<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" bill-type="olc" dms-id="H86652CC497CF44E6B4887FF858A581E0" public-private="public">
	<form>
		<distribution-code display="yes">I</distribution-code>
		<congress>112th CONGRESS</congress>
		<session>1st Session</session>
		<legis-num>H. R. 1707</legis-num>
		<current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber>
		<action>
			<action-date date="20110504">May 4, 2011</action-date>
			<action-desc><sponsor name-id="R000515">Mr. Rush</sponsor> (for
			 himself, <cosponsor name-id="B000213">Mr. Barton of Texas</cosponsor>, and
			 <cosponsor name-id="S001145">Ms. Schakowsky</cosponsor>) introduced the
			 following bill; which was referred to the <committee-name committee-id="HIF00">Committee on Energy and
			 Commerce</committee-name></action-desc>
		</action>
		<legis-type>A BILL</legis-type>
		<official-title>To protect consumers by requiring reasonable security
		  policies and procedures to protect data containing personal information, and to
		  provide for nationwide notice in the event of a security
		  breach.</official-title>
	</form>
	<legis-body id="H82DB7E97C36E4647AD04E49F197D0F43" style="OLC">
		<section id="H79A2ECAC3CE44CBE8EEF6EBA3654A21B" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the
			 <quote><short-title>Data Accountability and Trust
			 Act</short-title></quote>.</text>
		</section><section id="H8C8DB795156548A1BA382B689982904C"><enum>2.</enum><header>Requirements for
			 information security</header>
			<subsection id="H6F9E5BD92C774545B709AE6C1864E621"><enum>(a)</enum><header>General security
			 policies and procedures</header>
				<paragraph id="H370F4C302651465F976E66D4B9CEB83E"><enum>(1)</enum><header>Regulations</header><text>Not
			 later than 1 year after the date of enactment of this Act, the Commission shall
			 promulgate regulations under section 553 of title 5, United States Code, to
			 require each person engaged in interstate commerce that owns or possesses data
			 containing personal information, or contracts to have any third party entity
			 maintain such data for such person, to establish and implement policies and
			 procedures regarding information security practices for the treatment and
			 protection of personal information taking into consideration—</text>
					<subparagraph id="HA140750B4C89445A9AE1C6D0F65DA2B5"><enum>(A)</enum><text>the size of, and
			 the nature, scope, and complexity of the activities engaged in by, such
			 person;</text>
					</subparagraph><subparagraph id="H389C0F2B26AC4FE9A11426623E8A052C"><enum>(B)</enum><text>the current state
			 of the art in administrative, technical, and physical safeguards for protecting
			 such information; and</text>
					</subparagraph><subparagraph id="HA8B70389E57D40F689EB00555970ABC2"><enum>(C)</enum><text>the cost of
			 implementing such safeguards.</text>
					</subparagraph></paragraph><paragraph id="HCB13F853E30B48C685B979D1FCB1FBD5"><enum>(2)</enum><header>Requirements</header><text>Such
			 regulations shall require the policies and procedures to include the
			 following:</text>
					<subparagraph commented="no" id="H922E40CBAF094A9D9BB7DEFF582B3190"><enum>(A)</enum><text display-inline="yes-display-inline">A security policy with respect to the
			 collection, use, sale, other dissemination, and maintenance of such personal
			 information.</text>
					</subparagraph><subparagraph id="HA0332E7008374F918E6C47CE677D4E96"><enum>(B)</enum><text display-inline="yes-display-inline">The identification of an officer or other
			 individual as the point of contact with responsibility for the management of
			 information security.</text>
					</subparagraph><subparagraph commented="no" id="HDF2770016CA74C84A0E3225A9DC54051"><enum>(C)</enum><text display-inline="yes-display-inline">A process for identifying and assessing any
			 reasonably foreseeable vulnerabilities in the system or systems maintained by
			 such person that contains such data, which shall include regular monitoring for
			 a breach of security of such system or systems.</text>
					</subparagraph><subparagraph commented="no" id="HA4CF0A674CA246BDBA1DE7526F419391"><enum>(D)</enum><text>A process for
			 taking preventive and corrective action to mitigate against any vulnerabilities
			 identified in the process required by subparagraph (C), which may include
			 implementing any changes to security practices and the architecture,
			 installation, or implementation of network or operating software.</text>
					</subparagraph><subparagraph id="H6179B976B3A745438DC10C8FFC39FB7E"><enum>(E)</enum><text>A process for
			 disposing of data in electronic form containing personal information by
			 shredding, permanently erasing, or otherwise modifying the personal information
			 contained in such data to make such personal information permanently unreadable
			 or undecipherable.</text>
					</subparagraph><subparagraph commented="no" id="HB0F1A7051C454E3A995A49DEA872125C"><enum>(F)</enum><text>A standard method
			 or methods for the destruction of paper documents and other non-electronic data
			 containing personal information.</text>
					</subparagraph></paragraph><paragraph commented="no" id="H3A6CD45F63DC44E6B56F137B39D05747"><enum>(3)</enum><header>Treatment of
			 entities governed by other law</header><text display-inline="yes-display-inline">Any person who is in compliance with any
			 other Federal law that requires such person to maintain standards and
			 safeguards for information security and protection of personal information
			 that, taken as a whole and as the Commission shall determine in the rulemaking
			 required under paragraph (1), provide protections substantially similar to, or
			 greater than, those required under this subsection, shall be deemed to be in
			 compliance with this subsection.</text>
				</paragraph></subsection><subsection commented="no" id="HB3C50AF3A00B405A927216A44A6E8F4A"><enum>(b)</enum><header>Special
			 requirements for information brokers</header>
				<paragraph commented="no" id="H8AFAEC50B5E54B9D86EF5FC964DBF8F4"><enum>(1)</enum><header>Submission of
			 policies to the FTC</header><text display-inline="yes-display-inline">The
			 regulations promulgated under subsection (a) shall require each information
			 broker to submit its security policies to the Commission in conjunction with a
			 notification of a breach of security under section 3 or upon request of the
			 Commission.</text>
				</paragraph><paragraph id="H9559AD8D9A3D4A37B2399A76D9A6C5FE"><enum>(2)</enum><header>Post-breach
			 audit</header><text display-inline="yes-display-inline">For any information
			 broker required to provide notification under section 3, the Commission may
			 conduct audits of the information security practices of such information
			 broker, or require the information broker to conduct independent audits of such
			 practices (by an independent auditor who has not audited such information
			 broker’s security practices during the preceding 5 years).</text>
				</paragraph><paragraph commented="no" display-inline="no-display-inline" id="H52BAE764AA454BF084E1B175BC61C652"><enum>(3)</enum><header>Accuracy of and
			 individual access to personal information</header>
					<subparagraph commented="no" id="HEF25F5D4994A4874BABD3949B5A2466B"><enum>(A)</enum><header>Accuracy</header>
						<clause id="H947ADE5036CD4382921F641824834953"><enum>(i)</enum><header>In
			 general</header><text>Each information broker shall establish reasonable
			 procedures to assure the maximum possible accuracy of the personal information
