<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-LYN19648-PV6-YJ-9SX"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>116 S2889 IS: National Security and Personal Data Protection Act of 2019</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2019-11-18</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>116th CONGRESS</congress><session>1st Session</session><legis-num>S. 2889</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20191118">November 18, 2019</action-date><action-desc><sponsor name-id="S399">Mr. Hawley</sponsor> (for himself, <cosponsor name-id="S374">Mr. Cotton</cosponsor>, and <cosponsor name-id="S350">Mr. Rubio</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSCM00">Committee on Commerce, Science, and Transportation</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To safeguard data of Americans from foreign governments that pose risks to national security by
			 imposing data security requirements and strengthening review of foreign
			 investments, and for other purposes.</official-title></form>
	<legis-body>
 <section id="S1" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>National Security and Personal Data Protection Act of 2019</short-title></quote>.</text>
 </section><section id="id2D2C9054A99F494086D8CA788AE31BE5"><enum>2.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act:</text> <paragraph id="id5FD8130B236949F197A500D2145EE410"><enum>(1)</enum><header>Commission</header><text>The term <term>Commission</term> means the Federal Trade Commission.</text>
			</paragraph><paragraph id="id764EB513A30A4D61B4AABDC05DEC9E0D"><enum>(2)</enum><header>Country of concern</header>
 <subparagraph id="id26B2C1CDC8FE4909A970076A8E4EE142"><enum>(A)</enum><header>In general</header><text>Subject to subparagraph (B)(iii), the term <term>country of concern</term> means—</text> <clause id="id52BE043946A24BCE993FA28EDAC97AB0"><enum>(i)</enum><text>the People's Republic of China;</text>
 </clause><clause id="id16C21D947E6A463998C1C820F2144E7C"><enum>(ii)</enum><text>the Russian Federation; and</text> </clause><clause id="idF7BD3175C52845FDB4EEAA0BFD67A0EE"><enum>(iii)</enum><text>any other country designated by the Secretary of State as being of concern with respect to the protection of data privacy and security.</text>
 </clause></subparagraph><subparagraph id="id144208F12ED14ABD99568F031D63780C"><enum>(B)</enum><header>Designation of countries of concern</header><text>Not later than 1 year after the date of enactment of this Act, and annually thereafter, the Secretary of State shall—</text>
 <clause id="id8FAE614D2C474D42A5259AF8F80AEB84"><enum>(i)</enum><text>review the status of data privacy and security requirements (including by reviewing laws, policies, practices, and regulations related to data privacy and security) in each foreign country to determine—</text>
 <subclause id="idBB268921404041628F01696D3EB5E5F6"><enum>(I)</enum><text>whether it would pose a substantial risk to the national security of the United States if the government of such country gained access to the user data of citizens and residents of the United States; and</text>
 </subclause><subclause id="idFBB5D177A7104AECA88F64398D6A42E5"><enum>(II)</enum><text>whether there is a substantial risk that the government of such country will, in a manner that fails to afford similar respect for civil liberties and privacy as the Constitution and laws of the United States, obtain user data from companies that collect user data;</text>
 </subclause></clause><clause id="id6574DA7247114FD2AD074B3C873B331C"><enum>(ii)</enum><text>designate each country that meets the criteria of clause (i) as a country of concern; and</text> </clause><clause id="id94A77963F57D4671ABF43D7D5D897954"><enum>(iii)</enum><text>remove the designation from any country that was previously designated a country of concern (regardless of whether such designation was pursuant to clause (i) or (ii) of subparagraph (A) or was made by the Secretary of State pursuant to clause (iii) of such subparagraph) if the country—</text>
 <subclause id="idBF7F481F822146C2B16FAD06E5EADD36"><enum>(I)</enum><text>no longer meets the criteria of clause (i); and</text> </subclause><subclause id="id9BCB1D80F7A0421DBA9035DEBDCC3EBA"><enum>(II)</enum><text>is not at substantial risk of meeting such criteria.</text>
 </subclause></clause></subparagraph><subparagraph id="idC0A7187858E54768BCC17DBBDEA533F2"><enum>(C)</enum><header>Regulations</header><text>Not later than 90 days after the date of the enactment of this Act, the Secretary of State shall prescribe regulations—</text>
 <clause id="idae6ea0447c444baa8199360f587ea195"><enum>(i)</enum><text>establishing a process for a covered technology company or country of concern to petition the Secretary to remove the country of concern designation from a country that was designated as such pursuant to subparagraph (B)(ii); and</text>
