<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" public-private="public">
	<form>
		<distribution-code display="yes">II</distribution-code>
		<congress>112th CONGRESS</congress>
		<session>1st Session</session>
		<legis-num>S. 1732</legis-num>
		<current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber>
		<action>
			<action-date date="20111018">October 18, 2011</action-date>
			<action-desc><sponsor name-id="S213">Mr. Akaka</sponsor> introduced the
			 following bill; which was read twice and referred to the
			 <committee-name committee-id="SSGA00">Committee on Homeland Security and
			 Governmental Affairs</committee-name></action-desc>
		</action>
		<legis-type>A BILL</legis-type>
		<official-title>To amend section 552a of title 5, United States Code
		  (commonly referred to as the Privacy Act), the E-Government Act of 2002 (Public
		  Law 107–347), and chapters 35 and 36 of title 44, United States Code, and other
		  provisions of law to modernize and improve Federal privacy laws.
		  </official-title>
	</form>
	<legis-body>
		<section id="S1" section-type="section-one"><enum>1.</enum><header>Short
			 title</header><text display-inline="no-display-inline">This Act may be cited as
			 the <quote><short-title>Privacy Act Modernization for the
			 Information Age Act of 2011</short-title></quote>.</text>
		</section><section id="idC6D5782CF66B465FB9F70D418678EFB1"><enum>2.</enum><header>Amendments to
			 the Privacy Act</header>
			<subsection id="idC156E56521114C5B8983541FB049DA99"><enum>(a)</enum><header>Definitions</header><text>Section
			 552a(a) of title 5, United States Code (commonly referred to as the Privacy
			 Act), is amended—</text>
				<paragraph id="id293795BBED9B459D95DD90DFF3F9598A"><enum>(1)</enum><text>in paragraph (4),
			 by striking <quote>that is maintained by an agency, including, but not limited
			 to, his</quote> and inserting <quote>, including</quote>;</text>
				</paragraph><paragraph id="id8F53CCA3901C46C6A8AAE7066723C7A5"><enum>(2)</enum><text>by striking
			 paragraph (5) and inserting the following:</text>
					<quoted-block display-inline="no-display-inline" id="idAE2B263D6ABF4266B698D466EB095E02" style="OLC">
						<paragraph id="IDaef5817c86d44294961252fab409b853"><enum>(5)</enum><text>the term
				<term>system of records</term> means a group of any records maintained by, or
				otherwise under the control of any agency that is used for any authorized
				purpose by or on behalf of the
				agency;</text>
						</paragraph><after-quoted-block>;</after-quoted-block></quoted-block>
				</paragraph><paragraph id="id8B03340A64EC4B2DAFCEB2E6F7CD99AF"><enum>(3)</enum><text>by striking
			 paragraph (7) and inserting the following:</text>
					<quoted-block display-inline="no-display-inline" id="id4FA2363C68AE496F8403A867EEE5744A" style="OLC">
						<paragraph id="IDefdbf64ef1e546ab96a792ff52034c12"><enum>(7)</enum><text>the term
				<term>routine use</term> means, with respect to the disclosure of a record, the
				use of such record for a purpose which, as determined by the agency, is
				compatible with the purpose for which it was collected and is appropriate and
				reasonably necessary for the efficient and effective conduct of
				Government;</text>
						</paragraph><after-quoted-block>;
				and</after-quoted-block></quoted-block>
				</paragraph><paragraph id="id4CC410C9FACE438FB4309AD35256077E"><enum>(4)</enum><text>in paragraph
			 (8)(A)(i)—</text>
					<subparagraph id="id3FF6546D93BA47BDBC7BD1E7A116B2DC"><enum>(A)</enum><text>by striking
			 <quote>two or more automated systems of records or a system of records with
			 non-Federal records</quote> and inserting <quote>data from a system of
			 records</quote>;</text>
					</subparagraph><subparagraph id="idD709943866214B01AD0CE36697CD5822"><enum>(B)</enum><text>in subclause (I),
			 by inserting <quote>or State</quote> after <quote>Federal</quote>; and</text>
					</subparagraph><subparagraph id="id6041DA814245448AABD064FABF0854CB"><enum>(C)</enum><text>in subclause
			 (II), by inserting <quote>or State</quote> after <quote>Federal</quote>.</text>
					</subparagraph></paragraph></subsection><subsection id="id7A1EFFD8518B468CB731D9351F48646F"><enum>(b)</enum><header>Conditions of
			 disclosure</header><text>Section 552a(b) of title 5, United States Code, is
			 amended—</text>
				<paragraph id="idE9D9FDF9F8B747109CFE8BF2276FD401"><enum>(1)</enum><text>in paragraph (1),
			 by inserting <quote>that is consistent with, and related to, any purpose
			 described under subsection (e)(2)(D) of this section</quote> before the
			 semicolon;</text>
				</paragraph><paragraph id="idE37AA4BA00934DD7A038A778E27FBF2F"><enum>(2)</enum><text>in paragraph (3),
			 by striking <quote>(e)(4)(D)</quote> and inserting <quote>(e)(2)(D)(iv) or
			 subsection (v)</quote>;</text>
				</paragraph><paragraph id="idADAF882C3BE4423D9D785BD026CD3D49"><enum>(3)</enum><text>in paragraph (6),
			 by inserting <quote>or for records management inspections authorized by
			 statute</quote> before the semicolon;</text>
				</paragraph><paragraph id="idE1509DD40F8D49B5B9A8E5980C9D5C2C"><enum>(4)</enum><text>in paragraph (7),
			 by inserting <quote>, notwithstanding any requirements of a routine use as
			 defined under subsection (a)(7),</quote> before <quote>to another
			 agency</quote>;</text>
				</paragraph><paragraph id="id242B95A0C41B45E5A1F1834F1A972C91"><enum>(5)</enum><text>in paragraph (8),
			 by striking <quote>upon such disclosure notification is transmitted to the last
			 known address of such individual</quote> and inserting <quote>a reasonable
			 attempt to notify the individual is made promptly after the disclosure</quote>;
			 and</text>
				</paragraph><paragraph id="id0AB54404F0EF4A3E9AAE90776D53AE3F"><enum>(6)</enum><text>by striking
			 paragraph (9) and inserting the following:</text>
					<quoted-block display-inline="no-display-inline" id="idF799E5F28DC44ACD92F2ED6EA2E62D21" style="OLC">
						<paragraph id="id9AE337D924F640B78A75640E8310E9BB"><enum>(9)</enum><subparagraph commented="no" display-inline="yes-display-inline" id="id52FDD477DAF642379B33B6BCB0E4DE1F"><enum>(A)</enum><text>to either House of
				Congress;</text>
							</subparagraph><subparagraph id="id5C3785F59BA04CB18F9B60F92AA259A9" indent="up1"><enum>(B)</enum><text>to the extent of matter within its
				jurisdiction, any committee or subcommittee thereof, any joint committee of
				Congress or subcommittee of any such joint committee; or</text>
							</subparagraph><subparagraph id="idE28759508E1943FE980B1A49E5CA6253" indent="up1"><enum>(C)</enum><text>to the office of a Member of Congress
				when that office is requesting records about a specific individual on behalf of
				that individual in response to a written request for assistance by that
				individual;</text>
							</subparagraph></paragraph><after-quoted-block>.</after-quoted-block></quoted-block>
				</paragraph></subsection><subsection id="id5C990DAE6A68465CABEAD487585F4801"><enum>(c)</enum><header>Accounting of
			 certain disclosures</header><text>Section 552a(c) of title 5, United States
			 Code, is amended by inserting <quote>whether in an electronic or other
			 format</quote> after <quote>system of records under its control</quote>.</text>
			</subsection><subsection id="id5D605666EFE943E79DFC0D264666475C"><enum>(d)</enum><header>Agency
