All bills
H.R. 4081·115th Congress·House Bill

Consumer Privacy Protection Act of 2017

IntroducedTrack

Latest action (19 Oct 2017): Introduced

What this bill does

**What the bill would do:** H.R. 4081 would create a federal framework for protecting "sensitive personally identifiable information" (such as Social Security numbers, financial account numbers, biometric data, health information, and precise geolocation data). It would require covered businesses that handle such data on at least 10,000 people annually to establish data security programs with risk assessments, access controls, encryption or similar protections, employee training, and data-minimization plans, enforced by the Federal Trade Commission and state attorneys general. It would also create new federal crimes for intentionally concealing a security breach that causes at least $1,000 in economic harm, require annual reporting on certain computer-crime prosecutions, expand authority to shut down "botnets," and add device manufacturing/distribution offenses related to spying devices to the money-laundering statute. Separately, it would set new requirements for notifying individuals, the FTC, and law enforcement after a security breach.

**Who it affects:** The law would apply to businesses (for-profit and nonprofit) that collect or store sensitive personal data on a large scale, with exemptions for entities already regulated under the Gramm-Leach-Bliley Act (financial institutions) or HIPAA/HITECH (health entities), and for certain service providers. It would affect consumers whose data is compromised, by establishing notification and assistance requirements, and would give federal and state law enforcement expanded tools against cybercrime.

**Status:** The bill was introduced October 19, 2017, in the 115th Congress by Rep. David Cicilline and referred to the House Judiciary Committee, along with several other committees. It has not received a vote and did not become law.

Plain-English summary generated by Bill100 AI from the official record. Always verify against the source below.

Official summary

Consumer Privacy Protection Act of 2017

This bill amends the federal criminal code to make it a crime to intentionally and willfully conceal knowledge of a security breach that results in economic harm of at least $1,000 to any individual.

It imposes criminal penalties on a violator and authorizes the U.S. Secret Service and the Federal Bureau of Investigation to investigate offenses.

The bill authorizes the Department of Justice (DOJ) to file a civil action: (1) to prevent ongoing conduct that damages 100 or more protected computers (e.g., government computers); and (2) to prevent the disposition of unlawfully obtained property.

The bill also adds to the list of money laundering predicate offenses financial transactions that involve proceeds of unlawful manufacturing, distribution, possession, and advertising of wire, oral, or electronic communication intercepting devices.

Finally, the bill requires certain commercial entities to implement a comprehensive consumer privacy and data security program.

A commercial entity must notify a U.S. resident whose sensitive personally identifiable information (PII) has been, or is reasonably believed to have been, accessed or acquired. Sensitive PII includes electronic or digital forms of personal, financial, health, and biometric data, geographic location, and password-protected photographs and videos.

It establishes civil penalties for violations and authorizes DOJ, the Federal Trade Commission, and states to enforce compliance.

Common questions

What does H.R. 4081 do?
**What the bill would do:** H.R. 4081 would create a federal framework for protecting "sensitive personally identifiable information" (such as Social Security numbers, financial account numbers, biometric data, health information, and precise geolocation data). It would require covered businesses that handle such data on at least 10,000 people annually to establish data security programs with risk assessments, access controls, encryption or similar protections, employee training, and data-minimization plans, enforced by the Federal Trade Commission and state attorneys general. It would also create new federal crimes for intentionally concealing a security breach that causes at least $1,000 in economic harm, require annual reporting on certain computer-crime prosecutions, expand authority to shut down "botnets," and add device manufacturing/distribution offenses related to spying devices to the money-laundering statute. Separately, it would set new requirements for notifying individuals, the FTC, and law enforcement after a security breach. **Who it affects:** The law would apply to businesses (for-profit and nonprofit) that collect or store sensitive personal data on a large scale, with exemptions for entities already regulated under the Gramm-Leach-Bliley Act (financial institutions) or HIPAA/HITECH (health entities), and for certain service providers. It would affect consumers whose data is compromised, by establishing notification and assistance requirements, and would give federal and state law enforcement expanded tools against cybercrime. **Status:** The bill was introduced October 19, 2017, in the 115th Congress by Rep. David Cicilline and referred to the House Judiciary Committee, along with several other committees. It has not received a vote and did not become law.
Has H.R. 4081 become law?
Not yet. As of 19 Oct 2017, H.R. 4081 is introduced.
Who sponsored H.R. 4081?
H.R. 4081 was sponsored by Rep. David Cicilline [D-RI1, 2011-2023] (Democrat-RI), with 11 cosponsors.
What's the latest action on H.R. 4081?
Introduced (19 Oct 2017).

Related bills in Crime and Law Enforcement

Bill100 mirrors the public U.S. legislative record from Congress.gov and GovTrack and adds plain-English AI summaries. It is an information tool, not legal, compliance or lobbying advice, and it is not affiliated with the U.S. Congress or any government agency. AI summaries can simplify or omit detail — every bill links to the official source; verify there before you rely on it.