[Congressional Record Volume 164, Number 40 (Wednesday, March 7, 2018)]
[Senate]
[Pages S1498-S1501]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]
SA 2143. Mr. CARPER (for himself and Mr. Blunt) submitted an
amendment intended to be proposed by him to the bill S. 2155, to
promote economic growth, provide tailored regulatory relief, and
enhance consumer protections, and for other purposes; which was ordered
to lie on the table; as follows:
At the appropriate place, insert the following:
SEC. ___. DATA SECURITY.
(a) Purposes.--The purposes of this section are--
(1) to establish strong and uniform national data security
and breach notification standards for electronic data; and
(2) to expressly preempt any related State laws in order to
provide the Federal Trade Commission with authority to
enforce such standards for entities covered under this
section.
(b) Definitions.--For purposes of this section, the
following definitions shall apply:
(1) Affiliate.--The term ``affiliate'' means any company
that controls, is controlled by, or is under common control
with another company.
(2) Agency.--The term ``agency'' has the meaning given the
term in section 551 of title 5, United States Code.
(3) Breach of data security.--The term ``breach of data
security''--
(A) means the unauthorized acquisition of sensitive account
information or sensitive personal information; and
(B) does not include the unauthorized acquisition of
sensitive account information or sensitive personal
information that is encrypted, redacted, or otherwise
protected by another method that renders the information
unreadable and unusable if the encryption, redaction, or
protection process or key is not also acquired without
authorization.
(4) Carrier.--The term ``carrier'' means any entity that--
(A) provides electronic data transmission, routing,
intermediate, and transient storage, or connections to the
system or network of the entity;
(B) does not select or modify the content of the electronic
data;
(C) is not the sender or the intended recipient of the
data; and
(D) does not differentiate sensitive account information or
sensitive personal information from other information that
the entity transmits, routes, stores in intermediate or
transient storage, or for which such entity provides
connections.
(5) Commission.--The term ``Commission'' means the Federal
Trade Commission.
(6) Consumer.--The term ``consumer'' means an individual.
(7) Consumer reporting agency that compiles and maintains
files on consumers on a nationwide basis.--The term
``consumer reporting agency that compiles and maintains files
on consumers on a nationwide basis'' has the meaning given
the term in section 603(p) of the Fair Credit Reporting Act
(15 U.S.C. 1681a(p)).
(8) Covered entity.--The term ``covered entity''--
(A) means any individual, partnership, corporation, trust,
estate, cooperative, association, or entity that accesses,
maintains, communicates, or handles sensitive account
information or sensitive personal information; and
[[Page S1499]]
(B) does not include--
(i) an agency; or
(ii) any other unit of Federal, State, or local government
or any subdivision of such a unit.
(9) Financial institution.--The term ``financial
institution'' has the meaning given the term in section 509
of the Gramm-Leach-Bliley Act (15 U.S.C. 6809).
(10) Information security program.--The term ``information
security program'' means the administrative, technical, or
physical safeguards that a covered entity uses to access,
collect, distribute, process, protect, store, use, transmit,
dispose of, or otherwise handle sensitive account information
and sensitive personal information.
(11) Sensitive account information.--The term ``sensitive
account information'' means a financial account number
relating to a consumer, including a credit card number or
debit card number, in combination with any security code,
access code, password, or other personal identification
information required to access the financial account.
(12) Sensitive personal information.--The term ``sensitive
personal information''--
(A) means--
(i) a Social Security number; or
(ii) the first and last name of a consumer in combination
with--
(I) the consumer's driver's license number, passport
number, military identification number, or other similar
number issued on a government document used to verify
identity;
(II) information that could be used to access a consumer's
account, such as a user name and password or e-mail and
password; or
(III) biometric data of the consumer used to gain access to
financial accounts of the consumer; and
(B) does not include publicly available information that
is--
(i) lawfully made available to the general public; and
(ii) obtained from--
(I) Federal, State, or local government records; or
(II) widely distributed media.
(13) Substantial harm or inconvenience.--The term
``substantial harm or inconvenience'' means--
(A) identity theft; or
(B) fraudulent transactions on financial accounts.
(14) Third-party service provider.--The term ``third-party
service provider'' means any person that maintains,
processes, or otherwise is permitted access to sensitive
account information or sensitive personal information in
connection with providing services to a covered entity.
(c) Protection of Information and Security Breach
Notification.--
(1) Security procedures required.--
(A) In general.--Each covered entity shall develop,
implement, and maintain a comprehensive information security
program that contains administrative, technical, and physical
safeguards that are reasonably designed to achieve the
objectives in subparagraph (B).
