[Congressional Record Volume 164, Number 40 (Wednesday, March 7, 2018)]
[Senate]
[Pages S1498-S1501]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]

  SA 2143. Mr. CARPER (for himself and Mr. Blunt) submitted an 
amendment intended to be proposed by him to the bill S. 2155, to 
promote economic growth, provide tailored regulatory relief, and 
enhance consumer protections, and for other purposes; which was ordered 
to lie on the table; as follows:

       At the appropriate place, insert the following:

     SEC. ___. DATA SECURITY.

       (a) Purposes.--The purposes of this section are--
       (1) to establish strong and uniform national data security 
     and breach notification standards for electronic data; and
       (2) to expressly preempt any related State laws in order to 
     provide the Federal Trade Commission with authority to 
     enforce such standards for entities covered under this 
     section.
       (b) Definitions.--For purposes of this section, the 
     following definitions shall apply:
       (1) Affiliate.--The term ``affiliate'' means any company 
     that controls, is controlled by, or is under common control 
     with another company.
       (2) Agency.--The term ``agency'' has the meaning given the 
     term in section 551 of title 5, United States Code.
       (3) Breach of data security.--The term ``breach of data 
     security''--
       (A) means the unauthorized acquisition of sensitive account 
     information or sensitive personal information; and
       (B) does not include the unauthorized acquisition of 
     sensitive account information or sensitive personal 
     information that is encrypted, redacted, or otherwise 
     protected by another method that renders the information 
     unreadable and unusable if the encryption, redaction, or 
     protection process or key is not also acquired without 
     authorization.
       (4) Carrier.--The term ``carrier'' means any entity that--
       (A) provides electronic data transmission, routing, 
     intermediate, and transient storage, or connections to the 
     system or network of the entity;
       (B) does not select or modify the content of the electronic 
     data;
       (C) is not the sender or the intended recipient of the 
     data; and
       (D) does not differentiate sensitive account information or 
     sensitive personal information from other information that 
     the entity transmits, routes, stores in intermediate or 
     transient storage, or for which such entity provides 
     connections.
       (5) Commission.--The term ``Commission'' means the Federal 
     Trade Commission.
       (6) Consumer.--The term ``consumer'' means an individual.
       (7) Consumer reporting agency that compiles and maintains 
     files on consumers on a nationwide basis.--The term 
     ``consumer reporting agency that compiles and maintains files 
     on consumers on a nationwide basis'' has the meaning given 
     the term in section 603(p) of the Fair Credit Reporting Act 
     (15 U.S.C. 1681a(p)).
       (8) Covered entity.--The term ``covered entity''--
       (A) means any individual, partnership, corporation, trust, 
     estate, cooperative, association, or entity that accesses, 
     maintains, communicates, or handles sensitive account 
     information or sensitive personal information; and

[[Page S1499]]

       (B) does not include--
       (i) an agency; or
       (ii) any other unit of Federal, State, or local government 
     or any subdivision of such a unit.
       (9) Financial institution.--The term ``financial 
     institution'' has the meaning given the term in section 509 
     of the Gramm-Leach-Bliley Act (15 U.S.C. 6809).
       (10) Information security program.--The term ``information 
     security program'' means the administrative, technical, or 
     physical safeguards that a covered entity uses to access, 
     collect, distribute, process, protect, store, use, transmit, 
     dispose of, or otherwise handle sensitive account information 
     and sensitive personal information.
       (11) Sensitive account information.--The term ``sensitive 
     account information'' means a financial account number 
     relating to a consumer, including a credit card number or 
     debit card number, in combination with any security code, 
     access code, password, or other personal identification 
     information required to access the financial account.
       (12) Sensitive personal information.--The term ``sensitive 
     personal information''--
       (A) means--
       (i) a Social Security number; or
       (ii) the first and last name of a consumer in combination 
     with--

       (I) the consumer's driver's license number, passport 
     number, military identification number, or other similar 
     number issued on a government document used to verify 
     identity;
       (II) information that could be used to access a consumer's 
     account, such as a user name and password or e-mail and 
     password; or
       (III) biometric data of the consumer used to gain access to 
     financial accounts of the consumer; and

       (B) does not include publicly available information that 
     is--
       (i) lawfully made available to the general public; and
       (ii) obtained from--

       (I) Federal, State, or local government records; or
       (II) widely distributed media.

