All bills
S. 1158·114th Congress·Senate Bill

Consumer Privacy Protection Act of 2015

IntroducedTrack

Latest action (30 Apr 2015): Introduced

What this bill does

Here is a neutral summary of S. 1158:

The Consumer Privacy Protection Act of 2015 would establish federal requirements for businesses that handle "sensitive personally identifiable information," such as Social Security numbers, financial account numbers, biometric data, and certain health or location information. Covered businesses handling such data for at least 10,000 people over a 12-month period would need to maintain a written data security program with risk assessments, safeguards, employee training, and vulnerability testing, enforced by the FTC and state attorneys general. The bill would also require notice to affected individuals, credit reporting agencies, the FTC, and law enforcement after a security breach, with certain exemptions. Separately, it would create a new federal crime for knowingly and willfully concealing a security breach, expand authority to shut down "botnets," add cybercrime-reporting requirements for the Justice Department, and address devices used for unauthorized surveillance.

The bill would primarily affect businesses that collect or store sensitive personal data (with exceptions for entities already regulated under financial-privacy or health-privacy laws, and for certain service providers), as well as consumers whose data is compromised, who would gain new notification rights. Law enforcement agencies, including the FBI and Secret Service, would receive additional investigative authority under the bill.

The bill was introduced by Senator Patrick Leahy on April 30, 2015, with several cosponsors, and referred to the Senate Judiciary Committee. It did not receive a committee vote or further action and did not become law.

Plain-English summary generated by Bill100 AI from the official record. Always verify against the source below.

Official summary

Consumer Privacy Protection Act of 2015

Establishes a criminal offense for concealment of a security breach of computerized data containing sensitive personally identifiable information that results in economic harm of $1,000 or more to any individual.

Authorizes the Department of Justice (DOJ) to commence a civil action to enjoin unauthorized persons or entities from accessing or transmitting computer commands commonly referred to as botnets that would impair the integrity or availability of 100 or more computers used by financial institutions or the federal government or that affect interstate or foreign commerce or communications during any one-year period, including by denying access to the computers, installing unwanted software, or obtaining information without authorization. Allows DOJ to enjoin the alienation or disposal of, or to seek restraining orders prohibiting the disposal of, property obtained as a result of such a violation.

Expands categories of money laundering offenses to include financial transactions involving the proceeds of unlawful manufacturing, distribution, possession, and advertising of wire, oral, or electronic communication intercepting devices.

Requires certain business entities that collect, use, access, transmit, store, or dispose of sensitive personally identifiable information in electronic or digital form of 10,000 or more U.S. persons during any 12-month period to implement a consumer privacy and data security program that complies with safeguards identified by the Federal Trade Commission (FTC).

Requires entities, following discovery of a security breach, to notify U.S. residents whose unencrypted personal information is reasonably believed to have been accessed or acquired. Sets forth special notification procedures for: (1) third party entities that maintain or process data in electronic form on behalf of another entity; and (2) certain providers of electronic data transmission, routing, storage, or network connection services.

Directs entities to notify a federal entity designated by the Department of Homeland Security (DHS) if a security breach involves: (1) the personal information of more than 5,000 individuals, (2) databases containing the personal information of more than 500,000 individuals nationwide, (3) federal databases, or (4) federal employees and contractors involved in national security or law enforcement. Requires the DHS-designated entity to provide the information it receives to: (1) the U.S. Secret Service or the Federal Bureau of Investigation for law enforcement purposes; and (2) other federal agencies for law enforcement, national security, or data security purposes. Establishes a process for DOJ to adjust the thresholds for law enforcement and national security notifications.

Requires notice of certain breaches to be provided to consumer reporting agencies and the FTC.

Common questions

What does S. 1158 do?
Here is a neutral summary of S. 1158: The Consumer Privacy Protection Act of 2015 would establish federal requirements for businesses that handle "sensitive personally identifiable information," such as Social Security numbers, financial account numbers, biometric data, and certain health or location information. Covered businesses handling such data for at least 10,000 people over a 12-month period would need to maintain a written data security program with risk assessments, safeguards, employee training, and vulnerability testing, enforced by the FTC and state attorneys general. The bill would also require notice to affected individuals, credit reporting agencies, the FTC, and law enforcement after a security breach, with certain exemptions. Separately, it would create a new federal crime for knowingly and willfully concealing a security breach, expand authority to shut down "botnets," add cybercrime-reporting requirements for the Justice Department, and address devices used for unauthorized surveillance. The bill would primarily affect businesses that collect or store sensitive personal data (with exceptions for entities already regulated under financial-privacy or health-privacy laws, and for certain service providers), as well as consumers whose data is compromised, who would gain new notification rights. Law enforcement agencies, including the FBI and Secret Service, would receive additional investigative authority under the bill. The bill was introduced by Senator Patrick Leahy on April 30, 2015, with several cosponsors, and referred to the Senate Judiciary Committee. It did not receive a committee vote or further action and did not become law.
Has S. 1158 become law?
Not yet. As of 30 Apr 2015, S. 1158 is introduced.
Who sponsored S. 1158?
S. 1158 was sponsored by Sen. Patrick Leahy [D-VT, 1975-2022] (Democrat-VT), with 5 cosponsors.
What's the latest action on S. 1158?
Introduced (30 Apr 2015).

Related bills in Crime and Law Enforcement

Bill100 mirrors the public U.S. legislative record from Congress.gov and GovTrack and adds plain-English AI summaries. It is an information tool, not legal, compliance or lobbying advice, and it is not affiliated with the U.S. Congress or any government agency. AI summaries can simplify or omit detail — every bill links to the official source; verify there before you rely on it.