<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Reported-in-Senate" bill-type="olc" public-print="no" public-private="public" stage-count="1" star-print="no-star-print">
	<form display="yes">
		<distribution-code display="yes">II</distribution-code>
		<calendar>Calendar No. 208</calendar>
		<congress>111th CONGRESS</congress>
		<session>1st Session</session>
		<legis-num display="yes">S. 1490</legis-num>
		<current-chamber display="yes">IN THE SENATE OF THE UNITED
		  STATES</current-chamber>
		<action display="yes">
			<action-date date="20090722">July 22, 2009</action-date>
			<action-desc><sponsor name-id="S057">Mr. Leahy</sponsor> (for himself,
			 <cosponsor name-id="S307">Mr. Brown</cosponsor>, <cosponsor name-id="S230">Mr.
			 Feingold</cosponsor>, <cosponsor name-id="S270">Mr. Schumer</cosponsor>,
			 <cosponsor name-id="S161">Mr. Specter</cosponsor>, <cosponsor name-id="S308">Mr. Cardin</cosponsor>, and <cosponsor name-id="S118">Mr.
			 Hatch</cosponsor>) introduced the following bill; which was read twice and
			 referred to the <committee-name committee-id="SSJU00">Committee on the
			 Judiciary</committee-name></action-desc>
		</action>
		<action stage="Reported-in-Senate">
			<action-date>November 5, 2009</action-date>
			<action-desc>Reported by <sponsor name-id="S057">Mr. Leahy</sponsor>,
			 with amendments</action-desc>
			<action-instruction>Omit the part struck through and insert the part
			 printed in italic</action-instruction>
		</action>
		<legis-type display="yes">A BILL</legis-type>
		<official-title display="yes">To prevent and mitigate identity theft, to
		  ensure privacy, to provide notice of security breaches, and to enhance criminal
		  penalties, law enforcement assistance, and other protections against security
		  breaches, fraudulent access, and misuse of personally identifiable
		  information.</official-title>
	</form>
	<legis-body display-enacting-clause="yes-display-enacting-clause" style="OLC">
		<section commented="no" display-inline="no-display-inline" id="idBC757BBC5D2D452AB3FEEC0A005925EB" section-type="section-one"><enum>1.</enum><header display-inline="yes-display-inline">Short title; table of contents</header>
			<subsection commented="no" display-inline="no-display-inline" id="id0DC79081A5544A43ACEE0D3938C88A4A"><enum>(a)</enum><header display-inline="yes-display-inline">Short title</header><text display-inline="yes-display-inline">This Act may be cited as the
			 <quote><short-title>Personal Data Privacy and Security Act
			 of 2009</short-title></quote>.</text>
			</subsection><subsection commented="no" display-inline="no-display-inline" id="id908FE25517D846089A3520CDCB468544"><enum>(b)</enum><header display-inline="yes-display-inline">Table of contents</header><text display-inline="yes-display-inline">The table of contents of this Act is as
			 follows:</text>
				<toc>
					<toc-entry bold="off" idref="idBC757BBC5D2D452AB3FEEC0A005925EB" level="section">Sec. 1. Short title; table of contents.</toc-entry>
					<toc-entry bold="off" idref="idD75E514A664A45B39DAD2D9E8742B0E7" level="section">Sec. 2. Findings.</toc-entry>
					<toc-entry bold="off" idref="IDd589748af4d840b1a53a75db7bdb7d32" level="section">Sec. 3. Definitions.</toc-entry>
					<toc-entry bold="off" idref="id57BB7068312345C88A53B62678AE2D8A" level="title">TITLE I—Enhancing punishment for identity theft and other
				violations of data privacy and security</toc-entry>
					<toc-entry bold="off" idref="IDbbbfe7823d8b4212aeab45071b480182" level="section">Sec. 101. Organized criminal activity in connection with
				unauthorized access to personally identifiable information.</toc-entry>
					<toc-entry bold="off" idref="ID98057df8ce5e465296494f1084c8664c" level="section">Sec. 102. Concealment of security breaches involving sensitive
				personally identifiable information.</toc-entry>
					<toc-entry bold="off" idref="IDe2621a55b8dd4003ba8f4a73f015b644" level="section">Sec. 103. Review and amendment of Federal sentencing guidelines
				related to fraudulent access to or misuse of digitized or electronic personally
				identifiable information.</toc-entry>
					<toc-entry bold="off" idref="id52FE04166D504354BFFAC7070AD44326" level="section"><added-phrase reported-display-style="italic"></added-phrase>Sec. 104. Effects of identity
				theft on bankruptcy proceedings<added-phrase reported-display-style="italic">.</added-phrase></toc-entry>
					<toc-entry bold="off" idref="idF823923C0B90487788A0439B5A654169" level="title">TITLE II—Data brokers</toc-entry>
					<toc-entry bold="off" idref="IDe447c45d508a4eceac923d23f27156c0" level="section">Sec. 201. Transparency and accuracy of data
				collection.</toc-entry>
					<toc-entry bold="off" idref="IDe5bc6f4fb182485eaed306444501525e" level="section">Sec. 202. Enforcement.</toc-entry>
					<toc-entry bold="off" idref="ID10033cf1f27d420fab70142956e2f0b0" level="section">Sec. 203. Relation to State laws.</toc-entry>
					<toc-entry bold="off" idref="IDab58a1e4994746e3975f8bb335bea15c" level="section">Sec. 204. Effective date.</toc-entry>
					<toc-entry bold="off" idref="idD725C42479864A1D94B301FF34A11C92" level="title">TITLE III—Privacy and security of personally identifiable
				information </toc-entry>
					<toc-entry bold="off" idref="id3189B1C7B0974BA09A5D2EB0F2AA3456" level="subtitle">Subtitle A—A data privacy and security program</toc-entry>
					<toc-entry bold="off" idref="ID48089945808a49b592f4356d4079eae6" level="section">Sec. 301. Purpose and applicability of data privacy and
				security program.</toc-entry>
					<toc-entry bold="off" idref="ID01a5628cdcfe4d1aa8f738063c6c15c2" level="section">Sec. 302. Requirements for a personal data privacy and security
				program.</toc-entry>
					<toc-entry bold="off" idref="ID5cac3211a25b4f26a2628faea99c9f36" level="section">Sec. 303. Enforcement.</toc-entry>
					<toc-entry bold="off" idref="ID14b3a2c1aa4344dc97a4480451a1df47" level="section">Sec. 304. Relation to other laws.</toc-entry>
					<toc-entry bold="off" idref="idBC4FEB9AFE2A4E93BF957FCB6F00B7E3" level="subtitle">Subtitle B—Security breach notification</toc-entry>
					<toc-entry bold="off" idref="ID5510cd0d499f4913941a3308d15e6a1c" level="section">Sec. 311. Notice to individuals.</toc-entry>
					<toc-entry bold="off" idref="ID5dc909314300496fae2e47fd1f732bf2" level="section">Sec. 312. Exemptions.</toc-entry>
					<toc-entry bold="off" idref="IDbe5d0d5a9f634bfbbae2e9371a7cb5ab" level="section">Sec. 313. Methods of notice.</toc-entry>
					<toc-entry bold="off" idref="ID80d1a786110544b1b9b1a5fa3fc173b3" level="section">Sec. 314. Content of notification.</toc-entry>
					<toc-entry bold="off" idref="ID82ad6f96b46a4c7388f833d7611a6fc3" level="section">Sec. 315. Coordination of notification with credit reporting
				agencies.</toc-entry>
					<toc-entry bold="off" idref="IDde1241e504f94594beb8e50db8943996" level="section">Sec. 316. Notice to law enforcement.</toc-entry>
					<toc-entry bold="off" idref="ID300c058705674d1fa8a20180588bc781" level="section">Sec. 317. Enforcement.</toc-entry>
					<toc-entry bold="off" idref="ID28d22f15074d4f239f64734d16e27d82" level="section">Sec. 318. Enforcement by State attorneys general.</toc-entry>
					<toc-entry bold="off" idref="IDa5c5ed85f5b948b08f30d0800295937a" level="section">Sec. 319. Effect on Federal and State law.</toc-entry>
					<toc-entry bold="off" idref="ID90730e6c13ca4a49b382b3f1e9ee896e" level="section">Sec. 320. Authorization of appropriations.</toc-entry>
					<toc-entry bold="off" idref="ID0c5c8ec1f3e24cd886be5d8e2f850ca7" level="section">Sec. 321. Reporting on risk assessment exemptions.</toc-entry>
					<toc-entry bold="off" idref="ID527ade6c074f448da6e7e220dd02a32e" level="section">Sec. 322. Effective date.</toc-entry>
					<toc-entry bold="off" changed="deleted" idref="id75F2FE2314DC46D08187B9BAA28D1DD5" level="subtitle" reported-display-style="strikethrough">Subtitle C—Office of Federal Identity
				Protection</toc-entry>
					<toc-entry bold="off" changed="deleted" idref="id03A6D5A282264B0DAB093F8E9F1A89F2" level="section" reported-display-style="strikethrough">Sec. 331. Office of Federal Identity
				Protection.</toc-entry>
					<toc-entry bold="off" idref="id14E3D0E4F57E4B0A8C0C7207624800D1" level="title">TITLE IV—Government access to and use of commercial
				data</toc-entry>
					<toc-entry bold="off" idref="ID12b6cb5e199e41929bf7df592fcd092f" level="section">Sec. 401. General services administration review of
				contracts.</toc-entry>
					<toc-entry bold="off" idref="ID2c32eab739de4fea85488e717413b035" level="section">Sec. 402. Requirement to audit information security practices
				of contractors and third party business entities.</toc-entry>
					<toc-entry bold="off" idref="ID4056fc3599c54deeb9c0ed352866c385" level="section">Sec. 403. Privacy impact assessment of government use of
				commercial information services containing personally identifiable
				information.</toc-entry>
					<toc-entry bold="off" idref="ID938f0445fd614561aaba4ee7b370044f" level="section">Sec. 404. Implementation of chief privacy officer
				requirements.</toc-entry>
				</toc>
			</subsection></section><section commented="no" display-inline="no-display-inline" id="idD75E514A664A45B39DAD2D9E8742B0E7" section-type="subsequent-section"><enum>2.</enum><header display-inline="yes-display-inline">Findings</header><text display-inline="no-display-inline">Congress finds that—</text>
			<paragraph commented="no" display-inline="no-display-inline" id="IDa2c4c47dabdd4ad69f2d0f1c654437a6"><enum>(1)</enum><text display-inline="yes-display-inline">databases of personally identifiable
			 information are increasingly prime targets of hackers, identity thieves, rogue
			 employees, and other criminals, including organized and sophisticated criminal
			 operations;</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID04489a6412b1456689d78954a66c7729"><enum>(2)</enum><text display-inline="yes-display-inline">identity theft is a serious threat to the
			 Nation’s economic stability, homeland security, the development of e-commerce,
			 and the privacy rights of Americans;</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID0f26ae456c634482bf20d8082e5eed11"><enum>(3)</enum><text display-inline="yes-display-inline">over 9,300,000 individuals were victims of
			 identity theft in America last year;</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID55cac62686074915bc385d99731c5481"><enum>(4)</enum><text display-inline="yes-display-inline">security breaches are a serious threat to
			 consumer confidence, homeland security, e-commerce, and economic
			 stability;</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID1bad624abb344fe7b015322715f9b15a"><enum>(5)</enum><text display-inline="yes-display-inline">it is important for business entities that
			 own, use, or license personally identifiable information to adopt reasonable
			 procedures to ensure the security, privacy, and confidentiality of that
			 personally identifiable information;</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDd019a164205942959431067393e87109"><enum>(6)</enum><text display-inline="yes-display-inline">individuals whose personal information has
			 been compromised or who have been victims of identity theft should receive the
			 necessary information and assistance to mitigate their damages and to restore
			 the integrity of their personal information and identities;</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDf40de8e698734cfd86baf4922b350a82"><enum>(7)</enum><text display-inline="yes-display-inline">data brokers have assumed a significant
			 role in providing identification, authentication, and screening services, and
			 related data collection and analyses for commercial, nonprofit, and government
			 operations;</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID7d7aeccd1b7f452bbe50b38a9cf86a12"><enum>(8)</enum><text display-inline="yes-display-inline">data misuse and use of inaccurate data have
			 the potential to cause serious or irreparable harm to an individual’s
			 livelihood, privacy, and liberty and undermine efficient and effective business
			 and government operations;</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID454f8fced90146e0a8af810896df63ca"><enum>(9)</enum><text display-inline="yes-display-inline">there is a need to ensure that data brokers
			 conduct their operations in a manner that prioritizes fairness, transparency,
			 accuracy, and respect for the privacy of consumers;</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID59394f800d994f31a1158c488c7d4fff"><enum>(10)</enum><text display-inline="yes-display-inline">government access to commercial data can
			 potentially improve safety, law enforcement, and national security; and</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID80b5a6bc1c2d448f94909dc0ee00bdac"><enum>(11)</enum><text display-inline="yes-display-inline">because government use of commercial data
			 containing personal information potentially affects individual privacy, and law
			 enforcement and national security operations, there is a need for Congress to
			 exercise oversight over government use of commercial data.</text>
			</paragraph></section><section commented="no" display-inline="no-display-inline" id="IDd589748af4d840b1a53a75db7bdb7d32" section-type="subsequent-section"><enum>3.</enum><header display-inline="yes-display-inline">Definitions</header><text display-inline="no-display-inline">In this Act, the following definitions shall
			 apply:</text>
			<paragraph commented="no" display-inline="no-display-inline" id="ID6b46a295351f45bca8862eaacaa06801"><enum>(1)</enum><header display-inline="yes-display-inline">Agency</header><text display-inline="yes-display-inline">The term <term>agency</term> has the same
			 meaning given such term in section 551 of title 5, United States Code.</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDe27e8f808b154a4e82175769e61f717c"><enum>(2)</enum><header display-inline="yes-display-inline">Affiliate</header><text display-inline="yes-display-inline">The term <term>affiliate</term> means
			 persons related by common ownership or by corporate control.</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID45177ec08eb54f5d85a71563525e94e8"><enum>(3)</enum><header display-inline="yes-display-inline">Business entity</header><text display-inline="yes-display-inline">The term <term>business entity</term> means
			 any organization, corporation, trust, partnership, sole proprietorship,
			 unincorporated association, <added-phrase reported-display-style="italic"></added-phrase>or<added-phrase reported-display-style="italic"></added-phrase> venture established to make a
			 profit, or nonprofit.</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDbb1410bcbaed48e09a39a9d58c592601"><enum>(4)</enum><header display-inline="yes-display-inline">Identity
			 theft</header><text display-inline="yes-display-inline">The term <term>identity
			 theft</term> means a violation of section 1028 of title 18, United States
			 Code.</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID421132fe62314202b0a6b558eff900fc"><enum>(5)</enum><header display-inline="yes-display-inline">Data broker</header><text display-inline="yes-display-inline">The term <term>data broker</term> means a
			 business entity which for monetary fees or dues regularly engages in the
			 practice of collecting, transmitting, or providing access to sensitive
			 personally identifiable information on more than 5,000 individuals who are not
			 the customers or employees of that business entity or affiliate primarily for
			 the purposes of providing such information to nonaffiliated third parties on an
			 interstate basis.</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID3b80cbb1dae54c41bd803298c33a4114"><enum>(6)</enum><header display-inline="yes-display-inline">Data
			 furnisher</header><text display-inline="yes-display-inline">The term <term>data
			 furnisher</term> means any agency, organization, corporation, trust,
			 partnership, sole proprietorship, unincorporated association, or nonprofit that
			 serves as a source of information for a data broker.</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="idEAC844C6681D485491A58D0D6134494F"><enum>(7)</enum><header display-inline="yes-display-inline">Encryption</header><text display-inline="yes-display-inline">The term <quote>encryption</quote>—</text>
				<subparagraph commented="no" display-inline="no-display-inline" id="idFD707E02AC4E4C45814FE3598C7CA84C"><enum>(A)</enum><text display-inline="yes-display-inline">means the protection of data in electronic
			 form, in storage or in transit, using an encryption technology that has been
			 adopted by <deleted-phrase reported-display-style="strikethrough">an
			 established</deleted-phrase><added-phrase reported-display-style="italic">a
			 widely accepted</added-phrase> standards setting body<added-phrase reported-display-style="italic"> or, has been widely accepted as an effective
			 industry practice</added-phrase> which renders such data indecipherable in the
			 absence of associated cryptographic keys necessary to enable decryption of such
			 data; and</text>
				</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idD50D1D0CAFC8461F94DBAF994610965F"><enum>(B)</enum><text display-inline="yes-display-inline">includes appropriate management and
			 safeguards of such cryptographic keys so as to protect the integrity of the
			 encryption.</text>
				</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID708763bb5a6547018d66b9e4109a7115"><enum>(8)</enum><header display-inline="yes-display-inline">Personal electronic record</header>
				<subparagraph commented="no" display-inline="no-display-inline" id="ID5481d7730bee42ea9d77786a3ae95139"><enum>(A)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">The term <term>personal electronic
			 record</term> means data associated with an individual contained in a database,
			 networked or integrated databases, or other data system that
			 <added-phrase reported-display-style="italic"></added-phrase>is provided to
			 nonaffiliated third parties and includes<added-phrase reported-display-style="italic"></added-phrase> sensitive personally
			 identifiable information <added-phrase reported-display-style="italic"></added-phrase>about<added-phrase reported-display-style="italic"></added-phrase> that individual.</text>
				</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID4369a17e080f4a348ad99bf88bea9f3e"><enum>(B)</enum><header display-inline="yes-display-inline">Exclusions</header><text display-inline="yes-display-inline">The term <term>personal electronic
			 record</term> does not include—</text>
					<clause commented="no" display-inline="no-display-inline" id="IDd02a1a34ad8d4162b7dbfb508757011b"><enum>(i)</enum><text display-inline="yes-display-inline">any data related to an individual’s past
			 purchases of consumer goods; or</text>
					</clause><clause commented="no" display-inline="no-display-inline" id="IDeed2686065464aa3872c933c3dca25b4"><enum>(ii)</enum><text display-inline="yes-display-inline">any proprietary assessment or evaluation of
			 an individual or any proprietary assessment or evaluation of information about
			 an individual.</text>
					</clause></subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID277a6f9dfb7b437db77f20ff4f84aca8"><enum>(9)</enum><header display-inline="yes-display-inline">Personally identifiable
			 information</header><text display-inline="yes-display-inline">The term
			 <term>personally identifiable information</term> means any information, or
			 compilation of information, in electronic or digital form serving as a means of
			 identification, as defined by section 1028(d)(7) of title 18, United State
			 Code.</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID3d90719ddb9d4d89ac2511f5d43030d5"><enum>(10)</enum><header display-inline="yes-display-inline">Public record source</header><text display-inline="yes-display-inline">The term <term>public record source</term>
			 means the Congress, any agency, any State or local government agency, the
			 government of the District of Columbia and governments of the territories or
			 possessions of the United States, and Federal, State or local courts, courts
			 martial and military commissions, that maintain personally identifiable
			 information in records available to the public.</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDcf447112b33241bbafa2e1679b5ed4fd"><enum>(11)</enum><header display-inline="yes-display-inline">Security breach</header>
				<subparagraph commented="no" display-inline="no-display-inline" id="ID1795088a852f416cb8c1f8b6d46cf325"><enum>(A)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">The term <term>security breach</term> means
			 compromise of the security, confidentiality, or integrity of computerized data
			 through misrepresentation or actions that result in, or there is a reasonable
			 basis to conclude has resulted in, acquisition of or access to sensitive
			 personally identifiable information that is unauthorized or in excess of
			 authorization <added-phrase reported-display-style="italic">and which present a
			 significant risk of harm or fraud to any individual</added-phrase>.</text>
				</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID32aadcee3e724a14a6ff42e11bcda31d"><enum>(B)</enum><header display-inline="yes-display-inline">Exclusion</header><text display-inline="yes-display-inline">The term <term>security breach</term> does
			 not include—</text>
					<clause commented="no" display-inline="no-display-inline" id="IDdaa3112ae3d7459abf9485ef3d7d77ad"><enum>(i)</enum><text display-inline="yes-display-inline">a good faith acquisition of sensitive
			 personally identifiable information by a business entity or agency, or an
			 employee or agent of a business entity or agency, if the sensitive personally
			 identifiable information is not subject to further unauthorized disclosure;
			 or</text>
					</clause><clause commented="no" display-inline="no-display-inline" id="idD5FF6A5E552942ECBD9BB5200E4A06A1"><enum>(ii)</enum><text display-inline="yes-display-inline">the release of a public record not
			 otherwise subject to confidentiality or nondisclosure requirements.</text>
					</clause></subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDe99b189310e04a72969f33adb3158514"><enum>(12)</enum><header display-inline="yes-display-inline">Sensitive personally identifiable
			 information</header><text display-inline="yes-display-inline">The term
			 <term>sensitive personally identifiable information</term> means any
