Plain English summary not yet available
The full original text is available below. Check back soon as we process this bill.
I
116TH CONGRESS
1ST SESSION H. R. 1282
To require certain entities who collect and maintain personal information
of individuals to secure such information and to provide notice to such
individuals in the case of a breach of security involving such information,
and for other purposes.
IN THE HOUSE OF REPRESENTATIVES
FEBRUARY 14, 2019
Mr. RUSH (for himself, Ms. BLUNT ROCHESTER, and Ms. CLARKE of New
York) introduced the following bill; which was referred to the Committee
on Energy and Commerce
A BILL
To require certain entities who collect and maintain personal
information of individuals to secure such information
and to provide notice to such individuals in the case
of a breach of security involving such information, and
for other purposes.
Be it enacted by the Senate and House of Representa-
1
tives of the United States of America in Congress assembled,
2
SECTION 1. SHORT TITLE.
3
This Act may be cited as the ‘‘Data Accountability
4
and Trust Act’’.
5
VerDate Sep 11 2014
21:35 Mar 01, 2019
Jkt 089200
PO 00000
Frm 00001
Fmt 6652
Sfmt 6201
E:\BILLS\H1282.IH
H1282
pamtmann on DSKBFK8HB2PROD with BILLS
2
•HR 1282 IH
SEC. 2. REQUIREMENTS FOR INFORMATION SECURITY.
1
(a) GENERAL SECURITY POLICIES
AND PROCE-
2
DURES.—
3
(1) REGULATIONS.—Not later than 1 year after
4
the date of enactment of this Act, the Commission
5
shall promulgate regulations under section 553 of
6
title 5, United States Code, that require each cov-
7
ered entity to establish and implement policies and
8
procedures regarding information security practices
9
for the treatment and protection of personal infor-
10
mation taking into consideration—
11
(A) the size of and the nature, scope, and
12
complexity of the activities engaged in by such
13
covered entity;
14
(B) the sensitivity of any personal informa-
15
tion at issue;
16
(C) the current state of the art in adminis-
17
trative, technical, and physical safeguards for
18
protecting such information; and
19
(D) the cost of implementing such safe-
20
guards.
21
(2) REQUIREMENTS.—The regulations required
22
pursuant to paragraph (1) shall include a require-
23
ment that the policies and procedures include the
24
following:
25
VerDate Sep 11 2014
21:35 Mar 01, 2019
Jkt 089200
PO 00000
Frm 00002
Fmt 6652
Sfmt 6201
E:\BILLS\H1282.IH
H1282
pamtmann on DSKBFK8HB2PROD with BILLS
3
•HR 1282 IH
(A) A written security policy with respect
1
to the collection, use, sale, other dissemination,
2
and maintenance of the personal information.
3
(B) The identification of an officer or
4
other individual as the point of contact with re-
5
sponsibility for the management of information
6
security.
7
(C) A process for identifying and assessing
8
any reasonably foreseeable vulnerability in any
9
system maintained by the covered entity that
10
contains such data, including regular moni-
11
toring for a breach of security of any such sys-
12
tem.
13
(D) A process for—
14
(i) taking preventive and corrective
15
action to mitigate against any vulnerability
16
identified in the process required by sub-
17
paragraph (C), which may include imple-
18
menting any changes to security practices
19
and the architecture, installation, or imple-
20
mentation of network or operating soft-
21
ware; and
22
(ii) regularly testing or otherwise
23
monitoring the effectiveness of the key con-
24
VerDate Sep 11 2014
21:35 Mar 01, 2019
Jkt 089200
PO 00000
Frm 00003
Fmt 6652
Sfmt 6201
E:\BILLS\H1282.IH
H1282
pamtmann on DSKBFK8HB2PROD with BILLS
4
•HR 1282 IH
trols, systems, and procedures of the safe-
1
guards.
2
(E) A process for disposing of data con-
3
taining personal information by shredding, per-
4
manently erasing, or otherwise modifying the
5
personal information contained in such data to
6
make such personal information permanently
7
unreadable or undecipherable.
