Mr. President, I am pleased to introduce the ``Privacy Act of 2003.'' This legislation would establish, for the first time, a comprehensive national system of privacy protection. It would: require companies to gain consumers' written…
Mr. President, I am pleased to introduce the ``Privacy Act of 2003.''
This legislation would establish, for the first time, a comprehensive national system of privacy protection.
It would: require companies to gain consumers' written consent prior to selling their most sensitive personal information including personal health information, financial information, Social Security numbers, and drivers' license data; and require companies to provide consumers' notice and an opportunity to refuse to allow their less sensitive personal information to be sold.
Simply put, this legislation would give consumers more control over how their personal information is used.
The personal information of today's consumer is too vulnerable to abuse. With access to sensitive data so widely available--often just at the touch of a keyboard--it is easy to understand why identity theft has become one of the country's fastest growing crimes.
Recent statistics on the growth of identity theft suggest we have no time to waste in protecting personal privacy.
Identity theft is the number one consumer complaint reported to the Federal Trade Commission. American consumers filed approximately 163,000 identity theft complaints with the FTC in 2002. Fully 43 percent of all the complaints the FTC receives are about identity theft.
An estimated 700,000 cases of identity theft occur each year. The average victim spends an average of 175 hours over a two-year period clearing off an average of $17,000 fraud off their credit reports.
My own State, California, has more victims than any other state. The FTC recorded 30,738 identity theft cases last year from California consumers alone.
While modern technology has increased the threat to personal security and privacy, the protections for individual privacy have not kept pace. Our country's privacy laws form an incomplete and inconsistent patchwork.
For example, Americans enjoy the highest level of privacy protection concerning the names of the movies they rent at a video store. But, at the same time, it is perfectly legal to sell another person's Social Security number over the Internet.
The Privacy Act would establish a Federal privacy standard that adjusts the level of privacy protection according to the sensitivity of the information at issue.
The legislation provides the highest level of protection for a person's most sensitive data--personal financial data, health data, driver's license information, and Social Security numbers.
For this sensitive data, the bill gives the individual ultimate control over whether or not his or her information is shared. If an individual does not actively decide to permit sharing of personal data, the data is not disclosed.
Specifically, this legislation tightens the privacy provisions of the Financial Services Modernization Act, commonly known as the Gramm- Leach-Bliley Act. Under Gramm-Leach-Bliley, a bank can share a customer's personal information with other companies so long as it gives consumers notice and the right to opt-out of the data sharing.
The problem with opt-out is that most people toss out their privacy notices from banks along with the rest of the unrelenting pile of commercial solicitations they receive. Since the passage of Gramm- Leach-Bliley, banks have sent out over one billion privacy notices.
According to available published information, fewer than 5 percent of bank customers have opted out of sharing their personal information, and for many financial institutions, the response rate has been less than one percent.
It is not surprising that consumers do not respond overwhelmingly to these notices, since, by some estimates, the average American household received a dozen of these notices. A consumer should not have the burden of constantly monitoring how his or her most sensitive personal information is shared with other companies.
Accordingly, the Privacy Act prohibits the sale or disclosure of sensitive personal financial information to third parties unless the consumer affirmatively consents or opts in.
This legislation also toughens Federal financial privacy laws for affiliate sharing and joint marketing. An affiliate is a company that is linked by common ownership with another company. Under Federal law, a bank can share with affiliates or joint marketing partners regardless of whether the consumer wants this information shared.
The Privacy Act of 2003 would require that banks give consumers the option of opting out of the sharing of their personal financial information with the bank's affiliates or joint partners.
Some banks argue that affiliates are just branches of an organization, and a bank should for efficiency purposes be able to share data within the entire organization. In an era where a bank had one or two affiliates, that might be true.
But, now, some companies are so big that if a customer has no control over
affiliate sharing, then the customer is unable to prevent the disclosure of their data to hundreds of companies. For example, in recent testimony before Congress, U.S. PIRG reported that Citibank has 2,761 affiliates, Key Bank had 871 affiliates, and Bank of America has 1,576 affiliates.