			 it collects, assembles, or maintains, and any other information it collects,
			 assembles, or maintains that specifically identifies an individual, other than
			 information which merely identifies an individual’s name or address.</text>
						</clause><clause id="HD2E3622BE4C343948BD75EC232E56A6E"><enum>(ii)</enum><header>Limited
			 exception for fraud databases</header><text display-inline="yes-display-inline">The requirement in clause (i) shall not
			 prevent the collection or maintenance of information that may be inaccurate
			 with respect to a particular individual when that information is being
			 collected or maintained solely—</text>
							<subclause id="HC524EB1126464083BE7CBA40C344E344"><enum>(I)</enum><text>for the purpose of
			 indicating whether there may be a discrepancy or irregularity in the personal
			 information that is associated with an individual; and</text>
							</subclause><subclause id="HF4410D97CAF245D0B1CDD2BF082CA394"><enum>(II)</enum><text>to help identify,
			 or authenticate the identity of, an individual, or to protect against or
			 investigate fraud or other unlawful conduct.</text>
							</subclause></clause></subparagraph><subparagraph commented="no" id="H12985DFFC75F40A389B5FB59F8CB0A4D"><enum>(B)</enum><header>Consumer access
			 to information</header>
						<clause commented="no" id="H30BCD986E06542FCB2A20C29ED378C35"><enum>(i)</enum><header>Access</header><text>Each
			 information broker shall—</text>
							<subclause commented="no" id="H2FE3CB61ADA349389D535805BB2A34CE"><enum>(I)</enum><text display-inline="yes-display-inline">provide to each individual whose personal
			 information it maintains, at the individual’s request at least 1 time per year
			 and at no cost to the individual, and after verifying the identity of such
			 individual, a means for the individual to review any personal information
			 regarding such individual maintained by the information broker and any other
			 information maintained by the information broker that specifically identifies
			 such individual, other than information which merely identifies an individual’s
			 name or address; and</text>
							</subclause><subclause commented="no" id="HDD5E38A496F846F79B4A0F29EC575B4E"><enum>(II)</enum><text>place a
			 conspicuous notice on its Internet website (if the information broker maintains
			 such a website) instructing individuals how to request access to the
			 information required to be provided under subclause (I), and, as applicable,
			 how to express a preference with respect to the use of personal information for
			 marketing purposes under clause (iii).</text>
							</subclause></clause><clause commented="no" id="H0ACBB5AA606B417CA789A6CE0A6848C1"><enum>(ii)</enum><header>Disputed
			 information</header><text display-inline="yes-display-inline">Whenever an
			 individual whose information the information broker maintains makes a written
			 request disputing the accuracy of any such information, the information broker,
			 after verifying the identity of the individual making such request and unless
			 there are reasonable grounds to believe such request is frivolous or
			 irrelevant, shall—</text>
							<subclause commented="no" display-inline="no-display-inline" id="H87637F0D0F2D4B25A85B6E46B48EDE67"><enum>(I)</enum><text>correct any
			 inaccuracy; or</text>
							</subclause><subclause commented="no" id="H700E8763BB9F4ED88E90637548362F0F"><enum>(II)</enum><item commented="no" display-inline="yes-display-inline" id="HD1F7FDBE04814099A9AA26D07E72A8F9"><enum>(aa)</enum><text>in the case of
			 information that is public record information, inform the individual of the
			 source of the information, and, if reasonably available, where a request for
			 correction may be directed and, if the individual provides proof that the
			 public record has been corrected or that the information broker was reporting
			 the information incorrectly, correct the inaccuracy in the information broker’s
			 records; or</text>
								</item><item commented="no" id="H7254B05C71BA41B790F80058AE69C82F" indent="up1"><enum>(bb)</enum><text display-inline="yes-display-inline">in the case of information that is
			 non-public information, note the information that is disputed, including the
			 individual’s statement disputing such information, and take reasonable steps to
			 independently verify such information under the procedures outlined in
			 subparagraph (A) if such information can be independently verified.</text>
								</item></subclause></clause><clause commented="no" id="HF72347625C5B40A690F8BF549C514395"><enum>(iii)</enum><header>Alternative
			 procedure for certain marketing information</header><text display-inline="yes-display-inline">In accordance with regulations issued under
			 clause (v), an information broker that maintains any information described in
			 clause (i) which is used, shared, or sold by such information broker for
			 marketing purposes, may, in lieu of complying with the access and dispute
			 requirements set forth in clauses (i) and (ii), provide each individual whose
			 information it maintains with a reasonable means of expressing a preference not
			 to have his or her information used for such purposes. If the individual
			 expresses such a preference, the information broker may not use, share, or sell
			 the individual’s information for marketing purposes.</text>
						</clause><clause id="H5524FF847336476F87E7CD2923A82EF7"><enum>(iv)</enum><header>Limitations</header><text>An
			 information broker may limit the access to information required under clause
			 (i)(I) and is not required to provide notice to individuals as required under
			 clause (i)(II) in the following circumstances:</text>
							<subclause commented="no" id="H2B578218B8054740840376D70E113440"><enum>(I)</enum><text>If access of the
			 individual to the information is limited by law or legally recognized
			 privilege.</text>
							</subclause><subclause commented="no" id="HE2DC79F03A8348F1A2CECA75BC7AB1F9"><enum>(II)</enum><text>If the
			 information is used for a legitimate governmental or fraud prevention purpose
			 that would be compromised by such access.</text>
							</subclause><subclause id="H71E5ADF13B0C4D218AB06EA36B794F05"><enum>(III)</enum><text display-inline="yes-display-inline">If the information consists of a published
			 media record, unless that record has been included in a report about an
			 individual shared with a third party.</text>
							</subclause></clause><clause commented="no" id="H6251C7B4CFF34BE1A7586A3D62B8045A"><enum>(v)</enum><header>Rulemaking</header><text display-inline="yes-display-inline">Not later than 1 year after the date of the
			 enactment of this Act, the Commission shall promulgate regulations under
			 section 553 of title 5, United States Code, to carry out this paragraph and to
			 facilitate the purposes of this Act. In addition, the Commission shall issue
			 regulations, as necessary, under section 553 of title 5, United States Code, on
			 the scope of the application of the limitations in clause (iv), including any
			 additional circumstances in which an information broker may limit access to
			 information under such clause that the Commission determines to be
			 appropriate.</text>
						</clause></subparagraph><subparagraph commented="no" id="H0DA0E6628E944E82A7924CBB1FCD3BD7"><enum>(C)</enum><header>FCRA regulated
			 persons</header><text display-inline="yes-display-inline">Any information
			 broker who is engaged in activities subject to the Fair Credit Reporting Act
			 and who is in compliance with sections 609, 610, and 611 of such Act (15 U.S.C.
