H. R. 2029—709
(III) chapter 90 of such title (relating to protection of trade secrets).
(B) PROHIBITED ACTIVITIES.—Cyber threat indicators
and defensive measures provided to the Federal Government under this title shall not be disclosed to, retained
by, or used by any Federal agency or department for any
use not permitted under subparagraph (A).
(C) PRIVACY AND CIVIL LIBERTIES.—Cyber threat indicators and defensive measures provided to the Federal
Government under this title shall be retained, used, and
disseminated by the Federal Government—
(i) in accordance with the policies, procedures, and
guidelines required by subsections (a) and (b);
(ii) in a manner that protects from unauthorized
use or disclosure any cyber threat indicators that may
contain—
(I) personal information of a specific individual; or
(II) information that identifies a specific individual; and
(iii) in a manner that protects the confidentiality
of cyber threat indicators containing—
(I) personal information of a specific individual; or
(II) information that identifies a specific individual.
(D) FEDERAL REGULATORY AUTHORITY.—
(i) IN GENERAL.—Except as provided in clause (ii),
cyber threat indicators and defensive measures provided to the Federal Government under this title shall
not be used by any Federal, State, tribal, or local
government to regulate, including an enforcement
action, the lawful activities of any non-Federal entity
or any activities taken by a non-Federal entity pursuant to mandatory standards, including activities
relating to monitoring, operating defensive measures,
or sharing cyber threat indicators.
(ii) EXCEPTIONS.—
(I) REGULATORY AUTHORITY SPECIFICALLY
RELATING TO PREVENTION OR MITIGATION OF CYBERSECURITY THREATS.—Cyber threat indicators and
defensive measures provided to the Federal
Government under this title may, consistent with
Federal or State regulatory authority specifically
relating to the prevention or mitigation of cybersecurity threats to information systems, inform the
development or implementation of regulations
relating to such information systems.
(II) PROCEDURES DEVELOPED AND IMPLEMENTED UNDER THIS TITLE.—Clause (i) shall not
apply to procedures developed and implemented
under this title.
SEC. 106. PROTECTION FROM LIABILITY.
(a) MONITORING OF INFORMATION SYSTEMS.—No cause of action
shall lie or be maintained in any court against any private entity,
and such action shall be promptly dismissed, for the monitoring