Personal Data Privacy and Security Act of 2014
A BILL
To prevent and mitigate identity theft, to ensure privacy, to provide notice of security breaches, and to enhance criminal penalties, law enforcement assistance, and other protections against security breaches, fraudulent access, and misuse of personally identifiable information.
Sec. 2 Findings
Congress finds that—
databases of personally identifiable information are increasingly prime targets of hackers, identity thieves, rogue employees, and other criminals, including organized and sophisticated criminal operations;
identity theft is a serious threat to the Nation's economic stability, national security, homeland security, cybersecurity, the development of e-commerce, and the privacy rights of Americans;
security breaches are a serious threat to consumer confidence, homeland security, national security, e-commerce, and economic stability;
it is important for business entities that own, use, or license personally identifiable information to adopt reasonable procedures to ensure the security, privacy, and confidentiality of that personally identifiable information;
individuals whose personal information has been compromised or who have been victims of identity theft should receive the necessary information and assistance to mitigate their damages and to restore the integrity of their personal information and identities;
data misuse and use of inaccurate data have the potential to cause serious or irreparable harm to an individual's livelihood, privacy, and liberty and undermine efficient and effective business and government operations;
government access to commercial data can potentially improve safety, law enforcement, and national security; and
because government use of commercial data containing personal information potentially affects individual privacy, and law enforcement and national security operations, there is a need for Congress to exercise oversight over government use of commercial data.
Sec. 3 Definitions
In this Act, the following definitions shall apply:
Affiliate— The term affiliate means persons related by common ownership or by corporate control.
Agency— The term agency has the same meaning given such term in section 551 of title 5, United States Code.
Business entity— The term business entity means any organization, corporation, trust, partnership, sole proprietorship, unincorporated association, or venture established to make a profit, or nonprofit.
Data system communication information— The term data system communication information means dialing, routing, addressing, or signaling information that identifies the origin, direction, destination, processing, transmission, or termination of each communication initiated, attempted, or received.
Designated entity— The term designated entity means the Federal Government entity designated by the Secretary of Homeland Security under section 216(a).
Encryption— The term encryption—
means the protection of data in electronic form, in storage or in transit, using an encryption technology that has been generally accepted by experts in the field of information security that renders such data indecipherable in the absence of associated cryptographic keys necessary to enable decryption of such data; and
includes appropriate management and safeguards of such cryptographic keys so as to protect the integrity of the encryption.
Identity theft— The term identity theft means a violation of section 1028(a)(7) of title 18, United States Code.
Personally identifiable information— The term personally identifiable information means any information, or compilation of information, in electronic or digital form that is a means of identification, as defined by section 1028(d)(7) of title 18, United States Code.
Public record source— The term public record source means the Congress, any agency, any State or local government agency, the government of the District of Columbia and governments of the territories or possessions of the United States, and Federal, State or local courts, courts martial and military commissions, that maintain personally identifiable information in records available to the public.
Security breach—
In general— The term security breach means compromise of the security, confidentiality, or integrity of, or the loss of, computerized data that result in, or that there is a reasonable basis to conclude has resulted in—
the unauthorized acquisition of sensitive personally identifiable information; and
access to sensitive personally identifiable information that is for an unauthorized purpose, or in excess of authorization.
Exclusion— The term security breach does not include—
a good faith acquisition of sensitive personally identifiable information by a business entity or agency, or an employee or agent of a business entity or agency, if the sensitive personally identifiable information is not subject to further unauthorized disclosure;
the release of a public record not otherwise subject to confidentiality or nondisclosure requirements or the release of information obtained from a public record, including information obtained from a news report or periodical; or
any lawfully authorized investigative, protective, or intelligence activity of a law enforcement or intelligence agency of the United States, a State, or a political subdivision of a State.
Sensitive personally identifiable information— The term sensitive personally identifiable information means any information or compilation of information, in electronic or digital form that includes the following:
An individual's first and last name or first initial and last name in combination with any two of the following data elements:
Home address or telephone number.
Mother's maiden name.
Month, day, and year of birth.
A non-truncated social security number, driver's license number, passport number, or alien registration number or other government-issued unique identification number.
Unique biometric data such as a fingerprint, voice print, a retina or iris image, or any other unique physical representation.
A unique account identifier, including a financial account number or credit or debit card number, electronic identification number, user name, or routing code.
Any combination of the following data elements:
An individual's first and last name or first initial and last name.
A unique account identifier, including a financial account number or credit or debit card number, electronic identification number, user name, or routing code.
Any security code, access code, or password, or source code that could be used to generate such codes or passwords.
Service provider— The term service provider means a business entity that provides electronic data transmission, routing, intermediate and transient storage, or connections to its system or network, where the business entity providing such services does not select or modify the content of the electronic data, is not the sender or the intended recipient of the data, and the business entity transmits, routes, stores, or provides connections for personal information in a manner that personal information is undifferentiated from other types of data that such business entity transmits, routes, stores, or provides connections. Any such business entity shall be treated as a service provider under this Act only to the extent that it is engaged in the provision of such transmission, routing, intermediate and transient storage or connections.