<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" bill-type="olc" dms-id="H0C2675E3172C4B1BAD6FDA4DD5236DF9" public-private="public">
	<form>
		<distribution-code display="yes">I</distribution-code>
		<congress>112th CONGRESS</congress>
		<session>1st Session</session>
		<legis-num>H. R. 654</legis-num>
		<current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber>
		<action>
			<action-date date="20110211">February 11, 2011</action-date>
			<action-desc><sponsor name-id="S001175">Ms. Speier</sponsor> (for
			 herself, <cosponsor name-id="H000324">Mr. Hastings of Florida</cosponsor>, and
			 <cosponsor name-id="F000116">Mr. Filner</cosponsor>) introduced the following
			 bill; which was referred to the <committee-name committee-id="HIF00">Committee
			 on Energy and Commerce</committee-name></action-desc>
		</action>
		<legis-type>A BILL</legis-type>
		<official-title>To direct the Federal Trade Commission to prescribe
		  regulations regarding the collection and use of information obtained by
		  tracking the Internet activity of an individual, and for other
		  purposes.</official-title>
	</form>
	<legis-body id="H6E19C73E6E484ABF89F48F4422A0E926" style="OLC">
		<section id="H3B3261F3E160422C86D86C0298473F99" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the
			 <quote><short-title>Do Not Track Me Online
			 Act</short-title></quote>.</text>
		</section><section id="HF27E308AFB394E2FA006F426050376D7" section-type="subsequent-section"><enum>2.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act:</text>
			<paragraph id="H85AFB456C4F04EFDACBE4EA315F21F3F"><enum>(1)</enum><header>Commission</header><text>The
			 term <term>Commission</term> means the Federal Trade Commission.</text>
			</paragraph><paragraph commented="no" id="H63176098DB304862B9F598088B7CE42F"><enum>(2)</enum><header>Covered
			 entity</header><text>The term <term>covered entity</term> means a person
			 engaged in interstate commerce that collects or stores online data containing
			 covered information. Such term does not include—</text>
				<subparagraph commented="no" id="HBF49589834AF48C3998FA78A4D430E6D"><enum>(A)</enum><text>the Federal
			 Government or any instrumentality of the Federal Government, nor the government
			 of any State or political subdivision of a State; or</text>
				</subparagraph><subparagraph commented="no" id="HE92C4C48B8F44751A8ADC80721BB7F48"><enum>(B)</enum><text>any person that
			 can demonstrate that such person—</text>
					<clause id="H901D766BD9D14A8292F4CBFC2DD16992"><enum>(i)</enum><text display-inline="yes-display-inline">stores covered information from or about
			 fewer than 15,000 individuals;</text>
					</clause><clause id="H2E8DEA31D15C444DA99BCF4165CDDF41"><enum>(ii)</enum><text>collects covered
			 information from or about fewer than 10,000 individuals during any 12-month
			 period;</text>
					</clause><clause id="H158E7A8AE35A47B3954C0B83148AB166"><enum>(iii)</enum><text>does not collect
			 or store sensitive information; and</text>
					</clause><clause id="HA88051AE25A54A77811FF07A1F0F87BC"><enum>(iv)</enum><text>does not use
			 covered information to study, monitor, or analyze the behavior of individuals
			 as the person’s primary business.</text>
					</clause></subparagraph></paragraph><paragraph commented="no" id="HD5FED16C6D8E45AD95F9A5D1B3A5A8BA"><enum>(3)</enum><header>Covered
			 information</header>
				<subparagraph commented="no" id="H26F9C85D148A40879EBAA92DDCB33668"><enum>(A)</enum><header>In
			 general</header><text>The term <term>covered information</term> means, with
			 respect to an individual, any of the following that is transmitted
			 online:</text>
					<clause commented="no" id="HEF07EBDFCF0145F9BAE508C6AF259D3B"><enum>(i)</enum><text>The online
			 activity of the individual, including—</text>
						<subclause commented="no" id="H66FC1A2AD14F4F3884620004BE3D301F"><enum>(I)</enum><text>the web sites and
			 content from such web sites accessed;</text>
