<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" dms-id="HDC413DDE3FE8431BA50D5358A52DF481" public-private="public" key="H" bill-type="olc"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>117 HR 4659 IH: Balancing the Rights Of Web Surfers Equally and Responsibly Act of 2021</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2021-07-22</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">I</distribution-code><congress display="yes">117th CONGRESS</congress><session display="yes">1st Session</session><legis-num display="yes">H. R. 4659</legis-num><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action display="yes"><action-date date="20210722">July 22, 2021</action-date><action-desc><sponsor name-id="M001136">Mrs. McClain</sponsor> (for herself, <cosponsor name-id="B001291">Mr. Babin</cosponsor>, <cosponsor name-id="C001104">Mr. Cawthorn</cosponsor>, <cosponsor name-id="G000576">Mr. Grothman</cosponsor>, <cosponsor name-id="O000086">Mr. Owens</cosponsor>, and <cosponsor name-id="S001214">Mr. Steube</cosponsor>) introduced the following bill; which was referred to the <committee-name committee-id="HIF00">Committee on Energy and Commerce</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title display="yes">To require providers of broadband internet access service and edge services to clearly and conspicuously notify users of the privacy policies of those providers, to give users opt-in or opt-out approval rights with respect to the use of, disclosure of, and access to user information collected by those providers based on the level of sensitivity of the information, and for other purposes.</official-title></form><legis-body id="HE23DF0A652CF4E26B2DA4972F2A23672" style="OLC"><section section-type="section-one" id="H5C5447164D3F40E7A1782F0C90596BC0"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Balancing the Rights Of Web Surfers Equally and Responsibly Act of 2021</short-title></quote> or the <quote><short-title>BROWSER Act of 2021</short-title></quote>.</text></section><section id="H47CBFCD44C5E45CAB23BA25522168782"><enum>2.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act:</text><paragraph id="HF3ABF7AEC8674F65A38372D4928DB73A"><enum>(1)</enum><header>Broadband internet access service</header><subparagraph id="HD37C2CB1828A44CCA54F5B75AA3FAA3D"><enum>(A)</enum><header>In general</header><text>The term <term>broadband internet access service</term> means a mass-market retail service by wire or radio that provides the capability to transmit data to and receive data from all or substantially all internet endpoints, including any capabilities that are incidental to and enable the operation of the communications service, but excluding dial-up internet access service.</text></subparagraph><subparagraph id="H88AE799556F4442987977356C7562BD2"><enum>(B)</enum><header>Functional equivalent; evasion</header><text>The term <term>broadband internet access service</term> includes any service that—</text><clause id="H9D7E92C2937B4F30A52B4059D57B9B80"><enum>(i)</enum><text>the Commission finds to be providing a functional equivalent of the service described in subparagraph (A); or</text></clause><clause id="H2A803759742D42159AAB7CF2DF7B3807"><enum>(ii)</enum><text>is used to evade the protections set forth in this Act.</text></clause></subparagraph></paragraph><paragraph id="H7AF3ECCCF963466F98A93600BB6CD938"><enum>(2)</enum><header>Commission</header><text>The term <term>Commission</term> means the Federal Trade Commission.</text></paragraph><paragraph id="H4375848833BD453B8604A972FAF76709"><enum>(3)</enum><header>Covered service</header><text>The term <term>covered service</term> means—</text><subparagraph id="HAF67DDE3020C49B0B92C004CB93043CE"><enum>(A)</enum><text>broadband internet access service; or</text></subparagraph><subparagraph id="H3A1442940C534269996DECEEDB04753A"><enum>(B)</enum><text>an edge service.</text></subparagraph></paragraph><paragraph id="HE6242738F7484C4DB7CD4E1770EB33A3"><enum>(4)</enum><header>Edge service</header><text>The term <term>edge service</term>—</text><subparagraph id="H060397E118E84ECB8232635955B67C18"><enum>(A)</enum><text>means a service provided over the internet—</text><clause id="H770BD54FECCC4B55AF758A6D537B398B"><enum>(i)</enum><text>for which the provider requires the user to subscribe or establish an account in order to use the service;</text></clause><clause commented="no" id="HB8DE3C85583D4D24A19C393D98ABCFDB"><enum>(ii)</enum><text>that the user purchases from the provider of the service without a subscription or account;</text></clause><clause id="HFCB90B731CB94895A35EA58EBB44C096"><enum>(iii)</enum><text display-inline="yes-display-inline">by which a program searches for and identifies items in a database that correspond to keywords or characters specified by the user, used especially for finding particular sites on the world wide web; or</text></clause><clause id="H057029D9D02241B9A85722003EBFD841"><enum>(iv)</enum><text>by which the user divulges sensitive user information; and</text></clause></subparagraph><subparagraph id="H4CEBE3BA41A54ECD960D51BDCFE9E33D"><enum>(B)</enum><text>includes a service described in subparagraph (A) that is provided through a software program, including a mobile application.