			 requirements</header><text>Section 552a of title 5, United States Code, is
			 amended by striking subsection (e) and inserting the following:</text>
				<quoted-block display-inline="no-display-inline" id="id556D1FE913A7408CA8F9224CAC6EA2AD" style="OLC">
					<subsection id="IDea359b33f75947ddbdc4b65b3362aee3"><enum>(e)</enum><header>Agency
				requirements</header>
						<paragraph id="ID16d2a3cc828e463b884287db66503554"><enum>(1)</enum><header>Authorized
				purpose</header><text>No agency shall use a record except for an authorized
				purpose and as maintained in a system of records under this section.</text>
						</paragraph><paragraph id="ID3a03e0182f744d34ab67f83f14e9df82"><enum>(2)</enum><header>Requirements</header><text>Each
				agency shall—</text>
							<subparagraph id="ID9c0ba8cb32544f3da1b0164d5ffd5ebb"><enum>(A)</enum><text>maintain in its
				records only such information about an individual as is relevant and necessary
				to accomplish any specified purpose of the agency required to be accomplished
				by statute or by executive order of the President, and only retain such
				information as long as is necessary to fulfill that purpose or as otherwise
				required by law;</text>
							</subparagraph><subparagraph id="ID12984891827d437185067e533c34dafe"><enum>(B)</enum><text>collect
				information to the greatest extent practicable directly from the subject
				individual when the information may result in adverse determinations about an
				individual’s rights, benefits, and privileges;</text>
							</subparagraph><subparagraph id="ID3e0b7002fff7445da511b332978457d3"><enum>(C)</enum><text>inform each
				individual whom it asks to supply information creating a record, at the time
				the information is requested—</text>
								<clause id="ID4cd9ade3b7134c8487def00a436674ee"><enum>(i)</enum><text>the authority
				(whether granted by statute or by executive order of the President) which
				authorizes the solicitation of the information and whether disclosure of such
				information is voluntary or required to receive a right, benefit, or
				privilege;</text>
								</clause><clause id="IDc853c6eb96944ba8a798b76d9fe9a2c9"><enum>(ii)</enum><text>the principal
				purpose or purposes for which the information is intended to be used;</text>
								</clause><clause id="ID892d30daecca43cc83e082cc25cf8153"><enum>(iii)</enum><text>the routine
				uses which may be made of the information, as published under subparagraph
				(D)(iv);</text>
								</clause><clause id="ID1e18eda36fec4b39a71ec96c7d3b4c9e"><enum>(iv)</enum><text>any effects on
				that individual of not providing all or any part of the requested
				information;</text>
								</clause><clause id="IDdb61e8bc66804e2ba8d4af15cef71524"><enum>(v)</enum><text>the procedures
				and contact information for accessing or correcting such information;
				and</text>
								</clause><clause id="ID81c373ae5eaa4997aaa0cfaa2c5ca256"><enum>(vi)</enum><text>a reference to
				learning how such information will be used or disclosed, including the simplest
				access to the current system of records notice;</text>
								</clause></subparagraph><subparagraph id="ID426ba01b6a2b4a308827e344b98deb39"><enum>(D)</enum><text>subject to the
				provisions of subparagraph (K), publish in the Federal Register, make broadly
				accessible to the public through a centralized website maintained by the Office
				of Management and Budget, and link to such centralized website from each
				agency’s website, upon establishment or revision a notice of the existence and
				character of the system of records, which notice shall include—</text>
								<clause id="ID634279116a924a179ed5d462ec47a81e"><enum>(i)</enum><text>the name and
				location of the system;</text>
								</clause><clause id="IDe200d57487e94b798781488389eaa84d"><enum>(ii)</enum><text>the categories
				of individuals on whom records are maintained in the system;</text>
								</clause><clause id="ID9701cba5c0e64955b10c5039e8c32edf"><enum>(iii)</enum><text>the categories
				of records maintained in the system;</text>
								</clause><clause id="IDca42ee2612b74fb58e10b7cd3ce46c86"><enum>(iv)</enum><text>any purpose for
				which the information is intended to be used, including each routine
				use;</text>
								</clause><clause id="IDa922d6cd52034de4ac447d34c5d7252f"><enum>(v)</enum><text>the legal
				authority for any purpose for which the information is utilized granted by
				statute, executive order, or other authorization;</text>
								</clause><clause id="ID3458a67e9efb4d6082bb86ba00278216"><enum>(vi)</enum><text>the policies and
				practices of the agency regarding storage, retrievability, access controls,
				retention, and disposal of the records;</text>
								</clause><clause id="ID30496574ccf54bd785ff1536edb4f1b9"><enum>(vii)</enum><text>the title and
				business address of the agency official who is responsible for the system of
				records;</text>
								</clause><clause id="ID85ebe381ec664258b0e589364c9ea142"><enum>(viii)</enum><text>the agency
				procedures whereby an individual can be notified at his request if the system
				of records contains a record pertaining to him, how he can gain access to such
				a record, or contest its content; and</text>
								</clause><clause id="ID29344d0d1c134ac59fe506a3faaafef4"><enum>(ix)</enum><text>the sources of
				records in the system;</text>
								</clause></subparagraph><subparagraph id="ID945d9c872a9f49efa7e10860e19c39ea"><enum>(E)</enum><text>to the greatest
				extent practicable, ensure that all records, including records from a third
				party source, which are used by the agency in making any determination about an
				individual are of such accuracy, relevance, timeliness, and completeness as is
				reasonably necessary to assure fairness to the individual in the determination,
				and upon request of the individual, provide documentation of the same;</text>
							</subparagraph><subparagraph id="ID0452248cea6e40fcbdb6cba55cb024c8"><enum>(F)</enum><text>prior to
				disseminating any record about an individual to any person other than an
				agency, unless the dissemination is made pursuant to subsection (b)(2) of this
				section, make reasonable efforts to assure that such records are accurate,
				complete, timely, and relevant for agency purposes;</text>
							</subparagraph><subparagraph id="ID4050da5078b04e688c1f562460c47923"><enum>(G)</enum><text>maintain no
				record describing how any individual exercises rights guaranteed by the First
				Amendment unless expressly authorized by statute or by the individual about
				whom the record is maintained or unless pertinent to, and within the scope of,
				an authorized law enforcement activity;</text>
							</subparagraph><subparagraph id="ID655cd705817745c5b618c70ee0ce5516"><enum>(H)</enum><text>make reasonable
				efforts to notify an individual as promptly as practicable after the agency
				receives compulsory legal process for any record on the individual, unless that
				notification is prohibited by law or court order;</text>
							</subparagraph><subparagraph id="ID99d37ba54deb4a26a732aa76dedbd5ef"><enum>(I)</enum><text>establish rules
				of conduct for persons involved in the design, development, operation, or
