US Codex
Bill
Notes

Personal Data Protection and Breach Accountability Act of 2014

S. 1995 · 113th Congress · Feb 4, 2014 · Lineage

A BILL

To protect consumers by mitigating the vulnerability of personally identifiable information to theft through a security breach, providing notice and remedies to consumers in the wake of such a breach, holding companies accountable for preventable breaches, facilitating the sharing of post-breach technical information between companies, and enhancing criminal and civil penalties and other protections against the unauthorized collection or use of personally identifiable information.

Section 1 Short title; table of contents

(a)
Short title— This Act may be cited as the “Personal Data Protection and Breach Accountability Act of 2014”.
(b)
Table of contents— The table of contents of this Act is as follows:

Sec. 2 Findings

Congress finds that—
(1)
databases of personally identifiable information are increasingly prime targets of hackers, identity thieves, rogue employees, and other criminals, including organized and sophisticated criminal operations;
(2)
identity theft is a serious threat to the Nation’s economic stability, homeland security, the development of e-commerce, and the privacy rights of people in the United States;
(3)
over 9,300,000 individuals were victims of identity theft in the United States in 2010;
(4)
security breaches are a serious threat to consumer confidence, homeland security, e-commerce, and economic stability;
(5)
it is important for business entities that own, use, or license personally identifiable information to adopt reasonable procedures to ensure the security, privacy, and confidentiality of that personally identifiable information;
(6)
individuals whose personal information has been compromised or who have been victims of identity theft should receive the necessary information and assistance to mitigate their damages and to restore the integrity of their personal information and identities;
(7)
data misuse and use of inaccurate data have the potential to cause serious or irreparable harm to an individual’s livelihood, privacy, and liberty and undermine efficient and effective business and government operations;
(8)
there is a need to ensure that data brokers conduct their operations in a manner that prioritizes fairness, transparency, accuracy, and respect for the privacy of consumers;
(9)
government access to commercial data can potentially improve safety, law enforcement, and national security;
(10)
because government use of commercial data containing personal information potentially affects individual privacy, and law enforcement and national security operations, there is a need for Congress to exercise oversight over government use of commercial data;
(11)
over 22,960,000 cases of data breaches involving personally identifiable information were reported through July of 2011, and in 2009 through 2010, over 230,900,000 cases of personal data breaches were reported;
(12)
facilitating information sharing among business entities and across sectors in the event of a breach can assist in remediating the breach and preventing similar breaches in the future;
(13)
because the Federal Government has limited resources, consumers themselves play a vital and complementary role in facilitating prompt notification and protecting against future breaches of security;
(14)
in addition to the immediate damages caused by security breaches, the lack of basic remedial requirements often forces individuals whose sensitive personally identifiable information is compromised as a result of a security breach to incur the economic costs of litigation to seek remedies, and the economic costs of fees required in many States to freeze compromised accounts; and
(15)
victims of personal data breaches may suffer debilitating emotional and physical effects and become depressed or anxious, especially in cases of repeated or unresolved instances of data breaches.

