<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-type="olc" bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-RIL23082-3H2-CM-LT0"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>118 S2225 IS: Terms-of-service Labeling, Design, and Readability Act</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2023-07-11</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>118th CONGRESS</congress><session>1st Session</session><legis-num>S. 2225</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20230711">July 11, 2023</action-date><action-desc><sponsor name-id="S373">Mr. Cassidy</sponsor> (for himself and <cosponsor name-id="S409">Mr. Luján</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSCM00">Committee on Commerce, Science, and Transportation</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To require covered entities to issue a short-form terms of service summary statement, and for other purposes.</official-title></form><legis-body style="OLC" display-enacting-clause="yes-display-enacting-clause" id="HD4844C1580B84270A7ECB2CF31ECAF39"><section section-type="section-one" id="H1379C8B251EC49DA8BF5B7F16BA52430"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Terms-of-service Labeling, Design, and Readability Act</short-title></quote> or the <quote><short-title>TLDR Act</short-title></quote>.</text></section><section id="HEE73C598BED649DB8D39DD8C7CD05043"><enum>2.</enum><header>Standard terms of service summary statement</header><subsection id="H8379078709BF42AD8304B850FA8F16E7"><enum>(a)</enum><header>Deadline for terms of service summary statement</header><text display-inline="yes-display-inline">Not later than 360 days after the date of the enactment of this Act, the Commission shall issue a rule under section 553 of title 5, United States Code, with regard to a covered entity that publishes or has published a terms of service—</text><paragraph id="H38E52096261147C4B798D38E98687666"><enum>(1)</enum><text display-inline="yes-display-inline">that requires the covered entity to include a truthful and non-misleading short-form terms of service summary statement on the website of the entity;</text></paragraph><paragraph id="HF21A7F30EEBB448E9D38FE3F03F2F7B8"><enum>(2)</enum><text display-inline="yes-display-inline">that requires the covered entity to include a truthful and non-misleading graphic data flow diagram on the website of the entity; and</text></paragraph><paragraph id="HEDA0E097749642469E1957AECEFFE5F7"><enum>(3)</enum><text display-inline="yes-display-inline">that requires the covered entity to display the full terms of service of the entity in an interactive data format.</text></paragraph></subsection><subsection id="H1679484914B249278FB4D69CAD8CF059"><enum>(b)</enum><header>No New Contractual Obligation</header><text display-inline="yes-display-inline">The requirement to include a summary statement described in subsection (a)(1) does not create any new contractual obligation.</text></subsection><subsection id="HFB307A7CE85F4A89B805E20DF14A9CBB"><enum>(c)</enum><header>Requirements for short-Form terms of service summary statement</header><paragraph id="H3DE06129B8554C07B893B617BC556752"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">The short-form terms of service summary statement described in subsection (a)(1)—</text><subparagraph id="H61B3D3D10C774A8C9D1DF60E95815A2F"><enum>(A)</enum><text display-inline="yes-display-inline">shall be accessible to individuals with low levels of literacy and individuals with disabilities, be machine readable, and include tables, graphic icons, hyperlinks, or other means as the Commission may require; and</text></subparagraph><subparagraph id="HBBEEB37C306C4A4C9ACB916D0D5ADCBA"><enum>(B)</enum><text display-inline="yes-display-inline">may be presented differently depending on the interface or type of device on which the statement is being accessed by the user.</text></subparagraph></paragraph><paragraph display-inline="no-display-inline" id="H08408CFAD13E4E19AAF33C08216E9F6D"><enum>(2)</enum><header>Location of summary statement and graphic data flow diagram</header><text display-inline="yes-display-inline">The summary statement described in subsection (a)(1) shall be placed at the top of the permanent terms of service page of the covered entity, and the graphic data flow diagram described in subsection (a)(2) shall be located immediately below such summary statement. </text></paragraph><paragraph id="H850B34AC36B74958BCC692C88D0118CA"><enum>(3)</enum><header>Contents of summary statement</header><text display-inline="yes-display-inline">The summary statement described in subsection (a)(1) shall include the following:</text><subparagraph id="HC76A6726E0E94379AAF35B50BD98F26D"><enum>(A)</enum><text>The categories of sensitive information that the covered entity processes.