				maintenance of any system of records, or in maintaining any record, and
				instruct each such person with respect to such rules and the requirements of
				this section, including any other rules and procedures adopted pursuant to this
				section and the penalties for noncompliance;</text>
							</subparagraph><subparagraph id="IDd6209043775e482cbe1b48a0a12b8fc7"><enum>(J)</enum><text>establish
				appropriate administrative, technical, and physical safeguards to insure the
				security and confidentiality of records and to protect against any anticipated
				threats or hazards to their security or integrity which could result in
				substantial harm, embarrassment, inconvenience, or unfairness to any individual
				on whom information is maintained;</text>
							</subparagraph><subparagraph id="ID34ec75edb9274b45bdad2f4143a2e23d"><enum>(K)</enum><text>in regards to the
				establishment or revision of a system of records under subparagraph (D)—</text>
								<clause id="IDa575b7ab41b64db7afadfb097e3164ff"><enum>(i)</enum><text>at least 30 days
				prior to creation or modification of a system of records, publish the entire
				text of the proposed system of records notice in the Federal Register and on
				the centralized website established under subparagraph (D);</text>
								</clause><clause id="ID2ffca7cf4d554de5878d2c83a0834d6a"><enum>(ii)</enum><text>provide an
				opportunity for interested persons to submit written or electronic data, views,
				or arguments to the agency regarding the proposed system of records
				notice;</text>
								</clause><clause id="ID637cc8075a684df693bd7bbacfd07f30"><enum>(iii)</enum><text>within 180 days
				after publication of a proposed system of records notice, publish on the
				centralized website established under subparagraph (D), a response to the
				comments received, along with notice of whether the system of records notice as
				published has taken effect; and</text>
								</clause><clause id="id2E867F4DCB414C84A4F52E111885EED2"><enum>(iv)</enum><text>provide a link
				to the centralized website from the website of the agency,</text>
								</clause><continuation-text continuation-text-level="subparagraph">unless
				the Director of the Office of Management and Budget, through the Federal Chief
				Privacy Officer grants an exception, and that exception is published promptly
				in the Federal Register and on the centralized website established under
				subparagraph (D), including a link from the agency’s website;</continuation-text></subparagraph><subparagraph id="ID7d62b63a06b546dba1438a3087c9c4e4"><enum>(L)</enum><text>if such agency is
				a recipient agency or a source agency in a matching program with a non-Federal
				agency, with respect to any establishment or revision of a matching program, at
				least 30 days prior to conducting such program, publish in the Federal Register
				notice of such establishment or revision;</text>
							</subparagraph><subparagraph id="ID496389ed96224a898cdbe325f673887e"><enum>(M)</enum><text>shall—</text>
								<clause id="idC1CC5109885B4D45B984BAD62B87DAE1"><enum>(i)</enum><text>maintain an
				inventory on the number and scope of the systems of records of that agency in a
				manner that clearly and fairly describes activities of the agency to
				individuals; and</text>
								</clause><clause id="ID30b3e918896e4567be36d0c4917539bc"><enum>(ii)</enum><text>ensure that the
				inventory—</text>
									<subclause id="idCFF6ED2122444063B8B19B7DD64FA5E5"><enum>(I)</enum><text>is annually
				updated and published in the Federal Register, on the website established under
				subparagraph (D), and on the agency’s website; and</text>
									</subclause><subclause id="ID5c25a69f6b184c7e997daf04462cf536"><enum>(II)</enum><text>does not contain
				any information that would be exempted from disclosure under this section or
				section 522 of this title; and</text>
									</subclause></clause></subparagraph><subparagraph id="ID347bf1bf6c2b4672b928ff6ee71dfff3"><enum>(N)</enum><text>make reasonable
				efforts to limit disclosure from a system of records to minimum information
				necessary to accomplish the purpose of the
				disclosure.</text>
							</subparagraph></paragraph></subsection><after-quoted-block>.</after-quoted-block></quoted-block>
			</subsection><subsection id="id5C2EC0494C6849AAB1647042877FDA92"><enum>(e)</enum><header>Agency
			 rules</header><text>Section 552a(f) of title 5, United States Code, is amended
			 in the last sentence—</text>
				<paragraph id="id26B7256A5EB64A3FAEF33B640F41FCDC"><enum>(1)</enum><text>by striking
			 <quote>biennially</quote> and inserting <quote>annually</quote>;</text>
				</paragraph><paragraph id="id0F96731AA07C4F1CB3F15B76821BA603"><enum>(2)</enum><text>by striking
			 <quote>subsection (e)(4)</quote> and inserting <quote>subsection
			 (e)(2)(D)(iv)</quote>; and</text>
				</paragraph><paragraph id="id108ACAE358A8435FAE4757D31F314C9D"><enum>(3)</enum><text>by striking
			 <quote>at low cost</quote> and inserting <quote>electronically, or at low cost
			 physically</quote>.</text>
				</paragraph></subsection><subsection id="id466B151DD5D1422DBEDCDB0206734283"><enum>(f)</enum><header>Civil
			 remedies</header><text>Section 552a(g)(4) is amended—</text>
				<paragraph id="idBF0DF16FA94A41EDACBF3DB5D4A97EC0"><enum>(1)</enum><text>by inserting
			 <quote>and in which the complainant has substantially prevailed</quote> after
			 <quote>the agency acted in a manner which was intentional or willful</quote>;
			 and</text>
				</paragraph><paragraph id="idDAC1F7BB2D6D4D4D8A699B168CF43178"><enum>(2)</enum><text>in subparagraph
			 (A), by striking <quote>, but in no case shall a person entitled to recovery
			 receive less than the sum of $1,000</quote> and inserting <quote>or the sum of
			 $1,000, whichever is greater, except that in a class action the minimum for
			 each individual shall be reduced as necessary to ensure that the total recovery
			 in any class action or series of class actions arising out of the same refusal
			 or failure to comply by the same agency shall not be greater than
			 $10,000,000</quote>.</text>
				</paragraph></subsection><subsection id="id2F38797D161C426D8FF5D1EDAD334900"><enum>(g)</enum><header>Criminal
			 penalties</header><text>Section 552a(i) of title 5, United States Code, is
			 amended—</text>
				<paragraph id="idDDD1E8442CD34252A5112D31140784AC"><enum>(1)</enum><text>in paragraph
			 (1)—</text>
					<subparagraph id="idF45C1FBF39214A2CA298A6908AA69CE4"><enum>(A)</enum><text>by inserting
			 <quote>(A)</quote> before <quote>Any officer or employee</quote>; and</text>
					</subparagraph><subparagraph id="idC10E44E0C7AC45ABB29D27076FA85EAB"><enum>(B)</enum><text>by adding at the
			 end the following:</text>
						<quoted-block display-inline="no-display-inline" id="idE027A999B492475B99B88A41BD3134AB" style="OLC">
							<subparagraph id="ID4843caf596ff4d3c98130dfd2ac9e26c"><enum>(B)</enum><text>A person who
				commits the offense described under subparagraph (A) with the intent to sell,
				transfer, or use an agency record for commercial advantage, personal gain, or
				malicious harm shall be fined not more than $250,000, imprisoned for not more
				than 10 years, or both.</text>
							</subparagraph><after-quoted-block>;
				and</after-quoted-block></quoted-block>
