Federal
Data Breach Prevention and Compensation Act of 2019
Source: Congress.gov ·
4,111 words in original text
Plain English summary not yet available
The full original text is available below. Check back soon as we process this bill.
II
116TH CONGRESS
1ST SESSION
S. 1336
To create an Office of Cybersecurity at the Federal Trade Commission for
supervision of data security at consumer reporting agencies, to require
the promulgation of regulations establishing standards for effective cyber-
security at consumer reporting agencies, to impose penalties on credit
reporting agencies for cybersecurity breaches that put sensitive consumer
data at risk, and for other purposes.
IN THE SENATE OF THE UNITED STATES
MAY 7, 2019
Ms. WARREN (for herself and Mr. WARNER) introduced the following bill;
which was read twice and referred to the Committee on Banking, Hous-
ing, and Urban Affairs
A BILL
To create an Office of Cybersecurity at the Federal Trade
Commission for supervision of data security at consumer
reporting agencies, to require the promulgation of regula-
tions establishing standards for effective cybersecurity
at consumer reporting agencies, to impose penalties on
credit reporting agencies for cybersecurity breaches that
put sensitive consumer data at risk, and for other pur-
poses.
Be it enacted by the Senate and House of Representa-
1
tives of the United States of America in Congress assembled,
2
VerDate Sep 11 2014
00:41 May 11, 2019
Jkt 089200
PO 00000
Frm 00001
Fmt 6652
Sfmt 6201
\\ALPHA3\E\BILLS\S1336.IS
S1336
kjohnson on DSK79L0C42 with BILLS
2
•S 1336 IS
SECTION 1. SHORT TITLE.
1
This Act may be cited as the ‘‘Data Breach Preven-
2
tion and Compensation Act of 2019’’.
3
SEC. 2. DEFINITIONS.
4
In this Act:
5
(1) AFFECTED
CONSUMER.—The term ‘‘af-
6
fected consumer’’ means any individual to whom
7
personally identifying information pertains that was,
8
or that may have been, affected by a covered breach.
9
(2) AGENCY.—The term ‘‘agency’’ has the
10
meaning given the term in section 551 of title 5,
11
United States Code.
12
(3) CAREER
APPOINTEE.—The term ‘‘career
13
appointee’’ has the meaning given the term in sec-
14
tion 3132(a) of title 5, United States Code.
15
(4) COMMISSION.—The term ‘‘Commission’’
16
means the Federal Trade Commission.
17
(5) CONSUMER REPORT; CONSUMER REPORTING
18
AGENCY.—The terms ‘‘consumer report’’ and ‘‘con-
19
sumer reporting agency’’ have the meanings given
20
the terms in section 603 of the Fair Credit Report-
21
ing Act (15 U.S.C. 1681a).
22
(6) COVERED
BREACH.—The term ‘‘covered
23
breach’’ means any instance in which not less than
24
1 piece of personally identifying information held by
25
a covered consumer reporting agency is exposed, or
26
VerDate Sep 11 2014
00:41 May 11, 2019
Jkt 089200
PO 00000
Frm 00002
Fmt 6652
Sfmt 6201
\\ALPHA3\E\BILLS\S1336.IS
S1336
kjohnson on DSK79L0C42 with BILLS
3
•S 1336 IS
is reasonably likely to have been exposed, to an un-
1
authorized party.
2
(7) COVERED
CONSUMER
REPORTING
AGEN-
3
CY.—The term ‘‘covered consumer reporting agency’’
4
means—
5
(A) a consumer reporting agency described
6
in section 603(p) of the Fair Credit Reporting
7
Act (15 U.S.C. 1681a(p)); or
8
(B) a consumer reporting agency that
9
earns not less than $7,000,000 in annual rev-
10
enue from the sale of consumer reports.
11
(8) DETAIL.—The term ‘‘detail’’ means a tem-
12
porary assignment of an employee to a different po-
13
sition for a specified period, with the employee re-
14
turning to the regular duties of the employee at the
15
end of the specified period.
16
(9) DIRECTOR.—The term ‘‘Director’’ means
17
the Director of the Office.
18
(10) OFFICE.—The term ‘‘Office’’ means the
19
Office of Cybersecurity established under section
20
3(a).