(B) Objectives.--The objectives of this paragraph are to--
(i) ensure the security and confidentiality of sensitive
account information and sensitive personal information;
(ii) protect against any anticipated threats or hazards to
the security or integrity of such information; and
(iii) protect against unauthorized acquisition of such
information that could result in substantial harm to the
individuals to whom such information relates.
(C) Limitation.--The information security program of a
covered entity under subparagraph (A) shall be appropriate
to--
(i) the size and complexity of the covered entity;
(ii) the nature and scope of the activities of the covered
entity; and
(iii) the sensitivity of the consumer information to be
protected.
(D) Elements.--In order to develop, implement, and maintain
an information security program required under subparagraph
(A), a covered entity shall--
(i) designate an employee or employees to coordinate the
information security program;
(ii) identify reasonably foreseeable internal and external
risks to the security, confidentiality, and integrity of
sensitive account information and sensitive personal
information and assess the sufficiency of any safeguards in
place to control these risks, including consideration of
risks in each relevant area of the operations of the covered
entity, including--
(I) employee training and management;
(II) information systems, including network and software
design and information processing, storage, transmission, and
disposal; and
(III) detecting, preventing, and responding to attacks,
intrusions, or other systems failures;
(iii) design and implement information safeguards to
control the risks identified in the risk assessment of the
covered entity and regularly assess the effectiveness of the
key controls, systems, and procedures of those safeguards;
(iv) oversee service providers by--
(I) taking reasonable steps to select and retain service
providers that are capable of maintaining appropriate
safeguards for the sensitive account information or sensitive
personal information at issue;
(II) requiring service providers, by contract, to implement
and maintain the safeguards described in clause (iii); and
(III) reasonably oversee or obtain an assessment of the
compliance by the service provider with contractual
obligations, where appropriate in light of the risk
assessment of the covered entity; and
(v) evaluate and adjust the information security program in
light of the results of the risk assessments and testing and
monitoring required by clauses (iii) and (iv) and any
material changes to the operations or business arrangements
of the covered entity, or any other circumstances that the
covered entity knows or has reason to know may have a
material impact on the information security program of the
covered entity.
(E) Security controls.--
(i) In general.--Each covered entity shall--
(I) consider whether the security measures described in
clause (ii) are appropriate for the covered entity and, if
so, adopt those measures that the covered entity concludes
are appropriate;
(II) develop, implement, and maintain appropriate measures
to properly dispose of sensitive account information and
sensitive personal information; and
(III) train staff to implement the covered entity's
information security program.
(ii) Security measures.--The security measures described in
this clause are the following:
(I) Access controls on information systems, including
controls to authenticate and permit access only to authorized
individuals and controls to prevent employees from providing
sensitive account information or sensitive personal
information to unauthorized individuals who may seek to
obtain that information through fraudulent means.
(II) Access restrictions at physical locations containing
sensitive account information or sensitive personal
information, such as buildings, computer facilities, and
records storage facilities, to permit access only to
authorized individuals.
(III) Encryption of electronic sensitive account
information or sensitive personal information, including
while in transit or in storage on networks or systems to
which unauthorized individuals may have access.
(IV) Procedures designed to ensure that information system
modifications are consistent with the information security
program of the covered entity.
(V) Dual control procedures, segregation of duties, and
employee background checks for employees with
responsibilities for, or access to, sensitive account
information or sensitive personal information.
(VI) Monitoring systems and procedures to detect actual and
attempted attacks on, or intrusions into, information
systems.
(VII) Response programs that specify actions to be taken
when the covered entity suspects or detects that unauthorized
individuals have gained access to information systems.
(VIII) Measures to protect against destruction, loss, or
damage of sensitive account information or sensitive personal
information due to potential environmental hazards, such as
fire and water damage, or technological failures.
(F) Administrative requirements.--
(i) Board oversight.--If a covered entity has a board of
directors, the board of directors of the covered entity, or
an appropriate committee of the board of directors, shall--
(I) approve the written information security program of the
covered entity; and
(II) oversee the development, implementation, and
maintenance of the information security program of the
covered entity, including assigning specific responsibility
for the implementation of the program and reviewing reports
from management.
(ii) Report to the board.--If a covered entity has a board
of directors, the covered entity shall report to the board,
or an appropriate committee of the board, at least annually,
including describing--
(I) the overall status of the information security program
and the compliance of the covered entity with this section;
and
(II) material matters related to the program of the covered
entity, addressing issues such as risk assessment, risk
management and control decisions, service provider
arrangements, results of testing, security breaches or
violations and management's responses, and recommendations
for changes in the information security program.
