7.5 Privacy, Data Protection & Borrower Security
Key Takeaways
- Loan documents contain NPPI — Social Security numbers, bank and loan numbers, income, and IDs — that makes a signed package a complete identity-theft kit.
- SPW Principle 6 requires the NSA to respect borrower privacy and protect closing documents from unauthorized disclosure.
- Secure the physical package, the journal, and any digital copies; transmit only over lender-approved secure channels.
- Shred non-returnable copies; never keep unauthorized personal copies of a borrower's loan package, even with good intent.
- Do not discuss borrowers, properties, or loan terms with anyone not authorized to know — including on social media.
SPW Principle 6: Privacy, Data Protection & Borrower Security
Loan documents are among the most sensitive paper a civilian handles. A signed package contains the borrower's full name, address, Social Security number, loan number, employer, income, bank account, and signature — a complete identity-theft kit. SPW Principle 6 requires the NSA to respect borrower privacy and protect closing documents from unauthorized disclosure. This is not just a best practice; it is a binding obligation under the SPW Code of Conduct and, in many states, under privacy and data-security law.
Non-Public Personal Information (NPPI)
NPPI is any information that identifies a consumer in connection with a financial transaction. In a loan package, NPPI includes:
- Social Security numbers and dates of birth
- Bank and account numbers
- Loan numbers and property addresses tied to a named borrower
- Income and employment details
- Copies of government-issued IDs
The NSA handles NPPI the way a fiduciary would: minimize exposure, secure storage, and prompt, proper disposal.
Secure Handling of the Package, Journal, and Digital Copies
| Item | Secure-handling rule |
|---|---|
| Physical package | In your direct possession or a locked container until in the carrier's control |
| Notary journal | Stored locked; never left in a vehicle or unattended bag |
| Scan-back images | Stored only on encrypted, password-protected devices; deleted per lender instruction |
| Transmission | Only over the lender-approved secure channel; never personal email |
| Working copies | Shredded when no longer needed; never recycled whole |
Digital Copies, Scan-Backs, and eReturn Data Security
When a lender requires scan-backs or eReturn, the NSA is briefly a data custodian. The scanned file is a complete copy of the borrower's financial life, and it must be protected at every step:
- Scan to a secured location — a password-protected folder on an encrypted drive, not a public cloud bucket or a phone's default photo roll.
- Transmit only via the lender's approved method — a portal, encrypted email, or designated app. Never attach loan documents to a standard, unencrypted email.
- Delete per instruction — once the lender confirms receipt and authorizes destruction, securely delete the file (empty the trash or recycle bin, not just the visible folder).
- No copies "for your records" — keeping unauthorized copies of a borrower's loan package is itself a privacy breach, even if the NSA means no harm.
Proper Disposal of Non-Returnable Copies
Any copy that is not returned to the lender or the borrower — extra printouts, misprints, scratch notes with loan numbers — must be shredded, not tossed in household recycling. Cross-cut shredding is the baseline; a borrower whose loan number turns up because an NSA recycled a misprint is a borrower with a valid complaint.
No Sharing of Borrower Information
The NSA does not discuss the borrower, the property, or the loan terms with anyone not authorized to know. That includes family members, other notaries, social media, and — notably — the NSA's own marketing. A post that says "just closed a $650,000 refi on Maple Street for a great couple" has disclosed a borrower's transaction to the public and violates Principle 6. Privacy is not just about paper; it is about what the NSA says and types.
Breach Response & State Privacy Laws
Even careful NSAs can face a privacy incident — a lost package, a stolen journal, a misdirected scan-back email. SPW Principle 6 does not promise perfection; it requires the NSA to protect borrower information and respond responsibly when something goes wrong. Knowing what to do before an incident happens is what separates a recoverable mistake from a career-ending one.
If a Package or Journal Is Lost or Stolen
- Report immediately to the contracting company and, where required, to your state's notary regulating official.
- Document the facts — when and where the loss occurred, what the package or journal contained, and what you did next.
- File a police report for a stolen journal or package; the report number supports the lender's and borrowers' identity-theft defenses.
- Notify affected borrowers only through the contracting company or per state law — do not improvise borrower notification yourself.
State Privacy and Data-Security Law
Many states have data-breach notification laws that apply to NPPI held by businesses, and some specifically regulate notary records. The NSA should know:
- Whether the state requires a notary journal and prescribes its retention and security.
- Whether the state imposes specific breach-notification duties on the holder of NPPI.
- Whether electronic notarization or scan-back is permitted and under what security conditions.
When the state law is stricter than the lender's instruction, follow the state law. When the lender's instruction is stricter, follow the lender. The NSA never gets to choose the lower standard.
Treat Every Copy as NPPI
The discipline that prevents most breaches is simple: treat every copy — paper, scan, photo, or journal entry — as NPPI that you are temporarily holding for someone else. You secure it, you use it only for the transaction, and you dispose of it the moment the transaction no longer requires it.
An NSA completes an eReturn signing and wants to keep a scanned copy of the package "in case the lender loses it." Which statement is correct under SPW Principle 6?