<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-MUR21222-61C-W3-0PY"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>117 S1667 IS: Social Media Privacy Protection and Consumer Rights Act of 2021</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2021-05-18</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>117th CONGRESS</congress><session>1st Session</session><legis-num>S. 1667</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20210518">May 18, 2021</action-date><action-desc><sponsor name-id="S311">Ms. Klobuchar</sponsor> (for herself, <cosponsor name-id="S389">Mr. Kennedy</cosponsor>, <cosponsor name-id="S338">Mr. Manchin</cosponsor>, and <cosponsor name-id="S300">Mr. Burr</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSCM00">Committee on Commerce, Science, and Transportation</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To protect the privacy of users of social media and other online platforms.</official-title></form><legis-body display-enacting-clause="yes-display-enacting-clause" id="HB66453ACAE8B497686FE4F3DE459E52D"><section section-type="section-one" id="S1"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Social Media Privacy Protection and Consumer Rights Act of 2021</short-title></quote>.</text></section><section id="idFB3D2D655F764D029E3A5AD2F2EEDC14"><enum>2.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act:</text><paragraph id="id49DEA7D3C3C04149B40D495E1CFE38CD"><enum>(1)</enum><header>Commission</header><text>The term <term>Commission</term> means the Federal Trade Commission.</text></paragraph><paragraph id="id156C4E0A897B46E89B71C3FA11C94404"><enum>(2)</enum><header>Covered online platform</header><text>The term <term>covered online platform</term> means an online platform that collects personal data during the online behavior of a user of the online platform.</text></paragraph><paragraph id="iddb650972639747aea6cd0ac79dae707b"><enum>(3)</enum><header>Geolocation information</header><text>The term <term>geolocation information</term> means, with respect to an individual, any information that is not the content of a communication, concerning the location of a wireless communication device that—</text><subparagraph id="idFE87F7B3E4C140E5B96CD91729F386CA"><enum>(A)</enum><text>in whole or in part, is generated by or derived from the operation of that device; and</text></subparagraph><subparagraph id="idAE9BBD55366E41DA850D9B6F7BEB3A51"><enum>(B)</enum><text>could be used to determine or infer information regarding the location of the individual.</text></subparagraph></paragraph><paragraph id="idEA196B7C922246CEB795D14A47303A30"><enum>(4)</enum><header>Online platform</header><text>The term <term>online platform</term>—</text><subparagraph id="idCCC825F9F669483BA6B1B2922F34224E"><enum>(A)</enum><text>means any public-facing website, web application, or digital application (including a mobile application); and</text></subparagraph><subparagraph id="id312FF3932EFE46C0AE2B07D47E8745D6"><enum>(B)</enum><text>includes a social network, an ad network, a mobile operating system, a search engine, an email service, or an internet access service.</text></subparagraph></paragraph><paragraph id="id0B3252B369B6483092791D662043783F"><enum>(5)</enum><header>Operator</header><text>The term <term>operator</term> has the meaning given the term in section 1302 of the Children's Online Privacy Protection Act of 1998 (<external-xref legal-doc="usc" parsable-cite="usc/15/6501">15 U.S.C. 6501</external-xref>).</text></paragraph><paragraph id="id6BBFAE84CF8F4BE794D38AA65A5ADF0B"><enum>(6)</enum><header>Personal data</header><text>The term <term>personal data</term> means individually identifiable information about an individual collected online, including—</text><subparagraph id="id37dd70481140454bae5155dce002f11b"><enum>(A)</enum><text>location information sufficient to identify the name of a street and a city or town, including a physical address;</text></subparagraph><subparagraph id="idda23a730a92245dabb0ce801de253dff"><enum>(B)</enum><text>an email address;</text></subparagraph><subparagraph id="idc6601b887ce94e19b8dfb862ee4fb4a8"><enum>(C)</enum><text>a