US Codex
Bill
Notes

S. 3455 — what changed

No TikTok on Government Devices Act

From Reported in Senate to Engrossed in Senate. 1 section amended between Reported in Senate and Engrossed in Senate.

Sec. 2 Prohibition on the use of TikTok

(a)
changed In general—Definitions— Except as provided in subsection (b), no employee of the United States, officer of the United States, Member of Congress, congressional employee, or officer or employee of a government corporation may download or use TikTok or any successor application developed by ByteDance or any entity owned by ByteDance on any device issued by the United States or a government corporation.In this section—
(1)
added the term “covered application” means the social networking service TikTok or any successor application or service developed or provided by ByteDance Limited or an entity owned by ByteDance Limited;
(2)
added the term executive agency has the meaning given that term in section 133 of title 41, United States Code; and
(3)
added the term “information technology” has the meaning given that term in section 11101 of title 40, United States Code.
(b)
added Prohibition on the use of TikTok—
(1)
added In general— Not later than 60 days after the date of the enactment of this Act, the Director of the Office of Management and Budget, in consultation with the Administrator of General Services, the Director of the Cybersecurity and Infrastructure Security Agency, the Director of National Intelligence, and the Secretary of Defense, and consistent with the information security requirements under subchapter II of chapter 35 of title 44, United States Code, shall develop standards and guidelines for executive agencies requiring the removal of any covered application from information technology.
(2)
added National security and research exceptions— The standards and guidelines developed under paragraph (1) shall include—
(A)
added exceptions for law enforcement activities, national security interests and activities, and security researchers; and
(B)
added for any authorized use of a covered application under an exception, requirements for agencies to develop and document risk mitigation actions for such use.
(b)
removed Exception— Subsection (a) shall not apply to any investigation, cybersecurity research activity, enforcement action, disciplinary action, or intelligence activity.