(2) Investigation required.--
(A) In general.--If a covered entity believes that a breach
of data security has or may have occurred in relation to
sensitive account information or sensitive personal
information that is maintained, communicated, or otherwise
handled by, or on behalf of, the covered entity, the covered
entity shall conduct an investigation to--
(i) assess the nature and scope of the incident;
(ii) identify any sensitive account information or
sensitive personal information that may have been involved in
the incident;
(iii) determine if the sensitive account information or
sensitive personal information has been acquired without
authorization; and
(iv) take reasonable measures to restore the security and
confidentiality of the systems compromised in the breach.
(3) Notice required.--If a covered entity determines under
paragraph (2)(A)(iii) that
[[Page S1500]]
the unauthorized acquisition of sensitive account information
or sensitive personal information involved in a breach of
data security is reasonably likely to cause substantial harm
to the consumers to whom the information relates, the covered
entity, or a third party acting on behalf of the covered
entity, shall--
(A) notify, without unreasonable delay--
(i) an appropriate Federal law enforcement agency;
(ii) the appropriate agency or authority identified in
subsection (d);
(iii) any relevant payment card network, if the breach
involves a breach of payment card numbers;
(iv) each consumer reporting agency that compiles and
maintains files on consumers on a nationwide basis, if the
breach involves sensitive personal information or sensitive
account information relating to not fewer than 5,000
consumers; and
(v) all consumers to whom the sensitive account information
or sensitive personal information relates;
(B) provide notice to consumers by--
(i) written notification sent to the postal address of the
consumer in the records of the covered entity;
(ii) telephonic notification to the number of the consumer
in the records of the covered entity;
(iii) e-mail of the consumer or other electronic means in
the records of the covered entity; or
(iv) substitute notification in print and to broadcast
media where the individual whose personal information was
acquired resides, if providing written or e-mail notification
is not feasible due to--
(I) lack of sufficient contact information for the
consumers that must be notified;
(II) excessive cost to the covered entity; or
(III) exigent circumstances; and
(C) provide notice that includes--
(i) a description of the type of sensitive account
information or sensitive personal information involved in the
breach of data security;
(ii) a general description of the actions taken by the
covered entity to restore the security and confidentiality of
the sensitive account information or sensitive personal
information involved in the breach of data security; and
(iii) a summary of rights of victims of identity theft
prepared by the Commission under section 609(d) of the Fair
Credit Reporting Act (15 U.S.C. 1681g(d)), if the breach of
data security involves sensitive personal information.
(4) Clarification.--A financial institution shall have no
obligation under this section for a breach of security at
another covered entity involving sensitive account
information relating to an account owned by the financial
institution.
(5) Special notification requirements.--
(A) Third-party service providers.--In the event of a
breach of data security of a system maintained by a third-
party entity that has been contracted to maintain, store, or
process data in electronic form containing sensitive account
information or sensitive personal information on behalf of a
covered entity that owns or possesses that data, that third-
party entity shall notify--
(i) the covered entity; and
(ii) consumers if it is agreed in writing that the third-
party service provider will provide that notification on
behalf of the covered entity.
(B) Carrier obligations.--
(i) In general.--If a carrier becomes aware of a breach of
data security involving data in electronic form containing
sensitive account information or sensitive personal
information that is owned or licensed by a covered entity
that connects to or uses a system or network provided by the
carrier for the purpose of transmitting, routing, or
providing intermediate or transient storage of that data, the
carrier shall notify the covered entity that initiated such
connection, transmission, routing, or storage of the data
containing sensitive account information or sensitive
personal information, if such covered entity can be
reasonably identified. If a service provider is acting solely
as a service provider for purposes of this paragraph, the
service provider has no other notification obligations under
this subsection.
(ii) Covered entities who receive notice from carriers.--
Upon receiving notification from a service provider under
subparagraph (A), a covered entity shall provide notification
as required under this subsection.
(C) Communications with account holders.--If a covered
entity that is not a financial institution experiences a
breach of data security involving sensitive account
information, a financial institution that issues an account
to which the sensitive account information relates may
communicate with the account holder regarding the breach,
including--
(i) an explanation that the financial institution was not
breached, and that the breach occurred at a third-party that
had access to the sensitive account information of the
consumer; or
(ii) identify the covered entity that experienced the
breach after the covered entity has provided notice
consistent with this section.
