<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" dms-id="HFBA0CF25ED5949DEADD7FEF83954E827" public-private="public" key="H" bill-type="olc"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>119 HR 8413 IH: Securing and Establishing Consumer Uniform Rights and Enforcement over Data Act</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2026-04-21</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">I</distribution-code><congress display="yes">119th CONGRESS</congress><session display="yes">2d Session</session><legis-num display="yes">H. R. 8413</legis-num><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action display="yes"><action-date date="20260421">April 21, 2026</action-date><action-desc><sponsor name-id="J000302">Mr. Joyce of Pennsylvania</sponsor> (for himself, <cosponsor name-id="F000478">Mr. Fry</cosponsor>, <cosponsor name-id="K000398">Mr.
                    Kean</cosponsor>, <cosponsor name-id="O000019">Mr. Obernolte</cosponsor>,
                    <cosponsor name-id="L000600">Mr. Langworthy</cosponsor>, <cosponsor name-id="G000601">Mr. Goldman of Texas</cosponsor>, <cosponsor name-id="G000568">Mr. Griffith</cosponsor>, <cosponsor name-id="B001306">Mr.
                    Balderson</cosponsor>, and <cosponsor name-id="F000482">Mrs.
                    Fedorchak</cosponsor>) introduced the following bill; which was referred to the
                    <committee-name committee-id="HIF00">Committee on Energy and
                    Commerce</committee-name>, and in addition to the Committee on <committee-name committee-id="HJU00">the Judiciary</committee-name>, for a period to be
                subsequently determined by the Speaker, in each case for consideration of such
                provisions as fall within the jurisdiction of the committee concerned</action-desc></action><legis-type>A BILL</legis-type><official-title display="yes">To establish a national framework for consumer privacy rights and the protection of personal data, and for other purposes.</official-title></form><legis-body id="H54E8507238384F92A1FC89628FD7CC1D" style="OLC"> 
<section id="H91D960EF3C3C40EE86CC29A9DEB70647" section-type="section-one"><enum>1.</enum><header>Short title</header> 
<subsection id="H6A612C1D211B40EE96CF5C358B76F83C"><enum>(a)</enum><header>Short title</header><text display-inline="yes-display-inline">This Act may be cited as the <quote><short-title>Securing and Establishing Consumer Uniform Rights and Enforcement over Data Act</short-title></quote> or the <quote><short-title>SECURE Data Act</short-title></quote>.</text></subsection> <subsection id="H942B345B4E084C96AC3B6CA0E0E5F968"><enum>(b)</enum><header>Table of contents</header><text>The table of contents for the Act is as follows:</text> 
<toc container-level="legis-body-container" quoted-block="no-quoted-block" lowest-level="section" regeneration="yes-regeneration" lowest-bolded-level="division-lowest-bolded"> 
<toc-entry idref="H91D960EF3C3C40EE86CC29A9DEB70647" level="section">Sec. 1. Short title.</toc-entry> 
<toc-entry idref="H70515CE339A24B898D2D0A0D63F587E6" level="section">Sec. 2. Consumer privacy rights.</toc-entry> 
<toc-entry idref="H87E0EE4082E74A52A26149AD10DF2D0F" level="section">Sec. 3. Controllers.</toc-entry> 
<toc-entry idref="HA1A60CFB2CD84E6BBFFEAA5D451E40DE" level="section">Sec. 4. Data security.</toc-entry> 
<toc-entry idref="H6894C65B3EDD4940B79AF39CA91452DB" level="section">Sec. 5. Data brokers.</toc-entry> 
<toc-entry idref="H699A96492DBA4043B3388A3811BC1A33" level="section">Sec. 6. Processors.</toc-entry> 
<toc-entry idref="HA528E552A8DC4A709BF067AD93D8E805" level="section">Sec. 7. Deidentified and pseudonymous data.</toc-entry> 
<toc-entry idref="H88CC677985D8444DA0642D61577F1E14" level="section">Sec. 8. Codes of conduct.</toc-entry> 
<toc-entry idref="HAF2DA6122A444E2CA3E828C4F1458DAD" level="section">Sec. 9. Cross-border data flows.</toc-entry> 
<toc-entry idref="HF54E04E7E9FF4442B5EB8ADFF964C000" level="section">Sec. 10. Study on universal opt-out mechanisms.</toc-entry> 
<toc-entry idref="HE6DD03DFDACD49A29BDBCEB4F2C728BE" level="section">Sec. 11. Rules of construction.</toc-entry> 
<toc-entry idref="HCE30CAF237804A569AA5B757D8F37E87" level="section">Sec. 12. Enforcement.</toc-entry> 
<toc-entry idref="H3BD3E4A448C04270A4349592C6B44EF4" level="section">Sec. 13. Applicability.</toc-entry> 
<toc-entry idref="HFF9AB678AB17451FB56D359BF0A5558E" level="section">Sec. 14. Relationship to Federal laws.</toc-entry> 
<toc-entry idref="H189AA95F2A784E9C896D48249C3881E1" level="section">Sec. 15. Relationship to State laws.</toc-entry> 
<toc-entry idref="HFCED349055924209B942CF3CA7E38370" level="section">Sec. 16. Definitions.</toc-entry> 
<toc-entry idref="HAD19B009353A404182680B284958DEB9" level="section">Sec. 17. Severability.</toc-entry> 
<toc-entry idref="HF29DAEBCC662459D89C140B602BA468A" level="section">Sec. 18. Effective dates.</toc-entry> </toc></subsection></section> 
<section id="H70515CE339A24B898D2D0A0D63F587E6"><enum>2.</enum><header>Consumer privacy rights</header> 
<subsection id="H2E4CCABD945A4682BAE1EE8C6F520484"><enum>(a)</enum><header>Consumer privacy rights</header><text>A consumer has the following privacy rights with respect to a controller:</text> <paragraph id="H7331A88EFF174599BC486264981918EB"><enum>(1)</enum><text>To confirm whether a controller is processing the personal data of the consumer and have access to a copy of such data, unless the confirmation and access would require the controller to reveal a trade secret.</text></paragraph> 
<paragraph id="H7C5E8C97FC2F4586BFDAEE32F7CBE3AD"><enum>(2)</enum><text>To correct any inaccuracy in the personal data of the consumer, taking into account the nature of the personal data and the purpose of processing the personal data.</text></paragraph> <paragraph id="H980C83E2DD8F4F6BA7CA4BF943D8B0C3"><enum>(3)</enum><text>To delete personal data provided by or obtained about the consumer.</text></paragraph> 
<paragraph id="H87CA647A4BC2478CA478CA0C3F3FCC23"><enum>(4)</enum><text>If the data is available in a digital format and to the extent technically feasible, to obtain a copy of the personal data that the consumer previously provided to the controller in a portable and readily usable format that allows the consumer to transmit the data to another controller without hindrance.</text></paragraph> <paragraph id="H511D827F0D504B059C6A3A036E0B986F"><enum>(5)</enum><text display-inline="yes-display-inline">To opt out of the processing of the personal data for the following purposes:</text> 
<subparagraph id="H57D56E6CA2CD4E8081AC6EABEEE4B20C"><enum>(A)</enum><text>Targeted advertising.</text></subparagraph> <subparagraph id="H0F0996D8EF394D2FA2FEDE97A20CED3D"><enum>(B)</enum><text>The sale of personal data.</text></subparagraph> 
<subparagraph id="HE693805B3F424EC2AFA08079FA0341A4"><enum>(C)</enum><text>Reliance on profiling to make a decision that has a legal or similarly significant effect on the consumer.</text> </subparagraph></paragraph></subsection> <subsection id="HB2A1779C29E5448680AFFD371C135343" display-inline="no-display-inline"><enum>(b)</enum><header>Consent required for processing sensitive data</header> <paragraph id="HF2EB12283D4D4111B0398B32B01BB324"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">Except as provided in paragraphs (2) and (3), a controller may not process the sensitive data of a consumer without obtaining the consent of the consumer before processing.</text></paragraph> 
<paragraph id="HBC67DD56513B4CD695A3DF9D81EA89C4"><enum>(2)</enum><header>Applicability to a child</header><text display-inline="yes-display-inline">Notwithstanding paragraph (1), a controller shall process the sensitive data of a child in accordance with the Children’s Online Privacy Protection Act of 1998 (15 U.S.C. 6501 et seq).</text></paragraph> <paragraph id="H745EF922268F4ED0B8C17560AD1DFD5B"><enum>(3)</enum><header>Applicability to a teen</header><text display-inline="yes-display-inline">Notwithstanding paragraph (1), a controller may not process the sensitive data of a teen without obtaining the verifiable consent of a parent of the teen.</text></paragraph></subsection> 
<subsection id="H2643553B917B4554BBE41B6FB836BCBF">
                <enum>(c)</enum>
                <header>Consumer privacy rights requests</header>
                <paragraph id="HD7873A07352444C6BF96EED1BEFEC139">
                    <enum>(1)</enum>
                    <header>Request for consumer rights</header>
 <text display-inline="yes-display-inline">A controller shall comply with any consumer privacy right described in subsection (a) once a consumer submits a request that specifies each consumer privacy right the consumer requests to exercise and the controller authenticates the consumer.</text>
                </paragraph>
                <paragraph id="HFF82D9EF31C94DD5AB8944B0D47DE32E">
                    <enum>(2)</enum>
                    <header>Child and teen consumer rights</header>
 <text display-inline="yes-display-inline">With respect to a consumer privacy right described in subsection (a) for a child or teen, only a parent of the child or teen may exercise such consumer privacy right on behalf of the child or teen.</text>
                </paragraph>
            </subsection> 
<subsection id="HA70685DEA6324814A538E90C8FCA410C"><enum>(d)</enum><header>Controller requirements</header> 
<paragraph id="H1620DA24488641409B88680460FFC1D0"><enum>(1)</enum><header>Deadline for response</header><text>Except as provided in paragraph (2), without undue delay and not later than 45 days after the date on which a consumer submits a request under subsection (c), a controller—</text> <subparagraph id="H7FF3777D6C074C7FAFAAD40C9E2C13F0"><enum>(A)</enum><text>shall respond to the consumer and comply with each privacy right requested; or</text></subparagraph> 
<subparagraph id="H4E34AE5435E54CF7BBDC10147C30ADEE"><enum>(B)</enum><text display-inline="yes-display-inline">shall provide a notice to the consumer that—</text> <clause id="H4E7847A9EC444F5680ABB692C0655318"><enum>(i)</enum><text>the controller declines to take action;</text></clause> 
<clause id="HE17C0B0B28B442C88C6C58B3C2DDD439"><enum>(ii)</enum><text>includes a justification for such inaction; and</text></clause> <clause id="HE117A5F3DB4A4D2D8153675DD80CFA38"><enum>(iii)</enum><text>includes instructions on how the consumer can appeal the decision of such inaction.</text></clause></subparagraph></paragraph> 
<paragraph id="HC6E405F7BF8D49CA96AED51644BFFCC6"><enum>(2)</enum><header>Extension of response period</header><text>The controller may extend the period described in paragraph (1)(A) an additional 45 days when reasonably necessary, taking into consideration the complexity and number of requests submitted by the consumer, if the controller informs the consumer of the extension during such period with the reason for such extension.</text></paragraph> <paragraph id="H2B9F0CDD37B245CDA4EBDA8D1A8FED4D"><enum>(3)</enum><header>Fees charged</header> <subparagraph id="HCB20D8517B784732BBD606852B873A12"><enum>(A)</enum><header>Free of charge</header><text display-inline="yes-display-inline">For each consumer privacy right described in subsection (a), a consumer may submit to each controller 2 requests under subsection (c) related to such consumer privacy right in a year free of charge.</text></subparagraph> 
<subparagraph id="H1E19EF7A886F4BF5ADBF5EA2DED5C1E3"><enum>(B)</enum><header>Reasonable fee for administrative cost</header><text>If a consumer submits more than 2 such requests or submits a request that is technically infeasible or manifestly unfounded, the controller may—</text> <clause id="H185BA8BB46A4484D8669BCC3E611EF53"><enum>(i)</enum><text display-inline="yes-display-inline">charge the consumer a reasonable fee to cover the administrative costs of complying with the request if the controller has notified the consumer of such fee and the consumer has consented to pay such fee; or</text></clause> 
<clause id="HAA8D6C9186A84543A708A7125FD8676D"><enum>(ii)</enum><text>decline to act on the request.</text></clause></subparagraph> <subparagraph id="H944A93B47BC3461E9704B381C91606F6"><enum>(C)</enum><header>Controller documentation required</header><text display-inline="yes-display-inline">The controller shall demonstrate, document, and provide to the Commission or a State attorney general, upon request, any technically infeasible or manifestly unfounded nature of any such request.</text></subparagraph></paragraph> 
<paragraph id="H5DCFF9FD3D1E487F90CD0C1C5388A66E"><enum>(4)</enum><header>Authentication</header><text>If a controller is unable to authenticate a consumer who submits a request under subsection (c), the controller is not required to comply with such request and may request that the consumer provide additional information reasonably necessary to authenticate the consumer and the request.</text></paragraph> <paragraph id="HCFBB5087ECFD480D8BC522E6042A2E2D"><enum>(5)</enum><header>Personal data obtained from third party</header><text>A controller that obtains personal data about a consumer from a source other than the consumer is considered to be in compliance with the request of a consumer under subsection (c) to delete that personal data under subsection (a)(3) by—</text> 
<subparagraph id="H86D0DEBF77EF422EA7EC0611C33BE255"><enum>(A)</enum><text>retaining a record of the deletion request and the minimum data necessary for the purpose of ensuring the personal data of the consumer remains deleted from the records of the controller and not using the retained data for any other purpose under this Act; or</text></subparagraph> <subparagraph id="H1F762CD6A5704988AD79A042D9A8E143"><enum>(B)</enum><text>opting the consumer out of the processing of that personal data for any purpose other than a purpose that is exempt under the provisions of this Act.</text></subparagraph></paragraph> 
<paragraph id="H8D3D5925B9184ECFB9676CF63D971406" commented="no"><enum>(6)</enum><header>Applicability to a child</header><text display-inline="yes-display-inline">With respect to a request of a consumer under subsection (c) for a child, a controller shall be deemed to be in compliance with such subsection if the controller responds to an equivalent consumer privacy right exercised by a parent under the Children’s Online Privacy Protection Act of 1998 (15 U.S.C. 6501 et seq).</text> </paragraph></subsection> <subsection id="H2D1E446EBB1E4F0589E8DD12C869A27A" commented="no"><enum>(e)</enum><header>Appeal process</header> <paragraph id="H36BE70BA770F45129E53F01DB6AD4560" commented="no"><enum>(1)</enum><header>Establishment of process</header><text display-inline="yes-display-inline">A controller shall establish a process for a consumer to appeal a determination by the controller to not take action under subsection (d)(1)(B).</text></paragraph> 
