US Codex
Bill
Notes

Title II — Requirements for Covered Entities, Service Providers, and Third Parties

H.R. 4978 · 116th Congress · Nov 5, 2019 · Lineage

II Requirements for Covered Entities, Service Providers, and Third Parties

Sec. 201 Minimization and articulated basis for collection, processing, and maintenance

(a)
Articulated basis— A covered entity shall have a reasonable, articulated basis for the collection, processing, disclosure, and maintenance of personal information that takes into account the reasonable business needs of the covered entity and minimum amount of personal information necessary for providing the service, balanced with the intrusion on the privacy of, potential privacy harms to, and reasonable expectations of individuals to whom the personal information relates.
(b)
Minimization of collection, processing, disclosure, and maintenance—
(1)
Collection— A covered entity may not collect more personal information than is reasonably needed to provide a product or service that an individual has requested.
(2)
Processing— A covered entity may not process personal information for a purpose other than the purpose for which such information was originally collected from the individual or in the case of a service provider, a purpose other than that which is in accordance with the directions of a covered entity.
(3)
Disclosure— A covered entity may not disclose personal information for a purpose other than the purpose for which such information was originally collected from the individual or in the case of a service provider, a purpose other than that which is in accordance with the directions of a covered entity.
(4)
Maintenance— A covered entity may not maintain personal information once such information is no longer needed for the purpose for which such information was originally collected from the individual or in the case of a service provider, a purpose other than that which is in accordance with the directions of a covered entity.
(c)
Ancillary collection, processing, disclosure, and maintenance— Notwithstanding subsection (b), a covered entity may engage in collection, processing, disclosure, or maintenance of personal information beyond limitations under subsection (b) only if such covered entity complies with this subsection.
(1)
No notice or consent required— A covered entity may engage in collection, processing, or maintenance of personal information without additional notice or consent if the purpose for such collection, processing, or maintenance is substantially similar to the type of personal information and purpose for which such personal information was originally collected and such ancillary collection, processing, or maintenance will not result in additional or increased privacy harms.
(2)
Notice required— A covered entity shall provide notice of ancillary collection, processing, disclosure or maintenance of personal information in the case of one, but not more than one, of the following:
(A)
Such ancillary collection, processing, disclosure, or maintenance may result in additional or increased privacy harms (but not increased significant privacy harms), and is substantially similar to the purpose for which such personal information was originally collected.
(B)
The purpose for such ancillary collection, processing, disclosure, or maintenance is not substantially similar to the purpose for which such personal information was originally collected, but will not result in additional or increased privacy harms.
(C)
Such ancillary collection, processing, disclosure, or maintenance may result in additional or increased privacy harms (but not increased significant privacy harms) and the purpose is not substantially similar to the purpose for which such personal information was originally collected, so long as, the personal information is secured using privacy preserving computing.
(3)
Notice and consent required— For scenarios not covered under paragraph (1) or (2), and notwithstanding section 212(b)(2) and (3), a covered entity shall provide notice of and obtain consent for ancillary collection, processing, disclosure or maintenance of personal information.
(d)
Substitution— In cases in which personal information can be replaced with artificial personal information, personal information that has been de-identified, or the random personal information of a one or more individuals without substantially reducing the utility of the data or requiring an unreasonable amount of effort, such a replacement shall take place.

Sec. 202 Minimization and records of access by employees and contractors

(a)
Minimization— A covered entity shall restrict access to personal information and contents of communications by the employees or contractors of such covered entity based on an articulated balance between the potential for privacy harm, reasonable expectations of individuals to whom the personal information relates, and reasonable business needs.
(b)
Records of access—
(1)
In general— A covered entity shall maintain records identifying each instance in which an employee or a contractor of such covered entity accesses personal information or contents of communications if disclosure of, or a data breach or data sharing abuse involving, such personal information or contents may foreseeably result in increased privacy harms.
(2)
Information required— The records required by paragraph (1) shall include the following:
(A)
A unique identifier for the employee or contractor accessing personal information or contents of communications.
(B)
The date and time of access.
(C)
The fields of information accessed.
(D)
The individuals whose personal information was accessed or the contents of whose communications were accessed.
(3)
Small businesses excluded— This subsection does not apply to a small business.

