US Codex
Bill
Notes

Online Privacy Act of 2019

H.R. 4978 · 116th Congress · Nov 5, 2019 · Lineage

A BILL

To provide for individual rights relating to privacy of personal information, to establish privacy and security requirements for covered entities relating to personal information, and to establish an agency to be known as the United States Digital Privacy Agency to enforce such rights and requirements, and for other purposes.

1. Short title; table of contents

(a)
Short title— This Act may be cited as the “Online Privacy Act of 2019”.
(b)
Table of contents— The table of contents for this Act is as follows:

2. Definitions

In this Act:
(1)
Agency— The term “Agency” means the United States Digital Privacy Agency established by section 301.
(2)
Behavioral personalization—
(A)
In general— The term “behavioral personalization” means the processing of an individual’s personal information, using an algorithm, model, or other means built using that individual’s personal information collected over a period of time, or an aggregate of the personal information of one or more similarly situated individuals and designed to—
(i)
alter, influence, guide, or predict an individual’s behavior;
(ii)
tailor or personalize a product or service; or
(iii)
filter, sort, limit, promote, display or otherwise differentiate between specific content or categories of content that would otherwise be accessible to the individual.
(B)
Exclusions— The term “behavioral personalization” does not include the use of historical personal information to merely prevent the display of or provide additional information about previously accessed content.
(3)
Collect— The term “collect” includes, with respect to personal information or contents of communication, obtaining such information in any manner, except when solely transmitting, routing, providing intermediate storage for, or providing connections for personal information through a system or network.
(4)
Contents— The term “contents”, when used with respect to communication, has the meaning given such term in section 2510 of title 18, United States Code.
(5)
Covered entity—
(A)
In general— The term “covered entity” means a person who—
(i)
intentionally collects, processes, or maintains personal information; and
(ii)
sends or receives such personal information over the internet or a similar communications network.
(B)
Exclusion— The term “covered entity” does not include a natural person, except to the extent such person is engaged in a commercial activity that is more than de minimis.
(6)
Data breach— The term “data breach” means unauthorized access to or acquisition of personal information or contents of communications maintained by such covered entity.
(7)
Data sharing abuse— The term “data sharing abuse” means processing, by a third party, of personal information or contents of communications disclosed by a covered entity to the third party, for any purpose other than—
(A)
a purpose specified by the covered entity to the third party at the time of disclosure; or
(B)
a purpose to which the individual to whom the information relates has consented.
(8)
De-Identified—
(A)
In general— The term “de-identified” means information that cannot reasonably identify, relate to, describe, reference, be capable of being associated with, or be linked, directly or indirectly, to a particular individual or device, provided that a business that uses de-identified information—
(i)
has de-identified the personal information using best practices for the types of data the information contains;
(ii)
has implemented technical safeguards that prohibit re-identification of the individual with whom the information was linked;
(iii)
has implemented business processes that specifically prohibit re-identification of the information;
(iv)
has implemented business processes to prevent inadvertent release of de-identified information; and
(v)
makes no attempt to re-identify the information.
(B)
The Director may determine that a methodology of de-identifying personal information is insufficient for the purposes of this definition.
(9)
Director— The term “Director” means the Director of the Agency.
(10)
Disclose— The term “disclose” means, with respect to personal information or contents of communication, to sell, release, transfer, share, disseminate, make available, or otherwise cause to be communicated such information to a third party.
(11)
Individual— The term “individual” means a natural person residing in the United States.
(12)
Maintain— The term “maintain” means, with respect to personal information or contents of communication, to store, secure, or otherwise cause the retaining of such information, or taking actions necessary for such purposes.
(13)
Personal information—
(A)
In general— The term “personal information” means any information maintained by a covered entity that is linked or reasonably linkable to a specific individual or a specific device, including de-identified personal information and the means to behavioral personalization created for or linked to a specific individual.
(B)
Exclusions— The term “personal information” does not include—
(i)
publicly available information related to an individual; or
(ii)
information derived or inferred from personal information, if the derived or inferred information is not linked or reasonably linkable to a specific individual.
(14)
Privacy harm— The term “privacy harm” means adverse consequences or potential adverse consequences to an individual or society arising from the collection, processing, maintenance, or disclosure of personal information, including—
(A)
direct or indirect financial loss or economic harm;
(B)
physical harm;
(C)
psychological harm, including anxiety, embarrassment, fear, and other demonstrable mental trauma;
(D)
adverse outcomes or decisions with respect to the eligibility of an individual for rights, benefits, or privileges in employment (including hiring, firing, promotion, demotion, and compensation), credit and insurance (including denial of an application or obtaining less favorable terms), housing, education, professional certification, or the provision of health care and related services;
(E)
stigmatization or reputational harm;
(F)
price discrimination;
(G)
other adverse consequences that affect the private life of an individual, including private family matters and actions and communications within the home of such individual or a similar physical, online, or digital location where such individual has a reasonable expectation that personal information will not be collected, processed, or retained;
(H)
chilling of free expression or action of an individual, group of individuals, or society generally, due to perceived or actual pervasive and excessive collection, processing, disclosure, or maintenance of personal information by a covered entity;
(I)
impairing the autonomy of an individual, group of individuals, or society generally; and
(J)
other adverse consequences or potential adverse consequences, consistent with the provisions of this Act, as determined by the Director.
(15)
Privacy preserving computing—
(A)
In general— The term “privacy preserving computing” means—
(i)
the collecting, processing, disclosing, or maintaining of personal information that has been encrypted or otherwise rendered unintelligible using a means that cannot be reversed by a covered entity, or a covered entity’s service provider, such that—
(I)
if such personal information could be rendered intelligible through cooperation or sharing of cryptographic secrets by multiple persons, the covered entity has both technical safeguards and business processes to prevent such cooperation or sharing;
