<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-RIL24A92-8D5-3Y-2KY"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>118 S5579 IS: Auto Data Privacy and Autonomy Act</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2024-12-18</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>118th CONGRESS</congress><session>2d Session</session><legis-num>S. 5579</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20241218" legis-day="20241216">December 18 (legislative day, December 16), 2024</action-date><action-desc><sponsor name-id="S346">Mr. Lee</sponsor> (for himself and <cosponsor name-id="S322">Mr. Merkley</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSCM00">Committee on Commerce, Science, and Transportation</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To prevent covered vehicle manufacturers from accessing, selling, or otherwise selling certain covered vehicle data, and for other purposes.</official-title></form><legis-body><section id="S1" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Auto Data Privacy and Autonomy Act</short-title></quote>.</text></section><section id="id113f0b968c8a47209eae5cbbeaa92cd7"><enum>2.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act:</text><paragraph commented="no" display-inline="no-display-inline" id="idcd6391100b6d4983a9b08d4a0b8a5fa6"><enum>(1)</enum><header display-inline="yes-display-inline">Commission</header><text>The term <term>Commission</term> means the Federal Trade Commission.</text></paragraph><paragraph id="id642e44543c3e441b8e9004a8372ea95d"><enum>(2)</enum><header>Covered vehicle</header><text>The term <term>covered vehicle</term> means a motor vehicle or a vehicle primarily used for farming or construction.</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="idd75b07fbb36b471e95b05ad6154d3256"><enum>(3)</enum><header display-inline="yes-display-inline">Director</header><text>The term <term>Director</term> means the Director of the National Institute of Standards and Technology.</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id0e101d478d884583b3c9d9fe544c198b"><enum>(4)</enum><header display-inline="yes-display-inline">Motor vehicle</header><text>The term <term>motor vehicle</term> has the same meaning given such term in section 30102(a) of title 49, United States Code, and includes a motor vehicle trailer.</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="idacfd647885334e5b8016db3e8fdf19b5"><enum>(5)</enum><header>Operator data</header><text>The term <term>operator data</term> means—</text><subparagraph commented="no" display-inline="no-display-inline" id="idbac548748a8d4b2c8906cd8f93908960"><enum>(A)</enum><text>all electronic data generated or processed onboard a covered vehicle, such as data generated by sensors, receivers, computer processing units, or other vehicle components; and</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ide3e36e14964448ffade2d6a47ec8fda7"><enum>(B)</enum><text>data stored in a covered vehicle generated by the user of such covered vehicle.</text></subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id01c3d32c84f44c328a8e4142bcd29c0c"><enum>(6)</enum><header>Personally identifiable information</header><text>The term <term>personally identifiable information</term> means information that—</text><subparagraph commented="no" display-inline="no-display-inline" id="id4b3d4527f8b741a497c00105aceae169"><enum>(A)</enum><text display-inline="yes-display-inline">directly identifies an individual such as the name, address, social security number or other identifying number or code, telephone number, or email address of an individual;</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idef0d19e2df9640fb94dfad96bdc62e26"><enum>(B)</enum><text>indirectly identifies an individual such as the gender, race, or date of birth of an individual; or</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id9c290fb99b624235bf1eb1dacc594d3e"><enum>(C)</enum><text>reveals the physical location or internet activity of an individual.</text></subparagraph></paragraph><paragraph id="id9d1ab9a0afd246baaa2b26e3090eaba7"><enum>(7)</enum><header>Secretary</header><text>The term <term>Secretary</term> means the Secretary of Transportation.</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id535a078c21bb45e1817872a7de958498"><enum>(8)</enum><header>Secure</header><text>The term <term>secure</term> means, with respect to the interface for access and control of operator data described in section 4(c), designed to prevent malicious or unauthorized use or access of such data.