(a)
In general— An online service provider shall fulfill the duties of care, loyalty, and confidentiality under paragraphs (1), (2), and (3), respectively, of subsection (b).
(b)
Duties—
(1)
Duty of care— An online service provider shall—
(A)
reasonably secure individual identifying data from unauthorized access; and
(B)
subject to subsection (d), promptly inform an end user of any breach of the duty described in subparagraph (A) of this paragraph with respect to sensitive data of that end user.
(2)
Duty of loyalty— An online service provider may not use individual identifying data, or data derived from individual identifying data, in any way that—
(A)
will benefit the online service provider to the detriment of an end user; and
(B)
(i)
will result in reasonably foreseeable and material physical or financial harm to an end user; or
(ii)
would be unexpected and highly offensive to a reasonable end user.
(3)
Duty of confidentiality— An online service provider—
(A)
may not disclose or sell individual identifying data to, or share individual identifying data with, any other person except as consistent with the duties of care and loyalty under paragraphs (1) and (2), respectively;
(B)
may not disclose or sell individual identifying data to, or share individual identifying data with, any other person unless that person enters into a contract with the online service provider that imposes on the person the same duties of care, loyalty, and confidentiality toward the applicable end user as are imposed on the online service provider under this subsection; and
(C)
shall take reasonable steps to ensure that the practices of any person to whom the online service provider discloses or sells, or with whom the online service provider shares, individual identifying data fulfill the duties of care, loyalty, and confidentiality assumed by the person under the contract described in subparagraph (B), including by auditing, on a regular basis, the data security and data information practices of any such person.
(c)
Application of duties to third parties— If an online service provider transfers or otherwise provides access to individual identifying data to another person, the requirements of paragraphs (1), (2), and (3) of subsection (b) shall apply to such person with respect to such data in the same manner that such requirements apply to the online service provider.
(d)
Expansion of duty To inform regarding breaches— The Commission may promulgate regulations under section 553 of title 5, United States Code, to apply the breach notification requirement under subsection (b)(1)(B) with respect to specific categories of individual identifying data other than sensitive data, as the Commission determines necessary.
(e)
Exceptions—
(1)
Regulations— The Commission may promulgate regulations under section 553 of title 5, United States Code, to exempt categories of online service providers or persons described in subsection (c) from the requirement under subsection (a) or subsection (c) (as applicable).
(2)
Considerations— In promulgating regulations under paragraph (1), the Commission shall consider, among other factors—
(A)
the privacy risks posed by the use of individual identifying data by an online service provider or person described in subsection (c) based on—
(i)
the size of the provider or person;
(ii)
the complexity of the offerings of the provider;
(iii)
the nature and scope of the activities of the provider or person; and
(iv)
the sensitivity of the consumer information handled by the provider or person; and
(B)
the costs and benefits of applying the requirement under subsection (a) or subsection (c) (as applicable) to online service providers or persons with particular combinations of characteristics considered under subparagraph (A) of this paragraph.