<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" bill-type="olc" dms-id="H238F4DFAAA30488B8B7421D6AACEB7EB" public-private="public">
	<form>
		<distribution-code display="yes">I</distribution-code>
		<congress>111th CONGRESS</congress>
		<session>2d Session</session>
		<legis-num>H. R. 6236</legis-num>
		<current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber>
		<action>
			<action-date date="20100928">September 28, 2010</action-date>
			<action-desc><sponsor name-id="S001150">Mr. Schiff</sponsor> introduced
			 the following bill; which was referred to the
			 <committee-name committee-id="HIF00">Committee on Energy and
			 Commerce</committee-name>, and in addition to the Committees on
			 <committee-name committee-id="HGO00">Oversight and Government
			 Reform</committee-name>, <committee-name committee-id="HBA00">Financial
			 Services</committee-name>, and <committee-name committee-id="HJU00">the
			 Judiciary</committee-name>, for a period to be subsequently determined by the
			 Speaker, in each case for consideration of such provisions as fall within the
			 jurisdiction of the committee concerned</action-desc>
		</action>
		<legis-type>A BILL</legis-type>
		<official-title>To require Federal agencies, and persons engaged in
		  interstate commerce, in possession of data containing sensitive personally
		  identifiable information, to disclose any breach of such
		  information.</official-title>
	</form>
	<legis-body id="H9B659BE81D514824B82783E371A2BF8C" style="OLC">
		<section id="H922472A23BF54D3E9CB40776EA8B25EF" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the
			 <quote><short-title>Data Breach Notification
			 Act</short-title></quote>.</text>
		</section><section id="HBBDC18DEB04345D1B9EDFA044E678A33"><enum>2.</enum><header>Notice to
			 individuals</header>
			<subsection id="H5C959BDEC4064592BB0E40CD2DEC76F9"><enum>(a)</enum><header>In
			 General</header><text>Any agency, or business entity engaged in interstate
			 commerce, that uses, accesses, transmits, stores, disposes of or collects
			 sensitive personally identifiable information shall, following the discovery of
			 a security breach of such information notify any resident of the United States
			 whose sensitive personally identifiable information has been, or is reasonably
			 believed to have been, accessed, or acquired.</text>
			</subsection><subsection id="H73898A7700D04FE580038A0C57A0DD29"><enum>(b)</enum><header>Obligation of
			 Owner or Licensee</header>
				<paragraph id="HA536BA0B54EF46249005344D06C98E39"><enum>(1)</enum><header>Notice to owner
			 or licensee</header><text>Any agency, or business entity engaged in interstate
			 commerce, that uses, accesses, transmits, stores, disposes of, or collects
			 sensitive personally identifiable information that the agency or business
			 entity does not own or license shall notify the owner or licensee of the
			 information following the discovery of a security breach involving such
			 information.</text>
				</paragraph><paragraph id="HE467299D0F384334A07A05FC9FEB11AF"><enum>(2)</enum><header>Notice by owner,
			 licensee or other designated third party</header><text>Nothing in this Act
			 shall prevent or abrogate an agreement between an agency or business entity
			 required to give notice under this section and a designated third party,
			 including an owner or licensee of the sensitive personally identifiable
			 information subject to the security breach, to provide the notifications
			 required under subsection (a).</text>
				</paragraph><paragraph id="H7C852870ED95440FA0480CF73FA5540C"><enum>(3)</enum><header>Business entity
			 relieved from giving notice</header><text>A business entity obligated to give
			 notice under subsection (a) shall be relieved of such obligation if an owner or
			 licensee of the sensitive personally identifiable information subject to the
			 security breach, or other designated third party, provides such
			 notification.</text>
				</paragraph></subsection><subsection id="HE33FEF85D7B04C029BD77EFEAAEA969C"><enum>(c)</enum><header>Timeliness of
			 Notification</header>
				<paragraph id="HB3028553B777410E986811FAF2E8FCA7"><enum>(1)</enum><header>In
			 general</header><text>All notifications required under this section shall be
			 made without unreasonable delay following the discovery by the agency or
			 business entity of a security breach.</text>
				</paragraph><paragraph id="H05442D5E364942219FBA83DFF205DEB8"><enum>(2)</enum><header>Reasonable
			 delay</header><text>Reasonable delay under this subsection may include any time
			 necessary to determine the scope of the security breach, prevent further
			 disclosures, and restore the reasonable integrity of the data system and
			 provide notice to law enforcement when required.</text>
				</paragraph><paragraph id="H9E38CAB79F7F49988F6FAB5186341343"><enum>(3)</enum><header>Burden of
			 proof</header><text>The agency, business entity, owner, or licensee required to
			 provide notification under this section shall have the burden of demonstrating
			 that all notifications were made as required under this Act, including evidence
