H.R. 1165 — what changed
Data Privacy Act of 2023
From Introduced in House to Reported in House. 7 sections amended between Introduced in House and Reported in House.
Sec. 2 Protection of nonpublic personal information
Section 501 of the Gramm-Leach-Bliley Act (15 U.S.C. 6801) is amended—
changed
“(c) Use of nonpublic personal information—It information—Unless otherwise permitted under section 502(e), it shall be unlawful for a financial institution to willfully use nonpublic personal information without the consent of an individual with whom the financial institution has a customer or consumer relationship.”
Sec. 3 Obligations with respect to the collection and disclosure of nonpublic personal information
“(1) In general—A financial institution may not collect nonpublic personal information from an individual with whom such financial institution has a customer or consumer relationship or disclose nonpublic personal information to a nonaffiliated third party unless the individual with whom such financial institution has a consumer or customer relationship is given the opportunity, before the time that such information is initially collected or disclosed, to direct that such information not be collected or disclosed to such third party.”
removed
“(e) Exceptions—The general collection and disclosure procedures provided in subsections (a) and (b) shall not prohibit or otherwise limit the collection or disclosure of nonpublic personal information—
“(1) if the collection or disclosure is—
“(A) necessary to effect, administer, or enforce a transaction requested or authorized by the individual with whom the financial institution has a customer or consumer relationship;
“(B) in connection with servicing or processing a financial product or service requested or authorized by the individual with whom the financial institution has a customer or consumer relationship;
“(C) with the consent or at the direction of the individual with whom the financial institution has a customer or consumer relationship, and the financial institution obtains, from such individual, evidence of such individual’s authorization for such collection or disclosure; or
“(D) in connection with—
added “(i) maintaining or servicing the account, with such financial institution or with another entity as part of a private label or co-brand credit card program or an extension of credit on behalf of such entity, of an individual with whom such financial institution or entity has a customer or consumer relationship; or
removed
“(i) maintaining or servicing the account, with such financial institution or with another entity as part of a private label or co-brand credit card program or an extension of credit on behalf of such entity, of an individual with whom such financial institution or entity has a customer or consumer relationship;
“(ii) a proposed or actual securitization, secondary market sale (including sales of servicing rights), or similar transaction related to an account or a transaction of the individual which whom such entity or financial institution has a customer or consumer relationship; or
“(2) to a nonaffiliated third party to perform services for, or functions on behalf of, the financial institution, including marketing of the financial institution's own products or services, or financial products or services offered pursuant to joint agreements between two or more financial institutions that comply with the requirements imposed by the regulations prescribed under section 504, if the financial institution fully discloses the providing of such information and enters into a contractual agreement with the third party that requires the third party to maintain the confidentiality of such information;”
“(f) Notification to nonaffiliates when sharing is terminated
“(1) In general—If a financial institution is required to terminate sharing nonpublic personal information, of an individual with whom such financial institution has a customer or consumer relationship, with a nonaffiliated third party—
“(A) the financial institution shall notify the nonaffiliated third party that the sharing has been terminated and that such nonaffiliated third party may not share any nonpublic information of the individual already received from the financial institution; and
“(B) upon receipt of a notice described under subparagraph (A), the nonaffiliated third party may not share any nonpublic information of such individual already received from the financial institution.
“(2) Rulemaking—The agencies referred to in section 504 shall issue rules to establish the requirements for notices under paragraph (1), including the form of such notices, taking into account any privacy risks posed by such notices.
changed
“(g) Requirements with respect to the collection of consumer account credentials—A financial institution may not collect from an individual with whom such financial institution has a customer or consumer relationship account credentials such individual uses to access an account at a nonaffiliated third party that is a financial institution unless, prior to collecting the consumer account credentials—
changed
“(1) the financial institution clearly and conspicuously discloses to the consumer, individual, in a form permitted by the regulations prescribed under section 504—
“(A) that the financial institution is collecting such account credentials;
“(B) how such credentials will be used by the financial institution; and
“(C) whether such credentials may be disclosed to a nonaffiliated third party; and
“(2) such individual is given an opportunity to direct that such credentials not be collected or to direct that such credentials not be disclosed to any nonaffiliated third party.”
