Financial Privacy Landscape and Regulators
U.S. financial privacy is governed mainly by the FCRA (1970), GLBA (1999), and the Dodd-Frank Act (2010), which created the CFPB. Financial institutions face both restrictions on use/disclosure and mandatory disclosure duties under anti-money-laundering laws.
How this supports CIPP/US study
Use this lesson to separate sectoral scope, data type and regulated entity before testing an exception. Continue with the CIPP/US practice exam.
Banking and financial records have long been treated as confidential, both to encourage honest borrower reporting and to protect against thieves and fraudsters. This chapter covers how financial firms may collect, use and disclose personal information, plus the rules requiring them to disclose information (anti-money-laundering laws).
The chapter proceeds through the FCRA (1970, updated by FACTA in 2003), the privacy and security provisions of GLBA (1999), and the Dodd-Frank Act (2010), which created the CFPB. The CFPB now has rulemaking authority for the FCRA/FACTA and most GLBA institutions, sharing enforcement with the FTC and banking regulators.
FCRA/FACTA governs credit reporting; GLBA governs financial-institution data handling; Dodd-Frank created the regulator (CFPB) and added the "abusive" enforcement standard.
Key terms - quick answers
What is “FCRA”?
What is “FACTA”?
What is “GLBA”?
What is “Dodd-Frank Act”?
Sources and study method
This independent lesson uses active recall, spaced retrieval and scenario practice. Read the full study method.