			 demonstrating the reasons for any delay.</text>
				</paragraph></subsection><subsection id="H2FE3CF7B7FC24BA2947854D2BD7BD93A"><enum>(d)</enum><header>Delay of
			 Notification Authorized for Law Enforcement Purposes</header>
				<paragraph id="H85C1706B40814941B51F98A4596F8DEF"><enum>(1)</enum><header>In
			 general</header><text>If a Federal law enforcement agency determines that the
			 notification required under this section would impede a criminal investigation,
			 such notification shall be delayed upon written notice from such Federal law
			 enforcement agency to the agency or business entity that experienced the
			 breach.</text>
				</paragraph><paragraph id="HF48DF3EF6DC042B8BE2C5D58872B9F09"><enum>(2)</enum><header>Extended delay
			 of notification</header><text>If the notification required under subsection (a)
			 is delayed pursuant to paragraph (1), an agency or business entity shall give
			 notice 30 days after the day such law enforcement delay was invoked unless a
			 Federal law enforcement agency provides written notification that further delay
			 is necessary.</text>
				</paragraph><paragraph id="HAFE1648FDAD64572B8AED0C7F22CBAC4"><enum>(3)</enum><header>Law enforcement
			 immunity</header><text>No cause of action shall lie in any court against any
			 law enforcement agency for acts relating to the delay of notification for law
			 enforcement purposes under this Act.</text>
				</paragraph></subsection></section><section id="H1CE16974EE92459484D43DA6F5E3E4E7"><enum>3.</enum><header>Exemptions</header>
			<subsection id="H26D62D32AB91411CAC61DB074D3747EA"><enum>(a)</enum><header>Exemption for
			 National Security and Law Enforcement</header>
				<paragraph id="H38631D79F24149AB94DF01ADF4DFAF8B"><enum>(1)</enum><header>In
			 general</header><text>Section 2 shall not apply to an agency or business entity
			 if the agency or business entity certifies, in writing, that notification of
			 the security breach as required by section 2 reasonably could be expected
			 to—</text>
					<subparagraph id="H08E84EAC45F246F0858B68C5CF4E1944"><enum>(A)</enum><text>cause damage to
			 the national security; or</text>
					</subparagraph><subparagraph id="H883A7A163CE34467B1CAA90232A22E12"><enum>(B)</enum><text>hinder a law
			 enforcement investigation or the ability of the agency to conduct law
			 enforcement investigations.</text>
					</subparagraph></paragraph><paragraph id="H7DDB468F07CF4B2490B9C5A9475FF0B6"><enum>(2)</enum><header>Limits on
			 certifications</header><text>An agency or business entity may not execute a
			 certification under paragraph (1) to—</text>
					<subparagraph id="HB12DA208B3114ED88CC9DC9E869217EE"><enum>(A)</enum><text>conceal violations
			 of law, inefficiency, or administrative error;</text>
					</subparagraph><subparagraph id="HCD76A7757F8446CEB392AC8BB0F5664A"><enum>(B)</enum><text>prevent
			 embarrassment to a business entity, organization, or agency; or</text>
					</subparagraph><subparagraph id="H2E17BA72C01F4C3FA092064F8A84B9D3"><enum>(C)</enum><text>restrain
			 competition.</text>
					</subparagraph></paragraph><paragraph id="H36D1B53D3ABE4140AC6A5FD76C13D10F"><enum>(3)</enum><header>Notice</header><text>In
			 every case in which an agency or business entity issues a certification under
			 paragraph (1), the certification, accompanied by a description of the factual
			 basis for the certification, shall be immediately provided to the United States
			 Secret Service.</text>
				</paragraph><paragraph id="HB3E660734AF247F292D2CDBB3FECEC81"><enum>(4)</enum><header>Secret service
			 review of certifications</header>
					<subparagraph id="HE36A8499FAE043C3B7933AE26463F9AC"><enum>(A)</enum><header>In
			 general</header><text>The United States Secret Service may review a
			 certification provided by an agency under paragraph (3), and shall review a
			 certification provided by a business entity under paragraph (3), to determine
			 whether an exemption under paragraph (1) is merited. Such review shall be
			 completed not later than 10 business days after the date of receipt of the
			 certification, except as provided in paragraph (5)(C).</text>
					</subparagraph><subparagraph id="H3BF42DC18F42425FA33C25C570FE420E"><enum>(B)</enum><header>Notice</header><text>Upon
			 completing a review under subparagraph (A) the United States Secret Service
			 shall immediately notify the agency or business entity, in writing, of its
			 determination of whether an exemption under paragraph (1) is merited.</text>
					</subparagraph><subparagraph id="H39AB1E0167C04DCD975B5B303C34D90C"><enum>(C)</enum><header>Exemption</header><text>The
			 exemption under paragraph (1) shall not apply if the United States Secret
			 Service determines under this paragraph that the exemption is not
			 merited.</text>
					</subparagraph></paragraph><paragraph id="H42531712113F48298D9866B76241490A"><enum>(5)</enum><header>Additional
			 authority of the secret service</header>
					<subparagraph id="HC6FEAD72671D4E4CA8015B10EE682BF0"><enum>(A)</enum><header>In