					</subparagraph></paragraph><paragraph id="idF485CC287BC14140A292A8B3CDDD7289"><enum>(2)</enum><text>in paragraph (3),
			 by striking <quote>misdemeanor and fined not more than $5,000</quote> and
			 inserting <quote>felony and fined not more than $100,000, imprisoned for not
			 more than 5 years, or both</quote>.</text>
				</paragraph></subsection><subsection id="IDa97934305393466bb06bb0f7be730b1a"><enum>(h)</enum><header>General
			 exemptions</header><text>Section 552a(j) of title 5, United States Code, is
			 amended by striking <quote>The head of any agency</quote> and inserting
			 <quote>Notwithstanding any requirements of a routine use as defined under
			 subsection (a)(7), the head of any agency</quote>.</text>
			</subsection><subsection id="ID260b4278e9b64c8b8ef228109d6fcd84"><enum>(i)</enum><header>Specific
			 exemptions</header><text>Section 552a(k) of title 5, United States Code, is
			 amended by striking <quote>The head of any agency</quote> and inserting
			 <quote>Notwithstanding any requirements of a routine use as defined under
			 subsection (a)(7), the head of any agency</quote>.</text>
			</subsection><subsection id="id5C26810AECC74FAF8E2B8C3983CE0266"><enum>(j)</enum><header>Archival
			 records</header><text display-inline="yes-display-inline">Section 552a(l) of
			 title 5, United States Code, is amended in paragraphs (2) and (3) by striking
			 <quote>National Archives of the United States</quote> each place that term
			 appears and inserting <quote>National Archives and Records
			 Administration</quote>.</text>
			</subsection><subsection id="id45C258ACDA724CE3919CE28A7AD67CDE"><enum>(k)</enum><header>Government
			 contractors</header><text display-inline="yes-display-inline">Section 552(m)(1)
			 of title 5, United States Code, is amended by striking <quote>for the operation
			 by or on behalf of the agency of a system of records to accomplish an agency
			 function</quote> and inserting <quote>or other agreement, including with
			 another agency, for the maintenance of a system of records to accomplish an
			 agency function on behalf of the agency</quote>.</text>
			</subsection><subsection id="id55B79A34905849E09C039A1F770C27B3"><enum>(l)</enum><header>Office of
			 management and budget responsibilities</header><text display-inline="yes-display-inline">Section 552a(v) of title 5, United States
			 Code, is amended—</text>
				<paragraph id="id5768AE2A5BAC4A0FA66CAC826107BF8E"><enum>(1)</enum><text>in paragraph (1),
			 by striking <quote>and</quote> after the semicolon;</text>
				</paragraph><paragraph id="id81473350E28B47EA8D998FFD7DAF407B"><enum>(2)</enum><text>in paragraph (2),
			 by striking the period and inserting <quote>; and</quote>; and</text>
				</paragraph><paragraph id="idE59C62B6040946FFB9705884897C4D17"><enum>(3)</enum><text>by adding at the
			 end the following:</text>
					<quoted-block display-inline="no-display-inline" id="id9680207834D845488F5B905C7D6E13D4" style="OLC">
						<paragraph id="idF48F190B9FAE49B99A6A5B88B783E8CE"><enum>(3)</enum><text>establish and
				update a list of recommended standard routine
				uses.</text>
						</paragraph><after-quoted-block>.</after-quoted-block></quoted-block>
				</paragraph></subsection></section><section id="idC0BCF7A4F12C4639852CA509CA083C65"><enum>3.</enum><header>Amendments to
			 the E-Government Act of 2002</header><text display-inline="no-display-inline">Section 208 of the E-Government Act of 2002
			 (44 U.S.C. 3501 note; Public Law 107–347) is amended—</text>
			<paragraph id="id0F24AFB6C38D4EC4AE8F9AA5D2E53A30"><enum>(1)</enum><text>in subsection
			 (b)—</text>
				<subparagraph id="idF40E87FD55084E33B3BEA1A7D4B42AB2"><enum>(A)</enum><text>in paragraph
			 (1)(A)—</text>
					<clause id="ID2910f74df9d248c9adf9ab1eec68dfc3"><enum>(i)</enum><text>by
			 striking clause (i) and inserting the following:</text>
						<quoted-block display-inline="no-display-inline" id="id62AC4A8C522A443AA991CCB361F28B68" style="OLC">
							<clause id="id63E4F137C06B465FB0AB7F35EE544224"><enum>(i)</enum><text>developing,
				procuring, or otherwise making use of information technology that collects,
				maintains, or disseminates personally identifiable information;
				or</text>
							</clause><after-quoted-block>;</after-quoted-block></quoted-block>
					</clause><clause id="id220B06D83EF44A38B5A4FA579C7D3FA6"><enum>(ii)</enum><text>in
			 clause (ii)(II)—</text>
						<subclause id="idED4F9D4561BE4252A99B153F8BA148A1"><enum>(I)</enum><text>by striking
			 <quote>information in an identifiable form</quote> and inserting
			 <quote>personally identifiable information</quote>; and</text>
						</subclause><subclause id="id3F5BAF54CC324F6F97B5B4BF8F5D0F6D"><enum>(II)</enum><text>by striking
			 <quote>, other than agencies, instrumentalities, or employees of the Federal
			 Government.</quote> and inserting <quote>; and</quote>; and</text>
						</subclause></clause><clause id="idE998264437E5407BA8AAEB99F4E812EA"><enum>(iii)</enum><text>by adding at
			 the end the following:</text>
						<quoted-block display-inline="no-display-inline" id="idB99D3CD2576B40E6B67AA61BB172C644" style="OLC">
							<clause id="ID459462eb8a58403382c2e44b7db34851"><enum>(iii)</enum><text>using
				personally identifiable information purchased, or subscribed to for a fee, from
				a commercial data source.</text>
							</clause><after-quoted-block>;
				and</after-quoted-block></quoted-block>
					</clause></subparagraph><subparagraph id="id3FD30CDFFA5F4C59BE2A0F8A5A82BA64"><enum>(B)</enum><text>in paragraph
			 (2)(B)—</text>
					<clause id="id1A56D89533C44B49A5A9726221AB2950"><enum>(i)</enum><text>in
			 clause (i), by striking <quote>information that is in an identifiable
			 form</quote> and inserting <quote>personally identifiable information</quote>;
			 and</text>
					</clause><clause id="id038F464BC77048A69BC896607338BB26"><enum>(ii)</enum><text>in
			 clause (ii)—</text>
						<subclause id="id9A47733EC1F34EA19456AE686C4170D2"><enum>(I)</enum><text>in subclause
			 (VI), by striking <quote>and</quote> at the end;</text>
						</subclause><subclause id="id217A3BC6835A4CD79D7AB15255FF3465"><enum>(II)</enum><text>in subclause
			 (VII), by striking the period and inserting <quote>; and</quote>; and</text>
						</subclause><subclause id="idFBEF3A9962F04DD5A2FFCD5C10C7EAA2"><enum>(III)</enum><text>by adding at
			 the end the following:</text>
							<quoted-block display-inline="no-display-inline" id="id2C1B0E46A2F14DC8A09D1C62F5E2FA79" style="OLC">
								<subclause id="ID8cc429359c154ca5a644fb2a3a846bb8"><enum>(VIII)</enum><text>to what extent
				risks to privacy protection are created by the use of the information and what
				steps have been taken to mitigate such
				risks.</text>
								</subclause><after-quoted-block>;
				and</after-quoted-block></quoted-block>
						</subclause></clause></subparagraph></paragraph><paragraph id="idA31C5DEB93E54D1593EB45C6E3252C5E"><enum>(2)</enum><text>by striking
			 subsection (d) and inserting the following:</text>
				<quoted-block display-inline="no-display-inline" id="idBCB0F8FDF16F47749AC671CDBC61C579" style="OLC">
					<subsection id="id30E4226131794E9A92BDAEA7123FEC6D"><enum>(d)</enum><header>Definition</header><text>In
				this section, the term <term>personally identifiable information</term> means