<paragraph id="HCDA571D808224D739C7613501804CB69" commented="no"><enum>(2)</enum><header>Availability</header><text>The appeal process established pursuant to paragraph (1) shall be conspicuously available and similar to the process for a request submitted under subsection (c).</text></paragraph> <paragraph id="H5578662D092E45BCA64861F3B57B6A80" commented="no"><enum>(3)</enum><header>Deadline to respond</header><text>Not later than 60 days after the date on which an appeal is received by a controller, the controller—</text> 
<subparagraph id="HA48AB30E0B414E9EA76CAE9993D46542"><enum>(A)</enum><text>shall inform the consumer in writing of any action taken or not taken in response to the appeal, including a written explanation of each reason for a decision; and</text></subparagraph> <subparagraph id="HDF8C92AD171F44DD87E822D121782CAA" commented="no"><enum>(B)</enum><text>if the appeal is denied, shall provide the consumer with an online mechanism, if available, or other method through which the consumer may contact the Commission or a State attorney general to submit a complaint.</text></subparagraph></paragraph></subsection> 
<subsection id="HB933DE6997BB471A8640B020AD458F33" commented="no" display-inline="no-display-inline"><enum>(f)</enum><header>Exercising consumer rights</header> 
<paragraph id="H2A1371DF4B6245D99159FB2167524D6C" commented="no"><enum>(1)</enum><header>Submission of requests</header><text display-inline="yes-display-inline">A controller shall establish and describe in a privacy notice one or more secure and reliable means for a consumer to submit a request to exercise consumer privacy rights described under subsection (a).</text> </paragraph> <paragraph id="H25D426AA863740DDA27E25399A2E8408" commented="no"><enum>(2)</enum><header>Considerations</header><text>In establishing the means pursuant to paragraph (1), a controller shall take into account the ways in which a consumer normally interacts with the controller, the need for secure and reliable communication of such requests, and the ability of the controller to authenticate the consumer making the request.</text></paragraph> 
<paragraph id="HC41BAAC5E677494F94280198AD2DCCE7" commented="no"><enum>(3)</enum><header>New accounts not required</header><text display-inline="yes-display-inline">A controller may not require a consumer to create a new account in order to exercise consumer privacy rights described under subsection (a) but may require a consumer to use an existing account.</text></paragraph></subsection></section> <section id="H87E0EE4082E74A52A26149AD10DF2D0F"><enum>3.</enum><header>Controllers</header> <subsection id="H2880219FE48F4E94BF14421325C815B1"><enum>(a)</enum><header>Data minimization</header><text>A controller shall limit the collection of personal data to what is adequate, relevant, and reasonably necessary in relation to each purpose for which the data is processed as disclosed to the consumer.</text></subsection> 
<subsection id="HC29F05663C404BC3B6662B9270086F2A"><enum>(b)</enum><header>Limitation on secondary uses</header><text>Except as otherwise provided in this section, a controller may not process personal data for any purpose that is not reasonably necessary or compatible with the disclosed purpose for which the personal data is processed as disclosed to the consumer, unless the controller obtains the consent of the consumer before any such processing.</text></subsection> <subsection id="H161B9D9B3617410CB7409FEE8BB76096" commented="no"><enum>(c)</enum><header>Civil rights</header><text>A controller may not process personal data in violation of a Federal law that prohibits unlawful discrimination against a consumer.</text></subsection> 
<subsection id="H7841E6CE14454C1BA59E01C936FF9860" commented="no">
                <enum>(d)</enum>
                <header>Non-Discrimination</header>
 <text>A controller may not discriminate against a consumer for exercising any consumer right described under section 2, including by denying goods or services, charging different prices or rates for goods or services, or providing a different level of quality of goods and services to the consumer.</text>
            </subsection> 
<subsection id="H583C279CE40C4C968C1FB5CAA58E2B75"><enum>(e)</enum><header>Consumer loyalty programs</header><text>Nothing in subsection (d) may be construed—</text> <paragraph id="H47D8AEE7C3B2437E93F9DF4165237D4C" commented="no"><enum>(1)</enum><text>to require a controller to provide a product or service that requires the personal data of a consumer that the controller does not collect or maintain; or</text></paragraph> 
<paragraph id="H07248961749C4AF7BEA2B83BE0B397F6"><enum>(2)</enum><text>to prohibit a controller from offering a different price, rate, level, quality, or selection of goods or services to a consumer, including offering goods or services for no fee, if the offer is related to the voluntary participation of a consumer in a bona fide loyalty, rewards, premium features, discounts, or club card program.</text></paragraph></subsection> <subsection id="H332CD6E62EA14E5A91144009AA6A2B45" commented="no"> <enum>(f)</enum> <header>Non-Waiver of consumer rights</header> <text display-inline="yes-display-inline">Beginning on the date of the enactment of this Act, any provision of a contract or agreement of any kind that waives or limits a consumer right described under section 2 shall be deemed contrary to public policy and shall be void and unenforceable.</text>
            </subsection> 
<subsection id="H06C37057A3244D93A8931E834083C44B"><enum>(g)</enum><header>Notice to consumers</header><text display-inline="yes-display-inline">Before processing the personal data of a consumer, a controller shall provide that consumer with a reasonably accessible, clear, and meaningful privacy notice that includes the following:</text> <paragraph id="HA92241B538DF4C18AD4B31934AB2AF6F"><enum>(1)</enum><text>Each category of personal data processed by the controller.</text></paragraph> 
<paragraph id="HC1A02DB9F4524FCF97D9B056F9BF19FE"><enum>(2)</enum><text>Each purpose for processing personal data.</text></paragraph> <paragraph id="HC0677E51483847CAB65E7F990A9C73E5"><enum>(3)</enum><text display-inline="yes-display-inline">How a consumer may exercise a consumer right described under section 2, including how a consumer may appeal the decision of a controller under section 2(d).</text></paragraph> 
<paragraph id="H084758E724F54BAFA53D6A4175CDAD58"><enum>(4)</enum><text>Each category of personal data the controller shares with any other controller or any governmental entity.</text></paragraph> <paragraph id="H043BE1EAD33E492487E3754B2F948674"><enum>(5)</enum><text>Each category of other controllers or any governmental entity, if any, with whom the controller shares personal data.</text></paragraph> 
<paragraph id="HCE7FDDC46F6448299D38BC31DE5018A7"><enum>(6)</enum><text>Whether any personal data processed by the controller is transferred to, processed in, stored in, or sold to a covered nation.</text></paragraph></subsection> <subsection id="HFBDBC8B6422646B5B214FED8777C5074"><enum>(h)</enum><header>Disclosure of sale</header><text>If a controller sells personal data of a consumer, the controller shall clearly and conspicuously disclose—</text> 
<paragraph id="HA4BCC5D20E4043F4AB801C8B8E5028DC"><enum>(1)</enum><text>such activity before any collection or sale of personal data; and</text></paragraph> <paragraph id="H9BB482556D354DDAB2B52BB954434A27"><enum>(2)</enum><text>the manner in which a consumer may exercise the right to opt out of the sale of such personal data under section 2(a)(5).</text></paragraph></subsection> 
<subsection id="H76CF0B08AFD74559AAF9BB1BF4CB219F"><enum>(i)</enum><header>Disclosure of targeted advertising</header><text display-inline="yes-display-inline">If a controller processes personal data of a consumer for targeted advertising, the controller shall clearly and conspicuously disclose—</text> <paragraph id="H498CC2C82854456189036BD13337E9E3"><enum>(1)</enum><text>such activity before any collection or use of personal data; and</text></paragraph> 
<paragraph id="H9C015CCBE61E40A297F547530675F608"><enum>(2)</enum><text>the manner in which a consumer may exercise the right to opt out of such processing under section 2(a)(5).</text></paragraph></subsection> <subsection id="HAF685207121A46B4819F006570CE228E"><enum>(j)</enum><header>Automated decision making</header> <paragraph id="H7FB016E92EF346D897D75A450C264186"><enum>(1)</enum><header>Profiling</header><text>A controller that relies on profiling to make a decision that has a legal or similarly significant effect on a consumer shall clearly and conspicuously disclose to such consumer before any such decision is made that—</text> 
<subparagraph id="H64E8A676EE554DAE9D3BAE8BA38AA7C8"><enum>(A)</enum><text>the decision will be made using automated means; and</text></subparagraph> <subparagraph id="H7074F08F0ABA4F3D8448288C01233711"><enum>(B)</enum><text display-inline="yes-display-inline">the manner in which a consumer may exercise the right to opt out of such profiling.</text></subparagraph></paragraph> 
<paragraph id="HC57815AF00D74227BF30A83ABE3835C0"><enum>(2)</enum><header>Reliance on profiling</header><text display-inline="yes-display-inline">For purposes of paragraph (1) and section 2(a)(5), a controller relies on profiling to make a decision that has a legal or similarly significant effect on a consumer if such decision is made with no human review, involvement, oversight, or intervention.</text> </paragraph></subsection> </section> <section id="HA1A60CFB2CD84E6BBFFEAA5D451E40DE"><enum>4.</enum><header>Data security</header> <subsection id="H67172A45180846CD8EF4BC38B095F7D9" commented="no"><enum>(a)</enum><header>Data security</header><text display-inline="yes-display-inline">A controller shall establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data and that are appropriate to the volume, sensitivity, and nature of such personal data.</text> </subsection> 
<subsection id="H9B42A6E130F346F1ABC0E6CF51305B25" commented="no"><enum>(b)</enum><header>Rebuttable presumption</header><text>A controller has a rebuttable presumption to an alleged violation of this section if—</text> <paragraph id="H86806F6657B9484E8DAE38291F198356" commented="no"><enum>(1)</enum><text display-inline="yes-display-inline">the controller complies with a relevant code of conduct approved under section 8(a)(3) (or a relevant certification described in section 8(f)); or</text> </paragraph> 
<paragraph id="H123B45DF37124C13946657FF36E13B29" commented="no"><enum>(2)</enum><text display-inline="yes-display-inline">the controller has established, implemented, and maintained—</text> <subparagraph id="HBF80BB31A43F4024924F59FCCB7B03C1"> <enum>(A)</enum> <text>data security practices appropriate to the state-of-the-art in administrative, technical, and physical data security practices for the protection of the confidentiality, integrity, and accessibility of personal data, including such a practice demonstrated by adherence to a widely accepted technical specification or through a third-party attestation; and</text>
                    </subparagraph> 
<subparagraph id="H541A2A60FEAA4C7898EB9EE82AFFADB2" commented="no">
                        <enum>(B)</enum>
 <text>a comprehensive data security program that reasonably conforms to a relevant Federal or widely accepted international risk management framework for identifying and protecting against data security risks, and for detecting, responding to, and recovering from data security events.</text>
                    </subparagraph></paragraph> </subsection></section> 
<section id="H6894C65B3EDD4940B79AF39CA91452DB"><enum>5.</enum><header>Data brokers</header> 
<subsection id="HEF995A0B7D364DB48404C07542C00272"><enum>(a)</enum><header>Disclosure</header><text display-inline="yes-display-inline">A data broker shall post on a publicly available website or mobile application a conspicuous notice that—</text> <paragraph id="H9FB73943BC514FF09E62D8E0CD42E9FE"><enum>(1)</enum><text>states that the entity maintaining the website or application is a data broker;</text></paragraph> 
<paragraph id="H2D976DE9F6094DC9949138D2181E1CF1"><enum>(2)</enum><text>is clear, not misleading, and readily accessible by the public; and</text></paragraph> <paragraph id="H71B1C270EA7C46838AD8F42DDD66AF3F"><enum>(3)</enum><text display-inline="yes-display-inline">informs a consumer how to exercise any consumer right described under section 2.</text></paragraph></subsection> 
<subsection id="H2888D61337A643B58169DFFAA913295C"><enum>(b)</enum><header>Registration</header><text>Not later than 12 months after the date of the enactment of this Act, and annually thereafter, a data broker shall register with the Commission by filing a registration statement and paying a reasonable registration fee set by the Commission that includes the following information:</text> <paragraph id="H4F2C7EAFAEDF4ADD967F44AFA39A19A8"><enum>(1)</enum><text>The legal name of the data broker.</text></paragraph> 
<paragraph id="H16866765E0A849F39195C0A581887DC1">
                    <enum>(2)</enum>
 <text>A contact person and the primary physical address, email address, telephone number, and website address for the data broker.</text>
                </paragraph> 
<paragraph id="HAE4E6BF62113407BA7D2D5E6656BCEB3"><enum>(3)</enum><text>A description of each category of personal data sold by the data broker.</text></paragraph> <paragraph id="H1C180C912A1049A4BFF57653A84FD82F"><enum>(4)</enum><text>A statement of whether the data broker implements a purchaser credentialing process.</text></paragraph> 
<paragraph id="H1F27E3C475A14CC3A5D70CDEBAFD3782"><enum>(5)</enum><text display-inline="yes-display-inline">A description of any incident of unauthorized access to personal data that the data broker has reported to a Federal or State governmental entity pursuant to an applicable law, rule, or regulation during the year before the year in which the registration is filed, and if known, the total number of consumers affected by each previously reported incident of such unauthorized access.</text></paragraph> <paragraph id="H4BF9A0FDE5154F05BB79362E13766990"><enum>(6)</enum><text display-inline="yes-display-inline">A link to the privacy policy published in accordance with section 3(g).</text></paragraph> 
<paragraph id="H751D4ABC19CE419B91E59BD1BF1F4180"><enum>(7)</enum><text display-inline="yes-display-inline">A link to a website published by the data broker that informs a consumer how to exercise any consumer right described under section 2.</text></paragraph></subsection> <subsection id="HDE5AA669C08B41469A97EE1A66C6C974"><enum>(c)</enum><header>Data broker registry</header><text display-inline="yes-display-inline">Not later than 18 months after the date of the enactment of this Act, the Commission shall establish and maintain on a publicly available website of the Commission a searchable, central registry of data brokers registered under subsection (b) that includes the following:</text> 