			 general</header><text>In determining under paragraph (4) whether an exemption
			 under paragraph (1) is merited, the United States Secret Service may request
			 additional information from the agency or business entity regarding the basis
			 for the claimed exemption, if such additional information is necessary to
			 determine whether the exemption is merited.</text>
					</subparagraph><subparagraph id="H6835600C0D75498986354070743C7517"><enum>(B)</enum><header>Required
			 compliance</header><text>Any agency or business entity that receives a request
			 for additional information under subparagraph (A) shall cooperate with any such
			 request.</text>
					</subparagraph><subparagraph id="H5D20AC750E3343F4A9BD142DF8237F73"><enum>(C)</enum><header>Timing</header><text>If
			 the United States Secret Service requests additional information under
			 subparagraph (A), the United States Secret Service shall notify the agency or
			 business entity not later than 10 business days after the date of receipt of
			 the additional information whether an exemption under paragraph (1) is
			 merited.</text>
					</subparagraph></paragraph></subsection><subsection id="HB339A48DF63D4C75A80DC4E55A915EBE"><enum>(b)</enum><header>Safe
			 harbor</header>
				<paragraph id="HE1837AD8DDA640EF9BF73A48CC02ACCE"><enum>(1)</enum><header>In
			 general</header><text>An agency or business entity shall be exempt from the
			 notice requirements under section 2, if—</text>
					<subparagraph id="H7C0C6A5D68E742AB8D02A394C6B2BFA4"><enum>(A)</enum><text>a risk assessment
			 concludes that there is no significant risk that a security breach has resulted
			 in, or will result in, harm to the individual whose sensitive personally
			 identifiable information was subject to the security breach;</text>
					</subparagraph><subparagraph id="H5D4364AEB2B641309E6C6D8EBBCCB6AC"><enum>(B)</enum><text>without
			 unreasonable delay, but not later than 45 days after the discovery of a
			 security breach (unless extended by the United States Secret Service), the
			 agency or business entity notifies the United States Secret Service, in
			 writing, of—</text>
						<clause id="H143DF12C94CB4452B71B42D67E9299D3"><enum>(i)</enum><text>the
			 results of the risk assessment; and</text>
						</clause><clause id="HC9899AA722204D8AAA69E5265184D3CC"><enum>(ii)</enum><text>its
			 decision to invoke the risk assessment exemption; and</text>
						</clause></subparagraph><subparagraph id="HA6AB9882BD7F4478B5524F6281B07C12"><enum>(C)</enum><text>the United States
			 Secret Service does not indicate, in writing, and not later than 10 business
			 days after the date of receipt of the decision described in subparagraph
			 (B)(ii), that notice should be given.</text>
					</subparagraph></paragraph><paragraph id="H0139D0E71C6D4AAAA50BD7CDDBC1D696"><enum>(2)</enum><header>Presumptions</header><text>There
			 shall be a presumption that no significant risk of harm to the individual whose
			 sensitive personally identifiable information was subject to a security breach
			 if such information—</text>
					<subparagraph id="H8C947ED283614613846E12CB5D6B09ED"><enum>(A)</enum><text>was encrypted;
			 or</text>
					</subparagraph><subparagraph id="H1525AFAB8F8B49B0854F728D9187D328"><enum>(B)</enum><text>was rendered
			 indecipherable through the use of best practices or methods, such as redaction,
			 access controls, or other such mechanisms, that are widely accepted as an
			 effective industry practice, or an effective industry standard.</text>
					</subparagraph></paragraph></subsection><subsection id="HE9FE908F3D7947D490A683DEF192C41C"><enum>(c)</enum><header>Financial fraud
			 prevention exemption</header>
				<paragraph id="H6B6487CEABEC49DF8F5B45F417E119E7"><enum>(1)</enum><header>In
			 general</header><text>A business entity will be exempt from the notice
			 requirement under section 2 if the business entity utilizes or participates in
			 a security program that—</text>
					<subparagraph id="HA71A30BA36814265821CCF6BC4C8DFB0"><enum>(A)</enum><text>is designed to
			 block the use of the sensitive personally identifiable information to initiate
			 unauthorized financial transactions before they are charged to the account of
			 the individual; and</text>
					</subparagraph><subparagraph id="HB654F6092C924465A463A7B3678EA142"><enum>(B)</enum><text>provides for
			 notice to affected individuals after a security breach that has resulted in
			 fraud or unauthorized transactions.</text>
					</subparagraph></paragraph><paragraph id="H4223FA39426143D1A663C110715FAEC9"><enum>(2)</enum><header>Limitation</header><text>The
			 exemption by this subsection does not apply if—</text>
					<subparagraph id="H952DC191240F4A438948C7FE68E5B786"><enum>(A)</enum><text>the information
			 subject to the security breach includes sensitive personally identifiable
			 information, other than a credit card number or credit card security code, of
			 any type; or</text>
					</subparagraph><subparagraph id="H5F87C10A1A694F5BAF25864A0A9DFBC3"><enum>(B)</enum><text>the information
			 subject to the security breach includes both the individual’s credit card
