United States · Bill · HR
H.R. 4791 (110th)
Federal Agency Data Protection Act
Introduced
18 December 2007
Last action
—
Status
Received in the Senate and Read twice and referred to the Committee on Homeland Security and Governmental Affairs.
Sponsors
—
Subjects
Discovery layer
Source updated
7 April 2025
Summary
Federal Agency Data Protection Act - Defines "personally identifiable information" as any information about an individual maintained by a federal agency, including information about the individual's education, finances, medical, criminal, or employment history, that can be used to distinguish or trace such individual's identity or that is linked or linkable to the individual. Includes within the information security duties of the Director of the Office of Management and Budget (OMB): (1) the establishment of minimum requirements for the protection of information maintained in or transmitted by mobile digital devices, including requirements for the encryption of such information or the use of technologies that render information unusable by unauthorized persons; (2) the establishment of minimum requirements for agency actions following a breach of information security; (3) notification of individuals whose personally identifiable information may have been compromised or accessed during a security breach; and (4) requiring agencies to comply with minimally acceptable system configuration requirements consistent with best practices. Requires federal agencies to: (1) adopt plans and procedures for ensuring the adequacy of information security protections for systems maintaining or transmitting personally identifiable information; (2) develop and implement a plan to protect the security and privacy of federal government computers and networks from the risks posed by peer-to-peer file sharing; and (3) undergo audits (currently, evaluations are required) of their information programs and practices. Amends the E-Government Act of 2002 to prohibit agencies from contracting with data brokers to access information on U.S. persons unless agency head completes a privacy impact assessment and implements other safeguards. Extends the authorization of appropriations for information security programs through FY 2012.
This text is taken from the official record. PoliticalRepo does not editorialize.
Timeline
No timeline events have been ingested for this record yet.
Votes
No vote records are attached yet.
Versions
No version snapshots stored. Document URLs remain at the source.
Documents
10 official files
Referred in Senate (text)
Referred in Senate (text)
Referred in Senate · EN · 4 June 2008
Referred in Senate (PDF)
Referred in Senate · EN · 4 June 2008
Engrossed in House (text)
Engrossed in House · EN · 3 June 2008
Engrossed in House (PDF)
Engrossed in House · EN · 3 June 2008
Passed House amended
summary · EN · 3 June 2008
Reported in House (text)
Reported in House · EN · 21 May 2008
Reported in House (PDF)
Reported in House · EN · 21 May 2008
Introduced in House (text)
Introduced in House · EN · 18 December 2007
Introduced in House (PDF)
Introduced in House · EN · 18 December 2007
Introduced in House
summary · EN · 18 December 2007
Sponsors
No sponsors or actors listed by the source.
Related records
No cross-record relationships stored yet.
Sources
PoliticalRepo is an index and interpretation layer, not the authoritative legal source.
- Official source: https://www.congress.gov/bill/110th-congress/house-bill/4791
- Open data entity: https://api.congress.gov/v3/bill/110/hr/4791