(II)
if such personal information is rendered intelligible within a hardware processing unit or other means of performing operations on the information, there are technical safeguards that, during the normal course of operation—
(aa)
prevent rendering personal information intelligible anywhere but within the hardware processing unit or other means of performing operations; and
(bb)
make the exporting or otherwise observing of such intelligible information, or the cryptographic secret used to protect such information, impossible; and
(III)
if the result of such processing of the personal information is also personal information, such result must be unintelligible to the covered entity or service provider and protected by privacy preserving computing.
(B)
Insufficient methodologies— The Director may determine that a methodology of privacy preserving computing is insufficient for the purposes of this definition.
(16)
Process— The term “process” means to perform or cause to be performed any operation or set of operations on personal information or contents of communication, whether or not by automated means.
(17)
Protected class— The term “protected class” means the actual or perceived race, color, ethnicity, national origin, religion, sex (including sexual orientation and gender identity), familial status, or disability of an individual or group of individuals.
(18)
Publicly available information— The term “publicly available information” means—
(A)
information that is lawfully made available from Federal, State, or local government records;
(B)
information about a public individual or official that is made publicly accessible, without restrictions on accessibility other than the general authorization to access the services used to make the information accessible;
(C)
information made publicly accessible by the individual to whom it pertains, without restrictions on accessibility other than the general authorization to access the services used to make the information accessible, and that such individual has the ability to delete or change without relying on a request under section 102 or 103 of this Act; and
(D)
does not include—
(i)
biometric information collected by a covered entity relating to an individual without the individual’s knowledge;
(ii)
information used for a purpose that is not compatible with the purpose for which the information is maintained and made available in government records;
(iii)
information obtained from government records for the purpose of selling such information; or
(iv)
information used to contact or locate a private individual either physically or electronically.
(19)
Reasonable mechanism— The term “reasonable mechanism” means, in the case of a mechanism for individuals to exercise a right under title I or interact with a covered entity under title II, that such mechanism—
(A)
is equivalent in availability and ease of use to that of other mechanisms for communicating or interacting with the covered entity; and
(B)
includes an online means of exercising such right or engaging in such interaction, if such individuals communicate or interact with such covered entity through an online medium or if such covered entity provides information processing services through a public or widely available application programming interface (or similar mechanism).
(20)
Sell and sale—
(A)
In general— The terms “sell” and “sale” means the disclosure of personal information for monetary consideration by a covered entity to a third party for the purposes of processing, maintaining or disclosing such personal information at the third party’s discretion.
(B)
Exclusions— The terms “sell” and “sale” do not include—
(i)
the disclosure of personal data to a third party with which the individual has a direct relationship for purposes of providing a product or service requested by the individual or otherwise in a manner that is consistent with an individual’s reasonable expectations considering the context in which the individual provided the personal information to the covered entity;
(ii)
the disclosure or transfer of personal information to a subsidiary or an affiliate of the covered entity; or
(iii)
the disclosure or transfer of personal information to a third party as an asset that is part of a merger, acquisition, bankruptcy, or other transaction in which the third party assumes control of all or part of the covered entity’s assets, unless such assets are limited to personal information unless personal information makes up the majority of the value of such assets.
(21)
Service provider—
(A)
In general— The term “service provider” means a covered entity who—
(i)
processes, discloses, or maintains personal information, where such person does not process, disclose, or maintain the personal information other than in accordance with the directions and on behalf of another covered entity;
(ii)
does not directly collect personal information from or control the mechanism for collecting personal information from an individual;
(iii)
does not earn revenue from processing, maintaining, or disclosing personal information disclosed to the service provider by a covered entity except by providing contracted services to another covered entity;
(iv)
does not disclose personal information to another covered entity unless it was provided by that covered entity or resulted from maintaining or processing performed on personal information exclusively provide by that covered entity;
(v)
does not offer services that allow another covered entity to target specific individuals using personal information not provided by that covered entity;
(vi)
assists a covered entity on behalf of which it processes personal information to comply with title I, with respect to personal information processed or maintained by the service provider on behalf of the covered entity, including providing tools for such covered entities requirements under title I if requested; and
(vii)
does not link the personal information provided by another covered entity to personal information from any other source.
(B)
Any such person, and the personal information they disclose, process, or maintain, shall be treated as a service provider under this Act only to the extent that such person complies with the requirements under (A).
(22)
Significant privacy harm— The term “significant privacy harm” means adverse consequences to an individual arising from the collection, processing, maintenance, or disclosure of personal information, limited to subparagraph (A), (B), or (D) of paragraph (14).
(23)
Small business— The term “small business” means a covered entity that—
(A)
does not earn revenue from the sale of personal information;
(B)
earns less than half of annual revenues from the processing of personal information for targeted or personalized advertising;
(C)
has not, at any time during the preceding 6-month period, maintained personal information of 250,000 or more individuals;
(D)
has fewer than 200 employees; and
(E)
received less than $25,000,000 in gross revenue in the preceding 12-month period.
(24)
State— The term “State” means each State of the United States, the District of Columbia, each commonwealth, territory, or possession of the United States, and each federally recognized Indian Tribe.
(25)
Third party— The term “third party” means, with respect to a covered entity, a person—
(A)
to whom such covered entity disclosed personal information; and
(B)
is not—
(i)
such covered entity;
(ii)
a subsidiary or corporate affiliate of such covered entity; or
(iii)
a service provider of such covered entity.