				any information about an individual maintained by an agency, including—</text>
						<paragraph id="id7018657894454F64A57945155206E694"><enum>(1)</enum><text>any information
				that can be used to distinguish or trace an individual’s identity, such as
				name, social security number, date and place of birth, mother’s maiden name, or
				biometric records; or</text>
						</paragraph><paragraph id="id86874E1BFDB44A598F9E8CAFBB6B5BE3"><enum>(2)</enum><text>any other
				information that is linked or linkable to an individual, such as medical,
				educational, financial, and employment
				information.</text>
						</paragraph></subsection><after-quoted-block>.</after-quoted-block></quoted-block>
			</paragraph></section><section id="idD340A410E83641499DDB2A6CC39E3991"><enum>4.</enum><header>Amendments to
			 chapters 35 and 36 of title 44, United States Code</header>
			<subsection id="id7B1D371F70F249E4873B4307BF7C5333"><enum>(a)</enum><header>Office of
			 Management and Budget</header><text>Section 3504 of title 44, United States
			 Code, is amended—</text>
				<paragraph id="id1F9B85B3D4854C85B9269E202C886F61"><enum>(1)</enum><text>in subsection
			 (a)(1)(A)—</text>
					<subparagraph id="id34DA71FA6F664386B3A631F205A839C0"><enum>(A)</enum><text>in clause (iv),
			 by inserting <quote>and</quote> after the semicolon;</text>
					</subparagraph><subparagraph id="id8E1D0CD507804191B81FEB3D9AADB315"><enum>(B)</enum><text>by striking
			 clause (v); and</text>
					</subparagraph><subparagraph id="id4B53544588914DE8B6A46F71928C58BE"><enum>(C)</enum><text>by redesignating
			 clause (vi) as clause (v);</text>
					</subparagraph></paragraph><paragraph id="id30EFF3F88FE34EA4AF4976D290D5A55F"><enum>(2)</enum><text>by striking
			 subsection (g); and</text>
				</paragraph><paragraph id="idA3E8DDEC63BB4B8D88D6A50D0E0127BC"><enum>(3)</enum><text>by redesignating
			 subsection (h) as subsection (g).</text>
				</paragraph></subsection><subsection id="idAED00958B17F43D480BAC2E7DA44346A"><enum>(b)</enum><header>Federal
			 information privacy policy</header>
				<paragraph id="id491C3B92577E48A89B164AE28C08DCE4"><enum>(1)</enum><header>In
			 general</header><text>Chapter 35 of title 44, United States Code, is amended by
			 adding at the end the following:</text>
					<quoted-block display-inline="no-display-inline" id="idEAAD3D8065C3460CAD2873E91309FCD6" style="USC">
						<subchapter id="idF61C9752935F4E0C992B9DB3B74C6FEE"><enum>IV</enum><header>Federal
				information privacy policy</header>
							<section id="id493F6950A97E453E8F41479E0EB1FEAF"><enum>3561.</enum><header>Purposes</header><text display-inline="no-display-inline">The purposes of this subchapter are
				to—</text>
								<paragraph id="IDd4e1c2533009482ca0698d144651d88f"><enum>(1)</enum><text>ensure the
				consistent application of privacy protections to personally identifiable
				information collected, maintained, and used by all agencies;</text>
								</paragraph><paragraph id="ID540e4347c29246f7bd0916d193a05022"><enum>(2)</enum><text>strengthen the
				responsibility and accountability of the Office of Management and Budget for
				overseeing privacy protection in agencies;</text>
								</paragraph><paragraph id="ID915d9ce9c58f4bbcb0ca14dbb48ab29b"><enum>(3)</enum><text>improve agency
				responses to privacy breaches to better inform and protect the public from the
				misuse of personally identifiable information;</text>
								</paragraph><paragraph id="ID55a925273f6f4c2fbdd58abd77424186"><enum>(4)</enum><text>strengthen the
				responsibility and accountability of agency officials for ensuring effective
				implementation of privacy protection requirements; and</text>
								</paragraph><paragraph id="IDac1146284edc4239af5100c93946a2a3"><enum>(5)</enum><text>ensure that
				agency use of commercial sources of information and information system services
				provides adequate information security and privacy protections.</text>
								</paragraph></section><section id="ID55c07cfaef984f5caa3d90c75be8cf3a"><enum>3562.</enum><header>Definitions</header>
								<subsection id="IDb29ee2ea5f04412f81342b22a1a6a133"><enum>(a)</enum><header>In
				general</header><text>Except as provided under subsection (b), the definitions
				under section 3502 shall apply to this subchapter.</text>
								</subsection><subsection id="ID427c2f62150a4a3db224bf8a49e519ee"><enum>(b)</enum><header>Additional
				definitions</header><text>In this subchapter—</text>
									<paragraph id="id8B3AB8E7B3E24EBE8C174073B20D7E3D"><enum>(1)</enum><text>the term
				<term>Council</term> means the Chief Privacy Officers Council established under
				section 3567;</text>
									</paragraph><paragraph id="ID62f9aaf3cab94fda859ecb3290b7725b"><enum>(2)</enum><text>the term
				<term>personally identifiable information</term> means any information about an
				individual maintained by an agency, including—</text>
										<subparagraph id="id335019FDC2354B218E305E127E637A12"><enum>(A)</enum><text>any information
				that can be used to distinguish or trace an individual’s identity, such as
				name, social security number, date and place of birth, mother’s maiden name, or
				biometric records; and</text>
										</subparagraph><subparagraph id="id9120D43ACEC248228024FA8B83B3BDBC"><enum>(B)</enum><text>any other
				information that is linked or linkable to an individual, such as medical,
				educational, financial, and employment information; and</text>
										</subparagraph></paragraph><paragraph id="ID6f2043dad841447ca744e6c90efb7e93"><enum>(3)</enum><text>the term
				<term>data broker</term> means a person or entity that for a fee regularly
				engages in the practice of collecting, transmitting, or providing access to
				personally identifiable information concerning more than 5,000 individuals who
				are not the customers or employees of that person or entity (or an affiliated
				entity) primarily for the purposes of providing such information to
				non-affiliated third parties on an interstate basis.</text>
									</paragraph></subsection></section><section id="ID684ab144480340d28aaa7c5aa2d6718d"><enum>3563.</enum><header>Authority and
				functions of the Director</header>
								<subsection id="ID3ed0e55676a64ea884b90fc54fc24358"><enum>(a)</enum><text>In fulfilling the
				responsibility to administer the functions assigned under subchapter I, the
				Director of the Office of Management and Budget shall comply with this
				subchapter with respect to the specific matters covered by this
				subchapter.</text>
								</subsection><subsection id="id3DBFC64CAEC24F1584C20557ACC347B0"><enum>(b)</enum><text>The Director
				shall oversee agency privacy protection policies and practices, including
				by—</text>
									<paragraph id="IDfe022a40c95249c2bb76ecc1ff94604b"><enum>(1)</enum><text>developing and
				overseeing the implementation of policies, principles, standards, and
				guidelines on privacy protection;</text>
									</paragraph><paragraph id="ID04ddcb47bd49414db8889ac55b399d74"><enum>(2)</enum><text>providing
				direction and overseeing privacy, confidentiality, security, disclosure, and
				sharing of information;</text>
									</paragraph><paragraph id="ID89252f3a4ea845219351014fec6df4d2"><enum>(3)</enum><text>overseeing agency
