<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-MUR21299-RX3-G5-FYY">
<metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>117 S1444 IS: Mind Your Own Business Act of 2021</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2021-04-29</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code>
<congress>117th CONGRESS</congress><session>1st Session</session>
<legis-num>S. 1444</legis-num>
<current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber>
<action>
<action-date date="20210429">April 29, 2021</action-date>
<action-desc><sponsor name-id="S247">Mr. Wyden</sponsor> introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSFI00">Committee on Finance</committee-name></action-desc>
</action>
<legis-type>A BILL</legis-type>
<official-title>To amend the Federal Trade Commission Act to establish requirements and responsibilities for entities that use, store, or share personal information, to protect personal information, and for other purposes.</official-title>
</form>
<legis-body display-enacting-clause="yes-display-enacting-clause" id="H74450B4C99BE4500BE9556B4D3607FC1">
<section section-type="section-one" id="id71549E79A3AF4773A91B264E5479CD31"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Mind Your Own Business Act of 2021</short-title></quote>.</text></section> <section id="idf5141f8064424e08b9cc21a6a7ef85be"><enum>2.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act:</text>
<paragraph id="id5e61414eeedd45179bb0439326dcefd7"><enum>(1)</enum><header>Automated decision system</header><text>The term <term>automated decision system</term> means a computational process, including one derived from machine learning, statistics, or other data processing or artificial intelligence techniques, that makes a decision or facilitates human decision making, that impacts consumers.</text></paragraph> <paragraph id="idb623d65993b349c088a413a1457f1547"><enum>(2)</enum><header>Automated decision system impact assessment</header><text>The term <term>automated decision system impact assessment</term> means a study evaluating an automated decision system and the automated decision system’s development process, including the design and training data of the automated decision system, for impacts on accuracy, fairness, bias, discrimination, privacy, and security that includes, at a minimum—</text>
<subparagraph id="idfe28c194cf1a454c9be77f32798780a3"><enum>(A)</enum><text>a detailed description of the automated decision system, its design, its training, data, and its purpose;</text></subparagraph> <subparagraph id="id43a906a109b14a9d9e0138df1a54949d"><enum>(B)</enum><text>an assessment of the relative benefits and costs of the automated decision system in light of its purpose, taking into account relevant factors, including—</text>
<clause id="id9C7EDBB3AD4D4ABF8CB6554EEFB27693"><enum>(i)</enum><text>data minimization practices;</text></clause> <clause id="idCE6948DEFF0D4EAC882A0E1CBA5B7648"><enum>(ii)</enum><text>the duration for which personal information and the results of the automated decision system are stored;</text></clause>
<clause id="id0A51F3754B2447459E00E95ADF52BAB5"><enum>(iii)</enum><text>what information about the automated decision system is available to consumers;</text></clause> <clause id="id398D19A745A747239A48DFDB91851A1C"><enum>(iv)</enum><text>the extent to which consumers have access to the results of the automated decision system and may correct or object to its results; and</text></clause>
<clause id="idA5DDCF55E1E1463E85D3B983B902CB91"><enum>(v)</enum><text>the recipients of the results of the automated decision system;</text></clause></subparagraph> <subparagraph id="id77fdfba7969b4b3b8d992a50964e6c08"><enum>(C)</enum><text>an assessment of the risks posed by the automated decision system to the privacy or security of personal information of consumers and the risks that the automated decision system may result in or contribute to inaccurate, unfair, biased, or discriminatory decisions impacting consumers; and</text></subparagraph>
<subparagraph id="id2384a2a833d2483dab25aaf7b3d095e7"><enum>(D)</enum><text>the measures the covered entity will employ to minimize the risks described in subparagraph (C), including technological and physical safeguards.</text></subparagraph></paragraph> <paragraph id="idf35f702e02c5448186abb9ffa12f06c9"><enum>(3)</enum><header>Commission</header><text>The term <term>Commission</term> means Federal Trade Commission.</text></paragraph>
<paragraph id="id71689d68ae174c9fa35020ecfd302587"><enum>(4)</enum><header>Consumer</header><text>The term <term>consumer</term> means an individual.</text></paragraph> <paragraph id="idae99d6cc92c84c6ebaa1445e78ab1e17"><enum>(5)</enum><header>Covered entity</header><text>The term <term>covered entity</term>—</text>
<subparagraph id="idd576e57cd2ab41459e40efc95f71fb42"><enum>(A)</enum><text>means any person, partnership, or corporation over which the Commission has jurisdiction under section 5(a)(2) of the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/45">15 U.S.C. 45(a)(2)</external-xref>) that—</text> <clause id="id361578C151EF477BB8B92B300F6B68E9"><enum>(i)</enum><text>had greater than $50,000,000 in average annual gross receipts for the 3-taxable-year period preceding the most recent fiscal year, as determined in accordance with paragraphs (2) and (3) of <external-xref legal-doc="usc" parsable-cite="usc/26/448">section 448(c)</external-xref> of the Internal Revenue Code of 1986;</text></clause>
<clause id="id5FD045EC0A2942F7AD4B52DD92312D82"><enum>(ii)</enum><text>possesses or controls personal information on more than—</text> <subclause id="id284DEDBB535E4B4F97F87C0DDEFAF5DD"><enum>(I)</enum><text>1,000,000 consumers; or</text></subclause>
<subclause id="idC7C0FD8A7BDD45479C05A07DF9C8EC09"><enum>(II)</enum><text>1,000,000 consumer devices;</text></subclause></clause> <clause id="idb73f72cc0d1e4b27abf3d255fd142799"><enum>(iii)</enum><text>is substantially owned, operated, or controlled by a person, partnership, or corporation that meets the requirements under clauses (i) or (ii); or</text></clause>
<clause id="id447ee4a3dcb34d6c8ce19cb9a698383c"><enum>(iv)</enum><text>is a data broker or other commercial entity that, as a substantial part of their business, collects, assembles, or maintains personal information concerning an individual who is not a customer or an employee of that entity in order to sell or trade the information or provide third-party access to the information.</text></clause></subparagraph></paragraph> <paragraph id="id578e021ff5174aecbcc350ac512148a8"><enum>(6)</enum><header>Data protection impact assessment</header><text>The term <term>data protection impact assessment</term> means a study evaluating the extent to which an information system protects the privacy and security of personal information the system processes.</text></paragraph>
<paragraph id="id47886AE9313D4BDDB9287D12ED74C654"><enum>(7)</enum><header>Executive capacity</header><text>The term <term>executive capacity</term> means an assignment within an organization in which the employee primarily—</text> <subparagraph id="idd5544b7f342244469753f090cb304f8d"><enum>(A)</enum><text>directs the management of the organization or a major component or function of the organization;</text></subparagraph>
<subparagraph id="id85757406295447c994b5ce9da4269e20"><enum>(B)</enum><text>establishes the goals and policies of the organization, component, or function;</text></subparagraph> <subparagraph id="id8e0de6f82f864f03bd8686667bf8b2b7"><enum>(C)</enum><text>exercises wide latitude in discretionary decision-making; and</text></subparagraph>
<subparagraph id="ide3fc8afaad0d4979b90bf20db737022b"><enum>(D)</enum><text>receives only general supervision or direction from higher level executives, the board of directors, or stockholders of the organization.</text></subparagraph></paragraph> <paragraph id="id76a9f9122adb431ab7f8045362111a50"><enum>(8)</enum><header>High-risk automated decision system</header><text>The term <term>high-risk automated decision system</term> means an automated decision system that—</text>
<subparagraph id="id087605f1b1ae4eb69a74d8edfa23424c"><enum>(A)</enum><text>taking into account the novelty of the technology used and the nature, scope, context, and purpose of the automated decision system, poses a significant risk—</text> <clause id="id97b7c74542924e9fb38dbeee853d53fc"><enum>(i)</enum><text>to the privacy or security of personal information of consumers; or</text></clause>
<clause id="ida1baa0c6ca5f4ac5840c414cbc2cd030"><enum>(ii)</enum><text>of resulting in or contributing to inaccurate, unfair, biased, or discriminatory decisions impacting consumers;</text></clause></subparagraph> <subparagraph id="iddab894700a344adeb3474f60c72c6e19"><enum>(B)</enum><text>makes decisions, or facilitates human decision making, based on systematic and extensive evaluations of consumers, including attempts to analyze or predict sensitive aspects of their lives, such as their work performance, economic situation, health, personal preferences, interests, behavior, location, or movements, that—</text>
<clause id="id70567c9e7b374c378603c5397fdb5e8e"><enum>(i)</enum><text>alter legal rights of consumers; or</text></clause> <clause id="idb9e927cfb1414e6fb7ae024d94640b14"><enum>(ii)</enum><text>otherwise significantly impact consumers;</text></clause></subparagraph>
