<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-SIL24738-Y2S-H8-0WT"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>118 S5449 IS: Data Breach Prevention and Compensation Act of 2024</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2024-12-05</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>118th CONGRESS</congress><session>2d Session</session><legis-num>S. 5449</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20241205">December 5, 2024</action-date><action-desc><sponsor name-id="S366">Ms. Warren</sponsor> (for herself, <cosponsor name-id="S327">Mr. Warner</cosponsor>, and <cosponsor name-id="S324">Mrs. Shaheen</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSBK00">Committee on Banking, Housing, and Urban Affairs</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To create an Office of Cybersecurity at the Federal Trade Commission for supervision of data security at consumer reporting agencies, to require the promulgation of regulations establishing standards for effective cybersecurity at consumer reporting agencies, to impose penalties on credit reporting agencies for cybersecurity breaches that put sensitive consumer data at risk, and for other purposes.</official-title></form><legis-body display-enacting-clause="yes-display-enacting-clause"><section section-type="section-one" id="S1"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Data Breach Prevention and Compensation Act of 2024</short-title></quote>.</text></section><section section-type="subsequent-section" id="idDE77928C0305464DBD3C37D2FC1907DD"><enum>2.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act:</text><paragraph id="idDCFBD912DD6B49E79976EAAE602D5FF6"><enum>(1)</enum><header>Affected consumer</header><text>The term <term>affected consumer</term> means any individual to whom personally identifying information pertains that was, or that may have been, affected by a covered breach.</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="HD112D62C555347478D05D8F39A80D07E"><enum>(2)</enum><header display-inline="yes-display-inline">Agency</header><text display-inline="yes-display-inline">The term <term>agency</term> has the meaning given the term in section 551 of title 5, United States Code.</text></paragraph><paragraph id="id6D771FE883F645E8B041DB82653219A1"><enum>(3)</enum><header>Career appointee</header><text>The term <term>career appointee</term> has the meaning given the term in section 3132(a) of title 5, United States Code.</text></paragraph><paragraph id="idCDA91C77726942CD92C530D3365DE9CE"><enum>(4)</enum><header>Commission</header><text>The term <term>Commission</term> means the Federal Trade Commission.</text></paragraph><paragraph id="id1db2496229f44c0b995798f255297bb2"><enum>(5)</enum><header>Consumer report; consumer reporting agency</header><text>The terms <term>consumer report</term> and <term>consumer reporting agency</term> have the meanings given the terms in section 603 of the Fair Credit Reporting Act (<external-xref legal-doc="usc" parsable-cite="usc/15/1681a">15 U.S.C. 1681a</external-xref>).</text></paragraph><paragraph id="id5A37B83F33CB41F8A9E7DEBFE9C4EF59"><enum>(6)</enum><header>Covered breach</header><text>The term <term>covered breach</term> means any instance in which not less than 1 piece of personally identifying information held by a covered consumer reporting agency is exposed, or is reasonably likely to have been exposed, to an unauthorized party.</text></paragraph><paragraph id="idAC2465E218DD40FEA5E44706BF1CDA8C"><enum>(7)</enum><header>Covered consumer reporting agency</header><text>The term <term>covered consumer reporting agency</term> means—</text><subparagraph id="id9060F513DD524FE0A05C8CF209A4588E"><enum>(A)</enum><text>a consumer reporting agency described in section 603(p) of the Fair Credit Reporting Act (<external-xref legal-doc="usc" parsable-cite="usc/15/1681a">15 U.S.C. 1681a(p)</external-xref>); or</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id866911B2D6D94944BBA6005CBFAC6E50"><enum>(B)</enum><text>a consumer reporting agency that earns not less than $7,000,000 in annual revenue from the sale of consumer reports.