<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Reported-in-Senate" public-private="public">
	<form>
		<distribution-code display="yes">II</distribution-code>
		<calendar>Calendar No. 310</calendar>
		<congress>112th CONGRESS</congress>
		<session>2d Session</session>
		<legis-num>S. 1408</legis-num>
		<current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber>
		<action>
			<action-date date="20110722">July 22, 2011</action-date>
			<action-desc><sponsor name-id="S221">Mrs. Feinstein</sponsor>
			 introduced the following bill; which was read twice and referred to the
			 <committee-name added-display-style="italic" committee-id="SSJU00" deleted-display-style="strikethrough">Committee on the
			 Judiciary</committee-name></action-desc>
		</action>
		<action stage="Reported-in-Senate">
			<action-date>February 6, 2012</action-date>
			<action-desc>Reported by <sponsor name-id="S057">Mr. Leahy</sponsor>,
			 with an amendment</action-desc>
			<action-instruction>Strike out all after the enacting clause and insert
			 the part printed in italic</action-instruction>
		</action>
		<legis-type>A BILL</legis-type>
		<official-title>To require Federal agencies, and persons engaged in
		  interstate commerce, in possession of data containing sensitive personally
		  identifiable information, to disclose any breach of such
		  information.</official-title>
	</form>
	<legis-body>
		<section changed="deleted" committee-id="SSJU00" id="id22B8E40CF2434B7194724E1C1E5DEA5E" reported-display-style="strikethrough" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the
			 <quote><short-title>Data Breach Notification Act of
			 2011</short-title></quote>.</text>
		</section><section changed="deleted" committee-id="SSJU00" id="idEA93056FEEEF4EB08F0480B3B354E911" reported-display-style="strikethrough"><enum>2.</enum><header>Notice to
			 individuals</header>
			<subsection id="idD2E262EA82BC4F0CB67EF423C08FB4B8"><enum>(a)</enum><header>In
			 General</header><text>Any agency, or business entity engaged in interstate
			 commerce, that uses, accesses, transmits, stores, disposes of or collects
			 sensitive personally identifiable information shall, following the discovery of
			 a security breach of such information notify any resident of the United States
			 whose sensitive personally identifiable information has been, or is reasonably
			 believed to have been, accessed, or acquired.</text>
			</subsection><subsection id="id46C95A116808498192AB23B231FDD442"><enum>(b)</enum><header>Obligation of
			 Owner or Licensee</header>
				<paragraph id="id7C158BD1D84149B39B358196C6F498AD"><enum>(1)</enum><header>Notice to owner
			 or licensee</header><text>Any agency, or business entity engaged in interstate
			 commerce, that uses, accesses, transmits, stores, disposes of, or collects
			 sensitive personally identifiable information that the agency or business
			 entity does not own or license shall notify the owner or licensee of the
			 information following the discovery of a security breach involving such
			 information.</text>
				</paragraph><paragraph id="idC5AA8C6F57064092B472B0BE10EC8843"><enum>(2)</enum><header>Notice by owner,
			 licensee or other designated third party</header><text>Nothing in this Act
			 shall prevent or abrogate an agreement between an agency or business entity
			 required to give notice under this section and a designated third party,
			 including an owner or licensee of the sensitive personally identifiable
			 information subject to the security breach, to provide the notifications
			 required under subsection (a).</text>
				</paragraph><paragraph id="idAE334E583E4246E3A278FF6189635AFD"><enum>(3)</enum><header>Business entity
			 relieved from giving notice</header><text>A business entity obligated to give
			 notice under subsection (a) shall be relieved of such obligation if an owner or
			 licensee of the sensitive personally identifiable information subject to the
			 security breach, or other designated third party, provides such
			 notification.</text>
				</paragraph></subsection><subsection id="id0C1DA7F894F74379B2285A11B2540FC4"><enum>(c)</enum><header>Timeliness of
			 Notification</header>
				<paragraph id="idAB5D79837B55401188D0A5F02F4022F3"><enum>(1)</enum><header>In
			 general</header><text>All notifications required under this section shall be
			 made without unreasonable delay following the discovery by the agency or
			 business entity of a security breach.</text>
				</paragraph><paragraph id="id49556A8B1A604198A5763BB9F6BB17A0"><enum>(2)</enum><header>Reasonable
			 delay</header><text>Reasonable delay under this subsection may include any time
			 necessary to determine the scope of the security breach, prevent further
			 disclosures, and restore the reasonable integrity of the data system and
			 provide notice to law enforcement when required.</text>
				</paragraph><paragraph id="idB9A74C27A9AD4EB3987BFF6779B26A40"><enum>(3)</enum><header>Burden of
			 proof</header><text>The agency, business entity, owner, or licensee required to
			 provide notification under this section shall have the burden of demonstrating
			 that all notifications were made as required under this Act, including evidence
			 demonstrating the reasons for any delay.</text>
				</paragraph></subsection><subsection id="id0B724AAAA5F34861AF1541E650CF0F56"><enum>(d)</enum><header>Delay of
			 Notification Authorized for Law Enforcement Purposes</header>
				<paragraph id="id4550927DB99248D0A39AA06B25426118"><enum>(1)</enum><header>In
			 general</header><text>If a Federal law enforcement agency determines that the
			 notification required under this section would impede a criminal investigation,
			 such notification shall be delayed upon written notice from such Federal law
			 enforcement agency to the agency or business entity that experienced the
			 breach.</text>
				</paragraph><paragraph id="id9D7DCDFF0BCD4390BBEAD18BA12DDEEA"><enum>(2)</enum><header>Extended delay
			 of notification</header><text>If the notification required under subsection (a)
			 is delayed pursuant to paragraph (1), an agency or business entity shall give
			 notice 30 days after the day such law enforcement delay was invoked unless a
			 Federal law enforcement agency provides written notification that further delay
			 is necessary.</text>
				</paragraph><paragraph id="idD06FEABFE3D14125AF2AC2939BE398B4"><enum>(3)</enum><header>Law enforcement
			 immunity</header><text>No cause of action shall lie in any court against any
			 law enforcement agency for acts relating to the delay of notification for law
			 enforcement purposes under this Act.</text>
				</paragraph></subsection></section><section changed="deleted" committee-id="SSJU00" id="id4CF1E210AEFC4D0D86F7DF1133CA3865" reported-display-style="strikethrough"><enum>3.</enum><header>Exemptions</header>
			<subsection id="idF30B49722F784049A3E795AEE99EDF75"><enum>(a)</enum><header>Exemption for
			 National Security and Law Enforcement</header>
				<paragraph id="idC9D62C391A2746DC940DB101A7D996CD"><enum>(1)</enum><header>In
			 general</header><text>Section 2 shall not apply to an agency or business entity
			 if the agency or business entity certifies, in writing, that notification of
			 the security breach as required by section 2 reasonably could be expected
			 to—</text>
					<subparagraph id="idEC67FFFE4AE24BE38D849C18CD1D8CC6"><enum>(A)</enum><text>cause damage to
			 the national security; or</text>
					</subparagraph><subparagraph id="idC0E751C6E7CD45BCB243DE087E82CB2D"><enum>(B)</enum><text>hinder a law
			 enforcement investigation or the ability of the agency to conduct law
			 enforcement investigations.</text>
					</subparagraph></paragraph><paragraph id="id102DD2A679504400B463D9B9B47A98F7"><enum>(2)</enum><header>Limits on
			 certifications</header><text>An agency or business entity may not execute a
			 certification under paragraph (1) to—</text>
					<subparagraph id="idBBE9E008F15F45CD958E68934F458941"><enum>(A)</enum><text>conceal violations
			 of law, inefficiency, or administrative error;</text>
					</subparagraph><subparagraph id="id6DBB23C867CC4A349ACFC47793C58E6F"><enum>(B)</enum><text>prevent
			 embarrassment to a business entity, organization, or agency; or</text>
					</subparagraph><subparagraph id="id8009FBD7BE4E4C6CBDD393BF3EA5F3B2"><enum>(C)</enum><text>restrain
			 competition.</text>
					</subparagraph></paragraph><paragraph id="id59FD809D9D1542EE9F246F21121242EC"><enum>(3)</enum><header>Notice</header><text>In
			 every case in which an agency or business entity issues a certification under
			 paragraph (1), the certification, accompanied by a description of the factual
			 basis for the certification, shall be immediately provided to the United States
			 Secret Service.</text>
				</paragraph><paragraph id="ID03a548d7bf3d433693c4ab2b1bde7280"><enum>(4)</enum><header>Secret service
			 review of certifications</header>
					<subparagraph id="ID1602d3c72ed54448a19dbf73919739f8"><enum>(A)</enum><header>In
			 general</header><text>The United States Secret Service may review a
			 certification provided by an agency under paragraph (3), and shall review a
			 certification provided by a business entity under paragraph (3), to determine
			 whether an exemption under paragraph (1) is merited. Such review shall be
			 completed not later than 10 business days after the date of receipt of the
			 certification, except as provided in paragraph (5)(C).</text>
					</subparagraph><subparagraph id="IDe602279f6bae4c49be04bb7c236a80cd"><enum>(B)</enum><header>Notice</header><text>Upon
			 completing a review under subparagraph (A) the United States Secret Service
			 shall immediately notify the agency or business entity, in writing, of its
			 determination of whether an exemption under paragraph (1) is merited.</text>
					</subparagraph><subparagraph id="IDb2f94c610bf4422ead6561388120e2cd"><enum>(C)</enum><header>Exemption</header><text>The
			 exemption under paragraph (1) shall not apply if the United States Secret
			 Service determines under this paragraph that the exemption is not
			 merited.</text>
					</subparagraph></paragraph><paragraph id="IDf148dfa1623544b0a9caa32d0c71db86"><enum>(5)</enum><header>Additional
			 authority of the secret service</header>
					<subparagraph id="ID6517c455849e4249b1b05f812b7277c4"><enum>(A)</enum><header>In
			 general</header><text>In determining under paragraph (4) whether an exemption
			 under paragraph (1) is merited, the United States Secret Service may request
			 additional information from the agency or business entity regarding the basis
			 for the claimed exemption, if such additional information is necessary to
			 determine whether the exemption is merited.</text>
					</subparagraph><subparagraph id="ID431a29e012304bc493848737c25210e5"><enum>(B)</enum><header>Required
			 compliance</header><text>Any agency or business entity that receives a request
			 for additional information under subparagraph (A) shall cooperate with any such
			 request.</text>
					</subparagraph><subparagraph id="ID0b31ef44ccc14992880aa9343f54477c"><enum>(C)</enum><header>Timing</header><text>If
			 the United States Secret Service requests additional information under
			 subparagraph (A), the United States Secret Service shall notify the agency or
			 business entity not later than 10 business days after the date of receipt of
			 the additional information whether an exemption under paragraph (1) is
			 merited.</text>
					</subparagraph></paragraph></subsection><subsection id="idBCDDD5549241425AABFC3C14281C03A1"><enum>(b)</enum><header>Safe
			 harbor</header>
				<paragraph id="id36B7B5C078384924BFADECD3BCA67F1D"><enum>(1)</enum><header>In
			 general</header><text>An agency or business entity shall be exempt from the
			 notice requirements under section 2, if—</text>
					<subparagraph id="ID156359b897734909bb90e9e75a30b116"><enum>(A)</enum><text>a risk assessment
			 concludes that there is no significant risk that a security breach has resulted
			 in, or will result in, harm to the individual whose sensitive personally
			 identifiable information was subject to the security breach;</text>
					</subparagraph><subparagraph id="id53589D15D0DB468CB11D5E76E251A862"><enum>(B)</enum><text>without
			 unreasonable delay, but not later than 45 days after the discovery of a
			 security breach (unless extended by the United States Secret Service), the
			 agency or business entity notifies the United States Secret Service, in
			 writing, of—</text>
						<clause id="id60711ADD0591494792C5C0FE14AC0640"><enum>(i)</enum><text>the results of the
			 risk assessment; and</text>
						</clause><clause id="id7F555300ECDC4C10BD60D853379CBF01"><enum>(ii)</enum><text>its decision to
			 invoke the risk assessment exemption; and</text>
						</clause></subparagraph><subparagraph id="id463F5724D15C4567B0CCB4193FD65E04"><enum>(C)</enum><text>the United States
			 Secret Service does not indicate, in writing, and not later than 10 business
			 days after the date of receipt of the decision described in subparagraph
