Federal
National Security and Personal Data Protection Act of 2019
Source: Congress.gov ·
3,857 words in original text
Plain English summary not yet available
The full original text is available below. Check back soon as we process this bill.
II
116TH CONGRESS
1ST SESSION
S. 2889
To safeguard data of Americans from foreign governments that pose risks
to national security by imposing data security requirements and strength-
ening review of foreign investments, and for other purposes.
IN THE SENATE OF THE UNITED STATES
NOVEMBER 18, 2019
Mr. HAWLEY (for himself, Mr. COTTON, and Mr. RUBIO) introduced the fol-
lowing bill; which was read twice and referred to the Committee on Com-
merce, Science, and Transportation
A BILL
To safeguard data of Americans from foreign governments
that pose risks to national security by imposing data
security requirements and strengthening review of foreign
investments, and for other purposes.
Be it enacted by the Senate and House of Representa-
1
tives of the United States of America in Congress assembled,
2
SECTION 1. SHORT TITLE.
3
This Act may be cited as the ‘‘National Security and
4
Personal Data Protection Act of 2019’’.
5
SEC. 2. DEFINITIONS.
6
In this Act:
7
VerDate Sep 11 2014
04:08 Nov 20, 2019
Jkt 099200
PO 00000
Frm 00001
Fmt 6652
Sfmt 6201
E:\BILLS\S2889.IS
S2889
kjohnson on DSK79L0C42 with BILLS
2
•S 2889 IS
(1) COMMISSION.—The term ‘‘Commission’’
1
means the Federal Trade Commission.
2
(2) COUNTRY OF CONCERN.—
3
(A) IN
GENERAL.—Subject to subpara-
4
graph (B)(iii), the term ‘‘country of concern’’
5
means—
6
(i) the People’s Republic of China;
7
(ii) the Russian Federation; and
8
(iii) any other country designated by
9
the Secretary of State as being of concern
10
with respect to the protection of data pri-
11
vacy and security.
12
(B) DESIGNATION OF COUNTRIES OF CON-
13
CERN.—Not later than 1 year after the date of
14
enactment of this Act, and annually thereafter,
15
the Secretary of State shall—
16
(i) review the status of data privacy
17
and security requirements (including by re-
18
viewing laws, policies, practices, and regu-
19
lations related to data privacy and secu-
20
rity) in each foreign country to deter-
21
mine—
22
(I) whether it would pose a sub-
23
stantial risk to the national security
24
of the United States if the govern-
25
VerDate Sep 11 2014
04:08 Nov 20, 2019
Jkt 099200
PO 00000
Frm 00002
Fmt 6652
Sfmt 6201
E:\BILLS\S2889.IS
S2889
kjohnson on DSK79L0C42 with BILLS
3
•S 2889 IS
ment of such country gained access to
1
the user data of citizens and residents
2
of the United States; and
3
(II) whether there is a substan-
4
tial risk that the government of such
5
country will, in a manner that fails to
6
afford similar respect for civil liberties
7
and privacy as the Constitution and
8
laws of the United States, obtain user
9
data from companies that collect user
10
data;
11
(ii) designate each country that meets
12
the criteria of clause (i) as a country of
13
concern; and
14
(iii) remove the designation from any
15
country that was previously designated a
16
country of concern (regardless of whether
17
such designation was pursuant to clause (i)
18
or (ii) of subparagraph (A) or was made
19
by the Secretary of State pursuant to
20
clause (iii) of such subparagraph) if the
21
country—
22
(I) no longer meets the criteria of
23
clause (i); and
24
VerDate Sep 11 2014
04:08 Nov 20, 2019
Jkt 099200
PO 00000
Frm 00003
Fmt 6652
Sfmt 6201
E:\BILLS\S2889.IS
S2889
kjohnson on DSK79L0C42 with BILLS
4
•S 2889 IS
(II) is not at substantial risk of
1
meeting such criteria.