telephone number;</text></subparagraph><subparagraph id="id02b8adf3829c4b55a85efeb8f1a71645"><enum>(D)</enum><text>a government identifier, such as a Social Security number;</text></subparagraph><subparagraph id="idCEDE425ACB1E47FC9882EEB816B15104"><enum>(E)</enum><text>geolocation information;</text></subparagraph><subparagraph id="id661D53ED287D43EF865C937538E58BE2"><enum>(F)</enum><text>the content of a message;</text></subparagraph><subparagraph id="idEF73FF03A52D4B708955472F2F60C2F6"><enum>(G)</enum><text>protected health information, as defined in section 160.103 of title 45, Code of Federal Regulations, or any successor regulation; and</text></subparagraph><subparagraph id="id4E8443DA1B1248C5BA3BC4108860D86C"><enum>(H)</enum><text>nonpublic personal information, as defined in section 509 of the Gramm-Leach-Bliley Act (<external-xref legal-doc="usc" parsable-cite="usc/15/6809">15 U.S.C. 6809</external-xref>).</text></subparagraph></paragraph></section><section id="idF8D2ECAFF2504834A2E5B1881B5608EA"><enum>3.</enum><header>Privacy protections</header><subsection id="id7053AD79375C4286B40C27E01BAC6F68"><enum>(a)</enum><header>Transparency and terms of service</header><paragraph id="id041D9227C8064F1C8D221F535F704435"><enum>(1)</enum><header>Disclosure and obtaining initial consent and privacy preferences</header><subparagraph id="idCF2CE204F51F44D3A1F738DB17A928F6"><enum>(A)</enum><header>In general</header><text>Before a user creates an account with, or otherwise begins to use, a covered online platform, the operator of the online platform shall—</text><clause id="id92A2F3EEAB8D42F5822D4C5A0C8FE1D3"><enum>(i)</enum><text>inform the user that, unless the user makes an election under clause (ii)(II), personal data of the user produced during the online behavior of the user, whether on the online platform or otherwise, will be collected and used by the operator and third parties; and</text></clause><clause id="idF0682E27EA314CD3A2378B990DAF4640"><enum>(ii)</enum><text>provide the user the option to specify the privacy preferences of the user, including by—</text><subclause id="id8884549E3F9549A89046EF712D452455"><enum>(I)</enum><text>agreeing to the terms of service for use of the online platform, including, except as provided in subclause (II), the collection and use of personal data described in clause (i); and</text></subclause><subclause id="id6D77DF8D7F644C6F903A23C0FFA76284"><enum>(II)</enum><text>prohibiting, if the user so elects, the collection and use of personal data described in clause (i), subject to subparagraph (B).</text></subclause></clause></subparagraph><subparagraph id="id7A11D4F8583E4337A71D4F813A412EB5"><enum>(B)</enum><header>Consequence of prohibition of data collection</header><text>If the election of a user under subparagraph (A)(ii)(II) creates inoperability in the online platform, the operator of the online platform may deny certain services or completely deny access to the user.</text></subparagraph><subparagraph id="idBFD7D2CB75974BA2AC33D92452A454DC"><enum>(C)</enum><header>Form of disclosure</header><text>An operator of a covered online platform shall provide a user of the online platform with the terms of service for use of the online platform, including the collection and use of personal data described in subparagraph (A)(i), in a form that—</text><clause id="id0881434C6B954C60BB52FBE60FA94D08"><enum>(i)</enum><text>is—</text><subclause id="idFF0BA57CD97D4A2F81D60572DAADA557"><enum>(I)</enum><text>easily accessible;</text></subclause><subclause id="id4DA6543334AB4846843116BB5067625F"><enum>(II)</enum><text>of reasonable length; and</text></subclause><subclause id="id7F33F25185A74B7C8B1F5C5E97F92E34"><enum>(III)</enum><text>clearly distinguishable from other matters; and</text></subclause></clause><clause id="id97232B22F85B43C089066B7C8EDE340C"><enum>(ii)</enum><text>uses language that is clear, concise, and well organized, and follows other best practices appropriate to the subject and intended audience.