<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" dms-id="H03DC710D50254FCFAC06762FD88FA7B5" public-private="public" key="H" bill-type="olc"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>118 HR 4311 IH: Data Elimination and Limiting Extensive Tracking and Exchange Act</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2023-06-22</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">I</distribution-code><congress display="yes">118th CONGRESS</congress><session display="yes">1st Session</session><legis-num display="yes">H. R. 4311</legis-num><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action display="yes"><action-date date="20230622">June 22, 2023</action-date><action-desc><sponsor name-id="T000482">Mrs. Trahan</sponsor> (for herself and <cosponsor name-id="E000246">Mr. Edwards</cosponsor>) introduced the following bill; which was referred to the <committee-name committee-id="HIF00">Committee on Energy and Commerce</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title display="yes">To establish a centralized system to allow individuals to request the simultaneous deletion of their personal information across all data brokers, and for other purposes.</official-title></form><legis-body id="H401664046C7145B0929F84C9DE7001E4" style="OLC"> 
<section section-type="section-one" id="H8F03D671E7BD42F6BD06C642DDC80053"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Data Elimination and Limiting Extensive Tracking and Exchange Act</short-title></quote> or the <quote><short-title>DELETE Act</short-title></quote>.</text></section> <section id="HE9812664E2184DC5A4B7B7D6170710DB"><enum>2.</enum><header>Data deletion requirements</header> <subsection id="H1035DA4F057E45A9A26F42A8A119C67C"><enum>(a)</enum><header>Data broker annual registration</header> <paragraph id="H4B1344431F824EBC8B1DA2AC2B7773AD"><enum>(1)</enum><header>In general</header> <subparagraph commented="no" display-inline="no-display-inline" id="H4E5F62F4C19D49F199B5E3E788609CE6"><enum>(A)</enum><header>Regulations</header><text display-inline="yes-display-inline">Not later than 1 year after the date of enactment of this section, the Commission shall promulgate regulations to require any data broker to—</text> 
<clause id="HA9E4AF051F9F4F4D90ACB1097E2B5638"><enum>(i)</enum><text>not later than 18 months after the date of enactment of this section, and annually thereafter, register with the Commission; and</text></clause> <clause id="H9357D81689CC41018761475DC9FCD4F9"><enum>(ii)</enum><text>subject to subparagraph (B), provide with such registration certain information, including—</text> 
<subclause id="HFE9CB1AFDC9B4112BB70E6BD1BFD09B8"><enum>(I)</enum><text>the name and primary physical, email, and uniform resource locator (URL) addresses of the data broker;</text></subclause> <subclause id="HFD06BCC132C846449188ACA66CF03775"><enum>(II)</enum><text>if the data broker permits an individual to opt out of the data broker’s collection or use of personal information, certain sales of such information, or its databases—</text> 
<item id="H4961FFF957D14D3588708A33AB31AB43"><enum>(aa)</enum><text>the method for requesting an opt-out;</text></item> <item id="H48C336DA24A84F1CB030DC854601AF9C"><enum>(bb)</enum><text>any limitations on the type of data collection, uses, or sales for which an individual may opt-out; and </text></item> 
<item id="H3C67B345EC784C26948B61A3F5E6CA76"><enum>(cc)</enum><text>whether the data broker permits an individual to authorize a third party to perform the opt-out on the individual’s behalf;</text></item></subclause> <subclause id="H2B3A5E3FE4404BB2B2CE66566256C51D"><enum>(III)</enum><text>a response to a standardized form (as issued by the Commission) specifying the types of information the data broker collects or obtains and the sources from which the data broker obtains data;</text></subclause> 
<subclause id="H5A6BC83618684CFC98E44C8293FEC871"><enum>(IV)</enum><text>a statement as to whether the data broker implements a credentialing process and, if so, a description of that process;</text></subclause> <subclause id="H6C40C22BE496428F972E35999177822F"><enum>(V)</enum><text>any additional information or explanation the data broker chooses to provide concerning its data collection practices; and</text></subclause> 
