Nonpartisan civic infrastructure
AllCiv·Legis1
·

15 U.S.C. § 9901

U.S. CodeFederal
Prohibition on transfer of personally identifiable sensitive data of United States individuals to foreign adversaries
About This Law
/us/usc/t15/s9901
Title
15 — Commerce and Trade
Chapter
CH123
Release
119-84
Release Date
2026-04-17

Section Text

Highlight any text to annotate
(a) ProhibitionIt shall be unlawful for a data broker to sell, license, rent, trade, transfer, release, disclose, provide access to, or otherwise make available personally identifiable sensitive data of a United States individual to—(1) any foreign adversary country; or (2) any entity that is controlled by a foreign adversary. (b) Enforcement by Federal Trade Commission(1) Unfair or deceptive acts or practicesA violation of this section shall be treated as a violation of a rule defining an unfair or a deceptive act or practice under section 18(a)(1)(B) of the Federal Trade Commission Act (15 U.S.C. 57a(a)(1)(B)). (2) Powers of Commission(A) In generalThe Commission shall enforce this section in the same manner, by the same means, and with the same jurisdiction, powers, and duties as though all applicable terms and provisions of the Federal Trade Commission Act (15 U.S.C. 41 et seq.) were incorporated into and made a part of this section. (B) Privileges and immunitiesAny person who violates this section shall be subject to the penalties and entitled to the privileges and immunities provided in the Federal Trade Commission Act. (3) Authority preservedNothing in this section may be construed to limit the authority of the Commission under any other provision of law. (c) DefinitionsIn this section:(1) CommissionThe term “Commission” means the Federal Trade Commission. (2) Controlled by a foreign adversaryThe term “controlled by a foreign adversary” means, with respect to an individual or entity, that such individual or entity is—(A) a foreign person that is domiciled in, is headquartered in, has its principal place of business in, or is organized under the laws of a foreign adversary country; (B) an entity with respect to which a foreign person or combination of foreign persons described in subparagraph (A) directly or indirectly own at least a 20 percent stake; or (C) a person subject to the direction or control of a foreign person or entity described in subparagraph (A) or (B). (3) Data broker(A) In generalThe term “data broker” means an entity that, for valuable consideration, sells, licenses, rents, trades, transfers, releases, discloses, provides access to, or otherwise makes available data of United States individuals that the entity did not collect directly from such individuals to another entity that is not acting as a service provider. (B) ExclusionThe term “data broker” does not include an entity to the extent such entity—(i) is transmitting data of a United States individual, including communications of such an individual, at the request or direction of such individual; (ii) is providing, maintaining, or offering a product or service with respect to which personally identifiable sensitive data, or access to such data, is not the product or service; (iii) is reporting or publishing news or information that concerns local, national, or international events or other matters of public interest; (iv) is reporting, publishing, or otherwise making available news or information that is available to the general public—(I) including information from—(aa) a book, magazine, telephone book, or online directory; (bb) a motion picture; (cc) a television, internet, or radio program; (dd) the news media; or (ee) an internet site that is available to the general public on an unrestricted basis; and (II) not including an obscene visual depiction (as such term is used in section 1460 of title 18); or (v) is acting as a service provider. (4) Foreign adversary countryThe term “foreign adversary country” means a country specified in section 4872(d)(2) of title 10. (5) Personally identifiable sensitive dataThe term “personally identifiable sensitive data” means any sensitive data that identifies or is linked or reasonably linkable, alone or in combination with other data, to an individual or a device that identifies or is linked or reasonably linkable to an individual. (6) Precise geolocation informationThe term “precise geolocation information” means information that—(A) is derived from a device or technology of an individual; and (B) reveals the past or present physical location of an individual or device that identifies or is linked or reasonably linkable to 1 or more individuals, with sufficient precision to identify street level location information of an individual or device or the location of an individual or device within a range of 1,850 feet or less. (7) Sensitive dataThe term “sensitive data” includes the following:(A) A government-issued identifier, such as a Social Security number, passport number, or driver’s license number. (B) Any information that describes or reveals the past, present, or future physical health, mental health, disability, diagnosis, or healthcare condition or treatment of an individual. (C) A financial account number, debit card number, credit card number, or information that describes or reveals the income level or bank account balances of an individual. (D) Biometric information. (E) Genetic information. (F) Precise geolocation information. (G) An individual’s private communications such as voicemails, emails, texts, direct messages, mail, voice communications, and video communications, or information identifying the parties to such communications or pertaining to the transmission of such communications, including telephone numbers called, telephone numbers from which calls were placed, the time calls were made, call duration, and location information of the parties to the call. (H) Account or device