research
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
Privacy Rule compliance guidance
> /plugin marketplace add GRCEngClub/claude-grc-engineeringHow it fires
How this command gets triggered: by you, by Claude, or both.
/privacyContext preview
What this command does when you run it.
Privacy Rule compliance guidance
description: Privacy Rule compliance guidance
Provides guidance on implementing the GLBA Privacy Rule (16 CFR Part 313) requirements for consumer privacy notices and information sharing.
**Authority**: 16 CFR Part 313 **Effective**: July 1, 2001 (with amendments) **Purpose**: Ensure consumers receive clear privacy notices and control over information sharing **Enforced by**: FTC, banking regulators, SEC, state regulators
**Requirement**: Provide clear, conspicuous privacy notice before establishing customer relationship
**Timing**:
**Content Requirements**:
1. **Information Collection**:
2. **Information Sharing**:
3. **Security Practices**:
4. **Consumer Rights**:
5. **Contact Information**:
**Format Requirements**:
**Requirement**: Provide annual privacy notice to customers at least once in 12-month period
**Exception**: Annual notice NOT required if:
1. Only share with affiliates 2. Only share under GLBA exceptions (service providers, joint marketing) 3. Have not changed privacy policies
**Many institutions now exempt from annual notice requirement due to 2015 FAST Act amendments**
**When Required**:
**Delivery Timing**:
**Requirement**: Provide revised notice before implementing material changes to privacy policies
**Material Changes**:
**Timing**: Reasonable time before implementing change
**Opt-Out**: New opt-out right required if change affects previous opt-out
**Requirement**: Allow consumers to opt-out of information sharing with nonaffiliated third parties
**When Opt-Out Required**:
**When Opt-Out NOT Required** (Exceptions):
**Opt-Out Mechanisms**:
**Opt-Out Duration**:
**Definition**: Personally identifiable financial information not publicly available
**Examples**:
**NOT NPI**:
**Affiliate**:
**Nonaffiliated Third Party**:
**Methods**:
**Advantages**:
**Disadvantages**:
**Methods**:
**E-SIGN Act Requirements**:
1. **Consumer Consent**: Affirmative consent to electronic delivery 2. **Demonstration of Access**: Consumer demonstrates ability to access electronic records 3. **Hardware/Software Requirements**: Disclose technical requirements 4. **Right to Paper**: Consumer can request paper copy 5. **Change Notice**: Notify if hardware/software requirements change
**Advantages**:
**Disadvantages**:
**Continu
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
Query AWS for compliance-relevant configuration across IAM, S3, CloudTrail, EBS, and emit findings conforming to the v1 contract.
Install the frdocx-to-froscal-ssp Python pipeline and verify its dependencies. Idempotent.
Retrieve a single AWS Secrets Manager secret value to stdout or a 0600-permission file. Opt-in retrieval mode — never writes to the findings cache.
Run testssl.sh against one or more HTTPS endpoints and emit v1 Findings mapped to SOC 2, NIST 800-53, PCI DSS 4.0.1, ISO 27001, and SCF controls.