<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-GOE21644-YT5-6P-KDS"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>117 S2290 IS: Data Broker List Act of 2021</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2021-06-24</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>117th CONGRESS</congress><session>1st Session</session><legis-num>S. 2290</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20210624">June 24, 2021</action-date><action-desc><sponsor name-id="S380">Mr. Peters</sponsor> (for himself, <cosponsor name-id="S410">Ms. Lummis</cosponsor>, and <cosponsor name-id="S372">Mrs. Capito</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSCM00">Committee on Commerce, Science, and Transportation</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To provide for requirements for data brokers with respect to the acquisition, use, and protection of brokered personal information and to require that data brokers annually register with the Federal Trade Commission.</official-title></form><legis-body display-enacting-clause="yes-display-enacting-clause"><section section-type="section-one" id="S1"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Data Broker List Act of 2021</short-title></quote>.</text></section><section id="id40909246AC0345858F84FC243FCD6392"><enum>2.</enum><header>Requirements for data brokers</header><subsection id="idda82daff96464889933675e77da93b0d"><enum>(a)</enum><header>Requirements with respect to the acquisition and use of brokered personal information</header><text>A data broker shall not—</text><paragraph id="id676A3D6E994A4CC598AAD9807DF3B285"><enum>(1)</enum><text>acquire brokered personal information through fraudulent means;</text></paragraph><paragraph id="id4ef410053a7e41da94efbfe62262ead4"><enum>(2)</enum><text>acquire or use brokered personal information for the purpose of—</text><subparagraph id="id81e64e9908fb4df88181a608d3c64081"><enum>(A)</enum><text>stalking or harassing another person;</text></subparagraph><subparagraph id="id28f175e1c3be423e88664550a2209d99"><enum>(B)</enum><text>committing fraud, including identity theft, financial fraud, or e-mail fraud; or</text></subparagraph><subparagraph id="id98113b8b499a4894b58afe10ae2305dc"><enum>(C)</enum><text>engaging in unlawful discrimination, including unlawful discrimination in decisions regarding employment, housing, and credit eligibility; or</text></subparagraph></paragraph><paragraph id="id5a81ad13cffe44acaa8e764f2ba914e8"><enum>(3)</enum><text>sell or transfer brokered personal information to a third party if the data broker knows or reasonably should know that the third party intends to engage in any conduct prohibited by this Act.</text></paragraph></subsection><subsection commented="no" id="id33F82C0821D3473DBAA1B6CB3968C52A"><enum>(b)</enum><header>Duty To protect brokered personal information</header><paragraph commented="no" id="idEB268AD8B08741378BFD487B8D8452B4"><enum>(1)</enum><header>In general</header><text>A data broker shall develop, implement, and maintain a comprehensive information security program in order to protect from security breaches or other inadvertent or improper disclosure the brokered personal information acquired by the data broker.</text></paragraph><paragraph id="idbe3f2043d9e24b2f8a81306076670327"><enum>(2)</enum><header>Notification of change of ownership</header><text>If a data broker is purchased or otherwise acquired by another entity, such other entity shall provide notification of such purchase or acquisition to any consumer with respect to which—</text><subparagraph id="id1300880e64534efe89ec3dd1f68e00e8"><enum>(A)</enum><text>the data broker collected, processed, analyzed, stored or used brokered personal information; and</text></subparagraph><subparagraph id="id5e34bd0c3961445ea23e7f4aa4e663a5"><enum>(B)</enum><text>such other entity plans to continue to collect, process, analyze, store or use such information. </text></subparagraph></paragraph><paragraph commented="no" id="idF0DF8C1C079B496F8070691EB84843CD"><enum>(3)</enum><header>Program requirements</header><text>The comprehensive information security program required under paragraph (1) shall—</text><subparagraph commented="no" id="id3119D93932F749E2A30CFC1A050A0126"><enum>(A)</enum><text>be written in one or more readily accessible parts; and</text></subparagraph><subparagraph commented="no" id="id040595D6C2B74D5B8C317E0093843996"><enum>(B)</enum><text>contain