</text></subparagraph></paragraph><paragraph id="id8110BC16DF0C40D48C677BB4184365FC"><enum>(8)</enum><header>Detail</header><text>The term <term>detail</term> means a temporary assignment of an employee to a different position for a specified period, with the employee returning to the regular duties of the employee at the end of the specified period.</text></paragraph><paragraph id="id3CFD7C5711E34DEEB657A495C16F18AC"><enum>(9)</enum><header>Director</header><text>The term <term>Director</term> means the Director of the Office.</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id86B0336AC0294CB29E218A62770AD1C5"><enum>(10)</enum><header display-inline="yes-display-inline">Office</header><text display-inline="yes-display-inline">The term <term>Office</term> means the Office of Cybersecurity established under section 3(a).</text></paragraph><paragraph id="id2DFFBE321D1A4294B182F9132A1ACAAA"><enum>(11)</enum><header>Personally identifying information</header><text>The term <term>personally identifying information</term> means, with respect to an individual—</text><subparagraph id="idb0ea0045ea2045acb5757550cf902e00"><enum>(A)</enum><text>the social security number of the individual;</text></subparagraph><subparagraph id="idc3bdbf86c5194bcca9b5648457424b2b"><enum>(B)</enum><text>a driver’s license number of the individual;</text></subparagraph><subparagraph id="id291a5baf8c68490b81a11c77dc0505dd"><enum>(C)</enum><text>a passport number of the individual;</text></subparagraph><subparagraph id="id618037f6ac0947d8940ebc9097a603ba"><enum>(D)</enum><text>an alien registration number or other government-issued unique identification number of the individual;</text></subparagraph><subparagraph id="id1cc45a6c0bb14211aeba08198493a87d"><enum>(E)</enum><text>unique biometric data, such as a faceprint, a fingerprint, a voice print, an iris image, or any other unique physical representation of the individual;</text></subparagraph><subparagraph id="id74657535f1804e5a854feed972aa02bc"><enum>(F)</enum><text>the first and last name of the individual, or the first initial of the first name and the last name of the individual, in combination with any information that relates to—</text><clause id="idDD8F3E99E5FC46FFAA2BB9A03BA89C98"><enum>(i)</enum><text>the past, present, or future physical or mental health or condition of the individual; or</text></clause><clause id="idA0DC5779F08B4D34877E33B089D28FF9"><enum>(ii)</enum><text>the provision of health care to, or a diagnosis of, the individual;</text></clause></subparagraph><subparagraph id="idde6b626f517d43da8aa256f11f2f24cc"><enum>(G)</enum><clause commented="no" display-inline="yes-display-inline" id="id29633C1AFEE7494CBF41AB7761215B7C"><enum>(i)</enum><text>a financial account number, debit card number, or credit card number of the individual; or</text></clause><clause id="id297C2BC766AC4630A619812058DD5EAA" indent="up1"><enum>(ii)</enum><text>any passcode required to access an account described in clause (i); and</text></clause></subparagraph><subparagraph id="id25df7a8ebdf54614a947db060055c9ef"><enum>(H)</enum><text>such additional information, as determined by the Director.</text></subparagraph></paragraph></section><section id="id787b9850417f4e5b9fb4575bedd63087"><enum>3.</enum><header>Cybersecurity standards and FTC authority</header><subsection id="id4901c8cb5c5047ffa415a50461efdf55"><enum>(a)</enum><header>Establishment</header><text>There is established in the Commission an Office of Cybersecurity, which shall be headed by a Director, who shall be a career appointee.</text></subsection><subsection id="id41217d0e5b5e477f9f3bb6c7af2b666b"><enum>(b)</enum><header>Duties</header><text>The Office—</text><paragraph id="idbb99837f809a4b2c8b6c45cccf5cec0b"><enum>(1)</enum><text>shall—</text><subparagraph id="id2d46097ec748485a831de2cb3c26ef47"><enum>(A)</enum><text>supervise covered consumer reporting agencies with respect to data security;</text></subparagraph><subparagraph id="idfbed657f17514d2e9e9bc660a8115bec"><enum>(B)</enum><text>promulgate regulations, through notice and comment rulemaking that complies with section 553 of title 5, United States Code, for effective data security for covered consumer reporting agencies, including requirements for a covered consumer reporting agency to—</text><clause id="id0c82e018606848718b4b6c26f4529c6d"><enum>(i)</enum><text>provide the Commission