(a)
Individual notification—
(1)
In general— Each covered entity shall, following the discovery of a breach of security, notify each individual who is a citizen or resident of the United States whose personal information was, or is reasonably believed to have been, acquired or accessed by an unauthorized person, or used for an unauthorized purpose.
(2)
Timeliness of notification—
(A)
In general— Unless subject to a delay authorized under subparagraph (B), a notification required under paragraph (1) shall be made as expeditiously as practicable and without unreasonable delay, but not later than 30 days following the discovery of a breach of security.
(B)
Delay of notification authorized for law enforcement or national security purposes—
(i)
Law enforcement— If a Federal or State law enforcement agency, including an attorney general of a State, determines that the notification required under this section would impede a civil or criminal investigation, such notification shall be delayed upon the written request of the law enforcement agency for 30 days or such lesser period of time which the law enforcement agency determines is reasonably necessary and requests in writing. Such a law enforcement agency may, by a subsequent written request, revoke such delay or extend the period of time set forth in the original request made under this clause if further delay is necessary.
(ii)
National security— If a Federal national security agency or homeland security agency determines that the notification required under this section would threaten national or homeland security, such notification may be delayed for a period of time of up to 60 days which the national security agency or homeland security agency determines is reasonably necessary and requests in writing. A Federal national security agency or homeland security agency may revoke such delay or extend the period of time set forth in the original request made under this clause by a subsequent written request if further delay is necessary.
(iii)
Limitation on delay or extension— Any delay or extension of notification permitted under this subparagraph may not exceed a total time period of one year.
(b)
Coordination of notification with consumer reporting agencies— If a covered entity is required to provide notification to more than 5,000 individuals under subsection (a)(1), the covered entity shall also notify the major consumer reporting agencies that compile and maintain files on consumers on a nationwide basis, of the timing and distribution of the notifications, except for a case in which the only information that is the subject of the breach of security is the individual’s first name or initial and last name, address, or phone number, in combination with a credit or debit card number and any required security code. Such notification shall be given to the consumer reporting agencies without unreasonable delay and, if such notification will not delay notification to the affected individuals, prior to the distribution of notifications to the affected individuals.
(c)
Method and content of notification—
(1)
General notification— A covered entity required to provide notification to individuals under subsection (a)(1) shall be in compliance with such requirement if the covered entity provides conspicuous and clearly identified notification by one of the following methods (provided the selected method can reasonably be expected to reach the intended individual):
(A)
Written notification to the last known home mailing address of the individual in the records of the covered entity.
(B)
Notification by email or other electronic means, if—
(i)
the covered entity’s primary method of communication with the individual is by email or such other electronic means; or
(ii)
the individual has consented to receive such notification and the notification is provided in a manner that is consistent with the provisions permitting electronic transmission of notifications under section 101 of the Electronic Signatures in Global and National Commerce Act (
15 U.S.C. 7001).
(2)
Website notification— The covered entity shall also provide conspicuous notification on the Internet website of the covered entity (if such covered entity maintains such a website) for a period of not less than 90 days.
(3)
Media notification— If the number of residents of a State whose personal information was, or is reasonably believed to have been, acquired or accessed by an unauthorized person, or used for an unauthorized purpose, exceeds 5,000, the covered entity shall also provide notification in print and to broadcast media, including major media in metropolitan and rural areas where the individuals whose personal information was, or is reasonably believed to have been, acquired or accessed by an unauthorized person, or used for an unauthorized purpose, reside.
(4)
Content of notification—
(A)
In general— Regardless of the method by which notification is provided to an individual under paragraphs (1), (2), and (3), such notification shall include—
(i)
a description of the personal information that was, or is reasonably believed to have been, acquired or accessed by an unauthorized person, or used for an unauthorized purpose;
(ii)
a general description of the incident and the date or estimated date of the breach of security and the date range during which the personal information was compromised;
(iii)
the acts the covered entity, or the agent of the covered entity, has taken to protect personal information from further breach of security;
(iv)
a telephone number, website, and email address that the individual may use, at no cost to such individual, to contact the covered entity, or agent of the covered entity, to inquire about the breach of security or the information the covered entity maintained about that individual;
(v)
in the case of an individual that is entitled to receive services under subsection (e), notification that the individual is entitled to receive such services;
(vi)
the toll-free contact telephone numbers and addresses for the major consumer reporting agencies; and
(vii)
a toll-free telephone number and Internet website address for the Commission whereby the individual may obtain information regarding identity theft.
(B)
Direct business relationship— The notification required under subsection (a) shall identify the covered entity that has a direct business relationship with the individual, if applicable, as well as the entity that experienced the breach of security.