       (13) Substantial harm or inconvenience.--The term 
     ``substantial harm or inconvenience'' means--
       (A) identity theft; or
       (B) fraudulent transactions on financial accounts.
       (14) Third-party service provider.--The term ``third-party 
     service provider'' means any person that maintains, 
     processes, or otherwise is permitted access to sensitive 
     account information or sensitive personal information in 
     connection with providing services to a covered entity.
       (c) Protection of Information and Security Breach 
     Notification.--
       (1) Security procedures required.--
       (A) In general.--Each covered entity shall develop, 
     implement, and maintain a comprehensive information security 
     program that contains administrative, technical, and physical 
     safeguards that are reasonably designed to achieve the 
     objectives in subparagraph (B).
       (B) Objectives.--The objectives of this paragraph are to--
       (i) ensure the security and confidentiality of sensitive 
     account information and sensitive personal information;
       (ii) protect against any anticipated threats or hazards to 
     the security or integrity of such information; and
       (iii) protect against unauthorized acquisition of such 
     information that could result in substantial harm to the 
     individuals to whom such information relates.
       (C) Limitation.--The information security program of a 
     covered entity under subparagraph (A) shall be appropriate 
     to--
       (i) the size and complexity of the covered entity;
       (ii) the nature and scope of the activities of the covered 
     entity; and
       (iii) the sensitivity of the consumer information to be 
     protected.
       (D) Elements.--In order to develop, implement, and maintain 
     an information security program required under subparagraph 
     (A), a covered entity shall--
       (i) designate an employee or employees to coordinate the 
     information security program;
       (ii) identify reasonably foreseeable internal and external 
     risks to the security, confidentiality, and integrity of 
     sensitive account information and sensitive personal 
     information and assess the sufficiency of any safeguards in 
     place to control these risks, including consideration of 
     risks in each relevant area of the operations of the covered 
     entity, including--

       (I) employee training and management;
       (II) information systems, including network and software 
     design and information processing, storage, transmission, and 
     disposal; and
       (III) detecting, preventing, and responding to attacks, 
     intrusions, or other systems failures;

       (iii) design and implement information safeguards to 
     control the risks identified in the risk assessment of the 
     covered entity and regularly assess the effectiveness of the 
     key controls, systems, and procedures of those safeguards;
       (iv) oversee service providers by--

       (I) taking reasonable steps to select and retain service 
     providers that are capable of maintaining appropriate 
     safeguards for the sensitive account information or sensitive 
     personal information at issue;
       (II) requiring service providers, by contract, to implement 
     and maintain the safeguards described in clause (iii); and
       (III) reasonably oversee or obtain an assessment of the 
     compliance by the service provider with contractual 
     obligations, where appropriate in light of the risk 
     assessment of the covered entity; and

       (v) evaluate and adjust the information security program in 
     light of the results of the risk assessments and testing and 
     monitoring required by clauses (iii) and (iv) and any 
     material changes to the operations or business arrangements 
     of the covered entity, or any other circumstances that the 
     covered entity knows or has reason to know may have a 
     material impact on the information security program of the 
     covered entity.
       (E) Security controls.--
       (i) In general.--Each covered entity shall--

       (I) consider whether the security measures described in 
     clause (ii) are appropriate for the covered entity and, if 
     so, adopt those measures that the covered entity concludes 
     are appropriate;
       (II) develop, implement, and maintain appropriate measures 
     to properly dispose of sensitive account information and 
     sensitive personal information; and
       (III) train staff to implement the covered entity's 
     information security program.