						</subclause><subclause commented="no" id="HA33F50ED93FB4C0E945980AC0B74CB20"><enum>(II)</enum><text>the date and hour
			 of online access;</text>
						</subclause><subclause commented="no" id="HC07FE1927A864FDCB9866F658E53C681"><enum>(III)</enum><text>the computer and
			 geolocation from which online information was accessed; and</text>
						</subclause><subclause commented="no" id="H4D541E18F01648BCB4A15DC06820D93A"><enum>(IV)</enum><text display-inline="yes-display-inline">the means by which online information was
			 accessed, such as a device, browser, or application.</text>
						</subclause></clause><clause commented="no" id="H32208E101BCD4E91BF803C93F8691D8C"><enum>(ii)</enum><text display-inline="yes-display-inline">Any unique or substantially unique
			 identifier, such as a customer number or Internet protocol address.</text>
					</clause><clause commented="no" id="H6B2377B6D7D54FA497E3DB361ADF7456"><enum>(iii)</enum><text display-inline="yes-display-inline">Personal information such as—</text>
						<subclause commented="no" id="H184A2147908E4F30993A3F90FDEE11C3"><enum>(I)</enum><text>the name;</text>
						</subclause><subclause commented="no" id="H91F0B23ED3BB427D81BFC329B42BD278"><enum>(II)</enum><text>a postal address
			 or other location;</text>
						</subclause><subclause commented="no" id="H83056777CC7D465A9B2126D19D73DBC4"><enum>(III)</enum><text>an email address
			 or other user name;</text>
						</subclause><subclause commented="no" id="H549AE59BD08F4FD695D36127DEDA612C"><enum>(IV)</enum><text>a telephone or
			 fax number;</text>
						</subclause><subclause commented="no" id="H437FC533873141F2B20C0EFD913C4A2B"><enum>(V)</enum><text>a
			 government-issued identification number, such as a tax identification number, a
			 passport number, or a driver’s license number; or</text>
						</subclause><subclause commented="no" id="HE11D6EEE196F4C1D881263DEECBF3FDC"><enum>(VI)</enum><text>a financial
			 account number, or credit card or debit card number, or any required security
			 code, access code, or password that is necessary to permit access to an
			 individual’s financial account.</text>
						</subclause></clause></subparagraph><subparagraph commented="no" id="H9667DBAAD3B74FD391134A9FFC5DA7DC"><enum>(B)</enum><header>Exclusion</header><text>Such
			 term shall not include—</text>
					<clause commented="no" id="H018DE6708E054837B635F720C8084F3A"><enum>(i)</enum><text>the title,
			 business address, business email address, business telephone number, or
			 business fax number associated with an individual’s status as an employee of an
			 organization, or an individual’s name when collected, stored, used, or
			 disclosed in connection with such employment status; or</text>
					</clause><clause commented="no" id="H3E1E094C936C47B79A946C36AA0B9E84"><enum>(ii)</enum><text>any information
			 collected from or about an employee by an employer, prospective employer, or
			 former employer that directly relates to the employee-employer
			 relationship.</text>
					</clause></subparagraph></paragraph><paragraph display-inline="no-display-inline" id="HEA1A55DC8C9345EC8E4520475AEB1646"><enum>(4)</enum><header>Sensitive
			 information</header>
				<subparagraph id="H38A718ED8D194211AC4CCA0D34E70486"><enum>(A)</enum><header>Definition</header><text>The
			 term <term>sensitive information</term> means—</text>
					<clause id="H708917871C9D4055A408431416CCEB84"><enum>(i)</enum><text>any
			 information that is associated with covered information of an individual and
			 relates directly to that individual’s—</text>
						<subclause id="HF7714784A4674491BCB55191916AC35C"><enum>(I)</enum><text>medical history,
			 physical or mental health, or the provision of health care to the
			 individual;</text>
						</subclause><subclause id="H5DC616A60EF34F89947731ECED0D0ADC"><enum>(II)</enum><text>race or
			 ethnicity;</text>
						</subclause><subclause id="H6DF1A3C92923484EB2B3B29B566E279E"><enum>(III)</enum><text>religious
			 beliefs and affiliation;</text>
