A bill to create an Office of Cybersecurity at the Federal Trade Commission for supervision of data security at consumer reporting agencies, to require the promulgation of regulations establishing standards for effective cybersecurity at consumer reporting agencies, to impose penalties on credit reporting agencies for cybersecurity breaches that put sensitive consumer data at risk, and for other purposes.
About This Bill
Committee
Latest Action · December 5, 2024
Read twice and referred to the Committee on Banking, Housing, and Urban Affairs.
This bill establishes an Office of Cybersecurity within the Federal Trade Commission to oversee data security practices at large credit reporting agencies. The new office would create detailed cybersecurity standards for these agencies, conduct annual examinations for compliance, and investigate data breaches involving the exposure of sensitive personal information like Social Security numbers, financial account details, and health information. Credit reporting agencies would be required to notify the FTC within 10 days of discovering a breach and notify affected consumers on an expedited timeline, with exceptions only for ongoing law enforcement or national security investigations. When a breach occurs, courts would impose civil penalties starting at $100 per affected consumer plus $50 for each additional piece of exposed personal information, with amounts potentially doubled if agencies fail to meet notification deadlines or violate cybersecurity requirements, capped at 50 to 75 percent of the agency's annual gross revenue. The legislation authorizes $100 million in funding, with half going to cybersecurity research and agency inspections and half distributed to affected consumers as compensation.
Take Action
Your position
Add a comment
to comment on this bill.
Annotate the text
Highlight any passage on the Summary or Full Text tab to attach a note. Annotations appear on the Annotations tab.