<subparagraph id="id2857ae265b8341f38f91fccd565f2ca3"><enum>(C)</enum><text>involves the personal information of a significant number of consumers regarding race, color, national origin, political opinions, religion, trade union membership, genetic data, biometric data, health, gender, gender identity, sexuality, sexual orientation, criminal convictions, or arrests;</text></subparagraph> <subparagraph id="id827c1e5ea7924884a6c237953597bcfe"><enum>(D)</enum><text>systematically monitors a large, publicly accessible physical place; or</text></subparagraph>
<subparagraph id="idc35ac45a50ef49a5881717e6dbaa17b8"><enum>(E)</enum><text>meets any other criteria established by the Commission in regulations issued under section 7(b)(1).</text></subparagraph></paragraph> <paragraph id="idf0c367fa54d044bdbc463f8a06ba7761"><enum>(9)</enum><header>High-risk information system</header><text>The term <term>high-risk information system</term> means an information system that—</text>
<subparagraph id="id6e9c4ebd69ca4e85ba301913e64ffff4"><enum>(A)</enum><text>taking into account the novelty of the technology used and the nature, scope, context, and purpose of the information system, poses a significant risk to the privacy or security of personal information of consumers;</text></subparagraph> <subparagraph id="idfc499a6da62741ffa96461b0013f8442"><enum>(B)</enum><text>involves the personal information of a significant number of consumers regarding race, color, national origin, political opinions, religion, trade union membership, genetic data, biometric data, health, gender, gender identity, sexuality, sexual orientation, criminal convictions, or arrests;</text></subparagraph>
<subparagraph id="idefb946f77335474c8cd6bd81340471c8"><enum>(C)</enum><text>systematically monitors a large, publicly accessible physical place; or</text></subparagraph> <subparagraph id="idb633023817cb4ee19ef9c175ba7bfce2"><enum>(D)</enum><text>meets any other criteria established by the Commission in regulations issued under section 7(b)(1).</text></subparagraph></paragraph>
<paragraph id="id3dead2ebcc2b42868f2cdb1bbcf02abe"><enum>(10)</enum><header>Information system</header><text>The term <term>information system</term>—</text> <subparagraph id="id1E7B04D8DEE640A4A30A0FF9EFE65E8E"><enum>(A)</enum><text>means a process, automated or not, that involves personal information, such as the collection, recording, organization, structuring, storage, alteration, retrieval, consultation, use, sharing, disclosure, dissemination, combination, restriction, erasure, or destruction of personal information; and</text></subparagraph>
<subparagraph id="idC70981A024F7462E94D3999EAA6A8BE6"><enum>(B)</enum><text>does not include automated decision systems.</text></subparagraph></paragraph> <paragraph id="id152e2b0c940c47cd8a4dd17b1ce0a1e1"><enum>(11)</enum><header>Journalism</header><text>The term <term>journalism</term> means the gathering, preparing, collecting, photographing, recording, writing, editing, reporting, or publishing of news or information that concerns local, national, or international events or other matters of public interest for dissemination to the public.</text></paragraph>
<paragraph id="id06a1fd2a95a84d6daf70fc6e96d1e5d9"><enum>(12)</enum><header>Personal information</header><text>The term <term>personal information</term> means any information, regardless of how the information is collected, inferred, or obtained that is reasonably linkable to a specific consumer or consumer device.</text></paragraph> <paragraph id="ide4bc5de14e3d4f48b1945036e50a5f2a"><enum>(13)</enum><header>Share</header><text>The term <term>share</term>—</text>
<subparagraph id="ideea839057e3848c985c1f1823860e9ed"><enum>(A)</enum><text>means the actions of a person, partnership, or corporation transferring information to another person, partnership, or corporation; and</text></subparagraph> <subparagraph id="id3f5fe40b8279431594cd0f4b11ccf533"><enum>(B)</enum><text>includes actions to knowingly—</text>
<clause id="id48655153582443249BCF4A1684165714"><enum>(i)</enum><text>share, exchange, transfer, sell, lease, rent, provide, disclose, or otherwise permit access to information;</text></clause> <clause id="id3898ebc713e34bb9952b46dee63f697b"><enum>(ii)</enum><text>enable or facilitate the collection of personal information by a third party; or</text></clause>
<clause id="idea91b67433a4404a8d3d460a45c7a96c"><enum>(iii)</enum><text>use personal information substantially at the direction of or substantially for the benefit of a third party.</text></clause></subparagraph></paragraph> <paragraph id="id91b131dedefb48529b89cffef74cbfbc"><enum>(14)</enum><header>Store</header><text>The term <term>store</term>—</text>
<subparagraph id="id707f2b4dc1494bbaaeb3201581c6fb8d"><enum>(A)</enum><text>means the actions of a person, partnership, or corporation to retain information; and</text></subparagraph> <subparagraph id="id7029f90629a048cc8e46e045dc8ab21e"><enum>(B)</enum><text>includes actions to store, collect, assemble, possess, control, or maintain information.</text></subparagraph></paragraph>
<paragraph id="ided986a5943bd4c488c7414758da6b5ee"><enum>(15)</enum><header>Third party</header><text>The term <term>third party</term> means any person, partnership, or corporation that is not—</text> <subparagraph id="id260b918f25084d1bb19e4a7cbc61dfd3"><enum>(A)</enum><text>the person, partnership, or corporation, whether a covered entity or not, that is sharing the personal information;</text></subparagraph>
<subparagraph id="ide9160cc7f1d4462db8248997fee13bc3"><enum>(B)</enum><text>solely performing an outsourced function of the person, partnership, or corporation sharing the personal information if—</text> <clause id="idF03B365D865A4D28AABB174D478D2ACF"><enum>(i)</enum><text>the person, partnership, or corporation is contractually or legally prohibited from using, storing, or sharing the personal information after the conclusion of the outsourced function; and</text></clause>
<clause id="id307D730492C34AF592BB3C20EF882AA2"><enum>(ii)</enum><text>the person, partnership, or corporation is complying with regulations promulgated under subparagraphs (A) and (B) of section 7(b)(1), regardless of whether the person, partnership, or corporation is a covered entity; or</text></clause></subparagraph> <subparagraph id="idbd548ed42d3b40568b3f1c6980feb42b"><enum>(C)</enum><text>a person, partnership, or corporation for whom the consumer gave opt-in consent for the covered entity to disclose the personal information of the consumer.</text></subparagraph></paragraph>
<paragraph id="idde30ab6821ab49499202ded658bffa6a"><enum>(16)</enum><header>Use</header><text>The term <term>use</term> means the actions of a person, partnership, or corporation in using information, including actions to use, process, or access information.</text></paragraph></section> <section commented="no" display-inline="no-display-inline" id="id360b30fa934b4bb1840caa154bb9cbe1"><enum>3.</enum><header display-inline="yes-display-inline">Noneconomic injury</header><text display-inline="no-display-inline">The first sentence of section 5(n) of the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/45">15 U.S.C. 45(n)</external-xref>) is amended by inserting <quote>, including those involving noneconomic impacts and those creating a significant risk of unjustified exposure of personal information,</quote> after <quote>cause substantial injury</quote>.</text></section>
<section id="id038cbc92c4d147dcb491d8f564b94b04"><enum>4.</enum><header>Civil penalty authority</header><text display-inline="no-display-inline">Section 5 of the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/45">15 U.S.C. 45</external-xref>) is amended—</text> <paragraph id="id7bc7ba414cff4c8d9bdab0a5d6f7bb05"><enum>(1)</enum><text>in subsection (b)—</text>
<subparagraph id="id319968e7f12e4f78b8d327573a1c60da"><enum>(A)</enum><text>in the fifth sentence, by inserting <quote>, and it may, in its discretion depending on the nature and severity of the violation, include in the cease and desist order an assessment of a civil penalty, which shall be not more than an amount that is the greater of $50,000 per violation, taken as an aggregate sum of all violations, and 4 percent of the total annual gross revenue of the person, partnership, or corporation for the prior fiscal year</quote> before the period at the end;</text></subparagraph></paragraph> <paragraph id="id50a37e2433d242d48416ff66f72cf562"><enum>(2)</enum><text>in subsection (l)—</text>
<subparagraph id="ida6c5c412299f4a3eaf2fd1ee4566957a"><enum>(A)</enum><text>in the first sentence, by striking <quote>of not more than $10,000 for each violation</quote> and inserting <quote>, which shall be not more than an amount that is the greater of $50,000 per violation, taken as an aggregate sum of all violations, and 4 percent of the total annual gross revenue of the person, partnership, or corporation for the prior fiscal year</quote>; and</text></subparagraph></paragraph> <paragraph id="id6a8a3cb9808f4990b27b02145c0db3e8"><enum>(3)</enum><text>in subsection (m)(1)—</text>
