Or. Admin. Code § 836-080-0675

Current through Register Vol. 63, No. 11, November 1, 2024
Section 836-080-0675 - Disclosure Without Authorization

Unless disclosure is otherwise permitted pursuant to OAR 836-080-0665 or 836-080-0670, a licensee may disclose personal financial information about an individual to a nonaffiliated third party without obtaining the written authorization required by 836-080-0665 only if all of the following conditions are met:

(1) The nonaffiliated third party's only use of the information will be in connection with the marketing of a product or service.
(2) No information relating to an individual's character, personal habits, mode of living or general reputation may be disclosed, and no classification derived from such information may be disclosed.
(3) Prior to disclosure, the individual must have been given the notice described in OAR 836-080-0620 and, at the same time, an opportunity to decide whether to allow disclosure of the information by means of a clear and conspicuous notice that provides the following:
(a) That the licensee discloses or reserves the right to disclose personal financial information about the individual to a nonaffiliated third party;
(b) That the individual has the right to opt out of that disclosure; and
(c) A reasonable means by which the individual may exercise the opt out right.
(4) Disclosure of personal financial information that is also individually identifiable health information is not prohibited or otherwise regulated under the federal Health Insurance Portability and Accountability Act of 1996 (P.L. 104-191).

Or. Admin. Code § 836-080-0675

ID 4-2005, f. & cert. ef. 4-1-05

Stat. Auth.: ORS 731.244 & 746.608

Stats. Implemented: ORS 746.600 & 746.607