(a)
Individual notification—
(1)
In general— Each covered entity shall, following the discovery of a breach of security, notify each individual who is a citizen or resident of the United States whose personal information was, or is reasonably believed to have been, acquired or accessed by an unauthorized person, or used for an unauthorized purpose.
(2)
Timeliness of notification—
(A)
In general— Unless subject to a delay authorized under subparagraph (B), a notification required under paragraph (1) shall be made as expeditiously as practicable and without unreasonable delay, but not later than 30 days following the discovery of a breach of security.
(B)
Delay of notification authorized for law enforcement or national security purposes—
(i)
Law enforcement— If a Federal or State law enforcement agency, including an attorney general of a State, determines that the notification required under this section would impede a civil or criminal investigation, such notification shall be delayed upon the written request of the law enforcement agency for 30 days or such lesser period of time which the law enforcement agency determines is reasonably necessary and requests in writing. Such law enforcement agency may, by a subsequent written request, revoke such delay or extend the period of time set forth in the original request made under this paragraph if further delay is necessary.
(ii)
National security— If a Federal national security agency or homeland security agency determines that the notification required under this section would threaten national or homeland security, such notification may be delayed for a period of time which the national security agency or homeland security agency determines is reasonably necessary and requests in writing. A Federal national security agency or homeland security agency may revoke such delay or extend the period of time set forth in the original request made under this paragraph by a subsequent written request if further delay is necessary.
(b)
Coordination of notification with credit reporting agencies— If a covered entity is required to provide notification to more than 5,000 individuals under subsection (a)(1), the covered entity shall also notify the major consumer reporting agencies that compile and maintain files on consumers on a nationwide basis, of the timing and distribution of the notifications. Such notification shall be given to the credit reporting agencies without unreasonable delay and, if such notification will not delay notification to the affected individuals, prior to the distribution of notifications to the affected individuals.
(c)
Method and content of notification—
(1)
General notification— A covered entity required to provide notification to individuals under subsection (a)(1) shall be in compliance with such requirement if the covered entity provides conspicuous and clearly identified notification by one of the following methods (provided the selected method can reasonably be expected to reach the intended individual):
(A)
Written notification to the last known home mailing address of the individual in the records of the covered entity.
(B)
Notification by email or other electronic means, if—
(i)
the covered entity’s primary method of communication with the individual is by email or such other electronic means; or
(ii)
the individual has consented to receive such notification and the notification is provided in a manner that is consistent with the provisions permitting electronic transmission of notifications under section 101 of the Electronic Signatures in Global Commerce Act (
15 U.S.C. 7001).
(2)
Website notification— The covered entity shall also provide conspicuous notification on the Internet website of the covered entity (if such covered entity maintains such a website) for a period of not less than 90 days.
(3)
Media notification— If the number of residents of a State whose personal information was, or is reasonably believed to have been acquired or accessed by an unauthorized person, or used for an unauthorized purpose exceeds 5,000, the covered entity shall also provide notification in print and to broadcast media, including major media in metropolitan and rural areas where the individuals whose personal information was, or is reasonably believed to have been, acquired or accessed by an unauthorized person, or used for an unauthorized purpose, reside.
(4)
Content of notification—
(A)
In general— Regardless of the method by which notification is provided to an individual under paragraphs (1), (2), and (3), such notification shall include—
(i)
a description of the personal information that was, or is reasonably believed to have been, acquired or accessed by an unauthorized person, or used for an unauthorized purpose;
(ii)
a telephone number that the individual may use, at no cost to such individual, to contact the covered entity, or agent of the covered entity, to inquire about the breach of security or the information the covered entity maintained about that individual;
(iii)
notification that the individual is entitled to receive, at no cost to such individual, consumer credit reports on a quarterly basis for a period of 5 years, or credit monitoring or other service that enables consumers to detect the misuse of their personal information for a period of 5 years, and instructions to the individual on requesting such reports or service from the covered entity;
(iv)
the toll-free contact telephone numbers and addresses for the major credit reporting agencies; and
(v)
a toll-free telephone number and Internet website address for the Commission whereby the individual may obtain information regarding identity theft.
