<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-type="olc" bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-GOE22031-56H-S8-XMV"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>117 S3501 IS: Terms-of-service Labeling, Design, and Readability Act</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2022-01-13</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>117th CONGRESS</congress><session>2d Session</session><legis-num>S. 3501</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20220113" legis-day="20220110">January 13 (legislative day, January 10), 2022</action-date><action-desc><sponsor name-id="S373">Mr. Cassidy</sponsor> (for himself and <cosponsor name-id="S409">Mr. Luján</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSCM00">Committee on Commerce, Science, and Transportation</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To require the Federal Trade Commission to issue a short-form terms of service summary statement, and for other purposes.</official-title></form><legis-body style="OLC" display-enacting-clause="yes-display-enacting-clause" id="H8C118D158FF744338792587232FC2163"><section section-type="section-one" id="H418D135E32074D63B489B2D76C9977EE"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Terms-of-service Labeling, Design, and Readability Act</short-title></quote> or the <quote><short-title>TLDR Act</short-title></quote>.</text></section><section id="H07DA773256CE4F6ABED97D854CA90C01"><enum>2.</enum><header>Standard terms of service summary statement</header><subsection id="H56B8C25947754F0A83BBCF28DE908A4D"><enum>(a)</enum><header>Deadline for terms of service summary statement</header><text display-inline="yes-display-inline">Not later than 360 days after the date of the enactment of this Act, the Commission shall issue a rule under section 553 of title 5, United States Code—</text><paragraph id="H9E129C7B66D3416E9E309480DF7505F4"><enum>(1)</enum><text display-inline="yes-display-inline">that requires a covered entity to include a short-form terms of service summary statement on the website of the entity;</text></paragraph><paragraph id="HA844678C693B44BFBDD68B47548C36AE"><enum>(2)</enum><text>that requires a covered entity to include graphic data flow diagram on the website of the entity and includes guidance for such diagram; and</text></paragraph><paragraph id="H8510DC839B0D419E8E10B92253D78E61"><enum>(3)</enum><text display-inline="yes-display-inline">that requires a covered entity to display the full terms of service of the entity in an interactive data format.</text></paragraph></subsection><subsection id="H489690CD1B914B128EFB8E5F99B2673A"><enum>(b)</enum><header>Requirements for short-Form terms of service summary statement</header><paragraph id="H97943D845C144C7DA2EB5E44DC452CAD"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">The short-form terms of service summary statement described in subsection (a)—</text><subparagraph id="H49B2011BBBBC48A5B047DE52008448CB"><enum>(A)</enum><text>shall be easy to understand, machine readable, and may include tables, graphic icons, hyperlinks, or other means determined by the Commission; and</text></subparagraph><subparagraph id="H61722A94206540658B3AA3FEA7C6B46A"><enum>(B)</enum><text display-inline="yes-display-inline">may be established separately depending on the interface or type of device on which the statement is being accessed by the user.</text></subparagraph></paragraph><paragraph display-inline="no-display-inline" id="H8F0033A628474F0EA22BAFB79FCD1A7F"><enum>(2)</enum><header>Location of summary statement and graphic data flow diagram</header><text display-inline="yes-display-inline">The summary statement shall be placed at the top of the permanent terms of service page of the covered entity and any graphic data flow diagram shall be located immediately below the statement. </text></paragraph><paragraph id="HF91E3E7ED0234D45900D4A9F308FF4FC"><enum>(3)</enum><header>Contents of summary statement</header><text display-inline="yes-display-inline">The summary statement shall disclose the following:</text><subparagraph id="H9E920A1D0517407DB18261702B53BBDC"><enum>(A)</enum><text>The effort required by a user to read the entire terms of service text, such as through the total word count and approximate time to read the statement.</text></subparagraph><subparagraph id="HC58AD6167C664734874E5E7ABF64EFA9"><enum>(B)</enum><text>The categories of sensitive information that the covered entity processes.</text></subparagraph><subparagraph id="HAB61A9A96C6E43EEB98F117670CF6CF6"><enum>(C)</enum><text display-inline="yes-display-inline">The sensitive information that is required for the basic functioning of the service and what sensitive information is needed for additional features and future feature development.</text></subparagraph><subparagraph id="H90BDCE2FF9904C0ABF4B6CA34F9E7518"><enum>(D)</enum><text display-inline="yes-display-inline">A summary of the legal liabilities of a user and any rights transferred from the user to the covered entity, such as mandatory arbitration, class action waiver, any licensing by the covered entity of the content of the user, and any waiver of moral rights.</text></subparagraph><subparagraph id="H18BC79FEB95A48D8AA50C43874822333"><enum>(E)</enum><text>Historical versions of the terms of service and change logs.