 </clause><clause id="id7096479D942F41B49CE3920826ECFB3C"><enum>(ii)</enum><text>setting forth the procedures and criteria the Secretary will use in identifying or removing countries under subparagraphs (A)(iii) or (B)(iii).</text>
 </clause></subparagraph></paragraph><paragraph id="id0550726BD87249C588BC3576C3199167"><enum>(3)</enum><header>Covered technology company</header><text>The term <term>covered technology company</term> means an entity that provides an online data-based service such as a website or internet application in or affecting interstate or foreign commerce and—</text>
 <subparagraph id="id292260279CB04E5E87EDDF0EBDB1ADD5"><enum>(A)</enum><text>is organized under the laws of a country of concern;</text> </subparagraph><subparagraph id="idC7979E2207C045DCB4AEEA1E52E2E361"><enum>(B)</enum><text>in which foreign persons that are nationals of, or companies that are organized under the laws of, countries of concern have a plurality or controlling equity interest;</text>
 </subparagraph><subparagraph id="id808AEE8C41164146AB31382F6B42DB54"><enum>(C)</enum><text>is a subsidiary company of an entity described in subparagraph (A) or (B); or</text> </subparagraph><subparagraph id="id3bc25717c1a941e28362e4f2ddc5d4d8"><enum>(D)</enum><text>is otherwise subject to the jurisdiction of a country of concern in a manner that allows the country of concern to obtain the user data of citizens and residents of the United States without similar respect for civil liberties and privacy as provided under the Constitution and laws of the United States.</text>
 </subparagraph></paragraph><paragraph id="id77B1926E25984AAAB6C1A0C6C4BF5062"><enum>(4)</enum><header>Facial recognition technology</header><text>The term <term>facial recognition technology</term> means technology that analyzes facial features in still or video images and is used to identify, or facilitate identification of, an individual using facial physical characteristics.</text>
			</paragraph><paragraph id="idCB89F781EB1A464297B63A3AF050E58F"><enum>(5)</enum><header>Targeted advertising</header>
 <subparagraph id="id089c7c350e3a49f6b47d4143ff6b89af"><enum>(A)</enum><header>In general</header><text>The term <term>targeted advertising</term> means a form of advertising where advertisements are displayed to a user based on the user’s traits, information from a profile about the user that is created for the purpose of selling advertisements, or the user’s previous online or offline behavior.</text>
 </subparagraph><subparagraph id="id855d71d288994f8394b4bf50a7acd951"><enum>(B)</enum><header>Limitation</header><text>Such term shall not include advertising chosen because of the context of the internet service, such as—</text>
 <clause id="id10d1292199db4a80b0103731cb932f01"><enum>(i)</enum><text>advertising that is directed to a user based on the content of the website, online service, online application, or mobile application that the user is connected to; or</text>
 </clause><clause id="idf4fbb8dd76f64fed91f7e251842ef65b"><enum>(ii)</enum><text>advertising that is directed to a user by the operator of a website, online service, online application, or mobile application based on the search terms that the user used to arrive at such website, service, or application.</text>
 </clause></subparagraph></paragraph><paragraph id="idbd81661140354cc8b5b6a08ddc658dcd"><enum>(6)</enum><header>User data</header><text>The term <term>user data</term> means any information obtained by an entity that provides a data-based service such as a website or internet application that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked with an individual who is a citizen or resident of the United States without regard to whether such information is directly submitted by the individual to the entity, is derived by the entity from the observed activity of the individual, or is obtained by the entity by any other means.</text>
			</paragraph></section><section id="idC8DBF1F17A4647F8808F5AF675768C97"><enum>3.</enum><header>Data security requirements for covered technology companies</header>
 <subsection id="id9F00144025584F49901F3BE208C65DA2"><enum>(a)</enum><header>In general</header><text>The following requirements shall apply to a covered technology company:</text> <paragraph id="id54E7E462FC8B4859B89FF7D2EDEA1C17"><enum>(1)</enum><header>Minimal collection of data</header><text>The company shall not collect any more user data than is necessary for the operation of the website, service, or application of the company.</text>
