Cyber Privacy Fortification Act of 2013
Latest action (13 Mar 2013): Introduced
What this bill does
H.R. 1121, the Cyber Privacy Fortification Act of 2013, would create new federal requirements around data breaches and privacy in rulemaking. It would make it a federal crime, punishable by fine or up to five years in prison, for a person or entity with a legal obligation to notify affected individuals of a security breach involving sensitive personal information—such as Social Security numbers, financial account numbers, or biometric data—to knowingly fail to do so. It would also require anyone holding data on 10,000 or more individuals to promptly report major breaches to the Secret Service or FBI, which would publish annual lists of such notifications. Separately, the bill would let the U.S. Attorney General and state attorneys general pursue civil penalties (up to $500,000, or $1,000,000 for intentional violations) and injunctions against businesses violating future federal data security laws, with coordination rules between state and federal enforcement. Finally, it would require federal agencies to prepare privacy impact assessments when proposing or finalizing rules affecting personal information, with public comment, periodic review, and judicial review provisions.
The bill would primarily affect businesses and organizations that collect or store personal data, federal agencies engaged in rulemaking, and individuals whose personal information could be exposed in breaches. It would give federal and state authorities new enforcement tools and give individuals a mechanism to challenge agency rules that fail to adequately assess privacy impacts.
The bill was introduced in the House on March 13, 2013, by Rep. John Conyers and referred to the House Judiciary Committee. It did not receive a vote and did not advance further in the 113th Congress.
Plain-English summary generated by Bill100 AI from the official record. Always verify against the source below.
Official summary
Cyber Privacy Fortification Act of 2013 - Amends the federal criminal code to provide criminal penalties for intentional failures to provide required notices of a security breach involving sensitive personally identifiable information. Defines "sensitive personally identifiable information" to mean specified electronic or digital information.
Defines "security breach" as a compromise of the security, confidentiality, or integrity of computerized data that there is reason to believe has resulted in improper access to sensitive personally identifiable information.
Requires a person who owns or possesses data in electronic form containing a means of identification and who has knowledge of a major security breach of the system containing such data maintained by such person to provide prompt notice to the U.S. Secret Service or Federal Bureau of Investigation (FBI).
Defines "major security breach" as any security breach involving: (1) means of identification pertaining to at least 10,000 individuals reasonably believed to have been acquired, (2) databases owned by the federal government, or (3) means of identification of federal employees or contractors involved in national security matters or law enforcement.
Authorizes the Attorney General (DOJ) and any state attorney general to bring civil actions and obtain injunctive relief for violations of federal laws relating to data security.
Requires federal agencies as part of their rulemaking process to prepare and make available to the public privacy impact assessments that describe the impact of certain proposed and final agency rules on the privacy of individuals.
Sets forth authority for agencies to waive or delay certain privacy impact assessment requirements for emergencies and national security reasons.
Directs federal agencies to periodically review promulgated rules that have a significant privacy impact on individuals or a privacy impact on a substantial number of individuals. Requires agencies to consider whether each such rule can be amended or rescinded in a manner that minimizes any such impact while remaining in accordance with applicable statutes.
Common questions
- What does H.R. 1121 do?
- H.R. 1121, the Cyber Privacy Fortification Act of 2013, would create new federal requirements around data breaches and privacy in rulemaking. It would make it a federal crime, punishable by fine or up to five years in prison, for a person or entity with a legal obligation to notify affected individuals of a security breach involving sensitive personal information—such as Social Security numbers, financial account numbers, or biometric data—to knowingly fail to do so. It would also require anyone holding data on 10,000 or more individuals to promptly report major breaches to the Secret Service or FBI, which would publish annual lists of such notifications. Separately, the bill would let the U.S. Attorney General and state attorneys general pursue civil penalties (up to $500,000, or $1,000,000 for intentional violations) and injunctions against businesses violating future federal data security laws, with coordination rules between state and federal enforcement. Finally, it would require federal agencies to prepare privacy impact assessments when proposing or finalizing rules affecting personal information, with public comment, periodic review, and judicial review provisions. The bill would primarily affect businesses and organizations that collect or store personal data, federal agencies engaged in rulemaking, and individuals whose personal information could be exposed in breaches. It would give federal and state authorities new enforcement tools and give individuals a mechanism to challenge agency rules that fail to adequately assess privacy impacts. The bill was introduced in the House on March 13, 2013, by Rep. John Conyers and referred to the House Judiciary Committee. It did not receive a vote and did not advance further in the 113th Congress.
- Has H.R. 1121 become law?
- Not yet. As of 13 Mar 2013, H.R. 1121 is introduced.
- Who sponsored H.R. 1121?
- H.R. 1121 was sponsored by Rep. John Conyers [D-MI13, 2013-2017] (Democrat-MI), with 2 cosponsors.
- What's the latest action on H.R. 1121?
- Introduced (13 Mar 2013).
Related bills in Science, Technology, Communications
Open-Source AI Leadership Act
AI for Secure Networks Act
Memory Chip Competitiveness Assessment Act of 2026
ITS Codification Act
Bill100 mirrors the public U.S. legislative record from Congress.gov and GovTrack and adds plain-English AI summaries. It is an information tool, not legal, compliance or lobbying advice, and it is not affiliated with the U.S. Congress or any government agency. AI summaries can simplify or omit detail — every bill links to the official source; verify there before you rely on it.