All bills
H.R. 6183·112th Congress·House Bill

Cyber Privacy Fortification Act of 2012

IntroducedTrack

Latest action (25 Jul 2012): Introduced

What this bill does

H.R. 6183, the Cyber Privacy Fortification Act of 2012, would create new federal requirements around data breaches and privacy. It would make it a federal crime, punishable by fine or up to five years in prison, for anyone with a legal obligation to notify people of a security breach involving sensitive personal information (such as Social Security numbers, financial account numbers, or biometric data) to knowingly fail to do so. It would also require entities that experience a "major security breach"—affecting 10,000 or more people, federal databases, or certain federal employees—to promptly report it to the Secret Service or FBI, which would publish an annual list of such breaches. Separately, the bill would let the U.S. Attorney General and state attorneys general pursue civil penalties (up to $500,000, or $1 million for intentional violations) and injunctions against businesses violating future federal data-security laws, with procedures for coordinating state and federal enforcement. It would also require federal agencies to prepare privacy impact assessments when proposing or finalizing rules affecting personal information of 10 or more people, with public comment, periodic review, and judicial review provisions.

The bill would primarily affect businesses and organizations that hold personal data, federal agencies that write rules involving personal information, and individuals whose data is compromised in breaches, who would gain new notification rights and enforcement avenues. State and federal law enforcement and attorneys general would also gain new investigative and enforcement roles.

The bill was introduced in the House on July 25, 2012, by Rep. John Conyers and referred to the House Judiciary Committee. According to the official summary, it did not receive a vote before the 112th Congress ended, meaning it did not become law.

Plain-English summary generated by Bill100 AI from the official record. Always verify against the source below.

Official summary

Cyber Privacy Fortification Act of 2012 - Amends the federal criminal code to provide criminal penalties for intentional failures to provide required notices of a security breach involving sensitive personally identifiable information. Defines "sensitive personally identifiable information" to mean specified electronic or digital information.

Defines "security breach" as a compromise of the security, confidentiality, or integrity of computerized data that there is reason to believe has resulted in improper access to sensitive personally identifiable information.

Requires a person who owns or possesses data in electronic form containing a means of identification and who has knowledge of a major security breach of the system containing such data maintained by such person to provide prompt notice to the U.S. Secret Service or Federal Bureau of Investigation (FBI).

Defines "major security breach" as any security breach involving: (1) means of identification pertaining to at least 10,000 individuals reasonably believed to have been acquired, (2) databases owned by the federal government, or (3) means of identification of federal employees or contractors involved in national security matters or law enforcement.

Authorizes the Attorney General (DOJ) and any state attorney general to bring civil actions and obtain injunctive relief for violations of federal laws relating to data security.

Requires federal agencies as part of their rulemaking process to prepare and make available to the public privacy impact assessments that describe the impact of certain proposed and final agency rules on the privacy of individuals.

Sets forth authority for agencies to waive or delay certain privacy impact assessment requirements for emergencies and national security reasons.

Directs federal agencies to periodically review promulgated rules that have a significant privacy impact on individuals or a privacy impact on a substantial number of individuals. Requires agencies to consider whether each such rule can be amended or rescinded in a manner that minimizes any such impact while remaining in accordance with applicable statutes.

Common questions

What does H.R. 6183 do?
H.R. 6183, the Cyber Privacy Fortification Act of 2012, would create new federal requirements around data breaches and privacy. It would make it a federal crime, punishable by fine or up to five years in prison, for anyone with a legal obligation to notify people of a security breach involving sensitive personal information (such as Social Security numbers, financial account numbers, or biometric data) to knowingly fail to do so. It would also require entities that experience a "major security breach"—affecting 10,000 or more people, federal databases, or certain federal employees—to promptly report it to the Secret Service or FBI, which would publish an annual list of such breaches. Separately, the bill would let the U.S. Attorney General and state attorneys general pursue civil penalties (up to $500,000, or $1 million for intentional violations) and injunctions against businesses violating future federal data-security laws, with procedures for coordinating state and federal enforcement. It would also require federal agencies to prepare privacy impact assessments when proposing or finalizing rules affecting personal information of 10 or more people, with public comment, periodic review, and judicial review provisions. The bill would primarily affect businesses and organizations that hold personal data, federal agencies that write rules involving personal information, and individuals whose data is compromised in breaches, who would gain new notification rights and enforcement avenues. State and federal law enforcement and attorneys general would also gain new investigative and enforcement roles. The bill was introduced in the House on July 25, 2012, by Rep. John Conyers and referred to the House Judiciary Committee. According to the official summary, it did not receive a vote before the 112th Congress ended, meaning it did not become law.
Has H.R. 6183 become law?
Not yet. As of 25 Jul 2012, H.R. 6183 is introduced.
Who sponsored H.R. 6183?
H.R. 6183 was sponsored by Rep. John Conyers [D-MI13, 2013-2017] (Democrat-MI), with 2 cosponsors.
What's the latest action on H.R. 6183?
Introduced (25 Jul 2012).

Related bills in Science, Technology, Communications

Bill100 mirrors the public U.S. legislative record from Congress.gov and GovTrack and adds plain-English AI summaries. It is an information tool, not legal, compliance or lobbying advice, and it is not affiliated with the U.S. Congress or any government agency. AI summaries can simplify or omit detail — every bill links to the official source; verify there before you rely on it.