United States · Bill · HR
H.R. 2205 (114th)
Data Security Act of 2015
Introduced
1 May 2015
Last action
—
Status
Reported (Amended) by the Committee on Financial Services. H. Rept. 114-867, Part I.
Sponsors
—
Subjects
Discovery layer
Source updated
11 December 2025
Summary
Data Security Act of 2015 Requires individuals, corporations, or other non-government entities that access, maintain, communicate, or handle sensitive financial account information or nonpublic personal information to implement an information security program and to notify consumers, federal law enforcement, appropriate administrative agencies, payment card networks, and consumer reporting agencies of certain data breaches of unencrypted sensitive information likely to cause identity theft or fraudulent transactions on consumer financial accounts. Directs entities to require their third-party service providers by contract to implement appropriate safeguards for sensitive information. Allows an entity to delay notifications upon the request of a law enforcement agency. Provides special notification procedures for: (1) third-party service providers that maintain data in electronic form on behalf of another entity, and (2) certain electronic data carriers. Allows financial institutions to communicate with account holders regarding breaches at third-party entities with access to their account information. Sets forth alternative compliance procedures for: (1) financial institutions and affiliates under the Gramm-Leach-Bliley Act, and (2) entities complying with certain health record privacy laws. Requires this Act to be enforced by the Federal Trade Commission, the Comptroller of the Currency, the Federal Reserve System, the Federal Deposit Insurance Corporation, the National Credit Union Administration Board, the Securities and Exchange Commission, the Commodity Futures Trading Commission, the Office of Federal Housing Enterprise Oversight, or a state insurance authority depending on the type of entity handling the sensitive information. Prohibits certain state laws from being imposed for information security and breach notification purposes. Sets forth requirements concerning the application of this Act to entities regulated by the Federal Communications Commission.
This text is taken from the official record. PoliticalRepo does not editorialize.
Timeline
No timeline events have been ingested for this record yet.
Votes
No vote records are attached yet.
Versions
No version snapshots stored. Document URLs remain at the source.
Documents
4 official files
Introduced in House (text)
Reported to House amended, Part I
summary · EN · 12 December 2016
Introduced in House (text)
Introduced in House · EN · 1 May 2015
Introduced in House (PDF)
Introduced in House · EN · 1 May 2015
Introduced in House
summary · EN · 1 May 2015
Sponsors
No sponsors or actors listed by the source.
Related records
No cross-record relationships stored yet.
Sources
PoliticalRepo is an index and interpretation layer, not the authoritative legal source.
- Official source: https://www.congress.gov/bill/114th-congress/house-bill/2205
- Open data entity: https://api.congress.gov/v3/bill/114/hr/2205