the part
			 printed in italic</action-instruction>
		</action>
		<legis-type>A BILL</legis-type>
		<official-title>To prevent and mitigate identity theft, to ensure
		  privacy, to provide notice of security breaches, and to enhance criminal
		  penalties, law enforcement assistance, and other protections against security
		  breaches, fraudulent access, and misuse of personally identifiable
		  information.</official-title>
	</form>
	<legis-body>
		<section id="idBC757BBC5D2D452AB3FEEC0A005925EB" section-type="section-one"><enum>1.</enum><header>Short title; table of
			 contents</header>
			<subsection id="id0DC79081A5544A43ACEE0D3938C88A4A"><enum>(a)</enum><header>Short
			 title</header><text display-inline="yes-display-inline">This Act may be cited
			 as the <quote><short-title>Personal Data Privacy and
			 Security Act of 2007</short-title></quote>.</text>
			</subsection><subsection id="id908FE25517D846089A3520CDCB468544"><enum>(b)</enum><header>Table of
			 contents</header><text>The table of contents of this Act is as follows:</text>
				<toc>
					<toc-entry idref="idBC757BBC5D2D452AB3FEEC0A005925EB" level="section">Sec. 1. Short title; table of contents.</toc-entry>
					<toc-entry idref="idD75E514A664A45B39DAD2D9E8742B0E7" level="section">Sec. 2. Findings.</toc-entry>
					<toc-entry idref="IDd589748af4d840b1a53a75db7bdb7d32" level="section">Sec. 3. Definitions.</toc-entry>
					<toc-entry idref="id57BB7068312345C88A53B62678AE2D8A" level="title">TITLE I—Enhancing punishment for identity theft and other
				violations of data privacy and security</toc-entry>
					<toc-entry idref="IDbbbfe7823d8b4212aeab45071b480182" level="section">Sec. 101. Organized criminal activity in connection with
				unauthorized access to personally identifiable information.</toc-entry>
					<toc-entry idref="ID98057df8ce5e465296494f1084c8664c" level="section">Sec. 102. Concealment of security breaches involving sensitive
				personally identifiable information.</toc-entry>
					<toc-entry idref="IDe2621a55b8dd4003ba8f4a73f015b644" level="section">Sec. 103. Review and amendment of Federal sentencing guidelines
				related to fraudulent access to or misuse of digitized or electronic personally
				identifiable information.</toc-entry>
					<toc-entry idref="id52FE04166D504354BFFAC7070AD44326" level="section"><added-phrase reported-display-style="italic">Sec. 104. Effects
				of identity theft on bankruptcy proceedings.</added-phrase></toc-entry>
					<toc-entry idref="idF823923C0B90487788A0439B5A654169" level="title">TITLE II—Data brokers</toc-entry>
					<toc-entry idref="IDe447c45d508a4eceac923d23f27156c0" level="section">Sec. 201. Transparency and accuracy of data
				collection.</toc-entry>
					<toc-entry idref="IDe5bc6f4fb182485eaed306444501525e" level="section">Sec. 202. Enforcement.</toc-entry>
					<toc-entry idref="ID10033cf1f27d420fab70142956e2f0b0" level="section">Sec. 203. Relation to state laws.</toc-entry>
					<toc-entry idref="IDab58a1e4994746e3975f8bb335bea15c" level="section">Sec. 204. Effective date.</toc-entry>
					<toc-entry idref="idD725C42479864A1D94B301FF34A11C92" level="title">TITLE III—Privacy and security of personally identifiable
				information </toc-entry>
					<toc-entry idref="id3189B1C7B0974BA09A5D2EB0F2AA3456" level="subtitle">Subtitle A—A data privacy and security program</toc-entry>
					<toc-entry idref="ID48089945808a49b592f4356d4079eae6" level="section">Sec. 301. Purpose and applicability of data privacy and
				security program.</toc-entry>
					<toc-entry idref="ID01a5628cdcfe4d1aa8f738063c6c15c2" level="section">Sec. 302. Requirements for a personal data privacy and security
				program.</toc-entry>
					<toc-entry idref="ID5cac3211a25b4f26a2628faea99c9f36" level="section">Sec. 303. Enforcement.</toc-entry>
					<toc-entry idref="ID14b3a2c1aa4344dc97a4480451a1df47" level="section">Sec. 304. Relation to other laws.</toc-entry>
					<toc-entry idref="idBC4FEB9AFE2A4E93BF957FCB6F00B7E3" level="subtitle">Subtitle B—Security breach notification</toc-entry>
					<toc-entry idref="ID5510cd0d499f4913941a3308d15e6a1c" level="section">Sec. 311. Notice to individuals.</toc-entry>
					<toc-entry idref="ID5dc909314300496fae2e47fd1f732bf2" level="section">Sec. 312. Exemptions.</toc-entry>
					<toc-entry idref="IDbe5d0d5a9f634bfbbae2e9371a7cb5ab" level="section">Sec. 313. Methods of notice.</toc-entry>
					<toc-entry idref="ID80d1a786110544b1b9b1a5fa3fc173b3" level="section">Sec. 314. Content of notification.</toc-entry>
					<toc-entry idref="ID82ad6f96b46a4c7388f833d7611a6fc3" level="section">Sec. 315. Coordination of notification with credit reporting
				agencies.</toc-entry>
					<toc-entry idref="IDde1241e504f94594beb8e50db8943996" level="section">Sec. 316. Notice to law enforcement.</toc-entry>
					<toc-entry idref="ID300c058705674d1fa8a20180588bc781" level="section">Sec. 317. Enforcement.</toc-entry>
					<toc-entry idref="ID28d22f15074d4f239f64734d16e27d82" level="section">Sec. 318. Enforcement by State attorneys general.</toc-entry>
					<toc-entry idref="IDa5c5ed85f5b948b08f30d0800295937a" level="section">Sec. 319. Effect on Federal and State law.</toc-entry>
					<toc-entry idref="ID90730e6c13ca4a49b382b3f1e9ee896e" level="section">Sec. 320. Authorization of appropriations.</toc-entry>
					<toc-entry idref="ID0c5c8ec1f3e24cd886be5d8e2f850ca7" level="section">Sec. 321. Reporting on risk assessment exemptions.</toc-entry>
					<toc-entry idref="ID527ade6c074f448da6e7e220dd02a32e" level="section">Sec. 322. Effective date.</toc-entry>
					<toc-entry idref="id75F2FE2314DC46D08187B9BAA28D1DD5" level="subtitle"><added-phrase reported-display-style="italic">Subtitle
				C—Office of Federal Identity Protection</added-phrase></toc-entry>
					<toc-entry idref="id03A6D5A282264B0DAB093F8E9F1A89F2" level="section"><added-phrase reported-display-style="italic">Sec. 331. Office
				of Federal Identity Protection.</added-phrase></toc-entry>
					<toc-entry idref="id14E3D0E4F57E4B0A8C0C7207624800D1" level="title">TITLE IV—Government access to and use of commercial
				data</toc-entry>
					<toc-entry idref="ID12b6cb5e199e41929bf7df592fcd092f" level="section">Sec. 401. General services administration review of
				contracts.</toc-entry>
					<toc-entry idref="ID2c32eab739de4fea85488e717413b035" level="section">Sec. 402. Requirement to audit information security practices
				of contractors and third party business entities.</toc-entry>
					<toc-entry idref="ID4056fc3599c54deeb9c0ed352866c385" level="section">Sec. 403. Privacy impact assessment of government use of
				commercial information services containing personally identifiable
				information.</toc-entry>
					<toc-entry idref="ID938f0445fd614561aaba4ee7b370044f" level="section">Sec. 404. Implementation of chief privacy officer
				requirements.</toc-entry>
				</toc>
			</subsection></section><section id="idD75E514A664A45B39DAD2D9E8742B0E7"><enum>2.</enum><header>Findings</header><text display-inline="no-display-inline">Congress finds that—</text>
			<paragraph id="IDa2c4c47dabdd4ad69f2d0f1c654437a6"><enum>(1)</enum><text>databases of
			 personally identifiable information are increasingly prime targets of hackers,
			 identity thieves, rogue employees, and other criminals, including organized and
			 sophisticated criminal operations;</text>
			</paragraph><paragraph id="ID04489a6412b1456689d78954a66c7729"><enum>(2)</enum><text>identity theft is
			 a serious threat to the nation’s economic stability, homeland security, the
			 development of e-commerce, and the privacy rights of Americans;</text>
			</paragraph><paragraph id="ID0f26ae456c634482bf20d8082e5eed11"><enum>(3)</enum><text>over 9,300,000
			 individuals were victims of identity theft in America last year;</text>
			</paragraph><paragraph id="ID55cac62686074915bc385d99731c5481"><enum>(4)</enum><text>security breaches
			 are a serious threat to consumer confidence, homeland security, e-commerce, and
			 economic stability;</text>
			</paragraph><paragraph id="ID1bad624abb344fe7b015322715f9b15a"><enum>(5)</enum><text>it is important
			 for business entities that own, use, or license personally identifiable
			 information to adopt reasonable procedures to ensure the security, privacy, and
			 confidentiality of that personally identifiable information;</text>
			</paragraph><paragraph id="IDd019a164205942959431067393e87109"><enum>(6)</enum><text>individuals whose
			 personal information has been compromised or who have been victims of identity
			 theft should receive the necessary information and assistance to mitigate their
			 damages and to restore the integrity of their personal information and
			 identities;</text>
			</paragraph><paragraph id="IDf40de8e698734cfd86baf4922b350a82"><enum>(7)</enum><text>data brokers have
			 assumed a significant role in providing identification, authentication, and
			 screening services, and related data collection and analyses for commercial,
			 nonprofit, and government operations;</text>
			</paragraph><paragraph id="ID7d7aeccd1b7f452bbe50b38a9cf86a12"><enum>(8)</enum><text>data misuse and
			 use of inaccurate data have the potential to cause serious or irreparable harm
			 to an individual’s livelihood, privacy, and liberty and undermine efficient and
			 effective business and government operations;</text>
			</paragraph><paragraph id="ID454f8fced90146e0a8af810896df63ca"><enum>(9)</enum><text>there is a need
			 to insure that data brokers conduct their operations in a manner that
			 prioritizes fairness, transparency, accuracy, and respect for the privacy of
			 consumers;</text>
			</paragraph><paragraph id="ID59394f800d994f31a1158c488c7d4fff"><enum>(10)</enum><text>government
			 access to commercial data can potentially improve safety, law enforcement, and
			 national security; and</text>
			</paragraph><paragraph id="ID80b5a6bc1c2d448f94909dc0ee00bdac"><enum>(11)</enum><text>because
			 government use of commercial data containing personal information potentially
			 affects individual privacy, and law enforcement and national security
			 operations, there is a need for Congress to exercise oversight over government
			 use of commercial data.</text>
			</paragraph></section><section id="IDd589748af4d840b1a53a75db7bdb7d32"><enum>3.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act:</text>
			<paragraph id="ID6b46a295351f45bca8862eaacaa06801"><enum>(1)</enum><header>Agency</header><text>The
			 term <term>agency</term> has the same meaning given such term in section 551 of
			 title 5, United States Code.</text>
			</paragraph><paragraph id="IDe27e8f808b154a4e82175769e61f717c"><enum>(2)</enum><header>Affiliate</header><text>The
			 term <term>affiliate</term> means persons related by common ownership or by
			 corporate control.</text>
			</paragraph><paragraph id="ID45177ec08eb54f5d85a71563525e94e8"><enum>(3)</enum><header>Business
			 entity</header><text>The term <term>business entity</term> means any
			 organization, corporation, trust, partnership, sole proprietorship,
			 unincorporated association, <added-phrase reported-display-style="italic">or</added-phrase> venture established to make a
			 profit, or nonprofit<deleted-phrase reported-display-style="strikethrough">,
			 and any contractor, subcontractor, affiliate, or licensee thereof engaged in
			 interstate commerce</deleted-phrase>.</text>
			</paragraph><paragraph id="IDbb1410bcbaed48e09a39a9d58c592601"><enum>(4)</enum><header>Identity
			 theft</header><text>The term <term>identity theft</term> means a violation of
			 section 1028 of title 18, United States Code.</text>
			</paragraph><paragraph id="ID421132fe62314202b0a6b558eff900fc"><enum>(5)</enum><header>Data
			 broker</header><text>The term <term>data broker</term> means a business entity
			 which for monetary fees or dues regularly engages in the practice of
			 collecting, transmitting, or providing access to sensitive personally
			 identifiable information on more than 5,000 individuals who are not the
			 customers or employees of that business entity or affiliate primarily for the
			 purposes of providing such information to nonaffiliated third parties on an
			 interstate basis.</text>
			</paragraph><paragraph id="ID3b80cbb1dae54c41bd803298c33a4114"><enum>(6)</enum><header>Data
			 furnisher</header><text>The term <term>data furnisher</term> means any agency,
			 organization, corporation, trust, partnership, sole proprietorship,
			 unincorporated association, or nonprofit that serves as a source of information
			 for a data broker.</text>
			</paragraph><paragraph changed="added" id="idEAC844C6681D485491A58D0D6134494F" reported-display-style="italic"><enum>(7)</enum><header>Encryption</header><text>The
			 term <quote>encryption</quote>—</text>
				<subparagraph id="idFD707E02AC4E4C45814FE3598C7CA84C"><enum>(A)</enum><text>means the protection of
			 data in electronic form, in storage or in transit, using an encryption
			 technology that has been adopted by an established standards setting body which
			 renders such data indecipherable in the absence of associated cryptographic
			 keys necessary to enable decryption of such data; and</text>
				</subparagraph><subparagraph id="idD50D1D0CAFC8461F94DBAF994610965F"><enum>(B)</enum><text>includes appropriate
			 management and safeguards of such cryptographic keys so as to protect the
			 integrity of the encryption.</text>
				</subparagraph></paragraph><paragraph id="ID708763bb5a6547018d66b9e4109a7115"><enum>(<deleted-phrase reported-display-style="strikethrough">7</deleted-phrase><added-phrase reported-display-style="italic">8</added-phrase>)</enum><header>Personal
			 electronic record</header>
				<subparagraph id="ID5481d7730bee42ea9d77786a3ae95139"><enum>(A)</enum><header>In
			 general</header><text>The term <term>personal electronic record</term> means
			 data associated with an individual contained in a database, networked or
			 integrated databases, or other data system that
			 <deleted-phrase reported-display-style="strikethrough">holds</deleted-phrase><added-phrase reported-display-style="italic">is provided to non-affiliated third parties and
			 includes</added-phrase> sensitive personally identifiable information
			 <deleted-phrase reported-display-style="strikethrough">of</deleted-phrase><added-phrase reported-display-style="italic">about</added-phrase> that individual
			 <deleted-phrase reported-display-style="strikethrough">and is provided to
			 nonaffiliated third parties</deleted-phrase>.</text>
				</subparagraph><subparagraph id="ID4369a17e080f4a348ad99bf88bea9f3e"><enum>(B)</enum><header>Exclusions</header><text>The
			 term <term>personal electronic record</term> does not include—</text>
					<clause id="IDd02a1a34ad8d4162b7dbfb508757011b"><enum>(i)</enum><text>any
			 data related to an individual’s past purchases of consumer goods; or</text>
					</clause><clause id="IDeed2686065464aa3872c933c3dca25b4"><enum>(ii)</enum><text>any proprietary
			 assessment or evaluation of an individual or any proprietary assessment or
			 evaluation of information about an individual.</text>
					</clause></subparagraph></paragraph><paragraph id="ID277a6f9dfb7b437db77f20ff4f84aca8"><enum>(<deleted-phrase reported-display-style="strikethrough">8</deleted-phrase><added-phrase reported-display-style="italic">9</added-phrase>)</enum><header>Personally
			 identifiable information</header><text>The term <term>personally identifiable
			 information</term> means any information, or compilation of information, in
			 electronic or digital form serving as a means of identification, as defined by
			 section 1028(d)(7) of title 18, United States Code.</text>
			</paragraph><paragraph id="ID3d90719ddb9d4d89ac2511f5d43030d5"><enum>(<deleted-phrase reported-display-style="strikethrough">9</deleted-phrase><added-phrase reported-display-style="italic">10</added-phrase>)</enum><header>Public record
			 source</header><text>The term <term>public record source</term> means the
			 Congress, any agency, any State or local government agency, the government of
			 the District of Columbia and governments of the territories or possessions of
			 the United States, and Federal, State or local courts, courts martial and
			 military commissions, that maintain personally identifiable information in
			 records available to the public.</text>
			</paragraph><paragraph id="IDcf447112b33241bbafa2e1679b5ed4fd"><enum>(<deleted-phrase reported-display-style="strikethrough">10</deleted-phrase><added-phrase reported-display-style="italic">11</added-phrase>)</enum><header>Security
			 breach</header>
				<subparagraph id="ID1795088a852f416cb8c1f8b6d46cf325"><enum>(A)</enum><header>In
			 general</header><text>The term <term>security breach</term> means compromise of
			 the security, confidentiality, or integrity of computerized data through
			 misrepresentation or actions that result in, or there is a reasonable basis to
			 conclude has resulted in, acquisition of or access to sensitive personally
			 identifiable information that is unauthorized or in excess of
			 authorization.</text>
				</subparagraph><subparagraph id="ID32aadcee3e724a14a6ff42e11bcda31d"><enum>(B)</enum><header>Exclusion</header><text>The
			 term <term>security breach</term> does not include—</text>
					<clause id="IDdaa3112ae3d7459abf9485ef3d7d77ad"><enum>(i)</enum><text>a
			 good faith acquisition of sensitive personally identifiable information by a
			 business entity or agency, or an employee or agent of a business entity or
			 agency, if the sensitive personally identifiable information is not subject to
			 further unauthorized disclosure; or</text>
					</clause><clause changed="deleted" id="ID111e1c8f5e9c4dae818deb6f4d833de4" reported-display-style="strikethrough"><enum>(ii)</enum><text>the release of a
			 public record, or information derived from a single public record, not
			 otherwise subject to confidentiality or nondisclosure requirement, or
			 information obtained from a news report or periodical.</text>
					</clause><clause changed="added" id="idD5FF6A5E552942ECBD9BB5200E4A06A1" reported-display-style="italic"><enum>(ii)</enum><text>the release of a public
			 record not otherwise subject to confidentiality or nondisclosure
			 requirements.</text>
					</clause></subparagraph></paragraph><paragraph id="IDe99b189310e04a72969f33adb3158514"><enum>(<deleted-phrase reported-display-style="strikethrough">11</deleted-phrase><added-phrase reported-display-style="italic">12</added-phrase>)</enum><header>Sensitive
			 personally identifiable information</header><text>The term <term>sensitive