			 1681g; 1681h; 1681i) with respect to information subject to such Act, shall be
			 deemed to be in compliance with this paragraph with respect to such
			 information.</text>
					</subparagraph></paragraph><paragraph commented="no" id="H5BDA791FCF084C8498D92BFD72EA3113"><enum>(4)</enum><header>Requirement of
			 audit log of accessed and transmitted information</header><text display-inline="yes-display-inline">Not later than 1 year after the date of the
			 enactment of this Act, the Commission shall promulgate regulations under
			 section 553 of title 5, United States Code, to require information brokers to
			 establish measures which facilitate the auditing or retracing of any internal
			 or external access to, or transmissions of, any data containing personal
			 information collected, assembled, or maintained by such information
			 broker.</text>
				</paragraph><paragraph commented="no" id="H7417831346AA43BF9CAF18F7ED9B7A9A"><enum>(5)</enum><header>Prohibition on
			 pretexting by information brokers</header>
					<subparagraph commented="no" id="H889C1DB1C40B4965875FD2599EA9CCFD"><enum>(A)</enum><header>Prohibition on
			 obtaining personal information by false pretenses</header><text>It shall be
			 unlawful for an information broker to obtain or attempt to obtain, or cause to
			 be disclosed or attempt to cause to be disclosed to any person, personal
			 information or any other information relating to any person by—</text>
						<clause commented="no" id="HDE27B7CFF4B64B18B774309130218AF9"><enum>(i)</enum><text>making a false,
			 fictitious, or fraudulent statement or representation to any person; or</text>
						</clause><clause commented="no" id="H1B81C64A603748A29A8254D00C4EA934"><enum>(ii)</enum><text display-inline="yes-display-inline">providing any document or other information
			 to any person that the information broker knows or should know to be forged,
			 counterfeit, lost, stolen, or fraudulently obtained, or to contain a false,
			 fictitious, or fraudulent statement or representation.</text>
						</clause></subparagraph><subparagraph commented="no" id="HBDFC28A3630947528EF071589C02AF74"><enum>(B)</enum><header>Prohibition on
			 solicitation to obtain personal information under false pretenses</header><text display-inline="yes-display-inline">It shall be unlawful for an information
			 broker to request a person to obtain personal information or any other
			 information relating to any other person, if the information broker knew or
			 should have known that the person to whom such a request is made will obtain or
			 attempt to obtain such information in the manner described in subparagraph
			 (A).</text>
					</subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="H3086E3E20A5446E6B76E8A6197A4E135"><enum>(c)</enum><header>Exemption for
			 certain service providers</header><text display-inline="yes-display-inline">Nothing in this section shall apply to a
			 service provider for any electronic communication by a third party that is
			 transmitted, routed, or stored in intermediate or transient storage by such
			 service provider.</text>
			</subsection></section><section id="H3D4614210E02465E8B0BE8BB2903AE4A"><enum>3.</enum><header>Notification of
			 information security breach</header>
			<subsection id="HEBB9684A90844F8AA758907D1D7D115D"><enum>(a)</enum><header>Nationwide
			 Notification</header><text>Any person engaged in interstate commerce that owns
			 or possesses data in electronic form containing personal information shall,
			 following the discovery of a breach of security of the system maintained by
			 such person that contains such data—</text>
				<paragraph id="H764E614A087E49CF9B747ECCA8AA5C09"><enum>(1)</enum><text>notify each
			 individual who is a citizen or resident of the United States whose personal
			 information was acquired or accessed as a result of such a breach of security;
			 and</text>
				</paragraph><paragraph id="HF8016F1233AA42898248FAFED4400561"><enum>(2)</enum><text>notify the
			 Commission.</text>
				</paragraph></subsection><subsection id="HA28E07CB0E8446CB99AEE87C17D55E12"><enum>(b)</enum><header>Special
			 Notification Requirements</header>
				<paragraph id="HB1664A1DBA094E01A0A5CAB34F11B851"><enum>(1)</enum><header>Third party
			 agents</header><text>In the event of a breach of security by any third party
			 entity that has been contracted to maintain or process data in electronic form
			 containing personal information on behalf of any other person who owns or
			 possesses such data, such third party entity shall be required to notify such
			 person of the breach of security. Upon receiving such notification from such
			 third party, such person shall provide the notification required under
			 subsection (a).</text>
				</paragraph><paragraph commented="no" id="H6CF595BCE4954D4F889BEB4417AAC09E"><enum>(2)</enum><header>Service
			 providers</header><text display-inline="yes-display-inline">If a service
			 provider becomes aware of a breach of security of data in electronic form
			 containing personal information that is owned or possessed by another person
			 that connects to or uses a system or network provided by the service provider
			 for the purpose of transmitting, routing, or providing intermediate or
			 transient storage of such data, such service provider shall be required to
			 notify of such a breach of security only the person who initiated such
			 connection, transmission, routing, or storage if such person can be reasonably
			 identified. Upon receiving such notification from a service provider, such
			 person shall provide the notification required under subsection (a).</text>
				</paragraph><paragraph id="HC4BBDB0E676A431F9A3C55854BED4214"><enum>(3)</enum><header>Coordination of
			 notification with credit reporting agencies</header><text display-inline="yes-display-inline">If a person is required to provide
			 notification to more than 5,000 individuals under subsection (a)(1), the person
			 shall also notify the major credit reporting agencies that compile and maintain
			 files on consumers on a nationwide basis, of the timing and distribution of the
			 notices. Such notice shall be given to the credit reporting agencies without
			 unreasonable delay and, if it will not delay notice to the affected
			 individuals, prior to the distribution of notices to the affected individuals.</text>
				</paragraph></subsection><subsection id="H4635A084931D46889B9B3D426E293915"><enum>(c)</enum><header>Timeliness of
			 Notification</header>
				<paragraph commented="no" id="H957FA99C686546659716216A131E48C4"><enum>(1)</enum><header>In
			 general</header><text display-inline="yes-display-inline">Unless subject to a
			 delay authorized under paragraph (2), a notification required under subsection
			 (a) shall be made not later than 60 days following the discovery of a breach of
			 security, unless the person providing notice can show that providing notice
			 within such a time frame is not feasible due to extraordinary circumstances
			 necessary to prevent further breach or unauthorized disclosures, and reasonably
			 restore the integrity of the data system, in which case such notification shall
			 be made as promptly as possible.</text>
				</paragraph><paragraph commented="no" id="H75875A9CF0B546F0BC683F42538715B8"><enum>(2)</enum><header>Delay of
