Reasonable Expectation of American Privacy Act of 2013
A BILL
To amend title 18, United States Code, to provide increased protections for consumer or subscriber password information, and to amend the Foreign Intelligence Surveillance Act of 1978 to provide that the Director of the Federal Bureau of Investigation may not access password information pursuant to an order under section 501 of that Act, and for other purposes.
Sec. 2 Increased protections relating to voluntary disclosure of password information
“(4) a person or entity providing an electronic communication service or a remote computing service to the public shall not knowingly divulge to any person or entity the password information pertaining to a subscriber or customer of such service.”
“(d) Exceptions for Disclosure of Password Information—A provider described in subsection (a) may divulge the password information pertaining to a subscriber or customer of such service—
“(1) as otherwise authorized in 2703 of this title;
“(2) with the lawful consent of the subscriber or customer;
“(3) as may be necessarily incident to the rendition of the service or to the protection of the rights or property of the provider of that service;
“(4) to the National Center for Missing and Exploited Children, in connection with a report submitted thereto under section 2258A; or
“(5) to a governmental entity, if the provider, in good faith, believes that an emergency involving danger of death or serious physical injury to any person requires disclosure without delay of password information relating to the emergency.”
Sec. 3 Increased protections relating to required disclosure of customer communications and password information
“(b) Password information—A governmental entity may require a provider of electronic communication service or remote computing service to disclose the password information pertaining to a subscriber or customer of such service only pursuant to a warrant issued using the procedures described in the Federal Rules of Criminal Procedure (or in the case of a State court, issued using State warrant procedures) by a court of competent jurisdiction.”
Sec. 4 Password information excluded from transactional records available pursuant to a counterintelligence request
“(g) Password information—A request made pursuant to subsection (b) for electronic communication transactional records may not include a request for the password information pertaining to a subscriber or customer of a provider of electronic communication service or remote computing service.”