			 (B)(ii), that notice should be given.</text>
					</subparagraph></paragraph><paragraph id="id6E5B875D35A2479F8E572FB367D8202A"><enum>(2)</enum><header>Presumptions</header><text>There
			 shall be a presumption that no significant risk of harm to the individual whose
			 sensitive personally identifiable information was subject to a security breach
			 if such information—</text>
					<subparagraph id="id7261B6C05F82413BABA497FD6E68AB61"><enum>(A)</enum><text>was encrypted;
			 or</text>
					</subparagraph><subparagraph id="id7F2703711BA84E97B6C9D1824EFEEAEC"><enum>(B)</enum><text>was rendered
			 indecipherable through the use of best practices or methods, such as redaction,
			 access controls, or other such mechanisms, that are widely accepted as an
			 effective industry practice, or an effective industry standard.</text>
					</subparagraph></paragraph></subsection><subsection id="idC41B8677D8FA4D05824CACE96A776D43"><enum>(c)</enum><header>Financial fraud
			 prevention exemption</header>
				<paragraph id="id3ABB9DE7791944368389DED8F6138953"><enum>(1)</enum><header>In
			 general</header><text>A business entity will be exempt from the notice
			 requirement under section 2 if the business entity utilizes or participates in
			 a security program that—</text>
					<subparagraph id="id7BD40360F74742EF9276CE7179E3E9AE"><enum>(A)</enum><text>is designed to
			 block the use of the sensitive personally identifiable information to initiate
			 unauthorized financial transactions before they are charged to the account of
			 the individual; and</text>
					</subparagraph><subparagraph id="idF27444F27B1E4942AB8A1CAB4B1DBAC1"><enum>(B)</enum><text>provides for
			 notice to affected individuals after a security breach that has resulted in
			 fraud or unauthorized transactions.</text>
					</subparagraph></paragraph><paragraph id="id1E73AC2CA4C84D109FAD3C0E851D11E1"><enum>(2)</enum><header>Limitation</header><text>The
			 exemption by this subsection does not apply if—</text>
					<subparagraph id="IDccaaf79f9bff4a8f9888923e16126157"><enum>(A)</enum><text>the information
			 subject to the security breach includes sensitive personally identifiable
			 information, other than a credit card number or credit card security code, of
			 any type; or</text>
					</subparagraph><subparagraph id="IDb394dee646e848a78e2de26b9fe14d6e"><enum>(B)</enum><text>the information
			 subject to the security breach includes both the individual’s credit card
			 number and the individual’s first and last name.</text>
					</subparagraph></paragraph></subsection></section><section changed="deleted" committee-id="SSJU00" id="id044DF1A844054EA2B2816CEBD65F6126" reported-display-style="strikethrough"><enum>4.</enum><header>Methods of
			 notice</header><text display-inline="no-display-inline">An agency, or business
			 entity shall be in compliance with section 2 if it provides both:</text>
			<paragraph id="idF3351E9AF4BD4B6AB4AF3DAB394952B6"><enum>(1)</enum><header>Individual
			 notice</header>
				<subparagraph id="idF8E35A3DD7CD45BBA92822BE71169C6F"><enum>(A)</enum><text>Written
			 notification to the last known home mailing address of the individual in the
			 records of the agency or business entity;</text>
				</subparagraph><subparagraph id="id4129576F9A3540159A5E0A6FCC81AD8D"><enum>(B)</enum><text>telephone notice
			 to the individual personally; or</text>
				</subparagraph><subparagraph id="idD2BBA243098B4A8C959BA6B75F246D18"><enum>(C)</enum><text>e-mail notice, if
			 the individual has consented to receive such notice and the notice is
			 consistent with the provisions permitting electronic transmission of notices
			 under section 101 of the Electronic Signatures in Global and National Commerce
			 Act (15 U.S.C. 7001).</text>
				</subparagraph></paragraph><paragraph id="id054BFA79C9564CCC86B680D6B7FF30D6"><enum>(2)</enum><header>Media
			 notice</header><text>Notice to major media outlets serving a State or
			 jurisdiction, if the number of residents of such State whose sensitive
			 personally identifiable information was, or is reasonably believed to have
			 been, acquired by an unauthorized person exceeds 5,000.</text>
			</paragraph></section><section changed="deleted" committee-id="SSJU00" id="idDF26D460B503452BA171B9900FAF5A05" reported-display-style="strikethrough"><enum>5.</enum><header>Content of
			 notification</header>
			<subsection id="id8564F7F787C541808ABD5096BC25B276"><enum>(a)</enum><header>In
			 General</header><text>Regardless of the method by which notice is provided to
			 individuals under section 4, such notice shall include, to the extent
			 possible—</text>
				<paragraph id="idF2E8E915AF3D4EDBA194CF5BC0B85CD0"><enum>(1)</enum><text>a description of
			 the categories of sensitive personally identifiable information that was, or is
			 reasonably believed to have been, acquired by an unauthorized person;</text>
				</paragraph><paragraph id="id62C97F87F7C6414EBF5BFA58E8A86892"><enum>(2)</enum><text>a toll-free
			 number—</text>
					<subparagraph id="idD75D900B5FF84A278DE40E24B73794E1"><enum>(A)</enum><text>that the
			 individual may use to contact the agency or business entity, or the agent of
			 the agency or business entity; and</text>
					</subparagraph><subparagraph id="id5C184ED6989D4A3F8DB1D72038730C35"><enum>(B)</enum><text>from which the
			 individual may learn what types of sensitive personally identifiable
			 information the agency or business entity maintained about that individual;
			 and</text>
					</subparagraph></paragraph><paragraph id="id7451A0BC21F945279A51B89A9DC8E5BC"><enum>(3)</enum><text>the toll-free
			 contact telephone numbers and addresses for the major credit reporting
			 agencies.</text>
				</paragraph></subsection><subsection id="id29AB0E87A105487081B0B53304882A4E"><enum>(b)</enum><header>Additional
			 Content</header><text>Notwithstanding section 10, a State may require that a
			 notice under subsection (a) shall also include information regarding victim
			 protection assistance provided for by that State.</text>
			</subsection></section><section changed="deleted" committee-id="SSJU00" id="id9B29BDF393FA46E99F967A3C99CE3608" reported-display-style="strikethrough"><enum>6.</enum><header>Coordination of
			 notification with credit reporting agencies</header><text display-inline="no-display-inline">If an agency or business entity is required
			 to provide notification to more than 5,000 individuals under section 2(a), the
			 agency or business entity shall also notify all consumer reporting agencies
			 that compile and maintain files on consumers on a nationwide basis (as defined
			 in section 603(p) of the <act-name parsable-cite="FCRA">Fair Credit Reporting
			 Act</act-name> (15 U.S.C. 1681a(p))) of the timing and distribution of the
			 notices. Such notice shall be given to the consumer credit reporting agencies
			 without unreasonable delay and, if it will not delay notice to the affected
			 individuals, prior to the distribution of notices to the affected
			 individuals.</text>
		</section><section changed="deleted" committee-id="SSJU00" id="id3A76272160C24CCC94D335D29D696D70" reported-display-style="strikethrough"><enum>7.</enum><header>Notice to law
			 enforcement</header>
			<subsection id="id9DCC813E0DCC42C3AF8F14082A47F39F"><enum>(a)</enum><header>Secret
			 Service</header><text>Any business entity or agency shall notify the United
			 States Secret Service of the fact that a security breach has occurred
			 if—</text>
				<paragraph id="id83787FC3E1C34CD69E965DA2E56DE267"><enum>(1)</enum><text>the number of
			 individuals whose sensitive personally identifying information was, or is
			 reasonably believed to have been acquired by an unauthorized person exceeds
			 10,000;</text>
				</paragraph><paragraph id="id394E75506B534C3CA84B38A08E5BCEB5"><enum>(2)</enum><text>the security
			 breach involves a database, networked or integrated databases, or other data
			 system containing the sensitive personally identifiable information of more
			 than 1,000,000 individuals nationwide;</text>
				</paragraph><paragraph id="id19E7E43DE3E74FC38CFAE6832616A882"><enum>(3)</enum><text>the security
			 breach involves databases owned by the Federal Government; or</text>
				</paragraph><paragraph id="idB507BDE7583B4262844D3F7C44304C35"><enum>(4)</enum><text>the security
			 breach involves primarily sensitive personally identifiable information of
			 individuals known to the agency or business entity to be employees and
			 contractors of the Federal Government involved in national security or law
			 enforcement.</text>
				</paragraph></subsection><subsection id="idC03C797F93724D75964B7F15AD810D15"><enum>(b)</enum><header>Notice to other
			 law enforcement agencies</header><text>The United States Secret Service shall
			 be responsible for notifying—</text>
				<paragraph id="id8C9CDFDE3DCB42DBADEBEFB6B8728AC6"><enum>(1)</enum><text>the Federal Bureau
			 of Investigation, if the security breach involves espionage, foreign
			 counterintelligence, information protected against unauthorized disclosure for
			 reasons of national defense or foreign relations, or Restricted Data (as that
			 term is defined in section 11y of the <act-name parsable-cite="AEA54">Atomic
			 Energy Act of 1954</act-name> (42 U.S.C. 2014(y))), except for offenses
			 affecting the duties of the United States Secret Service under section 3056(a)
			 of title 18, United States Code;</text>
				</paragraph><paragraph id="id21D53D4AE5154EECB50E6362BA1224B5"><enum>(2)</enum><text>the United States
			 Postal Inspection Service, if the security breach involves mail fraud;
			 and</text>
				</paragraph><paragraph id="id601E31496F164FEB9CF980735D39F8E9"><enum>(3)</enum><text>the attorney
			 general of each State affected by the security breach.</text>
				</paragraph></subsection><subsection id="ID88f7ca432bca4bac8757ee3308e087b5"><enum>(c)</enum><header>Timing of
			 notices</header><text>The notices required under this section shall be
			 delivered as follows:</text>
				<paragraph id="IDd1eb1239b6cd444e8efb5cb3010a1411"><enum>(1)</enum><text>Notice under
			 subsection (a) shall be delivered as promptly as possible, but not later than
			 14 days after discovery of the events requiring notice.</text>
				</paragraph><paragraph id="ID64e262c1b4f44e1a829d5bf1c7fa80bf"><enum>(2)</enum><text>Notice under
			 subsection (b) shall be delivered not later than 14 days after the United
			 States Secret Service receives notice of a security breach from an agency or
			 business entity.</text>
				</paragraph></subsection></section><section changed="deleted" committee-id="SSJU00" id="id7CC73545ABB048DBA2B1872F8BFBBFF1" reported-display-style="strikethrough"><enum>8.</enum><header>Enforcement</header>
			<subsection id="id12765D730A9343D89C74CA1C0A56F1E4"><enum>(a)</enum><header>Civil actions by
			 the Attorney General</header><text>The Attorney General may bring a civil
			 action in the appropriate United States district court against any business
			 entity that engages in conduct constituting a violation of this Act and, upon
			 proof of such conduct by a preponderance of the evidence, such business entity
			 shall be subject to a civil penalty of not more than $1,000 per day per
			 individual whose sensitive personally identifiable information was, or is
			 reasonably believed to have been, accessed or acquired by an unauthorized
			 person, up to a maximum of $1,000,000 per violation, unless such conduct is
			 found to be willful or intentional.</text>
			</subsection><subsection id="id0EDB12B5CAA54E8CBD89886E678EF568"><enum>(b)</enum><header>Injunctive
			 actions by the Attorney General</header>
				<paragraph id="id4383365926FF4942870AAE40E95C0DA8"><enum>(1)</enum><header>In
			 general</header><text>If it appears that a business entity has engaged, or is
			 engaged, in any act or practice constituting a violation of this Act, the
			 Attorney General may petition an appropriate district court of the United
			 States for an order—</text>
					<subparagraph id="idDE35B3CE43B74E75B699BF4FD4B4D86D"><enum>(A)</enum><text>enjoining such act
			 or practice; or</text>
					</subparagraph><subparagraph id="id4AD83B990BDB420F8FC563FA02BBADA4"><enum>(B)</enum><text>enforcing
			 compliance with this Act.</text>
					</subparagraph></paragraph><paragraph id="id0BEFA247E33B464F8F33887CC0EB5163"><enum>(2)</enum><header>Issuance of
			 order</header><text>A court may issue an order under paragraph (1), if the
			 court finds that the conduct in question constitutes a violation of this
			 Act.</text>
				</paragraph></subsection><subsection id="idE1981FCD83864F4DA783730E7F678306"><enum>(c)</enum><header>Other rights and
			 remedies</header><text>The rights and remedies available under this Act are
			 cumulative and shall not affect any other rights and remedies available under
			 law.</text>
			</subsection><subsection id="id7D3B0E9140CB4E5680B5939E9B11B987"><enum>(d)</enum><header>Fraud
			 alert</header><text>Section 605A(b)(1) of the <act-name parsable-cite="FCRA">Fair Credit Reporting Act</act-name> (15 U.S.C.
