Mind Your Own Business Act of 2019
A BILL
To amend the Federal Trade Commission Act to establish requirements and responsibilities for entities that use, store, or share personal information, to protect personal information, and for other purposes.
Sec. 2 Definitions
Sec. 3 Noneconomic injury
Sec. 4 Civil penalty authority
Sec. 5 Annual data protection reports
“1352. Failure of corporate officers to certify data protection reports
“(a) Definitions—In this section:
“(1) Covered entity—The term covered entity has the meaning given the term in section 2 of the Mind Your Own Business Act of 2019.
“(2) Willfully—The term willfully means the voluntary, intentional violation of a known legal duty.
“(b) Certification of annual data protection reports—Each annual report filed by a company with the Federal Trade Commission pursuant to section 5(a) of the Mind Your Own Business Act of 2019 shall be accompanied by a written statement by the chief executive officer and chief privacy officer (or equivalent thereof) of the company.
“(c) Content—The statement required under subsection (b) shall certify that the annual report fully complies with the requirements of section 5(a) of the Mind Your Own Business Act of 2019.
“(d) Criminal penalties—Whoever—
“(1) certifies any statement as set forth in subsections (b) and (c) of this section knowing that the annual report accompanying the statement does not comport with all the requirements set forth in this section shall be fined not more than the greater of $1,000,000 or 5 percent of the largest amount of annual compensation the person received during the previous 3-year period from the covered entity, imprisoned not more than 10 years, or both; or
“(2) willfully certifies any statement as set forth in subsections (b) and (c) of this section knowing that the annual report accompanying the statement does not comport with all the requirements set forth in this section shall be fined not more than $5,000,000 or 25 percent of the largest amount of annual compensation the person received during the previous 3-year period from the covered entity, imprisoned not more than 20 years, or both.”
Sec. 6 “Do not track” data sharing opt out
Sec. 7 Data protection authority
Sec. 8 Bureau of Technology
Sec. 9 Additional personnel in the Bureau of Consumer Protection
Sec. 10 Complaint resolution
Sec. 11 Application programming interfaces
Sec. 12 News media protections
Sec. 13 Excise tax
“50A Failure to certify data protection reports
“5000D. Failure to certify data protection reports
“(a) Imposition of tax—In the case of any covered reporting entity with respect to which a responsible executive has been convicted under section 1352(d) of title 18, United States Code, there is imposed a tax equal to the amount determined under subsection (b).
“(b) Amount of tax
“(1) In general—The amount determined under this subsection is the applicable percentage of the amount determined under paragraph (3).
“(2) Applicable percentage—For purposes of paragraph (1), the applicable percentage is—
“(A) in the case of a covered reporting entity that is a corporation, the highest rate of tax in effect under section 11 for the taxable year which includes the date on which the specified annual data protection report to which the conviction relates is due, and
“(B) in the case of any other covered reporting entity, the highest rate of tax in effect under section 1 for such taxable year.
“(3) Amount determined
“(A) In general—The amount determined under this paragraph is the sum of the covered compensation amounts of each responsible executive of the covered reporting entity who has been convicted under section 1352(d) of title 18, United States Code.
“(B) Covered compensation amount—For purposes of subparagraph (A), the covered compensation amount with respect to any responsible executive is the largest amount of annual wages (as defined in section 3121(a), determined without regard to any dollar limitation contained in such section) of the responsible executive with respect to services performed for the covered reporting entity during the 3-year period preceding the year to which the specified annual data protection report relates.
“(c) Definitions—For purposes of this section—
“(1) Covered reporting entity
“(A) In general—The term covered reporting entity means any covered entity (as defined under section 2 of the Mind Your Own Business Act of 2019) which is required to file a specified annual data protection report.
“(B) Aggregation rules—For purposes of this paragraph, all covered entities who are treated as a single employer under subsection (b), (c), (m), or (o) of section 414 shall be treated as one person.
“(2) Responsible executive—For purposes of this subsection, the term responsible executive means, with respect to a covered reporting entity, any of the following officers:
“(A) The chief executive officer.
“(B) The chief privacy officer (or equivalent thereof).
“(3) Specified annual data protection report—The term specified annual data protection report means the report required to be filed under section 5(a) of the Mind Your Own Business Act of 2019.”