Sec. 203 Prohibition on the collection or maintenance of personal information

A covered entity may not collect or maintain personal information using a channel of interstate commerce unless such covered entity is in compliance with all requirements of this Act.

Sec. 204 Prohibitions on the disclosure of personal information

(a)
Consent for disclosure required—
(1)
In general— A covered entity may not intentionally disclose personal information unless the covered entity obtains consent of the individual whose personal information is being disclosed for each category of third party to which such personal information will be disclosed. Such covered entity must also provide such individual with notice of—
(A)
each category of third party;
(B)
the personal information to be disclosed; and
(C)
a concise and clear description of the business or commercial purpose for such disclosure.
(2)
Additional requirements for sale of personal information—
(A)
In general— A covered entity may not intentionally sell personal information unless the covered entity—
(i)
obtains the consent required by paragraph (1) for each individual disclosure of such person information; and
(ii)
and provides the individual to whom such personal information relates with the identity of the specific third party to which such personal information will be disclosed.
(B)
Disclosure services— Subparagraph (A) shall not apply to a covered entity in a case in which an individual is directing the covered entity to disclose the personal information of such individual for the sole purpose of procuring goods or services, or offers for goods or services, for such individual, if there is a reasonable mechanism for the individual to withdraw consent.
(3)
Requirement to include original purpose of collection— A covered entity may not intentionally disclose personal information without including the purpose for which the personal information was originally collected.
(4)
Exception for privacy preserving computing— Notwithstanding paragraph (1), consent is not required for a disclosure (not including sale) of personal information secured using privacy preserving computing.
(5)
Exception for de-identified personal information— Notwithstanding paragraph (1), consent is not required for a disclosure (not including sale) of de-identified personal information where the disclosed personal information is limited to the narrowest possible scope likely to yield the intended benefit and contractual obligations are in place that prohibit—
(A)
re-identification of the disclosed personal information; and
(B)
the processing of additional personal information in combination with the disclosed personal information that would allow for the reidentification of the disclosed personal information.
(b)
Disclosure for advertising or marketing purposes—
(1)
In general— A covered entity may not intentionally disclose for advertising or marketing purposes a unique identifier or any other personal information that would allow the disclosure of such information to be linked to past or future disclosures of information relating to the same individual or device.
(2)
Treatment of certain types of information— A disclosure for advertising or marketing purposes may not be treated as violating subparagraph (1) by reason of including any or all of the following:
(A)
Internet Protocol addresses truncated to no more than the first 24 bits for Internet Protocol version 4 and the first 48 bits for Internet Protocol version 6, or for a successor protocol truncated to limit the precision of the identifier to a network address of the internet access provider.
(B)
Geolocation information truncated to allow no more than the equivalent of two decimal degrees of precision at the equator or prime meridian, or an equivalent precision in another geolocation standard.
(C)
A general description of a device, browser, or operating system, or any combination thereof.
(D)
An identifier that is unique for each disclosure.

Sec. 205 Disclosure to entities not subject to United States jurisdiction or not compliant with this Act

