<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-LYN23691-VYG-4F-9M2"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>118 S3191 IS: Mitigating Automated Internet Networks for Event Ticketing Act</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2023-11-01</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>118th CONGRESS</congress><session>1st Session</session><legis-num>S. 3191</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20231101">November 1, 2023</action-date><action-desc><sponsor name-id="S396">Mrs. Blackburn</sponsor> (for herself and <cosponsor name-id="S409">Mr. Luján</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSCM00">Committee on Commerce, Science, and Transportation</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To improve online ticket sales and protect consumers, and for other purposes.</official-title></form><legis-body><section id="S1" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Mitigating Automated Internet Networks for Event Ticketing Act</short-title></quote> or the <quote><short-title>MAIN Event Ticketing Act</short-title></quote>.</text></section><section commented="no" display-inline="no-display-inline" id="id51c158fa13ca4bda92e17f4aad5bf9a8"><enum>2.</enum><header>Strengthening the BOTS Act</header><subsection commented="no" display-inline="no-display-inline" id="id80c4bd1d23c143449c663c87c19973ce"><enum>(a)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">Section 2 of the Better Online Ticket Sales Act of 2016 (<external-xref legal-doc="usc" parsable-cite="usc/15/45c">15 U.S.C. 45c</external-xref>) is amended—</text><paragraph commented="no" display-inline="no-display-inline" id="id798f8949f2674db7a393432f96339186"><enum>(1)</enum><text display-inline="yes-display-inline">in subsection (a)(1)—</text><subparagraph commented="no" display-inline="no-display-inline" id="id8a1c8d77a48644039560b4233dc2f1b1"><enum>(A)</enum><text>in subparagraph (A), by striking <quote>; or</quote> and inserting a semicolon;</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id3217aa9bd0274fbdacc7315d13688a3a"><enum>(B)</enum><text>in subparagraph (B), by striking the period at the end and inserting <quote>; or</quote>; and</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id32150b8edb6d437598435163c463a52e"><enum>(C)</enum><text>by adding at the end the following new subparagraph:</text><quoted-block id="idB0259DD261B64F739BA94E0069E53C9C" style="OLC" act-name=""><subparagraph id="id31B2E27476FE414D9AA44DE9CBB08240"><enum>(C)</enum><text>to use or cause to be used an application that performs automated tasks to purchase event tickets from an Internet website or online service in circumvention of posted online ticket purchasing order rules of the Internet website or online service, including a software application that circumvents an access control system, security measure, or other technological control or measure.</text></subparagraph><after-quoted-block>;</after-quoted-block></quoted-block></subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id307a7aa720d94dcbb2ef1785cc7755d5"><enum>(2)</enum><text display-inline="yes-display-inline">by redesignating subsections (b) and (c) as subsections (c) and (d), respectively;</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="idb6ae544abd924301ad11b48942e57f40"><enum>(3)</enum><text>by inserting after subsection (a) the following new subsection:</text><quoted-block style="OLC" display-inline="no-display-inline" id="idDA14995B823E4343ACD8E37950514937"><subsection commented="no" display-inline="no-display-inline" id="id9B85370B00EA49DD8A584884830D076B"><enum>(b)</enum><header>Requiring online ticket issuers To put in place site policies and establish safeguards To protect site security</header><paragraph commented="no" display-inline="no-display-inline" id="idA7403EF70EA441938AD991F7C16F4BEB"><enum>(1)</enum><header>Requirement to enforce site policies</header><text>Each ticket issuer that owns or operates an Internet website or online service that facilitates or executes the sale of event tickets shall ensure that such website or service has in place an access control system, security measure, or other technological control or measure to enforce posted event ticket purchasing limits.</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id4446C9AAA165487C9FF57D3A62C74C1B"><enum>(2)</enum><header>Requirement to establish site security safeguards</header><subparagraph commented="no" display-inline="no-display-inline" id="idBC59B4A9649446EBA8F5DB4D74C3EA8A"><enum>(A)</enum><header>In general</header><text>Each ticket issuer that owns or operates an Internet website or online service that facilitates or executes the sale of event tickets shall establish, implement, and maintain reasonable administrative, technical, and physical safeguards to protect the security, confidentiality, integrity, or availability of the website or service. </text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id4D74284E8BA64D8CAF9D54208E56D89C"><enum>(B)</enum><header>Considerations</header><text>In establishing the safeguards described in subparagraph (A), each ticket issuer described in such paragraph shall consider—</text><clause id="ida8e6c84a12b846e9afe1edc1bfd1a06c"><enum>(i)</enum><text>the