<subparagraph id="id9c4bb2d7dd4a492295240aa320670bca"><enum>(A)</enum><text>in subparagraph (A), in the second sentence, by striking <quote>of not more than $10,000 for each violation</quote> and inserting <quote>, which shall be not more than an amount that is the greater of $50,000 per violation, taken as an aggregate sum of all violations, and 4 percent of the total annual gross revenue of the person, partnership, or corporation for the prior fiscal year</quote>; and</text></subparagraph> <subparagraph commented="no" display-inline="no-display-inline" id="id3fb10e1199b344bca1cc12e4d9daafa6"><enum>(B)</enum><text>in subparagraph (B), in the matter following paragraph (2), by striking <quote>of not more than $10,000 for each violation</quote> and inserting <quote>, which shall be not more than an amount that is the greater of $50,000 per violation, taken as an aggregate sum of all violations, and 4 percent of the total annual gross revenue of the person, partnership, or corporation for the prior fiscal year</quote>.</text></subparagraph></paragraph></section>
<section id="id083bf700548341f9a75ac70913919bdc"><enum>5.</enum><header>Annual data protection reports</header>
<subsection id="idf7652ed0615841238b37f03b1697ca0a"><enum>(a)</enum><header>Reports</header>
<paragraph id="id48a661940e5044f69dbcd6c0a63cc59e"><enum>(1)</enum><header>In general</header><text>Each covered entity that has not less than $1,000,000,000 per year in revenue and stores, shares, or uses personal information on more than 1,000,000 consumers or consumer devices or any covered entity that stores, shares, or uses personal information on more than 50,000,000 consumers or consumer devices shall submit to the Commission an annual data protection report describing in detail whether, during the reporting period, the covered entity complied with the regulations promulgated in accordance with subparagraphs (A) and (B) of section 7(b)(1). To the extent that the covered entity did not comply with these regulations, this statement shall include a description of which regulations were violated and the number of consumers whose personal information was impacted.</text></paragraph> <paragraph id="idb9c083e2a5c84b5da6eb44e98567f3ab"><enum>(2)</enum><header>Regulations</header><text>Not later than 2 years after the date of enactment of this Act, the Commission shall promulgate regulations in accordance with section 553 of title 5, United States Code, carrying out this subsection.</text></paragraph></subsection>
<subsection id="id1d699dd9539c4aea9447c24844b64edf"><enum>(b)</enum><header>Failure of corporate officers To certify privacy and data security reports</header>
<paragraph id="id6aeb4cbcb82341aab1f6f498aa056416"><enum>(1)</enum><header>In general</header><text><external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/18/63">Chapter 63</external-xref> of title 18, United States Code, is amended by adding at the end the following:</text> <quoted-block style="USC" display-inline="no-display-inline" id="id9ce1b99167e54a549e387c57c3a6daae"> <section id="idCF6F7A7050494E73AEB729832EF4AB03"><enum>1352.</enum><header>Failure of corporate officers to certify data protection reports</header> <subsection id="id7326eaabe6484115acca11049776e70e"><enum>(a)</enum><header>Definitions</header><text>In this section:</text>
<paragraph id="id041D945403D2410A8E873623A1ADB882"><enum>(1)</enum><header>Covered entity</header><text>The term <term>covered entity</term> has the meaning given the term in section 2 of the <short-title>Mind Your Own Business Act of 2021</short-title>.</text></paragraph> <paragraph id="id5453BC50B197434090BE84F7CC32ACA6"><enum>(2)</enum><header>Willfully</header><text>The term <term>willfully</term> means the voluntary, intentional violation of a known legal duty.</text></paragraph></subsection>
<subsection id="id7DD340EEEEFC45F689E49FEBC469475B"><enum>(b)</enum><header>Certification of annual data protection reports</header><text>Each annual report filed by a company with the Federal Trade Commission pursuant to section 5(a) of the <short-title>Mind Your Own Business Act of 2021</short-title> shall be accompanied by a written statement by the chief executive officer and chief privacy officer (or equivalent thereof) of the company.</text></subsection> <subsection id="id83ae4b30f13b4b39843d42246f33afd4"><enum>(c)</enum><header>Content</header><text>The statement required under subsection (b) shall certify that the annual report fully complies with the requirements of section 5(a) of the <short-title>Mind Your Own Business Act of 2021</short-title>.</text></subsection>
<subsection id="idc8a89dd077934d51baa90240feeb37e4"><enum>(d)</enum><header>Criminal penalties</header><text>Whoever—</text> <paragraph id="id4a48a258bc8246fb81674f8efa37e1ca"><enum>(1)</enum><text>certifies any statement as set forth in subsections (b) and (c) of this section knowing that the annual report accompanying the statement does not comport with all the requirements set forth in this section shall be fined not more than the greater of $1,000,000 or 5 percent of the largest amount of annual compensation the person received during the previous 3-year period from the covered entity, imprisoned not more than 10 years, or both; or</text></paragraph>
<paragraph id="ida05a29eee84c4ce69231264a937568ca"><enum>(2)</enum><text>willfully certifies any statement as set forth in subsections (b) and (c) of this section knowing that the annual report accompanying the statement does not comport with all the requirements set forth in this section shall be fined not more than $5,000,000 or 25 percent of the largest amount of annual compensation the person received during the previous 3-year period from the covered entity, imprisoned not more than 20 years, or both.</text></paragraph></subsection></section><after-quoted-block>.</after-quoted-block></quoted-block></paragraph> <paragraph id="idfe77a896c6384466ab008da8a08dfb47"><enum>(2)</enum><header>Technical and conforming amendment</header><text>The table of sections for <external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/18/63">chapter 63</external-xref> of title 18, United States Code, is amended by adding at the end the following:</text>
<quoted-block style="USC" id="id1bffd8c6-3cef-47c3-ba81-0589763ef3a9">
<toc>
<toc-entry idref="idCF6F7A7050494E73AEB729832EF4AB03" level="section">1352. Failure of corporate officers to certify data protection reports.</toc-entry></toc><after-quoted-block>.</after-quoted-block></quoted-block></paragraph></subsection></section>
<section id="idf6f1db7c5f6846ac95e0f3b345d381d8"><enum>6.</enum><header><quote>Do not track</quote> data sharing opt out</header>
<subsection id="id98041b09bbd94cec92ecaf249b91495a"><enum>(a)</enum><header>Regulations</header><text>Not later than 2 years after the date of enactment of this Act, the Commission shall promulgate regulations, in accordance with section 553 of title 5, United States Code, to—</text> <paragraph id="id236b02f8fd5f4543839b287210f5b2a8"><enum>(1)</enum><text>implement and maintain a <quote>Do Not Track</quote> data sharing opt-out website—</text>
<subparagraph id="id564dc70a94d84ea582f57f4396242f83"><enum>(A)</enum><text>that allows consumers to opt-out of data sharing with 1 click after the consumer is logged into the website, view their opt-out status, and change their opt-out status;</text></subparagraph> <subparagraph id="idEB73ADFC049D49D0B85FDCD7061F34A8"><enum>(B)</enum><text>the effect of which opt-out is to prevent—</text>
<clause id="idc296b19a3dc448acaacacec6da8803d7"><enum>(i)</enum><text>covered entities from sharing the personal information of the consumer with third parties, including personal information shared with or stored by the covered entity prior to the opt-out unless—</text> <subclause id="idce50c8f139394132a7540389ee70d1fd"><enum>(I)</enum><text>the sharing is necessary for the primary purpose for which the consumer provided the personal information; and</text></subclause>
<subclause id="idf80370c0c5364ffca1324bd5279e1690"><enum>(II)</enum><text>the third party with whom the personal information was shared does not retain or use the personal information for secondary purposes; and</text></subclause></clause> <clause id="id56d3b2e2fc634b09a8bc8e0aaec4d8be"><enum>(ii)</enum><text>covered entities from storing or using personal information of the consumer that has been shared with them by non-covered entities, not including personal information shared with or stored by the covered entity prior to the opt-out;</text></clause></subparagraph>
<subparagraph id="idC99E1354730C43519ED26F385B3E8717"><enum>(C)</enum><text>that is reasonably accessible and usable by consumers; and</text></subparagraph> <subparagraph id="idd7709ae6ae044b3788337fd0a48372d3"><enum>(D)</enum><text>that enables consumers to make use of the features described in subparagraph (A) through an Application Programming Interface;</text></subparagraph></paragraph>
<paragraph id="idCEA17DF3D71A40AFB301D64FDAB18E3B"><enum>(2)</enum><text>as part of the implementation of the opt-out website described in paragraph (1)—</text> <subparagraph id="id0bf02e2f4f2f49d1aea7b518af0ef58d"><enum>(A)</enum><text>maintain a record of the opt-out status of consumers enrolled through the opt-out website, including the date and time when the consumer opted out;</text></subparagraph>
<subparagraph id="id6559A934D457496485CC5813A98D2225"><enum>(B)</enum><text>enable consumers to convey their opt-out status to covered entities in 1 or more privacy-protecting ways through technological means determined by the Commission, such as through a consumer’s web browser or operating system;</text></subparagraph> <subparagraph id="ida49875f6a412400da408dbb2796e8f0e"><enum>(C)</enum><text>enable covered entities to determine whether a particular consumer is enrolled in the opt-out website in a privacy-preserving way that does not result in the disclosure of any personal information other than a consumer’s opt-out status to that covered entity; and</text></subparagraph>