(5)
Regulations for substitute notification— Not later than 1 year after the date of enactment of this Act, the Commission shall, by regulation under
section 553 of title 5, United States
Code—
(A)
establish criteria for determining circumstances under which substitute notification may be provided in lieu of direct notification required by paragraph (1), including criteria for determining if notification under paragraph (1) is not feasible due to excessive costs to the covered entity required to provide such notification relative to the resources of such covered entity; and
(B)
establish the form and content of substitute notification.
(d)
Notification for law enforcement and other purposes— A covered entity shall, as expeditiously as practicable and without unreasonable delay, but not later than 5 days following the discovery of a breach of security, provide notification of the breach to—
(2)
the Federal Bureau of Investigation;
(4)
for common carriers, the Federal Communications Commission;
(5)
for entities that provide a consumer financial product or service (as defined in section 1002 of the Consumer Financial Protection Act of 2010 (
12 U.S.C. 5481)), the Bureau of Consumer Financial Protection; and
(6)
the attorney general of each State in which the personal information of a resident or residents of the State was, or is reasonably believed to have been, acquired or accessed by an unauthorized person, or used for an unauthorized purpose.
(e)
Other obligations following breach—
(1)
In general— A covered entity required to provide notification under subsection (a) shall, upon request of an individual whose personal information was included in the breach of security, provide or arrange for the provision of, to each such individual and at no cost to such individual—
(A)
at the option of such individual, either—
(i)
consumer credit reports from all of the major consumer reporting agencies beginning not later than 60 days following the individual’s request and continuing on a quarterly basis for a period of not less than 10 years thereafter; or
(ii)
a credit monitoring or other service that—
(I)
enables consumers to detect the misuse of their personal information, beginning not later than 60 days following the individual’s request and continuing for a period of not less than 10 years thereafter; and
(II)
includes monitoring of the individual’s credit file at all of the major consumer reporting agencies; and
(B)
a service that enables consumers to control access to their personal information and credit reports, beginning not later than 60 days following the individual’s request and continuing for a period of not less than 10 years thereafter.
(2)
Limitation— This subsection shall not apply if the only personal information which has been the subject of the breach of security is the individual’s first name or initial and last name, address, or phone number, in combination with a credit or debit card number and any required security code.
(f)
Exemption—
(1)
General exemption— A covered entity shall be exempt from the requirements under this section if the data containing personal information that was, or is reasonably believed to have been, acquired or accessed by an unauthorized person, or used for an unauthorized purpose, is unusable, unreadable, or indecipherable because of security technologies or methodologies generally accepted by experts in the field of information security at the time the breach of security occurred. This exemption does not apply with regard to the use of encryption technology generally accepted by experts in the field of information security at the time the breach of security occurred if any cryptographic keys necessary to enable decryption of such data are also accessed or acquired without authorization.
(2)
FTC guidance— Not later than 1 year after the date of enactment of this Act, the Commission shall issue guidance regarding the application of the exemption in paragraph (1).
(g)
Website notification of federal trade commission— If the Commission, upon receiving notification of any breach of security that is reported to the Commission under subsection (d)(1), finds that notification of such a breach of security via the Commission’s Internet website would be in the public interest, the Commission shall place such a notification in a clear and conspicuous location on its Internet website.
(h)
Website notification of state attorneys general— If a State attorney general, upon receiving notification of any breach of security that is reported to such State attorney general under subsection (d)(6), finds that notification of such breach of security via the State attorney general’s Internet website would be in the public interest or for the protection of consumers, the State attorney general may place such a notification in a clear and conspicuous location on its Internet website.
(i)
FTC study on notification in languages in addition to English— Not later than 1 year after the date of enactment of this Act, the Commission shall conduct a study on the practicality and cost effectiveness of requiring the notification required by subsection (c)(1) to be provided in a language in addition to English to individuals known to speak only such other language.
(j)
Education and outreach for small businesses— The Commission shall conduct education and outreach for small business concerns on data security practices and how to prevent hacking and other unauthorized access to, acquisition of, or use of data maintained by such small business concerns.
(k)
Website on data security best practices— The Commission shall maintain an Internet website containing nonbinding best practices for businesses regarding data security and how to prevent hacking and other unauthorized access to, acquisition of, or use of data maintained by such businesses.
(l)
General rulemaking authority—
(1)
In general— The Commission may promulgate regulations necessary under
section 553 of title 5, United States Code, to effectively enforce the requirements of this section.
(2)
Limitation— In promulgating rules under this Act, the Commission shall not require the deployment or use of any specific products or technologies, including any specific computer software or hardware.
(m)
Treatment of persons governed by other law— A covered entity who is in compliance with any other Federal law that requires such covered entity to provide notification to individuals following a breach of security in at least the same or substantially similar circumstances and in at the least same or substantially similar manner as required to be provided under this Act, taken as a whole and as determined by the Commission in the rulemaking required under this section, shall be deemed to be in compliance with this section with respect to activities and information covered under such Federal law.