US Codex
Bill
Notes

Title II — Data transparency, integrity, and security

S. 4626 · 116th Congress · Sep 17, 2020 · Lineage

II Data transparency, integrity, and security

Sec. 201 Algorithm bias, detection, and mitigation

(a)
FTC enforcement assistance—
(1)
In general— Whenever the Commission obtains information that a covered entity may have processed or transferred covered data in violation of Federal anti-discrimination laws, the Commission shall transmit such information (excluding any such information that is a trade secret as defined by section 1839 of title 18, United States Code) to the appropriate Executive agency or State agency with authority to initiate proceedings relating to such violation.
(2)
Annual report— Beginning in 2021, the Commission shall submit an annual report to Congress that includes—
(A)
a summary of the types of information the Commission transmitted to Executive agencies or State agencies during the preceding year pursuant to this subsection; and
(B)
a summary of how such information relates to Federal anti-discrimination laws.
(3)
Cooperation with other agencies— The Commission may implement this subsection by executing agreements or memoranda of understanding with the appropriate Executive agencies.
(4)
Relationship to other laws— Notwithstanding section 405, nothing in this subsection shall supersede any other provision of law.
(b)
Algorithm transparency reports—
(1)
Study and report—
(A)
Study— The Commission shall conduct a study, using the Commission's authority under section 6(b) of the Federal Trade Commission Act (15 U.S.C. 46(b)), examining the use of algorithms to process covered data in a manner that may violate Federal anti-discrimination laws.
(B)
Report— Not later than 3 years after the date of enactment of this Act, the Commission shall publish a report containing the results of the study required under subparagraph (A).
(C)
Guidance— The Commission shall use the results of the study described in paragraph (A) to develop guidance to assist covered entities in avoiding the discriminatory use of algorithms.
(2)
Updated report— Not later than 5 years after the publication of the report required under paragraph (1), the Commission shall publish an updated report.

Sec. 202 Digital content forgeries

(a)
Definition— Not later than 6 months after the date of enactment of this Act, the National Institute of Standards and Technology shall develop and publish a definition of digital content forgery and accompanying explanatory materials.
(b)
Elements of definition— In developing a definition of digital content forgery under subsection (a), the National Institute of Standards and Technology shall consider the following factors:
(1)
Whether the content is created with the intent to deceive an individual into believing the content was genuine.
(2)
Whether the content is genuine or manipulated.
(3)
The impression the content makes on a reasonable individual that observes the content.
(4)
Whether the production of the content was substantially dependent upon technical means, rather than the ability of another individual to physically or verbally impersonate such individual.
(5)
The scope of technologies that may be utilized during the creation or publication of digital content forgeries, including—
(A)
video recording or film;
(B)
sound recording;
(C)
electronic image or photograph; or
(D)
any digital representation of speech or conduct.
(c)
Scope of definition— The definition published by the National Institute of Standards and Technology under subsection (a) shall not supersede any other provision of law or be construed to limit the authority of any Executive agency related to digital content forgeries.
(d)
Commission reports—
(1)
Initial report— Not later than 1 year after the National Institute of Standards and Technology publishes the definition and materials required under subsection (a), the Commission shall publish a report regarding the impact of digital content forgeries on individuals and competition.
(2)
Subsequent reports— Not later than 2 years after the publication of the report required under paragraph (1), and as often as the Commission shall deem necessary thereafter, the Commission shall publish an updated version of such report.
(3)
Content of reports— Each report required under this subsection shall include—
(A)
a description of the types of digital content forgeries, including those used to commit fraud, cause adverse consequences, violate any provision of law enforced by the Commission, or violate civil rights recognized under Federal law;
(B)
a description of the common sources in the United States of digital content forgeries and commercial sources of digital content forgery technologies;
(C)
an assessment of the uses, applications, and adverse consequences of digital content forgeries, including the impact of digital content forgeries on individuals, digital identity, and competition;
(D)
an analysis of the methods available to individuals to identify digital content forgeries as well as a description of commercial technological countermeasures that are, or could be, used to address concerns with digital content forgeries, which may include countermeasures that warn individuals of suspect content;
(E)
a description of any remedies available to protect an individual’s identity and reputation from adverse consequences caused by digital content forgeries, such as protections or remedies available under the Federal Trade Commission Act (15 U.S.C. 41 et seq.) or any other law; and
(F)
any additional information the Commission determines appropriate.
(e)
Establishment of digital content forgery prize competition— Not later than 1 year after the date of enactment of this Act, the Director of the National Institute of Standards and Technology, in coordination with the Commission, shall establish under section 24 of the Stevenson-Wydler Technology Innovation Act of 1980 (15 U.S.C. 3719) a prize competition to spur the development of technical solutions to assist individuals and the public in identifying digital content forgeries and related technologies.

