<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-MDM20892-PN1-9L-MDS"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>104 S4400 IS: National Biometric Information Privacy Act of 2020</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2020-08-03</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>116th CONGRESS</congress><session>2d Session</session><legis-num>S. 4400</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20200803">August 3, 2020</action-date><action-desc><sponsor name-id="S322">Mr. Merkley</sponsor> (for himself and <cosponsor name-id="S313">Mr. Sanders</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSJU00">Committee on the Judiciary</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To regulate the collection, retention, disclosure, and destruction of biometric information, and for other purposes.</official-title></form><legis-body><section id="idCD43CD084AB743ED89DA96D4389ECED9" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>National Biometric Information Privacy Act of 2020</short-title></quote>.</text></section><section id="idcd02b42c35b147fc9f0d2ea2c8c0a8e8"><enum>2.</enum><header>Definitions</header><text display-inline="no-display-inline"> In this Act:</text><paragraph id="idD2F054623E1F4575AEAF9ED107F9344C"><enum>(1)</enum><header>Biometric identifier</header><text display-inline="yes-display-inline">The term <term>biometric identifier</term>—</text><subparagraph id="id31FF75EBA4244DCEA626088E9BD36BCB"><enum>(A)</enum><text display-inline="yes-display-inline">includes—</text><clause id="idD6A10A32E06D4057A2B478DA03EC16A7"><enum>(i)</enum><text display-inline="yes-display-inline">a retina or iris scan;</text></clause><clause id="idDCF7179B1740449A9A22728051AF9FE0"><enum>(ii)</enum><text display-inline="yes-display-inline">a voiceprint;</text></clause><clause id="idC7BB9D96F8A54B929CA100121EDAC9A4"><enum>(iii)</enum><text display-inline="yes-display-inline">a faceprint (including any face­print derived from a photograph); </text></clause><clause id="id807911A6351F4498AB40673EF4D2B302"><enum>(iv)</enum><text display-inline="yes-display-inline">fingerprints or palm prints; and</text></clause><clause id="idC2C3F32CC36E44D8AC27912515B11483"><enum>(v)</enum><text display-inline="yes-display-inline">any other uniquely identifying information based on the characteristics of an individual’s gait or other immutable characteristic of an individual;</text></clause></subparagraph><subparagraph id="idF8F3EA17195F466FA346794477C5C54C"><enum>(B)</enum><text display-inline="yes-display-inline">does not include writing samples, written signatures, photographs, human biological samples used for valid scientific testing or screening, demographic data, tattoo descriptions, or physical descriptions such as height, weight, hair color, or eye color;</text></subparagraph><subparagraph id="idA0530BC674EA401782D4A81F5DE46731"><enum>(C)</enum><text display-inline="yes-display-inline">does not include donated organs, tissues, or parts or blood or serum stored on behalf of recipients or potential recipients of living or cadaveric transplants and obtained or stored by a federally designated organ procurement agency;</text></subparagraph><subparagraph id="id9AD5A1E0FAEF4882A43E3F3673C8F5D4"><enum>(D)</enum><text display-inline="yes-display-inline">does not include information captured from a patient in a health care setting for a medical purpose or information collected, used, or stored for health care treatment, payment, or operations under the Health Insurance Portability and Accountability Act of 1996 (<external-xref legal-doc="public-law" parsable-cite="pl/104/191">Public Law 104–191</external-xref>); and</text></subparagraph><subparagraph id="id93D05477F0ED4007A3867F973059A8A1"><enum>(E)</enum><text display-inline="yes-display-inline">does not include an x ray, roentgen process, computed tomography, MRI, PET scan, mammography, or other image or film of the human anatomy used to diagnose, prognose, or treat an illness or other medical condition or to further validate scientific testing or screening.