</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="idcaf8e7ed992a45d688543da24cdc99ed"><enum>(9)</enum><header>Technology-neutral</header><text>The term <term>technology-neutral</term> means, with respect to the interface for access and control of operator data described in section 4(c), designed without preference or prejudice towards any technology or service used to access and control such data by a covered vehicle owner, and not contingent on ownership or licensing of proprietary technologies by a covered vehicle owner or manufacturer.</text></paragraph><paragraph id="idf3310bb1da7f40a0964e83861f050f96"><enum>(10)</enum><header>User preference</header><text>The term <term>user preference</term> means any choice with respect to a configurable setting of a covered vehicle made by or for the benefit of the owner or user of such covered vehicle.</text></paragraph></section><section id="id18b439b44b7a45bebf591645017d0cb4"><enum>3.</enum><header>Operator data privacy and security</header><subsection id="id9873fb221ff74377b2146dfe3d64d7c1"><enum>(a)</enum><header>Prohibition on manufacturers</header><text>A manufacturer of a covered vehicle may not, with respect to the covered vehicle of a covered vehicle owner that is manufactured by such manufacturer—</text><paragraph id="idd5370469d509413ba1ac3347a87db10e"><enum>(1)</enum><text>access operator data, unless—</text><subparagraph id="id354565fc1ec34929b117385b8412925d"><enum>(A)</enum><text>the covered vehicle owner affirmatively consents to such manufacturer accessing such data and such consent—</text><clause id="id18017da381f04a64ac0c9a3589ad751d"><enum>(i)</enum><text>is freely given;</text></clause><clause id="idd14afd4f8f6c4c22b0526f698b9e5730"><enum>(ii)</enum><text>is informed, specific, and unambiguous;</text></clause><clause id="idac51f21b30e54dc899f097b086aa4fec"><enum>(iii)</enum><text>is in writing; and</text></clause><clause id="id8db15b8791204c77ab530779d0286716"><enum>(iv)</enum><text>may be easily withdrawn; or</text></clause></subparagraph><subparagraph id="id5fcc4e0264b143fc8c41741f5514e97e"><enum>(B)</enum><text>such data is accessed solely to improve covered vehicle performance or safety;</text></subparagraph></paragraph><paragraph id="idd517b5a9a00d47a7b170a95f61d40f3f"><enum>(2)</enum><text>sell, lease, or otherwise share operator data, unless—</text><subparagraph id="id4d813433241a4145a8a20f8ffa8bd1d4"><enum>(A)</enum><text>required to do so—</text><clause id="idd247045eaf66461cb9b538cc47aeb7c9"><enum>(i)</enum><text>pursuant to a lawfully executed warrant;</text></clause><clause id="id879119a4edc24fa2b4cb5185916bc565"><enum>(ii)</enum><text>pursuant to a court order that provides the covered vehicle owner notice of the order and at least 48 hours to object and request a hearing; or</text></clause><clause id="idb2031a7329b045e68076f61db35318e9"><enum>(iii)</enum><text>to facilitate an emergency response; or</text></clause></subparagraph><subparagraph id="id7873f70f11884c1fb543c920232ea594"><enum>(B)</enum><text>expressly permitted to do so by the covered vehicle owner or, in the event of the death or incapacity of such person, the next of kin of such owner; or</text></subparagraph></paragraph><paragraph id="id7ba9add4cdae4b0db41f5dd7bd3bcb96"><enum>(3)</enum><text>sell, license, rent, trade, transfer, release, disclose, provide access to, or otherwise make available personally identifiable information of a United States citizen or lawful permanent resident to the following:</text><subparagraph id="id7e36435fecd54413b132b90a5f784ac6"><enum>(A)</enum><text>The Democratic People’s Republic of Korea.</text></subparagraph><subparagraph id="id6550c9c46eba48cd8b9a76fed944b493"><enum>(B)</enum><text>The People’s Republic of China.</text></subparagraph><subparagraph id="id018238f21e754487a0067b5cee0f7ffc"><enum>(C)</enum><text>The Russian Federation.</text></subparagraph><subparagraph id="id81f3dab283934c20a59b5e6a104347f2"><enum>(D)</enum><text>The Islamic Republic of Iran.</text></subparagraph><subparagraph id="id7306f0ff7d8f494f847fa1fcaf3945e9"><enum>(E)</enum><text>The Bolivarian Republic of Venezuela.</text></subparagraph></paragraph></subsection><subsection id="H0C86D4A38ABE4063992F930DA3D8ECFB"><enum>(b)</enum><header>Report</header><paragraph id="H5BB61E5524C1441E90B753C129A8FA4C"><enum>(1)</enum><header>In general</header><text>Not later than 180 days after the date of the enactment of this Act, the Commission shall submit to Congress a report that describes, with respect to operator data—</text><subparagraph id="HB1200AFCE4E044E1868B0494F6EDA4BB"><enum>(A)</enum><text display-inline="yes-display-inline">the types of such data that a manufacturer of a covered vehicle accesses;</text></subparagraph><subparagraph id="HC0743FE92E1E463B93B4DD8F06CCD6DD"><enum>(B)</enum><text>the individuals and entities, other than a manufacturer of a covered vehicle, that access such