<subclause commented="no" id="H1B8B47CD21FF4F33A625D42F20FBDEA8"><enum>(VI)</enum><text>any other information determined appropriate by the Commission.</text></subclause></clause></subparagraph> <subparagraph commented="no" display-inline="no-display-inline" id="HC936940876464B3BB76C199EDD6956A2"><enum>(B)</enum><header>Construction</header><text>Nothing in this paragraph shall be construed as requiring a data broker to disclose any information that is a trade secret or other kind of confidential information described in section 552(b)(4) of title 5, United States Code. </text></subparagraph></paragraph> 
<paragraph id="H6A721063365142ADB68D787EDCFD3727"><enum>(2)</enum><header>Public availability</header> 
<subparagraph id="H03D09C308FE546ED9E18A527E233A269"><enum>(A)</enum><header>In general</header><text>The Commission shall make the information provided pursuant to paragraph (1)(A)(ii) publicly available in a downloadable and machine-readable format, except in the event that the Commission—</text> <clause id="HEBFDE8A66E3B49AA8CBA3BBFB286B1D2"><enum>(i)</enum><text>determines that the risk of making such information available is not in the interest of public safety or welfare; and</text></clause> 
<clause id="HF9CDEF43289F4B19B2B5DE349D0C30DB"><enum>(ii)</enum><text>provides a justification for such determination.</text></clause></subparagraph> <subparagraph id="H27366A7A4598455A9D7B5BEE19507DBC"><enum>(B)</enum><header>Disclaimer</header><text>The Commission shall include on the website of the Commission a disclaimer that—</text> 
<clause id="HB929A2D32DCF413CA2B81D94E9E6EBA4"><enum>(i)</enum><text>the Commission cannot confirm the accuracy of the information provided pursuant to paragraph (1)(A)(ii); and</text></clause> <clause id="HAF1BF02DE3034644BD9F23EA0C42E8B2"><enum>(ii)</enum><text>individuals may contact a data broker who provided such information at their own risk.</text></clause></subparagraph></paragraph></subsection> 
<subsection id="HC70DE28249BB4418ADE6F635E50C4832"><enum>(b)</enum><header>Centralized data deletion system</header> 
<paragraph id="H2556106A70B34F969A8B78B9FEC30D7F"><enum>(1)</enum><header>Establishment</header> 
<subparagraph id="HFF2BEB84DE2D4CF18CE15AB828CEFB96"><enum>(A)</enum><header>In general</header><text>Not later than 1 year after the date of enactment of this section, the Commission shall promulgate regulations to establish a centralized system that—</text> <clause id="HB968726E73474F92BBF6CBA72E967586"><enum>(i)</enum><text>implements and maintains reasonable security procedures and practices (including administrative, physical, and technical safeguards) appropriate to the nature of the information and the purposes for which the personal information will be used, to protect individuals’ personal information from unauthorized use, disclosure, access, destruction, or modification;</text></clause> 
<clause id="HF9A108FD20EE45B38D2B2E15C4D4F80F"><enum>(ii)</enum><text>allows an individual, through a single submission, to request that every data broker who is registered under subsection (a) and who maintains any persistent identifiers (as described in subparagraph (B)(iii))—</text> <subclause commented="no" display-inline="no-display-inline" id="H7E0E41DDF0734070A6686AE7BCEB896A"><enum>(I)</enum><text display-inline="yes-display-inline">delete any personal information related to such individual held by such data broker or affiliated legal entity of the data broker; and</text></subclause> 
<subclause commented="no" display-inline="no-display-inline" id="H94EDD3B69ED0424CB9540458D9F3AB41"><enum>(II)</enum><text>unless otherwise specified by the individual, discontinue any present or future collection of personal information related to such individual; and</text></subclause></clause> <clause id="HD1B62735950B4A248AFC3D5C35B2D191"><enum>(iii)</enum><text>allows a registered data broker, prior to the collection of any personal information that is tied to a persistent identifier for which a registry exists, to submit a query to the centralized system to confirm that the persistent identifier is not subject to a deletion request described in clause (ii).</text></clause></subparagraph> 
<subparagraph id="H83CDB43D441946E0B4A1F023D300B63E"><enum>(B)</enum><header>Requirements</header><text>The centralized system established in subparagraph (A) shall meet the following requirements:</text> <clause id="HEA7CC6029A7D492685ECA32E1A900970"><enum>(i)</enum><text>The centralized system shall allow an individual to request the deletion of all personal information related to such individual and the discontinuation of any collection of such personal information related to such individual through a single deletion request.</text></clause> 