<paragraph id="H9CF6DB98A741446FB3DE5A4EA28313C4"><enum>(1)</enum><text>A search feature that allows a person searching the registry to identify a data broker.</text></paragraph> <paragraph id="H48C4259178D8464584C95CAA3CA69144"><enum>(2)</enum><text display-inline="yes-display-inline">For each data broker, a link to the privacy policy published in accordance with section 3(g).</text></paragraph> 
<paragraph id="H125784D59F874BEAAC2B7FDA8FED1B4C"><enum>(3)</enum><text display-inline="yes-display-inline">For each data broker, a link to a website published by the data broker that informs a consumer how to exercise any consumer right described under section 2.</text></paragraph></subsection></section> <section id="H699A96492DBA4043B3388A3811BC1A33"><enum>6.</enum><header>Processors</header> <subsection id="HE8AE6D1A15C24A12AC3C3AC0539DD6F4"><enum>(a)</enum><header>Adherence to controller instructions</header><text display-inline="yes-display-inline">A processor shall adhere to the instructions of a controller and shall assist the controller in meeting the requirements of this Act, including by taking into account the nature of processing and the information available to the processor—</text> 
<paragraph id="H3637B0F568B44EE8B845913D531FFFF4"><enum>(1)</enum><text display-inline="yes-display-inline">by appropriate administrative and technical measures, insofar as reasonably practicable, to fulfill the requirements of the controller to respond to an assertion of any consumer right described under section 2; and</text></paragraph> <paragraph id="H61372FFFFAAC4536A39FDA23FFF2AC03"><enum>(2)</enum><text>by assisting the controller in meeting the requirements of the controller under section 4.</text></paragraph></subsection> 
<subsection id="H21B0792DCF5949F0BCAB3162D0D75BFF" commented="no"><enum>(b)</enum><header>Contractual obligation</header><text display-inline="yes-display-inline">A contract between a controller and a processor shall govern the data processing procedures of the processor with respect to processing performed on behalf of the controller. The contract shall clearly set forth instructions for processing personal data, the nature and purpose of processing, the type of personal data subject to processing, the duration of processing, and the rights and obligations of both parties.</text></subsection> <subsection id="HFA99304EF7504810953609DB6A304F62"><enum>(c)</enum><header>Minimum requirements</header><text>At a minimum, the contract between a controller and processor shall include requirements that the processor does the following:</text> 
<paragraph id="HD5298C7388F840C8B12844B78B1123DB"><enum>(1)</enum><text>Ensures that each person processing personal data is subject to a duty of confidentiality with respect to the data.</text></paragraph> <paragraph id="H16280F0163E94770936B79C9F7184F92"><enum>(2)</enum><text>At the direction of the controller, deletes or returns all personal data to the controller as requested at the end of the provision of services, unless retention of the personal data is required by law.</text></paragraph> 
<paragraph id="HBEDD4499BC1646C4836C58CCEB19C764"><enum>(3)</enum><text>Upon the reasonable request of the controller, makes available to the controller all information in the possession of the processor necessary to demonstrate compliance by the processor with the requirements of this Act.</text></paragraph> <paragraph id="HDEDD70B03E374263A3597045F94AE077" commented="no"><enum>(4)</enum><text>Either—</text> 
<subparagraph id="H12137A175E7E4DEE9F50AD30CC9349EB" commented="no"><enum>(A)</enum><text>allows and cooperates with reasonable assessments by the controller or a designated assessor by the controller; or</text></subparagraph> <subparagraph id="H9ED07013D75944598646EEDF5946B1ED" commented="no"><enum>(B)</enum><text display-inline="yes-display-inline">the processor—</text> 
<clause id="HDE742DFD76534818A6A14F36B4B74AB9" commented="no"><enum>(i)</enum><text>arranges for a qualified and independent assessor to conduct an assessment of the policies and administrative and technical measures of such processor that meet the requirements of this Act using an appropriate and accepted control standard or framework and assessment procedure for such assessment; and</text></clause> <clause id="HF7C5CE48BAC74CC793DEBAE088B527DC" commented="no"><enum>(ii)</enum><text>provides a report of the assessment to the controller upon request.</text></clause></subparagraph></paragraph> 
<paragraph id="HD459520518FE4BE4B27BF916288F93E0"><enum>(5)</enum><text>If a processor engages a subcontractor, include in any subcontract a requirement that the subcontractor meet the obligations of the processor with respect to the personal data.</text></paragraph></subsection> <subsection id="H41DBD065CDD544E681D3AB4DB6C8FF3C"><enum>(d)</enum><header>Rule of construction</header><text display-inline="yes-display-inline">Nothing in this section may be construed to relieve a controller or processor from any liability imposed on the controller or processor by virtue of a role in a processing.</text> </subsection> 
<subsection id="HF36E1BA6F9F347F0AD7540477BDC2AF8" commented="no"><enum>(e)</enum><header>Applicability</header> 
<paragraph id="H8D4EF8B17A60413FAD2C545DD4F97470" commented="no"><enum>(1)</enum><header>Controller or processor</header><text display-inline="yes-display-inline">The determination about whether a person is acting as a controller or processor with respect to a specific processing of personal data is a fact-based determination that depends upon the context in which personal data is to be processed.</text></paragraph> <paragraph id="H3D3A71A576CB47B9AE5A0630B6CBB6BB"><enum>(2)</enum><header>Controller</header><text display-inline="yes-display-inline">If a processor, alone or jointly with others, begins determining the purpose and means of processing personal data, such processor is a controller with respect to a specific processing of such personal data.</text></paragraph> 
<paragraph id="H39983D90C0F64095B5DCCA9322D5616C" commented="no"><enum>(3)</enum><header>Processor</header><text>A processor that follows the instructions of a controller with respect to a specific processing of personal data remains a processor.</text></paragraph></subsection></section> <section id="HA528E552A8DC4A709BF067AD93D8E805"><enum>7.</enum><header>Deidentified and pseudonymous data</header> <subsection id="HF0392BFDDCAF4B4789A2AF089726669F"><enum>(a)</enum><header>In general</header><text>A controller in possession of deidentified data shall—</text> 
<paragraph id="HE39F7919E33B49568AB5C0574A153F84"><enum>(1)</enum><text>take reasonable measures to ensure the data cannot be associated with an individual;</text></paragraph> <paragraph id="HD6A9274EB7E44F4C8789C85DB376DCAC"><enum>(2)</enum><text>publicly commit to maintain and use deidentified data without attempting to re-identify the data; and</text></paragraph> 
<paragraph id="H910309A4A8564AB5B0AAA33C74209811"><enum>(3)</enum><text>contractually obligate any recipient of the deidentified data to comply with each requirement of this Act.</text></paragraph></subsection> <subsection id="H707E36639EA74A30AEA0B53749465C0A"><enum>(b)</enum><header>Ongoing compliance</header><text>A controller that discloses deidentified or pseudonymous data shall exercise reasonable oversight to monitor compliance with any contractual commitment to which the deidentified or pseudonymous data is subject and shall take appropriate steps to address any breach of such contractual commitment.</text></subsection> 
<subsection id="HE4EC1A660DF841719860CAB2045F00B7"><enum>(c)</enum><header>Pseudonymous data</header><text display-inline="yes-display-inline">An assertion of any consumer right described under section 2 does not apply to pseudonymous data for a case in which the controller is able to demonstrate any information necessary to identify the consumer is kept separately and is subject to appropriate administrative and technical measures to ensure that the personal data is not attributed to an identified or identifiable natural person.</text></subsection> <subsection id="H5AE5D8B842434E57847DACA6C01FAD77"><enum>(d)</enum><header>Rule of construction relating to deidentified or pseudonymous data</header><text>Nothing in this Act may be construed to require a controller or processor to—</text> 
<paragraph id="H2CBA29001B274615ADEF78DB2A043DD0"><enum>(1)</enum><text>re-identify deidentified data or pseudonymous data; or</text></paragraph> <paragraph id="HF6A5E3AF0BE447C0A2F65678110F813F"><enum>(2)</enum><text>maintain data in identifiable form, or collect, obtain, retain, or access any data or technology, in order to be capable of associating a consumer request with personal data.</text></paragraph></subsection> 
<subsection id="HBE76C8EC717F453B9AC553946131B770"><enum>(e)</enum><header>Rule of construction relating to consumer rights requests</header><text display-inline="yes-display-inline">Nothing in this Act may be construed to require a controller or processor to comply with an assertion of any consumer right described under section 2 if—</text> <paragraph id="H74F4503F5FCD45CB8157BB956587D354"><enum>(1)</enum><text>the controller is not reasonably capable of associating the request with the personal data or it would be unduly burdensome for the controller to associate the request with the personal data;</text></paragraph> 
<paragraph id="HFA719FAD52A2470DB2733C18547BB604" commented="no"><enum>(2)</enum><text>the controller does not use the personal data to recognize or respond to the specific consumer who is the subject of the personal data, or associate the personal data with other personal data about the same specific consumer; and</text></paragraph> <paragraph id="H342FEE5A811142709B7DC104DE346A37"><enum>(3)</enum><text display-inline="yes-display-inline">the controller does not sell the personal data to another controller or otherwise voluntarily disclose the personal data to any entity other than a processor, except as otherwise permitted in this section.</text> </paragraph></subsection></section> 
<section id="H88CC677985D8444DA0642D61577F1E14"><enum>8.</enum><header>Codes of conduct</header> 
<subsection id="H940D124A26FE4EF59D2D56FD213E0B63"><enum>(a)</enum><header>Application for approval of code of conduct</header> 
<paragraph id="HD98AA04DA0104582AB6F8CAAA952EC3C"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">A controller or processor (or a group of controllers or processors) may submit to the Secretary an application for approval of a code of conduct that meets or exceeds the requirements of the controller or processor (or the group of controllers or processors) under this Act.</text></paragraph> <paragraph id="H7C1D4D34756E47F9A4E9DB79A6264FCB"><enum>(2)</enum><header>Application requirements</header><text>An application submitted under paragraph (1) shall include the following:</text> 
<subparagraph id="H0D02709E87EA4E078F0FE1974BA10749"><enum>(A)</enum><text>A description of the specific requirements of this Act to which the code of conduct proposed in the application will apply.</text></subparagraph> <subparagraph id="H4E3DC5685D7F4A2887BE29F72BB1AF70"><enum>(B)</enum><text>A description of how the code of conduct will meet or exceed such requirements.</text></subparagraph> 
<subparagraph id="HFA0B5BEFEE1F411CB78DDE207DA0E132"><enum>(C)</enum><text>A description of the entities the code of conduct is designed to cover.</text></subparagraph> <subparagraph id="H0224BEF1C8E24F9D9013184843EDF71B"><enum>(D)</enum><text>A list of the controllers or processors, to the extent known at the time of application, that intend to comply with the code of conduct.</text></subparagraph> 
<subparagraph id="H0434ED99E57C4D2BADC7C6C4E2285989"><enum>(E)</enum><text display-inline="yes-display-inline">A description of the independent organization that will administer the code of conduct with respect to controllers or processors, including an explanation of how the independent organization is governed.</text></subparagraph> <subparagraph id="H9FF8DA138D434765A844F8AB39E8A926"><enum>(F)</enum><text>A description of how the entities described in subparagraph (C) will be assessed for compliance with the code of conduct by the independent organization described in subparagraph (E).</text></subparagraph> 
<subparagraph id="H0C6E8158C84947959FCB4F353D54E895" commented="no"><enum>(G)</enum><text>A description of how the independent organization will refer to the Commission or to a State attorney general any controller or processor that does not—</text> <clause id="H39B0D46CAF3B4474A66444A5F6020384" commented="no"><enum>(i)</enum><text>meet the requirements of this Act; or</text></clause> 
<clause id="HB436C789630841F595ED78F03236E429" commented="no"><enum>(ii)</enum><text>meet or exceed the requirements of the Act in accordance with the certification publicly disclosed by the controller or processor under subsection (c).</text> </clause></subparagraph></paragraph> <paragraph id="H0EACD52CB06546298147E3A24D17D348"><enum>(3)</enum><header>Review by Secretary</header> <subparagraph id="H9ED0FC08F60D40038EE3E6D38FA089DA"><enum>(A)</enum><header>Initial approval</header> <clause id="H2CB4E4DB9E1B445B98DFC234667E4C97"><enum>(i)</enum><header>Public comment period</header><text>Not later than 90 days after the date on which the Secretary receives an application submitted under paragraph (1), the Secretary shall publish the application and provide an opportunity for public comment on the code of conduct proposed in the application.</text></clause> 
<clause id="H4711FDAC91C9472C9A3DFEFBF23A00B3"><enum>(ii)</enum><header>Approval criteria</header><text display-inline="yes-display-inline">The Secretary, in consultation with the Commission, shall approve an application submitted under paragraph (1), including the independent organization that will administer the code of conduct, if the controller or processor (or the group of controllers or processors) that submits the application demonstrates that the code of conduct proposed in the application meets the following criteria:</text> <subclause id="H81A962EAEAFA434C80255546E1F827EE"><enum>(I)</enum><text>Meets or exceeds the relevant requirements of this Act.</text></subclause> 