</text></subparagraph></paragraph><paragraph id="id1489C3F173DB4284804DA80D154EAE31"><enum>(2)</enum><header>Confidential and sensitive information</header><text display-inline="yes-display-inline">The term <term>confidential and sensitive information</term>—</text><subparagraph id="id703FE2C3D7C34BF8974BC9430876321D"><enum>(A)</enum><text display-inline="yes-display-inline">means personal information that can be used to uniquely identify an individual or an individual’s account or property; and</text></subparagraph><subparagraph id="id844438DA317A4536973BF4C31411FDB6"><enum>(B)</enum><text display-inline="yes-display-inline">includes genetic markers, genetic testing information, unique identifier numbers to locate accounts or property, account numbers, personal identification numbers, pass codes, driver’s license numbers, or Social Security numbers.</text></subparagraph></paragraph><paragraph id="idD5234EAD661B49598B1FE5F5176748BF"><enum>(3)</enum><header>Private entity</header><text display-inline="yes-display-inline">The term <term>private entity</term>—</text><subparagraph id="id931962E8F56243EAB14DE02AD8198494"><enum>(A)</enum><text display-inline="yes-display-inline">means any individual, partnership, corporation, limited liability company, association, or other group, however organized; and</text></subparagraph><subparagraph id="id483F734958DF4A54BA7EEA9EB6E6651B"><enum>(B)</enum><text display-inline="yes-display-inline">does not include any Federal, State, or local government agency or academic institution.</text></subparagraph></paragraph><paragraph id="id618DD7588B6447E98AA4F35B9C5DA846"><enum>(4)</enum><header>Written release</header><text display-inline="yes-display-inline">The term <term>written release</term> means—</text><subparagraph id="idE575C9BB27444E998A33B8F47A1226D3"><enum>(A)</enum><text display-inline="yes-display-inline">specific, discrete, freely given, unambiguous, and informed written consent given by an individual who is not under any duress or undue influence of an entity or third party at the time such consent is given; or</text></subparagraph><subparagraph id="idA782E0067699415488DC45FEA7266312"><enum>(B)</enum><text display-inline="yes-display-inline">in the context of employment, a release executed by an employee as a condition of employment.</text></subparagraph></paragraph></section><section id="id59f12179c6944ef2900e2fa9ba5a50c4"><enum>3.</enum><header>Collection, retention, disclosure, and destruction of biometric information</header><subsection id="id939170c2945742e1be8195227c496a71"><enum>(a)</enum><header>Written policy</header><paragraph id="id1FE51E77BD0D4E35BBFA919BB21D943C"><enum>(1)</enum><header>In general</header><text>Not later than 60 days after the date of the enactment of this Act, any private entity in possession of biometric identifiers or biometric information concerning an individual shall develop and make available to the public a written policy establishing a retention schedule and guidelines for permanently destroying such biometric identifiers and biometric information not later than the earlier of—</text><subparagraph id="id107AE083910F43879129345C218B09FD"><enum>(A)</enum><text>the date on which the initial purpose for collecting or obtaining such identifiers or information has been satisfied, if the individual from whom the biometric information was collected—</text><clause id="id2DC6E25A5C78400FA5F70C3DE971A76C"><enum>(i)</enum><text>freely consented to the original purpose for such collection; and</text></clause><clause id="id9742C649253D4BB6A5E1B9D398351DFA"><enum>(ii)</enum><text>could have declined such collection without consequence; or </text></clause></subparagraph><subparagraph id="idBCBC864402FE4182A7C75390BB689B2C"><enum>(B)</enum><text>1 year after the individual’s last intentional interaction with the private entity. </text></subparagraph></paragraph><paragraph id="id60EBCE0DC75B4E7CA13E5CBEC3EAF977"><enum>(2)</enum><header>Compliance</header><text>Absent a valid warrant or subpoena issued by a court of competent jurisdiction, a private entity in possession of biometric identifiers or biometric information shall comply with the retention schedule and destruction guidelines established pursuant to paragraph (1).