Similarly, a customer must be able to restrict a bank's sharing of personal information with its joint venture partners if the customer wants to maintain control over his personal information.
I would also like to describe several other key components of the financial privacy section.
The bill prohibits banks from denying a customer a financial product or financial service just because the customer chooses to not disclose his personal information to third parties, affiliates, or joint venture partners. However, the bill does allow banks to offer incentives to customers to encourage them to permit the sharing of their personal information.
Additionally, the bill permits banks to disclose, but not sell, personal information to third parties for vital public interest purposes such as identifying or locating missing and abducted children, witnesses, criminals and fugitives, parents delinquent in child support payments, organ and bone marrow donors, pension fund beneficiaries, and missing heirs.
Just as with financial data, personal health data deserves the most stringent privacy protections.
The recently adopted Department of Health and Human Services privacy regulations set a basic opt-in framework for disclosure of health information. But more can be done to protect patient privacy.
The regulations only prohibit ``covered entities''--namely health insurers, health providers, and health care clearinghouses--from selling a patient's health information without that patient's prior consent.
Meanwhile, non-covered entities such as business associates, health researchers, schools or universities, and life insurers are not subject to this opt-in requirement, except through contractual arrangements.
This legislation would preserve the privacy of health information wherever the information is sold. Any business associate, life insurer, school or non-covered entity trying to sell or market protected health information would, like covered entities, have to get the patient's prior consent.
Drivers' license data also is given the strongest level of protection under this bill.
With its recent amendments, the Driver's Privacy Protection Act, DPPA, offers some meaningful protections for drivers privacy.
For example, under the DPPA, a State Department of Motor Vehicles must obtain the prior consent, Opt-in, of the driver before ``highly sensitive information''--defined as the driver's photograph, image, Social Security number, medical or disability information--can be disclosed to a third party.
However, loopholes remain. Other sensitive information found on a driver's license deserves equal protection.
The Privacy Act would expand the definition of ``highly sensitive information'' to include a physical copy of a driver's license, the driver identification number, birth date, information on the driver's physical characteristics and any biometric identifiers, such as a fingerprint, that are found on the driver's license.
Thus, this bill would ensure consumers have control over how their motor vehicle records and driver's license data are used.
I would like to take a moment to highlight the Social Security number section of the privacy bill, which reflects over four years of negotiation with Senator Hatch, Senator Gregg, Senator Grassley, Senator Baucus, and other Senate colleagues. I have also introduced this section as a stand-alone bill, Senate bill 228.
It is crucial to protect Social Security numbers because the numbers are the key to a person's identity. Many identity theft cases start with the theft of a Social Security number. Once a thief has access to a victim's Social Security number, it is only a short step to acquiring credit cards, driver's licenses, or other crucial identification documents.
Not surprisingly, members of the public have flooded our Federal agencies with pleas for assistance. Reports to the Social Security Administration of Social Security number misuse have increased from 7,868 in 1997 to 73,000 in 2002--an astonishing increase of over 800%.
The Feinstein/Gregg compromise bars the sale or display of Social Security numbers to the public except in a very narrow set of circumstances.
Display or sale is permitted if the Social Security number holder consents or if there are compelling public safety needs.
Government entities will have to redact Social Security numbers from electronic records that are readily available to the public on the Internet.
Moreover, State governments will no longer be permitted to use the Social Security number as the default driver's license number.
The legislation, however, recognizes that some industries rely on Social Security numbers to exchange information between databases and complete identification verification necessary for certain transactions.
Thus, the bill directs the Attorney General to develop regulations allowing for the sale or purchase of Social Security Numbers to facilitate business-to-business and business-to-government transactions so long as businesses put appropriate safeguards in place and do not permit public access to the number.
Recognizing that not all personal information merits the same restrictions, the bill permits businesses to collect and sell nonsensitive personal information, e.g., name, phone number, address, to third parties so long as they give customers notice and the opportunity to opt-out of the sale.
The opt-out standard for non-sensitive information means that if a person fills out a warranty card, signs up for a computer service, or submits an entry for a sweepstakes, the business must notify him before it sells his personal information to other businesses or marketers.
