Protecting Americans’ Data from Foreign Adversaries Act of 2024
What changed between versions
The prohibition now applies only to 'personally identifiable sensitive data' instead of all 'sensitive data,' meaning data that cannot be linked to a specific individual or device is no longer covered by the ban on transfer to foreign adversaries.
A new definition of 'personally identifiable sensitive data' was added: any sensitive data that identifies or is linked or reasonably linkable, alone or in combination with other data, to an individual or a device that identifies or is linked or reasonably linkable to an individual.
The definition of 'controlled by a foreign adversary' was expanded from applying only to an entity to applying to an individual or entity, broadening who can be deemed controlled by a foreign adversary.
The service provider definition was changed: it no longer requires the directing party to 'not be a data broker,' and now refers to 'an individual or entity that is not a foreign adversary country or controlled by a foreign adversary' rather than 'an entity that is not a data broker and is not controlled by a foreign adversary.'
A new data broker exclusion was added (new subsection (ii)): an entity is not a data broker to the extent it is providing, maintaining, or offering a product or service with respect to which personally identifiable sensitive data, or access to such data, is not the product or service. This could exempt many platforms and services from the definition.
The news and public information exclusion for data brokers was split into two separate exclusions: one for reporting or publishing news concerning local, national, or international events or matters of public interest, and another for making available information to the general public (now also explicitly including books, magazines, and motion pictures).
The precise geolocation information definition was narrowed slightly: it now requires the device or technology to be 'of an individual' rather than just any device or technology.