Sec. 4 Disclosure of institution privacy policy
Section 503 of the Gramm-Leach-Bliley Act (15 U.S.C. 6803) is amended—
“(1) collecting nonpublic personal information;”
“(b) Disclosure upon request—Upon the request of an individual with whom a financial institution has a customer or consumer relationship, a financial institution shall provide such individual with a copy of the disclosures required by subsection (a) in writing or in electronic or other form as permitted by the regulations prescribed under section 504.”
added “(B) the purpose for which the financial institution collects the nonpublic personal information of individuals with whom the financial institution has a customer or consumer relationship, as well as how the information will be used;”
removed
“(B) the purpose for which the financial institution collects the nonpublic personal information of individuals with whom the financial institution has a customer or consumer relationship, as well as how the data will be used;”
“(5) if the financial institution collects nonpublic personal information for any purpose other than to provide a specific product or service such an individual is seeking—
“(A) a description of such information;
“(B) the purpose for which such information is collected; and
“(C) the right of such individual to opt out of having such nonpublic personal information collected or disclosed to a nonaffiliated third party, and the manner in which such individual may make such opt out election;
added “(6) the data retention policies of the financial institution, including—
added “(A) the period of time for which the financial institution retains the nonpublic personal information relating to such individual; or
added “(B) the criteria used by the financial institution to determine the period of time for which such information is retained;
removed
“(6) the data retention policies of the financial institution, including the period of time for which the institution retains the nonpublic personal information relating to such individual;
“(7) the right of such individual to direct the financial institution to terminate the sharing of nonpublic personal information with a nonaffiliated third party, and the manner in which such individual may make such direction;
“(8) the right of such individual to request that the financial institution provide the individual with a list of all nonpublic personal information relating to the individual held by the financial institution, and the manner in which the individual may make such request; and
“(9) the right of such individual to direct the financial institution to delete nonpublic personal information of the individual held by the financial institution (subject to the exceptions provided under section 502A(b)(3)), and the manner in which the individual may make such direction.”
Sec. 7 Obligations with respect to access and deletion of nonpublic personal information
added “502A. Obligations with respect to access and deletion of nonpublic personal information
added “(a) Access to information
added “(1) In general—Upon an authorized request from an individual with whom a financial institution has a customer or consumer relationship, a financial institution shall disclose—
added “(A) any nonpublic personal information relating to such individual held by the financial institution;
added “(B) the list of categories of nonaffiliated third parties with whom the financial institution shares nonpublic personal information relating to such individual; and
added “(C) the list of categories of nonaffiliated third parties from whom the financial institution has received nonpublic personal information relating to such individual.
added “(2) Format—Disclosures described under paragraph (1) shall be in a structured, commonly used, and machine-readable format.
added “(3) Exception—For purposes of subparagraphs (B) and (C) of paragraph (1), a financial institution is not required to disclose a nonaffiliated third party with whom the financial institution shares or receives nonpublic personal information relating to such individual pursuant to an exception described under any of paragraphs (3) through (8) of section 502(e).
added “(b) Deletion of information
added “(1) In general—Upon an authorized request from an individual with whom a financial institution has a customer or consumer relationship, a financial institution shall delete any nonpublic personal information relating to such individual held by the financial institution.
added “(2) Certain inactive accounts—If such individual has not used a product or service provided by a financial institution for 1 year, the financial institution shall—
added “(A) notify such individual that such individual has the right to request the deletion of any nonpublic personal information relating to such individual held by the financial institution, and provide such individual with clear instructions on how to make such request; and
added “(B) for each additional 1-year period with respect to which such person continues to not use a product or service of the financial institution, resend the notice described under subparagraph (A).
added “(3) Exception
added “(A) In general—This subsection shall not require a financial institution to delete nonpublic personal information if—
added “(i) the financial institution is otherwise required by law to retain the nonpublic personal information;
added “(ii) the nonpublic personal information may be necessary to respond to a dispute under the Fair Credit Reporting Act; or
added “(iii) the nonpublic personal information may be necessary to retain for a purpose described in an exception under section 502(e).
added “(B) Limitation on retained nonpublic personal information—With respect to nonpublic personal information that a financial institution would be required to delete under this subsection but for the application of this paragraph, the financial institution may only use such nonpublic personal information for the applicable purpose described under subparagraph (A).
added “(c) Timing—A financial institution that receives an authorized request, under this section, from an individual with whom such financial institution has a customer or consumer relationship, shall respond within 45 business days.
added “(d) Rulemaking—Not later than the end of the 1-year period beginning on the date of enactment of this section, each agency or authority described in section 504 shall issue rules to carry out this section with respect to the financial institutions subject to its jurisdiction.”