administrative, technical, and physical safeguards that are appropriate to—</text><clause id="idecc96e79070a4405bd14372350c90214"><enum>(i)</enum><text>the size, scope, and type of business of the data broker;</text></clause><clause id="idf797ed6be2164087929b1ca6186a6eb7"><enum>(ii)</enum><text>the amount of resources available to the data broker;</text></clause><clause id="id49e8d9a962294204a56a1607a894cfc6"><enum>(iii)</enum><text>the amount of stored data of the data broker;</text></clause><clause id="idec4564dd63ee4dd0b142e9d5521cbfde"><enum>(iv)</enum><text>the nature and sensitivity of the brokered personal information stored by the data broker; and </text></clause><clause commented="no" display-inline="no-display-inline" id="id19392bfc946a4c99beb34c7ed1387288"><enum>(v)</enum><text>the need for security and confidentiality of brokered personal information.</text></clause></subparagraph></paragraph></subsection><subsection id="id967932e63b1f4ab6ab7eec1278e72d89"><enum>(c)</enum><header>Annual registration</header><paragraph id="id63B9C5ABC33042F597691E20C1A7D027"><enum>(1)</enum><header>In general</header><text>Annually, on or before January 31, a data broker shall—</text><subparagraph id="idd7b7cf602647412f91e01480ca72449b"><enum>(A)</enum><text>register with the Commission; and</text></subparagraph><subparagraph id="id57581b2f4a7d4877acad7e54dbcfcec5"><enum>(B)</enum><text>provide the following information with such registration:</text><clause id="idba7fa3ebe4384c3cb359de1ee8bd0f31"><enum>(i)</enum><text>The name and primary physical, e-mail, and internet addresses of the data broker.</text></clause><clause id="ida4983a3fbf19425b84664ca0baf28c4f"><enum>(ii)</enum><text>If the data broker permits a consumer to opt out of the data broker’s collection of brokered personal information, opt out of its databases, or opt out of certain sales of data—</text><subclause id="id7cbd231178464f688cd441caca3b2b09"><enum>(I)</enum><text>the method for requesting an opt-out;</text></subclause><subclause id="idfe2a28812e1d421cb2e5bf7a91c645ee"><enum>(II)</enum><text>if the opt-out applies to only certain activities or sales, which ones; and</text></subclause><subclause id="id2428f6c9c92143d5bdac6014df422f49"><enum>(III)</enum><text>whether the data broker permits a consumer to authorize a third party to perform the opt-out on the consumer’s behalf.</text></subclause></clause><clause id="id28003d15c8154fdc8297a8b7fe09aed5"><enum>(iii)</enum><text>A statement specifying the data collection, databases, or sales activities from which a consumer may not opt out, and why an opportunity to opt out is not available.</text></clause><clause id="id5a0e4603a7b74fbbbd35fc5d847576bc"><enum>(iv)</enum><text>A statement specifying the types of information being collected, as determined by the Commission, to the extent practicable.</text></clause><clause id="id8892342ac79640a6bbee7dd268dafddf"><enum>(v)</enum><text>A statement as to whether the data broker implements a purchaser credentialing process and, if so, a description of that process.</text></clause><clause id="idea5207327c264b518cce51b7c83a911d"><enum>(vi)</enum><text>The number of security breaches that the data broker experienced during the previous year, and if known, the total number of consumers whose personal information was accessed, downloaded, viewed, or otherwise affected in a breach.</text></clause><clause id="id8c4bdfcfd4ae4161878748d560085169"><enum>(vii)</enum><text>Where the data broker has actual knowledge that it possesses the brokered personal information of minors, a separate statement detailing the data collection practices, databases, sales activities, and opt-out policies that are applicable to the brokered personal information of minors.</text></clause><clause id="idcb43ffb991b14b91a55b5327996db412"><enum>(viii)</enum><text>Any additional information or explanation concerning its data collection practices. </text></clause></subparagraph></paragraph><paragraph commented="no" id="idB594F273636F4A59A0E4E125011AA40B"><enum>(2)</enum><header>Exception</header><text>The requirements under paragraph (1) shall not apply to a data broker that is already required to comply with such requirements with respect to another Federal agency.