			 1681c–1(b)(1)) is amended by inserting <quote>, or evidence that the consumer
			 has received notice that the consumer’s financial information has or may have
			 been compromised,</quote> after <quote>identity theft report</quote>.</text>
			</subsection></section><section changed="deleted" committee-id="SSJU00" id="idA3446BC98EC44D44801CB30531941B3F" reported-display-style="strikethrough"><enum>9.</enum><header>Enforcement by
			 State attorneys general</header>
			<subsection id="id03D0A9CEF9E343DA87744E58A1E2DED7"><enum>(a)</enum><header>In
			 general</header>
				<paragraph id="id9C20753C364F421289A323AC0D77A26C"><enum>(1)</enum><header>Civil
			 actions</header><text>In any case in which the attorney general of a State or
			 any State or local law enforcement agency authorized by the State attorney
			 general or by State statute to prosecute violations of consumer protection law,
			 has reason to believe that an interest of the residents of that State has been
			 or is threatened or adversely affected by the engagement of a business entity
			 in a practice that is prohibited under this Act, the State or the State or
			 local law enforcement agency on behalf of the residents of the agency’s
			 jurisdiction, may bring a civil action on behalf of the residents of the State
			 or jurisdiction in a district court of the United States of appropriate
			 jurisdiction or any other court of competent jurisdiction, including a State
			 court, to—</text>
					<subparagraph id="idA80F8B1F347C4DBAAE6519030ECF6BB7"><enum>(A)</enum><text>enjoin that
			 practice;</text>
					</subparagraph><subparagraph id="idEA1CD4C9848348DE974F8750296FF8DF"><enum>(B)</enum><text>enforce compliance
			 with this Act; or</text>
					</subparagraph><subparagraph id="id33604A45076F48C69A025A2EC89607C2"><enum>(C)</enum><text>obtain civil
			 penalties of not more than $1,000 per day per individual whose sensitive
			 personally identifiable information was, or is reasonably believed to have
			 been, accessed or acquired by an unauthorized person, up to a maximum of
			 $1,000,000 per violation, unless such conduct is found to be willful or
			 intentional.</text>
					</subparagraph></paragraph><paragraph id="idBB82E75F44AF478ABDC057F6B0FCDBF1"><enum>(2)</enum><header>Notice</header>
					<subparagraph id="idE38ADB6BE6A04BF6B6C2C8847126F8C6"><enum>(A)</enum><header>In
			 general</header><text>Before filing an action under paragraph (1), the attorney
			 general of the State involved shall provide to the Attorney General of the
			 United States—</text>
						<clause id="id5D5E7BBF0F54477AB8ED5DDCAF6B6A84"><enum>(i)</enum><text>written notice of
			 the action; and</text>
						</clause><clause id="id04B58A922FD74E7E8C902012A2C75E01"><enum>(ii)</enum><text>a copy of the
			 complaint for the action.</text>
						</clause></subparagraph><subparagraph id="id74E7C2757A734A759E58E5A091256EF3"><enum>(B)</enum><header>Exemption</header>
						<clause id="id5BA1A0142EE94C469589EA19E58EC155"><enum>(i)</enum><header>In
			 general</header><text>Subparagraph (A) shall not apply with respect to the
			 filing of an action by an attorney general of a State under this Act, if the
			 State attorney general determines that it is not feasible to provide the notice
			 described in such subparagraph before the filing of the action.</text>
						</clause><clause id="idF91F0ABFC9284300AAC5584E9F0AAC0F"><enum>(ii)</enum><header>Notification</header><text>In
			 an action described in clause (i), the attorney general of a State shall
			 provide notice and a copy of the complaint to the Attorney General at the time
			 the State attorney general files the action.</text>
						</clause></subparagraph></paragraph></subsection><subsection id="id6C2D2008627D495792F7C6726631A44C"><enum>(b)</enum><header>Federal
			 proceedings</header><text>Upon receiving notice under subsection (a)(2), the
			 Attorney General shall have the right to—</text>
				<paragraph id="idA3139A36B69347D381D7A7CE84DD71A1"><enum>(1)</enum><text>move to stay the
			 action, pending the final disposition of a pending Federal proceeding or
			 action;</text>
				</paragraph><paragraph id="id3211A522853D4037AF5AB649AA1CC9F3"><enum>(2)</enum><text>initiate an action
			 in the appropriate United States district court under section 8 and move to
			 consolidate all pending actions, including State actions, in such court;</text>
				</paragraph><paragraph id="id7D72F42B81D44B7387CC395F95FC3EA4"><enum>(3)</enum><text>intervene in an
			 action brought under subsection (a)(2); and</text>
				</paragraph><paragraph id="id9CF43A0F82C040A5B86EC90EAB00EB71"><enum>(4)</enum><text>file petitions for
			 appeal.</text>
				</paragraph></subsection><subsection id="id79F631FE9ABA47EBA61B0C794989C688"><enum>(c)</enum><header>Pending
			 proceedings</header><text>If the Attorney General has instituted a proceeding
			 or action for a violation of this Act or any regulations thereunder, no
			 attorney general of a State may, during the pendency of such proceeding or
			 action, bring an action under this Act against any defendant named in such
			 criminal proceeding or civil action for any violation that is alleged in that
			 proceeding or action.</text>
			</subsection><subsection id="idE5F75E54BF194C1FB8C6AE513CCDEB4B"><enum>(d)</enum><header>Rule of
			 construction</header><text>For purposes of bringing any civil action under
			 subsection (a), nothing in this Act regarding notification shall be construed
			 to prevent an attorney general of a State from exercising the powers conferred
			 on such attorney general by the laws of that State to—</text>
				<paragraph id="id5D4714C9F5EC44049D02AAC5376FB6D2"><enum>(1)</enum><text>conduct
			 investigations;</text>
				</paragraph><paragraph id="id64484CFE376E43C8B440647F3A3A0B57"><enum>(2)</enum><text>administer oaths
			 or affirmations; or</text>
				</paragraph><paragraph id="idB339440990F54CA98DBF366BF261649A"><enum>(3)</enum><text>compel the
			 attendance of witnesses or the production of documentary and other
			 evidence.</text>
				</paragraph></subsection><subsection id="id16880649E7D04705AE8A55BDFEDECE76"><enum>(e)</enum><header>Venue; service
			 of process</header>
				<paragraph id="idD6904BED3FF945F1941F86F38C6B7B30"><enum>(1)</enum><header>Venue</header><text>Any
			 action brought under subsection (a) may be brought in—</text>
					<subparagraph id="idF0B924230D58430B9EFAB5AE169073DE"><enum>(A)</enum><text>the district court
			 of the United States that meets applicable requirements relating to venue under
			 section 1391 of title 28, United States Code; or</text>
					</subparagraph><subparagraph id="id88D4919FCD0A460EBCF03817F2B7B69A"><enum>(B)</enum><text>another court of
			 competent jurisdiction.</text>
					</subparagraph></paragraph><paragraph id="idDE7F44A22E334EE698D31289F01A6882"><enum>(2)</enum><header>Service of
			 process</header><text>In an action brought under subsection (a), process may be
			 served in any district in which the defendant—</text>
					<subparagraph id="id6223B2F513B6425085E075FBAF55EAED"><enum>(A)</enum><text>is an inhabitant;
			 or</text>
					</subparagraph><subparagraph id="id2BDC9E2352CE4D23AAC0FED18D9A2B54"><enum>(B)</enum><text>may be
			 found.</text>
					</subparagraph></paragraph></subsection><subsection id="idDA36CE70D154493493B762EC53F24D55"><enum>(f)</enum><header>No private cause
			 of action</header><text>Nothing in this Act establishes a private cause of
			 action against a business entity for violation of any provision of this
			 Act.</text>
			</subsection></section><section changed="deleted" committee-id="SSJU00" id="id513B66C23BE447CB953218AD7189C428" reported-display-style="strikethrough"><enum>10.</enum><header>Effect on
			 Federal and State law</header><text display-inline="no-display-inline">The
			 provisions of this Act shall supersede any other provision of Federal law or
			 any provision of law of any State relating to notification by a business entity
			 engaged in interstate commerce or an agency of a security breach, except as
			 provided in section 5(b).</text>
		</section><section changed="deleted" committee-id="SSJU00" id="id29A954BBBF994D27986AE0061D82D148" reported-display-style="strikethrough"><enum>11.</enum><header>Authorization of
			 appropriations</header><text display-inline="no-display-inline">There are
			 authorized to be appropriated such sums as may be necessary to cover the costs
			 incurred by the United States Secret Service to carry out investigations and
			 risk assessments of security breaches as required under this Act.</text>
		</section><section changed="deleted" committee-id="SSJU00" id="id8C6C78DC9375443DB4E804EA4E9021A1" reported-display-style="strikethrough"><enum>12.</enum><header>Reporting on
			 risk assessment exemptions</header>
			<subsection id="id7C400914BE6042AE997B9D75625C16AE"><enum>(a)</enum><header>In
			 general</header><text display-inline="yes-display-inline">The United States
			 Secret Service shall report to Congress not later than 18 months after the date
			 of enactment of this Act, and upon the request by Congress thereafter,
			 on—</text>
				<paragraph id="id243E368A92BA444E9E5416A7E2CD96C3"><enum>(1)</enum><text>the number and
			 nature of the security breaches described in the notices filed by those
			 business entities invoking the risk assessment exemption under section 3(b) of
			 this Act and the response of the United States Secret Service to such notices;
			 and</text>
				</paragraph><paragraph id="id16E3465E18AC49EE90E6166EC67DA64C"><enum>(2)</enum><text>the number and
			 nature of security breaches subject to the national security and law
			 enforcement exemptions under section 3(a) of this Act.</text>
				</paragraph></subsection><subsection id="id7FEF13018A6B4ACCA51971B6E3A955A5"><enum>(b)</enum><header>Report</header><text>Any
			 report submitted under subsection (a) shall not disclose the contents of any
			 risk assessment provided to the United States Secret Service under this
			 Act.</text>
			</subsection></section><section changed="deleted" committee-id="SSJU00" id="idEEF2FAA3508B4279969DE9C8F39CE9BB" reported-display-style="strikethrough"><enum>13.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act, the following definitions shall
			 apply:</text>
			<paragraph id="id40069EE7532A4822A6F42316DC9DCF61"><enum>(1)</enum><header>Agency</header><text>The
			 term <term>agency</term> has the same meaning given such term in section 551 of
			 title 5, United States Code.</text>
			</paragraph><paragraph id="idDB41308A71A84D10897C18F76FF6F094"><enum>(2)</enum><header>Affiliate</header><text>The
			 term <term>affiliate</term> means persons related by common ownership or by
			 corporate control.</text>
			</paragraph><paragraph id="id8648254B691C4DE59500C28D0DD77A96"><enum>(3)</enum><header>Business
			 entity</header><text>The term <term>business entity</term> means any
			 organization, corporation, trust, partnership, sole proprietorship,
			 unincorporated association, venture established to make a profit, or nonprofit,
			 and any contractor, subcontractor, affiliate, or licensee thereof engaged in
			 interstate commerce.</text>
			</paragraph><paragraph id="IDc28f8875335c4c30a351e34bb3d4d1c0"><enum>(4)</enum><header>Encrypted</header><text>The
			 term <term>encrypted</term>—</text>
				<subparagraph id="IDa329d62a7c6446ee803d721a8dc95ead"><enum>(A)</enum><text>means the
			 protection of data in electronic form, in storage or in transit, using an
			 encryption technology that has been adopted by an established standards setting