administrative, technical, and physical safeguards that are appropriate to the size and complexity of the ticket issuer; </text></clause><clause commented="no" display-inline="no-display-inline" id="id0224febd2ee74a0090d7c568eec9e486"><enum>(ii)</enum><text display-inline="yes-display-inline">the nature and scope of the activities of the ticket issuer;</text></clause><clause commented="no" display-inline="no-display-inline" id="idc67f2e6b7e9f4efba99e68b54136abea"><enum>(iii)</enum><text display-inline="yes-display-inline">the sensitivity of any customer information at issue; and</text></clause><clause id="id128CF584805A4FC3BE7FA7DE66872BCF"><enum>(iv)</enum><text>the range of security risks and vulnerabilities that are reasonably foreseeable or known to the ticket issuer.</text></clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idA4D86940021A4C7B82386968BDDFFA68"><enum>(C)</enum><header>Third parties and service providers</header><clause commented="no" display-inline="no-display-inline" id="idc27dfb240e6640839c9cfdaf32421fb0"><enum>(i)</enum><header>In general</header><text display-inline="yes-display-inline">Where applicable, a ticket issuer that owns or operates an Internet website or online service that facilitates or executes the sale of event tickets shall implement and maintain procedures to require that any third party or service provider that performs services with respect to the sale of event tickets or has access to data regarding event ticket purchasing on the website or service maintains reasonable administrative, technical, and physical safeguards to protect the security and integrity of the website or service and that data. </text></clause><clause commented="no" display-inline="no-display-inline" id="idc6b4a3b780a043c9a490df4a1a078bc2"><enum>(ii)</enum><header>Oversight procedure requirements</header><text display-inline="yes-display-inline">The procedures implemented and maintained by a ticket issuer in accordance with clause (i) shall include the following:</text><subclause id="id3c70acce0a0b4b1e9b4b888e375b885b"><enum>(I)</enum><text>Taking reasonable steps to select and retain service providers that are capable of maintaining appropriate safeguards for the customer information at issue.</text></subclause><subclause id="id3cf37f50ee3046cb8666022d58c56cf4"><enum>(II)</enum><text>Requiring service providers by contract to implement and maintain adequate safeguards.</text></subclause><subclause id="id5fcdd9410c754d39a308df2d4e1435d9"><enum>(III)</enum><text>Periodically assessing service providers based on the risk they present and the continued adequacy of their safeguards. </text></subclause></clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id49A19B3707B2403BB2CCAECC6AF07B53"><enum>(D)</enum><header>Updates</header><text>A ticket issuer that owns or operates an Internet website or online service that facilitates or executes the sale of event tickets shall regularly evaluate and make adjustments to the safeguards described in subparagraph (A) in light of any material changes in technology, internal or external threats to system security, confidentiality, integrity, and availability, and the changing business arrangements or operations of the ticket issuer. </text></subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id0A8F4F655A7E485AAF29BED4C982413A"><enum>(3)</enum><header display-inline="yes-display-inline">Requirement to report incidents of circumvention; consumer complaints</header><subparagraph commented="no" display-inline="no-display-inline" id="idDA8447367D3D4811869CAFB2CB9511FB"><enum>(A)</enum><header>In general</header><text display-inline="yes-display-inline">A ticket issuer that owns or operates an Internet website or online service that facilitates or executes the sale of event tickets shall report to the Commission any incidents of circumvention of which the ticket issuer has actual knowledge.</text></subparagraph><subparagraph id="idFF4E33D5F3F84334B392255C69790B52"><enum>(B)</enum><header>Consumer complaint website</header><text>Not later than 180 days after the date of enactment of the <short-title>Mitigating Automated Internet Networks for Event Ticketing Act</short-title>, the Commission shall create a publicly available website (or modify an existing publicly available website of the Commission) to allow individuals to report violations of this subsection to the Commission. </text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id73DCD8DEC41143A9B300C01CA84EB023"><enum>(C)</enum><header>Reporting timeline and process</header><clause id="idCE9F97FC209D483EA7ADCD28E7B7B22F"><enum>(i)</enum><header>Timeline</header><text>A ticket issuer shall report known incidents of circumvention within a reasonable period of time after the incident of circumvention is discovered by the ticket issuer, and in no case later than 30 days after an incident of circumvention is discovered by the ticket issuer.</text></clause><clause id="idBFD72166ABB24728832951D2F1FFA378"><enum>(ii)</enum><header>Automated submission</header><text>The Commission may establish a reporting mechanism to provide for the automatic submission of reports required under this subsection.