Last year, the eight federal regulators that regulate the financial services industry issued a "simplified" model privacy notice that was published in the Federal Register on December 1, 2009. Today, the regulators released an "Online Form Builder" to guide a covered institution to select the version of the model form that fits its practices, such as whether the institution provides an opt-out for consumers.
Under the new regulation, to obtain a legal "safe harbor" and satisfy the disclosure requirements under the Gramm-Leach-Bliley Act, institutions must follow the instructions in the model form regulation when using the Online Form Builder.
The form is available here: Online Form Builder
Showing posts with label GLBA. Show all posts
Showing posts with label GLBA. Show all posts
Thursday, April 15, 2010
Thursday, June 18, 2009
FTC Issues Consent Order for GLBA Violations
In the run-up to the enforcement deadline for the Identity Theft Red Flag Rule (August 1, 2009 - more on that in another post), enforcement of the Gramm-Leach-Bliley Privacy Rule and Safeguards Rule has not been forgotten by the Federal Trade Commission.
This week, the FTC issued a consent order against mortgage lender James B. Nutter & Company for violations of GLBA resulting from the company's lack of an adequate information security program and safeguards.
This consent order, like similar orders issued by the FTC of late, provides a blueprint for executives and compliance officers: there are consequences that directly result from the failures to implement reasonable information security and privacy programs. The FTC order requires, among other things, that James B. Nutter & Company implement a comprehensive security program, and engage a third-party professional to perform an initial assessment of that program, followed by biennial assessments for 10 years. Compliance with an FTC consent order is more costly than establishing a compliance program from the start.
Links:
The FTC announcement
The FTC complaint
The Agreement and Consent Order
This week, the FTC issued a consent order against mortgage lender James B. Nutter & Company for violations of GLBA resulting from the company's lack of an adequate information security program and safeguards.
This consent order, like similar orders issued by the FTC of late, provides a blueprint for executives and compliance officers: there are consequences that directly result from the failures to implement reasonable information security and privacy programs. The FTC order requires, among other things, that James B. Nutter & Company implement a comprehensive security program, and engage a third-party professional to perform an initial assessment of that program, followed by biennial assessments for 10 years. Compliance with an FTC consent order is more costly than establishing a compliance program from the start.
Links:
The FTC announcement
The FTC complaint
The Agreement and Consent Order
Labels:
consent order,
FTC,
GLBA,
information security,
privacy,
Red Flag,
safeguards
Subscribe to:
Posts (Atom)