<subparagraph id="id7CCC901597494621BF0BAA1C58D3ABC0"><enum>(D)</enum><text>enable covered entities to make use of the mechanism described in subparagraph (C) through an Application Programming Interface, for which the Commission may charge a reasonable fee to cover the costs of operating the opt-out registry and access to the system;</text></subparagraph></paragraph> <paragraph id="id42A1B59E94BC4185A75C8ECABF347E7B"><enum>(3)</enum><text>require that a covered entity be bound by the opt-out of a consumer when the opt-out is conveyed through the opt-out website implemented and maintained by the Commission—</text>
<subparagraph id="idFA3AC338C0EE4221970F3F898E0C772D"><enum>(A)</enum><text>immediately for new customers; and</text></subparagraph> <subparagraph id="idA6BAB127109B48B5886A77F0825CD235"><enum>(B)</enum><text>within 30 days for existing customers or consumers who are not customers, unless, after the consumer has opted out in the manner described in paragraph (1)(A), the covered entity receives, in accordance with the procedures described in paragraph (10), consent from the consumer to not be bound by the consumer’s opt-out;</text></subparagraph></paragraph>
<paragraph id="id7170744146aa4d50885c0b765646dd6b"><enum>(4)</enum><text>require covered entities that store or use personal data on consumers with which they—</text> <subparagraph id="idECA26E0D335E432EBE64BB115DE58A52"><enum>(A)</enum><text>do not have a direct relationship; or</text></subparagraph>
<subparagraph id="id58a5dfbebfa445cc9f8932a22ac26bea"><enum>(B)</enum><text>otherwise do not have the ability to determine the consumer’s opt-out preference through one of the technological means established pursuant to paragraph (2)(B);</text></subparagraph><continuation-text continuation-text-level="paragraph">to make a good-faith effort to determine the consumer’s opt-out status at least as frequently as determined by the Commission, through the Application Programming Interface maintained by the Commission pursuant to paragraph (2)(D);</continuation-text></paragraph> <paragraph id="iddd0458cbace04f3581f68aa0c83c3329"><enum>(5)</enum><text>permit covered entities to not be bound by the consumer’s opt-out for—</text>
<subparagraph id="id4d621a4416f3419696ab820a74c355d7"><enum>(A)</enum><text>disclosures made to the government that are either required or permitted by law;</text></subparagraph> <subparagraph id="ide1073946b93d41f485aaaebca8dcb833"><enum>(B)</enum><text>disclosures made pursuant to an order of a court or administrative tribunal;</text></subparagraph>
<subparagraph id="idb1861f1883c142b49d429c7e024d2fc4"><enum>(C)</enum><text>disclosures made in response to a subpoena, discovery request, or other lawful process provided that such process is accompanied by a protective order that—</text> <clause id="idd03b27c1dd60469e9910b54aba2c0217"><enum>(i)</enum><text>prohibits the parties from using or disclosing the personal information for any purpose other than the litigation or proceeding for which such personal information was requested; and</text></clause>
<clause id="idb3c549cdfacb4452ae4a8d8a19240614"><enum>(ii)</enum><text>requires the return to the covered entity or destruction of the personal information (including all copies made) at the end of the litigation or proceeding; or</text></clause></subparagraph> <subparagraph id="idae6579724f5948cca8f4790f08fdcf3a"><enum>(D)</enum><text>disclosures made to investigate, protect themselves and their customers from, or recover from fraud, cyber attacks, or other unlawful activity;</text></subparagraph></paragraph>
<paragraph id="id7c3501ce7a5a41adad172060c5a902f7"><enum>(6)</enum><text>establish standards and procedures, including through an Application Programming Interface, for a covered entity to request, not more frequently than once per calendar year unless a consumer is signing up for a product or service, and obtain consent from a consumer who has opted-out in the manner described in paragraph (1)(A) for the covered entity to not be bound by the opt-out, provided such standards and procedures—</text> <subparagraph id="idf56140c83cfc47a4aa7210b46890c16f"><enum>(A)</enum><text>require the covered entity to provide the consumer, at the time the covered entity is seeking consent, in accordance with paragraph (10), and in a form that is understandable to a reasonable consumer—</text>
<clause id="id846e6d74e7ca4db7acb8cf55be9d82dd"><enum>(i)</enum><text>a list of each third party with whom the personal information of the consumer will or may be shared by the covered entity;</text></clause> <clause id="ida443c210a99241cdb4f12e461a6e45ca"><enum>(ii)</enum><text>a description of the personal information of that consumer that will or may be shared; and</text></clause>
<clause id="idd4da9208ef8a4409b9e642c01c194868"><enum>(iii)</enum><text>a description of the purposes for which the personal information of that consumer will or may be shared;</text></clause></subparagraph> <subparagraph id="id9143cc5cf32d45448943c3d0e9a36324"><enum>(B)</enum><text>if the covered entity requires consent as a condition for providing a product or service, require the covered entity to—</text>
<clause id="idC92ABE4108ED4F55A571B9228F0DCE93"><enum>(i)</enum><text>notify the consumer that he or she can obtain a substantially similar product or service in exchange for monetary payment or other compensation rather than by permitting the covered entity to share the consumer’s personal information, as provided in subsection (b)(1)(B); and</text></clause> <clause id="idDB548183468742F2A2B5E23284C6DD43"><enum>(ii)</enum><text>with respect to the notice described in clause (i)—</text>
<subclause id="id7A6CBBFA0C974D469410221588F01B9E"><enum>(I)</enum><text>make the notice in a clear and conspicuous manner; and</text></subclause> <subclause id="idA296B378DA4E45C79B0DC9249F338980"><enum>(II)</enum><text>include the cost of the fee, if any, and instructions for obtaining the substantially similar product or service described in clause (i);</text></subclause></clause></subparagraph>
<subparagraph id="idf897b8c2e44b4b2987424938bf1ff478"><enum>(C)</enum><text>if the covered entity does not require consent as a condition for providing a product or service, require the covered entity to clearly and conspicuously notify the consumer that the consumer may refuse to provide consent but still obtain the product or service; and</text></subparagraph> <subparagraph id="idd3cfb90653fb4b41a7f8758ce78df910"><enum>(D)</enum><text>require the covered entity to notify the consumer of his or her right, and how to exercise that right, to later withdraw consent for the covered entity to not be bound by the consumer’s opt-out;</text></subparagraph></paragraph>
<paragraph id="id4261fcdb42414dc5a3d656e00740a4a8"><enum>(7)</enum><text>not less frequently than every 2 years, examine the information that is presented to consumers in accordance with the procedures described in paragraph (6) to make sure that the information is useful, understandable, and to the extent possible, does not result in notification and consent fatigue;</text></paragraph> <paragraph id="idb354be5ac2c94727a140eb0f74e2efd8"><enum>(8)</enum><text>establish standards and procedures requiring that when a non-covered entity that is not the consumer shares personal information about that consumer with a covered entity, the covered entity shall make reasonable efforts to verify the opt-out status of the consumer whose personal information has been shared with the covered entity, after which the covered entity may only store or use that personal information for the benefit of the covered entity—</text>
<subparagraph id="idDF9F73FC980C48AD8E90D2DB182FD1A3"><enum>(A)</enum><text>if the consumer has not opted-out in the manner described in paragraph (2)(A); or</text></subparagraph> <subparagraph id="id37c141758b2d470c8c5a258de4ef92f7"><enum>(B)</enum> <clause commented="no" display-inline="yes-display-inline" id="id34B9F119D056400291649F62998C3062"><enum>(i)</enum><text>if the non-covered entity knowingly enabled or facilitated the collection of personal information by the covered entity and the covered entity itself receives consent from the consumer to store or use the consumer’s personal information in accordance with paragraph (9); or</text></clause>
<clause id="id7E378B14023B40538FDC024EDD0F6810" indent="up1"><enum>(ii)</enum><text>if the non-covered entity otherwise shares the information with the covered-entity and the consumer has given consent in accordance with paragraph (9) to the covered entity or non-covered entity for the non-covered entity to share the consumer’s personal information with the specific covered entity;</text></clause></subparagraph></paragraph> <paragraph id="iddb7969c5abb64c14b07559d54616a1d1"><enum>(9)</enum><text>establish standards and procedures for a person, partnership, or corporation to request and obtain consent from a consumer, in accordance with paragraph (8)(B) that clearly identifies the covered entity that will be storing or using the personal information and provides the consumer, at the time the person, partnership, or corporation is seeking consent, in accordance with paragraph (10), and in a form that is understandable to a reasonable consumer—</text>
