<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Reported-in-Senate" public-private="public">
	<form>
		<distribution-code display="yes">II</distribution-code>
		<calendar>Calendar No. 182</calendar>
		<congress>112th CONGRESS</congress>
		<session>1st Session</session>
		<legis-num>S. 1535</legis-num>
		<current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber>
		<action>
			<action-date date="20110908">September 8, 2011</action-date>
			<action-desc><sponsor name-id="S341">Mr. Blumenthal</sponsor> (for
			 himself and <cosponsor name-id="S332">Mr. Franken</cosponsor>) introduced the
			 following bill; which was read twice and referred to the
			 <committee-name added-display-style="italic" committee-id="SSJU00" deleted-display-style="strikethrough">Committee on the
			 Judiciary</committee-name></action-desc>
		</action>
		<action stage="Reported-in-Senate">
			<action-date>September 22, 2011</action-date>
			<action-desc>Reported by <sponsor name-id="S057">Mr. Leahy</sponsor>,
			 with an amendment</action-desc>
			<action-instruction>Strike out all after the enacting clause and insert
			 the part printed in italic</action-instruction>
		</action>
		<legis-type>A BILL</legis-type>
		<official-title display="yes">To protect consumers by mitigating the
		  vulnerability of personally identifiable information to theft through a
		  security breach, providing notice and remedies to consumers in the wake of such
		  a breach, holding companies accountable for preventable breaches, facilitating
		  the sharing of post-breach technical information between companies, and
		  enhancing criminal and civil penalties and other protections against the
		  unauthorized collection or use of personally identifiable
		  information.</official-title>
	</form>
	<legis-body display-enacting-clause="yes-display-enacting-clause" style="OLC">
		<section changed="deleted" commented="no" committee-id="SSJU00" display-inline="no-display-inline" id="idBC757BBC5D2D452AB3FEEC0A005925EB" reported-display-style="strikethrough" section-type="section-one"><enum>1.</enum><header display-inline="yes-display-inline">Short title; table of contents</header>
			<subsection commented="no" display-inline="no-display-inline" id="id0DC79081A5544A43ACEE0D3938C88A4A"><enum>(a)</enum><header display-inline="yes-display-inline">Short title</header><text display-inline="yes-display-inline">This Act may be cited as the
			 <quote><short-title>Personal Data Protection and Breach
			 Accountability Act of 2011</short-title></quote>.</text>
			</subsection><subsection commented="no" display-inline="no-display-inline" id="id908FE25517D846089A3520CDCB468544"><enum>(b)</enum><header display-inline="yes-display-inline">Table of contents</header><text display-inline="yes-display-inline">The table of contents of this Act is as
			 follows:</text>
				<toc changed="deleted" committee-id="SSJU00" reported-display-style="strikethrough">
					<toc-entry idref="idBC757BBC5D2D452AB3FEEC0A005925EB" level="section">Sec. 1. Short title; table of
				contents.</toc-entry>
					<toc-entry idref="idD75E514A664A45B39DAD2D9E8742B0E7" level="section">Sec. 2. Findings.</toc-entry>
					<toc-entry idref="IDd589748af4d840b1a53a75db7bdb7d32" level="section">Sec. 3. Definitions.</toc-entry>
					<toc-entry idref="id57BB7068312345C88A53B62678AE2D8A" level="title">TITLE I—Enhancing
				punishment for identity theft and other violations of data privacy and
				security</toc-entry>
					<toc-entry idref="IDbbbfe7823d8b4212aeab45071b480182" level="section">Sec. 101. Organized criminal activity in
				connection with unauthorized access to personally identifiable
				information.</toc-entry>
					<toc-entry idref="ID98057df8ce5e465296494f1084c8664c" level="section">Sec. 102. Concealment of security
				breaches involving sensitive personally identifiable information.</toc-entry>
					<toc-entry idref="idA19E197B95D54742A89513CA02E5A464" level="section">Sec. 103. Penalties for fraud and
				related activity in connection with computers.</toc-entry>
					<toc-entry idref="ID683573e5485643eea3d01d3e919e0c9f" level="section">Sec. 104. False
				notification.</toc-entry>
					<toc-entry idref="ID0ba8888617d74aaa8c3880d31b1d59cd" level="section">Sec. 105. Unauthorized installation of
				personal information collection features on a user's computer.</toc-entry>
					<toc-entry idref="idD725C42479864A1D94B301FF34A11C92" level="title">TITLE II—Privacy and
				security of personally identifiable information </toc-entry>
					<toc-entry idref="id3189B1C7B0974BA09A5D2EB0F2AA3456" level="subtitle">Subtitle A—A data privacy and security
				program</toc-entry>
					<toc-entry idref="ID48089945808a49b592f4356d4079eae6" level="section">Sec. 201. Purpose and applicability of
				data privacy and security program.</toc-entry>
					<toc-entry idref="ID01a5628cdcfe4d1aa8f738063c6c15c2" level="section">Sec. 202. Requirements for a personal
				data privacy and security program.</toc-entry>
					<toc-entry idref="ID5cac3211a25b4f26a2628faea99c9f36" level="section">Sec. 203. Federal
				enforcement.</toc-entry>
					<toc-entry idref="id2F1908FEFADB49B19264F6C00D6C8B7B" level="section">Sec. 204. Enforcement by State Attorneys
				General.</toc-entry>
					<toc-entry idref="ID8952766f976d4ef48ad73992dd4702e4" level="section">Sec. 205. Supplemental enforcement by
				individuals.</toc-entry>
					<toc-entry idref="idBC4FEB9AFE2A4E93BF957FCB6F00B7E3" level="subtitle">Subtitle B—Security breach
				notification</toc-entry>
					<toc-entry idref="ID5510cd0d499f4913941a3308d15e6a1c" level="section">Sec. 211. Notice to
				individuals.</toc-entry>
					<toc-entry idref="ID5dc909314300496fae2e47fd1f732bf2" level="section">Sec. 212. Exemptions from notice to
				individuals.</toc-entry>
					<toc-entry idref="IDbe5d0d5a9f634bfbbae2e9371a7cb5ab" level="section">Sec. 213. Methods of notice to
				individuals.</toc-entry>
					<toc-entry idref="ID80d1a786110544b1b9b1a5fa3fc173b3" level="section">Sec. 214. Content of notice to
				individuals.</toc-entry>
					<toc-entry idref="IDd1a9a538e2ea4808a43d262275fb8cfa" level="section">Sec. 215. Remedies for security
				breach.</toc-entry>
					<toc-entry idref="ID82ad6f96b46a4c7388f833d7611a6fc3" level="section">Sec. 216. Notice to credit reporting
				agencies.</toc-entry>
					<toc-entry idref="IDde1241e504f94594beb8e50db8943996" level="section">Sec. 217. Notice to law
				enforcement.</toc-entry>
					<toc-entry idref="ID300c058705674d1fa8a20180588bc781" level="section">Sec. 218. Federal
				enforcement.</toc-entry>
					<toc-entry idref="ID28d22f15074d4f239f64734d16e27d82" level="section">Sec. 219. Enforcement by State attorneys
				general.</toc-entry>
					<toc-entry idref="IDe9a2f5c9f18946eb836a3d703c1489b9" level="section">Sec. 220. Supplemental enforcement by
				individuals.</toc-entry>
					<toc-entry idref="IDa5c5ed85f5b948b08f30d0800295937a" level="section">Sec. 221. Relation to other
				laws.</toc-entry>
					<toc-entry idref="ID90730e6c13ca4a49b382b3f1e9ee896e" level="section">Sec. 222. Authorization of
				appropriations.</toc-entry>
					<toc-entry idref="ID0c5c8ec1f3e24cd886be5d8e2f850ca7" level="section">Sec. 223. Reporting on risk assessment
				exemptions.</toc-entry>
					<toc-entry idref="idA5C50B11C7414F79894531F4CFED06C9" level="subtitle">Subtitle C—Post-Breach technical
				information clearinghouse</toc-entry>
					<toc-entry idref="id4065DF23EA25436984EB9D2241C0450E" level="section">Sec. 230. Clearinghouse information
				collection, maintenance, and access.</toc-entry>
					<toc-entry idref="IDd2d7a89e15af43ec89ed1d424bae38b8" level="section">Sec. 231. Protections for clearinghouse
				participants.</toc-entry>
					<toc-entry idref="ID527ade6c074f448da6e7e220dd02a32e" level="section">Sec. 232. Effective date.</toc-entry>
					<toc-entry idref="id14E3D0E4F57E4B0A8C0C7207624800D1" level="title">TITLE III—Access to and
				use of commercial data</toc-entry>
					<toc-entry idref="ID12b6cb5e199e41929bf7df592fcd092f" level="section">Sec. 301. General services
				administration review of contracts.</toc-entry>
					<toc-entry idref="ID2c32eab739de4fea85488e717413b035" level="section">Sec. 302. Requirement to audit
				information security practices of contractors and third party business
				entities.</toc-entry>
					<toc-entry idref="ID4056fc3599c54deeb9c0ed352866c385" level="section">Sec. 303. Privacy impact assessment of
				government use of commercial information services containing personally
				identifiable information.</toc-entry>
					<toc-entry idref="IDa9f9d9e4f507470bbec0376f56e2d704" level="section">Sec. 304. FBI report on reported
				breaches and compliance.</toc-entry>
					<toc-entry idref="ID88bb272cdb2248499a23e4dfc0e06771" level="section">Sec. 305. Department of Justice report
				on enforcement actions.</toc-entry>
					<toc-entry idref="ID7a6f708f7aa6478a8b5c133959fd140d" level="section">Sec. 306. Department of Justice report
				on enforcement actions.</toc-entry>
					<toc-entry idref="ID0366fb23d1cb45d685d40473ea2fe486" level="section">Sec. 307. FBI report on notification
				effectiveness.</toc-entry>
					<toc-entry idref="idA76D6B98B64A432F88A7865C97AD99DC" level="title">TITLE IV—Compliance with
				Statutory Pay-As-You-Go Act</toc-entry>
					<toc-entry idref="idB4E6245612214115BF32E26DC4B83579" level="section">Sec. 401. Budget compliance.</toc-entry>
				</toc>
			</subsection></section><section changed="deleted" commented="no" committee-id="SSJU00" display-inline="no-display-inline" id="idD75E514A664A45B39DAD2D9E8742B0E7" reported-display-style="strikethrough" section-type="subsequent-section"><enum>2.</enum><header display-inline="yes-display-inline">Findings</header><text display-inline="no-display-inline">Congress finds that—</text>
			<paragraph commented="no" display-inline="no-display-inline" id="IDa2c4c47dabdd4ad69f2d0f1c654437a6"><enum>(1)</enum><text display-inline="yes-display-inline">databases of personally identifiable
			 information are increasingly prime targets of hackers, identity thieves, rogue
			 employees, and other criminals, including organized and sophisticated criminal
			 operations;</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID04489a6412b1456689d78954a66c7729"><enum>(2)</enum><text display-inline="yes-display-inline">identity theft is a serious threat to the
			 Nation’s economic stability, homeland security, the development of e-commerce,
			 and the privacy rights of Americans;</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID0f26ae456c634482bf20d8082e5eed11"><enum>(3)</enum><text display-inline="yes-display-inline">over 9,300,000 individuals were victims of
			 identity theft in America last year;</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID55cac62686074915bc385d99731c5481"><enum>(4)</enum><text display-inline="yes-display-inline">security breaches are a serious threat to
			 consumer confidence, homeland security, e-commerce, and economic
			 stability;</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID1bad624abb344fe7b015322715f9b15a"><enum>(5)</enum><text display-inline="yes-display-inline">it is important for business entities that
			 own, use, or license personally identifiable information to adopt reasonable
			 procedures to ensure the security, privacy, and confidentiality of that
			 personally identifiable information;</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDd019a164205942959431067393e87109"><enum>(6)</enum><text display-inline="yes-display-inline">individuals whose personal information has
			 been compromised or who have been victims of identity theft should receive the
			 necessary information and assistance to mitigate their damages and to restore
			 the integrity of their personal information and identities;</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDf40de8e698734cfd86baf4922b350a82"><enum>(7)</enum><text display-inline="yes-display-inline">data brokers have assumed a significant
			 role in providing identification, authentication, and screening services, and
			 related data collection and analyses for commercial, nonprofit, and government
			 operations;</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID7d7aeccd1b7f452bbe50b38a9cf86a12"><enum>(8)</enum><text display-inline="yes-display-inline">data misuse and use of inaccurate data have
			 the potential to cause serious or irreparable harm to an individual’s
			 livelihood, privacy, and liberty and undermine efficient and effective business
			 and government operations;</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID454f8fced90146e0a8af810896df63ca"><enum>(9)</enum><text display-inline="yes-display-inline">there is a need to ensure that data brokers
			 conduct their operations in a manner that prioritizes fairness, transparency,
			 accuracy, and respect for the privacy of consumers;</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID59394f800d994f31a1158c488c7d4fff"><enum>(10)</enum><text display-inline="yes-display-inline">government access to commercial data can
			 potentially improve safety, law enforcement, and national security;</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID80b5a6bc1c2d448f94909dc0ee00bdac"><enum>(11)</enum><text display-inline="yes-display-inline">because government use of commercial data
			 containing personal information potentially affects individual privacy, and law
			 enforcement and national security operations, there is a need for Congress to
			 exercise oversight over government use of commercial data;</text>
			</paragraph><paragraph id="ID8b28850b67534c5a97289f8f0d265296"><enum>(12)</enum><text>over 22,960,000
			 cases of data breaches involving personally identifiable information were
			 reported through July of 2011, and in 2009 through 2010, over 230,900,000 cases
			 of personal data breaches were reported;</text>
			</paragraph><paragraph id="ID4810d70cdbf04e32b4cf2751ec71a9b3"><enum>(13)</enum><text>facilitating
			 information sharing among business entities and across sectors in the event of
			 a breach can assist in remediating the breach and preventing similar breaches
			 in the future;</text>
			</paragraph><paragraph id="ID6995b1ccf8d34f08b210d4e3b72b657e"><enum>(14)</enum><text>because the
			 Federal Government has limited resources, consumers themselves play a vital and
			 complementary role in facilitating prompt notification and protecting against
			 future breaches of security;</text>
			</paragraph><paragraph id="ID21f4ffd5d29c4e72bd615d4edd890038"><enum>(15)</enum><text>in addition to
			 the immediate damages caused by security breaches, the lack of basic remedial
			 requirements often forces individuals whose sensitive personally identifiable
			 information is compromised as a result of a security breach to incur the
			 economic costs of litigation to seek remedies, and the economic costs of fees
			 required in many States to freeze compromised accounts; and</text>
			</paragraph><paragraph id="IDb1b96c1fc43346848910deb643781f2e"><enum>(16)</enum><text>victims of
			 personal data breaches may suffer debilitating emotional and physical effects
			 and become depressed or anxious, especially in cases of repeated or unresolved
			 instances of data breaches.</text>
			</paragraph></section><section changed="deleted" commented="no" committee-id="SSJU00" display-inline="no-display-inline" id="IDd589748af4d840b1a53a75db7bdb7d32" reported-display-style="strikethrough" section-type="subsequent-section"><enum>3.</enum><header display-inline="yes-display-inline">Definitions</header><text display-inline="no-display-inline">In this Act, the following definitions shall
			 apply:</text>
			<paragraph commented="no" display-inline="no-display-inline" id="IDe27e8f808b154a4e82175769e61f717c"><enum>(1)</enum><header display-inline="yes-display-inline">Affiliate</header><text display-inline="yes-display-inline">The term <term>affiliate</term> means
			 persons related by common ownership or by corporate control.</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID6b46a295351f45bca8862eaacaa06801"><enum>(2)</enum><header display-inline="yes-display-inline">Agency</header><text display-inline="yes-display-inline">The term <term>agency</term> has the
			 meaning given such term in section 551 of title 5, United States Code.</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID45177ec08eb54f5d85a71563525e94e8"><enum>(3)</enum><header display-inline="yes-display-inline">Business entity</header><text display-inline="yes-display-inline">The term <term>business entity</term> means
			 any organization, corporation, trust, partnership, sole proprietorship,
			 unincorporated association, or venture established to make a profit, or
			 nonprofit.</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id80B2909E7F044C5E940838F12F00E104"><enum>(4)</enum><header>Credit rating
			 agency</header><text display-inline="yes-display-inline">The term <term>credit
			 rating agency</term> has the meaning given such term in section 3(a)(61) of the
			 Securities Exchange Act of 1934 (12 U.S.C. 78c(a)(61)).</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id0BAF13E60C564DD78D3A5F2147D85A42"><enum>(5)</enum><header>Credit
			 report</header><text>The term <term>credit report</term> means a consumer
			 report, as that term is defined in section 603 of the Fair Credit Reporting Act
			 (15 U.S.C. 1681a).</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID421132fe62314202b0a6b558eff900fc"><enum>(6)</enum><header display-inline="yes-display-inline">Data broker</header><text display-inline="yes-display-inline">The term <term>data broker</term> means a
			 business entity which for monetary fees or dues regularly engages in the
			 practice of collecting, transmitting, or providing access to sensitive
			 personally identifiable information on more than 5,000 individuals who are not
			 the customers or employees of that business entity or affiliate primarily for
			 the purposes of providing such information to nonaffiliated third parties on an
			 interstate basis.</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID3b80cbb1dae54c41bd803298c33a4114"><enum>(7)</enum><header display-inline="yes-display-inline">Data
			 furnisher</header><text display-inline="yes-display-inline">The term <term>data
			 furnisher</term> means any agency, organization, corporation, trust,
			 partnership, sole proprietorship, unincorporated association, or nonprofit that
			 serves as a source of information for a data broker.</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="idEAC844C6681D485491A58D0D6134494F"><enum>(8)</enum><header display-inline="yes-display-inline">Encryption</header><text display-inline="yes-display-inline">The term <quote>encryption</quote>—</text>
				<subparagraph commented="no" display-inline="no-display-inline" id="idFD707E02AC4E4C45814FE3598C7CA84C"><enum>(A)</enum><text display-inline="yes-display-inline">means the protection of data in electronic
			 form, in storage or in transit, using an encryption technology that has been
			 adopted by a widely accepted standards setting body or, has been widely
			 accepted as an effective industry practice which renders such data
			 indecipherable in the absence of associated cryptographic keys necessary to
			 enable decryption of such data; and</text>
				</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idD50D1D0CAFC8461F94DBAF994610965F"><enum>(B)</enum><text display-inline="yes-display-inline">includes appropriate management and
			 safeguards of such cryptographic keys so as to protect the integrity of the
			 encryption.</text>
				</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDbb1410bcbaed48e09a39a9d58c592601"><enum>(9)</enum><header display-inline="yes-display-inline">Identity
			 theft</header><text display-inline="yes-display-inline">The term <term>identity
			 theft</term> means a violation of section 1028(a)(7) of title 18, United States
			 Code.</text>
			</paragraph><paragraph id="IDdb32691ed86548ee9c7f75c4dc97ed21"><enum>(10)</enum><header>Intelligence
			 community</header><text>The term <term>intelligence community</term> includes
			 the following:</text>
				<subparagraph id="IDd7b261e64ec74163ad0be27a8d34513f"><enum>(A)</enum><text>The Office of the
			 Director of National Intelligence.</text>
				</subparagraph><subparagraph id="IDaa2f95f184fe48b1b370163402055df2"><enum>(B)</enum><text>The Central
			 Intelligence Agency.</text>
				</subparagraph><subparagraph id="IDded78a674b7d4737b0892ed6667804f8"><enum>(C)</enum><text>The National
			 Security Agency.</text>
				</subparagraph><subparagraph id="IDa7011d2e56d14049a50f7d51369d5d89"><enum>(D)</enum><text>The Defense
			 Intelligence Agency.</text>
				</subparagraph><subparagraph id="ID514cfd4cf5c1412495d03704a443a846"><enum>(E)</enum><text>The National
			 Geospatial-Intelligence Agency.</text>
				</subparagraph><subparagraph id="ID04f6417c4c664dcaaf4beb2765d3c1ac"><enum>(F)</enum><text>The National
			 Reconnaissance Office.</text>
				</subparagraph><subparagraph id="ID89bd585ce6674f6a90d70fbbc4336f16"><enum>(G)</enum><text>Other offices
			 within the Department of Defense for the collection of specialized national
			 intelligence through reconnaissance programs.</text>
				</subparagraph><subparagraph id="ID569d429f8b564175bd3b09f86c188d37"><enum>(H)</enum><text>The intelligence
			 elements of the Army, the Navy, the Air Force, the Marine Corps, the Federal
			 Bureau of Investigation, and the Department of Energy.</text>
				</subparagraph><subparagraph id="ID3e9893511af94ae89771e6b785fc77fa"><enum>(I)</enum><text>The Bureau of
			 Intelligence and Research of the Department of State.</text>
				</subparagraph><subparagraph id="IDf20a4df7d3f74467afd729b2086db2e7"><enum>(J)</enum><text>The Office of
			 Intelligence and Analysis of the Department of the Treasury.</text>
				</subparagraph><subparagraph id="ID845785f3093845be849093fe2b1b07d9"><enum>(K)</enum><text>The elements of
			 the Department of Homeland Security concerned with the analysis of intelligence
			 information, including the Office of Intelligence of the Coast Guard.</text>
				</subparagraph><subparagraph id="IDeef457fa4e034b54ac30f50b84dcbc09"><enum>(L)</enum><text>Such other
			 elements of any other department or agency as may be designated by the
			 President, or designated jointly by the Director of National Intelligence and
			 the head of the department or agency concerned, as an element of the
			 intelligence community.</text>
				</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID708763bb5a6547018d66b9e4109a7115"><enum>(11)</enum><header display-inline="yes-display-inline">Personal electronic record</header>
				<subparagraph commented="no" display-inline="no-display-inline" id="ID5481d7730bee42ea9d77786a3ae95139"><enum>(A)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">The term <term>personal electronic
			 record</term> means data associated with an individual contained in a database,
			 networked or integrated databases, or other data system that is provided by a
			 data broker to nonaffiliated third parties and includes personally identifiable
			 information about that individual.</text>
				</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID4369a17e080f4a348ad99bf88bea9f3e"><enum>(B)</enum><header display-inline="yes-display-inline">Exclusions</header><text display-inline="yes-display-inline">The term <term>personal electronic
			 record</term> does not include—</text>
					<clause commented="no" display-inline="no-display-inline" id="IDd02a1a34ad8d4162b7dbfb508757011b"><enum>(i)</enum><text display-inline="yes-display-inline">any data related to an individual’s past
			 purchases of consumer goods; or</text>
					</clause><clause commented="no" display-inline="no-display-inline" id="IDeed2686065464aa3872c933c3dca25b4"><enum>(ii)</enum><text display-inline="yes-display-inline">any proprietary assessment or evaluation of
			 an individual or any proprietary assessment or evaluation of information about
			 an individual.</text>
					</clause></subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID277a6f9dfb7b437db77f20ff4f84aca8"><enum>(12)</enum><header display-inline="yes-display-inline">Personally identifiable
			 information</header><text display-inline="yes-display-inline">The term
			 <term>personally identifiable information</term> means any information, or
			 compilation of information, in electronic or digital form that is a means of
			 identification (as defined in section 1028(d)(7) of title 18, United State
			 Code).</text>
			</paragraph><paragraph id="IDef4a940fb53f41f6839d6947a5373e9a"><enum>(13)</enum><header>Predispute
			 arbitration agreement</header><text>The term <term>predispute arbitration
			 agreement</term> means any agreement to arbitrate a dispute that had not yet
			 arisen at the time of the making of the agreement.</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID3d90719ddb9d4d89ac2511f5d43030d5"><enum>(14)</enum><header display-inline="yes-display-inline">Public record source</header><text display-inline="yes-display-inline">The term <term>public record source</term>
			 means the Congress, any agency, any State or local government agency, the
			 government of the District of Columbia and governments of the territories or
			 possessions of the United States, and Federal, State or local courts, courts
			 martial and military commissions, that maintain personally identifiable
			 information in records available to the public.</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDcf447112b33241bbafa2e1679b5ed4fd"><enum>(15)</enum><header display-inline="yes-display-inline">Security breach</header>
				<subparagraph id="ID4f6cc463ce3a43cc9d9468643621f576"><enum>(A)</enum><header>In
			 general</header><text>The term <term>security breach</term> means compromise of
			 the security, confidentiality, or integrity of computerized data through
			 misrepresentation or actions—</text>
					<clause id="id2E5CB24316CD4038BD8996CF18051284"><enum>(i)</enum><text>that result in, or
			 that there is a reasonable basis to conclude has resulted in—</text>
						<subclause id="id1D21D4D90E204731BBCD90F4CBA874DD"><enum>(I)</enum><text>the unauthorized
			 acquisition of sensitive personally identifiable information; or</text>
						</subclause><subclause id="id46FF6FA1411F47D28B11A8545EC4155B"><enum>(II)</enum><text>access to
			 sensitive personally identifiable information that is for an unauthorized
			 purpose, or in excess of authorization; and</text>
						</subclause></clause><clause id="idCC91657CD4094E0FA3526CAF9E921318"><enum>(ii)</enum><text>which present a
			 significant risk of harm or fraud to any individual.</text>
					</clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID32aadcee3e724a14a6ff42e11bcda31d"><enum>(B)</enum><header display-inline="yes-display-inline">Exclusion</header><text display-inline="yes-display-inline">The term <term>security breach</term> does
			 not include—</text>
					<clause commented="no" display-inline="no-display-inline" id="IDdaa3112ae3d7459abf9485ef3d7d77ad"><enum>(i)</enum><text display-inline="yes-display-inline">a good faith acquisition of sensitive
			 personally identifiable information by a business entity or agency, or an
			 employee or agent of a business entity or agency, if the sensitive personally
			 identifiable information is not subject to further unauthorized
			 disclosure;</text>
					</clause><clause commented="no" display-inline="no-display-inline" id="idD5FF6A5E552942ECBD9BB5200E4A06A1"><enum>(ii)</enum><text display-inline="yes-display-inline">the release of a public record not
			 otherwise subject to confidentiality or nondisclosure requirements; or</text>
					</clause><clause id="ID2f0ff32004a1469a98223f62446ae736"><enum>(iii)</enum><text>any lawfully
			 authorized criminal investigation or authorized investigative, protective, or
			 intelligence activities that are carried out by or on behalf of any element of
			 the intelligence community and conducted in accordance with the United States
			 laws, authorities, and regulations governing such intelligence
			 activities.</text>
					</clause></subparagraph></paragraph><paragraph id="IDa72f456fe5b644898e587bd06f3f1c23"><enum>(16)</enum><header>Security
			 freeze</header><text>The term <term>security freeze</term> means a notice, at
			 the request of the consumer and subject to exceptions in section 215(b), that
			 prohibits the consumer reporting agency from releasing all or any part of the
			 consumer’s credit report or any information derived from it without the express
			 authorization of the consumer.</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDe99b189310e04a72969f33adb3158514"><enum>(17)</enum><header display-inline="yes-display-inline">Sensitive personally identifiable
			 information</header><text display-inline="yes-display-inline">The term
			 <term>sensitive personally identifiable information</term> means any
			 information or compilation of information, in electronic or digital form that
			 includes—</text>
				<subparagraph commented="no" display-inline="no-display-inline" id="ID3dc22ad332974f5f8df1fdb0edb915b2"><enum>(A)</enum><text display-inline="yes-display-inline">an individual's first and last name or
			 first initial and last name in combination with any 1 of the following data
			 elements:</text>
					<clause commented="no" display-inline="no-display-inline" id="ID78ada63e7c82488dac32cd2b523ccaab"><enum>(i)</enum><text display-inline="yes-display-inline">A nontruncated social security number,
			 driver's license number, passport number, or alien registration number.</text>
					</clause><clause commented="no" display-inline="no-display-inline" id="ID8b166ce6db234d039fa880e8311901c3"><enum>(ii)</enum><text display-inline="yes-display-inline">Any 2 of the following:</text>
						<subclause commented="no" display-inline="no-display-inline" id="ID32ce80211bca4306a8ee62599e1fec11"><enum>(I)</enum><text display-inline="yes-display-inline">Home address.</text>
						</subclause><subclause commented="no" display-inline="no-display-inline" id="id17FC2083E5F24B11BCA8371A42CA50CB"><enum>(II)</enum><text display-inline="yes-display-inline">Telephone number.</text>
						</subclause><subclause commented="no" display-inline="no-display-inline" id="IDa0d1db2d079740468b98f0a7696a13c0"><enum>(III)</enum><text display-inline="yes-display-inline">Mother's maiden name.</text>
						</subclause><subclause commented="no" display-inline="no-display-inline" id="ID1ec42025860143229b6bd52e8434a072"><enum>(IV)</enum><text display-inline="yes-display-inline">Month, day, and year of birth.</text>
						</subclause></clause><clause commented="no" display-inline="no-display-inline" id="ID8c601c35ad2d4a809aeeee8f9e1a3fff"><enum>(iii)</enum><text display-inline="yes-display-inline">Unique biometric data such as a finger
			 print, voice print, a retina or iris image, or any other unique physical
			 representation.</text>
					</clause><clause commented="no" display-inline="no-display-inline" id="ID5ebc421720fb4463a4f69f324113db8c"><enum>(iv)</enum><text display-inline="yes-display-inline">A unique account identifier, electronic
			 identification number, user name, or routing code in combination with any
			 associated security code, access code, or password if the code or password is
			 required for an individual to obtain money, goods, services, or any other thing
			 of value;</text>
					</clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDb275561b64d34e31823ff4a792b2b881"><enum>(B)</enum><text display-inline="yes-display-inline">a financial account number or credit or
			 debit card number in combination with any security code, access code, or
			 password that is required for an individual to obtain credit, withdraw funds,
			 or engage in a financial transaction; or</text>
				</subparagraph><subparagraph id="ID7bd0ef99435f4610a0e393fdc0a61753"><enum>(C)</enum><text>any other
			 combination of data elements that could allow unauthorized access to or
			 acquisition of the information described in subparagraph (A) or (B),
			 including—</text>
					<clause id="id620ABE9A2CBA441A8EE55A5C605CFD69"><enum>(i)</enum><text>a unique account
			 identifier;</text>
					</clause><clause id="id14E87E462F8B4F36A7F9FDA91551BF29"><enum>(ii)</enum><text>an electronic
			 identification number;</text>
					</clause><clause id="id19500D245546423887CE046FB0752E11"><enum>(iii)</enum><text>a user
			 name;</text>
					</clause><clause id="idA91E6591E24E451FA9423E10CF2659E8"><enum>(iv)</enum><text>a routing code;
			 or</text>
					</clause><clause id="id05A3640B937F44E3AB9B4D02E8996888"><enum>(v)</enum><text>any associated
			 security code, access code, or password or any associated security questions
			 and answers that could allow unauthorized access to the account.</text>
					</clause></subparagraph></paragraph></section><title changed="deleted" commented="no" committee-id="SSJU00" id="id57BB7068312345C88A53B62678AE2D8A" level-type="subsequent" reported-display-style="strikethrough"><enum>I</enum><header display-inline="yes-display-inline">Enhancing punishment for identity theft and
			 other violations of data privacy and security</header>
			<section commented="no" display-inline="no-display-inline" id="IDbbbfe7823d8b4212aeab45071b480182" section-type="subsequent-section"><enum>101.</enum><header display-inline="yes-display-inline">Organized criminal activity in connection
			 with unauthorized access to personally identifiable information</header><text display-inline="no-display-inline">Section 1961(1) of title 18, United States
			 Code, is amended by inserting <quote>section 1030 (relating to fraud and
			 related activity in connection with computers) if the act is a felony,</quote>
			 before <quote>section 1084</quote>.</text>
			</section><section commented="no" display-inline="no-display-inline" id="ID98057df8ce5e465296494f1084c8664c" section-type="subsequent-section"><enum>102.</enum><header display-inline="yes-display-inline">Concealment of security breaches involving
			 sensitive personally identifiable information</header>
				<subsection commented="no" display-inline="no-display-inline" id="ID574a854e62eb447bb4f50ec14b792143"><enum>(a)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">Chapter 47 of title 18, United States Code,
			 is amended by adding at the end the following:</text>
					<quoted-block changed="deleted" committee-id="SSJU00" display-inline="no-display-inline" id="idF9342237D76A4CEAAE27A5A099B89861" reported-display-style="strikethrough" style="USC">
						<section commented="no" display-inline="no-display-inline" id="IDa347d393004b4e53878f3745e4bd6e88" section-type="subsequent-section"><enum>1041.</enum><header display-inline="yes-display-inline">Concealment of security breaches involving
				sensitive personally identifiable information</header>
							<subsection commented="no" display-inline="no-display-inline" id="ID4bcfaf400ddf414582209c7244832564"><enum>(a)</enum><text display-inline="yes-display-inline">Whoever, having knowledge of a security
				breach and having the obligation to provide notice of such breach to
				individuals under the <short-title>Personal Data
				Protection and Breach Accountability Act of 2011</short-title>, and having not
				otherwise qualified for an exemption from providing notice under section 212 of
				the <short-title>Personal Data Protection and Breach
				Accountability Act of 2011</short-title>, intentionally or willfully conceals
				the fact of such security breach and which breach causes economic damage or
				substantial emotional distress to 1 or more persons, shall be fined under this
				title or imprisoned not more than 5 years, or both.</text>
							</subsection><subsection commented="no" display-inline="no-display-inline" id="IDa6c6cc34315f4ba599f4b63575125021"><enum>(b)</enum><text display-inline="yes-display-inline">For purposes of subsection (a), the term
				<term>person</term> has the same meaning as in section 1030(e)(12) of title 18,
				United States Code.</text>
							</subsection><subsection commented="no" display-inline="no-display-inline" id="id8463FC3B2CCE41E0A211E3946F886E25"><enum>(c)</enum><text display-inline="yes-display-inline">Any person seeking an exemption under
				section 212(b) of the <short-title>Personal Data
				Protection and Breach Accountability Act of 2011</short-title> shall be immune
				from prosecution under this section if the United States Secret Service does
				not indicate, in writing, that such notice be given under section 212(b)(3) of
				the <short-title>Personal Data Protection and Breach
				Accountability Act of
				2011</short-title>.</text>
							</subsection></section><after-quoted-block>.</after-quoted-block></quoted-block>
				</subsection><subsection commented="no" display-inline="no-display-inline" id="IDe250299bce944fcb9cedfd92fc33a8c7"><enum>(b)</enum><header display-inline="yes-display-inline">Conforming and technical
			 amendments</header><text display-inline="yes-display-inline">The table of
			 sections for chapter 47 of title 18, United States Code, is amended by adding
			 at the end the following:</text>
					<quoted-block changed="deleted" committee-id="SSJU00" display-inline="no-display-inline" id="id4A4F3645F72549419DD8D57CB66D2322" reported-display-style="strikethrough" style="OLC">
						<toc changed="deleted" committee-id="SSJU00" reported-display-style="strikethrough">
							<toc-entry bold="off" level="section">1041. Concealment of
				security breaches involving personally identifiable
				information.</toc-entry>
						</toc>
						<after-quoted-block>.</after-quoted-block></quoted-block>
				</subsection><subsection commented="no" display-inline="no-display-inline" id="ID0cfb1f2062d849319cbd7ed151526023"><enum>(c)</enum><header display-inline="yes-display-inline">Enforcement authority</header>
					<paragraph commented="no" display-inline="no-display-inline" id="id74BEB32B70524064BF1CC860F6B7ADD3"><enum>(1)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">The United States Secret Service shall have
			 the authority to investigate offenses under this section.</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id7117EAAA2D194B5A824D86D68273DD2E"><enum>(2)</enum><header display-inline="yes-display-inline">Nonexclusivity</header><text display-inline="yes-display-inline">The authority granted in paragraph (1)
			 shall not be exclusive of any existing authority held by any other Federal
			 agency.</text>
					</paragraph></subsection></section><section id="idA19E197B95D54742A89513CA02E5A464"><enum>103.</enum><header>Penalties for
			 fraud and related activity in connection with computers</header><text display-inline="no-display-inline">Section 1030(c) of title 18, United States
			 Code, is amended—</text>
				<paragraph id="id4C551329A38A4DB68DCC711A3E3E4285"><enum>(1)</enum><text>by inserting
			 <quote>or conspiracy</quote> after <quote>or an attempt</quote> each place it
			 appears, except for paragraph (4);</text>
				</paragraph><paragraph id="idBE6035DAE4744EAB815A11003072D92C"><enum>(2)</enum><text>in paragraph
			 (2)(B)—</text>
					<subparagraph id="id4CB555489CAA4A35BCA2E5443BF6E299"><enum>(A)</enum><text>in clause (i), by
			 inserting <quote>, or attempt or conspiracy or conspiracy to commit an
			 offense,</quote> after <quote>the offense</quote>;</text>
					</subparagraph><subparagraph id="idEDF2B66576E34FDCBD9BC712CFB4230C"><enum>(B)</enum><text>in clause (ii), by
			 inserting <quote>, or attempt or conspiracy or conspiracy to commit an
			 offense,</quote> after <quote>the offense</quote>; and</text>
					</subparagraph><subparagraph id="id042AED36F20341DBA9E9E2307683C198"><enum>(C)</enum><text>in clause (iii),
			 by inserting <quote>(or, in the case of an attempted offense, would, if
			 completed, have obtained)</quote> after <quote>information obtained</quote>;
			 and</text>
					</subparagraph></paragraph><paragraph id="id4D9ED00754874F1593623A9E35C78D6C"><enum>(3)</enum><text>in paragraph
			 (4)—</text>
					<subparagraph id="id88548A8C02654883AEECA3D1D7714323"><enum>(A)</enum><text>in subparagraph
			 (A)—</text>
						<clause id="id8E2096A2BFB7420B9E0C6BE68085C8F5"><enum>(i)</enum><text>by striking clause
			 (ii);</text>
						</clause><clause id="idB1F64FA30B7442E189C7606F2ECD6534"><enum>(ii)</enum><text>by striking
			 <quote>in the case of—</quote> and all that follows through <quote>an offense
			 under subsection (a)(5)(B)</quote> and inserting <quote>in the case of an
			 offense, or an attempt or conspiracy to commit an offense, under subsection
			 (a)(5)(B)</quote>;</text>
						</clause><clause id="id400769E67412484DBEC2FB2B95EC6ECE"><enum>(iii)</enum><text>by inserting
			 <quote>or conspiracy</quote> after <quote>if the offense</quote>;</text>
						</clause><clause id="id3A67AB5234E74D84A0162E40D70E8185"><enum>(iv)</enum><text>by redesignating
			 subclauses (I) through (VI) as clauses (i) through (vi), respectively, and
			 adjusting the margin accordingly; and</text>
						</clause><clause id="id970557CE4E214D7EA02E4D84B4EE543C"><enum>(v)</enum><text>in clause (vi), as
			 so redesignated, by striking <quote>; or</quote> and inserting a
			 semicolon;</text>
						</clause></subparagraph><subparagraph id="id4A8CD47BF5384D80B907FF172A71E9E3"><enum>(B)</enum><text>in subparagraph
			 (B)—</text>
						<clause id="id757A7CBA720A45C29333229C5D071D5A"><enum>(i)</enum><text>by striking clause
			 (ii);</text>
						</clause><clause id="id1D7333828A6B419C80D75811FF508168"><enum>(ii)</enum><text>by striking
			 <quote>in the case of—</quote> and all that follows through <quote>an offense
			 under subsection (a)(5)(A)</quote> and inserting <quote>in the case of an
			 offense, or an attempt or conspiracy to commit an offense, under subsection
			 (a)(5)(A)</quote>;</text>
						</clause><clause id="idBE6B738E28184042AF6CEF4C99BA0789"><enum>(iii)</enum><text>by inserting
			 <quote>or conspiracy</quote> after <quote>if the offense</quote>; and</text>
						</clause><clause id="id290DEDC7D5B44BC98D5892B14B654115"><enum>(iv)</enum><text>by striking
			 <quote>; or</quote> and inserting a semicolon;</text>
						</clause></subparagraph><subparagraph id="id9C7164388E4240ADA22F1DB9F523A69A"><enum>(C)</enum><text>in subparagraph
			 (C)—</text>
						<clause id="id0561CA2EACE2427B94189E2165AC3137"><enum>(i)</enum><text>by striking clause
			 (ii);</text>
						</clause><clause id="id0968B5BC142D4034A3C6449E4EFB07A2"><enum>(ii)</enum><text>by striking
			 <quote>in the case of—</quote> and all that follows through <quote>an offense
			 or an attempt to commit an offense</quote> and inserting <quote>in the case of
			 an offense, or an attempt or conspiracy to commit an offense,</quote>;
			 and</text>
						</clause><clause id="idA723D8122AC7471E955E39B1A56EE4D0"><enum>(iii)</enum><text>by striking
			 <quote>; or</quote> and inserting a semicolon;</text>
						</clause></subparagraph><subparagraph id="idB622B16F8B754D25B6B5DD9CCC417E42"><enum>(D)</enum><text>in subparagraph
			 (D)—</text>
						<clause id="id9B30E7DFE63549618DB8952CB3F197E0"><enum>(i)</enum><text>by striking clause
			 (ii);</text>
						</clause><clause id="idB94FCAF465B9460DACEED46632FC047B"><enum>(ii)</enum><text>by striking
			 <quote>in the case of—</quote> and all that follows through <quote>an offense
			 or an attempt to commit an offense</quote> and inserting <quote>in the case of
			 an offense, or an attempt or conspiracy to commit an offense,</quote>;
			 and</text>
						</clause><clause id="idA0897BEDE75048689E7AD0FAD05A1BDE"><enum>(iii)</enum><text>by striking
			 <quote>; or</quote> and inserting a semicolon;</text>
						</clause></subparagraph><subparagraph id="idD8E5B42E18BB4A668B5F18AC1C9066B8"><enum>(E)</enum><text>in subparagraph
			 (E), by inserting <quote>or conspires</quote> after <quote>offender
			 attempts</quote>;</text>
					</subparagraph><subparagraph id="idC8241EACFDC94621929FE6EC755D28DB"><enum>(F)</enum><text>in subparagraph
			 (F), by inserting <quote>or conspires</quote> after <quote>offender
			 attempts</quote>; and</text>
					</subparagraph><subparagraph id="idE33DAC91CE754C3FB558F1BFCA16D81F"><enum>(G)</enum><text>in subparagraph
			 (G)(ii), by inserting <quote>or conspiracy</quote> after <quote>an
			 attempt</quote>.</text>
					</subparagraph></paragraph></section><section commented="no" id="ID683573e5485643eea3d01d3e919e0c9f"><enum>104.</enum><header>False
			 notification</header>
				<subsection commented="no" id="ID4469eeb71de845cba2887e4609123460"><enum>(a)</enum><header>In
			 general</header><text>It shall be unlawful for an individual to send a
			 notification of a breach of security that is false or intentionally misleading
			 in order to obtain sensitive personally identifiable information in an effort
			 to defraud an individual.</text>
				</subsection><subsection commented="no" id="ID67c47dbe2b6744c48bad56720c0c6d96"><enum>(b)</enum><header>Penalty</header><text>Any
			 person that violates subsection (a) shall be fined not more than $1,000,000,
			 imprisoned not more than 5 years, or both.</text>
				</subsection><subsection commented="no" id="ID5ee9192692a445469dd9206faace291a"><enum>(c)</enum><header>Rule of
			 construction</header><text>For purposes of this section, any single action or
			 conduct that violates subsection (a) with respect to multiple protected
			 computers shall be construed to be a single violation.</text>
				</subsection></section><section commented="no" id="ID0ba8888617d74aaa8c3880d31b1d59cd"><enum>105.</enum><header>Unauthorized
			 installation of personal information collection features on a user's
			 computer</header>
				<subsection commented="no" id="id4110D2C872E44C618D50AD2D3CCB5686"><enum>(a)</enum><header>Definition</header><text>In
			 this section, the term <term>protected computer</term> has the meaning given
			 the term in section 1030(e)(2) of title 18, United States Code.</text>
				</subsection><subsection commented="no" id="ID4b4df3d1af0b4dc9abe6482bea72c21e"><enum>(b)</enum><header>In
			 general</header><text>It shall be unlawful for a person that is not an
			 authorized user of a protected computer to cause the installation on the
			 protected computer of software that collects sensitive personally identifiable
			 information from an authorized user, unless the person—</text>
					<paragraph commented="no" id="id5BCC4F55BC7548F3B86F14ADA0DA5A96"><enum>(1)</enum><text>provides a clear
			 and conspicuous disclosure of such collection; and</text>
					</paragraph><paragraph commented="no" id="id1A79B7BBC8DC4442804DDD733BC68617"><enum>(2)</enum><text>obtains the
			 consent of an authorized user of the protected computer prior to any collection
			 of sensitive personally identifiable information.</text>
					</paragraph></subsection><subsection commented="no" id="ID7d9dd4070f2f495785cb857c2b64a933"><enum>(c)</enum><header>Collection and
			 use of personal information in web searches</header><text>It shall be unlawful
			 for an Internet service provider or proxy server to knowingly or
			 intentionally—</text>
					<paragraph commented="no" id="ID6e50ae26579a4f8683efba971bb6627e"><enum>(1)</enum><text>bypass the display
			 of search engine results and redirect web searches or queries entered by an
			 authorized user of a protected computer directly to a commercial website,
			 counterfeit web page, or targeted advertisement and derive an economic benefit
			 from such activity; or</text>
					</paragraph><paragraph commented="no" id="IDfb9a387242c6422799a98b270d6a1710"><enum>(2)</enum><text>monitor,
			 manipulate, aggregate, and market the data collected in the process of
			 intercepting a web search or query entered by an authorized user of a protected
			 computer and derive an economic benefit from such activity.</text>
					</paragraph></subsection><subsection commented="no" id="ID24a8ab4707f44139aac2275baf36532d"><enum>(d)</enum><header>Other collection
			 of personal information</header>
					<paragraph commented="no" id="id67AC0B8CF1FA435EA38DA32DEA0BB3ED"><enum>(1)</enum><header>In
			 general</header><text>It shall be unlawful for a person who is not an
			 authorized user of a protected computer to cause the installation on the
			 protected computer of software that engages in any of the collection practices
			 described in paragraph (2), unless the person—</text>
						<subparagraph commented="no" id="id687C54610C9A4B0687D7BE6DE72CFA9A"><enum>(A)</enum><text>provides a clear
			 and conspicuous disclosure of such collection; and</text>
						</subparagraph><subparagraph commented="no" id="id08E4E5E5D76545D4A5D906CBBB134990"><enum>(B)</enum><text>obtains the
			 consent of an authorized user of the protected computer prior to any such
			 collection of information.</text>
						</subparagraph></paragraph><paragraph commented="no" id="id1ED986286ED5446199C1B041033D2E26"><enum>(2)</enum><header>Collection
			 practices described</header><text>The collection practices described in this
			 paragraph are—</text>
						<subparagraph commented="no" id="IDe69531ba070f41939b6174c6a76a3751"><enum>(A)</enum><text>the use of a
			 keystroke-logging function that records all or substantially all keystrokes
			 made by an owner or operator of a computer and transfers that information from
			 the computer to another person;</text>
						</subparagraph><subparagraph commented="no" id="ID01731442cc704d2e9357dedc56f29342"><enum>(B)</enum><text>the collection of
			 data in a manner that—</text>
							<clause commented="no" id="id7B74AA228FAB41C987FC04A9C89E7339"><enum>(i)</enum><text>correlates
			 sensitive personally identifiable information with a history of—</text>
								<subclause commented="no" id="id4C1668DCB69F40FEB7198AF430FD017B"><enum>(I)</enum><text>all, or
			 substantially all, of the websites visited by an owner or operator, other than
			 websites operated by the person providing such software; or</text>
								</subclause><subclause commented="no" id="idAEAEFFFF2FF143D2BBFF4C7F18F29048"><enum>(II)</enum><text>all, or
			 substantially all, of the web searches conducted by an owner or operator other
			 than search data collected by a search engine; and</text>
								</subclause></clause><clause commented="no" id="id3C6F47267B0449E9910BE214B0B9409C"><enum>(ii)</enum><text>uses the