			 Notification Authorized for Law Enforcement or National Security
			 Purposes</header>
					<subparagraph commented="no" id="H0C6557E9ADA2421688FD1FF068D4398F"><enum>(A)</enum><header>Law
			 enforcement</header><text>If a Federal, State, or local law enforcement agency
			 determines that the notification required under this section would impede a
			 civil or criminal investigation, such notification shall be delayed upon the
			 written request of the law enforcement agency for 30 days or such lesser period
			 of time which the law enforcement agency determines is reasonably necessary and
			 requests in writing. A law enforcement agency may, by a subsequent written
			 request, revoke such delay or extend the period of time set forth in the
			 original request made under this paragraph if further delay is
			 necessary.</text>
					</subparagraph><subparagraph commented="no" id="HA33FA3375C734CB89F5E637206A5CCE2"><enum>(B)</enum><header>National
			 security</header><text>If a Federal national security agency or homeland
			 security agency determines that the notification required under this section
			 would threaten national or homeland security, such notification may be delayed
			 for a period of time which the national security agency or homeland security
			 agency determines is reasonably necessary and requests in writing. A Federal
			 national security agency or homeland security agency may revoke such delay or
			 extend the period of time set forth in the original request made under this
			 paragraph by a subsequent written request if further delay is necessary.</text>
					</subparagraph></paragraph></subsection><subsection id="H9AF6EEDD33814AC3A3195CE8150974DB"><enum>(d)</enum><header>Method and
			 Content of Notification</header>
				<paragraph id="H93F14E494B32434F85C5749647A41ED3"><enum>(1)</enum><header>Direct
			 notification</header>
					<subparagraph id="H3DD75672B3C945C39397398585ACA38E"><enum>(A)</enum><header>Method of
			 notification</header><text>A person required to provide notification to
			 individuals under subsection (a)(1) shall be in compliance with such
			 requirement if the person provides conspicuous and clearly identified
			 notification by one of the following methods (provided the selected method can
			 reasonably be expected to reach the intended individual):</text>
						<clause id="H38257409C6AE40AD82992277179A606A"><enum>(i)</enum><text>Written
			 notification.</text>
						</clause><clause id="H4E9E6654367148A9888E719714476027"><enum>(ii)</enum><text>Notification by
			 email or other electronic means, if—</text>
							<subclause id="H490129A7867E469987D54D3B697B1DC1"><enum>(I)</enum><text>the person’s
			 primary method of communication with the individual is by email or such other
			 electronic means; or</text>
							</subclause><subclause id="HFF8E5951E74A4F77B4A8349D8CFA65B3"><enum>(II)</enum><text>the individual
			 has consented to receive such notification and the notification is provided in
			 a manner that is consistent with the provisions permitting electronic
			 transmission of notices under section 101 of the Electronic Signatures in
			 Global and National Commerce Act (15 U.S.C. 7001).</text>
							</subclause></clause></subparagraph><subparagraph id="H3B7329F7CA9C447680E138A3BCE8FDBD"><enum>(B)</enum><header>Content of
			 notification</header><text>Regardless of the method by which notification is
			 provided to an individual under subparagraph (A), such notification shall
			 include—</text>
						<clause id="H60607494F5FE43379EBF00E44E3FB880"><enum>(i)</enum><text>a
			 description of the personal information that was acquired or accessed by an
			 unauthorized person;</text>
						</clause><clause id="HADF99840BE0445B6B5978BB3C3E47D86"><enum>(ii)</enum><text>a
			 telephone number that the individual may use, at no cost to such individual, to
			 contact the person to inquire about the breach of security or the information
			 the person maintained about that individual;</text>
						</clause><clause commented="no" id="H8C91545BCD6D4387B46CA55F888A8256"><enum>(iii)</enum><text display-inline="yes-display-inline">notice that the individual is entitled to
			 receive, at no cost to such individual, consumer credit reports on a quarterly
			 basis for a period of 2 years, or credit monitoring or other service that
			 enables consumers to detect the misuse of their personal information for a
			 period of 2 years, and instructions to the individual on requesting such
			 reports or service from the person, except when the only information which has
			 been the subject of the security breach is the individual’s first name or
			 initial and last name, or address, or phone number, in combination with a
			 credit or debit card number, and any required security code;</text>
						</clause><clause id="HDED863CFCE914962A5E8527105CF06BD"><enum>(iv)</enum><text>the
			 toll-free contact telephone numbers and addresses for the major credit
			 reporting agencies; and</text>
						</clause><clause id="H52275B8FFB4041238B7B7F50141D243D"><enum>(v)</enum><text>a
			 toll-free telephone number and Internet website address for the Commission
			 whereby the individual may obtain information regarding identity theft.</text>
						</clause></subparagraph></paragraph><paragraph id="HC6093E5EFEE24FDF9AD1D78B79B9B30E"><enum>(2)</enum><header>Substitute
			 notification</header>
					<subparagraph id="HD43C15769C23455583FC19E312AA763A"><enum>(A)</enum><header>Circumstances
			 giving rise to substitute notification</header><text>A person required to
			 provide notification to individuals under subsection (a)(1) may provide
			 substitute notification in lieu of the direct notification required by
			 paragraph (1) if the person owns or possesses data in electronic form
			 containing personal information of fewer than 1,000 individuals and such direct
			 notification is not feasible due to—</text>
						<clause id="HFBF321BD087D4871AD34C57CE7745405"><enum>(i)</enum><text>excessive cost to
			 the person required to provide such notification relative to the resources of
			 such person, as determined in accordance with the regulations issued by the
			 Commission under paragraph (3)(A); or</text>
						</clause><clause id="H1D0ACE9BC9BF48A89D809E280E22106E"><enum>(ii)</enum><text>lack of
			 sufficient contact information for the individual required to be
			 notified.</text>
						</clause></subparagraph><subparagraph id="H3A0D04BEA8394EB6B67558DBC532C964"><enum>(B)</enum><header>Form of
			 substitute notification</header><text>Such substitute notification shall
			 include—</text>
						<clause id="HBD5300F1C0C74DA48AA07B7F7730CBDD"><enum>(i)</enum><text>email notification
			 to the extent that the person has email addresses of individuals to whom it is
			 required to provide notification under subsection (a)(1);</text>
						</clause><clause id="H4D003C2D1E594F1CBB0ED356852F663C"><enum>(ii)</enum><text>a
			 conspicuous notice on the Internet website of the person (if such person
			 maintains such a website); and</text>
						</clause><clause id="HFAE5B5336CBB43E080BA12D63242046D"><enum>(iii)</enum><text>notification in
			 print and to broadcast media, including major media in metropolitan and rural
			 areas where the individuals whose personal information was acquired