<clause id="H6BE91737E4014FE68419291F13A7A52D"><enum>(ii)</enum><text>The centralized system shall provide a standardized form to allow an individual to make such request.</text></clause> <clause id="H355EE20826B94133892941D2526FB981"><enum>(iii)</enum><text>Such standardized form shall include the individual's email, phone number, physical address, and any other persistent identifier determined by the Commission to aid in the deletion request.</text></clause> 
<clause id="H5F38C9883A3746FEA0E38349D431AB2D"><enum>(iv)</enum><text>The centralized system shall automatically salt and hash all submitted information and allow the Commission to maintain independent hashed registries of each type of information obtained through such form.</text></clause> <clause commented="no" display-inline="no-display-inline" id="H5A5372DEBA7740808301D79ED4BD5ECC"><enum>(v)</enum><text display-inline="yes-display-inline">The centralized system shall only permit data brokers who are registered with the Commission to submit hashed queries to the independent hashed registries described in clause (iv).</text></clause> 
<clause commented="no" display-inline="no-display-inline" id="HB37DEAABDA854B5782D51121C672A4BF"><enum>(vi)</enum><text display-inline="yes-display-inline">With respect to the independent hashed registries described in clause (iv), the salt shall be different for each such registry and shall be made available to all registered data brokers for the purposes of submitting hashed queries, as described in clause (v).</text></clause> <clause commented="no" display-inline="no-display-inline" id="HD60234628AD44496BEFA6768FE8C58BD"><enum>(vii)</enum><text display-inline="yes-display-inline">The centralized system shall allow an individual to make such request using an internet website operated by the Commission.</text></clause> 
<clause commented="no" display-inline="no-display-inline" id="H93663AB21D124A7F900ACACF5F6B9E91"><enum>(viii)</enum><text display-inline="yes-display-inline">The centralized system shall not charge the individual to make such request.</text></clause></subparagraph> <subparagraph id="H5F4513AD95984349880D616828D30C72"><enum>(C)</enum><header>Transition</header> <clause id="H47BD5E95C9EC497FBE8D726F85A7D007"><enum>(i)</enum><header>In general</header><text>Not later than 8 months after the effective date of the regulations promulgated under subparagraph (A), each data broker shall—</text> 
<subclause id="HF1AC7AAD7AAC4060A59444EAF2D0212E"><enum>(I)</enum><text>not less than once every 31 days, access the hashed registries maintained by the Commission as described in subparagraph (B)(iv); and</text></subclause> <subclause id="H7F0937EAB8F74D929806127360FB7907"><enum>(II)</enum><text>process any deletion request associated with a match between such hashed registries and the records of the data broker.</text></subclause></clause> 
<clause id="HF3F38150DF5F4F139B1002E318944EAA"><enum>(ii)</enum><header>FTC guidance</header><text>Not later than 6 months after the effective date of the regulations promulgated under subparagraph (A), the Commission shall publish guidance on the process and standards to which a data broker must adhere in carrying out clause (i).</text></clause></subparagraph></paragraph> <paragraph id="H12B9D413171245F791C9A8E3B1E18080"><enum>(2)</enum><header>Deletion</header> <subparagraph id="H2FD7A4E9EFC44DB0B423C200DE3361C2"><enum>(A)</enum><header>Information deletion</header> <clause id="HEFAB0302CC3E40B3BDF9A9CDCC1DF6EF"><enum>(i)</enum><header>In general</header><text>Subject to clause (ii), not later than 31 days after accessing the hashed registries described in paragraph (1)(B)(iv), a data broker and any associated legal entity shall delete all personal information in its possession related to the individual making the request and discontinue the collection of personal information related to such individual. Immediately following the deletion, the data broker shall send an affirmative representation to the Commission with the number of records deleted pursuant to each match with a value in the hashed registries.</text></clause> 
