Gramm-Leach-Bliley Act Overview
Nonpublic Personal Information
Financial data like SSN, not publicly available
Disposal Rule
Guidelines for proper disposal of nonpublic personal information
Identity Theft Prevention Program (ITPP)
Identifies, detects, and responds to identity theft red flags
Privacy Rule
Informs customers on nonpublic personal information usage
Enforcement Actions
Initiated by FTC for non-compliance with Privacy/Safeguards Rules
Red Flags
Patterns indicating potential identity theft
Information Security Program (ISP)
Protects NPI, appoints compliance officer, and implements safeguards
Safeguards Rule
Protects customer info from identity theft in paper/electronic formats
Due Diligence
Required for document destruction contractor under Disposal Rule
Financial Privacy Rule
Requires initial Privacy Notice to be given to every customer
Red Flags Rule
Requires measures to prevent identity theft in car purchases
Challenge Questions
Used to verify identity by recalling specific information
Safe Harbor Protection
Using FTC-approved forms for Privacy Notice
Gramm-Leach-Bliley Act
Legislation including Privacy, Safeguards, and Disposal Rules
FTC Fines
May reach $46,517 per violation for non-compliance