National Security and Personal Data Protection Act of 2019
A BILL
To safeguard data of Americans from foreign governments that pose risks to national security by imposing data security requirements and strengthening review of foreign investments, and for other purposes.
2. Definitions
3. Data security requirements for covered technology companies
4. Data security requirements for other technology companies
5. Enforcement of data security requirements
6. Requirement for approval of Committee on Foreign Investment in the United States of certain transactions
“(9) Approval required for certain transactions
“(A) In general—A covered transaction described in subparagraph (C) is prohibited unless the Committee—
“(i) reviews the transaction under this subsection; and
“(ii) determines that the transaction does not pose a risk to the national security of the United States.
“(B) Mitigation—The Committee, or a lead agency on behalf of the Committee, may negotiate, enter into or impose, and enforce an agreement or condition under subsection (l)(3) with any party to a covered transaction described in subparagraph (C) to mitigate any risk to the national security of the United States that arises as a result of the covered transaction.
“(C) Covered transaction described—A covered transaction described in this subparagraph is a transaction that could result in foreign control of a United States company—
“(i) that collects, sells, buys, or processes user data (as defined in section 2 of the National Security and Personal Data Protection Act of 2019) and whose business consists substantially more of transferring data than manufacturing, delivering, repairing, or servicing physical goods or providing physical services; or
“(ii) that operates a social media platform or website.”