			 information described in clause (i) to deliver advertising to, or display
			 advertising on, the computer; and</text>
							</clause></subparagraph><subparagraph commented="no" id="ID0f35d0105fea4c66a72541f6f4eb7fbe"><enum>(C)</enum><text>the extracting
			 from the hard drive or other storage medium of the computer—</text>
							<clause commented="no" id="ID718b8a22131b4cccbb36b501ea68097f"><enum>(i)</enum><text>the substantive
			 contents of files, data, software, or other information knowingly saved or
			 installed by the authorized user of a protected computer; or</text>
							</clause><clause commented="no" id="ID0315c2715b174b75940715dc37eb97f9"><enum>(ii)</enum><text>the substantive
			 contents of communications sent by an authorized user of a protected computer
			 to any other computer.</text>
							</clause></subparagraph></paragraph></subsection><subsection commented="no" id="IDd7eb6ec335f74214a80ffc5ae7ec330f"><enum>(e)</enum><header>Exception</header><text>This
			 section shall not restrict a person from causing the installation of software
			 that collects information for the provider of an online service or website
			 knowingly used or subscribed to by an authorized user if the information
			 collected is used only to affect the experience of the user while using that
			 online service or website.</text>
				</subsection><subsection commented="no" id="IDcd19083a4a9047b5bdf08d2c806a37db"><enum>(f)</enum><header>Uninstall
			 functionality</header>
					<paragraph commented="no" id="IDd3f2821ca7c64ff297184e15c7bf3ff8"><enum>(1)</enum><header>In
			 general</header><text>Software that performs any function described in
			 subsection (b) or (c) shall have the capability to subsequently be uninstalled
			 or disabled by an authorized user through a program removal function that is
			 usual and customary with the operating system of the computer or otherwise as
			 clearly and conspicuously disclosed to the user.</text>
					</paragraph><paragraph commented="no" id="IDc31d37a69d8747c4941a009de2f3b107"><enum>(2)</enum><header>Authority to
			 uninstall</header><text>Software that enables an authorized user of a protected
			 computer, such as a parent, employer, or system administrator, to choose to
			 prevent another user of the same computer from uninstalling or disabling the
			 software shall not be considered to prevent reasonable efforts to uninstall or
			 disable the software within the meaning of paragraph (1) if not less than 1
			 authorized user retains the ability to uninstall or disable the
			 software.</text>
					</paragraph></subsection><subsection commented="no" id="ID89e369fe56bb44d7bc5afcff9393c81c"><enum>(g)</enum><header>Limitations on
			 liability</header>
					<paragraph commented="no" id="ID5347df6a266145c99cf15c7b28cb4a87"><enum>(1)</enum><header>In
			 general</header><text>The restrictions imposed under this section do not apply
			 to any monitoring of, or interaction with, a subscriber's Internet or other
			 network connection or service, or a protected computer, by or at the direction
			 of a telecommunications carrier, cable operator, computer hardware or software
			 provider, financial institution or provider of information services or
			 interactive computer service for—</text>
						<subparagraph commented="no" id="IDa261a7e1380b43ecab1f43c3d17a0ecc"><enum>(A)</enum><text>network or
			 computer security purposes;</text>
						</subparagraph><subparagraph commented="no" id="ID7eba2962c90e4895aa2a8fe0f5636691"><enum>(B)</enum><text>diagnostics;</text>
						</subparagraph><subparagraph commented="no" id="ID666b6be0cf364601934e5b1e2ef876ef"><enum>(C)</enum><text>technical
			 support;</text>
						</subparagraph><subparagraph commented="no" id="ID1c1426889aee40d29179c25a295f5f47"><enum>(D)</enum><text>repair;</text>
						</subparagraph><subparagraph commented="no" id="ID7c7bcf09017641cf9a5b74ed6fff7159"><enum>(E)</enum><text>network
			 management;</text>
						</subparagraph><subparagraph commented="no" id="ID30d94602203744e29d7ba2675ceda194"><enum>(F)</enum><text>authorized updates
			 of software or system firmware;</text>
						</subparagraph><subparagraph commented="no" id="IDa261552c9415434193bccfc31e4aac58"><enum>(G)</enum><text>authorized remote
			 system management;</text>
						</subparagraph><subparagraph commented="no" id="IDad54f520342b4470b1a640d2cc4fb373"><enum>(H)</enum><text>authorized
			 provision of protection for users of the computer from objectionable
			 content;</text>
						</subparagraph><subparagraph commented="no" id="ID7ef41b0f3d664d34a65c9377fa893740"><enum>(I)</enum><text>authorized
			 scanning for computer software used in violation of this section for removal by
			 an authorized user; or</text>
						</subparagraph><subparagraph commented="no" id="ID06b95a5f17ce4423ab80dd7f6c2799e6"><enum>(J)</enum><text>detection or
			 prevention of the unauthorized use of software fraudulent or other illegal
			 activities.</text>
						</subparagraph></paragraph><paragraph commented="no" id="IDf875c6b5e15c4aa49629f7239c205990"><enum>(2)</enum><header>Manufacturer's
			 liability for third-party software</header><text>A manufacturer or retailer of
			 a computer shall not be liable under any provision of this section for causing
			 the installation on the computer, prior to the first retail sale and delivery
			 of the computer, of third-party branded software, unless the manufacturer or
			 retailer knowingly allows the installation of such third-party branded software
			 and derives a benefit from the operation of such software.</text>
					</paragraph><paragraph commented="no" id="ID2b012d859ea740018ce6a07fd15ae175"><enum>(3)</enum><header>Exception for
			 authorized investigative agencies</header><text>Nothing in this section
			 prohibits any lawfully authorized criminal investigation or authorized
			 investigative, protective, or intelligence activities that are carried out by
			 or on behalf of any element of the intelligence community and conducted in
			 accordance with the United States laws, authorities, and regulations governing
			 such intelligence activities, of a law enforcement agency of the United States,
			 a State, or a political subdivision of a State, or of an intelligence agency of
			 the United States.</text>
					</paragraph></subsection><subsection commented="no" id="ID775625bb349a4fdfbc4add50d71e908c"><enum>(h)</enum><header>Enforcement by
			 the Attorney General</header>
					<paragraph commented="no" id="ID7b9ae213b36f48b8a315ec5d2cd114e9"><enum>(1)</enum><header>Liability and
			 penalty for violations</header><text>Any person who engages in an activity in
			 violation of this section shall be fined not more than $500,000, imprisoned not
			 more than 5 years, or both.</text>
					</paragraph><paragraph commented="no" id="IDbe7f061c5831477b84745c95c345231f"><enum>(2)</enum><header>Enhanced
			 liability and penalties for pattern or practice of violations</header>
						<subparagraph commented="no" id="ID8843456b12934d848a072dd6fe945870"><enum>(A)</enum><header>In
			 general</header><text>Any person who engages in a pattern or practice of
			 activity that violates the provisions of this section shall be fined not more
			 than $1,000,000, imprisoned not more than 5 years, or both.</text>
						</subparagraph><subparagraph commented="no" id="ID0482e8fb03fb4676bdcbbdafc4389764"><enum>(B)</enum><header>Treatment of
			 single action or conduct</header><text>For purposes of subparagraph (A), any
			 single action or conduct that violates this section with respect to multiple
			 protected computers shall be construed as a single violation.</text>
						</subparagraph></paragraph><paragraph commented="no" id="ID4bb2921f65654e5881ff92d8af87429f"><enum>(3)</enum><header>Considerations</header><text>In
			 determining the amount of any penalty under paragraph (1) or (2), the court
			 shall take into account—</text>
						<subparagraph commented="no" id="id37363AAC899E47E5BEE1AE63A129E4FB"><enum>(A)</enum><text>the degree of
			 culpability of the defendant;</text>
						</subparagraph><subparagraph commented="no" id="id1261AC3E615647A59232AC19F07B49CE"><enum>(B)</enum><text>any history of
			 prior such conduct;</text>
						</subparagraph><subparagraph commented="no" id="idDB52253A58694BA2B4DF4B5A83B339A1"><enum>(C)</enum><text>the ability of the
			 defendant to pay any fine imposed;</text>
						</subparagraph><subparagraph commented="no" id="id46CB82B2E1FD4B0D9F5322D62AFAC5B3"><enum>(D)</enum><text>the effect on the
			 ability of the defendant to continue to do business; and</text>
						</subparagraph><subparagraph commented="no" id="id3383112BE7634B0AB1BC122390CE7C08"><enum>(E)</enum><text>such other matters
			 as justice may require.</text>
						</subparagraph></paragraph></subsection></section></title><title changed="deleted" commented="no" committee-id="SSJU00" id="idD725C42479864A1D94B301FF34A11C92" level-type="subsequent" reported-display-style="strikethrough"><enum>II</enum><header display-inline="yes-display-inline">Privacy and security of personally
			 identifiable information </header>
			<subtitle commented="no" id="id3189B1C7B0974BA09A5D2EB0F2AA3456" level-type="subsequent"><enum>A</enum><header display-inline="yes-display-inline">A data privacy and security
			 program</header>
				<section commented="no" display-inline="no-display-inline" id="ID48089945808a49b592f4356d4079eae6" section-type="subsequent-section"><enum>201.</enum><header display-inline="yes-display-inline">Purpose and applicability of data privacy
			 and security program</header>
					<subsection commented="no" display-inline="no-display-inline" id="IDddbd1c5a93e94835af6783727a4e0d4d"><enum>(a)</enum><header display-inline="yes-display-inline">Purpose</header><text display-inline="yes-display-inline">The purpose of this subtitle is to ensure
			 standards for developing and implementing administrative, technical, and
			 physical safeguards to protect the security of sensitive personally
			 identifiable information.</text>
					</subsection><subsection commented="no" display-inline="no-display-inline" id="ID1d16430a563849c88f30c306297d0517"><enum>(b)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">A business entity engaging in interstate
			 commerce that involves collecting, accessing, transmitting, using, storing, or
			 disposing of sensitive personally identifiable information in electronic or
			 digital form on 10,000 or more United States persons is subject to the
			 requirements for a data privacy and security program under section 202 for
			 protecting sensitive personally identifiable information.</text>
					</subsection><subsection commented="no" display-inline="no-display-inline" id="ID84c02c5382924cd5880326c0d63e96dc"><enum>(c)</enum><header display-inline="yes-display-inline">Limitations</header><text display-inline="yes-display-inline">Notwithstanding any other obligation under
			 this subtitle, this subtitle does not apply to:</text>
						<paragraph commented="no" display-inline="no-display-inline" id="ID560a85637f8c42c19982f35cb3f1461e"><enum>(1)</enum><header display-inline="yes-display-inline">Financial institutions</header><text display-inline="yes-display-inline">Financial institutions—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="IDa9ac03fede8c4d3bacfa4686a427f4f1"><enum>(A)</enum><text display-inline="yes-display-inline">subject to the data security requirements
			 and implementing regulations under the Gramm-Leach-Bliley Act (15 U.S.C. 6801
			 et seq.); and</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID6a256ee27e134fe3af78121215ed174f"><enum>(B)</enum><text display-inline="yes-display-inline">subject to—</text>
								<clause commented="no" display-inline="no-display-inline" id="ID5c74fafda772492bbb9771f6c10c7e46"><enum>(i)</enum><text display-inline="yes-display-inline">examinations for compliance with the
			 requirements of this Act by a Federal Functional Regulator or State Insurance
			 Authority (as those terms are defined in section 509 of the Gramm-Leach-Bliley
			 Act (15 U.S.C. 6809)); or</text>
								</clause><clause commented="no" display-inline="no-display-inline" id="IDa8fffe318bd242b5a4adabd150a5cce7"><enum>(ii)</enum><text display-inline="yes-display-inline">compliance with part 314 of title 16, Code
			 of Federal Regulations.</text>
								</clause></subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID1bea77b1d96049d19342fc06938e8260"><enum>(2)</enum><header display-inline="yes-display-inline">HIPAA regulated entities</header>
							<subparagraph commented="no" display-inline="no-display-inline" id="ID91b41aa91ccb4edda6d95f64add28769"><enum>(A)</enum><header display-inline="yes-display-inline">Covered entities</header><text display-inline="yes-display-inline">Covered entities subject to the Health
			 Insurance Portability and Accountability Act of 1996 (42 U.S.C. 1301 et seq.),
			 including the data security requirements and implementing regulations of that
			 Act.</text>
							</subparagraph><subparagraph id="ID1ba8205e944d416581459ba6409efff0"><enum>(B)</enum><header>Business
			 entities</header><text>A business entity shall be deemed in compliance with
			 this Act if the business entity—</text>
								<clause id="idD76E963574FC454BB9E8914910345AE1"><enum>(i)</enum><text>is acting as a
			 business associate, as that term is defined under the Health Insurance
			 Portability and Accountability Act of 1996 (42 U.S.C. 1301 et seq.) and is in
			 compliance with the requirements imposed under that Act and implementing
			 regulations promulgated under that Act; and</text>
								</clause><clause id="id44580D503E9F4E2D9AE5853437922E95"><enum>(ii)</enum><text>is subject to,
			 and currently in compliance, with the privacy and data security requirements
			 under sections 13401 and 13404 of division A of the American Reinvestment and
			 Recovery Act of 2009 (42 U.S.C. 17931 and 17934) and implementing regulations
			 promulgated under such sections.</text>
								</clause></subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id752B5A0D23AD45DF819B11B11D4B6161"><enum>(3)</enum><header display-inline="yes-display-inline">Public
			 records</header><text display-inline="yes-display-inline">Public records not
			 otherwise subject to a confidentiality or nondisclosure requirement, or
			 information obtained from a news report or periodical.</text>
						</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="id87AC98F957514080864FE533CC4403B0"><enum>(d)</enum><header>Rule of
			 construction</header><text>Nothing in this subtitle shall be construed to
			 modify, limit, or supersede the operation of the provisions of the
			 Gramm-Leach-Bliley Act (15 U.S.C. 6801 et seq.), or its implementing
			 regulations, including such regulations adopted or enforced by the
			 States.</text>
					</subsection></section><section commented="no" display-inline="no-display-inline" id="ID01a5628cdcfe4d1aa8f738063c6c15c2" section-type="subsequent-section"><enum>202.</enum><header display-inline="yes-display-inline">Requirements for a personal data privacy
			 and security program</header>
					<subsection commented="no" display-inline="no-display-inline" id="IDe06ec5d327734ccfbcb3025711448bcd"><enum>(a)</enum><header display-inline="yes-display-inline">Personal data privacy and security
			 program</header><text display-inline="yes-display-inline">A business entity
			 subject to this subtitle shall comply with the following safeguards and any
			 other administrative, technical, or physical safeguards identified by the
			 Federal Trade Commission in a rulemaking process pursuant to section 553 of
			 title 5, United States Code, for the protection of sensitive personally
			 identifiable information:</text>
						<paragraph commented="no" display-inline="no-display-inline" id="ID32f2da88aaeb4e9a9356cdfa751bf96e"><enum>(1)</enum><header display-inline="yes-display-inline">Scope</header><text display-inline="yes-display-inline">A business entity shall implement a
			 comprehensive personal data privacy and security program that includes
			 administrative, technical, and physical safeguards appropriate to the size and
			 complexity of the business entity and the nature and scope of its
			 activities.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDc422286e3b5e4282880c6d4dda9e61ef"><enum>(2)</enum><header display-inline="yes-display-inline">Design</header><text display-inline="yes-display-inline">The personal data privacy and security
			 program shall be designed to—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="ID832224a994d04e60aa6c94efa1588cf6"><enum>(A)</enum><text display-inline="yes-display-inline">ensure the privacy, security, and
			 confidentiality of sensitive personally identifiable information;</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDabaa6ac0cead448288f59c56e7b28aae"><enum>(B)</enum><text display-inline="yes-display-inline">protect against any anticipated
			 vulnerabilities to the privacy, security, or integrity of sensitive personally
			 identifiable information; and</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID878a6358d1d7420db96cfdb96d77744b"><enum>(C)</enum><text display-inline="yes-display-inline">protect against unauthorized access or use
			 of sensitive personally identifiable information that could create a
			 significant risk of harm or fraud to any individual.</text>
							</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID4b950d47eff549f6988d73682c9f11ce"><enum>(3)</enum><header display-inline="yes-display-inline">Risk assessment</header><text display-inline="yes-display-inline">A business entity shall—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="ID760c690786bc445d9bc2677d8f95f00e"><enum>(A)</enum><text display-inline="yes-display-inline">identify reasonably foreseeable internal
			 and external vulnerabilities that could result in unauthorized access,
			 disclosure, use, or alteration of sensitive personally identifiable information
			 or systems containing sensitive personally identifiable information;</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID553382e18b2e43f1a9f3e85ed691c714"><enum>(B)</enum><text display-inline="yes-display-inline">assess the likelihood of and potential
			 damage from unauthorized access, disclosure, use, or alteration of sensitive
			 personally identifiable information;</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID676012ab86234c0aac757acb3a03d1f6"><enum>(C)</enum><text display-inline="yes-display-inline">assess the sufficiency of its policies,
			 technologies, and safeguards in place to control and minimize risks from
			 unauthorized access, disclosure, use, or alteration of sensitive personally
			 identifiable information; and</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idC1C4AE57A42F48318FE5D2321E156F0A"><enum>(D)</enum><text display-inline="yes-display-inline">assess the vulnerability of sensitive
			 personally identifiable information during destruction and disposal of such
			 information, including through the disposal or retirement of hardware.</text>
							</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID746a427c8ac84218b69ce3920d5a9f26"><enum>(4)</enum><header display-inline="yes-display-inline">Risk management and control</header><text display-inline="yes-display-inline">Each business entity shall—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="ID0d4167033d5e428a96e89c8a307f2779"><enum>(A)</enum><text display-inline="yes-display-inline">design its personal data privacy and
			 security program to control the risks identified under paragraph (3);
			 and</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID7de281b8fa6d44e6a955e840dd025689"><enum>(B)</enum><text display-inline="yes-display-inline">adopt measures commensurate with the
			 sensitivity of the data as well as the size, complexity, and scope of the
			 activities of the business entity that—</text>
								<clause commented="no" display-inline="no-display-inline" id="IDcb31d2a8cc9c45e7a827fb3cad9e004e"><enum>(i)</enum><text display-inline="yes-display-inline">control access to systems and facilities
			 containing sensitive personally identifiable information, including controls to
			 authenticate and permit access only to authorized individuals;</text>
								</clause><clause commented="no" display-inline="no-display-inline" id="IDd2ebc6309fec4e80957b78c33a013747"><enum>(ii)</enum><text display-inline="yes-display-inline">detect, record, and preserve information
			 relevant to actual and attempted fraudulent, unlawful, or unauthorized access,
			 disclosure, use, or alteration of sensitive personally identifiable
			 information, including by employees and other individuals otherwise authorized
			 to have access;</text>
								</clause><clause commented="no" display-inline="no-display-inline" id="IDcc80fec448474095b98acf35dbf50a95"><enum>(iii)</enum><text display-inline="yes-display-inline">protect sensitive personally identifiable
			 information during use, transmission, storage, and disposal by encryption,
			 redaction, or access controls that are widely accepted as an effective industry
			 practice or industry standard, or other reasonable means (including as directed
			 for disposal of records under section 628 of the Fair Credit Reporting Act (15
			 U.S.C. 1681w) and the implementing regulations of such Act as set forth in
			 section 682 of title 16, Code of Federal Regulations);</text>
								</clause><clause commented="no" display-inline="no-display-inline" id="idDC2AB053A4F84CE899BDA286A381B0A4"><enum>(iv)</enum><text display-inline="yes-display-inline">ensure that sensitive personally
			 identifiable information is properly destroyed and disposed of, including
			 during the destruction of computers, diskettes, and other electronic media that
			 contain sensitive personally identifiable information;</text>
								</clause><clause commented="no" display-inline="no-display-inline" id="idA65F7941A0984AA792DB0EA52A944E3F"><enum>(v)</enum><text display-inline="yes-display-inline">trace access to records containing
			 sensitive personally identifiable information so that the business entity can
			 determine who accessed or acquired such sensitive personally identifiable
			 information pertaining to specific individuals;</text>
								</clause><clause commented="no" display-inline="no-display-inline" id="id35C1CA572F594C458CA61F42D2275173"><enum>(vi)</enum><text display-inline="yes-display-inline">ensure that no third party or customer of
			 the business entity is authorized to access or acquire sensitive personally
			 identifiable information without the business entity first performing
			 sufficient due diligence to ascertain, with reasonable certainty, that such
			 information is being sought for a valid legal purpose; and</text>
								</clause><clause commented="no" display-inline="no-display-inline" id="idC1658671EAC1498297C6BC1D6024CAEE"><enum>(vii)</enum><text>minimize the
			 amount of personal information maintained by the business entity, providing for
			 the retention of such personal information only as reasonably needed for the
			 business purposes of the business entity or as necessary to comply with any
			 other provision of law.</text>
								</clause></subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="IDac0bcd641fab47ec8d169bbdd3e2cbd6"><enum>(b)</enum><header display-inline="yes-display-inline">Training</header><text display-inline="yes-display-inline">Each business entity subject to this
			 subtitle shall take steps to ensure employee training and supervision for
			 implementation of the data security program of the business entity.</text>
					</subsection><subsection commented="no" display-inline="no-display-inline" id="IDc8546a0096344b8093d2c7c421a2bf04"><enum>(c)</enum><header display-inline="yes-display-inline">Vulnerability testing</header>
						<paragraph commented="no" display-inline="no-display-inline" id="IDe55eff11713942b3b734ead03b647a72"><enum>(1)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">Each business entity subject to this
			 subtitle shall take steps to ensure regular testing of key controls, systems,
			 and procedures of the personal data privacy and security program to detect,
			 prevent, and respond to attacks or intrusions, or other system failures.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDb7ebf96c0fd4459c97654057f389508c"><enum>(2)</enum><header display-inline="yes-display-inline">Frequency</header><text display-inline="yes-display-inline">The frequency and nature of the tests
			 required under paragraph (1) shall be determined by the risk assessment of the
			 business entity under subsection (a)(3).</text>
						</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="IDa0671a094a6e446d8b3ead55be2ac24b"><enum>(d)</enum><header display-inline="yes-display-inline">Relationship to service
			 providers</header><text display-inline="yes-display-inline">In the event a
			 business entity subject to this subtitle engages service providers not subject
			 to this subtitle, such business entity shall—</text>
						<paragraph commented="no" display-inline="no-display-inline" id="IDa0c9f487ec3f4cc3a43321f9fb1e75f6"><enum>(1)</enum><text display-inline="yes-display-inline">exercise appropriate due diligence in
			 selecting those service providers for responsibilities related to sensitive
			 personally identifiable information, and take reasonable steps to select and
			 retain service providers that are capable of maintaining appropriate safeguards
			 for the security, privacy, and integrity of the sensitive personally
			 identifiable information at issue; and</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID00c3ca79bcb34d02bbcc049d21cf0938"><enum>(2)</enum><text display-inline="yes-display-inline">require those service providers by contract
			 to implement and maintain appropriate measures designed to meet the objectives
			 and requirements governing entities subject to section 201, this section, and
			 subtitle B.</text>
						</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="ID0a463bfe19fa46a69db7e98862c0d304"><enum>(e)</enum><header display-inline="yes-display-inline">Periodic assessment and personal data
			 privacy and security modernization</header><text display-inline="yes-display-inline">Each business entity subject to this
			 subtitle shall on a regular basis monitor, evaluate, and adjust, as appropriate
			 its data privacy and security program in light of any relevant changes
			 in—</text>
						<paragraph commented="no" display-inline="no-display-inline" id="ID0d4f9c7be89448b19bc7acc3df798c94"><enum>(1)</enum><text display-inline="yes-display-inline">technology;</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID78b825c133324ea99829bb80cdd35dac"><enum>(2)</enum><text display-inline="yes-display-inline">the sensitivity of personally identifiable
			 information;</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID5a4c0fdefdcd430f938a0d14c111ba57"><enum>(3)</enum><text display-inline="yes-display-inline">internal or external threats to personally
			 identifiable information; and</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID9e21f4e291504ec19aa24c9a45152c9e"><enum>(4)</enum><text display-inline="yes-display-inline">the changing business arrangements of the
			 business entity, such as—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="IDde6f7259eddf4738b0ef8a759540216f"><enum>(A)</enum><text display-inline="yes-display-inline">mergers and acquisitions;</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID15c1ca9356fe48a18ee457775ee5110f"><enum>(B)</enum><text display-inline="yes-display-inline">alliances and joint ventures;</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID262c91919f004097b81ed65d35558174"><enum>(C)</enum><text display-inline="yes-display-inline">outsourcing arrangements;</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID1d26ec6a0c5340f380d57ebaa82c9628"><enum>(D)</enum><text display-inline="yes-display-inline">bankruptcy; and</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID9a63adfb34454b6aa70ae2d0e1db625e"><enum>(E)</enum><text display-inline="yes-display-inline">changes to sensitive personally
			 identifiable information systems.</text>
							</subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="IDacc913ed0f0a43b39ed94b6a1b28f785"><enum>(f)</enum><header display-inline="yes-display-inline">Implementation timeline</header><text display-inline="yes-display-inline">Not later than 1 year after the date of
			 enactment of this Act, a business entity subject to the provisions of this
			 subtitle shall implement a data privacy and security program pursuant to this
			 subtitle.</text>
					</subsection></section><section commented="no" display-inline="no-display-inline" id="ID5cac3211a25b4f26a2628faea99c9f36" section-type="subsequent-section"><enum>203.</enum><header display-inline="yes-display-inline">Federal enforcement</header>
					<subsection commented="no" display-inline="no-display-inline" id="IDad519693d2a34f75a85128cd145d1103"><enum>(a)</enum><header display-inline="yes-display-inline">Civil penalties</header>
						<paragraph commented="no" display-inline="no-display-inline" id="ID8710c7c96e804d8493e3f127daa59e1d"><enum>(1)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">The Attorney General may bring a civil
			 action in the appropriate United States district court against any business
			 entity that engages in conduct constituting a violation of this subtitle and,
			 upon proof of such conduct by a preponderance of the evidence, such business
			 entity shall be subject to a civil penalty of not more than $5,000 per
			 violation per day while such a violation exists, with a maximum of $20,000,000
			 per violation, unless such conduct is found to be willful or
			 intentional.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID1eab52f9bdfe4428a9ec5ba12bcb6ecb"><enum>(2)</enum><header display-inline="yes-display-inline">Intentional or willful
			 violation</header><text display-inline="yes-display-inline">A business entity
			 that intentionally or willfully violates the provisions of this subtitle shall
			 be subject to additional penalties in the amount of $5,000 per violation per
			 day while such a violation exists.</text>
						</paragraph><paragraph id="idECC2DFE9CBC7439CA58FD69CF55CD760"><enum>(3)</enum><header>Considerations</header><text>In
			 determining the amount of a civil penalty under this subsection, the court
			 shall take into account—</text>
							<subparagraph id="id6F5C9E1F28F246F8B64A76BDA00C14A4"><enum>(A)</enum><text>the degree of
			 culpability of the business entity;</text>
							</subparagraph><subparagraph id="idCA0CC3BF256649058D1E14E70C7D765A"><enum>(B)</enum><text>any prior
			 violations of this subtitle by the business entity;</text>
							</subparagraph><subparagraph id="id42BFAA47B1984FF1B79459FBA5FC61A3"><enum>(C)</enum><text>the ability of the
			 business entity to pay a civil penalty;</text>
							</subparagraph><subparagraph id="id000A6D4B7CCC456E9D2CDCE27A5E74F5"><enum>(D)</enum><text>the effect on the
			 ability of the business entity to continue to do business;</text>
							</subparagraph><subparagraph id="id6A6A7EDA8A0A49BC8E32F1B3BE9840E9"><enum>(E)</enum><text>the number of
			 individuals whose personally identifiable information was compromised by the
			 breach;</text>
							</subparagraph><subparagraph id="id42B27E53AF1847F8B49672B1AABB0BC5"><enum>(F)</enum><text>the relative cost
			 of compliance with this subtitle; and</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idF25075A5982D444AAB55ECA7D3E044C7"><enum>(G)</enum><text>such other matters
			 as justice may require.</text>
							</subparagraph></paragraph></subsection><subsection id="ID1ad01f34844b4d8dbbb0a26a91a8f8ba"><enum>(b)</enum><header>Injunctive
			 actions by the Attorney General</header>
						<paragraph id="IDfcdcf812f6e942b29bafb75cf9ff9a85"><enum>(1)</enum><header>In
			 general</header><text>If it appears that a business entity has engaged, or is
			 engaged, in any act or practice constituting a violation of this subtitle, the
			 Attorney General may petition an appropriate district court of the United
			 States for an order—</text>
							<subparagraph id="ID0c07976b9ba443c4965228c24e59eaa1"><enum>(A)</enum><text>enjoining such act
			 or practice; or</text>
							</subparagraph><subparagraph id="ID116b926d6298440f9f2c5602a1acf9ae"><enum>(B)</enum><text>enforcing
			 compliance with this subtitle.</text>
							</subparagraph></paragraph><paragraph id="IDfa5972f26ebd429eb29e63117147ef20"><enum>(2)</enum><header>Issuance of
			 order</header><text>A court may issue an order under paragraph (1), if the
			 court finds that the conduct in question constitutes a violation of this
			 subtitle.</text>
						</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="ID1a0f43fcf8a843a992c5ec63ef09d71e"><enum>(c)</enum><header display-inline="yes-display-inline">Other rights and remedies</header><text display-inline="yes-display-inline">The rights and remedies available under
			 this section are cumulative and shall not affect any other rights and remedies
			 available under law.</text>
					</subsection></section><section id="id2F1908FEFADB49B19264F6C00D6C8B7B"><enum>204.</enum><header>Enforcement by
			 State Attorneys General</header>
					<subsection commented="no" display-inline="no-display-inline" id="id810B9D5D00074BE393DF02F906BE3E4E"><enum>(a)</enum><header display-inline="yes-display-inline">Civil actions</header>
						<paragraph commented="no" display-inline="no-display-inline" id="id859D7845C8184A57B1BDEB8898FE5F5A"><enum>(1)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">In any case in which the attorney general
			 of a State or any State or local law enforcement agency authorized by the State
			 attorney general or by State statute to prosecute violations of consumer
			 protection law, has reason to believe that an interest of the residents of that
			 State has been or is threatened or adversely affected by the acts or practices
			 of a business entity that violate this subtitle, the State may bring a civil
			 action on behalf of the residents of that State in a district court of the
			 United States of appropriate jurisdiction, or any other court of competent
			 jurisdiction, to—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="id31812F04C77546E79C7AF0DB05FFA2F6"><enum>(A)</enum><text display-inline="yes-display-inline">enjoin that act or practice;</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id73BD179F12624B21BB1A5D184B17248A"><enum>(B)</enum><text display-inline="yes-display-inline">enforce compliance with this subtitle;
			 or</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idE21FE7A642D7412AB24279947B427352"><enum>(C)</enum><text display-inline="yes-display-inline">obtain civil penalties of not more than
			 $5,000 per violation per day while such violations persist, up to a maximum of
			 $20,000,000 per violation.</text>
							</subparagraph></paragraph><paragraph id="IDe8b0d278bee4421dbbefd5c8fef6e38c"><enum>(2)</enum><header>Considerations</header><text>In
			 determining the amount of a civil penalty under this subsection, the court
			 shall take into account—</text>
							<subparagraph id="idBCACD7C2D2AA4E6EB5C43E314F06D0E1"><enum>(A)</enum><text>the degree of
			 culpability of the business entity;</text>
							</subparagraph><subparagraph id="idE26934F508B6461F8A967B6CAD7A91A4"><enum>(B)</enum><text>any prior
			 violations of this subtitle by the business entity;</text>
							</subparagraph><subparagraph id="id69A4631FE91F49469E3FCE524D71D82D"><enum>(C)</enum><text>the ability of the
			 business entity to pay a civil penalty;</text>
							</subparagraph><subparagraph id="idB2C43DF5BA3F44EB8219C885C0EFACF9"><enum>(D)</enum><text>the effect on the
			 ability of the business entity to continue to do business;</text>
							</subparagraph><subparagraph id="IDf10d9e367ea744eab99a92b75b52ed4a"><enum>(E)</enum><text>the number of
			 individuals whose personally identifiable information was compromised by the
			 breach;</text>
							</subparagraph><subparagraph id="idC803B792D68846D993D42E9BD5899F69"><enum>(F)</enum><text>the relative cost
			 of compliance with this subtitle; and</text>
							</subparagraph><subparagraph id="idC361C59E132B4B67900F5A573FD2A360"><enum>(G)</enum><text>such other matters
			 as justice may require.</text>
							</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDb035a912d0134c8e88e798c195f63e25"><enum>(3)</enum><header display-inline="yes-display-inline">Notice</header>
							<subparagraph commented="no" display-inline="no-display-inline" id="ID10a26e09510c4bf08a652182d2d3bb76"><enum>(A)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">Before filing an action under this
			 subsection, the attorney general of the State involved shall provide to the
			 Attorney General—</text>
								<clause commented="no" display-inline="no-display-inline" id="IDe1187d19b84a49b3993eb68910cba8cb"><enum>(i)</enum><text display-inline="yes-display-inline">a written notice of that action; and</text>
								</clause><clause commented="no" display-inline="no-display-inline" id="ID7abbfa78320441b9a8e2acdd3ea96ce0"><enum>(ii)</enum><text display-inline="yes-display-inline">a copy of the complaint for that
			 action.</text>
								</clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDb390c579fafe4fddb34cc2f7f87d2850"><enum>(B)</enum><header display-inline="yes-display-inline">Exemption</header>
								<clause commented="no" display-inline="no-display-inline" id="id238949A31C4341F58AFEFE08DF06CBAD"><enum>(i)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">Subparagraph (A) shall not apply with
			 respect to the filing of an action by an attorney general of a State under this
			 subsection, if the attorney general of a State determines that it is not
			 feasible to provide the notice described in this subparagraph before the filing
			 of the action.</text>
								</clause><clause commented="no" display-inline="no-display-inline" id="IDdf0df3125ba0430a9162deb90f36b0c3"><enum>(ii)</enum><header display-inline="yes-display-inline">Notification</header><text display-inline="yes-display-inline">In an action described in clause (i), the
			 attorney general of a State shall provide notice and a copy of the complaint to
			 the Attorney General at the time the State attorney general files the
			 action.</text>
								</clause></subparagraph></paragraph></subsection><subsection id="ID2e0c6a0884fe47bca9c1aaa05bfca382"><enum>(b)</enum><header>Federal
			 proceedings</header><text>Upon receiving notice under subsection (a)(2), the
			 Attorney General shall have the right to—</text>
						<paragraph id="IDc4c283636ea24933ba49283ff8ddd96e"><enum>(1)</enum><text>move to stay the
			 action, pending the final disposition of a pending Federal proceeding or
			 action;</text>
						</paragraph><paragraph id="ID576435895d964bbaa2865fb922cdba2f"><enum>(2)</enum><text>initiate an action
			 in the appropriate United States district court under section 217 and move to
			 consolidate all pending actions, including State actions, in such court;</text>
						</paragraph><paragraph id="ID0928676b49914c25b500b569fe1d1e5a"><enum>(3)</enum><text>intervene in an
			 action brought under subsection (a)(2); and</text>
						</paragraph><paragraph id="ID62c0c5d5d8ff409181680e6372867366"><enum>(4)</enum><text>file petitions for
			 appeal.</text>
						</paragraph></subsection><subsection id="ID58ba37777b6f43a2aa802f898ca6339e"><enum>(c)</enum><header>Pending
			 proceedings</header><text>If the Attorney General has instituted a proceeding
			 or action for a violation of this subtitle or any regulations thereunder, no
			 attorney general of a State may, during the pendency of such proceeding or
			 action, bring an action under this subtitle against any defendant named in such
			 criminal proceeding or civil action for any violation that is alleged in that
			 proceeding or action.</text>
					</subsection><subsection id="IDe7ce971097884fd487ec39f37889c669"><enum>(d)</enum><header>Construction</header><text>For
			 purposes of bringing any civil action under subsection (a), nothing in this
			 subtitle regarding notification shall be construed to prevent an attorney
			 general of a State from exercising the powers conferred on such attorney
			 general by the laws of that State to—</text>
						<paragraph id="IDecb664406f634befbf604fae54de3ae3"><enum>(1)</enum><text>conduct
			 investigations;</text>
						</paragraph><paragraph id="ID507e8b5065b247eba84eeac0150c3a81"><enum>(2)</enum><text>administer oaths
			 or affirmations; or</text>
						</paragraph><paragraph id="ID4d41221cde7041afaab0109d2bc9d9cf"><enum>(3)</enum><text>compel the
			 attendance of witnesses or the production of documentary and other
			 evidence.</text>
						</paragraph></subsection><subsection id="ID88df503485654a8ab2d52f90276cfb63"><enum>(e)</enum><header>Venue; service
			 of process</header>
						<paragraph id="ID8ce65c0b61fd4c46b56240547d367e49"><enum>(1)</enum><header>Venue</header><text>Any
			 action brought under subsection (a) may be brought in—</text>
							<subparagraph id="IDb5827812daf047abb6d5d8851c70a5d1"><enum>(A)</enum><text>the district court
			 of the United States that meets applicable requirements relating to venue under
			 section 1391 of title 28, United States Code; or</text>
							</subparagraph><subparagraph id="ID0aaf7e689c4d4a93834549b3ae364dd4"><enum>(B)</enum><text>another court of
			 competent jurisdiction.</text>
							</subparagraph></paragraph><paragraph id="ID96fdf9451b514313a504c67d0ebab169"><enum>(2)</enum><header>Service of
			 process</header><text>In an action brought under subsection (a), process may be
			 served in any district in which the defendant—</text>
							<subparagraph id="IDad72e6d8c30f4dec96c7b72f26f6a23b"><enum>(A)</enum><text>is an inhabitant;
			 or</text>
							</subparagraph><subparagraph id="ID20576a6fa1754879a5c37a25a52b65d8"><enum>(B)</enum><text>may be
			 found.</text>
							</subparagraph></paragraph></subsection></section><section id="ID8952766f976d4ef48ad73992dd4702e4"><enum>205.</enum><header>Supplemental
			 enforcement by individuals</header>
					<subsection id="IDc89b63a704bc4a7c8c026cb291e747f9"><enum>(a)</enum><header>In
			 general</header><text>Any person aggrieved by a violation of the provisions of
			 this subtitle by a business entity may bring a civil action in a court of
			 appropriate jurisdiction to recover for personal injuries sustained as a result
			 of the violation.</text>
					</subsection><subsection id="ID3a769d75600e47f585a7406a80567d88"><enum>(b)</enum><header>Authority To
			 bring civil action; jurisdiction</header><text>As provided in subsection (c),
			 any person may commence a civil action on his own behalf against any business
			 entity who is alleged to have violated the provisions of this subtitle.</text>
					</subsection><subsection id="ID826f136b7972484db4ff2b83a99f250d"><enum>(c)</enum><header>Remedies in a
			 citizen suit</header>
						<paragraph id="ID56ab0f4d462b4fc895c4f08c97f1b98f"><enum>(1)</enum><header>Damages</header><text>Any
			 individual harmed by a failure of a business entity to comply with the
			 provisions of this subtitle, shall be able to collect damages of not more than
			 $10,000 per violation per day while such violations persist, up to a maximum of
			 $20,000,000 per violation.</text>
						</paragraph><paragraph id="IDe3cc8a626c6f4213b3d87156b14aa895"><enum>(2)</enum><header>Punitive
			 damages</header><text>A business entity may be liable for punitive damages if
			 the business entity intentionally or willfully violates the provisions of this
			 subtitle.</text>
						</paragraph><paragraph commented="no" id="ID86aa66f810a34947ac579974a5d2d312"><enum>(3)</enum><header>Equitable
			 relief</header><text display-inline="yes-display-inline">A business entity that
			 violates the provisions of this subtitle may be enjoined to comply with the
			 provisions of those sections.</text>
						</paragraph></subsection><subsection id="IDdb9cf7f2194948bea1158854fee52446"><enum>(d)</enum><header>Other rights and
			 remedies</header><text>The rights and remedies available under this subsection
			 are cumulative and shall not affect any other rights and remedies available
			 under law.</text>
					</subsection><subsection id="ID1f81a689d82945bd9c923e016adfc18c"><enum>(e)</enum><header>Access to
			 justice</header><text>The rights and remedies afforded by this section shall
			 not be abridged or precluded by any predispute arbitration agreement, and any
			 claims under this section that arise from the same security breach are presumed
			 to meet the commonality requirement under rule 23(a)(2) of the Federal Rules of
			 Civil Procedure.</text>
					</subsection></section></subtitle><subtitle commented="no" id="idBC4FEB9AFE2A4E93BF957FCB6F00B7E3" level-type="subsequent"><enum>B</enum><header display-inline="yes-display-inline">Security breach notification</header>
				<section commented="no" display-inline="no-display-inline" id="ID5510cd0d499f4913941a3308d15e6a1c" section-type="subsequent-section"><enum>211.</enum><header display-inline="yes-display-inline">Notice to individuals</header>
					<subsection commented="no" display-inline="no-display-inline" id="ID720d8016c4274ef7a360b8e4164e0fe0"><enum>(a)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">Any agency, or business entity engaged in
			 interstate commerce, that uses, accesses, transmits, stores, disposes of or
			 collects sensitive personally identifiable information that experiences a
			 security breach of such information, shall, following the discovery of such
			 security breach of such information, notify any resident of the United States
			 whose sensitive personally identifiable information has been, or is reasonably
			 believed to have been, accessed, or acquired.</text>
					</subsection><subsection commented="no" display-inline="no-display-inline" id="IDb2d0cfaa8a5b4717a05063975b9b42d1"><enum>(b)</enum><header display-inline="yes-display-inline">Obligation of owner or licensee</header>
						<paragraph commented="no" display-inline="no-display-inline" id="IDcacc642274d644e481d4de87564c1952"><enum>(1)</enum><header display-inline="yes-display-inline">Notice to owner or licensee</header><text display-inline="yes-display-inline">Any agency, or business entity engaged in
			 interstate commerce, that uses, accesses, transmits, stores, disposes of, or
			 collects sensitive personally identifiable information that the agency or
			 business entity does not own or license shall notify the owner or licensee of
			 the information following the discovery of a security breach involving such
			 information.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDa8a5bddb36854ef58c349f7d8f4e916b"><enum>(2)</enum><header display-inline="yes-display-inline">Notice by owner, licensee or other
			 designated third party</header><text display-inline="yes-display-inline">Nothing in this subtitle shall prevent or
			 abrogate an agreement between an agency or business entity required to give
			 notice under this section and a designated third party, including an owner or
			 licensee of the sensitive personally identifiable information subject to the
			 security breach, to provide the notifications required under subsection
			 (a).</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID8c3282340c68464c8cc16a7e96ac21b1"><enum>(3)</enum><header display-inline="yes-display-inline">Business entity relieved from giving
			 notice</header><text display-inline="yes-display-inline">A business entity
			 obligated to give notice under subsection (a) shall be relieved of such
			 obligation if an owner or licensee of the sensitive personally identifiable
			 information subject to the security breach, or other designated third party,
			 provides such notification.</text>
						</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="IDcba7ac64bcb3449d9c9ea5dad732fcaf"><enum>(c)</enum><header display-inline="yes-display-inline">Timeliness of notification</header>
						<paragraph commented="no" display-inline="no-display-inline" id="ID47e0ad09389e43368af2d01671e67128"><enum>(1)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">All notifications required under this
			 section shall be made without unreasonable delay following the discovery by the
			 agency or business entity of a security breach.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id053C9368FAB84DB48DBDF31BD947DFA8"><enum>(2)</enum><header display-inline="yes-display-inline">Reasonable delay</header><text display-inline="yes-display-inline">Reasonable delay under this subsection may
			 include any time necessary to determine the scope of the security breach,
			 conduct the risk assessment described in section 212(b)(1), and provide notice
			 to law enforcement when required.</text>
						</paragraph><paragraph id="ID571764e20a044583b351190edf5d6a52"><enum>(3)</enum><header>Burden of
			 production</header><text>The agency, business entity, owner, or licensee
			 required to provide notice under this subtitle shall, upon the request of the
			 Attorney General or the attorney general of a State or any State or local law
			 enforcement agency authorized by the attorney general of the State or by State
			 statute to prosecute violations of consumer protection law, provide records or
			 other evidence of the notifications required under this subtitle, including to
			 the extent applicable, the reasons for any delay of notification.</text>
						</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="IDe00e27f9a69d45aca089facd8a9a1fe8"><enum>(d)</enum><header display-inline="yes-display-inline">Delay of notification authorized for law
			 enforcement purposes</header>
						<paragraph id="ID3c1c49b6824e4af3822dd67648b1d26b"><enum>(1)</enum><header>In
			 general</header><text>If a Federal law enforcement agency or member of the
			 intelligence community determines that the notification required under this
			 section would impede any lawfully authorized criminal investigation or
			 authorized investigative, protective, or intelligence activities that are
			 carried out by or on behalf of any element of the intelligence community and