			 number and the individual’s first and last name.</text>
					</subparagraph></paragraph></subsection></section><section id="H168D4C89A3064FADACB71887B6D9DC2C"><enum>4.</enum><header>Methods of
			 notice</header><text display-inline="no-display-inline">An agency, or business
			 entity shall be in compliance with section 2 if it provides both:</text>
			<paragraph id="H57AA36257AB745EDB8AD0EA49841D1DA"><enum>(1)</enum><header>Individual
			 notice</header>
				<subparagraph id="HB71374A4251440DCBAF5872D77771FD3"><enum>(A)</enum><text>Written
			 notification to the last known home mailing address of the individual in the
			 records of the agency or business entity;</text>
				</subparagraph><subparagraph id="HD31AE9E866974A56970EBAFAFA517871"><enum>(B)</enum><text>telephone notice
			 to the individual personally; or</text>
				</subparagraph><subparagraph id="H76B17242DBF346478200F45202EA295B"><enum>(C)</enum><text>email notice, if
			 the individual has consented to receive such notice and the notice is
			 consistent with the provisions permitting electronic transmission of notices
			 under section 101 of the Electronic Signatures in Global and National Commerce
			 Act (15 U.S.C. 7001).</text>
				</subparagraph></paragraph><paragraph id="H2AEC5378A9E94A10A37844DA26BDD3A1"><enum>(2)</enum><header>Media
			 notice</header><text>Notice to major media outlets serving a State or
			 jurisdiction, if the number of residents of such State whose sensitive
			 personally identifiable information was, or is reasonably believed to have
			 been, acquired by an unauthorized person exceeds 5,000.</text>
			</paragraph></section><section id="H072E7FC1FEBC42CDA389EC649421F988"><enum>5.</enum><header>Content of
			 notification</header>
			<subsection id="HBA7B271FA5C347199506F7DCE4831910"><enum>(a)</enum><header>In
			 General</header><text>Regardless of the method by which notice is provided to
			 individuals under section 4, such notice shall include, to the extent
			 possible—</text>
				<paragraph id="H8A7F24C024DD45618A6B0D1E85D227A9"><enum>(1)</enum><text>a
			 description of the categories of sensitive personally identifiable information
			 that was, or is reasonably believed to have been, acquired by an unauthorized
			 person;</text>
				</paragraph><paragraph id="HD67ED82490144A7CB3C2A0D6B4816CA8"><enum>(2)</enum><text>a
			 toll-free number—</text>
					<subparagraph id="HBA99EE9465DA4EF1983B6F0A02F4EFEC"><enum>(A)</enum><text>that the
			 individual may use to contact the agency or business entity, or the agent of
			 the agency or business entity; and</text>
					</subparagraph><subparagraph id="H07C4AC5BA480477293830A00932F4616"><enum>(B)</enum><text>from which the
			 individual may learn what types of sensitive personally identifiable
			 information the agency or business entity maintained about that individual;
			 and</text>
					</subparagraph></paragraph><paragraph id="H017B990F9C7D4EFEBDE9F845923BCD30"><enum>(3)</enum><text>the toll-free
			 contact telephone numbers and addresses for the major credit reporting
			 agencies.</text>
				</paragraph></subsection><subsection id="HA3417BBFFA604DF8B0C01A9DC4F9F6FA"><enum>(b)</enum><header>Additional
			 Content</header><text>Notwithstanding section 10, a State may require that a
			 notice under subsection (a) shall also include information regarding victim
			 protection assistance provided for by that State.</text>
			</subsection></section><section id="H3537972DB2A849228EED18F621E52A85"><enum>6.</enum><header>Coordination of
			 notification with credit reporting agencies</header><text display-inline="no-display-inline">If an agency or business entity is required
			 to provide notification to more than 5,000 individuals under section 2(a), the
			 agency or business entity shall also notify all consumer reporting agencies
			 that compile and maintain files on consumers on a nationwide basis (as defined
			 in section 603(p) of the <act-name parsable-cite="FCRA">Fair Credit Reporting
			 Act</act-name> (15 U.S.C. 1681a(p)) of the timing and distribution of the
			 notices. Such notice shall be given to the consumer credit reporting agencies
			 without unreasonable delay and, if it will not delay notice to the affected
			 individuals, prior to the distribution of notices to the affected
			 individuals.</text>
		</section><section id="H63B6E9DF108543E79FDFD3114E18E1FC"><enum>7.</enum><header>Notice to law
			 enforcement</header>
			<subsection id="H450E825918DA45F49673D3F931C231E5"><enum>(a)</enum><header>Secret
			 Service</header><text>Any business entity or agency shall notify the United
			 States Secret Service of the fact that a security breach has occurred
			 if—</text>
				<paragraph id="HC8F79FDF2EDE4073983454FE42159AAB"><enum>(1)</enum><text>the number of
			 individuals whose sensitive personally identifying information was, or is
			 reasonably believed to have been acquired by an unauthorized person exceeds
			 10,000;</text>
				</paragraph><paragraph id="HC84B98EAE9E14A6BB33B38BB042803C4"><enum>(2)</enum><text>the security
			 breach involves a database, networked or integrated databases, or other data