 </paragraph><paragraph id="id8C21408D4A53453AAE1DF159E21A87B2"><enum>(2)</enum><header>Prohibition on secondary uses</header><text>The company shall not use any user data collected under paragraph (1) for any purpose that is secondary to the operation of the website, service, or application of the company, including providing targeted advertising, unnecessarily sharing such data with a third party, or unnecessarily facilitating facial recognition technology.</text>
 </paragraph><paragraph id="id9633B81F86CF4131BFE3D9CBB3F0B845"><enum>(3)</enum><header>Right to view and delete data</header><text>The company shall allow an individual to—</text> <subparagraph id="id3B32B4DA7DCF420CB1CB25CE7B0A1ADF"><enum>(A)</enum><text>view any user data held by the company that relates to the individual; and</text>
 </subparagraph><subparagraph id="id9B103B3D9BD64B1F97AEF109DEB4F5F8"><enum>(B)</enum><text>permanently delete any user data held by the company that has been collected, directly or indirectly, from the individual.</text>
 </subparagraph></paragraph><paragraph id="id345144AD9DD84DF58751EA5EF90C8AEB"><enum>(4)</enum><header>Prohibition on transfer to countries of concern</header><text>The company shall not transfer any user data or information needed to decipher that data, such as encryption keys, to any country of concern (including indirectly through a third country that is not a country of concern).</text>
 </paragraph><paragraph id="id0054CE7F97424244975A018ED3C8B957"><enum>(5)</enum><header>Data storage requirement</header><text>The company shall not store any user data collected from citizens or residents of the United States or information needed to decipher that data, such as encryption keys, on a server or other data storage device that is located outside of the United States or a country that maintains an agreement with the United States to share data with law enforcement agencies through a process established by law.</text>
 </paragraph><paragraph id="idccb66e94a2064484b7042e658e3a0eed"><enum>(6)</enum><header>Reporting requirement</header><text>Not less frequently than annually, the chief executive officer or equivalent officer of the company shall submit, under penalty of perjury, a report to the Commission, the Attorney General of the United States, and the Attorney General of each State certifying compliance with the requirements of this section.</text>
				</paragraph></subsection><subsection id="idB701E4FADB1444858089BF92D8D6A690"><enum>(b)</enum><header>Exceptions</header>
 <paragraph id="id0FEEB3242B0F45F8A9707108296D99D3"><enum>(1)</enum><header>Exception for law enforcement and military</header><text>The requirements of paragraphs (1) through (4) of subsection (a) shall not apply where data is collected, used, retained, stored, or shared by a covered technology company solely for the purpose of assisting a law enforcement or military agency that is not affiliated with a country of concern.</text>
 </paragraph><paragraph id="id56D852C5A1E446F4B6B0875DEA141D66"><enum>(2)</enum><header>Transfer of shared content</header><text>The requirements of paragraph (4) and (5) of subsection (a) shall not apply to user data that is content produced by a user for the purpose of sharing with other users (such as social media posts, emails, or data related to a transaction involving the user) or information needed to decipher that data provided that the transfer and any storage necessary to enact the transfer is conducted solely to carry out the user’s intent to share such data with individual users in other countries and that necessary storage occurs only on the intended recipient's individual device.</text>
 </paragraph></subsection><subsection id="id0DA46B55CFDC40B692CF5136B1AB6187"><enum>(c)</enum><header>Effective date</header><text>The requirements of this section shall take effect 90 days after the date of enactment of this Act.</text> </subsection></section><section id="idC003BF86AA7E49A380A82C0D09A3DB1F"><enum>4.</enum><header>Data security requirements for other technology companies</header> <subsection id="id9289DE03A04D4FFE9FD98A116D25C9B6"><enum>(a)</enum><header>In general</header><text>The following requirements shall apply to any company operating in or affecting interstate or foreign commerce that provides a data-based service such as a website or internet application but is not a covered technology company:</text>
 <paragraph id="ida50b0812d44b49ea90a6facb28c16f85"><enum>(1)</enum><header>Prohibition on transfer to countries of concern</header><text>The company shall not transfer any user data collected from an individual in the United States or information needed to decipher that data, such as encryption keys, to any country of concern (including indirectly through a third country that is not a country of concern).</text>