			 personally identifiable information</term> means any information or compilation
			 of information, in electronic or digital form that includes—</text>
				<subparagraph id="ID3dc22ad332974f5f8df1fdb0edb915b2"><enum>(A)</enum><text>an individual's
			 first and last name or first initial and last name in combination with any 1 of
			 the following data elements:</text>
					<clause id="ID78ada63e7c82488dac32cd2b523ccaab"><enum>(i)</enum><text>A
			 non-truncated social security number, driver's license number, passport number,
			 or alien registration number.</text>
					</clause><clause id="ID8b166ce6db234d039fa880e8311901c3"><enum>(ii)</enum><text>Any 2 of the
			 following:</text>
						<subclause id="ID32ce80211bca4306a8ee62599e1fec11"><enum>(I)</enum><text>Home address or
			 telephone number.</text>
						</subclause><subclause id="IDa0d1db2d079740468b98f0a7696a13c0"><enum>(II)</enum><text>Mother's maiden
			 name, if identified as such.</text>
						</subclause><subclause id="ID1ec42025860143229b6bd52e8434a072"><enum>(III)</enum><text>Month, day, and
			 year of birth.</text>
						</subclause></clause><clause id="ID8c601c35ad2d4a809aeeee8f9e1a3fff"><enum>(iii)</enum><text>Unique
			 biometric data such as a finger print, voice print, a retina or iris image, or
			 any other unique physical representation.</text>
					</clause><clause id="ID5ebc421720fb4463a4f69f324113db8c"><enum>(iv)</enum><text>A
			 unique account identifier, electronic identification number, user name, or
			 routing code in combination with any associated security code, access code, or
			 password that is required for an individual to obtain money, goods, services,
			 or any other thing of value; or</text>
					</clause></subparagraph><subparagraph id="IDb275561b64d34e31823ff4a792b2b881"><enum>(B)</enum><text>a financial
			 account number or credit or debit card number in combination with any security
			 code, access code or password that is required for an individual to obtain
			 credit, withdraw funds, or engage in a financial transaction.</text>
				</subparagraph></paragraph></section><title id="id57BB7068312345C88A53B62678AE2D8A"><enum>I</enum><header>Enhancing
			 punishment for identity theft and other violations of data privacy and
			 security</header>
			<section id="IDbbbfe7823d8b4212aeab45071b480182"><enum>101.</enum><header>Organized
			 criminal activity in connection with unauthorized access to personally
			 identifiable information</header><text display-inline="no-display-inline">Section 1961(1) of title 18, United States
			 Code, is amended by inserting <quote>section 1030(a)(2)(D) (relating to fraud
			 and related activity in connection with unauthorized access to sensitive
			 personally identifiable information as defined in the
			 <short-title>Personal Data Privacy and Security Act of
			 2007</short-title>,</quote> before <quote>section 1084</quote>.</text>
			</section><section id="ID98057df8ce5e465296494f1084c8664c"><enum>102.</enum><header>Concealment of
			 security breaches involving sensitive personally identifiable
			 information</header>
				<subsection id="ID574a854e62eb447bb4f50ec14b792143"><enum>(a)</enum><header>In
			 general</header><text display-inline="yes-display-inline">Chapter 47 of title
			 18, United States Code, is amended by adding at the end the following:</text>
					<quoted-block display-inline="no-display-inline" id="idF9342237D76A4CEAAE27A5A099B89861" style="USC">
						<section id="IDa347d393004b4e53878f3745e4bd6e88"><enum>1040.</enum><header>Concealment
				of security breaches involving sensitive personally identifiable
				information</header>
							<subsection id="ID4bcfaf400ddf414582209c7244832564"><enum>(a)</enum><text>Whoever, having
				knowledge of a security breach and of the obligation to provide notice of such
				breach to individuals under title III of the <short-title>Personal Data Privacy and Security Act of
				2007</short-title>, and having not otherwise qualified for an exemption from
				providing notice under section 312 of such Act, intentionally and willfully
				conceals the fact of such security breach and which breach causes economic
				damage to 1 or more persons, shall be fined under this title or imprisoned not
				more than 5 years, or both.</text>
							</subsection><subsection id="IDa6c6cc34315f4ba599f4b63575125021"><enum>(b)</enum><text>For purposes of
				subsection (a), the term <term>person</term> has the same meaning as in section
				1030(e)(12) of title 18, United States Code.</text>
							</subsection><subsection id="id8463FC3B2CCE41E0A211E3946F886E25"><enum>(c)</enum><text>Any person
				seeking an exemption under section 312(b) of the
				<short-title>Personal Data Privacy and Security Act of
				2007</short-title> shall be immune from prosecution under this section if the
				United States Secret Service does not indicate, in writing, that such notice be
				given under section 312(b)(3) of such
				Act</text>
							</subsection></section><after-quoted-block>.</after-quoted-block></quoted-block>
				</subsection><subsection id="IDe250299bce944fcb9cedfd92fc33a8c7"><enum>(b)</enum><header>Conforming and
			 technical amendments</header><text display-inline="yes-display-inline">The
			 table of sections for chapter 47 of title 18, United States Code, is amended by
			 adding at the end the following:</text>
					<quoted-block display-inline="no-display-inline" id="id4A4F3645F72549419DD8D57CB66D2322" style="OLC">
						<toc>
							<toc-entry level="section">1040. Concealment of security breaches
				involving personally identifiable
				information.</toc-entry>
						</toc>
						<after-quoted-block>.</after-quoted-block></quoted-block>
				</subsection><subsection id="ID0cfb1f2062d849319cbd7ed151526023"><enum>(c)</enum><header>Enforcement
			 authority</header>
					<paragraph id="id74BEB32B70524064BF1CC860F6B7ADD3"><enum>(1)</enum><header>In
			 general</header><text>The United States Secret Service shall have the authority
			 to investigate offenses under this section.</text>
					</paragraph><paragraph id="id7117EAAA2D194B5A824D86D68273DD2E"><enum>(2)</enum><header>Non-exclusivity</header><text>The
			 authority granted in paragraph (1) shall not be exclusive of any existing
			 authority held by any other Federal agency.</text>
					</paragraph></subsection></section><section id="IDe2621a55b8dd4003ba8f4a73f015b644"><enum>103.</enum><header>Review and
			 amendment of Federal sentencing guidelines related to fraudulent access to or
			 misuse of digitized or electronic personally identifiable information</header>
				<subsection id="ID04468b6f7d6641249b40f88e02dbaa1b"><enum>(a)</enum><header>Review and
			 amendment</header><text>The United States Sentencing Commission, pursuant to
			 its authority under section 994 of title 28, United States Code, and in
			 accordance with this section, shall review and, if appropriate, amend the
			 Federal sentencing guidelines (including its policy statements) applicable to
			 persons convicted of using fraud to access, or misuse of, digitized or
			 electronic personally identifiable information, including identity theft or any
			 offense under—</text>
					<paragraph id="ID28a6ebacad884345902a831f3934e048"><enum>(1)</enum><text>sections 1028,
			 1028A, 1030, 1030A, 2511, and 2701 of title 18, United States Code; and</text>
					</paragraph><paragraph id="IDac0a76ec593f418296e707cc6967b755"><enum>(2)</enum><text>any other
			 relevant provision.</text>
					</paragraph></subsection><subsection id="ID777e36d16fa44b08a9cab1cca9ab992c"><enum>(b)</enum><header>Requirements</header><text display-inline="yes-display-inline">In carrying out the requirements of this
			 section, the United States Sentencing Commission shall—</text>
					<paragraph id="ID2112f8ae2e224dc493bed3a4a3dea482"><enum>(1)</enum><text>ensure that the
			 Federal sentencing guidelines (including its policy statements) reflect—</text>
						<subparagraph id="IDddd417aaa96b40799d7fb2d9fe7bcbcf"><enum>(A)</enum><text>the serious
			 nature of the offenses and penalties referred to in this Act;</text>
						</subparagraph><subparagraph id="IDc7e8057b660b413db7c588bc04973c91"><enum>(B)</enum><text>the growing
			 incidences of theft and misuse of digitized or electronic personally
			 identifiable information, including identity theft; and</text>
						</subparagraph><subparagraph id="ID24235709f8ba463c9bec64b91e0cf856"><enum>(C)</enum><text>the need to
			 deter, prevent, and punish such offenses;</text>
						</subparagraph></paragraph><paragraph id="ID180963dc2404432a9773ad4013d4b26d"><enum>(2)</enum><text>consider the
			 extent to which the Federal sentencing guidelines (including its policy
			 statements) adequately address violations of the sections amended by this Act
			 to—</text>
						<subparagraph id="ID2f8e06ff702b43b0bccaedeb1b29d9de"><enum>(A)</enum><text>sufficiently
			 deter and punish such offenses; and</text>
						</subparagraph><subparagraph id="ID166d86e267d04eaf9fbfb884317b274e"><enum>(B)</enum><text>adequately
			 reflect the enhanced penalties established under this Act;</text>
						</subparagraph></paragraph><paragraph id="ID0fdef680829b4a0a95ff50fecf118a62"><enum>(3)</enum><text>maintain
			 reasonable consistency with other relevant directives and sentencing
			 guidelines;</text>
					</paragraph><paragraph id="ID4d1e8b2b14e54fa1b286aa7f359637db"><enum>(4)</enum><text>account for any
			 additional aggravating or mitigating circumstances that might justify
			 exceptions to the generally applicable sentencing ranges;</text>
					</paragraph><paragraph id="ID13e363721f074364a24861e4248919c5"><enum>(5)</enum><text>consider whether
			 to provide a sentencing enhancement for those convicted of the offenses
			 described in subsection (a), if the conduct involves—</text>
						<subparagraph id="ID8e9e812c18dc46adbae1111afaa7b46c"><enum>(A)</enum><text>the online sale
			 of fraudulently obtained or stolen personally identifiable information;</text>
						</subparagraph><subparagraph id="ID29dd62998d7d4d429977552414c517cc"><enum>(B)</enum><text>the sale of
			 fraudulently obtained or stolen personally identifiable information to an
			 individual who is engaged in terrorist activity or aiding other individuals
			 engaged in terrorist activity; or</text>
						</subparagraph><subparagraph id="IDad4f7e9b223742f09c6dead5d1e7e53b"><enum>(C)</enum><text>the sale of
			 fraudulently obtained or stolen personally identifiable information to finance
			 terrorist activity or other criminal activities;</text>
						</subparagraph></paragraph><paragraph id="IDbab007e0bfb340679731fe66f185c15d"><enum>(6)</enum><text>make any
			 necessary conforming changes to the Federal sentencing guidelines to ensure
			 that such guidelines (including its policy statements) as described in
			 subsection (a) are sufficiently stringent to deter, and adequately reflect
			 crimes related to fraudulent access to, or misuse of, personally identifiable
			 information; and</text>
					</paragraph><paragraph id="IDeafa42fefc00458397ebba0dec9e9392"><enum>(7)</enum><text>ensure that the
			 Federal sentencing guidelines adequately meet the purposes of sentencing under
			 section 3553(a)(2) of title 18, United States Code.</text>
					</paragraph></subsection><subsection id="IDccf6ee99775147f6823d50b216346604"><enum>(c)</enum><header>Emergency
			 authority to sentencing commission</header><text>The United States Sentencing
			 Commission may, as soon as practicable, promulgate amendments under this
			 section in accordance with procedures established in section 21(a) of the
			 Sentencing Act of 1987 (28 U.S.C. 994 note) as though the authority under that
			 Act had not expired.</text>
				</subsection></section><section changed="added" id="id52FE04166D504354BFFAC7070AD44326" reported-display-style="italic"><enum>104.</enum><header>Effects of identity
			 theft on bankruptcy proceedings</header>
				<subsection id="ID8f38b172c35b40d69385b471967d620e"><enum>(a)</enum><header>Definitions</header><text>Section
			 101 of title 11, United States Code, is amended—</text>
					<paragraph id="IDed69982a43e64db8a507b0f4e022dc3e"><enum>(1)</enum><text>by redesignating
			 paragraph (27B) as paragraph (27D); and</text>
					</paragraph><paragraph id="IDe87d3913af5c403b9f34a5021aa13808"><enum>(2)</enum><text>by inserting after
			 paragraph (27A) the following:</text>
						<quoted-block changed="added" display-inline="no-display-inline" id="idA5EC9B6BB8BB437196009F6F636769E9" reported-display-style="italic" style="OLC">
							<paragraph id="ID3bb22de8a36146178e6a991181626573"><enum>(27B)</enum><text><quote>identity
				theft</quote> means a fraud committed or attempted using the personally
				identifiable information of another person;</text>
							</paragraph><paragraph id="IDa4cae35c1d4040058c3699a76921b5d1"><enum>(27C)</enum><text><quote>identity theft
				victim</quote> means a debtor who, as a result of an identify theft in any
				consecutive 12-month period during the 3-year period before the date on which a
				petition is filed under this title, had claims asserted against such debtor in
				excess of the least of—</text>
								<subparagraph id="ID0b1f59c51f88455096e1d67140ee2051"><enum>(A)</enum><text>$20,000;</text>
								</subparagraph><subparagraph id="ID49e5ee2a54dc421089978e60a8560c30"><enum>(B)</enum><text>50 percent of all claims
				asserted against such debtor; or</text>
								</subparagraph><subparagraph id="IDaf69a3187fd84fde8dbf931bf8eee25f"><enum>(C)</enum><text>25 percent of the
				debtor's gross income for such 12-month
				period.</text>
								</subparagraph></paragraph><after-quoted-block>.</after-quoted-block></quoted-block>
					</paragraph></subsection><subsection id="ID7ca86c31ef1d4905aff135c23e499ee9"><enum>(b)</enum><header>Prohibition</header><text>Section
			 707(b) of title 11, United States Code, is amended by adding at the end the
			 following:</text>
					<quoted-block changed="added" display-inline="no-display-inline" id="id2FEAD0E5739743E7AB41436CAD7E7CF0" reported-display-style="italic" style="OLC">
						<paragraph id="ID68bb70cf0e1145509a6198dffbbe3aa9" indent="up1"><enum>(8)</enum><text>No
				judge, United States trustee (or bankruptcy administrator, if any), trustee, or
				other party in interest may file a motion under paragraph (2) if the debtor is
				an identity theft
				victim.</text>
						</paragraph><after-quoted-block>.</after-quoted-block></quoted-block>
				</subsection></section></title><title id="idF823923C0B90487788A0439B5A654169"><enum>II</enum><header>Data
			 brokers</header>
			<section id="IDe447c45d508a4eceac923d23f27156c0"><enum>201.</enum><header>Transparency
			 and accuracy of data collection</header>
				<subsection id="ID5ef1a5d7920f442e8511ebad763bb79b"><enum>(a)</enum><header>In
			 general</header><text>Data brokers engaging in interstate commerce are subject
			 to the requirements of this title for any product or service offered to third
			 parties that allows access or use of sensitive personally identifiable
			 information.</text>
				</subsection><subsection id="ID38b0e3b0df144f1db76af36be35174b5"><enum>(b)</enum><header>Limitation</header><text>Notwithstanding
			 any other provision of this title, this section shall not apply to—</text>
					<paragraph id="ID7ba8e3ebb34947e096be36b15d339822"><enum>(1)</enum><text>any product or
			 service offered by a data broker engaging in interstate commerce where such
			 product or service is currently subject to, and in compliance with, access and
			 accuracy protections similar to those under subsections (c) through (f) of this
			 section under the Fair Credit Reporting Act (Public Law 91–508);</text>
					</paragraph><paragraph id="IDd8bc7350b33d44efb801991c9594ed1d"><enum>(2)</enum><text>any data broker
			 that is subject to regulation under the Gramm-Leach-Bliley Act (Public Law
			 106–102);</text>
					</paragraph><paragraph id="id2C6FD2E6DA354716AD838DF200E72ADD"><enum>(3)</enum><text>any data broker
			 currently subject to and in compliance with the data security requirements for
			 such entities under the Health Insurance Portability and Accountability Act
			 (Public Law 104–191), and its implementing regulations;</text>
					</paragraph><paragraph id="IDc0f4642652ad4cfc807ffc48c901746a"><enum>(4)</enum><text>information in a
			 personal electronic record that—</text>
						<subparagraph id="ID926e4ab368134b8f8c2144b1dc2461f3"><enum>(A)</enum><text>the data broker
			 has identified as inaccurate, but maintains for the purpose of aiding the data
			 broker in preventing inaccurate information from entering an individual's
			 personal electronic record; and</text>
						</subparagraph><subparagraph id="IDf355b3045cdd48c1822f93fe75b41f24"><enum>(B)</enum><text>is not maintained
			 primarily for the purpose of transmitting or otherwise providing that
			 information, or assessments based on that information, to non-affiliated third
			 parties; and</text>
						</subparagraph></paragraph><paragraph id="ID948931ace4664580a20f656cd8be5925"><enum>(5)</enum><text>information
			 concerning proprietary methodologies, techniques, scores, or algorithms
			 relating to fraud prevention not normally provided to third parties in the
			 ordinary course of business.</text>
					</paragraph></subsection><subsection id="ID4ffc3e4061eb495cb9e180fe4317af5c"><enum>(c)</enum><header>Disclosures to
			 individuals</header>
					<paragraph id="ID891adecdafe74a719c3bb7e176a9dbec"><enum>(1)</enum><header>In
			 general</header><text>A data broker shall, upon the request of an individual,
			 disclose to such individual for a reasonable fee all personal electronic
			 records pertaining to that individual maintained specifically for disclosure to
			 third parties that request information on that individual in the ordinary
			 course of business in the databases or systems of the data broker at the time
			 of such request.</text>
					</paragraph><paragraph id="ID11879646a8c8459a82322ecf97375d53"><enum>(2)</enum><header>Information on
			 how to correct inaccuracies</header><text>The disclosures required under
			 paragraph (1) shall also include guidance to individuals on procedures for
			 correcting inaccuracies.</text>
					</paragraph></subsection><subsection changed="added" id="id1A741AE49E27420D8142076CA2F56CE8" reported-display-style="italic"><enum>(d)</enum><header>Disclosure to
			 individuals of adverse actions taken by third parties</header>
					<paragraph id="idE34DFF0987924A6DBBE4B9B0AD3DDB48"><enum>(1)</enum><header>In
