US Codex
Bill
Notes

Title II — Oversight and responsibility

S. 2968 · 116th Congress · Dec 3, 2019 · Lineage

II Oversight and responsibility

Sec. 201 Executive responsibility

(a)
In general— Beginning 1 year after the date of enactment of this Act, the chief executive officer of a covered entity that is a large data holder (or, if the entity does not have a chief executive officer, the highest ranking officer of the entity) and each privacy officer and data security officer of such entity shall annually certify to the Commission, in a manner specified by the Commission, that the entity maintains—
(1)
adequate internal controls to comply with this Act; and
(2)
reporting structures to ensure that such certifying officers are involved in, and are responsible for, decisions that impact the entity’s compliance with this Act.
(b)
Requirements— A certification submitted under subsection (a) shall be based on a review of the effectiveness of a covered entity’s internal controls and reporting structures that is conducted by the certifying officers no more than 90 days before the submission of the certification.

Sec. 202 Privacy and data security officers; comprehensive privacy and data security programs; risk assessments and compliance

(a)
Privacy and data security officer— A covered entity shall designate—
(1)
1 or more qualified employees as privacy officers; and
(2)
1 or more qualified employees (in addition to any employee designated under paragraph (1)) as data security officers.
(b)
Comprehensive privacy and data security programs, risk assessments, and compliance— An employee who is designated by a covered entity as a privacy officer or a data security officer shall be responsible for, at a minimum—
(1)
implementing a comprehensive written data privacy program and data security program to safeguard the privacy and security of covered data throughout the life cycle of development and operational practices of the covered entity’s products or services;
(2)
annually conducting privacy and data security risk assessments, data hygiene, and other quality control practices; and
(3)
facilitating the covered entity’s ongoing compliance with this Act.

Sec. 203 Service providers and third parties

(a)
Service providers— A service provider—
(1)
shall not process service provider data for any processing purpose other than one performed on behalf of, and at the direction of, the covered entity that transferred such data to the service provider, except that a service provider may process data to comply with a legal obligation or the establishment, exercise, or defense of legal claims;
(2)
shall not transfer service provider data to a third party without the affirmative express consent, obtained by, or on behalf of, the covered entity, of the individual to whom the service provider data is linked or reasonably linkable;
(3)
shall delete or de-identify service provider data after the agreed upon end of the provision of services;
(4)
is exempt from the requirements of sections 102(a), 103, 104, and 105(a) with respect to service provider data, but shall, to the extent practicable—
(A)
assist the covered entity from which it received the service provider data in fulfilling requests made by individuals under such sections; and
(B)
shall delete, de-identify, or correct (as applicable), any service provider data that is subject to a verified request from an individual described in section 103 or 104; and
(5)
is exempt from the requirements of section 106 with respect to service provider data, but shall have the same responsibilities and obligations as a covered entity with respect to such data under all other provisions of this Act.
(b)
Third parties— A third party—
(1)
shall not process third party data for a purpose that is inconsistent with the expectations of a reasonable individual;
(2)
may reasonably rely on representations made by the covered entity that transferred third party data regarding the expectation of a reasonable individual, provided the third party conducts reasonable due diligence on the representations of the covered entity and finds those representations to be credible; and
(3)
upon receipt of any third party data, is exempt from the requirements of section 105(c) with respect to such data, but shall have the same responsibilities and obligations as a covered entity with respect to such data under all other provisions of this Act.
(c)
Additional obligations on covered entities—
(1)
In general— A covered entity shall—
(A)
exercise reasonable due diligence in selecting a service provider and conduct reasonable oversight of its service providers to ensure compliance with the applicable requirements of this section; and
(B)
exercise reasonable due diligence in deciding to transfer covered data to a third party, and conduct oversight of third parties to which it transfers data to ensure compliance with the applicable requirements of this subsection.
(2)
Guidance— Not later than 1 year after the date of enactment of this Act, the Commission shall issue guidance for covered entities regarding compliance with this subsection.
(d)
In general— The Commission shall have authority under section 553 of title 5, United States Code, to promulgate regulations necessary to carry out the provisions of this section.

Sec. 204 Whistleblower protections

(a)
In general— A covered entity shall not, directly or indirectly, discharge, demote, suspend, threaten, harass, or in any other manner discriminate against a covered individual of the covered entity because—
(1)
the covered individual, or anyone perceived as assisting the covered individual, takes (or the covered entity suspects that the covered individual has taken or will take) a lawful action in providing to the Federal Government or the attorney general of a State information relating to any act or omission that the covered individual reasonably believes to be a violation of this Act or any regulation promulgated under this Act;
(2)
the covered individual provides information that the covered individual reasonably believes evidences such a violation to—
(A)
a person with supervisory authority over the covered individual at the covered entity; or
(B)
another individual working for the covered entity who the covered individual reasonably believes has the authority to investigate, discover, or terminate the violation or to take any other action to address the violation;
(3)
the covered individual testifies (or the covered entity expects that the covered individual will testify) in an investigation or judicial or administrative proceeding concerning such a violation; or
(4)
the covered individual assists or participates (or the covered entity expects that the covered individual will assist or participate) in such an investigation or judicial or administrative proceeding, or the covered individual takes any other action to assist in carrying out the purposes of this Act.
(b)
Enforcement— An individual who alleges discharge or other discrimination in violation of subsection (a) may bring an action governed by the rules, procedures, statute of limitations, and legal burdens of proof in section 42121(b) of title 49, United States Code. If the individual has not received a decision within 180 days and there is no showing that such delay is due to the bad faith of the claimant, the individual may bring an action for a jury trial, governed by the burden of proof in section 42121(b) of title 49, United States Code, in the appropriate district court of the United States for the following relief:
(1)
Temporary relief while the case is pending.
(2)
Reinstatement with the same seniority status that the individual would have had, but for the discharge or discrimination.
(3)
Three times the amount of back pay otherwise owed to the individual, with interest.
(4)
Consequential and compensatory damages, and compensation for litigation costs, expert witness fees, and reasonable attorneys’ fees.
(c)
Waiver of rights and remedies— The rights and remedies provided for in this section shall not be waived by any policy form or condition of employment, including by a predispute arbitration agreement.
(d)
Predispute arbitration agreements— No predispute arbitration agreement shall be valid or enforceable if the agreement requires arbitration of a dispute arising under this section.
(e)
Covered Individual defined— In this section, the term covered individual means an applicant, current or former employee, contractor, subcontractor, grantee, or agent of an employer.

Sec. 205 Digital content forgeries

(a)
Reports— Not later than 1 year after the date of enactment of this Act, and annually thereafter, the Director of the National Institute of Standards and Technology shall publish a report regarding digital content forgeries.
(b)
Requirements— Each report under subsection (a) shall include the following:
(1)
A definition of digital content forgeries along with accompanying explanatory materials. The definition developed pursuant to this section shall not supersede any other provision of law or be construed to limit the authority of any executive agency related to digital content forgeries.
(2)
A description of the common sources in the United States of digital content forgeries and commercial sources of digital content forgery technologies.
(3)
An assessment of the uses, applications, and harms of digital content forgeries.
(4)
An analysis of the methods and standards available to identify digital content forgeries as well as a description of the commercial technological counter-measures that are, or could be, used to address concerns with digital content forgeries, which may include the provision of warnings to viewers of suspect content.
(5)
A description of the types of digital content forgeries, including those used to commit fraud, cause harm or violate any provision of law.
(6)
Any other information determined appropriate by the Director.