This framework guarantees basic privacy protections for consumers without unduly impacting commerce.
To further minimize the regulatory burden of these privacy rules, the bill sets up a safe harbor so that industries and industry-sponsored seal programs which have already adopted Notice-and-Opt Out information policies, will be exempt from the regulatory requirements of the legislation.
To ensure uniformity of the laws across all 50 states, the bill preempts inconsistent state laws regarding the treatment of non- sensitive information.
A jumbled patchwork of State privacy laws helps neither businesses nor consumers. Consumers will have confused expectations about what information is protected.
Another distinguishing characteristic of the Privacy Act of 2003 is that it protects the privacy of information regardless of the medium through which it is collected.
Other privacy proposals have tried to confine privacy legislation to the Internet.
These proposals unfairly discriminate against high technology users. Put simply, companies and other entities can misuse personal information from off-line sources just as easily as with on-line sources.
For example, telemarketers who besiege consumers with phone calls during the dinner hour do not typically get customer information from the Internet. Much of the identifying information used to make these calls comes from consumers filling out and mailing back warranty and registration cards.
Regardless of how information is collected, it should get equal protection.
This legislation codifies steps Congress can take to protect citizens from identity thieves and other predators of personal information.
It restores to an individual more control over his or her most sensitive personal information such as Social Security numbers, health information, and financial information. It also sets reasonable guidelines for businesses that handle our personal information every day.
A byproduct of our information economy--personal information is much more vulnerable to exploitation than ever before.
Every American has a fundamental right to privacy, no matter how fast our technology grows or changes. A
person should be able to have control over how their most sensitive personal information is used.
But our right to privacy only will remain vital, if we take strong action to protect it.
I ask unanimous consent that the text of the legislation be printed in the Record.
I look forward to working with my colleagues to enact the Privacy Act of 2003.
Mr. President, I rise today to introduce the Anti- Terrorism and Port Security Act of 2003, comprehensive legislation aimed at preventing and punishing a terrorist attack at or through one of our nation's 361 seaports. I would like to thank Senator Kyl for joining me in sponsoring this bill.
Currently, our seaports are the gaping hole in our nation's defense against terrorism. According to the U.S. Bureau of Transportation Statistics, about 13 million containers, twenty-foot equivalent units, came into United States ports in 2002.
However, the U.S. government inspected only about two or three percent of these containers--they rest were simply waved through. In addition, in almost every case, these inspections occurred after the containers arrive in the United States.
The problem is that a single container could contain 60,000 pounds of explosives--10 to 15 times the amount in the Ryder truck used to blow up the Murrah Federal Building in Oklahoma City--and a single container ship can carry as many as 8,000 containers at one time.
Containers could easily be exploited to detonate a bomb that would destroy a bridge, seaport, or other critical infrastructure, causing mass destruction and killing thousands.
Worse, a suitcase-sized nuclear device or radiological ``dirty bomb'' could also be installed in a container and shipped to the United States. The odds are that the container would never be inspected.
And, even if the container was inspected, it would be too late. The weapon would already be in the United States--most likely near a major population center.
In addition, any attack on or through a seaport could have devastating economic consequences.
Excluding trade with Mexico and Canada, America's ports handle 95 percent of U.S. trade. Every year U.S. ports handle over 800 million tons of cargo valued at approximately $600 billion.
The West Coast labor disruption last year cost the U.S. economy somewhere $1-2 billion a day--a total of $10-20 billion. A terrorist attack would have an ever graver impact.
The U.S. would likely shut down all major U.S. ports, bringing thousands of factories to a standstill and leaving retailers with bare shelves within days. And this shut down will have a ripple effect around the globe, raising the cost exponentially.