</text></subparagraph><subparagraph id="HD916468B8FA64D9985F01FD17E80BA7E"><enum>(B)</enum><text display-inline="yes-display-inline">The sensitive information that is required for the basic functioning of the service and what sensitive information is needed for additional features and future feature development.</text></subparagraph><subparagraph id="H5886011914C846539FD4F248E0319329"><enum>(C)</enum><text display-inline="yes-display-inline">A summary of the legal liabilities of a user and any rights transferred from the user to the covered entity, such as mandatory arbitration, class action waiver, any licensing or sale by the covered entity of the content of the user, and any waiver of moral rights.</text></subparagraph><subparagraph id="H437BE418C66F4470A8240A40187870B0"><enum>(D)</enum><text>Historical versions of the terms of service and change logs.</text></subparagraph><subparagraph id="H9723DDEA7F8B4CDD96CA10D8D2D6A74F"><enum>(E)</enum><text display-inline="yes-display-inline">If the covered entity provides user deletion services, directions for how the user can delete sensitive information or discontinue the use of sensitive information.</text></subparagraph><subparagraph id="H4F2DA037D95A4AE4820CEF125210E5E9"><enum>(F)</enum><text>A list of data breaches from the previous 3 years reported to consumers under existing Federal and State laws.</text></subparagraph><subparagraph id="HFE1A843B92DB4BD3802635423AAFBF7D"><enum>(G)</enum><text>The effort required by a user to read the entire terms of service text, such as through the total word count and approximate time to read the statement.</text></subparagraph><subparagraph commented="no" id="H94BC85A4498A40EFB811BE51BEF497E9"><enum>(H)</enum><text display-inline="yes-display-inline">Any other information the Commission determines to be necessary if that information is included in the terms of service by the covered entity.</text></subparagraph></paragraph><paragraph commented="no" id="H4F0DC55D82974E9197D76599CC7ECD4F"><enum>(4)</enum><header>Additional information required by the Commission</header><text>In the rule issued under subsection (a), the Commission shall include a list of other information the Commission determines to be necessary under paragraph (3)(H).</text></paragraph></subsection><subsection id="HE69D036C0D7B4E25A17AFD528367BDD0"><enum>(d)</enum><header>Guidance on graphic data flow diagrams</header><text display-inline="yes-display-inline">Not later than 360 days after the date of the enactment of this Act, the Commission shall publish guidelines on how a covered entity can graphically display how the sensitive information of a user is shared with a subsidiary or corporate affiliate of such entity and how such sensitive information is shared with third parties.</text></subsection><subsection commented="no" id="H9EA264AF1C454DFD86B865A36F50D2BA"><enum>(e)</enum><header>Interactive data format terms of service</header><text>Not later than 360 days after the date of the enactment of this Act, the Commission shall issue a rule under section 553 of title 5, United States Code, that requires a covered entity to tag portions of the terms of services of the entity according to an interactive data format.</text></subsection><subsection id="H1B961A98D7EC4ADBAD47D3ACAF7F6496"><enum>(f)</enum><header>Enforcement</header><paragraph commented="no" display-inline="no-display-inline" id="id6781161659b94efe83615d51187c3216"><enum>(1)</enum><header display-inline="yes-display-inline">Enforcement by the Commission</header><subparagraph id="HB8EF4DE33F834147B3D2CDA7E3AF23CA"><enum>(A)</enum><header>Unfair or deceptive acts or practices</header><text>A violation of this Act or a regulation promulgated under this Act shall be treated as a violation of a rule defining an unfair or deceptive act or practice under section 18(a)(1)(B) of the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/57a">15 U.S.C. 57a(a)(1)(B)</external-xref>).