Sec. 203 Data brokers

(a)
In general— Not later than January 31 of each calendar year that follows a calendar year during which a covered entity acted as a data broker, such covered entity shall register with the Commission pursuant to the requirements of this section.
(b)
Registration requirements— In registering with the Commission as required under subsection (a), a data broker shall do the following:
(1)
Pay to the Commission a registration fee of $100.
(2)
Provide the Commission with the following information:
(A)
The name and primary physical, email, and internet addresses of the data broker.
(B)
Any additional information or explanation the data broker chooses to provide concerning its data collection and processing practices.
(c)
Penalties— A data broker that fails to register as required under subsection (a) shall be liable for—
(1)
a civil penalty of $50 for each day it fails to register, not to exceed a total of $10,000 for each year; and
(2)
an amount equal to the fees due under this section for each year that it failed to register as required under subsection (a).
(d)
Publication of registration information— The Commission shall publish on the internet website of the Commission the registration information provided by data brokers under this section.

Sec. 204 Protection of covered data

(a)
In general— A covered entity shall establish, implement, and maintain reasonable administrative, technical, and physical data security policies and practices to protect against risks to the confidentiality, security, and integrity of covered data.
(b)
Data security requirements— The data security policies and practices required under subsection (a) shall be—
(1)
appropriate to the size and complexity of the covered entity, the nature and scope of the covered entity’s collection or processing of covered data, the volume and nature of the covered data at issue, and the cost of available tools to improve security and reduce vulnerabilities; and
(2)
designed to—
(A)
identify and assess vulnerabilities to covered data;
(B)
take reasonable preventative and corrective action to address known vulnerabilities to covered data; and
(C)
detect, respond to, and recover from cybersecurity incidents related to covered data.
(c)
Rulemaking and guidance—
(1)
Rulemaking authority and scope—
(A)
In general— The Commission may, pursuant to a proceeding in accordance with section 553 of title 5, United States Code, issue regulations to identify processes for receiving and assessing information regarding vul­ner­a­bil­i­ties to covered data that are reported to the covered entity.
(B)
Consultation with NIST— In promulgating regulations under this paragraph, the Commission shall consult with, and take into consideration guidance from, the National Institute for Standards and Technology
(2)
Guidance— Not later than 1 year after the date of enactment of this Act, the Commission shall issue guidance to covered entities on how to—
(A)
identify and assess vulnerabilities to covered data, including—
(i)
the potential for unauthorized access to covered data;
(ii)
vulnerabilities in the covered entity’s collection or processing of covered data;
(iii)
the management of access rights; and
(iv)
the use of service providers to process covered data;
(B)
take reasonable preventative and corrective action to address vulnerabilities to covered data; and
(C)
detect, respond to, and recover from cybersecurity incidents and events.
(d)
Applicability of other information security laws— A covered entity that is required to comply with title V of the Gramm-Leach-Bliley Act (15 U.S.C. 6801 et seq.) or the Health Information Technology for Economic and Clinical Health Act (42 U.S.C. 17931 et seq.), and is in compliance with the information security requirements of such Act, shall be deemed to be in compliance with the requirements of this section with respect to covered data that is subject to the requirements of such Act.

