Regulations— Not later than 1 year after the date of the enactment of this Act, the Federal Trade Commission shall promulgate regulations under
section 553 of title 5, United States Code, to require, except as provided in subsection (b), any operator that provides services to the public involving the collection, storage, processing, sale, sharing with third parties, or other use of sensitive personal information from United States persons or persons located in the United States when the data is collected, to meet the following requirements:
(1)
Affirmative, express, and opt in consent— Provide users with notice through a privacy and data use policy of a specific request to use their data and require that users provide affirmative, express, and opt in consent to any functionality that involves the collection, storage, processing, sale, sharing, or other use of sensitive personal information, including sharing personal data with third parties.
(2)
Privacy and data use policy— Provide users with an up-to-date, transparent privacy, security, and data use policy that meets general requirements, including that such policy, presented to users in the context where it applies—
(A)
is concise and intelligible;
(B)
is clear and prominent in appearance;
(C)
uses clear and plain language;
(D)
uses visualizations where appropriate to make complex information understandable by the ordinary user; and
(E)
is provided free of charge.
(3)
Additional requirements for privacy and data use policy— The privacy, security, and data use policy required under paragraph (2) shall include the following:
(A)
Identity and contact information of the entity collecting the sensitive personal information.
(B)
The purpose or use for collecting, storing, processing, selling, sharing, or otherwise using the personal information, including how the sensitive personal information is shared with third parties.
(C)
Third parties with whom the sensitive personal information will be shared and for what purposes.
(D)
The storage period for how long the personal information will be retained by the operator and any third party, as applicable.
(E)
How consent to collecting, storing, processing, selling, sharing, or otherwise using the sensitive personal information, including sharing with third parties, may be withdrawn.
(F)
How a user can view the sensitive personal information that they have provided to an operator and whether it can be exported to other web-based platforms.
(G)
What kind of sensitive personal information is collected.
(H)
Whether the sensitive personal information will be used to create profiles about users.
(I)
How sensitive personal information is protected from unauthorized access or acquisition.
(4)
Opt out consent— For any collection, storage, processing, selling, sharing, or other use of non-sensitive personal information, including sharing with third parties, Operators shall provide users with the ability to opt out at any time.
(5)
Privacy audits—
(A)
In general— Annually, Operators collecting, storing, processing, selling, sharing, or otherwise using sensitive personal information shall obtain a privacy audit from an objective, independent third-party professional with substantial experience in the field of privacy and data protection, who uses procedures and standards generally accepted in such field.
(B)
Audit requirements— Each such audit shall—
(i)
set forth the privacy, security, and data use controls that the operator has implemented and maintained during the reporting period;
(ii)
describe whether such controls are appropriate to the size and complexity of the operator, the nature and scope of the activities of the operator, and the nature of the sensitive personal information or behavioral data collected by the operator;
(iii)
certify whether the privacy and security controls operate with sufficient effectiveness to provide reasonable assurance to protect the privacy and security of sensitive personal information or behavioral data and that the controls have so operated throughout the reporting period;
(iv)
be prepared and completed within 60 days after the end of the reporting period to which the audit applies; and
(v)
be provided to the Federal Trade Commission or to the attorney general of a State, or other authorized State officer, within 10 days of notification by the Commission or the attorney general of a State, or other authorized State officer where such person has presented to the Operator allegations that a violation of this Act or any regulation issued under this Act has been committed by the Operator.
(C)
Small business exemption— Notwithstanding other authorities of the FTC, the audit requirements set forth above shall not apply to Operators with 500 or fewer employees.
(D)
Non-sensitive personal information exemption— The audit requirements set forth above shall not apply to Operators who do not collect, store, process, sell, share, or otherwise use sensitive personal information.