with descriptions of technical and organizational security measures of the consumer reporting agency, including—</text><subclause id="id4ebf6f7b7c7f44f1a2931fa357bd153a"><enum>(I)</enum><text>system and network security measures, including—</text><item id="id5e7004c90314452b8162c768c444c26c"><enum>(aa)</enum><text>asset management, including—</text><subitem id="id9c3620e9f48e462aac886fc44ca52b09"><enum>(AA)</enum><text>an inventory of devices of the covered consumer reporting agency that are authorized to access data maintained by the covered consumer reporting agency;</text></subitem><subitem id="id216757a77fb044069d36ff75019a264f"><enum>(BB)</enum><text>an inventory of software that is authorized by the covered consumer reporting agency to access data maintained by the covered consumer reporting agency, including application whitelisting; and</text></subitem><subitem id="idc3a83731261d4e9da91fd252bd3efd53"><enum>(CC)</enum><text>secure configurations for hardware and software of the covered consumer reporting agency;</text></subitem></item><item id="idce124f0702174f5fb9c438091d6b3623"><enum>(bb)</enum><text>network management and monitoring, including—</text><subitem id="id18de573858ab40c894b23add52f435fc"><enum>(AA)</enum><text>mapped data flows, including functional mission mapping;</text></subitem><subitem id="id595def8828004174a0f33fe98c64968d"><enum>(BB)</enum><text>maintenance, monitoring, and analysis of audit logs;</text></subitem><subitem id="id7e7b04d5c360414390d534a6d6f2fc12"><enum>(CC)</enum><text>network segmentation; and</text></subitem><subitem id="id7317f18bb2b14083989eb35072090031"><enum>(DD)</enum><text>local and remote access privileges, defined and managed; and</text></subitem></item><item id="id10fce9c3abe3402a92b7a415df4370b0"><enum>(cc)</enum><text>application management, including—</text><subitem id="id38484790e6a543b68fd2385e2ca93ec0"><enum>(AA)</enum><text>continuous vulnerability assessment and remediation;</text></subitem><subitem id="id956d6b04d05a464aa885d371f47c5891"><enum>(BB)</enum><text>server application hardening;</text></subitem><subitem id="id58fa579d157b4328b32f8f6f7af7efb2"><enum>(CC)</enum><text>vulnerability handling, such as coordinated vulnerability disclosure policy; and</text></subitem><subitem id="idae139cfd60d44fa98e4bbb6632ddab76"><enum>(DD)</enum><text>patch management, including at, or near, real-time dashboards of patch implementation across network hosts; and</text></subitem></item></subclause><subclause id="id13db9e4c7e0342a5b48434f87d8a74a6"><enum>(II)</enum><text>data security measures, including—</text><item id="idc9e47291f20a47b1866381cda85fb0e1"><enum>(aa)</enum><text>data-centric security mechanisms such as format-preserving encryption, cryptographic data-splitting, and data-tagging and lineage;</text></item><item id="id6f731e120a484541b81bc816183cca78"><enum>(bb)</enum><text>encryption for data at rest;</text></item><item id="id7589ee0f753f4ce2b2d745501bfad10c"><enum>(cc)</enum><text>encryption for data in transit;</text></item><item id="id35ef81ad71644561bf9ccedfb7f5e3e0"><enum>(dd)</enum><text>systemwide data minimization evaluations and policies; and</text></item><item id="id5787084394984e969a8a875d36a58b96"><enum>(ee)</enum><text>data recovery capability;</text></item></subclause></clause><clause id="id51f10a3269c74ebfab3e36c3e72942c6"><enum>(ii)</enum><text>employ reasonable technical measures and corporate governance processes for continuous monitoring of data, intrusion detection, and continuous evaluation and timely patching of vulnerabilities;</text></clause><clause id="id0FC29FE17C504FF4B5EF75D1443F4A94"><enum>(iii)</enum><text>employ reasonable technical measures and corporate governance processes that satisfy and exceed all relevant data security policy recommendations contained in the framework of the National Institute of Standards and Technology entitled <quote>Framework for Improving Critical Infrastructure Cybersecurity</quote>, dated February 12, 2014, or any successor thereto, as determined appropriate by the Office; and</text></clause><clause id="id8206405F7A7146D9928254E96FB2C6B8"><enum>(iv)</enum><text>create and maintain documentation demonstrating that the covered consumer reporting agency is employing the technical