Sec. 205 Filter bubble transparency

(a)
In general— Beginning on the date that is 1 year after the date of enactment of this Act, it shall be unlawful—
(1)
for any person to operate a covered internet platform that uses an opaque algorithm unless the person complies with the requirements of subsection (b); or
(2)
for any upstream provider to grant access to an index of web pages on the internet under a search syndication contract that does not comply with the requirements of subsection (c).
(b)
Opaque algorithm requirements—
(1)
In general— The requirements of this subsection with respect to a person that operates a covered internet platform that uses an opaque algorithm are the following:
(A)
The person provides notice to users of the platform that the platform uses an opaque algorithm that makes inferences based on user-specific data to select the content the user sees. Such notice shall be presented in a clear, conspicuous manner on the platform whenever the user interacts with an opaque algorithm for the first time, and may be a one-time notice that can be dismissed by the user.
(B)
The person makes available a version of the platform that uses an input-transparent algorithm and enables users to easily switch between the version of the platform that uses an opaque algorithm and the version of the platform that uses the input-transparent algorithm by selecting a prominently placed icon, which shall be displayed wherever the user interacts with an opaque algorithm.
(2)
Nonapplication to certain downstream providers— Paragraph (1) shall not apply with respect to an internet search engine if—
(A)
the search engine is operated by a downstream provider with fewer than 1,000 employees; and
(B)
the search engine uses an index of web pages on the internet to which such provider received access under a search syndication contract.
(c)
Search syndication contract requirement— The requirements of this subsection with respect to a search syndication contract are that—
(1)
as part of the contract, the upstream provider makes available to the downstream provider the same input-transparent algorithm used by the upstream provider for purposes of complying with subsection (b)(1)(B); and
(2)
the upstream provider does not impose any additional costs, degraded quality, reduced speed, or other constraint on the functioning of such algorithm when used by the downstream provider to operate an internet search engine relative to the performance of such algorithm when used by the upstream provider to operate an internet search engine.

Sec. 206 Unfair and deceptive acts and practices relating to the manipulation of user interfaces