<subparagraph id="id648aad5187374f7abb1cef8180009d88"><enum>(A)</enum><text>the name and contact information of the person, partnership, or corporation from whom the personal information of that consumer is to be obtained;</text></subparagraph> <subparagraph id="idd803aef4c7954857b916fa12477d812d"><enum>(B)</enum><text>a description of the personal information of that consumer that will be shared; and</text></subparagraph>
<subparagraph id="idcb6939a14db44594aa50e8965b200a1a"><enum>(C)</enum><text>a description of the purposes for which the personal information of that consumer will be shared;</text></subparagraph></paragraph> <paragraph id="id5cb4bfc5af044c19b7b50a8d40ebabf1"><enum>(10)</enum><text>detail the standardized form and manner in which certain information related to sharing shall be disclosed to consumers, which shall, to the extent that the Commission determines to be practicable and appropriate, be in the form of a table that—</text>
<subparagraph id="ide0f525160ab24596aeafdceaf2228ede"><enum>(A)</enum><text>contains clear and concise headings for each item of such information; and</text></subparagraph> <subparagraph id="idee460e675cd54e3f9973f366e9ddb20c"><enum>(B)</enum><text>provides a clear and concise form for stating each item of information required to be disclosed under each such heading; and</text></subparagraph></paragraph>
<paragraph id="id0be6a5d98aca4f8e848207b1871f2001"><enum>(11)</enum><text>permit a consumer to withdraw his or her consent to a covered entity to not be bound by the consumer’s opt-out at any time, including through an Application Programming Interface.</text></paragraph></subsection> <subsection id="id896c6b24d9f64a9baf5cd02e8c668fdc"><enum>(b)</enum><header>Acts prohibited</header> <paragraph id="id649BAA203B5044859E4137496E9FA3F8"><enum>(1)</enum><header>In general</header><text>It shall be unlawful for any covered entity to condition its products or services upon a requirement that consumers—</text>
<subparagraph id="id21FDC09055434A4AAD8FF9E31EBE375B"><enum>(A)</enum><text>change their opt-out status through the opt-out website maintained by the Commission pursuant to subsection (a)(2); or</text></subparagraph> <subparagraph id="idEFB3EF4813A043A9944F58FB2DE17A94"><enum>(B)</enum><text>give the covered entity consent to not be bound by the consumer’s opt-out status, unless the consumer is also given an option to pay a fee to use a substantially similar service that is not conditioned upon a requirement that the consumer give the covered entity consent to not be bound by the consumer’s opt-out status.</text></subparagraph></paragraph>
<paragraph id="idDEB22FF594044E69B72B6C6DB162FB9D"><enum>(2)</enum><header>Fee</header>
<subparagraph id="id476A140FBDBE427DA4FD1DDAA0FA6B55"><enum>(A)</enum><header>Disclosure</header><text>Each covered entity shall disclose to a consumer the amount of the fee described in paragraph (1)(B), including the amount that the covered entity—</text> <clause id="id9D9CBBAA5D5B45598DD50E3BF4E8FF70"><enum>(i)</enum><text>would have charged the consumer if the consumer had not opted out; and</text></clause>
<clause id="id99CAD7E9897346F2A5A4726821875B16"><enum>(ii)</enum><text>the amount that the covered entity is charging to recoup the cost of providing service to low-income consumers.</text></clause></subparagraph> <subparagraph id="idB1E6CB1178154A6DBF84D564EB47BCCF"><enum>(B)</enum><header>Amount</header><text>Except as provided in subparagraph (C), the fee described in paragraph (1)(B) shall not be greater than the amount of monetary gain the covered entity would have earned had the average consumer not opted-out.</text></subparagraph>
<subparagraph id="id6773F68D8CAC4BB8A5A6EE6FB4C6BDD4"><enum>(C)</enum><header>Exception</header><text>No covered entity may charge a fee to any consumer that meets the requirements described in subsection (a) or (b) of section 54.409 of title 47, Code of Federal Regulations (or successor regulation).</text></subparagraph> <subparagraph id="idA652E3D2238745769B3574F8743B739F"><enum>(D)</enum><header>Rulemaking</header><text>The Commission may promulgate regulations to facilitate and ensure that covered entities are complying with subparagraph (C).</text></subparagraph></paragraph></subsection>
<subsection id="id6a8d8f83cc594efa958943d3ed8a2b69"><enum>(c)</enum><header>Enforcement by the Commission</header><text>A violation of subsection (b) shall be treated as a violation of a rule defining an unfair or deceptive act or practice under section 18(a)(1)(B) of the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/57a">15 U.S.C. 57a(a)(1)(B)</external-xref>).</text></subsection></section> <section id="id2548e6e923e04d5d8c7b35ee88dafb59"><enum>7.</enum><header>Data protection authority</header> <subsection id="idb3a725bcc041440e81b5ce8cd4b5cdf3"><enum>(a)</enum><header>Acts prohibited</header><text>It is unlawful for any covered entity to—</text>
<paragraph id="id2a51cf85523b47aab3971d98465302eb"><enum>(1)</enum><text>violate a regulation promulgated under subsection (b); or</text></paragraph> <paragraph id="idace425c8f8a14753b3e719138a4c2aab"><enum>(2)</enum><text>knowingly provide substantial assistance to any person, partnership, or corporation whose actions violate this Act.</text></paragraph></subsection>
<subsection id="ideab70f17356347daafec0710bc602831"><enum>(b)</enum><header>Regulations</header>
<paragraph id="idccd5c11225db402aadeb6a6494d1261e"><enum>(1)</enum><header>In general</header><text>Not later than 2 years after the date of enactment of this section, the Commission shall promulgate regulations, in accordance with section 553 of title 5, United States Code, that—</text> <subparagraph id="id213d925210524ad6858f98c15b67dd20"><enum>(A)</enum><text>require each covered entity to establish and implement reasonable cyber security and privacy policies, practices, and procedures to protect personal information used, stored, or shared by the covered entity from improper access, disclosure, exposure, or use;</text></subparagraph>
<subparagraph id="id031a395413594321995c6da9649cb427"><enum>(B)</enum><text>require each covered entity to implement reasonable physical, technical, and organizational measures to ensure that technologies or products used, produced, sold, offered, or leased by the covered entity that the covered entity knows or has reason to believe store, process, or otherwise interact with personal information are built and function consistently with reasonable data protection practices;</text></subparagraph> <subparagraph id="ide4cb48bd56f848ac9c6652192baa1f8e"><enum>(C)</enum><text>require each covered entity to designate at least 1 employee who reports directly to an employee acting in an executive capacity in the covered entity, to coordinate its efforts to comply with and carry out its responsibilities under this Act, including any request or challenge related to the sharing of personal information;</text></subparagraph>
<subparagraph id="id3bcab77420534c4bb665c29fb68c2778"><enum>(D)</enum><text>require each covered entity to provide once per calendar year, at no cost, not later than 30 business days after receiving a written request from a verified consumer about whom the covered entity stores personal information—</text> <clause id="id6bf87408e84f4be6a06df4fa55d432f0"><enum>(i)</enum><text>a reasonable means to review any stored personal information of that verified consumer, including the manner in which the information was collected and the date of collection, in a form that is understandable to a reasonable consumer;</text></clause>
<clause id="ide89b8c9c09f24880b2e8af723e497d34"><enum>(ii)</enum><text>a reasonable means to challenge the accuracy of any stored personal information of that verified consumer, including—</text> <subclause id="idDB96F8D6BF3542E5B83EEDACDCB8AAFF"><enum>(I)</enum><text>by providing publicly accessible contact information for any employee responsible for overseeing such a challenge; and</text></subclause>
<subclause id="id7D9B0C536FBA44058BB2713DCD42122B"><enum>(II)</enum><text>implementing a reasonable process for responding to such challenges, including the ability of the covered entity to terminate an investigation of information disputed by a consumer under this clause, and providing notice to the consumer of such termination, if the covered entity reasonably determines that the dispute by the consumer is frivolous or irrelevant, including by reason of a failure by a consumer to provide sufficient information to investigate the disputed information;</text></subclause></clause> <clause id="id857d0b90c1af47a08355fddccdfe9ead"><enum>(iii)</enum><text>a list of each person, partnership, or corporation with whom the personal information of that verified consumer was shared by the covered entity that—</text>
<subclause id="id4003602baabf485cb5e3ad7cc3ae28d4"><enum>(I)</enum><text>does not include—</text> <item id="iddbadba0a717a4c25be59b0df9dca0e4f"><enum>(aa)</enum><text>disclosures to governmental entities pursuant to a court order or law that prohibits the covered entity from revealing that disclosure to the consumer;</text></item>