(a)
Prohibition— A covered entity may not intentionally disclose personal information to any entity that—
(1)
is not subject to the jurisdiction of the United States; or
(2)
is not in compliance with all requirements of this Act.
(b)
Exception— Notwithstanding subsection (a), a covered entity may disclose personal information where that personal information is limited to an identifier created primarily for the purpose of sending or receiving electronic communications and the sole purpose of the disclosure is to send or receive an electronic communication at the request of the individual whose personal information is being disclosed.
(c)
Disclosure safe harbors— Notwithstanding subsection (a), a covered entity may disclose personal information to another covered entity (the receiving covered entity) that is not subject to the jurisdiction of the United States if either—
(1)
the receiving covered entity has entered into an agreement, as described in subsection (e), with the Agency, and—
(A)
the covered entity has a reasonable belief that the receiving covered entity is sufficiently solvent to compensate victims or pay fines for violations of this Act;
(B)
a contract between the covered entity and receiving covered entity requires that the receiving covered entity complies with this Act, and the covered entity has reason to believe the receiving covered entity is compliant with this Act; and
(C)
a contract between the covered entity and the receiving covered entity prohibits the receiving covered entity from using the disclosed personal information for any purpose other than provided in the contract; or
(2)
the covered entity has—
(A)
entered into an agreement with the receiving covered entity that—
(i)
requires the receiving covered entity to comply with this Act;
(ii)
prohibits the receiving covered entity from using the disclosed personal information for any purpose other than provided in the contract;
(iii)
requires the receiving covered entity to indemnify the covered entity against violations of this Act committed by the receiving covered entity for any amount the covered entity is unable to pay of a judgment for such violation;
(iv)
grants the covered entity the authority to audit, including physical access to electronic devices and data, the receiving covered entity’s compliance with this Act and the contract; and
(v)
requires the receiving covered entity to assist the covered entity in responding to and complying with any court orders, Agency orders, or the exercising of an individual’s rights under this Act;
(B)
actual knowledge that the receiving covered entity is in compliance with this Act and not using personal information contrary to their agreement;
(C)
actual knowledge that the receiving covered entity is sufficiently solvent to compensate victims or pay fines for violations of this Act;
(D)
an auditing and compliance program to ensure the receiving covered entity’s continued compliance with this Act and contract terms;
(E)
filed with the Agency the terms of said contract, proof of its actual knowledge of the receiving covered entity’s compliance with this Act and contract terms, and documents detailing its auditing and compliance program for approval and publication by the Agency; and
(F)
the covered entity has entered into an agreement with the Agency where it agrees to accept, respond to, or comply with a court order, agency order, or request by an individual regarding actions taken by the receiving covered entity with respect to the data it has disclosed.
(d)
For the purposes of subsection (c)(2), the covered entity shall be jointly liable for a violation of this Act by the receiving covered entity regarding the data the covered entity disclosed, except where the covered entity was the first to notify the Agency of the violation, in which case, it shall be severally liable. Where the covered entity should reasonably have known of a violation of this Act by the receiving covered entity and fails to disclose the violation to the Agency, each day of continuance of the failure to report such violation shall be treated as a separate violation.
(e)
Agency agreements— Upon the request of a covered entity not subject to the jurisdiction of the United States, the Agency shall enter into an agreement with the covered entity that includes, but is not limited to, the following conditions:
(1)
The principle place of business for the covered entity must be in a country that allows for the domestication of a United States court decision for civil fines payable to a government entity and injunctive relief. Where a foreign court refuses to enforce a United States court decision under this Act, the agreement, and all other agreements with covered entities with a principle place of business in the same jurisdiction, shall be void.
(2)
The covered entity agrees to comply with this Act.
(3)
The covered entity agrees to be subject to this Act with choice of venue being a United States court.
(4)
The covered entity agrees to comply with Agency investigative requests or orders, and United States court orders or decisions under this Act.
(5)
The covered entity consents to United States Federal court personal jurisdiction for the sole purpose of enforcing this Act.
(6)
Where enforcement of the decision requires the use of a foreign court, the covered entity agrees to pay reasonable attorney fees necessary to enforce the judgment.
(7)
A default judgment, failure to comply with Agency investigative requests or orders, or failure to comply with United States court orders or decisions shall result in the immediate termination of the agreement.
(f)
Rule of construction against data localization— Nothing in this section shall be construed to require the localization of processing or maintaining personal information by a covered entity to within the United State, or limit internal disclosure of personal information within a covered entity or to subsidiary or corporate affiliate of such covered entity, regardless of the country in which the covered entity will process, disclose, or maintain that personal information.

Sec. 206 Prohibition on reidentification

(a)
In general— Except as required under title I, a covered entity shall not use personal information collected from an individual, acquired from a third party, or acquired from a publicly available information to reidentify an individual from de-identified information.
(b)
Third-Party prohibition— A covered entity that discloses de-identified information to a third party shall prohibit such third party from reidentifying an individual using such de-identified information.
(c)
Exception— Subsection (a) shall not apply to qualified research entities, as determined by the Director, conducting research not for commercial purposes.

