Vermont Adopts Provisions Regarding Privacy of Consumer Financial and Health Information

The Vermont Department of Financial Regulation, Banking Division, adopted provisions relating to Regulation B-2018-01 regarding privacy of consumer financial and health information.  This regulation replaces Regulation B-2015-02 and is effective immediately.

Regulation B-2018-01 directs the handling of nonpublic personal information about consumers by financial institutions. “This regulation:

(1) Requires a financial institution to provide notice to individuals about its privacy policies and practices;

(2) Describes the conditions under which a financial institution may disclose nonpublic personal information about consumers to nonaffiliated third parties;

(3) Requires financial institutions to obtain consumer consent prior to disclosing that information, subject to the exceptions in Sections 14, 15, 16 and 17 of this regulation and 8 V.S.A. § 10204 and subject to the federal Fair Credit Reporting Act and Vermont Fair Credit Reporting Act; and,

(4) Provides an exemption from the provisions of 8 V.S.A. §§ 10201 et seq. for information about business customers.” (VT Regulation B-2018-01 Section 2(A))

The regulation is applicable to nonpublic personal information about individuals and nonpublic personal health information (VT Regulation B-2018-01 Section 2(B)).  The following, among others, are required to comply with this regulation:

  • financial institutions
  • lenders, mortgage brokers, sales finance companies, and mortgage loan originators
  • independent trust companies
  • money services providers
  • debt adjusters under
  • loan servicers
  • branches and agencies of foreign banks (VT Regulation B-2018-01 Section 2(C)).

Everyone subject to Regulation B-2018-01, regardless of the jurisdiction or domicile, is required to comply with the rules of the regulation when conducting transactions with Vermont consumers (VT Regulation B-2018-01 Section 2(D)).

Financial institutions are required to issue notice reflecting its privacy policies related to nonpublic personal information to customers and consumers (VT Regulation B-2018-01 Section 5(A)) and must provide this notice annually during a continued relationship (VT Regulation B-2018-01 Section 6(A)).

The full text of Regulation B-2018-01 can be found here: http://www.dfr.vermont.gov/sites/default/files/regulation-b-2018-1-privacy-of-consumer-financial-health-information.pdf

  • 781-402-6400

Comments are closed.