H. R. 2029—709 (III) chapter 90 of such title (relating to protection of trade secrets). (B) PROHIBITED ACTIVITIES.—Cyber threat indicators and defensive measures provided to the Federal Government under this title shall not be disclosed to, retained by, or used by any Federal agency or department for any use not permitted under subparagraph (A). (C) PRIVACY AND CIVIL LIBERTIES.—Cyber threat indicators and defensive measures provided to the Federal Government under this title shall be retained, used, and disseminated by the Federal Government— (i) in accordance with the policies, procedures, and guidelines required by subsections (a) and (b); (ii) in a manner that protects from unauthorized use or disclosure any cyber threat indicators that may contain— (I) personal information of a specific individual; or (II) information that identifies a specific individual; and (iii) in a manner that protects the confidentiality of cyber threat indicators containing— (I) personal information of a specific individual; or (II) information that identifies a specific individual. (D) FEDERAL REGULATORY AUTHORITY.— (i) IN GENERAL.—Except as provided in clause (ii), cyber threat indicators and defensive measures provided to the Federal Government under this title shall not be used by any Federal, State, tribal, or local government to regulate, including an enforcement action, the lawful activities of any non-Federal entity or any activities taken by a non-Federal entity pursuant to mandatory standards, including activities relating to monitoring, operating defensive measures, or sharing cyber threat indicators. (ii) EXCEPTIONS.— (I) REGULATORY AUTHORITY SPECIFICALLY RELATING TO PREVENTION OR MITIGATION OF CYBERSECURITY THREATS.—Cyber threat indicators and defensive measures provided to the Federal Government under this title may, consistent with Federal or State regulatory authority specifically relating to the prevention or mitigation of cybersecurity threats to information systems, inform the development or implementation of regulations relating to such information systems. (II) PROCEDURES DEVELOPED AND IMPLEMENTED UNDER THIS TITLE.—Clause (i) shall not apply to procedures developed and implemented under this title. SEC. 106. PROTECTION FROM LIABILITY. (a) MONITORING OF INFORMATION SYSTEMS.—No cause of action shall lie or be maintained in any court against any private entity, and such action shall be promptly dismissed, for the monitoring

Select target paragraph3