</text></subparagraph></paragraph><paragraph id="H809F1B5481D64494BF85425865D5CA0B"><enum>(5)</enum><header>Emergency services</header><text display-inline="yes-display-inline">The term <term>emergency services</term> has the meaning given the term in section 222 of the Communications Act of 1934 (<external-xref legal-doc="usc" parsable-cite="usc/47/222">47 U.S.C. 222</external-xref>).</text></paragraph><paragraph id="H8C0F10614C974288A8ED845742CB2BDE"><enum>(6)</enum><header>Material</header><text display-inline="yes-display-inline">The term <term>material</term> means, with respect to a change in a privacy policy of a provider of a covered service, any change in the policy that a user of the service, acting reasonably under the circumstances, would consider important to the decisions of the user regarding the privacy of the user, including any change to information required to be included in a privacy notice under section 3.</text></paragraph><paragraph id="H2BC24AB07E3C48B2BB4B03FAF7B75CD0"><enum>(7)</enum><header>Mobile application</header><text>The term <term>mobile application</term> means a software program that runs on the operating system of a mobile device.</text></paragraph><paragraph id="H3A5C3B46B7004C41A1F64143F88F819F"><enum>(8)</enum><header>Non-sensitive user information</header><text>The term <term>non-sensitive user information</term> means any user information that is not sensitive user information.</text></paragraph><paragraph id="HCBE504DA14A2494AAEB030D3E1C3B25C"><enum>(9)</enum><header>Opt-in approval</header><text display-inline="yes-display-inline">The term <term>opt-in approval</term> means a method for obtaining from a user of a covered service consent to use, disclose, or permit access to sensitive user information under which the provider of the service obtains express consent allowing the requested usage of, disclosure of, or access to the sensitive user information.</text></paragraph><paragraph id="H3646D2C08A1E41A9830628D3CDC879BA"><enum>(10)</enum><header>Opt-out approval</header><text display-inline="yes-display-inline">The term <term>opt-out approval</term> means a method for obtaining from a user of a covered service consent to use, disclose, or permit access to non-sensitive user information under which the user is deemed to have consented to the use of, disclosure of, or access to the non-sensitive user information if the user has failed to object to the use, disclosure, or access.</text></paragraph><paragraph id="HFCD3E1B20CBA4FACB91CB1A524B562D4"><enum>(11)</enum><header>Public safety answering point</header><text>The term <term>public safety answering point</term> has the meaning given the term in section 222 of the Communications Act of 1934 (<external-xref legal-doc="usc" parsable-cite="usc/47/222">47 U.S.C. 222</external-xref>).</text></paragraph><paragraph id="HEBC434AD96D04141A58BF7B1B646BFD4"><enum>(12)</enum><header>Sensitive user information</header><text>The term <term>sensitive user information</term> includes any of the following:</text><subparagraph id="H3C4CFB1D9B314588A53F6AA2BAA3B58C"><enum>(A)</enum><text display-inline="yes-display-inline">Financial information.</text></subparagraph><subparagraph id="H12034206A1834879AB11D70A93AD5C66"><enum>(B)</enum><text>Health information.</text></subparagraph><subparagraph id="H551E73B011674A999C34E6685DABF206"><enum>(C)</enum><text>Information pertaining to children under the age of 13.</text></subparagraph><subparagraph id="H6640D9141F5841F18E9E9024CBE1F229"><enum>(D)</enum><text>Social Security number.</text></subparagraph><subparagraph id="HDA68F191A49C45B2A89CE56A42C3B0D1"><enum>(E)</enum><text>Precise geolocation information.</text></subparagraph><subparagraph id="H0DE29A86F59C478599A6D12AB035B3B9"><enum>(F)</enum><text>Content of communications.</text></subparagraph><subparagraph id="H89FDE30DB8AD4C8785B8D6236FAAB1D2"><enum>(G)</enum><text display-inline="yes-display-inline">Web browsing history, history of usage of a software program (including a mobile application), and the functional equivalents of either.