Summary#
This bill stops the Securities and Exchange Commission (SEC) from requiring that personally identifiable information (PII) be submitted as part of consolidated audit trail (CAT) reporting. The main change is a ban on SEC-mandated collection of PII tied to orders or other reportable events under the current CAT rules. The bill’s stated goal is to protect investors’ personal information.
- Main change: The SEC may not require a national securities exchange, a national securities association, or a member of those entities to provide personally identifiable information about a market participant to meet CAT reporting rules.
- Definition added: The bill defines “personally identifiable information” to include name, address, date or year of birth, Social Security number, phone number, email, and IP address, and any information that can be used to identify an individual.
- Scope: The restriction applies to collection required to meet the specific CAT reporting rule cited (the rule for orders and reportable events).
- Does not say: The bill does not explicitly forbid private parties or exchanges from collecting or sharing PII voluntarily, nor does it describe alternative data that would be required instead.
What it means for you#
- Investors / Individuals: Your name, address, SSN, phone, email, IP address, or birth date would not be required to be submitted to meet the SEC’s CAT reporting requirement, which could reduce the sharing of that personal data with regulators under that rule.
- National securities exchanges and associations: They cannot be required by the SEC to include the listed PII fields when submitting information under the CAT rule quoted in the bill.
- Broker-dealers / Members of exchanges: They would not be compelled by the SEC to send PII as part of CAT order or reportable-event reports. They might still collect PII for other reasons (accounts, compliance) unless other laws say otherwise.
- Market regulators and investigators: The SEC could be prevented from receiving certain PII through CAT reports. This could change how regulators match orders to individual persons during surveillance or investigations (this is a likely effect inferred from the change).
- Service providers and technology firms that run CAT systems: They may need to adjust data collection and reporting processes if the ban becomes law.
Expenses#
No publicly available information.
- The bill text and supplied status do not include a fiscal note or cost estimate.
- Possible fiscal or administrative effects (not estimated here): changes to reporting systems, updates to data storage and handling, or adjustments in SEC or exchange staffing and processes. These are not quantified in the materials provided.
Proponents' View#
- The bill appears intended to protect investors’ private information by preventing the SEC from requiring disclosure of sensitive personal data in CAT reports.
- This could be seen as reducing the risk that personal data collected for market surveillance is exposed through a breach or misused.
- It may be viewed as narrowing data collected to what is strictly necessary for market oversight, limiting the scope of personal data shared with regulators.
Opponents' View#
- One concern is that removing required PII from CAT reports could make it harder for regulators to trace orders to specific individuals during fraud investigations or market abuse surveillance.
- The bill does not clearly say what alternative identifiers, if any, would be required. That leaves unclear how order-level data would be linked to real persons when needed.
- It is uncertain whether exchanges or firms could still collect or share PII by other means; the practical effect on data flows and enforcement is not fully spelled out in the bill text.
- The materials provided do not show any cost estimates or analysis of the trade-off between privacy protection and regulatory effectiveness.