<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="\billres.xsl" type="text/xsl"?>
<!DOCTYPE amendment-doc PUBLIC "-//US Congress//DTDs/amend v2.8 20020720//EN" "http://xml.house.gov/amend.dtd">
<amendment-doc dms-id="H545DB87F8203441593581EB204DE6860" amend-stage="proposed" amend-type="house-amendment" amend-degree="first" key="H"> 
<pre-form><meta-house><holc-filename>G:\CMTE\WM\15\OASDI\BILLS\H5192_RCP.XML</holc-filename><holc-attorney>XXXXXXX</holc-attorney><holc-last-author>XXXXXXX</holc-last-author><holc-last-saved>4/11/2018 14:33</holc-last-saved><holc-creator>XXXXXXX</holc-creator><holc-creation-date>04/11/2018 14:25</holc-creation-date><version><version-filename>XXXXXXXXXXXXXXXXXXXXXXXXXXXXX</version-filename><version-date>XXXXXXXXXXXXXXXXXXX</version-date><version-creator>XXXXXXX</version-creator></version> <holc-job-number/><holc-doc-number>690326|1</holc-doc-number> </meta-house> 
<author-note display="no"><?xm-replace_text {author-note}?></author-note> 
<running-header display="no">[Discussion Draft]</running-header> 
<legis-counsel/> 
<first-page-header display="no">[Discussion Draft]</first-page-header> 
<first-page-date display="yes">April 11, 2018</first-page-date> 
<first-page-desc display="no"><?xm-replace_text {first-page-desc}?></first-page-desc> 
</pre-form> 
<amendment-form> 
<purpose display="no"><?xm-replace_text {purpose}?></purpose> 
<congress display="no">115th CONGRESS</congress> <session display="no">2d Session</session> 
<legis-num> Rules Committee Print 115-68</legis-num> 
<action> 
<action-desc blank-lines-after="1">Protecting Children from Identity Theft Act</action-desc> 
<action-instruction>[Showing the text of H.R. 5192 as ordered reported by the Committee on Ways and Means]</action-instruction> 
</action> 
</amendment-form> 
<amendment-body> <amendment> 
<amendment-instruction line-numbers="off"><text><?xm-replace_text {amendment-instruction}?></text></amendment-instruction>
<amendment-block style="OLC" id="HF766C9635AA04B8B8FA802CB7FEE8A05">
<section id="H5DA16FBE3D1F463C83561BC61AF97A9B" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Protecting Children from Identity Theft Act</short-title></quote>.</text> </section>
<section id="H117512D778C94C4EADBC4AA463070B0B"><enum>2.</enum><header>Reducing identity fraud</header> 
<subsection id="H3239BA5248394A67BC3ED7FECE8ED9B1"><enum>(a)</enum><header>Purpose</header><text>The purpose of this section is to reduce the prevalence of synthetic identity fraud, which disproportionally affects vulnerable populations, such as minors and recent immigrants, by facilitating the validation by permitted entities of fraud protection data, pursuant to electronically received consumer consent, through use of a database maintained by the Commissioner.</text> </subsection> 
<subsection id="HC356CB2C869646C08934372B740A6554"><enum>(b)</enum><header>Definitions</header><text>In this section:</text> 
<paragraph id="H64911049C3744E67817E150E44B4FC6B"><enum>(1)</enum><header>Commissioner</header><text>The term <quote>Commissioner</quote> means the Commissioner of the Social Security Administration.</text> </paragraph> 
<paragraph id="H2EB870B7EACF42FC8AAB65D7169B8DCF"><enum>(2)</enum><header>Financial institution</header><text>The term <quote>financial institution</quote> has the meaning given the term in section 509 of the Gramm-Leach-Bliley Act (15 U.S.C. 6809).</text> </paragraph> 
<paragraph id="HA945D5F7D4EF404491EE8C6A24D325E9"><enum>(3)</enum><header>Fraud protection data</header><text>The term <quote>fraud protection data</quote> means a combination of the following information with respect to an individual:</text> 
<subparagraph id="H551B62DC6E7647F79359453902330067"><enum>(A)</enum><text>The name of the individual (including the first name and any family forename or surname of the individual).</text> </subparagraph> 
