All bills
H.R. 4175·110th Congress·House Bill

Privacy and Cybercrime Enforcement Act of 2007

IntroducedTrack

Latest action (14 Nov 2007): Introduced

What this bill does

Here is a neutral, plain-English summary based only on the provided text:

H.R. 4175, the Privacy and Cybercrime Enforcement Act of 2007, would amend federal law to address computer crime and data privacy. It would add computer fraud (18 U.S.C. § 1030) to the list of offenses covered by federal racketeering (RICO) law, create a new federal crime for knowingly failing to provide legally required notice of a security breach involving sensitive personal information (punishable by fine and up to five years in prison), and require entities that experience a "major security breach" affecting 10,000 or more people, federal databases, or certain federal personnel to report it to the Secret Service or FBI. It would broaden computer-crime jurisdiction, add cyber-extortion and conspiracy offenses, increase maximum penalties under Section 1030, allow criminal forfeiture and victim restitution for time spent remediating harm, and direct the U.S. Sentencing Commission to review related sentencing guidelines. It also would authorize the Attorney General and state attorneys general to seek civil penalties (up to $500,000, or $1,000,000 for intentional violations) and injunctions against businesses violating future federal data-security laws, require coordination between state and federal enforcement, and require federal agencies to prepare privacy impact assessments when rulemaking affects personal information. It also authorizes funding for federal cybercrime investigation/prosecution resources and for state/local law enforcement grants and the National White Collar Crime Center.

This bill would primarily affect businesses that hold personal data, federal agencies, and federal and state law enforcement and prosecutors, by creating new criminal and civil liability for data breaches and mishandling of personal information, new enforcement authority for the Justice Department and states, and new procedural requirements for agency rulemaking.

The bill was introduced in the House on November 14, 2007, by Rep. John Conyers with several cosponsors, and referred to the House Judiciary Committee. According to the official record, it did not receive a vote and did not advance further in the 110th Congress.

Plain-English summary generated by Bill100 AI from the official record. Always verify against the source below.

Official summary

Privacy and Cybercrime Enforcement Act of 2007 - Amends federal criminal code provisions relating to computer fraud and unauthorized access to computers to: (1) include computer fraud within the definition of racketeering activity; (2) provide criminal penalties for intentional failures to provide required notices of a security breach involving sensitive personally identifiable information; (3) expand penalties for conspiracies to commit computer fraud and extortion attempts involving threats to access computers without authorization; (4) provide for forfeiture of property used to commit computer fraud; and (5) require restitution for victims of identity theft and computer fraud.

Authorizes additional appropriations for investigating and prosecuting criminal activity involving computers.

Directs the U.S. Sentencing Commission to review and amend, if appropriate, its sentencing guidelines and policies related to identity theft and computer fraud offenses.

Authorizes the Attorney General and state attorneys general to bring civil actions and obtain injunctive relief for violations of federal laws relating to data security.

Requires federal agencies as part of their rulemaking process to prepare and make available to the public privacy impact assessments that describe the impact of proposed agency rules on the privacy of individuals.

Authorizes the Office of Justice Programs of the Department of Justice (DOJ) to award grants to states for programs to increase enforcement efforts involving fraudulent, unauthorized, or other criminal use of personally identifiable information.

Authorizes the Director of the Bureau of Justice Assistance to make grants to improve the identification, investigation, and prosecution of criminal or terrorist conspiracies or activities that span jurisdictional boundaries, including terrorism, economic crime, and high-tech crime.

Common questions

What does H.R. 4175 do?
Here is a neutral, plain-English summary based only on the provided text: H.R. 4175, the Privacy and Cybercrime Enforcement Act of 2007, would amend federal law to address computer crime and data privacy. It would add computer fraud (18 U.S.C. § 1030) to the list of offenses covered by federal racketeering (RICO) law, create a new federal crime for knowingly failing to provide legally required notice of a security breach involving sensitive personal information (punishable by fine and up to five years in prison), and require entities that experience a "major security breach" affecting 10,000 or more people, federal databases, or certain federal personnel to report it to the Secret Service or FBI. It would broaden computer-crime jurisdiction, add cyber-extortion and conspiracy offenses, increase maximum penalties under Section 1030, allow criminal forfeiture and victim restitution for time spent remediating harm, and direct the U.S. Sentencing Commission to review related sentencing guidelines. It also would authorize the Attorney General and state attorneys general to seek civil penalties (up to $500,000, or $1,000,000 for intentional violations) and injunctions against businesses violating future federal data-security laws, require coordination between state and federal enforcement, and require federal agencies to prepare privacy impact assessments when rulemaking affects personal information. It also authorizes funding for federal cybercrime investigation/prosecution resources and for state/local law enforcement grants and the National White Collar Crime Center. This bill would primarily affect businesses that hold personal data, federal agencies, and federal and state law enforcement and prosecutors, by creating new criminal and civil liability for data breaches and mishandling of personal information, new enforcement authority for the Justice Department and states, and new procedural requirements for agency rulemaking. The bill was introduced in the House on November 14, 2007, by Rep. John Conyers with several cosponsors, and referred to the House Judiciary Committee. According to the official record, it did not receive a vote and did not advance further in the 110th Congress.
Has H.R. 4175 become law?
Not yet. As of 14 Nov 2007, H.R. 4175 is introduced.
Who sponsored H.R. 4175?
H.R. 4175 was sponsored by Rep. John Conyers [D-MI13, 2013-2017] (Democrat-MI), with 7 cosponsors.
What's the latest action on H.R. 4175?
Introduced (14 Nov 2007).

Related bills in Crime and Law Enforcement

Bill100 mirrors the public U.S. legislative record from Congress.gov and GovTrack and adds plain-English AI summaries. It is an information tool, not legal, compliance or lobbying advice, and it is not affiliated with the U.S. Congress or any government agency. AI summaries can simplify or omit detail — every bill links to the official source; verify there before you rely on it.