			 body which renders such data indecipherable in the absence of associated
			 cryptographic keys necessary to enable decryption of such data; and</text>
				</subparagraph><subparagraph id="ID26d3d226c83e4623b24529020b5280e6"><enum>(B)</enum><text>includes
			 appropriate management and safeguards of such cryptographic keys so as to
			 protect the integrity of the encryption.</text>
				</subparagraph></paragraph><paragraph id="id56FA40FA14294C2390C2227446370B22"><enum>(5)</enum><header>Personally
			 identifiable information</header><text>The term <term>personally identifiable
			 information</term> means any information, or compilation of information, in
			 electronic or digital form serving as a means of identification, as defined by
			 section 1028(d)(7) of title 18, United State Code.</text>
			</paragraph><paragraph id="id1E89750AD7474EB98D8D11BD9082E241"><enum>(6)</enum><header>Security
			 breach</header>
				<subparagraph id="idF3BF03EFF4C9415AB580247A789178DB"><enum>(A)</enum><header>In
			 general</header><text>The term <term>security breach</term> means compromise of
			 the security, confidentiality, or integrity of computerized data through
			 misrepresentation or actions that result in, or there is a reasonable basis to
			 conclude has resulted in, acquisition of or access to sensitive personally
			 identifiable information that is unauthorized or in excess of
			 authorization.</text>
				</subparagraph><subparagraph id="id6549E95277844F1DAFF723AE986CFE2C"><enum>(B)</enum><header>Exclusion</header><text>The
			 term <term>security breach</term> does not include—</text>
					<clause id="id941AD42EE44C4D23870DFB2CC97B6610"><enum>(i)</enum><text>a good faith
			 acquisition of sensitive personally identifiable information by a business
			 entity or agency, or an employee or agent of a business entity or agency, if
			 the sensitive personally identifiable information is not subject to further
			 unauthorized disclosure; or</text>
					</clause><clause id="id097B6DF0965046AB887B908D38493775"><enum>(ii)</enum><text>the release of a
			 public record not otherwise subject to confidentiality or nondisclosure
			 requirements.</text>
					</clause></subparagraph></paragraph><paragraph id="id390183035D4F449C91335548A635DE5C"><enum>(7)</enum><header>Sensitive
			 personally identifiable information</header><text>The term <term>sensitive
			 personally identifiable information</term> means any information or compilation
			 of information, in electronic or digital form that includes—</text>
				<subparagraph id="idCEB4B31C65BD4E269A1A46697ECD9F5B"><enum>(A)</enum><text>an individual’s
			 first and last name or first initial and last name in combination with any 1 of
			 the following data elements:</text>
					<clause id="idF11EE7B09608428C91BEF2CC1EF33C10"><enum>(i)</enum><text>A non-truncated
			 Social Security number, driver’s license number, passport number, or alien
			 registration number.</text>
					</clause><clause id="id4E39342EB8B9496E8E6548A74A6B1928"><enum>(ii)</enum><text>Any 2 of the
			 following:</text>
						<subclause id="id1FABB1DE8C384F32B4FF2DC0674F4F9C"><enum>(I)</enum><text>Home address or
			 telephone number.</text>
						</subclause><subclause id="idA889DB1DC8704C0FB133A050D617315F"><enum>(II)</enum><text>Mother’s maiden
			 name, if identified as such.</text>
						</subclause><subclause id="id1A61C07FA3E04079867D9FB891407BCD"><enum>(III)</enum><text>Month, day, and
			 year of birth.</text>
						</subclause></clause><clause id="id90686653D1D64332B6044139335CA17A"><enum>(iii)</enum><text>Unique biometric
			 data such as a finger print, voice print, a retina or iris image, or any other
			 unique physical representation.</text>
					</clause><clause id="idC45101592F884D20B879B82EE59515B5"><enum>(iv)</enum><text>A unique account
			 identifier, electronic identification number, user name, or routing code in
			 combination with any associated security code, access code, or password that is
			 required for an individual to obtain money, goods, services or any other thing
			 of value; or</text>
					</clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id89D366ACFC11457EBD2F6A2FCF57338D"><enum>(B)</enum><text>a financial
			 account number or credit or debit card number in combination with any security
			 code, access code or password that is required for an individual to obtain
			 credit, withdraw funds, or engage in a financial transaction.</text>
				</subparagraph></paragraph></section><section changed="deleted" commented="no" committee-id="SSJU00" display-inline="no-display-inline" id="id12CE6BD914B940788BBB680F0FD487F9" reported-display-style="strikethrough" section-type="subsequent-section"><enum>14.</enum><header>Effective
			 date</header><text display-inline="no-display-inline">This Act shall take
			 effect on the expiration of the date which is 90 days after the date of
			 enactment of this Act.</text>
		</section></legis-body>
	<legis-body display-enacting-clause="no-display-enacting-clause">
		<section changed="added" committee-id="SSJU00" id="ID76968f3342a94deeb0ef01431b2549f5" reported-display-style="italic" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the
			 <short-title>Data Breach Notification Act of
			 2011</short-title>.</text>
		</section><section changed="added" committee-id="SSJU00" id="id0ecdcd05-c9d0-4f27-89b8-32b92347e56a" reported-display-style="italic"><enum>2.</enum><header>Notice to
			 individuals</header>
			<subsection id="idc6ec4fe0-e1c5-46ae-ae0d-1f2018d22fef"><enum>(a)</enum><header>In
			 General</header><text>Any agency, or business entity engaged in interstate
			 commerce, that uses, accesses, transmits, stores, disposes of or collects
			 sensitive personally identifiable information shall, following the discovery of
			 a security breach of such information notify any resident of the United States
			 whose sensitive personally identifiable information has been, or is reasonably
			 believed to have been, accessed, or acquired.</text>
			</subsection><subsection id="idc67f8acd-04c0-4553-aa74-3be9306d0f21"><enum>(b)</enum><header>Obligation of Owner or
			 Licensee</header>
				<paragraph id="id051accfb-cc04-4d1c-9e75-29b1fb3d7afc"><enum>(1)</enum><header>Notice to owner or
			 licensee</header><text>Any agency, or business entity engaged in interstate
			 commerce, that uses, accesses, transmits, stores, disposes of, or collects
			 sensitive personally identifiable information that the agency or business
			 entity does not own or license shall notify the owner or licensee of the
			 information following the discovery of a security breach involving such
			 information.</text>
				</paragraph><paragraph id="id0a7a0814-a46a-441d-ae42-ec4667a0c545"><enum>(2)</enum><header>Notice by owner,
			 licensee or other designated third party</header><text>Nothing in this Act
			 shall prevent or abrogate an agreement between an agency or business entity
			 required to give notice under this section and a designated third party,
			 including an owner or licensee of the sensitive personally identifiable
			 information subject to the security breach, to provide the notifications
			 required under subsection (a).</text>
				</paragraph><paragraph id="id4613e9e1-688e-4b01-9fb4-7f29f606a371"><enum>(3)</enum><header>Business entity
			 relieved from giving notice</header><text>A business entity obligated to give
			 notice under subsection (a) shall be relieved of such obligation if an owner or
			 licensee of the sensitive personally identifiable information subject to the
			 security breach, or other designated third party, provides such
			 notification.</text>
				</paragraph></subsection><subsection id="id841268c1-1f10-4db6-8463-f1b7631397ed"><enum>(c)</enum><header>Timeliness of
			 Notification</header>
				<paragraph id="id30193d1a-b505-4f43-9aa7-ea99254f8ffd"><enum>(1)</enum><header>In
			 general</header><text>All notifications required under this section shall be
			 made without unreasonable delay following the discovery by the agency or
			 business entity of a security breach.</text>
				</paragraph><paragraph id="idd0e26868-0319-42a5-b73f-70ec945955c8"><enum>(2)</enum><header>Reasonable
			 delay</header>
					<subparagraph id="idE1FC43814D7B42ACB01D4AAEA1BDCE6B"><enum>(A)</enum><header>In
			 general</header><text>Reasonable delay under this subsection may include any
			 time necessary to determine the scope of the security breach, prevent further
			 disclosures, conduct the risk assessment described in section 3(b)(1), and
			 restore the reasonable integrity of the data system and provide notice to law
			 enforcement when required.</text>
					</subparagraph><subparagraph id="ID25b5a5d0d4664f01bb0c81d096bd708a"><enum>(B)</enum><header>Exception</header>
						<clause id="id5F8A7069BB904856927FA742E4E100AB"><enum>(i)</enum><header>In
			 general</header><text>Except as provided in section 3, delay of notification
			 shall not exceed 60 days following the discovery of the security breach,
			 unless—</text>
							<subclause id="idCBBC6D629EAE4B58ACABB3CBD74D05E4"><enum>(I)</enum><text>the business entity or
			 agency requests an extension of time from the Federal Trade Commission;
			 and</text>
							</subclause><subclause id="id4BDBBAE85E61477CAE5C307519EF34D4"><enum>(II)</enum><text>the Federal Trade
			 Commission determines that the additional time requested under subclause (II)
			 is reasonably necessary.</text>
							</subclause></clause><clause id="ID7b5166d739424bf593de41f1b1e783c8"><enum>(ii)</enum><header>Additional
			 time</header><text>If a request for delay is approved under clause (i), the
			 agency or business entity that requested the delay may delay the time period
			 for notification for an additional period of 30 days. Successive requests for
			 delay are not prohibited.</text>
						</clause></subparagraph></paragraph><paragraph id="id32daec17-e711-42bb-a617-b34b494eee75"><enum>(3)</enum><header>Burden of
			 proof</header><text>The agency, business entity, owner, or licensee required to
			 provide notification under this section shall have the burden of demonstrating
			 that all notifications were made as required under this Act, including evidence
			 demonstrating the reasons for any delay.</text>
				</paragraph></subsection><subsection id="id7323d4e1-f809-49bb-b1d8-036315fc558c"><enum>(d)</enum><header>Delay of Notification
			 Authorized for Law Enforcement or National Security Purposes</header>
				<paragraph id="id63000f0f-6759-4174-8273-a15334cf5776"><enum>(1)</enum><header>In
			 general</header><text>If the United States Secret Service or the Federal Bureau
			 of Investigation determines that a notification required under this section
			 would impede a criminal investigation, or national security activity, such
			 notification shall be delayed upon written notice from the United States Secret
			 Service or the Federal Bureau of Investigation to the agency or business entity
			 that experienced the security breach. The notification from the United States
			 Secret Service or the Federal Bureau of Investigation shall specify in writing
			 the period of delay requested for law enforcement or national security
			 purposes.</text>
				</paragraph><paragraph commented="no" id="id43d03d1f-0d10-482f-a1fa-3b89fb39ca63"><enum>(2)</enum><header>Extended delay of
			 notification</header>
					<subparagraph commented="no" id="id1BD4884677054B90AED05C6490FE74B0"><enum>(A)</enum><header>In
			 general</header><text>If the notification required under subsection (a) is
			 delayed pursuant to paragraph (1), an agency or business entity shall give
			 notice 30 days after the day such law enforcement delay was invoked unless a