8
(F) A process for overseeing persons to
9
whom personal information is disclosed, or who
10
have access to internet-connected devices, by—
11
(i) taking reasonable steps to select
12
and retain persons that are capable of
13
maintaining appropriate safeguards for the
14
personal information or internet-connected
15
devices at issue; and
16
(ii) requiring all such persons to im-
17
plement and maintain such safeguards.
18
(3) TREATMENT OF ENTITIES GOVERNED BY
19
OTHER FEDERAL LAW.—Any covered entity who is
20
in compliance with any other Federal law that re-
21
quires the covered entity to maintain standards and
22
safeguards for information security and protection of
23
personal information that, taken as a whole and as
24
the Commission shall determine in the rulemaking
25
VerDate Sep 11 2014
21:35 Mar 01, 2019
Jkt 089200
PO 00000
Frm 00004
Fmt 6652
Sfmt 6201
E:\BILLS\H1282.IH
H1282
pamtmann on DSKBFK8HB2PROD with BILLS
5
•HR 1282 IH
required under this subsection, provide protections
1
substantially similar to, or greater than, those re-
2
quired under this subsection, shall be deemed to be
3
in compliance with this subsection.
4
(b) SPECIAL REQUIREMENTS
FOR INFORMATION
5
BROKERS.—
6
(1) SUBMISSION OF POLICIES TO THE FTC.—
7
The regulations promulgated pursuant to subsection
8
(a) shall include a requirement for an information
9
broker to submit each security policy of the broker
10
to the Commission in conjunction with a notification
11
of a breach of security under section 3 or upon re-
12
quest of the Commission.
13
(2) POST-BREACH AUDIT.—For any information
14
broker required to provide notification under section
15
3, the Commission may conduct audits of the infor-
16
mation security practices of such information broker,
17
or require the information broker to conduct inde-
18
pendent audits of such practices (by an independent
19
auditor who has not audited the information bro-
20
ker’s security practices during the preceding 5
21
years).
22
(3) ACCURACY OF AND INDIVIDUAL ACCESS TO
23
PERSONAL INFORMATION.—The regulations promul-
24
VerDate Sep 11 2014
21:35 Mar 01, 2019
Jkt 089200
PO 00000
Frm 00005
Fmt 6652
Sfmt 6201
E:\BILLS\H1282.IH
H1282
pamtmann on DSKBFK8HB2PROD with BILLS
6
•HR 1282 IH
gated pursuant to subsection (a) shall include a re-
1
quirement for the following:
2
(A) ACCURACY.—
3
(i) IN
GENERAL.—Each information
4
broker to establish reasonable procedures
5
to assure the maximum possible accuracy
6
of the personal information the informa-
7
tion broker collects, assembles, or main-
8
tains, and any other information the infor-
9
mation broker collects, assembles, or main-
10
tains that specifically identifies an indi-
11
vidual, other than information which mere-
12
ly identifies an individual’s name or ad-
13
dress.
14
(ii) LIMITED EXCEPTION FOR FRAUD
15
DATABASES.—The requirement in clause
16
(i) shall not prevent the collection or main-
17
tenance of information that may be inac-
18
curate with respect to a particular indi-
19
vidual when that information is being col-
20
lected or maintained solely—
21
(I) for the purpose of indicating
22
whether there may be a discrepancy
23
or irregularity in the personal infor-
24
VerDate Sep 11 2014
21:35 Mar 01, 2019
Jkt 089200
PO 00000
Frm 00006
Fmt 6652
Sfmt 6201
E:\BILLS\H1282.IH
H1282
pamtmann on DSKBFK8HB2PROD with BILLS
7
•HR 1282 IH
mation that is associated with an indi-
1
vidual; and
2
(II) to help identify, or authen-
3
ticate the identity of, an individual, or
4
to protect against or investigate fraud
5
or other unlawful conduct.
