H.R.2577 - SAFE Data Act

To protect consumers by requiring reasonable security policies and procedures to protect data containing personal information, and to provide for nationwide notice in the event of a security breach. view all titles (3)

All Bill Titles

  • Official: To protect consumers by requiring reasonable security policies and procedures to protect data containing personal information, and to provide for nationwide notice in the event of a security breach. as introduced.
  • Short: SAFE Data Act as introduced.
  • Short: Secure and Fortify Electronic Data Act as introduced.

This Bill currently has no wiki content. If you would like to create a wiki entry for this bill, please Login, and then select the wiki tab to create it.

Bill’s Views

  • Today: 12
  • Past Seven Days: 19
  • All-Time: 5,564
 
Introduced
 
House
Passes
 
Senate
Passes
 
President
Signs
 

 
07/18/11
 
 
 
 
 
 
 

Official Summary

Secure and Fortify Electronic Data Act or the SAFE Data Act - Requires the Federal Trade Commission (FTC) to promulgate regulations requiring any person engaged in interstate commerce that owns or possesses data containing personal information to establish and implement reasonable security

Official Summary

Secure and Fortify Electronic Data Act or the SAFE Data Act - Requires the Federal Trade Commission (FTC) to promulgate regulations requiring any person engaged in interstate commerce that owns or possesses data containing personal information to establish and implement reasonable security policies and procedures to treat and protect such information. Requires such regulations to include specified policies and procedures, including:
(1) a process for identifying and assessing vulnerabilities in the system, and
(2) a process for taking preventive and corrective action to mitigate such vulnerabilities. Requires a person covered by this Act to establish a plan and procedures for minimizing the amount of personal information maintained. Exempts services providers from such requirements for any electronic communication by a third party that is transmitted, routed, or stored in intermediate or transient storage by the provider. Establishes notification procedures in the event of a breach of security of any system that contains personal information. Allows an exemption from notification requirements if a person subject to this Act determines that there is no reasonable risk of identity theft, fraud, or other unlawful conduct. Creates a presumption that no reasonable risk of such conduct exists following a breach of security if the data containing personal information is unusable, unreadable, or indecipherable to an unauthorized person by encryption or other security technology that is generally accepted by experts in the information security field. Directs a person subject to this Act to provide a credit report and credit monitoring if certain identifying information is breached. Sets forth provisions regarding enforcement of this Act by the FTC and by state attorneys general. Establishes civil penalties for violations. Exempts from the requirements of this Act any person subject to the information security requirements of the Health Insurance Portability and Accountability Act (HIPAA) or the Gramm-Leach Bliley Act.

...Read the Rest

Organizations Supporting H.R.2577

  • Marketing Research Association
  • Center for Democracy and Technology
  • Business Software Alliance
  • Software and Information Industry Association

Organizations Opposing H.R.2577

  • U. S. Chamber of Commerce




Vote on This Bill

100% Users Support Bill

2 in favor / 0 opposed
 

Send Your Rep a Letter

about this bill Support Oppose Tracking
Track with MyOC