			 information or compilation of information, in electronic or digital form that
			 includes—</text>
				<subparagraph commented="no" display-inline="no-display-inline" id="ID3dc22ad332974f5f8df1fdb0edb915b2"><enum>(A)</enum><text display-inline="yes-display-inline">an individual's first and last name or
			 first initial and last name in combination with any 1 of the following data
			 elements:</text>
					<clause commented="no" display-inline="no-display-inline" id="ID78ada63e7c82488dac32cd2b523ccaab"><enum>(i)</enum><text display-inline="yes-display-inline">A non-truncated social security number,
			 driver's license number, passport number, or alien registration number.</text>
					</clause><clause commented="no" display-inline="no-display-inline" id="ID8b166ce6db234d039fa880e8311901c3"><enum>(ii)</enum><text display-inline="yes-display-inline">Any 2 of the following:</text>
						<subclause commented="no" display-inline="no-display-inline" id="ID32ce80211bca4306a8ee62599e1fec11"><enum>(I)</enum><text display-inline="yes-display-inline">Home address or telephone number.</text>
						</subclause><subclause commented="no" display-inline="no-display-inline" id="IDa0d1db2d079740468b98f0a7696a13c0"><enum>(II)</enum><text display-inline="yes-display-inline">Mother's maiden name, if identified as
			 such.</text>
						</subclause><subclause commented="no" display-inline="no-display-inline" id="ID1ec42025860143229b6bd52e8434a072"><enum>(III)</enum><text display-inline="yes-display-inline">Month, day, and year of birth.</text>
						</subclause></clause><clause commented="no" display-inline="no-display-inline" id="ID8c601c35ad2d4a809aeeee8f9e1a3fff"><enum>(iii)</enum><text display-inline="yes-display-inline">Unique biometric data such as a finger
			 print, voice print, a retina or iris image, or any other unique physical
			 representation.</text>
					</clause><clause commented="no" display-inline="no-display-inline" id="ID5ebc421720fb4463a4f69f324113db8c"><enum>(iv)</enum><text display-inline="yes-display-inline">A unique account identifier, electronic
			 identification number, user name, or routing code in combination with any
			 associated security code, access code, or password that is required for an
			 individual to obtain money, goods, services, or any other thing of value;
			 or</text>
					</clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDb275561b64d34e31823ff4a792b2b881"><enum>(B)</enum><text display-inline="yes-display-inline">a financial account number or credit or
			 debit card number in combination with any security code, access code, or
			 password that is required for an individual to obtain credit, withdraw funds,
			 or engage in a financial transaction.</text>
				</subparagraph></paragraph></section><title commented="no" id="id57BB7068312345C88A53B62678AE2D8A" level-type="subsequent"><enum>I</enum><header display-inline="yes-display-inline">Enhancing punishment for identity theft and
			 other violations of data privacy and security</header>
			<section commented="no" display-inline="no-display-inline" id="IDbbbfe7823d8b4212aeab45071b480182" section-type="subsequent-section"><enum>101.</enum><header display-inline="yes-display-inline">Organized criminal activity in connection
			 with unauthorized access to personally identifiable information</header><text display-inline="no-display-inline">Section 1961(1) of title 18, United States
			 Code, is amended by inserting <quote>section 1030(a)(2)(D) (relating to fraud
			 and related activity in connection with unauthorized access to sensitive
			 personally identifiable information as defined in the
			 <short-title>Personal Data Privacy and Security Act of
			 2009</short-title>,</quote> before <quote>section 1084</quote>.</text>
			</section><section commented="no" display-inline="no-display-inline" id="ID98057df8ce5e465296494f1084c8664c" section-type="subsequent-section"><enum>102.</enum><header display-inline="yes-display-inline">Concealment of security breaches involving
			 sensitive personally identifiable information</header>
				<subsection commented="no" display-inline="no-display-inline" id="ID574a854e62eb447bb4f50ec14b792143"><enum>(a)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">Chapter 47 of title 18, United States Code,
			 is amended by adding at the end the following:</text>
					<quoted-block display-inline="no-display-inline" id="idF9342237D76A4CEAAE27A5A099B89861" style="USC">
						<section commented="no" display-inline="no-display-inline" id="IDa347d393004b4e53878f3745e4bd6e88" section-type="subsequent-section"><enum>1041.</enum><header display-inline="yes-display-inline">Concealment of security breaches involving
				sensitive personally identifiable information</header>
							<subsection commented="no" display-inline="no-display-inline" id="ID4bcfaf400ddf414582209c7244832564"><enum>(a)</enum><text display-inline="yes-display-inline">Whoever, having knowledge of a security
				breach and of the obligation to provide notice of such breach to individuals
				under title III of the <short-title>Personal Data Privacy
				and Security Act of 2009</short-title>, and having not otherwise qualified for
				an exemption from providing notice under section 312 of such Act, intentionally
				and willfully conceals the fact of such security breach and which breach causes
				economic damage to 1 or more persons, shall be fined under this title or
				imprisoned not more than 5 years, or both.</text>
							</subsection><subsection commented="no" display-inline="no-display-inline" id="IDa6c6cc34315f4ba599f4b63575125021"><enum>(b)</enum><text display-inline="yes-display-inline">For purposes of subsection (a), the term
				<term>person</term> has the same meaning as in section 1030(e)(12) of title 18,
				United States Code.</text>
							</subsection><subsection commented="no" display-inline="no-display-inline" id="id8463FC3B2CCE41E0A211E3946F886E25"><enum>(c)</enum><text display-inline="yes-display-inline">Any person seeking an exemption under
				section 312(b) of the <short-title>Personal Data Privacy
				and Security Act of 2009</short-title> shall be immune from prosecution under
				this section if the United States Secret Service does not indicate, in writing,
				that such notice be given under section 312(b)(3) of such Act<added-phrase reported-display-style="italic">.</added-phrase></text>
							</subsection></section><after-quoted-block>.</after-quoted-block></quoted-block>
				</subsection><subsection commented="no" display-inline="no-display-inline" id="IDe250299bce944fcb9cedfd92fc33a8c7"><enum>(b)</enum><header display-inline="yes-display-inline">Conforming and technical
			 amendments</header><text display-inline="yes-display-inline">The table of
			 sections for chapter 47 of title 18, United States Code, is amended by adding
			 at the end the following:</text>
					<quoted-block display-inline="no-display-inline" id="id4A4F3645F72549419DD8D57CB66D2322" style="OLC">
						<toc>
							<toc-entry bold="off" level="section">1041. Concealment of security
				breaches involving personally identifiable
				information.</toc-entry>
						</toc>
						<after-quoted-block>.</after-quoted-block></quoted-block>
				</subsection><subsection commented="no" display-inline="no-display-inline" id="ID0cfb1f2062d849319cbd7ed151526023"><enum>(c)</enum><header display-inline="yes-display-inline">Enforcement authority</header>
					<paragraph commented="no" display-inline="no-display-inline" id="id74BEB32B70524064BF1CC860F6B7ADD3"><enum>(1)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">The United States Secret Service shall have
			 the authority to investigate offenses under this section.</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id7117EAAA2D194B5A824D86D68273DD2E"><enum>(2)</enum><header display-inline="yes-display-inline">Nonexclusivity</header><text display-inline="yes-display-inline">The authority granted in paragraph (1)
			 shall not be exclusive of any existing authority held by any other Federal
			 agency.</text>
					</paragraph></subsection></section><section commented="no" display-inline="no-display-inline" id="IDe2621a55b8dd4003ba8f4a73f015b644" section-type="subsequent-section"><enum>103.</enum><header display-inline="yes-display-inline">Review and amendment of Federal sentencing
			 guidelines related to fraudulent access to or misuse of digitized or electronic
			 personally identifiable information</header>
				<subsection commented="no" display-inline="no-display-inline" id="ID04468b6f7d6641249b40f88e02dbaa1b"><enum>(a)</enum><header display-inline="yes-display-inline">Review and amendment</header><text display-inline="yes-display-inline">The United States Sentencing Commission,
			 pursuant to its authority under section 994 of title 28, United States Code,
			 and in accordance with this section, shall review and, if appropriate, amend
			 the Federal sentencing guidelines (including its policy statements) applicable
			 to persons convicted of using fraud to access, or misuse of, digitized or
			 electronic personally identifiable information, including identity theft or any
			 offense under—</text>
					<paragraph commented="no" display-inline="no-display-inline" id="ID28a6ebacad884345902a831f3934e048"><enum>(1)</enum><text display-inline="yes-display-inline">sections 1028, 1028A, 1030, 1030A, 2511,
			 and 2701 of title 18, United States Code; and</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDac0a76ec593f418296e707cc6967b755"><enum>(2)</enum><text display-inline="yes-display-inline">any other relevant provision.</text>
					</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="ID777e36d16fa44b08a9cab1cca9ab992c"><enum>(b)</enum><header display-inline="yes-display-inline">Requirements</header><text display-inline="yes-display-inline">In carrying out the requirements of this
			 section, the United States Sentencing Commission shall—</text>
					<paragraph commented="no" display-inline="no-display-inline" id="ID2112f8ae2e224dc493bed3a4a3dea482"><enum>(1)</enum><text display-inline="yes-display-inline">ensure that the Federal sentencing
			 guidelines (including its policy statements) reflect—</text>
						<subparagraph commented="no" display-inline="no-display-inline" id="IDddd417aaa96b40799d7fb2d9fe7bcbcf"><enum>(A)</enum><text display-inline="yes-display-inline">the serious nature of the offenses and
			 penalties referred to in this Act;</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDc7e8057b660b413db7c588bc04973c91"><enum>(B)</enum><text display-inline="yes-display-inline">the growing incidences of theft and misuse
			 of digitized or electronic personally identifiable information, including
			 identity theft; and</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID24235709f8ba463c9bec64b91e0cf856"><enum>(C)</enum><text display-inline="yes-display-inline">the need to deter, prevent, and punish such
			 offenses;</text>
						</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID180963dc2404432a9773ad4013d4b26d"><enum>(2)</enum><text display-inline="yes-display-inline">consider the extent to which the Federal
			 sentencing guidelines (including its policy statements) adequately address
			 violations of the sections amended by this Act to—</text>
						<subparagraph commented="no" display-inline="no-display-inline" id="ID2f8e06ff702b43b0bccaedeb1b29d9de"><enum>(A)</enum><text display-inline="yes-display-inline">sufficiently deter and punish such
			 offenses; and</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID166d86e267d04eaf9fbfb884317b274e"><enum>(B)</enum><text display-inline="yes-display-inline">adequately reflect the enhanced penalties
			 established under this Act;</text>
						</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID0fdef680829b4a0a95ff50fecf118a62"><enum>(3)</enum><text display-inline="yes-display-inline">maintain reasonable consistency with other
			 relevant directives and sentencing guidelines;</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID4d1e8b2b14e54fa1b286aa7f359637db"><enum>(4)</enum><text display-inline="yes-display-inline">account for any additional aggravating or
			 mitigating circumstances that might justify exceptions to the generally
			 applicable sentencing ranges;</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID13e363721f074364a24861e4248919c5"><enum>(5)</enum><text display-inline="yes-display-inline">consider whether to provide a sentencing
			 enhancement for those convicted of the offenses described in subsection (a), if
			 the conduct involves—</text>
						<subparagraph commented="no" display-inline="no-display-inline" id="ID8e9e812c18dc46adbae1111afaa7b46c"><enum>(A)</enum><text display-inline="yes-display-inline">the online sale of fraudulently obtained or
			 stolen personally identifiable information;</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID29dd62998d7d4d429977552414c517cc"><enum>(B)</enum><text display-inline="yes-display-inline">the sale of fraudulently obtained or stolen
			 personally identifiable information to an individual who is engaged in
			 terrorist activity or aiding other individuals engaged in terrorist activity;
			 or</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDad4f7e9b223742f09c6dead5d1e7e53b"><enum>(C)</enum><text display-inline="yes-display-inline">the sale of fraudulently obtained or stolen
			 personally identifiable information to finance terrorist activity or other
			 criminal activities;</text>
						</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDbab007e0bfb340679731fe66f185c15d"><enum>(6)</enum><text display-inline="yes-display-inline">make any necessary conforming changes to
			 the Federal sentencing guidelines to ensure that such guidelines (including its
			 policy statements) as described in subsection (a) are sufficiently stringent to
			 deter, and adequately reflect crimes related to fraudulent access to, or misuse
			 of, personally identifiable information; and</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDeafa42fefc00458397ebba0dec9e9392"><enum>(7)</enum><text display-inline="yes-display-inline">ensure that the Federal sentencing
			 guidelines adequately meet the purposes of sentencing under section 3553(a)(2)
			 of title 18, United States Code.</text>
					</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="IDccf6ee99775147f6823d50b216346604"><enum>(c)</enum><header display-inline="yes-display-inline">Emergency authority to sentencing
			 commission</header><text display-inline="yes-display-inline">The United States
			 Sentencing Commission may, as soon as practicable, promulgate amendments under
			 this section in accordance with procedures established in section 21(a) of the
			 Sentencing Act of 1987 (28 U.S.C. 994 note) as though the authority under that
			 Act had not expired.</text>
				</subsection></section><section commented="no" display-inline="no-display-inline" id="id52FE04166D504354BFFAC7070AD44326" section-type="subsequent-section"><enum>104.</enum><header display-inline="yes-display-inline">Effects of identity theft on bankruptcy
			 proceedings</header>
				<subsection commented="no" display-inline="no-display-inline" id="ID8f38b172c35b40d69385b471967d620e"><enum>(a)</enum><header display-inline="yes-display-inline">Definitions</header><text display-inline="yes-display-inline">Section 101 of title 11, United States
			 Code, is amended—</text>
					<paragraph commented="no" display-inline="no-display-inline" id="IDed69982a43e64db8a507b0f4e022dc3e"><enum>(1)</enum><text display-inline="yes-display-inline">by redesignating paragraph (27B) as
			 paragraph (27D); and</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDe87d3913af5c403b9f34a5021aa13808"><enum>(2)</enum><text display-inline="yes-display-inline">by inserting after paragraph (27A) the
			 following:</text>
						<quoted-block display-inline="no-display-inline" id="idA5EC9B6BB8BB437196009F6F636769E9" style="OLC">
							<paragraph commented="no" display-inline="no-display-inline" id="ID3bb22de8a36146178e6a991181626573"><enum>(27)</enum><text display-inline="yes-display-inline">The term <quote>identity theft</quote>
				means a fraud committed or attempted using the personally identifiable
				information of another person.</text>
							</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDa4cae35c1d4040058c3699a76921b5d1"><enum>(28)</enum><text display-inline="yes-display-inline">The term <quote>identity theft
				victim</quote> means a debtor who, as a result of an identify theft in any
				consecutive 12-month period during the 3-year period before the date on which a
				petition is filed under this title, had claims asserted against such debtor in
				excess of the least of—</text>
								<subparagraph commented="no" display-inline="no-display-inline" id="ID0b1f59c51f88455096e1d67140ee2051"><enum>(A)</enum><text display-inline="yes-display-inline">$20,000;</text>
								</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID49e5ee2a54dc421089978e60a8560c30"><enum>(B)</enum><text display-inline="yes-display-inline">50 percent of all claims asserted against
				such debtor; or</text>
								</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDaf69a3187fd84fde8dbf931bf8eee25f"><enum>(C)</enum><text display-inline="yes-display-inline">25 percent of the debtor's gross income for
				such 12-month
				period.</text>
								</subparagraph></paragraph><after-quoted-block>.</after-quoted-block></quoted-block>
					</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="ID7ca86c31ef1d4905aff135c23e499ee9"><enum>(b)</enum><header display-inline="yes-display-inline">Prohibition</header><text display-inline="yes-display-inline">Section 707(b) of title 11, United States
			 Code, is amended by adding at the end the following:</text>
					<quoted-block display-inline="no-display-inline" id="id2FEAD0E5739743E7AB41436CAD7E7CF0" style="OLC">
						<paragraph commented="no" display-inline="no-display-inline" id="ID68bb70cf0e1145509a6198dffbbe3aa9" indent="up1"><enum>(8)</enum><text display-inline="yes-display-inline">No judge, United States trustee (or
				bankruptcy administrator, if any), trustee, or other party in interest may file
				a motion under paragraph (2) if the debtor is an identity theft
				victim.</text>
						</paragraph><after-quoted-block>.</after-quoted-block></quoted-block>
				</subsection></section></title><title commented="no" id="idF823923C0B90487788A0439B5A654169" level-type="subsequent"><enum>II</enum><header display-inline="yes-display-inline">Data brokers</header>
			<section commented="no" display-inline="no-display-inline" id="IDe447c45d508a4eceac923d23f27156c0" section-type="subsequent-section"><enum>201.</enum><header display-inline="yes-display-inline">Transparency and accuracy of data
			 collection</header>
				<subsection commented="no" display-inline="no-display-inline" id="ID5ef1a5d7920f442e8511ebad763bb79b"><enum>(a)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">Data brokers engaging in interstate
			 commerce are subject to the requirements of this title for any product or
			 service offered to third parties that allows access or use of sensitive
			 personally identifiable information.</text>
				</subsection><subsection commented="no" display-inline="no-display-inline" id="ID38b0e3b0df144f1db76af36be35174b5"><enum>(b)</enum><header display-inline="yes-display-inline">Limitation</header><text display-inline="yes-display-inline">Notwithstanding any other provision of this
			 title, this section shall not apply to—</text>
					<paragraph commented="no" display-inline="no-display-inline" id="ID7ba8e3ebb34947e096be36b15d339822"><enum>(1)</enum><text display-inline="yes-display-inline">any product or service offered by a data
			 broker engaging in interstate commerce where such product or service is
			 currently subject to, and in compliance with, access and accuracy protections
			 similar to those under subsections (c) through
			 <deleted-phrase reported-display-style="strikethrough">(f)</deleted-phrase><added-phrase reported-display-style="italic">(e)</added-phrase> of this section under the
			 Fair Credit Reporting Act (Public Law 91–508);</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDd8bc7350b33d44efb801991c9594ed1d"><enum>(2)</enum><text display-inline="yes-display-inline">any data broker that is subject to
			 regulation under the Gramm-Leach-Bliley Act (Public Law 106–102);</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id2C6FD2E6DA354716AD838DF200E72ADD"><enum>(3)</enum><text display-inline="yes-display-inline">any data broker currently subject to and in
			 compliance with the data security requirements for such entities under the
			 Health Insurance Portability and Accountability Act (Public Law 104–191), and
			 its implementing regulations;</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDc0f4642652ad4cfc807ffc48c901746a"><enum>(4)</enum><text display-inline="yes-display-inline">information in a personal electronic record
			 that—</text>
						<subparagraph commented="no" display-inline="no-display-inline" id="ID926e4ab368134b8f8c2144b1dc2461f3"><enum>(A)</enum><text display-inline="yes-display-inline">the data broker has identified as
			 inaccurate, but maintains for the purpose of aiding the data broker in
			 preventing inaccurate information from entering an individual's personal
			 electronic record; and</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDf355b3045cdd48c1822f93fe75b41f24"><enum>(B)</enum><text display-inline="yes-display-inline">is not maintained primarily for the purpose
			 of transmitting or otherwise providing that information, or assessments based
			 on that information, to nonaffiliated third parties;
			 <deleted-phrase reported-display-style="strikethrough">and</deleted-phrase></text>
						</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID948931ace4664580a20f656cd8be5925"><enum>(5)</enum><text display-inline="yes-display-inline">information concerning proprietary
			 methodologies, techniques, scores, or algorithms relating to fraud prevention
			 not normally provided to third parties in the ordinary course of
			 business<deleted-phrase reported-display-style="strikethrough">.</deleted-phrase><added-phrase reported-display-style="italic"> ; and</added-phrase></text>
					</paragraph><paragraph changed="added" id="idE95C2CA7EF3B466F995DB0E8C50705E6" reported-display-style="italic"><enum>(6)</enum><text>information that is used
			 for legitimate governmental or fraud prevention purposes that would be
			 compromised by disclosure to the individual.
