Data Breach Prevention and Compensation Act of 2024
S 5449 establishes new cybersecurity standards for consumer reporting agencies (like credit bureaus) that handle personal data, requiring them to implement specific security measures and report breaches to the Federal Trade Commission (FTC) within 10 days. Covered agencies must notify affected consumers about breaches, including the risks involved, and face penalties of $100 per consumer for basic data exposure plus $50 per additional data type exposed, capped at 50% of their prior year's revenue. The FTC’s new Office of Cybersecurity will enforce these rules, investigate violations, and use penalty funds - split equally between cybersecurity research and direct compensation to affected consumers. The law applies to agencies meeting revenue thresholds or listed in the Fair Credit Reporting Act, directly impacting millions of consumers whose data is stored by these entities.
Bill status
in committee
1 of 4 stages cleared
Introduction
Dec 2024
Committee Review
Floor Vote
President
Introduced Dec 5, 2024
Last action Dec 5, 2024
Floor votes
How they voted
No floor votes recorded yet.
Full legislative history
Actions timeline
Total actions
2
Key actions
0
Committee
1
Dec 5, 2024
Committee
Read twice and referred to the Committee on Banking, Housing, and Urban Affairs.
upper
Dec 5, 2024
Introduced
Introduced in Senate
upper
1 primary · 2 co-sponsors
Sponsors
Role
Legislator
Party
State
District
P
Elizabeth Warren
DDemocratic
Co
Jeanne Shaheen
DDemocratic
Co
Mark R. Warner
DDemocratic
Ask Maddy
·
AI policy assistant
Ask Maddy about S 5449
Scope: US
Hi! I can help you understand S 5449. What would you like to know?
Try one of these
i
Maddy answers using official bill text and legislative records. Always verify before sharing.
Sources cited inline