Skip to main content
S 1193 113th Congress Senate Commerce Bank accounts, deposits, capital Civil actions and liability Computer security and identity theft Consumer affairs Internet and video services Internet, web applications, social media Right of privacy

Data Security and Breach Notification Act of 2013

Introduced: June 20, 2013 See on congress.gov
This bill died when the 113th Congress ended
It never became law before the 113th Congress (2013–2014) adjourned, and bills don't carry over to the next Congress. It would have to be reintroduced. You can still save it for reference, but it won't receive updates.
 Everywhere this bill has been 2 steps
Introduced
In committee
Reported out
Passed House
Passed Senate
To President
Became law
Jun 20, 2013
Read twice and referred to the Committee on Commerce, Science, and Transportation.
Jun 20, 2013
Introduced in Senate
 Ask about this bill AI · grounded in the bill text

Have a question about what this bill does? Ask in plain English; the answer is drawn from the bill's actual text and official record, and it'll tell you when something isn't in the text rather than guess.

AI answers can be imperfect; always confirm against the full bill text.

 Plain-English summary Congressional Research Service

Data Security and Breach Notification Act of 2013 - Requires commercial entities that acquire, maintain, store, or utilize personal information (covered entities) to take reasonable measures to protect and secure data in electronic form containing personal information.

Directs a covered entity that owns or licenses such data to give notice of any breach of security that the entity reasonably believes has caused or will cause identity theft or other actual financial harm to each individual: (1) who is a U.S. citizen or resident; and (2) whose personal information was, or that the covered entity reasonably believes has been, accessed and acquired by an unauthorized person.

Requires a covered entity to notify the Secret Service or the Federal Bureau of Investigation (FBI) of a security breach of personal information involving more than 10,000 individuals.

Requires a third-party entity contracted to maintain, store, or process data containing personal information to notify the covered entity of a breach of security of a system. Requires a service provider to notify the covered entity if it becomes aware of a breach of security involving personal information owned or possessed by a covered entity and if such covered entity can be reasonably identified.

Allows delays of notifications to avoid interfering with a civil or criminal investigation or threatening national or homeland security.

Sets forth the methods for notification under this Act.

Preempts information security practices of the Communications Act of 1934 applicable to telecommunication carriers, satellite operators, and cable operators.

Sets forth the enforcement authority for the Federal Trade Commission (FTC) along with civil monetary penalties for violations of this Act.

Exempts certain financial institutions and entities subject to the Health Insurance Portability and Accountability Act of 1996 (HIPAA).

What's happening now June 20, 2013

Read twice and referred to the Committee on Commerce, Science, and Transportation.

 Related & companion bills 2
 Bill text 1 version

Source documents hosted by congress.gov.

 Committees of jurisdiction 1
Cite this page click to expand
APA
U.S. Congress. (2026). S. 1193: Data Security and Breach Notification Act of 2013. 113th Congress. Open America. https://openamerica.io/bill/113-S-1193/
MLA
"S. 1193: Data Security and Breach Notification Act of 2013." 113th Congress, 2026, Open America, https://openamerica.io/bill/113-S-1193/.
Bluebook (legal)
S. 1193, 113th Cong. (2026), https://openamerica.io/bill/113-S-1193/.
Markdown link
[S. 1193: Data Security and Breach Notification Act of 2013](https://openamerica.io/bill/113-S-1193/)
Report a problem