Skip to content
BOL Conferences
Thread Options
#311667 - 02/02/05 08:51 PM Confidentiality agreements
Ellis Offline
Junior Member
Ellis
Joined: Feb 2003
Posts: 25
Can someone give me the regulatory site where it says that banks have to have confidentiality agreements with third-party vendors who might have access to their customer's non-public information. I know it is from the G-L-B Act but have not been able to find the information security site to reference. Thank you in advance.

Return to Top
Security - PUBLIC
#311668 - 02/10/05 04:31 PM Re: Confidentiality agreements
GregS Offline
100 Club
Joined: Jan 2005
Posts: 135
Sunny Florida
HeeereYaaaGo.
I believe this it the FDIC IT Handbook
The IT Handbook’s “Outsourcing Technology Services Booklet” lists detailed contract recommendations for TSPs. Institutions should tailor these recommendations to e-banking services as necessary.
_________________________
We shall endeavor to persevere.

Return to Top
#311669 - 02/11/05 04:14 PM Re: Confidentiality agreements
E.E.G.B Offline
Power Poster
E.E.G.B
Joined: Jul 2002
Posts: 6,726
the sandy shore
It's in the section pertaining to safeguarding customer information - 508, I want to say, although I've been reading obscure laws for three days now and that might not be the right number. Anyway, it's in the section regarding vendor management. The regulatory agencies FILs on the topic also give some guidance.
_________________________
I disbelieved what he was saying so hard, I probably created an alternate universe where it wasn't true.

Return to Top
#311670 - 02/11/05 07:31 PM Re: Confidentiality agreements
Reads Regs Offline
Diamond Poster
Joined: Nov 2004
Posts: 2,310
Section 501(b) of title V of the GLBA requires us to safeguard customer information and it required the regulatory agencies to issue guidelines. The OTS guidelines for safeguarding of customer information can be found in Appendix B of 12 CFR part 570. Here is the text of section III. D. of the guidelines.

"D. OVERSEE SERVICE PROVIDER ARRANGEMENTS. You shall:
1. Exercise appropriate due diligence in selecting your service providers;
2. Require your service providers by contract to implement appropriate measures designed to meet the objectives of these Guidelines ; and
3. Where indicated by your risk assessment, monitor your service providers to confirm that they have satisfied their obligations as required by paragraph D.2. As part of this monitoring, you should review audits, summaries of test results, or other equivalent evaluations of your service providers."

There is also something in the privacy regulations that requires something in your contract if you enter into a joint marketing agreement. Here is the text of section 573.13 of the OTS regulations.

"§ 573.13 Exception to opt out requirements for service providers and joint marketing.
(a) General rule.
(1) The opt out requirements in §§573.7 and 573.10 do not apply when you provide nonpublic personal information to a nonaffiliated third party to perform services for you or functions on your behalf, if you:
(i) Provide the initial notice in accordance with §573.4; and
(ii) Enter into a contractual agreement with the third party that prohibits the third party from disclosing or using the information other than to carry out the purposes for which you disclosed the information, including use under an exception in §573.14 or 573.15 in the ordinary course of business to carry out those purposes.
(2) EXAMPLE. If you disclose nonpublic personal information under this section to a financial institution with which you perform joint marketing, your contractual agreement with that institution meets the requirements of paragraph (a)(1)(ii) of this section if it prohibits the institution from disclosing or using the nonpublic personal information except as necessary to carry out the joint marketing or under an exception in §573.14 or 573.15 in the ordinary course of business to carry out that joint marketing."

Return to Top
#311671 - 02/11/05 09:13 PM Re: Confidentiality agreements
E.E.G.B Offline
Power Poster
E.E.G.B
Joined: Jul 2002
Posts: 6,726
the sandy shore
(501, 508, whatever works. ) Thanks for posting the data, regs!
_________________________
I disbelieved what he was saying so hard, I probably created an alternate universe where it wasn't true.

Return to Top
#311672 - 02/14/05 02:47 PM Re: Confidentiality agreements
Retired DQ Offline
10K Club
Retired DQ
Joined: Dec 2002
Posts: 40,766
Turnpike Exit 10
Ellis, I have a confidentiality that we have been using for vendors, if you send me your email address, I can send it to you.
_________________________
Get your facts first, then you can distort them as you please. - Mark Twain

Return to Top
#311673 - 03/24/05 08:59 PM Re: Confidentiality agreements
Dip Offline
Power Poster
Dip
Joined: Mar 2005
Posts: 6,298
San Diego, CA
it's in the "interagency guidelines establishing standards for information security." new guidelines came out this month though, which add another provision for the agreements, called "guidance on response programs for unauthorized access to customer information and customer notice."
_________________________
Dabbling in banking, law, accounting...the life of a trustee.

Return to Top
#311674 - 04/23/05 03:46 PM Re: Confidentiality agreements
Sisyphus Offline
100 Club
Sisyphus
Joined: Jun 2004
Posts: 214
Connecticut
_________________________
Michele A. Johnson, Compliance Manager Integrated Compliance Solutions, LLC

Return to Top

Moderator:  Andy_Z