The easiest way to email your members of Congress
Donate NowS.1558 - Federal Agency Data Breach Protection Act
A bill to amend title 14, United States Code, to strengthen requirements related to security breaches of data involving the disclosure of sensitive personal information.

Loading Bill Text
Rollover any line of text to comment and/or link to it.
S 1558 ISCommentsClose CommentsPermalink
To amend title 44, United States Code, to strengthen requirements related to security breaches of data involving the disclosure of sensitive personal information.CommentsClose CommentsPermalink
June 6, 2007
Mr. COLEMAN introduced the following bill; which was read twice and referred to the Committee on Homeland Security and Governmental AffairsCommentsClose CommentsPermalink
To amend title 44, United States Code, to strengthen requirements related to security breaches of data involving the disclosure of sensitive personal information.CommentsClose CommentsPermalink
Be it enacted by the Senate and House of Representatives of the United States of America in Congress assembled,CommentsClose CommentsPermalink
SECTION 1. SHORT TITLE.
This Act may be cited as the `Federal Agency Data Breach Protection Act'.CommentsClose CommentsPermalink
SEC. 2. FEDERAL AGENCY DATA BREACH NOTIFICATION REQUIREMENTS.
(a) Authority of Director of Office of Management and Budget To Establish Data Breach Policies-
(1) by striking `and' at the end of paragraph (7);CommentsClose CommentsPermalink
(2) by striking the period and inserting `; and' at the end of paragraph (8); andCommentsClose CommentsPermalink
(3) by adding at the end the following:CommentsClose CommentsPermalink
`(9) establishing policies, procedures, and standards for agencies to follow in the event of a breach of data security involving the disclosure of sensitive personal information and for which harm to an individual could reasonably be expected to result, specifically including--CommentsClose CommentsPermalink
`(A) a requirement for timely notice to be provided to those individuals whose sensitive personal information could be compromised as a result of such breach, except no notice shall be required if the breach does not create a reasonable risk of identity theft, fraud, or other unlawful conduct regarding such individual;CommentsClose CommentsPermalink
`(B) guidance on determining how timely notice is to be provided; andCommentsClose CommentsPermalink
`(C) guidance regarding whether additional special actions are necessary and appropriate, including data breach analysis, fraud resolution services, identity theft insurance, and credit protection or monitoring services.'.CommentsClose CommentsPermalink
(b) Authority of Chief Information Officer To Enforce Data Breach Policies and Develop and Maintain Inventories-
(1) by inserting after `authority to ensure compliance with' the following: `and, to the extent determined necessary and explicitly authorized by the head of the agency, to enforce';CommentsClose CommentsPermalink
(2) by striking `and' at the end of subparagraph (D);CommentsClose CommentsPermalink
(3) by inserting `and' at the end of subparagraph (E); andCommentsClose CommentsPermalink
(4) by adding at the end the following:CommentsClose CommentsPermalink
`(F) developing and maintaining an inventory of all personal computers, laptops, or any other hardware containing sensitive personal information;'.CommentsClose CommentsPermalink
(c) Inclusion of Data Breach Notification in Agency Information Security Programs-
(1) by striking `and' at the end of paragraph (7);CommentsClose CommentsPermalink
(2) by striking the period and inserting `; and' at the end of paragraph (8); andCommentsClose CommentsPermalink
(3) by adding at the end the following:CommentsClose CommentsPermalink
`(9) procedures for notifying individuals whose sensitive personal information is compromised consistent with policies, procedures, and standards established under section 3543(a)(9) of this title.'.CommentsClose CommentsPermalink
(d) Authority of Agency Chief Human Capital Officers To Assess Federal Personal Property-
(1) by striking `, and' at the end of paragraph (5) and inserting a semicolon;CommentsClose CommentsPermalink
(2) by striking the period and inserting `; and' at the end of paragraph (6); andCommentsClose CommentsPermalink
(3) by adding at the end the following:CommentsClose CommentsPermalink
`(7) prescribing policies and procedures for exit interviews of employees, including a full accounting of all Federal personal property that was assigned to the employee during the course of employment.'.CommentsClose CommentsPermalink
(e) Sensitive Personal Information Definition-
`(4) The term `sensitive personal information', with respect to an individual, means any information about the individual maintained by an agency, including--CommentsClose CommentsPermalink
`(A) education, financial transactions, medical history, and criminal or employment history;CommentsClose CommentsPermalink
`(B) information that can be used to distinguish or trace the individual's identity, including name, social security number, date and place of birth, mother's maiden name, or biometric records; orCommentsClose CommentsPermalink
`(C) any other personal information that is linked or linkable to the individual.'.CommentsClose CommentsPermalink
Vote on This Bill
-
Share This Bill
More Share via Email
OC Blog Articles Related To This Bill
- With SOPA Shelved, Congress Readies its Next Attack on the Internet Feb 13, 2012
- Anti-Web Censorship Bill Protest from Our Perspective at OC Feb 08, 2012
- Join the Public Mark-up of SOPA Nov 19, 2011
- House Passes Bill to Weaken NLRB's Ability to Enforce Labor Laws Sep 15, 2011
- Dems Propose Ban on Hiring Discrimination Against the Unemployed Jul 18, 2011
Recent OC Blog Articles
- Yes, let's stride towards an open VCS for legislation (or, GitHub for laws on OC) May 23, 2012
- Contact Congress Today to #FreeTHOMAS May 17, 2012
- Yochai Benkler: Blueprint for Democratic Participation May 10, 2012
- New NDAA Would Give the Military Clandestine Cyberwar Powers May 08, 2012
- The Week Ahead in Congress May 07, 2012

U.S. Congress - Text of S.1558 as Introduced in Senate Federal Agency Data Breach Protection Act