 </paragraph><paragraph id="id17d73ccade5d42b5ad21a098c2cc7866"><enum>(2)</enum><header>Prohibition on storing data in countries of concern</header><text>The company shall not store any user data collected from an individual in the United States or information needed to decipher that data, such as encryption keys, on a server or other data storage device that is located in any country of concern.</text>
				</paragraph></subsection><subsection id="idE661673F7158475AA9AB1FE4E435EEC8"><enum>(b)</enum><header>Exceptions</header>
 <paragraph id="idA9A17567C4584BD7A214AACE21DF9A81"><enum>(1)</enum><header>Exception for law enforcement and military</header><text>The requirements of subsection (a) shall not apply where data is collected, used, retained, stored, or shared by a covered technology company solely for the purpose of assisting a law enforcement or military agency that is not affiliated with a country of concern.</text>
 </paragraph><paragraph commented="no" display-inline="no-display-inline" id="id65F46FA6BEF04B2396FC0E990E7275FE"><enum>(2)</enum><header>Transfer of shared content</header><text>The requirements of subsection (a) shall not apply to user data that is content produced by a user for the purpose of sharing with other users (such as social media posts, emails, or data related to a transaction involving the user) or information needed to decipher that data provided that the transfer and any storage necessary to enact the transfer is conducted solely to carry out the user’s intent to share such data with individual users in other countries and that necessary storage occurs only on the intended recipient's individual device.</text>
 </paragraph></subsection><subsection id="idD0F2E99D10DB4210B4E7766F3B43C376"><enum>(c)</enum><header>Effective date</header><text>The requirements of this section shall take effect 90 days after the date of enactment of this Act.</text> </subsection></section><section id="idE857486510804111B9408E3225AEBFD8"><enum>5.</enum><header>Enforcement of data security requirements</header> <subsection id="idbfbc6e8ff1e2441e865badddcf23e976"><enum>(a)</enum><header>Enforcement by the Commission</header> <paragraph id="id61CB6EC06FA446EBB9F76DB93F41E2E9"><enum>(1)</enum><header>In general</header><text>Except as otherwise provided, sections 3 and 4 shall be enforced by the Commission under the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/41">15 U.S.C. 41</external-xref> et seq.).</text>
 </paragraph><paragraph id="id8880f314283e48a79e127802679530fa"><enum>(2)</enum><header>Unfair or deceptive acts or practices</header><text>A violation of section 3 or 4 shall be treated as a violation of a rule defining an unfair or deceptive act or practice prescribed under section 18(a)(1)(B) of the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/57a">15 U.S.C. 57a(a)(1)(B)</external-xref>).</text>
 </paragraph><paragraph id="id8df1a177fe72470c94562b77436f02c9"><enum>(3)</enum><header>Actions by the Commission</header><text>Except as otherwise provided, the Commission shall prevent any person from violating section 3 or 4 in the same manner, by the same means, and with the same jurisdiction, powers, and duties as though all applicable terms and provisions of the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/41">15 U.S.C. 41</external-xref> et seq.) were incorporated into and made a part of this Act, and any person who violates such section shall be subject to the penalties and entitled to the privileges and immunities provided in the Federal Trade Commission Act.</text>
 </paragraph><paragraph commented="no" display-inline="no-display-inline" id="idbc0e6b8dd71b41b487e34b50fa58a185"><enum>(4)</enum><header>Authority preserved</header><text>Nothing in this Act shall be construed to limit the authority of the Commission under any other provision of law.</text>
				</paragraph></subsection><subsection id="id73544F871C76410282BA11DE0691787D"><enum>(b)</enum><header>Criminal penalty</header>
 <paragraph id="id063987A6A9BA45C28F463FE824FB5FAD"><enum>(1)</enum><header>Offense</header><text>It shall be unlawful to knowingly cause a technology company to violate a requirement of section 3 or 4.</text>
 </paragraph><paragraph id="id3BACC2EAEA9E445CBB36A6DC541D1B96"><enum>(2)</enum><header>Penalty</header><text>Any person who violates paragraph (1) shall be imprisoned for not more than 5 years, fined under title 18, United States Code, or both.</text>
				</paragraph></subsection><subsection id="idA0C7C3D448EC4F11B34BBB0554CECCA9"><enum>(c)</enum><header>Enforcement by State attorneys general</header>
				<paragraph id="idab510e6f0abe448f8bf1d3e3e3ee511b"><enum>(1)</enum><header>In general</header>