			 conducted in accordance with the United States laws, authorities, and
			 regulations governing such intelligence activities, such notification shall be
			 delayed upon written notice from such Federal law enforcement or intelligence
			 agency to the agency or business entity that experienced the breach.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID777040e96ce943efa72ca96e9edd8cd5"><enum>(2)</enum><header display-inline="yes-display-inline">Extended delay of
			 notification</header><text display-inline="yes-display-inline">If the
			 notification required under subsection (a) is delayed pursuant to paragraph
			 (1), an agency or business entity shall give notice 30 days after the day such
			 law enforcement delay was invoked unless a Federal law enforcement or
			 intelligence agency provides written notification that further delay is
			 necessary.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDe8d332a9b4f846cea0d31c6733439553"><enum>(3)</enum><header display-inline="yes-display-inline">Law enforcement immunity</header><text display-inline="yes-display-inline">No cause of action shall lie in any court
			 against any law enforcement agency for acts relating to the delay of
			 notification for law enforcement or intelligence purposes under this
			 subtitle.</text>
						</paragraph></subsection></section><section commented="no" display-inline="no-display-inline" id="ID5dc909314300496fae2e47fd1f732bf2" section-type="subsequent-section"><enum>212.</enum><header display-inline="yes-display-inline">Exemptions from notice to
			 individuals</header>
					<subsection commented="no" display-inline="no-display-inline" id="IDc0d77acc21dc4bd09bb886123fe643e8"><enum>(a)</enum><header display-inline="yes-display-inline">Exemption for national security and law
			 enforcement</header>
						<paragraph commented="no" display-inline="no-display-inline" id="ID5f8d9f0ccc2f464a8881c81fd09cd4da"><enum>(1)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">Section 211 shall not apply to an agency or
			 business entity if the agency or business entity certifies, in writing, that
			 notification of the security breach as required by section 211 reasonably could
			 be expected to—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="ID37a53412e42e4e18954878bf2b16dcb3"><enum>(A)</enum><text display-inline="yes-display-inline">cause damage to the national security;
			 or</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID0d053913bc2b400d8df6e3ff2775efac"><enum>(B)</enum><text display-inline="yes-display-inline">hinder a law enforcement investigation or
			 the ability of the agency to conduct law enforcement investigations.</text>
							</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDef500e6acfb34c17859262dc8e6af033"><enum>(2)</enum><header display-inline="yes-display-inline">Limits on certifications</header><text display-inline="yes-display-inline">An agency or business entity may not
			 execute a certification under paragraph (1) to—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="IDf487a4dfaf624465aa7aa15fd61bb942"><enum>(A)</enum><text display-inline="yes-display-inline">conceal violations of law, inefficiency, or
			 administrative error;</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID51e0f169985f4f06a8b55baf00b4c2b4"><enum>(B)</enum><text display-inline="yes-display-inline">prevent embarrassment to a business entity,
			 organization, or agency;</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDf3bc9fee9cca49da98fc288ad90f2fc8"><enum>(C)</enum><text display-inline="yes-display-inline">restrain competition; or</text>
							</subparagraph><subparagraph id="ID1963960c8dd44f4a85fd938e94f13f40"><enum>(D)</enum><text>delay notification
			 under section 211 for any other reason, except where the agency or business
			 entity reasonably believes an exemption under paragraph (1) applies.</text>
							</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID588bcbb0cc3f49cea8884f01cbd0f4a1"><enum>(3)</enum><header display-inline="yes-display-inline">Notice</header><text display-inline="yes-display-inline">In every case in which an agency or
			 business agency issues a certification under paragraph (1), the certification,
			 accompanied by a description of the factual basis for the certification, shall
			 be immediately provided to the United States Secret Service and the Federal
			 Bureau of Investigation.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID03a548d7bf3d433693c4ab2b1bde7280"><enum>(4)</enum><header display-inline="yes-display-inline">Secret service and FBI review of
			 certifications</header>
							<subparagraph commented="no" display-inline="no-display-inline" id="ID1602d3c72ed54448a19dbf73919739f8"><enum>(A)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">The United States Secret Service or the
			 Federal Bureau of Investigation may review a certification provided by an
			 agency under paragraph (3), and shall review a certification provided by a
			 business entity under paragraph (3), to determine whether an exemption under
			 paragraph (1) is merited. Such review shall be completed not later than 7
			 business days after the date of receipt of the certification, except as
			 provided in paragraph (5)(C).</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDe602279f6bae4c49be04bb7c236a80cd"><enum>(B)</enum><header display-inline="yes-display-inline">Notice</header><text display-inline="yes-display-inline">Upon completing a review under subparagraph
			 (A) the United States Secret Service or the Federal Bureau of Investigation
			 shall immediately notify the agency or business entity, in writing, of its
			 determination of whether an exemption under paragraph (1) is merited.</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDb2f94c610bf4422ead6561388120e2cd"><enum>(C)</enum><header display-inline="yes-display-inline">Exemption</header><text display-inline="yes-display-inline">The exemption under paragraph (1) shall not
			 apply if the United States Secret Service or the Federal Bureau of
			 Investigation determines under this paragraph that the exemption is not
			 merited.</text>
							</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDf148dfa1623544b0a9caa32d0c71db86"><enum>(5)</enum><header display-inline="yes-display-inline">Additional authority of the secret service
			 and FBI</header>
							<subparagraph commented="no" display-inline="no-display-inline" id="ID6517c455849e4249b1b05f812b7277c4"><enum>(A)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">In determining under paragraph (4) whether
			 an exemption under paragraph (1) is merited, the United States Secret Service
			 or the Federal Bureau of Investigation may request additional information from
			 the agency or business entity regarding the basis for the claimed exemption, if
			 such additional information is necessary to determine whether the exemption is
			 merited.</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID431a29e012304bc493848737c25210e5"><enum>(B)</enum><header display-inline="yes-display-inline">Required compliance</header><text display-inline="yes-display-inline">Any agency or business entity that receives
			 a request for additional information under subparagraph (A) shall cooperate
			 with any such request.</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID0b31ef44ccc14992880aa9343f54477c"><enum>(C)</enum><header display-inline="yes-display-inline">Timing</header><text display-inline="yes-display-inline">If the United States Secret Service or the
			 Federal Bureau of Investigation requests additional information under
			 subparagraph (A), the United States Secret Service or the Federal Bureau of
			 Investigation shall notify the agency or business entity not later than 7
			 business days after the date of receipt of the additional information whether
			 an exemption under paragraph (1) is merited.</text>
							</subparagraph></paragraph></subsection><subsection commented="no" id="IDd16da982e8804326b26107a76b6f5a49"><enum>(b)</enum><header>Safe
			 harbor</header>
						<paragraph id="id1048327FFBD64A83BCB37E7B89CE757A"><enum>(1)</enum><header>In
			 general</header><text>An agency or business entity will be exempt from the
			 notice requirements under section 211, if—</text>
							<subparagraph id="id6E1E7A3896154DFDA23E37BA5D302495"><enum>(A)</enum><text>a risk assessment
			 conducted by the agency or business entity concludes that there is no
			 significant risk that a security breach has resulted in, or will result in harm
			 to the individuals whose sensitive personally identifiable information was
			 subject to the security breach; and</text>
							</subparagraph><subparagraph id="id2DB3CE02C63C4AD3A43359FF20DE719C"><enum>(B)</enum><text>the United States
			 Secret Service or the Federal Bureau of Investigation does not indicate within
			 7 business days from the receipt of written notification from an agency or
			 business entity pursuant to subsection (b)(2), that the agency or business
			 entity should not be exempt from the notice requirements of section 211.</text>
							</subparagraph></paragraph><paragraph id="IDdfc4b184e57b4aa2b99029e4127991f3"><enum>(2)</enum><header>Risk assessment
			 requirements</header>
							<subparagraph id="IDd8f96c6236d444b19100ee52dadca44b"><enum>(A)</enum><header>Conducting a
			 risk assessment</header><text>Upon discovery of a security breach of an agency
			 or business entity, the agency or business entity shall conduct a risk
			 assessment to determine if there is a significant risk that the security breach
			 resulted in, or will result in, harm to the individuals whose sensitive
			 personally identifiable information was subject to the security breach.</text>
								<clause id="IDa519077601b7418ba6693f6b5b577c98"><enum>(i)</enum><header>Presumption of
			 no significant risk</header><text>It is presumed that there is no significant
			 risk that the security breach has resulted in, or will result in, harm to the
			 individuals whose sensitive personally identifiable information was subject to
			 the security breach, if such sensitive personally identifiable information has
			 been rendered indecipherable through the use of best practices or methods as
			 described by the Federal Trade Commission, such as redaction, access controls,
			 or other such mechanisms, which are widely accepted as an effective industry
			 practice, or an effective industry standard, or other such mechanisms
			 establishing a presumption that no significant risk exists.</text>
								</clause><clause id="IDdc64780974c34fb4a27c2c67d6b66069"><enum>(ii)</enum><header>Presumption of
			 significant risk</header><text>It is presumed that there is a significant risk
			 that the security breach has resulted in, or will result in, harm to
			 individuals whose sensitive personally identifiable information was subject to
			 the security breach if the agency or business entity failed to render such
			 sensitive personally identifiable information indecipherable through the use of
			 best practices or methods, such as redaction, access controls, or other such
			 mechanisms which are widely accepted as an effective industry practice or an
			 effective industry standard, or other such mechanisms establishing a
			 presumption that a significant risk exists.</text>
								</clause></subparagraph><subparagraph id="ID5a1eadb795584ef6962457bd612be922"><enum>(B)</enum><header>Written
			 notification to law enforcement</header><text>Without unreasonable delay, but
			 not later than 7 days after the discovery of a security breach, unless extended
			 by the United States Secret Service or the Federal Bureau of Investigation, the
			 agency or business entity must notify the United States Secret Service and the
			 Federal Bureau of Investigation, in writing, of—</text>
								<clause id="ID08877ec8fec14356aca23448540ea0e9"><enum>(i)</enum><text>the results of the
			 risk assessment; and</text>
								</clause><clause id="ID63c36fd45f614c5797b40b5cec9f5386"><enum>(ii)</enum><text>its decision to
			 invoke the risk assessment exemption.</text>
								</clause></subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="ID3137a79e39dd461e8ed1121bbe2cc8c4"><enum>(c)</enum><header display-inline="yes-display-inline">Financial fraud prevention
			 exemption</header>
						<paragraph commented="no" display-inline="no-display-inline" id="ID2fa5f58f805649e59111c250cd64d89c"><enum>(1)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">A business entity shall be exempt from the
			 notice requirement under section 211 if the business entity utilizes or
			 participates in a security program that—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="ID1e3ddaeecac341d3ac43346c1b30b6e4"><enum>(A)</enum><text display-inline="yes-display-inline">is designed to block the use of the
			 sensitive personally identifiable information to initiate unauthorized
			 financial transactions before they are charged to the account of the
			 individual; and</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID4e382831c69c4cb7898e45b7562f0db5"><enum>(B)</enum><text display-inline="yes-display-inline">provides for notice to affected individuals
			 after a security breach that has resulted in fraud or unauthorized
			 transactions.</text>
							</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDbbcd5b778fad470b9d59c081de9dd58d"><enum>(2)</enum><header display-inline="yes-display-inline">Limitation</header><text display-inline="yes-display-inline">Paragraph (1) does not apply to a business
			 entity if—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="id537D1A12D0264326A2201A03B154946C"><enum>(A)</enum><text display-inline="yes-display-inline">the information subject to the security
			 breach includes sensitive personally identifiable information, other than a
			 credit card or credit card security code, of any type of the sensitive
			 personally identifiable information identified in section 3; or</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idB059C50331DE456591C43D831EBEA9B5"><enum>(B)</enum><text display-inline="yes-display-inline">the security breach includes both the
			 individual's credit card number and the individual’s first and last
			 name.</text>
							</subparagraph></paragraph></subsection></section><section commented="no" display-inline="no-display-inline" id="IDbe5d0d5a9f634bfbbae2e9371a7cb5ab" section-type="subsequent-section"><enum>213.</enum><header display-inline="yes-display-inline">Methods of notice to
			 individuals</header><text display-inline="no-display-inline">To comply with
			 section 211, an agency or business entity shall provide the following forms of
			 notice:</text>
					<paragraph commented="no" display-inline="no-display-inline" id="ID19cfa3779734495ba271ec2ec3a85bd9"><enum>(1)</enum><header display-inline="yes-display-inline">Individual written notice</header><text display-inline="yes-display-inline">Written notice to individuals by 1 of the
			 following means:</text>
						<subparagraph commented="no" display-inline="no-display-inline" id="ID852b07c2909f42379ca05f7a4131f093"><enum>(A)</enum><text display-inline="yes-display-inline">Individual written notification to the last
			 known home mailing address of the individual in the records of the agency or
			 business entity.</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID97a508ad4f444592bf57a3a5e307dc02"><enum>(B)</enum><text display-inline="yes-display-inline">E-mail notice, unless the individual has
			 expressly opted not to receive such notices of security breaches or the notice
			 is inconsistent with the provisions permitting electronic transmission of
			 notices under section 101 of the Electronic Signatures in Global and National
			 Commerce Act (15 U.S.C. 7001).</text>
						</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="idAB2D19BBC4B14A4B88ADC644D9CCB7CA"><enum>(2)</enum><header>Telephone
			 notice</header><text>Telephone notice to the individual personally.</text>
					</paragraph><paragraph id="IDb3bf164cd82f4ca083354092ea74b09c"><enum>(3)</enum><header>Public
			 notice</header>
						<subparagraph id="IDb43cc414294640d0b4419d234e97c2f4"><enum>(A)</enum><header>Electronic
			 notice</header><text>Prominent notice via all reasonable means of electronic
			 contact between the individual and the agency or business entity, including any
			 website, networked devices, or other interface through which the agency or
			 business entity regularly interacts with the consumer, if the number of
			 individuals whose personally identifiable information was or is reasonably
			 believed to have been accessed or acquired by an unauthorized person exceeds
			 5,000.</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID0db86297bf754ae4a902e952ee3f2f54"><enum>(B)</enum><header display-inline="yes-display-inline">Media notice</header><text display-inline="yes-display-inline">Notice to major media outlets serving a
			 State or jurisdiction, if the number of residents of such State whose sensitive
			 personally identifiable information was, or is reasonably believed to have
			 been, accessed or acquired by an unauthorized person exceeds 5,000.</text>
						</subparagraph></paragraph></section><section commented="no" display-inline="no-display-inline" id="ID80d1a786110544b1b9b1a5fa3fc173b3" section-type="subsequent-section"><enum>214.</enum><header display-inline="yes-display-inline">Content of notice to individuals</header>
					<subsection commented="no" display-inline="no-display-inline" id="IDfa2d92fea3304ca696af6618f796eae0"><enum>(a)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">Regardless of the method by which
			 individual notice is provided to individuals under section 213(1), such notice
			 shall include—</text>
						<paragraph commented="no" display-inline="no-display-inline" id="IDceb22bde1f7a4d6c8796d46691c4cbb8"><enum>(1)</enum><text display-inline="yes-display-inline">a description of the categories of
			 sensitive personally identifiable information that was, or is reasonably
			 believed to have been, accessed or acquired by an unauthorized person, and how
			 the agency or business entity came into possession the sensitive personally
			 identifiable information at issue;</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID28e1b7f46b724a5b9a2ce60cc5131cb7"><enum>(2)</enum><text display-inline="yes-display-inline">a toll-free number—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="IDbd40229a7320422989ee3c0ac557bd8b"><enum>(A)</enum><text display-inline="yes-display-inline">that the individual may use to contact the
			 agency or business entity, or the agent of the agency or business entity;
			 and</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDfc951cf3f101457c8627707bc09e9e0f"><enum>(B)</enum><text display-inline="yes-display-inline">from which the individual may learn what
			 types of sensitive personally identifiable information the agency or business
			 entity maintained about that individual;</text>
							</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDc5bea62ecdf44e3a8787fd9191a02c54"><enum>(3)</enum><text display-inline="yes-display-inline">the toll-free contact telephone numbers,
			 websites, and addresses for the major credit reporting agencies;</text>
						</paragraph><paragraph id="ID05dd4d4647dd45fd81ed40b974df33b3"><enum>(4)</enum><text>the telephone
			 numbers and websites for the relevant Federal agencies that provide information
			 regarding identity theft prevention and protection;</text>
						</paragraph><paragraph id="IDb1e72eb6d6ee4cc3a2dad95269fff59a"><enum>(5)</enum><text>notice that the
			 individual is entitled to receive, at no cost to such individual, consumer
			 credit reports on a quarterly basis for a period of 2 years, credit monitoring
			 or any other service that enables consumers to detect the misuse of sensitive
			 personally identifiable information for a period of 2 years, and instructions
			 to the individual on requesting such reports or service from the agency or
			 business entity;</text>
						</paragraph><paragraph id="ID5596988b159a4780be83257bd2922dd3"><enum>(6)</enum><text>notice that the
			 individual is entitled to receive a security freeze and that the agency or
			 business entity will be liable for any costs associated with the security
			 freeze for 2 years and the necessary instructions for requesting a security
			 freeze; and</text>
						</paragraph><paragraph id="IDf89a178aa5704db1bfa150364768670e"><enum>(7)</enum><text>notice that any
			 costs or damages incurred by an individual as a result of a security breach
			 will be paid by the business entity or agency that experienced the security
			 breach.</text>
						</paragraph></subsection><subsection id="IDbeb1d6d5ddfb44a29bcd23daed46971d"><enum>(b)</enum><header>Telephone
			 notice</header><text>Telephone notice described in section 213(2) shall
			 include, to the extent possible—</text>
						<paragraph id="ID4627bda4ad97469b829690b30b79e7ce"><enum>(1)</enum><text>notification that
			 a security breach has occurred and that the individual’s sensitive personally
			 identifiable information may have been compromised;</text>
						</paragraph><paragraph id="ID8271b610a8fd461ca01b9ea69af47424"><enum>(2)</enum><text>a description of
			 the categories of sensitive personally identifiable information that were, or
			 are reasonably believed to have been, accessed or acquired by an unauthorized
			 person;</text>
						</paragraph><paragraph id="ID61593df17cb540b8aa219c9b7790c4da"><enum>(3)</enum><text>a toll-free number
			 and website—</text>
							<subparagraph id="ID0faa9423183a4ecd962e596767010e06"><enum>(A)</enum><text>that the
			 individual may use to contact the agency or business entity, or the authorized
			 agent of the agency or business entity; and</text>
							</subparagraph><subparagraph id="ID4428c108d86f4606b5695e68a76ceb28"><enum>(B)</enum><text>from which the
			 individual may learn what types of sensitive personally identifiable
			 information the agency or business entity maintained about that individual and
			 remedies available to that individual; and</text>
							</subparagraph></paragraph><paragraph id="ID8dfd382048e54dff85981203694a015d"><enum>(4)</enum><text>an alert to the
			 individual that the agency or business entity is sending or has sent written
			 notification containing additional information as required under section
			 213(1)(A).</text>
						</paragraph></subsection><subsection id="ID256b84574a904ea784fb06c8d48b7672"><enum>(c)</enum><header>Public
			 notice</header><text>Public notice described in section 213(3) shall
			 include—</text>
						<paragraph id="IDd6a82fcbbab0486983d0b82bca4d11c3"><enum>(1)</enum><text>electronic notice,
			 which includes—</text>
							<subparagraph id="ID7a361394ca944d9f92a691300ad6663e"><enum>(A)</enum><text>notification that
			 a security breach has occurred and that the individual’s sensitive personally
			 identifiable information may have been compromised;</text>
							</subparagraph><subparagraph id="IDa16dbb99060a4cf5aad05f05d59cf90a"><enum>(B)</enum><text>a description of
			 the categories of sensitive personally identifiable information that were, or
			 are reasonably believed to have been, accessed or acquired by an unauthorized
			 person; and</text>
							</subparagraph><subparagraph id="ID173a7002c9ca47fb9d57c720b167d892"><enum>(C)</enum><text>a toll-free number
			 and website—</text>
								<clause id="ID57024d62b17a4359ad9272b734bcea8a"><enum>(i)</enum><text>that the
			 individual may use to contact the agency or business entity, or the authorized
			 agent of the agency or business entity; and</text>
								</clause><clause id="ID11f73fea91e34409b4692d1e42e14c83"><enum>(ii)</enum><text>from which the
			 individual may learn what types of sensitive personally identifiable
			 information the agency or business entity maintained about that individual and
			 remedies available to that individual;</text>
								</clause></subparagraph></paragraph><paragraph id="ID0824c2fd3da04ec9afb5859ff6325ea8"><enum>(2)</enum><text>media notice,
			 which includes—</text>
							<subparagraph id="IDf0d105fb40b94dd1ae0ab82f2adaa4bd"><enum>(A)</enum><text>a description of
			 the categories of sensitive personally identifiable information that was, or is
			 reasonably believed to have been, accessed or acquired by an unauthorized
			 person;</text>
							</subparagraph><subparagraph id="ID3f46fbafd2524f5dacb6f9aa16ca2cdf"><enum>(B)</enum><text>a toll-free
			 number—</text>
								<clause id="IDa490932149ca4484b72987dbea8c60ac"><enum>(i)</enum><text>that the
			 individual may use to contact the agency or business entity, or the authorized
			 agent of the agency or business entity; and</text>
								</clause><clause id="IDc336443cef1f48ff8e400a4efd3f3c28"><enum>(ii)</enum><text>from which the
			 individual may learn what types of sensitive personally identifiable
			 information the agency or business entity maintained about that individual and
			 remedies available to that individual;</text>
								</clause></subparagraph><subparagraph id="IDbdf7af2b584b418cbf197dbdb4fa50d9"><enum>(C)</enum><text>the toll-free
			 contact telephone numbers, websites, and addresses for the major credit
			 reporting agencies;</text>
							</subparagraph><subparagraph id="ID730cf48f5c7f4767a83f9c1a73e0fdb2"><enum>(D)</enum><text>the telephone
			 numbers and websites for the relevant Federal agencies that provide information
			 regarding identity theft prevention and protection;</text>
							</subparagraph><subparagraph id="IDc665322dad344364a65ec8ded6f97733"><enum>(E)</enum><text>notice that the
			 affected individuals are entitled to receive, at no cost to such individuals,
			 consumer credit reports on a quarterly basis for a period of 2 years, credit
			 monitoring, or any other service that enables consumers to detect the misuse of
			 sensitive personally identifiable information for a period of 2 years;</text>
							</subparagraph><subparagraph id="ID6b0fceff310643cdac6262a1906f9dd1"><enum>(F)</enum><text>notice that the
			 individual is entitled to receive a security freeze and that the agency or
			 business entity will be liable for any costs associated with the security
			 freeze for 2 years; and</text>
							</subparagraph><subparagraph id="IDfc3896ff922f47dea0b83c9353c7c765"><enum>(G)</enum><text>notice that the
			 individual is entitled to receive compensation from the business entity or
			 agency for any costs or damages incurred by the individual resulting from the
			 security breach.</text>
							</subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="IDdb1385c3b8ef44f2b26816b9ae6527dd"><enum>(d)</enum><header display-inline="yes-display-inline">Additional content</header><text display-inline="yes-display-inline">Notwithstanding section 221, a State may
			 require that a notice under subsection (a) shall also include information
			 regarding victim protection assistance provided for by that State.</text>
					</subsection></section><section id="IDd1a9a538e2ea4808a43d262275fb8cfa"><enum>215.</enum><header>Remedies for
			 security breach</header>
					<subsection id="ID0a24699b032d48449fbee916dfd1e6ad"><enum>(a)</enum><header>Credit reports
			 and credit monitoring</header><text>An agency or business entity required to
			 provide notification under this subtitle shall, upon request of an individual
			 whose sensitive personally identifiable information was included in the
			 security breach, provide or arrange for the provision of, to each such
			 individual and at no cost to such individual—</text>
						<paragraph id="ID3d1b569988fa451488ca5a0142a894f6"><enum>(1)</enum><text>consumer credit
			 reports from not fewer than 1 of the major credit reporting agencies beginning
			 not later than 60 days following the request of the individual and continuing
			 on a quarterly basis for a period of 2 years thereafter; and</text>
						</paragraph><paragraph id="ID6e3b0740fe074f5e800116b15c8a3124"><enum>(2)</enum><text>a credit
			 monitoring or other service that enables consumers to detect the misuse of
			 their personal information, beginning not later than 60 days following the
			 request of the individual and continuing for a period of 2 years.</text>
						</paragraph></subsection><subsection id="ID1a652d047ecc47b29ba96b6d1a3abdbb"><enum>(b)</enum><header>Security
			 freeze</header>
						<paragraph id="IDe8875fcbf6374f19a0cf0ecb0d7975aa"><enum>(1)</enum><header>Request</header><text>Any
			 consumer may submit a written request, by certified mail or such other secure
			 method as authorized by a credit rating agency, to a credit rating agency to
			 place a security freeze on the credit report of the consumer.</text>
						</paragraph><paragraph id="id9E2FEF4432A14710BD23E1F7BC56BA47"><enum>(2)</enum><header>Implementation
			 of security freeze</header><text>Upon receipt of a written request under
			 paragraph (1), a credit rating agency shall—</text>
							<subparagraph id="ID87ab560b94d64832941dfad7397e2140"><enum>(A)</enum><text>not later than 5
			 business days after receipt of the request, place a security freeze on the
			 credit report of the consumer; and</text>
							</subparagraph><subparagraph id="IDea242c10fc2445c6a576097798cd3804"><enum>(B)</enum><text>not later than 10
			 business days after placing a security freeze, send a written confirmation of
			 such security freeze to the consumer, which shall provide the consumer with a
			 unique personal identification number or password to be used by the consumer
			 when providing authorization for the release of the credit report of the
			 consumer to a third party or for a specified period of time.</text>
							</subparagraph></paragraph><paragraph id="ID31580b40999741db955949cdda3f3408"><enum>(3)</enum><header>Duration of
			 security freeze</header><text>Except as provided in paragraph (4), any security
			 freeze authorized pursuant to the provisions of this section shall remain in
			 effect until the consumer requests security freeze to be removed.</text>
						</paragraph><paragraph id="ID36037eb4b4554cac8b452bbba4f1b3dc"><enum>(4)</enum><header>Disclosure of
			 credit report to third party</header>
							<subparagraph id="id1483D96D893D48E797C41ED3C6C67F3F"><enum>(A)</enum><header>In
			 general</header><text>If a consumer that has requested a security freeze under
			 this subsection wishes to authorize the disclosure of the credit report of the
			 consumer to a third party, or for a specified period of time, while such
			 security freeze is in effect, the consumer shall contact the credit rating
			 agency and provide—</text>
								<clause id="ID1ae3ced7d82c4dc986d5ce65bd0fcbde"><enum>(i)</enum><text>proper
			 identification;</text>
								</clause><clause id="ID8ac3dee682844ca18da41c178874aaea"><enum>(ii)</enum><text>the unique
			 personal identification number or password described in paragraph (2)(B);
			 and</text>
								</clause><clause id="IDef729d9bc01e41eab9bd9554df43dca5"><enum>(iii)</enum><text>proper
			 information regarding the third party who is to receive the credit report or
			 the time period for which the credit report shall be available.</text>
								</clause></subparagraph><subparagraph id="id8A920ED0F9E14161BF031B2BF406666E"><enum>(B)</enum><header>Requirement</header><text>Not
			 later than 3 business days after receipt of a request under subparagraph (A), a
			 credit rating agency shall lift the security freeze.</text>
							</subparagraph></paragraph><paragraph id="id206942F485724606AB380337749191DC"><enum>(5)</enum><header>Procedures</header>
							<subparagraph id="id2EDF526F4F0A4F5297AB24F04D7EF0CE"><enum>(A)</enum><header>In
			 general</header><text>A credit rating agency shall develop procedures to
			 receive and process requests from consumers under paragraph (2) of this
			 section.</text>
							</subparagraph><subparagraph id="idF5489C78FC8C49EEB0602E5FCC1C0629"><enum>(B)</enum><header>Requirement</header><text>Procedures
			 developed under subparagraph (A), at a minimum, shall include the ability of a
			 consumer to send such temporary lift or removal request by electronic mail,
			 letter, telephone, or facsimile.</text>
							</subparagraph></paragraph><paragraph id="ID1f39b171a16c43dc9d8cd58c2edcf431"><enum>(6)</enum><header>Requests by
			 third party</header><text>If a third party requests access to a credit report
			 of a consumer that has been frozen under this subsection and the consumer has
			 not authorized the disclosure of the credit report of the consumer to the third
			 party, the third party may deem such credit application as incomplete.</text>
						</paragraph><paragraph id="IDef6404ea7c3848c0bb8af0451a467b07"><enum>(7)</enum><header>Determination by
			 credit rating agency</header>
							<subparagraph id="id5FB383B167334A7EB7DD4F0DE676522F"><enum>(A)</enum><header>In
			 general</header><text>A credit rating agency may refuse to implement or may
			 remove a security freeze under this subsection if the agency determines, in
			 good faith, that—</text>
								<clause id="ID795a86068b154d7c950c83b4610e4882"><enum>(i)</enum><text>the request for a
			 security freeze was made as part of a fraud that the consumer participated in,
			 had knowledge of, or that can be demonstrated by circumstantial evidence;
			 or</text>
								</clause><clause id="IDd2d85eb4c1a44a749827a7e443f3bce2"><enum>(ii)</enum><text>the consumer
			 credit report was frozen due to a material misrepresentation of fact by the
			 consumer.</text>
								</clause></subparagraph><subparagraph id="id3322C6B8B2D943FDABAE346C1312FE7A"><enum>(B)</enum><header>Notice</header><text>If
			 a credit rating agency makes a determination under subparagraph (A) to not
			 implement, or to remove, a security freeze under this subsection, the credit
			 rating agency shall notify the consumer in writing of such
			 determination—</text>
								<clause id="id9933C69764F94AC8A6B14D4597789D4E"><enum>(i)</enum><text>in the case of a
			 determination not to implement a security freeze, not later than 5 business
			 days after the determination is made; and</text>
								</clause><clause id="idA33FD9BD88014A5E83F338B4E2803F6E"><enum>(ii)</enum><text>in the case of a
			 removal of a security freeze, prior to removing the freeze on the credit report
			 of the consumer.</text>
								</clause></subparagraph></paragraph><paragraph id="IDa9aa3597dea54c0c94e4be4da9da230d"><enum>(8)</enum><header>Rule of
			 construction</header><text>Nothing in this section shall be construed to
			 prohibit disclosure of a credit report of a consumer to—</text>
							<subparagraph id="ID3e522a0bd4274c858828f7b9f11d1563"><enum>(A)</enum><text>a person, or the
			 person's subsidiary, affiliate, agent or assignee with which the consumer has
			 or, prior to assignment, had an account, contract or debtor-creditor
			 relationship for the purpose of reviewing the account or collecting the
			 financial obligation owing for the account, contract or debt;</text>
							</subparagraph><subparagraph id="IDc4da75fed47c4b2789211ad6d4e44d95"><enum>(B)</enum><text>a subsidiary,
			 affiliate, agent, assignee or prospective assignee of a person to whom access
			 has been granted under paragraph (4) for the purpose of facilitating the
			 extension of credit or other permissible use;</text>
							</subparagraph><subparagraph id="ID0f9792842b444b3c96776f3e5408248a"><enum>(C)</enum><text>any person acting
			 pursuant to a court order, warrant or subpoena;</text>
							</subparagraph><subparagraph id="IDb3e23a81856d46fca563c2737e5d9e09"><enum>(D)</enum><text>any person for the
			 purpose of using such credit information to prescreen as provided by the Fair
			 Credit Reporting Act (15 U.S.C. 1681 et seq.);</text>
							</subparagraph><subparagraph id="ID68d1724c19a3481cb36bfffd893ebc39"><enum>(E)</enum><text>any person for the
			 sole purpose of providing a credit file monitoring subscription service to
			 which the consumer has subscribed;</text>
							</subparagraph><subparagraph id="IDe34f39ffff884542aac2069e4767d835"><enum>(F)</enum><text>a credit rating
			 agency for the sole purpose of providing a consumer with a copy of the credit
			 report of the consumer upon the request of the consumer; or</text>
							</subparagraph><subparagraph id="ID7d3d095d92854c309578a681f243c293"><enum>(G)</enum><text>a Federal, State
			 or local governmental entity, including a law enforcement agency, or court, or
			 their agents or assignees pursuant to their statutory or regulatory duties. For
			 purposes of this subsection, <quote>reviewing the account</quote> includes
			 activities related to account maintenance, monitoring, credit line increases
			 and account upgrades and enhancements; and</text>
							</subparagraph><subparagraph commented="no" id="ID3ef3045874d2407ab03e98380705f0d7"><enum>(H)</enum><text>any person for the
			 sole purpose of providing a remedy requested by an individual under this
			 section.</text>
							</subparagraph></paragraph><paragraph id="ID15c29d441b9d4f8497c29a3649c5c8d9"><enum>(9)</enum><header>Exceptions</header><text>The
			 following persons shall not be required to place a security freeze under this
			 subsection, but shall be subject to any security freeze placed on a credit
			 report by another credit rating agency:</text>
							<subparagraph id="id3ABA4BDC859B428BA7FA6EA9998EC2FA"><enum>(A)</enum><text>A check services
			 or fraud prevention services company that reports on incidents of fraud or
			 issues authorizations for the purpose of approving or processing negotiable
			 instruments, electronic fund transfers or similar methods of payment.</text>
							</subparagraph><subparagraph id="id4A87048E96674C38B316A926BC3C1E9D"><enum>(B)</enum><text>A deposit account
			 information service company that issues reports regarding account closures due
			 to fraud, substantial overdrafts, automated teller machine abuse, or similar
			 information regarding a consumer to inquiring banks or other financial
			 institutions for use only in reviewing a consumer request for a deposit account
			 at the inquiring bank or financial institution.</text>
							</subparagraph><subparagraph id="id5DDA3B4C84FC4908952FFB42A23B2894"><enum>(C)</enum><text>A credit rating
			 agency that—</text>
								<clause id="id9ADA1F6908284B4AAFE269C919EA0ADA"><enum>(i)</enum><text>acts only to
			 resell credit information by assembling and merging information contained in a
			 database of 1 or more credit reporting agencies; and</text>
								</clause><clause id="idF4B021FC88C1481E83D72C3A89A6BCE6"><enum>(ii)</enum><text>does not maintain
			 a permanent database of credit information from which new credit reports are
			 produced.</text>
								</clause></subparagraph></paragraph><paragraph id="ID3141b7a9861d4c5fac16208557b0e3ec"><enum>(10)</enum><header>Fees</header>
							<subparagraph id="id0D2D8444575D4E42B382A4088578032F"><enum>(A)</enum><header>In
			 general</header><text>A credit rating agency may charge reasonable fees for
			 each security freeze, removal of such freeze or temporary lift of such freeze
			 for a period of time, and a temporary lift of such freeze for a specific
			 party.</text>
							</subparagraph><subparagraph id="idA7F003B7DCD148CB8853A3378667E51F"><enum>(B)</enum><header>Requirement</header><text>Any
			 fees charged under subparagraph (A) shall be borne by the agency or business
			 entity providing notice under section 214 for 2 years following the
			 establishment of the security freeze under this subsection.</text>
							</subparagraph></paragraph></subsection><subsection id="ID4195917d41974963a60d6f46db29688b"><enum>(c)</enum><header>Costs resulting
			 from a security breach</header>
						<paragraph id="ID8983a5c4cc7a41db97f07906aed49970"><enum>(1)</enum><header>In
			 general</header><text>A business entity or agency that experiences a security
			 breach and is required to provide notice under this subtitle shall pay, upon
			 request, to any individual whose sensitive personally identifiable information
			 has been, or is reasonably believed to have been, accessed or acquired as a
			 result of such security breach, any costs or damages incurred by the individual
			 as a result of such security breach, including costs associated with identity
			 theft suffered as a result of such security breach.</text>
						</paragraph><paragraph id="ID53e6faab52384107a240e47cb5d3527f"><enum>(2)</enum><header>Compliance</header><text>A
			 business entity or agency shall be deemed in compliance with this subsection if
			 the business entity or agency—</text>
							<subparagraph id="ID4a369dde352a4591971c7ef26a6c87f3"><enum>(A)</enum><text>provides insurance
			 to any individual whose sensitive personally identifiable information has been,
			 or is reasonably believed to have been, accessed or acquired as a result of a
			 security breach and such insurance is sufficient to compensate the consumer for
			 not less than $25,000 of costs or damages; or</text>
							</subparagraph><subparagraph id="ID419b7ead23ec455bb6698fcb7ac0a384"><enum>(B)</enum><text>pays, without
			 unreasonable delay, any actual costs or damages incurred by an individual as a
			 result of the security breach.</text>
							</subparagraph></paragraph></subsection></section><section commented="no" display-inline="no-display-inline" id="ID82ad6f96b46a4c7388f833d7611a6fc3" section-type="subsequent-section"><enum>216.</enum><header display-inline="yes-display-inline">Notice to credit reporting
			 agencies</header><text display-inline="no-display-inline">If an agency or
			 business entity is required to provide notification to more than 5,000
			 individuals under section 211(a), the agency or business entity shall also
			 notify all consumer reporting agencies that compile and maintain files on
			 consumers on a nationwide basis (as defined in section 603(p) of the Fair
			 Credit Reporting Act (15 U.S.C. 1681a(p)) of the timing and distribution of the
			 notices. Such notice shall be given to the consumer credit reporting agencies
			 without unreasonable delay and, if it will not delay notice to the affected
			 individuals, prior to the distribution of notices to the affected
			 individuals.</text>
				</section><section commented="no" display-inline="no-display-inline" id="IDde1241e504f94594beb8e50db8943996" section-type="subsequent-section"><enum>217.</enum><header display-inline="yes-display-inline">Notice to law enforcement</header>
					<subsection commented="no" display-inline="no-display-inline" id="ID6470f926c275412da556385924db03f0"><enum>(a)</enum><header display-inline="yes-display-inline">Secret service and FBI</header><text display-inline="yes-display-inline">Any business entity or agency shall notify
			 the United States Secret Service and the Federal Bureau of Investigation of the
			 fact that a security breach has occurred if—</text>
						<paragraph commented="no" display-inline="no-display-inline" id="ID25eedd40ea824dffb164a4b7c3699d78"><enum>(1)</enum><text display-inline="yes-display-inline">the number of individuals whose sensitive
			 personally identifying information was, or is reasonably believed to have been
			 accessed or acquired by an unauthorized person exceeds 5,000;</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID274b8ba63d414bbea3287932981bcb9e"><enum>(2)</enum><text display-inline="yes-display-inline">the security breach involves a database,
			 networked or integrated databases, or other data system containing the
			 sensitive personally identifiable information of more than 500,000 individuals
			 nationwide;</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDd6ac3a83b97545cba8b1492d56e51717"><enum>(3)</enum><text display-inline="yes-display-inline">the security breach involves databases
			 owned by the Federal Government; or</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID1f9e4a10bebc46e6a27dd33efeb1c501"><enum>(4)</enum><text display-inline="yes-display-inline">the security breach involves primarily
			 sensitive personally identifiable information of individuals known to the
			 agency or business entity to be employees and contractors of the Federal
			 Government involved in national security or law enforcement.</text>
						</paragraph></subsection><subsection id="ID6a639f2340dc431a8d88c90004cc9e8e"><enum>(b)</enum><header>FTC review of
			 thresholds</header><text>The Federal Trade Commission may alter the
			 circumstances under which notification is required under subsection (a) in a
			 matter consistent with the public interest.</text>
					</subsection><subsection commented="no" display-inline="no-display-inline" id="ID2876b95d5ce348b68756b462b093b46c"><enum>(c)</enum><header display-inline="yes-display-inline">Notice to other law enforcement
			 agencies</header><text display-inline="yes-display-inline">The United States
			 Secret Service and the Federal Bureau of Investigation shall be responsible for
			 notifying—</text>
						<paragraph commented="no" display-inline="no-display-inline" id="ID2f36ab20661346abb989fad28adfa9f8"><enum>(1)</enum><text display-inline="yes-display-inline">the United States Postal Inspection
			 Service, if the security breach involves mail fraud;</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDcdf577b7108b42459b612171122e7e16"><enum>(2)</enum><text display-inline="yes-display-inline">the attorney general of each State affected
			 by the security breach; and</text>
						</paragraph><paragraph id="ID495feda6869a4089ac85885633126e24"><enum>(3)</enum><text>the Federal Trade
			 Commission, if the security breach involves consumer reporting agencies subject
			 to the Fair Credit Reporting Act (15 U.S.C. 1681 et seq.), or anticompetitive
			 conduct.</text>
						</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="idF9AAB61503E149CB80A21B96C66251B8"><enum>(d)</enum><header display-inline="yes-display-inline">Timing of notices</header><text display-inline="yes-display-inline">The notices required under this section
			 shall be delivered as follows:</text>
						<paragraph commented="no" display-inline="no-display-inline" id="IDc7204f9082b7462e811801d0ff03a6f9"><enum>(1)</enum><text display-inline="yes-display-inline">Notice under subsection (a) shall be
			 delivered as promptly as possible, but not later than 10 days after discovery
			 of the security breach.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID8ea1687feefa47b48adfa72874d9a9c8"><enum>(2)</enum><text display-inline="yes-display-inline">Notice under section 211 shall be delivered
			 to individuals not later than 48 hours after the Federal Bureau of
			 Investigation or the Secret Service receives notice of a security breach from
			 an agency or business entity.</text>
						</paragraph></subsection></section><section commented="no" display-inline="no-display-inline" id="ID300c058705674d1fa8a20180588bc781" section-type="subsequent-section"><enum>218.</enum><header display-inline="yes-display-inline">Federal enforcement</header>
					<subsection commented="no" display-inline="no-display-inline" id="IDbe141416b255483ab71bcf923f75d07e"><enum>(a)</enum><header display-inline="yes-display-inline">Civil actions by the Attorney
			 General</header>
						<paragraph commented="no" display-inline="no-display-inline" id="idDF48599E2D66454E9641E99B04EB8771"><enum>(1)</enum><header>In
			 general</header><text display-inline="yes-display-inline">The Attorney General
			 may bring a civil action in the appropriate United States district court
			 against any business entity that engages in conduct constituting a violation of
			 this subtitle and, upon proof of such conduct by a preponderance of the
			 evidence, such business entity shall be subject to a civil penalty of not more
			 than $500 per day per individual whose sensitive personally identifiable
			 information was, or is reasonably believed to have been, accessed or acquired
			 by an unauthorized person, up to a maximum of $20,000,000 per violation, unless
			 such conduct is found to be willful or intentional.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="idF2D4990F2C5440A5B68076E9F4C4BA5F"><enum>(2)</enum><header>Presumption</header><text display-inline="yes-display-inline">A violation of section 212(a)(2) shall be
			 presumed to be willful or intentional conduct.</text>
						</paragraph></subsection><subsection id="id4CFF858575F840EDBC141045604FD12D"><enum>(b)</enum><header>Considerations</header><text>In
			 determining the amount of a civil penalty under this subsection, the court
			 shall take into account—</text>
						<paragraph id="id548CF406A9904F9E9D4FCE4E896E7FB1"><enum>(1)</enum><text>the degree of
			 culpability of the business entity;</text>
						</paragraph><paragraph id="idDFBB154BF36542A896185D8B1A956553"><enum>(2)</enum><text>any prior
			 violations of this subtitle by the business entity;</text>
						</paragraph><paragraph id="id70832C1E43A949DEA6C848E07DEAF50F"><enum>(3)</enum><text>the ability of the
			 business entity to pay a civil penalty;</text>
						</paragraph><paragraph id="idDEF24BA7E535423EB0EB6C99F395285A"><enum>(4)</enum><text>the effect on the
			 ability of the business entity to continue to do business;</text>
						</paragraph><paragraph id="idD4D3ADEC966B47AC9D7632A2F27B9DCA"><enum>(5)</enum><text>the number of
			 individuals whose personally identifiable information was compromised by the
			 breach;</text>
						</paragraph><paragraph id="idB9CC2BC32D3747F4A2F7CEFC76D4A283"><enum>(6)</enum><text>the relative cost
			 of compliance with this subtitle; and</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="idEDE32F4A22B9444780BC27183BFB94D5"><enum>(7)</enum><text>such other matters
			 as justice may require.</text>
						</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="ID631759b47738493ba66ec30f99662368"><enum>(c)</enum><header display-inline="yes-display-inline">Injunctive actions by the Attorney
			 General</header>
						<paragraph commented="no" display-inline="no-display-inline" id="idA40BA83000324B59A06AB9324F2EE801"><enum>(1)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">If it appears that a business entity has
			 engaged, or is engaged, in any act or practice constituting a violation of this
