(a)
Individual notification— Not later than 1 year after the date of enactment of this Act, the Commission shall promulgate regulations under section 553 of title 5, United States Code, that require the following:
(1)
In general— Each covered entity to, following the discovery of a breach of security, notify each individual who is a citizen or resident of the United States whose personal information was, or is reasonably believed to have been, acquired or accessed by an unauthorized person, or used for an unauthorized purpose.
(2)
Timeliness of notification—
(A)
In general— Unless subject to a delay authorized under subparagraph (B), a notification required under paragraph (1) shall be made as expeditiously as practicable and without unreasonable delay, but not later than 30 days following the discovery of a breach of security.
(B)
Delay of notification authorized for law enforcement or national security purposes—
(i)
Law enforcement— If a Federal or State law enforcement agency, including an attorney general of a State, determines that the notification required under this section would impede a civil or criminal investigation, such notification shall be delayed upon the written request of the law enforcement agency for 30 days or such lesser period of time which the law enforcement agency determines is reasonably necessary and requests in writing. Such law enforcement agency may, by a subsequent written request, revoke such delay or extend the period of time set forth in the original request made under this clause if further delay is necessary.
(ii)
National security— If a Federal national security agency or homeland security agency determines that the notification required under this section would threaten national or homeland security, such notification may be delayed for a period of time which the national security agency or homeland security agency determines is reasonably necessary and requests in writing. A Federal national security agency or homeland security agency may revoke such delay or extend the period of time set forth in the original request made under this clause by a subsequent written request if further delay is necessary.
(3)
Coordination of notification with credit reporting agencies— If a covered entity is required to provide notification to more than 5,000 individuals under paragraph (1), the covered entity shall also notify the major consumer reporting agencies that compile and maintain files on consumers on a nationwide basis, of the timing and distribution of the notifications. Such notification shall be given to the credit reporting agencies without unreasonable delay and, if such notification will not delay notification to the affected individuals, prior to the distribution of notifications to the affected individuals.
(4)
Method and content of notification—
(A)
General notification— A covered entity required to provide notification to individuals under paragraph (1) shall be in compliance with such requirement if the covered entity provides conspicuous and clearly identified notification by one of the following methods (provided the selected method can reasonably be expected to reach the intended individual):
(i)
Written notification to the last known home mailing address of the individual in the records of the covered entity.
(ii)
Notification by email or other electronic means, if—
(I)
the covered entity’s primary method of communication with the individual is by email or such other electronic means; or
(II)
the individual has consented to receive such notification and the notification is provided in a manner that is consistent with the provisions permitting electronic transmission of notifications under section 101 of the Electronic Signatures in Global Commerce Act (
15 U.S.C. 7001).
(B)
Website notification— The covered entity shall also provide conspicuous notification on the internet website of the covered entity (if such covered entity maintains such a website) for a period of not less than 90 days.
(C)
Media notification— If the number of residents of a State whose personal information was, or is reasonably believed to have been acquired or accessed by an unauthorized person, or used for an unauthorized purpose exceeds 5,000, the covered entity shall also provide notification in print and to broadcast media, including major media in metropolitan and rural areas where the individuals whose personal information was, or is reasonably believed to have been, acquired or accessed by an unauthorized person, or used for an unauthorized purpose, reside.
(D)
Content of notification—
(i)
In general— Any notification provided under subparagraph (A), (B), or (C) shall include—
(I)
a description of the personal information that was, or is reasonably believed to have been, acquired or accessed by an unauthorized person, or used for an unauthorized purpose;
(II)
a telephone number that the individual may use, at no cost to such individual, to contact the covered entity, or agent of the covered entity, to inquire about the breach of security or the information the covered entity maintained about that individual;
(III)
notification that the individual is entitled to receive, at no cost to such individual, consumer credit reports on a quarterly basis for a period of 10 years, or credit monitoring or other service that enables consumers to detect the misuse of their personal information for a period of 10 years, and instructions to the individual on requesting such reports or service from the covered entity;
(IV)
the toll-free contact telephone numbers and addresses for the major credit reporting agencies; and
(V)
a toll-free telephone number and internet website address for the Commission whereby the individual may obtain information regarding identity theft.
