House Passes Data Accountability and Trust Act (DATA)

On December 8, 2009, the Data Accountability and Trust Act -- HR 2221(DATA) moved one step closer to law by passing the House of Representatives.  DATA is sponsored by Congressman Bobby Rush (D-IL).  Note that the InfoLawGroup has previously commented on similar data security bills currently pending in the Senate.  The DATA in Congress has similar elements as Senator Leahy's S. 1490, the Personal Data Privacy and Security Act, including not only breach notice obligations, but also information security policy requirements.

Both the Leahy and Rush bills also impose increased obligations on "information brokers," defined as follows in the Rush bill:

(6) INFORMATION BROKER- The term `information broker'--

(A) means a commercial entity whose business is to collect, assemble, or maintain personal information concerning individuals who are not current or former customers of such entity in order to sell such information or provide access to such information to any nonaffiliated third party in exchange for consideration, whether such collection, assembly, or maintenance of personal information is performed by the information broker directly, or by contract or subcontract with any other entity; and

(B) does not include a commercial entity to the extent that such entity processes information collected by and received from a nonaffiliated third party concerning individuals who are current or former customers or employees of such third party to enable such third party to (1) provide benefits for its employees or (2) directly transact business with its customers.

(the Leahy bill uses the term "data broker", but has a similar definition).  Information brokers would be required to submit their security policies to the FTC in the event their breach notice obligations where triggered.  Moreover, the DATA imposes obligations on information brokers concerning data accuracy, data access and disputed data.  Information brokers would also be required to maintain audit logs or similar measures "which facilitate the auditing or retracing of any internal or external access to, or transmissions of, any data containing personal information collected, assembled, or maintained by such information broker."

While sometimes touted as a "national" data security law, the DATA appears to apply only to those entities regulated by the FTC:

The requirements of sections 2 and 3 shall only apply to those persons, partnerships, or corporations over which the Commission has authority pursuant to section 5(a)(2) of the Federal Trade Commission Act.

As such, it would not appear to apply to financial institutions, insurance companies, governmental bodies or common carriers (e.g. telecommunications companies or transportation companies).

Please note, while passage of DATA by the House is a major milestone, there may still be a long way before DATA becomes law.  The Senate will have to pass their version of the bill and then it would have to go through reconciliation.  Stay tuned.