			 general</header><text>In addition to any other rights established under this
			 Act, if a person takes any adverse action with respect to any individual that
			 is based, in whole or in part, on any information contained in a personal
			 electronic record that is maintained, updated, or otherwise owned or possessed
			 by a data broker, such person, at no cost to the affected individual, shall
			 provide—</text>
						<subparagraph id="ID7ffaea0ba64a4827b605afd454e0b5b9"><enum>(A)</enum><text>written or electronic
			 notice of the adverse action to the individual;</text>
						</subparagraph><subparagraph id="ID895b67bd775d4e38a90921ed60ef319c"><enum>(B)</enum><text>to the individual, in
			 writing or electronically, the name, address, and telephone number of the data
			 broker that furnished the information to the person;</text>
						</subparagraph><subparagraph id="id513AD5550CAD4625ACAC7FE49952B931"><enum>(C)</enum><text>a copy of the information
			 such person obtained from the data broker; and</text>
						</subparagraph><subparagraph id="id74E97A7CBFA14CB786AC7C15B5B63B48"><enum>(D)</enum><text>information to the
			 individual on the procedures for correcting any inaccuracies in such
			 information.</text>
						</subparagraph></paragraph><paragraph id="idA6F09B96C8EB4D67B33CAAA4DD56A6B4"><enum>(2)</enum><header>Accepted methods of
			 notice</header><text>A person shall be in compliance with the notice
			 requirements under paragraph (1) if such person provides written or electronic
			 notice in the same manner and using the same methods as are required under
			 section 313(1) of this Act.</text>
					</paragraph></subsection><subsection id="IDe7f47b828c524e09ade1a5be3482448f"><enum>(<deleted-phrase reported-display-style="strikethrough">d</deleted-phrase><added-phrase reported-display-style="italic">e</added-phrase>)</enum><header>Accuracy
			 resolution process</header>
					<paragraph id="IDba5b406d200e4eea86382044cb6abc9a"><enum>(1)</enum><header>Information
			 from a public record or licensor</header>
						<subparagraph id="ID6c920096d7974dfcb4eb67aba8c92d27"><enum>(A)</enum><header>In
			 general</header><text>If an individual notifies a data broker of a dispute as
			 to the completeness or accuracy of information disclosed to such individual
			 under subsection (c) that is obtained from a public record source or a license
			 agreement, such data broker shall determine within 30 days whether the
			 information in its system accurately and completely records the information
			 available from the <deleted-phrase reported-display-style="strikethrough">public record source or</deleted-phrase>
			 licensor <added-phrase reported-display-style="italic">or public record
			 source</added-phrase>.</text>
						</subparagraph><subparagraph id="IDbed3e535f70e43e5acae274cce51f8fa"><enum>(B)</enum><header>Data broker
			 actions</header><text>If a data broker determines under subparagraph (A) that
			 the information in its systems does not accurately and completely record the
			 information available from a public record source or licensor, the data broker
			 shall—</text>
							<clause id="ID8a965599be5a4332baee772bef1fd310"><enum>(i)</enum><text>correct any
			 inaccuracies or incompleteness, and provide to such individual written notice
			 of such changes; and</text>
							</clause><clause id="ID0e179d0e15884933981e3308e2e67ab7"><enum>(ii)</enum><text>provide such
			 individual with the contact information of the public record or
			 licensor.</text>
							</clause></subparagraph></paragraph><paragraph id="IDecffc4013a1f48acbcaea78b9a7865e3"><enum>(2)</enum><header>Information not
			 from a public record source or licensor</header><text>If an individual notifies
			 a data broker of a dispute as to the completeness or accuracy of information
			 not from a public record or licensor that was disclosed to the individual under
			 subsection (c), the data broker shall, within 30 days of receiving notice of
			 such dispute—</text>
						<subparagraph id="ID1d6d082656ed4ab2a02d267343a2d496"><enum>(A)</enum><text>review and
			 consider free of charge any information submitted by such individual that is
			 relevant to the completeness or accuracy of the disputed information;
			 and</text>
						</subparagraph><subparagraph id="IDbc51b6376c174cc287b92279a25499cc"><enum>(B)</enum><text>correct any
			 information found to be incomplete or inaccurate and provide notice to such
			 individual of whether and what information was corrected, if any.</text>
						</subparagraph></paragraph><paragraph id="ID1881a4cb16b84048b95e3ac6cb273a5a"><enum>(3)</enum><header>Extension of
			 review period</header><text>The 30-day period described in paragraph (1) may be
			 extended for not more than 30 additional days if a data broker receives
			 information from the individual during the initial 30-day period that is
			 relevant to the completeness or accuracy of any disputed information.</text>
					</paragraph><paragraph id="ID50f4a0d2dc32477ea215f5fdc3ed385a"><enum>(4)</enum><header>Notice
			 identifying the data furnisher</header><text>If the completeness or accuracy of
			 any information not from a public record source or licensor that was disclosed
			 to an individual under subsection (c) is disputed by such individual, the data
			 broker shall provide, upon the request of such individual, the contact
			 information of any data furnisher that provided the disputed
			 information.</text>
					</paragraph><paragraph id="ID1a34c07593d940dd86e599d161d3392e"><enum>(5)</enum><header>Determination
			 that dispute is frivolous or irrelevant</header>
						<subparagraph id="ID59a3c2caa5524a44830c75d3d9931593"><enum>(A)</enum><header>In
			 general</header><text>Notwithstanding paragraphs (1) through (3), a data broker
			 may decline to investigate or terminate a review of information disputed by an
			 individual under those paragraphs if the data broker reasonably determines that
			 the dispute by the individual is frivolous or intended to perpetrate
			 fraud.</text>
						</subparagraph><subparagraph id="IDf63d4c29405f4999ad789f7ea14b3ff1"><enum>(B)</enum><header>Notice</header><text>A
			 data broker shall notify an individual of a determination under subparagraph
			 (A) within a reasonable time by any means available to such data broker.</text>
						</subparagraph></paragraph></subsection></section><section id="IDe5bc6f4fb182485eaed306444501525e"><enum>202.</enum><header>Enforcement</header>
				<subsection id="ID398d4ec1307d4f06897d972e814f3d21"><enum>(a)</enum><header>Civil
			 penalties</header>
					<paragraph id="IDd5e9e2debb2148a1af8cfa15849ef268"><enum>(1)</enum><header>Penalties</header><text>Any
			 data broker that violates the provisions of section 201 shall be subject to
			 civil penalties of not more than $1,000 per violation per day while such
			 violations persist, up to a maximum of $250,000 per violation.</text>
					</paragraph><paragraph id="ID17f322c46adc4851a85db713c6fe880b"><enum>(2)</enum><header>Intentional or
			 willful violation</header><text>A data broker that intentionally or willfully
			 violates the provisions of section 201 shall be subject to additional penalties
			 in the amount of $1,000 per violation per day, to a maximum of an additional
			 $250,000 per violation, while such violations persist.</text>
					</paragraph><paragraph id="ID4e8b76f5306248e1924a209ddfd374c9"><enum>(3)</enum><header>Equitable
			 relief</header><text>A data broker engaged in interstate commerce that violates
			 this section may be enjoined from further violations by a court of competent
			 jurisdiction.</text>
					</paragraph><paragraph id="ID13e613745540438c84f9a9cdb1a65123"><enum>(4)</enum><header>Other rights
			 and remedies</header><text>The rights and remedies available under this
			 subsection are cumulative and shall not affect any other rights and remedies
			 available under law.</text>
					</paragraph></subsection><subsection id="ID7928235f2c394835b5e3d77afefe1dcf"><enum>(b)</enum><header>Federal trade
			 commission authority</header><text>Any data broker shall have the provisions of
			 this title enforced against it by the Federal Trade Commission.</text>
				</subsection><subsection id="ID80713dcce96646f99c2edd271c2438b9"><enum>(c)</enum><header>State
			 enforcement</header>
					<paragraph id="IDe697a6a08bac4a389d6e1dda7aac2731"><enum>(1)</enum><header>Civil
			 actions</header><text>In any case in which the attorney general of a State or
			 any State or local law enforcement agency authorized by the State attorney
			 general or by State statute to prosecute violations of consumer protection law,
			 has reason to believe that an interest of the residents of that State has been
			 or is threatened or adversely affected by the acts or practices of a data
			 broker that violate this title, the State may bring a civil action on behalf of
			 the residents of that State in a district court of the United States of
			 appropriate jurisdiction, or any other court of competent jurisdiction,
			 to—</text>
						<subparagraph id="ID89fb438e37f04dabb7676d706b8f5d14"><enum>(A)</enum><text>enjoin that act
			 or practice;</text>
						</subparagraph><subparagraph id="IDcc70f9505cdd4d1aa7c58a36bd97a98d"><enum>(B)</enum><text>enforce
			 compliance with this title; or</text>
						</subparagraph><subparagraph id="ID51ad849463b9447f9ff9ada98e9dcfed"><enum>(C)</enum><text>obtain civil
			 penalties of not more than $1,000 per violation per day while such violations
			 persist, up to a maximum of $250,000 per violation.</text>
						</subparagraph></paragraph><paragraph id="ID7d5e0d91f23b452aa7f462b5b6518eea"><enum>(2)</enum><header>Notice</header>
						<subparagraph id="ID1892e5442ba5464199fb13e1aecea4d9"><enum>(A)</enum><header>In
			 general</header><text>Before filing an action under this subsection, the
			 attorney general of the State involved shall provide to the Federal Trade
			 Commission—</text>
							<clause id="IDa28f24f2a6b14ab29f5f6e95831e0d54"><enum>(i)</enum><text>a
			 written notice of that action; and</text>
							</clause><clause id="IDc06985d85d1d4daebcbbf715ca94337f"><enum>(ii)</enum><text>a
			 copy of the complaint for that action.</text>
							</clause></subparagraph><subparagraph id="IDa293ae70e23d4592a8c579e4370bc270"><enum>(B)</enum><header>Exception</header><text>Subparagraph
			 (A) shall not apply with respect to the filing of an action by an attorney
			 general of a State under this subsection, if the attorney general of a State
			 determines that it is not feasible to provide the notice described in
			 subparagraph (A) before the filing of the action.</text>
						</subparagraph><subparagraph id="ID43a0018520ee4de5ab76818810a576d9"><enum>(C)</enum><header>Notification
			 when practicable</header><text>In an action described under subparagraph (B),
			 the attorney general of a State shall provide the written notice and the copy
			 of the complaint to the Federal Trade Commission as soon after the filing of
			 the complaint as practicable.</text>
						</subparagraph></paragraph><paragraph id="ID47d72766655345fa809cf1bfadb0134d"><enum>(3)</enum><header>Federal trade
			 commission authority</header><text>Upon receiving notice under paragraph (2),
			 the Federal Trade Commission shall have the right to—</text>
						<subparagraph id="ID6821fa789cfc462aa409f90e4761fe69"><enum>(A)</enum><text>move to stay the
			 action, pending the final disposition of a pending Federal proceeding or action
			 as described in paragraph (4);</text>
						</subparagraph><subparagraph id="ID1be5846d9beb44a884387f5087ba4f17"><enum>(B)</enum><text>intervene in an
			 action brought under paragraph (1); and</text>
						</subparagraph><subparagraph id="ID7eb41f24604b42ea8ce7c604aabf9339"><enum>(C)</enum><text>file petitions
			 for appeal.</text>
						</subparagraph></paragraph><paragraph id="ID04055883d9b84f7dbb41852545613dc1"><enum>(4)</enum><header>Pending
			 proceedings</header><text>If the Federal Trade Commission has instituted a
			 proceeding or civil action for a violation of this title, no attorney general
			 of a State may, during the pendency of such proceeding or civil action, bring
			 an action under this subsection against any defendant named in such civil
			 action for any violation that is alleged in that civil action.</text>
					</paragraph><paragraph id="ID30947854f7394a84bef37dba3eaf0f72"><enum>(5)</enum><header>Rule of
			 construction</header><text>For purposes of bringing any civil action under
			 paragraph (1), nothing in this title shall be construed to prevent an attorney
			 general of a State from exercising the powers conferred on the attorney general
			 by the laws of that State to—</text>
						<subparagraph id="ID5340179ed41d4ca9b938c5c458bd6758"><enum>(A)</enum><text>conduct
			 investigations;</text>
						</subparagraph><subparagraph id="ID3ab5ac1932dd40ffa72d5bf7d0813c88"><enum>(B)</enum><text>administer oaths
			 and affirmations; or</text>
						</subparagraph><subparagraph id="ID45650d3b189541749fb700efb1c971b1"><enum>(C)</enum><text>compel the
			 attendance of witnesses or the production of documentary and other
			 evidence.</text>
						</subparagraph></paragraph><paragraph id="IDb7956dff4a454fe8ab0f5817abc2b8dc"><enum>(6)</enum><header>Venue; service
			 of process</header>
						<subparagraph id="IDacb4da8bdf994f32b1474c85b0a0afde"><enum>(A)</enum><header>Venue</header><text>Any
			 action brought under this subsection may be brought in the district court of
			 the United States that meets applicable requirements relating to venue under
			 section 1391 of title 28, United States Code.</text>
						</subparagraph><subparagraph id="ID7fb8803320ed49fc96807317bc95327f"><enum>(B)</enum><header>Service of
			 process</header><text>In an action brought under this subsection process may be
			 served in any district in which the defendant—</text>
							<clause id="IDea9ef869bcb944839d922a84ddff058f"><enum>(i)</enum><text>is
			 an inhabitant; or</text>
							</clause><clause id="IDa6772e58950f46b9a3ba39473e2d9abf"><enum>(ii)</enum><text>may be
			 found.</text>
							</clause></subparagraph></paragraph></subsection><subsection id="ID3008ccdecfbc4b34ba1e44a67151a3a5"><enum>(d)</enum><header>No private
			 cause of action</header><text>Nothing in this title establishes a private cause
			 of action against a data broker for violation of any provision of this
			 title.</text>
				</subsection></section><section id="ID10033cf1f27d420fab70142956e2f0b0"><enum>203.</enum><header>Relation to
			 state laws</header><text display-inline="no-display-inline">No requirement or
			 prohibition may be imposed under the laws of any State with respect to any
			 subject matter regulated under section 201, relating to individual access to,
			 and correction of, personal electronic records held by data brokers.</text>
			</section><section id="IDab58a1e4994746e3975f8bb335bea15c"><enum>204.</enum><header>Effective
			 date</header><text display-inline="no-display-inline">This title shall take
			 effect 180 days after the date of enactment of this Act.</text>
			</section></title><title id="idD725C42479864A1D94B301FF34A11C92"><enum>III</enum><header>Privacy and
			 security of personally identifiable information </header>
			<subtitle id="id3189B1C7B0974BA09A5D2EB0F2AA3456"><enum>A</enum><header>A
			 data privacy and security program</header>
				<section id="ID48089945808a49b592f4356d4079eae6"><enum>301.</enum><header>Purpose and
			 applicability of data privacy and security program</header>
					<subsection id="IDddbd1c5a93e94835af6783727a4e0d4d"><enum>(a)</enum><header>Purpose</header><text>The
			 purpose of this subtitle is to ensure standards for developing and implementing
			 administrative, technical, and physical safeguards to protect the security of
			 sensitive personally identifiable information.</text>
					</subsection><subsection id="ID1d16430a563849c88f30c306297d0517"><enum>(b)</enum><header>In
			 general</header><text>A business entity engaging in interstate commerce that
			 involves collecting, accessing, transmitting, using, storing, or disposing of
			 sensitive personally identifiable information in electronic or digital form on
			 10,000 or more United States persons is subject to the requirements for a data
			 privacy and security program under section 302 for protecting sensitive
			 personally identifiable information.</text>
					</subsection><subsection id="ID84c02c5382924cd5880326c0d63e96dc"><enum>(c)</enum><header>Limitations</header><text>Notwithstanding
			 any other obligation under this subtitle, this subtitle does not apply
			 to:</text>
						<paragraph id="ID560a85637f8c42c19982f35cb3f1461e"><enum>(1)</enum><header>Financial
			 institutions</header><text>Financial institutions—</text>
							<subparagraph id="IDa9ac03fede8c4d3bacfa4686a427f4f1"><enum>(A)</enum><text>subject to the
			 data security requirements and implementing regulations under the
			 Gramm-Leach-Bliley Act (15 U.S.C. 6801 et seq.); and</text>
							</subparagraph><subparagraph id="ID6a256ee27e134fe3af78121215ed174f"><enum>(B)</enum><text>subject
			 to—</text>
								<clause id="ID5c74fafda772492bbb9771f6c10c7e46"><enum>(i)</enum><text>examinations for
			 compliance with the requirements of this Act by a Federal Functional Regulator
			 or State Insurance Authority (as those terms are defined in section 509 of the
			 Gramm-Leach-Bliley Act (15 U.S.C. 6809)); or</text>
								</clause><clause id="IDa8fffe318bd242b5a4adabd150a5cce7"><enum>(ii)</enum><text>compliance with
			 part 314 of title 16, Code of Federal Regulations.</text>
								</clause></subparagraph></paragraph><paragraph id="ID1bea77b1d96049d19342fc06938e8260"><enum>(2)</enum><header>HIPPA regulated
			 entities</header>
							<subparagraph id="ID91b41aa91ccb4edda6d95f64add28769"><enum>(A)</enum><header>Covered
			 entities</header><text>Covered entities subject to the Health Insurance
			 Portability and Accountability Act of 1996 (42 U.S.C. 1301 et seq.), including
			 the data security requirements and implementing regulations of that Act.</text>
							</subparagraph><subparagraph id="IDe1bdc4f3ed43418f8c11f65dcf65e220"><enum>(B)</enum><header>Business
			 entities</header><text>A business entity shall be deemed in compliance with the
			 privacy and security program requirements under section 302 if the business
			 entity is acting as a <term>business associate</term> as that term is defined
			 in the Health Insurance Portability and Accountability Act of 1996 (42 U.S.C.