<subparagraph id="H6EB7CB9B054048C28D8DC40002D636A4"><enum>(B)</enum><text>The Social Security account number of the individual.</text> </subparagraph> 
<subparagraph id="H2A52B7905CC74393AE98D6AA84187BD8"><enum>(C)</enum><text>The date of birth (including the month, day, and year) of the individual.</text> </subparagraph></paragraph> 
<paragraph id="H5029001F29224DB58AF9077A81796622"><enum>(4)</enum><header>Permitted entity</header><text>The term <quote>permitted entity</quote> means a financial institution or a service provider, subsidiary, affiliate, agent, contractor, or assignee of a financial institution.</text> </paragraph></subsection> 
<subsection id="H052FE668CC334950960F2912E74C736B"><enum>(c)</enum><header>Efficiency</header> 
<paragraph id="HAEFB77EF08E944F5972CE73BF48258BE"><enum>(1)</enum><header>Reliance on existing methods</header><text>The Commissioner shall evaluate the feasibility of making modifications to any database that is in existence as of the date of enactment of this Act or a similar resource such that the database or resource—</text> 
<subparagraph id="HFF4FD5D29A08482FB4D3D5FAE15EC8EF"><enum>(A)</enum><text>is reasonably designed to effectuate the purpose of this section; and</text> </subparagraph> 
<subparagraph id="HCAB1ADF1D6D14E0780FD2B8EAFAA32C7"><enum>(B)</enum><text>meets the requirements of subsection (d).</text> </subparagraph></paragraph> 
<paragraph id="HBC025C0ACA1B47B7BB62F23BC7F8D961"><enum>(2)</enum><header>Execution</header><text>The Commissioner shall establish a system to carry out subsection (a), in accordance with section 1106 of the Social Security Act. In doing so, the Commissioner shall make the modifications necessary to any database that is in existence as of the date of enactment of this Act or similar resource, or develop a database or similar resource.</text> </paragraph></subsection> 
<subsection id="H5BD912DA673B42AF951A852FAEAF0AE1"><enum>(d)</enum><header>Protection of vulnerable consumers</header><text>The database or similar resource described in subsection (c) shall—</text> 
<paragraph id="H9B1DD65883654B5FA9A611865E2E41A1"><enum>(1)</enum><text display-inline="yes-display-inline">compare fraud protection data provided in an inquiry by a permitted entity against such information maintained by the Commissioner in order to confirm (or not confirm) the validity of the information provided, and in such a manner as to deter fraudulent use of the database or similar resource;</text> </paragraph> 
<paragraph id="H436C5140BECA4E0F9E857AE1600BA811"><enum>(2)</enum><text>be scalable and accommodate reasonably anticipated volumes of verification requests from permitted entities with commercially reasonable uptime and availability; and</text> </paragraph> 
<paragraph id="H7046937332C747EB9B983D68CD0F417F"><enum>(3)</enum><text>allow permitted entities to submit—</text> 
<subparagraph id="HB5788C3BBF524DEE9BC4B357CBBBB170"><enum>(A)</enum><text>one or more individual requests electronically for real-time machine-to-machine (or similar functionality) accurate responses; and</text> </subparagraph> 
<subparagraph id="H852C6837EB504F588A6925587C45499B"><enum>(B)</enum><text>multiple requests electronically, such as those provided in a batch format, for accurate electronic responses within a reasonable period of time from submission, not to exceed 24 hours.</text> </subparagraph></paragraph></subsection> 
<subsection id="H7B4739ACD6C54AE6B924A71DF3840236"><enum>(e)</enum><header>Certification required</header><text>Before providing confirmation of fraud protection data to a permitted entity, the Commissioner shall ensure that the Commissioner has a certification from the permitted entity that is dated not more than 2 years before the date on which that confirmation is provided that includes the following declarations:</text> 
<paragraph id="H03B0C0F3B22B45DB97F9F5D73B3A94BB"><enum>(1)</enum><text>The entity is a permitted entity.</text> </paragraph> 