			 <added-phrase reported-display-style="italic"></added-phrase></text>
					</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="ID4ffc3e4061eb495cb9e180fe4317af5c"><enum>(c)</enum><header display-inline="yes-display-inline">Disclosures to individuals</header>
					<paragraph commented="no" display-inline="no-display-inline" id="ID891adecdafe74a719c3bb7e176a9dbec"><enum>(1)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">A data broker shall, upon the request of an
			 individual, disclose to such individual for a reasonable fee all personal
			 electronic records pertaining to that individual maintained specifically for
			 disclosure to third parties that request information on that individual in the
			 ordinary course of business in the databases or systems of the data broker at
			 the time of such request.</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID11879646a8c8459a82322ecf97375d53"><enum>(2)</enum><header display-inline="yes-display-inline">Information on how to correct
			 inaccuracies</header><text display-inline="yes-display-inline">The disclosures
			 required under paragraph (1) shall also include guidance to individuals on
			 procedures for correcting inaccuracies.</text>
					</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="id1A741AE49E27420D8142076CA2F56CE8"><enum>(d)</enum><header display-inline="yes-display-inline">Disclosure to individuals of adverse
			 actions taken by third parties</header>
					<paragraph commented="no" display-inline="no-display-inline" id="idE34DFF0987924A6DBBE4B9B0AD3DDB48"><enum>(1)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">In addition to any other rights established
			 under this Act, if a person takes any adverse action with respect to any
			 individual that is based, in whole or in part, on any information contained in
			 a personal electronic record that is maintained, updated, or otherwise owned or
			 possessed by a data broker, such person, at no cost to the affected individual,
			 shall provide—</text>
						<subparagraph commented="no" display-inline="no-display-inline" id="ID7ffaea0ba64a4827b605afd454e0b5b9"><enum>(A)</enum><text display-inline="yes-display-inline">written or electronic notice of the adverse
			 action to the individual;</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID895b67bd775d4e38a90921ed60ef319c"><enum>(B)</enum><text display-inline="yes-display-inline">to the individual, in writing or
			 electronically, the name, address, and telephone number of the data broker that
			 furnished the information to the person;</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id513AD5550CAD4625ACAC7FE49952B931"><enum>(C)</enum><text display-inline="yes-display-inline">a copy of the information such person
			 obtained from the data broker; and</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id74E97A7CBFA14CB786AC7C15B5B63B48"><enum>(D)</enum><text display-inline="yes-display-inline">information to the individual on the
			 procedures for correcting any inaccuracies in such information.</text>
						</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="idA6F09B96C8EB4D67B33CAAA4DD56A6B4"><enum>(2)</enum><header display-inline="yes-display-inline">Accepted methods of notice</header><text display-inline="yes-display-inline">A person shall be in compliance with the
			 notice requirements under paragraph (1) if such person provides written or
			 electronic notice in the same manner and using the same methods as are required
			 under section 313(1) of this Act.</text>
					</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="IDe7f47b828c524e09ade1a5be3482448f"><enum>(e)</enum><header display-inline="yes-display-inline">Accuracy resolution process</header>
					<paragraph commented="no" display-inline="no-display-inline" id="IDba5b406d200e4eea86382044cb6abc9a"><enum>(1)</enum><header display-inline="yes-display-inline">Information from a public record or
			 licensor</header>
						<subparagraph commented="no" display-inline="no-display-inline" id="ID6c920096d7974dfcb4eb67aba8c92d27"><enum>(A)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">If an individual notifies a data broker of
			 a dispute as to the completeness or accuracy of information disclosed to such
			 individual under subsection (c) that is obtained from a public record source or
			 a license agreement, such data broker shall determine within 30 days whether
			 the information in its system accurately and completely records the information
			 available from the licensor or public record source.</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDbed3e535f70e43e5acae274cce51f8fa"><enum>(B)</enum><header display-inline="yes-display-inline">Data broker actions</header><text display-inline="yes-display-inline">If a data broker determines under
			 subparagraph (A) that the information in its systems does not accurately and
			 completely record the information available from a public record source or
			 licensor, the data broker shall—</text>
							<clause commented="no" display-inline="no-display-inline" id="ID8a965599be5a4332baee772bef1fd310"><enum>(i)</enum><text display-inline="yes-display-inline">correct any inaccuracies or incompleteness,
			 and provide to such individual written notice of such changes; and</text>
							</clause><clause commented="no" display-inline="no-display-inline" id="ID0e179d0e15884933981e3308e2e67ab7"><enum>(ii)</enum><text display-inline="yes-display-inline">provide such individual with the contact
			 information of the public record or licensor.</text>
							</clause></subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDecffc4013a1f48acbcaea78b9a7865e3"><enum>(2)</enum><header display-inline="yes-display-inline">Information not from a public record source
			 or licensor</header><text display-inline="yes-display-inline">If an individual
			 notifies a data broker of a dispute as to the completeness or accuracy of
			 information not from a public record or licensor that was disclosed to the
			 individual under subsection (c), the data broker shall, within 30 days of
			 receiving notice of such dispute—</text>
						<subparagraph commented="no" display-inline="no-display-inline" id="ID1d6d082656ed4ab2a02d267343a2d496"><enum>(A)</enum><text display-inline="yes-display-inline">review and consider free of charge any
			 information submitted by such individual that is relevant to the completeness
			 or accuracy of the disputed information; and</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDbc51b6376c174cc287b92279a25499cc"><enum>(B)</enum><text display-inline="yes-display-inline">correct any information found to be
			 incomplete or inaccurate and provide notice to such individual of whether and
			 what information was corrected, if any.</text>
						</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID1881a4cb16b84048b95e3ac6cb273a5a"><enum>(3)</enum><header display-inline="yes-display-inline">Extension of review period</header><text display-inline="yes-display-inline">The 30-day period described in paragraph
			 (1) may be extended for not more than 30 additional days if a data broker
			 receives information from the individual during the initial 30-day period that
			 is relevant to the completeness or accuracy of any disputed information.</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID50f4a0d2dc32477ea215f5fdc3ed385a"><enum>(4)</enum><header display-inline="yes-display-inline">Notice identifying the data
			 furnisher</header><text display-inline="yes-display-inline">If the completeness
			 or accuracy of any information not from a public record source or licensor that
			 was disclosed to an individual under subsection (c) is disputed by such
			 individual, the data broker shall provide, upon the request of such individual,
			 the contact information of any data furnisher that provided the disputed
			 information.</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID1a34c07593d940dd86e599d161d3392e"><enum>(5)</enum><header display-inline="yes-display-inline">Determination that dispute is frivolous or
			 irrelevant</header>
						<subparagraph commented="no" display-inline="no-display-inline" id="ID59a3c2caa5524a44830c75d3d9931593"><enum>(A)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">Notwithstanding paragraphs (1) through (3),
			 a data broker may decline to investigate or terminate a review of information
			 disputed by an individual under those paragraphs if the data broker reasonably
			 determines that the dispute by the individual is frivolous or intended to
			 perpetrate fraud.</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDf63d4c29405f4999ad789f7ea14b3ff1"><enum>(B)</enum><header display-inline="yes-display-inline">Notice</header><text display-inline="yes-display-inline">A data broker shall notify an individual of
			 a determination under subparagraph (A) within a reasonable time by any means
			 available to such data broker.</text>
						</subparagraph></paragraph></subsection></section><section commented="no" display-inline="no-display-inline" id="IDe5bc6f4fb182485eaed306444501525e" section-type="subsequent-section"><enum>202.</enum><header display-inline="yes-display-inline">Enforcement</header>
				<subsection commented="no" display-inline="no-display-inline" id="ID398d4ec1307d4f06897d972e814f3d21"><enum>(a)</enum><header display-inline="yes-display-inline">Civil penalties</header>
					<paragraph commented="no" display-inline="no-display-inline" id="IDd5e9e2debb2148a1af8cfa15849ef268"><enum>(1)</enum><header display-inline="yes-display-inline">Penalties</header><text display-inline="yes-display-inline">Any data broker that violates the
			 provisions of section 201 shall be subject to civil penalties of not more than
			 $1,000 per violation per day while such violations persist, up to a maximum of
			 $250,000 per violation.</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID17f322c46adc4851a85db713c6fe880b"><enum>(2)</enum><header display-inline="yes-display-inline">Intentional or willful
			 violation</header><text display-inline="yes-display-inline">A data broker that
			 intentionally or willfully violates the provisions of section 201 shall be
			 subject to additional penalties in the amount of $1,000 per violation per day,
			 to a maximum of an additional $250,000 per violation, while such violations
			 persist.</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID4e8b76f5306248e1924a209ddfd374c9"><enum>(3)</enum><header display-inline="yes-display-inline">Equitable relief</header><text display-inline="yes-display-inline">A data broker engaged in interstate
			 commerce that violates this section may be enjoined from further violations by
			 a court of competent jurisdiction.</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID13e613745540438c84f9a9cdb1a65123"><enum>(4)</enum><header display-inline="yes-display-inline">Other rights and remedies</header><text display-inline="yes-display-inline">The rights and remedies available under
			 this subsection are cumulative and shall not affect any other rights and
			 remedies available under law.</text>
					</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="ID7928235f2c394835b5e3d77afefe1dcf"><enum>(b)</enum><header display-inline="yes-display-inline">Federal trade commission
			 authority</header><text display-inline="yes-display-inline">Any data broker
			 shall have the provisions of this title enforced against it by the Federal
			 Trade Commission.</text>
				</subsection><subsection commented="no" display-inline="no-display-inline" id="ID80713dcce96646f99c2edd271c2438b9"><enum>(c)</enum><header display-inline="yes-display-inline">State enforcement</header>
					<paragraph commented="no" display-inline="no-display-inline" id="IDe697a6a08bac4a389d6e1dda7aac2731"><enum>(1)</enum><header display-inline="yes-display-inline">Civil actions</header><text display-inline="yes-display-inline">In any case in which the attorney general
			 of a State or any State or local law enforcement agency authorized by the State
			 attorney general or by State statute to prosecute violations of consumer
			 protection law, has reason to believe that an interest of the residents of that
			 State has been or is threatened or adversely affected by the acts or practices
			 of a data broker that violate this title, the State may bring a civil action on
			 behalf of the residents of that State in a district court of the United States
			 of appropriate jurisdiction, or any other court of competent jurisdiction,
			 to—</text>
						<subparagraph commented="no" display-inline="no-display-inline" id="ID89fb438e37f04dabb7676d706b8f5d14"><enum>(A)</enum><text display-inline="yes-display-inline">enjoin that act or practice;</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDcc70f9505cdd4d1aa7c58a36bd97a98d"><enum>(B)</enum><text display-inline="yes-display-inline">enforce compliance with this title;
			 or</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID51ad849463b9447f9ff9ada98e9dcfed"><enum>(C)</enum><text display-inline="yes-display-inline">obtain civil penalties of not more than
			 $1,000 per violation per day while such violations persist, up to a maximum of
			 $250,000 per violation.</text>
						</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID7d5e0d91f23b452aa7f462b5b6518eea"><enum>(2)</enum><header display-inline="yes-display-inline">Notice</header>
						<subparagraph commented="no" display-inline="no-display-inline" id="ID1892e5442ba5464199fb13e1aecea4d9"><enum>(A)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">Before filing an action under this
			 subsection, the attorney general of the State involved shall provide to the
			 Federal Trade Commission—</text>
							<clause commented="no" display-inline="no-display-inline" id="IDa28f24f2a6b14ab29f5f6e95831e0d54"><enum>(i)</enum><text display-inline="yes-display-inline">a written notice of that action; and</text>
							</clause><clause commented="no" display-inline="no-display-inline" id="IDc06985d85d1d4daebcbbf715ca94337f"><enum>(ii)</enum><text display-inline="yes-display-inline">a copy of the complaint for that
			 action.</text>
							</clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDa293ae70e23d4592a8c579e4370bc270"><enum>(B)</enum><header display-inline="yes-display-inline">Exception</header><text display-inline="yes-display-inline">Subparagraph (A) shall not apply with
			 respect to the filing of an action by an attorney general of a State under this
			 subsection, if the attorney general of a State determines that it is not
			 feasible to provide the notice described in subparagraph (A) before the filing
			 of the action.</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID43a0018520ee4de5ab76818810a576d9"><enum>(C)</enum><header display-inline="yes-display-inline">Notification when practicable</header><text display-inline="yes-display-inline">In an action described under subparagraph
			 (B), the attorney general of a State shall provide the written notice and the
			 copy of the complaint to the Federal Trade Commission as soon after the filing
			 of the complaint as practicable.</text>
						</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID47d72766655345fa809cf1bfadb0134d"><enum>(3)</enum><header display-inline="yes-display-inline">Federal trade commission
			 authority</header><text display-inline="yes-display-inline">Upon receiving
			 notice under paragraph (2), the Federal Trade Commission shall have the right
			 to—</text>
						<subparagraph commented="no" display-inline="no-display-inline" id="ID6821fa789cfc462aa409f90e4761fe69"><enum>(A)</enum><text display-inline="yes-display-inline">move to stay the action, pending the final
			 disposition of a pending Federal proceeding or action as described in paragraph
			 (4);</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID1be5846d9beb44a884387f5087ba4f17"><enum>(B)</enum><text display-inline="yes-display-inline">intervene in an action brought under
			 paragraph (1); and</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID7eb41f24604b42ea8ce7c604aabf9339"><enum>(C)</enum><text display-inline="yes-display-inline">file petitions for appeal.</text>
						</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID04055883d9b84f7dbb41852545613dc1"><enum>(4)</enum><header display-inline="yes-display-inline">Pending proceedings</header><text display-inline="yes-display-inline">If the Federal Trade Commission has
			 instituted a proceeding or civil action for a violation of this title, no
			 attorney general of a State may, during the pendency of such proceeding or
			 civil action, bring an action under this subsection against any defendant named
			 in such civil action for any violation that is alleged in that civil
			 action.</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID30947854f7394a84bef37dba3eaf0f72"><enum>(5)</enum><header display-inline="yes-display-inline">Rule of construction</header><text display-inline="yes-display-inline">For purposes of bringing any civil action
			 under paragraph (1), nothing in this title shall be construed to prevent an
			 attorney general of a State from exercising the powers conferred on the
			 attorney general by the laws of that State to—</text>
						<subparagraph commented="no" display-inline="no-display-inline" id="ID5340179ed41d4ca9b938c5c458bd6758"><enum>(A)</enum><text display-inline="yes-display-inline">conduct investigations;</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID3ab5ac1932dd40ffa72d5bf7d0813c88"><enum>(B)</enum><text display-inline="yes-display-inline">administer oaths and affirmations;
			 or</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID45650d3b189541749fb700efb1c971b1"><enum>(C)</enum><text display-inline="yes-display-inline">compel the attendance of witnesses or the
			 production of documentary and other evidence.</text>
						</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDb7956dff4a454fe8ab0f5817abc2b8dc"><enum>(6)</enum><header display-inline="yes-display-inline">Venue; service of process</header>
						<subparagraph commented="no" display-inline="no-display-inline" id="IDacb4da8bdf994f32b1474c85b0a0afde"><enum>(A)</enum><header display-inline="yes-display-inline">Venue</header><text display-inline="yes-display-inline">Any action brought under this subsection
			 may be brought in the district court of the United States that meets applicable
			 requirements relating to venue under section 1391 of title 28, United States
			 Code.</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID7fb8803320ed49fc96807317bc95327f"><enum>(B)</enum><header display-inline="yes-display-inline">Service of process</header><text display-inline="yes-display-inline">In an action brought under this subsection,
			 process may be served in any district in which the defendant—</text>
							<clause commented="no" display-inline="no-display-inline" id="IDea9ef869bcb944839d922a84ddff058f"><enum>(i)</enum><text display-inline="yes-display-inline">is an inhabitant; or</text>
							</clause><clause commented="no" display-inline="no-display-inline" id="IDa6772e58950f46b9a3ba39473e2d9abf"><enum>(ii)</enum><text display-inline="yes-display-inline">may be found.</text>
							</clause></subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="ID3008ccdecfbc4b34ba1e44a67151a3a5"><enum>(d)</enum><header display-inline="yes-display-inline">No private cause of action</header><text display-inline="yes-display-inline">Nothing in this title establishes a private
			 cause of action against a data broker for violation of any provision of this
			 title.</text>
				</subsection></section><section commented="no" display-inline="no-display-inline" id="ID10033cf1f27d420fab70142956e2f0b0" section-type="subsequent-section"><enum>203.</enum><header display-inline="yes-display-inline">Relation to State laws</header><text display-inline="no-display-inline">No requirement or prohibition may be imposed
			 under the laws of any State with respect to any subject matter regulated under
			 section 201, relating to individual access to, and correction of, personal
			 electronic records held by data brokers.</text>
			</section><section commented="no" display-inline="no-display-inline" id="IDab58a1e4994746e3975f8bb335bea15c" section-type="subsequent-section"><enum>204.</enum><header display-inline="yes-display-inline">Effective
			 date</header><text display-inline="no-display-inline">This title shall take
			 effect 180 days after the date of enactment of this Act.</text>
			</section></title><title commented="no" id="idD725C42479864A1D94B301FF34A11C92" level-type="subsequent"><enum>III</enum><header display-inline="yes-display-inline">Privacy and security of personally
			 identifiable information </header>
			<subtitle commented="no" id="id3189B1C7B0974BA09A5D2EB0F2AA3456" level-type="subsequent"><enum>A</enum><header display-inline="yes-display-inline">A data privacy and security