</text></clause></subparagraph><subparagraph id="idE4DA92C9F0F24BCDBF28753A736584E8"><enum>(D)</enum><header>Privacy or security program</header><text>An operator of a covered online platform shall—</text><clause id="id56D0E29332E04A82B01524B3F1622B90"><enum>(i)</enum><text>establish and maintain a privacy or security program for the online platform; and</text></clause><clause id="id48C87C6C2393492D96C85019CE07570E"><enum>(ii)</enum><text>publish a description of the privacy or security program that—</text><subclause id="id81068443F02242739FF010CC3609052F"><enum>(I)</enum><text>details how the operator will use the personal data of a user of the online platform, including requirements for how the operator will address privacy risks associated with the development of new products and services; and</text></subclause><subclause id="id63e2016e128b43a682d902a60e1fd0c3"><enum>(II)</enum><text>includes details of the access that employees and contractors of the operator have to the personal data of a user of the online platform, and internal policies for the use of that personal data.</text></subclause></clause></subparagraph></paragraph><paragraph id="idCC053FD2ECAD4CBBAAC6A0F47BF94963"><enum>(2)</enum><header>New products; changes to privacy or security program</header><text>An operator of a covered online platform may not introduce a new product, or implement any material change to the privacy or security program of the online platform that overrides the privacy preferences of a user of the online platform, as specified under paragraph (1)(A)(ii), unless the operator has—</text><subparagraph id="id5551BBDCC50B46CBBF2F18094172F1DE"><enum>(A)</enum><text>informed the user that the new product or change will result in the collection and use of personal data described in paragraph (1)(A)(i), if that is the case;</text></subparagraph><subparagraph id="id42C4538907094780BE73D15A4B68C389"><enum>(B)</enum><text>provided the user the option under paragraph (1)(A)(ii); and</text></subparagraph><subparagraph id="id88528D5332FC485D89A96C26256B4C6D"><enum>(C)</enum><text>obtained affirmative express consent from the user to the introduction of the new product or the implementation of the change.</text></subparagraph></paragraph><paragraph id="id629E71D80CE04403A9D05220258830C9"><enum>(3)</enum><header>Withdrawal of consent</header><text>An operator of a covered online platform shall ensure that—</text><subparagraph id="id2984CF010C7B4F2DB7044101DE38FC7C"><enum>(A)</enum><text>a user of the online platform is able to withdraw consent to the terms of service for use of the online platform, including the collection and use of personal data described in paragraph (1)(A)(i), as easily as the user is able to give such consent; and</text></subparagraph><subparagraph id="id0AFC28489D6C46E08D4C204973D4A619"><enum>(B)</enum><text>except as otherwise required by law, no person is able to access the personal data of a user of the online platform later than 30 days after the date on which the user closes his or her account or otherwise terminates his or her use of the online platform.</text></subparagraph></paragraph></subsection><subsection id="idC85D2EF13C694343A11FC20209980039"><enum>(b)</enum><header>Right to access</header><text>An operator of a covered online platform shall offer a user of the online platform a copy of the personal data of the user that the operator has processed, free of charge and in an electronic and easily accessible format, including a list of each person that received the personal data from the operator for business purposes, whether through sale or other means.</text></subsection><subsection id="idAAED6B62180A4F51BB60D0A61881A1F0"><enum>(c)</enum><header>Violations of privacy</header><paragraph id="id5A2691F95D064119AE6279EA8E0E9548"><enum>(1)</enum><header>In general</header><text>Not later than 72 hours after an operator of a covered online platform becomes aware that the personal data of a user of the online platform has been transmitted in violation of the privacy or security program of the online platform, including the privacy preferences specified by the user under subsection (a)(1)(A)(ii), the operator shall—</text><subparagraph id="idF7FD7D92EBE44077B970356449B9C45A"><enum>(A)</enum><text>notify the user of