			 system containing the sensitive personally identifiable information of more
			 than 1,000,000 individuals nationwide;</text>
				</paragraph><paragraph id="HFD17D7716212482EB496EDB9DA0DDB49"><enum>(3)</enum><text>the security
			 breach involves databases owned by the Federal Government; or</text>
				</paragraph><paragraph id="HFB3FBDE77D6C48EEAF6C45E1880B5AFF"><enum>(4)</enum><text>the security
			 breach involves primarily sensitive personally identifiable information of
			 individuals known to the agency or business entity to be employees and
			 contractors of the Federal Government involved in national security or law
			 enforcement.</text>
				</paragraph></subsection><subsection id="H6196E94B4CAB4CF99F6A3B60450091AB"><enum>(b)</enum><header>Notice to other
			 law enforcement agencies</header><text>The United States Secret Service shall
			 be responsible for notifying—</text>
				<paragraph id="H579160C41AD143098546B8527A66455D"><enum>(1)</enum><text>the Federal Bureau
			 of Investigation, if the security breach involves espionage, foreign
			 counterintelligence, information protected against unauthorized disclosure for
			 reasons of national defense or foreign relations, or Restricted Data (as that
			 term is defined in section 11y of the <act-name parsable-cite="AEA54">Atomic
			 Energy Act of 1954</act-name> (42 U.S.C. 2014(y)), except for offenses
			 affecting the duties of the United States Secret Service under section 3056(a)
			 of title 18, United States Code;</text>
				</paragraph><paragraph id="H2F6239120313462C95D060764D453ECF"><enum>(2)</enum><text>the United States
			 Postal Inspection Service, if the security breach involves mail fraud;
			 and</text>
				</paragraph><paragraph id="HD50D8D3141E743B6AB44E013567D2237"><enum>(3)</enum><text>the attorney
			 general of each State affected by the security breach.</text>
				</paragraph></subsection><subsection id="H2ABEB6D8FA174EBAAFA64A20BE1E3EEE"><enum>(c)</enum><header>Timing of
			 notices</header><text>The notices required under this section shall be
			 delivered as follows:</text>
				<paragraph id="H1959B4D6AB874F36AA8CB220F6AE417B"><enum>(1)</enum><text>Notice under
			 subsection (a) shall be delivered as promptly as possible, but not later than
			 14 days after discovery of the events requiring notice.</text>
				</paragraph><paragraph id="HEEFE4BF6BA45404AB1EAF29BCF01BC67"><enum>(2)</enum><text>Notice under
			 subsection (b) shall be delivered not later than 14 days after the United
			 States Secret Service receives notice of a security breach from an agency or
			 business entity.</text>
				</paragraph></subsection></section><section id="H88D38987ACC241198F5F634FCACE415D"><enum>8.</enum><header>Enforcement</header>
			<subsection id="H2FB00CA797EB4FD6AA7DDF9D48671D30"><enum>(a)</enum><header>Civil actions by
			 the Attorney General</header><text>The Attorney General may bring a civil
			 action in the appropriate United States district court against any business
			 entity that engages in conduct constituting a violation of this Act and, upon
			 proof of such conduct by a preponderance of the evidence, such business entity
			 shall be subject to a civil penalty of not more than $1,000 per day per
			 individual whose sensitive personally identifiable information was, or is
			 reasonably believed to have been, accessed or acquired by an unauthorized
			 person, up to a maximum of $1,000,000 per violation, unless such conduct is
			 found to be willful or intentional.</text>
			</subsection><subsection id="H7DF8A2678F7C45FC84497CE1B0626937"><enum>(b)</enum><header>Injunctive
			 actions by the Attorney General</header>
				<paragraph id="H825B4D32C42B4B6A9211C890843E13FD"><enum>(1)</enum><header>In
			 general</header><text>If it appears that a business entity has engaged, or is
			 engaged, in any act or practice constituting a violation of this Act, the
			 Attorney General may petition an appropriate district court of the United
			 States for an order—</text>
					<subparagraph id="H990C313706FD4C1897C12F14C2B7AF43"><enum>(A)</enum><text>enjoining such act
			 or practice; or</text>
					</subparagraph><subparagraph id="H151AB7A96802467C8DFD6E957A76C370"><enum>(B)</enum><text>enforcing
			 compliance with this Act.</text>
					</subparagraph></paragraph><paragraph id="HD995D616ADB44BFEA7A661832C04CE1D"><enum>(2)</enum><header>Issuance of
			 order</header><text>A court may issue an order under paragraph (1), if the
			 court finds that the conduct in question constitutes a violation of this
			 Act.</text>
				</paragraph></subsection><subsection id="H1A8DAE254FE9458495FF126499615F4A"><enum>(c)</enum><header>Other rights and
			 remedies</header><text>The rights and remedies available under this Act are
			 cumulative and shall not affect any other rights and remedies available under
			 law.</text>
			</subsection><subsection id="H61D88001C3DE405AAD9699CB28A14EFB"><enum>(d)</enum><header>Fraud
			 alert</header><text>Section 605A(b)(1) of the <act-name parsable-cite="FCRA">Fair Credit Reporting Act</act-name> (15 U.S.C.
