Bill
Bill > S1976
US S1976
US S1976A bill to protect consumers by requiring reasonable security policies and procedures to protect data containing personal information, and to provide for nationwide notice in the event of a breach of security.
summary
Introduced
01/30/2014
01/30/2014
In Committee
01/30/2014
01/30/2014
Crossed Over
Passed
Dead
01/03/2015
01/03/2015
Introduced Session
113th Congress
Bill Summary
A bill to protect consumers by requiring reasonable security policies and procedures to protect data containing personal information, and to provide for nationwide notice in the event of a breach of security.
AI Summary
This bill, known as the Data Security and Breach Notification Act of 2014, aims to protect consumers by establishing nationwide standards for data security and breach notification. It requires "covered entities" – which include businesses, non-profits, and other commercial organizations that handle personal information – to implement reasonable security policies and procedures to safeguard data containing "personal information," defined broadly to include Social Security numbers, financial account details, and certain combinations of identifying information. In the event of a "breach of security," meaning the compromise of data leading to unauthorized access or acquisition of personal information, covered entities must notify affected individuals and the Federal Trade Commission (FTC), with specific notification requirements for large-scale breaches or those involving government databases. The bill also outlines procedures for third-party service providers and includes exemptions for certain situations, such as when there's no reasonable risk of identity theft or for national security and law enforcement purposes. Enforcement is primarily handled by the FTC, with provisions for state attorneys general to bring civil actions, and penalties for violations, including concealment of breaches. Existing federal laws like the Gramm-Leach-Bliley Act and the Health Information Technology for Economic and Clinical Health Act (HITECH Act) are recognized, and the bill preempts conflicting state laws regarding data security and breach notification, while preserving other state consumer protection laws.
Committee Categories
Transportation and Infrastructure
Sponsors (4)
Last Action
Read twice and referred to the Committee on Commerce, Science, and Transportation. (on 01/30/2014)
Official Document
bill text
bill summary
Loading...
bill summary
Loading...
bill summary
| Document Type | Source Location | Created |
|---|---|---|
| State Bill Page | https://www.congress.gov/bill/113th-congress/senate-bill/1976/all-info | 01/31/2014 |
| BillText | http://gpo.gov/fdsys/pkg/BILLS-113s1976is/pdf/BILLS-113s1976is.pdf | 02/05/2014 |
| Bill | http://gpo.gov/fdsys/pkg/BILLS-113s1976is/pdf/BILLS-113s1976is.pdf.pdf | 02/05/2014 |
Loading...