(a) Disclosure required

At the time of establishing a customer relationship with a consumer and not less than annually during the continuation of such relationship, a financial institution shall provide a clear and conspicuous disclosure to such consumer, in writing or in electronic form or other form permitted by the regulations prescribed under section 6804 of this title, of such financial institution’s policies and practices with respect to—

(1) disclosing nonpublic personal information to affiliates and nonaffiliated third parties, consistent with section 6802 of this title, including the categories of information that may be disclosed;

(2) disclosing nonpublic personal information of persons who have ceased to be customers of the financial institution; and

(3) protecting the nonpublic personal information of consumers.

(b) Regulations

Ask a business law question, get an answer ASAP!
Thousands of highly rated, verified business lawyers.
Click here to chat with a lawyer about your rights.

Terms Used In 15 USC 6803

  • consumer: means an individual who obtains, from a financial institution, financial products or services which are to be used primarily for personal, family, or household purposes, and also means the legal representative of such an individual. See 15 USC 6809
  • financial institution: means any institution the business of which is engaging in financial activities as described in section 1843(k) of title 12. See 15 USC 6809
  • nonpublic personal information: means personally identifiable financial information&mdash. See 15 USC 6809
  • State: means a State, the District of Columbia, the Commonwealth of Puerto Rico, or any other territory or possession of the United States. See 1 USC 7
  • writing: includes printing and typewriting and reproductions of visual symbols by photographing, multigraphing, mimeographing, manifolding, or otherwise. See 1 USC 1

Disclosures required by subsection (a) shall be made in accordance with the regulations prescribed under section 6804 of this title.

(c) Information to be included

The disclosure required by subsection (a) shall include—

(1) the policies and practices of the institution with respect to disclosing nonpublic personal information to nonaffiliated third parties, other than agents of the institution, consistent with section 6802 of this title, and including—

(A) the categories of persons to whom the information is or may be disclosed, other than the persons to whom the information may be provided pursuant to section 6802(e) of this title; and

(B) the policies and practices of the institution with respect to disclosing of nonpublic personal information of persons who have ceased to be customers of the financial institution;


(2) the categories of nonpublic personal information that are collected by the financial institution;

(3) the policies that the institution maintains to protect the confidentiality and security of nonpublic personal information in accordance with section 6801 of this title; and

(4) the disclosures required, if any, under section 1681a(d)(2)(A)(iii) of this title.

(d) Exemption for certified public accountants

(1) In general

The disclosure requirements of subsection (a) do not apply to any person, to the extent that the person is—

(A) a certified public accountant;

(B) certified or licensed for such purpose by a State; and

(C) subject to any provision of law, rule, or regulation issued by a legislative or regulatory body of the State, including rules of professional conduct or ethics, that prohibits disclosure of nonpublic personal information without the knowing and expressed consent of the consumer.

(2) Limitation

Nothing in this subsection shall be construed to exempt or otherwise exclude any financial institution that is affiliated or becomes affiliated with a certified public accountant described in paragraph (1) from any provision of this section.

(3) Definitions

For purposes of this subsection, the term “State” means any State or territory of the United States, the District of Columbia, Puerto Rico, Guam, American Samoa, the Trust Territory of the Pacific Islands, the Virgin Islands, or the Northern Mariana Islands.

(e) Model forms

(1) In general

The agencies referred to in section 6804(a)(1) of this title shall jointly develop a model form which may be used, at the option of the financial institution, for the provision of disclosures under this section.

(2) Format

A model form developed under paragraph (1) shall—

(A) be comprehensible to consumers, with a clear format and design;

(B) provide for clear and conspicuous disclosures;

(C) enable consumers easily to identify the sharing practices of a financial institution and to compare privacy practices among financial institutions; and

(D) be succinct, and use an easily readable type font.

(3) Timing

A model form required to be developed by this subsection shall be issued in proposed form for public comment not later than 180 days after October 13, 2006.

(4) Safe harbor

Any financial institution that elects to provide the model form developed by the agencies under this subsection shall be deemed to be in compliance with the disclosures required under this section.

(f) Exception to annual notice requirement

A financial institution that—

(1) provides nonpublic personal information only in accordance with the provisions of subsection (b)(2) or (e) of section 6802 of this title or regulations prescribed under section 6804(b) of this title, and

(2) has not changed its policies and practices with regard to disclosing nonpublic personal information from the policies and practices that were disclosed in the most recent disclosure sent to consumers in accordance with this section,


shall not be required to provide an annual disclosure under this section until such time as the financial institution fails to comply with any criteria described in paragraph (1) or (2).