In its December 2002 report, the Hart-Rudman Terrorism Task Force discussed the implications of a possible terrorist attack at a seaport. Here is what they said:
If an explosive device were loaded in a container and set
off in a port, it would almost automatically raise concern
about the integrity of the 21,000 containers that arrive in
U.S. ports each day and the many thousands more that arrive
by truck and rail across U.S. land borders. A three-to-four-
week closure of U.S. ports would bring the global container
industry to its knees. Megaports such as Rotterdam and
Singapore would have to close their gates to prevent boxes
from piling up on their limited pier space. Trucks, trains,
and barges would be stranded outside the terminals with no
way to unload their boxes. Boxes bound for the United States
would have to be unloaded from their outbound ships. Service
contracts would need to be renegotiated. As the system became
gridlocked, so would much of global commerce.
I am particularly concerned about such an attack because such an enormous proportion of U.S. foreign trade passes through my home state of California.
Last year, 6.2 million imported containers--48 percent--passed through California, 5.7 million just through two ports alone: the Port of Los Angeles and the Port of Long Beach.
That means that, if terrorists succeeded in putting a weapon of mass destruction into a container undetected, there is about a one in two chance that this weapon would arrive and/or be detonated in Southern California.
And the problem is not just with containers.
Nearly one-quarter of all of California's imported crude oil is offloaded in one area. A suicide attack on a tanker at an offloading facility in this area could leave Southern California without refined fuels within a few days.
There is no doubt in my mind that terrorists are seeking to exploit vulnerabilities at our seaports right now.
Indeed, the Al Qaeda training manual specifically mentions seaports as a point of vulnerability in our security.
In addition, we know that Al Qaeda has already tried to attack American interests at and through seaports in the past. Let me mention some examples.
In October 2001, Italian authorities found an Egyptian man suspected of
having ties to Al Qaeda in a container bound for Canada. He had false identifications, maps of airports, a computer, a satellite phone, cameras, and plenty of cash on hand.
In October 2000, Al Qaeda operatives successfully carried out a deadly bombing attack against the U.S.S. Cole in the port of Yemen.
In 1998, Al Qaeda bombed the American Embassies in Kenya and Tanzania. Evidence suggests that the explosives the terrorists used were shipped to them by sea. And the investigation of the embassy bombings concluded that Bin Laden has close financial ties to various shipping companies.
We cannot afford to be complacent. Terrorists can be very patient. We cannot forget the successful attack on the World Trade Center on September 11 took place eight years after a relatively unsuccessful attack on the same target.
I introduced legislation in the last Congress to offer a comprehensive solution to the problem of seaport vulnerability. I am pleased that some of its provisions we adopted in some form by recent regulatory changes as well as the Maritime transportation Security Act of 2002 and Trade Act of 2002.
For example, one provision in my bill required shippers to provide manifest information to Customs at least 24 hours before departure from a foreign port. Soon after the bill was introduced, Customs published a draft regulation with the same requirement.
This requirement is now being enforced. However, Customs is still not getting all relevant information from every important party involved in the shipping process.
In addition, I am pleased that, especially in the last six months, Customs has aggressively promoted its Container Security Initiative (CSI). One of the core elements of this initiative involves placing U.S. Customs inspectors at major foreign seaports to pre-screen cargo containers before they were shipped to America.
Most of the biggest ports in the world are now participating in CSI. However, Customs has posted relatively few inspectors overseas and I believe that CSI can and should be expanded further.
The Maritime Transportation Safety Act of 2002 and Trade Act of 2002 also included a number of security measures.
However, in my view, many of these measures do not go nearly far enough, particularly in the areas of criminal penalties, pushing back the border, minimum port and security standards, employee identification cards, research and development, and so on. And even the strongest provisions in these bills are, in some cases, years away from implementation.
The bottom line is that, while we have made some modest improvements in seaport security in the last year, much more remains to be done. And, crucially, much remains to be done right now.
In fact, I believe that our seaports remain almost as vulnerable today as they were before September 11. That is why I am introducing the Anti-Terrorism and Port Security Act of 2003.
This legislation builds on improvements made to our laws in the last year but goes much further than those changes to ensure the security of our seaports.
The Anti-Terrorism and Port Security Act of 2003 does three main things:
First, the bill ensure that our criminal laws apply to deter and punish terrorists who choose to strike against our seaports. The bill closes a number of loopholes in our criminal laws to ensure that terrorists are held accountable for any attacks. Let me provide a couple of examples.
