US Codex
Bill
Notes

Title I — Enhancing punishment for identity theft and other violations of data privacy and security

S. 1995 · 113th Congress · Feb 4, 2014 · Lineage

I Enhancing punishment for identity theft and other violations of data privacy and security

Sec. 101 Concealment of security breaches involving sensitive personally identifiable information

(a)
In general— Chapter 47 of title 18, United States Code, is amended by adding at the end the following:

“1041. Concealment of security breaches involving sensitive personally identifiable information

“(a) Whoever, having knowledge of a security breach and of the fact that notice of such security breach is required under title II of the Personal Data Protection and Breach Accountability Act of 2014, intentionally or willfully conceals the fact of such security breach and which breach, shall, in the event that such security breach results in economic harm or substantial emotional distress to 1 or more persons, shall be fined under this title or imprisoned not more than 5 years, or both.

“(b) For purposes of subsection (a), the term person has the meaning given the term in section 1030(e)(12) of title 18, United States Code.

“(c) Any person seeking an exemption under section 212(b) of the Personal Data Protection and Breach Accountability Act of 2014 shall be immune from prosecution under this section if the United States Secret Service does not indicate, in writing, that such notice be given under section 212(b)(1)(B) of the Personal Data Protection and Breach Accountability Act of 2014.”

(b)
Conforming and technical amendments— The table of sections for chapter 47 of title 18, United States Code, is amended by adding at the end the following:
(c)
Enforcement authority—
(1)
In general— The United States Secret Service and the Federal Bureau of Investigation shall have the authority to investigate offenses under section 1041 of title 18, United States Code, as added by subsection (a).
(2)
Nonexclusivity— The authority granted in paragraph (1) shall not be exclusive of any existing authority held by any other Federal agency.

Sec. 102 Unauthorized manipulation of Internet traffic on a user’s computer

(a)
Definition— In this section, the term protected computer has the meaning given the term in section 1030(e)(2) of title 18, United States Code.
(b)
Prohibition—
(1)
In general— Unless a service provider provides a clear and conspicuous disclosure of data collected in the process of intercepting a web search or query entered by an authorized user of a protected computer, and obtains the consent of an authorized user of the protected computer prior to any such action, it shall be unlawful for a service provider to knowingly or intentionally—
(A)
bypass the display of search engine results and redirect web searches or queries entered by an authorized user of a protected computer directly to a commercial website, counterfeit web page, or targeted advertisement and derive an economic benefit from such activity; or
(B)
monitor, manipulate, aggregate, and market the data collected in the process of intercepting a web search or query entered by an authorized user of a protected computer and derive an economic benefit from such activity.
(2)
Consent— A service provider may not require consent to perform the collection of data described in paragraph (1) as a condition of providing service to an authorized user of the protected computer.
(c)
Limitations on liability— The restrictions imposed under this section do not apply to any monitoring of, or interaction with, a subscriber's Internet or other network connection or service, or a protected computer, by or at the direction of a telecommunications carrier, cable operator, computer hardware or software provider, financial institution or provider of information services or interactive computer service for—
(1)
network or computer security purposes;
(2)
diagnostics;
(3)
technical support;
(4)
repair;
(5)
network management;
(6)
authorized updates of software or system firmware;
(7)
authorized remote system management;
(8)
authorized provision of protection for users of the computer from objectionable content;
(9)
authorized scanning for computer software used in violation of this section for removal by an authorized user; or
(10)
detection or prevention of fraud.
(d)
Enforcement by the Attorney General—
(1)
Liability and penalty for violations— Any person who engages in an activity in violation of this section shall be fined not more than $500,000.
(2)
Enhanced liability and penalties for pattern or practice of violations—
(A)
In general— Any person who engages in a pattern or practice of activity that violates the provisions of this section shall be fined not more than $1,000,000.
(B)
Treatment of single action or conduct— For purposes of subparagraph (A), any single action or conduct that violates this section with respect to multiple protected computers shall be construed as a single violation.
(3)
Considerations— In determining the amount of any penalty under paragraph (1) or (2), the court shall take into account—
(A)
the degree of culpability of the defendant;
(B)
any history of prior such conduct;
(C)
the ability of the defendant to pay any fine imposed;
(D)
the effect on the ability of the defendant to continue to do business; and
(E)
such other matters as justice may require.