United States · Bill · S
S. 1535 (112th)
Personal Data Protection and Breach Accountability Act of 2011
Introduced
8 September 2011
Last action
—
Status
Placed on Senate Legislative Calendar under General Orders. Calendar No. 182.
Sponsors
—
Subjects
Discovery layer
Source updated
10 August 2026
Summary
Personal Data Protection and Breach Accountability Act of 2011 - Amends the federal criminal code to: (1) establish fraud in connection with the unauthorized access of personally identifiable information as a predicate for a racketeering prosecution, (2) prohibit concealment of security breaches involving sensitive personally identifiable information, and (3) impose criminal penalties for conspiracies to commit fraud in connection with computers. Imposes a criminal penalty for sending false or intentionally misleading notifications of a security breach in order to obtain sensitive personally identifiable information in an effort to defraud an individual. Makes it unlawful to install, without authorization, software that collects sensitive personally identifiable information from an authorized user. Makes an interstate business entity that collects, accesses, transmits, uses, stores, or disposes of sensitive personally identifiable information in electronic or digital form on 10,000 or more U.S. persons subject to the data privacy and security safeguards of this Act. Requires such business entities to notify: (1) any U.S. resident whose sensitive personally identifiable information has been, or is reasonably believed to have been, accessed or acquired, (2) all nationwide consumer reporting agencies if an entity is required to notify more than 5,000 such individuals, and (3) the U.S. Secret Service and the Federal Bureau of Investigation (FBI) if the number of individuals involved exceeds 5,000. Allows an exemption from such notice requirements to prevent damage to the national security or hindrance to a law enforcement investigation. Authorizes the Attorney General and state attorneys general to bring civil actions against business entities and seek civil penalties for violations of this Act. Authorizes individuals aggrieved by a violation of this Act to bring a civil action to recover for personal injuries resulting from such violation. Requires the Attorney General to maintain a clearinghouse of technical information concerning system vulnerabilities identified in the wake of security breaches. Requires the Administrator of the General Services Administration (GSA), in considering contract awards totaling more than $500,000, to evaluate: (1) the data privacy and security program of a data broker and the broker's compliance with such program, (2) the extent to which databases and systems have been compromised by security breaches, and (3) data broker responses to such breaches. Defines a "data broker" as a business entity that collects, transmits, or provides access to sensitive personally identifiable information on more than 5,000 individuals who are not the customers or employees of that business entity for purposes of providing such information to non-affiliated third parties on an interstate basis. Requires federal agency information security programs to include procedures for evaluating and auditing the information security practices of contractors or third party business entities supporting the agency information systems or operations involving personally identifiable information and for ensuring remedial action to address any significant deficiencies. Requires federal agencies to conduct a privacy impact assessment before purchasing or subscribing to personally identifiable information from a data broker. Requires annual reports by: (1) the FBI on reported security breaches at agencies or businesses in the preceding year and the effectiveness of post-breach notification practices by such agencies and businesses, and (2) the Attorney General on enforcement actions taken in the previous year to address violations of this Act.
This text is taken from the official record. PoliticalRepo does not editorialize.
Timeline
No timeline events have been ingested for this record yet.
Votes
No vote records are attached yet.
Versions
No version snapshots stored. Document URLs remain at the source.
Documents
6 official files
Reported to Senate (text)
Reported to Senate · EN · 22 September 2011
Reported to Senate (PDF)
Reported to Senate · EN · 22 September 2011
Reported to Senate with amendment(s)
summary · EN · 22 September 2011
Introduced in Senate (text)
Introduced in Senate · EN · 8 September 2011
Introduced in Senate (PDF)
Introduced in Senate · EN · 8 September 2011
Introduced in Senate
summary · EN · 8 September 2011
Sponsors
No sponsors or actors listed by the source.
Related records
No cross-record relationships stored yet.
Sources
PoliticalRepo is an index and interpretation layer, not the authoritative legal source.
- Official source: https://www.congress.gov/bill/112th-congress/senate-bill/1535
- Open data entity: https://api.congress.gov/v3/bill/112/s/1535