			 subtitle, the Attorney General may petition an appropriate district court of
			 the United States for an order—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="ID74548a65207a4be1b5560768fd8301ec"><enum>(A)</enum><text display-inline="yes-display-inline">enjoining such act or practice; or</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDeb83e5afed4e49eca123a19958cb01d7"><enum>(B)</enum><text display-inline="yes-display-inline">enforcing compliance with this
			 subtitle.</text>
							</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="idA696A113E8B84FC592D67CA706DB4191"><enum>(2)</enum><header display-inline="yes-display-inline">Issuance of order</header><text display-inline="yes-display-inline">A court may issue an order under paragraph
			 (1), if the court finds that the conduct in question constitutes a violation of
			 this subtitle.</text>
						</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="ID2d946cff5da64c3eacb4d51276222d66"><enum>(d)</enum><header display-inline="yes-display-inline">Other rights and remedies</header><text display-inline="yes-display-inline">The rights and remedies available under
			 this subtitle are cumulative and shall not affect any other rights and remedies
			 available under law.</text>
					</subsection><subsection commented="no" display-inline="no-display-inline" id="ID5874a4e4f1ba4c40b090e66b9db432eb"><enum>(e)</enum><header display-inline="yes-display-inline">Fraud alert</header><text display-inline="yes-display-inline">Section 605A(b)(1) of the Fair Credit
			 Reporting Act (15 U.S.C. 1681c–1(b)(1)) is amended by inserting <quote>, or
			 evidence that the consumer has received notice that the consumer's financial
			 information has or may have been compromised,</quote> after <quote>identity
			 theft report</quote>.</text>
					</subsection></section><section commented="no" display-inline="no-display-inline" id="ID28d22f15074d4f239f64734d16e27d82" section-type="subsequent-section"><enum>219.</enum><header display-inline="yes-display-inline">Enforcement by State attorneys
			 general</header>
					<subsection commented="no" display-inline="no-display-inline" id="ID158448a7945943d2800a68223fa1c66f"><enum>(a)</enum><header display-inline="yes-display-inline">In general</header>
						<paragraph commented="no" display-inline="no-display-inline" id="ID5e7013c2684b41fcaaa6367e9a467271"><enum>(1)</enum><header display-inline="yes-display-inline">Civil actions</header>
							<subparagraph commented="no" display-inline="no-display-inline" id="idC027FD8F49D343F79286A77551F9A882"><enum>(A)</enum><header>In
			 general</header><text display-inline="yes-display-inline">In any case in which
			 the attorney general of a State or any State or local law enforcement agency
			 authorized by the State attorney general or by State statute to prosecute
			 violations of consumer protection law, has reason to believe that an interest
			 of the residents of that State has been or is threatened or adversely affected
			 by the engagement of a business entity in a practice that is prohibited under
			 this subtitle, the State or the State or local law enforcement agency on behalf
			 of the residents of the agency’s jurisdiction, may bring a civil action on
			 behalf of the residents of the State or jurisdiction in a district court of the
			 United States of appropriate jurisdiction or any other court of competent
			 jurisdiction, including a State court, to—</text>
								<clause commented="no" display-inline="no-display-inline" id="ID06956a544afc45749fc0dbd4ca0ac7b0"><enum>(i)</enum><text display-inline="yes-display-inline">enjoin that practice;</text>
								</clause><clause commented="no" display-inline="no-display-inline" id="ID9c8b6e64896e4dac88bd5fde14d8348f"><enum>(ii)</enum><text display-inline="yes-display-inline">enforce compliance with this subtitle;
			 or</text>
								</clause><clause commented="no" display-inline="no-display-inline" id="ID1e58ea4082c74d2ca134ca9129b3c6bc"><enum>(iii)</enum><text display-inline="yes-display-inline">obtain civil penalties of not more than
			 $500 per day per individual whose sensitive personally identifiable information
			 was, or is reasonably believed to have been, accessed or acquired by an
			 unauthorized person, up to a maximum of $20,000,000 per violation, unless such
			 conduct is found to be willful or intentional.</text>
								</clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idE51310569FA94CB08A33DCECE1FDF409"><enum>(B)</enum><header>Presumption</header><text display-inline="yes-display-inline">A violation of section 212(a)(2) shall be
			 presumed to be willful or intentional.</text>
							</subparagraph></paragraph><paragraph id="IDc67ff4068c2049f694727ef3c247944a"><enum>(2)</enum><header>Considerations</header><text>In
			 determining the amount of a civil penalty under this subsection, the court
			 shall take into account—</text>
							<subparagraph id="id9E20BF9C5FCD48E98F99EE0546697ED8"><enum>(A)</enum><text>the degree of
			 culpability of the business entity;</text>
							</subparagraph><subparagraph id="id1AB7A285260D4E11A5E1AF847654BCA5"><enum>(B)</enum><text>any prior
			 violations of this subtitle by the business entity;</text>
							</subparagraph><subparagraph id="id601849FA65A74D1BABE4742E9D0ADA53"><enum>(C)</enum><text>the ability of the
			 business entity to pay a civil penalty;</text>
							</subparagraph><subparagraph id="idB6E9028FC5A04814BFCCE0990D5C38C0"><enum>(D)</enum><text>the effect on the
			 ability of the business entity to continue to do business;</text>
							</subparagraph><subparagraph id="id9348923A3AF744EC98D15557E21393C5"><enum>(E)</enum><text>the number of
			 individuals whose personally identifiable information was compromised by the
			 breach;</text>
							</subparagraph><subparagraph id="idBC56E9A8606146B4B98F0D623866F505"><enum>(F)</enum><text>the relative cost
			 of compliance with this subtitle; and</text>
							</subparagraph><subparagraph id="idD03BA8CAD456490ABA16DC8CC3D71572"><enum>(G)</enum><text>such other matters
			 as justice may require.</text>
							</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDcac299cc128a49aaa541ed6dd90eb98c"><enum>(3)</enum><header display-inline="yes-display-inline">Notice</header>
							<subparagraph commented="no" display-inline="no-display-inline" id="ID36cb88ea917c4f3bbfd3588bf949c4e0"><enum>(A)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">Before filing an action under paragraph
			 (1), the attorney general of the State involved shall provide to the Attorney
			 General of the United States—</text>
								<clause commented="no" display-inline="no-display-inline" id="ID529bbf03fe7f4c7594b9508261fe891a"><enum>(i)</enum><text display-inline="yes-display-inline">written notice of the action; and</text>
								</clause><clause commented="no" display-inline="no-display-inline" id="IDe2292626c56a40f7aa11edc6929dcaf4"><enum>(ii)</enum><text display-inline="yes-display-inline">a copy of the complaint for the
			 action.</text>
								</clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID0ad31433f66a4571a9f315c10cdd38c2"><enum>(B)</enum><header display-inline="yes-display-inline">Exemption</header>
								<clause commented="no" display-inline="no-display-inline" id="ID9c3e5026e335415f94ddf78c665486e0"><enum>(i)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">Subparagraph (A) shall not apply with
			 respect to the filing of an action by an attorney general of a State under this
			 subtitle, if the State attorney general determines that it is not feasible to
			 provide the notice described in such subparagraph before the filing of the
			 action.</text>
								</clause><clause commented="no" display-inline="no-display-inline" id="ID29e7139ab7c24cd79ce8b2cad0fba4b8"><enum>(ii)</enum><header display-inline="yes-display-inline">Notification</header><text display-inline="yes-display-inline">In an action described in clause (i), the
			 attorney general of a State shall provide notice and a copy of the complaint to
			 the Attorney General at the time the State attorney general files the
			 action.</text>
								</clause></subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="IDb4eb145eecea482ab7ecbe2f6d40f36c"><enum>(b)</enum><header display-inline="yes-display-inline">Federal proceedings</header><text display-inline="yes-display-inline">Upon receiving notice under subsection
			 (a)(2), the Attorney General shall have the right to—</text>
						<paragraph commented="no" display-inline="no-display-inline" id="ID26f41fd7f1cf46ffad598e468846a90a"><enum>(1)</enum><text display-inline="yes-display-inline">move to stay the action, pending the final
			 disposition of a pending Federal proceeding or action;</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id4E300CFE489848D1B21A6A1A6258C25E"><enum>(2)</enum><text display-inline="yes-display-inline">initiate an action in the appropriate
			 United States district court under section 217 and move to consolidate all
			 pending actions, including State actions, in such court;</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID66487e1b00654427bbd02a953c7f3344"><enum>(3)</enum><text display-inline="yes-display-inline">intervene in an action brought under
			 subsection (a)(2); and</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID6fb3b32f5626404b9d0907977a93d1d0"><enum>(4)</enum><text display-inline="yes-display-inline">file petitions for appeal.</text>
						</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="IDb15d3714cf524105a323f95c838f931c"><enum>(c)</enum><header display-inline="yes-display-inline">Pending proceedings</header><text display-inline="yes-display-inline">If the Attorney General has instituted a
			 proceeding or action for a violation of this subtitle or any regulations
			 thereunder, no attorney general of a State may, during the pendency of such
			 proceeding or action, bring an action under this subtitle against any defendant
			 named in such criminal proceeding or civil action for any violation that is
			 alleged in that proceeding or action.</text>
					</subsection><subsection commented="no" display-inline="no-display-inline" id="ID11b3d09326ab42b5a7039ab72e901f56"><enum>(d)</enum><header display-inline="yes-display-inline">Construction</header><text display-inline="yes-display-inline">For purposes of bringing any civil action
			 under subsection (a), nothing in this subtitle regarding notification shall be
			 construed to prevent an attorney general of a State from exercising the powers
			 conferred on such attorney general by the laws of that State to—</text>
						<paragraph commented="no" display-inline="no-display-inline" id="IDf0b18861c7dd4211aefde7a73679597c"><enum>(1)</enum><text display-inline="yes-display-inline">conduct investigations;</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDc52d3767f683458e8510bfda8261c65e"><enum>(2)</enum><text display-inline="yes-display-inline">administer oaths or affirmations; or</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDa7edebada22b454c840d70f0fff4c763"><enum>(3)</enum><text display-inline="yes-display-inline">compel the attendance of witnesses or the
			 production of documentary and other evidence.</text>
						</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="ID79f340f19ca84e1b8a9b8f1ce237716e"><enum>(e)</enum><header display-inline="yes-display-inline">Venue; service of process</header>
						<paragraph commented="no" display-inline="no-display-inline" id="ID2c88083250b3444a832e60e4ce40a2ba"><enum>(1)</enum><header display-inline="yes-display-inline">Venue</header><text display-inline="yes-display-inline">Any action brought under subsection (a) may
			 be brought in—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="IDf0a91014a2a84fd99bea1e2c7bdcdca3"><enum>(A)</enum><text display-inline="yes-display-inline">the district court of the United States
			 that meets applicable requirements relating to venue under section 1391 of
			 title 28, United States Code; or</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID8639d88534d8455097a8b05a580b0de3"><enum>(B)</enum><text display-inline="yes-display-inline">another court of competent
			 jurisdiction.</text>
							</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDf957252071c14424b32a3b3ead23cfb0"><enum>(2)</enum><header display-inline="yes-display-inline">Service of process</header><text display-inline="yes-display-inline">In an action brought under subsection (a),
			 process may be served in any district in which the defendant—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="ID0708d5b6cfac45f0b642801232c2bfbe"><enum>(A)</enum><text display-inline="yes-display-inline">is an inhabitant; or</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDd8a6af6a09b544afa2b24224adf2c9cc"><enum>(B)</enum><text display-inline="yes-display-inline">may be found.</text>
							</subparagraph></paragraph></subsection></section><section id="IDe9a2f5c9f18946eb836a3d703c1489b9"><enum>220.</enum><header>Supplemental
			 enforcement by individuals</header>
					<subsection id="IDbcfa88e9efe04efba00ad0ee8d508b77"><enum>(a)</enum><header>In
			 general</header><text>Any person aggrieved by a violation of the provisions of
			 section 211, 213, 214, 215, or 216 by a business entity may bring a civil
			 action in a court of appropriate jurisdiction to recover for personal injuries
			 sustained as a result of the violation.</text>
					</subsection><subsection id="ID2f2518f66e4d4d529aa84170f54c23ca"><enum>(b)</enum><header>Remedies in a
			 citizen suit</header>
						<paragraph id="idA270A29A78094B81B4E921277B88CA09"><enum>(1)</enum><header>Damages</header><text>Any
			 individual harmed by a failure of a business entity to comply with the
			 provisions of section 211, 213, 214, 215, or 216, shall be able to collect
			 damages of not more than $500 per day per individual whose sensitive personally
			 identifiable information was, or is reasonably believed to have been, accessed
			 or acquired by an unauthorized person, up to a maximum of $20,000,000 per
			 violation.</text>
						</paragraph><paragraph id="ID039c90451c4a472c8dc81608f95fb97e"><enum>(2)</enum><header>Punitive
			 damages</header><text>A business entity may be liable for punitive damages if
			 it—</text>
							<subparagraph id="IDc07d749cd4d640508f95aa55238fa8cf"><enum>(A)</enum><text>intentionally or
			 willfully violates the provisions of section 211, 213, 214, 215, or 216;
			 or</text>
							</subparagraph><subparagraph id="ID78a656a303fe45de8c3f0bd3efacaa99"><enum>(B)</enum><text>failed to comply
			 with the requirements of subsections (a) through (d) of section 202.</text>
							</subparagraph></paragraph><paragraph id="ID16500d58e0a4468db633e6072e393210"><enum>(3)</enum><header>Equitable
			 relief</header><text>A business entity that violates the provisions of section
			 211, 213, 214, 215, or 216 may be enjoined to provide required remedies under
			 section 215 by a court of competent jurisdiction.</text>
						</paragraph><paragraph id="IDc68a904b5c894434ab29b9165207d473"><enum>(4)</enum><header>Other rights and
			 remedies</header><text>The rights and remedies available under this subsection
			 are cumulative and shall not affect any other rights and remedies available
			 under law.</text>
						</paragraph></subsection><subsection id="IDb362e02c0c554fbc907b72214a6ed6fc"><enum>(c)</enum><header>Access to
			 justice</header><text>The rights and remedies afforded by this section shall
			 not be abridged or precluded by any predispute arbitration agreement, and any
			 claims under this section that arise from the same security breach are presumed
			 to meet the commonality requirement under rule 23(a)(2) of the Federal Rules of
			 Civil Procedure.</text>
					</subsection></section><section commented="no" display-inline="no-display-inline" id="IDa5c5ed85f5b948b08f30d0800295937a"><enum>221.</enum><header display-inline="yes-display-inline">Relation to other laws</header>
					<subsection commented="no" display-inline="no-display-inline" id="idC5FED7093E304F548BB6172EE4EB79DE"><enum>(a)</enum><header>In
			 general</header><text display-inline="yes-display-inline">The provisions of
			 this subtitle shall supersede any other provision of Federal law or any
			 provision of law of any State relating to notification by a business entity
			 engaged in interstate commerce or an agency of a security breach, except as
			 provided in section 214(c).</text>
					</subsection><subsection commented="no" id="ID4c6510dc27474c1fb8d89793026060f1"><enum>(b)</enum><header>Rule of
			 construction</header><text>Nothing in this subtitle shall be construed to
			 exempt any entity from liability under common law, including through the
			 operation of ordinary preemption principles, for damages caused by the failure
			 to notify an individual following a security breach.</text>
					</subsection><subsection commented="no" id="idBB677D4822E743DB899CC690914B63EA"><enum>(c)</enum><header>Presumption of
			 per se negligence</header><text>If a business entity fails to comply with the
			 requirements in section 211, 212, 213, 214, 215, or 216, there shall be a
			 presumption that the entity was per se negligent.</text>
					</subsection></section><section commented="no" display-inline="no-display-inline" id="ID90730e6c13ca4a49b382b3f1e9ee896e"><enum>222.</enum><header display-inline="yes-display-inline">Authorization of
			 appropriations</header><text display-inline="no-display-inline">There are
			 authorized to be appropriated such sums as may be necessary to cover the costs
			 incurred by the United States Secret Service to carry out investigations and
			 risk assessments of security breaches as required under this subtitle.</text>
				</section><section commented="no" display-inline="no-display-inline" id="ID0c5c8ec1f3e24cd886be5d8e2f850ca7"><enum>223.</enum><header display-inline="yes-display-inline">Reporting on risk assessment
			 exemptions</header><text display-inline="no-display-inline">The United States
			 Secret Service and the Federal Bureau of Investigation shall report to Congress
			 not later than 18 months after the date of enactment of this Act, and upon the
			 request by Congress thereafter, on—</text>
					<paragraph commented="no" display-inline="no-display-inline" id="IDa7b8f800cc534389b40bb6e89642575f"><enum>(1)</enum><text display-inline="yes-display-inline">the number and nature of the security
			 breaches described in the notices filed by those business entities invoking the
			 risk assessment exemption under section 212(b) and the response of the United
			 States Secret Service and the Federal Bureau of Investigation to such notices;
			 and</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID2882bcf4ab6e40599f78f745dbac92ff"><enum>(2)</enum><text display-inline="yes-display-inline">the number and nature of security breaches
			 subject to the national security and law enforcement exemptions under section
			 212(a), provided that such report may not disclose the contents of any risk
			 assessment provided to the United States Secret Service and the Federal Bureau
			 of Investigation pursuant to this subtitle.</text>
					</paragraph></section></subtitle><subtitle id="idA5C50B11C7414F79894531F4CFED06C9"><enum>C</enum><header>Post-Breach
			 technical information clearinghouse</header>
				<section id="id4065DF23EA25436984EB9D2241C0450E"><enum>230.</enum><header>Clearinghouse
			 information collection, maintenance, and access</header>
					<subsection id="ID81d647d163374a5bb8cd37691607cefd"><enum>(a)</enum><header>In
			 general</header><text>The Attorney General shall maintain a clearinghouse of
			 technical information concerning system vulnerabilities identified in the wake
			 of security breaches, which shall—</text>
						<paragraph id="idCAC29A4D70EE4901B704131B82B928E2"><enum>(1)</enum><text>contain
			 information disclosed by agencies or business entities under subsection (b);
			 and</text>
						</paragraph><paragraph id="id936B85BBBA8C4E9CB45555ECBC6AAE82"><enum>(2)</enum><text>be accessible to
			 certified entities under subsection (c).</text>
						</paragraph></subsection><subsection id="IDbfa01f2c351b429c89d3b19bf56096d2"><enum>(b)</enum><header>Post-Breach
			 technical notification</header><text>In any instance where an agency or
			 business entity is required to notify the United States Secret Service and the
			 Federal Bureau of Investigation under section 217, the agency or business
			 entity shall also provide the Attorney General with technical information
			 concerning the nature of the security breach, including—</text>
						<paragraph id="ID125f9f7928394ebd8e60d5ddad0efeac"><enum>(1)</enum><text>technical
			 information regarding any system vulnerabilities of the agency or business
			 entity revealed by or identified as a consequence of the security
			 breach;</text>
						</paragraph><paragraph id="IDabbea1c74b94484c8cc2ea265680ca6d"><enum>(2)</enum><text>technical
			 information regarding any system vulnerabilities of the agency or business
			 entity actually exploited during the security breach; and</text>
						</paragraph><paragraph id="IDda5baca6944b49178bcea2682f5fa0ae"><enum>(3)</enum><text>any other
			 technical information concerning the nature of the security breach deemed
			 appropriate for collection by the Attorney General in furtherance of this
			 subtitle.</text>
						</paragraph></subsection><subsection id="ID54996a6f327d441f9091efb3157e2c08"><enum>(c)</enum><header>Access to
			 clearinghouse</header><text>Any entity certified under subsection (d) may
			 review information maintained by the technical information clearinghouse for
			 the purpose of preventing security breaches that threaten the security of
			 sensitive personally identifiable information.</text>
					</subsection><subsection id="ID741aa94a10e8449ca32bb6c997e43323"><enum>(d)</enum><header>Certification
			 for access</header><text>The Attorney General shall issue and revoke
			 certifications to agencies and business entities wishing to review information
			 maintained by the technical information clearinghouse and shall establish
			 conditions for obtaining and maintaining such certifications, including
			 agreement that any information obtained directly or derived indirectly from the
			 review of information maintained by the technical information
			 clearinghouse—</text>
						<paragraph id="ID500ea0410fc94276a94010a46af53efc"><enum>(1)</enum><text>shall only be used
			 to improve the security and reduce the vulnerability of networks that use
			 personally identifiable information;</text>
						</paragraph><paragraph id="IDc136cda3313b4eb7878799fb52579479"><enum>(2)</enum><text>may not be used
			 for any competitive commercial purpose; and</text>
						</paragraph><paragraph id="IDf15180f80e0a4ab2b6918663755a6993"><enum>(3)</enum><text>may not be shared
			 with any third party, including other parties certified for access to the
			 information clearinghouse, without the express written consent of the Attorney
			 General.</text>
						</paragraph></subsection><subsection id="IDf531913231884db9a8628c4c57a32770"><enum>(e)</enum><header>Rulemaking</header><text>In
			 consultation with the private sector, appropriate representatives of State and
			 local governments, and other appropriate Federal agencies, the Attorney General
			 shall promulgate any regulations pursuant to section 553 of title 5, United
			 States Code, necessary to carry out the provisions of this section.</text>
					</subsection></section><section id="IDd2d7a89e15af43ec89ed1d424bae38b8"><enum>231.</enum><header>Protections for
			 clearinghouse participants</header>
					<subsection id="idAD22A961394C494AA279E687E9C16257"><enum>(a)</enum><header>Protection of
			 proprietary information</header><text display-inline="yes-display-inline">To
			 the extent feasible, the Attorney General shall ensure that any technical
			 information disclosed to the Attorney General under this subtitle shall be
			 stored in a format designed to protect proprietary business information from
			 inadvertent disclosure.</text>
					</subsection><subsection id="IDef1b95ea1304433198927a6b86e8ae42"><enum>(b)</enum><header>Anonymous data
			 release</header><text>To the extent feasible, the Attorney General shall ensure
			 that all information stored in the technical information clearinghouse and
			 accessed by certified parties is presented in a form that minimizes the
			 potential for such information to be traced to a particular network, company,
			 or security breach incident.</text>
					</subsection><subsection id="ID8779b33c11d14f20be606482f153a537"><enum>(c)</enum><header>Protection from
			 public disclosure</header><text>Except as otherwise provided in this
			 subtitle—</text>
						<paragraph id="ID31c8b718584e4ec5b066489ba6769283"><enum>(1)</enum><text>security and
			 vulnerability information collected under this section and provided to the
			 Federal Government, including aggregated analysis and data, shall be exempt
			 from disclosure under section 552(b)(3) of title 5, United States Code;
			 and</text>
						</paragraph><paragraph id="ID6215f9b77c7841cba53c135be576fffe"><enum>(2)</enum><text>under section
			 230(e), security and vulnerability-related information provided to the Federal
			 Government under this section, including aggregated analysis and data, shall be
			 protected from public disclosure, except that this paragraph—</text>
							<subparagraph id="IDfb60eec819cf4f2d93a06928695155e4"><enum>(A)</enum><text>does not prohibit
			 the sharing of such information, as the Attorney General determines to be
			 appropriate, in order to mitigate cybersecurity threats or further the official
			 functions of a government agency; and</text>
							</subparagraph><subparagraph id="ID68308095f85b42c9978d0cc74a5c147d"><enum>(B)</enum><text>does not
			 authorized such information to be withheld from a committee of Congress
			 authorized to request the information.</text>
							</subparagraph></paragraph></subsection><subsection id="ID5a1b1888528a4caeba3853553e25327c"><enum>(d)</enum><header>Protection of
			 classified information</header><text>Nothing in this subtitle permits the
			 unauthorized disclosure of classified information.</text>
					</subsection></section><section commented="no" display-inline="no-display-inline" id="ID527ade6c074f448da6e7e220dd02a32e"><enum>232.</enum><header display-inline="yes-display-inline">Effective
			 date</header><text display-inline="no-display-inline">This subtitle shall take
			 effect on the expiration of the date which is 90 days after the date of
			 enactment of this Act.</text>
				</section></subtitle></title><title changed="deleted" commented="no" committee-id="SSJU00" id="id14E3D0E4F57E4B0A8C0C7207624800D1" level-type="subsequent" reported-display-style="strikethrough"><enum>III</enum><header display-inline="yes-display-inline">Access to and use of commercial
			 data</header>
			<section commented="no" display-inline="no-display-inline" id="ID12b6cb5e199e41929bf7df592fcd092f" section-type="subsequent-section"><enum>301.</enum><header display-inline="yes-display-inline">General services administration review of
			 contracts</header>
				<subsection commented="no" display-inline="no-display-inline" id="ID995b836df04c406a91e33953d556a900"><enum>(a)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">In considering contract awards totaling
			 more than $500,000 and entered into after the date of enactment of this Act
			 with data brokers, the Administrator of the General Services Administration
			 shall evaluate—</text>
					<paragraph commented="no" display-inline="no-display-inline" id="IDd81fec140bdb4eb3b0924ba3030a135e"><enum>(1)</enum><text display-inline="yes-display-inline">the data privacy and security program of a
			 data broker to ensure the privacy and security of data containing personally
			 identifiable information, including whether such program adequately addresses
			 privacy and security threats created by malicious software or code, or the use
			 of peer-to-peer file sharing software;</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID6b25f35cb40e491eb48de6f3d6768bd4"><enum>(2)</enum><text display-inline="yes-display-inline">the compliance of a data broker with such
			 program;</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID60a4e479908346c2839ef7b4423f45c3"><enum>(3)</enum><text display-inline="yes-display-inline">the extent to which the databases and
			 systems containing personally identifiable information of a data broker have
			 been compromised by security breaches; and</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID949ad97ace5b4929bb68f4ca8b544025"><enum>(4)</enum><text display-inline="yes-display-inline">the response by a data broker to such
			 breaches, including the efforts by such data broker to mitigate the impact of
			 such security breaches.</text>
					</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="IDce3b2ba9c6b2469dbd50314cb6268e3e"><enum>(b)</enum><header display-inline="yes-display-inline">Compliance safe harbor</header><text display-inline="yes-display-inline">The data privacy and security program of a
			 data broker shall be deemed sufficient for the purposes of subsection (a), if
			 the data broker complies with or provides protection equal to industry
			 standards, as identified by the Federal Trade Commission, that are applicable
			 to the type of personally identifiable information involved in the ordinary
			 course of business of such data broker.</text>
				</subsection><subsection commented="no" display-inline="no-display-inline" id="ID3bd4f223fe26433ab41f1ca859884b6a"><enum>(c)</enum><header display-inline="yes-display-inline">Penalties</header><text display-inline="yes-display-inline">In awarding contracts with data brokers for
			 products or services related to access, use, compilation, distribution,
			 processing, analyzing, or evaluating personally identifiable information, the
			 Administrator of the General Services Administration shall—</text>
					<paragraph commented="no" display-inline="no-display-inline" id="IDebdaa8ec56814a069eaffb85c34f2ba9"><enum>(1)</enum><text display-inline="yes-display-inline">include monetary or other penalties—</text>
						<subparagraph commented="no" display-inline="no-display-inline" id="ID96f2956451cb41baaa8ae62030fdb0a8"><enum>(A)</enum><text display-inline="yes-display-inline">for failure to comply with subtitles A and
			 B of title III; or</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDaa149b7ee8a94b318052713319405cf3"><enum>(B)</enum><text display-inline="yes-display-inline">if a contractor knows or has reason to know
			 that the personally identifiable information being provided is inaccurate, and
			 provides such inaccurate information; and</text>
						</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDa7ac7c96c6d9487ba2685498956532ab"><enum>(2)</enum><text display-inline="yes-display-inline">require a data broker that engages service
			 providers not subject to subtitle A of title III for responsibilities related
			 to sensitive personally identifiable information to—</text>
						<subparagraph commented="no" display-inline="no-display-inline" id="ID9f1b82ec90eb4e2c8fc6122262c60788"><enum>(A)</enum><text display-inline="yes-display-inline">exercise appropriate due diligence in
			 selecting those service providers for responsibilities related to personally
			 identifiable information;</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDcff9a67f57044095a9372fd650b53077"><enum>(B)</enum><text display-inline="yes-display-inline">take reasonable steps to select and retain
			 service providers that are capable of maintaining appropriate safeguards for
			 the security, privacy, and integrity of the personally identifiable information
			 at issue; and</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDb86e5489dd9d4867b1104a90a8c56370"><enum>(C)</enum><text display-inline="yes-display-inline">require such service providers, by
			 contract, to implement and maintain appropriate measures designed to meet the
			 objectives and requirements in title III.</text>
						</subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="ID2ed921e9172648cfa9d7e97f01e18642"><enum>(d)</enum><header display-inline="yes-display-inline">Limitation</header><text display-inline="yes-display-inline">The penalties under subsection (c) shall
			 not apply to a data broker providing information that is accurately and
			 completely recorded from a public record source or licensor.</text>
				</subsection></section><section commented="no" display-inline="no-display-inline" id="ID2c32eab739de4fea85488e717413b035" section-type="subsequent-section"><enum>302.</enum><header display-inline="yes-display-inline">Requirement to audit information security
			 practices of contractors and third party business entities</header><text display-inline="no-display-inline">Section 3544(b) of title 44, United States
			 Code, is amended—</text>
				<paragraph commented="no" display-inline="no-display-inline" id="ID886fac1dc8d54a45a34cd023c3f0603a"><enum>(1)</enum><text display-inline="yes-display-inline">in paragraph (7)(C)(iii), by striking
			 <quote>and</quote> after the semicolon;</text>
				</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID86d7b3ac16e14a24a17152aa29d8f8fa"><enum>(2)</enum><text display-inline="yes-display-inline">in paragraph (8), by striking the period
			 and inserting <quote>; and</quote>; and</text>
				</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID487bd2dd97084bb592f9c8b701bada8d"><enum>(3)</enum><text display-inline="yes-display-inline">by adding at the end the following:</text>
					<quoted-block changed="deleted" committee-id="SSJU00" display-inline="no-display-inline" id="id51C65F1CDDDA4661ABF00BC805968E30" reported-display-style="strikethrough" style="OLC">
						<paragraph commented="no" display-inline="no-display-inline" id="IDfe9569912cd9418d80acea18528c30c7"><enum>(9)</enum><text display-inline="yes-display-inline">procedures for evaluating and auditing the
				information security practices of contractors or third party business entities
				supporting the information systems or operations of the agency involving
				personally identifiable information (as that term is defined in section 3 of
				the <short-title>Personal Data Protection and Breach
				Accountability Act of 2011</short-title>) and ensuring remedial action to
				address any significant
				deficiencies.</text>
						</paragraph><after-quoted-block>.</after-quoted-block></quoted-block>
				</paragraph></section><section commented="no" display-inline="no-display-inline" id="ID4056fc3599c54deeb9c0ed352866c385" section-type="subsequent-section"><enum>303.</enum><header display-inline="yes-display-inline">Privacy impact assessment of government use
			 of commercial information services containing personally identifiable
			 information</header>
				<subsection commented="no" display-inline="no-display-inline" id="ID5ce43dba31a3469d8b31a5e94d0ff19e"><enum>(a)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">Section 208(b)(1) of the E-Government Act
			 of 2002 (44 U.S.C. 3501 note) is amended—</text>
					<paragraph commented="no" display-inline="no-display-inline" id="ID8514e50d74594d6ab9ccc96eaa8a555a"><enum>(1)</enum><text display-inline="yes-display-inline">in subparagraph (A)(i), by striking
			 <quote>or</quote>;</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID4a6f00d902c043c1af3a0a1bbc4c338a"><enum>(2)</enum><text display-inline="yes-display-inline">in subparagraph (A)(ii), by striking the
			 period and inserting <quote>; or</quote>; and</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDc02e3e37ef45496d915ac736eabee83a"><enum>(3)</enum><text display-inline="yes-display-inline">by inserting after clause (ii) the
			 following:</text>
						<quoted-block changed="deleted" committee-id="SSJU00" display-inline="no-display-inline" id="idBB13C89F7A95426D9ADE3BE28B30BDA4" reported-display-style="strikethrough" style="OLC">
							<clause commented="no" display-inline="no-display-inline" id="IDa49e55dafba94f21a8f9e8abdb9d2094"><enum>(iii)</enum><text display-inline="yes-display-inline">purchasing or subscribing for a fee to
				personally identifiable information from a data broker (as such terms are
				defined in section 3 of the <short-title>Personal Data
				Protection and Breach Accountability Act of
				2011</short-title>).</text>
							</clause><after-quoted-block>.</after-quoted-block></quoted-block>
					</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="IDb0f703f2ffff413d8304e950ee6002a0"><enum>(b)</enum><header display-inline="yes-display-inline">Limitation</header><text display-inline="yes-display-inline">Notwithstanding any other provision of law,
			 commencing 1 year after the date of enactment of this Act, no Federal agency
			 may enter into a contract with a data broker to access for a fee any database
			 consisting primarily of personally identifiable information concerning United
			 States persons (other than news reporting or telephone directories) unless the
			 head of such department or agency—</text>
					<paragraph commented="no" display-inline="no-display-inline" id="IDbd9a44cb0f8347f48c4ffc2e9d43e1af"><enum>(1)</enum><text display-inline="yes-display-inline">completes a privacy impact assessment under
			 section 208 of the E-Government Act of 2002 (44 U.S.C. 3501 note), which shall
			 subject to the provision in that Act pertaining to sensitive information,
			 include a description of—</text>
						<subparagraph commented="no" display-inline="no-display-inline" id="IDd9c08f20b45a4ad0a9fbe129d268f7ef"><enum>(A)</enum><text display-inline="yes-display-inline">such database;</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID5f3a37fd1cde4cf29c866b52941d8fd6"><enum>(B)</enum><text display-inline="yes-display-inline">the name of the data broker from whom it is
			 obtained; and</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID0e42886510c84307bd1b8ff76f26348d"><enum>(C)</enum><text display-inline="yes-display-inline">the amount of the contract for use;</text>
						</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID7fd6917e701945c9b29407ea764b2358"><enum>(2)</enum><text display-inline="yes-display-inline">adopts regulations that specify—</text>
						<subparagraph commented="no" display-inline="no-display-inline" id="IDc2d0e5565e274bb8a62c879648972b07"><enum>(A)</enum><text display-inline="yes-display-inline">the personnel permitted to access, analyze,
			 or otherwise use such databases;</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDed199cff45a94ca6857c1fdc4f42ba73"><enum>(B)</enum><text display-inline="yes-display-inline">standards governing the access, analysis,
			 or use of such databases;</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID5f5fee5062cc4fed9f55394fe0b12ce4"><enum>(C)</enum><text display-inline="yes-display-inline">any standards used to ensure that the
			 personally identifiable information accessed, analyzed, or used is the minimum
			 necessary to accomplish the intended legitimate purpose of the Federal
			 agency;</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID489c12de6977443b834d48a26009897e"><enum>(D)</enum><text display-inline="yes-display-inline">standards limiting the retention and
			 redisclosure of personally identifiable information obtained from such
			 databases;</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDdb1a32a1904a4f108fc798f4eb7627ad"><enum>(E)</enum><text display-inline="yes-display-inline">procedures ensuring that such data meet
			 standards of accuracy, relevance, completeness, and timeliness;</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID9f20a216795e4ffa94c388eee36c08d4"><enum>(F)</enum><text display-inline="yes-display-inline">the auditing and security measures to
			 protect against unauthorized access, analysis, use, or modification of data in
			 such databases;</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID39a555ea4350456cb5a5388d3531afb1"><enum>(G)</enum><text display-inline="yes-display-inline">applicable mechanisms by which individuals
			 may secure timely redress for any adverse consequences wrongly incurred due to
			 the access, analysis, or use of such databases;</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDd3b6e9327d7d40da8f9d58f61cb46f71"><enum>(H)</enum><text display-inline="yes-display-inline">mechanisms, if any, for the enforcement and
			 independent oversight of existing or planned procedures, policies, or
			 guidelines; and</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="IDd244312f492a424f8cd060941aafb73d"><enum>(I)</enum><text display-inline="yes-display-inline">an outline of enforcement mechanisms for
			 accountability to protect individuals and the public against unlawful or
			 illegitimate access or use of databases; and</text>
						</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID21a7368695e04683b6b2556783e36345"><enum>(3)</enum><text display-inline="yes-display-inline">incorporates into the contract or other
			 agreement totaling more than $500,000, provisions—</text>
						<subparagraph commented="no" display-inline="no-display-inline" id="ID52450c4b015e4106b52161964153f4b0"><enum>(A)</enum><text display-inline="yes-display-inline">providing for penalties—</text>
							<clause commented="no" display-inline="no-display-inline" id="ID47368893b6114f4a8e949a7e5908021d"><enum>(i)</enum><text display-inline="yes-display-inline">for failure to comply with title III of
			 this Act; or</text>
							</clause><clause commented="no" display-inline="no-display-inline" id="ID524c9d6d46814f64bb14403a6b3e8c86"><enum>(ii)</enum><text display-inline="yes-display-inline">if the entity knows or has reason to know
			 that the personally identifiable information being provided to the Federal
			 department or agency is inaccurate, and provides such inaccurate information;
			 and</text>
							</clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ID5830c7e15b514afabc350d588a163c16"><enum>(B)</enum><text display-inline="yes-display-inline">requiring a data broker that engages
			 service providers not subject to subtitle A of title III for responsibilities
			 related to sensitive personally identifiable information to—</text>
							<clause commented="no" display-inline="no-display-inline" id="IDc820784a80784abf8d8422b62333783a"><enum>(i)</enum><text display-inline="yes-display-inline">exercise appropriate due diligence in
			 selecting those service providers for responsibilities related to personally
			 identifiable information;</text>
							</clause><clause commented="no" display-inline="no-display-inline" id="ID52a184cf261f43fbbe693fea76df4c09"><enum>(ii)</enum><text display-inline="yes-display-inline">take reasonable steps to select and retain
			 service providers that are capable of maintaining appropriate safeguards for
			 the security, privacy, and integrity of the personally identifiable information
			 at issue; and</text>
							</clause><clause commented="no" display-inline="no-display-inline" id="ID824d34d50448495f8e3998930307cbd6"><enum>(iii)</enum><text display-inline="yes-display-inline">require such service providers, by
			 contract, to implement and maintain appropriate measures designed to meet the
			 objectives and requirements in title III.</text>
							</clause></subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="IDee4893ba854540c99c2733dfb1bddf7d"><enum>(c)</enum><header display-inline="yes-display-inline">Limitation on penalties</header><text display-inline="yes-display-inline">The penalties under subsection (b)(3)(A)
			 shall not apply to a data broker providing information that is accurately and
			 completely recorded from a public record source.</text>
				</subsection><subsection commented="no" display-inline="no-display-inline" id="id104D66BAD0F0492FB042C3DCF1573537"><enum>(d)</enum><header display-inline="yes-display-inline">Study of government use</header>
					<paragraph commented="no" display-inline="no-display-inline" id="idFA2A5D39AE0D4066A7DFB48438EA740A"><enum>(1)</enum><header display-inline="yes-display-inline">Scope
			 of study</header><text display-inline="yes-display-inline">Not later than 180
			 days after the date of enactment of this Act, the Comptroller General of the
			 United States shall conduct a study and audit and prepare a report on Federal
			 agency actions to address the recommendations in the Government Accountability
			 Office's April 2006 report on agency adherence to key privacy principles in
			 using data brokers or commercial databases containing personally identifiable
			 information.</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id076A50E3C6FF4B178BB62383248C9913"><enum>(2)</enum><header display-inline="yes-display-inline">Report</header><text display-inline="yes-display-inline">A copy of the report required under
			 paragraph (1) shall be submitted to Congress.</text>
					</paragraph></subsection></section><section id="IDa9f9d9e4f507470bbec0376f56e2d704"><enum>304.</enum><header>FBI report on
			 reported breaches and compliance</header>
				<subsection id="IDb987b66b35c84be5b5e1588ce046b53d"><enum>(a)</enum><header>In
			 general</header><text>Not later than 1 year after the date of enactment of this
			 Act, and each year thereafter, the Federal Bureau of Investigation, in
			 coordination with the Secret Service, shall submit to the Committee on the
			 Judiciary of the Senate and the Committee on the Judiciary of the House of
			 Representatives a report regarding any reported breaches at agencies or
			 business entities during the preceding year.</text>
				</subsection><subsection id="ID08c121b615454f89a9875bb4efc0bb08"><enum>(b)</enum><header>Report
			 content</header><text>Such reporting shall include—</text>
					<paragraph id="ID13c4eda31e2c4918a3335a3bfc2f7e0f"><enum>(1)</enum><text>the total
			 instances of breaches of security in the previous year;</text>
					</paragraph><paragraph id="ID855aafd9918346f6adb3041cfa12c3e2"><enum>(2)</enum><text>the percentage of
			 breaches described in subsection (a) that occurred at an agency or business
			 entity that did not comply with the personal data privacy and security program
			 under section 202; and</text>
					</paragraph><paragraph id="ID4dd40e5ed1ca40a18c01349ffa80d9e6"><enum>(3)</enum><text>recommendations,
			 if any, for modifying or amending this Act to increase its
			 effectiveness.</text>
					</paragraph></subsection></section><section id="ID88bb272cdb2248499a23e4dfc0e06771"><enum>305.</enum><header>Department of
			 Justice report on enforcement actions</header>
				<subsection id="IDa38a850cbe97450ab22aaabe9367124b"><enum>(a)</enum><header>In
			 general</header><text>Not later than 1 year after the date of enactment of this
			 Act, and each year thereafter, the Attorney General shall submit to Congress a
			 report on the enforcement actions taken in the previous year in cases of
			 violations of any sections of this Act.</text>
				</subsection><subsection id="ID5b8a5c47768147a28ffe37167d40ef2f"><enum>(b)</enum><header>Report
			 content</header><text>The report required under subsection (a) shall
			 include—</text>
					<paragraph id="IDe510d9f1dfad4072a239a44ce312517e"><enum>(1)</enum><text>statistics on
			 Federal enforcement actions, State attorneys general enforcement actions, and
			 private enforcement actions related to the provisions of this Act; and</text>
					</paragraph><paragraph id="IDd05328e334234498af3739a5a14741f0"><enum>(2)</enum><text>recommendations,
			 if any, for modifying of amending this Act to increase the effectiveness of
			 such enforcement actions.</text>
					</paragraph></subsection></section><section id="ID7a6f708f7aa6478a8b5c133959fd140d"><enum>306.</enum><header>Department of
			 Justice report on enforcement actions</header><text display-inline="no-display-inline">Section 529 of title 28, United States Code,
			 is amended by adding at the end the following:</text>
				<quoted-block changed="deleted" committee-id="SSJU00" display-inline="no-display-inline" id="id1EAD7959898A48788F9F07A60A496EAB" reported-display-style="strikethrough" style="OLC">
					<subsection id="id09FA5174BAA548739C0692512847F75E"><enum>(c)</enum><text>Not later than 1
				year after the date of enactment of the <short-title>Personal Data Protection and Breach Accountability Act of
				2011</short-title>, and every fiscal year thereafter, the Attorney General
				shall submit to Congress a report on the efforts of the Federal Government to
				enforce the <short-title>Personal Data Protection and
				Breach Accountability Act of 2011</short-title> that shall include a
				description of the best practices for enforcement of such
				Act.</text>
					</subsection><after-quoted-block>.</after-quoted-block></quoted-block>
			</section><section id="ID0366fb23d1cb45d685d40473ea2fe486"><enum>307.</enum><header>FBI report on
			 notification effectiveness</header>
				<subsection id="ID3161b8dba92a4d3c9f6df7d3a84b8937"><enum>(a)</enum><header>In
			 general</header><text>Not later than 1 year after the date of enactment of this
			 Act, and each year thereafter, the Federal Bureau of Investigation, in
			 coordination with the Secret Service, shall submit to the Committee on the
			 Judiciary of the Senate and the Committee on the Judiciary of the House of
			 Representatives a report regarding the effectiveness of post-breach
			 notification practices by agencies and business entities.</text>
				</subsection><subsection id="IDb02f7327df654fe4ba62642d6a8ed963"><enum>(b)</enum><header>Report
			 content</header><text>The report required under subsection (a) shall
			 include—</text>
					<paragraph id="ID2e6afdb3cda143189fa1dac5b0933173"><enum>(1)</enum><text>in each instance
			 of a breach of security, the amount of time between the instance of the breach
			 and the discovery of the breach by the affected business entity;</text>
					</paragraph><paragraph id="IDf56186edaa7b41fe881d60dc049e7ce3"><enum>(2)</enum><text>in each instance
			 of a breach of security, the amount of time between the discovery of the breach
			 by the affected business entity and the notification to the FBI and Secret