<subclause id="H6CED9E25B6BE4059A6737F9832391FE7" commented="no"><enum>(II)</enum><text>Provides for regular review and validation by the independent organization to ensure that the controller or processor (or the group of controllers or processors) that complies with the code of conduct continues to meet or exceed the relevant requirements of this Act.</text> </subclause> <subclause id="H22991535A17D41E8A059588D2C3B14C5"><enum>(III)</enum><text>Includes referral to the Commission for enforcement or referral to the appropriate State attorney general for enforcement.</text> </subclause></clause> 
<clause id="H05A8B400E3B8435491D1EF826CCD2EC3"><enum>(iii)</enum><header>Timeline</header><text>Not later than 1 year after the date on which the Secretary receives an application submitted under paragraph (1), the Secretary shall issue a public determination approving or denying the application and providing the reasons for such approval or denial.</text></clause></subparagraph> <subparagraph id="H0519D830F30A435AAD978C51CF75714A"><enum>(B)</enum><header>Approval of modifications</header> <clause id="H05F4FDB54DC24A039448CA2D4A8BAE44"><enum>(i)</enum><header>In general</header><text>If an independent organization that administers a code of conduct approved under subparagraph (A) makes significant updates to the code of conduct—</text> 
<subclause id="HE4C551BD1BEB49809651E83C6D503276"><enum>(I)</enum><text display-inline="yes-display-inline">the independent organization shall submit to the Secretary an application for approval of the significant updates made to the code of conduct; and</text></subclause> <subclause id="H40FCF888978340F994EF8B34F1E9A7F4"><enum>(II)</enum><text display-inline="yes-display-inline">not later than 90 days after the date on which the Secretary receives an application for an updated code of conduct submitted under subclause (I), the Secretary shall publish the proposed updated code of conduct and provide an opportunity for public comment.</text></subclause></clause> 
<clause id="H6E1BEC6CF6E44CFBB65EB90F839275F5"><enum>(ii)</enum><header>Timeline</header><text>Not later than 180 days after the date on which the Secretary receives an application for an updated code of conduct submitted under clause (i)(I), the Secretary, considering the approval criteria described in subparagraph (A)(ii), shall issue a public determination approving or denying the application and providing the reasons for such approval or denial.</text></clause></subparagraph></paragraph></subsection> <subsection id="HAEE7318BB3A1467D8F4DC840C6AE3A1E"><enum>(b)</enum><header>Withdrawal of approval</header> <paragraph id="H27782DF954254F45AE8BACA255031AE0"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">If the Secretary has clear and convincing evidence that a code of conduct approved under subsection (a)(3) no longer meets the relevant requirements of this Act or that compliance with the code of conduct is insufficiently assessed by the independent organization that administers the code of conduct, the Secretary shall notify the relevant controller or processor (or the relevant group of controllers or processors) and the independent organization of a potential withdrawal of approval by the Secretary and of the opportunity to cure any alleged deficiency under paragraph (2).</text> </paragraph> 
<paragraph id="HC4F8D6F250D043828FBE306E7265F4B3"><enum>(2)</enum><header>Opportunity to cure</header> 
<subparagraph id="HA297C8030C3E459A9EB10CEFD9D51CD7"><enum>(A)</enum><header>In general</header><text>Not later than 180 days after the date on which a controller or processor (or a group of controllers or processors) receives the notice described in paragraph (1), the controller or processor (or the group of controllers or processors) and the relevant independent organization may—</text> <clause id="H7864B6AD68954A28802D0F822ABE9BCB"><enum>(i)</enum><text>create a proposed cure to any alleged deficiency of the code of conduct or the enforcement of the code of conduct; and</text></clause> 
<clause id="H39D90B30316A47859A245DA67AB1E5B8"><enum>(ii)</enum><text>submit each such proposed cure to the Secretary.</text></clause></subparagraph> <subparagraph id="H3B4044A422BB4963BA480A2F432DDCD2"><enum>(B)</enum><header>Review of proposed cure</header><text>If the Secretary determines within 60 days that a proposed cure submitted under subparagraph (A)(ii) eliminates an alleged deficiency of the code of conduct or the assessment of compliance with the code of conduct, the Secretary may not withdraw the approval of such code of conduct on the basis of such deficiency.</text></subparagraph></paragraph> 
<paragraph id="HD40B0BF0F477458D9712101F067C8782"><enum>(3)</enum><header>Withdrawal of approval</header> 
<subparagraph id="H45141E606F8349CA910C0E84F4E48A94"><enum>(A)</enum><header>Determination</header><text>If the Secretary determines that a proposed cure submitted under subparagraph (A)(ii) does not eliminate an alleged deficiency of the code of conduct or the assessment of compliance with the code of the conduct, the Secretary may withdraw approval of such code of conduct on the basis of such deficiency.</text></subparagraph> <subparagraph id="H4DBFA604DB954920B1300D2CF2039260"><enum>(B)</enum><header>Notification</header><text>Not later than 10 days after the date on which the Secretary makes a determination under subparagraph (A), the Secretary shall notify the relevant controller or processor (or the relevant group of controllers or processors) and the independent organization of the relevant withdrawal of approval described in subparagraph (A).</text></subparagraph> 
<subparagraph id="HE1D5E43536D34802991F4B9EAE314A93"><enum>(C)</enum><header>Effect</header><text>A withdrawal of approval described in subparagraph (A) shall take effect on the date that is 30 days after the date on which the Secretary provides the notification required by subparagraph (B).</text></subparagraph> <subparagraph id="H0E5ED47A4FC84CC18A1DFBBD3CC9F8A1"> <enum>(D)</enum> <header>Publication</header> <text display-inline="yes-display-inline">Not later than 30 days after the date on which the Secretary provides notification required by subparagraph (B), the Secretary shall publish on a publicly available website a notice about the relevant withdrawal of approval described in subparagraph (A).</text>
                    </subparagraph></paragraph></subsection> 
<subsection id="H713CF7AAF714408C9B485C6D8B893CA2"><enum>(c)</enum><header>Public disclosure</header><text display-inline="yes-display-inline">A controller or processor that participates in a code of conduct approved under subsection (a)(3) shall certify on a publicly available website that the controller or processor is in compliance with the code of conduct, including by listing the independent organization that administers the code of conduct.</text> </subsection> <subsection id="H18C8774A35324F14AD179CCB324FC4E3"><enum>(d)</enum><header>Rebuttable presumption</header><text display-inline="yes-display-inline">A controller or processor that complies with a relevant code of conduct approved under subsection (a)(3) (or a relevant certification described in subsection (f)) shall be entitled to a rebuttable presumption that the controller or processor is in compliance with the relevant requirements of this Act to which the code of conduct (or certification) applies.</text></subsection> 
<subsection id="H183AF4D8CE88477B8D20BC18187ED44D"><enum>(e)</enum><header>Codes of conduct for small businesses</header> 
<paragraph id="H8A4095AE0D1E47848E2401D8FA7BAA01"><enum>(1)</enum><header>In general</header><text>Not later than 2 years after the date of the enactment of this Act, the Secretary shall publish codes of conduct for businesses that otherwise would be persons to whom this Act applies but that do not meet the applicability requirements described in section 13(a)(2).</text> </paragraph> <paragraph id="H042D4DC15E504451A4B3A402E2733CA4"><enum>(2)</enum><header>Procedures</header><text>In carrying out paragraph (1), the Secretary shall—</text> 
<subparagraph id="HDB64A7CEEFA849CD8CAB24CDEADC7C8C"><enum>(A)</enum><text>follow the same procedures described in subsections (a) and (b); and</text></subparagraph> <subparagraph id="H110349CD113C485384410153A2DC6E99"><enum>(B)</enum><text>solicit independent organizations to administer the codes of conduct.</text></subparagraph></paragraph> 
<paragraph id="H52D2A8F7DA1448ED986FC22C2C015DEA"><enum>(3)</enum><header>Requirements for code of conduct</header><text>A code of conduct published under paragraph (1) shall meet the following requirements:</text> <subparagraph id="H076E4BA30F5E40C0A61BE4A5985A677D"><enum>(A)</enum><text>Be consistent with the requirements of this Act.</text></subparagraph> 
<subparagraph id="HABEC2B50C61545BF9D8F3730A05B112F"><enum>(B)</enum><text display-inline="yes-display-inline">Be cost-effective for any participant in the code of conduct.</text></subparagraph> <subparagraph id="H206E9AE741B64838BB1CB267DC8944B2"><enum>(C)</enum><text>Be appropriate to the risks, size, and limitations of any such participant.</text></subparagraph></paragraph> 
<paragraph id="H517A79B22547454CB0B90DFF408EDB79"><enum>(4)</enum><header>Voluntary participation</header><text>Participation in a code of conduct published under paragraph (1) shall be voluntary.</text></paragraph> <paragraph id="HA5DAE7C98E7741B6BE700B7CC48E5083"><enum>(5)</enum><header>Requirements for participation</header><text>A participant in a code of conduct published under paragraph (1) shall publicly self-certify that the participant is in compliance with the code of conduct, including by listing the independent organization that administers the code of conduct.</text> </paragraph></subsection> 
<subsection id="H5D492EBB83514FE29C3DA9A123AB1A7A" display-inline="no-display-inline">
                <enum>(f)</enum>
                <header>Cross-Border privacy rules system</header>
 <text>A certification by a controller pursuant to the Global Cross Border Privacy Rules System, or any successor system, or a certification by a processor pursuant to the Global Cross Border Privacy Rules System Privacy Recognition for Processors, or any successor system, shall be treated as participation in a code of conduct approved under subsection (a)(3).</text>
            </subsection></section> 
<section id="HAF2DA6122A444E2CA3E828C4F1458DAD"><enum>9.</enum><header>Cross-border data flows</header> 
<subsection id="HFD3857570E1D4C96AADD6937AA730396" commented="no"><enum>(a)</enum><header>Principal advisor</header><text>The Secretary shall serve as the principal advisor to the President on policy relating to the international flow of personal data and the protection of personal data in international commerce.</text> </subsection> <subsection id="HEB6A474288794A51BEE270AAC63432C7"><enum>(b)</enum><header>Duties</header><text display-inline="yes-display-inline">The Secretary shall take any action necessary and appropriate to support the international flow of personal data and the protection of personal data in international commerce, including the following:</text> 
<paragraph id="HA2BF2A08F1934F889C5B8433545137B8"><enum>(1)</enum><text>Assessing the laws, regulations, requirements, frameworks, and practices (and the implementation thereof) of foreign governments for—</text> <subparagraph id="HF20D0DC1BC5C41699D17593B0F25CCDA"><enum>(A)</enum><text display-inline="yes-display-inline">alignment with the consumer rights and protections of personal data described in this Act;</text></subparagraph> 
<subparagraph id="H922374508C9E47089DC624F1071954B8" commented="no"><enum>(B)</enum><text display-inline="yes-display-inline">any impact on consumers and businesses in the United States, including with respect to economic competitiveness, innovation, and data security; and</text> </subparagraph> <subparagraph id="HD6134DFEC73D4EC48187406A9019AE76"><enum>(C)</enum><text>any impact on the economic and security interests of the United States.</text></subparagraph></paragraph> 
<paragraph id="H3864C0D549FB462B97FC1E3FA95ADB5A"><enum>(2)</enum><text>Developing policy and recommendations relating to—</text> <subparagraph id="H043434D0C5C54DB4A37F15C8467C81A3"><enum>(A)</enum><text display-inline="yes-display-inline">identifying the benefits of the international flow of personal data to consumers and businesses, including economic competitiveness, innovation, and data security;</text></subparagraph> 
<subparagraph id="HDE5D8FD535854B8C95F075BFCE4A5B07"><enum>(B)</enum><text display-inline="yes-display-inline">addressing any negative impact on consumers and businesses in the United States of laws, regulations, requirements, frameworks, and practices (and the implementation thereof) of foreign governments that limit or restrict the international flow of personal data;</text></subparagraph> <subparagraph id="H7C13E149CF1642A48E7E4DDB622974E7"><enum>(C)</enum><text display-inline="yes-display-inline">promoting the protection of personal data in a manner that maintains the international flow of personal data in international commerce; and</text></subparagraph> 
<subparagraph id="H23A2AF2BAD504EEBB474FFA803342B80"><enum>(D)</enum><text display-inline="yes-display-inline">mitigating the risk posed by covered nations to the international flow of personal data and the protection of personal data in international commerce.</text></subparagraph></paragraph> <paragraph id="H7959CB7B9A2141D696446E752044A7FB"><enum>(3)</enum><text>Establishing, maintaining, and promoting frameworks, certifications, principles, and partnerships to facilitate the international flow of personal data for commercial purposes and the protection of personal data in international commerce.</text></paragraph> 
<paragraph id="HF04285E4BD7A418C9126074E8F3D0D9E"><enum>(4)</enum><text>Coordinating with any relevant agency as needed.</text></paragraph></subsection> <subsection id="H3E896582E4A1438F826577F4E8F157E5"><enum>(c)</enum><header>International cooperation</header> <paragraph id="H4F6C11A5DD4741699E157E11EE68D7D0"><enum>(1)</enum><header>Authority to enter agreement</header><text display-inline="yes-display-inline">The Secretary, as the Secretary determines appropriate, may enter into an agreement with a foreign government, international forum, or foreign political or economic union to promote the international flow of personal data and the protection of personal data in international commerce.</text></paragraph> 
<paragraph id="H6A8718901E544578BEB5FB045545C30B"><enum>(2)</enum><header>Requirements for agreement</header><text>Any agreement entered into pursuant to paragraph (1)—</text> <subparagraph id="HEF7ACFFAF87148F387130222DDCD21FB"><enum>(A)</enum><text display-inline="yes-display-inline">may not have provisions that conflict with the protections for personal data described in this Act;</text></subparagraph> 
