Financial Laws Flashcards
Gramm Leach Bailey Act
(GLBA)
privacy rule- notice
FI and affiliates must provide notice in clear and conspicuous manner of privacy policies and data sharing policies prior to disclosure
timing
1. at time of establishing customer relationship
2. 1 annually during relationship
safe harbor for violation- if have model disclosure form
GLBA privacy rule
disclosure
no disclosure to nonaffiliated unless
- opt out opportunity (that is implemented in 30 days)
- to service provider of FI
- consent
-joint marketing purpose
- necessary for transaction or law
GLBA privacy rule
refuse/resell
non-affiliates can’t reuse/resell info or disclose account # or access code to non affiliate for marketing (unless to a CRA)
GLBA safeguard rule
- adopt info security program (TAP)
- appoint qualified individual to oversee
- conduct risk assessment
- regularly test safeguards
- establish incident response plan
- establish contract requiring service providers to adopt safeguards
GLBA written contracts with service providers
written contracts are required FI under safeguard rule but not FI under privacy rule
state laws that exempt FI from GLBA regulation
- CCPA california
- Virginia VCDPA
- Connecticut
- Colorado CPA
Enforcement - Financial regulators
- federal reserve
- comptroller of currency
- FDIC
- NCUA
- SEC
state level insurance agencies
FTC anything not subject to financial regulator
FCRA importance
1st federal law to regulate use of PI by private businesses
FCRA
consumer report definition
3 components
- form of communication (oral written or any other)
- purpose ( eligibility for credit, employment, insurance, business in general)
- type of info contained inside
- bears on credit worthiness
- standing
- capacity
- character
-general reputation
- personal characteristics
- mode of living
FCRA
not consumer report
communications between affiliates
transmission that is only interactions between consumer and party making communication (ex. bank transaction record)
affiliate sharing info with CRA + consumer opt out opportunity
FCRA
additional requirements for investigative consumer report
(doesn’t apply if employer investigation)/relates to character
- notification to consumer within 3 days
- verification of all negative info before including
- certification to CRA that disclosures to consumers have been made by user and will make required disclosures upon consumer report
FCRA
user of CR
- permissible purpose
- must notify consumer affected by adverse action (business, credit employment with neg impact)
- no resell unless notify CRA of identity of end user and permissible purposes end user will use report for
- adequate records of criteria used for past 3 years (if use prescreened list of preselected qualifications)
FCRA- user
is there a right to amend
NO- user doesn’t need to correct inaccurate info
FCRA
furnishers of PI to CRA requirements
- up to date, accurate info (no cause to believe not accurate)
- notice of any
- consumer dispute
- closure of consumer account
- delinquency within 90 days of collection
- identity theft - notice to consumer of negative info included (30 days)
NO PERMISSIBLE PURPOSE NEEDED
FCRA
permissible purposes to generate CR
needed for CRA and User
court order
credit transaction
consent
employment offer/reassignment
business transaction
credit/prepayment risk
child support
liquidation of financial institution
gov benefit eligibility
underwriting insurance