			 reside.</text>
						</clause></subparagraph><subparagraph id="HDA2884A166644FF486F2B211AB1885EC"><enum>(C)</enum><header>Content of
			 substitute notice</header><text>Each form of substitute notice under this
			 paragraph shall include—</text>
						<clause id="HE75CEEEEC0F546F18A02AF05369CADA9"><enum>(i)</enum><text display-inline="yes-display-inline">notice that individuals whose personal
			 information is included in the breach of security are entitled to receive, at
			 no cost to the individuals, consumer credit reports on a quarterly basis for a
			 period of 2 years, or credit monitoring or other service that enables consumers
			 to detect the misuse of their personal information for a period of 2 years, and
			 instructions on requesting such reports or service from the person, except when
			 the only information which has been the subject of the security breach is the
			 individual’s first name or initial and last name, or address, or phone number,
			 in combination with a credit or debit card number, and any required security
			 code; and</text>
						</clause><clause id="H6652CCBF7AC048EEB19E04F9F0364E62"><enum>(ii)</enum><text>a
			 telephone number by which an individual can, at no cost to such individual,
			 learn whether that individual’s personal information is included in the breach
			 of security.</text>
						</clause></subparagraph></paragraph><paragraph id="H7858418A0556413CAEE94EF96315084C"><enum>(3)</enum><header>Regulations and
			 guidance</header>
					<subparagraph id="HB6801DBA08714D6B938E5D5331BF6EC0"><enum>(A)</enum><header>Regulations</header><text>Not
			 later than 1 year after the date of enactment of this Act, the Commission
			 shall, by regulation under section 553 of title 5, United States Code,
			 establish criteria for determining circumstances under which substitute
			 notification may be provided under paragraph (2), including criteria for
			 determining if notification under paragraph (1) is not feasible due to
			 excessive costs to the person required to provided such notification relative
			 to the resources of such person. Such regulations may also identify other
			 circumstances where substitute notification would be appropriate for any
			 person, including circumstances under which the cost of providing notification
			 exceeds the benefits to consumers.</text>
					</subparagraph><subparagraph id="H483675DB02084C18AC4E49C4F29B29C1"><enum>(B)</enum><header>Guidance</header><text>In
			 addition, the Commission shall provide and publish general guidance with
			 respect to compliance with this subsection. Such guidance shall include—</text>
						<clause commented="no" id="HB06FF19AEA4C4A3EB2BCB08C9B4A1ED7"><enum>(i)</enum><text>a description of
			 written or email notification that complies with the requirements of paragraph
			 (1); and</text>
						</clause><clause commented="no" id="HF97DF6BD18CC40798FF101BB279EB51A"><enum>(ii)</enum><text>guidance on the
			 content of substitute notification under paragraph (2), including the extent of
			 notification to print and broadcast media that complies with the requirements
			 of such paragraph.</text>
						</clause></subparagraph></paragraph></subsection><subsection commented="no" id="H35BDC85A4127439FAA3FE2FC8B414B7C"><enum>(e)</enum><header>Other
			 Obligations Following Breach</header>
				<paragraph commented="no" id="H9CA7255A895E4AE794B9FE4253B664A2"><enum>(1)</enum><header>In
			 general</header><text>A person required to provide notification under
			 subsection (a) shall, upon request of an individual whose personal information
			 was included in the breach of security, provide or arrange for the provision
			 of, to each such individual and at no cost to such individual—</text>
					<subparagraph id="HA31791E5D4CD442FA7B4F57B43621F7B"><enum>(A)</enum><text>consumer credit
			 reports from at least one of the major credit reporting agencies beginning not
			 later than 60 days following the individual’s request and continuing on a
			 quarterly basis for a period of 2 years thereafter; or</text>
					</subparagraph><subparagraph id="H10B30C43380348DEA3DAFEE2E31D9DC0"><enum>(B)</enum><text display-inline="yes-display-inline">a credit monitoring or other service that
			 enables consumers to detect the misuse of their personal information, beginning
			 not later than 60 days following the individual’s request and continuing for a
			 period of 2 years.</text>
					</subparagraph></paragraph><paragraph commented="no" id="H6EA5EC32D1544016809D5BFC104C5318"><enum>(2)</enum><header>Limitation</header><text>This
			 subsection shall not apply if the only personal information which has been the
			 subject of the security breach is the individual’s first name or initial and
			 last name, or address, or phone number, in combination with a credit or debit
			 card number, and any required security code.</text>
				</paragraph><paragraph commented="no" id="HB7C687BFB6E54373B4B1BDF0E7AA0333"><enum>(3)</enum><header>Rulemaking</header><text>As
			 part of the Commission’s rulemaking described in subsection (d)(3), the
			 Commission shall determine the circumstances under which a person required to
			 provide notification under subsection (a)(1) shall provide or arrange for the
			 provision of free consumer credit reports or credit monitoring or other service
			 to affected individuals.</text>
				</paragraph></subsection><subsection id="H3A0338C2EF6D423F954BA25878A7B724"><enum>(f)</enum><header>Exemption</header>
				<paragraph id="H9852FAF01A874F6B87C53F6E05C91F24"><enum>(1)</enum><header>General
			 exemption</header><text>A person shall be exempt from the requirements under
			 this section if, following a breach of security, such person determines that
			 there is no reasonable risk of identity theft, fraud, or other unlawful
			 conduct.</text>
				</paragraph><paragraph id="H2A237950F509480BB1B397926D4CC564"><enum>(2)</enum><header>Presumption</header>
					<subparagraph id="H7D5A73D3860E4255BD84FD242A9A6994"><enum>(A)</enum><header>In
			 general</header><text>If the data in electronic form containing personal
			 information is rendered unusable, unreadable, or indecipherable through
			 encryption or other security technology or methodology (if the method of
			 encryption or such other technology or methodology is generally accepted by
			 experts in the information security field), there shall be a presumption that
			 no reasonable risk of identity theft, fraud, or other unlawful conduct exists
			 following a breach of security of such data. Any such presumption may be
			 rebutted by facts demonstrating that the encryption or other security
			 technologies or methodologies in a specific case, have been or are reasonably
			 likely to be compromised.</text>
					</subparagraph><subparagraph commented="no" id="H6FA1116CC4E24E32A2A1FC224E9AD31F"><enum>(B)</enum><header>methodologies or
			 technologies</header><text display-inline="yes-display-inline">Not later than 1
			 year after the date of the enactment of this Act and biannually thereafter, the
			 Commission shall issue rules (pursuant to section 553 of title 5, United States
			 Code) or guidance to identify security methodologies or technologies which
			 render data in electronic form unusable, unreadable, or indecipherable, that
