Skip to content
Security
Command

/privacy

Privacy Rule compliance guidance

From plugin
trust-center
367139 skills139 commands1 MCP
Install
$ npx -y skills add GRCEngClub/claude-grc-engineering --agent claude-code

How it fires

How this command gets triggered: by you, by Claude, or both.

  • Fires itselfClaude auto-loads it when your prompt matches the work.
  • You can call itInvoke it directly when you want it.
  • Slash command/privacy

Context preview

What this command does when you run it.

Privacy Rule compliance guidance

Command definition

privacy.md
description: Privacy Rule compliance guidance

GLBA Privacy Rule Compliance

Provides guidance on implementing the GLBA Privacy Rule (16 CFR Part 313) requirements for consumer privacy notices and information sharing.

Arguments

  • `$1` - Focus area (required: all, initial-notice, annual-notice, opt-out, sharing-practices, exceptions)
  • `$2` - Delivery method (optional: paper, electronic, website)

Privacy Rule Overview

**Authority**: 16 CFR Part 313 **Effective**: July 1, 2001 (with amendments) **Purpose**: Ensure consumers receive clear privacy notices and control over information sharing **Enforced by**: FTC, banking regulators, SEC, state regulators

Core Requirements

1. Initial Privacy Notice

**Requirement**: Provide clear, conspicuous privacy notice before establishing customer relationship

**Timing**:

  • At account opening
  • Before disclosing nonpublic personal information
  • Not later than when relationship established

**Content Requirements**:

1. **Information Collection**:

  • Categories of nonpublic personal information collected
  • Sources of information (customer, transactions, third parties)

2. **Information Sharing**:

  • Categories shared with affiliates
  • Categories shared with nonaffiliated third parties
  • Purpose of sharing

3. **Security Practices**:

  • Policies and practices to protect information
  • Safeguards implemented

4. **Consumer Rights**:

  • Right to opt-out of certain sharing
  • How to exercise opt-out rights

5. **Contact Information**:

  • How to contact institution
  • Customer service contact details

**Format Requirements**:

  • Clear and conspicuous
  • Reasonably understandable
  • Plain language
  • Separate document or prominent part of document

2. Annual Privacy Notice

**Requirement**: Provide annual privacy notice to customers at least once in 12-month period

**Exception**: Annual notice NOT required if:

1. Only share with affiliates 2. Only share under GLBA exceptions (service providers, joint marketing) 3. Have not changed privacy policies

**Many institutions now exempt from annual notice requirement due to 2015 FAST Act amendments**

**When Required**:

  • Share with nonaffiliated third parties beyond exceptions
  • Privacy policies have changed

**Delivery Timing**:

  • At least once in any 12-month period
  • No requirement to coordinate with account anniversary

3. Revised Privacy Notice

**Requirement**: Provide revised notice before implementing material changes to privacy policies

**Material Changes**:

  • New categories of information collected
  • New categories of affiliates/third parties to whom info disclosed
  • New purposes for disclosure
  • Changes to opt-out rights
  • Changes to security policies

**Timing**: Reasonable time before implementing change

**Opt-Out**: New opt-out right required if change affects previous opt-out

4. Opt-Out Rights

**Requirement**: Allow consumers to opt-out of information sharing with nonaffiliated third parties

**When Opt-Out Required**:

  • Sharing nonpublic personal information with nonaffiliated third parties
  • Sharing beyond GLBA exceptions

**When Opt-Out NOT Required** (Exceptions):

  • Sharing with service providers (processing transactions)
  • Joint marketing agreements (with customer authorization)
  • Sharing as permitted by law
  • Sharing with consumer reporting agencies
  • Sharing necessary to effect transaction customer requested

**Opt-Out Mechanisms**:

  • Must provide reasonable means to opt-out
  • Examples: Check-off box, reply form, toll-free number, online portal
  • Must allow opt-out at any time
  • Opt-out effective within reasonable time (30 days standard)

**Opt-Out Duration**:

  • Continues until revoked by consumer
  • Revocation must be voluntary and clear
  • Institution may require periodic reaffirmation (but not mandatory)

Information Categories

Nonpublic Personal Information (NPI)

**Definition**: Personally identifiable financial information not publicly available

**Examples**:

  • Name, address, SSN, income
  • Account numbers and balances
  • Transaction history
  • Credit scores and reports
  • Information from applications
  • Information from consumer reports

**NOT NPI**:

  • Publicly available information (phone book, government records)
  • De-identified/aggregated data
  • Information customer authorizes to be public

Affiliate vs. Nonaffiliated Third Party

**Affiliate**:

  • Company controlled by, controlling, or under common control
  • Example: Parent company, subsidiaries, sister companies
  • **Rule**: Can share with affiliates without opt-out (but annual notice may be required under FCRA)

**Nonaffiliated Third Party**:

  • Any entity not affiliated
  • Examples: Marketing companies, data brokers, unrelated financial institutions
  • **Rule**: Must provide opt-out unless exception applies

Privacy Notice Delivery Methods

Paper Delivery

**Methods**:

  • Mailed to customer's address
  • Hand-delivered at branch/office
  • Included with account statements

**Advantages**:

  • Accessible to all customers
  • Creates physical record
  • Familiar to customers

**Disadvantages**:

  • Printing and mailing costs
  • Delivery delays
  • Environmental impact

Electronic Delivery

**Methods**:

  • Email (with PDF attachment or link)
  • Website posting (with customer acknowledgment)
  • Mobile app notification
  • Secure messaging portal

**E-SIGN Act Requirements**:

1. **Consumer Consent**: Affirmative consent to electronic delivery 2. **Demonstration of Access**: Consumer demonstrates ability to access electronic records 3. **Hardware/Software Requirements**: Disclose technical requirements 4. **Right to Paper**: Consumer can request paper copy 5. **Change Notice**: Notify if hardware/software requirements change

**Advantages**:

  • Cost-effective
  • Immediate delivery
  • Eco-friendly
  • Easy to update

**Disadvantages**:

  • Requires customer consent
  • Technology barriers
  • Spam filters may block
  • Accessibility concerns

Website Posting

**Continu

Read more
Ships withtrust-center

Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.

Get the whole plugin, auto-invoked
Stats
367
Stars
0
Views
82
Forks
Active
Maintenance
JavaScript
Language
1d ago
Last commit
7mo ago
Created

Repo: GRCEngClub/claude-grc-engineering