<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="ID11E55BED66C34EAB90BC9614C5956EB4" public-private="public">
	<form>
		<distribution-code display="yes">II</distribution-code>
		<congress>112th CONGRESS</congress>
		<session>1st Session</session>
		<legis-num>S. 799</legis-num>
		<current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber>
		<action>
			<action-date date="20110412">April 12, 2011</action-date>
			<action-desc><sponsor name-id="S173">Mr. Kerry</sponsor> (for himself
			 and <cosponsor name-id="S197">Mr. McCain</cosponsor>) introduced the following
			 bill; which was read twice and referred to the
			 <committee-name committee-id="SSCM00">Committee on Commerce, Science, and
			 Transportation</committee-name></action-desc>
		</action>
		<legis-type>A BILL</legis-type>
		<official-title>To establish a regulatory framework for the comprehensive
		  protection of personal data for individuals under the aegis of the Federal
		  Trade Commission, and for other purposes.</official-title>
	</form>
	<legis-body id="ID96DDA9590D1E49318C09BB6171DF7FE8" style="OLC">
		<section id="ID08AE9AD04BEF4694AFB2FCDD32E5F7A2" section-type="section-one"><enum>1.</enum><header>Short title; table of
			 contents</header>
			<subsection id="IDDD8A2E788C7745A28C060308F8549D0D"><enum>(a)</enum><header>Short
			 title</header><text>This Act may be cited as the <quote><short-title>Commercial Privacy Bill of Rights Act of
			 2011</short-title></quote>.</text>
			</subsection><subsection id="ID16A614E503BA4BC780A3F42AA0B95B7F"><enum>(b)</enum><header>Table of
			 contents</header><text>The table of contents for this Act is as follows:</text>
				<toc>
					<toc-entry idref="ID08AE9AD04BEF4694AFB2FCDD32E5F7A2" level="section">Sec. 1. Short title; table of contents.</toc-entry>
					<toc-entry idref="ID1CBE799910FD4334B0BBFC318C672A95" level="section">Sec. 2. Findings.</toc-entry>
					<toc-entry idref="IDDC7640A1B70B48E49F7869BF33FC4144" level="section">Sec. 3. Definitions.</toc-entry>
					<toc-entry idref="IDB46BEDB6A323470392A46C0B59D19D0D" level="title">TITLE I—Right to security and accountability</toc-entry>
					<toc-entry idref="ID4CA46AD4F32144588E586685256010E1" level="section">Sec. 101. Security.</toc-entry>
					<toc-entry idref="ID9A265885F4F441E5A9BC71CB5E6D617E" level="section">Sec. 102. Accountability.</toc-entry>
					<toc-entry idref="id97DDB8DF897749B3B63484D6108CC741" level="section">Sec. 103. Privacy by design.</toc-entry>
					<toc-entry idref="ID825DDA0E130B4886A879AD488CFA0B1A" level="title">TITLE II—Right to notice and individual participation</toc-entry>
					<toc-entry idref="IDA181E5162B2F4EC2AE67BC9BF9F86AD2" level="section">Sec. 201. Transparent notice of practices and
				purposes.</toc-entry>
					<toc-entry idref="ID637E5D16C8B14E9880943F341077075F" level="section">Sec. 202. Individual participation.</toc-entry>
					<toc-entry idref="ID717DCBA4EDEC49FCB66D8829E3C996F7" level="title">TITLE III—Rights relating to data minimization, constraints on
				distribution, and data integrity</toc-entry>
					<toc-entry idref="idF795DB6B50244DC5A08619E2FACEDE64" level="section">Sec. 301. Data minimization.</toc-entry>
					<toc-entry idref="ID3E9F4EBB04E44525912351CF7D0E25F0" level="section">Sec. 302. Constraints on distribution of
				information.</toc-entry>
					<toc-entry idref="ID0A5C0D8973EB4C0B80D5538494BC8D2D" level="section">Sec. 303. Data integrity.</toc-entry>
					<toc-entry idref="IDB55C089BDF6B4CA2BA22D13C1581D668" level="title">TITLE IV—Enforcement</toc-entry>
					<toc-entry idref="ID1D14C2EED2E144B9BE84CC259257D950" level="section">Sec. 401. General application.</toc-entry>
					<toc-entry idref="ID4E7960C9B01F45788D6AD21C175529CC" level="section">Sec. 402. Enforcement by the Federal Trade
				Commission.</toc-entry>
					<toc-entry idref="IDB9D3FF75855C4C6999C5881071D2FD6E" level="section">Sec. 403. Enforcement by State attorneys general.</toc-entry>
					<toc-entry idref="ID981AD43AE0394BDEB8D21B253FAA49EA" level="section">Sec. 404. Civil penalties.</toc-entry>
					<toc-entry idref="ID85D25D4A4E0C47DB9BE3407B43191594" level="section">Sec. 405. Effect on other laws.</toc-entry>
					<toc-entry idref="ID8089E0D9CD894FFDAE004119801BADBB" level="section">Sec. 406. No private right of action.</toc-entry>
					<toc-entry idref="ID1DAB2E3D98B747799A58621C13AC0425" level="title">TITLE V—Co-regulatory safe harbor programs</toc-entry>
					<toc-entry idref="ID0B24BA96848841EF8BDA9B996129645C" level="section">Sec. 501. Establishment of safe harbor programs.</toc-entry>
					<toc-entry idref="ID23e53dc29c964d5d92130ea1075d5e8f" level="section">Sec. 502. Participation in safe harbor program.</toc-entry>
					<toc-entry idref="ID8C8750AA42DD466AA0960D135ACD04B7" level="title">TITLE VI—Application with other Federal laws</toc-entry>
					<toc-entry idref="ID2D1058163FFC4DFFAAD3C3A95F03B438" level="section">Sec. 601. Application with other Federal laws.</toc-entry>
					<toc-entry idref="IDBDC35D4271CB4F0CB2A6B6FD7D95040D" level="title">TITLE VII—Development of commercial data privacy policy in the
				Department of Commerce</toc-entry>
					<toc-entry idref="IDBF6BD70197A14643AC74A9E8118D1263" level="section">Sec. 701. Direction to develop commercial data privacy
				policy.</toc-entry>
				</toc>
			</subsection></section><section id="ID1CBE799910FD4334B0BBFC318C672A95"><enum>2.</enum><header>Findings</header><text display-inline="no-display-inline">The Congress finds the following:</text>
			<paragraph id="ID8476717062244A1EB722809900B19E11"><enum>(1)</enum><text>Personal privacy
			 is worthy of protection through appropriate legislation.</text>
			</paragraph><paragraph id="ID679855E86C074CF0BE9C7E68952C9BDD"><enum>(2)</enum><text>Trust in the
			 treatment of personally identifiable information collected on and off the
			 Internet is essential for businesses to succeed.</text>
			</paragraph><paragraph id="IDE9E27E61683A462596B4D229362D6376"><enum>(3)</enum><text>Persons
			 interacting with others engaged in interstate commerce have a significant
			 interest in their personal information, as well as a right to control how that
			 information is collected, used, stored, or transferred.</text>
			</paragraph><paragraph id="IDFD9823A17FD440369BFBAB638EFC827E"><enum>(4)</enum><text>Persons engaged
			 in interstate commerce and collecting personally identifiable information on
			 individuals have a responsibility to treat that information with respect and in
			 accordance with common standards.</text>
			</paragraph><paragraph id="IDCE6F0A78F7B34B26AF710FAA324334D0"><enum>(5)</enum><text>To the extent
			 that States regulate the treatment of personally identifiable information,
			 their efforts to address Internet privacy could lead to a patchwork of
			 inconsistent standards and protections.</text>
			</paragraph><paragraph id="IDEB36E8D9AE534109BBC5619D539E49CA"><enum>(6)</enum><text>On the day before
			 the date of the enactment of this Act, the laws of the Federal Government and
			 State and local governments provided inadequate privacy protection for
			 individuals engaging in and interacting with persons engaged in interstate
			 commerce.</text>
			</paragraph><paragraph id="ID223971B146CC4C1DAC10D1FA1DF4A335"><enum>(7)</enum><text>As of the day
			 before the date of the enactment of this Act, with the exception of Federal
			 Trade Commission enforcement of laws against unfair and deceptive practices,
			 the Federal Government has eschewed general commercial privacy laws in favor of
			 industry self-regulation, which has led to several self-policing schemes, some
			 of which are enforceable, and some of which provide insufficient privacy
			 protection to individuals.</text>
			</paragraph><paragraph id="ID01BAFCE1D7E64A8CB047993492385213"><enum>(8)</enum><text>As of the day
			 before the date of the enactment of this Act, many collectors of personally
			 identifiable information have yet to provide baseline fair information practice
			 protections for individuals.</text>
			</paragraph><paragraph id="ID49BE6B7698FF4DAFAF4EFEF45970E9E8"><enum>(9)</enum><text>The ease of
			 gathering and compiling personal information on the Internet and off, both
			 overtly and surreptitiously, is becoming increasingly efficient and effortless
			 due to advances in technology which have provided information gatherers the
			 ability to compile seamlessly highly detailed personal histories of
			 individuals.</text>
			</paragraph><paragraph id="ID3EC8A02E434A4B0A8570FD7BA33D97B2"><enum>(10)</enum><text>Personal
			 information requires greater privacy protection than is available on the day
			 before the date of the enactment of this Act. Vast amounts of personal
			 information, including sensitive information, about individuals are collected
			 on and off the Internet, often combined and sold or otherwise transferred to
			 third parties, for purposes unknown to an individual to whom the personally
			 identifiable information pertains.</text>
			</paragraph><paragraph id="IDF58079F0607F44818A0E072EA1C12763"><enum>(11)</enum><text>Toward the close
			 of the 20th Century, as individuals' personal information was increasingly
			 collected, profiled, and shared for commercial purposes, and as technology
			 advanced to facilitate these practices, Congress enacted numerous statutes to
			 protect privacy.</text>
			</paragraph><paragraph id="ID8EC5497B45784CF9A1A9609808783BA1"><enum>(12)</enum><text>Those statutes
			 apply to the government, telephones, cable television, e-mail, video tape
			 rentals, and the Internet (but only with respect to children and law
			 enforcement requests).</text>
			</paragraph><paragraph id="ID2361EE73444B4333BC2874B8E5DB9A75"><enum>(13)</enum><text>As in those
			 instances, the Federal Government has a substantial interest in creating a
			 level playing field of protection across all collectors of personally