			 shall, if applied to such data, establish a presumption that no reasonable risk
			 of identity theft, fraud, or other unlawful conduct exists following a breach
			 of security of such data. Any such presumption may be rebutted by facts
			 demonstrating that any such methodology or technology in a specific case has
			 been or is reasonably likely to be compromised. In issuing such rules or
			 guidance, the Commission shall consult with relevant industries, consumer
			 organizations, and data security and identity theft prevention experts and
			 established standards setting bodies.</text>
					</subparagraph></paragraph><paragraph id="HE6E3E6F0760146AD841F27530825F3D7"><enum>(3)</enum><header>FTC
			 guidance</header><text display-inline="yes-display-inline">Not later than 1
			 year after the date of the enactment of this Act the Commission shall issue
			 guidance regarding the application of the exemption in paragraph (1).</text>
				</paragraph></subsection><subsection id="H0D37C7BF6974468692158DBA9BD61CB2"><enum>(g)</enum><header>Website Notice
			 of Federal Trade Commission</header><text>If the Commission, upon receiving
			 notification of any breach of security that is reported to the Commission under
			 subsection (a)(2), finds that notification of such a breach of security via the
			 Commission’s Internet website would be in the public interest or for the
			 protection of consumers, the Commission shall place such a notice in a clear
			 and conspicuous location on its Internet website.</text>
			</subsection><subsection id="H561172FF2D0E49D881A05D79C6EE508E"><enum>(h)</enum><header>FTC Study on
			 Notification in Languages in Addition to English</header><text>Not later than 1
			 year after the date of enactment of this Act, the Commission shall conduct a
			 study on the practicality and cost effectiveness of requiring the notification
			 required by subsection (d)(1) to be provided in a language in addition to
			 English to individuals known to speak only such other language.</text>
			</subsection><subsection id="HC14370010341428A8DDBC21E64A9DA9C"><enum>(i)</enum><header>General
			 rulemaking authority</header><text display-inline="yes-display-inline">The
			 Commission may promulgate regulations necessary under section 553 of title 5,
			 United States Code, to effectively enforce the requirements of this
			 section.</text>
			</subsection><subsection commented="no" id="HEF95DC469212473694FF8288245095EA"><enum>(j)</enum><header>Treatment of
			 persons governed by other law</header><text display-inline="yes-display-inline">A person who is in compliance with any
			 other Federal law that requires such person to provide notification to
			 individuals following a breach of security, and that, taken as a whole,
			 provides protections substantially similar to, or greater than, those required
			 under this section, as the Commission shall determine by rule (under section
			 553 of title 5, United States Code), shall be deemed to be in compliance with
			 this section.</text>
			</subsection></section><section id="H2E7B6FB55EB747129585C3E45C9F0C39"><enum>4.</enum><header>Application and
			 Enforcement</header>
			<subsection commented="no" id="HF4661019100B4BC6A92C399CA904B2CC"><enum>(a)</enum><header>General
			 application</header><text display-inline="yes-display-inline">The requirements
			 of sections 2 and 3 shall only apply to those persons, partnerships, or
			 corporations over which the Commission has authority pursuant to section
			 5(a)(2) of the Federal Trade Commission Act (15 U.S.C. 45(a)(2)).</text>
			</subsection><subsection id="HAEEA5736437B4289B914C5FE19E62C80"><enum>(b)</enum><header>Enforcement by
			 the Federal Trade Commission</header>
				<paragraph id="H522F1D4B699E491798F5896EE327CB98"><enum>(1)</enum><header>Unfair or
			 deceptive acts or practices</header><text>A violation of section 2 or 3 shall
			 be treated as an unfair and deceptive act or practice in violation of a
			 regulation under section 18(a)(1)(B) of the Federal Trade Commission Act (15
			 U.S.C. 57a(a)(1)(B)) regarding unfair or deceptive acts or practices.</text>
				</paragraph><paragraph id="HE3ECA7E11E68483C850DE3B6E3851BFC"><enum>(2)</enum><header>Powers of
			 commission</header><text>The Commission shall enforce this Act in the same
			 manner, by the same means, and with the same jurisdiction, powers, and duties
			 as though all applicable terms and provisions of the Federal Trade Commission
			 Act (15 U.S.C. 41 et seq.) were incorporated into and made a part of this Act.
			 Any person who violates such regulations shall be subject to the penalties and
			 entitled to the privileges and immunities provided in that Act.</text>
				</paragraph><paragraph id="HA9310D27121342FEBF449ED8C9979BAD"><enum>(3)</enum><header>Limitation</header><text>In
			 promulgating rules under this Act, the Commission shall not require the
			 deployment or use of any specific products or technologies, including any
			 specific computer software or hardware.</text>
				</paragraph></subsection><subsection id="H977B543B33F24EB7B6D8BCD88191A4B3"><enum>(c)</enum><header>Enforcement by
			 State Attorneys General</header>
				<paragraph id="H34ABC4D65A38447A8F94221D4F7BEFEF"><enum>(1)</enum><header>Civil
			 action</header><text>In any case in which the attorney general of a State, or
			 an official or agency of a State, has reason to believe that an interest of the
			 residents of that State has been or is threatened or adversely affected by any
			 person who violates section 2 or 3 of this Act, the attorney general, official,
			 or agency of the State, as parens patriae, may bring a civil action on behalf
			 of the residents of the State in a district court of the United States of
			 appropriate jurisdiction—</text>
					<subparagraph id="H94B890BAFB94447AAE19509F7931DAAA"><enum>(A)</enum><text>to enjoin further
			 violation of such section by the defendant;</text>
					</subparagraph><subparagraph id="H5FEBD089C9A040BDA3C080BA04BB3CBD"><enum>(B)</enum><text>to compel
			 compliance with such section; or</text>
					</subparagraph><subparagraph id="HA170BB9C6EC7473D985B1AEC7CDCFEF7"><enum>(C)</enum><text>to obtain civil
			 penalties in the amount determined under paragraph (2).</text>
					</subparagraph></paragraph><paragraph id="H3A595B6523F74EA28320AAF4433635CD"><enum>(2)</enum><header>Civil
			 penalties</header>
					<subparagraph id="HF3D8DE0220C142D7A17E9873C5454FE7"><enum>(A)</enum><header>Calculation</header>
						<clause id="H675454ED851B4E2C94014927E8D5E62A"><enum>(i)</enum><header>Treatment of
			 violations of section 2</header><text>For purposes of paragraph (1)(C) with
			 regard to a violation of section 2, the amount determined under this paragraph
			 is the amount calculated by multiplying the number of days that a person is not
			 in compliance with such section by an amount not greater than $11,000.</text>
						</clause><clause id="H1E712C97489349278C1DE5A932283BC4"><enum>(ii)</enum><header>Treatment of
			 violations of section 3</header><text display-inline="yes-display-inline">For
			 purposes of paragraph (1)(C) with regard to a violation of section 3, the
			 amount determined under this paragraph is the amount calculated by multiplying
			 the number of violations of such section by an amount not greater than $11,000.
