§431:3A-203 - Information to be included in privacy notices.
[§431:3A-203] Information to be included in privacy notices. (a) The initial, annual,and revised privacy notices that a licensee provides under sections 431:3A-201,431:3A-202, and 431:3A-205 shall include the following information, in additionto any other information the licensee wishes to provide, that applies to thelicensee and to the consumers to whom the licensee sends its privacy notice:
(1)Ā The categories of nonpublic personal financialinformation that the licensee collects;
(2)Ā The categories of nonpublic personal financialinformation that the licensee discloses;
(3)Ā The categories of affiliates and nonaffiliatedthird parties to whom the licensee discloses nonpublic personal financialinformation, other than those parties to whom the licensee disclosesinformation under sections 431:3A-402 and 431:3A-403;
(4)Ā The categories of nonpublic personal financialinformation about the licenseeās former customers that the licensee discloses,and the categories of affiliates and nonaffiliated third parties to whom thelicensee discloses nonpublic personal financial information about thelicenseeās former customers, other than those parties to whom the licenseediscloses information under sections 431:3A-402 and 431:3A-403;
(5)Ā A separate description of the categories ofinformation the licensee discloses and the categories of third parties withwhom the licensee has contracted, if a licensee discloses nonpublic personalfinancial information to a nonaffiliated third party under section 431:3A-401 andno other exception in sections 431:3A-402 and 431:3A-403 applies to thatdisclosure;
(6)Ā An explanation of the consumerās right undersection 431:3A-301(a) to opt out of the disclosure of nonpublic personalfinancial information to nonaffiliated third parties, including the methods bywhich the consumer may exercise that right at that time;
(7)Ā Any disclosures that the licensee makes undersection 603(d)(2)(A)(iii) of the federal Fair Credit Reporting Act, Title 15United States Code section 1681a(d)(2)(A)(iii), as amended;
(8)Ā The licenseeās policies and practices withrespect to protecting the confidentiality and security of nonpublic personalinformation; and
(9)Ā Any disclosure that the licensee makes undersubsection (b).
(b)Ā If alicensee discloses nonpublic personal financial information under sections431:3A-402 and 431:3A-403, the licensee is not required to list thoseexceptions in the initial or annual privacy notices required by sections431:3A-201 and 431:3A-202.Ā When describing the categories of parties to whomdisclosure is made, the licensee shall state only that it makes disclosures toother affiliated or nonaffiliated third parties, as applicable, as permitted bylaw.
(c)Ā Alicensee may satisfy the initial notice requirements in sections 431:3A-201(a)and 431:3A-204(c) for a consumer who is not a customer by providing a shortform initial notice at the same time the licensee delivers an opt out noticeunder section 431:3A-204.Ā A short form initial notice shall:
(1)Ā Be clear and conspicuous;
(2)Ā State that the licenseeās privacy notice isavailable upon request; and
(3)Ā Explain a reasonable means by which the consumermay obtain that notice.
Thelicensee shall deliver a short form initial notice in accordance with section431:3A-206.Ā The licensee shall not be required to deliver its privacy noticewith its short form initial notice; provided that the licensee provides theconsumer a reasonable means to obtain a privacy notice.Ā If a consumer receivesthe licenseeās short form notice and requests a privacy notice, the licenseeshall deliver a privacy notice under section 431:3A-206.
(d)Ā Theprivacy notice may include:
(1)Ā Categories of nonpublic personal financialinformation that the licensee reserves the right to disclose in the future, butdoes not currently disclose; and
(2) Categories of affiliates or nonaffiliated thirdparties to whom the licensee reserves the right in the future to disclose, butto whom the licensee does not currently disclose, nonpublic personal financialinformation. [L 2001, c 220, pt of §1]