			 identifiable information, both in the United States and abroad.</text>
			</paragraph><paragraph id="ID6d88212c00224c87a8f6625125212868"><enum>(14)</enum><text>The Federal
			 Trade Commission has called private self regulation efforts as of the day
			 before the date of the introduction of this Act inadequate. The Commission has
			 also distinguished publishers’ first-party data collection practices from
			 third-party practices related specifically to behavioral advertising. The
			 Commission has noted that when dealing directly with an Internet website,
			 consumers are likely to understand why they receive a recommendation or
			 advertisement from that entity and may expect it.</text>
			</paragraph><paragraph id="ID4205096CC2DC474EB4518C83B9E807FC"><enum>(15)</enum><text>Enhancing
			 individual privacy protection in a balanced way that establishes clear,
			 consistent rules, both domestically and internationally, will stimulate
			 commerce by instilling greater consumer confidence at home and greater
			 confidence abroad as more and more entities digitize personally identifiable
			 information, whether collected, stored, or used online or offline.</text>
			</paragraph></section><section id="IDDC7640A1B70B48E49F7869BF33FC4144"><enum>3.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act:</text>
			<paragraph id="idFDC54BF284F54CD6815A1B4D0CF8A97D"><enum>(1)</enum><header>Commission</header><text>The
			 term <term>Commission</term> means the Federal Trade Commission.</text>
			</paragraph><paragraph id="ID4E141E123723457890000AD2F44CE929"><enum>(2)</enum><header>Covered
			 entity</header><text>The term <term>covered entity</term> means any person to
			 whom this Act applies under section 401.</text>
			</paragraph><paragraph id="IDFEF32194B3B246689A3CAA16C45E73C7"><enum>(3)</enum><header>Covered
			 information</header>
				<subparagraph id="id3A8B8DC6C1AD4D64A6D9EF29102BFBE4"><enum>(A)</enum><header>In
			 general</header><text>Except as provided in subparagraph (B), the term
			 <term>covered information</term> means only the following:</text>
					<clause id="IDE28A22F58BE44BE8BFAB6762A941AF9E"><enum>(i)</enum><text>Personally
			 identifiable information.</text>
					</clause><clause id="ID6EF63EF54A944862A8ED091527DB7177"><enum>(ii)</enum><text>Unique
			 identifier information.</text>
					</clause><clause id="ID8883671AFC574A47A5323E87519FCBAA"><enum>(iii)</enum><text>Any information
			 that is collected, used, or stored in connection with personally identifiable
			 information or unique identifier information in a manner that may reasonably be
			 used by the party collecting the information to identify a specific
			 individual.</text>
					</clause></subparagraph><subparagraph id="IDd4ee5baa740e4dc69585f76eed532081"><enum>(B)</enum><header>Exception</header><text>The
			 term <term>covered information</term> does not include the following:</text>
					<clause id="idC84202A07F0346D698B82D91C15AAFB4"><enum>(i)</enum><text>Personally
			 identifiable information obtained from public records that is not merged with
			 covered information gathered elsewhere.</text>
					</clause><clause id="id4FD9577ED1DA44F4B7F46CFF83C1C812"><enum>(ii)</enum><text>Personally
			 identifiable information that is obtained from a forum—</text>
						<subclause id="idA91F7B4998044A5B91FE5AF20CFE098B"><enum>(I)</enum><text>where the
			 individual voluntarily shared the information or authorized the information to
			 be shared; and</text>
						</subclause><subclause id="id7B6C968B5B214459880B6CD742F1B781"><enum>(II)</enum><text>that—</text>
							<item id="id2055AACF22A24FCB88E26737D3203E16"><enum>(aa)</enum><text>is
			 widely and publicly available; and</text>
							</item><item id="idA5A5E5E6001446B1B876CE858676AC8B"><enum>(bb)</enum><text>contains no
			 restrictions on who can access and view such information.</text>
							</item></subclause></clause><clause id="id4668805DBAD445DE9599B922AB9E9397"><enum>(iii)</enum><text>Personally
			 identifiable information reported in public media.</text>
					</clause><clause id="id86729812AC2B4E5BA656D01D862CAE71"><enum>(iv)</enum><text>Personally
			 identifiable information dedicated to contacting an individual at the
			 individual's place of work.</text>
					</clause></subparagraph></paragraph><paragraph id="id441679F34F314900866786F6B1A80986"><enum>(4)</enum><header>Established
			 business relationship</header><text>The term <term>established business
			 relationship</term> means, with respect to a covered entity and a person, a
			 relationship formed with or without the exchange of consideration, involving
			 the establishment of an account by the person with the covered entity for the
			 receipt of products or services offered by the covered entity.</text>
			</paragraph><paragraph id="ID9B5731CF71514CA4B20CC16B08DA50CD"><enum>(5)</enum><header>Personally
			 identifiable information</header><text>The term <term>personally identifiable
			 information</term> means only the following:</text>
				<subparagraph id="ID5F116DE8AEBA4F04B8010D976CA61358"><enum>(A)</enum><text>Any of the
			 following information about an individual:</text>
					<clause id="ID5866ACEEDDC348F1B4684EEC8F57BDDB"><enum>(i)</enum><text>The
			 first name (or initial) and last name of an individual, whether given at birth
			 or time of adoption, or resulting from a lawful change of name.</text>
					</clause><clause id="ID3236558DF68A4E8EBD7049CEF58CD868"><enum>(ii)</enum><text>The postal
			 address of a physical place of residence of such individual.</text>
					</clause><clause id="IDF24A4FE437684EACBE31D9170EAEB4DB"><enum>(iii)</enum><text>An e-mail
			 address.</text>
					</clause><clause id="IDCB3F19D3797E42D6BF7564C324F5A51A"><enum>(iv)</enum><text>A
			 telephone number or mobile device number.</text>
					</clause><clause id="IDD2E7DA90F6EE42C3956EC1C941AA0766"><enum>(v)</enum><text>A
			 social security number or other government issued identification number issued
			 to such individual.</text>
					</clause><clause id="IDDB2147A5447943839E00FB69538556F7"><enum>(vi)</enum><text>The account
			 number of a credit card issued to such individual.</text>
					</clause><clause id="IDC5C80A14033C445BBC918EDF24B1709D"><enum>(vii)</enum><text>Unique
			 identifier information that alone can be used to identify a specific
			 individual.</text>
					</clause><clause id="IDE9D4CC017D494DA184F0870CC6D1B415"><enum>(viii)</enum><text>Biometric data
			 about such individual, including fingerprints and retina scans.</text>
					</clause></subparagraph><subparagraph id="ID95C9B5D6AA7F4368926A481E0D980666"><enum>(B)</enum><text>If used,
			 transferred, or stored in connection with 1 or more of the items of information
			 described in subparagraph (A), any of the following:</text>
					<clause id="IDD2983F4CDEC849C2A31019145FF8A393"><enum>(i)</enum><text>A
			 date of birth.</text>
					</clause><clause id="id95C38C935C6B4B9FB2209EB0F4BED799"><enum>(ii)</enum><text>The number of a
			 certificate of birth or adoption.</text>
					</clause><clause id="idAD0EFFB114D149EA9A9B7F2F26F2F55D"><enum>(iii)</enum><text>A
			 place of birth.</text>
					</clause><clause id="ID5AC6EA5616144A18B5F3568AFFCECB95"><enum>(iv)</enum><text>Unique
			 identifier information that alone cannot be used to identify a specific
			 individual.</text>
					</clause><clause id="ID4648D97E61274F8BAFA50F45B421C449"><enum>(v)</enum><text>Precise
			 geographic location, at the same degree of specificity as a global positioning
			 system or equivalent system, and not including any general geographic
			 information that may be derived from an Internet Protocol address.</text>
					</clause><clause id="id3283CBE8857A472B9BD8206DC05CD177"><enum>(vi)</enum><text>Information
			 about an individual's quantity, technical configuration, type, destination,
			 location, and amount of uses of voice services, regardless of technology
			 used.</text>
					</clause><clause id="ID9C09EEC7A05940A290D8A4683FCD55BA"><enum>(vii)</enum><text>Any other
			 information concerning an individual that may reasonably be used by the party
			 using, collecting, or storing that information to identify that
			 individual.</text>
					</clause></subparagraph></paragraph><paragraph id="ID0F51542974CD43498C577D5A5801340F"><enum>(6)</enum><header>Sensitive
			 personally identifiable information</header><text>The term <term>sensitive
			 personally identifiable information</term> means—</text>
				<subparagraph id="id2E8C5F961DE94AE0B2BC4A3535481163"><enum>(A)</enum><text>personally
			 identifiable information which, if lost, compromised, or disclosed without
			 authorization either alone or with other information, carries a significant
			 risk of economic or physical harm; or</text>
				</subparagraph><subparagraph id="id5CD88C916BCC41EC835247E86223DB04"><enum>(B)</enum><text>information
			 related to—</text>
					<clause id="id29088C8C74DF47B4957297AA4BB8CD32"><enum>(i)</enum><text>a
			 particular medical condition or a health record; or</text>
					</clause><clause id="id4FBFA509BD0343DBACB5BC046E86B47F"><enum>(ii)</enum><text>the religious
			 affiliation of an individual.</text>
					</clause></subparagraph></paragraph><paragraph id="IDC453CCDB034549118B15B72AC3DEE663"><enum>(7)</enum><header>Third
			 party</header><text>The term <term>third party</term> means, with respect to a
			 covered entity, a person that—</text>
				<subparagraph id="id692623027EDA45E78B97215D531136AF"><enum>(A)</enum><text>is not related to
			 the covered entity by common ownership or corporate control;</text>
				</subparagraph><subparagraph id="idF48BD3F6345E44E1B634A85ED6DB471F"><enum>(B)</enum><text>is not a service
			 provider used by the covered entity to receive personally identifiable
			 information or sensitive personally identifiable information in performing
			 services or functions on behalf of and under the instruction of the covered