data;</text></subparagraph><subparagraph id="HF2DC16951ACE44299848F017A66EFD32"><enum>(C)</enum><text>the Federal or State government entities that access such data and how such entities use such data;</text></subparagraph><subparagraph id="HE43EBAC57A11427EAC3153EED4EC81F5"><enum>(D)</enum><text>the individuals and entities to whom such data may be sold or otherwise shared;</text></subparagraph><subparagraph id="HCCC84C72300F469FB99B7095E22F3F55"><enum>(E)</enum><text display-inline="yes-display-inline">the foreign governments to whom such data may be sold or otherwise shared and how such data is used by such foreign governments;</text></subparagraph><subparagraph id="H334A3EA30DD549AEB573EFCBFC4E445D"><enum>(F)</enum><text>the cybersecurity capabilities and risks associated with covered vehicles; and</text></subparagraph><subparagraph id="HA136FE12D16647EB9FD9364C11FB4115"><enum>(G)</enum><text>occurrences of such data being compromised, including the prevalence of such occurrences and any entities with ties to foreign governments associated with such occurrences.</text></subparagraph></paragraph><paragraph id="H41E522B1F0B64F65BA8BCF3F72241E35"><enum>(2)</enum><header>Consultation</header><text>In completing the report required under paragraph (1), the Commission shall consult with—</text><subparagraph id="H6534D1B646FE48C8871F4AA86249FDB2"><enum>(A)</enum><text display-inline="yes-display-inline">the Attorney General;</text></subparagraph><subparagraph id="HE69EB319944C447C83C5BD76252EEE6B"><enum>(B)</enum><text>the Secretary of Homeland Security;</text></subparagraph><subparagraph id="H3D7D7FF6F5FA4157937A3AFA6E0D68D0"><enum>(C)</enum><text>the Secretary of Transportation; and</text></subparagraph><subparagraph id="HEE96AE9A527546739E781EE310468D4C" commented="no" display-inline="no-display-inline"><enum>(D)</enum><text>the Federal Communications Commission.</text></subparagraph></paragraph></subsection></section><section id="id1008ec5bfc3c47e8ad4e041958fd8c1c"><enum>4.</enum><header>Operator data access</header><subsection id="id5a929ccd869b45fab418e2374be978b4"><enum>(a)</enum><header>In general</header><text>A manufacturer of a covered vehicle shall provide to a covered vehicle owner access to, and control of, operator data—</text><paragraph commented="no" display-inline="no-display-inline" id="ide8946b241465415db0e3fee6204752d4"><enum>(1)</enum><text display-inline="yes-display-inline">at no cost beyond the purchase price of such vehicle;</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id53f0cc84e0704d41b5ce8243a6d03c10"><enum>(2)</enum><text>without any restriction or limitation, consistent with subsection (c); and</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id5ca6b5c578a4476da550ad638b16e206"><enum>(3)</enum><text>without a requirement that the covered vehicle owner—</text><subparagraph commented="no" display-inline="no-display-inline" id="ide316f548380e4fa8a41f7623917b3433"><enum>(A)</enum><text display-inline="yes-display-inline">pay a fee or purchase a license to decrypt operator data; or</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id84534b7bffde4cc8acb03f38c757c6cc"><enum>(B)</enum><text>use a device provided by such manufacturer to access and use operator data.</text></subparagraph></paragraph></subsection><subsection id="id840b2cfe43f04438a0f4dfc2cb1381b0"><enum>(b)</enum><header>Data deletion and user preferences</header><text>To facilitate the access and control of operator data described in subsection (a), a manufacturer of a covered vehicle shall enable the operation of open application programming interfaces that— </text><paragraph commented="no" display-inline="no-display-inline" id="id6f906fdc20b04f0aba415493715ba5b7"><enum>(1)</enum><text display-inline="yes-display-inline">facilitate deletion of all data stored in a covered vehicle generated by the user of such covered vehicle; and</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id2a3cc2021cbb46128a19ec1888a296d6"><enum>(2)</enum><text display-inline="yes-display-inline">enable the setting of any user preference by the covered vehicle owner or another user of the covered vehicle.</text></paragraph></subsection><subsection id="id59685de35d4c4622aa3aea7b3c92d2b1"><enum>(c)</enum><header>Technology-neutral, secure, standards-based interface</header><text>The manufacturer of a covered vehicle shall provide to a covered vehicle owner the access and control required by subsection (a) by means of a technology-neutral and secure interface that meets the standards set by the Commission pursuant to section 5.</text></subsection></section><section id="idc252336ac276420abe6632f80b63e7a4"><enum>5.