(ii)
Direct business relationship— Any notification provided under this subsection shall identify the covered entity that has a direct business relationship with the individual.
(E)
Substitute notification— Criteria for determining circumstances under which substitute notification may be provided in lieu of direct notification required by subparagraph (A), including criteria for determining if notification under subparagraph (A) is not feasible due to excessive costs to the covered entity required to provide such notification relative to the resources of such covered entity and the form and content of substitute notification.
(5)
Notification for law enforcement and other purposes— A covered entity to, as expeditiously as practicable and without unreasonable delay, but not later than 7 days following the discovery of a breach of security, provide notification of the breach to—
(B)
the Federal Bureau of Investigation;
(D)
for common carriers, the Federal Communications Commission;
(E)
for entities that provide a consumer financial product or service (as defined in section 1002 of the Consumer Financial Protection Act of 2010 (
12 U.S.C. 5481)), the Consumer Financial Protection Bureau; and
(F)
the attorney general of each State in which the personal information of a resident or residents of the State was, or is reasonably believed to have been, acquired or accessed by an unauthorized person, or used for an unauthorized purpose.
(6)
Other obligations following breach—
(A)
In general— A covered entity required to provide notification under subsection (a) to, upon request of an individual whose personal information was included in the breach of security, provide or arrange for the provision of, to each such individual and at no cost to such individual—
(i)
consumer credit reports from the major credit reporting agencies beginning not later than 60 days following the individual’s request and continuing on a quarterly basis for a period of 10 years thereafter; or
(ii)
a credit monitoring or other service that enables consumers to detect the misuse of their personal information, beginning not later than 60 days following the individual’s request and continuing for a period of 10 years.
(B)
Rulemaking— The circumstances under which a covered entity required to provide notification under paragraph (1) shall provide or arrange for the provision of free consumer credit reports or credit monitoring or other service to affected individuals.
(b)
Website notification—
(1)
Federal Trade Commission— If the Commission, upon receiving notification of any breach of security that is reported to the Commission under subsection (a)(5)(A), finds that notification of such a breach of security through the website of the Commission would be in the public interest or for the protection of consumers, the Commission shall place such a notification in a clear and conspicuous location on the website.
(2)
Other Federal agency— If another Federal agency (such as the Federal Communications Commission, the Consumer Financial Protection Bureau, or the Department of Justice) receives notice of a breach of security from a covered entity and finds that notification of such a breach of security through the website of the Commission would be in the public interest or for the protection of consumers, that Federal agency shall place such a notification in a clear and conspicuous location on the website of that agency.
(c)
Website notification of State attorneys general— If a State attorney general, upon receiving notification of any breach of security that is reported to the Commission under subsection (d)(5), finds that notification of such a breach of security through the State attorney general’s internet website would be in the public interest or for the protection of consumers, the State attorney general shall place such a notification in a clear and conspicuous location on its internet website.
(d)
FTC study on notification in languages in addition to English— Not later than 1 year after the date of enactment of this Act, the Commission shall conduct a study on the practicality and cost effectiveness of requiring the notification required by subsection (c)(1) to be provided in a language in addition to English to individuals known to speak only such other language.
(e)
Education and outreach for small businesses— The Commission shall conduct education and outreach for small business concerns on data security practices and how to prevent hacking and other unauthorized access to, acquisition of, or use of data maintained by such small business concerns.
(f)
Website on data security best practices— The Commission shall establish and maintain an internet website containing non-binding best practices for businesses regarding data security and how to prevent hacking and other unauthorized access to, acquisition of, or use of data maintained by such businesses.
(g)
General rulemaking authority—
(1)
In general— The Commission may promulgate regulations necessary under section 553 of title 5, United States Code, to effectively enforce the requirements of this section.
(2)
Limitation— In promulgating rules under this Act, the Commission shall not require the deployment or use of any specific product or technology, including any specific computer software or hardware.
(h)
Treatment of persons governed by other law— A covered entity who is in compliance with any other Federal law that requires such covered entity to provide notification to individuals following a breach of security, shall be deemed to be in compliance with this section with respect to activities and information covered under such Federal law.