						</subclause><subclause id="H5F905EC4834C40A8ADABE6B53861F433"><enum>(IV)</enum><text>sexual
			 orientation or sexual behavior;</text>
						</subclause><subclause id="HFF0AD04E402341B9A3A330D0C9993DAC"><enum>(V)</enum><text>income, assets,
			 liabilities, or financial records, and other financial information associated
			 with a financial account, including balances and other financial information,
			 except when financial account information is provided by the individual and is
			 used only to process an authorized credit or debit to the account; or</text>
						</subclause><subclause id="H65B2EE88D0C446EB8DD08C282BD8CF29"><enum>(VI)</enum><text>precise
			 geolocation information and any information about the individual’s activities
			 and relationships associated with such geolocation; or</text>
						</subclause></clause><clause id="H2D4BBDDEE9974FBFA54EBB103F631FA0"><enum>(ii)</enum><text>an
			 individual’s—</text>
						<subclause id="HA4685F36A7E54FD898615766EB2AF5C0"><enum>(I)</enum><text>unique biometric
			 data, including a fingerprint or retina scan; or</text>
						</subclause><subclause id="H0B455FAD20244420ACF49073F2EC874D"><enum>(II)</enum><text>Social Security
			 number.</text>
						</subclause></clause></subparagraph><subparagraph id="H149D3DCC61BD415C882ED3817E5EB025"><enum>(B)</enum><header>Modified
			 definition by rulemaking</header><text>The Commission may, by regulations
			 promulgated under section 553 of title 5, United States Code, modify the scope
			 or application of the definition of <quote>sensitive information</quote> for
			 purposes of this Act. In promulgating such regulations, the Commission shall
			 consider—</text>
					<clause id="HA55C40A525B14C86BFFE6C506923960F"><enum>(i)</enum><text>the
			 purposes of the collection of the information and the context of the use of the
			 information;</text>
					</clause><clause id="H4CE29823B6314354AF3B641BE86694FE"><enum>(ii)</enum><text>how
			 easily the information can be used to identify a specific individual;</text>
					</clause><clause id="HCFFA79C295C344518D271733B6123095"><enum>(iii)</enum><text>the nature and
			 extent of authorized access to the information;</text>
					</clause><clause id="H2087826A8A354F1FB07B52C7551CE4F4"><enum>(iv)</enum><text>an
			 individual’s reasonable expectations under the circumstances; and</text>
					</clause><clause id="H8A2312A7694842D78FDEFFAD8E3C9C7A"><enum>(v)</enum><text>adverse effects
			 that may be experienced by an individual if the information is disclosed to an
			 unauthorized person.</text>
					</clause></subparagraph></paragraph></section><section id="HF1E5484E5CCA4B4E9DFD506238C995E1"><enum>3.</enum><header>Regulations
			 requiring <quote>do-not-track</quote> mechanism</header>
			<subsection commented="no" id="HF87D745E76124186B6C6DFAD630AE953"><enum>(a)</enum><header>FTC
			 Rulemaking</header><text display-inline="yes-display-inline">Not later than 18
			 months after the date of enactment of this Act, the Commission shall promulgate
			 regulations under section 553 of title 5, United States Code, that establish
			 standards for the required use of an online opt-out mechanism to allow a
			 consumer to effectively and easily prohibit the collection or use of any
			 covered information and to require a covered entity to respect the choice of
			 such consumer to opt-out of such collection or use. Regulations prescribed
			 pursuant to this subsection shall be treated as regulations defining unfair and
			 deceptive acts or practices affecting commerce prescribed under section
			 18(a)(1)(B) of the Federal Trade Commission Act (15 U.S.C. 57a(a)(1)(B)).</text>
			</subsection><subsection commented="no" id="H937142B2B3444FA685EB972CB9997B37"><enum>(b)</enum><header>Requirements To
			 be included in regulations</header><text display-inline="yes-display-inline">The regulations prescribed under subsection
			 (a)—</text>
				<paragraph commented="no" id="HBE91F1C71BC14B33AF42D42BFC472BFC"><enum>(1)</enum><text>shall include a