<clause id="H73D0284B76214DF7A284F3FA03685C7D"><enum>(ii)</enum><header>Exclusions</header><text>In carrying out clause (i), a data broker may retain, where required, the following information:</text> <subclause id="H8F39A27B39A8474085B64B66E512A183"><enum>(I)</enum><text>Any personal information that is processed or maintained solely as part of human subjects research conducted in compliance with any legal requirements for the protection of human subjects.</text></subclause> 
<subclause id="H585F688EB88D421DA724800151059D77"><enum>(II)</enum><text>Any personal information necessary to comply with a warrant, subpoena, court order, rule, or other applicable law.</text></subclause> <subclause id="HD3AC8CE194EA4445A6A4C5213A744EE5"><enum>(III)</enum><text>Any information necessary for an activity described in subsection (f)(3)(B), provided that the retained information is used solely for any such activity. </text></subclause></clause> 
<clause id="HE98056E6DAD44EA2A9A2EECFA7DB6CE6"><enum>(iii)</enum><header>Use of information</header><text>Any personal information excluded under clause (ii) may only be used for the purpose described in the applicable subclause of clause (ii), and may not be used for any other purpose, including marketing purposes.</text></clause></subparagraph> <subparagraph id="HE83C1B59681D4170A3721C3A805CF8EF"><enum>(B)</enum><header>Annual report</header><text>Each data broker registered under subsection (a) shall submit to the Commission, on an annual basis, a report on the completion rate with respect to the completion of deletion requests under subparagraph (A).</text></subparagraph> 
<subparagraph id="H2AEBA735DF414637B455D559DAD3A245"><enum>(C)</enum><header>Audit</header> 
<clause id="HED7EFEAB607F48CC80B9DC24356248D2"><enum>(i)</enum><header>In general</header><text>Not later than 3 years after the date of enactment of this section, and every 3 years thereafter, each data broker registered under subsection (a) shall undergo an independent third party audit to determine compliance with this subsection.</text></clause> <clause id="H645F95F8659040ACBD1E11F12A8AA759"><enum>(ii)</enum><header>Audit report</header><text>Not later than 6 months after the completion of any audit under clause (i), each such data broker shall submit to the Commission any report produced as a result of the audit, along with any related materials.</text></clause> 
<clause id="HA32E117FCC434607A68166DB727B9CF5"><enum>(iii)</enum><header>Maintain records</header><text>Each such data broker shall maintain the materials described in clause (ii) for a period of not less than 6 years.</text></clause></subparagraph></paragraph> <paragraph id="H2DB7E3F588A74A7DB425C78F69F9291D"><enum>(3)</enum><header>Annual fee</header> <subparagraph id="HA7F86DD176C74945B78571AA46717A2A"><enum>(A)</enum><header>In general</header><text>Subject to subparagraph (B), each data broker registered under subsection (a) and who maintains any persistent identifiers (as described in paragraph (1)(B)(iii)) shall pay to the Commission, on an annual basis, a subscription fee determined by the Commission to access the database. </text></subparagraph> 
<subparagraph id="HD5C1B0955DE34C70BA69EF8ADFE50B3F"><enum>(B)</enum><header>Limit</header><text>The amount of the subscription fee under subparagraph (A) may not exceed 1 percent of the expected annual cost of operating the centralized system and hashed registries described in paragraph (1), as determined by the Commission.</text></subparagraph> <subparagraph id="H57C05D01C1274CB6B7F912295DD69C08"><enum>(C)</enum><header>Availability</header><text>Any amounts collected by the Commission pursuant to this paragraph shall be available without further appropriation to the Commission for the exclusive purpose of enforcing and administering this section, including the implementation and maintenance of such centralized system and hashed registries and the promotion of public awareness of the centralized system.</text></subparagraph></paragraph></subsection> 
<subsection id="HD7532BA4E34D4D758E9861057E00502D"><enum>(c)</enum><header>Enforcement by the Commission</header> 
