Current through Register Vol. XLI, No. 45, November 8, 2024
Section 114-62-1 - General1.1. Scope. -- This rule establishes standards for developing and implementing administrative, technical and physical safeguards to protect the security, confidentiality and integrity of customer information, pursuant to sections 501 and 507, and subsection 505(b) of the Gramm-Leach-Bliley Act, codified at 15 U.S.C. 6801, 6807 and 6805(b). Section 507 of the Act provides, among other things, that a state regulation may afford persons greater privacy protections than those provided by subtitle A of Title V of the Gramm-Leach-Bliley Act. The safeguards established pursuant to this rule shall apply to nonpublic personal information, including nonpublic personal financial information and nonpublic personal health information.1.2. Authority. -- W.Va. Code §§ 33-6F-1 and 33-2-10. a. Subsection 501(a) of the Gramm-Leach-Bliley Act, 15 U.S.C. 6801, provides that it is the policy of the Congress that each financial institution has an affirmative and continuing obligation to respect the privacy of its customers and to protect the security and confidentiality of those customers' nonpublic personal information.b. Subsection 501(b) of the Act requires the state insurance regulatory authorities to establish appropriate standards relating to administrative, technical and physical safeguards:1. To ensure the security and confidentiality of customer records and information;2. To protect against any anticipated threats or hazards to the security or integrity of such records; and3. To protect against unauthorized access to or use of records or information that could result in substantial harm or inconvenience to a customer.c. Paragraph 505(b)(2) of the Gramm-Leach-Bliley Act, 15 U.S.C. 6805(b), calls on state insurance regulatory authorities to implement the standards prescribed under subsection 501(b) by regulation with respect to persons engaged in providing insurance.d. Paragraph 503(a)(3) of the Gramm-Leach-Bliley Act, codified at 15 U.S.C. section 6803 (a)(3), requires each financial institution to develop policies for protecting the nonpublic personal information of consumers and to make those policies available in written form.1.3. Filing Date. -- April 3, 2003.1.4. Effective Date. -- April 3, 2003.W. Va. Code R. § 114-62-1