Have you ever filled out an application for a loan or applied for a credit card and wondered about the security of the personal information you have provided? If so, you are not alone.
Over the last few years, there has been growing consumer concern regarding the collection and dissemination of information provided by consumers to financial institutions when obtaining financial services or products.
Beyond Cash Donations: How New Forms of Giving Are Transforming Not-for-Profit Accounting
Evolving Funding Landscape for Not-for-Profits Not-for-profit organizations are being asked to do more with less,…
Learn More
In response to this concern, Congress included financial information privacy protection provisions in the recently enacted Gramm Leach Bliley Act. Although not the Act’s primary focus, it requires “financial institutions,” a broadly defined term which includes retailers who issue credit cards and tax preparers, to make certain disclosures to individuals regarding their privacy policies and to give these individuals the opportunity to prevent the release of certain personal information.
The Act also empowers several regulatory agencies, including the Federal Trade Commission, to implement additional consumer privacy protections.
On May 24, 2000, the FTC enacted its own privacy rules. These rules impose additional legal requirements for banks and other defined “financial institutions” and companies. A financial institution is defined by the FTC Rules as any business engaging in a “financial activity” as defined in the Bank Holding Company Act of 1946 and includes:
- Banks
- Credit Card companies
- Retailers that extend credit by issuing credit cards directly to consumers
- Personal property or real estate appraisers
- Businesses that regularly wire money to and from customers
- Tax preparers that are in the business of completing income tax returns
- Mortgage brokers, and
- Investment advisory companies or credit counseling services.
Entities specifically excluded from the FTC’s definition are:
- Retailers who provide lay-a-way and deferred payment plans
- Retailers who accept payment in the form of cash, checks, or credit cards issued by others, and
- Merchants who allow an individual to “run a tab.”
The FTC rules require financial institutions to: (1) provide notice to customers about a company’s privacy policies and practices; (2) describe the conditions under which the company may disclose non-public personal information about its customers to non-affiliated third parties; and (3) provide a method for customers to prevent disclosure by “opting out.” The FTC privacy rules only apply to nonpublic personal information provided by individuals when obtaining financial products or services primarily for personal, family or household purposes from financial institutions. Non-public personal information includes any information that the company obtains about a consumer in connection with a financial product or service such as, information that an individual provides on an application to obtain a financial product or service, account balance information, payment history, overdraft history, and credit or debit card purchase information.
The timing of the privacy notice depends on whether the individual is a customer or consumer. A consumer is defined by the rules as an individual who obtains or who has obtained a financial product or service from a financial institution such as an individual who applies for credit for personal, family or household purposes, regardless of whether credit is actually extended. A financial institution is required to provide a consumer with notice of its practices only at the time the financial institution intends to share personal information collected about the consumer with a non-affiliated third party.
A customer is an individual who has an ongoing relationship with a financial institution in which the company provides one or more products or services to the customer. Financial institutions must provide notice of its practices both at the time the customer relationship is formed and annually thereafter.
The FTC rules require that the privacy notice include certain information regarding the company’s policies and practices such as:
- The categories of nonpublic personal information collected and disclosed
- The categories of affiliates and non-affiliated third parties to whom the company discloses non-public personal information about its consumers to
- The categories of nonpublic personal information disclosed about the company’s former customers
- The categories of nonpublic personal information disclosed to a non-affiliated third party who perform services for the company
- An explanation of the consumer’s right to “opt out” of disclosures of nonpublic personal information to nonaffiliated third parties, including the methods for “opting out”
- Any disclosures that the company makes under the Fair Credit Reporting Act
- The company’s policies and practices with respect to protecting the confidentiality of nonpublic personal information; and
- Any disclosures the company makes of the information to nonaffiliated third parties.
The opt-out provision of the rules provides individuals with the most protection. Under these rules, an “opt out” notice must provide a clear and conspicuous disclosure that states that the institution discloses, or reserves the right to disclose, nonpublic personal information about the consumer to a nonaffiliated third party, that the consumer has a reasonable right to “opt out” of such disclosure and provide a reasonable means to exercise that right.
Although the effect of these privacy protections remains to be seen, the mandatory discloser and opt-out provisions of the rule alert consumers to the type of information collected by defined financial institutions and affords the consumer some control over the dissemination of such information to third parties.
Amy B. Spagnole is an associate in the law firm of Hinckley, Allen & Snyder LLP and her practice concentrates in the area of intellectual property law and litigation.