Sec. 207 Restrictions on collection, processing, and disclosure of contents of communications

(a)
In general— A covered entity may not collect, process, maintain, or disclose the contents of any communication, regardless of whether the sender or intended recipient of the communication is an individual, other person, or an electronic device, for any purpose other than—
(1)
transmission or display of the communication to any intended recipient or the original sender, or maintenance of such communications for such purposes;
(2)
detecting, responding to, or preventing security incidents or threats;
(3)
providing services to assist in the drafting or creation of the content of a communication;
(4)
processing expressly requested by the sender or intended recipient, if the sender or intended recipient can terminate such processing using a reasonable mechanism;
(5)
a disclosure otherwise required by law;
(6)
the filtering of a communication where primary purpose of the communication is the commercial advertisement or promotion of a commercial product or service; or
(7)
detecting or enforcing an abuse or violation of the service’s terms of service that would result in either a temporary or permanent ban from using the service.
(b)
Intended recipient— A covered entity is not considered an intended recipient of a communication, or any communication used in the creation of the content of said communication, where—
(1)
at least one intended recipient is a natural person other than an employee or contractor of the covered entity;
(2)
at least one intended recipient is a person other than the covered entity; or
(3)
a purpose of the covered entity’s service is to maintain, at the direction of the sender, the content of said communication for more than a transitory period.
(c)
Sender— The sender of a communication is the person for whom the communication, and its content, is disclosed at the direction of and on behalf of.
(1)
Where the sender is a natural person, they shall be the sender of the entire content of the communication, regardless of the original author of any portion of the content.
(2)
Otherwise, a sender shall be the sender of only the content it was an original author of, or content it received as an intended recipient.
(d)
Exception for publicly available communications— Subsection (a) shall not apply where the contents of communication that are made publicly accessible by the sender without restrictions on accessibility other than the general authorization to access the services used to make the information accessible.
(e)
Encryption protection— A covered entity shall not—
(1)
prohibit or prevent a person from encrypting or otherwise rendering unintelligible the content of a communication using a means that prevents the covered entity from being able to decrypt or otherwise render intelligible said content; and
(2)
require or cause a person to disclose or circumvent the means described in paragraph (1) to the covered entity that would allow it to render the content intelligible.
(f)
Service providers safe harbor— A service provider shall not be held liable for a violation of this section if such service provider is acting at the direction of and on behalf of a covered entity and has a reasonable belief that the covered entity’s directions are in compliance with this section.

Sec. 208 Prohibition on discriminatory processing

(a)
Discrimination in economic opportunities— A covered entity shall not process personal information or contents of communication for advertising, marketing, soliciting, offering, selling, leasing, licensing, renting, or otherwise commercially contracting for employment, finance, healthcare, credit, insurance, housing, or education opportunities in a manner that discriminates against or otherwise makes opportunities unavailable on the basis of an individual’s protected class status.
(b)
Public accommodations— A covered entity shall not process personal information in a manner that segregates, discriminates in, or otherwise makes unavailable the goods, services, facilities, privileges, advantages, or accommodations of any place of public accommodation on the basis of a person’s or a group’s protected class status.
(c)
The Director shall promulgate regulations to implement this section.