</text></subparagraph><subparagraph id="H326D94E55F7E49E48873558B2CAD3DEA"><enum>(B)</enum><header>Powers of the Commission</header><clause commented="no" display-inline="no-display-inline" id="ida0e499175801474ca0203395c161496c"><enum>(i)</enum><header>In general</header><text display-inline="yes-display-inline">The Commission shall enforce this section and the regulations promulgated under this section in the same manner, by the same means, and with the same jurisdiction, powers, and duties as though all applicable terms and provisions of the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/41">15 U.S.C. 41 et seq.</external-xref>) were incorporated into and made a part of this section. </text></clause><clause commented="no" display-inline="no-display-inline" id="idaf97f2bb1f83407ba395d75c2cae5b5e"><enum>(ii)</enum><header>Privileges and immunities</header><text display-inline="yes-display-inline">Any person who violates this section or a regulation promulgated under this section shall be subject to the penalties and entitled to the privileges and immunities provided in the Federal Trade Commission Act. </text></clause><clause commented="no" display-inline="no-display-inline" id="id7e4ca9bbfd684647be68808bb21f1603"><enum>(iii)</enum><header>Authority persevered</header><text>Nothing in this section shall be construed to limit the authority of the Commission under any other provision of law.</text></clause></subparagraph></paragraph><paragraph commented="no" id="HEA768747151A4A78BC1C1CD40A642589"><enum>(2)</enum><header>Enforcement by States</header><subparagraph commented="no" display-inline="no-display-inline" id="idcd74232bf38b44eda81fcb83668f3a88"><enum>(A)</enum><header>In general</header><text display-inline="yes-display-inline">In any case in which the attorney general of a State has reason to believe that an interest of at least 1,000 residents of that State has been or is threatened or adversely affected by the engagement of any person in a practice that violates this section or a regulation promulgated under this section, the attorney general of the State, as parens patriae, may bring a civil action on behalf of the residents of the State in a district court of the United States of appropriate jurisdiction—</text><clause commented="no" id="H60733D52FC684BE3A080B2ED3370054E"><enum>(i)</enum><text>to enjoin that practice;</text></clause><clause commented="no" id="H78930A8DA52641E9957122B328B22429"><enum>(ii)</enum><text>to enforce compliance with this section;</text></clause><clause commented="no" id="H3E9B1B3F432A427F86D860F9C9E1BB0C"><enum>(iii)</enum><text>to obtain damages, restitution, or other compensation on behalf of such residents; and</text></clause><clause commented="no" id="HB8BC732769C64ED7B0F1503EA0B0C523"><enum>(iv)</enum><text>to obtain such other relief as the court may consider to be appropriate.</text></clause></subparagraph><subparagraph commented="no" id="H40AC63ABDB644CEF83C88A5466647D4E"><enum>(B)</enum><header>Rights of the Commission</header><clause commented="no" display-inline="no-display-inline" id="id6a6a0f8945ab4a36b9edc2dd70665044"><enum>(i)</enum><header display-inline="yes-display-inline">Notice to the Commission</header><subclause commented="no" id="H518EEEE03311426E832E2E703155530C"><enum>(I)</enum><header>In general</header><text>Except as provided in subclause (III), the attorney general of a State shall notify the Commission in writing that the attorney general intends to bring a civil action under subparagraph (A) before initiating the civil action. </text></subclause><subclause commented="no" display-inline="no-display-inline" id="idf455d8f66526452394bfcf3ebf7b05c5"><enum>(II)</enum><header>Contents</header><text>The notification required by subclause (I) with respect to a civil action shall include a copy of the complaint to be filed to initiate the civil action.</text></subclause><subclause commented="no" id="H1746AE2F8C094FA8AD415C23AAF5B860"><enum>(III)</enum><header>Exemption</header><text>If it is not feasible for the attorney general of a State to provide the notification required by subclause (I) before initiating a civil action under subparagraph (A), the attorney general shall notify the Commission immediately upon instituting the civil action. </text></subclause></clause><clause id="H9D0648FD6CBD41EEAB9DD96055EC7CA8"><enum>(ii)</enum><header>Intervention by the Commission</header><text>The Commission may—</text><subclause commented="no" display-inline="no-display-inline" id="id3b1f32783c8e4851b65b73f2dfa9ca00"><enum>(I)</enum><text display-inline="yes-display-inline">intervene in any civil action brought by the attorney general of a State under subparagraph (A); and</text></subclause><subclause commented="no" display-inline="no-display-inline" id="id743929bce3fc4c62bacd59888cfa99b8"><enum>(II)</enum><text>upon intervening—</text><item commented="no" display-inline="no-display-inline" id="id073d82b42f7749439cbad684f61204a2"><enum>(aa)</enum><text display-inline="yes-display-inline">be heard on all matters arising in the civil action; and</text></item><item commented="no" display-inline="no-display-inline" id="id91ad0dd499df4bc29c6073837f897913"><enum>(bb)</enum><text>file petitions for appeal.