log-in credentials, or security or access codes for an account or device. (I) Information identifying the sexual behavior of an individual. (J) Calendar information, address book information, phone or text logs, photos, audio recordings, or videos, maintained for private use by an individual, regardless of whether such information is stored on the individual’s device or is accessible from that device and is backed up in a separate location. (K) A photograph, film, video recording, or other similar medium that shows the naked or undergarment-clad private area of an individual. (L) Information revealing the video content requested or selected by an individual. (M) Information about an individual under the age of 17. (N) An individual’s race, color, ethnicity, or religion. (O) Information identifying an individual’s online activities over time and across websites or online services. (P) Information that reveals the status of an individual as a member of the Armed Forces. (Q) Any other data that a data broker sells, licenses, rents, trades, transfers, releases, discloses, provides access to, or otherwise makes available to a foreign adversary country, or entity that is controlled by a foreign adversary, for the purpose of identifying the types of data listed in subparagraphs (A) through (P). (8) Service providerThe term “service provider” means an entity that—(A) collects, processes, or transfers data on behalf of, and at the direction of—(i) an individual or entity that is not a foreign adversary country or controlled by a foreign adversary; or (ii) a Federal, State, Tribal, territorial, or local government entity; and (B) receives data from or on behalf of an individual or entity described in subparagraph (A)(i) or a Federal, State, Tribal, territorial, or local government entity. (9) United States individualThe term “United States individual” means a natural person residing in the United States. (d) Effective dateThis section shall take effect on the date that is 60 days after April 24, 2024. (Pub. L. 118–50, div. I, § 2, Apr. 24, 2024, 138 Stat. 960.) Editorial Notes References in TextThe Federal Trade Commission Act, referred to in subsec. (b)(2), is act Sept. 26, 1914, ch. 311, 38 Stat. 717, which is classified generally to subchapter I (§ 41 et seq.) of chapter 2 of this title. For complete classification of this Act to the Code, see section 58 of this title and Tables. Statutory Notes and Related Subsidiaries Short TitlePub. L. 118–50, div. I, § 1, Apr. 24, 2024, 138 Stat. 960, provided that: “This division [enacting this chapter] may be cited as the ‘Protecting Americans’ Data from Foreign Adversaries Act of 2024’.” Protecting Americans from Foreign Adversary Controlled ApplicationsPub. L. 118–50, div. H, Apr. 24, 2024, 138 Stat. 955, provided that: Executive Documents Delegation of Authority Under the Protecting Americans From Foreign Adversary Controlled Applications Act Memorandum of President of the United States, July 24, 2024, 89 F.R. 60793, provided: Memorandum for the Secretary of State[,] the Secretary of the Treasury[,] the Secretary of Defense[,] the Attorney General[,] the Secretary of Commerce[,] the Secretary of Homeland Security[, and] the Director of National Intelligence By the authority vested in me as President by the Constitution and the laws of the United States of America, including section 301 of title 3, United States Code, I hereby order as follows: Section 1. (a) I hereby delegate to the Attorney General, in consultation with the Secretary of the Treasury, the Secretary of Commerce, and the Secretary of Homeland Security, all authorities vested in the President by the Protecting Americans from Foreign Adversary Controlled Applications Act (Division H of Public Law 118–50) [set out as a note above]. (b) In exercising the authorities delegated in subsection (a) of this section, the Attorney General may, as appropriate, consult with the Director of National Intelligence and the heads of other relevant executive departments and agencies (agencies). Sec. 2. (a) There is established a Committee for the Review of Foreign Adversary Controlled Applications (Committee), composed of the Secretary of State, the Secretary of the Treasury, the Secretary of Defense, the Attorney General, the Secretary of Commerce, the Secretary of Homeland Security, and the Director of National Intelligence. Not later than 180 days after the date of this memorandum [July 24, 2024], the members of the Committee, through a process convened by National Security Council staff consistent with National Security Memorandum 2 of February 4, 2021 (Renewing the National Security Council System), shall determine rules and procedures sufficient for the Committee to exercise the authorities delegated to the Attorney General under section 1 of this memorandum. Upon conclusion of the 180-day period, the Committee shall exercise those authorities in accordance with such rules and procedures. (b) The Director of National Intelligence and the heads of other relevant agencies, as the Attorney General under section 1 of this memorandum or the Committee under section 2 of this memorandum determines appropriate, shall provide assessments of the threat to national security posed by foreign adversary controlled applications in connection with the discharge of the responsibilities, respectively, of the Attorney General or the Committee. In providing such assessments, the Director of National Intelligence shall solicit and incorporate the views of the Intelligence Community, as appropriate. Sec. 3. The Attorney General is authorized and directed to publish this memorandum in the Federal Register. J.R. Biden, Jr.

Take Action

Your position
Add a comment
to comment on this section.
Annotate the text
Highlight any passage on the Full Text tab to attach a note. Annotations appear on the Annotations tab.