<subparagraph id="H49D071ABC021499FBABCDA5022049DA2"><enum>(B)</enum><text>shall be consistent with the economic and security interests of the United States; and</text></subparagraph> <subparagraph id="H1B416BCCDBBC45F49F82E4AECA93EA9A"><enum>(C)</enum><text display-inline="yes-display-inline">not later than 60 days after the date on which the agreement is entered into, shall be submitted to the Committee on Energy and Commerce of the House of Representatives and the Committee on Commerce, Science, and Transportation of the Senate.</text></subparagraph></paragraph></subsection> 
<subsection id="H939413DA50AA4E088D4B38C61C1D3100"><enum>(d)</enum><header>Rule of construction</header><text display-inline="yes-display-inline">Nothing in this section may be construed to alter the authority of any agency with rulemaking and enforcement authority under subtitle A of title V of the Gramm-Leach-Bliley Act (<external-xref legal-doc="usc" parsable-cite="usc/15/6801">15 U.S.C. 6801 et seq.</external-xref>).</text> </subsection> </section> <section id="HF54E04E7E9FF4442B5EB8ADFF964C000"><enum>10.</enum><header>Study on universal opt-out mechanisms</header> <subsection id="H98BD414F7C5548C885650291F1D92BAA"><enum>(a)</enum><header>Study</header><text>Not later than 3 years after the date of the enactment of this Act, the Secretary shall publish on a publicly available website a report that—</text> 
<paragraph id="HCDCE7FCA00F340B280199D4DE56D463F"><enum>(1)</enum><text>is developed through a process of public consultation;</text></paragraph> <paragraph id="H76A6C353F4CF4499952B1FD346B9F039"><enum>(2)</enum><text>reviews commercially available technologies, including a web browser setting or extension or a global setting on an electronic device, that allow a consumer to opt out of the processing of the personal data of the consumer by a controller;</text></paragraph> 
<paragraph id="H1227EEAFDB2843C3B52D836A5D6CE708"><enum>(3)</enum><text display-inline="yes-display-inline">considers the feasibility of a universal opt-out mechanism in a manner that makes use of commercially available technologies and accounts for beneficial uses of personal data; and</text></paragraph> <paragraph id="H559C827ED5894EA29D081529342DF49B" commented="no"><enum>(4)</enum><text display-inline="yes-display-inline">limits such review and consideration in accordance with the scope of this Act.</text> </paragraph></subsection> 
<subsection id="HE78BFBFF2D554C7CAE3B4ECBF8E078CB"><enum>(b)</enum><header>Commercially available technologies</header><text>The commercially available technologies reviewed pursuant to the study required by subsection (a) shall meet the following requirements:</text> <paragraph id="HCB80819B018545EBA9ADCFCCD7029238"><enum>(1)</enum><text display-inline="yes-display-inline">Shall require a consumer to make an affirmative, freely given, and unambiguous choice to indicate the intent of the consumer to opt out of any processing of the personal data of the consumer by a controller.</text></paragraph> 
<paragraph id="H1FFCDAEC091B40D79C610CFE383BEA9A"><enum>(2)</enum><text>Shall be consumer-friendly and easy to use by the average consumer.</text></paragraph> <paragraph id="H099AA583BA374F7AA6C4502E975BFFF1"><enum>(3)</enum><text display-inline="yes-display-inline">May not unduly burden lawful data processing by a controller or processor, including with respect to beneficial uses of personal data.</text></paragraph> </subsection></section> 
<section id="HE6DD03DFDACD49A29BDBCEB4F2C728BE"><enum>11.</enum><header>Rules of construction</header> 
<subsection id="H39CC86EB4AAF456B9891B122EC034469"><enum>(a)</enum><header>In general</header><text display-inline="yes-display-inline">Nothing in this Act may be construed to restrict the ability of a controller or processor to do any of the following:</text> <paragraph id="HB3FA8F2F202C44539933936BFCA7822B"><enum>(1)</enum><text>Cooperate with a law enforcement agency with respect to conduct or activity that the controller or processor reasonably and in good faith believes may violate a Federal, State, or local law, rule, or regulation.</text></paragraph> 
<paragraph id="HAA2F95D3CB1542EE8F11AA5A4290805E"><enum>(2)</enum><text>Investigate, establish, exercise, prepare for, or defend a legal claim.</text></paragraph> <paragraph id="H4087AAF45732446D8DC0EAB042A10B49"><enum>(3)</enum><text>Provide a product or service specifically requested by a consumer or a parent of a consumer (if the consumer is a child or teen).</text></paragraph> 
<paragraph id="H08E872A166D2445697D6DCD4B98C0027"><enum>(4)</enum><text display-inline="yes-display-inline">Perform a contract to which a consumer or a parent of a consumer (if the consumer is a child or teen) is a party, including by fulfilling the terms of a written warranty.</text></paragraph> <paragraph id="H2C048E0B94174D7EBF789D258DAF1EB8"><enum>(5)</enum><text>Take immediate steps to protect an interest that is essential to the life or physical safety of a consumer or of another individual.</text></paragraph> 
<paragraph id="H73E5B7497C544899BB57D1F28F3AE9E4"><enum>(6)</enum><text>Prevent, detect, protect against, or respond to a security incident, including a data security incident, identity theft, fraud, harassment, malicious or deceptive activity, or any other similar illegal activity.</text></paragraph> <paragraph id="H941F4CDA4E824993BF8257DAAD7D2BF0"><enum>(7)</enum><text>Preserve the integrity or security of systems.</text></paragraph> 
<paragraph id="H5E631CB68D314D3498CA5D6EACA55EB4"><enum>(8)</enum><text>Investigate, report, or prosecute a person responsible for any such security incident.</text></paragraph> <paragraph id="HB76D094817324ADDA3D1D55E5D5F945E"><enum>(9)</enum><text>Engage in public or peer-reviewed scientific or statistical research in the public interest that adheres to any applicable Federal or State ethics or privacy law and is approved, monitored, and governed by an institutional review board (or similar independent oversight entity) that considers the following:</text> 
<subparagraph id="HC2B53D4B600A492BA466A4DD0DB87826"><enum>(A)</enum><text>If the deletion of the personal data of a consumer is likely to provide substantial benefits that do not exclusively accrue to the controller.</text></subparagraph> <subparagraph id="H3F97773B71FB4B34B47273816A8B7869"><enum>(B)</enum><text display-inline="yes-display-inline">If the controller has implemented reasonable safeguards to mitigate privacy and data security risks to a consumer associated with research, including any risks associated with re-identification of the personal data of the consumer.</text></subparagraph> 
<subparagraph id="H453EDDFD52174FF9A1E50CF0268AC120"><enum>(C)</enum><text>If the expected benefits of the research outweigh such privacy and data security risks.</text></subparagraph> </paragraph></subsection> <subsection id="HE5B5F2231098443788A74D5BE69B4DB0"><enum>(b)</enum><header>Personal data</header><text>Nothing in this Act may be construed to restrict the ability of a controller or processor to collect, use, or retain the personal data of a consumer to do any of the following:</text> 
<paragraph id="HF5205506D28F48F8826F2FDCA2ACF75A"><enum>(1)</enum><text>Conduct internal research to develop, improve, or repair a product, service, or technology.</text></paragraph> <paragraph id="HA5800989798744408B00AF60F995707D"><enum>(2)</enum><text>Effectuate a product recall.</text></paragraph> 
<paragraph id="HB2201B9B6E104F119AE5FEF4E5C42BF5"><enum>(3)</enum><text display-inline="yes-display-inline">Identify and repair any technical error that impairs the functionality of a product, service, or technology.</text></paragraph> <paragraph id="HDFB1FF23E1164A5B8017459C3882C0D1"><enum>(4)</enum><text display-inline="yes-display-inline">Perform an internal operation that—</text> 
<subparagraph id="HE60F1DE1DB3D4813B22B57A0BDF357B0"><enum>(A)</enum><text>is reasonably aligned with the expectations of a consumer;</text></subparagraph> <subparagraph id="HA8817B9193B244E8B5F5DE9D032F7DD1"><enum>(B)</enum><text>is reasonably anticipated based on the relationship of a consumer with the controller; or</text></subparagraph> 
<subparagraph id="HA668F6E88D6343A38C33CB87CB73E584"><enum>(C)</enum><text>is otherwise compatible with processing data to—</text> <clause id="H8337A2A08AF441048E73C488AF71B607"><enum>(i)</enum><text>provide a product or service specifically requested by a consumer or a parent of a consumer (if the consumer is a child or teen); or</text></clause> 
<clause id="HB77534E274534D01AC89D274225962D4"><enum>(ii)</enum><text display-inline="yes-display-inline">perform a contract to which a consumer or a parent of a consumer (if the consumer is a child or teen) is a party.</text></clause></subparagraph></paragraph></subsection> <subsection id="H89831BC010684C87AF47491674F9A30B" commented="no"><enum>(c)</enum><header>Privileged communication</header><text>Nothing in this Act may be construed to prevent a controller or processor from providing the personal data of a consumer to a person covered by an evidentiary privilege under Federal or State law as part of a privileged communication.</text> </subsection> 
<subsection id="H461121E2454D45F29FB8B806372223DB"><enum>(d)</enum><header>Protected disclosure</header><text>A controller or processor that discloses the personal data of a consumer to another controller or processor in compliance with the requirements of this Act does not violate this Act if the controller or processor that receives and processes such personal data violates this Act if, at the time of disclosing the personal data, the disclosing controller or processor did not have knowledge that the receiving controller or processor intended to commit such a violation.</text></subsection> <subsection id="H8C16B8F8E4934CF79D88DAF6EB165E08" commented="no"><enum>(e)</enum><header>Protected rights</header><text>Nothing in this Act may be construed as a requirement imposed on a controller or processor that adversely affects the privacy or any other right or freedom of any person, including the right to freedom of speech under the Constitution of the United States, or that applies to the processing of personal data by a person in the course of a purely personal or household activity.</text> </subsection> </section> 
<section id="HCE30CAF237804A569AA5B757D8F37E87"><enum>12.</enum><header>Enforcement</header> 
<subsection id="H4C0DB92DFBBD415CB3B9545677630F1F"><enum>(a)</enum><header>Enforcement by Commission</header> 
<paragraph id="H5B23FFD25FDB4B34A6DEC1AFC4647688"><enum>(1)</enum><header>Unfair or deceptive acts or practices</header><text>A violation of this Act shall be treated as a violation of a regulation under section 18(a)(1)(B) of the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/57a">15 U.S.C. 57a(a)(1)(B)</external-xref>) regarding unfair or deceptive acts or practices.</text></paragraph> <paragraph id="HCA94FB0641F342D38AE843452C0F8A2E"><enum>(2)</enum><header>Powers of Commission</header><text>Except as provided in paragraphs (3) and (4), the Commission shall enforce this Act in the same manner, by the same means, and with the same jurisdiction, powers, and duties as though all applicable terms and provisions of the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/41">15 U.S.C. 41 et seq.</external-xref>) were incorporated into and made a part of this Act, and any person who violates this Act shall be subject to the penalties and entitled to the privileges and immunities provided in the Federal Trade Commission Act.</text></paragraph> 
<paragraph id="H43F2DFBCEF634D8E8CC7203659A5940A" commented="no"><enum>(3)</enum><header>Common carriers</header><text display-inline="yes-display-inline">Notwithstanding section 4, 5(a)(2), or 6 of the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/44">15 U.S.C. 44</external-xref>; 45(a)(2); 46) or any jurisdictional limitation of the Federal Trade Commission, the Federal Trade Commission shall also enforce this Act, in the same manner provided in paragraphs (1) and (2), with respect to common carriers subject to the Communications Act of 1934 (<external-xref legal-doc="usc" parsable-cite="usc/47/151">47 U.S.C. 151 et seq.</external-xref>).</text> </paragraph> <paragraph id="HD6E60EC113E54AB787B1EBB85058B458"><enum>(4)</enum><header>Civil rights violations</header> <subparagraph id="HAE2CEEEC3BC14220A602E9334EE155E8"><enum>(A)</enum><header>Exception</header><text>Notwithstanding paragraphs (1), (2), and (3), the Commission may not enforce any violation of section 3(c) of this Act.</text></subparagraph> 
<subparagraph id="HE27DD4B3AA174F64B1BD35C775750AB5"><enum>(B)</enum><header>Transmission by Commission</header><text display-inline="yes-display-inline">If the Commission receives information alleging that a controller is in violation of section 3(c), the Commission shall transmit such information, as allowable under Federal law, to any agency with authority to initiate an enforcement action or proceeding relating to the alleged violation described in the information.</text></subparagraph></paragraph></subsection> <subsection id="H532219F917614B0E9E0A4106BD245313"><enum>(b)</enum><header>Actions by States</header> <paragraph id="H6621B2731CF94B38A0B1FF14B354655A"><enum>(1)</enum><header>In general</header><text>In any case in which the attorney general of a State has reason to believe that an interest of the residents of such State has been or is threatened or adversely affected by an act or practice in violation of this Act, the attorney general, as parens patriae, may bring a civil action on behalf of the residents of the State in an appropriate district court of the United States to—</text> 
<subparagraph id="HA0C9F5FB184F47FE98FEE8526EBF13A0"><enum>(A)</enum><text>enjoin such act or practice;</text></subparagraph> <subparagraph id="HEEBD0384ACCB492299E8896F5934F56A"><enum>(B)</enum><text>enforce compliance with this Act;</text></subparagraph> 
<subparagraph id="H94A36394ED6748F79A81D27EE54CFE52"><enum>(C)</enum><text>obtain damages, restitution, or other compensation on behalf of residents of the State; or</text></subparagraph> <subparagraph id="HEF01E998B9714BFF8C004A5E7D03AA34"><enum>(D)</enum><text>obtain such other legal and equitable relief as the court may consider to be appropriate.</text></subparagraph></paragraph> 
<paragraph id="H1D9C00030645466CAFF30551E5BB51B6"><enum>(2)</enum><header>Notice</header><text>Before filing an action under this subsection, the attorney general of the State involved shall provide to the Commission a written notice of such action and a copy of the complaint for such action. If the attorney general determines that it is not feasible to provide the notice described in this paragraph before the filing of the action, the attorney general shall provide written notice of the action and a copy of the complaint to the Commission immediately upon the filing of the action.</text></paragraph> <paragraph id="H448C1B215A5E4AE69676101D0BF51FC2"><enum>(3)</enum><header>Authority of Commission</header> <subparagraph id="H37246DEFDBD84739B70C386B9858FA6C"><enum>(A)</enum><header>In general</header><text>On receiving notice under paragraph (2) of an action under this subsection, the Commission shall have the right—</text> 
