<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" dms-id="HF0C108104FE142EF8E9ADE99F1CE9F60" public-private="public" key="H" bill-type="olc"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>117 HR 474 IH: Protecting Consumer Information Act of 2021</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2021-01-25</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">I</distribution-code><congress display="yes">117th CONGRESS</congress><session display="yes">1st Session</session><legis-num display="yes">H. R. 474</legis-num><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action display="yes"><action-date date="20210125">January 25, 2021</action-date><action-desc><sponsor name-id="L000582">Mr. Lieu</sponsor> introduced the following bill; which was referred to the <committee-name committee-id="HBA00">Committee on Financial Services</committee-name>, and in addition to the Committee on <committee-name committee-id="HIF00">Energy and Commerce</committee-name>, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned</action-desc></action><legis-type>A BILL</legis-type><official-title display="yes">To direct the Federal Trade Commission to review and potentially revise its standards for safeguarding customer information to ensure that such standards require certain consumer reporting agencies and service providers of such agencies to maintain sufficient safeguards against cyber attacks and related threats, to provide for additional authority to enforce such standards with respect to such agencies and providers, and for other purposes.</official-title></form><legis-body id="HEF351EABD4724484AD59C38D35BD7BEA" style="OLC"><section id="H3AD68DF886974232998DBA8E681A2474" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Protecting Consumer Information Act of 2021</short-title></quote>.</text></section><section id="HADF18A086B65429FB82AABD61846DC34"><enum>2.</enum><header>Standards for cybersecurity safeguards for certain consumer reporting agencies and service providers</header><subsection commented="no" id="H235DDF8FEBC34B738EB5F44D404B6F39"><enum>(a)</enum><header>Review of standards; potential revision</header><paragraph commented="no" id="H914CCAB947B94A859E8474CD117BEC24"><enum>(1)</enum><header>Review</header><text>Not later than 90 days after the date of the enactment of this Act, the Commission shall complete a review of the standards contained in the regulations issued by the Commission under section 501 of the Gramm-Leach-Bliley Act (<external-xref legal-doc="usc" parsable-cite="usc/15/6801">15 U.S.C. 6801</external-xref>) to determine whether such standards require covered consumer reporting agencies and covered service providers to maintain sufficient safeguards to protect customer records and information against cyber attacks and related threats.</text></paragraph><paragraph commented="no" id="H7FB12FF093844752B162DA0CE1FA9402"><enum>(2)</enum><header>Revision</header><text display-inline="yes-display-inline">If the Commission determines in the review completed under paragraph (1) that the standards contained in the regulations issued by the Commission under section 501 of the Gramm-Leach-Bliley Act (<external-xref legal-doc="usc" parsable-cite="usc/15/6801">15 U.S.C. 6801</external-xref>) do not require covered consumer reporting agencies and covered service providers to maintain sufficient safeguards to protect customer records and information against cyber attacks and related threats, not later than 180 days after the date of the completion of the review, the Commission shall, pursuant to section 553 of title 5, United States Code, revise such regulations so as to provide for standards applicable to covered consumer reporting agencies and covered service providers that require such agencies and providers to maintain sufficient safeguards to protect customer records and information against cyber attacks and related threats.</text></paragraph></subsection><subsection id="HD3D972B71A3D4AFDA118ECBE504BCC99"><enum>(b)</enum><header>Investigations</header><paragraph id="HBAF19CFD11114BFBB0D781E37D0A9678"><enum>(1)</enum><header>Initial investigation</header><subparagraph id="H367FD3DC78314D8BB2E5A9A38A084EBC"><enum>(A)</enum><header>In general</header><text>Not later than 18 months after the date described in subparagraph (B), the Commission shall complete an investigation of each person or entity that, as of the date described in such subparagraph, is a covered consumer reporting agency or covered service provider, to determine whether such agency or provider is in compliance with the regulations issued by the Commission under section 501 of the Gramm-Leach-Bliley Act (<external-xref legal-doc="usc" parsable-cite="usc/15/6801">15 U.S.C. 6801</external-xref>).