			 Federal law enforcement or intelligence agency provides written notification
			 that further delay is necessary.</text>
					</subparagraph><subparagraph commented="no" id="IDd9054f81135d4ed2a96dfc4992456898"><enum>(B)</enum><header>Written justification
			 requirements</header>
						<clause commented="no" id="id302D02595B9D4B32AACD21BA1B0E662E"><enum>(i)</enum><header>United States Secret
			 Service</header><text>If the United States Secret Service instructs the agency
			 or business entity to delay notification under this section longer than 30
			 days, the United States Secret Service shall submit written justification for
			 such delay to the Secretary of Homeland Security before such delay takes
			 place.</text>
						</clause><clause commented="no" id="ID995bb96da7ef4d97b186ed0253ee2c82"><enum>(ii)</enum><header>Federal Bureau of
			 Investigation</header><text>If the Federal Bureau of Investigation instructs
			 the agency or business entity to delay notification under this section longer
			 than 30 days, the Federal Bureau of Investigation shall submit written
			 justification for such delay to the Attorney General before such delay takes
			 place.</text>
						</clause></subparagraph></paragraph><paragraph id="id52f8b5f1-31f0-4fe2-9354-c06ab286dd09"><enum>(3)</enum><header>Law enforcement
			 immunity</header><text>No cause of action shall lie in any court against any
			 agency for acts relating to the delay of notification for law enforcement or
			 national security purposes under this Act.</text>
				</paragraph></subsection></section><section changed="added" committee-id="SSJU00" id="id28025e37-7592-4f9c-a16c-062985a8dcfd" reported-display-style="italic"><enum>3.</enum><header>Exemptions</header>
			<subsection id="id496cce26-2b1f-4ed5-98b3-6737ca5694d7"><enum>(a)</enum><header>Exemption for National
			 Security and Law Enforcement</header>
				<paragraph id="id96ed7ecb-7d26-40e2-8065-d68fc663e5d6"><enum>(1)</enum><header>In
			 general</header><text>Section 2 shall not apply to an agency or business entity
			 if—</text>
					<subparagraph id="iddea7c15b-86f6-41b7-81e6-b2d928c896b1"><enum>(A)</enum><text>the United States Secret
			 Service or the Federal Bureau of Investigation determines that notification of
			 the security breach could be expected to reveal sensitive sources and methods
			 or similarly impede the ability of the Government to conduct law enforcement or
			 intelligence investigations; or</text>
					</subparagraph><subparagraph id="idf27b9ef9-36cb-44e5-a80b-022854194673"><enum>(B)</enum><text>the Federal Bureau of
			 Investigation determines that notification of the security breach could be
			 expected to cause damage to the national security.</text>
					</subparagraph></paragraph><paragraph id="idE0CA4ED9FCFD4EADA07390C1A56C8F66"><enum>(2)</enum><header>Written justification
			 requirements</header>
					<subparagraph id="id758269243D62444BA2C82B23DEABCC87"><enum>(A)</enum><header>United States Secret
			 Service</header><text>If the United States Secret Service invokes the exemption
			 in this section, the United States Secret Service shall submit written
			 justification for such exemption to the Secretary of Homeland Security before
			 such exemption is invoked.</text>
					</subparagraph><subparagraph id="id4F303B6AC4184D94B079F6C95011ACAD"><enum>(B)</enum><header>Federal Bureau of
			 Investigation</header><text>If the Federal Bureau of Investigation invokes the
			 exemption in this section, the Federal Bureau of Investigation shall submit
			 written justification for such exemption to the Attorney General before such
			 exemption is invoked.</text>
					</subparagraph></paragraph><paragraph id="idd1eb50f9-e644-4214-8bba-34d49adaf59e"><enum>(3)</enum><header>Immunity</header><text>No
			 cause of action shall lie in any court against any Federal agency for acts
			 relating to the exemption from notification for law enforcement or national
			 security purposes under this title.</text>
				</paragraph></subsection><subsection id="id57d6444c-a03d-4c8e-816c-9becbfda636c"><enum>(b)</enum><header>Safe harbor</header>
				<paragraph id="idb4f955c1-54c8-4257-aee2-95fac9538b41"><enum>(1)</enum><header>In
			 general</header><text>An agency or business entity shall be exempt from the
			 notice requirements under section 2, if—</text>
					<subparagraph id="id39e669e9-69b2-4173-be61-04266775d189"><enum>(A)</enum><text>a risk assessment
			 concludes that there is no significant risk that a security breach has resulted
			 in, or will result in, identity theft, economic loss or harm, or physical harm
			 to the individuals whose sensitive personally identifiable information was
			 subject to the security breach;</text>
					</subparagraph><subparagraph id="id74a88128-dbb4-438c-ace1-8cc4d953a154"><enum>(B)</enum><text>without unreasonable
			 delay, but not later than 45 days after the discovery of a security breach
			 (unless extended by the Federal Trade Commission), the agency or business
			 entity notifies the Federal Trade Commission, in writing, of—</text>
						<clause id="idc39d827e-549e-4ab2-92d1-385210dcc01e"><enum>(i)</enum><text>the results of the risk
			 assessment; and</text>
						</clause><clause id="id5b3d75a2-ef5c-43cd-a617-b5b6f5f2c350"><enum>(ii)</enum><text>its decision to invoke
			 the risk assessment exemption; and</text>
						</clause></subparagraph><subparagraph id="id69329c88-fc32-409c-b971-6c695e6f5138"><enum>(C)</enum><text>the Federal Trade
			 Commission does not indicate, in writing, and not later than 10 business days
			 after the date of receipt of the decision described in subparagraph (B)(ii),
			 that notice should be given.</text>
					</subparagraph></paragraph><paragraph id="idd875a1a8-67f4-40b0-86ea-ff7d495d33ea"><enum>(2)</enum><header>Presumptions</header><text>There
			 shall be a presumption that no significant risk of harm to the individual whose
			 sensitive personally identifiable information was subject to a security breach
			 if such information—</text>
					<subparagraph id="id3fcdcca4-4eab-4fec-bcfb-fa3a8f48b476"><enum>(A)</enum><text>was encrypted; or</text>
					</subparagraph><subparagraph id="id791748da-e9d5-43a3-b789-77c5cdefe852"><enum>(B)</enum><text>was otherwise rendered
			 unusable, unreadable, or indecipherable through the use of data security
			 technology that is generally accepted by experts in the field of information
			 security as an effective information security practice.</text>
					</subparagraph></paragraph></subsection><subsection id="ide136340f-99d7-4196-9eac-7198a70d0121"><enum>(c)</enum><header>Financial fraud
			 prevention exemption</header>
				<paragraph id="id9055a1cd-d24d-4386-bf61-3d6a70b210df"><enum>(1)</enum><header>In
			 general</header><text>A business entity will be exempt from the notice
			 requirement under section 2 if the business entity utilizes or participates in
			 a security program that—</text>
					<subparagraph id="idec4e6e44-8a13-484e-ba19-6c0f3ebc94fb"><enum>(A)</enum><text>effectively blocks the
			 use of the sensitive personally identifiable information to initiate
			 unauthorized financial transactions before they are charged to the account of
			 the individual; and</text>
					</subparagraph><subparagraph id="id9b23b8c3-cd8a-4554-aceb-c5f114fdccf4"><enum>(B)</enum><text>provides for notice to
			 affected individuals after a security breach that has resulted in fraud or
			 unauthorized transactions.</text>
					</subparagraph></paragraph><paragraph id="id5f941d9f-5eb6-4c5c-bc71-e7a7b5a9929b"><enum>(2)</enum><header>Limitation</header><text>The
			 exemption by this subsection does not apply if—</text>
					<subparagraph id="idf79f09e8-56b1-47ad-979b-de69a32cab58"><enum>(A)</enum><text>the information subject
			 to the security breach includes sensitive personally identifiable information,
			 other than a credit card number or credit card security code, of any type;
			 or</text>
					</subparagraph><subparagraph id="id237b78ee-798f-4134-b446-1d7f492e365a"><enum>(B)</enum><text>the information subject
			 to the security breach includes both the individual’s credit card number and
			 the individual’s first and last name.</text>
					</subparagraph></paragraph></subsection><subsection id="IDa35bdba6e79e4762aba52d6faafe2ca7"><enum>(d)</enum><header>Limitations</header>
				<paragraph id="ID8b61f4052309411fb9e12add127bb1c3"><enum>(1)</enum><header>Definitions</header><text>In
			 this subsection—</text>
					<subparagraph id="ID7f2be4e7167f4fa3aeca72e6a79b46df"><enum>(A)</enum><text>the term <term>covered
			 financial institution</term> means a financial institution that is subject
			 to—</text>
						<clause id="ID1997007358804ed9b62fed46a9df7e11"><enum>(i)</enum><text>the data security
			 requirements of the Gramm-Leach-Bliley Act (15 U.S.C. 6801 et seq.);</text>
						</clause><clause id="ID4f0dd0967f424c35b6e722e66c2b5b6f"><enum>(ii)</enum><text>any implementing
			 regulations issued under that Act; and</text>
						</clause><clause id="IDd61f0c59d8de4084a1a4de952477ff55"><enum>(iii)</enum><text>the jurisdiction of a
			 Federal functional regulator under that Act; and</text>
						</clause></subparagraph><subparagraph id="ID7abae29c254e4d5597c9cdd812f5272f"><enum>(B)</enum><text>the terms <term>Federal
			 functional regulator</term> and <term>financial institution</term> have the
			 meaning given those terms in section 509 of the Gramm-Leach-Bliley Act (15
			 U.S.C. 6809).</text>
					</subparagraph></paragraph><paragraph id="ID38aded1f669f47499f6281f430aa494b"><enum>(2)</enum><header>Financial institutions
			 regulated by Federal functional regulators</header><text>Nothing in this Act
			 shall apply to a covered financial institution if the Federal functional
			 regulator with jurisdiction over the covered financial institution has issued a
			 regulation under title V of the Gramm-Leach-Bliley Act (15 U.S.C. 6801 et seq.)
			 that—</text>
					<subparagraph id="IDfb2c45f82a744e9e864f95fb4ffedd43"><enum>(A)</enum><text>requires financial
			 institutions within its jurisdiction to provide notification to individuals
			 following a breach of security; and</text>
					</subparagraph><subparagraph id="IDe3ad6b0bbac04af2ba6d51b9c7187915"><enum>(B)</enum><text>provides protections
			 substantially similar to, or greater than, those required under this
			 Act.</text>
					</subparagraph></paragraph></subsection></section><section changed="added" committee-id="SSJU00" id="id1c93ca78-d032-45bd-83c2-72b3344668d7" reported-display-style="italic"><enum>4.</enum><header>Methods of
			 notice</header><text display-inline="no-display-inline">An agency or business
			 entity shall be in compliance with section 2 if it provides both:</text>
			<paragraph id="id91af892e-2352-4a85-bc7b-d003675918c9"><enum>(1)</enum><header>Individual
			 notice</header>
				<subparagraph id="id365c00b8-fc9b-4117-b681-7b3015c81e28"><enum>(A)</enum><text>Written notification to
			 the last known home mailing address of the individual in the records of the
			 agency or business entity;</text>
				</subparagraph><subparagraph id="idb94725e9-0725-47de-ae7d-2fbfcdd062ce"><enum>(B)</enum><text>telephone notice to the
			 individual personally; or</text>
				</subparagraph><subparagraph id="idf9dcc0c7-4cef-4ba4-8f17-2effa15273a1"><enum>(C)</enum><text>e-mail notice, if the
			 individual has consented to receive such notice and the notice is consistent
			 with the provisions permitting electronic transmission of notices under section
			 101 of the Electronic Signatures in Global and National Commerce Act (15 U.S.C.