</text></subparagraph></paragraph><paragraph commented="no" id="H825DFE0C55D14B7D8F8BE2D15B6BD0ED"><enum>(13)</enum><header>State</header><text display-inline="yes-display-inline">The term <term>State</term> means each of the several States, the District of Columbia, the Commonwealth of Puerto Rico, Guam, American Samoa, the United States Virgin Islands, the Commonwealth of the Northern Mariana Islands, any other territory or possession of the United States, and each federally recognized Indian Tribe.</text></paragraph><paragraph id="H8CD2E9B7E2CB4AD59DFC22FE51E40EAF"><enum>(14)</enum><header>User</header><text>The term <term>user</term> means, with respect to a covered service, a person who—</text><subparagraph id="H113F963812174089A04FBBCD7A122AFC"><enum>(A)</enum><text display-inline="yes-display-inline">is a current or former—</text><clause id="HFB6953E9FBE74447B7A13BA7B2570A4C"><enum>(i)</enum><text>subscriber to the service; or</text></clause><clause id="H29816BBCEC1745F88C4193EEFF03DE40"><enum>(ii)</enum><text display-inline="yes-display-inline">holder of an account for the service;</text></clause></subparagraph><subparagraph commented="no" id="H988F6FDCDCB94004A3D9D4F87B20B1B4"><enum>(B)</enum><text>purchases the service without a subscription or account;</text></subparagraph><subparagraph id="H453157EF89DB49D1BA42EE9D5A132460"><enum>(C)</enum><text>is an applicant for the service; or</text></subparagraph><subparagraph commented="no" id="H8E471C99809E45E49E099AF2C13FA970"><enum>(D)</enum><text>in the case of a service described in clause (iii) or (iv) of paragraph (4)(A), uses the service.</text></subparagraph></paragraph><paragraph id="HE156DD509BA94353B9DC6234F02CDEDF"><enum>(15)</enum><header>User information</header><text>The term <term>user information</term> means any information that—</text><subparagraph commented="no" id="H9638EFBFB1034B86A964CAAE5CDD7DB1"><enum>(A)</enum><text>a provider of a covered service acquires in connection with the provision of the service; and</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="H3D32BA70083545BA86CB89F7ACC43382"><enum>(B)</enum><text>is linked or reasonably linkable to an individual.</text></subparagraph></paragraph></section><section id="HE2CDDEC3F98B4EBEBC2D85DA7CC826E8"><enum>3.</enum><header>Notice of privacy policies</header><subsection id="HAC69617AC48A47A7937F921708EACCB3"><enum>(a)</enum><header>In general</header><text display-inline="yes-display-inline">A provider of a covered service shall provide a user of the service with clear and conspicuous notice of the privacy policies of the provider with respect to the service.</text></subsection><subsection id="H798E8C9768164E869B9E471595FC4676"><enum>(b)</enum><header>Availability to prospective users</header><text>The notice required by subsection (a) shall be made available to a prospective user of a covered service—</text><paragraph id="HBA8B37023A0542D38CFAB4D67D6A3BE4"><enum>(1)</enum><text>at the point of sale of, subscription to, or establishment of an account for the covered service, prior to that sale, subscription, or establishment, without regard to whether the point of sale, subscription, or establishment is in person, online, over the telephone, or through another means; or</text></paragraph><paragraph id="H8C4441FCB2E046069CA7A8C1CFB215AB"><enum>(2)</enum><text>if there is no such sale, subscription, or establishment, before the user uses the service.</text></paragraph></subsection><subsection id="H24E8CAF3784E4A5696D3EAFEB2569696"><enum>(c)</enum><header>Persistent availability</header><text display-inline="yes-display-inline">The notice required by subsection (a) shall be made persistently available.</text></subsection><subsection id="HE38EF66A3CB2490781E4FA1E3B5388FD"><enum>(d)</enum><header>Material changes</header><text display-inline="yes-display-inline">A provider of a covered service shall provide a user of the service with clear and conspicuous advance notice of any material change to the privacy policies of the provider with respect to the service.</text></subsection></section><section id="HE91C593B21BB4311ACC854DA96AFC7E4"><enum>4.</enum><header>User opt-in or opt-out approval rights based on sensitivity of information</header><subsection id="HC8488CC2C63F4B87BE2C93C34E78C4AA"><enum>(a)</enum><header>Opt-In approval required for sensitive user information</header><text>Except as provided in subsection (c), a provider of a covered service shall obtain opt-in approval from a user to use, disclose, or permit access to the sensitive user information of the user.