removed
Section 509 of the Gramm-Leach-Bliley Act (15 U.S.C. 6809) is amended—
removed
“(11) Customer or consumer relationship
removed
“(A) In general—The term “customer or consumer relationship” means a customer relationship or a consumer relationship.
removed
“(B) Customer relationship—The term “customer relationship” shall have the meaning given the term in rules issued pursuant to section 504.
removed
“(C) Consumer Relationship—The term “consumer relationship” shall have the meaning given the term in rules issued pursuant to section 504 and such meaning shall—
removed
“(i) include situations in which a financial institution obtains nonpublic information from an individual with whom the financial institution does not have a customer relationship; and
removed
“(ii) deem a financial institution to no longer to be in a consumer relationship with an individual at such time as the financial institution no longer collects, controls, possesses, transmits, or maintains any nonpublic personal information of such individual.
removed
“(D) Treatment of certain transactions—When the terms “customer relationship” and “consumer relationship”are defined by rule, it shall be specified that the following transactions do not, by themselves, establish a consumer relationship or a consumer relationship:
removed
“(i) The use of an automated teller machine.
removed
“(ii) The use of a credit card or debit card to make a purchase.
removed
“(iii) Such other similar transactions as the agencies determine appropriate.”
removed
“(12) Account credentials—The term “account credentials” means nonpublic information that an individual with whom a financial institution has a customer or consumer relationship uses to access an account of the individual at such financial institution, including a username, password, or an answer to a security question.
removed
“(13) Data aggregator—The term “data aggregator”—
removed
“(A) means any person that operates a commercial business or enterprise for the business purpose of accessing, aggregating, collecting, selling, or sharing nonpublic personal information about financial accounts or transactions, relating to an individual; and
removed
“(B) does not include—
removed
“(i) a service provider acting at the express instruction of a financial institution, that accesses, aggregates, collects, or shares nonpublic personal information about an individual with whom such financial institution has a customer or consumer relationship in accordance with paragraphs (1), (2), (3)(A), (3)(B), (3)(C), (3)(D), or (6) of section 502(2); or
removed
“(ii) an attorney or accountant acting on behalf of an individual with whom such attorney or accountant has a customer or consumer relationship, in accordance with section 502(e)(3)(E).
removed
“(14) Person engaged in providing insurance—The term “person engaged in providing insurance” means a person that engages in the “business of insurance”, as that term is defined in section 1002 of the Dodd-Frank Wall Street Reform and Consumer Protection Act (12 U.S.C. 5481).”
Sec. 8 Obligations with respect to the international sharing of nonpublic personal information
changed
“502A. “502B. Obligations with respect to access and deletion the international sharing of nonpublic personal information
changed
“(a) Access In general—A financial institution may not share with a foreign government nonpublic personal information relating to informationan individual with whom such financial institution has a customer or consumer relationship.
changed
“(1) In general—Upon an authorized request from “(b) Law enforcement exception—Subsection (a) shall not apply to the sharing of the nonpublic personal information relating to such an individual with whom a financial institution has a customer or consumer relationship, a financial institution shall disclose—foreign government authority if such sharing is—
changed
“(A) any nonpublic personal information relating to such individual held by the financial institution;“(1) done for legitimate law enforcement purposes; or
changed
“(B) the list of categories of nonaffiliated third parties with whom “(2) to a foreign government authority having jurisdiction over the financial institution shares nonpublic personal information relating to such individual; andfor examination, compliance, or other purposes as authorized by law.”
removed
“(C) the list of categories of nonaffiliated third parties from whom the financial institution has received nonpublic personal information relating to such individual.
removed
“(2) Format—Disclosures described under paragraph (1) shall be in a structured, commonly used, and machine-readable format.
removed
“(3) Exception—For purposes of subparagraphs (B) and (C) of paragraph (1), a financial institution is not required to disclose a nonaffiliated third party with whom the financial institution shares or receives nonpublic personal information relating to such individual pursuant to an exception described under any of paragraphs (3) through (8) of section 502(e).
removed
“(b) Deletion of information
removed
“(1) In general—Upon an authorized request from an individual with whom a financial institution has a customer or consumer relationship, a financial institution shall delete any nonpublic personal information relating to such individual held by the financial institution.
removed
“(2) Certain inactive accounts—If such individual has not used a product or service provided by a financial institution for 1 year, the financial institution shall—
removed
“(A) notify such individual that such individual has the right to request the deletion of any nonpublic personal information relating to such individual held by the financial institution, and provide such individual with clear instructions on how to make such request; and
removed
“(B) for each additional 1-year period with respect to which such person continues to not use a product or service of the financial institution, resend the notice described under subparagraph (A).
