S.239 - Notification of Risk to Personal Data Act of 2007 Sponsor: Dianne Feinstein / 110th Congress

Title
110th Congress - A bill to require Federal agencies, and persons engaged in interstate commerce, in possession of data containing sensitive personally identifiable information, to disclose any breach of such information. hidemore...
Summary
A bill to require Federal agencies, and persons engaged in interstate commerce, in possession of data containing sensitive personally identifiable information, to disclose any breach of such information. (by CRS)
Status
The bill has passed through committee and has been put on a legislative calendar.

Customize

Customize the interests supporting and opposing this bill

To remove an interest, click the Remove button next to its name below this box.

To add an interest, choose one from this list:

To add an interest, click Support or Oppose.

You can share your customized pages with other people by sending them the URL for pages about this bill. Other MAPLight.org users will not see your customizations unless they use the URL you send them. To save your customizations for your next visit, create a free New Account, then Sign In.

Done

Interests who did want this bill to become law included these interests and specific groups:

Interests who did not want this bill to become law included these interests and specific groups:

(None found)

Contribution data provided by the Center for Responsive Politics (OpenSecrets.org)

Comments RSS feed

consumer protection? by Joey Nolan, Mar 13, 2008 (7:01pm)

The bill requires any entity engaged in interstate commerce to notify any person whose electronic, sensitive, personally identifiable information, has been, or is reasonably believed to have been breached. Notification must be made to each individual believed to be affected with additional notification to law enforcement and credit reporting agencies under certain circumstances. Critics argue that the “circumstances” allow too much leeway in that the industries determine what “significant risk” or “loss”: is.
Bill S. 239 has been paired with S. 495 the Personal Data Privacy and Security Act, and contains almost identical language. Patrick Leahy (D-Vt)claims the amended bill now enjoys the support of the amended bill now enjoys support from Microsoft, the Center for Democracy and Technology, Consumers Union, Cyber Security Industry Alliance and Consumer Federation of America. (note) Researcher could find no official statement from Microsoft about this bill.