</text></subparagraph><subparagraph id="HFF726BB6931A47EF85BF01FFA884BE83"><enum>(F)</enum><text display-inline="yes-display-inline">If the covered entity provides user deletion services, directions for how the user can delete sensitive information or discontinue the use of sensitive information.</text></subparagraph><subparagraph id="HC9A493FA84F0421A951FD03D57318D46"><enum>(G)</enum><text>A list of data breaches from the previous 3 years reported to consumers under existing Federal and State laws.</text></subparagraph><subparagraph id="HCEA1C9F051EA41A09B40B58BDDAF05B7"><enum>(H)</enum><text>Anything else determined to be necessary by the Commission.</text></subparagraph></paragraph></subsection><subsection id="HE0E2F7DA92F244438556D6AED512AF0F"><enum>(c)</enum><header>Guidance on graphic data flow diagrams</header><text display-inline="yes-display-inline">Not later than 360 days after the date of the enactment of this Act, the Commission shall publish guidelines on how a covered entity can graphically display how sensitive information of a user is shared with a subsidiary or corporate affiliate of such the entity and how sensitive information is shared with third parties.</text></subsection><subsection commented="no" id="H7269911C75644AB28084F85CEE30B28D"><enum>(d)</enum><header>Interactive data format terms of service</header><text>Not later than 360 days after the date of the enactment of this Act, the Commission shall issue a rule under section 553 of title 5, United States Code, that requires a covered entity to tag portions of the terms of services of the entity according to an interactive data format.</text></subsection><subsection id="HC96FBF2A3A314B27A3A56E77A73DA317"><enum>(e)</enum><header>Enforcement</header><paragraph id="H292AE83DCE724E9E98FB0C427605590B"><enum>(1)</enum><header>Unfair or deceptive acts or practices</header><text>A violation of this section or a regulation promulgated under this section shall be treated as a violation of a regulation under section 18(a)(1)(B) of the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/57a">15 U.S.C. 57a(a)(1)(B)</external-xref>) regarding unfair or deceptive acts or practices.</text></paragraph><paragraph id="H3D7E82F7A9124ECEB5DAC7B7EDD334FA"><enum>(2)</enum><header>Powers of the commission</header><text>The Commission shall enforce this section and the regulations promulgated under this section in the same manner, by the same means, and with the same jurisdiction, powers, and duties as though all applicable terms and provisions of the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/41">15 U.S.C. 41 et seq.</external-xref>) were incorporated into and made a part of this section, and any person who violates this section or a regulation promulgated under this section shall be subject to the penalties and entitled to the privileges and immunities provided in the Federal Trade Commission Act. </text></paragraph><paragraph commented="no" id="H44F3EA7C6DA943D680CA1471A634867A"><enum>(3)</enum><header>Enforcement by State Attorneys General</header><text display-inline="yes-display-inline">In any case in which the attorney general of a State has reason to believe that an interest of at least 1,000 residents of that State has been or is threatened or adversely affected by the engagement of any person in a practice that violates this section or a regulation promulgated under this section, the State, as parens patriae, may bring a civil action on behalf of the residents of the State in a district court of the United States of appropriate jurisdiction to—</text><subparagraph commented="no" id="HA8215BE195A7467598967CCAF4DFEB99"><enum>(A)</enum><text>enjoin that practice;</text></subparagraph><subparagraph commented="no" id="HF1562B2069ED48AFB9CDDCCECE4712EA"><enum>(B)</enum><text>enforce compliance with the regulation;</text></subparagraph><subparagraph commented="no" id="H2429E6622AA34950AD5B02B7A49F6271"><enum>(C)</enum><text>obtain damage, restitution, or other compensation on behalf of residents of the State; or</text></subparagraph><subparagraph commented="no" id="HD7494E69C9984DC2B03A4364CFA85986"><enum>(D)</enum><text>obtain such other relief as the court may consider to be appropriate.</text></subparagraph></paragraph><paragraph commented="no" id="H5B0300EA43F04137AC493F2A6D28AA51"><enum>(4)</enum><header>Notice</header><subparagraph commented="no" id="H2D5E46F9EA0D4CAFBEEDD3F62855F65E"><enum>(A)</enum><header>In general</header><text>Before filing an action under paragraph (3), the attorney general of the State involved shall provide to the Commission—</text><clause commented="no" id="H5AB8A66FB56748C390E835C641C26869"><enum>(i)</enum><text>written notice of that action; and</text></clause><clause commented="no" id="H9EC4899B4A384107A02BBB0B2C25E755"><enum>(ii)</enum><text>a copy of the complaint for that action.</text></clause></subparagraph><subparagraph commented="no" id="HC4C6FFF03ADE4D59943DC8837C544348"><enum>(B)</enum><header>Exemption</header><clause commented="no" id="H648E8BA223F1463883A8D19292F35305"><enum>(i)</enum><header>In general</header><text>Subparagraph (A) shall not apply with respect to the filing of an action by an attorney general of a State under this subsection, if the attorney general determines that it is not feasible to provide the notice described in that subparagraph before the filing of the action.