       (ii) Security measures.--The security measures described in 
     this clause are the following:

       (I) Access controls on information systems, including 
     controls to authenticate and permit access only to authorized 
     individuals and controls to prevent employees from providing 
     sensitive account information or sensitive personal 
     information to unauthorized individuals who may seek to 
     obtain that information through fraudulent means.
       (II) Access restrictions at physical locations containing 
     sensitive account information or sensitive personal 
     information, such as buildings, computer facilities, and 
     records storage facilities, to permit access only to 
     authorized individuals.
       (III) Encryption of electronic sensitive account 
     information or sensitive personal information, including 
     while in transit or in storage on networks or systems to 
     which unauthorized individuals may have access.
       (IV) Procedures designed to ensure that information system 
     modifications are consistent with the information security 
     program of the covered entity.
       (V) Dual control procedures, segregation of duties, and 
     employee background checks for employees with 
     responsibilities for, or access to, sensitive account 
     information or sensitive personal information.
       (VI) Monitoring systems and procedures to detect actual and 
     attempted attacks on, or intrusions into, information 
     systems.
       (VII) Response programs that specify actions to be taken 
     when the covered entity suspects or detects that unauthorized 
     individuals have gained access to information systems.
       (VIII) Measures to protect against destruction, loss, or 
     damage of sensitive account information or sensitive personal 
     information due to potential environmental hazards, such as 
     fire and water damage, or technological failures.

       (F) Administrative requirements.--
       (i) Board oversight.--If a covered entity has a board of 
     directors, the board of directors of the covered entity, or 
     an appropriate committee of the board of directors, shall--

       (I) approve the written information security program of the 
     covered entity; and
       (II) oversee the development, implementation, and 
     maintenance of the information security program of the 
     covered entity, including assigning specific responsibility 
     for the implementation of the program and reviewing reports 
     from management.

       (ii) Report to the board.--If a covered entity has a board 
     of directors, the covered entity shall report to the board, 
     or an appropriate committee of the board, at least annually, 
     including describing--

       (I) the overall status of the information security program 
     and the compliance of the covered entity with this section; 
     and
       (II) material matters related to the program of the covered 
     entity, addressing issues such as risk assessment, risk 
     management and control decisions, service provider 
     arrangements, results of testing, security breaches or 
     violations and management's responses, and recommendations 
     for changes in the information security program.

       (2) Investigation required.--
       (A) In general.--If a covered entity believes that a breach 
     of data security has or may have occurred in relation to 
     sensitive account information or sensitive personal 
     information that is maintained, communicated, or otherwise 
     handled by, or on behalf of, the covered entity, the covered 
     entity shall conduct an investigation to--
       (i) assess the nature and scope of the incident;
       (ii) identify any sensitive account information or 
     sensitive personal information that may have been involved in 
     the incident;
       (iii) determine if the sensitive account information or 
     sensitive personal information has been acquired without 
     authorization; and
       (iv) take reasonable measures to restore the security and 
     confidentiality of the systems compromised in the breach.
       (3) Notice required.--If a covered entity determines under 
     paragraph (2)(A)(iii) that

[[Page S1500]]

     the unauthorized acquisition of sensitive account information 
     or sensitive personal information involved in a breach of 
     data security is reasonably likely to cause substantial harm 
     to the consumers to whom the information relates, the covered 
     entity, or a third party acting on behalf of the covered 
     entity, shall--
       (A) notify, without unreasonable delay--
       (i) an appropriate Federal law enforcement agency;
       (ii) the appropriate agency or authority identified in 
     subsection (d);
       (iii) any relevant payment card network, if the breach 
     involves a breach of payment card numbers;
       (iv) each consumer reporting agency that compiles and 
     maintains files on consumers on a nationwide basis, if the 
     breach involves sensitive personal information or sensitive 
     account information relating to not fewer than 5,000 
     consumers; and
       (v) all consumers to whom the sensitive account information 
     or sensitive personal information relates;
       (B) provide notice to consumers by--
       (i) written notification sent to the postal address of the 
     consumer in the records of the covered entity;
       (ii) telephonic notification to the number of the consumer 
     in the records of the covered entity;
       (iii) e-mail of the consumer or other electronic means in 
     the records of the covered entity; or
       (iv) substitute notification in print and to broadcast 
     media where the individual whose personal information was 
     acquired resides, if providing written or e-mail notification 
     is not feasible due to--

       (I) lack of sufficient contact information for the 
     consumers that must be notified;
       (II) excessive cost to the covered entity; or
       (III) exigent circumstances; and