			 1681c–1(b)(1)) is amended by inserting <quote>, or evidence that the consumer
			 has received notice that the consumer’s financial information has or may have
			 been compromised,</quote> after <quote>identity theft report</quote>.</text>
			</subsection></section><section id="H46FC35252EE9473CAA877C63A0CA7E6C"><enum>9.</enum><header>Enforcement by
			 State attorneys general</header>
			<subsection id="HA9F28F6BD9E14A7D911D9E3AB689BCE6"><enum>(a)</enum><header>In
			 general</header>
				<paragraph id="H362AD063BA8447F690211972873FB7FB"><enum>(1)</enum><header>Civil
			 actions</header><text>In any case in which the attorney general of a State or
			 any State or local law enforcement agency authorized by the State attorney
			 general or by State statute to prosecute violations of consumer protection law,
			 has reason to believe that an interest of the residents of that State has been
			 or is threatened or adversely affected by the engagement of a business entity
			 in a practice that is prohibited under this Act, the State or the State or
			 local law enforcement agency on behalf of the residents of the agency’s
			 jurisdiction, may bring a civil action on behalf of the residents of the State
			 or jurisdiction in a district court of the United States of appropriate
			 jurisdiction or any other court of competent jurisdiction, including a State
			 court, to—</text>
					<subparagraph id="H800A6BD5537349F2AF165BF75C2C1649"><enum>(A)</enum><text>enjoin that
			 practice;</text>
					</subparagraph><subparagraph id="H80CCAD8FD5F848218073EFAABB032A95"><enum>(B)</enum><text>enforce compliance
			 with this Act; or</text>
					</subparagraph><subparagraph id="H97F7E9873738441A88C9BDEC92C69150"><enum>(C)</enum><text>obtain civil
			 penalties of not more than $1,000 per day per individual whose sensitive
			 personally identifiable information was, or is reasonably believed to have
			 been, accessed or acquired by an unauthorized person, up to a maximum of
			 $1,000,000 per violation, unless such conduct is found to be willful or
			 intentional.</text>
					</subparagraph></paragraph><paragraph id="H405C9EC1D14F4F7380299C2957CE299A"><enum>(2)</enum><header>Notice</header>
					<subparagraph id="HFD90165532C142A6A0A9358350B53531"><enum>(A)</enum><header>In
			 general</header><text>Before filing an action under paragraph (1), the attorney
			 general of the State involved shall provide to the Attorney General of the
			 United States—</text>
						<clause id="H95F9DED07F03490A88F8DEA0B1572575"><enum>(i)</enum><text>written notice of
			 the action; and</text>
						</clause><clause id="H995824F85BD846CB9B49D499CE047D1F"><enum>(ii)</enum><text>a
			 copy of the complaint for the action.</text>
						</clause></subparagraph><subparagraph id="HE5751AB472A84DA0B1DC466581024888"><enum>(B)</enum><header>Exemption</header>
						<clause id="H881AEA2D1E4E4665B42807782FA90429"><enum>(i)</enum><header>In
			 general</header><text>Subparagraph (A) shall not apply with respect to the
			 filing of an action by an attorney general of a State under this Act, if the
			 State attorney general determines that it is not feasible to provide the notice
			 described in such subparagraph before the filing of the action.</text>
						</clause><clause id="H31EE8B9A843B49E2BB15DAE8E182B8F1"><enum>(ii)</enum><header>Notification</header><text>In
			 an action described in clause (i), the attorney general of a State shall
			 provide notice and a copy of the complaint to the Attorney General at the time
			 the State attorney general files the action.</text>
						</clause></subparagraph></paragraph></subsection><subsection id="H6E77902EA68240DE9D07F2C4B5F57B21"><enum>(b)</enum><header>Federal
			 proceedings</header><text>Upon receiving notice under subsection (a)(2), the
			 Attorney General shall have the right to—</text>
				<paragraph id="H3FDD70D9CF00477BA2E26919E9CD4BCD"><enum>(1)</enum><text>move to stay the
			 action, pending the final disposition of a pending Federal proceeding or
			 action;</text>
				</paragraph><paragraph id="H66A6FBA2B09846E6A8DEA7AF75DB3E59"><enum>(2)</enum><text>initiate an action
			 in the appropriate United States district court under section 8 and move to
			 consolidate all pending actions, including State actions, in such court;</text>
				</paragraph><paragraph id="HA1C11F37AA1340AC858762B55EA44719"><enum>(3)</enum><text>intervene in an
			 action brought under subsection (a)(2); and</text>
				</paragraph><paragraph id="HA89436E9F4D443D7B4FA11D709C64FEE"><enum>(4)</enum><text>file petitions for
			 appeal.</text>
				</paragraph></subsection><subsection id="H07C66C1B3D614297BEAE14C943C7CE22"><enum>(c)</enum><header>Pending
			 proceedings</header><text>If the Attorney General has instituted a proceeding
			 or action for a violation of this Act or any regulations thereunder, no
			 attorney general of a State may, during the pendency of such proceeding or
			 action, bring an action under this Act against any defendant named in such
			 criminal proceeding or civil action for any violation that is alleged in that
			 proceeding or action.</text>
			</subsection><subsection id="H9F3C0E33A10141FA95024FB7AFCFCE67"><enum>(d)</enum><header>Rule of
			 construction</header><text>For purposes of bringing any civil action under