<item id="ide3bba4e9a14045da9bbfbe2ada02f3a8"><enum>(bb)</enum><text>disclosures of personal information to third parties when the personal information of the consumer was made available to and readily accessible by the general public with the consent of the verified consumer and shared with the third party through a mechanism available to any member of the general public; or</text></item> <item id="id5CBDD7A3DCCB4D95BE4A8D80BF3FBB08"><enum>(cc)</enum><text>disclosures of information about the verified consumer that the covered entity did not obtain from that consumer, if revealing that disclosure of information would expose another consumer to likely harm; and</text></item></subclause>
<subclause id="id24ED80F81D2B406BAC81DDE727BC96CE"><enum>(II)</enum><text>except as provided in subparagraph (I), includes, at a minimum—</text> <item id="idacc56bf9b1454a42abe9abb64da8fe6e"><enum>(aa)</enum><text>the name and contact information of each person, partnership, or corporation with whom the personal information of that verified consumer was shared;</text></item>
<item id="idb623aba18fff4002b91df96825526b90"><enum>(bb)</enum><text>a description of the personal information of that verified consumer that was shared, in a form that is understandable to a reasonable consumer;</text></item> <item id="id06e181cfd5ef4abd885fb8dc39fb2abe"><enum>(cc)</enum><text>a statement of the purposes for which the personal information of that verified consumer was shared;</text></item>
<item id="id1b035f1aa276441b94a5c03305ab38d8"><enum>(dd)</enum><text>if the covered entity claims consent from the consumer as the basis for sharing, a statement of the circumstances surrounding that consumer consent, specifically when, where, and how the consent was obtained and by whom the consent was obtained; and</text></item> <item id="idcf8c15ef7af54bee824a2f6a861497a7"><enum>(ee)</enum><text>a statement of when the personal information of that verified consumer was shared; and</text></item></subclause></clause>
<clause id="ida04cfc0ada01461686ffc3fb74224436"><enum>(iv)</enum><text>for any personal information about that verified consumer stored by the covered entity that the covered entity did not obtain directly from that verified consumer, a list identifying—</text> <subclause id="id5692577fffef44c5a1e1532d093d3952"><enum>(I)</enum><text>the name and contact information of each person, partnership, or corporation from whom the personal information of that verified consumer was obtained;</text></subclause>
<subclause id="id8dce5020a64c4ab8819f721f0aac45cb"><enum>(II)</enum><text>a description of the personal information, in a form that is understandable to a reasonable consumer;</text></subclause> <subclause id="id90daa5c8a4554f3d8689604d6bcaa44e"><enum>(III)</enum><text>a statement of the purposes for which the personal information of that verified consumer was obtained by the covered entity; and</text></subclause>
<subclause id="idd7cf2f128ef5442792589262756757dd"><enum>(IV)</enum><text>a statement of the purposes for which the personal information of that verified consumer was shared with the covered entity;</text></subclause></clause></subparagraph> <subparagraph id="idba0494aa9ef14df5ac7a9ffa36dad4c4"><enum>(E)</enum><text>detail the standardized form and manner in which the information in subparagraph (D) shall be disclosed to consumers which shall, to the extent the Commission determines to be practicable and appropriate, be in the form of a table that—</text>
<clause id="id25564a00f9a5482cb3fffafc0d70827f"><enum>(i)</enum><text>contains clear and concise headings for each item of information; and</text></clause> <clause id="idd65b1281ffed40c888df4c135d79f5e5"><enum>(ii)</enum><text>provides a clear and concise form for stating each item of information required to be disclosed under each such heading;</text></clause></subparagraph>
<subparagraph id="id4811adc679c04f06bf09f90ab175fb0e"><enum>(F)</enum><text>require each covered entity to correct the stored personal information of the verified consumer if, after investigating a challenge by a verified consumer under subparagraph (D), the covered entity determines that the personal information is inaccurate;</text></subparagraph> <subparagraph id="id1356d4821fa84b6e8140cd450fc061a4"><enum>(G)</enum><text>require each covered entity to conduct automated decision system impact assessments of—</text>
<clause id="id24c81bcb3c0e4e7098d7e8aeda42a162"><enum>(i)</enum><text>existing high-risk automated decision systems, as frequently as the Commission determines is necessary; and</text></clause> <clause id="id1e607c20308440f6b78f16a84fe7c60d"><enum>(ii)</enum><text>new high-risk automated decision systems, prior to implementation;</text></clause><continuation-text continuation-text-level="subparagraph">provided that a covered entity may evaluate similar high-risk automated decision systems that present similar risks in a single assessment;</continuation-text></subparagraph>
<subparagraph id="idebccbf52bc85437f826fd98f49dc9b7d"><enum>(H)</enum><text>require each covered entity to conduct data protection impact assessments of—</text> <clause id="id674e981c45a644be8e2009438da79bf6"><enum>(i)</enum><text>existing high-risk information systems, as frequently as the Commission determines is necessary; and</text></clause>
<clause id="id6ce73817f39947919f7fea83a573f54a"><enum>(ii)</enum><text>new high-risk information systems, prior to implementation;</text></clause><continuation-text continuation-text-level="subparagraph">provided that a covered entity may evaluate similar high-risk information systems that present similar risks in a single assessment;</continuation-text></subparagraph> <subparagraph id="id626328d6a3d24a3585279bd7ab999962"><enum>(I)</enum><text>require each covered entity to conduct the impact assessments under subparagraphs (G) and (H), if reasonably possible, in consultation with external third parties, including independent auditors and independent technology experts; and</text></subparagraph>
<subparagraph id="id7a5ce339bf0e42a0bc44a01506903471"><enum>(J)</enum><text>require each covered entity to reasonably address in a timely manner the results of the impact assessments under subparagraphs (G) and (H).</text></subparagraph></paragraph> <paragraph id="id18a77c66abc04d60a56e9cfdedeb4c29"><enum>(2)</enum><header>Consultation</header><text>The Commission shall promulgate regulations under subparagraphs (A) and (B) of paragraph (1) in consultation with the National Institute of Standards and Technology.</text></paragraph>
<paragraph id="id8287b41c462c46aaabd9ead4ab0b19fb"><enum>(3)</enum><header>Optional publication of impact assessments</header><text>The impact assessments under subparagraphs (G) and (H) may be made public by the covered entity at its sole discretion.</text></paragraph> <paragraph id="id1802BCFC688240C6A323178417A0FF17"><enum>(4)</enum><header>Applicability</header><text>The regulations promulgated under subparagraphs (D) and (F) of paragraph (1) shall only apply to information stored by a covered entity for the covered entity and not on behalf of another entity.</text></paragraph>
<paragraph id="id33C71A9EE93644869E48169C16E31191"><enum>(5)</enum><header>Reasonable fee</header><text>A covered entity may charge a consumer a reasonable fee to cover the cost of any additional request described in paragraph (1)(D).</text></paragraph></subsection> <subsection id="id7c67e4bfb6b244cfb1743d28d71ccc1f"><enum>(c)</enum><header>Preemption of private contracts</header><text>It shall be unlawful for any covered entity to commit the acts prohibited in subsection (a), regardless of specific agreements between entities or consumers.</text></subsection>
<subsection id="idd4fe529d8bba49e3968209d9bbf1e5bb"><enum>(d)</enum><header>Enforcement by the commission</header>
<paragraph id="id208382cffc7d472fbfbeb02324b1d220"><enum>(1)</enum><header>Unfair or deceptive acts or practices</header><text>A violation of subsection (a) shall be treated as a violation of a rule defining an unfair or deceptive act or practice under section 18(a)(1)(B) of the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/57a">15 U.S.C. 57a(a)(1)(B)</external-xref>).</text></paragraph> <paragraph id="id3d2e2999729949e296defe1c564b2595"><enum>(2)</enum><header>Powers of the commission</header> <subparagraph id="id67c077896a2c470eb846b42e35f6ec31"><enum>(A)</enum><header>In general</header><text>The Commission shall enforce this section in the same manner, by the same means, and with the same jurisdiction, powers, and duties as though all applicable terms and provisions of the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/41">15 U.S.C. 41</external-xref> et seq.) were incorporated into and made a part of this section.</text></subparagraph>
<subparagraph id="idf041ee41de0343d6a9178f02658c3646"><enum>(B)</enum><header>Privileges and immunities</header><text>Any person who violates subsection (a) shall be subject to the penalties and entitled to the privileges and immunities provided in the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/41">15 U.S.C. 41</external-xref> et seq.).</text></subparagraph> <subparagraph commented="no" display-inline="no-display-inline" id="id2BF0177B31124E92B32E36C7DFFE7B7D"><enum>(C)</enum><header>Authority preserved</header><text>Nothing in this section shall be construed to limit the authority of the Commission under any other provision of law.</text></subparagraph></paragraph></subsection>
<subsection id="id05fdcb88d98f45299cc7301be0f067dd"><enum>(e)</enum><header>Enforcement by States</header>