			 1301 et seq.) and is in compliance with requirements imposed under that Act and
			 its implementing regulations.</text>
							</subparagraph></paragraph><paragraph id="id752B5A0D23AD45DF819B11B11D4B6161"><enum>(3)</enum><header>Public
			 records</header><text>Public records not otherwise subject to a confidentiality
			 or nondisclosure requirement, or information obtained from a news report or
			 periodical.</text>
						</paragraph></subsection><subsection id="ID82fac130e6294b52bb29e212f466f2e0"><enum>(d)</enum><header>Safe
			 harbors</header>
						<paragraph id="IDf9419999edd14c728631734d1d83b15f"><enum>(1)</enum><header>In
			 general</header><text>A business entity shall be deemed in compliance with the
			 privacy and security program requirements under section 302 if the business
			 entity complies with or provides protection equal to industry standards, as
			 identified by the Federal Trade Commission, that are applicable to the type of
			 sensitive personally identifiable information involved in the ordinary course
			 of business of such business entity.</text>
						</paragraph><paragraph id="IDa4e3cf89f3ff4bd4872a39c8f94ede1b"><enum>(2)</enum><header>Limitation</header><text>Nothing
			 in this subsection shall be construed to permit, and nothing does permit, the
			 Federal Trade Commission to issue regulations requiring, or according greater
			 legal status to, the implementation of or application of a specific technology
			 or technological specifications for meeting the requirements of this
			 title.</text>
						</paragraph></subsection></section><section id="ID01a5628cdcfe4d1aa8f738063c6c15c2"><enum>302.</enum><header>Requirements
			 for a personal data privacy and security program</header>
					<subsection id="IDe06ec5d327734ccfbcb3025711448bcd"><enum>(a)</enum><header>Personal data
			 privacy and security program</header><text>A business entity subject to this
			 subtitle shall comply with the following safeguards and any other
			 administrative, technical, or physical safeguards identified by the Federal
			 Trade Commission in a rulemaking process pursuant to section 553 of title 5,
			 United States Code, for the protection of sensitive personally identifiable
			 information:</text>
						<paragraph id="ID32f2da88aaeb4e9a9356cdfa751bf96e"><enum>(1)</enum><header>Scope</header><text>A
			 business entity shall implement a comprehensive personal data privacy and
			 security program that includes administrative, technical, and physical
			 safeguards appropriate to the size and complexity of the business entity and
			 the nature and scope of its activities.</text>
						</paragraph><paragraph id="IDc422286e3b5e4282880c6d4dda9e61ef"><enum>(2)</enum><header>Design</header><text>The
			 personal data privacy and security program shall be designed to—</text>
							<subparagraph id="ID832224a994d04e60aa6c94efa1588cf6"><enum>(A)</enum><text>ensure the
			 privacy, security, and confidentiality of sensitive personally identifying
			 information;</text>
							</subparagraph><subparagraph id="IDabaa6ac0cead448288f59c56e7b28aae"><enum>(B)</enum><text>protect against
			 any anticipated vulnerabilities to the privacy, security, or integrity of
			 sensitive personally identifying information; and</text>
							</subparagraph><subparagraph id="ID878a6358d1d7420db96cfdb96d77744b"><enum>(C)</enum><text>protect against
			 unauthorized access to use of sensitive personally identifying information that
			 could result in substantial harm or inconvenience to any individual.</text>
							</subparagraph></paragraph><paragraph id="ID4b950d47eff549f6988d73682c9f11ce"><enum>(3)</enum><header>Risk
			 assessment</header><text>A business entity shall—</text>
							<subparagraph id="ID760c690786bc445d9bc2677d8f95f00e"><enum>(A)</enum><text>identify
			 reasonably foreseeable internal and external vulnerabilities that could result
			 in unauthorized access, disclosure, use, or alteration of sensitive personally
			 identifiable information or systems containing sensitive personally
			 identifiable information;</text>
							</subparagraph><subparagraph id="ID553382e18b2e43f1a9f3e85ed691c714"><enum>(B)</enum><text>assess the
			 likelihood of and potential damage from unauthorized access, disclosure, use,
			 or alteration of sensitive personally identifiable information;</text>
							</subparagraph><subparagraph id="ID676012ab86234c0aac757acb3a03d1f6"><enum>(C)</enum><text>assess the
			 sufficiency of its policies, technologies, and safeguards in place to control
			 and minimize risks from unauthorized access, disclosure, use, or alteration of
			 sensitive personally identifiable information; and</text>
							</subparagraph><subparagraph id="idC1C4AE57A42F48318FE5D2321E156F0A"><enum>(D)</enum><text>assess the
			 vulnerability of sensitive personally identifiable information during
			 destruction and disposal of such information, including through the disposal or
			 retirement of hardware.</text>
							</subparagraph></paragraph><paragraph id="ID746a427c8ac84218b69ce3920d5a9f26"><enum>(4)</enum><header>Risk management
			 and control</header><text>Each business entity shall—</text>
							<subparagraph id="ID0d4167033d5e428a96e89c8a307f2779"><enum>(A)</enum><text>design its
			 personal data privacy and security program to control the risks identified
			 under paragraph (3); and</text>
							</subparagraph><subparagraph id="ID7de281b8fa6d44e6a955e840dd025689"><enum>(B)</enum><text>adopt measures
			 commensurate with the sensitivity of the data as well as the size, complexity,
			 and scope of the activities of the business entity that—</text>
								<clause id="IDcb31d2a8cc9c45e7a827fb3cad9e004e"><enum>(i)</enum><text>control access to
			 systems and facilities containing sensitive personally identifiable
			 information, including controls to authenticate and permit access only to
			 authorized individuals;</text>
								</clause><clause id="IDd2ebc6309fec4e80957b78c33a013747"><enum>(ii)</enum><text>detect actual
			 and attempted fraudulent, unlawful, or unauthorized access, disclosure, use, or
			 alteration of sensitive personally identifiable information, including by
			 employees and other individuals otherwise authorized to have access;</text>
								</clause><clause id="IDcc80fec448474095b98acf35dbf50a95"><enum>(iii)</enum><text>protect
			 sensitive personally identifiable information during use, transmission,
			 storage, and disposal by encryption<added-phrase committee-id="SSJU00" reported-display-style="italic">,</added-phrase><added-phrase reported-display-style="italic"> redaction, or access controls that are widely
			 accepted as an effective industry practice or industry standard,
			 </added-phrase>or other reasonable means (including as directed for disposal of
			 records under section 628 of the Fair Credit Reporting Act (15 U.S.C. 1681w)
			 and the implementing regulations of such Act as set forth in section 682 of
			 title 16, Code of Federal Regulations);
			 <deleted-phrase reported-display-style="strikethrough">and</deleted-phrase></text>
								</clause><clause id="idDC2AB053A4F84CE899BDA286A381B0A4"><enum>(iv)</enum><text>ensure that
			 sensitive personally identifiable information is properly destroyed and
			 disposed of, including during the destruction of computers, diskettes, and
			 other electronic media that contain sensitive personally identifiable
			 information<deleted-phrase reported-display-style="strikethrough">.</deleted-phrase><added-phrase reported-display-style="italic">; and</added-phrase></text>
								</clause><clause changed="added" id="idA65F7941A0984AA792DB0EA52A944E3F" reported-display-style="italic"><enum>(v)</enum><text>trace access to records
			 containing sensitive personally identifiable information so that the business
			 entity can determine who accessed or acquired such sensitive personally
			 identifiable information pertaining to specific individuals; and</text>
								</clause><clause changed="added" id="id35C1CA572F594C458CA61F42D2275173" reported-display-style="italic"><enum>(vi)</enum><text>ensure that no third
			 party or customer of the business entity is authorized to access or acquire
			 sensitive personally identifiable information without the business entity first
			 performing sufficient due diligence to ascertain, with reasonable certainty,
			 that such information is being sought for a valid legal purpose.