</text></subparagraph><subparagraph id="HE714856DAFCD4583AE2DFB16A8394C0A"><enum>(B)</enum><header>Date described</header><text>The date described in this subparagraph is—</text><clause id="H7004AA43A3DC4E6FAEA471F8ABD7E9BE"><enum>(i)</enum><text>if no revision of such regulations is required by paragraph (2) of subsection (a), the date of the completion of the review required by paragraph (1) of such subsection; or</text></clause><clause id="H99A005281FB545368C19946CA2352D2A"><enum>(ii)</enum><text>if revision of such regulations is required by paragraph (2) of such subsection, the date on which the Commission issues the revised regulations.</text></clause></subparagraph></paragraph><paragraph commented="no" id="HC7D0BF2F363E4FD49A98F12A9B9E10D5"><enum>(2)</enum><header>Subsequent investigations</header><text display-inline="yes-display-inline">From time to time after the date that is 18 months after the date described in paragraph (1)(B), the Commission shall complete an investigation of each covered consumer reporting agency and each covered service provider to determine whether such agency or provider is in compliance with the regulations issued by the Commission under section 501 of the Gramm-Leach-Bliley Act (<external-xref legal-doc="usc" parsable-cite="usc/15/6801">15 U.S.C. 6801</external-xref>).</text></paragraph></subsection></section><section commented="no" id="H9BC7A7A992034A5EAFA770C847B2E271"><enum>3.</enum><header>Enforcement by Federal Trade Commission</header><subsection commented="no" id="H689D6C91B7ED42CF82B57DD6EA753D3A"><enum>(a)</enum><header>Unfair or deceptive acts or practices</header><text display-inline="yes-display-inline">A violation of a regulation issued by the Commission under section 501 of the Gramm-Leach-Bliley Act (<external-xref legal-doc="usc" parsable-cite="usc/15/6801">15 U.S.C. 6801</external-xref>) by a covered consumer reporting agency or a covered service provider shall be treated as a violation of a rule under section 18(a)(1)(B) of the <act-name parsable-cite="FTCA">Federal Trade Commission Act</act-name> (<external-xref legal-doc="usc" parsable-cite="usc/15/57a">15 U.S.C. 57a(a)(1)(B)</external-xref>) regarding unfair or deceptive acts or practices.</text></subsection><subsection commented="no" id="H730A131C243B43B785C9059029C709A2"><enum>(b)</enum><header>Powers of Commission</header><text display-inline="yes-display-inline">The Commission shall enforce, with respect to covered consumer reporting agencies and covered service providers, the regulations issued by the Commission under section 501 of the Gramm-Leach-Bliley Act (<external-xref legal-doc="usc" parsable-cite="usc/15/6801">15 U.S.C. 6801</external-xref>) in the same manner, by the same means, and with the same jurisdiction, powers, and duties as though all applicable terms and provisions of the <act-name parsable-cite="FTCA">Federal Trade Commission Act</act-name> (<external-xref legal-doc="usc" parsable-cite="usc/15/41">15 U.S.C. 41</external-xref> et seq.) were incorporated into and made a part of such section. Any covered consumer reporting agency or covered service provider that violates such a regulation shall be subject to the penalties and entitled to the privileges and immunities provided in the Federal Trade Commission Act.</text></subsection></section><section commented="no" id="H126A390B374A4DDCBA07B02F1E60BAF4"><enum>4.</enum><header>Enforcement by State attorneys general</header><subsection commented="no" id="HF063F27488F4466BB82674451D5CCFB8"><enum>(a)</enum><header>In general</header><text display-inline="yes-display-inline">In any case in which the attorney general of a State, or an official or agency of a State, has reason to believe that an interest of the residents of such State has been or is threatened or adversely affected by an act or practice by a covered consumer reporting agency or covered service provider in violation of a regulation issued by the Commission under section 501 of the Gramm-Leach-Bliley Act (<external-xref legal-doc="usc" parsable-cite="usc/15/6801">15 U.S.C. 6801</external-xref>), the State, as parens patriae, may bring a civil action on behalf of the residents of the State in an appropriate district court of the United States to—</text><paragraph commented="no" id="HB15C88CC534A4C539CF5BB9B3A88B35D"><enum>(1)</enum><text>enjoin such act or practice;</text></paragraph><paragraph commented="no" id="HC39C9B3497824EF9B4D41A96C60DB488"><enum>(2)</enum><text>enforce compliance with such regulation;</text></paragraph><paragraph commented="no" id="H6CA79BE798AE425CBB9337659FC58B22"><enum>(3)</enum><text>obtain damages, restitution, or other compensation on behalf of residents of the State; or</text></paragraph><paragraph commented="no" id="HA9343092918944A79EC04822C67784C0"><enum>(4)</enum><text>obtain such other legal and equitable relief as the court may consider to be appropriate.