<paragraph id="HFDB97FD3947A40BFBA9E860E38A54F0C"><enum>(2)</enum><text>The entity is in compliance with this section.</text> </paragraph> 
<paragraph id="HA1CC53B9EF5445A59DD086EC6554FD49"><enum>(3)</enum><text>The entity is, and will remain, in compliance with its privacy and data security requirements, as described in title V of the Gramm-Leach-Bliley Act (15 U.S.C. 6801 et seq.) and as required by the Commissioner, with respect to information the entity receives from the Commissioner pursuant to this section.</text> </paragraph> 
<paragraph id="H1D1EC07D50604ACCBBB3828FBF1CC826"><enum>(4)</enum><text>The entity will retain sufficient records to demonstrate its compliance with its certification and this section for a period of not less than 2 years.</text> </paragraph></subsection> 
<subsection id="H47C657EDDBC34E2A9DC40F8E0F4F4385"><enum>(f)</enum><header>Consumer consent</header> 
<paragraph id="H54699FC1B9914700B5BBC0E0D5333396"><enum>(1)</enum><header>In general</header><text>Notwithstanding any other provision of law or regulation, a permitted entity may submit a request to the database or similar resource described in subsection (c) only—</text> 
<subparagraph id="H67880454784E43DE9D208E6BF0EAA628"><enum>(A)</enum><text>pursuant to the written, including electronic, consent received by a permitted entity from the individual who is the subject of the request; and</text> </subparagraph> 
<subparagraph id="HD606B4846BF142D0AD2E8076F01BE1E6"><enum>(B)</enum><text>in connection with any circumstance described in section 604 of the Fair Credit Reporting Act (15 U.S.C. 1681b).</text> </subparagraph></paragraph> 
<paragraph id="HF033EE18CB594EDCBAF4577B8F7D735D"><enum>(2)</enum><header>Electronic consent requirements</header><text>For a permitted entity to use the consent of an individual received electronically pursuant to paragraph (1)(A), the permitted entity must obtain the individual’s electronic signature, as defined in section 106 of the Electronic Signatures in Global and National Commerce Act (15 U.S.C. 7006). Permitted entities must develop and use an electronic signature process in accordance with all Federal laws and requirements as designated by the Commissioner.</text> </paragraph> 
<paragraph id="H35FB87EE48AB43AD80A5180A2A18C16C"><enum>(3)</enum><header>Effectuating electronic consent</header><text>No provision of law or requirement, including section 552a of title 5, United States Code, shall prevent the use of electronic consent for purposes of this subsection or for use in any other consent based verification under the discretion of the Commissioner.</text> </paragraph></subsection> 
<subsection id="HABC23407C9DA482CB160373DBDAF8AB9"><enum>(g)</enum><header>Compliance and enforcement</header> 
<paragraph id="H6DD7711E975846C0BA38E69BB42085A9"><enum>(1)</enum><header>Audits and monitoring</header> 
<subparagraph id="H8F5846FB2BD341379BA9BEA27FAF3B04"><enum>(A)</enum><header>In general</header><text>The Commissioner—</text> 
<clause id="HE3EFBF789CB74AE1A0F6639A723D2057"><enum>(i)</enum><text>shall conduct audits and monitoring to—</text> 
<subclause id="HCCAF892FBC15468B8DAC2B87924BB1AF"><enum>(I)</enum><text>ensure proper use by permitted entities of the database or similar resource described in subsection (c); and</text> </subclause> 
<subclause id="H63F1B48E7BAC49429F2B93863E5A50ED"><enum>(II)</enum><text>deter fraud and misuse by permitted entities with respect to the database or similar resource described in subsection (c); and</text> </subclause></clause> 
<clause id="HB69413CFADAD4931A37AD1FA5DC062FF"><enum>(ii)</enum><text>may terminate services for any permitted entity that prevents or refuses to allow the Commissioner to carry out the activities described in clause (i) and may terminate or suspend services for any permitted entity as necessary to enforce any violation of this section or of any certification made under this section.</text> </clause></subparagraph></paragraph> 
