Bill

Bill > HR1770


US HR1770

US HR1770
Data Security and Breach Notification Act of 2015


summary

Introduced
04/14/2015
In Committee
04/17/2015
Crossed Over
Passed
Dead
01/03/2017

Introduced Session

114th Congress

Bill Summary

Data Security and Breach Notification Act of 2015 Requires certain commercial entities and non-profit organizations that use, access, transmit, store, dispose of, or collect unencrypted nonpublic personal information to restore the integrity, security, and confidentiality of their data systems following the discovery of a security breach. Requires notification to: (1) affected U.S. residents when there is a reasonable risk that such a breach has resulted in, or will result in, identity theft, economic harm, or financial fraud; (2) the Federal Trade Commission (FTC) and the U.S. Secret Service or the Federal Bureau of Investigation if an unauthorized person accesses or acquires the personal information of more than 10,000 individuals; and (3) consumer reporting agencies if notice must be provided to more than 10,000 individuals. Establishes special procedures to coordinate the notices that must be provided when: (1) a breached entity processes personal data on behalf of a non-breached entity; or (2) a provider of electronic data transmission, storage, or network connection services becomes aware of a breach. Provides authority to the FTC and states to enforce against violations of this Act. Directs the FTC to educate small businesses about data security and establish an Internet website containing non-binding best practices. Preempts state information security and notification laws, but does not exempt an entity from liability under common law. Provides for the requirements of this Act to apply to certain entities in place of security practices and notification standards currently enforced by the Federal Communications Commission (FCC), except for FCC regulations that pertain solely to 9-1-1 calls.

AI Summary

This bill, the Data Security and Breach Notification Act of 2015, requires commercial entities and non-profit organizations that handle unencrypted personal information to maintain secure data systems and notify individuals in the event of a data breach that poses a risk of identity theft, economic harm, or financial fraud. Specifically, it mandates notification to affected U.S. residents, the Federal Trade Commission (FTC) and law enforcement if over 10,000 individuals are impacted, and consumer reporting agencies in such large-scale breaches. The bill also establishes procedures for coordinating notifications when data is processed by one entity on behalf of another or when a service provider experiences a breach, and it grants enforcement authority to the FTC and states, while preempting conflicting state laws on data security and breach notification, though it does not eliminate liability under common law. Additionally, the FTC is directed to provide educational resources to small businesses on data security and maintain a website with best practices.

Committee Categories

Business and Industry

Sponsors (4)

Last Action

Placed on the Union Calendar, Calendar No. 719. (on 01/03/2017)

bill text


bill summary

Loading...

bill summary

Loading...
Loading...