measures and corporate governance processes described in clauses (ii) and (iii);</text></clause></subparagraph><subparagraph id="id98459852eafb4195bfea8e0c2e3a1b50"><enum>(C)</enum><text>annually examine the data security measures of covered consumer reporting agencies for compliance with the requirements described in clauses (ii) and (iii) of subparagraph (B);</text></subparagraph><subparagraph id="id504c1318fc424c0a9069b0d46810914b"><enum>(D)</enum><text>investigate any covered consumer reporting agency if the Office has reason to suspect—</text><clause id="idBDEB811FCDFC4470A392847B49D54E98"><enum>(i)</enum><text>a covered breach has occurred and the covered consumer reporting agency was subject to the covered breach; or</text></clause><clause id="idDED86EFB218E4EEF87C61212A08D84F2"><enum>(ii)</enum><text>the covered consumer reporting agency is not in compliance with the requirements described in clauses (ii) and (iii) of subparagraph (B);</text></clause></subparagraph><subparagraph id="ida41f8ded732946c594849b1db4965c4b"><enum>(E)</enum><text>after consultation with members of the technical and academic communities, develop a rigorous, repeatable methodology—</text><clause id="idEA4E0812266D413AA2729BACFD25B1C7"><enum>(i)</enum><text>for evaluating, testing, and measuring effective data security practices of covered consumer reporting agencies; and</text></clause><clause id="id65FA013CDD50435CBA5CB3CC634B53A1"><enum>(ii)</enum><text>that employs forms of static and dynamic software analysis and penetration testing;</text></clause></subparagraph><subparagraph id="id72c7fa3da7824d549cf778e78a667fd9"><enum>(F)</enum><text>submit to Congress an annual report on the findings of each investigation carried out under subparagraph (D) during the year covered by the report that includes a statement of how Congress could enhance the authorities of the Office in order to assist the Office in carrying out the duties of the Office under this Act;</text></subparagraph><subparagraph id="idc8dee938d9d849708f52049f6ed90173"><enum>(G)</enum><text>determine whether covered consumer reporting agencies are complying with the requirements described in clauses (ii) and (iii) of subparagraph (B); and</text></subparagraph><subparagraph id="idc6cc76fdf04e470b9ad6244024815c98"><enum>(H)</enum><text>coordinate with the National Institute of Standards and Technology and the National Cybersecurity and Communications Integration Center of the Department of Homeland Security; and</text></subparagraph></paragraph><paragraph id="id026b3171919f4d3c82705cf5ed8ff641"><enum>(2)</enum><text>may—</text><subparagraph id="id299bbea8c02e4d2aafeebe052953e6ac"><enum>(A)</enum><text>investigate any covered breach to determine if the covered consumer reporting agency that was subject to the covered breach was in compliance with the requirements described in clauses (ii) and (iii) of paragraph (1)(B) as of the date on which the covered breach occurred; and</text></subparagraph><subparagraph id="id059060ed74a24f1fb4bacd660c849c54"><enum>(B)</enum><text>if the Director has reason to believe that any covered consumer reporting agency is violating, or in the immediate future will violate, a requirement described in clause (ii) or (iii) of paragraph (1), bring a suit in an appropriate district court of the United States to enjoin any such act or practice.</text></subparagraph></paragraph></subsection><subsection id="idC0458F1150394A44BBF72EF1542D4431"><enum>(c)</enum><header>Staff</header><paragraph id="idccd86ee5955a4848b2c8eb536f1cc575"><enum>(1)</enum><header>In general</header><text>The Director shall, without regard to the civil service laws and regulations, appoint such personnel, including computer security researchers and practitioners with technical expertise in computer science, engineering, and cybersecurity, as the Director determines are necessary to carry out the duties of the Office.</text></paragraph><paragraph id="idacf9835b26e4433885fcfbc2c6eb5a6c"><enum>(2)</enum><header>Details</header><subparagraph id="idB7AB3588C40F4B64BD86681FE17AB8ED"><enum>(A)</enum><header>In general</header><text>An employee of the National Institute of Standards and Technology, the Bureau of Consumer Financial Protection, or the National Cybersecurity and Communications Integration Center of the Department of Homeland Security may be detailed to the Office, without reimbursement.