(a)
Conduct prohibited—
(1)
In general— It shall be unlawful for any large online operator—
(A)
to design, modify, or manipulate a user interface with the purpose or substantial effect of obscuring, subverting, or impairing user autonomy, decision making, or choice to obtain consent or user data;
(B)
to subdivide or segment consumers of online services into groups for the purposes of behavioral or psychological experiments or studies, except with the informed consent of each user involved; or
(C)
to design, modify, or manipulate a user interface on a website or online service, or portion thereof, that is directed to an individual under the age of 13, with the purpose or substantial effect of cultivating compulsive usage, including video auto-play functions initiated without the consent of a user.
(b)
Duties of large online operators— Any large online operator that engages in any form of behavioral or psychological research based on the activity or data of its users shall—
(1)
disclose to its users on a routine basis, but not less than once each 90 days, any experiments or studies that a user was subjected to or enrolled in with the purpose of promoting engagement or product conversion;
(2)
disclose to the public on a routine basis, but not less than once each 90 days, any experiments or studies with the purposes of promoting engagement or product conversion being currently undertaken, or concluded since the prior disclosure;
(3)
shall present the disclosures in paragraphs (1) and (2) in a manner that—
(A)
is clear, conspicuous, context appropriate, and easily accessible; and
(B)
is not deceptively obscured;
(4)
establish an Independent Review Board for any behavioral or psychological research, of any purpose, conducted on users or on the basis of user activity or data, which shall review and have authority to approve, require modification in, or disapprove all behavioral or psychological experiments or research; and
(5)
ensure that any Independent Review Board established under paragraph (4) shall register with the Commission, including providing to the Commission—
(A)
the names and resumes of every board member;
(B)
the composition and reporting structure of the Board to the management of the operator;
(C)
the process by which the Board is to be notified of proposed studies or modifications along with the processes by which the Board is capable of vetoing or amending such proposals;
(D)
any compensation provided to board members; and
(E)
any conflict of interest that might exist concerning a board member's participation in the Board.
(c)
Registered professional standards body—
(1)
In general— An association of large online operators may register as a professional standards body by filing with the Commission an application for registration in such form as the Commission, by rule, may prescribe containing the rules of the association and such other information and documents as the Commission, by rule, may prescribe as necessary or appropriate in the public interest or for protecting the welfare of users of large online operators.
(2)
Professional standards body— An association of large online operators may not register as a professional standards body unless the Commission determines that—
(A)
the association is so organized and has the capacity to enforce compliance by its members and persons associated with its members, with the provisions of this Act;
(B)
the rules of the association provide that any large online operator may become a member of such association;
(C)
the rules of the association ensure a fair representation of its members in the selection of its directors and administration of its affairs and provide that one or more directors shall be representative of users and not be associated with, or receive any direct or indirect funding from, a member of the association or any large online operator;
(D)
the rules of the association are designed to prevent exploitative and manipulative acts or practices, to promote transparent and fair principles of technology development and design, to promote research in keeping with best practices of study design and informed consent, and to continually evaluate industry practices and issue binding guidance consistent with the objectives of this Act;
(E)
the rules of the association provide that its members and persons associated with its members shall be appropriately disciplined for violation of any provision of this Act, the rules or regulations thereunder, or the rules of the association, by expulsion, suspension, limitation of activities, functions, fine, censure, being suspended or barred from being associated with a member, or any other appropriate sanction; and
(F)
the rules of the association are in accordance with the provisions of this Act, and, in general, provide a fair procedure for the disciplining of members and persons associated with members, the denial of membership to any person seeking membership therein, the barring of any person from becoming associated with a member thereof, and the prohibition or limitation by the association of any person with respect to access to services offered by the association or a member thereof.
(3)
Responsibilities and activities—
(A)
Bright-line rules— An association shall develop, on a continuing basis, guidance and bright-line rules for the development and design of technology products of large online operators consistent with subparagraph (B).
(B)
Safe harbors— In formulating guidance under subparagraph (A), the association shall define conduct that does not have the purpose or substantial effect of subverting or impairing user autonomy, decision making, or choice, or of cultivating compulsive usage for children such as—
(i)
de minimis user interface changes derived from testing consumer preferences, including different styles, layouts, or text, where such changes are not done with the purpose of obtaining user consent or user data;
(ii)
algorithms or data outputs outside the control of a large online operator or its affiliates; and
(iii)
establishing default settings that provide enhanced privacy protection to users or otherwise enhance their autonomy and decision-making ability.
(d)
Enforcement by the Commission—
(1)
Unfair or deceptive acts or practice— A violation of subsection (a) or (b) shall be treated as a violation of a rule defining an unfair or deceptive act or practice under section 18(a)(1)(B) of the Federal Trade Commission Act (15 U.S.C. 57a(a)(1)(B)).
(2)
Determination— For purposes of enforcement of this Act, the Commission shall determine an act or practice is unfair or deceptive if the act or practice—
(A)
has the purpose, or substantial effect, of subverting or impairing user autonomy, decision making, or choice to obtain consent or user data; or
(B)
has the purpose, or substantial effect, of cultivating compulsive usage by a child under 13.
(3)
Regulations— Not later than 1 year after the date of enactment of this Act, the Commission shall promulgate regulations under section 553 of title 5, United States Code, that—
(A)
establish rules and procedures for obtaining the informed consent of users;
(B)
establish rules for the registration, formation, oversight, and management of the independent review boards, including standards that ensure effective independence of such entities from improper or undue influence by a large online operator;
(C)
establish rules for the registration, formation, oversight, and management of professional standards bodies, including procedures for the regular oversight of such bodies and revocation of their designation; and
(D)
in consultation with a professional standards body established under subsection (c), define conduct that does not have the purpose or substantial effect of subverting or impairing user autonomy, decision making, or choice, or of cultivating compulsive usage for children such as—
(i)
de minimis user interface changes derived from testing consumer preferences, including different styles, layouts, or text, where such changes are not done with the purpose of obtaining user consent or user data;
(ii)
algorithms or data outputs outside the control of a large online operator or its affiliates; and
(iii)
establishing default settings that provide enhanced privacy protection to users or otherwise enhance their autonomy and decision-making ability.
(4)
Safe harbor— The Commission may not bring an enforcement action under this section against any large online operator that relied in good faith on the guidance of a professional standards body.