Code of Vermont Rules
Agency 21 - DEPARTMENT OF FINANCIAL REGULATION
Sub-Agency 030 - SECURITIES DIVISION
Chapter 004 - REGULATION S-2001-01: PRIVACY OF CONSUMER FINANCIAL AND HEALTH INFORMATION
Section 21 030 004 - REGULATION S-2001-01: PRIVACY OF CONSUMER FINANCIAL AND HEALTH INFORMATION
Current through August, 2024
Section 1 Authority
This Regulation is promulgated pursuant to the Commissioner's authority under 9 V.S.A., Chapter 131, Section 4224a, Section 4229 and Section 4237 and Title 8, Section 10.
Section 2 Purpose, Scope and Compliance
Section 3 Rule of Construction
The examples in this Regulation and the sample clauses in the Appendix of this Regulation provide guidance concerning the Regulation's application in ordinary circumstances. The facts and circumstances of each individual situation, however, will determine whether compliance with an example or use of a sample clause, to the extent applicable, constitutes compliance with this Regulation.
Section 4 Definitions
As used in this Regulation, unless the context requires otherwise:
Section 5 Initial Privacy Notice to Consumers Required
Section 6 Annual Privacy Notice to Customers Required
Section 7 Information to be Included in Privacy Notices
Section 8 Form of Opt in Notice to Consumers; Opt in Methods
Section 9 Revised Privacy Notices
Section 10 Delivering Privacy and Opt in Notices
Section 11 Limits on Disclosure of Nonpublic Personal Financial Information to Nonaffiliated Third Parties
Section 12 Limits on Redisclosure and Reuse of Nonpublic Personal Financial Information
Section 13 Limits on Sharing Account Number Information for Marketing Purposes
Section 14 Exception to Opt In Requirements for Disclosure of Nonpublic Personal Information for Service Providers and Joint Marketing
Section 15 Exceptions to Notice and Opt in Requirements for Disclosure of Nonpublic Personal Financial Information for Processing and Servicing Transactions
Section 16 Other Exceptions to Notice and Opt in Requirements for Disclosure of Nonpublic Personal Financial Information
Section 17 When Authorization Required for Disclosure of Nonpublic Personal Health Information
Section 18 Authorizations
Section 19 Authorization Request Delivery
A request for authorization and an authorization form may be delivered to a consumer or a customer as part of an opt in notice pursuant to § 10, provided that the request and the authorization form are clear and conspicuous. An authorization form is not required to be delivered to the consumer or customer unless you intend to disclose protected health information pursuant to Section 17(a).
Section 20 Relationship to Federal Rules
Irrespective of whether you are subject to the federal Health Insurance Portability and Accountability Act privacy rule as promulgated by the U.S. Department of Health and Human Services, 45 C.F.R. Parts 160 and 164, (the "federal rule"), if you comply with all requirements of the federal rule and its effective date provision, you shall be deemed to be in compliance with the provisions of this Subpart D; provided, however, you shall be prohibited from making disclosures under the provisions of 45 C.F.R. § 164.514(e)(2) without the consumer's prior written consent. Nothing in this regulation shall be deemed to make applicable any provision of the federal Health Insurance Portability and Accountability Act of 1996 or the regulations promulgated thereunder to any financial institution not otherwise subject thereto.
Section 21 Relationship to State Laws
Nothing in this article shall preempt or supercede existing state law related to medical records, health or insurance information privacy.
Section 22 Protection of Fair Credit Reporting Acts
Section 23 Nondiscrimination
Section 24 Violations
In addition to any other sanctions available to the commissioner under Vermont law for violations of this Regulation, any violation of this Regulation shall be deemed an unfair method of competition or an unfair or deceptive act or practice in the conduct of a broker-dealer or investment adviser for the purposes of Chapter 131 of Title 9 V.S.A.
Section 25 Severability
If any section or portion of a section of this Regulation or its applicability to any person or circumstance is held invalid by a court, the remainder of the Regulation or the applicability of the provision to other persons or circumstances shall not be affected.
Section 26 Effective Date
Section 27 Procedures to Safeguard Customer Records and Information
Every broker-dealer and every investment adviser registered with the Department must adopt policies and procedures that address administrative, technical, and physical safeguards for the protection of customer records and information. These policies and procedures must be reasonably designed to:
Appendix. Sample Clauses.
Financial institutions, including a group of financial holding company affiliates that use a common privacy notice, may use the following sample clauses, if the clause is accurate for each institution that uses the notice. (Note that disclosure of certain information, such as assets, income, and information from a consumer reporting agency, may give rise to obligations under the Fair Credit Reporting Act, such as a requirement to permit a consumer to opt in to disclosures to affiliates or designation as a consumer reporting agency if disclosures are made to nonaffiliated third parties.)
A-1-Categories of information you collect (all institutions)
You may use this clause, as applicable, to meet the requirement of § 7(a)(1) to describe the categories of nonpublic personal financial information you collect.
Sample Clause A-1:
We collect nonpublic personal financial information about you from the following sources:
Information we receive from you on applications or other forms;
Information about your transactions with us, our affiliates, or others; and
Information we receive from a consumer reporting agency.