<clause id="H3FB0111D1D874CACA03EAD4E7156DD3C"><enum>(i)</enum><text>to intervene in the action;</text></clause> <clause id="HC250F367419148C4AB9CE8BF20083BFF"><enum>(ii)</enum><text>upon so intervening, to be heard on all matters arising therein; and</text></clause> 
<clause id="H84DCBD7E3AA24A86966785BC3E496994"><enum>(iii)</enum><text>to file petitions for appeal.</text></clause></subparagraph> <subparagraph id="H3D4E47D9A6474D10B9EDDF7D02B5D672"><enum>(B)</enum><header>Limitation on State action while Federal action is pending</header><text>If the Commission or the Attorney General of the United States has instituted a civil action for violation of this Act (referred to in this subparagraph as the <quote>Federal action</quote>), no State attorney general may bring an action under this subsection during the pendency of the Federal action against any defendant named in the complaint in the Federal action for any violation of this Act alleged in such complaint.</text></subparagraph></paragraph> 
<paragraph id="HE258465039EE483C8969388A6AAEC7D9"><enum>(4)</enum><header>Rule of construction</header><text>For purposes of bringing a civil action under this subsection, nothing in this Act may be construed to prevent an attorney general of a State from exercising the powers conferred on the attorney general by the laws of such State to conduct investigations, administer oaths and affirmations, or compel the attendance of witnesses or the production of documentary and other evidence.</text></paragraph></subsection> <subsection id="HD93C41221BB447BCB6F98D5E0F0580B2"> <enum>(c)</enum> <header>Right To cure</header> <paragraph id="H05F5CCFF1737431D925F9407C28A1D85"> <enum>(1)</enum> <header>In general</header> <text display-inline="yes-display-inline">Neither the Commission nor a State attorney general may initiate any action for a violation of this Act until—</text>
                    <subparagraph id="H31911CEAD61E4AC691A31F8FC5907B47">
                        <enum>(A)</enum>
 <text>the Commission or the attorney general has provided written notice to a controller or processor alleged to be in violation of this Act of the alleged violation that identifies the specific provision of this Act alleged to have been violated; and</text>
                    </subparagraph>
                    <subparagraph id="HB4A81E92F59C4D6FB49161FFB2AAD950">
                        <enum>(B)</enum>
 <text>not fewer than 45 days have passed since the date on which such written notice has been provided.</text>
                    </subparagraph>
                </paragraph>
                <paragraph id="HA57CC881DADA4DA89E0B5DB848496D82">
                    <enum>(2)</enum>
                    <header>Effect of cure</header>
 <text display-inline="yes-display-inline">There shall be no violation of this Act with respect to an allegation made under paragraph (1)(A) if, during the period of time described in paragraph (1)(B), the controller or processor alleged to be in violation of this Act cures the alleged violation of this Act and provides the Commission or the State attorney general with a written statement that such violation has been cured and that no such further violation shall occur.</text>
                </paragraph>
                <paragraph id="H6A41F7F0184D44F2BAF845FA93B2CC68">
                    <enum>(3)</enum>
                    <header>Failure to cure</header>
 <text display-inline="yes-display-inline">The Commission or the State attorney general may initiate an action pursuant to subsection (a) or (b) (as the case may be) to remedy an allegation made under paragraph (1)(A) if the controller or processor alleged to be in violation of this Act—</text>
                    <subparagraph id="HA02C44AD698142C3917BFDE3850BD498">
                        <enum>(A)</enum>
 <text display-inline="yes-display-inline">fails to cure the alleged violation pursuant to paragraph (2); or</text>
                    </subparagraph>
                    <subparagraph id="H49FF49BFE8BA422EA72D207FDDFB03DE">
                        <enum>(B)</enum>
 <text>after curing the alleged violation pursuant to paragraph (2), continues to violate this Act.</text>
                    </subparagraph>
                </paragraph>
            </subsection> </section> 
<section id="H3BD3E4A448C04270A4349592C6B44EF4"><enum>13.</enum><header>Applicability</header> 
<subsection id="HBCA9969FD25C43478C2E93F1F152AEAA"><enum>(a)</enum><header>In general</header><text>This Act shall apply to any person that is subject to the Federal Trade Commission Act (<external-xref legal-doc="usc" parsable-cite="usc/15/41">15 U.S.C. 41 et seq.</external-xref>) or is a common carrier subject to title II of the Communications Act of 1934 (<external-xref legal-doc="usc" parsable-cite="usc/47/201">47 U.S.C. 201 et seq.</external-xref>) and—</text> <paragraph id="H66979E92F2724F868D68E54D2A4F3121"><enum>(1)</enum><text>with respect to the business of the person—</text> 
<subparagraph id="H580699656F1D48A696E0880A131B4A1E"><enum>(A)</enum><text>conducts business in the United States or offers for use or sale to a resident of the United States a product or service; or</text></subparagraph> <subparagraph id="HB0B4A82CD4924E36916A669017C8842E"><enum>(B)</enum><text>processes or engages in the sale of personal data of a resident of the United States; and</text></subparagraph></paragraph> 
<paragraph id="H37E2E92BE1094A9288403234BCAE7432"><enum>(2)</enum><text display-inline="yes-display-inline">with respect to personal data and annual gross revenue in the course of such business—</text> <subparagraph id="H670E66D37F784BB3AF55DE1FB53742E9"><enum>(A)</enum><text display-inline="yes-display-inline">collects and processes personal data of more than 200,000 consumers annually (excluding personal data controlled or processed solely for the purpose of completing a payment transaction) and has an annual gross revenue of $25,000,000 or more (as adjusted on January 1 each year by the percentage increase (if any), during the preceding 12-month period, in the Consumer Price Index for All Urban Consumers published by the Bureau of Labor Statistics); or</text></subparagraph> 
<subparagraph id="HFBBA54CBADF440DF8F088642352CC398"><enum>(B)</enum><text display-inline="yes-display-inline">collects and processes personal data of 100,000 or more consumers annually (excluding personal data controlled or processed solely for the purpose of completing a payment transaction) and derives 25 percent or more of the annual gross revenue of the person from the sale of such personal data.</text></subparagraph> </paragraph></subsection> <subsection id="HAC7587B156B44193A551C1F1A928B145"><enum>(b)</enum><header>Exemptions</header><text>This Act does not apply to the following:</text> 
<paragraph id="H15F35040E2084DDBAA55FDB4D95286D7"><enum>(1)</enum><text>A Federal, State, or local governmental entity.</text></paragraph> <paragraph id="HC4FFD036AC594A40AA94DAE9FBD96DC3"><enum>(2)</enum><text>An entity that collects, processes, retains, or transfers personal data on behalf of such Federal or State governmental entity, to the extent that such entity is acting as a processor to the governmental entity.</text></paragraph> 
<paragraph id="HB5F78C15C08F4BE387CA47E19F56A68F" commented="no"><enum>(3)</enum><text>A financial institution subject to title V of the Gramm-Leach-Bliley Act (<external-xref legal-doc="usc" parsable-cite="usc/15/6801">15 U.S.C. 6801 et seq.</external-xref>).</text></paragraph> <paragraph id="HD593FB91D8BE42DDBC376B17A8A7A482" commented="no"><enum>(4)</enum><text>A covered entity or business associate subject to parts 160 and 164 of title 45, Code of Federal Regulations.</text></paragraph> 
<paragraph id="H23D7643645544CAF92A0EE5558B4E035"><enum>(5)</enum><text display-inline="yes-display-inline">A nonprofit organization.</text></paragraph> <paragraph id="H37C6E79D0F2D4F0FA6EF429190F751BE"><enum>(6)</enum><text>A nonprofit organization with the primary mission of preventing, investigating, or deterring fraud, training anti-fraud professionals, or educating the public about fraud, including insurance fraud, securities fraud, and financial fraud.</text></paragraph> 
<paragraph id="H39B6F30B53254B4AB981CD09023F15CD"><enum>(7)</enum><text>An institution of higher education.</text></paragraph> <paragraph id="HFBE616ED02884C3FA0B50A66D21B8705"><enum>(8)</enum><text>The National Center for Missing and Exploited Children.</text></paragraph> 
<paragraph id="H83066B0DFFE14F6A9B6C42CA2C38B574"><enum>(9)</enum><text>An entity created by a Federal or State statute to pay for claims arising from the liquidation of an insurance company.</text></paragraph> <paragraph id="HA9B1C47515244404A53D4516973B473E"><enum>(10)</enum><text>A futures association registered pursuant to section 17 of the Commodity Exchange Act (<external-xref legal-doc="usc" parsable-cite="usc/7/21">7 U.S.C. 21</external-xref>).</text></paragraph> 
<paragraph id="HE87A71FD675C42E8ACD7272627ABAD2F"><enum>(11)</enum><text>A national securities association registered pursuant to section 15A of the Securities Exchange Act of 1934 (<external-xref legal-doc="usc" parsable-cite="usc/15/78o-3">15 U.S.C. 78o–3</external-xref>).</text></paragraph> <paragraph id="H1C0A09CDE2664C7B9D69F98E2CA4F831"><enum>(12)</enum><text>Data processed or maintained—</text> 
<subparagraph id="H288C3D7D41094FA68635F4C1D9858159"><enum>(A)</enum><text>by an individual applying to, employed by, or acting as an agent or independent contractor of a controller or processor for such application, employment, or action;</text></subparagraph> <subparagraph id="H6E85E5FB4E954EDC8E428DF4DE1E251B"><enum>(B)</enum><text>for inclusion in the emergency contact information relating an individual; or</text></subparagraph> 
<subparagraph id="H027D98FA2B834DDBB3CCB19DEE362228"><enum>(C)</enum><text>that is necessary for the administration of benefits for an individual.</text></subparagraph></paragraph> <paragraph id="H04B9BAEE35C64655B2F65B7F156FD692"><enum>(13)</enum><text>The following information:</text> 
<subparagraph id="H708D7DFA30D04A1F87AEED89AFC78625" commented="no" display-inline="no-display-inline"><enum>(A)</enum><text display-inline="yes-display-inline">Health information protected under and collected or used for public health activities and purposes in accordance with HIPAA.</text> </subparagraph> <subparagraph id="HDF05BC1104FB4FB0965228F44B78C8B5" commented="no"><enum>(B)</enum><text display-inline="yes-display-inline">Health records.</text></subparagraph> 
<subparagraph id="H213B4B4904084126922EA296E36D93F7" commented="no"><enum>(C)</enum><text display-inline="yes-display-inline">Records relating to the identity, diagnosis, prognosis, or treatment of a patient under section 543 of the Public Health Service Act (<external-xref legal-doc="usc" parsable-cite="usc/42/290dd-2">42 U.S.C. 290dd–2</external-xref>).</text></subparagraph> <subparagraph id="H25CF31D6823C43DCA4710CDF87C0F428"><enum>(D)</enum><text>Data, information, or identifiable private information (as such term is defined in section 46.102 of title 45, Code of Federal Regulations) obtained pursuant to any of the following:</text> 
<clause id="H2C68E7D67D4F4F7995DDC5E3AA14E343"><enum>(i)</enum><text display-inline="yes-display-inline">Part 46 of title 45, Code of Federal Regulations.</text></clause> <clause id="HC98F6444EE9547E2B4266E4375B1ACF7"><enum>(ii)</enum><text>The Guideline for Good Clinical Practice E6(R3) issued by The International Council for Harmonisation of Technical Requirements for Pharmaceuticals for Human Use.</text></clause> 
<clause id="H1639BB8E1FE343E589E992775F3986E6"><enum>(iii)</enum><text>Part 50 or part 56 of title 21, Code of Federal Regulations.</text></clause> </subparagraph> <subparagraph id="HCF80D506025A48E0A90BA6F48A210FE4" commented="no"><enum>(E)</enum><text display-inline="yes-display-inline">Information reported pursuant to the Health Care Quality Improvement Act of 1986 (<external-xref legal-doc="usc" parsable-cite="usc/42/11101">42 U.S.C. 11101 et seq.</external-xref>).</text></subparagraph> 
<subparagraph id="H0B516AC57EBB4266B0691CC5C7E947B3"><enum>(F)</enum><text display-inline="yes-display-inline">Identifiable patient safety work product and nonidentifiable patient safety work product (as such terms are defined in section 921 of the Public Health Service Act (<external-xref legal-doc="usc" parsable-cite="usc/42/299b-21">42 U.S.C. 299b–21</external-xref>)) protected under Part C of title IX of the Public Health Service Act (<external-xref legal-doc="usc" parsable-cite="usc/42/299b-21">42 U.S.C. 299b–21 et seq.</external-xref>).</text></subparagraph> <subparagraph id="H7C1280AC945D46A981A3A1E5741EAAEB" commented="no" display-inline="no-display-inline"><enum>(G)</enum><text display-inline="yes-display-inline">Information derived from any of the health care related information listed in this paragraph that is de-identified in accordance with section 164.514(e) of title 45, Code of Federal Regulations.</text> </subparagraph> 
<subparagraph id="HE9DC703FF4184CF383712D5BA22A8C3E"><enum>(H)</enum><text>Information that is included in a limited data set in accordance with the standards and specifications under section 164.514(e) of title 45, Code of Federal Regulations.</text></subparagraph> <subparagraph id="HAC473E2EBB294C9FA1A2D0631A4C88E7" commented="no"><enum>(I)</enum><text display-inline="yes-display-inline">Personal data that—</text> 
<clause id="H9D5A2AB17AF2423D8E1EB42C0B1B5CFF" commented="no"><enum>(i)</enum><text>may impact the creditworthiness, credit standing, credit capacity, character, general reputation, personal characteristics, or mode of living of a consumer; and</text></clause> <clause id="HCA381C7C73EF42BAB0FDEFFD301E4230" commented="no"><enum>(ii)</enum><text display-inline="yes-display-inline">is collected or disclosed by a consumer reporting agency (as such term is defined in section 603(f) of the Fair Credit Reporting Act (<external-xref legal-doc="usc" parsable-cite="usc/15/1681a">15 U.S.C. 1681a(f)</external-xref>)) or a furnisher, to the extent that the consumer reporting agency or furnisher is engaged in activities subject to the Fair Credit Reporting Act.</text></clause> </subparagraph> 
