Search bills, members, committees and pages...
881. Disclosing of personal information with the intent to cause harm
(a) In general
Whoever uses a channel of interstate or foreign commerce to knowingly disclose an individual’s personal information with the intent—(1) to threaten, intimidate, or harass any person, incite or facilitate the commission of a crime of violence against any person, or place any person in reasonable fear of death or serious bodily injury; or(2) that the information will be used to threaten, intimidate, or harass any person, incite or facilitate the commission of a crime of violence against any person, or place any person in reasonable fear of death or serious bodily injury,shall be fined under this title or imprisoned not more than 5 years, or both.(b) Digital Privacy Agency
(1) Support functions
The Director of the Digital Privacy Agency may—(A) receive complaints and refer credible complaints to the Attorney General;(B) coordinate with appropriate law enforcement agencies to support investigations; and(C) provide technical assistance upon the request of the Attorney General.(2) Rule of construction
Nothing in this section shall be construed to authorize the Digital Privacy Agency to prosecute an offense under this section.(c) Definitions
In this section:(1) Contents
The term contents when used with respect to communication, has the meaning given such term in section 2510 of this title.(2) Disclose
The term disclose means, with respect to personal information or contents of communication, to sell, release, transfer, share, disseminate, make available, or otherwise cause to be communicated such information or contents to a third party.(3) Government entity
The term government entity means—(A) a Federal agency (as that term is defined in section 3371 of title 5);(B) a State or political subdivision thereof; or(C) any agency, authority, or instrumentality of a State or political subdivision thereof.(4) Individual
The term individual means a natural person residing in the United States.(5) Personal information
(A) In general
The term personal information means any information maintained by a person that, on its own or combined with other information, is linked or reasonably linkable to a specific individual.(B) Exclusions
The term personal information does not include—(i) publicly available information linked to an individual; or(ii) information derived or inferred from personal information, if the derived or inferred information is not linked or reasonably linkable to a specific individual.(6) Publicly available information
The term publicly available information—(A) means—(i) information that is lawfully made available from a government entity;(ii) information linked to a public individual or official that is made publicly accessible, without restrictions on accessibility other than the general authorization to access the services used to make the information accessible; or(iii) information of an individual that—(I) is made publicly accessible by such individual, without restrictions on accessibility other than the general authorization to access the services used to make the information accessible; and(II) such individual has the ability to delete or change; and(B) does not include—(i) biometric information of an individual collected by a covered entity without the individual’s knowledge;(ii) information used for a purpose that is not compatible with the purpose for which the information is maintained and made available in government records;(iii) information obtained from government records for the purpose of selling such information; or(iv) information used to contact or locate a private individual either physically or electronically.(7) State
The term State means each State of the United States, the District of Columbia, each commonwealth, territory, or possession of the United States, and each federally recognized Indian Tribe.
881. Disclosing of personal information with the intent to cause harm.
(f) Privacy risk management research
In carrying out the activities under subsection (c)(19), the Director, in consultation and collaboration with the Director of the Digital Privacy Agency, shall, to the extent practicable and appropriate carry out the following:(1) Develop, and periodically update, in collaboration with appropriate Federal agencies, industry, State, local, and Tribal governments, civil society, other nonprofit organizations, and the Information Security and Privacy Advisory Board, a privacy risk management framework that covers risks associated with data processing and that—(A) identifies voluntary, consensus-based technical standards, guidelines, best practices, methodologies, procedures, and processes for—(i) developing privacy-enhanced information systems and networks, including emerging technologies; and(ii) assessing and mitigating privacy risks to help organizations protect individuals’ privacy in information systems and networks;(B) establishes common definitions and characterizations for aspects of privacy risk management;(C) provides case studies and risk profiles of framework implementation;(D) provides guidance to enable organizations to use the framework to meet privacy requirements from Federal, State, local, and Tribal governments and international policymakers;(E) incorporates voluntary, consensus-based technical standards and best practices;(F) facilitates use by regulators and markets with the aim of reducing barriers to trade; and(G) does not prescribe or otherwise require the use of specific information or communications technology products or services.(2) Carry out research associated with mitigating privacy risks associated with information systems and networks, including to inform periodic updates to the privacy risk management framework developed pursuant to paragraph (1).(3) In consultation with the Director of the Digital Privacy Agency, the Federal Trade Commission, and other related sector-specific risk management agencies, support the development of guidance and risk profiles to help organizations utilize the privacy risk management framework developed pursuant to paragraph (1), to the extent practicable, to adopt privacy requirements and regulations established by the Federal Government, States, and international policymakers.(4) Support activities to improve the efficacy and applicability of privacy-preserving computing, de-identification techniques and processes, and other technological means of mitigating individuals’ privacy risks by enhancing predictability, manageability, disassociability, and confidentiality.(5) Support and strategically engage in the development of voluntary, consensus-based technical standards for privacy-enhanced systems and networks, including international technical standards, through open, transparent, and consensus-based processes.(6) Conduct such other activities as determined necessary by the Director to help public and private sector organizations mitigate the privacy risks associated with information systems and networks.