<paragraph id="H43258B6634844A04B171ABF90A91DDC5"><enum>(1)</enum><header>Unfair or deceptive acts or practices</header><text>A violation of subsection (a) or (b) or a regulation promulgated under this section shall be treated as a violation of a rule defining an unfair or deceptive act or practice under section 18(a)(1)(B) of the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/57a">15 U.S.C. 57a(a)(1)(B)</external-xref>).</text></paragraph> <paragraph id="H3476AAB0A25F47B5A47E4A197A8509F2"><enum>(2)</enum><header>Powers of the Commission</header> <subparagraph id="H4446C532B4F14E1F8BE8DCDC9DF20A57"><enum>(A)</enum><header>In general</header><text>The Commission shall enforce this section in the same manner, by the same means, and with the same jurisdiction, powers, and duties as though all applicable terms and provisions of the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/41">15 U.S.C. 41 et seq.</external-xref>) were incorporated into and made a part of this section.</text></subparagraph> 
<subparagraph id="H8D2C4BFC65DB431E9355086795AB6948"><enum>(B)</enum><header>Privileges and immunities</header><text>Any person who violates subsection (a) or (b) or a regulation promulgated under this section shall be subject to the penalties and entitled to the privileges and immunities provided in the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/41">15 U.S.C. 41 et seq.</external-xref>).</text></subparagraph> <subparagraph id="H9C85BB532C4A4ACA8AD973A539A33C62"><enum>(C)</enum><header>Authority preserved</header><text>Nothing in this section shall be construed to limit the authority of the Commission under any other provision of law.</text></subparagraph> 
<subparagraph id="H7308478999384F2CB1E125F33836256F"><enum>(D)</enum><header>Rulemaking</header><text>The Commission shall promulgate in accordance with section 553 of title 5, United States Code, such rules as may be necessary to carry out this section.</text></subparagraph></paragraph></subsection> <subsection id="HB1DB70CB21F9419684D3F0D103A8F0B8"><enum>(d)</enum><header>Study and report</header> <paragraph id="HC85AB61E0EC949628AE15B4A8BA868FB"><enum>(1)</enum><header>Study</header><text display-inline="yes-display-inline">The Commission shall conduct a study on the implementation and enforcement of this section. Such study shall include—</text> 
<subparagraph id="H4672600D98524787AC7974D3CEDB3082"><enum>(A)</enum><text>an analysis of the effectiveness of the centralized system established in subsection (b)(1)(A);</text></subparagraph> <subparagraph id="H63F70AB7CA414B43BC78F4D435336846"><enum>(B)</enum><text>the number deletion requests submitted annually using such centralized system;</text></subparagraph> 
<subparagraph id="H6A7C1BFF6BF249FE88476FC1874C5486"><enum>(C)</enum><text>an analysis of the progress of coordinating the operation and enforcement of such requests with similar systems established and maintained by the various States; and</text></subparagraph> <subparagraph id="H29A8E54DFC1B4AC3A7C4D00403E846E1"><enum>(D)</enum><text>any other area determined appropriate by the Commission.</text></subparagraph></paragraph> 
<paragraph id="H97483F7F125B49D0ABB4920BA7E54D9D"><enum>(2)</enum><header>Report</header><text display-inline="yes-display-inline">Not later than 3 years after the date of enactment of this section, and annually thereafter for each of the next 4 years, the Commission shall submit to the Committee on Commerce, Science, and Transportation of the Senate and the Committee on Energy and Commerce of the House of Representatives a report containing—</text> <subparagraph id="HF7DFDD5DE79D4AA38C81FD4ACB2F6D8C"><enum>(A)</enum><text display-inline="yes-display-inline">the results of the study conducted pursuant to paragraph (1);</text></subparagraph> 
<subparagraph id="HAD53FD387B1F4C39A68E6FE4604E8882"><enum>(B)</enum><text display-inline="yes-display-inline">a summary of any enforcement actions taken pursuant to this Act; and</text></subparagraph> <subparagraph id="H7A8E1DC82BFA438690E4A569A69D93C0"><enum>(C)</enum><text display-inline="yes-display-inline">recommendations for any legislation and administrative action as the Commission determines appropriate.</text></subparagraph></paragraph></subsection> 
<subsection id="H0D13932F47CA45CE9C53D67AB76BD520" commented="no"><enum>(e)</enum><header>Preemption</header> 
