(a)
In general— Not later than 1 year after the date of the enactment of this Act, the Attorney General, in consultation with the Secretary of Homeland Security, shall develop and issue guidance, which shall include best practices for State, Tribal, territorial, and local governments and public safety agencies regarding the establishment, operation, and oversight of voluntary swatting registries and related public safety protocols.
(b)
Consultation— In developing the guidance under subsection (a), the Attorney General shall consult with—
(1)
State, local, Tribal, and territorial law enforcement agencies and public safety answering points, including those serving large, mid-sized, and rural jurisdictions;
(2)
public safety, emergency communications, and 9–1–1 system experts with experience in call-taking, dispatch, computer-aided dispatch systems, and incident response protocols;
(3)
privacy, cybersecurity, data governance, and civil liberties experts with demonstrated technical expertise in the secure design, operation, oversight, and auditing of sensitive public safety databases;
(4)
disability access, language access, and victim services experts with demonstrated expertise in ensuring voluntary registry programs are accessible to individuals who may face elevated risks of swatting or targeting harassment;
(5)
technology providers and 9–1–1 system vendors with relevant expertise in secure database design, caller authentication, and call-handling protocols; and
(6)
individuals and households who have been victims of swatting incidents.
(c)
Guidance—
(1)
Contents— The guidance required under subsection (a) shall include, at a minimum, the following:
(A)
Program design and eligibility— The best practices for designing voluntary swatting registries that—
(i)
allow voluntary opt-in by residents;
(ii)
identify categories of higher-risk registrants, including individuals reasonably believed to face an elevated risk of swatting or targeting harassment;
(iii)
provide clear criteria and procedures for registration, renewal, and removal; and
(iv)
ensure equitable access for communities with limited English proficiency, persons with disabilities, and other underserved groups.
(B)
Data elements and data minimization— The best practices regarding the necessary data elements to be collected and stored, which may include—
(i)
the address and, where applicable, unit or apartment number;
(ii)
primary and secondary telephone numbers;
(iii)
additional contact methods such as email addresses or other secure, verifiable communication channels;
(iv)
optional verification mechanisms, such as pre-agreed code words or phrases, and contact information for multiple household members; and
(v)
associated time frames or conditions (such as expected periods of heightened risk), where applicable, while minimizing the collection and retention of personally identifiable information.
(C)
Incident response integration— The best practices for integrating registry information into call-taking and dispatch workflows, including—
(i)
automated dispatch flags or alerts when a call originates from, or concerns, a registered address;
(ii)
guidance for tactical response adjustments when verification suggests a likely hoax, including options for lower-escalation approaches such as staged responses, announcements, or requests for occupants to meet officers outside when safe to do so; and
(iii)
protocols for documentation and after-action review of incidents involving registered addresses.
(D)
Officer safety and training— Recommendations for training call-takers, dispatch personnel, and responding officers on—
(i)
the nature and risks of swatting;
(ii)
appropriate use of swatting registry information in assessing risk and selecting tactics; and
(iii)
avoiding overreliance on unverified registry data while using such data to reduce unnecessary risk.
(E)
Privacy, civil rights, and civil liberties protections— The best practices to—
(i)
ensure participation is voluntary and based on informed consent;
(ii)
restrict access to registry data to authorized personnel, with role-based access controls;
(iii)
require encryption of records at rest and in transit, and other appropriate cybersecurity safeguards;
(iv)
provide full audit logging of access and use;
(v)
prevent misuse of registry information for discriminatory or retaliatory purposes; and
(vi)
provide notice, redress, and complaint mechanisms for registrants and the public.
(F)
Data retention, accuracy, and governance— The best practices regarding—
(i)
reasonable limits on data retention;
(ii)
procedures for registrants to update or delete their information at any time;
(iii)
periodic review and renewal mechanisms, including annual prompts or other methods to ensure accuracy; and
(iv)
appropriate governance, including designation of responsible officers, policy review cycles, and community engagement.
(G)
Technology, interoperability, and funding considerations— Recommendations regarding—
(i)
technical approaches for integrating swatting registries with existing 9–1–1 and computer-aided dispatch systems;
(ii)
secure online portals or mechanisms for registration and updates;
(iii)
scalability for small and resource-constrained jurisdictions; and
(iv)
potential Federal resources, including existing grant programs, that may support implementation.
(H)
Metrics and evaluation— Recommended metrics and methodologies to evaluate—
(i)
impact on safety outcomes for residents, pets, and officers;
(ii)
impact on property damage, use-of-force incidents, and traumatic forced entries;
(iii)
impact on litigation exposure and settlement costs; and
(iv)
impact on operational efficiency and deterrence of swatting.
(I)
Use beyond swatting— Considerations for how registry information, if appropriately designed and consented to, may safely assist in other types of emergencies (such as medical crises or wellness checks), while maintaining clear limitations and safeguards to prevent overcollection or misuse.
(d)
Public availability— The Attorney General shall make the guidance issued under this subsection publicly available on the website of the Department of Justice, except for any material that would disclose information that is sensitive or classified.
(e)
Updates— The Attorney General may periodically update the guidance issued under this subsection as appropriate, including to reflect technological developments, emerging threats, and lessons learned from State, Tribal, territorial, and local implementation.