3. Prohibition on waivers

(a)
In general— The provisions under this Act may not be waived. Any agreement purporting to waive compliance with or modify any provision of this Act shall be void as contrary to public policy.
(b)
Prohibition on predispute arbitration agreements— No predispute arbitration agreement shall be valid or enforceable with respect to any claims under this Act.

4. Effective date

(a)
In general— This Act shall apply beginning on the date that is 1 year after the date of the enactment of this Act.
(b)
Authority To promulgate regulations and take certain other actions— Nothing in subsection (a) affects the authority to take an action expressly required by a provision of this Act to be taken before the effective date described in such subsection.

5. Journalism protection

(a)
In general— Covered entities engaged in journalism shall not be subject to the obligations imposed under this Act to the extent that those obligations directly infringe on the journalism rather than the business practices of the covered entity, so long as, the covered entity has technical safeguards and business processes that prevent the collection, processing, maintaining, or disclosure of such personal information for business practices other than journalism.
(b)
Journalism— The term “journalism” includes the collecting, maintaining, processing, and disclosing of personal information about a public individual or official, or that otherwise concerns matters of public interest, for dissemination to the public.

6. Small business compliance ramp

Upon losing its status as a small business, a covered entity shall have nine months to comply with provisions of this Act that a small business is exempt from complying with.

7. Criminal prohibition on disclosing personal information

Chapter 41 of title 18, United States Code, is amended by adding at the end the following:

“881. Disclosure of personal information with the intent to cause harm

“Whoever uses a channel of interstate or foreign commerce to knowingly disclose an individual’s personal information—

“(1) with the intent to threaten, intimidate, or harass any person, incite or facilitate the commission of a crime of violence against any person, or place any person in reasonable fear of death or serious bodily injury; or

“(2) with the intent that the information will be used to threaten, intimidate, or harass any person, incite or facilitate the commission of a crime of violence against any person, or place any person in reasonable fear of death or serious bodily injury,”

8. Limitation on disclosing nonredacted government records

(a)
In general— A Federal or State government entity may not use a channel of interstate commerce to disclose the personal information of an individual in a government record without an agreement prohibiting the recipient of such information from selling the information without the express consent of the individual for each disclosure.
(b)
Exception— Notwithstanding subsection (a), nothing in this section shall prohibit the disclosure of personal information using a channel of interstate commerce to another government entity without consent of the individual.