			 Service; and</text>
					</paragraph><paragraph id="ID3d7b39d9354144999c6b67411d5b2159"><enum>(3)</enum><text>in each instance
			 of a breach of security, the amount of time between the discovery of the breach
			 by the affected business entity and the notification to individuals whose
			 sensitive personally identifiable information was compromised.</text>
					</paragraph></subsection></section></title><title changed="deleted" committee-id="SSJU00" id="idA76D6B98B64A432F88A7865C97AD99DC" reported-display-style="strikethrough"><enum>IV</enum><header>Compliance with
			 Statutory Pay-As-You-Go Act</header>
			<section id="idB4E6245612214115BF32E26DC4B83579"><enum>401.</enum><header>Budget
			 compliance</header><text display-inline="no-display-inline">The budgetary
			 effects of this Act, for the purpose of complying with the Statutory
			 Pay-As-You-Go Act of 2010, shall be determined by reference to the latest
			 statement titled <quote>Budgetary Effects of PAYGO Legislation</quote> for this
			 Act, submitted for printing in the Congressional Record by the Chairman of the
			 Senate Budget Committee, provided that such statement has been submitted prior
			 to the vote on passage.</text>
			</section></title></legis-body>
	<legis-body display-enacting-clause="no-display-enacting-clause">
		<section changed="added" commented="no" committee-id="SSJU00" display-inline="no-display-inline" id="ida79cba6c-08e1-415b-9c0f-605c0c9fd7f2" reported-display-style="italic" section-type="section-one"><enum>1.</enum><header display-inline="yes-display-inline">Short title; table of contents</header>
			<subsection commented="no" display-inline="no-display-inline" id="id0ea6fc92-e116-4c55-8a30-af034cd35113"><enum>(a)</enum><header display-inline="yes-display-inline">Short title</header><text display-inline="yes-display-inline">This Act may be cited as the
			 <quote><short-title>Personal Data Protection and Breach
			 Accountability Act of 2011</short-title></quote>.</text>
			</subsection><subsection commented="no" display-inline="no-display-inline" id="id690cd186-1f2c-430c-b55a-690bbcad56a3"><enum>(b)</enum><header display-inline="yes-display-inline">Table of contents</header><text display-inline="yes-display-inline">The table of contents of this Act is as
			 follows:</text>
				<toc changed="added" committee-id="SSJU00" reported-display-style="italic">
					<toc-entry idref="idBC757BBC5D2D452AB3FEEC0A005925EB" level="section">Sec. 1. Short title; table of
				contents.</toc-entry>
					<toc-entry idref="idD75E514A664A45B39DAD2D9E8742B0E7" level="section">Sec. 2. Findings.</toc-entry>
					<toc-entry idref="IDd589748af4d840b1a53a75db7bdb7d32" level="section">Sec. 3. Definitions.</toc-entry>
					<toc-entry idref="id57BB7068312345C88A53B62678AE2D8A" level="title">TITLE I—Enhancing punishment for
				identity theft and other violations of data privacy and security</toc-entry>
					<toc-entry idref="ID98057df8ce5e465296494f1084c8664c" level="section">Sec. 101. Concealment of security breaches
				involving sensitive personally identifiable information.</toc-entry>
					<toc-entry idref="ID0ba8888617d74aaa8c3880d31b1d59cd" level="section">Sec. 102. Unauthorized manipulation of Internet
				traffic on a user’s computer.</toc-entry>
					<toc-entry idref="idD725C42479864A1D94B301FF34A11C92" level="title">TITLE II—Privacy and security of
				sensitive personally identifiable information </toc-entry>
					<toc-entry idref="id3189B1C7B0974BA09A5D2EB0F2AA3456" level="subtitle">Subtitle A—A data privacy and security
				program</toc-entry>
					<toc-entry idref="ID48089945808a49b592f4356d4079eae6" level="section">Sec. 201. Purpose and applicability of data
				privacy and security program.</toc-entry>
					<toc-entry idref="ID01a5628cdcfe4d1aa8f738063c6c15c2" level="section">Sec. 202. Requirements for a personal data
				privacy and security program.</toc-entry>
					<toc-entry idref="ID5cac3211a25b4f26a2628faea99c9f36" level="section">Sec. 203. Federal enforcement.</toc-entry>
					<toc-entry idref="id2F1908FEFADB49B19264F6C00D6C8B7B" level="section">Sec. 204. Enforcement by State Attorneys
				General.</toc-entry>
					<toc-entry idref="ID8952766f976d4ef48ad73992dd4702e4" level="section">Sec. 205. Supplemental enforcement by
				individuals.</toc-entry>
					<toc-entry idref="idBC4FEB9AFE2A4E93BF957FCB6F00B7E3" level="subtitle">Subtitle B—Security breach
				notification</toc-entry>
					<toc-entry idref="ID5510cd0d499f4913941a3308d15e6a1c" level="section">Sec. 211. Notice to individuals.</toc-entry>
					<toc-entry idref="ID5dc909314300496fae2e47fd1f732bf2" level="section">Sec. 212. Exemptions from notice to
				individuals.</toc-entry>
					<toc-entry idref="IDbe5d0d5a9f634bfbbae2e9371a7cb5ab" level="section">Sec. 213. Methods of notice to
				individuals.</toc-entry>
					<toc-entry idref="ID80d1a786110544b1b9b1a5fa3fc173b3" level="section">Sec. 214. Content of notice to
				individuals.</toc-entry>
					<toc-entry idref="IDd1a9a538e2ea4808a43d262275fb8cfa" level="section">Sec. 215. Remedies for security
				breach.</toc-entry>
					<toc-entry idref="ID82ad6f96b46a4c7388f833d7611a6fc3" level="section">Sec. 216. Notice to credit reporting
				agencies.</toc-entry>
					<toc-entry idref="IDde1241e504f94594beb8e50db8943996" level="section">Sec. 217. Notice to law
				enforcement.</toc-entry>
					<toc-entry idref="ID300c058705674d1fa8a20180588bc781" level="section">Sec. 218. Federal enforcement.</toc-entry>
					<toc-entry idref="ID28d22f15074d4f239f64734d16e27d82" level="section">Sec. 219. Enforcement by State attorneys
				general.</toc-entry>
					<toc-entry idref="IDe9a2f5c9f18946eb836a3d703c1489b9" level="section">Sec. 220. Supplemental enforcement by
				individuals.</toc-entry>
					<toc-entry idref="IDa5c5ed85f5b948b08f30d0800295937a" level="section">Sec. 221. Relation to other laws.</toc-entry>
					<toc-entry idref="ID90730e6c13ca4a49b382b3f1e9ee896e" level="section">Sec. 222. Authorization of
				appropriations.</toc-entry>
					<toc-entry idref="ID0c5c8ec1f3e24cd886be5d8e2f850ca7" level="section">Sec. 223. Reporting on risk assessment
				exemptions.</toc-entry>
					<toc-entry idref="idA5C50B11C7414F79894531F4CFED06C9" level="subtitle">Subtitle C—Post-Breach technical information
				clearinghouse</toc-entry>
					<toc-entry idref="id4065DF23EA25436984EB9D2241C0450E" level="section">Sec. 230. Clearinghouse information collection,
				maintenance, and access.</toc-entry>
					<toc-entry idref="IDd2d7a89e15af43ec89ed1d424bae38b8" level="section">Sec. 231. Protections for clearinghouse
				participants.</toc-entry>
					<toc-entry idref="ID527ade6c074f448da6e7e220dd02a32e" level="section">Sec. 232. Effective date.</toc-entry>
					<toc-entry idref="id14E3D0E4F57E4B0A8C0C7207624800D1" level="title">TITLE III—Access to and use of
				commercial data</toc-entry>
					<toc-entry idref="ID12b6cb5e199e41929bf7df592fcd092f" level="section">Sec. 301. General services administration
				review of contracts.</toc-entry>
					<toc-entry idref="ID2c32eab739de4fea85488e717413b035" level="section">Sec. 302. Requirement to audit information
				security practices of contractors and third party business
				entities.</toc-entry>
					<toc-entry idref="ID4056fc3599c54deeb9c0ed352866c385" level="section">Sec. 303. Privacy impact assessment of
				government use of commercial information services containing sensitive
				personally identifiable information.</toc-entry>
					<toc-entry idref="IDa9f9d9e4f507470bbec0376f56e2d704" level="section">Sec. 304. FBI report on reported breaches and
				compliance.</toc-entry>
					<toc-entry idref="ID7a6f708f7aa6478a8b5c133959fd140d" level="section">Sec. 305. Department of Justice report on
				enforcement actions.</toc-entry>
					<toc-entry idref="ID0366fb23d1cb45d685d40473ea2fe486" level="section">Sec. 306. Report on notification
				effectiveness.</toc-entry>
					<toc-entry idref="idA76D6B98B64A432F88A7865C97AD99DC" level="title">TITLE IV—Compliance with
				Statutory Pay-As-You-Go Act</toc-entry>
					<toc-entry idref="idB4E6245612214115BF32E26DC4B83579" level="section">Sec. 401. Budget compliance.</toc-entry>
				</toc>
			</subsection></section><section changed="added" commented="no" committee-id="SSJU00" display-inline="no-display-inline" id="idce734c51-34ac-46dd-8964-09668340f21c" reported-display-style="italic" section-type="subsequent-section"><enum>2.</enum><header display-inline="yes-display-inline">Findings</header><text display-inline="no-display-inline">Congress finds that—</text>
			<paragraph commented="no" display-inline="no-display-inline" id="id2e9e6eaf-0552-41ac-bb98-d2d015e6e43d"><enum>(1)</enum><text display-inline="yes-display-inline">databases of personally identifiable
			 information are increasingly prime targets of hackers, identity thieves, rogue
			 employees, and other criminals, including organized and sophisticated criminal
			 operations;</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="iddb4012ae-1e44-4391-8d4e-bf7d3a19fde4"><enum>(2)</enum><text display-inline="yes-display-inline">identity theft is a serious threat to the
			 Nation’s economic stability, homeland security, the development of e-commerce,
			 and the privacy rights of Americans;</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id53a62e6c-ef66-42cb-91f7-d0277dfee374"><enum>(3)</enum><text display-inline="yes-display-inline">over 9,300,000 individuals were victims of
			 identity theft in America last year;</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id5208634c-dd1e-456f-aa80-9c38b8eb9075"><enum>(4)</enum><text display-inline="yes-display-inline">security breaches are a serious threat to
			 consumer confidence, homeland security, e-commerce, and economic
			 stability;</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id11054430-38ea-4d8b-a737-ef649e8ea3fb"><enum>(5)</enum><text display-inline="yes-display-inline">it is important for business entities that
			 own, use, or license personally identifiable information to adopt reasonable
			 procedures to ensure the security, privacy, and confidentiality of that
			 personally identifiable information;</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id43b299fc-1571-47a8-b6ef-c381d1d70be6"><enum>(6)</enum><text display-inline="yes-display-inline">individuals whose personal information has
			 been compromised or who have been victims of identity theft should receive the
			 necessary information and assistance to mitigate their damages and to restore
			 the integrity of their personal information and identities;</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id6008e52d-d5f1-43f4-9aa5-67b0ab126f69"><enum>(7)</enum><text display-inline="yes-display-inline">data misuse and use of inaccurate data have
			 the potential to cause serious or irreparable harm to an individual’s
			 livelihood, privacy, and liberty and undermine efficient and effective business
			 and government operations;</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="idc359c4ba-a187-41a8-b745-6409198ab8b4"><enum>(8)</enum><text display-inline="yes-display-inline">there is a need to ensure that data brokers
			 conduct their operations in a manner that prioritizes fairness, transparency,
			 accuracy, and respect for the privacy of consumers;</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id5d814332-c34d-4da3-86e8-d870213c4df0"><enum>(9)</enum><text display-inline="yes-display-inline">government access to commercial data can
			 potentially improve safety, law enforcement, and national security;</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="idcd567487-0ec1-4599-bd56-5331b5bd2449"><enum>(10)</enum><text display-inline="yes-display-inline">because government use of commercial data
			 containing personal information potentially affects individual privacy, and law
			 enforcement and national security operations, there is a need for Congress to
			 exercise oversight over government use of commercial data;</text>
			</paragraph><paragraph id="id4f6cf5e4-18ef-49ba-91cb-7392cb24ed01"><enum>(11)</enum><text>over 22,960,000 cases of
			 data breaches involving personally identifiable information were reported
			 through July of 2011, and in 2009 through 2010, over 230,900,000 cases of
			 personal data breaches were reported;</text>
			</paragraph><paragraph id="id48c6ebbd-2d62-49d7-8695-d4640f1543e5"><enum>(12)</enum><text>facilitating information
			 sharing among business entities and across sectors in the event of a breach can
			 assist in remediating the breach and preventing similar breaches in the
			 future;</text>
			</paragraph><paragraph id="id16eb483b-8994-499a-a833-a4183edf29ac"><enum>(13)</enum><text>because the Federal
			 Government has limited resources, consumers themselves play a vital and
			 complementary role in facilitating prompt notification and protecting against
			 future breaches of security;</text>
			</paragraph><paragraph id="idaa633124-ef88-4d85-9106-e7af075d2481"><enum>(14)</enum><text>in addition to the
			 immediate damages caused by security breaches, the lack of basic remedial
			 requirements often forces individuals whose sensitive personally identifiable
			 information is compromised as a result of a security breach to incur the
			 economic costs of litigation to seek remedies, and the economic costs of fees
			 required in many States to freeze compromised accounts; and</text>
			</paragraph><paragraph id="ide35887c2-851d-4ee5-89d0-3312d6e4d36e"><enum>(15)</enum><text>victims of personal data
			 breaches may suffer debilitating emotional and physical effects and become
			 depressed or anxious, especially in cases of repeated or unresolved instances
			 of data breaches.</text>
			</paragraph></section><section changed="added" commented="no" committee-id="SSJU00" display-inline="no-display-inline" id="id703391fe-3680-42d5-8d79-165339fdca84" reported-display-style="italic" section-type="subsequent-section"><enum>3.</enum><header display-inline="yes-display-inline">Definitions</header>
			<subsection commented="no" display-inline="no-display-inline" id="id5D538F56894942A8B019293F9DCFFAC2"><enum>(a)</enum><header>In
			 general</header><text display-inline="yes-display-inline">In this Act, the
			 following definitions shall apply:</text>
				<paragraph commented="no" display-inline="no-display-inline" id="ida493bd7f-1fca-4eb2-828e-6b9f924492c4"><enum>(1)</enum><header display-inline="yes-display-inline">Affiliate</header><text display-inline="yes-display-inline">The term <term>affiliate</term> means
			 persons related by common ownership or by corporate control.</text>
				</paragraph><paragraph commented="no" display-inline="no-display-inline" id="idd343ce37-2bb9-4c85-9d61-0292eff5aaa7"><enum>(2)</enum><header display-inline="yes-display-inline">Agency</header><text display-inline="yes-display-inline">The term <term>agency</term> has the
			 meaning given such term in section 551 of title 5, United States Code.</text>
				</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id2c939d9d-e95d-4e06-b7fa-d1d5cb5c92d4"><enum>(3)</enum><header display-inline="yes-display-inline">Business entity</header><text display-inline="yes-display-inline">The term <term>business entity</term> means
			 any organization, corporation, trust, partnership, sole proprietorship,
			 unincorporated association, or venture established to make a profit, or
			 nonprofit.</text>
				</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id6af88efe-bfec-4f2b-b4cd-6e5819640e69"><enum>(4)</enum><header>Credit rating
			 agency</header><text display-inline="yes-display-inline">The term <term>credit
			 rating agency</term> has the meaning given such term in section 3(a)(61) of the
			 Securities Exchange Act of 1934 (12 U.S.C. 78c(a)(61)).</text>
				</paragraph><paragraph commented="no" display-inline="no-display-inline" id="iddad9f5bc-1999-44d4-a361-bc0ca8daa7e9"><enum>(5)</enum><header>Credit
			 report</header><text>The term <term>credit report</term> means a consumer
			 report, as that term is defined in section 603 of the Fair Credit Reporting Act
			 (15 U.S.C. 1681a).</text>
				</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id22a56758-8193-40de-8808-4c53345b25f0"><enum>(6)</enum><header display-inline="yes-display-inline">Data broker</header><text display-inline="yes-display-inline">The term <term>data broker</term> means a
			 business entity which for monetary fees or dues regularly engages in the
			 practice of collecting, transmitting, or providing access to sensitive
			 personally identifiable information on more than 5,000 individuals who are not
			 the customers or employees of that business entity or affiliate primarily for
			 the purposes of providing such information to nonaffiliated third parties on an
			 interstate basis.</text>
				</paragraph><paragraph id="IDe19a8a8918d9406e8782621152c4dd28"><enum>(7)</enum><header>Designated
			 entity</header><text>The term <term>designated entity</term> means the Federal
			 Government entity designated under section 217(a).</text>
				</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id16417bc6-a552-4b37-9fe6-bd1b496cbd0e"><enum>(8)</enum><header display-inline="yes-display-inline">Encryption</header><text display-inline="yes-display-inline">The term <quote>encryption</quote>—</text>
					<subparagraph commented="no" display-inline="no-display-inline" id="idd9c15353-489b-4bd9-a8bc-8973a233e465"><enum>(A)</enum><text display-inline="yes-display-inline">means the protection of data in electronic
			 form, in storage or in transit, using an encryption technology that has been
			 generally accepted by experts in the field of information security that renders
			 such data indecipherable in the absence of associated cryptographic keys
			 necessary to enable decryption of such data; and</text>
					</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idd546e186-fbe2-4853-88b5-541b9ac01774"><enum>(B)</enum><text display-inline="yes-display-inline">includes appropriate management and
			 safeguards of such cryptographic keys so as to protect the integrity of the
			 encryption.</text>
					</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id4b48fb14-40e7-49a8-8de9-4d5d22a971f2"><enum>(9)</enum><header display-inline="yes-display-inline">Identity
			 theft</header><text display-inline="yes-display-inline">The term <term>identity
			 theft</term> means a violation of section 1028(a)(7) of title 18, United States
			 Code.</text>
				</paragraph><paragraph id="idf0afb458-b121-4e8e-9dd3-78e92b6ef4c5"><enum>(10)</enum><header>Intelligence
			 community</header><text>The term <term>intelligence community</term> includes
			 the following:</text>
					<subparagraph id="id67824745-18c0-4f4c-a0b4-0c16d662973b"><enum>(A)</enum><text>The Office of the
			 Director of National Intelligence.</text>
					</subparagraph><subparagraph id="id2cedaf70-4511-467f-b39e-943b3880d019"><enum>(B)</enum><text>The Central Intelligence
			 Agency.</text>
					</subparagraph><subparagraph id="id136e4ec4-ed38-4215-aa3d-59d7292ee219"><enum>(C)</enum><text>The National Security
			 Agency.</text>
					</subparagraph><subparagraph id="id63c12923-f291-453a-83e2-2bef9b762a3e"><enum>(D)</enum><text>The Defense Intelligence
			 Agency.</text>
					</subparagraph><subparagraph id="idcdef6d68-2dc4-4ee4-840e-68d505f4e9ed"><enum>(E)</enum><text>The National
			 Geospatial-Intelligence Agency.</text>
					</subparagraph><subparagraph id="idb9cafada-c145-4836-a347-a978ab426cbd"><enum>(F)</enum><text>The National
			 Reconnaissance Office.</text>
					</subparagraph><subparagraph id="ide50ad6c1-4eaf-4f17-8c54-ddb880795421"><enum>(G)</enum><text>Other offices within the
			 Department of Defense for the collection of specialized national intelligence
			 through reconnaissance programs.</text>
					</subparagraph><subparagraph id="id51ebc573-7673-49c4-9128-03cb7da38a8c"><enum>(H)</enum><text>The intelligence elements
			 of the Army, the Navy, the Air Force, the Marine Corps, the Federal Bureau of
			 Investigation, and the Department of Energy.</text>
					</subparagraph><subparagraph id="id605bf2b8-65d4-453e-9f0f-c4c27fe11ff7"><enum>(I)</enum><text>The Bureau of
			 Intelligence and Research of the Department of State.</text>
					</subparagraph><subparagraph id="idd918958a-ebb5-44e0-ab9b-aa7ff528033f"><enum>(J)</enum><text>The Office of
			 Intelligence and Analysis of the Department of the Treasury.</text>
					</subparagraph><subparagraph id="idc9577dd1-57d6-44f5-a7e5-712008574db6"><enum>(K)</enum><text>The elements of the
			 Department of Homeland Security concerned with the analysis of intelligence
			 information, including the Office of Intelligence of the Coast Guard.</text>
					</subparagraph><subparagraph id="id2b718f7d-bbee-4479-ae6b-5ef246b56c9f"><enum>(L)</enum><text>Such other elements of
			 any other department or agency as may be designated by the President, or
			 designated jointly by the Director of National Intelligence and the head of the
			 department or agency concerned, as an element of the intelligence
			 community.</text>
					</subparagraph></paragraph><paragraph id="idf6be0cb4-6449-4eff-ad0d-5f81dc7a32ea"><enum>(11)</enum><header>Predispute arbitration
			 agreement</header><text>The term <term>predispute arbitration agreement</term>
			 means any agreement to arbitrate a dispute that had not yet arisen at the time
			 of the making of the agreement.</text>
				</paragraph><paragraph commented="no" display-inline="no-display-inline" id="idd1b3a9cf-6ffd-4887-9521-4a2838f2ad5c"><enum>(12)</enum><header display-inline="yes-display-inline">Public record source</header><text display-inline="yes-display-inline">The term <term>public record source</term>
			 means the Congress, any agency, any State or local government agency, the
			 government of the District of Columbia and governments of the territories or
			 possessions of the United States, and Federal, State or local courts, courts
			 martial and military commissions, that maintain personally identifiable
			 information in records available to the public.</text>
				</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ida6741a58-8fa8-4d06-a87f-e1b13f8d6067"><enum>(13)</enum><header display-inline="yes-display-inline">Security breach</header>
					<subparagraph id="ID1145994d7539445bbd1312450dd88f6b"><enum>(A)</enum><header>In
			 general</header><text>The term <term>security breach</term> means compromise of
			 the security, confidentiality, or integrity of, or the loss of, computerized
			 data through misrepresentation or actions that result in, or that there is a
			 reasonable basis to conclude has resulted in—</text>
						<clause id="ID271a1af0b079410496e033be6909de8a"><enum>(i)</enum><text>the unauthorized
			 acquisition of sensitive personally identifiable information; or</text>
						</clause><clause id="ID1386d417f0454a028ca0a6c0130ae208"><enum>(ii)</enum><text>access to sensitive
			 personally identifiable information that is for an unauthorized purpose, or in
			 excess of authorization.</text>
						</clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id0efdeed3-fbe9-4bca-a06b-449a05e28abf"><enum>(B)</enum><header display-inline="yes-display-inline">Exclusion</header><text display-inline="yes-display-inline">The term <term>security breach</term> does
			 not include—</text>
						<clause commented="no" display-inline="no-display-inline" id="id0cef8e77-6456-4a3b-a7aa-bcebd77ebd24"><enum>(i)</enum><text display-inline="yes-display-inline">a good faith acquisition of sensitive
			 personally identifiable information by a business entity or agency, or an
			 employee or agent of a business entity or agency, if the sensitive personally
			 identifiable information is not subject to further unauthorized
			 disclosure;</text>
						</clause><clause commented="no" display-inline="no-display-inline" id="idf4578c7b-9cb2-465a-911b-fbf04b83e5b5"><enum>(ii)</enum><text display-inline="yes-display-inline">the release of a public record not
			 otherwise subject to confidentiality or nondisclosure requirements or the
			 release of information obtained from a public record; or</text>
						</clause><clause id="idb75dabb6-29af-460e-8e57-e7396e45d2e1"><enum>(iii)</enum><text>any lawfully authorized
			 criminal investigation or authorized investigative, protective, or intelligence
			 activities that are carried out by or on behalf of any element of the
			 intelligence community and conducted in accordance with the United States laws,
			 authorities, and regulations governing such intelligence activities.</text>
						</clause></subparagraph></paragraph><paragraph id="idea7c9122-242b-477d-a4ba-39b5b518460c"><enum>(14)</enum><header>Security
			 freeze</header><text>The term <term>security freeze</term> means a notice, at
			 the request of the consumer and subject to exceptions in section 215(b), that
			 prohibits the consumer reporting agency from releasing all or any part of the
			 consumer’s credit report or any information derived from it without the express
			 authorization of the consumer.</text>
				</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id690661f6-d471-4f16-9f91-ddce28bb3cb3"><enum>(15)</enum><header display-inline="yes-display-inline">Sensitive personally identifiable
			 information</header><text display-inline="yes-display-inline">The term
			 <term>sensitive personally identifiable information</term> means any
			 information or compilation of information, in electronic or digital form that
			 includes the following:</text>
					<subparagraph id="ID5fdcee04b9044a239abc4af595623470"><enum>(A)</enum><text>An individual’s first and
			 last name or first initial and last name in combination with any 2 of the
			 following data elements:</text>
						<clause id="IDc0a75dabfcb347ac9fbd2928ebc3c71b"><enum>(i)</enum><text>Home address.</text>
						</clause><clause id="ID3165446f648c4453b12ef6945b0a220c"><enum>(ii)</enum><text>Telephone number of the
			 individual.</text>
						</clause><clause id="ID98d73c21bcd8433eb6eec7112994c7d2"><enum>(iii)</enum><text>Mother’s maiden
			 name.</text>
						</clause><clause id="ID2e45fd220f404d1f9022f7a0213092d1"><enum>(iv)</enum><text>Month, day, and year of
			 birth.</text>
						</clause></subparagraph><subparagraph id="IDf6c89021bc174a73a94671461c73de3b"><enum>(B)</enum><text>A non-truncated social
			 security number, driver’s license number, passport number, or alien
			 registration number or other government-issued unique identification
			 number.</text>
					</subparagraph><subparagraph id="ID74948644a7694ed2815ba0f1c47b73a5"><enum>(C)</enum><text>Information about an
			 individual’s geographic location that is in whole or in part generated by or
			 derived from that individual’s use of a wireless communication device or other
			 electronic device, excluding telephone and instrument numbers and network or
			 Internet Protocol addresses.</text>
					</subparagraph><subparagraph id="ID8893c038532448fabb95ef5015134a93"><enum>(D)</enum><text>Unique biometric data
			 such as a finger print, voice print, face print, a retina or iris image, or any
			 other unique physical representation.</text>
					</subparagraph><subparagraph id="ID6ed8a2943152442b8ec464a2636f49e5"><enum>(E)</enum><text>A unique account
			 identifier, including a financial account number or credit or debit card
			 number, electronic identification number, user name, health insurance policy or
			 subscriber identification number, or routing code.</text>
					</subparagraph><subparagraph id="ID440e96ce636e4cf6b4d057fa43e3f0ff"><enum>(F)</enum><text>Not less than 2 of the
			 following data elements:</text>
						<clause id="IDd342462f7c1d45c4be077a6356c281aa"><enum>(i)</enum><text>An individual’s first and
			 last name or first initial and last name.</text>
						</clause><clause id="ID6dd0732e82c94221a5463da44e9dcefd"><enum>(ii)</enum><text>A unique account
			 identifier, including a financial account number or credit or debit card
			 number, electronic identification number, user name, or routing code.</text>
						</clause><clause id="ID338ec72d40df46a7b494e7dd39048e6e"><enum>(iii)</enum><text>Any security code,
			 access code, or password, or source code that could be used to generate such
			 codes and passwords.</text>
						</clause><clause id="ID3755d90d75ea4e259bf3cb5f6912995d"><enum>(iv)</enum><text>Information regarding an
			 individual’s medical history, mental or physical medical condition, or medical
			 treatment or diagnosis by a health care professional.</text>
						</clause></subparagraph><subparagraph id="ID5babe90fa41147bca148cb43eb321e47"><enum>(G)</enum><text>Any other combination of
			 data elements that could allow unauthorized access to or acquisition of the
			 information described in subparagraph (A), (B), (C), (D), (E), or (F),
			 including—</text>
						<clause id="IDb55d42f2b7894237b4661ecef191be1f"><enum>(i)</enum><text>a unique account
			 identifier;</text>
						</clause><clause id="IDb79d664ca6c04497b591a756363812f7"><enum>(ii)</enum><text>an electronic
			 identification number;</text>
						</clause><clause id="ID2b062aa908bc42ebbc0c5e940963ca62"><enum>(iii)</enum><text>a user name;</text>
						</clause><clause id="ID68e4ce741c734473af712031382b1aa9"><enum>(iv)</enum><text>a routing code;
			 or</text>
						</clause><clause id="ID6527ada04ef54903a171c8e84fb38a7d"><enum>(v)</enum><text>any associated security
			 code, access code, or password or any associated security questions and answers
			 that could allow unauthorized access to the account.</text>
						</clause></subparagraph></paragraph><paragraph id="ID8d6c0d1037a845a8bbddc3a9d61bf8d7"><enum>(16)</enum><header>Service
			 provider</header>
					<subparagraph id="id12F60D3B08CC428FA422646CC7625CC7"><enum>(A)</enum><header>In
			 general</header><text>The term <term>service provider</term> means a business
			 entity that—</text>
						<clause id="id4CD060A5599E41BCAB8BABE7323D0A48"><enum>(i)</enum><text>provides electronic data
			 transmission, routing, intermediate and transient storage, or connections to
			 the system or network of the business entity;</text>
						</clause><clause id="id06ADF3CF1D2E4558B7B321ED20056C2E"><enum>(ii)</enum><text>is not the sender or the
			 intended recipient of the data;</text>
						</clause><clause id="id14D650A6B8D143949EDE26DD90043111"><enum>(iii)</enum><text>is not ordinarily
			 expected to select or modify the content of the electronic data; and</text>
						</clause><clause id="id2DB08994420B44BAB1AD94A5EB83F655"><enum>(iv)</enum><text>transmits, routes,
			 stores, or provides connections for personal information in a manner that
			 personal information is undifferentiated from other types of data that such
			 business entity transmits, routes, stores, or provides connections.</text>
						</clause></subparagraph><subparagraph id="id26C63E381DD64242B2EF63A38C6BCD24"><enum>(B)</enum><header>Savings
			 clause</header><text>Any such business entity shall be treated as a service
			 provider under this Act only to the extent that the business entity is engaged
			 in the provision of the transmission, routing, intermediate and transient
			 storage or connections described in subparagraph (A).</text>
					</subparagraph></paragraph></subsection><subsection id="ID298438eaff704a72a9a709977d1a1428"><enum>(b)</enum><header>Modified definition by
			 rulemaking</header><text>The Federal Trade Commission may, by rule promulgated
			 under section 553 of title 5, United States Code, modify the definition of
			 <quote>sensitive personally identifiable information</quote> in a manner
			 consistent with the purposes of this Act and to the extent that such
			 modification will not unreasonably impede interstate commerce.</text>
			</subsection></section><title changed="added" commented="no" committee-id="SSJU00" id="id10b669c3-9fdc-4164-b59f-2e3978cc6df8" level-type="subsequent" reported-display-style="italic"><enum>I</enum><header display-inline="yes-display-inline">Enhancing punishment for identity theft and
			 other violations of data privacy and security</header>
			<section commented="no" display-inline="no-display-inline" id="idd6e6893b-eff4-46d0-a725-d34982bb54fe" section-type="subsequent-section"><enum>101.</enum><header display-inline="yes-display-inline">Concealment of security breaches involving
			 sensitive personally identifiable information</header>
				<subsection commented="no" display-inline="no-display-inline" id="id232f1cd1-6b09-4f3e-ae1f-a58915f5e79b"><enum>(a)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">Chapter 47 of title 18, United States Code,
			 is amended by adding at the end the following:</text>
					<quoted-block changed="added" committee-id="SSJU00" display-inline="no-display-inline" id="id8605f08d-5484-4265-9c37-d2451abf0dd7" reported-display-style="italic" style="USC">
						<section commented="no" display-inline="no-display-inline" id="id6f1c441d-7e39-4829-bb8d-5791cff651b6" section-type="subsequent-section"><enum>1041.</enum><header display-inline="yes-display-inline">Concealment of security breaches involving
				sensitive personally identifiable information</header>
							<subsection id="ID2a90de9248be4c9f98c8e5d9cbab5449"><enum>(a)</enum><text>Whoever, having knowledge
				of a security breach and of the fact that notice of such security breach is
				required under title II of the <short-title>Personal Data
				Protection and Breach Accountability Act of 2011</short-title>, intentionally
				or willfully conceals the fact of such security breach and which breach, shall,
				in the event that such security breach results in economic harm or substantial
				emotional distress to 1 or more persons, shall be fined under this title or
				imprisoned not more than 5 years, or both.</text>
							</subsection><subsection commented="no" display-inline="no-display-inline" id="ide533c734-2a3e-4cac-961f-0e0c778533e5"><enum>(b)</enum><text display-inline="yes-display-inline">For purposes of subsection (a), the term
				<term>person</term> has the same meaning as in section 1030(e)(12) of title 18,
				United States Code.</text>
							</subsection><subsection commented="no" display-inline="no-display-inline" id="id57bed7b5-3a0a-4057-b239-cb0c11387561"><enum>(c)</enum><text display-inline="yes-display-inline">Any person seeking an exemption under
				section 212(b) of the <short-title>Personal Data
				Protection and Breach Accountability Act of 2011</short-title> shall be immune
				from prosecution under this section if the United States Secret Service does
				not indicate, in writing, that such notice be given under section 212(b)(1)(B)
				of the <short-title>Personal Data Protection and Breach
				Accountability Act of
				2011</short-title>.</text>
							</subsection></section><after-quoted-block>.</after-quoted-block></quoted-block>
				</subsection><subsection commented="no" display-inline="no-display-inline" id="id6d718484-fe74-436a-9dbe-64f7303871ad"><enum>(b)</enum><header display-inline="yes-display-inline">Conforming and technical
			 amendments</header><text display-inline="yes-display-inline">The table of
			 sections for chapter 47 of title 18, United States Code, is amended by adding
			 at the end the following:</text>
					<quoted-block changed="added" committee-id="SSJU00" display-inline="no-display-inline" id="id60150ddc-58e5-416c-be09-7be7125ae129" reported-display-style="italic" style="OLC">
						<toc changed="added" committee-id="SSJU00" reported-display-style="italic">
							<toc-entry bold="off" level="section">1041. Concealment of security
				breaches involving sensitive personally identifiable
				information.</toc-entry>
						</toc>
						<after-quoted-block>.</after-quoted-block></quoted-block>
				</subsection><subsection commented="no" display-inline="no-display-inline" id="id3763cc58-e660-4d13-b6fa-0bcc9447dc40"><enum>(c)</enum><header display-inline="yes-display-inline">Enforcement authority</header>
					<paragraph commented="no" display-inline="no-display-inline" id="idc99f4746-8b5c-4c33-b7f6-84274785e0dd"><enum>(1)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">The United States Secret Service and the
			 Federal Bureau of Investigation shall have the authority to investigate
			 offenses under this section.</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id2b0ede96-a702-441e-b72c-6295979e4e29"><enum>(2)</enum><header display-inline="yes-display-inline">Nonexclusivity</header><text display-inline="yes-display-inline">The authority granted in paragraph (1)
			 shall not be exclusive of any existing authority held by any other Federal
			 agency.</text>
					</paragraph></subsection></section><section commented="no" id="idd65e79f2-e0aa-4b8a-963a-c8ff03795de7"><enum>102.</enum><header>Unauthorized
			 manipulation of Internet traffic on a user’s computer</header>
				<subsection commented="no" id="idee74f2af-0ec4-4269-8869-be84dbd60300"><enum>(a)</enum><header>Definition</header><text>In
			 this section, the term <term>protected computer</term> has the meaning given
			 the term in section 1030(e)(2) of title 18, United States Code.</text>
				</subsection><subsection id="IDf5528b2749d7425a84c9bcd9d832b53f"><enum>(b)</enum><header>Prohibition</header>
					<paragraph id="idA0E8554438C746D0AD4AD655A354D651"><enum>(1)</enum><header>In
			 general</header><text>Unless a service provider provides a clear and
			 conspicuous disclosure of data collected in the process of intercepting a web
			 search or query entered by an authorized user of a protected computer, and
			 obtains the consent of an authorized user of the protected computer prior to
			 any such action, it shall be unlawful for a service provider to knowingly or
			 intentionally—</text>
						<subparagraph id="ID6e1358f03b9d486e976824c58651dfda"><enum>(A)</enum><text>bypass the display of
			 search engine results and redirect web searches or queries entered by an
			 authorized user of a protected computer directly to a commercial website,
			 counterfeit web page, or targeted advertisement and derive an economic benefit
			 from such activity; or</text>
						</subparagraph><subparagraph id="ID5d41f5f299d846d290d5e336b0fb4ad5"><enum>(B)</enum><text>monitor, manipulate,
			 aggregate, and market the data collected in the process of intercepting a web
			 search or query entered by an authorized user of a protected computer and
			 derive an economic benefit from such activity.</text>
						</subparagraph></paragraph><paragraph id="idAFD01923BACC47608DA749C0F8E5E722"><enum>(2)</enum><header>Consent</header><text>A
			 service provider may not require consent to perform the collection of data
			 described in paragraph (1) as a condition of providing service to an authorized
			 user of the protected computer.</text>
					</paragraph></subsection><subsection commented="no" id="id65115d84-c3d3-42c3-a6d1-7db20bbb0d3c"><enum>(c)</enum><header>Limitations on
			 liability</header><text>The restrictions imposed under this section do not
			 apply to any monitoring of, or interaction with, a subscriber's Internet or
			 other network connection or service, or a protected computer, by or at the
			 direction of a telecommunications carrier, cable operator, computer hardware or
			 software provider, financial institution or provider of information services or
			 interactive computer service for—</text>
					<paragraph commented="no" id="id5eb5913e-e8f0-4b8a-9728-2c99e54ae653"><enum>(1)</enum><text>network or computer
			 security purposes;</text>
					</paragraph><paragraph commented="no" id="idb63889d3-6eb6-4b28-92d1-dd39003f47a8"><enum>(2)</enum><text>diagnostics;</text>
					</paragraph><paragraph commented="no" id="idcf68df29-d50c-4f7d-906f-8be871965e22"><enum>(3)</enum><text>technical support;</text>
					</paragraph><paragraph commented="no" id="id72dfcf94-e021-4e1c-a060-4ac972204e70"><enum>(4)</enum><text>repair;</text>
					</paragraph><paragraph commented="no" id="idfe227b9d-8124-4af8-8340-715a5c3831d0"><enum>(5)</enum><text>network
			 management;</text>
					</paragraph><paragraph commented="no" id="id6f81bc48-e5a0-400f-9ae9-681d66fff04f"><enum>(6)</enum><text>authorized updates of
			 software or system firmware;</text>
					</paragraph><paragraph commented="no" id="id03e56f2f-d238-439a-9018-ac299787048f"><enum>(7)</enum><text>authorized remote system
			 management;</text>
					</paragraph><paragraph commented="no" id="id030c9f93-813d-4aa6-8419-24017df8aa1a"><enum>(8)</enum><text>authorized provision of
			 protection for users of the computer from objectionable content;</text>
					</paragraph><paragraph commented="no" id="idc4932e6c-4625-41cd-8fd7-c85aa971c016"><enum>(9)</enum><text>authorized scanning for
			 computer software used in violation of this section for removal by an
			 authorized user; or</text>
					</paragraph><paragraph commented="no" id="idb34084fe-b3d5-45d5-b83a-96561aa10de2"><enum>(10)</enum><text>detection or prevention
			 of fraud.</text>
					</paragraph></subsection><subsection commented="no" id="id8a5a1a1a-4421-4492-8e40-60b57cb26a89"><enum>(d)</enum><header>Enforcement by the
			 Attorney General</header>
					<paragraph commented="no" id="id3eae7f17-8430-4c4d-a6cf-1cc55e2321de"><enum>(1)</enum><header>Liability and penalty
			 for violations</header><text>Any person who engages in an activity in violation
			 of this section shall be fined not more than $500,000.</text>
					</paragraph><paragraph commented="no" id="ide774419a-2cf2-4fc1-b1e3-d45281630d1d"><enum>(2)</enum><header>Enhanced liability and
			 penalties for pattern or practice of violations</header>
						<subparagraph commented="no" id="idffb1f327-99a6-49b2-8371-913ebf69efa5"><enum>(A)</enum><header>In
			 general</header><text>Any person who engages in a pattern or practice of
			 activity that violates the provisions of this section shall be fined not more
			 than $1,000,000.</text>
						</subparagraph><subparagraph commented="no" id="idda50783d-70eb-477c-b92f-a585b5062a9c"><enum>(B)</enum><header>Treatment of single
			 action or conduct</header><text>For purposes of subparagraph (A), any single
			 action or conduct that violates this section with respect to multiple protected
			 computers shall be construed as a single violation.</text>
						</subparagraph></paragraph><paragraph commented="no" id="id5c646a46-2f08-4a93-a063-b467ae4068d7"><enum>(3)</enum><header>Considerations</header><text>In
			 determining the amount of any penalty under paragraph (1) or (2), the court
			 shall take into account—</text>
						<subparagraph commented="no" id="id96b15ab0-3aa3-490d-978a-63ba73c26913"><enum>(A)</enum><text>the degree of culpability
			 of the defendant;</text>
						</subparagraph><subparagraph commented="no" id="id2d1c3fec-2809-4f17-8bfa-a79041a74bd9"><enum>(B)</enum><text>any history of prior such
			 conduct;</text>
						</subparagraph><subparagraph commented="no" id="id8d6f7368-2642-4b51-b751-92ac1bc8ec60"><enum>(C)</enum><text>the ability of the
			 defendant to pay any fine imposed;</text>
						</subparagraph><subparagraph commented="no" id="id8b278ef4-e83c-4886-908f-353652d47528"><enum>(D)</enum><text>the effect on the ability
			 of the defendant to continue to do business; and</text>
						</subparagraph><subparagraph commented="no" id="id99c83d51-2914-431f-a3ee-841ae67ad1fc"><enum>(E)</enum><text>such other matters as
			 justice may require.</text>
						</subparagraph></paragraph></subsection></section></title><title changed="added" commented="no" committee-id="SSJU00" id="ide02ece16-5353-4199-865c-0847567b7a97" level-type="subsequent" reported-display-style="italic"><enum>II</enum><header display-inline="yes-display-inline">Privacy and security of sensitive
			 personally identifiable information </header>
			<subtitle commented="no" id="id815b73cd-45cc-48d7-ba16-cb8c903639c9" level-type="subsequent"><enum>A</enum><header display-inline="yes-display-inline">A data privacy and security
			 program</header>
				<section commented="no" display-inline="no-display-inline" id="id37e16823-cf2a-45f1-a749-85613311f5f7" section-type="subsequent-section"><enum>201.</enum><header display-inline="yes-display-inline">Purpose and applicability of data privacy
			 and security program</header>
					<subsection commented="no" display-inline="no-display-inline" id="idfb463667-5b28-411a-b33a-cf42d61eae43"><enum>(a)</enum><header display-inline="yes-display-inline">Purpose</header><text display-inline="yes-display-inline">The purpose of this subtitle is to ensure
			 standards for developing and implementing administrative, technical, and
			 physical safeguards to protect the security of sensitive personally
			 identifiable information.</text>
					</subsection><subsection commented="no" display-inline="no-display-inline" id="id8e119a8f-9c13-4af0-8b3c-490e4403c906"><enum>(b)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">A business entity engaging in interstate
			 commerce that involves collecting, accessing, transmitting, using, storing, or
			 disposing of sensitive personally identifiable information in electronic or
			 digital form on 10,000 or more United States persons is subject to the
			 requirements for a data privacy and security program under section 202 for
			 protecting sensitive personally identifiable information.</text>
					</subsection><subsection commented="no" display-inline="no-display-inline" id="idb686541f-86da-4b3a-a9ac-59aa0d29a371"><enum>(c)</enum><header display-inline="yes-display-inline">Limitations</header><text display-inline="yes-display-inline">Notwithstanding any other obligation under
			 this subtitle, this subtitle does not apply to the following:</text>
						<paragraph id="ID9b53eedadacc4b17a4c30a9137eacbcc"><enum>(1)</enum><header>Financial
			 institutions</header><text>A financial institution subject to the data security
			 requirements and standards under 501(b) of the Gramm-Leach-Bliley Act (15
			 U.S.C. 6801(b)) and subject to the jurisdiction of an agency or authority
			 described in section 505(a) of the Gramm-Leach-Bliley Act (15 U.S.C. 6805(a)),
			 if the Federal functional regulator (as defined in section 509 of the
			 Gramm-Leach-Bliley Act (15 U.S.C. 6809)) with jurisdiction over that financial
			 institution has issued a regulation under title V of the Gramm-Leach-Bliley Act
			 (15 U.S.C. 6801 et seq.) that requires financial institutions within its
			 jurisdiction to provide notification to individuals following a breach of
			 security.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id46d464a8-b8ab-4ad1-9ece-ac3c27a7510b"><enum>(2)</enum><header display-inline="yes-display-inline">HIPAA regulated entities</header>
							<subparagraph commented="no" display-inline="no-display-inline" id="id8b4ea644-63d0-4d2d-a9a4-c0ee207b4b18"><enum>(A)</enum><header display-inline="yes-display-inline">Covered entities</header><text display-inline="yes-display-inline">A business entity subject to the Health
			 Insurance Portability and Accountability Act of 1996 (42 U.S.C. 1301 et seq.),
			 including the data security requirements and implementing regulations of that
			 Act.</text>
							</subparagraph><subparagraph id="id2cff8799-f958-4fa3-a2db-627ada40a77e"><enum>(B)</enum><header>Compliance</header><text>A
			 business entity that—</text>
								<clause id="id9b1be6ba-076e-4fc5-90af-330150e458c3"><enum>(i)</enum><text>is acting as a business
			 associate, as that term is defined under the Health Insurance Portability and
			 Accountability Act of 1996 (42 U.S.C. 1301 et seq.) and is in compliance with
			 the requirements imposed under that Act and implementing regulations
			 promulgated under that Act; and</text>
								</clause><clause id="idc670f1e6-62d0-4f06-95b0-07e3130ec359"><enum>(ii)</enum><text>is subject to, and
			 currently in compliance, with the privacy and data security requirements under
			 sections 13401 and 13404 of division A of the American Reinvestment and
			 Recovery Act of 2009 (42 U.S.C. 17931 and 17934) and implementing regulations
			 promulgated under such sections.</text>
								</clause></subparagraph></paragraph><paragraph id="IDf93c3eff71f4438e933f63454d4ecf1a"><enum>(3)</enum><header>Service
			 providers</header><text>A service provider for any electronic communication by
			 a third-party, to the extent that the service provider is exclusively engaged
			 in the transmission, routing, or temporary, intermediate, or transient storage
			 of that communication.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="idcfd91895-7e74-4664-8892-b2c92aedfe7e"><enum>(4)</enum><header display-inline="yes-display-inline">Public
			 records</header><text display-inline="yes-display-inline">Public records not
			 otherwise subject to a confidentiality or nondisclosure requirement, or
			 information obtained from a public record, including information obtained from
			 a news report or periodical.</text>
						</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="id320a92ff-f731-4234-8de6-2b3b5752ffd3"><enum>(d)</enum><header>Rule of
			 construction</header><text>Nothing in this subtitle shall be construed to
			 modify, limit, or supersede the operation of the provisions of the
			 Gramm-Leach-Bliley Act (15 U.S.C. 6801 et seq.), or its implementing
			 regulations, including such regulations adopted or enforced by the
			 States.</text>
					</subsection></section><section commented="no" display-inline="no-display-inline" id="id9e672e58-3c3e-4dac-85c8-b0d05166fe76" section-type="subsequent-section"><enum>202.</enum><header display-inline="yes-display-inline">Requirements for a personal data privacy
			 and security program</header>
					<subsection commented="no" display-inline="no-display-inline" id="id22331952-af50-4b94-b0d2-d2a25c294c19"><enum>(a)</enum><header display-inline="yes-display-inline">Personal data privacy and security
			 program</header><text display-inline="yes-display-inline">A business entity
			 subject to this subtitle shall comply with the following safeguards and any
			 other administrative, technical, or physical safeguards identified by the
			 Federal Trade Commission in a rulemaking process pursuant to section 553 of
			 title 5, United States Code, for the protection of sensitive personally
			 identifiable information:</text>
						<paragraph commented="no" display-inline="no-display-inline" id="idb5b66820-9e6e-42fb-80b9-4be74c4c40a4"><enum>(1)</enum><header display-inline="yes-display-inline">Scope</header><text display-inline="yes-display-inline">A business entity shall implement a