</enum><header>Standards</header><subsection id="ida11bdf233dc040588900bf9677b4fee5"><enum>(a)</enum><header>Standards report</header><text>Not later than 180 days after the date of enactment of this Act, the Commission shall submit to the Committee on Commerce, Science, and Transportation of the Senate and the Committee on Energy and Commerce of the House of Representatives a report on the current practices employed for operator data generation, storage, transmission, and cybersecurity.</text></subsection><subsection id="ide1f99c0f1df54fc08568441e3914ae5c"><enum>(b)</enum><header>Standards setting</header><text>Not later than 1 year after the date on which the Commission submits the report under subsection (a), the Commission shall, in coordination with the Director, relevant industry stakeholders, including manufacturers of covered vehicles and covered vehicle owners, and with other agencies as necessary, establish 1 or more standards for the technology-neutral, standards-based, secure interface required by section 4(c).</text></subsection><subsection id="iddab0f6f13ca142c6992cf0158fa31be4"><enum>(c)</enum><header>Standards review and revision</header><text>Not later than 5 years after the date on which the Commission, in coordination with the Director, establishes the standards required under subsection (b), and not less frequently than once every 5 years thereafter, the Commission shall review and revise such standards as appropriate.</text></subsection></section><section commented="no" display-inline="no-display-inline" id="id15d6dcd7b9c246a8bb3d4583de90fa80"><enum>6.</enum><header>Enforcement</header><subsection commented="no" display-inline="no-display-inline" id="id3904e031a1c24980b23b2fd57653fca9"><enum>(a)</enum><header display-inline="yes-display-inline">Unfair or deceptive act or practice</header><text>A violation of this Act shall be treated as a violation of a rule defining an unfair or deceptive act or practice under section 18(a)(1)(B) of the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/57a">15 U.S.C. 57a(a)(1)(B)</external-xref>).</text></subsection><subsection commented="no" display-inline="no-display-inline" id="id0427eed7c2d141b5945e9b5e005f0abe"><enum>(b)</enum><header>Powers of the Commission</header><paragraph commented="no" display-inline="no-display-inline" id="idf118b87bc29e406096e4d88491bccedc"><enum>(1)</enum><header display-inline="yes-display-inline">In general</header><text>The Commission shall enforce this Act in the same manner, by the same means, and with the same jurisdiction, powers, and duties as though all applicable terms and provisions of the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/41">15 U.S.C. 41 et seq.</external-xref>) were incorporated into and made a part of this Act.</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="idcb585ad1931a4aea8375d58364967827"><enum>(2)</enum><header>Privileges and immunities</header><text>Any person who violates this Act shall be subject to the penalties and entitled to the privileges and immunities provided in the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/41">15 U.S.C. 41 et seq.</external-xref>).</text></paragraph><paragraph id="idb98328ff1d2d452c90af41ad940b7ae7" commented="no" display-inline="no-display-inline"><enum>(3)</enum><header>Authority preserved</header><text>Nothing in this Act shall be construed to limit the authority of the Commission under any other provision of law. </text></paragraph></subsection></section><section id="idde224d1cc6ce4ca4966c47c4ad6541d3"><enum>7.</enum><header>Relation to other laws</header><text display-inline="no-display-inline">This Act supersedes any statute, rule, requirement, or other legal obligation of a State or political subdivision thereof, or any Federal law or regulation, that relates to the requirements in this Act.</text></section><section id="ide202a738bb044ad7afd54c2abcf2ea69"><enum>8.</enum><header>Disclosure of confidential business information</header><text display-inline="no-display-inline">Except as provided in section 4, nothing in this Act shall require a manufacturer of a covered vehicle to divulge confidential business information (as that term is defined in section 512.3(c) of title 49, Code of Federal Regulations).</text></section><section id="id90aea23c3d9b45ea85424676caabe596"><enum>9.</enum><header>Effective date</header><text display-inline="no-display-inline">This Act shall take effect on the date that is 3 months after the date of enactment of this Act.</text></section><section id="id117a704fdd8f4c9bb4ad49b2e84ddfae"><enum>10.</enum><header>No new appropriations</header><text display-inline="no-display-inline">The Commission shall carry out this Act using unobligated funds appropriated to the Commission and available as of the date of the enactment of this Act. </text></section></legis-body></bill> 