			 <added-phrase reported-display-style="italic"></added-phrase></text>
								</clause></subparagraph></paragraph></subsection><subsection id="IDac0bcd641fab47ec8d169bbdd3e2cbd6"><enum>(b)</enum><header>Training</header><text>Each
			 business entity subject to this subtitle shall take steps to ensure employee
			 training and supervision for implementation of the data security program of the
			 business entity.</text>
					</subsection><subsection id="IDc8546a0096344b8093d2c7c421a2bf04"><enum>(c)</enum><header>Vulnerability
			 testing</header>
						<paragraph id="IDe55eff11713942b3b734ead03b647a72"><enum>(1)</enum><header>In
			 general</header><text>Each business entity subject to this subtitle shall take
			 steps to ensure regular testing of key controls, systems, and procedures of the
			 personal data privacy and security program to detect, prevent, and respond to
			 attacks or intrusions, or other system failures.</text>
						</paragraph><paragraph id="IDb7ebf96c0fd4459c97654057f389508c"><enum>(2)</enum><header>Frequency</header><text>The
			 frequency and nature of the tests required under paragraph (1) shall be
			 determined by the risk assessment of the business entity under subsection
			 (a)(3).</text>
						</paragraph></subsection><subsection id="IDa0671a094a6e446d8b3ead55be2ac24b"><enum>(d)</enum><header>Relationship to
			 service providers</header><text>In the event a business entity subject to this
			 subtitle engages service providers not subject to this subtitle, such business
			 entity shall—</text>
						<paragraph id="IDa0c9f487ec3f4cc3a43321f9fb1e75f6"><enum>(1)</enum><text>exercise
			 appropriate due diligence in selecting those service providers for
			 responsibilities related to sensitive personally identifiable information, and
			 take reasonable steps to select and retain service providers that are capable
			 of maintaining appropriate safeguards for the security, privacy, and integrity
			 of the sensitive personally identifiable information at issue; and</text>
						</paragraph><paragraph id="ID00c3ca79bcb34d02bbcc049d21cf0938"><enum>(2)</enum><text>require those
			 service providers by contract to implement and maintain appropriate measures
			 designed to meet the objectives and requirements governing entities subject to
			 section 301, this section, and subtitle B.</text>
						</paragraph></subsection><subsection id="ID0a463bfe19fa46a69db7e98862c0d304"><enum>(e)</enum><header>Periodic
			 assessment and personal data privacy and security
			 modernization</header><text>Each business entity subject to this subtitle shall
			 on a regular basis monitor, evaluate, and adjust, as appropriate its data
			 privacy and security program in light of any relevant changes in—</text>
						<paragraph id="ID0d4f9c7be89448b19bc7acc3df798c94"><enum>(1)</enum><text>technology;</text>
						</paragraph><paragraph id="ID78b825c133324ea99829bb80cdd35dac"><enum>(2)</enum><text>the sensitivity
			 of personally identifiable information;</text>
						</paragraph><paragraph id="ID5a4c0fdefdcd430f938a0d14c111ba57"><enum>(3)</enum><text>internal or
			 external threats to personally identifiable information; and</text>
						</paragraph><paragraph id="ID9e21f4e291504ec19aa24c9a45152c9e"><enum>(4)</enum><text>the changing
			 business arrangements of the business entity, such as—</text>
							<subparagraph id="IDde6f7259eddf4738b0ef8a759540216f"><enum>(A)</enum><text>mergers and
			 acquisitions;</text>
							</subparagraph><subparagraph id="ID15c1ca9356fe48a18ee457775ee5110f"><enum>(B)</enum><text>alliances and
			 joint ventures;</text>
							</subparagraph><subparagraph id="ID262c91919f004097b81ed65d35558174"><enum>(C)</enum><text>outsourcing
			 arrangements;</text>
							</subparagraph><subparagraph id="ID1d26ec6a0c5340f380d57ebaa82c9628"><enum>(D)</enum><text>bankruptcy;
			 and</text>
							</subparagraph><subparagraph id="ID9a63adfb34454b6aa70ae2d0e1db625e"><enum>(E)</enum><text>changes to
			 sensitive personally identifiable information systems.</text>
							</subparagraph></paragraph></subsection><subsection id="IDacc913ed0f0a43b39ed94b6a1b28f785"><enum>(f)</enum><header>Implementation
			 time line</header><text>Not later than 1 year after the date of enactment of
			 this Act, a business entity subject to the provisions of this subtitle shall
			 implement a data privacy and security program pursuant to this subtitle.</text>
					</subsection></section><section id="ID5cac3211a25b4f26a2628faea99c9f36"><enum>303.</enum><header>Enforcement</header>
					<subsection id="IDad519693d2a34f75a85128cd145d1103"><enum>(a)</enum><header>Civil
			 penalties</header>
						<paragraph id="ID8710c7c96e804d8493e3f127daa59e1d"><enum>(1)</enum><header>In
			 general</header><text>Any business entity that violates the provisions of
			 sections 301 or 302 shall be subject to civil penalties of not more than $5,000
			 per violation per day while such a violation exists, with a maximum of $500,000
			 per violation.</text>
						</paragraph><paragraph id="ID1eab52f9bdfe4428a9ec5ba12bcb6ecb"><enum>(2)</enum><header>Intentional or
			 willful violation</header><text>A business entity that intentionally or
			 willfully violates the provisions of sections 301 or 302 shall be subject to
			 additional penalties in the amount of $5,000 per violation per day while such a
			 violation exists, with a maximum of an additional $500,000 per
			 violation.</text>
						</paragraph><paragraph id="IDfffa7d0cf76c45fe9ea25f34a77f1893"><enum>(3)</enum><header>Equitable
			 relief</header><text>A business entity engaged in interstate commerce that
			 violates this section may be enjoined from further violations by a court of
			 competent jurisdiction.</text>
						</paragraph><paragraph id="ID1a0f43fcf8a843a992c5ec63ef09d71e"><enum>(4)</enum><header>Other rights
			 and remedies</header><text>The rights and remedies available under this section
			 are cumulative and shall not affect any other rights and remedies available
			 under law.</text>
						</paragraph></subsection><subsection id="id595483F7BE794C5680EAF7D333EA3302"><enum>(b)</enum><header>Federal trade
			 commission authority</header><text>Any data broker shall have the provisions of
			 this subtitle enforced against it by the Federal Trade Commission.</text>
					</subsection><subsection id="idCD3E66347B2A42B4A48CD9747536F0D7"><enum>(c)</enum><header>State
			 enforcement</header>
						<paragraph id="id810B9D5D00074BE393DF02F906BE3E4E"><enum>(1)</enum><header>Civil
			 actions</header><text>In any case in which the attorney general of a State or
			 any State or local law enforcement agency authorized by the State attorney
			 general or by State statute to prosecute violations of consumer protection law,
			 has reason to believe that an interest of the residents of that State has been
			 or is threatened or adversely affected by the acts or practices of a data
			 broker that violate this subtitle, the State may bring a civil action on behalf
			 of the residents of that State in a district court of the United States of
			 appropriate jurisdiction, or any other court of competent jurisdiction,
			 to—</text>
							<subparagraph id="id31812F04C77546E79C7AF0DB05FFA2F6"><enum>(A)</enum><text>enjoin that act
			 or practice;</text>
							</subparagraph><subparagraph id="id73BD179F12624B21BB1A5D184B17248A"><enum>(B)</enum><text>enforce
			 compliance with this subtitle; or</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idE21FE7A642D7412AB24279947B427352"><enum>(C)</enum><text>obtain civil
			 penalties of not more than $5,000 per violation per day while such violations
			 persist, up to a maximum of $500,000 per violation.</text>
							</subparagraph></paragraph><paragraph id="IDb035a912d0134c8e88e798c195f63e25"><enum>(2)</enum><header>Notice</header>
							<subparagraph id="ID10a26e09510c4bf08a652182d2d3bb76"><enum>(A)</enum><header>In
			 general</header><text>Before filing an action under this subsection, the
			 attorney general of the State involved shall provide to the Federal Trade
			 Commission—</text>
								<clause id="IDe1187d19b84a49b3993eb68910cba8cb"><enum>(i)</enum><text>a
			 written notice of that action; and</text>
								</clause><clause id="ID7abbfa78320441b9a8e2acdd3ea96ce0"><enum>(ii)</enum><text>a
			 copy of the complaint for that action.</text>
								</clause></subparagraph><subparagraph id="IDb390c579fafe4fddb34cc2f7f87d2850"><enum>(B)</enum><header>Exception</header><text>Subparagraph
			 (A) shall not apply with respect to the filing of an action by an attorney
			 general of a State under this subsection, if the attorney general of a State
			 determines that it is not feasible to provide the notice described in this
			 subparagraph before the filing of the action.</text>
							</subparagraph><subparagraph id="IDdf0df3125ba0430a9162deb90f36b0c3"><enum>(C)</enum><header>Notification
			 when practicable</header><text>In an action described under subparagraph (B),
			 the attorney general of a State shall provide the written notice and the copy
			 of the complaint to the Federal Trade Commission as soon after the filing of
			 the complaint as practicable.</text>
							</subparagraph></paragraph><paragraph id="IDce85cede46504f3fbd8c43a11d7e1e0e"><enum>(3)</enum><header>Federal trade
			 commission authority</header><text>Upon receiving notice under paragraph (2),
			 the Federal Trade Commission shall have the right to—</text>
							<subparagraph id="ID175a18cc4a0e48fa891fae7cf6a60117"><enum>(A)</enum><text>move to stay the
			 action, pending the final disposition of a pending Federal proceeding or action
			 as described in paragraph (4);</text>
							</subparagraph><subparagraph id="ID3fa662b5a06c48afa8b43d1041ff91fc"><enum>(B)</enum><text>intervene in an
			 action brought under paragraph (1); and</text>
							</subparagraph><subparagraph id="IDe446c3abe4644940b0d6455f0346a379"><enum>(C)</enum><text>file petitions
			 for appeal.</text>
							</subparagraph></paragraph><paragraph id="ID9bb7da67e82547119a40748f48dc65fd"><enum>(4)</enum><header>Pending
			 proceedings</header><text>If the Federal Trade Commission has instituted a
			 proceeding or action for a violation of this subtitle or any regulations
			 thereunder, no attorney general of a State may, during the pendency of such
			 proceeding or action, bring an action under this subsection against any
			 defendant named in such criminal proceeding or civil action for any violation
			 that is alleged in that proceeding or action.</text>
						</paragraph><paragraph id="ID3fc63de47c244814be783834e893beb2"><enum>(5)</enum><header>Rule of
			 construction</header><text>For purposes of bringing any civil action under
			 paragraph (1) nothing in this subtitle shall be construed to prevent an
			 attorney general of a State from exercising the powers conferred on the
			 attorney general by the laws of that State to—</text>
							<subparagraph id="IDa92fba318e92423fafb27f7543905061"><enum>(A)</enum><text>conduct
			 investigations;</text>
							</subparagraph><subparagraph id="ID5c4d666eb3e84136a49a3ea4be1c4c9e"><enum>(B)</enum><text>administer oaths
			 and affirmations; or</text>
							</subparagraph><subparagraph id="ID1cf4e5dcc7b9453ab5222aa74ed43bde"><enum>(C)</enum><text>compel the
			 attendance of witnesses or the production of documentary and other
			 evidence.</text>
							</subparagraph></paragraph><paragraph id="ID96d3ee3e4091401bbe650d295518f1ed"><enum>(6)</enum><header>Venue; service
			 of process</header>
							<subparagraph id="ID174f48431c8e486b9c4b9f86f7857876"><enum>(A)</enum><header>Venue</header><text>Any
			 action brought under this subsection may be brought in the district court of
			 the United States that meets applicable requirements relating to venue under
			 section 1391 of title 28, United States Code.</text>
							</subparagraph><subparagraph id="IDcdf640d6d7454abdaadcfb01381339e7"><enum>(B)</enum><header>Service of
			 process</header><text>In an action brought under this subsection process may be
			 served in any district in which the defendant—</text>
								<clause id="IDb59f7680c4684e92a42fcc0549f09203"><enum>(i)</enum><text>is
			 an inhabitant; or</text>
								</clause><clause id="IDf034fb9872a249af9a258587e9b38280"><enum>(ii)</enum><text>may be
			 found.</text>
								</clause></subparagraph></paragraph></subsection><subsection id="IDa4ae129d580443afb37c73c7e333ecb7"><enum>(d)</enum><header>No private
			 cause of action</header><text>Nothing in this subtitle establishes a private
			 cause of action against a business entity for violation of any provision of
			 this subtitle.</text>
					</subsection></section><section id="ID14b3a2c1aa4344dc97a4480451a1df47"><enum>304.</enum><header>Relation to
			 other laws</header>
					<subsection id="IDedb819fd16414fa18aaa55a6180d5a68"><enum>(a)</enum><header>In
			 general</header><text>No State may require any business entity subject to this
			 subtitle to comply with any requirements with respect to administrative,
			 technical, and physical safeguards for the protection of sensitive personally
			 identifying information.</text>
					</subsection><subsection id="ID3e1f4aed55cb4507a15acb3ae01bf3cf"><enum>(b)</enum><header>Limitations</header><text>Nothing
			 in this subtitle shall be construed to modify, limit, or supersede the
			 operation of the Gramm-Leach-Bliley Act or its implementing regulations,
			 including those adopted or enforced by States.</text>
					</subsection></section></subtitle><subtitle id="idBC4FEB9AFE2A4E93BF957FCB6F00B7E3"><enum>B</enum><header>Security breach
			 notification</header>
				<section id="ID5510cd0d499f4913941a3308d15e6a1c"><enum>311.</enum><header>Notice to
			 individuals</header>
					<subsection id="ID720d8016c4274ef7a360b8e4164e0fe0"><enum>(a)</enum><header>In
			 general</header><text>Any agency, or business entity engaged in interstate
			 commerce, that uses, accesses, transmits, stores, disposes of or collects
			 sensitive personally identifiable information shall, following the discovery of
			 a security breach <deleted-phrase reported-display-style="strikethrough">of the
			 systems or databases of such agency or business
			 entity</deleted-phrase><added-phrase reported-display-style="italic">of such
			 information,</added-phrase> notify any resident of the United States whose
			 sensitive personally identifiable information has been, or is reasonably
			 believed to have been, accessed, or acquired.</text>
					</subsection><subsection id="IDb2d0cfaa8a5b4717a05063975b9b42d1"><enum>(b)</enum><header>Obligation of
			 owner or licensee</header>
						<paragraph id="IDcacc642274d644e481d4de87564c1952"><enum>(1)</enum><header>Notice to owner
			 or licensee</header><text>Any agency, or business entity engaged in interstate
			 commerce, that uses, accesses, transmits, stores, disposes of, or collects
			 sensitive personally identifiable information that the agency or business
			 entity does not own or license shall notify the owner or licensee of the
			 information following the discovery of a security breach involving such
			 information.</text>
						</paragraph><paragraph id="IDa8a5bddb36854ef58c349f7d8f4e916b"><enum>(2)</enum><header>Notice by
			 owner, licensee or other designated third party</header><text>Nothing in this
			 subtitle shall prevent or abrogate an agreement between an agency or business
			 entity required to give notice under this section and a designated third party,
			 including an owner or licensee of the sensitive personally identifiable
			 information subject to the security breach, to provide the notifications
			 required under subsection (a).</text>
						</paragraph><paragraph id="ID8c3282340c68464c8cc16a7e96ac21b1"><enum>(3)</enum><header>Business entity
			 relieved from giving notice</header><text>A business entity obligated to give
			 notice under subsection (a) shall be relieved of such obligation if an owner or
			 licensee of the sensitive personally identifiable information subject to the
			 security breach, or other designated third party, provides such
			 notification.</text>
						</paragraph></subsection><subsection id="IDcba7ac64bcb3449d9c9ea5dad732fcaf"><enum>(c)</enum><header>Timeliness of
			 notification</header>
						<paragraph id="ID47e0ad09389e43368af2d01671e67128"><enum>(1)</enum><header>In
			 general</header><text>All notifications required under this section shall be
			 made without unreasonable delay following the discovery by the agency or
			 business entity of a security breach.</text>
						</paragraph><paragraph id="id053C9368FAB84DB48DBDF31BD947DFA8"><enum>(2)</enum><header>Reasonable
			 delay</header><text>Reasonable delay under this subsection may include any time
			 necessary to determine the scope of the security breach, prevent further
			 disclosures, and restore the reasonable integrity of the data system and
			 provide notice to law enforcement when required.</text>
						</paragraph><paragraph id="ID3e7e880e342546bd8c593af9fe9e1c03"><enum>(3)</enum><header>Burden of
			 proof</header><text>The agency, business entity, owner, or licensee required to
			 provide notification under this section shall have the burden of demonstrating
			 that all notifications were made as required under this subtitle, including
			 evidence demonstrating the reasons for any delay.</text>
						</paragraph></subsection><subsection id="IDe00e27f9a69d45aca089facd8a9a1fe8"><enum>(d)</enum><header>Delay of
			 notification authorized for law enforcement purposes</header>
						<paragraph id="ID06936b350f164c5885b1797fa476970b"><enum>(1)</enum><header>In
			 general</header><text>If a Federal law enforcement agency determines that the
			 notification required under this section would impede a criminal investigation,
			 such notification shall be delayed upon written notice from such Federal law
			 enforcement agency to the agency or business entity that experienced the
			 breach.</text>
						</paragraph><paragraph id="ID777040e96ce943efa72ca96e9edd8cd5"><enum>(2)</enum><header>Extended delay
			 of notification</header><text>If the notification required under subsection (a)
			 is delayed pursuant to paragraph (1), an agency or business entity shall give