</text></subparagraph><subparagraph id="id2E2676BBE4964820BA591FE07A3100E5"><enum>(B)</enum><header>Civil service status and privilege</header><text>Detail under subparagraph (A) shall be without interruption or loss of the civil service status or privilege of the employee who is detailed to the Office.</text></subparagraph></paragraph></subsection></section><section id="id76598f0801b44a8eb377ec41c78cc09e"><enum>4.</enum><header>Notification and enforcement</header><subsection id="id47E0ACC64519466CB6486F9D94D0CC66"><enum>(a)</enum><header>Notification</header><paragraph id="id9940a478ffa3431eb291423e972b742c"><enum>(1)</enum><header>Notification to the Commission and relevant federal law enforcement and intelligence agencies</header><subparagraph id="id62e05015e5f04abeb86030b6056a9de8"><enum>(A)</enum><header>Notification to the Commission</header><text>Except as provided in paragraph (3), not later than 10 days after the date on which a covered breach occurs, any covered consumer reporting agency that was subject to the covered breach shall notify the Commission of the covered breach.</text></subparagraph><subparagraph id="idf4ff267a906f4923a1a0d83c7681b188"><enum>(B)</enum><header>Notification to relevant federal law enforcement and intelligence agencies</header><text>Not later than 10 days after the date on which the Commission receives a notification under subparagraph (A) that a covered breach has occurred, the Commission shall—</text><clause id="idd728821bdd47409e9bf20a7b30893e76"><enum>(i)</enum><text>notify the relevant Federal law enforcement agencies and intelligence agencies that the covered breach has occurred; and</text></clause><clause id="idba2b577506794b19ad48ff7b1fb50f57"><enum>(ii)</enum><text>with respect to the covered breach, consult with the relevant Federal law enforcement agencies and intelligence agencies, as appropriate.</text></clause></subparagraph></paragraph><paragraph id="id48D8FF884F6946ABB4C0564114BFE4CA"><enum>(2)</enum><header>Notification to affected consumers and the public</header><subparagraph id="id3F24F8D64160429D933077504F32C3AB"><enum>(A)</enum><header>In general</header><text>Except as provided in paragraph (3), on an expeditious and practical timeline, as determined appropriate by the Commission, a covered consumer reporting agency that is subject to a covered breach shall—</text><clause id="id39E2F8F6775247538364410502896DB7"><enum>(i)</enum><text>submit to each affected consumer with respect to whom the covered consumer reporting agency holds a piece of personally identifying information a notification regarding the covered breach that complies with subparagraph (B); and</text></clause><clause id="idD7B109AB9CE54CAB81E4420C121ADB1F"><enum>(ii)</enum><text>publish on the internet website of the covered consumer reporting agency a notice that contains a statement of—</text><subclause id="id8E956782F9EE4B42822FEC195DE753DA"><enum>(I)</enum><text>the information described in clauses (i) and (ii) of subparagraph (B) and subclauses (I) and (II) of clause (iii) of that subparagraph; and</text></subclause><subclause id="id2DDFA8048D7A41FCA4FB0225B617CF29"><enum>(II)</enum><text>the steps that the covered consumer reporting agency is taking to notify the affected consumers described in clause (i) regarding the covered breach.</text></subclause></clause></subparagraph><subparagraph id="idC9D9FFA91B6F4200859A31B639D2F274"><enum>(B)</enum><header>Notification to affected consumers</header><text>In a notification to affected consumers under subparagraph (A)(i), the covered consumer reporting agency submitting the notification shall include a statement of—</text><clause id="id843D5C0EFFCB4BFA9438A12252E40ADC"><enum>(i)</enum><text>the fact that the covered breach occurred;</text></clause><clause id="id3AB2D1548FF44337BB7C43DCA5FC5961"><enum>(ii)</enum><text>the approximate date on which the covered breach occurred; and</text></clause><clause id="idFE503FBF758D4098BAF6B03B4C13133A"><enum>(iii)</enum><text>with respect to the covered breach—</text><subclause id="id9437B26278244CEDB52F8DB710B5BA86"><enum>(I)</enum><text>the number of affected consumers;</text></subclause><subclause id="id9C73048D762E402CA654D1D32F1FBE15"><enum>(II)</enum><text>the measures that the covered consumer reporting agency is taking to remedy the covered breach; and</text></subclause><subclause id="idB9A099641BB14045B215332BB61307AD"><enum>(III)</enum><text>the potential risks created by the covered breach, a list of which the covered consumer reporting agency shall develop in consultation with the Office.