If a person blows up an airplane, he commits a crime. However, if he blows up a oil tanker, he does not commit a crime--unless he is doing it to injure the person.
If a person distributes explosives to a non-U.S. national, he commits a crime. But if the same person sows mines in the San Francisco harbor, he does not commit a crime.
Specifically, the bill would: Make it a crime for terrorists to attack a port or a cruise ship or deploy a weapon of mass destruction at or through a seaport. Make it a crime to put devices in U.S. waters that can destroy a ship or cargo or interfere with safe navigation or maritime commerce. Update our federal criminal piracy and privateering laws and increase penalties. Make it a crime to use a dangerous weapon or explosive to try to kill someone on board a passenger vessel. Make it a crime to fail to heave to (that is, to slow or stop) a vessel at the direction of a Coast Guard or other authorized federal law enforcement official seeking to board that vessel or to interfere with boarding by such an officer. Make it a crime to destroy an aid to maritime navigation, such as a buoy or shoal/breakwater light, maintained by the Coast Guard if this would endanger the safe navigation of a vessel. Make it a crime for terrorists or criminals to try to attack U.S. citizens or U.S. marine live by putting poisons in the water off shore. Require the Attorney General to issue regulations making it easier to determine the extent of crime and terrorism at seaports and improve communication between different law enforcement agencies involved at ports.
Second, the bill would help improve physical security at seaports by beefing up standards and ensuring greater coordination. Specific provisions would: Designate the Captain-of-the-Port as the primary authority for seaport security at each port. This would enable all parties involved in business at a port to understand who has final say on all security matters. Require minimum federal security standards for ports. These standards include restrictions on private vehicle access, a prohibition on unauthorized guns and explosives, and unauthorized physical access to terminal areas. They would also mandate that terminal areas at ports have a secure perimeter, monitored or locked access points, sufficient lighting, and son on. Mandate that all Customs inspectors have personal radiation detection pagers. Require all port employees and contractors to have biometric smart identification cards. Require Captains-of-the-Port to keep sensitive information on the port secure and protected. Such information would include, but not be limited to maps, blueprints, and information on the Internet.
Third, the bill would ensure that we devote our limited cargo inspection resources in the most efficient and effective manner. The bill would improve our shipment profiling system by requiring additional information from more relevant parties to the shipping process, and it would substantially improve container security. Specifically, it would establish a comprehensive risk profiling plan for the Customs Service to focus their limited inspection capabilities on high-risk cargo and containers. Under this plan, all relevant parties in the shipment process would provide electronically relevant and timely information to enable Customs to determine which shipments to inspect. Impose steep monetary sanctions for failure to comply with information filing requirements, including filing incorrect information (the current penalty is only up to a few thousand dollars). The Seaport Commission found that about \1/2\ of the information on ship manifests was inaccurate. Push U.S. security scrutiny beyond our nation's borders and improve our ability to monitor and inspect cargo and containers before they arrive near America's shores. If a weapon of mass destruction arrives in a U.S. port, it is too late. Require the use of high security seals on all containers coming into the U.S. Require that each container to be transported through U.S. ports receive a universal transaction number that could be used to track container movement from origin to destination. Require all empty containers destined for U.S. ports to be secured. Authorize pilot programs to develop high-tech seals and sensors, including those that would provide real-time evidence of container tampering to a monitor at a terminal. Require ports to provide space to Customs so that the agency is able to use non-intrusive inspection technology. In many cases, Customs has to keep this technology outside the port and bring it in every day, which prevents some of the best inspection technology (which is not portable) from being used. Require the Department of Homeland Security to take the relative number of imported containers received at each port into account in exercising its discretion in determining the allocation of funds appropriated for seaport security grants.
I believe that the Anti-Terrorism and Port Security Act of 2003 would make a
significant contribution to protecting America from terrorist attacks at or through our seaports. I urge my colleagues to support the legislation.;
I ask unanimous consent that the text of the bill be printed in the Record.