</text></paragraph><paragraph commented="no" id="idB424E2198C3549D0AC5B6E66D1324F4F"><enum>(3)</enum><header>Public availability</header><text>The Commission shall make the information described in paragraph (1) available on the internet website of the Commission, except as necessary to protect the integrity of ongoing investigations or to protect the privacy of consumers, or if it is in the interest of public safety or welfare.</text></paragraph></subsection></section><section commented="no" display-inline="no-display-inline" id="idb31b34d4-b455-4123-a1cf-9b3eda436c8c"><enum>3.</enum><header display-inline="yes-display-inline">Enforcement by the Federal Trade Commission</header><subsection commented="no" display-inline="no-display-inline" id="id34895b78-9415-4c33-9c0c-d31ab4641102"><enum>(a)</enum><header display-inline="yes-display-inline">Unfair or deceptive acts or practices</header><text display-inline="yes-display-inline">A violation of section 2 shall be treated as a violation of a rule defining an unfair or a deceptive act or practice under section 18(a)(1)(B) of the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/57a">15 U.S.C. 57a(a)(1)(B)</external-xref>). The Commission shall begin enforcement of such violations by not later than 1 year after the date of the enactment of this Act.</text></subsection><subsection commented="no" display-inline="no-display-inline" id="id2aae6977-256a-4c23-a7e2-8db1300fb35c"><enum>(b)</enum><header display-inline="yes-display-inline">Powers of Commission</header><paragraph commented="no" display-inline="no-display-inline" id="idbc4b49b3-628b-4811-b9bf-30dee95a0464"><enum>(1)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">The Commission shall enforce this Act in the same manner, by the same means, and with the same jurisdiction, powers, and duties as though all applicable terms and provisions of the <act-name parsable-cite="FTCA">Federal Trade Commission Act</act-name> (<external-xref legal-doc="usc" parsable-cite="usc/15/41">15 U.S.C. 41 et seq.</external-xref>) were incorporated into and made a part of this Act.</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id62badbc8-b144-471b-87c5-8de40c6979bb"><enum>(2)</enum><header display-inline="yes-display-inline">Privileges and immunities</header><text display-inline="yes-display-inline">Any data broker who violates section 2 shall be subject to the penalties and entitled to the privileges and immunities provided in the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/41">15 U.S.C. 41 et seq.</external-xref>).</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id92A178F2B0EA43E5973351284769A92C"><enum>(3)</enum><header>Civil penalty</header><text>A data broker that fails to register as required under section 2(c) shall be liable for a civil penalty in an amount determined by the Commission through the rulemaking authority under subsection (c).</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id4eb0393a3ce54c0bbfec97e16f6b23e7"><enum>(4)</enum><header display-inline="yes-display-inline">Authority preserved</header><text display-inline="yes-display-inline">Nothing in this Act shall be construed to limit the authority of the Federal Trade Commission under any other provision of law.</text></paragraph></subsection><subsection id="id044c0f198fb84ecb980d56168eb5666a"><enum>(c)</enum><header>Rulemaking authority for the Commission</header><text>The Commission shall have authority under section 553 of title 5, United States Code, to promulgate regulations the Commission determines to be necessary to carry out the provisions of this Act.</text></subsection></section><section id="H82D20B5D162B494F97F7B61E1B29BEE6"><enum>4.</enum><header>FTC annual review and report</header><subsection id="H41B67F23A8AA4D4EB0DC43E86188DF29"><enum>(a)</enum><header>Annual review</header><text>The Commission shall conduct an annual review of the implementation of the provisions of this Act. Such study shall include an analysis of—</text><paragraph id="idD91B87F11D464DF6B07C497317BD2427"><enum>(1)</enum><text>compliance by data brokers with the requirements under section 2;</text></paragraph><paragraph id="idA3AC755ED71545C8A4C4BE29FE4BA1D3"><enum>(2)</enum><text>enforcement actions taken by the Commission with respect to violations of such requirements; and</text></paragraph><paragraph id="id3E6C937D22C54709B689CBDF32D38BE5"><enum>(3)</enum><text>other areas determined appropriate by the Commission.