			 Each failure to send notification as required under section 3 to a resident of
			 the State shall be treated as a separate violation.</text>
						</clause></subparagraph><subparagraph id="H1001DD5D76414BEDAF59B8C2588551DC"><enum>(B)</enum><header>Adjustment for
			 inflation</header><text>Beginning on the date that the Consumer Price Index is
			 first published by the Bureau of Labor Statistics that is after 1 year after
			 the date of enactment of this Act, and each year thereafter, the amounts
			 specified in clauses (i) and (ii) of subparagraph (A) shall be increased by the
			 percentage increase in the Consumer Price Index published on that date from the
			 Consumer Price Index published the previous year.</text>
					</subparagraph><subparagraph id="H37E70ACDDC584DA1A9A17964BE922FF9"><enum>(C)</enum><header>Maximum total
			 liability</header><text display-inline="yes-display-inline">Notwithstanding the
			 number of actions which may be brought against a person under this subsection,
			 the maximum civil penalty for which any person may be liable under this
			 subsection shall not exceed—</text>
						<clause id="H0E074CCDEB664FF9B1C4596B0FB2A9A8"><enum>(i)</enum><text>$5,000,000 for
			 each violation of section 2; and</text>
						</clause><clause id="HE3A209A4342048D2AD201BDC12334AD2"><enum>(ii)</enum><text>$5,000,000 for
			 all violations of section 3 resulting from a single breach of security.</text>
						</clause></subparagraph></paragraph><paragraph id="H08D63C2A711D46908748CB7D59568953"><enum>(3)</enum><header>Intervention by
			 the FTC</header>
					<subparagraph id="H3E96E6B0FF4C4013924E10F3DBC7D09D"><enum>(A)</enum><header>Notice and
			 intervention</header><text>The State shall provide prior written notice of any
			 action under paragraph (1) to the Commission and provide the Commission with a
			 copy of its complaint, except in any case in which such prior notice is not
			 feasible, in which case the State shall serve such notice immediately upon
			 instituting such action. The Commission shall have the right—</text>
						<clause id="HD321C84EA2C24DF89A88FCFC7C35AAF5"><enum>(i)</enum><text>to
			 intervene in the action;</text>
						</clause><clause id="H33D5C91B38C941A8AC22219DCEE573DD"><enum>(ii)</enum><text>upon so
			 intervening, to be heard on all matters arising therein; and</text>
						</clause><clause id="HD8F2B9DEC96247BB948F8C5A87C6DE7D"><enum>(iii)</enum><text>to
			 file petitions for appeal.</text>
						</clause></subparagraph><subparagraph id="HA4B7D7320A824242BFEF680C161AFCC6"><enum>(B)</enum><header>Limitation on
			 state action while federal action is pending</header><text>If the Commission
			 has instituted a civil action for violation of this Act, no State attorney
			 general, or official or agency of a State, may bring an action under this
			 subsection during the pendency of that action against any defendant named in
			 the complaint of the Commission for any violation of this Act alleged in the
			 complaint.</text>
					</subparagraph></paragraph><paragraph id="HE438B53742F24231A11B413CB2128547"><enum>(4)</enum><header>Construction</header><text>For
			 purposes of bringing any civil action under paragraph (1), nothing in this Act
			 shall be construed to prevent an attorney general of a State from exercising
			 the powers conferred on the attorney general by the laws of that State
			 to—</text>
					<subparagraph id="H100DFC919B56436A8F6B98CE9D81BDE2"><enum>(A)</enum><text>conduct
			 investigations;</text>
					</subparagraph><subparagraph id="HEC3CCC55D15F4ACF94560A389853097F"><enum>(B)</enum><text>administer oaths
			 or affirmations; or</text>
					</subparagraph><subparagraph id="H20B7A9A0F2D344D9AE5296ED067AD86A"><enum>(C)</enum><text>compel the
			 attendance of witnesses or the production of documentary and other
			 evidence.</text>
					</subparagraph></paragraph></subsection><subsection id="HB71309F3244B4D59B4E04ACA3F246E64"><enum>(d)</enum><header>Affirmative
			 Defense for a Violation of section 3</header>
				<paragraph id="H8D33511EC909462D83CAC956A0D59743"><enum>(1)</enum><header>In
			 general</header><text display-inline="yes-display-inline">It shall be an
			 affirmative defense to an enforcement action brought under subsection (b), or a
			 civil action brought under subsection (c), based on a violation of section 3,
			 that all of the personal information contained in the data in electronic form
			 that was acquired or accessed as a result of a breach of security of the
			 defendant is public record information that is lawfully made available to the
			 general public from Federal, State, or local government records and was
			 acquired by the defendant from such records.</text>
				</paragraph><paragraph commented="no" id="H113AB2E2E4E547F3A0A9A69834AC4F0D"><enum>(2)</enum><header>No effect on
			 other requirements</header><text>Nothing in this subsection shall be construed
			 to exempt any person from the requirement to notify the Commission of a breach
			 of security as required under section 3(a).</text>
				</paragraph></subsection></section><section id="HECE5BC9776124D3F82171A47C0AC54AC"><enum>5.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act, the following definitions
			 apply:</text>
			<paragraph id="HF987F6C8FF9443D199C86B66C6CE2A30"><enum>(1)</enum><header>Breach of
			 security</header><text>The term <term>breach of security</term> means
			 unauthorized access to or acquisition of data in electronic form containing
			 personal information.</text>
			</paragraph><paragraph id="HCF114B297A35471281215B18D48F0E4A"><enum>(2)</enum><header>Commission</header><text>The
			 term <term>Commission</term> means the Federal Trade Commission.</text>
			</paragraph><paragraph id="HDBFC5813F56D4F91B281AA7BBF32A0E2"><enum>(3)</enum><header>Data in
			 electronic form</header><text>The term <term>data in electronic form</term>
			 means any data stored electronically or digitally on any computer system or
			 other database and includes recordable tapes and other mass storage
			 devices.</text>
			</paragraph><paragraph id="H4C866445A11741758F9A819B56734932"><enum>(4)</enum><header>Encryption</header><text>The
			 term <term>encryption</term> means the protection of data in electronic form in
			 storage or in transit using an encryption technology that has been adopted by
			 an established standards setting body which renders such data indecipherable in
			 the absence of associated cryptographic keys necessary to enable decryption of
			 such data. Such encryption must include appropriate management and safeguards
			 of such keys to protect the integrity of the encryption.</text>
			</paragraph><paragraph id="HC713CB7E507744F3B1BAD59C3A0347AC"><enum>(5)</enum><header>Identity
			 theft</header><text>The term <term>identity theft</term> means the unauthorized
			 use of another person’s personal information for the purpose of engaging in
			 commercial transactions under the name of such other person.</text>
			</paragraph><paragraph id="H3987C08544BA4F7F94EE57BFCB547FB4"><enum>(6)</enum><header>Information
			 broker</header><text>The term <term>information broker</term>—</text>
				<subparagraph id="HCBD0D6F3C9F54B12AD894AAF97C794D6"><enum>(A)</enum><text>means a commercial
			 entity whose business is to collect, assemble, or maintain personal information
			 concerning individuals who are not current or former customers of such entity
			 in order to sell such information or provide access to such information to any
			 nonaffiliated third party in exchange for consideration, whether such