</text></item></subclause></clause></subparagraph><subparagraph id="HED7E36AEBF9C4CDBA30310925FDF05BC"><enum>(C)</enum><header>Construction</header><text>Nothing in this paragraph may be construed to prevent an attorney general of a State from exercising the powers conferred on the attorney general by the laws of that State to—</text><clause id="HB752099F858B4D1DB3AB7EE7640C6E1C"><enum>(i)</enum><text>conduct investigations;</text></clause><clause id="H48CAE67CF45D40778263E4F1925E849F"><enum>(ii)</enum><text>administer oaths or affirmations; or</text></clause><clause id="H318BD144F7644DCBA83A3BD1AD641624"><enum>(iii)</enum><text>compel the attendance of witnesses or the production of documentary and other evidence.</text></clause></subparagraph><subparagraph id="HDA83FC2D96CB4252A90E98929582AD81"><enum>(D)</enum><header>Actions by the Commission</header><text>In any case in which an action is instituted by or on behalf of the Commission for a violation of this section or a regulation promulgated under this section, a State may not, during the pendency of that action, institute a separate action under subparagraph (A) against any defendant named in the complaint in the action instituted by or on behalf of the Commission for that violation.</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id4d5e23b79ae741e98e580d56ab12b8dd"><enum>(E)</enum><header>Venue; Service of process</header><clause commented="no" display-inline="no-display-inline" id="id93180b46a019471a88e148a6f867dfba"><enum>(i)</enum><header display-inline="yes-display-inline">Venue</header><text>Any action brought under subparagraph (A) may be brought in—</text><subclause commented="no" display-inline="no-display-inline" id="id7953497863b94e5b94a525d0f0b99783"><enum>(I)</enum><text display-inline="yes-display-inline">the district court of the United States that meets applicable requirements relating to venue under section 1391 of title 28, United States Code; or</text></subclause><subclause commented="no" display-inline="no-display-inline" id="id6601d72a5390402fbf8338b62e996fec"><enum>(II)</enum><text display-inline="yes-display-inline">another court of competent jurisdiction.</text></subclause></clause><clause commented="no" display-inline="no-display-inline" id="idc7cc30d5091b4c91b687e1c84a1a5803"><enum>(ii)</enum><header>Service of process</header><text display-inline="yes-display-inline">In an action brought under paragraph (1), process may be served in any district in which the defendant—</text><subclause commented="no" display-inline="no-display-inline" id="ide921b09684bc4a6bbb8531f4fb63404d"><enum>(I)</enum><text display-inline="yes-display-inline">is an inhabitant; or</text></subclause><subclause commented="no" display-inline="no-display-inline" id="id259285b719694ce8ae0d1573a26f152c"><enum>(II)</enum><text display-inline="yes-display-inline">may be found.</text></subclause></clause></subparagraph></paragraph></subsection><subsection id="H71E94137AB834E2A965A5037E0931EF7"><enum>(g)</enum><header>Definitions</header><text>In this section:</text><paragraph id="H31DF57B165EA4411932DF5C4572301B7"><enum>(1)</enum><header>Commission</header><text>The term <term>Commission</term> means the Federal Trade Commission.</text></paragraph><paragraph commented="no" id="H144B3676E6454F388A0F1193C8D7586E"><enum>(2)</enum><header>Covered entity</header><text display-inline="yes-display-inline">The term <term>covered entity</term>—</text><subparagraph commented="no" id="HDE11BD62FCDC4295A277F093E565718B"><enum>(A)</enum><text display-inline="yes-display-inline">means any person that operates a website located on the internet or an online service that is operated for commercial purposes; and</text></subparagraph><subparagraph commented="no" id="H973D2569123A415F9F171039E46C79C1"><enum>(B)</enum><text>does not include a small business concern (as defined in section 3 of the Small Business Act (<external-xref legal-doc="usc" parsable-cite="usc/15/632">15 U.S.C. 632</external-xref>)).