Privacy protection and reimbursements

Full Title:
RECOVER PII Act

Summary#

This bill makes changes to federal identity-protection rules and lets agencies pay employees back for certain privacy tools. Its main changes are to a 2017 law that provided identity protection to people harmed by federal data breaches, and a new rule letting agencies reimburse staff for “privacy-enhancing services.” The broad goal is to extend and strengthen protection for people affected by agency data breaches and to encourage use of privacy tools by agency staff.

  • Extends the earlier identity-protection authority so it applies for fiscal year 2016 and every fiscal year after that (removing the previous 2016–2026 limit).
  • Makes identity-protection coverage “effective for the remainder of the life of the affected individual.”
  • Requires identity theft insurance of not less than $5,000,000 (the bill wording does not specify whether that amount is per person, per incident, or in total).
  • Allows any federal agency (executive, legislative, or judicial branch authority) to use amounts in its salaries-and-expenses appropriations for FY2026 or later to reimburse an employee, or a contractor’s employee who supports the agency, for up to 100% of the cost of privacy-enhancing services.
  • Requires employees or contractor employees to give whatever documentation the agency reasonably requires to get reimbursement.
  • Defines “privacy-enhancing service” broadly to include software, hardware, technical processes, or other technological means that reduce or suppress personal information.

What it means for you#

  • Individuals whose personal data was exposed in federal agency breaches

    • Could keep identity-protection coverage indefinitely instead of only through 2026.
    • Could have access to identity theft insurance under the program; the bill sets a floor of $5,000,000 but does not clearly say how that amount is applied.
  • Federal employees and contractor employees who support agencies

    • May be able to get reimbursed (up to 100%) for buying privacy tools or services if their agency approves and the cost is documented.
    • Reimbursements would come from the agency’s salaries-and-expenses funds for FY2026 or later.
  • Other members of the public

    • If you are not an affected individual or a federal employee/contractor, this bill likely has little direct effect on you.
  • Agencies and agency IT/security staff

    • May need to set rules and documentation procedures for reimbursements.
    • May need to manage expanded, indefinite identity-protection benefits for breach victims.

Expenses#

No publicly available information.

  • The bill does not include a fiscal note or specific budget numbers in the provided text.
  • Possible public costs (not quantified in the bill) include: continuing identity-protection program costs beyond FY2026; insurance premiums tied to the $5,000,000 requirement; and agencies using salaries-and-expenses appropriations to reimburse employees for privacy tools.
  • Administrative costs could rise because agencies must process reimbursements and collect documentation.
  • It is unclear whether the $5,000,000 insurance requirement refers to a per-person policy limit, a group limit, or something else.

Proponents' View#

  • The bill appears intended to make identity-protection help for federal breach victims permanent rather than time-limited.
  • It appears intended to provide stronger financial protection by adding a minimum identity-theft insurance amount.
  • Allowing agencies to reimburse staff for privacy-enhancing services could increase employee adoption of tools that reduce privacy risk and help protect agency data.
  • Reimbursements could help employees and contractor staff pay for security measures they otherwise could not afford.

Opponents' View#

  • One concern is that the bill does not explain how the $5,000,000 insurance amount is applied (per person, per incident, or in total), which affects how useful that number is in practice.
  • The bill does not provide a cost estimate or say how agencies will fund ongoing identity-protection benefits, so long-term budget impacts are unclear.
  • Letting agencies use salary-and-expense funds for reimbursements may divert money from other personnel needs unless additional funding is provided.
  • The definition of “privacy-enhancing service” is broad, which may create questions about what qualifies and increase administrative work to review claims.
  • It is not clear whether non-employee victims of breaches (for example, contractors’ customers or other members of the public) get the same access to reimbursements or how the two parts of the bill (identity protection and reimbursements) interact.