			 requirement for a covered entity to disclose, in a manner that is easily
			 accessible to a consumer, information on the collection of information
			 practices of such entity, how such entity uses or discloses such information,
			 and the names of the persons to whom such entity would disclose such
			 information; and</text>
				</paragraph><paragraph commented="no" id="HD101444558DC4B28BEA5821512B49471"><enum>(2)</enum><text>shall prohibit the
			 collection or use of covered information by a covered entity for which a
			 consumer has opted-out of such collection or use, unless the consumer changes
			 their opt-out preference to allow the collection or use of such
			 information.</text>
				</paragraph></subsection><subsection id="HE37116BBE7E84E16A306E1DE063FFEAF"><enum>(c)</enum><header>Additional
			 regulatory authority</header><text>The regulations prescribed under subsection
			 (a)—</text>
				<paragraph commented="no" id="H3E78688455E94F6CA08395FAE049D65F"><enum>(1)</enum><text>may include a
			 requirement that a covered entity provide a consumer with a means to access the
			 covered information of such consumer and the data retention and security
			 policies of the covered entity in a format that is clear and easy to
			 understand; and</text>
				</paragraph><paragraph commented="no" id="HFD6896F373DE46A98B6D4C883CC186BC"><enum>(2)</enum><text>may include a
			 requirement that some or all of the regulations apply with regard to the
			 collection and use of covered information, regardless of the source.</text>
				</paragraph></subsection><subsection id="HFDB93921B83B44A988952A34D46EA2E5"><enum>(d)</enum><header>Exemptive
			 authority</header><text>The Commission may exempt from some or all of the
			 regulations required by this section certain commonly accepted commercial
			 practices, including the following:</text>
				<paragraph commented="no" id="H3E0D8E79E3C3436D9A5E516E11708EF3"><enum>(1)</enum><text>Providing,
			 operating, or improving a product or service used, requested, or authorized by
			 an individual, including the ongoing provision of customer service and
			 support.</text>
				</paragraph><paragraph commented="no" id="H3B9C23C633794539995B15B46FB718D4"><enum>(2)</enum><text>Analyzing data
			 related to use of the product or service for purposes of improving the
			 products, services, or operations.</text>
				</paragraph><paragraph commented="no" id="H8B83A537F72E4C61955068EA83C827AD"><enum>(3)</enum><text>Basic business
			 functions such as accounting, inventory and supply chain management, quality
			 assurance, and internal auditing.</text>
				</paragraph><paragraph commented="no" id="H0E4A032CC8054BEFAD099299251F2B81"><enum>(4)</enum><text>Protecting or
			 defending rights or property, including intellectual property, against actual
			 or potential security threats, fraud, theft, unauthorized transactions, or
			 other illegal activities.</text>
				</paragraph><paragraph commented="no" id="H9F5BB39B1C8047D7A713167E26B5408C"><enum>(5)</enum><text>Preventing
			 imminent danger to the personal safety of an individual or group of
			 individuals.</text>
				</paragraph><paragraph commented="no" id="H8F698560F3774FCAACE737D43C13534B"><enum>(6)</enum><text>Complying with a
			 Federal, State, or local law, rule, or other applicable legal requirement,
			 including disclosures pursuant to a court order, subpoena, summons, or other
			 properly executed compulsory process.</text>
				</paragraph><paragraph commented="no" id="HF1CAE969DA874C60AECA9BD84D924B95"><enum>(7)</enum><text>Any other category
			 of operational use specified by the Commission by regulation that is consistent
			 with the purposes of this Act.</text>
				</paragraph></subsection></section><section id="H75B3A656917B4ECEBCC4226BDC2970C5"><enum>4.</enum><header>Additional FTC
			 authority</header><text display-inline="no-display-inline">In implementing and
			 enforcing the regulations prescribed under section 3, the Commission
			 shall—</text>