				compliance with laws relating to privacy protection, including the requirements
				of this subchapter, section 552a of title 5 (commonly referred to as the
				Privacy Act), and section 208 of the E-Government Act of 2002;</text>
									</paragraph><paragraph id="IDd4b4e0efdbe14fc2974184eacfe1405d"><enum>(4)</enum><text>coordinating
				privacy protection policies and procedures with related information resources
				management policies and procedures, including through ensuring that privacy
				protection considerations are taken into account in managing the collection of
				information and the control of paperwork as provided under subchapter I;
				and</text>
									</paragraph><paragraph id="id4EC05B7663A54D24A6DDC1155AD0B022"><enum>(5)</enum><text>appointing a
				Federal Chief Privacy Officer under section 3564.</text>
									</paragraph></subsection></section><section id="IDf2ef51ae45cc4afd8dabc1e75da814a5"><enum>3564.</enum><header>Specific
				responsibilities of the Federal Chief Privacy Officer</header>
								<subsection commented="no" id="ID6e15ed830f72413b86d4e772921f040d"><enum>(a)</enum><header>Federal Chief
				Privacy Officer</header>
									<paragraph id="id30256F9D4E3F4BD2A5819E91B6A8A14E"><enum>(1)</enum><header>Definitions</header><text>In
				this section—</text>
										<subparagraph id="id7E1B77F3DC5C459CBF6F51A808E004B6"><enum>(A)</enum><text>the term
				<term>Senior Executive Service position</term> has the meaning given under
				section 3132(a)(2) of title 5; and</text>
										</subparagraph><subparagraph id="id7B90E961F10646CE8624FF9B057423DF"><enum>(B)</enum><text>the term
				<term>noncareer appointee</term> has the meaning given under section 3132(a)(7)
				of title 5.</text>
										</subparagraph></paragraph><paragraph commented="no" id="id3D579E6D7E5044AC80E821EB410F7633"><enum>(2)</enum><header>Establishment</header><text>There
				is established the position of the Federal Chief Privacy Officer within the
				Office of Management and Budget. The position shall be a Senior Executive
				Service position. The Director shall appoint a noncareer appointee to the
				position. The primary responsibilities of the position shall be the
				responsibilities under subsection (b).</text>
									</paragraph><paragraph commented="no" id="idB79CE9AB4BC346269A184401495C7823"><enum>(3)</enum><header>Qualifications</header><text>The
				individual appointed to be the Federal Chief Privacy Officer shall possess
				demonstrated expertise in privacy protection policy and Government
				information.</text>
									</paragraph></subsection><subsection commented="no" id="idC4895AEE403C490ABD51A20136951FA9"><enum>(b)</enum><header>Responsibilities</header><text>The
				Federal Chief Privacy Officer shall—</text>
									<paragraph id="ID185100cfbe144b7fa82481818e1bf78d"><enum>(1)</enum><text>carry out the
				responsibilities of the Director under this subchapter;</text>
									</paragraph><paragraph id="IDc77d83fb83d24ae39551f49e8c599c76"><enum>(2)</enum><text>provide overall
				direction, consistent with the Office of Management and Budget guidance,
				section 552a of title 5 (commonly referred to as the Privacy Act), and section
				208 of the E-Government Act of 2002, of privacy policy governing the Federal
				Government’s collection, use, sharing, disclosure, transfer, storage, security,
				and disposition of personally identifiable information;</text>
									</paragraph><paragraph id="idA5D165DA46774BB789753ED02F08BB99"><enum>(3)</enum><text>to the extent
				that the Federal Chief Privacy Officer considers appropriate, establish
				procedures to review and approve privacy documentation before public
				dissemination;</text>
									</paragraph><paragraph id="ID514aeb7dc9fc4728875b417437c29dec"><enum>(4)</enum><text>serve as the
				principal advisor for Federal privacy policy matters to the Executive Office of
				the President, including the President, the Director, the National Security
				Council, the Homeland Security Council, and the Office of Science and
				Technology Policy;</text>
									</paragraph><paragraph id="ID8a02967325c540d78aae86cdc66e42a5"><enum>(5)</enum><text>coordinate with
				the Privacy and Civil Liberties Oversight Board established under section 1061
				of the Intelligence Reform and Terrorism Prevention Act of 2004 (5 U.S.C. 601
				note); and</text>
									</paragraph><paragraph id="ID546a5e72736c42f8b6ace092fd5637de"><enum>(6)</enum><text>every 2 years
				submit a report to Congress on the protection of privacy by the United States
				Government, including the status of implementation of requirements under this
				subchapter and other privacy related laws and policies.</text>
									</paragraph></subsection></section><section id="ID668e7f3f97524d4aa782f65508841a48"><enum>3565.</enum><header>Privacy
				breach requirements</header><text display-inline="no-display-inline">The
				Director shall establish and oversee policies and procedures for agencies to
				follow in the event of a breach of information security involving the
				disclosure of personally identifiable information and for which harm to an
				individual could reasonably be expected to result, including—</text>
								<paragraph id="ID4a75f3aa29ec4ee9a16a7b11efbfab2f"><enum>(1)</enum><text>a requirement for
				timely notice to be provided to those individuals whose personally identifiable
				information could be compromised as a result of such breach, except no notice
				shall be required if the breach does not create a reasonable risk of identity
				theft, fraud, or other unlawful conduct regarding such individual;</text>
								</paragraph><paragraph id="IDdaa6868ba37941f99941b430573c9aba"><enum>(2)</enum><text>guidance on
				determining how timely notice is to be provided;</text>
								</paragraph><paragraph id="ID83a2b3dd97f74af0b5c14d925982db17"><enum>(3)</enum><text>guidance
				regarding whether additional actions are necessary and appropriate, including
				data breach analysis, fraud resolution services, identity theft insurance, and
				credit protection or monitoring services; and</text>
								</paragraph><paragraph id="ID2b344d64af8a4ad79ecdb47202deeb77"><enum>(4)</enum><text>requirements for
				timely reporting by the agencies of such breaches to the director and the
				Federal information security incident center referred to in section
				3546.</text>
								</paragraph></section><section id="ID8d298b9ca8564c49931d8bab6a9b8395"><enum>3566.</enum><header>Agency
				responsibilities</header>
								<subsection id="idD5D46BCCD4C04891842F39BB3D6918E2"><enum>(a)</enum><header>In
				general</header><text display-inline="yes-display-inline">In addition to
				requirements under section 1062 of the National Security Intelligence Reform
				Act of 2004, and in fulfilling the responsibilities under section 3506(g), the
				head of each agency shall ensure compliance with laws relating to privacy
				protection, including the requirements of this subchapter, section 552a of
				title 5 (commonly referred to as the Privacy Act), and section 208 of the
				E-Government Act of 2002.</text>
								</subsection><subsection id="idCB9BDE8104FB4BB79B8137297FCE1487"><enum>(b)</enum><header>Chief Privacy
				Officers</header><text display-inline="yes-display-inline">In the case of an