			 program</header>
				<section commented="no" display-inline="no-display-inline" id="ID48089945808a49b592f4356d4079eae6" section-type="subsequent-section"><enum>301.</enum><header display-inline="yes-display-inline">Purpose and applicability of data privacy
			 and security program</header>
					<subsection commented="no" display-inline="no-display-inline" id="IDddbd1c5a93e94835af6783727a4e0d4d"><enum>(a)</enum><header display-inline="yes-display-inline">Purpose</header><text display-inline="yes-display-inline">The purpose of this subtitle is to ensure
			 standards for developing and implementing administrative, technical, and
			 physical safeguards to protect the security of sensitive personally
			 identifiable information.</text>
					</subsection><subsection commented="no" display-inline="no-display-inline" id="ID1d16430a563849c88f30c306297d0517"><enum>(b)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">A business entity engaging in interstate
			 commerce that involves collecting, accessing, transmitting, using, storing, or
			 disposing of sensitive personally identifiable information in electronic or
			 digital form on 10,000 or more United States persons is subject to the
			 requirements for a data privacy and security program under section 302 for
			 protecting sensitive personally identifiable information.</text>
					</subsection><subsection commented="no" display-inline="no-display-inline" id="ID84c02c5382924cd5880326c0d63e96dc"><enum>(c)</enum><header display-inline="yes-display-inline">Limitations</header><text display-inline="yes-display-inline">Notwithstanding any other obligation under
			 this subtitle, this subtitle does not apply to:</text>
						<paragraph commented="no" display-inline="no-display-inline" id="ID560a85637f8c42c19982f35cb3f1461e"><enum>(1)</enum><header display-inline="yes-display-inline">Financial institutions</header><text display-inline="yes-display-inline">Financial institutions—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="IDa9ac03fede8c4d3bacfa4686a427f4f1"><enum>(A)</enum><text display-inline="yes-display-inline">subject to the data security requirements
			 and implementing regulations under the Gramm-Leach-Bliley Act (15 U.S.C. 6801
			 et seq.); and</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID6a256ee27e134fe3af78121215ed174f"><enum>(B)</enum><text display-inline="yes-display-inline">subject to—</text>
								<clause commented="no" display-inline="no-display-inline" id="ID5c74fafda772492bbb9771f6c10c7e46"><enum>(i)</enum><text display-inline="yes-display-inline">examinations for compliance with the
			 requirements of this Act by a Federal Functional Regulator or State Insurance
			 Authority (as those terms are defined in section 509 of the Gramm-Leach-Bliley
			 Act (15 U.S.C. 6809)); or</text>
								</clause><clause commented="no" display-inline="no-display-inline" id="IDa8fffe318bd242b5a4adabd150a5cce7"><enum>(ii)</enum><text display-inline="yes-display-inline">compliance with part 314 of title 16, Code
			 of Federal Regulations.</text>
								</clause></subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID1bea77b1d96049d19342fc06938e8260"><enum>(2)</enum><header display-inline="yes-display-inline">HIPPA regulated entities</header>
							<subparagraph commented="no" display-inline="no-display-inline" id="ID91b41aa91ccb4edda6d95f64add28769"><enum>(A)</enum><header display-inline="yes-display-inline">Covered entities</header><text display-inline="yes-display-inline">Covered entities subject to the Health
			 Insurance Portability and Accountability Act of 1996 (42 U.S.C. 1301 et seq.),
			 including the data security requirements and implementing regulations of that
			 Act.</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDe1bdc4f3ed43418f8c11f65dcf65e220"><enum>(B)</enum><header display-inline="yes-display-inline">Business entities</header><text display-inline="yes-display-inline">A business entity shall be deemed in
			 compliance with the privacy and security program requirements under section 302
			 if the business entity is acting as a <term>business associate</term> as that
			 term is defined in the Health Insurance Portability and Accountability Act of
			 1996 (42 U.S.C. 1301 et seq.) and is in compliance with requirements imposed
			 under that Act and its implementing regulations.</text>
							</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id752B5A0D23AD45DF819B11B11D4B6161"><enum>(3)</enum><header display-inline="yes-display-inline">Public
			 records</header><text display-inline="yes-display-inline">Public records not
			 otherwise subject to a confidentiality or nondisclosure requirement, or
			 information obtained from a news report or periodical.</text>
						</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="ID82fac130e6294b52bb29e212f466f2e0"><enum>(d)</enum><header display-inline="yes-display-inline">Safe harbors</header>
						<paragraph commented="no" display-inline="no-display-inline" id="IDf9419999edd14c728631734d1d83b15f"><enum>(1)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">A business entity shall be deemed in
			 compliance with the privacy and security program requirements under section 302
			 if the business entity complies with or provides protection equal to industry
			 standards <added-phrase reported-display-style="italic">or widely accepted as
			 an effective industry practice</added-phrase>, as identified by the Federal
			 Trade Commission, that are applicable to the type of sensitive personally
			 identifiable information involved in the ordinary course of business of such
			 business entity.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDa4e3cf89f3ff4bd4872a39c8f94ede1b"><enum>(2)</enum><header display-inline="yes-display-inline">Limitation</header><text display-inline="yes-display-inline">Nothing in this subsection shall be
			 construed to permit, and nothing does permit, the Federal Trade Commission to
			 issue regulations requiring, or according greater legal status to, the
			 implementation of or application of a specific technology or technological
			 specifications for meeting the requirements of this title.</text>
						</paragraph></subsection></section><section commented="no" display-inline="no-display-inline" id="ID01a5628cdcfe4d1aa8f738063c6c15c2" section-type="subsequent-section"><enum>302.</enum><header display-inline="yes-display-inline">Requirements for a personal data privacy
			 and security program</header>
					<subsection commented="no" display-inline="no-display-inline" id="IDe06ec5d327734ccfbcb3025711448bcd"><enum>(a)</enum><header display-inline="yes-display-inline">Personal data privacy and security
			 program</header><text display-inline="yes-display-inline">A business entity
			 subject to this subtitle shall comply with the following safeguards and any
			 other administrative, technical, or physical safeguards identified by the
			 Federal Trade Commission in a rulemaking process pursuant to section 553 of
			 title 5, United States Code, for the protection of sensitive personally
			 identifiable information:</text>
						<paragraph commented="no" display-inline="no-display-inline" id="ID32f2da88aaeb4e9a9356cdfa751bf96e"><enum>(1)</enum><header display-inline="yes-display-inline">Scope</header><text display-inline="yes-display-inline">A business entity shall implement a
			 comprehensive personal data privacy and security program that includes
			 administrative, technical, and physical safeguards appropriate to the size and
			 complexity of the business entity and the nature and scope of its
			 activities.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDc422286e3b5e4282880c6d4dda9e61ef"><enum>(2)</enum><header display-inline="yes-display-inline">Design</header><text display-inline="yes-display-inline">The personal data privacy and security
			 program shall be designed to—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="ID832224a994d04e60aa6c94efa1588cf6"><enum>(A)</enum><text display-inline="yes-display-inline">ensure the privacy, security, and
			 confidentiality of sensitive personally identifying information;</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDabaa6ac0cead448288f59c56e7b28aae"><enum>(B)</enum><text display-inline="yes-display-inline">protect against any anticipated
			 vulnerabilities to the privacy, security, or integrity of sensitive personally
			 identifying information; and</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID878a6358d1d7420db96cfdb96d77744b"><enum>(C)</enum><text display-inline="yes-display-inline">protect against unauthorized access to use
			 of sensitive personally identifying information that could
			 <deleted-phrase reported-display-style="strikethrough">result in substantial
			 harm or inconvenience to any individual</deleted-phrase><added-phrase reported-display-style="italic">create a significant risk of harm or fraud to
			 any individual</added-phrase>.</text>
							</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID4b950d47eff549f6988d73682c9f11ce"><enum>(3)</enum><header display-inline="yes-display-inline">Risk assessment</header><text display-inline="yes-display-inline">A business entity shall—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="ID760c690786bc445d9bc2677d8f95f00e"><enum>(A)</enum><text display-inline="yes-display-inline">identify reasonably foreseeable internal
			 and external vulnerabilities that could result in unauthorized access,
			 disclosure, use, or alteration of sensitive personally identifiable information
			 or systems containing sensitive personally identifiable information;</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID553382e18b2e43f1a9f3e85ed691c714"><enum>(B)</enum><text display-inline="yes-display-inline">assess the likelihood of and potential
			 damage from unauthorized access, disclosure, use, or alteration of sensitive
			 personally identifiable information;</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID676012ab86234c0aac757acb3a03d1f6"><enum>(C)</enum><text display-inline="yes-display-inline">assess the sufficiency of its policies,
			 technologies, and safeguards in place to control and minimize risks from
			 unauthorized access, disclosure, use, or alteration of sensitive personally
			 identifiable information; and</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idC1C4AE57A42F48318FE5D2321E156F0A"><enum>(D)</enum><text display-inline="yes-display-inline">assess the vulnerability of sensitive
			 personally identifiable information during destruction and disposal of such
			 information, including through the disposal or retirement of hardware.</text>
							</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID746a427c8ac84218b69ce3920d5a9f26"><enum>(4)</enum><header display-inline="yes-display-inline">Risk management and control</header><text display-inline="yes-display-inline">Each business entity shall—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="ID0d4167033d5e428a96e89c8a307f2779"><enum>(A)</enum><text display-inline="yes-display-inline">design its personal data privacy and
			 security program to control the risks identified under paragraph (3);
			 and</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID7de281b8fa6d44e6a955e840dd025689"><enum>(B)</enum><text display-inline="yes-display-inline">adopt measures commensurate with the
			 sensitivity of the data as well as the size, complexity, and scope of the
			 activities of the business entity that—</text>
								<clause commented="no" display-inline="no-display-inline" id="IDcb31d2a8cc9c45e7a827fb3cad9e004e"><enum>(i)</enum><text display-inline="yes-display-inline">control access to systems and facilities
			 containing sensitive personally identifiable information, including controls to
			 authenticate and permit access only to authorized individuals;</text>
								</clause><clause commented="no" display-inline="no-display-inline" id="IDd2ebc6309fec4e80957b78c33a013747"><enum>(ii)</enum><text display-inline="yes-display-inline">detect actual and attempted fraudulent,
			 unlawful, or unauthorized access, disclosure, use, or alteration of sensitive
			 personally identifiable information, including by employees and other
			 individuals otherwise authorized to have access;</text>
								</clause><clause commented="no" display-inline="no-display-inline" id="IDcc80fec448474095b98acf35dbf50a95"><enum>(iii)</enum><text display-inline="yes-display-inline">protect sensitive personally identifiable
			 information during use, transmission, storage, and disposal by
			 encryption<added-phrase committee-id="SSJU00" reported-display-style="italic">,
			 </added-phrase><added-phrase reported-display-style="italic"></added-phrase>redaction, or access controls
			 that are widely accepted as an effective industry practice or industry
			 standard, <added-phrase reported-display-style="italic"></added-phrase>or other
			 reasonable means (including as directed for disposal of records under section
			 628 of the Fair Credit Reporting Act (15 U.S.C. 1681w) and the implementing
			 regulations of such Act as set forth in section 682 of title 16, Code of
			 Federal Regulations);</text>
								</clause><clause commented="no" display-inline="no-display-inline" id="idDC2AB053A4F84CE899BDA286A381B0A4"><enum>(iv)</enum><text display-inline="yes-display-inline">ensure that sensitive personally
			 identifiable information is properly destroyed and disposed of, including
			 during the destruction of computers, diskettes, and other electronic media that
			 contain sensitive personally identifiable information<added-phrase reported-display-style="italic"></added-phrase>;<added-phrase reported-display-style="italic"></added-phrase></text>
								</clause><clause commented="no" display-inline="no-display-inline" id="idA65F7941A0984AA792DB0EA52A944E3F"><enum>(v)</enum><text display-inline="yes-display-inline">trace access to records containing
			 sensitive personally identifiable information so that the business entity can
			 determine who accessed or acquired such sensitive personally identifiable
			 information pertaining to specific individuals; and</text>
								</clause><clause commented="no" display-inline="no-display-inline" id="id35C1CA572F594C458CA61F42D2275173"><enum>(vi)</enum><text display-inline="yes-display-inline">ensure that no third party or customer of
			 the business entity is authorized to access or acquire sensitive personally
			 identifiable information without the business entity first performing
			 sufficient due diligence to ascertain, with reasonable certainty, that such
			 information is being sought for a valid legal purpose.</text>
								</clause></subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="IDac0bcd641fab47ec8d169bbdd3e2cbd6"><enum>(b)</enum><header display-inline="yes-display-inline">Training</header><text display-inline="yes-display-inline">Each business entity subject to this
			 subtitle shall take steps to ensure employee training and supervision for
			 implementation of the data security program of the business entity.</text>
					</subsection><subsection commented="no" display-inline="no-display-inline" id="IDc8546a0096344b8093d2c7c421a2bf04"><enum>(c)</enum><header display-inline="yes-display-inline">Vulnerability testing</header>
						<paragraph commented="no" display-inline="no-display-inline" id="IDe55eff11713942b3b734ead03b647a72"><enum>(1)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">Each business entity subject to this
			 subtitle shall take steps to ensure regular testing of key controls, systems,
			 and procedures of the personal data privacy and security program to detect,
			 prevent, and respond to attacks or intrusions, or other system failures.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDb7ebf96c0fd4459c97654057f389508c"><enum>(2)</enum><header display-inline="yes-display-inline">Frequency</header><text display-inline="yes-display-inline">The frequency and nature of the tests
			 required under paragraph (1) shall be determined by the risk assessment of the
			 business entity under subsection (a)(3).</text>
						</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="IDa0671a094a6e446d8b3ead55be2ac24b"><enum>(d)</enum><header display-inline="yes-display-inline">Relationship to service
			 providers</header><text display-inline="yes-display-inline">In the event a
			 business entity subject to this subtitle engages service providers not subject
			 to this subtitle, such business entity shall—</text>
						<paragraph commented="no" display-inline="no-display-inline" id="IDa0c9f487ec3f4cc3a43321f9fb1e75f6"><enum>(1)</enum><text display-inline="yes-display-inline">exercise appropriate due diligence in
			 selecting those service providers for responsibilities related to sensitive
			 personally identifiable information, and take reasonable steps to select and
			 retain service providers that are capable of maintaining appropriate safeguards
			 for the security, privacy, and integrity of the sensitive personally
			 identifiable information at issue; and</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID00c3ca79bcb34d02bbcc049d21cf0938"><enum>(2)</enum><text display-inline="yes-display-inline">require those service providers by contract
			 to implement and maintain appropriate measures designed to meet the objectives
			 and requirements governing entities subject to section 301, this section, and
			 subtitle B.</text>
						</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="ID0a463bfe19fa46a69db7e98862c0d304"><enum>(e)</enum><header display-inline="yes-display-inline">Periodic assessment and personal data
			 privacy and security modernization</header><text display-inline="yes-display-inline">Each business entity subject to this
			 subtitle shall on a regular basis monitor, evaluate, and adjust, as appropriate
			 its data privacy and security program in light of any relevant changes
			 in—</text>
						<paragraph commented="no" display-inline="no-display-inline" id="ID0d4f9c7be89448b19bc7acc3df798c94"><enum>(1)</enum><text display-inline="yes-display-inline">technology;</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID78b825c133324ea99829bb80cdd35dac"><enum>(2)</enum><text display-inline="yes-display-inline">the sensitivity of personally identifiable
			 information;</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID5a4c0fdefdcd430f938a0d14c111ba57"><enum>(3)</enum><text display-inline="yes-display-inline">internal or external threats to personally
			 identifiable information; and</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID9e21f4e291504ec19aa24c9a45152c9e"><enum>(4)</enum><text display-inline="yes-display-inline">the changing business arrangements of the
			 business entity, such as—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="IDde6f7259eddf4738b0ef8a759540216f"><enum>(A)</enum><text display-inline="yes-display-inline">mergers and acquisitions;</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID15c1ca9356fe48a18ee457775ee5110f"><enum>(B)</enum><text display-inline="yes-display-inline">alliances and joint ventures;</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID262c91919f004097b81ed65d35558174"><enum>(C)</enum><text display-inline="yes-display-inline">outsourcing arrangements;</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID1d26ec6a0c5340f380d57ebaa82c9628"><enum>(D)</enum><text display-inline="yes-display-inline">bankruptcy; and</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID9a63adfb34454b6aa70ae2d0e1db625e"><enum>(E)</enum><text display-inline="yes-display-inline">changes to sensitive personally
			 identifiable information systems.</text>
							</subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="IDacc913ed0f0a43b39ed94b6a1b28f785"><enum>(f)</enum><header display-inline="yes-display-inline">Implementation timeline</header><text display-inline="yes-display-inline">Not later than 1 year after the date of
			 enactment of this Act, a business entity subject to the provisions of this
			 subtitle shall implement a data privacy and security program pursuant to this
			 subtitle.</text>
					</subsection></section><section commented="no" display-inline="no-display-inline" id="ID5cac3211a25b4f26a2628faea99c9f36" section-type="subsequent-section"><enum>303.</enum><header display-inline="yes-display-inline">Enforcement</header>
					<subsection commented="no" display-inline="no-display-inline" id="IDad519693d2a34f75a85128cd145d1103"><enum>(a)</enum><header display-inline="yes-display-inline">Civil penalties</header>
						<paragraph commented="no" display-inline="no-display-inline" id="ID8710c7c96e804d8493e3f127daa59e1d"><enum>(1)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">Any business entity that violates the
			 provisions of sections 301 or 302 shall be subject to civil penalties of not
			 more than $5,000 per violation per day while such a violation exists, with a