</text></subsection><subsection id="HC7692DAB05B44954A006C24B04A07164"><enum>(b)</enum><header>Opt-Out approval required for non-Sensitive user information</header><text display-inline="yes-display-inline">Except as provided in subsection (c), a provider of a covered service—</text><paragraph id="HC067CAF5203D400B8700FBD814189AF7"><enum>(1)</enum><text display-inline="yes-display-inline">shall obtain opt-out approval from a user to use, disclose, or permit access to any of the non-sensitive user information of the user; or</text></paragraph><paragraph id="H33ACCB3BFC764967B43F414A83AEF2E3"><enum>(2)</enum><text>if the provider so chooses, may comply with the requirement of paragraph (1) by obtaining opt-in approval from the user to use, disclose, or permit access to any of the non-sensitive user information of the user.</text></paragraph></subsection><subsection id="HA5CFAC960CAF4674AA7D58421ADC80F8"><enum>(c)</enum><header>Limitations and exceptions</header><text display-inline="yes-display-inline">A provider of a covered service may use, disclose, or permit access to user information without user approval for the following purposes:</text><paragraph id="HDEF73E9670544D15A9CC1A4230E1B25C"><enum>(1)</enum><text display-inline="yes-display-inline">In providing the covered service from which the information is derived, or in providing services necessary to, or used in, the provision of the service.</text></paragraph><paragraph id="H17061B518D4E438C8FCB7211D76E1ED3"><enum>(2)</enum><text>To initiate, render, bill for, and collect for the covered service.</text></paragraph><paragraph id="H9D8F564D7C534E7E986820BE0AFDBE41"><enum>(3)</enum><text>To protect the rights or property of the provider, or to protect users of the covered service and other service providers from fraudulent, abusive, or unlawful use of the service.</text></paragraph><paragraph id="H2AB9D343392048189D7C027C01A964DF"><enum>(4)</enum><text>To provide location information or non-sensitive user information—</text><subparagraph id="H39A0DCD3263A43F7BD31C612828C1DDF"><enum>(A)</enum><text display-inline="yes-display-inline">to a public safety answering point, emergency medical service provider or emergency dispatch provider, public safety, fire service, or law enforcement official, or hospital emergency or trauma care facility, in order to respond to the request of the user for emergency services;</text></subparagraph><subparagraph id="H635A52D634FE47E696B629B469A0C7B1"><enum>(B)</enum><text>to inform the legal guardian of the user, or members of the immediate family of the user, of the location of the user in an emergency situation that involves the risk of death or serious physical harm; or</text></subparagraph><subparagraph id="HDF243330FDC84FE2A239D2D6D5417E7C"><enum>(C)</enum><text>to providers of information or database management services solely for purposes of assisting in the delivery of emergency services in response to an emergency.</text></subparagraph></paragraph><paragraph id="HE6BA60EFDA654195AF27F6D2F2DF9049"><enum>(5)</enum><text>As otherwise required or authorized by law.</text></paragraph></subsection><subsection id="HC8C1E99CDB46438EA691B86D1F036417"><enum>(d)</enum><header>Mechanism for exercising user approval</header><paragraph id="HDC9AE1C12AD0437D9DAB22D099260666"><enum>(1)</enum><header>In general</header><text>A provider of a covered service shall make available a simple, easy-to-use mechanism for a user to grant, deny, or withdraw opt-in approval or opt-out approval at any time.</text></paragraph><paragraph id="HF86BEF0902BE4A379D76C3E7C8A90F29"><enum>(2)</enum><header>Form and manner</header><text>The mechanism required by paragraph (1) shall be—</text><subparagraph id="H99237164CD14420DA104AA246A81A45C"><enum>(A)</enum><text>clear and conspicuous; and</text></subparagraph><subparagraph id="H8A142F394DD3485EAF2DCE46861477BE"><enum>(B)</enum><text display-inline="yes-display-inline">made available—</text><clause id="H91309723FE26444787FA9E5F65D2D196"><enum>(i)</enum><text>at no additional cost to the user; and</text></clause><clause id="H55BCF343FD484EE9A51DAF005D97FC4B"><enum>(ii)</enum><text>in a language other than English, if the provider transacts business with the user in that other language.</text></clause></subparagraph></paragraph><paragraph id="H1FF801A3B69E4500A4B67EC61D449821"><enum>(3)</enum><header>Effect</header><text>The grant, denial, or withdrawal of opt-in approval or opt-out approval by a user shall—</text><subparagraph id="HF99A89F8FDB542D89228E63A5BBFF883"><enum>(A)</enum><text>be given effect promptly; and</text></subparagraph><subparagraph id="H8EB9039A6D22412DBEF8D36C2BDF2F84"><enum>(B)</enum><text>remain in effect until the user revokes or limits the grant, denial, or withdrawal of approval.</text></subparagraph></paragraph></subsection></section><section id="HB1AFD19DD50B4AA9A5E15B137C568807"><enum>5.