</text></paragraph></subsection><subsection id="idcb0be27f844e4906b81d6054cae303e6"><enum>(b)</enum><header>Limitations</header><paragraph id="idA029051DE9B94AE4AF0578AC5D1703A8"><enum>(1)</enum><header>In general</header><text>A private entity may not collect, capture, purchase, receive through trade, or otherwise obtain a person’s or a customer’s biometric identifier or biometric information unless—</text><subparagraph id="idCEE82F0926F5406FAF52DC71FAFA5A8B"><enum>(A)</enum><text>the entity requires the identifier or information—</text><clause id="idEB784328E8BF45BB9C00BFD4EE6BE4D3"><enum>(i)</enum><text>to provide a service for the person or customer; or</text></clause><clause id="id40D3A1A7C0C640EE94AE2A5AC77626FC"><enum>(ii)</enum><text>for another valid business purpose specified in the written policy published pursuant to section 3; and</text></clause></subparagraph><subparagraph id="id57A6C808D7B842F681EB6303BF20B57E"><enum>(B)</enum><text>the entity first— </text><clause id="id330f1bf60669474194f2a15206989b4a"><enum>(i)</enum><text>informs the person or customer, or his or her legally authorized representative, in writing—</text><subclause id="idFAFC534A1E534C9ABEEB2987B49EBAA2"><enum>(I)</enum><text>that such biometric identifier or biometric information is being collected or stored; and</text></subclause><subclause id="ide0da22255075438daa2b70bbd502f8c7"><enum>(II)</enum><text>of the specific purpose and length of term for which a biometric identifier or biometric information is being collected, stored, and used; and</text></subclause></clause><clause id="ideb4760de4aad41888ff1c746c278d4d0"><enum>(ii)</enum><text>receives a written release executed by the subject of the biometric identifier or biometric information or by the subject’s legally authorized representative.</text></clause></subparagraph></paragraph><paragraph id="id96CFC00DDBF8408190650082304D8E7E"><enum>(2)</enum><header>Written release</header><text>A written release under paragraph (1)(B)—</text><subparagraph id="id027DC2048BF34DD39247ABEC12A1878B"><enum>(A)</enum><text>may not be sought through, as a part of, or otherwise combined with any other consent or permission seeking instrument or function;</text></subparagraph><subparagraph id="id8AC4031879E4424D9573F9D0E3DDF88B"><enum>(B)</enum><text>may not be combined with an employment contract; and</text></subparagraph><subparagraph id="idC8235DE1D8FC4885873FCC0A7DD2F122"><enum>(C)</enum><text>if it involves a minor, may only be obtained through the minor’s parent or guardian.</text></subparagraph></paragraph></subsection><subsection id="id6f27f6cb350e45beaea338a27ae7977a"><enum>(c)</enum><header>Prohibited acts</header><text>A private entity in possession of a biometric identifier or biometric information may not sell, lease, trade, use for advertising purposes, or otherwise profit from a person’s or a customer’s biometric identifier or biometric information.</text></subsection><subsection id="idaa78f5206e034811ba5689d8f30e1f20"><enum>(d)</enum><header>Disclosure</header><text>A private entity in possession of a biometric identifier or the biometric information of a person, including a consumer, job applicant, employee, former employee, or contractor, may not disclose, redisclose, sell, lease, trade, use for advertising purposes, otherwise disseminate, or profit from such biometric identifier or biometric information unless—</text><paragraph id="idef9966facdda47bfb2a02a6ed5f0662f"><enum>(1)</enum><text>the subject of the biometric identifier or biometric information, or the subject’s legally authorized representative, provides a written release to such specified action immediately prior to such disclosure or redisclosure, including a description of—</text><subparagraph id="id8FD6782AD0424709B4DDE3042D056F22"><enum>(A)</enum><text>the data that will be disclosed;</text></subparagraph><subparagraph id="idDED3C9E82D31480E994F20388311C447"><enum>(B)</enum><text>the reason for such disclosure; and</text></subparagraph><subparagraph id="id96CFD0EA713D46C3BD8AC3EE4EC65A16"><enum>(C)</enum><text>the recipients of such data;</text></subparagraph></paragraph><paragraph id="idbed968e2f1dc43c48dc5e487ecf1ed31"><enum>(2)</enum><text>the disclosure or redisclosure completes a financial transaction requested or authorized by the subject of the biometric identifier or the biometric information or the subject’s legally authorized representative; or</text></paragraph><paragraph id="id487eeef08c6446d8b86dc0bc1f2bb464"><enum>(3)</enum><text>the disclosure or redisclosure—</text><subparagraph id="id0FC075395FA545408B594E7899FD6F0E"><enum>(A)</enum><text>is required by Federal, State, or municipal law; or</text></subparagraph><subparagraph id="idCF1657F4BBA34848962A1A155EDBB439"><enum>(B)</enum><text>is required pursuant to a valid warrant or subpoena issued by a court of competent jurisdiction.