			 maximum of $500,000 per violation.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID1eab52f9bdfe4428a9ec5ba12bcb6ecb"><enum>(2)</enum><header display-inline="yes-display-inline">Intentional or willful
			 violation</header><text display-inline="yes-display-inline">A business entity
			 that intentionally or willfully violates the provisions of sections 301 or 302
			 shall be subject to additional penalties in the amount of $5,000 per violation
			 per day while such a violation exists, with a maximum of an additional $500,000
			 per violation.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDfffa7d0cf76c45fe9ea25f34a77f1893"><enum>(3)</enum><header display-inline="yes-display-inline">Equitable relief</header><text display-inline="yes-display-inline">A business entity engaged in interstate
			 commerce that violates this section may be enjoined from further violations by
			 a court of competent jurisdiction.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID1a0f43fcf8a843a992c5ec63ef09d71e"><enum>(4)</enum><header display-inline="yes-display-inline">Other rights and remedies</header><text display-inline="yes-display-inline">The rights and remedies available under
			 this section are cumulative and shall not affect any other rights and remedies
			 available under law.</text>
						</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="id595483F7BE794C5680EAF7D333EA3302"><enum>(b)</enum><header display-inline="yes-display-inline">Federal trade commission
			 authority</header><text display-inline="yes-display-inline">Any
			 <deleted-phrase reported-display-style="strikethrough">data
			 broker</deleted-phrase><added-phrase reported-display-style="italic">business
			 entity</added-phrase> shall have the provisions of this subtitle enforced
			 against it by the Federal Trade Commission.</text>
					</subsection><subsection commented="no" display-inline="no-display-inline" id="idCD3E66347B2A42B4A48CD9747536F0D7"><enum>(c)</enum><header display-inline="yes-display-inline">State enforcement</header>
						<paragraph commented="no" display-inline="no-display-inline" id="id810B9D5D00074BE393DF02F906BE3E4E"><enum>(1)</enum><header display-inline="yes-display-inline">Civil actions</header><text display-inline="yes-display-inline">In any case in which the attorney general
			 of a State or any State or local law enforcement agency authorized by the State
			 attorney general or by State statute to prosecute violations of consumer
			 protection law, has reason to believe that an interest of the residents of that
			 State has been or is threatened or adversely affected by the acts or practices
			 of a <deleted-phrase reported-display-style="strikethrough">data
			 broker</deleted-phrase><added-phrase reported-display-style="italic">business
			 entity</added-phrase> that violate this subtitle, the State may bring a civil
			 action on behalf of the residents of that State in a district court of the
			 United States of appropriate jurisdiction, or any other court of competent
			 jurisdiction, to—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="id31812F04C77546E79C7AF0DB05FFA2F6"><enum>(A)</enum><text display-inline="yes-display-inline">enjoin that act or practice;</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id73BD179F12624B21BB1A5D184B17248A"><enum>(B)</enum><text display-inline="yes-display-inline">enforce compliance with this subtitle;
			 or</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idE21FE7A642D7412AB24279947B427352"><enum>(C)</enum><text display-inline="yes-display-inline">obtain civil penalties of not more than
			 $5,000 per violation per day while such violations persist, up to a maximum of
			 $500,000 per violation.</text>
							</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDb035a912d0134c8e88e798c195f63e25"><enum>(2)</enum><header display-inline="yes-display-inline">Notice</header>
							<subparagraph commented="no" display-inline="no-display-inline" id="ID10a26e09510c4bf08a652182d2d3bb76"><enum>(A)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">Before filing an action under this
			 subsection, the attorney general of the State involved shall provide to the
			 Federal Trade Commission—</text>
								<clause commented="no" display-inline="no-display-inline" id="IDe1187d19b84a49b3993eb68910cba8cb"><enum>(i)</enum><text display-inline="yes-display-inline">a written notice of that action; and</text>
								</clause><clause commented="no" display-inline="no-display-inline" id="ID7abbfa78320441b9a8e2acdd3ea96ce0"><enum>(ii)</enum><text display-inline="yes-display-inline">a copy of the complaint for that
			 action.</text>
								</clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDb390c579fafe4fddb34cc2f7f87d2850"><enum>(B)</enum><header display-inline="yes-display-inline">Exception</header><text display-inline="yes-display-inline">Subparagraph (A) shall not apply with
			 respect to the filing of an action by an attorney general of a State under this
			 subsection, if the attorney general of a State determines that it is not
			 feasible to provide the notice described in this subparagraph before the filing
			 of the action.</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDdf0df3125ba0430a9162deb90f36b0c3"><enum>(C)</enum><header display-inline="yes-display-inline">Notification when practicable</header><text display-inline="yes-display-inline">In an action described under subparagraph
			 (B), the attorney general of a State shall provide the written notice and the
			 copy of the complaint to the Federal Trade Commission as soon after the filing
			 of the complaint as practicable.</text>
							</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDce85cede46504f3fbd8c43a11d7e1e0e"><enum>(3)</enum><header display-inline="yes-display-inline">Federal trade commission
			 authority</header><text display-inline="yes-display-inline">Upon receiving
			 notice under paragraph (2), the Federal Trade Commission shall have the right
			 to—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="ID175a18cc4a0e48fa891fae7cf6a60117"><enum>(A)</enum><text display-inline="yes-display-inline">move to stay the action, pending the final
			 disposition of a pending Federal proceeding or action as described in paragraph
			 (4);</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID3fa662b5a06c48afa8b43d1041ff91fc"><enum>(B)</enum><text display-inline="yes-display-inline">intervene in an action brought under
			 paragraph (1); and</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDe446c3abe4644940b0d6455f0346a379"><enum>(C)</enum><text display-inline="yes-display-inline">file petitions for appeal.</text>
							</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID9bb7da67e82547119a40748f48dc65fd"><enum>(4)</enum><header display-inline="yes-display-inline">Pending proceedings</header><text display-inline="yes-display-inline">If the Federal Trade Commission has
			 instituted a proceeding or action for a violation of this subtitle or any
			 regulations thereunder, no attorney general of a State may, during the pendency
			 of such proceeding or action, bring an action under this subsection against any
			 defendant named in such criminal proceeding or civil action for any violation
			 that is alleged in that proceeding or action.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID3fc63de47c244814be783834e893beb2"><enum>(5)</enum><header display-inline="yes-display-inline">Rule of construction</header><text display-inline="yes-display-inline">For purposes of bringing any civil action
			 under paragraph (1) nothing in this subtitle shall be construed to prevent an
			 attorney general of a State from exercising the powers conferred on the
			 attorney general by the laws of that State to—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="IDa92fba318e92423fafb27f7543905061"><enum>(A)</enum><text display-inline="yes-display-inline">conduct investigations;</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID5c4d666eb3e84136a49a3ea4be1c4c9e"><enum>(B)</enum><text display-inline="yes-display-inline">administer oaths and affirmations;
			 or</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID1cf4e5dcc7b9453ab5222aa74ed43bde"><enum>(C)</enum><text display-inline="yes-display-inline">compel the attendance of witnesses or the
			 production of documentary and other evidence.</text>
							</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID96d3ee3e4091401bbe650d295518f1ed"><enum>(6)</enum><header display-inline="yes-display-inline">Venue; service of process</header>
							<subparagraph commented="no" display-inline="no-display-inline" id="ID174f48431c8e486b9c4b9f86f7857876"><enum>(A)</enum><header display-inline="yes-display-inline">Venue</header><text display-inline="yes-display-inline">Any action brought under this subsection
			 may be brought in the district court of the United States that meets applicable
			 requirements relating to venue under section 1391 of title 28, United States
			 Code.</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDcdf640d6d7454abdaadcfb01381339e7"><enum>(B)</enum><header display-inline="yes-display-inline">Service of process</header><text display-inline="yes-display-inline">In an action brought under this subsection,
			 process may be served in any district in which the defendant—</text>
								<clause commented="no" display-inline="no-display-inline" id="IDb59f7680c4684e92a42fcc0549f09203"><enum>(i)</enum><text display-inline="yes-display-inline">is an inhabitant; or</text>
								</clause><clause commented="no" display-inline="no-display-inline" id="IDf034fb9872a249af9a258587e9b38280"><enum>(ii)</enum><text display-inline="yes-display-inline">may be found.</text>
								</clause></subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="IDa4ae129d580443afb37c73c7e333ecb7"><enum>(d)</enum><header display-inline="yes-display-inline">No private cause of action</header><text display-inline="yes-display-inline">Nothing in this subtitle establishes a
			 private cause of action against a business entity for violation of any
			 provision of this subtitle.</text>
					</subsection></section><section commented="no" display-inline="no-display-inline" id="ID14b3a2c1aa4344dc97a4480451a1df47" section-type="subsequent-section"><enum>304.</enum><header display-inline="yes-display-inline">Relation to other laws</header>
					<subsection commented="no" display-inline="no-display-inline" id="IDedb819fd16414fa18aaa55a6180d5a68"><enum>(a)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">No State may require any business entity
			 subject to this subtitle to comply with any requirements with respect to
			 administrative, technical, and physical safeguards for the protection of
			 sensitive personally identifying information.</text>
					</subsection><subsection commented="no" display-inline="no-display-inline" id="ID3e1f4aed55cb4507a15acb3ae01bf3cf"><enum>(b)</enum><header display-inline="yes-display-inline">Limitations</header><text display-inline="yes-display-inline">Nothing in this subtitle shall be construed
			 to modify, limit, or supersede the operation of the Gramm-Leach-Bliley Act or
			 its implementing regulations, including those adopted or enforced by
			 States.</text>
					</subsection></section></subtitle><subtitle commented="no" id="idBC4FEB9AFE2A4E93BF957FCB6F00B7E3" level-type="subsequent"><enum>B</enum><header display-inline="yes-display-inline">Security breach notification</header>
				<section commented="no" display-inline="no-display-inline" id="ID5510cd0d499f4913941a3308d15e6a1c" section-type="subsequent-section"><enum>311.</enum><header display-inline="yes-display-inline">Notice to individuals</header>
					<subsection commented="no" display-inline="no-display-inline" id="ID720d8016c4274ef7a360b8e4164e0fe0"><enum>(a)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">Any agency, or business entity engaged in
			 interstate commerce, that uses, accesses, transmits, stores, disposes of or
			 collects sensitive personally identifiable information shall, following the
			 discovery of a security breach <added-phrase reported-display-style="italic"></added-phrase>of such
			 information,<added-phrase reported-display-style="italic"></added-phrase>
			 notify any resident of the United States whose sensitive personally
			 identifiable information has been, or is reasonably believed to have been,
			 accessed, or acquired.</text>
					</subsection><subsection commented="no" display-inline="no-display-inline" id="IDb2d0cfaa8a5b4717a05063975b9b42d1"><enum>(b)</enum><header display-inline="yes-display-inline">Obligation of owner or licensee</header>
						<paragraph commented="no" display-inline="no-display-inline" id="IDcacc642274d644e481d4de87564c1952"><enum>(1)</enum><header display-inline="yes-display-inline">Notice to owner or licensee</header><text display-inline="yes-display-inline">Any agency, or business entity engaged in
			 interstate commerce, that uses, accesses, transmits, stores, disposes of, or
			 collects sensitive personally identifiable information that the agency or
			 business entity does not own or license shall notify the owner or licensee of
			 the information following the discovery of a security breach involving such
			 information.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDa8a5bddb36854ef58c349f7d8f4e916b"><enum>(2)</enum><header display-inline="yes-display-inline">Notice by owner, licensee or other
			 designated third party</header><text display-inline="yes-display-inline">Nothing in this subtitle shall prevent or
			 abrogate an agreement between an agency or business entity required to give
			 notice under this section and a designated third party, including an owner or
			 licensee of the sensitive personally identifiable information subject to the
			 security breach, to provide the notifications required under subsection
			 (a).</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID8c3282340c68464c8cc16a7e96ac21b1"><enum>(3)</enum><header display-inline="yes-display-inline">Business entity relieved from giving
			 notice</header><text display-inline="yes-display-inline">A business entity
			 obligated to give notice under subsection (a) shall be relieved of such
			 obligation if an owner or licensee of the sensitive personally identifiable
			 information subject to the security breach, or other designated third party,
			 provides such notification.</text>
						</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="IDcba7ac64bcb3449d9c9ea5dad732fcaf"><enum>(c)</enum><header display-inline="yes-display-inline">Timeliness of notification</header>
						<paragraph commented="no" display-inline="no-display-inline" id="ID47e0ad09389e43368af2d01671e67128"><enum>(1)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">All notifications required under this
			 section shall be made without unreasonable delay following the discovery by the
			 agency or business entity of a security breach.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id053C9368FAB84DB48DBDF31BD947DFA8"><enum>(2)</enum><header display-inline="yes-display-inline">Reasonable delay</header><text display-inline="yes-display-inline">Reasonable delay under this subsection may
			 include any time necessary to determine the scope of the security breach,
			 prevent further disclosures, and restore the reasonable integrity of the data
			 system and provide notice to law enforcement when required.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID3e7e880e342546bd8c593af9fe9e1c03"><enum>(3)</enum><header display-inline="yes-display-inline">Burden of proof</header><text display-inline="yes-display-inline">The agency, business entity, owner, or
			 licensee required to provide notification under this section shall have the
			 burden of demonstrating that all notifications were made as required under this
			 subtitle, including evidence demonstrating the reasons for any delay.</text>
						</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="IDe00e27f9a69d45aca089facd8a9a1fe8"><enum>(d)</enum><header display-inline="yes-display-inline">Delay of notification authorized for law
			 enforcement purposes</header>
						<paragraph commented="no" display-inline="no-display-inline" id="ID06936b350f164c5885b1797fa476970b"><enum>(1)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">If a Federal law enforcement agency
			 determines that the notification required under this section would impede a
			 criminal investigation, such notification shall be delayed upon written notice
			 from such Federal law enforcement agency to the agency or business entity that
			 experienced the breach.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID777040e96ce943efa72ca96e9edd8cd5"><enum>(2)</enum><header display-inline="yes-display-inline">Extended delay of
			 notification</header><text display-inline="yes-display-inline">If the
			 notification required under subsection (a) is delayed pursuant to paragraph
			 (1), an agency or business entity shall give notice 30 days after the day such
			 law enforcement delay was invoked unless a Federal law enforcement agency
			 provides written notification that further delay is necessary.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDe8d332a9b4f846cea0d31c6733439553"><enum>(3)</enum><header display-inline="yes-display-inline">Law enforcement immunity</header><text display-inline="yes-display-inline">No cause of action shall lie in any court
			 against any law enforcement agency for acts relating to the delay of
			 notification for law enforcement purposes under this subtitle.</text>
						</paragraph></subsection></section><section commented="no" display-inline="no-display-inline" id="ID5dc909314300496fae2e47fd1f732bf2" section-type="subsequent-section"><enum>312.</enum><header display-inline="yes-display-inline">Exemptions</header>
					<subsection commented="no" display-inline="no-display-inline" id="IDc0d77acc21dc4bd09bb886123fe643e8"><enum>(a)</enum><header display-inline="yes-display-inline">Exemption for national security and law
			 enforcement</header>
						<paragraph commented="no" display-inline="no-display-inline" id="ID5f8d9f0ccc2f464a8881c81fd09cd4da"><enum>(1)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">Section 311 shall not apply to an agency or
			 business entity if the agency or business entity certifies, in writing, that
			 notification of the security breach as required by section 311 reasonably could
			 be expected to—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="ID37a53412e42e4e18954878bf2b16dcb3"><enum>(A)</enum><text display-inline="yes-display-inline">cause damage to the national security;
			 or</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID0d053913bc2b400d8df6e3ff2775efac"><enum>(B)</enum><text display-inline="yes-display-inline">hinder a law enforcement investigation or
			 the ability of the agency to conduct law enforcement investigations.</text>
							</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDef500e6acfb34c17859262dc8e6af033"><enum>(2)</enum><header display-inline="yes-display-inline">Limits on certifications</header><text display-inline="yes-display-inline">An agency
			 <added-phrase reported-display-style="italic"></added-phrase>or business
			 entity<added-phrase reported-display-style="italic"></added-phrase> may not
			 execute a certification under paragraph (1) to—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="IDf487a4dfaf624465aa7aa15fd61bb942"><enum>(A)</enum><text display-inline="yes-display-inline">conceal violations of law, inefficiency, or
			 administrative error;</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID51e0f169985f4f06a8b55baf00b4c2b4"><enum>(B)</enum><text display-inline="yes-display-inline">prevent embarrassment to a business entity,
			 organization, or agency; or</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDf3bc9fee9cca49da98fc288ad90f2fc8"><enum>(C)</enum><text display-inline="yes-display-inline">restrain competition.</text>
							</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID588bcbb0cc3f49cea8884f01cbd0f4a1"><enum>(3)</enum><header display-inline="yes-display-inline">Notice</header><text display-inline="yes-display-inline">In every case in which an agency
			 <added-phrase reported-display-style="italic"></added-phrase>or business
			 agency<added-phrase reported-display-style="italic"></added-phrase> issues a
			 certification under paragraph (1), the certification, accompanied by a
			 description of the factual basis for the certification, shall be immediately
			 provided to the United States Secret Service.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID03a548d7bf3d433693c4ab2b1bde7280"><enum>(4)</enum><header display-inline="yes-display-inline">Secret service review of
			 certifications</header>