			 entity; and</text>
				</subparagraph><subparagraph id="id2F619B8958154DA783CD98B2E8C0FE8D"><enum>(C)</enum><text>does not have an
			 established business relationship with the individual and does not identify
			 itself to the individual at the time of collection of covered information in a
			 clear and conspicuous manner that is visible to the individual.</text>
				</subparagraph></paragraph><paragraph id="IDBD858F26A4DE407FBC80C1739ED6FF99"><enum>(8)</enum><header>Unauthorized
			 use</header>
				<subparagraph id="id1A989DAEF10B4BF9BDB0A14ECCEED490"><enum>(A)</enum><header>In
			 general</header><text>The term <term>unauthorized use</term> means the use of
			 covered information by a covered entity or its service provider for any purpose
			 not authorized by the individual to whom such information relates.</text>
				</subparagraph><subparagraph id="id9D79E14E08D44941915F4131B0B3FDA9"><enum>(B)</enum><header>Exceptions</header><text>Except
			 as provided in subparagraph (C), the term <term>unauthorized use</term> does
			 not include use of covered information relating to an individual by a covered
			 entity or its service provider as follows:</text>
					<clause id="ID9928DFE4BD79418EB198DDD8F0568153"><enum>(i)</enum><text>To
			 process and enforce a transaction or deliver a service requested by that
			 individual.</text>
					</clause><clause id="IDABAB2D67BDE443558CC704F347E2CE95"><enum>(ii)</enum><text>To
			 operate the covered entity that is providing a transaction or delivering a
			 service requested by that individual, such as inventory management, financial
			 reporting and accounting, planning, and product or service improvement or
			 forecasting.</text>
					</clause><clause id="ID4FF6121B9BB0442EB84B3CDEC3863FD0"><enum>(iii)</enum><text>To prevent or
			 detect fraud or to provide for a physically or virtually secure
			 environment.</text>
					</clause><clause id="IDDC4D754CA6B04894AFCB774E0E8D4940"><enum>(iv)</enum><text>To
			 investigate a possible crime.</text>
					</clause><clause id="id471FB188B27A4CC6909AB87DCBC33F7B"><enum>(v)</enum><text>That is required
			 by a provision of law or legal process.</text>
					</clause><clause id="ID5D28F5E60BE34FFA982BEC402B69E716"><enum>(vi)</enum><text>To
			 market or advertise to an individual from a covered entity within the context
			 of a covered entity's own Internet website, services, or products if the
			 covered information used for such marketing or advertising was—</text>
						<subclause id="idC6C8B00472CD4FFEAA35880BAF13165F"><enum>(I)</enum><text>collected
			 directly by the covered entity; or</text>
						</subclause><subclause id="id9DF337A08C1744769CF0A52A2270F288"><enum>(II)</enum><text>shared with the
			 covered entity—</text>
							<item id="id96446EB545104E70B76FB43279C9591C"><enum>(aa)</enum><text>at
			 the affirmative request of the individual; or</text>
							</item><item id="idD6E8629696FC4D95A13414EA2127C89E"><enum>(bb)</enum><text>by
			 an entity with which the individual has an established business
			 relationship.</text>
							</item></subclause></clause><clause id="IDC2D707F5509544339B135492C8540042"><enum>(vii)</enum><text>Use that is
			 necessary for the improvement of transaction or service delivery through
			 research, testing, analysis, and development.</text>
					</clause><clause id="ID897D125C07CE485192B5152C0E9F4439"><enum>(viii)</enum><text>Use that is
			 necessary for internal operations, including the following:</text>
						<subclause id="id982675544DF34B1482BB474706275A2A"><enum>(I)</enum><text>Collecting
			 customer satisfaction surveys and conducting customer research to improve
			 customer service information.</text>
						</subclause><subclause id="id7F9800CD03064FEAAB0A17D1A39309D4"><enum>(II)</enum><text>Information
			 collected by an Internet website about the visits to such website and the
			 click-through rates at such website—</text>
							<item id="id0AF0D98115864F57846F090AAE6735DE"><enum>(aa)</enum><text>to
			 improve website navigation and performance; or</text>
							</item><item id="id70A54C4DC580438D8298C3961A6F61EA"><enum>(bb)</enum><text>to
			 understand and improve the interaction of an individual with the advertising of
			 a covered entity.</text>
							</item></subclause></clause><clause id="id14E974EDFDB74E05A4872BCEFEDA283B"><enum>(ix)</enum><text>Use—</text>
						<subclause id="idB5D25B3D983749D7944CC0BB1B16C2F3"><enum>(I)</enum><text>by a covered
			 entity with which an individual has an established business
			 relationship;</text>
						</subclause><subclause id="idA088744A8A7B4932AD4304C3A9327B8A"><enum>(II)</enum><text>which the
			 individual could have reasonably expected, at the time such relationship was
			 established, was related to a service provided pursuant to such relationship;
			 and</text>
						</subclause><subclause id="id7C83551A7964431A925D7A823581C1CE"><enum>(III)</enum><text>which does not
			 constitute a material change in use or practice from what could have reasonably
			 been expected.</text>
						</subclause></clause></subparagraph><subparagraph id="id62D1442895134098883D23CC83A7A0B0"><enum>(C)</enum><header>Savings</header><text>A
			 use of covered information regarding an individual by a covered entity or its
			 service provider may only be excluded under subparagraph (B) from the
			 definition of <quote>unauthorized use</quote> under subparagraph (A) if the use
			 is reasonable and consistent with the practices and purposes described in the
			 notice given the individual in accordance with section 201(a)(1).</text>
				</subparagraph></paragraph><paragraph id="ID87B74D28F88048C8B5441A8E901C9905"><enum>(9)</enum><header>Unique
			 identifier information</header><text>The term <term>unique identifier
			 information</term> means a unique persistent identifier associated with an
			 individual or a networked device, including a customer number held in a cookie,
			 a user ID, a processor serial number, or a device serial number.</text>
			</paragraph></section><title id="IDB46BEDB6A323470392A46C0B59D19D0D"><enum>I</enum><header>Right to security
			 and accountability</header>
			<section id="ID4CA46AD4F32144588E586685256010E1"><enum>101.</enum><header>Security</header>
				<subsection id="id76B72F54E499416B83C7578D99C593D7"><enum>(a)</enum><header>Rulemaking
			 required</header><text display-inline="yes-display-inline">Not later than 180
			 days after the date of the enactment of this Act, the Commission shall initiate
			 a rulemaking proceeding to require each covered entity to carry out security
			 measures to protect the covered information it collects and maintains.</text>
				</subsection><subsection id="id039C446A7A474B68B17B0E14E91CF8AB"><enum>(b)</enum><header>Proportion</header><text display-inline="yes-display-inline">The requirements prescribed under
			 subsection (a) shall provide for security measures that are proportional to the
			 size, type, and nature of the covered information a covered entity
			 collects.</text>
				</subsection><subsection id="id13924EE057424FB1969FEA7D2A40D721"><enum>(c)</enum><header>Consistency</header><text>The
			 requirements prescribed under subsection (a) shall be consistent with guidance
			 provided by the Commission and recognized industry practices for safety and
			 security on the day before the date of the enactment of this Act.</text>
				</subsection><subsection id="idDF87749FE79A4EC8A27B29EB810AEC96"><enum>(d)</enum><header>Technological
			 means</header><text display-inline="yes-display-inline">In a rule prescribed
			 under subsection (a), the Commission may not require a specific technological
			 means of meeting a requirement.</text>
				</subsection></section><section id="ID9A265885F4F441E5A9BC71CB5E6D617E"><enum>102.</enum><header>Accountability</header><text display-inline="no-display-inline">Each covered entity shall, in a manner
			 proportional to the size, type, and nature of the covered information it
			 collects—</text>
				<paragraph id="ID56CC2390BE81452D95B2E7EDDD985278"><enum>(1)</enum><text>have managerial
			 accountability, proportional to the size and structure of the covered entity,
			 for the adoption and implementation of policies consistent with this
			 Act;</text>
				</paragraph><paragraph id="IDAA491F154A8947F8A450D8117EB32970"><enum>(2)</enum><text>have a process to
			 respond to non-frivolous inquiries from individuals regarding the collection,
			 use, transfer, or storage of covered information relating to such individuals;
			 and</text>
				</paragraph><paragraph id="IDBCE3A65C0B844DDDA776E80BD8D2CAAF"><enum>(3)</enum><text>describe the
			 means of compliance of the covered entity with the requirements of this Act
			 upon request from—</text>
					<subparagraph id="id36DC78FF73A74771A31EB9D068FF4B7F"><enum>(A)</enum><text>the Commission;
			 or</text>
					</subparagraph><subparagraph id="idE5CDC056CC6A41808834AF306C4C83EC"><enum>(B)</enum><text>an appropriate
			 safe harbor program established under section 501.</text>
					</subparagraph></paragraph></section><section id="id97DDB8DF897749B3B63484D6108CC741"><enum>103.</enum><header>Privacy by
			 design</header><text display-inline="no-display-inline">Each covered entity
			 shall, in a manner proportional to the size, type, and nature of the covered
			 information that it collects, implement a comprehensive information privacy
			 program by—</text>
				<paragraph id="ID172941727f1e42dd86e60396a285f7be"><enum>(1)</enum><text>incorporating
			 necessary development processes and practices throughout the product life cycle
			 that are designed to safeguard the personally identifiable information that is
			 covered information of individuals based on—</text>
					<subparagraph id="idFE0BC375CF464401AB4649F14C51E7A7"><enum>(A)</enum><text>the reasonable
			 expectations of such individuals regarding privacy; and</text>