removed
“(3) Exception
removed
“(A) In general—This subsection shall not require a financial institution to delete nonpublic personal information if—
removed
“(i) the financial institution is otherwise required by law to retain the nonpublic personal information;
removed
“(ii) the nonpublic personal information may be necessary to respond to a dispute under the Fair Credit Reporting Act; or
removed
“(iii) the nonpublic personal information may be necessary to retain for a purpose described in an exception under section 502(e).
removed
“(B) Limitation on retained nonpublic personal information—With respect to nonpublic personal information that a financial institution would be required to delete under this subsection but for the application of this paragraph, the financial institution may only use such nonpublic personal information for the applicable purpose described under subparagraph (A).
removed
“(c) Timing—A financial institution that receives an authorized request, under this section, from an individual with whom such financial institution has a customer or consumer relationship, shall respond within 45 business days.
removed
“(d) Rulemaking—Not later than the end of the 1-year period beginning on the date of enactment of this section, each agency or authority described in section 504 shall issue rules to carry out this section with respect to the financial institutions subject to its jurisdiction.”
Sec. 9 Definitions
added Section 509 of the Gramm-Leach-Bliley Act (15 U.S.C. 6809) is amended—
removed
“502B. Obligations with respect to the international sharing of nonpublic personal information
removed
“(a) In general—A financial institution may not share with a foreign government nonpublic personal information relating to an individual with whom such financial institution has a customer or consumer relationship.
removed
“(b) Law enforcement exception—Subsection (a) shall not apply to the sharing of the nonpublic personal information relating to such an individual with a foreign government authority if such sharing is—
removed
“(1) done for legitimate law enforcement purposes; or
removed
“(2) to a foreign government authority having jurisdiction over the financial institution for examination, compliance, or other purposes as authorized by law.”
added “(11) Customer or consumer relationship
added “(A) In general—The term “customer or consumer relationship” means a customer relationship or a consumer relationship.
added “(B) Customer relationship—The term “customer relationship” shall have the meaning given the term in rules issued pursuant to section 504.
added “(C) Consumer Relationship—The term “consumer relationship” shall have the meaning given the term in rules issued pursuant to section 504 and such meaning shall—
added “(i) include situations in which a financial institution obtains nonpublic information from an individual with whom the financial institution does not have a customer relationship; and
added “(ii) deem a financial institution to no longer to be in a consumer relationship with an individual at such time as the financial institution no longer collects, controls, possesses, transmits, or maintains any nonpublic personal information of such individual.
added “(D) Treatment of certain transactions—When the terms “customer relationship” and “consumer relationship” are defined by rule, it shall be specified that the following transactions do not, by themselves, establish a consumer relationship or a consumer relationship:
added “(i) The use of an automated teller machine.
added “(ii) The use of a credit card or debit card to make a purchase.
added “(iii) Such other similar transactions as the agencies determine appropriate.”
added “(12) Account credentials—The term “account credentials” means nonpublic personal information that an individual with whom a financial institution has a customer or consumer relationship uses to access an account of the individual at such financial institution, including a username, password, or an answer to a security question.
added “(13) Data aggregator—The term “data aggregator”—
added “(A) means any person that operates a commercial business or enterprise for the business purpose of accessing, aggregating, collecting, selling, or sharing nonpublic personal information about financial accounts or transactions relating to an individual; and
added “(B) does not include—
added “(i) a service provider acting at the express instruction of a financial institution that accesses, aggregates, collects, or shares nonpublic personal information about an individual with whom such financial institution has a customer or consumer relationship in accordance with paragraphs (1), (2), (3)(A), (3)(B), (3)(C), (3)(D), or (6) of section 502(e); or
added “(ii) an attorney or accountant acting on behalf of an individual with whom such attorney or accountant has a customer or consumer relationship, in accordance with section 502(e)(3)(E).
added “(14) Person engaged in providing insurance—The term “person engaged in providing insurance” means a person that engages in the business of insurance, as that term is defined in section 1002 of the Dodd-Frank Wall Street Reform and Consumer Protection Act (12 U.S.C. 5481).”
Sec. 11 GAO report
removed
The Comptroller General of the United States shall, not later than 1 year after the date of the enactment of this Act, submit to the Congress a report that assesses—