<paragraph id="idd40de46b8ebd4575aedd68f9be6f17ac"><enum>(1)</enum><header>In general</header><text>If the attorney general of a State has reason to believe that an interest of the residents of the State has been or is being threatened or adversely affected by a practice that violates subsection (a), the attorney general of the State may, as parens patriae, bring a civil action on behalf of the residents of the State in an appropriate district court of the United States to obtain appropriate relief.</text></paragraph> <paragraph commented="no" id="idf98da423d14a49d99131b0ef79945486"><enum>(2)</enum><header>Rights of Commission</header> <subparagraph commented="no" id="idd3d5e1a39cd14438baa87eae7b8e7a3c"><enum>(A)</enum><header>Notice to Commission</header> <clause commented="no" id="idb192d3849c2b4a9cb1486a257819c886"><enum>(i)</enum><header>In general</header><text>Except as provided in clause (iii), the attorney general of a State, before initiating a civil action under paragraph (1), shall provide written notification to the Commission that the attorney general intends to bring such civil action.</text></clause>
<clause commented="no" id="id1465d7c37e794d9eb7d8894a20ba5770"><enum>(ii)</enum><header>Contents</header><text>The notification required under clause (i) shall include a copy of the complaint to be filed to initiate the civil action.</text></clause> <clause commented="no" id="idad954eb464384154a5352f5a560de027"><enum>(iii)</enum><header>Exception</header><text>If it is not feasible for the attorney general of a State to provide the notification required under clause (i) before initiating a civil action under paragraph (1), the attorney general shall notify the Commission immediately upon instituting the civil action.</text></clause></subparagraph>
<subparagraph commented="no" id="id9d6e8fa7ad0f434c8004a4f453f444ec"><enum>(B)</enum><header>Intervention by Commission</header><text>The Commission may—</text> <clause commented="no" id="id814fa2fe75f749249f4c27c4110828de"><enum>(i)</enum><text>intervene in any civil action brought by the attorney general of a State under paragraph (1); and</text></clause>
<clause commented="no" id="idb0b7ce144a99453c99a867ac53b3d15c"><enum>(ii)</enum><text>upon intervening—</text> <subclause commented="no" id="id5614c1c923ab42ae81072b1a772783f1"><enum>(I)</enum><text>be heard on all matters arising in the civil action; and</text></subclause>
<subclause commented="no" id="id2fb1ff85f4644cf38525aff571277480"><enum>(II)</enum><text>file petitions for appeal of a decision in the civil action.</text></subclause></clause></subparagraph></paragraph> <paragraph commented="no" id="id609a1e0e280b42b6a290f7ff7849e11a"><enum>(3)</enum><header>Investigatory powers</header><text>Nothing in this subsection may be construed to prevent the attorney general of a State from exercising the powers conferred on the attorney general by the laws of the State to conduct investigations, to administer oaths or affirmations, or to compel the attendance of witnesses or the production of documentary or other evidence.</text></paragraph>
<paragraph commented="no" id="idc9f7a316345a4da18910f6b8dfce6f4e"><enum>(4)</enum><header>Venue; service of process</header>
<subparagraph commented="no" id="id650a1f5736c94d0cbf36f458a2e4a1cb"><enum>(A)</enum><header>Venue</header><text>Any action brought under paragraph (1) may be brought in—</text> <clause commented="no" id="ide12829ed3bb3491192e2147af2563fde"><enum>(i)</enum><text>the district court of the United States that meets applicable requirements relating to venue under section 1391 of title 28, United States Code; or</text></clause>
<clause commented="no" id="idd5d04100535647adadc1a870c1079024"><enum>(ii)</enum><text>another court of competent jurisdiction.</text></clause></subparagraph> <subparagraph commented="no" id="id87c64b24d6834563a9ce65611a7b5cfe"><enum>(B)</enum><header>Service of process</header><text>In an action brought under paragraph (1), process may be served in any district in which—</text>
<clause commented="no" id="idbc54a715e3cd4e04861fc307eac002d4"><enum>(i)</enum><text>the defendant is an inhabitant, may be found, or transacts business; or</text></clause> <clause commented="no" id="ide51d46d0deed491ab84b37070b47e8c7"><enum>(ii)</enum><text>venue is proper under section 1391 of title 28, United States Code.</text></clause></subparagraph></paragraph>
<paragraph commented="no" id="ida8acac8738b14d25bc85e825b53a5d70"><enum>(5)</enum><header>Actions by other State officials</header>
<subparagraph commented="no" id="id6e5ef5d548884ad993e800d125a8d53a"><enum>(A)</enum><header>In general</header><text>In addition to a civil action brought by an attorney general of a State under paragraph (1), any other officer of a State who is authorized by the attorney general of the State to do so may bring a civil action under paragraph (1), subject to the same requirements and limitations that apply under this subsection to civil actions brought by State attorneys general.</text></subparagraph> <subparagraph commented="no" id="idc75acbc25caf46ac8c45a368d6ff18d1"><enum>(B)</enum><header>Savings provision</header><text>Nothing in this subsection may be construed to prohibit an authorized official of a State from initiating or continuing any proceeding in a court of the State for a violation of any civil or criminal law of the State.</text></subparagraph></paragraph></subsection>
<subsection commented="no" id="id1200E94F7D1E4319B98DB849A3138AEC"><enum>(f)</enum><header>Right of action by protection and advocacy organizations</header>
<paragraph commented="no" id="idF2B7055CDCB943A487844C0B348AA27B"><enum>(1)</enum><header>In general</header><text>A protection and advocacy organization designated under paragraph (3) may bring a civil action against a covered entity that violates subsection (a) in an appropriate district court of the United States to obtain appropriate relief.</text></paragraph> <paragraph commented="no" id="idB1D8B9B64A3A4A78AFC9C4C86BB92269"><enum>(2)</enum><header>Grants</header> <subparagraph commented="no" id="id55E76E368D3846DDB3D2F701EAF78542"><enum>(A)</enum><header>In general</header><text>Of the fines collected by the Commission, the Commission may award grants to protection and advocacy organizations designated under paragraph (3).</text></subparagraph>
<subparagraph commented="no" id="id377A65FF93034AF898820D39B821EDF4"><enum>(B)</enum><header>Allocation</header><text>The Commission shall distribute amounts under this paragraph on the basis of the ratio of the population of each State represented by a designated protection and advocacy organization to the population of all States represented by designated protection and advocacy organizations.</text></subparagraph></paragraph> <paragraph commented="no" id="idBA5AE9A5421E461F9C21AFEDC97585AB"><enum>(3)</enum><header>Designation</header><text>Each State may designate 1 protection and advocacy organization to bring a civil action under paragraph (1).</text></paragraph></subsection></section>
<section id="id91fe2e8621a241ca9c16ac93371dd2d0"><enum>8.</enum><header>Bureau of Technology</header>
<subsection id="idfcd614ef55d5426e856a736f19b59635"><enum>(a)</enum><header>Establishment</header><text>There is established in the Commission a bureau to be known as the Bureau of Technology (referred to in this section as the <quote>Bureau</quote>).</text></subsection> <subsection id="id3cb267a972fb4c6b9b7ed3cd7ee428da"><enum>(b)</enum><header>Chief Technologist</header><text>The Bureau shall be headed by a chief technologist, who shall be appointed by the Chairman of the Commission.</text></subsection>
<subsection id="id27ec0fd59844455a939b9dcae71cf113"><enum>(c)</enum><header>Staff</header>
<paragraph id="id2488691d48d94bfe849ded256b15cd0b"><enum>(1)</enum><header>In general</header><text>Except as provided in paragraph (2), the Director of the Bureau may, without regard to the civil service laws (including regulations), appoint and terminate 50 additional personnel with expertise in management, technology, digital design, user experience, product management, software engineering, and other related fields to technologist and management positions to enable the Bureau to perform the duties of the Bureau.</text></paragraph> <paragraph id="id8cecb80f21c84c72bde5806ad9c6351e"><enum>(2)</enum><header>Excepted service</header><text>Not fewer than 40 of the additional personnel appointed under paragraph (1) shall be appointed to positions described in section 213.3102(r) of title 5, Code of Federal Regulations.</text></paragraph></subsection>
<subsection id="idd1e63ad1654045aabd78e0216e2ec19c"><enum>(d)</enum><header>Authorization of appropriations</header><text>There is authorized to be appropriated to the Bureau such sums as are necessary to carry out this section.</text></subsection></section> <section id="idc2fad987e0df4998a170cae23e473281"><enum>9.</enum><header>Additional personnel in the Bureau of Consumer Protection</header> <subsection id="id9b53b63049fc4e67a6665d15ddeece53"><enum>(a)</enum><header>In general</header><text>Notwithstanding any other provision of law, the Director of the Bureau of Consumer Protection of the Federal Trade Commission may, without regard to the civil service laws (including regulations), appoint—</text>