6
(B) CONSUMER
ACCESS
TO
INFORMA-
7
TION.—Each information broker to—
8
(i) provide to each individual whose
9
personal
information
the
information
10
broker maintains (at the individual’s re-
11
quest at least once per year, at no cost to
12
the individual, and after verifying the iden-
13
tity of the individual), a means for the in-
14
dividual to review any personal information
15
regarding such individual maintained by
16
the information broker and any other in-
17
formation maintained by the information
18
broker that specifically identifies the indi-
19
vidual, other than information which mere-
20
ly identifies an individual’s name or ad-
21
dress; and
22
(ii) place a conspicuous notice on the
23
internet website of the information broker
24
(if the information broker maintains such
25
VerDate Sep 11 2014
21:35 Mar 01, 2019
Jkt 089200
PO 00000
Frm 00007
Fmt 6652
Sfmt 6201
E:\BILLS\H1282.IH
H1282
pamtmann on DSKBFK8HB2PROD with BILLS
8
•HR 1282 IH
a website) instructing individuals how to
1
request access to the information required
2
to be provided under clause (i), and, as ap-
3
plicable, how to express a preference with
4
respect to the use of personal information
5
for marketing purposes.
6
(C) DISPUTED INFORMATION.—
7
(i) IN GENERAL.—Whenever an indi-
8
vidual whose information the information
9
broker maintains makes a written request
10
disputing the accuracy of the information,
11
the information broker, after verifying the
12
identity of the individual making such re-
13
quest and unless there are reasonable
14
grounds to believe such request is frivolous
15
or irrelevant, to—
16
(I) correct any inaccuracy; or
17
(II) in the case of information
18
that is—
19
(aa) public record informa-
20
tion, inform the individual of the
21
source of the information, and, if
22
reasonably available, where a re-
23
quest for correction may be di-
24
rected and, if the individual pro-
25
VerDate Sep 11 2014
21:35 Mar 01, 2019
Jkt 089200
PO 00000
Frm 00008
Fmt 6652
Sfmt 6201
E:\BILLS\H1282.IH
H1282
pamtmann on DSKBFK8HB2PROD with BILLS
9
•HR 1282 IH
vides proof that the public record
1
has been corrected or that the in-
2
formation broker was reporting
3
the information incorrectly, cor-
4
rect the inaccuracy in the infor-
5
mation broker’s records; or
6
(bb) nonpublic information,
7
note the information that is dis-
8
puted, including the individual’s
9
statement disputing such infor-
10
mation,
and
take
reasonable
11
steps to independently verify such
12
information under the procedures
13
outlined in subparagraph (A) if
14
such information can be inde-
15
pendently verified.
16
(ii) STRUCTURE FOR DISPUTE PROC-
17
ESS.—A basic structure for the dispute
18
process described in clause (i) which shall
19
be in writing, require an online option for
20
the submission of a dispute, and provide
21
an electronic receipt acknowledging the
22
submission.
23
(D) LIMITATIONS.—A provision, including
24
the scope of the application, that allows an in-
25
VerDate Sep 11 2014
21:35 Mar 01, 2019
Jkt 089200
PO 00000
Frm 00009
Fmt 6652
Sfmt 6201
E:\BILLS\H1282.IH
H1282
pamtmann on DSKBFK8HB2PROD with BILLS
10
•HR 1282 IH
formation broker to limit the access to informa-
1
tion required under subparagraph (B)(i) and is
2
not required to provide notice to individuals as
3
required under subparagraph (B)(ii) in the fol-
4
lowing circumstances:
5
(i) If access of the individual to the
6
information is limited by law or legally rec-
7
ognized privilege.
8
(ii) If the information is used for a le-
9
gitimate governmental or fraud prevention
10
purpose that would be compromised by
11
such access.
12
(iii) If the information consists of in-
13
formation already made available to the
14
public, unless that record has been in-
15
cluded in a report about an individual
16
shared with a third party.
17
(iv) Any other circumstance in which
18
an information broker may limit access to
19
information that the Commission deter-
20
mines to be appropriate.