(B)
Direct business relationship— Regardless of whether the covered entity or a designated third party provides notification under this subsection, such notification shall identify the covered entity that has a direct business relationship with the individual.
(5)
Regulations for substitute notification— Not later than 1 year after the date of enactment of this Act, the Commission shall, by regulation under
section 553 of title 5, United States
Code—
(A)
establish criteria for determining circumstances under which substitute notification may be provided in lieu of direct notification required by paragraph (1), including criteria for determining if notification under paragraph (1) is not feasible due to excessive costs to the covered entity required to provided such notification relative to the resources of such covered entity; and
(B)
establish the form and content of substitute notification.
(d)
Notification for law enforcement and other purposes— A covered entity shall, as expeditiously as practicable and without unreasonable delay, but not later than 14 days following the discovery of a breach of security, provide notification of the breach to—
(2)
the Federal Bureau of Investigation;
(4)
for common carriers, the Federal Communications Commission;
(5)
the Consumer Financial Protection Bureau; and
(6)
the attorney general of each State in which the personal information of a resident or residents of the State was, or is reasonably believed to have been, acquired or accessed by an unauthorized person, or used for an unauthorized purpose.
(e)
Other obligations following breach—
(1)
In general— A covered entity required to provide notification under subsection (a) shall, upon request of an individual whose personal information was included in the breach of security, provide or arrange for the provision of, to each such individual and at no cost to such individual—
(A)
consumer credit reports from the major credit reporting agencies beginning not later than 60 days following the individual’s request and continuing on a quarterly basis for a period of 5 years thereafter; or
(B)
a credit monitoring or other service that enables consumers to detect the misuse of their personal information, beginning not later than 60 days following the individual’s request and continuing for a period of 5 years.
(2)
Rulemaking— As part of the Commission’s rulemaking described in subsection (c)(5), the Commission shall determine the circumstances under which a covered entity required to provide notification under subsection (a) shall provide or arrange for the provision of free consumer credit reports or credit monitoring or other service to affected individuals.
(f)
Website notification of Federal Trade Commission— If the Commission, upon receiving notification of any breach of security that is reported to the Commission under subsection (d)(1), finds that notification of such a breach of security via the Commission’s Internet website would be in the public interest or for the protection of consumers, the Commission shall place such a notification in a clear and conspicuous location on its Internet website.
(g)
Website notification of State attorneys general— If a State attorney general, upon receiving notification of any breach of security that is reported to the Commission under subsection (d)(5), finds that notification of such a breach of security through the State attorney general’s Internet website would be in the public interest or for the protection of consumers, the State attorney general shall place such a notification in a clear and conspicuous location on its Internet website.
(h)
FTC study on notification in languages in addition to English— Not later than 1 year after the date of enactment of this Act, the Commission shall conduct a study on the practicality and cost effectiveness of requiring the notification required by subsection (c)(1) to be provided in a language in addition to English to individuals known to speak only such other language.
(i)
Education and outreach for small businesses— The Commission shall conduct education and outreach for small business concerns on data security practices and how to prevent hacking and other unauthorized access to, acquisition of, or use of data maintained by such small business concerns.
(j)
Website on data security best practices— The Commission shall establish and maintain an Internet website containing non-binding best practices for businesses regarding data security and how to prevent hacking and other unauthorized access to, acquisition of, or use of data maintained by such businesses.
(k)
General rulemaking authority—
(1)
In general— The Commission may promulgate regulations necessary under
section 553 of title 5, United States Code, to effectively enforce the requirements of this section.
(2)
Limitation— In promulgating rules under this Act, the Commission shall not require the deployment or use of any specific products or technologies, including any specific computer software or hardware.
(l)
Treatment of persons governed by other law— A covered entity who is in compliance with any other Federal law that requires such covered entity to provide notification to individuals following a breach of security, shall be deemed to be in compliance with this section with respect to activities and information covered under such Federal law.