/privacy
Privacy Rule compliance guidance
$ npx -y skills add GRCEngClub/claude-grc-engineering --agent claude-codeHow it fires
How this command gets triggered: by you, by Claude, or both.
- Fires itselfClaude auto-loads it when your prompt matches the work.
- You can call itInvoke it directly when you want it.
- Slash command
/privacy
Context preview
What this command does when you run it.
Privacy Rule compliance guidance
Command definition
privacy.mddescription: Privacy Rule compliance guidance
GLBA Privacy Rule Compliance
Provides guidance on implementing the GLBA Privacy Rule (16 CFR Part 313) requirements for consumer privacy notices and information sharing.
Arguments
- `$1` - Focus area (required: all, initial-notice, annual-notice, opt-out, sharing-practices, exceptions)
- `$2` - Delivery method (optional: paper, electronic, website)
Privacy Rule Overview
**Authority**: 16 CFR Part 313 **Effective**: July 1, 2001 (with amendments) **Purpose**: Ensure consumers receive clear privacy notices and control over information sharing **Enforced by**: FTC, banking regulators, SEC, state regulators
Core Requirements
1. Initial Privacy Notice
**Requirement**: Provide clear, conspicuous privacy notice before establishing customer relationship
**Timing**:
- At account opening
- Before disclosing nonpublic personal information
- Not later than when relationship established
**Content Requirements**:
1. **Information Collection**:
- Categories of nonpublic personal information collected
- Sources of information (customer, transactions, third parties)
2. **Information Sharing**:
- Categories shared with affiliates
- Categories shared with nonaffiliated third parties
- Purpose of sharing
3. **Security Practices**:
- Policies and practices to protect information
- Safeguards implemented
4. **Consumer Rights**:
- Right to opt-out of certain sharing
- How to exercise opt-out rights
5. **Contact Information**:
- How to contact institution
- Customer service contact details
**Format Requirements**:
- Clear and conspicuous
- Reasonably understandable
- Plain language
- Separate document or prominent part of document
2. Annual Privacy Notice
**Requirement**: Provide annual privacy notice to customers at least once in 12-month period
**Exception**: Annual notice NOT required if:
1. Only share with affiliates 2. Only share under GLBA exceptions (service providers, joint marketing) 3. Have not changed privacy policies
**Many institutions now exempt from annual notice requirement due to 2015 FAST Act amendments**
**When Required**:
- Share with nonaffiliated third parties beyond exceptions
- Privacy policies have changed
**Delivery Timing**:
- At least once in any 12-month period
- No requirement to coordinate with account anniversary
3. Revised Privacy Notice
**Requirement**: Provide revised notice before implementing material changes to privacy policies
**Material Changes**:
- New categories of information collected
- New categories of affiliates/third parties to whom info disclosed
- New purposes for disclosure
- Changes to opt-out rights
- Changes to security policies
**Timing**: Reasonable time before implementing change
**Opt-Out**: New opt-out right required if change affects previous opt-out
4. Opt-Out Rights
**Requirement**: Allow consumers to opt-out of information sharing with nonaffiliated third parties
**When Opt-Out Required**:
- Sharing nonpublic personal information with nonaffiliated third parties
- Sharing beyond GLBA exceptions
**When Opt-Out NOT Required** (Exceptions):
- Sharing with service providers (processing transactions)
- Joint marketing agreements (with customer authorization)
- Sharing as permitted by law
- Sharing with consumer reporting agencies
- Sharing necessary to effect transaction customer requested
**Opt-Out Mechanisms**:
- Must provide reasonable means to opt-out
- Examples: Check-off box, reply form, toll-free number, online portal
- Must allow opt-out at any time
- Opt-out effective within reasonable time (30 days standard)
**Opt-Out Duration**:
- Continues until revoked by consumer
- Revocation must be voluntary and clear
- Institution may require periodic reaffirmation (but not mandatory)
Information Categories
Nonpublic Personal Information (NPI)