the transmission;</text></subparagraph><subparagraph id="id8b1132e1e6ff40f1928f3c5670fd3d31"><enum>(B)</enum><text>offer the user the option to elect to prohibit the operator from collecting and using the personal data of the user, subject to paragraph (2);</text></subparagraph><subparagraph id="idab3557f630f74874b3073c17512d66eb"><enum>(C)</enum><text>except as provided in paragraph (3), offer the user the option to have the operator—</text><clause id="idB735C885484D40618A7AD87C4F828077"><enum>(i)</enum><text>erase all personal data of the user tracked by the operator; and</text></clause><clause id="idD9574D8F461D4AE2BF404F102CE1BD7B"><enum>(ii)</enum><text>cease further dissemination of personal data of the user tracked by the operator;</text></clause></subparagraph><subparagraph id="id637aa96809c84c209616f7990bd250c1"><enum>(D)</enum><text>offer the user a copy of the personal data of the user in accordance with subsection (b); and</text></subparagraph><subparagraph id="idb1715df1442f4decb38671e76c11e04c"><enum>(E)</enum><text>offer the user the option to close his or her account or otherwise terminate his or her use of the online platform.</text></subparagraph></paragraph><paragraph id="id5A314A7075A04C10BFEB4A5045C80684"><enum>(2)</enum><header>Consequence of prohibition of data collection</header><text>If the election of a user under paragraph (1)(B) creates inoperability in the online platform, the operator of the online platform may deny certain services or completely deny access to the user.</text></paragraph><paragraph id="id0BEA6BD4AE834C05AB4C294CAA388BDD"><enum>(3)</enum><header>Public safety exception</header><text>If the operator of a covered online platform, in good faith, believes that an emergency involving danger of death or serious physical injury to any individual requires disclosure without delay of specific personal data of a user of the online platform that relates to the emergency, the operator shall—</text><subparagraph id="id91470D0747FF4257BF446E8A7D4A40FF"><enum>(A)</enum><text>retain the specific personal data; and</text></subparagraph><subparagraph id="id0A0E3E4A923D43F59AA55714F4F4F2AD"><enum>(B)</enum><text>notify the proper authorities.</text></subparagraph></paragraph></subsection><subsection id="id3ED0181ED61F4131B2B90559C1531CE3"><enum>(d)</enum><header>Compliance</header><text>Not less frequently than once every 2 years, the operator of a covered online platform shall audit the privacy or security program of the online platform.</text></subsection><subsection id="id538C483CC43B44A6BE5C611C8FEB4B73"><enum>(e)</enum><header>Safe harbor</header><text>Subsections (a), (b), and (c) shall not apply with respect to the development of privacy-enhancing technology by an operator of an online platform.</text></subsection></section><section id="id08F68DD10F5D4CA5BB242E19C24F7CB7"><enum>4.</enum><header>Enforcement</header><subsection id="idFFDDD9AB00C440A988FB956F780C4562"><enum>(a)</enum><header>Enforcement by Commission</header><paragraph id="idF80923D2A5A5412BB1A7D666B9B8F05A"><enum>(1)</enum><header>Unfair or deceptive acts or practices</header><text>A violation of section 3 shall be treated as a violation of a rule defining an unfair or deceptive act or practice prescribed under section 18(a)(1)(B) of the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/57a">15 U.S.C. 57a(a)(1)(B)</external-xref>).</text></paragraph><paragraph id="id21f53e1e1a354ef597da64deafeb7fb7"><enum>(2)</enum><header>Powers of Commission</header><subparagraph id="id9fdc643617cb48158368ad318667861d"><enum>(A)</enum><header>In general</header><text>Except as provided in subparagraph (C), the Commission shall enforce this Act in the same manner, by the same means, and with the same jurisdiction, powers, and duties as though all applicable terms and provisions of the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/41">15 U.S.C. 41</external-xref> et seq.) were incorporated into and made a part of this Act.