			 notice 30 days after the day such law enforcement delay was invoked unless a
			 Federal law enforcement agency provides written notification that further delay
			 is necessary.</text>
						</paragraph><paragraph id="IDe8d332a9b4f846cea0d31c6733439553"><enum>(3)</enum><header>Law enforcement
			 immunity</header><text>No cause of action shall lie in any court against any
			 law enforcement agency for acts relating to the delay of notification for law
			 enforcement purposes under this subtitle.</text>
						</paragraph></subsection></section><section id="ID5dc909314300496fae2e47fd1f732bf2"><enum>312.</enum><header>Exemptions</header>
					<subsection id="IDc0d77acc21dc4bd09bb886123fe643e8"><enum>(a)</enum><header>Exemption for
			 national security and law enforcement</header>
						<paragraph id="ID5f8d9f0ccc2f464a8881c81fd09cd4da"><enum>(1)</enum><header>In
			 general</header><text>Section 311 shall not apply to an agency or business
			 entity if the agency or business entity certifies, in writing, that
			 notification of the security breach as required by section 311 reasonably could
			 be expected to—</text>
							<subparagraph id="ID37a53412e42e4e18954878bf2b16dcb3"><enum>(A)</enum><text>cause damage to
			 the national security; or</text>
							</subparagraph><subparagraph id="ID0d053913bc2b400d8df6e3ff2775efac"><enum>(B)</enum><text>hinder a law
			 enforcement investigation or the ability of the agency to conduct law
			 enforcement investigations.</text>
							</subparagraph></paragraph><paragraph id="IDef500e6acfb34c17859262dc8e6af033"><enum>(2)</enum><header>Limits on
			 certifications</header><text>An agency
			 <added-phrase reported-display-style="italic">or business entity</added-phrase>
			 may not execute a certification under paragraph (1) to—</text>
							<subparagraph id="IDf487a4dfaf624465aa7aa15fd61bb942"><enum>(A)</enum><text>conceal
			 violations of law, inefficiency, or administrative error;</text>
							</subparagraph><subparagraph id="ID51e0f169985f4f06a8b55baf00b4c2b4"><enum>(B)</enum><text>prevent
			 embarrassment to a business entity, organization, or agency; or</text>
							</subparagraph><subparagraph id="IDf3bc9fee9cca49da98fc288ad90f2fc8"><enum>(C)</enum><text>restrain
			 competition.</text>
							</subparagraph></paragraph><paragraph id="ID588bcbb0cc3f49cea8884f01cbd0f4a1"><enum>(3)</enum><header>Notice</header><text>In
			 every case in which an agency <added-phrase reported-display-style="italic">or
			 business agency</added-phrase> issues a certification under paragraph (1), the
			 certification, accompanied by a description of the factual basis for the
			 certification, shall be immediately provided to the United States Secret
			 Service.</text>
						</paragraph><paragraph changed="added" id="ID03a548d7bf3d433693c4ab2b1bde7280" reported-display-style="italic"><enum>(4)</enum><header>Secret service review
			 of certifications</header>
							<subparagraph id="ID1602d3c72ed54448a19dbf73919739f8"><enum>(A)</enum><header>In
			 general</header><text>The United States Secret Service may review a
			 certification provided by an agency under paragraph (3), and shall review a
			 certification provided by a business entity under paragraph (3), to determine
			 whether an exemption under paragraph (1) is merited. Such review shall be
			 completed not later than 10 business days after the date of receipt of the
			 certification, except as provided in paragraph (5)(C).</text>
							</subparagraph><subparagraph id="IDe602279f6bae4c49be04bb7c236a80cd"><enum>(B)</enum><header>Notice</header><text>Upon
			 completing a review under subparagraph (A) the United States Secret Service
			 shall immediately notify the agency or business entity, in writing, of its
			 determination of whether an exemption under paragraph (1) is merited.</text>
							</subparagraph><subparagraph id="IDb2f94c610bf4422ead6561388120e2cd"><enum>(C)</enum><header>Exemption</header><text>The
			 exemption under paragraph (1) shall not apply if the United States Secret
			 Service determines under this paragraph that the exemption is not
			 merited.</text>
							</subparagraph></paragraph><paragraph changed="added" id="IDf148dfa1623544b0a9caa32d0c71db86" reported-display-style="italic"><enum>(5)</enum><header>Additional authority of
			 the secret service</header>
							<subparagraph id="ID6517c455849e4249b1b05f812b7277c4"><enum>(A)</enum><header>In
			 general</header><text>In determining under paragraph (4) whether an exemption
			 under paragraph (1) is merited, the United States Secret Service may request
			 additional information from the agency or business entity regarding the basis
			 for the claimed exemption, if such additional information is necessary to
			 determine whether the exemption is merited.</text>
							</subparagraph><subparagraph id="ID431a29e012304bc493848737c25210e5"><enum>(B)</enum><header>Required
			 compliance</header><text>Any agency or business entity that receives a request
			 for additional information under subparagraph (A) shall cooperate with any such
			 request.</text>
							</subparagraph><subparagraph id="ID0b31ef44ccc14992880aa9343f54477c"><enum>(C)</enum><header>Timing</header><text>If
			 the United States Secret Service requests additional information under
			 subparagraph (A), the United States Secret Service shall notify the agency or
			 business entity not later than 10 business days after the date of receipt of
			 the additional information whether an exemption under paragraph (1) is
			 merited.</text>
							</subparagraph></paragraph></subsection><subsection id="ID7b2a1925c2b546dab03966fdcd2c38f9"><enum>(b)</enum><header>Safe
			 harbor</header><text>An agency or business entity will be exempt from the
			 notice requirements under section 311, if—</text>
						<paragraph changed="deleted" id="ID5c3c24aa77054f2fa7fc61c37bd976c4" reported-display-style="strikethrough"><enum>(1)</enum><text>a risk assessment
			 concludes that there is no significant risk that the security breach has
			 resulted in, or will result in, harm to the individuals whose sensitive
			 personally identifiable information was subject to the security breach;</text>
						</paragraph><paragraph changed="added" id="IDd75777fcdf0c44d3b5b97deb02f526f1" reported-display-style="italic"><enum>(1)</enum><text>a risk assessment
			 concludes that—</text>
							<subparagraph id="idF2E9AC39B8CC47B286C04FB11863338F"><enum>(A)</enum><text>there is no significant
			 risk that a security breach has resulted in, or will result in, harm to the
			 individuals whose sensitive personally identifiable information was subject to
			 the security breach, with the encryption of such information establishing a
			 presumption that no significant risk exists; or</text>
							</subparagraph><subparagraph id="IDec967b93635b4b2fa9d0b310a875ac0e"><enum>(B)</enum><text>there is no significant
			 risk that a security breach has resulted in, or will result in, harm to the
			 individuals whose sensitive personally identifiable information was subject to
			 the security breach, with the rendering of such sensitive personally
			 identifiable information indecipherable through the use of best practices or
			 methods, such as redaction, access controls, or other such mechanisms, which
			 are widely accepted as an effective industry practice, or an effective industry
			 standard, establishing a presumption that no significant risk exist;</text>
							</subparagraph></paragraph><paragraph id="idB38244735D794F688042D7727E960120"><enum>(2)</enum><text>without
			 unreasonable delay, but not later than 45 days after the discovery of a
			 security breach, unless extended by the United States Secret Service, the
			 agency or business entity notifies the United States Secret Service, in
			 writing, of—</text>
							<subparagraph id="ID1bdadecacee840c093363c08c8e6258d"><enum>(A)</enum><text>the results of
			 the risk assessment; and</text>
							</subparagraph><subparagraph id="IDbe57df04f7994eb4a496e4a803663bee"><enum>(B)</enum><text>its decision to
			 invoke the risk assessment exemption; and</text>
							</subparagraph></paragraph><paragraph id="ID36a5edeb67b54aea843d0e691050cc89"><enum>(3)</enum><text>the United States
			 Secret Service does not indicate, in writing, within 10
			 <added-phrase reported-display-style="italic">business</added-phrase> days from
			 receipt of the decision, that notice should be given.</text>
						</paragraph></subsection><subsection id="ID3137a79e39dd461e8ed1121bbe2cc8c4"><enum>(c)</enum><header>Financial fraud
			 prevention exemption</header>
						<paragraph id="ID2fa5f58f805649e59111c250cd64d89c"><enum>(1)</enum><header>In
			 general</header><text>A business entity will be exempt from the notice
			 requirement under section 311 if the business entity utilizes or participates
			 in a security program that—</text>
							<subparagraph id="ID1e3ddaeecac341d3ac43346c1b30b6e4"><enum>(A)</enum><text>is designed to
			 block the use of the sensitive personally identifiable information to initiate
			 unauthorized financial transactions before they are charged to the account of
			 the individual; and</text>
							</subparagraph><subparagraph id="ID4e382831c69c4cb7898e45b7562f0db5"><enum>(B)</enum><text>provides for
			 notice to affected individuals after a security breach that has resulted in
			 fraud or unauthorized transactions.</text>
							</subparagraph></paragraph><paragraph id="IDbbcd5b778fad470b9d59c081de9dd58d"><enum>(2)</enum><header>Limitation</header><text>The
			 exemption by this subsection does not apply
			 <deleted-phrase reported-display-style="strikethrough">if the information
			 subject to the security breach includes sensitive personally identifiable
			 information in addition to the sensitive personally identifiable information
			 identified in section 3</deleted-phrase><added-phrase reported-display-style="italic">if—</added-phrase></text>
							<subparagraph changed="added" id="id537D1A12D0264326A2201A03B154946C" reported-display-style="italic"><enum>(A)</enum><text>the information subject
			 to the security breach includes sensitive personally identifiable information,
			 other than a credit card or credit card security code, of any type of the
			 sensitive personally identifiable information identified in section 3;
			 or</text>
							</subparagraph><subparagraph changed="added" commented="no" display-inline="no-display-inline" id="idB059C50331DE456591C43D831EBEA9B5" reported-display-style="italic"><enum>(B)</enum><text display-inline="yes-display-inline">the security breach includes both the
			 individual's credit card number and the individual’s first and last name.
			 <added-phrase reported-display-style="italic"></added-phrase></text>
							</subparagraph></paragraph></subsection></section><section id="IDbe5d0d5a9f634bfbbae2e9371a7cb5ab"><enum>313.</enum><header>Methods of
			 notice</header><text display-inline="no-display-inline">An agency, or business
			 entity shall be in compliance with section 311 if it provides both:</text>
					<paragraph id="ID19cfa3779734495ba271ec2ec3a85bd9"><enum>(1)</enum><header>Individual
			 notice</header>
						<subparagraph id="ID852b07c2909f42379ca05f7a4131f093"><enum>(A)</enum><text>Written
			 notification to the last known home mailing address of the individual in the
			 records of the agency or business entity;</text>
						</subparagraph><subparagraph id="ID68509b55bd4c4326af03b115762bf2e1"><enum>(B)</enum><text>Telephone notice
			 to the individual personally; or</text>
						</subparagraph><subparagraph id="ID97a508ad4f444592bf57a3a5e307dc02"><enum>(C)</enum><text><deleted-phrase reported-display-style="strikethrough">Electronic notice, if the primary method
			 used by the agency or business entity to communicate with the individual is by
			 electronic means, or</deleted-phrase><added-phrase reported-display-style="italic">E-mail notice, if </added-phrase>the individual
			 has consented to receive such notice and the notice is consistent with the
			 provisions permitting electronic transmission of notices under section 101 of
			 the Electronic Signatures in Global and National Commerce Act (15 U.S.C.
			 7001).</text>
						</subparagraph></paragraph><paragraph id="ID0db86297bf754ae4a902e952ee3f2f54"><enum>(2)</enum><header>Media
			 notice</header><text>Notice to major media outlets serving a State or
			 jurisdiction, if the number of residents of such State whose sensitive
			 personally identifiable information was, or is reasonably believed to have
			 been, acquired by an unauthorized person exceeds 5,000.</text>
					</paragraph></section><section id="ID80d1a786110544b1b9b1a5fa3fc173b3"><enum>314.</enum><header>Content of
			 notification</header>
					<subsection id="IDfa2d92fea3304ca696af6618f796eae0"><enum>(a)</enum><header>In
			 general</header><text>Regardless of the method by which notice is provided to
			 individuals under section 313, such notice shall include, to the extent
			 possible—</text>
						<paragraph id="IDceb22bde1f7a4d6c8796d46691c4cbb8"><enum>(1)</enum><text>a description of
			 the categories of sensitive personally identifiable information that was, or is
			 reasonably believed to have been, acquired by an unauthorized person;</text>
						</paragraph><paragraph id="ID28e1b7f46b724a5b9a2ce60cc5131cb7"><enum>(2)</enum><text>a toll-free
			 number <deleted-phrase reported-display-style="strikethrough">or, if the
			 primary method used by the agency or business entity to communicate with the
			 individual is by electronic means, an electronic mail
			 address</deleted-phrase>—</text>
							<subparagraph id="IDbd40229a7320422989ee3c0ac557bd8b"><enum>(A)</enum><text>that the
			 individual may use to contact the agency or business entity, or the agent of
			 the agency or business entity; and</text>
							</subparagraph><subparagraph id="IDfc951cf3f101457c8627707bc09e9e0f"><enum>(B)</enum><text>from which the
			 individual may learn what types of sensitive personally identifiable
			 information the agency or business entity maintained about that individual;
			 and</text>
							</subparagraph></paragraph><paragraph id="IDc5bea62ecdf44e3a8787fd9191a02c54"><enum>(3)</enum><text>the toll-free
			 contact telephone numbers and addresses for the major credit reporting
			 agencies.</text>
						</paragraph></subsection><subsection id="IDdb1385c3b8ef44f2b26816b9ae6527dd"><enum>(b)</enum><header>Additional
			 content</header><text>Notwithstanding section 319, a State may require that a
			 notice under subsection (a) shall also include information regarding victim
			 protection assistance provided for by that State.</text>
					</subsection></section><section id="ID82ad6f96b46a4c7388f833d7611a6fc3"><enum>315.</enum><header>Coordination
			 of notification with credit reporting agencies</header><text display-inline="no-display-inline">If an agency or business entity is required
			 to provide notification to more than
			 <deleted-phrase reported-display-style="strikethrough">1,000
			 individuals</deleted-phrase><added-phrase reported-display-style="italic">5,000
			 individuals</added-phrase> under section 311(a), the agency or business entity
			 shall also notify<deleted-phrase reported-display-style="strikethrough">,
			 without unreasonable delay,</deleted-phrase> all consumer reporting agencies
			 that compile and maintain files on consumers on a nationwide basis (as defined
			 in section 603(p) of the Fair Credit Reporting Act (15 U.S.C. 1681a(p)) of the
			 timing and distribution of the notices.
			 <added-phrase reported-display-style="italic">Such notice shall be given to the
			 consumer credit reporting agencies without unreasonable delay and, if it will
			 not delay notice to the affected individuals, prior to the distribution of
			 notices to the affected individuals.</added-phrase></text>
				</section><section commented="no" display-inline="no-display-inline" id="IDde1241e504f94594beb8e50db8943996" section-type="subsequent-section"><enum>316.</enum><header>Notice to law
			 enforcement</header>
					<subsection id="ID6470f926c275412da556385924db03f0"><enum>(a)</enum><header>Secret
			 service</header><text>Any business entity or agency shall
			 <deleted-phrase reported-display-style="strikethrough">give notice of a
			 security breach to the United States Secret
			 Service</deleted-phrase><added-phrase reported-display-style="italic">notify
			 the United States Secret Service of the fact that a security breach has
			 occurred</added-phrase> if—</text>
						<paragraph id="ID25eedd40ea824dffb164a4b7c3699d78"><enum>(1)</enum><text>the number of
			 individuals whose sensitive personally identifying information was, or is
			 reasonably believed to have been acquired by an unauthorized person exceeds
			 10,000;</text>
						</paragraph><paragraph id="ID274b8ba63d414bbea3287932981bcb9e"><enum>(2)</enum><text>the security
			 breach involves a database, networked or integrated databases, or other data
			 system containing the sensitive personally identifiable information of more
			 than 1,000,000 individuals nationwide;</text>
						</paragraph><paragraph id="IDd6ac3a83b97545cba8b1492d56e51717"><enum>(3)</enum><text>the security
			 breach involves databases owned by the Federal Government; or</text>
						</paragraph><paragraph id="ID1f9e4a10bebc46e6a27dd33efeb1c501"><enum>(4)</enum><text>the security
			 breach involves primarily sensitive personally identifiable information of
			 individuals known to the agency or business entity to be employees and
			 contractors of the Federal Government involved in national security or law
			 enforcement.</text>
						</paragraph></subsection><subsection id="ID2876b95d5ce348b68756b462b093b46c"><enum>(b)</enum><header>Notice to other
			 law enforcement agencies</header><text>The United States Secret Service shall
			 be responsible for notifying—</text>
						<paragraph id="IDc6061b421a474781bb0db35ef5bf4fa1"><enum>(1)</enum><text>the Federal
			 Bureau of Investigation, if the security breach involves espionage, foreign
			 counterintelligence, information protected against unauthorized disclosure for
			 reasons of national defense or foreign relations, or Restricted Data (as that
			 term is defined in section 11y of the Atomic Energy Act of 1954 (42 U.S.C.