</text></paragraph></subsection><subsection commented="no" id="H7475CC857DAD4DA5A93E3F470F89B2C5"><enum>(b)</enum><header>Notice</header><text>Before filing an action under this section, the attorney general, official, or agency of the State involved shall provide to the Commission a written notice of such action and a copy of the complaint for such action. If the attorney general, official, or agency determines that it is not feasible to provide the notice described in this subsection before the filing of the action, the attorney general, official, or agency shall provide written notice of the action and a copy of the complaint to the Commission immediately upon the filing of the action.</text></subsection><subsection commented="no" id="H18EDFA41A2AE4BE68AB46567664FA8D4"><enum>(c)</enum><header>Authority of Commission</header><paragraph id="H7D83EA404AB74A87B0E58283A04E7149"><enum>(1)</enum><header>In general</header><text>On receiving notice under subsection (b) of an action under this section, the Commission shall have the right—</text><subparagraph commented="no" id="H1596E9C8410E45E6820DBA202665AEFD"><enum>(A)</enum><text>to intervene in the action;</text></subparagraph><subparagraph id="H8E394D78EB97414582BC5BD0757D4CDD"><enum>(B)</enum><text>upon so intervening, to be heard on all matters arising therein; and</text></subparagraph><subparagraph commented="no" id="H13DD0AA49E1742D3B963D9784013129B"><enum>(C)</enum><text>to file petitions for appeal.</text></subparagraph></paragraph><paragraph commented="no" id="HEA79B17754D14CB5B0FF9ABC6D9D22A8"><enum>(2)</enum><header>Limitation on State action while Federal action is pending</header><text display-inline="yes-display-inline">If the Commission or the Attorney General of the United States has instituted a civil action for violation of a regulation issued by the Commission under section 501 of the Gramm-Leach-Bliley Act (<external-xref legal-doc="usc" parsable-cite="usc/15/6801">15 U.S.C. 6801</external-xref>) by a covered consumer reporting agency or covered service provider (referred to in this paragraph as the <quote>Federal action</quote>), no State attorney general, official, or agency may bring an action under this section during the pendency of the Federal action against any defendant named in the complaint in the Federal action for any violation of such regulation alleged in such complaint.</text></paragraph></subsection><subsection commented="no" id="HB236566875A6401CA82597AD44A741F6"><enum>(d)</enum><header>Rule of construction</header><text>For purposes of bringing a civil action under this section, nothing in this Act shall be construed to prevent an attorney general, official, or agency of a State from exercising the powers conferred on the attorney general, official, or agency by the laws of such State to conduct investigations, administer oaths and affirmations, or compel the attendance of witnesses or the production of documentary and other evidence.</text></subsection></section><section id="HDFE2F8F27F864021803C76EFD61FF783"><enum>5.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act:</text><paragraph id="H4327E7680EF54634B91A3F8B7A50E12C"><enum>(1)</enum><header>Commission</header><text>The term <term>Commission</term> means the Federal Trade Commission.</text></paragraph><paragraph id="H12BA2B73FA2A49C2A05EBD8B7BE6E22D"><enum>(2)</enum><header>Covered consumer reporting agency</header><text display-inline="yes-display-inline">The term <term>covered consumer reporting agency</term> means a consumer reporting agency that compiles and maintains files on consumers on a nationwide basis (as defined in section 603(p) of the Fair Credit Reporting Act (<external-xref legal-doc="usc" parsable-cite="usc/15/1681a">15 U.S.C. 1681a(p)</external-xref>)).</text></paragraph><paragraph id="HC1C5CD0DE6BF42AE95FD15CDF06E1812"><enum>(3)</enum><header>Covered service provider</header><text>The term <term>covered service provider</term> means any person or entity that is a service provider (as defined in section 314.2 of title 16, Code of Federal Regulations) through provision of services to a covered consumer reporting agency.</text></paragraph></section></legis-body></bill> 