<paragraph id="idAFD22A50B4AF451FB1A0168174A7E4C3"><enum>(1)</enum><text>100 additional personnel in the Division of Privacy and Identity Protection of the Bureau of Consumer Protection; and</text></paragraph> <paragraph id="id8A5DD275A464470AB7AE435967CFB381"><enum>(2)</enum><text>25 additional personnel in the Division of Enforcement of the Bureau of Consumer Protection.</text></paragraph></subsection>
<subsection id="id5e73d09ec4884d2f8b79d79e8e93052f"><enum>(b)</enum><header>Authorization of appropriations</header><text>There is authorized to be appropriated to the Director of the Bureau of Consumer Protection such sums as may be necessary to carry out this section.</text></subsection></section> <section id="idaa0997b4f64540629692c1afd260470f"><enum>10.</enum><header>Complaint resolution</header><text display-inline="no-display-inline">The Commission shall create rules and guidance establishing procedures for the resolution of complaints by consumers regarding covered entities that improperly use, store, or share the personal information of consumers, including procedures to—</text>
<paragraph id="idd65ba1ce4496407597116dbde59b1912"><enum>(1)</enum><text>properly process and store complaints;</text></paragraph> <paragraph id="id255e0518937b42e6bb9a3f1920802543"><enum>(2)</enum><text>provide a consumer with email updates regarding the status of the consumer’s complaint;</text></paragraph>
<paragraph id="id7e97258f3c8744f3ba8753cb19f8381f"><enum>(3)</enum><text>create an online portal that allows a consumer to log in and track the status of the consumer’s complaint;</text></paragraph> <paragraph id="idd2af293881464b288290a7cb824ad98b"><enum>(4)</enum><text>review and forward complaints to the correct person, partnership, corporation, government agency, or other entity; and</text></paragraph>
<paragraph id="idb8b3adc5563f49fba9fecf9624e22229"><enum>(5)</enum><text>process and store each response from a person, partnership, corporation, government agency, or other entity to which a complaint was forwarded.</text></paragraph></section> <section id="id044e619f011d4ed1bbd915476423ce22"><enum>11.</enum><header>Application programming interfaces</header><text display-inline="no-display-inline">The Commission shall, in consultation with the National Institute of Standards and Technology and relevant stakeholders, including consumer advocates and independent technology experts—</text>
<paragraph id="ideb53f487fd6f41f094a44de51d71d7d2"><enum>(1)</enum><text>standardize Application Programming Interfaces necessary to permit consumers and covered entities to programmatically avail themselves of the rights and responsibilities created by this Act;</text></paragraph> <paragraph id="idd332496e84d34bedad2b04de57029278"><enum>(2)</enum><text>permit and enable consumers to securely delegate the ability to make requests on their behalf; and</text></paragraph>
<paragraph id="ideab62498a3bf449faf867982699d3c9c"><enum>(3)</enum><text>require covered entities to implement the Application Programming Interfaces, as appropriate.</text></paragraph></section> <section id="idc78260c1d1f041ae8c5e4216d4e65262"><enum>12.</enum><header>News media protections</header><text display-inline="no-display-inline">Covered entities engaged in journalism shall not be subject to the obligations imposed under this Act to the extent that those obligations directly infringe on the journalism, rather than the business practices, of the covered entity.</text></section>
<section id="id869BDB9596964476B327D1628AC41303"><enum>13.</enum><header>Excise tax</header>
<subsection id="idd4f5cced06fa4e44a61bf7adf0f152fd"><enum>(a)</enum><header>In general</header><text>Subtitle D of the Internal Revenue Code of 1986 is amended by adding at the end the following new chapter:</text> <quoted-block style="OLC" display-inline="no-display-inline" id="id492d022277c5421ba93dc21291ca1f61"> <chapter id="id6094fb4a6e3d4279b0ca00a236cd26de"><enum>50A</enum><header>Failure to certify data protection reports</header> <toc> <toc-entry idref="idb9b8e969e3614c84805ab06518c12834" level="section">Sec. 5000D. Failure to certify data protection reports. </toc-entry></toc> <section id="idb9b8e969e3614c84805ab06518c12834"><enum>5000D.</enum><header>Failure to certify data protection reports</header> <subsection id="id2d1ad3f04bfb446cb0fd7fb0710035dd"><enum>(a)</enum><header>Imposition of tax</header><text>In the case of any covered reporting entity with respect to which a responsible executive has been convicted under section 1352(d) of title 18, United States Code, there is imposed a tax equal to the amount determined under subsection (b).</text></subsection>
<subsection id="id7A629C8F75CF429FAFD1F141AA58A7E2"><enum>(b)</enum><header>Amount of tax</header>
<paragraph id="idC1E6BDEB5E75466F989EC044F1F0A0CF"><enum>(1)</enum><header>In general</header><text>The amount determined under this subsection is the applicable percentage of the amount determined under paragraph (3).</text></paragraph> <paragraph id="id3458410EE9314296A487E4018EC3FFBD"><enum>(2)</enum><header>Applicable percentage</header><text>For purposes of paragraph (1), the applicable percentage is—</text>
<subparagraph id="id3AAD1258E75F4D5AAFD842BF4E023D59"><enum>(A)</enum><text>in the case of a covered reporting entity that is a corporation, the highest rate of tax in effect under section 11 for the taxable year which includes the date on which the specified annual data protection report to which the conviction relates is due, and</text></subparagraph> <subparagraph id="id02091C58492943EE8371AC1225178E03"><enum>(B)</enum><text>in the case of any other covered reporting entity, the highest rate of tax in effect under section 1 for such taxable year.</text></subparagraph></paragraph>
<paragraph id="id2688D2EE6C534CB08B138DEEEC8DA601"><enum>(3)</enum><header>Amount determined</header>
<subparagraph id="idFA3A4E2AB00F43EB8ADB9A3BBE22F14E"><enum>(A)</enum><header>In general</header><text>The amount determined under this paragraph is the sum of the covered compensation amounts of each responsible executive of the covered reporting entity who has been convicted under section 1352(d) of title 18, United States Code.</text></subparagraph> <subparagraph id="id814D9519A69C4CDFB930576310A7B192"><enum>(B)</enum><header>Covered compensation amount</header><text>For purposes of subparagraph (A), the covered compensation amount with respect to any responsible executive is the largest amount of annual wages (as defined in section 3121(a), determined without regard to any dollar limitation contained in such section) of the responsible executive with respect to services performed for the covered reporting entity during the 3-year period preceding the year to which the specified annual data protection report relates.</text></subparagraph></paragraph></subsection>
<subsection id="id2FB2E1503B6D4204852240E663966D54"><enum>(c)</enum><header>Definitions</header><text>For purposes of this section—</text> <paragraph id="idE3A000E1DC3D49C3A5D470C521E953A4"><enum>(1)</enum><header>Covered reporting entity</header> <subparagraph id="idA1DD3207815D4758BC74B5EB94A0AD05"><enum>(A)</enum><header>In general</header><text>The term <term>covered reporting entity</term> means any covered entity (as defined under section 2 of the <short-title>Mind Your Own Business Act of 2021</short-title>) which is required to file a specified annual data protection report.</text></subparagraph>
<subparagraph id="idbea03df0a6ef476eb29d50c4bcc11920"><enum>(B)</enum><header>Aggregation rules</header><text>For purposes of this paragraph, all covered entities who are treated as a single employer under subsection (b), (c), (m), or (o) of section 414 shall be treated as one person.</text></subparagraph></paragraph> <paragraph id="id5EB28C58FB0C4D79AE8341EF92B29F9A"><enum>(2)</enum><header>Responsible executive</header><text>For purposes of this subsection, the term <term>responsible executive</term> means, with respect to a covered reporting entity, any of the following officers:</text>
<subparagraph id="id59770CAC2B2B4284AB26389DF0E8DB0A"><enum>(A)</enum><text>The chief executive officer.</text></subparagraph> <subparagraph id="id8EC983B825B2437191A9F78ED29552B2"><enum>(B)</enum><text>The chief privacy officer (or equivalent thereof).</text></subparagraph></paragraph>
<paragraph id="id1E1A870371424C29905E60E18CBCA1DB"><enum>(3)</enum><header>Specified annual data protection report</header><text>The term <term>specified annual data protection report</term> means the report required to be filed under section 5(a) of the <short-title>Mind Your Own Business Act of 2021</short-title>.</text></paragraph></subsection></section></chapter><after-quoted-block>.</after-quoted-block></quoted-block></subsection> <subsection id="id62f327dee19c49d98637d3741ed8495d"><enum>(b)</enum><header>Clerical amendment</header><text>The table of chapters for subtitle D of the Internal Revenue Code of 1986 is amended by adding at the end the following new item:</text>
<quoted-block style="OLC" id="id246bb962-ed38-4920-b123-e3c1daee0219">
<toc>
<toc-entry idref="id6094fb4a6e3d4279b0ca00a236cd26de" level="chapter">Chapter 50A—Failure to certify data protection reports</toc-entry></toc><after-quoted-block>.</after-quoted-block></quoted-block></subsection></section>
<section id="idC333AC68B3F3411E91D341508D79DFDC"><enum>14.</enum><header>No preemption</header><text display-inline="no-display-inline">Nothing in this Act may be construed to preempt any State law.</text></section> </legis-body> </bill> 