					</subparagraph><subparagraph id="idFA075E199BA54261B97A3C51213D1FD1"><enum>(B)</enum><text>the relevant
			 threats that need to be guarded against in meeting those expectations;
			 and</text>
					</subparagraph></paragraph><paragraph id="id12D737D7BB2B47E38607112480657CB3"><enum>(2)</enum><text>maintaining
			 appropriate management processes and practices throughout the data life cycle
			 that are designed to ensure that information systems comply with—</text>
					<subparagraph id="idDC073ED418EE4D6280747843F6C88501"><enum>(A)</enum><text>the provisions of
			 this Act;</text>
					</subparagraph><subparagraph id="idAB61674C94E0404E8B1B8F9FFAAB8CD2"><enum>(B)</enum><text>the privacy
			 policies of a covered entity; and</text>
					</subparagraph><subparagraph id="id2AAC952697A24838A72FA62D3F387BDD"><enum>(C)</enum><text>the privacy
			 preferences of individuals that are consistent with the consent choices and
			 related mechanisms of individual participation as described in section
			 202.</text>
					</subparagraph></paragraph></section></title><title id="ID825DDA0E130B4886A879AD488CFA0B1A"><enum>II</enum><header>Right to notice
			 and individual participation</header>
			<section id="IDA181E5162B2F4EC2AE67BC9BF9F86AD2"><enum>201.</enum><header>Transparent
			 notice of practices and purposes</header>
				<subsection id="IDBBD12DC872EF4C7C81AA5491C8AF7885"><enum>(a)</enum><header>In
			 general</header><text>Not later than 60 days after the date of the enactment of
			 this Act, the Commission shall initiate a rulemaking proceeding to require each
			 covered entity—</text>
					<paragraph id="ID9C484381460F4B6CB021460D5C82B242"><enum>(1)</enum><text>to provide clear,
			 concise, and timely notice to individuals of—</text>
						<subparagraph id="id1646C3AF8FF94D77B3ABAE43212D4DD1"><enum>(A)</enum><text>the practices of
			 the covered entity regarding the collection, use, transfer, and storage of
			 covered information; and</text>
						</subparagraph><subparagraph id="id5AE441B318074FD996F6DC10828C46B7"><enum>(B)</enum><text>the specific
			 purposes of those practices;</text>
						</subparagraph></paragraph><paragraph id="IDA1B649ED068040D185DB702AB7AB42E8"><enum>(2)</enum><text>to provide clear,
			 concise, and timely notice to individuals before implementing a material change
			 in such practices; and</text>
					</paragraph><paragraph id="ID9C472F52087E4478991C030F5BED0683"><enum>(3)</enum><text>to maintain the
			 notice required by paragraph (1) in a form that individuals can readily
			 access.</text>
					</paragraph></subsection><subsection id="IDDE917CCDD3DC49F99A8CF90D85E39A02"><enum>(b)</enum><header>Compliance and
			 other considerations</header><text>In the rulemaking required by subsection
			 (a), the Commission—</text>
					<paragraph id="IDC1969019F6FC456E8B201EC76EC39175"><enum>(1)</enum><text>shall consider
			 the types of devices and methods individuals will use to access the required
			 notice;</text>
					</paragraph><paragraph id="ID3458C5EA96094F24A0F906DAEFFB0EEE"><enum>(2)</enum><text>may provide that
			 a covered entity unable to provide the required notice when information is
			 collected may comply with the requirement of subsection (a)(1) by providing an
			 alternative time and means for an individual to receive the required notice
			 promptly;</text>
					</paragraph><paragraph id="IDD20CC5E7FF7F464EA1477736C878625B"><enum>(3)</enum><text>may draft
			 guidance for covered entities to use in designing their own notice and may
			 include a draft model template for covered entities to use in designing their
			 own notice; and</text>
					</paragraph><paragraph id="IDFCA874075E1641028ACB41E6DFC2F974"><enum>(4)</enum><text>may provide
			 guidance on how to construct computer-readable notices or how to use other
			 technology to deliver the required notice.</text>
					</paragraph></subsection></section><section id="ID637E5D16C8B14E9880943F341077075F"><enum>202.</enum><header>Individual
			 participation</header>
				<subsection id="IDF448EA7A183B454A920BF88ACEAFEB78"><enum>(a)</enum><header>In
			 general</header><text>Not later than 180 days after the date of the enactment
			 of this Act, the Commission shall initiate a rulemaking proceeding to require
			 each covered entity—</text>
					<paragraph id="ID6E5A510AA383422D8F9F63DAF64F44B9"><enum>(1)</enum><text>to offer
			 individuals a clear and conspicuous mechanism for opt-out consent for any use
			 of their covered information that would otherwise be unauthorized use, except
			 with respect to any use requiring opt-in consent under paragraph (3);</text>
					</paragraph><paragraph id="id0EC2A7A9D2D44A0DB2DCA1F309F37557"><enum>(2)</enum><text>to offer
			 individuals a robust, clear, and conspicuous mechanism for opt-out consent for
			 the use by third parties of the individuals' covered information for behavioral
			 advertising or marketing;</text>
					</paragraph><paragraph id="IDD7A8B6A6BBCD4C8C95B1B00FF7A05DAE"><enum>(3)</enum><text>to offer
			 individuals a clear and conspicuous mechanism for opt-in consent for—</text>
						<subparagraph id="IDBDB05E648A8F4A82BC46508324613D72"><enum>(A)</enum><text>the collection,
			 use, or transfer of sensitive personally identifiable information other
			 than—</text>
							<clause id="id415014B140F047CAAF2B6E456B3AAE74"><enum>(i)</enum><text>to
			 process or enforce a transaction or deliver a service requested by that
			 individual;</text>
							</clause><clause id="idCB87B129DD984CC1873F34BB71F4499B"><enum>(ii)</enum><text>for fraud
			 prevention and detection; or</text>
							</clause><clause id="idB44D8081C20541FBA5A72E156D912885"><enum>(iii)</enum><text>to provide for
			 a secure physical or virtual environment; and</text>
							</clause></subparagraph><subparagraph id="IDF385921916824235B3507D565776FD7C"><enum>(B)</enum><text>the use of
			 previously collected covered information or transfer to a third party for an
			 unauthorized use of previously collected covered information, if—</text>
							<clause id="id69711E7E654049DB8C396441F8ABB83D"><enum>(i)</enum><text>there is a
			 material change in the covered entity's stated practices that requires notice
			 under section 201(a)(2); and</text>
							</clause><clause id="id6FFA303E2361419ABA4E1ED588AFFC77"><enum>(ii)</enum><text>such use or
			 transfer creates a risk of economic or physical harm to an individual;</text>
							</clause></subparagraph></paragraph><paragraph id="ID8DFDEED19B54444CBFC5C7E452F78633"><enum>(4)</enum><text>to provide any
			 individual to whom the personally identifiable information that is covered
			 information pertains, and which the covered entity or its service provider
			 stores, appropriate and reasonable—</text>
						<subparagraph id="idF3F3314070BA489B85472F38F98A43BC"><enum>(A)</enum><text>access to such
			 information; and</text>
						</subparagraph><subparagraph id="idBBBCB036E90D420E9740A79CA734CFAB"><enum>(B)</enum><text>mechanisms to
			 correct such information to improve the accuracy of such information;
			 and</text>
						</subparagraph></paragraph><paragraph id="id67E8693FA9C249A1AB3B7D32877A0725"><enum>(5)</enum><text>in the case that
			 a covered entity enters bankruptcy or an individual requests the termination of
			 a service provided by the covered entity to the individual or termination of
			 some other relationship with the covered entity, to permit the individual to
			 easily request that—</text>
						<subparagraph id="id48D500BB72574DE0836640EDAB3C4A5D"><enum>(A)</enum><text>all of the
			 personally identifiable information that is covered information that the
			 covered entity maintains relating to the individual, except for information the
			 individual authorized the sharing of or which the individual shared with the
			 covered entity in a forum that is widely and publicly available, be rendered
			 not personally identifiable; or</text>
						</subparagraph><subparagraph id="idD19C0DAE6A1346289F76E279B6841433"><enum>(B)</enum><text>if rendering such
			 information not personally identifiable is not possible, to cease the
			 unauthorized use or transfer to a third party for an unauthorized use of such
			 information or to cease use of such information for marketing, unless such
			 unauthorized use or transfer is otherwise required by a provision of
			 law.</text>
						</subparagraph></paragraph></subsection><subsection id="ID520F040A93744ADFB08479AD864943AA"><enum>(b)</enum><header>Unauthorized
			 use transfers</header><text>In the rulemaking required by subsection (a), the
			 Commission shall provide that with respect to transfers of covered information
			 to a third party for which an individual provides opt-in consent, the third
			 party to which the information is transferred may not use such information for
			 any unauthorized use other than a use—</text>
					<paragraph id="id170F2A811A934C99972CA197CD6A1940"><enum>(1)</enum><text>specified
			 pursuant to the purposes stated in the required notice under section 201(a);
			 and</text>
					</paragraph><paragraph id="id137CBA052649498C84775B4DEA0930D7"><enum>(2)</enum><text>authorized by the
			 individual when the individual granted consent for the transfer of the
			 information to the third party.</text>
					</paragraph></subsection><subsection id="ID18C64F99156B4BF78A68C8DD968E0BBE"><enum>(c)</enum><header>Alternative
			 means To terminate use of covered information</header><text>In the rulemaking
			 required by subsection (a), the Commission shall allow a covered entity to
			 provide individuals an alternative means, in lieu of the access, consent, and
			 correction requirements, of prohibiting a covered entity from use or transfer
			 of that individual's covered information.</text>
				</subsection><subsection id="ID24251CDEAEF84636ABFA6B905AE878C4"><enum>(d)</enum><header>Service
			 providers</header>