 <subparagraph id="id868f354ac6a54cccbaaaeca90ba84cbd"><enum>(A)</enum><header>Civil actions</header><text>In any case in which the attorney general of a State has reason to believe that an interest of the residents of that State has been or is threatened or adversely affected by the engagement of any person in a practice that violates section 3 or 4, the State, as parens patriae, may bring a civil action on behalf of the residents of the State in a district court of the United States or a State court of appropriate jurisdiction to—</text>
 <clause id="id26116d125be4424bb73631cdfcbf2167"><enum>(i)</enum><text>enjoin that practice;</text> </clause><clause id="id1d913d02295e438ebfc2befe9c88b0a6"><enum>(ii)</enum><text>enforce compliance with such section;</text>
 </clause><clause id="id7b0b68671e284904be7c5a08c535a648"><enum>(iii)</enum><text>on behalf of residents of the State, obtain damages, statutory damages, restitution, or other compensation, each of which shall be distributed in accordance with State law; or</text>
 </clause><clause id="id2cbaad7a9b124095a02d8230259e1e64"><enum>(iv)</enum><text>obtain such other relief as the court may consider to be appropriate.</text> </clause></subparagraph><subparagraph id="idb65b145a519444f49eaeb9927109267f"><enum>(B)</enum><header>Notice</header> <clause id="id18f850ff9b664be8b4499c85fcddc92a"><enum>(i)</enum><header>In general</header><text>Before filing an action under subparagraph (A), the attorney general of the State involved shall provide to the Commission—</text>
 <subclause id="id86d51e4e9c774b3ba0cd9bf643a4cdc8"><enum>(I)</enum><text>written notice of that action; and</text> </subclause><subclause id="idfd37540892d64a0b9c09a0cfd16c9275"><enum>(II)</enum><text>a copy of the complaint for that action.</text>
							</subclause></clause><clause id="id275633c102e54eed932348ab36b454f5"><enum>(ii)</enum><header>Exemption</header>
 <subclause id="ided175beb99e44c629b47312ea255959e"><enum>(I)</enum><header>In general</header><text>Clause (i) shall not apply with respect to the filing of an action by an attorney general of a State under this paragraph if the attorney general of the State determines that it is not feasible to provide the notice described in that clause before the filing of the action.</text>
 </subclause><subclause id="idaa8e0a4981384286932cdae3b31b295c"><enum>(II)</enum><header>Notification</header><text>In an action described in subclause (I), the attorney general of a State shall provide notice and a copy of the complaint to the Commission at the same time as the attorney general files the action.</text>
							</subclause></clause></subparagraph></paragraph><paragraph id="idaff18975cf904195b1dde2dfc53f4037"><enum>(2)</enum><header>Intervention</header>
 <subparagraph id="idabde30e2902340d6a529561eb4f4089f"><enum>(A)</enum><header>In general</header><text>On receiving notice under paragraph (1)(B), the Commission shall have the right to intervene in the action that is the subject of the notice.</text>
 </subparagraph><subparagraph id="idd9af389d936941aab21ef1835346543a"><enum>(B)</enum><header>Effect of intervention</header><text>If the Commission intervenes in an action under paragraph (1), it shall have the right—</text> <clause id="idf5bb65c05ae7419f89313f59cfad94bc"><enum>(i)</enum><text>to be heard with respect to any matter that arises in that action; and</text>
 </clause><clause id="id05891ee75ee946aeb4a35935a4993d7d"><enum>(ii)</enum><text>to file a petition for appeal.</text> </clause></subparagraph></paragraph><paragraph id="id32dbafa3554142bfacbb9cc3995c9852"><enum>(3)</enum><header>Construction</header><text>For purposes of bringing any civil action under paragraph (1), nothing in this Act shall be construed to prevent an attorney general of a State from exercising the powers conferred on the attorney general by the laws of that State to—</text>
 <subparagraph id="idc37dcf1df7734758b916bad5fbcea6d7"><enum>(A)</enum><text>conduct investigations;</text> </subparagraph><subparagraph id="idef53224e47f2492a9cb00e4cc0513262"><enum>(B)</enum><text>administer oaths or affirmations; or</text>
 </subparagraph><subparagraph id="id3f47484157c64aeb8a27d565a9ca372b"><enum>(C)</enum><text>compel the attendance of witnesses or the production of documentary and other evidence.</text> </subparagraph></paragraph><paragraph id="id0d5d7c6a39524abcb33b18ad8e23fa9f"><enum>(4)</enum><header>Actions by the Commission</header><text>In any case in which an action is instituted by or on behalf of the Commission for violation of section 3 or 4, no State may, during the pendency of that action, institute an action under paragraph (1) against any defendant named in the complaint in the action instituted by or on behalf of the Commission for that violation.</text>
				</paragraph><paragraph id="id9523a9589a5d4af6af91d6006f9572cb"><enum>(5)</enum><header>Venue; service of process</header>