       (C) provide notice that includes--
       (i) a description of the type of sensitive account 
     information or sensitive personal information involved in the 
     breach of data security;
       (ii) a general description of the actions taken by the 
     covered entity to restore the security and confidentiality of 
     the sensitive account information or sensitive personal 
     information involved in the breach of data security; and
       (iii) a summary of rights of victims of identity theft 
     prepared by the Commission under section 609(d) of the Fair 
     Credit Reporting Act (15 U.S.C. 1681g(d)), if the breach of 
     data security involves sensitive personal information.
       (4) Clarification.--A financial institution shall have no 
     obligation under this section for a breach of security at 
     another covered entity involving sensitive account 
     information relating to an account owned by the financial 
     institution.
       (5) Special notification requirements.--
       (A) Third-party service providers.--In the event of a 
     breach of data security of a system maintained by a third-
     party entity that has been contracted to maintain, store, or 
     process data in electronic form containing sensitive account 
     information or sensitive personal information on behalf of a 
     covered entity that owns or possesses that data, that third-
     party entity shall notify--
       (i) the covered entity; and
       (ii) consumers if it is agreed in writing that the third-
     party service provider will provide that notification on 
     behalf of the covered entity.
       (B) Carrier obligations.--
       (i) In general.--If a carrier becomes aware of a breach of 
     data security involving data in electronic form containing 
     sensitive account information or sensitive personal 
     information that is owned or licensed by a covered entity 
     that connects to or uses a system or network provided by the 
     carrier for the purpose of transmitting, routing, or 
     providing intermediate or transient storage of that data, the 
     carrier shall notify the covered entity that initiated such 
     connection, transmission, routing, or storage of the data 
     containing sensitive account information or sensitive 
     personal information, if such covered entity can be 
     reasonably identified. If a service provider is acting solely 
     as a service provider for purposes of this paragraph, the 
     service provider has no other notification obligations under 
     this subsection.
       (ii) Covered entities who receive notice from carriers.--
     Upon receiving notification from a service provider under 
     subparagraph (A), a covered entity shall provide notification 
     as required under this subsection.
       (C) Communications with account holders.--If a covered 
     entity that is not a financial institution experiences a 
     breach of data security involving sensitive account 
     information, a financial institution that issues an account 
     to which the sensitive account information relates may 
     communicate with the account holder regarding the breach, 
     including--
       (i) an explanation that the financial institution was not 
     breached, and that the breach occurred at a third-party that 
     had access to the sensitive account information of the 
     consumer; or
       (ii) identify the covered entity that experienced the 
     breach after the covered entity has provided notice 
     consistent with this section.
       (6) Compliance.--
       (A) In general.--An entity shall be deemed to be in 
     compliance with--
       (i) in the case of a financial institution--

       (I) paragraph (1), if the financial institution maintains 
     policies and procedures to protect the confidentiality and 
     security of sensitive account information and sensitive 
     personal information that are consistent with the policies 
     and procedures of the financial institution that are designed 
     to comply with the requirements of section 501(b) of the 
     Gramm-Leach-Bliley Act (15 U.S.C. 6801(b)) and any 
     regulations or guidance prescribed under that section that 
     are applicable to the financial institution; and
       (II) paragraphs (2) and (3), if the financial institution--

       (aa)(AA) maintains policies and procedures to investigate 
     and provide notice to consumers of breaches of data security 
     that are consistent with the policies and procedures of the 
     financial institution that are designed to comply with the 
     investigation and notice requirements established by 
     regulations or guidance under section 501(b) of the Gramm-
     Leach-Bliley Act (15 U.S.C. 6801(b)) that are applicable to 
     the financial institution;
       (BB) is an affiliate of a bank holding company that 
     maintains policies and procedures to investigate and provide 
     notice to consumers of breaches of data security that are 
     consistent with the policies and procedures of a bank that is 
     an affiliate of the financial institution, and the policies 
     and procedures of the bank are designed to comply with the 
     investigation and notice requirements established by any 
     regulations or guidance under section 501(b) of the Gramm-
     Leach-Bliley Act (15 U.S.C. 6801(b)) that are applicable to 
     the bank; or
       (CC) is an affiliate of a savings and loan holding company 
     that maintains policies and procedures to investigate and 
     provide notice to consumers of data breaches of data security 
     that are consistent with the policies and procedures of a 
     savings association that is an affiliate of the financial 
     institution and the policies and procedures of the savings 
     association are designed to comply with the investigation and 
     notice requirements established by any regulations or 
     guidelines under section 501(b) of the Gramm-Leach-Bliley Act 
     (15 U.S.C. 6801(b)) that are applicable to savings 
     associations; and
       (bb) provides for notice to the entities described under 
     clauses (ii), (iii), and (iv) of paragraph (3)(A), if notice 
     is provided to consumers pursuant to the policies and 
     procedures of the financial institution described in item 
     (aa); and
       (ii) paragraphs (1), (2), and (3)--