</text></subparagraph></paragraph><paragraph id="H475A1E9D9C7E4EC38F819313825A5148"><enum>(3)</enum><header>Disability</header><text display-inline="yes-display-inline">The term <term>disability</term> has the meaning given the term in section 3 of the Americans with Disabilities Act of 1990 (<external-xref legal-doc="usc" parsable-cite="usc/42/12102">42 U.S.C. 12102</external-xref>).</text></paragraph><paragraph commented="no" id="H212A4BC293434E7BBF5375A4CBA14C32"><enum>(4)</enum><header>Interactive data format</header><text display-inline="yes-display-inline">The term <term>interactive data format</term> means an electronic data format in which pieces of information are identified using an interactive data standard, such as eXtensible Markup Language (commonly known as <quote>XML</quote>), that is a standardized list of electronic tags that mark the information described in subsection (c)(3) within the terms of service of a covered entity.</text></paragraph><paragraph id="H989E74429C1E426FA80730BD5E0DCD59"><enum>(5)</enum><header>Moral rights</header><text display-inline="yes-display-inline">The term <term>moral rights</term> means the rights conferred by section 106A(a) of title 17, United States Code.</text></paragraph><paragraph id="H3A68693D31D443539EC86E7B86B93176"><enum>(6)</enum><header>Process</header><text display-inline="yes-display-inline">The term <term>process</term> means any operation or set of operations performed on sensitive information, including collection, analysis, organization, structuring, retaining, using, or otherwise handling sensitive information. </text></paragraph><paragraph id="H1F7995D10D0948B2BC7DC55C7B6E4BB6"><enum>(7)</enum><header>Sensitive information</header><text>The term <term>sensitive information</term> means any of the following:</text><subparagraph id="HEDAF7DC9B6DF4ED58CA9C4F733A4A949"><enum>(A)</enum><text>Health information.</text></subparagraph><subparagraph id="H80556DA8FA4F4038AFAB14757512CBBE"><enum>(B)</enum><text>Biometric information.</text></subparagraph><subparagraph id="H8B37EB399BCB44B7BEA3286077D86720"><enum>(C)</enum><text>Precise geolocation information.</text></subparagraph><subparagraph id="H487FC6B8AF924BF48AD1BE85F2A30B98"><enum>(D)</enum><text>Social security number.</text></subparagraph><subparagraph id="H1B0F24BA98D64E39B932C49CD1606560"><enum>(E)</enum><text>Information concerning the race, color, religion, national origin, sex, age, or disability of an individual.</text></subparagraph><subparagraph id="HE3E6650150AF44999FCFC8A70E9C22B1"><enum>(F)</enum><text>The content and parties to a communication.</text></subparagraph><subparagraph id="H0067AB9D5C83437A9467C555334917E2"><enum>(G)</enum><text>Audio and video recordings captured through a consumer device.</text></subparagraph><subparagraph id="H496865B10E944E3CB4D17F886DE04CC0"><enum>(H)</enum><text>Financial information, including a bank account number, credit card number, debit card number, or insurance policy number.</text></subparagraph><subparagraph id="HCA01F05AA1E448E787CD45B2A4A037FA"><enum>(I)</enum><text display-inline="yes-display-inline">Online browsing history, which means information revealing online activities over time or across websites or online services not owned or operated by the covered entity.</text></subparagraph></paragraph><paragraph commented="no" id="HBCF73DD9ECF44563BA01D96D9058DA58"><enum>(8)</enum><header>State</header><text display-inline="yes-display-inline">The term <term>State</term> means each of the several States, the District of Columbia, each commonwealth, territory, or possession of the United States, and each Federally recognized Indian Tribe. </text></paragraph><paragraph commented="no" id="H47DB34D9FAFD4E9C98F002F0802D21C3"><enum>(9)</enum><header>Third party</header><text>The term <term>third party</term> means, with respect to a covered entity, a person—</text><subparagraph commented="no" id="HCFFD13D24B164D7D9E1E62F5BE4031C4"><enum>(A)</enum><text>to which the covered entity disclosed sensitive information; and</text></subparagraph><subparagraph commented="no" id="HF808014537AF42AB890A312206807CA6"><enum>(B)</enum><text>that is not—</text><clause commented="no" id="H424747D4EB794CF4B5D33ED3318352C1"><enum>(i)</enum><text>the covered entity;</text></clause><clause commented="no" id="H9CF2510CB0234EC0850D33C0FE942EDE"><enum>(ii)</enum><text>a subsidiary or corporate affiliate of the covered entity; or</text></clause><clause commented="no" id="HE7A0B94649A14E1A82F283EF0DF3B7AE"><enum>(iii)</enum><text>a service provider of the covered entity.</text></clause></subparagraph></paragraph></subsection></section></legis-body></bill> 