2
(C) REGULATIONS.—Not later than 90
3
days after the date of the enactment of this
4
Act, the Secretary of State shall prescribe regu-
5
lations—
6
(i) establishing a process for a covered
7
technology company or country of concern
8
to petition the Secretary to remove the
9
country of concern designation from a
10
country that was designated as such pur-
11
suant to subparagraph (B)(ii); and
12
(ii) setting forth the procedures and
13
criteria the Secretary will use in identi-
14
fying or removing countries under subpara-
15
graphs (A)(iii) or (B)(iii).
16
(3) COVERED
TECHNOLOGY
COMPANY.—The
17
term ‘‘covered technology company’’ means an entity
18
that provides an online data-based service such as a
19
website or internet application in or affecting inter-
20
state or foreign commerce and—
21
(A) is organized under the laws of a coun-
22
try of concern;
23
(B) in which foreign persons that are na-
24
tionals of, or companies that are organized
25
VerDate Sep 11 2014
04:08 Nov 20, 2019
Jkt 099200
PO 00000
Frm 00004
Fmt 6652
Sfmt 6201
E:\BILLS\S2889.IS
S2889
kjohnson on DSK79L0C42 with BILLS
5
•S 2889 IS
under the laws of, countries of concern have a
1
plurality or controlling equity interest;
2
(C) is a subsidiary company of an entity
3
described in subparagraph (A) or (B); or
4
(D) is otherwise subject to the jurisdiction
5
of a country of concern in a manner that allows
6
the country of concern to obtain the user data
7
of citizens and residents of the United States
8
without similar respect for civil liberties and
9
privacy as provided under the Constitution and
10
laws of the United States.
11
(4) FACIAL RECOGNITION TECHNOLOGY.—The
12
term ‘‘facial recognition technology’’ means tech-
13
nology that analyzes facial features in still or video
14
images and is used to identify, or facilitate identi-
15
fication of, an individual using facial physical char-
16
acteristics.
17
(5) TARGETED ADVERTISING.—
18
(A) IN GENERAL.—The term ‘‘targeted ad-
19
vertising’’ means a form of advertising where
20
advertisements are displayed to a user based on
21
the user’s traits, information from a profile
22
about the user that is created for the purpose
23
of selling advertisements, or the user’s previous
24
online or offline behavior.
25
VerDate Sep 11 2014
04:08 Nov 20, 2019
Jkt 099200
PO 00000
Frm 00005
Fmt 6652
Sfmt 6201
E:\BILLS\S2889.IS
S2889
kjohnson on DSK79L0C42 with BILLS
6
•S 2889 IS
(B) LIMITATION.—Such term shall not in-
1
clude advertising chosen because of the context
2
of the internet service, such as—
3
(i) advertising that is directed to a
4
user based on the content of the website,
5
online service, online application, or mobile
6
application that the user is connected to;
7
or
8
(ii) advertising that is directed to a
9
user by the operator of a website, online
10
service, online application, or mobile appli-
11
cation based on the search terms that the
12
user used to arrive at such website, service,
13
or application.
14
(6) USER DATA.—The term ‘‘user data’’ means
15
any information obtained by an entity that provides
16
a data-based service such as a website or internet
17
application that identifies, relates to, describes, is
18
capable of being associated with, or could reasonably
19
be linked with an individual who is a citizen or resi-
20
dent of the United States without regard to whether
21
such information is directly submitted by the indi-
22
vidual to the entity, is derived by the entity from the
23
observed activity of the individual, or is obtained by
24
the entity by any other means.
25
VerDate Sep 11 2014
04:08 Nov 20, 2019
Jkt 099200
PO 00000
Frm 00006
Fmt 6652
Sfmt 6201
E:\BILLS\S2889.IS
S2889
kjohnson on DSK79L0C42 with BILLS
7
•S 2889 IS
SEC. 3. DATA SECURITY REQUIREMENTS FOR COVERED
1
TECHNOLOGY COMPANIES.
2
(a) IN GENERAL.—The following requirements shall
3
apply to a covered technology company:
4
(1) MINIMAL COLLECTION OF DATA.—The com-
5
pany shall not collect any more user data than is
6
necessary for the operation of the website, service, or
7
application of the company.