</text></clause><clause id="idFCF72F0D044D4931906D0549B793666C"><enum>(iii)</enum><header>Coordination with state attorneys general</header><text>The Commission shall—</text><subclause id="id980F511532014045B9798D1CAE39CC60"><enum>(I)</enum><text>share reports received from ticket issuers under subparagraph (A) with State attorneys general as appropriate; and</text></subclause><subclause id="id7F3C7C6549CC4B87B7C80BA329BA7BCF"><enum>(II)</enum><text>share consumer complaints submitted through the website established under subparagraph (B) with State attorneys general as appropriate.</text></subclause></clause></subparagraph></paragraph><paragraph id="id3482A7EA3D3A4E9FBC1991B1673CC512"><enum>(4)</enum><header>Duty to address causes of circumvention</header><text>A ticket issuer that owns or operates an Internet website or online service that facilitates or executes the sale of event tickets must take reasonable steps to improve its access control systems, security measures, and other technological controls or measures to address any incidents of circumvention of which the ticket issuer has actual knowledge.</text></paragraph><paragraph id="id13666051204B43DCA207F48E5F1B11F6" commented="no" display-inline="no-display-inline"><enum>(5)</enum><header>FTC guidance</header><text>Not later than 1 year after the date of enactment of the <short-title>Mitigating Automated Internet Networks for Event Ticketing Act</short-title>, the Commission shall publish guidance for ticket issuers on compliance with the requirements of this subsection.</text></paragraph></subsection><after-quoted-block>; </after-quoted-block></quoted-block></paragraph><paragraph commented="no" display-inline="no-display-inline" id="ide0f9e7c4853b488b86ae024ede446896"><enum>(4)</enum><text>in subsection (c), as redesignated by paragraph (1) of this subsection—</text><subparagraph commented="no" display-inline="no-display-inline" id="idb4de2813afb649a3891da0c397397f9f"><enum>(A)</enum><text display-inline="yes-display-inline">by striking <quote>subsection (a)</quote> each place it appears and inserting <quote>subsection (a) or (b)</quote>;</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idcd7c68b74ecf44a3a25e69e0d8ffd739"><enum>(B)</enum><text display-inline="yes-display-inline">in paragraph (2)—</text><clause commented="no" display-inline="no-display-inline" id="id8f4bad6343dd4ab19899ef4b0eb2de1b"><enum>(i)</enum><text display-inline="yes-display-inline">in subparagraph (A), by striking <quote>The Commission</quote> and inserting <quote>Except as provided in paragraph (3), the Commission</quote>; and</text></clause><clause commented="no" display-inline="no-display-inline" id="idb703fb5032f248d9a8278f03a582759d"><enum>(ii)</enum><text>in subparagraph (B), by striking <quote>Any person</quote> and inserting <quote>Subject to paragraph (3), any person</quote>; and</text></clause></subparagraph><subparagraph id="id65f22f0cc54a4db8b29da9f2a602f826"><enum>(C)</enum><text>by adding at the end the following new paragraphs:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id4FBAB3D192604A52957A5D4EE92B28F5"><paragraph id="id9B63FAFC156C4BA3B659E7B673ACB0DD"><enum>(3)</enum><header>Civil action</header><subparagraph commented="no" display-inline="no-display-inline" id="id892a9ee8358d4c5a8a0adcab2cbde2e3"><enum>(A)</enum><header>In general</header><text display-inline="yes-display-inline">If the Commission has reason to believe that any person has committed a violation of subsection (a) or (b), the Commission may bring a civil action in an appropriate district court of the United States to—</text><clause id="idE12D6AE629804F12B566DEB6A2C87E71"><enum>(i)</enum><text>recover a civil penalty under paragraph (4); and</text></clause><clause id="idEE698AC340CD4B8EBE346E7DB4300CE3"><enum>(ii)</enum><text>seek other appropriate relief, including injunctive relief and other equitable relief.</text></clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ida5d30aed4826466abc76da7c255f8800"><enum>(B)</enum><header>Litigation authority</header><text display-inline="yes-display-inline">Except as otherwise provided in section 16(a)(3) of the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/56">15 U.S.C. 56(a)(3)</external-xref>), the Commission shall have exclusive authority to commence or defend, and supervise the litigation of, any civil action authorized under this paragraph and any appeal of such action in its own name by any of its attorneys designated by it for such purpose, unless the Commission authorizes the Attorney General to do so. The Commission shall inform the Attorney General of the exercise of such authority and such exercise shall not preclude the Attorney General from intervening on behalf of the United States in such action and any appeal of such action as may be otherwise provided by law.