			 7001).</text>
				</subparagraph></paragraph><paragraph id="idcbfaa2e6-c534-4df1-acf8-ba6e0e315070"><enum>(2)</enum><header>Media
			 notice</header><text>Notice to major media outlets serving a State or
			 jurisdiction, if the number of residents of such State whose sensitive
			 personally identifiable information was, or is reasonably believed to have
			 been, acquired by an unauthorized person exceeds 5,000.</text>
			</paragraph></section><section changed="added" committee-id="SSJU00" id="id6c0c4965-1c76-4e30-af17-722da684d974" reported-display-style="italic"><enum>5.</enum><header>Content of
			 notification</header>
			<subsection id="ided398974-e959-4bae-9977-37c53718113c"><enum>(a)</enum><header>In
			 General</header><text>Regardless of the method by which notice is provided to
			 individuals under section 4, such notice shall include, to the extent
			 possible—</text>
				<paragraph id="ide355c753-6b4c-42dc-9826-13baa2325abe"><enum>(1)</enum><text>a description of the
			 categories of sensitive personally identifiable information that was, or is
			 reasonably believed to have been, acquired by an unauthorized person;</text>
				</paragraph><paragraph id="id435b53f9-7bc9-4b43-8582-7f21878b62d1"><enum>(2)</enum><text>a toll-free
			 number—</text>
					<subparagraph id="idb252f653-58b0-4017-9887-74fc07508d60"><enum>(A)</enum><text>that the individual may
			 use to contact the agency or business entity, or the agent of the agency or
			 business entity; and</text>
					</subparagraph><subparagraph id="ide2c8b3d5-fb21-4be0-872b-9da8c6a79c8d"><enum>(B)</enum><text>from which the individual
			 may learn what types of sensitive personally identifiable information the
			 agency or business entity maintained about that individual; and</text>
					</subparagraph></paragraph><paragraph id="idfb81c079-1911-4c32-b398-11ec3dd01eb5"><enum>(3)</enum><text>the toll-free contact
			 telephone numbers and addresses for the major credit reporting agencies.</text>
				</paragraph></subsection><subsection id="id3733c244-a08d-4a22-96c6-6f4613fa3443"><enum>(b)</enum><header>Additional
			 Content</header><text>Notwithstanding section 11, a State may require that a
			 notice under subsection (a) shall also include information regarding victim
			 protection assistance provided for by that State.</text>
			</subsection></section><section changed="added" committee-id="SSJU00" id="ideb0bfae1-1138-4ea9-8e01-34b47723a138" reported-display-style="italic"><enum>6.</enum><header>Coordination of
			 notification with credit reporting agencies</header><text display-inline="no-display-inline">If an agency or business entity is required
			 to provide notification to more than 5,000 individuals under section 2(a), the
			 agency or business entity shall also notify all consumer reporting agencies
			 that compile and maintain files on consumers on a nationwide basis (as defined
			 in section 603(p) of the <act-name parsable-cite="FCRA">Fair Credit Reporting
			 Act</act-name> (15 U.S.C. 1681a(p)) of the timing and distribution of the
			 notices. Such notice shall be given to the consumer credit reporting agencies
			 without unreasonable delay and, if it will not delay notice to the affected
			 individuals, prior to the distribution of notices to the affected
			 individuals.</text>
		</section><section changed="added" committee-id="SSJU00" id="id8da3943b-6d12-4a72-8bc7-5507f7b35fa4" reported-display-style="italic"><enum>7.</enum><header>Notice to law
			 enforcement</header>
			<subsection id="ID1b128642f69f4dedaf722f296a77ca46"><enum>(a)</enum><header>Designation of
			 government entity to receive notice</header>
				<paragraph id="ID0bd85eaeeb1c4f5a819f87a9400be64f"><enum>(1)</enum><header>In
			 general</header><text>Not later than 60 days after the date of enactment of
			 this Act, the Secretary of the Department of Homeland Security shall designate
			 a Federal Government entity to receive the notices required under this
			 section.</text>
				</paragraph><paragraph id="IDc78bf5db9444484ab89f3a28cd251273"><enum>(2)</enum><header>Responsibilities of the
			 designated entity</header><text>The designated entity shall promptly provide
			 the notices and other information it receives under this section to—</text>
					<subparagraph id="ID4789530476324c308e945fb5a60f5f54"><enum>(A)</enum><text>the United States Secret
			 Service;</text>
					</subparagraph><subparagraph id="IDebc686cf55c546fe86d5dcf6b59751cd"><enum>(B)</enum><text>the Federal Bureau of
			 Investigation;</text>
					</subparagraph><subparagraph id="ID88c2736fcc204737a313193df0cc0124"><enum>(C)</enum><text>the Federal Trade
			 Commission;</text>
					</subparagraph><subparagraph id="ID3551e8f6a9bf438984762379765ded27"><enum>(D)</enum><text>the United States Postal
			 Inspection Service, if the security breach involves mail fraud;</text>
					</subparagraph><subparagraph id="ID92cbc11cd08543c1a35d7a3ac9dc7516"><enum>(E)</enum><text>the attorney general of
			 each State affected by the security breach; and</text>
					</subparagraph><subparagraph id="ID64e4259eca444c1cbb2791463c190f3b"><enum>(F)</enum><text>as appropriate, to other
			 Federal agencies for law enforcement, national security, or data security
			 purposes.</text>
					</subparagraph></paragraph></subsection><subsection id="id9eb01a83-12ae-4b60-916d-be5366d85994"><enum>(b)</enum><header>Notice</header><text>Any
			 business entity or agency shall notify the designated entity of the fact that a
			 security breach has occurred if—</text>
				<paragraph id="idcfdf868e-8d5f-4882-a4f5-2b83196fb2c9"><enum>(1)</enum><text>the number of individuals
			 whose sensitive personally identifying information was, or is reasonably
			 believed to have been, accessed, or acquired by an unauthorized person exceeds
			 10,000;</text>
				</paragraph><paragraph id="idf58b9904-649b-4d0a-9b99-c2b6f103e012"><enum>(2)</enum><text>the security breach
			 involves a database, networked or integrated databases, or other data system
			 containing the sensitive personally identifiable information of more than
			 1,000,000 individuals nationwide;</text>
				</paragraph><paragraph id="idb5f61215-a532-47f0-baa3-3eaf6b756682"><enum>(3)</enum><text>the security breach
			 involves databases owned by the Federal Government; or</text>
				</paragraph><paragraph id="idf6805c78-7597-4828-95fb-6341b0366f84"><enum>(4)</enum><text>the security breach
			 involves primarily sensitive personally identifiable information of individuals
			 known to the agency or business entity to be employees or contractors of the
			 Federal Government involved in national security or law enforcement.</text>
				</paragraph></subsection><subsection id="id35ff640a-2742-415f-8613-5e4654914d91"><enum>(c)</enum><header>Timing of
			 notices</header><text>The notices required under this section shall be
			 delivered as follows:</text>
				<paragraph id="id6ab0b16c-6121-4469-8365-fc163e7dc371"><enum>(1)</enum><text>Notice under subsection
			 (b) shall be delivered as promptly as possible, but must occur not more than 72
			 hours before notification of an individual pursuant to section 2, or within 10
			 days after discovery of the events requiring notice, whichever occurs
			 first.</text>
				</paragraph><paragraph id="ide815b376-feec-4171-af39-3abb0fd157a3"><enum>(2)</enum><text>Notice under subsection
			 (a)(2) shall be delivered as promptly as possible after the designated entity
			 receives notice of a security breach from an agency or business entity.</text>
				</paragraph></subsection></section><section changed="added" committee-id="SSJU00" id="idd2ec303c-f7c7-4be9-a550-cba327d159e2" reported-display-style="italic"><enum>8.</enum><header>Enforcement</header>
			<subsection id="id9eb0f987-a379-47b5-8f49-7c14819851d8"><enum>(a)</enum><header>Civil actions by the
			 Attorney General</header><text>The Attorney General may bring a civil action in
			 the appropriate United States district court against any business entity that
			 engages in conduct constituting a violation of this Act and, upon proof of such
			 conduct by a preponderance of the evidence, such business entity shall be
			 subject to a civil penalty of not more than $11,000 per day per security
			 breach.</text>
			</subsection><subsection id="idBF6E6A4077004A72A1398EA61415586D"><enum>(b)</enum><header>Penalty
			 limitations</header>
				<paragraph id="id7e764419-b32e-44f6-8acb-4be09bc93534"><enum>(1)</enum><header>In
			 general</header><text>Notwithstanding any other provision of law, the total
			 amount of the civil penalty assessed against a business entity for conduct
			 involving the same or related acts or omissions that results in a violation of
			 this Act may not exceed $1,000,000, unless the violation was willful or
			 intentional.</text>
				</paragraph><paragraph id="id212001044B564AD2913A4B936E26C276"><enum>(2)</enum><header>Willful or intentional
			 violation</header><text>If a violation of this Act is found to be willful or
			 intentional, an additional civil penalty up to a maximum of $1,000,000 may be
			 imposed.</text>
				</paragraph></subsection><subsection id="id0C034C02DC9F4E17869EC98C3B09176C"><enum>(c)</enum><header>Injunctive actions by
			 the Attorney General</header>
				<paragraph id="id26817356-d30d-4f9f-9ca6-53df4e76e72f"><enum>(1)</enum><header>In
			 general</header><text>If it appears that a business entity has engaged, or is
			 engaged, in any act or practice constituting a violation of this Act, the
			 Attorney General may petition an appropriate district court of the United
			 States for an order—</text>
					<subparagraph id="id66e521d5-45ed-401c-881b-9a1c0e0a301d"><enum>(A)</enum><text>enjoining such act or
			 practice; or</text>
					</subparagraph><subparagraph id="id935d83ea-3a48-4a1f-9e59-64d0c6ffd2b5"><enum>(B)</enum><text>enforcing compliance with
			 this Act.</text>
					</subparagraph></paragraph><paragraph id="id0bb72ca2-67ef-4231-9ce5-2e8d2e8defd6"><enum>(2)</enum><header>Issuance of
			 order</header><text>A court may issue an order under paragraph (1), if the
			 court finds that the conduct in question constitutes a violation of this
			 Act.</text>
				</paragraph></subsection><subsection id="idbf2db5c7-f5ed-42f2-91fe-3d5382a808d4"><enum>(d)</enum><header>Other rights and
			 remedies</header><text>The rights and remedies available under this Act are
			 cumulative and shall not affect any other rights and remedies available under
			 law.</text>
			</subsection><subsection id="id0a5c7a12-49e2-4261-a007-1d4c195299c9"><enum>(e)</enum><header>Fraud
			 alert</header><text>Section 605A(b)(1) of the <act-name parsable-cite="FCRA">Fair Credit Reporting Act</act-name> (15 U.S.C.