Sec. 209 Restrictions on genetic information

(a)
In general— A covered entity may not collect, process, maintain, or disclose genetic information for any purpose other than—
(1)
providing medical treatment or testing to the individual whose genetic information is being collected, processed, maintained, or disclosed;
(2)
research and services related to medical, historical, or population uses of genetic information, if, in the case of disclosure of genetic information—
(A)
such genetic information is only disclosed to qualified research entities, as determined by the Director;
(B)
additional personal information disclosed with such genetic information is limited to the narrowest possible scope likely to yield the intended benefit; and
(C)
the covered entity limits, through contractual obligations, additional types of personal information that can be processed with the disclosed genetic information and personal information.
(3)
a purpose specified by the Director by regulation, taking into account the potential privacy harms and potential benefits of such collection, processing, maintenance, or disclosure; or
(4)
to comply with a Federal criminal investigation request or order.
(b)
Genetic information defined— In this section, the term “genetic information” has the meaning given such term in section 201 of the Genetic Information Nondiscrimination Act of 2008 (42 U.S.C. 2000ff).
(c)
Service providers safe harbor— A service provider shall not be held liable for a violation of this section if such service provider is acting at the direction of and on behalf of a covered entity and has a reasonable belief that is the covered entity’s directions are in compliance with this section.

Sec. 210 Requirements for notice and consent processes and privacy policies

(a)
Minimum threshold— The Director shall establish a minimum threshold that a covered entity must meet for the percentage of individuals who read and understand a notice or consent process or privacy policy required by this Act. In establishing such minimum thresholds, the Director shall take into account expectations of individuals, potential privacy harms, and individuals’ awareness of privacy harms.
(b)
Consent revocation— A covered entity shall make available a reasonable mechanism by which an individual may revoke consent for any consent given under this Act.
(c)
Safe harbor—
(1)
Approval procedures— The Director shall develop procedures for analyzing and approving data submitted by a covered entity to establish that a notice and consent process or privacy policy of such covered entity meets the threshold established under subsection (a).
(2)
Presumption— If a covered entity submits testing data to and receives an approval from the Director under paragraph (1) establishing that a notice or consent process or privacy policy of such covered entity meets the threshold established under subsection (a), such notice or consent process or privacy policy shall be presumed to have met such threshold. Such presumption may be rebutted by clear and convincing evidence.
(3)
Public availability of Approved processes and policies and associated testing data— The Director shall make publicly available online the notice and consent processes and privacy policies and associated testing data that the Director approves under paragraph (1).
(4)
Small business adoption of notice or consent process of another covered entity—
(A)
In general— If a small business adopts a notice or consent process of another covered entity that collects, processes, maintains, or discloses personal information in substantially the same way as such small business, if the process of such other covered entity has been approved under paragraph (1), the process of such small business shall receive the presumption under paragraph (2).
(B)
Ability to freely use Approved process— A covered entity whose notice or consent process is approved under paragraph (1) shall permit a small business to freely use such process, or a derivative thereof, as described in subparagraph (A).
(C)
No published process— In the case of a small business for which there is no approved notice or consent process published under paragraph (3) of a covered entity that collects, processes, maintains, or discloses personal information in substantially the same way as such small business, any requirement under this title for a notice or consent process to be objectively shown to meet the threshold established by the Director under subsection (a) shall not apply to such small business. Nothing in the preceding sentence exempts a small business from the requirement to use such notice or consent process or that such process be concise and clear.
(D)
Inapplicability to privacy policy— Paragraph (4) does not apply with respect to a privacy policy.
(5)
Minor changes— A covered entity may make minor changes in a notice or consent process or privacy policy approved under paragraph (1) and retain the presumption under paragraph (2) for such process or policy without retesting or resubmission of testing data to the Director.

Sec. 211 Prohibition on deceptive notice and consent processes and privacy policies

In providing notice, obtaining consent, or maintaining a privacy policy as required by this title, a covered entity may not intentionally take any action that substantially impairs, obscures, or subverts the ability of an individual to—
(1)
understand the contents of such notice or such privacy policy;
(2)
understand the process for granting such consent;
(3)
make a decision regarding whether to grant or withdraw such consent; or
(4)
act on any such decision.