			 2014(y)), except for offenses affecting the duties of the United States Secret
			 Service under section 3056(a) of title 18, United States Code;</text>
						</paragraph><paragraph id="ID2f36ab20661346abb989fad28adfa9f8"><enum>(2)</enum><text>the United States
			 Postal Inspection Service, if the security breach involves mail fraud;
			 and</text>
						</paragraph><paragraph id="IDcdf577b7108b42459b612171122e7e16"><enum>(3)</enum><text>the attorney
			 general of each State affected by the security breach.</text>
						</paragraph></subsection><subsection changed="deleted" id="IDb3d0b44936e941a6b7a3e83220e3edd1" reported-display-style="strikethrough"><enum>(c)</enum><header>14-Day
			 rule</header><text>The notices to Federal law enforcement and the attorney
			 general of each State affected by a security breach required under this section
			 shall be delivered as promptly as possible, but not later than 14 days after
			 discovery of the events requiring notice.</text>
					</subsection><subsection changed="added" id="idF9AAB61503E149CB80A21B96C66251B8" reported-display-style="italic"><enum>(c)</enum><header>Timing of
			 notices</header><text>The notices required under this section shall be
			 delivered as follows:</text>
						<paragraph id="IDc7204f9082b7462e811801d0ff03a6f9"><enum>(1)</enum><text>Notice under subsection
			 (a) shall be delivered as promptly as possible, but not later than 14 days
			 after discovery of the events requiring notice.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID8ea1687feefa47b48adfa72874d9a9c8"><enum>(2)</enum><text>Notice under subsection
			 (b) shall be delivered not later than 14 days after the Service receives notice
			 of a security breach from an agency or business entity.</text>
						</paragraph></subsection></section><section id="ID300c058705674d1fa8a20180588bc781"><enum>317.</enum><header>Enforcement</header>
					<subsection id="IDbe141416b255483ab71bcf923f75d07e"><enum>(a)</enum><header>Civil actions
			 by the Attorney General</header><text>The Attorney General may bring a civil
			 action in the appropriate United States district court against any business
			 entity that engages in conduct constituting a violation of this subtitle and,
			 upon proof of such conduct by a preponderance of the evidence, such business
			 entity shall be subject to a civil penalty of not more than $1,000 per day per
			 individual whose sensitive personally identifiable information was, or is
			 reasonably believed to have been, accessed or acquired by an unauthorized
			 person, up to a maximum of $1,000,000 per violation, unless such conduct is
			 found to be willful or intentional.</text>
					</subsection><subsection id="ID631759b47738493ba66ec30f99662368"><enum>(b)</enum><header>Injunctive
			 actions by the Attorney General</header>
						<paragraph id="idA40BA83000324B59A06AB9324F2EE801"><enum>(1)</enum><header>In
			 general</header><text>If it appears that a business entity has engaged, or is
			 engaged, in any act or practice constituting a violation of this subtitle, the
			 Attorney General may petition an appropriate district court of the United
			 States for an order—</text>
							<subparagraph id="ID74548a65207a4be1b5560768fd8301ec"><enum>(A)</enum><text>enjoining such
			 act or practice; or</text>
							</subparagraph><subparagraph id="IDeb83e5afed4e49eca123a19958cb01d7"><enum>(B)</enum><text>enforcing
			 compliance with this subtitle.</text>
							</subparagraph></paragraph><paragraph id="idA696A113E8B84FC592D67CA706DB4191"><enum>(2)</enum><header>Issuance of
			 order</header><text>A court may issue an order under paragraph (1), if the
			 court finds that the conduct in question constitutes a violation of this
			 subtitle.</text>
						</paragraph></subsection><subsection id="ID2d946cff5da64c3eacb4d51276222d66"><enum>(c)</enum><header>Other rights
			 and remedies</header><text>The rights and remedies available under this
			 subtitle are cumulative and shall not affect any other rights and remedies
			 available under law.</text>
					</subsection><subsection id="ID5874a4e4f1ba4c40b090e66b9db432eb"><enum>(d)</enum><header>Fraud
			 alert</header><text>Section 605A(b)(1) of the Fair Credit Reporting Act (15
			 U.S.C. 1681c–1(b)(1)) is amended by inserting <quote>, or evidence that the
			 consumer has received notice that the consumer's financial information has or
			 may have been compromised,</quote> after <quote>identity theft
			 report</quote>.</text>
					</subsection></section><section id="ID28d22f15074d4f239f64734d16e27d82"><enum>318.</enum><header>Enforcement by
			 State attorneys general</header>
					<subsection id="ID158448a7945943d2800a68223fa1c66f"><enum>(a)</enum><header>In
			 general</header>
						<paragraph id="ID5e7013c2684b41fcaaa6367e9a467271"><enum>(1)</enum><header>Civil
			 actions</header><text>In any case in which the attorney general of a State or
			 any State or local law enforcement agency authorized by the State attorney
			 general or by State statute to prosecute violations of consumer protection law,
			 has reason to believe that an interest of the residents of that State has been
			 or is threatened or adversely affected by the engagement of a business entity
			 in a practice that is prohibited under this subtitle, the State or the State or
			 local law enforcement agency on behalf of the residents of the agency’s
			 jurisdiction, may bring a civil action on behalf of the residents of the State
			 or jurisdiction in a district court of the United States of appropriate
			 jurisdiction or any other court of competent jurisdiction, including a State
			 court, to—</text>
							<subparagraph id="ID06956a544afc45749fc0dbd4ca0ac7b0"><enum>(A)</enum><text>enjoin that
			 practice;</text>
							</subparagraph><subparagraph id="ID9c8b6e64896e4dac88bd5fde14d8348f"><enum>(B)</enum><text>enforce
			 compliance with this subtitle; or</text>
							</subparagraph><subparagraph id="ID1e58ea4082c74d2ca134ca9129b3c6bc"><enum>(C)</enum><text>civil penalties
			 of not more than $1,000 per day per individual whose sensitive personally
			 identifiable information was, or is reasonably believed to have been, accessed
			 or acquired by an unauthorized person, up to a maximum of $1,000,000 per
			 violation, unless such conduct is found to be willful or intentional.</text>
							</subparagraph></paragraph><paragraph id="IDcac299cc128a49aaa541ed6dd90eb98c"><enum>(2)</enum><header>Notice</header>
							<subparagraph id="ID36cb88ea917c4f3bbfd3588bf949c4e0"><enum>(A)</enum><header>In
			 general</header><text>Before filing an action under paragraph (1), the attorney
			 general of the State involved shall provide to the Attorney General of the
			 United States—</text>
								<clause id="ID529bbf03fe7f4c7594b9508261fe891a"><enum>(i)</enum><text>written notice of
			 the action; and</text>
								</clause><clause id="IDe2292626c56a40f7aa11edc6929dcaf4"><enum>(ii)</enum><text>a
			 copy of the complaint for the action.</text>
								</clause></subparagraph><subparagraph id="ID0ad31433f66a4571a9f315c10cdd38c2"><enum>(B)</enum><header>Exemption</header>
								<clause id="ID9c3e5026e335415f94ddf78c665486e0"><enum>(i)</enum><header>In
			 general</header><text>Subparagraph (A) shall not apply with respect to the
			 filing of an action by an attorney general of a State under this subtitle, if
			 the State attorney general determines that it is not feasible to provide the
			 notice described in such subparagraph before the filing of the action.</text>
								</clause><clause id="ID29e7139ab7c24cd79ce8b2cad0fba4b8"><enum>(ii)</enum><header>Notification</header><text>In
			 an action described in clause (i), the attorney general of a State shall
			 provide notice and a copy of the complaint to the Attorney General at the time
			 the State attorney general files the action.</text>
								</clause></subparagraph></paragraph></subsection><subsection id="IDb4eb145eecea482ab7ecbe2f6d40f36c"><enum>(b)</enum><header>Federal
			 proceedings</header><text>Upon receiving notice under subsection (a)(2), the
			 Attorney General shall have the right to—</text>
						<paragraph id="ID26f41fd7f1cf46ffad598e468846a90a"><enum>(1)</enum><text>move to stay the
			 action, pending the final disposition of a pending Federal proceeding or
			 action;</text>
						</paragraph><paragraph id="id4E300CFE489848D1B21A6A1A6258C25E"><enum>(2)</enum><text>initiate an
			 action in the appropriate United States district court under section 317 and
			 move to consolidate all pending actions, including State actions, in such
			 court;</text>
						</paragraph><paragraph id="ID66487e1b00654427bbd02a953c7f3344"><enum>(3)</enum><text>intervene in an
			 action brought under subsection (a)(2); and</text>
						</paragraph><paragraph id="ID6fb3b32f5626404b9d0907977a93d1d0"><enum>(4)</enum><text>file petitions
			 for appeal.</text>
						</paragraph></subsection><subsection id="IDb15d3714cf524105a323f95c838f931c"><enum>(c)</enum><header>Pending
			 proceedings</header><text>If the Attorney General has instituted a proceeding
			 or action for a violation of this subtitle or any regulations thereunder, no
			 attorney general of a State may, during the pendency of such proceeding or
			 action, bring an action under this subtitle against any defendant named in such
			 criminal proceeding or civil action for any violation that is alleged in that
			 proceeding or action.</text>
					</subsection><subsection id="ID11b3d09326ab42b5a7039ab72e901f56"><enum>(d)</enum><header>Construction</header><text>For
			 purposes of bringing any civil action under subsection (a), nothing in this
			 subtitle regarding notification shall be construed to prevent an attorney
			 general of a State from exercising the powers conferred on such attorney
			 general by the laws of that State to—</text>
						<paragraph id="IDf0b18861c7dd4211aefde7a73679597c"><enum>(1)</enum><text>conduct
			 investigations;</text>
						</paragraph><paragraph id="IDc52d3767f683458e8510bfda8261c65e"><enum>(2)</enum><text>administer oaths
			 or affirmations; or</text>
						</paragraph><paragraph id="IDa7edebada22b454c840d70f0fff4c763"><enum>(3)</enum><text>compel the
			 attendance of witnesses or the production of documentary and other
			 evidence.</text>
						</paragraph></subsection><subsection id="ID79f340f19ca84e1b8a9b8f1ce237716e"><enum>(e)</enum><header>Venue; service
			 of process</header>
						<paragraph id="ID2c88083250b3444a832e60e4ce40a2ba"><enum>(1)</enum><header>Venue</header><text>Any
			 action brought under subsection (a) may be brought in—</text>
							<subparagraph id="IDf0a91014a2a84fd99bea1e2c7bdcdca3"><enum>(A)</enum><text>the district
			 court of the United States that meets applicable requirements relating to venue
			 under section 1391 of title 28, United States Code; or</text>
							</subparagraph><subparagraph id="ID8639d88534d8455097a8b05a580b0de3"><enum>(B)</enum><text>another court of
			 competent jurisdiction.</text>
							</subparagraph></paragraph><paragraph id="IDf957252071c14424b32a3b3ead23cfb0"><enum>(2)</enum><header>Service of
			 process</header><text>In an action brought under subsection (a), process may be
			 served in any district in which the defendant—</text>
							<subparagraph id="ID0708d5b6cfac45f0b642801232c2bfbe"><enum>(A)</enum><text>is an inhabitant;
			 or</text>
							</subparagraph><subparagraph id="IDd8a6af6a09b544afa2b24224adf2c9cc"><enum>(B)</enum><text>may be
			 found.</text>
							</subparagraph></paragraph></subsection><subsection id="IDf57afe347d774657bf92f82edd4ec59e"><enum>(f)</enum><header>No private
			 cause of action</header><text>Nothing in this subtitle establishes a private
			 cause of action against a business entity for violation of any provision of
			 this subtitle.</text>
					</subsection></section><section id="IDa5c5ed85f5b948b08f30d0800295937a"><enum>319.</enum><header>Effect on
			 Federal and State law</header><text display-inline="no-display-inline">The
			 provisions of this subtitle shall supersede any other provision of Federal law
			 or any provision of law of any State relating to notification
			 <added-phrase reported-display-style="italic">by a business entity engaged in
			 interstate commerce or an agency</added-phrase> of a security breach, except as
			 provided in section 314(b).</text>
				</section><section id="ID90730e6c13ca4a49b382b3f1e9ee896e"><enum>320.</enum><header>Authorization
			 of appropriations</header><text display-inline="no-display-inline">There are
			 authorized to be appropriated such sums as may be necessary to cover the costs
			 incurred by the United States Secret Service to carry out investigations and
			 risk assessments of security breaches as required under this subtitle.</text>
				</section><section id="ID0c5c8ec1f3e24cd886be5d8e2f850ca7"><enum>321.</enum><header>Reporting on
			 risk assessment exemptions</header><text display-inline="no-display-inline">The
			 United States Secret Service shall report to Congress not later than 18 months
			 after the date of enactment of this Act, and upon the request by Congress
			 thereafter, on—</text>
					<paragraph id="IDa7b8f800cc534389b40bb6e89642575f"><enum>(1)</enum><text>the number and
			 nature of the security breaches described in the notices filed by those
			 business entities invoking the risk assessment exemption under section 312(b)
			 and the response of the United States Secret Service to such notices;
			 and</text>
					</paragraph><paragraph id="ID2882bcf4ab6e40599f78f745dbac92ff"><enum>(2)</enum><text>the number and
			 nature of security breaches subject to the national security and law
			 enforcement exemptions under section 312(a), provided that such report may not
			 disclose the contents of any risk assessment provided to the United States
			 Secret Service pursuant to this subtitle.</text>
					</paragraph></section><section id="ID527ade6c074f448da6e7e220dd02a32e"><enum>322.</enum><header>Effective
			 date</header><text display-inline="no-display-inline">This subtitle shall take
			 effect on the expiration of the date which is 90 days after the date of
			 enactment of this Act.</text>
				</section></subtitle><subtitle changed="added" id="id75F2FE2314DC46D08187B9BAA28D1DD5" reported-display-style="italic"><enum>C</enum><header>Office of Federal
			 Identity Protection</header>
				<section id="id03A6D5A282264B0DAB093F8E9F1A89F2"><enum>331.</enum><header>Office of Federal
			 Identity Protection</header>
					<subsection commented="no" display-inline="no-display-inline" id="id5E7D41E1399A47F5A2ADEA1E39A8276B"><enum>(a)</enum><header>Establishment</header><text display-inline="yes-display-inline">There is established in the Federal Trade
			 Commission an Office of Federal Identity Protection.</text>
					</subsection><subsection commented="no" display-inline="no-display-inline" id="id7FE1873B3AEC424990700F47FBA3B67F"><enum>(b)</enum><header>Duties</header><text>The
			 Office of Federal Identity Protection shall be responsible for assisting each
			 consumer with—</text>
						<paragraph id="IDa79408e5488346a1b0c0464f76abfd31"><enum>(1)</enum><text>addressing the
			 consequences of the theft or compromise of the personally identifiable
			 information of that consumer;</text>
						</paragraph><paragraph id="idBBAD25BE845A446BB30AB6E14B1FA733"><enum>(2)</enum><text>accessing remedies
			 provided under Federal law and providing information about remedies available
			 under State law;</text>
						</paragraph><paragraph id="id7DB56F78980A46E184B01AF50B1081EE"><enum>(3)</enum><text>restoring the accuracy
			 of—</text>
							<subparagraph id="idECDE47519D6A4653BA9B704B0F10BF48"><enum>(A)</enum><text>the personally
			 identifiable information of that consumer; and</text>
							</subparagraph><subparagraph id="idEDA45A7741724E0CAD326F3A62997A22"><enum>(B)</enum><text>records containing the
			 personally identifiable information of that consumer that were stolen or
			 compromised; and</text>
							</subparagraph></paragraph><paragraph id="id65F47D9B8C6248719A148F1F849C2B79"><enum>(4)</enum><text>retrieving any stolen or
			 compromised personally identifiable information of that consumer.</text>
						</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="id4343EFB55058459DA6E7BE136B610AF5"><enum>(c)</enum><header>Activities</header><text display-inline="yes-display-inline">In order to perform the duties required
			 under subsection (b), the Office of Federal Identity Protection shall carry out
			 the following activities:</text>
						<paragraph commented="no" display-inline="no-display-inline" id="IDc90107ac65aa4403bf57084a31025143"><enum>(1)</enum><text display-inline="yes-display-inline">Establish a website, easily and
			 conspicuously accessible from ftc.gov, dedicated to assisting consumers with
			 the retrieval of the stolen or compromised personally identifiable information
			 of the consumer.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDa35492535c3f4c1d9ee8a9d57b5edca8"><enum>(2)</enum><text display-inline="yes-display-inline">Maintain a toll-free phone number to help
			 answer questions concerning identity theft from consumers.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDad7fbc04bb5447ff9b4469f1024cf0c1"><enum>(3)</enum><text display-inline="yes-display-inline">Establish online and offline
			 consumer-service teams to assist consumers seeking the retrieval of the
			 personally identifiable information of the consumer.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="idBDEBFD88337643718A829A0C7E1BEE70"><enum>(4)</enum><text>Provide guidance and
			 information to service organizations or pro bono legal services programs that
			 offer individualized assistance or counseling to victims of identity
			 theft.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID4ab92ac113ce480f9f362136bc58de2a"><enum>(5)</enum><text display-inline="yes-display-inline">Establish a reasonable standard for
			 determining when an individual becomes a victim of identity theft.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID8aa1f41f7d344bf584ad5e5256883d82"><enum>(6)</enum><text display-inline="yes-display-inline">Issue certifications to individuals who,
			 under the standard described in paragraph (5), are identity theft
			 victims.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID42de201466be4c4a9f6c8b886f495db9"><enum>(7)</enum><text display-inline="yes-display-inline">Permit an individual to use the Office of
			 Federal Identity Protection certification—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="id734FAF55B78B4D4D98A0455D77FFB42D"><enum>(A)</enum><text display-inline="yes-display-inline">in all Federal, State, and local
			 jurisdictions, in lieu of a police report or any other document required by
			 State or local law, as a prerequisite to accessing business records of
			 transactions done by someone claiming to be the individual; and</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idBAF596AC46894C4E94FD2585ED026B86"><enum>(B)</enum><text>to establish the
			 eligibility of that individual for—</text>
								<clause commented="no" display-inline="no-display-inline" id="id4160AA9E76C64320B46E81D80845E7B5"><enum>(i)</enum><text>the fraud alert
			 protections under section 605A of the Fair Credit Reporting Act (15 U.S.C.
			 1681c–1); and</text>
								</clause><clause commented="no" display-inline="no-display-inline" id="idA3DB86FFDF574D8FA22DE23CA9636950"><enum>(ii)</enum><text>the reporting
			 protections under section 605B(a) of the Fair Credit Reporting Act (15 U.S.C.
