Skip to content
BOL Conferences

Thread Options
#656380 - 12/22/06 05:00 PM privacy statement for vendors
kira Offline
100 Club
Joined: Jul 2006
Posts: 219
This was posed to me and I have research with little findings. Does anyone have or use a list of critical vendors that you send out an annual privacy statement?
At my other employement, any firm that had a contact acknowledged our privacy statement. Here they want to send out a privacy statement to all critical vendors annually , have it signed and returned. What is anyone else doing?? The auditor wants to do an audit and doesn't know, go figure..
Thanks for any infor on this.

Return to Top
Operations Compliance
#657367 - 12/26/06 09:32 PM Re: privacy statement for vendors kira
kira Offline
100 Club
Joined: Jul 2006
Posts: 219
Thanks, I'll look into that

Return to Top
#658323 - 12/28/06 03:28 PM Re: privacy statement for vendors kira
J.R. Offline
Junior Member
Joined: Aug 2005
Posts: 40
Midwest
We are performing an annual risk assessment of all our vendors along with that we indicate if they have access to customer information. If they do we require an annual ackowledgement. That means the folks who wash our windows and clean our facilities sign it along with our external auditors and most of our IT vendors.

Return to Top
#658329 - 12/28/06 03:36 PM Re: privacy statement for vendors J.R.
kira Offline
100 Club
Joined: Jul 2006
Posts: 219
Thanks for sharing its very helpful..anyone else??

Return to Top
#659312 - 12/29/06 08:24 PM Re: privacy statement for vendors kira
kira Offline
100 Club
Joined: Jul 2006
Posts: 219
Are there any guidelines regarding vendor acknowledgement on this privacy issue and what is required? The questions won't stop. Thanks

Return to Top
#660177 - 01/03/07 02:13 PM Re: privacy statement for vendors kira
Starter Offline
Platinum Poster
Starter
Joined: Aug 2004
Posts: 513
NJ
I also have some additional questions:

Is a signature required from our vendors or do we have to just show proof that we sent them our own privacy policy for review?

Is an annual mailing required to our vendors, or is the initial signature good for as long as services are provided?

Who exactly should we be getting notices to - only our critical vendors or do we need them from contractors hired to perform work inside our branches?

Return to Top
#660234 - 01/03/07 03:16 PM Re: privacy statement for vendors Starter
rlcarey Online
10K Club
rlcarey
Joined: Jul 2001
Posts: 84,659
Galveston, TX
Sending them a copy of your privacy notice or policy accomplishes nothing. The regulation requires that you ensure that your vendors maintain the information that you provide them confidential. It has nothing to do with the bank's privacy policy.

You have to have a "contractual" agreement with your vendors to the fact that information may not be shared beyond what is allowed by the regulation. Having them sign an annual notice is meaningless in my mind as long as the original contract is still in place and contains the appropriate contractual clauses.
_________________________
The opinions expressed here should not be construed to be those of my employer: PPDocs.com

Return to Top
#663302 - 01/09/07 03:59 PM Re: privacy statement for vendors rlcarey
kira Offline
100 Club
Joined: Jul 2006
Posts: 219
This has come up again, the bank is determined to have new privacy agreements sent to various vendors for acknowledgement. I do not believe it has been done correctly in the past and they want to get it right with one shot. I believe, given your statement above, this need only be done once as long as there has not been a change in vendor or poilcy. I am correct?

Return to Top
#664607 - 01/11/07 02:24 PM Re: privacy statement for vendors kira
Patsy Cline Offline
Diamond Poster
Patsy Cline
Joined: Sep 2002
Posts: 1,117
On the road...
What is your definition of privacy agreement? In addition to your bank's internal privacy and safeguarding policies you must require that your vendors implement an info security program too. "Information Security and Incident Response Agreement" This must be agreed to as part of the written agreement. This program should ensure the security and confidentiality of customer information; protect against any anticipated threats or hazards to the security and integrity of such information; and protect against unauthorized access to or use of such information that could result in substantial harm or inconvenience to any customer. The agreement must also include incident response.
_________________________
Michelle CRCM

"What would you attempt to do if you knew you could not fail?" ~ unknown


Return to Top

Moderator:  Andy_Z, John Burnett