			 subsection (a), nothing in this Act regarding notification shall be construed
			 to prevent an attorney general of a State from exercising the powers conferred
			 on such attorney general by the laws of that State to—</text>
				<paragraph id="HBE68DA7FCCC44DBCBB6D7413DEEF498F"><enum>(1)</enum><text>conduct
			 investigations;</text>
				</paragraph><paragraph id="H94F868BA2EAC446E8AED1BAD67CE624A"><enum>(2)</enum><text>administer oaths
			 or affirmations; or</text>
				</paragraph><paragraph id="H2BFEB3E0C08C4041B7FE4E688306ACAF"><enum>(3)</enum><text>compel the
			 attendance of witnesses or the production of documentary and other
			 evidence.</text>
				</paragraph></subsection><subsection id="H7AB1F7839AB7491E80A46C0A11E0C30A"><enum>(e)</enum><header>Venue; service
			 of process</header>
				<paragraph id="HFC9124FF36874909BF6465E69CC33DB6"><enum>(1)</enum><header>Venue</header><text>Any
			 action brought under subsection (a) may be brought in—</text>
					<subparagraph id="H4E6D78A4D2784415819D3E65DB9745BC"><enum>(A)</enum><text>the district court
			 of the United States that meets applicable requirements relating to venue under
			 section 1391 of title 28, United States Code; or</text>
					</subparagraph><subparagraph id="H0E9F828D868D40D08BE4D9476C30CFD9"><enum>(B)</enum><text>another court of
			 competent jurisdiction.</text>
					</subparagraph></paragraph><paragraph id="H05ACC61C2DDD4360A9426474F53E4A6E"><enum>(2)</enum><header>Service of
			 process</header><text>In an action brought under subsection (a), process may be
			 served in any district in which the defendant—</text>
					<subparagraph id="HB09AD36D19814DC5BB8A625F893484F3"><enum>(A)</enum><text>is an inhabitant;
			 or</text>
					</subparagraph><subparagraph id="H0AEECA227B3F45C8BFA911BE0C0C8903"><enum>(B)</enum><text>may be
			 found.</text>
					</subparagraph></paragraph></subsection><subsection id="H94099785D1D44F8DA63A472A03D7F8C5"><enum>(f)</enum><header>No private cause
			 of action</header><text>Nothing in this Act establishes a private cause of
			 action against a business entity for violation of any provision of this
			 Act.</text>
			</subsection></section><section id="HD30FB282ED704A7E8297B30456CE7F30"><enum>10.</enum><header>Effect on
			 Federal and State law</header><text display-inline="no-display-inline">The
			 provisions of this Act shall supersede any other provision of Federal law or
			 any provision of law of any State relating to notification by a business entity
			 engaged in interstate commerce or an agency of a security breach, except as
			 provided in section 5(b).</text>
		</section><section id="HAF2D5762A8F74910AC0F9739EB04EFA1"><enum>11.</enum><header>Authorization of
			 appropriations</header><text display-inline="no-display-inline">There are
			 authorized to be appropriated such sums as may be necessary to cover the costs
			 incurred by the United States Secret Service to carry out investigations and
			 risk assessments of security breaches as required under this Act.</text>
		</section><section id="H6F3FD51A11A64D848696C797A384A7DC"><enum>12.</enum><header>Reporting on
			 risk assessment exemptions</header>
			<subsection id="HB493A2A0387846DA908E9E34F71BB25A"><enum>(a)</enum><header>In
			 general</header><text display-inline="yes-display-inline">The United States
			 Secret Service shall report to Congress not later than 18 months after the date
			 of enactment of this Act, and upon the request by Congress thereafter,
			 on—</text>
				<paragraph id="H769752C80E8045D48D3461475B401F79"><enum>(1)</enum><text>the number and
			 nature of the security breaches described in the notices filed by those
			 business entities invoking the risk assessment exemption under section 3(b) of
			 this Act and the response of the United States Secret Service to such notices;
			 and</text>
				</paragraph><paragraph id="HF9D8E47AC7464DD7A64DD3BEFAE95AA0"><enum>(2)</enum><text>the number and
			 nature of security breaches subject to the national security and law
			 enforcement exemptions under section 3(a) of this Act.</text>
				</paragraph></subsection><subsection id="H4AF2E99026EC4AF98F9327CA6D4CC318"><enum>(b)</enum><header>Report</header><text>Any
			 report submitted under subsection (a) shall not disclose the contents of any
			 risk assessment provided to the United States Secret Service under this
			 Act.</text>
			</subsection></section><section id="HD735C02C5C53446FAE1CADD1B7CFB0DA"><enum>13.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act, the following definitions shall
			 apply:</text>
			<paragraph id="HAE62AE1D4F6B4DF8883B148F6201932C"><enum>(1)</enum><header>Agency</header><text>The
			 term <term>agency</term> has the same meaning given such term in section 551 of
			 title 5, United States Code.</text>
			</paragraph><paragraph id="HB71E672A27524647B3C430980C3F55B5"><enum>(2)</enum><header>Affiliate</header><text>The
			 term <term>affiliate</term> means persons related by common ownership or by
			 corporate control.</text>
			</paragraph><paragraph id="H316202933AF641E39812475C1A701E68"><enum>(3)</enum><header>Business
			 entity</header><text>The term <term>business entity</term> means any
			 organization, corporation, trust, partnership, sole proprietorship,
			 unincorporated association, venture established to make a profit, or nonprofit,
