Sec. 4. Disclosure of institution privacy policy
673 words·~3 min read·
/bill/118/hr/1165/rh/section-4A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
Section 503 of the Gramm-Leach-Bliley Act ( 15 U.S.C. 6803 ) is amended— in subsection (a)— by striking customer relationship with a consumer and inserting customer or consumer relationship ; by striking clear and conspicuous disclosure to such consumer and inserting clear and conspicuous disclosure to such individual with whom such financial institution has a customer or consumer relationship ; by redesignating paragraphs (1), (2), and
(3)as paragraphs (2), (3), and (4), respectively; by inserting before paragraph (2), as so redesignated, the following: collecting nonpublic personal information; ; in paragraph (3), as so redesignated, by striking have ceased to be customers of and inserting have ceased to have a customer or consumer relationship with ; and in paragraph (4), as so redesignated, by striking personal information of consumers and inserting personal information of individuals with whom such financial institution has a customer or consumer relationship ; by redesignating subsections
(b)through
(f)as subsections
(c)through (g), respectively; by inserting after subsection
(a)the following: Upon the request of an individual with whom a financial institution has a customer or consumer relationship, a financial institution shall provide such individual with a copy of the disclosures required by subsection
(a)in writing or in electronic or other form as permitted by the regulations prescribed under section 504. ; and in subsection (d), as so redesignated— in paragraph (1)— by inserting collecting or before disclosing nonpublic ; and by striking subparagraph
(B)and inserting the following: the purpose for which the financial institution collects the nonpublic personal information of individuals with whom the financial institution has a customer or consumer relationship, as well as how the information will be used; ; in paragraph (2), by inserting before the semicolon the following: , provided in a manner that provides individuals with whom the financial institution has a customer or consumer relationship a meaningful understanding of the information that is collected ; in paragraph (3), by striking and at the end; in paragraph (4), by striking the period at the end and inserting a semicolon; and by adding at the end the following: if the financial institution collects nonpublic personal information for any purpose other than to provide a specific product or service such an individual is seeking— a description of such information; the purpose for which such information is collected; and the right of such individual to opt out of having such nonpublic personal information collected or disclosed to a nonaffiliated third party, and the manner in which such individual may make such opt out election; the data retention policies of the financial institution, including— the period of time for which the financial institution retains the nonpublic personal information relating to such individual; or the criteria used by the financial institution to determine the period of time for which such information is retained; the right of such individual to direct the financial institution to terminate the sharing of nonpublic personal information with a nonaffiliated third party, and the manner in which such individual may make such direction; the right of such individual to request that the financial institution provide the individual with a list of all nonpublic personal information relating to the individual held by the financial institution, and the manner in which the individual may make such request; and the right of such individual to direct the financial institution to delete nonpublic personal information of the individual held by the financial institution (subject to the exceptions provided under section 502A(b)(3)), and the manner in which the individual may make such direction. ; in subsection (f), as so redesignated— in paragraph (2)(A), by striking to consumers and inserting to individuals with whom a financial institution has a customer or consumer relationship ; and in paragraph (2)(C), by striking enable consumers and inserting enable individuals with whom a financial institution has a customer or consumer relationship ; and in subsection (g), as so redesignated, by striking sent to consumers and inserting sent to individuals with whom a financial institution has a customer or consumer relationship .
Connectionstraces to 1
Traces to 1 document
Citation graph
cites case law
Sec. 4
Disclosure of institution privacy policy
Cites 1Cited by 0 across 0 sources