Rules for
Privacy of Consumer Financial Information
Regulation S-P
Appendix B -- Sample Clauses
Financial institutions, including a group of financial holding company affiliates
that use a common privacy notice, may use the following sample clauses, if the
clause is accurate for each institution that uses the notice. (Note that disclosure
of certain information, such as assets, income, and information from a consumer
reporting agency, may give rise to obligations under the Fair Credit Reporting
Act, such as a requirement to permit a consumer to opt out of disclosures to affiliates
or designation as a consumer reporting agency if disclosures are made to nonaffiliated
third parties.)
A-1--Categories of Information You Collect (All Institutions)
You may use this clause, as applicable, to meet the requirement of Part 248.6(a)(1) to describe the categories of nonpublic personal information you collect.
Sample Clause A-1:
We collect nonpublic personal information about you from the following sources:
Information we receive from you on applications or other forms;
Information about your transactions with us, our affiliates, or others; and
Information we receive from a consumer reporting agency.
A-2--Categories of Information You Disclose (Institutions That Disclose Outside
of the Exceptions)
You may use one of these clauses, as applicable, to meet the requirement of §
248.6(a)(2) to describe the categories of nonpublic personal information you disclose.
You may use these clauses if you disclose nonpublic personal information other
than as permitted by the exceptions in § § 248.13, 248.14, and 248.15.
Sample Clause A-2, Alternative 1:
We may disclose the following kinds of nonpublic personal information about you:
Information we receive from you on applications or other forms, such as
[provide illustrative examples, such as "your name, address, social security
number, assets, and income"];
Information about your transactions with us, our affiliates, or others,
such as [ provide illustrative examples, such as "your account balance,
payment history, parties to transactions, and credit card usage"]; and
Information we receive from a consumer reporting agency, such as [provide
illustrative examples, such as "your creditworthiness and credit history"].
Sample Clause A-2, Alternative 2:
We may disclose all of the information that we collect, as described [describe
location in the notice, such as "above" or "below"].
A-3--Categories of Information You Disclose and Parties to Whom You Disclose
(Institutions That Do Not Disclose Outside of the Exceptions)
You may use this clause, as applicable, to meet the requirements of § § 248.6(a)(2),
(3), and (4) to describe the categories of nonpublic personal information about
customers and former customers that you disclose and the categories of affiliates
and nonaffiliated third parties to whom you disclose. You may use this clause
if you do not disclose nonpublic personal information to any party, other than
as permitted by the exceptions in § § 248.14 and 248.15.
Sample Clause A-3:
We do not disclose any nonpublic personal information about our customers or former
customers to anyone, except as permitted by law.
A-4--Categories of Parties to Whom You Disclose (Institutions That Disclose
Outside of the Exceptions)
You may use this clause, as applicable, to meet the requirement of § 248.6(a)(3)
to describe the categories of affiliates and nonaffiliated third parties to whom
you disclose nonpublic personal information. You may use this clause if you disclose
nonpublic personal information other than as permitted by the exceptions in §
§ 248.13, 248.14, and 248.15, as well as when permitted by the exceptions in §
§ 248.14 and 248.15.
Sample Clause A-4:
We may disclose nonpublic personal information about you to the following types
of third parties:
Financial service providers, such as [provide illustrative examples, such
as "mortgage bankers, securities broker-dealers, and insurance agents"];
Non-financial companies, such as [provide illustrative examples, such as
"retailers, direct marketers, airlines, and publishers"];
Others, such as [provide illustrative examples, such as "non-profit organizations"].
We may also disclose nonpublic personal information about you to nonaffiliated
third parties as permitted by law.
A-5--Service Provider/Joint Marketing Exception
You may use one of these clauses, as applicable, to meet the requirements of §
248.6(a)(5) related to the exception for service providers and joint marketers
in § 248.13. If you disclose nonpublic personal information under this exception,
you must describe the categories of nonpublic personal information you disclose
and the categories of third parties with whom you have contracted.
Sample Clause A-5, Alternative 1:
We may disclose the following information to companies that perform marketing
services on our behalf or to other financial institutions with which we have joint
marketing agreements:
Information we receive from you on applications or other forms, such as [ provide
illustrative examples, such as "your name, address, social security number, assets,
and income" ];
Information about your transactions with us, our affiliates, or others, such as
[ provide illustrative examples, such as "your account balance, payment history,
parties to transactions, and credit card usage" ]; and
Information we receive from a consumer reporting agency, such as [ provide illustrative
examples, such as "your creditworthiness and credit history" ].
Sample Clause A-5, Alternative 2:
We may disclose all of the information we collect, as described [ describe location
in the notice, such as "above" or "below" ] to companies that perform marketing
services on our behalf or to other financial institutions with whom we have joint
marketing agreements.
A-6--Explanation of Opt Out Right (Institutions That Disclose Outside of the
Exceptions)
You may use this clause, as applicable, to meet the requirement of § 248.6(a)(6)
to provide an explanation of the consumer's right to opt out of the disclosure
of nonpublic personal information to nonaffiliated third parties, including the
method(s) by which the consumer may exercise that right. You may use this clause
if you disclose nonpublic personal information other than as permitted by the
exceptions in § § 248.13, 248.14, and 248.15.
Sample Clause A-6:
If you prefer that we not disclose nonpublic personal information about you to
nonaffiliated third parties, you may opt out of those disclosures, that is, you
may direct us not to make those disclosures (other than disclosures permitted
by law). If you wish to opt out of disclosures to nonaffiliated third parties,
you may [describe a reasonable means of opting out, such as "call the following
toll-free number: (insert number)"].
A-7--Confidentiality and Security (All Institutions)
You may use this clause, as applicable, to meet the requirement of § 248.6(a)(8)
to describe your policies and practices with respect to protecting the confidentiality
and security of nonpublic personal information.
Sample Clause A-7:
We restrict access to nonpublic personal information about you to [provide
an appropriate description, such as "those employees who need to know that information
to provide products or services to you"]. We maintain physical, electronic,
and procedural safeguards that comply with federal standards to guard your nonpublic
personal information.
Notice to Users: The Deskbook is made available
with the understanding that the University of Cincinnati College
of Law is not engaged in rendering legal, accounting or other professional
services. If legal advice or other expert assistance is required,
the services of a competent professional person should be sought. See Terms and Conditions of Use.