21
(11)
PERSONALLY
IDENTIFYING
INFORMA-
22
TION.—The term ‘‘personally identifying informa-
23
tion’’ means, with respect to an individual—
24
VerDate Sep 11 2014
00:41 May 11, 2019
Jkt 089200
PO 00000
Frm 00003
Fmt 6652
Sfmt 6201
\\ALPHA3\E\BILLS\S1336.IS
S1336
kjohnson on DSK79L0C42 with BILLS
4
•S 1336 IS
(A) the social security number of the indi-
1
vidual;
2
(B) a driver’s license number of the indi-
3
vidual;
4
(C) a passport number of the individual;
5
(D) an alien registration number or other
6
government-issued unique identification number
7
of the individual;
8
(E) unique biometric data, such as a
9
faceprint, a fingerprint, a voice print, an iris
10
image, or any other unique physical representa-
11
tion of the individual;
12
(F) the first and last name of the indi-
13
vidual, or the first initial of the first name and
14
the last name of the individual, in combination
15
with any information that relates to—
16
(i) the past, present, or future phys-
17
ical or mental health or condition of the in-
18
dividual; or
19
(ii) the provision of health care to, or
20
a diagnosis of, the individual;
21
(G)(i) a financial account number, debit
22
card number, or credit card number of the indi-
23
vidual; or
24
VerDate Sep 11 2014
00:41 May 11, 2019
Jkt 089200
PO 00000
Frm 00004
Fmt 6652
Sfmt 6201
\\ALPHA3\E\BILLS\S1336.IS
S1336
kjohnson on DSK79L0C42 with BILLS
5
•S 1336 IS
(ii) any passcode required to access an ac-
1
count described in clause (i); and
2
(H) such additional information, as deter-
3
mined by the Director.
4
SEC. 3. CYBERSECURITY STANDARDS AND FTC AUTHORITY.
5
(a) ESTABLISHMENT.—There is established in the
6
Commission an Office of Cybersecurity, which shall be
7
headed by a Director, who shall be a career appointee.
8
(b) DUTIES.—The Office—
9
(1) shall—
10
(A) supervise covered consumer reporting
11
agencies with respect to data security;
12
(B) promulgate regulations, through notice
13
and comment rulemaking that complies with
14
section 553 of title 5, United States Code, for
15
effective data security for covered consumer re-
16
porting agencies, including requirements for a
17
covered consumer reporting agency to—
18
(i) provide the Commission with de-
19
scriptions of technical and organizational
20
security measures of the consumer report-
21
ing agency, including—
22
(I) system and network security
23
measures, including—
24
VerDate Sep 11 2014
00:41 May 11, 2019
Jkt 089200
PO 00000
Frm 00005
Fmt 6652
Sfmt 6201
\\ALPHA3\E\BILLS\S1336.IS
S1336
kjohnson on DSK79L0C42 with BILLS
6
•S 1336 IS
(aa) asset management, in-
1
cluding—
2
(AA) an inventory of
3
devices of the covered con-
4
sumer reporting agency that
5
are authorized to access
6
data maintained by the cov-
7
ered
consumer
reporting
8
agency;
9
(BB) an inventory of
10
software that is authorized
11
by the covered consumer re-
12
porting agency to access
13
data maintained by the cov-
14
ered
consumer
reporting
15
agency, including application
16
whitelisting; and
17
(CC) secure configura-
18
tions for hardware and soft-
19
ware of the covered con-
20
sumer reporting agency;
21
(bb) network management
22
and monitoring, including—
23
VerDate Sep 11 2014
00:41 May 11, 2019
Jkt 089200
PO 00000
Frm 00006
Fmt 6652
Sfmt 6201
\\ALPHA3\E\BILLS\S1336.IS
S1336
kjohnson on DSK79L0C42 with BILLS
7
•S 1336 IS
(AA)
mapped
data
1
flows, including functional
2
mission mapping;
3
(BB)
maintenance,
4
monitoring, and analysis of
5
audit logs;
6
(CC)
network
seg-
7
mentation; and
8
(DD) local and remote
9
access
privileges,
defined
10
and managed; and
11
(cc)
application
manage-
12
ment, including—
13
(AA) continuous vulner-
14
ability assessment and reme-
15
diation;
16
(BB) server application
17
hardening;
18
(CC) vulnerability han-
19
dling, such as coordinated
20
vulnerability disclosure pol-
21
icy; and
22
(DD) patch manage-
23
ment, including at, or near,
24
real-time
dashboards
of
25
VerDate Sep 11 2014
00:41 May 11, 2019
Jkt 089200
PO 00000
Frm 00007
Fmt 6652
Sfmt 6201
\\ALPHA3\E\BILLS\S1336.IS
S1336
kjohnson on DSK79L0C42 with BILLS
8
•S 1336 IS
patch implementation across
