Title III — Access to and use of commercial data
III Access to and use of commercial data
Sec. 302 Requirement to audit information security practices of contractors and third-party business entities
“(9) procedures for evaluating and auditing the information security practices of contractors or third-party business entities supporting the information systems or operations of the agency involving sensitive personally identifiable information (as that term is defined in section 3 of the Personal Data Protection and Breach Accountability Act of 2014) and ensuring remedial action to address any significant deficiencies.”
Sec. 303 Privacy impact assessment of government use of commercial information services containing sensitive personally identifiable information
“(iii) purchasing or subscribing for a fee to sensitive personally identifiable information from a data broker (as such terms are defined in section 3 of the Personal Data Protection and Breach Accountability Act of 2014).”
Sec. 304 FBI report on reported breaches and compliance
Sec. 305 Department of Justice report on enforcement actions
“(c) Not later than 1 year after the date of enactment of the Personal Data Protection and Breach Accountability Act of 2014, and every fiscal year thereafter, the Attorney General shall submit to Congress a report on Federal enforcement actions, State attorneys general enforcement actions, and private enforcement actions, undertaken pursuant to the Personal Data Protection and Breach Accountability Act of 2014 that shall include a description of the best practices for enforcement of such Act as well as recommendations, if any, for modifying or amending this Act to increase the effectiveness of such enforcement actions.”