<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" dms-id="HDA4CB8E026A0496884359607B96BA50C" public-private="public" key="H" bill-type="olc"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>117 HR 9588 IH: Consumer Information Notification Requirement Act</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2022-12-15</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">I</distribution-code><congress display="yes">117th CONGRESS</congress><session display="yes">2d Session</session><legis-num display="yes">H. R. 9588</legis-num><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action display="yes"><action-date date="20221215">December 15, 2022</action-date><action-desc><sponsor name-id="L000569">Mr. Luetkemeyer</sponsor> (for himself, <cosponsor name-id="H001072">Mr. Hill</cosponsor>, <cosponsor name-id="T000480">Mr. Timmons</cosponsor>, <cosponsor name-id="W000816">Mr. Williams of Texas</cosponsor>, <cosponsor name-id="G000589">Mr. Gooden of Texas</cosponsor>, <cosponsor name-id="L000491">Mr. Lucas</cosponsor>, and <cosponsor name-id="D000626">Mr. Davidson</cosponsor>) introduced the following bill; which was referred to the <committee-name committee-id="HBA00">Committee on Financial Services</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title display="yes">To amend the Gramm-Leach-Bliley Act to provide a national standard for financial institution data security and breach notification on behalf of all consumers, and for other purposes.</official-title></form><legis-body id="HBBEF7CF26E404F838C66193D5A260FC3" style="OLC"> 
<section id="H04424D49FC214A42939DA2A4D3882F3A" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Consumer Information Notification Requirement Act</short-title></quote>.</text></section> <section id="H08A2659D2930405ABD4DDAD9008B9F51"><enum>2.</enum><header>Breach notification standards</header><text display-inline="no-display-inline">Section 501 of the Gramm-Leach-Bliley Act (<external-xref legal-doc="usc" parsable-cite="usc/15/6801">15 U.S.C. 6801</external-xref>) is amended—</text> 
<paragraph id="HE60CFF16492E45D9836B627B22EEEA08"><enum>(1)</enum><text>in subsection (b)(3) by striking the period at the end and inserting <quote>, including through the provision of a breach notice in the event of unauthorized access that is reasonably likely to result in identity theft, fraud, or economic loss.</quote>; and</text></paragraph> <paragraph id="H58FD1CE86F4D420BB4EF8701A6584C83"><enum>(2)</enum><text>by adding at the end the following:</text> 
<quoted-block display-inline="no-display-inline" id="HCA95EEADFA7C43358CFC5037132DD97E" style="OLC"> 
<subsection id="HE012FB2AB4A74B45B17F2906BAC6771A"><enum>(c)</enum><header>Standards with respect to breach notification</header><text display-inline="yes-display-inline">Subject to section 504(a)(2) and sections 505(b) and 505(c), within 6 months after the date of enactment of this subsection, each agency or authority required to establish standards described under subsection (b)(3) with respect to the provision of a breach notice shall ensure that such standards are in compliance with subsection (b).</text></subsection> <after-quoted-block>.</after-quoted-block></quoted-block></paragraph></section> <section id="H577F951B3AEA497B8592127BE67576BD"><enum>3.</enum><header>Preemption with respect to financial institution safeguards</header><text display-inline="no-display-inline">Section 507 of the Gramm-Leach-Bliley Act (<external-xref legal-doc="usc" parsable-cite="usc/15/6807">15 U.S.C. 6807</external-xref>) is amended to read as follows:</text> 
<quoted-block display-inline="no-display-inline" id="H93BD98702CFC426FB3366449AEC3D0B0" style="OLC"> 
<section id="HAE52B48B3745404B82B5E2018CCE27FC"><enum>507.</enum><header>Relation to State laws</header> <text display-inline="no-display-inline">This subtitle preempts any law, rule, regulation, requirement, standard, or other provision having the force and effect of law of any State, or political subdivision of a State, with respect to a financial institution (other than a financial institution engaged in providing insurance) or affiliate thereof securing personal information from unauthorized access or acquisition, including notification of unauthorized access or acquisition of data.</text></section><after-quoted-block>.</after-quoted-block></quoted-block></section> </legis-body></bill> 

