<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-type="olc" bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-EHF23637-R7G-CY-N6F"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>118 S2230 IS: Protecting Investors’ Personally Identifiable Information Act</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2023-07-11</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>118th CONGRESS</congress><session>1st Session</session><legis-num>S. 2230</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20230711">July 11, 2023</action-date><action-desc><sponsor name-id="S389">Mr. Kennedy</sponsor> (for himself, <cosponsor name-id="S343">Mr. Boozman</cosponsor>, <cosponsor name-id="S347">Mr. Moran</cosponsor>, <cosponsor name-id="S374">Mr. Cotton</cosponsor>, <cosponsor name-id="S375">Mr. Daines</cosponsor>, <cosponsor name-id="S416">Mrs. Britt</cosponsor>, <cosponsor name-id="S381">Mr. Rounds</cosponsor>, and <cosponsor name-id="S412">Mr. Tuberville</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSBK00">Committee on Banking, Housing, and Urban Affairs</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To prohibit the Securities and Exchange Commission from requiring that personally identifiable information be collected under consolidated audit trail reporting requirements, and for other purposes.</official-title></form><legis-body style="OLC" display-enacting-clause="yes-display-enacting-clause" id="H59D0B08A001D4DB78E171C5FB4B0A32F"><section section-type="section-one" id="H604C3934C2E64277A735C11CC0AD1216"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Protecting Investors’ Personally Identifiable Information Act</short-title></quote>. </text></section><section id="HBDD5BACE1B754C8B8A4AFE26FBC70A1C"><enum>2.</enum><header>Personally identifiable information excluded from consolidated audit trail reporting requirements</header><subsection id="HBD19B255349D4E19BDC0B28BDB33A5C9"><enum>(a)</enum><header>Definitions</header><text display-inline="yes-display-inline">In this section: </text><paragraph commented="no" display-inline="no-display-inline" id="id4e4e15290eb74c13805b6cb512ea0784"><enum>(1)</enum><header>Commission</header><text>The term <term>Commission</term> means the Securities and Exchange Commission.</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id271976ac49b04a0c94c1f3884e66ee64"><enum>(2)</enum><header>Personally identifiable information</header><text display-inline="yes-display-inline">The term <term>personally identifiable information</term>—</text><subparagraph id="H77D6D1D7F3DF402AB38A6706919353D5"><enum>(A)</enum><text display-inline="yes-display-inline">means information that can be used to distinguish or trace the identity of an individual, either alone or when combined with other personal or identifying information that is linked or linkable to that individual, including the name, address, date or year of birth, Social Security number, telephone number, email address, or IP-address of the individual; and</text></subparagraph><subparagraph id="HBF8D79780A924A3D9EF521167D11A99E" commented="no" display-inline="no-display-inline"><enum>(B)</enum><text display-inline="yes-display-inline">does not include a CAT-Order-ID or CAT-Reporter-ID, as those terms are defined in section 242.613(j) of title 17, Code of Federal Regulations, or any successor regulation. </text></subparagraph></paragraph></subsection><subsection id="HF677037CAF2F4028A86246110C713105"><enum>(b)</enum><header>Prohibition</header><text display-inline="yes-display-inline">Except as provided in subsection (c), the Commission may not require a national securities exchange, a national securities association, or a member of such an exchange or association to provide personally identifiable information with respect to a market participant to meet the requirements relating to an order or a reportable event under section 242.613(c)(7) of title 17, Code of Federal Regulations, or any successor regulation. </text></subsection><subsection id="H19355C30B13744DC85F7B2D63F5180FA"><enum>(c)</enum><header>Exception</header><text display-inline="yes-display-inline">The Commission may only require a national securities exchange, a national securities association, or a member of such an exchange or association to provide personally identifiable information with respect to a market participant, as described in subsection (b), if—</text><paragraph id="HDDC89AD600B14641861CB676387F9C87"><enum>(1)</enum><text>the Commission makes a request for that information; and</text></paragraph><paragraph id="HA47FC1F89C8B481C947E0920E75AD803"><enum>(2)</enum><text display-inline="yes-display-inline">the information is related to an investigation of— </text><subparagraph commented="no" display-inline="no-display-inline" id="ide98d651e6c9742b688e6bc12347dbee0"><enum>(A)</enum><text display-inline="yes-display-inline">a violation of the Federal securities laws or a regulation issued under the Federal securities laws; or </text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id73010791e5324eab9a279e85e40dfade"><enum>(B)</enum><text display-inline="yes-display-inline">an enforcement action with respect to a violation described in subparagraph (A).</text></subparagraph></paragraph></subsection><subsection id="HD2BED1AA526D482B8AF50CC2109C6AA2"><enum>(d)</enum><header>Request for extension</header><text display-inline="yes-display-inline">At the request of the Commission under subsection (c), a national securities exchange, a national securities association, or a member of such an exchange or association shall provide the personally identifiable information subject to that request not later than 24 hours after receiving that request, unless, at the request of that national securities exchange, national securities association, or member, the Commission provides a reasonable extension.</text></subsection><subsection id="H8B097D6AFB9E48C1968165326264FCDC"><enum>(e)</enum><header>Destruction of personally identifiable information</header><text>In the case of personally identifiable information provided to the Commission under subsection (c), the Commission shall destroy that information not later than 1 day after the conclusion of the investigation or other matter for which that information was required. </text></subsection></section></legis-body></bill> 

