CIPP-US - Limits on Private-Sector Collection and Use of Data - Section 2.3

Describe the consumer financial privacy protections under GLBA, FCRA/FACTA, and the requirements governing credit reporting, opt-out rights, and data accuracy.

Describe how the GLBA Safeguards Rule and annual financial privacy notice require financial institutions to protect customer data and disclose their sharing practices, with consumers able to opt out of sharing with non-affiliated third parties. Apply FCRA adverse action notices and the FACTA disposal rule, distinguishing consumer reporting agencies from furnishers.

GLBA Safeguards RuleFCRA adverse actionFACTA disposal ruleFinancial privacy notice

Practice question for this objective

Free sampleLimits on Private-Sector Collection and Use of Datahard

A holding company is selling one of its subsidiaries, a consumer lender that is a financial institution under the Gramm-Leach-Bliley Act, to an unaffiliated buyer. The subsidiary's customer files contain nonpublic personal information collected under GLBA privacy notices. The deal team asks whether the transfer of these customer files to the buyer requires the lender first to give each customer an opt-out under the GLBA Privacy Rule. What is the most accurate answer?

  • ANo, because the GLBA Privacy Rule includes an exception permitting disclosure in connection with a proposed or actual sale or transfer of a business or operating unit, so a separate opt-out is not required for the transfer itself. Correct
  • BYes, the lender must provide every customer a fresh opt-out notice and wait out the opt-out period before the files may be transferred, because any disclosure of nonpublic personal information to a nonaffiliated party requires opt-out.
  • CNo, because nonpublic personal information loses GLBA protection the moment it changes corporate hands, so the buyer may use the files for any purpose without restriction.
  • DNo, but only if the buyer signs a contract promising to send each affected customer a corrective notice within thirty days of closing, which the Privacy Rule mandates as the substitute for opt-out.
Recognise that the GLBA Privacy Rule's business-transfer exception lets a financial institution transfer customer data in a sale without first providing an opt-out. The GLBA Privacy Rule permits disclosure of nonpublic personal information to a nonaffiliated party without opt-out when the disclosure is made in connection with a proposed or actual sale, merger, transfer, or exchange of all or part of a business or operating unit, which is the basis for moving customer files in an acquisition of the lender.

Why A is correct: Correct: the Privacy Rule expressly excepts disclosures made in connection with a sale, merger, transfer, or exchange of a business or operating unit, so the lender may transfer the files as part of the deal without first running a customer opt-out for that transfer.

Why B is wrong: This is tempting because nonaffiliated sharing usually triggers opt-out, but the Privacy Rule contains exceptions that cover transfers in connection with a sale or transfer of the business, so a blanket opt-out requirement overstates the rule.

Why C is wrong: A candidate may assume a sale strips the data of its status, but the information remains nonpublic personal information in the buyer's hands and the buyer remains bound by GLBA limits, so this overstates the freedom a transfer creates.

Why D is wrong: The thirty-day corrective-notice substitute is invented; the Privacy Rule's business-transfer exception applies on its own terms and does not impose a fixed post-closing notice deadline, so this fabricates a requirement.

See more CIPP-US practice questions, answers explained.

More in this domain

Back to all Limits on Private-Sector Collection and Use of Data objectives, or the CIPP-US cert hub.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.