← Back to results
Federal

Data Care Act of 2023

Source: Congress.gov  ·  3,110 words in original text
The Data Care Act establishes rules that online service providers must follow when collecting and using information about their users. These rules require providers to protect user data from theft, be honest about how they use that data, and share data responsibly with other companies.
- Online service providers (companies that collect information about users on the internet) - People who use online services - Companies that receive user data from online service providers - The Federal Trade Commission - State attorneys general - Nonprofit organizations that operate online services - Common carriers that provide online services
- Online service providers must protect user information from unauthorized access and quickly tell users if sensitive information is stolen (Sec. 3(b)(1)) - Online service providers cannot use user information in ways that help the company but hurt the user, especially if the use would cause serious harm or be offensive to a reasonable person (Sec. 3(b)(2)) - Online service providers cannot sell or share user information unless the other company agrees to follow the same data protection rules (Sec. 3(b)(3)) - The Federal Trade Commission can create exceptions for certain types of online providers if the privacy risks are small enough (Sec. 3(e)) - The Federal Trade Commission can expand breach notification rules to cover more types of user information beyond sensitive data (Sec. 3(d))
If this becomes law, online service providers must adopt three new duties when handling user information: a duty of care to protect data, a duty of loyalty to not use data against users, and a duty of confidentiality to control who receives that data. Violations can be treated as deceptive business practices. State attorneys general gain the power to sue companies that violate these duties on behalf of their residents and collect money damages.
- End user: A person who uses an online service or logs into it over the internet - Individual identifying data: Any information collected online that can be connected to a specific person or their device - Online service provider: A company that does business on the internet and collects information about users - Sensitive data: High-risk information including social security numbers, financial account numbers, biometric data like fingerprints, health information, and nonpublic personal messages
The law takes effect on the date it is signed. The specific data protection rules in Section 3 apply 180 days after the law is signed.
Important: This plain English summary was generated by AI and is provided for informational purposes only. It is not legal advice. Always consult the official bill text on Congress.gov or a qualified attorney for legal matters.