			 1681c–1(b)(1)) is amended by inserting <quote>, or evidence that the consumer
			 has received notice that the consumer’s financial information has or may have
			 been compromised,</quote> after <quote>identity theft report</quote>.</text>
			</subsection></section><section changed="added" committee-id="SSJU00" id="idccd3f463-3de2-4995-827c-596d20b6427d" reported-display-style="italic"><enum>9.</enum><header>Enforcement by State
			 attorneys general</header>
			<subsection id="id559b1c73-1cf2-49ea-971d-07658c5fdf68"><enum>(a)</enum><header>In general</header>
				<paragraph id="id96165246-a900-47cc-b541-a282dc13d979"><enum>(1)</enum><header>Civil
			 actions</header><text>In any case in which the attorney general of a State or
			 any State or local law enforcement agency authorized by the State attorney
			 general or by State statute to prosecute violations of State consumer
			 protection law, has reason to believe that an interest of the residents of that
			 State has been or is threatened or adversely affected by the engagement of a
			 business entity in a practice that constitutes a violation of this Act, the
			 State or the State or local law enforcement agency on behalf of the residents
			 of the agency’s jurisdiction, may bring a civil action on behalf of the
			 residents of the State or jurisdiction in a district court of the United States
			 of appropriate jurisdiction or any other court of competent jurisdiction,
			 including a State court, to—</text>
					<subparagraph id="id6d34173e-6c7e-4f09-a56f-5c32a606d8ac"><enum>(A)</enum><text>enjoin that
			 practice;</text>
					</subparagraph><subparagraph id="idd3f31c4c-e184-4aba-befe-10f55f8185c9"><enum>(B)</enum><text>enforce compliance with
			 this Act; or</text>
					</subparagraph><subparagraph id="id37dd55ed-b6e5-4c98-9b52-f5ca76f52088"><enum>(C)</enum><text>obtain civil penalties of
			 not more than $11,000 per day per security breach.</text>
					</subparagraph></paragraph><paragraph id="idAC305D0F962B4BF18815FD1B9EC8C74B"><enum>(2)</enum><header>Overall maximum penalty
			 for actions brought by State attorneys general</header>
					<subparagraph id="id2091177E6B654576BDDE2B7F5B130AE5"><enum>(A)</enum><header>In
			 general</header><text>If more than 1 civil action is brought against a business
			 entity under this section and the civil actions all arose out of the same
			 security breach—</text>
						<clause id="id48092AC1D69343588D8F63E476E4576C"><enum>(i)</enum><text>the business entity may
			 file a motion, in any United States district court for the district in which
			 not less than 1 of the civil actions brought under this section is pending, to
			 consolidate the civil actions in such United States district court;</text>
						</clause><clause id="idBB00B9BB73FB4A74916BBE7A16A54680"><enum>(ii)</enum><text>the United States
			 district court in which a motion is filed under clause (i) shall order that the
			 civil actions be consolidated before such court; and</text>
						</clause><clause id="id8B990E329F284688BD557EDC38F6972D"><enum>(iii)</enum><text>any civil action
			 subsequently brought against the business entity under this section that arises
			 out of the same security breach at issue in the consolidated actions shall be
			 consolidated with the consolidated actions.</text>
						</clause></subparagraph><subparagraph id="id2EEE2AE2B3AE4BD29815E1E1D97BED72"><enum>(B)</enum><header>Transfer of
			 venue</header><text>If a United States district court issues an order described
			 in subparagraph (A)(ii), such court may, at anytime after the order is issued,
			 consider whether the consolidated actions should be transferred to another
			 district for the convenience of the parties and witnesses, in interest of
			 justice.</text>
					</subparagraph><subparagraph id="id784F3D6BE7DF405A92A0D5B221356405"><enum>(C)</enum><header>Penalty
			 limitations</header>
						<clause id="idED74A1DB096D444EB5A84857149C6E3D"><enum>(i)</enum><header>In
			 general</header><text>Notwithstanding any other provision of law, the total
			 amount of the civil penalty assessed against a business entity for conduct
			 involving the same or related acts or omissions that results in a violation of
			 this Act may not exceed $1,000,000, unless the violation was willful or
			 intentional.</text>
						</clause><clause id="id55B52C41B76245DC90BA9985D0A175AB"><enum>(ii)</enum><header>Willful or intentional
			 violation</header><text>If a violation of this Act is found to be willful or
			 intentional, an additional civil penalty up to a maximum of $1,000,000 may be
			 imposed.</text>
						</clause></subparagraph></paragraph><paragraph id="id1fa87104-c370-43c5-bc90-9f4fc4751b61"><enum>(3)</enum><header>Notice</header>
					<subparagraph id="ide2868448-9864-431b-ab50-8db8648c48d4"><enum>(A)</enum><header>In
			 general</header><text>Before filing an action under paragraph (1), the attorney
			 general of the State involved shall provide to the Attorney General of the
			 United States—</text>
						<clause id="id10e06ca0-2e65-4c2b-a6b0-2760cc985c9e"><enum>(i)</enum><text>written notice of the
			 action; and</text>
						</clause><clause id="idfb4bedcb-42a0-41c3-8468-71d4cc16f3b0"><enum>(ii)</enum><text>a copy of the complaint
			 for the action.</text>
						</clause></subparagraph><subparagraph id="id2b8babe1-55ed-4175-8b48-07dbedd4545f"><enum>(B)</enum><header>Exemption</header>
						<clause id="idcb30d234-a9be-4157-98ec-1f8ead77b872"><enum>(i)</enum><header>In
			 general</header><text>Subparagraph (A) shall not apply with respect to the
			 filing of an action by an attorney general of a State under this Act, if the
			 State attorney general determines that it is not feasible to provide the notice
			 described in such subparagraph before the filing of the action.</text>
						</clause><clause id="id97cce01a-3175-4f64-902a-b1f87eff0ec5"><enum>(ii)</enum><header>Notification</header><text>In
			 an action described in clause (i), the attorney general of a State shall
			 provide notice and a copy of the complaint to the Attorney General at the time
			 the State attorney general files the action.</text>
						</clause></subparagraph></paragraph></subsection><subsection id="idda44d313-896b-4bf8-8574-4e46199fb90a"><enum>(b)</enum><header>Federal
			 proceedings</header><text>Upon receiving notice under subsection (a)(3), the
			 Attorney General shall have the right to—</text>
				<paragraph id="id6194137e-d9ec-4839-9726-38b38d6fcaaa"><enum>(1)</enum><text>move to stay the action,
			 pending the final disposition of a pending Federal proceeding or action;</text>
				</paragraph><paragraph id="id9a162570-4476-4e16-9dcb-cf4154d3734d"><enum>(2)</enum><text>initiate an action in the
			 appropriate United States district court under section 8 and move to
			 consolidate all pending actions, including State actions, in such court;</text>
				</paragraph><paragraph id="id34abc545-cedc-4ea8-b95a-10752186f8fe"><enum>(3)</enum><text>intervene in an action
			 brought under subsection (a); and</text>
				</paragraph><paragraph id="id18cc2b2c-6b30-418a-9c7b-5398e7a55c74"><enum>(4)</enum><text>file petitions for
			 appeal.</text>
				</paragraph></subsection><subsection id="ide8b4529f-d915-43ea-a92b-3f05425fa40f"><enum>(c)</enum><header>Pending
			 proceedings</header><text>If the Attorney General has initiated a criminal
			 proceeding or civil action for a violation of this Act, no attorney general of
			 a State or any State or local law enforcement agency authorized by the State
			 attorney general or by State statute to prosecute violations of State consumer
			 protection law may bring an action for a violation of a provision of this Act
			 against a defendant named in the Federal criminal proceeding or civil
			 action.</text>
			</subsection><subsection id="id0f58ccbd-670c-47eb-9040-f508913037e3"><enum>(d)</enum><header>Rule of
			 construction</header><text>For purposes of bringing any civil action under
			 subsection (a), nothing in this Act regarding notification shall be construed
			 to prevent an attorney general of a State from exercising the powers conferred
			 on such attorney general by the laws of that State to—</text>
				<paragraph id="idc26ca87b-5d4b-408c-bbd1-c93bacd38489"><enum>(1)</enum><text>conduct
			 investigations;</text>
				</paragraph><paragraph id="id09b6fc0b-62a6-48ad-a528-74c13ce1a11a"><enum>(2)</enum><text>administer oaths or
			 affirmations; or</text>
				</paragraph><paragraph id="idba81ddd4-f49a-4864-ba84-5c5f12ae22aa"><enum>(3)</enum><text>compel the attendance of
			 witnesses or the production of documentary and other evidence.</text>
				</paragraph></subsection><subsection id="id9f884f2c-efcf-4e2c-80d9-b597f983d95c"><enum>(e)</enum><header>Venue; service of
			 process</header>
				<paragraph id="id0eb70ec1-a3a8-4678-b055-0a4fc3ffbd49"><enum>(1)</enum><header>Venue</header><text>Any
			 action brought under subsection (a) may be brought in—</text>
					<subparagraph id="id7591da3d-94ed-4fe3-8726-7e757bab6728"><enum>(A)</enum><text>the district court of the
			 United States that meets applicable requirements relating to venue under
			 section 1391 of title 28, United States Code; or</text>
					</subparagraph><subparagraph id="id705036a5-f11e-4fd5-9979-0a7527724627"><enum>(B)</enum><text>another court of
			 competent jurisdiction.</text>
					</subparagraph></paragraph><paragraph id="idcca8d3df-27de-4ef2-be79-3899bcf72f77"><enum>(2)</enum><header>Service of
			 process</header><text>In an action brought under subsection (a), process may be
			 served in any district in which the defendant—</text>
					<subparagraph id="idcf43bfaa-379c-4dce-87ab-f07b3b143224"><enum>(A)</enum><text>is an inhabitant;
			 or</text>
					</subparagraph><subparagraph id="id8cdc61b1-5b22-4fe1-b9f8-52fefb2acf61"><enum>(B)</enum><text>may be found.</text>
					</subparagraph></paragraph></subsection><subsection id="id99f6562a-facb-4d10-85bf-9b95e261e5e7"><enum>(f)</enum><header>No private cause of
			 action</header><text>Nothing in this Act establishes a private cause of action
			 against a business entity for violation of any provision of this Act.</text>
			</subsection></section><section changed="added" committee-id="SSJU00" id="ID8c1ca6d615b54e1394ea58a08edd54f4" reported-display-style="italic"><enum>10.</enum><header>Concealment of security
			 breach involving sensitive personally identifiable information</header>
			<subsection id="IDf2f07baad0044cd2a8526a2e41683d8b"><enum>(a)</enum><header>In
			 general</header><text>Chapter 47 of title 18, United States Code, is amended by
			 adding at the end the following:</text>
				<quoted-block changed="added" committee-id="SSJU00" display-inline="no-display-inline" id="id7576DA6532C4456681465667C3CFA75C" reported-display-style="italic" style="USC">
					<section id="IDb2e96de48bfe4d1f824f0fe387743af6"><enum>1041.</enum><header>Concealment of
				security breaches involving sensitive personally identifiable
				information</header>
						<subsection id="ID695bb7e91f7e4619aa39f92f4827f005"><enum>(a)</enum><header>In
				general</header><text>Any person who, having knowledge of a security breach and
				of the fact that notice of such security breach is required under the
				<short-title>Data Breach Notification Act of
				2011</short-title>, intentionally and willfully conceals the fact of such
				security breach, shall, in the event that such security breach results in
				economic harm to any individual in the amount of $1,000 or more, be fined under
				this title, imprisoned for not more than 5 years, or both.</text>
						</subsection><subsection id="ID6a2199e1e201478996fb8c5cd80287fd"><enum>(b)</enum><header>Person
				defined</header><text>For purposes of subsection (a), the term
				<term>person</term> has the same meaning as in section 1030(a)(12) of title 18,
				United States Code.</text>
						</subsection><subsection id="ID517e7242c6394d989535b6ccd124d90f"><enum>(c)</enum><header>Notice
				requirement</header><text>Any persons seeking an exemption under section 3(b)
				of the <short-title>Data Breach Notification Act of
				2011</short-title> shall be immune from prosecution under this section if the
				Federal Trade Commission does not indicate, in writing, that notice be given
				under such Act.</text>
						</subsection><subsection id="ID72f4b649c67a4e439ad8c688773fba09"><enum>(d)</enum><header>Enforcement
				authority</header>
							<paragraph id="ID34f113750517446593414bf6a9c50a46"><enum>(1)</enum><header>In
				general</header><text>The United States Secret Service and the Federal Bureau
				of Investigation shall have the authority to investigate offenses under this
				section.</text>
							</paragraph><paragraph id="ID4ba1e01c74ef4ba2b21c0bda43738a17"><enum>(2)</enum><header>Nonexclusivity</header><text>The
				authority granted in paragraph (1) shall not be exclusive of any existing
				authority held by any other Federal
				agency.</text>
							</paragraph></subsection></section><after-quoted-block>.</after-quoted-block></quoted-block>
			</subsection><subsection id="IDdc04a1c0adb34472954422f55fd99f2b"><enum>(b)</enum><header>Conforming and
			 technical amendments</header><text display-inline="yes-display-inline">The
			 table of sections for chapter 47 of title 18, United States Code, is amended by
			 adding at the end the following:</text>
				<quoted-block changed="added" committee-id="SSJU00" display-inline="no-display-inline" id="id9E4CE6C2FDE14FF4A7AF606B506D0A4B" reported-display-style="italic" style="OLC">
					<toc changed="added" committee-id="SSJU00" reported-display-style="italic">
						<toc-entry bold="off" level="section">1041. Concealment of security
				breaches involving sensitive personally identifiable
				information</toc-entry>
					</toc>
					<after-quoted-block>.</after-quoted-block></quoted-block>
			</subsection></section><section changed="added" committee-id="SSJU00" id="id3f4ea175-a252-4ce1-82d8-bb5e25ae2541" reported-display-style="italic"><enum>11.</enum><header>Effect on Federal and
			 State law</header>
			<subsection id="idE2732857D6C94044B2FE7655989B8EAD"><enum>(a)</enum><header>In
			 general</header><text display-inline="yes-display-inline">The provisions of
			 this Act shall supersede any other provision of Federal law or any provision of
			 law of any State relating to notification by a business entity engaged in
			 interstate commerce or an agency of a security breach, except as provided in
			 section 5(b).</text>
			</subsection><subsection id="ID01de264140f84c3987139a1318317863"><enum>(b)</enum><header>Limitations</header>
				<paragraph id="ID9bac0b80d35f42fe829a0ff80c87c29b"><enum>(1)</enum><header>Gramm-Leach-Bliley
			 Act</header><text>Nothing in this Act shall supersede the data security
			 requirements of the Gramm-Leach-Bliley Act (15 U.S.C. 6801 et seq.), or
			 implementing regulations issued under that Act.</text>
				</paragraph><paragraph id="IDf7ef149d8a1a40d88061e795d8feae07"><enum>(2)</enum><header>Health privacy</header>
					<subparagraph id="ID6044a0a3157c42e88b83e213f0effdce"><enum>(A)</enum><text>To the extent that a
			 business entity acts as a covered entity or a business associate under the
			 Health Information Technology for Economic and Clinical Health Act (42 U.S.C.