			 comprehensive personal data privacy and security program that includes
			 administrative, technical, and physical safeguards appropriate to the size and
			 complexity of the business entity and the nature and scope of its
			 activities.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id8882fb7c-f195-445f-8e41-9358dfa7ff7d"><enum>(2)</enum><header display-inline="yes-display-inline">Design</header><text display-inline="yes-display-inline">The personal data privacy and security
			 program shall be designed to—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="idf5d8a9b4-1d4a-4f04-9a6a-9d7a5648e26b"><enum>(A)</enum><text display-inline="yes-display-inline">ensure the privacy, security, and
			 confidentiality of sensitive personally identifiable information;</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id9108d3c6-ffb1-4a26-99b4-b3681ef20a0f"><enum>(B)</enum><text display-inline="yes-display-inline">protect against any anticipated
			 vulnerabilities to the privacy, security, or integrity of sensitive personally
			 identifiable information; and</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idb936b5bd-f4e5-40b5-a7a6-9adccade0894"><enum>(C)</enum><text display-inline="yes-display-inline">protect against unauthorized access to or
			 use of sensitive personally identifiable information that could create a
			 significant risk of harm to any individual.</text>
							</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id871dde32-84b4-4d8e-a985-e784f7814b1a"><enum>(3)</enum><header display-inline="yes-display-inline">Risk assessment</header><text display-inline="yes-display-inline">A business entity shall—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="ide5c0f28a-869c-4a1c-9b94-4cf97401b40b"><enum>(A)</enum><text display-inline="yes-display-inline">identify reasonably foreseeable internal
			 and external vulnerabilities that could result in unauthorized access,
			 disclosure, use, or alteration of sensitive personally identifiable information
			 or systems containing sensitive personally identifiable information;</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idb7e28882-1615-4966-9f51-c37f86228376"><enum>(B)</enum><text display-inline="yes-display-inline">assess the likelihood of and potential
			 damage from unauthorized access, disclosure, use, or alteration of sensitive
			 personally identifiable information;</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idd8595023-8e8f-41fc-ad26-4bbff6273087"><enum>(C)</enum><text display-inline="yes-display-inline">assess the sufficiency of its policies,
			 technologies, and safeguards in place to control and minimize risks from
			 unauthorized access, disclosure, use, or alteration of sensitive personally
			 identifiable information; and</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id7a79bae0-875b-43a7-9f68-8832ea0590b8"><enum>(D)</enum><text display-inline="yes-display-inline">assess the vulnerability of sensitive
			 personally identifiable information during destruction and disposal of such
			 information, including through the disposal or retirement of hardware.</text>
							</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="idc8982593-531b-4ea8-ab6b-6a28279d4e59"><enum>(4)</enum><header display-inline="yes-display-inline">Risk management and control</header><text display-inline="yes-display-inline">Each business entity shall—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="id055ba2f7-df73-4044-9af1-da2b69365fae"><enum>(A)</enum><text display-inline="yes-display-inline">design its personal data privacy and
			 security program to control the risks identified under paragraph (3);
			 and</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idaa4929e9-fd1e-46ec-a137-6e0b98558dc5"><enum>(B)</enum><text display-inline="yes-display-inline">adopt measures commensurate with the
			 sensitivity of the data as well as the size, complexity, and scope of the
			 activities of the business entity that—</text>
								<clause commented="no" display-inline="no-display-inline" id="idd51aa4b4-ed85-48c5-8a00-832346d784f3"><enum>(i)</enum><text display-inline="yes-display-inline">control access to systems and facilities
			 containing sensitive personally identifiable information, including controls to
			 authenticate and permit access only to authorized individuals;</text>
								</clause><clause commented="no" display-inline="no-display-inline" id="id4946cea4-ec2e-42b3-88c1-adc1266dfb71"><enum>(ii)</enum><text display-inline="yes-display-inline">detect, record, and preserve information
			 relevant to actual and attempted fraudulent, unlawful, or unauthorized access,
			 disclosure, use, or alteration of sensitive personally identifiable
			 information, including by employees and other individuals otherwise authorized
			 to have access;</text>
								</clause><clause commented="no" display-inline="no-display-inline" id="idd9f7ee75-7ac0-4de2-b848-85ecc3023e57"><enum>(iii)</enum><text display-inline="yes-display-inline">protect sensitive personally identifiable
			 information during use, transmission, storage, and disposal by encryption,
			 redaction, or access controls that are widely accepted as an effective industry
			 practice or industry standard, or other reasonable means (including as directed
			 for disposal of records under section 628 of the Fair Credit Reporting Act (15
			 U.S.C. 1681w) and the implementing regulations of such Act as set forth in
			 section 682 of title 16, Code of Federal Regulations);</text>
								</clause><clause commented="no" display-inline="no-display-inline" id="ide5e32441-bcbb-4c4c-9f41-a994261b2770"><enum>(iv)</enum><text display-inline="yes-display-inline">ensure that sensitive personally
			 identifiable information is properly destroyed and disposed of, including
			 during the destruction of computers, diskettes, and other electronic media that
			 contain sensitive personally identifiable information;</text>
								</clause><clause commented="no" display-inline="no-display-inline" id="idce2019c1-1859-4cb2-8ebf-2a750bdab25a"><enum>(v)</enum><text display-inline="yes-display-inline">trace access to records containing
			 sensitive personally identifiable information so that the business entity can
			 determine who accessed or acquired such sensitive personally identifiable
			 information pertaining to specific individuals;</text>
								</clause><clause commented="no" display-inline="no-display-inline" id="id4065beb4-bab1-4f77-bb25-17ca0f1d52e8"><enum>(vi)</enum><text display-inline="yes-display-inline">ensure that no third party or customer of
			 the business entity is authorized to access or acquire sensitive personally
			 identifiable information without the business entity first performing
			 sufficient due diligence to ascertain, with reasonable certainty, that such
			 information is being sought for a valid legal purpose; and</text>
								</clause><clause commented="no" display-inline="no-display-inline" id="idb278ddc6-c07c-404e-8ec8-59d2c651412d"><enum>(vii)</enum><text>minimize the amount of
			 personal information maintained by the business entity, providing for the
			 retention of such personal information only as reasonably needed for the
			 business purposes of the business entity or as necessary to comply with any
			 other provision of law.</text>
								</clause></subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="idef0fbd4b-75c7-40d7-961a-1629eb8a27eb"><enum>(b)</enum><header display-inline="yes-display-inline">Training</header><text display-inline="yes-display-inline">Each business entity subject to this
			 subtitle shall take steps to ensure employee training and supervision for
			 implementation of the data security program of the business entity.</text>
					</subsection><subsection commented="no" display-inline="no-display-inline" id="id0bc69fe8-4fe1-401b-b472-93198b56873f"><enum>(c)</enum><header display-inline="yes-display-inline">Vulnerability testing</header>
						<paragraph commented="no" display-inline="no-display-inline" id="iddedc1b5a-dbb6-471f-a9e6-b2410c13e08e"><enum>(1)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">Each business entity subject to this
			 subtitle shall take steps to ensure regular testing of key controls, systems,
			 and procedures of the personal data privacy and security program to detect,
			 prevent, and respond to attacks or intrusions, or other system failures.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id9870b4a8-efd0-4ffe-b6cf-99fc3f0657a7"><enum>(2)</enum><header display-inline="yes-display-inline">Frequency</header><text display-inline="yes-display-inline">The frequency and nature of the tests
			 required under paragraph (1) shall be determined by the risk assessment of the
			 business entity under subsection (a)(3).</text>
						</paragraph></subsection><subsection id="IDe25ee61f1a5a4dfbb2e6f3f924335386"><enum>(d)</enum><header>Certain relationship to
			 providers of services</header><text>In the event a business entity subject to
			 this subtitle engages a person or entity not subject to this subtitle (other
			 than a service provider) to receive sensitive personally identifiable
			 information in performing services or functions (other than the services or
			 functions provided by a service provider) on behalf of and under the
			 instruction of such business entity, such business entity shall—</text>
						<paragraph id="IDf89681f474f74eb189120f726fc61d9e"><enum>(1)</enum><text>exercise appropriate due
			 diligence in selecting the person or entity for responsibilities related to
			 sensitive personally identifiable information, and take reasonable steps to
			 select and retain a person or entity that is capable of maintaining appropriate
			 safeguards for the security, privacy, and integrity of the sensitive personally
			 identifiable information at issue; and</text>
						</paragraph><paragraph id="IDc2b7cf032e4549cd865d4a3501d35bf9"><enum>(2)</enum><text>require the person or
			 entity by contract to implement and maintain appropriate measures designed to
			 meet the objectives and requirements governing entities subject to section 201,
			 this section, and subtitle B.</text>
						</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="id54afd684-0fc8-48b5-aa09-47a221482cd4"><enum>(e)</enum><header display-inline="yes-display-inline">Periodic assessment and personal data
			 privacy and security modernization</header><text display-inline="yes-display-inline">Each business entity subject to this
			 subtitle shall on a regular basis monitor, evaluate, and adjust, as appropriate
			 its data privacy and security program in light of any relevant changes
			 in—</text>
						<paragraph commented="no" display-inline="no-display-inline" id="idd0a5812d-f3af-4f71-bc6d-f8807711a993"><enum>(1)</enum><text display-inline="yes-display-inline">technology;</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id45e5eef4-acd0-4c09-a69a-13759c59a2d5"><enum>(2)</enum><text display-inline="yes-display-inline">the sensitivity of sensitive personally
			 identifiable information;</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ida40a927b-8ed0-441c-b117-da14c7fabf75"><enum>(3)</enum><text display-inline="yes-display-inline">internal or external threats to sensitive
			 personally identifiable information; and</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id9a499bd6-bed8-4000-b388-81db20977793"><enum>(4)</enum><text display-inline="yes-display-inline">the changing business arrangements of the
			 business entity, such as—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="id9de5709b-0fa5-4580-be21-184bcfd9e152"><enum>(A)</enum><text display-inline="yes-display-inline">mergers and acquisitions;</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idf96a4615-9160-427d-aa57-3027b38b428d"><enum>(B)</enum><text display-inline="yes-display-inline">alliances and joint ventures;</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idc51c944b-8df7-4be8-87cf-67397997891d"><enum>(C)</enum><text display-inline="yes-display-inline">outsourcing arrangements;</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idff67ef9b-2047-4581-b8c5-97a55e828df3"><enum>(D)</enum><text display-inline="yes-display-inline">bankruptcy; and</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idfca464b8-ee43-42f4-911a-00ba7018db90"><enum>(E)</enum><text display-inline="yes-display-inline">changes to sensitive personally
			 identifiable information systems.</text>
							</subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="id14f108e3-541d-4ea2-8a5f-e16afc63a6e4"><enum>(f)</enum><header display-inline="yes-display-inline">Implementation timeline</header><text display-inline="yes-display-inline">Not later than 1 year after the date of
			 enactment of this Act, a business entity subject to the provisions of this
			 subtitle shall implement a data privacy and security program pursuant to this
			 subtitle.</text>
					</subsection></section><section commented="no" display-inline="no-display-inline" id="id3c51042e-88bb-4997-b088-40c5d7f6ba59" section-type="subsequent-section"><enum>203.</enum><header display-inline="yes-display-inline">Federal enforcement</header>
					<subsection commented="no" display-inline="no-display-inline" id="idd86a2554-40d2-4502-81fd-4854717efa50"><enum>(a)</enum><header display-inline="yes-display-inline">Civil penalties</header>
						<paragraph commented="no" display-inline="no-display-inline" id="id1a69b4b9-9fb7-4e7c-9301-4878c11f9f8b"><enum>(1)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">The Attorney General may bring a civil
			 action in the appropriate United States district court against any business
			 entity that engages in conduct constituting a violation of this subtitle and,
			 upon proof of such conduct by a preponderance of the evidence, such business
			 entity shall be subject to a civil penalty of not more than $5,000 per
			 violation per day while such a violation exists, with a maximum of $20,000,000
			 per violation, unless such conduct is found to be willful or
			 intentional.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ida8cc43ff-c9c5-41f6-af0d-081a34eb77a8"><enum>(2)</enum><header display-inline="yes-display-inline">Intentional or willful
			 violation</header><text display-inline="yes-display-inline">A business entity
			 that intentionally or willfully violates the provisions of this subtitle shall
			 be subject to additional penalties in the amount of $5,000 per violation per
			 day while such a violation exists.</text>
						</paragraph><paragraph id="id3d289493-3c78-4963-9282-005548045e41"><enum>(3)</enum><header>Considerations</header><text>In
			 determining the amount of a civil penalty under this subsection, the court
			 shall take into account—</text>
							<subparagraph id="id946e117b-9193-45ec-b1f2-8e77f215041b"><enum>(A)</enum><text>the degree of culpability
			 of the business entity;</text>
							</subparagraph><subparagraph id="id238d44d0-0274-43a3-9aa1-2d4507ce39e2"><enum>(B)</enum><text>any prior violations of
			 this subtitle by the business entity;</text>
							</subparagraph><subparagraph id="id2beb3bd7-d975-489a-bcad-da975eeaca12"><enum>(C)</enum><text>the ability of the
			 business entity to pay a civil penalty;</text>
							</subparagraph><subparagraph id="id12fdfa6b-eb3a-4ed5-b1a5-e4f5a29f0b1c"><enum>(D)</enum><text>the effect on the ability
			 of the business entity to continue to do business;</text>
							</subparagraph><subparagraph id="idfb990d6f-b6a3-45f4-8e5d-5f9eaab208ed"><enum>(E)</enum><text>the number of individuals
			 whose sensitive personally identifiable information was compromised by the
			 breach;</text>
							</subparagraph><subparagraph id="id5b482b47-edde-4b71-bc10-725a76689c78"><enum>(F)</enum><text>the relative cost of
			 compliance with this subtitle; and</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idb22af75d-7359-4613-946b-dfdaffaae35d"><enum>(G)</enum><text>such other matters as
			 justice may require.</text>
							</subparagraph></paragraph></subsection><subsection id="id976e5885-8375-4c66-938c-ce1bd10e8d88"><enum>(b)</enum><header>Injunctive actions by
			 the Attorney General</header>
						<paragraph id="idedf663b7-b41a-4de7-9e1f-0983134c3e51"><enum>(1)</enum><header>In
			 general</header><text>If it appears that a business entity has engaged, or is
			 engaged, in any act or practice constituting a violation of this subtitle, the
			 Attorney General may petition an appropriate district court of the United
			 States for an order—</text>
							<subparagraph id="id6993bbec-21ff-4b67-b174-b9fc5802774a"><enum>(A)</enum><text>enjoining such act or
			 practice; or</text>
							</subparagraph><subparagraph id="idc4b9c5e4-d034-430f-9a17-365180bee860"><enum>(B)</enum><text>enforcing compliance with
			 this subtitle.</text>
							</subparagraph></paragraph><paragraph id="id013b0110-2cb8-4c1b-803d-9c0b8ea274b2"><enum>(2)</enum><header>Issuance of
			 order</header><text>A court may issue an order under paragraph (1), if the
			 court finds that the conduct in question constitutes a violation of this
			 subtitle.</text>
						</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="id61d6ffed-629a-41c4-9dbf-408ba5f9f075"><enum>(c)</enum><header display-inline="yes-display-inline">Other rights and remedies</header><text display-inline="yes-display-inline">The rights and remedies available under
			 this section are cumulative and shall not affect any other rights and remedies
			 available under law.</text>
					</subsection></section><section id="idbf69c520-12c4-47c4-8e41-79b9829559c9"><enum>204.</enum><header>Enforcement by State
			 Attorneys General</header>
					<subsection commented="no" display-inline="no-display-inline" id="idd5885374-1de9-4b0e-bfa3-82011eaa3bf7"><enum>(a)</enum><header display-inline="yes-display-inline">Civil actions</header>
						<paragraph commented="no" display-inline="no-display-inline" id="idb1a839b0-21ef-464b-bf41-a8245a88f19f"><enum>(1)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">In any case in which the attorney general
			 of a State or any State or local law enforcement agency authorized by the State
			 attorney general or by State statute to prosecute violations of consumer
			 protection law, has reason to believe that an interest of the residents of that
			 State has been or is threatened or adversely affected by the acts or practices
			 of a business entity that violate this subtitle, the State may bring a civil
			 action on behalf of the residents of that State in a district court of the
			 United States of appropriate jurisdiction, or any other court of competent
			 jurisdiction, to—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="id4117c4f1-d4b0-4c04-9b4b-076825b6cf17"><enum>(A)</enum><text display-inline="yes-display-inline">enjoin that act or practice;</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id36aa6f38-4080-42f1-beb5-dcf59cee057e"><enum>(B)</enum><text display-inline="yes-display-inline">enforce compliance with this subtitle;
			 or</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id4c1ce98a-9274-41a0-9953-267d7bc71da2"><enum>(C)</enum><text display-inline="yes-display-inline">obtain civil penalties of not more than
			 $5,000 per violation per day while such violations persist, up to a maximum of
			 $20,000,000 per violation.</text>
							</subparagraph></paragraph><paragraph id="idb4de21b4-a348-4854-8a81-9a764e2bf7da"><enum>(2)</enum><header>Considerations</header><text>In
			 determining the amount of a civil penalty under this subsection, the court
			 shall take into account—</text>
							<subparagraph id="id2f940dfd-914a-4412-8cab-70c65cf920f8"><enum>(A)</enum><text>the degree of culpability
			 of the business entity;</text>
							</subparagraph><subparagraph id="id45c30c47-807d-44be-a8d8-8bc80f43030d"><enum>(B)</enum><text>any prior violations of
			 this subtitle by the business entity;</text>
							</subparagraph><subparagraph id="id44b72214-4b94-4702-bc76-122f7fc860f3"><enum>(C)</enum><text>the ability of the
			 business entity to pay a civil penalty;</text>
							</subparagraph><subparagraph id="id0db31d6f-f0a2-4489-83fc-059dad9df7ac"><enum>(D)</enum><text>the effect on the ability
			 of the business entity to continue to do business;</text>
							</subparagraph><subparagraph id="id65c68662-7f7e-491a-b2b7-347fbf7c2679"><enum>(E)</enum><text>the number of individuals
			 whose sensitive personally identifiable information was compromised by the
			 breach;</text>
							</subparagraph><subparagraph id="id73471672-f863-4afa-af34-df87cebcaebb"><enum>(F)</enum><text>the relative cost of
			 compliance with this subtitle; and</text>
							</subparagraph><subparagraph id="idddb4f6bc-a6a3-4f3f-bb4d-f0ddfae2487b"><enum>(G)</enum><text>such other matters as
			 justice may require.</text>
							</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="idbae4f63d-dda4-4a92-b794-8bb5856ce32d"><enum>(3)</enum><header display-inline="yes-display-inline">Notice</header>
							<subparagraph commented="no" display-inline="no-display-inline" id="id6b9383d9-4e2c-4acd-a207-45bf9b54cd84"><enum>(A)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">Before filing an action under this
			 subsection, the attorney general of the State involved shall provide to the
			 Attorney General—</text>
								<clause commented="no" display-inline="no-display-inline" id="id6b61b0a1-5407-41f7-b014-256e6ae921c1"><enum>(i)</enum><text display-inline="yes-display-inline">a written notice of that action; and</text>
								</clause><clause commented="no" display-inline="no-display-inline" id="id3390fa65-25b4-410d-9abd-961e1dcbd3da"><enum>(ii)</enum><text display-inline="yes-display-inline">a copy of the complaint for that
			 action.</text>
								</clause></subparagraph><subparagraph id="IDff0a6a663a5c4da480bc6365ff476d8e"><enum>(B)</enum><header>Exception</header><text>Subparagraph
			 (A) shall not apply with respect to the filing of an action by an attorney
			 general of a State under this subsection, if the attorney general of a State
			 determines that it is not feasible to provide the notice described in this
			 subparagraph before the filing of the action.</text>
							</subparagraph><subparagraph id="IDd74ef70caf7741179cc260afa21fe928"><enum>(C)</enum><header>Notification when
			 practicable</header><text>In an action described in subparagraph (B), the
			 attorney general of a State shall provide the written notice and a copy of the
			 complaint to the Attorney General as soon after the filing of the complaint as
			 practicable.</text>
							</subparagraph></paragraph></subsection><subsection id="ide3f78ac1-fc0c-4582-845d-5d0245077b3f"><enum>(b)</enum><header>Federal
			 proceedings</header><text>Upon receiving notice under subsection (a)(3), the
			 Attorney General shall have the right to—</text>
						<paragraph id="idb0162d14-6d4d-4f1b-8756-854759767a38"><enum>(1)</enum><text>move to stay the action,
			 pending the final disposition of a pending Federal proceeding or action
			 described in subsection (c);</text>
						</paragraph><paragraph id="ida8d53859-9146-48a7-8de6-2ca02e8cd006"><enum>(2)</enum><text>initiate an action in the
			 appropriate United States district court under section 218 and move to
			 consolidate all pending actions, including State actions, in such court;</text>
						</paragraph><paragraph id="id2fad56a7-b18c-42c7-b828-ffc6b6cb1bf1"><enum>(3)</enum><text>intervene in an action
			 brought under subsection (a)(2); and</text>
						</paragraph><paragraph id="ide357b18a-06f4-4851-ae4c-b1cc7db6b85b"><enum>(4)</enum><text>file petitions for
			 appeal.</text>
						</paragraph></subsection><subsection id="id468d89fe-17bf-4188-8d7a-539a46d5be28"><enum>(c)</enum><header>Pending
			 proceedings</header><text>If the Attorney General has instituted a proceeding
			 or action for a violation of this subtitle or any regulations thereunder, no
			 attorney general of a State may, during the pendency of such proceeding or
			 action, bring an action under this section against any defendant named in such
			 criminal proceeding or civil action for any violation that is alleged in that
			 proceeding or action.</text>
					</subsection><subsection id="id468bda52-f5d9-4c56-8fc3-403550d03f1f"><enum>(d)</enum><header>Construction</header><text>For
			 purposes of bringing any civil action under subsection (a), nothing in this
			 section shall be construed to prevent an attorney general of a State from
			 exercising the powers conferred on such attorney general by the laws of that
			 State to—</text>
						<paragraph id="id06a35a5e-a18e-4da3-be7f-7ad8532ccbe8"><enum>(1)</enum><text>conduct
			 investigations;</text>
						</paragraph><paragraph id="idcfb61a71-adf4-4ef9-b8fb-615e6563bcb6"><enum>(2)</enum><text>administer oaths or
			 affirmations; or</text>
						</paragraph><paragraph id="idd7d48e6c-e271-4997-8697-49e8db701c7f"><enum>(3)</enum><text>compel the attendance of
			 witnesses or the production of documentary and other evidence.</text>
						</paragraph></subsection><subsection id="id22be7603-774e-4994-b72f-b9c7eb20647a"><enum>(e)</enum><header>Venue; service of
			 process</header>
						<paragraph id="id2df0b54e-a4b0-4240-a395-db57538116c3"><enum>(1)</enum><header>Venue</header><text>Any
			 action brought under subsection (a) may be brought in—</text>
							<subparagraph id="id91353561-8a5b-4895-b097-960c4bd2b0e1"><enum>(A)</enum><text>the district court of the
			 United States that meets applicable requirements relating to venue under
			 section 1391 of title 28, United States Code; or</text>
							</subparagraph><subparagraph id="id799141a8-4374-4e7a-a6c7-8a284b093189"><enum>(B)</enum><text>another court of
			 competent jurisdiction.</text>
							</subparagraph></paragraph><paragraph id="idfb6afd6c-d4de-4997-bf22-cdcc6afe1a2f"><enum>(2)</enum><header>Service of
			 process</header><text>In an action brought under subsection (a), process may be
			 served in any district in which the defendant—</text>
							<subparagraph id="id931710c5-c882-478e-a8c3-6ed9346585a6"><enum>(A)</enum><text>is an inhabitant;
			 or</text>
							</subparagraph><subparagraph id="id65ccac3d-955e-47c9-8889-8fcfe9aaff1d"><enum>(B)</enum><text>may be found.</text>
							</subparagraph></paragraph></subsection></section><section id="id5be57fa2-4ff5-4749-a41a-43a35714f3fb"><enum>205.</enum><header>Supplemental
			 enforcement by individuals</header>
					<subsection id="id88339e0c-ddfb-47b5-b077-348c551f94aa"><enum>(a)</enum><header>In
			 general</header><text>Any person aggrieved by a violation of the provisions of
			 this subtitle by a business entity may bring a civil action in a court of
			 appropriate jurisdiction to recover for personal injuries sustained as a result
			 of the violation.</text>
					</subsection><subsection id="id5771ac89-1202-4540-aabe-cb618ed32b3a"><enum>(b)</enum><header>Authority To bring
			 civil action; jurisdiction</header><text>As provided in subsection (c), any
			 person may commence a civil action on his own behalf against any business
			 entity who is alleged to have violated the provisions of this subtitle.</text>
					</subsection><subsection id="idb20f2a4d-a090-4618-ae88-ad357384e50c"><enum>(c)</enum><header>Remedies in a citizen
			 suit</header>
						<paragraph id="id1e5a0ad3-1dd5-404b-a3f9-9d288d94e5e3"><enum>(1)</enum><header>Damages</header><text>Any
			 individual harmed by a failure of a business entity to comply with the
			 provisions of this subtitle, shall be able to collect damages of not more than
			 $10,000 per violation per day while such violations persist, up to a maximum of
			 $20,000,000 per violation.</text>
						</paragraph><paragraph id="idb6b448a5-826e-446c-98e2-98646ccbcbb5"><enum>(2)</enum><header>Punitive
			 damages</header><text>A business entity may be liable for punitive damages if
			 the business entity intentionally or willfully violates the provisions of this
			 subtitle.</text>
						</paragraph><paragraph commented="no" id="idda3343c7-04c5-4ee9-9962-11f8c727c11c"><enum>(3)</enum><header>Equitable
			 relief</header><text display-inline="yes-display-inline">A business entity that
			 violates the provisions of this subtitle may be enjoined to comply with the
			 provisions of those sections.</text>
						</paragraph></subsection><subsection id="ida20afe15-a823-4748-9d56-5320429ef4d2"><enum>(d)</enum><header>Other rights and
			 remedies</header><text>The rights and remedies available under this subsection
			 are cumulative and shall not affect any other rights and remedies available
			 under law.</text>
					</subsection><subsection id="ID84513af6dd29490dbe4d9b159251d2af"><enum>(e)</enum><header>Nonenforceability of
			 certain provisions waiving rights and remedies or requiring arbitration of
			 disputes</header>
						<paragraph id="IDb78fd28acae74ea0ba409b4c54c1b86a"><enum>(1)</enum><header>Waiver of rights and
			 remedies</header><text>The rights and remedies provided for in this section may
			 not be waived by any agreement, policy form, or condition of employment
			 including by a predispute arbitration agreement.</text>
						</paragraph><paragraph id="ID81d06d80b91c4e41971bdfb6226daa2e"><enum>(2)</enum><header>Predispute arbitration
			 agreements</header><text>No predispute arbitration agreement shall be valid or
			 enforceable, if the agreement requires arbitration of a dispute arising under
			 this section.</text>
						</paragraph></subsection><subsection id="ID70a4c4e67b084740bf337a0cec1bd75b"><enum>(f)</enum><header>Considerations</header><text>In
			 determining the amount of a civil penalty under this subsection, the court
			 shall take into account—</text>
						<paragraph id="ID7e49c6d9fd3c40ce9cb448ef375cf4b1"><enum>(1)</enum><text>the degree of culpability
			 of the business entity;</text>
						</paragraph><paragraph id="IDdab329144e0a4390bd336b883abc778b"><enum>(2)</enum><text>any prior violations of
			 this subtitle by the business entity;</text>
						</paragraph><paragraph id="ID1bfc88969094475ab935df85398b73c4"><enum>(3)</enum><text>the ability of the
			 business entity to pay a civil penalty;</text>
						</paragraph><paragraph id="IDf04af3d0bb334c288e0a7bb58447d83e"><enum>(4)</enum><text>the effect on the ability
			 of the business entity to continue to do business;</text>
						</paragraph><paragraph id="IDf6bce8c6af09419397c156a2861fe7f1"><enum>(5)</enum><text>the number of individuals
			 whose sensitive personally identifiable information was compromised by the
			 breach;</text>
						</paragraph><paragraph id="IDf467d5aa1c5c4ba5b43543ae1ed5e23b"><enum>(6)</enum><text>the relative cost of
			 compliance with this subtitle; and</text>
						</paragraph><paragraph id="IDf4aad34b37834b568f8da79501f11e67"><enum>(7)</enum><text>such other matters as
			 justice may require.</text>
						</paragraph></subsection></section></subtitle><subtitle commented="no" id="idd22dd1d0-b2fd-4e3c-acfa-deed14dbc8ef" level-type="subsequent"><enum>B</enum><header display-inline="yes-display-inline">Security breach notification</header>
				<section commented="no" display-inline="no-display-inline" id="id552e895d-1720-4150-90f0-a83b7919373b" section-type="subsequent-section"><enum>211.</enum><header display-inline="yes-display-inline">Notice to individuals</header>
					<subsection commented="no" display-inline="no-display-inline" id="idb2d5287d-da6d-4e04-9aab-20082781e783"><enum>(a)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">Any agency, or business entity engaged in
			 interstate commerce other than a service provider, that uses, accesses,
			 transmits, stores, disposes of or collects sensitive personally identifiable
			 information that experiences a security breach of such information, shall,
			 following the discovery of such security breach of such information, notify any
			 resident of the United States whose sensitive personally identifiable
			 information has been, or is reasonably believed to have been, accessed, or
			 acquired.</text>
					</subsection><subsection commented="no" display-inline="no-display-inline" id="id83489321-73ce-4855-b511-2c9cd468186d"><enum>(b)</enum><header display-inline="yes-display-inline">Obligation of owner or licensee</header>
						<paragraph commented="no" display-inline="no-display-inline" id="ida8538ca9-fd04-49aa-bdb6-7f3f9c3982d9"><enum>(1)</enum><header display-inline="yes-display-inline">Notice to owner or licensee</header><text display-inline="yes-display-inline">Any agency, or business entity engaged in
			 interstate commerce, that uses, accesses, transmits, stores, disposes of, or
			 collects sensitive personally identifiable information that the agency or
			 business entity does not own or license shall notify the owner or licensee of
			 the information following the discovery of a security breach involving such
			 information.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id22584a77-fa6e-429e-a64e-b23e80979026"><enum>(2)</enum><header display-inline="yes-display-inline">Notice by owner, licensee or other
			 designated third party</header><text display-inline="yes-display-inline">Nothing in this subtitle shall prevent or
			 abrogate an agreement between an agency or business entity required to give
			 notice under this section and a designated third party, including an owner or
			 licensee of the sensitive personally identifiable information subject to the
			 security breach, to provide the notifications required under subsection
			 (a).</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="idc264f9db-4ff6-414b-ada3-c8e3294c2ea2"><enum>(3)</enum><header display-inline="yes-display-inline">Business entity relieved from giving
			 notice</header><text display-inline="yes-display-inline">A business entity
			 obligated to give notice under subsection (a) shall be relieved of such
			 obligation if an owner or licensee of the sensitive personally identifiable
			 information subject to the security breach, or other designated third party,
			 provides such notification.</text>
						</paragraph><paragraph id="ID7e7f6d26dc8e4832bf150d83abd86619"><enum>(4)</enum><header>Service
			 providers</header><text>If a service provider becomes aware of a security
			 breach containing sensitive personally identifiable information that is owned
			 or possessed by another business entity that connects to or uses a system or
			 network provided by the service provider for the purpose of transmitting,
			 routing, or providing intermediate or transient storage of such data, the
			 service provider shall be required to notify the business entity who initiated
			 such connection, transmission, routing, or storage of the security breach if
			 the business entity can be reasonably identified. Upon receiving such
			 notification from a service provider, the business entity shall be required to
			 provide the notification required under subsection (a).</text>
						</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="ida34ef047-05ad-483f-ba06-c7a887b31b5a"><enum>(c)</enum><header display-inline="yes-display-inline">Timeliness of notification</header>
						<paragraph commented="no" display-inline="no-display-inline" id="idf80cff37-4ea8-4875-95ea-3d7ab8c41f98"><enum>(1)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">All notifications required under this
			 section shall be made without unreasonable delay following the discovery by the
			 agency or business entity of a security breach.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="idd257a145-74ea-4051-80b8-c111ad514f15"><enum>(2)</enum><header display-inline="yes-display-inline">Reasonable delay</header><text display-inline="yes-display-inline">Reasonable delay under this subsection may
			 include any time necessary to determine the scope of the security breach,
			 conduct the risk assessment described in section 212(b)(1), and provide notice
			 to law enforcement when required.</text>
						</paragraph><paragraph id="id7360002a-7e3c-498b-816a-9d57ad4573c5"><enum>(3)</enum><header>Burden of
			 production</header><text>The agency, business entity, owner, or licensee
			 required to provide notice under this subtitle shall, upon the request of the
			 Attorney General, the Federal Trade Commission, or the attorney general of a
			 State or any State or local law enforcement agency authorized by the attorney
			 general of the State or by State statute to prosecute violations of consumer
			 protection law, provide records or other evidence of the notifications required
			 under this subtitle, including to the extent applicable, the reasons for any
			 delay of notification.</text>
						</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="ida763129d-b46e-425f-93d8-a59974d93ea1"><enum>(d)</enum><header display-inline="yes-display-inline">Delay of notification authorized for law
			 enforcement or national security purposes</header>
						<paragraph id="ide75ea4d2-0eb5-4ec8-9af4-f4737739b26a"><enum>(1)</enum><header>In
			 general</header><text>If a Federal law enforcement agency or member of the
			 intelligence community determines that the notification required under this
			 section would impede any lawfully authorized criminal investigation or
			 authorized investigative, protective, or intelligence activities that are
			 carried out by or on behalf of any element of the intelligence community and
			 conducted in accordance with the United States laws, authorities, and
			 regulations governing such intelligence activities, such notification shall be
			 delayed upon written notice from such Federal law enforcement agency or member
			 of the intelligence community to the agency or business entity that experienced
			 the breach. The notification shall specify in writing the period of delay
			 required.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id31adfbcf-2149-4a92-92a1-66a4225093e2"><enum>(2)</enum><header display-inline="yes-display-inline">Extended delay of
			 notification</header><text display-inline="yes-display-inline">If the
			 notification required under subsection (a) is delayed pursuant to paragraph
			 (1), an agency or business entity shall give notice 30 days after the day such
			 law enforcement delay was invoked unless a Federal law enforcement or member of
			 the intelligence community provides written notification that further delay is
			 necessary.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id689e7596-75de-40d2-a6d1-0e0c8eacffb5"><enum>(3)</enum><header display-inline="yes-display-inline">Law enforcement immunity</header><text display-inline="yes-display-inline">No non-constitutional cause of action shall
			 lie in any court against an agency for acts relating to the delay of
			 notification for law enforcement or intelligence purposes under this
			 subtitle.</text>
						</paragraph></subsection></section><section commented="no" display-inline="no-display-inline" id="id68cccb79-7de6-44ab-a892-42e0118490b6" section-type="subsequent-section"><enum>212.</enum><header display-inline="yes-display-inline">Exemptions from notice to
			 individuals</header>
					<subsection commented="no" display-inline="no-display-inline" id="idc3070f1e-e18d-4156-99d6-cbf5e883df87"><enum>(a)</enum><header display-inline="yes-display-inline">Exemption for national security and law
			 enforcement</header>
						<paragraph commented="no" display-inline="no-display-inline" id="ide76c1b94-9fac-449d-82a2-91f7f5e1fdab"><enum>(1)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">Section 211 shall not apply to an agency or
			 business entity if—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="id7aaed83b-3025-42bb-8fb5-0f916f59904a"><enum>(A)</enum><text>the United States Secret
			 Service or the Federal Bureau of Investigation determines that notification of
			 the security breach could be expected to reveal sensitive sources and methods
			 or similarly impede the ability of the Government to conduct law enforcement
			 investigations; or</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id330f31e1-07d4-4a6f-bb5d-b56d1b34e46e"><enum>(B)</enum><text>the Federal Bureau of
			 Investigation determines that notification of the security breach could be
			 expected to cause damage to national security.</text>
							</subparagraph></paragraph><paragraph id="IDa952781137c04d38a95e241336fba5ff"><enum>(2)</enum><header>Immunity</header><text>No
			 non-constitutional cause of action shall lie in any court against any Federal
			 agency for acts relating to the exemption from notification under this
			 subtitle.</text>
						</paragraph></subsection><subsection commented="no" id="id65b55fc3-e577-4a63-bbc0-e5c646562899"><enum>(b)</enum><header>Safe harbor</header>
						<paragraph id="id3bc50223-3b77-440f-b708-90fdc4b6bc06"><enum>(1)</enum><header>In
			 general</header><text>An agency or business entity shall be exempt from the
			 notice requirements under section 211, if—</text>
							<subparagraph id="id2ca00ca1-3c58-477d-9795-af145ff4c555"><enum>(A)</enum><text>a risk assessment
			 conducted by the agency or business entity, in consultation with the Federal
			 Trade Commission, concludes that there is no significant risk that a security
			 breach has resulted in, or will result in harm to the individuals whose
			 sensitive personally identifiable information was subject to the security
			 breach; and</text>
							</subparagraph><subparagraph id="id260bdd27-583e-4f13-afa4-4a55944893ba"><enum>(B)</enum><text>the Federal Trade
			 Commission or designated entity does not indicate within 7 business days from
			 the receipt of written notification from an agency or business entity pursuant
			 to subsection 212 (b)(2), that the agency or business entity should not be
			 exempt from the notice requirements of section 211.</text>
							</subparagraph></paragraph><paragraph id="idb146e6d0-e5fb-4eb8-928f-3e5781c7d4fd"><enum>(2)</enum><header>Risk assessment
			 requirements</header>
							<subparagraph id="ida91bc0f6-6e1b-44e1-9b2b-2312b35db91f"><enum>(A)</enum><header>Conducting a risk
			 assessment</header><text>Upon discovery of a security breach of an agency or
			 business entity, the agency or business entity shall conduct a risk assessment
			 to determine if there is a significant risk that the security breach resulted
			 in, or will result in, harm to the individuals whose sensitive personally
			 identifiable information was subject to the security breach.</text>
								<clause id="id1b360b64-2e30-4ff9-854d-2ae032b58f7a"><enum>(i)</enum><header>Presumption of no
			 significant risk</header><text>It is presumed that there is no significant risk
			 that the security breach has resulted in, or will result in, harm to the
			 individuals whose sensitive personally identifiable data was subject to the
			 security breach, if the sensitive personally identifiable information has been
			 rendered unusable, unreadable, or indecipherable through a security technology
			 or methodology (if the technology or methodology is generally accepted by
			 experts in the information security field). Any such presumption may be
			 rebutted by facts demonstrating that the security technologies or methodologies
			 in a specific case, have been or are reasonably likely to be
			 compromised.</text>
								</clause><clause id="id52b7c02c-d7cf-4825-a4e9-886ab618350c"><enum>(ii)</enum><header>Presumption of
			 significant risk</header><text>It is presumed that there is a significant risk
			 that the security breach has resulted in, or will result in, harm to
			 individuals whose sensitive personally identifiable information was subject to
			 the security breach if the agency or business entity failed to render such
			 sensitive personally identifiable information indecipherable through a security
			 technology or methodology (if the technology or methodology is generally
			 accepted by experts in the information security field).</text>
								</clause><clause id="IDce5ecbd7e57f4001879b5605c0cfc800"><enum>(iii)</enum><header>Methodologies or
			 technologies</header>
									<subclause id="id585A583FB9AD43E9801D9864FA9AD7F9"><enum>(I)</enum><header>Required
			 rulemaking</header><text>Not later than 1 year after the date of the enactment
			 of this Act, and biannually thereafter, the Federal Trade Commission, after
			 consultation with the National Institute of Standards and Technology, shall
			 issue rules (pursuant to section 553 of title 5, United States Code) or
			 guidance to identify security methodologies or technologies, such as
			 encryption, which render sensitive personally identifiable information
			 unusable, unreadable, or indecipherable, that shall, if applied to such
			 sensitive personally identifiable information, establish a presumption that no
			 significant risk of harm exists to individuals whose sensitive personally
			 identifiable information was subject to a security breach. Any such presumption
			 may be rebutted by facts demonstrating that any such methodology or technology
			 in a specific case has been or is reasonably likely to be compromised.</text>
									</subclause><subclause id="id9DD6171F4F344E00B8A3B6E66E3E31FF"><enum>(II)</enum><header>Required
			 consultation</header><text>In issuing rules or guidance under subclause (II),
			 the Commission shall also consult with relevant industries, consumer
			 organizations, and data security and identity theft prevention experts and
			 established standards setting bodies.</text>
									</subclause></clause><clause id="IDe6fa4e45139a492d93a3791ad2febcf7"><enum>(iv)</enum><header>FTC
			 guidance</header><text>Not later than 1 year after the date of the enactment of
			 this Act, the Federal Trade Commission, after consultation with the National
			 Institute of Standards and Technology, shall issue guidance regarding the
			 application of the exemption in clause (i).</text>
								</clause></subparagraph><subparagraph id="id1589f6da-92d6-4984-a734-9e89f4c3a2b0"><enum>(B)</enum><header>Written
			 notification</header><text>Without unreasonable delay, but not later than 7
			 days after the discovery of a security breach, unless extended by the United
			 States Secret Service or the Federal Bureau of Investigation, the agency or
			 business entity must notify the Federal Trade Commission and designated entity,
			 in writing, of—</text>
								<clause id="id6b5b9b29-2f31-4860-afc0-ef4a96293f09"><enum>(i)</enum><text>the results of the risk
			 assessment; and</text>
								</clause><clause id="id016ee2c0-e1de-4a5a-a51c-af25dcd6ef32"><enum>(ii)</enum><text>its decision to invoke
			 the risk assessment exemption.</text>
								</clause></subparagraph><subparagraph id="ID79d88dc58d3843b7bbbfad37e40bb364"><enum>(C)</enum><header>Violations</header><text>It
			 shall be a violation of this section to—</text>
								<clause id="ID01527d2c1b634d7d950d4cfb5b4aee57"><enum>(i)</enum><text>fail to conduct a risk
			 assessment in a reasonable manner, or according to standards generally accepted
			 by experts in the field of information security; or</text>
								</clause><clause id="IDe11149f5629b438bac84805867cd7287"><enum>(ii)</enum><text>submit results of a risk
			 assessment that—</text>
									<subclause id="ID66634a5e275c4abdb5a88a5a38ea2b90"><enum>(I)</enum><text>conceal violations of
			 law, inefficiency, or administrative error;</text>
									</subclause><subclause id="ID4ddb2d7f6157423aab3fd327e8cdf814"><enum>(II)</enum><text>prevent embarrassment to
			 a business entity, organization, or agency;</text>
									</subclause><subclause id="IDd5a9d89397ff414e82027781761dcf8f"><enum>(III)</enum><text>restrain
			 competition;</text>
									</subclause><subclause id="ID688a4e263a304fa9ac7a3dce19d23a71"><enum>(IV)</enum><text>contain fraudulent or
			 deliberately misleading information; or</text>
									</subclause><subclause id="ID1dd9ca54959548a58f8b06c62a3737ee"><enum>(V)</enum><text>delay notification under
			 section 211 for any other reason, except where the agency or business entity
			 reasonably believes that the risk assessment exception may apply.</text>
									</subclause></clause></subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="id5991471a-eca0-4705-8b58-3eef67637e3a"><enum>(c)</enum><header display-inline="yes-display-inline">Financial fraud prevention
			 exemption</header>
						<paragraph commented="no" display-inline="no-display-inline" id="id673e7f25-9db5-435b-a492-0b617801738d"><enum>(1)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">A business entity shall be exempt from the
			 notice requirements of this subtitle if the business entity utilizes or
			 participates in a security program that—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="id0ca45208-377b-4931-8676-f66495e895d1"><enum>(A)</enum><text display-inline="yes-display-inline">effectively blocks the use of the sensitive
			 personally identifiable information to initiate unauthorized financial
			 transactions before they are charged to the account of the individual;
			 and</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id0917ba7c-7b94-42ec-83ba-1fcbcaf989b1"><enum>(B)</enum><text display-inline="yes-display-inline">provides for notice to affected individuals
			 after a security breach that has resulted in fraud or unauthorized
			 transactions.</text>
							</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id5b7a5a6f-5f0a-48d5-a66e-53c559152ee5"><enum>(2)</enum><header display-inline="yes-display-inline">Limitation</header><text display-inline="yes-display-inline">Paragraph (1) shall not apply to a business
			 entity if the information subject to the security breach includes an
			 individual's first and last name, or any other type of sensitive personally
			 identifiable information, other than a credit card or credit card security code
			 identified in section 3, unless that information is only a credit card number
			 or a credit card security code.</text>
						</paragraph></subsection><subsection id="IDd5cc9700cb5748efaba67872c3770579"><enum>(d)</enum><header>Limitations</header><text>Notwithstanding
			 any other obligation under this subtitle, this subtitle does not apply to the
			 following—</text>
						<paragraph id="ID1efa43382fa44a6a8aa93c5d8e1cd4a2"><enum>(1)</enum><header>Financial