					<paragraph id="IDB06C8FCBB38D46D1870EEA42BB697D86"><enum>(1)</enum><header>In
			 general</header><text>The use of a service provider by a covered entity to
			 receive covered information in performing services or functions on behalf of
			 and under the instruction of the covered entity does not constitute an
			 unauthorized use of such information by the covered entity if the covered
			 entity and the service provider execute a contract that requires the service
			 provider to collect, use, and store the information on behalf of the covered
			 entity in a manner consistent with—</text>
						<subparagraph id="id190DB45E5B15468180CA8B946B8F76B6"><enum>(A)</enum><text>the requirements
			 of this Act; and</text>
						</subparagraph><subparagraph id="idF695E51463C24D489F172A110B51EB47"><enum>(B)</enum><text>the policies and
			 practices related to such information of the covered entity.</text>
						</subparagraph></paragraph><paragraph id="ID8942CDC599CE43A8B3EFDCD4CC802B2C"><enum>(2)</enum><header>Transfers
			 between service providers for a covered entity</header><text>The disclosure by
			 a service provider of covered information pursuant to a contract with a covered
			 entity to another service provider in order to perform the same service or
			 functions for that covered entity does not constitute an unauthorized
			 use.</text>
					</paragraph><paragraph id="IDD5809A1EA27848568DD32E659E26ED70"><enum>(3)</enum><header>Liability
			 remains with covered entity</header><text>A covered entity remains responsible
			 and liable for the protection of covered information that has been transferred
			 to a service provider for processing, notwithstanding any agreement to the
			 contrary between a covered entity and the service provider.</text>
					</paragraph></subsection></section></title><title id="ID717DCBA4EDEC49FCB66D8829E3C996F7"><enum>III</enum><header>Rights relating
			 to data minimization, constraints on distribution, and data integrity</header>
			<section id="idF795DB6B50244DC5A08619E2FACEDE64"><enum>301.</enum><header>Data
			 minimization</header><text display-inline="no-display-inline">Each covered
			 entity shall—</text>
				<paragraph id="ID96d06f460662443c9cc4627073e2b5de"><enum>(1)</enum><text>collect only as
			 much covered information relating to an individual as is reasonably
			 necessary—</text>
					<subparagraph id="ID7b027b7a657a459197f3d9f7e6284050"><enum>(A)</enum><text>to process or
			 enforce a transaction or deliver a service requested by such individual;</text>
					</subparagraph><subparagraph id="IDe30b89d2d5274090a722a14c69504bdf"><enum>(B)</enum><text>for the covered
			 entity to provide a transaction or delivering a service requested by such
			 individual, such as inventory management, financial reporting and accounting,
			 planning, product or service improvement or forecasting, and customer support
			 and service;</text>
					</subparagraph><subparagraph id="ID9291675f5d1b433cbdbcbd05de45473f"><enum>(C)</enum><text>to prevent or
			 detect fraud or to provide for a secure environment;</text>
					</subparagraph><subparagraph id="ID3575302411c345ffa91d3db86f02cc3f"><enum>(D)</enum><text>to investigate a
			 possible crime;</text>
					</subparagraph><subparagraph id="id2551213AD032402CB5906154E59BF1FE"><enum>(E)</enum><text>to comply with a
			 provision of law;</text>
					</subparagraph><subparagraph id="ID7c93da76075f481ab4eb69e3d120b66c"><enum>(F)</enum><text>for the covered
			 entity to market or advertise to such individual if the covered information
			 used for such marketing or advertising was collected directly by the covered
			 entity;</text>
					</subparagraph><subparagraph id="IDa81adea5513a4923b31f95b336e47c51"><enum>(G)</enum><text>for research and
			 development conducted for the improvement of carrying out a transaction or
			 delivering a service; or</text>
					</subparagraph><subparagraph id="IDfa302f0a9973404888ca00d45f7429f9"><enum>(H)</enum><text>for internal
			 operations, including—</text>
						<clause id="id7E7B8CC6DA2041CC89C204D38131ACEF"><enum>(i)</enum><text>collecting
			 customer satisfaction surveys and conducting customer research to improve
			 customer service; and</text>
						</clause><clause id="idF63E23FEDC434306A0AEC650CB8FB116"><enum>(ii)</enum><text>collection from
			 an Internet website of information about visits and click-through rates
			 relating to such website to improve—</text>
							<subclause id="idEC731678DAB7485FB52626F811D2E782"><enum>(I)</enum><text>website
			 navigation and performance; and</text>
							</subclause><subclause id="id7B5FE42891B546489A4E7982797A1B5B"><enum>(II)</enum><text>the customer’s
			 experience; and</text>
							</subclause></clause></subparagraph></paragraph><paragraph id="IDde62a45edd2c4e5094b662fbfeec11e9"><enum>(2)</enum><text>retain covered
			 information for only such duration as—</text>
					<subparagraph id="idB265F05B8B3E4A188E5E572E137B9F06"><enum>(A)</enum><text>with respect to
			 the provision of a transaction or delivery of a service to an
			 individual—</text>
						<clause id="id81A14964D7834539825DBBDED9AC6202"><enum>(i)</enum><text>is
			 necessary to provide such transaction or deliver such service to such
			 individual; or</text>
						</clause><clause id="idC23C8E6AC3F3464185C314D78F29FA73"><enum>(ii)</enum><text>if
			 such service is ongoing, is reasonable for the ongoing nature of the
			 service;</text>
						</clause></subparagraph><subparagraph id="id4C7DABC967CC4B05AFE9CFA89A7983A5"><enum>(B)</enum><text>with respect to
			 research and development described in paragraph (1)(G), is necessary for such
			 research and development; or</text>
					</subparagraph><subparagraph id="id501D01A1997248BBA8B1AF6C2884B5F4"><enum>(C)</enum><text>is required by a
			 provision of law.</text>
					</subparagraph></paragraph></section><section id="ID3E9F4EBB04E44525912351CF7D0E25F0"><enum>302.</enum><header>Constraints on
			 distribution of information</header>
				<subsection id="IDB3ACB18FF9D54D569C53299EE84DF875"><enum>(a)</enum><header>In
			 general</header><text>Each covered entity shall—</text>
					<paragraph id="ID5D6AD6A2CA2B42448154C4EDE77EB4C9"><enum>(1)</enum><text>require by
			 contract that any third party to which it transfers covered information use the
			 information only for purposes that are consistent with—</text>
						<subparagraph id="idEABC3ECA70E9491C903134B4BCFE4A88"><enum>(A)</enum><text>the provisions of
			 this Act; and</text>
						</subparagraph><subparagraph id="id708692ED823949D6B24D5C5338219BE5"><enum>(B)</enum><text>as specified in
			 the contract;</text>
						</subparagraph></paragraph><paragraph id="ID791959C6730C4803B05B15B5D382460D"><enum>(2)</enum><text>require by
			 contract that such third party may not combine information that the covered
			 entity has transferred to it, that relates to an individual, and that is not
			 personally identifiable information with other information in order to identify
			 such individual, unless the covered entity has obtained the opt-in consent of
			 such individual for such combination and identification; and</text>
					</paragraph><paragraph id="ID7E576EFE59074BAFAD6605F35463F1CD"><enum>(3)</enum><text>before executing
			 a contract with a third party—</text>
						<subparagraph id="idF637E4FA8B724FF6A07B290D5F2FF14E"><enum>(A)</enum><text>assure through
			 due diligence that the third party is a legitimate organization; and</text>
						</subparagraph><subparagraph id="id2DF51356296949269B17F375CA226833"><enum>(B)</enum><text>in the case of a
			 material violation of the contract, at a minimum notify the Commission of such
			 violation.</text>
						</subparagraph></paragraph></subsection><subsection id="IDDDC296E5DDD84A589C4D636EDBDC2E39"><enum>(b)</enum><header>Transfers to
			 unreliable third parties prohibited</header><text>A covered entity may not
			 transfer covered information to a third party that the covered entity
			 knows—</text>
					<paragraph id="id7CEAD5DB26484FE6B1854FB9E525F2F0"><enum>(1)</enum><text>has intentionally
			 or willfully violated a contract required by subsection (a); and</text>
					</paragraph><paragraph id="id586C799939DE404983A2180662BE3292"><enum>(2)</enum><text>is reasonably
			 likely to violate such contract.</text>
					</paragraph></subsection><subsection id="IDB7EBC31DB19142658C535867BC92F1DD"><enum>(c)</enum><header>Application of
			 rules to third parties</header>
					<paragraph id="IDF95950CA837D4121ADB6D4BD6DC2BA46"><enum>(1)</enum><header>In
			 general</header><text>Except as provided in paragraph (2), a third party that
			 receives covered information from a covered entity shall be subject to the
			 provisions of this Act as if it were a covered entity.</text>
					</paragraph><paragraph id="ID2F4D9EA8EFEC42F0A3249CE283B3704A"><enum>(2)</enum><header>Exemption</header><text>The
			 Commission may, as it determines appropriate, exempt classes of third parties
			 from liability under any provision of title II if the Commission finds
			 that—</text>
						<subparagraph id="idC2D5CFB96705405C9E0558F7D577F941"><enum>(A)</enum><text>such class of
			 third parties cannot reasonably comply with such provision; or</text>
						</subparagraph><subparagraph id="idFCE8FF6AD0C6416285FCD8D33B9F3E8E"><enum>(B)</enum><text>with respect to
			 covered information relating to individuals that is transferred to such class,
			 compliance by such class with such provision would not sufficiently benefit
			 such individuals.</text>
						</subparagraph></paragraph></subsection></section><section id="ID0A5C0D8973EB4C0B80D5538494BC8D2D"><enum>303.</enum><header>Data
			 integrity</header>
				<subsection id="id607E0D7058B9454F9217E502E1CFE2FD"><enum>(a)</enum><header>In
			 general</header><text display-inline="yes-display-inline">Each covered entity
			 shall attempt to establish and maintain reasonable procedures to ensure that