			<paragraph id="HD81EDD1B3799435E9327D8C2EF874105"><enum>(1)</enum><text display-inline="yes-display-inline">have the authority to prescribe such
			 regulations as may be necessary to carry out the purposes of this Act in
			 accordance with section 553 of title 5, United States Code;</text>
			</paragraph><paragraph id="HD90639840125436FB1EAF0B6A4357004"><enum>(2)</enum><text display-inline="yes-display-inline">monitor for risks to consumers in the
			 provision of products and services, including the development of new hardware
			 or software designed to limit, restrict, or circumvent the ability of a
			 consumer to control the collection and use of the covered information of such
			 consumer, as set forth in the regulations prescribed under section 3;</text>
			</paragraph><paragraph id="H0D0F3997D4434969A07323FEB1AAC285"><enum>(3)</enum><text>perform random
			 audits of covered entities, including Internet browsing for investigative
			 purposes, to ensure compliance with the regulations issued under section
			 3;</text>
			</paragraph><paragraph id="H6B5B7902D72943E7BFA1C52EE195DBA7"><enum>(4)</enum><text>assess consumers’
			 understanding of the risks posed by the tracking of a consumer’s Internet
			 activity and the collection and use of covered information relating to a
			 consumer; and</text>
			</paragraph><paragraph id="H1E7A16896B5948C19F306CBA79618137"><enum>(5)</enum><text display-inline="yes-display-inline">make available to the public at least 1
			 report of significant findings of the monitoring required by this section in
			 each calendar year after the date on which final regulations are issued
			 pursuant to section 3(a).</text>
			</paragraph></section><section id="H5389405323AA46BDB2C1C37C9F895CDE"><enum>5.</enum><header>Enforcement by
			 State Attorneys General</header>
			<subsection id="H78D95BDE04684667AA7164CD42843C9B"><enum>(a)</enum><header>Civil
			 action</header><text>In any case in which the Attorney General of a State, or
			 an official or agency of a State, has reason to believe that an interest of the
			 residents of that State has been or is threatened or adversely affected by any
			 person who violates the regulations prescribed under section 3, the attorney
			 general, official, or agency of the State, as parens patriae, may bring a civil
			 action on behalf of the residents of the State in an appropriate district court
			 of the United States—</text>
				<paragraph id="HE0564ED7F6A54E078D891A279084C15A"><enum>(1)</enum><text display-inline="yes-display-inline">to enjoin further violation of the
			 regulations prescribed under section 3 by the defendant;</text>
				</paragraph><paragraph id="H9018ABAE03CE44DDA2D7DBEFB579170F"><enum>(2)</enum><text display-inline="yes-display-inline">to compel compliance with the regulations
			 prescribed under section 3; or</text>
				</paragraph><paragraph id="H08B5CB9430CC4F04A2762CE01509816E"><enum>(3)</enum><text display-inline="yes-display-inline">to obtain civil penalties for violations of
			 the regulations prescribed under section 3 in the amount determined under
			 subsection (b).</text>
				</paragraph></subsection><subsection display-inline="no-display-inline" id="H204B509247214CA8B3B25B8DE579FF79"><enum>(b)</enum><header>Civil
			 penalties</header>
				<paragraph id="HC1EFA63AC8D84F12AE1BD0855E1BB23C"><enum>(1)</enum><header>Calculation</header><text display-inline="yes-display-inline">For purposes of calculating the civil
			 penalties that may be obtained under subsection (a)(3), the amount determined
			 under this paragraph is the amount calculated by multiplying the number of days
			 that a covered entity is not in compliance with the regulations prescribed
			 under section 3 by an amount not to exceed $11,000.</text>
				</paragraph><paragraph id="H382A472CF28D43AEA5CAC2D1B0F1BFBF"><enum>(2)</enum><header>Adjustment for
			 inflation</header><text>Beginning on the date that the Consumer Price Index for
			 All Urban Consumers is first published by the Bureau of Labor Statistics that