<paragraph commented="no" display-inline="no-display-inline" id="HF957F2791574426A93A489756893447A"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">The provisions of this Act shall preempt any State privacy law only to the extent that such State law is inconsistent with the provisions of this Act.</text></paragraph> <paragraph id="HECC57B95D2D547EFB58032DB86D0888A"><enum>(2)</enum><header>Greater protection under State law</header><text>For purposes of paragraph (1), a State privacy law is not inconsistent with the provisions of this Act if the protection such law affords any person is greater than the protection provided under this Act, as determined by the Commission.</text></paragraph></subsection> 
<subsection id="H72C75E573763478287EFAFD4D7815B4E"><enum>(f)</enum><header>Definitions</header><text>In this section:</text> <paragraph id="HEA1FFAB3584846C1BE3C4557626A8003"><enum>(1)</enum><header>Commission</header><text>The term <term>Commission</term> means the Federal Trade Commission.</text></paragraph> 
<paragraph commented="no" id="H52E82F5F15D14DD3A27640F9E751AAC5"><enum>(2)</enum><header>Credentialing process</header><text>The term <term>credentialing process</term> means the practice of taking reasonable steps to confirm—</text> <subparagraph commented="no" id="H298ACD02CF1942CC854CF86AC1CE7FE2"><enum>(A)</enum><text>the identity of the entity with whom the data broker has a direct relationship;</text></subparagraph> 
<subparagraph commented="no" id="HB6345952AE244DDA986418E75E6B00C0"><enum>(B)</enum><text>that any data disclosed to the entity by such data broker will be used for the described purpose of such disclosure; and</text></subparagraph> <subparagraph commented="no" id="HE4B723D22F904BB0A604E87176809422"><enum>(C)</enum><text>that such data will not be used for unlawful purposes.</text></subparagraph></paragraph> 
<paragraph id="HA521498BB7744D76876AB0933B205347"><enum>(3)</enum><header>Data broker</header> 
<subparagraph id="H7359AF0EBF6B42BFB7C413C4854FD879"><enum>(A)</enum><header>In general</header><text>The term <term>data broker</term> means an entity that knowingly collects or obtains the personal information of an individual with whom the entity does not have a direct relationship and then—</text> <clause id="H4104C265C3F64FB1AC560728990E2324"><enum>(i)</enum><text>uses the personal information to perform a service for a third party; or</text></clause> 
<clause id="HE1106E5BB0C44B7DA7CBEE79A15FC970"><enum>(ii)</enum><text>sells, licenses, trades, provides for consideration, or is otherwise compensated for disclosing personal information to a third party.</text></clause></subparagraph> <subparagraph id="H8C6B02006E0D4359949D94AED98BCCC6"><enum>(B)</enum><header>Exclusion</header><text>The term <term>data broker</term> does not include an entity who solely uses, sells, licenses, trades, provides for consideration, or is otherwise compensated for disclosing personal information for 1 or more of the following activities: </text> 
<clause id="H5F49BE2D972942D6BB72DC5D7BEE2A4C"><enum>(i)</enum><text>Providing 411 directory assistance or directory information services, including name, address, and telephone number, on behalf of or as a function of a telecommunications carrier.</text></clause> <clause id="H093B52ACFE3044CBB34E50D1559D81E0"><enum>(ii)</enum><text>Providing an individual's publicly available information if the information is being used by the recipient as it relates to that individual's business or profession.</text></clause> 
<clause id="H89BCA29E9AB340CE9D3EBC27B0EBD0C1"><enum>(iii)</enum><text>Providing personal information to a third party at the express direction of the individual for a clearly disclosed single-use purpose.</text></clause> <clause id="H855F6C5B8D9F42BDB3862A20CDF1269B"><enum>(iv)</enum><text>Providing or using personal information for assessing, verifying, or authenticating an individual's identity, or for investigating or preventing actual or potential fraud.</text></clause> 
<clause id="HC69C3CB90BDA425DA8AFC969E157D78F"><enum>(v)</enum><text>Gathering, preparing, collecting, photographing, recording, writing, editing, reporting, or publishing news or information that concerns local, national, or international events or other matters of public interest (as determined by the Commission) for dissemination to the public.</text></clause> <clause id="H9612F9D9879943F28C6961C7ABE1531B"><enum>(vi)</enum><text display-inline="yes-display-inline">Acting as a consumer reporting agency (as defined in section 603(f) of the Fair Credit Reporting Act (<external-xref legal-doc="usc" parsable-cite="usc/15/1681a">15 U.S.C. 1681a(f)</external-xref>)).</text></clause></subparagraph> 