				agency that has not designated a Chief Privacy Officer under section 522 of the
				Transportation, Treasury, Independent Agencies and General Government
				Appropriations Act, 2005 (42 U.S.C. 2000ee–2), the head of each agency
				shall—</text>
									<paragraph id="id901E049E745E4EBB850D53C29C9AE24A"><enum>(1)</enum><text>designate a
				senior official to be the chief privacy officer of that agency; and</text>
									</paragraph><paragraph id="ID3a9670b440c546b0ac8f086630673eac"><enum>(2)</enum><text>provide to the
				chief privacy officer such information as the officer considers
				necessary.</text>
									</paragraph></subsection><subsection id="idE0889C242D49405E8E5051BD74354F33"><enum>(c)</enum><header>Responsibilities
				of agency chief privacy officer</header><text>Each chief privacy officer shall
				have primary responsibility for assuring the adequacy of privacy protections
				for personally identifiable information collected, used, or disclosed by the
				agency, including—</text>
									<paragraph id="ID67d5b66818e1466f940ff2f32d0bb141"><enum>(1)</enum><text>ensuring that the
				use of technologies sustain, and do not erode, privacy protections relating to
				the use, collection, and disclosure of personal information, including through
				the conduct of privacy impact assessments as provided by section 208 of the
				E-Government Act of 2002;</text>
									</paragraph><paragraph id="ID2924734371ce4a168796091c8acc5a13"><enum>(2)</enum><text>ensuring that
				personal information is handled in full compliance with fair information
				practices under section 552a of title 5 (commonly referred to as the Privacy
				Act) and other applicable laws and policies;</text>
									</paragraph><paragraph id="ID6857ab4d987247dcbc9a3d99839bb480"><enum>(3)</enum><text>evaluating
				legislative and regulatory proposals involving collection, use, and disclosure
				of personally identifiable information;</text>
									</paragraph><paragraph id="IDe0cc9daf93184f6bbdc4e222a746dd45"><enum>(4)</enum><text>coordinating with
				the chief information officer to ensure that privacy is adequately addressed in
				the agency information security program, established under section 3544;</text>
									</paragraph><paragraph id="ID25c5528896b94e1c8b1f79e893ca891e"><enum>(5)</enum><text>coordinating with
				other senior officials to ensure programs, policies, and procedures involving
				civil rights, civil liberties, and privacy considerations addressed in an
				integrated and comprehensive manner; and</text>
									</paragraph><paragraph id="IDce434b5faba64b0eaac6373b2d517a78"><enum>(6)</enum><text>reporting
				periodically to the head of the agency on agency privacy protection
				activities.</text>
									</paragraph></subsection></section><section id="ID9ffa1b3b0339462daba861304394433a"><enum>3567.</enum><header>Chief Privacy
				Officers Council</header>
								<subsection id="ID3d282ecc079c4aa7a274980a416f66d9"><enum>(a)</enum><header>Establishment</header><text>There
				is established in the executive branch a Chief Privacy Officers Council.</text>
								</subsection><subsection id="ID01dc638c289849b0b18112e61bb60ff7"><enum>(b)</enum><header>Membership</header>
									<paragraph id="id509627B20EAB43C086C60ED54C329AD5"><enum>(1)</enum><header>In
				general</header><text>The members of the Council shall be as follows:</text>
										<subparagraph id="ID03e549c20f0d49c6859c78762b534b62"><enum>(A)</enum><text>The Federal Chief
				Privacy Officer, who shall serve as chairperson of the Council.</text>
										</subparagraph><subparagraph id="ID384927079a8a44338bc4d9d783428b05"><enum>(B)</enum><text>Chief Privacy
				Officers established under section 522 of division H of the Consolidated
				Appropriations Act, 2005 (42 U.S.C. 2000ee–2; Public Law 108–447).</text>
										</subparagraph><subparagraph id="ID5f152a9048e74956a36d5af8d88373ce"><enum>(C)</enum><text>The chairperson
				of the Privacy and Civil Liberties Oversight Board.</text>
										</subparagraph><subparagraph id="ID14a62f5195fe46f989aaf643bb77d7fd"><enum>(D)</enum><text>As designated by
				the chairperson of the Council, any senior agency official designated to be a
				chief privacy officer under section 3566.</text>
										</subparagraph><subparagraph id="ID3a2f7e4212a0415696abfc139f9e0e53"><enum>(E)</enum><text>The Administrator
				of the Office of Electronic Government, as an ex-officio member.</text>
										</subparagraph><subparagraph id="ID54e83dd31a19482b9ef480e03a62cc65"><enum>(F)</enum><text>The Administrator
				of the Office of Information and Regulatory Affairs, as an ex-officio
				member.</text>
										</subparagraph><subparagraph id="ID32bbf403e37443a8ae831cb4efb9d705"><enum>(G)</enum><text>Any other officer
				or employee of the United States designated by the chairperson.</text>
										</subparagraph></paragraph><paragraph id="id5F06EDF27B1D47DAB0C78EA754621F39"><enum>(2)</enum><header>Ex-officio
				members</header><text>An ex-officio member may not vote in Council
				proceedings.</text>
									</paragraph></subsection><subsection id="ID7932c90c90db44fcba8b642ef54476dc"><enum>(c)</enum><header>Administrative
				support</header><text>The Administrator of the General Services shall provide
				administrative and other support for the Council.</text>
								</subsection><subsection id="IDcb748dec18ff426eb86ba50c5e103e8f"><enum>(d)</enum><header>Functions</header><text>The
				Council shall—</text>
									<paragraph id="idB71819FDB57D42FABD2CF50FABC07577"><enum>(1)</enum><text>be an interagency
				forum for establishing best practices for agency privacy policy;</text>
									</paragraph><paragraph id="ID5f8a7a931ac94b20ae4bd893128cd076"><enum>(2)</enum><text>share, and
				promote the development of, best practices to assure that the use of
				technologies sustains, and does not erode, privacy protections relating to the
				use, collection, and disclosure of personal information; assure that personal
				information contained in systems of records are handled in full compliance with
				fair information practices; and evaluate legislative and regulatory proposals
				involving collection, use, and disclosure of personal information by the
				Federal Government; and</text>
									</paragraph><paragraph id="IDb81e1d77d98544b3a96a7ecc0d4e6c16"><enum>(3)</enum><text>submit proposed
				improvements to privacy practices to the
				Director.</text>
									</paragraph></subsection></section></subchapter><after-quoted-block>.</after-quoted-block></quoted-block>
				</paragraph><paragraph id="id22F1763043A746F5BFF1B3A869CC916D"><enum>(2)</enum><header>Technical and
			 conforming amendment</header><text>The table of sections for chapter 35 of
			 title 44, United States Code, is amended by adding at the end the
			 following:</text>
					<quoted-block id="id3e3e8a8c-509c-4326-9cec-3d2075fff494" style="USC">
						<toc>
							<toc-entry idref="idF61C9752935F4E0C992B9DB3B74C6FEE" level="subchapter">SUBCHAPTER IV—Federal information privacy policy</toc-entry>
							<toc-entry level="section">Sec. </toc-entry>
							<toc-entry idref="id493F6950A97E453E8F41479E0EB1FEAF" level="section">3561. Purposes.</toc-entry>
							<toc-entry idref="ID55c07cfaef984f5caa3d90c75be8cf3a" level="section">3562. Definitions.</toc-entry>