</text></subparagraph></paragraph></subsection><subsection id="ida0d626e542584aff969566041850e485"><enum>(e)</enum><header>Conditions</header><text>A private entity in possession of a biometric identifier or biometric information shall store, transmit, and protect from disclosure all biometric identifiers and biometric information—</text><paragraph id="idAF22326A8BC14D32BEC488AD917B7384"><enum>(1)</enum><text>using the reasonable standard of care within the private entity’s industry; and</text></paragraph><paragraph id="id01d3852c1ab146ed9c94fad99fa84ab1"><enum>(2)</enum><text>in a manner that is the same as, or more protective than, the manner in which the private entity stores, transmits, and protects other confidential and sensitive information.</text></paragraph></subsection><subsection id="id728535536eab48c282e19b1cfaa2d552" commented="no"><enum>(f)</enum><header>Right To know</header><text>Any business that collects, uses, shares, or sells biometric identifiers or biometric information, upon the request of an individual, shall disclose, free of charge, any such information relating to such individual collected during the preceding 12-month period, including—</text><paragraph id="id86f8a46c7aca4b8998f8ff102bc1beda" commented="no"><enum>(1)</enum><text>the categories of personal information;</text></paragraph><paragraph id="id26a2b8aa8198448f8fe1c8ca7274aa79" commented="no"><enum>(2)</enum><text>specific pieces of personal information;</text></paragraph><paragraph id="idc4eb42c07cdb47d98c4c4da2a3917561" commented="no"><enum>(3)</enum><text>the categories of sources from which the business collected personal information;</text></paragraph><paragraph id="id16dd8e6064254e3db1375c4e1b05fcbb" commented="no"><enum>(4)</enum><text>the purposes for which the business uses the personal information;</text></paragraph><paragraph id="id21d448088d9f410d8bc4fc8d0c386c7b" commented="no"><enum>(5)</enum><text>the categories of third parties with whom the business shares the personal information; and</text></paragraph><paragraph id="idc5e736a13ecb4fbfaa48072a0660a2df" commented="no" display-inline="no-display-inline"><enum>(6)</enum><text>the categories of information that the business sells or discloses to third parties. </text></paragraph></subsection></section><section id="id0e02c01583c644e8a72dd252476bfeef"><enum>4.</enum><header>Cause of action</header><subsection id="id59EE8AC2C86B4B449545011B36FEAD64"><enum>(a)</enum><header>In general</header><text display-inline="yes-display-inline">Any individual aggrieved by a violation of section 3 may bring a civil action in a court of competent jurisdiction against a private entity that allegedly committed such violation. Any such violation constitutes an injury-in-fact and a harm to any affected individual.</text></subsection><subsection id="ide7f8fa4f4655491f9022e6fc6f27f2ee"><enum>(b)</enum><header>Admissibility</header><text>Except in a judicial investigation or proceeding alleging a violation of section 3, information obtained in violation of section 3 is not admissible by the Federal Government in any criminal, civil, administrative, or other investigation or proceeding.</text></subsection><subsection id="id2DFF9872DF15463C96834E07D6E3B8AA"><enum>(c)</enum><header>Right to sue</header><text>An individual described in subsection (a) may institute legal proceedings against a private entity alleged to have violated section 3 for the relief described in subsection (e) in any court of competent jurisdiction.