			 institutions</header><text>A financial institution subject to the data security
			 requirements and standards under 501(b) of the Gramm-Leach-Bliley Act (15
			 U.S.C. 6801 et seq.), and subject to the jurisdiction of an agency or authority
			 described in section 505(a) of the Gramm-Leach-Bliley Act (15 U.S.C. 6805(a)),
			 if the Federal functional regulator (as defined by section 509 of the
			 Gramm-Leach-Bliley Act (15 U.S.C. 6809)) with jurisdiction over that financial
			 institution has issued a regulation under title V of the Gramm-Leach-Bliley Act
			 (15 U.S.C. 6801 et seq.) that requires financial institutions within its
			 jurisdiction to provide notification to individuals following a breach of
			 security.</text>
						</paragraph><paragraph id="ID04f90c152dce48abaaf45c07d5a39c06"><enum>(2)</enum><header>HIPAA regulated
			 entities exemption</header>
							<subparagraph id="IDe8b710e153b148668cee183f112e2493"><enum>(A)</enum><header>In
			 general</header><text>A business entity shall be exempt from the notice
			 requirement under section 211 if the business entity is one of the
			 following:</text>
								<clause id="IDc59010276c3f43a7ab42c989d6bfba98"><enum>(i)</enum><header>Covered
			 entities</header><text>A business entity subject to the Health Insurance
			 Portability and Accountability Act of 1996 (42 U.S.C. 1301 et seq.), including
			 the data breach notification requirements and implementing regulations of that
			 Act.</text>
								</clause><clause id="ID2b106378d4444505a8fce36c5cf3dcf2"><enum>(ii)</enum><header>Business
			 entities</header><text>A business entity that—</text>
									<subclause id="IDe48e6bce9fb7468782f451a7748a35f0"><enum>(I)</enum><text>is acting as a business
			 associate, as that term is defined under the Health Insurance Portability and
			 Accountability Act of 1996 (42 U.S.C. 1301 et seq.) and is in compliance with
			 the requirements imposed under that Act and implementing regulations
			 promulgated under that Act; and</text>
									</subclause><subclause id="ID458e546697be4ca6b1f405c8f63788b1"><enum>(II)</enum><text>is subject to, and
			 currently in compliance with, the data breach notification requirements under
			 section 13402 or 13407 of the American Reinvestment and Recovery Act of 2009
			 (42 U.S.C. 17932 and 17937) and implementing regulations promulgated under such
			 sections.</text>
									</subclause></clause></subparagraph><subparagraph id="ID03361592ad9848eeb7fddbc1edf115a7"><enum>(B)</enum><header>Limitation</header><text>Paragraph
			 (1) shall not apply to a business entity if the information subject to the
			 security breach includes an individual’s first and last name, or any other type
			 of sensitive personally identifiable information other than a health insurance
			 policy or subscriber identification number or information regarding an
			 individual’s medical history, mental or physical medical condition, or medical
			 treatment or diagnosis by a health care professional as identified in section 3
			 unless that information is only a health insurance policy or subscriber
			 identification number or information regarding an individual’s medical history,
			 mental or physical medical condition, or medical treatment or diagnosis by a
			 health care professional.</text>
							</subparagraph></paragraph></subsection></section><section commented="no" display-inline="no-display-inline" id="id627c793e-76c7-4f36-b718-5551a63edd34" section-type="subsequent-section"><enum>213.</enum><header display-inline="yes-display-inline">Methods of notice to
			 individuals</header><text display-inline="no-display-inline">To comply with
			 section 211, an agency or business entity shall provide the following forms of
			 notice:</text>
					<paragraph commented="no" display-inline="no-display-inline" id="id94a0e97e-6267-4eac-8dd3-d2633f9682d0"><enum>(1)</enum><header display-inline="yes-display-inline">Individual written notice</header><text display-inline="yes-display-inline">Written notice to individuals by 1 of the
			 following means:</text>
						<subparagraph commented="no" display-inline="no-display-inline" id="id55ff2f5c-71cf-4829-8bed-918ac1e6ca00"><enum>(A)</enum><text display-inline="yes-display-inline">Individual written notification to the last
			 known home mailing address of the individual in the records of the agency or
			 business entity.</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id58c6353d-a960-44f4-b392-dcc9895b933d"><enum>(B)</enum><text display-inline="yes-display-inline">E-mail notice, unless the individual has
			 expressly opted not to receive such notices of security breaches or the notice
			 is inconsistent with the provisions permitting electronic transmission of
			 notices under section 101 of the Electronic Signatures in Global and National
			 Commerce Act (15 U.S.C. 7001).</text>
						</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id62139ec0-3500-4b57-8914-ce9e2b775b11"><enum>(2)</enum><header>Telephone
			 notice</header><text>Telephone notice to the individual personally.</text>
					</paragraph><paragraph id="id05fe39b5-79cb-4319-bbf7-e6879feae17a"><enum>(3)</enum><header>Public notice</header>
						<subparagraph id="ida1e25c77-f227-41ca-86aa-8571de6ad2d3"><enum>(A)</enum><header>Electronic
			 notice</header><text>Prominent notice via all reasonable means of electronic
			 contact between the individual and the agency or business entity, including any
			 website, networked devices, or other interface through which the agency or
			 business entity regularly interacts with the consumer, if the number of
			 individuals whose sensitive personally identifiable information was or is
			 reasonably believed to have been accessed or acquired by an unauthorized person
			 exceeds 5,000.</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id5c891f5d-7003-4c7f-855b-22fd575eb9ba"><enum>(B)</enum><header display-inline="yes-display-inline">Media notice</header><text display-inline="yes-display-inline">Notice to major media outlets serving a
			 State or jurisdiction, if the number of residents of such State whose sensitive
			 personally identifiable information was, or is reasonably believed to have
			 been, accessed or acquired by an unauthorized person exceeds 5,000.</text>
						</subparagraph></paragraph></section><section commented="no" display-inline="no-display-inline" id="id57f709f4-e389-4f08-8e86-b5b23d80a681" section-type="subsequent-section"><enum>214.</enum><header display-inline="yes-display-inline">Content of notice to individuals</header>
					<subsection commented="no" display-inline="no-display-inline" id="id9deb8b37-b8b1-42e3-9225-002120406ed8"><enum>(a)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">Regardless of the method by which
			 individual notice is provided to individuals under section 213(1), such notice
			 shall include—</text>
						<paragraph commented="no" display-inline="no-display-inline" id="id62c0dc54-0e91-4df0-ba7c-f20692849820"><enum>(1)</enum><text display-inline="yes-display-inline">a description of the categories of
			 sensitive personally identifiable information that was, or is reasonably
			 believed to have been, accessed or acquired by an unauthorized person, and how
			 the agency or business entity came into possession of the sensitive personally
			 identifiable information at issue;</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id279e0a0a-3d1a-4516-88f6-25d1876faf9f"><enum>(2)</enum><text display-inline="yes-display-inline">a toll-free number—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="idcc215dd6-9c91-4c2f-9a4f-adf002ae7be7"><enum>(A)</enum><text display-inline="yes-display-inline">that the individual may use to contact the
			 agency or business entity, or the agent of the agency or business entity;
			 and</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id7713f3a3-68ac-494b-b00e-6646554a86a7"><enum>(B)</enum><text display-inline="yes-display-inline">from which the individual may learn what
			 types of sensitive personally identifiable information the agency or business
			 entity maintained about that individual;</text>
							</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id606aef14-8c16-425b-9d64-503c19d67c3a"><enum>(3)</enum><text display-inline="yes-display-inline">the toll-free contact telephone numbers,
			 websites, and addresses for the major credit reporting agencies;</text>
						</paragraph><paragraph id="idc41f2eb7-c639-4349-8454-d692e21ded10"><enum>(4)</enum><text>the telephone numbers and
			 websites for the relevant Federal agencies that provide information regarding
			 identity theft prevention and protection;</text>
						</paragraph><paragraph id="idd713956b-3565-4cf1-8934-ba483717657d"><enum>(5)</enum><text>notice that the
			 individual is entitled to receive, at no cost to such individual, consumer
			 credit reports on a quarterly basis for a period of 2 years, credit monitoring
			 or any other service that enables consumers to detect the misuse of sensitive
			 personally identifiable information for a period of 2 years, and instructions
			 to the individual on requesting such reports or service from the agency or
			 business entity;</text>
						</paragraph><paragraph id="id7705fafe-4002-4c08-914f-fa458923f8c5"><enum>(6)</enum><text>notice that the
			 individual is entitled to receive a security freeze and that the agency or
			 business entity will be liable for any costs associated with the security
			 freeze for 2 years and the necessary instructions for requesting a security
			 freeze; and</text>
						</paragraph><paragraph id="id157f05cd-e878-48d8-939a-5888c15607eb"><enum>(7)</enum><text>notice that any costs or
			 damages incurred by an individual as a result of a security breach will be paid
			 by the business entity or agency that experienced the security breach.</text>
						</paragraph></subsection><subsection id="id433f1cef-7275-4d05-a141-5d228734e9e3"><enum>(b)</enum><header>Telephone
			 notice</header><text>Telephone notice described in section 213(2) shall
			 include, to the extent possible—</text>
						<paragraph id="id370abca9-12b6-436f-9ca7-f3bd18868d06"><enum>(1)</enum><text>notification that a
			 security breach has occurred and that the individual’s sensitive personally
			 identifiable information may have been compromised;</text>
						</paragraph><paragraph id="id80d3da37-fbba-4079-9b69-669e8cccfaa8"><enum>(2)</enum><text>a description of the
			 categories of sensitive personally identifiable information that were, or are
			 reasonably believed to have been, accessed or acquired by an unauthorized
			 person;</text>
						</paragraph><paragraph id="id7b370a2d-8584-4872-8670-6b4dc519a93d"><enum>(3)</enum><text>a toll-free number and
			 website—</text>
							<subparagraph id="id112e232e-3503-4773-8ec5-07d81ffdaa28"><enum>(A)</enum><text>that the individual may
			 use to contact the agency or business entity, or the authorized agent of the
			 agency or business entity; and</text>
							</subparagraph><subparagraph id="id4101baa7-2895-441f-ab08-42572ef298a4"><enum>(B)</enum><text>from which the individual
			 may learn what types of sensitive personally identifiable information the
			 agency or business entity maintained about that individual and remedies
			 available to that individual; and</text>
							</subparagraph></paragraph><paragraph id="idd1014f50-9dd3-47d2-82b8-24138918e80a"><enum>(4)</enum><text>an alert to the
			 individual that the agency or business entity is sending or has sent written
			 notification containing additional information as required under section
			 213(1)(A).</text>
						</paragraph></subsection><subsection id="idd9cb91ad-e881-480d-9bf6-652d1c27b46e"><enum>(c)</enum><header>Public
			 notice</header><text>Public notice described in section 213(3) shall
			 include—</text>
						<paragraph id="id1d7e633a-22cf-4221-b254-7770602f7359"><enum>(1)</enum><text>electronic notice, which
			 includes—</text>
							<subparagraph id="id9d7c941c-9201-4f41-afb7-63029d098aa9"><enum>(A)</enum><text>notification that a
			 security breach has occurred and that the individual’s sensitive personally
			 identifiable information may have been compromised;</text>
							</subparagraph><subparagraph id="idf4174b01-a384-49e1-ab19-db59031b0154"><enum>(B)</enum><text>a description of the
			 categories of sensitive personally identifiable information that were, or are
			 reasonably believed to have been, accessed or acquired by an unauthorized
			 person; and</text>
							</subparagraph><subparagraph id="idb7c1b446-09e0-4416-8651-0af3ca83ca26"><enum>(C)</enum><text>a toll-free number and
			 website—</text>
								<clause id="id08c09f06-815b-4a2f-8c1b-8c89a48968dd"><enum>(i)</enum><text>that the individual may
			 use to contact the agency or business entity, or the authorized agent of the
			 agency or business entity; and</text>
								</clause><clause id="id97b7ab3c-11e4-40f9-8676-9681f3f2f277"><enum>(ii)</enum><text>from which the
			 individual may learn what types of sensitive personally identifiable
			 information the agency or business entity maintained about that individual and
			 remedies available to that individual;</text>
								</clause></subparagraph></paragraph><paragraph id="id270d003f-f619-4c26-8e13-13f8f98abbb5"><enum>(2)</enum><text>media notice, which
			 includes—</text>
							<subparagraph id="idf18e2499-7407-456c-b4b3-ab642a7ce287"><enum>(A)</enum><text>a description of the
			 categories of sensitive personally identifiable information that was, or is
			 reasonably believed to have been, accessed or acquired by an unauthorized
			 person;</text>
							</subparagraph><subparagraph id="id1838f8f0-a8b3-4b2e-b408-2c418f8e1e13"><enum>(B)</enum><text>a toll-free
			 number—</text>
								<clause id="id59be9f0e-0c65-4230-90cd-5292948557e9"><enum>(i)</enum><text>that the individual may
			 use to contact the agency or business entity, or the authorized agent of the
			 agency or business entity; and</text>
								</clause><clause id="id7385a9c8-6eb0-46fd-b37c-60692f2d2fbf"><enum>(ii)</enum><text>from which the
			 individual may learn what types of sensitive personally identifiable
			 information the agency or business entity maintained about that individual and
			 remedies available to that individual;</text>
								</clause></subparagraph><subparagraph id="id9e889f13-cd4e-4a59-93eb-2514a9019e7d"><enum>(C)</enum><text>the toll-free contact
			 telephone numbers, websites, and addresses for the major credit reporting
			 agencies;</text>
							</subparagraph><subparagraph id="idf8e52a16-abad-4daf-86b0-178a5690e0d1"><enum>(D)</enum><text>the telephone numbers and
			 websites for the relevant Federal agencies that provide information regarding
			 identity theft prevention and protection;</text>
							</subparagraph><subparagraph id="id7446e96c-755c-4e4a-894c-6e9e1cf21797"><enum>(E)</enum><text>notice that the affected
			 individuals are entitled to receive, at no cost to such individuals, consumer
			 credit reports on a quarterly basis for a period of 2 years, credit monitoring,
			 or any other service that enables consumers to detect the misuse of sensitive
			 personally identifiable information for a period of 2 years;</text>
							</subparagraph><subparagraph id="id946292c7-16ed-4cb8-bf9a-5a6b2d8fb495"><enum>(F)</enum><text>notice that the
			 individual is entitled to receive a security freeze and that the agency or
			 business entity will be liable for any costs associated with the security
			 freeze for 2 years; and</text>
							</subparagraph><subparagraph id="idb59eb563-7bab-4902-b79e-2069bdc325d9"><enum>(G)</enum><text>notice that the
			 individual is entitled to receive compensation from the business entity or
			 agency for any costs or damages incurred by the individual resulting from the
			 security breach.</text>
							</subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="iddfa9d149-02e2-4904-afae-207ca8a01c4d"><enum>(d)</enum><header display-inline="yes-display-inline">Additional content</header><text display-inline="yes-display-inline">Notwithstanding section 221, a State may
			 require that a notice under subsection (a) shall also include information
			 regarding victim protection assistance provided for by that State.</text>
					</subsection><subsection id="ID8ccf29f0ab294984b718957f56beaad5"><enum>(e)</enum><header>Direct business
			 relationship</header><text>Regardless of whether a business entity, agency, or
			 a designated third party provides the notice required pursuant to section
			 211(b), such notice shall include the name of the business entity or agency
			 that has a direct relationship with the individual being notified.</text>
					</subsection></section><section id="iddb6eb31b-07d1-4cd7-9e5e-059f27eb227a"><enum>215.</enum><header>Remedies for security
			 breach</header>
					<subsection id="idf88df8c3-1e1e-4a0f-9712-76f307d0721f"><enum>(a)</enum><header>Credit reports and
			 credit monitoring</header><text>An agency or business entity required to
			 provide notification under this subtitle shall, upon request of an individual
			 whose sensitive personally identifiable information was included in the
			 security breach, provide or arrange for the provision of, to each such
			 individual and at no cost to such individual—</text>
						<paragraph id="id4d5cb167-0d2e-4db4-9e5b-260731245bb1"><enum>(1)</enum><text>consumer credit reports
			 from not fewer than 1 of the major credit reporting agencies beginning not
			 later than 60 days following the request of the individual and continuing on a
			 quarterly basis for a period of 2 years thereafter; and</text>
						</paragraph><paragraph id="id7dcbab57-9031-487a-856b-83553666c689"><enum>(2)</enum><text>a credit monitoring or
			 other service that enables consumers to detect the misuse of their personal
			 information, beginning not later than 60 days following the request of the
			 individual and continuing for a period of 2 years.</text>
						</paragraph></subsection><subsection id="id1cad4ed9-5692-4553-886e-01694216b474"><enum>(b)</enum><header>Security
			 freeze</header>
						<paragraph id="id7e893c92-d218-4317-8997-90488757054c"><enum>(1)</enum><header>Request</header><text>Any
			 consumer may submit a written request, by certified mail or such other secure
			 method as authorized by a credit rating agency, to a credit rating agency to
			 place a security freeze on the credit report of the consumer.</text>
						</paragraph><paragraph id="id2519e636-ad3c-4c11-afb8-79f5b25a48f2"><enum>(2)</enum><header>Implementation of
			 security freeze</header><text>Upon receipt of a written request under paragraph
			 (1), a credit rating agency shall—</text>
							<subparagraph id="id7ba838d5-57b8-4c12-8670-498a48cef11d"><enum>(A)</enum><text>not later than 5 business
			 days after receipt of the request, place a security freeze on the credit report
			 of the consumer; and</text>
							</subparagraph><subparagraph id="ide787734f-4db5-415b-a51a-426a51acdf9d"><enum>(B)</enum><text>not later than 10
			 business days after placing a security freeze, send a written confirmation of
			 such security freeze to the consumer, which shall provide the consumer with a
			 unique personal identification number or password to be used by the consumer
			 when providing authorization for the release of the credit report of the
			 consumer to a third party or for a specified period of time.</text>
							</subparagraph></paragraph><paragraph id="idc019c1ce-299d-452f-a26a-662555008bbf"><enum>(3)</enum><header>Duration of security
			 freeze</header><text>Except as provided in paragraph (4), any security freeze
			 authorized pursuant to the provisions of this section shall remain in effect
			 until the consumer requests security freeze to be removed.</text>
						</paragraph><paragraph id="id66b231c9-da8f-462f-be3a-374e65a52eea"><enum>(4)</enum><header>Disclosure of credit
			 report to third party</header>
							<subparagraph id="id23efd1b5-1420-4e41-b1cb-985794c7e9b1"><enum>(A)</enum><header>In
			 general</header><text>If a consumer that has requested a security freeze under
			 this subsection wishes to authorize the disclosure of the credit report of the
			 consumer to a third party, or for a specified period of time, while such
			 security freeze is in effect, the consumer shall contact the credit rating
			 agency and provide—</text>
								<clause id="id8c5af3f0-9f7a-4850-bb2f-731210591b9b"><enum>(i)</enum><text>proper
			 identification;</text>
								</clause><clause id="id905f1cfd-2b7b-4c60-852f-90709277ee40"><enum>(ii)</enum><text>the unique personal
			 identification number or password described in paragraph (2)(B); and</text>
								</clause><clause id="idf6b1e273-1fb7-48f6-8193-5c4876f2246e"><enum>(iii)</enum><text>proper information
			 regarding the third party who is to receive the credit report or the time
			 period for which the credit report shall be available.</text>
								</clause></subparagraph><subparagraph id="id97b5a3bb-58e7-43d0-a4a3-39f63ceb6cef"><enum>(B)</enum><header>Requirement</header><text>Not
			 later than 3 business days after receipt of a request under subparagraph (A), a
			 credit rating agency shall lift the security freeze.</text>
							</subparagraph></paragraph><paragraph id="id3a591715-7a6a-499f-9aab-7135b8519281"><enum>(5)</enum><header>Procedures</header>
							<subparagraph id="id3552ed83-33d4-4a0c-98e1-32395ed98c39"><enum>(A)</enum><header>In
			 general</header><text>A credit rating agency shall develop procedures to
			 receive and process requests from consumers under paragraph (2) of this
			 section.</text>
							</subparagraph><subparagraph id="id515b1932-0f46-40b9-900d-0163e14cd7e2"><enum>(B)</enum><header>Requirement</header><text>Procedures
			 developed under subparagraph (A), at a minimum, shall include the ability of a
			 consumer to send such temporary lift or removal request by electronic mail,
			 letter, telephone, or facsimile.</text>
							</subparagraph></paragraph><paragraph id="id23256124-e114-4cc3-a864-bd1c4c7d3cf2"><enum>(6)</enum><header>Requests by third
			 party</header><text>If a third party requests access to a credit report of a
			 consumer that has been frozen under this subsection and the consumer has not
			 authorized the disclosure of the credit report of the consumer to the third
			 party, the third party may deem such credit application as incomplete.</text>
						</paragraph><paragraph id="idc858cc8d-583a-460b-a776-409b73ac1256"><enum>(7)</enum><header>Determination by credit
			 rating agency</header>
							<subparagraph id="idd8297afb-1e1f-4858-813c-6e691823e488"><enum>(A)</enum><header>In
			 general</header><text>A credit rating agency may refuse to implement or may
			 remove a security freeze under this subsection if the agency determines, in
			 good faith, that—</text>
								<clause id="id083f7297-2123-46a8-ad5a-b9019c4483d4"><enum>(i)</enum><text>the request for a
			 security freeze was made as part of a fraud that the consumer participated in,
			 had knowledge of, or that can be demonstrated by circumstantial evidence;
			 or</text>
								</clause><clause id="id59f096b5-7cd4-4499-a742-4807794852a1"><enum>(ii)</enum><text>the consumer credit
			 report was frozen due to a material misrepresentation of fact by the
			 consumer.</text>
								</clause></subparagraph><subparagraph id="id7939ac31-ec30-41f2-b15f-26fb250199ca"><enum>(B)</enum><header>Notice</header><text>If
			 a credit rating agency makes a determination under subparagraph (A) to not
			 implement, or to remove, a security freeze under this subsection, the credit
			 rating agency shall notify the consumer in writing of such
			 determination—</text>
								<clause id="idee75c3a0-5d4c-4c84-99f2-0629ca35504b"><enum>(i)</enum><text>in the case of a
			 determination not to implement a security freeze, not later than 5 business
			 days after the determination is made; and</text>
								</clause><clause id="id516f9fcf-ffad-45a0-97d9-d7997e2905ee"><enum>(ii)</enum><text>in the case of a removal
			 of a security freeze, prior to removing the freeze on the credit report of the
			 consumer.</text>
								</clause></subparagraph></paragraph><paragraph id="ide2cad4be-9e29-4929-9234-6e38049682b5"><enum>(8)</enum><header>Rule of
			 construction</header><text>Nothing in this section shall be construed to
			 prohibit disclosure of a credit report of a consumer to—</text>
							<subparagraph id="id1d5215fc-6541-4ab3-a3d9-f4fc37e2df5d"><enum>(A)</enum><text>a person, or the person's
			 subsidiary, affiliate, agent or assignee with which the consumer has or, prior
			 to assignment, had an account, contract or debtor-creditor relationship for the
			 purpose of reviewing the account or collecting the financial obligation owing
			 for the account, contract or debt;</text>
							</subparagraph><subparagraph id="id264758ac-2b6d-468b-b8b6-de0383134206"><enum>(B)</enum><text>a subsidiary, affiliate,
			 agent, assignee or prospective assignee of a person to whom access has been
			 granted under paragraph (4) for the purpose of facilitating the extension of
			 credit or other permissible use;</text>
							</subparagraph><subparagraph id="id27cbd74a-a34c-4548-9435-d8c270b00894"><enum>(C)</enum><text>any person acting
			 pursuant to a court order, warrant or subpoena;</text>
							</subparagraph><subparagraph id="id5326c2a4-952f-4504-86e6-a530265b824d"><enum>(D)</enum><text>any person for the
			 purpose of using such credit information to prescreen as provided by the Fair
			 Credit Reporting Act (15 U.S.C. 1681 et seq.);</text>
							</subparagraph><subparagraph id="id6b19d7e1-e331-4926-a29e-e8b604fbea23"><enum>(E)</enum><text>any person for the sole
			 purpose of providing a credit file monitoring subscription service to which the
			 consumer has subscribed;</text>
							</subparagraph><subparagraph id="ida870f2e1-34e1-4f56-b729-7e4a1b98168b"><enum>(F)</enum><text>a credit rating agency
			 for the sole purpose of providing a consumer with a copy of the credit report
			 of the consumer upon the request of the consumer; or</text>
							</subparagraph><subparagraph id="id7b15cf6e-3bfc-475a-a692-a69da5717a54"><enum>(G)</enum><text>a Federal, State or local
			 governmental entity, including a law enforcement agency, or court, or their
			 agents or assignees pursuant to their statutory or regulatory duties. For
			 purposes of this subsection, <quote>reviewing the account</quote> includes
			 activities related to account maintenance, monitoring, credit line increases
			 and account upgrades and enhancements; and</text>
							</subparagraph><subparagraph commented="no" id="id83e61d28-1c6e-4465-949a-0762aa1c1132"><enum>(H)</enum><text>any person for the sole
			 purpose of providing a remedy requested by an individual under this
			 section.</text>
							</subparagraph></paragraph><paragraph id="id666c7f11-78db-4b0e-b0fb-5026a31c3730"><enum>(9)</enum><header>Exceptions</header><text>The
			 following persons shall not be required to place a security freeze under this
			 subsection, but shall be subject to any security freeze placed on a credit
			 report by another credit rating agency:</text>
							<subparagraph id="idf3ea92df-c5e9-493f-a05a-ac7b7e2fcd5e"><enum>(A)</enum><text>A check services or fraud
			 prevention services company that reports on incidents of fraud or issues
			 authorizations for the purpose of approving or processing negotiable
			 instruments, electronic fund transfers or similar methods of payment.</text>
							</subparagraph><subparagraph id="id96601caf-1738-4c04-984b-f92bf475040e"><enum>(B)</enum><text>A deposit account
			 information service company that issues reports regarding account closures due
			 to fraud, substantial overdrafts, automated teller machine abuse, or similar
			 information regarding a consumer to inquiring banks or other financial
			 institutions for use only in reviewing a consumer request for a deposit account
			 at the inquiring bank or financial institution.</text>
							</subparagraph><subparagraph id="idacc1f7c2-78ce-4fcf-b2bd-8bcbfb377b0f"><enum>(C)</enum><text>A credit rating agency
			 that—</text>
								<clause id="id7b021ed9-93da-4960-9462-c46b94d787ee"><enum>(i)</enum><text>acts only to resell
			 credit information by assembling and merging information contained in a
			 database of 1 or more credit reporting agencies; and</text>
								</clause><clause id="idc5e51eb6-2788-48cb-9222-bcd40d88ec59"><enum>(ii)</enum><text>does not maintain a
			 permanent database of credit information from which new credit reports are
			 produced.</text>
								</clause></subparagraph></paragraph><paragraph id="ide4de7f1b-41e8-4765-b94b-fa4ab2379b8e"><enum>(10)</enum><header>Fees</header>
							<subparagraph id="id4cc8f417-c9e4-46d6-bee7-4c64676bb244"><enum>(A)</enum><header>In
			 general</header><text>A credit rating agency may charge reasonable fees for
			 each security freeze, removal of such freeze or temporary lift of such freeze
			 for a period of time, and a temporary lift of such freeze for a specific
			 party.</text>
							</subparagraph><subparagraph id="id58b50d4c-c1ca-4b4c-b69f-12987db76137"><enum>(B)</enum><header>Requirement</header><text>Any
			 fees charged under subparagraph (A) shall be borne by the agency or business
			 entity providing notice under section 214 for 2 years following the
			 establishment of the security freeze under this subsection.</text>
							</subparagraph></paragraph></subsection><subsection id="id74b5469f-98ff-4432-96ce-e60768a268b4"><enum>(c)</enum><header>Costs resulting from a
			 security breach</header>
						<paragraph id="id34c0679c-b954-4ebc-b5bd-d5815e12bbb5"><enum>(1)</enum><header>In
			 general</header><text>A business entity or agency that experiences a security
			 breach and is required to provide notice under this subtitle shall pay, upon
			 request, to any individual whose sensitive personally identifiable information
			 has been, or is reasonably believed to have been, accessed or acquired as a
			 result of such security breach, any costs or damages incurred by the individual
			 as a result of such security breach, including costs associated with identity
			 theft suffered as a result of such security breach.</text>
						</paragraph><paragraph id="id184f9e9e-bc45-4d98-873d-8018d917e019"><enum>(2)</enum><header>Compliance</header><text>A
			 business entity or agency shall be deemed in compliance with this subsection if
			 the business entity or agency—</text>
							<subparagraph id="idd5d138c4-4d9c-4f16-8638-8a4ee6abc2bc"><enum>(A)</enum><text>provides insurance to any
			 individual whose sensitive personally identifiable information has been, or is
			 reasonably believed to have been, accessed or acquired as a result of a
			 security breach and such insurance is sufficient to compensate the consumer for
			 not less than $25,000 of costs or damages; or</text>
							</subparagraph><subparagraph id="idcf0d6f97-b02e-43f8-90ee-e17efc6b0134"><enum>(B)</enum><text>pays, without
			 unreasonable delay, any actual costs or damages incurred by an individual as a
			 result of the security breach.</text>
							</subparagraph></paragraph></subsection></section><section commented="no" display-inline="no-display-inline" id="idb19e16fa-c1ee-4ff1-b670-53cae2a23a54" section-type="subsequent-section"><enum>216.</enum><header display-inline="yes-display-inline">Notice to credit reporting
			 agencies</header><text display-inline="no-display-inline">If an agency or
			 business entity is required to provide notification to more than 5,000
			 individuals under section 211(a), the agency or business entity shall also
			 notify all consumer reporting agencies that compile and maintain files on
			 consumers on a nationwide basis (as defined in section 603(p) of the Fair
			 Credit Reporting Act (15 U.S.C. 1681a(p)) of the timing and distribution of the
			 notices. Such notice shall be given to the consumer credit reporting agencies
			 without unreasonable delay and, if it will not delay notice to the affected
			 individuals, prior to the distribution of notices to the affected
			 individuals.</text>
				</section><section commented="no" display-inline="no-display-inline" id="idd662a039-6c3c-4602-8783-e03607c259ff" section-type="subsequent-section"><enum>217.</enum><header display-inline="yes-display-inline">Notice to law enforcement</header>
					<subsection id="IDd3152be81443482e9746258d6135d40d"><enum>(a)</enum><header>Designation of a
			 government entity to receive notice</header>
						<paragraph id="ID195026c47def4a68981831f7153715fa"><enum>(1)</enum><header>In
			 general</header><text>Not later than 60 days after the date of enactment of
			 this Act, the Secretary of Homeland Security, in consultation with the Attorney
			 General, shall designate a Federal Government entity to receive the information
			 required to be submitted under this subtitle, and any other reports and
			 information about information security incidents, threats, and
			 vulnerabilities.</text>
						</paragraph><paragraph id="IDfa51c6bfbdbd49e39a0d53e9436068a2"><enum>(2)</enum><header>Responsibilities of the
			 designated entity</header><text>The designated entity shall—</text>
							<subparagraph id="IDdc215a0d355348049be0cdee940d64ea"><enum>(A)</enum><text>be responsible for
			 promptly providing the information it receives to the United States Secret
			 Service and the Federal Bureau of Investigation, and to the Federal Trade
			 Commission for civil law enforcement purposes; and</text>
							</subparagraph><subparagraph id="ID9d421ea9468c42a69401807467a8ec47"><enum>(B)</enum><text>provide the information
			 described in subparagraph (A) as appropriate to other Federal agencies for law
			 enforcement, national security, or data security purposes.</text>
							</subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="idf2874d84-415c-4e85-bb64-c9f79f3f1cd7"><enum>(b)</enum><header display-inline="yes-display-inline">Notice</header><text display-inline="yes-display-inline">Any business entity or agency shall notify
			 the designated entity of the fact that a security breach has occurred
			 if—</text>
						<paragraph commented="no" display-inline="no-display-inline" id="idfde68825-dca1-4017-83a8-ef95aa727436"><enum>(1)</enum><text display-inline="yes-display-inline">the number of individuals whose sensitive
			 personally identifiable information was, or is reasonably believed to have
			 been, accessed or acquired by an unauthorized person exceeds 5,000;</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="idede05a51-833a-4691-b542-60d7b0d3f50e"><enum>(2)</enum><text display-inline="yes-display-inline">the security breach involves a database,
			 networked or integrated databases, or other data system containing the
			 sensitive personally identifiable information of more than 500,000 individuals
			 nationwide;</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="idbcd5f313-1798-431b-841c-07ba39505f5f"><enum>(3)</enum><text display-inline="yes-display-inline">the security breach involves databases
			 owned by the Federal Government; or</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id53db33df-f06f-4ade-baa4-1cc118c89adb"><enum>(4)</enum><text display-inline="yes-display-inline">the security breach involves primarily
			 sensitive personally identifiable information of individuals known to the
			 agency or business entity to be employees and contractors of the Federal
			 Government involved in national security or law enforcement.</text>
						</paragraph></subsection><subsection id="id4fd35f19-89d4-44db-aa35-946a710bb896"><enum>(c)</enum><header>FTC review of
			 thresholds</header>
						<paragraph id="id47F7B3DCA8C34683AC64228AAA89AEEE"><enum>(1)</enum><header>Review</header><text>Not
			 later than 1 year after the date of enactment of this Act, the Federal Trade
			 Commission, in consultation with the Attorney General and the Secretary of
			 Homeland Security, shall promulgate regulations regarding the reports required
			 under subsection (a).</text>
						</paragraph><paragraph id="idE7E3E33D13C748DBA4FE22EE81F99EA7"><enum>(2)</enum><header>Rulemaking</header><text>The
			 Federal Trade Commission, in consultation with the Attorney General and the
			 Secretary of Homeland Security, after notice and the opportunity for public
			 comment, and in a manner consistent with this section, shall promulgate
			 regulations, as necessary, under section 553 of title 5, United States Code, to
			 adjust the thresholds for notice to law enforcement and national security
			 authorities under subsection (a) and to facilitate the purposes of this
			 section.</text>
						</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="id1ac95cca-0d17-4a45-ab7b-2145f0a9e3dc"><enum>(d)</enum><header display-inline="yes-display-inline">Timing of notices</header><text display-inline="yes-display-inline">The notices required under this section
			 shall be delivered as follows:</text>
						<paragraph commented="no" display-inline="no-display-inline" id="id7c68e6c6-47c3-43bd-b820-83b12adb7f6b"><enum>(1)</enum><text display-inline="yes-display-inline">Notice under subsection (a) shall be
			 delivered as promptly as possible, but not later than 10 days after discovery
			 of the security breach.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id08e89dca-ac91-464b-8440-cf3e7781c15c"><enum>(2)</enum><text display-inline="yes-display-inline">Notice under section 211 shall be delivered
			 to individuals not later than 48 hours after the Federal Bureau of
			 Investigation or the Secret Service receives notice of a security breach from
			 an agency or business entity.</text>
						</paragraph></subsection></section><section commented="no" display-inline="no-display-inline" id="id9566de15-3344-4a53-b310-6bdd7f247ddd" section-type="subsequent-section"><enum>218.</enum><header display-inline="yes-display-inline">Federal enforcement</header>
					<subsection commented="no" display-inline="no-display-inline" id="ida77eca54-ca88-4ba5-accd-be55747fd67b"><enum>(a)</enum><header display-inline="yes-display-inline">Civil actions by the Attorney
			 General</header>
						<paragraph commented="no" display-inline="no-display-inline" id="id725cf712-1717-4f62-bb41-f0dfdfb70d58"><enum>(1)</enum><header>In
			 general</header><text display-inline="yes-display-inline">The Attorney General
			 may bring a civil action in the appropriate United States district court
			 against any business entity that engages in conduct constituting a violation of
			 this subtitle and, upon proof of such conduct by a preponderance of the
			 evidence, such business entity shall be subject to a civil penalty of not more
			 than $500 per day per individual whose sensitive personally identifiable
			 information was, or is reasonably believed to have been, accessed or acquired
			 by an unauthorized person, up to a maximum of $20,000,000 per violation, unless
			 such conduct is found to be willful or intentional.</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id2fc6117c-b1b4-416c-bd24-ddc6f10ba7f7"><enum>(2)</enum><header>Presumption</header><text display-inline="yes-display-inline">A violation of section 212(b)(2)(C) shall
			 be presumed to be willful or intentional conduct.</text>
						</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="idbcb88e1f-210f-49cb-baa2-6b04be9fed0e"><enum>(b)</enum><header display-inline="yes-display-inline">Injunctive actions by the Attorney
			 General</header>
						<paragraph commented="no" display-inline="no-display-inline" id="idd1a3c509-09bb-47e0-8a66-7e8f290ed158"><enum>(1)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">If it appears that a business entity has
			 engaged, or is engaged, in any act or practice constituting a violation of this
			 subtitle, the Attorney General may petition an appropriate district court of
			 the United States for an order—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="idad5dde80-b3cc-4fe3-b097-4f3c2798b9bf"><enum>(A)</enum><text display-inline="yes-display-inline">enjoining such act or practice; or</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ide7fe2994-183d-4c88-a540-a78b631d3752"><enum>(B)</enum><text display-inline="yes-display-inline">enforcing compliance with this
			 subtitle.</text>
							</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id568158d4-1aff-45b1-9418-e5ff04b760f1"><enum>(2)</enum><header display-inline="yes-display-inline">Issuance of order</header><text display-inline="yes-display-inline">A court may issue an order under paragraph
			 (1), if the court finds that the conduct in question constitutes a violation of
			 this subtitle.</text>
						</paragraph></subsection><subsection id="ID3df9f5473da04dbfa73417f3d575c354"><enum>(c)</enum><header>Civil actions by the
			 Federal trade commission</header>
						<paragraph id="ID706453226d854e229a3b4836bdb33448"><enum>(1)</enum><header>In
			 general</header><text>Compliance with the requirements imposed under this
			 subtitle may be enforced under the Federal Trade Commission Act (15 U.S.C. 41
			 et seq.) by the Federal Trade Commission with respect to business entities
			 subject to this Act. All of the functions and powers of the Federal Trade
			 Commission under the Federal Trade Commission Act are available to the
			 Commission to enforce compliance by any person with the requirements imposed
			 under this title.</text>
						</paragraph><paragraph id="ID4c74632a3e1845b9b3c02ca1ce915d43"><enum>(2)</enum><header>Unfair or deceptive
			 acts or practices</header><text>For the purpose of the exercise by the Federal
			 Trade Commission of its functions and powers under the Federal Trade Commission
			 Act, a violation of any requirement or prohibition imposed under this title
			 shall constitute an unfair or deceptive act or practice in commerce in
			 violation of a regulation under section 18(a)(1)(B) of the Federal Trade
			 Commission Act (15 U.S.C. 57a(a)(I)(B)) regarding unfair or deceptive acts or
			 practices and shall be subject to enforcement by the Federal Trade Commission
			 under that Act with respect to any business entity, irrespective of whether
			 that business entity is engaged in commerce or meets any other jurisdictional
			 tests in the Federal Trade Commission.</text>
						</paragraph></subsection><subsection id="IDb8b98ca1749a47379bcad4f9c2d8cbe7"><enum>(d)</enum><header>Considerations</header><text>In
			 determining the amount of a civil penalty under this subsection, the court
			 shall take into account—</text>
						<paragraph id="ID796ad64cddd04ec69d4e3ea3ce065f20"><enum>(1)</enum><text>the degree of culpability
			 of the business entity;</text>
						</paragraph><paragraph id="ID4d0cb63b9f7749debf0219692290f468"><enum>(2)</enum><text>any prior violations of
			 this subtitle by the business entity;</text>
						</paragraph><paragraph id="IDa5ee840465ae425197531da01f158f2f"><enum>(3)</enum><text>the ability of the
			 business entity to pay a civil penalty;</text>
						</paragraph><paragraph id="ID84f500aa76704f8bb2b16cd23e88f75f"><enum>(4)</enum><text>the effect on the ability
			 of the business entity to continue to do business;</text>
						</paragraph><paragraph id="ID69f05f7f232048ff93d7a59a0c5616bb"><enum>(5)</enum><text>the number of individuals
			 whose sensitive personally identifiable information was compromised by the
			 breach;</text>
						</paragraph><paragraph id="IDd9896ac55e524b1aaf28b7321a08c593"><enum>(6)</enum><text>the relative cost of
			 compliance with this subtitle; and</text>
						</paragraph><paragraph id="ID496dac7e82924754a4ac3815f1f8bf3d"><enum>(7)</enum><text>such other matters as
			 justice may require.</text>
						</paragraph></subsection><subsection id="ID6cddd2b5b43e49aab8f9d050aadbb4e7"><enum>(e)</enum><header>Coordination of
			 enforcement</header>
						<paragraph id="IDd97190d3f0f94476aade87d06f106e09"><enum>(1)</enum><header>In
			 general</header><text>Before opening an investigation, the Federal Trade
			 Commission shall consult with the Attorney General.</text>
						</paragraph><paragraph id="ID9ce3fc92e7854730804bee66e925e4f2"><enum>(2)</enum><header>Limitation</header><text>The
			 Federal Trade Commission may initiate investigations under this subsection
			 unless the Attorney General determines that such an investigation would impede
			 an ongoing criminal investigation or national security activity.</text>
						</paragraph><paragraph id="IDd47ff5f8f10e46258b95de9ef9c5eead"><enum>(3)</enum><header>Coordination
			 agreement</header>
							<subparagraph id="ID3a4ae5878d764bd5a0313a47e083302c"><enum>(A)</enum><header>In
			 general</header><text>In order to avoid conflicts and promote consistency
			 regarding the enforcement and litigation of matters under this Act, not later
			 than 180 days after the enactment of this Act, the Attorney General and the
			 Commission shall enter into an agreement for coordination regarding the
			 enforcement of this Act.</text>
							</subparagraph><subparagraph id="ID11e97404cdfa420aa5ddc1ec3a6bcb21"><enum>(B)</enum><header>Requirement</header><text>The
			 coordination agreement entered into under subparagraph (A) shall include
			 provisions to ensure that parallel investigations and proceedings under this
			 section are conducted in a manner that avoids conflicts and does not impede the
			 ability of the Attorney General to prosecute violations of Federal criminal
			 laws.</text>
							</subparagraph></paragraph><paragraph id="ID825f89761a4c44cc8f7dfc55c1810a39"><enum>(4)</enum><header>Coordination with the
			 FCC</header><text>If an enforcement action under this Act relates to customer
			 proprietary network information, the Federal Trade Commission shall coordinate
			 the enforcement action with the Federal Communications Commission.</text>
						</paragraph></subsection><subsection id="ID96f0549aa4154c7092e54bd80735a7ea"><enum>(f)</enum><header>Rulemaking</header><text>The
			 Federal Trade Commission may, in consultation with the Attorney General, issue
			 such other regulations as it determines to be necessary to carry out this
			 subtitle. All regulations promulgated under this Act shall be issued in
			 accordance with section 553 of title 5, United States Code. Where regulations
			 relate to customer proprietary network information, the promulgation of such
			 regulations will be coordinated with the Federal Communications
			 Commission.</text>
					</subsection><subsection commented="no" display-inline="no-display-inline" id="id31ffc9d4-0c9e-4185-87dc-0d3c218739ec"><enum>(g)</enum><header display-inline="yes-display-inline">Other rights and remedies</header><text display-inline="yes-display-inline">The rights and remedies available under
			 this subtitle are cumulative and shall not affect any other rights and remedies
			 available under law.</text>
					</subsection><subsection commented="no" display-inline="no-display-inline" id="id3e252825-5fdd-4a5f-b093-72776c7bb2a4"><enum>(h)</enum><header display-inline="yes-display-inline">Fraud alert</header><text display-inline="yes-display-inline">Section 605A(b)(1) of the Fair Credit
			 Reporting Act (15 U.S.C. 1681c–1(b)(1)) is amended by inserting <quote>, or
			 evidence that the consumer has received notice that the consumer's financial
			 information has or may have been compromised,</quote> after <quote>identity
			 theft report</quote>.</text>
					</subsection></section><section commented="no" display-inline="no-display-inline" id="id303db9fe-d234-43bb-b852-bc14029b41fc" section-type="subsequent-section"><enum>219.</enum><header display-inline="yes-display-inline">Enforcement by State attorneys
			 general</header>
					<subsection commented="no" display-inline="no-display-inline" id="id8e2e62e4-2afc-4a29-9c5c-3ae235a9a453"><enum>(a)</enum><header display-inline="yes-display-inline">In general</header>
						<paragraph commented="no" display-inline="no-display-inline" id="id52d6e4c6-d05c-432e-8d05-882d80250a68"><enum>(1)</enum><header display-inline="yes-display-inline">Civil actions</header>
							<subparagraph commented="no" display-inline="no-display-inline" id="id9031ed04-cedc-4b27-b749-f9d04f98785a"><enum>(A)</enum><header>In
			 general</header><text display-inline="yes-display-inline">In any case in which
			 the attorney general of a State or any State or local law enforcement agency
			 authorized by the State attorney general or by State statute to prosecute
			 violations of consumer protection law, has reason to believe that an interest
			 of the residents of that State has been or is threatened or adversely affected
			 by the engagement of a business entity in a practice that is prohibited under
			 this subtitle, the State or the State or local law enforcement agency on behalf
			 of the residents of the agency’s jurisdiction, may bring a civil action on
			 behalf of the residents of the State or jurisdiction in a district court of the
			 United States of appropriate jurisdiction or any other court of competent
			 jurisdiction, including a State court, to—</text>
								<clause commented="no" display-inline="no-display-inline" id="id4378777f-43d1-4acf-b861-38fec5eeb12c"><enum>(i)</enum><text display-inline="yes-display-inline">enjoin that practice;</text>
								</clause><clause commented="no" display-inline="no-display-inline" id="id07e9cee4-38d9-48d6-8b7d-cf85b40b9608"><enum>(ii)</enum><text display-inline="yes-display-inline">enforce compliance with this subtitle;
			 or</text>
								</clause><clause commented="no" display-inline="no-display-inline" id="idb5d85c7a-6f1f-4fc1-81b8-20ff2e653986"><enum>(iii)</enum><text display-inline="yes-display-inline">obtain civil penalties of not more than
			 $500 per day per individual whose sensitive personally identifiable information
			 was, or is reasonably believed to have been, accessed or acquired by an
			 unauthorized person, up to a maximum of $20,000,000 per violation, unless such
			 conduct is found to be willful or intentional.</text>
								</clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idaa571c73-7ef0-464a-97b8-2a6696f64b54"><enum>(B)</enum><header>Presumption</header><text display-inline="yes-display-inline">A violation of section 212(b)(2)(C) shall
