Skip to main content
S 177 114th Congress Senate

Data Security and Breach Notification Act of 2015

Official title: A bill to protect consumers by requiring reasonable security policies and procedures to protect data containing personal information, and to provide for nation… Show full official titleShow less

Official title: A bill to protect consumers by requiring reasonable security policies and procedures to protect data containing personal information, and to provide for nationwide notice in the event of a breach of security.

Introduced: April 20, 2015 See on congress.gov
Commerce Administrative law and regulatory proceduresBank accounts, deposits, capitalBanking and financial institutions regulationBusiness records
More subjectsShow fewer subjects
Civil actions and liabilityComputer security and identity theftComputers and information technologyCongressional oversightConsumer affairsConsumer creditCriminal investigation, prosecution, interrogationFederal Trade Commission (FTC)Fraud offenses and financial crimesIntelligence activities, surveillance, classified informationInternet and video servicesInternet, web applications, social mediaRight of privacySmall businessSocial work, volunteer service, charitable organizations
This bill died when the 114th Congress ended
It never became law before the 114th Congress (2015–2016) adjourned, and bills don't carry over to the next Congress. It would have to be reintroduced. You can still save it for reference, but it won't receive updates.
 Everywhere this bill has been 2 steps
Introduced
In committee
Reported out
Passed House
Passed Senate
To President
Became law
Jan 13, 2015
Read twice and referred to the Committee on Commerce, Science, and Transportation.
Jan 13, 2015
Introduced in Senate
 Ask about this bill AI · grounded in the bill text

Have a question about what this bill does? Ask in plain English; the answer is drawn from the bill's actual text and official record, and it'll tell you when something isn't in the text rather than guess.

AI answers can be imperfect; always confirm against the full bill text.

 Latest action January 13, 2015

Read twice and referred to the Committee on Commerce, Science, and Transportation.

 Plain-English summary Congressional Research Service

Data Security and Breach Notification Act of 2015

Requires the Federal Trade Commission (FTC) to promulgate regulations requiring commercial entities, nonprofit and for-profit corporations, estates, trusts, cooperatives, and other specified entities that own or possess data containing personal information (covered entities), or that contract to have a third-party maintain or process such data for the entity, to implement information security policies and procedures for the treatment and protection of personal information.

Establishes procedures to be followed in the event of an information security breach. Requires a covered entity that discovers a breach to notify the FTC (unless the covered entity has already notified a federal entity designated by the Department of Homeland Security [DHS] to receive such information) and affected individuals. Sets forth requirements concerning such notification, including methods of notification and timeliness requirements. Allows an exemption from notification requirements if such entity reasonably concludes that there is no reasonable risk of identity theft, fraud, or other unlawful conduct. Establishes a presumption that there is no such risk for encrypted data.

Directs DHS to designate a federal entity that covered entities would be required to notify if a security breach involves: (1) the personal information of more than 10,000 individuals, (2) a database containing the personal information of more than 1 million individuals, (3) federal government databases, or (4) the personal information of federal employees or contractors known to be involved in national security or law enforcement.

Requires the designated entity to provide each notice it receives to:

  • the U.S. Secret Service;
  • the Federal Bureau of Investigation;
  • the FTC;
  • the U.S. Postal Inspection Service, if mail fraud is involved;
  • attorneys general of affected states; and
  • appropriate federal agencies for law enforcement, national security, or data security purposes.

Sets forth enforcement provisions for the FTC, state attorneys general, and the Attorney General.

Establishes criminal penalties of a fine, imprisonment for up to five years, or both, for concealment of a security breach that results in economic harm of at least $1,000 to an individual.

 Bill text 1 version

Source documents hosted by congress.gov.

 Committees of jurisdiction 1
Cite this page click to expand
APA
U.S. Congress. (2026). S. 177: Data Security and Breach Notification Act of 2015. 114th Congress. Open America. https://openamerica.io/bill/114-S-177/
MLA
"S. 177: Data Security and Breach Notification Act of 2015." 114th Congress, 2026, Open America, https://openamerica.io/bill/114-S-177/.
Bluebook (legal)
S. 177, 114th Cong. (2026), https://openamerica.io/bill/114-S-177/.
Markdown link
[S. 177: Data Security and Breach Notification Act of 2015](https://openamerica.io/bill/114-S-177/)
Report a problem