<subparagraph id="H6D8DE0EABC2248088EB5859F1D597B61"><enum>(C)</enum><header>Exclusion from sale</header> 
<clause id="H5D8E06B417EA4E0D943E95B28304E6E8"><enum>(i)</enum><header>In general</header><text>For purposes of this paragraph, the term <term>sells</term> does not include a one-time or occasional sale of assets of an entity as part of a transfer of control of those assets that is not part of the ordinary conduct of the entity.</text></clause> <clause id="HB91C232CC40F4F47A1A316D9677C655D"><enum>(ii)</enum><header>Notice required</header><text>To meet the exclusion criteria described in clause (i), an entity must provide notice to the Commission, in the manner determined appropriate by the Commission, of any such one-time or occasional sale of assets.</text></clause></subparagraph></paragraph> 
<paragraph commented="no" id="H29827A5D6DA14B77A1525252B0C1B3DF"><enum>(4)</enum><header>Delete</header><text>The term <term>delete</term> means to remove or destroy information such that the information is not maintained in human- or machine-readable form and cannot be retrieved or utilized in such form in the normal course of business.</text></paragraph> <paragraph id="H5D4BD60E1F7249A080B2421EFDEEE1A7"><enum>(5)</enum><header>Direct relationship</header> <subparagraph id="H7578E84FDD104B91A4C759E24E3F8DF3"><enum>(A)</enum><header>In general</header><text>The term <term>direct relationship</term> means a relationship between an individual and an entity where the individual—</text> 
<clause id="HA6BEEBBFC8F547438DD9E6A7741BAFA4"><enum>(i)</enum><text>is a current customer;</text></clause> <clause id="HD273F981F4AD4A859493451216BE6D4A"><enum>(ii)</enum><text>has obtained a good or service from the entity within the prior 18 months; or</text></clause> 
<clause commented="no" display-inline="no-display-inline" id="H27C92A3D23914182A484037DB166464B"><enum>(iii)</enum><text>has made an inquiry about the products or services of the entity within the prior 90 days. </text></clause></subparagraph> <subparagraph commented="no" display-inline="no-display-inline" id="HF22B1F71DC884FBDAA1F4058B0E7B2E8"><enum>(B)</enum><header>Exclusion</header><text>The term <term>direct relationship</term> does not include a relationship—</text> 
<clause commented="no" display-inline="no-display-inline" id="H2CCB8925BDA24FA08957A7A7726CFF89"><enum>(i)</enum><text display-inline="yes-display-inline">between an individual and a data broker where the individual's only connection to the data broker is based on the individual's request—</text> <subclause commented="no" display-inline="no-display-inline" id="HCCF7B2C8CFC14AE5A47426C781AB15A5"><enum>(I)</enum><text>for the data broker to delete the personal information of the individual; or</text></subclause> 
<subclause commented="no" display-inline="no-display-inline" id="H2B9F04AD89A14CCCA02A8759E7544C46"><enum>(II)</enum><text>to opt-out of the data broker’s collection or use of personal information, certain sales of such information, or its databases; or</text></subclause></clause> <clause commented="no" display-inline="no-display-inline" id="H08F77716B59B4DC4958B21AFE7E2704A"><enum>(ii)</enum><text>required under any State or Federal law related to the use of personal information.</text></clause></subparagraph></paragraph> 
<paragraph commented="no" id="H3E7D0C8532454836B06D4EF8B102609D"><enum>(6)</enum><header>Hash</header><text>The term <term>hash</term> means to input data to a cryptographic, one-way, collision resistant function that maps a bit string of arbitrary length to a fixed-length bit string to produce a cryptographically secure value.</text></paragraph> <paragraph commented="no" id="HDBD969C4CD0B47FF90567D31F700CE50"><enum>(7)</enum><header>Hashed</header><text>The term <term>hashed</term> means the type of value produced by hashing data.</text></paragraph> 
<paragraph commented="no" id="H9B34187F5B704E699C1478EB54706DF7"><enum>(8)</enum><header>Human subjects research</header><text>The term <term>human subjects research</term> means research that—</text> <subparagraph commented="no" id="H74A508F7F1AB4CF1A3EC98E5EC8D6B57"><enum>(A)</enum><text>an investigator (whether professional or student) conducts on a living individual; and</text></subparagraph> 