Sec. 212 Notice and consent required

(a)
Notice— A covered entity shall provide an individual with notice of the personal information such covered entity collects, processes, maintains, and discloses through a process that is concise and clear and can be objectively shown to meet the threshold established by the Director under section 210(a).
(b)
Consent—
(1)
Express consent required— Except as provided in paragraphs (2) and (3), a covered entity may not collect from an individual personal information that creates or increases the risk of foreseeable privacy harms, or process or maintain any such personal information collected from an individual, unless such entity obtains the express consent of such individual to the collection, processing, or maintenance (or any combination thereof) of such information through a process that is concise and clear and can be objectively shown to meet the threshold established by the Director under section 210(a).
(2)
Exception for implied consent— Notwithstanding paragraph (1), express consent is not required for collection, processing, or maintenance of personal information if the collection, processing, or maintenance is, on its face, obvious and necessary to provide a service at the request of the individual and the personal information is collected, processed, or maintained only for such request. Nothing in this paragraph shall be construed to exempt the covered entity from the requirement of subsection (a) to provide notice to such individual with respect to such collection, processing, or maintenance.
(3)
Exemption for privacy preserving computing— Notwithstanding paragraph (1), except with regard to consent for purposes of section 106, express consent is not required for collection, processing, or maintenance of personal information secured using privacy preserving computing. Nothing in this paragraph shall be construed to exempt the covered entity from the requirement of subsection (a) to provide notice to such individual with respect to such collection, processing, or maintenance.
(c)
Service providers excluded— This section does not apply to a service provider if such service provider has a reasonable belief that a covered entity for which it processes, maintains, or discloses personal information is in compliance with this section.

Sec. 213 Privacy policy

(a)
Policy required— A covered entity shall maintain a privacy policy relating to the practices of such entity regarding the collection, processing, maintenance, and disclosure of personal information.
(b)
Contents— The privacy policy required by subsection (a) shall contain the following:
(1)
A general description of the practices of the covered entity regarding the collection, processing, maintenance, and disclosure of personal information.
(2)
A description of how individuals may exercise the rights provided by title I.
(3)
A clear and concise summary of the following:
(A)
The categories of personal information collected or otherwise obtained by the covered entity.
(B)
The business or commercial purposes of the covered entity for collecting, processing, maintaining, or disclosing personal information.
(C)
The categories and a list of third parties to which the covered entity discloses personal information.
(4)
A description of the personal information that the covered entity maintains that the covered entity does not collect from individuals and how the covered entity obtains such personal information.
(5)
A list of the third parties to which the covered entity has disclosed personal information.
(6)
A list of the third parties from which the covered entity has obtained personal information at any time on or after the effective date specified in section 4(a).
(7)
The articulated basis for the collection, processing, disclosure and maintenance of personal information, as required under section 201(a).
(c)
Exemption for personal information for particular purposes— The privacy policy required by subsection (a) is not required to contain information relating to personal information that is collected, processed, maintained, or disclosed exclusively for any of the purposes described in paragraph (1) of section 109(a) (or a combination of such purposes), except as provided in paragraph (2) of such section.
(d)
Availability of privacy policy—
(1)
Form and manner— The privacy policy required by subsection (a) shall be—
(A)
clear and in plain language; and
(B)
made publicly available in a prominent location on an ongoing basis.
(2)
Timing— The privacy policy required by subsection (a) shall be made available as required by paragraph (1) before any collection of personal information by the covered entity that occurs after the effective date specified in section 4(a).
(e)
Small businesses excluded— Subsections (b)(7) and (d) do not apply to a small business.
(f)
Service providers excluded— This section does not apply to a service provider if such service provider has a reasonable belief that a covered entity for which it processes, maintains, or discloses personal information is in compliance with this section.