							<toc-entry idref="ID684ab144480340d28aaa7c5aa2d6718d" level="section">3563. Authority and functions of the Director.</toc-entry>
							<toc-entry idref="IDf2ef51ae45cc4afd8dabc1e75da814a5" level="section">3564. Specific responsibilities of the Chief Privacy
				Officer.</toc-entry>
							<toc-entry idref="ID668e7f3f97524d4aa782f65508841a48" level="section">3565. Privacy breach requirements.</toc-entry>
							<toc-entry idref="ID8d298b9ca8564c49931d8bab6a9b8395" level="section">3566. Agency responsibilities.</toc-entry>
							<toc-entry idref="ID9ffa1b3b0339462daba861304394433a" level="section">3567. Chief Privacy Officers
				Council.</toc-entry>
						</toc>
						<after-quoted-block>.</after-quoted-block></quoted-block>
				</paragraph></subsection><subsection id="id1F6BBB8544C54742BFDCDBB781E760B8"><enum>(c)</enum><header>Electronic
			 Government</header><text display-inline="yes-display-inline">Section 3602(d) of
			 title 44, United States Code, is amended by inserting <quote>and the Federal
			 Chief Privacy Officer</quote> after <quote>Information and Regulatory
			 Affairs</quote>.</text>
			</subsection></section><section id="ID471a766ef5de4420a4d27afad28542e9"><enum>5.</enum><header>Amendments to
			 section 1062 of the National Intelligence Reform Act of 2004</header><text display-inline="no-display-inline">Section 1062 of the National Intelligence
			 Reform Act of 2004 (42 U.S.C. 2000ee–1) is amended—</text>
			<paragraph id="idFA9903B4A7F54F09A0569825990EB3AF"><enum>(1)</enum><text display-inline="yes-display-inline">by redesignating subsection (d) through (h)
			 as subsections (e) through (i); and</text>
			</paragraph><paragraph id="id2F4483278ADF4AC8A22321636D54113C"><enum>(2)</enum><text>by striking
			 subsection (c) and inserting the following:</text>
				<quoted-block display-inline="no-display-inline" id="idAC351DDECFC44E31B3D40FEDB53D8EAA" style="OLC">
					<subsection id="IDa038042e74504a55ab6ef5efa6acafe0"><enum>(c)</enum><header>Authority To
				Investigate</header>
						<paragraph id="ID95b4f7e0105a45c18f0a88895201435a"><enum>(1)</enum><header>In
				general</header><text>Each privacy officer or civil liberties officer described
				under subsection (a) or (b) may—</text>
							<subparagraph id="ID147d7d4c830c4ac18614cff93780130b"><enum>(A)</enum><text>have access to
				all records, reports, audits, reviews, documents, papers, recommendations, and
				other materials available to the Department, agency, or element of the
				executive branch that relate to programs and operations with respect to the
				responsibilities of the senior official under this section;</text>
							</subparagraph><subparagraph id="ID41e0b5135e7f40eba1d586fc8d3a05ca"><enum>(B)</enum><text>make such
				investigations and reports relating to the administration of the programs and
				operations of the Department, agency, or element of the executive branch as
				are, in the senior official's judgment, necessary or desirable;</text>
							</subparagraph><subparagraph id="IDcd0e75c02b4c418891c7c10b8a5a3fb2"><enum>(C)</enum><text>subject to the
				approval of the Secretary or head of the agency or element of the executive
				branch, require by subpoena the production, by any person other than a Federal
				agency, of all information, documents, reports, answers, records, accounts,
				papers, and other data and documentary evidence necessary to performance of the
				responsibilities of the senior official under this section; and</text>
							</subparagraph><subparagraph id="IDe0ba9de6711a44f59e07f4f35d2e5ebe"><enum>(D)</enum><text>administer to or
				take from any person an oath, affirmation, or affidavit, whenever necessary to
				performance of the responsibilities of the senior official under this
				section.</text>
							</subparagraph></paragraph><paragraph id="ID1de1501514af4dc28a97933834a8dc37"><enum>(2)</enum><header>Enforcement of
				subpoenas</header><text>Any subpoena issued under paragraph (1)(C) shall, in
				the case of contumacy or refusal to obey, be enforceable by order of any
				appropriate United States district court.</text>
						</paragraph><paragraph id="ID43d80450f549441bbe4e39003cb800d7"><enum>(3)</enum><header>Effect of
				oaths</header><text>Any oath, affirmation, or affidavit administered or taken
				under paragraph (1)(D) by or before an employee of the Privacy Office
				designated for that purpose by the senior official appointed under subsection
				(a) shall have the same force and effect as if administered or taken by or
				before an officer having a seal of office.</text>
						</paragraph></subsection><subsection id="IDb6c2b58368874b32ab49e2c106efea73"><enum>(d)</enum><header>Supervision and
				coordination</header>
						<paragraph id="ID3027cc009cd6424c8f084b019a10b519"><enum>(1)</enum><header>In
				general</header><text>Each privacy officer or civil liberties officer described
				under subsection (a) or (b) shall—</text>
							<subparagraph id="IDa91231bc072f43e8bd453abcab24e56e"><enum>(A)</enum><text>report to, and be
				under the general supervision of, the Secretary; and</text>
							</subparagraph><subparagraph id="IDc42d90fb6a6e4eeb842e9b71d5cae122"><enum>(B)</enum><text>coordinate
				activities with the Inspector General of the Department in order to avoid
				duplication of effort.</text>
							</subparagraph></paragraph><paragraph id="ID8e187322bd3c4b089dcca942736b2c35"><enum>(2)</enum><header>Coordination
				with the Inspector General</header>
							<subparagraph id="ID2c5b687a2de147e080575ec839b7fc4e"><enum>(A)</enum><header>In
				general</header><text>Except as provided in subparagraph (B), the senior
				official appointed under subsection (a) may investigate any matter relating to
				possible violations or abuse concerning the administration of any program or
				operation of the Department, agency, or element of the executive branch
				relevant to the purposes under this section.</text>
							</subparagraph><subparagraph id="ID71efbfd7215e473f9d924901ad32da9d"><enum>(B)</enum><header>Coordination</header>
								<clause id="ID01a0bbbedbc94050ac0ff73ed8df6bd9"><enum>(i)</enum><header>Referral</header><text>Before
				initiating any investigation described under subparagraph (A), the senior
				official shall refer the matter and all related complaints, allegations, and
				information to the Inspector General of the Department, agency, or element of
				the executive branch.</text>
								</clause><clause id="ID10f39ca5c7a54f6086eae17cda32e67f"><enum>(ii)</enum><header>Determinations
				and notifications by the Inspector General</header><text>Not later than 30 days
				after the receipt of a matter referred under clause (i), the Inspector General
				shall—</text>
									<subclause id="ID5cc887838b9f4e54a5fa3a0bc6290f73"><enum>(I)</enum><text>make a
				determination regarding whether the Inspector General intends to initiate an
				audit or investigation of the matter referred under clause (i); and</text>
									</subclause><subclause id="ID65408346c55e4e738331cbfe6edd0047"><enum>(II)</enum><text>notify the
				senior official of that
				determination.</text>
									</subclause></clause></subparagraph></paragraph></subsection><after-quoted-block>.</after-quoted-block></quoted-block>
			</paragraph></section></legis-body>
</bill>