			 1681c–2(a)).</text>
								</clause></subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="idE61DC16C36764F57999F21776453963F"><enum>(8)</enum><text>Coordinate, as the Office
			 determines necessary, with the designated Chief Privacy Officer of each Federal
			 agency, or any other designated senior official in such agency in charge of
			 privacy, in order to meet the duties of assisting consumers as required under
			 subsection (b).</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDbbd804b8524248ee896d3d7439568a94"><enum>(9)</enum><text display-inline="yes-display-inline">In addition to the requirements in
			 paragraphs (1) through (7), the Federal Trade Commission shall promulgate
			 regulations that enable the Office of Federal Identity Protection to help
			 consumers restore their stolen or otherwise compromised personally identifiable
			 information quickly and inexpensively.</text>
						</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="ID5f1d3af4131e44b5b3d462765135557a"><enum>(d)</enum><header>Authorization of
			 appropriations</header><text display-inline="yes-display-inline">There are
			 authorized to be appropriated for the Office of Federal Identity Protection
			 such sums as are necessary for fiscal year 2008 and each of the 4 succeeding
			 fiscal years.</text>
					</subsection></section></subtitle></title><title id="id14E3D0E4F57E4B0A8C0C7207624800D1"><enum>IV</enum><header>Government
			 access to and use of commercial data</header>
			<section id="ID12b6cb5e199e41929bf7df592fcd092f"><enum>401.</enum><header>General
			 services administration review of contracts</header>
				<subsection id="ID995b836df04c406a91e33953d556a900"><enum>(a)</enum><header>In
			 general</header><text>In considering contract awards totaling more than
			 $500,000 and entered into after the date of enactment of this Act with data
			 brokers, the Administrator of the General Services Administration shall
			 evaluate—</text>
					<paragraph id="IDd81fec140bdb4eb3b0924ba3030a135e"><enum>(1)</enum><text>the data privacy
			 and security program of a data broker to ensure the privacy and security of
			 data containing personally identifiable information, including whether such
			 program adequately addresses privacy and security threats created by malicious
			 software or code, or the use of peer-to-peer file sharing software;</text>
					</paragraph><paragraph id="ID6b25f35cb40e491eb48de6f3d6768bd4"><enum>(2)</enum><text>the compliance of
			 a data broker with such program;</text>
					</paragraph><paragraph id="ID60a4e479908346c2839ef7b4423f45c3"><enum>(3)</enum><text>the extent to
			 which the databases and systems containing personally identifiable information
			 of a data broker have been compromised by security breaches; and</text>
					</paragraph><paragraph id="ID949ad97ace5b4929bb68f4ca8b544025"><enum>(4)</enum><text>the response by a
			 data broker to such breaches, including the efforts by such data broker to
			 mitigate the impact of such security breaches.</text>
					</paragraph></subsection><subsection id="IDce3b2ba9c6b2469dbd50314cb6268e3e"><enum>(b)</enum><header>Compliance safe
			 harbor</header><text>The data privacy and security program of a data broker
			 shall be deemed sufficient for the purposes of subsection (a), if the data
			 broker complies with or provides protection equal to industry standards, as
			 identified by the Federal Trade Commission, that are applicable to the type of
			 personally identifiable information involved in the ordinary course of business
			 of such data broker.</text>
				</subsection><subsection id="ID3bd4f223fe26433ab41f1ca859884b6a"><enum>(c)</enum><header>Penalties</header><text>In
			 awarding contracts with data brokers for products or services related to
			 access, use, compilation, distribution, processing, analyzing, or evaluating
			 personally identifiable information, the Administrator of the General Services
			 Administration shall—</text>
					<paragraph id="IDebdaa8ec56814a069eaffb85c34f2ba9"><enum>(1)</enum><text>include monetary
			 or other penalties—</text>
						<subparagraph id="ID96f2956451cb41baaa8ae62030fdb0a8"><enum>(A)</enum><text>for failure to
			 comply with subtitles A and B of title III; or</text>
						</subparagraph><subparagraph id="IDaa149b7ee8a94b318052713319405cf3"><enum>(B)</enum><text>if a contractor
			 knows or has reason to know that the personally identifiable information being
			 provided is inaccurate, and provides such inaccurate information; and</text>
						</subparagraph></paragraph><paragraph id="IDa7ac7c96c6d9487ba2685498956532ab"><enum>(2)</enum><text>require a data
			 broker that engages service providers not subject to subtitle A of title III
			 for responsibilities related to sensitive personally identifiable information
			 to—</text>
						<subparagraph id="ID9f1b82ec90eb4e2c8fc6122262c60788"><enum>(A)</enum><text>exercise
			 appropriate due diligence in selecting those service providers for
			 responsibilities related to personally identifiable information;</text>
						</subparagraph><subparagraph id="IDcff9a67f57044095a9372fd650b53077"><enum>(B)</enum><text>take reasonable
			 steps to select and retain service providers that are capable of maintaining
			 appropriate safeguards for the security, privacy, and integrity of the
			 personally identifiable information at issue; and</text>
						</subparagraph><subparagraph id="IDb86e5489dd9d4867b1104a90a8c56370"><enum>(C)</enum><text>require such
			 service providers, by contract, to implement and maintain appropriate measures
			 designed to meet the objectives and requirements in title III.</text>
						</subparagraph></paragraph></subsection><subsection id="ID2ed921e9172648cfa9d7e97f01e18642"><enum>(d)</enum><header>Limitation</header><text>The
			 penalties under subsection (c) shall not apply to a data broker providing
			 information that is accurately and completely recorded from a public record
			 source or licensor.</text>
				</subsection></section><section id="ID2c32eab739de4fea85488e717413b035"><enum>402.</enum><header>Requirement to
			 audit information security practices of contractors and third party business
			 entities</header><text display-inline="no-display-inline">Section 3544(b) of
			 title 44, United States Code, is amended—</text>
				<paragraph id="ID886fac1dc8d54a45a34cd023c3f0603a"><enum>(1)</enum><text>in paragraph
			 (7)(C)(iii), by striking <quote>and</quote> after the semicolon;</text>
				</paragraph><paragraph id="ID86d7b3ac16e14a24a17152aa29d8f8fa"><enum>(2)</enum><text>in paragraph (8),
			 by striking the period and inserting <quote>; and</quote>; and</text>
				</paragraph><paragraph id="ID487bd2dd97084bb592f9c8b701bada8d"><enum>(3)</enum><text>by adding at the
			 end the following:</text>
					<quoted-block display-inline="no-display-inline" id="id51C65F1CDDDA4661ABF00BC805968E30" style="OLC">
						<paragraph id="IDfe9569912cd9418d80acea18528c30c7"><enum>(9)</enum><text>procedures for
				evaluating and auditing the information security practices of contractors or
				third party business entities supporting the information systems or operations
				of the agency involving personally identifiable information (as that term is
				defined in section 3 of the <short-title>Personal Data
				Privacy and Security Act of 2007</short-title>) and ensuring remedial action to
				address any significant
				deficiencies.</text>
						</paragraph><after-quoted-block>.</after-quoted-block></quoted-block>
				</paragraph></section><section id="ID4056fc3599c54deeb9c0ed352866c385"><enum>403.</enum><header>Privacy impact
			 assessment of government use of commercial information services containing
			 personally identifiable information</header>
				<subsection id="ID5ce43dba31a3469d8b31a5e94d0ff19e"><enum>(a)</enum><header>In
			 general</header><text>Section 208(b)(1) of the E-Government Act of 2002 (44
			 U.S.C. 3501 note) is amended—</text>
					<paragraph id="ID8514e50d74594d6ab9ccc96eaa8a555a"><enum>(1)</enum><text>in subparagraph
			 (A)(i), by striking <quote>or</quote>; and</text>
					</paragraph><paragraph id="ID4a6f00d902c043c1af3a0a1bbc4c338a"><enum>(2)</enum><text>in subparagraph
			 (A)(ii), by striking the period and inserting <quote>; or</quote>; and</text>
					</paragraph><paragraph id="IDc02e3e37ef45496d915ac736eabee83a"><enum>(3)</enum><text>by inserting
			 after clause (ii) the following:</text>
						<quoted-block display-inline="no-display-inline" id="idBB13C89F7A95426D9ADE3BE28B30BDA4" style="OLC">
							<clause id="IDa49e55dafba94f21a8f9e8abdb9d2094"><enum>(iii)</enum><text>purchasing or
				subscribing for a fee to personally identifiable information from a data broker
				(as such terms are defined in section 3 of the
				<short-title>Personal Data Privacy and Security Act of
				2007</short-title>).</text>
							</clause><after-quoted-block>.</after-quoted-block></quoted-block>
					</paragraph></subsection><subsection id="IDb0f703f2ffff413d8304e950ee6002a0"><enum>(b)</enum><header>Limitation</header><text>Notwithstanding
			 any other provision of law, commencing 1 year after the date of enactment of
			 this Act, no Federal agency may enter into a contract with a data broker to
			 access for a fee any database consisting primarily of personally identifiable
			 information concerning United States persons (other than news reporting or
			 telephone directories) unless the head of such department or agency—</text>
					<paragraph id="IDbd9a44cb0f8347f48c4ffc2e9d43e1af"><enum>(1)</enum><text>completes a
			 privacy impact assessment under section 208 of the E-Government Act of 2002 (44
			 U.S.C. 3501 note), which shall subject to the provision in that Act pertaining
			 to sensitive information, include a description of—</text>
						<subparagraph id="IDd9c08f20b45a4ad0a9fbe129d268f7ef"><enum>(A)</enum><text>such
			 database;</text>
						</subparagraph><subparagraph id="ID5f3a37fd1cde4cf29c866b52941d8fd6"><enum>(B)</enum><text>the name of the
			 data broker from whom it is obtained; and</text>
						</subparagraph><subparagraph id="ID0e42886510c84307bd1b8ff76f26348d"><enum>(C)</enum><text>the amount of the
			 contract for use;</text>
						</subparagraph></paragraph><paragraph id="ID7fd6917e701945c9b29407ea764b2358"><enum>(2)</enum><text>adopts
			 regulations that specify—</text>
						<subparagraph id="IDc2d0e5565e274bb8a62c879648972b07"><enum>(A)</enum><text>the personnel
			 permitted to access, analyze, or otherwise use such databases;</text>
						</subparagraph><subparagraph id="IDed199cff45a94ca6857c1fdc4f42ba73"><enum>(B)</enum><text>standards
			 governing the access, analysis, or use of such databases;</text>
						</subparagraph><subparagraph id="ID5f5fee5062cc4fed9f55394fe0b12ce4"><enum>(C)</enum><text>any standards
			 used to ensure that the personally identifiable information accessed, analyzed,
			 or used is the minimum necessary to accomplish the intended legitimate purpose
			 of the Federal agency;</text>
						</subparagraph><subparagraph id="ID489c12de6977443b834d48a26009897e"><enum>(D)</enum><text>standards
			 limiting the retention and redisclosure of personally identifiable information
			 obtained from such databases;</text>
						</subparagraph><subparagraph id="IDdb1a32a1904a4f108fc798f4eb7627ad"><enum>(E)</enum><text>procedures
			 ensuring that such data meet standards of accuracy, relevance, completeness,
			 and timeliness;</text>
						</subparagraph><subparagraph id="ID9f20a216795e4ffa94c388eee36c08d4"><enum>(F)</enum><text>the auditing and
			 security measures to protect against unauthorized access, analysis, use, or
			 modification of data in such databases;</text>
						</subparagraph><subparagraph id="ID39a555ea4350456cb5a5388d3531afb1"><enum>(G)</enum><text>applicable
			 mechanisms by which individuals may secure timely redress for any adverse
			 consequences wrongly incurred due to the access, analysis, or use of such
			 databases;</text>
						</subparagraph><subparagraph id="IDd3b6e9327d7d40da8f9d58f61cb46f71"><enum>(H)</enum><text>mechanisms, if
			 any, for the enforcement and independent oversight of existing or planned
			 procedures, policies, or guidelines; and</text>
						</subparagraph><subparagraph id="IDd244312f492a424f8cd060941aafb73d"><enum>(I)</enum><text>an outline of
			 enforcement mechanisms for accountability to protect individuals and the public
			 against unlawful or illegitimate access or use of databases; and</text>
						</subparagraph></paragraph><paragraph id="ID21a7368695e04683b6b2556783e36345"><enum>(3)</enum><text>incorporates into
			 the contract or other agreement totaling more than $500,000, provisions—</text>
						<subparagraph id="ID52450c4b015e4106b52161964153f4b0"><enum>(A)</enum><text>providing for
			 penalties—</text>
							<clause id="ID47368893b6114f4a8e949a7e5908021d"><enum>(i)</enum><text>for
			 failure to comply with title III of this Act; or</text>
							</clause><clause id="ID524c9d6d46814f64bb14403a6b3e8c86"><enum>(ii)</enum><text>if
			 the entity knows or has reason to know that the personally identifiable
			 information being provided to the Federal department or agency is inaccurate,
			 and provides such inaccurate information; and</text>
							</clause></subparagraph><subparagraph id="ID5830c7e15b514afabc350d588a163c16"><enum>(B)</enum><text>requiring a data
			 broker that engages service providers not subject to subtitle A of title III
			 for responsibilities related to sensitive personally identifiable information
			 to—</text>
							<clause id="IDc820784a80784abf8d8422b62333783a"><enum>(i)</enum><text>exercise
			 appropriate due diligence in selecting those service providers for
			 responsibilities related to personally identifiable information;</text>
							</clause><clause id="ID52a184cf261f43fbbe693fea76df4c09"><enum>(ii)</enum><text>take reasonable
			 steps to select and retain service providers that are capable of maintaining
			 appropriate safeguards for the security, privacy, and integrity of the
			 personally identifiable information at issue; and</text>
							</clause><clause id="ID824d34d50448495f8e3998930307cbd6"><enum>(iii)</enum><text>require such
			 service providers, by contract, to implement and maintain appropriate measures
			 designed to meet the objectives and requirements in title III.</text>
							</clause></subparagraph></paragraph></subsection><subsection id="IDee4893ba854540c99c2733dfb1bddf7d"><enum>(c)</enum><header>Limitation on
			 penalties</header><text>The penalties under subsection (b)(3)(A) shall not
			 apply to a data broker providing information that is accurately and completely
			 recorded from a public record source.</text>
				</subsection><subsection changed="deleted" id="ID8dcba88a38df4617b2dacfd4d2d496c2" reported-display-style="strikethrough"><enum>(d)</enum><header>Study of
			 government use</header>
					<paragraph id="ID6de28876a1ee4bef844e570bd41d39fd"><enum>(1)</enum><header>Scope of
			 study</header><text>Not later than 180 days after the date of enactment of this
			 Act, the Comptroller General of the United States shall conduct a study and
			 audit and prepare a report on Federal agency use of data brokers or commercial
			 databases containing personally identifiable information, including the impact
			 on privacy and security, and the extent to which Federal contracts include
			 sufficient provisions to ensure privacy and security protections, and penalties
			 for failures in privacy and security practices.</text>
					</paragraph><paragraph id="IDf33d20f38c0b4bdc927f7a4b3f0baeba"><enum>(2)</enum><header>Report</header><text>A
			 copy of the report required under paragraph (1) shall be submitted to
			 Congress.</text>
					</paragraph></subsection><subsection changed="added" id="id104D66BAD0F0492FB042C3DCF1573537" reported-display-style="italic"><enum>(d)</enum><header>Study of government
			 use</header>
					<paragraph id="idFA2A5D39AE0D4066A7DFB48438EA740A"><enum>(1)</enum><header>Scope of
			 study</header><text>Not later than 180 days after the date of enactment of this
			 Act, the Comptroller General of the United States shall conduct a study and
			 audit and prepare a report on Federal agency actions to address the
			 recommendations in the Government Accountability Office's April 2006 report on
			 agency adherence to key privacy principles in using data brokers or commercial
			 databases containing personally identifiable information.</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id076A50E3C6FF4B178BB62383248C9913"><enum>(2)</enum><header>Report</header><text>A
			 copy of the report required under paragraph (1) shall be submitted to
			 Congress.</text>
					</paragraph></subsection></section><section id="ID938f0445fd614561aaba4ee7b370044f"><enum>404.</enum><header>Implementation
			 of chief privacy officer requirements</header>
				<subsection id="ID18bc26c0b5194508b7813d651b51591b"><enum>(a)</enum><header>Designation of
			 the chief privacy officer</header><text>Pursuant to the requirements under
			 section 522 of the Transportation, Treasury, Independent Agencies, and General
			 Government Appropriations Act, 2005 (division H of Public Law 108–447; 118
			 Stat. 3199) that each agency designate a Chief Privacy Officer, the Department
			 of Justice shall implement such requirements by designating a department-wide
			 Chief Privacy Officer, whose primary role shall be to fulfill the duties and
			 responsibilities of Chief Privacy Officer and who shall report directly to the
			 Deputy Attorney General.</text>
				</subsection><subsection id="ID51d5e6f4a9f34cdcab14d97cdeeed25a"><enum>(b)</enum><header>Duties and
			 responsibilities of chief privacy officer</header><text>In addition to the
			 duties and responsibilities outlined under section 522 of the Transportation,
			 Treasury, Independent Agencies, and General Government Appropriations Act, 2005
			 (division H of Public Law 108–447; 118 Stat. 3199), the Department of Justice
			 Chief Privacy Officer shall—</text>
					<paragraph id="ID6e62e410e9b8451d842da5813b497620"><enum>(1)</enum><text>oversee the
			 Department of Justice’s implementation of the requirements under section 403 to
			 conduct privacy impact assessments of the use of commercial data containing
			 personally identifiable information by the Department; and</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDc1c9e9832b064e8aa387f3ecf87cc622"><enum>(2)</enum><text>coordinate with
			 the Privacy and Civil Liberties Oversight Board, established in the
			 Intelligence Reform and Terrorism Prevention Act of 2004 (Public Law 108–458),
			 in implementing this section.</text>
					</paragraph></subsection></section></title></legis-body>
	<endorsement>
		<action-date date="20070523">May 23, 2007</action-date>
		<action-desc>Reported with amendments</action-desc>
	</endorsement>
</bill>