(6) Compliance.--
(A) In general.--An entity shall be deemed to be in
compliance with--
(i) in the case of a financial institution--
(I) paragraph (1), if the financial institution maintains
policies and procedures to protect the confidentiality and
security of sensitive account information and sensitive
personal information that are consistent with the policies
and procedures of the financial institution that are designed
to comply with the requirements of section 501(b) of the
Gramm-Leach-Bliley Act (15 U.S.C. 6801(b)) and any
regulations or guidance prescribed under that section that
are applicable to the financial institution; and
(II) paragraphs (2) and (3), if the financial institution--
(aa)(AA) maintains policies and procedures to investigate
and provide notice to consumers of breaches of data security
that are consistent with the policies and procedures of the
financial institution that are designed to comply with the
investigation and notice requirements established by
regulations or guidance under section 501(b) of the Gramm-
Leach-Bliley Act (15 U.S.C. 6801(b)) that are applicable to
the financial institution;
(BB) is an affiliate of a bank holding company that
maintains policies and procedures to investigate and provide
notice to consumers of breaches of data security that are
consistent with the policies and procedures of a bank that is
an affiliate of the financial institution, and the policies
and procedures of the bank are designed to comply with the
investigation and notice requirements established by any
regulations or guidance under section 501(b) of the Gramm-
Leach-Bliley Act (15 U.S.C. 6801(b)) that are applicable to
the bank; or
(CC) is an affiliate of a savings and loan holding company
that maintains policies and procedures to investigate and
provide notice to consumers of data breaches of data security
that are consistent with the policies and procedures of a
savings association that is an affiliate of the financial
institution and the policies and procedures of the savings
association are designed to comply with the investigation and
notice requirements established by any regulations or
guidelines under section 501(b) of the Gramm-Leach-Bliley Act
(15 U.S.C. 6801(b)) that are applicable to savings
associations; and
(bb) provides for notice to the entities described under
clauses (ii), (iii), and (iv) of paragraph (3)(A), if notice
is provided to consumers pursuant to the policies and
procedures of the financial institution described in item
(aa); and
(ii) paragraphs (1), (2), and (3)--
(I) if the entity is a covered entity for purposes of the
regulations promulgated under section 264(c) of the Health
Insurance Portability and Accountability Act of 1996 (42
U.S.C. 1320d-2 note), to the extent that the entity is in
compliance with those regulations; or
(II) if the entity is in compliance with sections 13402 and
13407 of the HITECH Act (42 U.S.C. 17932 and 17937).
(B) Definitions.--In this paragraph--
(i) the terms ``bank holding company'' and ``bank'' have
the meanings given those terms in section 2 of the Bank
Holding Company Act of 1956 (12 U.S.C. 1841);
(ii) the term ``savings and loan holding company'' has the
meaning given the term in section 10(a) of the Home Owners'
Loan Act (12 U.S.C. 1467a(a)); and
(iii) the term ``savings association'' has the meaning
given the term in section 2 of the Home Owners' Loan Act (12
U.S.C. 1462).
(d) Administrative Enforcement.--
(1) In general.--Notwithstanding any other provision of
law, subsection (c) shall be enforced exclusively under--
(A) section 8 of the Federal Deposit Insurance Act (12
U.S.C. 1818), in the case of--
(i) a national bank, a Federal branch or Federal agency of
a foreign bank, or any subsidiary thereof (other than a
broker, dealer, person providing insurance, investment
company, or investment adviser), or a savings association,
the deposits of which are insured by the Federal Deposit
Insurance Corporation, or any subsidiary thereof (other than
a broker, dealer, person providing insurance, investment
company, or investment adviser), by the Office of the
Comptroller of the Currency;
(ii) a member bank of the Federal Reserve System (other
than a national bank), a branch or agency of a foreign bank
(other than a Federal branch, Federal agency, or insured
State branch of a foreign bank), a commercial lending company
owned or controlled by a foreign bank, an organization
operating under section 25 or 25A of the Federal Reserve Act
(12 U.S.C. 601, 611), or a bank holding company and its
nonbank subsidiary or affiliate (other than a broker, dealer,
person providing insurance, investment company, or investment
adviser), by the Board of Governors of the Federal Reserve
System; and
(iii) a bank, the deposits of which are insured by the
Federal Deposit Insurance Corporation (other than a member of
the Federal Reserve System), an insured State branch of a
foreign bank, or any subsidiary thereof (other than a broker,
dealer, person providing insurance, investment company, or
