<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" dms-id="H144CA448129D4BE8A61A7EEDBBA70B77" public-private="public" key="H" bill-type="olc"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>117 HR 3854 IH: Small Business Credit Protection Act of 2021</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2021-06-11</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">I</distribution-code><congress display="yes">117th CONGRESS</congress><session display="yes">1st Session</session><legis-num display="yes">H. R. 3854</legis-num><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action display="yes"><action-date date="20210611">June 11, 2021</action-date><action-desc><sponsor name-id="S001214">Mr. Steube</sponsor> introduced the following bill; which was referred to the <committee-name committee-id="HSM00">Committee on Small Business</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title display="yes">To amend the Small Business Act to require that credit reporting companies provide certain protections to small businesses, and for other purposes.</official-title></form><legis-body id="HE7747CE438CF4E868BBEA21D745B619F" style="OLC"><section id="H7D99849D80744381AAEF0307A69EEAEC" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Small Business Credit Protection Act of 2021</short-title></quote>.</text></section><section id="H8573F58FE7484686A1548F757359A880" section-type="subsequent-section"><enum>2.</enum><header>Data breaches</header><subsection id="H33012A9C238349ECBAE7904A89944394"><enum>(a)</enum><header>In general</header><text display-inline="yes-display-inline">The Small Business Act (<external-xref legal-doc="usc" parsable-cite="usc/15/631">15 U.S.C. 631 et seq.</external-xref>) is amended—</text><paragraph id="H2363A5BC7EF440E6A12B48CD03390F71"><enum>(1)</enum><text>by redesignating section 49 (<external-xref legal-doc="usc" parsable-cite="usc/15/631">15 U.S.C. 631</external-xref> note) as section 50; and</text></paragraph><paragraph id="H529FEA4F926F4250BE37086206DA60D3"><enum>(2)</enum><text>by inserting after section 48 (<external-xref legal-doc="usc" parsable-cite="usc/15/657u">15 U.S.C. 657u</external-xref>) the following new section:</text><quoted-block id="H4C4D88A2C55741FA8B61E83D7E48003D" style="OLC"><section id="H0E3885B1C5554F9C8E96207AA3FE11D2"><enum>49.</enum><header>Data breaches</header><subsection id="HBDB0407E499C4D0DA20CD86A38DE3678"><enum>(a)</enum><header>Definition</header><text>In this section—</text><paragraph id="HD9BCD0B7F6BC4698BC5EBF053A63325F"><enum>(1)</enum><text>the term <term>consumer report</term> has the meaning given the term in section 603 of the Fair Credit Reporting Act (<external-xref legal-doc="usc" parsable-cite="usc/15/1681a">15 U.S.C. 1681a</external-xref>); and</text></paragraph><paragraph id="HF34DE9BC2D014AB3951E3C21D36B5FFD"><enum>(2)</enum><text>the term <term>credit reporting company</term>—</text><subparagraph id="HF719C019E293473083E7F3224358876F"><enum>(A)</enum><text>has the meaning given the term <term>consumer reporting agency</term> in section 603 of the Fair Credit Reporting Act (<external-xref legal-doc="usc" parsable-cite="usc/15/1681a">15 U.S.C. 1681a</external-xref>); and</text></subparagraph><subparagraph id="H7F542496B4134D66B8813AFCC60F41AC"><enum>(B)</enum><text>includes an entity that collects commercial credit data.</text></subparagraph></paragraph></subsection><subsection id="HE6F3E34AEE204806BC3C9800F7C2D2B9"><enum>(b)</enum><header>Requirements for reporting breaches</header><paragraph id="HD9A39DFF8F6F4BACAACEFDEF92945F26"><enum>(1)</enum><header>Applicable state law</header><subparagraph id="HC695F1652F254A9799AD8928D99C383F"><enum>(A)</enum><header>In general</header><text>Except as provided in paragraph (2), if nonpublic data of a small business concern that is collected or stored by a credit reporting company has been breached, the credit reporting company shall report the breach promptly and not later than as required under the law of the State in which the small business concern is located.</text></subparagraph><subparagraph id="H8A576D017A604E91BAA54B6CAFCA70FB"><enum>(B)</enum><header>Locations in multiple states</header><text>If a small business concern that is affected by a breach described in subparagraph (A) has locations in more than 1 State, for the purposes of that subparagraph, the law of the State that imposes the shortest period for the reporting of the breach shall apply.</text></subparagraph></paragraph><paragraph id="H3799ABEEDBB6441C850D3CCCFEC02FAD"><enum>(2)</enum><header>Exception</header><subparagraph id="HFD1CCF54F80B4A86AA2C5C9C1623B08D"><enum>(A)</enum><header>In general</header><text>If a small business concern that is affected by a breach described in paragraph (1)(A) is located in a State that does not have a law that imposes a set period for the reporting of the breach, the credit reporting company to which the requirement under that paragraph applies shall report the breach in the most expeditious manner practicable and without unreasonable delay.</text></subparagraph><subparagraph id="H7604A2E94B14422696C133EEB3BABD00"><enum>(B)</enum><header>Rule of construction regarding a law enforcement request</header><text>For the purposes of subparagraph (A), a delay with respect to the reporting of a breach described in that subparagraph that is caused by a requirement to respond to a request submitted by a law enforcement agency shall be construed to be a reasonable delay.</text></subparagraph></paragraph></subsection><subsection id="HF60DAC831C5B408A9CD09A54B9A81615"><enum>(c)</enum><header>Prohibition</header><text>During the 180-day period beginning on the date on which a breach described in subsection (b)(1)(A) occurs, a credit reporting company may not charge a small business concern that is affected by that breach for providing the small business concern with the consumer report of the small business concern.</text></subsection><subsection id="H856151EA43204E0E8034C78D830847CE"><enum>(d)</enum><header>No preemption</header><text>Nothing in this section shall preempt any State law with respect to credit reporting companies.</text></subsection></section><after-quoted-block>.</after-quoted-block></quoted-block></paragraph></subsection><subsection id="H829E5F120BF84626AEDA2E66672B0A43"><enum>(b)</enum><header>GAO report</header><paragraph id="HC1D080EBFCD8488A8DBC2EE5693675F7"><enum>(1)</enum><header>Definitions</header><text>In this subsection, the term <term>credit reporting company</term>—</text><subparagraph id="H64CA2AE92061473DB033520CD945A8AA"><enum>(A)</enum><text>has the meaning given the term <term>consumer reporting agency</term> in section 603 of the Fair Credit Reporting Act (<external-xref legal-doc="usc" parsable-cite="usc/15/1681a">15 U.S.C. 1681a</external-xref>); and</text></subparagraph><subparagraph id="HB3674DA07CD34A4A8E1B8B5B34F21858"><enum>(B)</enum><text>includes an entity that collects commercial credit data.</text></subparagraph></paragraph><paragraph id="H57A58159A541455BAE2A6603356541D6"><enum>(2)</enum><header>Report</header><text>Not later than 1 year after the date of enactment of this Act, the Comptroller General of the United States shall submit to Congress a report regarding the economic harm incurred by small business concerns as a result of data breaches at credit reporting companies.</text></paragraph></subsection></section></legis-body></bill> 

