US Codex
Bill
Notes

Title III — Access to and use of commercial data

S. 1995 · 113th Congress · Feb 4, 2014 · Lineage

III Access to and use of commercial data

Sec. 301 General services administration review of contracts

(a)
In general— In considering contract awards totaling more than $500,000 and entered into after the date of enactment of this Act with data brokers, the Administrator of the General Services Administration shall evaluate—
(1)
the data privacy and security program of a data broker to ensure the privacy and security of data containing sensitive personally identifiable information, including whether such program adequately addresses privacy and security threats created by malicious software or code, or the use of peer-to-peer file sharing software;
(2)
the compliance of a data broker with such program;
(3)
the extent to which the databases and systems containing sensitive personally identifiable information of a data broker have been compromised by security breaches; and
(4)
the response by a data broker to such breaches, including the efforts by such data broker to mitigate the impact of such security breaches.
(b)
Compliance safe harbor— The data privacy and security program of a data broker shall be deemed sufficient for the purposes of subsection (a), if the data broker complies with or provides protection equal to industry standards, as identified by the Federal Trade Commission, that are applicable to the type of sensitive personally identifiable information involved in the ordinary course of business of such data broker.
(c)
Penalties— In awarding contracts with data brokers for products or services related to access, use, compilation, distribution, processing, analyzing, or evaluating sensitive personally identifiable information, the Administrator of the General Services Administration shall—
(1)
include monetary or other penalties—
(A)
for failure to comply with subtitles A and B of title II; or
(B)
if a contractor knows or has reason to know that the sensitive personally identifiable information being provided is inaccurate, and provides such inaccurate information; and
(2)
require a data broker that engages service providers not subject to subtitle A of title II for responsibilities related to sensitive personally identifiable information to—
(A)
exercise appropriate due diligence in selecting those service providers for responsibilities related to sensitive personally identifiable information;
(B)
take reasonable steps to select and retain service providers that are capable of maintaining appropriate safeguards for the security, privacy, and integrity of the sensitive personally identifiable information at issue; and
(C)
require such service providers, by contract, to implement and maintain appropriate measures designed to meet the objectives and requirements in title II.
(d)
Limitation— The penalties under subsection (c) shall not apply to a data broker providing information that is accurately and completely recorded from a public record source or licensor.

Sec. 302 Requirement to audit information security practices of contractors and third-party business entities

Section 3544(b) of title 44, United States Code, is amended—
(1)
in paragraph (7)(C)(iii), by striking “and” after the semicolon;
(2)
in paragraph (8), by striking the period and inserting “; and”; and
(3)
by adding at the end the following:

“(9) procedures for evaluating and auditing the information security practices of contractors or third-party business entities supporting the information systems or operations of the agency involving sensitive personally identifiable information (as that term is defined in section 3 of the Personal Data Protection and Breach Accountability Act of 2014) and ensuring remedial action to address any significant deficiencies.”

Sec. 303 Privacy impact assessment of government use of commercial information services containing sensitive personally identifiable information

(a)
In general— Section 208(b)(1) of the E-Government Act of 2002 (44 U.S.C. 3501 note) is amended in subparagraph (A)—
(1)
in clause (i), by striking “or”;
(2)
in clause (ii)(II), by striking the period and inserting “; or”; and
(3)
by adding at the end the following:

“(iii) purchasing or subscribing for a fee to sensitive personally identifiable information from a data broker (as such terms are defined in section 3 of the Personal Data Protection and Breach Accountability Act of 2014).”