       (I) if the entity is a covered entity for purposes of the 
     regulations promulgated under section 264(c) of the Health 
     Insurance Portability and Accountability Act of 1996 (42 
     U.S.C. 1320d-2 note), to the extent that the entity is in 
     compliance with those regulations; or
       (II) if the entity is in compliance with sections 13402 and 
     13407 of the HITECH Act (42 U.S.C. 17932 and 17937).

       (B) Definitions.--In this paragraph--
       (i) the terms ``bank holding company'' and ``bank'' have 
     the meanings given those terms in section 2 of the Bank 
     Holding Company Act of 1956 (12 U.S.C. 1841);
       (ii) the term ``savings and loan holding company'' has the 
     meaning given the term in section 10(a) of the Home Owners' 
     Loan Act (12 U.S.C. 1467a(a)); and
       (iii) the term ``savings association'' has the meaning 
     given the term in section 2 of the Home Owners' Loan Act (12 
     U.S.C. 1462).
       (d) Administrative Enforcement.--
       (1) In general.--Notwithstanding any other provision of 
     law, subsection (c) shall be enforced exclusively under--
       (A) section 8 of the Federal Deposit Insurance Act (12 
     U.S.C. 1818), in the case of--
       (i) a national bank, a Federal branch or Federal agency of 
     a foreign bank, or any subsidiary thereof (other than a 
     broker, dealer, person providing insurance, investment 
     company, or investment adviser), or a savings association, 
     the deposits of which are insured by the Federal Deposit 
     Insurance Corporation, or any subsidiary thereof (other than 
     a broker, dealer, person providing insurance, investment 
     company, or investment adviser), by the Office of the 
     Comptroller of the Currency;
       (ii) a member bank of the Federal Reserve System (other 
     than a national bank), a branch or agency of a foreign bank 
     (other than a Federal branch, Federal agency, or insured 
     State branch of a foreign bank), a commercial lending company 
     owned or controlled by a foreign bank, an organization 
     operating under section 25 or 25A of the Federal Reserve Act 
     (12 U.S.C. 601, 611), or a bank holding company and its 
     nonbank subsidiary or affiliate (other than a broker, dealer, 
     person providing insurance, investment company, or investment 
     adviser), by the Board of Governors of the Federal Reserve 
     System; and
       (iii) a bank, the deposits of which are insured by the 
     Federal Deposit Insurance Corporation (other than a member of 
     the Federal Reserve System), an insured State branch of a 
     foreign bank, or any subsidiary thereof (other than a broker, 
     dealer, person providing insurance, investment company, or 
     investment adviser), by the Board of Directors of the Federal 
     Deposit Insurance Corporation;
       (B) the Federal Credit Union Act (12 U.S.C. 1751 et seq.), 
     by the National Credit Union Administration Board with 
     respect to any federally insured credit union;
       (C) the Securities Exchange Act of 1934 (15 U.S.C. 78a et 
     seq.), by the Securities and Exchange Commission with respect 
     to any broker or dealer;
       (D) the Investment Company Act of 1940 (15 U.S.C. 80a-1 et 
     seq.), by the Securities and Exchange Commission with respect 
     to any investment company;

[[Page S1501]]