</text></subclause></clause></subparagraph></paragraph><paragraph id="H92FA35E283B944168C9FE38AD4741A86"><enum>(3)</enum><header>Delay of notification authorized for law enforcement or national security purposes</header><subparagraph id="H301CD7BDF25D46A0A322F34E03684FC8"><enum>(A)</enum><header>Notification by law enforcement agency or intelligence agency</header><text>If a Federal law enforcement agency or intelligence agency to which the Commission has provided notice under paragraph (1)(B)(i) determines that the notification required under paragraph (2) may impede a criminal investigation or national security activity—</text><clause id="id23DE74712447418DA429B94F8A436741"><enum>(i)</enum><text>the Federal law enforcement agency or intelligence agency shall provide written notice to the Commission and the covered consumer reporting agency that was subject to the covered breach that is the subject of the notification that states—</text><subclause id="idFC2AE7DA758F4439AF04F6A2E3F2B89E"><enum>(I)</enum><text>that the notification required under paragraph (2) shall be delayed for law enforcement or national security purposes; and</text></subclause><subclause id="id1FAA9FFB66C44E26A078F8E2EB21EDAC"><enum>(II)</enum><text>the date on which the delay imposed under subclause (I) shall end; and</text></subclause></clause><clause id="id30BBB66CA41B4320965ADE826AA700C7"><enum>(ii)</enum><text>subject to subparagraph (B), the covered consumer reporting agency that was subject to the covered breach shall delay notification under paragraph (2) until the date described in clause (i)(II) of this subparagraph.</text></clause></subparagraph><subparagraph id="H3298EB063F324E95A513CDECFCEDB992"><enum>(B)</enum><header>Extended delay of notification</header><text>If the notification required under paragraph (2) is delayed under subparagraph (A) of this paragraph, a covered consumer reporting agency that is required to provide notice under paragraph (2) shall provide that notice on an expeditious and practical timeline, as determined appropriate by the Commission, after the date on which the law enforcement or national security delay under subparagraph (A) of this paragraph ends, unless a Federal law enforcement or intelligence agency to which the Commission has provided notice under paragraph (1)(B)(i) provides written notification to the Commission and the covered consumer reporting agency that states—</text><clause id="id9BE249E2EAC54AE6845CE4CFBAF72D0B"><enum>(i)</enum><text>that further delay is necessary; and</text></clause><clause commented="no" id="id891E2443D734459192840DFD08AD83C9"><enum>(ii)</enum><text>the date on which the further delay shall end.</text></clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="H8D901119E700466185C47342D5F9D047"><enum>(C)</enum><header>Law enforcement immunity</header><text>No nonconstitutional cause of action shall lie in any court against any agency for acts relating to the delay of notification under subparagraph (A), or the extended delay of notification under subparagraph (B), for law enforcement or national security purposes.</text></subparagraph></paragraph></subsection><subsection id="id8785CE9BF1C74A40B015FD53A19011A9"><enum>(b)</enum><header>Penalty</header><paragraph id="id5A65847C23554CB48AE5671437FB975B"><enum>(1)</enum><header>In general</header><text>In the event of a covered breach, the Commission shall, not later than 30 days after the date on which the Commission receives notification of the covered breach under subsection (a)(1)(A), commence a civil action to recover a civil penalty in an appropriate district court of the United States against the covered consumer reporting agency that was subject to the covered breach.