**Definition**: Personally identifiable financial information not publicly available
**Examples**:
- Name, address, SSN, income
- Account numbers and balances
- Transaction history
- Credit scores and reports
- Information from applications
- Information from consumer reports
**NOT NPI**:
- Publicly available information (phone book, government records)
- De-identified/aggregated data
- Information customer authorizes to be public
Affiliate vs. Nonaffiliated Third Party
**Affiliate**:
- Company controlled by, controlling, or under common control
- Example: Parent company, subsidiaries, sister companies
- **Rule**: Can share with affiliates without opt-out (but annual notice may be required under FCRA)
**Nonaffiliated Third Party**:
- Any entity not affiliated
- Examples: Marketing companies, data brokers, unrelated financial institutions
- **Rule**: Must provide opt-out unless exception applies
Privacy Notice Delivery Methods
Paper Delivery
**Methods**:
- Mailed to customer's address
- Hand-delivered at branch/office
- Included with account statements
**Advantages**:
- Accessible to all customers
- Creates physical record
- Familiar to customers
**Disadvantages**:
- Printing and mailing costs
- Delivery delays
- Environmental impact
Electronic Delivery
**Methods**:
- Email (with PDF attachment or link)
- Website posting (with customer acknowledgment)
- Mobile app notification
- Secure messaging portal
**E-SIGN Act Requirements**:
1. **Consumer Consent**: Affirmative consent to electronic delivery 2. **Demonstration of Access**: Consumer demonstrates ability to access electronic records 3. **Hardware/Software Requirements**: Disclose technical requirements 4. **Right to Paper**: Consumer can request paper copy 5. **Change Notice**: Notify if hardware/software requirements change
**Advantages**:
- Cost-effective
- Immediate delivery
- Eco-friendly
- Easy to update
**Disadvantages**:
- Requires customer consent
- Technology barriers
- Spam filters may block
- Accessibility concerns
Website Posting
**Continu
Read more
description: Privacy Rule compliance guidance
GLBA Privacy Rule Compliance
Provides guidance on implementing the GLBA Privacy Rule (16 CFR Part 313) requirements for consumer privacy notices and information sharing.
Arguments
- `$1` - Focus area (required: all, initial-notice, annual-notice, opt-out, sharing-practices, exceptions)
- `$2` - Delivery method (optional: paper, electronic, website)
Privacy Rule Overview
**Authority**: 16 CFR Part 313 **Effective**: July 1, 2001 (with amendments) **Purpose**: Ensure consumers receive clear privacy notices and control over information sharing **Enforced by**: FTC, banking regulators, SEC, state regulators
Core Requirements
1. Initial Privacy Notice
**Requirement**: Provide clear, conspicuous privacy notice before establishing customer relationship
**Timing**:
- At account opening
- Before disclosing nonpublic personal information
- Not later than when relationship established
**Content Requirements**:
1. **Information Collection**:
- Categories of nonpublic personal information collected
- Sources of information (customer, transactions, third parties)
2. **Information Sharing**:
- Categories shared with affiliates
- Categories shared with nonaffiliated third parties
- Purpose of sharing
3. **Security Practices**:
- Policies and practices to protect information
- Safeguards implemented
4. **Consumer Rights**:
- Right to opt-out of certain sharing
- How to exercise opt-out rights
5. **Contact Information**:
- How to contact institution
- Customer service contact details
**Format Requirements**:
- Clear and conspicuous
- Reasonably understandable
- Plain language
- Separate document or prominent part of document
2. Annual Privacy Notice
**Requirement**: Provide annual privacy notice to customers at least once in 12-month period
**Exception**: Annual notice NOT required if:
1. Only share with affiliates 2. Only share under GLBA exceptions (service providers, joint marketing) 3. Have not changed privacy policies
**Many institutions now exempt from annual notice requirement due to 2015 FAST Act amendments**
**When Required**:
- Share with nonaffiliated third parties beyond exceptions
- Privacy policies have changed
**Delivery Timing**:
- At least once in any 12-month period
- No requirement to coordinate with account anniversary