							<subparagraph commented="no" display-inline="no-display-inline" id="ID1602d3c72ed54448a19dbf73919739f8"><enum>(A)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">The United States Secret Service may review
			 a certification provided by an agency under paragraph (3), and shall review a
			 certification provided by a business entity under paragraph (3), to determine
			 whether an exemption under paragraph (1) is merited. Such review shall be
			 completed not later than 10 business days after the date of receipt of the
			 certification, except as provided in paragraph (5)(C).</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDe602279f6bae4c49be04bb7c236a80cd"><enum>(B)</enum><header display-inline="yes-display-inline">Notice</header><text display-inline="yes-display-inline">Upon completing a review under subparagraph
			 (A) the United States Secret Service shall immediately notify the agency or
			 business entity, in writing, of its determination of whether an exemption under
			 paragraph (1) is merited.</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDb2f94c610bf4422ead6561388120e2cd"><enum>(C)</enum><header display-inline="yes-display-inline">Exemption</header><text display-inline="yes-display-inline">The exemption under paragraph (1) shall not
			 apply if the United States Secret Service determines under this paragraph that
			 the exemption is not merited.</text>
							</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDf148dfa1623544b0a9caa32d0c71db86"><enum>(5)</enum><header display-inline="yes-display-inline">Additional authority of the secret
			 service</header>
							<subparagraph commented="no" display-inline="no-display-inline" id="ID6517c455849e4249b1b05f812b7277c4"><enum>(A)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">In determining under paragraph (4) whether
			 an exemption under paragraph (1) is merited, the United States Secret Service
			 may request additional information from the agency or business entity regarding
			 the basis for the claimed exemption, if such additional information is
			 necessary to determine whether the exemption is merited.</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID431a29e012304bc493848737c25210e5"><enum>(B)</enum><header display-inline="yes-display-inline">Required compliance</header><text display-inline="yes-display-inline">Any agency or business entity that receives
			 a request for additional information under subparagraph (A) shall cooperate
			 with any such request.</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID0b31ef44ccc14992880aa9343f54477c"><enum>(C)</enum><header display-inline="yes-display-inline">Timing</header><text display-inline="yes-display-inline">If the United States Secret Service
			 requests additional information under subparagraph (A), the United States
			 Secret Service shall notify the agency or business entity not later than 10
			 business days after the date of receipt of the additional information whether
			 an exemption under paragraph (1) is merited.</text>
							</subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="ID7b2a1925c2b546dab03966fdcd2c38f9"><enum>(b)</enum><header display-inline="yes-display-inline">Safe harbor</header><text display-inline="yes-display-inline">An agency or business entity will be exempt
			 from the notice requirements under section 311, if—</text>
						<paragraph commented="no" display-inline="no-display-inline" id="IDd75777fcdf0c44d3b5b97deb02f526f1"><enum>(1)</enum><text display-inline="yes-display-inline">a risk assessment concludes that—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="idF2E9AC39B8CC47B286C04FB11863338F"><enum>(A)</enum><text display-inline="yes-display-inline">there is no significant risk that a
			 security breach has resulted in, or will result in, harm to the individuals
			 whose sensitive personally identifiable information was subject to the security
			 breach, with the encryption of such information establishing a presumption that
			 no significant risk exists; or</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDec967b93635b4b2fa9d0b310a875ac0e"><enum>(B)</enum><text display-inline="yes-display-inline">there is no significant risk that a
			 security breach has resulted in, or will result in, harm to the individuals
			 whose sensitive personally identifiable information was subject to the security
			 breach, with the rendering of such sensitive personally identifiable
			 information indecipherable through the use of best practices or methods, such
			 as redaction, access controls, or other such mechanisms, which are widely
			 accepted as an effective industry practice, or an effective industry standard,
			 establishing a presumption that no significant risk exists;</text>
							</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="idB38244735D794F688042D7727E960120"><enum>(2)</enum><text display-inline="yes-display-inline">without unreasonable delay, but not later
			 than 45 days after the discovery of a security breach, unless extended by the
			 United States Secret Service, the agency or business entity notifies the United
			 States Secret Service, in writing, of—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="ID1bdadecacee840c093363c08c8e6258d"><enum>(A)</enum><text display-inline="yes-display-inline">the results of the risk assessment;
			 and</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDbe57df04f7994eb4a496e4a803663bee"><enum>(B)</enum><text display-inline="yes-display-inline">its decision to invoke the risk assessment
			 exemption; and</text>
							</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID36a5edeb67b54aea843d0e691050cc89"><enum>(3)</enum><text display-inline="yes-display-inline">the United States Secret Service does not
			 indicate, in writing, within 10 business days from receipt of the decision,
			 that notice should be given.</text>
						</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="ID3137a79e39dd461e8ed1121bbe2cc8c4"><enum>(c)</enum><header display-inline="yes-display-inline">Financial fraud prevention
			 exemption</header>
						<paragraph commented="no" display-inline="no-display-inline" id="ID2fa5f58f805649e59111c250cd64d89c"><enum>(1)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">A business entity will be exempt from the
			 notice requirement under section 311 if the business entity utilizes or
			 participates in a security program that—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="ID1e3ddaeecac341d3ac43346c1b30b6e4"><enum>(A)</enum><text display-inline="yes-display-inline">is designed to block the use of the
			 sensitive personally identifiable information to initiate unauthorized
			 financial transactions before they are charged to the account of the
			 individual; and</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID4e382831c69c4cb7898e45b7562f0db5"><enum>(B)</enum><text display-inline="yes-display-inline">provides for notice to affected individuals
			 after a security breach that has resulted in fraud or unauthorized
			 transactions.</text>
							</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDbbcd5b778fad470b9d59c081de9dd58d"><enum>(2)</enum><header display-inline="yes-display-inline">Limitation</header><text display-inline="yes-display-inline">The exemption by this subsection does not
			 apply <added-phrase reported-display-style="italic"></added-phrase>if<added-phrase reported-display-style="italic">—</added-phrase></text>
							<subparagraph commented="no" display-inline="no-display-inline" id="id537D1A12D0264326A2201A03B154946C"><enum>(A)</enum><text display-inline="yes-display-inline">the information subject to the security
			 breach includes sensitive personally identifiable information, other than a
			 credit card or credit card security code, of any type of the sensitive
			 personally identifiable information identified in section 3; or</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idB059C50331DE456591C43D831EBEA9B5"><enum>(B)</enum><text display-inline="yes-display-inline">the security breach includes both the
			 individual's credit card number and the individual’s first and last
			 name.</text>
							</subparagraph></paragraph></subsection></section><section commented="no" display-inline="no-display-inline" id="IDbe5d0d5a9f634bfbbae2e9371a7cb5ab" section-type="subsequent-section"><enum>313.</enum><header display-inline="yes-display-inline">Methods of notice</header><text display-inline="no-display-inline">An agency or business entity shall be in
			 compliance with section 311 if it provides both:</text>
					<paragraph commented="no" display-inline="no-display-inline" id="ID19cfa3779734495ba271ec2ec3a85bd9"><enum>(1)</enum><header display-inline="yes-display-inline">Individual notice</header><text display-inline="yes-display-inline">Notice to individuals by 1 of the following
			 means:</text>
						<subparagraph commented="no" display-inline="no-display-inline" id="ID852b07c2909f42379ca05f7a4131f093"><enum>(A)</enum><text display-inline="yes-display-inline">Written notification to the last known home
			 mailing address of the individual in the records of the agency or business
			 entity.</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID68509b55bd4c4326af03b115762bf2e1"><enum>(B)</enum><text display-inline="yes-display-inline">Telephone notice to the individual
			 personally.</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID97a508ad4f444592bf57a3a5e307dc02"><enum>(C)</enum><text display-inline="yes-display-inline"><added-phrase reported-display-style="italic"></added-phrase>E-mail notice, if
			 <added-phrase reported-display-style="italic"></added-phrase>the individual has
			 consented to receive such notice and the notice is consistent with the
			 provisions permitting electronic transmission of notices under section 101 of
			 the Electronic Signatures in Global and National Commerce Act (15 U.S.C.
			 7001).</text>
						</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID0db86297bf754ae4a902e952ee3f2f54"><enum>(2)</enum><header display-inline="yes-display-inline">Media notice</header><text display-inline="yes-display-inline">Notice to major media outlets serving a
			 State or jurisdiction, if the number of residents of such State whose sensitive
			 personally identifiable information was, or is reasonably believed to have
			 been, <added-phrase reported-display-style="italic">accessed or</added-phrase>
			 acquired by an unauthorized person exceeds 5,000.</text>
					</paragraph></section><section commented="no" display-inline="no-display-inline" id="ID80d1a786110544b1b9b1a5fa3fc173b3" section-type="subsequent-section"><enum>314.</enum><header display-inline="yes-display-inline">Content of notification</header>
					<subsection commented="no" display-inline="no-display-inline" id="IDfa2d92fea3304ca696af6618f796eae0"><enum>(a)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">Regardless of the method by which notice is
			 provided to individuals under section 313, such notice shall include, to the
			 extent possible—</text>
						<paragraph commented="no" display-inline="no-display-inline" id="IDceb22bde1f7a4d6c8796d46691c4cbb8"><enum>(1)</enum><text display-inline="yes-display-inline">a description of the categories of
			 sensitive personally identifiable information that was, or is reasonably
			 believed to have been, <added-phrase reported-display-style="italic">accessed
			 or</added-phrase> acquired by an unauthorized person;</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID28e1b7f46b724a5b9a2ce60cc5131cb7"><enum>(2)</enum><text display-inline="yes-display-inline">a toll-free number—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="IDbd40229a7320422989ee3c0ac557bd8b"><enum>(A)</enum><text display-inline="yes-display-inline">that the individual may use to contact the
			 agency or business entity, or the agent of the agency or business entity;
			 and</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDfc951cf3f101457c8627707bc09e9e0f"><enum>(B)</enum><text display-inline="yes-display-inline">from which the individual may learn what
			 types of sensitive personally identifiable information the agency or business
			 entity maintained about that individual; and</text>
							</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDc5bea62ecdf44e3a8787fd9191a02c54"><enum>(3)</enum><text display-inline="yes-display-inline">the toll-free contact telephone numbers and
			 addresses for the major credit reporting agencies.</text>
						</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="IDdb1385c3b8ef44f2b26816b9ae6527dd"><enum>(b)</enum><header display-inline="yes-display-inline">Additional content</header><text display-inline="yes-display-inline">Notwithstanding section 319, a State may
			 require that a notice under subsection (a) shall also include information
			 regarding victim protection assistance provided for by that State.</text>
					</subsection></section><section commented="no" display-inline="no-display-inline" id="ID82ad6f96b46a4c7388f833d7611a6fc3" section-type="subsequent-section"><enum>315.</enum><header display-inline="yes-display-inline">Coordination of notification with credit
			 reporting agencies</header><text display-inline="no-display-inline">If an
			 agency or business entity is required to provide notification to more than
			 5,000 individuals under section 311(a), the agency or business entity shall
			 also notify all consumer reporting agencies that compile and maintain files on
			 consumers on a nationwide basis (as defined in section 603(p) of the Fair
			 Credit Reporting Act (15 U.S.C. 1681a(p)) of the timing and distribution of the
			 notices. <added-phrase reported-display-style="italic"></added-phrase>Such
			 notice shall be given to the consumer credit reporting agencies without
			 unreasonable delay and, if it will not delay notice to the affected
			 individuals, prior to the distribution of notices to the affected
			 individuals.<added-phrase reported-display-style="italic"></added-phrase></text>
				</section><section commented="no" display-inline="no-display-inline" id="IDde1241e504f94594beb8e50db8943996" section-type="subsequent-section"><enum>316.</enum><header display-inline="yes-display-inline">Notice to law enforcement</header>
					<subsection commented="no" display-inline="no-display-inline" id="ID6470f926c275412da556385924db03f0"><enum>(a)</enum><header display-inline="yes-display-inline">Secret
			 service</header><text display-inline="yes-display-inline">Any business entity
			 or agency shall <added-phrase reported-display-style="italic"></added-phrase>notify the United States Secret
			 Service of the fact that a security breach has occurred<added-phrase reported-display-style="italic"></added-phrase> if—</text>
						<paragraph commented="no" display-inline="no-display-inline" id="ID25eedd40ea824dffb164a4b7c3699d78"><enum>(1)</enum><text display-inline="yes-display-inline">the number of individuals whose sensitive
			 personally identifying information was, or is reasonably believed to have been
			 <added-phrase reported-display-style="italic">accessed or</added-phrase>
			 acquired by an unauthorized person exceeds 10,000;</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID274b8ba63d414bbea3287932981bcb9e"><enum>(2)</enum><text display-inline="yes-display-inline">the security breach involves a database,
			 networked or integrated databases, or other data system containing the
			 sensitive personally identifiable information of more than 1,000,000
			 individuals nationwide;</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDd6ac3a83b97545cba8b1492d56e51717"><enum>(3)</enum><text display-inline="yes-display-inline">the security breach involves databases
			 owned by the Federal Government; or</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID1f9e4a10bebc46e6a27dd33efeb1c501"><enum>(4)</enum><text display-inline="yes-display-inline">the security breach involves primarily
			 sensitive personally identifiable information of individuals known to the
			 agency or business entity to be employees and contractors of the Federal
			 Government involved in national security or law enforcement.</text>
						</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="ID2876b95d5ce348b68756b462b093b46c"><enum>(b)</enum><header display-inline="yes-display-inline">Notice to other law enforcement
			 agencies</header><text display-inline="yes-display-inline">The United States
			 Secret Service shall be responsible for notifying—</text>
						<paragraph commented="no" display-inline="no-display-inline" id="IDc6061b421a474781bb0db35ef5bf4fa1"><enum>(1)</enum><text display-inline="yes-display-inline">the Federal Bureau of Investigation, if the
			 security breach involves espionage, foreign counterintelligence, information
			 protected against unauthorized disclosure for reasons of national defense or
			 foreign relations, or Restricted Data (as that term is defined in section 11y
			 of the Atomic Energy Act of 1954 (42 U.S.C. 2014(y)), except for offenses
			 affecting the duties of the United States Secret Service under section 3056(a)
			 of title 18, United States Code;</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID2f36ab20661346abb989fad28adfa9f8"><enum>(2)</enum><text display-inline="yes-display-inline">the United States Postal Inspection
			 Service, if the security breach involves mail fraud; and</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDcdf577b7108b42459b612171122e7e16"><enum>(3)</enum><text display-inline="yes-display-inline">the attorney general of each State affected
			 by the security breach.</text>
						</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="idF9AAB61503E149CB80A21B96C66251B8"><enum>(c)</enum><header display-inline="yes-display-inline">Timing of notices</header><text display-inline="yes-display-inline">The notices required under this section
			 shall be delivered as follows:</text>
						<paragraph commented="no" display-inline="no-display-inline" id="IDc7204f9082b7462e811801d0ff03a6f9"><enum>(1)</enum><text display-inline="yes-display-inline">Notice under subsection (a) shall be
			 delivered as promptly as possible, but not later than 14 days after discovery
			 of the events requiring notice.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID8ea1687feefa47b48adfa72874d9a9c8"><enum>(2)</enum><text display-inline="yes-display-inline">Notice under subsection (b) shall be
			 delivered not later than 14 days after the Service receives notice of a
			 security breach from an agency or business entity.</text>
						</paragraph></subsection></section><section commented="no" display-inline="no-display-inline" id="ID300c058705674d1fa8a20180588bc781" section-type="subsequent-section"><enum>317.</enum><header display-inline="yes-display-inline">Enforcement</header>
					<subsection commented="no" display-inline="no-display-inline" id="IDbe141416b255483ab71bcf923f75d07e"><enum>(a)</enum><header display-inline="yes-display-inline">Civil actions by the Attorney
			 General</header><text display-inline="yes-display-inline">The Attorney General
			 may bring a civil action in the appropriate United States district court
			 against any business entity that engages in conduct constituting a violation of
			 this subtitle and, upon proof of such conduct by a preponderance of the
			 evidence, such business entity shall be subject to a civil penalty of not more
			 than $1,000 per day per individual whose sensitive personally identifiable
			 information was, or is reasonably believed to have been, accessed or acquired
			 by an unauthorized person, up to a maximum of $1,000,000 per violation, unless
			 such conduct is found to be willful or intentional.</text>
					</subsection><subsection commented="no" display-inline="no-display-inline" id="ID631759b47738493ba66ec30f99662368"><enum>(b)</enum><header display-inline="yes-display-inline">Injunctive actions by the Attorney
			 General</header>
						<paragraph commented="no" display-inline="no-display-inline" id="idA40BA83000324B59A06AB9324F2EE801"><enum>(1)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">If it appears that a business entity has
			 engaged, or is engaged, in any act or practice constituting a violation of this
			 subtitle, the Attorney General may petition an appropriate district court of
			 the United States for an order—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="ID74548a65207a4be1b5560768fd8301ec"><enum>(A)</enum><text display-inline="yes-display-inline">enjoining such act or practice; or</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDeb83e5afed4e49eca123a19958cb01d7"><enum>(B)</enum><text display-inline="yes-display-inline">enforcing compliance with this
			 subtitle.</text>
							</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="idA696A113E8B84FC592D67CA706DB4191"><enum>(2)</enum><header display-inline="yes-display-inline">Issuance of order</header><text display-inline="yes-display-inline">A court may issue an order under paragraph
