All bills
H.R. 135·115th Congress·House Bill

Cyber Privacy Fortification Act of 2017

IntroducedTrack

Latest action (3 Jan 2017): Introduced

What this bill does

H.R. 135, the Cyber Privacy Fortification Act of 2017, would create new federal requirements around data breach notification and agency rulemaking involving personal information. Title I would make it a federal crime, punishable by fine, up to five years in prison, or both, for a person or entity with a legal obligation to notify individuals of a data breach involving sensitive personally identifiable information (such as Social Security numbers, financial account numbers, or biometric data) to knowingly fail to do so. It would also require anyone who owns or possesses data involved in a "major security breach"—affecting 10,000 or more people, federal databases, or certain federal employees—to promptly report it to the Secret Service or FBI, which would publish annual lists of such breaches. Title II would let the U.S. Attorney General and state attorneys general sue businesses that violate future federal data-security laws, seeking civil penalties up to $500,000 (or $1,000,000 for intentional violations) and injunctions, with coordination rules between state and federal actions. It would also require federal agencies to prepare privacy impact assessments, subject to public comment and periodic review, before issuing certain rules affecting personal data.

The bill would primarily affect businesses and other entities that collect or hold sensitive personal data, federal agencies that write rules involving personal information, and individuals whose data is compromised in breaches, who would gain notification rights and potential legal remedies.

The bill was introduced by Rep. John Conyers on January 3, 2017, and referred to the House Committee on the Judiciary. According to official records, it did not receive a vote and saw no further action before the end of the 115th Congress.

Plain-English summary generated by Bill100 AI from the official record. Always verify against the source below.

Official summary

Cyber Privacy Fortification Act of 2017

This bill amends the federal criminal code to provide criminal penalties for intentional failures to provide required notices regarding security breaches of computerized data that there is reason to believe resulted in improper access to specified sensitive personally identifiable information that is electronic or digital.

A person who owns or possesses data in electronic form containing a means of identification, and who has knowledge of a major security breach of the system containing such data, must notify the U.S. Secret Service or the Federal Bureau of Investigation.

A "major security breach" involves: (1) a means of identification pertaining to at least 10,000 individuals that is reasonably believed to have been acquired, (2) databases owned by the federal government, or (3) a means of identification of federal employees or contractors involved in national security matters or law enforcement.

The Department of Justice and state attorneys general may bring civil actions and obtain injunctive relief for violations of federal laws relating to data security.

Federal agencies must prepare and make available to the public privacy impact assessments that describe the impact of certain proposed and final agency rules on the privacy of individuals. Agencies may waive or delay certain privacy impact assessment requirements for emergencies and national security reasons.

Federal agencies must: (1) periodically review promulgated rules that have a significant privacy impact on individuals or a privacy impact on a substantial number of individuals, and (2) consider whether each such rule can be amended or rescinded in a manner that minimizes any such impact while remaining in accordance with applicable statutes.

The bill provides access to judicial review to individuals adversely affected or aggrieved by final agency action on any such rule.

Common questions

What does H.R. 135 do?
H.R. 135, the Cyber Privacy Fortification Act of 2017, would create new federal requirements around data breach notification and agency rulemaking involving personal information. Title I would make it a federal crime, punishable by fine, up to five years in prison, or both, for a person or entity with a legal obligation to notify individuals of a data breach involving sensitive personally identifiable information (such as Social Security numbers, financial account numbers, or biometric data) to knowingly fail to do so. It would also require anyone who owns or possesses data involved in a "major security breach"—affecting 10,000 or more people, federal databases, or certain federal employees—to promptly report it to the Secret Service or FBI, which would publish annual lists of such breaches. Title II would let the U.S. Attorney General and state attorneys general sue businesses that violate future federal data-security laws, seeking civil penalties up to $500,000 (or $1,000,000 for intentional violations) and injunctions, with coordination rules between state and federal actions. It would also require federal agencies to prepare privacy impact assessments, subject to public comment and periodic review, before issuing certain rules affecting personal data. The bill would primarily affect businesses and other entities that collect or hold sensitive personal data, federal agencies that write rules involving personal information, and individuals whose data is compromised in breaches, who would gain notification rights and potential legal remedies. The bill was introduced by Rep. John Conyers on January 3, 2017, and referred to the House Committee on the Judiciary. According to official records, it did not receive a vote and saw no further action before the end of the 115th Congress.
Has H.R. 135 become law?
Not yet. As of 3 Jan 2017, H.R. 135 is introduced.
Who sponsored H.R. 135?
H.R. 135 was sponsored by Rep. John Conyers [D-MI13, 2013-2017] (Democrat-MI), with 1 cosponsor.
What's the latest action on H.R. 135?
Introduced (3 Jan 2017).

Related bills in Science, Technology, Communications

Bill100 mirrors the public U.S. legislative record from Congress.gov and GovTrack and adds plain-English AI summaries. It is an information tool, not legal, compliance or lobbying advice, and it is not affiliated with the U.S. Congress or any government agency. AI summaries can simplify or omit detail — every bill links to the official source; verify there before you rely on it.