       (E) the Investment Advisers Act of 1940 (15 U.S.C. 80b-1 et 
     seq.), by the Securities and Exchange Commission with respect 
     to any investment adviser registered with the Securities and 
     Exchange Commission under that Act;
       (F) the Commodity Exchange Act (7 U.S.C. 1 et seq.), by the 
     Commodity Futures Trading Commission with respect to any 
     futures commission merchant, commodity trading advisor, 
     commodity pool operator, or introducing broker;
       (G) the provisions of title XIII of the Housing and 
     Community Development Act of 1992 (12 U.S.C. 4501 et seq.), 
     by the Director of Federal Housing Enterprise Oversight (and 
     any successor to the functional regulatory agency) with 
     respect to the Federal National Mortgage Association, the 
     Federal Home Loan Mortgage Corporation, and any other entity 
     or enterprise (as defined in that title) subject to the 
     jurisdiction of the functional regulatory agency under that 
     title, including any affiliate of any the enterprise;
       (H) State insurance law, in the case of any person engaged 
     in providing insurance, by the applicable State insurance 
     authority of the State in which the person is domiciled; and
       (I) the Federal Trade Commission Act (15 U.S.C. 41 et 
     seq.), by the Commission for any other covered entity that is 
     not subject to the jurisdiction of any agency or authority 
     described under subparagraphs (A) through (H), including--
       (i) notwithstanding section 5(a)(2) of the Federal Trade 
     Commission Act (15 U.S.C. 45(a)(2)), common carriers subject 
     to the Communications Act of 1934 (47 U.S.C. 151 et seq.);
       (ii) notwithstanding the Federal Aviation Act of 1958 (49 
     U.S.C. App. 1301 et seq.), include the authority to enforce 
     compliance by air carriers and foreign air carriers; and
       (iii) notwithstanding the Packers and Stockyards Act (7 
     U.S.C. 181 et seq.), include the authority to enforce 
     compliance by persons, partnerships, and corporations subject 
     to the provisions of that Act.
       (2) Application to cable operators, satellite operators, 
     and telecommunications carriers.--
       (A) Data security and breach notification.--Sections 201, 
     202, 222, 338, and 631 of the Communications Act of 1934 (47 
     U.S.C. 201, 202, 222, 338, and 551), and any regulations 
     promulgated in accordance with those sections, shall not 
     apply with respect to the information security practices, 
     including practices relating to the notification of 
     unauthorized access to data in electronic form, of any 
     covered entity otherwise subject to those sections.
       (B) Rule of construction.--Nothing in this paragraph 
     otherwise limits authority of the Federal Communication 
     Commission with respect to sections 201, 202, 222, 338, and 
     631 of the Communications Act of 1934 (47 U.S.C. 201, 202, 
     222, 338, and 551).
       (3) No private right of action.--
       (A) In general.--This section may not be construed to 
     provide a private right of action, including a class action 
     with respect to any Act or practice regulated under this 
     section.
       (B) Exception.--A consumer or entity that suffers financial 
     harm as a result of the violation by a covered entity of this 
     section may bring an action in a district court of the United 
     States for the judicial district in which the consumer or 
     entity suffered the harm against the covered entity to 
     recover--
       (i) in the case of a negligent violation of this section, 
     actual financial damages, court costs allowed by the rules of 
     the court, and reasonable attorney's fees; and
       (ii) in the case of a knowing violation of this section, 
     the damages, costs, and attorney's fees described in clause 
     (i) of this subsection and punitive damages.
       (e) Relation to State Law.--No requirement or prohibition 
     may be imposed under the laws of any State with respect to 
     the responsibilities of any person to--
       (1) protect the security of information relating to 
     consumers that is maintained, communicated, or otherwise 
     handled by, or on behalf of, the person;
       (2) safeguard information relating to consumers from--
       (A) unauthorized access; and
       (B) unauthorized acquisition;
       (3) investigate or provide notice of the unauthorized 
     acquisition of, or access to, information relating to 
     consumers, or the potential misuse of the information, for 
     fraudulent, illegal, or other purposes; or
       (4) mitigate any potential or actual loss or harm resulting 
     from the unauthorized acquisition of, or access to, 
     information relating to consumers.
       (f) Delayed Effective Date for Certain Provisions.--
     Subsections (c) and (e) shall take effect on the date that is 
     1 year after the date of enactment of this Act.
                                 ______