<paragraph id="HF69501080B7B43E4A2A73B9D330AA80C"><enum>(2)</enum><header>Enforcement</header> 
<subparagraph id="H84A15A7028164C1EAD8CD2FAA4B2B6EA"><enum>(A)</enum><header>In general</header><text>Notwithstanding any other provision of law, including the matter preceding paragraph (1) of section 505(a) of the Gramm-Leach-Bliley Act (15 U.S.C. 6805(a)), any violation of this section and any certification made under this section shall be enforced in accordance with paragraphs (1) through (7) of such section 505(a) by the agencies described in those paragraphs.</text> </subparagraph> 
<subparagraph id="H86B5E57F3C3C41D2BDFB997D529FB028"><enum>(B)</enum><header>Relevant information</header><text>Upon discovery by the Commissioner of any violation of this section or any certification made under this section, the Commissioner shall forward any relevant information pertaining to that violation to the appropriate agency described in subparagraph (A) for evaluation by the agency for purposes of enforcing this section.</text> </subparagraph></paragraph></subsection> 
<subsection id="H14A34C77366E45B6B7AB0BB3949C4543"><enum>(h)</enum><header>Recovery of costs</header> 
<paragraph id="H77B86AE83A1A4E3396E436559CF2F34E"><enum>(1)</enum><header>In general</header> 
<subparagraph id="H11C750C6FE654EBD8636C835783BF085"><enum>(A)</enum><header>In general</header><text>Amounts obligated to carry out this section shall be fully recovered from the users of the database or verification system by way of advances, reimbursements, user fees, or other recoveries as determined by the Commissioner. The funds recovered under this paragraph shall be deposited as an offsetting collection to the account providing appropriations for the Social Security Administration, to be used for the administration of this section without fiscal year limitation.</text> </subparagraph> 
<subparagraph id="HDE1D46A49D71401BA86E69E3BAEE0108"><enum>(B)</enum><header>Prices fixed by commissioner</header><text display-inline="yes-display-inline">The Commissioner shall establish the amount to be paid by the users under this paragraph, including the costs of any services or work performed, such as any appropriate upgrades, maintenance, and associated direct and indirect administrative costs, in support of carrying out the purposes described in this section, by reimbursement or in advance as determined by the Commissioner. The amount of such prices shall be periodically adjusted by the Commissioner to ensure that amounts collected are sufficient to fully offset the cost of the administration of this section.</text> </subparagraph></paragraph> 
<paragraph id="H647082ABE2594885A4B2DF317E5AD6AB"><enum>(2)</enum><header>Initial development</header><text>The Commissioner shall not begin development of a verification system to carry out this section until the Commissioner determines that amounts equal to at least 50 percent of program start-up costs have been collected under paragraph (1).</text> </paragraph> 
<paragraph id="H20FD6CE3B82141819AD9ACD97DFBF463"><enum>(3)</enum><header>Existing resources</header><text>The Commissioner of Social Security may use funds designated for information technology modernization to carry out this section, but in all cases shall be fully reimbursed under paragraph (1)(A).</text> </paragraph> 
<paragraph id="H222271F3825C408EA0A7459C16409F0F"><enum>(4)</enum><header>Annual report</header><text>The Commissioner of Social Security shall annually submit to the Committee on Ways and Means of the House of Representatives and the Committee on Finance of the Senate a report on the amount of indirect costs to the Social Security Administration arising as a result of the implementation of this section.</text> </paragraph></subsection></section>
</amendment-block></amendment> </amendment-body></amendment-doc>
