Federal Agency Data Breach Notification Act of 2014
A BILL
To strengthen privacy and data security, and for other purposes.
Sec. 2 Privacy breach requirements
“3550. Privacy breach requirements
“(a) Policies and Procedures—The Director of the Office of Management and Budget shall establish and oversee policies and procedures for agencies to follow in the event of a breach of information security involving the disclosure of personally identifiable information, including requirements for—
“(1) not later than 72 hours after the agency discovers such a breach, or discovers evidence that reasonably indicates such a breach has occurred, notice to the individuals whose personally identifiable information could be compromised as a result of such breach;
“(2) timely reporting to a Federal cybersecurity center, as designated by the Director of the Office of Management and Budget; and
“(3) any additional actions that the Director finds necessary and appropriate, including data breach analysis, fraud resolution services, identity theft insurance, and credit protection or monitoring services.
“(b) Required Agency Action—The head of each agency shall ensure that actions taken in response to a breach of information security involving the disclosure of personally identifiable information under the authority or control of the agency comply with policies and procedures established by the Director of the Office of Management and Budget under subsection (a).
“(c) Report—Not later than March 1 of each year, the Director of the Office of Management and Budget shall report to Congress on agency compliance with the policies and procedures established under subsection (a).
“(d) Federal cybersecurity center defined—The term Federal cybersecurity center means any of the following:
“(1) The Department of Defense Cyber Crime Center.
“(2) The Intelligence Community Incident Response Center.
“(3) The United States Cyber Command Joint Operations Center.
“(4) The National Cyber Investigative Joint Task Force.
“(5) Central Security Service Threat Operations Center of the National Security Agency.
“(6) The United States Computer Emergency Readiness Team.
“(7) Any successor to a center, team, or task force described in paragraphs (1) through (6).
“(8) Any center that the Director of the Office of Management and Budget determines is appropriate to carry out the requirements of this section.”
“(iii) using information in an identifiable form purchased, or subscribed to for a fee, from a commercial data source.”
“(3) designate a Federal Chief Privacy Officer within the Office of Management and Budget who is a noncareer appointee in a Senior Executive Service position and who is a trained and experienced privacy professional to carry out the responsibilities of the Director with regard to privacy.”