</text></subparagraph><subparagraph id="ida3d9c71af6844342abe44ed1b02dd200"><enum>(B)</enum><header>Privileges and immunities</header><text>Except as provided in subparagraph (C), any person who violates this Act shall be subject to the penalties and entitled to the privileges and immunities provided in the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/41">15 U.S.C. 41</external-xref> et seq.).</text></subparagraph><subparagraph id="idd0a22836d5554abab79a21947ca93274"><enum>(C)</enum><header>Common carriers and nonprofit organizations</header><text>Notwithstanding section 4, 5(a)(2), or 6 of the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/44">15 U.S.C. 44</external-xref>, 45(a)(2), 46) or any jurisdictional limitation of the Commission, the Commission shall also enforce this Act, in the same manner provided in subparagraphs (A) and (B) of this paragraph, with respect to—</text><clause id="id3f4d73a30aa14c4294ce75aa628ba562"><enum>(i)</enum><text>common carriers subject to the Communications Act of 1934 (<external-xref legal-doc="usc" parsable-cite="usc/47/151">47 U.S.C. 151</external-xref> et seq.) and Acts amendatory thereof and supplementary thereto; and</text></clause><clause id="id7e87ce269f26472a93ec720e4578093b"><enum>(ii)</enum><text>organizations not organized to carry on business for their own profit or that of their members.</text></clause></subparagraph><subparagraph id="idbc0e6b8dd71b41b487e34b50fa58a185"><enum>(D)</enum><header>Authority preserved</header><text>Nothing in this Act shall be construed to limit the authority of the Commission under any other provision of law.</text></subparagraph></paragraph></subsection><subsection id="id29a8b8af90fc4fd7b1606c6b715899d7"><enum>(b)</enum><header>Enforcement by States</header><paragraph id="id6c5986fa6a9e4a51a054242887b0b11f"><enum>(1)</enum><header>Authorization</header><text>Subject to paragraph (2), in any case in which the attorney general of a State has reason to believe, based on a legitimate consumer complaint, that an interest of the residents of the State has been or is threatened or adversely affected by the engagement of any person subject to section 3 in a practice that violates that section, the attorney general of the State may, as parens patriae, bring a civil action on behalf of the residents of the State in an appropriate district court of the United States to obtain appropriate relief.</text></paragraph><paragraph id="idcbe6bc06b7c24837b12d392f5189f475"><enum>(2)</enum><header>Rights of Federal Trade Commission</header><subparagraph id="id9730da7e20c24807b49ac8af31e4eb87"><enum>(A)</enum><header>Notice to Federal Trade Commission</header><clause id="id158ba369244543898d6c3bd0972cc473"><enum>(i)</enum><header>In general</header><text>Except as provided in clause (iii), the attorney general of a State shall notify the Commission in writing that the attorney general intends to bring a civil action under paragraph (1) before initiating the civil action against a person subject to this Act.</text></clause><clause id="idc627cff1fddb467889bd7c499e612399"><enum>(ii)</enum><header>Contents</header><text>The notification required by clause (i) with respect to a civil action shall include a copy of the complaint to be filed to initiate the civil action.</text></clause><clause id="idfbf21f7846e74f67acaf9c919649dee8"><enum>(iii)</enum><header>Exception</header><text>If it is not feasible for the attorney general of a State to provide the notification required by clause (i) before initiating a civil action under paragraph (1), the attorney general shall notify the Commission immediately upon instituting the civil action.</text></clause></subparagraph><subparagraph id="id9904584820bf4c1da22464e840cd6b61"><enum>(B)</enum><header>Intervention by Federal Trade Commission</header><text>The Commission may—</text><clause id="id63df64cb90d34a3297d3cd08b01c5e1a"><enum>(i)</enum><text>intervene in any civil action brought by the attorney general of a State under paragraph (1); and</text></clause><clause id="id4851268ac28a40b59884f12b49128e1c"><enum>(ii)</enum><text>upon intervening—</text><subclause id="id689a8667654344c78b8e45b5184a1b4a"><enum>(I)</enum><text>be heard on all matters arising in the civil action; and</text></subclause><subclause id="id6cc647b987fe42da80268b003678ef39"><enum>(II)</enum><text>file petitions for appeal of a decision in the civil action.