</text></clause><clause commented="no" id="H417CE0ADA7CF4221B354A7989E36A5EF"><enum>(ii)</enum><header>Notification</header><text>In an action described in clause (i), the attorney general of a State shall provide notice and a copy of the complaint to the Commission at the same time as the attorney general files the action.</text></clause></subparagraph></paragraph><paragraph id="HA046A86B260A4C4E9904F7D6A21B5E4D"><enum>(5)</enum><header>Removal to Federal court</header><text display-inline="yes-display-inline">The Commission may intervene in any action brought under paragraph (3) and remove the action to the appropriate United States district court.</text></paragraph></subsection><subsection id="H654537F0F8F04D90839CD89974D831CE"><enum>(f)</enum><header>Rule of construction</header><text display-inline="yes-display-inline">Nothing in this section shall be construed to limit the authority of the Commission under any other provision of law.</text></subsection><subsection id="H8C325FAB1D754D02AEBD57154FFF0C8B"><enum>(g)</enum><header>Definitions</header><text>In this section:</text><paragraph id="HA1192BF67A5F4C2BB128C1AF04D08C98"><enum>(1)</enum><header>Commission</header><text>The term <term>Commission</term> means the Federal Trade Commission.</text></paragraph><paragraph commented="no" id="H9AE882EAD60A48E38B3167AEB7A9D9DB"><enum>(2)</enum><header>Covered entity</header><text display-inline="yes-display-inline">The term <term>covered entity</term>—</text><subparagraph commented="no" id="HEB11822E85674CD286F058EE92C82995"><enum>(A)</enum><text display-inline="yes-display-inline">means any person that operates a website located on the internet or an online service, that is operated for commercial purposes; and</text></subparagraph><subparagraph commented="no" id="H447CAAA24B5C4FF3A6E0A47840CB2BF0"><enum>(B)</enum><text>does not include a small business concern (as defined in section 3 of the Small Business Act (<external-xref legal-doc="usc" parsable-cite="usc/15/632">15 U.S.C. 632</external-xref>)).</text></subparagraph></paragraph><paragraph commented="no" id="H3067C9C857614EEF9612A319BB69E511"><enum>(3)</enum><header>Interactive data format</header><text display-inline="yes-display-inline">The term <term>interactive data format</term> means an electronic data format in which pieces of information are identified using an interactive data standard, such as eXtensible Markup Language (XML), that is a standardized list of electronic tags that mark the information described in section 2(b)(3) within the terms of service of a covered entity.</text></paragraph><paragraph id="HE9BC02DE39F2442C96A52FC06F665314"><enum>(4)</enum><header>Sensitive information</header><text>The term <term>sensitive information</term> means any of the following:</text><subparagraph id="HFE0FD5D85CFF418EA0AF277ECEEE6B74"><enum>(A)</enum><text>Health information.</text></subparagraph><subparagraph id="H87F73FEA8A6C4299AABB5618BB8D34E2"><enum>(B)</enum><text>Biometric information.</text></subparagraph><subparagraph id="HA2B4C581E74845229A1EE06747CB9282"><enum>(C)</enum><text>Precise geolocation information.</text></subparagraph><subparagraph id="HE89335F5681449249CD9C5E7AB44E8BF"><enum>(D)</enum><text>Social security number.</text></subparagraph><subparagraph id="H8B7755C8F0C94611974C2833B7645761"><enum>(E)</enum><text>Information concerning the race, color, religion, national origin, sex, age, or disability of an individual.</text></subparagraph><subparagraph id="H93274F9F79DC460EB43D0D8B85BDD770"><enum>(F)</enum><text>The content and parties to a communication.</text></subparagraph><subparagraph id="H9603E65BB64F45119E158E5658D55124"><enum>(G)</enum><text>Audio and video recordings captured through a consumer device.</text></subparagraph><subparagraph id="HC3AC6AF25ACF4B81BF15A3D95A37AB5E"><enum>(H)</enum><text>Financial information, including a bank account number, credit card number, debit card number, or insurance policy number.</text></subparagraph><subparagraph id="HDB698632B2714CF1BF6C921A7981B378"><enum>(I)</enum><text>Online browsing history related to the information described in subparagraphs (A) through (H).</text></subparagraph></paragraph><paragraph commented="no" id="H8409120DFA1B4062A741E46750CEB1C2"><enum>(5)</enum><header>State</header><text display-inline="yes-display-inline">The term <term>State</term> means each of the several States, the District of Columbia, each commonwealth, territory, or possession of the United States, and each federally recognized Indian Tribe. </text></paragraph><paragraph commented="no" id="HAC70406DD8B34E8CA5A93DB67AC71807"><enum>(6)</enum><header>Third party</header><text>The term <term>third party</term> means, with respect to a covered entity, a person—</text><subparagraph commented="no" id="H0128018D1BA44D1487710596D3670855"><enum>(A)</enum><text>to whom the covered entity disclosed sensitive information; and</text></subparagraph><subparagraph commented="no" id="H8645C3AF8B39495BA1068017D62C1BD4"><enum>(B)</enum><text>is not—</text><clause commented="no" id="H470C5E53B63E4C658F818317E4F71A18"><enum>(i)</enum><text>the covered entity;</text></clause><clause commented="no" id="H2DEA95002B9A48F48914CFF68C6ED530"><enum>(ii)</enum><text>a subsidiary or corporate affiliate of the covered entity; or</text></clause><clause commented="no" id="H05E0950B44234F3FA12B33DDE685F59F"><enum>(iii)</enum><text>a service provider of the covered entity.</text></clause></subparagraph></paragraph></subsection></section></legis-body></bill> 