			 personally identifiable information that is covered information and maintained
			 by the covered entity is accurate in those instances where the covered
			 information could be used to deny consumers benefits or cause significant
			 harm.</text>
				</subsection><subsection id="idD64EB7FA1E3442F889460FB5D175640E"><enum>(b)</enum><header>Exception</header><text display-inline="yes-display-inline">Subsection (a) shall not apply to covered
			 information of an individual maintained by a covered entity that is
			 provided—</text>
					<paragraph id="id3D679FA980F849EEBF1D4F387475448C"><enum>(1)</enum><text display-inline="yes-display-inline">directly to the covered entity by the
			 individual; or</text>
					</paragraph><paragraph id="id4CCEE44F60024B2BBE3CE80EDF8ADB61"><enum>(2)</enum><text display-inline="yes-display-inline">to the covered entity by another entity at
			 the request of the individual.</text>
					</paragraph></subsection></section></title><title id="IDB55C089BDF6B4CA2BA22D13C1581D668"><enum>IV</enum><header>Enforcement</header>
			<section id="ID1D14C2EED2E144B9BE84CC259257D950"><enum>401.</enum><header>General
			 application</header><text display-inline="no-display-inline">The requirements
			 of this Act shall apply to any person who—</text>
				<paragraph id="IDDABA742D20C847DCBF1135318135B8D3"><enum>(1)</enum><text>collects, uses,
			 transfers, or stores covered information concerning more than 5,000 individuals
			 during any consecutive 12-month period; and</text>
				</paragraph><paragraph id="ID237F2B4C8FFB48018900251ED4854082"><enum>(2)</enum><text>is—</text>
					<subparagraph id="ID8725363053394A7EBE6FE47DAA801DCA"><enum>(A)</enum><text>a person over
			 which the Commission has authority pursuant to section 5(a)(2) of the
			 <act-name parsable-cite="FTCA">Federal Trade Commission Act</act-name> (15
			 U.S.C. 45(a)(2));</text>
					</subparagraph><subparagraph id="ID1D98A5D93214465E8D5B9F630D87E711"><enum>(B)</enum><text>a common carrier
			 subject to the <act-name parsable-cite="CA34">Communications Act of
			 1934</act-name> (47 U.S.C. 151 et seq.), notwithstanding the definition of the
			 term <quote>Acts to regulate commerce</quote> in section 4 of the
			 <act-name parsable-cite="FTCA">Federal Trade Commission Act</act-name> (15
			 U.S.C. 44) and the exception provided by section 5(a)(2) of the
			 <act-name parsable-cite="FTCA">Federal Trade Commission Act</act-name> (15
			 U.S.C. 45(a)(2)) for such carriers; or</text>
					</subparagraph><subparagraph id="ID518BDB709A0D4D029C729AADEA8BFBE7"><enum>(C)</enum><text>a non-profit
			 organization, including any organization described in section 501(c) of the
			 Internal Revenue code of 1986 that is exempt from taxation under section 501(a)
			 of such Code, notwithstanding the definition of the term <quote>Acts to
			 regulate commerce</quote> in section 4 of the <act-name parsable-cite="FTCA">Federal Trade Commission Act</act-name> (15 U.S.C. 44) and
			 the exception provided by section 5(a)(2) of the <act-name parsable-cite="FTCA">Federal Trade Commission Act</act-name> (15 U.S.C.
			 45(a)(2)) for such organizations.</text>
					</subparagraph></paragraph></section><section id="ID4E7960C9B01F45788D6AD21C175529CC"><enum>402.</enum><header>Enforcement by
			 the Federal Trade Commission</header>
				<subsection id="IDF83B488A593E461B81EF60C5308B695B"><enum>(a)</enum><header>Unfair or
			 deceptive acts or practices</header><text>A knowing or repetitive violation of
			 a provision of this Act or a regulation promulgated under this Act shall be
			 treated as an unfair or deceptive act or practice in violation of a regulation
			 under section 18(a)(1)(B) of the <act-name parsable-cite="FTCA">Federal Trade
			 Commission Act</act-name> (15 U.S.C. 57a(a)(1)(B)) regarding unfair or
			 deceptive acts or practices.</text>
				</subsection><subsection id="IDA754B63077F54F18AF2116B2AFB4C435"><enum>(b)</enum><header>Powers of
			 commission</header>
					<paragraph id="ID47EB07B95B2946C4B92B1CC498852057"><enum>(1)</enum><header>In
			 general</header><text>The Commission shall enforce this Act in the same manner,
			 by the same means, and with the same jurisdiction, powers, and duties as though
			 all applicable terms and provisions of the <act-name parsable-cite="FTCA">Federal Trade Commission Act</act-name> (15 U.S.C. 41 et
			 seq.) were incorporated into and made a part of this Act. Any person who
			 violates this Act or the regulations issued under this Act shall be subject to
			 the penalties and entitled to the privileges and immunities provided in that
			 Act.</text>
					</paragraph><paragraph id="ID4D03D65F7C3448A48A26AF01BE6DB371"><enum>(2)</enum><header>Special
			 rule</header><text>The Commission shall enforce this Act under paragraph (1) of
			 this subsection with respect to common carriers and non-profit organizations
			 described in section 401 to the extent necessary to effectuate the purposes of
			 this Act as if such carriers and non-profit organizations were persons over
			 which the Commission has authority pursuant to section 5(a)(2) of the
			 <act-name parsable-cite="FTCA">Federal Trade Commission Act</act-name> (15
			 U.S.C. 45(a)(2)).</text>
					</paragraph></subsection><subsection id="IDE443486922B44940954F55A03CA6CF14"><enum>(c)</enum><header>Rulemaking
			 authority</header>
					<paragraph id="ID50D6DE4212D94091BA63E543D5694E34"><enum>(1)</enum><header>Limitation</header><text>In
			 promulgating rules under this Act, the Commission may not require the
			 deployment or use of any specific products or technologies, including any
			 specific computer software or hardware.</text>
					</paragraph><paragraph id="ID43F4D13C32A44D19B9128775004A404D"><enum>(2)</enum><header>Administrative
			 procedure</header><text>The Commission shall promulgate regulations under this
			 Act in accordance with section 553 of title 5, United States Code.</text>
					</paragraph></subsection></section><section id="IDB9D3FF75855C4C6999C5881071D2FD6E"><enum>403.</enum><header>Enforcement by
			 State attorneys general</header>
				<subsection id="IDB3A44622CE7F4E4F9CF531BDD600A608"><enum>(a)</enum><header>Civil
			 action</header><text>In any case in which the attorney general of a State has
			 reason to believe that an interest of the residents of that State has been or
			 is adversely affected by a covered entity who violates any part of this Act in
			 a manner that results in economic or physical harm to an individual or engages
			 in a pattern or practice that violates any part of this Act other than title
			 III, the attorney general may, as parens patriae, bring a civil action on
			 behalf of the residents of the State in an appropriate district court of the
			 United States—</text>
					<paragraph id="IDEE6E90E78360429A9D274F516CA3921A"><enum>(1)</enum><text>to enjoin further
			 violation of this Act or a regulation promulgated under this Act by the
			 defendant;</text>
					</paragraph><paragraph id="ID3289D48ED2994534B1D31EA559431784"><enum>(2)</enum><text>to compel
			 compliance with this Act or a regulation promulgated under this Act; or</text>
					</paragraph><paragraph id="ID9ABB135527764D0C8E2A099C9A709907"><enum>(3)</enum><text>for violations of
			 this Act or a regulation promulgated under this Act to obtain civil penalties
			 in the amount determined under section 404.</text>
					</paragraph></subsection><subsection id="id2724F1BDE09F4A2D8521F59360770F28"><enum>(b)</enum><header>Rights of
			 Federal Trade Commission</header>
					<paragraph id="idC0B790DC068D4BC1A67B1299122C65FB"><enum>(1)</enum><header>Notice to
			 Federal Trade Commission</header>
						<subparagraph id="id382AB7FFFA0147ABA5FE47CB012A4AB3"><enum>(A)</enum><header>In
			 general</header><text>Except as provided in subparagraph (C), the attorney
			 general of a State shall notify the Federal Trade Commission in writing of any
			 civil action under subsection (b), prior to initiating such civil
			 action.</text>
						</subparagraph><subparagraph id="id9CA7BBEEF49546DE9BE7667CFB63720B"><enum>(B)</enum><header>Contents</header><text>The
			 notice required by subparagraph (A) shall include a copy of the complaint to be
			 filed to initiate such civil action.</text>
						</subparagraph><subparagraph id="id06BB6C08B4D845E987AF62E06484E082"><enum>(C)</enum><header>Exception</header><text>If
			 it is not feasible for the attorney general of a State to provide the notice
			 required by subparagraph (A), the State shall provide notice immediately upon
			 instituting a civil action under subsection (b).</text>
						</subparagraph></paragraph><paragraph id="idFDA71129413D49D091CB7378BDC4CDF7"><enum>(2)</enum><header>Intervention by
			 Federal Trade Commission</header><text>Upon receiving notice required by
			 paragraph (1) with respect to a civil action, the Federal Trade Commission
			 may—</text>
						<subparagraph id="id29250F981EFF4C33AAC89F00E4FD620D"><enum>(A)</enum><text>intervene in such
			 action; and</text>
						</subparagraph><subparagraph id="id58B841634B2144CFAF8EA4CB2D5F1208"><enum>(B)</enum><text>upon
			 intervening—</text>
							<clause id="id1D60CA42B48142F7A2BB2BC56A3C0725"><enum>(i)</enum><text>be
			 heard on all matters arising in such civil action; and</text>
							</clause><clause commented="no" display-inline="no-display-inline" id="idEFA533783CF84EC280AA505434FBDA1B"><enum>(ii)</enum><text>file petitions
			 for appeal of a decision in such action.</text>
							</clause></subparagraph></paragraph></subsection><subsection id="HFCAC11A2050245859700994D9E465916"><enum>(c)</enum><header>Preemptive
			 action by Federal Trade Commission</header><text>If the Federal Trade
			 Commission institutes a civil action for violation of this Act or a regulation
			 promulgated under this Act, no attorney general of a State may bring a civil