</text></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="id903f7822fbc745f5ba1ed87b2ad10abc"><enum>(b)</enum><header>Annual report</header><text>Not later than 1 year after the date of the enactment of this Act, and annually thereafter the Commission shall submit to Congress a report on the review conducted under subsection (a), together with recommendations for such legislation and administrative action as the Commission determines appropriate.</text></subsection></section><section id="id375CDA9CF0ED415E83CDC12968506949"><enum>5.</enum><header>Definitions</header><text display-inline="no-display-inline">In this section:</text><paragraph id="id1940790d3ba04a18be5ecf593ef296a5"><enum>(1)</enum><header>Brokered personal information</header><text>The term <term>brokered personal information</term> means any personal information that is categorized or organized for sale, license, or trade, or is otherwise disclosed for compensation, to a third party. </text></paragraph><paragraph id="id99215b6f5ad94e1397c7aaa218924a0e"><enum>(2)</enum><header>Business</header><subparagraph id="idBF978F3A08404ED199714FEDC1059871"><enum>(A)</enum><header>In general</header><text>The term <term>business</term> means a commercial entity, including a sole proprietorship, partnership, corporation, association, limited liability company, or other group, however organized and whether or not organized to operate at a profit, including a financial institution organized, chartered, or holding a license or authorization certificate under the laws of a State, the United States, or any other country, or the parent, affiliate, or subsidiary of a financial institution.</text></subparagraph><subparagraph id="id997F12223723454FAC622879FEC2C6C7"><enum>(B)</enum><header>Exclusion</header><text>The term <term>business</term> does not include a State, a State agency, any political subdivision of a State, or a vendor acting solely on behalf of, and at the direction of, a State.</text></subparagraph></paragraph><paragraph id="id85d9252e14c84c968729362e20287f84"><enum>(3)</enum><header>Commission</header><text>The term <term>Commission</term> means the Federal Trade Commission.</text></paragraph><paragraph commented="no" id="id6CF84BF2D17B40459218ED83A679FBCE"><enum>(4)</enum><header>Consumer</header><text>The term <term>consumer</term> means an individual residing in the United States acting in a personal, family, or household capacity.</text></paragraph><paragraph id="id455AF0D9D2234FAA9B232F43A92C689B"><enum>(5)</enum><header>Data broker</header><subparagraph id="id04ABEAC5D54947089D43831B52E9779A"><enum>(A)</enum><header>In general</header><text>The term <term>data broker</term> means a business that knowingly collects or obtains the personal information of a consumer with whom the business does not have a direct relationship and then sells, licenses, trades, provides for consideration, or is otherwise compensated for disclosing that information to a third party. </text></subparagraph><subparagraph id="idb2aac6a7e374446998f07556f71f5180"><enum>(B)</enum><header>Direct relationship</header><text>For purposes of subparagraph (A), a direct relationship with a business exists if the consumer—</text><clause id="idD9B895E8B5274DAD91A4E78A041054C7"><enum>(i)</enum><text>is a current customer;</text></clause><clause id="id17CA636842B84AF6BBF41D4653FF1B3B"><enum>(ii)</enum><text>obtained a good or service from the business within the prior 18 months; or</text></clause><clause id="idA16424662BEB44C68E4B3F76EE1404B7"><enum>(iii)</enum><text>made an inquiry about the products or services of the business within the prior 90 days.</text></clause></subparagraph><subparagraph commented="no" id="idf474aa2157d24408817cf3465a7bba8e"><enum>(C)</enum><header>Exclusion</header><text>The following activities conducted by a business, and the collection and sale or licensing of brokered personal information incidental to conducting these activities, do not qualify the business as a data broker:</text><clause commented="no" id="id928ff82da3a743028e1729a605802254"><enum>(i)</enum><text>Providing 411 directory assistance or directory information services, including name, address, and telephone number, on behalf of or as a function of a telecommunications carrier.</text></clause><clause commented="no" id="idf7e941a90c344ebd8a9df45dc712211b"><enum>(ii)</enum><text>Providing a consumer's publicly available information if the information is being used by the recipient as it relates to that consumer's business or profession.