 <subparagraph id="idb8e80a6e234e465bbdaa7cc325aa914a"><enum>(A)</enum><header>Venue</header><text>Any action brought under paragraph (1) may be brought in—</text> <clause id="id5ABC15123F824B6B83B18A4AC2DC109D"><enum>(i)</enum><text>the district court of the United States that meets applicable requirements relating to venue under section 1391 of title 28, United States Code; or</text>
 </clause><clause id="idB50DF2137D0B4A11A677E1CBE28B7787"><enum>(ii)</enum><text>a State court of competent jurisdiction.</text> </clause></subparagraph><subparagraph id="id9dfda314b2ba46968eb8169f83160522"><enum>(B)</enum><header>Service of process</header><text>In an action brought under paragraph (1) in a district court of the United States, process may be served wherever defendant—</text>
 <clause commented="no" display-inline="no-display-inline" id="id63dd487938aa4959b46e985d56721abb"><enum>(i)</enum><text>is an inhabitant; or</text> </clause><clause commented="no" display-inline="no-display-inline" id="id68E3F2FB0E7B402483C634D6F9D77BF2"><enum>(ii)</enum><text>may be found.</text>
						</clause></subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="id9CD47BFDBD214CFB90EE74DDB423BE6F"><enum>(d)</enum><header>Private right of action</header>
 <paragraph commented="no" display-inline="no-display-inline" id="id5A03F62D5ED24B1F905F3125B46097D1"><enum>(1)</enum><header>In general</header><text>Any individual who suffers injury as a result of an act, practice, or omission of a covered technology company that violates section 3 may bring a civil action against such company in any court of competent jurisdiction.</text>
 </paragraph><paragraph commented="no" display-inline="no-display-inline" id="id5BF53BCAF88B424BB56851EA94B5CD6D"><enum>(2)</enum><header>Relief</header><text>In a civil action brought under paragraph (1) in which the plaintiff prevails, the court may award such plaintiff up to $1,000 for each day that such plaintiff was affected by a violation of section 3 (up to a maximum of $15,000 per each such violation per plaintiff).</text>
				</paragraph></subsection></section><section id="id469CA04663EF4D38A3367BE867A0BF9B"><enum>6.</enum><header>Requirement for approval of Committee on Foreign Investment in the United States of certain
 transactions</header><text display-inline="no-display-inline">Section 721(b) of the Defense Production Act of 1950 (<external-xref legal-doc="usc" parsable-cite="usc/50/4565">50 U.S.C. 4565(b)</external-xref>) is amended by adding at the end the following:</text>
			<quoted-block display-inline="no-display-inline" id="id84A25D7E7F784F69917E1EDF4C6FE764" style="OLC">
				<paragraph id="idD2FAABAC224C4634AAA139D65B7D73F6"><enum>(9)</enum><header>Approval required for certain transactions</header>
 <subparagraph id="id162513F83F33492988573E250747BF5A"><enum>(A)</enum><header>In general</header><text>A covered transaction described in subparagraph (C) is prohibited unless the Committee—</text> <clause id="id6DDE278A22C84898915DFD88B92C6137"><enum>(i)</enum><text>reviews the transaction under this subsection; and</text>
 </clause><clause id="id82FC400B5D0A411396469B036FF2F0B8"><enum>(ii)</enum><text>determines that the transaction does not pose a risk to the national security of the United States.</text> </clause></subparagraph><subparagraph commented="no" id="id0D20EE0B8DC94006BB0FEAF08555C456"><enum>(B)</enum><header>Mitigation</header><text>The Committee, or a lead agency on behalf of the Committee, may negotiate, enter into or impose, and enforce an agreement or condition under subsection (l)(3) with any party to a covered transaction described in subparagraph (C) to mitigate any risk to the national security of the United States that arises as a result of the covered transaction.</text>
 </subparagraph><subparagraph commented="no" id="id8461592AB83B4C3580BE2B520F48054E"><enum>(C)</enum><header>Covered transaction described</header><text>A covered transaction described in this subparagraph is a transaction that could result in foreign control of a United States company—</text>
 <clause commented="no" id="id9FD427F0A28945DD930EA62011620DAA"><enum>(i)</enum><text>that collects, sells, buys, or processes user data (as defined in section 2 of the <short-title>National Security and Personal Data Protection Act of 2019</short-title>) and whose business consists substantially more of transferring data than manufacturing, delivering, repairing, or servicing physical goods or providing physical services; or</text>
 </clause><clause commented="no" id="idB7EA9EE545BE4C3EAEABB2E19610C484"><enum>(ii)</enum><text>that operates a social media platform or website.</text></clause></subparagraph></paragraph><after-quoted-block>.</after-quoted-block></quoted-block></section></legis-body></bill> 