<subparagraph id="HE30FC2E5E75B482C9C4C5FCFC6F6E8B7" commented="no"><enum>(J)</enum><text display-inline="yes-display-inline">Personal information (as such term is defined in section 2725 of title 18, United States Code) collected, processed, sold, or disclosed under section 2721 of title 18, United States Code.</text></subparagraph> <subparagraph id="H8DE8F3E03DB245B1825E15F9B26EC810" commented="no"><enum>(K)</enum><text display-inline="yes-display-inline">Personally identifiable information and personally identifiable data regulated in accordance with section 444 of the General Education Provisions Act (commonly known as the <quote>Family Educational Rights and Privacy Act of 1974</quote>) (<external-xref legal-doc="usc" parsable-cite="usc/20/1232g">20 U.S.C. 1232g</external-xref>).</text></subparagraph> 
<subparagraph id="H1B7CB173CD59484180CF397D149E4474" commented="no"><enum>(L)</enum><text display-inline="yes-display-inline">Personal data collected, processed, sold, or disclosed as a result of an activity authorized under the Farm Credit Act of 1971 (<external-xref legal-doc="usc" parsable-cite="usc/12/2001">12 U.S.C. 2001 et seq.</external-xref>).</text> </subparagraph> <subparagraph id="H18762794FB4D4A8FA41DACF298CB6916" commented="no"><enum>(M)</enum><text display-inline="yes-display-inline">Nonpublic personal information (as such term is defined in section 509 of the Gramm-Leach-Bliley Act (<external-xref legal-doc="usc" parsable-cite="usc/15/6809">15 U.S.C. 6809</external-xref>)).</text></subparagraph> 
<subparagraph id="H22D5D926E9F3408F84F27E3E62F7EC8B" commented="no"><enum>(N)</enum><text display-inline="yes-display-inline">Any information that originates from, is intermingled with, or is treated in the same manner as information described in subparagraphs (A) through (M) that is maintained by the following:</text> <clause id="H1C8469956C0E4813B7E9B463138ACFD8" commented="no"><enum>(i)</enum><text>A covered entity or business associate.</text></clause> 
<clause id="HAACC4EFBABC04B1AADFF54B3AE54F57F" commented="no"><enum>(ii)</enum><text display-inline="yes-display-inline">A program or a qualified service organization (as such terms are defined in section 2.11 of title 42, Code of Federal Regulations).</text> </clause></subparagraph></paragraph> </subsection></section> <section id="HFF9AB678AB17451FB56D359BF0A5558E"><enum>14.</enum><header>Relationship to Federal laws</header> <subsection id="H1AED2EF439FC49CE8F345893603F3761"><enum>(a)</enum><header>In general</header><text>Nothing in this Act may be construed to relieve or change an obligation that a controller or processor may have under any of the following:</text> 
<paragraph id="H0218DFF6E4D74453BC3F5ECC8C0E63F5"><enum>(1)</enum><text display-inline="yes-display-inline">The Children’s Online Privacy Protection Act of 1998 (15 U.S.C. 6501 et seq).</text> </paragraph> <paragraph id="H2A00BE539A51465093067BE2CFEBD70E"><enum>(2)</enum><text>Title V of the Gramm-Leach-Bliley Act (<external-xref legal-doc="usc" parsable-cite="usc/15/6801">15 U.S.C. 6801 et seq.</external-xref>).</text></paragraph> 
<paragraph id="HA2D858ABF98E48FCBBB8863F75588EB1"><enum>(3)</enum><text>Part C of title XI of the Social Security Act (<external-xref legal-doc="usc" parsable-cite="usc/42/1320d">42 U.S.C. 1320d et seq.</external-xref>).</text></paragraph> <paragraph id="HE06A4BBDB579468594A9C026A5525A53" commented="no"><enum>(4)</enum><text>Subtitle D of the HITECH Act (<external-xref legal-doc="usc" parsable-cite="usc/42/17921">42 U.S.C. 17921 et seq.</external-xref>).</text></paragraph> 
<paragraph id="H8C806D3DD5EB46FA97E0E5C27E4A04F2" commented="no"><enum>(5)</enum><text display-inline="yes-display-inline">Any regulations promulgated under section 264(c) of HIPAA (<external-xref legal-doc="usc" parsable-cite="usc/42/1320d-2">42 U.S.C. 1320d–2</external-xref> note).</text></paragraph> <paragraph id="H8039FD8F6FD042A7AF1CF34DD063A172" commented="no"><enum>(6)</enum><text display-inline="yes-display-inline">The requirements regarding the confidentiality of substance use disorder information under section 543 of the Public Health Service Act (<external-xref legal-doc="usc" parsable-cite="usc/42/290dd-2">42 U.S.C. 290dd–2</external-xref>) or any regulation promulgated under such section.</text></paragraph> 
<paragraph id="H75F62E39B61B4A49A82BA9C13336EC40"><enum>(7)</enum><text>The Fair Credit Reporting Act (<external-xref legal-doc="usc" parsable-cite="usc/15/1681">15 U.S.C. 1681 et seq.</external-xref>).</text></paragraph> <paragraph id="H8300D0B254444D55B0A317A8830163B3"><enum>(8)</enum><text>Section 444 of the General Education Provisions Act (commonly known as the <quote>Family Educational Rights and Privacy Act of 1974</quote>) (<external-xref legal-doc="usc" parsable-cite="usc/20/1232g">20 U.S.C. 1232g</external-xref>) and part 99 of title 34, Code of Federal Regulations (or any successor regulation), to the extent a controller or processor is an educational agency or institution (as such term is defined in 99.3 of such title (or any successor regulation)).</text></paragraph> 
<paragraph id="H496E635D20B34705A51441B193F80002"><enum>(9)</enum><text>The regulations related to the protection of human subjects under part 46 of title 45, Code of Federal Regulations.</text></paragraph> <paragraph id="HA2D02918AE3C4CBD8554E63C5EA1F2DF" commented="no"><enum>(10)</enum><text display-inline="yes-display-inline">The Health Care Quality Improvement Act of 1986 (<external-xref legal-doc="usc" parsable-cite="usc/42/11101">42 U.S.C. 11101 et seq.</external-xref>).</text></paragraph> 
<paragraph id="HC4019D110B4F4C1282F56C0071BFD11D" commented="no"><enum>(11)</enum><text display-inline="yes-display-inline">Part C of title IX of the Public Health Service Act (<external-xref legal-doc="usc" parsable-cite="usc/42/299b-21">42 U.S.C. 299b–21 et seq.</external-xref>).</text></paragraph> <paragraph id="H8BD803C300F74E6A9E3755562843537A"><enum>(12)</enum><text><external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/18/123">Chapter 123</external-xref> of title 18, United States Code.</text></paragraph></subsection> 
<subsection id="H063F7BE60F6448888FDAD0937D06F9BC" commented="no"><enum>(b)</enum><header>Relationship to Communications Act of 1934</header> 
<paragraph id="H5C94503A48654E2F851CA87D993D1987" commented="no"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">Except as provided in paragraph (2), the Communications Act of 1934 (<external-xref legal-doc="usc" parsable-cite="usc/47/151">47 U.S.C. 151 et seq.</external-xref>), and any regulation promulgated by the Federal Communications Commission pursuant to such Act, shall not apply to a controller or processor with respect to the collection, use, processing, transferring, or security of personal data.</text> </paragraph> <paragraph id="HFD956B875E844D81904195AC7F47C638" commented="no"><enum>(2)</enum><header>Exception</header><text display-inline="yes-display-inline">Paragraph (1) does not apply to the extent a regulation or order pertains solely to emergency services.</text> </paragraph></subsection> 
<subsection id="H1E8EB75B6BF841C3B9E37D144223BD57"><enum>(c)</enum><header>Repeal</header><text>Section 2710 of title 18, United States Code, is repealed.</text></subsection> </section> <section id="H189AA95F2A784E9C896D48249C3881E1"><enum>15.</enum><header>Relationship to State laws</header><text display-inline="no-display-inline">No State or political subdivision of a State may prescribe, maintain, or enforce any law, rule, regulation, requirement, standard, or other provision having the force and effect of law, if such law, rule, regulation, requirement, standard, or other provision relates to the provisions of this Act.</text></section> 
<section id="HFCED349055924209B942CF3CA7E38370"><enum>16.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act:</text> <paragraph id="H3587A37E61E748018C59B390BBB368E2"><enum>(1)</enum><header>Affiliate</header> <subparagraph id="H4D194856B0564464B3B30400916FBBC6"><enum>(A)</enum><header>In general</header><text>The term <term>affiliate</term> means a legal entity that controls, is controlled by, or is under common control with another legal entity or shares common branding with another legal entity.</text></subparagraph> 
<subparagraph id="HE7A9CA3B466B45E5B1AB6EA8E57292C8"><enum>(B)</enum><header>Control; controlled</header><text>In subparagraph (A), the terms <term>control</term> and <term>controlled</term> mean—</text> <clause id="H62CFEBD8C8954BE38D186307D8CE562D"><enum>(i)</enum><text>ownership of, or the power to vote, more than 50 percent of the outstanding shares of any class of voting security of a company;</text></clause> 
<clause id="H29441B18E6C743ACA62286732F2D7F27"><enum>(ii)</enum><text>control in any manner over the election of a majority of the directors or of individuals exercising similar functions; or</text></clause> <clause id="H7B54058CB8B14C1590E767C3E9675450"><enum>(iii)</enum><text>the power to exercise controlling influence over the management of a company.</text></clause></subparagraph></paragraph> 
<paragraph id="H85BEEE8306934FF3A03B4EB600AB2248" commented="no"><enum>(2)</enum><header>Agency</header><text display-inline="yes-display-inline">The term <term>agency</term> has the meaning given that term in section 551 of title 5, United States Code.</text> </paragraph> <paragraph id="H07187D9DA3C44D6ABA5845977F4EAE2D"><enum>(3)</enum><header>Authenticate</header><text>The term <term>authenticate</term> means to verify through commercially reasonable means that the consumer, entitled to exercise the consumer rights described under section 2, is the same consumer that exercises such a consumer right with respect to the relevant personal data.</text></paragraph> 
<paragraph id="HD0DC7BA08C1E4A029B4D7747A3DE4B0D"><enum>(4)</enum><header>Biometric data</header><text>The term <term>biometric data</term>—</text> <subparagraph id="H86A2009565B347C9845EA78D08EF79F1"><enum>(A)</enum><text display-inline="yes-display-inline">means data generated by automatic measurements of the biological characteristics of an individual, such as a fingerprint, voiceprint, eye retinas, irises, or other unique biological patterns or characteristics that is used to identify a specific individual; and</text></subparagraph> 
<subparagraph id="H212BE3F636304B339324CC714A2C5C19" commented="no"><enum>(B)</enum><text display-inline="yes-display-inline">does not include a physical or digital photograph, a video or audio recording (or data generated therefrom), or information collected, used, or stored for health care treatment, payment, or operations pursuant to HIPAA.</text></subparagraph></paragraph> <paragraph id="H9EBC4CADC56843BD94A91E9ECA884CE1" commented="no"><enum>(5)</enum><header>Business associate; covered entity; healthcare provider; protected health information</header><text display-inline="yes-display-inline">The terms <term>business associate</term>, <term>covered entity</term>, <term>healthcare provider</term>, and <term>protected health information</term> have the meanings given those terms in for purposes of regulations promulgated pursuant to section 264(c) of the Health Insurance Portability and Accountability Act (<external-xref legal-doc="usc" parsable-cite="usc/42/1320d-2">42 U.S.C. 1320d–2</external-xref> note).</text></paragraph> 
<paragraph id="HAC7859A6832C4479A5014DE8F1F364E7"><enum>(6)</enum><header>Child</header><text>The term <term>child</term> means an individual who is under the age of 13.</text></paragraph> <paragraph id="H76BA37D04634466A9DA716EECCDAECE2"><enum>(7)</enum><header>Commission</header><text>The term <term>Commission</term> means the Federal Trade Commission.</text></paragraph> 
<paragraph id="HE802D9A65B124FFFB1751238F5B264C2"><enum>(8)</enum><header>Consent</header><text>The term <term>consent</term>—</text> <subparagraph id="H0043452C1FCF4D038A927AA1B2A8DEB0"><enum>(A)</enum><text>means a clear affirmative act that signifies the freely given, specific, informed, and unambiguous agreement by a consumer to process personal data relating to the consumer; and</text></subparagraph> 
<subparagraph id="HA474AD14413E4280AB8D8C75AF5CF1DA"><enum>(B)</enum><text>includes a written statement, including a statement written by electronic means, or any other unambiguous affirmative action.</text></subparagraph></paragraph> <paragraph id="HCFF8145939244E35AD8DD6D3A54B3280"><enum>(9)</enum><header>Consumer</header><text>The term <term>consumer</term> means—</text> 
<subparagraph id="HF80FD941D5BF4B51A696E333B151E93D"><enum>(A)</enum><text>an individual that acts in an individual or household capacity; and</text></subparagraph> <subparagraph id="HE0F83A58E28F4F268B6FE6ABEB7B9C01"><enum>(B)</enum><text>does not include an individual that acts in a commercial or employment context.</text></subparagraph></paragraph> 
<paragraph id="HD442D7F0665A4BAD9DAD44B9BC990C20"><enum>(10)</enum><header>Controller</header><text>The term <term>controller</term> means a person that, alone or jointly with others, determines the purpose and means of processing personal data.</text></paragraph> <paragraph id="HD6F35D50B1B54C269C91E0B40415C608"><enum>(11)</enum><header>Covered nation</header><text>The term <term>covered nation</term> has the meaning given that term in section 4872(f) of title 10, United States Code.</text></paragraph> 
<paragraph id="H577870CC8A7945EB8F14BE0EBA41BECA"><enum>(12)</enum><header>Data broker</header> 
<subparagraph id="H5156D10165E94A0686113B5A9D4F3284"><enum>(A)</enum><header>In general</header><text>The term <term>data broker</term> means a controller that meets the following—</text> <clause id="HD27926883C644BA680E6186EED25FB62"><enum>(i)</enum><text>The controller collects and processes personal data concerning a consumer who is not:</text> 
<subclause id="H98210B982C2F44A896673E0D1F39ABF8"><enum>(I)</enum><text>a customer or a client of the controller; or</text></subclause> <subclause id="H1DC67BF64BB14290A2541BF7305E89E4"><enum>(II)</enum><text display-inline="yes-display-inline">a user, reader, or subscriber of a product or service provided by the controller; and</text></subclause> </clause> 
<clause id="HFABA1D80A13B46D18E390C4060C355D6"><enum>(ii)</enum><text display-inline="yes-display-inline">The controller derives 50 percent or more of annual gross revenue from the sale of such personal data.</text></clause></subparagraph> <subparagraph id="H0F5D99DF9A294B0BA5BF957022131943"><enum>(B)</enum><header>Limitation</header><text display-inline="yes-display-inline">The term <term>data broker</term> does not include a person acting as a processor.</text></subparagraph></paragraph> 
<paragraph id="HFF6D42923BC04DD38243066D43250164" commented="no"><enum>(13)</enum><header>Decision that has a legal or similarly significant effect</header><text>The term <term>decision that has a legal or similarly significant effect</term> means a decision made by a controller about a consumer to deny one of the following to the consumer:</text> <subparagraph id="HB7C6A69552E34B1487CB6DF6215D7069" commented="no"><enum>(A)</enum><text display-inline="yes-display-inline">A healthcare service (as defined in part 318.2 of title 16, Code of Federal Regulations).</text></subparagraph> 