Sec. 3 Definitions

(a)
In general— In this Act, the following definitions shall apply:
(1)
Affiliate— The term affiliate means persons related by common ownership or by corporate control.
(2)
Agency— The term agency has the meaning given the term in section 551 of title 5, United States Code.
(3)
Business entity— The term business entity means any organization, corporation, trust, partnership, sole proprietorship, unincorporated association, or venture established to make a profit, or nonprofit.
(4)
Credit rating agency— The term credit rating agency has the meaning given the term in section 3(a)(61) of the Securities Exchange Act of 1934 (15 U.S.C. 78c(a)(61)).
(5)
Credit report— The term credit report means a consumer report, as that term is defined in section 603(d) of the Fair Credit Reporting Act (15 U.S.C. 1681a(d)).
(6)
Data broker— The term data broker means a business entity which for monetary fees or dues regularly engages in the practice of collecting, transmitting, or providing access to sensitive personally identifiable information on more than 5,000 individuals who are not the customers or employees of that business entity or affiliate primarily for the purposes of providing such information to nonaffiliated third parties on an interstate basis.
(7)
Designated entity— The term designated entity means the Federal Government entity designated under section 217(a).
(8)
Encryption— The term “encryption”—
(A)
means the protection of data in electronic form, in storage or in transit, using an encryption technology that has been generally accepted by experts in the field of information security that renders such data indecipherable in the absence of associated cryptographic keys necessary to enable decryption of such data; and
(B)
includes appropriate management and safeguards of such cryptographic keys so as to protect the integrity of the encryption.
(9)
Identity theft— The term identity theft means a violation of section 1028(a)(7) of title 18, United States Code.
(10)
Intelligence community— The term intelligence community includes the following:
(A)
The Office of the Director of National Intelligence.
(B)
The Central Intelligence Agency.
(C)
The National Security Agency.
(D)
The Defense Intelligence Agency.
(E)
The National Geospatial-Intelligence Agency.
(F)
The National Reconnaissance Office.
(G)
Other offices within the Department of Defense for the collection of specialized national intelligence through reconnaissance programs.
(H)
The intelligence elements of the Army, the Navy, the Air Force, the Marine Corps, the Federal Bureau of Investigation, and the Department of Energy.
(I)
The Bureau of Intelligence and Research of the Department of State.
(J)
The Office of Intelligence and Analysis of the Department of the Treasury.
(K)
The elements of the Department of Homeland Security concerned with the analysis of intelligence information, including the Office of Intelligence of the Coast Guard.
(L)
Such other elements of any other department or agency as may be designated by the President, or designated jointly by the Director of National Intelligence and the head of the department or agency concerned, as an element of the intelligence community.
(11)
Predispute arbitration agreement— The term predispute arbitration agreement means any agreement to arbitrate a dispute that had not yet arisen at the time of the making of the agreement.
(12)
Public record source— The term public record source means the Congress, any agency, any State or local government agency, the government of the District of Columbia and governments of the territories or possessions of the United States, and Federal, State or local courts, courts martial and military commissions, that maintain personally identifiable information in records available to the public.
(13)
Security breach—
(A)
In general— The term security breach means compromise of the security, confidentiality, or integrity of, or the loss of, computerized data through misrepresentation or actions that result in, or that there is a reasonable basis to conclude has resulted in—
(i)
the unauthorized acquisition of sensitive personally identifiable information; or
(ii)
access to sensitive personally identifiable information that is for an unauthorized purpose, or in excess of authorization.
(B)
Exclusion— The term security breach does not include—
(i)
a good faith acquisition of sensitive personally identifiable information by a business entity or agency, or an employee or agent of a business entity or agency, if the sensitive personally identifiable information is not subject to further unauthorized disclosure;
(ii)
the release of a public record not otherwise subject to confidentiality or nondisclosure requirements or the release of information obtained from a public record; or
(iii)
any lawfully authorized criminal investigation or authorized investigative, protective, or intelligence activities that are carried out by or on behalf of any element of the intelligence community and conducted in accordance with the United States laws, authorities, and regulations governing such intelligence activities.
(14)
Security freeze— The term security freeze means a notice, at the request of the consumer and subject to exceptions in section 215(b), that prohibits the consumer reporting agency from releasing all or any part of the consumer’s credit report or any information derived from it without the express authorization of the consumer.
(15)
Sensitive personally identifiable information— The term sensitive personally identifiable information means any information or compilation of information, in electronic or digital form that includes the following:
(A)
An individual’s first and last name or first initial and last name in combination with any 2 of the following data elements:
(i)
Home address.
(ii)
Telephone number of the individual.
(iii)
Mother’s maiden name.
(iv)
Month, day, and year of birth.
(B)
A non-truncated social security number, driver’s license number, passport number, or alien registration number or other government-issued unique identification number.
(C)
Information about an individual’s geographic location that is in whole or in part generated by or derived from that individual’s use of a wireless communication device or other electronic device, excluding telephone and instrument numbers and network or Internet Protocol addresses.
(D)
Unique biometric data such as a fingerprint, voice print, face print, a retina or iris image, or any other unique physical representation.
(E)
A unique account identifier, including a financial account number or credit or debit card number, electronic identification number, user name, health insurance policy or subscriber identification number, or routing code.
(F)
Not less than 2 of the following data elements:
(i)
An individual’s first and last name or first initial and last name.
(ii)
A unique account identifier, including a financial account number or credit or debit card number, electronic identification number, user name, or routing code.
(iii)
Any security code, access code, or password, or source code that could be used to generate such codes and passwords.
(iv)
Information regarding an individual’s medical history, mental or physical medical condition, or medical treatment or diagnosis by a health care professional.
(G)
Any other combination of data elements that could allow unauthorized access to or acquisition of the information described in subparagraph (A), (B), (C), (D), (E), or (F), including—
(i)
a unique account identifier;
(ii)
an electronic identification number;
(iii)
a user name;
(iv)
a routing code; or
(v)
any associated security code, access code, or password or any associated security questions and answers that could allow unauthorized access to the account.
(16)
Service provider—
(A)
In general— The term service provider means a business entity that—
(i)
provides electronic data transmission, routing, intermediate and transient storage, or connections to the system or network of the business entity;
(ii)
is not the sender or the intended recipient of the data;
(iii)
is not ordinarily expected to select or modify the content of the electronic data; and
(iv)
transmits, routes, stores, or provides connections for personal information in a manner that personal information is undifferentiated from other types of data that such business entity transmits, routes, stores, or provides connections.
(B)
Savings clause— Any such business entity shall be treated as a service provider under this Act only to the extent that the business entity is engaged in the provision of the transmission, routing, intermediate and transient storage or connections described in subparagraph (A).
(b)
Modified definition by rulemaking— The Federal Trade Commission may, by rule promulgated under section 553 of title 5, United States Code, modify the definition of “sensitive personally identifiable information” in a manner consistent with the purposes of this Act and to the extent that such modification will not unreasonably impede interstate commerce.