1
network hosts; and
2
(II) data security measures, in-
3
cluding—
4
(aa)
data-centric
security
5
mechanisms such as format-pre-
6
serving encryption, cryptographic
7
data-splitting, and data-tagging
8
and lineage;
9
(bb) encryption for data at
10
rest;
11
(cc) encryption for data in
12
transit;
13
(dd) systemwide data mini-
14
mization evaluations and policies;
15
and
16
(ee) data recovery capability;
17
(ii) employ reasonable technical meas-
18
ures and corporate governance processes
19
for continuous monitoring of data, intru-
20
sion detection, and continuous evaluation
21
and timely patching of vulnerabilities;
22
(iii) employ reasonable technical meas-
23
ures and corporate governance processes
24
that satisfy and exceed all relevant data se-
25
VerDate Sep 11 2014
00:41 May 11, 2019
Jkt 089200
PO 00000
Frm 00008
Fmt 6652
Sfmt 6201
\\ALPHA3\E\BILLS\S1336.IS
S1336
kjohnson on DSK79L0C42 with BILLS
9
•S 1336 IS
curity policy recommendations contained in
1
the framework of the National Institute of
2
Standards
and
Technology
entitled
3
‘‘Framework for Improving Critical Infra-
4
structure Cybersecurity’’, dated February
5
12, 2014, or any successor thereto, as de-
6
termined appropriate by the Office; and
7
(iv) create and maintain documenta-
8
tion demonstrating that the covered con-
9
sumer reporting agency is employing the
10
technical measures and corporate govern-
11
ance processes described in clauses (ii) and
12
(iii);
13
(C) annually examine the data security
14
measures of covered consumer reporting agen-
15
cies for compliance with the requirements de-
16
scribed in clauses (ii) and (iii) of subparagraph
17
(B);
18
(D) investigate any covered consumer re-
19
porting agency if the Office has reason to sus-
20
pect—
21
(i) a covered breach has occurred and
22
the covered consumer reporting agency was
23
subject to the covered breach; or
24
VerDate Sep 11 2014
00:41 May 11, 2019
Jkt 089200
PO 00000
Frm 00009
Fmt 6652
Sfmt 6201
\\ALPHA3\E\BILLS\S1336.IS
S1336
kjohnson on DSK79L0C42 with BILLS
10
•S 1336 IS
(ii) the covered consumer reporting
1
agency is not in compliance with the re-
2
quirements described in clauses (ii) and
3
(iii) of subparagraph (B);
4
(E) after consultation with members of the
5
technical and academic communities, develop a
6
rigorous, repeatable methodology—
7
(i) for evaluating, testing, and meas-
8
uring effective data security practices of
9
covered consumer reporting agencies; and
10
(ii) that employs forms of static and
11
dynamic software analysis and penetration
12
testing;
13
(F) submit to Congress an annual report
14
on the findings of each investigation carried out
15
under subparagraph (D) during the year cov-
16
ered by the report that includes a statement of
17
how Congress could enhance the authorities of
18
the Office in order to assist the Office in car-
19
rying out the duties of the Office under this
20
Act;
21
(G) determine whether covered consumer
22
reporting agencies are complying with the re-
23
quirements described in clauses (ii) and (iii) of
24
subparagraph (B); and
25
VerDate Sep 11 2014
00:41 May 11, 2019
Jkt 089200
PO 00000
Frm 00010
Fmt 6652
Sfmt 6201
\\ALPHA3\E\BILLS\S1336.IS
S1336
kjohnson on DSK79L0C42 with BILLS
11
•S 1336 IS
(H) coordinate with the National Institute
1
of Standards and Technology and the National
2
Cybersecurity and Communications Integration
3
Center of the Department of Homeland Secu-
4
rity; and
5
(2) may—
6
(A) investigate any covered breach to de-
7
termine if the covered consumer reporting agen-
8
cy that was subject to the covered breach was
9
in compliance with the requirements described
10
in clauses (ii) and (iii) of paragraph (1)(B) as
11
of the date on which the covered breach oc-
12
curred; and
13
(B) if the Director has reason to believe
14
that any covered consumer reporting agency is
15
violating, or in the immediate future will vio-
16
late, a requirement described in clause (ii) or
17
(iii) of paragraph (1), bring a suit in an appro-
18
priate district court of the United States to en-
19
join any such act or practice.