<subparagraph id="HCF334038C7854C7B892CF8A0488E8293" commented="no"><enum>(B)</enum><text display-inline="yes-display-inline">A rental or lease of housing.</text></subparagraph> <subparagraph id="H71E209A6A12B49FFABC80FACA10FD5FA" commented="no"><enum>(C)</enum><text>An employment opportunity.</text></subparagraph></paragraph> 
<paragraph id="H87CAA811B9CF4F9B93394F3CA74FE1A9"><enum>(14)</enum><header>Deidentified data</header><text>The term <term>deidentified data</term> means data that cannot reasonably be linked to an identified or identifiable individual or a device linked to an individual.</text></paragraph> <paragraph id="HC087455BB43B4DA79858DA207F64BE69" commented="no"><enum>(15)</enum><header>Health record</header><text display-inline="yes-display-inline">The term <term>health record</term> means a record, other than for financial or billing purposes, relating to an individual, kept by a health care provider as a result of the professional relationship established between the health care provider and the individual.</text></paragraph> 
<paragraph id="H7FB56249EC7642C884D5EEDBF483D69D" commented="no"><enum>(16)</enum><header>HIPAA</header><text display-inline="yes-display-inline">The term <term>HIPAA</term> means Health Insurance Portability and Accountability Act of 1996 (<external-xref legal-doc="usc" parsable-cite="usc/42/1320d">42 U.S.C. 1320d et seq.</external-xref>).</text></paragraph> <paragraph id="H83FED0A4FA9C4A198E9331855C8E82FB"><enum>(17)</enum><header>Identified or identifiable natural person</header><text>The term <term>identified or identifiable natural person</term> means a person who can be readily identified, directly or indirectly.</text></paragraph> 
<paragraph id="H63FFE72128594FE69C263A164418F0A3"><enum>(18)</enum><header>Institution of higher education</header><text display-inline="yes-display-inline">The term <term>institution of higher education</term> has the meaning given that term in section 101 of Higher Education Act of 1965 (<external-xref legal-doc="usc" parsable-cite="usc/20/1001">20 U.S.C. 1001</external-xref>).</text></paragraph> <paragraph id="H94FC4385AA5E403D98BE53DEA9B520C5"><enum>(19)</enum><header>Nonprofit organization</header><text>The term <term>nonprofit organization</term> means an organization that is described in <external-xref legal-doc="usc" parsable-cite="usc/26/501">section 501(c)(3)</external-xref> of the Internal Revenue Code of 1986 and exempt from taxation under section 501(a) of such Code.</text></paragraph> 
<paragraph id="HE7E72DB89FB542D195FE4C3E8F713C55"><enum>(20)</enum><header>Parent</header><text display-inline="yes-display-inline">The term <term>parent</term>, with respect to a child or teen, means an adult with the legal right to make decisions on behalf of the child or teen, including—</text> <subparagraph id="H306211EABFD8400D87BDD028A6B6FC23"><enum>(A)</enum><text>a natural parent;</text></subparagraph> 
<subparagraph id="H6A72F4ED9BDF44D9A056F2E65CC63273"><enum>(B)</enum><text>an adoptive parent;</text></subparagraph> <subparagraph id="H5B90DCB2C4674BE093A255E7DA443A1B"><enum>(C)</enum><text>a legal guardian; and</text></subparagraph> 
<subparagraph id="HCF682E5B225C4A1B9F3E4E7F4CC423A5"><enum>(D)</enum><text>an individual with legal custody over the child or teen.</text></subparagraph></paragraph> <paragraph id="H943E50691D114BF68DFE9ED2B21A3C26"><enum>(21)</enum><header>Personal data</header><text>The term <term>personal data</term>—</text> 
<subparagraph id="H5715781B880643F7865DE2C3F90AF1EC"><enum>(A)</enum><text>means any information that is linked or reasonably linkable to an identified or identifiable natural person; and</text></subparagraph> <subparagraph id="HD96FB39FC04A4A429923A414ADBF7C4F"><enum>(B)</enum><text>does not include deidentified data or publicly available information.</text></subparagraph></paragraph> 
<paragraph id="H173C3FED18BF4C9C9C0350E6B86FD846"><enum>(22)</enum><header>Precise geolocation data</header><text>The term <term>precise geolocation data</term>—</text> <subparagraph id="H7B7DDA26ACBE49CF96FE83C5E85808E6"><enum>(A)</enum><text>means information derived from technology, including global positioning system level latitude and longitude coordinates or other mechanisms, that directly identifies the specific location of a natural person with precision and accuracy within a radius of 1,750 feet; and</text></subparagraph> 
<subparagraph id="H781519F03FD4486284D0CA21D554FB70"><enum>(B)</enum><text>does not include—</text> <clause id="HD67B25D019004CBBBC748695EE97B315"><enum>(i)</enum><text>the content of communications; or</text></clause> 
<clause id="H7B6D637E8FDA482F9E58118A6DC15D34"><enum>(ii)</enum><text>any data generated by or connected to advanced utility metering infrastructure systems or equipment for use by a utility.</text></clause></subparagraph></paragraph> <paragraph id="H6BB2EBA0CD0E48CA8F14FFC7A37875E9"><enum>(23)</enum><header>Process or processing</header><text>The term <term>process</term> or <term>processing</term> means any operation or set of operations performed, whether by manual or automated means, on personal data or on sets of personal data, such as the collection, use, storage, disclosure, analysis, deletion, or modification of personal data.</text></paragraph> 
<paragraph id="HA520FF93F5064491A71BF9408A55FD54"><enum>(24)</enum><header>Processor</header><text>The term <term>processor</term> means a person that processes personal data on behalf of a controller.</text></paragraph> <paragraph id="H863F9B92118B4D6B869DD3E835DFD710"><enum>(25)</enum><header>Profiling</header><text display-inline="yes-display-inline">The term <term>profiling</term> means any form of processing that is solely automated and performed on personal data to evaluate, analyze, or predict personal aspects of the economic situation, health, personal preference, interest, reliability, behavior, location, or movement of an identified or identifiable consumer.</text></paragraph> 
<paragraph id="H02B16427A7104B09A182DBEA26F67062"><enum>(26)</enum><header>Pseudonymous data</header><text>The term <term>pseudonymous data</term> means personal data that cannot be attributed to a specific individual without the use of additional information if the additional information is kept separately and is subject to appropriate administrative and technical measures to ensure that the personal data is not attributed to an identified or identifiable individual.</text></paragraph> <paragraph id="HAEF7453C1AB146E0AE9B010F44424BE2"><enum>(27)</enum><header>Publicly available information</header><text>The term <term>publicly available information</term> means information that is lawfully made available through Federal, State, or local government records, or information that a business has a reasonable basis to believe is lawfully made available to the public through widely distributed media, by the consumer, or by a person to whom the consumer has disclosed the information, unless the consumer has restricted the information to a specific audience.</text></paragraph> 
<paragraph id="HBB3DF5BCB9D5490E92DF94AAECAEBBC1"><enum>(28)</enum><header>Sale of personal data</header><text>The term <term>sale of personal data</term>—</text> <subparagraph id="H7770D0A28A7B49F8B3CB0C3071EED993"><enum>(A)</enum><text>means the exchange of personal data for monetary consideration by the controller to another controller or to a governmental entity; and</text></subparagraph> 
<subparagraph id="HD5FF1E0103BE4E958E22EC45BB07E4C9"><enum>(B)</enum><text>does not include—</text> <clause id="H9175F5E5260A4C718184B2F33CAB468B"><enum>(i)</enum><text>the disclosure of personal data to a processor that processes the personal data on behalf of the controller;</text></clause> 
<clause id="H37361075E73B46B28875CEFB8348CE80"><enum>(ii)</enum><text>the disclosure of personal data to another controller for the purposes of providing a product or service requested by the consumer;</text></clause> <clause id="H191932E686484BE4834CF6D9AFDFF34D"><enum>(iii)</enum><text>the disclosure or transfer of personal data to an affiliate of the controller;</text></clause> 
<clause id="H94A1C92AF7B54B3DA0F583582C12752A"><enum>(iv)</enum><text>the disclosure of information that the consumer intentionally made available to the public;</text></clause> <clause id="HF5208D5B80CE4EFDB5107C05E4093C9E"><enum>(v)</enum><text display-inline="yes-display-inline">the disclosure or transfer of personal data to another controller as an asset that is part of a merger, acquisition, bankruptcy, or other transaction in which the new controller assumes control of any of the assets of the previous controller; or</text></clause> 
<clause id="HC576132FDF474AD396CC6791024D6698"><enum>(vi)</enum><text>the disclosure of personal data in the course of reporting, news-gathering, speaking, or other activities intended to inform the public on matters of public interest or public concern.</text></clause></subparagraph></paragraph> <paragraph id="H4234A6AF9E5C4805B4CA3C230D042267"><enum>(29)</enum><header>Secretary</header><text>The term <term>Secretary</term> means the Secretary of Commerce.</text></paragraph> 
<paragraph id="H6258F957126F4BE18DCBC3DB46B5B578"><enum>(30)</enum><header>Sensitive data</header><text>The term <term>sensitive data</term> means a category of personal data that includes—</text> <subparagraph id="HEA14C3AA4B3848EA82589752202C6170"><enum>(A)</enum><text>personal data that discloses racial or ethnic origin, religious belief, mental or physical health diagnosis, sexual orientation, or citizenship or immigration status;</text></subparagraph> 
<subparagraph id="HE2D16060CBC744029C8697E401929732"><enum>(B)</enum><text>genetic or biometric data that is processed for the purpose of uniquely identifying a specific individual;</text></subparagraph> <subparagraph id="H77469AF4B95C496DA16185CA36A0E709"><enum>(C)</enum><text>personal data collected from a child or teen; and</text></subparagraph> 
<subparagraph id="H1DD921274C97432FA844E89268DBCB29"><enum>(D)</enum><text>precise geolocation data.</text></subparagraph></paragraph> <paragraph id="H888022FAD32E4E48BDFFD858336F2343" commented="no" display-inline="no-display-inline"><enum>(31)</enum><header>State</header><text display-inline="yes-display-inline">The term <term>State</term> means each State of the United States, the District of Columbia, each commonwealth, territory, or possession of the United States, and each federally recognized Indian Tribe.</text> </paragraph> 
<paragraph id="H60D5F0ADBAFC4FE2A518E1E5E15686D2"><enum>(32)</enum><header>Targeted advertising</header><text>The term <term>targeted advertising</term>—</text> <subparagraph id="H02E7C7C419B44B4985B7E9A0510D0864"><enum>(A)</enum><text>means to display an advertisement to a consumer in which the advertisement is selected based on personal data obtained from the activities of that consumer over time and across nonaffiliated websites or online applications to predict the preferences or interests of that consumer; and</text></subparagraph> 
<subparagraph id="HB85D8A62B21D43239212CEEF05A8502B"><enum>(B)</enum><text>does not include—</text> <clause id="H54C2DA3B7309450D8542138228935390"><enum>(i)</enum><text>an advertisement based on activities within the website or online application of a controller;</text></clause> 
<clause id="H481237F9901C4E6EA07FE0EC0E0BF4F7"><enum>(ii)</enum><text>an advertisement based on the context of a current search query, visit to a website, or online application of a consumer;</text></clause> <clause id="H4A1C842DEBED4542B4AD9744E00D2412"><enum>(iii)</enum><text>an advertisement directed to a consumer in response to the request for information or feedback by the consumer; or</text></clause> 
<clause id="H01FA1D390D434E8CAED32125BC679275"><enum>(iv)</enum><text>processing personal data processed solely for measuring or reporting advertising or content performance, reach, or frequency, including independent measurement.</text></clause></subparagraph> </paragraph> <paragraph id="H5610CD3BFBF342B691C0BF31C3662D1E"><enum>(33)</enum><header>Teen</header><text display-inline="yes-display-inline">The term <term>teen</term> means an individual who is the age of 13 or over and under the age of 16.</text></paragraph> 
<paragraph id="H1845BD55B5ED475A83937D66D2A16D2E"><enum>(34)</enum><header>Trade secret</header><text>The term <term>trade secret</term> has the meaning given that term in section 1839 of title 18, United States Code.</text></paragraph> <paragraph id="H999BE8D9DCFB46AEB743976A235A25DE"><enum>(35)</enum><header>Verifiable consent</header><text display-inline="yes-display-inline">The term <term>verifiable consent</term> means any reasonable effort (taking into consideration available technology) by a controller, including a request for authorization for future processing of personal data, to ensure that the parent of a teen—</text> 
<subparagraph id="H483F99486E694A41A91D1CCEACBF6E37"><enum>(A)</enum><text display-inline="yes-display-inline">receives direct notice of the processing practices of the controller with respect to personal data; and</text></subparagraph> <subparagraph id="H89F0A52FB0F447B588D479FCD6D8B679"><enum>(B)</enum><text>before the personal data of the teen is collected, freely and unambiguously authorizes—</text> 
<clause id="H3C7136952B9048459D16A9C5DFAF2A22"><enum>(i)</enum><text>the processing of the personal data; and</text></clause> <clause id="HDD8A620B85B24B57AA12DC914920C4A4"><enum>(ii)</enum><text>any subsequent use of the personal data.</text></clause></subparagraph></paragraph> </section> 
<section id="HAD19B009353A404182680B284958DEB9" commented="no"><enum>17.</enum><header>Severability</header><text display-inline="no-display-inline">If any provision of this Act or the application of this Act to any person or circumstance is held invalid, the remaining provisions of this Act and the application of this Act to other persons or circumstances shall not be affected.</text></section> <section id="HF29DAEBCC662459D89C140B602BA468A"><enum>18.</enum><header>Effective dates</header> <subsection id="H015BA82F26184DD98D2BFABAEE858124"><enum>(a)</enum><header>In general</header><text display-inline="yes-display-inline">Except as provided in subsection (b), this Act shall take effect 2 years after the date of the enactment of this Act.</text></subsection> 
<subsection id="H2AAEE48BB14A4F1B80399E86DB5F508C" commented="no"><enum>(b)</enum><header>Exceptions</header><text display-inline="yes-display-inline">Notwithstanding subsection (a), sections 2, 4, and 5 shall take effect 1 year after the date of the enactment of this Act.</text> </subsection></section> </legis-body></bill>

