Protecting Investors’ Personally Identifiable Information Act
Summary
HB1483, titled the Protecting Investors’ Personally Identifiable Information Act, would bar the Securities and Exchange Commission from requiring the collection of personally identifiable information in connection with consolidated audit trail reporting requirements. The bill applies to national securities exchanges, national securities associations, and their members, and it specifically targets information submitted for orders or reportable events under the SEC’s CAT rules.
The bill defines personally identifiable information broadly to include data such as a person’s name, address, date or year of birth, Social Security number, telephone number, email address, and IP address. In effect, it would limit the SEC’s ability to use CAT reporting to gather data that can identify or trace individual market participants, while leaving the broader audit trail framework in place.
Impact
If enacted, the bill would amend the practical scope of SEC consolidated audit trail reporting by prohibiting the agency from mandating personally identifiable information in those reports. It would affect securities exchanges, broker-dealers, and other market participants subject to CAT obligations, and would likely require the SEC to revise or narrow existing rules and data-collection practices under 17 CFR 242.613(c)(7) or successor regulations.
Sentiment
The available legislative history suggests generally favorable committee sentiment toward the bill, as reflected by its being ordered to be reported on an amended basis by a 27-21 vote. That vote indicates support from a majority of the committee, but not unanimity, and the absence of recorded transcripts limits insight into the full range of arguments. Overall, the bill appears to have been advanced as a privacy-protection measure for investors and market participants.
Contention
The main point of contention is the balance between investor privacy and market surveillance. Supporters appear to favor limiting the SEC’s collection of sensitive personal data to reduce privacy and cybersecurity risks, while opponents likely worry that restricting personally identifiable information could weaken the usefulness of the consolidated audit trail for regulatory oversight, enforcement, and market integrity. The close committee vote suggests this privacy-versus-regulation tradeoff was the central issue dividing members.