			 and any contractor, subcontractor, affiliate, or licensee thereof engaged in
			 interstate commerce.</text>
			</paragraph><paragraph id="H30D542E4408A45E3ACBF1FDAD2B13359"><enum>(4)</enum><header>Encrypted</header><text>The
			 term <term>encrypted</term>—</text>
				<subparagraph id="H28A695C3C86249799315F593F7A13F7F"><enum>(A)</enum><text>means the
			 protection of data in electronic form, in storage or in transit, using an
			 encryption technology that has been adopted by an established standards setting
			 body which renders such data indecipherable in the absence of associated
			 cryptographic keys necessary to enable decryption of such data; and</text>
				</subparagraph><subparagraph id="H31EF728BA857474F94D3FB864D8807F0"><enum>(B)</enum><text>includes
			 appropriate management and safeguards of such cryptographic keys so as to
			 protect the integrity of the encryption.</text>
				</subparagraph></paragraph><paragraph id="H3A2D4218B28F4EFD9B769AEA650BB435"><enum>(5)</enum><header>Personally
			 identifiable information</header><text>The term <term>personally identifiable
			 information</term> means any information, or compilation of information, in
			 electronic or digital form serving as a means of identification, as defined by
			 section 1028(d)(7) of title 18, United State Code.</text>
			</paragraph><paragraph id="H08AABC29A89140ACBEB4255F308FF680"><enum>(6)</enum><header>Security
			 breach</header>
				<subparagraph id="HF35D7336EE7C4D699A273B3B108C0FEC"><enum>(A)</enum><header>In
			 general</header><text>The term <term>security breach</term> means compromise of
			 the security, confidentiality, or integrity of computerized data through
			 misrepresentation or actions that result in, or there is a reasonable basis to
			 conclude has resulted in, acquisition of or access to sensitive personally
			 identifiable information that is unauthorized or in excess of
			 authorization.</text>
				</subparagraph><subparagraph id="HAF8E37D44FF54F6F82E81FFD66400E98"><enum>(B)</enum><header>Exclusion</header><text>The
			 term <term>security breach</term> does not include—</text>
					<clause id="HE3D5455A72584FFCA800CD001A3AE7E9"><enum>(i)</enum><text>a
			 good faith acquisition of sensitive personally identifiable information by a
			 business entity or agency, or an employee or agent of a business entity or
			 agency, if the sensitive personally identifiable information is not subject to
			 further unauthorized disclosure; or</text>
					</clause><clause id="HABA7B359A3924B909E67948F07B699EC"><enum>(ii)</enum><text>the
			 release of a public record not otherwise subject to confidentiality or
			 nondisclosure requirements.</text>
					</clause></subparagraph></paragraph><paragraph id="H780DC29FE4E54703A5B9B68ADC64CE1E"><enum>(7)</enum><header>Sensitive
			 personally identifiable information</header><text>The term <term>sensitive
			 personally identifiable information</term> means any information or compilation
			 of information, in electronic or digital form that includes—</text>
				<subparagraph id="H00617934697041ABB4C0FC2F60067919"><enum>(A)</enum><text>an individual’s
			 first and last name or first initial and last name in combination with any 1 of
			 the following data elements:</text>
					<clause id="HFAEA250038AF44C292D750E5E3AE21EF"><enum>(i)</enum><text>A
			 non-truncated Social Security number, driver’s license number, passport number,
			 or alien registration number.</text>
					</clause><clause id="HBD3A7673DB904D3E91B08CE5E4820290"><enum>(ii)</enum><text>Any
			 2 of the following:</text>
						<subclause id="HFC6A5AE2C199404C84EB9C19B4EDC6B1"><enum>(I)</enum><text>Home address or
			 telephone number.</text>
						</subclause><subclause id="HA8A965E9A14142E69D3BC7E45C90ED21"><enum>(II)</enum><text>Mother’s maiden
			 name, if identified as such.</text>
						</subclause><subclause id="HA88A21C11B534363B134DB98527EE1DF"><enum>(III)</enum><text>Month, day, and
			 year of birth.</text>
						</subclause></clause><clause id="HBC484F3DA6B147D3984049A112B9759F"><enum>(iii)</enum><text>Unique biometric
			 data such as a finger print, voice print, a retina or iris image, or any other
			 unique physical representation.</text>
					</clause><clause id="HD45E8D064E0A4830B77359A8C7E6A30B"><enum>(iv)</enum><text>A
			 unique account identifier, electronic identification number, user name, or
			 routing code in combination with any associated security code, access code, or
			 password that is required for an individual to obtain money, goods, services or
			 any other thing of value; or</text>
					</clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="H514795B57F4F43AD9C44260D2810646D"><enum>(B)</enum><text>a financial
			 account number or credit or debit card number in combination with any security
			 code, access code or password that is required for an individual to obtain
			 credit, withdraw funds, or engage in a financial transaction.</text>
				</subparagraph></paragraph></section><section commented="no" display-inline="no-display-inline" id="H0026239C002A4C619F1ADA1486912276" section-type="subsequent-section"><enum>14.</enum><header>Effective
			 date</header><text display-inline="no-display-inline">This Act shall take
			 effect on the expiration of the date which is 90 days after the date of
			 enactment of this Act.</text>
		</section></legis-body>
</bill>