</text></clause><clause commented="no" id="id45b7626fe40941878a1f74ce35e9aaa6"><enum>(iii)</enum><text>Providing publicly available information via real-time or near-real-time alert services for health or safety purposes.</text></clause><clause id="idca089bc3785f43b39b942652456ee480"><enum>(iv)</enum><text>Providing or using information in a manner that is regulated under another Federal or State law, including the Fair Credit Reporting Act, the Gramm-Leach-Bliley Act, or the Health Insurance Portability and Accountability Act.</text></clause><clause id="ide71c6f04841e46e0909f648918b5fd10"><enum>(v)</enum><text>Providing data to a third party at the direction of the consumer and with the consumer’s affirmative express consent. </text></clause><clause id="ide89faf7f3d1440ddb0c874278944dae9"><enum>(vi)</enum><text>Providing or using information for assessing, verifying, or authenticating a person’s identity, or for investigating or preventing actual or potential fraud. </text></clause></subparagraph><subparagraph commented="no" id="idc98e35e9cdd54b3cad6fe5674179ec35"><enum>(D)</enum><header>Exclusion from sale</header><text>For purposes of this paragraph, the term <term>sells</term> does not include a one-time or occasional sale of assets of a business as part of a transfer of control of those assets that is not part of the ordinary conduct of the business.</text></subparagraph></paragraph><paragraph id="idF58F4C72C65A489B9D324DC7E8E0F9E1"><enum>(6)</enum><header>Data broker security breach</header><subparagraph id="idCF6271D384B9497AAA0FAB53FECC5222"><enum>(A)</enum><header>In general</header><text>The term <term>data broker security breach</term> means an unauthorized acquisition or a reasonable belief of an unauthorized acquisition of more than one element of brokered personal information maintained by a data broker when the brokered personal information is not encrypted, redacted, or protected by another method that renders the information unreadable or unusable by an unauthorized person or entity.</text></subparagraph><subparagraph id="id1e23dddb1d2d4e008434fdaa66fd7050"><enum>(B)</enum><header>Exclusion</header><text>The term <term>data broker security breach</term> does not include good faith but unauthorized acquisition of brokered personal information by an employee or agent of the data broker for a legitimate purpose of the data broker, provided that the brokered personal information is not used for a purpose unrelated to the data broker’s business or subject to further unauthorized disclosure.</text></subparagraph><subparagraph id="ide96aabf2982845ac995bb44a9d7d76c8"><enum>(C)</enum><header>Application</header><text>In determining whether brokered personal information has been acquired or is reasonably believed to have been acquired without valid authorization, a data broker may consider the following factors, among others:</text><clause id="id471dac9b2ae448f291b52efa870aab4d"><enum>(i)</enum><text>Indications that the brokered personal information is in the physical possession and control of a person or entity without valid authorization, such as a lost or stolen computer or other device containing brokered personal information.</text></clause><clause id="id46e62643151d4a2ba2e293b453c99040"><enum>(ii)</enum><text>Indications that the brokered personal information has been downloaded or copied.</text></clause><clause id="id97bf70027d0e4dadbab6e2d961adedbd"><enum>(iii)</enum><text>Indications that the brokered personal information was used by an unauthorized person or entity, such as fraudulent accounts opened or instances of identity theft reported.</text></clause><clause id="id714e741fc590495f92d8c9817fb4b48c"><enum>(iv)</enum><text>That the brokered personal information has been made public.</text></clause></subparagraph></paragraph><paragraph id="idF92B3F9F92D4406A9B5CB7D73576E571"><enum>(7)</enum><header>Personal information</header><text>The term <term>personal information</term> means information which is related to any identified or identifiable person.</text></paragraph><paragraph id="id25B9315117B7499B8B3C325A5850B798"><enum>(8)</enum><header>State</header><text>The term <term>State</term> means any State of the United States, the District of Columbia, the Commonwealth of Puerto Rico, Guam, American Samoa, the Commonwealth of Northern Mariana Islands, and the United States Virgin Islands.</text></paragraph></section></legis-body></bill>