Sec. 214 Information security requirements

(a)
In general— A covered entity shall establish and implement reasonable information security policies, practices, and procedures for the protection of personal information collected, processed, maintained, or disclosed by such covered entity, taking into consideration—
(1)
the nature, scope, and complexity of the activities engaged in by such covered entity;
(2)
the sensitivity of any personal information at issue;
(3)
the current state of the art in administrative, technical, and physical safeguards for protecting such information; and
(4)
the cost of implementing such administrative, technical, and physical safeguards.
(b)
Point of contact— A covered entity shall identify an officer or other individual as the point of contact with responsibility for the management of information security.
(c)
Specific policies, practices, and procedures— The policies, practices, and procedures required by subsection (a) shall include the following:
(1)
A written security policy with respect to the collection, processing, maintenance, and disclosure of personal information. Such policy shall be made publicly available in a prominent location on an ongoing basis, except that the publicly available version is not required to contain information that would compromise a purpose described in paragraph (1) of section 109(a).
(2)
A process for identifying and assessing reasonably foreseeable security vulnerabilities in the system or systems used by such covered entity that contain personal information, which shall include regular monitoring for vulnerabilities or data breaches involving such system or systems.
(3)
A process for taking action designed to mitigate against vulnerabilities identified in the process required by paragraph (2), which may include implementing any changes to security practices and the architecture, installation, or implementation of network or operating software, or for regularly testing or otherwise monitoring the effectiveness of the existing safeguards.
(4)
A process for determining if personal information is no longer needed and disposing of personal information by shredding, permanently erasing, or otherwise modifying the medium on which such personal information is maintained to make such personal information permanently unreadable or indecipherable.
(5)
A process for overseeing persons who have access to personal information, including through network-connected devices.
(6)
A process for employee training and supervision for implementation of the policies, practices, and procedures required by this section.
(7)
A written plan or protocol for internal and public response in the event of a data breach or data sharing abuse.
(d)
Regulations— The Director, in consultation with the National Institute of Standards and Technology, shall promulgate regulations to implement this section.
(e)
Small businesses assistance— The Director, in consultation with the National Institute of Standards and Technology, the Small Business Association, and small businesses, shall develop policy templates, toolkits, tip sheets, configuration guidelines for commonly used hardware and software, interactive tools, and other materials to assist small businesses with complying with this section.

Sec. 215 Notification of data breach or data sharing abuse

(a)
Notification of agency—
(1)
In general— In the case of a data breach or data sharing abuse with respect to personal information maintained by a covered entity, such covered entity shall, without undue delay and, if feasible, not later than 72 hours after becoming aware of such data breach or data sharing abuse, notify the Director of such data breach or data sharing abuse, unless such data breach or data sharing abuse is unlikely to create or increase foreseeable privacy harms.
(2)
Reasons for delay— If the notification required by paragraph (1) is made more than 72 hours after the covered entity becomes aware of the data breach or data sharing abuse, such notification shall be accompanied by a statement of the reasons for the delay.
(b)
Notification of other covered entity— In the case of a data breach or data sharing abuse with respect to personal information maintained by a covered entity that such covered entity obtained from another covered entity, the covered entity experiencing such data breach or data sharing abuse shall, without undue delay and, if feasible, not later than 72 hours after becoming aware of such data breach or data sharing abuse, notify such other covered entity of such data breach or data sharing abuse, unless such data breach or data sharing abuse is unlikely to create or increase foreseeable privacy harms. A covered entity receiving notice under this subsection of a data breach or data sharing abuse shall notify any other covered entity from which the covered entity receiving notice obtained personal information involved in such data breach or data sharing abuse, in the same manner as required under the preceding sentence for the covered entity experiencing such data breach or data sharing abuse.
(c)
Notification of individuals—
(1)
In general— In the case of a data breach or data sharing abuse with respect to personal information maintained by a covered entity (or a data breach or data sharing abuse about which a covered entity is notified under subsection (b)), if such covered entity has a relationship with an individual whose personal information was involved or potentially involved in such data breach or data sharing abuse, such covered entity shall notify such individual of such data breach or data sharing abuse not later than 14 days after becoming aware of such data breach or data sharing abuse (or, in the case of a data breach or data sharing abuse about which a covered entity is notified under subsection (b), not later than 14 days after being so notified), if such data breach or data sharing abuse creates or increases foreseeable privacy harms.
(2)
Medium of notification— A covered entity shall notify an individual as required by paragraph (1) through—
(A)
the same medium through which such individual routinely interacts with such covered entity; and
(B)
one additional medium of notification, if such covered entity has the personal information necessary to make a notification through such an additional medium without causing excessive financial burden for such covered entity.
(d)
Rule of construction— This section shall not apply to a covered entity if a person uses personal information obtained from a data breach or data sharing abuse not involving such covered entity.