</text></subclause></clause></subparagraph></paragraph><paragraph id="id1da553d299884536a6390db7f46580be"><enum>(3)</enum><header>Investigatory powers</header><text>Nothing in this subsection may be construed to prevent the attorney general of a State from exercising the powers conferred on the attorney general by the laws of the State to conduct investigations, to administer oaths or affirmations, or to compel the attendance of witnesses or the production of documentary or other evidence.</text></paragraph><paragraph id="id60c8e8f62f9746dcbdc75eae62cc2499"><enum>(4)</enum><header>Action by Federal Trade Commission</header><text>If the Commission institutes a civil action or an administrative action with respect to a violation of section 3, the attorney general of a State may not, during the pendency of the action, bring a civil action under paragraph (1) against any defendant named in the complaint of the Commission for the violation with respect to which the Commission instituted such action.</text></paragraph><paragraph id="id64eb37b12ab844b291ae8ddc190b8583"><enum>(5)</enum><header>Venue; service of process</header><subparagraph id="id24ad766963d24797a348bb2c304918b0"><enum>(A)</enum><header>Venue</header><text>Any action brought under paragraph (1) may be brought in—</text><clause id="id79d00ffbc11a4fb8843b14836217f0d0"><enum>(i)</enum><text>the district court of the United States that meets applicable requirements relating to venue under section 1391 of title 28, United States Code; or</text></clause><clause id="id0bfce019ce4644e1bd80a3180aebce84"><enum>(ii)</enum><text>another court of competent jurisdiction.</text></clause></subparagraph><subparagraph id="id9aa1ccc9e21147e382ee0423c488d834"><enum>(B)</enum><header>Service of process</header><text>In an action brought under paragraph (1), process may be served in any district in which the defendant—</text><clause id="id1b9b3509a0bf40f9aafc3d38093c0267"><enum>(i)</enum><text>is an inhabitant; or</text></clause><clause id="idda19b78227634688bc0b5ab641c28fe7"><enum>(ii)</enum><text>may be found.</text></clause></subparagraph></paragraph><paragraph id="idf1736c80a95c4678ae3510cc8b946b86"><enum>(6)</enum><header>Actions by other State officials</header><subparagraph id="idf1514f8d449c4cdfa395a1edd9550e87"><enum>(A)</enum><header>In general</header><text>In addition to civil actions brought by attorneys general under paragraph (1), any other consumer protection officer of a State who is authorized by the State to do so may bring a civil action under paragraph (1), subject to the same requirements and limitations that apply under this subsection to civil actions brought by attorneys general.</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ida55a6eb04c4b479ea3fb22e8b6548092"><enum>(B)</enum><header>Savings provision</header><text>Nothing in this subsection may be construed to prohibit an authorized official of a State from initiating or continuing any proceeding in a court of the State for a violation of any civil or criminal law of the State.</text></subparagraph></paragraph></subsection></section><section id="id6B7C11C0CB6E40EFAF2A8D94BA5B72C2"><enum>5.</enum><header>Effective date</header><subsection id="id50D3CF3FDB5447AB89FE107436597734"><enum>(a)</enum><header>In general</header><text display-inline="yes-display-inline">This Act shall take effect 180 days after the date of enactment of this Act.</text></subsection><subsection id="idF2289BF977E14B389EF461AE78C4F8CD"><enum>(b)</enum><header>Applicability to existing users of online platforms</header><text>An individual who becomes a user of a covered online platform before the effective date under subsection (a) shall be treated as if he or she had become a user of the online platform on that effective date.</text></subsection><subsection id="idB2B7379EAE6847329D9099E406FB39E7"><enum>(c)</enum><header>No retroactive applicability</header><text>This Act shall not apply to any conduct that occurred before the effective date under subsection (a).</text></subsection></section></legis-body></bill>