</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idbbeea19d024344b7af1867814ca08732"><enum>(C)</enum><header>Rule of construction</header><text>Any civil penalty or relief sought through a civil action under this paragraph shall be in addition to other penalties and relief as may be prescribed by law. </text></subparagraph></paragraph><paragraph id="id23F70BB388EE424B8E8913E0CDC77602"><enum>(4)</enum><header>Civil penalties</header><subparagraph id="id467B910BB4F04A43945E6804F3859F44"><enum>(A)</enum><header>In general</header><text>Any person who violates subsection (a) or (b) shall be liable for—</text><clause id="id7A7B74216464441286CFA983359FB38F"><enum>(i)</enum><text>a civil penalty of not less than $10,000 for each day during which the violation occurs or continues to occur; and</text></clause><clause commented="no" display-inline="no-display-inline" id="id4AE60F413268458E987BA4821DF79222"><enum>(ii)</enum><text display-inline="yes-display-inline">an additional civil penalty of not less than $1,000 per violation.</text></clause></subparagraph><subparagraph id="idC16372C458A640A7BBD20B23DE5E81D8" commented="no" display-inline="no-display-inline"><enum>(B)</enum><header>Enhanced civil penalty for intentional violations</header><text>In addition to the civil penalties under subparagraph (A), a person that intentionally violates subsection (a) or (b) shall be liable for a civil penalty of not less than $10,000 per violation.</text></subparagraph></paragraph><after-quoted-block>;</after-quoted-block></quoted-block></subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id798732750b1c477dbc91aba3e497cd67"><enum>(5)</enum><text display-inline="yes-display-inline">in subsection (d), as redesignated by paragraph (1) of this subsection, by striking <quote>subsection (a)</quote> each place it appears and inserting <quote>subsection (a) or (b)</quote>; and</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id87d43c73240a4782ac689d22ee4a0722"><enum>(6)</enum><text display-inline="yes-display-inline">by adding at the end the following new subsections:</text><quoted-block id="idA12D521C17C2493DBEFBBA776A4BD29E" display-inline="no-display-inline" style="OLC" act-name=""><subsection id="idFFF95F74625A4948B61BBF7AD51E33AF"><enum>(e)</enum><header>Law enforcement coordination</header><paragraph commented="no" display-inline="no-display-inline" id="id547E53D9C0BB4D2C9C3CE2E013DFFCAB"><enum>(1)</enum><header display-inline="yes-display-inline">In general</header><text>The Federal Bureau of Investigation, the Department of Justice, and other relevant State or local law enforcement officials shall coordinate as appropriate with the Commission to share information about known instances of cyberattacks on security measures, access control systems, or other technological controls or measures on an Internet website or online service that are used by ticket issuers to enforce posted event ticket purchasing limits or to maintain the integrity of posted online ticket purchasing order rules. Such coordination may include providing information about ongoing investigations but may exclude classified information or information that could compromise a law enforcement or national security effort, as appropriate.</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id087FA2950612453DB97D3DD485BE1C18"><enum>(2)</enum><header>Cyberattack defined</header><text display-inline="yes-display-inline">In this paragraph, the term <term>cyberattack</term> means an attack, via cyberspace, targeting an enterprise’s use of cyberspace for the purpose of— </text><subparagraph commented="no" display-inline="no-display-inline" id="id26BA7C3518194D76A5F723C607C058D5"><enum>(A)</enum><text display-inline="yes-display-inline">disrupting, disabling, destroying, or maliciously controlling a computing environment or computing infrastructure; or</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id4AAB49DB78EA4F00BA4D8410AB05034F"><enum>(B)</enum><text display-inline="yes-display-inline">destroying the integrity of data or stealing controlled information.</text></subparagraph></paragraph></subsection><subsection id="idC051109B093B474EB6E191FC4FDDC81A" commented="no"><enum>(f)</enum><header>Congressional report</header><text display-inline="yes-display-inline">Not later than 1 year after the date of enactment of this paragraph, the Commission shall report to Committee on Commerce, Science, and Transportation of the Senate and the Committee on Energy and Commerce of the House of Representatives on the status of enforcement actions taken pursuant to this Act, as well as any identified limitations to the Commission’s ability to pursue incidents of circumvention described in subsection (a)(1)(A).</text></subsection><after-quoted-block>.</after-quoted-block></quoted-block></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="id68f0ddd511b94020a15013144a085397"><enum>(b)</enum><header>Additional definition</header><text>Section 3 of the Better Online Ticket Sales Act of 2016 (<external-xref legal-doc="usc" parsable-cite="usc/15/45c">15 U.S.C. 45c</external-xref> note) is amended by adding at the end the following new paragraph:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id5B9FE456FBAB4771868EC0FC0A92D4F3"><paragraph id="idF0000D327F384908B6D556E5C18CDDBD"><enum>(4)</enum><header>Circumvention</header><text>The term <term>circumvention</term> means the act of avoiding, bypassing, removing, deactivating, or otherwise impairing an access control system, security measure, safeguard, or other technological control or measure described in section 2(b)(1). </text></paragraph><after-quoted-block>.</after-quoted-block></quoted-block></subsection></section></legis-body></bill> 