			 action under subsection (a) against any defendant named in the complaint of the
			 Commission for violation of this Act or a regulation promulgated under this Act
			 that is alleged in such complaint.</text>
				</subsection><subsection id="HD352B695DE604A66B0CCE992535EF35B"><enum>(d)</enum><header>Investigatory
			 powers</header><text>Nothing in this section may be construed to prevent the
			 attorney general of a State from exercising the powers conferred on such
			 attorney general by the laws of such State to conduct investigations or to
			 administer oaths or affirmations or to compel the attendance of witnesses or
			 the production of documentary and other evidence.</text>
				</subsection></section><section id="ID981AD43AE0394BDEB8D21B253FAA49EA"><enum>404.</enum><header>Civil
			 penalties</header>
				<subsection id="IDF39B3B42965243ADAB8FAB655A14D38A"><enum>(a)</enum><header>In
			 general</header><text>In an action brought under section 403, in addition to
			 any other penalty otherwise applicable to a violation of this Act or any
			 regulation promulgated under this Act, the following civil penalties shall
			 apply:</text>
					<paragraph id="ID6AC51CE36498490390C3D8CE8DD230B7"><enum>(1)</enum><header>Title I
			 violations</header><text>A covered entity that knowingly or repeatedly violates
			 title I is liable for a civil penalty equal to the amount calculated by
			 multiplying the number of days that the entity is not in compliance with such
			 title by an amount not to exceed $16,500.</text>
					</paragraph><paragraph id="IDC54FAC86A9CA4E719CE5FCD979FDA3A1"><enum>(2)</enum><header>Title II
			 violations</header><text>A covered entity that knowingly or repeatedly violates
			 title II is liable for a civil penalty equal to the amount calculated by
			 multiplying the number of days that such an entity is not in compliance with
			 such title, or the number of individuals for whom the entity failed to obtain
			 consent as required by such title, whichever is greater, by an amount not to
			 exceed $16,500.</text>
					</paragraph></subsection><subsection id="IDE95FC862199F4C7FA8C9B186A5220300"><enum>(b)</enum><header>Adjustment for
			 inflation</header><text>Beginning on the date that the Consumer Price Index for
			 All Urban Consumers is first published by the Bureau of Labor Statistics that
			 is after 1 year after the date of the enactment of this Act, and each year
			 thereafter, each of the amounts specified in subsection (a) shall be increased
			 by the percentage increase in the Consumer Price Index published on that date
			 from the Consumer Price Index published the previous year.</text>
				</subsection><subsection id="ID2B786D7AD4234B9F98837B8459E1FC7E"><enum>(c)</enum><header>Maximum total
			 liability</header><text>Notwithstanding the number of actions which may be
			 brought against a covered entity under section 403, the maximum civil penalty
			 for which any covered entity may be liable under this section in such actions
			 shall not exceed—</text>
					<paragraph id="ID0A5F7851927140C8A505329FEB3814EB"><enum>(1)</enum><text>$3,000,000 for
			 any related series of violations of any rule promulgated under title I;
			 and</text>
					</paragraph><paragraph id="IDC81E2B383CEF4AE5B030275546ED928B"><enum>(2)</enum><text>$3,000,000 for
			 any related series of violations of title II.</text>
					</paragraph></subsection></section><section id="ID85D25D4A4E0C47DB9BE3407B43191594"><enum>405.</enum><header>Effect on
			 other laws</header>
				<subsection id="ID78D5364096A340D19B1D07F2F127078E"><enum>(a)</enum><header>Preemption of
			 State laws</header><text>The provisions of this Act shall supersede any
			 provisions of the law of any State relating to those entities covered by the
			 regulations issued pursuant to this Act, to the extent that such provisions
			 relate to the collection, use, or disclosure of—</text>
					<paragraph id="id5729696FCA234FE78ED6279D164FAB8A"><enum>(1)</enum><text>covered
			 information addressed in this Act; or</text>
					</paragraph><paragraph id="id734BD5E72E2A4B39B1F6F2FB85130EB6"><enum>(2)</enum><text>personally
			 identifiable information or personal identification information addressed in
			 provisions of the law of a State.</text>
					</paragraph></subsection><subsection id="ID58EA0B8D7B86498184C56D916E61C1B5"><enum>(b)</enum><header>Unauthorized
			 civil actions; certain state laws</header>
					<paragraph id="IDAEC0985CE9D54D9F95EC6D34EF695C8B"><enum>(1)</enum><header>Unauthorized
			 actions</header><text>No person other than a person specified in section 403
			 may bring a civil action under the laws of any State if such action is premised
			 in whole or in part upon the defendant violating this Act or a regulation
			 promulgated under this Act.</text>
					</paragraph><paragraph id="ID726CBDD5B9734DB0A6A32A14047815F6"><enum>(2)</enum><header>Protection of
			 certain state laws</header><text>This Act shall not be construed to preempt the
			 applicability of—</text>
						<subparagraph id="ID38B50830DB3B4832A3B8FFCDB0A33CC9"><enum>(A)</enum><text>State laws that
			 address the collection, use, or disclosure of health information or financial
			 information;</text>
						</subparagraph><subparagraph id="IDA09580C38CBC4E6EBAE0A9F2A0AF2B95"><enum>(B)</enum><text>State laws that
			 address notification requirements in the event of a data breach; or</text>
						</subparagraph><subparagraph id="ID199F2041BA474A198F92F5D6C79E55E0"><enum>(C)</enum><text>other State laws
			 to the extent that those laws relate to acts of fraud.</text>
						</subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="ID7741578E61A94B14B36C511333F3DAB7"><enum>(c)</enum><header>Rule of
			 construction relating to required disclosures to government
			 entities</header><text>This Act shall not be construed to expand or limit the
			 duty or authority of a covered entity or third party to disclose personally
			 identifiable information to a government entity under any provision of
			 law.</text>
				</subsection></section><section id="ID8089E0D9CD894FFDAE004119801BADBB"><enum>406.</enum><header>No private
			 right of action</header><text display-inline="no-display-inline">This Act may
			 not be construed to provide any private right of action.</text>
			</section></title><title id="ID1DAB2E3D98B747799A58621C13AC0425"><enum>V</enum><header>Co-regulatory
			 safe harbor programs</header>
			<section id="ID0B24BA96848841EF8BDA9B996129645C"><enum>501.</enum><header>Establishment
			 of safe harbor programs</header>
				<subsection id="IDdfedd18bcc6a45eb804b9ea6c6b22047"><enum>(a)</enum><header>In
			 general</header><text>Not later than 365 days after the date of the enactment
			 of this Act, the Commission shall initiate a rulemaking proceeding to establish
			 requirements for the establishment and administration of safe harbor programs
			 under which a nongovernmental organization will administer a program
			 that—</text>
					<paragraph id="IDe12bfe769e1943cb8f2d03c266769605"><enum>(1)</enum><text>establishes a
			 mechanism for participants to implement the requirements of this Act with
			 regards to—</text>
						<subparagraph id="IDad844a064a0d495f92bd68a9e9110ff9"><enum>(A)</enum><text>certain types of
			 unauthorized uses of covered information as described in paragraph (2);
			 or</text>
						</subparagraph><subparagraph id="id390D2530EDFC4A8E94DE6BF740D6C11C"><enum>(B)</enum><text>any unauthorized
			 use of covered information; and</text>
						</subparagraph></paragraph><paragraph id="ID7f798a505cd5423daa6e5ca477c90c2e"><enum>(2)</enum><text>offers consumers
			 a clear, conspicuous, persistent, and effective means of opting out of the
			 transfer of covered information by a covered entity participating in the safe
			 harbor program to a third party for—</text>
						<subparagraph id="ID7566f8139c9644799096db5a6c68738a"><enum>(A)</enum><text>behavioral
			 advertising purposes;</text>
						</subparagraph><subparagraph id="IDf5bb463f3c9b4286a26c2429e8e5a3b0"><enum>(B)</enum><text>location-based
			 advertising purposes;</text>
						</subparagraph><subparagraph id="ID1a8e65d18a904e2ea3304a0bedd9a2b2"><enum>(C)</enum><text>other specific
			 types of unauthorized use; or</text>
						</subparagraph><subparagraph id="ID6708160a0bba4034a1c8d9a63a373a9d"><enum>(D)</enum><text>any unauthorized
			 use.</text>
						</subparagraph></paragraph></subsection><subsection id="ID03c8c98ee1234bee9d45bc985fc1c466"><enum>(b)</enum><header>Selection of
			 nongovernmental organizations To administer program</header>
					<paragraph id="id675B6EE34AB748DFBF80337AC65A1AB1"><enum>(1)</enum><header>Submittal of
			 applications</header><text>An applicant seeking to administer a program under
			 the requirements established pursuant to subsection (a) shall submit to the
			 Commission an application therefor at such time, in such manner, and containing
			 such information as the Commission may require.</text>
					</paragraph><paragraph id="idDF9DA1ABEFAE4D27806413D8CE578C77"><enum>(2)</enum><header>Notice and
			 receipt of applications</header><text>Upon completion of the rulemaking
			 proceedings required by subsection (a), the Commission shall—</text>
						<subparagraph id="idE8688D0AEBB14B559D06741634276544"><enum>(A)</enum><text>publish a notice
			 in the Federal Register that it will receive applications for approval of safe
			 harbor programs under this title; and</text>
						</subparagraph><subparagraph id="idFDE598136FCB4C33B147D8A0F006BE55"><enum>(B)</enum><text>begin receiving
			 applications under paragraph (1).</text>
						</subparagraph></paragraph><paragraph id="idD2FBE66007AE41208802BF30A51FDFA7"><enum>(3)</enum><header>Selection</header><text>Not
			 later than 270 days after the date on which the Commission receives a completed
			 application under this subsection, the Commission shall grant or deny the