</text></paragraph><paragraph id="id0C81F0AA8D214BD2891A258F3C3E15EC"><enum>(2)</enum><header>Determining penalty amount</header><subparagraph id="id94C07D8D2E7E4976A7569338597C8963"><enum>(A)</enum><header>In general</header><text>Except as provided in subparagraph (B), in determining the amount of a civil penalty under paragraph (1), the court shall impose a civil penalty on a covered consumer reporting agency of—</text><clause id="idfe9919e079d5449dafef4a28140e6224"><enum>(i)</enum><text>$100 for each consumer for whom the first and last name, or the first initial of the first name and last name, and 1 other item of personally identifying information were exposed to an unauthorized party; and</text></clause><clause id="id0eb14ee2092344d1a594ddb266349789"><enum>(ii)</enum><text>in addition to the penalty imposed under clause (i), an additional $50 for each item of personally identifying information of the consumer, other than an item described in that clause, that was exposed to an unauthorized party.</text></clause></subparagraph><subparagraph id="idDF5D8C7E84284F10ABD09CCE34CA0EC8"><enum>(B)</enum><header>Exception</header><clause id="id2DB1D63A649840148956FAEF708B2CE8"><enum>(i)</enum><header>In general</header><text>Except as provided in clause (ii), in an action commenced under this subsection, a court may not impose a civil penalty in an amount that is more than 50 percent of the gross revenue of the covered consumer reporting agency against which the action is brought for the fiscal year before the fiscal year in which the covered consumer reporting agency became aware of the covered breach that is the subject of the action.</text></clause><clause id="id13DA538F23C4406AAF353C2DE5847D67"><enum>(ii)</enum><header>Penalty doubled</header><text>In an action commenced under this subsection, the court shall impose a civil penalty on a covered consumer reporting agency in an amount that is 2 times the amount of the penalty described in subparagraph (A), but not greater than 75 percent of the gross revenue of the covered consumer reporting agency for the fiscal year before the fiscal year in which the covered consumer reporting agency became aware of the covered breach that is subject to the action, if—</text><subclause id="id3FBC9136BE5F4F1DB50E1300031E9911"><enum>(I)</enum><text>the covered consumer reporting agency fails to notify the Commission of the covered breach before the deadline established under subsection (a)(1)(A); or</text></subclause><subclause id="id04BDEFC4A5AA4B349396813DEEA6299F"><enum>(II)</enum><text>the covered consumer reporting agency violates any requirement described in clause (ii) or (iii) of section 3(b)(1)(B).</text></subclause></clause></subparagraph></paragraph><paragraph id="idBC27E613E0C14564A373B8CAA9A27B18"><enum>(3)</enum><header>Proceeds of the penalties</header><text>Of the penalties imposed under this subsection—</text><subparagraph id="id11222ECFCFA34440A748B190FF3C0AD4"><enum>(A)</enum><text>50 percent shall be used for cybersecurity research and inspections by the Office; and</text></subparagraph><subparagraph id="id6B13F38157EC456ABEED2527E1FF3544"><enum>(B)</enum><text>50 percent shall be used by the Office to be divided fairly among consumers affected by the covered breach.</text></subparagraph></paragraph><paragraph id="idd1f2f61091fe43119081afdbc50adeab"><enum>(4)</enum><header>No preemption</header><text>Nothing in this subsection shall preclude an action by a consumer under State or other Federal law.</text></paragraph></subsection><subsection id="id2F3E95F7FAEB44D3B30069DDD0478B96"><enum>(c)</enum><header>Injunctive relief</header><text>The Commission, acting through the Office, may bring suit in an appropriate district court of the United States or in the United States court of any territory to require a covered consumer reporting agency to implement or correct a particular security measure in order to promote effective security in accordance with the requirements described in clauses (ii) and (iii) of section 3(b)(1)(B).</text></subsection></section><section id="idCA98AFA193CF405A8C4B7E0F9C8225F6"><enum>5.</enum><header>Authorization of appropriations</header><text display-inline="no-display-inline">There are authorized to be appropriated $100,000,000 to carry out this Act, to remain available until expended.</text></section></legis-body></bill> 