3. Revised Privacy Notice
**Requirement**: Provide revised notice before implementing material changes to privacy policies
**Material Changes**:
- New categories of information collected
- New categories of affiliates/third parties to whom info disclosed
- New purposes for disclosure
- Changes to opt-out rights
- Changes to security policies
**Timing**: Reasonable time before implementing change
**Opt-Out**: New opt-out right required if change affects previous opt-out
4. Opt-Out Rights
**Requirement**: Allow consumers to opt-out of information sharing with nonaffiliated third parties
**When Opt-Out Required**:
- Sharing nonpublic personal information with nonaffiliated third parties
- Sharing beyond GLBA exceptions
**When Opt-Out NOT Required** (Exceptions):
- Sharing with service providers (processing transactions)
- Joint marketing agreements (with customer authorization)
- Sharing as permitted by law
- Sharing with consumer reporting agencies
- Sharing necessary to effect transaction customer requested
**Opt-Out Mechanisms**:
- Must provide reasonable means to opt-out
- Examples: Check-off box, reply form, toll-free number, online portal
- Must allow opt-out at any time
- Opt-out effective within reasonable time (30 days standard)
**Opt-Out Duration**:
- Continues until revoked by consumer
- Revocation must be voluntary and clear
- Institution may require periodic reaffirmation (but not mandatory)
Information Categories
Nonpublic Personal Information (NPI)
**Definition**: Personally identifiable financial information not publicly available
**Examples**:
- Name, address, SSN, income
- Account numbers and balances
- Transaction history
- Credit scores and reports
- Information from applications
- Information from consumer reports
**NOT NPI**:
- Publicly available information (phone book, government records)
- De-identified/aggregated data
- Information customer authorizes to be public
Affiliate vs. Nonaffiliated Third Party
**Affiliate**:
- Company controlled by, controlling, or under common control
- Example: Parent company, subsidiaries, sister companies
- **Rule**: Can share with affiliates without opt-out (but annual notice may be required under FCRA)
**Nonaffiliated Third Party**:
- Any entity not affiliated
- Examples: Marketing companies, data brokers, unrelated financial institutions
- **Rule**: Must provide opt-out unless exception applies
Privacy Notice Delivery Methods
Paper Delivery
**Methods**:
- Mailed to customer's address
- Hand-delivered at branch/office
- Included with account statements
**Advantages**:
- Accessible to all customers
- Creates physical record
- Familiar to customers
**Disadvantages**:
- Printing and mailing costs
- Delivery delays
- Environmental impact
Electronic Delivery
**Methods**:
- Email (with PDF attachment or link)
- Website posting (with customer acknowledgment)
- Mobile app notification
- Secure messaging portal
**E-SIGN Act Requirements**:
1. **Consumer Consent**: Affirmative consent to electronic delivery 2. **Demonstration of Access**: Consumer demonstrates ability to access electronic records 3. **Hardware/Software Requirements**: Disclose technical requirements 4. **Right to Paper**: Consumer can request paper copy 5. **Change Notice**: Notify if hardware/software requirements change
**Advantages**:
- Cost-effective
- Immediate delivery
- Eco-friendly
- Easy to update
**Disadvantages**:
- Requires customer consent
- Technology barriers
- Spam filters may block
- Accessibility concerns
Website Posting
**Continu
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Other commands on trust-center.
- /research
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
Open command - /collect
Query AWS for compliance-relevant configuration across IAM, S3, CloudTrail, EBS, and emit findings conforming to the v1 contract.
Open command - /setup
Install the frdocx-to-froscal-ssp Python pipeline and verify its dependencies. Idempotent.
Open command - /status
Check the deployment status of the trust center.
Open command - /scan
Run testssl.sh against one or more HTTPS endpoints and emit v1 Findings mapped to SOC 2, NIST 800-53, PCI DSS 4.0.1, ISO 27001, and SCF controls.
Open command - /compliance-posture
Serve a localhost compliance posture dashboard from monitor-continuous JSON
Open command