			 application on the basis of the Commission's evaluation of the applicant’s
			 capacity to provide protection of individuals’ covered information with regard
			 to specific types of unauthorized uses of covered information as described in
			 subsection (a)(2) that is substantially equivalent to or superior to the
			 protection otherwise provided under this Act.</text>
					</paragraph><paragraph id="id49C468BC557A4C60800FDF2237B9F38C"><enum>(4)</enum><header>Written
			 findings</header><text>Any decision reached by the Commission under this
			 subsection shall be accompanied by written findings setting forth the basis for
			 and reasons supporting such decision.</text>
					</paragraph></subsection><subsection id="IDcfad05169b7d4fa4b433ad7fd7625b56"><enum>(c)</enum><header>Scope of safe
			 harbor protection</header><text>The scope of protection offered by safe harbor
			 programs approved by the Commission that establish mechanisms for participants
			 to implement the requirements of the Act only for certain uses of covered
			 information as described in subsection (a)(2) shall be limited to participating
			 entities’ use of those particular types of covered information.</text>
				</subsection><subsection id="ID75c3aec5ef0c4bc182e0582c5e33951c"><enum>(d)</enum><header>Supervision by
			 Federal Trade Commission</header>
					<paragraph id="id94E4D62E71584B41A965CCE0C0E1BA39"><enum>(1)</enum><header>In
			 general</header><text>The Commission shall exercise oversight and supervisory
			 authority of a safe harbor program approved under this section through—</text>
						<subparagraph id="id69FB54737F7F4DD3885E10B75EB40DCF"><enum>(A)</enum><text>ongoing review of
			 the practices of the nongovernmental organization administering the
			 program;</text>
						</subparagraph><subparagraph id="idD5E16446693C43C9871A9895FB81A193"><enum>(B)</enum><text>the imposition of
			 civil penalties on the nongovernmental organization if it is not compliant with
			 the requirements established under subsection (a); and</text>
						</subparagraph><subparagraph id="id459BF1A9EB704D0F87950D662FE31EE5"><enum>(C)</enum><text>withdrawal of
			 authorization to administer the safe harbor program under this title.</text>
						</subparagraph></paragraph><paragraph id="idD6D2C6564870456B9B268EDDFAA5614A"><enum>(2)</enum><header>Annual reports
			 by nongovernmental organizations</header><text>Each year, each nongovernmental
			 organization administering a safe harbor program under this section shall
			 submit to the Commission a report on its activities under this title during the
			 preceding year.</text>
					</paragraph></subsection></section><section id="ID23e53dc29c964d5d92130ea1075d5e8f"><enum>502.</enum><header>Participation
			 in safe harbor program</header>
				<subsection id="IDbcdbd78a42bd450980eb431314d14e5e"><enum>(a)</enum><header>Exemption</header><text>Any
			 covered entity that participates in, and demonstrates compliance with, a safe
			 harbor program administered under section 501 shall be exempt any provision of
			 title II or title III if the Commission finds that the requirements of the safe
			 harbor program are substantially the same as or more protective of privacy of
			 individuals than the requirements of the provision from which the exemption is
			 granted.</text>
				</subsection><subsection id="ID6e0f506394ef40ea88d637b04cbadc6b"><enum>(b)</enum><header>Limitation</header><text>Nothing
			 in this title shall be construed to exempt any covered entity participating in
			 a safe harbor program from compliance with any other requirement of the
			 regulations promulgated under this Act for which the safe harbor does not
			 provide an exception.</text>
				</subsection></section></title><title id="ID8C8750AA42DD466AA0960D135ACD04B7"><enum>VI</enum><header>Application with
			 other Federal laws</header>
			<section id="ID2D1058163FFC4DFFAAD3C3A95F03B438"><enum>601.</enum><header>Application
			 with other Federal laws</header>
				<subsection id="id469DAFFB2E2349F993E670D4E2B12587"><enum>(a)</enum><header>Qualified
			 exemption for persons subject to other Federal privacy laws</header><text>If a
			 person is subject to a provision of this Act and a provision of a Federal
			 privacy law described in subsection (d), such provision of this Act shall not
			 apply to such person to the extent that such provision of Federal privacy law
			 applies to such person.</text>
				</subsection><subsection id="id0478D44F94FB414A8D1EFD343D2C1784"><enum>(b)</enum><header>Protection of
			 other Federal privacy laws</header><text>Nothing in this Act may be construed
			 to modify, limit, or supersede the operation of the Federal privacy laws
			 described in subsection (d) or the provision of information permitted or
			 required, expressly or by implication, by such laws, with respect to Federal
			 rights and practices.</text>
				</subsection><subsection id="id18164BD22E5941CE91C83C16021FBBED"><enum>(c)</enum><header>Communications
			 infrastructure and privacy</header><text>If a person is subject to a provision
			 of section 222 or 631 of the Communications Act of 1934 (47 U.S.C. 222 and 551)
			 and a provision of this Act, such provision of such section 222 or 631 shall
			 not apply to such person to the extent that such provision of this Act applies
			 to such person.</text>
				</subsection><subsection id="id202C58563ACB4085B418ECA432F90CA7"><enum>(d)</enum><header>Other Federal
			 privacy laws described</header><text>The Federal privacy laws described in this
			 subsection are as follows:</text>
					<paragraph id="idE831933693EE41EB93AFB88C3BC8F238"><enum>(1)</enum><text>Section 552a of
			 title 5, United States Code (commonly known as the Privacy Act of 1974).</text>
					</paragraph><paragraph id="idB63161AAF6DD4241B4C7D69E1B28544C"><enum>(2)</enum><text>The Right to
			 Financial Privacy Act of 1978 (12 U.S.C. 3401 et seq.).</text>
					</paragraph><paragraph id="id61E02E4C47B0412EAFC5C19456F601A6"><enum>(3)</enum><text>The Fair Credit
			 Reporting Act (15 U.S.C. 1681 et seq.).</text>
					</paragraph><paragraph id="idD785C582E782479196F7A655C12E1357"><enum>(4)</enum><text>The Fair Debt
			 Collection Practices Act (15 U.S.C. 1692 et seq.).</text>
					</paragraph><paragraph id="id23C9C59C82CA46878B7ED0E438D910C8"><enum>(5)</enum><text>The Children’s
			 Online Privacy Protection Act of 1998 (15 U.S.C. 6501 et seq.).</text>
					</paragraph><paragraph id="id325326C01FD7437AA0908468EE29B805"><enum>(6)</enum><text>Title V of the
			 Gramm-Leach-Bliley Act of 1999 (15 U.S.C. 6801 et seq.).</text>
					</paragraph><paragraph id="id40190CA5472D4652A167100F55E1B16E"><enum>(7)</enum><text>Chapters 119,
			 123, and 206 of title 18, United States Code.</text>
					</paragraph><paragraph id="idD4DB16240A0C4776A395DDE94764F9C3"><enum>(8)</enum><text>Section 2710 of
			 title 18, United States Code.</text>
					</paragraph><paragraph id="id224B61A4BADE4CA7A417B2389CCEA369"><enum>(9)</enum><text>Section 444 of
			 the General Education Provisions Act (20 U.S.C. 1232g) (commonly referred to as
			 the <quote>Family Educational Rights and Privacy Act of 1974</quote>).</text>
					</paragraph><paragraph id="id74D2C21101F5405F8A02E380885D269B"><enum>(10)</enum><text>Section 445 of
			 the General Education Provisions Act (20 U.S.C. 1232h).</text>
					</paragraph><paragraph id="id47C5DCD2A01C4F5A95BE73632F20A73D"><enum>(11)</enum><text>The Privacy
			 Protection Act of 1980 (42 U.S.C. 2000aa et seq.).</text>
					</paragraph><paragraph id="idA52B77783F364C7C8146F02520EED9B6"><enum>(12)</enum><text>The regulations
			 promulgated under section 264(c) of the Health Insurance Portability and
			 Accountability Act of 1996 (42 U.S.C. 1320d–2 note), as such regulations relate
			 to a person described in section 1172(a) of the Social Security Act (42 U.S.C.
			 1320d–1(a)) or to transactions referred to in section 1173(a)(1) of such Act
			 (42 U.S.C. 1320d–2(a)(1)).</text>
					</paragraph><paragraph id="idEDA5E0AD214249318F79504927971C7C"><enum>(13)</enum><text>The
			 Communications Assistance for Law Enforcement Act (47 U.S.C. 1001 et
			 seq.).</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="idB6F4BBE20F8243159E8BB1DF988D985D"><enum>(14)</enum><text>Section 227 of
			 the Communications Act of 1934 (47 U.S.C. 227).</text>
					</paragraph></subsection></section></title><title id="IDBDC35D4271CB4F0CB2A6B6FD7D95040D"><enum>VII</enum><header>Development of
			 commercial data privacy policy in the Department of Commerce</header>
			<section id="IDBF6BD70197A14643AC74A9E8118D1263"><enum>701.</enum><header>Direction to
			 develop commercial data privacy policy</header><text display-inline="no-display-inline">The Secretary of Commerce shall contribute
			 to the development of commercial data privacy policy by—</text>
				<paragraph id="ID61CE9BDA78BC41FEA09B380A39953856"><enum>(1)</enum><text>convening private
			 sector stakeholders, including members of industry, civil society groups,
			 academia, in open forums, to develop codes of conduct in support of
			 applications for safe harbor programs under title V;</text>
				</paragraph><paragraph id="IDCFE93F48EDA448A2AB9C26E6096D1815"><enum>(2)</enum><text>expanding
			 interoperability between the United States commercial data privacy framework
			 and other national and regional privacy frameworks;</text>
				</paragraph><paragraph id="ID06028F7A2A544ED4A12C49ED6CECA8EF"><enum>(3)</enum><text>conducting
			 research related to improving privacy protection under this Act; and</text>
				</paragraph><paragraph id="id81655AE7F0D94310938B87D2A10CBF3E"><enum>(4)</enum><text>conducting
			 research related to improving data sharing practices, including the use of
			 anonymised data, and growing the information economy.</text>
				</paragraph></section></title></legis-body>
</bill>
