Click any annotated section or its icon to see analysis.
Referenced Laws
15 U.S.C. 57a(a)(1)(B)
15 U.S.C. 41 et seq.
Section 1
1. Short title This Act may be cited as the Protecting Americans’ Data from Foreign Adversaries Act of 2024.
Section 2
2. Prohibition on transfer of personally identifiable sensitive data of United States individuals to foreign adversaries It shall be unlawful for a data broker to sell, license, rent, trade, transfer, release, disclose, provide access to, or otherwise make available personally identifiable sensitive data of a United States individual to— any foreign adversary country; or any entity that is controlled by a foreign adversary. A violation of this section shall be treated as a violation of a rule defining an unfair or a deceptive act or practice under section 18(a)(1)(B) of the Federal Trade Commission Act (15 U.S.C. 57a(a)(1)(B)). The Commission shall enforce this section in the same manner, by the same means, and with the same jurisdiction, powers, and duties as though all applicable terms and provisions of the Federal Trade Commission Act (15 U.S.C. 41 et seq.) were incorporated into and made a part of this section. Any person who violates this section shall be subject to the penalties and entitled to the privileges and immunities provided in the Federal Trade Commission Act. Nothing in this section may be construed to limit the authority of the Commission under any other provision of law. In this section: The term Commission means the Federal Trade Commission. The term controlled by a foreign adversary means, with respect to an individual or entity, that such individual or entity is— a foreign person that is domiciled in, is headquartered in, has its principal place of business in, or is organized under the laws of a foreign adversary country; an entity with respect to which a foreign person or combination of foreign persons described in subparagraph (A) directly or indirectly own at least a 20 percent stake; or a person subject to the direction or control of a foreign person or entity described in subparagraph (A) or (B). The term data broker means an entity that, for valuable consideration, sells, licenses, rents, trades, transfers, releases, discloses, provides access to, or otherwise makes available data of United States individuals that the entity did not collect directly from such individuals to another entity that is not acting as a service provider. The term data broker does not include an entity to the extent such entity— is transmitting data of a United States individual, including communications of such an individual, at the request or direction of such individual; is providing, maintaining, or offering a product or service with respect to which personally identifiable sensitive data, or access to such data, is not the product or service; is reporting or publishing news or information that concerns local, national, or international events or other matters of public interest; is reporting, publishing, or otherwise making available news or information that is available to the general public— including information from— a book, magazine, telephone book, or online directory; a motion picture; a television, internet, or radio program; the news media; or an internet site that is available to the general public on an unrestricted basis; and not including an obscene visual depiction (as such term is used in section 1460 of title 18, United States Code); or is acting as a service provider. The term foreign adversary country means a country specified in section 4872(d)(2) of title 10, United States Code. The term personally identifiable sensitive data means any sensitive data that identifies or is linked or reasonably linkable, alone or in combination with other data, to an individual or a device that identifies or is linked or reasonably linkable to an individual. The term precise geolocation information means information that— is derived from a device or technology of an individual; and reveals the past or present physical location of an individual or device that identifies or is linked or reasonably linkable to 1 or more individuals, with sufficient precision to identify street level location information of an individual or device or the location of an individual or device within a range of 1,850 feet or less. The term sensitive data includes the following: A government-issued identifier, such as a Social Security number, passport number, or driver’s license number. Any information that describes or reveals the past, present, or future physical health, mental health, disability, diagnosis, or healthcare condition or treatment of an individual. A financial account number, debit card number, credit card number, or information that describes or reveals the income level or bank account balances of an individual. Biometric information. Genetic information. Precise geolocation information. An individual’s private communications such as voicemails, emails, texts, direct messages, mail, voice communications, and video communications, or information identifying the parties to such communications or pertaining to the transmission of such communications, including telephone numbers called, telephone numbers from which calls were placed, the time calls were made, call duration, and location information of the parties to the call. Account or device log-in credentials, or security or access codes for an account or device. Information identifying the sexual behavior of an individual. Calendar information, address book information, phone or text logs, photos, audio recordings, or videos, maintained for private use by an individual, regardless of whether such information is stored on the individual’s device or is accessible from that device and is backed up in a separate location. A photograph, film, video recording, or other similar medium that shows the naked or undergarment-clad private area of an individual. Information revealing the video content requested or selected by an individual. Information about an individual under the age of 17. An individual’s race, color, ethnicity, or religion. Information identifying an individual’s online activities over time and across websites or online services. Information that reveals the status of an individual as a member of the Armed Forces. Any other data that a data broker sells, licenses, rents, trades, transfers, releases, discloses, provides access to, or otherwise makes available to a foreign adversary country, or entity that is controlled by a foreign adversary, for the purpose of identifying the types of data listed in subparagraphs (A) through (P). The term service provider means an entity that— collects, processes, or transfers data on behalf of, and at the direction of— an individual or entity that is not a foreign adversary country or controlled by a foreign adversary; or a Federal, State, Tribal, territorial, or local government entity; and receives data from or on behalf of an individual or entity described in subparagraph (A)(i) or a Federal, State, Tribal, territorial, or local government entity. The term United States individual means a natural person residing in the United States. This section shall take effect on the date that is 60 days after the date of the enactment of this Act.