			 17932), and has the obligation to provide breach notification under that Act or
			 its implementing regulations, the requirements of this Act shall not
			 apply;</text>
					</subparagraph><subparagraph id="IDe44a483afa5040e88628185307dabbcb"><enum>(B)</enum><text>To the extent that a
			 business entity acts as a vendor of personal health records, a third party
			 service provider, or other entity subject to the Health Information Technology
			 for Economical and Clinical Health Act (42 U.S.C. 17937), and has the
			 obligation to provide breach notification under that Act or its implementing
			 regulations, the requirements of this Act shall not apply.</text>
					</subparagraph></paragraph></subsection></section><section changed="added" committee-id="SSJU00" id="ide7fee8df-0b4d-4aac-90ae-cd62af94a0ac" reported-display-style="italic"><enum>12.</enum><header>Authorization of
			 appropriations</header><text display-inline="no-display-inline">There are
			 authorized to be appropriated such sums as may be necessary to cover the costs
			 incurred by agencies to carry out investigations, risk assessments, and civil
			 actions relating to security breaches under this Act.</text>
		</section><section changed="added" committee-id="SSJU00" id="id850e10fb-349d-49c1-9e34-b7eeb31fafa7" reported-display-style="italic"><enum>13.</enum><header>Reporting on
			 exemptions</header>
			<subsection id="id41c4902a-0266-4dcf-8182-b4ffc5a633f4"><enum>(a)</enum><header>FTC reports</header>
				<paragraph id="idA0276E8A7663429792647C0EDAB0A0B1"><enum>(1)</enum><header>In
			 general</header><text display-inline="yes-display-inline">Not later than 18
			 months after the date of enactment of this Act, and upon the request by
			 Congress thereafter, the Federal Trade Commission shall submit to Congress a
			 report on the number and nature of the security breaches described in the
			 notices filed by those business entities invoking the risk assessment exemption
			 under section 3(b) of this Act and the response of the Federal Trade Commission
			 to such notices.</text>
				</paragraph><paragraph id="idCDBFF9F9427C482292912F18AA5532C8"><enum>(2)</enum><header>Prohibited
			 disclosure</header><text>Any report submitted under paragraph (1) shall not
			 disclose the contents of any risk assessment provided to the Federal Trade
			 Commission under this Act.</text>
				</paragraph></subsection><subsection id="idbdb5402c-3a61-4acc-9b4c-ba4d275295ad"><enum>(b)</enum><header>Law enforcement
			 reports</header><text>Not later than 18 months after the date of enactment of
			 this Act, and upon request by Congress thereafter, the United States Secret
			 Service and Federal Bureau of Investigation shall submit to Congress a report
			 on the number and nature of security breaches subject to the national security
			 and law enforcement exemptions under section 3(a) of this Act.</text>
			</subsection></section><section changed="added" committee-id="SSJU00" id="id28c7e1af-3d0b-4bd2-bb78-c9523fb37790" reported-display-style="italic"><enum>14.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act, the following definitions shall
			 apply:</text>
			<paragraph id="id825b1f27-7659-4ac5-8ef1-a837981660d7"><enum>(1)</enum><header>Agency</header><text>The
			 term <term>agency</term> has the same meaning given such term in section 551 of
			 title 5, United States Code.</text>
			</paragraph><paragraph id="idaba0775f-ebfa-45e3-930c-d657f7b60175"><enum>(2)</enum><header>Affiliate</header><text>The
			 term <term>affiliate</term> means persons related by common ownership or by
			 corporate control.</text>
			</paragraph><paragraph id="ide827ac60-5fc6-42d6-bb4f-e81efabed28d"><enum>(3)</enum><header>Business
			 entity</header><text>The term <term>business entity</term> means any
			 organization, corporation, trust, partnership, sole proprietorship,
			 unincorporated association, venture established to make a profit, or nonprofit,
			 and any contractor, subcontractor, affiliate, or licensee thereof engaged in
			 interstate commerce.</text>
			</paragraph><paragraph id="ID8ce630a5150a48d3967393df5f562a8f"><enum>(4)</enum><header>Designated
			 entity</header><text>The term <term>designated entity</term> means the Federal
			 Government entity designated by the Secretary of Homeland Security under
			 section 7.</text>
			</paragraph><paragraph id="idf0d5a4a7-49dc-4975-a44e-ec77470a048e"><enum>(5)</enum><header>Encrypted</header><text>The
			 term <term>encrypted</term>—</text>
				<subparagraph id="idce08c5f4-5c97-489e-8c27-29768919b378"><enum>(A)</enum><text>means the protection of
			 data in electronic form, in storage or in transit, using an encryption
			 technology that is generally accepted by experts in the field of information
			 security which renders such data indecipherable in the absence of associated
			 cryptographic keys necessary to enable decryption of such data; and</text>
				</subparagraph><subparagraph id="id51518956-32d5-4653-80bf-4c223f89c873"><enum>(B)</enum><text>includes appropriate
			 management and safeguards of such cryptographic keys so as to protect the
			 integrity of the encryption.</text>
				</subparagraph></paragraph><paragraph id="ideaf2de3b-1bcc-4c1c-9aa9-fd9bcd4f8d86"><enum>(6)</enum><header>Personally identifiable
			 information</header><text>The term <term>personally identifiable
			 information</term> means any information, or compilation of information, in
			 electronic or digital form serving as a means of identification, as defined by
			 section 1028(d)(7) of title 18, United State Code.</text>
			</paragraph><paragraph id="id6c8a960b-20b8-4225-8a34-0bf95c9da94e"><enum>(7)</enum><header>Security
			 breach</header>
				<subparagraph id="idf74bcded-f1d3-47e6-a070-428a265cf474"><enum>(A)</enum><header>In
			 general</header><text>The term <term>security breach</term> means compromise of
			 the security, confidentiality, or integrity of, or the loss of, computerized
			 data that results in, or there is a reasonable basis to conclude has resulted
			 in, acquisition of or access to sensitive personally identifiable information
			 that is unauthorized or in excess of authorization.</text>
				</subparagraph><subparagraph id="id8467f46a-7fa7-4506-a150-251d492029f8"><enum>(B)</enum><header>Exclusion</header><text>The
			 term <term>security breach</term> does not include—</text>
					<clause id="id8ab9bfd0-5140-4c8f-9dab-c497c1ee090d"><enum>(i)</enum><text>a good faith acquisition
			 of sensitive personally identifiable information by a business entity or
			 agency, or an employee or agent of a business entity or agency, if the
			 sensitive personally identifiable information is not subject to further
			 unauthorized disclosure;</text>
					</clause><clause id="IDa81161b5bc524019b3f7e71c2ce17e70"><enum>(ii)</enum><text>any lawfully authorized
			 investigative, protective, or intelligence activity of a law enforcement or
			 intelligence agency of the United States, a State, or a political subdivision
			 of a State; or</text>
					</clause><clause id="id3ec63b78-2f63-4b75-bf1b-882490c5ccd1"><enum>(iii)</enum><text>the release of a public
			 record not otherwise subject to confidentiality or nondisclosure
			 requirements.</text>
					</clause></subparagraph></paragraph><paragraph id="id2ba3ac67-588f-4d9a-ac2b-b6cdcc306b70"><enum>(8)</enum><header>Sensitive personally
			 identifiable information</header><text>The term <term>sensitive personally
			 identifiable information</term> means any information or compilation of
			 information, in electronic or digital form that includes—</text>
				<subparagraph id="id2367a167-714b-4676-9e01-f2ffce4f0097"><enum>(A)</enum><text>an individual’s first and
			 last name or first initial and last name in combination with any 1 of the
			 following data elements:</text>
					<clause id="ide1f370eb-da87-4b7c-bada-753b20ce84d3"><enum>(i)</enum><text>A non-truncated social
			 security number, driver’s license number, passport number, or alien
			 registration number.</text>
					</clause><clause id="ide1e0d1d2-b793-47b3-9c7a-8063d9c2b392"><enum>(ii)</enum><text>Any 2 of the
			 following:</text>
						<subclause id="id34b85cd8-8f83-41f9-bb46-54b2cd21a93d"><enum>(I)</enum><text>Home address or telephone
			 number.</text>
						</subclause><subclause id="id9a0b5afb-8b39-42b7-bd9d-69dcac681312"><enum>(II)</enum><text>Mother’s maiden name, if
			 identified as such.</text>
						</subclause><subclause id="id5433edaf-d05b-4260-973f-bc916afe8769"><enum>(III)</enum><text>Month, day, and year of
			 birth.</text>
						</subclause></clause><clause id="id43817f41-cd74-4962-b714-366e55ffe4cd"><enum>(iii)</enum><text>Unique biometric data
			 such as a finger print, voice print, a retina or iris image, or any other
			 unique physical representation.</text>
					</clause><clause id="id7e85dc39-e421-4d25-89bd-3a68a47ce643"><enum>(iv)</enum><text>A unique account
			 identifier, electronic identification number, user name, or routing code in
			 combination with any associated security code, access code, or password that is
			 required for an individual to obtain money, goods, services, or any other thing
			 of value; or</text>
					</clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id0c77e049-3cad-4bdb-b421-1dfc7fde45ce"><enum>(B)</enum><text>a financial account
			 number or credit or debit card number in combination with any security code,
			 access code, or password that is required for an individual to obtain credit,
			 withdraw funds, or engage in a financial transaction.</text>
				</subparagraph></paragraph></section><section changed="added" commented="no" committee-id="SSJU00" display-inline="no-display-inline" id="idbf713c13-f5bc-494d-9d9c-eb2c37f77c6a" reported-display-style="italic" section-type="subsequent-section"><enum>15.</enum><header>Effective
			 date</header><text display-inline="no-display-inline">This Act shall take
			 effect on the expiration of the date which is 90 days after the date of
			 enactment of this Act.</text>
		</section></legis-body>
	<endorsement>
		<action-date>February 6, 2012</action-date>
		<action-desc>Reported with an amendment</action-desc>
	</endorsement>
</bill>