			 (1), if the court finds that the conduct in question constitutes a violation of
			 this subtitle.</text>
						</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="ID2d946cff5da64c3eacb4d51276222d66"><enum>(c)</enum><header display-inline="yes-display-inline">Other rights and remedies</header><text display-inline="yes-display-inline">The rights and remedies available under
			 this subtitle are cumulative and shall not affect any other rights and remedies
			 available under law.</text>
					</subsection><subsection commented="no" display-inline="no-display-inline" id="ID5874a4e4f1ba4c40b090e66b9db432eb"><enum>(d)</enum><header display-inline="yes-display-inline">Fraud alert</header><text display-inline="yes-display-inline">Section 605A(b)(1) of the Fair Credit
			 Reporting Act (15 U.S.C. 1681c–1(b)(1)) is amended by inserting <quote>, or
			 evidence that the consumer has received notice that the consumer's financial
			 information has or may have been compromised,</quote> after <quote>identity
			 theft report</quote>.</text>
					</subsection></section><section commented="no" display-inline="no-display-inline" id="ID28d22f15074d4f239f64734d16e27d82" section-type="subsequent-section"><enum>318.</enum><header display-inline="yes-display-inline">Enforcement by State attorneys
			 general</header>
					<subsection commented="no" display-inline="no-display-inline" id="ID158448a7945943d2800a68223fa1c66f"><enum>(a)</enum><header display-inline="yes-display-inline">In general</header>
						<paragraph commented="no" display-inline="no-display-inline" id="ID5e7013c2684b41fcaaa6367e9a467271"><enum>(1)</enum><header display-inline="yes-display-inline">Civil actions</header><text display-inline="yes-display-inline">In any case in which the attorney general
			 of a State or any State or local law enforcement agency authorized by the State
			 attorney general or by State statute to prosecute violations of consumer
			 protection law, has reason to believe that an interest of the residents of that
			 State has been or is threatened or adversely affected by the engagement of a
			 business entity in a practice that is prohibited under this subtitle, the State
			 or the State or local law enforcement agency on behalf of the residents of the
			 agency’s jurisdiction, may bring a civil action on behalf of the residents of
			 the State or jurisdiction in a district court of the United States of
			 appropriate jurisdiction or any other court of competent jurisdiction,
			 including a State court, to—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="ID06956a544afc45749fc0dbd4ca0ac7b0"><enum>(A)</enum><text display-inline="yes-display-inline">enjoin that practice;</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID9c8b6e64896e4dac88bd5fde14d8348f"><enum>(B)</enum><text display-inline="yes-display-inline">enforce compliance with this subtitle;
			 or</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID1e58ea4082c74d2ca134ca9129b3c6bc"><enum>(C)</enum><text display-inline="yes-display-inline">civil penalties of not more than $1,000 per
			 day per individual whose sensitive personally identifiable information was, or
			 is reasonably believed to have been, accessed or acquired by an unauthorized
			 person, up to a maximum of $1,000,000 per violation, unless such conduct is
			 found to be willful or intentional.</text>
							</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDcac299cc128a49aaa541ed6dd90eb98c"><enum>(2)</enum><header display-inline="yes-display-inline">Notice</header>
							<subparagraph commented="no" display-inline="no-display-inline" id="ID36cb88ea917c4f3bbfd3588bf949c4e0"><enum>(A)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">Before filing an action under paragraph
			 (1), the attorney general of the State involved shall provide to the Attorney
			 General of the United States—</text>
								<clause commented="no" display-inline="no-display-inline" id="ID529bbf03fe7f4c7594b9508261fe891a"><enum>(i)</enum><text display-inline="yes-display-inline">written notice of the action; and</text>
								</clause><clause commented="no" display-inline="no-display-inline" id="IDe2292626c56a40f7aa11edc6929dcaf4"><enum>(ii)</enum><text display-inline="yes-display-inline">a copy of the complaint for the
			 action.</text>
								</clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID0ad31433f66a4571a9f315c10cdd38c2"><enum>(B)</enum><header display-inline="yes-display-inline">Exemption</header>
								<clause commented="no" display-inline="no-display-inline" id="ID9c3e5026e335415f94ddf78c665486e0"><enum>(i)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">Subparagraph (A) shall not apply with
			 respect to the filing of an action by an attorney general of a State under this
			 subtitle, if the State attorney general determines that it is not feasible to
			 provide the notice described in such subparagraph before the filing of the
			 action.</text>
								</clause><clause commented="no" display-inline="no-display-inline" id="ID29e7139ab7c24cd79ce8b2cad0fba4b8"><enum>(ii)</enum><header display-inline="yes-display-inline">Notification</header><text display-inline="yes-display-inline">In an action described in clause (i), the
			 attorney general of a State shall provide notice and a copy of the complaint to
			 the Attorney General at the time the State attorney general files the
			 action.</text>
								</clause></subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="IDb4eb145eecea482ab7ecbe2f6d40f36c"><enum>(b)</enum><header display-inline="yes-display-inline">Federal proceedings</header><text display-inline="yes-display-inline">Upon receiving notice under subsection
			 (a)(2), the Attorney General shall have the right to—</text>
						<paragraph commented="no" display-inline="no-display-inline" id="ID26f41fd7f1cf46ffad598e468846a90a"><enum>(1)</enum><text display-inline="yes-display-inline">move to stay the action, pending the final
			 disposition of a pending Federal proceeding or action;</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id4E300CFE489848D1B21A6A1A6258C25E"><enum>(2)</enum><text display-inline="yes-display-inline">initiate an action in the appropriate
			 United States district court under section 317 and move to consolidate all
			 pending actions, including State actions, in such court;</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID66487e1b00654427bbd02a953c7f3344"><enum>(3)</enum><text display-inline="yes-display-inline">intervene in an action brought under
			 subsection (a)(2); and</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID6fb3b32f5626404b9d0907977a93d1d0"><enum>(4)</enum><text display-inline="yes-display-inline">file petitions for appeal.</text>
						</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="IDb15d3714cf524105a323f95c838f931c"><enum>(c)</enum><header display-inline="yes-display-inline">Pending proceedings</header><text display-inline="yes-display-inline">If the Attorney General has instituted a
			 proceeding or action for a violation of this subtitle or any regulations
			 thereunder, no attorney general of a State may, during the pendency of such
			 proceeding or action, bring an action under this subtitle against any defendant
			 named in such criminal proceeding or civil action for any violation that is
			 alleged in that proceeding or action.</text>
					</subsection><subsection commented="no" display-inline="no-display-inline" id="ID11b3d09326ab42b5a7039ab72e901f56"><enum>(d)</enum><header display-inline="yes-display-inline">Construction</header><text display-inline="yes-display-inline">For purposes of bringing any civil action
			 under subsection (a), nothing in this subtitle regarding notification shall be
			 construed to prevent an attorney general of a State from exercising the powers
			 conferred on such attorney general by the laws of that State to—</text>
						<paragraph commented="no" display-inline="no-display-inline" id="IDf0b18861c7dd4211aefde7a73679597c"><enum>(1)</enum><text display-inline="yes-display-inline">conduct investigations;</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDc52d3767f683458e8510bfda8261c65e"><enum>(2)</enum><text display-inline="yes-display-inline">administer oaths or affirmations; or</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDa7edebada22b454c840d70f0fff4c763"><enum>(3)</enum><text display-inline="yes-display-inline">compel the attendance of witnesses or the
			 production of documentary and other evidence.</text>
						</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="ID79f340f19ca84e1b8a9b8f1ce237716e"><enum>(e)</enum><header display-inline="yes-display-inline">Venue; service of process</header>
						<paragraph commented="no" display-inline="no-display-inline" id="ID2c88083250b3444a832e60e4ce40a2ba"><enum>(1)</enum><header display-inline="yes-display-inline">Venue</header><text display-inline="yes-display-inline">Any action brought under subsection (a) may
			 be brought in—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="IDf0a91014a2a84fd99bea1e2c7bdcdca3"><enum>(A)</enum><text display-inline="yes-display-inline">the district court of the United States
			 that meets applicable requirements relating to venue under section 1391 of
			 title 28, United States Code; or</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID8639d88534d8455097a8b05a580b0de3"><enum>(B)</enum><text display-inline="yes-display-inline">another court of competent
			 jurisdiction.</text>
							</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDf957252071c14424b32a3b3ead23cfb0"><enum>(2)</enum><header display-inline="yes-display-inline">Service of process</header><text display-inline="yes-display-inline">In an action brought under subsection (a),
			 process may be served in any district in which the defendant—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="ID0708d5b6cfac45f0b642801232c2bfbe"><enum>(A)</enum><text display-inline="yes-display-inline">is an inhabitant; or</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDd8a6af6a09b544afa2b24224adf2c9cc"><enum>(B)</enum><text display-inline="yes-display-inline">may be found.</text>
							</subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="IDf57afe347d774657bf92f82edd4ec59e"><enum>(f)</enum><header display-inline="yes-display-inline">No private cause of action</header><text display-inline="yes-display-inline">Nothing in this subtitle establishes a
			 private cause of action against a business entity for violation of any
			 provision of this subtitle.</text>
					</subsection></section><section commented="no" display-inline="no-display-inline" id="IDa5c5ed85f5b948b08f30d0800295937a" section-type="subsequent-section"><enum>319.</enum><header display-inline="yes-display-inline">Effect on Federal and State
			 law</header><text display-inline="no-display-inline">The provisions of this
			 subtitle shall supersede any other provision of Federal law or any provision of
			 law of any State relating to notification by a business entity engaged in
			 interstate commerce or an agency of a security breach, except as provided in
			 section 314(b).</text>
				</section><section commented="no" display-inline="no-display-inline" id="ID90730e6c13ca4a49b382b3f1e9ee896e" section-type="subsequent-section"><enum>320.</enum><header display-inline="yes-display-inline">Authorization of
			 appropriations</header><text display-inline="no-display-inline">There are
			 authorized to be appropriated such sums as may be necessary to cover the costs
			 incurred by the United States Secret Service to carry out investigations and
			 risk assessments of security breaches as required under this subtitle.</text>
				</section><section commented="no" display-inline="no-display-inline" id="ID0c5c8ec1f3e24cd886be5d8e2f850ca7" section-type="subsequent-section"><enum>321.</enum><header display-inline="yes-display-inline">Reporting on risk assessment
			 exemptions</header><text display-inline="no-display-inline">The United States
			 Secret Service shall report to Congress not later than 18 months after the date
			 of enactment of this Act, and upon the request by Congress thereafter,
			 on—</text>
					<paragraph commented="no" display-inline="no-display-inline" id="IDa7b8f800cc534389b40bb6e89642575f"><enum>(1)</enum><text display-inline="yes-display-inline">the number and nature of the security
			 breaches described in the notices filed by those business entities invoking the
			 risk assessment exemption under section 312(b) and the response of the United
			 States Secret Service to such notices; and</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID2882bcf4ab6e40599f78f745dbac92ff"><enum>(2)</enum><text display-inline="yes-display-inline">the number and nature of security breaches
			 subject to the national security and law enforcement exemptions under section
			 312(a), provided that such report may not disclose the contents of any risk
			 assessment provided to the United States Secret Service pursuant to this
			 subtitle.</text>
					</paragraph></section><section commented="no" display-inline="no-display-inline" id="ID527ade6c074f448da6e7e220dd02a32e" section-type="subsequent-section"><enum>322.</enum><header display-inline="yes-display-inline">Effective
			 date</header><text display-inline="no-display-inline">This subtitle shall take
			 effect on the expiration of the date which is 90 days after the date of
			 enactment of this Act.</text>
				</section></subtitle><subtitle changed="deleted" commented="no" id="id75F2FE2314DC46D08187B9BAA28D1DD5" level-type="subsequent" reported-display-style="strikethrough"><enum>C</enum><header display-inline="yes-display-inline">Office of Federal Identity
			 Protection</header>
				<section commented="no" display-inline="no-display-inline" id="id03A6D5A282264B0DAB093F8E9F1A89F2" section-type="subsequent-section"><enum>331.</enum><header display-inline="yes-display-inline">Office of Federal Identity
			 Protection</header>
					<subsection commented="no" display-inline="no-display-inline" id="id5E7D41E1399A47F5A2ADEA1E39A8276B"><enum>(a)</enum><header display-inline="yes-display-inline">Establishment</header><text display-inline="yes-display-inline">There is established in the Federal Trade
			 Commission an Office of Federal Identity Protection.</text>
					</subsection><subsection commented="no" display-inline="no-display-inline" id="id7FE1873B3AEC424990700F47FBA3B67F"><enum>(b)</enum><header display-inline="yes-display-inline">Duties</header><text display-inline="yes-display-inline">The Office of Federal Identity Protection
			 shall be responsible for assisting each consumer with—</text>
						<paragraph commented="no" display-inline="no-display-inline" id="IDa79408e5488346a1b0c0464f76abfd31"><enum>(1)</enum><text display-inline="yes-display-inline">addressing the consequences of the theft or
			 compromise of the personally identifiable information of that consumer;</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="idBBAD25BE845A446BB30AB6E14B1FA733"><enum>(2)</enum><text display-inline="yes-display-inline">accessing remedies provided under Federal
			 law and providing information about remedies available under State law;</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id7DB56F78980A46E184B01AF50B1081EE"><enum>(3)</enum><text display-inline="yes-display-inline">restoring the accuracy of—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="idECDE47519D6A4653BA9B704B0F10BF48"><enum>(A)</enum><text display-inline="yes-display-inline">the personally identifiable information of
			 that consumer; and</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idEDA45A7741724E0CAD326F3A62997A22"><enum>(B)</enum><text display-inline="yes-display-inline">records containing the personally
			 identifiable information of that consumer that were stolen or compromised;
			 and</text>
							</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id65F47D9B8C6248719A148F1F849C2B79"><enum>(4)</enum><text display-inline="yes-display-inline">retrieving any stolen or compromised
			 personally identifiable information of that consumer.</text>
						</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="id4343EFB55058459DA6E7BE136B610AF5"><enum>(c)</enum><header display-inline="yes-display-inline">Activities</header><text display-inline="yes-display-inline">In order to perform the duties required
			 under subsection (b), the Office of Federal Identity Protection shall carry out
			 the following activities:</text>
						<paragraph commented="no" display-inline="no-display-inline" id="IDc90107ac65aa4403bf57084a31025143"><enum>(1)</enum><text display-inline="yes-display-inline">Establish a website, easily and
			 conspicuously accessible from ftc.gov, dedicated to assisting consumers with
			 the retrieval of the stolen or compromised personally identifiable information
			 of the consumer.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDa35492535c3f4c1d9ee8a9d57b5edca8"><enum>(2)</enum><text display-inline="yes-display-inline">Maintain a toll-free phone number to help
			 answer questions concerning identity theft from consumers.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDad7fbc04bb5447ff9b4469f1024cf0c1"><enum>(3)</enum><text display-inline="yes-display-inline">Establish online and offline
			 consumer-service teams to assist consumers seeking the retrieval of the
			 personally identifiable information of the consumer.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="idBDEBFD88337643718A829A0C7E1BEE70"><enum>(4)</enum><text display-inline="yes-display-inline">Provide guidance and information to service
			 organizations or pro bono legal services programs that offer individualized
			 assistance or counseling to victims of identity theft.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID4ab92ac113ce480f9f362136bc58de2a"><enum>(5)</enum><text display-inline="yes-display-inline">Establish a reasonable standard for
			 determining when an individual becomes a victim of identity theft.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID8aa1f41f7d344bf584ad5e5256883d82"><enum>(6)</enum><text display-inline="yes-display-inline">Issue certifications to individuals who,
			 under the standard described in paragraph (5), are identity theft
			 victims.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID42de201466be4c4a9f6c8b886f495db9"><enum>(7)</enum><text display-inline="yes-display-inline">Permit an individual to use the Office of
			 Federal Identity Protection certification—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="id734FAF55B78B4D4D98A0455D77FFB42D"><enum>(A)</enum><text display-inline="yes-display-inline">in all Federal, State, and local
			 jurisdictions, in lieu of a police report or any other document required by
			 State or local law, as a prerequisite to accessing business records of
			 transactions done by someone claiming to be the individual; and</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idBAF596AC46894C4E94FD2585ED026B86"><enum>(B)</enum><text display-inline="yes-display-inline">to establish the eligibility of that
			 individual for—</text>
								<clause commented="no" display-inline="no-display-inline" id="id4160AA9E76C64320B46E81D80845E7B5"><enum>(i)</enum><text display-inline="yes-display-inline">the fraud alert protections under section
			 605A of the Fair Credit Reporting Act (15 U.S.C. 1681c–1); and</text>
								</clause><clause commented="no" display-inline="no-display-inline" id="idA3DB86FFDF574D8FA22DE23CA9636950"><enum>(ii)</enum><text display-inline="yes-display-inline">the reporting protections under section
			 605B(a) of the Fair Credit Reporting Act (15 U.S.C. 1681c–2(a)).</text>
								</clause></subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="idE61DC16C36764F57999F21776453963F"><enum>(8)</enum><text display-inline="yes-display-inline">Coordinate, as the Office determines
			 necessary, with the designated Chief Privacy Officer of each Federal agency, or
			 any other designated senior official in such agency in charge of privacy, in
			 order to meet the duties of assisting consumers as required under subsection
			 (b).</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDbbd804b8524248ee896d3d7439568a94"><enum>(9)</enum><text display-inline="yes-display-inline">In addition to the requirements in
			 paragraphs (1) through (7), the Federal Trade Commission shall promulgate
			 regulations that enable the Office of Federal Identity Protection to help
			 consumers restore their stolen or otherwise compromised personally identifiable
			 information quickly and inexpensively.</text>
						</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="ID5f1d3af4131e44b5b3d462765135557a"><enum>(d)</enum><header display-inline="yes-display-inline">Authorization of
			 appropriations</header><text display-inline="yes-display-inline">There are
