Florida Administrative Code (Last Updated: October 28, 2024) |
69. Department of Financial Services |
69O. OIR – Insurance Regulation |
69O-128. Privacy Of Consumer Financial And Health Information |
1(1)(a) Information the licensee receives under an exception. If a licensee receives nonpublic personal financial information from a nonaffiliated financial institution under an exception in Rule 2769O-128.015 28or 2969O-128.016, 30F.A.C., the licensee’s disclosure and use of that information is limited as follows:
431. The licensee may disclose the information to the affiliates of the financial institution from which the licensee received the information,
642. The licensee may disclose the information to its affiliates, but the licensee’s affiliates may, in turn, disclose and use the information only to the extent that the licensee may disclose and use the information; and,
1003. The licensee may disclose and use the information pursuant to an exception in Rule 11569O-128.015 116or 11769O-128.016, 118F.A.C., in the ordinary course of business to carry out the activity covered by the exception under which the licensee received the information.
141(b) Example. If a licensee receives information from a nonaffiliated financial institution for claims settlement purposes, the licensee may disclose the information for fraud prevention, or in response to a properly authorized subpoena. The licensee may not disclose that information to a third party for marketing purposes or use that information for its own marketing purposes.
197(2)(a) Information a licensee receives outside of an exception. If a licensee receives nonpublic personal financial information from a nonaffiliated financial institution other than under an exception in Rule 22669O-128.015 227or 22869O-128.016, 229F.A.C., the licensee may disclose the information only:
2371. To the affiliates of the financial institution from which the licensee received the information,
2522. To its affiliates, but its affiliates may, in turn, disclose the information only to the extent that the licensee may disclose the information; and,
2773. To any other person, if the disclosure would be lawful if made directly to that person by the financial institution from which the licensee received the information.
305(b) Example. If a licensee obtains a customer list from a nonaffiliated financial institution outside of the exceptions in Rule 32569O-128.015 326or 32769O-128.016, 328F.A.C.:
3291. The licensee may use that list for its own purposes; and,
3412. The licensee may disclose that list to another nonaffiliated third party only if the financial institution from which the licensee purchased the list could have lawfully disclosed the list to that third party. That is, the licensee may disclose the list in accordance with the privacy policy of the financial institution from which the licensee received the list, as limited by the opt out direction of each consumer whose nonpublic personal financial information the licensee intends to disclose, and the licensee may disclose the list in accordance with an exception in Rule 43469O-128.015 435or 43669O-128.016, 437F.A.C., such as to the licensee’s attorneys or accountants.
446(3) Information a licensee discloses under an exception. If a licensee discloses nonpublic personal financial information to a nonaffiliated third party under an exception in Rule 47269O-128.015 473or 47469O-128.016, 475F.A.C., the third party may disclose and use that information only as follows:
488(a) The third party may disclose the information to the licensee’s affiliates;
500(b) The third party may disclose the information to its affiliates, but its affiliates may, in turn, disclose and use the information only to the extent that the third party may disclose and use the information; and,
537(c) The third party may disclose and use the information pursuant to an exception in Rule 55369O-128.015 554or 55569O-128.016, 556F.A.C., in the ordinary course of business to carry out the activity covered by the exception under which it received the information.
578(4) Information a licensee discloses outside of an exception. If a licensee discloses nonpublic personal financial information to a nonaffiliated third party other than under an exception in Rule 60769O-128.015 608or 60969O-128.016, 610F.A.C., the third party may disclose the information only:
619(a) To the licensee’s affiliates;
624(b) To the third party’s affiliates, but the third party’s affiliates, in turn, may disclose the information only to the extent the third party can disclose the information; and,
653(c) To any other person, if the disclosure would be lawful if the licensee made it directly to that person.
673Rulemaking 674Authority 675624.308, 676626.9651 FS. 678Law Implemented 680624.307(1), 681626.9651 FS. 683History–New 12-16-01, Formerly 4-128.012.