Ask AI
S. 139

Data Breach Notification Act

(This measure has not been amended since it was introduced. The summary has been expanded because action occurred on the measure.)

Data Breach Notification Act - (Sec. 2) Requires any agency or business entity with sensitive personally identifiable information to notify without unreasonable delay any U.S. resident of a security breach in which such resident's information has been, or is reasonably believed to have been, accessed or acquired.

(Sec. 3) Exempts agencies or business entities from security breach notification requirements if they provide written certification to the Secret Service that providing such notification would impede a criminal investigation or damage national security. Requires the Secret Service to evaluate the merits of such certifications.

(Sec. 4) Requires an agency or business entity to give notice of a security breach to any affected individuals: (1) by written notice to their last known home mailing address, by telephone, or by email (if email notification was consented to); and (2) to major media outlets if the number of residents in a state affected by a security breach exceeds 5,000.

(Sec. 5) Requires the notification to individuals whose sensitive personally identifiable information has been acquired to include: (1) a description of the categories of information an unauthorized individual has acquired; and (2) toll-free numbers for contacting the agency or business entity whose databases have been breached and major credit reporting agencies.

(Sec. 6) Requires any business entity or agency that is required to provide notification to more than 5,000 individuals of a security breach to notify all consumer reporting agencies.

(Sec. 7) Requires any business entity or agency to notify the Secret Service of security breaches of sensitive personally identifying information within 14 days of any data security breach that involves: (1) more than 10,000 individuals; (2) a database that contains information about more than one million individuals nationwide; (3) a federal government database; or (4) individuals known to be government employees or contractors involved in national security or law enforcement. Requires the Secret Service to notify the Federal Bureau of Investigation (FBI), the U.S. Postal Service, and the attorney general of each affected state of a security breach within 14 days of receiving notice of any breach.

(Sec. 8) Authorizes the Attorney General to bring a civil action, including an injunction, in a U.S. district court for violations of security breach notification requirements.

(Sec. 9) Allows state attorneys general to bring a civil action in a U.S. district court to enforce security breach notification requirements. Authorizes the Attorney General to stay, or intervene in, any state action.

(Sec. 10) Declares that the provisions of this subtitle shall supersede any other provision of federal or state law relating to notification by an interstate business entity or agency of a security breach.

(Sec. 11) Authorizes appropriations to the Secret Service to carry out investigations and risk assessments of security breaches.

(Sec. 12) Requires the Secret Service to report to Congress on security breaches resulting from risk assessment exemptions.

Placed on Senate Legislative Calendar under General Orders. Calendar No. 563.

Sen. Feinstein, Dianne [D-CA](D-CA)Sponsor
1committees7actions1related bills13subjects
  1. Calendars

    Placed on Senate Legislative Calendar under General Orders. Calendar No. 563.

  2. Committee

    Committee on the Judiciary. Reported by Senator Leahy without amendment. With written report No. 111-290. Additional views filed.

    Judiciary Committee
  3. Committee14000

    Committee on the Judiciary. Reported by Senator Leahy without amendment. With written report No. 111-290. Additional views filed.

    Judiciary Committee
  4. Committee

    Committee on the Judiciary. Ordered to be reported without amendment favorably.

    Judiciary Committee
  5. IntroReferral

    Read twice and referred to the Committee on the Judiciary. (text of measure as introduced: CR S117-119)

    Judiciary Committee
  6. IntroReferralB00100

    Sponsor introductory remarks on measure. (CR S116-117)

  7. IntroReferral10000

    Introduced in Senate

Sep 15, 201080

(This measure has not been amended since it was introduced. The summary has been expanded because action occurred on the measure.)

Data Breach Notification Act - (Sec. 2) Requires any agency or business entity with sensitive personally identifiable information to notify without unreasonable delay any U.S. resident of a security breach in which such resident's information has been, or is reasonably believed to have been, accessed or acquired.

(Sec. 3) Exempts agencies or business entities from security breach notification requirements if they provide written certification to the Secret Service that providing such notification would impede a criminal investigation or damage national security. Requires the Secret Service to evaluate the merits of such certifications.

(Sec. 4) Requires an agency or business entity to give notice of a security breach to any affected individuals: (1) by written notice to their last known home mailing address, by telephone, or by email (if email notification was consented to); and (2) to major media outlets if the number of residents in a state affected by a security breach exceeds 5,000.

(Sec. 5) Requires the notification to individuals whose sensitive personally identifiable information has been acquired to include: (1) a description of the categories of information an unauthorized individual has acquired; and (2) toll-free numbers for contacting the agency or business entity whose databases have been breached and major credit reporting agencies.

(Sec. 6) Requires any business entity or agency that is required to provide notification to more than 5,000 individuals of a security breach to notify all consumer reporting agencies.

(Sec. 7) Requires any business entity or agency to notify the Secret Service of security breaches of sensitive personally identifying information within 14 days of any data security breach that involves: (1) more than 10,000 individuals; (2) a database that contains information about more than one million individuals nationwide; (3) a federal government database; or (4) individuals known to be government employees or contractors involved in national security or law enforcement. Requires the Secret Service to notify the Federal Bureau of Investigation (FBI), the U.S. Postal Service, and the attorney general of each affected state of a security breach within 14 days of receiving notice of any breach.

(Sec. 8) Authorizes the Attorney General to bring a civil action, including an injunction, in a U.S. district court for violations of security breach notification requirements.

(Sec. 9) Allows state attorneys general to bring a civil action in a U.S. district court to enforce security breach notification requirements. Authorizes the Attorney General to stay, or intervene in, any state action.

(Sec. 10) Declares that the provisions of this subtitle shall supersede any other provision of federal or state law relating to notification by an interstate business entity or agency of a security breach.

(Sec. 11) Authorizes appropriations to the Secret Service to carry out investigations and risk assessments of security breaches.

(Sec. 12) Requires the Secret Service to report to Congress on security breaches resulting from risk assessment exemptions.

Jan 6, 200900

Data Breach Notification Act - Requires any federal agency or business entity engaged in interstate commerce that uses, accesses, or collects sensitive personally identifiable information, following the discovery of a security breach, to notify: (1) any U.S. resident whose information may have been accessed or acquired; and (2) the owner or licensee of any such information that the agency or business does not own or license.

Exempts: (1) agencies and business entities from notification requirements for national security and law enforcement purposes and for security breaches that a risk assessment concludes do not have a significant risk of resulting in harm if specified certification or notice is provided, subject to review by the Secret Service; and (2) business entities which utilize a security program that blocks the use of sensitive personally identifiable information and provide notice of a breach to affected individuals.

Requires notifications regarding security breaches under specified circumstances to the Secret Service, the Federal Bureau of Investigation (FBI), the Postal Inspection Service, and state attorneys general.

Authorizes the Attorney General to bring a civil action in U.S. district court against any business entity that violates this Act. Sets civil penalties for violations.

Amends the Fair Credit Reporting Act to require agencies to include a fraud alert in the file of a consumer that submits evidence of compromised financial information to a consumer reporting agency.

Authorizes: (1) civil actions by state attorneys general to enforce this Act; and (2) appropriations for costs incurred by the Secret Service to investigate and conduct risk assessments of security breaches.

Data Breach Notification Act — Informed