			 be presumed to be willful or intentional.</text>
							</subparagraph></paragraph><paragraph id="idaa0ed1b9-d95c-4f30-976d-374b9a3b4bce"><enum>(2)</enum><header>Considerations</header><text>In
			 determining the amount of a civil penalty under this subsection, the court
			 shall take into account—</text>
							<subparagraph id="id39b96e15-c100-4ec5-950d-b7afcce20df1"><enum>(A)</enum><text>the degree of culpability
			 of the business entity;</text>
							</subparagraph><subparagraph id="ide54cf861-2fe7-4a97-8a8b-ed3019105cb6"><enum>(B)</enum><text>any prior violations of
			 this subtitle by the business entity;</text>
							</subparagraph><subparagraph id="id99823bcb-3958-4e2c-97bc-9924ec18f479"><enum>(C)</enum><text>the ability of the
			 business entity to pay a civil penalty;</text>
							</subparagraph><subparagraph id="idb1918b92-1a68-4a9f-ae6d-5086ce7b04b6"><enum>(D)</enum><text>the effect on the ability
			 of the business entity to continue to do business;</text>
							</subparagraph><subparagraph id="id281362e0-6154-4907-afe0-662283bc43b5"><enum>(E)</enum><text>the number of individuals
			 whose sensitive personally identifiable information was compromised by the
			 breach;</text>
							</subparagraph><subparagraph id="id9637859a-714b-450a-9289-c47696df82a7"><enum>(F)</enum><text>the relative cost of
			 compliance with this subtitle; and</text>
							</subparagraph><subparagraph id="ide3abef5c-979d-4751-95eb-5b20b03f5a93"><enum>(G)</enum><text>such other matters as
			 justice may require.</text>
							</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="idf5859912-52e9-4789-8da8-6147f1363756"><enum>(3)</enum><header display-inline="yes-display-inline">Notice</header>
							<subparagraph commented="no" display-inline="no-display-inline" id="id1927b657-d871-466c-9377-2bc9b6316645"><enum>(A)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">Before filing an action under paragraph
			 (1), the attorney general of the State involved shall provide to the Attorney
			 General of the United States—</text>
								<clause commented="no" display-inline="no-display-inline" id="id47e1accb-29cd-4e5d-909f-1311dd12fc9c"><enum>(i)</enum><text display-inline="yes-display-inline">written notice of the action; and</text>
								</clause><clause commented="no" display-inline="no-display-inline" id="id41efaffa-08d6-4d58-b275-a91992aea7ce"><enum>(ii)</enum><text display-inline="yes-display-inline">a copy of the complaint for the
			 action.</text>
								</clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id2b1e3988-40f4-434d-9217-b1595b0bec28"><enum>(B)</enum><header display-inline="yes-display-inline">Exemption</header>
								<clause commented="no" display-inline="no-display-inline" id="id5edae2ff-9226-4057-9f6a-347dc333867e"><enum>(i)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">Subparagraph (A) shall not apply with
			 respect to the filing of an action by an attorney general of a State under this
			 subtitle, if the State attorney general determines that it is not feasible to
			 provide the notice described in such subparagraph before the filing of the
			 action.</text>
								</clause><clause commented="no" display-inline="no-display-inline" id="id2c31f248-054e-4afe-bde0-c10b84e35665"><enum>(ii)</enum><header display-inline="yes-display-inline">Notification</header><text display-inline="yes-display-inline">In an action described in clause (i), the
			 attorney general of a State shall provide notice and a copy of the complaint to
			 the Attorney General at the time the State attorney general files the
			 action.</text>
								</clause></subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="id05c95ff0-c801-467a-96b0-f7dae7ee524d"><enum>(b)</enum><header display-inline="yes-display-inline">Federal proceedings</header><text display-inline="yes-display-inline">Upon receiving notice under subsection
			 (a)(2), the Attorney General shall have the right to—</text>
						<paragraph commented="no" display-inline="no-display-inline" id="idc2822a1e-c21a-467a-b705-1ead73ee5bee"><enum>(1)</enum><text display-inline="yes-display-inline">move to stay the action, pending the final
			 disposition of a pending Federal proceeding or action;</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id2c50c0f0-4549-4d87-b7fc-ad05af160f8e"><enum>(2)</enum><text display-inline="yes-display-inline">initiate an action in the appropriate
			 United States district court under section 218 and move to consolidate all
			 pending actions, including State actions, in such court;</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id135b7a58-fc71-4aed-8164-ee6ef66599ae"><enum>(3)</enum><text display-inline="yes-display-inline">intervene in an action brought under
			 subsection (a)(2); and</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id4791dbd1-5df5-4181-b0b4-de54365e02b1"><enum>(4)</enum><text display-inline="yes-display-inline">file petitions for appeal.</text>
						</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="idb1950210-b274-422f-ad9e-e474cf037ab1"><enum>(c)</enum><header display-inline="yes-display-inline">Pending proceedings</header><text display-inline="yes-display-inline">If the Attorney General has instituted a
			 proceeding or action for a violation of this subtitle or any regulations
			 thereunder, no attorney general of a State may, during the pendency of such
			 proceeding or action, bring an action under this subtitle against any defendant
			 named in such criminal proceeding or civil action for any violation that is
			 alleged in that proceeding or action.</text>
					</subsection><subsection commented="no" display-inline="no-display-inline" id="idf8790b09-7c7c-4083-91ae-3bd4c86f51e4"><enum>(d)</enum><header display-inline="yes-display-inline">Construction</header><text display-inline="yes-display-inline">For purposes of bringing any civil action
			 under subsection (a), nothing in this subtitle regarding notification shall be
			 construed to prevent an attorney general of a State from exercising the powers
			 conferred on such attorney general by the laws of that State to—</text>
						<paragraph commented="no" display-inline="no-display-inline" id="id7d4f70e6-66c8-4cfb-8131-07595ae4eef5"><enum>(1)</enum><text display-inline="yes-display-inline">conduct investigations;</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id6c2dd220-3064-4f56-9817-7de128e7f526"><enum>(2)</enum><text display-inline="yes-display-inline">administer oaths or affirmations; or</text>
						</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id956cd526-34c2-40c8-bea6-d0558ebd6872"><enum>(3)</enum><text display-inline="yes-display-inline">compel the attendance of witnesses or the
			 production of documentary and other evidence.</text>
						</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="id6ca23308-861c-4824-9656-9c874509769e"><enum>(e)</enum><header display-inline="yes-display-inline">Venue; service of process</header>
						<paragraph commented="no" display-inline="no-display-inline" id="ida21c0e23-e953-4f87-a2ea-385b9644281a"><enum>(1)</enum><header display-inline="yes-display-inline">Venue</header><text display-inline="yes-display-inline">Any action brought under subsection (a) may
			 be brought in—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="ida99092bd-2480-4595-99b9-0af3688e4d39"><enum>(A)</enum><text display-inline="yes-display-inline">the district court of the United States
			 that meets applicable requirements relating to venue under section 1391 of
			 title 28, United States Code; or</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="iddae3f985-3629-4dc4-8192-ea8678ac7a2b"><enum>(B)</enum><text display-inline="yes-display-inline">another court of competent
			 jurisdiction.</text>
							</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id3fd579d3-9bef-47b4-b9bf-3e462e336f5a"><enum>(2)</enum><header display-inline="yes-display-inline">Service of process</header><text display-inline="yes-display-inline">In an action brought under subsection (a),
			 process may be served in any district in which the defendant—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="idf021b6a1-196a-4ce6-af3a-6d808c9af4bc"><enum>(A)</enum><text display-inline="yes-display-inline">is an inhabitant; or</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id78cb672e-2641-4853-83fb-4e8ace3d7f14"><enum>(B)</enum><text display-inline="yes-display-inline">may be found.</text>
							</subparagraph></paragraph></subsection></section><section id="id0a6214aa-a929-446b-904c-d082450cdda2"><enum>220.</enum><header>Supplemental
			 enforcement by individuals</header>
					<subsection id="id6b6dd5eb-5c96-44bf-b422-5b0c7c952aae"><enum>(a)</enum><header>In
			 general</header><text>Any person aggrieved by a violation of the provisions of
			 section 211, 213, 214, 215, or 216 by a business entity may bring a civil
			 action in a court of appropriate jurisdiction to recover for personal injuries
			 sustained as a result of the violation.</text>
					</subsection><subsection id="ID1bc64002021d46fba9d104e3aa11c453"><enum>(b)</enum><header>Authority to bring
			 civil action; jurisdiction</header><text>As provided in subsection (c), an
			 individual may commence a civil action on his own behalf against any business
			 entity who is alleged to have violated the provisions of this subtitle.</text>
					</subsection><subsection id="idd968e6ed-0e94-46ba-a9dc-a750e44a3ff9"><enum>(c)</enum><header>Remedies in a citizen
			 suit</header>
						<paragraph id="iddea25800-42fb-420b-ab98-d8e4958397ab"><enum>(1)</enum><header>Damages</header><text>Any
			 individual harmed by a failure of a business entity to comply with the
			 provisions of section 211, 213, 214, 215, or 216, shall be able to collect
			 damages of not more than $500 per day per individual whose sensitive personally
			 identifiable information was, or is reasonably believed to have been, accessed
			 or acquired by an unauthorized person, up to a maximum of $20,000,000 per
			 violation</text>
						</paragraph><paragraph id="id9849b998-cd2e-45bf-b5fa-1c808ae566a1"><enum>(2)</enum><header>Punitive
			 damages</header><text>A business entity may be liable for punitive damages if
			 it—</text>
							<subparagraph id="id5a6e052c-7171-486d-be9d-6b21a9be2ce3"><enum>(A)</enum><text>intentionally or
			 willfully violates the provisions of section 211, 213, 214, 215, or 216;
			 or</text>
							</subparagraph><subparagraph id="idddb8f85e-4a50-4316-997e-be0c3a7381aa"><enum>(B)</enum><text>failed to comply with the
			 requirements of subsections (a) through (d) of section 202.</text>
							</subparagraph></paragraph><paragraph id="idc7845118-f579-4de0-9a6f-98bee9351854"><enum>(3)</enum><header>Equitable
			 relief</header><text>A business entity that violates the provisions of section
			 211, 213, 214, 215, or 216 may be enjoined to provide required remedies under
			 section 215 by a court of competent jurisdiction.</text>
						</paragraph></subsection><subsection id="IDfc642ed0c1f94ed6be735bae98768ab8"><enum>(d)</enum><header>Other rights and
			 remedies</header><text>The rights and remedies available under this subsection
			 are cumulative and shall not affect any other rights and remedies available
			 under law.</text>
					</subsection><subsection id="idf71df424-fd39-44f0-9e74-edbe506435a4"><enum>(e)</enum><header>Nonenforceability of
			 Certain Provisions Waiving Rights and Remedies or Requiring Arbitration of
			 Disputes</header>
						<paragraph id="IDe694ac0a59304739bfdf40c536b21191"><enum>(1)</enum><header>Waiver of rights and
			 remedies</header><text>The rights and remedies provided for in this section may
			 not be waived by any agreement, policy form, or condition of employment
			 including by a predispute arbitration agreement.</text>
						</paragraph><paragraph id="ID4c67ebdaedf24ab687fc535d3a6145b1"><enum>(2)</enum><header>Predispute arbitration
			 agreements</header><text>No predispute arbitration agreement shall be valid or
			 enforceable, if the agreement requires arbitration of a dispute arising under
			 this section.</text>
						</paragraph></subsection><subsection id="ID8a038990875544baa473c84c3db43df2"><enum>(f)</enum><header>Considerations</header><text>In
			 determining the amount of a civil penalty under this subsection, the court
			 shall take into account—</text>
						<paragraph id="IDca5de82eb3584e9cb2e24075c0b93587"><enum>(1)</enum><text>the degree of culpability
			 of the business entity;</text>
						</paragraph><paragraph id="ID53419dc290e84ccda796cfe614f1b8d1"><enum>(2)</enum><text>any prior violations of
			 this subtitle by the business entity;</text>
						</paragraph><paragraph id="IDc5fc91a3cd2d4f0cba386f584ddc45a0"><enum>(3)</enum><text>the ability of the
			 business entity to pay a civil penalty;</text>
						</paragraph><paragraph id="ID14d535521a764b3794840cb0f7087d54"><enum>(4)</enum><text>the effect on the ability
			 of the business entity to continue to do business;</text>
						</paragraph><paragraph id="ID9c8a6e8ac7b0485ab0d60f0e8e203b06"><enum>(5)</enum><text>the number of individuals
			 whose sensitive personally identifiable information was compromised by the
			 breach;</text>
						</paragraph><paragraph id="IDd0a4c300d6c44a38906cca1f0abf7baa"><enum>(6)</enum><text>the relative cost of
			 compliance with this subtitle; and</text>
						</paragraph><paragraph id="ID5e3199985bdf485aa8e3fcbe3bcb0057"><enum>(7)</enum><text>such other matters as
			 justice may require.</text>
						</paragraph></subsection></section><section commented="no" display-inline="no-display-inline" id="id861d9118-91fd-4375-b975-6896404633dd"><enum>221.</enum><header display-inline="yes-display-inline">Relation to other laws</header>
					<subsection commented="no" display-inline="no-display-inline" id="id55dd5eb4-7aa0-48b3-966f-2e7d332a77ec"><enum>(a)</enum><header>In
			 general</header><text display-inline="yes-display-inline">The provisions of
			 this subtitle shall supersede any other provision of Federal law or any
			 provision of law of any State relating to notification by a business entity
			 engaged in interstate commerce or an agency of a security breach, except as
			 provided in this subsection.</text>
					</subsection><subsection commented="no" id="id47ac48f0-c301-4800-b983-dec1ae25c50d"><enum>(b)</enum><header>Limitations</header>
						<paragraph commented="no" id="id6EC1F5550278490FBA1AF0EC6F470475"><enum>(1)</enum><header>State common
			 law</header><text>Nothing in this subtitle shall be construed to exempt any
			 entity from liability under common law, including through the operation of
			 ordinary preemption principles, and including liability through state trespass,
			 contract, or tort law, for damages caused by the failure to notify an
			 individual following a security breach.</text>
						</paragraph><paragraph id="ID0990a559838645ed9109d33259242ad8"><enum>(2)</enum><header>Gramm-Leach-Bliley
			 Act</header><text>Nothing in this Act shall supersede the data security
			 requirements of the Gramm-Leach-Bliley Act (15 U.S.C. 6801 et seq.), or
			 implementing regulations based on that Act.</text>
						</paragraph><paragraph id="IDaebf426961c14cfb9a57d9efdd9175ec"><enum>(3)</enum><header>Health Privacy</header>
							<subparagraph id="ID7870dcbeb17f459e95cd6ea9cb152013"><enum>(A)</enum><text>To the extent that a
			 business entity acts as a covered entity or a business associate under the
			 Health Information Technology for Economic and Clinical Health Act (42 U.S.C.
			 17932), and has the obligation to provide breach notification under that Act or
			 its implementing regulations, the requirements of this Act shall not
			 apply.</text>
							</subparagraph><subparagraph id="ID618f2ff19f1340f7948e449c57652caf"><enum>(B)</enum><text>To the extent that a
			 business entity acts as a vendor of personal health records, a third party
			 service provider, or other entity subject to the Health Information Technology
			 for Economical and Clinical Health Act (42 U.S.C. 17937), and has the
			 obligation to provide breach notification under that Act or its implementing
			 regulations, the requirements of this Act shall not apply.</text>
							</subparagraph></paragraph></subsection></section><section commented="no" display-inline="no-display-inline" id="idd022a39f-1a4e-4a48-82a7-51323c57cddb"><enum>222.</enum><header display-inline="yes-display-inline">Authorization of
			 appropriations</header><text display-inline="no-display-inline">There are
			 authorized to be appropriated such sums as may be necessary to cover the costs
			 incurred by the United States Secret Service to carry out investigations and
			 risk assessments of security breaches as required under this subtitle.</text>
				</section><section commented="no" display-inline="no-display-inline" id="id9544d646-caf3-44b1-b465-60496b157301"><enum>223.</enum><header display-inline="yes-display-inline">Reporting on risk assessment
			 exemptions</header><text display-inline="no-display-inline">The United States
			 Secret Service and the Federal Bureau of Investigation shall report to Congress
			 not later than 18 months after the date of enactment of this Act, and upon the
			 request by Congress thereafter, on—</text>
					<paragraph commented="no" display-inline="no-display-inline" id="idce219c31-3c69-4493-aed5-6f6968c589c4"><enum>(1)</enum><text display-inline="yes-display-inline">the number and nature of the security
			 breaches described in the notices filed by those business entities invoking the
			 risk assessment exemption under section 212(b) and the response of the United
			 States Secret Service and the Federal Bureau of Investigation to such notices;
			 and</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id1ba1a428-0836-41b1-ac07-a818737eafa2"><enum>(2)</enum><text display-inline="yes-display-inline">the number and nature of security breaches
			 subject to the national security and law enforcement exemptions under section
			 212(a), provided that such report may not disclose the contents of any risk
			 assessment provided to the United States Secret Service and the Federal Bureau
			 of Investigation pursuant to this subtitle.</text>
					</paragraph></section></subtitle><subtitle id="idfe620273-376a-42be-a473-7c73b7b8286b"><enum>C</enum><header>Post-Breach technical
			 information clearinghouse</header>
				<section id="id04b18cf1-6d51-4dcf-aef2-a50f77ba721d"><enum>230.</enum><header>Clearinghouse
			 information collection, maintenance, and access</header>
					<subsection id="id1a0b601c-41d2-4040-8f13-fa6e756e2cbf"><enum>(a)</enum><header>In
			 general</header><text>The designated entity shall maintain a clearinghouse of
			 technical information concerning system vulnerabilities identified in the wake
			 of security breaches, which shall—</text>
						<paragraph id="id18a2897a-7359-4ac6-b344-21ac619d5e66"><enum>(1)</enum><text>contain information
			 disclosed by agencies or business entities under subsection (b); and</text>
						</paragraph><paragraph id="id66edf54b-6aec-4336-893b-a61833412091"><enum>(2)</enum><text>be accessible to
			 certified entities under subsection (c).</text>
						</paragraph></subsection><subsection id="iddb64771b-1124-4c99-b029-02814052c7e5"><enum>(b)</enum><header>Post-breach technical
			 notification</header><text>In any instance where an agency or business entity
			 is required to notify the designated entity under section 217, the agency or
			 business entity shall also provide the designated entity with technical
			 information concerning the nature of the security breach, including—</text>
						<paragraph id="id4307ad6b-df05-4469-9c8c-920d7e25db85"><enum>(1)</enum><text>technical information
			 regarding any system vulnerabilities of the agency or business entity revealed
			 by or identified as a consequence of the security breach;</text>
						</paragraph><paragraph id="id59b74a2d-da00-4604-aa2a-dcd13644ce7b"><enum>(2)</enum><text>technical information
			 regarding any system vulnerabilities of the agency or business entity actually
			 exploited during the security breach; and</text>
						</paragraph><paragraph id="id51b295a8-f02c-47f9-8aab-075440ffb25e"><enum>(3)</enum><text>any other technical
			 information concerning the nature of the security breach deemed appropriate for
			 collection by the designated entity in furtherance of this subtitle.</text>
						</paragraph></subsection><subsection id="ida11a00b5-4e98-4e87-8ba5-2d2ebadfb391"><enum>(c)</enum><header>Access to
			 clearinghouse</header><text>Any entity certified under subsection (d) may
			 review information maintained by the technical information clearinghouse for
			 the purpose of preventing security breaches that threaten the security of
			 sensitive personally identifiable information.</text>
					</subsection><subsection id="id3f88baf5-2bea-4058-aa8f-0eecf3b192af"><enum>(d)</enum><header>Certification for
			 access</header><text>The designated entity shall issue and revoke
			 certifications to agencies and business entities wishing to review information
			 maintained by the technical information clearinghouse and shall establish
			 conditions for obtaining and maintaining such certifications, including
			 agreement that any information obtained directly or derived indirectly from the
			 review of information maintained by the technical information
			 clearinghouse—</text>
						<paragraph id="idbe1c2eeb-2d80-4c7c-894d-219797a13cfa"><enum>(1)</enum><text>shall only be used to
			 improve the security and reduce the vulnerability of networks that collect,
			 access, transmit, use, store, or dispose of sensitive personally identifiable
			 information;</text>
						</paragraph><paragraph id="id33c8374b-ce9a-4722-a3be-c84a9a8a6450"><enum>(2)</enum><text>may not be used for any
			 competitive commercial purpose; and</text>
						</paragraph><paragraph id="id83676ab6-49e3-45d3-849b-51f27dd04b6f"><enum>(3)</enum><text>may not be shared with
			 any third party, including other parties certified for access to the
			 information clearinghouse, without the express written consent of the
			 designated entity.</text>
						</paragraph></subsection><subsection id="idd022c22a-d913-4d14-bd35-e9d9cc18064f"><enum>(e)</enum><header>Rulemaking</header><text>In
			 consultation with the private sector, appropriate representatives of State and
			 local governments, and other appropriate Federal agencies, the designated
			 entity may issue such regulations as it determines to be necessary to carry out
			 this subtitle. All regulations promulgated under this Act shall be issued in
			 accordance with section 553 of title 5, United States Code.</text>
					</subsection></section><section id="id90a08508-8e8a-4b91-b5d9-4e5ca6feaab5"><enum>231.</enum><header>Protections for
			 clearinghouse participants</header>
					<subsection id="id976faa3d-8a12-41aa-9c5e-31ded31362e3"><enum>(a)</enum><header>Protection of
			 proprietary information</header><text display-inline="yes-display-inline">To
			 the extent feasible, the designated entity shall ensure that any technical
			 information disclosed to the designated entity under this subtitle shall be
			 stored in a format designed to protect proprietary business information from
			 inadvertent disclosure.</text>
					</subsection><subsection id="id69d23b97-3664-42f3-a3c9-2ae37a4bde36"><enum>(b)</enum><header>Anonymous data
			 release</header><text>To the extent feasible, the designated entity shall
			 ensure that all information stored in the technical information clearinghouse
			 and accessed by certified parties is presented in a form that minimizes the
			 potential for such information to be traced to a particular network, company,
			 or security breach incident.</text>
					</subsection><subsection id="idac9d5d82-5963-4de7-9209-e627a55c366f"><enum>(c)</enum><header>Protection from public
			 disclosure</header><text>Except as otherwise provided in this subtitle—</text>
						<paragraph id="id8cbd4492-3bc5-4dad-acfe-4c715e25cfbd"><enum>(1)</enum><text>security and
			 vulnerability information collected under this section and provided to the
			 Federal Government, including aggregated analysis and data, shall be exempt
			 from disclosure under section 552(b)(3) of title 5, United States Code;
			 and</text>
						</paragraph><paragraph id="idfbba7224-9479-4ca6-a29e-1e97fde13a22"><enum>(2)</enum><text>under section 230(e),
			 security and vulnerability-related information provided to the Federal
			 Government under this section, including aggregated analysis and data, shall be
			 protected from public disclosure, except that this paragraph—</text>
							<subparagraph id="id5179f678-0ec0-4992-8f0c-46bf3507bb56"><enum>(A)</enum><text>does not prohibit the
			 sharing of such information, as the designated entity determines to be
			 appropriate, in order to mitigate cybersecurity threats or further the official
			 functions of a government agency; and</text>
							</subparagraph><subparagraph id="id14c215f9-318b-489b-9471-8e004d13c5e8"><enum>(B)</enum><text>does not authorized such
			 information to be withheld from a committee of Congress authorized to request
			 the information.</text>
							</subparagraph></paragraph></subsection><subsection id="ide69fd54d-9197-4f31-ac72-59081912ca62"><enum>(d)</enum><header>Protection of
			 classified information</header><text>Nothing in this subtitle permits the
			 unauthorized disclosure of classified information.</text>
					</subsection></section><section commented="no" display-inline="no-display-inline" id="id8a82ef6e-1ec0-4f2a-bafe-9b5ceaa8260a"><enum>232.</enum><header display-inline="yes-display-inline">Effective
			 date</header><text display-inline="no-display-inline">This subtitle shall take
			 effect on the expiration of the date which is 90 days after the date of
			 enactment of this Act.</text>
				</section></subtitle></title><title changed="added" commented="no" committee-id="SSJU00" id="id78f1d118-9870-4652-b8e7-65b4bbad135d" level-type="subsequent" reported-display-style="italic"><enum>III</enum><header display-inline="yes-display-inline">Access to and use of commercial
			 data</header>
			<section commented="no" display-inline="no-display-inline" id="id5e23738a-79b2-48b9-b90b-10ecd97f6760" section-type="subsequent-section"><enum>301.</enum><header display-inline="yes-display-inline">General services administration review of
			 contracts</header>
				<subsection commented="no" display-inline="no-display-inline" id="idfa638cdc-0b70-4dc8-b054-094103964bd5"><enum>(a)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">In considering contract awards totaling
			 more than $500,000 and entered into after the date of enactment of this Act
			 with data brokers, the Administrator of the General Services Administration
			 shall evaluate—</text>
					<paragraph commented="no" display-inline="no-display-inline" id="idb9cd8fff-b0bd-464c-a679-0af6765af2f3"><enum>(1)</enum><text display-inline="yes-display-inline">the data privacy and security program of a
			 data broker to ensure the privacy and security of data containing sensitive
			 personally identifiable information, including whether such program adequately
			 addresses privacy and security threats created by malicious software or code,
			 or the use of peer-to-peer file sharing software;</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ide54c5a4a-c0a6-4286-8ce1-d51b767d7c22"><enum>(2)</enum><text display-inline="yes-display-inline">the compliance of a data broker with such
			 program;</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id43659c29-2a4f-4835-9537-1b465be0722e"><enum>(3)</enum><text display-inline="yes-display-inline">the extent to which the databases and
			 systems containing sensitive personally identifiable information of a data
			 broker have been compromised by security breaches; and</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id8048d7cf-af47-4469-89fa-cbf673734de6"><enum>(4)</enum><text display-inline="yes-display-inline">the response by a data broker to such
			 breaches, including the efforts by such data broker to mitigate the impact of
			 such security breaches.</text>
					</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="ida1c2dfd6-0d3a-46bc-b1e5-c6b4d70e87c3"><enum>(b)</enum><header display-inline="yes-display-inline">Compliance safe harbor</header><text display-inline="yes-display-inline">The data privacy and security program of a
			 data broker shall be deemed sufficient for the purposes of subsection (a), if
			 the data broker complies with or provides protection equal to industry
			 standards, as identified by the Federal Trade Commission, that are applicable
			 to the type of sensitive personally identifiable information involved in the
			 ordinary course of business of such data broker.</text>
				</subsection><subsection commented="no" display-inline="no-display-inline" id="idd7705970-ca85-4003-b64c-d5259f652a56"><enum>(c)</enum><header display-inline="yes-display-inline">Penalties</header><text display-inline="yes-display-inline">In awarding contracts with data brokers for
			 products or services related to access, use, compilation, distribution,
			 processing, analyzing, or evaluating sensitive personally identifiable
			 information, the Administrator of the General Services Administration
			 shall—</text>
					<paragraph commented="no" display-inline="no-display-inline" id="id87d24bb3-aa11-4a13-879a-3189047dd321"><enum>(1)</enum><text display-inline="yes-display-inline">include monetary or other penalties—</text>
						<subparagraph commented="no" display-inline="no-display-inline" id="id7c2efc9c-0ae0-4c6b-958e-6b32a196c646"><enum>(A)</enum><text display-inline="yes-display-inline">for failure to comply with subtitles A and
			 B of title II; or</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id29adc7e3-fd3f-4a2c-a938-67e229812587"><enum>(B)</enum><text display-inline="yes-display-inline">if a contractor knows or has reason to know
			 that the sensitive personally identifiable information being provided is
			 inaccurate, and provides such inaccurate information; and</text>
						</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="idc1d8778e-017f-4b73-a22d-61ea64956260"><enum>(2)</enum><text display-inline="yes-display-inline">require a data broker that engages service
			 providers not subject to subtitle A of title II for responsibilities related to
			 sensitive personally identifiable information to—</text>
						<subparagraph commented="no" display-inline="no-display-inline" id="idd745baee-5728-47b5-97f1-b9c9a8798b61"><enum>(A)</enum><text display-inline="yes-display-inline">exercise appropriate due diligence in
			 selecting those service providers for responsibilities related to sensitive
			 personally identifiable information;</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id3c7c8321-de05-4a44-8cec-1e92aa2764bb"><enum>(B)</enum><text display-inline="yes-display-inline">take reasonable steps to select and retain
			 service providers that are capable of maintaining appropriate safeguards for
			 the security, privacy, and integrity of the sensitive personally identifiable
			 information at issue; and</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id48989e86-7961-463f-8974-94e26203bb0a"><enum>(C)</enum><text display-inline="yes-display-inline">require such service providers, by
			 contract, to implement and maintain appropriate measures designed to meet the
			 objectives and requirements in title II.</text>
						</subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="id43aa9396-3d77-47a8-9d6f-f7dd1dd2e7af"><enum>(d)</enum><header display-inline="yes-display-inline">Limitation</header><text display-inline="yes-display-inline">The penalties under subsection (c) shall
			 not apply to a data broker providing information that is accurately and
			 completely recorded from a public record source or licensor.</text>
				</subsection></section><section commented="no" display-inline="no-display-inline" id="id727cf56e-2ea5-4f23-93f2-9c857207ba6d" section-type="subsequent-section"><enum>302.</enum><header display-inline="yes-display-inline">Requirement to audit information security
			 practices of contractors and third party business entities</header><text display-inline="no-display-inline">Section 3544(b) of title 44, United States
			 Code, is amended—</text>
				<paragraph commented="no" display-inline="no-display-inline" id="id4a30863f-9804-467e-b1a7-45969b7c67e5"><enum>(1)</enum><text display-inline="yes-display-inline">in paragraph (7)(C)(iii), by striking
			 <quote>and</quote> after the semicolon;</text>
				</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id2b891c07-c8b1-4842-808a-0320b1242046"><enum>(2)</enum><text display-inline="yes-display-inline">in paragraph (8), by striking the period
			 and inserting <quote>; and</quote>; and</text>
				</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ida74447f2-5519-4386-bc10-310fd5389999"><enum>(3)</enum><text display-inline="yes-display-inline">by adding at the end the following:</text>
					<quoted-block changed="added" committee-id="SSJU00" display-inline="no-display-inline" id="ide3efe831-53b3-4999-ad13-3e98fd33bc5b" reported-display-style="italic" style="OLC">
						<paragraph commented="no" display-inline="no-display-inline" id="id8755cfd9-91db-4c7f-a662-dca44d55fa28"><enum>(9)</enum><text display-inline="yes-display-inline">procedures for evaluating and auditing the
				information security practices of contractors or third party business entities
				supporting the information systems or operations of the agency involving
				sensitive personally identifiable information (as that term is defined in
				section 3 of the <short-title>Personal Data Protection and
				Breach Accountability Act of 2011</short-title>) and ensuring remedial action
				to address any significant
				deficiencies.</text>
						</paragraph><after-quoted-block>.</after-quoted-block></quoted-block>
				</paragraph></section><section commented="no" display-inline="no-display-inline" id="idd66f12e4-a6d2-498b-90d1-ea6a231827c0" section-type="subsequent-section"><enum>303.</enum><header display-inline="yes-display-inline">Privacy impact assessment of government use
			 of commercial information services containing sensitive personally identifiable
			 information</header>
				<subsection commented="no" display-inline="no-display-inline" id="id85848f29-b92f-4f59-b81e-23f39d0fcb41"><enum>(a)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">Section 208(b)(1) of the E-Government Act
			 of 2002 (44 U.S.C. 3501 note) is amended—</text>
					<paragraph commented="no" display-inline="no-display-inline" id="id30d97913-6de1-4536-b210-0e564e1e1836"><enum>(1)</enum><text display-inline="yes-display-inline">in subparagraph (A)(i), by striking
			 <quote>or</quote>;</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id6130e4ca-a518-4b2c-ba33-b46015bda7db"><enum>(2)</enum><text display-inline="yes-display-inline">in subparagraph (A)(ii), by striking the
			 period and inserting <quote>; or</quote>; and</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id7a47bb92-7772-432b-b92e-1e8b37874f58"><enum>(3)</enum><text display-inline="yes-display-inline">by inserting after clause (ii) the
			 following:</text>
						<quoted-block changed="added" committee-id="SSJU00" display-inline="no-display-inline" id="id9040241a-9198-4d03-94b1-6685ceeb23be" reported-display-style="italic" style="OLC">
							<clause commented="no" display-inline="no-display-inline" id="idf15df905-e6f6-48a2-bf19-3e8220191df5"><enum>(iii)</enum><text display-inline="yes-display-inline">purchasing or subscribing for a fee to
				sensitive personally identifiable information from a data broker (as such terms
				are defined in section 3 of the <short-title>Personal Data
				Protection and Breach Accountability Act of
				2011</short-title>).</text>
							</clause><after-quoted-block>.</after-quoted-block></quoted-block>
					</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="idc1616aa4-3644-4711-946a-4c4b8049ce78"><enum>(b)</enum><header display-inline="yes-display-inline">Limitation</header><text display-inline="yes-display-inline">Notwithstanding any other provision of law,
			 commencing 1 year after the date of enactment of this Act, no Federal agency
			 may enter into a contract with a data broker to access for a fee any database
			 consisting primarily of sensitive personally identifiable information
			 concerning United States persons (other than news reporting or telephone
			 directories) unless the head of such department or agency—</text>
					<paragraph commented="no" display-inline="no-display-inline" id="id51c4899d-1a28-4a7e-bade-d3790c567e0d"><enum>(1)</enum><text display-inline="yes-display-inline">completes a privacy impact assessment under
			 section 208 of the E-Government Act of 2002 (44 U.S.C. 3501 note), which shall
			 subject to the provision in that Act pertaining to sensitive information,
			 include a description of—</text>
						<subparagraph commented="no" display-inline="no-display-inline" id="id2d8fa80b-c0dc-4552-8e9c-5423873e15f4"><enum>(A)</enum><text display-inline="yes-display-inline">such database;</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id9bce9358-7454-4979-908a-889c350eae62"><enum>(B)</enum><text display-inline="yes-display-inline">the name of the data broker from whom it is
			 obtained; and</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ida59381d8-9f39-4def-8be6-d178c34fa4e4"><enum>(C)</enum><text display-inline="yes-display-inline">the amount of the contract for use;</text>
						</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id10323ef2-cfc4-4247-b451-c8443e50001c"><enum>(2)</enum><text display-inline="yes-display-inline">adopts regulations that specify—</text>
						<subparagraph commented="no" display-inline="no-display-inline" id="idef4f2a14-9452-483c-97af-41df522f7fcd"><enum>(A)</enum><text display-inline="yes-display-inline">the personnel permitted to access, analyze,
			 or otherwise use such databases;</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id7d0dec2e-7ab6-4022-a086-0a902c179d31"><enum>(B)</enum><text display-inline="yes-display-inline">standards governing the access, analysis,
			 or use of such databases;</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id6baabdd3-c716-4ad7-bd13-6b5ed8eecff5"><enum>(C)</enum><text display-inline="yes-display-inline">any standards used to ensure that the
			 sensitive personally identifiable information accessed, analyzed, or used is
			 the minimum necessary to accomplish the intended legitimate purpose of the
			 Federal agency;</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idfaa0d146-c006-4a8e-9678-4e29781aa3fe"><enum>(D)</enum><text display-inline="yes-display-inline">standards limiting the retention and
			 redisclosure of sensitive personally identifiable information obtained from
			 such databases;</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idb6172216-3673-45ae-834d-a02b50e39f5f"><enum>(E)</enum><text display-inline="yes-display-inline">procedures ensuring that such data meet
			 standards of accuracy, relevance, completeness, and timeliness;</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id0e619b61-e0a2-4baf-a6fd-34c7ece286d4"><enum>(F)</enum><text display-inline="yes-display-inline">the auditing and security measures to
			 protect against unauthorized access, analysis, use, or modification of data in
			 such databases;</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id30ae3430-8795-4cb3-b68d-eb66f935712c"><enum>(G)</enum><text display-inline="yes-display-inline">applicable mechanisms by which individuals
			 may secure timely redress for any adverse consequences wrongly incurred due to
			 the access, analysis, or use of such databases;</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id47100a73-4727-4475-a3e8-b5abd4861321"><enum>(H)</enum><text display-inline="yes-display-inline">mechanisms, if any, for the enforcement and
			 independent oversight of existing or planned procedures, policies, or
			 guidelines; and</text>
						</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ide8a50b9e-904e-4813-a431-dc719a726365"><enum>(I)</enum><text display-inline="yes-display-inline">an outline of enforcement mechanisms for
			 accountability to protect individuals and the public against unlawful or
			 illegitimate access or use of databases; and</text>
						</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="idbd7bfb48-cba3-443a-9af2-7fa821036471"><enum>(3)</enum><text display-inline="yes-display-inline">incorporates into the contract or other
			 agreement totaling more than $500,000, provisions—</text>
						<subparagraph commented="no" display-inline="no-display-inline" id="id03b1bfad-f819-4bbd-a23b-c0dadcb3b279"><enum>(A)</enum><text display-inline="yes-display-inline">providing for penalties—</text>
							<clause commented="no" display-inline="no-display-inline" id="id6e757a37-bc5e-46c7-bba3-fdbc5ba67177"><enum>(i)</enum><text display-inline="yes-display-inline">for failure to comply with title II of this
			 Act; or</text>
							</clause><clause commented="no" display-inline="no-display-inline" id="id208ff2d1-933e-48b7-bed9-716e5bf2b41b"><enum>(ii)</enum><text display-inline="yes-display-inline">if the entity knows or has reason to know
			 that the sensitive personally identifiable information being provided to the
			 Federal department or agency is inaccurate, and provides such inaccurate
			 information; and</text>
							</clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id4d9a40a0-ec7e-41da-90fe-32b163487f6f"><enum>(B)</enum><text display-inline="yes-display-inline">requiring a data broker that engages
			 service providers not subject to subtitle A of title II for responsibilities
			 related to sensitive personally identifiable information to—</text>
							<clause commented="no" display-inline="no-display-inline" id="id1298d659-7090-435c-9267-522f51002a37"><enum>(i)</enum><text display-inline="yes-display-inline">exercise appropriate due diligence in
			 selecting those service providers for responsibilities related to sensitive
			 personally identifiable information;</text>
							</clause><clause commented="no" display-inline="no-display-inline" id="idf310a152-4558-4e03-882d-163bb1ab5bfb"><enum>(ii)</enum><text display-inline="yes-display-inline">take reasonable steps to select and retain
			 service providers that are capable of maintaining appropriate safeguards for
			 the security, privacy, and integrity of the sensitive personally identifiable
			 information at issue; and</text>
							</clause><clause commented="no" display-inline="no-display-inline" id="id1b796f71-a196-4555-82c9-ccf537293cf8"><enum>(iii)</enum><text display-inline="yes-display-inline">require such service providers, by
			 contract, to implement and maintain appropriate measures designed to meet the
			 objectives and requirements in title II.</text>
							</clause></subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="id0c366d26-b40d-4ef5-8c04-ba8077181144"><enum>(c)</enum><header display-inline="yes-display-inline">Limitation on penalties</header><text display-inline="yes-display-inline">The penalties under subsection (b)(3)(A)
			 shall not apply to a data broker providing information that is accurately and
			 completely recorded from a public record source.</text>
				</subsection><subsection commented="no" display-inline="no-display-inline" id="id33d0e169-9cd0-450c-80dd-e1263c9935b4"><enum>(d)</enum><header display-inline="yes-display-inline">Study of government use</header>
					<paragraph commented="no" display-inline="no-display-inline" id="idc55dd5fb-0a99-4467-8ffc-d2b9504a041f"><enum>(1)</enum><header display-inline="yes-display-inline">Scope
			 of study</header><text display-inline="yes-display-inline">Not later than 180
			 days after the date of enactment of this Act, the Comptroller General of the
			 United States shall conduct a study and audit and prepare a report on Federal
			 agency actions to address the recommendations in the Government Accountability
			 Office's April 2006 report on agency adherence to key privacy principles in
			 using data brokers or commercial databases containing sensitive personally
			 identifiable information.</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ide8affa1b-72ee-45d2-a4fd-6a80f623224d"><enum>(2)</enum><header display-inline="yes-display-inline">Report</header><text display-inline="yes-display-inline">A copy of the report required under
			 paragraph (1) shall be submitted to Congress.</text>
					</paragraph></subsection></section><section id="idc62ca697-5ab4-4d5a-a6e1-97fafdcc2659"><enum>304.</enum><header>FBI report on reported
			 breaches and compliance</header>
				<subsection id="idd46f46aa-b626-4b36-ac5d-0ce27b1b9576"><enum>(a)</enum><header>In
			 general</header><text>Not later than 1 year after the date of enactment of this
			 Act, and each year thereafter, the Federal Bureau of Investigation, in
			 coordination with the Secret Service, shall submit to the Committee on the
			 Judiciary of the Senate and the Committee on the Judiciary of the House of
			 Representatives a report regarding any reported breaches at agencies or
			 business entities during the preceding year.</text>
				</subsection><subsection id="id0bc0f0cf-64f5-4238-8d31-30e50e984651"><enum>(b)</enum><header>Report
			 content</header><text>Such reporting shall include—</text>
					<paragraph id="id9115c083-8b26-4dd8-8322-42f967265b34"><enum>(1)</enum><text>the total instances of
			 breaches of security in the previous year;</text>
					</paragraph><paragraph id="id89b56ec9-019b-4318-93d9-6ea338ed5cf1"><enum>(2)</enum><text>the percentage of
			 breaches described in subsection (a) that occurred at an agency or business
			 entity that did not comply with the personal data privacy and security program
			 under section 202; and</text>
					</paragraph><paragraph id="id29d11e6c-fa08-46b4-a841-72d7d7c39bb2"><enum>(3)</enum><text>recommendations, if any,
			 for modifying or amending this Act to increase its effectiveness.</text>
					</paragraph></subsection></section><section id="iddd4f8b9b-c3ca-4ffd-9413-17dca5e64ea2"><enum>305.</enum><header>Department of Justice
			 report on enforcement actions</header><text display-inline="no-display-inline">Section 529 of title 28, United States Code,
			 is amended by adding at the end the following:</text>
				<quoted-block changed="added" committee-id="SSJU00" display-inline="no-display-inline" id="id4a91b18a-163e-444b-bc74-951fb4f6c698" reported-display-style="italic" style="OLC">
					<subsection id="id8b4f0763-22d0-48c8-9f17-b0db4f8afa69"><enum>(c)</enum><text>Not later than 1 year
				after the date of enactment of the <short-title>Personal
				Data Protection and Breach Accountability Act of 2011</short-title>, and every
				fiscal year thereafter, the Attorney General shall submit to Congress a report
				on Federal enforcement actions, State attorneys general enforcement actions,
				and private enforcement actions, undertaken pursuant to the
				<short-title>Personal Data Protection and Breach
				Accountability Act of 2011</short-title> that shall include a description of
				the best practices for enforcement of such Act as well as recommendations, if
				any, for modifying or amending this Act to increase the effectiveness of such
				enforcement
				actions.</text>
					</subsection><after-quoted-block>.</after-quoted-block></quoted-block>
			</section><section id="idc2e2951e-3b56-4c4f-bdb6-cdc302eaf350"><enum>306.</enum><header>Report on notification
			 effectiveness</header>
				<subsection id="id4ff9514c-d0fa-44aa-b300-394ede54a546"><enum>(a)</enum><header>In
			 general</header><text>Not later than 1 year after the date of enactment of this
			 Act, and each year thereafter, the designated entity, in coordination with the
			 Attorney General and the Federal Trade Commission, shall submit to the
			 Committee on the Judiciary of the Senate and the Committee on the Judiciary of
			 the House of Representatives a report regarding the effectiveness of
			 post-breach notification practices by agencies and business entities.</text>
				</subsection><subsection id="idf008ffb6-c624-45f0-836c-c36bfe2d515c"><enum>(b)</enum><header>Report
			 content</header><text>The report required under subsection (a) shall
			 include—</text>
					<paragraph id="id00052c37-686a-4e0d-af71-9a2367428562"><enum>(1)</enum><text>in each instance of a
			 breach of security, the amount of time between the instance of the breach and
			 the discovery of the breach by the affected business entity;</text>
					</paragraph><paragraph id="id7b81001c-df58-4479-a5c9-c0429eb57aff"><enum>(2)</enum><text>in each instance of a
			 breach of security, the amount of time between the discovery of the breach by
			 the affected business entity and the notification to the FBI and Secret
			 Service; and</text>
					</paragraph><paragraph id="ide0f83d52-93c2-4294-8c31-6d09a27c4614"><enum>(3)</enum><text>in each instance of a
			 breach of security, the amount of time between the discovery of the breach by
			 the affected business entity and the notification to individuals whose
			 sensitive personally identifiable information was compromised.</text>
					</paragraph></subsection></section></title><title changed="added" committee-id="SSJU00" id="id209cb2f5-1d97-46a8-9c56-b7e3dbc3333c" reported-display-style="italic"><enum>IV</enum><header>Compliance with
			 Statutory Pay-As-You-Go Act</header>
			<section id="id7a5d476a-64f0-4884-a06a-c11c43e654d2"><enum>401.</enum><header>Budget
			 compliance</header><text display-inline="no-display-inline">The budgetary
			 effects of this Act, for the purpose of complying with the Statutory
			 Pay-As-You-Go Act of 2010, shall be determined by reference to the latest
			 statement titled <quote>Budgetary Effects of PAYGO Legislation</quote> for this
			 Act, submitted for printing in the Congressional Record by the Chairman of the
			 Senate Budget Committee, provided that such statement has been submitted prior
			 to the vote on passage.</text>
			</section></title></legis-body>
	<endorsement>
		<action-date>September 22, 2011</action-date>
		<action-desc>Reported with an amendment</action-desc>
	</endorsement>
</bill>