<subparagraph commented="no" id="H4F1AFAFC034349978A871C8D4260F332"><enum>(B)</enum><text>either—</text> <clause commented="no" id="H98FDE1D6C5CB46B2BBC99B312DDD9C64"><enum>(i)</enum><text>obtains information or biospecimens through intervention or interaction with the individual, and uses, studies, or analyzes the information or biospecimens; or</text></clause> 
<clause commented="no" id="H03468EE668794AA8B43AF88A93BBD455"><enum>(ii)</enum><text>obtains, uses, studies, analyzes, or generates personal information or identifiable biospecimens.</text></clause></subparagraph></paragraph> <paragraph id="HEC3A7C3CA35E43A29475BEB7B5DE972A"><enum>(9)</enum><header>Personal information</header> <subparagraph id="HB85180C7B2CA4C46B13D393F2884E7C7"><enum>(A)</enum><header>In general</header><text>The term <term>personal information</term> means any information held by a data broker, regardless of how the information is collected, inferred, created, or obtained, that is linked or reasonably linkable by the data broker to a particular individual or consumer device, including the following:</text> 
<clause id="H46C087D3C7B148C7ABAB7D144B9C4B6F"><enum>(i)</enum><text>Financial information, including any bank account number, credit card number, debit card number, or insurance policy number.</text></clause> <clause id="HA178E5858FB94F6396E78BBC5E7909C4"><enum>(ii)</enum><text>A name, alias, home or other physical address, online identifier, Internet Protocol address, email address, phone number, account name, State identification card number, driver's license number, passport number, or an identifying number on a government-issued identification.</text></clause> 
<clause id="H95175D67C037401DB2A95A3AC1025DB2"><enum>(iii)</enum><text>Geolocation information.</text></clause> <clause id="H25356B241AF44428A50A50DC0AEF738F"><enum>(iv)</enum><text>Biometric information.</text></clause> 
<clause id="H9F20DF8F6AB14D98898E39CAF6C5F196"><enum>(v)</enum><text>The contents of, attachments to, or parties to information, including with respect to email, text messages, picture messages, voicemails, audio conversations, or video conversations.</text></clause> <clause id="HFCF8E8B66EFB4573817A12D02768988B"><enum>(vi)</enum><text>Web browsing history, including any search query.</text></clause> 
<clause id="HBB293A847A3B47238A0AA5A5ABD9281F"><enum>(vii)</enum><text>Genetic sequencing information.</text></clause> <clause id="HBA6354A264BE40EC8CCD52780BB364AE"><enum>(viii)</enum><text>A device identifier, online identifier, persistent identifier, or digital fingerprinting information.</text></clause> 
<clause id="H91007F29F7AF443DB24B8C5C90426575"><enum>(ix)</enum><text>Any inference drawn from any of the information described in this paragraph that is used to create a profile about an individual that reflects such individual's preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, or aptitudes.</text></clause> <clause id="HC27D09B65F05447BB12E7597EC3C8DC3"><enum>(x)</enum><text>Any other information determined appropriate by the Commission.</text></clause></subparagraph> 
<subparagraph id="HBA3B266271674324BBAAA57F625D438D"><enum>(B)</enum><header>Linked or reasonably linkable</header><text>For purposes of subparagraph (A), information is <quote>linked or reasonably linkable</quote> to a particular individual or consumer device if the information can be used on its own or in combination with other information held by or readily accessible to a data broker to identify a particular individual or consumer device.</text></subparagraph></paragraph> <paragraph id="HA5DD8F41C0D94AD3BD294E4C0515AEA5"><enum>(10)</enum><header>Process</header><text>The term <term>process</term> means to perform or direct the performance of an operation on personal information, including the collection, transmission, use, disclosure, analysis, prediction, or modification of such personal information, whether or not by automated means.</text></paragraph> 
<paragraph commented="no" display-inline="no-display-inline" id="HE9F56EC5B26D4B85B4827E68DEEA9FF3"><enum>(11)</enum><header>Salt</header><text>The term <term>salt</term> means to add a random string of data to the input of a hash function.</text></paragraph> <paragraph id="HBE09A2B795914858A9F507026BD20C81"><enum>(12)</enum><header>Uniform resource locator; URL</header><text>The term <term>uniform resource locator</term> or <term>URL</term> means a short string containing an address that refers to an object on the web.</text></paragraph></subsection></section> 
</legis-body></bill>