20
(c) STAFF.—
21
(1) IN GENERAL.—The Director shall, without
22
regard to the civil service laws and regulations, ap-
23
point such personnel, including computer security re-
24
searchers and practitioners with technical expertise
25
VerDate Sep 11 2014
00:41 May 11, 2019
Jkt 089200
PO 00000
Frm 00011
Fmt 6652
Sfmt 6201
\\ALPHA3\E\BILLS\S1336.IS
S1336
kjohnson on DSK79L0C42 with BILLS
12
•S 1336 IS
in computer science, engineering, and cybersecurity,
1
as the Director determines are necessary to carry
2
out the duties of the Office.
3
(2) DETAILS.—
4
(A) IN GENERAL.—An employee of the Na-
5
tional Institute of Standards and Technology,
6
the Bureau of Consumer Financial Protection,
7
or the National Cybersecurity and Communica-
8
tions Integration Center of the Department of
9
Homeland Security may be detailed to the Of-
10
fice, without reimbursement.
11
(B) CIVIL
SERVICE
STATUS
AND
PRIVI-
12
LEGE.—Detail under subparagraph (A) shall be
13
without interruption or loss of the civil service
14
status or privilege of the employee who is de-
15
tailed to the Office.
16
SEC. 4. NOTIFICATION AND ENFORCEMENT.
17
(a) NOTIFICATION.—
18
(1) NOTIFICATION
TO
THE
COMMISSION
AND
19
RELEVANT FEDERAL LAW ENFORCEMENT AND IN-
20
TELLIGENCE AGENCIES.—
21
(A) NOTIFICATION TO THE COMMISSION.—
22
Except as provided in paragraph (3), not later
23
than 10 days after the date on which a covered
24
breach occurs, any covered consumer reporting
25
VerDate Sep 11 2014
00:41 May 11, 2019
Jkt 089200
PO 00000
Frm 00012
Fmt 6652
Sfmt 6201
\\ALPHA3\E\BILLS\S1336.IS
S1336
kjohnson on DSK79L0C42 with BILLS
13
•S 1336 IS
agency that was subject to the covered breach
1
shall notify the Commission of the covered
2
breach.
3
(B) NOTIFICATION
TO
RELEVANT
FED-
4
ERAL LAW ENFORCEMENT AND INTELLIGENCE
5
AGENCIES.—Not later than 10 days after the
6
date on which the Commission receives a notifi-
7
cation under subparagraph (A) that a covered
8
breach has occurred, the Commission shall—
9
(i) notify the relevant Federal law en-
10
forcement agencies and intelligence agen-
11
cies that the covered breach has occurred;
12
and
13
(ii) with respect to the covered breach,
14
consult with the relevant Federal law en-
15
forcement agencies and intelligence agen-
16
cies, as appropriate.
17
(2) NOTIFICATION TO AFFECTED CONSUMERS
18
AND THE PUBLIC.—
19
(A) IN GENERAL.—Except as provided in
20
paragraph (3), on an expeditious and practical
21
timeline, as determined appropriate by the
22
Commission, a covered consumer reporting
23
agency that is subject to a covered breach
24
shall—
25
VerDate Sep 11 2014
00:41 May 11, 2019
Jkt 089200
PO 00000
Frm 00013
Fmt 6652
Sfmt 6201
\\ALPHA3\E\BILLS\S1336.IS
S1336
kjohnson on DSK79L0C42 with BILLS
14
•S 1336 IS
(i) submit to each affected consumer
1
with respect to whom the covered con-
2
sumer reporting agency holds a piece of
3
personally identifying information a notifi-
4
cation regarding the covered breach that
5
complies with subparagra
[Text truncated for display. Full text available on Congress.gov.]
Important: This plain English summary was generated by AI and is provided for informational purposes only.
It is not legal advice. Always consult the official bill text on Congress.gov
or a qualified attorney for legal matters.