</text></subsection><subsection id="id710603141e5e47db88b572295c73f07b"><enum>(d)</enum><header>Enforcement by State attorneys general</header><text>The chief law enforcement officer of a State, or any other State officer authorized by law to bring actions on behalf of the residents of a State, may bring a civil action, as parens patriae, on behalf of the residents of such State in an appropriate district court of the United States to enforce this Act if the chief law enforcement officer or other State officer has reason to believe that the interests of the residents of the State have been or are being threatened or adversely affected by a violation of section 3.</text></subsection><subsection id="idCB1244309E774F6FBA05D989F1778241"><enum>(e)</enum><header>Forms of relief</header><paragraph id="idB453D05A77604A3CB5D5FA9C26BF1953"><enum>(1)</enum><header>In general</header><text>A plaintiff bringing a civil action under this section may recover—</text><subparagraph id="id6b29b10236614ffdbffe6b48fb166d28"><enum>(A)</enum><clause commented="no" display-inline="yes-display-inline" id="id39EF93F011F241CF8EBE07A711E4539A"><enum>(i)</enum><text>for the negligent violations of any provision of section 3, the greater of—</text><subclause id="idCE3AA5817691434F9DC39F3311D77D6D" indent="up1"><enum>(I)</enum><text>$1,000 in liquidated damages per violation; or </text></subclause><subclause indent="up1" id="id0B43A98B085C4DA4BD5E71D965C4A849"><enum>(II)</enum><text>the actual damages suffered by the plaintiff; or</text></subclause></clause><clause indent="up1" id="idD1D38DDC622E478A88154BF2576D846C"><enum>(ii)</enum><text>for the intentional or reckless violation of any provision of section 3, the sum of—</text><subclause id="id641C50C275AA4D9B9CDB77BD9DDEFAA2"><enum>(I)</enum><text>the actual damages suffered by the plaintiff; and</text></subclause><subclause id="idBA06C0F86ACC488C81A70552784448BD"><enum>(II)</enum><text>any punitive damages awarded by the court, which shall be limited to $5,000 per violation;</text></subclause></clause></subparagraph><subparagraph id="ide981177f2a4b422996eb7f701fbe3045"><enum>(B)</enum><text>reasonable attorneys’ fees and costs, including expert witness fees and other litigation expenses; and</text></subparagraph><subparagraph id="idf3b986a5f9364a59ad40fa9a7da30162"><enum>(C)</enum><text>other relief, including an injunction, as the court may deem appropriate.</text></subparagraph></paragraph><paragraph id="id1BE2A4A1E41342A7840A5E72CD8456E6"><enum>(2)</enum><header>Specific performance</header><text>A court may require a private entity to permanently destroy the biometric identifiers, biometric information, or confidential and sensitive information of a plaintiff under this section.</text></paragraph></subsection></section><section id="id7542fd57c6da41f480008e42ab4badaa"><enum>5.</enum><header>Rules of construction</header><text display-inline="no-display-inline">Nothing in this Act may be construed—</text><paragraph id="id8990ED109F43488FB8A6F42517206557"><enum>(1)</enum><text display-inline="yes-display-inline">to impact the admission or discovery of biometric identifiers and biometric information in any action of any kind in any court, or before any tribunal, board, agency, or person;</text></paragraph><paragraph id="id06483f8d36404332b9bc78c3429c328f"><enum>(2)</enum><text>to conflict with the Health Insurance Portability and Accountability Act of 1996 (<external-xref legal-doc="public-law" parsable-cite="pl/104/191">Public Law 104–191</external-xref>);</text></paragraph><paragraph id="idAAA5A95D86804B47AEFE2FFDF097B4E1"><enum>(3)</enum><text>to conflict with title V of the Federal Gramm-Leach-Bliley Act (<external-xref legal-doc="usc" parsable-cite="usc/15/6801">15 U.S.C. 6801</external-xref> et seq.);</text></paragraph><paragraph id="id63d436d99fa74812bf3591b7e1c88128"><enum>(4)</enum><text>to apply to a contractor, subcontractor, or agent of a Federal, State, or local government agency in the course of employment with such agency; or</text></paragraph><paragraph id="id688A568B86354499AB3BBF440E93C1DB"><enum>(5)</enum><text>to preempt or supersede any Federal, State, or local law that imposes a more stringent limitation than the limitations described in section 3.</text></paragraph></section></legis-body></bill> 