8
(2) PROHIBITION ON SECONDARY USES.—The
9
company shall not use any user data collected under
10
paragraph (1) for any purpose that is secondary to
11
the operation of the website, service, or application
12
of the company, including providing targeted adver-
13
tising, unnecessarily sharing such data with a third
14
party, or unnecessarily facilitating facial recognition
15
technology.
16
(3) RIGHT TO VIEW AND DELETE DATA.—The
17
company shall allow an individual to—
18
(A) view any user data held by the com-
19
pany that relates to the individual; and
20
(B) permanently delete any user data held
21
by the company that has been collected, directly
22
or indirectly, from the individual.
23
(4) PROHIBITION ON TRANSFER TO COUNTRIES
24
OF CONCERN.—The company shall not transfer any
25
user data or information needed to decipher that
26
VerDate Sep 11 2014
04:08 Nov 20, 2019
Jkt 099200
PO 00000
Frm 00007
Fmt 6652
Sfmt 6201
E:\BILLS\S2889.IS
S2889
kjohnson on DSK79L0C42 with BILLS
8
•S 2889 IS
data, such as encryption keys, to any country of con-
1
cern (including indirectly through a third country
2
that is not a country of concern).
3
(5) DATA STORAGE REQUIREMENT.—The com-
4
pany shall not store any user data collected from
5
citizens or residents of the United States or informa-
6
tion needed to decipher that data, such as
7
encryption keys, on a server or other data storage
8
device that is located outside of the United States or
9
a country that maintains an agreement with the
10
United States to share data with law enforcement
11
agencies through a process established by law.
12
(6) REPORTING REQUIREMENT.—Not less fre-
13
quently than annually, the chief executive officer or
14
equivalent officer of the company shall submit,
15
under penalty of perjury, a report to the Commis-
16
sion, the Attorney General of the United States, and
17
the Attorney General of each State certifying compli-
18
ance with the requirements of this section.
19
(b) EXCEPTIONS.—
20
(1) EXCEPTION FOR LAW ENFORCEMENT AND
21
MILITARY.—The requirements of paragraphs (1)
22
through (4) of subsection (a) shall not apply where
23
data is collected, used, retained, stored, or shared by
24
a covered technology company solely for the purpose
25
VerDate Sep 11 2014
04:08 Nov 20, 2019
Jkt 099200
PO 00000
Frm 00008
Fmt 6652
Sfmt 6201
E:\BILLS\S2889.IS
S2889
kjohnson on DSK79L0C42 with BILLS
9
•S 2889 IS
of assisting a law enforcement or military agency
1
that is not affiliated with a country of concern.
2
(2) TRANSFER OF SHARED CONTENT.—The re-
3
quirements of paragraph (4) and (5) of subsection
4
(a) shall not apply to user data that is content pro-
5
duced by a user for the purpose of sharing with
6
other users (such as social media posts, emails, or
7
data related to a transaction involving the user) or
8
information needed to decipher that data provided
9
that the transfer and any storage necessary to enact
10
the transfer is conducted solely to carry out the
11
user’s intent to share such data with individual
12
users in other countries and that necessary storage
13
occurs only on the intended recipient’s individual de-
14
vice.
15
(c) EFFECTIVE DATE.—The requirements of this sec-
16
tion shall take effect 90 days after the date of enactment
17
of this Act.
18
SEC. 4. DATA SECURITY REQUIREMENTS FOR OTHER TECH-
19
NOLOGY COMPANIES.
20
(a) IN GENERAL.—The following requirements shall
21
apply to any company operating in or affecting interstate
22
or foreign commerce that provides a data-based service
23
such as a website or internet application but is not a cov-
24
ered technology company:
25
VerDate Sep 11 2014
04:08 Nov 20, 2019
Jkt 099200
PO 00000
Frm 00009
Fmt 6652
Sfmt 6201
E:\BILLS\S2889.IS
S2889
kjohnson on DSK79L0C42 with BILLS
10
•S 2889 IS
(1) PROHIBITION ON TRANSFER TO COUNTRIES
1
OF CONCERN.—The company shall not transfer any
2
user data collected from an individual in the United
3
States or information needed to decipher that data,
4
such as encryption keys, to any country of concern
5
(including indirectly through a third country that is
6
not a country of concern).
