Gramm Leach Bailey Act
(GLBA)
privacy rule- notice
FI and affiliates must provide notice in clear and conspicuous manner of privacy policies and data sharing policies prior to disclosure
timing
1. at time of establishing customer relationship
2. 1 annually during relationship
safe harbor for violation- if have model disclosure form
GLBA privacy rule
disclosure
no disclosure to nonaffiliated unless
- opt out opportunity (that is implemented in 30 days)
- to service provider of FI
- consent
-joint marketing purpose
- necessary for transaction or law
GLBA privacy rule
refuse/resell
non-affiliates can’t reuse/resell info or disclose account # or access code to non affiliate for marketing (unless to a CRA)
GLBA safeguard rule
GLBA written contracts with service providers
written contracts are required FI under safeguard rule but not FI under privacy rule
state laws that exempt FI from GLBA regulation
Enforcement - Financial regulators
FTC anything not subject to financial regulator
FCRA importance
1st federal law to regulate use of PI by private businesses
FCRA
consumer report definition
3 components
FCRA
not consumer report
communications between affiliates
transmission that is only interactions between consumer and party making communication (ex. bank transaction record)
affiliate sharing info with CRA + consumer opt out opportunity
FCRA
additional requirements for investigative consumer report
(doesn’t apply if employer investigation)/relates to character
FCRA
user of CR
FCRA- user
is there a right to amend
NO- user doesn’t need to correct inaccurate info
FCRA
furnishers of PI to CRA requirements
NO PERMISSIBLE PURPOSE NEEDED
FCRA
permissible purposes to generate CR
needed for CRA and User
court order
credit transaction
consent
employment offer/reassignment
business transaction
credit/prepayment risk
child support
liquidation of financial institution
gov benefit eligibility
underwriting insurance
CRA requirements
current info
doesn’t apply to
- criminal convictions
- life insurance transactions 150,000+
- employment salary 75,000+
CRA requirements
complete info
bankruptcy file
- whether case is voluntary withdrawn
- chapter
if # of credit inquiries affects score
if consumer disputes info contained
CRA requirements
accurate info
if consumer dispute must
- reinvestigate within 30 days
- notify furnisher within 5 days + after investigation concluded
if accurate
- written statement must be included in all future disclosures form consumer on dispute
if inaccurate: delete + notify recipients in last 6 months
CRA requirements
consumer access
provide access to
1. info contained in file maintained by CRA
2. info on who disclosures to in last 2 years (employment) or 1 year (other)
3. inquiries received by CRA in last year
4. sources obtained info for CR
Fair and Accurate Credit Transactions Act (FACTA)
individual rights
FACTA
disposal rule
protect upon disposal from
1. unauthorized access
2. misses of info
includes destruction of property containing info (ex. flash drive)
FACTA
red flags rule
financial regulators must create guidelines for FI and creditors to use to guard against identity theft
program must be approved by BOD and have oversight by BOD
FACTA
preemption
stricter laws are preempt unless
1. CA or CO credit score laws
Enforcement federal
1st- FTC section 5 authority
2nd- functional regulators (within their jurisdiction)
3rd- CFPB