investment adviser), by the Board of Directors of the Federal
Deposit Insurance Corporation;
(B) the Federal Credit Union Act (12 U.S.C. 1751 et seq.),
by the National Credit Union Administration Board with
respect to any federally insured credit union;
(C) the Securities Exchange Act of 1934 (15 U.S.C. 78a et
seq.), by the Securities and Exchange Commission with respect
to any broker or dealer;
(D) the Investment Company Act of 1940 (15 U.S.C. 80a-1 et
seq.), by the Securities and Exchange Commission with respect
to any investment company;
[[Page S1501]]
(E) the Investment Advisers Act of 1940 (15 U.S.C. 80b-1 et
seq.), by the Securities and Exchange Commission with respect
to any investment adviser registered with the Securities and
Exchange Commission under that Act;
(F) the Commodity Exchange Act (7 U.S.C. 1 et seq.), by the
Commodity Futures Trading Commission with respect to any
futures commission merchant, commodity trading advisor,
commodity pool operator, or introducing broker;
(G) the provisions of title XIII of the Housing and
Community Development Act of 1992 (12 U.S.C. 4501 et seq.),
by the Director of Federal Housing Enterprise Oversight (and
any successor to the functional regulatory agency) with
respect to the Federal National Mortgage Association, the
Federal Home Loan Mortgage Corporation, and any other entity
or enterprise (as defined in that title) subject to the
jurisdiction of the functional regulatory agency under that
title, including any affiliate of any the enterprise;
(H) State insurance law, in the case of any person engaged
in providing insurance, by the applicable State insurance
authority of the State in which the person is domiciled; and
(I) the Federal Trade Commission Act (15 U.S.C. 41 et
seq.), by the Commission for any other covered entity that is
not subject to the jurisdiction of any agency or authority
described under subparagraphs (A) through (H), including--
(i) notwithstanding section 5(a)(2) of the Federal Trade
Commission Act (15 U.S.C. 45(a)(2)), common carriers subject
to the Communications Act of 1934 (47 U.S.C. 151 et seq.);
(ii) notwithstanding the Federal Aviation Act of 1958 (49
U.S.C. App. 1301 et seq.), include the authority to enforce
compliance by air carriers and foreign air carriers; and
(iii) notwithstanding the Packers and Stockyards Act (7
U.S.C. 181 et seq.), include the authority to enforce
compliance by persons, partnerships, and corporations subject
to the provisions of that Act.
(2) Application to cable operators, satellite operators,
and telecommunications carriers.--
(A) Data security and breach notification.--Sections 201,
202, 222, 338, and 631 of the Communications Act of 1934 (47
U.S.C. 201, 202, 222, 338, and 551), and any regulations
promulgated in accordance with those sections, shall not
apply with respect to the information security practices,
including practices relating to the notification of
unauthorized access to data in electronic form, of any
covered entity otherwise subject to those sections.
(B) Rule of construction.--Nothing in this paragraph
otherwise limits authority of the Federal Communication
Commission with respect to sections 201, 202, 222, 338, and
631 of the Communications Act of 1934 (47 U.S.C. 201, 202,
222, 338, and 551).
(3) No private right of action.--
(A) In general.--This section may not be construed to
provide a private right of action, including a class action
with respect to any Act or practice regulated under this
section.
(B) Exception.--A consumer or entity that suffers financial
harm as a result of the violation by a covered entity of this
section may bring an action in a district court of the United
States for the judicial district in which the consumer or
entity suffered the harm against the covered entity to
recover--
(i) in the case of a negligent violation of this section,
actual financial damages, court costs allowed by the rules of
the court, and reasonable attorney's fees; and
(ii) in the case of a knowing violation of this section,
the damages, costs, and attorney's fees described in clause
(i) of this subsection and punitive damages.
(e) Relation to State Law.--No requirement or prohibition
may be imposed under the laws of any State with respect to
the responsibilities of any person to--
(1) protect the security of information relating to
consumers that is maintained, communicated, or otherwise
handled by, or on behalf of, the person;
(2) safeguard information relating to consumers from--
(A) unauthorized access; and
(B) unauthorized acquisition;
(3) investigate or provide notice of the unauthorized
acquisition of, or access to, information relating to
consumers, or the potential misuse of the information, for
fraudulent, illegal, or other purposes; or
(4) mitigate any potential or actual loss or harm resulting
from the unauthorized acquisition of, or access to,
information relating to consumers.
(f) Delayed Effective Date for Certain Provisions.--
Subsections (c) and (e) shall take effect on the date that is
1 year after the date of enactment of this Act.
______