			 authorized to be appropriated for the Office of Federal Identity Protection
			 such sums as are necessary for fiscal year 2010 and each of the 4 succeeding
			 fiscal years.</text>
					</subsection></section></subtitle></title><title commented="no" id="id14E3D0E4F57E4B0A8C0C7207624800D1" level-type="subsequent"><enum>IV</enum><header display-inline="yes-display-inline">Government access to and use of commercial
			 data</header>
			<section commented="no" display-inline="no-display-inline" id="ID12b6cb5e199e41929bf7df592fcd092f" section-type="subsequent-section"><enum>401.</enum><header display-inline="yes-display-inline">General services administration review of
			 contracts</header>
				<subsection commented="no" display-inline="no-display-inline" id="ID995b836df04c406a91e33953d556a900"><enum>(a)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">In considering contract awards totaling
			 more than $500,000 and entered into after the date of enactment of this Act
			 with data brokers, the Administrator of the General Services Administration
			 shall evaluate—</text>
					<paragraph commented="no" display-inline="no-display-inline" id="IDd81fec140bdb4eb3b0924ba3030a135e"><enum>(1)</enum><text display-inline="yes-display-inline">the data privacy and security program of a
			 data broker to ensure the privacy and security of data containing personally
			 identifiable information, including whether such program adequately addresses
			 privacy and security threats created by malicious software or code, or the use
			 of peer-to-peer file sharing software;</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID6b25f35cb40e491eb48de6f3d6768bd4"><enum>(2)</enum><text display-inline="yes-display-inline">the compliance of a data broker with such
			 program;</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID60a4e479908346c2839ef7b4423f45c3"><enum>(3)</enum><text display-inline="yes-display-inline">the extent to which the databases and
			 systems containing personally identifiable information of a data broker have
			 been compromised by security breaches; and</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID949ad97ace5b4929bb68f4ca8b544025"><enum>(4)</enum><text display-inline="yes-display-inline">the response by a data broker to such
			 breaches, including the efforts by such data broker to mitigate the impact of
			 such security breaches.</text>
					</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="IDce3b2ba9c6b2469dbd50314cb6268e3e"><enum>(b)</enum><header display-inline="yes-display-inline">Compliance safe harbor</header><text display-inline="yes-display-inline">The data privacy and security program of a
			 data broker shall be deemed sufficient for the purposes of subsection (a), if
			 the data broker complies with or provides protection equal to industry
			 standards, as identified by the Federal Trade Commission, that are applicable
			 to the type of personally identifiable information involved in the ordinary
			 course of business of such data broker.</text>
				</subsection><subsection commented="no" display-inline="no-display-inline" id="ID3bd4f223fe26433ab41f1ca859884b6a"><enum>(c)</enum><header display-inline="yes-display-inline">Penalties</header><text display-inline="yes-display-inline">In awarding contracts with data brokers for
			 products or services related to access, use, compilation, distribution,
			 processing, analyzing, or evaluating personally identifiable information, the
			 Administrator of the General Services Administration shall—</text>
					<paragraph commented="no" display-inline="no-display-inline" id="IDebdaa8ec56814a069eaffb85c34f2ba9"><enum>(1)</enum><text display-inline="yes-display-inline">include monetary or other penalties—</text>
						<subparagraph commented="no" display-inline="no-display-inline" id="ID96f2956451cb41baaa8ae62030fdb0a8"><enum>(A)</enum><text display-inline="yes-display-inline">for failure to comply with subtitles A and
			 B of title III; or</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDaa149b7ee8a94b318052713319405cf3"><enum>(B)</enum><text display-inline="yes-display-inline">if a contractor knows or has reason to know
			 that the personally identifiable information being provided is inaccurate, and
			 provides such inaccurate information; and</text>
						</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDa7ac7c96c6d9487ba2685498956532ab"><enum>(2)</enum><text display-inline="yes-display-inline">require a data broker that engages service
			 providers not subject to subtitle A of title III for responsibilities related
			 to sensitive personally identifiable information to—</text>
						<subparagraph commented="no" display-inline="no-display-inline" id="ID9f1b82ec90eb4e2c8fc6122262c60788"><enum>(A)</enum><text display-inline="yes-display-inline">exercise appropriate due diligence in
			 selecting those service providers for responsibilities related to personally
			 identifiable information;</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDcff9a67f57044095a9372fd650b53077"><enum>(B)</enum><text display-inline="yes-display-inline">take reasonable steps to select and retain
			 service providers that are capable of maintaining appropriate safeguards for
			 the security, privacy, and integrity of the personally identifiable information
			 at issue; and</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDb86e5489dd9d4867b1104a90a8c56370"><enum>(C)</enum><text display-inline="yes-display-inline">require such service providers, by
			 contract, to implement and maintain appropriate measures designed to meet the
			 objectives and requirements in title III.</text>
						</subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="ID2ed921e9172648cfa9d7e97f01e18642"><enum>(d)</enum><header display-inline="yes-display-inline">Limitation</header><text display-inline="yes-display-inline">The penalties under subsection (c) shall
			 not apply to a data broker providing information that is accurately and
			 completely recorded from a public record source or licensor.</text>
				</subsection></section><section commented="no" display-inline="no-display-inline" id="ID2c32eab739de4fea85488e717413b035" section-type="subsequent-section"><enum>402.</enum><header display-inline="yes-display-inline">Requirement to audit information security
			 practices of contractors and third party business entities</header><text display-inline="no-display-inline">Section 3544(b) of title 44, United States
			 Code, is amended—</text>
				<paragraph commented="no" display-inline="no-display-inline" id="ID886fac1dc8d54a45a34cd023c3f0603a"><enum>(1)</enum><text display-inline="yes-display-inline">in paragraph (7)(C)(iii), by striking
			 <quote>and</quote> after the semicolon;</text>
				</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID86d7b3ac16e14a24a17152aa29d8f8fa"><enum>(2)</enum><text display-inline="yes-display-inline">in paragraph (8), by striking the period
			 and inserting <quote>; and</quote>; and</text>
				</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID487bd2dd97084bb592f9c8b701bada8d"><enum>(3)</enum><text display-inline="yes-display-inline">by adding at the end the following:</text>
					<quoted-block display-inline="no-display-inline" id="id51C65F1CDDDA4661ABF00BC805968E30" style="OLC">
						<paragraph commented="no" display-inline="no-display-inline" id="IDfe9569912cd9418d80acea18528c30c7"><enum>(9)</enum><text display-inline="yes-display-inline">procedures for evaluating and auditing the
				information security practices of contractors or third party business entities
				supporting the information systems or operations of the agency involving
				personally identifiable information (as that term is defined in section 3 of
				the <short-title>Personal Data Privacy and Security Act of
				2009</short-title>) and ensuring remedial action to address any significant
				deficiencies.</text>
						</paragraph><after-quoted-block>.</after-quoted-block></quoted-block>
				</paragraph></section><section commented="no" display-inline="no-display-inline" id="ID4056fc3599c54deeb9c0ed352866c385" section-type="subsequent-section"><enum>403.</enum><header display-inline="yes-display-inline">Privacy impact assessment of government use
			 of commercial information services containing personally identifiable
			 information</header>
				<subsection commented="no" display-inline="no-display-inline" id="ID5ce43dba31a3469d8b31a5e94d0ff19e"><enum>(a)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">Section 208(b)(1) of the E-Government Act
			 of 2002 (44 U.S.C. 3501 note) is amended—</text>
					<paragraph commented="no" display-inline="no-display-inline" id="ID8514e50d74594d6ab9ccc96eaa8a555a"><enum>(1)</enum><text display-inline="yes-display-inline">in subparagraph (A)(i), by striking
			 <quote>or</quote>; and</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID4a6f00d902c043c1af3a0a1bbc4c338a"><enum>(2)</enum><text display-inline="yes-display-inline">in subparagraph (A)(ii), by striking the
			 period and inserting <quote>; or</quote>; and</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDc02e3e37ef45496d915ac736eabee83a"><enum>(3)</enum><text display-inline="yes-display-inline">by inserting after clause (ii) the
			 following:</text>
						<quoted-block display-inline="no-display-inline" id="idBB13C89F7A95426D9ADE3BE28B30BDA4" style="OLC">
							<clause commented="no" display-inline="no-display-inline" id="IDa49e55dafba94f21a8f9e8abdb9d2094"><enum>(iii)</enum><text display-inline="yes-display-inline">purchasing or subscribing for a fee to
				personally identifiable information from a data broker (as such terms are
				defined in section 3 of the <short-title>Personal Data
				Privacy and Security Act of
				2009</short-title>).</text>
							</clause><after-quoted-block>.</after-quoted-block></quoted-block>
					</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="IDb0f703f2ffff413d8304e950ee6002a0"><enum>(b)</enum><header display-inline="yes-display-inline">Limitation</header><text display-inline="yes-display-inline">Notwithstanding any other provision of law,
			 commencing 1 year after the date of enactment of this Act, no Federal agency
			 may enter into a contract with a data broker to access for a fee any database
			 consisting primarily of personally identifiable information concerning United
			 States persons (other than news reporting or telephone directories) unless the
			 head of such department or agency—</text>
					<paragraph commented="no" display-inline="no-display-inline" id="IDbd9a44cb0f8347f48c4ffc2e9d43e1af"><enum>(1)</enum><text display-inline="yes-display-inline">completes a privacy impact assessment under
			 section 208 of the E-Government Act of 2002 (44 U.S.C. 3501 note), which shall
			 subject to the provision in that Act pertaining to sensitive information,
			 include a description of—</text>
						<subparagraph commented="no" display-inline="no-display-inline" id="IDd9c08f20b45a4ad0a9fbe129d268f7ef"><enum>(A)</enum><text display-inline="yes-display-inline">such database;</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID5f3a37fd1cde4cf29c866b52941d8fd6"><enum>(B)</enum><text display-inline="yes-display-inline">the name of the data broker from whom it is
			 obtained; and</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID0e42886510c84307bd1b8ff76f26348d"><enum>(C)</enum><text display-inline="yes-display-inline">the amount of the contract for use;</text>
						</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID7fd6917e701945c9b29407ea764b2358"><enum>(2)</enum><text display-inline="yes-display-inline">adopts regulations that specify—</text>
						<subparagraph commented="no" display-inline="no-display-inline" id="IDc2d0e5565e274bb8a62c879648972b07"><enum>(A)</enum><text display-inline="yes-display-inline">the personnel permitted to access, analyze,
			 or otherwise use such databases;</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDed199cff45a94ca6857c1fdc4f42ba73"><enum>(B)</enum><text display-inline="yes-display-inline">standards governing the access, analysis,
			 or use of such databases;</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID5f5fee5062cc4fed9f55394fe0b12ce4"><enum>(C)</enum><text display-inline="yes-display-inline">any standards used to ensure that the
			 personally identifiable information accessed, analyzed, or used is the minimum
			 necessary to accomplish the intended legitimate purpose of the Federal
			 agency;</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID489c12de6977443b834d48a26009897e"><enum>(D)</enum><text display-inline="yes-display-inline">standards limiting the retention and
			 redisclosure of personally identifiable information obtained from such
			 databases;</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDdb1a32a1904a4f108fc798f4eb7627ad"><enum>(E)</enum><text display-inline="yes-display-inline">procedures ensuring that such data meet
			 standards of accuracy, relevance, completeness, and timeliness;</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID9f20a216795e4ffa94c388eee36c08d4"><enum>(F)</enum><text display-inline="yes-display-inline">the auditing and security measures to
			 protect against unauthorized access, analysis, use, or modification of data in
			 such databases;</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID39a555ea4350456cb5a5388d3531afb1"><enum>(G)</enum><text display-inline="yes-display-inline">applicable mechanisms by which individuals
			 may secure timely redress for any adverse consequences wrongly incurred due to
			 the access, analysis, or use of such databases;</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDd3b6e9327d7d40da8f9d58f61cb46f71"><enum>(H)</enum><text display-inline="yes-display-inline">mechanisms, if any, for the enforcement and
			 independent oversight of existing or planned procedures, policies, or
			 guidelines; and</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDd244312f492a424f8cd060941aafb73d"><enum>(I)</enum><text display-inline="yes-display-inline">an outline of enforcement mechanisms for
			 accountability to protect individuals and the public against unlawful or
			 illegitimate access or use of databases; and</text>
						</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID21a7368695e04683b6b2556783e36345"><enum>(3)</enum><text display-inline="yes-display-inline">incorporates into the contract or other
			 agreement totaling more than $500,000, provisions—</text>
						<subparagraph commented="no" display-inline="no-display-inline" id="ID52450c4b015e4106b52161964153f4b0"><enum>(A)</enum><text display-inline="yes-display-inline">providing for penalties—</text>
							<clause commented="no" display-inline="no-display-inline" id="ID47368893b6114f4a8e949a7e5908021d"><enum>(i)</enum><text display-inline="yes-display-inline">for failure to comply with title III of
			 this Act; or</text>
							</clause><clause commented="no" display-inline="no-display-inline" id="ID524c9d6d46814f64bb14403a6b3e8c86"><enum>(ii)</enum><text display-inline="yes-display-inline">if the entity knows or has reason to know
			 that the personally identifiable information being provided to the Federal
			 department or agency is inaccurate, and provides such inaccurate information;
			 and</text>
							</clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID5830c7e15b514afabc350d588a163c16"><enum>(B)</enum><text display-inline="yes-display-inline">requiring a data broker that engages
			 service providers not subject to subtitle A of title III for responsibilities
			 related to sensitive personally identifiable information to—</text>
							<clause commented="no" display-inline="no-display-inline" id="IDc820784a80784abf8d8422b62333783a"><enum>(i)</enum><text display-inline="yes-display-inline">exercise appropriate due diligence in
			 selecting those service providers for responsibilities related to personally
			 identifiable information;</text>
							</clause><clause commented="no" display-inline="no-display-inline" id="ID52a184cf261f43fbbe693fea76df4c09"><enum>(ii)</enum><text display-inline="yes-display-inline">take reasonable steps to select and retain
			 service providers that are capable of maintaining appropriate safeguards for
			 the security, privacy, and integrity of the personally identifiable information
			 at issue; and</text>
							</clause><clause commented="no" display-inline="no-display-inline" id="ID824d34d50448495f8e3998930307cbd6"><enum>(iii)</enum><text display-inline="yes-display-inline">require such service providers, by
			 contract, to implement and maintain appropriate measures designed to meet the
			 objectives and requirements in title III.</text>
							</clause></subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="IDee4893ba854540c99c2733dfb1bddf7d"><enum>(c)</enum><header display-inline="yes-display-inline">Limitation on penalties</header><text display-inline="yes-display-inline">The penalties under subsection (b)(3)(A)
			 shall not apply to a data broker providing information that is accurately and
			 completely recorded from a public record source.</text>
				</subsection><subsection commented="no" display-inline="no-display-inline" id="id104D66BAD0F0492FB042C3DCF1573537"><enum>(d)</enum><header display-inline="yes-display-inline">Study of government use</header>
					<paragraph commented="no" display-inline="no-display-inline" id="idFA2A5D39AE0D4066A7DFB48438EA740A"><enum>(1)</enum><header display-inline="yes-display-inline">Scope
			 of study</header><text display-inline="yes-display-inline">Not later than 180
			 days after the date of enactment of this Act, the Comptroller General of the
			 United States shall conduct a study and audit and prepare a report on Federal
			 agency actions to address the recommendations in the Government Accountability
			 Office's April 2006 report on agency adherence to key privacy principles in
			 using data brokers or commercial databases containing personally identifiable
			 information.</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id076A50E3C6FF4B178BB62383248C9913"><enum>(2)</enum><header display-inline="yes-display-inline">Report</header><text display-inline="yes-display-inline">A copy of the report required under
			 paragraph (1) shall be submitted to Congress.</text>
					</paragraph></subsection></section><section commented="no" display-inline="no-display-inline" id="ID938f0445fd614561aaba4ee7b370044f" section-type="subsequent-section"><enum>404.</enum><header display-inline="yes-display-inline">Implementation of chief privacy officer
			 requirements</header>
				<subsection commented="no" display-inline="no-display-inline" id="ID18bc26c0b5194508b7813d651b51591b"><enum>(a)</enum><header display-inline="yes-display-inline">Designation of the chief privacy
			 officer</header><text display-inline="yes-display-inline">Pursuant to the
			 requirements under section 522 of the Transportation, Treasury, Independent
			 Agencies, and General Government Appropriations Act, 2005 (division H of Public
			 Law 108–447; 118 Stat. 3199) that each agency designate a Chief Privacy
			 Officer, the Department of Justice shall implement such requirements by
			 designating a department-wide Chief Privacy Officer, whose primary role shall
			 be to fulfill the duties and responsibilities of Chief Privacy Officer and who
			 shall report directly to the Deputy Attorney General.</text>
				</subsection><subsection commented="no" display-inline="no-display-inline" id="ID51d5e6f4a9f34cdcab14d97cdeeed25a"><enum>(b)</enum><header display-inline="yes-display-inline">Duties and responsibilities of chief
			 privacy officer</header><text display-inline="yes-display-inline">In addition
			 to the duties and responsibilities outlined under section 522 of the
			 Transportation, Treasury, Independent Agencies, and General Government
			 Appropriations Act, 2005 (division H of Public Law 108–447; 118 Stat. 3199),
			 the Department of Justice Chief Privacy Officer shall—</text>
					<paragraph commented="no" display-inline="no-display-inline" id="ID6e62e410e9b8451d842da5813b497620"><enum>(1)</enum><text display-inline="yes-display-inline">oversee the Department of Justice’s
			 implementation of the requirements under section 403 to conduct privacy impact
			 assessments of the use of commercial data containing personally identifiable
			 information by the Department; and</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDc1c9e9832b064e8aa387f3ecf87cc622"><enum>(2)</enum><text display-inline="yes-display-inline">coordinate with the Privacy and Civil
			 Liberties Oversight Board, established in the Intelligence Reform and Terrorism
			 Prevention Act of 2004 (Public Law 108–458), in implementing this
			 section.</text>
					</paragraph></subsection></section></title></legis-body>
	<endorsement>
		<action-date>November 5, 2009</action-date>
		<action-desc>Reported with amendments</action-desc>
	</endorsement>
</bill>