			 is after 1 year after the date of enactment of this Act, and each year
			 thereafter, the amount specified in paragraph (1) shall be increased by the
			 percentage increase in the Consumer Price Index published on that date from the
			 Consumer Price Index published the previous year.</text>
				</paragraph><paragraph id="H37B9803CCED04D84BF05C536D62BED1F"><enum>(3)</enum><header>Maximum total
			 liability</header><text display-inline="yes-display-inline">Notwithstanding the
			 number of actions which may be brought against a person under this section the
			 maximum civil penalty for which any person may be liable under this section
			 shall not exceed $5,000,000 for any related series of violations of the
			 regulations prescribed under section 3.</text>
				</paragraph></subsection><subsection id="H5EA51030C156468886F130D26DADF5B1"><enum>(c)</enum><header>Intervention by
			 the FTC</header>
				<paragraph id="H9124E5D5306648799550EFE3031C61F9"><enum>(1)</enum><header>Notice and
			 intervention</header><text>The State shall provide prior written notice of any
			 action under subsection (a) to the Commission and provide the Commission with a
			 copy of its complaint, except in any case in which such prior notice is not
			 feasible, in which case the State shall serve such notice immediately upon
			 instituting such action. The Commission shall have the right—</text>
					<subparagraph id="HDDA5F91C40B641218D4FC4F73290A010"><enum>(A)</enum><text>to intervene in
			 the action;</text>
					</subparagraph><subparagraph id="H776D3B2A7B964E25AA3F41C8C20AE884"><enum>(B)</enum><text>upon so
			 intervening, to be heard on all matters arising therein; and</text>
					</subparagraph><subparagraph id="H49709A8B3A7E4A1ABEC0BD6785F62DCE"><enum>(C)</enum><text>to file petitions
			 of appeal.</text>
					</subparagraph></paragraph><paragraph id="H0B753BC69EB248EA9F00610EC6E6E6A0"><enum>(2)</enum><header>Limitation on
			 State action while Federal action is pending</header><text display-inline="yes-display-inline">If the Commission has instituted a civil
			 action for violation of the regulations prescribed under section 3, no attorney
			 general of a State, or official, or agency of a State, may bring an action
			 under this section during the pendency of that action against any defendant
			 named in the complaint of the Commission for any violation of the regulations
			 issued under this Act alleged in the complaint.</text>
				</paragraph></subsection></section><section id="H266BA94DF0B148829D4F80D253DCFFF3"><enum>6.</enum><header>Effect on other
			 laws</header>
			<subsection commented="no" id="H4383C5F6977942269C749C7B4F137215"><enum>(a)</enum><header>Other authority
			 of Federal Trade Commission</header><text display-inline="yes-display-inline">Nothing in this Act shall be construed to
			 limit or affect in any way the Commission’s authority to bring enforcement
			 actions or take any other measure under the Federal Trade Commission Act (15
			 U.S.C. 41 et seq.) or any other provision of law.</text>
			</subsection><subsection commented="no" id="H25997403899241EF98FAA88033E6169F"><enum>(b)</enum><header>State
			 law</header><text display-inline="yes-display-inline">The regulations
			 prescribed under section 3 shall not annul, alter, affect, or exempt any person
			 subject to the provisions of such regulations from complying with the law of
			 any State except to the extent that such law is inconsistent with any provision
			 of such regulations, and then only to the extent of the inconsistency. For
			 purposes of this subsection, a State statute, regulation, order, or
			 interpretation is not inconsistent with the provisions of the regulations
			 prescribed under section 3 if the protection such statute, regulation, order,
			 or interpretation affords any person is greater than the protection provided
			 under the regulations prescribed under section 3.</text>
			</subsection></section></legis-body>
</bill>
