Skip to main content
HR 2577 112th Congress House

SAFE Data Act

Official title: To protect consumers by requiring reasonable security policies and procedures to protect data containing personal information, and to provide for nationwide notice in the event of a security breach.

Introduced: July 18, 2011 See on congress.gov
Commerce Administrative law and regulatory proceduresCivil actions and liabilityComputer security and identity theftComputers and information technology
More subjectsShow fewer subjects
Consumer affairsConsumer creditFederal Trade Commission (FTC)Federal preemptionFraud offenses and financial crimesGovernment studies and investigationsInternet and video servicesInternet, web applications, social mediaRight of privacyTelephone and wireless communication
This bill died when the 112th Congress ended
It never became law before the 112th Congress (2011–2012) adjourned, and bills don't carry over to the next Congress. It would have to be reintroduced. You can still save it for reference, but it won't receive updates.
 Everywhere this bill has been 3 steps
Introduced
In committee
Reported out
Passed House
Passed Senate
To President
Became law
Jul 29, 2011
Referred to the Subcommittee on Commerce, Manufacturing, and Trade.
Jul 18, 2011
Referred to the House Committee on Energy and Commerce.
Jul 18, 2011
Introduced in House
 Ask about this bill AI · grounded in the bill text

Have a question about what this bill does? Ask in plain English; the answer is drawn from the bill's actual text and official record, and it'll tell you when something isn't in the text rather than guess.

AI answers can be imperfect; always confirm against the full bill text.

 Latest action July 29, 2011

Referred to the Subcommittee on Commerce, Manufacturing, and Trade.

 Plain-English summary Congressional Research Service

Secure and Fortify Electronic Data Act or the SAFE Data Act - Requires the Federal Trade Commission (FTC) to promulgate regulations requiring any person engaged in interstate commerce that owns or possesses data containing personal information to establish and implement reasonable security policies and procedures to treat and protect such information.

Requires such regulations to include specified policies and procedures, including: (1) a process for identifying and assessing vulnerabilities in the system, and (2) a process for taking preventive and corrective action to mitigate such vulnerabilities.

Requires a person covered by this Act to establish a plan and procedures for minimizing the amount of personal information maintained.

Exempts services providers from such requirements for any electronic communication by a third party that is transmitted, routed, or stored in intermediate or transient storage by the provider.

Establishes notification procedures in the event of a breach of security of any system that contains personal information. Allows an exemption from notification requirements if a person subject to this Act determines that there is no reasonable risk of identity theft, fraud, or other unlawful conduct. Creates a presumption that no reasonable risk of such conduct exists following a breach of security if the data containing personal information is unusable, unreadable, or indecipherable to an unauthorized person by encryption or other security technology that is generally accepted by experts in the information security field.

Directs a person subject to this Act to provide a credit report and credit monitoring if certain identifying information is breached.

Sets forth provisions regarding enforcement of this Act by the FTC and by state attorneys general. Establishes civil penalties for violations.

Exempts from the requirements of this Act any person subject to the information security requirements of the Health Insurance Portability and Accountability Act (HIPAA) or the Gramm-Leach Bliley Act.

 Related & companion bills 3
 Bill text 1 version

Source documents hosted by congress.gov.

 Committees of jurisdiction 2
Cite this page click to expand
APA
U.S. Congress. (2026). H.R. 2577: SAFE Data Act. 112th Congress. Open America. https://openamerica.io/bill/112-HR-2577/
MLA
"H.R. 2577: SAFE Data Act." 112th Congress, 2026, Open America, https://openamerica.io/bill/112-HR-2577/.
Bluebook (legal)
H.R. 2577, 112th Cong. (2026), https://openamerica.io/bill/112-HR-2577/.
Markdown link
[H.R. 2577: SAFE Data Act](https://openamerica.io/bill/112-HR-2577/)
Report a problem