7
(2) PROHIBITION ON STORING DATA IN COUN-
8
TRIES OF CONCERN.—The company shall not store
9
any user data collected from an individual in the
10
United States or information needed to decipher
11
that data, such as encryption keys, on a server or
12
other data storage device that is located in any
13
country of concern.
14
(b) EXCEPTIONS.—
15
(1) EXCEPTION FOR LAW ENFORCEMENT AND
16
MILITARY.—The requirements of subsection (a) shall
17
not apply where data is collected, used, retained,
18
stored, or shared by a covered technology company
19
solely for the purpose of assisting a law enforcement
20
or military agency that is not affiliated with a coun-
21
try of concern.
22
(2) TRANSFER OF SHARED CONTENT.—The re-
23
quirements of subsection (a) shall not apply to user
24
data that is content produced by a user for the pur-
25
VerDate Sep 11 2014
04:08 Nov 20, 2019
Jkt 099200
PO 00000
Frm 00010
Fmt 6652
Sfmt 6201
E:\BILLS\S2889.IS
S2889
kjohnson on DSK79L0C42 with BILLS
11
•S 2889 IS
pose of sharing with other users (such as social
1
media posts, emails, or data related to a transaction
2
involving the user) or information needed to decipher
3
that data provided that the transfer and any storage
4
necessary to enact the transfer is conducted solely to
5
carry out the user’s intent to share such data with
6
individual users in other countries and that nec-
7
essary storage occurs only on the intended recipi-
8
ent’s individual device.
9
(c) EFFECTIVE DATE.—The requirements of this sec-
10
tion shall take effect 90 days after the date of enactment
11
of this Act.
12
SEC. 5. ENFORCEMENT OF DATA SECURITY REQUIRE-
13
MENTS.
14
(a) ENFORCEMENT BY THE COMMISSION.—
15
(1) IN
GENERAL.—Except as otherwise pro-
16
vided, sections 3 and 4 shall be enforced by the
17
Commission under the Federal Trade Commission
18
Act (15 U.S.C. 41 et seq.).
19
(2) UNFAIR
OR
DECEPTIVE
ACTS
OR
PRAC-
20
TICES.—A violation of section 3 or 4 shall be treated
21
as a violation of a rule defining an unfair or decep-
22
tive act or practice prescribed under section
23
18(a)(1)(B) of the Federal Trade Commission Act
24
(15 U.S.C. 57a(a)(1)(B)).
25
VerDate Sep 11 2014
04:08 Nov 20, 2019
Jkt 099200
PO 00000
Frm 00011
Fmt 6652
Sfmt 6201
E:\BILLS\S2889.IS
S2889
kjohnson on DSK79L0C42 with BILLS
12
•S 2889 IS
(3) ACTIONS BY THE COMMISSION.—Except as
1
otherwise provided, the Commission shall prevent
2
any person from violating section 3 or 4 in the same
3
manner, by the same means, and with the same ju-
4
risdiction, powers, and duties as though all applica-
5
ble terms and provisions of the Federal Trade Com-
6
mission Act (15 U.S.C. 41 et seq.) were incor-
7
porated into and made a part of this Act, and any
8
person who violates such section shall be subject to
9
the penalties and entitled to the privileges and im-
10
munities provided in the Federal Trade Commission
11
Act.
12
(4) AUTHORITY PRESERVED.—Nothing in this
13
Act shall be construed to limit the authority of the
14
Commission under any other provision of law.
15
(b) CRIMINAL PENALTY.—
16
(1) OFFENSE.—It shall be unlawful to know-
17
ingly cause a technology company to violate a re-
18
quirement of section 3 or 4.
19
(2) PENAL
[Text truncated for display. Full text available on Congress.gov.]
Important: This plain English summary was generated by AI and is provided for informational purposes only.
It is not legal advice. Always consult the official bill text on Congress.gov
or a qualified attorney for legal matters.