(b)
Limitation— Notwithstanding any other provision of law, beginning 1 year after the date of enactment of this Act, no Federal agency may enter into a contract with a data broker to access for a fee any database consisting primarily of sensitive personally identifiable information concerning United States persons (other than news reporting or telephone directories) unless the head of the agency—
(1)
completes a privacy impact assessment under section 208 of the E-Government Act of 2002 (44 U.S.C. 3501 note), which shall subject to the provision in that Act pertaining to sensitive information, include a description of—
(A)
such database;
(B)
the name of the data broker from whom it is obtained; and
(C)
the amount of the contract for use;
(2)
adopts regulations that specify—
(A)
the personnel permitted to access, analyze, or otherwise use such databases;
(B)
standards governing the access, analysis, or use of such databases;
(C)
any standards used to ensure that the sensitive personally identifiable information accessed, analyzed, or used is the minimum necessary to accomplish the intended legitimate purpose of the Federal agency;
(D)
standards limiting the retention and redisclosure of sensitive personally identifiable information obtained from such databases;
(E)
procedures ensuring that such data meet standards of accuracy, relevance, completeness, and timeliness;
(F)
the auditing and security measures to protect against unauthorized access, analysis, use, or modification of data in such databases;
(G)
applicable mechanisms by which individuals may secure timely redress for any adverse consequences wrongly incurred due to the access, analysis, or use of such databases;
(H)
mechanisms, if any, for the enforcement and independent oversight of existing or planned procedures, policies, or guidelines; and
(I)
an outline of enforcement mechanisms for accountability to protect individuals and the public against unlawful or illegitimate access or use of databases; and
(3)
incorporates into the contract or other agreement totaling more than $500,000, provisions—
(A)
providing for penalties—
(i)
for failure to comply with title II of this Act; or
(ii)
if the entity knows or has reason to know that the sensitive personally identifiable information being provided to the Federal department or agency is inaccurate, and provides such inaccurate information; and
(B)
requiring a data broker that engages service providers not subject to subtitle A of title II of this Act for responsibilities related to sensitive personally identifiable information to—
(i)
exercise appropriate due diligence in selecting those service providers for responsibilities related to sensitive personally identifiable information;
(ii)
take reasonable steps to select and retain service providers that are capable of maintaining appropriate safeguards for the security, privacy, and integrity of the sensitive personally identifiable information at issue; and
(iii)
require such service providers, by contract, to implement and maintain appropriate measures designed to meet the objectives and requirements in title II of this Act.
(c)
Limitation on penalties— The penalties under subsection (b)(3)(A) shall not apply to a data broker providing information that is accurately and completely recorded from a public record source.
(d)
Study of government use—
(1)
Scope of study— Not later than 180 days after the date of enactment of this Act, the Comptroller General of the United States shall conduct a study and audit and prepare a report on Federal agency actions to address the recommendations in the Government Accountability Office's April 2006 report on agency adherence to key privacy principles in using data brokers or commercial databases containing sensitive personally identifiable information.
(2)
Report— A copy of the report required under paragraph (1) shall be submitted to Congress.

Sec. 304 FBI report on reported breaches and compliance

(a)
In general— Not later than 1 year after the date of enactment of this Act, and each year thereafter, the Federal Bureau of Investigation, in coordination with the Secret Service, shall submit to the Committee on the Judiciary of the Senate and the Committee on the Judiciary of the House of Representatives a report regarding any reported breaches at agencies or business entities during the preceding year.
(b)
Report content— Such reporting shall include—
(1)
the total instances of breaches of security in the previous year;
(2)
the percentage of breaches described in subsection (a) that occurred at an agency or business entity that did not comply with the personal data privacy and security program under section 202; and
(3)
recommendations, if any, for modifying or amending this Act to increase its effectiveness.

Sec. 305 Department of Justice report on enforcement actions

Section 529 of title 28, United States Code, is amended by adding at the end the following:

“(c) Not later than 1 year after the date of enactment of the Personal Data Protection and Breach Accountability Act of 2014, and every fiscal year thereafter, the Attorney General shall submit to Congress a report on Federal enforcement actions, State attorneys general enforcement actions, and private enforcement actions, undertaken pursuant to the Personal Data Protection and Breach Accountability Act of 2014 that shall include a description of the best practices for enforcement of such Act as well as recommendations, if any, for modifying or amending this Act to increase the effectiveness of such enforcement actions.”

Sec. 306 Report on notification effectiveness

(a)
In general— Not later than 1 year after the date of enactment of this Act, and each year thereafter, the designated entity, in coordination with the Attorney General and the Federal Trade Commission, shall submit to the Committee on the Judiciary of the Senate and the Committee on the Judiciary of the House of Representatives a report regarding the effectiveness of post-breach notification practices by agencies and business entities.
(b)
Report content— The report required under subsection (a) shall include—
(1)
in each instance of a breach of security, the amount of time between the instance of the breach and the discovery of the breach by the affected business entity;
(2)
in each instance of a breach of security, the amount of time between the discovery of the breach by the affected business entity and the notification to the Federal Bureau of Investigation and the United States Secret Service; and
(3)
in each instance of a breach of security, the amount of time between the discovery of the breach by the affected business entity and the notification to individuals whose sensitive personally identifiable information was compromised.