26.3 Privacy Notices, Sharing and Opt-Out Opportunities
Key Takeaways
Regulation P notices explain applicable information collection and sharing practices.
Nonexempt sharing with nonaffiliated third parties requires the applicable opt-out opportunity.
The annual-notice exception applies only when its sharing and notice-change conditions are met.
1. Statutory Architecture and Key Regulatory Definitions
Regulation P enforces strict operational requirements on financial institutions to ensure transparency and consumer control over personally identifiable financial data.
Nonpublic Personal Information (NPI, 12 CFR § 1016.3(p))
Nonpublic Personal Information is defined as personally identifiable financial information (PIFI) provided by a consumer to a financial institution, resulting from any transaction with or service performed for the consumer, or otherwise obtained by the financial institution. It also encompasses any list, description, or grouping of consumers derived using personally identifiable financial information.
- Included Data: Information provided on account applications (e.g., name, Social Security Number, income, assets); account balances, payment history, and overdraft records; credit scores and consumer report data; the fact that an individual is or has been a customer of the bank; and internet tracking data (cookies or IP addresses) collected in connection with financial services.
- Publicly Available Information Exclusion: NPI does not include publicly available information, provided the financial institution has a reasonable basis to believe the information is lawfully made available to the general public from government records, widely distributed media, or disclosures required by federal, state, or local law.
- The Derived List Rule: If a list is compiled using NPI, the entire list is classified as NPI, even if individual entries contain publicly available information. For example, a list of all property owners in a municipal land registry is publicly available; however, a list of mortgagors who hold home loans with a specific bank is NPI because the list was derived using the bank's nonpublic customer records.
Consumer vs. Customer: A Critical Compliance Distinction
Regulation P draws a sharp operational distinction between "consumers" and "customers" under 12 CFR § 1016.3(e) and (i):
2. Privacy Notice Requirements (12 CFR § 1016.4, § 1016.5, § 1016.8)
Regulation P establishes strict rules governing the form, content, and delivery timing of consumer privacy disclosures.
Initial Privacy Notice (12 CFR § 1016.4)
- Customer Delivery Mandate: A depository institution must provide a clear and conspicuous initial privacy notice that accurately reflects its privacy policies and practices to an individual not later than when the institution establishes a customer relationship (typically at or before account opening).
- Exceptions to Prior Delivery (§ 1016.4(e)): A bank may deliver an initial notice within a reasonable time after establishing a customer relationship only under two narrow operational circumstances:
- Establishing the relationship is not at the customer's election (e.g., the bank purchases loan servicing rights in the secondary mortgage market);
- Providing the notice at account opening would substantially delay the customer's transaction and the customer agrees to receive the notice at a later time (e.g., transactions conducted via telephone where immediate written delivery is impossible).
- Consumer Delivery Rule: A bank is not required to deliver an initial privacy notice to a consumer who is not a customer, unless the bank intends to disclose NPI about the consumer to a nonaffiliated third party outside the statutory exceptions.
Annual Privacy Notice (12 CFR § 1016.5)
A financial institution must provide a privacy notice to customers at least once in any period of 12 consecutive months during the continuation of the customer relationship.
The FAST Act Exception to Annual Privacy Notices (12 CFR § 1016.5(e))
Enacted under Section 75001 of the Fixing America's Surface Transportation (FAST) Act of 2015 and incorporated into Regulation P in August 2018, depository institutions are granted a statutory exemption from providing an annual privacy notice if they satisfy a two-prong test:
If changed sharing requires a revised notice under Section 1016.8, deliver that notice and a reasonable opt-out opportunity before the non-exempt sharing. Resume annual notices under Section 1016.5(e)’s applicable timing rule. Thirty days after mailing is an example of a reasonable opportunity, not a universal fixed deadline.
Revised Privacy Notice (12 CFR § 1016.8)
A financial institution must deliver a revised privacy notice and provide a fresh opt-out opportunity before:
- Disclosing a new category of NPI to any nonaffiliated third party;
- Disclosing NPI to a new category of nonaffiliated third party; or
- Disclosing NPI about a former customer who has not had an opportunity to opt out regarding that sharing category.
3. Information Sharing Categories & Opt-Out Rules
Under 12 CFR § 1016.10, a financial institution may not disclose NPI about a consumer to a nonaffiliated third party unless it satisfies three conditions:
- Provided an initial privacy notice;
- Provided a clear opt-out notice explaining the consumer's right to opt out;
- Provided a reasonable opportunity to opt out (thirty days after mailing or electronic delivery is a regulatory example); and
- The consumer has not exercised the opt-out right.
Reasonable Opt-Out Mechanisms (12 CFR § 1016.7)
The institution must provide a reasonable and convenient means for consumers to opt out. Permissible methods include:
- Designating a toll-free telephone number staffed during standard business hours;
- Providing a detachable check-off form with a pre-addressed return envelope;
- Providing an electronic opt-out mechanism for customers who open accounts online.
Important
Unreasonable Opt-Out Barriers: Requiring a consumer to draft their own letter, write an email with customized text, or place a long-distance toll telephone call at their own expense is strictly deemed unreasonable and unlawful under 12 CFR § 1016.7(a)(2).
The Three Statutory Exceptions to the Opt-Out Requirement
Congress established three explicit statutory exceptions where a financial institution may disclose NPI to nonaffiliated third parties without providing consumers an opt-out notice or opt-out opportunity:
A community bank has not altered its customer information sharing practices or privacy policies for four consecutive years. The bank shares customer NPI exclusively with core transaction processing vendors under Section 14, regulatory supervisory agencies under Section 15, and an affiliated mortgage company in compliance with FCRA. How does the FAST Act statutory exception (12 CFR § 1016.5(e)) apply to the bank's annual privacy notice obligations?
The bank must post an abbreviated privacy notice on its website homepage each quarter to maintain the annual notice exemption.
The bank loses its exemption because sharing information with core IT vendors requires an affirmative annual notice disclosure.
The bank is required to mail an annual privacy notice every two years rather than annually under the FAST Act relief framework.
The bank is completely exempt from delivering an annual privacy notice to its customers because it shares NPI solely under non-opt-out statutory exceptions and its policies have remained unchanged.
Sections you finish are checked off in the contents.