A-2-Categories of information you disclose (institutions that disclose outside of the exceptions)
You may use one of these clauses, as applicable, to meet the requirement of § 7(a)(2) to describe the categories of nonpublic personal financial information you disclose. You may use these clauses if you disclose nonpublic personal financial information other than as permitted by the exceptions in § 14, § 15, and § 16.
Sample Clause A-2, Alternative 1:
We may disclose the following kinds of nonpublic personal financial information about you:
Information we receive from you on applications or other forms, such as [provide illustrative examples, such as "your name, address, social security number, assets, and income"];
Information about your transactions with us, our affiliates, or others, such as [provide illustrative examples, such as "your account balance, payment history, parties to transactions, and credit card usage"]; and
Information we receive from a consumer reporting agency, such as [provide illustrative examples, such as "your creditworthiness and credit history"].
Sample Clause A-2, Alternative 2:
We may disclose all of the information that we collect, as described [describe location in the notice, such as "above" or "below"].
A-3-Categories of information you disclose and parties to whom you disclose (institutions that do not disclose outside of the exceptions)
You may use this clause, as applicable, to meet the requirements of § 7(a)(2), (3), and (4) to describe the categories of nonpublic personal financial information about customers and former customers that you disclose and the categories of affiliates and nonaffiliated third parties to whom you disclose. You may use this clause if you do not disclose nonpublic personal financial information to any party, other than as permitted by the exceptions in § 15 and § 16.
Sample Clause A-3:
We do not disclose any nonpublic personal financial information about our customers or former customers to anyone, except as permitted by law.
A-4-Categories of parties to whom you disclose (institutions that disclose outside of the exceptions)
You may use this clause, as applicable, to meet the requirement of § 7(a)(3) to describe the categories of affiliates and nonaffiliated third parties to whom you disclose nonpublic personal financial information. You may use this clause if you disclose nonpublic personal financial information other than as permitted by the exceptions in § 14, § 15, and § 16, as well as when permitted by the exceptions in § 15 and § 16.
Sample Clause A-4:
We may disclose nonpublic personal financial information about you to the following types of third parties:
. Financial service providers, such as [provide illustrative examples, such as "mortgage bankers, securities broker-dealers, and insurance agents"];
. Non-financial companies, such as [provide illustrative examples, such as "retailers, direct marketers, airlines, and publishers"]; and
. Others, such as [provide illustrative examples, such as "non-profit organizations"].
We may also disclose nonpublic personal financial information about you to nonaffiliated third parties as permitted by law.
A-5-Service provider/joint marketing exception
You may use one of these clauses, as applicable, to meet the requirements of § 7(a)(5) related to the exception for service providers and joint marketers in § 14. If you disclose nonpublic personal information under this exception, you must describe the categories of nonpublic personal financial information you disclose and the categories of third parties with whom you have contracted.
Sample Clause A-5, Alternative 1:
We may disclose the following information to companies that perform marketing services on our behalf or to other financial institutions with which we have joint marketing agreements.
Information we receive from you on applications or other forms, such as [provide illustrative examples, such as "your name, address, social security number, assets, and income"];
. Information about your transactions with us, our affiliates, or others, such as [provide illustrative examples, such as "your account balance, payment history, parties to transactions, and credit card usage"]; and
. Information we receive from a consumer reporting agency, such as [provide illustrative examples, such as "your creditworthiness and credit history"].
Sample Clause A-5, Alternative 2:
We may disclose all of the information we collect, as described [describe location in the notice, such as "above" or "below"] to companies that perform marketing services on our behalf or to other financial institutions with whom we have joint marketing agreements.
Sample Clause A-5, Alternative 3:
We may disclose the following information to other financial institutions with which we have joint marketing agreements:
. The following information we receive from you: "your name and contact information";
. Information about your transactions with us or our affiliates, such as [provide illustrative examples of own transaction and experience information, such h as "your account balance, payment history, parties to transactions, and credit card usage"].
A-6 Explanation of opt in right (institutions that disclose to non affiliates outside of the exceptions)
You may use this clause, as applicable, to meet the requirement of § 7(a)(6) to provide an explanation of the consumer's right to opt in to the disclosure of nonpublic personal financial information to nonaffiliated third parties, including the method(s) by which the consumer may exercise that right. You may use this clause if you disclose nonpublic personal financial information to nonaffiliated third parties other than as permitted by the exceptions in § 14, § 15, and § 16.
Sample Clause A-6-b:
We will not disclose nonpublic personal financial information about you to nonaffiliated third parties (other than disclosures permitted by law), unless you authorize us to make those disclosures. Your authorization must be in writing or, if you agree, in electronic form. If you wish to authorize us to disclose your nonpublic personal financial information to nonaffiliated third parties, you may [describe a reasonable means of opting in, such as "sign the attached, postage prepaid card and mail it to us"].
A-7-Confidentiality and security (all institutions)
You may use this clause, as applicable, to meet the requirement of § 7(a)(8) to describe your policies and practices with respect to protecting the confidentiality and security of nonpublic personal information.
Sample Clause A-7:
We restrict access to nonpublic personal information about you to [provide an appropriate description, such as "those employees who need to know that information to provide products or services to you"]. We maintain physical, electronic, and procedural safeguards that comply with federal standards to guard your nonpublic personal information. 8 V.S.A. § 10; 9 V.S.A. §§ 4224a, 4229, 4237