</enum><header>Service offers conditioned on waivers of privacy rights</header><text display-inline="no-display-inline">A provider of a covered service may not—</text><paragraph id="H83A3E919611C4A208A771EB34D5308CD"><enum>(1)</enum><text>condition, or effectively condition, provision of the service on agreement by a user to waive privacy rights guaranteed by law or regulation, including this Act; or</text></paragraph><paragraph id="HDEAA6E70C7B14BCCA1B33E77685A6B81"><enum>(2)</enum><text>terminate the service or otherwise refuse to provide the service as a direct or indirect consequence of the refusal of a user to waive any privacy rights described in paragraph (1).</text></paragraph></section><section id="H42521C3706B347CD8CADF1C2CAF0834D"><enum>6.</enum><header>Enforcement by Federal Trade Commission</header><subsection id="HD5065D2761294632A7631C97292AE1D5"><enum>(a)</enum><header>General application</header><text display-inline="yes-display-inline">The requirements of this Act apply, according to their terms, to—</text><paragraph id="HFD2C850B76E944EE8B616A68602F865A"><enum>(1)</enum><text display-inline="yes-display-inline">those persons, partnerships, and corporations over which the Commission has authority pursuant to section 5(a)(2) of the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/45">15 U.S.C. 45(a)(2)</external-xref>); and</text></paragraph><paragraph commented="no" id="H99C2E1E8510C4729B9F6DEB72F3BF157"><enum>(2)</enum><text display-inline="yes-display-inline">providers of broadband internet access service, notwithstanding the exception in such section 5(a)(2) for common carriers subject to the Communications Act of 1934 (<external-xref legal-doc="usc" parsable-cite="usc/47/151">47 U.S.C. 151 et seq.</external-xref>).</text></paragraph></subsection><subsection id="H9CEF0736B3714CE5B0094D7332335E92"><enum>(b)</enum><header>Unfair or deceptive acts or practices</header><text display-inline="yes-display-inline">A violation of this Act shall be treated as an unfair or deceptive act or practice in or affecting commerce for purposes of section 5(a)(2) of the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/45">15 U.S.C. 45(a)(2)</external-xref>).</text></subsection><subsection id="HBE94F81525B54951A3ADF49432D44D8D"><enum>(c)</enum><header>Powers of Commission</header><text display-inline="yes-display-inline">Except as provided in subsection (a)(2) of this section—</text><paragraph id="HF191AA37AB194B70A09D508408FB831D"><enum>(1)</enum><text>the Commission shall enforce this Act in the same manner, by the same means, and with the same jurisdiction, powers, and duties as though all applicable terms and provisions of the <act-name parsable-cite="FTCA">Federal Trade Commission Act</act-name> (<external-xref legal-doc="usc" parsable-cite="usc/15/41">15 U.S.C. 41 et seq.</external-xref>) were incorporated into and made a part of this Act; and</text></paragraph><paragraph id="H9FEEFBCF2F614187A225993207AF3115"><enum>(2)</enum><text>any person who violates this Act shall be subject to the penalties and entitled to the privileges and immunities provided in the Federal Trade Commission Act.</text></paragraph></subsection></section><section commented="no" id="HC21FEB65EAF84CCAAA5F0B48C04522DC"><enum>7.</enum><header>Relationship to other law</header><subsection id="HFA8EBB267EF9477396FDB29E47BE8E28"><enum>(a)</enum><header>Preemption of State law</header><text display-inline="yes-display-inline">No State or political subdivision of a State shall, with respect to a provider of a covered service subject to this Act, adopt, maintain, enforce, or impose or continue in effect any law, rule, regulation, duty, requirement, standard, or other provision having the force and effect of law relating to or with respect to the privacy of user information.</text></subsection><subsection id="H4D4526C47BA84BD49BCE41DF819DC419"><enum>(b)</enum><header>Other Federal law</header><paragraph id="H69D2FAB7034746F2B60BCE49D0D694AA"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">Except as provided in paragraph (2), nothing in this Act shall be construed to supersede any Federal statute or regulation relating to information privacy.</text></paragraph><paragraph id="H098663BC2CD54AEDBDF1B5D0B4D2958C"><enum>(2)</enum><header>Communications Act of 1934</header><text display-inline="yes-display-inline">Insofar as any provision of the Communications Act of 1934 (<external-xref legal-doc="usc" parsable-cite="usc/47/151">47 U.S.C. 151 et seq.</external-xref>) or any regulations promulgated under that Act apply to any person, partnership, or corporation subject to this Act with respect to privacy policies, terms of service, and practices covered by this Act, the provision or regulations shall have no force or effect, unless the regulations pertain to emergency services.</text></paragraph></subsection></section></legis-body></bill> 