21
(E) FCRA REGULATED PERSONS.—A pro-
22
vision that any information broker that is en-
23
gaged in activities subject to the Fair Credit
24
Reporting Act and who is in compliance with
25
VerDate Sep 11 2014
21:35 Mar 01, 2019
Jkt 089200
PO 00000
Frm 00010
Fmt 6652
Sfmt 6201
E:\BILLS\H1282.IH
H1282
pamtmann on DSKBFK8HB2PROD with BILLS
11
•HR 1282 IH
sections 609, 610, and 611 of such Act (15
1
U.S.C. 1681g; 1681h; 1681i) with respect to in-
2
formation subject to such Act is deemed to be
3
in compliance with this paragraph with respect
4
to such information.
5
(F) REQUIREMENT
OF
AUDIT
LOG
OF
6
ACCESSED AND TRANSMITTED INFORMATION.—
7
Each information broker to establish measures
8
which facilitate the auditing or retracing of any
9
internal or external access to, or transmissions
10
of, any data containing personal information
11
collected, assembled, or maintained by such in-
12
formation broker.
13
(4) PROHIBITION ON PRETEXTING BY INFOR-
14
MATION
BROKERS.—The regulations promulgated
15
pursuant to subsection (a) shall include a prohibition
16
on the following:
17
(A) PROHIBITION
ON
OBTAINING
PER-
18
SONAL INFORMATION BY FALSE PRETENSES.—
19
An information broker to obtain, attempt to ob-
20
tain, cause to be disclosed, or attempt to cause
21
to be disclosed to any person, personal informa-
22
tion or any other information relating to any
23
person by—
24
VerDate Sep 11 2014
21:35 Mar 01, 2019
Jkt 089200
PO 00000
Frm 00011
Fmt 6652
Sfmt 6201
E:\BILLS\H1282.IH
H1282
pamtmann on DSKBFK8HB2PROD with BILLS
12
•HR 1282 IH
(i) making a false, fictitious, or fraud-
1
ulent statement or representation to any
2
person; or
3
(ii) providing any document or other
4
information to any person that the infor-
5
mation broker knows or should know—
6
(I) to be forged, counterfeit, lost,
7
stolen, or fraudulently obtained; or
8
(II) to contain a false, fictitious,
9
or fraudulent statement or representa-
10
tion.
11
(B) PROHIBITION
ON
SOLICITATION
TO
12
OBTAIN PERSONAL INFORMATION UNDER FALSE
13
PRETENSES.—An information broker to request
14
a person to obtain personal information or any
15
other information relating to any other person,
16
if the information broker knew or should have
17
known that the person to whom such a request
18
is made will obtain or attempt to obtain such
19
information in the manner described in sub-
20
paragraph (A).
21
SEC.
3.
NOTIFICATION
OF
INFORMATION
SECURITY
22
BREACH.
23
(a) INDIVIDUAL NOTIFICATION.—Not later than 1
24
year after the date of enactment of this Act, the Commis-
25
VerDate Sep 11 2014
21:35 Mar 01, 2019
Jkt 089200
PO 00000
Frm 00012
Fmt 6652
Sfmt 6201
E:\BILLS\H1282.IH
H1282
pamtmann on DSKBFK8HB2PROD with BILLS
13
•HR 1282 IH
sion shall promulgate regulations under section 553 of
1
title 5, United States Code, that require the following:
2
(1) IN GENERAL.—Each covered entity to, fol-
3
lowing the discovery of a breach of security, notify
4
each individual who is a citizen or resident of the
5
United States whose personal information was, or is
6
reasonably believed to have been, acquired or
7
accessed by an unauthorized person, or used for an
8
unauthorized purpose.
9
(2) TIMELINESS OF NOTIFICATION.—
10
(A) IN
GENERAL.—Unless subject to a
11
delay authorized under subparagraph (B), a no-
12
tification required under paragraph (1) shall be
13
made as expeditiously as pract
[Text truncated for display. Full text available on Congress.gov.]
Important: This plain English summary was generated by AI and is provided for informational purposes only.
It is not legal advice. Always consult the official bill text on Congress.gov
or a qualified attorney for legal matters.