			 collection, assembly, or maintenance of personal information is performed by
			 the information broker directly, or by contract or subcontract with any other
			 entity; and</text>
				</subparagraph><subparagraph commented="no" id="H7AD5E0CD6D264A63BF1429C4EDA0085C"><enum>(B)</enum><text display-inline="yes-display-inline">does not include a commercial entity to the
			 extent that such entity processes information collected by and received from a
			 nonaffiliated third party concerning individuals who are current or former
			 customers or employees of such third party to enable such third party to (1)
			 provide benefits for its employees or (2) directly transact business with its
			 customers.</text>
				</subparagraph></paragraph><paragraph id="H352FE530A0934C8C82B7DCC98B8D6ACC"><enum>(7)</enum><header>Personal
			 information</header>
				<subparagraph id="H370E516474A240B186E55A4A01E425D5"><enum>(A)</enum><header>Definition</header><text>The
			 term <term>personal information</term> means an individual’s first name or
			 initial and last name, or address, or phone number, in combination with any 1
			 or more of the following data elements for that individual:</text>
					<clause id="H99E0376E41B0497C94C5D3EEC45696E2"><enum>(i)</enum><text>Social Security
			 number.</text>
					</clause><clause id="HFF9C23D015E44132B81A6BD6EE6B346D"><enum>(ii)</enum><text>Driver’s license
			 number, passport number, military identification number, or other similar
			 number issued on a government document used to verify identity.</text>
					</clause><clause id="HA319E7F3E73E4517B5BA9901DF6AE9AE"><enum>(iii)</enum><text>Financial
			 account number, or credit or debit card number, and any required security code,
			 access code, or password that is necessary to permit access to an individual’s
			 financial account.</text>
					</clause></subparagraph><subparagraph id="HA683712A6EF845F2BE18A5DC31ACE1F3"><enum>(B)</enum><header>Modified
			 definition by rulemaking</header><text display-inline="yes-display-inline">The
			 Commission may, by rule promulgated under section 553 of title 5, United States
			 Code, modify the definition of <quote>personal information</quote> under
			 subparagraph (A)—</text>
					<clause id="HF0A95ED7447F46D3BBFC1CCA63581EFC"><enum>(i)</enum><text display-inline="yes-display-inline">for the purpose of section 2 to the extent
			 that such modification will not unreasonably impede interstate commerce, and
			 will accomplish the purposes of this Act; or</text>
					</clause><clause id="HB46940A6F69849718D74CEE75C3FC0A2"><enum>(ii)</enum><text>for
			 the purpose of section 3, to the extent that such modification is necessary to
			 accommodate changes in technology or practices, will not unreasonably impede
			 interstate commerce, and will accomplish the purposes of this Act.</text>
					</clause></subparagraph></paragraph><paragraph id="H7EB472A9FABE4C4D9367FD6DC4417CE0"><enum>(8)</enum><header>Public record
			 information</header><text>The term <term>public record information</term> means
			 information about an individual which has been obtained originally from records
			 of a Federal, State, or local government entity that are available for public
			 inspection.</text>
			</paragraph><paragraph id="H2CAC374B97D841DCB2F9A79B7887B0B8"><enum>(9)</enum><header>Non-public
			 information</header><text>The term <term>non-public information</term> means
			 information about an individual that is of a private nature and neither
			 available to the general public nor obtained from a public record.</text>
			</paragraph><paragraph id="HACC1C36F004D4403A0DCAA519D1D5346"><enum>(10)</enum><header>Service
			 provider</header><text display-inline="yes-display-inline">The term
			 <term>service provider</term> means an entity that provides to a user
			 transmission, routing, intermediate and transient storage, or connections to
			 its system or network, for electronic communications, between or among points
			 specified by such user of material of the user’s choosing, without modification
			 to the content of the material as sent or received. Any such entity shall be
			 treated as a service provider under this Act only to the extent that it is
			 engaged in the provision of such transmission, routing, intermediate and
			 transient storage or connections.</text>
			</paragraph></section><section id="H86A3C2B8BA6E4F96AE90359A6B92A562"><enum>6.</enum><header>Effect on other
			 laws</header>
			<subsection id="H9FA18A39E043427E88AC64E321AE3A61"><enum>(a)</enum><header>Preemption of
			 State Information Security Laws</header><text>This Act supersedes any provision
			 of a statute, regulation, or rule of a State or political subdivision of a
			 State, with respect to those entities covered by the regulations issued
			 pursuant to this Act, that expressly—</text>
				<paragraph id="H152C6562F43940D99A49588B4BFF9988"><enum>(1)</enum><text>requires
			 information security practices and treatment of data containing personal
			 information similar to any of those required under section 2; and</text>
				</paragraph><paragraph id="H126FE926B80245F585B699EBF6211821"><enum>(2)</enum><text>requires
			 notification to individuals of a breach of security resulting in unauthorized
			 access to or acquisition of data in electronic form containing personal
			 information.</text>
				</paragraph></subsection><subsection id="H973E16EBF11A4467994939FBFBAD6C2F"><enum>(b)</enum><header>Additional
			 Preemption</header>
				<paragraph id="H2077C836E40A41B4A8E509FBE2DE37A1"><enum>(1)</enum><header>In
			 general</header><text>No person other than a person specified in section 4(c)
			 may bring a civil action under the laws of any State if such action is premised
			 in whole or in part upon the defendant violating any provision of this
			 Act.</text>
				</paragraph><paragraph id="H4066ACA5A89A44F2A875FB6D3F8DB234"><enum>(2)</enum><header>Protection of
			 consumer protection laws</header><text>This subsection shall not be construed
			 to limit the enforcement of any State consumer protection law by an attorney
			 general of a State.</text>
				</paragraph></subsection><subsection id="HEA73C719010F49DBA40C80A85EB6C692"><enum>(c)</enum><header>Protection of
			 Certain State Laws</header><text>This Act shall not be construed to preempt the
			 applicability of—</text>
				<paragraph id="H829CAFD12C784E6FAB45587A9EEE4691"><enum>(1)</enum><text>State trespass,
			 contract, or tort law; or</text>
				</paragraph><paragraph id="HE6B033A5F5C64962A4BE02961EC33645"><enum>(2)</enum><text>other State laws
			 to the extent that those laws relate to acts of fraud.</text>
				</paragraph></subsection><subsection id="HB712D9D907DD40E5AE0FA393DFF85AB6"><enum>(d)</enum><header>Preservation of
			 FTC Authority</header><text>Nothing in this Act may be construed in any way to
			 limit or affect the Commission’s authority under any other provision of
			 law.</text>
			</subsection></section><section commented="no" id="H3D4847DDCBE5483AAC38F1157EE30DB7"><enum>7.</enum><header>Effective
			 date</header><text display-inline="no-display-inline">This Act shall take
			 effect 1 year after the date of enactment of this Act.</text>
		</section><section id="H10CB2FBFC32143E2B2521779EBDA9A15"><enum>8.</enum><header>Authorization of
			 appropriations</header><text display-inline="no-display-inline">There is
			 authorized to be appropriated to the Commission $1,000,000 for each of fiscal
			 years 2011 through 2016 to carry out this Act.</text>
		</section></legis-body>
</bill>
